Skip to content

Fix win-11 integration tests - #763

Merged
Paamicky merged 2 commits into
mainfrom
win11-test
Sep 18, 2026
Merged

Paamicky merged 2 commits into
mainfrom
win11-test

Conversation

@Paamicky

@Paamicky Paamicky commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Description of the issue

Windows 11 integration tests have failed since the win-11 build AMI was rebuilt (2026-09-07) onto a newer client Windows base. On client SKUs(desktop editions) the Network Interface Card boots into the Public firewall profile, where inbound WinRM (5985) is blocked, so Terraform's winrm provisioner can't connect. The test harness has no WinRM/firewall setup of its own and relies on the AMI, so every win-11 run fails at connect. Windows Server editions are not affected. give

Description of changes

  • Add first-boot EC2 user_data (gated to win-11 runs via var.ami) in terraform/ec2/win/main.tf that sets the network profile to Private, that allows 5985 inbound on all firewall profiles. All other Windows OS runs are unchanged.
  • JMX GC fix: jvm_gc_collection_seconds_sum now reports after forcing GC with a 32MB heap. Test was flakey and now passes.

License

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

Tests

WinRM now connects and the tests pass:

@Paamicky
Paamicky requested a review from a team as a code owner September 17, 2026 20:50
Comment thread terraform/ec2/win/main.tf
associate_public_ip_address = true
instance_initiated_shutdown_behavior = "terminate"
user_data = length(regexall("/feature/windows/custom_start/userdata", var.test_dir)) > 0 ? data.template_file.user_data.rendered : ""
user_data = length(regexall("/feature/windows/custom_start/userdata", var.test_dir)) > 0 ? data.template_file.user_data.rendered : (length(regexall("win-11", var.ami)) > 0 ? local.winrm_bootstrap_userdata : "")

@jefchien jefchien Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: So this only works because /feature/windows/custom_start/userdata isn't run against win-11 tests (currently only win-2019). If it ever was, the win-11 userdata wouldn't be selected and could fail again.

Comment thread terraform/ec2/win/main.tf
Comment on lines +91 to +108
# First-boot WinRM bootstrap for win-11: client SKUs boot with the NIC in the Public
# firewall profile where 5985 is blocked. Open the firewall (no WinRM restart), and pin
# the NIC to Private via a periodic task so NLA can't flip it to Public mid-session
# (a profile change reloads the firewall and resets live WinRM sessions).
locals {
winrm_bootstrap_userdata = <<EOT
<powershell>
New-NetFirewallRule -DisplayName "WinRM 5985 Any Profile" -Direction Inbound -Protocol TCP -LocalPort 5985 -Action Allow -Profile Any -ErrorAction SilentlyContinue
Enable-NetFirewallRule -DisplayGroup "Windows Remote Management" -ErrorAction SilentlyContinue
Set-NetFirewallRule -Name WINRM-HTTP-In-TCP-PUBLIC -RemoteAddress Any -Enabled True -ErrorAction SilentlyContinue
Set-Service -Name WinRM -StartupType Automatic
Get-NetConnectionProfile | Set-NetConnectionProfile -NetworkCategory Private -ErrorAction SilentlyContinue
$act = New-ScheduledTaskAction -Execute powershell.exe -Argument '-NoProfile -WindowStyle Hidden -Command "Get-NetConnectionProfile | Set-NetConnectionProfile -NetworkCategory Private"'
$t1 = New-ScheduledTaskTrigger -AtStartup
$t2 = New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) -RepetitionInterval (New-TimeSpan -Minutes 1) -RepetitionDuration (New-TimeSpan -Hours 2)
Register-ScheduledTask -TaskName "PinPrivateNetworkProfile" -Action $act -Trigger $t1,$t2 -User "SYSTEM" -RunLevel Highest -Force -ErrorAction SilentlyContinue
</powershell>
EOT

@jefchien jefchien Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Would prefer if this was fixed in the AMI itself so we don't rely on this runtime fix.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes I will create a backlog item and investigate the pipeline build failure so we can fix in the AMI

@Paamicky
Paamicky merged commit f5c3018 into main Sep 18, 2026
6 checks passed
@Paamicky
Paamicky deleted the win11-test branch September 18, 2026 19:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants