Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -395,13 +395,17 @@ def load_arguments(self, _): # pylint: disable=too-many-locals, too-many-statem
with self.argument_context('storage account keys list') as c:
c.argument('account_name', acct_name_type, id_part=None)

with self.argument_context('storage account network-rule') as c:
with self.argument_context('storage account network-rule', resource_type=ResourceType.MGMT_STORAGE) as c:
from ._validators import validate_subnet
c.argument('account_name', acct_name_type, id_part=None)
c.argument('ip_address', help='IPv4 address or CIDR range.')
c.argument('subnet', help='Name or ID of subnet. If name is supplied, `--vnet-name` must be supplied.')
c.argument('vnet_name', help='Name of a virtual network.', validator=validate_subnet)
c.argument('action', help='The action of virtual network rule.')
c.argument('resource_id', help='The resource id to add in network rule.', arg_group='Resource Access Rule',
min_api='2020-08-01-preview')
c.argument('tenant_id', help='The tenant id to add in network rule.', arg_group='Resource Access Rule',
min_api='2020-08-01-preview')

with self.argument_context('storage account blob-service-properties show',
resource_type=ResourceType.MGMT_STORAGE) as c:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -368,7 +368,7 @@ def list_network_rules(client, resource_group_name, account_name):


def add_network_rule(cmd, client, resource_group_name, account_name, action='Allow', subnet=None,
vnet_name=None, ip_address=None): # pylint: disable=unused-argument
vnet_name=None, ip_address=None, tenant_id=None, resource_id=None): # pylint: disable=unused-argument
sa = client.get_properties(resource_group_name, account_name)
rules = sa.network_rule_set
if subnet:
Expand All @@ -387,14 +387,21 @@ def add_network_rule(cmd, client, resource_group_name, account_name, action='All
rules.ip_rules = []
rules.ip_rules = [r for r in rules.ip_rules if r.ip_address_or_range != ip_address]
rules.ip_rules.append(IpRule(ip_address_or_range=ip_address, action=action))
if resource_id:
ResourceAccessRule = cmd.get_models('ResourceAccessRule')
if not rules.resource_access_rules:
rules.resource_access_rules = []
rules.resource_access_rules = [r for r in rules.resource_access_rules if r.resource_id !=
resource_id or r.tenant_id != tenant_id]
rules.resource_access_rules.append(ResourceAccessRule(tenant_id=tenant_id, resource_id=resource_id))

StorageAccountUpdateParameters = cmd.get_models('StorageAccountUpdateParameters')
params = StorageAccountUpdateParameters(network_rule_set=rules)
return client.update(resource_group_name, account_name, params)


def remove_network_rule(cmd, client, resource_group_name, account_name, ip_address=None, subnet=None,
vnet_name=None): # pylint: disable=unused-argument
vnet_name=None, tenant_id=None, resource_id=None): # pylint: disable=unused-argument
sa = client.get_properties(resource_group_name, account_name)
rules = sa.network_rule_set
if subnet:
Expand All @@ -403,6 +410,10 @@ def remove_network_rule(cmd, client, resource_group_name, account_name, ip_addre
if ip_address:
rules.ip_rules = [x for x in rules.ip_rules if x.ip_address_or_range != ip_address]

if resource_id:
rules.resource_access_rules = [x for x in rules.resource_access_rules if
not (x.tenant_id == tenant_id and x.resource_id == resource_id)]

StorageAccountUpdateParameters = cmd.get_models('StorageAccountUpdateParameters')
params = StorageAccountUpdateParameters(network_rule_set=rules)
return client.update(resource_group_name, account_name, params)
Expand Down
Loading