-
Notifications
You must be signed in to change notification settings - Fork 1.5k
[AKS] az aks update: Set CMK property "enabled" to false and remove other CMK properties when enable PMK on a CMK-disabled cluster
#9385
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
️✔️Azure CLI Extensions Breaking Change Test
|
|
Thank you for your contribution! We will review the pull request and get back to you soon. |
|
The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR. Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions). pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>
|
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull Request Overview
This PR enables PMK (Platform-Managed Keys) to be activated on AKS clusters that previously had CMK (Customer-Managed Keys) disabled, ensuring proper cleanup of stale CMK properties.
- Version bump from 19.0.0b10 to 19.0.0b11
- Modified
update_kms_pmk_cmk()to clear CMK properties when enabling PMK on CMK-disabled clusters - Added comprehensive test coverage for the new scenario
Reviewed Changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| setup.py | Version bump to 19.0.0b11 |
| managed_cluster_decorator.py | Added logic to detect and clear stale CMK properties when enabling PMK on CMK-disabled clusters |
| test_managed_cluster_decorator.py | Added unit test verifying CMK property cleanup when enabling PMK on CMK-disabled cluster |
| test_aks_commands.py | Added end-to-end integration test for the CMK → disable CMK → enable PMK workflow |
| HISTORY.rst | Updated changelog with new version and feature description |
|
/azp run |
|
Azure Pipelines successfully started running 2 pipeline(s). |
… other CMK properties when enable PMK on a CMK-disabled cluster
50ef379 to
3615ca1
Compare
AbelHu
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. Thanks for the PR.
|
/azp run |
|
Azure Pipelines successfully started running 2 pipeline(s). |
| name_prefix="clitest", | ||
| location="eastus2euap", | ||
| ) | ||
| def test_aks_create_with_kms_cmk_and_disable_cmk_and_update_pmk( |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Live test passed!
|
[Release] Update index.json for extension [ aks-preview-19.0.0b11 ] : https://dev.azure.com/msazure/One/_build/results?buildId=142827702&view=results |
This checklist is used to make sure that common guidelines for a pull request are followed.
Related command
General Guidelines
azdev style <YOUR_EXT>locally? (pip install azdevrequired)python scripts/ci/test_index.py -qlocally? (pip install wheel==0.30.0required)For new extensions:
About Extension Publish
There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update
src/index.jsonautomatically.You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify
src/index.json.