Skip to content

{AKS} aks-preview: reject legacy --outbound-type managedNATGatewayV2 with a fail-fast error - #10300

Merged
Julie Zhu (yanzhudd) merged 2 commits into
Azure:mainfrom
christine33-creator:cdossa/aks-preview-reject-legacy-natgwv2
Sep 8, 2026
Merged

Julie Zhu (yanzhudd) merged 2 commits into
Azure:mainfrom
christine33-creator:cdossa/aks-preview-reject-legacy-natgwv2

Conversation

@christine33-creator

@christine33-creator Christine DOSSA (christine33-creator) commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor

🤖 PR Validation — ️✔️ All clear

Breaking Changes
️✔️ None

Related command

az aks create / az aks update (--outbound-type)

Description

The aks-preview extension targets the GA-aligned 2026-06-02-preview api-version, where NAT Gateway V2 is expressed as --outbound-type managedNATGateway --outbound-type-sku StandardV2. On that api-version the RP rejects the legacy outboundType=managedNATGatewayV2 value with an HTTP 400.

Previously the CLI passed managedNATGatewayV2 through unchanged (its client-side validators only rejected it when combined with the V2 flags/SKU), so a bare --outbound-type managedNATGatewayV2 produced no local error and the user only discovered the failure after a round-trip to the RP.

This change fails fast locally, on both az aks create and az aks update, with an actionable message:

--outbound-type managedNATGatewayV2 is no longer supported. Use --outbound-type managedNATGateway --outbound-type-sku StandardV2 instead.

The --outbound-type help text is updated to stop advertising managedNATGatewayV2, and the change is recorded under HISTORY.rst Pending.

General Guidelines

  • Have you run azdev style <YOUR_EXT> locally? flake8 clean; pylint 10.00/10 on the changed files.
  • Have you run python scripts/ci/test_index.py -q locally?
  • My extension version conforms to the Extension version schema — recorded under HISTORY.rst Pending (no version bump, consistent with the other unreleased entries at 22.0.0b6).

Testing

Added unit tests to TestValidateNatGatewayV2Params and TestValidateNatGatewayV2ParamsForUpdate: a bare --outbound-type managedNATGatewayV2 (no V2 flags) is rejected on both create and update, and the error text points to --outbound-type-sku StandardV2. All validator-class tests pass locally.

@azure-client-tools-bot-prd

Copy link
Copy Markdown

Hi Christine DOSSA (@christine33-creator),
Please write the description of changes which can be perceived by customers into HISTORY.rst.
If you want to release a new extension version, please update the version in pyproject.toml (or setup.py, if the extension has not migrated yet) as well.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The help updates still leave nearby argument help text advertising managedNATGatewayV2, creating contradictory guidance relative to the new fail-fast behavior.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR updates the aks-preview extension’s client-side validation so az aks create / az aks update --outbound-type managedNATGatewayV2 fails fast with an actionable error message, aligning the UX with the GA-aligned 2026-06-02-preview API behavior (which rejects the legacy value server-side).

Changes:

  • Add a validator helper to explicitly reject --outbound-type managedNATGatewayV2 on both create and update flows.
  • Add unit tests ensuring a bare legacy outbound type is rejected and the message points users to --outbound-type-sku StandardV2.
  • Update command help text and record the behavior change in HISTORY.rst (Pending).
File summaries
File Description
src/aks-preview/HISTORY.rst Records the new fail-fast behavior under Pending.
src/aks-preview/azext_aks_preview/tests/latest/test_natgateway.py Adds unit tests covering the new rejection behavior for create and update validators.
src/aks-preview/azext_aks_preview/_validators.py Implements local validation to reject the legacy managedNATGatewayV2 outbound type early.
src/aks-preview/azext_aks_preview/_help.py Updates --outbound-type help text to remove/replace legacy guidance.
Review details

Suppressed comments (1)

src/aks-preview/azext_aks_preview/_help.py:1066

  • This updated --outbound-type help states the legacy managedNATGatewayV2 value is no longer supported, but the help text for --nat-gateway-managed-outbound-ip-count and --nat-gateway-idle-timeout in the same section still lists managedNATGatewayV2 as valid, which is inconsistent with the fail-fast behavior.
          long-summary: This option will change the way how the outbound connections are managed in the AKS cluster. Available options are loadbalancer, managedNATGateway, userAssignedNATGateway, userDefinedRouting, none and block. For clusters using a custom virtual network, supported values are loadbalancer, userAssignedNATGateway and userDefinedRouting. For clusters using an AKS-managed virtual network, supported values are loadbalancer, managedNATGateway and userDefinedRouting. For NAT Gateway V2, use managedNATGateway with --outbound-type-sku StandardV2; the legacy managedNATGatewayV2 value is no longer supported.
  • Files reviewed: 4/4 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/aks-preview/azext_aks_preview/_help.py
@yonzhan

Copy link
Copy Markdown
Collaborator

AKS

@FumingZhang FumingZhang left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

Comment thread src/aks-preview/azext_aks_preview/_help.py
@yanzhudd
Julie Zhu (yanzhudd) merged commit fecf7e7 into Azure:main Sep 8, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants