[Key Vault] az keyvault ekm-connection: Remove preview status - #34095
Yash (notyashhh) wants to merge 1 commit into
Conversation
|
Thank you for your contribution! We will review the pull request and get back to you soon. |
There was a problem hiding this comment.
🟢 Approval recommended
No unresolved issues were identified that would block approval.
Pull request overview
Removes preview metadata from the Key Vault EKM connection commands and --external-key-id, promoting them to GA without changing behavior.
Changes:
- Removes preview status from EKM command groups.
- Removes preview status from
--external-key-id.
File summaries
| File | Description |
|---|---|
| src/azure-cli/azure/cli/command_modules/keyvault/commands.py | Updated as part of this pull request. |
| src/azure-cli/azure/cli/command_modules/keyvault/_params.py | Updated as part of this pull request. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
🔔 Routing this PR to @Azure/act-identity-squad. |
Live test skipped⏭️ Skipping the live test for this revision because no changed test file was found ( The live-test pipeline runs only the test files a PR changes, so there is nothing to execute for this commit. A skipped live test is not a passing test result. The Agent review separately checks whether the affected command module includes focused regression tests or updated recordings. If a test file is changed in a later commit, the live test will run automatically. |
There was a problem hiding this comment.
Review
Reviewed head a34502c46fab4597d5441d962217ebc95b1bca2a. This is a focused GA metadata change: commands.py:146-154 removes preview status from both EKM command groups, and _params.py:363-364 does the same for --external-key-id. Handlers, validators, request/response mappings and API versions are unchanged; the History Notes cover both public surfaces. The reported is_preview property-removal warnings match this intended promotion. No additional semantic defect was confirmed.
Non-blocking CI follow-up: the completed CI failures below are not introduced by these edits. The package jobs quote Debian archive HTTP 404s; Credential Scanner identifies acr/tests/latest/recordings/test_acr_login_expose_token.yaml:312, which is not changed by this PR. No source change is requested for these CI failures; rerun or escalate the affected pipelines to their owners. This is not an all-green result.
Upstream CI
Azure.azure-cli
- Result: failure
- Included checks:
Azure.azure-cli (Build Deb Packages Bullseye ARM64),Azure.azure-cli (Build Deb Packages Bullseye AMD64) - Failure details:
- Build Deb Packages Bullseye ARM64 / Build debian bullseye arm64 Package (Not PR-related)
- Evidence: E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/g/gnupg2/gpg-wks-server_2.2.27-2%2bdeb11u3_arm64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/g/gnupg2/gnupg_2.2.27-2%2bdeb11u3_all.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/f/freetype/libfreetype6_2.10.4%2bdfsg-1%2bdeb11u2_arm64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/p/python3.9/libpython3.9_3.9.2-1%2bdeb11u7_arm64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/p/python3.9/libpython3.9-dev_3.9.2-1%2bdeb11u7_arm64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/o/openssl/libssl-dev_1.1.1w-0%2bdeb11u8_arm64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/p/python3.9/python3.9-dev_3.9.2-1%2bdeb11u7_arm64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Unable to fetch some archives, maybe run apt-get update or try with --fix-missing?
Bash exited with code '100'. - Next action: Pipeline owners should refresh the Bullseye package indexes/base image and retry the unavailable Debian package downloads. The PR changes only Key Vault preview metadata, not package dependencies. No source change is requested in this PR for these download failures.
- Verify: Re-run the Bullseye ARM64 and AMD64 package-build tasks in build 350113 and confirm the quoted 404 errors and exit code 100 are gone.
- Evidence: E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/g/gnupg2/gpg-wks-server_2.2.27-2%2bdeb11u3_arm64.deb 404 Not Found [IP: 146.75.38.132 80]
- Build Deb Packages Bullseye AMD64 / Build debian bullseye amd64 Package (Not PR-related)
- Evidence: E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/g/gnupg2/gpg-agent_2.2.27-2%2bdeb11u3_amd64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/g/gnupg2/gpgsm_2.2.27-2%2bdeb11u3_amd64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/g/gnupg2/gnupg_2.2.27-2%2bdeb11u3_all.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/t/tiff/libtiff5_4.2.0-1%2bdeb11u8_amd64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/libg/libgd2/libgd3_2.3.0-2%2bdeb11u2_amd64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/e/expat/libexpat1-dev_2.2.10-2%2bdeb11u7_amd64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/o/openssl/libssl-dev_1.1.1w-0%2bdeb11u8_amd64.deb 404 Not Found [IP: 146.75.38.132 80]
E: Unable to fetch some archives, maybe run apt-get update or try with --fix-missing?
Bash exited with code '100'. - Next action: Pipeline owners should refresh the Bullseye package indexes/base image and retry the unavailable Debian package downloads. The PR changes only Key Vault preview metadata, not package dependencies. No source change is requested in this PR for these download failures.
- Verify: Re-run the Bullseye ARM64 and AMD64 package-build tasks in build 350113 and confirm the quoted 404 errors and exit code 100 are gone.
- Evidence: E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/g/gnupg2/gpg-agent_2.2.27-2%2bdeb11u3_amd64.deb 404 Not Found [IP: 146.75.38.132 80]
- Credential Scanner / Post Analysis (Not PR-related)
- Evidence: Guardian is searching for results that meet the given criteria to break the build.
Results Query Summary:
Tool Filters (Include): credscan:Error
Baselines: default
Suppression Sets: default
Policy: Microsoft
- Evidence: Guardian is searching for results that meet the given criteria to break the build.
- Build Deb Packages Bullseye ARM64 / Build debian bullseye arm64 Package (Not PR-related)
- Credential Scanner Error CSCAN-AZURE0140 - File: src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml:src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml. Line: 312. Column 33.
Signature: e5b6932e11299bd6a58637112d571811a673c34fe3ad6d0de7ba8c73cdbb415e- Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
- Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.
- Credential Scanner / Post Analysis (Not PR-related)
- Evidence: Guardian is searching for results that meet the given criteria to break the build.
Results Query Summary:
Tool Filters (Include): credscan:Error
Baselines: default
Suppression Sets: default
Policy: Microsoft
- Evidence: Guardian is searching for results that meet the given criteria to break the build.
- Credential Scanner Error CSCAN-AZURE0140 - File: src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml:src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml. Line: 312. Column 33.
Signature: e5b6932e11299bd6a58637112d571811a673c34fe3ad6d0de7ba8c73cdbb415e
Tool: Credential Scanner: Rule: CSCAN-AZURE0140 (Azure AD Client Access Token). https://aka.ms/credscan- Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
- Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.
- Credential Scanner / Post Analysis (Not PR-related)
- Evidence: Suppressed results: 0
Results excluded by tool filters: 0
Results below minimum severity: 0
Results classified as Pass: 0
Results in flight: 0
Guardian detected one or more breaking results.
Error: Guardian exited with an error exit code: 8
##[section]Finishing: Post Analysis - Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
- Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.
- Evidence: Suppressed results: 0
Azure.azure-cli (Credential Scanner)
- Result: failure
- Failure details:
- Credential Scanner / Post Analysis (Not PR-related)
- Evidence: Guardian is searching for results that meet the given criteria to break the build.
Results Query Summary:
Tool Filters (Include): credscan:Error
Baselines: default
Suppression Sets: default
Policy: Microsoft
- Evidence: Guardian is searching for results that meet the given criteria to break the build.
- Credential Scanner / Post Analysis (Not PR-related)
- Credential Scanner Error CSCAN-AZURE0140 - File: src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml:src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml. Line: 312. Column 33.
Signature: e5b6932e11299bd6a58637112d571811a673c34fe3ad6d0de7ba8c73cdbb415e- Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
- Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.
- Credential Scanner / Post Analysis (Not PR-related)
- Evidence: Guardian is searching for results that meet the given criteria to break the build.
Results Query Summary:
Tool Filters (Include): credscan:Error
Baselines: default
Suppression Sets: default
Policy: Microsoft
- Evidence: Guardian is searching for results that meet the given criteria to break the build.
- Credential Scanner Error CSCAN-AZURE0140 - File: src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml:src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml. Line: 312. Column 33.
Signature: e5b6932e11299bd6a58637112d571811a673c34fe3ad6d0de7ba8c73cdbb415e
Tool: Credential Scanner: Rule: CSCAN-AZURE0140 (Azure AD Client Access Token). https://aka.ms/credscan- Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
- Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.
- Credential Scanner / Post Analysis (Not PR-related)
- Evidence: Suppressed results: 0
Results excluded by tool filters: 0
Results below minimum severity: 0
Results classified as Pass: 0
Results in flight: 0
Guardian detected one or more breaking results.
Error: Guardian exited with an error exit code: 8
##[section]Finishing: Post Analysis - Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
- Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.
- Evidence: Suppressed results: 0
Test validation
- Live test: Skipped: this PR changes no runnable test files; no new live-test run was dispatched.
- Regression coverage: Gap detected for
keyvault: production behavior changed without a focused test or recording change.
For the keyvault coverage gap, add src/azure-cli/azure/cli/command_modules/keyvault/tests/latest/test_keyvault_ekm_preview_status.py with focused command-metadata/help assertions: the parent listing, both EKM groups, all six EKM commands, and keyvault key create --external-key-id must no longer be marked preview. Include an unchanged preview feature such as keyvault key get-policy-template as a negative control, so the test does not pass merely because all preview markers disappeared. Assert the specific option's status rather than the absence of every preview label in key create help, because unrelated options remain preview.
Run the focused selector azdev test test_keyvault_ekm_preview_status through the repository test harness and rerun the command/help compatibility checks. No service payload or output-shape change is present in this diff, so no scenario re-recording is indicated solely for these metadata edits; automated help/registration coverage is the missing regression evidence. The PR author's reported manual help/GET exercises are useful context, but are not changed automated tests or a new Agent live-test result.
Risk assessment
31/100 · Medium · High confidence
The Medium rating is driven by public CLI behavior, no changed regression test.
- Change scope: 2 changed files, 5 changed lines (
+2/-3), including 2 production files. - Affected components:
keyvault - Risk drivers: public CLI behavior (+18); no changed regression test (+10)
- Regression evidence: No changed regression test was detected for the production changes, increasing risk.
- Confidence: High because changed-line patches were available for every production file.
- Required review: Owning-squad review is recommended for
keyvaultbefore merge.
|
🔔 Routing this PR to @Azure/act-identity-squad. |
🤖 PR Validation —⚠️ Review suggested
Related command
az keyvault ekm-connectionaz keyvault key create --external-key-idDescription
Removes the preview labels from the EKM connection command group, its certificate subgroup, and
--external-key-idfor EKM GA. No SDK, API version, or command behavior changes.Related to Azure/CLIPS#605 (CLI portion only).
Testing Guide
--external-key-id. The relevant preview labels are gone.az keyvault ekm-connection showandaz keyvault ekm-connection certificate showagainst an existing Managed HSM. Both returned HTTP 200, and the returned certificates parsed successfully.History Notes
[Key Vault]
az keyvault ekm-connection: Remove preview status[Key Vault]
az keyvault key create: Remove preview status from--external-key-id