Allow IP Restrictions to be a Slot Setting
In the same way as we have with App Settings it should be possible to make the IP Restrictions a slot setting (sticky) so that they don't migrate when you swap slots. This could be per IP even....
Thank you for your feedback! IP restrictions are now sticky to the slot. (Meaning that a IP restriction on the production slot will stay there after the production and staging content is swapped.)
Wasn't the purpose of this to make it a setting, so one can choose if it should be sticky or not?
Jelmer de Jong commented
Access Restrictions for Azure WebApps are slot sticky now
Any progress - this is a major issue; we would like IP restrictions on a staging slot, but not on production once the slots are swapped.
Leo Tabakov commented
I believe that this feature should be optional, similarly to application settings. In our scenario we deploy applications and apply all settings including IP restrictions to "offline" slot. Then we execute tests against "offline" slot and only if all tests passed we perform slot swap.
We bought dedicated Application Gateways for each slot to get around all of the problems of going through a central Application Gateway/Web Application Firewall for all deployment environments. Well now we find out that IP Restrictions are not sticky to the deployment slots. Isn't this a fine mess? Please escalate this request as even throwing money at all the extra Gateways does not help us unless we open a gaping hole in security.
Must feature, please include
Jose Parra commented
We need this, please!!
I agree, it should be a setting, so that one can choose if it should be sticky or not.
Srihari Mylvaganam commented
Very important feature indeed!