Skip to content

Fix Hub virtual network IPv6 peering contract - #45637

Merged
carenlim20 merged 5 commits into
Azure:release-microsoft-network-2026-01-01from
carenlim20:enableOnlyIPv6Peering-boolean
Sep 1, 2026
Merged

carenlim20 merged 5 commits into
Azure:release-microsoft-network-2026-01-01from
carenlim20:enableOnlyIPv6Peering-boolean

Conversation

@carenlim20

@carenlim20 carenlim20 commented Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • correct HubVirtualNetworkConnectionProperties.enableOnlyIPv6Peering to match the deployed NRP JSON contract
  • model the property as boolean instead of the Enabled/Disabled string union
  • regenerate the 2025-09-01 and 2026-01-01 Swagger and examples from TypeSpec

Versioning rationale

The property was introduced in API version 2025-09-01, so both 2025-09-01 and 2026-01-01 must describe the same deployed wire contract. The PR targets the release-microsoft-network-2026-01-01 branch while correcting both generated stable projections on that branch.

Validation

  • npx tsp compile .
  • generated virtualWan.json uses enableOnlyIPv6Peering with type: boolean in both versions
  • generated examples use true/false
  • pre-2025-09-01 API-version files are unchanged
  • git diff --check

@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

Next Steps to Merge

✅ All automated merging requirements have been met! To get your PR merged, see aka.ms/azsdk/specreview/merge.

Comment generated by summarize-checks workflow run.

@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

API Change Check

APIView identified API level changes in this PR and created the following API reviews

Language API Review for Package
TypeSpec Microsoft.Network
Go sdk/resourcemanager/network/armnetwork
JavaScript @azure/arm-network
Java com.azure.resourcemanager:azure-resourcemanager-network
Python azure-mgmt-network

Comment generated by After APIView workflow run.

@github-actions github-actions Bot added ARMReview resource-manager TypeSpec Authored with TypeSpec WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required BreakingChange-Go-Sdk BreakingChange-JavaScript-Sdk BreakingChange-Python-Sdk labels Aug 19, 2026
carenlim and others added 2 commits August 24, 2026 08:50
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@carenlim20
carenlim20 force-pushed the enableOnlyIPv6Peering-boolean branch from 56e6d29 to 1084428 Compare August 24, 2026 15:50
@github-actions github-actions Bot added ARMChangesRequested and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 24, 2026
@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45637 at head SHA 10844284f30f79e340c4822fdbc151cf5e2efd70 | Triggered by: pull_request_target

Approval labels observed: none.

Category Count
🔴 Blocking 2
🟠 Warning 0
🔵 Suggestion 0

This PR renames the already-published property enableOnlyIpv6Peering to enableOnlyIPv6Peering and changes its type from a string enum to boolean in place within the already-existing stable/2025-09-01 and stable/2026-01-01 API versions (models.tsp, common.json, virtualWan.json), which is a same-version breaking change requiring a Versioning-Approved-* label (none observed); both instances were posted inline and critic-verified (PASS, High confidence).

posted-by: arm-api-reviewer-agent | rule: summary | severity: blocking | classification: new | critic: pass | head-sha: 1084428

🔍 ARM API review by ARM API Review: Automated Workflow

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ARM API Review

Posting findings from the ARM API Reviewer agent (critic-verified, 2 iteration(s), Blocking findings identified) against commit 10844284f30f79e340c4822fdbc151cf5e2efd70. See inline comments for findings 1-2.

Approval labels observed: none.

🔍 ARM API review by ARM API Review: Automated Workflow

@carenlim20 carenlim20 added the VersioningReviewRequired <valid label in PR review process>add this label when versioning review is required label Aug 26, 2026
@sandipsh Sandip Shahane (sandipsh) added the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Aug 26, 2026
@github-actions github-actions Bot removed the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Aug 26, 2026
@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45637 at head SHA 10844284f30f79e340c4822fdbc151cf5e2efd70 | Triggered by: pull_request_target

Approval labels observed: none.

Category Count
🔴 Blocking 2
🟠 Warning 0
🔵 Suggestion 0

No new commits since the last review at this same head SHA. Both previously-posted Blocking findings (RPC-Versioning: in-place rename/retype of the already-published enableOnlyIpv6Peering → enableOnlyIPv6Peering boolean in stable/2025-09-01 and stable/2026-01-01 virtualWan.json) remain open — the author replied with a justification (pre-GA feature, NRP contract mismatch, no live consumers) but no Versioning-Approved-* or BreakingChange-Approved-* label has been applied yet, so both findings are SKIP-COVERED (not reposted) rather than resolved. No new candidate findings were identified in this run.

posted-by: arm-api-reviewer-agent | rule: summary | severity: blocking | classification: existing | critic: pass | head-sha: 1084428

🔍 ARM API review by ARM API Review: Automated Workflow

@carenlim20 carenlim20 added WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required and removed NotReadyForARMReview labels Aug 26, 2026
@github-actions github-actions Bot added NotReadyForARMReview ARMAutoSignedOff-IncrementalTSP ARMSignedOff <valid label in PR review process>add this label when ARM approve updates after review and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 26, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ARM API Review

Posting reconciliation update from the ARM API Reviewer agent (Critic unavailable; reviewer self-check only, 3 dispatch attempts, both prior Blocking findings now covered by approval label) against commit a638272c5ca44b8601ee245c49b35c4f54bbe5b9. No new inline findings; both previously-posted Blocking findings are now approved and their threads have replies acknowledging resolution. All findings are reported in the summary comment.

Approval labels observed: BreakingChange-Approved-BugFix.

🔍 ARM API review by ARM API Review: Automated Workflow

@kazrael2119

Copy link
Copy Markdown
Member

/azp run SDK Validation - JS

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@github-actions github-actions Bot added WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required and removed ARMAutoSignedOff-Test ARMAutoSignedOff-IncrementalTSP ARMSignedOff <valid label in PR review process>add this label when ARM approve updates after review labels Sep 1, 2026
@github-actions github-actions Bot added BreakingChange-Go-Sdk-Suppression BreakingChange-JavaScript-Sdk-Suppression ARMAutoSignedOff-IncrementalTSP ARMSignedOff <valid label in PR review process>add this label when ARM approve updates after review and removed BreakingChange-Go-Sdk WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Sep 1, 2026
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45637 at head SHA 0af32a9cb330755f9b5b6513728ff45993c85a0f | Triggered by: pull_request_target

Approval labels observed: BreakingChange-Approved-BugFix.

Category Count
🔴 Blocking 0
🟠 Warning 0
🔵 Suggestion 0

Since the last review (head a638272c5ca44b8601ee245c49b35c4f54bbe5b9), two new commits were pushed: Update client.tsp (adds @@clientName`` mitigations for Azure.ResourceManager.CommonTypes.ProxyResource/`Resource` for JavaScript) and `Update sdk-suppressions.yaml` (adds Go/JS SDK breaking-change suppression entries for the `EnableOnlyIPv6Peering`/`EnableOnlyIpv6PeeringState` rename-and-retype). Both previously-posted Blocking `RPC-Versioning` findings (in-place same-version rename/retype of `enableOnlyIpv6Peering` → `enableOnlyIPv6Peering`, string enum → `boolean`, in `stable/2025-09-01` and `stable/2026-01-01` `virtualWan.json`) remain covered: `BreakingChange-Approved-BugFix` is still present, the corresponding threads are already resolved, and no further changes to those definitions occurred in this push. The new `client.tsp` client-name mitigations and `sdk-suppressions.yaml` additions are consistent with, and directly support, the already-approved breaking change (they suppress/mitigate downstream Go/JS SDK breaks from the same property rename/retype); no new violations were identified. No new candidate findings were identified in this run.

posted-by: arm-api-reviewer-agent | rule: summary | severity: suggestion | classification: existing | critic: unknown | head-sha: 0af32a9

🔍 ARM API review by ARM API Review: Automated Workflow

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ARM API Review

Posting findings from the ARM API Reviewer agent (Critic unavailable; reviewer self-check only, 1 iteration, no new findings) against commit 0af32a9cb330755f9b5b6513728ff45993c85a0f. All findings are reported in the summary comment.

Approval labels observed: BreakingChange-Approved-BugFix.

🔍 ARM API review by ARM API Review: Automated Workflow

@arganapathy arganapathy left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good

@carenlim20
carenlim20 merged commit 7afe363 into Azure:release-microsoft-network-2026-01-01 Sep 1, 2026
148 of 154 checks passed
@santoshgh317 santoshgh317 mentioned this pull request Sep 3, 2026
5 of 9 tasks
santoshgh317 added a commit that referenced this pull request Sep 15, 2026
* Add API version 2026-01-01 for Microsoft.Network (#45569)

Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com>

* Add Enum values for VPN migrationType (#45647)

Co-authored-by: Akshat Kale <akale@microsoft.com>

* Fix Bug 38477992: type computedDisabledRules.rules as integers (2026-01-01) (#45621)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com>
Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3

* [Network] Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01 (#45625)

* Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01

Ports the change from azure-rest-api-specs-pr PR 29807 onto the public
2026-01-01 release branch.

Adds three read-only properties that NRP surfaces from api-version
2026-01-01 for Application Gateway WAF:

- paranoiaLevel on ApplicationGatewayFirewallRule
- displayName on ApplicationGatewayFirewallRuleSetPropertiesFormat
- displayName on ApplicationGatewayFirewallManifestRuleSet
- displayName on DefaultRuleSetPropertyFormat

paranoiaLevel uses a new extensible enum ApplicationGatewayWafRuleParanoiaLevel
with values PL1 to PL4.

All new members are annotated with @added(Versions.v2026_01_01). The change is
additive and all new properties are optional.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Retrigger CI

The SDK Validation - Rust build failed on a transient GitHub timeout
while installing the Azure SDK Tools CLI. Nothing in the spec changed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Centurion WAF: add WAF policy tier + Basic_v2/Basic_WAF_v2 SKUs (2026-01-01) (#45766)

* Add Centurion WAF updates for 2026-01-01

Update WAF policy tier and reserved capacity support.

Add Basic_v2 and Basic_WAF_v2 SKUs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Basic v2 application gateway tiers

WebApplicationFirewallPolicyTier ordering aligns Standard=0 and Basic=1.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Basic WAF and application gateway examples

Add Basic WAF policy create/get examples and Basic-tier coverage.

Add Basic_v2 and Basic_WAF_v2 application gateway create/get examples, including reservedCapacity and WAF policy association.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add AuthenticationPolicy resource and Application Gateway authConfigs binding for 2026-01-01 (#45764)

* Add AuthenticationPolicy support for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Align AuthenticationPolicy contract with service behavior

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Enforce AuthenticationPolicy name and binding constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add authentication policy tags update

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

---------

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 (#45650)

* Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01

Adds optional min/max allocation-size bounds to the Microsoft.Network
IpamPool resource in api-version 2026-01-01:

- IpamPoolProperties (PUT/GET): minAllocationSize, maxAllocationSize
- IpamPoolUpdateProperties (PATCH): minAllocationSize, maxAllocationSize
  marked x-nullable so an explicit null clears the bound while an absent
  bound is preserved, per ARM merge-patch semantics.

Both properties are gated with @added(Versions.v2026_01_01) so earlier
api-versions are unchanged. Regenerated virtualNetwork.json and updated
the 2026-01-01 IpamPools Create/Get/List/Update examples.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Move min/max allocation size into dedicated IpamPool examples

The allocation-size bounds are optional, so the baseline IpamPools
examples should not imply they are always supplied. Restores
IpamPools_Create/Get/List/Update to their original content and adds
dedicated examples that exercise the feature:

- IpamPools_CreateWithAllocationBounds.json: PUT setting both bounds.
- IpamPools_UpdateAllocationBounds.json: PATCH setting both bounds.
- IpamPools_UpdateClearAllocationBounds.json: PATCH clearing both
  bounds with an explicit null, per ARM merge-patch semantics.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Address ARM review: drop nullable union on new min/max update properties

New properties must not use a nullable union, since backward
compatibility does not apply to additions. The RP already treats an
empty string as a clear on PATCH, so the explicit null is unnecessary.

- IpamPoolUpdateProperties min/maxAllocationSize: string | null -> string,
  removing the no-nullable suppressions and x-nullable from the swagger.
- Document clearing via an empty string.
- IpamPools_UpdateClearAllocationBounds example now clears with "".

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add Swagger Avocado suppression for frozen 2018-10-01 VMSS surface

Per ARM reviewer guidance on PR #45650: the package-2026-01-01 default
tag intentionally retains stable/2018-10-01/vmssNetwork.json for
backward compatibility, which trips Avocado's MULTIPLE_API_VERSION rule.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix Avocado suppression tool name to SwaggerAvocado

Per ARM reviewer bot feedback on PR #45650: the suppression tool name
has no space.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add approvalReference to private endpoint connection in 2026-01-01 (#45604)

* Add approvalReference (create-only) to private endpoint connection in 2026-01-01

Adds optional approvalReference.privateEndpointId to PrivateLinkServiceConnectionProperties, gated @added(v2026_01_01) with @visibility(Lifecycle.Read, Lifecycle.Create) so it is create-only (emits x-ms-mutability: [read, create]) and is not resupplied on update.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Regenerate vmssNetwork.json for approvalReference (Vmss project)

The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and emits stable/2018-10-01/vmssNetwork.json, which must be regenerated so approvalReference/ApprovalReference are included. Fixes TypeSpec Validation (Vmss).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Remove x-ms-mutability (create-only) from approvalReference

Per internal discussion, drop the create-only mutability restriction on
approvalReference. Removes the @visibility(Lifecycle.Read, Lifecycle.Create)
decorator in Common/main.tsp and regenerates the Network and Vmss project
swaggers so x-ms-mutability is no longer emitted. The approvalReference
property and ApprovalReference model are retained.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Type approvalReference.privateEndpointId as armResourceIdentifier

Address ARM review finding [TSP-ARM-RESOURCE-ID]: privateEndpointId references an existing private endpoint, so type it as Azure.Core.armResourceIdentifier<Microsoft.Network/privateEndpoints> instead of plain string. Regenerated swagger emits format: arm-id and x-ms-arm-id-details.allowedResources.

---------

Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Add ExpressRoutCircuit on ExpressRouteLag (#45689)

* Add ExpressRoutCircuit on ExpressRouteLag

* Fix ExpressRouteLag examples: sync circuits to output copies and remove invalid circuit properties

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Align ExpressRouteCircuitCreateOnExpressRouteLag responses with request (EX-PARAM-CONSISTENCY)

Fix response bodies to match request: LAG reference lagName (was test),
enableDirectPortRateLimit true, and SKU Premium_MeteredData in the 200 response.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* Add AppGw Advanced Routing Rule in NRR API 2026-01-01 (#45844)

* Add advanced routing features to Application Gateway for API version 2026-01-01

* buid artifacts after changes to models.tsp

* added examples

* fix merge conflict

---------

Co-authored-by: Paawan Kohli <paawankohli@microsoft.com>

* Modify sdk-suppressions.yaml for breaking changes (#45914)

Updated breaking changes for Azure SDK suppressions in network resource manager.

* [Microsoft.Network] Add provider-led ExpressRoute circuit migration APIs (#45905)

* Add ExpressRoute circuit migration APIs

Add TypeSpec operations and models for provider-led ExpressRoute circuit migration, generated 2026-01-01 Swagger, examples, and the scoped brownfield resource-name suppression.

* Fix Network specification validation

Use valid UUID subscription IDs, add required TypeSpec example metadata, regenerate migration LRO metadata, and suppress the intentional mixed-version VMSS surface in the combined Network package.

* Fix Network Avocado suppression

Move the mixed API-version exception from an unsupported AutoRest directive to the Network SwaggerAvocado path-suppression file, scoped to the default-tag readme.

* Fix Network validation suppressions

* Correct Avocado suppression identifier

* Geo-Ip filter changes (#45631)

* Geo Ip Filter Changes

* Document GeoIP filter format (ISO 3166-1 alpha-2) and fix WAF scrubbing-rule model

* Fixing Swagger ModelValidation Filure related errors

* Dummy Push to reinitate build

* Type Spec validation failure fix

* Remove duplicate GeoIP filter properties

---------

Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com>

* Add NeuroShield API for 2026-01-01 (#45722)

* Add NeuroShield API for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add NeuroShield API for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Align NeuroShield contract with service behavior

Require customer-facing configuration, align mitigation responses with the safe service projection, make cancellation synchronous, and correct protected-resource delete polling.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Refine NeuroShield 2026-01-01 contract

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Fix NeuroShield validation regressions

* Address ARM review feedback for NeuroShield

Use supported ARM resource templates, scope Swagger suppressions to exact operations, and isolate inherited Network validation debt.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Fix NeuroShield LintDiff suppressions

* Use standard ARM entity tag property

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Add post calls for auth key of authorization objects for expressrouteciruits and expressrouteports (#45679)

* Added post calls for expressroute auth key

* Added the objects in 2026-01-01 version

* addressed ai comments

* Addressed comments

* fixed

* removed suppression

* fixed suppressions

---------

Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com>

* Fix Hub virtual network IPv6 peering contract (#45637)

* Fix IPv6 peering contract for Network 2026-01-01
* Correct IPv6 peering contract in Network 2025-09-01
* Update client.tsp

* Update sdk-suppressions.yaml

---------

Co-authored-by: Caren Lim <carenlim@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: kazrael2119 <98569699+kazrael2119@users.noreply.github.com>

* Correct AuthenticationPolicy contract for 2026-01-01 (#45892)

* Correct authentication policy contract

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Keep provider type extensible

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Document authentication policy constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Align authentication examples with service

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Restore authentication policy tags update

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Suppress PatchIdentityProperty for AuthenticationPolicies_UpdateTags

The tags-only PATCH takes the shared Network RP TagsObject body, matching
ApplicationGateways_UpdateTags. The service only updates tags on this
operation, so identity does not belong in the request body.

* Complete authentication policy constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Correct Basic v2 authentication example

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Address ARM review feedback on AuthenticationPolicy 2026-01-01

- Make the arm-resource-invalid-envelope-property suppression reason self-contained by stating why the user-assigned identity belongs in the resource envelope.
- Scope the PatchIdentityProperty suppression with a where: clause targeting the AuthenticationPolicies_UpdateTags PATCH operation.
- Type issuer as url and require an https scheme, consistent with jwksUri and clientSecret.
- Document the sessionTimeout string syntax and units, and constrain it with a base-10 integer pattern and max length.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Also scope PatchIdentityProperty suppression to the PATCH body parameter path

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Remove AuthenticationPolicy PATCH operation

The service supports only GET, PUT, and DELETE for authenticationPolicies,
matching ApplicationGatewayWebApplicationFirewallPolicies, which also ships
without a PATCH. Removing the tags-only PATCH also resolves the
PatchIdentityProperty finding at its source: that rule fires only on an
existing PATCH, so with no PATCH the identity envelope property no longer
needs a suppression.

- Remove AuthenticationPolicies_UpdateTags and its source and generated examples.
- Drop the PatchIdentityProperty suppression.
- Restore the TrackedResourcePatchOperation no-PATCH suppression.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Drop stale PATCH path from ProvisioningStateMustBeReadOnly suppression

The AuthenticationPolicy PATCH operation was removed, so the patch response
entry in the where: list no longer matches anything.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Restore AuthenticationPolicy PATCH with a resource-specific update model

AuthenticationPolicy is a tracked resource: it extends the Network RP
Resource base type, which supplies location, tags and x-ms-azure-resource.
ARM requires resource providers to support PATCH for updating tags on a
tracked resource, so removing the operation was incorrect.

Restore PATCH using a resource-specific AuthenticationPolicyUpdateParameters
model carrying both tags and identity, rather than the shared TagsObject.
This satisfies the tracked-resource tags requirement and the MSI onboarding
requirement that the control plane accept identity updates on PATCH, which
means PatchIdentityProperty is now satisfied at the source and needs no
suppression.

- Add AuthenticationPolicyUpdateParameters (tags, identity).
- Add AuthenticationPolicies_Update, replacing the former tags-only
  AuthenticationPolicies_UpdateTags.
- Add an example exercising both tags and identity updates.
- Drop the TrackedResourcePatchOperation suppression, no longer applicable.
- Scope ProvisioningStateMustBeReadOnly to the new PATCH 200 response schema.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add bastion session recording configuration and identity properties (#45630)

* Add bastion session recording configuration property

* Fix the patch body for identity support

* Update examples

* Fix prettier violation

* Revert documentation changes

* Add BastionHostUpdate model instead of anonymous type

* Add tpye constraint for userAssignedIdentityId

* Fix invalid arm id for public ip in example

* Fix wrong name in 200 responses in new examples

* Fix documentation for BastionHostUpdate

* Preserve existing updateTags operation

* Update suppression justification

* Revert previous changes which maintained the old operation

* Update suppression justification for update operation

---------

Co-authored-by: Matthew Lee <matthelee@microsoft.com>

* Add azureFirewall enableAiAddOn (#45976)

* Add azureFirewall enableAiAddOn

* Enable aiSecurityAddOn in Azure Firewall configuration

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* copilot messed up, fix typescript

* fix fields in exampels

* fix fields in examples

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Revert "Add NeuroShield API for 2026-01-01 (#45722)" (#46208)

This reverts commit efb6f29.

* Address swagger review findings on AuthenticationPolicy for 2026-01-01 (#46260)

* Address swagger review findings on AuthenticationPolicy

Resolves five of the review findings at the source rather than by
suppression, removing four AuthenticationPolicy suppressions.

RequiredReadOnlySystemData: declare systemData explicitly on
AuthenticationPolicy, following the existing Network RP pattern used by
AdminRuleCollection, BaseAdminRule and Commit. It is emitted read-only.

RPC-Delete-V1-01: drop the ArmDeletedNoContentResponse override so the
sync DELETE emits 200, 204 and default. AuthenticationPolicy was the only
resource in this project overriding the delete response; every sibling
uses the default. Removes the DeleteResponseCodes and
DeleteOperationResponses suppressions.

SEC-SECRET-DETECT: remove the secret-prop suppression. The rule only
fires on properties typed as the builtin string, and clientSecret is
typed url, so the suppression had no effect. The property holds only a
Key Vault reference, which the documentation now states explicitly. The
XMSSecretInResponse suppression is also removed, as nothing in the
generated file is marked x-ms-secret.

RPC-SUPPRESS-SCOPE: scope RequiredPropertiesMissingInResourceModel to
$.definitions.AuthenticationPolicy, and explain why
LatestVersionOfCommonTypesMustBeUsed stays file-level: the common-types
version is pinned package-wide by arm-types-dir, so the finding applies
to every common-types reference in the file rather than to any single
definition.

Section 4.1: document the authenticationPolicy Features member instead of
suppressing documentation-required, and replace the placeholder FIXME
justification on WebApplicationFirewallPolicyTier with a real one.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix LintDiff and ModelValidation failures on AuthenticationPolicy 2026-01-01

Three CI failures introduced by the previous review-feedback commit:

1. LintDiff RequiredPropertiesMissingInResourceModel: the where: scope added
   for this rule only covered $.definitions.AuthenticationPolicy, but the rule
   also fires on AuthenticationPolicyListResult. Added that definition to the
   scope and extended the reason to explain that the list result is a paged
   envelope rather than a resource.

2. LintDiff XMSSecretInResponse on clientSecret: removing the TypeSpec
   secret-prop suppression did not clear this because the swagger rule matches
   purely on the property name ending in a sensitive keyword. The property only
   ever carries an absolute HTTPS Key Vault reference URL, never secret
   material, so annotating it with x-ms-secret would be incorrect - it would
   stop the service returning the reference in GET. Renamed the property to
   clientSecretUrl, which both clears the rule without any suppression and
   describes the value accurately. 2026-01-01 is not yet published, so the
   rename carries no breaking-change cost.

3. ModelValidation RESPONSE_STATUS_CODE_NOT_IN_EXAMPLE: the delete operation
   now declares a 200 response, so AuthenticationPolicyDelete.json needs a
   matching (bodyless) 200 entry alongside the existing 204.

Swagger Avocado remains failing with MULTIPLE_API_VERSION on the
package-2026-01-01 tag. That failure reproduces on the base release branch PR
(#46086) and is unrelated to this change.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Rename clientSecretUrl to clientSecretUri

TypeSpec Validation compiles client.tsp with --warn-as-error, which surfaces
@azure-tools/typespec-client-generator-core/csharp-no-url-suffix: properties
ending in 'Url' must use the 'Uri' suffix so the generated C# surface is
idiomatic. The local emit-only compile of the Network project does not run
client.tsp, so this was missed.

clientSecretUri still avoids the LintDiff XMSSecretInResponse keyword match,
which only fires on names ending in a sensitive keyword.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Revert clientSecret rename and suppress XMSSecretInResponse instead

The rename to clientSecretUrl/clientSecretUri was wrong. The property name is
part of the contract already implemented by the Network resource provider, so
the spec has to match NRP rather than pick a name that happens to dodge the
linter's keyword match. Reverted to clientSecret.

To keep LintDiff green, XMSSecretInResponse is suppressed instead, scoped to
$.definitions.AuthenticationProviderProperties.properties.clientSecret. The
justification is substantive rather than a waiver: the property carries only an
absolute HTTPS Key Vault secret URL, never secret material - the secret value is
read from Key Vault at runtime using the resource's user-assigned identity and
is never accepted or returned by this API. Annotating it with x-ms-secret would
be actively incorrect, because that would stop the service returning the Key
Vault reference on GET, which callers need in order to see how a policy is
configured.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com>
Co-authored-by: Akshat Kale <kaleakshat@gmail.com>
Co-authored-by: Akshat Kale <akale@microsoft.com>
Co-authored-by: yaarark <yaararonenkr@gmail.com>
Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com>
Co-authored-by: Shaigoldbourt22 <118125561+Shaigoldbourt22@users.noreply.github.com>
Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: baoqihuang0326 <119557638+baoqihuang0326@users.noreply.github.com>
Co-authored-by: Arjun Patel <94936045+arjun-d-patel@users.noreply.github.com>
Co-authored-by: ajoyduwary <ajoyduwary@gmail.com>
Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com>
Co-authored-by: mshrimankar10 <66165250+mshrimankar10@users.noreply.github.com>
Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: paawankohli <44478509+paawankohli@users.noreply.github.com>
Co-authored-by: Paawan Kohli <paawankohli@microsoft.com>
Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com>
Co-authored-by: gurram-amulya <111553857+gurram-amulya@users.noreply.github.com>
Co-authored-by: kshitizmathur-max <kshitiz.mathur@gmail.com>
Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com>
Co-authored-by: Satya-Kotha1008 <sathi.kotha1008@gmail.com>
Co-authored-by: carenlim20 <carenlim+github@microsoft.com>
Co-authored-by: Caren Lim <carenlim@microsoft.com>
Co-authored-by: Matthew Lee <mwlee29@gmail.com>
Co-authored-by: Matthew Lee <matthelee@microsoft.com>
Co-authored-by: Ben Eshed <105308016+bewatersmsft@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3
Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants