Skip to content

{Compute} az vmss encryption: Migrate to AAZ#31622

Merged
yanzhudd merged 5 commits intoAzure:devfrom
cxznmhdcxz:vmss-encryption-migrate
Jul 1, 2025
Merged

{Compute} az vmss encryption: Migrate to AAZ#31622
yanzhudd merged 5 commits intoAzure:devfrom
cxznmhdcxz:vmss-encryption-migrate

Conversation

@cxznmhdcxz
Copy link
Copy Markdown
Member

@cxznmhdcxz cxznmhdcxz commented Jun 10, 2025

Related command

az vmss encryption enable/disable/show

Description

Migrate to AAZ code
aaz Azure/aaz#782

Testing Guide

History Notes

[Component Name 1] BREAKING CHANGE: az command a: Make some customer-facing breaking change
[Component Name 2] az command b: Add some customer-facing feature


This checklist is used to make sure that common guidelines for a pull request are followed.

@azure-client-tools-bot-prd
Copy link
Copy Markdown

azure-client-tools-bot-prd bot commented Jun 10, 2025

️✔️AzureCLI-FullTest
️✔️acr
️✔️latest
️✔️3.12
️✔️3.9
️✔️acs
️✔️latest
️✔️3.12
️✔️3.9
️✔️advisor
️✔️latest
️✔️3.12
️✔️3.9
️✔️ams
️✔️latest
️✔️3.12
️✔️3.9
️✔️apim
️✔️latest
️✔️3.12
️✔️3.9
️✔️appconfig
️✔️latest
️✔️3.12
️✔️3.9
️✔️appservice
️✔️latest
️✔️3.12
️✔️3.9
️✔️aro
️✔️latest
️✔️3.12
️✔️3.9
️✔️backup
️✔️latest
️✔️3.12
️✔️3.9
️✔️batch
️✔️latest
️✔️3.12
️✔️3.9
️✔️batchai
️✔️latest
️✔️3.12
️✔️3.9
️✔️billing
️✔️latest
️✔️3.12
️✔️3.9
️✔️botservice
️✔️latest
️✔️3.12
️✔️3.9
️✔️cdn
️✔️latest
️✔️3.12
️✔️3.9
️✔️cloud
️✔️latest
️✔️3.12
️✔️3.9
️✔️cognitiveservices
️✔️latest
️✔️3.12
️✔️3.9
️✔️compute_recommender
️✔️latest
️✔️3.12
️✔️3.9
️✔️computefleet
️✔️latest
️✔️3.12
️✔️3.9
️✔️config
️✔️latest
️✔️3.12
️✔️3.9
️✔️configure
️✔️latest
️✔️3.12
️✔️3.9
️✔️consumption
️✔️latest
️✔️3.12
️✔️3.9
️✔️container
️✔️latest
️✔️3.12
️✔️3.9
️✔️containerapp
️✔️latest
️✔️3.12
️✔️3.9
️✔️core
️✔️latest
️✔️3.12
️✔️3.9
️✔️cosmosdb
️✔️latest
️✔️3.12
️✔️3.9
️✔️databoxedge
️✔️latest
️✔️3.12
️✔️3.9
️✔️dls
️✔️latest
️✔️3.12
️✔️3.9
️✔️dms
️✔️latest
️✔️3.12
️✔️3.9
️✔️eventgrid
️✔️latest
️✔️3.12
️✔️3.9
️✔️eventhubs
️✔️latest
️✔️3.12
️✔️3.9
️✔️feedback
️✔️latest
️✔️3.12
️✔️3.9
️✔️find
️✔️latest
️✔️3.12
️✔️3.9
️✔️hdinsight
️✔️latest
️✔️3.12
️✔️3.9
️✔️identity
️✔️latest
️✔️3.12
️✔️3.9
️✔️iot
️✔️latest
️✔️3.12
️✔️3.9
️✔️keyvault
️✔️latest
️✔️3.12
️✔️3.9
️✔️lab
️✔️latest
️✔️3.12
️✔️3.9
️✔️managedservices
️✔️latest
️✔️3.12
️✔️3.9
️✔️maps
️✔️latest
️✔️3.12
️✔️3.9
️✔️marketplaceordering
️✔️latest
️✔️3.12
️✔️3.9
️✔️monitor
️✔️latest
️✔️3.12
️✔️3.9
️✔️mysql
️✔️latest
️✔️3.12
️✔️3.9
️✔️netappfiles
️✔️latest
️✔️3.12
️✔️3.9
️✔️network
️✔️latest
️✔️3.12
️✔️3.9
️✔️policyinsights
️✔️latest
️✔️3.12
️✔️3.9
️✔️privatedns
️✔️latest
️✔️3.12
️✔️3.9
️✔️profile
️✔️latest
️✔️3.12
️✔️3.9
️✔️rdbms
️✔️latest
️✔️3.12
️✔️3.9
️✔️redis
️✔️latest
️✔️3.12
️✔️3.9
️✔️relay
️✔️latest
️✔️3.12
️✔️3.9
️✔️resource
️✔️latest
️✔️3.12
️✔️3.9
️✔️role
️✔️latest
️✔️3.12
️✔️3.9
️✔️search
️✔️latest
️✔️3.12
️✔️3.9
️✔️security
️✔️latest
️✔️3.12
️✔️3.9
️✔️servicebus
️✔️latest
️✔️3.12
️✔️3.9
️✔️serviceconnector
️✔️latest
️✔️3.12
️✔️3.9
️✔️servicefabric
️✔️latest
️✔️3.12
️✔️3.9
️✔️signalr
️✔️latest
️✔️3.12
️✔️3.9
️✔️sql
️✔️latest
️✔️3.12
️✔️3.9
️✔️sqlvm
️✔️latest
️✔️3.12
️✔️3.9
️✔️storage
️✔️latest
️✔️3.12
️✔️3.9
️✔️synapse
️✔️latest
️✔️3.12
️✔️3.9
️✔️telemetry
️✔️latest
️✔️3.12
️✔️3.9
️✔️util
️✔️latest
️✔️3.12
️✔️3.9
️✔️vm
️✔️latest
️✔️3.12
️✔️3.9

@azure-client-tools-bot-prd
Copy link
Copy Markdown

azure-client-tools-bot-prd bot commented Jun 10, 2025

️✔️AzureCLI-BreakingChangeTest
️✔️Non Breaking Changes

@yonzhan
Copy link
Copy Markdown
Collaborator

yonzhan commented Jun 10, 2025

Thank you for your contribution! We will review the pull request and get back to you soon.

@github-actions
Copy link
Copy Markdown

The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR.

Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions).
After that please run the following commands to enable git hooks:

pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>

@cxznmhdcxz cxznmhdcxz force-pushed the vmss-encryption-migrate branch from eb2fb0f to a2bd755 Compare June 10, 2025 07:08
@cxznmhdcxz cxznmhdcxz changed the title [Compute] Vmss encryption migrate {Compute} Vmss encryption migrate Jun 12, 2025
@cxznmhdcxz cxznmhdcxz changed the title {Compute} Vmss encryption migrate {Compute} az vmss encryption: Vmss encryption migrate Jun 12, 2025
@cxznmhdcxz cxznmhdcxz changed the title {Compute} az vmss encryption: Vmss encryption migrate {Compute} az vmss encryption: Migrate to AAZ Jun 12, 2025
@cxznmhdcxz cxznmhdcxz marked this pull request as ready for review June 16, 2025 04:51
Copilot AI review requested due to automatic review settings June 16, 2025 04:51
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR migrates virtual machine scale set (VMSS) disk encryption commands to the AAZ framework and updates related VMSS listing schemas to newer API versions and richer read-only metadata.

  • Migrate encrypt_vmss, decrypt_vmss, and identity updates to use AAZ Patch/Update commands
  • Replace old model-based calls with AAZ operations and update key vault verification to AAZ-style dictionaries
  • Bump API versions and add read-only flags in VMSS list-related schemas

