Azure Container Services Docs – Weekly Update (2025-12-28 to 2026-01-04)
The most meaningful Azure Kubernetes Service, Container Registry, Application Gateway for Containers, and Fleet Manager documentation changes from the last 7 days. Summaries are AI-filtered to skip trivial edits.
📊 Updates this week: ACR (1), AKS (23), Fleet (2)
|
||
| Security 🆕 New Modified: 2025-12-29 23:35 | ||
|
Summary A new article has been added that explains data encryption at rest concepts for Kubernetes secrets in Azure Kubernetes Service (AKS) using Azure Key Vault and the KMS provider. It covers key concepts, encryption models, and key management options available for protecting Kubernetes secrets at rest. |
||
|
|
||
| General 🆕 New Modified: 2025-12-29 23:35 | ||
|
Summary The documentation now includes a clear distinction between the legacy Key Management Service (KMS) experience and the new KMS data encryption experience for Azure Kubernetes Service (AKS). Users are advised to transition to the new KMS experience for clusters running Kubernetes version 1.33 or later, which provides enhanced features such as platform-managed keys and automatic key rotation. Additio… |
||
|
|
||
| General 🆕 New Modified: 2025-12-28 23:02 | ||
|
Summary The documentation now indicates that task agent pools are available in preview in additional regions, specifically Jio India West and Jio India Central, expanding the options for users in those areas. Additionally, the examples for the `–registry` parameter have been updated to use lowercase "myregistry" instead of "MyRegistry," ensuring consistency and clarity in command usage. |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-30 23:02 | ||
|
Summary The documentation for the "API Server Authorized IP Ranges in Azure Kubernetes Service (AKS)" article has been updated to clarify that users can now specify up to 200 authorized IP ranges, with the option to use API Server VNet Integration for up to 2,000 ranges. Additionally, the article now emphasizes that the rules for authorized IP ranges can take up to two minutes to propagate, which is impor… |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-29 23:35 | ||
|
Summary The documentation title has been updated to indicate that it pertains to the legacy Key Vault mode for Azure Kubernetes Service (AKS) clusters using KMS etcd encryption. This change clarifies that the content is specific to older configurations, helping users understand the context and applicability of the instructions provided. |
||
|
|
||
| General 🗑️ Removal Modified: 2025-12-29 23:35 | ||
|
Summary The documentation for the AKS cluster auto-upgrade feature has been updated to clarify that users can no longer upgrade the control plane separately from the node pools; the auto-upgrade process now upgrades both simultaneously. Additionally, the section on cluster autoupgrade limitations now specifies that running the `az aks upgrade –control-plane-only` command will result in an error, ensuring… |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-29 23:35 | ||
|
Summary The documentation has been updated to clarify troubleshooting steps for the AI-powered CLI agent for AKS. Users are now instructed to check their large language model (LLM) provider configuration and confirm cluster connectivity using the `kubectl cluster-info` command, with improved wording for clarity. Additionally, the guidance on handling installation failures and variable setup issues has bee… |
||
|
|
||
| General 🆕 New Modified: 2025-12-29 23:35 | ||
|
Summary The documentation now specifies that the EiT feature is available in preview starting with AKS version 1.33, and it clarifies that Ubuntu 20.04, Azure Linux, arm64, and Windows nodes are not currently supported. This update provides users with clearer information regarding the compatibility of the EiT feature with different node types. |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-29 23:35 | ||
|
Summary The documentation now clarifies that LRP is supported starting from Kubernetes v1.29 and Cilium v1.14. Additionally, it emphasizes that to prevent high Cilium identity generation in high-churning workloads like Spark jobs, users should exclude specific labels in the Cilium configmap. It also notes that AKS Local DNS is not compatible with Advanced Container Networking Services (ACNS) – FQDN Filter… |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-30 23:02 | ||
|
Summary The documentation for setting up a custom domain name and SSL certificate with the application routing add-on for Azure Kubernetes Service (AKS) has been updated to clarify the integration with Azure Key Vault and Azure DNS. Users can now find detailed instructions on configuring SSL/TLS certificates stored in Azure Key Vault and managing DNS zones with Azure DNS, including specific commands and p… |
||
|
|
||
| General 🆕 New Modified: 2025-12-30 06:02 | ||
|
Summary The documentation for creating and managing a Managed Fleet Namespace has been updated to clarify user access and configuration options. Users can now grant access to a Managed Fleet Namespace across member clusters using Azure RBAC built-in roles, and they can create a new Managed Fleet Namespace either from Fleet Manager or Kubernetes center. Additionally, the examples for member cluster names h… |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-29 23:35 | ||
|
Summary The documentation for the agentic CLI for AKS has been updated to clarify its capabilities, emphasizing that users can now ask natural language questions about their cluster’s health, configuration, and issues using the `az aks agent` command group. Additionally, the section on security considerations now specifies the need for proper role-based access control permissions and mentions Microsoft En… |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-30 23:02 | ||
|
Summary The documentation has been updated to reflect changes in the Azure DNS zone creation and configuration processes. Users can now create a global Azure DNS zone instead of a public one and enable Azure DNS integration for the application routing add-on, enhancing their ability to manage DNS settings effectively. |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-30 23:02 | ||
|
Summary The title of the document has been updated from "Azure Kubernetes Services (AKS) Core Concepts" to "Azure Kubernetes Service (AKS) Core Concepts," reflecting a change in terminology. Additionally, the content has been restructured for clarity, particularly in the sections describing key components like `kube-apiserver`, `etcd`, and `kube-scheduler`, which may enhance user understanding of their ro… |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-29 23:35 | ||
|
Summary The documentation now specifies that users should select **Infrastructure Services** instead of **Containers** when navigating to Azure Kubernetes Service (AKS) in the portal. Additionally, users can now change the preset configuration during cluster creation by selecting **Compare presets**, providing more flexibility in cluster setup. The recommended VM size has also been updated to **D2s_v5** f… |
||
|
|
||
| General 🆕 New Modified: 2025-12-30 23:02 | ||
|
Summary The documentation now includes an example of how the `nodeTaintsPolicy: Honor` setting affects pod distribution, enhancing user understanding of Kubernetes pod configuration. Additionally, the table formatting for LRS and ZRS storage options has been updated for clarity, providing users with clearer distinctions between the benefits and drawbacks of each storage type. These changes aim to improve… |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-29 23:35 | ||
|
Summary The documentation has been updated to reflect the legacy status of the observability features for Azure Kubernetes Service (AKS) clusters with Key Management Service (KMS) etcd encryption. Users can now find guidance on migrating to KMS v2 for etcd encryption, which is crucial for maintaining up-to-date security practices. Additionally, the title has been modified to indicate that the content pert… |
||
|
|
||
| General ✨ Update Modified: 2025-12-29 23:35 | ||
|
Summary Learn how to enable Key Management Service (KMS) data encryption with platform-managed keys or customer-managed keys in AKS. |
||
|
|
||
| Operations ✨ Update Modified: 2025-12-29 23:35 | ||
|
Summary Learn how to configure and customize rolling upgrades for Azure Kubernetes Service (AKS) node pools, including surge settings, drain timeout, and soak time. |
||
|
|
||
| Operations ✨ Update Modified: 2025-12-29 23:35 | ||
|
Summary Learn how to plan for capacity and costs when upgrading Azure Kubernetes Service (AKS) clusters, including surge node requirements, quota management, and IP address planning. |
||
|
|
||
| Operations ✨ Update Modified: 2025-12-29 23:35 | ||
|
Summary Learn how to upgrade the control plane of an Azure Kubernetes Service (AKS) cluster to get the latest Kubernetes version features and security updates. |
||
|
|
||
| Operations ♻️ Rework Modified: 2025-12-29 23:35 | ||
|
Summary The documentation for installing and using the Agentic CLI for Azure Kubernetes Service (AKS) has been updated to reflect changes in the installation process and to clarify the purpose of the CLI in troubleshooting clusters and gaining insights. |
||
|
|
||
| Security 🆕 New Modified: 2025-12-29 23:35 | ||
|
Summary The article has been updated to clarify that it applies to clusters using the legacy KMS experience that need to migrate from KMS v1 to KMS v2. It emphasizes the recommendation for clusters running Kubernetes version 1.33 or later to use the new KMS data encryption experience. |
||
|
|
||
| Networking 🆕 New Modified: 2025-12-30 23:02 | ||
|
Summary This new article provides guidance on using service tags for API server authorized IP ranges in Azure Kubernetes Service (AKS). It details the prerequisites, limitations, and installation steps for the `aks-preview` Azure CLI extension, enhancing the security and management of AKS clusters. |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-29 23:35 | ||
|
Summary The documentation for configuring HTTP and HTTPS proxies in Azure Kubernetes Service (AKS) has been updated to remove the trailing slashes from the proxy URLs. Users should now ensure that their proxy configurations do not include a trailing slash for proper functionality. |
||
|
|
||
| General ♻️ Rework Modified: 2025-12-30 06:02 | ||
|
Summary The documentation has been updated to clarify that users can now create and configure Managed Fleet Namespaces, enhancing their ability to manage Kubernetes resources. Additionally, users can view Managed Fleet Namespaces they have access to from both the Fleet Manager and Kubernetes center in the Azure portal, with specific instructions provided for navigating these interfaces. The commands for l… |
||
|
Full tracker with filters: Azure Container Services Docs Tracker