Skip to content

[docs] Document Azure provisioning service coverage and limits - #1748

Merged
Eric Erhardt (eerhardt) merged 4 commits into
release/13.6from
sebros/provisioning-coverage-docs
Sep 29, 2026
Merged

Eric Erhardt (eerhardt) merged 4 commits into
release/13.6from
sebros/provisioning-coverage-docs

Conversation

@sebastienros

Copy link
Copy Markdown
Contributor

Documents changes from microsoft/aspire#20131

Source: microsoft/aspire#20131 by Sébastien Ros (@sebastienros).

Documentation gap and changes

The release branch already explains typed provisioning proxies and includes Storage, Service Bus, Key Vault and Managed Redis examples. It does not enumerate the expanded service mappings, callback-specific lookup restrictions, IP address collection behavior or explicit member exclusions. This updates the existing src/frontend/src/content/docs/integrations/cloud/azure/customize-resources.mdx page; no pages or executable examples are added.

  • Map AppConfiguration, AppContainers, AppService, Cdn, ContainerService, Kusto, Network, PrivateDns, PostgreSql, Redis, RedisEnterprise and SignalR packages to selected SDK models.
  • Explain separate SDK opt-ins and hosting/SDK naming differences.
  • Distinguish Container Apps environment root lookups from app/job identifier lookups, and App Service _asplan/webapp identifiers and callback scope.
  • Document IPv4/IPv6 strings and Bicep handles, validation failures, read-only output restrictions and BinaryData projection exclusions.

Target resolution

Base: release/13.6. Candidate source: pr_milestone; detail: 13.6; candidate: release/13.6; resolution: exact_match. The effective target matches the source milestone, not main.

Docs base commit: 201a9af638b2454a4203bf9af900711dfbcc50a3. Source head inspected: 6a905d20a7bf47be2f4388b183a29ccc49b04891 (merged as acd827322437be2b79b84b4542cf5bb3b8a34d99).

Deterministic signal evidence

Signal Source evidence and treatment
integration_readme_changed READMEs under all 12 src/Aspire.Hosting.Azure.Provisioning.<SDK>/ packages plus the shared provisioning README describe service mappings and bounded behavior. Missing coverage is added to the existing guide.
new_hosting_integration_project Twelve added Aspire.Hosting.Azure.Provisioning.<SDK>.csproj projects and their AtsTypeMappings.cs files establish opt-in packages and selected models.
new_package_added Those projects are packable and reference their SDK/hosting dependencies; package identifiers are explicitly listed in the guide.
polyglot_code_generator_changed src/Aspire.Hosting.CodeGeneration.Java/AtsJavaCodeGenerator.cs disambiguates normalized enum names while preserving original wire values. This supports the expanded SDK surface, not a separate undocumented configuration API.
pr_body_has_user_facing_section The source Usage section shows aspire add Aspire.Hosting.Azure.Provisioning.AppConfiguration and configureInfrastructure/getAppConfigurationStore. The guide already teaches installation and equivalent tag customization; this update names the AppConfiguration package and lookup.
target_framework_changed The added projects declare $(DefaultTargetFramework). This is new-project registration, not evidence of a changed user runtime prerequisite; no minimum version is invented.

Source and review evidence

Package mappings and limits and the per-package mappings/READMEs were checked against cached source patches. Paginated conversation and inline review comments were read. Resolved review feedback specifically confirms non-root app/job and plan/site models, string-typed Bicep handles in IP collections, and product-oriented documentation without completion counts or stacked-PR history.

Validation and human review

The page responds with HTTP 200 in the local Astro preview. Playwright confirms the rendered 15-row package table and both added section anchors. git diff --check passes. Edited tables were formatted with Prettier; the complete page has pre-existing formatting differences on both the unchanged base and this patch. No code examples were changed or added.

This is a draft requiring human review before merge. Suggested SME: Eric Erhardt (@eerhardt). No deployment defaults, authentication changes, complete SDK coverage, or new runtime requirements are claimed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@aspire-repo-bot

Copy link
Copy Markdown
Contributor

Frontend HTML artifact ready

The latest frontend build uploaded the frontend-dist artifact for PR #1748. Use the VS Code button below to open this PR with GitHub Artifacts Explorer and browse the built HTML locally.

VS Code: Open PR #1748 artifacts

This comment updates automatically when a new frontend build artifact is uploaded.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Human review is recommended, including correction of the PrivateDns wording.

Review effort: Lite
Findings: None

What changed in this PR

Documents Azure provisioning service coverage, lookup restrictions, IP handling, and unsupported SDK members.

Changes:

  • Adds a 15-row hosting/provisioning package mapping table.
  • Documents service-specific lookup and callback behavior.
  • Describes IP validation, Bicep handles, and projection exclusions.
File Summary
src/​frontend/​src/​content/​docs/​integrations/​cloud/​azure/​customize-resources.mdx Expands Azure provisioning documentation; clarify the PrivateDns integration wording.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@IEvangelist David Pine (IEvangelist) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Automated docs-accuracy review — PR #1748

Phase A source of truth: microsoft/aspire @ release/13.6 — f544a9c660afc22ac6cdb5650c21eb2f908b3054
Reviewed PR head: 98d83905db6aa0fc781f524b11b88e9b9135e416
Claims extracted: 25 (all verifiable)

Verdict Count
✅ verified 25
🟡 verified-with-nuance 0
❔ unverifiable 0
❌ contradicted 0

Phase B (blind-user doc-tester): 1 route exercised — /integrations/cloud/azure/customize-resources/ (## Azure.Provisioning customization and its new subsections). 0 critical, 2 warnings. Live browser rendering was not executed (no PR preview deployment; the frontend-dist artifact is large; local site build disallowed by policy), so this phase evaluated the PR-built page content and the docs collection.

Verdict: COMMENT

Every factual claim on this page checks out against the release source — all 15 package→SDK-model rows, the package-naming prose, the service-specific lookup method names, the IP-collection property lists, and the excluded-member table. Nothing is contradicted or unverifiable, so this is not a blocking review. Two non-blocking items are worth a look: one nuance on the table's "Selected SDK models" column (it's inconsistent about exhaustiveness), and a suggestion to add one worked lookup example. Both are inline below and in the Phase B report.


Phase A — Claim verification

No contradicted or unverifiable claims, so there are no blocking inline comments. One inline note flags a minor table-consistency nuance. Full evidence for every extracted claim:

✅ Verified — all 25 claims with source evidence (click to expand)

Evidence paths are in microsoft/aspire @ f544a9c66 (release/13.6). Package dir prefix src/Aspire.Hosting.Azure.Provisioning.<Pkg>/.

Package → selected SDK model table (customize-resources.mdx:165-181) — ✅ all verified against each package's AtsTypeMappings.cs:

  • App Configuration → AppConfigurationStore — AppConfiguration/AtsTypeMappings.cs:7
  • Container Apps → ContainerAppManagedEnvironment, ContainerApp, ContainerAppJob — AppContainers/AtsTypeMappings.cs:7-9,11,12
  • App Service → AppServicePlan, WebSite — AppService/AtsTypeMappings.cs:7-11,12 (both IsInfrastructureRoot = false)
  • Front Door → CdnProfile — Cdn/AtsTypeMappings.cs:7
  • Kubernetes Service → ContainerServiceManagedCluster — ContainerService/AtsTypeMappings.cs:7-9
  • Data Explorer → KustoCluster — Kusto/AtsTypeMappings.cs:7
  • Networking → VirtualNetwork, NetworkSecurityGroup, NatGateway, PublicIPAddress, PrivateEndpoint, NetworkSecurityPerimeter — Network/AtsTypeMappings.cs:7-9,12-16
  • Private DNS → PrivateDnsZone — PrivateDns/AtsTypeMappings.cs:7
  • PostgreSQL → PostgreSqlFlexibleServer — PostgreSql/AtsTypeMappings.cs:7
  • Cache for Redis → RedisResource — Redis/AtsTypeMappings.cs:6-8
  • Managed Redis → RedisEnterpriseCluster — RedisEnterprise/AtsTypeMappings.cs:7
  • SignalR → SignalRService — SignalR/AtsTypeMappings.cs:7
  • Storage → StorageAccount — Storage/AtsTypeMappings.cs:7
  • Service Bus → ServiceBusNamespace — ServiceBus/AtsTypeMappings.cs:7-9
  • Key Vault → KeyVaultService — KeyVault/AtsTypeMappings.cs:7

Nuance (non-blocking, inline): the "Selected SDK models" column lists proxied children for some packages (Network, Container Apps, App Service) but only the root for others (Service Bus, Storage, Key Vault also proxy ServiceBusQueue/Topic/Subscription/Rule, FileShare, KeyVaultSecret). Everything listed is correct; the column just isn't uniformly exhaustive.

Package-naming prose (customize-resources.mdx:183) — ✅ verified: Front Door=Cdn, Kubernetes=ContainerService, PostgreSQL=PostgreSql; Network/PrivateDns and Redis/RedisEnterprise are separate package directories.

Supporting resources need their own package (customize-resources.mdx:183) — ✅ verified: ContainerRegistry package exists; a Log Analytics workspace is provisioned via the OperationalInsights package. Consistent with the opt-in proxy model.

Service-specific lookups (customize-resources.mdx:199-202) — ✅ verified:

  • getAppConfigurationStore() — AppConfiguration/README.md:33
  • getContainerAppManagedEnvironment(); apps/jobs identifier-based in publish callbacks; SDK Bicep id = normalized workload name vs synthetic hosting id — AppContainers/README.md:33,41
  • getAppServicePlanByIdentifier(...) + _asplan suffix; sites use webapp in the website publish callback; neither has a no-arg root lookup — AppService/AtsTypeMappings.cs:9, AppService/README.md:31,34,40,46
  • Child resources (e.g., Kusto databases) use identifier-based lookup — consistent with KustoCluster being the IncludeContainingAssemblyTypes root.

IP address collections (customize-resources.mdx:206-208) — ✅ verified: AppContainers OutboundIPAddressList (AppContainers/README.md:43); AppService IPAddresses, ExternalInboundIPAddresses, InternalInboundIPAddresses, LinuxOutboundIPAddresses, WindowsOutboundIPAddresses (AppService/README.md:46, exact list match). Writable/validation/getter-preservation semantics match both READMEs.

Excluded-member table (customize-resources.mdx:212-216) — ✅ verified:

  • ContainerService / CustomCATrustCertificates / BicepList<BinaryData> — ContainerService/AtsTypeMappings.cs:11 + README.md:43
  • Network / AdditionalProperties / BicepDictionary<BinaryData> — Network/AtsTypeMappings.cs:11 + README.md:43
  • Redis / AdditionalProperties / BicepDictionary<BinaryData> — Redis/AtsTypeMappings.cs:10 + README.md:53

LearnMore anchor (customize-resources.mdx:220-223) — ✅ verified: #hosting-to-provisioning-inventory resolves to ## Hosting-to-provisioning inventory in src/Aspire.Hosting.Azure.Provisioning/README.md:35. The link pins a microsoft/aspire commit SHA as a permalink (not the release tip); the anchor resolves regardless.


Phase B — Doc-tester results (blind-user)

Environment: Live browser (Playwright) rendering was not executed — no PR preview deployment, the site build artifact is large, and a local build is disallowed by policy. The blind-user evaluation below was performed against the PR-built page and the docs content collection. No microsoft/aspire source was consulted in this phase.

Focus route: /integrations/cloud/azure/customize-resources/ — ## Azure.Provisioning customization → ### Enable typed provisioning proxies, ### Service-specific lookups, ### IP address collections and projection limits

Category Passed Failed Warnings
Content accuracy (blind) — 0 1
Code examples n/a 0 0
CLI commands n/a 0 0
Links pass 0 0

Critical issues

None detectable from the documentation alone.

Warnings

  1. "Selected SDK models" column is inconsistent about exhaustiveness. Purely from the page: Azure networking lists six models and Container Apps lists three, but Azure Service Bus lists only ServiceBusNamespace, Azure Storage only StorageAccount, and Azure Key Vault only KeyVaultService. A reader can't tell whether the column is the complete set of proxied models or a representative subset. Recommend a one-line note clarifying the column lists primary/root models (or making it consistent). (This is also the Phase A nuance.)
  2. Reference sections give method names with no worked example. ### Service-specific lookups introduces getAppConfigurationStore(), getContainerAppManagedEnvironment(), and getAppServicePlanByIdentifier(...), plus terms like "infrastructure callback", "publish callback", "Bicep identifier", and "no-argument root lookup" — but shows no TypeScript snippet demonstrating a single lookup end to end. A blind reader learning the proxy API would benefit from one short example (e.g., the App Configuration store callback).

Knowledge gap: Azure provisioning / Bicep vocabulary

What I needed to know: "infrastructure callback", "publish callback", "Bicep identifier", "no-argument root lookup", "typed resource list".
Source of my knowledge: built-in/prior knowledge, not this page's new sections.
User impact: readers new to Azure.Provisioning / Bicep may not follow the service-specific lookup rules.
Recommendation: a brief prerequisite pointer, or the worked example from Warning 2, would close most of the gap. Some Azure familiarity is reasonable to assume on an advanced customization page.

Passed checks

  • Heading nesting is correct: the two new ### sections sit under ## Azure.Provisioning customization, as siblings of ### Enable typed provisioning proxies.
  • :::caution[Experimental API] matches the established repo convention and correctly cites the experimental diagnostic (ASPIREAZUREPROVISIONING001).
  • Package/model, excluded-member, and IP-collection tables render as valid, well-formed Markdown tables.
  • All imports are used (LearnMore, Aside, Image, …); no unused-import smell in the added content.
  • No site-relative internal links were added, so this diff introduces no internal broken-link/anchor risk; external links are well-formed (broken-link checking is CI-owned / out of scope).

Recommendations

  1. Clarify the "Selected SDK models" column semantics (exhaustive vs representative).
  2. Add one worked TypeScript lookup example in "Service-specific lookups".

Automated hourly docs-from-code review. Phase A reads microsoft/aspire release source; Phase B evaluates the docs blind to that source; this comment merges both.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Pine (IEvangelist) pushed a commit that referenced this pull request Sep 28, 2026
Documents changes from microsoft/aspire#19675:
microsoft/aspire#19675, authored by
@sebastienros.

## Scope and documentation gap

This is the explicitly requested **separate follow-up**, not a
replacement for #1747 (integration authoring/diagnostics) or #1748
(service coverage). Neither existing PR nor its branch is modified. The
release rollup #1599 is not the source PR and is untouched.

Adds a focused, user-oriented reference for `infrastructure.bicep()`:

- All **32 factory exports**, including the `resourceIdentifier` export
alias, with arguments, return/value semantics, underlying C# SDK
counterpart or AST node, and emitted Bicep.
- All **3 string-builder methods**, **3 infrastructure declaration
helpers**, **16 binary / 3 unary operators**, value/security metadata,
and explicit array/object/null constructor and declaration-type
boundaries.
- Complete TypeScript and C# Storage examples: deterministic
valid-length naming, resource-group location, parameter/deployment tags,
concatenation, and resource-ID output.
- Complete TypeScript and C# Key Vault examples: JSON object/array data,
variable/member/index access, deployment-time equality/conditional,
retention settings, purge-protection caveats, and integer output.
Existing authorization stays intact.
- Clear separation of remote handles, host-language evaluation,
deployment-time functions, GUID/URI literals versus functions, SDK
typing versus conversions, and secure metadata versus protection of
output destinations.

### Files

- Added
`src/frontend/src/content/docs/integrations/cloud/azure/bicep-helpers.mdx`.
- Added one cross-link in
`src/frontend/src/content/docs/integrations/cloud/azure/customize-resources.mdx`;
existing guidance and examples are preserved.
- Added discovery entries in
`src/frontend/config/sidebar/integrations.topics.ts` and
`deployment.topics.ts`.

## Exact target rationale and provenance

Prepared target resolution: `candidate_source=pr_milestone`,
`candidate_source_detail=13.6`, `candidate_target_branch=release/13.6`,
`target_resolution=exact_match`. The matching docs release branch
exists; this is not a latest-release or main fallback.

- Docs base: `release/13.6` at
`e20e81f100b699c4dd6adbf01a52f6fd7bad11bd`.
- Head: `sebros/bicep-helper-reference`, on the origin
`microsoft/aspire.dev`, not a fork.
- Product release source:
[`43496a2a306c81c862c947b11b4f4e5494b6fe08`](https://github.com/microsoft/aspire/tree/43496a2a306c81c862c947b11b4f4e5494b6fe08).
Factory, value wrapper, declaration and string-builder implementations
checked against this release, not 14.x main.
- Actual generated SDK and installed CLI: **13.6.0-preview.1.26473.12**,
source `a11eca9611073f7cf66fa87faac63c2119e87713`, matching this docs
branch's generated API data.
- Exact Aspire packages restored from the official public `dotnet9` feed
after the original staging darc feed returned HTTP 404. Only isolated
scratch configuration changed.

## Official Azure SDK verification

Verified Microsoft Learn and the corresponding official SDK
implementation, rather than inferring mappings from Aspire XML
summaries:

- [BicepFunction, Azure.Provisioning
1.6.0](https://learn.microsoft.com/dotnet/api/azure.provisioning.expressions.bicepfunction?view=azure-dotnet),
with [stable pinned
source](https://github.com/Azure/azure-sdk-for-net/blob/4d32854480515e716c762be7925660bce6da251a/sdk/provisioning/Azure.Provisioning/src/Expressions/BicepFunction.cs).
-
[BicepValue<T>](https://learn.microsoft.com/dotnet/api/azure.provisioning.bicepvalue-1?view=azure-dotnet),
[expression AST
namespace](https://learn.microsoft.com/dotnet/api/azure.provisioning.expressions?view=azure-dotnet),
and declaration types.
- [Stable literal serialization
implementation](https://github.com/Azure/azure-sdk-for-net/blob/4d32854480515e716c762be7925660bce6da251a/sdk/provisioning/Azure.Provisioning/src/Expressions/BicepTypeMapping.cs):
`double(1.5)` emits `json('1.5')`, whole `double(2)` emits `2`,
standalone one-hour `TimeSpan` emits `'01:00:00'`; property-specific
formats can differ.
- [StorageAccount
1.1.2](https://learn.microsoft.com/dotnet/api/azure.provisioning.storage.storageaccount?view=azure-dotnet),
[KeyVaultProperties
1.1.0](https://learn.microsoft.com/dotnet/api/azure.provisioning.keyvault.keyvaultproperties?view=azure-dotnet),
and [retention
bounds](https://learn.microsoft.com/dotnet/api/azure.provisioning.keyvault.keyvaultproperties.softdeleteretentionindays?view=azure-dotnet).
- Bicep language references for string/resource/scope functions,
operators, secure parameters and Azure resource naming; Key Vault
soft-delete documentation for immutable retention and purge protection.

## Validation

- Extracted both exact TypeScript snippets and compiled them using `tsc
-p tsconfig.apphost.json` against **genuine generated release SDK
code**, with no SDK patches, casts, diagnostics suppression or
production changes.
- Both TypeScript AppHosts successfully ran local `aspire publish` with
a nonsecret `Parameters__environment=Production` input and generated
Storage / Key Vault Bicep. Expected warning: no compute environment in
these resource-only examples.
- Compiled both exact C# counterparts with the matching Aspire packages
and generated local manifests. **Storage and Key Vault Bicep files are
each byte-for-byte identical between the C# and TypeScript versions.**
- Independently ran Azure.Provisioning 1.6.0 offline generation to
confirm literals, interpolation and all operator spellings.
- The full existing `pnpm test:unit:twoslash-blocks` gate passed (2
tests). New proxy examples intentionally use ordinary TypeScript fences,
as their operator/runtime surface is checked against genuine SDK modules
rather than the site's simplified declaration bundle.
- Frontmatter SEO checks passed (3 tests); touched sidebar files passed
ESLint; Prettier and `git diff --check` passed.
- Local Astro route returned 200; Playwright inspected desktop/mobile
tables, synchronized TypeScript/C# tabs, headings and cross-link
navigation. No page-wide mobile overflow. Unrelated dev-only
`/api/live/` and `/api/live/stream/` requests return 404 without the
static host.
- All 19 external links in the new page returned HTTP 200.
- No production site build, Azure deployment, cloud access mutation,
secret creation, billing operation, workflow dispatch, or
dependency-manifest/lockfile change in this PR.

### SME attention: tested preview string-builder limitation

The exact generated **13.6.0-preview.1.26473.12 TypeScript SDK**
implements `BicepStringBuilderProxyImpl.build()` with `await
this._client.flushPendingPromises()`
(`.aspire/modules/aspire.mts:18905-18906`). Inside
`configureInfrastructure`, this waits for the enclosing pending
callback. The fully awaited original Storage sample consistently timed
out after 120 seconds, with `Flushing 2 pending promise(s)` in the
trace.

The runnable sample now uses `concat` and publishes successfully. The
page preserves the underlying string-builder reference and narrowly
labels this exact preview limitation; it does not attribute the problem
to C# `BicepStringBuilder` or Bicep itself. Please reassess/remove this
caveat when the generated SDK is fixed. No product fix, SDK
modification, or new product issue is included.

Minimal reproduction (inside a configured callback, after obtaining
`bicep`):

```typescript
const label = await bicep.createStringBuilder();
await label.appendLiteral('storage-');
await label.appendValue(await bicep.string('example'));
await label.build();
```

## Original source signal accounting

Prepared inputs require documentation and are not excluded. This
user-requested helper follow-up narrows the original broad PR's
remaining gap; #1747 remains the relevant authoring/diagnostics draft.

| Triggered category | Concrete source evidence and treatment |
| --- | --- |
| `cli_command_file_changed` |
`src/Aspire.Cli/Commands/Sdk/SdkDumpCommand.cs`: experimental capability
metadata. Existing authoring draft #1747; this page documents
experimental helper boundaries, not CLI behavior again. |
| `diagnostic_documentation_changed` | `docs/list-of-diagnostics.md`:
provisioning/projection diagnostics. Existing #1747; new page retains
`ASPIREAZUREPROVISIONING001` caveat. |
| `diff_scan_skipped_due_to_missing_patch` |
`AspireProvisioningProxyGenerator.cs` exceeded cached patch coverage.
This follow-up directly reads release source and validates actual
generated package SDK instead of treating missing patch as a skip. |
| `integration_readme_changed` | Shared
`Aspire.Hosting.Azure.Provisioning/README.md` and per-service READMEs.
New page adds the missing complete helper-to-SDK/Bicep mapping without
duplicating general authoring prose. |
| `new_hosting_integration_project` | Shared runtime and original
provisioning service `.csproj` additions. New examples explicitly name
Storage/KeyVault opt-in packages; service inventory stays separate. |
| `new_package_added` | Runtime, generator and original 12 provisioning
service packages. Actual matching runtime/Storage/KeyVault packages used
to generate and execute snippets. |
| `new_public_type` | `BicepValueProxy`, `ProvisionableResourceProxy`,
export provider attribute. Reference explains value/resource handle
distinctions and factory/declaration semantics; export provider
authoring stays in #1747. |
| `polyglot_code_generator_changed` | TypeScript/Python/Java code
generators and TypeScript projector. Genuine generated TypeScript SDK
validated; the observed build-method limitation is explicitly surfaced.
|
| `pr_body_has_user_facing_section` | Source PR's “User-facing usage”
section contains customization examples. This adds complete
user-oriented Storage and Key Vault scenarios, not more internal
authoring guidance. |
| `target_framework_changed` | New provisioning project target-framework
declarations. No evidence of a changed AppHost prerequisite; this PR
doesn't change prerequisites or dependency manifests. |

**Human review is required before merging**, especially the
exact-preview string-builder caveat and exhaustive mapping tables. SME
requested: @eerhardt.

---------

Co-authored-by: Sébastien Ros <1165805+sebastienros@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Pine (IEvangelist) added a commit that referenced this pull request Sep 28, 2026
…ps (#1780)

## Summary

<!-- Describe what this pull request changes and why. -->

Reconcile the 13.6 wiki audit and **all 25 open `docs-from-code`
proposals targeting `release/13.6`** against the actual release source.
Add missing canonical guidance rather than putting all coverage in
What's new. This is a new, isolated feature PR into `release/13.6`; it
does not update the release rollup #1599, merge or close another
proposal, or push directly to a release branch.

**Draft with explicit remaining packaging/validation gates:** the six
REPL walkthroughs are source-verified, but current publicly available
13.6 packages do not contain the late `WithRepl` exports. Generated API
catalogs have deliberately not been fabricated or refreshed from 14.x.
See the open checklist below.

### Evidence baseline

- Documentation base: `717442f6666948bcf77f3d704dc2dadf7c080ec2`.
- Product source of truth:
[`microsoft/aspire@e8fd6fbb954f50ccd2e66479538392f65e13e71d`](https://github.com/microsoft/aspire/tree/e8fd6fbb954f50ccd2e66479538392f65e13e71d),
current `release/13.6` at audit time. Source was read from that Git
object, not the stale source working directory.
- [13.6 wiki](https://github.com/microsoft/aspire/wiki/13.6-Change-log)
snapshot `8e01a371d4f16a1306e48174d4cf1fdeca714348`, whose cutoff is
product PR 20511. Later backports 20541/20546/20548 are included here.
- Proposal base branches alone were **not** used as proof of release
membership. Direct ancestry and known release backports were checked.
Four fallback-targeted proposals are excluded below.
- Wiki link corrections: its REPL link #1752 actually covers Sandboxes;
the REPL proposal is #1740. Its AOT link #1714 covers PFX certificates,
not AOT.

### Complete audit-gap checklist

Checked items mean documentation coverage is implemented, not that cloud
deployment or every product runtime scenario was executed.

- [x] **1. Dotnet API graduation:** correct removal to **13.6**, not
14.0, in What's new, both Dotnet guides, and the diagnostic page;
preserve the prerelease package caveat. This applies to core
`AddDotnetProject`, `DotnetProjectResource`, and related
`WithBuildEnvironment` overloads, not all uses of the diagnostic.
Source: microsoft/aspire#20496.
- [x] **2. Sandboxes:** remove obsolete API suppressions in the article
and deployment guide while preserving Azure service preview/access and
prerelease package limitations. Source: microsoft/aspire#20483.
- [x] **3. Docked REPL documentation:** all six
PostgreSQL/MySQL/MongoDB/SQL Server/Redis/Valkey guides plus the article
now cover opt-in `WithRepl`/`withRepl`, run-only availability, actual
client privileges, credential handling, and explicit exit versus closing
a viewer. Source: microsoft/aspire#20419, backport of
microsoft/aspire#20231. Package-backed checks remain open below.
- [x] **4. Terminal CLI flag:** update current 13.6 article,
`with-terminal`, and all three terminal command references. Preserve
`terminals.v1` and experimental hosting API distinctions. Current
configuration/schema data had no flag entry to remove; historical 13.5
notes remain historical. Source: microsoft/aspire#20548.
- [x] **5. First-party Rust:** rewrite both canonical Rust guides around
`Aspire.Hosting.Rust`; document Cargo versus application arguments,
typed targets, debugging, generated Dockerfiles, workspace context, ABI
constraints, and Toolkit migration. Bacon remains explicitly
Toolkit-only. Add exact first-party package mapping. Source:
microsoft/aspire#18906 and current Rust README.
- [x] **6. Agent setup:** align command reference, skills guide,
AI-agent guide, and article on MCP opt-in, `--mcp`,
chained/non-interactive behavior, seven-skill catalog, Project v2
migration, and Copilot app detection. Also fix stale default-selection
text: all applicable bundle skills are preselected; companion tools
remain opt-in. Sources: microsoft/aspire#19893, microsoft/aspire#20405,
microsoft/aspire#19820.
- [x] **7. Deno AppHost runtime:** document Deno 2+ detection, commands,
permissions, native watch/type checking, doctor, and `DENO_CERT`,
separately from Deno guest hosting. Source: microsoft/aspire#18627,
distinct from microsoft/aspire#18628.
- [x] **8. Native AOT / Fluent UI v5:** concise article, dashboard
exploration, and standalone guidance; automatic packaged-dashboard
selection, no invented performance figures. Source:
microsoft/aspire#19565 and release packaging sources.
- [x] **9. NuGet:** document bundled in-process operations, credential
providers, non-interactive authentication, and realistic
troubleshooting. Correct the proposal's `dotnet nuget locals`
authentication advice: cache commands do not authenticate a feed.
Source: microsoft/aspire#20391.
- [x] **10. Multithreaded builds:** article and coordinated-build guide
explain `-mt`, SDK detection, distinct project/file-based SDK floors,
and fallback. Source: microsoft/aspire#20441.
- [x] **11. Radius:** add a real deployment guide with C#/TypeScript
setup, recipe-backed connections versus local endpoints, per-resource
credential behavior, unauthenticated Redis limitation, secret exposure
boundaries, and actionable runtime diagnostics 070–091. Wire navigation
and exact package mapping. Source: microsoft/aspire#19555 and release
README.
- [x] **12. Connection aliases:** replace contradictory no-encoding
guidance, retain composed logical-key-first lookup and portable-target
behavior, explain collision detection and custom-publisher metadata.
Source: microsoft/aspire#19729.
- [x] **13. Connector Namespace / Toolbox / provisioning:** add
Connector Namespace walkthrough, security/consent/revocation limits and
mapping/sidebar; add Foundry Toolbox walkthrough, connection properties,
roles, index prerequisites, approval enforcement boundaries, immutable
versions, and existing-resource behavior. Extend existing Azure
provisioning guide without a duplicate page. Sources:
microsoft/aspire#19024, microsoft/aspire#17742, microsoft/aspire#20131.
- [x] **14. Remaining high-impact items:** article covers opt-in
manifest-aware DNX and new-template CLI bundling (existing SDK guides
retained), migration skill and Copilot app detection; canonical inline
`CsiVolumeSourceV1`/`VolumeV1.Csi` example, management links, Cosmos
vNext telemetry, and AI Inference `GetModelInfoAsync`/`/info` health
checks with `DisableHealthChecks`. No Azure OpenAI health-check claim.
Sources: microsoft/aspire#19310, microsoft/aspire#19076,
microsoft/aspire#19826, microsoft/aspire#20070, microsoft/aspire#15671,
microsoft/aspire#15969.
- [x] **15. All 25 proposal dispositions:** listed below, including
newer dashboard backports and four exclusions. Existing Sandbox
inference coverage is retained rather than copied from a stale draft.
- [ ] **16. Refresh generated API/catalog/Twoslash data from an official
post-backport 13.6 build.** Existing `26473.12`/`a11eca96` data remains
untouched. The newest public `dotnet9` feed package checked,
`13.6.0-preview.1.26474.10` at
`43496a2a306c81c862c947b11b4f4e5494b6fe08`, still has no Redis
`WithRepl` in its actual package XML. Do not use 14.x, hand-edit
declarations, or attribute source changes to older binaries.
- [ ] **Validate the six REPL examples against that actual post-backport
SDK and running clients.** Their new TypeScript fences are plain
TypeScript, not annotated with unsupported Twoslash data. No existing
diagnostics are allowlisted or suppressed; no generated API exports are
fabricated. Enable Twoslash when the genuine catalog catches up.

### All 25 open proposal dispositions and provenance

Text is selectively adapted from these proposals, not merged wholesale.
#1778 and #1748 are authored by @sebastienros; the other proposals are
authored by the Aspire repo bot. The table credits the associated
product-change authors where supplied by the proposals. Existing PRs
remain open and unchanged.

| Docs PR | Release source / credited product author | Disposition |
| --- | --- | --- |
| #1778 | microsoft/aspire#19729 — @sebastienros | **Adopted:**
canonical connection-string alias correction, including logical-first
resolution and migration. |
| #1771 | microsoft/aspire#20481 — @sebastienros | **Excluded:** flat
polyglot feature keys are not in the audited release tip; no verified
backport. Preserve release key names. |
| #1770 | microsoft/aspire#20525 → microsoft/aspire#20548 — @mitchdenny
| **Corrected/adopted:** command guides plus the still-current 13.6
article, which the proposal incorrectly treats as historical. |
| #1769 | microsoft/aspire#20416 — @JamesNK | **Excluded:** brand hover
change has no verified 13.6 membership/backport. |
| #1768 | microsoft/aspire#20523 → microsoft/aspire#20546 — @JamesNK |
**Adopted:** run pin/unpin preserves selector and current selection. |
| #1766 | microsoft/aspire#20537 → microsoft/aspire#20541 — @mitchdenny
| **Adopted:** terminal dock empty state. |
| #1761 | microsoft/aspire#20490 → microsoft/aspire#20496 — @eerhardt |
**Corrected:** graduation is 13.6, package remains prerelease,
Blazor-specific exception retained. |
| #1760 | microsoft/aspire#20436 — @eerhardt | **Excluded:** CLI
net11/tools-any retarget is not in the audited release; no fallback-base
inference. |
| #1748 | microsoft/aspire#20131 — @sebastienros | **Adopted:** extend
existing provisioning guide with service-specific models/lookups and
projection limits. |
| #1744 | microsoft/aspire#20337 → microsoft/aspire#20441 — @karolz-ms |
**Adopted:** precise SDK-conditional multithreaded build coverage. |
| #1740 | microsoft/aspire#20231 → microsoft/aspire#20419 — @mitchdenny
| **Adapted:** all six guides; TypeScript-first tabs, source-verified
lifecycle/security. Actual post-backport SDK/runtime gate is open above.
|
| #1738 | microsoft/aspire#20158 → microsoft/aspire#20405 — @karolz-ms |
**Partly already covered / completed:** existing seven-skill catalog
retained; add project migration guidance and correct command
catalog/defaults. Do not misclassify the bundled skill as a companion
tool. |
| #1735 | microsoft/aspire#20334 — @karolz-ms | **Excluded:** enhanced
startup errors are not in the audited release; no verified backport. |
| #1731 | microsoft/aspire#19847 → microsoft/aspire#20391 — @eerhardt |
**Corrected/adopted:** in-process NuGet and real authenticated-restore
troubleshooting, not cache-command authentication. |
| #1719 | microsoft/aspire#20299 → microsoft/aspire#20407 — @JamesNK |
**Corrected/adopted:** cookie naming/scoping; identical names can
collide but do not guarantee cross-dashboard cookie decryptability or
shared sign-in. |
| #1664 | microsoft/aspire#20011 — @maddymontaquila | **Adopted:**
concise Azure environment icon release note. |
| #1628 | microsoft/aspire#17742 — @davidfowl | **Adapted/expanded:**
canonical Toolbox examples, consumer contract, role/index prerequisites,
approval/security and concurrency limits. |
| #1623 | microsoft/aspire#19810 — @mitchdenny | **Already covered:**
current Sandbox guide/article already describe compute inference,
explicit selection and external endpoints. Preserve that guidance while
removing obsolete suppressions. |
| #1620 | microsoft/aspire#19243 — @sebastienros | **Adapted:** AKS
credential-before-Helm cleanup and destructive-operation warning; omit
misleading ambient-context workaround. |
| #1614 | microsoft/aspire#19870 — @sebastienros | **Adopted:** typed
callback handle behavior in extension authoring and article. |
| #1574 | microsoft/aspire#19430 — @mitchdenny | **Adapted:** canonical
hostname inheritance, explicit-host precedence, catch-all default
backend. |
| #1570 | microsoft/aspire#19590 — @karolz-ms | **Adopted:** Dev Tunnel
URL regression troubleshooting. |
| #1565 | microsoft/aspire#19429 — @mitchdenny | **Corrected/adopted:**
Helm embedded parameters with real `refExpr` and `addParameter(name, {
value })`, not stringifying a handle or using an invalid actual-SDK
overload. |
| #1564 | microsoft/aspire#19026 — @karolz-ms | **Corrected/adopted:**
C#/TypeScript Dotnet gateway walkthrough. Retain both experimental
diagnostics; remove obsolete run-only restriction after
microsoft/aspire#19997 publishing support. Avoid imported ambiguous API
reference. |
| #1499 | microsoft/aspire#19248 — @IEvangelist | **Adopted:** describe
exact secret-value redaction and embedded-secret limit; release article
already covered the fix. |

### Important source-verified corrections to proposals / earlier audit
assumptions

-
[`BlazorGatewayExtensions.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Hosting.Blazor/BlazorGatewayExtensions.cs):
`AddDotnetProjectBlazorGateway` and the Dotnet `WithBlazorClientApp`
overload still carry `ASPIREDOTNETPROJECT001`; the class carries
`ASPIREBLAZOR001`. They share `WithBlazorClientAppCore`/`WithBlazorApp`
and the publish-companion path. Thus neither blanket diagnostic
retirement nor the proposal's old run-only claim is correct.
-
[`SkillDefinition.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Agents/SkillDefinition.cs)
sets bundled skills' `IsDefault=true`;
[`AgentInitCommand.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Commands/AgentInitCommand.cs)
selects the applicable catalog defaults for both flows. MCP has its own
standalone-only binding.
-
[`TypeScriptAppHostToolchainResolver.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Projects/TypeScriptAppHostToolchainResolver.cs)
is the source for Deno flags and certificate variable; guest Deno
hosting is separate.
- [`Radius
README`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Hosting.Radius/README.md)
supplies the resource-specific credential rules and publish diagnostics,
not assumptions about local endpoints.

## Third-party links and affiliations

<!-- List third-party links and disclose material affiliations. -->

Links point to official Microsoft Learn, VS Code Marketplace debugger
extensions, Rust/Cargo/Bacon documentation, Radius documentation, and
source repositories. No sponsorship, commercial endorsement, or
affiliation claim is introduced. Maintainers should supply any personal
affiliation disclosure required by policy; automation has not inferred
one.

## Validation

<!-- List the checks you ran or explain why validation isn't needed. -->

- **97 passing focused unit checks** across API-reference
authoring/rendering, Twoslash blocks, file-tree formatting, CLI
configuration schema, SEO lengths, and resource catalog.
- **82 passing structured-data checks**, including exact integration
mapping uniqueness and page resolution.
- **11 C# samples compile**, zero warnings/errors, using genuine
`13.6.0-preview.1.26473.12` packages. Scope: Rust, Connector Namespace,
Radius, Toolbox, inline CSI, Helm, Blazor gateway, and provisioning.
`Projects.Api/Worker/Client` use compile-only `IProjectMetadata`
stand-ins; no claim of running those apps or provisioning cloud
resources.
- **10 TypeScript samples pass `tsc`** under `strict`, `NodeNext`, and
`ES2022` against three **unmodified actual SDK files**, not just the
site's declaration bundle. The fixture uses the exact `e8fd6fbb` release
`AtsCapabilityScanner` and genuine `26473.12`
TypeSystem/code-generator/integration binaries, whose informational
source is `a11eca96`. This is an isolated local generation fixture,
**not** a claim that official CLI generation or a new packaged release
was tested. An attempted restore with the older handed-off local CLI
could not discover an AppHost server; the bounded direct generator
fixture was used instead.
- The SDK scan is **not globally warning-free**: it reports a Radius
`withContainerImage` collision on `CSharpAppResource` and an App
Configuration `createRoleAssignment` overload collision. None of the
compiled examples calls those colliding methods; the warnings are
retained in evidence, not suppressed, and no generated declarations were
edited.
- Browser: Connector Namespace, Radius, both Rust pages, Foundry
hosting, and What's new return **HTTP 200**, correct headings, and no
rendered Twoslash errors. New guide/article page-local anchors and the
cross-page Blazor anchor resolve. Connector/Radius mobile layouts have
no horizontal overflow; Connector language-tab interaction works.
Standalone Astro preview emits expected `/api/live` 404s because
StaticHost is not running.
- `git diff --check` passes. No production `pnpm build`, cloud
deployment, REPL runtime session, full product suite, or blanket
validation of every pre-existing example was performed.
- Generated C#/TypeScript API data, declaration bundles, integration
catalogs, image catalogs, and contributor data are unchanged. Only the
authored package-to-guide mapping is updated.

**Before merging:** complete the two packaging/REPL checkboxes above,
inspect CI, and obtain human review. This PR intentionally does not
close or merge the source documentation proposals.

---------

Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@eerhardt
Eric Erhardt (eerhardt) merged commit a300d47 into release/13.6 Sep 29, 2026
16 checks passed
@eerhardt
Eric Erhardt (eerhardt) deleted the sebros/provisioning-coverage-docs branch September 29, 2026 16:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs-from-code Copilot initiated issue from dotnet/aspire repo

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants