Skip to content

Add HTTPS bindings to IIS deploy step (Phase 2)

Placeholder ppxd requested to merge feat/iis-deploy-https-bindings into main

Summary

  • HTTPS binding paths in the embedded DeployToIISWebSite.ps1 were already byte-identical to Octopus's (netsh http add sslcert, SNI branch, cert-thumbprint lookup, rebind-replace logic). This PR adds test coverage at all three tiers + Squid-fies the operator-facing "Octopus" strings the namespace rename missed in Phase 1.
  • Cert-variable system (Octopus-style first-class cert variables fanning out to .Thumbprint / .PfxData / .Password) is NOT included — Squid doesn't have it yet. The PS1's certificateVariable branch is preserved unchanged for forward compat; a unit test pins the passthrough shape so the future system has nothing to re-plumb. Operators in Phase 2 use the direct thumbprint field on the binding, pointing at a cert already installed in LocalMachine\My on the target Tentacle.

What ships

Component Notes
DeployToIISWebSite.ps1 Squid-fication 6 operator-facing "Octopus" mentions (lines 345/348/403/406/502/510) → "Squid" or rewritten without the Octopus-specific feature reference. Mutex literal Global\Octopus-IIS-Metabase-Mutex KEPT — that's deliberate cross-vendor interop so a Squid Tentacle and an Octopus Tentacle on the same Windows host serialize their IIS metabase edits through one mutex
New drift-detector test EmbeddedScript_NoOctopusBrandInExecutableText_ExceptInteropMutexLiteral — belt-and-braces follow-up to the namespace-leak test; catches the broader category of operator-facing brand mentions in error messages and prose
Unit tests for HTTPS shape 4 new test methods + 1 Theory: thumbprint round-trip, requireSni flag preserved verbatim, certificateVariable passthrough (future-proof), mixed http+https multi-binding on single assignment line
Pipeline-tier E2E Variable-substitution test: Bindings JSON with #{CertThumbprint} reference must be resolved by the pipeline BEFORE the builder serialises. Theory across both Tentacle styles × plaintext/sensitive variable
Real-host E2E (🟢 high-fidelity) 4 new tests against real IIS on windows-latest: SNI binding via netsh hostnameport=, non-SNI via netsh ipport=, missing-cert error path, cert-rotation re-bind (delete-old + add-new)

Test plan

  • dotnet test --filter FullyQualifiedName~IISDeploy on macOS — 39 unit tests green
  • dotnet test --filter Category=IISDeployE2E on macOS — 9 real-host tests skip cleanly via OS guard
  • dotnet build clean across Squid.Core, Squid.UnitTests, Squid.E2ETests, Squid.WindowsTentacleE2ETests — 0 errors
  • CI run on windows-latest: confirm real-IIS HTTPS bindings land in netsh http show sslcert table + cert/netsh teardown via Dispose

Out of scope (future phases)

  • Phase 3: Authentication toggles (Anonymous / Basic / Windows) — PS1 appcmd.exe branches exist; needs dedicated E2E
  • Phase 4: WebApplication + VirtualDirectory deployment types — toggles + PS1 branches exist (dormant in Phase 1+2), tests deferred
  • Squid cert-variable system: when shipped, the certificateVariable branch lights up; the binding-JSON passthrough is already tested

Breaking-change risk

None. The PS1 changes are operator-facing string edits (better Squid branding, no functional change). Tests are additive. No public-API signatures changed. No DB migration. No env-var-driven behaviour change.

Merge request reports

Loading