Skip to content

[Key Vault] az keyvault ekm-connection: Remove preview status - #34095

Open
Yash (notyashhh) wants to merge 1 commit into
devfrom
yash/ekm-ga-remove-preview
Open

Yash (notyashhh) wants to merge 1 commit into
devfrom
yash/ekm-ga-remove-preview

Conversation

@notyashhh

@notyashhh Yash (notyashhh) commented Sep 17, 2026

Copy link
Copy Markdown
Member

🤖 PR Validation — ⚠️ Review suggested

Breaking Changes Tests
⚠️ None ️✔️ 130/130
⚠️AzureCLI-BreakingChangeTest
⚠️keyvault
rule cmd_name rule_message suggest_message
⚠️ 1004 - CmdPropRemove keyvault ekm-connection certificate show cmd keyvault ekm-connection certificate show removed property is_preview
⚠️ 1004 - CmdPropRemove keyvault ekm-connection check cmd keyvault ekm-connection check removed property is_preview
⚠️ 1004 - CmdPropRemove keyvault ekm-connection create cmd keyvault ekm-connection create removed property is_preview
⚠️ 1004 - CmdPropRemove keyvault ekm-connection delete cmd keyvault ekm-connection delete removed property is_preview
⚠️ 1004 - CmdPropRemove keyvault ekm-connection show cmd keyvault ekm-connection show removed property is_preview
⚠️ 1004 - CmdPropRemove keyvault ekm-connection update cmd keyvault ekm-connection update removed property is_preview

Related command
az keyvault ekm-connection
az keyvault key create --external-key-id

Description
Removes the preview labels from the EKM connection command group, its certificate subgroup, and --external-key-id for EKM GA. No SDK, API version, or command behavior changes.

Related to Azure/CLIPS#605 (CLI portion only).

Testing Guide

  • Verified 10 help views covering both groups, all six commands, the parent listing, and --external-key-id. The relevant preview labels are gone.
  • Ran az keyvault ekm-connection show and az keyvault ekm-connection certificate show against an existing Managed HSM. Both returned HTTP 200, and the returned certificates parsed successfully.
  • Live testing was GET-only. No resources were changed. Write operations and documentation generation were not tested locally.

History Notes
[Key Vault] az keyvault ekm-connection: Remove preview status
[Key Vault] az keyvault key create: Remove preview status from --external-key-id


Copilot AI lite review requested due to automatic review settings September 17, 2026 00:18
@notyashhh
Yash (notyashhh) requested a review from a team as a code owner September 17, 2026 00:18
@yonzhan

Copy link
Copy Markdown
Collaborator

Thank you for your contribution! We will review the pull request and get back to you soon.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved issues were identified that would block approval.

Pull request overview

Removes preview metadata from the Key Vault EKM connection commands and --external-key-id, promoting them to GA without changing behavior.

Changes:

  • Removes preview status from EKM command groups.
  • Removes preview status from --external-key-id.
File summaries
File Description
src/azure-cli/azure/cli/command_modules/keyvault/commands.py Updated as part of this pull request.
src/azure-cli/azure/cli/command_modules/keyvault/_params.py Updated as part of this pull request.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@a0x1ab Aditya Pujara (a0x1ab) added the Request X Engineering Agent Request X Engineering Agent testing and review label Sep 17, 2026
@microsoft-github-policy-service

Copy link
Copy Markdown
Contributor

🔔 Routing this PR to @Azure/act-identity-squad.

@x-engineering-agent

Copy link
Copy Markdown
Contributor

Live test skipped

⏭️ Skipping the live test for this revision because no changed test file was found (tests/**/test_*.py).

The live-test pipeline runs only the test files a PR changes, so there is nothing to execute for this commit. A skipped live test is not a passing test result. The Agent review separately checks whether the affected command module includes focused regression tests or updated recordings. If a test file is changed in a later commit, the live test will run automatically.

@x-engineering-agent x-engineering-agent Bot added the X Engineering Agent Reviewed Pull request reviewed by X Engineering Agent label Sep 17, 2026

@x-engineering-agent x-engineering-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yash (@notyashhh)

Review

Reviewed head a34502c46fab4597d5441d962217ebc95b1bca2a. This is a focused GA metadata change: commands.py:146-154 removes preview status from both EKM command groups, and _params.py:363-364 does the same for --external-key-id. Handlers, validators, request/response mappings and API versions are unchanged; the History Notes cover both public surfaces. The reported is_preview property-removal warnings match this intended promotion. No additional semantic defect was confirmed.

Non-blocking CI follow-up: the completed CI failures below are not introduced by these edits. The package jobs quote Debian archive HTTP 404s; Credential Scanner identifies acr/tests/latest/recordings/test_acr_login_expose_token.yaml:312, which is not changed by this PR. No source change is requested for these CI failures; rerun or escalate the affected pipelines to their owners. This is not an all-green result.

Upstream CI

Azure.azure-cli

  1. Credential Scanner Error CSCAN-AZURE0140 - File: src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml:src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml. Line: 312. Column 33.
    Signature: e5b6932e11299bd6a58637112d571811a673c34fe3ad6d0de7ba8c73cdbb415e
    • Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
    • Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.
  • Credential Scanner / Post Analysis (Not PR-related)
    • Evidence: Guardian is searching for results that meet the given criteria to break the build.
      Results Query Summary:
      Tool Filters (Include): credscan:Error
      Baselines: default
      Suppression Sets: default
      Policy: Microsoft
  1. Credential Scanner Error CSCAN-AZURE0140 - File: src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml:src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml. Line: 312. Column 33.
    Signature: e5b6932e11299bd6a58637112d571811a673c34fe3ad6d0de7ba8c73cdbb415e
    Tool: Credential Scanner: Rule: CSCAN-AZURE0140 (Azure AD Client Access Token). https://aka.ms/credscan
    • Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
    • Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.
  • Credential Scanner / Post Analysis (Not PR-related)
    • Evidence: Suppressed results: 0
      Results excluded by tool filters: 0
      Results below minimum severity: 0
      Results classified as Pass: 0
      Results in flight: 0
      Guardian detected one or more breaking results.
      Error: Guardian exited with an error exit code: 8
      ##[section]Finishing: Post Analysis
    • Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
    • Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.

Azure.azure-cli (Credential Scanner)

  • Result: failure
  • Failure details:
    • Credential Scanner / Post Analysis (Not PR-related)
      • Evidence: Guardian is searching for results that meet the given criteria to break the build.
        Results Query Summary:
        Tool Filters (Include): credscan:Error
        Baselines: default
        Suppression Sets: default
        Policy: Microsoft
  1. Credential Scanner Error CSCAN-AZURE0140 - File: src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml:src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml. Line: 312. Column 33.
    Signature: e5b6932e11299bd6a58637112d571811a673c34fe3ad6d0de7ba8c73cdbb415e
    • Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
    • Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.
  • Credential Scanner / Post Analysis (Not PR-related)
    • Evidence: Guardian is searching for results that meet the given criteria to break the build.
      Results Query Summary:
      Tool Filters (Include): credscan:Error
      Baselines: default
      Suppression Sets: default
      Policy: Microsoft
  1. Credential Scanner Error CSCAN-AZURE0140 - File: src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml:src/azure-cli/azure/cli/command_modules/acr/tests/latest/recordings/test_acr_login_expose_token.yaml. Line: 312. Column 33.
    Signature: e5b6932e11299bd6a58637112d571811a673c34fe3ad6d0de7ba8c73cdbb415e
    Tool: Credential Scanner: Rule: CSCAN-AZURE0140 (Azure AD Client Access Token). https://aka.ms/credscan
    • Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
    • Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.
  • Credential Scanner / Post Analysis (Not PR-related)
    • Evidence: Suppressed results: 0
      Results excluded by tool filters: 0
      Results below minimum severity: 0
      Results classified as Pass: 0
      Results in flight: 0
      Guardian detected one or more breaking results.
      Error: Guardian exited with an error exit code: 8
      ##[section]Finishing: Post Analysis
    • Next action: The flagged ACR recording is absent from this PR's diff. Escalate the existing recording finding to the ACR/security and pipeline owners for approved sanitization or false-positive disposition, without reproducing the suspected value. No Key Vault source change is requested for this failure.
    • Verify: Re-run Credential Scanner / Post Analysis for builds 350113 and 350115 and confirm CSCAN-AZURE0140 is resolved through the approved security process.

Test validation

  • Live test: Skipped: this PR changes no runnable test files; no new live-test run was dispatched.
  • Regression coverage: Gap detected for keyvault: production behavior changed without a focused test or recording change.

For the keyvault coverage gap, add src/azure-cli/azure/cli/command_modules/keyvault/tests/latest/test_keyvault_ekm_preview_status.py with focused command-metadata/help assertions: the parent listing, both EKM groups, all six EKM commands, and keyvault key create --external-key-id must no longer be marked preview. Include an unchanged preview feature such as keyvault key get-policy-template as a negative control, so the test does not pass merely because all preview markers disappeared. Assert the specific option's status rather than the absence of every preview label in key create help, because unrelated options remain preview.

Run the focused selector azdev test test_keyvault_ekm_preview_status through the repository test harness and rerun the command/help compatibility checks. No service payload or output-shape change is present in this diff, so no scenario re-recording is indicated solely for these metadata edits; automated help/registration coverage is the missing regression evidence. The PR author's reported manual help/GET exercises are useful context, but are not changed automated tests or a new Agent live-test result.

Risk assessment

31/100 · Medium · High confidence

The Medium rating is driven by public CLI behavior, no changed regression test.

  • Change scope: 2 changed files, 5 changed lines (+2 / -3), including 2 production files.
  • Affected components: keyvault
  • Risk drivers: public CLI behavior (+18); no changed regression test (+10)
  • Regression evidence: No changed regression test was detected for the production changes, increasing risk.
  • Confidence: High because changed-line patches were available for every production file.
  • Required review: Owning-squad review is recommended for keyvault before merge.

@x-engineering-agent x-engineering-agent Bot removed the Request X Engineering Agent Request X Engineering Agent testing and review label Sep 17, 2026
@microsoft-github-policy-service

Copy link
Copy Markdown
Contributor

🔔 Routing this PR to @Azure/act-identity-squad.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

act-identity-squad Auto-Assign Auto assign by bot KeyVault az keyvault X Engineering Agent Reviewed Pull request reviewed by X Engineering Agent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants