Skip to content

Block sensitive variable imports and harden confirmation lifecycle

Summary

  • Block confirmation for selected sensitive variables because source secret values cannot be imported in this release. OctopusImportPreviewValidator reconstructs required inputs from the server-side graph, preventing clients from bypassing the blocker by modifying the preview payload.
  • Harden confirmation lifecycle handling with atomic admission, rollback and failure persistence independent of request cancellation, exception handling after entering Importing, and recovery of stale Importing sessions.
  • Retain the earlier P0 safeguards for log redaction, permission enforcement, stale-plan validation, unsupported Machine/Team resources, project rename conflicts, multiple channels, and idempotent concurrent confirmation.
  • Add PostgreSQL integration coverage for archive planning, transactional rollback, confirmation races, session ownership/expiry, stale-session recovery, and archive-to-release-to-deployment execution. No public API schema changes are introduced.

Test plan

  • dotnet build tests/Squid.UnitTests/Squid.UnitTests.csproj --configuration Release --no-restore --maxcpucount:1 — succeeded with 0 errors.
  • dotnet build tests/Squid.IntegrationTests/Squid.IntegrationTests.csproj --configuration Release --no-restore --maxcpucount:1 — succeeded with 0 errors.
  • git diff --check — passed.

Merge request reports

Loading