-
Notifications
You must be signed in to change notification settings - Fork 596
feat: Enable AVM WAF implementation to align with updated AVM standards #1898
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Prajwal-Microsoft
merged 160 commits into
Azure-Samples:waf-avm
from
Prasanjeet-Microsoft:infra-avm-waf
Sep 15, 2025
Merged
feat: Enable AVM WAF implementation to align with updated AVM standards #1898
Prajwal-Microsoft
merged 160 commits into
Azure-Samples:waf-avm
from
Prasanjeet-Microsoft:infra-avm-waf
Sep 15, 2025
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Co-authored-by: Roopan P M <[email protected]>
Co-authored-by: Roopan P M <[email protected]>
…es#1541) Co-authored-by: Ajit Padhi <[email protected]>
Co-authored-by: Roopan-Microsoft <[email protected]>
Co-authored-by: Roopan-Microsoft <[email protected]>
Co-authored-by: Roopan-Microsoft <[email protected]> Co-authored-by: Ross Smith <[email protected]> Co-authored-by: gpickett <[email protected]> Co-authored-by: Francia Riesco <[email protected]> Co-authored-by: Francia Riesco <[email protected]> Co-authored-by: Prajwal D C <[email protected]>
…nd Update Conversation flow based on template selection (Azure-Samples#1567) Co-authored-by: Pavan Kumar <v-kupavan.microsoft.com>
Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Pavan-Microsoft <[email protected]>
…ations, enhance parameter handling
…rvices and storage account configurations
…e services Bicep file
…al parameters and improved descriptions
…ervices Bicep files
…uration for enhanced authentication control
…ervices Bicep files
…account Bicep module
…tive Services module
…vices module and include resource group and subscription ID in web app settings
… and enhance PostgreSQL configurations
…os SQL role assignments, App Service settings, App Service plans, ACR access permissions, role assignments, custom types for private networking, and private DNS zone configurations to streamline the infrastructure codebase.
…tgreSQL module to enhance security and simplify configuration
…ity handling in scripts
…meters and adding high availability support
Prajwal-Microsoft
approved these changes
Sep 15, 2025
|
🎉 This PR is included in version 1.16.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Purpose
This pull request introduces a consistent approach to passing the managed identity client ID to the
get_azure_credentialfunction throughout the codebase. This change improves security and flexibility by ensuring that Azure service clients use the correct identity for authentication, especially in environments configured for RBAC. Additionally, environment variable handling and secret management are enhanced for better reliability and key vault usage.Authentication and Credential Management:
get_azure_credentialto passMANAGED_IDENTITY_CLIENT_IDfrom environment variables, ensuring proper managed identity authentication for Azure services [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18].MANAGED_IDENTITY_CLIENT_IDto theEnvHelperclass, loading it from environment variables for centralized access.Secret and Key Vault Handling:
FUNCTION_KEYwhen available, and added a check to ensureAZURE_KEY_VAULT_ENDPOINTis set when Key Vault is enabled [1] [2] [3].Configuration and Dependency Injection:
EnvHelperto use the managed identity client ID for acquiring tokens.EnvHelperintoPostgresConversationClientfor easier access to environment configuration [1] [2].Minor and Cosmetic Changes:
metadatasection inazure.yamlfor clarity or future use.These changes collectively strengthen the application's authentication mechanisms and improve maintainability by centralizing environment and credential management.
Does this introduce a breaking change?
How to Test
What to Check
Verify that the deployment and application end to end testing.