Skip to content

Harden 1.6.9 IIS deploy: cert chain split, identity-type ACL, journal failure trap

Placeholder ppxd requested to merge feat/iis-deploy-1.6.9-hardening into main

Summary

Closes the four operator-visible Octopus-alignment gaps surfaced by the post-1.6.9 audit:

  • Cert chain import: PFX import now splits the chain across LocalMachine\My (leaf), LocalMachine\CA (intermediates), and LocalMachine\Root (trailing self-signed). Mirrors Octopus's WindowsX509CertificateStore.cs:265-282.
  • AppPool private-key ACL switches on ApplicationPoolIdentityType: maps all 5 Octopus identity types to the correct NT principal (IIS AppPool\<Pool>, NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\SYSTEM, NT AUTHORITY\NETWORK SERVICE, DOMAIN\user). Hardcoded IIS APPPOOL\<Pool> silently broke HTTPS for non-default pool identities.
  • Journal failure tracking via PowerShell trap: top-level trap records Status='Failed' before re-throwing, so SkipIfAlreadyInstalled=True re-runs see the failed attempt instead of a stale success entry.
  • Composite real-world test enhanced to exercise the 1.6.9 surface in one deploy — #{X | Filter}, JSON type preservation (int/bool/array), AdditionalPaths, packaged PreDeploy/PostDeploy, journal idempotence (second run short-circuits, witness file survives).

Test plan

  • Unit: 5212/5212 pass locally, 19 IIS drift-detector tests including 3 new ones pinning chain-split / identity-type / journal-trap invariants
  • Build: zero errors across all projects
  • Windows CI: composite real-world test runs the 11-feature deploy on a real IIS instance + asserts journal idempotence on the second run

🤖 Generated with Claude Code

Merge request reports

Loading