-
Notifications
You must be signed in to change notification settings - Fork 190
Redesign airlock storage account architecture #5048
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
Marcus Robinson (marrobi)
wants to merge
67
commits into
microsoft:main
Choose a base branch
from
marrobi:copilot/copilotredesign-airlock-storage-accounts
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from 2 commits
Commits
Show all changes
67 commits
Select commit
Hold shift + click to select a range
260a1be
Redesign airlock storage account architecture
marrobi 63e8ab0
Merge branch 'main' into copilot/copilotredesign-airlock-storage-acco…
marrobi d64ec28
Fix airlock v2 defaults, scan verdict persistence, and processor edge…
marrobi 53118a7
Airlock v2: allow API-issued SAS to read import-in-progress for revie…
marrobi bf205c1
Consolidate airlock v2 changelog into a single enhancement with doc l…
marrobi 0f477db
Store early airlock scan verdict on request instead of container meta…
marrobi 6e7909e
Address PR #5048 review: per-workspace airlock DNS, request migration…
marrobi 963df68
Restore per-workspace airlock SAS signer + version-change guard from …
marrobi 560175f
Finish legacy-airlock guards and address review comments (#5048)
marrobi 19609d4
Version-aware import-review: restore v1 (stalimip) connectivity behin…
marrobi 8d5c8f7
Backfill airlock_version in the startup guard before the block check …
marrobi d1751f5
Address review: v2 submit file handling, version-change/patch guards,…
marrobi cf281ac
Address PR #5048 review #4963131058: guard/blob-created/review-worksp…
marrobi 6fc28b6
Fix airlock review #4963547500 + live-found isPrivateLink ABAC bug
marrobi 7a0eb3c
Address suppressed review #4964016031 (K1/K2/K3)
marrobi 8ac8674
Make airlock CHANGELOG entry concise
marrobi 6f9fee5
Add breaking-change note to set enable_legacy_airlock explicitly
marrobi 9c38eba
update changelog
marrobi a61df5f
Create the airlock SAS signer for every workspace, including manual auth
marrobi 9db39d4
Revert unintended terraform lock file provider bump
marrobi db13c7d
Correct stale airlock docs/comments after manual-auth v2 support
marrobi c87fe95
Make the airlock container stage update atomic and stop dead-letterin…
marrobi 413d32d
Delete a workspace's airlock containers when the workspace is deleted
marrobi 8fa83a1
Give core its own DNS zone for the shared global airlock account
marrobi a304c4f
Remove the App Gateway airlock storage proxy
marrobi fdc7030
Address review 4965636608: legacy-safe version defaults, retry fields…
marrobi 61c6dc6
Check an airlock request belongs to the workspace in the path
marrobi 0c9651b
Address review feedback: sovereign-cloud signer issuer, airlock_versi…
marrobi b331528
Make submission file validation authoritative over an early scan verdict
marrobi 47e76ab
Wire ENABLE_LEGACY_AIRLOCK through the core deployment workflow
marrobi af61381
Refactor airlock logic and documentation for clarity and accuracy
marrobi 53d07d9
Record the airlock scan verdict as a fact and decide the submission o…
marrobi ac37848
Report submission files only after the container stage is locked
marrobi b1de06c
Remove airlock_version backfills, the unused import-review identity a…
marrobi 0a9db05
Remove unreachable legacy routing, unused helpers and the dead in-fli…
marrobi 9c2e5f0
Restrict researcher access to export data once it leaves draft
marrobi 0327329
Seal submissions by copying out of a draft container and deleting it
marrobi b869f0c
Preserve v1 terraform state addresses when gating legacy airlock behi…
marrobi ea6122c
Enumerate the draft container when validating submitted files
marrobi 57e7613
Add e2e coverage for the draft container seal, file count validation …
marrobi eb18ef8
Add airlock e2e selector and /test-airlock PR command
marrobi c37d4f2
Assert in-progress airlock data is refused from the public internet
marrobi 66a9329
Fix late scan verdicts stranding requests and sovereign cloud token e…
marrobi c9dbcdd
Only block airlock version changes for in-flight requests
marrobi 9b8f709
Gate review on the submitted copy's scan verdict and acknowledge dupl…
marrobi b8d9369
Fail closed on malformed verdicts and unknown request types, remove d…
marrobi 690162f
Default new workspaces to airlock v2 and stamp pre-v2 workspaces via …
marrobi a58ced4
Persist late file enumeration results instead of discarding them
marrobi d9a17db
Cover the malware-scanning-disabled submit path
marrobi 55c10b1
Block airlock version downgrade and abort a copy left pending at timeout
marrobi ffd0b0b
Fix markdownlint line-length and code-block-style in airlock-legacy docs
marrobi 3633fd2
Correct docs: upgrading a workspace to v2 deletes completed v1 reques…
marrobi 303f85f
Acknowledge file-only step results as facts without republishing a st…
marrobi aeb69ac
Retry transient processor errors and remove dead terminal-stage skip …
marrobi f943efb
Tag the airlock workspace-global DNS A record with tre_id
marrobi 21180ea
Include cancelled requests in workspace deletion airlock cleanup
marrobi 2c0ee29
Allow cancelling a Submitted airlock request
marrobi b6c539b
Reject airlock request creation on v1 workspace when legacy airlock d…
marrobi 509dbd0
Version base workspace as minor 2.11.0 so v1 workspaces can upgrade i…
marrobi 150ff05
Guard blob/event parsing and fix malformed scan-result log statement
marrobi 17749fe
Sync airlock docs with current code: submit seal/immutability, cancel…
marrobi ee7d3bd
Remove spurious v1 airlock moved blocks for already-counted resources
marrobi 76e6233
Revert Submitted->Cancelled (async ordering race); version import-rev…
marrobi 44f8921
Docs: revert cancel-from-submitted to match reverted transition
marrobi 7928af7
Wrap long markdown lines to satisfy MD013 (400 char limit)
marrobi 41f92fc
Derive workspace airlock_version from template; make legacy defaults …
marrobi 252486a
Airlock robustness + e2e SAS log fixes from PR review
marrobi File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -214,3 +214,4 @@ validation.txt | |
|
|
||
| /index.html | ||
| .DS_Store | ||
| *_old.tf | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1 +1 @@ | ||
| __version__ = "0.8.12" | ||
| __version__ = "0.8.13" |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.