microsoft / microsoft/msstore-cli
Unable to configure msstore in container image
Nobody has claimed this yet.
- Dominant language
- C#
- Stars
- 163
- Forks
- 22
- Avg merge
- 5d 6h
- Merged PRs (30d)
- 10
Description
I have been trying to create a container image that installs and configure msstore CLI so I can easily create a Gitlab pipeline job that use it. But if I run msstore in my entrypoint it doesn't work.
Below I'm listing my Dockerfile and entrypoint.sh as well as a few examples of the output I'm getting from gitlab.
Dockerfile
# syntax=docker/dockerfile:1.6
FROM mcr.microsoft.com/dotnet/runtime:9.0-bookworm-slim
ENV DEBIAN_FRONTEND=noninteractive
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
apt-transport-https \
ca-certificates \
curl \
dbus \
dbus-x11 \
gnome-keyring \
gnupg \
libsecret-1-0 \
software-properties-common \
git \
wget \
&& rm -rf /var/lib/apt/lists/*
RUN curl -fsSL https://packages.microsoft.com/config/debian/12/packages-microsoft-prod.deb -o /tmp/packages-microsoft-prod.deb \
&& dpkg -i /tmp/packages-microsoft-prod.deb \
&& rm /tmp/packages-microsoft-prod.deb \
&& apt-get update \
&& apt-get install -y --no-install-recommends powershell \
&& rm -rf /var/lib/apt/lists/*
COPY entrypoint.sh /usr/local/bin/entrypoint
RUN chmod +x /usr/local/bin/entrypoint
# Preinstall MSStore CLI so runtime container doesn't need to download it each time
RUN curl --location https://github.com/microsoft/msstore-cli/releases/latest/download/MSStoreCLI-linux-x64.tar.gz --output /tmp/MSStoreCLI-linux-x64.tar.gz \
&& mkdir -p /tmp/MSStoreCLI \
&& tar -xzf /tmp/MSStoreCLI-linux-x64.tar.gz -C /tmp/MSStoreCLI \
&& cp -R /tmp/MSStoreCLI/. /usr/local/bin \
&& rm -rf /tmp/MSStoreCLI /tmp/MSStoreCLI-linux-x64.tar.gz
ENTRYPOINT ["/usr/local/bin/entrypoint"]
Whatever else I change in the following the Dockerfile remains the same.
entrypoint.sh
#!/usr/bin/env bash
echo "Running entrypoint..."
set -Eeuo pipefail
trap 'echo "❌ Failed at line $LINENO: $BASH_COMMAND"; exit 1' ERR
echo "Unlock gnome keyring..."
export $(dbus-launch)
eval "$(echo '\n' | gnome-keyring-daemon --unlock)"
echo "Verify msstore CLI installation..."
echo "MSStore CLI $(msstore --version)"
echo "Configure msstore CLI..."
msstore reconfigure \
--tenantId "$WINDOWS_STORE_CLI_TENANT_ID" \
--clientId "$WINDOWS_STORE_CLI_CLIENT_ID" \
--clientSecret "$WINDOWS_STORE_CLI_CLIENT_SECRET" \
--sellerId "$WINDOWS_STORE_CLI_SELLER_ID"
echo "Debug: Number of arguments: $#"
echo "Debug: Arguments: $*"
echo "Executing command..."
exec "$@"
Expected output
The below output is from when I've moved the two msstore calls output of the image into my pipeline
Cloning into 'tmp_repo'...
Your branch is up to date with 'origin/kbi/publish-spark-app-script'.
Verify msstore CLI installation...
MSStore CLI 0.3.1.12+5558dc0d12
Configure msstore CLI...
__ __ _ __ _
| \/ | (_) ___ _ __ ___ ___ ___ / _| | |_
| |\/| | | | / __| | '__| / _ \ / __| / _ \ | |_ | __|
| | | | | | | (__ | | | (_) | \__ \ | (_) | | _| | |_
|_| |_| |_| \___| |_| \___/ |___/ \___/ |_| \__|
____ _ ____
/ ___| | |_ ___ _ __ ___ | _ \ ___ __ __
\___ \ | __| / _ \ | '__| / _ \ | | | | / _ \ \ \ / /
___) | | |_ | (_) | | | | __/ | |_| | | __/ \ V /
|____/ \__| \___/ |_| \___| |____/ \___| \_/
____ _ ___
/ ___| | | |_ _|
| | | | | |
| |___ | |___ | |
\____| |_____| |___|
Use of the Microsoft Store Developer CLI is subject to the terms of the
Microsoft Privacy Statement: https://aka.ms/privacy
You might need to provide some credentials to call the Microsoft Store APIs.
Let's start!
Testing configuration...
Configuration saved!
Awesome! It seems to be working!
$ echo "Waiting for SparkShowcaseAppPreAlpha publish to complete..." # collapsed multi-line command
Waiting for SparkShowcaseAppPreAlpha publish to complete...
Awaiting app published to complete (duration: 00:00:00.1690671)...
Retrieving Submission
Could not find a Pending Submission, but found the Last Published Submission.
Retrieving Last Published Submission
- Current submission status: Published
App update published successfully (duration: 00:00:14.5420774).
Finished waiting for app publish completion (total duration: 00:00:14.5423679).
$ echo "Waiting for SafePilotOpsPreAlpha publish to complete..." # collapsed multi-line command
Waiting for SafePilotOpsPreAlpha publish to complete...
Awaiting app published to complete (duration: 00:00:00.0860610)...
Retrieving Submission
Could not find a Pending Submission, but found the Last Published Submission.
Retrieving Last Published Submission
- Current submission status: Published
App update published successfully (duration: 00:00:15.6268892).
Finished waiting for app publish completion (total duration: 00:00:15.6272581).
$ echo "Waiting for SafeTugPreAlpha publish to complete..." # collapsed multi-line command
Waiting for SafeTugPreAlpha publish to complete...
Awaiting app published to complete (duration: 00:00:00.0808169)...
Retrieving Submission
Could not find a Pending Submission, but found the Last Published Submission.
Retrieving Last Published Submission
- Current submission status: Published
App update published successfully (duration: 00:00:12.6933439).
Finished waiting for app publish completion (total duration: 00:00:12.6936113).
Cleaning up project directory and file based variables
Job succeeded
As you can tell there is a bunch of stuff happening after Executing command....
Failure no. 1
With the image as defined above this is the output I get:
Running with gitlab-runner 18.4.0~pre.195.g5de42c65 (5de42c65)
on blue-4.saas-linux-small-amd64.runners-manager.gitlab.com/default J2nyww-sK, system ID: s_cf1798852952
Resolving secrets
Preparing the "docker+machine" executor
Using Docker executor with image registry.gitlab.com/redacted/redacted/windows-store-job:latest ...
Using effective pull policy of [always] for container registry.gitlab.com/redacted/redacted/windows-store-job:latest
Authenticating with credentials from job payload (GitLab Registry)
Pulling docker image registry.gitlab.com/redacted/redacted/windows-store-job:latest ...
Using docker image sha256:f73e409512ff64abdcee1639a0088b46e73338b21cb9dee52fde675541172bae for registry.gitlab.com/redacted/redacted/windows-store-job:latest with digest registry.gitlab.com/redacted/redacted/windows-store-job@sha256:84440f26550ed37da3a7ca847252167350778bc6b8731b578dca181daa7dd4d7 ...
Preparing environment
Using effective pull policy of [always] for container sha256:3f58170193143480f6b76a2f98c1c8bea597c48bd0efc331f38454734158d2c9
Running on runner-j2nyww-sk-project-8121549-concurrent-0 via runner-j2nyww-sk-s-l-s-amd64-1761501241-d033f367...
Getting source from Git repository
Skipping Git repository setup
Skipping Git checkout
Skipping Git submodules setup
Executing "step_script" stage of the job script
Using effective pull policy of [always] for container registry.gitlab.com/redacted/redacted/windows-store-job:latest
Using docker image sha256:f73e409512ff64abdcee1639a0088b46e73338b21cb9dee52fde675541172bae for registry.gitlab.com/redacted/redacted/windows-store-job:latest with digest registry.gitlab.com/redacted/redacted/windows-store-job@sha256:84440f26550ed37da3a7ca847252167350778bc6b8731b578dca181daa7dd4d7 ...
Running entrypoint...
Unlock gnome keyring...
Verify msstore CLI installation...
MSStore CLI 0.3.1.12+5558dc0d12
Configure msstore CLI...
__ __ _ __ _
| \/ | (_) ___ _ __ ___ ___ ___ / _| | |_
| |\/| | | | / __| | '__| / _ \ / __| / _ \ | |_ | __|
| | | | | | | (__ | | | (_) | \__ \ | (_) | | _| | |_
|_| |_| |_| \___| |_| \___/ |___/ \___/ |_| \__|
____ _ ____
/ ___| | |_ ___ _ __ ___ | _ \ ___ __ __
\___ \ | __| / _ \ | '__| / _ \ | | | | / _ \ \ \ / /
___) | | |_ | (_) | | | | __/ | |_| | | __/ \ V /
|____/ \__| \___/ |_| \___| |____/ \___| \_/
____ _ ___
/ ___| | | |_ _|
| | | | | |
| |___ | |___ | |
\____| |_____| |___|
Use of the Microsoft Store Developer CLI is subject to the terms of the
Microsoft Privacy Statement: https://aka.ms/privacy
You might need to provide some credentials to call the Microsoft Store APIs.
Let's start!
Testing configuration...
Configuration saved!
Awesome! It seems to be working!
Debug: Number of arguments: 3
Debug: Arguments: sh -c if [ -x /usr/local/bin/bash ]; then
exec /usr/local/bin/bash
elif [ -x /usr/bin/bash ]; then
exec /usr/bin/bash
elif [ -x /bin/bash ]; then
exec /bin/bash
elif [ -x /usr/local/bin/sh ]; then
exec /usr/local/bin/sh
elif [ -x /usr/bin/sh ]; then
exec /usr/bin/sh
elif [ -x /bin/sh ]; then
exec /bin/sh
elif [ -x /busybox/sh ]; then
exec /busybox/sh
else
echo shell not found
exit 1
fi
Executing command...
Cleaning up project directory and file based variables
Job succeeded
As you can see the pipeline script isn't executed. It prints Executing command... and then completes.
Failure no. 2
While the above is the actual problem I'd like to solve, trying to do so let me to the following curious error. If I remove the first call to msstore on line 12 (echo "MSStore CLI $(msstore --version)") I get the following result:
Running with gitlab-runner 18.4.0~pre.195.g5de42c65 (5de42c65)
on blue-2.saas-linux-small-amd64.runners-manager.gitlab.com/default XxUrkriXT, system ID: s_f46a988edce4
Resolving secrets
Preparing the "docker+machine" executor
Using Docker executor with image registry.gitlab.com/redacted/redacted/windows-store-job:latest ...
Using effective pull policy of [always] for container registry.gitlab.com/redacted/redacted/windows-store-job:latest
Authenticating with credentials from job payload (GitLab Registry)
Pulling docker image registry.gitlab.com/redacted/redacted/windows-store-job:latest ...
Using docker image sha256:41af784ad5c14aa89419208aab47f70121b9d3c6a4b80e3080949fb4a8584983 for registry.gitlab.com/redacted/redacted/windows-store-job:latest with digest registry.gitlab.com/redacted/redacted/windows-store-job@sha256:c35f31d1360e350c59aa2b759f42c111e7b2a223c290efdac59ea5295535cc0d ...
Preparing environment
Using effective pull policy of [always] for container sha256:d95b77ef3370f4c87650e799119a8de1f9ed228aeceb1ce2da85133d322dc516
Running on runner-xxurkrixt-project-8121549-concurrent-0 via runner-xxurkrixt-s-l-s-amd64-1761501491-dd185b9c...
Getting source from Git repository
Skipping Git repository setup
Skipping Git checkout
Skipping Git submodules setup
Executing "step_script" stage of the job script
Using effective pull policy of [always] for container registry.gitlab.com/redacted/redacted/windows-store-job:latest
Using docker image sha256:41af784ad5c14aa89419208aab47f70121b9d3c6a4b80e3080949fb4a8584983 for registry.gitlab.com/redacted/redacted/windows-store-job:latest with digest registry.gitlab.com/redacted/redacted/windows-store-job@sha256:c35f31d1360e350c59aa2b759f42c111e7b2a223c290efdac59ea5295535cc0d ...
Running entrypoint...
Unlock gnome keyring...
Verify msstore CLI installation...
Configure msstore CLI...
Unrecognized command or argument '#!/usr/bin/env bash
trap exit 1 TERM
if set -o | grep pipefail > /dev/null; then set -o pipefail; fi; set -o errexit
set +o noclobber
: | eval $'export FF_TEST_FEATURE=false\nexport REDACTED ENV VARS echo $\'\\x1b[32;1m$ echo "Waiting for SparkShowcaseAppPreAlpha publish to complete..." # collapsed multi-line command\\x1b[0;m\'\necho "Waiting for SparkShowcaseAppPreAlpha publish to complete..."\n./Scripts/Wait-ForSparkAppPublishToWindowsStoreCompleted.ps1 -AppName SparkShowcaseAppPreAlpha\necho $\'\\x1b[32;1m$ echo "Waiting for SafePilotOpsPreAlpha publish to complete..." # collapsed multi-line command\\x1b[0;m\'\necho "Waiting for SafePilotOpsPreAlpha publish to complete..."\n./Scripts/Wait-ForSparkAppPublishToWindowsStoreCompleted.ps1 -AppName SafePilotOpsPreAlpha\necho $\'\\x1b[32;1m$ echo "Waiting for SafeTugPreAlpha publish to complete..." # collapsed multi-line command\\x1b[0;m\'\necho "Waiting for SafeTugPreAlpha publish to complete..."\n./Scripts/Wait-ForSparkAppPublishToWindowsStoreCompleted.ps1 -AppName SafeTugPreAlpha\n'
exit 0
'.
Description:
Re-configure the Microsoft Store Developer CLI.
Usage:
msstore reconfigure [options]
Options:
-t, --tenantId <tenantId> Specify the tenant Id that should be used.
-s, --sellerId <sellerId> Specify the seller Id that should be used.
-c, --clientId <clientId> Specify the client Id that should be used.
-cs, --clientSecret <clientSecret> Specify the client Secret that should be used.
-ct, --certificateThumbprint <certificateThumbprint> Specify the certificate Thumbprint that should be used.
-cfp, --certificateFilePath <certificateFilePath> Specify the certificate file path that should be used.
-cp, --certificatePassword <certificatePassword> Specify the certificate password that should be used.
--reset Only reset the credentials, without starting over.
-v, --verbose Verbose output
-?, -h, --help Show help and usage information
❌ Failed at line 15: msstore reconfigure --tenantId "$WINDOWS_STORE_CLI_TENANT_ID" --clientId "$WINDOWS_STORE_CLI_CLIENT_ID" --clientSecret "$WINDOWS_STORE_CLI_CLIENT_SECRET" --sellerId "$WINDOWS_STORE_CLI_SELLER_ID"
Cleaning up project directory and file based variables
ERROR: Job failed: exit code 1
For some reason msstore doesn't understand the reconfigure command, and it now prints the entire command provided by Gitlab.
I've redacted all the environment variables passed in, but they actually contain the variables I reference in the reconfigure call - as if they weren't available before executing the command after the entrypoint. But as we've seen from the previous run, they reconfigure command works fine.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Reproduce the issue with the provided Dockerfile and entrypoint.sh, then start by tracing the command and arguments GitLab passes to the entrypoint. Compare both failure cases and verify how msstore configuration affects the shell command. Done means the GitLab job script executes after configuration and the msstore CLI remains usable in the container.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- bash, csharp, docker, gitlab
- Domain
- cli, devops
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100