Skip to content

[Network] az network firewall policy kube-selector-group: Add new command group - #10418

Merged
Ethan Yang (necusjz) merged 1 commit into
Azure:mainfrom
huiii99:network-firewall-policy-kube-selector-group-33902
Oct 2, 2026
Merged

Ethan Yang (necusjz) merged 1 commit into
Azure:mainfrom
huiii99:network-firewall-policy-kube-selector-group-33902

Conversation

@huiii99

Copy link
Copy Markdown
Member

This checklist is used to make sure that common guidelines for a pull request are followed.

Related command

az network firewall policy kube-selector-group create/show/list/update/delete/wait

Related issue: Azure/azure-cli#33902
AAZ PR: Azure/aaz#1111
Swagger PR: Azure/azure-rest-api-specs#44865 (merged)
PowerShell reference PR: Azure/azure-powershell#30007 (merged)

Adds the Microsoft.Network/firewallPolicies/kubeSelectorGroups sub-resource (API version 2025-09-01) as a new command group. --pod-selector and --namespace-selector use the CLI shorthand syntax and support both matchLabels and matchExpressions (operator: In|NotIn|Exists|DoesNotExist); no extra selector builder commands were added. update is read-modify-write, so a selector that is not passed keeps its current value and an explicit null clears it. delete handles the 204 No Content response.

setup.py is bumped to 2.4.0 and the entries of #10413 are moved under it, since those changes did not ship in the released 2.3.0.

Validation

Command Result
python -m pytest azext_firewall/tests/latest/test_azure_firewall_scenario.py -k "ArgumentTest" passed (5 tests)
python -m pytest azext_firewall/tests/latest/test_azure_firewall_scenario.py -k kube_selector_group (live, recorded) passed
python -m pytest azext_firewall/tests/latest/test_azure_firewall_scenario.py -k kube_selector_group (playback) passed
azdev style azure-firewall passed (pylint + flake8)
python scripts/ci/test_index.py -q passed (9 tests, 2 skipped)

azdev linter azure-firewall could not run in this environment: it fails while loading the unrelated backup command module (ImportError: cannot import name 'InstantItemRecoveryOperationResultRequest' from 'azure.mgmt.recoveryservicesbackup.models').

General Guidelines

  • Have you run azdev style <YOUR_EXT> locally? (pip install azdev required)
  • Have you run python scripts/ci/test_index.py -q locally? (pip install azdev required)
  • My extension version conforms to the Extension version schema

For new extensions:

About Extension Publish

There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update src/index.json automatically.
You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify src/index.json.

…ommand group

Add the `kubeSelectorGroups` sub-resource of `Microsoft.Network/firewallPolicies`
(API version 2025-09-01) as `az network firewall policy kube-selector-group`
create/show/list/update/delete/wait.

`--pod-selector` and `--namespace-selector` use the CLI shorthand syntax and
support both `matchLabels` and `matchExpressions`; `update` is read-modify-write,
so a selector that is not passed keeps its current value and an explicit `null`
clears it.

Copilot-Session: 2aac2679-f367-4fb7-8be4-398b163db419

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The response schemas omit the API-defined lastUpdated field across several commands.

Review effort: Balanced
Findings: 5 Medium severity

Open (5)
What changed in this PR

Adds CRUD and wait commands for Azure Firewall Policy Kubernetes selector groups using API 2025-09-01.

Changes:

  • Adds generated create/show/list/update/delete/wait commands.
  • Adds selector and read-modify-write scenario coverage.
  • Bumps the extension to 2.4.0 and updates release history.
File Description
setup.py Bumps extension version.
HISTORY.rst Documents release changes.
test_azure_firewall_scenario.py Adds command and argument tests.
test_azure_firewall_policy_kube_selector_group.yaml Records the scenario.
_create.py Implements create.
_delete.py Implements delete.
_list.py Implements list.
_show.py Implements show.
_update.py Implements read-modify-write update.
_wait.py Implements wait.
__init__.py Exports commands.
__cmd_group.py Registers the command group.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@yonzhan Yong Zhang (yonzhan) added this to the Backlog milestone Oct 2, 2026
@yonzhan

Copy link
Copy Markdown
Collaborator

Network

Comment on lines +6 to +17
2.4.0
++++++
* `az network firewall policy show` : Expose read-only property `afcManaged` indicating whether the firewall policy is managed by Azure Firewall Configuration (AFC).
* Bump API version to `2025-09-01` for `az network firewall policy` create/update/show/list/delete/wait.
* `az network firewall policy kube-selector-group` : Add new command group (`create`/`show`/`list`/`update`/`delete`/`wait`) to manage Kubernetes selector groups of a firewall policy, with `--pod-selector` and `--namespace-selector` supporting `matchLabels` and `matchExpressions`.
* `az network firewall show/list` : Expose read-only property `afcConfiguration` (with read-only `serviceEndpoint`) for the Azure Firewall for Containers endpoint.
* `az network firewall create/update` : Add `--create-afc-control-plane`/`--create-afc` to create an AFC control plane for the Azure Firewall.
* Bump API version to `2025-09-01` for `az network firewall` create/update/show/list/delete/wait.

2.3.0
++++++
* `az network firewall policy show` : Expose read-only property `afcManaged` indicating whether the firewall policy is managed by Azure Firewall Configuration (AFC).
* Bump API version to `2025-09-01` for `az network firewall policy` create/update/show/list/delete/wait.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

good job!

@necusjz
Ethan Yang (necusjz) merged commit 336d9b2 into Azure:main Oct 2, 2026
44 checks passed
@azclibot

Copy link
Copy Markdown
Collaborator

[Release] Update index.json for extension [ azure-firewall-2.4.0 ] : https://dev.azure.com/msazure/One/_build/results?buildId=183839837&view=results

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants