confcom: add kube-proxy fragment support for VN2 policies - #10414
Merged
Merged
Conversation
Add --include-kube-proxy for Linux VN2 policy generation, including input validation, documentation, configuration, and tests. Bump the confcom extension version to 2.3.0. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Collaborator
|
confcom |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Several user-facing descriptions omit the enforced Linux-only restriction.
Review effort: Balanced
Findings: 3
Open (3)
What changed in this PR
Adds optional kube-proxy image-attached fragment support for Linux VN2 policy generation.
Changes:
- Adds and validates
--allow-kubeproxy. - Defines the kube-proxy fragment and tests YAML/JSON generation.
- Updates documentation and bumps the extension to 2.3.0.
| File | Description |
|---|---|
src/confcom/setup.py |
Bumps version to 2.3.0. |
src/confcom/HISTORY.rst |
Records the new option. |
src/confcom/azext_confcom/tests/latest/test_confcom_acipolicygen_vn2.py |
Tests fragment inclusion and validation. |
src/confcom/azext_confcom/security_policy.py |
Allows mutation of empty fragment lists. |
src/confcom/azext_confcom/README.md |
Documents the option. |
src/confcom/azext_confcom/docs/acipolicygen.md |
Documents usage and Linux scope. |
src/confcom/azext_confcom/data/internal_config.json |
Defines kube-proxy fragment metadata. |
src/confcom/azext_confcom/custom.py |
Validates and adds the fragment. |
src/confcom/azext_confcom/config.py |
Exposes fragment configuration. |
src/confcom/azext_confcom/_params.py |
Registers the CLI argument. |
src/confcom/azext_confcom/_help.py |
Adds command help. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Clarified usage of --allow-kubeproxy for VN2 policy. Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Ethan Yang (necusjz)
approved these changes
Oct 2, 2026
Collaborator
|
[Release] Update index.json for extension [ confcom ] : https://dev.azure.com/msazure/One/_build/results?buildId=183817273&view=results |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Add --allow-kubeproxy for policy generation to include the image attached fragment for the kube-proxy sidecar.
e.g.
az confcom acipolicygen --virtual-node-yaml info.yaml --allow-kubeproxy --outraw-pretty-printprints policy includes:Bump the confcom extension version to 2.3.0.
Test
Generated a policy for the confidential-aci-dashboard VN2 payload and replaced the image-attached fragment feed with the feed for the dev kube-proxy image.
Confirmed that the kube-proxy container started with the replacement. Without the replacement (i.e. with the MCR feed) the container was rejected by the policy.
This checklist is used to make sure that common guidelines for a pull request are followed.
Related command
General Guidelines
azdev style <YOUR_EXT>locally? (pip install azdevrequired)python scripts/ci/test_index.py -qlocally? (pip install azdevrequired)For new extensions:
About Extension Publish
There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update
src/index.jsonautomatically.You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify
src/index.json.