Reap orphaned Azure provisioning tunnels - #432
Merged
Merged
Conversation
Provisioning tunnels run outside the CLI process group so the console can hard-kill DreadGOAD without reaching them. Supervise the Azure CLI process group from a pipe-backed watchdog that survives long enough to clean up after abrupt parent exit.
There was a problem hiding this comment.
Pull request overview
This PR hardens Azure provisioning tunnels by introducing a dedicated watchdog subprocess that can terminate and reap the entire az network bastion tunnel process group even if the main DreadGOAD CLI process is abruptly killed, preventing orphaned tunnel processes from persisting.
Changes:
- Adds a hidden
__bastion-watchdogCobra command that supervises a child command until a parent-lifetime FD closes. - Refactors provisioning tunnel startup/teardown to launch and coordinate with the watchdog via a pipe-based liveness signal.
- Expands regression tests to cover parent-death cleanup and “leader exited but descendant still alive” process-group tracking.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| cli/internal/azure/provision_tunnel.go | Introduces watchdog-backed bastion tunnel lifecycle management and process-group reaping logic. |
| cli/internal/azure/provision_tunnel_test.go | Adds/updates tests validating watchdog cleanup behavior and process-group termination semantics. |
| cli/cmd/bastion_watchdog.go | Adds the hidden __bastion-watchdog CLI entry point used by provisioning tunnels. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Azure provisioning tunnels now clean up even when the DreadGOAD CLI is hard-killed by the console.
Added
Fixed
az network bastion tunnelprocesses no longer survive abrupt CLI termination.Notes
dreadgoad bastion tunnelcommand remains on its existing interactive lifecycle path.