Skip to content

[AKS] az aks nodepool update: Allow Windows2022 to Windows2025 upgrades - #34141

Open
janenotjung-hue wants to merge 1 commit into
Azure:devfrom
janenotjung-hue:janejung/aks-windows2025-upgrade
Open

janenotjung-hue wants to merge 1 commit into
Azure:devfrom
janenotjung-hue:janejung/aks-windows2025-upgrade

Conversation

@janenotjung-hue

Copy link
Copy Markdown

Related command

az aks nodepool update --os-sku

az aks nodepool add --os-sku Windows2025

Description

Port the Windows Server upgrade support from azure-cli-extensions PR #10255 into the built-in AKS command module.

  • Allow Windows2022 and Windows2025 for az aks nodepool update --os-sku.
  • Default new Windows2025 node pools to a FIPS-enabled image, matching aks-preview.
  • Preserve update behavior: upgrading a non-FIPS Windows2022 pool requires an explicit --enable-fips-image; unrelated updates do not silently change FIPS.
  • Document the forward Windows2022-to-Windows2025 upgrade and add an example. Accepting both SKU values does not enable downgrades.
  • Add regression coverage for SKU choices, create-time FIPS defaults, invalid FIPS arguments, and the node-pool update request.

This reuses the existing agent-pool update API and SDK. It does not change cluster-creation OS SKU choices or add a new upgrade command.

Testing Guide

Local checks used the built-in CLI with no extensions installed:

python -m unittest \
  azure.cli.command_modules.acs.tests.latest.test_agentpool_decorator \
  azure.cli.command_modules.acs.tests.latest.test_validators \
  azure.cli.command_modules.acs.tests.latest.test_managed_cluster_decorator -q
azdev style acs
az aks nodepool update --help
az aks nodepool add --help
  • All 791 focused unit tests passed.
  • New regression cases reproduced the missing Windows update choices and Windows2025 FIPS default before the implementation was changed.
  • Pylint and flake8 passed, and the rendered help includes the new choices and FIPS guidance.
  • azdev linter acs --min-severity medium completed with exit code 0 and passed custom pylint rules. It also reported unrelated require_wait_command_if_no_wait findings for existing command groups.

A live AKS migration was not run. To exercise it against a supported Windows2022 pool, use core CLI without aks-preview:

az aks nodepool update \
  --resource-group MyResourceGroup \
  --cluster-name MyManagedCluster \
  --name npwin \
  --os-sku Windows2025 \
  --enable-fips-image

Confirm that the operation succeeds and returns osSku: Windows2025 and enableFips: true.

History Notes

[AKS] az aks nodepool update: Allow upgrading Windows2022 node pools to Windows2025 with --os-sku

[AKS] az aks nodepool add: Automatically enable FIPS images for Windows2025 node pools


  • The PR title and description follow the submitting-pull-requests guidelines.
  • I adhere to the Command Guidelines.
  • I adhere to the Error Handling Guidelines.

Port the aks-preview Windows OS SKU update choices and Windows2025 create-time FIPS defaults into core CLI. Document explicit FIPS enablement for migration and cover the request behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 35c75d7c-9ed3-432d-9b78-0de1f30a3339
@janenotjung-hue
janenotjung-hue requested review from a team and FumingZhang as code owners September 28, 2026 21:55
Copilot AI balanced review requested due to automatic review settings September 28, 2026 21:55
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation matches the stated behavior and includes focused regression coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Enables supported AKS Windows Server 2022-to-2025 node-pool upgrades while preserving FIPS behavior.

Changes:

  • Adds Windows2022 and Windows2025 update choices.
  • Defaults new Windows2025 pools to FIPS images.
  • Adds help guidance and regression coverage.
File Description
acs/​_params.py Adds Windows update SKU choices.
acs/​agentpool_decorator.py Applies the Windows2025 FIPS default.
acs/​_help.py Documents upgrade and FIPS requirements.
acs/​tests/​latest/​test_validators.py Verifies update SKU choices.
acs/​tests/​latest/​test_agentpool_decorator.py Tests create and update FIPS behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

@yonzhan

Copy link
Copy Markdown
Collaborator

Please fix CI issues

@yonzhan Yong Zhang (yonzhan) added this to the Backlog milestone Sep 29, 2026
@FumingZhang

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

act-observability-squad AKS az aks/acs/openshift Auto-Assign Auto assign by bot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants