Review App Service Python runtime support

Maintain security fixes and compatibility with a supported Python runtime and dependencies.

Description

End-of-support Python versions may stop receiving security fixes, increasing operational risk. The runtime also affects framework and package compatibility, so choose a version offered by App Service that remains under security support. A version is not necessarily unsupported simply because it is not the newest.

Potential impact

  • Known Python vulnerabilities may remain unfixed.
  • End of support or library incompatibility can increase operational work.

Remediation

Check App Service’s available runtimes and Python support periods. Set a supported version through site_config.application_stack.python_version on current Linux Web Apps and test the app and its main libraries. Review versions regularly so upgrades can occur before support ends.

Examples

The first excerpt is a historical Windows configuration using Python 2.7. Current built-in Python runtimes are supported on Linux. Supply an actual Linux plan ID and supported Python version to the second excerpt.

Before

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
    python_version           = "2.7"
  }
}

After

hcl
resource "azurerm_linux_web_app" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  service_plan_id     = var.service_plan_id

  site_config {
    application_stack {
      python_version = var.python_version
    }
  }
}

The revision uses current Linux Web App runtime settings. When moving an existing Windows app, also review operating-system differences such as dependencies and startup commands.

References