Skip to content

Add Windows Azure VM integration test job - #2296

Merged
movence merged 5 commits into
mainfrom
hsookim/azure-vm-windows-integ-test
Sep 22, 2026
Merged

movence merged 5 commits into
mainfrom
hsookim/azure-vm-windows-integ-test

Conversation

@movence

@movence movence commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Description of the issue

The Azure VM integration coverage is Linux-only, so Windows-specific regressions in the MSI or Windows Azure -m auto detection (fixed in #2289) have no CI job exercising them. Companion to aws/amazon-cloudwatch-agent-test#764.

Description of changes

  • Add an AzureVMWindowsIntegrationTest job (AzureVM-default-otel-Windows) to test-artifacts.yml, cloned from the Linux Azure VM job (same if: gate, secrets/vars, WIP convention, destroy-always cleanup).
  • The job verifies the MSI exists at integration-test/packaging/${build_id}/ (same artifact source as the EC2 Windows test), presigns it (1h, masked) and passes the URL to terraform as agent_msi_url; the VM downloads it directly.
  • Destroy runs with -lock=false so a killed apply cannot leave the state locked and leak resources.
  • Rename the Linux job to AzureVM-default-otel-Linux and point both jobs at the restructured terraform/azure/vm/{linux,win} paths from Remove Linux test as dependency of macOS test #764.

Testing

Worth noting

License

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.


Integration Tests

To run integration tests against this PR, add the ready for testing label.

Add an additive AzureVMWindowsIntegrationTest job to
test-artifacts.yml, cloned from the existing Linux Azure VM job. It
consumes the agent MSI from integration-test/packaging/${build_id}/ and
reuses the same secrets, vars, [WIP] naming convention, and
destroy-always cleanup as the Linux job.

Companion test lives in aws/amazon-cloudwatch-agent-test
(branch hsookim/azure-vm-windows-integ-test); depends on that PR.
@movence
movence requested a review from a team as a code owner September 18, 2026 19:52
@movence movence added the ready for testing Indicates this PR is ready for integration tests to run label Sep 18, 2026
Point the two Azure VM jobs at the restructured directories:
terraform/azure/vm -> terraform/azure/vm/linux and
terraform/azure/vm-windows -> terraform/azure/vm/win.

aws/amazon-cloudwatch-agent-test#764
The Windows Azure VM can no longer receive the MSI over the slow
WinRM file provisioner (~41 min, run 35537032697). Presign the MSI
S3 object and pass the URL to Terraform so the VM downloads it
directly; the presign resolves the bucket region since SigV4
presigned URLs are region-specific, and masks the URL in the logs.

Also add -lock=false to the destroy so a stale local state lock left
by a timed-out apply no longer blocks cleanup.
Use a common AzureVM-default-otel prefix with a Linux/Windows suffix so
the two jobs sort together and the OS is explicit in both names.
@movence
movence merged commit e6ab83d into main Sep 22, 2026
473 of 503 checks passed
@movence
movence deleted the hsookim/azure-vm-windows-integ-test branch September 22, 2026 17:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready for testing Indicates this PR is ready for integration tests to run

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants