Skip to content

[Network] az network firewall: Expose AFC endpoint (afcConfiguration) and add --create-afc-control-plane - #10413

Merged
Ethan Yang (necusjz) merged 5 commits into
Azure:mainfrom
huiii99:network-firewall-33904
Oct 1, 2026
Merged

Ethan Yang (necusjz) merged 5 commits into
Azure:mainfrom
huiii99:network-firewall-33904

Conversation

@huiii99

@huiii99 Jian Hui (huiii99) commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

This checklist is used to make sure that common guidelines for a pull request are followed.

Related command

az network firewall create / az network firewall update / az network firewall show / az network firewall list

Resolves Azure/azure-cli#33904
AAZ command model PR: Azure/aaz#1109

What's changed

  • Bump az network firewall create/update/show/list/delete/wait to API version 2025-09-01 (minimum version required by the feature).
  • az network firewall show/list: surface the read-only afcConfiguration property (with read-only serviceEndpoint) for the Azure Firewall for Containers endpoint.
  • az network firewall create/update: expose the writable createAfcControlPlane PUT query parameter as --create-afc-control-plane.
  • The new argument is hidden on the az network firewall threat-intel-allowlist commands, which reuse the generated update command but must not expose it.
  • Extension version bumped to 2.3.0 with a matching HISTORY.rst entry.

Tests

  • AzureFirewallAfcArgumentTest (offline, runs in CI): asserts --create-afc-control-plane is registered on create/update and hidden on threat-intel-allowlist create/update/delete.
  • test_azure_firewall_afc_control_plane (@live_only()): creates a firewall with --create-afc-control-plane true and checks afcConfiguration.serviceEndpoint is returned by show/list. Marked live-only until a recording can be captured against a subscription with AFC enabled — this is the remaining work before the PR leaves draft.
  • Existing recordings were re-stamped to 2025-09-01 to match the bumped API version.

Validation run

Command Result
azdev style azure-firewall passed (pylint PASSED, flake8 PASSED)
python scripts/ci/test_index.py -q passed (Ran 9 tests, OK, skipped=2)
pytest azext_firewall/tests/latest/test_azure_firewall_scenario.py::AzureFirewallAfcArgumentTest passed (2 passed)
azdev test test_azure_firewall_afc_control_plane --live not run — no subscription with AFC available yet; recording still to be captured

General Guidelines

  • Have you run azdev style <YOUR_EXT> locally? (pip install azdev required)
  • Have you run python scripts/ci/test_index.py -q locally? (pip install azdev required)
  • My extension version conforms to the Extension version schema

For new extensions:

About Extension Publish

There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update src/index.json automatically.
You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify src/index.json.

@yonzhan

Copy link
Copy Markdown
Collaborator

Network

@huiii99
Jian Hui (huiii99) marked this pull request as ready for review October 1, 2026 00:07
Copilot AI balanced review requested due to automatic review settings October 1, 2026 00:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The AFC behavior test is excluded from CI, and its recording lacks the expected AFC response and list interaction.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds AFC control-plane support to Azure Firewall commands using API version 2025-09-01.

Changes:

  • Adds AFC creation arguments and response schemas.
  • Hides AFC arguments from threat-intelligence allowlist commands.
  • Updates tests, recordings, release history, and extension version.
File Description
HISTORY.rst Documents AFC support and API bump.
_create.py Adds AFC creation query parameter and response schema.
_delete.py Updates delete API version.
_list.py Updates API and exposes AFC configuration.
_show.py Exposes AFC configuration.
_update.py Adds AFC update query parameter and response schema.
_wait.py Updates wait API and response schema.
custom.py Hides AFC argument from allowlist commands.
test_azure_firewall.yaml Updates recorded API versions.
test_azure_firewall_afc_control_plane.yaml Adds AFC scenario recording.
test_azure_firewall_autoscale_configuration.yaml Updates recorded API versions.
test_azure_firewall_extended_location.yaml Updates recorded API versions.
test_azure_firewall_ip_config.yaml Updates recorded API versions.
test_azure_firewall_management_ip_config.yaml Updates recorded API versions.
test_azure_firewall_packet_capture.yaml Updates recorded API versions.
test_azure_firewall_rules.yaml Updates recorded API versions.
test_azure_firewall_rules_with_ipgroups.yaml Updates recorded API versions.
test_azure_firewall_threat_intel_allowlist.yaml Updates recorded API versions.
test_azure_firewall_tier.yaml Updates recorded API versions.
test_azure_firewall_with_firewall_policy.yaml Updates recorded API versions.
test_azure_firewall_zones.yaml Updates recorded API versions.
test_firewall_basic_sku.yaml Updates recorded API versions.
test_firewall_standard_sku_management_ip_config.yaml Updates recorded API versions.
test_firewall_vhub_create_with_public_ip.yaml Updates recorded API versions.
test_firewall_with_additional_log.yaml Updates recorded API versions.
test_firewall_with_dns_proxy.yaml Updates recorded API versions.
test_firewall_with_route_server.yaml Updates recorded API versions.
test_azure_firewall_scenario.py Adds AFC scenario and argument tests.
setup.py Bumps extension version to 2.3.0.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/azure-firewall/azext_firewall/tests/latest/test_azure_firewall_scenario.py Outdated
Bump `az network firewall create/delete/list/show/update/wait` to API
version 2025-09-01 so the read-only `afcConfiguration.serviceEndpoint`
property is returned by `show`/`list`, and expose the writable PUT query
parameter as `--create-afc-control-plane` on `create`/`update`.

The new argument is hidden on the `threat-intel-allowlist` commands,
which reuse the generated update command but must not expose it.

Resolves Azure/azure-cli#33904
Add an offline check that `--create-afc-control-plane` is registered on
`network firewall create/update` and hidden on the
`threat-intel-allowlist` commands that reuse the generated update
command, plus a live-only scenario test asserting
`afcConfiguration.serviceEndpoint` is returned by show/list.

Related to Azure/azure-cli#33904
…FC test

The CLI linter rule option_length_too_long (threshold 22) failed because
--create-afc-control-plane was the only option on the argument. Add
--create-afc as the short abbreviation, matching the AAZ command model.

The live scenario test now creates the firewall with a VNet and public IP,
since the RP only provisions an AFC control plane for a firewall that has
an IP configuration.
The RP only returns afcConfiguration once an AFC control plane is actually deployed for the firewall, so asserting serviceEndpoint against a live subscription cannot pass. Replay the existing recording to cover the createAfcControlPlane query parameter and assert the generated read schemas offline instead.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 2ba09730-869d-4878-b078-7d7d162f5ea9
Comment on lines +10 to +12
* `az network firewall show/list` : Expose read-only property `afcConfiguration` (with read-only `serviceEndpoint`) for the Azure Firewall for Containers endpoint.
* `az network firewall create/update` : Add `--create-afc-control-plane`/`--create-afc` to create an AFC control plane for the Azure Firewall.
* Bump API version to `2025-09-01` for `az network firewall` create/update/show/list/delete/wait.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the changes in this pr won't be included in 2.3.0. but it doesn't matter, we can update setup.py with a upper version in the 3rd feature request.

@necusjz
Ethan Yang (necusjz) merged commit 984178c into Azure:main Oct 1, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Network] Expose afcConfiguration (AFC endpoint) on az network firewall

4 participants