Repository navigation
feat: support GA and preview runtimes - #948
Conversation
Azure SRE Agent - automated reviewReviewing Scope note. 56 files / +6735. I read the new runtime subsystem ( Blocking1. Gating the OPC UA feature backfill on runtime readiness is clearly right. Gating a tags/description write on it is a behaviour regression. Suggest deferring 2. Same call path adds new RBAC requirements to Suggestions3. 4. Upgrade preflight list failures changed from tolerant to fatal, reversing a previously-documented decision. 5. 6. The preview consent prompt defaults to accept. 7. Nits8. The ARM-expression branch of Checked and clean (recording the negatives so they are not re-derived)
This is an automated review and may be incomplete — in particular it does not cover the new test modules, the generated preview template payload, or the CI workflow changes in depth. |
Azure SRE Agent - automated reviewReviewing This increment answers two of Yuelin Zhao (@cheatsheet1999)'s inline asks directly (profile-carried management API, Blocking
Suggestions
Nits
Checked and clean (recording the negatives so they don't get re-derived)
This is an automated review and may be incomplete; I did not exercise the preview API against a live service, and the field-preservation tests are mocked — they don't establish server-side preservation of preview-only child resources. |
Azure SRE Agent - automated reviewReviewing The refactor itself is correct. I checked the new code filter against the string-prefix filter it replaces, issue by issue, and the recovery set is preserved exactly:
BlockingNone. Suggestions
Nits
Checked and clean
Carried forward (unchanged by this increment, not re-derived)
This is an automated review and may be incomplete; scope was the three files in the |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Preview identity/secret-sync writes can use the GA API, and container cleanup repeats the API-version failure seen in the referenced integration run.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds bundled GA and preview runtime profiles with explicit preview consent, channel-aware lifecycle handling, and dual-channel qualification.
Changes:
- Introduces runtime catalogs, discovery, compatibility validation, preview consent, and profile-specific templates/APIs.
- Expands unit and integration coverage across stable and preview channels.
- Reworks CI to test one hash-verified candidate wheel across isolated channel jobs.
| File | Description |
|---|---|
tox.ini |
Uses the isolated wheel-based integration runner. |
tools/integration_runner.py |
Verifies, installs, and tests candidate wheels. |
setup.cfg |
Exempts the generated preview template from line limits. |
docs/tox-testing.md |
Documents channel-aware tox execution. |
docs/integration-tests.md |
Documents dual-channel qualification and upgrades. |
azext_edge/tests/settings.py |
Adds runtime test environment variables. |
azext_edge/tests/runtime_checks.py |
Adds live runtime identity assertions. |
azext_edge/tests/edge/support/test_support_unit.py |
Tests both schema registry layouts. |
azext_edge/tests/edge/support/create_bundle_int/test_schemaregistry_int.py |
Supports GA and preview schema workloads. |
azext_edge/tests/edge/orchestration/test_work_unit.py |
Updates deployment expectations and request mocks. |
azext_edge/tests/edge/orchestration/test_upgrade_int.py |
Verifies channel-preserving upgrades. |
azext_edge/tests/edge/orchestration/test_template_preview_unit.py |
Validates the preview blueprint and consent flow. |
azext_edge/tests/edge/orchestration/test_targets_unit.py |
Updates template parameter expectations. |
azext_edge/tests/edge/orchestration/test_runtime_unit.py |
Tests runtime discovery and eligibility. |
azext_edge/tests/edge/orchestration/test_runtime_registration_unit.py |
Tests command registration and validation hooks. |
azext_edge/tests/edge/orchestration/test_runtime_profiles_unit.py |
Tests profiles, catalog selection, and boundaries. |
azext_edge/tests/edge/orchestration/test_runtime_dependencies_unit.py |
Tests foundation compatibility policies. |
azext_edge/tests/edge/orchestration/test_runtime_commands_unit.py |
Tests consent, routing, and upgrade guards. |
azext_edge/tests/edge/orchestration/test_runtime_channels_int.py |
Adds live cross-channel checks. |
azext_edge/tests/edge/orchestration/test_runtime_activation_unit.py |
Exercises bundled preview lifecycle behavior. |
azext_edge/tests/edge/orchestration/test_get_versions_unit.py |
Tests runtime profile reporting. |
azext_edge/tests/edge/orchestration/resources/test_instances_unit.py |
Tests API routing and field preservation. |
azext_edge/tests/edge/orchestration/resources/registry_endpoint/test_registry_endpoints_unit.py |
Supports profile-specific test endpoints. |
azext_edge/tests/edge/orchestration/resources/connector/akri/test_connector_templates_unit.py |
Supports profile-specific connector endpoints. |
azext_edge/tests/edge/init/int/test_init_int.py |
Provisions and verifies channel-specific runtimes. |
azext_edge/tests/conftest.py |
Registers markers and runtime qualification checks. |
azext_edge/edge/util/az_client.py |
Adds the preview management API version. |
azext_edge/edge/providers/support/schemaregistry.py |
Collects both schema registry layouts. |
azext_edge/edge/providers/orchestration/work.py |
Selects profiles and validates dependencies before creation. |
azext_edge/edge/providers/orchestration/targets.py |
Builds deployments from profile-specific blueprints. |
azext_edge/edge/providers/orchestration/runtime.py |
Implements runtime discovery and capability validation. |
azext_edge/edge/providers/orchestration/runtime_requirements.py |
Defines command and parameter restrictions. |
azext_edge/edge/providers/orchestration/runtime_profiles.py |
Defines runtime identities, profiles, and boundaries. |
azext_edge/edge/providers/orchestration/runtime_dependencies.py |
Defines foundation compatibility checks. |
azext_edge/edge/providers/orchestration/runtime_commands.py |
Integrates runtime validation with command parsing. |
azext_edge/edge/providers/orchestration/runtime_catalog.py |
Registers bundled stable and preview targets. |
azext_edge/edge/providers/orchestration/template_preview.py |
Supplies the generated preview deployment blueprint. |
azext_edge/edge/providers/orchestration/resources/registryendpoints.py |
Allows reuse of a profile-selected client. |
azext_edge/edge/providers/orchestration/resources/instances.py |
Adds runtime-aware instance reads and updates. |
azext_edge/edge/providers/orchestration/resources/connector_templates.py |
Reuses profile-selected clients for backfills. |
azext_edge/edge/providers/orchestration/resources/clusters.py |
Preserves cluster subscription routing. |
azext_edge/edge/providers/orchestration/preview.py |
Implements preview terms and consent. |
azext_edge/edge/params.py |
Adds preview selection and updated help text. |
azext_edge/edge/commands_edge.py |
Exposes preview creation and profile reporting. |
azext_edge/edge/_help.py |
Documents inline runtime profile output. |
azext_edge/constants.py |
Advances the package to 2.10.0a1. |
azext_edge/__init__.py |
Registers runtime command hooks. |
.github/workflows/int_test.yml |
Runs stable/preview jobs using one candidate wheel. |
.github/workflows/container_int_test.yml |
Adds dual-channel container qualification. |
.github/test-scenarios.yml |
Adds runtime and explicit upgrade-path scenarios. |
.github/test-container-scenarios.yml |
Defines the container test scenario. |
.github/skills/sync-aio-bicep-templates/SKILL.md |
Extends template synchronization guidance. |
.github/skills/sync-aio-bicep-templates/references/runtime-profiles.md |
Documents profile-aware synchronization. |
.github/actions/build-int-test-matrix/build_matrix.py |
Expands scenarios by channel and validates baselines. |
.github/actions/build-int-test-matrix/action.yml |
Exposes channel and baseline inputs. |
.dockerignore |
Includes the runner while excluding generated results. |
.coveragerc |
Normalizes installed-wheel coverage paths. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Azure SRE Agent - automated reviewReviewing No blocking findings. The change is coherent and, as far as I can verify in-repo, correct:
Suggestions
Nits
I have not restated the two inline comments Copilot posted earlier today on This is an automated review and may be incomplete. |
Azure SRE Agent - automated reviewReviewing Net product change is three things: Two things worth recording up front, because they close prior threads:
Blocking None. Suggestions
Nits
Summary — the increment does what it says: Automated review — may be incomplete. I did not re-review the runtime subsystem outside this increment, and I have not restated the existing inline comments on this PR. |
Azure SRE Agent - automated reviewReviewing Scope: the six product files in the increment ( Blocking1. The new
"deviceInboundEndpointTypes": [
{"endpointType": "Microsoft.OpcUa"},
{"endpointType": "Microsoft.OpcUa.WoT"},
],But both production callers — if (template.get("provisioningState") or "").lower() == PROVISIONING_STATE_FAILED.lower():
return True, template.get("name")
logger.debug("Default OPC UA connector template already exists.")
return False, NoneSo the only paths that can ever observe the new endpoint type are (a) a brand-new instance, where ARM deploys That is the same create-or-confirm shape as the Suggestions2. The preview runtime version moved Relatedly, the docstring change drops the release-policy override note ("pin upstream 1.6.0-preview.11 to the release owner's recommended 1.6.0-preview.9") in favour of "The pinned source deploys 1.6.0-preview.19 without a runtime-version override." Worth confirming the override was actually retired by the release owner rather than just removed from the comment. 3. 4. Nits5. Checked and clean
This is an automated review and may be incomplete; please treat the findings as input rather than as a gate. |
Azure SRE Agent - automated reviewReviewing Scope: the preview blueprint version/connector refresh in Blocking None. Suggestions 1. A >32-character instance name silently drops the MCP connection and leaves the policy orphaned. # template_preview.py, "mcpAioConnection"
"condition": "[and(equals(tryGet(tryGet(parameters('features'), 'mcp'), 'mode'), 'Preview'),
lessOrEquals(length(coalesce(parameters('aioInstanceName'), format('aio-{0}', variables('HASH')))), 32))]"but its sibling "condition": "[equals(tryGet(tryGet(parameters('features'), 'mcp'), 'mode'), 'Preview')]"So for Nothing on the Python side knows about the limit either. mcp_aio_connection = template.content["resources"].get("mcpAioConnection")
if mcp_aio_connection is not None:
mcp_aio_connection["name"] = f"{self.instance_name}/aio"
mcp_aio_connection["properties"]["service"]["name"] = f"{self.instance_name}-mcp"Two options, either is fine: mirror the existing If the 32 is a service-side name limit (e.g. Nits 2. The for moniker in template_vars["VERSIONS"]:
if moniker not in EXTENSION_TYPE_TO_MONIKER_MAP.values():
continue
version_map[moniker] = {"version": template_vars["VERSIONS"][moniker]}
for moniker in template_vars["TRAINS"]:
version_map[moniker]["train"] = template_vars["TRAINS"][moniker] # unguardedSafe today — 3. The blueprint now depends on a manual post-processing step. The new module docstring says:
So Checked and clean (recording the negatives so they don't get re-derived):
This is an automated review and may be incomplete. |
|
The linked integration run tested the #947 snapshot at The description should also note that changing |
Azure SRE Agent - automated reviewReviewing One commit, Refresh GA and preview runtimes and simplify preview opt-in — 26 files. Scope: the 12 product files in the increment plus Blocking
Suggestions
Nits
Checked and clean (recording the negatives so they are not re-derived)
This is an automated review and may be incomplete; please treat the findings as input rather than a gate. |
Azure SRE Agent - automated reviewReviewing This increment responds directly to Paymaun (@digimaun)'s three inline comments from 02:26Z, so I am not restating them. Instead I verified whether each fix actually holds, and below is what that turned up. Blocking1. The What is in that set on this head:
Both bundled blueprints are on the integration train (
Paymaun (@digimaun)'s specific example ( Suggested shape: either hoist the Test gap for the same point: Suggestions2. The
Given Ketki Naik (@ketkimnaik)'s reply says "equivalent check-side fix from #960 implemented", it may be cleaner to take #960 first and rebase, so the retirement lands as one coherent change with its regression tests. 3. 4. Checked and cleanRecording these so they do not get re-derived:
This is an automated review and may be incomplete; it is scoped to the single commit |
Azure SRE Agent - automated reviewReviewing The change itself is correct and the second new test is a genuine lock. My one substantive point is that the fix is gated to the preview channel while the same drift now also exists on the GA channel — and the first new test pins it there. Blocking
Suggestions
Nits
Checked and clean (recording the negatives so they are not re-derived):
I did not restate digimaun's three open inline threads ( This is an automated review and may be incomplete; please verify findings before acting on them. |
Azure SRE Agent - automated reviewReviewing Context: this increment answers Paymaun (@digimaun)'s inline thread on
Blocking
Suggestions
Nits
Summary: the three paths Paymaun (@digimaun) reported are genuinely fixed and well covered by the 23 new command-level parametrizations. The one remaining defect is This is an automated review and may be incomplete; please verify findings before acting on them. |
Azure SRE Agent - automated reviewReviewing One commit, one line: Blocking None introduced by this commit. Suggestions None. Nits None. Checked and clean
Still open from the previous review (not re-derived here) The Summary: cosmetic, responsive to the request, and verified safe. Nothing to change in this increment. This is an automated review and may be incomplete. |
Paymaun (digimaun)
left a comment
There was a problem hiding this comment.
Approved with a couple suggestions.
Azure SRE Agent - automated reviewReviewing Increment is one product commit plus a
I am not restating Paymaun (@digimaun)'s inline threads; this review verifies the fix against the code and reports what is new. Blocking None. Suggestions
Nits
Verification of the fix The open ask from inline comment 4224200946 / 4224406505 is genuinely closed, and the mechanism is the one that was suggested:
Checked and clean
This is an automated review and may be incomplete. |
Azure SRE Agent - automated reviewReviewing Increment is one commit, Remove obsolete create confirmation ignore, touching a single line: Blocking None. Suggestions None. Nits None. Checked and clean
This is an automated review and may be incomplete; please verify findings before acting on them. |


Overview
Integration test run: https://github.com/Azure/azure-iot-ops-cli-extension/actions/runs/36269685104
Instance creations for preview: