Microsoft Certified: DevOps Engineer ExpertDesign and implement source controlMedium
A team is developing a new application that uses a combination of public open-source NuGet packages and internal proprietary NuGet packages. They are using Azure Artifacts for their private feeds. The team wants to ensure that when a developer builds the application, the build process first attempts to retrieve packages from the internal feed. If a package is not found in the internal feed, it should then attempt to retrieve it from nuget.org. This order of resolution is critical for security and performance. Which Azure Artifacts configuration should they implement?
- ACreate a new feed view that filters public packages.
- BManually add both internal and nuget.org feeds to the pipeline's NuGet.config.
- CSet up a separate proxy server for public NuGet packages.
- DConfigure the internal feed to use nuget.org as an upstream source.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure the internal feed to use nuget.org as an upstream source.
Configuring nuget.org as an upstream source for the internal Azure Artifacts feed allows the feed to act as a single point of access. When a package is requested, the feed first checks its own content (internal packages), then consults its upstream sources (nuget.org). This ensures the desired resolution order and simplifies the client's NuGet configuration to a single feed.
Why the other options are wrong
- A. Feed views control visibility within a single feed, not the order of resolution between multiple distinct feeds.
- B. Manually adding both feeds to NuGet.config requires developers to manage the order and can be error-prone; it doesn't consolidate the sources.
- C. Setting up a separate proxy server is an overly complex solution for this scenario when Azure Artifacts provides the upstream sources feature natively.
Azure Artifacts Upstream Sources (Resolution Order)
Upstream sources in Azure Artifacts allow a single feed to serve packages from multiple sources, with a default resolution order of local feed content first, then configured upstream sources.
- Primary feed's packages are always resolved first.
- Upstream sources are queried in the order they are listed if the package isn't found locally.
- Caches packages from upstream sources for improved performance.
- Simplifies client NuGet.config by requiring only one feed URL.
Memory trick: Upstream sources prioritize local then flow to public.