Skip to content

confcom: add kube-proxy fragment support for VN2 policies - #10414

Merged
Ethan Yang (necusjz) merged 4 commits into
Azure:mainfrom
takuro-sato:kube-proxy-support
Oct 2, 2026
Merged

Ethan Yang (necusjz) merged 4 commits into
Azure:mainfrom
takuro-sato:kube-proxy-support

Conversation

@takuro-sato

@takuro-sato Takuro Sato (takuro-sato) commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Add --allow-kubeproxy for policy generation to include the image attached fragment for the kube-proxy sidecar.

e.g. az confcom acipolicygen --virtual-node-yaml info.yaml --allow-kubeproxy --outraw-pretty-print prints policy includes:

fragments := [
    { <infra fragment> },
    {
        "feed": "acidevacr.azurecr.io/internal/aci/sc-proxy",
        "includes": [
            "containers"
        ],
        "issuer": "did:x509:0:sha256:wVkSM46SDpw4LuyEYoH6r5ym07whL5lWxNlGN-UPtf4::eku:1.3.6.1.4.1.311.10.3.13",
        "minimum_svn": "1"
    }
]

Bump the confcom extension version to 2.3.0.

Test

Generated a policy for the  confidential-aci-dashboard VN2  payload and replaced the image-attached fragment feed with the feed for the dev kube-proxy image.
Confirmed that the kube-proxy container started with the replacement. Without the replacement (i.e. with the MCR feed) the container was rejected by the policy.


This checklist is used to make sure that common guidelines for a pull request are followed.

Related command

General Guidelines

  • Have you run azdev style <YOUR_EXT> locally? (pip install azdev required)
  • Have you run python scripts/ci/test_index.py -q locally? (pip install azdev required)
  • My extension version conforms to the Extension version schema

For new extensions:

About Extension Publish

There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update src/index.json automatically.
You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify src/index.json.

Add --include-kube-proxy for Linux VN2 policy generation, including input validation, documentation, configuration, and tests.

Bump the confcom extension version to 2.3.0.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@yonzhan

Copy link
Copy Markdown
Collaborator

confcom

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@takuro-sato
Takuro Sato (takuro-sato) marked this pull request as ready for review October 1, 2026 16:14
Copilot AI balanced review requested due to automatic review settings October 1, 2026 16:14

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several user-facing descriptions omit the enforced Linux-only restriction.

Review effort: Balanced
Findings: 3 Low severity

Open (3)
What changed in this PR

Adds optional kube-proxy image-attached fragment support for Linux VN2 policy generation.

Changes:

  • Adds and validates --allow-kubeproxy.
  • Defines the kube-proxy fragment and tests YAML/JSON generation.
  • Updates documentation and bumps the extension to 2.3.0.
File Description
src/​confcom/​setup.py Bumps version to 2.3.0.
src/​confcom/​HISTORY.rst Records the new option.
src/​confcom/​azext_confcom/​tests/​latest/​test_confcom_acipolicygen_vn2.py Tests fragment inclusion and validation.
src/​confcom/​azext_confcom/​security_policy.py Allows mutation of empty fragment lists.
src/​confcom/​azext_confcom/​README.md Documents the option.
src/​confcom/​azext_confcom/​docs/​acipolicygen.md Documents usage and Linux scope.
src/​confcom/​azext_confcom/​data/​internal_config.json Defines kube-proxy fragment metadata.
src/​confcom/​azext_confcom/​custom.py Validates and adds the fragment.
src/​confcom/​azext_confcom/​config.py Exposes fragment configuration.
src/​confcom/​azext_confcom/​_params.py Registers the CLI argument.
src/​confcom/​azext_confcom/​_help.py Adds command help.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/confcom/azext_confcom/README.md Outdated
Comment thread src/confcom/azext_confcom/_help.py Outdated
Comment thread src/confcom/azext_confcom/_params.py Outdated
Clarified usage of --allow-kubeproxy for VN2 policy.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@necusjz
Ethan Yang (necusjz) merged commit 9db8b0c into Azure:main Oct 2, 2026
24 checks passed
@azclibot

Copy link
Copy Markdown
Collaborator

[Release] Update index.json for extension [ confcom ] : https://dev.azure.com/msazure/One/_build/results?buildId=183817273&view=results

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants