Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[AKS] Add a new command to check outbound network from nodes az aks check-network outbound #7280

Merged
merged 36 commits into from
Apr 2, 2024

Conversation

alyssa1303
Copy link
Contributor

@alyssa1303 alyssa1303 commented Feb 9, 2024


This checklist is used to make sure that common guidelines for a pull request are followed.

Related command

az aks check-network outbound

General Guidelines

  • Have you run azdev style <YOUR_EXT> locally? (pip install azdev required)
  • Have you run python scripts/ci/test_index.py -q locally? (pip install wheel==0.30.0 required)
  • My extension version conforms to the Extension version schema

For new extensions:

About Extension Publish

There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update src/index.json automatically.
You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify src/index.json.

Copy link

azure-client-tools-bot-prd bot commented Feb 9, 2024

⚠️Azure CLI Extensions Breaking Change Test
⚠️aks-preview
rule cmd_name rule_message suggest_message
⚠️ 1011 - SubgroupAdd aks check-network sub group aks check-network added

Copy link

Hi @alyssa1303,
Please write the description of changes which can be perceived by customers into HISTORY.rst.
If you want to release a new extension version, please update the version in setup.py as well.

@yonzhan
Copy link
Collaborator

yonzhan commented Feb 9, 2024

AKS

@alyssa1303
Copy link
Contributor Author

Please add some unit test cases (see examples in test_helpers.py) and at least one live test case (see examples in test_aks_commands.py) for the newly added command.

I've finished adding unit test and live test. All CI passes except for the Cred run which I believe need help from CI team

@zhoxing-ms
Copy link
Contributor

@yanzhudd Could you please help review this PR?

src/aks-preview/HISTORY.rst Outdated Show resolved Hide resolved
src/aks-preview/azext_aks_preview/custom.py Outdated Show resolved Hide resolved
src/aks-preview/azext_aks_preview/custom.py Outdated Show resolved Hide resolved
src/aks-preview/azext_aks_preview/custom.py Outdated Show resolved Hide resolved
src/aks-preview/azext_aks_preview/custom.py Outdated Show resolved Hide resolved
src/aks-preview/azext_aks_preview/custom.py Show resolved Hide resolved
src/aks-preview/azext_aks_preview/custom.py Show resolved Hide resolved
@FumingZhang
Copy link
Member

Please also resolve the merge conflicts.

Copy link

gitguardian bot commented Feb 29, 2024

⚠️ GitGuardian has uncovered 61 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_get_customdomainverificationid_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_get_customdomainverificationid_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_storage.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_identity_system.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_identity_system.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_mtls.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_create_with_vnet_yaml.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_create_with_vnet_yaml.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_certificate_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_update_custom_domains.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_update_custom_domains.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_custom_domains_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_secret_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_secret_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_custom_domains_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_custom_domains_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_usages.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_custom_domains.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_update_custom_domains.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_custom_domains.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_custom_domains.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_custom_domains.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_secret_update_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_secret_update_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_la_dynamic_json.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_create_with_vnet_yaml.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_azurefile_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_certificate_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_certificate_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_secret_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_logs_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_logs_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_logs_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_dapr_components.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_secret_update_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_dapr_components.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_dapr_components.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_nfsazurefile_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_nfsazurefile_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_storage.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_storage.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_azurefile_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_azurefile_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_container_app_mount_nfsazurefile_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_get_customdomainverificationid_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_internal_only_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_usages.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_usages.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_identity_system.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_la_dynamic_json.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_la_dynamic_json.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_la_dynamic_json.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_la_dynamic_json.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_logs_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_mtls.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_mtls.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_internal_only_e2e.yaml View secret
- Microsoft Azure Storage Account Key 650a869 src/containerapp/azext_containerapp/tests/latest/recordings/test_containerapp_env_internal_only_e2e.yaml View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Our GitHub checks need improvements? Share your feedbacks!

@alyssa1303
Copy link
Contributor Author

⚠️ GitGuardian has uncovered 61 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secrets in your pull request
🛠 Guidelines to remediate hardcoded secrets
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.Our GitHub checks need improvements? Share your feedbacks!

Can someone help me look into this problem? Seem like a serious one but I'm pretty sure it's not from my change but something from the main branch after I got the latest change @zhoxing-ms @yanzhudd @FumingZhang

@FumingZhang
Copy link
Member

/azp run

Copy link

Azure Pipelines successfully started running 2 pipeline(s).

@FumingZhang
Copy link
Member

/azp run

Copy link

Azure Pipelines successfully started running 2 pipeline(s).

Copy link

github-actions bot commented Mar 15, 2024

⚠️ Suggestions

Module: aks-preview

  • Update version to 2.0.0b8 in setup.py
  • Set azext.isPreview to true in azext_aks-preview/azext_metadata.json if not exists

Notes

  • Stable/preview tag is inherited from last release. If needed, please add stable/preview label to modify it.
  • Major/minor/patch/pre increment of version number is calculated by pull request code changes automatically. If needed, please add major/minor/patch/pre label to adjust it.
  • For more info about extension versioning, please refer to Extension version schema

@FumingZhang
Copy link
Member

Default API version has been updated to 2024-02-02-preview, the recording file of test_aks_check_network is outdated so the CI failed. Requeued live test.

Copy link
Member

@FumingZhang FumingZhang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@FumingZhang
Copy link
Member

Requeued another live test including recent changes. Test passed!

@yanzhudd yanzhudd merged commit 0c6adfd into Azure:main Apr 2, 2024
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

7 participants