Skip to content

az deployment group create sends invalid JSON as deployment payload #32357

Description

Describe the bug

When using the az deployment group command I expect, that the API called under the hood (https://learn.microsoft.com/en-us/rest/api/resources/deployments/create-or-update?view=rest-resources-2025-04-01&tabs=HTTP) will receive a proper payload as described in the documentation, for instance:

PUT https://management.azure.com/subscriptions/00000000-0000-0000-0000-000000000001/resourcegroups/my-resource-group/providers/Microsoft.Resources/deployments/my-deployment?api-version=2025-04-01

{
  "properties": {
    "template": {
      "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
      "contentVersion": "1.0.0.0",
      "parameters": {
        "inputObj": {
          "type": "object"
        }
      },
      "resources": [],
      "outputs": {
        "inputObj": {
          "type": "object",
          "value": "[parameters('inputObj')]"
        }
      }
    },
    "parameters": {
      "inputObj": {
        "expression": "[createObject('foo', externalInputs('fooValue'))]"
      }
    },
    "externalInputDefinitions": {
      "fooValue": {
        "kind": "sys.envVar",
        "config": "FOO_VALUE"
      }
    },
    "externalInputs": {
      "fooValue": {
        "value": "baz"
      }
    },
    "mode": "Incremental"
  }
}

However, instead, it gets an invalid JSON as the template property isn't correctly serialized:

{"properties": {"parameters": {}, "mode": "Incremental", template:{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": []
}}}

Note that it happens only for a custom cloud environment created.

Related command

az deployment group create -n test-deployment --template-file templates/empty-deployment.json -g rg-test

