Skip to content

feat(azure-devops): add optional bot PAT + username for the resolver - #1161

Draft
ak684 wants to merge 2 commits into
mainfrom
alona/ado-bot-kots-v2
Draft

ak684 wants to merge 2 commits into
mainfrom
alona/ado-bot-kots-v2

Conversation

@ak684

@ak684 ak684 commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Stacked on #1160. Draft until OpenHands/enterprise#257 (bot posting support) merges and the enterprise pin includes it; before that these fields would be dead config.

What

Optional KOTS fields under Azure DevOps Authentication:

  • azure_devops_bot_token (password) → azure-devops-app/bot-token → AZURE_DEVOPS_BOT_TOKEN (checksummed, support-bundle redacted)
  • azure_devops_bot_username (text) → azureDevOps.botUsername → AZURE_DEVOPS_BOT_USERNAME

When set, the resolver posts replies as the bot account and skips the bot's own comments. Unset = current run-as-mentioner behavior. Mirrors the Bitbucket DC bot_token / bot_username pair.

Validation

helm lint both charts; helm template renders both envs; check_secret_checksum.py OK (43/43). Live validation on a Replicated test install tracked in the same report as #1160.

…nd KOTS config

The Azure DevOps resolver (enterprise >=1.48) requires AZURE_DEVOPS_WEBHOOK_SECRET
to verify service hooks and to install them from Settings > Git. The env was
never wired, so installs show "Missing secret" and the Install button 503s.

- KOTS: hidden, generated azure_devops_webhook_secret (RandomString), added to
  secretsChecksum so a change rolls the pod
- openhands-secrets: webhook-secret key on the azure-devops-app Secret
- openhands: AZURE_DEVOPS_WEBHOOK_SECRET from that Secret (optional, so
  existing secrets without the key still deploy); support-bundle redaction
@github-actions github-actions Bot added the type: feat A new feature label Aug 26, 2026
Optional KOTS fields azure_devops_bot_token / azure_devops_bot_username, wired
to AZURE_DEVOPS_BOT_TOKEN (azure-devops-app/bot-token, checksummed) and
AZURE_DEVOPS_BOT_USERNAME on the openhands deployment. When set, the resolver
posts replies as the bot and ignores the bot's own comments.
Base automatically changed from alona/ado-webhook-secret-kots to main August 26, 2026 18:48

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: feat A new feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant