Skip to content

[App Service] az webapp create: Add --site-scoped-certs parameter to support enabling or disabling site-scoped certificates#33306

Open
danielw5 wants to merge 5 commits into
Azure:devfrom
danielw5:dev
Open

[App Service] az webapp create: Add --site-scoped-certs parameter to support enabling or disabling site-scoped certificates#33306
danielw5 wants to merge 5 commits into
Azure:devfrom
danielw5:dev

Conversation

@danielw5
Copy link
Copy Markdown
Member

@danielw5 danielw5 commented May 1, 2026

Related command

Description

Testing Guide

History Notes

[Component Name 1] BREAKING CHANGE: az command a: Make some customer-facing breaking change
[Component Name 2] az command b: Add some customer-facing feature


This checklist is used to make sure that common guidelines for a pull request are followed.

Copilot AI review requested due to automatic review settings May 1, 2026 01:11
@azure-client-tools-bot-prd
Copy link
Copy Markdown

azure-client-tools-bot-prd Bot commented May 1, 2026

️✔️AzureCLI-FullTest
️✔️acr
️✔️latest
️✔️3.12
️✔️3.13
️✔️acs
️✔️latest
️✔️3.12
️✔️3.13
️✔️advisor
️✔️latest
️✔️3.12
️✔️3.13
️✔️ams
️✔️latest
️✔️3.12
️✔️3.13
️✔️apim
️✔️latest
️✔️3.12
️✔️3.13
️✔️appconfig
️✔️latest
️✔️3.12
️✔️3.13
️✔️appservice
️✔️latest
️✔️3.12
️✔️3.13
️✔️aro
️✔️latest
️✔️3.12
️✔️3.13
️✔️backup
️✔️latest
️✔️3.12
️✔️3.13
️✔️batch
️✔️latest
️✔️3.12
️✔️3.13
️✔️batchai
️✔️latest
️✔️3.12
️✔️3.13
️✔️billing
️✔️latest
️✔️3.12
️✔️3.13
️✔️botservice
️✔️latest
️✔️3.12
️✔️3.13
️✔️cdn
️✔️latest
️✔️3.12
️✔️3.13
️✔️cloud
️✔️latest
️✔️3.12
️✔️3.13
️✔️cognitiveservices
️✔️latest
️✔️3.12
️✔️3.13
️✔️compute_recommender
️✔️latest
️✔️3.12
️✔️3.13
️✔️computefleet
️✔️latest
️✔️3.12
️✔️3.13
️✔️config
️✔️latest
️✔️3.12
️✔️3.13
️✔️configure
️✔️latest
️✔️3.12
️✔️3.13
️✔️consumption
️✔️latest
️✔️3.12
️✔️3.13
️✔️container
️✔️latest
️✔️3.12
️✔️3.13
️✔️containerapp
️✔️latest
️✔️3.12
️✔️3.13
️✔️core
️✔️latest
️✔️3.12
️✔️3.13
️✔️cosmosdb
️✔️latest
️✔️3.12
️✔️3.13
️✔️databoxedge
️✔️latest
️✔️3.12
️✔️3.13
️✔️dls
️✔️latest
️✔️3.12
️✔️3.13
️✔️dms
️✔️latest
️✔️3.12
️✔️3.13
️✔️eventgrid
️✔️latest
️✔️3.12
️✔️3.13
️✔️eventhubs
️✔️latest
️✔️3.12
️✔️3.13
️✔️feedback
️✔️latest
️✔️3.12
️✔️3.13
️✔️find
️✔️latest
️✔️3.12
️✔️3.13
️✔️hdinsight
️✔️latest
️✔️3.12
️✔️3.13
️✔️identity
️✔️latest
️✔️3.12
️✔️3.13
️✔️iot
️✔️latest
️✔️3.12
️✔️3.13
️✔️keyvault
️✔️latest
️✔️3.12
️✔️3.13
️✔️lab
️✔️latest
️✔️3.12
️✔️3.13
️✔️managedservices
️✔️latest
️✔️3.12
️✔️3.13
️✔️maps
️✔️latest
️✔️3.12
️✔️3.13
️✔️marketplaceordering
️✔️latest
️✔️3.12
️✔️3.13
️✔️monitor
️✔️latest
️✔️3.12
️✔️3.13
️✔️mysql
️✔️latest
️✔️3.12
️✔️3.13
️✔️netappfiles
️✔️latest
️✔️3.12
️✔️3.13
️✔️network
️✔️latest
️✔️3.12
️✔️3.13
️✔️policyinsights
️✔️latest
️✔️3.12
️✔️3.13
️✔️postgresql
️✔️latest
️✔️3.12
️✔️3.13
️✔️privatedns
️✔️latest
️✔️3.12
️✔️3.13
️✔️profile
️✔️latest
️✔️3.12
️✔️3.13
️✔️rdbms
️✔️latest
️✔️3.12
️✔️3.13
️✔️redis
️✔️latest
️✔️3.12
️✔️3.13
️✔️relay
️✔️latest
️✔️3.12
️✔️3.13
️✔️resource
️✔️latest
️✔️3.12
️✔️3.13
️✔️role
️✔️latest
️✔️3.12
️✔️3.13
️✔️search
️✔️latest
️✔️3.12
️✔️3.13
️✔️security
️✔️latest
️✔️3.12
️✔️3.13
️✔️servicebus
️✔️latest
️✔️3.12
️✔️3.13
️✔️serviceconnector
️✔️latest
️✔️3.12
️✔️3.13
️✔️servicefabric
️✔️latest
️✔️3.12
️✔️3.13
️✔️signalr
️✔️latest
️✔️3.12
️✔️3.13
️✔️sql
️✔️latest
️✔️3.12
️✔️3.13
️✔️sqlvm
️✔️latest
️✔️3.12
️✔️3.13
️✔️storage
️✔️latest
️✔️3.12
️✔️3.13
️✔️synapse
️✔️latest
️✔️3.12
️✔️3.13
️✔️telemetry
️✔️latest
️✔️3.12
️✔️3.13
️✔️util
️✔️latest
️✔️3.12
️✔️3.13
️✔️vm
️✔️latest
️✔️3.12
️✔️3.13

@azure-client-tools-bot-prd
Copy link
Copy Markdown

azure-client-tools-bot-prd Bot commented May 1, 2026

❌AzureCLI-BreakingChangeTest
⚠️appservice
rule cmd_name rule_message suggest_message
⚠️ 1006 - ParaAdd webapp create cmd webapp create added parameter site_scoped_certs
⚠️ 1006 - ParaAdd webapp update cmd webapp update added parameter site_scoped_certs
❌network
rule cmd_name rule_message suggest_message
1007 - ParaRemove network virtual-network-appliance create cmd network virtual-network-appliance create removed parameter private_ip_address_version please add back parameter private_ip_address_version for cmd network virtual-network-appliance create
1010 - ParaPropUpdate network virtual-network-appliance create cmd network virtual-network-appliance create update parameter bandwidth_in_gbps: updated property options from ['--bandwidth-gbps', '--bandwidth-in-gbps'] to ['--bandwidth-in-gbps'] please change property options from ['--bandwidth-in-gbps'] to ['--bandwidth-gbps', '--bandwidth-in-gbps'] for parameter bandwidth_in_gbps of cmd network virtual-network-appliance create
1007 - ParaRemove network virtual-network-appliance update cmd network virtual-network-appliance update removed parameter private_ip_address_version please add back parameter private_ip_address_version for cmd network virtual-network-appliance update
1010 - ParaPropUpdate network virtual-network-appliance update cmd network virtual-network-appliance update update parameter bandwidth_in_gbps: updated property options from ['--bandwidth-gbps', '--bandwidth-in-gbps'] to ['--bandwidth-in-gbps'] please change property options from ['--bandwidth-in-gbps'] to ['--bandwidth-gbps', '--bandwidth-in-gbps'] for parameter bandwidth_in_gbps of cmd network virtual-network-appliance update
⚠️ 1010 - ParaPropUpdate network virtual-network-appliance create cmd network virtual-network-appliance create update parameter bandwidth_in_gbps: updated property aaz_type from float to int
⚠️ 1010 - ParaPropUpdate network virtual-network-appliance create cmd network virtual-network-appliance create update parameter bandwidth_in_gbps: updated property type from float to int
⚠️ 1009 - ParaPropRemove network virtual-network-appliance list cmd network virtual-network-appliance list update parameter resource_group: removed property required=True
⚠️ 1010 - ParaPropUpdate network virtual-network-appliance update cmd network virtual-network-appliance update update parameter bandwidth_in_gbps: updated property aaz_type from float to int
⚠️ 1010 - ParaPropUpdate network virtual-network-appliance update cmd network virtual-network-appliance update update parameter bandwidth_in_gbps: updated property type from float to int

Please submit your Breaking Change Pre-announcement ASAP if you haven't already. Please note:

  • Breaking changes can only be merged during the designated breaking change window
  • A pre-announcement must be released at least one month in advance

For more details on how to introduce breaking changes, refer to the documentation: azure-cli/doc/how_to_introduce_breaking_changes.md

@yonzhan
Copy link
Copy Markdown
Collaborator

yonzhan commented May 1, 2026

Thank you for your contribution! We will review the pull request and get back to you soon.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 1, 2026

The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR.

Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions).
After that please run the following commands to enable git hooks:

pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds support in the App Service command module for configuring the App Service SiteScopedCertificatesEnabled setting via Azure CLI, exposed on az webapp create and az webapp update.

Changes:

  • Adds --site-scoped-certificates-enabled parameter to webapp create and webapp update argument contexts.
  • Wires the parameter through create_webapp (Site payload construction) and update_webapp (generic update mutation) to set site_scoped_certificates_enabled.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.

File Description
src/azure-cli/azure/cli/command_modules/appservice/custom.py Adds the new function parameter and maps it into the Site model for create/update flows.
src/azure-cli/azure/cli/command_modules/appservice/_params.py Exposes --site-scoped-certificates-enabled on webapp create and webapp update.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/azure-cli/azure/cli/command_modules/appservice/_params.py Outdated
Comment on lines +260 to +264
https_only=https_only, virtual_network_subnet_id=subnet_resource_id,
public_network_access=public_network_access, outbound_vnet_routing=outbound_vnet_routing,
auto_generated_domain_name_label_scope=auto_generated_domain_name_label_scope,
end_to_end_encryption_enabled=end_to_end_encryption_enabled)
end_to_end_encryption_enabled=end_to_end_encryption_enabled,
site_scoped_certificates_enabled=site_scoped_certificates_enabled)
Copy link

Copilot AI May 1, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

site_scoped_certificates_enabled (and currently end_to_end_encryption_enabled) come from get_three_state_flag(return_label=True), which returns the strings 'true'/'false'. Passing these strings directly into the Site(...) model will serialize as JSON strings (or potentially raise if the model validates types) rather than booleans. Convert these values to booleans (e.g., val == 'true') before constructing Site, keeping None as-is, to match the behavior already used in update_webapp.

Copilot uses AI. Check for mistakes.
Comment thread src/azure-cli/azure/cli/command_modules/appservice/custom.py Outdated
Comment thread src/azure-cli/azure/cli/command_modules/appservice/_params.py Outdated
@yanzhudd
Copy link
Copy Markdown
Contributor

yanzhudd commented May 5, 2026

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 3 pipeline(s).

@yanzhudd
Copy link
Copy Markdown
Contributor

yanzhudd commented May 6, 2026

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 3 pipeline(s).

@yanzhudd
Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 3 pipeline(s).

@yanzhudd yanzhudd changed the title [App Service] Add SiteScopedCertificatesEnabled property [App Service] az webapp create: Add --site-scoped-certs parameter to support enabling or disabling site-scoped certificates May 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants