Gap-3: Container Apps Operate (C → A) — Revisions, day-2 ops, networking - #1637
Conversation
There was a problem hiding this comment.
Pull request overview
Adds operational reference documentation for Azure Container Apps covering revision management, day-2 operations, and networking/custom domains to support “operate (C → A)” readiness.
Changes:
- Introduces revision management guidance (modes, traffic splitting, rollback) with Bicep/Terraform/CLI examples
- Adds day-2 operational runbooks (restart/exec/logs/env updates/secrets & rotation)
- Documents networking patterns (ingress modes, VNet integration, custom domains/TLS, IP restrictions)
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 6 comments.
| File | Description |
|---|---|
| plugin/skills/azure-prepare/references/services/container-apps/revisions.md | New doc for revision modes, traffic splitting patterns, rollback, and IaC examples |
| plugin/skills/azure-prepare/references/services/container-apps/networking.md | New doc for ingress/VNet/custom domain/TLS/IP restriction guidance |
| plugin/skills/azure-prepare/references/services/container-apps/day2-operations.md | New doc for day-2 ops tasks including logs, exec, env/secret updates, rotation workflow |
Details# 🔍 Token Analysis Report
fatal: path 'plugin/skills/azure-prepare/references/services/container-apps/day2-operations.md' exists on disk, but not in 'origin/main' 📊 Token Change ReportComparing Summary
Changed Files
📊 Token Limit Check ReportChecked: 587 files
|
| File | Tokens | Limit | Over By |
|---|---|---|---|
.github/skills/analyze-skill-issues/SKILL.md |
2109 | 500 | +1609 |
.github/skills/analyze-test-run/SKILL.md |
2471 | 500 | +1971 |
.github/skills/file-test-bug/SKILL.md |
628 | 500 | +128 |
.github/skills/sensei/README.md |
3531 | 2000 | +1531 |
.github/skills/sensei/SKILL.md |
3026 | 500 | +2526 |
.github/skills/sensei/references/EXAMPLES.md |
3701 | 2000 | +1701 |
.github/skills/sensei/references/LOOP.md |
4181 | 2000 | +2181 |
.github/skills/sensei/references/SCORING.md |
4299 | 2000 | +2299 |
.github/skills/skill-authoring/SKILL.md |
839 | 500 | +339 |
plugin/skills/airunway-aks-setup/SKILL.md |
1025 | 500 | +525 |
plugin/skills/appinsights-instrumentation/SKILL.md |
911 | 500 | +411 |
plugin/skills/azure-ai/SKILL.md |
820 | 500 | +320 |
plugin/skills/azure-aigateway/SKILL.md |
1261 | 500 | +761 |
plugin/skills/azure-aigateway/references/policies.md |
2342 | 2000 | +342 |
plugin/skills/azure-cloud-migrate/SKILL.md |
600 | 500 | +100 |
plugin/skills/azure-cloud-migrate/references/services/container-apps/cloudrun-deployment-guide.md |
2029 | 2000 | +29 |
plugin/skills/azure-cloud-migrate/references/services/functions/lambda-to-functions.md |
2600 | 2000 | +600 |
plugin/skills/azure-cloud-migrate/references/services/functions/runtimes/javascript.md |
2181 | 2000 | +181 |
plugin/skills/azure-compliance/SKILL.md |
1188 | 500 | +688 |
plugin/skills/azure-compute/SKILL.md |
1090 | 500 | +590 |
plugin/skills/azure-compute/workflows/vm-recommender/vm-recommender.md |
2631 | 2000 | +631 |
plugin/skills/azure-compute/workflows/vm-troubleshooter/vm-troubleshooter.md |
2509 | 2000 | +509 |
plugin/skills/azure-cost/SKILL.md |
1980 | 500 | +1480 |
plugin/skills/azure-deploy/SKILL.md |
1645 | 500 | +1145 |
plugin/skills/azure-deploy/references/pre-deploy-checklist.md |
4095 | 2000 | +2095 |
plugin/skills/azure-deploy/references/recipes/azd/errors.md |
4004 | 2000 | +2004 |
plugin/skills/azure-deploy/references/troubleshooting.md |
2038 | 2000 | +38 |
plugin/skills/azure-diagnostics/SKILL.md |
1134 | 500 | +634 |
plugin/skills/azure-enterprise-infra-planner/SKILL.md |
1002 | 500 | +502 |
plugin/skills/azure-enterprise-infra-planner/references/constraints/compute-apps.md |
2022 | 2000 | +22 |
plugin/skills/azure-hosted-copilot-sdk/SKILL.md |
1263 | 500 | +763 |
plugin/skills/azure-kubernetes/SKILL.md |
2606 | 500 | +2106 |
plugin/skills/azure-kubernetes/azure-kubernetes-automatic-readiness/SKILL.md |
3609 | 500 | +3109 |
plugin/skills/azure-kusto/SKILL.md |
2152 | 500 | +1652 |
plugin/skills/azure-messaging/SKILL.md |
970 | 500 | +470 |
plugin/skills/azure-prepare/SKILL.md |
3219 | 500 | +2719 |
plugin/skills/azure-prepare/references/aspire.md |
4617 | 2000 | +2617 |
plugin/skills/azure-prepare/references/plan-template.md |
2559 | 2000 | +559 |
plugin/skills/azure-prepare/references/recipes/azd/terraform.md |
3528 | 2000 | +1528 |
plugin/skills/azure-prepare/references/research.md |
2274 | 2000 | +274 |
plugin/skills/azure-prepare/references/resources-limits-quotas.md |
3322 | 2000 | +1322 |
plugin/skills/azure-prepare/references/security.md |
2147 | 2000 | +147 |
plugin/skills/azure-prepare/references/services/functions/bicep.md |
3065 | 2000 | +1065 |
plugin/skills/azure-prepare/references/services/functions/templates/SPEC-composable-templates.md |
6187 | 2000 | +4187 |
plugin/skills/azure-prepare/references/services/functions/templates/recipes/composition.md |
4649 | 2000 | +2649 |
plugin/skills/azure-prepare/references/services/functions/terraform.md |
3358 | 2000 | +1358 |
plugin/skills/azure-quotas/SKILL.md |
2821 | 500 | +2321 |
plugin/skills/azure-quotas/references/commands.md |
2644 | 2000 | +644 |
plugin/skills/azure-resource-lookup/SKILL.md |
1291 | 500 | +791 |
plugin/skills/azure-resource-visualizer/SKILL.md |
2122 | 500 | +1622 |
plugin/skills/azure-storage/SKILL.md |
1183 | 500 | +683 |
plugin/skills/azure-upgrade/SKILL.md |
1009 | 500 | +509 |
plugin/skills/azure-upgrade/references/services/functions/automation.md |
3463 | 2000 | +1463 |
plugin/skills/azure-upgrade/references/services/functions/consumption-to-flex.md |
2773 | 2000 | +773 |
plugin/skills/azure-validate/SKILL.md |
950 | 500 | +450 |
plugin/skills/entra-app-registration/SKILL.md |
2070 | 500 | +1570 |
plugin/skills/entra-app-registration/references/api-permissions.md |
2545 | 2000 | +545 |
plugin/skills/entra-app-registration/references/cli-commands.md |
2211 | 2000 | +211 |
plugin/skills/entra-app-registration/references/console-app-example.md |
2752 | 2000 | +752 |
plugin/skills/entra-app-registration/references/oauth-flows.md |
2375 | 2000 | +375 |
plugin/skills/microsoft-foundry/SKILL.md |
2939 | 500 | +2439 |
plugin/skills/microsoft-foundry/foundry-agent/create/create.md |
4125 | 2000 | +2125 |
plugin/skills/microsoft-foundry/foundry-agent/deploy/deploy.md |
5871 | 2000 | +3871 |
plugin/skills/microsoft-foundry/foundry-agent/eval-datasets/eval-datasets.md |
2344 | 2000 | +344 |
plugin/skills/microsoft-foundry/foundry-agent/eval-datasets/references/trace-to-dataset.md |
4268 | 2000 | +2268 |
plugin/skills/microsoft-foundry/foundry-agent/invoke/invoke.md |
2059 | 2000 | +59 |
plugin/skills/microsoft-foundry/foundry-agent/observe/observe.md |
2542 | 2000 | +542 |
plugin/skills/microsoft-foundry/foundry-agent/trace/references/kql-templates.md |
2701 | 2000 | +701 |
plugin/skills/microsoft-foundry/models/deploy-model/SKILL.md |
1640 | 500 | +1140 |
plugin/skills/microsoft-foundry/models/deploy-model/capacity/SKILL.md |
1739 | 500 | +1239 |
plugin/skills/microsoft-foundry/models/deploy-model/customize/SKILL.md |
2235 | 500 | +1735 |
plugin/skills/microsoft-foundry/models/deploy-model/customize/references/customize-workflow.md |
3335 | 2000 | +1335 |
plugin/skills/microsoft-foundry/models/deploy-model/preset/SKILL.md |
1226 | 500 | +726 |
plugin/skills/microsoft-foundry/models/deploy-model/preset/references/preset-workflow.md |
5534 | 2000 | +3534 |
plugin/skills/microsoft-foundry/quota/quota.md |
2288 | 2000 | +288 |
plugin/skills/microsoft-foundry/quota/references/capacity-planning.md |
2080 | 2000 | +80 |
plugin/skills/microsoft-foundry/references/sdk/foundry-sdk-py.md |
2162 | 2000 | +162 |
Consider moving content to
references/subdirectories.
Automated token analysis. See skill authoring guidelines for best practices.
- Fix: replace non-existent 'az containerapp stop/start' with update --min/max-replicas - Fix: subnet size table now shows /27 for workload profiles (default) and /23 for consumption-only (legacy) - Fix: subnet delegation note for consumption-only (must NOT delegate) - Fix: IP restrictions remove invalid Allow+Deny mix (docs say cannot combine) - Fix: internal ingress description corrected - Fix: Bicep traffic config uses latestRevision:true instead of non-existent revision names - Fix: blue/green queries actual revision name from revision list - Fix: rollback uses label-based routing or explicit revision name - Fix: remove plaintext password, add CLI secret exposure warning All fixes validated against official Microsoft ACA documentation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…rences - Bump metadata.version 1.1.1 → 1.1.7 (main is 1.1.6) - Link day2-operations.md, networking.md, revisions.md from container-apps README Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Addresses Copilot review comment — rules need deterministic evaluation order. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Blue/green: capture NEW_REV from update output instead of assuming list order - Canary: use actual revision names from revision list, not placeholders - Resume: use <previous-min>/<previous-max> instead of hard-coded values - Troubleshooting: fix env var guidance to focus on traffic routing - Networking: clarify VNet-injected caveat for internal microservice Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…/day2-operations.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Jon Gallant (jongio)
left a comment
There was a problem hiding this comment.
Three useful Container Apps reference docs, but several factual accuracy issues would mislead users if merged as-is.
CI is failing because the azure-prepare skill version wasn't bumped from 1.1.8. That needs fixing.
The PR says "Closes #1611" but only delivers 3 of the 6 deliverables in that issue (upgrade-paths.md, azure-upgrade extension, and integration tests are missing). Consider changing to "Part of #1611" and splitting the rest into a follow-up.
See inline comments for specifics.
|
Hey Paul — nice additions on the operate side, especially the networking and revisions coverage. I reviewed it against the latest ACA docs and caught a few things: the IP restriction rules actually can mix Allow and Deny (evaluated by priority), subnet delegation is needed for both workload-profiles and consumption-only environments, and the fully-private topology has two distinct sub-modes worth calling out. Also bumped the version. Fixes are in #2025 targeting your branch — feel free to merge whenever. All tested across 5 models. Thanks! |
- Bump azure-prepare version 1.1.8 → 1.1.9 (fixes Skill Structure CI check) - Fix incorrect claim that Allow/Deny IP rules cannot be mixed - Fix subnet delegation for consumption-only environments (requires Microsoft.App/environments) - Clarify 'fully private' topology: VNet-wide vs env-only based on ingress external flag - Clarify first-deployment revision tip Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
revisions.md: - Add blue/green warning: latestRevision:true auto-routes traffic, must pin to named revision first for validation window networking.md: - Remove non-existent priority field from ipSecurityRestrictions Bicep (Container Apps API uses array order, not priority) - Add managed cert prerequisites (public DNS, external access only) and point to bring-your-own-cert for internal/private scenarios - Fix hostname add comment (registers hostname only, no cert) day2-operations.md: - Show both Azure Monitor (new) and legacy Log Analytics KQL table names (ContainerAppConsoleLogs vs ContainerAppConsoleLogs_CL) - Add missing configuration.secrets block for secretRef example - Replace non-existent --file param with shell substitution pattern Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…r-Azure into pass-equity-gap-3 # Conflicts: # plugin/skills/azure-prepare/SKILL.md
🧪 E2E Skill Validation — Container Apps Operate (PR #1637)Tested the operational skill docs end-to-end against a live Container App ( Results
Key Validations
Notes
Command output logsRevision list (3 revisions after all tests): IP restriction applied: [{"action":"Allow","description":"Test","ipAddressRange":"203.0.113.0/24","name":"test-rule"}]Exec session: KQL table validation (ContainerAppConsoleLogs schema confirmed): Cleanup: Resource group |
Jon Gallant (jongio)
left a comment
There was a problem hiding this comment.
Checked current HEAD (b80c4a5) against my 6 change requests from April 8:
- IP restrictions: priority field removed, array-order evaluation documented
- Managed TLS certs: prerequisites warning added (public DNS, external access)
- Custom domain CLI: comment clarified (hostname only, no cert provisioned)
- Secrets warning: replaced nonexistent
--filewith shell substitution pattern - Bicep secrets:
configuration.secretsblock added abovetemplate.containers - KQL tables:
ContainerAppConsoleLogsas primary, legacy_CLas commented alternative
All 6 items are addressed. E2E validation against a live Container App confirms the commands and syntax work (13/13 scenarios).
One remaining nit: the blue/green example in revisions.md deploys a new revision directly (az containerapp update --image), but the warning above says to pin traffic to the current revision first. Adding an explicit pin step before the deploy would make the example match the warning.
Jon Gallant (jongio)
left a comment
There was a problem hiding this comment.
All change requests addressed. Approving.
Closes #1611 | Parent: #1608
3 files: revisions.md (traffic splitting, rollback), day2-operations.md (restart, exec, log streaming), networking.md (VNet, ingress, custom domains).