Skip to content

Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 - #45650

Merged
santoshgh317 merged 6 commits into
Azure:release-microsoft-network-2026-01-01from
arjun-d-patel:arjun/ipam-minmax-allocation-size
Aug 27, 2026
Merged

santoshgh317 merged 6 commits into
Azure:release-microsoft-network-2026-01-01from
arjun-d-patel:arjun/ipam-minmax-allocation-size

Conversation

@arjun-d-patel

Copy link
Copy Markdown
Contributor

ARM (Control Plane) API Specification Update Pull Request

Tip

Overwhelmed by all this guidance? See the Getting help section at the bottom of this PR description.

PR review workflow diagram

Please understand this diagram before proceeding. It explains how to get your PR approved & merged.

spec_pr_review_workflow_diagram

Purpose of this PR

What's the purpose of this PR? Check the specific option that applies. This is mandatory!

  • New resource provider.
  • New API version for an existing resource provider. (If API spec is not defined in TypeSpec, the PR should have been created in adherence to OpenAPI specs PR creation guidance).
  • Update existing version for a new feature. (This is applicable only when you are revising a private preview API version.)
  • Update existing version to fix OpenAPI spec quality issues in S360.
  • Convert existing OpenAPI spec to TypeSpec spec (do not combine this with implementing changes for a new API version).
  • Other, please clarify:
    • edit this with your clarification

Due diligence checklist

To merge this PR, you must go through the following checklist and confirm you understood
and followed the instructions by checking all the boxes:

  • I confirm this PR is modifying Azure Resource Manager (ARM) related specifications, and not data plane related specifications.
  • I have reviewed following Resource Provider guidelines, including
    ARM resource provider contract and
    REST guidelines (estimated time: 4 hours).
    I understand this is required before I can proceed to the diagram Step 2, "ARM API changes review", for this PR.
  • A release plan has been created. If not, please create one as it will help guide you through the REST API and SDK creation process.

Additional information

Viewing API changes

For convenient view of the API changes made by this PR, refer to the URLs provided in the table
in the Generated ApiView comment added to this PR. You can use ApiView to show API versions diff.

Suppressing failures

If one or multiple validation error/warning suppression(s) is detected in your PR, please follow the
suppressions guide to get approval.

Getting help

  • First, please carefully read through this PR description, from top to bottom. Please fill out the Purpose of this PR and Due diligence checklist.
  • If you don't have permissions to remove or add labels to the PR, request write access per aka.ms/azsdk/access#request-access-to-rest-api-or-sdk-repositories
  • To understand what you must do next to merge this PR, see the Next Steps to Merge comment. It will appear within few minutes of submitting this PR and will continue to be up-to-date with current PR state.
  • For guidance on fixing this PR CI check failures, see the hyperlinks provided in given failure
    and https://aka.ms/ci-fix.
  • For help with ARM review (PR workflow diagram Step 2), see https://aka.ms/azsdk/pr-arm-review.
  • If the PR CI checks appear to be stuck in queued state, please add a comment with contents /azp run.
    This should result in a new comment denoting a PR validation pipeline has started and the checks should be updated after few minutes.
  • If the help provided by the previous points is not enough, post to https://aka.ms/azsdk/support/specreview-channel and link to this PR.
  • For guidance on SDK breaking change review, refer to https://aka.ms/ci-fix.

Adds optional min/max allocation-size bounds to the Microsoft.Network
IpamPool resource in api-version 2026-01-01:

- IpamPoolProperties (PUT/GET): minAllocationSize, maxAllocationSize
- IpamPoolUpdateProperties (PATCH): minAllocationSize, maxAllocationSize
  marked x-nullable so an explicit null clears the bound while an absent
  bound is preserved, per ARM merge-patch semantics.

Both properties are gated with @added(Versions.v2026_01_01) so earlier
api-versions are unchanged. Regenerated virtualNetwork.json and updated
the 2026-01-01 IpamPools Create/Get/List/Update examples.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

Next Steps to Merge

✅ All automated merging requirements have been met! To get your PR merged, see aka.ms/azsdk/specreview/merge.

Comment generated by summarize-checks workflow run.

@github-actions github-actions Bot added ARMReview resource-manager TypeSpec Authored with TypeSpec WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 19, 2026
The allocation-size bounds are optional, so the baseline IpamPools
examples should not imply they are always supplied. Restores
IpamPools_Create/Get/List/Update to their original content and adds
dedicated examples that exercise the feature:

- IpamPools_CreateWithAllocationBounds.json: PUT setting both bounds.
- IpamPools_UpdateAllocationBounds.json: PATCH setting both bounds.
- IpamPools_UpdateClearAllocationBounds.json: PATCH clearing both
  bounds with an explicit null, per ARM merge-patch semantics.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

API Change Check

APIView identified API level changes in this PR and created the following API reviews

Language API Review for Package
TypeSpec Microsoft.Network
Go sdk/resourcemanager/network/armnetwork
JavaScript @azure/arm-network
Java com.azure.resourcemanager:azure-resourcemanager-network
Python azure-mgmt-network
C# Azure.ResourceManager.Network

Comment generated by After APIView workflow run.

@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45650 at head SHA b5805a5d59d12d3056a924b5ef3fe2156cba1961 | Triggered by: pull_request_target

Approval labels observed: none.

Category Count
🔴 Blocking 0
🟠 Warning 1
🔵 Suggestion 1

This PR adds minAllocationSize/maxAllocationSize to IpamPool for API version 2026-01-01 (TypeSpec + generated OpenAPI + examples). Two inline findings were posted: (1) the new IpamPoolUpdateProperties fields use a string | null union with a suppressed lint rule, which the anti-pattern rules disallow for newly-added properties; (2) both properties represent numeric IP-count bounds but are typed string rather than a numeric scalar. No breaking changes, security issues, or blocking violations were found; examples and readme/tag wiring for the new scenarios look consistent with the schema changes.

posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: new | critic: unknown | head-sha: b5805a5

🔍 ARM API review by ARM API Review: Automated Workflow

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ARM API Review

Posting findings from the ARM API Reviewer agent (Critic unavailable; reviewer self-check only, 1 iteration(s), 2 findings posted) against commit b5805a5d59d12d3056a924b5ef3fe2156cba1961. See inline comments for findings 1-2.

Approval labels observed: none.

🔍 ARM API review by ARM API Review: Automated Workflow

New properties must not use a nullable union, since backward
compatibility does not apply to additions. The RP already treats an
empty string as a clear on PATCH, so the explicit null is unnecessary.

- IpamPoolUpdateProperties min/maxAllocationSize: string | null -> string,
  removing the no-nullable suppressions and x-nullable from the swagger.
- Document clearing via an empty string.
- IpamPools_UpdateClearAllocationBounds example now clears with "".

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45650 at head SHA 4f5974927f6f9c6f532af6ccda42a551c53e1fbc | Triggered by: pull_request_target

Approval labels observed: none.

Category Count
🔴 Blocking 0
🟠 Warning 0
🔵 Suggestion 0

Both prior findings from the previous run (head b5805a5d59d12d3056a924b5ef3fe2156cba1961) were reconciled at the current head SHA and closed: the nullable-union anti-pattern on IpamPoolUpdateProperties.minAllocationSize/maxAllocationSize was fixed (now plain string, suppressions removed, clear-via-empty-string demonstrated in the updated example), and the numeric-scalar suggestion for the same properties was resolved by the author's documented rationale that IPv6 allocation-size bounds (up to 2^121) exceed every TypeSpec integer scalar's range, making string/BigInteger serialization an intentional, sound design choice. No new findings were identified against the current diff. The Critic subagent was unavailable in this run (missing protocol files in its sandbox after retry), so this reconciliation reflects reviewer self-check only; no Blocking findings were involved, so no label changes were made.

posted-by: arm-api-reviewer-agent | rule: summary | severity: suggestion | classification: existing | critic: unknown | head-sha: 4f59749

🔍 ARM API review by ARM API Review: Automated Workflow

@psah434

Copy link
Copy Markdown
Member

required check swagger avocado is failing. Please check

@arjun-d-patel

Copy link
Copy Markdown
Contributor Author

required check swagger avocado is failing. Please check

Hi Pallavi Sah (@psah434) it is in the upstream branch where the issue is. I don't think my changes are causing this issue. Do you need me to resolve it in this PR?

@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45650 at head SHA 33490449c8603d5865edd7d3d55b3de668b27350 | Triggered by: pull_request_target

Approval labels observed: none.

Category Count
🔴 Blocking 0
🟠 Warning 0
🔵 Suggestion 0

This PR adds minAllocationSize/maxAllocationSize to IpamPool for API version 2026-01-01 (TypeSpec + generated OpenAPI + examples). Reconciliation against the existing discussion surfaces confirms both prior findings from earlier runs (nullable-union anti-pattern on IpamPoolUpdateProperties.minAllocationSize/maxAllocationSize, and the string-vs-numeric-type suggestion) were already addressed and resolved: both properties are plain string (no | null union), the no-nullable suppressions were removed, and the author documented a sound rationale (IPv6 allocation-size bounds up to 2^121 exceed every TypeSpec integer scalar) for retaining string/BigInteger semantics. The current diff at this head SHA is unchanged from the previously-reviewed and resolved state (4f5974927f6f9c6f532af6ccda42a551c53e1fbc) — no new spec content, operations, or schema changes were introduced. No new violations, breaking changes, or security issues were identified. No label changes are required since no Blocking finding is queued for publication.

posted-by: arm-api-reviewer-agent | rule: summary | severity: suggestion | classification: existing | critic: unknown | head-sha: 3349044

🔍 ARM API review by ARM API Review: Automated Workflow

@arjun-d-patel

Copy link
Copy Markdown
Contributor Author

required check swagger avocado is failing. Please check

Hi Pallavi Sah (Pallavi Sah (@psah434)) it is in the upstream branch where the issue is. I don't think my changes are causing this issue. Do you need me to resolve it in this PR?

Correction to this. Hi ARM reviewer team, can you also please add suppression for Swagger Avacodo as the default tag intentionally includes vmssNetwork.json from 2018-10-01 for backward compatibility. Please find reference PR where suppression was provided
Add API version 2025-07-01 for Microsoft.Network by santoshgh317 · Pull Request #41904 · Azure/azur…

@sandipsh

Copy link
Copy Markdown
Contributor

Following up on the Avocado failure: the narrow exception is approved from the ARM review perspective. This is a pre-existing frozen VMSS surface, not an issue introduced by the IpamPool change.

Please add this to Network/Network/suppressions.yaml and rerun CI:

- tool: Swagger Avocado
  path: ./stable/2018-10-01/vmssNetwork.json
  reason: The package-2026-01-01 default tag intentionally retains the frozen 2018-10-01 VMSS network surface for backward compatibility; moving it to 2026-01-01 would break existing clients.

This keeps the exception scoped to the legacy file; without it, the required Avocado check remains blocking.

@sandipsh Sandip Shahane (sandipsh) added ARMChangesRequested and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 24, 2026
Per ARM reviewer guidance on PR Azure#45650: the package-2026-01-01 default
tag intentionally retains stable/2018-10-01/vmssNetwork.json for
backward compatibility, which trips Avocado's MULTIPLE_API_VERSION rule.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@arjun-d-patel

Copy link
Copy Markdown
Contributor Author

Thanks Sandip Shahane (@sandipsh) — added the suppression in 5485f40 as requested.

Before we wait on a CI cycle, could you sanity-check a couple of things I ran into while adding it? I may well be misreading the tooling here, so I'd rather ask than assume.

  1. I couldn't find where the Avocado job consumes suppressions.yaml. .github/workflows/avocado-code.yaml looks like it invokes the CLI directly with --excludePaths/--includePaths/--file, and I don't see a get-suppressions call or an @azure-tools/suppressions import in that job. Is the suppression picked up somewhere else in the pipeline that I'm not seeing?

  2. eng/tools/suppressions/README.md lists the recognized Swagger tool names as SwaggerLintDiff, SwaggerModelValidation, SwaggerSemanticValidation, SwaggerBreakingChange, SwaggerBreakingChangeCrossVersion, and SwaggerAll. Should the tool value be one of those rather than Swagger Avocado?

  3. On the path: the README says patterns are relative to the suppressions.yaml file, and getSuppressions walks up from the file being analyzed. vmssNetwork.json lives at Network/stable/2018-10-01/, whereas the file I edited is at Network/Network/suppressions.yaml — and Network/Network/stable/ doesn't exist. Would this be better placed in Network/suppressions.yaml so the ./stable/2018-10-01/... pattern resolves? Happy to move it.

Separately, I noticed .github/workflows/avocado-status.yaml declares overriding_label: "Approved-Avocado" for the Swagger Avocado required check, and the reference PR #41904 carries that label. Would applying Approved-Avocado here be the intended path as well, or is the suppression meant to replace that?

Happy to adjust whichever way you'd like — just want to make sure we land it correctly rather than burning CI runs.

@arjun-d-patel Arjun Patel (arjun-d-patel) added WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required and removed ARMChangesRequested labels Aug 24, 2026
@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45650 at head SHA 5485f40b07a571caa38b287cc349ad9b6ed8f4f6.

Approval labels observed: none.

Category Count
Blocking 0
Warning 1
Suggestion 0
Resolved from prior runs 2

The spec changes (minAllocationSize/maxAllocationSize on IpamPool for 2026-01-01) are sound; the two previously-raised findings (nullable-property anti-pattern and numeric-type-as-string suggestion) were already addressed by the author and remain resolved with no regressions. One new warning was posted on the newly-added suppressions.yaml entry: it uses tool: Swagger Avocado (with a space), but the Azure/avocado tool's source only recognizes SwaggerAvocado (no space) and SwaggerAll, so the suppression likely won't take effect as written — this doesn't contest the underlying ARM-approved exception for the frozen vmssNetwork.json surface, just flags a probable mechanical typo to fix (SwaggerAvocado). Critic review was unavailable after 3 attempts due to missing protocol files in this checkout, so the finding is disclosed with critic: unknown.

posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: new | critic: unknown | head-sha: 5485f40

🔍 ARM API review by ARM API Review: Automated Workflow

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed at head SHA 5485f40b07a571caa38b287cc349ad9b6ed8f4f6. Both prior findings (nullable-property anti-pattern, numeric-type-as-string suggestion) remain resolved — no regressions. One new warning-level finding posted inline on suppressions.yaml regarding a likely tool-name mismatch (Swagger Avocado vs. expected SwaggerAvocado) that may prevent the intended CI suppression from taking effect; this does not contest the underlying ARM-approved exception itself. Critic review was unavailable after 3 attempts (missing protocol files), so this finding is marked critic: unknown per fallback policy.

posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: new | critic: unknown | head-sha: 5485f40

🔍 ARM API review by ARM API Review: Automated Workflow

Per ARM reviewer bot feedback on PR Azure#45650: the suppression tool name
has no space.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@arjun-d-patel

Copy link
Copy Markdown
Contributor Author

Good catch — fixed the tool name to SwaggerAvocado (no space) in ad98419.

@github-actions

Copy link
Copy Markdown

ARM API Review Summary

Reviewed PR #45650 at head SHA ad98419794b5edfccb2102ad7ed8143845819bf7 | Triggered by: pull_request_target

Approval labels observed: none.

Category Count
🔴 Blocking 0
🟠 Warning 0
🔵 Suggestion 0

All prior findings from earlier runs are resolved as of this head SHA: the nullable-union anti-pattern on IpamPoolUpdateProperties.minAllocationSize/maxAllocationSize was fixed, the string-vs-numeric-type suggestion was addressed by the author's documented IPv6-range rationale, and the suppressions.yaml tool-name mismatch (Swagger Avocado → SwaggerAvocado) reported in the previous run was fixed in commit ad98419794b. No new violations, breaking changes, or security issues were identified against the current diff.

posted-by: arm-api-reviewer-agent | rule: summary | severity: suggestion | classification: existing | critic: unknown | head-sha: ad98419

🔍 ARM API review by ARM API Review: Automated Workflow

@sandipsh Sandip Shahane (sandipsh) added ARMSignedOff <valid label in PR review process>add this label when ARM approve updates after review Approved-Avocado and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Aug 25, 2026
@santoshgh317 santoshgh317 self-assigned this Aug 27, 2026
@santoshgh317
santoshgh317 self-requested a review August 27, 2026 05:26
@santoshgh317
santoshgh317 merged commit cd2c909 into Azure:release-microsoft-network-2026-01-01 Aug 27, 2026
186 of 190 checks passed
@santoshgh317 santoshgh317 mentioned this pull request Sep 3, 2026
5 of 9 tasks
santoshgh317 added a commit that referenced this pull request Sep 15, 2026
* Add API version 2026-01-01 for Microsoft.Network (#45569)

Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com>

* Add Enum values for VPN migrationType (#45647)

Co-authored-by: Akshat Kale <akale@microsoft.com>

* Fix Bug 38477992: type computedDisabledRules.rules as integers (2026-01-01) (#45621)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com>
Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3

* [Network] Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01 (#45625)

* Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01

Ports the change from azure-rest-api-specs-pr PR 29807 onto the public
2026-01-01 release branch.

Adds three read-only properties that NRP surfaces from api-version
2026-01-01 for Application Gateway WAF:

- paranoiaLevel on ApplicationGatewayFirewallRule
- displayName on ApplicationGatewayFirewallRuleSetPropertiesFormat
- displayName on ApplicationGatewayFirewallManifestRuleSet
- displayName on DefaultRuleSetPropertyFormat

paranoiaLevel uses a new extensible enum ApplicationGatewayWafRuleParanoiaLevel
with values PL1 to PL4.

All new members are annotated with @added(Versions.v2026_01_01). The change is
additive and all new properties are optional.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Retrigger CI

The SDK Validation - Rust build failed on a transient GitHub timeout
while installing the Azure SDK Tools CLI. Nothing in the spec changed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Centurion WAF: add WAF policy tier + Basic_v2/Basic_WAF_v2 SKUs (2026-01-01) (#45766)

* Add Centurion WAF updates for 2026-01-01

Update WAF policy tier and reserved capacity support.

Add Basic_v2 and Basic_WAF_v2 SKUs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Basic v2 application gateway tiers

WebApplicationFirewallPolicyTier ordering aligns Standard=0 and Basic=1.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Basic WAF and application gateway examples

Add Basic WAF policy create/get examples and Basic-tier coverage.

Add Basic_v2 and Basic_WAF_v2 application gateway create/get examples, including reservedCapacity and WAF policy association.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add AuthenticationPolicy resource and Application Gateway authConfigs binding for 2026-01-01 (#45764)

* Add AuthenticationPolicy support for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Align AuthenticationPolicy contract with service behavior

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Enforce AuthenticationPolicy name and binding constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add authentication policy tags update

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

---------

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 (#45650)

* Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01

Adds optional min/max allocation-size bounds to the Microsoft.Network
IpamPool resource in api-version 2026-01-01:

- IpamPoolProperties (PUT/GET): minAllocationSize, maxAllocationSize
- IpamPoolUpdateProperties (PATCH): minAllocationSize, maxAllocationSize
  marked x-nullable so an explicit null clears the bound while an absent
  bound is preserved, per ARM merge-patch semantics.

Both properties are gated with @added(Versions.v2026_01_01) so earlier
api-versions are unchanged. Regenerated virtualNetwork.json and updated
the 2026-01-01 IpamPools Create/Get/List/Update examples.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Move min/max allocation size into dedicated IpamPool examples

The allocation-size bounds are optional, so the baseline IpamPools
examples should not imply they are always supplied. Restores
IpamPools_Create/Get/List/Update to their original content and adds
dedicated examples that exercise the feature:

- IpamPools_CreateWithAllocationBounds.json: PUT setting both bounds.
- IpamPools_UpdateAllocationBounds.json: PATCH setting both bounds.
- IpamPools_UpdateClearAllocationBounds.json: PATCH clearing both
  bounds with an explicit null, per ARM merge-patch semantics.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Address ARM review: drop nullable union on new min/max update properties

New properties must not use a nullable union, since backward
compatibility does not apply to additions. The RP already treats an
empty string as a clear on PATCH, so the explicit null is unnecessary.

- IpamPoolUpdateProperties min/maxAllocationSize: string | null -> string,
  removing the no-nullable suppressions and x-nullable from the swagger.
- Document clearing via an empty string.
- IpamPools_UpdateClearAllocationBounds example now clears with "".

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add Swagger Avocado suppression for frozen 2018-10-01 VMSS surface

Per ARM reviewer guidance on PR #45650: the package-2026-01-01 default
tag intentionally retains stable/2018-10-01/vmssNetwork.json for
backward compatibility, which trips Avocado's MULTIPLE_API_VERSION rule.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix Avocado suppression tool name to SwaggerAvocado

Per ARM reviewer bot feedback on PR #45650: the suppression tool name
has no space.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add approvalReference to private endpoint connection in 2026-01-01 (#45604)

* Add approvalReference (create-only) to private endpoint connection in 2026-01-01

Adds optional approvalReference.privateEndpointId to PrivateLinkServiceConnectionProperties, gated @added(v2026_01_01) with @visibility(Lifecycle.Read, Lifecycle.Create) so it is create-only (emits x-ms-mutability: [read, create]) and is not resupplied on update.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Regenerate vmssNetwork.json for approvalReference (Vmss project)

The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and emits stable/2018-10-01/vmssNetwork.json, which must be regenerated so approvalReference/ApprovalReference are included. Fixes TypeSpec Validation (Vmss).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Remove x-ms-mutability (create-only) from approvalReference

Per internal discussion, drop the create-only mutability restriction on
approvalReference. Removes the @visibility(Lifecycle.Read, Lifecycle.Create)
decorator in Common/main.tsp and regenerates the Network and Vmss project
swaggers so x-ms-mutability is no longer emitted. The approvalReference
property and ApprovalReference model are retained.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Type approvalReference.privateEndpointId as armResourceIdentifier

Address ARM review finding [TSP-ARM-RESOURCE-ID]: privateEndpointId references an existing private endpoint, so type it as Azure.Core.armResourceIdentifier<Microsoft.Network/privateEndpoints> instead of plain string. Regenerated swagger emits format: arm-id and x-ms-arm-id-details.allowedResources.

---------

Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a

* Add ExpressRoutCircuit on ExpressRouteLag (#45689)

* Add ExpressRoutCircuit on ExpressRouteLag

* Fix ExpressRouteLag examples: sync circuits to output copies and remove invalid circuit properties

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Align ExpressRouteCircuitCreateOnExpressRouteLag responses with request (EX-PARAM-CONSISTENCY)

Fix response bodies to match request: LAG reference lagName (was test),
enableDirectPortRateLimit true, and SKU Premium_MeteredData in the 200 response.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

* Add AppGw Advanced Routing Rule in NRR API 2026-01-01 (#45844)

* Add advanced routing features to Application Gateway for API version 2026-01-01

* buid artifacts after changes to models.tsp

* added examples

* fix merge conflict

---------

Co-authored-by: Paawan Kohli <paawankohli@microsoft.com>

* Modify sdk-suppressions.yaml for breaking changes (#45914)

Updated breaking changes for Azure SDK suppressions in network resource manager.

* [Microsoft.Network] Add provider-led ExpressRoute circuit migration APIs (#45905)

* Add ExpressRoute circuit migration APIs

Add TypeSpec operations and models for provider-led ExpressRoute circuit migration, generated 2026-01-01 Swagger, examples, and the scoped brownfield resource-name suppression.

* Fix Network specification validation

Use valid UUID subscription IDs, add required TypeSpec example metadata, regenerate migration LRO metadata, and suppress the intentional mixed-version VMSS surface in the combined Network package.

* Fix Network Avocado suppression

Move the mixed API-version exception from an unsupported AutoRest directive to the Network SwaggerAvocado path-suppression file, scoped to the default-tag readme.

* Fix Network validation suppressions

* Correct Avocado suppression identifier

* Geo-Ip filter changes (#45631)

* Geo Ip Filter Changes

* Document GeoIP filter format (ISO 3166-1 alpha-2) and fix WAF scrubbing-rule model

* Fixing Swagger ModelValidation Filure related errors

* Dummy Push to reinitate build

* Type Spec validation failure fix

* Remove duplicate GeoIP filter properties

---------

Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com>

* Add NeuroShield API for 2026-01-01 (#45722)

* Add NeuroShield API for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add NeuroShield API for 2026-01-01

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Align NeuroShield contract with service behavior

Require customer-facing configuration, align mitigation responses with the safe service projection, make cancellation synchronous, and correct protected-resource delete polling.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Refine NeuroShield 2026-01-01 contract

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Fix NeuroShield validation regressions

* Address ARM review feedback for NeuroShield

Use supported ARM resource templates, scope Swagger suppressions to exact operations, and isolate inherited Network validation debt.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Fix NeuroShield LintDiff suppressions

* Use standard ARM entity tag property

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac

* Add post calls for auth key of authorization objects for expressrouteciruits and expressrouteports (#45679)

* Added post calls for expressroute auth key

* Added the objects in 2026-01-01 version

* addressed ai comments

* Addressed comments

* fixed

* removed suppression

* fixed suppressions

---------

Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com>

* Fix Hub virtual network IPv6 peering contract (#45637)

* Fix IPv6 peering contract for Network 2026-01-01
* Correct IPv6 peering contract in Network 2025-09-01
* Update client.tsp

* Update sdk-suppressions.yaml

---------

Co-authored-by: Caren Lim <carenlim@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: kazrael2119 <98569699+kazrael2119@users.noreply.github.com>

* Correct AuthenticationPolicy contract for 2026-01-01 (#45892)

* Correct authentication policy contract

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Keep provider type extensible

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Document authentication policy constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Align authentication examples with service

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Restore authentication policy tags update

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Suppress PatchIdentityProperty for AuthenticationPolicies_UpdateTags

The tags-only PATCH takes the shared Network RP TagsObject body, matching
ApplicationGateways_UpdateTags. The service only updates tags on this
operation, so identity does not belong in the request body.

* Complete authentication policy constraints

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Correct Basic v2 authentication example

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Address ARM review feedback on AuthenticationPolicy 2026-01-01

- Make the arm-resource-invalid-envelope-property suppression reason self-contained by stating why the user-assigned identity belongs in the resource envelope.
- Scope the PatchIdentityProperty suppression with a where: clause targeting the AuthenticationPolicies_UpdateTags PATCH operation.
- Type issuer as url and require an https scheme, consistent with jwksUri and clientSecret.
- Document the sessionTimeout string syntax and units, and constrain it with a base-10 integer pattern and max length.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Also scope PatchIdentityProperty suppression to the PATCH body parameter path

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Remove AuthenticationPolicy PATCH operation

The service supports only GET, PUT, and DELETE for authenticationPolicies,
matching ApplicationGatewayWebApplicationFirewallPolicies, which also ships
without a PATCH. Removing the tags-only PATCH also resolves the
PatchIdentityProperty finding at its source: that rule fires only on an
existing PATCH, so with no PATCH the identity envelope property no longer
needs a suppression.

- Remove AuthenticationPolicies_UpdateTags and its source and generated examples.
- Drop the PatchIdentityProperty suppression.
- Restore the TrackedResourcePatchOperation no-PATCH suppression.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Drop stale PATCH path from ProvisioningStateMustBeReadOnly suppression

The AuthenticationPolicy PATCH operation was removed, so the patch response
entry in the where: list no longer matches anything.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Restore AuthenticationPolicy PATCH with a resource-specific update model

AuthenticationPolicy is a tracked resource: it extends the Network RP
Resource base type, which supplies location, tags and x-ms-azure-resource.
ARM requires resource providers to support PATCH for updating tags on a
tracked resource, so removing the operation was incorrect.

Restore PATCH using a resource-specific AuthenticationPolicyUpdateParameters
model carrying both tags and identity, rather than the shared TagsObject.
This satisfies the tracked-resource tags requirement and the MSI onboarding
requirement that the control plane accept identity updates on PATCH, which
means PatchIdentityProperty is now satisfied at the source and needs no
suppression.

- Add AuthenticationPolicyUpdateParameters (tags, identity).
- Add AuthenticationPolicies_Update, replacing the former tags-only
  AuthenticationPolicies_UpdateTags.
- Add an example exercising both tags and identity updates.
- Drop the TrackedResourcePatchOperation suppression, no longer applicable.
- Scope ProvisioningStateMustBeReadOnly to the new PATCH 200 response schema.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3

* Add bastion session recording configuration and identity properties (#45630)

* Add bastion session recording configuration property

* Fix the patch body for identity support

* Update examples

* Fix prettier violation

* Revert documentation changes

* Add BastionHostUpdate model instead of anonymous type

* Add tpye constraint for userAssignedIdentityId

* Fix invalid arm id for public ip in example

* Fix wrong name in 200 responses in new examples

* Fix documentation for BastionHostUpdate

* Preserve existing updateTags operation

* Update suppression justification

* Revert previous changes which maintained the old operation

* Update suppression justification for update operation

---------

Co-authored-by: Matthew Lee <matthelee@microsoft.com>

* Add azureFirewall enableAiAddOn (#45976)

* Add azureFirewall enableAiAddOn

* Enable aiSecurityAddOn in Azure Firewall configuration

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* copilot messed up, fix typescript

* fix fields in exampels

* fix fields in examples

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Revert "Add NeuroShield API for 2026-01-01 (#45722)" (#46208)

This reverts commit efb6f29.

* Address swagger review findings on AuthenticationPolicy for 2026-01-01 (#46260)

* Address swagger review findings on AuthenticationPolicy

Resolves five of the review findings at the source rather than by
suppression, removing four AuthenticationPolicy suppressions.

RequiredReadOnlySystemData: declare systemData explicitly on
AuthenticationPolicy, following the existing Network RP pattern used by
AdminRuleCollection, BaseAdminRule and Commit. It is emitted read-only.

RPC-Delete-V1-01: drop the ArmDeletedNoContentResponse override so the
sync DELETE emits 200, 204 and default. AuthenticationPolicy was the only
resource in this project overriding the delete response; every sibling
uses the default. Removes the DeleteResponseCodes and
DeleteOperationResponses suppressions.

SEC-SECRET-DETECT: remove the secret-prop suppression. The rule only
fires on properties typed as the builtin string, and clientSecret is
typed url, so the suppression had no effect. The property holds only a
Key Vault reference, which the documentation now states explicitly. The
XMSSecretInResponse suppression is also removed, as nothing in the
generated file is marked x-ms-secret.

RPC-SUPPRESS-SCOPE: scope RequiredPropertiesMissingInResourceModel to
$.definitions.AuthenticationPolicy, and explain why
LatestVersionOfCommonTypesMustBeUsed stays file-level: the common-types
version is pinned package-wide by arm-types-dir, so the finding applies
to every common-types reference in the file rather than to any single
definition.

Section 4.1: document the authenticationPolicy Features member instead of
suppressing documentation-required, and replace the placeholder FIXME
justification on WebApplicationFirewallPolicyTier with a real one.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix LintDiff and ModelValidation failures on AuthenticationPolicy 2026-01-01

Three CI failures introduced by the previous review-feedback commit:

1. LintDiff RequiredPropertiesMissingInResourceModel: the where: scope added
   for this rule only covered $.definitions.AuthenticationPolicy, but the rule
   also fires on AuthenticationPolicyListResult. Added that definition to the
   scope and extended the reason to explain that the list result is a paged
   envelope rather than a resource.

2. LintDiff XMSSecretInResponse on clientSecret: removing the TypeSpec
   secret-prop suppression did not clear this because the swagger rule matches
   purely on the property name ending in a sensitive keyword. The property only
   ever carries an absolute HTTPS Key Vault reference URL, never secret
   material, so annotating it with x-ms-secret would be incorrect - it would
   stop the service returning the reference in GET. Renamed the property to
   clientSecretUrl, which both clears the rule without any suppression and
   describes the value accurately. 2026-01-01 is not yet published, so the
   rename carries no breaking-change cost.

3. ModelValidation RESPONSE_STATUS_CODE_NOT_IN_EXAMPLE: the delete operation
   now declares a 200 response, so AuthenticationPolicyDelete.json needs a
   matching (bodyless) 200 entry alongside the existing 204.

Swagger Avocado remains failing with MULTIPLE_API_VERSION on the
package-2026-01-01 tag. That failure reproduces on the base release branch PR
(#46086) and is unrelated to this change.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Rename clientSecretUrl to clientSecretUri

TypeSpec Validation compiles client.tsp with --warn-as-error, which surfaces
@azure-tools/typespec-client-generator-core/csharp-no-url-suffix: properties
ending in 'Url' must use the 'Uri' suffix so the generated C# surface is
idiomatic. The local emit-only compile of the Network project does not run
client.tsp, so this was missed.

clientSecretUri still avoids the LintDiff XMSSecretInResponse keyword match,
which only fires on names ending in a sensitive keyword.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Revert clientSecret rename and suppress XMSSecretInResponse instead

The rename to clientSecretUrl/clientSecretUri was wrong. The property name is
part of the contract already implemented by the Network resource provider, so
the spec has to match NRP rather than pick a name that happens to dodge the
linter's keyword match. Reverted to clientSecret.

To keep LintDiff green, XMSSecretInResponse is suppressed instead, scoped to
$.definitions.AuthenticationProviderProperties.properties.clientSecret. The
justification is substantive rather than a waiver: the property carries only an
absolute HTTPS Key Vault secret URL, never secret material - the secret value is
read from Key Vault at runtime using the resource's user-assigned identity and
is never accepted or returned by this API. Annotating it with x-ms-secret would
be actively incorrect, because that would stop the service returning the Key
Vault reference on GET, which callers need in order to see how a policy is
configured.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com>
Co-authored-by: Akshat Kale <kaleakshat@gmail.com>
Co-authored-by: Akshat Kale <akale@microsoft.com>
Co-authored-by: yaarark <yaararonenkr@gmail.com>
Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com>
Co-authored-by: Shaigoldbourt22 <118125561+Shaigoldbourt22@users.noreply.github.com>
Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: baoqihuang0326 <119557638+baoqihuang0326@users.noreply.github.com>
Co-authored-by: Arjun Patel <94936045+arjun-d-patel@users.noreply.github.com>
Co-authored-by: ajoyduwary <ajoyduwary@gmail.com>
Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com>
Co-authored-by: mshrimankar10 <66165250+mshrimankar10@users.noreply.github.com>
Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: paawankohli <44478509+paawankohli@users.noreply.github.com>
Co-authored-by: Paawan Kohli <paawankohli@microsoft.com>
Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com>
Co-authored-by: gurram-amulya <111553857+gurram-amulya@users.noreply.github.com>
Co-authored-by: kshitizmathur-max <kshitiz.mathur@gmail.com>
Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com>
Co-authored-by: Satya-Kotha1008 <sathi.kotha1008@gmail.com>
Co-authored-by: carenlim20 <carenlim+github@microsoft.com>
Co-authored-by: Caren Lim <carenlim@microsoft.com>
Co-authored-by: Matthew Lee <mwlee29@gmail.com>
Co-authored-by: Matthew Lee <matthelee@microsoft.com>
Co-authored-by: Ben Eshed <105308016+bewatersmsft@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3
Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a
Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants