From e7b9670da3f6b6a43956444eff4a9db772553db1 Mon Sep 17 00:00:00 2001 From: Mark Cornmesser Date: Wed, 16 Sep 2026 16:15:45 -0700 Subject: [PATCH 1/6] Add FooFrix image build resource group in West US 3 --- terraform/azure_foofrix/README.md | 3 ++- terraform/azure_foofrix/images.tf | 12 ++++++++++-- terraform/azure_foofrix/outputs.tf | 2 +- terraform/azure_foofrix/tests/access.tftest.hcl | 13 +++++++++++-- 4 files changed, 24 insertions(+), 6 deletions(-) diff --git a/terraform/azure_foofrix/README.md b/terraform/azure_foofrix/README.md index 6d033dbb..d870b842 100644 --- a/terraform/azure_foofrix/README.md +++ b/terraform/azure_foofrix/README.md @@ -62,7 +62,8 @@ The workflow needs `id-token: write` and audience `api://AzureADTokenExchange`. No image-build client secret is needed. Configure Packer to use the existing `image_build_resource_group` output for -temporary resources. Publish to `image_gallery_name` in +temporary resources in West US 3. The original Central US build group is retained; +the gallery, storage, and identities remain in Central US. Publish to `image_gallery_name` in `image_gallery_resource_group`, using the definition from `windows_image_definition_id`. The workflow logs in with `image_build_client_id`. Attach `image_build_identity_id` to the temporary VM. The guest bootstrap must diff --git a/terraform/azure_foofrix/images.tf b/terraform/azure_foofrix/images.tf index d1daa5ab..74d3e47c 100644 --- a/terraform/azure_foofrix/images.tf +++ b/terraform/azure_foofrix/images.tf @@ -83,6 +83,13 @@ resource "azurerm_resource_group" "image_build" { tags = local.common_tags } +# Packer uses the build resource group's location for its temporary VM. +resource "azurerm_resource_group" "image_build_westus3" { + name = "rg-foofrix-image-build-westus3" + location = "westus3" + tags = local.common_tags +} + resource "azurerm_user_assigned_identity" "image_build" { name = "id-foofrix-image-build" resource_group_name = azurerm_resource_group.foofrix.name @@ -94,8 +101,9 @@ resource "azurerm_user_assigned_identity" "image_build" { resource "azurerm_role_assignment" "image_build_contributor" { for_each = { - build = azurerm_resource_group.image_build.id - gallery = azurerm_shared_image_gallery.foofrix.id + build = azurerm_resource_group.image_build.id + build_westus3 = azurerm_resource_group.image_build_westus3.id + gallery = azurerm_shared_image_gallery.foofrix.id } scope = each.value role_definition_name = "Contributor" diff --git a/terraform/azure_foofrix/outputs.tf b/terraform/azure_foofrix/outputs.tf index 7d1ef253..04c7b84a 100644 --- a/terraform/azure_foofrix/outputs.tf +++ b/terraform/azure_foofrix/outputs.tf @@ -43,7 +43,7 @@ output "image_build_client_id" { } output "image_build_resource_group" { - value = azurerm_resource_group.image_build.name + value = azurerm_resource_group.image_build_westus3.name } output "image_build_identity_id" { diff --git a/terraform/azure_foofrix/tests/access.tftest.hcl b/terraform/azure_foofrix/tests/access.tftest.hcl index 03bba726..5e153b09 100644 --- a/terraform/azure_foofrix/tests/access.tftest.hcl +++ b/terraform/azure_foofrix/tests/access.tftest.hcl @@ -12,6 +12,12 @@ override_resource { values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix-image-build" } } +override_resource { + target = azurerm_resource_group.image_build_westus3 + override_during = plan + values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix-image-build-westus3" } +} + override_resource { target = azurerm_shared_image_gallery.foofrix override_during = plan @@ -35,8 +41,11 @@ run "build_and_team_access" { assert { condition = ( - length(azurerm_role_assignment.image_build_contributor) == 2 && + length(azurerm_role_assignment.image_build_contributor) == 3 && azurerm_role_assignment.image_build_contributor["build"].scope == azurerm_resource_group.image_build.id && + azurerm_resource_group.image_build_westus3.location == "westus3" && + output.image_build_resource_group == azurerm_resource_group.image_build_westus3.name && + azurerm_role_assignment.image_build_contributor["build_westus3"].scope == azurerm_resource_group.image_build_westus3.id && azurerm_role_assignment.image_build_contributor["gallery"].scope == azurerm_shared_image_gallery.foofrix.id && azurerm_role_assignment.image_build_identity_operator.scope == azurerm_user_assigned_identity.image_build.id && alltrue([for grant in azurerm_role_assignment.image_build_blob_reader : grant.scope == azurerm_storage_container.artifacts.id]) && @@ -45,7 +54,7 @@ run "build_and_team_access" { length(azurerm_role_assignment.image_build_blob_reader) == 2 && azurerm_role_assignment.image_build_identity_operator.role_definition_name == "Managed Identity Operator" ) - error_message = "The builder needs two Contributor grants, identity attachment, and read access for both build identities." + error_message = "The builder needs three Contributor grants, identity attachment, and read access for both build identities." } assert { From ad12241440c6036ab3888822f01411ab3f15bb19 Mon Sep 17 00:00:00 2001 From: Mark Cornmesser Date: Mon, 21 Sep 2026 09:52:26 -0700 Subject: [PATCH 2/6] Add FooFrix Windows 11 25H2 image definition --- terraform/azure_foofrix/README.md | 11 ++++++----- terraform/azure_foofrix/images.tf | 18 ++++++++++++++++++ terraform/azure_foofrix/outputs.tf | 4 ++++ 3 files changed, 28 insertions(+), 5 deletions(-) diff --git a/terraform/azure_foofrix/README.md b/terraform/azure_foofrix/README.md index d870b842..5cd8df9a 100644 --- a/terraform/azure_foofrix/README.md +++ b/terraform/azure_foofrix/README.md @@ -14,9 +14,9 @@ The harness source and image provisioning scripts are in This Terraform stack manages the subscription, a resource group in Central US, a Key Vault available for Windows worker secrets, and a managed identity for the VMs. -Terraform manages the `foofrix` Compute Gallery and its `win11_64_24h2` image -definition. It uses the existing FXCI Windows 11 24H2 properties: Windows, x64, -Hyper-V V2, generalized, and `MicrosoftWindowsDesktop/Windows-11/win11-24h2-avd`. +Terraform manages the `foofrix` Compute Gallery and its `win11_64_24h2` and +`win11_64_25h2` image definitions. They use the existing FXCI properties: +Windows, x64, Hyper-V V2, generalized, and the matching 24H2 or 25H2 AVD SKU. The worker-images workflow publishes image versions. A private `artifacts` Blob Storage container holds Azure build and image files in Standard LRS storage. The GCP launcher manages the VMs through `sp-foofrix-azure-devtest`. The application and @@ -64,8 +64,9 @@ No image-build client secret is needed. Configure Packer to use the existing `image_build_resource_group` output for temporary resources in West US 3. The original Central US build group is retained; the gallery, storage, and identities remain in Central US. Publish to `image_gallery_name` in -`image_gallery_resource_group`, using the definition from -`windows_image_definition_id`. The workflow logs in with `image_build_client_id`. +`image_gallery_resource_group`, using `windows_image_definition_id` for 24H2 or +`windows_25h2_image_definition_id` for 25H2. The workflow logs in with +`image_build_client_id`. Attach `image_build_identity_id` to the temporary VM. The guest bootstrap must use that managed identity to authenticate artifact downloads, with `image_build_identity_client_id` to select it. The GitHub login does not provide diff --git a/terraform/azure_foofrix/images.tf b/terraform/azure_foofrix/images.tf index 74d3e47c..ed995e92 100644 --- a/terraform/azure_foofrix/images.tf +++ b/terraform/azure_foofrix/images.tf @@ -73,6 +73,24 @@ resource "azurerm_shared_image" "windows" { } } +resource "azurerm_shared_image" "windows_25h2" { + name = "win11_64_25h2" + gallery_name = azurerm_shared_image_gallery.foofrix.name + resource_group_name = azurerm_resource_group.foofrix.name + location = local.location + os_type = "Windows" + architecture = "x64" + hyper_v_generation = "V2" + specialized = false + tags = local.common_tags + + identifier { + publisher = "MicrosoftWindowsDesktop" + offer = "Windows-11" + sku = "win11-25h2-avd" + } +} + data "azuread_service_principal" "foofrix_image_build" { display_name = "sp-foofrix-image-build" } diff --git a/terraform/azure_foofrix/outputs.tf b/terraform/azure_foofrix/outputs.tf index 04c7b84a..1977131d 100644 --- a/terraform/azure_foofrix/outputs.tf +++ b/terraform/azure_foofrix/outputs.tf @@ -38,6 +38,10 @@ output "windows_image_definition_id" { value = azurerm_shared_image.windows.id } +output "windows_25h2_image_definition_id" { + value = azurerm_shared_image.windows_25h2.id +} + output "image_build_client_id" { value = data.azuread_service_principal.foofrix_image_build.client_id } From 3198d2c4159bd65a5be624b8cf4c656da4a3cd4a Mon Sep 17 00:00:00 2001 From: Mark Cornmesser Date: Mon, 21 Sep 2026 09:59:49 -0700 Subject: [PATCH 3/6] Remove unused FooFrix West US 3 build group --- terraform/azure_foofrix/README.md | 3 +-- terraform/azure_foofrix/images.tf | 12 ++---------- terraform/azure_foofrix/outputs.tf | 2 +- terraform/azure_foofrix/tests/access.tftest.hcl | 13 ++----------- 4 files changed, 6 insertions(+), 24 deletions(-) diff --git a/terraform/azure_foofrix/README.md b/terraform/azure_foofrix/README.md index 5cd8df9a..9e6bafa4 100644 --- a/terraform/azure_foofrix/README.md +++ b/terraform/azure_foofrix/README.md @@ -62,8 +62,7 @@ The workflow needs `id-token: write` and audience `api://AzureADTokenExchange`. No image-build client secret is needed. Configure Packer to use the existing `image_build_resource_group` output for -temporary resources in West US 3. The original Central US build group is retained; -the gallery, storage, and identities remain in Central US. Publish to `image_gallery_name` in +temporary resources. Publish to `image_gallery_name` in `image_gallery_resource_group`, using `windows_image_definition_id` for 24H2 or `windows_25h2_image_definition_id` for 25H2. The workflow logs in with `image_build_client_id`. diff --git a/terraform/azure_foofrix/images.tf b/terraform/azure_foofrix/images.tf index ed995e92..c7e35edc 100644 --- a/terraform/azure_foofrix/images.tf +++ b/terraform/azure_foofrix/images.tf @@ -101,13 +101,6 @@ resource "azurerm_resource_group" "image_build" { tags = local.common_tags } -# Packer uses the build resource group's location for its temporary VM. -resource "azurerm_resource_group" "image_build_westus3" { - name = "rg-foofrix-image-build-westus3" - location = "westus3" - tags = local.common_tags -} - resource "azurerm_user_assigned_identity" "image_build" { name = "id-foofrix-image-build" resource_group_name = azurerm_resource_group.foofrix.name @@ -119,9 +112,8 @@ resource "azurerm_user_assigned_identity" "image_build" { resource "azurerm_role_assignment" "image_build_contributor" { for_each = { - build = azurerm_resource_group.image_build.id - build_westus3 = azurerm_resource_group.image_build_westus3.id - gallery = azurerm_shared_image_gallery.foofrix.id + build = azurerm_resource_group.image_build.id + gallery = azurerm_shared_image_gallery.foofrix.id } scope = each.value role_definition_name = "Contributor" diff --git a/terraform/azure_foofrix/outputs.tf b/terraform/azure_foofrix/outputs.tf index 1977131d..c114d7b4 100644 --- a/terraform/azure_foofrix/outputs.tf +++ b/terraform/azure_foofrix/outputs.tf @@ -47,7 +47,7 @@ output "image_build_client_id" { } output "image_build_resource_group" { - value = azurerm_resource_group.image_build_westus3.name + value = azurerm_resource_group.image_build.name } output "image_build_identity_id" { diff --git a/terraform/azure_foofrix/tests/access.tftest.hcl b/terraform/azure_foofrix/tests/access.tftest.hcl index 5e153b09..03bba726 100644 --- a/terraform/azure_foofrix/tests/access.tftest.hcl +++ b/terraform/azure_foofrix/tests/access.tftest.hcl @@ -12,12 +12,6 @@ override_resource { values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix-image-build" } } -override_resource { - target = azurerm_resource_group.image_build_westus3 - override_during = plan - values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix-image-build-westus3" } -} - override_resource { target = azurerm_shared_image_gallery.foofrix override_during = plan @@ -41,11 +35,8 @@ run "build_and_team_access" { assert { condition = ( - length(azurerm_role_assignment.image_build_contributor) == 3 && + length(azurerm_role_assignment.image_build_contributor) == 2 && azurerm_role_assignment.image_build_contributor["build"].scope == azurerm_resource_group.image_build.id && - azurerm_resource_group.image_build_westus3.location == "westus3" && - output.image_build_resource_group == azurerm_resource_group.image_build_westus3.name && - azurerm_role_assignment.image_build_contributor["build_westus3"].scope == azurerm_resource_group.image_build_westus3.id && azurerm_role_assignment.image_build_contributor["gallery"].scope == azurerm_shared_image_gallery.foofrix.id && azurerm_role_assignment.image_build_identity_operator.scope == azurerm_user_assigned_identity.image_build.id && alltrue([for grant in azurerm_role_assignment.image_build_blob_reader : grant.scope == azurerm_storage_container.artifacts.id]) && @@ -54,7 +45,7 @@ run "build_and_team_access" { length(azurerm_role_assignment.image_build_blob_reader) == 2 && azurerm_role_assignment.image_build_identity_operator.role_definition_name == "Managed Identity Operator" ) - error_message = "The builder needs three Contributor grants, identity attachment, and read access for both build identities." + error_message = "The builder needs two Contributor grants, identity attachment, and read access for both build identities." } assert { From 83c855c0572002b2f0c161a0215d9691496dc9d1 Mon Sep 17 00:00:00 2001 From: Mark Cornmesser Date: Mon, 21 Sep 2026 10:11:46 -0700 Subject: [PATCH 4/6] Use a dedicated gallery for FooFrix 25H2 --- terraform/azure_foofrix/README.md | 11 +++--- terraform/azure_foofrix/images.tf | 34 +++++++++++++------ terraform/azure_foofrix/outputs.tf | 8 +++++ .../azure_foofrix/tests/access.tftest.hcl | 12 +++++-- 4 files changed, 47 insertions(+), 18 deletions(-) diff --git a/terraform/azure_foofrix/README.md b/terraform/azure_foofrix/README.md index 9e6bafa4..147b83ef 100644 --- a/terraform/azure_foofrix/README.md +++ b/terraform/azure_foofrix/README.md @@ -14,8 +14,8 @@ The harness source and image provisioning scripts are in This Terraform stack manages the subscription, a resource group in Central US, a Key Vault available for Windows worker secrets, and a managed identity for the VMs. -Terraform manages the `foofrix` Compute Gallery and its `win11_64_24h2` and -`win11_64_25h2` image definitions. They use the existing FXCI properties: +Terraform manages the `foofrix` Compute Gallery for `win11_64_24h2` and a +dedicated `win11_64_25h2` gallery and image definition. They use the existing FXCI properties: Windows, x64, Hyper-V V2, generalized, and the matching 24H2 or 25H2 AVD SKU. The worker-images workflow publishes image versions. A private `artifacts` Blob Storage container holds Azure build and image files in Standard LRS storage. @@ -28,7 +28,7 @@ service principal are managed in `../azure_ad/foofrix.tf`. | `sp-foofrix-azure-devtest` | Subscription Contributor; Key Vault Secrets Officer; blob read/write | | `id-foofrix-worker` | Read vault secrets; blob read/write | | Platform Performance | Subscription Contributor; Key Vault Secrets Officer; blob read/write | -| `sp-foofrix-image-build` | Contributor on the build resource group and gallery; blob read; attach the build identity | +| `sp-foofrix-image-build` | Contributor on the build resource group and galleries; blob read; attach the build identity | | `id-foofrix-image-build` | Blob read during image creation | The GCP launcher uses a tenant ID, client ID, and client secret to @@ -63,8 +63,9 @@ No image-build client secret is needed. Configure Packer to use the existing `image_build_resource_group` output for temporary resources. Publish to `image_gallery_name` in -`image_gallery_resource_group`, using `windows_image_definition_id` for 24H2 or -`windows_25h2_image_definition_id` for 25H2. The workflow logs in with +`image_gallery_resource_group`, using `windows_image_definition_id` for 24H2. +For 25H2, use `windows_25h2_image_gallery_name` and +`windows_25h2_image_definition_id`. The workflow logs in with `image_build_client_id`. Attach `image_build_identity_id` to the temporary VM. The guest bootstrap must use that managed identity to authenticate artifact downloads, with diff --git a/terraform/azure_foofrix/images.tf b/terraform/azure_foofrix/images.tf index c7e35edc..2b5c8f0e 100644 --- a/terraform/azure_foofrix/images.tf +++ b/terraform/azure_foofrix/images.tf @@ -8,6 +8,16 @@ resource "azurerm_shared_image_gallery" "foofrix" { depends_on = [azurerm_resource_provider_registration.this["Microsoft.Compute"]] } +resource "azurerm_shared_image_gallery" "windows_25h2" { + name = "win11_64_25h2" + resource_group_name = azurerm_resource_group.foofrix.name + location = local.location + description = "Shared Image Gallery for win11-25h2-avd" + tags = local.common_tags + + depends_on = [azurerm_resource_provider_registration.this["Microsoft.Compute"]] +} + resource "azurerm_storage_account" "foofrix" { name = "safoofrix${substr(azurerm_subscription.foofrix.subscription_id, 0, 8)}" resource_group_name = azurerm_resource_group.foofrix.name @@ -74,15 +84,16 @@ resource "azurerm_shared_image" "windows" { } resource "azurerm_shared_image" "windows_25h2" { - name = "win11_64_25h2" - gallery_name = azurerm_shared_image_gallery.foofrix.name - resource_group_name = azurerm_resource_group.foofrix.name - location = local.location - os_type = "Windows" - architecture = "x64" - hyper_v_generation = "V2" - specialized = false - tags = local.common_tags + name = "win11_64_25h2" + gallery_name = azurerm_shared_image_gallery.windows_25h2.name + resource_group_name = azurerm_resource_group.foofrix.name + location = local.location + os_type = "Windows" + release_note_uri = "https://github.com/mozilla-platform-ops/worker-images/releases" + hyper_v_generation = "V2" + architecture = "x64" + disk_controller_type_nvme_enabled = true + tags = local.common_tags identifier { publisher = "MicrosoftWindowsDesktop" @@ -112,8 +123,9 @@ resource "azurerm_user_assigned_identity" "image_build" { resource "azurerm_role_assignment" "image_build_contributor" { for_each = { - build = azurerm_resource_group.image_build.id - gallery = azurerm_shared_image_gallery.foofrix.id + build = azurerm_resource_group.image_build.id + gallery = azurerm_shared_image_gallery.foofrix.id + gallery_25h2 = azurerm_shared_image_gallery.windows_25h2.id } scope = each.value role_definition_name = "Contributor" diff --git a/terraform/azure_foofrix/outputs.tf b/terraform/azure_foofrix/outputs.tf index c114d7b4..dec14ff8 100644 --- a/terraform/azure_foofrix/outputs.tf +++ b/terraform/azure_foofrix/outputs.tf @@ -42,6 +42,14 @@ output "windows_25h2_image_definition_id" { value = azurerm_shared_image.windows_25h2.id } +output "windows_25h2_image_gallery_id" { + value = azurerm_shared_image_gallery.windows_25h2.id +} + +output "windows_25h2_image_gallery_name" { + value = azurerm_shared_image_gallery.windows_25h2.name +} + output "image_build_client_id" { value = data.azuread_service_principal.foofrix_image_build.client_id } diff --git a/terraform/azure_foofrix/tests/access.tftest.hcl b/terraform/azure_foofrix/tests/access.tftest.hcl index 03bba726..4d9042f3 100644 --- a/terraform/azure_foofrix/tests/access.tftest.hcl +++ b/terraform/azure_foofrix/tests/access.tftest.hcl @@ -18,6 +18,12 @@ override_resource { values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix/providers/Microsoft.Compute/galleries/foofrix" } } +override_resource { + target = azurerm_shared_image_gallery.windows_25h2 + override_during = plan + values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix/providers/Microsoft.Compute/galleries/win11_64_25h2" } +} + override_resource { target = azurerm_user_assigned_identity.image_build override_during = plan @@ -35,9 +41,11 @@ run "build_and_team_access" { assert { condition = ( - length(azurerm_role_assignment.image_build_contributor) == 2 && + length(azurerm_role_assignment.image_build_contributor) == 3 && azurerm_role_assignment.image_build_contributor["build"].scope == azurerm_resource_group.image_build.id && azurerm_role_assignment.image_build_contributor["gallery"].scope == azurerm_shared_image_gallery.foofrix.id && + azurerm_role_assignment.image_build_contributor["gallery_25h2"].scope == azurerm_shared_image_gallery.windows_25h2.id && + azurerm_shared_image.windows_25h2.disk_controller_type_nvme_enabled && azurerm_role_assignment.image_build_identity_operator.scope == azurerm_user_assigned_identity.image_build.id && alltrue([for grant in azurerm_role_assignment.image_build_blob_reader : grant.scope == azurerm_storage_container.artifacts.id]) && alltrue([for grant in azurerm_role_assignment.image_build_contributor : grant.role_definition_name == "Contributor"]) && @@ -45,7 +53,7 @@ run "build_and_team_access" { length(azurerm_role_assignment.image_build_blob_reader) == 2 && azurerm_role_assignment.image_build_identity_operator.role_definition_name == "Managed Identity Operator" ) - error_message = "The builder needs two Contributor grants, identity attachment, and read access for both build identities." + error_message = "The builder needs three Contributor grants, identity attachment, and read access for both build identities." } assert { From 06bd8e3ae633c0cb1e4a5827d71e725777be6637 Mon Sep 17 00:00:00 2001 From: Jonathan Moss Date: Mon, 21 Sep 2026 13:20:08 -0400 Subject: [PATCH 5/6] RELOPS-2548: Share FooFrix image resource definitions --- terraform/azure_foofrix/images.tf | 68 +++++++++---------- terraform/azure_foofrix/moved.tf | 21 ++++++ terraform/azure_foofrix/outputs.tf | 12 ++-- .../azure_foofrix/tests/access.tftest.hcl | 22 ++++-- 4 files changed, 75 insertions(+), 48 deletions(-) create mode 100644 terraform/azure_foofrix/moved.tf diff --git a/terraform/azure_foofrix/images.tf b/terraform/azure_foofrix/images.tf index 2b5c8f0e..677489cd 100644 --- a/terraform/azure_foofrix/images.tf +++ b/terraform/azure_foofrix/images.tf @@ -1,18 +1,28 @@ -resource "azurerm_shared_image_gallery" "foofrix" { - name = "foofrix" - resource_group_name = azurerm_resource_group.foofrix.name - location = local.location - description = "Windows images for FooFrix performance agents." - tags = local.common_tags - - depends_on = [azurerm_resource_provider_registration.this["Microsoft.Compute"]] +locals { + shared_images = { + win11_64_24h2 = { + gallery_name = "foofrix" + gallery_description = "Windows images for FooFrix performance agents." + sku = "win11-24h2-avd" + nvme_enabled = false + release_note_uri = null + } + win11_64_25h2 = { + gallery_name = "win11_64_25h2" + gallery_description = "Shared Image Gallery for win11-25h2-avd" + sku = "win11-25h2-avd" + nvme_enabled = true + release_note_uri = "https://github.com/mozilla-platform-ops/worker-images/releases" + } + } } -resource "azurerm_shared_image_gallery" "windows_25h2" { - name = "win11_64_25h2" +resource "azurerm_shared_image_gallery" "this" { + for_each = local.shared_images + name = each.value.gallery_name resource_group_name = azurerm_resource_group.foofrix.name location = local.location - description = "Shared Image Gallery for win11-25h2-avd" + description = each.value.gallery_description tags = local.common_tags depends_on = [azurerm_resource_provider_registration.this["Microsoft.Compute"]] @@ -65,40 +75,24 @@ resource "azurerm_role_assignment" "blob_contributor" { skip_service_principal_aad_check = each.value.type == "ServicePrincipal" } -resource "azurerm_shared_image" "windows" { - name = "win11_64_24h2" - gallery_name = azurerm_shared_image_gallery.foofrix.name - resource_group_name = azurerm_resource_group.foofrix.name - location = local.location - os_type = "Windows" - architecture = "x64" - hyper_v_generation = "V2" - specialized = false - tags = local.common_tags - - identifier { - publisher = "MicrosoftWindowsDesktop" - offer = "Windows-11" - sku = "win11-24h2-avd" - } -} - -resource "azurerm_shared_image" "windows_25h2" { - name = "win11_64_25h2" - gallery_name = azurerm_shared_image_gallery.windows_25h2.name +resource "azurerm_shared_image" "this" { + for_each = local.shared_images + name = each.key + gallery_name = azurerm_shared_image_gallery.this[each.key].name resource_group_name = azurerm_resource_group.foofrix.name location = local.location os_type = "Windows" - release_note_uri = "https://github.com/mozilla-platform-ops/worker-images/releases" + release_note_uri = each.value.release_note_uri hyper_v_generation = "V2" architecture = "x64" - disk_controller_type_nvme_enabled = true + specialized = false + disk_controller_type_nvme_enabled = each.value.nvme_enabled tags = local.common_tags identifier { publisher = "MicrosoftWindowsDesktop" offer = "Windows-11" - sku = "win11-25h2-avd" + sku = each.value.sku } } @@ -124,8 +118,8 @@ resource "azurerm_user_assigned_identity" "image_build" { resource "azurerm_role_assignment" "image_build_contributor" { for_each = { build = azurerm_resource_group.image_build.id - gallery = azurerm_shared_image_gallery.foofrix.id - gallery_25h2 = azurerm_shared_image_gallery.windows_25h2.id + gallery = azurerm_shared_image_gallery.this["win11_64_24h2"].id + gallery_25h2 = azurerm_shared_image_gallery.this["win11_64_25h2"].id } scope = each.value role_definition_name = "Contributor" diff --git a/terraform/azure_foofrix/moved.tf b/terraform/azure_foofrix/moved.tf new file mode 100644 index 00000000..3e41e174 --- /dev/null +++ b/terraform/azure_foofrix/moved.tf @@ -0,0 +1,21 @@ +# Keep the existing galleries and image definitions when their addresses change. + +moved { + from = azurerm_shared_image_gallery.foofrix + to = azurerm_shared_image_gallery.this["win11_64_24h2"] +} + +moved { + from = azurerm_shared_image_gallery.windows_25h2 + to = azurerm_shared_image_gallery.this["win11_64_25h2"] +} + +moved { + from = azurerm_shared_image.windows_25h2 + to = azurerm_shared_image.this["win11_64_25h2"] +} + +moved { + from = azurerm_shared_image.windows + to = azurerm_shared_image.this["win11_64_24h2"] +} diff --git a/terraform/azure_foofrix/outputs.tf b/terraform/azure_foofrix/outputs.tf index dec14ff8..cd74b944 100644 --- a/terraform/azure_foofrix/outputs.tf +++ b/terraform/azure_foofrix/outputs.tf @@ -19,7 +19,7 @@ output "key_vault_uri" { } output "image_gallery_id" { - value = azurerm_shared_image_gallery.foofrix.id + value = azurerm_shared_image_gallery.this["win11_64_24h2"].id } output "artifacts_container_url" { @@ -27,7 +27,7 @@ output "artifacts_container_url" { } output "image_gallery_name" { - value = azurerm_shared_image_gallery.foofrix.name + value = azurerm_shared_image_gallery.this["win11_64_24h2"].name } output "image_gallery_resource_group" { @@ -35,19 +35,19 @@ output "image_gallery_resource_group" { } output "windows_image_definition_id" { - value = azurerm_shared_image.windows.id + value = azurerm_shared_image.this["win11_64_24h2"].id } output "windows_25h2_image_definition_id" { - value = azurerm_shared_image.windows_25h2.id + value = azurerm_shared_image.this["win11_64_25h2"].id } output "windows_25h2_image_gallery_id" { - value = azurerm_shared_image_gallery.windows_25h2.id + value = azurerm_shared_image_gallery.this["win11_64_25h2"].id } output "windows_25h2_image_gallery_name" { - value = azurerm_shared_image_gallery.windows_25h2.name + value = azurerm_shared_image_gallery.this["win11_64_25h2"].name } output "image_build_client_id" { diff --git a/terraform/azure_foofrix/tests/access.tftest.hcl b/terraform/azure_foofrix/tests/access.tftest.hcl index 4d9042f3..4ae22afa 100644 --- a/terraform/azure_foofrix/tests/access.tftest.hcl +++ b/terraform/azure_foofrix/tests/access.tftest.hcl @@ -13,13 +13,13 @@ override_resource { } override_resource { - target = azurerm_shared_image_gallery.foofrix + target = azurerm_shared_image_gallery.this["win11_64_24h2"] override_during = plan values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix/providers/Microsoft.Compute/galleries/foofrix" } } override_resource { - target = azurerm_shared_image_gallery.windows_25h2 + target = azurerm_shared_image_gallery.this["win11_64_25h2"] override_during = plan values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix/providers/Microsoft.Compute/galleries/win11_64_25h2" } } @@ -39,13 +39,25 @@ override_resource { run "build_and_team_access" { command = plan + assert { + condition = ( + azurerm_shared_image_gallery.this["win11_64_24h2"].name == "foofrix" && + azurerm_shared_image_gallery.this["win11_64_25h2"].name == "win11_64_25h2" && + !azurerm_shared_image.this["win11_64_24h2"].disk_controller_type_nvme_enabled && + azurerm_shared_image.this["win11_64_25h2"].disk_controller_type_nvme_enabled && + alltrue([for key, image in azurerm_shared_image.this : + image.name == key && image.gallery_name == azurerm_shared_image_gallery.this[key].name + ]) + ) + error_message = "Keep the existing gallery and image names, with NVMe enabled only for 25H2." + } + assert { condition = ( length(azurerm_role_assignment.image_build_contributor) == 3 && azurerm_role_assignment.image_build_contributor["build"].scope == azurerm_resource_group.image_build.id && - azurerm_role_assignment.image_build_contributor["gallery"].scope == azurerm_shared_image_gallery.foofrix.id && - azurerm_role_assignment.image_build_contributor["gallery_25h2"].scope == azurerm_shared_image_gallery.windows_25h2.id && - azurerm_shared_image.windows_25h2.disk_controller_type_nvme_enabled && + azurerm_role_assignment.image_build_contributor["gallery"].scope == azurerm_shared_image_gallery.this["win11_64_24h2"].id && + azurerm_role_assignment.image_build_contributor["gallery_25h2"].scope == azurerm_shared_image_gallery.this["win11_64_25h2"].id && azurerm_role_assignment.image_build_identity_operator.scope == azurerm_user_assigned_identity.image_build.id && alltrue([for grant in azurerm_role_assignment.image_build_blob_reader : grant.scope == azurerm_storage_container.artifacts.id]) && alltrue([for grant in azurerm_role_assignment.image_build_contributor : grant.role_definition_name == "Contributor"]) && From 35cf4a1e24ee7b72a11ec5e0e6ab0b993ddc0ee7 Mon Sep 17 00:00:00 2001 From: Jonathan Moss Date: Mon, 21 Sep 2026 13:21:11 -0400 Subject: [PATCH 6/6] Revert "RELOPS-2548: Share FooFrix image resource definitions" This reverts commit 06bd8e3ae633c0cb1e4a5827d71e725777be6637. --- terraform/azure_foofrix/images.tf | 68 ++++++++++--------- terraform/azure_foofrix/moved.tf | 21 ------ terraform/azure_foofrix/outputs.tf | 12 ++-- .../azure_foofrix/tests/access.tftest.hcl | 22 ++---- 4 files changed, 48 insertions(+), 75 deletions(-) delete mode 100644 terraform/azure_foofrix/moved.tf diff --git a/terraform/azure_foofrix/images.tf b/terraform/azure_foofrix/images.tf index 677489cd..2b5c8f0e 100644 --- a/terraform/azure_foofrix/images.tf +++ b/terraform/azure_foofrix/images.tf @@ -1,28 +1,18 @@ -locals { - shared_images = { - win11_64_24h2 = { - gallery_name = "foofrix" - gallery_description = "Windows images for FooFrix performance agents." - sku = "win11-24h2-avd" - nvme_enabled = false - release_note_uri = null - } - win11_64_25h2 = { - gallery_name = "win11_64_25h2" - gallery_description = "Shared Image Gallery for win11-25h2-avd" - sku = "win11-25h2-avd" - nvme_enabled = true - release_note_uri = "https://github.com/mozilla-platform-ops/worker-images/releases" - } - } +resource "azurerm_shared_image_gallery" "foofrix" { + name = "foofrix" + resource_group_name = azurerm_resource_group.foofrix.name + location = local.location + description = "Windows images for FooFrix performance agents." + tags = local.common_tags + + depends_on = [azurerm_resource_provider_registration.this["Microsoft.Compute"]] } -resource "azurerm_shared_image_gallery" "this" { - for_each = local.shared_images - name = each.value.gallery_name +resource "azurerm_shared_image_gallery" "windows_25h2" { + name = "win11_64_25h2" resource_group_name = azurerm_resource_group.foofrix.name location = local.location - description = each.value.gallery_description + description = "Shared Image Gallery for win11-25h2-avd" tags = local.common_tags depends_on = [azurerm_resource_provider_registration.this["Microsoft.Compute"]] @@ -75,24 +65,40 @@ resource "azurerm_role_assignment" "blob_contributor" { skip_service_principal_aad_check = each.value.type == "ServicePrincipal" } -resource "azurerm_shared_image" "this" { - for_each = local.shared_images - name = each.key - gallery_name = azurerm_shared_image_gallery.this[each.key].name +resource "azurerm_shared_image" "windows" { + name = "win11_64_24h2" + gallery_name = azurerm_shared_image_gallery.foofrix.name + resource_group_name = azurerm_resource_group.foofrix.name + location = local.location + os_type = "Windows" + architecture = "x64" + hyper_v_generation = "V2" + specialized = false + tags = local.common_tags + + identifier { + publisher = "MicrosoftWindowsDesktop" + offer = "Windows-11" + sku = "win11-24h2-avd" + } +} + +resource "azurerm_shared_image" "windows_25h2" { + name = "win11_64_25h2" + gallery_name = azurerm_shared_image_gallery.windows_25h2.name resource_group_name = azurerm_resource_group.foofrix.name location = local.location os_type = "Windows" - release_note_uri = each.value.release_note_uri + release_note_uri = "https://github.com/mozilla-platform-ops/worker-images/releases" hyper_v_generation = "V2" architecture = "x64" - specialized = false - disk_controller_type_nvme_enabled = each.value.nvme_enabled + disk_controller_type_nvme_enabled = true tags = local.common_tags identifier { publisher = "MicrosoftWindowsDesktop" offer = "Windows-11" - sku = each.value.sku + sku = "win11-25h2-avd" } } @@ -118,8 +124,8 @@ resource "azurerm_user_assigned_identity" "image_build" { resource "azurerm_role_assignment" "image_build_contributor" { for_each = { build = azurerm_resource_group.image_build.id - gallery = azurerm_shared_image_gallery.this["win11_64_24h2"].id - gallery_25h2 = azurerm_shared_image_gallery.this["win11_64_25h2"].id + gallery = azurerm_shared_image_gallery.foofrix.id + gallery_25h2 = azurerm_shared_image_gallery.windows_25h2.id } scope = each.value role_definition_name = "Contributor" diff --git a/terraform/azure_foofrix/moved.tf b/terraform/azure_foofrix/moved.tf deleted file mode 100644 index 3e41e174..00000000 --- a/terraform/azure_foofrix/moved.tf +++ /dev/null @@ -1,21 +0,0 @@ -# Keep the existing galleries and image definitions when their addresses change. - -moved { - from = azurerm_shared_image_gallery.foofrix - to = azurerm_shared_image_gallery.this["win11_64_24h2"] -} - -moved { - from = azurerm_shared_image_gallery.windows_25h2 - to = azurerm_shared_image_gallery.this["win11_64_25h2"] -} - -moved { - from = azurerm_shared_image.windows_25h2 - to = azurerm_shared_image.this["win11_64_25h2"] -} - -moved { - from = azurerm_shared_image.windows - to = azurerm_shared_image.this["win11_64_24h2"] -} diff --git a/terraform/azure_foofrix/outputs.tf b/terraform/azure_foofrix/outputs.tf index cd74b944..dec14ff8 100644 --- a/terraform/azure_foofrix/outputs.tf +++ b/terraform/azure_foofrix/outputs.tf @@ -19,7 +19,7 @@ output "key_vault_uri" { } output "image_gallery_id" { - value = azurerm_shared_image_gallery.this["win11_64_24h2"].id + value = azurerm_shared_image_gallery.foofrix.id } output "artifacts_container_url" { @@ -27,7 +27,7 @@ output "artifacts_container_url" { } output "image_gallery_name" { - value = azurerm_shared_image_gallery.this["win11_64_24h2"].name + value = azurerm_shared_image_gallery.foofrix.name } output "image_gallery_resource_group" { @@ -35,19 +35,19 @@ output "image_gallery_resource_group" { } output "windows_image_definition_id" { - value = azurerm_shared_image.this["win11_64_24h2"].id + value = azurerm_shared_image.windows.id } output "windows_25h2_image_definition_id" { - value = azurerm_shared_image.this["win11_64_25h2"].id + value = azurerm_shared_image.windows_25h2.id } output "windows_25h2_image_gallery_id" { - value = azurerm_shared_image_gallery.this["win11_64_25h2"].id + value = azurerm_shared_image_gallery.windows_25h2.id } output "windows_25h2_image_gallery_name" { - value = azurerm_shared_image_gallery.this["win11_64_25h2"].name + value = azurerm_shared_image_gallery.windows_25h2.name } output "image_build_client_id" { diff --git a/terraform/azure_foofrix/tests/access.tftest.hcl b/terraform/azure_foofrix/tests/access.tftest.hcl index 4ae22afa..4d9042f3 100644 --- a/terraform/azure_foofrix/tests/access.tftest.hcl +++ b/terraform/azure_foofrix/tests/access.tftest.hcl @@ -13,13 +13,13 @@ override_resource { } override_resource { - target = azurerm_shared_image_gallery.this["win11_64_24h2"] + target = azurerm_shared_image_gallery.foofrix override_during = plan values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix/providers/Microsoft.Compute/galleries/foofrix" } } override_resource { - target = azurerm_shared_image_gallery.this["win11_64_25h2"] + target = azurerm_shared_image_gallery.windows_25h2 override_during = plan values = { id = "/subscriptions/00000000-0000-0000-0000-000000000001/resourceGroups/rg-foofrix/providers/Microsoft.Compute/galleries/win11_64_25h2" } } @@ -39,25 +39,13 @@ override_resource { run "build_and_team_access" { command = plan - assert { - condition = ( - azurerm_shared_image_gallery.this["win11_64_24h2"].name == "foofrix" && - azurerm_shared_image_gallery.this["win11_64_25h2"].name == "win11_64_25h2" && - !azurerm_shared_image.this["win11_64_24h2"].disk_controller_type_nvme_enabled && - azurerm_shared_image.this["win11_64_25h2"].disk_controller_type_nvme_enabled && - alltrue([for key, image in azurerm_shared_image.this : - image.name == key && image.gallery_name == azurerm_shared_image_gallery.this[key].name - ]) - ) - error_message = "Keep the existing gallery and image names, with NVMe enabled only for 25H2." - } - assert { condition = ( length(azurerm_role_assignment.image_build_contributor) == 3 && azurerm_role_assignment.image_build_contributor["build"].scope == azurerm_resource_group.image_build.id && - azurerm_role_assignment.image_build_contributor["gallery"].scope == azurerm_shared_image_gallery.this["win11_64_24h2"].id && - azurerm_role_assignment.image_build_contributor["gallery_25h2"].scope == azurerm_shared_image_gallery.this["win11_64_25h2"].id && + azurerm_role_assignment.image_build_contributor["gallery"].scope == azurerm_shared_image_gallery.foofrix.id && + azurerm_role_assignment.image_build_contributor["gallery_25h2"].scope == azurerm_shared_image_gallery.windows_25h2.id && + azurerm_shared_image.windows_25h2.disk_controller_type_nvme_enabled && azurerm_role_assignment.image_build_identity_operator.scope == azurerm_user_assigned_identity.image_build.id && alltrue([for grant in azurerm_role_assignment.image_build_blob_reader : grant.scope == azurerm_storage_container.artifacts.id]) && alltrue([for grant in azurerm_role_assignment.image_build_contributor : grant.role_definition_name == "Contributor"]) &&