Fix win-11 integration tests - #763
Merged
Merged
Conversation
Paamicky
force-pushed
the
win11-test
branch
from
September 18, 2026 00:51
70595a8 to
9457c55
Compare
jefchien
approved these changes
Sep 18, 2026
| associate_public_ip_address = true | ||
| instance_initiated_shutdown_behavior = "terminate" | ||
| user_data = length(regexall("/feature/windows/custom_start/userdata", var.test_dir)) > 0 ? data.template_file.user_data.rendered : "" | ||
| user_data = length(regexall("/feature/windows/custom_start/userdata", var.test_dir)) > 0 ? data.template_file.user_data.rendered : (length(regexall("win-11", var.ami)) > 0 ? local.winrm_bootstrap_userdata : "") |
Contributor
There was a problem hiding this comment.
nit: So this only works because /feature/windows/custom_start/userdata isn't run against win-11 tests (currently only win-2019). If it ever was, the win-11 userdata wouldn't be selected and could fail again.
Comment on lines
+91
to
+108
| # First-boot WinRM bootstrap for win-11: client SKUs boot with the NIC in the Public | ||
| # firewall profile where 5985 is blocked. Open the firewall (no WinRM restart), and pin | ||
| # the NIC to Private via a periodic task so NLA can't flip it to Public mid-session | ||
| # (a profile change reloads the firewall and resets live WinRM sessions). | ||
| locals { | ||
| winrm_bootstrap_userdata = <<EOT | ||
| <powershell> | ||
| New-NetFirewallRule -DisplayName "WinRM 5985 Any Profile" -Direction Inbound -Protocol TCP -LocalPort 5985 -Action Allow -Profile Any -ErrorAction SilentlyContinue | ||
| Enable-NetFirewallRule -DisplayGroup "Windows Remote Management" -ErrorAction SilentlyContinue | ||
| Set-NetFirewallRule -Name WINRM-HTTP-In-TCP-PUBLIC -RemoteAddress Any -Enabled True -ErrorAction SilentlyContinue | ||
| Set-Service -Name WinRM -StartupType Automatic | ||
| Get-NetConnectionProfile | Set-NetConnectionProfile -NetworkCategory Private -ErrorAction SilentlyContinue | ||
| $act = New-ScheduledTaskAction -Execute powershell.exe -Argument '-NoProfile -WindowStyle Hidden -Command "Get-NetConnectionProfile | Set-NetConnectionProfile -NetworkCategory Private"' | ||
| $t1 = New-ScheduledTaskTrigger -AtStartup | ||
| $t2 = New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(1) -RepetitionInterval (New-TimeSpan -Minutes 1) -RepetitionDuration (New-TimeSpan -Hours 2) | ||
| Register-ScheduledTask -TaskName "PinPrivateNetworkProfile" -Action $act -Trigger $t1,$t2 -User "SYSTEM" -RunLevel Highest -Force -ErrorAction SilentlyContinue | ||
| </powershell> | ||
| EOT |
Contributor
There was a problem hiding this comment.
nit: Would prefer if this was fixed in the AMI itself so we don't rely on this runtime fix.
Contributor
Author
There was a problem hiding this comment.
Yes I will create a backlog item and investigate the pipeline build failure so we can fix in the AMI
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of the issue
Windows 11 integration tests have failed since the win-11 build AMI was rebuilt (2026-09-07) onto a newer client Windows base. On client SKUs(desktop editions) the Network Interface Card boots into the Public firewall profile, where inbound WinRM (5985) is blocked, so Terraform's
winrmprovisioner can't connect. The test harness has noWinRM/firewallsetup of its own and relies on the AMI, so every win-11 run fails at connect. Windows Server editions are not affected. giveDescription of changes
var.ami) interraform/ec2/win/main.tfthat sets the network profile to Private, that allows 5985 inbound on all firewall profiles. All other Windows OS runs are unchanged.jvm_gc_collection_seconds_sumnow reports after forcing GC with a 32MB heap. Test was flakey and now passes.License
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.
Tests
WinRM now connects and the tests pass: