Harden 1.6.9 IIS deploy: cert chain split, identity-type ACL, journal failure trap
Summary
Closes the four operator-visible Octopus-alignment gaps surfaced by the post-1.6.9 audit:
-
Cert chain import: PFX import now splits the chain across
LocalMachine\My(leaf),LocalMachine\CA(intermediates), andLocalMachine\Root(trailing self-signed). Mirrors Octopus'sWindowsX509CertificateStore.cs:265-282. -
AppPool private-key ACL switches on
ApplicationPoolIdentityType: maps all 5 Octopus identity types to the correct NT principal (IIS AppPool\<Pool>,NT AUTHORITY\LOCAL SERVICE,NT AUTHORITY\SYSTEM,NT AUTHORITY\NETWORK SERVICE,DOMAIN\user). HardcodedIIS APPPOOL\<Pool>silently broke HTTPS for non-default pool identities. -
Journal failure tracking via PowerShell
trap: top-leveltraprecordsStatus='Failed'before re-throwing, soSkipIfAlreadyInstalled=Truere-runs see the failed attempt instead of a stale success entry. -
Composite real-world test enhanced to exercise the 1.6.9 surface in one deploy —
#{X | Filter}, JSON type preservation (int/bool/array),AdditionalPaths, packaged PreDeploy/PostDeploy, journal idempotence (second run short-circuits, witness file survives).
Test plan
-
Unit: 5212/5212 pass locally, 19 IIS drift-detector tests including 3 new ones pinning chain-split / identity-type / journal-trap invariants -
Build: zero errors across all projects -
Windows CI: composite real-world test runs the 11-feature deploy on a real IIS instance + asserts journal idempotence on the second run