Update to Azure Disk Encryption extension for Linux - minor version change?

Sriramadhesikan, Sam 21 Reputation points
2020-10-01T13:18:02.317+00:00

Azure customers have been notified through an alert email asking them to prepare for breaking changes through an Azure Disk Encryption Extension. All the notification specifies is a general outline "to improve security, we are making potentially breaking changes to the Azure Disk Encryption extension to all Azure Regions on 1 November 2020. As a result, we are publishing extension changes" .

The linked Update page here:

https://gist.github.com/emmajdong/d3557f8f87a57afcab9026b150161da8

Does not specify what the new extension version is going to be. Is it a minor version change? A major version change?

Our existing ADE extensions are set up with auto_upgrade_minor_version = true. If this flag is set on the extension, will the upgrade be automatic? Or customers must manually trigger the extension despite setting auto_upgrade to true?

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
162 questions
0 comments No comments
{count} votes

Accepted answer
  1. deherman-MSFT 34,036 Reputation points Microsoft Employee
    2020-10-01T16:48:11.103+00:00

    @Sriramadhesikan, Sam
    I have confirmed with that the new Linux version will be 1.1.0.52 and Windows will be 2.2.0.35. This is not considered a minor version update, so even if auto_upgrade_minor_version = true, they will need to be updated manually following the process outlined in the document. The extension update will be available October 6th.

    Hope this helps. Please let us know if you have further questions or issues and we will do out best to assist.

    ------------------

    Please don’t forget to "Accept the answer" and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.


1 additional answer

Sort by: Most helpful
  1. Shanmuga Sundaram 1 Reputation point
    2020-10-22T20:39:21.983+00:00

    Dear MS: I have a question:

    I see this note under https://gist.github.com/emmajdong/d3557f8f87a57afcab9026b150161da8
    Does this mean the VM just need a reboot to get the new ADE version automatically?
    We have a maintenance where we reboot all VMs in couple of days for MS patching.

    Option 1: Reboot (Recommended)
    Identify a maintenance window for the impacted machine(s).
    Reboot the VM or Scale Set instances to trigger the goal state update to download the latest version of the extension on your machine(s).

    0 comments No comments