Skip to content

Gap-3: Container Apps Operate (C → A) — Revisions, day-2 ops, networking - #1637

Merged
kvenkatrajan merged 11 commits into
mainfrom
pass-equity-gap-3
Apr 27, 2026
Merged

Gap-3: Container Apps Operate (C → A) — Revisions, day-2 ops, networking#1637
kvenkatrajan merged 11 commits into
mainfrom
pass-equity-gap-3

Conversation

@paulyuk

Copy link
Copy Markdown
Member

Closes #1611 | Parent: #1608

3 files: revisions.md (traffic splitting, rollback), day2-operations.md (restart, exec, log streaming), networking.md (VNet, ingress, custom domains).

Starting assessment — domain experts should review.

Closes #1611 | Parent: #1608
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds operational reference documentation for Azure Container Apps covering revision management, day-2 operations, and networking/custom domains to support “operate (C → A)” readiness.

Changes:

  • Introduces revision management guidance (modes, traffic splitting, rollback) with Bicep/Terraform/CLI examples
  • Adds day-2 operational runbooks (restart/exec/logs/env updates/secrets & rotation)
  • Documents networking patterns (ingress modes, VNet integration, custom domains/TLS, IP restrictions)

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 6 comments.

File Description
plugin/skills/azure-prepare/references/services/container-apps/revisions.md New doc for revision modes, traffic splitting patterns, rollback, and IaC examples
plugin/skills/azure-prepare/references/services/container-apps/networking.md New doc for ingress/VNet/custom domain/TLS/IP restriction guidance
plugin/skills/azure-prepare/references/services/container-apps/day2-operations.md New doc for day-2 ops tasks including logs, exec, env/secret updates, rotation workflow

Comment thread plugin/skills/azure-prepare/references/services/container-apps/revisions.md Outdated
Comment thread plugin/skills/azure-prepare/references/services/container-apps/networking.md Outdated
@github-actions

github-actions Bot commented Apr 1, 2026

Copy link
Copy Markdown
Contributor
Details# 🔍 Token Analysis Report

@github-copilot-for-azure/scripts@1.0.0 tokens
node --import tsx src/tokens/cli.ts compare --base origin/main --head HEAD --markdown

fatal: path 'plugin/skills/azure-prepare/references/services/container-apps/day2-operations.md' exists on disk, but not in 'origin/main'
fatal: path 'plugin/skills/azure-prepare/references/services/container-apps/networking.md' exists on disk, but not in 'origin/main'
fatal: path 'plugin/skills/azure-prepare/references/services/container-apps/revisions.md' exists on disk, but not in 'origin/main'

📊 Token Change Report

Comparing origin/mainHEAD

Summary

Metric Value
📈 Total Change +3,892 tokens (+1243%)
Before 313 tokens
After 4,205 tokens
Files Changed 4

Changed Files

File Before After Change
plugin/skills/azure-prepare/references/services/container-apps/day2-operations.md - 1,303 +1303
plugin/skills/azure-prepare/references/services/container-apps/networking.md - 1,295 +1295
plugin/skills/azure-prepare/references/services/container-apps/revisions.md - 1,261 +1261
plugin/skills/azure-prepare/references/services/container-apps/README.md 313 346 +33 (+11%)

@github-copilot-for-azure/scripts@1.0.0 tokens
node --import tsx src/tokens/cli.ts check --markdown

📊 Token Limit Check Report

Checked: 587 files
Exceeded: 77 files

⚠️ Files Exceeding Token Limits

File Tokens Limit Over By
.github/skills/analyze-skill-issues/SKILL.md 2109 500 +1609
.github/skills/analyze-test-run/SKILL.md 2471 500 +1971
.github/skills/file-test-bug/SKILL.md 628 500 +128
.github/skills/sensei/README.md 3531 2000 +1531
.github/skills/sensei/SKILL.md 3026 500 +2526
.github/skills/sensei/references/EXAMPLES.md 3701 2000 +1701
.github/skills/sensei/references/LOOP.md 4181 2000 +2181
.github/skills/sensei/references/SCORING.md 4299 2000 +2299
.github/skills/skill-authoring/SKILL.md 839 500 +339
plugin/skills/airunway-aks-setup/SKILL.md 1025 500 +525
plugin/skills/appinsights-instrumentation/SKILL.md 911 500 +411
plugin/skills/azure-ai/SKILL.md 820 500 +320
plugin/skills/azure-aigateway/SKILL.md 1261 500 +761
plugin/skills/azure-aigateway/references/policies.md 2342 2000 +342
plugin/skills/azure-cloud-migrate/SKILL.md 600 500 +100
plugin/skills/azure-cloud-migrate/references/services/container-apps/cloudrun-deployment-guide.md 2029 2000 +29
plugin/skills/azure-cloud-migrate/references/services/functions/lambda-to-functions.md 2600 2000 +600
plugin/skills/azure-cloud-migrate/references/services/functions/runtimes/javascript.md 2181 2000 +181
plugin/skills/azure-compliance/SKILL.md 1188 500 +688
plugin/skills/azure-compute/SKILL.md 1090 500 +590
plugin/skills/azure-compute/workflows/vm-recommender/vm-recommender.md 2631 2000 +631
plugin/skills/azure-compute/workflows/vm-troubleshooter/vm-troubleshooter.md 2509 2000 +509
plugin/skills/azure-cost/SKILL.md 1980 500 +1480
plugin/skills/azure-deploy/SKILL.md 1645 500 +1145
plugin/skills/azure-deploy/references/pre-deploy-checklist.md 4095 2000 +2095
plugin/skills/azure-deploy/references/recipes/azd/errors.md 4004 2000 +2004
plugin/skills/azure-deploy/references/troubleshooting.md 2038 2000 +38
plugin/skills/azure-diagnostics/SKILL.md 1134 500 +634
plugin/skills/azure-enterprise-infra-planner/SKILL.md 1002 500 +502
plugin/skills/azure-enterprise-infra-planner/references/constraints/compute-apps.md 2022 2000 +22
plugin/skills/azure-hosted-copilot-sdk/SKILL.md 1263 500 +763
plugin/skills/azure-kubernetes/SKILL.md 2606 500 +2106
plugin/skills/azure-kubernetes/azure-kubernetes-automatic-readiness/SKILL.md 3609 500 +3109
plugin/skills/azure-kusto/SKILL.md 2152 500 +1652
plugin/skills/azure-messaging/SKILL.md 970 500 +470
plugin/skills/azure-prepare/SKILL.md 3219 500 +2719
plugin/skills/azure-prepare/references/aspire.md 4617 2000 +2617
plugin/skills/azure-prepare/references/plan-template.md 2559 2000 +559
plugin/skills/azure-prepare/references/recipes/azd/terraform.md 3528 2000 +1528
plugin/skills/azure-prepare/references/research.md 2274 2000 +274
plugin/skills/azure-prepare/references/resources-limits-quotas.md 3322 2000 +1322
plugin/skills/azure-prepare/references/security.md 2147 2000 +147
plugin/skills/azure-prepare/references/services/functions/bicep.md 3065 2000 +1065
plugin/skills/azure-prepare/references/services/functions/templates/SPEC-composable-templates.md 6187 2000 +4187
plugin/skills/azure-prepare/references/services/functions/templates/recipes/composition.md 4649 2000 +2649
plugin/skills/azure-prepare/references/services/functions/terraform.md 3358 2000 +1358
plugin/skills/azure-quotas/SKILL.md 2821 500 +2321
plugin/skills/azure-quotas/references/commands.md 2644 2000 +644
plugin/skills/azure-resource-lookup/SKILL.md 1291 500 +791
plugin/skills/azure-resource-visualizer/SKILL.md 2122 500 +1622
plugin/skills/azure-storage/SKILL.md 1183 500 +683
plugin/skills/azure-upgrade/SKILL.md 1009 500 +509
plugin/skills/azure-upgrade/references/services/functions/automation.md 3463 2000 +1463
plugin/skills/azure-upgrade/references/services/functions/consumption-to-flex.md 2773 2000 +773
plugin/skills/azure-validate/SKILL.md 950 500 +450
plugin/skills/entra-app-registration/SKILL.md 2070 500 +1570
plugin/skills/entra-app-registration/references/api-permissions.md 2545 2000 +545
plugin/skills/entra-app-registration/references/cli-commands.md 2211 2000 +211
plugin/skills/entra-app-registration/references/console-app-example.md 2752 2000 +752
plugin/skills/entra-app-registration/references/oauth-flows.md 2375 2000 +375
plugin/skills/microsoft-foundry/SKILL.md 2939 500 +2439
plugin/skills/microsoft-foundry/foundry-agent/create/create.md 4125 2000 +2125
plugin/skills/microsoft-foundry/foundry-agent/deploy/deploy.md 5871 2000 +3871
plugin/skills/microsoft-foundry/foundry-agent/eval-datasets/eval-datasets.md 2344 2000 +344
plugin/skills/microsoft-foundry/foundry-agent/eval-datasets/references/trace-to-dataset.md 4268 2000 +2268
plugin/skills/microsoft-foundry/foundry-agent/invoke/invoke.md 2059 2000 +59
plugin/skills/microsoft-foundry/foundry-agent/observe/observe.md 2542 2000 +542
plugin/skills/microsoft-foundry/foundry-agent/trace/references/kql-templates.md 2701 2000 +701
plugin/skills/microsoft-foundry/models/deploy-model/SKILL.md 1640 500 +1140
plugin/skills/microsoft-foundry/models/deploy-model/capacity/SKILL.md 1739 500 +1239
plugin/skills/microsoft-foundry/models/deploy-model/customize/SKILL.md 2235 500 +1735
plugin/skills/microsoft-foundry/models/deploy-model/customize/references/customize-workflow.md 3335 2000 +1335
plugin/skills/microsoft-foundry/models/deploy-model/preset/SKILL.md 1226 500 +726
plugin/skills/microsoft-foundry/models/deploy-model/preset/references/preset-workflow.md 5534 2000 +3534
plugin/skills/microsoft-foundry/quota/quota.md 2288 2000 +288
plugin/skills/microsoft-foundry/quota/references/capacity-planning.md 2080 2000 +80
plugin/skills/microsoft-foundry/references/sdk/foundry-sdk-py.md 2162 2000 +162

Consider moving content to references/ subdirectories.


Automated token analysis. See skill authoring guidelines for best practices.

Simon J (simonjj) and others added 2 commits April 6, 2026 12:28
- Fix: replace non-existent 'az containerapp stop/start' with update --min/max-replicas
- Fix: subnet size table now shows /27 for workload profiles (default) and /23 for consumption-only (legacy)
- Fix: subnet delegation note for consumption-only (must NOT delegate)
- Fix: IP restrictions remove invalid Allow+Deny mix (docs say cannot combine)
- Fix: internal ingress description corrected
- Fix: Bicep traffic config uses latestRevision:true instead of non-existent revision names
- Fix: blue/green queries actual revision name from revision list
- Fix: rollback uses label-based routing or explicit revision name
- Fix: remove plaintext password, add CLI secret exposure warning

All fixes validated against official Microsoft ACA documentation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…rences

- Bump metadata.version 1.1.1 → 1.1.7 (main is 1.1.6)
- Link day2-operations.md, networking.md, revisions.md from container-apps README

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings April 6, 2026 19:42
Addresses Copilot review comment — rules need deterministic evaluation order.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 5 out of 5 changed files in this pull request and generated 6 comments.

Comment thread plugin/skills/azure-prepare/references/services/container-apps/revisions.md Outdated
Comment thread plugin/skills/azure-prepare/references/services/container-apps/revisions.md Outdated
Comment thread plugin/skills/azure-prepare/references/services/container-apps/day2-operations.md Outdated
Comment thread plugin/skills/azure-prepare/references/services/container-apps/networking.md Outdated
Comment thread plugin/skills/azure-prepare/SKILL.md
Paul Yuknewicz (paulyuk) and others added 2 commits April 6, 2026 12:59
- Blue/green: capture NEW_REV from update output instead of assuming list order
- Canary: use actual revision names from revision list, not placeholders
- Resume: use <previous-min>/<previous-max> instead of hard-coded values
- Troubleshooting: fix env var guidance to focus on traffic routing
- Networking: clarify VNet-injected caveat for internal microservice

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings April 6, 2026 20:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 5 out of 5 changed files in this pull request and generated 2 comments.

Comment thread plugin/skills/azure-prepare/SKILL.md
Comment thread plugin/skills/azure-prepare/references/services/container-apps/day2-operations.md Outdated
Paul Yuknewicz (paulyuk) and others added 2 commits April 7, 2026 10:58
…/day2-operations.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings April 7, 2026 17:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated 4 comments.

Comment thread plugin/skills/azure-prepare/references/services/container-apps/networking.md Outdated
Comment thread plugin/skills/azure-prepare/references/services/container-apps/revisions.md Outdated

@jongio Jon Gallant (jongio) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Three useful Container Apps reference docs, but several factual accuracy issues would mislead users if merged as-is.

CI is failing because the azure-prepare skill version wasn't bumped from 1.1.8. That needs fixing.

The PR says "Closes #1611" but only delivers 3 of the 6 deliverables in that issue (upgrade-paths.md, azure-upgrade extension, and integration tests are missing). Consider changing to "Part of #1611" and splitting the rest into a follow-up.

See inline comments for specifics.

Comment thread plugin/skills/azure-prepare/references/services/container-apps/revisions.md Outdated
Comment thread plugin/skills/azure-prepare/references/services/container-apps/day2-operations.md Outdated
Comment thread plugin/skills/azure-prepare/references/services/container-apps/day2-operations.md Outdated
@simonjj

Copy link
Copy Markdown
Contributor

Hey Paul — nice additions on the operate side, especially the networking and revisions coverage.

I reviewed it against the latest ACA docs and caught a few things: the IP restriction rules actually can mix Allow and Deny (evaluated by priority), subnet delegation is needed for both workload-profiles and consumption-only environments, and the fully-private topology has two distinct sub-modes worth calling out. Also bumped the version.

Fixes are in #2025 targeting your branch — feel free to merge whenever. All tested across 5 models.

Thanks!

Simon J (simonjj) and others added 2 commits April 24, 2026 07:46
- Bump azure-prepare version 1.1.8 → 1.1.9 (fixes Skill Structure CI check)
- Fix incorrect claim that Allow/Deny IP rules cannot be mixed
- Fix subnet delegation for consumption-only environments (requires Microsoft.App/environments)
- Clarify 'fully private' topology: VNet-wide vs env-only based on ingress external flag
- Clarify first-deployment revision tip

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
revisions.md:
- Add blue/green warning: latestRevision:true auto-routes traffic,
  must pin to named revision first for validation window

networking.md:
- Remove non-existent priority field from ipSecurityRestrictions
  Bicep (Container Apps API uses array order, not priority)
- Add managed cert prerequisites (public DNS, external access only)
  and point to bring-your-own-cert for internal/private scenarios
- Fix hostname add comment (registers hostname only, no cert)

day2-operations.md:
- Show both Azure Monitor (new) and legacy Log Analytics KQL table
  names (ContainerAppConsoleLogs vs ContainerAppConsoleLogs_CL)
- Add missing configuration.secrets block for secretRef example
- Replace non-existent --file param with shell substitution pattern

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings April 24, 2026 14:48

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 5 out of 5 changed files in this pull request and generated 3 comments.

…r-Azure into pass-equity-gap-3

# Conflicts:
#	plugin/skills/azure-prepare/SKILL.md
@paulyuk

Copy link
Copy Markdown
Member Author

🧪 E2E Skill Validation — Container Apps Operate (PR #1637)

Tested the operational skill docs end-to-end against a live Container App (pr1637-test-app in rg-pr1637-test, East US 2).

Results

Test Skill File Status Details
Deploy second revision revisions.md az containerapp update --set-env-vars created revision --0000001 alongside original --hzabjam
Traffic splitting (50/50) revisions.md az containerapp ingress traffic set --revision-weight split traffic evenly between both revisions
Label-based routing revisions.md Assigned stable/canary labels, routed 80/20 via --label-weight — syntax matches docs exactly
Rollback to previous revisions.md --label-weight stable=100 instantly shifted all traffic back; canary went to 0%
Restart revision day2-operations.md az containerapp revision restart succeeded without creating a new revision (still 2 revisions)
List replicas day2-operations.md az containerapp replica list returned replica names for the target revision
Log streaming day2-operations.md az containerapp logs show --type system returned system events (revision updates, replica scheduling)
Exec into container day2-operations.md az containerapp exec --command /bin/sh connected successfully; ran echo inside container
KQL table name (new format) day2-operations.md ContainerAppConsoleLogs table exists in workspace (queried via REST). This env uses log-analytics destination so the legacy _CL suffix comment in the doc is also correct
Update env vars → new revision day2-operations.md Adding STAGE/REGION env vars created revision --0000002 as documented
Verify ingress config networking.md --query properties.configuration.ingress returns full ingress JSON with traffic, fqdn, transport
IP restriction (no priority field) networking.md az containerapp ingress access-restriction set succeeded without --priority; the stored rule has no priority field — confirms JonG's fix is accurate
FQDN query networking.md --query properties.configuration.ingress.fqdn returns pr1637-test-app.ambitiousflower-5aeefc7e.eastus2.azurecontainerapps.io

Key Validations

  • Multiple revision mode works with traffic splitting
  • IP restrictions deploy without priority field (action, description, ipAddressRange, name only — no priority)
  • KQL ContainerAppConsoleLogs table exists (not legacy _CL); doc correctly notes both formats with comments
  • Revision restart works without creating new revision (verified revision count stayed at 2)

Notes

  • The docs correctly document both --revision-weight and --label-weight syntax for traffic management
  • Label-based routing workflow (assign labels → route by label → swap targets) works as described
  • The warning about priority field not existing in the Container Apps API is confirmed — the REST response has no priority property
  • Env vars: log-analytics destination uses the legacy ContainerAppConsoleLogs_CL table format per the doc comments, but this new env also has the ContainerAppConsoleLogs (non-CL) table available
Command output logs

Revision list (3 revisions after all tests):

CreatedTime                Active    Replicas    TrafficWeight    HealthState    Name
2026-04-24T14:59:51+00:00  True      2           100              Healthy        pr1637-test-app--hzabjam
2026-04-24T15:01:36+00:00  True      1           0                Healthy        pr1637-test-app--0000001

IP restriction applied:

[{"action":"Allow","description":"Test","ipAddressRange":"203.0.113.0/24","name":"test-rule"}]

Exec session:

INFO: Connecting to the container 'pr1637-test-app'...
INFO: Successfully connected to container: 'pr1637-test-app'. [ Revision: 'pr1637-test-app--0000002', Replica: 'pr1637-test-app--0000002-776b74b57d-tqpwn']
sh-5.2# echo "exec-works" && exit
exec-works

KQL table validation (ContainerAppConsoleLogs schema confirmed):
Columns: TenantId, TimeGenerated, OperationName, Location, ContainerName, ContainerGroupName, ContainerImage, Stream, ContainerGroupId, EnvironmentName, Log, ContainerAppName, ContainerId, RevisionName, JobName, SourceSystem, Type, _ResourceId

Cleanup: Resource group rg-pr1637-test deletion initiated (--no-wait).

@jongio Jon Gallant (jongio) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checked current HEAD (b80c4a5) against my 6 change requests from April 8:

  • IP restrictions: priority field removed, array-order evaluation documented
  • Managed TLS certs: prerequisites warning added (public DNS, external access)
  • Custom domain CLI: comment clarified (hostname only, no cert provisioned)
  • Secrets warning: replaced nonexistent --file with shell substitution pattern
  • Bicep secrets: configuration.secrets block added above template.containers
  • KQL tables: ContainerAppConsoleLogs as primary, legacy _CL as commented alternative

All 6 items are addressed. E2E validation against a live Container App confirms the commands and syntax work (13/13 scenarios).

One remaining nit: the blue/green example in revisions.md deploys a new revision directly (az containerapp update --image), but the warning above says to pin traffic to the current revision first. Adding an explicit pin step before the deploy would make the example match the warning.

@jongio Jon Gallant (jongio) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All change requests addressed. Approving.

@kvenkatrajan
kvenkatrajan merged commit c5dc986 into main Apr 27, 2026
13 checks passed
@kvenkatrajan
kvenkatrajan deleted the pass-equity-gap-3 branch April 27, 2026 22:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Gap-3: Container Apps Operate (C → A) — Revisions, day-2 ops, networking, upgrade paths

5 participants