Skip to content

{Network} az network firewall policy: Expose read-only afcManaged property and bump API version to 2025-09-01 - #10409

Merged
Ethan Yang (necusjz) merged 2 commits into
Azure:mainfrom
huiii99:network-firewall-policy-33903
Oct 1, 2026
Merged

Ethan Yang (necusjz) merged 2 commits into
Azure:mainfrom
huiii99:network-firewall-policy-33903

Conversation

@huiii99

@huiii99 Jian Hui (huiii99) commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Related command

az network firewall policy show / create / update / list / delete / wait

General Guidelines

  • Have you run azdev style <YOUR_EXT> locally? (pip install azdev required)
  • Have you run python scripts/ci/test_index.py -q locally? (pip install azdev required)
  • My extension version conforms to the Extension version schema

For new extensions:

About Extension Publish

There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update src/index.json automatically.
You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify src/index.json.

Description

Fixes Azure/azure-cli#33903
AAZ Azure/aaz#1108

Microsoft.Network/firewallPolicies now returns a read-only afcManaged boolean property indicating whether a firewall policy is managed by Azure Firewall Configuration (AFC) (see swagger PR Azure/azure-rest-api-specs#44867, minimum API version 2025-09-01). This PR:

  • Bumps the API version for az network firewall policy create/update/show/list/delete/wait (and intrusion-detection add/remove, which reuse the same underlying resource operations) from 2022-01-01 to 2025-09-01.
  • Exposes afcManaged as a read-only property in the command output (mainly visible via az network firewall policy show). No new write parameter (--afc-managed) is added, since the property is read-only in the swagger.
  • Does not expose the PUT-only query parameter afcManagedSync, since it is intended for the AFC service to write managed policies, not for general CLI users.
  • Fixes a couple of unrelated regressions surfaced by AAZ regeneration for the policy node so they don't leak into this PR:
    • Restored the --idps-profile argument name on create/update (regenerator had renamed it to --profile).
    • Disabled the newly generated --system-assigned/--user-assigned identity args on create to avoid duplicating the existing custom --identity argument.
    • Reverted incidental changes to network firewall policy deploy and rule-collection-group[/draft] collection command groups whose API version was not part of this change.

Testing Guide

# Requires API version >= 2025-09-01
az network firewall policy create -g MyRG -n MyPolicy --sku Premium
az network firewall policy show -g MyRG -n MyPolicy
# -> output now includes "afcManaged": false (read-only, set by the service)

Scenario tests updated/verified:

  • test_azure_firewall_policy (added self.check('afcManaged', False) assertion on show output)
  • test_azure_policy_idps_profiles
  • test_azure_firewall_policy_intrusion_detection
  • test_azure_firewall_policy_app_rules_with_custom_headers

VCR recordings for the affected commands were updated to api-version=2025-09-01.

History Notes

[Network] az network firewall policy show: Add read-only afcManaged property indicating whether the policy is managed by Azure Firewall Configuration (AFC)
{Network} az network firewall policy: Bump API version to 2025-09-01 for create/update/show/list/delete/wait

…ings to 2025-09-01

These 9 recording files were unrelated to the afcManaged/policy change but
failed CI (CannotOverwriteExistingCassetteException) because azure-cli core's
network public-ip create/show commands now default to api-version=2025-09-01
while the cassettes were recorded against 2024-07-01. Only blocks whose
CommandName is 'network public-ip *' were updated; unrelated blocks
(e.g. subnet/vnet show, still on 2024-07-01 upstream) were left untouched.
@huiii99
Jian Hui (huiii99) marked this pull request as ready for review September 30, 2026 06:27
Copilot AI balanced review requested due to automatic review settings September 30, 2026 06:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The regenerated update command introduces a misspelled IDPS argument group that splits related options in help output.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Updates Azure Firewall Policy commands to API 2025-09-01, exposing the read-only afcManaged property requested by Azure/azure-cli#33903.

Changes:

  • Regenerates policy operations and schemas for the new API.
  • Preserves existing identity and IDPS command interfaces.
  • Adds validation, recordings, release history, and version 2.3.0.
File Description
src/​azure-firewall/​setup.py Bumps the extension version.
src/​azure-firewall/​HISTORY.rst Documents the API and output changes.
src/​azure-firewall/​azext_firewall/​tests/​latest/​test_azure_firewall_scenario.py Verifies afcManaged output.
.../​recordings/​test_firewall_vhub_create_with_public_ip.yaml Refreshes public-IP API requests.
.../​recordings/​test_firewall_basic_sku.yaml Refreshes public-IP API requests.
.../​recordings/​test_azure_policy_rcg_draft.yaml Updates parent policy requests.
.../​recordings/​test_azure_firewall_with_firewall_policy_premium.yaml Updates policy requests.
.../​recordings/​test_azure_firewall_policy_rules_with_fqdns.yaml Updates policy requests.
.../​recordings/​test_azure_firewall_extended_location.yaml Refreshes public-IP API requests.
.../​recordings/​test_azure_firewall_autoscale_configuration.yaml Refreshes public-IP API requests.
src/​azure-firewall/​azext_firewall/​custom.py Hides duplicate generated identity arguments.
.../​policy/​_wait.py Updates wait schema and API version.
.../​policy/​_update.py Updates policy read/write schemas and API version.
.../​policy/​_show.py Exposes afcManaged in show output.
.../​policy/​_list.py Updates list operations and response schemas.
.../​policy/​_delete.py Updates delete to the new API.
.../​policy/​_create.py Updates create schema, identity handling, and API version.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@yonzhan Yong Zhang (yonzhan) added this to the Backlog milestone Sep 30, 2026
@yonzhan

Copy link
Copy Markdown
Collaborator

Network

@necusjz
Ethan Yang (necusjz) merged commit e380019 into Azure:main Oct 1, 2026
24 checks passed
@azclibot

Copy link
Copy Markdown
Collaborator

[Release] Update index.json for extension [ azure-firewall-2.3.0 ] : https://dev.azure.com/msazure/One/_build/results?buildId=183638995&view=results

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Network] Expose Azure Firewall for Containers (AFC) managed Firewall Policy on az network firewall policy

5 participants