Changes to az commands to support managed identity in Connected Registry [DRAFT] - #33910
Conversation
Add user-assigned managed identity as an authentication mode between a
connected registry and its parent, alongside existing sync-token auth.
New / changed CLI surface
-------------------------
* `az acr connected-registry create`
* `--auth-type {SyncToken, ManagedIdentity}` (default: `SyncToken`).
* `--identity <user-assigned identity resource id>` (required when
`--auth-type ManagedIdentity`).
* `--sync-token` and `--repository` are rejected in `ManagedIdentity`
mode.
* `az acr connected-registry update`
* Supports migrating an existing connected registry between
`SyncToken` and `ManagedIdentity` auth modes.
* Registry must be in `Offline` state; same-mode credential rotation
is not supported.
* Migration MI -> SyncToken deliberately omits `identity` from the
PATCH payload to avoid ARM `ConflictingAuthInput`.
* `az acr connected-registry get-settings`
* When the target is `ManagedIdentity`-mode, emits a MI-flavored
connection string with `ACR_MANAGED_IDENTITY_CLIENT_ID` and
`ACR_MANAGED_IDENTITY_RESOURCE_ID` and skips sync-token password
generation.
* `az acr connected-registry permissions {show, update}`
* Reject with a clear error against `ManagedIdentity`-mode registries
(sync-token scope map is not applicable in that mode).
Implementation notes
--------------------
* Direct imports of `AuthType`, `ConnectionState`, `ManagedServiceIdentity`,
`ManagedServiceIdentityType`, `UserAssignedIdentity` etc. from the flat
`azure.mgmt.containerregistry.models` namespace; SDK enums are coerced
via `.value` because they are not `StrEnum`.
* `_get_current_auth_type` is defensive against both raw-string and enum
server responses (bug guard).
* Delete skips sync-token / scope-map cleanup for MI-mode registries
(bug guard).
Tests
-----
* Unit tests: `test_acr_connected_registry_mi_unit.py` (31 tests) cover
create/update validation, migration state machine (both directions,
including MI -> SyncToken identity-omission regression guard), delete
MI-mode cleanup guard, `get-settings` MI branch, and permissions
MI-mode rejection.
* Scenario test: `test_acr_connectedregistry_managed_identity` added
(currently `@record_only()`; cassette pending because the SDK preview
API is not yet available on the public control plane).
Dependencies
------------
* Bump `azure-mgmt-containerregistry` to `15.1.0b3` for the preview
api-version that exposes the connected-registry MI contract.
|
Hi Dhawal Jain (@dhawal777), |
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
There was a problem hiding this comment.
Pull request overview
This PR updates the ACR connected-registry command set to support Managed Identity (user-assigned) authentication in addition to the existing SyncToken flow, including migration between the two modes.
Changes:
- Adds
--auth-type(SyncToken|ManagedIdentity) and--identitytoaz acr connected-registry create/update, plus migration validation logic. - Updates
get-settingsoutput and blockspermissionsoperations for ManagedIdentity-mode registries. - Bumps
azure-mgmt-containerregistryto15.1.0b3and adds scenario + unit test coverage for MI paths.
Reviewed changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| src/azure-cli/setup.py | Bumps azure-mgmt-containerregistry dependency to 15.1.0b3. |
| src/azure-cli/HISTORY.rst | Adds upcoming release notes for MI support and SDK bump. |
| src/azure-cli/azure/cli/command_modules/acr/connected_registry.py | Implements MI auth support, migration validation, MI-aware delete/get-settings/permissions behavior. |
| src/azure-cli/azure/cli/command_modules/acr/_params.py | Introduces CLI parameters --auth-type, --identity, and update-only --sync-token for migration. |
| src/azure-cli/azure/cli/command_modules/acr/_help.py | Documents MI create and migration examples; updates permissions group description. |
| src/azure-cli/azure/cli/command_modules/acr/tests/latest/test_acr_connectedregistry_commands.py | Adds a recorded scenario test covering MI create/show/get-settings/delete. |
| src/azure-cli/azure/cli/command_modules/acr/tests/latest/test_acr_connected_registry_mi_unit.py | Adds unit tests for MI mode validation, PATCH shape, MI-mode delete behavior, and MI get-settings output. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
Live test results —
|
There was a problem hiding this comment.
The following CI checks are failing:
- azdev-linter
- azdev-style
- Azure.azure-cli
- Azure.azure-cli (Integration Test against Profiles Python314)
- Azure.azure-cli (Integration Test against Profiles Python312)
- Azure.azure-cli (Test Python Wheels Python314)
- Azure.azure-cli (Test Python Wheels Python312)
- Azure.azure-cli (Test Extensions Loading Python314)
- Azure.azure-cli (Build Windows MSI x86)
- Azure.azure-cli (Build Windows MSI x64)
- Azure.azure-cli (Build Windows ZIP x64)
- Azure.azure-cli Full Test
- Azure.azure-cli Full Test (Automation Full Test Python314 Profile Latest instance7)
- Azure.azure-cli Full Test (Automation Full Test Python314 Profile Latest instance8)
- Azure.azure-cli Full Test (Automation Full Test Python314 Profile Latest instance2)
- Azure.azure-cli Full Test (Automation Full Test Python314 Profile Latest instance5)
- Azure.azure-cli Full Test (Automation Full Test Python314 Profile Latest instance6)
- Azure.azure-cli Full Test (Automation Full Test Python314 Profile Latest instance1)
- Azure.azure-cli Full Test (Automation Full Test Python314 Profile Latest instance4)
- Azure.azure-cli Full Test (Automation Full Test Python312 Profile Latest instance7)
- Azure.azure-cli Full Test (Automation Full Test Python314 Profile Latest instance3)
- Azure.azure-cli Full Test (Automation Full Test Python312 Profile Latest instance6)
- Azure.azure-cli Breaking Change Test
- Azure.azure-cli (PerformanceCheck Python312)
- Azure.azure-cli (Secret Scan)
- Azure.azure-cli Full Test (Automation Full Test Python312 Profile Latest instance1)
- Azure.azure-cli Full Test (Automation Full Test Python312 Profile Latest instance2)
- Azure.azure-cli Full Test (Automation Full Test Python312 Profile Latest instance5)
- Azure.azure-cli Full Test (Automation Full Test Python312 Profile Latest instance8)
- Azure.azure-cli Full Test (Automation Full Test Python312 Profile Latest instance3)
- Azure.azure-cli (Unit Test for Telemetry Python312)
- Azure.azure-cli (Unit Test for Telemetry Python314)
- Azure.azure-cli Full Test (Automation Full Test Python312 Profile Latest instance4)
- Azure.azure-cli (Check License, History, and DocMap)
- Azure.azure-cli (Check the Format of Pull Request Title and Content)
- Azure.azure-cli (PerformanceCheck Python314)
- Azure.azure-cli (Verify latest index assets)
- Azure.azure-cli (Unit Test for Core Python312)
- Azure.azure-cli (Check CLI Linter)
- Azure.azure-cli (Verify src/azure-cli/requirements.*.Linux.txt)
- Azure.azure-cli (Unit Test for Core Python314)
- Azure.azure-cli (Check CLI Style)
- Azure.azure-cli (Verify src/azure-cli/requirements.*.Windows.txt)
- Azure.azure-cli (Verify src/azure-cli/requirements.*.Darwin.txt)
- azdev-style
- azdev-linter
- Live test run failed (see the dispatched
live-test.ymlworkflow run for details).
| 'azure-mgmt-compute~=34.1.0', | ||
| 'azure-mgmt-containerinstance==10.2.0b1', | ||
| 'azure-mgmt-containerregistry==15.1.0b2', | ||
| 'azure-mgmt-containerregistry==15.1.0b3', |
There was a problem hiding this comment.
Also need to update the files below once the SDK is ready:
src/azure-cli/requirements.py3.Linux.txt
src/azure-cli/requirements.py3.Linux.txt
src/azure-cli/requirements.py3.Darwin.txt
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
…SyncToken -> ManagedIdentity
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
There was a problem hiding this comment.
Could we also update the summaries for az acr connected-registry permissions show and az acr connected-registry permissions update to clarify that these commands support only connected registries using SyncToken authentication? The help text defined for the permissions group does not appear in the help output for the individual subcommands.
- Simplify _get_current_auth_type to use authType as the sole source of truth (drop identity-based inference and try/except guard; matches pre-existing direct-access style). - get-settings (MI mode): emit only the spec-required connection string; drop the extra ACR_MANAGED_IDENTITY_CLIENT_ID / ACR_MANAGED_IDENTITY_RESOURCE_ID env vars. - Coerce connection_state via .value before comparing to CONNECTION_STATE_OFFLINE (defensive against future SDK regen; symmetry with auth_type). - Help/params/constants tidy-ups: typo fixes (midnight, its, immediate), MI parameter help, SyncToken caveats on permissions show/update. - Tests: update _fake_cr helper so has_identity=True implies MI auth_type; rework TestGetCurrentAuthType; add plain-Enum coercion regression guard for connection_state; tighten MI get-settings assertions.
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
Related command
Description
Testing Guide
History Notes
[Component Name 1] BREAKING CHANGE:
az command a: Make some customer-facing breaking change[Component Name 2]
az command b: Add some customer-facing featureThis checklist is used to make sure that common guidelines for a pull request are followed.
The PR title and description has followed the guideline in Submitting Pull Requests.
I adhere to the Command Guidelines.
I adhere to the Error Handling Guidelines.