Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -147,6 +147,14 @@ def __init__(self):

DEPLOYMENT_STORAGE_AUTH_TYPES = ['SystemAssignedIdentity', 'UserAssignedIdentity', 'StorageAccountConnectionString']

FLEX_REGISTRY_AUTH_TYPES = ['Anonymous', 'SystemAssignedIdentity', 'UserAssignedIdentity', 'Basic']

FLEX_REGISTRY_API_VERSION = '2025-05-01'

# Registry apps have no runtime stack to supply scale defaults.
FLEX_DEFAULT_MAXIMUM_INSTANCE_COUNT = 1000
FLEX_DEFAULT_INSTANCE_MEMORY_MB = 2048

UPDATE_STRATEGY_TYPES = ['Recreate', 'RollingUpdate']

STORAGE_BLOB_DATA_CONTRIBUTOR_ROLE_ID = 'ba92f5b4-2d11-453d-a403-e96b0029c9fe'
26 changes: 26 additions & 0 deletions src/azure-cli/azure/cli/command_modules/appservice/_help.py
Original file line number Diff line number Diff line change
Expand Up @@ -596,16 +596,36 @@
helps['functionapp deployment config set'] = """
type: command
short-summary: Update an existing function app's deployment configuration.
long-summary: >
Use the --deployment-storage-* arguments for blob container deployment storage, or the --deployment-image
arguments for a Flex Consumption app that runs a container image (Registry deployment storage). Registry settings
are stored in the app's functionAppConfig and are separate from the legacy Linux container settings managed by
`az functionapp config container`. Switching to Registry removes the
functionAppConfig runtime. The service accepting the configuration doesn't prove that the registry is reachable,
that access is authorized, or that deployment succeeds. The CLI doesn't track tags; setting the same tag again
doesn't pull a newer image.
examples:
- name: Set the function app's deployment storage.
text: az functionapp deployment config set --name MyFunctionApp --resource-group MyResourceGroup --deployment-storage-name MyStorageAccount --deployment-storage-container-name MyStorageContainer
- name: Set the function app's deployment storage authentication method.
text: az functionapp deployment config set --name MyFunctionApp --resource-group MyResourceGroup --deployment-storage-auth-type userAssignedIdentity --deployment-storage-auth-value myAssignedId
- name: Run a public container image (Anonymous authentication).
text: az functionapp deployment config set --name MyFunctionApp --resource-group MyResourceGroup --deployment-image mcr.microsoft.com/azure-functions/dotnet-isolated:4-dotnet-isolated8.0 --deployment-image-auth-type Anonymous
- name: Pull a container image by digest with the app's system-assigned identity.
text: az functionapp deployment config set --name MyFunctionApp --resource-group MyResourceGroup --deployment-image myregistry.azurecr.io/myimage@sha256:<digest> --deployment-image-auth-type SystemAssignedIdentity
- name: Pull the container image with a user-assigned identity.
text: az functionapp deployment config set --name MyFunctionApp --resource-group MyResourceGroup --deployment-image myregistry.azurecr.io/myimage:v1 --deployment-image-auth-type UserAssignedIdentity --deployment-image-identity /subscriptions/<subscription-id>/resourceGroups/MyResourceGroup/providers/Microsoft.ManagedIdentity/userAssignedIdentities/MyIdentity
- name: Pull the container image with a username and password stored in app settings (Basic authentication).
text: az functionapp deployment config set --name MyFunctionApp --resource-group MyResourceGroup --deployment-image myregistry.azurecr.io/myimage:v1 --deployment-image-auth-type Basic --deployment-image-username-setting REGISTRY_USERNAME --deployment-image-password-setting REGISTRY_PASSWORD
"""

helps['functionapp deployment config show'] = """
type: command
short-summary: Get the details of a function app's deployment configuration.
long-summary: >
For Registry deployment storage, shows the image reference and authentication type, with the user-assigned
identity resource ID or the names of the app settings that hold Basic credentials. Credential values aren't
retrieved or shown.
examples:
- name: Get the details of a function app's deployment configuration.
text: az functionapp deployment config show --name MyFunctionApp --resource-group MyResourceGroup
Expand All @@ -624,6 +644,9 @@
helps['functionapp runtime config set'] = """
type: command
short-summary: Update an existing function app's runtime configuration.
long-summary: >
Registry deployment storage has no runtime. Use `az functionapp deployment config set` to update its container
image instead. This command updates the runtime for Flex apps using blob container deployment storage.
examples:
- name: Set the function app's runtime version.
text: az functionapp runtime config set --name MyFunctionApp --resource-group MyResourceGroup --runtime-version 3.11
Expand Down Expand Up @@ -780,6 +803,9 @@
- name: Create a flex consumption function app. See https://aka.ms/flex-http-concurrency for more information on default http concurrency values.
text: >
az functionapp create -g MyResourceGroup --name MyUniqueAppName -s MyStorageAccount --flexconsumption-location northeurope --runtime java --instance-memory 2048
- name: Create a flex consumption function app that runs a container image from Azure Container Registry, pulled with the app's system-assigned identity. The service accepting the configuration doesn't prove that the registry is reachable, that access is authorized, or that deployment succeeds.
text: >
az functionapp create -g MyResourceGroup --name MyUniqueAppName -s MyStorageAccount --flexconsumption-location northeurope --deployment-image myregistry.azurecr.io/myimage:v1 --deployment-image-auth-type SystemAssignedIdentity --assign-identity [system] --role AcrPull --scope /subscriptions/<subscription-id>/resourceGroups/MyResourceGroup/providers/Microsoft.ContainerRegistry/registries/myregistry
"""

helps['functionapp delete'] = """
Expand Down
18 changes: 17 additions & 1 deletion src/azure-cli/azure/cli/command_modules/appservice/_params.py
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,8 @@

from ._completers import get_hostname_completion_list
from ._constants import (FUNCTIONS_VERSIONS, LOGICAPPS_NODE_RUNTIME_VERSIONS, WINDOWS_OS_NAME, LINUX_OS_NAME,
DEPLOYMENT_STORAGE_AUTH_TYPES, UPDATE_STRATEGY_TYPES, ISOLATED_V4_SKUS)
DEPLOYMENT_STORAGE_AUTH_TYPES, UPDATE_STRATEGY_TYPES, ISOLATED_V4_SKUS,
FLEX_REGISTRY_AUTH_TYPES)

from ._validators import (validate_timeout_value, validate_site_create, validate_asp_create,
validate_ase_create, validate_ip_address,
Expand Down Expand Up @@ -1230,6 +1231,21 @@ def load_arguments(self, _):
"this should be the user assigned identity resource id. For the storage account connection string authentication type, this should be the name of the app setting that will contain the storage account connection "
"string. For the system assigned managed-identity authentication type, this parameter is not applicable and should be left empty.")

for scope in ['functionapp create', 'functionapp deployment config set']:
with self.argument_context(scope, arg_group='Flex Registry Deployment') as c:
c.argument('deployment_image', options_list=['--deployment-image'],
help="Container image for a Flex Consumption app, e.g. `myregistry.azurecr.io/myimage:v1` or `myregistry.azurecr.io/myimage@sha256:<digest>`. "
"Saved unchanged as the app's Registry deployment storage; the CLI doesn't validate, resolve, or pull it. Unrelated to legacy Linux container settings.")
c.argument('deployment_image_auth_type', options_list=['--deployment-image-auth-type', '--diat'], arg_type=get_enum_type(FLEX_REGISTRY_AUTH_TYPES),
help="How the platform authenticates to the registry: Anonymous (public image), SystemAssignedIdentity, UserAssignedIdentity (requires --deployment-image-identity), "
"or Basic (requires --deployment-image-username-setting and --deployment-image-password-setting). The CLI doesn't assign identities or grant registry access.")
c.argument('deployment_image_identity', options_list=['--deployment-image-identity', '--dii'],
help="Resource ID of the user-assigned managed identity used to pull the image. Only valid with UserAssignedIdentity. Saved as provided; the CLI doesn't create, look up, or assign it.")
c.argument('deployment_image_username_setting', options_list=['--deployment-image-username-setting', '--dius'],
help="Name of the app setting that stores the registry username. Only valid with Basic.")
c.argument('deployment_image_password_setting', options_list=['--deployment-image-password-setting', '--dips'],
help="Name of the app setting that stores the registry password. Only valid with Basic. Pass the app setting name, not the password.")

with self.argument_context('functionapp cors credentials') as c:
c.argument('enable', help='enable/disable access-control-allow-credentials', arg_type=get_three_state_flag())

Expand Down
Loading
Loading