Skip to content

[App Service] az functionapp create, az functionapp deployment config set: Add Flex Consumption Registry deployment storage support - #34147

Open
pragatikushwaha wants to merge 5 commits into
Azure:devfrom
pragatikushwaha:byoc/flex-registry-functionappconfig
Open

pragatikushwaha wants to merge 5 commits into
Azure:devfrom
pragatikushwaha:byoc/flex-registry-functionappconfig

Conversation

@pragatikushwaha

@pragatikushwaha pragatikushwaha commented Sep 29, 2026 •

Copy link
Copy Markdown

Related command
az functionapp create
az functionapp deployment config set
az functionapp deployment config show
az functionapp show

Description
Flex Consumption apps can run a container image by setting functionAppConfig.deployment.storage.type to Registry (Microsoft.Web API version 2025-05-01). This PR adds CLI support for configuring it.

New arguments, in a Flex Registry Deployment argument group on az functionapp create and az functionapp deployment config set:

Argument Alias Notes
--deployment-image Image reference (tag, digest, or tag and digest). Sent unchanged.
--deployment-image-auth-type --diat Anonymous, SystemAssignedIdentity, UserAssignedIdentity, or Basic.
--deployment-image-identity --dii User-assigned identity resource ID. UserAssignedIdentity only.
--deployment-image-username-setting --dius Name of the app setting that stores the registry username. Basic only.
--deployment-image-password-setting --dips Name of the app setting that stores the registry password. Basic only.

Behavior:

  • Each authentication mode sends exactly its own fields. Arguments that don't apply to the selected mode are rejected before any request is sent. Basic takes username and password app-setting names; the CLI never accepts a registry password and never reads app settings.
  • As requested in review, neither create nor config set accepts --deployment-image-server-url/--diurl. A newly constructed Basic authentication object contains only type, usernameSettingName, and passwordSettingName (no serverUrl). A site that already has a service-set serverUrl may still show it and preserve it when authentication is not replaced; explicitly replacing authentication writes only the supplied mode's fields. This narrows the CLI from the current ADO task/GitHub Add missing pyyaml dependency in setup.py #86/Provide TSV (tab separated values) output formatter  #88 optional-field criterion, without changing the Microsoft.Web API schema; owner confirmation and task-criterion alignment are pending.
  • The CLI doesn't parse or validate the image reference. Service validation errors are surfaced as returned.
  • az functionapp create --deployment-image ... builds a Registry functionAppConfig without a runtime. --runtime, --runtime-version, --environment, --deployment-storage-*, and the legacy --registry-* arguments are rejected. --maximum-instance-count defaults to 1000 for Registry creates (per review request, with owner sign-off still needed), and --instance-memory defaults to 2048 MB; existing Blob create defaults are unchanged. --always-ready-instances is supported, and Application Insights is created unless --disable-app-insights is set. Registry image configuration does not automatically assign identities or grant registry access; use --assign-identity, --role AcrPull, and --scope for that.
  • az functionapp deployment config set --deployment-image ... reads the site at 2025-05-01, updates only deployment.storage, removes functionAppConfig.runtime, and writes the site back with a single PUT at 2025-05-01, so other properties are preserved. Switching from blob storage requires both the image and the authentication type; on an app that already uses Registry storage, either can be updated alone. Blob and Registry arguments can't be combined, and blob arguments are rejected on Registry apps.
  • az functionapp show and az functionapp deployment config show re-read apps that use Registry storage at 2025-05-01, so they return the persisted Registry configuration, including its authentication fields. Blob storage apps keep their existing requests and output. Credential values are never retrieved; Basic shows only the app setting names.
  • Existing Flex scale, always-ready, and update-strategy writes also preserve Registry authentication: they re-read Registry apps at 2025-05-01, remove response-only null fields/runtime, and PUT at 2025-05-01. Blob apps keep their original GET/PUT requests at 2023-12-01. az functionapp runtime config set rejects Registry apps because they have no runtime.
  • Registry az functionapp identity assign and az functionapp identity remove re-read at 2025-05-01 and preserve Basic authentication setting names, omitting the unused runtime and other modes' null fields in the identity PUT. Blob apps keep their existing requests.
  • Existing blob storage behavior and legacy Linux container settings (az functionapp config container) are unchanged.

Testing Guide

# Create a Flex Consumption app that pulls from Azure Container Registry with its system-assigned identity
az functionapp create -g MyResourceGroup -n MyApp -s MyStorageAccount --flexconsumption-location eastus \
    --deployment-image myregistry.azurecr.io/myimage@sha256:<digest> --deployment-image-auth-type SystemAssignedIdentity \
    --assign-identity [system] --role AcrPull --scope <acr-resource-id>

# Switch an existing Flex Consumption app to a container image pulled with a user-assigned identity
az functionapp deployment config set -g MyResourceGroup -n MyApp --deployment-image myregistry.azurecr.io/myimage:v1 \
    --deployment-image-auth-type UserAssignedIdentity --deployment-image-identity <identity-resource-id>

# On the existing Registry app, change only the authentication to Basic, with the credentials stored in app settings
az functionapp deployment config set -g MyResourceGroup -n MyApp --deployment-image-auth-type Basic \
    --deployment-image-username-setting REGISTRY_USERNAME --deployment-image-password-setting REGISTRY_PASSWORD

# A subsequent scale update preserves the Registry Basic authentication references
az functionapp scale config set -g MyResourceGroup -n MyApp --maximum-instance-count 50
az functionapp deployment config show -g MyResourceGroup -n MyApp
az functionapp show -g MyResourceGroup -n MyApp --query properties.functionAppConfig

Tests:

  • test_functionapp_commands_thru_mock.py: TestFlexRegistryDeploymentConfigMocked, TestFlexRegistryIdentityMocked, TestFlexRegistryCreateMocked, and TestFlexRegistryArgumentParsing cover exact request payloads and API versions for every authentication mode and image form, set/show round-trips through both show commands (blob requests unchanged), partial updates, rejection of invalid arguments without writing, a service rejection followed by a show that returns the previous configuration, absence of secrets in debug logs and in set/show output, preservation of Registry authentication across scale/always-ready/update-strategy and real-SDK identity assign/remove writes with Blob HTTP requests unchanged, runtime-set rejection, create conflicts and defaults, legacy container markers never set on create (container kind, linuxFxVersion, DOCKER_* settings), and argument aliases, including rejection of both removed server URL flags.
  • test_functionapp_commands.py: live scenario test_functionapp_flex_registry_deployment (FunctionAppFlex is a LiveScenarioTest) covers create, both show commands, identity and Basic updates, digest and tag-plus-digest images, and a rejected update followed by show.

Review and rollout

  • Owner sign-off is needed for argument names/aliases, the Registry-only 1000 scale default (1000 is a documented scale-out ceiling, while the existing Blob default is 100), default Application Insights behavior, and this CLI-only omission of the optional service serverUrl. The mocked command test file passes (65 tests, 45 subtests); the appservice linter passes. Live Registry E2E has not run on this head; it requires a Registry-enabled region and the published 2025-05-01 contract.
  • Older Azure CLI versions can lose Registry Basic authentication references when changing other Flex configuration; use this version to make those changes. The current task contract accepts explicit tag-only, digest-only, and tag-plus-digest references; the CLI transmits them unchanged for service validation.

History Notes
[App Service] az functionapp create: Add --deployment-image and related arguments to create Flex Consumption apps that run a container image
[App Service] az functionapp deployment config set: Add --deployment-image and related arguments to configure container image deployment for Flex Consumption apps
[App Service] az functionapp show, az functionapp deployment config show: Return the container image deployment configuration of Flex Consumption apps
[App Service] az functionapp scale config set, az functionapp scale config always-ready set, az functionapp scale config always-ready delete, az functionapp update-strategy config set: Preserve Registry authentication in Flex configuration updates
[App Service] az functionapp identity assign, az functionapp identity remove: Preserve Registry authentication through identity changes
[App Service] az functionapp runtime config set: Explain that Registry-based Flex apps have no runtime to update


This checklist is used to make sure that common guidelines for a pull request are followed.

…fig set`: Add Flex Consumption Registry deployment storage support

Add --deployment-image, --deployment-image-auth-type, --deployment-image-identity,
--deployment-image-username-setting, --deployment-image-password-setting and
--deployment-image-server-url so Flex Consumption apps can run a container image from
functionAppConfig.deployment.storage of type Registry (Microsoft.Web 2025-05-01).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

…g show`: Return Flex Registry configuration with API version 2025-05-01

- Re-read Flex apps that use Registry deployment storage at 2025-05-01 so both show commands return the persisted Registry configuration. Blob storage apps keep their existing request and output.
- Tests: show round-trips for both show commands, a rejected update followed by show, secret-safe set/show output, and legacy container markers never set on create. The live scenario covers the same flows end to end.
- Help: describe what deployment config show returns for Registry storage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

… updates

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@pragatikushwaha
pragatikushwaha marked this pull request as ready for review September 29, 2026 11:21
@pragatikushwaha
pragatikushwaha requested a review from a team as a code owner September 29, 2026 11:21
Copilot AI balanced review requested due to automatic review settings September 29, 2026 11:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A post-create identity update can erase Basic Registry authentication fields by rewriting the site through an older API.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

Adds Flex Consumption Registry deployment storage support to App Service commands.

Changes:

  • Adds Registry image/authentication arguments and validation.
  • Uses API 2025-05-01 while preserving Registry configuration.
  • Adds help, mocked tests, and a live scenario.
File Description
utils.py Supports explicit API versions for raw reads.
custom.py Implements Registry create, update, show, and preservation logic.
_params.py Registers Registry deployment arguments.
_help.py Documents Registry workflows and examples.
_constants.py Defines auth modes, API version, and defaults.
test_functionapp_commands.py Adds live Registry coverage.
test_functionapp_commands_thru_mock.py Adds request, validation, and preservation tests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/azure-cli/azure/cli/command_modules/appservice/custom.py
Comment thread src/azure-cli/azure/cli/command_modules/appservice/_help.py Outdated
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

FLEX_REGISTRY_API_VERSION = '2025-05-01'

# Registry apps have no runtime stack to supply scale defaults, so use the Flex Consumption stack defaults.
FLEX_DEFAULT_MAXIMUM_INSTANCE_COUNT = 100

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why we need to set this?

Also 1000 seems tobe default for flex? https://learn.microsoft.com/en-us/azure/azure-functions/functions-scale#scale

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks. The Registry create path emits scaleAndConcurrency explicitly and does not look up the runtime-stack defaults used by Blob creates; 100 was an assumption here. Per the review request I changed the Registry-only maximum-instance fallback to 1000 in 5c8dc26, leaving the existing Blob default of 100 untouched. The linked Functions documentation gives 1000 as a supported scale-out ceiling, not an explicit service default. Could the feature owner confirm whether 1000 should be sent on Registry creates, or whether this property should instead be omitted to use a service default? I have left this thread open for that confirmation.

Comment thread src/azure-cli/azure/cli/command_modules/appservice/custom.py
…tity changes

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants