[Network] az network firewall: Expose AFC endpoint (afcConfiguration) and add --create-afc-control-plane - #10413
Merged
Conversation
microsoft-github-policy-service
Bot
requested review from
Yu Chen (jsntcy),
Ethan Yang (necusjz) and
Yong Zhang (yonzhan)
September 30, 2026 13:12
Collaborator
|
Network |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The AFC behavior test is excluded from CI, and its recording lacks the expected AFC response and list interaction.
Review effort: Balanced
Findings: 1
What changed in this PR
Adds AFC control-plane support to Azure Firewall commands using API version 2025-09-01.
Changes:
- Adds AFC creation arguments and response schemas.
- Hides AFC arguments from threat-intelligence allowlist commands.
- Updates tests, recordings, release history, and extension version.
| File | Description |
|---|---|
HISTORY.rst |
Documents AFC support and API bump. |
_create.py |
Adds AFC creation query parameter and response schema. |
_delete.py |
Updates delete API version. |
_list.py |
Updates API and exposes AFC configuration. |
_show.py |
Exposes AFC configuration. |
_update.py |
Adds AFC update query parameter and response schema. |
_wait.py |
Updates wait API and response schema. |
custom.py |
Hides AFC argument from allowlist commands. |
test_azure_firewall.yaml |
Updates recorded API versions. |
test_azure_firewall_afc_control_plane.yaml |
Adds AFC scenario recording. |
test_azure_firewall_autoscale_configuration.yaml |
Updates recorded API versions. |
test_azure_firewall_extended_location.yaml |
Updates recorded API versions. |
test_azure_firewall_ip_config.yaml |
Updates recorded API versions. |
test_azure_firewall_management_ip_config.yaml |
Updates recorded API versions. |
test_azure_firewall_packet_capture.yaml |
Updates recorded API versions. |
test_azure_firewall_rules.yaml |
Updates recorded API versions. |
test_azure_firewall_rules_with_ipgroups.yaml |
Updates recorded API versions. |
test_azure_firewall_threat_intel_allowlist.yaml |
Updates recorded API versions. |
test_azure_firewall_tier.yaml |
Updates recorded API versions. |
test_azure_firewall_with_firewall_policy.yaml |
Updates recorded API versions. |
test_azure_firewall_zones.yaml |
Updates recorded API versions. |
test_firewall_basic_sku.yaml |
Updates recorded API versions. |
test_firewall_standard_sku_management_ip_config.yaml |
Updates recorded API versions. |
test_firewall_vhub_create_with_public_ip.yaml |
Updates recorded API versions. |
test_firewall_with_additional_log.yaml |
Updates recorded API versions. |
test_firewall_with_dns_proxy.yaml |
Updates recorded API versions. |
test_firewall_with_route_server.yaml |
Updates recorded API versions. |
test_azure_firewall_scenario.py |
Adds AFC scenario and argument tests. |
setup.py |
Bumps extension version to 2.3.0. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Jian Hui (huiii99)
force-pushed
the
network-firewall-33904
branch
from
October 1, 2026 00:36
39e78f1 to
d027475
Compare
Bump `az network firewall create/delete/list/show/update/wait` to API version 2025-09-01 so the read-only `afcConfiguration.serviceEndpoint` property is returned by `show`/`list`, and expose the writable PUT query parameter as `--create-afc-control-plane` on `create`/`update`. The new argument is hidden on the `threat-intel-allowlist` commands, which reuse the generated update command but must not expose it. Resolves Azure/azure-cli#33904
Add an offline check that `--create-afc-control-plane` is registered on `network firewall create/update` and hidden on the `threat-intel-allowlist` commands that reuse the generated update command, plus a live-only scenario test asserting `afcConfiguration.serviceEndpoint` is returned by show/list. Related to Azure/azure-cli#33904
…FC test The CLI linter rule option_length_too_long (threshold 22) failed because --create-afc-control-plane was the only option on the argument. Add --create-afc as the short abbreviation, matching the AAZ command model. The live scenario test now creates the firewall with a VNet and public IP, since the RP only provisions an AFC control plane for a firewall that has an IP configuration.
The RP only returns afcConfiguration once an AFC control plane is actually deployed for the firewall, so asserting serviceEndpoint against a live subscription cannot pass. Replay the existing recording to cover the createAfcControlPlane query parameter and assert the generated read schemas offline instead. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 2ba09730-869d-4878-b078-7d7d162f5ea9
Jian Hui (huiii99)
force-pushed
the
network-firewall-33904
branch
from
October 1, 2026 01:30
d027475 to
bc51abc
Compare
Comment on lines
+10
to
+12
| * `az network firewall show/list` : Expose read-only property `afcConfiguration` (with read-only `serviceEndpoint`) for the Azure Firewall for Containers endpoint. | ||
| * `az network firewall create/update` : Add `--create-afc-control-plane`/`--create-afc` to create an AFC control plane for the Azure Firewall. | ||
| * Bump API version to `2025-09-01` for `az network firewall` create/update/show/list/delete/wait. |
Member
There was a problem hiding this comment.
the changes in this pr won't be included in 2.3.0. but it doesn't matter, we can update setup.py with a upper version in the 3rd feature request.
Ethan Yang (necusjz)
approved these changes
Oct 1, 2026
3 of 4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This checklist is used to make sure that common guidelines for a pull request are followed.
Related command
az network firewall create/az network firewall update/az network firewall show/az network firewall listResolves Azure/azure-cli#33904
AAZ command model PR: Azure/aaz#1109
What's changed
az network firewall create/update/show/list/delete/waitto API version2025-09-01(minimum version required by the feature).az network firewall show/list: surface the read-onlyafcConfigurationproperty (with read-onlyserviceEndpoint) for the Azure Firewall for Containers endpoint.az network firewall create/update: expose the writablecreateAfcControlPlanePUT query parameter as--create-afc-control-plane.az network firewall threat-intel-allowlistcommands, which reuse the generated update command but must not expose it.2.3.0with a matchingHISTORY.rstentry.Tests
AzureFirewallAfcArgumentTest(offline, runs in CI): asserts--create-afc-control-planeis registered oncreate/updateand hidden onthreat-intel-allowlist create/update/delete.test_azure_firewall_afc_control_plane(@live_only()): creates a firewall with--create-afc-control-plane trueand checksafcConfiguration.serviceEndpointis returned byshow/list. Marked live-only until a recording can be captured against a subscription with AFC enabled — this is the remaining work before the PR leaves draft.2025-09-01to match the bumped API version.Validation run
azdev style azure-firewallpython scripts/ci/test_index.py -qpytest azext_firewall/tests/latest/test_azure_firewall_scenario.py::AzureFirewallAfcArgumentTestazdev test test_azure_firewall_afc_control_plane --liveGeneral Guidelines
azdev style <YOUR_EXT>locally? (pip install azdevrequired)python scripts/ci/test_index.py -qlocally? (pip install azdevrequired)For new extensions:
About Extension Publish
There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update
src/index.jsonautomatically.You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify
src/index.json.