[App Service] az functionapp create, az functionapp deployment config set: Add Flex Consumption Registry deployment storage support - #34147
Conversation
…fig set`: Add Flex Consumption Registry deployment storage support Add --deployment-image, --deployment-image-auth-type, --deployment-image-identity, --deployment-image-username-setting, --deployment-image-password-setting and --deployment-image-server-url so Flex Consumption apps can run a container image from functionAppConfig.deployment.storage of type Registry (Microsoft.Web 2025-05-01). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
…g show`: Return Flex Registry configuration with API version 2025-05-01 - Re-read Flex apps that use Registry deployment storage at 2025-05-01 so both show commands return the persisted Registry configuration. Blob storage apps keep their existing request and output. - Tests: show round-trips for both show commands, a rejected update followed by show, secret-safe set/show output, and legacy container markers never set on create. The live scenario covers the same flows end to end. - Help: describe what deployment config show returns for Registry storage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
… updates Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
A post-create identity update can erase Basic Registry authentication fields by rewriting the site through an older API.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds Flex Consumption Registry deployment storage support to App Service commands.
Changes:
- Adds Registry image/authentication arguments and validation.
- Uses API
2025-05-01while preserving Registry configuration. - Adds help, mocked tests, and a live scenario.
| File | Description |
|---|---|
utils.py |
Supports explicit API versions for raw reads. |
custom.py |
Implements Registry create, update, show, and preservation logic. |
_params.py |
Registers Registry deployment arguments. |
_help.py |
Documents Registry workflows and examples. |
_constants.py |
Defines auth modes, API version, and defaults. |
test_functionapp_commands.py |
Adds live Registry coverage. |
test_functionapp_commands_thru_mock.py |
Adds request, validation, and preservation tests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
/azp run |
| FLEX_REGISTRY_API_VERSION = '2025-05-01' | ||
|
|
||
| # Registry apps have no runtime stack to supply scale defaults, so use the Flex Consumption stack defaults. | ||
| FLEX_DEFAULT_MAXIMUM_INSTANCE_COUNT = 100 |
There was a problem hiding this comment.
Why we need to set this?
Also 1000 seems tobe default for flex? https://learn.microsoft.com/en-us/azure/azure-functions/functions-scale#scale
There was a problem hiding this comment.
Thanks. The Registry create path emits scaleAndConcurrency explicitly and does not look up the runtime-stack defaults used by Blob creates; 100 was an assumption here. Per the review request I changed the Registry-only maximum-instance fallback to 1000 in 5c8dc26, leaving the existing Blob default of 100 untouched. The linked Functions documentation gives 1000 as a supported scale-out ceiling, not an explicit service default. Could the feature owner confirm whether 1000 should be sent on Registry creates, or whether this property should instead be omitted to use a service default? I have left this thread open for that confirmation.
…tity changes Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |


Related command
az functionapp createaz functionapp deployment config setaz functionapp deployment config showaz functionapp showDescription
Flex Consumption apps can run a container image by setting
functionAppConfig.deployment.storage.typetoRegistry(Microsoft.Web API version2025-05-01). This PR adds CLI support for configuring it.New arguments, in a
Flex Registry Deploymentargument group onaz functionapp createandaz functionapp deployment config set:--deployment-image--deployment-image-auth-type--diatAnonymous,SystemAssignedIdentity,UserAssignedIdentity, orBasic.--deployment-image-identity--diiUserAssignedIdentityonly.--deployment-image-username-setting--diusBasiconly.--deployment-image-password-setting--dipsBasiconly.Behavior:
Basictakes username and password app-setting names; the CLI never accepts a registry password and never reads app settings.--deployment-image-server-url/--diurl. A newly constructedBasicauthentication object contains onlytype,usernameSettingName, andpasswordSettingName(noserverUrl). A site that already has a service-setserverUrlmay still show it and preserve it when authentication is not replaced; explicitly replacing authentication writes only the supplied mode's fields. This narrows the CLI from the current ADO task/GitHub Add missing pyyaml dependency in setup.py #86/Provide TSV (tab separated values) output formatter #88 optional-field criterion, without changing the Microsoft.Web API schema; owner confirmation and task-criterion alignment are pending.az functionapp create --deployment-image ...builds a RegistryfunctionAppConfigwithout a runtime.--runtime,--runtime-version,--environment,--deployment-storage-*, and the legacy--registry-*arguments are rejected.--maximum-instance-countdefaults to 1000 for Registry creates (per review request, with owner sign-off still needed), and--instance-memorydefaults to 2048 MB; existing Blob create defaults are unchanged.--always-ready-instancesis supported, and Application Insights is created unless--disable-app-insightsis set. Registry image configuration does not automatically assign identities or grant registry access; use--assign-identity,--role AcrPull, and--scopefor that.az functionapp deployment config set --deployment-image ...reads the site at2025-05-01, updates onlydeployment.storage, removesfunctionAppConfig.runtime, and writes the site back with a single PUT at2025-05-01, so other properties are preserved. Switching from blob storage requires both the image and the authentication type; on an app that already uses Registry storage, either can be updated alone. Blob and Registry arguments can't be combined, and blob arguments are rejected on Registry apps.az functionapp showandaz functionapp deployment config showre-read apps that use Registry storage at2025-05-01, so they return the persisted Registry configuration, including its authentication fields. Blob storage apps keep their existing requests and output. Credential values are never retrieved;Basicshows only the app setting names.2025-05-01, remove response-only null fields/runtime, and PUT at2025-05-01. Blob apps keep their original GET/PUT requests at2023-12-01.az functionapp runtime config setrejects Registry apps because they have no runtime.az functionapp identity assignandaz functionapp identity removere-read at2025-05-01and preserve Basic authentication setting names, omitting the unused runtime and other modes' null fields in the identity PUT. Blob apps keep their existing requests.az functionapp config container) are unchanged.Testing Guide
Tests:
test_functionapp_commands_thru_mock.py:TestFlexRegistryDeploymentConfigMocked,TestFlexRegistryIdentityMocked,TestFlexRegistryCreateMocked, andTestFlexRegistryArgumentParsingcover exact request payloads and API versions for every authentication mode and image form, set/show round-trips through both show commands (blob requests unchanged), partial updates, rejection of invalid arguments without writing, a service rejection followed by a show that returns the previous configuration, absence of secrets in debug logs and in set/show output, preservation of Registry authentication across scale/always-ready/update-strategy and real-SDK identity assign/remove writes with Blob HTTP requests unchanged, runtime-set rejection, create conflicts and defaults, legacy container markers never set on create (containerkind,linuxFxVersion,DOCKER_*settings), and argument aliases, including rejection of both removed server URL flags.test_functionapp_commands.py: live scenariotest_functionapp_flex_registry_deployment(FunctionAppFlexis aLiveScenarioTest) covers create, both show commands, identity andBasicupdates, digest and tag-plus-digest images, and a rejected update followed by show.Review and rollout
serverUrl. The mocked command test file passes (65 tests, 45 subtests); the appservice linter passes. Live Registry E2E has not run on this head; it requires a Registry-enabled region and the published2025-05-01contract.History Notes
[App Service]
az functionapp create: Add--deployment-imageand related arguments to create Flex Consumption apps that run a container image[App Service]
az functionapp deployment config set: Add--deployment-imageand related arguments to configure container image deployment for Flex Consumption apps[App Service]
az functionapp show,az functionapp deployment config show: Return the container image deployment configuration of Flex Consumption apps[App Service]
az functionapp scale config set,az functionapp scale config always-ready set,az functionapp scale config always-ready delete,az functionapp update-strategy config set: Preserve Registry authentication in Flex configuration updates[App Service]
az functionapp identity assign,az functionapp identity remove: Preserve Registry authentication through identity changes[App Service]
az functionapp runtime config set: Explain that Registry-based Flex apps have no runtime to updateThis checklist is used to make sure that common guidelines for a pull request are followed.
The PR title and description has followed the guideline in Submitting Pull Requests.
I adhere to the Command Guidelines.
I adhere to the Error Handling Guidelines.