Skip to content

[App Service] az functionapp create, az functionapp deployment config set: Add Flex Consumption Registry deployment storage support - #34147

Open
pragatikushwaha wants to merge 9 commits into
Azure:devfrom
pragatikushwaha:byoc/flex-registry-functionappconfig
Open

pragatikushwaha wants to merge 9 commits into
Azure:devfrom
pragatikushwaha:byoc/flex-registry-functionappconfig

Conversation

@pragatikushwaha

@pragatikushwaha pragatikushwaha commented Sep 29, 2026 •

Copy link
Copy Markdown

Related command
az functionapp create
az functionapp deployment config set
az functionapp deployment config show
az functionapp show

Description
Flex Consumption apps can run a container image by setting functionAppConfig.deployment.storage.type to Registry (Microsoft.Web API version 2025-05-01). This PR adds CLI support for configuring it.

New arguments, in a Flex Registry Deployment argument group on az functionapp create and az functionapp deployment config set:

Argument Alias Notes
--deployment-image Image reference (tag, digest, or tag and digest). Sent unchanged.
--deployment-image-auth-type --diat Anonymous, SystemAssignedIdentity, UserAssignedIdentity, or Basic.
--deployment-image-identity --dii User-assigned identity resource ID. UserAssignedIdentity only.
--deployment-image-username-setting --dius Name of the app setting that stores the registry username. Basic only.
--deployment-image-password-setting --dips Name of the app setting that stores the registry password. Basic only.

Behavior:

  • Each authentication mode sends exactly its own fields. Arguments that don't apply to the selected mode are rejected before any request is sent. Basic takes username and password app-setting names; the CLI never accepts a registry password and never reads app settings.
  • As requested in review, neither create nor config set accepts --deployment-image-server-url/--diurl. A newly constructed Basic authentication object contains only type, usernameSettingName, and passwordSettingName (no serverUrl). A site that already has a service-set serverUrl may still show it and preserve it when authentication is not replaced; explicitly replacing authentication writes only the supplied mode's fields. This narrows the CLI from the current ADO task/GitHub Add missing pyyaml dependency in setup.py #86/Provide TSV (tab separated values) output formatter  #88 optional-field criterion, without changing the Microsoft.Web API schema; owner confirmation and task-criterion alignment are pending.
  • The CLI requires a non-empty image but doesn't parse or validate OCI syntax. Service validation errors are surfaced as returned.
  • az functionapp create --deployment-image ... builds a Registry functionAppConfig without a runtime and explicitly sends siteUpdateStrategy.type = Recreate, matching the service default. --runtime, --runtime-version, --environment, --deployment-storage-*, and the legacy --registry-* arguments are rejected. --maximum-instance-count defaults to 1000 for Registry creates (per review request, with owner sign-off still needed), and --instance-memory defaults to 2048 MB; existing Blob create defaults are unchanged. --always-ready-instances is supported, and Application Insights is created unless --disable-app-insights is set. Registry image configuration does not automatically assign identities or grant registry access; use --assign-identity, --role AcrPull, and --scope for that.
  • az functionapp deployment config set --deployment-image ... reads the site at 2025-05-01, updates only deployment.storage, removes functionAppConfig.runtime, and writes the site back with a single PUT at 2025-05-01, so other properties are preserved. Switching from blob storage requires both the image and the authentication type; on an app that already uses Registry storage, either can be updated alone only when the retained counterpart is non-empty. The merged configuration must contain a non-empty image and authentication type before any PUT; supplying valid values can repair missing stored configuration. Blob and Registry arguments can't be combined, and blob arguments are rejected on Registry apps.
  • az functionapp show and az functionapp deployment config show use their existing raw 2023-12-01 reads, without a Registry-specific second GET. The full returned JSON preserves Registry authentication and unknown fields without older-schema projection. show_functionapp matches the baseline implementation exactly; non-Flex apps and slots retain their existing SDK/configuration/publishing-information path. Credential values are never retrieved; Basic shows only the app setting names.
  • Existing Flex scale, always-ready, and update-strategy writes also preserve Registry authentication: they use the existing raw 2023-12-01 GET, remove response-only null fields/runtime for Registry, and PUT Registry configuration at 2025-05-01. Blob apps keep their original GET/PUT requests at 2023-12-01. az functionapp runtime config set rejects Registry apps because they have no runtime. The explicit newer API remains on new Registry deployment writes to honor the published contract; redundant read/identity version switching has been removed.
  • Registry az functionapp identity assign and az functionapp identity remove use normal SDK API selection, without Registry-specific GET/PUT overrides, and preserve Basic authentication setting names and unknown configuration. The unused runtime and other modes' null fields are still omitted in the identity PUT. Real-SDK transport tests cover default-version requests for Registry Basic, Blob, and non-Flex apps; Blob and non-Flex requests remain unchanged.
  • Existing blob storage behavior and legacy Linux container settings (az functionapp config container) are unchanged.

Testing Guide

# Create a Flex Consumption app that pulls from Azure Container Registry with its system-assigned identity
az functionapp create -g MyResourceGroup -n MyApp -s MyStorageAccount --flexconsumption-location eastus \
    --deployment-image myregistry.azurecr.io/myimage@sha256:<digest> --deployment-image-auth-type SystemAssignedIdentity \
    --assign-identity [system] --role AcrPull --scope <acr-resource-id>

# Switch an existing Flex Consumption app to a container image pulled with a user-assigned identity
az functionapp deployment config set -g MyResourceGroup -n MyApp --deployment-image myregistry.azurecr.io/myimage:v1 \
    --deployment-image-auth-type UserAssignedIdentity --deployment-image-identity <identity-resource-id>

# On the existing Registry app, change only the authentication to Basic, with the credentials stored in app settings
az functionapp deployment config set -g MyResourceGroup -n MyApp --deployment-image-auth-type Basic \
    --deployment-image-username-setting REGISTRY_USERNAME --deployment-image-password-setting REGISTRY_PASSWORD

# A subsequent scale update preserves the Registry Basic authentication references
az functionapp scale config set -g MyResourceGroup -n MyApp --maximum-instance-count 50
az functionapp deployment config show -g MyResourceGroup -n MyApp
az functionapp show -g MyResourceGroup -n MyApp --query properties.functionAppConfig

Tests:

  • test_functionapp_commands_thru_mock.py: TestFlexRegistryDeploymentConfigMocked, TestFlexRegistryIdentityMocked, TestFlexRegistryCreateMocked, and TestFlexRegistryArgumentParsing cover exact request payloads and API versions for every authentication mode and image form, set/show round-trips through both show commands (blob requests unchanged), partial updates, missing/null/empty merged image/authentication rejection without writing, repair of invalid stored configuration, non-Flex app/slot routing, rejection of invalid arguments without writing, a service rejection followed by a show that returns the previous configuration, absence of secrets in debug logs and in set/show output, preservation of Registry authentication across scale/always-ready/update-strategy and real-SDK identity assign/remove writes with Blob HTTP requests unchanged, runtime-set rejection, create conflicts and defaults, legacy container markers never set on create (container kind, linuxFxVersion, DOCKER_* settings), and argument aliases, including rejection of both removed server URL flags.
  • test_functionapp_commands.py: live scenario test_functionapp_flex_registry_deployment (FunctionAppFlex is a LiveScenarioTest) covers create, both show commands, identity and Basic updates, digest and tag-plus-digest images, and a rejected update followed by show.

Review and rollout

  • Owner sign-off is needed for argument names/aliases, the Registry-only 1000 scale default (1000 is a documented scale-out ceiling, while the existing Blob default is 100), default Application Insights behavior, and this CLI-only omission of the optional service serverUrl. The complete mocked command test file passes against the actual CLI 2.91 source (68 tests, 58 subtests); full App Service pylint/PEP8 and the command/help linter with CI exclusions pass. Changed Python compilation, help YAML parsing, baseline show-implementation comparison, and whitespace checks also pass. Full remote CI and live Registry E2E are separate release gates. On this head, the repo-wide style jobs fail on the same pre-existing ACS, SQL, and CLI-core diagnostics seen on the prior head, with no App Service style diagnostics; live E2E has not run on this head and requires a Registry-enabled region and the published 2025-05-01 contract.
  • Preservation is validated for this CLI and its current SDK models; other CLI/SDK versions and other full-site writers require separate compatibility validation. No migration, new dependency, feature flag, or telemetry is introduced; rollback is a revert commit. The current task contract accepts explicit tag-only, digest-only, and tag-plus-digest references; the CLI transmits them unchanged for service validation.

History Notes
[App Service] az functionapp create: Add --deployment-image and related arguments to create Flex Consumption apps that run a container image
[App Service] az functionapp deployment config set: Add --deployment-image and related arguments to configure container image deployment for Flex Consumption apps
[App Service] az functionapp show, az functionapp deployment config show: Return the container image deployment configuration of Flex Consumption apps
[App Service] az functionapp scale config set, az functionapp scale config always-ready set, az functionapp scale config always-ready delete, az functionapp update-strategy config set: Preserve Registry authentication in Flex configuration updates
[App Service] az functionapp identity assign, az functionapp identity remove: Preserve Registry authentication through identity changes
[App Service] az functionapp runtime config set: Explain that Registry-based Flex apps have no runtime to update


This checklist is used to make sure that common guidelines for a pull request are followed.

…fig set`: Add Flex Consumption Registry deployment storage support

Add --deployment-image, --deployment-image-auth-type, --deployment-image-identity,
--deployment-image-username-setting, --deployment-image-password-setting and
--deployment-image-server-url so Flex Consumption apps can run a container image from
functionAppConfig.deployment.storage of type Registry (Microsoft.Web 2025-05-01).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

…g show`: Return Flex Registry configuration with API version 2025-05-01

- Re-read Flex apps that use Registry deployment storage at 2025-05-01 so both show commands return the persisted Registry configuration. Blob storage apps keep their existing request and output.
- Tests: show round-trips for both show commands, a rejected update followed by show, secret-safe set/show output, and legacy container markers never set on create. The live scenario covers the same flows end to end.
- Help: describe what deployment config show returns for Registry storage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

… updates

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@pragatikushwaha
pragatikushwaha marked this pull request as ready for review September 29, 2026 11:21
@pragatikushwaha
pragatikushwaha requested a review from a team as a code owner September 29, 2026 11:21
Copilot AI balanced review requested due to automatic review settings September 29, 2026 11:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A post-create identity update can erase Basic Registry authentication fields by rewriting the site through an older API.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

Adds Flex Consumption Registry deployment storage support to App Service commands.

Changes:

  • Adds Registry image/authentication arguments and validation.
  • Uses API 2025-05-01 while preserving Registry configuration.
  • Adds help, mocked tests, and a live scenario.
File Description
utils.py Supports explicit API versions for raw reads.
custom.py Implements Registry create, update, show, and preservation logic.
_params.py Registers Registry deployment arguments.
_help.py Documents Registry workflows and examples.
_constants.py Defines auth modes, API version, and defaults.
test_functionapp_commands.py Adds live Registry coverage.
test_functionapp_commands_thru_mock.py Adds request, validation, and preservation tests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/azure-cli/azure/cli/command_modules/appservice/custom.py
Comment thread src/azure-cli/azure/cli/command_modules/appservice/_help.py Outdated
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

Comment thread src/azure-cli/azure/cli/command_modules/appservice/_constants.py Outdated
Comment thread src/azure-cli/azure/cli/command_modules/appservice/custom.py
…tity changes

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

@yonzhan

Copy link
Copy Markdown
Collaborator

Please fix CI issues

Comment thread src/azure-cli/azure/cli/command_modules/appservice/custom.py Outdated
Comment thread src/azure-cli/azure/cli/command_modules/appservice/custom.py
Comment thread src/azure-cli/azure/cli/command_modules/appservice/custom.py Outdated
Comment thread src/azure-cli/azure/cli/command_modules/appservice/custom.py Outdated
Comment thread src/azure-cli/azure/cli/command_modules/appservice/custom.py
Set the explicit Recreate strategy for Registry creates, validate merged image/authentication before updates, and remove redundant Registry re-reads and identity API-version overrides while preserving the published API for new Registry writes. Cover default-version field preservation and unchanged non-Flex app/slot behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

list_flexconsumption_locations and list_flexconsumption_zone_redundant_locations
normalized geo region display names by lowercasing and removing spaces only, so
"North Central US (Stage)" became "northcentralus(stage)" and never matched the
subscription location "northcentralusstage". `az functionapp create
--flexconsumption-location northcentralusstage` therefore failed with
"Location is invalid" before creating any resources.

Reuse _normalize_flex_location in both functions and make it also strip
parentheses. ARM location names never contain parentheses, so existing
matches are unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0eb1467a-223a-47a0-a810-3e7250c19520
Co-authored-by: Dobby <dobby@microsoft.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

The previous commit made stage regions pass the CLI location check as
"northcentralusstage", but App Service only recognizes stage regions by their
geo region name: creating the plan failed with "Cannot find GeoRegion with name
northcentralusstage." App Service accepts "northcentralus(stage)".

Keep the existing normalization and ignore parentheses only when matching
subscription locations. `az functionapp list-flexconsumption-locations` now
lists "northcentralus(stage)", and `az functionapp create
--flexconsumption-location "northcentralus(stage)"` sends that name to App
Service. Non-stage regions are unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0eb1467a-223a-47a0-a810-3e7250c19520
Co-authored-by: Dobby <dobby@microsoft.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

Registry deployment storage has no runtime, so functionAppConfig.runtime is
null. _get_functionapp_runtime_info read it as a dict, so
`az functionapp config appsettings set` and `az functionapp config set`
failed with AttributeError before sending the update. Treat a missing
runtime as not detected, as for other apps, so the runtime check is skipped.

Found while validating Registry apps in North Central US (Stage).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0eb1467a-223a-47a0-a810-3e7250c19520
Co-authored-by: Dobby <dobby@microsoft.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants