Skip to content

Add approvalReference to private endpoint connection in 2026-01-01 - #45604

Merged
santoshgh317 merged 4 commits into
release-microsoft-network-2026-01-01from
ajoyduwary/pe-approval-reference-2026-01-01
Aug 27, 2026
Merged

santoshgh317 merged 4 commits into
release-microsoft-network-2026-01-01from
ajoyduwary/pe-approval-reference-2026-01-01

Conversation

@ajoyduwary

@ajoyduwary ajoyduwary commented Aug 18, 2026 •

Copy link
Copy Markdown
Member

Summary

Adds an optional approvalReference.privateEndpointId property to PrivateLinkServiceConnectionProperties, gated @added(Versions.v2026_01_01). The property is emitted into the new stable/2026-01-01 swagger outputs (common.json, virtualNetwork.json).

approvalReference lets a manual private endpoint connection inherit the connection-approval state of an existing, already-approved private endpoint at creation time.

Notes

  • No mutability restriction. Per internal design discussion, the property is intentionally a normal read/write property — it does not carry x-ms-mutability/@visibility, and there is no create-only enforcement in the swagger. (An earlier revision of this PR added @visibility(Lifecycle.Read, Lifecycle.Create); that was removed by design.)
  • stable/2018-10-01/vmssNetwork.json change is a generated artifact. The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and pins @useDependency(Common.Versions.v2026_01_01), so tsp compile emits this new Common property into its single 2018-10-01 output. This is the same behavior as prior Network releases (e.g. ddosCustomPolicy/disablePeeringRoute added to the same file in the 2025-07-01 release). The regenerated file is required for TypeSpec Validation to pass; it cannot be hand-trimmed without breaking the compile-parity check.

… 2026-01-01

Adds optional approvalReference.privateEndpointId to PrivateLinkServiceConnectionProperties, gated @added(v2026_01_01) with @visibility(Lifecycle.Read, Lifecycle.Create) so it is create-only (emits x-ms-mutability: [read, create]) and is not resupplied on update.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a
@github-actions

github-actions Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Next Steps to Merge

Important checks have failed. As of today they are not blocking this PR, but in near future they may.
Addressing the following failures is highly recommended:
  • ⚠️ The check named Swagger BreakingChange has failed. To unblock this PR, follow the process at aka.ms/brch.
If you still want to proceed merging this PR without addressing the above failures, refer to step 4 in the PR workflow diagram.

Comment generated by summarize-checks workflow run.

@github-actions github-actions Bot added ARMReview resource-manager TypeSpec Authored with TypeSpec WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 18, 2026
@github-actions

github-actions Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

API Change Check

APIView identified API level changes in this PR and created the following API reviews

Language API Review for Package
Go sdk/resourcemanager/network/armnetwork
JavaScript @azure/arm-network
Java com.azure.resourcemanager:azure-resourcemanager-network
Python azure-mgmt-network
C# Azure.ResourceManager.Network

Comment generated by After APIView workflow run.

The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and emits stable/2018-10-01/vmssNetwork.json, which must be regenerated so approvalReference/ApprovalReference are included. Fixes TypeSpec Validation (Vmss).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a
@github-actions

Copy link
Copy Markdown

ARM API Review Critic — Verdict: FAIL (environment/input failure)

I could not perform the independent verification required by protocol due to missing required inputs in this execution environment:

  1. Missing instruction files: None of the following required files exist in the checkout at /home/runner/work/azure-rest-api-specs/azure-rest-api-specs:

    • .github/agents/arm-api-review-critic.agent.md
    • .github/agents/protocols/arm-api-review-critic.protocol.md
    • .github/agents/protocols/arm-api-review-critic-inputs.template.md

    Only an unrelated file, .github/agents/arm-api-review-critic-runtime.agent.md, is present in .github/agents/. No protocols/ subdirectory exists at all.

  2. Missing git repository: The working directory /home/runner/work/azure-rest-api-specs/azure-rest-api-specs is not a git repository (fatal: not a git repository), so I have no way to check out the PR branch/base branch, diff vmssNetwork.json, or verify the claim that the file "already existed on the base branch (pre-PR)" versus being newly added, or to inspect the TypeSpec source's @added(Versions.v2026_01_01) gating.

Per my binding instructions, when required instruction files, inputs, or evidence are unavailable, I must return an explicit failure verdict rather than claim Critic-verified status. This is a genuine environment/tooling gap, not a judgment on the underlying finding's correctness — I was unable to independently confirm or refute whether the approvalReference/ApprovalReference property addition to vmssNetwork.json is correctly version-gated or represents a Blocking spec issue, because I had no access to the protocol definition or the actual repository content/history needed to check it.

Recommendation: Re-run this Critic step in an environment where (a) the .github/agents/protocols/arm-api-review-critic.protocol.md and arm-api-review-critic-inputs.template.md files are present, and (b) a working git clone of Azure/azure-rest-api-specs with the PR #45604 branch and base branch is available for diffing.

No claim of Critic-verified PASS or FAIL on the substantive finding is made here — this is strictly an infrastructure/input-availability failure report.

🔍 ARM API review by ARM API Review: Automated Workflow

@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45604 at head SHA 9e09295a3903b489ebce4d69dbdd6db403504463 | Triggered by: pull_request_target

Approval labels observed: none.

Category Count
🔴 Blocking 0
🟠 Warning 1
🔵 Suggestion 0

This PR adds an optional, create-only approvalReference.privateEndpointId property to PrivateLinkServiceConnectionProperties, correctly gated with @added(Versions.v2026_01_01) / @visibility(Lifecycle.Read, Lifecycle.Create) (x-ms-mutability: [read, create]) in TypeSpec and in the new stable/2026-01-01 swagger outputs (common.json, virtualNetwork.json) — those two files are compliant additive changes to a brand-new API version. However, the same ApprovalReference/approvalReference content was also emitted into stable/2018-10-01/vmssNetwork.json, a file already published/merged on the base branch (release-microsoft-network-2026-01-01), which appears to be an unintended generation artifact inconsistent with the @added(Versions.v2026_01_01) gate; see the inline finding for details. The three mandatory Critic dispatch attempts (Step 5.6) all returned an explicit FAIL because required Critic protocol/instruction files were unavailable in this run's sandbox, so per protocol the one finding was downgraded from Blocking to Warning and marked critic: unknown rather than being posted as unverified Blocking or silently dropped.

posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: new | critic: unknown | head-sha: 9e09295

🔍 ARM API review by ARM API Review: Automated Workflow

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ARM API Review

Posting findings from the ARM API Reviewer agent (Critic unavailable; reviewer self-check only, 3 iteration(s), 1 finding posted) against commit 9e09295a3903b489ebce4d69dbdd6db403504463. See inline comments for findings on specification/network/resource-manager/Microsoft.Network/Network/stable/2018-10-01/vmssNetwork.json line 3478.

Approval labels observed: none.

🔍 ARM API review by ARM API Review: Automated Workflow

@ajoyduwary

Copy link
Copy Markdown
Member Author

@microsoft-github-policy-service agree company="Microsoft"

Per internal discussion, drop the create-only mutability restriction on
approvalReference. Removes the @visibility(Lifecycle.Read, Lifecycle.Create)
decorator in Common/main.tsp and regenerates the Network and Vmss project
swaggers so x-ms-mutability is no longer emitted. The approvalReference
property and ApprovalReference model are retained.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a
@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45604 at head SHA 721e83b33bfcaf0c9069247eef929a0aba731f65 | Triggered by: pull_request_target

Approval labels observed: none.

Category Count
🔴 Blocking 0
🟠 Warning 2
🔵 Suggestion 0

This PR adds an optional approvalReference.privateEndpointId property to PrivateLinkServiceConnectionProperties, gated @added(Versions.v2026_01_01) in TypeSpec, correctly emitted only into the new stable/2026-01-01 swagger outputs. A prior run's finding (still open, unresolved thread) flags that the same ApprovalReference/approvalReference content was also emitted into the already-published stable/2018-10-01/vmssNetwork.json, an apparent version-scoping/generation bug — that thread remains open pending author action and was not duplicated here. A new finding from this run: the PR description states the field is intended to be create-only via @visibility(Lifecycle.Read, Lifecycle.Create), but the actual TypeSpec source has no @visibility decorator on approvalReference/privateEndpointId, so the compiled stable/2026-01-01 swagger carries no x-ms-mutability/readOnly annotation and the field is fully mutable, contradicting the stated design. The Critic subagent could not run (required protocol/instruction files not present in this environment), so this finding is posted as Warning with critic: unknown per the degraded-Critic protocol rather than Blocking.

posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: new | critic: unknown | head-sha: 721e83b

🔍 ARM API review by ARM API Review: Automated Workflow

@ajoyduwary ajoyduwary changed the title Add approvalReference (create-only) to private endpoint connection in… Add approvalReference to private endpoint connection in 2026-01-01 Aug 20, 2026
@ajoyduwary

Copy link
Copy Markdown
Member Author

Summary for ARM reviewer

This PR adds one optional property, approvalReference.privateEndpointId, to PrivateLinkServiceConnectionProperties, gated @added(Versions.v2026_01_01). It lets a manual private endpoint connection inherit the approval state of an existing, already-approved private endpoint at creation time.

Intended API surface (the actual change):

  • stable/2026-01-01/common.json — new ApprovalReference definition
  • stable/2026-01-01/virtualNetwork.json — new optional approvalReference property

The property is a normal read/write property by design (no x-ms-mutability/@visibility).

The two failing checks are known/expected, not new code issues:

  1. Swagger BreakingChange (rule 1041) and the stable/2018-10-01/vmssNetwork.json diff — this is a generated artifact, not a hand edit. The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and pins @useDependency(Common.Versions.v2026_01_01), so tsp compile emits every @added(<= v2026_01_01) Common property into its single 2018-10-01 output. This is the same behavior as prior releases — the base branch copy of that file already contains ddosCustomPolicy/disablePeeringRoute emitted the same way by the 2025-07-01 release. It cannot be hand-trimmed: TypeSpec Validation enforces compile parity and would immediately re-fail. Could you please apply the appropriate Versioning-Approved-* / BreakingChange-Approved-* label per aka.ms/brch, consistent with how prior releases handled this emission?

  2. Swagger Avocado — MULTIPLE_API_VERSION — pre-existing/structural. readme.md is unchanged in this PR; the package-2026-01-01 default tag already bundles the legacy stable/2018-10-01/vmssNetwork.json alongside the 2026-01-01 files, which is the trigger. Not introduced by this change.

The automated ARM API review returned 0 Blocking; both inline findings have author replies. CLA is signed and TypeSpec Validation passes. Requesting ARMSignedOff when convenient — happy to adjust if a different resolution is preferred. Thank you!

@ajoyduwary ajoyduwary left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please add Approved-Avocado. This is intentional: the default tag includes stable/2018-10-01/vmssNetwork.json for backward compatibility, same as PR #41904.
#41904

@sandipsh Sandip Shahane (sandipsh) left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ARM API Review

Posting findings from the ARM API Reviewer agent (critic-verified, 1 iteration(s), converged) against commit 721e83b. See inline comments for finding 1.

Approval labels observed: none.

Comment thread specification/network/resource-manager/Microsoft.Network/Network/Common/main.tsp Outdated
@sandipsh Sandip Shahane (sandipsh) added ARMChangesRequested and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 25, 2026
Address ARM review finding [TSP-ARM-RESOURCE-ID]: privateEndpointId references an existing private endpoint, so type it as Azure.Core.armResourceIdentifier<Microsoft.Network/privateEndpoints> instead of plain string. Regenerated swagger emits format: arm-id and x-ms-arm-id-details.allowedResources.
@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45604 at head SHA 3aa0658467cf6bc405fee55a858c443900e04f9f | Triggered by: pull_request_target

Approval labels observed: none.

Category Count
🔴 Blocking 0
🟠 Warning 0
🔵 Suggestion 0

This PR adds an optional approvalReference.privateEndpointId property to PrivateLinkServiceConnectionProperties, gated @added(Versions.v2026_01_01), emitted only into the new stable/2026-01-01 swagger outputs (common.json, virtualNetwork.json). Since the last automated run, the author has fixed both prior open findings: (1) privateEndpointId is now typed as Azure.Core.armResourceIdentifier<[{ type: "Microsoft.Network/privateEndpoints" }]>, so the compiled schema correctly carries format: arm-id and x-ms-arm-id-details.allowedResources — the prior TSP-ARM-RESOURCE-ID Blocking finding is resolved (see reply on that thread); and (2) Vmss/main.tsp now pins @useDependency(Common.Versions.v2025_09_01) instead of v2026_01_01, so stable/2018-10-01/vmssNetwork.json is no longer touched by this PR, resolving the earlier version-scoping concern. The property is intentionally a normal read/write field with no x-ms-mutability restriction, per the author's stated design (earlier mutability finding already addressed). No new blocking, warning, or suggestion findings from this run.

posted-by: arm-api-reviewer-agent | rule: summary | severity: suggestion | classification: existing | critic: unknown | head-sha: 3aa0658

🔍 ARM API review by ARM API Review: Automated Workflow

@ajoyduwary
ajoyduwary force-pushed the ajoyduwary/pe-approval-reference-2026-01-01 branch from 3aa0658 to 401c5b1 Compare August 26, 2026 01:33
@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45604 at head SHA 401c5b1251b697b1548491f0809e4becd60ed23f | Triggered by: pull_request_target

Approval labels observed: none.

Category Count
🔴 Blocking 0
🟠 Warning 1
🔵 Suggestion 0

This run re-verified the canonical PR head via the Pull Requests API and found it is 401c5b1251b697b1548491f0809e4becd60ed23f — a commit that types ApprovalReference.privateEndpointId as Azure.Core.armResourceIdentifier<[{ type: "Microsoft.Network/privateEndpoints" }]> (resolving the earlier TSP-ARM-RESOURCE-ID finding, confirmed via the thread reply). However, the previous run's claim that a later commit (3aa0658..., reverting Vmss/main.tsp's @useDependency to v2025_09_01) removed stable/2018-10-01/vmssNetwork.json from scope does not hold at the current canonical head: that commit is not the PR's current tip, and at 401c5b1 the Vmss project still pins @useDependency(Common.Versions.v2026_01_01), so ApprovalReference/approvalReference are still emitted into the already-published stable/2018-10-01/vmssNetwork.json. A correction reply was posted on the existing RPC-Schema-V1-26.0 thread reflagging this as [EXISTING] rather than opening a duplicate finding, since the author has already acknowledged this as an intentional, generated, cross-version emission (consistent with prior Network releases) and requested the appropriate Versioning-Approved-*/BreakingChange-Approved-* label. No new Blocking findings this run.

posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: existing | critic: unknown | head-sha: 401c5b1

🔍 ARM API review by ARM API Review: Automated Workflow

@sandipsh

Copy link
Copy Markdown
Contributor

Next Steps to Merge

Next steps that must be taken to merge this PR:

  • ❌ This PR is in purview of the ARM review (label: ARMReview). This PR must get ARMSignedOff label from an ARM reviewer.This PR is awaiting ARM reviewer feedback (label: WaitForARMFeedback).To learn when this PR will get reviewed, see ARM review queue at aka.ms/azsdk/pr-arm-reviewFor details of the ARM review, see aka.ms/azsdk/pr-arm-review
  • ❌ The required check named Swagger Avocado has failed. Refer to the check in the PR's 'Checks' tab for details on how to fix it and consult the aka.ms/ci-fix guide

Important checks have failed. As of today they are not blocking this PR, but in near future they may.
Addressing the following failures is highly recommended:

  • ⚠️ The check named Swagger BreakingChange has failed. To unblock this PR, follow the process at aka.ms/brch.

Comment generated by summarize-checks workflow run.

this is not addressed yet.

@sandipsh Sandip Shahane (sandipsh) added Approved-Avocado ARMChangesRequested and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 26, 2026
@github-actions github-actions Bot added ARMAutoSignedOff-IncrementalTSP ARMSignedOff <valid label in PR review process>add this label when ARM approve updates after review and removed ARMChangesRequested labels Aug 26, 2026
@ajoyduwary

Copy link
Copy Markdown
Member Author

ZiWei Chen (@kazrael2119) Chenjie Shi (@tadelesh) — requesting breaking-change sign-off for the Go (BreakingChange-Go-Sdk) and JavaScript (BreakingChange-JavaScript-Sdk) SDKs on this PR. These two labels are the only remaining merge blockers (ARM review is complete — ARMSignedOff).

Why the labels fire: This PR adds one optional property, approvalReference.privateEndpointId (gated @added(Versions.v2026_01_01)), to the shared PrivateLinkServiceConnectionProperties model. The Vmss TypeSpec project pins @useDependency(Common.Versions.v2026_01_01), so tsp compile emits the new property into its single stable/2018-10-01/vmssNetwork.json output. That emission into an already-shipped stable file is what the SDK breaking-change detectors flag — it is additive (a new optional field), not a runtime break.

Precedent: This is the same established shared-model emission pattern already approved in prior Network releases — see #41904 (API version 2025-07-01), where ddosCustomPolicy / disablePeeringRoute were emitted into the same stable/2018-10-01/vmssNetwork.json file and signed off via BreakingChange-Go-Sdk-Approved / BreakingChange-JavaScript-Sdk-Approved.

Could you please review and apply the *-Approved labels? Happy to provide any additional detail. Thank you!

@santoshgh317
santoshgh317 merged commit b33a4ee into release-microsoft-network-2026-01-01 Aug 27, 2026
224 of 231 checks passed
@santoshgh317
santoshgh317 deleted the ajoyduwary/pe-approval-reference-2026-01-01 branch August 27, 2026 10:42
@santoshgh317 santoshgh317 mentioned this pull request Sep 3, 2026
5 of 9 tasks
santoshgh317 added a commit that referenced this pull request Sep 15, 2026
* Add API version 2026-01-01 for Microsoft.Network (#45569)

Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com>

* Add Enum values for VPN migrationType (#45647)

Co-authored-by: Akshat Kale <akale@microsoft.com>

* Fix Bug 38477992: type computedDisabledRules.rules as integers (2026-01-01) (#45621)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com>
Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3

* [Network] Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01 (#45625)

* Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01

Ports the change from azure-rest-api-specs-pr PR 29807 onto the public
2026-01-01 release branch.

Adds three read-only properties that NRP surfaces from api-version
2026-01-01 for Application Gateway WAF:

- paranoiaLevel on ApplicationGatewayFirewallRule
- displayName on ApplicationGatewayFirewallRuleSetPropertiesFormat
- displayName on ApplicationGatewayFirewallManifestRuleSet
- displayName on DefaultRuleSetPropertyFormat

paranoiaLevel uses a new extensible enum ApplicationGatewayWafRuleParanoiaLevel
with values PL1 to PL4.

All new members are annotated with @added(Versions.v2026_01_01). The change is
additive and all new properties are optional.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Retrigger CI

The SDK Validation - Rust build failed on a transient GitHub timeout
while installing the Azure SDK Tools CLI. Nothing in the spec changed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Centurion WAF: add WAF policy tier + Basic_v2/Basic_WAF_v2 SKUs (2026-01-01) (#45766)

* Add Centurion WAF updates for 2026-01-01

Update WAF policy tier and reserved capacity support.

Add Basic_v2 and Basic_WAF_v2 SKUs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Basic v2 application gateway tiers

WebApplicationFirewallPolicyTier ordering aligns Standard=0 and Basic=1.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Basic WAF and application gateway examples

Add Basic WAF policy create/get examples and Basic-tier coverage.

Add Basic_v2 and Basic_WAF_v2 application gateway create/get examples, including reservedCapacity and WAF policy association.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add AuthenticationPolicy resource and Application Gateway authConfigs binding for 2026-01-01 (#45764)

* Add AuthenticationPolicy support for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Align AuthenticationPolicy contract with service behavior

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Enforce AuthenticationPolicy name and binding constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add authentication policy tags update

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

---------

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 (#45650)

* Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01

Adds optional min/max allocation-size bounds to the Microsoft.Network
IpamPool resource in api-version 2026-01-01:

- IpamPoolProperties (PUT/GET): minAllocationSize, maxAllocationSize
- IpamPoolUpdateProperties (PATCH): minAllocationSize, maxAllocationSize
  marked x-nullable so an explicit null clears the bound while an absent
  bound is preserved, per ARM merge-patch semantics.

Both properties are gated with @added(Versions.v2026_01_01) so earlier
api-versions are unchanged. Regenerated virtualNetwork.json and updated
the 2026-01-01 IpamPools Create/Get/List/Update examples.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Move min/max allocation size into dedicated IpamPool examples

The allocation-size bounds are optional, so the baseline IpamPools
examples should not imply they are always supplied. Restores
IpamPools_Create/Get/List/Update to their original content and adds
dedicated examples that exercise the feature:

- IpamPools_CreateWithAllocationBounds.json: PUT setting both bounds.
- IpamPools_UpdateAllocationBounds.json: PATCH setting both bounds.
- IpamPools_UpdateClearAllocationBounds.json: PATCH clearing both
  bounds with an explicit null, per ARM merge-patch semantics.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Address ARM review: drop nullable union on new min/max update properties

New properties must not use a nullable union, since backward
compatibility does not apply to additions. The RP already treats an
empty string as a clear on PATCH, so the explicit null is unnecessary.

- IpamPoolUpdateProperties min/maxAllocationSize: string | null -> string,
  removing the no-nullable suppressions and x-nullable from the swagger.
- Document clearing via an empty string.
- IpamPools_UpdateClearAllocationBounds example now clears with "".

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add Swagger Avocado suppression for frozen 2018-10-01 VMSS surface

Per ARM reviewer guidance on PR #45650: the package-2026-01-01 default
tag intentionally retains stable/2018-10-01/vmssNetwork.json for
backward compatibility, which trips Avocado's MULTIPLE_API_VERSION rule.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix Avocado suppression tool name to SwaggerAvocado

Per ARM reviewer bot feedback on PR #45650: the suppression tool name
has no space.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add approvalReference to private endpoint connection in 2026-01-01 (#45604)

* Add approvalReference (create-only) to private endpoint connection in 2026-01-01

Adds optional approvalReference.privateEndpointId to PrivateLinkServiceConnectionProperties, gated @added(v2026_01_01) with @visibility(Lifecycle.Read, Lifecycle.Create) so it is create-only (emits x-ms-mutability: [read, create]) and is not resupplied on update.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Regenerate vmssNetwork.json for approvalReference (Vmss project)

The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and emits stable/2018-10-01/vmssNetwork.json, which must be regenerated so approvalReference/ApprovalReference are included. Fixes TypeSpec Validation (Vmss).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Remove x-ms-mutability (create-only) from approvalReference

Per internal discussion, drop the create-only mutability restriction on
approvalReference. Removes the @visibility(Lifecycle.Read, Lifecycle.Create)
decorator in Common/main.tsp and regenerates the Network and Vmss project
swaggers so x-ms-mutability is no longer emitted. The approvalReference
property and ApprovalReference model are retained.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Type approvalReference.privateEndpointId as armResourceIdentifier

Address ARM review finding [TSP-ARM-RESOURCE-ID]: privateEndpointId references an existing private endpoint, so type it as Azure.Core.armResourceIdentifier<Microsoft.Network/privateEndpoints> instead of plain string. Regenerated swagger emits format: arm-id and x-ms-arm-id-details.allowedResources.

---------

Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Add ExpressRoutCircuit on ExpressRouteLag (#45689)

* Add ExpressRoutCircuit on ExpressRouteLag

* Fix ExpressRouteLag examples: sync circuits to output copies and remove invalid circuit properties

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Align ExpressRouteCircuitCreateOnExpressRouteLag responses with request (EX-PARAM-CONSISTENCY)

Fix response bodies to match request: LAG reference lagName (was test),
enableDirectPortRateLimit true, and SKU Premium_MeteredData in the 200 response.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* Add AppGw Advanced Routing Rule in NRR API 2026-01-01 (#45844)

* Add advanced routing features to Application Gateway for API version 2026-01-01

* buid artifacts after changes to models.tsp

* added examples

* fix merge conflict

---------

Co-authored-by: Paawan Kohli <paawankohli@microsoft.com>

* Modify sdk-suppressions.yaml for breaking changes (#45914)

Updated breaking changes for Azure SDK suppressions in network resource manager.

* [Microsoft.Network] Add provider-led ExpressRoute circuit migration APIs (#45905)

* Add ExpressRoute circuit migration APIs

Add TypeSpec operations and models for provider-led ExpressRoute circuit migration, generated 2026-01-01 Swagger, examples, and the scoped brownfield resource-name suppression.

* Fix Network specification validation

Use valid UUID subscription IDs, add required TypeSpec example metadata, regenerate migration LRO metadata, and suppress the intentional mixed-version VMSS surface in the combined Network package.

* Fix Network Avocado suppression

Move the mixed API-version exception from an unsupported AutoRest directive to the Network SwaggerAvocado path-suppression file, scoped to the default-tag readme.

* Fix Network validation suppressions

* Correct Avocado suppression identifier

* Geo-Ip filter changes (#45631)

* Geo Ip Filter Changes

* Document GeoIP filter format (ISO 3166-1 alpha-2) and fix WAF scrubbing-rule model

* Fixing Swagger ModelValidation Filure related errors

* Dummy Push to reinitate build

* Type Spec validation failure fix

* Remove duplicate GeoIP filter properties

---------

Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com>

* Add NeuroShield API for 2026-01-01 (#45722)

* Add NeuroShield API for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add NeuroShield API for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Align NeuroShield contract with service behavior

Require customer-facing configuration, align mitigation responses with the safe service projection, make cancellation synchronous, and correct protected-resource delete polling.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Refine NeuroShield 2026-01-01 contract

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Fix NeuroShield validation regressions

* Address ARM review feedback for NeuroShield

Use supported ARM resource templates, scope Swagger suppressions to exact operations, and isolate inherited Network validation debt.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Fix NeuroShield LintDiff suppressions

* Use standard ARM entity tag property

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Add post calls for auth key of authorization objects for expressrouteciruits and expressrouteports (#45679)

* Added post calls for expressroute auth key

* Added the objects in 2026-01-01 version

* addressed ai comments

* Addressed comments

* fixed

* removed suppression

* fixed suppressions

---------

Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com>

* Fix Hub virtual network IPv6 peering contract (#45637)

* Fix IPv6 peering contract for Network 2026-01-01
* Correct IPv6 peering contract in Network 2025-09-01
* Update client.tsp

* Update sdk-suppressions.yaml

---------

Co-authored-by: Caren Lim <carenlim@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: kazrael2119 <98569699+kazrael2119@users.noreply.github.com>

* Correct AuthenticationPolicy contract for 2026-01-01 (#45892)

* Correct authentication policy contract

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Keep provider type extensible

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Document authentication policy constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Align authentication examples with service

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Restore authentication policy tags update

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Suppress PatchIdentityProperty for AuthenticationPolicies_UpdateTags

The tags-only PATCH takes the shared Network RP TagsObject body, matching
ApplicationGateways_UpdateTags. The service only updates tags on this
operation, so identity does not belong in the request body.

* Complete authentication policy constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Correct Basic v2 authentication example

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Address ARM review feedback on AuthenticationPolicy 2026-01-01

- Make the arm-resource-invalid-envelope-property suppression reason self-contained by stating why the user-assigned identity belongs in the resource envelope.
- Scope the PatchIdentityProperty suppression with a where: clause targeting the AuthenticationPolicies_UpdateTags PATCH operation.
- Type issuer as url and require an https scheme, consistent with jwksUri and clientSecret.
- Document the sessionTimeout string syntax and units, and constrain it with a base-10 integer pattern and max length.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Also scope PatchIdentityProperty suppression to the PATCH body parameter path

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Remove AuthenticationPolicy PATCH operation

The service supports only GET, PUT, and DELETE for authenticationPolicies,
matching ApplicationGatewayWebApplicationFirewallPolicies, which also ships
without a PATCH. Removing the tags-only PATCH also resolves the
PatchIdentityProperty finding at its source: that rule fires only on an
existing PATCH, so with no PATCH the identity envelope property no longer
needs a suppression.

- Remove AuthenticationPolicies_UpdateTags and its source and generated examples.
- Drop the PatchIdentityProperty suppression.
- Restore the TrackedResourcePatchOperation no-PATCH suppression.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Drop stale PATCH path from ProvisioningStateMustBeReadOnly suppression

The AuthenticationPolicy PATCH operation was removed, so the patch response
entry in the where: list no longer matches anything.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Restore AuthenticationPolicy PATCH with a resource-specific update model

AuthenticationPolicy is a tracked resource: it extends the Network RP
Resource base type, which supplies location, tags and x-ms-azure-resource.
ARM requires resource providers to support PATCH for updating tags on a
tracked resource, so removing the operation was incorrect.

Restore PATCH using a resource-specific AuthenticationPolicyUpdateParameters
model carrying both tags and identity, rather than the shared TagsObject.
This satisfies the tracked-resource tags requirement and the MSI onboarding
requirement that the control plane accept identity updates on PATCH, which
means PatchIdentityProperty is now satisfied at the source and needs no
suppression.

- Add AuthenticationPolicyUpdateParameters (tags, identity).
- Add AuthenticationPolicies_Update, replacing the former tags-only
  AuthenticationPolicies_UpdateTags.
- Add an example exercising both tags and identity updates.
- Drop the TrackedResourcePatchOperation suppression, no longer applicable.
- Scope ProvisioningStateMustBeReadOnly to the new PATCH 200 response schema.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add bastion session recording configuration and identity properties (#45630)

* Add bastion session recording configuration property

* Fix the patch body for identity support

* Update examples

* Fix prettier violation

* Revert documentation changes

* Add BastionHostUpdate model instead of anonymous type

* Add tpye constraint for userAssignedIdentityId

* Fix invalid arm id for public ip in example

* Fix wrong name in 200 responses in new examples

* Fix documentation for BastionHostUpdate

* Preserve existing updateTags operation

* Update suppression justification

* Revert previous changes which maintained the old operation

* Update suppression justification for update operation

---------

Co-authored-by: Matthew Lee <matthelee@microsoft.com>

* Add azureFirewall enableAiAddOn (#45976)

* Add azureFirewall enableAiAddOn

* Enable aiSecurityAddOn in Azure Firewall configuration

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* copilot messed up, fix typescript

* fix fields in exampels

* fix fields in examples

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Revert "Add NeuroShield API for 2026-01-01 (#45722)" (#46208)

This reverts commit efb6f29.

* Address swagger review findings on AuthenticationPolicy for 2026-01-01 (#46260)

* Address swagger review findings on AuthenticationPolicy

Resolves five of the review findings at the source rather than by
suppression, removing four AuthenticationPolicy suppressions.

RequiredReadOnlySystemData: declare systemData explicitly on
AuthenticationPolicy, following the existing Network RP pattern used by
AdminRuleCollection, BaseAdminRule and Commit. It is emitted read-only.

RPC-Delete-V1-01: drop the ArmDeletedNoContentResponse override so the
sync DELETE emits 200, 204 and default. AuthenticationPolicy was the only
resource in this project overriding the delete response; every sibling
uses the default. Removes the DeleteResponseCodes and
DeleteOperationResponses suppressions.

SEC-SECRET-DETECT: remove the secret-prop suppression. The rule only
fires on properties typed as the builtin string, and clientSecret is
typed url, so the suppression had no effect. The property holds only a
Key Vault reference, which the documentation now states explicitly. The
XMSSecretInResponse suppression is also removed, as nothing in the
generated file is marked x-ms-secret.

RPC-SUPPRESS-SCOPE: scope RequiredPropertiesMissingInResourceModel to
$.definitions.AuthenticationPolicy, and explain why
LatestVersionOfCommonTypesMustBeUsed stays file-level: the common-types
version is pinned package-wide by arm-types-dir, so the finding applies
to every common-types reference in the file rather than to any single
definition.

Section 4.1: document the authenticationPolicy Features member instead of
suppressing documentation-required, and replace the placeholder FIXME
justification on WebApplicationFirewallPolicyTier with a real one.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix LintDiff and ModelValidation failures on AuthenticationPolicy 2026-01-01

Three CI failures introduced by the previous review-feedback commit:

1. LintDiff RequiredPropertiesMissingInResourceModel: the where: scope added
   for this rule only covered $.definitions.AuthenticationPolicy, but the rule
   also fires on AuthenticationPolicyListResult. Added that definition to the
   scope and extended the reason to explain that the list result is a paged
   envelope rather than a resource.

2. LintDiff XMSSecretInResponse on clientSecret: removing the TypeSpec
   secret-prop suppression did not clear this because the swagger rule matches
   purely on the property name ending in a sensitive keyword. The property only
   ever carries an absolute HTTPS Key Vault reference URL, never secret
   material, so annotating it with x-ms-secret would be incorrect - it would
   stop the service returning the reference in GET. Renamed the property to
   clientSecretUrl, which both clears the rule without any suppression and
   describes the value accurately. 2026-01-01 is not yet published, so the
   rename carries no breaking-change cost.

3. ModelValidation RESPONSE_STATUS_CODE_NOT_IN_EXAMPLE: the delete operation
   now declares a 200 response, so AuthenticationPolicyDelete.json needs a
   matching (bodyless) 200 entry alongside the existing 204.

Swagger Avocado remains failing with MULTIPLE_API_VERSION on the
package-2026-01-01 tag. That failure reproduces on the base release branch PR
(#46086) and is unrelated to this change.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Rename clientSecretUrl to clientSecretUri

TypeSpec Validation compiles client.tsp with --warn-as-error, which surfaces
@azure-tools/typespec-client-generator-core/csharp-no-url-suffix: properties
ending in 'Url' must use the 'Uri' suffix so the generated C# surface is
idiomatic. The local emit-only compile of the Network project does not run
client.tsp, so this was missed.

clientSecretUri still avoids the LintDiff XMSSecretInResponse keyword match,
which only fires on names ending in a sensitive keyword.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Revert clientSecret rename and suppress XMSSecretInResponse instead

The rename to clientSecretUrl/clientSecretUri was wrong. The property name is
part of the contract already implemented by the Network resource provider, so
the spec has to match NRP rather than pick a name that happens to dodge the
linter's keyword match. Reverted to clientSecret.

To keep LintDiff green, XMSSecretInResponse is suppressed instead, scoped to
$.definitions.AuthenticationProviderProperties.properties.clientSecret. The
justification is substantive rather than a waiver: the property carries only an
absolute HTTPS Key Vault secret URL, never secret material - the secret value is
read from Key Vault at runtime using the resource's user-assigned identity and
is never accepted or returned by this API. Annotating it with x-ms-secret would
be actively incorrect, because that would stop the service returning the Key
Vault reference on GET, which callers need in order to see how a policy is
configured.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com>
Co-authored-by: Akshat Kale <kaleakshat@gmail.com>
Co-authored-by: Akshat Kale <akale@microsoft.com>
Co-authored-by: yaarark <yaararonenkr@gmail.com>
Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com>
Co-authored-by: Shaigoldbourt22 <118125561+Shaigoldbourt22@users.noreply.github.com>
Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: baoqihuang0326 <119557638+baoqihuang0326@users.noreply.github.com>
Co-authored-by: Arjun Patel <94936045+arjun-d-patel@users.noreply.github.com>
Co-authored-by: ajoyduwary <ajoyduwary@gmail.com>
Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com>
Co-authored-by: mshrimankar10 <66165250+mshrimankar10@users.noreply.github.com>
Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: paawankohli <44478509+paawankohli@users.noreply.github.com>
Co-authored-by: Paawan Kohli <paawankohli@microsoft.com>
Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com>
Co-authored-by: gurram-amulya <111553857+gurram-amulya@users.noreply.github.com>
Co-authored-by: kshitizmathur-max <kshitiz.mathur@gmail.com>
Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com>
Co-authored-by: Satya-Kotha1008 <sathi.kotha1008@gmail.com>
Co-authored-by: carenlim20 <carenlim+github@microsoft.com>
Co-authored-by: Caren Lim <carenlim@microsoft.com>
Co-authored-by: Matthew Lee <mwlee29@gmail.com>
Co-authored-by: Matthew Lee <matthelee@microsoft.com>
Co-authored-by: Ben Eshed <105308016+bewatersmsft@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3
Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants