Skip to content

{ARM} az policy: Rewrite Azure Policy CRUD commands using auto-generation#31496

Merged
zhoxing-ms merged 20 commits intoAzure:devfrom
mentat9:feature-policy
Aug 26, 2025
Merged

{ARM} az policy: Rewrite Azure Policy CRUD commands using auto-generation#31496
zhoxing-ms merged 20 commits intoAzure:devfrom
mentat9:feature-policy

Conversation

@mentat9
Copy link
Copy Markdown
Member

@mentat9 mentat9 commented May 16, 2025

Related command

az policy assignment {create, delete, list, show, update}
az policy assignment identity {assign, remove, show}
az policy assignment non-compliance-message {create, delete, list, show, update}
az policy definition {create, delete, list, show, update}
az policy exemption {create, delete, list, show, update}
az policy set-definition {create, delete, list, show, update}

Description

Reimplement all azure policy CRUD commands using the auto-generation toolset with customization.
Remove existing custom implementations.

Testing Guide

All tests are updated and passing in record and playback modes.
Few new tests added.

History Notes

{ARM} Rewrite Azure Policy CRUD commands using auto generation toolset
{ARM} Rerecord tests
{ARM} Reorganize tests for simpler code and better cleanup
{ARM} Add setup for recording attestation tests


This checklist is used to make sure that common guidelines for a pull request are followed.

Copilot AI review requested due to automatic review settings May 16, 2025 22:26
@azure-client-tools-bot-prd
Copy link
Copy Markdown

azure-client-tools-bot-prd bot commented May 16, 2025

️✔️AzureCLI-FullTest
️✔️acr
️✔️latest
️✔️3.12
️✔️3.13
️✔️acs
️✔️latest
️✔️3.12
️✔️3.13
️✔️advisor
️✔️latest
️✔️3.12
️✔️3.13
️✔️ams
️✔️latest
️✔️3.12
️✔️3.13
️✔️apim
️✔️latest
️✔️3.12
️✔️3.13
️✔️appconfig
️✔️latest
️✔️3.12
️✔️3.13
️✔️appservice
️✔️latest
️✔️3.12
️✔️3.13
️✔️aro
️✔️latest
️✔️3.12
️✔️3.13
️✔️backup
️✔️latest
️✔️3.12
️✔️3.13
️✔️batch
️✔️latest
️✔️3.12
️✔️3.13
️✔️batchai
️✔️latest
️✔️3.12
️✔️3.13
️✔️billing
️✔️latest
️✔️3.12
️✔️3.13
️✔️botservice
️✔️latest
️✔️3.12
️✔️3.13
️✔️cdn
️✔️latest
️✔️3.12
️✔️3.13
️✔️cloud
️✔️latest
️✔️3.12
️✔️3.13
️✔️cognitiveservices
️✔️latest
️✔️3.12
️✔️3.13
️✔️compute_recommender
️✔️latest
️✔️3.12
️✔️3.13
️✔️computefleet
️✔️latest
️✔️3.12
️✔️3.13
️✔️config
️✔️latest
️✔️3.12
️✔️3.13
️✔️configure
️✔️latest
️✔️3.12
️✔️3.13
️✔️consumption
️✔️latest
️✔️3.12
️✔️3.13
️✔️container
️✔️latest
️✔️3.12
️✔️3.13
️✔️containerapp
️✔️latest
️✔️3.12
️✔️3.13
️✔️core
️✔️latest
️✔️3.12
️✔️3.13
️✔️cosmosdb
️✔️latest
️✔️3.12
️✔️3.13
️✔️databoxedge
️✔️latest
️✔️3.12
️✔️3.13
️✔️dls
️✔️latest
️✔️3.12
️✔️3.13
️✔️dms
️✔️latest
️✔️3.12
️✔️3.13
️✔️eventgrid
️✔️latest
️✔️3.12
️✔️3.13
️✔️eventhubs
️✔️latest
️✔️3.12
️✔️3.13
️✔️feedback
️✔️latest
️✔️3.12
️✔️3.13
️✔️find
️✔️latest
️✔️3.12
️✔️3.13
️✔️hdinsight
️✔️latest
️✔️3.12
️✔️3.13
️✔️identity
️✔️latest
️✔️3.12
️✔️3.13
️✔️iot
️✔️latest
️✔️3.12
️✔️3.13
️✔️keyvault
️✔️latest
️✔️3.12
️✔️3.13
️✔️lab
️✔️latest
️✔️3.12
️✔️3.13
️✔️managedservices
️✔️latest
️✔️3.12
️✔️3.13
️✔️maps
️✔️latest
️✔️3.12
️✔️3.13
️✔️marketplaceordering
️✔️latest
️✔️3.12
️✔️3.13
️✔️monitor
️✔️latest
️✔️3.12
️✔️3.13
️✔️mysql
️✔️latest
️✔️3.12
️✔️3.13
️✔️netappfiles
️✔️latest
️✔️3.12
️✔️3.13
️✔️network
️✔️latest
️✔️3.12
️✔️3.13
️✔️policyinsights
️✔️latest
️✔️3.12
️✔️3.13
️✔️privatedns
️✔️latest
️✔️3.12
️✔️3.13
️✔️profile
️✔️latest
️✔️3.12
️✔️3.13
️✔️rdbms
️✔️latest
️✔️3.12
️✔️3.13
️✔️redis
️✔️latest
️✔️3.12
️✔️3.13
️✔️relay
️✔️latest
️✔️3.12
️✔️3.13
️✔️resource
️✔️latest
️✔️3.12
️✔️3.13
️✔️role
️✔️latest
️✔️3.12
️✔️3.13
️✔️search
️✔️latest
️✔️3.12
️✔️3.13
️✔️security
️✔️latest
️✔️3.12
️✔️3.13
️✔️servicebus
️✔️latest
️✔️3.12
️✔️3.13
️✔️serviceconnector
️✔️latest
️✔️3.12
️✔️3.13
️✔️servicefabric
️✔️latest
️✔️3.12
️✔️3.13
️✔️signalr
️✔️latest
️✔️3.12
️✔️3.13
️✔️sql
️✔️latest
️✔️3.12
️✔️3.13
️✔️sqlvm
️✔️latest
️✔️3.12
️✔️3.13
️✔️storage
️✔️latest
️✔️3.12
️✔️3.13
️✔️synapse
️✔️latest
️✔️3.12
️✔️3.13
️✔️telemetry
️✔️latest
️✔️3.12
️✔️3.13
️✔️util
️✔️latest
️✔️3.12
️✔️3.13
️✔️vm
️✔️latest
️✔️3.12
️✔️3.13

@azure-client-tools-bot-prd
Copy link
Copy Markdown

azure-client-tools-bot-prd bot commented May 16, 2025

❌AzureCLI-BreakingChangeTest
❌resource
rule cmd_name rule_message suggest_message
1007 - ParaRemove policy assignment create cmd policy assignment create removed parameter sku please add back parameter sku for cmd policy assignment create
1007 - ParaRemove policy assignment update cmd policy assignment update removed parameter sku please add back parameter sku for cmd policy assignment update
1008 - ParaPropAdd policy assignment update cmd policy assignment update update parameter name: added property required=True please remove property required=True for parameter name of cmd policy assignment update
1007 - ParaRemove policy definition create cmd policy definition create removed parameter subscription please add back parameter subscription for cmd policy definition create
1007 - ParaRemove policy definition delete cmd policy definition delete removed parameter subscription please add back parameter subscription for cmd policy definition delete
1007 - ParaRemove policy definition list cmd policy definition list removed parameter subscription please add back parameter subscription for cmd policy definition list
1007 - ParaRemove policy definition show cmd policy definition show removed parameter subscription please add back parameter subscription for cmd policy definition show
1007 - ParaRemove policy definition update cmd policy definition update removed parameter subscription please add back parameter subscription for cmd policy definition update
1008 - ParaPropAdd policy exemption create cmd policy exemption create update parameter exemption_category: added property required=True please remove property required=True for parameter exemption_category of cmd policy exemption create
1008 - ParaPropAdd policy exemption create cmd policy exemption create update parameter policy_assignment: added property required=True please remove property required=True for parameter policy_assignment of cmd policy exemption create
1010 - ParaPropUpdate policy exemption list cmd policy exemption list update parameter disable_scope_strict_match: updated property options from ['--disable-scope-strict-match', '-i'] to ['--disable-scope-strict-match', '-d'] please change property options from ['--disable-scope-strict-match', '-d'] to ['--disable-scope-strict-match', '-i'] for parameter disable_scope_strict_match of cmd policy exemption list
1007 - ParaRemove policy set-definition create cmd policy set-definition create removed parameter subscription please add back parameter subscription for cmd policy set-definition create
1007 - ParaRemove policy set-definition delete cmd policy set-definition delete removed parameter subscription please add back parameter subscription for cmd policy set-definition delete
1007 - ParaRemove policy set-definition list cmd policy set-definition list removed parameter subscription please add back parameter subscription for cmd policy set-definition list
1007 - ParaRemove policy set-definition show cmd policy set-definition show removed parameter subscription please add back parameter subscription for cmd policy set-definition show
1007 - ParaRemove policy set-definition update cmd policy set-definition update removed parameter subscription please add back parameter subscription for cmd policy set-definition update

Please submit your Breaking Change Pre-announcement ASAP if you haven't already. Please note:

  • Breaking changes can only be merged during the designated breaking change window
  • A pre-announcement must be released at least one month in advance

For more details on how to introduce breaking changes, refer to the documentation: azure-cli/doc/how_to_introduce_breaking_changes.md

@yonzhan
Copy link
Copy Markdown
Collaborator

yonzhan commented May 16, 2025

Thank you for your contribution! We will review the pull request and get back to you soon.

@github-actions
Copy link
Copy Markdown

The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR.

Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions).
After that please run the following commands to enable git hooks:

pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>

@microsoft-github-policy-service microsoft-github-policy-service bot added the Auto-Assign Auto assign by bot label May 16, 2025
@microsoft-github-policy-service microsoft-github-policy-service bot added the ARM az resource/group/lock/tag/deployment/policy/managementapp/account management-group label May 16, 2025
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR replaces custom Azure Policy CRUD implementations with autogenerated AAZ-based commands and removes legacy parameter and completer definitions.

  • Introduces AAZ command groups and operations for policy, assignment, identity, non-compliance-message, definition, exemption.
  • Removes custom parameter contexts and completers for policy commands in the resource module.
  • Cleans up deprecated client factory functions for policy resources.

Reviewed Changes

Copilot reviewed 72 out of 72 changed files in this pull request and generated no comments.

Show a summary per file
File Description
src/.../policy/exemption/__cmd_group.py Adds autogenerated command group for policy exemptions.
src/.../policy/definition/_delete.py Replaces policy definition delete with AAZ-generated code.
src/.../resource/_params.py Removes old policy argument contexts (custom parameters).
src/.../resource/_completers.py Removes legacy policy completer functions.
src/.../policyinsights/_completers.py Adds policy completers under policyinsights module.
Comments suppressed due to low confidence (2)

src/azure-cli/azure/cli/command_modules/resource/_params.py:209

  • The removal of the policy argument context in _params.py disables all custom CLI parameter definitions for policy commands, breaking argument parsing. Please reintroduce or migrate these parameter contexts to support the new AAZ-based command implementations.
with self.argument_context('policy') as c:

src/azure-cli/azure/cli/command_modules/resource/_completers.py:8

  • Legacy policy completer functions were removed, which will break tab-completion for policy definitions, assignments, and exemptions. Ensure completers are either restored in this module or correctly imported in the new AAZ command context.
from azure.cli.command_modules.resource._client_factory import (_resource_policy_client_factory, _resource_client_factory)

@necusjz
Copy link
Copy Markdown
Member

necusjz commented May 22, 2025

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 3 pipeline(s).

@zhoxing-ms
Copy link
Copy Markdown
Contributor

Please refer to this guideline https://github.com/Azure/azure-cli/tree/dev/doc/authoring_command_modules#format-pr-title and specify the breaking changes included in this PR in the History Notes section.
image

@zhoxing-ms
Copy link
Copy Markdown
Contributor

Additionally, since you missed the Build Breaking Change Window, we can only postpone it to the Ignite Breaking Change Window to release it

@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented May 22, 2025

Please refer to this guideline https://github.com/Azure/azure-cli/tree/dev/doc/authoring_command_modules#format-pr-title and specify the breaking changes included in this PR in the History Notes section. image

Updated

@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented May 22, 2025

Additionally, since you missed the Build Breaking Change Window, we can only postpone it to the Ignite Breaking Change Window to release it

OK. What's the process for that?

@zhoxing-ms
Copy link
Copy Markdown
Contributor

@mentat9 Actually, what I want to ask is, could you specify which breaking changes are there? Because customers need to know the details of these breaking changes to help them better migrate usage

@zhoxing-ms
Copy link
Copy Markdown
Contributor

OK. What's the process for that?

This is the process https://github.com/Azure/azure-cli/blob/dev/doc/how_to_introduce_breaking_changes.md about how to introduce Breaking Changes

@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented May 23, 2025

OK. What's the process for that?

This is the process https://github.com/Azure/azure-cli/blob/dev/doc/how_to_introduce_breaking_changes.md about how to introduce Breaking Changes

@zhoxing-ms - I believe we've done everything documented there. My question is what is the process for "postpone it to the Ignite Breaking Change Window to release it".

@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented May 23, 2025

@mentat9 Actually, what I want to ask is, could you specify which breaking changes are there? Because customers need to know the details of these breaking changes to help them better migrate usage

OK, made the change.

@mentat9 mentat9 requested a review from zhoxing-ms August 13, 2025 16:41
@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented Aug 13, 2025

@zhoxing-ms - Is there anything else I need to do to get approval for this PR? If not, can you please approve?

zhoxing-ms
zhoxing-ms previously approved these changes Aug 14, 2025
@zhoxing-ms
Copy link
Copy Markdown
Contributor

@mentat9 I have approved this PR, do we need to merge it now?

@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented Aug 14, 2025

@mentat9 I have approved this PR, do we need to merge it now?

@zhoxing-ms - Yes, please merge this PR as soon as you can. I would do it myself, but I'm still not allowed.

image

@zhoxing-ms
Copy link
Copy Markdown
Contributor

image

Sorry, currently this PR still needs approval from @jsntcy, but @jsntcy is OOF this week. If this PR is not in a hurry to merge, then we can wait for his approval

@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented Aug 18, 2025

@jsntcy - Please review/approve as soon as you get a chance, thanks.
cc:: @zhoxing-ms

@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented Aug 19, 2025

@zhoxing-ms, @jsntcy - I had to reintegrate this PR yet again, so

  1. All review approvals were dismissed.
  2. Automation needs to run again. I need someone from your team to execute the automation (/azp run).

I still need to merge this PR as soon as possible and need your help:
@zhoxing-ms, please re-approve (there are no changes).
@zhoxing-ms (or anyone else from the CLI team), please add the /azp run comment.
@jsntcy, please review and approve.
cc: @calecarter

@zhoxing-ms
Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 3 pipeline(s).

@yanzhudd
Copy link
Copy Markdown
Contributor

please fix the CI issues.

@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented Aug 22, 2025

please fix the CI issues.

@yanzhudd - AFAICT, the SBOM failures are false-positive caused by the way PRs are built in this repo (see this thread: https://teams.microsoft.com/l/message/19:uI30QGN30KqwIekK4iquJi0SE5yHF2Nu3Kfi8s_xPOQ1@thread.tacv2/1749777015327?tenantId=72f988bf-86f1-41af-91ab-2d7cd011db47&groupId=ef54ced4-3f58-4488-a2fd-6511552227ea&parentMessageId=1749777015327&teamName=SBOM%20Support&channelName=SBOM%20Support%20-%20General&createdTime=1749777015327).

If you know something different, can you tell me how to follow this up?

Note that many/most/all builds are failing the same way right now:

image

@wangzelin007
Copy link
Copy Markdown
Member

please fix the CI issues.

@yanzhudd - AFAICT, the SBOM failures are false-positive caused by the way PRs are built in this repo (see this thread: https://teams.microsoft.com/l/message/19:uI30QGN30KqwIekK4iquJi0SE5yHF2Nu3Kfi8s_xPOQ1@thread.tacv2/1749777015327?tenantId=72f988bf-86f1-41af-91ab-2d7cd011db47&groupId=ef54ced4-3f58-4488-a2fd-6511552227ea&parentMessageId=1749777015327&teamName=SBOM%20Support&channelName=SBOM%20Support%20-%20General&createdTime=1749777015327).

If you know something different, can you tell me how to follow this up?

Note that many/most/all builds are failing the same way right now:

image

The real reason for the failure is that the Partner Center dependency package is outdated.
We’ve already fixed this in #31967.
Please merge the latest code from the dev branch.

@yanzhudd
Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 3 pipeline(s).

@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented Aug 25, 2025

/azp run

@azure-pipelines
Copy link
Copy Markdown

Commenter does not have sufficient privileges for PR 31496 in repo Azure/azure-cli

@mentat9
Copy link
Copy Markdown
Member Author

mentat9 commented Aug 25, 2025

@wangzelin007 - I've refreshed from upstream dev.
@yanzhudd - Please add /azp run comment to execute CI.
@jsntcy - Please add a review to unblock.

@zhoxing-ms
Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 3 pipeline(s).

@zhoxing-ms zhoxing-ms merged commit ed0af96 into Azure:dev Aug 26, 2025
48 checks passed
mentat9 added a commit to mentat9/aaz that referenced this pull request Aug 26, 2025
…this PR: Azure/azure-cli#31496 to onboard the policy CLI commands to auto-generation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ARM az resource/group/lock/tag/deployment/policy/managementapp/account management-group Auto-Assign Auto assign by bot

Projects

None yet

Development

Successfully merging this pull request may close these issues.