Skip to content

Conversation

amih90
Copy link
Contributor

@amih90 amih90 commented Oct 5, 2025

ARM (Control Plane) API Specification Update Pull Request

Tip

Overwhelmed by all this guidance? See the Getting help section at the bottom of this PR description.

PR review workflow diagram

Please understand this diagram before proceeding. It explains how to get your PR approved & merged.

spec_pr_review_workflow_diagram

Purpose of this PR

What's the purpose of this PR? Check the specific option that applies. This is mandatory!

  • New resource provider.
  • New API version for an existing resource provider. (If API spec is not defined in TypeSpec, the PR should have been created in adherence to OpenAPI specs PR creation guidance).
  • Update existing version for a new feature. (This is applicable only when you are revising a private preview API version.)
  • Update existing version to fix OpenAPI spec quality issues in S360.
  • Convert existing OpenAPI spec to TypeSpec spec (do not combine this with implementing changes for a new API version).
  • [] Other, please clarify:
    • edit this with your clarification

Due diligence checklist

To merge this PR, you must go through the following checklist and confirm you understood
and followed the instructions by checking all the boxes:

  • I confirm this PR is modifying Azure Resource Manager (ARM) related specifications, and not data plane related specifications.
  • I have reviewed following Resource Provider guidelines, including
    ARM resource provider contract and
    REST guidelines (estimated time: 4 hours).
    I understand this is required before I can proceed to the diagram Step 2, "ARM API changes review", for this PR.
  • A release plan has been created. If not, please create one as it will help guide you through the REST API and SDK creation process.

Additional information

Viewing API changes

For convenient view of the API changes made by this PR, refer to the URLs provided in the table
in the Generated ApiView comment added to this PR. You can use ApiView to show API versions diff.

Suppressing failures

If one or multiple validation error/warning suppression(s) is detected in your PR, please follow the
suppressions guide to get approval.

Getting help

  • First, please carefully read through this PR description, from top to bottom. Please fill out the Purpose of this PR and Due diligence checklist.
  • If you don't have permissions to remove or add labels to the PR, request write access per aka.ms/azsdk/access#request-access-to-rest-api-or-sdk-repositories
  • To understand what you must do next to merge this PR, see the Next Steps to Merge comment. It will appear within few minutes of submitting this PR and will continue to be up-to-date with current PR state.
  • For guidance on fixing this PR CI check failures, see the hyperlinks provided in given failure
    and https://aka.ms/ci-fix.
  • For help with ARM review (PR workflow diagram Step 2), see https://aka.ms/azsdk/pr-arm-review.
  • If the PR CI checks appear to be stuck in queued state, please add a comment with contents /azp run.
    This should result in a new comment denoting a PR validation pipeline has started and the checks should be updated after few minutes.
  • If the help provided by the previous points is not enough, post to https://aka.ms/azsdk/support/specreview-channel and link to this PR.
  • For guidance on SDK breaking change review, refer to https://aka.ms/ci-fix.

Copy link

github-actions bot commented Oct 5, 2025

Next Steps to Merge

Next steps that must be taken to merge this PR:
  • ❌ This PR is in purview of the ARM review (label: ARMReview). This PR must get ARMSignedOff label from an ARM reviewer.
    This PR is awaiting ARM reviewer feedback (label: WaitForARMFeedback).
    To learn when this PR will get reviewed, see ARM review queue at aka.ms/azsdk/pr-arm-review
    For details of the ARM review, see aka.ms/azsdk/pr-arm-review


Comment generated by summarize-checks workflow run.

@github-actions github-actions bot added brownfield Brownfield services will soon be required to convert to TypeSpec. See https://aka.ms/azsdk/typespec. ARMReview new-api-version resource-manager WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Oct 5, 2025
Copy link

github-actions bot commented Oct 5, 2025

API Change Check

APIView identified API level changes in this PR and created the following API reviews

Language API Review for Package
Swagger common
Go sdk/resourcemanager/security/armsecurity
Java com.azure.resourcemanager:azure-resourcemanager-security
JavaScript @azure/arm-security

"200": {
"description": "Successfully retrieved the operation result."
},
"202": {
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When reading the operation resource entity, the status code should always be 200. The response payload indicates if the async operation is still running or has completed (successfully or with a failure).

See here:
https://github.com/cloud-and-ai-microsoft/resource-provider-contract/blob/master/v1.0/async-api-reference.md#asynchronous-operations

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please check the table at https://github.com/cloud-and-ai-microsoft/resource-provider-contract/blob/master/v1.0/async-api-reference.md#example-flow
operation results has 202 and Location, RetryAfter support. tried to map it again and updated the PR accordingly

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is about the 200 status code

@amih90 amih90 added the PublishToCustomers Acknowledgement the changes will be published to Azure customers. label Oct 6, 2025
@mentat9
Copy link
Member

mentat9 commented Oct 6, 2025

@amih90 - Your PR is not ready for ARM review. Please fill out the onboarding form so reviewers have context for the review. Also, if this PR is for a new API version, you need to start with a base commit made by copying the existing files unchanged to the new API version folder. Then apply changes for the new API version in subsequent commits.

