Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions src/azure-cli/azure/cli/command_modules/acr/_constants.py
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,12 @@

USER_ASSIGNED_IDENTITY_RESOURCE_ID_TEMPLATE = '/subscriptions/{sub_id}/resourceGroups/{rg}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identity_name}'


class ConnectedRegistryAuthType(Enum):
SYNC_TOKEN = 'SyncToken'
MANAGED_IDENTITY = 'ManagedIdentity'


TASK_RESOURCE_TYPE = REGISTRY_RESOURCE_TYPE + '/tasks'
TASK_VALID_VSTS_URLS = ['visualstudio.com', 'dev.azure.com']
TASK_RESOURCE_ID_TEMPLATE = '/subscriptions/{sub_id}/resourceGroups/{rg}/providers/Microsoft.ContainerRegistry/registries/{reg}/tasks/{name}'
Expand Down
28 changes: 24 additions & 4 deletions src/azure-cli/azure/cli/command_modules/acr/_help.py
Original file line number Diff line number Diff line change
Expand Up @@ -1628,6 +1628,10 @@
helps['acr connected-registry create'] = """
type: command
short-summary: Create a connected registry for an Azure Container Registry.
long-summary: |
ManagedIdentity authentication requires --identity and cannot be combined with --parent, --sync-token, or --repository.
ManagedIdentity connected registries must be top-level and cannot have children.
If --auth-type is omitted, SyncToken authentication is used.
examples:
- name: Create a connected registry in registry mode with access to repos app/hello-world and service/mycomponent. It'll create a sync token and scope-map with the right repo permissions.
text: |
Expand All @@ -1642,6 +1646,11 @@
az acr connected-registry create -r mycloudregistry -n myreadonlyacr -p myconnectedregistry \\
--repository "app/mycomponent" -m ReadOnly -s "0 12 * * *" -w PT4H \\
--client-tokens myTokenName1 myTokenName2
- name: Create a connected registry that authenticates with its parent using a user-assigned managed identity.
text: |
az acr connected-registry create --registry mycloudregistry --name myconnectedregistry \\
--auth-type ManagedIdentity \\
--identity "/subscriptions/<SUBSCRIPTION ID>/resourceGroups/<RESOURCE GROUP>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myUserAssignedIdentity"
"""

helps['acr connected-registry delete'] = """
Expand Down Expand Up @@ -1701,6 +1710,10 @@
helps['acr connected-registry update'] = """
type: command
short-summary: Update a connected registry for an Azure Container Registry.
long-summary: |
Only one-way migration from SyncToken to ManagedIdentity authentication is supported.
The connected registry must have an Offline connection state before migration. If it is Online, run `az acr connected-registry deactivate` and wait until it is Offline.
Changing the managed identity of a connected registry already using ManagedIdentity authentication is not supported.
examples:
- name: Update the connected registry client Tokens.
text: |
Expand All @@ -1711,11 +1724,17 @@
text: |
az acr connected-registry update --registry mycloudregistry --name myreadonlyacr \\
--sync-schedule "0 12 * * *" --sync-window PT4H
- name: Migrate an offline connected registry from SyncToken to ManagedIdentity authentication.
text: |
az acr connected-registry update --registry mycloudregistry --name myconnectedregistry \\
--auth-type ManagedIdentity \\
--identity "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myUserAssignedIdentity"
"""

helps['acr connected-registry get-settings'] = """
type: command
short-summary: Retrieve information required to activate a connected registry, and creates or rotates the sync token credentials.
short-summary: Retrieve information required to activate a connected registry, optionally generating SyncToken credentials.
long-summary: ManagedIdentity settings do not require a sync token password and do not support --generate-password.
examples:
- name: Get the settings information required to install a connected registry without the password.
text: >
Expand All @@ -1727,12 +1746,12 @@

helps['acr connected-registry permissions'] = """
type: group
short-summary: Manage the repository permissions accross multiple connected registries. Please see https://aka.ms/acr/connected-registry for more information.
short-summary: Manage the repository permissions across multiple connected registries. Only supported for connected registries configured with SyncToken authentication (output is derived from the sync-token scope map). Please see https://aka.ms/acr/connected-registry for more information.
"""

helps['acr connected-registry permissions update'] = """
type: command
short-summary: Add and remove repository permissions accross all the necessary connected registry sync scope maps.
short-summary: Add and remove repository permissions across all the necessary connected registry sync scope maps. Only supported for connected registries configured with SyncToken authentication.
examples:
- name: Add permissions to synchronize images from 'repo1' and 'repo2' to the connected registry 'myconnectedregistry' and its ancestors.
text: >
Expand All @@ -1747,7 +1766,7 @@

