Azure Container Services Docs – Weekly Update (2026-05-31 to 2026-06-07)
The most meaningful Azure Kubernetes Service, AKS Arc, Container Registry, Application Gateway for Containers, and Fleet Manager documentation changes from the last 7 days. AKS everywhere! Summaries are AI-filtered to skip trivial edits.
📊 Updates this week: ACR (22), AGC (20), AKS (285), Fleet (6)
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-04 19:21 |
||
|
Summary The document has undergone multiple updates to improve clarity and accuracy regarding traffic splitting using the Gateway API, including corrected references and enhanced examples, which are crucial for users implementing this feature. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-04 19:21 |
||
|
Summary The documentation for the ALB Controller has been updated to reflect the implementation of version v1 of the Gateway API, with new links provided for the GatewayClass, Gateway, HTTPRoute, and ReferenceGrant specifications. Users can now access the latest API specifications directly through these updated links, ensuring they have the most current information for configuring and utilizing the ALB Controller effectively. |
||
|
|
||
|
Storage ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-04 19:21 |
||
|
Summary The API specification documentation has been updated to include new links and references, improving the clarity and accessibility of the information related to the Kubernetes Gateway API. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 19:21 |
||
|
Summary The documentation has been updated to reflect changes in the URL Rewrites section, specifically regarding the filters used as defined by the Kubernetes Gateway API. Users can now access the correct API specification link for the HTTP URL Rewrite Filter, ensuring they have the most accurate and up-to-date information for implementing URL rewrites in their applications. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now emphasizes that AKS Automatic includes a pod readiness SLA that guarantees 99.9% of qualifying pod readiness operations complete within 5 minutes, enhancing the reliability and self-healing capabilities of applications. Additionally, a new section on the Kubernetes gateway has been included, providing users with more comprehensive guidance on integrating this feature into their workflows. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now provides a clearer explanation of how the Azure App Configuration extension for AKS allows for the management of application settings and feature flags, improving user understanding of its functionality. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-03 06:03 |
||
|
Summary The documentation has been updated to clarify that when using a custom virtual network with AKS Automatic, users must create an API server subnet, which AKS will delegate to `Microsoft.ContainerService/managedClusters`. Additionally, the Bicep file now sets the `clusterName` parameter to *aksPrivateAutomaticCluster*, and users are required to provide both user node and system node subnet resource IDs when deploying the Bicep file via Azure CLI. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-04 19:21 |
||
|
Summary The documentation now includes support for Network Security Groups (NSGs) on the Application Gateway for Containers association subnet for associations created on or after April 23, 2026, allowing users to configure both inbound and outbound rules. Additionally, users can implement User Defined Routes (UDRs) for fine-grain control over routing, including scenarios to disable BGP route propagation and direct traffic to the internet, enhancing traffic management capabilities. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation title and headings have been updated to remove the term "AKS-managed," reflecting a broader focus on Microsoft Entra integration. Users can now configure node-side access modes that inherit Conditional Access, including Microsoft Entra ID-based SSH, by following the new instructions provided in the "Manage SSH access on AKS cluster nodes" section. |
||
|
|
||
|
Operations ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Compliance ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security ♻️ Rework Modified: 2026-06-04 05:12 |
||
|
Summary The documentation has been updated to reflect changes in the management of secret encryption on AKS Edge Essentials clusters. Users can now validate and troubleshoot the Key Management Service (KMS) provider, which is enabled by default for all newly created clusters starting with version 1.12.269.0, and is supported for versions 1.10.868.0 and later. Additionally, the process for ensuring secrets are re-encrypted with the latest Key Encryption Key (KEK) has been clarified, emphasizing that users may optionally re-write infrequently updated secrets every 30 days to maintain compliance with Kubernetes best practices. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to configure AKS node auto-drain to evict specific pods before freeze events occur on underlying virtual machines. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now indicates that the Agentic CLI for Azure Kubernetes Service (AKS) is in preview, which may affect user expectations regarding stability and features. Additionally, a new table has been added that summarizes the ideal use cases and characteristics of the two deployment modes—client mode and cluster mode—helping users choose the best option for their environments. This enhancement provides clearer guidance on when to use each mode based on specific operational requirements and security models. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-05 06:02 |
||
|
Summary The documentation has been updated to remove notes regarding required tweaks for dashboard panels in Prometheus/Grafana, which may simplify user setup. Additionally, the mention of Cilium’s lack of support for DNS metrics and dashboards has been eliminated, clarifying the current capabilities of Cilium for users. |
||
|
|
||
|
Compute ♻️ Rework Modified: 2026-06-02 22:14 |
||
|
Summary The documentation for the ‘Terminate’ VM state in the Azure Kubernetes Service (AKS) has been updated to indicate that no action will be taken when a VM is scheduled for deletion, replacing the previous instruction to cordon and drain the VM. This change affects how users manage VM terminations within their Virtual Machine Scale Sets, simplifying the process by removing the need for prior notifications and actions. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 22:03 |
||
|
Summary Learn how to connect to your Azure Kubernetes Service on bare metal cluster using the Azure Arc proxy and kubectl. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Operations ✨ Update Modified: 2026-06-05 22:08 |
||
|
Summary This update provides comprehensive best practices for performance and scaling for large workloads in AKS, emphasizing the use of AKS Automatic as the default for most production workloads. It includes guidance on scaling, security, networking, monitoring, and upgrades, making it a valuable resource for users managing large AKS clusters. |
||
|
|
||
|
Operations ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to set up a compatible Azure Kubernetes Service (AKS) cluster for AKS desktop. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 19:21 |
||
|
Summary The documentation has been updated to provide clearer references for creating a Gateway and HTTPRoute resource. Users can now find updated links to the Gateway API concepts and HTTPRoute API types, which may enhance their understanding and implementation of these resources in their applications. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for deploying applications using AKS Desktop has been updated to clarify that users can now deploy containerized applications without writing Kubernetes manifests. Additionally, the prerequisites have been refined to specify the need for Azure CLI version 2.64.0 or later and appropriate Role-Based Access Control (RBAC) roles for team members. The article also emphasizes the recommended use of AKS Automatic clusters for enhanced features and insights within the AKS Desktop interface. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-04 05:12 |
||
|
Summary This overview discusses the Key Management Service (KMS) provider for secret encryption in AKS Edge Essentials, detailing its default enablement in newer versions and the implications for securing Kubernetes secrets. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now specifies that version 2.87.0 or later of the Azure CLI is required, an update from the previous requirement of version 2.0.64. Additionally, users must install the `aks-preview` extension and register the `AksWindows2025Preview` feature flag to use the `–os-sku Windows2025`, with a minimum extension version of 18.0.0b40 required for this functionality. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to deploy Container Network Insights Agent as an AKS extension to troubleshoot networking issues in Azure Kubernetes Service (AKS) clusters. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now clarifies that the `–token-auth-file` parameter is managed by AKS and is auto-rotated, making it non-configurable by customers. Additionally, the links for Entra authentication and local accounts have been updated to point to new sections, providing users with more accurate resources for managing authentication and account settings. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-05 22:08 |
||
|
Summary The documentation now emphasizes the use of AKS Automatic as the recommended production-ready default for most workloads, providing managed defaults for networking, scaling, security, monitoring, and upgrades. It also clarifies the differences between AKS Automatic and AKS Standard modes, enhancing user understanding of ingress networking in Azure Kubernetes Service. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn about cross-cluster networking use cases for Azure Kubernetes Fleet Manager (Fleet), including high availability, shared services, and multi-cluster observability across AKS clusters. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🗑️ Removal Modified: 2026-06-02 19:01 |
||
|
Summary This document has been removed, indicating a significant update or change in the best practices for identity management in AKS. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-04 05:12 |
||
|
Summary Security vulnerability advisories and mitigation guidance for AKS enabled by Azure Arc. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Operations 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now reflects a schema v2 change, where the configuration for targets is separated into `cluster-metrics` and `controlplane-metrics`, allowing users to manage ingestion volume for cluster-level and control plane targets independently. Users migrating from v1 must update their configurations accordingly, including changing the key name from ‘default-scrape-settings-enabled’ to ‘default-targets-scrape-enabled’ and removing the "controlplane-" prefix from target names. Additionally, the settings for minimal ingestion profiles have been updated to reflect the new structure, enhancing clarity on how to configure metrics ingestion. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Reference for the Azure permissions required by the identity creating an AKS cluster, the cluster identity at runtime, and AKS node access. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The document has been significantly revised to include a comprehensive list of partner solutions for Azure Linux AKS, detailing various categories such as DevOps, Networking, and Security, along with links to partner resources. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation has been updated to remove the "public preview" designation for WireGuard encryption with Advanced Container Networking Services (ACNS), indicating that this feature is now fully available. Additionally, the section clarifying which traffic types are encrypted and which are not supported has been retained, ensuring users have clear guidance on the capabilities of WireGuard in their Kubernetes clusters. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Troubleshoot common issues you might encounter when deploying, configuring, or using Container Network Insights Agent on Azure Kubernetes Service (AKS). |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-04 19:21 |
||
|
Summary The documentation now includes updated links for the [Gateway](https://gateway-api.sigs.k8s.io/docs/concepts/api-overview/#gateway) resource and the [HTTPRoute](https://gateway-api.sigs.k8s.io/reference/api-types/httproute/) resources, providing users with access to the latest API concepts and reference materials. This change ensures that users can find the most current information and guidelines for implementing multiple site hosting with the Gateway API. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now includes updated information regarding the Kubernetes Service Address Range, specifying that users can extend the service IP range after cluster creation using the `ServiceCIDR` resource starting with Kubernetes version 1.33. This enhancement allows for greater flexibility in managing IP address planning within AKS clusters. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary Similar to the workflow documentation, the author information has been updated in the AKS extension draft deployment documentation, ensuring accurate representation of contributors. |
||
|
|
||
|
Cost ♻️ Rework Modified: 2026-06-05 06:02 |
||
|
Summary The documentation for "Best Practices for Cluster Security in Azure Kubernetes Service (AKS)" has been updated to include specific guidance for both AKS Automatic and AKS Standard modes, highlighting their differing security responsibilities and preconfigured controls. Users can now better understand how to secure API server access using Microsoft Entra ID and Kubernetes RBAC, manage upgrades, and apply security patches, with a clearer distinction on the operational responsibilities associated with each cluster mode. Additionally, the upgrade process for AKS clusters has been clarified, emphasizing the importance of monitoring and managing upgrades effectively. |
||
|
|
||
|
Operations ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-05 21:49 |
||
|
Summary [!IMPORTANT] |
||
|
|
||
|
Compute 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now includes a new section on Azure Container Linux (ACL) node images, detailing their validation by AKS and their construction from Azure Linux packages using Flatcar tooling. Users can now find specific use cases for ACL node images, including options for AMD64 and ARM64 VM sizes that utilize Trusted Launch. Additionally, the versioning format for both Azure Linux with OS Guard and Flatcar Container Linux node images has been clarified to follow the AKS date-based format. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now specifies that users need Azure CLI version 2.87.0 or later to create and manage AKS node pools. Additionally, it clarifies that system pools must contain at least two nodes, and users can now create multiple Windows Server 2025 node pools, enhancing the flexibility in managing AKS clusters. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now specifies that AKS clusters with Calico CNI cannot use the address ranges `172.30.0.0/16` or `172.31.0.0/16`, in addition to the previously stated restrictions on `169.254.0.0/16` and `192.0.2.0/24`. Users can also find updated information about the Container Network Service (CNS), which manages pod networking and sends telemetry to a Microsoft managed Application Insights endpoint for improved troubleshooting of IP address assignment issues. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now includes updated instructions for users deploying Windows Server 2025 containers on Azure Kubernetes Service (AKS). Users must install the `aks-preview` extension and register the `AksWindows2025Preview` feature flag to utilize this version, with specific commands provided for installation, updating, and verifying the registration status. Additionally, it is emphasized that Windows Server 2025 requires a minimum version of the `aks-preview` extension (18.0.0b40). |
||
|
|
||
|
General ✨ Update Modified: 2026-06-05 06:02 |
||
|
Summary The documentation now clarifies that Deployment Safeguards and the baseline Pod Security Standard are enabled by default in `Enforce` mode for AKS Automatic clusters, while users can opt out of enforcement for specific workloads by excluding their namespaces. Additionally, it specifies that on AKS Standard clusters, Deployment Safeguards are optional and can be set to either `Warn` or `Enforce`, allowing for more flexibility in managing compliance levels. Users can also now see a summary table that outlines the behavior of Deployment Safeguards across both AKS modes. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now clarifies that the AKS-ACR integration through `az aks –attach-acr` is not supported for ABAC-enabled ACR registries, which require the `Container Registry Repository Reader` role instead of the `AcrPull` role. Additionally, users are advised to pre-create a user-assigned identity and use it as the kubelet identity to avoid latency issues when granting roles to Microsoft Entra groups. The article also emphasizes the need for specific Azure CLI and PowerShell versions to ensure compatibility with the commands provided. |
||
|
|
||
|
Storage ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn about Azure Container Linux (ACL), an immutable, container-optimized operating system for Azure Kubernetes Service (AKS) that builds on Flatcar Container Linux while integrating Azure Linux packages and platform features. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 22:03 |
||
|
Summary Learn about Azure Kubernetes Service (AKS) on bare metal, a deployment option that runs Kubernetes directly on hardware without a hypervisor layer. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-04 06:02 |
||
|
Summary The document has been updated to clarify the two cluster modes in Azure Kubernetes Service (AKS): AKS Automatic and AKS Standard. It describes the operational responsibilities and recommended use cases for each mode, emphasizing the benefits of reduced operational overhead with AKS Automatic and the flexibility of AKS Standard. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary An update has been made to include a link to the Kaito fine-tuning GitHub repository, enhancing the resources available for users interested in fine-tuning language models. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation has been updated to clarify that Arc-enabled Kubernetes clusters no longer have a preview status regarding log ingestion support. Users can now understand that these clusters do not support log ingestion, aligning with the current capabilities of AKS clusters. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Compute 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now clarifies that blue-green upgrades for AKS node pools involve adding new _green_ nodes with updated configurations to the existing node pool, rather than creating a separate _green_ pool. Additionally, users can now utilize the `az aks nodepool rollback` command to initiate a rollback during the final soak period, providing a clear method for reverting changes if needed. The section on potential issues during the upgrade process has also been expanded to include considerations for stateful workloads and monitoring requirements. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation for Azure Container Registry has been updated to reflect changes in the references to firewall access rules, specifically updating links from "container-registry-firewall-access-rules.md" to "container-registry-firewall-rules.md." Users can now find more accurate guidance on configuring network security rules and using service tags for image import and firewall access. This ensures that users have the correct resources for setting up their Azure Container Registry configurations. |
||
|
|
||
|
Security ♻️ Rework Modified: 2026-06-05 17:15 |
||
|
Summary The documentation for the Azure Container Registry RBAC built-in roles has been updated to clarify the capabilities of the roles regarding the `az` CLI commands. Users can now authenticate and log in to the registry using the `az acr login` command and run control plane commands that read, update, or delete registry configuration, with important notes on the limitations regarding data plane permissions. Additionally, the sections on configuring and viewing network access and private endpoint settings have been revised to reflect the correct links and instructions for managing these settings effectively. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now specifies that AKS supports Long Term Servicing Channel Releases (LTSC) for Windows Server 2025 and Windows Server 2022, removing the mention of Windows Server 2019. This change clarifies the supported versions for users, ensuring they are aware of the current recommendations for using AKS with Windows Server LTSC releases. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now includes information about the migration of Azure Monitor services, such as Container Insights and Managed Prometheus, to a cluster extension-based backend model. This change is nondisruptive, ensuring that users will not experience any changes in functionality or user experience, and all existing tools like Azure CLI and the Azure portal will continue to operate as expected. Additionally, users are informed about the Container Network Insights Agent, which can be utilized for diagnosing and troubleshooting networking issues in AKS clusters. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-04 06:02 |
||
|
Summary The documentation for Azure Kubernetes Service (AKS) has been updated to include detailed descriptions of the two cluster modes: AKS Automatic and AKS Standard. Users can now better understand the differences between these modes, including management features, security defaults, and scaling options, allowing them to choose the most suitable configuration for their needs. Additionally, the article emphasizes the benefits of using AKS Automatic for quick onboarding and reduced operational overhead. |
||
|
|
||
|
Storage 🆕 New Modified: 2026-06-03 22:12 |
||
|
Summary The documentation now clarifies that each AKS cluster includes built-in storage classes configured for Azure Disks, specifically highlighting the new _managed-csi-premium-v2_ storage class available starting with Kubernetes version 1.35, which provisions Premium SSD v2 disks ideal for I/O-intensive workloads. Additionally, it specifies that effective from Kubernetes version 1.29, AKS uses zone-redundant storage (ZRS) for managed disks across availability zones, enhancing data resilience, though at a higher cost compared to locally redundant storage (LRS). Users can now also utilize the `managed-csi-premium-v2` storage class for provisioning Premium SSD v2 disks, expanding their options for performance and cost management. |
||
|
|
||
|
Storage ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The title and content have been updated for consistency in capitalization regarding Azure managed disks. This change enhances readability and maintains a professional tone throughout the documentation. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for Azure Kubernetes Service (AKS) has been updated to provide a clearer overview of the five identity scenarios, including Kubernetes control-plane authentication and authorization, AKS resource authorization, cluster identity, and workload identity. Users can now find specific deep-dive documentation linked for each scenario, enhancing their ability to select the appropriate authentication and authorization model for their needs. Additionally, the article emphasizes the integration of Microsoft Entra ID for managing user permissions and access to resources within AKS. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Operations ✨ Update Modified: 2026-06-04 22:03 |
||
|
Summary Learn how to upgrade the Kubernetes version on your Azure Kubernetes Service on bare metal cluster using the Azure portal. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 05:12 |
||
|
Summary Learn about scale requirements for AKS on Azure Local, Rack Scale deployments, including cluster, node pool, and node limits. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 19:21 |
||
|
Summary The documentation now clarifies that Application Gateway for Containers supports regular expression matching for `headers`, `queryParams`, and `path` rules using Regular Expression 2 (RE2) syntax. Additionally, the links to the Gateway API resources have been updated to direct users to the correct sections for both the Gateway and HTTPRoute resources. Users can now find more accurate information regarding the API specifications and how to implement these features effectively. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for creating an AKS Automatic cluster with managed system node pools has been significantly revised, including prerequisites and commands for setting up the cluster. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for container network logs in Azure Kubernetes Service (AKS) has been updated to reflect the renaming of key components for clarity and consistency. Users must now update their Azure CLI and the preview CLI extension, disable and re-enable monitoring, and apply new naming conventions for the `ContainerNetworkLog` custom resource definition (CRD) and associated commands. Additionally, the documentation now emphasizes the importance of using flow log aggregation to manage data volume and costs effectively while providing detailed insights into network flows. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-04 19:21 |
||
|
Summary The documentation now clarifies that when the add-on is enabled on an AKS cluster using the AKS-managed virtual network option, a subnet named `aks-appgateway` is automatically created with delegation enabled for `Microsoft.ServiceNetworking/TrafficController`. Additionally, it specifies that users should see a condition labeled **Valid GatewayClass**, indicating that a default GatewayClass is set up and managed by the ALB Controller. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary In this Azure Linux article, you learn how to migrate nodes to Azure Container Linux (ACL) for AKS. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Cost 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now includes a new section on DNS resolution performance, highlighting its impact on application response times in microservices architectures. Users are advised to enable LocalDNS on their node pools to improve DNS query resolution by deploying a per-node DNS proxy, which reduces network hops and alleviates `conntrack` table pressure. Additionally, LocalDNS offers support for cached stale responses during upstream DNS outages, enhancing workload connectivity. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary The local accounts document has been renamed, indicating a potential reorganization of content within the AKS documentation. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for setting up permissions and role-based access control (RBAC) in AKS Desktop has been updated to clarify how users can manage permissions based on their roles as cluster operators or developers. Users can now provide environments for developers to deploy and manage applications, and the article emphasizes the need to maintain or automate permissions over time. Additionally, it notes that there is currently no UI option to modify Project permissions after creation, requiring users to utilize the Azure portal or Azure CLI for updates. |
||
|
|
||
|
Compute ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security 🆕 New Modified: 2026-06-05 06:02 |
||
|
Summary The documentation for Azure Kubernetes Service (AKS) has been updated to clarify security concepts, particularly highlighting the differences between AKS Automatic and AKS Standard modes. Users can now understand that AKS Automatic provides a hardened security baseline with preconfigured controls, while AKS Standard offers more flexibility in configuration. Additionally, new sections on build and registry security emphasize the importance of continuous vulnerability assessment and the use of trusted images, enhancing the overall security posture for users managing their AKS environments. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The document has been updated to clarify the integration of the Model Context Protocol (MCP) with AKS, which is essential for developers working with AI models. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 19:21 |
||
|
Summary The documentation now correctly references the updated URL for the RequestRedirect rule filter in the Kubernetes Gateway API, allowing users to access the most current specifications. This change ensures that users can implement URL redirects using the latest API guidelines effectively. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The document has been updated to clarify the configuration of DNS records for private endpoints in Azure Container Registry. It now specifies the number of private IP addresses required based on registry features, enhancing understanding for users setting up private endpoints. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-04 05:12 |
||
|
Summary The documentation for AKS Edge system requirements has been updated to reflect a change in the disk space requirement, increasing the minimum from 14 GB to 19 GB. This adjustment informs users that they need to ensure at least 19 GB of free disk space for proper system functionality. |
||
|
|
||
|
Operations ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how the Cluster Health Monitor checker in Azure Kubernetes Service (AKS) runs data plane health checks and supports CoreDNS remediation. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The draft Dockerfile for AKS extensions has been updated with new authorship and content improvements, enhancing the guidance for developers creating extensions. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation now correctly references "Private Link" as "Private Endpoints" in the context of virtual network configuration for Azure Container Registry. This change clarifies the feature’s name, ensuring users have accurate information when configuring their network settings. Users can now better understand how to implement private connectivity options for enhanced security and performance. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for installing Trident has been updated to reflect new links for the Trident Install Guide and installation methods. Users can now access the updated Trident Install Guide for more streamlined installation processes, including using Helm and `tridentctl`. This change enhances clarity on the available installation options for Trident. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 20:12 |
||
|
Summary The introduction to connected registries has been enhanced with new information about fully qualified regional data endpoints, which are crucial for synchronization with connected registries. This update improves clarity and technical accuracy. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn about Projects in AKS desktop, the application-centric grouping of Kubernetes resources that simplifies deployment and management of applications on Azure Kubernetes Service (AKS). |
||
|
|
||
|
Cost ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary This article provides insights into monitoring correlated GPU metrics to help improve long term GPU node utilization and performance on AKS. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The pod sandboxing concepts document has been revised to include updated links and authorship, enhancing the clarity and accuracy of the information provided. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now includes a section on Cilium mTLS Encryption, which offers transparent mutual TLS encryption and authentication for pod-to-pod traffic in Kubernetes without requiring application changes. Additionally, the Cross Cluster Networking feature has been detailed, enabling direct pod-to-pod communication across multiple AKS clusters, enhancing east-west connectivity and security enforcement through a managed Cilium Cluster Mesh. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for Azure Kubernetes Service (AKS) has been updated to reflect a change in the reference for Azure Active Directory integration. Users can now find information on AAD integration under the new section titled "Entra ID Control Plane Authentication," which provides updated guidance on configuring authentication for AKS clusters. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to interpret and use vulnerability data from the AKS Vulnerability Data API for security reviews, compliance reporting, and upgrade planning. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation has been updated to correct the link for the private endpoint configuration in a Premium container registry, now directing users to the appropriate section on private endpoints. This change ensures that users can access the correct information regarding setting up private endpoints for their container registries. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 22:03 |
||
|
Summary This document provides a comprehensive guide on creating an Azure Kubernetes Service (AKS) cluster on bare metal using a Bicep template. It includes prerequisites, detailed steps for downloading parameters and templates, deployment commands, and verification processes. |
||
|
|
||
|
Compute 🆕 New Modified: 2026-06-05 06:02 |
||
|
Summary The documentation now includes a dedicated section on "AKS cluster modes for MLOps," detailing the differences between AKS Automatic and AKS Standard, which allows users to choose the appropriate mode based on their management preferences and operational needs. Users can now better understand how each mode impacts baseline cluster setup, security controls, and operational behavior, enabling them to make informed decisions about their MLOps implementations on Azure Kubernetes Service. Additionally, the article emphasizes the importance of automation for policy validation and configuration drift detection across both modes. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary Updates to the component versioning documentation include new links to Azure CLI installation and extensions, providing users with better resources for managing AKS components. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how Azure Kubernetes Service (AKS) authenticates Kubernetes API requests using Microsoft Entra ID, and how to disable local cluster admin accounts in production. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to troubleshoot Kubernetes applications in AKS desktop using the built-in Insights feature powered by Inspektor Gadget. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation now clarifies that allowing trusted services does not apply to container registries configured with a service endpoint, and it specifies that this feature only affects registries restricted with a private endpoint or those with public IP access rules. Additionally, the references to "private endpoint" have been updated to consistently point to the correct section on private endpoints with Azure Private Link, ensuring users can find accurate information on configuring access restrictions for their registries. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-04 19:21 |
||
|
Summary The documentation now includes updated links for the `Gateway` and `HTTPRoute` resources, directing users to the latest API overview and reference pages. This change ensures that users have access to the most current information and guidelines when creating these resources with HTTPS listeners and back-end service references. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-05 06:03 |
||
|
Summary The documentation for Azure Container Registry’s geo-replication has been updated to clarify that images and tags pushed to a geo-replica via the regional endpoint will propagate to all other geo-replicas under eventual consistency. Additionally, users can now push, pull, and delete images from any geo-replica using both the global and regional endpoints, with the global endpoint automatically routing requests to the healthiest geo-replica. The changes also emphasize the importance of managing DNS caching and provide updated guidance on handling potential eventual consistency issues during cross-region operations. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation has been updated to provide a clearer overview of container network metrics in Advanced Container Networking Services for Azure Kubernetes Service (AKS), including enhanced descriptions and the introduction of source-level filtering for Cilium clusters. Users can now filter metrics at the source before collection, allowing for more targeted observability and reduced ingestion costs, particularly beneficial in large-scale environments. Additionally, the section on metrics collection has been refined to emphasize the differences in availability and functionality between Cilium and non-Cilium clusters. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 19:21 |
||
|
Summary The documentation has been updated to reflect the correct reference for the RequestRedirect rule filter used in URL redirects within the Kubernetes Gateway API. Users can now access the accurate API specification link, which provides detailed information on implementing URL redirects more effectively. This change ensures that users are directed to the most relevant and up-to-date resources for their configurations. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation has been updated to clarify the use of labels for node pools in load balancer configurations, which is important for users managing their AKS environments. |
||
|
|
||
|
Compliance ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Compliance ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Compute ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation now specifies that users can connect to Azure Container Registry using a private endpoint, enhancing security and connectivity options for those utilizing the Premium pricing plan. Additionally, the reference to the private endpoint documentation has been updated to direct users to the correct resource for further details. |
||
|
|
||
|
Compliance 🆕 New Modified: 2026-06-04 05:12 |
||
|
Summary The article announces the retirement of the Key Manager for Kubernetes extension (preview) on April 15, 2026, and provides guidance for users regarding this change. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 22:03 |
||
|
Summary Learn how to deploy an Azure Kubernetes Service (AKS) cluster on bare metal using the Azure portal. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security ♻️ Rework Modified: 2026-06-04 05:12 |
||
|
Summary The documentation now emphasizes the importance of installing the Key Manager for Kubernetes on an AKS Edge Essentials cluster to automatically rotate signing keys for Kubernetes service account tokens. Additionally, it provides instructions for users who have not installed the Key Manager, guiding them on how to ensure periodic token rotation. This change enhances security practices for users managing workloads in Azure Arc-enabled Kubernetes. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-05 05:18 |
||
|
Summary The documentation for Azure Container Registry has been updated to clarify the API request rate limits associated with different SKUs, detailing the specific limits for operations such as DataplaneRead, DataplaneWrite, and DataplaneDelete. Users can now better understand how their request rates are managed and the implications of exceeding these limits, including receiving HTTP `429 Too Many Requests` errors and the need for implementing retry logic with exponential backoff. Additionally, the Premium SKU features have been expanded to highlight benefits like geo-replication and private link capabilities for enhanced access control and high availability. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 05:12 |
||
|
Summary Learn how to deploy an AKS enabled by Azure Arc cluster on Azure Local (multi-rack) using an Azure Resource Manager template (ARM template). |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary This article explains how to enable a pre-created kubelet managed identity on a new or existing AKS cluster, get the properties of the kubelet managed identity, and add a role assignment for the kubelet managed identity. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 19:21 |
||
|
Summary The documentation has been modified to include updated references to the RequestRedirect rule filter in the Kubernetes Gateway API, enhancing clarity on load balancing strategies. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Compliance ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 22:03 |
||
|
Summary Learn how to deploy a containerized application to your Azure Kubernetes Service on bare metal cluster. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now clarifies that AKS clusters running Kubernetes versions earlier than 1.33 cannot update the service address range, pod address range, or cluster virtual network address range after creation. However, for clusters running Kubernetes 1.33 or later, users can extend the service IP range post-creation using the `ServiceCIDR` resource. Additionally, there are repeated reminders to review the virtual network prerequisites when bringing your own virtual network. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now includes a new tip that informs users they can optionally specify the `–vnet-subnet-id` parameter when creating the gateway node pool. This enhancement allows users to allocate the gateway nodes’ private IPs from a custom subnet, improving network isolation and IP address planning for static private IPs used for egress. |
||
|
|
||
|
Storage ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 03:04 |
||
|
Summary The documentation for creating an Azure Kubernetes Service (AKS) cluster on bare metal using an ARM template has been updated to improve clarity on control plane IP conflict resolution, now advising users to select an IP within the same subnet as the edge machine IP. Additionally, the parameters and commands for AKS bare metal cluster creation have been refactored, allowing for clearer configuration of the `edgeMachineName`, `controlPlaneIp`, `adminGroupObjectIds`, and `sshPublicKey`. Users can now follow more streamlined instructions for deploying their clusters effectively. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary This document has been updated to enhance clarity on how tool calling works within AKS, emphasizing its scalability and security, which is vital for developers using AI tools in their applications. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for the agentic CLI for Azure Kubernetes Service (AKS) has been updated to clarify the installation and usage instructions for both client and cluster modes. Users can now find detailed prerequisites, including the requirement for Azure CLI version 2.76 or later and the need for a large language model (LLM) API key from supported providers. Additionally, the command syntax has been refined to specify the `–namespace` parameter for cluster mode, enhancing the clarity of the setup process. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The app routing document has been updated to include a new link for creating a free Azure account, enhancing user accessibility. |
||
|
|
||
|
Cost ✨ Update Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now recommends Windows Server 2025 as the preferred operating system for Windows node pools on AKS, replacing Windows Server 2022. Additionally, it clarifies that AKS supports Long Term Servicing Channel Releases (LTSC) for both Windows Server 2025 and Windows Server 2022, emphasizing that customers using Long Term Support (LTS) should opt for Windows Server 2025. Users should ensure that the Windows container image version matches the host version when upgrading their Windows node OS. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-04 05:12 |
||
|
Summary The documentation now includes significant updates for the AKS Edge Essentials version 1.12.269.0, highlighting that cross-distribution upgrades are supported, allowing users to upgrade Kubernetes versions within the same release version. Additionally, the KMS provider is enabled by default for new deployments, simplifying the setup process as no extra configuration is needed. Users can also refer to the newly added upgrade paths table for guidance on supported upgrade combinations. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The automated deployments documentation has been enhanced with new references to Kubernetes documentation and deployment safeguards, improving the guidance for users on deploying applications in AKS. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for monitoring inference metrics via the AI Toolchain Operator has been updated to reflect changes in the Grafana dashboard configuration. Users should now refer to the updated link for the `grafana.json` file, which has moved to the observability section, ensuring they access the correct resources for inference workload monitoring. Additionally, a minor correction was made to the command for labeling the service, ensuring accuracy in the provided instructions. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to deploy a production-ready Azure Kubernetes Service (AKS) cluster using Terraform with an Azure Verified Module (AVM). |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now emphasizes the importance of reviewing the virtual network prerequisites when users bring their own virtual network to Azure Kubernetes Service (AKS). Additionally, the link for creating a free Azure account has been updated to direct users to the correct page for account options. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for the Center for Internet Security (CIS) benchmarks for Ubuntu images used by Azure Kubernetes Service (AKS) has been updated to clarify that the guidance now applies to both Ubuntu 24.04 and Ubuntu 22.04 images. Additionally, the structure of the recommendation table has been expanded from four to five sections, including a new "Level" designation that categorizes recommendations into L1 and L2, allowing users to better understand the severity of each recommendation. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now reflects that Fleet Manager supports joining AKS and Arc-enabled Kubernetes clusters as member clusters without the preview designation, indicating that this feature is now generally available. Users can confidently utilize Fleet Manager to manage their existing AKS and Arc-enabled clusters without concerns about preview limitations. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-04 19:21 |
||
|
Summary The documentation now includes updates for version 1.10.28, which introduces security updates, and version 1.10.27, which provides a hotfix for a pod crash related to GitHub issue 5758. Additionally, the release notes for version 1.0.0 highlight the General Availability of the Gateway API, including a URL redirect for both Gateway and Ingress API, and breaking changes regarding the TLS Policy for Gateway API and the renaming of the Listener to SectionName. Users should review these changes to understand the implications for their configurations and deployments. |
||
|
|
||
|
Security 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary A new document on Entra ID authorization has been added, providing comprehensive information on managing access and permissions within Azure Kubernetes Service using Microsoft Entra ID. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Cost ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for Azure Kubernetes Service (AKS) pricing tiers has been updated to clarify the features and recommendations for the Free, Standard, and Premium tiers. Users can now see that the Free tier supports clusters with up to 1,000 nodes, while the Standard and Premium tiers are recommended for production workloads with support for up to 5,000 nodes. Additionally, the instructions for updating clusters between the Base SKU and Automatic SKU have been enhanced to ensure users enable all necessary AKS Automatic features before proceeding with updates. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now clarifies that Azure Kubernetes Fleet Manager’s support for Arc-enabled Kubernetes clusters has been removed from preview status, indicating that users can expect more stable functionality. Additionally, the capabilities table has been updated to reflect that cross-cluster networking is now in preview for AKS clusters, while Arc-enabled clusters remain unsupported in this area. Users should also note that Fleet Manager support for Arc-enabled clusters is limited to Azure public cloud regions due to dependencies on Azure Arc Gateway. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation now emphasizes the introduction of dedicated data endpoints for Azure Container Registry, which provide scoped, registry-specific URLs for downloading container image layers. This change allows users to implement tightly scoped firewall rules, significantly reducing the risk of data exfiltration by replacing the previous wildcard Azure storage account endpoints. Additionally, users are informed that dedicated data endpoints are utilized only during layer blob downloads, enhancing security during image pulls. |
||
|
|
||
|
Compute 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now highlights that Azure Kubernetes Service (AKS) supports fully managed GPU nodes in preview, which automatically installs and maintains the NVIDIA GPU driver, device plugin, and Data Center GPU Manager metrics exporter. Users can create a managed GPU node pool in a single step, simplifying the process and allowing for configurations such as management mode and Multi-Instance GPU (MIG) strategy during node pool creation. Additionally, the minimum required Azure CLI version has been updated to 2.85.0 or later. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn about Container Network Insights Agent, an AI-powered diagnostic assistant that helps you troubleshoot networking issues in Azure Kubernetes Service (AKS) clusters. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 22:14 |
||
|
Summary The documentation has been updated to reflect changes in the Azure CLI commands for creating a resource group and an AKS Automatic cluster, specifically changing the location from "eastus" to "canadacentral." Additionally, users can now utilize the `–enable-hosted-system` parameter when creating the cluster, and the output examples have been updated to show new node pool names and statuses. The minimum required Azure CLI version has also been updated to 2.86.0 or later. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 05:12 |
||
|
Summary The documentation now specifies that the Azure Arc gateway can be enabled on AKS clusters specifically on Azure Local, enhancing clarity for users. Additionally, users are informed that the Arc gateway simplifies network configuration requirements and that newly created AKS Arc clusters will automatically utilize this gateway for improved connectivity. The prerequisites for creating AKS clusters on Azure Local have also been emphasized, ensuring users are aware of necessary steps before implementation. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 19:21 |
||
|
Summary The documentation for creating a Gateway and HTTPRoute resources has been updated to reflect changes in the reference links. Users can now access the latest information on the Gateway and HTTPRoute resources through the updated links, which direct them to the appropriate sections in the Gateway API documentation. This ensures that users have access to the most current and relevant information when configuring their services. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 05:12 |
||
|
Summary This document provides a guide on deploying the MetalLB extension for Azure Arc-enabled Kubernetes clusters using Azure CLI. It includes prerequisites, installation steps, and configuration details necessary for setting up a load balancer in AKS on Azure Local. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to quickly deploy an Azure Kubernetes Service (AKS) cluster with Azure Container Linux (ACL) for AKS using an Azure Resource Manager (ARM) template. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Compute ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now refers to "Confidential Virtual Machines (CVMs)" instead of "CVM," clarifying the terminology throughout the article. Users can now create node pools with both AMD and Intel-based Confidential VMs, enhancing their options for deploying secure workloads in Azure Kubernetes Service (AKS). Additionally, the supported OS versions section has been updated to reflect the latest compatibility details for CVMs, including specific defaults for various Kubernetes versions. |
||
|
|
||
|
Compute ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Compliance ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now correctly refers to the Federal Information Processing Standards (FIPS) in the context of AKS virtual machine sizes, improving the accuracy of compliance information. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn about GPU partitioning in Azure Kubernetes Service (AKS), including AKS managed multi-instance GPU (MIG) or time-slicing and multi-processing service (MPS) with self-managed NVIDIA GPU Operator. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to use the AI-powered troubleshooting assistant in AKS desktop to diagnose and resolve Kubernetes issues using natural language. |
||
|
|
||
|
Security ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation has been updated to reflect changes in the configuration for restricting access to Azure Container Registry using private endpoints, now linking to the correct private endpoints documentation. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-04 22:03 |
||
|
Summary Known limitations and scope for the Azure Kubernetes Service on bare metal public preview. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Cost ♻️ Rework Modified: 2026-06-05 06:02 |
||
|
Summary The documentation for Azure Kubernetes Service (AKS) has been updated to include guidance on two cluster modes: AKS Automatic and AKS Standard. Users can now choose AKS Automatic for a production-ready baseline with reduced management overhead or AKS Standard for more control over infrastructure and configuration. Additionally, the best practices section has been expanded to clarify the differences in implementation responsibilities and security controls between the two modes, enhancing user understanding of how to effectively manage their AKS environments. |
||
|
|
||
|
Cost ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-03 06:03 |
||
|
Summary The documentation has been updated to clarify the creation and delegation of the API server subnet for AKS Automatic, emphasizing that AKS will handle the delegation to `Microsoft.ContainerService/managedClusters` on behalf of the user. Additionally, users are now instructed to create both user node and system node subnets alongside the API server subnet when setting up a virtual network, enhancing clarity on the required network configuration. The Azure CLI version requirement has also been updated to version 2.86.0 or later. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for the Advanced Container Networking Services (ACNS) guide has been updated to enhance user experience in diagnosing and resolving network issues in Azure Kubernetes Service (AKS). The article now provides a user-first troubleshooting approach, detailing specific symptoms such as DNS failures, packet drops, traffic imbalances, and L7 errors, along with corresponding metrics and logs to check. Additionally, the guide emphasizes a task-oriented structure, allowing users to navigate directly to relevant playbooks based on their specific network issues. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now specifies that users must ensure their AKS cluster is running Kubernetes version 1.34.0 or later and that it is using Cilium version 1.18 or later for mutual TLS configuration. This update clarifies the minimum version requirements necessary for proper functionality. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 05:12 |
||
|
Summary Learn about the network requirements for deploying AKS enabled by Azure Arc clusters on Azure Local (multi-rack), including logical network configuration, IP address requirements, and port requirements. |
||
|
|
||
|
Security 🆕 New Modified: 2026-06-04 05:12 |
||
|
Summary This article introduces access and identity management options for Kubernetes clusters in AKS on Azure Local, emphasizing the use of Kubernetes role-based access control (RBAC) for securing cluster access. It details how to grant users and service accounts access to necessary resources, along with the limitations of Azure RBAC in multi-rack deployments. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-04 05:12 |
||
|
Summary The documentation now includes two new known issues related to AKS clusters: one for clusters with Azure Policy or Gatekeeper becoming unhealthy after an upgrade, and another for cluster creation failures following an Azure Local update from version 2510. Users can refer to these sections for guidance on troubleshooting these specific issues. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now states that Fleet Manager can support joining up to 1,000 Kubernetes clusters, an increase from the previous limit of 500. Additionally, it clarifies that Fleet Manager supports both Azure-hosted AKS clusters and Arc-enabled Kubernetes clusters as member clusters, removing the previous mention of Arc-enabled cluster support being in preview. |
||
|
|
||
|
Operations ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now recommends using `–os-type Linux` and `–os-sku AzureContainerLinux` when creating clusters and node pools for Azure Container Linux (ACL), which will ensure users are automatically updated to the latest default ACL version based on their Kubernetes version. Additionally, it clarifies that `–os-sku Ubuntu2204` is for rolling back to Ubuntu 22.04, and users must switch to a supported OS SKU to upgrade their Kubernetes version to 1.37 and above. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to migrate your Azure Kubernetes Service (AKS) cluster from cluster autoscaler to node auto-provisioning. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn CVE API endpoint definitions, request and response schemas, and data models for programmatically accessing vulnerability data for AKS‑managed platform components |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-03 22:12 |
||
|
Summary The documentation now includes a Service Level Agreement (SLA) for AKS Automatic clusters, detailing a pod readiness SLA that guarantees 99.9% of qualifying pod readiness operations complete within 5 minutes, benefiting workloads that require predictable scaling. Additionally, an uptime SLA guarantees 99.95% availability of the Kubernetes API server, both of which are automatically included with every AKS Automatic cluster without requiring user configuration. Changes also clarify that Pod Security Standards are now optional, allowing users to enforce Kubernetes best practices through Azure Policy controls in either enforcement or warning mode. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary The RBAC documentation for Kubernetes with Entra ID has been renamed, reflecting updates in the structure and content of the document. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary [!IMPORTANT] |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-04 05:12 |
||
|
Summary The documentation now specifies that the supported Kubernetes versions have been updated to include 1.33.4 and 1.33.5. Additionally, it clarifies that Windows node pools are not supported, providing users with clearer guidance on compatibility. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security 🗑️ Removal Modified: 2026-06-02 19:01 |
||
|
Summary This file has been removed, indicating a significant change in the documentation structure or content related to Azure RBAC management in AKS. The removal suggests a potential consolidation or update of related content elsewhere. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for installing Trident has been updated to reflect new links for the installation methods, including the Trident operator and `tridentctl`. Users can now access the updated Install Guide, which provides a more streamlined approach to deploying Trident, particularly for those using Helm. Additionally, the guidance for enabling Windows worker nodes remains unchanged, ensuring users are aware of this requirement during installation. |
||
|
|
||
|
Cost ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 20:12 |
||
|
Summary The documentation now correctly references "private endpoints (preview)" with an updated link to the relevant section, enhancing clarity on how to restrict access to the Azure Container Registry. Users can better understand the security features available in the Premium service tier, including image tag signing and integration with Microsoft Defender for Cloud for image scanning upon push. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how authorization for the Kubernetes API works in Azure Kubernetes Service (AKS), and how to choose between Kubernetes RBAC and Microsoft Entra ID authorization with optional Azure ABAC conditions. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-04 19:21 |
||
|
Summary The documentation has been updated to reflect the new version 1.10.28 for the service mesh integration with Azure Application Gateway for containers. Users can now access the latest features and improvements associated with this version, enhancing their integration experience. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 22:03 |
||
|
Summary Hardware, network, and Azure prerequisites for deploying Azure Kubernetes Service on bare metal. |
||
|
|
||
|
Operations 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for troubleshooting the Agentic CLI for Azure Kubernetes Service (AKS) has been updated to reflect its preview status. Users can now find more detailed troubleshooting steps for various issues, including Docker-related problems, Azure credential issues, and service account configurations, with clearer instructions and commands tailored for different operating systems. Additionally, the article emphasizes the importance of ensuring proper permissions and configurations for successful operation of the Agentic CLI. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for AKS Desktop has been updated to clarify its purpose and benefits for development teams, emphasizing that it simplifies application deployment and management on Azure Kubernetes Service (AKS) without requiring deep Kubernetes expertise. Users can now leverage features like Projects for grouping related resources, guided workflows for deploying applications without writing manifests, and enhanced observability tools for monitoring application health and performance. Additionally, the documentation now highlights the integration of AKS Desktop with existing tools and environments, making it easier for teams to manage applications across multiple clusters and environments. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now clarifies that the ACNS Security Agent with FQDN filtering ensures seamless DNS resolution and policy enforcement even if the Cilium agent fails, enhancing security and stability in dynamic environments. Additionally, it emphasizes that if Advanced Container Networking Services (ACNS) security is disabled, FQDN and L7 policies will be blocked, and it provides guidance for Alpine-based container images facing DNS resolution issues with Cilium Network Policies. |
||
|
|
||
|
Compute 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for AKS Automatic Clusters with Managed System Node Pools has been updated to clarify that managed system node pools are now enabled by default for new AKS Automatic clusters. Users can benefit from simplified cluster creation as they no longer need to track compute quotas for system node pools, which AKS manages automatically. Additionally, the documentation highlights that features like autoscaling and node repair are enabled for system nodes in the managed system node pool, enhancing performance and reliability. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation for Azure Container Registry has been updated to reflect support for Azure Private Link, allowing users to create private endpoints from a virtual network to the registry. Users are now directed to the correct resources for connecting privately to the registry and configuring access rules behind a client firewall, enhancing their ability to manage network security and access. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now reflects that Windows Server 2025 is officially supported, removing the "Preview" designation. Additionally, users can now extend the service IP range after cluster creation using the `ServiceCIDR` Kubernetes resource starting with Kubernetes version 1.33, enhancing network configuration flexibility. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to quickly deploy an Azure Kubernetes Service (AKS) cluster with Azure Container Linux (ACL) for AKS using the Azure CLI. |
||
|
|
||
|
Compute 🆕 New Modified: 2026-06-04 05:12 |
||
|
Summary The documentation now includes support for the NVIDIA RTX Pro 6000 GPU model in Azure Kubernetes Service (AKS) on Azure Local, along with its associated VM sizes. Users can now utilize the RTX Pro 6000 with specific SKUs, enhancing their GPU options for workloads. Additionally, the GPU model names have been standardized to "NVIDIA" throughout the document for consistency. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 05:12 |
||
|
Summary This article explains how to deploy sample OPC PLC server containers in Azure and discover them by deploying Akri on an AKS Edge Essentials cluster, detailing the communication protocol used in industrial automation. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 22:03 |
||
|
Summary Learn how to delete Azure Kubernetes Service on bare metal cluster resources and edge machine resources from Azure in the correct order. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-05 22:08 |
||
|
Summary The documentation for the Azure Kubernetes Service (AKS) has been updated to recommend starting with **AKS Automatic** as the default for most production workloads, highlighting its preconfigured best-practice defaults for scaling, security, networking, monitoring, and upgrades. Users can now choose between two cluster modes: **AKS Automatic**, which is ideal for most scenarios, and **AKS Standard**, which allows for deeper customization of platform configurations. Additionally, the section on creating AKS clusters has been expanded to include specific instructions for creating Linux-based AKS Automatic clusters. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Compute ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for using the Cluster Autoscaler in Azure Kubernetes Service (AKS) has been updated to clarify commands and parameters. Users can now find consistent command formatting for creating and updating AKS clusters with the `–enable-cluster-autoscaler`, `–min-count`, and `–max-count` parameters, as well as for setting the cluster autoscaler profile. Additionally, the section on retrieving cluster autoscaler logs has been refined to specify enabling control plane logging for better diagnostics. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now includes an updated link for creating a free Azure account, directing users to a more relevant page for account setup. Additionally, the section on registering the `EnableAzureCNIOverlayPodCIDRExpansion` feature flag remains unchanged, ensuring users can still follow the same steps to enable pod CIDR expansion in Azure CNI Overlay AKS clusters. |
||
|
|
||
|
Security 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary This article explains how to enable a system-assigned managed identity on a new or existing AKS cluster, get the principal ID of the system-assigned managed identity, and add a role assignment for the system-assigned managed identity. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 19:21 |
||
|
Summary The documentation has been updated to provide users with the latest links to the Gateway and HTTPRoute resources in the Gateway API. Users can now access the most current information on creating a Gateway resource with an HTTPS listener and an HTTPRoute that references a backend service, ensuring they are following the latest guidelines and best practices. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to view VM SKUs that are available for AKS node pool creation in a specific Azure region. |
||
|
|
||
|
Cost 🆕 New Modified: 2026-06-05 22:08 |
||
|
Summary The documentation now includes detailed guidance on the differences between AKS Automatic and AKS Standard cluster modes, emphasizing that AKS Automatic offers preconfigured reliability defaults, while AKS Standard requires explicit management of reliability features. Users can now better understand the implications of cluster mode on operational readiness, scaling behavior, and the need for application-specific settings, such as Deployment Safeguards and Pod Disruption Budgets. Additionally, the article clarifies that Container Insights is enabled by default in AKS Automatic but remains optional in AKS Standard, enhancing user awareness of monitoring capabilities across different cluster configurations. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now highlights that the Confidential Containers preview will sunset in March 2026, after which users will experience reduced functionality and will be unable to create new nodes with the `KataCcIsolation` runtime. It also provides alternative options for users to transition away from Confidential Containers, including Confidential VMs on AKS, application enclave support, and Azure RedHat OpenShift Confidential Containers, among others. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary [!IMPORTANT] |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 05:12 |
||
|
Summary This document provides an overview of supported Kubernetes versions for AKS on Azure Local, including compatibility notes and upgrade paths to ensure clusters remain supported and secure. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 05:12 |
||
|
Summary Plan the IP addresses needed to deploy AKS enabled by Azure Arc clusters on Azure Local (multi-rack), including node IPs, control plane endpoints, and load balancer addresses. |
||
|
|
||
|
General 🗑️ Removal Modified: 2026-06-02 19:01 |
||
|
Summary This document has been removed, indicating a significant change in the approach to authentication in AKS. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now includes updated details on the `terminationGracePeriodSeconds`, `minReadySeconds`, and `healthCheckNodePort` parameters, providing users with clearer guidance on configuring pod lifecycle, deployment readiness checks, and service health probe settings. These enhancements allow users to better manage application availability and performance in their Istio Gateway API configurations. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for Azure NetApp Files has been updated to reflect new links for the Trident installation guide, Helm chart, and Trident CLI commands. Users can now access the quickstart guide and updated installation instructions, which may streamline their deployment process and provide more current information for setting up Trident in Kubernetes environments. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-04 19:21 |
||
|
Summary The documentation has been updated to reflect the latest version of the application gateway for containers, changing the version parameter from 1.10.21 and 1.10.27 to 1.10.28 in multiple command examples. Users can now utilize the updated version, which may include new features or fixes not present in the previous versions. This change ensures that users are following the most current practices when deploying the application gateway. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now clarifies that to use dual-stack networking, users must have Kubernetes version 1.26.3 or later, along with the `azure` network plugin and `overlay` mode. Additionally, the command syntax for enabling API Server VNet integration has been updated to use `–enable-apiserver-vnet-integration` instead of `–enable-api-server-vnet-integration`, ensuring users have the correct command for deploying both public and private AKS clusters. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary Step-by-step guide to migrate ingress traffic from the application routing add-on with ingress-nginx to the application routing Gateway API (Istio) implementation on Azure Kubernetes Service with zero downtime. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The author information has been updated in the AKS extension draft GitHub workflow documentation, reflecting the current contributors and improving the accuracy of authorship. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-03 06:03 |
||
|
Summary This document has been updated to include AKS on bare metal as a supported distribution and to remove the preview label from Arc-enabled clusters. These updates enhance the clarity and comprehensiveness of the supported environments for Azure Kubernetes Fleet Manager. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Cost 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for optimizing costs in Azure Kubernetes Service (AKS) has been updated to emphasize the use of AKS Automatic for built-in cost optimization, which simplifies the configuration process and reduces operational overhead. Users can now leverage features like node auto-provisioning, workload autoscaling, and managed Prometheus without additional setup, ensuring more efficient resource utilization and cost savings. Additionally, the article now includes detailed descriptions of cost-efficient infrastructure options and best practices for managing workloads effectively. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now includes additional information on planning IP addresses for Azure Kubernetes Service clusters, specifically for users bringing their own virtual network. This enhances clarity on prerequisites for network configuration. |
||
|
|
||
|
Cost 🆕 New Modified: 2026-06-05 06:02 |
||
|
Summary The documentation now includes detailed guidance on choosing between AKS Automatic and AKS Standard for MLOps, highlighting their differences in cluster management and operational behavior. Users can better understand how to leverage preconfigured defaults in AKS Automatic versus the explicit configurations required in AKS Standard, enhancing their ability to implement MLOps practices effectively. Additionally, the section on security controls emphasizes the importance of integrating scanning for Common Vulnerabilities and Exposures (CVEs) and maintaining an audit trail for compliance, which are critical for both cluster modes. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for eBPF Host Routing has been updated to clarify that enabling this feature updates nodes through rolling upgrades for node pools, ensuring existing connections are respected during node drain timeout. Additionally, it now explicitly states that eBPF Host Routing supports dual-stack connectivity and cannot be used with Static Egress Gateway or Istio Ambient in self-managed installations with ACNS Performance mode. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now includes a new section on DNS resolution in AKS, highlighting the use of CoreDNS for internal name resolution and introducing LocalDNS as an option for improved performance and reliability. Users can now learn about LocalDNS, which deploys a DNS proxy on each node to reduce latency, alleviate `conntrack` table pressure, and enhance workload resilience during upstream DNS outages, particularly in large clusters or high query environments. |
||
|
|
||
|
Security ♻️ Rework Modified: 2026-06-05 17:15 |
||
|
Summary The documentation now clarifies the role of `Container Registry Contributor and Data Access Configuration Administrator`, specifically detailing that it allows developers and command line scripts to authenticate and log in to the registry using the `az acr login` command, as well as to execute other `az` CLI control plane commands. Additionally, the scenarios have been updated to specify that this role does not grant data plane permissions, which are managed separately, enhancing user understanding of permissions related to Azure Container Registry. |
||
|
|
||
|
Operations 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now clarifies that Windows Server 2025 is supported starting in Kubernetes version 1.32, removing the previous mention of it being in preview. Additionally, users are informed that Windows Server 2025 requires a minimum version of the `aks-preview` Azure CLI extension, specifically version 18.0.0b5, to function properly. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary This new quickstart guide provides detailed instructions on deploying and managing applications using AKS Desktop without writing Kubernetes manifests. It includes prerequisites, environment variable setup, and commands for creating Azure resources, making it easier for developers to get started with AKS. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now clarifies that the feature discussed is not compatible with API Server VNet Integration, providing users with important information regarding feature limitations. This change helps users understand the constraints when planning their network configurations in Azure Kubernetes Service (AKS). |
||
|
|
||
|
General ✨ Update Modified: 2026-06-04 05:12 |
||
|
Summary Learn about the architecture of AKS enabled by Azure Arc on Azure Local (multi-rack), including how clusters are deployed, managed, and connected to Azure. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The AI toolchain operator documentation has been updated with new examples and clearer instructions for fine-tuning models, improving usability for developers. |
||
|
|
||
|
Operations ✨ Update Modified: 2026-06-04 05:12 |
||
|
Summary This document outlines the process for upgrading an AKS cluster on Azure Local for multi-rack deployments, detailing the steps required for a seamless upgrade and the supported Kubernetes versions. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-04 19:21 |
||
|
Summary The documentation now includes updated links for the Gateway and HTTPRoute resources, directing users to the latest API overview and reference pages. This change ensures that users have access to the most current information and guidelines when creating a Gateway resource with an HTTPS listener and an HTTPRoute that references a backend service. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security 🆕 New Modified: 2026-06-02 20:12 |
||
|
Summary This document has been updated to include new firewall rules for Azure Container Registry, enhancing security measures and providing users with the latest guidelines for configuring access rules effectively. |
||
|
|
||
|
Operations ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation for accessing Azure Container Registries has been updated to reflect changes in the links for dedicated data endpoints and private link configurations. Users will now find references to "container-registry-firewall-rules" and "container-registry-private-endpoints" instead of the previous terms, ensuring they access the correct resources for configuring firewall rules and private connections. This update enhances clarity and directs users to the appropriate sections for troubleshooting access issues. |
||
|
|
||
|
Compute 🆕 New Modified: 2026-06-04 05:12 |
||
|
Summary The documentation now includes updated installer versions for Kubernetes and K3s, specifically K8s installer version 1.33.5 and K3s installer version 1.33.5. Users can now access the latest installers through the provided links, ensuring they are using the most current versions for their setups. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Security 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation has been updated to clarify the prerequisites for creating a service account and configuring workload identity for the Agentic CLI for Azure Kubernetes Service (AKS). Users are now explicitly instructed to check their Azure CLI version and set their active subscription before proceeding, along with detailed commands for verifying the creation of service accounts and role bindings. Additionally, the section on workload identity now includes specific commands for assigning roles to managed identities, enhancing clarity on the setup process. |
||
|
|
||
|
Operations ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Cost ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Storage 🆕 New Modified: 2026-06-03 22:12 |
||
|
Summary The documentation now includes a new storage class, `managed-csi-premium-v2`, which utilizes Azure Premium SSD v2 locally redundant storage (LRS) for managed disks, available starting with Kubernetes version 1.35. Additionally, it clarifies that when creating a new AKS cluster or adding a node pool, the default OS disk size is determined by the number of vCPUs, and it emphasizes that AKS defaults to ephemeral OS disks if Azure Managed Disks are not explicitly requested. Furthermore, the documentation highlights that starting with Kubernetes version 1.29, AKS utilizes zone-redundant storage (ZRS) for managed disks in multi-availability zone deployments, enhancing data resilience. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation now correctly references the dedicated data endpoint for the Azure container registry, directing users to the appropriate section on enabling firewall rules instead of access rules. This change ensures that users can accurately follow the steps necessary for their connected registry to communicate effectively with the cloud registry. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 20:12 |
||
|
Summary The documentation now clarifies the authentication requirements for Red Hat registries in the artifact cache overview. Users can see that the Red Hat Registry (`registry.redhat.io`) supports only authenticated pulls, while the Red Hat Public Registry (`registry.access.redhat.com`) allows unauthenticated pulls, providing clearer guidance for using these registries with Azure CLI. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 20:09 |
||
|
Summary The documentation now includes a note about the retirement of the Windows annual channel, providing important information for users managing Windows containers. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Learn how to enable Microsoft Entra ID authentication for the Kubernetes API server (control plane) on an Azure Kubernetes Service (AKS) cluster. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-04 19:21 |
||
|
Summary The documentation has been updated to clarify the implementation of GRPCRoute resources through the Kubernetes Gateway API, providing a link to the relevant API specification. |
||
|
|
||
|
Storage ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now clarifies that starting with Kubernetes 1.33, users can extend the service IP range after cluster creation using the `ServiceCIDR` resource, which was not previously possible. This update allows for greater flexibility in managing service address ranges in Kubernetes clusters. Users running earlier versions are still limited to the original service address range set at cluster creation. |
||
|
|
||
|
Compute 🆕 New Modified: 2026-06-04 17:03 |
||
|
Summary The documentation now specifies that users can create an AKS cluster with a GPU-enabled default node pool using newly added GPU types, including NVIDIA L-series GPUs and NVIDIA RTX 6000 Ada GPUs. Additionally, the commands for creating the cluster and adding a node pool have been updated to use the placeholder `<GPU_ENABLED_VM_SIZE>` instead of the previous `<Standard_NC16_L4_1>`, allowing for more flexibility in selecting GPU sizes. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Operations 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now emphasizes the deprecation of Availability Sets in Azure Kubernetes Service (AKS) and provides guidance on migrating to Virtual Machine node pools, which offer enhanced management features. Users can utilize a new script to facilitate this migration, which also upgrades Basic-tier load balancers to Standard-tier. Additionally, the article clarifies the necessary steps and commands for verifying the migration’s success and managing associated resources. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-03 06:03 |
||
|
Summary This article provides guidance on updating existing Azure Kubernetes Service (AKS) clusters to newer IP address management (IPAM) modes and data plane technologies. It covers the migration path to Azure CNI Overlay for IPAM and Azure CNI Powered by Cilium for the data plane, highlighting the benefits of these updates. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-05 22:08 |
||
|
Summary The documentation now includes detailed guidance on using AKS Automatic and AKS Standard for AI and ML workloads, highlighting the differences in cluster operations, node management, upgrades, security, monitoring, and networking. Users can choose AKS Automatic for faster setup with preconfigured defaults or AKS Standard for deeper customization options. Additionally, the section on designing and deploying AI and ML workloads has been expanded to emphasize the benefits of using high-performance infrastructure and improved operational reliability. |
||
|
|
||
|
General ♻️ Rework Modified: 2026-06-02 20:12 |
||
|
Summary The documentation now clarifies that IP network rules do not apply to private endpoints configured with Private Link, directing users to the updated section on private endpoints. Additionally, the guidance for setting up registry access rules from behind a client firewall has been refined, ensuring users have the correct references for both private endpoints and firewall rules. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-04 05:12 |
||
|
Summary The document outlines the latest updates for AKS on Azure Local, including the deprecation of KMS v1 and the introduction of KMS v2 for secret encryption. It also notes the end of support for Kubernetes version 1.30 and highlights the importance of upgrading to supported versions. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Operations ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now includes updated deprecation dates for several API versions, extending the timeline for users to transition to newer versions. Specifically, the newly added entries for the 2023-10-02-preview through 2024-09-02-preview versions indicate that these will be announced on March 24, 2026, and deprecated on July 1, 2026, providing users with additional time to adapt to changes. |
||
|
|
||
|
Compute ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now clarifies that when transitioning from the Istio service mesh add-on to the application routing Gateway API implementation, users must delete specific Istio CRDs and the Istio GatewayClass to prevent control plane failures. Additionally, it specifies that configuring HTTPS ingress access via the `TLSRoute` resource is currently unsupported and will be available only after AKS adds support for Istio 1.30. Users are also informed that they must use Azure CLI version `2.86.0` or higher for compatibility. |
||
|
|
||
|
Security ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General 🆕 New Modified: 2026-06-02 19:01 |
||
|
Summary The documentation for AKS Automatic clusters has been updated to clarify several limitations and requirements. Users must now ensure their subscription has a quota for 16 vCPUs of specific virtual machine sizes when deploying clusters, and Azure CLI version 2.86.0 or later is required. Additionally, new AKS Automatic clusters will automatically enable managed system node pools and LocalDNS, and several extensions, including Dapr and Azure Machine Learning, are no longer supported. |
||
|
|
||
|
Networking ♻️ Rework Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now specifies that Azure CLI version 2.48.1 or later is required to assign IP addresses from an overlay network or a virtual network, and version 2.69.0 or later is needed for assigning IP addresses from the node subnet. Additionally, the Local Redirect Policy (LRP) is confirmed to be supported from Kubernetes version 1.29 and above, with updated YAML examples provided for configuring Cilium Network Policies to allow pod egress to LocalDNS IP addresses. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 20:12 |
||
|
Summary Reference for all Azure Container Registry endpoint types, including global, regional, and dedicated data endpoints, along with CLI flag details. |
||
|
|
||
|
Cost ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
General ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary Updates content with clarifications and improvements. |
||
|
|
||
|
Networking ✨ Update Modified: 2026-06-02 19:01 |
||
|
Summary The documentation now specifies that Cilium installs iptables rules to redirect outbound traffic to the ztunnel on port 15001, enhancing traffic management within the pod network. Additionally, it clarifies that when a namespace is labeled with “io.cilium/mtls-enabled=true,” all pods in that namespace are enrolled, ensuring that every packet is encrypted without any plaintext exposure. Users can expect improved security and traffic handling in their Kubernetes environments with these updates. |
||
|
Full tracker with filters: Azure Container Services Docs Tracker