Errors

The command failed with an unexpected error. Here is the traceback:
The content for this response was already consumed
Traceback (most recent call last):
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/init.py", line 703, in _run_job
result = cmd_copy(params)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/init.py", line 336, in call
return self.handler(*args, **kwargs)
~~~~~~~~~~~~^^^^^^^^^^^^^^^^^
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/command_operation.py", line 120, in handler
return op(**command_args)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/command_modules/resource/custom.py", line 602, in deploy_arm_template_at_resource_group
return _deploy_arm_template_at_resource_group(cmd=cmd,
resource_group_name=resource_group_name,
...<4 lines>...
no_prompt=no_prompt, template_spec=template_spec, query_string=query_string,
validation_level=validation_level)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/command_modules/resource/custom.py", line 661, in _deploy_arm_template_at_resource_group
return sdk_no_wait(no_wait, mgmt_client.begin_create_or_update, resource_group_name, deployment_name, deployment)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/util.py", line 759, in sdk_no_wait
return func(*args, **kwargs)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/core/tracing/decorator.py", line 119, in wrapper_use_tracer
return func(*args, **kwargs)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/mgmt/resource/deployments/operations/_deployments_operations.py", line 5411, in begin_create_or_update
raw_result = self._create_or_update_initial(
resource_group_name=resource_group_name,
...<7 lines>...
**kwargs
)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/mgmt/resource/deployments/operations/_deployments_operations.py", line 5304, in _create_or_update_initial
raise HttpResponseError(response=response, error_format=ARMErrorFormat)
azure.core.exceptions.HttpResponseError: (InternalError) Internal error: 't' is an invalid start of a property name. Expected a '"'. Path: $.properties | LineNumber: 0 | BytePositionInLine: 57.
Code: InternalError
Message: Internal error: 't' is an invalid start of a property name. Expected a '"'. Path: $.properties | LineNumber: 0 | BytePositionInLine: 57.

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/arm.py", line 109, in handle_template_based_exception
raise CLIError(ex.inner_exception.error.message)
^^^^^^^^^^^^^^^^^^^^^^^^
AttributeError: 'NoneType' object has no attribute 'error'

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/knack/cli.py", line 233, in invoke
cmd_result = self.invocation.execute(args)
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/init.py", line 666, in execute
raise ex
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/init.py", line 734, in _run_jobs_serially
results.append(self._run_job(expanded_arg, cmd_copy))
~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/init.py", line 726, in _run_job
return cmd_copy.exception_handler(ex)
~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/azure/cli/core/commands/arm.py", line 112, in handle_template_based_exception
raise_subdivision_deployment_error(ex.response.internal_response.text, ex.error.code if ex.error else None)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/requests/models.py", line 926, in text
if not self.content:
^^^^^^^^^^^^
File "/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/lib/python3.13/site-packages/requests/models.py", line 897, in content
raise RuntimeError("The content for this response was already consumed")
RuntimeError: The content for this response was already consumed

Issue script & Debug output

debug.log

Expected behavior

The provided template is correctly serialized and the command does not fail.

Environment Summary

azure-cli 2.78.0

core 2.78.0
telemetry 1.1.0

Extensions:
application-insights 1.2.3

Dependencies:
msal 1.34.0b1
azure-mgmt-resource 23.3.0

Python location '/opt/homebrew/Cellar/azure-cli/2.78.0/libexec/bin/python'
Config directory '/Users/kamilmrzyglod/.azure'
Extensions directory '/Users/kamilmrzyglod/.azure/cliextensions'

Python (Darwin) 3.13.9 (main, Oct 14 2025, 13:52:31) [Clang 17.0.0 (clang-1700.3.19.1)]

Legal docs and information: aka.ms/AzureCliLegal

Your CLI is up-to-date.

Additional context

No response

Activity

  1. added
    bugThis issue requires a change to an existing behavior in the product in order to be resolved.
    on Oct 30, 2025
  2. yonzhan commented on Oct 30, 2025

    @yonzhan
    Collaborator

    Thank you for opening this issue, we will look into it.

  3. microsoft-github-policy-service commented on Oct 30, 2025

    @microsoft-github-policy-service
    Contributor

    Thanks for the feedback! We are routing this to the appropriate team for follow-up. cc @Azure/deployments-owners.

  4. torreymicrosoft commented on Jun 9, 2026

    @torreymicrosoft
    Member

    Thanks for your patience — this was recently picked up as an outstanding open issue for the ARM Deployments team to review.

    Kamil Mrzygłód (@kamil-mrzyglod) — thanks, your diagnosis nailed it: the template property is being emitted unquoted in the request body, which is why ARM comes back with:

    (InternalError) Internal error: 't' is an invalid start of a property name. Expected a '"'.
    

    I deployed an equivalent output-only template on public cloud (CLI 2.85.0) and the payload serializes correctly and deploys — which matches your observation that this only reproduces on a custom cloud environment. So this looks like a real client-side serialization bug specific to the custom-cloud code path, where the deployment payload's template isn't being JSON-serialized the same way.

    (The trailing The content for this response was already consumed is a separate error-rendering bug that was fixed in 2.78+, so on a current CLI you'd see the ARM InternalError directly rather than that masking message.)

    I couldn't fully reproduce because it needs a registered custom cloud pointing at a custom Resource Manager endpoint. We'll look into this further. Thanks!

  5. azclibot commented on Jun 22, 2026

    @azclibot
    Collaborator

    Bug: az deployment group create sends invalid JSON for the template property

    Issue summary: When running az deployment group create against a custom cloud environment, the ARM deployment payload serializes the template property without quoting the key — producing template:{...} instead of "template":{...}. This causes an InternalError from the ARM API: 't' is an invalid start of a property name. Expected a '"'.

    Failing command:

    az deployment group create -n test-deployment --template-file templates/empty-deployment.json -g rg-test
    

    Repro context: Custom cloud environment (standard Azure public cloud is apparently unaffected). CLI version 2.78.0 on macOS (Apple Silicon).

    Root cause (from issue thread): The template property in the deployment properties dict is not being JSON-serialized before being embedded in the request body — the template dict is interpolated as a Python repr/str() instead of json.dumps(). The fix likely lives in azure/cli/command_modules/resource/custom.py around the _deploy_arm_template_at_resource_group function (line ~661), where the deployment object's template field should be properly serialized.

    Expected fix: Ensure the ARM deployment payload always serializes all nested dict/object properties (particularly template) as valid JSON, regardless of the cloud environment in use.

    PR title & description format (required)

    This repo enforces a PR format (guide). Please author the PR exactly as follows or CI's Check the Format of Pull Request Title and Content will fail.

    Title

    • Start with [Resource] — square brackets [] for a customer-facing change (added to HISTORY.rst), curly {} if not. A bug fix is customer-facing, so use [].
    • Then Fix #32357: to link the issue.
    • Then optionally the affected command az <command>:.
    • Then a present-tense, capitalized verb (Fix for bug fixes; Add/Change/Deprecate/Remove otherwise) and a concise summary.
    • Recommended title: [Resource] Fix #32357: az <command>: Fix <concise description of the fix>

    Description — follow the PR template and fill in:

    • Link the issue — start the Description with a closing keyword so the PR auto-links and closes it: Fixes #32357.
    • Related command — the az ... command this affects.
    • Description (mandatory) — why the bug happens, what you changed, and the resulting behavior.
    • Testing Guide — example command(s) showing the fix works.
    • History Notes — leave the title to drive the history note, or add [Resource] az <command>: <note> lines for extra notes.
    • Keep the template checklist and tick the items you've satisfied.

    Posted by agent-assist (autonomous bug-fix pipeline).

  6. added 2 commits that reference this issue on Jun 22, 2026
    ebbd723
    0272114
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Auto-AssignAuto assign by botAzure Deploymentsaz deployment/bicep/stack/deployment-scripts/ts/group exportService AttentionThis issue is responsible by Azure service team.act-codegen-extensibility-squadbugThis issue requires a change to an existing behavior in the product in order to be resolved.customer-reportedIssues that are reported by GitHub users external to the Azure organization.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions