Microsoft.ContainerService 託管群集

Remarks

有關可用附加元件的資訊,請參見 Add-ons, extensions 及其他與 Azure Kubernetes Service 的整合。

Bicep 資源定義

managedClusters 資源類型可以使用目標作業來部署:

如需每個 API 版本中已變更屬性的清單,請參閱 變更記錄檔。

使用範例

Bicep 範例

部署託管 Kubernetes 叢集(亦稱為 AKS / Azure Kubernetes Service)的基本範例。

param resourceName string = 'acctest0001'
param location string = 'westeurope'

resource managedCluster 'Microsoft.ContainerService/managedClusters@2023-04-02-preview' = {
  name: resourceName
  location: location
  properties: {
    agentPoolProfiles: [
      {
        count: 1
        mode: 'System'
        name: 'default'
        vmSize: 'Standard_DS2_v2'
      }
    ]
    dnsPrefix: resourceName
  }
}

Azure 已驗證的模組

以下的 Azure 已驗證模組 可用於部署此資源類型。

Module Description
Azure Kubernetes Service (AKS) 管理叢集 AVM Resource Module for Azure Kubernetes Service (AKS) Managed Cluster

Azure 快速入門範例

以下的 Azure 快速啟動範本 包含用於部署此資源類型的 Bicep 範例。

Bicep 檔 Description
AKS 叢集,包含 NAT 閘道和 Application Gateway 本範例展示了如何部署一個 AKS 叢集,NAT 閘道用於出站連線,使用 Application Gateway 進行入站連線。
AKS 叢集搭配 Application Gateway 入口控制器 本範例展示了如何部署包含 Application Gateway、Application Gateway Ingress Controller、Azure Container Registry、Log Analytics 及 金鑰保存庫 的 AKS 叢集
Azure 貨櫃服務(AKS) Deploy a managed cluster with Azure Container Service (AKS) using Azure Linux container hosts
Azure 貨櫃服務(AKS) Deploy a managed cluster with Azure Container Service (AKS)
Azure 貨櫃服務(AKS)配備 Helm Deploy a managed cluster with Azure Container Service (AKS) with Helm
Azure Kubernetes Service (AKS) Deploying a managed cluster with Azure Kubernetes Service (AKS) using Azure Linux with OS Guard
Azure Kubernetes Service (AKS) Deploys a managed Kubernetes cluster through Azure Kubernetes Service (AKS)
Azure Machine Learning端對端安全設置 這組 Bicep 範本示範如何在安全環境中端對端設定 Azure Machine Learning。 此參考實作包括工作區、計算叢集、計算實例和附加的私人 AKS 叢集。
Azure Machine Learning端對端安全設定(舊有) 這組 Bicep 範本示範如何在安全環境中端對端設定 Azure Machine Learning。 此參考實作包括工作區、計算叢集、計算實例和附加的私人 AKS 叢集。
建立私人 AKS 叢集 此範例展示了如何在virtual network中建立私有的 AKS 叢集,並搭配跳板虛擬機。
用 Prometheus 和 Grafana 用 privae 連結 這將建立 Azure grafana、AKS,並在 Azure Kubernetes Service(AKS)叢集上安裝 Prometheus,一個開源的監控與警示工具包。 接著你使用 Azure 受控 Grafana 的受控私人端點連接到這個 Prometheus 伺服器,並在 Grafana 儀表板中顯示 Prometheus 資料

資源格式

若要建立 Microsoft.ContainerService/managedClusters 資源,請將下列 Bicep 新增至範本。

resource symbolicname 'Microsoft.ContainerService/managedClusters@2026-06-02-preview' = {
  extendedLocation: {
    name: 'string'
    type: 'string'
  }
  identity: {
    delegatedResources: {
      {customized property}: {
        location: 'string'
        referralResource: 'string'
        resourceId: 'string'
        tenantId: 'string'
      }
    }
    type: 'string'
    userAssignedIdentities: {
      {customized property}: {}
    }
  }
  kind: 'string'
  location: 'string'
  name: 'string'
  properties: {
    aadProfile: {
      adminGroupObjectIDs: [
        'string'
      ]
      clientAppID: 'string'
      enableAzureRBAC: bool
      managed: bool
      serverAppID: 'string'
      serverAppSecret: 'string'
      tenantID: 'string'
    }
    addonProfiles: {
      {customized property}: {
        config: {
          {customized property}: 'string'
        }
        enabled: bool
      }
    }
    agentPoolProfiles: [
      {
        artifactStreamingProfile: {
          enabled: bool
        }
        availabilityZones: [
          'string'
        ]
        capacityReservationGroupID: 'string'
        count: int
        creationData: {
          sourceResourceId: 'string'
        }
        enableAutoScaling: bool
        enableEncryptionAtHost: bool
        enableFIPS: bool
        enableNodePublicIP: bool
        enableOSDiskFullCaching: bool
        enableUltraSSD: bool
        gatewayProfile: {
          publicIPPrefixSize: int
        }
        gpuInstanceProfile: 'string'
        gpuProfile: {
          driver: 'string'
          driverType: 'string'
          nvidia: {
            driverMode: 'string'
            managementMode: 'string'
            migStrategy: 'string'
          }
        }
        hostGroupID: 'string'
        kubeletConfig: {
          allowedUnsafeSysctls: [
            'string'
          ]
          containerLogMaxFiles: int
          containerLogMaxSizeMB: int
          cpuCfsQuota: bool
          cpuCfsQuotaPeriod: 'string'
          cpuManagerPolicy: 'string'
          evictionMaxPodGracePeriodInSeconds: int
          failSwapOn: bool
          hardEvictionThreshold: {
            memoryAvailable: 'string'
            nodeFsAvailable: 'string'
            nodeFsInodesFree: 'string'
          }
          imageGcHighThreshold: int
          imageGcLowThreshold: int
          kubeReserved: {
            cpuMillicores: int
            memoryMB: int
          }
          podMaxPids: int
          seccompDefault: 'string'
          softEvictionGracePeriod: {
            memoryAvailable: 'string'
            nodeFsAvailable: 'string'
            nodeFsInodesFree: 'string'
          }
          softEvictionThreshold: {
            memoryAvailable: 'string'
            nodeFsAvailable: 'string'
            nodeFsInodesFree: 'string'
          }
          topologyManagerPolicy: 'string'
        }
        kubeletDiskType: 'string'
        linuxOSConfig: {
          swapFileSizeMB: int
          sysctls: {
            fsAioMaxNr: int
            fsFileMax: int
            fsInotifyMaxUserWatches: int
            fsNrOpen: int
            kernelThreadsMax: int
            netCoreNetdevMaxBacklog: int
            netCoreOptmemMax: int
            netCoreRmemDefault: int
            netCoreRmemMax: int
            netCoreSomaxconn: int
            netCoreWmemDefault: int
            netCoreWmemMax: int
            netIpv4IpLocalPortRange: 'string'
            netIpv4NeighDefaultGcThresh1: int
            netIpv4NeighDefaultGcThresh2: int
            netIpv4NeighDefaultGcThresh3: int
            netIpv4TcpFinTimeout: int
            netIpv4TcpkeepaliveIntvl: int
            netIpv4TcpKeepaliveProbes: int
            netIpv4TcpKeepaliveTime: int
            netIpv4TcpMaxSynBacklog: int
            netIpv4TcpMaxTwBuckets: int
            netIpv4TcpTwReuse: bool
            netNetfilterNfConntrackBuckets: int
            netNetfilterNfConntrackMax: int
            vmMaxMapCount: int
            vmSwappiness: int
            vmVfsCachePressure: int
          }
          transparentHugePageDefrag: 'string'
          transparentHugePageEnabled: 'string'
        }
        localDNSProfile: {
          kubeDNSOverrides: {
            {customized property}: {
              cacheDurationInSeconds: int
              forwardDestination: 'string'
              forwardPolicy: 'string'
              maxConcurrent: int
              protocol: 'string'
              queryLogging: 'string'
              serveStale: 'string'
              serveStaleDurationInSeconds: int
            }
          }
          mode: 'string'
          vnetDNSOverrides: {
            {customized property}: {
              cacheDurationInSeconds: int
              forwardDestination: 'string'
              forwardPolicy: 'string'
              maxConcurrent: int
              protocol: 'string'
              queryLogging: 'string'
              serveStale: 'string'
              serveStaleDurationInSeconds: int
            }
          }
        }
        maxCount: int
        maxPods: int
        messageOfTheDay: 'string'
        minCount: int
        mode: 'string'
        name: 'string'
        networkProfile: {
          allowedHostPorts: [
            {
              portEnd: int
              portStart: int
              protocol: 'string'
            }
          ]
          applicationSecurityGroups: [
            'string'
          ]
          dranet: {
            mode: 'string'
          }
          nodePublicIPPrefixIDs: [
            'string'
          ]
          nodePublicIPTags: [
            {
              ipTagType: 'string'
              tag: 'string'
            }
          ]
          secondaryNetworkInterfaces: [
            {
              enableAcceleratedNetworking: bool
              publicIPAddressConfiguration: {
                ipTags: [
                  {
                    ipTagType: 'string'
                    tag: 'string'
                  }
                ]
                publicIPAddressVersion: 'string'
                publicIPPrefixID: 'string'
              }
              type: 'string'
              vnetSubnetId: 'string'
            }
          ]
        }
        nodeImageVersion: 'string'
        nodeInitializationTaints: [
          'string'
        ]
        nodeLabels: {
          {customized property}: 'string'
        }
        nodePublicIPPrefixID: 'string'
        nodeTaints: [
          'string'
        ]
        orchestratorVersion: 'string'
        osDiskSizeGB: int
        osDiskType: 'string'
        osSKU: 'string'
        osType: 'string'
        podIPAllocationMode: 'string'
        podSubnetID: 'string'
        powerState: {
          code: 'string'
        }
        preparedImageSpecificationProfile: {
          preparedImageSpecificationId: 'string'
        }
        proximityPlacementGroupID: 'string'
        scaleDownMode: 'string'
        scaleSetEvictionPolicy: 'string'
        scaleSetPriority: 'string'
        securityProfile: {
          enableSecureBoot: bool
          enableVTPM: bool
          sshAccess: 'string'
        }
        spotMaxPrice: int
        status: {}
        tags: {
          {customized property}: 'string'
        }
        type: 'string'
        upgradeSettings: {
          drainTimeoutInMinutes: int
          maxBlockedNodes: 'string'
          maxSurge: 'string'
          maxUnavailable: 'string'
          nodeSoakDurationInMinutes: int
          undrainableNodeBehavior: 'string'
        }
        upgradeSettingsBlueGreen: {
          batchSoakDurationInMinutes: int
          drainBatchSize: 'string'
          drainTimeoutInMinutes: int
          finalSoakDurationInMinutes: int
        }
        upgradeStrategy: 'string'
        virtualMachineNodesStatus: [
          {
            count: int
            size: 'string'
          }
        ]
        virtualMachinesProfile: {
          scale: {
            autoscale: [
              {
                maxCount: int
                minCount: int
                size: 'string'
              }
            ]
            manual: [
              {
                count: int
                size: 'string'
              }
            ]
          }
        }
        vmSize: 'string'
        vnetSubnetID: 'string'
        windowsProfile: {
          disableOutboundNat: bool
        }
        workloadRuntime: 'string'
      }
    ]
    aiToolchainOperatorProfile: {
      enabled: bool
    }
    apiServerAccessProfile: {
      authorizedIPRanges: [
        'string'
      ]
      disableRunCommand: bool
      enablePrivateCluster: bool
      enablePrivateClusterPublicFQDN: bool
      enableVnetIntegration: bool
      privateDNSZone: 'string'
      subnetId: 'string'
    }
    autoScalerProfile: {
      balance-similar-node-groups: 'string'
      daemonset-eviction-for-empty-nodes: bool
      daemonset-eviction-for-occupied-nodes: bool
      expander: 'string'
      ignore-daemonsets-utilization: bool
      max-empty-bulk-delete: 'string'
      max-graceful-termination-sec: 'string'
      max-node-provision-time: 'string'
      max-total-unready-percentage: 'string'
      new-pod-scale-up-delay: 'string'
      ok-total-unready-count: 'string'
      scale-down-delay-after-add: 'string'
      scale-down-delay-after-delete: 'string'
      scale-down-delay-after-failure: 'string'
      scale-down-unneeded-time: 'string'
