[Network] az network firewall policy kube-selector-group: Add new command group - #10418
Merged
Ethan Yang (necusjz) merged 1 commit intoOct 2, 2026
Conversation
…ommand group Add the `kubeSelectorGroups` sub-resource of `Microsoft.Network/firewallPolicies` (API version 2025-09-01) as `az network firewall policy kube-selector-group` create/show/list/update/delete/wait. `--pod-selector` and `--namespace-selector` use the CLI shorthand syntax and support both `matchLabels` and `matchExpressions`; `update` is read-modify-write, so a selector that is not passed keeps its current value and an explicit `null` clears it. Copilot-Session: 2aac2679-f367-4fb7-8be4-398b163db419
microsoft-github-policy-service
Bot
requested review from
Yu Chen (jsntcy),
Ethan Yang (necusjz) and
Yong Zhang (yonzhan)
October 1, 2026 07:28
Jian Hui (huiii99)
marked this pull request as ready for review
October 2, 2026 00:02
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The response schemas omit the API-defined lastUpdated field across several commands.
Review effort: Balanced
Findings: 5
Open (5)
What changed in this PR
Adds CRUD and wait commands for Azure Firewall Policy Kubernetes selector groups using API 2025-09-01.
Changes:
- Adds generated create/show/list/update/delete/wait commands.
- Adds selector and read-modify-write scenario coverage.
- Bumps the extension to
2.4.0and updates release history.
| File | Description |
|---|---|
setup.py |
Bumps extension version. |
HISTORY.rst |
Documents release changes. |
test_azure_firewall_scenario.py |
Adds command and argument tests. |
test_azure_firewall_policy_kube_selector_group.yaml |
Records the scenario. |
_create.py |
Implements create. |
_delete.py |
Implements delete. |
_list.py |
Implements list. |
_show.py |
Implements show. |
_update.py |
Implements read-modify-write update. |
_wait.py |
Implements wait. |
__init__.py |
Exports commands. |
__cmd_group.py |
Registers the command group. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Collaborator
|
Network |
Comment on lines
+6
to
+17
| 2.4.0 | ||
| ++++++ | ||
| * `az network firewall policy show` : Expose read-only property `afcManaged` indicating whether the firewall policy is managed by Azure Firewall Configuration (AFC). | ||
| * Bump API version to `2025-09-01` for `az network firewall policy` create/update/show/list/delete/wait. | ||
| * `az network firewall policy kube-selector-group` : Add new command group (`create`/`show`/`list`/`update`/`delete`/`wait`) to manage Kubernetes selector groups of a firewall policy, with `--pod-selector` and `--namespace-selector` supporting `matchLabels` and `matchExpressions`. | ||
| * `az network firewall show/list` : Expose read-only property `afcConfiguration` (with read-only `serviceEndpoint`) for the Azure Firewall for Containers endpoint. | ||
| * `az network firewall create/update` : Add `--create-afc-control-plane`/`--create-afc` to create an AFC control plane for the Azure Firewall. | ||
| * Bump API version to `2025-09-01` for `az network firewall` create/update/show/list/delete/wait. | ||
|
|
||
| 2.3.0 | ||
| ++++++ | ||
| * `az network firewall policy show` : Expose read-only property `afcManaged` indicating whether the firewall policy is managed by Azure Firewall Configuration (AFC). | ||
| * Bump API version to `2025-09-01` for `az network firewall policy` create/update/show/list/delete/wait. | ||
|
|
Ethan Yang (necusjz)
approved these changes
Oct 2, 2026
Collaborator
|
[Release] Update index.json for extension [ azure-firewall-2.4.0 ] : https://dev.azure.com/msazure/One/_build/results?buildId=183839837&view=results |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This checklist is used to make sure that common guidelines for a pull request are followed.
Related command
az network firewall policy kube-selector-group create/show/list/update/delete/waitRelated issue: Azure/azure-cli#33902
AAZ PR: Azure/aaz#1111
Swagger PR: Azure/azure-rest-api-specs#44865 (merged)
PowerShell reference PR: Azure/azure-powershell#30007 (merged)
Adds the
Microsoft.Network/firewallPolicies/kubeSelectorGroupssub-resource (API version2025-09-01) as a new command group.--pod-selectorand--namespace-selectoruse the CLI shorthand syntax and support bothmatchLabelsandmatchExpressions(operator:In|NotIn|Exists|DoesNotExist); no extra selector builder commands were added.updateis read-modify-write, so a selector that is not passed keeps its current value and an explicitnullclears it.deletehandles the204 No Contentresponse.setup.pyis bumped to2.4.0and the entries of #10413 are moved under it, since those changes did not ship in the released2.3.0.Validation
python -m pytest azext_firewall/tests/latest/test_azure_firewall_scenario.py -k "ArgumentTest"python -m pytest azext_firewall/tests/latest/test_azure_firewall_scenario.py -k kube_selector_group(live, recorded)python -m pytest azext_firewall/tests/latest/test_azure_firewall_scenario.py -k kube_selector_group(playback)azdev style azure-firewallpython scripts/ci/test_index.py -qazdev linter azure-firewallcould not run in this environment: it fails while loading the unrelatedbackupcommand module (ImportError: cannot import name 'InstantItemRecoveryOperationResultRequest' from 'azure.mgmt.recoveryservicesbackup.models').General Guidelines
azdev style <YOUR_EXT>locally? (pip install azdevrequired)python scripts/ci/test_index.py -qlocally? (pip install azdevrequired)For new extensions:
About Extension Publish
There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update
src/index.jsonautomatically.You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify
src/index.json.