Skip to content

sre-lab: start from a fork in Codespaces with one shared environment - #50

Merged
hellices merged 2 commits into
mainfrom
feat/sre-lab-codespaces
Aug 15, 2026
Merged

hellices merged 2 commits into
mainfrom
feat/sre-lab-codespaces

Conversation

@hellices

Copy link
Copy Markdown
Owner

Why

Three gaps in the guided lab:

  • every manual step rebound the same azd values by hand (21 places)
  • the guides named this repository as the Agent's connected repo, so every participant's incident issues would land here
  • there was no Codespaces path, so az login and tooling were the operator's problem

What changed

  • .devcontainer/sre-agent-event-lab/devcontainer.json: Codespaces configuration with az, azd, gh, Python and uv; postCreateCommand builds app/.venv. No login, no credentials, non-root user.
  • scripts/lab-env.sh: sourced once after az login, exports every value the walkthrough uses, and reports LAB_READY=0 with the reason when anything is missing.
  • guides and README: fork-first flow; the scenario setup blocks collapse to source ./scripts/lab-env.sh.

Safety

  • refuses a git remote that carries credentials rather than rewriting it, so a proxy clone URL cannot leak a token to the terminal, the environment, or azd env set
  • stops the lab when the active Azure CLI subscription is not the lab's, and pins --subscription on every mutating command in the guides
  • fails closed outside bash and outside the lab directory; sourcing never kills the shell
  • S3 rechecks the RBAC values immediately before the delete

Verification

  • pytest scripts infra -q — 611 passed; pytest app -q — 10 passed
  • 31 guide bash blocks: bash -n clean, no set -e/exit/trap
  • simulated failing azd, wrong subscription, credentialed remote, zsh, and direct execution
  • independent security review: no vulnerabilities found

…nment

Add a Codespaces configuration and a sourced lab-env.sh so an operator logs in once and every later command reads exported values instead of rebinding each one. Point the Agent at the operator's own fork, since the connector files issues into whatever repository it is connected to. The environment refuses to publish a git remote that carries credentials, and stops the lab when the active CLI subscription is not the lab's.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the SRE Agent event lab to support a fork-first workflow and a smoother Codespaces experience by centralizing all repeatedly-used lab values into a single sourced environment script and aligning the guides/tests around it.

Changes:

  • Add a Codespaces devcontainer configuration for the lab (Azure CLI, azd, gh, Python+uv) and provision a local venv on create.
  • Introduce scripts/lab-env.sh to resolve/export azd deployment outputs once (and fail closed with LAB_READY=0), then update scenario guides/README to consume those exported values.
  • Add/extend contract tests to enforce the fork-first connected-repo guidance and to validate the devcontainer + lab-env.sh behavior.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
monitor/sre-agent-event-lab/scripts/tests/test_lab_guides.py Tightens guide contract checks (including fork-first connected repo) and updates S3 command expectations.
monitor/sre-agent-event-lab/scripts/tests/test_lab_env.py Adds new contract tests for the devcontainer, lab-env.sh, and guide changes.
monitor/sre-agent-event-lab/scripts/lab-env.sh New one-shot sourced environment script that exports all required lab outputs and readiness state.
monitor/sre-agent-event-lab/README.md Documents fork + Codespaces startup and replaces repeated manual bindings with a single source.
monitor/sre-agent-event-lab/guides/01-agent-setup.md Updates setup flow to emphasize fork-first and to use sourced env values for connected repo guidance.
monitor/sre-agent-event-lab/guides/02-scenario-s1.md Switches manual setup to source ./scripts/lab-env.sh and pins mutating commands with --subscription.
monitor/sre-agent-event-lab/guides/03-scenario-s2.md Same as S1: consume sourced env + pin mutating commands with --subscription.
monitor/sre-agent-event-lab/guides/04-scenario-s3.md Uses sourced env and pins RBAC delete/create operations with --subscription, plus stronger readiness gating.
.devcontainer/sre-agent-event-lab/devcontainer.json Adds a Codespaces devcontainer configuration for the lab and runs setup-venv.sh on create.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread monitor/sre-agent-event-lab/guides/01-agent-setup.md Outdated
Comment thread .devcontainer/sre-agent-event-lab/devcontainer.json
lab-env.sh leaves SRE_REPOSITORY_URL empty when the git remote carries credentials or git is unavailable. Gate the azd env set on a non-empty value so the environment is never configured with an empty repository.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

Suppressed comments (1)

monitor/sre-agent-event-lab/scripts/tests/test_lab_env.py:296

  • The test uses a GitHub PAT-like prefix ("ghp_…") for the embedded-token example. Even though it’s fake, this pattern commonly triggers GitHub secret scanning and can create noisy security alerts/automated revocations. The test doesn’t need a real PAT format—any unique marker string works for verifying that credentialed remotes are refused and not echoed back.
def test_a_remote_with_an_embedded_token_is_refused(tmp_path):
    """Cloning with `https://user:<PAT>@github.com/...` is routine behind a
    corporate proxy. Publishing that remote would put the token in the
    terminal, in scrollback, and in every child process."""
    token = "ghp_000000000000000000000000000000000000"

@hellices
hellices merged commit 253995c into main Aug 15, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants