Skip to content

Enable DefaultDeny network isolation for CI - #10850

Merged
ReubenBond merged 1 commit into
dotnet:mainfrom
ReubenBond:sfi-es4.2.4/default-deny
Aug 27, 2026
Merged

ReubenBond merged 1 commit into
dotnet:mainfrom
ReubenBond:sfi-es4.2.4/default-deny

Conversation

@ReubenBond

@ReubenBond ReubenBond commented Aug 27, 2026 •

Copy link
Copy Markdown
Member

Configure the Orleans Azure DevOps CI pipeline to use the DefaultDeny network isolation policy, as required by SFI-ES4.2.4.

Microsoft Reviewers: Open in CodeFlow

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings August 27, 2026 20:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

Review tier: Lite
Findings: None

What changed in this PR

This PR updates the Orleans Azure DevOps pipeline configuration to enable the DefaultDeny network isolation policy, aligning CI execution with the SFI-ES4.2.4 requirement.

Changes:

  • Set settings.networkIsolationPolicy to DefaultDeny in the 1ES pipeline template parameters.
File Description
.azure/​pipelines/​build.yaml Enables DefaultDeny network isolation via 1ES pipeline settings parameters for CI runs.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@ReubenBond
ReubenBond merged commit 7967e90 into dotnet:main Aug 27, 2026
70 of 72 checks passed
@ReubenBond
ReubenBond deleted the sfi-es4.2.4/default-deny branch August 27, 2026 20:36
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 27, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants