Repository navigation
az network application-gateway waf-policy custom-rule create always fails since 2.61.0 #29059
Description
Activity
- addedbugThis issue requires a change to an existing behavior in the product in order to be resolved.This issue requires a change to an existing behavior in the product in order to be resolved.
on May 30, 2024 Thank you for opening this issue, we will look into it.
- addedcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.Networkaz network vnet/lb/nic/dns/etc...az network vnet/lb/nic/dns/etc...
on May 30, 2024 - addedAuto-AssignAuto assign by botAuto assign by botAzure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
on May 30, 2024 - removedbugThis issue requires a change to an existing behavior in the product in order to be resolved.This issue requires a change to an existing behavior in the product in order to be resolved.
on May 31, 2024 Hi Yong Zhang (@yonzhan), Could you post a status of this bug item? This issue persists and we have open tickets due to this bug. If this is not an active work item, kindly prioritize this.
there is nothing changed within 2.61.0 from client side, but could you input proper
--match-conditionsfor your command?i will also ask service team for help
- addedService AttentionThis issue is responsible by Azure service team.This issue is responsible by Azure service team.
on Jun 19, 2024 - removedAzure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI team
on Jun 19, 2024 Ethan Yang (@necusjz) I haven't tried to get
--match-conditionsto work since it's not mandatory and we setup our rule in the second step (using amatch-condition addstatement).If you have an example of a create statement with
--match-conditions, I'd be happy to try it though.Ernst Lindoorn (@elindoorn) snippets in our code base
, you can take a lookazure-cli/src/azure-cli/azure/cli/command_modules/network/tests/latest/test_network_commands.py
Lines 2527 to 2538 in 1a1c762
self.cmd('network application-gateway waf-policy custom-rule create -g {rg} ' '--policy-name {waf} -n {rule} ' '--priority 1 ' '--action Block ' '--rule-type MatchRule ' '--match-conditions [{{"variables":[{{"variable_name":"RemoteAddr"}}],"operator":"IPMatch","values":["192.168.2.0/24","10.0.2.0/24"]}}]') self.cmd('network application-gateway waf-policy custom-rule create -g {rg} ' '--policy-name {waf} -n {rule2} ' '--priority 2 ' '--action Block ' '--rule-type MatchRule ' '--match-conditions [{{"variables":[{{"variable_name":"RemoteAddr"}}],"operator":"IPMatch","values":["192.168.2.0/24","10.0.2.0/24"]}}]') Ethan Yang (@necusjz) thanks for the example, the command with the --match-conditions argument does succeed
az network application-gateway waf-policy custom-rule create --resource-group xxx --policy-name xxx --name demoIssue --action Allow --priority 99 --rule-type MatchRule --match-conditions '[{"variables":[{"variable_name":"RemoteAddr"}],"operator":"IPMatch","values":["192.168.2.0/24","10.0.2.0/24"]}]'returns:
{ "action": "Allow", "matchConditions": [ { "matchValues": [ "192.168.2.0/24", "10.0.2.0/24" ], "matchVariables": [ { "variableName": "RemoteAddr" } ], "negationConditon": false, "operator": "IPMatch", "transforms": [] } ], "name": "demoIssue", "priority": 99, "ruleType": "MatchRule", "state": "Enabled" }PS. might want to get this added to the docs :)
Reacted by Ethan Yang
Describe the bug
We use a dynamic az cli script to add a WAF rule in our build pipeline so we can temporarily give our build agent access to our app and test something. After we're done we remove the rule again, something like the following:
az network application-gateway waf-policy custom-rule create
az network application-gateway waf-policy custom-rule match-condition add
do something
az network application-gateway waf-policy custom-rule delete
However after upgrading to 2.61.0 (from 2.60.0) the cli command to create a custom WAF rule (the custom-rule create command) always (unless the rule already exists) fails with the following error: Custom Rule 'demoIssue' does not have a match condition defined in context 'properties.customRules[8]'
Related command
az network application-gateway waf-policy custom-rule create
--subscription xxx
--resource-group xxx
--policy-name xxx
--name demoIssue
--action Allow
--priority 99
--rule-type MatchRule
Errors
(ApplicationGatewayFirewallCustomRuleNoMatchConditionNotSupported) Custom Rule 'demoIssue' does not have a match condition defined in context 'properties.customRules[8]'.
Code: ApplicationGatewayFirewallCustomRuleNoMatchConditionNotSupported
Message: Custom Rule 'demoIssue' does not have a match condition defined in context 'properties.customRules[8]'.
Issue script & Debug output
Command group 'az network' is in preview and under development. Reference and support levels: https://aka.ms/CLI_refstatus
(ApplicationGatewayFirewallCustomRuleNoMatchConditionNotSupported) Custom Rule 'demoIssue' does not have a match condition defined in context 'properties.customRules[8]'.
Code: ApplicationGatewayFirewallCustomRuleNoMatchConditionNotSupported
Message: Custom Rule 'demoIssue' does not have a match condition defined in context 'properties.customRules[8]'.
Expected behavior
Expected the following response:
{
"action": "Allow",
"matchConditions": [],
"name": "demoIssue",
"priority": 99,
"ruleType": "MatchRule",
"state": "Enabled"
}
Environment Summary
azure-cli 2.61.0
core 2.61.0
telemetry 1.1.0
Extensions:
application-insights 1.2.1
azure-devops 1.0.1
bastion 0.3.0
datafactory 1.0.0
interactive 0.5.3
ssh 2.0.3
Dependencies:
msal 1.28.0
azure-mgmt-resource 23.1.1
Python location 'C:\Program Files\Microsoft SDKs\Azure\CLI2\python.exe'
Extensions directory 'C:\Users\e.azure\cliextensions'
Python (Windows) 3.11.8 (tags/v3.11.8:db85d51, Feb 6 2024, 22:03:32) [MSC v.1937 64 bit (AMD64)]
Additional context
Confirmed on multiple laptops as well as azure pipeline