AKS Service Mesh-Istio returning unknown gvk: security.istio.io/v1, Kind=AuthorizationPolicy
Three months ago I successfully created a AuthorizatioPolicy in the preview version (1.18) of the Istio Service Mesh into our AKS cluster. Yesterday, I made an attempt to modify the policy and received the following error: Error from server: error when…
Error when upgrading node pool: Kind and SKU Basic do not match
I am encountering an error when trying to upgrade a node pool in Germany West Central. The error message says: (BadRequest) Kind and SKU Basic do not match, please make them match or not set Kind Code: BadRequest Message: Kind and SKU Basic do not…
Application Gateway for Containers, how to secure the public IP on the frontend?
Question: Securing Public IP frontend for Application Gateway for Containers I am considering using Azure Application Gateway for Containers with my internal private DNS and a private AKS cluster. I would appreciate some guidance on how best to secure…
Why does my AKS cluster i just deployed has lots of vulnerabilities after running a WIZ scan
We recently deployed a private AKS cluster 1.28.5 version. Cluster is not yet configured. We installed Helm and then ran a WIZ scan to identify vulnerabilities. Several vulnerabilities were identified, please see screenshot below. Was wondering were…
Why do Pods fail to mount PersistentVolumes that were just created by the StorageClass provisioner?
When creating PersistentVolumeClaims for storage classes provisioned by disk.csi.azure.com, the generated PersistentVolumes are bound immediately, but they are not available when starting Pods that use them. I get events like: Warning …
getaddrinfo EAI_AGAIN error when connecting to Postgres DB
Hi, One of our team is getting the below error when their API hosted in AKS connecting to Postgres DB (Configured using Private endpoint). This error is generated at random requests, say in a day 50 requests fails due to this. I verified the internal…
Is Azure Kubernetes Service (AKS) an IaaS or Paas?
Is AKS considered an IaaS or Paas? Is ACS considered an Iaas?
AKS Taints & Tolerations
How to ensure AKS system pods to run only on System node pool and application pods to run only on the user node pools? I do NOT want application pods to be on system node pool and system pods to be on user node pool. I see that creating a dedicated…
Service principal creation failed by privilege access
We are trying to create a main service for Atlas MongoDB to provide access to our API in Kubernetes, however, we saw that our permission was not necessary to be able to create the account, when trying to add the permission (Global Administrator) we saw…
Use one user assigned managed-identity for all subscriptions VS. Use one user assinged managed-identity for each subscription
Hi, In CMEK scenario, according to this article:…
Nodes Not ready state
Hi Team, I am trying to provision AKS cluster and the nodes are ending with Not ready state. These are the system/default nodes. Can you please help me with this. Steps tried: Multiple times re-provisioned the cluster and VMSS. Deleted nodes and start…
Azure Retirement: Azure Kubernetes Service 2022-11-02-preview API end of life is 20 June 2024
I have received this notice earlier. How i am suppose to see which API CLI is using? The query provided in notification is not working. API_VERSION=2022-04-01-preview az monitor activity-log list --offset 30d --max-events 10000 --namespace…
AKS Azure network policy manager not applying policies properly
Not a question, but there's no place for bug reports Azure network policy manager does not enforce defined network policies on the local node. For example if you define a network policy to filter out all egress traffic from the pod, the traffic going…
![](https://techprofile.blob.core.windows.net/images/lERuGqIsfE-3j2IJgoDLSw.png?8D844E)
Memory & CPU Utilization drastically different for AKS
I am planning to use Descheduler in my AKS deployment to balance memory consumption of AKS nodes. My current output of kubectl top nodes is: NAME CPU(cores) CPU% MEMORY(bytes) MEMORY% …
![](https://techprofile.blob.core.windows.net/images/lERuGqIsfE-3j2IJgoDLSw.png?8D844E)
Implement AKS egress via private endpoint
Hello, We have a private AKS cluster with ingress connected to the corporate virtual network via a private link service. This works wonderfully and is well-supported by Azure, allowing communication with services in the cluster from the corporate…
![](https://techprofile.blob.core.windows.net/images/lERuGqIsfE-3j2IJgoDLSw.png?8D844E)
Migrating a SaaS app to Azure Cloud Platform
I am looking to migrate my SaaS product to the Azure Cloud Platform and I need some resources and a quote for the move. Can anyone provide guidance on how to proceed with the migration process and recommend resources that could help me?
AKS upgrade failing which GPU node pool "(OperationNotAllowed) Code="OperationNotAllowed" Message="The 'Placement' option override for the ephemeral OS disk is not supported. Please upgrade the VM Size with desired placement option for provisioning the "
AKS version upgrade failing becuase it's having GPU noedpool (OperationNotAllowed) Code="OperationNotAllowed" Message="The 'Placement' option override for the ephemeral OS disk is not supported. Please upgrade the VM Size with desired…
AKS pod websocket connection is breaking
I am using AKS to run my pods and Azure Application Gateway as a web traffic load balancer. I have an issue with one of the pods using WebSocket, the WebSocket connection is breaking. The Application Gateway documentation states that Application Gateway…
Memory consumption by ama-logs and ama-logs-rs containers
Hello, I've enable container insight for AKS cluster with settings: Cost-optimized preset Prometheus endpoint disabled In result were added log analyzers containers to the nodes with next memory consuming: ama-logs for each node with consuming …
How can I expose a TCP service using AKS Gateway Controller
Hello, I have an AKS cluster where I have successfully deployed the Azure Application Gateway controller. I have a GatewayClass for the "alb.networking.azure.io/alb-controller" However, when I want to create a Gateway resource to use this with…