Skip to content

Conversation

@vittoriasalim
Copy link
Contributor

as title

@vittoriasalim vittoriasalim marked this pull request as ready for review January 23, 2026 06:34
Copilot AI review requested due to automatic review settings January 23, 2026 06:34
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an issue where Microsoft pods were stuck due to Cilium image pull failures caused by restrictive firewall configuration. The change adds Microsoft Container Registry (MCR) FQDNs to the Azure Firewall's allowed egress list.

Changes:

  • Adds mcr.microsoft.com and *.mcr.microsoft.com to the firewall allow list to enable Cilium container image pulls from Microsoft Container Registry

target_fqdns = ["*.azure.com", "*.azure.net",
"*.windows.net", "*.azurecr.io", "*.ubuntu.com", "AzureKubernetesService",
"mcr-0001.mcr-msedge.net", "*.microsoft.com",
"mcr-0001.mcr-msedge.net", "*.microsoft.com", "mcr.microsoft.com", "*.mcr.microsoft.com",
Copy link

Copilot AI Jan 23, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The FQDN mcr.microsoft.com is redundant because it's already covered by the existing *.microsoft.com wildcard pattern. The wildcard *.microsoft.com matches any subdomain of microsoft.com, including mcr.microsoft.com. You can remove mcr.microsoft.com from this list while keeping *.mcr.microsoft.com to allow subdomains of mcr.microsoft.com (e.g., <region>.mcr.microsoft.com).

Suggested change
"mcr-0001.mcr-msedge.net", "*.microsoft.com", "mcr.microsoft.com", "*.mcr.microsoft.com",
"mcr-0001.mcr-msedge.net", "*.microsoft.com", "*.mcr.microsoft.com",

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants