Skip to content

Floci Azure: add WithStorage child resource and fix dev account key - #2223

Open
thomhurst wants to merge 1 commit into
CommunityToolkit:mainfrom
thomhurst:floci-azure-storage-resource
Open

thomhurst wants to merge 1 commit into
CommunityToolkit:mainfrom
thomhurst:floci-azure-storage-resource

Conversation

@thomhurst

Copy link
Copy Markdown
Contributor

Closes #2222

Adds WithStorage(), which models floci-az's Blob, Queue and Table APIs as a FlociAzureStorageResource child. It follows the existing WithCosmos() / FlociAzureCosmosResource pattern: a Resource that implements IResourceWithParent<FlociAzureContainerResource> and IResourceWithConnectionString, uses WithParentRelationship, and works with Aspire's standard WithReference flow.

  • Health: the child has no health check of its own. Aspire's ResourceHealthCheckService applies ancestor health checks, so the child reports the Floci container's /_floci/health and WaitFor(storage) works. This removes the reason AppHosts redirect AzureStorageResource to Floci, which leaves Aspire's blob health check permanently Unhealthy ("Connection string is not initialized.").
  • Endpoints: BlobEndpoint, QueueEndpoint and TableEndpoint use EndpointProperty.IPV4Host rather than localhost. The Azure Storage SDKs only take the account name from the path for IP hosts, so with localhost, BlobServiceClient.AccountName resolves to localhost and SAS generation signs for the wrong account.
  • Account key fix: FlociAzureContainerResource.DefaultAccountKey ended in ...GMh0==; the well-known devstoreaccount1 key ends in ...GMGw==. floci-az validates SharedKey signatures, so requests signed with the old key failed with AuthenticationFailed. The new functional test failed for this reason before the fix. The fix also corrects AZURE_STORAGE_CONNECTION_STRING from WithReference(azure).

PR Checklist

  • Created a feature/dev branch in your fork (vs. submitting directly from a commit on main)
  • Based off latest main branch of toolkit
  • PR doesn't include merge commits (always rebase on top of our main, if needed)
  • Tests for the changes have been added (for bug fixes / features) (if applicable)
  • Contains NO breaking changes
  • Every new API (including internal ones) has full XML docs
  • Code follows all style conventions

Other information

Tests:

  • WithReferenceTests covers the child resource and parent relationship, the connection string shape (including the IPv4 host), custom names, argument validation, and that the child inherits the parent's health check rather than adding its own.
  • New [RequiresDocker] AzureStorageFunctionalTests starts floci-az, waits for the storage child to become healthy, then round-trips a blob with BlobServiceClient. It also checks that AccountName is devstoreaccount1 and that a generated SAS URI downloads the blob.
  • Locally, 89 of 90 tests in CommunityToolkit.Aspire.Hosting.Floci.Tests pass. The one failure, TypeScriptAppHostTests.TypeScriptAppHostCompilesAndStarts, also fails on unmodified main on my Windows machine: the floci-mount bind-mount container never starts. It is unrelated to this change.

I did not hand-edit the generated api/*.cs file, per the repo instructions.

The issue has not been triaged yet. I'm opening this PR alongside it so maintainers can see the concrete shape; I'm happy to rework it if a different API is preferred.

Adds WithStorage(), which models floci-az's Blob, Queue and Table APIs as a
FlociAzureStorageResource child alongside WithCosmos and WithServiceBus. The
child reports the Floci container's health, so dependents can WaitFor it
without redirecting Aspire's AzureStorageResource, whose health checks never
initialize when redirected.

Storage endpoints use the IPv4 host so the Azure Storage SDKs read the account
name from the path. Also corrects DefaultAccountKey to the well-known
devstoreaccount1 key; floci-az rejected SharedKey requests signed with the old
value.

Closes CommunityToolkit#2222
Copilot AI balanced review requested due to automatic review settings October 6, 2026 16:29
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/CommunityToolkit/Aspire/main/eng/scripts/dogfood-pr.sh | bash -s -- 2223

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/CommunityToolkit/Aspire/main/eng/scripts/dogfood-pr.ps1) } 2223"

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The documented TypeScript export lacks coverage in the existing generated AppHost test, and one credential comment is now inaccurate.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Adds first-class Floci Azure Storage child-resource support and corrects SharedKey authentication.

Changes:

  • Adds exported WithStorage() and storage connection metadata.
  • Corrects the development account key.
  • Adds unit, functional, and usage documentation coverage.
File Description
WithReferenceTests.cs Tests storage references, health, naming, and validation.
CommunityToolkit.Aspire.Hosting.Floci.Tests.csproj Adds the Blob SDK dependency.
AzureStorageFunctionalTests.cs Tests Blob operations and SAS authentication.
README.md Documents C# and TypeScript usage.
FlociHostingExtension.Azure.cs Adds the exported WithStorage() API.
FlociAzureStorageResource.cs Defines the Storage child resource and connection string.
FlociAzureContainerResource.cs Corrects the development account key.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

/// <param name="builder">The Floci Azure resource builder.</param>
/// <param name="name">The name of the Storage resource (default: <c>storage</c>).</param>
/// <returns>A reference to the <see cref="IResourceBuilder{FlociAzureStorageResource}"/> for further configuration.</returns>
[AspireExport]
// Well-known Azurite-compatible dev credentials that floci-az accepts by default (no auth enforced).
internal const string DefaultAccountName = "devstoreaccount1";
internal const string DefaultAccountKey = "Eby8vdM02xNOcqFlqUwJPLlmEtlCDXJ1OUzFT50uSRZ6IFsuFq2UVErCz4I6tq/K1SZFPTOtr/KBHBeksoGMh0==";
internal const string DefaultAccountKey = "Eby8vdM02xNOcqFlqUwJPLlmEtlCDXJ1OUzFT50uSRZ6IFsuFq2UVErCz4I6tq/K1SZFPTOtr/KBHBeksoGMGw==";

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Floci Azure: add a Storage child resource (WithStorage) and fix the dev account key

2 participants