Description
Add Connector Namespace trigger and event-subscription support after #19024 lands the connection and managed MCP foundation.
Trigger provisioning needs explicit lifecycle reconciliation rather than independent incremental child deployments:
- Persist the deployed trigger identities for each Connector Namespace.
- Delete trigger children that were removed or renamed in the AppHost.
- Reconcile even when the desired trigger set becomes empty.
- Define retry, partial-failure, and concurrent-deployment behavior.
- Snapshot mutable trigger input DTOs before deferred provisioning.
- Preserve managed-identity delivery to non-anonymous sandbox callback ports without broadening sandbox data-plane permissions.
Deployment coverage
Add an opt-in deployment end-to-end test that deploys a sandbox callback endpoint and Connector Namespace trigger, then verifies:
- ADC accepts the
OnDemand port authorization request with the Connector Namespace managed identity in the Microsoft Entra allow-list.
- Anonymous requests to the callback port are rejected.
- Requests authenticated as the Connector Namespace managed identity are accepted.
- Removing and renaming a trigger deletes the previous Azure child resource.
- Removing the final trigger leaves no stale active subscription.
The deployment-test environment must support the preview Connector Namespace and Azure Dev Compute APIs and expose any required provider registration or feature flags. The test does not need to complete downstream connector OAuth consent.
Related
Description
Add Connector Namespace trigger and event-subscription support after #19024 lands the connection and managed MCP foundation.
Trigger provisioning needs explicit lifecycle reconciliation rather than independent incremental child deployments:
Deployment coverage
Add an opt-in deployment end-to-end test that deploys a sandbox callback endpoint and Connector Namespace trigger, then verifies:
OnDemandport authorization request with the Connector Namespace managed identity in the Microsoft Entra allow-list.The deployment-test environment must support the preview Connector Namespace and Azure Dev Compute APIs and expose any required provider registration or feature flags. The test does not need to complete downstream connector OAuth consent.
Related