API Version Mismatch for Application Gateway
integrationActiveRisingThe Azure CLI uses an outdated API version for the Application Gateway GET command, preventing access to Managed HSM properties.
Score Breakdown
Heuristic ranking from public discussion signals — not a validated prediction of commercial opportunity, demand, or willingness to pay.
Composite 69/100 (High, unvalidated). Top driver: Willingness to pay (30% weight, 22.5 pts).
Heuristic only — often urgency map or random scaffolding on ingest, not measured mention frequency. Maps to XPS relevance (with market size).
LLM/mock judgment of intensity from title/summary text — not ops or ticket data. Maps to XPS quality (with willingness to pay).
LLM/mock purchase-intent guess from text — not invoices, surveys, or paid seats. Maps to XPS quality.
Heuristic/scaffold (often random or fixed on insert) — not a verified mention trajectory. Maps to XPS novelty.
Heuristic/scaffold (often random or fixed) — not TAM research. Maps to XPS relevance (with frequency).
Catalog notes (not predictive analysis)
API Version Mismatch for Application Gateway (integration). Catalog heuristic opportunity score: 69/100 — a chosen formula over discussion-signal facets, not evidence of demand, conversion, or willingness to pay. Treat as browsing rank, not a commercial prediction.
The Azure CLI uses an outdated API version for the Application Gateway GET command, preventing access to Managed HSM properties.
Source Examples
“The latest Azure CLI release (`2.89.1`) still generates the parent Application Gateway GET command with API version `2024-10-01` ### Describe the bug `az network application-gateway show` Managed HSM support for Application Gateway SSL certificates was added in API version `2025-07-01` and implemented for the SSL certificate command group under #33263. The SSL certificate commands correctly use `2025-07-01`, but the parent Application Gateway GET remains pinned to `2024-10-01`. As a result, retrieving the complete Application Gateway resource through the parent `show` command can omit the Managed HSM properties under `sslCertificates[].properties.hsm`. HSM PR: https://github.com/Azure/azure-cli/issues/33263 ### Related command ```bash az network application-gateway show \ --resource-group <resource-group> \ --name <application-gateway> \ --debug ``` ### Errors There is no CLI exception. The problem is the API version selected for the parent GET request and the resulting response shape. - Actual parent GET API version: `2024-10-01` - Minimum API version containing `ApplicationGatewayManagedHsm`: `2025-07-01` ### Issue script & Debug output The sanitized parent GET request shown by `--debug` uses: ```text GET https://management.azure.com/subscriptions/<subscription-id>/resourceGroups/<resource-group>/providers/Microsoft.Network/applicationGateways/<application-gateway>?api-version=2024-10-01 ``` The generated AAZ source in release `azure-cli-2.89.1` confirms the mismatch: - `src/azure-cli/azure/cli/command_modules/network/aaz/latest/network/application_gateway/_show.py` - `_aaz_info["version"] = "2024-10-01"` - `ApplicationGatewaysGet` uses `2024-10-01` - `src/azure-cli/azure/cli/command_modules/network/aaz/latest/network/application_gateway/ssl_cert/_show.py` - `_aaz_info["version"] = "2025-07-01"` - The response schema includes `hsm.keyId` and `hsm.publicCertData` The same parent/child API-version mismatch exists for generated Application Gateway create/update versus SSL certificate create/update. Those operations should also be assessed for read-modify-write behavior that could omit HSM properties. ### Expected behavior `az network application-gateway show` should use an API version that supports Managed HSM, at minimum `2025-07-01`, and return these fields when configured: ```text sslCertificates[].properties.hsm.keyId sslCertificates[].properties.hsm.publicCertData ``` Please also verify that parent Application Gateway create/update operations cannot omit or overwrite Managed HSM SSL certificate properties because they use the older API version. Regression coverage should verify: 1. The parent Application Gateway GET request uses the intended API version. 2. Managed HSM fields are preserved in the returned model. 3. Parent create/update read-modify-write flows preserve HSM-backed SSL certificate configuration. ### Environment Summary azure-cli 2.89.1 ### Additional context _No response_”
Competitive Landscape
- Existing solutions are either too expensive or too limited
- Most competitors target enterprise, leaving mid-market underserved
- Community scripts and manual processes are the primary alternative
Recommended Next Steps
- ✓Validate pain intensity with 5-10 target customer interviews
- ✓Build minimal viable solution addressing the core workflow
- ✓Test pricing with early adopters from community forums
Related Pain Points
Target Customers
- IT teams at mid-size organizations (100-2000 employees)
- MSPs and consultants managing multiple client environments
- Teams without dedicated specialist staff for this domain
Monetization Ideas
- 1SaaS subscription model ($99-$499/month depending on scale)
- 2Usage-based pricing aligned with value delivered
- 3Freemium tier to drive adoption and prove value