[{"author":"learn-build-service-prod","date":"2026-09-14T16:52:15+00:00","message":"Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/azure-docs (branch main) (#320467)\n\n* Note that Newtonsoft serialization attributes stop working after migration (#128734)\n\nFollow-up to the `AllowSynchronousIO` clarification in #128726 and the *Migrate to asynchronous HTTP stream I/O* section that was added alongside it. That async guidance is correct as written: replacing `ReadToEnd` with `ReadToEndAsync` keeps the same serializer, so a migrated app keeps behaving identically. This PR covers a step of the migration that isn't behavior-preserving.\n\n## Problem\n\nThe in-process model used *Newtonsoft.Json*. The isolated worker model uses *System.Text.Json* by default. Types that a migrated app binds to usually still carry *Newtonsoft.Json* attributes (`[JsonProperty(\"customer_name\")]` being the common one), and *System.Text.Json* doesn't recognize them. It binds the affected property to its default value and reports nothing: HTTP 200, property `null`, no exception and no log entry.\n\nThe *JSON serialization* section of this guide covers the serializer switch itself and links to *Customizing JSON serialization* for options and for moving back to JSON.NET. It says nothing about the attributes already sitting on the reader's types. `JsonProperty` and `JsonPropertyName` currently appear nowhere in this guide, its includes, or `dotnet-isolated-process-guide.md`, so a reader whose property silently stops binding has nothing to search for.\n\nMeasured on `Microsoft.Azure.Functions.Worker` 2.52.0, `Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore` 2.1.1, Core Tools 4.13.0, host 4.1051.300.26316: a DTO carrying `[JsonProperty(\"customer_name\")]` binds to `null` on every input path tested while the app stays on *System.Text.Json*, with no diagnostic on any of them.\n\n## Change\n\nOne file, one added paragraph, nothing removed: note that *Newtonsoft.Json* serialization attributes carried over from the in-process model are ignored by *System.Text.Json* without an error. The paragraph gives the two ways out: replace them with their *System.Text.Json* equivalents, or configure *Newtonsoft.Json* for the layer that handles the payload.\n\n## Notes for review\n\nThe edited file is an include, `includes/functions-dotnet-migrate-isolated-other-code-changes.md`. It renders inside `articles/azure-functions/migrate-dotnet-to-isolated-model.md`, which is also the file changed by my open PR #128730. The two touch different files and don't conflict, but they land on the same rendered page, so you may want to look at them together.\n\n\"Configure *Newtonsoft.Json* for the layer that handles the payload\" is deliberately unspecific about which layer, because that depends on whether the app uses ASP.NET Core integration. There's a companion change for `articles/azure-functions/dotnet-isolated-process-guide.md` that makes that distinction precise; it's a different file with a different owner, so I'm submitting it separately. Either change stands on its own.\n\n* Include Fluent Bit ConfigMap for log collection (#128767)\n\nAdded Fluent Bit configuration examples for log collection using Azure Files in AKS. and added support limitation.\n\n* Document listSecrets access granted by Container Apps built-in roles (#128755)\n\n* Document listSecrets access in Container Apps built-in roles\n\nSeveral Container Apps built-in roles define permissions with wildcard\npatterns that match the listSecrets action, so they grant read access to\nsecret values in plain text even when the role name or description\nsuggests narrower access.\n\n- manage-secrets.md: add a 'Permissions for managing secrets' section\n  listing the built-in roles that grant listSecrets, plus a custom role\n  example that omits it.\n- jobs.md: correct the Permissions section to name the Jobs Contributor\n  and Jobs Operator roles, call out that both grant listSecrets, and fix\n  the custom role action list (executions/read, stop/action,\n  managedEnvironments/read).\n- security.md: add secrets management best practices covering role\n  review and custom roles.\n\nRoles verified against live ARM role definitions and\narticles/role-based-access-control/built-in-roles/containers.md.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\n* Correct claim that a custom role without listSecrets blocks secret access\n\nThe job start API accepts a template override that replaces the container\nimage, command, and environment variables for the execution. An identity\nholding only Microsoft.App/jobs/start/action can therefore run an\narbitrary container with the job's secrets injected and read the values\nfrom inside it. Omitting listSecrets from a custom role does not prevent\nthis, so the previous guidance was misleading.\n\n- jobs.md: replace the vague 'you get access to all the secrets' note\n  with an IMPORTANT callout explaining the override mechanism, and stop\n  presenting the custom role action list as a way to run jobs without\n  secret access.\n- manage-secrets.md: change the custom role example to a monitor-only\n  role that omits start/action, and add a WARNING covering the\n  start/action escalation path.\n\nVerified against the job start REST contract documented in jobs.md and\nthe --image/--command/--env-vars parameters of 'az containerapp job start'.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\n* Clarify Container Apps job permissions and secret access\n\nRefine the role guidance after review:\n- explain that job start can reference retained secrets rather than\n  implying all secrets are injected automatically\n- qualify managed identity access by container identity availability\n- link directly to the Jobs - Start REST API\n- replace Contributor requirements with jobs/start/action\n- add individual execution read and stop operations to custom roles\n- correct wildcard and ConnectedEnvironments role descriptions\n- normalize the permissions table and scope the jobs-specific warning\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\n* Address Container Apps permissions review findings\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\n* Clarify Container Apps secret access guidance\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\n* Update articles/container-apps/jobs.md\n\n* Update articles/container-apps/jobs.md\n\nCo-authored-by: Craig Shoemaker <craigshoemaker@gmail.com>\n\n---------\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCo-authored-by: Craig Shoemaker <craigshoemaker@gmail.com>\n\n* Add FAQ about multiple X-Azure-Ref values (#128749)\n\n* Add FAQ about multiple X-Azure-Ref values\n\n      - question: Why do I see multiple X-Azure-Ref values in my backend application logs when requests pass through Azure Front Door?\n        answer: The X-Azure-Ref value displayed in the client response and Azure Front Door access logs represents the primary request correlation identifier generated by Azure Front Door. Additional X-Azure-Ref values observed only in backend application logs are expected and are internal correlation identifiers generated during request processing within the Azure Front Door platform. These internal identifiers are used by the service for request tracking and diagnostics and don't indicate multiple client requests.\n\n* Potential fix for pull request finding\n\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\n\n* docs: remove duplicate 'the' in NSG diagnostics comments (#128783)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* Clarify Prometheus counter visibility (#128772)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: 09f5c5be-413a-4b74-b070-c848484e0d73\n\n* docs: fix 'enviroment' typo in Data Factory access strategies (#128774)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'for' in Azure NetApp Files clone FAQ (#128775)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'to' in private link relocation guide (#128776)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'the' in Logic Apps Reassert docs (#128777)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'the' in storage task runs alt-text (#128781)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'the' in WebJobs deploy alt-text (#128780)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'to' in Container Apps volume mount error (#128778)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'to' in Functions identity-based connections (#128779)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'the' in SignalR Front Door alt-text (#128784)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'the' in Site Recovery reprotect guide (#128785)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'the' in Batch upgrade policy note (#128782)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'the' in Planetary Computer ingestion overview (#128786)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n* docs: remove duplicate 'the' in IoT Edge downstream device guide (#128787)\n\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\n\n---------\n\nCo-authored-by: learn-build-service-prod[bot] <113403604+learn-build-service-prod[bot]@users.noreply.github.com>\nCo-authored-by: Fabian <info@fzankl.de>\nCo-authored-by: jacobbaek <dubaek@gmail.com>\nCo-authored-by: Learn Build Service GitHub App <Learn Build Service LearnBuild@microsoft.com>\nCo-authored-by: Tiago Alves Macambira <tmacam@burocrata.org>\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCo-authored-by: Craig Shoemaker <craigshoemaker@gmail.com>\nCo-authored-by: Jagan Peddabavi <157447885+Jpeddabavi@users.noreply.github.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\nCo-authored-by: mrchatam <chatam@proton.me>\nCo-authored-by: mrchatam <mrchatam@users.noreply.github.com>\nCo-authored-by: Kelly Shields <kellyshields@microsoft.com>\nCopilot-Session: 09f5c5be-413a-4b74-b070-c848484e0d73","sha":"e51d1a135b2f3c560082e5a227af03d5edb54f3c","url":"https://github.com/MicrosoftDocs/azure-docs/commit/e51d1a135b2f3c560082e5a227af03d5edb54f3c"},{"author":"kshimazu-ms","date":"2026-09-04T14:32:23+00:00","message":"Document cross-signed certificate support in domain.md\n\nAdded information about cross-signed certificate support for Azure Front Door.","sha":"1bf5e9dee0e23171beea3fd857cce1dac7386c5d","url":"https://github.com/MicrosoftDocs/azure-docs/commit/1bf5e9dee0e23171beea3fd857cce1dac7386c5d"},{"author":"halkazwini","date":"2026-09-01T17:26:41+00:00","message":"docs: update Front Door billing link to unicast","sha":"ac323e5a6cfdd95dda5d6397c171014d58c35037","url":"https://github.com/MicrosoftDocs/azure-docs/commit/ac323e5a6cfdd95dda5d6397c171014d58c35037"},{"author":"halkazwini","date":"2026-09-01T09:21:47+00:00","message":"docs: scope Front Door WAF managed-rules guidance to Premium","sha":"cbe43864bfadd81a617a70873b12fb7b298f077c","url":"https://github.com/MicrosoftDocs/azure-docs/commit/cbe43864bfadd81a617a70873b12fb7b298f077c"},{"author":"halkazwini","date":"2026-09-01T08:02:35+00:00","message":"docs: update Front Door references to unicast","sha":"dfd17a9e5e10b60de641fc323fc33993dac76449","url":"https://github.com/MicrosoftDocs/azure-docs/commit/dfd17a9e5e10b60de641fc323fc33993dac76449"},{"author":"halkazwini","date":"2026-08-27T17:29:30+00:00","message":"Add post-migration endpoint cutover guidance to tier migration articles (#319970)\n\n* Update tier-migration.md\n\n* Add post-migration endpoint cutover details\n\nAdded post-migration instructions for Azure Front Door endpoints, including DNS updates and hostname replacements. Included a warning about the deadline for endpoint cutover.\n\n* Update migrate-tier-powershell.md\n\n* Add post-migration endpoint cutover guidance to tier migration articles\n\n* Apply editorial style and clarity improvements to tier migration articles\n\n* Use bullet list for post-migration endpoint cutover actions\n\n* docs: update stale DNS records link to post-migration endpoint cutover section\n\n---------\n\nCo-authored-by: Jessie <jessiejyy16@outlook.com>","sha":"d248380fa3512f5e3bd1699afb93ffa54887a1dd","url":"https://github.com/MicrosoftDocs/azure-docs/commit/d248380fa3512f5e3bd1699afb93ffa54887a1dd"},{"author":"halkazwini","date":"2026-08-26T21:14:14+00:00","message":"Revise Front Door and CDN classic tier migration guidance (#319927)\n\n* Update migrate-tier.md\n\n* Update migrate-tier.md\n\n* Update migration-faq.md\n\n* docs: remove trailing whitespace from imported content\n\n* Revise Front Door migration guidance\n\n* Revise classic tier migration guidance\n\n* docs: remove trailing periods from related content links\n\n* docs: fix note indentation and update endpoint cutover link\n\n* docs: fix broken relative link to Front Door endpoint article\n\n* Apply suggestions from PR review\n\nUse bullets instead of numbers for nonsequential lists.\n\n---------\n\nCo-authored-by: Jessie <jessiejyy16@outlook.com>\nCo-authored-by: Anna Huff <v-annahuff@microsoft.com>","sha":"dabd4ce9b8a95bddb52da5b5fb6cecf4160f91b3","url":"https://github.com/MicrosoftDocs/azure-docs/commit/dabd4ce9b8a95bddb52da5b5fb6cecf4160f91b3"},{"author":"prmerger-automator","date":"2026-08-24T18:21:47+00:00","message":"Merge pull request #319767 from halkazwini/afd-faq-tweaks\n\nImprove Azure Front Door FAQ language","sha":"707795b659c9b125bcd31bb919eb5b3b065c5872","url":"https://github.com/MicrosoftDocs/azure-docs/commit/707795b659c9b125bcd31bb919eb5b3b065c5872"},{"author":"halkazwini","date":"2026-08-24T17:42:33+00:00","message":"docs: improve Front Door routing article structure","sha":"aeee7d80f12d9b8e5f1bf1643f0ed2d0f86fd225","url":"https://github.com/MicrosoftDocs/azure-docs/commit/aeee7d80f12d9b8e5f1bf1643f0ed2d0f86fd225"},{"author":"halkazwini","date":"2026-08-24T17:21:28+00:00","message":"Merge branch 'main' of https://github.com/MicrosoftDocs/azure-docs-pr into afd-origin-retry-behavior","sha":"69c671f9659dcaec7fc2f317d3083caa8ef3c0f4","url":"https://github.com/MicrosoftDocs/azure-docs/commit/69c671f9659dcaec7fc2f317d3083caa8ef3c0f4"},{"author":"halkazwini","date":"2026-08-24T17:21:13+00:00","message":"docs: finalize Front Door retry guidance","sha":"7f45ab91cfdfe30474fe79cf5b961637ac3292d2","url":"https://github.com/MicrosoftDocs/azure-docs/commit/7f45ab91cfdfe30474fe79cf5b961637ac3292d2"},{"author":"kshimazu-ms","date":"2026-08-24T17:17:55+00:00","message":"Clarify Azure Front Door origin retry behavior","sha":"aec203c935d9d00f92f7126adbb7933e67fc6a2e","url":"https://github.com/MicrosoftDocs/azure-docs/commit/aec203c935d9d00f92f7126adbb7933e67fc6a2e"},{"author":"halkazwini","date":"2026-08-21T23:23:27+00:00","message":"tier name corrections","sha":"a557c8600b8f69086a9fabaabca96cdd2225aeee","url":"https://github.com/MicrosoftDocs/azure-docs/commit/a557c8600b8f69086a9fabaabca96cdd2225aeee"},{"author":"halkazwini","date":"2026-08-21T23:20:19+00:00","message":"tweaks","sha":"27d167ef0912136093e7888b8cd79f4c9bd9393f","url":"https://github.com/MicrosoftDocs/azure-docs/commit/27d167ef0912136093e7888b8cd79f4c9bd9393f"},{"author":"halkazwini","date":"2026-08-21T23:12:11+00:00","message":"docs: improve Front Door FAQ language","sha":"5cd4c8caf8289d94325e526d5a599822a7b901f6","url":"https://github.com/MicrosoftDocs/azure-docs/commit/5cd4c8caf8289d94325e526d5a599822a7b901f6"},{"author":"halkazwini","date":"2026-08-21T20:50:43+00:00","message":"docs: refresh Front Door FAQ metadata","sha":"87d33cefb65452bcad00f75430ded7ebad5bd362","url":"https://github.com/MicrosoftDocs/azure-docs/commit/87d33cefb65452bcad00f75430ded7ebad5bd362"},{"author":"halkazwini","date":"2026-08-21T20:41:44+00:00","message":"docs: update Front Door unicast FAQ","sha":"3164be29577bb1bea59f36c2d5fa8ac2d8764ae4","url":"https://github.com/MicrosoftDocs/azure-docs/commit/3164be29577bb1bea59f36c2d5fa8ac2d8764ae4"},{"author":"halkazwini","date":"2026-08-20T16:46:21+00:00","message":"docs: refine Front Door origin retry guidance","sha":"f4ce69e4277921bb6e7622e2be317f4108138325","url":"https://github.com/MicrosoftDocs/azure-docs/commit/f4ce69e4277921bb6e7622e2be317f4108138325"},{"author":"kshimazu-ms","date":"2026-08-20T16:45:42+00:00","message":"Update TCP connection retry conditions in documentation\n\nClarify conditions for Azure Front Door TCP connection retries.","sha":"0629fad4ed7bdce3f749a0af470a807d971d05e5","url":"https://github.com/MicrosoftDocs/azure-docs/commit/0629fad4ed7bdce3f749a0af470a807d971d05e5"},{"author":"kshimazu-ms","date":"2026-08-20T16:45:42+00:00","message":"Clarify origin retry behavior for Azure Front Door priority routing\n\nAdded information about retrying requests against eligible origins when the primary origin is unreachable.","sha":"b04b5e3542924126a34236698afe2f549a603f65","url":"https://github.com/MicrosoftDocs/azure-docs/commit/b04b5e3542924126a34236698afe2f549a603f65"}]
