{AKS} aks-preview: reject legacy --outbound-type managedNATGatewayV2 with a fail-fast error - #10300
Conversation
…with a fail-fast error
|
Hi Christine DOSSA (@christine33-creator), |
There was a problem hiding this comment.
🟡 Changes recommended
The help updates still leave nearby argument help text advertising managedNATGatewayV2, creating contradictory guidance relative to the new fail-fast behavior.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR updates the aks-preview extension’s client-side validation so az aks create / az aks update --outbound-type managedNATGatewayV2 fails fast with an actionable error message, aligning the UX with the GA-aligned 2026-06-02-preview API behavior (which rejects the legacy value server-side).
Changes:
- Add a validator helper to explicitly reject
--outbound-type managedNATGatewayV2on both create and update flows. - Add unit tests ensuring a bare legacy outbound type is rejected and the message points users to
--outbound-type-sku StandardV2. - Update command help text and record the behavior change in
HISTORY.rst(Pending).
File summaries
| File | Description |
|---|---|
| src/aks-preview/HISTORY.rst | Records the new fail-fast behavior under Pending. |
| src/aks-preview/azext_aks_preview/tests/latest/test_natgateway.py | Adds unit tests covering the new rejection behavior for create and update validators. |
| src/aks-preview/azext_aks_preview/_validators.py | Implements local validation to reject the legacy managedNATGatewayV2 outbound type early. |
| src/aks-preview/azext_aks_preview/_help.py | Updates --outbound-type help text to remove/replace legacy guidance. |
Review details
Suppressed comments (1)
src/aks-preview/azext_aks_preview/_help.py:1066
- This updated --outbound-type help states the legacy managedNATGatewayV2 value is no longer supported, but the help text for --nat-gateway-managed-outbound-ip-count and --nat-gateway-idle-timeout in the same section still lists managedNATGatewayV2 as valid, which is inconsistent with the fail-fast behavior.
long-summary: This option will change the way how the outbound connections are managed in the AKS cluster. Available options are loadbalancer, managedNATGateway, userAssignedNATGateway, userDefinedRouting, none and block. For clusters using a custom virtual network, supported values are loadbalancer, userAssignedNATGateway and userDefinedRouting. For clusters using an AKS-managed virtual network, supported values are loadbalancer, managedNATGateway and userDefinedRouting. For NAT Gateway V2, use managedNATGateway with --outbound-type-sku StandardV2; the legacy managedNATGatewayV2 value is no longer supported.
- Files reviewed: 4/4 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
AKS |
🤖 PR Validation — ️✔️ All clear
Related command
az aks create/az aks update(--outbound-type)Description
The aks-preview extension targets the GA-aligned
2026-06-02-previewapi-version, where NAT Gateway V2 is expressed as--outbound-type managedNATGateway --outbound-type-sku StandardV2. On that api-version the RP rejects the legacyoutboundType=managedNATGatewayV2value with an HTTP 400.Previously the CLI passed
managedNATGatewayV2through unchanged (its client-side validators only rejected it when combined with the V2 flags/SKU), so a bare--outbound-type managedNATGatewayV2produced no local error and the user only discovered the failure after a round-trip to the RP.This change fails fast locally, on both
az aks createandaz aks update, with an actionable message:The
--outbound-typehelp text is updated to stop advertisingmanagedNATGatewayV2, and the change is recorded under HISTORY.rst Pending.General Guidelines
azdev style <YOUR_EXT>locally? flake8 clean; pylint 10.00/10 on the changed files.python scripts/ci/test_index.py -qlocally?Testing
Added unit tests to
TestValidateNatGatewayV2ParamsandTestValidateNatGatewayV2ParamsForUpdate: a bare--outbound-type managedNATGatewayV2(no V2 flags) is rejected on both create and update, and the error text points to--outbound-type-sku StandardV2. All validator-class tests pass locally.