-
Notifications
You must be signed in to change notification settings - Fork 0
Pipeline Execution Evidence
The deploy workflow at .github/workflows/deploy-croesus.yml builds the SPA and API, deploys both to Azure App Service over an OpenID Connect federated credential (no stored deploy secret), and runs a post-deploy evidence job.
| Field | Value |
|---|---|
| Run | 28406696203 |
| Trigger |
push to main
|
| Commit | b4df14a |
| Result | success |
| Job | Result |
|---|---|
| Build SPA | success |
| Build API | success |
| Deploy SPA + API | success |
| Post-deploy OBO evidence | success |
The evidence job stays green in this MFA-enforcing tenant because the two ROPC-dependent steps are gated behind the ENABLE_ROPC_EVIDENCE repository variable (default off) and skip cleanly rather than fail.
| Step | Result |
|---|---|
| Azure login (OIDC, no stored secret) | success |
| OBO evidence mode | success |
| Smoke test (two-leg claim summary) | skipped |
| Negative control (mismatched-audience rejection) | skipped |
| Correlate sign-in legs via Log Analytics | success |
| Portal deep links | success |
| Upload claim summary artifact | success |
The headless smoke and negative tests acquire a user token through the resource-owner-password (ROPC) grant. This tenant enforces multi-factor authentication for every user through a Microsoft-managed Conditional Access policy, so ROPC fails with AADSTS50079 and no headless token can be obtained.
Rather than let an unsatisfiable login fail the pipeline, the workflow gates those two steps behind the ENABLE_ROPC_EVIDENCE repository variable:
- When
ENABLE_ROPC_EVIDENCEis nottrue(the default), the smoke and negative steps are skipped and the run stays green. Set it totrueonly in a tenant that permits a dedicated, non-MFA CI test user. - The remaining evidence steps (Log Analytics correlation, portal deep links, artifact upload) always run.
To validate the full OBO claim evidence, sign in interactively at the SPA, which completes MFA in the browser. See Live application evidence and docs/obo-demo-guide.md.