Problem
The identity prompt that sets up the GitHub ↔ Azure connection may overwrite existing GitHub repository secrets. For example, if a user already has a secret named AZURE_SUBSCRIPTION_ID for other workflows, the identity prompt will silently overwrite it, potentially breaking their existing CI/CD pipelines.
Proposed Solution
Update the identity prompt to check for existing secrets and interactively prompt the user before writing:
- Check if the secret already exists — before setting each secret (e.g.,
AZURE_SUBSCRIPTION_ID, AZURE_CLIENT_ID, AZURE_TENANT_ID), query the GitHub API to see if a secret with that name is already present
- If a conflict exists, prompt the user — show the user which secrets already exist and ask whether they want to:
- Overwrite the existing secret (e.g., if it's from a previous APIOps setup)
- Use a different name (e.g.,
APIOPS_AZURE_SUBSCRIPTION_ID) — let the user confirm or customize the alternative name
- Reuse the existing secret — if the existing value is already correct, skip setting it
- Update pipeline references — ensure the scaffolded pipeline YAML files reference the correct secret names based on the user's choices
- Inform the user — summarize what was set and what was skipped/renamed
Acceptance Criteria
Problem
The identity prompt that sets up the GitHub ↔ Azure connection may overwrite existing GitHub repository secrets. For example, if a user already has a secret named
AZURE_SUBSCRIPTION_IDfor other workflows, the identity prompt will silently overwrite it, potentially breaking their existing CI/CD pipelines.Proposed Solution
Update the identity prompt to check for existing secrets and interactively prompt the user before writing:
AZURE_SUBSCRIPTION_ID,AZURE_CLIENT_ID,AZURE_TENANT_ID), query the GitHub API to see if a secret with that name is already presentAPIOPS_AZURE_SUBSCRIPTION_ID) — let the user confirm or customize the alternative nameAcceptance Criteria