Loading...

AKS on Azure Stack HCI and Windows Server - May 2022 update

AKS on Azure Stack HCI and Windows Server - May 2022 update

Hello everyone,

 

The May update of AKS on Azure Stack HCI and Windows Server is now available! 

 

This is primarily a security and quality update, however, we did add the ability to update no_proxy configurations and have improved cert management .  While not a product change, we published guidance for integrating AAD role based access controls (RBAC) with kubernetes RBAC.

 

As always, you can try AKS on AzureStack HCI or Windows Server any time by registering here. If you do not have the hardware handy to evaluate AKS on physical hardware you can use an Azure VM:  https://aka.ms/aks-hci-evalonazure.

 

Here are some of the changes you'll see in this update:

 

Update proxy exclusion list (no-proxy settings) without needing to redeploy using PowerShell

If you want to change the proxy exclusion list for your AKS deployment (which may happen if you have trusted components outside your corporate environment), we now offer the ability to change that proxy exclusion list post deployment using PowerShell. Previously, you'd need to redeploy in order to change your proxy exclusion settings.  Once the list has been updated, changes will take effect at the next AKS update.

 

For example, running `Set-AksHciProxySetting -noProxy constoso.azurecr.io` adds the URL to the proxy exclusion list for your AKS deployment. Read more.

 

Guidance for using Azure AD (AAD) for Kubernetes role based access control (RBAC)

Kubernetes has many tools for configuring role-based access controls (RBAC), many of which are based on tokens.  Managing certs and tokens is annoying over time deferred maintenance can lead to an insecure Kubernetes deployment.  This is why I'm so excited to share that we now have guidance for AKS cluster administrators to configure Kubernetes RBAC roles using Azure Active Directory (Azure AD) for user authentication!

 

In this configuration, AKS cluster administrators can use the built-in Kubernetes role-based access control (Kubernetes RBAC) or make custom RBAC roles to manage access to namespaces and cluster resources based on a user's identity or group membership in Azure AD.

Clusters users simply have to login to Azure and use Azure Arc to access the cluster namespace from anywhere. For more information and a step-by-step guide, read more in the docs.

 

Improved our certificate management and added instructions for repairing expired internal certificates

Now that AKS on HCI and Windows Server has been in market for a year (!) we're beginning to run into cert lifecycle issues based on cert lifecycle and rotation both with our internal certificates and the certificates people add so that Kubernetes can run in your own unique IT environment.

 

We have done several things to help with certificate lifecycle:

  1. We strategically modified the lifecycle of our internal certs to span 2 releases incase folks skip an update.
  2. We're introducing new certificate repair cmdlets.

 

Security and reliability improvements

Updated versions of underling components:

  • New Mariner kernel version with too many CVEs fixed to list.  Read more about the May Mariner Update.
  • Updated to CAPI v0.4.8
  • Updated ContainerD to 1.5.9
  • Updated kube-vip
  • Updated Calico versions to match between Windows and Linux nodes

Bug fixes:

  • CAPH pod had been failing to renew its certificate, causing the certificate to expire - we have fixed this so certs renew appropriately.

 

Documentation

We published a of new documentation this month from new docs supporting AAD RBAC, no-proxy changes, more troubleshooting guides, and some language changes.

 

Supporting documentation for AAD RBAC - Control access using Azure AD and Kubernetes RBAC Azure Kubernetes Service on Azure Stack HCI and Windows Server

 

We also updated topics related to proxy to accommodate the changes to no-proxy and some other minor fixes:

 

New docs for certificate management -

 

While largely clerical, this month includes a language shift from "AKS on HCI" to "AKS on HCI or Windows Server" throughout our docs.  We were finding that the service name (AKS-HCI) was leading to confusion about Windows Server support.  This should be much less confusing with the latest round of doc changes.

 

Last but not least, we also published new troubleshooting guides:

Once you have downloaded and installed the AKS on Azure Stack HCI April Update – you can report any issues you encounter and track future feature work on our GitHub Project at  https://github.com/Azure/aks-hci.

 

We look forward to hearing from you all!

 

Cheers,

Sarah

Published on:

Learn more
Azure Stack Blog articles
Azure Stack Blog articles

Azure Stack Blog articles

Share post:

Related posts

Public Preview of Azure Migrate from VMware to Azure Stack HCI

Today, we are thrilled to announce the public preview of the Azure Migrate functionality to migrate VMs from VMware to Azure Stack HCI, a sign...

1 year ago

Sneak peek at new Azure edge infrastructure at Hannover Messe 2024

Written by Cosmos Darwin, Principal Group Manager on the Azure Edge & Platform team This week is Hannover Messe 2024, the world’s biggest ...

2 years ago

Apply critical update for Azure Stack HCI VMs to maintain Azure verification

Azure verification for VMs on Azure Stack HCI makes it possible for Azure-exclusive benefits to work outside of the cloud and in on-premises a...

2 years ago

Logical Networks in Azure Portal for HCI: Setting the Stage for Software Defined Networking

At this past Microsoft Ignite 2023, we officially announced the public preview of logical networks in Azure Portal for Azure Stack HCI. These ...

2 years ago

Introducing Azure Virtual Desktop workload in Azure Stack HCI Sizer!

Earlier in February 2024, we announced the general availability of Azure Virtual Desktop for Azure Stack HCI which extends the capabilities of...

2 years ago

Hyper-V VM Migration to Azure Stack HCI, version 23H2

Written by Kerim Hanif, Senior Program Manager on the Azure Edge & Platform team     Azure Migrate is a unified platform t...

2 years ago

Possible MAC address assignment strategies for tenant VMs running on Stack-HCI environment

Azure Stack HCI is a hyperconverged infrastructure (HCI) cluster solution consists of windows servers (Hyper-V), Storage Spaces Direct, a...

2 years ago

Azure Stack HCI version 23H2 is generally available

Written by Cosmos Darwin, Principal PM Manager on the Azure Edge & Platform team     Today we’re announcing the general availab...

2 years ago

AKS enabled by Azure Arc is now available on Azure Stack HCI 23H2

  Azure Kubernetes Service (AKS) allows you to run a managed Kubernetes solution at the edge wherever you need it, with built-in support...

2 years ago

MAC address assignment strategies for tenant VMs running on Stack-HCI environment

Azure Stack HCI is a hyperconverged infrastructure (HCI) cluster solution consists of windows servers (Hyper-V), Storage Spaces Direct, a...

2 years ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.