Skip to content

Pipeline Execution Evidence

Croesus Evidence Bot edited this page Jun 29, 2026 · 1 revision

Pipeline execution evidence

The deploy workflow at .github/workflows/deploy-croesus.yml builds the SPA and API, deploys both to Azure App Service over an OpenID Connect federated credential (no stored deploy secret), and runs a post-deploy evidence job.

Latest successful run

Field Value
Run 28406696203
Trigger push to main
Commit b4df14a
Result success

Job results

Job Result
Build SPA success
Build API success
Deploy SPA + API success
Post-deploy OBO evidence success

Evidence job step breakdown

The evidence job stays green in this MFA-enforcing tenant because the two ROPC-dependent steps are gated behind the ENABLE_ROPC_EVIDENCE repository variable (default off) and skip cleanly rather than fail.

Step Result
Azure login (OIDC, no stored secret) success
OBO evidence mode success
Smoke test (two-leg claim summary) skipped
Negative control (mismatched-audience rejection) skipped
Correlate sign-in legs via Log Analytics success
Portal deep links success
Upload claim summary artifact success

The MFA constraint and how it is handled

The headless smoke and negative tests acquire a user token through the resource-owner-password (ROPC) grant. This tenant enforces multi-factor authentication for every user through a Microsoft-managed Conditional Access policy, so ROPC fails with AADSTS50079 and no headless token can be obtained.

Rather than let an unsatisfiable login fail the pipeline, the workflow gates those two steps behind the ENABLE_ROPC_EVIDENCE repository variable:

  • When ENABLE_ROPC_EVIDENCE is not true (the default), the smoke and negative steps are skipped and the run stays green. Set it to true only in a tenant that permits a dedicated, non-MFA CI test user.
  • The remaining evidence steps (Log Analytics correlation, portal deep links, artifact upload) always run.

To validate the full OBO claim evidence, sign in interactively at the SPA, which completes MFA in the browser. See Live application evidence and docs/obo-demo-guide.md.

Clone this wiki locally