Reviewed Changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
src/azure-cli/azure/cli/command_modules/vm/disk_encryption.py Migrate encryption and identity logic to AAZ Patch/Update classes
src/azure-cli/azure/cli/command_modules/vm/aaz/latest/vmss/_list_instances.py Bump to 2024-11-01, switch to AAZIdentityObjectType, add read-only flags
src/azure-cli/azure/cli/command_modules/vm/aaz/latest/vmss/_list_instance_public_ips.py Add flags={"read_only": True} to new schema properties
src/azure-cli/azure/cli/command_modules/vm/aaz/latest/vmss/_list.py Replace AAZObjectType() with AAZIdentityObjectType() for identity
src/azure-cli/azure/cli/command_modules/vm/aaz/latest/vmss/_get_os_upgrade_history.py Mark rollbackError as read-only
src/azure-cli/azure/cli/command_modules/vm/aaz/latest/vmss/init.py Import new AAZ modules (_patch, _update, _wait)
Comments suppressed due to low confidence (2)

src/azure-cli/azure/cli/command_modules/vm/disk_encryption.py:108

  • New AAZ-based Patch logic for VMSS encryption should be covered by unit or functional tests to validate payload formation and long-running operation handling.
from .aaz.latest.vmss import Patch

src/azure-cli/azure/cli/command_modules/vm/disk_encryption.py:555

  • Ensure that import uuid is present at the top of this module; otherwise, uuid will be undefined when generating force_update_tag.
                    'force_update_tag': str(uuid.uuid4())

.user_assigned_identity_resource_id.lower() != encryption_identity:
vmss.virtual_machine_profile.security_profile.encryption_identity.user_assigned_identity_resource_id \
= encryption_identity
if vmss['properties']['virtualMachineProfile'].get('securityProfile', {}).get('encryptionIdentity', {}).\
Copy link

Copilot AI Jun 16, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Avoid using backslashes for line continuation. Wrap the entire condition in parentheses and use hanging indents for readability, e.g.:

if (
    vmss['properties']['virtualMachineProfile']
        .get('securityProfile', {})
        .get('encryptionIdentity', {})
        .get('userAssignedIdentityResourceId', '')
).lower() != encryption_identity.lower():

Copilot uses AI. Check for mistakes.
@cxznmhdcxz cxznmhdcxz marked this pull request as draft June 16, 2025 04:53
@cceneag
Copy link
Copy Markdown

cceneag commented Jun 18, 2025

This pull request introduces several changes to the Azure CLI's Virtual Machine Scale Sets (VMSS) command module, focusing on schema updates, new imports, and refactoring. Key updates include adding new helper methods, marking fields as read-only, replacing object types with more specific ones, and updating the API version. Below is a breakdown of the most important changes:

Schema Enhancements and Refactoring:

  • Added new helper methods _build_schema_api_entity_reference_read and _build_schema_host_endpoint_settings_read in _ListInstancesHelper to streamline schema construction for API entity references and host endpoint settings. (src/azure-cli/azure/cli/command_modules/vm/aaz/latest/vmss/_list_instances.py) [1] [2]
  • Replaced AAZObjectType with AAZIdentityObjectType or AAZFreeFormDictType for fields like identity, protected_settings, and settings to improve type specificity. (src/azure-cli/azure/cli/command_modules/vm/aaz/latest/vmss/_list_instances.py) [1] [2] [3]

Read-Only Flag Additions:

  • Marked various fields as read-only, such as rollbackError, outboundRule, and vmHealth.status, across multiple schema-building methods to ensure immutability where appropriate. (src/azure-cli/azure/cli/command_modules/vm/aaz/latest/vmss/_list_instances.py, _list_instance_public_ips.py) [1] [2] [3]

API Version Updates:

  • Updated the API version from 2023-09-01 to 2024-11-01 in the ListInstances command and related query parameters to align with the latest Azure Compute API. (src/azure-cli/azure/cli/command_modules/vm/aaz/latest/vmss/_list_instances.py) [1] [2]

New Imports:

  • Added imports for _patch, _update, and _wait modules in the VMSS command module's __init__.py file to support additional commands. (src/azure-cli/azure/cli/command_modules/vm/aaz/latest/vmss/__init__.py)

Code Cleanup:

  • Removed unused _compute_client_factory and _is_linux_os imports from disk_encryption.py to streamline the codebase. (src/azure-cli/azure/cli/command_modules/vm/disk_encryption.py)

@cxznmhdcxz cxznmhdcxz marked this pull request as ready for review June 30, 2025 03:52
Comment thread src/azure-cli/azure/cli/command_modules/vm/disk_encryption.py
@yanzhudd yanzhudd merged commit e39ecb4 into Azure:dev Jul 1, 2025
48 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants