Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 22 additions & 3 deletions src/aks-preview/HISTORY.rst
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,28 @@ Pending
* `az aks nodepool update`: Preserve the existing GPU management mode when `--enable-managed-gpu` is omitted, including when enabling, updating, or disabling the cluster autoscaler.
* `az aks alert-config add`: Reject an empty `--name` before looking up existing configurations instead of reporting that it already exists.
* `az aks nodepool scale`: add `--use-patch-api` to optionally scale a VMSS node pool via the new dedicated PATCH agent pool API (scales to the target count without triggering full reconciliation). The default behavior continues to use the PUT agent pool API.
* `az aks create` and `az aks update`: Reject `--enable-azure-monitor-logs` on clusters using service principal authentication, since the Azure Monitor profile onboards with managed identity only.
* `az aks update`: Reject `--enable-azure-monitor-logs` when Azure Monitor logs is already enabled on the cluster, matching `az aks enable-addons -a monitoring`. Run `--disable-azure-monitor-logs` first to change the configuration.
* `az aks update`: `--disable-azure-monitor-logs` now removes the data collection rule association and resets the Container Insights settings (syslog port, Prometheus scraping and container network logs) back to their defaults, and asks for confirmation when OpenTelemetry logs and traces are enabled.
* `az aks update`: Fix `--enable-azure-monitor-logs` not creating the data collection rule and association unless the Log Analytics workspace changed, which left the agent running with no data collection rule attached so no logs were ingested.
* `az aks update`: Create the data collection rule and association before the cluster update when enabling with `--enable-azure-monitor-logs`, matching `az aks enable-addons -a monitoring`. Provisioning them afterwards meant the agent started before the association existed and then stayed idle for several minutes before restarting once the configuration arrived.
* `az aks update`: Declining the OpenTelemetry confirmation prompt for `--disable-azure-monitor-metrics` now leaves the cluster unchanged and exits without an error, matching every other confirmation prompt, instead of failing the command.
* `az aks enable-addons`, `az aks addon enable` and `az aks addon update`: Warn that shared key authentication for the monitoring addon is deprecated when `--enable-msi-auth-for-monitoring false` is passed, and point to `--enable-azure-monitor-logs`. The warning reflects the value you supply, so it stays silent when the flag is omitted on a cluster using service principal authentication.
* `az aks update`: Fix `--enable-syslog`, `--data-collection-settings` and `--ampls-resource-id` being silently ignored when supplied on their own, as none of them re-provisioned the data collection rule that carries them, so the command reported success while the agent kept using the previous rule.
* `az aks update`: Reject the OpenTelemetry port flags (`--opentelemetry-metrics-port-http`, `--opentelemetry-metrics-port-grpc`, `--opentelemetry-logs-traces-port-http` and `--opentelemetry-logs-traces-port-grpc`) when the matching receiver is being disabled in the same command, instead of accepting the port and then silently dropping it.
* `az aks update`: Collect every monitoring disable confirmation before any of them deletes collection resources. Combining `--disable-azure-monitor-logs` with `--disable-azure-monitor-metrics` used to delete the logs data collection rule and association before asking about metrics, so declining that prompt aborted the command with Container Insights still enabled on the cluster but its collection objects already removed.
* `az aks disable-addons`: Disabling the `monitoring` addon now resets the Container Insights settings (syslog port, Prometheus scraping and container network logs) back to their defaults and turns off OpenTelemetry logs and traces, matching `az aks update --disable-azure-monitor-logs`. The addon settings used to survive the disable and were silently inherited by the next onboarding.
* `az aks disable-addons`: Ask for confirmation before disabling the `monitoring` addon when OpenTelemetry logs and traces are enabled, since that collection is disabled along with it. Add `--yes` to skip the prompt.
* `az aks disable-addons`: Fix the monitoring cleanup being skipped when `monitoring` was passed alongside other addons, for example `--addons monitoring,azure-policy`.
* `az aks update`: Reset the Container Insights settings to their defaults when `--enable-azure-monitor-logs` re-onboards a cluster, so a previous onboarding's syslog port, Prometheus scraping and container network logs settings are no longer inherited.
* `az aks update`: Preserve the existing data collection rule settings when reconfiguring a cluster that is already onboarded, so that changing one setting no longer drops the others. `--enable-syslog` on its own used to rebuild the rule without the cluster's high log scale mode, custom data collection settings and ingestion data collection endpoint, and `--data-collection-settings` on its own used to drop syslog. Enabling Azure Monitor logs still starts from the documented defaults.
* `az aks create` and `az aks update`: Reject the OpenTelemetry port flags at argument validation time when the matching receiver is being disabled in the same command. The conflict was previously caught only after the Azure Monitor collection resources had already been removed, so the command failed with the cluster partially torn down.
* `az aks disable-addons`: Validate every addon name and its installed state before any cleanup runs. Disabling an unknown or not-installed addon alongside `monitoring` used to delete the monitoring data collection rule association first and only then fail, skipping the cluster update and leaving monitoring enabled with nothing to collect into.
* Fix `--enable-high-log-scale-mode` mutating the shared list of Container Insights streams, so the stream set leaked between data collection rules built in the same command invocation.
* `az aks create` and `az aks update`: Fix the `--data-collection-settings` size limit being applied to the file path instead of the settings it holds, which let an oversized file through to fail the data collection rule call with `Request Header Fields Too Large`.
* `az aks update`: Fix `--enable-syslog false` being rejected with `Please specify one or more of "--enable-syslog"` after prompting to reconcile the cluster. Explicitly turning syslog collection off is a real update request, but the falsy value made the command treat it as though no argument had been supplied.
* `az aks update`: Stop reopening public network access on the ingestion data collection endpoint of a cluster that is linked to an Azure Monitor Private Link Scope. The endpoint is created or updated on every reconfiguration, but `--ampls-resource-id` is only supplied on the command that links the scope, so an unrelated update such as `--enable-syslog` used to flip an existing private endpoint back to public. The existing network configuration is now preserved unless the caller explicitly asks to change it.
* `az aks update`: Fix `--ampls-resource-id` being rejected with `--ampls-resource-id can only be used with private cluster in MSI mode.` on a cluster that is already private. The private state was only read from the command line, so it was invisible unless `--enable-private-cluster` happened to be supplied again in the same command; it is now read from the cluster as well.

22.0.0b8
+++++++++
Expand Down Expand Up @@ -793,7 +815,6 @@ Pending
* Update --enable-advanced-network-observability description to note additional costs and add missing flag to create command.
* Change default value of `--vm-set-type` to VirtualMachines when `--vm-sizes` is set.


4.0.0b5
++++++++
* Add warnings to `az aks mesh` commands for out of support asm revision in use.
Expand Down Expand Up @@ -888,7 +909,6 @@ Pending
* Add `--sku` to the `az aks update` command.
* Support cluster service health probe mode by `--cluster-service-load-balancer-health-probe-mode {Shared, Servicenodeport}`


3.0.0b1
+++++++
* [BREAKING CHANGE] Remove support for nodeSelector for egress gateway for `az aks mesh` command.
Expand Down Expand Up @@ -1010,7 +1030,6 @@ Pending
* Add `--node-soak-duration` to the `az aks nodepool add/update/upgrade` commands.
* Add `--drain-timeout` to the `az aks nodepool add/update/upgrade` commands (already in [azure-cli](https://github.com/Azure/azure-cli/pull/27475)).


0.5.168
+++++++
* Add `--enable-image-integrity` to the `az aks update` command.
Expand Down
8 changes: 8 additions & 0 deletions src/aks-preview/azext_aks_preview/_consts.py
Original file line number Diff line number Diff line change
Expand Up @@ -188,6 +188,14 @@
CONST_MONITORING_LOG_ANALYTICS_WORKSPACE_RESOURCE_ID = "logAnalyticsWorkspaceResourceID"
CONST_MONITORING_USING_AAD_MSI_AUTH = "useAADAuth"

# container network logs (azureMonitorProfile.containerInsights.containerNetworkLogs)
CONST_CONTAINER_NETWORK_LOGS_ENABLED = "Enabled"
CONST_CONTAINER_NETWORK_LOGS_DISABLED = "Disabled"
# legacy omsagent addon config key, superseded by containerNetworkLogs on the AMP path
CONST_MONITORING_ENABLE_RETINA_NETWORK_FLAGS = "enableRetinaNetworkFlags"
# server-side default for azureMonitorProfile.containerInsights.syslogPort
CONST_CONTAINER_INSIGHTS_DEFAULT_SYSLOG_PORT = 28330

# virtual node
CONST_VIRTUAL_NODE_ADDON_NAME = "aciConnector"
CONST_VIRTUAL_NODE_SUBNET_NAME = "SubnetName"
Expand Down
37 changes: 34 additions & 3 deletions src/aks-preview/azext_aks_preview/_help.py
Original file line number Diff line number Diff line change
Expand Up @@ -197,7 +197,9 @@
- name: --enable-azure-monitor-logs
type: bool
short-summary: Enable Azure Monitor logs for the cluster.
long-summary: This is equivalent to using "--enable-addons monitoring". Turn on Log Analytics monitoring. Uses the Log Analytics Default Workspace if it exists, else creates one. Specify "--workspace-resource-id" to use an existing workspace. If monitoring addon is enabled --no-wait argument will have no effect
long-summary: |
Enables Log Analytics monitoring for the cluster through the Azure Monitor profile. Uses the Log Analytics Default Workspace if it exists, else creates one. Specify "--workspace-resource-id" to use an existing workspace.
Requires the cluster to use a managed identity; clusters created with service principal authentication are not supported.
- name: --disable-rbac
type: bool
short-summary: Disable Kubernetes Role-Based Access Control.
Expand Down Expand Up @@ -338,6 +340,16 @@
- name: --ampls-resource-id
type: string
short-summary: Resource ID of Azure Monitor Private Link scope for Monitoring Addon.
- name: --syslog-port
type: int
short-summary: Host port used by the Azure Monitor agent to collect syslog. Defaults to 28330 when unset.
long-summary: Applies to the Azure Monitor profile, configured with --enable-azure-monitor-logs. Distinct from --enable-syslog, which toggles syslog collection itself.
- name: --enable-prometheus-metrics-scraping
type: bool
short-summary: Enable Prometheus metrics scraping by the Azure Monitor agent. Applies to the Azure Monitor profile.
- name: --disable-prometheus-metrics-scraping
type: bool
short-summary: Disable Prometheus metrics scraping by the Azure Monitor agent. Applies to the Azure Monitor profile.
- name: --enable-cluster-autoscaler
type: bool
short-summary: Enable cluster autoscaler, default value is false.
Expand Down Expand Up @@ -869,6 +881,8 @@
text: az aks create -g MyResourceGroup -n MyManagedCluster --enable-opentelemetry-logs-traces --enable-addons monitoring
- name: Create a kubernetes cluster with Azure Monitor logs enabled (shorthand)
text: az aks create -g MyResourceGroup -n MyManagedCluster --enable-azure-monitor-logs
- name: Create a kubernetes cluster with Azure Monitor logs, Prometheus scraping disabled and a custom syslog port
text: az aks create -g MyResourceGroup -n MyManagedCluster --enable-azure-monitor-logs --disable-prometheus-metrics-scraping --syslog-port 28331
- name: Create a kubernetes cluster with OpenTelemetry metrics on custom port
text: az aks create -g MyResourceGroup -n MyManagedCluster --enable-opentelemetry-metrics --opentelemetry-metrics-port-http 8888 --enable-azure-monitor-metrics
- name: Create a kubernetes cluster with OpenTelemetry logs and traces on custom ports
Expand Down Expand Up @@ -1143,11 +1157,16 @@
- name: --enable-azure-monitor-logs
type: bool
short-summary: Enable Azure Monitor logs for the cluster.
long-summary: This is equivalent to using "az aks enable-addons -a monitoring". Enables Log Analytics monitoring for the cluster. Uses the Log Analytics Default Workspace if it exists, else creates one. Specify "--workspace-resource-id" to use an existing workspace. If monitoring addon is enabled --no-wait argument will have no effect
long-summary: |
Enables Log Analytics monitoring for the cluster through the Azure Monitor profile. Uses the Log Analytics Default Workspace if it exists, else creates one. Specify "--workspace-resource-id" to use an existing workspace.
Requires the cluster to use a managed identity; clusters using service principal authentication are not supported.
Fails if Azure Monitor logs is already enabled on the cluster, or if the cluster was onboarded with legacy (non-managed-identity) authentication. To change the configuration, run "az aks update --disable-azure-monitor-logs" first.
- name: --disable-azure-monitor-logs
type: bool
short-summary: Disable Azure Monitor logs for the cluster.
long-summary: This is equivalent to using "az aks disable-addons -a monitoring". Disables Log Analytics monitoring for the cluster.
long-summary: |
Disables Log Analytics monitoring for the cluster, removes the data collection rule association, and resets the Container Insights settings (syslog port, Prometheus scraping and container network logs) back to their defaults. The workspace is left recorded on the profile but is unused while disabled, and is replaced on the next enable.
If OpenTelemetry logs and traces are enabled they are disabled as well, and confirmation is requested first unless "--yes" is specified.
- name: --workspace-resource-id
type: string
short-summary: The resource ID of an existing Log Analytics Workspace to use for storing monitoring data. If not specified, uses the default Log Analytics Workspace if it exists, otherwise creates one.
Expand All @@ -1166,6 +1185,16 @@
- name: --ampls-resource-id
type: string
short-summary: Resource ID of Azure Monitor Private Link scope for Monitoring Addon.
- name: --syslog-port
type: int
short-summary: Host port used by the Azure Monitor agent to collect syslog. Defaults to 28330 when unset.
long-summary: Applies to the Azure Monitor profile, configured with --enable-azure-monitor-logs. Distinct from --enable-syslog, which toggles syslog collection itself.
- name: --enable-prometheus-metrics-scraping
type: bool
short-summary: Enable Prometheus metrics scraping by the Azure Monitor agent. Applies to the Azure Monitor profile.
- name: --disable-prometheus-metrics-scraping
type: bool
short-summary: Disable Prometheus metrics scraping by the Azure Monitor agent. Applies to the Azure Monitor profile.
- name: --enable-secret-rotation
type: bool
short-summary: Enable secret rotation. Use with azure-keyvault-secrets-provider addon.
Expand Down Expand Up @@ -1715,6 +1744,8 @@
text: az aks update -g MyResourceGroup -n MyManagedCluster --safeguards-level Warning --safeguards-excluded-ns ns1,ns2
- name: Enable Azure Monitor logs for a kubernetes cluster
text: az aks update -g MyResourceGroup -n MyManagedCluster --enable-azure-monitor-logs
- name: Re-enable Prometheus scraping and change the syslog port on a cluster with Azure Monitor logs enabled
text: az aks update -g MyResourceGroup -n MyManagedCluster --enable-prometheus-metrics-scraping --syslog-port 29000
- name: Enable Azure Backup for a kubernetes cluster (default Week strategy). Requires the 'dataprotection' extension.
text: az aks update -g MyResourceGroup -n MyManagedCluster --enable-backup --yes
- name: Enable Azure Backup with a custom strategy using an existing vault and policy
Expand Down
Loading
Loading