Add Deploy to IIS step (Phase 1: WebSite foundation)
Summary
- Introduces the
Squid.DeployToIISWebSiteaction type for Windows Tentacle (Polling + Listening) targets - Mirrors Octopus Calamari's IIS deploy step verbatim — every line of deployment logic in the embedded
DeployToIISWebSite.ps1is byte-identical to Octopus'sOctopus.Features.IISWebSite_BeforePostDeploy.ps1after one mechanical substitution (Octopus.→Squid.,$OctopusParameters→$SquidParameters) - Diverges only at the dispatch seam: Squid pre-renders the
$SquidParametershashtable on the server (Path A in the implementation plan) instead of relying on a Calamari runtime bootstrapper thatSquid.Tentacledoesn't yet emit for PowerShell — so this PR ships without requiring a Tentacle binary upgrade
What ships
| Component | Lines | Purpose |
|---|---|---|
SpecialVariables.ActionTypes.DeployToIISWebSite |
+2 | New action-type constant + entry in the All set |
IISDeployProperties |
100 | 30+ Squid.Action.IISWebSite.* constants matching Octopus's taxonomy 1:1 |
IISDeployScriptBuilder |
150 | Server-side preamble generation with PowerShell single-quote escape (doubling apostrophes, collapsing newlines) |
IISDeployActionHandler |
75 | Auto-registered via IScopedDependency; emits RunScriptIntent with Syntax = PowerShell; OS guard rejects known non-Windows targets with an actionable error |
DeployToIISWebSite.ps1 (embedded) |
850 | Verbatim port of Octopus's IIS deploy script — mutex, retry loop, app-pool setup, SNI handling, netsh http add sslcert, appcmd.exe auth toggles, PS-7.3 compat-session wrapper |
TentaclePollingTransport / TentacleListeningTransport
|
+1 each | Declare DeployToIISWebSite in SupportedActionTypes
|
Test plan — three tiers, all green locally
-
Unit (33 new tests, full suite 5162 / 5162 green) -
IISDeployScriptBuilderTests— preamble generation, hashtable coverage of every recognised property, single-quote escape rules, newline collapse for multi-line JSON, adversarial-input containment (apostrophe inO'Brienusername; PowerShell-injection attempt in WebSiteName) -
IISDeployActionHandlerTests— intent emission, syntax / step-name / action-name propagation, OS-guard Theory matrix (Linux / Darwin / FreeBSD rejected with actionable messages; Windows accepted; cache-miss / empty-string proceed optimistically) -
IISDeployScriptDriftDetectorTests(Rule 12.5 mirror-tier guard) — structural invariants for every critical operation; soft comparison against the upstream Octopus reference path when checked out locally; namespace-leak check on executable lines
-
-
E2E pipeline-tier ( IISDeployPipelineE2ETests) — full Squid pipeline viaDeploymentPipelineFixture+CapturingExecutionStrategy, Theory acrossTentaclePolling+TentacleListening. Asserts script-body shape (PowerShell syntax, preamble assignments, embedded body contents, multi-line bindings JSON collapsed onto one line) -
E2E execution-tier (real Windows IIS host) — deferred to a follow-up PR; requires a Windows runner with IIS-WebServerRoleenabled
Out of scope (future phases per the implementation plan)
- Phase 2: HTTPS bindings + cert variable resolution — the embedded PS1 already has all the code paths (
netsh http add sslcert, SNI flag handling), only test coverage will be added - Phase 3: Authentication toggles (Anonymous / Basic / Windows) — same: PS1 code present, dedicated tests deferred
- Phase 4: Web Application + Virtual Directory deployment types — the
CreateOrUpdatetoggles for each are inIISDeployPropertiesand the PS1 branches exist (dormant when toggle defaults to false), tests deferred - Phase 5: Real-Windows execution-tier E2E — needs
windows-latestGitHub runner with IIS feature enabled
Breaking-change risk
None. The change is purely additive — new action type, new constants, new handler, embedded resource. The two existing transport files gain one entry in SupportedActionTypes, which is a list addition (no removals / renames). No public-API signature changes. No DB migration. No env-var-driven behaviour change.