Is there an existing issue for this?
Related issues:
Is your feature request related to a problem? Please describe the problem.
Third-party integrations sometimes need to replace Aspire's default Kubernetes configuration/secret emission with a target-native or external mechanism such as Consul Template, External Secrets, or another secret agent.
A concrete example is a connection string containing both:
- Kubernetes endpoint values that must be translated to the target service DNS name and port.
- Secret values that should be emitted as Consul Template expressions instead of a Kubernetes
Secret and Helm values references.
The integration needs a supported point where deployment-target values have been translated, but the generated Kubernetes objects have not yet been serialized to disk.
PublishAsKubernetesService(...) is currently the closest public API. The implementation invokes it after KubernetesResource.ProcessResourceAsync(...) has processed endpoints, environment variables, arguments, ConfigMaps, and Secrets, and before WriteKubernetesTemplatesForResource(...) serializes them. However, that timing and the state of the generated model are not documented as a compatibility contract.
WellKnownPipelineSteps.PublishPrereq does provide stable pipeline ordering before publisher steps. The Kubernetes publish-{environment} step depends on it, so a custom step that is requiredBy PublishPrereq can run before serialization. If the custom step also depends on WellKnownPipelineSteps.ProcessParameters, it can run after parameter processing. A step that instead depends on PublishPrereq is only a sibling of the Kubernetes publisher and may run concurrently with it.
That solves the basic ordering problem, but the customizer still receives the already-flattened generated model. For example, connection strings are available through Secret.StringData as strings containing Kubernetes/Helm expressions. There is no public API to translate an arbitrary ReferenceExpression using the Kubernetes publisher's endpoint and port allocation rules while preserving structured secret references. IComputeEnvironmentResource.GetHostAddressExpression(...) and GetEndpointPropertyExpression(...) help with individual endpoint properties, but do not replace the publisher's complete value translation.
As a result, integrations still have to parse and rewrite flattened Helm expressions or reimplement Kubernetes endpoint and connection-string translation.
Describe the solution you'd like
- Document the lifecycle and guarantees of
PublishAsKubernetesService(...), including whether it is guaranteed to run after target value translation and immediately before serialization.
- Document the
ProcessParameters -> custom step -> PublishPrereq ordering pattern for integrations that need an async, service-aware pre-publish operation.
- Provide an async, typed pre-serialization customization context that exposes the source resource, generated Kubernetes resource, services/model, cancellation token, and structured target-translated environment/secret values.
- Allow customizers to suppress or replace Aspire's default ConfigMap/Secret generation without manually repairing workload references.
- Expose a supported helper for translating a
ReferenceExpression through the selected compute environment while preserving parameters and secret references.
A documented example that replaces a generated Kubernetes Secret with an external secret/template provider would validate the API end to end.
Additional context
The existing PublishAsKubernetesService(...) callback and WellKnownPipelineSteps.PublishPrereq may already be the right foundation. The main gaps are their documented timing/contracts, access to structured translated values before they are flattened, and a supported way to replace default secret/config emission.
Is there an existing issue for this?
Related issues:
prepare-deployment-targets-{environment}step is brittle.Is your feature request related to a problem? Please describe the problem.
Third-party integrations sometimes need to replace Aspire's default Kubernetes configuration/secret emission with a target-native or external mechanism such as Consul Template, External Secrets, or another secret agent.
A concrete example is a connection string containing both:
Secretand Helm values references.The integration needs a supported point where deployment-target values have been translated, but the generated Kubernetes objects have not yet been serialized to disk.
PublishAsKubernetesService(...)is currently the closest public API. The implementation invokes it afterKubernetesResource.ProcessResourceAsync(...)has processed endpoints, environment variables, arguments, ConfigMaps, and Secrets, and beforeWriteKubernetesTemplatesForResource(...)serializes them. However, that timing and the state of the generated model are not documented as a compatibility contract.WellKnownPipelineSteps.PublishPrereqdoes provide stable pipeline ordering before publisher steps. The Kubernetespublish-{environment}step depends on it, so a custom step that isrequiredByPublishPrereqcan run before serialization. If the custom step also depends onWellKnownPipelineSteps.ProcessParameters, it can run after parameter processing. A step that instead depends onPublishPrereqis only a sibling of the Kubernetes publisher and may run concurrently with it.That solves the basic ordering problem, but the customizer still receives the already-flattened generated model. For example, connection strings are available through
Secret.StringDataas strings containing Kubernetes/Helm expressions. There is no public API to translate an arbitraryReferenceExpressionusing the Kubernetes publisher's endpoint and port allocation rules while preserving structured secret references.IComputeEnvironmentResource.GetHostAddressExpression(...)andGetEndpointPropertyExpression(...)help with individual endpoint properties, but do not replace the publisher's complete value translation.As a result, integrations still have to parse and rewrite flattened Helm expressions or reimplement Kubernetes endpoint and connection-string translation.
Describe the solution you'd like
PublishAsKubernetesService(...), including whether it is guaranteed to run after target value translation and immediately before serialization.ProcessParameters-> custom step ->PublishPrereqordering pattern for integrations that need an async, service-aware pre-publish operation.ReferenceExpressionthrough the selected compute environment while preserving parameters and secret references.A documented example that replaces a generated Kubernetes Secret with an external secret/template provider would validate the API end to end.
Additional context
The existing
PublishAsKubernetesService(...)callback andWellKnownPipelineSteps.PublishPrereqmay already be the right foundation. The main gaps are their documented timing/contracts, access to structured translated values before they are flattened, and a supported way to replace default secret/config emission.