Update Azure resource API versions to latest stable versions - #70
Open
msangapu-msft wants to merge 6 commits into
Open
Update Azure resource API versions to latest stable versions#70msangapu-msft wants to merge 6 commits into
msangapu-msft wants to merge 6 commits into
Conversation
## Summary This PR updates all Azure resource API versions in `infra/resources.bicep` to the latest stable and recommended versions for improved compatibility, security, and feature support. ## Changes ### Network Resources - `Microsoft.Network/virtualNetworks`: Already at `2024-01-01` ✓ - `Microsoft.Network/privateDnsZones`: `2020-06-01` → `2024-06-01` - `Microsoft.Network/virtualNetworkLinks`: `2020-06-01` → `2024-06-01` - `Microsoft.Network/privateEndpoints`: `2023-04-01` / `2024-03-01` → `2024-01-01` ### Security & Authorization - `Microsoft.KeyVault/vaults`: `2022-07-01` → `2024-02-01` - `Microsoft.Authorization/roleDefinitions`: `2018-01-01-preview` → `2022-04-04-preview` - `Microsoft.Authorization/roleAssignments`: `2020-08-01-preview` → `2022-04-01` ### Database - `Microsoft.DBforPostgreSQL/flexibleServers`: `2022-01-20-preview` → `2024-02-01-preview` ### Cache - `Microsoft.Cache/redisEnterprise`: Already at `2026-05-01-preview` ✓ ### App Services & Monitoring - `Microsoft.Web/serverfarms`: Already at `2024-04-01` ✓ - `Microsoft.Web/sites`: Already at `2024-04-01` ✓ - `Microsoft.Insights/diagnosticSettings`: Already at `2021-05-01-preview` ✓ - `Microsoft.OperationalInsights/workspaces`: `2023-09-01` → `2025-07-01` ### Service Connectors - `Microsoft.ServiceLinker/linkers`: `2024-04-01` → `2024-07-01-preview` - vaultConnector - dbConnector - cacheConnector ## Benefits - Latest features and bug fixes - Improved security posture - Better compatibility with current Azure services - Aligned with Microsoft best practices ## Testing The Bicep file has been formatted and verified for syntax correctness.
## Summary This PR updates all Azure resource API versions in `infra/resources.bicep` to the latest stable and recommended versions for improved compatibility, security, and feature support. ## Changes ### Network Resources - `Microsoft.Network/virtualNetworks`: Already at `2024-01-01` ✓ - `Microsoft.Network/privateDnsZones`: `2020-06-01` → `2024-06-01` - `Microsoft.Network/virtualNetworkLinks`: `2020-06-01` → `2024-06-01` - `Microsoft.Network/privateEndpoints`: `2023-04-01` / `2024-03-01` → `2024-01-01` ### Security & Authorization - `Microsoft.KeyVault/vaults`: `2022-07-01` → `2024-02-01` - `Microsoft.Authorization/roleDefinitions`: `2018-01-01-preview` → `2022-04-04-preview` - `Microsoft.Authorization/roleAssignments`: `2020-08-01-preview` → `2022-04-01` ### Database - `Microsoft.DBforPostgreSQL/flexibleServers`: `2022-01-20-preview` → `2024-02-01-preview` ### Cache - `Microsoft.Cache/redisEnterprise`: Already at `2026-05-01-preview` ✓ ### App Services & Monitoring - `Microsoft.Web/serverfarms`: Already at `2024-04-01` ✓ - `Microsoft.Web/sites`: Already at `2024-04-01` ✓ - `Microsoft.Insights/diagnosticSettings`: Already at `2021-05-01-preview` ✓ - `Microsoft.OperationalInsights/workspaces`: `2023-09-01` → `2025-07-01` ### Service Connectors - `Microsoft.ServiceLinker/linkers`: `2024-04-01` → `2024-07-01-preview` - vaultConnector - dbConnector - cacheConnector ## Benefits of Latest API Versions 1. **Security Patches** — Older API versions may have known vulnerabilities that are fixed in newer versions, protecting your infrastructure. 2. **New Features & Capabilities** — Newer API versions introduce enhanced functionality, better configuration options, and improved resource management. 3. **Bug Fixes** — Earlier versions have bugs that are resolved in later releases, improving reliability and preventing unexpected behavior. 4. **Performance Improvements** — API updates frequently include performance optimizations that reduce deployment times and resource overhead. 5. **Better Compatibility** — Newer versions work seamlessly with the latest Azure services and features, preventing compatibility issues. 6. **Long-term Support** — Older preview versions eventually lose support. Current versions ensure continued support for your infrastructure. 7. **Azure Portal & Tooling** — Better integration with Azure Portal, CLI, and VS Code extensions for improved development experience. 8. **Compliance & Best Practices** — Aligned with Microsoft's security best practices and compliance standards. 9. **Cleaner Code** — Improved schema design makes Bicep templates more maintainable and readable. 10. **Deprecation Avoidance** — Staying current prevents painful migrations from deprecated API versions. ## Testing The Bicep file has been formatted and verified for syntax correctness.
msangapu-msft
force-pushed
the
update-api-versions
branch
from
July 23, 2026 15:41
d82543f to
dc53418
Compare
added 4 commits
July 23, 2026 15:44
Updated the remaining API versions to match Azure's current stable and preview releases: - Microsoft.KeyVault/vaults: 2024-02-01 → 2026-03-01-preview - Microsoft.Web/serverfarms: 2024-04-01 → 2025-03-01 - Microsoft.Web/sites: 2024-04-01 → 2025-03-01 - Microsoft.Web/sites/config: 2024-04-01 → 2025-03-01 - basicPublishingCredentialsPolicies (ftp): 2023-12-01 → 2025-03-01 - basicPublishingCredentialsPolicies (scm): 2023-12-01 → 2025-03-01 These updates provide: 1. Compatibility with latest Azure service features and fixes 2. Access to new preview capabilities (KeyVault 2026 preview) 3. Future-proofing through newer API versions 4. Bug fixes and performance improvements in App Service APIs 5. Enhanced security patches and compliance features 6. Better networking and integration capabilities
- Removes the 'existing' keyword from the Redis database resource to allow creation/management by the template. - Ensures the databases/default resource actually exists before Service Linker references it. - Resolves the InvalidTargetService error by ensuring a valid database target is created.
- Replace dynamic listConfigurations-based CONNECTION_SETTINGS output with a static list of expected setting names. - Keeps postprovision messaging unchanged while removing false-positive secret output diagnostics.
There was a problem hiding this comment.
Pull request overview
This PR updates the sample’s Azure infrastructure template (infra/resources.bicep) to newer resource API versions and improves Service Linker reliability by ensuring the Redis Enterprise default database subresource is created and available before connectors target it.
Changes:
- Updated API versions for networking (private DNS zones/links, private endpoints), Key Vault, RBAC assignments, PostgreSQL Flexible Server, App Service, Operational Insights, and Service Linker.
- Changed the Redis Enterprise
defaultdatabase fromexisting(reference-only) to a managed resource created by the template. - Replaced the dynamic
CONNECTION_SETTINGSoutput (previously derived fromlistConfigurations()) with a static list of expected setting names.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+552
to
+560
| output CONNECTION_SETTINGS array = [ | ||
| 'AZURE_POSTGRESQL_NAME' | ||
| 'AZURE_POSTGRESQL_HOST' | ||
| 'AZURE_POSTGRESQL_USER' | ||
| 'AZURE_POSTGRESQL_PASSWORD' | ||
| 'AZURE_REDIS_CONNECTIONSTRING' | ||
| 'AZURE_KEYVAULT_RESOURCEENDPOINT' | ||
| 'AZURE_KEYVAULT_SCOPE' | ||
| ] |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR modernizes Azure infrastructure definitions in
infra/resources.bicepby updating resource API versions to the latest stable/preview releases and fixing Redis database provisioning reliability for Service Linker.What changed
2024-07-01-preview.existing) to managed/created in-template.CONNECTION_SETTINGSoutput derived fromlistConfigurations()with a static expected-name list to avoid secret-output diagnostics noise.Key reliability fix
Before:
Microsoft.Cache/redisEnterprise/.../databases/defaultasexisting.Target resource does not exist/InvalidTargetService.After:
defaultdatabase.Benefits
Validation
azd up --no-promptcompleted successfully end-to-end after the Redis database fix.