[App Service] az functionapp create, az functionapp deployment config set: Add Flex Consumption Registry deployment storage support - #34147
Open
pragatikushwaha wants to merge 9 commits into
Conversation
…fig set`: Add Flex Consumption Registry deployment storage support Add --deployment-image, --deployment-image-auth-type, --deployment-image-identity, --deployment-image-username-setting, --deployment-image-password-setting and --deployment-image-server-url so Flex Consumption apps can run a container image from functionAppConfig.deployment.storage of type Registry (Microsoft.Web 2025-05-01). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
microsoft-github-policy-service
Bot
requested a review
from Yong Zhang (yonzhan)
September 29, 2026 09:38
Member
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
…g show`: Return Flex Registry configuration with API version 2025-05-01 - Re-read Flex apps that use Registry deployment storage at 2025-05-01 so both show commands return the persisted Registry configuration. Blob storage apps keep their existing request and output. - Tests: show round-trips for both show commands, a rejected update followed by show, secret-safe set/show output, and legacy container markers never set on create. The live scenario covers the same flows end to end. - Help: describe what deployment config show returns for Registry storage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Member
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
… updates Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
A post-create identity update can erase Basic Registry authentication fields by rewriting the site through an older API.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds Flex Consumption Registry deployment storage support to App Service commands.
Changes:
- Adds Registry image/authentication arguments and validation.
- Uses API
2025-05-01while preserving Registry configuration. - Adds help, mocked tests, and a live scenario.
| File | Description |
|---|---|
utils.py |
Supports explicit API versions for raw reads. |
custom.py |
Implements Registry create, update, show, and preservation logic. |
_params.py |
Registers Registry deployment arguments. |
_help.py |
Documents Registry workflows and examples. |
_constants.py |
Defines auth modes, API version, and defaults. |
test_functionapp_commands.py |
Adds live Registry coverage. |
test_functionapp_commands_thru_mock.py |
Adds request, validation, and preservation tests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Member
|
/azp run |
pragatikushwaha
commented
Sep 30, 2026
…tity changes Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Member
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Member
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
Mani (manikantanallagatla)
approved these changes
Sep 30, 2026
Collaborator
|
Please fix CI issues |
pragatikushwaha
commented
Oct 1, 2026
pragatikushwaha
commented
Oct 1, 2026
pragatikushwaha
commented
Oct 1, 2026
pragatikushwaha
commented
Oct 1, 2026
pragatikushwaha
commented
Oct 1, 2026
Set the explicit Recreate strategy for Registry creates, validate merged image/authentication before updates, and remove redundant Registry re-reads and identity API-version overrides while preserving the published API for new Registry writes. Cover default-version field preservation and unchanged non-Flex app/slot behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Member
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
list_flexconsumption_locations and list_flexconsumption_zone_redundant_locations normalized geo region display names by lowercasing and removing spaces only, so "North Central US (Stage)" became "northcentralus(stage)" and never matched the subscription location "northcentralusstage". `az functionapp create --flexconsumption-location northcentralusstage` therefore failed with "Location is invalid" before creating any resources. Reuse _normalize_flex_location in both functions and make it also strip parentheses. ARM location names never contain parentheses, so existing matches are unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0eb1467a-223a-47a0-a810-3e7250c19520 Co-authored-by: Dobby <dobby@microsoft.com>
Member
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
The previous commit made stage regions pass the CLI location check as "northcentralusstage", but App Service only recognizes stage regions by their geo region name: creating the plan failed with "Cannot find GeoRegion with name northcentralusstage." App Service accepts "northcentralus(stage)". Keep the existing normalization and ignore parentheses only when matching subscription locations. `az functionapp list-flexconsumption-locations` now lists "northcentralus(stage)", and `az functionapp create --flexconsumption-location "northcentralus(stage)"` sends that name to App Service. Non-stage regions are unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0eb1467a-223a-47a0-a810-3e7250c19520 Co-authored-by: Dobby <dobby@microsoft.com>
Member
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
Registry deployment storage has no runtime, so functionAppConfig.runtime is null. _get_functionapp_runtime_info read it as a dict, so `az functionapp config appsettings set` and `az functionapp config set` failed with AttributeError before sending the update. Treat a missing runtime as not detected, as for other apps, so the runtime check is skipped. Found while validating Registry apps in North Central US (Stage). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0eb1467a-223a-47a0-a810-3e7250c19520 Co-authored-by: Dobby <dobby@microsoft.com>
Member
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Related command
az functionapp createaz functionapp deployment config setaz functionapp deployment config showaz functionapp showDescription
Flex Consumption apps can run a container image by setting
functionAppConfig.deployment.storage.typetoRegistry(Microsoft.Web API version2025-05-01). This PR adds CLI support for configuring it.New arguments, in a
Flex Registry Deploymentargument group onaz functionapp createandaz functionapp deployment config set:--deployment-image--deployment-image-auth-type--diatAnonymous,SystemAssignedIdentity,UserAssignedIdentity, orBasic.--deployment-image-identity--diiUserAssignedIdentityonly.--deployment-image-username-setting--diusBasiconly.--deployment-image-password-setting--dipsBasiconly.Behavior:
Basictakes username and password app-setting names; the CLI never accepts a registry password and never reads app settings.--deployment-image-server-url/--diurl. A newly constructedBasicauthentication object contains onlytype,usernameSettingName, andpasswordSettingName(noserverUrl). A site that already has a service-setserverUrlmay still show it and preserve it when authentication is not replaced; explicitly replacing authentication writes only the supplied mode's fields. This narrows the CLI from the current ADO task/GitHub Add missing pyyaml dependency in setup.py #86/Provide TSV (tab separated values) output formatter #88 optional-field criterion, without changing the Microsoft.Web API schema; owner confirmation and task-criterion alignment are pending.az functionapp create --deployment-image ...builds a RegistryfunctionAppConfigwithout a runtime and explicitly sendssiteUpdateStrategy.type = Recreate, matching the service default.--runtime,--runtime-version,--environment,--deployment-storage-*, and the legacy--registry-*arguments are rejected.--maximum-instance-countdefaults to 1000 for Registry creates (per review request, with owner sign-off still needed), and--instance-memorydefaults to 2048 MB; existing Blob create defaults are unchanged.--always-ready-instancesis supported, and Application Insights is created unless--disable-app-insightsis set. Registry image configuration does not automatically assign identities or grant registry access; use--assign-identity,--role AcrPull, and--scopefor that.az functionapp deployment config set --deployment-image ...reads the site at2025-05-01, updates onlydeployment.storage, removesfunctionAppConfig.runtime, and writes the site back with a single PUT at2025-05-01, so other properties are preserved. Switching from blob storage requires both the image and the authentication type; on an app that already uses Registry storage, either can be updated alone only when the retained counterpart is non-empty. The merged configuration must contain a non-empty image and authentication type before any PUT; supplying valid values can repair missing stored configuration. Blob and Registry arguments can't be combined, and blob arguments are rejected on Registry apps.az functionapp showandaz functionapp deployment config showuse their existing raw2023-12-01reads, without a Registry-specific second GET. The full returned JSON preserves Registry authentication and unknown fields without older-schema projection.show_functionappmatches the baseline implementation exactly; non-Flex apps and slots retain their existing SDK/configuration/publishing-information path. Credential values are never retrieved;Basicshows only the app setting names.2023-12-01GET, remove response-only null fields/runtime for Registry, and PUT Registry configuration at2025-05-01. Blob apps keep their original GET/PUT requests at2023-12-01.az functionapp runtime config setrejects Registry apps because they have no runtime. The explicit newer API remains on new Registry deployment writes to honor the published contract; redundant read/identity version switching has been removed.az functionapp identity assignandaz functionapp identity removeuse normal SDK API selection, without Registry-specific GET/PUT overrides, and preserve Basic authentication setting names and unknown configuration. The unused runtime and other modes' null fields are still omitted in the identity PUT. Real-SDK transport tests cover default-version requests for Registry Basic, Blob, and non-Flex apps; Blob and non-Flex requests remain unchanged.az functionapp config container) are unchanged.Testing Guide
Tests:
test_functionapp_commands_thru_mock.py:TestFlexRegistryDeploymentConfigMocked,TestFlexRegistryIdentityMocked,TestFlexRegistryCreateMocked, andTestFlexRegistryArgumentParsingcover exact request payloads and API versions for every authentication mode and image form, set/show round-trips through both show commands (blob requests unchanged), partial updates, missing/null/empty merged image/authentication rejection without writing, repair of invalid stored configuration, non-Flex app/slot routing, rejection of invalid arguments without writing, a service rejection followed by a show that returns the previous configuration, absence of secrets in debug logs and in set/show output, preservation of Registry authentication across scale/always-ready/update-strategy and real-SDK identity assign/remove writes with Blob HTTP requests unchanged, runtime-set rejection, create conflicts and defaults, legacy container markers never set on create (containerkind,linuxFxVersion,DOCKER_*settings), and argument aliases, including rejection of both removed server URL flags.test_functionapp_commands.py: live scenariotest_functionapp_flex_registry_deployment(FunctionAppFlexis aLiveScenarioTest) covers create, both show commands, identity andBasicupdates, digest and tag-plus-digest images, and a rejected update followed by show.Review and rollout
serverUrl. The complete mocked command test file passes against the actual CLI 2.91 source (68 tests, 58 subtests); full App Service pylint/PEP8 and the command/help linter with CI exclusions pass. Changed Python compilation, help YAML parsing, baseline show-implementation comparison, and whitespace checks also pass. Full remote CI and live Registry E2E are separate release gates. On this head, the repo-wide style jobs fail on the same pre-existing ACS, SQL, and CLI-core diagnostics seen on the prior head, with no App Service style diagnostics; live E2E has not run on this head and requires a Registry-enabled region and the published2025-05-01contract.History Notes
[App Service]
az functionapp create: Add--deployment-imageand related arguments to create Flex Consumption apps that run a container image[App Service]
az functionapp deployment config set: Add--deployment-imageand related arguments to configure container image deployment for Flex Consumption apps[App Service]
az functionapp show,az functionapp deployment config show: Return the container image deployment configuration of Flex Consumption apps[App Service]
az functionapp scale config set,az functionapp scale config always-ready set,az functionapp scale config always-ready delete,az functionapp update-strategy config set: Preserve Registry authentication in Flex configuration updates[App Service]
az functionapp identity assign,az functionapp identity remove: Preserve Registry authentication through identity changes[App Service]
az functionapp runtime config set: Explain that Registry-based Flex apps have no runtime to updateThis checklist is used to make sure that common guidelines for a pull request are followed.
The PR title and description has followed the guideline in Submitting Pull Requests.
I adhere to the Command Guidelines.
I adhere to the Error Handling Guidelines.