-
Notifications
You must be signed in to change notification settings - Fork 5.5k
Update description for RBAC flag in Key Vault #15161
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Hi, @jlichwa Thanks for your PR. I am workflow bot for review process. Here are some small tips. Any feedback about review process or workflow bot, pls contact swagger and tools team. [email protected] |
[Call for Action] To better understand Azure service dev/test scenario, and support Azure service developer better on Swagger and REST API related tests in early phase, please help to fill in with this survey https://aka.ms/SurveyForEarlyPhase. It will take 5 to 10 minutes. If you already complete survey, please neglect this comment. Thanks. |
Swagger Validation Report
|
Rule | Message |
---|---|
R4010 - RequiredDefaultResponse |
The response is defined but without a default error response implementation.Consider adding it.' Location: Microsoft.KeyVault/preview/2020-04-01-preview/secrets.json#L268 |
R4013 - IntegerTypeMustHaveFormat |
The integer type does not have a format, please add it. Location: Microsoft.KeyVault/preview/2020-04-01-preview/secrets.json#L300 |
R4013 - IntegerTypeMustHaveFormat |
The integer type does not have a format, please add it. Location: Microsoft.KeyVault/preview/2020-04-01-preview/secrets.json#L306 |
R4013 - IntegerTypeMustHaveFormat |
The integer type does not have a format, please add it. Location: Microsoft.KeyVault/preview/2020-04-01-preview/secrets.json#L312 |
R4013 - IntegerTypeMustHaveFormat |
The integer type does not have a format, please add it. Location: Microsoft.KeyVault/preview/2020-04-01-preview/secrets.json#L318 |
R4036 - ImplementPrivateEndpointAPIs |
The private endpoint API: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.KeyVault/vaults/{vaultName}/privateEndpointConnections is missing. Location: Microsoft.KeyVault/preview/2020-04-01-preview/managedHsm.json#L36 |
R4036 - ImplementPrivateEndpointAPIs |
The private endpoint API: /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.KeyVault/vaults/{vaultName}/privateEndpointConnections is missing. Location: Microsoft.KeyVault/preview/2020-04-01-preview/managedHsm.json#L36 |
R4037 - MissingTypeObject |
The schema 'CloudError' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/common.json#L10 |
R4037 - MissingTypeObject |
The schema 'CloudErrorBody' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/common.json#L19 |
R4037 - MissingTypeObject |
The schema 'SystemData' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/common.json#L33 |
R4037 - MissingTypeObject |
The schema 'Sku' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1035 |
R4037 - MissingTypeObject |
The schema 'AccessPolicyEntry' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1068 |
R4037 - MissingTypeObject |
The schema 'Permissions' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1096 |
R4037 - MissingTypeObject |
The schema 'VaultProperties' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1208 |
R4037 - MissingTypeObject |
The schema 'VaultPatchProperties' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1314 |
R4037 - MissingTypeObject |
The schema 'VaultAccessPolicyProperties' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1380 |
R4037 - MissingTypeObject |
The schema 'DeletedVaultProperties' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1395 |
R4037 - MissingTypeObject |
The schema 'VaultCreateOrUpdateParameters' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1435 |
R4037 - MissingTypeObject |
The schema 'VaultPatchParameters' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1460 |
R4037 - MissingTypeObject |
The schema 'VaultAccessPolicyParameters' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1477 |
R4037 - MissingTypeObject |
The schema 'Vault' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1510 |
R4037 - MissingTypeObject |
The schema 'DeletedVault' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1553 |
R4037 - MissingTypeObject |
The schema 'VaultListResult' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1577 |
R4037 - MissingTypeObject |
The schema 'DeletedVaultListResult' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1593 |
R4037 - MissingTypeObject |
The schema 'ResourceListResult' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1609 |
R4037 - MissingTypeObject |
The schema 'Resource' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1625 |
R4037 - MissingTypeObject |
The schema 'VaultCheckNameAvailabilityParameters' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1659 |
R4037 - MissingTypeObject |
The schema 'CheckNameAvailabilityResult' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1683 |
R4037 - MissingTypeObject |
The schema 'NetworkRuleSet' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1711 |
R4037 - MissingTypeObject |
The schema 'IPRule' is considered an object but without a 'type:object', please add the missing 'type:object'. Location: Microsoft.KeyVault/preview/2021-04-01-preview/keyvault.json#L1754 |
️️✔️
Avocado succeeded [Detail] [Expand]
Validation passes for Avocado.
️️✔️
ModelValidation succeeded [Detail] [Expand]
Validation passes for ModelValidation.
️️✔️
SemanticValidation succeeded [Detail] [Expand]
Validation passes for SemanticValidation.
️️✔️
Cross-Version Breaking Changes succeeded [Detail] [Expand]
There are no breaking changes.
️️✔️
CredScan succeeded [Detail] [Expand]
There is no credential detected.
️️✔️
[Staging] SDK Track2 Validation succeeded [Detail] [Expand]
Validation passes for SDKTrack2Validation
- The following tags are being changed in this PR
- keyvault/resource-manager/readme.md#package-preview-2021-04
- keyvault/resource-manager/readme.md#package-preview-2021-04-full
- keyvault/resource-manager/readme.md#package-preview-2020-04
- keyvault/resource-manager/readme.md#package-preview-2020-04-full
- keyvault/resource-manager/readme.md#package-2019-09
- keyvault/resource-manager/readme.md#profile-hybrid-2020-09-01
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-preview-2021-04",
"details":"> Installing AutoRest extension '@microsoft.azure/openapi-validator' (1.8.0)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-preview-2021-04",
"details":"> Installed AutoRest extension '@microsoft.azure/openapi-validator' (1.8.0->1.8.0)"|
The following errors/warnings exist before current PR submission:
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-preview-2021-04",
"details":"> Loading AutoRest extension '@autorest/modelerfour' (4.15.456->4.15.456)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-preview-2021-04-full",
"details":"> Loading AutoRest extension '@microsoft.azure/openapi-validator' (1.8.0->1.8.0)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-preview-2021-04-full",
"details":"> Loading AutoRest extension '@autorest/modelerfour' (4.15.456->4.15.456)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-preview-2020-04",
"details":"> Loading AutoRest extension '@microsoft.azure/openapi-validator' (1.8.0->1.8.0)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-preview-2020-04",
"details":"> Loading AutoRest extension '@autorest/modelerfour' (4.15.456->4.15.456)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-preview-2020-04-full",
"details":"> Loading AutoRest extension '@microsoft.azure/openapi-validator' (1.8.0->1.8.0)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-preview-2020-04-full",
"details":"> Loading AutoRest extension '@autorest/modelerfour' (4.15.456->4.15.456)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-2019-09",
"details":"> Loading AutoRest extension '@microsoft.azure/openapi-validator' (1.8.0->1.8.0)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"package-2019-09",
"details":"> Loading AutoRest extension '@autorest/modelerfour' (4.15.456->4.15.456)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"profile-hybrid-2020-09-01",
"details":"> Loading AutoRest extension '@microsoft.azure/openapi-validator' (1.8.0->1.8.0)"|
|:speech_balloon: AutorestCore/Exception|"readme":"keyvault/resource-manager/readme.md",
"tag":"profile-hybrid-2020-09-01",
"details":"> Loading AutoRest extension '@autorest/modelerfour' (4.15.456->4.15.456)"|
️️✔️
[Staging] PrettierCheck succeeded [Detail] [Expand]
Validation passes for PrettierCheck.
️️✔️
[Staging] SpellCheck succeeded [Detail] [Expand]
Validation passes for SpellCheck.
️️✔️
[Staging] Lint(RPaaS) succeeded [Detail] [Expand]
Validation passes for Lint(RPaaS).
Swagger Generation Artifacts
|
#sign-off |
@@ -1260,7 +1260,7 @@ | |||
"enableRbacAuthorization": { | |||
"type": "boolean", | |||
"default": false, | |||
"description": "Property that controls how data actions are authorized. When true, the key vault will use Role Based Access Control (RBAC) for authorization of data actions, and the access policies specified in vault properties will be ignored (warning: this is a preview feature). When false, the key vault will use the access policies specified in vault properties, and any policy stored on Azure Resource Manager will be ignored. If null or not specified, the vault is created with the default value of false. Note that management actions are always authorized with RBAC." | |||
"description": "Property that controls how data actions are authorized. When true, the key vault will use Role Based Access Control (RBAC) for authorization of data actions, and the access policies specified in vault properties will be ignored. When false, the key vault will use the access policies specified in vault properties, and any policy stored on Azure Resource Manager will be ignored. If null or not specified, the vault is created with the default value of false. Note that management actions are always authorized with RBAC." |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
First two change happens in preview version swagger, why do we also remove preview declaration in the description.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@raych1 Feature GA-ed , any swagger going forward has that feature completed. Upcoming preview versions are created for new features, with other features in preview.... Is that make sense?
MSFT employees can try out our new experience at OpenAPI Hub - one location for using our validation tools and finding your workflow.
Changelog
Please ensure to add changelog with this PR by answering the following questions.
Contribution checklist:
If any further question about AME onboarding or validation tools, please view the FAQ.
ARM API Review Checklist
Ensure to check this box if one of the following scenarios meet updates in the PR, so that label “WaitForARMFeedback” will be added automatically to involve ARM API Review. Failure to comply may result in delays for manifest application. Note this does not apply to data plane APIs, all “removals” and “adding a new property” no more require ARM API review.
Please ensure you've reviewed following guidelines including ARM resource provider contract and REST guidelines. Estimated time (4 hours). This is required before you can request review from ARM API Review board.
If you are blocked on ARM review and want to get the PR merged with urgency, please get the ARM oncall for reviews (RP Manifest Approvers team under Azure Resource Manager service) from IcM and reach out to them.
Breaking Change Review Checklist
If there are following updates in the PR, ensure to request an approval from Breaking Change Review Board as defined in the Breaking Change Policy.
Action: to initiate an evaluation of the breaking change, create a new intake using the template for breaking changes. Addition details on the process and office hours are on the Breaking change Wiki.
Please follow the link to find more details on PR review process.