@github-actions github-actions bot removed the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Oct 6, 2025
@amih90 amih90 force-pushed the ami/35421676-microsoft.security-public-api branch from cdf261c to 4f3d4fe Compare October 6, 2025 19:42
@amih90 amih90 force-pushed the ami/35421676-microsoft.security-public-api branch from 4f3d4fe to 6384cca Compare October 6, 2025 19:53
@amih90 amih90 force-pushed the ami/35421676-microsoft.security-public-api branch from 6384cca to bd3e603 Compare October 6, 2025 19:56
@github-actions github-actions bot added the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Oct 6, 2025
@mentat9
Copy link
Member

mentat9 commented Oct 7, 2025

@amih90 - Please ensure your PR passes Swagger LintDiff and Avocado checks.

@github-actions github-actions bot removed the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Oct 7, 2025
@amih90
Copy link
Contributor Author

amih90 commented Oct 7, 2025

@amih90 - Please ensure your PR passes Swagger LintDiff and Avocado checks.

@mentat9

  • Avodaco: I will ask and exception for Avocado as Microsoft.Security RP has not yet migrated to a single api-versions at the moment. I am not sure I can do anything with it in this specific scope.
  • LintDiff: by https://github.com/Azure/azure-resource-manager-rpc/blob/master/v1.0/async-api-reference.md it clearly state that i should support also 204 status code. Can you suggest if I should follow the spec or remove 204 from the API to fix the validation?

@github-actions github-actions bot added the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Oct 9, 2025
@mentat9
Copy link
Member

mentat9 commented Oct 9, 2025

@amih90 - Please ensure your PR passes Swagger LintDiff and Avocado checks.

@mentat9

  • Avodaco: I will ask and exception for Avocado as Microsoft.Security RP has not yet migrated to a single api-versions at the moment. I am not sure I can do anything with it in this specific scope.
  • LintDiff: by https://github.com/Azure/azure-resource-manager-rpc/blob/master/v1.0/async-api-reference.md it clearly state that i should support also 204 status code. Can you suggest if I should follow the spec or remove 204 from the API to fix the validation?
  • Avocado - When does your team plan to move to uniform versioning? I've added the approval label but note that some SDKs depend on it, so you may have issues generating SDKs.
  • LintDiff - Add a suppression for false positive: https://aka.ms/azsdk/pr-suppressions.

@github-actions github-actions bot removed the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Oct 9, 2025
@amih90
Copy link
Contributor Author

amih90 commented Oct 12, 2025

@amih90 - Please ensure your PR passes Swagger LintDiff and Avocado checks.

@mentat9

  • Avodaco: I will ask and exception for Avocado as Microsoft.Security RP has not yet migrated to a single api-versions at the moment. I am not sure I can do anything with it in this specific scope.
  • LintDiff: by https://github.com/Azure/azure-resource-manager-rpc/blob/master/v1.0/async-api-reference.md it clearly state that i should support also 204 status code. Can you suggest if I should follow the spec or remove 204 from the API to fix the validation?
  • Avocado - When does your team plan to move to uniform versioning? I've added the approval label but note that some SDKs depend on it, so you may have issues generating SDKs.
  • LintDiff - Add a suppression for false positive: https://aka.ms/azsdk/pr-suppressions.
  • Avocado: It's in our plans. @eliagrady can you provide an ETA?
  • LintDiff: Added a surpression request, I hope it's align to the requirement.

@github-actions github-actions bot added the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Oct 12, 2025
}
},
"paths": {
"/providers/Microsoft.Security/operations": {
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is this a tenant level API?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PAS Approval and questions about authorization needs to be discussed.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The operations.json is an existing api and out of scope for this PR, it was added to address first comment by @mentat9 "if this PR is for a new API version, you need to start with a base commit made by copying the existing files unchanged to the new API version folder."

@psah434 psah434 added Approved-LintDiff ARMChangesRequested and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Oct 13, 2025
@amih90
Copy link
Contributor Author

amih90 commented Oct 15, 2025

Not sure which changes are required.

@github-actions github-actions bot added the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Oct 15, 2025
Copy link
Member

@eliagrady eliagrady left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

reviewed

@amih90 amih90 enabled auto-merge (squash) October 15, 2025 14:17
@psah434 psah434 added ARMChangesRequested and removed WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required labels Oct 15, 2025
@github-actions github-actions bot added the WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required label Oct 16, 2025
@eliagrady
Copy link
Member

@mentat9 - if the first commit (base commit) only does a partial copy (since we're still not using a unified API version) - will it help? as we understand what a base commit for a new api version should look like, but we cannot make it include all of our RP's resource types.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Approved-Avocado Approved-LintDiff ARMReview brownfield Brownfield services will soon be required to convert to TypeSpec. See https://aka.ms/azsdk/typespec. new-api-version PublishToCustomers Acknowledgement the changes will be published to Azure customers. resource-manager SuppressionReviewRequired WaitForARMFeedback <valid label in PR review process> add this label when ARM review is required

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants