An Azure service that provides a general-purpose, serverless container platform.
Hi @Trevor Germain ,
The Microsoft Azure Team has investigated the issue you reported related to container app updates in the Container Apps environment (Canada Central). Between 18:08 UTC and 22:09 UTC on 1 October 2026, update operations on 20 container apps stayed in the InProgress provisioning state. New revisions were created and running, but the operations did not complete, and further updates to those apps were rejected with 409 ContainerAppOperationInProgress.
This issue was caused by a transient authorization error (HTTP 403) returned by Azure Resource Manager (ARM). It occurred at 18:10 UTC, when the Container Apps platform made a routine networking configuration request for the environment, against a resource that Azure manages for you. This was not related to permissions in your subscription. Because of the error, one environment-level operation stayed pending, and all container app updates in the environment queued behind it. Our investigation also found a platform defect: updates that did not change the app's ingress ports still waited on this operation when they should not have. The issue was not caused by your applications, container images or configuration.
At 22:09 UTC the pending operation was released. Nineteen of the 20 update operations then completed successfully. The update to stg-np-preprocessor completed with a Failed status; it was redeployed successfully on 2 October 2026 at 19:43 UTC. All 20 container apps are now in the Succeeded state, and later updates in the environment have completed normally. No action is required from you.
This transient ARM error has not recurred since 1 October in Canada Central or any other region. Thousands of identical requests have since completed normally, including on this environment. We therefore do not expect it to affect your production environment. The platform improvements below will also prevent a transient error of this kind from blocking container app updates in the future.
We are continuously taking steps to improve the service and our processes to ensure such incidents do not occur in the future, and in this case it includes (but is not limited to):
Ensuring container app updates that do not change ingress ports no longer wait on environment-level networking operations.
Improving how this operation recovers automatically from transient errors, so it can no longer stay pending for an extended period.
We apologize for any inconvenience. Please let us know if issue still persists or any further questions.