Repository navigation
Conversation
…ryption) Adds the 2026-10-01 stable api-version to recoveryservicessiterecovery: - main.tsp/models.tsp: v2026_10_01 version + CVM models (ConfidentialDiskEncryptionInfo, UpdateConfidentialDiskEncryptionInfo) - readme.md/service.yaml: 2026-10-01 tag + typespec entry - stable/2026-10-01/service.json + examples (157) and stable/examples copy (157) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Azure Pipelines: Successfully started running 10 pipeline(s). 2 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Next Steps to MergeNext steps that must be taken to merge this PR:
Comment generated by summarize-checks workflow run. |
API Change CheckAPIView identified API level changes in this PR and created the following API reviews Comment generated by After APIView workflow run. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…c policy Folds the A2A IPv6 dual-stack REST contract into api-version 2026-10-01: - IPVersion extensible enum (IPv4/IPv6, modelAsString) used by ipVersion on both IPConfigDetails and IPConfigInputDetails. SRS parses the value case-insensitively and defaults to IPv4 for unrecognized input (NetworkHelper.GetIPAddressVersion), so an extensible enum is correct. - RecoveryNetworkConfigAutoSyncPolicy extensible enum (Disabled/Enabled) and the vault-level recoveryNetworkConfigAutoSync leaf on both VaultSettingProperties and VaultSettingCreationInputProperties, backing the SRS NIC-change auto-sync monitor route. - ReplicationVaultSetting Create/Get/List examples updated accordingly. Also regenerates stable/2026-10-01/service.json, which picks up the pending ReplicationProtectedItems_AddDisks x-ms-examples rename that was already in the .tsp source but not in the committed swagger. That drift was failing TypeSpec Validation on this branch. Verified with the repo-pinned toolchain (@typespec/compiler 1.15.0, Node 24): tsp compile --warn-as-error clean, client.tsp clean, and a second compile produces a byte-identical service.json (no drift). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…recovery-2026-10-01
Razvan Badea (razvanbadea-msft)
left a comment
There was a problem hiding this comment.
ARM API Review
Posting findings from the ARM API Reviewer agent (critic-verified, 3 iteration(s), converged) against commit bf7a74a. Findings SR-1, SR-2, and SR-6 concern lines outside the PR diff and are posted as top-level PR comments rather than inline comments. SR-4 was clarified in its existing review thread. Other findings remain unposted pending human review.
Approval labels observed: none.
|
[EXISTING] 🔴 Blocking [SEC-SECRET-DETECT] models.tsp — line 5534 — BitLocker key data lacks secret metadata. Issue: Classification reasoning: The same unannotated field is present in the previous preview, line 10114, and previous GA, line 7695; not introduced in this batch. Suggested fix: Annotate the TypeSpec leaf and regenerate; verify /** BEK data. */
@secret
secretData?: string; |
|
[EXISTING] 🔴 Blocking [SEC-SECRET-DETECT] models.tsp — lines 5954–5967 — Export-result SAS credentials suppress secret detection instead of declaring secrets. Issue: Classification reasoning: Both defects exist in the previous preview, lines 12503 and 12511, and previous GA, lines 9798 and 9806. The TODO suppressions also exist in base TypeSpec at lines 5937 and 5949. Approval context: Checked Suggested fix: Replace both /** SAS key to access the blob. It expires in 15 mins. */
@secret
blobSasKey?: string;
/** SAS key to access the blob. It expires in 15 mins. */
@secret
excelFileBlobSasKey?: string; |
|
[EXISTING] 🔴 Blocking [SEC-SECRET-DETECT] models.tsp — lines 3273–3285 — Security PIN response credentials lack secret annotations. Issue: Classification reasoning: Both unmarked leaves exist in the previous preview, lines 18060 and 18069, and previous GA, lines 15035 and 15044. Base TypeSpec has the same token suppression at line 3267. Approval context: Checked Suggested fix: Remove the /** Token value. */
@secret
token?: string;
/** Security PIN */
#suppress "@azure-tools/typespec-azure-core/casing-style" "FIXME: Update justification, follow aka.ms/tsp/conversion-fix for details"
@secret
securityPIN?: string;Note: Expanded after critic review to include the adjacent |
Razvan Badea (razvanbadea-msft)
left a comment
There was a problem hiding this comment.
ARM API Review
Posting findings from the ARM API Reviewer agent (critic-verified, 3 iteration(s), converged) against commit bf7a74a. Findings B-1, B-2, and B-3 concern lines outside the PR diff and are posted as top-level PR comments rather than inline comments. These are existing Backup secret-handling findings, not regressions introduced by this PR. Other unapproved findings remain unposted pending human review.
Approval labels observed: none.
Razvan Badea (razvanbadea-msft)
left a comment
There was a problem hiding this comment.
ARM API Review
Posting findings from the ARM API Reviewer agent (critic-verified, 3 iteration(s), converged) against commit bf7a74a. See inline comments for findings RS-1 through RS-11.
At the human reviewer's request, all eleven are non-blocking Suggestions concerning pre-existing Recovery Services contract debt, not regressions introduced by this PR. Compatibility-sensitive remediation is follow-up work, not a condition of merging this version update. No breaking changes are requested without the applicable service/SDK review and API approval.
Approval labels observed: none.
Brings in RecoveryServicesBackup 2026-10-01 (Azure#46044). Backup 2026-11-01 now carries forward 2026-10-01: conflicts resolved by keeping the 2026-10-01 version boundaries, adding v2026_11_01 after v2026_10_01, and regenerating stable/2026-11-01/bms.json. Adds the six 2026-10-01 examples for operations inherited by 2026-11-01 and the masked BackupSecurityPin_Get example. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…-11-01 Addresses SEC-SECRET-DETECT review findings SR-1 and SR-2. Adds a secret SecretString scalar and changes ExportJobDetails.sasToken and the ten primary/secondary KEK certificate PFX properties to it from 2026-11-01 via @typeChangedFrom, removing the sasToken secret-prop suppression. Earlier published versions are unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Carries the Instant Access policy fields, existingBasicVMProtection and the private endpoint delete response from the 2026-10-01 examples into 2026-11-01, changing only the API version. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Re: SR-1 — Fixed in 87574667f5. From 2026-11-01, On redaction: the annotation classifies the value; whether GET/LIST return it is service behavior, and the token is only produced by the existing |
|
Re: SR-2 — KEK certificate PFX properties Fixed in 87574667f5. From 2026-11-01, |
|
Requesting breaking-change review for the Cross-Version |
|
Re: B-1 — Razvan Badea (@razvanbadea-msft), this is an existing item and is not introduced or changed by this PR. |
|
Re: B-2 — Razvan Badea (@razvanbadea-msft), this is an existing item and is not introduced or changed by this PR. The two |
|
Razvan Badea (@razvanbadea-msft), this is an existing item and is not introduced or changed by this PR. The |
|
Re: SR-6 — default error responses Razvan Badea (@razvanbadea-msft), this is an existing item and is not introduced or changed by this PR. As noted in the finding, the same 137 operations have no |
|
Razvan Badea (@razvanbadea-msft), following up on the Avocado discussion: after merging the latest |
|
Mushegh Malkhasyan (@MushMal), could you review the Cross-Version |
There was a problem hiding this comment.
ARM API Review
Posting findings from the ARM API Reviewer agent (critic-verified, 3 iterations, converged) against commit c0dbc0940a76df3eb4b2747d66ac41944b427d61. No new actionable findings were identified in the scoped high-risk review, and no inline findings were posted.
Scoped review: 13 of 667 changed specification/ files reviewed (PR exceeds the automated-review size cap). Not reviewed: the remaining generated/example files and lower-risk duplicated examples outside the selected TypeSpec, configuration, and generated-contract surfaces.
Approval labels observed: BreakingChange-Go-Sdk-Approved, BreakingChange-JavaScript-Sdk-Approved.
| Category | Count |
|---|---|
| 🔴 Blocking | 0 |
| 🟠 Warning | 0 |
| 🔵 Suggestion | 0 |
No issues found in the reviewed scope. Existing prior findings were reconciled and were not reposted as new regressions.
🔍 ARM API review by ARM API Review: Automated Workflow
Adding SiteRecovery api-version 2026-11-01
Adds a new stable api-version 2026-11-01 to
recoveryservicessiterecovery, covering two independent A2A feature areas: Confidential VM (CVM) disk encryption and IPv6 dual-stack networking. The change is purely additive (new version folder +@added(Versions.v2026_11_01)-guarded models); no existing version is modified.The two Site Recovery feature areas share one API version. This PR also includes matching versioned contracts for vault management and Backup, with no new functionality in those two areas.
What's included
A2A Confidential VM (CVM) disk encryption
ConfidentialDiskEncryptionInfo,UpdateConfidentialDiskEncryptionInfomodels and theconfidentialDiskEncryptionInfo/recoveryConfidentialDataDiskEncryptionIdentitypropertiesA2A IPv6 dual-stack networking
ipVersionon NIC ip-configs: newIPVersionextensible enum (IPv4/IPv6,modelAsString: true) surfaced asipVersiononIPConfigDetails. Declares the address family of a recovery NIC ip-config, orthogonal to the existing static/dynamic allocation type. A missing value is treated asIPv4, so existing clients are unaffected. The leaf is response-only: an ip-config's address family is derived from the source NIC during discovery, and the service update path resolves it from the stored configuration rather than from caller input, so it is deliberately not exposed onIPConfigInputDetails.RecoveryNetworkConfigAutoSyncPolicyextensible enum (Disabled/Enabled) surfaced asrecoveryNetworkConfigAutoSynconVaultSettingProperties(response) andVaultSettingCreationInputProperties(input). Controls whether the A2A recovery network configuration is automatically kept in sync as the source VM's network configuration changes. On the creation input an omitted value leaves the stored policy unchanged.ReplicationVaultSetting_Create/_Get/_Listupdated to show the new auto-sync leaf. NewReplicationProtectedItems_Update_A2ADualStackshows an A2A NIC carrying both an IPv4 and an IPv6 ip-config, on the update input and on the response, so theipVersionwire shape is demonstrated end to end.Both enums use
modelAsString: truein line with the Azure ARM guidelines for new enums, so that a future service-side value does not break already-generated SDKs. This governs SDK/response forward-compatibility only, and is not a statement about request validation: the service validates supplied values and rejects an unrecognizedrecoveryNetworkConfigAutoSyncwithInvalidParameter(HTTP 400), which is the intended behaviour for a request enum.Shared / version plumbing
v2026_11_01version enum entrypackage-2026-11-01tag + default-tag updateVault management and Backup version alignment
2026-11-01, carrying forward the stable2026-07-01vault-management contract and its 45 examples without new fields or operations.2026-11-01, carrying forward the stable2026-08-01Backup contract and its 116 examples without new fields or operations.service.yamlentries. Existing published versions and the ASR files are unchanged by this follow-up.Notes for reviewers
stable/2026-11-01/service.jsonis fully regenerated from the TypeSpec sources. This also picks up the pendingReplicationProtectedItems_AddDisksx-ms-examplesrename that was already present in the.tspsource but missing from the committed swagger — that drift was previously failing TypeSpec Validation on this branch.ipVersion; previously published API versions are unchanged.Contribution checklist
service.json.