Skip to content
Merged
Show file tree
Hide file tree
Changes from 5 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,63 +1,68 @@
## Applicability
Az.Network supports the retrieval of private link resource in `Get-AzPrivateLinkResource` as well as the management of private endpoint connection in `Approve-AzPrivateEndpointConnect`, `Deny-AzPrivateEndpointConnect`, `Remove-AzPrivateEndpointConnect` and `Set-AzPrivateEndpointConnect`.
Az.Network supports the retrieval of private link resource in `Get-AzPrivateLinkResource` as well as the management of private endpoint connection by `Get-AzPrivateEndpointConnection`, `Approve-AzPrivateEndpointConnection`, `Deny-AzPrivateEndpointConnection`, `Remove-AzPrivateEndpointConnection` and `Set-AzPrivateEndpointConnection`.

For providers who
- supports the features of private linke resource and private endpoint connection already
- and want to onboard these features in Azure PowerShell,
For provider who
- supports the features of private link resource or private endpoint connection already
- and wants to onboard these features in Azure PowerShell,
You need to register provider configuration in [ProviderConfiguration.cs](https://github.com/Azure/azure-powershell/blob/main/src/Network/Network/PrivateLinkService/PrivateLinkServiceProvider/ProviderConfiguration.cs#L12).

they need register provider configuration in [ProviderConfiguration.cs](https://github.com/Azure/azure-powershell/blob/main/src/Network/Network/PrivateLinkService/PrivateLinkServiceProvider/ProviderConfiguration.cs#L12).

Notes: No additional commands for the features of private linke resource and private endpoint connection need to be added.
Notes: No additional commands for the features of PrivateLinkResource and PrivateEndpointConnection need to be added.

## Prerequisite
We assume the API for `List` private link resource and `Get` private endpoint connection is available in the provider that claims to support private endpoint connection features. That means it supports following APIs:

```
# List Private Link Resource API
"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{provider}/{Top-Level-Resource}/{Top-Level-Resource-Name}/privateLinkResources"
"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{provider}/{topResourceType}/{topResourceName}/privateLinkResources"
```
```
# Get Private Endpoint Connection API
"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{provider}/{Top-Level-Resource}/{Top-Level-Resource-Name}/privateEndpointConnections/{PrivateEndpointConnection-Name}"
"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{provider}/{topResourceType}/{topResourceName}/privateEndpointConnections/{privateEndpointConnectionName}"
```

if "List Private Endpoint Connection API" is not available, `privateEndpointConnections` must be included in the properties of top resource returned by
"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{provider}/{Top-Level-Resource}/{Top-Level-Resource-Name}". So that `Private Endpoint Connections` will be retrieved from the top resource.
if "List Private Endpoint Connection API" below is not available, `privateEndpointConnections` must be included in the properties of top resource returned by
"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{provider}/{topResourceType}/{topResourceName}". So that `Get-AzPrivateEndpointConnect` will retrieve connections from the top resource.

```
# List Private Endpoint Connection API
"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{provider}/{Top-Level-Resource}/{Top-Level-Resource-Name}/privateEndpointConnections"
"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{provider}/{topResourceType}/{topResourceName}/privateEndpointConnections"
```

## Code Changes Needed
To add corresponding {Provider}, {Top-Level-Resource} and {API-Version} into [ProviderConfiguration.cs](https://github.com/Azure/azure-powershell/blob/main/src/Network/Network/PrivateLinkService/PrivateLinkServiceProvider/ProviderConfiguration.cs#L12), we need to follow
in following pattern:
To add corresponding {Provider}, {topResourceType} and {API-Version} into [ProviderConfiguration.cs](https://github.com/Azure/azure-powershell/blob/main/src/Network/Network/PrivateLinkService/PrivateLinkServiceProvider/ProviderConfiguration.cs#L12), we need to follow in following pattern:
```
RegisterConfiguration("{Provider}/{Top-Level-Resource}", "{API-Version}", bool hasPrivateEndppointConnectionsURI, bool hasPrivateLinkResourceURI)
RegisterConfiguration(string type, string apiVersion, bool hasConnectionsURI = false, bool supportGetPrivateLinkResource = false, bool supportPrivateLinkResource = true)
```
- "{Provider}/{Top-Level-Resource}" describes the type of provider. For example, "Microsoft.Sql/servers".
- "{API-Version}" specifies the API version to be used. For example, "2018-06-01-preview".
- `hasPrivateEndppointConnectionsURI` marks the provider whether provides "List Private Endpoint Connection API".
- `type` includes resource provider and resource type which supports PrivateLink feature. For example, "Microsoft.Sql/servers".
- `apiVersion` specifies the API version to be used. For example, "2018-06-01-preview".
- `hasConnectionsURI` marks whether the provider exposes "List Private Endpoint Connection API". Default value is false.
```
# Get Private Link Resource API
"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{provider}/{Top-Level-Resource}/{Top-Level-Resource-Name}/privateLinkResources/{PrivateLinkResource-Name}"
"/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{provider}/{topResourceType}/{topResourceName}/privateLinkResources/{privateLinkResourceName}"
```
- `hasPrivateLinkResourceURI` marks the provider whether providers "Get Private Endpoint Connection API".
- `supportGetPrivateLinkResource` marks whether the provider supports Get API of PrivateLinkResource. Default value is false.

For instance, for provider "Microsoft.Sql/servers" with API version "2018-06-01-preview", it supports "List Private Endpoint Connection API" and "Get Private Endpoint Connection API". So it's registration configuration should be
For instance, for provider "Microsoft.Sql/servers" with API version "2018-06-01-preview", it supports "List Private Endpoint Connection API" and "Get Private Link Resource API". So its registration configuration should be:
```
RegisterConfiguration("Microsoft.Sql/servers", "2018-06-01-preview", true, true);
```

- `supportListPrivateLinkResource` marks whether the provider supports List API of PrivateLinkResource. Default value is true.

For instance, `Microsoft.Network/privateLinkServices` supports PrivateEndpointConnections but doesn't support resource type PrivateLinkResource (We assume List API is mandatory to resource support). Its configuration should be:
```
RegisterConfiguration("Microsoft.Network/privateLinkServices", "2020-05-01", true, false, false);
```

## End-To-End Test

### Item Needed

+ Top level resource
```
New-Az{Top-Level-Resource} -ResourceGroupName {rg_name} -Name {top_level_resource_name}
New-Az{topResourceType} -ResourceGroupName {rgName} -Name {topResourceName}

$TopLevelResource = Get-Az{Top-Level-Resource} -ResourceGroupName {rg_name} -Name {top_level_resource_name}
$TopLevelResource = Get-Az{topResourceType} -ResourceGroupName {rgName} -Name {topResourceName}
```

+ private link resource
Expand All @@ -67,24 +72,24 @@ $PrivateLinkResource = Get-AzPrivateLinkResource -PrivateLinkResourceId $TopLeve

+ subnet config (object in memory)
```
$SubnetConfig = New-AzVirtualNetworkSubnetConfig -Name {config_name} -AddressPrefix "11.0.1.0/24" -PrivateEndpointNetworkPolicies "Disabled"
$SubnetConfig = New-AzVirtualNetworkSubnetConfig -Name {configName} -AddressPrefix "11.0.1.0/24" -PrivateEndpointNetworkPolicies "Disabled"
```

+ virtual network
```
New-AzVirtualNetwork -ResourceGroupName {rg_name} -Name {vnet_name} -Location {location} -AddressPrefix "11.0.0.0/16" -Subnet $SubnetConfig
New-AzVirtualNetwork -ResourceGroupName {rgName} -Name {vnetName} -Location {location} -AddressPrefix "11.0.0.0/16" -Subnet $SubnetConfig

$VNet=Get-AzVirtualNetwork -ResourceGroupName {rg_name} -Name {vnet_name}
$VNet=Get-AzVirtualNetwork -ResourceGroupName {rgName} -Name {vnetName}
```

+ private link service connection (object in memory)
```
$PLSConnection = New-AzPrivateLinkServiceConnection -Name {pls_connection_name} -PrivateLinkServiceId $TopLevelResource.Id -GroupId $TopLevelResource.GroupId
$PLSConnection = New-AzPrivateLinkServiceConnection -Name {plsConnectionName} -PrivateLinkServiceId $TopLevelResource.Id -GroupId $TopLevelResource.GroupId
```

+ endpoint
```
New-AzPrivateEndpoint -ResourceGroupName {rg_name} -Name {endpoint_name} -Location {location} -Subnet $VNet.subnets[0] -PrivateLinkServiceConnection $PLSConnection -ByManualRequest
New-AzPrivateEndpoint -ResourceGroupName {rgName} -Name {endpointName} -Location {location} -Subnet $VNet.subnets[0] -PrivateLinkServiceConnection $PLSConnection -ByManualRequest
```

### step-by-step
Expand All @@ -99,7 +104,7 @@ $connection = Get-AzPrivateEndpointConnection -PrivateLinkResourceId $TopLevelRe

* To get the connection, if `list` for private endpoint connection was not supported,
```
$TopLevelResource = Get-Az{Top-Level-Resource} -ResourceGroupName {rg_name} -Name {top_level_resource_name}
$TopLevelResource = Get-Az{topResourceType} -ResourceGroupName {rgName} -Name {topResourceName}

$ConnectionId = $TopLevelResource.PrivateEndpointConnection[0].Id

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -60,9 +60,10 @@ public abstract class PrivateEndpointConnectionBaseCmdlet : NetworkBaseCmdlet, I
string NamedContextParameterSet = "ByResource";
public new object GetDynamicParameters()
{
InvocationInfo invocationInfo = MyInvocation;
var parameters = new RuntimeDefinedParameterDictionary();
RuntimeDefinedParameter namedParameter;
if (ProviderConfiguration.TryGetProvideServiceParameter(privateEndpointTypeName, NamedContextParameterSet, out namedParameter))
if (ProviderConfiguration.TryGetProvideServiceParameter("PEC", privateEndpointTypeName, NamedContextParameterSet, out namedParameter))
{
parameters.Add(privateEndpointTypeName, namedParameter);
}
Expand All @@ -76,6 +77,8 @@ public abstract class PrivateEndpointConnectionBaseCmdlet : NetworkBaseCmdlet, I

protected IPrivateLinkProvider BuildProvider(string subscription, string privateLinkResourceType)
{
if (!GenericProvider.SupportsPrivateLinkResourceType(privateLinkResourceType))
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please help to rename method to SupportsPrivateLinkFeature because it includes resource type and connection endpoint both.

throw new System.Exception($"The {privateLinkResourceType} doesn't support private endpoint connection");
return PrivateLinkProviderFactory.CreatePrivateLinkProvder(this, subscription, privateLinkResourceType);
}
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -63,9 +63,10 @@ public class GetAzurePrivateLinkResourceCommand : NetworkBaseCmdlet, IDynamicPar

public new object GetDynamicParameters()
{
InvocationInfo invocationInfo = MyInvocation;
var parameters = new RuntimeDefinedParameterDictionary();
RuntimeDefinedParameter namedParameter;
if (ProviderConfiguration.TryGetProvideServiceParameter(privateEndpointTypeName, NamedContextParameterSet, out namedParameter))
if (ProviderConfiguration.TryGetProvideServiceParameter("PLR", privateEndpointTypeName, NamedContextParameterSet, out namedParameter))
{
parameters.Add(privateEndpointTypeName, namedParameter);
}
Expand All @@ -89,6 +90,12 @@ public override void Execute()
this.Subscription = DefaultProfile.DefaultContext.Subscription.Id;
this.PrivateLinkResourceType = DynamicParameters[privateEndpointTypeName].Value as string;
}

if (!GenericProvider.SupportsPrivateLinkResourceType(this.PrivateLinkResourceType))
{
throw new Exception($"The {this.PrivateLinkResourceType} doesn't support private link resource");
}

IPrivateLinkProvider provider = PrivateLinkProviderFactory.CreatePrivateLinkProvder(this, Subscription, PrivateLinkResourceType);
if (provider == null)
{
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -133,7 +133,11 @@ public void DeletePrivateEndpointConnection(string resourceGroupName, string ser

public PSPrivateLinkResource GetPrivateLinkResource(string resourceGroupName, string serviceName, string name)
{
if (_configuration.HasResourceURI)
if (!_configuration.SupportPrivateLinkResource)
{
throw new System.Exception($"The {_configuration.Type} api {_configuration.ApiVersion} doesn't support private link resource");
}
if (_configuration.SupportGetPrivateLinkResource)
{
string url = BuildPrivateLinkResourceURL(resourceGroupName, serviceName, name);
PrivateLinkResource resource = ServiceClient.Operations.GetResource<PrivateLinkResource>(url, _configuration.ApiVersion);
Expand All @@ -147,6 +151,10 @@ public PSPrivateLinkResource GetPrivateLinkResource(string resourceGroupName, st

public List<PSPrivateLinkResource> ListPrivateLinkResource(string resourceGroupName, string serviceName)
{
if (!_configuration.SupportPrivateLinkResource)
{
throw new System.Exception($"The {_configuration.Type} api {_configuration.ApiVersion} doesn't support private link resource");
}
var psPLRs = new List<PSPrivateLinkResource>();
string url = BuildPrivateLinkResourcesURL(resourceGroupName, serviceName);
IPage<PrivateLinkResource> list = ServiceClient.Operations.GetResourcePage<Page<PrivateLinkResource>, PrivateLinkResource>(url, _configuration.ApiVersion);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,7 @@ static ProviderConfiguration()
RegisterConfiguration("Microsoft.Migrate/assessmentProjects", "2020-05-01-preview", false, false);
RegisterConfiguration("Microsoft.Migrate/migrateProjects", "2020-06-01-preview", false, false);
RegisterConfiguration("Microsoft.Network/applicationgateways", "2020-05-01", true, false);
RegisterConfiguration("Microsoft.Network/privateLinkServices", "2020-05-01", true, false, false);
RegisterConfiguration("Microsoft.OffAzure/masterSites", "2020-07-07", false, false);
RegisterConfiguration("Microsoft.PowerBI/privateLinkServicesForPowerBI", "2020-06-01", false, true);
RegisterConfiguration("Microsoft.Purview/accounts", "2020-12-01-preview", true, true);
Expand All @@ -71,50 +72,62 @@ static ProviderConfiguration()
RegisterConfiguration("Microsoft.Web/hostingEnvironments", "2020-10-01", true, false);
RegisterConfiguration("Microsoft.BotService/botServices", "2021-05-01-preview", true, true);
}

private static void RegisterConfiguration(string type, string apiVersion, bool hasConnectionsURI = false, bool hasResourceURI = false)
/// <summary>
/// Register private endpoint connection and private link resource configuration
/// </summary>
/// <param name="type">Resource type</param>
/// <param name="apiVersion">Resource api version</param>
/// <param name="hasConnectionsURI">True if the private endpoint connection can be list by URL <see cref="GenericProvider.BuildPrivateEndpointConnectionsURL(string, string)"/>, otherwise it can be list by URL <see cref="GenericProvider.BuildPrivateEndpointConnectionsOwnerURL(string, string)"/></param>
/// <param name="supportGetPrivateLinkResource">True if the private link resource can be get by Id, otherwise it can be list</param>
/// <param name="supportPrivateLinkResource">True if the private link resource be supported, otherwise false</param>
private static void RegisterConfiguration(string type, string apiVersion, bool hasConnectionsURI = false, bool supportGetPrivateLinkResource = false, bool supportPrivateLinkResource = true)
{
ProviderConfiguration configuration = new ProviderConfiguration
{
Type = type,
ApiVersion = apiVersion,
HasConnectionsURI = hasConnectionsURI,
HasResourceURI = hasResourceURI
SupportGetPrivateLinkResource = supportGetPrivateLinkResource,
SupportPrivateLinkResource = supportPrivateLinkResource,
};
_configurations.Add(type, configuration);
}

public string Type { get; set; }
public string ApiVersion { get; set; }
public bool HasConnectionsURI { get; set; }
public bool HasResourceURI { get; set; }
public bool SupportGetPrivateLinkResource { get; set; }
public bool SupportPrivateLinkResource { get; set; }

public static ProviderConfiguration GetProviderConfiguration(string type)
{
return _configurations[type];
ProviderConfiguration outProviderConfiguration = null;
_configurations.TryGetValue(type, out outProviderConfiguration);
return outProviderConfiguration;
}

/// <summary>
/// Generate a runtime parameter with ValidateSet matching the current context
/// </summary>
/// <param name="serviceType">Has two value, PLR => private link resource, PEC => private endpoint connection.</param>
/// <param name="name">The name of the parameter</param>
/// <param name="runtimeParameter">The returned runtime parameter for context, with appropriate validate set</param>
/// <returns>True if one or more contexts were found, otherwise false</returns>
public static bool TryGetProvideServiceParameter(string name, string parameterSetName, out RuntimeDefinedParameter runtimeParameter)
public static bool TryGetProvideServiceParameter(string serviceType, string name, string parameterSetName, out RuntimeDefinedParameter runtimeParameter)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My understanding is It is not required. Let's discuss further.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If possible, the method should be moved to each cmdlet implementation. So, one should go to privateendpointconnnection, another goes to GetAzurePrivateLinkResource.

{
var result = false;
runtimeParameter = null;
if (_configurations != null && _configurations.Values != null)
{
var ObjArray = _configurations.Values.ToArray();
var ProvideTypeList = ObjArray.Select(c => c.Type).ToArray();
var ProvideTypeList = serviceType.ToUpper() == "PLR" ? ObjArray.Where(c => c.SupportPrivateLinkResource).Select(c => c.Type).ToArray() : ObjArray.Select(c => c.Type).ToArray();
runtimeParameter = new RuntimeDefinedParameter(
name, typeof(string),
new Collection<Attribute>()
{
new ParameterAttribute { Mandatory = false,
ValueFromPipeline = true,
HelpMessage = "The private link resource type.",
HelpMessage = "The resource provider and resource type which supports private link resource.",
ParameterSetName = parameterSetName },
new ValidateSetAttribute(ProvideTypeList)
}
Expand Down