Add HTTPS bindings to IIS deploy step (Phase 2)
Summary
- HTTPS binding paths in the embedded
DeployToIISWebSite.ps1were already byte-identical to Octopus's (netsh http add sslcert, SNI branch, cert-thumbprint lookup, rebind-replace logic). This PR adds test coverage at all three tiers + Squid-fies the operator-facing "Octopus" strings the namespace rename missed in Phase 1. - Cert-variable system (Octopus-style first-class cert variables fanning out to
.Thumbprint/.PfxData/.Password) is NOT included — Squid doesn't have it yet. The PS1'scertificateVariablebranch is preserved unchanged for forward compat; a unit test pins the passthrough shape so the future system has nothing to re-plumb. Operators in Phase 2 use the directthumbprintfield on the binding, pointing at a cert already installed inLocalMachine\Myon the target Tentacle.
What ships
| Component | Notes |
|---|---|
DeployToIISWebSite.ps1 Squid-fication |
6 operator-facing "Octopus" mentions (lines 345/348/403/406/502/510) → "Squid" or rewritten without the Octopus-specific feature reference. Mutex literal Global\Octopus-IIS-Metabase-Mutex KEPT — that's deliberate cross-vendor interop so a Squid Tentacle and an Octopus Tentacle on the same Windows host serialize their IIS metabase edits through one mutex |
| New drift-detector test |
EmbeddedScript_NoOctopusBrandInExecutableText_ExceptInteropMutexLiteral — belt-and-braces follow-up to the namespace-leak test; catches the broader category of operator-facing brand mentions in error messages and prose |
| Unit tests for HTTPS shape | 4 new test methods + 1 Theory: thumbprint round-trip, requireSni flag preserved verbatim, certificateVariable passthrough (future-proof), mixed http+https multi-binding on single assignment line |
| Pipeline-tier E2E | Variable-substitution test: Bindings JSON with #{CertThumbprint} reference must be resolved by the pipeline BEFORE the builder serialises. Theory across both Tentacle styles × plaintext/sensitive variable |
| Real-host E2E ( |
4 new tests against real IIS on windows-latest: SNI binding via netsh hostnameport=, non-SNI via netsh ipport=, missing-cert error path, cert-rotation re-bind (delete-old + add-new) |
Test plan
-
dotnet test --filter FullyQualifiedName~IISDeployon macOS — 39 unit tests green -
dotnet test --filter Category=IISDeployE2Eon macOS — 9 real-host tests skip cleanly via OS guard -
dotnet buildclean acrossSquid.Core,Squid.UnitTests,Squid.E2ETests,Squid.WindowsTentacleE2ETests— 0 errors -
CI run on windows-latest: confirm real-IIS HTTPS bindings land innetsh http show sslcerttable + cert/netsh teardown via Dispose
Out of scope (future phases)
- Phase 3: Authentication toggles (Anonymous / Basic / Windows) — PS1
appcmd.exebranches exist; needs dedicated E2E - Phase 4: WebApplication + VirtualDirectory deployment types — toggles + PS1 branches exist (dormant in Phase 1+2), tests deferred
- Squid cert-variable system: when shipped, the
certificateVariablebranch lights up; the binding-JSON passthrough is already tested
Breaking-change risk
None. The PS1 changes are operator-facing string edits (better Squid branding, no functional change). Tests are additive. No public-API signatures changed. No DB migration. No env-var-driven behaviour change.