helps['acr connected-registry permissions show'] = """
type: command
short-summary: Show the connected registry sync scope map information.
short-summary: Show the connected registry sync scope map information. Only supported for connected registries configured with SyncToken authentication.
examples:
- name: Show details and attributes of a sync scope map for a connected registry.
text: >
Expand All @@ -1772,6 +1791,7 @@
helps['acr connected-registry install renew-credentials'] = """
type: command
short-summary: Retrieve information required to activate a connected registry, and renews the sync token credentials.
long-summary: Only supported for connected registries configured with SyncToken authentication.
examples:
- name: Set http as the parent protocol, and prints the values in json format required to activate a connected registry and the newly generated sync token credentials.
text: >
Expand Down
9 changes: 7 additions & 2 deletions src/azure-cli/azure/cli/command_modules/acr/_params.py
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@

from ._constants import (
AbacRoleAssignmentMode,
ConnectedRegistryAuthType,
REGISTRY_RESOURCE_TYPE,
WEBHOOK_RESOURCE_TYPE,
REPLICATION_RESOURCE_TYPE,
Expand Down Expand Up @@ -564,12 +565,12 @@ def load_arguments(self, _): # pylint: disable=too-many-statements
c.argument('parent_name', options_list=['--parent', '-p'], help='The name of the parent connected registry.')
c.argument('repositories', options_list=['--repository'], nargs='+', help='Specify the repositories that need to be sync to the connected registry. It can be in the format [REPO01] [REPO02]...')
c.argument('sync_token_name', options_list=['--sync-token'], help='Specifies the sync token used to synchronize the connected registry with its parent. It most have only repo permissions and at least the actions required for its mode. It can include access for multiple repositories.')
c.argument('cleanup', help='It will aslo delete the sync token and the scope map resources.')
c.argument('cleanup', help='Delete the associated sync token and scope map for a connected registry configured with SyncToken authentication. This option has no effect for a connected registry configured with ManagedIdentity authentication. The connected registry is still deleted, but the managed identity and role assignments are retained.')
c.argument('no_children', help='Used to remove all children from the list.', action='store_true')
c.argument('sync_audit_logs_enabled', options_list=['--audit-logs-enabled'], help='Indicate whether audit log synchronization is enabled. It is enabled by default.', required=False, arg_type=get_three_state_flag(), deprecate_info=c.deprecate(hide=True))

c.argument('parent_protocol', arg_type=get_enum_type(['http', 'https']), options_list=['--parent-protocol'], help='Specify the protocol used to communicate with its parent.', required=True)
c.argument('generate_password', arg_type=get_enum_type(['1', '2']), options_list=['--generate-password'], help='Select which password you want to generate, and it is required to retrieve the password from the sync token.')
c.argument('generate_password', arg_type=get_enum_type(['1', '2']), options_list=['--generate-password'], help='Select which password you want to generate, and it is required to retrieve the password from the sync token. Not supported for a connected registry configured with ManagedIdentity authentication.')

with self.argument_context('acr connected-registry create') as c:
c.argument('log_level', help='Set the log level for logging on the instance. Accepted log levels are Debug, Information, Warning, Error, and None.', required=False, default="Information")
Expand All @@ -583,6 +584,8 @@ def load_arguments(self, _): # pylint: disable=too-many-statements
help='Indicate whether garbage collection is enabled. It is enabled by default.', arg_type=get_three_state_flag(), required=False, default="true")
c.argument('garbage_collection_schedule', options_list=['--gc-schedule'],
help='Used to determine garbage collection schedule. Uses cron expression to determine the schedule. If not specified, garbage collection is set to run once a day.', required=False, default="0 0 * * *")
c.argument('identity', help='Resource ID of a user-assigned managed identity to authenticate the connected registry with its parent. Required when --auth-type is ManagedIdentity.')
c.argument('auth_type', arg_type=get_enum_type([e.value for e in ConnectedRegistryAuthType]), options_list=['--auth-type'], help='Authentication type used by the connected registry to sync with its parent. Defaults to SyncToken.')

with self.argument_context('acr connected-registry update') as c:
c.argument('log_level', help='Set the log level for logging on the instance. Accepted log levels are Debug, Information, Warning, Error, and None.')
Expand All @@ -600,6 +603,8 @@ def load_arguments(self, _): # pylint: disable=too-many-statements
c.argument('garbage_collection_enabled', options_list=['--gc-enabled'],
help='Indicate whether garbage collection is enabled. It is enabled by default.', arg_type=get_three_state_flag())
c.argument('garbage_collection_schedule', options_list=['--gc-schedule'], help='Used to determine garbage collection schedule. Uses cron expression to determine the schedule. If not specified, garbage collection is set to run once a day.')
c.argument('identity', help='Resource ID of a user-assigned managed identity. Requires --auth-type ManagedIdentity.')
c.argument('auth_type', arg_type=get_enum_type([ConnectedRegistryAuthType.MANAGED_IDENTITY.value]), options_list=['--auth-type'], help='Target authentication type. Only one-way migration from SyncToken to ManagedIdentity is supported.')
with self.argument_context('acr connected-registry permissions') as c:
c.argument('add_repos', options_list=['--add'], nargs='*',
help='repository permissions to be added to the targeted connected registry and it\'s ancestors sync scope maps. Use the format "--add [REPO1 REPO2 ...]" per flag. ' + repo_valid_actions)
Expand Down
Loading
Loading