Skip to content

Azure client: full version (parked, not for merge) - #88

Draft
DrisDary wants to merge 12 commits into
mainfrom
feat/azure-client-full
Draft

DrisDary wants to merge 12 commits into
mainfrom
feat/azure-client-full

Conversation

@DrisDary

@DrisDary DrisDary commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Parked copy of #86 before the round-1 cut (head 6669013). Everything removed from #86 lives here and comes back in smaller PRs. Not for merge.

Adds localstack-azure-client, a tool that runs the Azure CLI against the
LocalStack for Azure emulator (never real Azure), and extends
localstack-management to start, stop, restart and report the Azure
emulator.

- The tool runs the host's az (2.85 or newer) in an isolated CLI profile
  that is logged in to the emulator only. A policy refuses shell syntax,
  logins, profile changes, extension installs and commands that open a
  browser, shell or tunnel, and keeps file arguments inside the working
  directory and out of the user's credential folders. An egress guard
  rewrites absolute management.azure.com URLs and blocks every other
  host. Failures come back classified, with a hint. An experimental warm
  worker (LOCALSTACK_AZ_RUNNER=worker) keeps az imports loaded.
- localstack-management: the Azure stack's container spec and port
  checks. A restart carries an externally started container's own
  settings, and refuses a container this machine cannot recreate.
- Setup follows the Snowflake tool: the user installs the Azure CLI, and
  a missing az answers with the install commands. A new command,
  install-azure-addons, installs the pinned Azure CLI extensions and
  Bicep the tool uses. The init wizard is unchanged. The setup and the
  LOCALSTACK_AZ_* settings are documented in README.md and
  docs/DOCKER.md.
- The Docker image bundles az 2.90, the 26 pinned extensions and Bicep,
  with image assertions and a size gate.
- Tests: unit tests with an Azure coverage gate (90 % of lines), a live
  command matrix, the official Azure samples replayed through the tool,
  and model evals. New CI workflows: azure-live.yml and azure-weekly.yml.
- CODEOWNERS requests @localstack/smurf and @HarshCasper on the
  Azure-only paths. .gitattributes keeps shell scripts LF and .cmd
  files CRLF on every checkout.
Comments, docs and fixtures state facts without citing internal plans, reviews, checks, test runs or benchmarks. build-corpus.py now builds the samples corpus from the in-repo extract.py and bash_argv.py output (the same 736 cases), and scripts/extract-leak-commands.mjs is removed: its input was never in the repository. tests/azure/README.md defines the test layers the CI jobs name.
The README's Azure section keeps its notes on using the emulator with the other tools. The E2 evals describe their builders, variants and seven answer-reading pitfalls on their own terms, and recorded fixtures use neutral resource names.
…he token

Removes the weekly E2 job, the only one that needed an Anthropic API key. The emulator start stops as soon as the container exits and prints the licence reason. The ~/.azure fingerprint is taken before the emulator starts, the live path filter covers core, cli and the Azure fixtures, the weekly token is set per step, and the matrix YAML is pinned to LF.
File paths are checked as the OS opens them, analytics drop values stuck to short options, and the egress guard allows only the emulator's ports. The AWS client runs in the Snowflake container, stop and restart handle the Azure emulator beside an AWS one, and the MCP env block wins on restart. A venv Python in LOCALSTACK_AZ_PATH is run by its own path, and a Windows az behind any WSL mount is refused. Also fixes the warm worker's log level and cancel, LOCALSTACK_HOSTNAME and port hints, the tool description, server.json and fixture redaction, and removes internal references.
…cret

The Azure jobs and steps take their token from LOCALSTACK_AUTH_TOKEN_AZURE, else LOCALSTACK_AUTH_TOKEN. The smoke test runs its AWS and Snowflake stages with LOCALSTACK_AUTH_TOKEN and the Azure stage on its own with the Azure token. Also repairs four comments that an earlier cleanup left with stray punctuation.
… work

The Azure emulator shares files with the containers it starts for Function and Web Apps from /var/lib/localstack, and refuses to unless that folder is a bind mount. The CI start script and the internal-network job now bind-mount a runner folder there. Starting the Azure emulator on a named volume, as when this server runs in Docker, now says that app deployments need LOCALSTACK_VOLUME_DIR, and the Docker docs and README say so too.
One token whose licence covers AWS, Snowflake and Azure, with no fallback, so a gap in its licence fails the run instead of hiding behind LOCALSTACK_AUTH_TOKEN.
Its licence covers AWS, Snowflake and Azure, so the separate LOCALSTACK_AUTH_TOKEN_AZURE secret is gone.
audit-ci --high now fails on this advisory, published on 30 Sep. It covers 1.14.0 to 1.14.4, which dockerode pulled in. Lockfile only.
localstack-docs calls an external search service. When that service times out, refuses, or returns a 5xx, the direct test is skipped and the image harness warns, each with the tool's answer. A 4xx or any other wrong answer still fails.
command_path took every leading word-shaped token, so a positional value (az find <term>) or an unknown command could reach analytics. It now keeps a word only if az's command table has it. scripts/gen-az-file-args.py --command-words generates the list (az 2.90.0 with the 26 curated extensions: 7,048 commands, 1,592 words), and DR4 checks it on every pin move. The property test now also tries secrets passed as positional values.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant