Add PR-gated Windows tentacle lifecycle smoke E2E
Summary
- The comprehensive Windows suite (
tentacle-windows-e2e.yml, ~210 tests incl. the 66-test IIS surface) runs nightly + on merge to main, not on PRs —windows-latestis 2x-billed and the full suite would exhaust the Team-plan minute budget. Gap: a PowerShell upgrade-script orsc.exeservice-host regression could merge green (unit + Linux-container gates pass) and only surface post-merge. - Add a fast, paths-filtered PR gate (
tentacle-windows-smoke-e2e.yml) covering the agent's service + upgrade lifecycle on a real Windows host:sc.exeservice install/start/stop/uninstall → blue-green versioned upgrade (download + SHA256 verify + extract + swap + health-check + rollback + GC +last-upgrade.json) → Task Scheduler detach. -
54 tests across 5 deterministic,
🟢 high-fidelity categories. ExcludesIISDeployE2E(kept nightly) so the job skips the slow IIS feature + XDT install; runs in ~4 min. Concurrency-cancels superseded runs; 30-min ceiling. Mirrors how the Linux upgrade path is PR-gated bye2e-upgrade-matrix.yml. - Strictly additive: one new workflow file; no edits to existing workflows, code, or tests.
Gated categories: WindowsServiceHostE2E, TentacleUpgradeLifecycleE2E, WindowsUpgradeShaVerifyE2E, WindowsUpgradeWrapperE2E, WindowsUpgradeServiceE2E (carries the Phase B drift detector).
Bugs this gate surfaced (tracked separately)
On its first run the gate exposed that the full Windows suite has been red on every push to main (invisible because it wasn't PR-gated). Two pre-existing test-quality issues in the TentacleInstallScriptE2E category — a fragile global-function cmdlet mock in the UAC tests, and a shared-%ProgramData% parallel race in the install-info test. That category is therefore out of scope here and re-added to this gate once those tests are deterministic. The 5 gated categories pass deterministically.
Test plan
-
YAML validates; 1 job, pull_request(5 path filters) +workflow_dispatch; both filters resolve to 54 tests locally -
Project builds clean on a non-Windows host (tests skip-guard at runtime) -
Gate runs on this PR (touches the workflow, in its own paths filter) on windows-latestand goes 54/54 green -
After merge: add the check as a required status check in branch protection to make it blocking (repo-settings step)