Skip to content

refactor foundry local packaging pipeline - #1090

Merged
Prathik Rao (prathikr) merged 8 commits into
mainfrom
prathikrao/refactor-foundry-local-packaging-pipeline
Sep 16, 2026
Merged

Prathik Rao (prathikr) merged 8 commits into
mainfrom
prathikrao/refactor-foundry-local-packaging-pipeline

Conversation

@prathikr

Copy link
Copy Markdown
Collaborator

Pipeline Cleanup and Feed Compliance

  • Reorganized .pipelines/ into the following structure: templates/, docker/, docs/, and the root foundry-local-packaging.yml entry point.
  • Moved sdk_v2 build, test, packaging, and stage templates into .pipelines/templates, then updated active template includes to their new locations.
  • Moved the manylinux Docker build asset to .pipelines/docker/manylinux/Dockerfile and updated Linux build steps to use the new path.
  • Moved SDK v2 pipeline reference documents into .pipelines/docs and corrected their internal links and layout references.
  • Removed the legacy checkout-steps.yml flow and all active dependencies on the test-data-shared Git/LFS checkout (now done via azure artifacts universal packages).
  • Routed NuGet, pip, npm, Cargo, and Universal Package model downloads through authenticated AIFoundryLocal_PublicPackages endpoints; no direct public language package registries remain in active pipeline configuration.
  • Added private-feed authentication/configuration to packaged Python, JavaScript, and Rust consumer validation paths so dependency resolution cannot silently fall back to public registries.
  • Validated static YAML template references, local documentation links, pipeline diagnostics, and diff whitespace checks after the reorganization.

Copilot AI balanced review requested due to automatic review settings September 9, 2026 18:44
@vercel

vercel Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
foundry-local Ready Ready Preview Sep 15, 2026 8:20pm UTC

Request Review

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Cargo source replacement, Python feed authentication, and undocumented v1 retirement currently prevent safe approval.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Refactors the packaging pipeline around SDK v2, centralizes authenticated package feeds, and removes legacy SDK v1 stages.

Changes:

  • Consolidates SDK v2 build, test, and packaging templates.
  • Routes package and model acquisition through Azure Artifacts.
  • Removes the legacy v1 packaging pipeline.
File summaries
File Description
sdk_v2/rust/build.rs Generalizes feed documentation.
sdk_v2/rust/build_support.rs Changes the default NuGet feed.
sdk_v2/js/script/install-native.cjs Changes the native package feed.
sdk_v2/cs/NuGet.config Restricts NuGet sources.
sdk_v2/cpp/CMakeLists.txt Updates feed documentation.
sdk_v2/cpp/cmake/FindWinMLEpCatalog.cmake Redirects WinML acquisition.
sdk_v2/cpp/cmake/FindOnnxRuntimeGenAI.cmake Redirects GenAI acquisition.
sdk_v2/cpp/cmake/FindOnnxRuntime.cmake Redirects ORT acquisition.
.pipelines/v1/templates/update-deps-versions-steps.yml Removes v1 dependency updating.
.pipelines/v1/templates/test-rust-steps.yml Removes v1 Rust testing.
.pipelines/v1/templates/test-python-steps.yml Removes v1 Python testing.
.pipelines/v1/templates/test-js-steps.yml Removes v1 JavaScript testing.
.pipelines/v1/templates/test-cs-steps.yml Removes v1 C# testing.
.pipelines/v1/templates/stages-sdk-v1.yml Removes the v1 stage graph.
.pipelines/v1/templates/package-core-steps.yml Removes legacy core packaging.
.pipelines/v1/templates/build-rust-steps.yml Removes v1 Rust packaging.
.pipelines/v1/templates/build-python-steps.yml Removes v1 Python packaging.
.pipelines/v1/templates/build-js-steps.yml Removes v1 JavaScript packaging.
.pipelines/v1/templates/build-js-addon-steps.yml Removes v1 addon builds.
.pipelines/v1/templates/build-cs-steps.yml Removes v1 C# packaging.
.pipelines/v1/templates/build-core-steps.yml Removes legacy core builds.
.pipelines/templates/steps-test-python.yml Adds feed authentication and model-cache usage.
.pipelines/templates/steps-test-js.yml Adds npm authentication and model-cache usage.
.pipelines/templates/steps-test-cs.yml Removes public NuGet and checkout inputs.
.pipelines/templates/steps-prefetch-nuget.yml Adds authenticated dependency prefetching.
.pipelines/templates/steps-pack-nuget.yml Adds runtime NuGet packaging.
.pipelines/templates/steps-pack-js.yml Adds npm feed authentication.
.pipelines/templates/steps-pack-cpp-sdk.yml Adds platform C++ SDK bundles.
.pipelines/templates/steps-build-windows.yml Updates template and model paths.
.pipelines/templates/steps-build-rust.yml Configures Cargo and native feeds.
.pipelines/templates/steps-build-python.yml Configures authenticated Python feeds.
.pipelines/templates/steps-build-macos.yml Updates model-fetch inclusion.
.pipelines/templates/steps-build-linux.yml Updates feeds and manylinux paths.
.pipelines/templates/steps-build-js.yml Adds npm feed authentication.
.pipelines/templates/steps-build-cs.yml Removes direct public NuGet.
.pipelines/templates/stages-sdk-v2.yml Adds the consolidated v2 coordinator.
.pipelines/templates/stages-rust.yml Updates model fetching and Cargo setup.
.pipelines/templates/stages-python.yml Updates model fetching and consumer authentication.
.pipelines/templates/stages-js.yml Updates model fetching and consumer authentication.
.pipelines/templates/stages-cs.yml Updates model-fetch template usage.
.pipelines/templates/stages-build-native.yml Adds native build and packaging stages.
.pipelines/templates/checkout-steps.yml Removes legacy repository checkout.
.pipelines/foundry-local-packaging.yml Makes the pipeline v2-only.
.pipelines/docs/sdk_v2-pipeline-plan.md Updates pipeline layout documentation.
.pipelines/docs/sdk_v2-js-pipeline-plan.md Updates JavaScript pipeline paths.
.pipelines/docker/manylinux/Dockerfile Relocates the manylinux image definition.
Review details

Files not reviewed (1)

  • sdk_v2/js/package-lock.json: Generated file

Suppressed comments (9)

.pipelines/templates/steps-build-rust.yml:105

  • replace-with names a Cargo source, but this block only defines an alternate registry. Cargo will fail source resolution because AIFoundryLocal_PublicPackages has no [source.AIFoundryLocal_PublicPackages] definition. Keep the registry entry for cargo login, and also define the replacement source.
    .pipelines/templates/stages-rust.yml:234
  • replace-with names a Cargo source, but this block only defines an alternate registry. The crate-pack job will fail source resolution because AIFoundryLocal_PublicPackages has no [source.AIFoundryLocal_PublicPackages] definition.
    .pipelines/templates/steps-build-python.yml:307
  • The authenticated pip variables created on the host are not inherited by docker run, and this command uses only the credential-free feed URL. On an authenticated feed, both Linux wheel builds fail while bootstrapping their build dependencies. Explicitly forward the authenticated pip environment into the ephemeral container and remove this naked command-line override.
    .pipelines/templates/steps-test-python.yml:62
  • pip config unset exits nonzero when the key is absent. Because this is the final command and PowerShell@2 checks the last native exit code by default, clean agents can fail before any tests run. Treat the missing-key case as success, as the Linux template already does with || true.
    .pipelines/templates/steps-build-python.yml:74
  • pip config unset exits nonzero when the key is absent. Since it is the final native command in this PowerShell@2 task, a clean agent can fail here before the build starts. Treat the missing-key case as success.
    .pipelines/templates/stages-python.yml:422
  • pip config unset returns a nonzero exit code when no extra index is configured. As the task's final native command, that makes the package-consumer validation fail on clean agents. Normalize the expected missing-key result to success.
    .pipelines/templates/steps-build-linux.yml:94
  • PipAuthenticate@1 exposes the authenticated index URL in the host job environment, but this container receives neither that variable nor a credential file. The explicit credential-free --index-url therefore cannot access the authenticated feed, so the manylinux native build stops while installing CMake. Forward the authenticated pip settings into this ephemeral container without baking the token into the image or logs.
    .pipelines/templates/steps-build-python.yml:336
  • This command-line --index-url overrides the authenticated PIP_INDEX_URL set by PipAuthenticate@1, replacing it with a credential-free URL. The auditwheel validation then fails against an authenticated feed. Let pip use the authenticated environment value instead.
    .pipelines/docs/sdk_v2-pipeline-plan.md:275
  • This update says pipeline dependencies are routed through AIFoundryLocal_PublicPackages, but the same document still says ORT/GenAI resolve from public PyPI with no private-feed plumbing (decisions 3 and 9, and lines 367-368), and it still describes v1 version artifacts that this PR removes. Update those sections so this plan reflects the new feed and v2-only pipeline.
  • Files reviewed: 41/47 changed files
  • Comments generated: 1
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .pipelines/foundry-local-packaging.yml
@prathikr
Prathik Rao (prathikr) merged commit bde03d1 into main Sep 16, 2026
60 checks passed
@prathikr
Prathik Rao (prathikr) deleted the prathikrao/refactor-foundry-local-packaging-pipeline branch September 16, 2026 16:54

This branch was successfully deployed

1 active deployment
Preview — 5fab0cde Deployed Sep 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants