Repository navigation
sre-lab: start from a fork in Codespaces with one shared environment - #50
Merged
Merged
Conversation
…nment Add a Codespaces configuration and a sourced lab-env.sh so an operator logs in once and every later command reads exported values instead of rebinding each one. Point the Agent at the operator's own fork, since the connector files issues into whatever repository it is connected to. The environment refuses to publish a git remote that carries credentials, and stops the lab when the active CLI subscription is not the lab's. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Pull request overview
This PR updates the SRE Agent event lab to support a fork-first workflow and a smoother Codespaces experience by centralizing all repeatedly-used lab values into a single sourced environment script and aligning the guides/tests around it.
Changes:
- Add a Codespaces devcontainer configuration for the lab (Azure CLI, azd, gh, Python+uv) and provision a local venv on create.
- Introduce
scripts/lab-env.shto resolve/export azd deployment outputs once (and fail closed withLAB_READY=0), then update scenario guides/README to consume those exported values. - Add/extend contract tests to enforce the fork-first connected-repo guidance and to validate the devcontainer +
lab-env.shbehavior.
Reviewed changes
Copilot reviewed 9 out of 9 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
monitor/sre-agent-event-lab/scripts/tests/test_lab_guides.py |
Tightens guide contract checks (including fork-first connected repo) and updates S3 command expectations. |
monitor/sre-agent-event-lab/scripts/tests/test_lab_env.py |
Adds new contract tests for the devcontainer, lab-env.sh, and guide changes. |
monitor/sre-agent-event-lab/scripts/lab-env.sh |
New one-shot sourced environment script that exports all required lab outputs and readiness state. |
monitor/sre-agent-event-lab/README.md |
Documents fork + Codespaces startup and replaces repeated manual bindings with a single source. |
monitor/sre-agent-event-lab/guides/01-agent-setup.md |
Updates setup flow to emphasize fork-first and to use sourced env values for connected repo guidance. |
monitor/sre-agent-event-lab/guides/02-scenario-s1.md |
Switches manual setup to source ./scripts/lab-env.sh and pins mutating commands with --subscription. |
monitor/sre-agent-event-lab/guides/03-scenario-s2.md |
Same as S1: consume sourced env + pin mutating commands with --subscription. |
monitor/sre-agent-event-lab/guides/04-scenario-s3.md |
Uses sourced env and pins RBAC delete/create operations with --subscription, plus stronger readiness gating. |
.devcontainer/sre-agent-event-lab/devcontainer.json |
Adds a Codespaces devcontainer configuration for the lab and runs setup-venv.sh on create. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
lab-env.sh leaves SRE_REPOSITORY_URL empty when the git remote carries credentials or git is unavailable. Gate the azd env set on a non-empty value so the environment is never configured with an empty repository. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.
Suppressed comments (1)
monitor/sre-agent-event-lab/scripts/tests/test_lab_env.py:296
- The test uses a GitHub PAT-like prefix ("ghp_…") for the embedded-token example. Even though it’s fake, this pattern commonly triggers GitHub secret scanning and can create noisy security alerts/automated revocations. The test doesn’t need a real PAT format—any unique marker string works for verifying that credentialed remotes are refused and not echoed back.
def test_a_remote_with_an_embedded_token_is_refused(tmp_path):
"""Cloning with `https://user:<PAT>@github.com/...` is routine behind a
corporate proxy. Publishing that remote would put the token in the
terminal, in scrollback, and in every child process."""
token = "ghp_000000000000000000000000000000000000"
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Three gaps in the guided lab:
az loginand tooling were the operator's problemWhat changed
.devcontainer/sre-agent-event-lab/devcontainer.json: Codespaces configuration withaz,azd,gh, Python anduv;postCreateCommandbuildsapp/.venv. No login, no credentials, non-root user.scripts/lab-env.sh: sourced once afteraz login, exports every value the walkthrough uses, and reportsLAB_READY=0with the reason when anything is missing.source ./scripts/lab-env.sh.Safety
azd env set--subscriptionon every mutating command in the guidesVerification
pytest scripts infra -q— 611 passed;pytest app -q— 10 passedbash -nclean, noset -e/exit/trapazd, wrong subscription, credentialed remote, zsh, and direct execution