Skip to content

Add Deploy to IIS step (Phase 1: WebSite foundation)

Placeholder ppxd requested to merge feat/iis-deploy-step-foundation into main

Summary

  • Introduces the Squid.DeployToIISWebSite action type for Windows Tentacle (Polling + Listening) targets
  • Mirrors Octopus Calamari's IIS deploy step verbatim — every line of deployment logic in the embedded DeployToIISWebSite.ps1 is byte-identical to Octopus's Octopus.Features.IISWebSite_BeforePostDeploy.ps1 after one mechanical substitution (Octopus. → Squid., $OctopusParameters → $SquidParameters)
  • Diverges only at the dispatch seam: Squid pre-renders the $SquidParameters hashtable on the server (Path A in the implementation plan) instead of relying on a Calamari runtime bootstrapper that Squid.Tentacle doesn't yet emit for PowerShell — so this PR ships without requiring a Tentacle binary upgrade

What ships

Component Lines Purpose
SpecialVariables.ActionTypes.DeployToIISWebSite +2 New action-type constant + entry in the All set
IISDeployProperties 100 30+ Squid.Action.IISWebSite.* constants matching Octopus's taxonomy 1:1
IISDeployScriptBuilder 150 Server-side preamble generation with PowerShell single-quote escape (doubling apostrophes, collapsing newlines)
IISDeployActionHandler 75 Auto-registered via IScopedDependency; emits RunScriptIntent with Syntax = PowerShell; OS guard rejects known non-Windows targets with an actionable error
DeployToIISWebSite.ps1 (embedded) 850 Verbatim port of Octopus's IIS deploy script — mutex, retry loop, app-pool setup, SNI handling, netsh http add sslcert, appcmd.exe auth toggles, PS-7.3 compat-session wrapper
TentaclePollingTransport / TentacleListeningTransport +1 each Declare DeployToIISWebSite in SupportedActionTypes

Test plan — three tiers, all green locally

  • Unit (33 new tests, full suite 5162 / 5162 green)
    • IISDeployScriptBuilderTests — preamble generation, hashtable coverage of every recognised property, single-quote escape rules, newline collapse for multi-line JSON, adversarial-input containment (apostrophe in O'Brien username; PowerShell-injection attempt in WebSiteName)
    • IISDeployActionHandlerTests — intent emission, syntax / step-name / action-name propagation, OS-guard Theory matrix (Linux / Darwin / FreeBSD rejected with actionable messages; Windows accepted; cache-miss / empty-string proceed optimistically)
    • IISDeployScriptDriftDetectorTests (Rule 12.5 mirror-tier guard) — structural invariants for every critical operation; soft comparison against the upstream Octopus reference path when checked out locally; namespace-leak check on executable lines
  • E2E pipeline-tier (IISDeployPipelineE2ETests) — full Squid pipeline via DeploymentPipelineFixture + CapturingExecutionStrategy, Theory across TentaclePolling + TentacleListening. Asserts script-body shape (PowerShell syntax, preamble assignments, embedded body contents, multi-line bindings JSON collapsed onto one line)
  • E2E execution-tier (real Windows IIS host) — deferred to a follow-up PR; requires a Windows runner with IIS-WebServerRole enabled

Out of scope (future phases per the implementation plan)

  • Phase 2: HTTPS bindings + cert variable resolution — the embedded PS1 already has all the code paths (netsh http add sslcert, SNI flag handling), only test coverage will be added
  • Phase 3: Authentication toggles (Anonymous / Basic / Windows) — same: PS1 code present, dedicated tests deferred
  • Phase 4: Web Application + Virtual Directory deployment types — the CreateOrUpdate toggles for each are in IISDeployProperties and the PS1 branches exist (dormant when toggle defaults to false), tests deferred
  • Phase 5: Real-Windows execution-tier E2E — needs windows-latest GitHub runner with IIS feature enabled

Breaking-change risk

None. The change is purely additive — new action type, new constants, new handler, embedded resource. The two existing transport files gain one entry in SupportedActionTypes, which is a list addition (no removals / renames). No public-API signature changes. No DB migration. No env-var-driven behaviour change.

🤖 Generated with Claude Code

Merge request reports

Loading