Azure Container Services Docs – Weekly Update (2026-04-05 to 2026-04-12)
The most meaningful Azure Kubernetes Service, AKS Arc, Container Registry, Application Gateway for Containers, and Fleet Manager documentation changes from the last 7 days. AKS everywhere! Summaries are AI-filtered to skip trivial edits.
📊 Updates this week: ACR (2), AGC (3), AKS (69), Fleet (4)
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary Clarified documentation regarding Azure Linux with OS Guard for AKS, ensuring users have accurate information. |
||
|
|
||
|
General ACR Modified: 2026-04-06 22:08 |
||
|
Summary The article has been revised to improve clarity on managing service health notifications, including updated links to relevant Azure portal documentation. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary This document has been updated with new author metadata, which is important for recognizing contributions and ensuring proper attribution. |
||
|
|
||
|
General AKS Modified: 2026-04-07 22:08 |
||
|
Summary The documentation has been updated to include Terraform examples for deploying an AKS cluster with OpenID Connect (OIDC) issuer and Microsoft Entra Workload ID enabled. This improves the clarity and accessibility of the deployment process. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary Links to the Kaito fine-tuning documentation were added, providing users with direct access to relevant resources for fine-tuning language models. |
||
|
|
||
|
General Fleet Modified: 2026-04-07 06:01 |
||
|
Summary The documentation for the placement policy section has been updated to clarify that users should define how to pick clusters using the `placementType` parameter instead of the previously mentioned `placeType`. This change ensures that users are accurately informed about the correct terminology and usage when configuring cluster selection methods. Minor typographical errors have also been corrected for improved clarity. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary This document has been updated with new author metadata. The changes include updates to the author fields, which may reflect a change in the content ownership or contributions. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary This document has been updated to reflect changes in authorship, ensuring that the information is current and accurately attributed. |
||
|
|
||
|
Security AKS Modified: 2026-04-07 22:08 |
||
|
Summary The documentation now clarifies that the built-in role binding `aks-service-rolebinding` for the `aks-service` role is specifically bound to the `aks-support` Microsoft Support service identity. This change enhances user understanding of how Microsoft/AKS manages cluster actions with user consent, providing more transparency regarding the role of support services in cluster operations. |
||
|
|
||
|
Networking AGC Modified: 2026-04-09 18:37 |
||
|
Summary The documentation for Application Gateway for Containers has been updated to include connectivity requirements necessary for successful operation, detailing specific endpoints and ports required for various functionalities. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary This document provides customer stories showcasing the benefits of Windows containers on Azure Kubernetes Service (AKS), highlighting improvements in operational efficiency and reduced support costs. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary The documentation for the AKS HTTP proxy has been updated to correct the casing of the "trustedCA" parameter to "trustedCa." This change ensures consistency and may prevent potential issues for users configuring trusted certificates in their AKS environments. Users should now refer to the updated parameter name for accurate configuration. |
||
|
|
||
|
Operations AKS Modified: 2026-04-06 22:07 |
||
|
Summary This document has been updated to improve clarity regarding the rolling upgrade process for AKS node pools, ensuring users understand the steps involved. |
||
|
|
||
|
General AKS Modified: 2026-04-07 22:08 |
||
|
Summary The documentation has been updated to clarify the requirements for updating Cilium Network Policies to enable DNS resolution with Azure LocalDNS. Users can now find specific guidance on implementing CIDR-based policies for Azure CNI Powered by Cilium versions up to v1.16 with Kubernetes versions up to 1.31, and Cilium Network Policies for versions v1.17 and above with Kubernetes 1.32 and above. Additionally, the section titles have been revised for better clarity and relevance. |
||
|
|
||
|
Compute AKS Modified: 2026-04-10 06:02 |
||
|
Summary The documentation now emphasizes the need for careful planning when upgrading node pools, particularly for stateful workloads to ensure data consistency during migration. Users are informed that they will require double the node capacity during the upgrade process, which may lead to increased infrastructure costs and necessitate extra compute quota in their Azure subscription. Additionally, the overall upgrade duration is longer compared to in-place upgrades, with a validation period that adds time before the final cutover. |
||
|
|
||
|
Networking AKS Modified: 2026-04-06 22:07 |
||
|
Summary The documentation for deploying AKS clusters has been updated to correct the parameter name for API Server VNet integration from `–enable-api-server-vnet-integration` to `–enable-apiserver-vnet-integration`. This change affects the commands used for both public and private AKS cluster deployments, ensuring users utilize the correct syntax for enabling API Server VNet integration. |
||
|
|
||
|
Compliance AKS Modified: 2026-04-09 06:02 |
||
|
Summary Starting on March 17, 2027, Azure Kubernetes Service (AKS) will no longer support or provide security updates for Ubuntu 20.04. Users are advised to migrate to a supported Ubuntu version to avoid disruptions. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary Updates have been made to the author metadata and content related to scale-down mode in Azure AKS, ensuring that the information is current and accurately reflects the intended audience’s needs. |
||
|
|
||
|
Networking AKS Modified: 2026-04-08 11:02 |
||
|
Summary The section on WireGuard encryption has been updated to reflect its preview status, and additional information about Cilium mTLS encryption has been added, providing users with more options for securing pod-to-pod traffic. |
||
|
|
||
|
Networking AKS Modified: 2026-04-10 17:13 |
||
|
Summary The documentation now includes a preview notice for the `managedNATGatewayV2` outbound type, allowing users to configure AKS clusters with this new option, which provisions a StandardV2 NAT gateway. Additionally, the migration paths for outbound types have been clarified, specifying that migration is supported only between certain managed or user-defined outbound types, which may affect the cluster’s egress IP addresses and require updates to firewall rules. Users should be aware that changing the outbound type can disrupt network connectivity and impact existing connections. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary The documentation for the `–token-auth-file` parameter in the AKS section has been updated to clarify that this parameter is managed by AKS and is auto-rotated, making it non-configurable by customers. This change helps users understand that they do not need to manage this parameter themselves, as it is handled automatically by the AKS service. |
||
|
|
||
|
Security AKS Modified: 2026-04-10 06:02 |
||
|
Summary The documentation for configuring external identity provider authentication in Azure Kubernetes Service (AKS) has been updated to remove the `certificateAuthority` parameter from the issuer configuration, as it is not yet supported. Users should note that this change clarifies the current capabilities and limitations regarding TLS verification when connecting to the issuer URL. |
||
|
|
||
|
General AKS Modified: 2026-04-08 22:06 |
||
|
Summary The documentation now includes a new section on the migration of Azure Monitor services, such as Container Insights and Managed Prometheus, to a cluster extension-based backend model. This update clarifies that the transition is non-disruptive and does not affect user experience, workloads, or monitoring functionality, ensuring that users can continue to utilize Azure CLI, Azure Portal, and other client experiences without any changes. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary Improved clarity and updated links in the documentation regarding FQDN filtering policies for Azure Kubernetes Service. |
||
|
|
||
|
Compute AKS Modified: 2026-04-06 22:07 |
||
|
Summary The documentation has been updated to reflect changes in the parameters used for creating and updating AKS clusters with node initialization taints. Users should now use the `–node-init-taints` parameter instead of the previous `–node-initialization-taints` when executing the `az aks create` and `az aks update` commands to specify the taint `sku=gpu:NoSchedule`. This change improves clarity and ensures users are using the correct command syntax. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary This document has been updated to reflect changes in authorship, ensuring that the information is current and accurately attributed. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary This document has been updated with new author metadata, reflecting changes in contributions and ensuring proper attribution. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary Clarifications were made regarding Federal Information Processing Standards (FIPS)-enabled node pools, specifying that they are only supported with Arm64 SKUs when using Azure Linux 3.0+. |
||
|
|
||
|
General AKS Modified: 2026-04-06 19:21 |
||
|
Summary Updated links for NVIDIA NVLink to improve clarity in the GPU health monitoring documentation for Azure Kubernetes Service (AKS). |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary Updated links in the documentation for deploying EKS on Azure, improving clarity and accessibility. |
||
|
|
||
|
General AKS Modified: 2026-04-09 06:02 |
||
|
Summary The documentation for private clusters has been updated to clarify the command for setting the subscription context using the `az account set` command, enhancing user understanding and accuracy. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary The documentation for Azure App Configuration has been updated to improve clarity regarding the Azure App Configuration Kubernetes Provider, which allows users to manage key-values, Key Vault references, and feature flags within Kubernetes ConfigMaps and Secrets. Additionally, the links to the Kubernetes Provider have been streamlined for better accessibility, enhancing the overall user experience when integrating Azure App Configuration with Azure Kubernetes Service (AKS). |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary Updated links in the Helm quickstart documentation to improve clarity and accessibility for users. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary The article has been updated to reflect changes in authorship, ensuring that the information is current and accurately attributed. |
||
|
|
||
|
General Fleet Modified: 2026-04-08 06:02 |
||
|
Summary The documentation for Azure Kubernetes Fleet Manager has been updated to clarify the roles and permissions associated with managing Kubernetes resources. Key changes include improved descriptions of role assignments, particularly for private hub clusters, and the introduction of new roles for member clusters. Additionally, the date metadata has been updated to reflect the latest changes. |
||
|
|
||
|
Networking AKS Modified: 2026-04-11 06:01 |
||
|
Summary The documentation has been updated to clarify the use of the label `node.kubernetes.io/exclude-from-external-load-balancers=true` for preventing a node pool from being part of the load balancer’s backend pool. This change enhances the understanding of load balancer configurations in Azure AKS. |
||
|
|
||
|
General ACR Modified: 2026-04-10 06:02 |
||
|
Summary This document has been updated with new author metadata, which is crucial for maintaining accurate records of contributions. |
||
|
|
||
|
General Fleet Modified: 2026-04-08 06:02 |
||
|
Summary The documentation has been updated to reflect an increase in the maximum concurrency limit for stage levels from 10 to 50. Users can now specify a higher `MaxConcurrency` for stages, allowing for greater parallel processing capabilities when no specific limit is set. This change enhances the flexibility and efficiency of orchestration in Kubernetes Fleet. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary The document received updates to author information and links, enhancing clarity and ensuring the content is up-to-date. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary This update highlights the `tags` storage class parameter for Azure Files and explains how to manage tags on existing volumes. It ensures users understand the immutability of the `PersistentVolume` spec after creation. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary The documentation for deploying Java Quarkus applications in Azure Kubernetes Service (AKS) has been updated to improve clarity and accuracy. Users can now access the correct URLs for resources related to deploying MicroProfile and Quarkus applications, ensuring they have the most relevant and up-to-date information for their deployments. This change enhances the overall user experience by directing them to the appropriate learning modules and documentation. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary This update clarifies the behavior of tags with immutable storage classes in Azure Kubernetes Service (AKS). It includes important notes on how to update tags for existing persistent volumes and the implications of changing tags on underlying Azure resources. |
||
|
|
||
|
Networking AKS Modified: 2026-04-08 11:02 |
||
|
Summary The documentation has been revised to indicate that WireGuard encryption is in preview, along with instructions for installing the aks-preview Azure CLI extension and registering the necessary feature flag. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary This update includes changes to the author metadata for the document, reflecting a new author. While the content changes are minimal, they indicate a shift in authorship which may be relevant for tracking contributions and updates in the documentation. |
||
|
|
||
|
General AKS Modified: 2026-04-07 06:01 |
||
|
Summary The documentation now includes clearer instructions for users on how to create a directory and switch to it in their terminal session, specifically using the command `mkdir demorepo` followed by `cd demorepo`. Additionally, the steps for cloning the sample application and viewing created images and running containers have been renumbered for better clarity, ensuring users can follow the tutorial more easily. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary The Standard tier for Azure Kubernetes Service (AKS) provides a 99.9% uptime service-level agreement (SLA) for production workloads, ensuring greater cluster reliability and support for up to 5,000 nodes. |
||
|
|
||
|
Compliance AKS Modified: 2026-04-09 06:02 |
||
|
Summary Starting on June 30, 2027, AKS will no longer support or provide security updates for Ubuntu 22.04. Users must transition to Ubuntu 24.04 or later by that date to avoid service disruptions. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary This document has been updated to reflect changes in authorship and improve clarity on pod sandboxing considerations in AKS, ensuring users have the most accurate information. |
||
|
|
||
|
General AGC Modified: 2026-04-09 18:37 |
||
|
Summary The topic has been updated to reflect changes in the approach to handling WebSocket connections through the Application Gateway for Containers, enhancing the guidance provided. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary The document has been revised to improve clarity regarding the process of creating Kubernetes deployments using Automated Deployments in a code editor. This update is beneficial for developers looking to streamline application management. |
||
|
|
||
|
General AKS Modified: 2026-04-08 17:05 |
||
|
Summary The tutorial has been updated to improve clarity and usability. It now includes detailed instructions for creating an Azure Container Registry (ACR) instance, emphasizing the need for unique registry names and providing examples of commands. Additionally, it clarifies the use of Azure CLI commands and the importance of switching to the correct directory before executing build commands. |
||
|
|
||
|
Compute AKS Modified: 2026-04-06 22:07 |
||
|
Summary The documentation now clarifies that users can enable Federal Information Processing Standards (FIPS) compliant node images in Azure Kubernetes Service (AKS). Additionally, the language has been improved for better understanding, directing users to the FIPS documentation for more information. |
||
|
|
||
|
General AKS Modified: 2026-04-09 22:06 |
||
|
Summary A new article has been added that provides a comprehensive guide on deploying a production-ready Azure Kubernetes Service (AKS) cluster using Terraform with an Azure Verified Module (AVM). It includes prerequisites, Terraform configuration details, and best practices for deployment. |
||
|
|
||
|
Security AKS Modified: 2026-04-09 22:03 |
||
|
Summary The document has been updated to reflect that KMS v2 is now used for encrypting the Kubernetes secret store for all new clusters created on Azure Local 2510 and later, while KMS v1 continues to be supported for existing clusters. |
||
|
|
||
|
Security AKS Modified: 2026-04-06 22:07 |
||
|
Summary The document has been updated to clarify the Federal Information Processing Standards (FIPS) related to Azure Kubernetes Service (AKS), ensuring compliance with security standards. |
||
|
|
||
|
Compliance AKS Modified: 2026-04-10 22:05 |
||
|
Summary The support policies for Azure Kubernetes Service (AKS) have been revised to clarify that AKS is a mix of Infrastructure as a Service (IaaS) and Platform as a Service (PaaS). The updates also emphasize the shared responsibility model for agent nodes and the management of the control plane by Microsoft. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary The document has undergone revisions to enhance the clarity of the GitHub workflow for AKS extensions, which is crucial for developers implementing CI/CD practices in their Kubernetes environments. |
||
|
|
||
|
Operations AKS Modified: 2026-04-09 06:02 |
||
|
Summary The document was updated to include a note regarding the retirement of Ubuntu 20.04, which is crucial for users managing AKS clusters to ensure they are aware of OS version support and planning for upgrades. |
||
|
|
||
|
Networking AKS Modified: 2026-04-10 22:05 |
||
|
Summary The NAT gateway documentation for AKS has been updated to include details about the new `managedNATGatewayV2` (Preview), which offers zone redundancy and supports IPv6, higher throughput, and flow logs. Users can now create AKS clusters with this new managed NAT gateway type using specific Azure CLI commands, including parameters for outbound IP configurations, and are informed that the `managedNATGatewayV2` is currently in preview, requiring the installation of the `aks-preview` Azure CLI extension and registration of the corresponding feature flag. Additionally, the documentation clarifies the differences between Azure-managed and customer-defined outbound IPs for the NAT gateway. |
||
|
|
||
|
Storage AKS Modified: 2026-04-10 06:02 |
||
|
Summary The documentation now includes important information regarding the immutability of the PersistentVolume spec after creation. It explains how to update tags on existing volumes and emphasizes that changes to the storage class only affect newly provisioned volumes. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary The article has been revised to update author information and improve the content related to managed namespaces in AKS, providing users with clearer guidance. |
||
|
|
||
|
Networking AKS Modified: 2026-04-08 11:02 |
||
|
Summary The documentation has been updated to clarify that WireGuard encryption with Advanced Container Networking Services is currently in preview. It includes instructions for installing the aks-preview Azure CLI extension and registering the AdvancedNetworkingWireGuardPreview feature flag. |
||
|
|
||
|
Operations AKS Modified: 2026-04-08 11:02 |
||
|
Summary Links have been updated for control plane metrics documentation, enhancing clarity and ensuring users have access to the latest information regarding node auto-provisioning. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary The document now includes a detailed explanation of the risks associated with rolling back node pool versions in AKS, including vulnerability exposure and service disruption. It emphasizes the need for careful planning during the rollback process. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary Enhanced the documentation with additional links and clarity regarding automated deployments in Azure Kubernetes Service. |
||
|
|
||
|
General AKS Modified: 2026-04-10 06:02 |
||
|
Summary This file has been modified to update the author metadata, which is important for maintaining accurate records of contributions to the documentation. |
||
|
|
||
|
Security Fleet Modified: 2026-04-06 22:07 |
||
|
Summary The documentation has been improved with updated links and enhanced clarity regarding the use of Azure Bastion for securing access to private hub clusters. |
||
|
|
||
|
Compliance AKS Modified: 2026-04-09 06:02 |
||
|
Summary The Istio support policy has been updated to reflect new timelines for the asm-1-26 and asm-1-29 versions. Users can now expect the end of support for asm-1-26 to be in April 2026, and the introduction of asm-1-29 with support expected to last until approximately September 2026. Additionally, the supported versions for asm-1-29 have been specified as 1.31 through 1.35. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary The documentation for deploying Flatcar on Azure Kubernetes Service (AKS) has been updated to reflect changes in the agent pool naming convention, specifically changing from "aks-agentpool-238955149-vmss000002" to "aks-agentpool-38955149-vmss000002." This update improves clarity and ensures users have the correct information for managing their AKS deployments. |
||
|
|
||
|
Networking AGC Modified: 2026-04-09 18:37 |
||
|
Summary New components and connectivity requirements for the Application Gateway for Containers have been added, detailing necessary endpoints and their purposes. |
||
|
|
||
|
General AKS Modified: 2026-04-09 06:02 |
||
|
Summary The documentation now includes updated information regarding the retirement of Ubuntu 20.04 and Ubuntu 22.04, ensuring users are aware of the support status for these operating systems in relation to Azure Kubernetes Service (AKS). This change helps users make informed decisions about their AKS node configurations and the operating systems they choose to deploy. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary This document has been updated to improve clarity and links related to the AI toolchain operator for fine-tuning models in Azure Kubernetes Service (AKS). |
||
|
|
||
|
General AKS Modified: 2026-04-06 19:21 |
||
|
Summary Updated links for NVIDIA Multi-Instance GPU to improve clarity in the documentation for Azure Kubernetes Service. |
||
|
|
||
|
Compliance AKS Modified: 2026-04-09 06:02 |
||
|
Summary The document includes updates regarding the retirement of Ubuntu 20.04, emphasizing the importance of migrating to supported versions to ensure continued security and functionality. |
||
|
|
||
|
Security AKS Modified: 2026-04-10 17:13 |
||
|
Summary The documentation for user-assigned managed identities in AKS has been updated to clarify that after switching from a service principal to a user-assigned managed identity, the control plane and pods will utilize the new identity for Azure service authorization. It also emphasizes that Kubelet will continue using the service principal until the node pool is upgraded, which requires downtime as nodes are cordoned, drained, and reimaged. Users can now follow the provided command to upgrade their node pools accordingly. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary New links were added to improve clarity regarding Azure CLI installation and extensions, making it easier for users to find relevant resources. |
||
|
|
||
|
Security AKS Modified: 2026-04-06 22:07 |
||
|
Summary The security best practices section emphasizes the importance of limiting container privileges and using built-in Linux security features like AppArmor and seccomp to secure container access to resources. |
||
|
|
||
|
General AKS Modified: 2026-04-06 22:07 |
||
|
Summary Clarified the requirements for the Istio plugin CA add-on, ensuring users have the correct Azure CLI version information. |
||
|
Full tracker with filters: Azure Container Services Docs Tracker
