Traefik Loadbalancer is enabled in my AKS cluster needs to use istio service mesh for mtls
Traefik Loadbalancer is used as external loadbalancer need to use istio for mtls in my AKS cluster if i enable istio addon will it help for me to set up only mtls without loadbalancer. The aim is to make communication between the pods using istio and…
Unable to upgrade AKS cluster due to InvalidAuthenticationTokenTenant for VNet
Hi, we have a Kubernetes cluster which was down for 2 months due to non payment. Now we have made the payment but the cluster is in Failed (Running) state because the kubernetes version of control plane is 1.26.6 which is not supported any more by Azure.…
How to increase subnet size to solve "insufficient Subnet Size" for aks system subnet while upgrading
Hello, We have an AKS cluster configured with the AzureCNI plugin for networking, which means that the pods take IP addresses from the subnet. Currently, there are only 9 IP addresses available, preventing us from updating the cluster. To resolve…
nestjs microservices using grpc to azure kubenertes using the LoadBalancer service
Hello, we have deployed a nestjs microservices using grpc to azure kubenertes using the LoadBalancer service method exposing a public IP from azure. The application itself is running and working, but sporadic we are getting the status code 14 unavailable…
Custom Role with least privileged permission to install apps in AKS
Hi Team, We are using Azure RBAC for authentication and authorization in AKS and with this authentication we want to grant access to a team to install apps on the AKS what are the minimum permission we need to give to an app teams to install apps like…
![](https://techprofile.blob.core.windows.net/images/Nw9OZIzCZUiYqD_eTMTQaA.png?8D812F)
AKs nodepool upgrade failure on pool with Standard_NC6s_v3 gpu machines
Received the following error when attempting to up to run a node pool upgrade via the azure cli on an existing pool using the Standard_NC6s_v3 machine type: (OperationNotAllowed) Code="OperationNotAllowed" Message="The 'Placement' option…
AKS unable to pull images from mcr.micosoft.com
Hello I am having few AKS private clusters which were running normal, but overnight I started observing following issues in many kube-system pods: Failed to pull image "mcr.microsoft.com/***": rpc error: code = Unknown desc = failed to pull and…
Not able to install AppServices Extension into Arc onprem cluster, MicroK8s
I am failing to install AppService extension into my Arc K8s cluster, running by MicroK8s. Have a VM in datacenter, Ubuntu 22, installed lates Azure CLI and all the required extensions according to…
![](https://techprofile.blob.core.windows.net/images/lERuGqIsfE-3j2IJgoDLSw.png?8D844E)
Istio Service Mesh
Current Setup: With Free Trial Azure Cloud Account. I am following below docs to setup Istio on my AKS CLuster https://learn.microsoft.com/en-us/azure/aks/istio-deploy-addon https://learn.microsoft.com/en-us/azure/aks/istio-deploy-ingress When I…
Control access to blob container from a pod running on AKS in a multi tenant deployment
We have a scenario where we are having a storage account that is accessed using user managed identity from pods on AKS. We have separate pods running for each tenant on AKS and have a separate blob container for storing a tenant's data. How can we…
Outbound connection failed when connecting k8s cluster
I'm trying to register an existing k8s cluster with azure arc. I've run the following command on one of the k8s nodes: az connectedk8s connect -g $ARC_RG_NAME -n $ARC_CLUSTER_NAME -l "West Europe" And get the following output: ~$ az…
Error when upgrading node pool: Kind and SKU Basic do not match
I am encountering an error when trying to upgrade a node pool in Germany West Central. The error message says: (BadRequest) Kind and SKU Basic do not match, please make them match or not set Kind Code: BadRequest Message: Kind and SKU Basic do not…
![](https://techprofile.blob.core.windows.net/images/lERuGqIsfE-3j2IJgoDLSw.png?8D844E)
Application Gateway for Containers, how to secure the public IP on the frontend?
Question: Securing Public IP frontend for Application Gateway for Containers I am considering using Azure Application Gateway for Containers with my internal private DNS and a private AKS cluster. I would appreciate some guidance on how best to secure…
![](https://techprofile.blob.core.windows.net/images/lvNaBJBqh0eurOu4q2bQSQ.png?8DA4E8)
Why does my AKS cluster i just deployed has lots of vulnerabilities after running a WIZ scan
We recently deployed a private AKS cluster 1.28.5 version. Cluster is not yet configured. We installed Helm and then ran a WIZ scan to identify vulnerabilities. Several vulnerabilities were identified, please see screenshot below. Was wondering were…
Why do Pods fail to mount PersistentVolumes that were just created by the StorageClass provisioner?
When creating PersistentVolumeClaims for storage classes provisioned by disk.csi.azure.com, the generated PersistentVolumes are bound immediately, but they are not available when starting Pods that use them. I get events like: Warning …
getaddrinfo EAI_AGAIN error when connecting to Postgres DB
Hi, One of our team is getting the below error when their API hosted in AKS connecting to Postgres DB (Configured using Private endpoint). This error is generated at random requests, say in a day 50 requests fails due to this. I verified the internal…
AKS Service Mesh-Istio returning unknown gvk: security.istio.io/v1, Kind=AuthorizationPolicy
Three months ago I successfully created a AuthorizatioPolicy in the preview version (1.18) of the Istio Service Mesh into our AKS cluster. Yesterday, I made an attempt to modify the policy and received the following error: Error from server: error when…
Use one user assigned managed-identity for all subscriptions VS. Use one user assinged managed-identity for each subscription
Hi, In CMEK scenario, according to this article:…
AKS Taints & Tolerations
How to ensure AKS system pods to run only on System node pool and application pods to run only on the user node pools? I do NOT want application pods to be on system node pool and system pods to be on user node pool. I see that creating a dedicated…
Memory & CPU Utilization drastically different for AKS
I am planning to use Descheduler in my AKS deployment to balance memory consumption of AKS nodes. My current output of kubectl top nodes is: NAME CPU(cores) CPU% MEMORY(bytes) MEMORY% …
![](https://techprofile.blob.core.windows.net/images/lERuGqIsfE-3j2IJgoDLSw.png?8D844E)