Repository navigation
az deployment group create sends invalid JSON as deployment payload #32357
Description
Activity
- addedbugThis issue requires a change to an existing behavior in the product in order to be resolved.This issue requires a change to an existing behavior in the product in order to be resolved.
on Oct 30, 2025 - addedcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.Auto-AssignAuto assign by botAuto assign by botAzure Deploymentsaz deployment/bicep/stack/deployment-scripts/ts/group exportaz deployment/bicep/stack/deployment-scripts/ts/group export
on Oct 30, 2025 Thank you for opening this issue, we will look into it.
- addedService AttentionThis issue is responsible by Azure service team.This issue is responsible by Azure service team.
on Oct 30, 2025 microsoft-github-policy-service commented
on Oct 30, 2025 ContributorMore actionsThanks for the feedback! We are routing this to the appropriate team for follow-up. cc @Azure/deployments-owners.
torreymicrosoft commented
on Jun 9, 2026 MemberMore actionsThanks for your patience — this was recently picked up as an outstanding open issue for the ARM Deployments team to review.
Kamil Mrzygłód (@kamil-mrzyglod) — thanks, your diagnosis nailed it: the
templateproperty is being emitted unquoted in the request body, which is why ARM comes back with:(InternalError) Internal error: 't' is an invalid start of a property name. Expected a '"'.I deployed an equivalent output-only template on public cloud (CLI 2.85.0) and the payload serializes correctly and deploys — which matches your observation that this only reproduces on a custom cloud environment. So this looks like a real client-side serialization bug specific to the custom-cloud code path, where the deployment payload's
templateisn't being JSON-serialized the same way.(The trailing
The content for this response was already consumedis a separate error-rendering bug that was fixed in 2.78+, so on a current CLI you'd see the ARMInternalErrordirectly rather than that masking message.)I couldn't fully reproduce because it needs a registered custom cloud pointing at a custom Resource Manager endpoint. We'll look into this further. Thanks!
Reacted by Kamil MrzygłódBug:
az deployment group createsends invalid JSON for thetemplatepropertyIssue summary: When running
az deployment group createagainst a custom cloud environment, the ARM deployment payload serializes thetemplateproperty without quoting the key — producingtemplate:{...}instead of"template":{...}. This causes anInternalErrorfrom the ARM API:'t' is an invalid start of a property name. Expected a '"'.Failing command:
az deployment group create -n test-deployment --template-file templates/empty-deployment.json -g rg-testRepro context: Custom cloud environment (standard Azure public cloud is apparently unaffected). CLI version 2.78.0 on macOS (Apple Silicon).
Root cause (from issue thread): The
templateproperty in the deployment properties dict is not being JSON-serialized before being embedded in the request body — the template dict is interpolated as a Pythonrepr/str()instead ofjson.dumps(). The fix likely lives inazure/cli/command_modules/resource/custom.pyaround the_deploy_arm_template_at_resource_groupfunction (line ~661), where thedeploymentobject'stemplatefield should be properly serialized.Expected fix: Ensure the ARM deployment payload always serializes all nested dict/object properties (particularly
template) as valid JSON, regardless of the cloud environment in use.PR title & description format (required)
This repo enforces a PR format (guide). Please author the PR exactly as follows or CI's Check the Format of Pull Request Title and Content will fail.
Title
- Start with
[Resource]— square brackets[]for a customer-facing change (added toHISTORY.rst), curly{}if not. A bug fix is customer-facing, so use[]. - Then
Fix #32357:to link the issue. - Then optionally the affected command
az <command>:. - Then a present-tense, capitalized verb (Fix for bug fixes; Add/Change/Deprecate/Remove otherwise) and a concise summary.
- Recommended title:
[Resource] Fix #32357: az <command>: Fix <concise description of the fix>
Description — follow the PR template and fill in:
- Link the issue — start the Description with a closing keyword so the PR auto-links and closes it:
Fixes #32357. - Related command — the
az ...command this affects. - Description (mandatory) — why the bug happens, what you changed, and the resulting behavior.
- Testing Guide — example command(s) showing the fix works.
- History Notes — leave the title to drive the history note, or add
[Resource] az <command>: <note>lines for extra notes. - Keep the template checklist and tick the items you've satisfied.
Posted by agent-assist (autonomous bug-fix pipeline).
- Start with
- added 2 commits that reference this issue
on Jun 22, 2026
Describe the bug
When using the
az deployment group commandI expect, that the API called under the hood (https://learn.microsoft.com/en-us/rest/api/resources/deployments/create-or-update?view=rest-resources-2025-04-01&tabs=HTTP) will receive a proper payload as described in the documentation, for instance:However, instead, it gets an invalid JSON as the
templateproperty isn't correctly serialized:Note that it happens only for a custom cloud environment created.
Related command
az deployment group create -n test-deployment --template-file templates/empty-deployment.json -g rg-test
Errors
The command failed with an unexpected error. Here is the traceback:
The content for this response was already consumed
Traceback (most recent call last):
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/init.py", line 703, in _run_job
result = cmd_copy(params)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/init.py", line 336, in call
return self.handler(*args, **kwargs)
~~~~~~~~~~~~^^^^^^^^^^^^^^^^^
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/command_operation.py", line 120, in handler
return op(**command_args)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/command_modules/resource/custom.py", line 602, in deploy_arm_template_at_resource_group
return _deploy_arm_template_at_resource_group(cmd=cmd,
resource_group_name=resource_group_name,
...<4 lines>...
no_prompt=no_prompt, template_spec=template_spec, query_string=query_string,
validation_level=validation_level)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/command_modules/resource/custom.py", line 661, in _deploy_arm_template_at_resource_group
return sdk_no_wait(no_wait, mgmt_client.begin_create_or_update, resource_group_name, deployment_name, deployment)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/util.py", line 759, in sdk_no_wait
return func(*args, **kwargs)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/core/tracing/decorator.py", line 119, in wrapper_use_tracer
return func(*args, **kwargs)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/mgmt/resource/deployments/operations/_deployments_operations.py", line 5411, in begin_create_or_update
raw_result = self._create_or_update_initial(
resource_group_name=resource_group_name,
...<7 lines>...
**kwargs
)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/mgmt/resource/deployments/operations/_deployments_operations.py", line 5304, in _create_or_update_initial
raise HttpResponseError(response=response, error_format=ARMErrorFormat)
azure.core.exceptions.HttpResponseError: (InternalError) Internal error: 't' is an invalid start of a property name. Expected a '"'. Path: $.properties | LineNumber: 0 | BytePositionInLine: 57.
Code: InternalError
Message: Internal error: 't' is an invalid start of a property name. Expected a '"'. Path: $.properties | LineNumber: 0 | BytePositionInLine: 57.
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/arm.py", line 109, in handle_template_based_exception
raise CLIError(ex.inner_exception.error.message)
^^^^^^^^^^^^^^^^^^^^^^^^
AttributeError: 'NoneType' object has no attribute 'error'
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/knack/cli.py", line 233, in invoke
cmd_result = self.invocation.execute(args)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/init.py", line 666, in execute
raise ex
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/init.py", line 734, in _run_jobs_serially
results.append(self._run_job(expanded_arg, cmd_copy))
~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/init.py", line 726, in _run_job
return cmd_copy.exception_handler(ex)
~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/arm.py", line 112, in handle_template_based_exception
raise_subdivision_deployment_error(ex.response.internal_response.text, ex.error.code if ex.error else None)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/requests/models.py", line 926, in text
if not self.content:
^^^^^^^^^^^^
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/requests/models.py", line 897, in content
raise RuntimeError("The content for this response was already consumed")
RuntimeError: The content for this response was already consumed
Issue script & Debug output
debug.log
Expected behavior
The provided template is correctly serialized and the command does not fail.
Environment Summary
azure-cli 2.78.0
core 2.78.0
telemetry 1.1.0
Extensions:
application-insights 1.2.3
Dependencies:
msal 1.34.0b1
azure-mgmt-resource 23.3.0
Python location '/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/bin/python'
Config directory '/Users/kamilmrzyglod/.azure'
Extensions directory '/Users/kamilmrzyglod/.azure/cliextensions'
Python (Darwin) 3.13.9 (main, Oct 14 2025, 13:52:31) [Clang 17.0.0 (clang-1700.3.19.1)]
Legal docs and information: aka.ms/AzureCliLegal
Your CLI is up-to-date.
Additional context
No response