Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions src/azure-firewall/HISTORY.rst
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,11 @@
Release History
===============

2.3.0
++++++
* `az network firewall policy show` : Expose read-only property `afcManaged` indicating whether the firewall policy is managed by Azure Firewall Configuration (AFC).
* Bump API version to `2025-09-01` for `az network firewall policy` create/update/show/list/delete/wait.

2.2.1
++++++
* `az network firewall create` : Fix `managementIpConfiguration.subnet.id` not being set for non-Basic tier firewalls when `--m-conf-name` is provided.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,9 +19,9 @@ class Create(AAZCommand):
"""

_aaz_info = {
"version": "2022-01-01",
"version": "2025-09-01",
"resources": [
["mgmt-plane", "/subscriptions/{}/resourcegroups/{}/providers/microsoft.network/firewallpolicies/{}", "2022-01-01"],
["mgmt-plane", "/subscriptions/{}/resourcegroups/{}/providers/microsoft.network/firewallpolicies/{}", "2025-09-01"],
]
}

Expand Down Expand Up @@ -63,13 +63,11 @@ def _build_arguments_schema(cls, *args, **kwargs):
_args_schema.sku = AAZStrArg(
options=["--sku"],
help="SKU of Firewall policy.",
is_preview=True,
enum={"Basic": "Basic", "Premium": "Premium", "Standard": "Standard"},
)
_args_schema.sql = AAZBoolArg(
options=["--sql"],
help="A flag to indicate if SQL Redirect traffic filtering is enabled.",
is_preview=True,
)
_args_schema.threat_intel_mode = AAZStrArg(
options=["--threat-intel-mode"],
Expand Down Expand Up @@ -141,7 +139,7 @@ def _build_arguments_schema(cls, *args, **kwargs):
)
explicit_proxy.pac_file = AAZStrArg(
options=["pac-file"],
help="URL for PAC file.",
help="SAS URL for PAC file.",
)
explicit_proxy.pac_file_port = AAZIntArg(
options=["pac-file-port"],
Expand All @@ -152,6 +150,25 @@ def _build_arguments_schema(cls, *args, **kwargs):
),
)

# define Arg Group "Identity"

_args_schema = cls._args_schema
_args_schema.mi_system_assigned = AAZStrArg(
options=["--system-assigned", "--mi-system-assigned"],
arg_group="Identity",
help="Set the system managed identity.",
blank="True",
)
_args_schema.mi_user_assigned = AAZListArg(
options=["--user-assigned", "--mi-user-assigned"],
arg_group="Identity",
help="Set the user managed identities.",
blank=[],
)

mi_user_assigned = cls._args_schema.mi_user_assigned
mi_user_assigned.Element = AAZStrArg()

# define Arg Group "Identity Instance"

_args_schema = cls._args_schema
Expand All @@ -172,24 +189,20 @@ def _build_arguments_schema(cls, *args, **kwargs):
blank={},
)

# define Arg Group "IntrusionDetection"

# define Arg Group "Intrustion Detection"

_args_schema = cls._args_schema
_args_schema.idps_mode = AAZStrArg(
options=["--idps-mode"],
arg_group="Intrustion Detection",
help="IDPS mode.",
is_preview=True,
enum={"Alert": "Alert", "Deny": "Deny", "Off": "Off"},
)

_args_schema.idps_profile = AAZStrArg(
options=["--idps-profile"],
arg_group="Intrusion Detection",
help="IDPS mode.",
is_preview=True,
help="IDPS profile name. When attached to a parent policy, the firewall's effective profile is the profile name of the parent policy.",
nullable=True,
enum={"Off": "Off", "Emerging": "Emerging", "Core": "Core", "Extended": "Extended"},
)
Expand Down Expand Up @@ -223,13 +236,11 @@ def _build_arguments_schema(cls, *args, **kwargs):
options=["--key-vault-secret-id"],
arg_group="TLS Inspection",
help="Secret Id of (base-64 encoded unencrypted pfx) Secret or Certificate object stored in KeyVault.",
is_preview=True,
)
_args_schema.cert_name = AAZStrArg(
options=["--cert-name"],
arg_group="TLS Inspection",
help="Name of the CA certificate.",
is_preview=True,
)

# define Arg Group "Threat Intel Allowlist"
Expand Down Expand Up @@ -352,7 +363,7 @@ def url_parameters(self):
def query_parameters(self):
parameters = {
**self.serialize_query_param(
"api-version", "2022-01-01",
"api-version", "2025-09-01",
required=True,
),
}
Expand All @@ -377,7 +388,7 @@ def content(self):
typ=AAZObjectType,
typ_kwargs={"flags": {"required": True, "client_flatten": True}}
)
_builder.set_prop("identity", AAZObjectType)
_builder.set_prop("identity", AAZIdentityObjectType)
_builder.set_prop("location", AAZStrType, ".location")
_builder.set_prop("properties", AAZObjectType, typ_kwargs={"flags": {"client_flatten": True}})
_builder.set_prop("tags", AAZDictType, ".tags")
Expand All @@ -386,11 +397,17 @@ def content(self):
if identity is not None:
identity.set_prop("type", AAZStrType, ".identity_type")
identity.set_prop("userAssignedIdentities", AAZDictType, ".user_assigned_identities")
identity.set_prop("userAssigned", AAZListType, ".mi_user_assigned", typ_kwargs={"flags": {"action": "create"}})
identity.set_prop("systemAssigned", AAZStrType, ".mi_system_assigned", typ_kwargs={"flags": {"action": "create"}})

user_assigned_identities = _builder.get(".identity.userAssignedIdentities")
if user_assigned_identities is not None:
user_assigned_identities.set_elements(AAZObjectType, ".")

user_assigned = _builder.get(".identity.userAssigned")
if user_assigned is not None:
user_assigned.set_elements(AAZStrType, ".")

properties = _builder.get(".properties")
if properties is not None:
properties.set_prop("basePolicy", AAZObjectType)
Expand Down Expand Up @@ -498,7 +515,7 @@ def _build_schema_on_200_201(cls):
flags={"read_only": True},
)
_schema_on_200_201.id = AAZStrType()
_schema_on_200_201.identity = AAZObjectType()
_schema_on_200_201.identity = AAZIdentityObjectType()
_schema_on_200_201.location = AAZStrType()
_schema_on_200_201.name = AAZStrType(
flags={"read_only": True},
Expand Down Expand Up @@ -539,6 +556,10 @@ def _build_schema_on_200_201(cls):
)

properties = cls._schema_on_200_201.properties
properties.afc_managed = AAZBoolType(
serialized_name="afcManaged",
flags={"read_only": True},
)
properties.base_policy = AAZObjectType(
serialized_name="basePolicy",
)
Expand All @@ -560,6 +581,10 @@ def _build_schema_on_200_201(cls):
properties.intrusion_detection = AAZObjectType(
serialized_name="intrusionDetection",
)
properties.kube_selector_groups = AAZListType(
serialized_name="kubeSelectorGroups",
flags={"read_only": True},
)
properties.provisioning_state = AAZStrType(
serialized_name="provisioningState",
flags={"read_only": True},
Expand All @@ -568,6 +593,9 @@ def _build_schema_on_200_201(cls):
serialized_name="ruleCollectionGroups",
flags={"read_only": True},
)
properties.size = AAZStrType(
flags={"read_only": True},
)
properties.sku = AAZObjectType()
properties.snat = AAZObjectType()
properties.sql = AAZObjectType()
Expand Down Expand Up @@ -716,6 +744,10 @@ def _build_schema_on_200_201(cls):
_element.id = AAZStrType()
_element.mode = AAZStrType()

kube_selector_groups = cls._schema_on_200_201.properties.kube_selector_groups
kube_selector_groups.Element = AAZObjectType()
_CreateHelper._build_schema_sub_resource_read(kube_selector_groups.Element)

rule_collection_groups = cls._schema_on_200_201.properties.rule_collection_groups
rule_collection_groups.Element = AAZObjectType()
_CreateHelper._build_schema_sub_resource_read(rule_collection_groups.Element)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,9 +19,9 @@ class Delete(AAZCommand):
"""

_aaz_info = {
"version": "2022-01-01",
"version": "2025-09-01",
"resources": [
["mgmt-plane", "/subscriptions/{}/resourcegroups/{}/providers/microsoft.network/firewallpolicies/{}", "2022-01-01"],
["mgmt-plane", "/subscriptions/{}/resourcegroups/{}/providers/microsoft.network/firewallpolicies/{}", "2025-09-01"],
]
}

Expand Down Expand Up @@ -139,7 +139,7 @@ def url_parameters(self):
def query_parameters(self):
parameters = {
**self.serialize_query_param(
"api-version", "2022-01-01",
"api-version", "2025-09-01",
required=True,
),
}
Expand Down
Loading
Loading