Repository navigation
docs: Update Azure DevOps integration #821
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
15 commits
Select commit
Hold shift + click to select a range
f7c77fb
docs: update Azure DevOps integration
warp-agent-staging[bot] bf39300
docs: clarify Azure DevOps automation credentials
warp-agent-staging[bot] 127d947
docs: add Azure DevOps identity troubleshooting
warp-agent-staging[bot] cfb0f07
docs: address Azure DevOps review feedback
warp-agent-staging[bot] a551a6b
docs: restore Azure DevOps automation prerequisite
warp-agent-staging[bot] 3726b8d
docs: restore Azure DevOps Server setup guidance
warp-agent-staging[bot] 6ed178b
Merge remote-tracking branch 'origin/main' into factory/update-azure-…
warp-agent-staging[bot] e01c3fc
docs: split Azure DevOps factory and cloud agent setup
warp-agent-staging[bot] acfc670
docs: align standalone Azure DevOps setup style
warp-agent-staging[bot] 259d895
docs: prevent wrapped Azure DevOps auth headers
warp-agent-staging[bot] fe3fa25
docs: clarify Azure DevOps troubleshooting
warp-agent-staging[bot] c173ff2
ci: retry cancelled CodeQL checks
warp-agent-staging[bot] 6851db6
docs: address final Azure DevOps feedback
warp-agent-staging[bot] 8caa5ba
docs: tighten Azure DevOps guidance
warp-agent-staging[bot] 3b957b1
docs: finalize Azure DevOps copy
warp-agent-staging[bot] File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
151 changes: 151 additions & 0 deletions
151
src/content/docs/factories/integrations/azure-devops.mdx
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,151 @@ | ||
| --- | ||
| title: Connect Azure DevOps to your factory | ||
| sidebar: | ||
| label: "Azure DevOps" | ||
| description: >- | ||
| Connect Azure DevOps Services to a factory with dedicated identities, | ||
| repository access, and event-driven automations. | ||
| --- | ||
| import { VARS } from '@data/vars'; | ||
|
|
||
| Connect Azure DevOps Services to a factory so agents can work in selected repositories, open pull requests, and start runs from work item and pull request events. Warp creates a dedicated Microsoft Entra identity for each factory's Git and pull request operations. | ||
|
|
||
| {/* VERIFY: Confirm first-class Azure DevOps Services support is enabled in production before merging this documentation. */} | ||
|
|
||
| :::note | ||
| Warp Factories is in Early Access and available to a limited set of teams. [Request access](https://www.warp.dev/factories/request-access) to use it with your team. | ||
| ::: | ||
|
|
||
| The first-class integration supports hosted Azure DevOps Services at `dev.azure.com`. It doesn't support Azure DevOps Server. To use a self-hosted Azure DevOps Server repository, [configure it as another code forge](/factories/code-forges/other-code-forges/). For standalone cloud agent environments, use the [Azure DevOps access token setup](/platform/integrations/azure-devops/). | ||
|
|
||
| ## How identities and access work | ||
|
|
||
| Your personal Azure DevOps OAuth connection limits what appears during setup. The Azure DevOps Manager creates and manages each factory identity. | ||
|
|
||
| | Identity | Purpose | Access | | ||
| | --- | --- | --- | | ||
| | Your connected Azure DevOps account | Lists resources during setup and supplies your identity for creator-based runs. | Limited to resources your Azure DevOps user can read. | | ||
| | Azure DevOps Manager | Creates and maintains factory identities in one Microsoft Entra tenant and Azure DevOps organization. | Has Basic access and belongs to Project Collection Administrators. | | ||
| | Factory identity | Authenticates the factory's Git and pull request operations after a run starts. | Has Basic access and permissions on the selected repositories. | | ||
|
|
||
| Each factory identity consists of a separate Microsoft Entra application and service principal that Warp adds to Azure DevOps. | ||
|
|
||
| ## Requirements | ||
|
|
||
| * **A Warp team with Warp Factories access** - A factory belongs to a [Warp team](/knowledge-and-collaboration/teams/). | ||
| * **An Azure DevOps Services organization** - Use an organization hosted at `dev.azure.com`, with the project and repositories the factory needs. | ||
| * **A connected Azure DevOps user** - Connect a user who can read the organization, project, and repositories you want to select. | ||
| * **An active connection for each automation creator** - The user who creates an Azure DevOps automation must keep their own Azure DevOps OAuth connection active with the required scopes. | ||
| * **Microsoft Entra and Azure DevOps administrators** - Administrators with the roles listed below approve and add the Manager. | ||
|
|
||
| The Microsoft Entra and Azure DevOps approvals can be completed by different people. A setup link lets each administrator complete their step without a Warp account. | ||
|
|
||
| ### Required administrator permissions | ||
|
|
||
| | System | Administrator | What the administrator approves | | ||
| | --- | --- | --- | | ||
| | Microsoft Entra | Global Administrator or Privileged Role Administrator | The Manager's Microsoft Graph `Application.ReadWrite.OwnedBy` permission, limited to applications the Manager owns. | | ||
| | Azure DevOps | Project Collection Administrator | Basic access and Project Collection Administrators membership. Warp doesn't retain the administrator's sign-in. | | ||
|
|
||
| Reuse tenant approval for another Azure DevOps organization in the same Microsoft Entra tenant. Each organization requires Azure DevOps approval. | ||
|
|
||
| :::caution | ||
| The Manager and every factory identity use one Azure DevOps Basic seat each. Check available licenses before connecting an organization or adding factories. | ||
| ::: | ||
|
|
||
| ## Connect Azure DevOps | ||
|
|
||
| Start from factory setup to connect your account, select repositories, and provision the runtime identity. | ||
|
|
||
| 1. Sign in to the <a href={VARS.FACTORY_WEB_APP_URL}>{VARS.FACTORY_WEB_APP}</a>. Next to the factory list, click **+** to create a factory. | ||
| 2. In the code host step, find the Azure DevOps row and click **Connect**. Complete the Microsoft sign-in to connect your Azure DevOps user. | ||
| 3. Choose an Azure DevOps organization and project, then select the repositories the factory will use. Only resources your connected user can read appear. | ||
| 4. If the organization already has an active Azure DevOps Manager, continue setup. Otherwise, connect the Manager yourself or send the setup link to the required administrators. | ||
| 5. Complete the Manager approval in this order: | ||
| 1. A Global Administrator or Privileged Role Administrator completes the Microsoft Entra approval. | ||
| 2. A Project Collection Administrator completes the Azure DevOps approval. | ||
| 6. Continue factory setup. Warp creates the factory identity, adds Azure DevOps Basic access, and grants access to the selected repositories. Microsoft and Azure DevOps can take several minutes to apply these changes. | ||
|
|
||
| When setup confirms that the identity is ready, the factory uses that identity for Git and pull request operations. You can retry identity provisioning from the factory's settings if setup is interrupted. | ||
|
|
||
| ## Configure Azure DevOps automations | ||
|
|
||
| An Azure DevOps automation starts a factory run when a supported event matches its filters. Before starting a run, Warp checks the automation creator's Azure DevOps connection. New Azure DevOps factories include a default automation for pull request mentions, work item mentions, and work item assignments. | ||
|
|
||
| To configure an automation as code, ask the Warp Agent to update the factory definition or edit its `automations/` files directly. See [definitions as code](/factories/factory-as-code/). | ||
|
|
||
| To add or change a trigger in the factory dashboard: | ||
|
|
||
| 1. In the factory dashboard, open **Automations**, then create an automation or edit an existing one. | ||
| 2. Add an Azure DevOps trigger, then choose an event and its filters. | ||
| 3. Click **Save**. Perform a matching action in Azure DevOps and confirm that a run starts in the factory dashboard. | ||
|
|
||
| For general filter behavior, see [factory automations](/factories/automations/). | ||
|
|
||
| ### Supported events and filters | ||
|
|
||
| | Azure DevOps event | Available filters | | ||
| | --- | --- | | ||
| | Work item created | Work item types, labels, assignees, and authors | | ||
| | Work item assigned | Work item types, labels, assignees, and authors | | ||
| | Work item labeled | Work item types, labels, assignees, and authors | | ||
| | Mentioned in a work item | Mentioned users | | ||
| | Pull request created | Repository and target branches | | ||
| | Pull request merged | Repository and target branches | | ||
| | Pull request closed | Repository and target branches | | ||
| | Pull request updated | Repository and target branches | | ||
| | Pull request commented | Repository and target branches | | ||
| | Mentioned in a pull request | Repository and mentioned users | | ||
|
|
||
| ## Troubleshooting | ||
|
|
||
| ### An organization, project, or repository doesn't appear | ||
|
|
||
| **Cause:** Your Azure DevOps user lacks access to the resource. | ||
|
|
||
| **Solution:** Grant the user access, then refresh the connection. | ||
|
|
||
| ### Manager approval can't continue | ||
|
|
||
| **Cause:** The Microsoft Entra approval is incomplete. | ||
|
|
||
| **Solution:** Complete the Microsoft Entra step before the Azure DevOps step. Reopen the setup link if another administrator completed the first step. | ||
|
|
||
| ### Identity provisioning remains in progress | ||
|
|
||
| **Cause:** Microsoft Entra and Azure DevOps permission changes can take several minutes to propagate. | ||
|
|
||
| **Solution:** Wait, then retry from the factory's settings if setup reports an error. | ||
|
|
||
| ### An event doesn't start a run | ||
|
|
||
| **Cause:** The automation is disabled, a filter doesn't match, or its creator's Azure DevOps OAuth connection is missing, revoked, or under-scoped. | ||
|
|
||
| **Solution:** Enable the automation, check every filter, and reconnect its creator's Azure DevOps account with the required scopes. | ||
|
|
||
| ### Factory identity doesn't appear in comment mention autocomplete | ||
|
|
||
| **Cause:** Azure DevOps doesn't yet recognize the factory identity for comment autocomplete. | ||
|
|
||
| **Workaround:** Make Azure DevOps recognize the factory identity by using it once in the organization: | ||
|
|
||
| 1. In the Azure DevOps organization and project connected to the factory, assign the factory identity to a work item and save the work item. | ||
| 2. Return to the comment, enter `@` followed by the factory identity's name, then select the identity from autocomplete. | ||
| 3. Confirm that Azure DevOps formats the selection as a mention. Plain text with the same name doesn't trigger the automation. | ||
|
|
||
| ### `The identity value 'X' for field 'Assigned To' is an unknown identity.` | ||
|
|
||
| **Cause:** Azure DevOps can't resolve the factory identity for the current work item. This can happen when the work item is outside the organization or project configured for the factory. | ||
|
|
||
| **Solution:** | ||
|
|
||
| 1. In the factory's settings, confirm its Azure DevOps organization and project. | ||
| 2. In Azure DevOps, open the work item from that organization and project, then assign the factory identity again. | ||
|
|
||
| ## Related pages | ||
|
|
||
| * [Warp Factories quickstart](/factories/quickstart/) - Create a factory and send its first work item. | ||
| * [Factory automations](/factories/automations/) - Configure triggers, filters, and routing. | ||
| * [Azure DevOps access for standalone cloud agents](/platform/integrations/azure-devops/) - Configure a PAT, Warp-managed secret, and environment clone command. | ||
| * [Other code forges](/factories/code-forges/other-code-forges/) - Connect repositories that don't have a first-class integration, including Azure DevOps Server. | ||
| * [Infrastructure and security](/factories/infrastructure-and-security/) - Review how factories handle execution, credentials, and access. | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
small note to self that this should no longer be request access after tomorrow, should probably take you directly to platform.warp.dev or warp.dev/factories
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Leaving this open for production enablement. The public Factories page still says closed Early Access, and the request-access URL is live, so the link should change only when the PR's
VERIFYgate is cleared.Responding as Docs Factory (V2): Open session · View in factory