Skip to content

{Keyvault} Bump azure-keyvault-keys to 4.11.0b1 - #31288

Merged
Yishi Wang (evelyn-ys) merged 9 commits into
Azure:devfrom
evelyn-ys:keyvault_get_attestation
May 6, 2025
Merged

Yishi Wang (evelyn-ys) merged 9 commits into
Azure:devfrom
evelyn-ys:keyvault_get_attestation

Conversation

@evelyn-ys

@evelyn-ys Yishi Wang (evelyn-ys) commented Apr 17, 2025

Copy link
Copy Markdown
Contributor

Related command

Description

This PR bumps API version for keyvault key from 7.5-preview.1 to 7.6-preview.2
Will add new feature support for key attestation in separate PR

Testing Guide

History Notes

[Component Name 1] BREAKING CHANGE: az command a: Make some customer-facing breaking change
[Component Name 2] az command b: Add some customer-facing feature


This checklist is used to make sure that common guidelines for a pull request are followed.

@azure-client-tools-bot-prd

azure-client-tools-bot-prd Bot commented Apr 17, 2025

Copy link
Copy Markdown
️✔️AzureCLI-FullTest
️✔️acr
️✔️latest
️✔️3.12
️✔️3.9
️✔️acs
️✔️latest
️✔️3.12
️✔️3.9
️✔️advisor
️✔️latest
️✔️3.12
️✔️3.9
️✔️ams
️✔️latest
️✔️3.12
️✔️3.9
️✔️apim
️✔️latest
️✔️3.12
️✔️3.9
️✔️appconfig
️✔️latest
️✔️3.12
️✔️3.9
️✔️appservice
️✔️latest
️✔️3.12
️✔️3.9
️✔️aro
️✔️latest
️✔️3.12
️✔️3.9
️✔️backup
️✔️latest
️✔️3.12
️✔️3.9
️✔️batch
️✔️latest
️✔️3.12
️✔️3.9
️✔️batchai
️✔️latest
️✔️3.12
️✔️3.9
️✔️billing
️✔️latest
️✔️3.12
️✔️3.9
️✔️botservice
️✔️latest
️✔️3.12
️✔️3.9
️✔️cdn
️✔️latest
️✔️3.12
️✔️3.9
️✔️cloud
️✔️latest
️✔️3.12
️✔️3.9
️✔️cognitiveservices
️✔️latest
️✔️3.12
️✔️3.9
️✔️compute_recommender
️✔️latest
️✔️3.12
️✔️3.9
️✔️computefleet
️✔️latest
️✔️3.12
️✔️3.9
️✔️config
️✔️latest
️✔️3.12
️✔️3.9
️✔️configure
️✔️latest
️✔️3.12
️✔️3.9
️✔️consumption
️✔️latest
️✔️3.12
️✔️3.9
️✔️container
️✔️latest
️✔️3.12
️✔️3.9
️✔️containerapp
️✔️latest
️✔️3.12
️✔️3.9
️✔️core
️✔️latest
️✔️3.12
️✔️3.9
️✔️cosmosdb
️✔️latest
️✔️3.12
️✔️3.9
️✔️databoxedge
️✔️latest
️✔️3.12
️✔️3.9
️✔️dls
️✔️latest
️✔️3.12
️✔️3.9
️✔️dms
️✔️latest
️✔️3.12
️✔️3.9
️✔️eventgrid
️✔️latest
️✔️3.12
️✔️3.9
️✔️eventhubs
️✔️latest
️✔️3.12
️✔️3.9
️✔️feedback
️✔️latest
️✔️3.12
️✔️3.9
️✔️find
️✔️latest
️✔️3.12
️✔️3.9
️✔️hdinsight
️✔️latest
️✔️3.12
️✔️3.9
️✔️identity
️✔️latest
️✔️3.12
️✔️3.9
️✔️iot
️✔️latest
️✔️3.12
️✔️3.9
️✔️keyvault
️✔️latest
️✔️3.12
️✔️3.9
️✔️lab
️✔️latest
️✔️3.12
️✔️3.9
️✔️managedservices
️✔️latest
️✔️3.12
️✔️3.9
️✔️maps
️✔️latest
️✔️3.12
️✔️3.9
️✔️marketplaceordering
️✔️latest
️✔️3.12
️✔️3.9
️✔️monitor
️✔️latest
️✔️3.12
️✔️3.9
️✔️mysql
️✔️latest
️✔️3.12
️✔️3.9
️✔️netappfiles
️✔️latest
️✔️3.12
️✔️3.9
️✔️network
️✔️latest
️✔️3.12
️✔️3.9
️✔️policyinsights
️✔️latest
️✔️3.12
️✔️3.9
️✔️privatedns
️✔️latest
️✔️3.12
️✔️3.9
️✔️profile
️✔️latest
️✔️3.12
️✔️3.9
️✔️rdbms
️✔️latest
️✔️3.12
️✔️3.9
️✔️redis
️✔️latest
️✔️3.12
️✔️3.9
️✔️relay
️✔️latest
️✔️3.12
️✔️3.9
️✔️resource
️✔️latest
️✔️3.12
️✔️3.9
️✔️role
️✔️latest
️✔️3.12
️✔️3.9
️✔️search
️✔️latest
️✔️3.12
️✔️3.9
️✔️security
️✔️latest
️✔️3.12
️✔️3.9
️✔️servicebus
️✔️latest
️✔️3.12
️✔️3.9
️✔️serviceconnector
️✔️latest
️✔️3.12
️✔️3.9
️✔️servicefabric
️✔️latest
️✔️3.12
️✔️3.9
️✔️signalr
️✔️latest
️✔️3.12
️✔️3.9
️✔️sql
️✔️latest
️✔️3.12
️✔️3.9
️✔️sqlvm
️✔️latest
️✔️3.12
️✔️3.9
️✔️storage
️✔️latest
️✔️3.12
️✔️3.9
️✔️synapse
️✔️latest
️✔️3.12
️✔️3.9
️✔️telemetry
️✔️latest
️✔️3.12
️✔️3.9
️✔️util
️✔️latest
️✔️3.12
️✔️3.9
️✔️vm
️✔️latest
️✔️3.12
️✔️3.9

@azure-client-tools-bot-prd

Copy link
Copy Markdown

Hi Yishi Wang (@evelyn-ys),
Since the current milestone time is less than 7 days, this pr will be reviewed in the next milestone.

@azure-client-tools-bot-prd

azure-client-tools-bot-prd Bot commented Apr 17, 2025

Copy link
Copy Markdown
❌AzureCLI-BreakingChangeTest
⚠️keyvault
rule cmd_name rule_message suggest_message
⚠️ 1010 - ParaPropUpdate keyvault key decrypt cmd keyvault key decrypt update parameter algorithm: updated property choices from ['A128CBC', 'A128CBCPAD', 'A128GCM', 'A192CBC', 'A192CBCPAD', 'A192GCM', 'A256CBC', 'A256CBCPAD', 'A256GCM', 'RSA-OAEP', 'RSA-OAEP-256', 'RSA1_5'] to ['A128CBC', 'A128CBCPAD', 'A128GCM', 'A192CBC', 'A192CBCPAD', 'A192GCM', 'A256CBC', 'A256CBCPAD', 'A256GCM', 'CKM_AES_KEY_WRAP', 'CKM_AES_KEY_WRAP_PAD', 'RSA-OAEP', 'RSA-OAEP-256', 'RSA1_5']
⚠️ 1010 - ParaPropUpdate keyvault key encrypt cmd keyvault key encrypt update parameter algorithm: updated property choices from ['A128CBC', 'A128CBCPAD', 'A128GCM', 'A192CBC', 'A192CBCPAD', 'A192GCM', 'A256CBC', 'A256CBCPAD', 'A256GCM', 'RSA-OAEP', 'RSA-OAEP-256', 'RSA1_5'] to ['A128CBC', 'A128CBCPAD', 'A128GCM', 'A192CBC', 'A192CBCPAD', 'A192GCM', 'A256CBC', 'A256CBCPAD', 'A256GCM', 'CKM_AES_KEY_WRAP', 'CKM_AES_KEY_WRAP_PAD', 'RSA-OAEP', 'RSA-OAEP-256', 'RSA1_5']
⚠️ 1010 - ParaPropUpdate keyvault key sign cmd keyvault key sign update parameter algorithm: updated property choices from ['ES256', 'ES256K', 'ES384', 'ES512', 'PS256', 'PS384', 'PS512', 'RS256', 'RS384', 'RS512'] to ['ES256', 'ES256K', 'ES384', 'ES512', 'HS256', 'HS384', 'HS512', 'PS256', 'PS384', 'PS512', 'RS256', 'RS384', 'RS512']
⚠️ 1010 - ParaPropUpdate keyvault key verify cmd keyvault key verify update parameter algorithm: updated property choices from ['ES256', 'ES256K', 'ES384', 'ES512', 'PS256', 'PS384', 'PS512', 'RS256', 'RS384', 'RS512'] to ['ES256', 'ES256K', 'ES384', 'ES512', 'HS256', 'HS384', 'HS512', 'PS256', 'PS384', 'PS512', 'RS256', 'RS384', 'RS512']
❌rdbms
rule cmd_name rule_message suggest_message
1010 - ParaPropUpdate postgres flexible-server geo-restore cmd postgres flexible-server geo-restore update parameter restore_point_in_time: updated property default from 2025-04-28T11:06:05+00:00 to 2025-04-28T11:02:26+00:00 please change property default from 2025-04-28T11:02:26+00:00 to 2025-04-28T11:06:05+00:00 for parameter restore_point_in_time of cmd postgres flexible-server geo-restore

Please submit your Breaking Change Pre-announcement ASAP if you haven't already. Please note:

  • Breaking changes can only be merged during the designated breaking change window
  • A pre-announcement must be released at least one month in advance

For more details on how to introduce breaking changes, refer to the documentation: azure-cli/doc/how_to_introduce_breaking_changes.md

@yonzhan

Copy link
Copy Markdown
Collaborator

Thank you for your contribution! We will review the pull request and get back to you soon.

@github-actions

Copy link
Copy Markdown

The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR.

Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions).
After that please run the following commands to enable git hooks:

pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>

@evelyn-ys
Yishi Wang (evelyn-ys) merged commit cd9a1ae into Azure:dev May 6, 2025
vidyadharijami pushed a commit to vidyadharijami/azure-cli that referenced this pull request Jul 27, 2026
The KeyVaultPreparer was pinned to --enable-rbac-authorization false (Access-Policy
mode) by commit cd9a1ae (Azure#31288), but the CMK encryption identities are granted
via RBAC role assignments (Key Vault Crypto Service Encryption User). AP-mode vaults
ignore RBAC assignments, so 'backup vault encryption update' failed live with 403
UserErrorCMKKeyVaultAuthFailure. Flip the preparer to --enable-rbac-authorization
true so the (live-only) RBAC grants take effect. Grants stay commented because role
assignments use non-deterministic GUIDs that cannot be recorded/replayed; re-recorded
the cassette. Verified: playback passes, live passes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Auto-Assign Auto assign by bot KeyVault az keyvault

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants