Skip to content

Route PowerShell through Calamari (opt-in via env flag)

Placeholder ppxd requested to merge feat/tentacle-calamari-powershell-optin into main

Summary

Connects PR-4's capability (Calamari can run PowerShell) to the Tentacle routing decision. Default OFF — zero behaviour change. Operators with custom PowerShell package deploys opt in to gain the rewriter + convention pipeline for PS scripts.

Two co-dependent changes (both required)

The prior IsCalamariCompatible docstring + drift test warned that flipping PowerShell routing needs BOTH halves:

  1. Gate — IsCalamariCompatible(PowerShell) returns true only when SQUID_TENTACLE_CALAMARI_POWERSHELL is truthy (1/true/yes/on). Bash always qualifies. Default (unset) = PowerShell on the direct launcher, exactly as before.
  2. Per-syntax --script path — BuildCalamariProcessStartInfo now emits --script=script.ps1 for PowerShell (was hardcoded script.sh). This was the co-dependent crash cause: Tentacle wrote script.ps1, Calamari read script.sh → FileNotFoundException.

Why opt-in (not default-on)

Server-side PS-emitting paths (IIS deploy, Windows upgrade) already inline variables via $SquidParameters and don't need Calamari's bootstrap; routing them through the extra Calamari child changes the process-tree / cancellation / output-capture path. The env gate keeps the default conservative + makes it reversible. Operators who want rewriters on their custom PS deploys flip the flag explicitly.

Test plan

  • Tentacle.Tests: 1467/1467
  • Build: 0 errors
  • Default-env truth table — PowerShell stays FALSE (back-compat pin)
  • Truthy theory (5 cases) → PowerShell routes through Calamari
  • Falsy theory (6 cases) → stays off; bash never affected
  • CalamariPowerShellEnvVar constant pinned (Rule 8)
  • --script=script.ps1 for PowerShell, script.sh for bash
  • Staging: opt-in agent runs a custom .ps1 package deploy through Calamari with SubstituteInFiles applied

Non-breaking guarantee

Surface Status
Default agent (flag unset) Identical — PowerShell on direct launcher, bash on Calamari
Existing bash Calamari routing --script=script.sh unchanged
IIS / upgrade PS paths Unchanged unless operator sets the flag (then they route through Calamari, gaining nothing but losing nothing — variables already inlined)
BuildCalamariProcessStartInfo signature Internal — only LocalScriptService + its tests; all call sites updated
SquidWeb Untouched

Merge request reports

Loading