      scale-down-unready-time: 'string'
      scale-down-utilization-threshold: 'string'
      scan-interval: 'string'
      skip-nodes-with-local-storage: 'string'
      skip-nodes-with-system-pods: 'string'
    }
    autoUpgradeProfile: {
      nodeOSUpgradeChannel: 'string'
      upgradeChannel: 'string'
    }
    azureMonitorProfile: {
      appMonitoring: {
        autoInstrumentation: {
          enabled: bool
        }
        openTelemetryLogsAndTraces: {
          enabled: bool
          grpcPort: int
          httpPort: int
        }
        openTelemetryMetrics: {
          enabled: bool
          grpcPort: int
          httpPort: int
        }
      }
      containerInsights: {
        containerNetworkLogs: 'string'
        disablePrometheusMetricsScraping: bool
        enabled: bool
        logAnalyticsWorkspaceResourceId: 'string'
        syslogPort: int
      }
      metrics: {
        controlPlane: {
          enabled: bool
        }
        enabled: bool
        kubeStateMetrics: {
          metricAnnotationsAllowList: 'string'
          metricLabelsAllowlist: 'string'
        }
      }
    }
    bootstrapProfile: {
      artifactSource: 'string'
      containerRegistryId: 'string'
    }
    controlPlaneScalingProfile: {
      scalingSize: 'string'
    }
    creationData: {
      sourceResourceId: 'string'
    }
    disableLocalAccounts: bool
    diskEncryptionSetID: 'string'
    dnsPrefix: 'string'
    enableFIPS: bool
    enableNamespaceResources: bool
    enableNodeHardening: bool
    enableRBAC: bool
    fqdnSubdomain: 'string'
    healthMonitorProfile: {
      enableContinuousControlPlaneAndAddonMonitor: bool
      enableOnDemandMonitor: bool
    }
    hostedSystemProfile: {
      enabled: bool
      nodeSubnetID: 'string'
      systemNodeSubnetID: 'string'
    }
    httpProxyConfig: {
      enabled: bool
      httpProxy: 'string'
      httpsProxy: 'string'
      noProxy: [
        'string'
      ]
      trustedCa: 'string'
    }
    identityProfile: {
      {customized property}: {
        clientId: 'string'
        objectId: 'string'
        resourceId: 'string'
      }
    }
    ingressProfile: {
      applicationLoadBalancer: {
        enabled: bool
      }
      gatewayAPI: {
        installation: 'string'
      }
      webAppRouting: {
        defaultDomain: {
          enabled: bool
        }
        dnsZoneResourceIds: [
          'string'
        ]
        enabled: bool
        gatewayAPIImplementations: {
          appRoutingIstio: {
            mode: 'string'
          }
        }
        nginx: {
          defaultIngressControllerType: 'string'
        }
      }
    }
    kubernetesVersion: 'string'
    linuxProfile: {
      adminUsername: 'string'
      ssh: {
        publicKeys: [
          {
            keyData: 'string'
          }
        ]
      }
    }
    metricsProfile: {
      costAnalysis: {
        enabled: bool
      }
    }
    networkProfile: {
      advancedNetworking: {
        enabled: bool
        observability: {
          enabled: bool
        }
        performance: {
          accelerationMode: 'string'
        }
        security: {
          advancedNetworkPolicies: 'string'
          enabled: bool
          transitEncryption: {
            type: 'string'
          }
        }
      }
      bastionProfile: {
        enabled: bool
        publicIpAddressId: 'string'
        scaleUnits: int
        sku: 'string'
      }
      dnsServiceIP: 'string'
      ipFamilies: [
        'string'
      ]
      kubeProxyConfig: {
        enabled: bool
        ipvsConfig: {
          scheduler: 'string'
          tcpFinTimeoutSeconds: int
          tcpTimeoutSeconds: int
          udpTimeoutSeconds: int
        }
        mode: 'string'
      }
      loadBalancerProfile: {
        allocatedOutboundPorts: int
        backendPoolType: 'string'
        clusterServiceLoadBalancerHealthProbeMode: 'string'
        enableMultipleStandardLoadBalancers: bool
        idleTimeoutInMinutes: int
        managedOutboundIPs: {
          count: int
          countIPv6: int
        }
        outboundIPPrefixes: {
          publicIPPrefixes: [
            {
              id: 'string'
            }
          ]
        }
        outboundIPs: {
          publicIPs: [
            {
              id: 'string'
            }
          ]
        }
      }
      loadBalancerSku: 'string'
      natGatewayId: 'string'
      natGatewayProfile: {
        idleTimeoutInMinutes: int
        managedOutboundIPProfile: {
          count: int
          countIPv6: int
        }
        outboundIPPrefixes: {
          publicIPPrefixes: [
            'string'
          ]
        }
        outboundIPs: {
          publicIPs: [
            'string'
          ]
        }
        sku: 'string'
      }
      networkDataplane: 'string'
      networkMode: 'string'
      networkPlugin: 'string'
      networkPluginMode: 'string'
      networkPolicy: 'string'
      outboundType: 'string'
      podCidr: 'string'
      podCidrs: [
        'string'
      ]
      podLinkLocalAccess: 'string'
      serviceCidr: 'string'
      serviceCidrs: [
        'string'
      ]
      staticEgressGatewayProfile: {
        enabled: bool
      }
    }
    nodeDisruptionProfile: {
      nodeDisruptionPolicy: 'string'
    }
    nodeProvisioningProfile: {
      defaultNodePools: 'string'
      mode: 'string'
    }
    nodeResourceGroup: 'string'
    nodeResourceGroupProfile: {
      restrictionLevel: 'string'
    }
    oidcIssuerProfile: {
      enabled: bool
    }
    podIdentityProfile: {
      allowNetworkPluginKubenet: bool
      enabled: bool
      userAssignedIdentities: [
        {
          bindingSelector: 'string'
          identity: {
            clientId: 'string'
            objectId: 'string'
            resourceId: 'string'
          }
          name: 'string'
          namespace: 'string'
        }
      ]
      userAssignedIdentityExceptions: [
        {
          name: 'string'
          namespace: 'string'
          podLabels: {
            {customized property}: 'string'
          }
        }
      ]
    }
    privateLinkResources: [
      {
        groupId: 'string'
        id: 'string'
        name: 'string'
        requiredMembers: [
          'string'
        ]
        type: 'string'
      }
    ]
    publicNetworkAccess: 'string'
    schedulerProfile: {
      upstream: {
        schedulerConfigMode: 'string'
      }
    }
    securityProfile: {
      azureKeyVaultKms: {
        enabled: bool
        keyId: 'string'
        keyVaultNetworkAccess: 'string'
        keyVaultResourceId: 'string'
      }
      customCATrustCertificates: [
        any(...)
      ]
      defender: {
        logAnalyticsWorkspaceResourceId: 'string'
        securityGating: {
          allowSecretAccess: bool
          enabled: bool
          identities: [
            {
              azureContainerRegistry: 'string'
              identity: {
                clientId: 'string'
                objectId: 'string'
                resourceId: 'string'
              }
            }
          ]
        }
        securityMonitoring: {
          enabled: bool
        }
      }
      imageCleaner: {
        enabled: bool
        intervalHours: int
      }
      imageIntegrity: {
        enabled: bool
      }
      kubernetesResourceObjectEncryptionProfile: {
        infrastructureEncryption: 'string'
      }
      nodeRestriction: {
        enabled: bool
      }
      serviceAccountImagePullProfile: {
        defaultManagedIdentityId: 'string'
        enabled: bool
      }
      workloadIdentity: {
        enabled: bool
      }
    }
    serviceMeshProfile: {
      istio: {
        certificateAuthority: {
          plugin: {
            certChainObjectName: 'string'
            certObjectName: 'string'
            keyObjectName: 'string'
            keyVaultId: 'string'
            rootCertObjectName: 'string'
          }
        }
        components: {
          egressGateways: [
            {
              enabled: bool
              gatewayConfigurationName: 'string'
              name: 'string'
              namespace: 'string'
            }
          ]
          ingressGateways: [
            {
              enabled: bool
              mode: 'string'
            }
          ]
          proxyRedirectionMechanism: 'string'
        }
        revisions: [
          'string'
        ]
      }
      mode: 'string'
    }
    servicePrincipalProfile: {
      clientId: 'string'
      secret: 'string'
    }
    status: {}
    storageProfile: {
      blobCSIDriver: {
        enabled: bool
      }
      diskCSIDriver: {
        enabled: bool
      }
      fileCSIDriver: {
        enabled: bool
      }
      snapshotController: {
        enabled: bool
      }
    }
    supportPlan: 'string'
    upgradeSettings: {
      overrideSettings: {
        forceUpgrade: bool
        until: 'string'
      }
    }
    windowsProfile: {
      adminPassword: 'string'
      adminUsername: 'string'
      enableCSIProxy: bool
      gmsaProfile: {
        dnsServer: 'string'
        enabled: bool
        rootDomainName: 'string'
      }
      licenseType: 'string'
    }
    workloadAutoScalerProfile: {
      keda: {
        enabled: bool
      }
      verticalPodAutoscaler: {
        addonAutoscaling: 'string'
        enabled: bool
      }
    }
  }
  sku: {
    name: 'string'
    tier: 'string'
  }
  tags: {
    {customized property}: 'string'
  }
}

屬性值

Microsoft.ContainerService/managedClusters

Name Description Value
extendedLocation 虛擬機的擴充位置。 ExtendedLocation
身分識別 如果已設定,則為受控叢集的身分識別。 ManagedClusterIdentity
kind 這主要用來在入口網站中針對不同類型公開不同的UI體驗 字串
位置 資源所在的地理位置 字串 (必要)
name 資源名稱 string

Constraints:
最小長度 = 1
最大長度 = 63
模式 = ^[a-zA-Z0-9]$|^[a-zA-Z0-9][-_a-zA-Z0-9]{0,61}[a-zA-Z0-9]$ (必要)
properties 受控叢集的屬性。 ManagedClusterProperties
sku 受控叢集 SKU。 ManagedClusterSKU
tags 資源標籤 標記名稱和值的字典。 請參考模板中的標籤

AdvancedNetworking

Name Description Value
enabled 表示啟用 AKS 叢集上可檢視性和安全性的進階網路功能。 當此設定為 true 時,除非明確停用,否則所有可檢視性和安全性功能都會設定為啟用。 如果未指定,則預設值為 false。 bool
可檢視性 可檢視性配置檔,可啟用具有歷程記錄內容的進階網路計量和流量記錄。 AdvancedNetworkingObservability
效能 設定檔可啟用使用 Azure CNI 由 Cilium 驅動的叢集的效能提升功能。 進階網路效能
安全性 安全性配置檔,以在 cilium 型叢集上啟用安全性功能。 AdvancedNetworkingSecurity

AdvancedNetworkingObservability

Name Description Value
enabled 表示在叢集上啟用進階網路可檢視性功能。 bool

進階網路效能

Name Description Value
加速模式 啟用進階網路加速選項。 這允許用戶使用 BPF 主機路由配置加速。 這只能透過 Cilium 資料平面啟用。 如果未指定,預設值為 None (無加速)。 加速模式可以在預先存在的叢集上變更。 詳細說明見https://aka.ms/acnsperformance “BpfVeth”
'None'

AdvancedNetworkingSecurity

Name Description Value
advancedNetworkPolicies 啟用高級網路策略。 這可讓用戶設定第 7 層網路原則(FQDN、HTTP、Kafka)。 原則本身必須透過 Cilium 網路原則資源進行設定,請參閱 https://docs.cilium.io/en/latest/security/policy/index.html。 這隻能在 cilium 型叢集上啟用。 如果未指定,如果 security.enabled 設定為 true,則預設值為 FQDN。 'FQDN'
'L7'
'None'
enabled 此功能可讓使用者根據 DNS (FQDN) 名稱來設定網路原則。 它只能在 cilium 型叢集上啟用。 如果未指定,則預設值為 false。 bool
transitEncryption 基於 Cilium 的集群的加密配置。 啟用后,Cilium 託管的 Pod 之間的所有流量在離開節點邊界時都將被加密。 AdvancedNetworkingSecurityTransitEncryption

AdvancedNetworkingSecurityTransitEncryption

Name Description Value
型別 配置 Pod 到 Pod 加密。 這隻能在 Cilium 型叢集上啟用。 如果未指定,預設值為 None。 「mTLS」
'None'
'WireGuard'

AgentPoolArtifactStreamingProfile

Name Description Value
enabled 成品串流可透過隨選映射載入,加速節點上容器的冷啟動。 若要使用這項功能,容器映像也必須在 ACR 上啟用成品串流。 如果未指定,則預設值為 false。 bool

AgentPoolBlueGreenUpgradeSettings

Name Description Value
batchSoakDurationInMinutes 清空一批節點後的浸泡持續時間,即清空一批節點後等待的時間量(以分鐘為單位),然後再繼續下一個批次。 如果未指定,則預設值為 15 分鐘。 int

Constraints:
最小值 = 0
最大值 = 1440
drainBatch大小 藍綠升級期間要批次清空的節點數目或百分比。 必須是非零數字。 這可以設定為整數(例如 '5')或百分比(例如 '50%')。 如果指定百分比,則它是起始升級作業的藍色節點總數百分比。 針對百分比,小數節點會四捨五入。 如果未指定,則預設值為 10%。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
drainTimeoutInMinutes 節點的清空逾時,即等待 Pod 收回和每個節點正常終止的時間量 (以分鐘為單位)。 此收回等候時間會接受等候 Pod 中斷預算。 如果超過這個時間,升級就會失敗。 如果未指定,則預設值為 30 分鐘。 int

Constraints:
最小值 = 1
最大值 = 1440
finalSoak持續時間在分鐘 節點集區的浸泡持續時間,即在移除舊節點之前,所有舊節點清空後等待的時間量 (以分鐘為單位)。 如果未指定,則預設值為 60 分鐘。 僅適用於藍綠升級策略。 int

Constraints:
最小值 = 0
最大值 = 10080

AgentPoolGatewayProfile

Name Description Value
publicIPPrefixSize 網關代理程式集區會為每個靜態輸出閘道建立一個公用IPPrefix的關聯,以提供公用輸出。 用戶應該選取公用IPPrefix的大小。 代理程式集區中的每個節點都會從IPPrefix指派一個IP。 因此,IPPrefix 大小會做為閘道代理程式集區大小的上限。 由於 Azure 公開 IPPrefix 大小限制,有效值範圍為 [28, 31](/31 = 2 節點/IP,/30 = 4 節點/IP,/29 = 8 節點/IP,/28 = 16 節點/IP)。 預設值為 31。 int

Constraints:
最小值 = 28
最大值 = 31

代理池網路介面

Name Description Value
enableAcceleratedNetworking 這個次要網卡是否啟用了加速網路。 若省略,則僅在代理池虛擬機 SKU 支援加速網路時,此設定才會自動為 true。 若驗證在不支援的 SKU 或 NIC 配置上啟用,則驗證將失敗。 bool
publicIPAddress配置 這個次要網卡的公共 IP 設定。 只有當 type 是 時 Standard才有效。 設定 publicIPAddressVersion 為為每個虛擬機的實例層級公共 IP 配置 NIC,然後可選擇性地以 ipTags 或 publicIPPrefixID來塑造。 若省略,則不會設定公共 IP。 閒置逾時是無法設定的。 如需詳細資訊,請參閱 https://aka.ms/aks/multi-nic AgentPoolNICPublicIPAddressConfiguration
型別 虛擬機上要配置的網卡類型。 “動態”
'Standard'
vnetSubnetId 將連接至次級網路介面的子網資源 ID。 當 type 是 Standard時 必須;必須是空字串(),""或當 是 type時省略。Dynamic 字串

AgentPoolNetworkProfile

Name Description Value
allowedHostPorts 允許 access 的埠範圍。 允許指定的範圍重疊。 PortRange[]
applicationSecurityGroups 應用程式安全組的標識碼,代理程式集區會在建立時產生關聯。 string[]
德拉內特 DRANET 代理池的設定。 DranetProfile
nodePublicIPPrefixIDs 節點公共 IP 前綴的資源 ID。 最多只能指定一個 IPv4 和一個 IPv6 前綴。 順序不重要;RP 則從參考資源的 publicIPAddressVersion 決定 IP 版本。 需要 enableNodePublicIP 在代理池上為真。 與頂層 nodePublicIPPrefixID 屬性互斥。 節點池建立後不可變。 要更改前綴,請刪除並重新建立節點池。 如需詳細資訊,請參閱 https://aka.ms/aks/ipv6-ilpip string[]
nodePublicIPTags 實例層級公用IP的IPTag。 IPTag[]
次要網路介面 代理池中每個虛擬機的次級網路介面設定。 每個條目都是一個範本:每個條目會在每個虛擬實例上配置一個實體網卡。 這些介面是在代理池建立時建立,且是不可變的。 清單長度必須小於網卡容量減去代理池虛擬機大小的 1(AKS 管理主要網卡)。 例如,Standard_D8a_v4虛擬機最多支援 4 個網卡,因此最多允許的次要介面數為 3 個。 對於混合 SKU VM 池,有效容量為所有 SKU 的最小值:count(次要網路介面)+ 1 <= min(maxNIC)。 如需詳細資訊,請參閱 https://aka.ms/aks/multi-nic 代理池網路介面[]

AgentPoolNICPublicIPAddressConfiguration

Name Description Value
ip標籤 IP 標籤要附加到該 NIC 分配的公共 IP。 每個標籤 ipTagType 必須是 FirstPartyUsage、 NetworkDomain或 RoutingPreference。 與 publicIPPrefixID互斥。 IPTag[]
publicIPAddress版本 為此網卡配置的公共 IP 版本。 必要條件:其存在是啟用公共 IP 配置的關鍵,因此空設定不會分配任何資料。 IPv4 是唯一被接受的值。 「IPv4」(必填)
publicIPPrefixID 公共 IP 前綴的資源 ID,用來擷取該網卡的公共 IP。 與 ipTags互斥。 字串

AgentPoolSecurityProfile

Name Description Value
enableSecureBoot 安全開機是受信任的啟動功能,可確保只有已簽署的作系統和驅動程式才能開機。 如需詳細資訊,請參閱 aka.ms/aks/trustedlaunch。 如果未指定,則預設值為 false。 bool
enableVTPM vTPM 是受信任的啟動功能,用於設定節點上本機所保留密鑰和度量的專用安全保存庫。 如需詳細資訊,請參閱 aka.ms/aks/trustedlaunch。 如果未指定,則預設值為 false。 bool
sshAccess 代理池的 SSH access 方法。 'Disabled'
“EntraId”
'LocalUser'

AgentPoolStatus

Name Description Value

AgentPoolUpgradeSettings

Name Description Value
drainTimeoutInMinutes 節點的耗盡超時。 等待收回 Pod 的時間量,以及每個節點的正常終止時間。 此收回等候時間會接受等候 Pod 中斷預算。 如果超過這個時間,升級就會失敗。 如果未指定,則預設值為 30 分鐘。 int

Constraints:
最小值 = 1
最大值 = 1440
maxBlockedNodes 當無法解析的節點行為為 Cordon 時,在代理程式集區中允許封鎖的額外節點數目或百分比上限。 這可以設定為整數(例如 '5')或百分比(例如 '50%')。 如果指定了百分比,則它是升級時代理程式集區大小總計的百分比。 針對百分比,小數節點會四捨五入。 如果未指定,預設值為 maxSurge。 這一律必須大於或等於 maxSurge。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
maxSurge 升級期間激增的節點數目或百分比上限。 這可以設定為整數(例如 '5')或百分比(例如 '50%')。 如果指定了百分比,則它是升級時代理程式集區大小總計的百分比。 針對百分比,小數節點會四捨五入。 如果未指定,則預設值為 10%。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
maxUnavailable 升級期間可以同時無法使用的節點數目或百分比上限。 這可以設定為整數(例如 '1')或百分比(例如 '5%')。 如果指定了百分比,則它是升級時代理程式集區大小總計的百分比。 針對百分比,小數節點會四捨五入。 如果未指定,則預設值為 0。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
nodeSoakDurationInMinutes 節點的soak持續時間。 清空節點並重新製作映射並移至下一個節點之前,等待的時間量(以分鐘為單位)。 如果未指定,則預設值為0分鐘。 int

Constraints:
最小值 = 0
最大值 = 30
undrainableNodeBehavior 定義升級期間無法透支節點的行為。 無法透支節點最常見的原因是 Pod 中斷預算 (PDB),但其他問題,例如 Pod 終止寬限期超過剩餘的個別節點清空逾時,或 Pod 仍在執行中狀態,也可能導致無法執行的節點。 'Cordon'
'Schedule'

AgentPoolWindowsProfile

Name Description Value
disableOutboundNat 是否在 Windows 節點中禁用 OutboundNAT。 預設值為 false。 只有在叢集 outboundType 是 NAT 閘道,且 Windows 代理程式集區未啟用節點公用 IP 時,才能停用輸出 NAT。 bool

AutoScaleProfile

Name Description Value
maxCount 指定大小的節點數目上限。 int
minCount 指定大小的節點數目下限。 int
size AKS 在建立和調整時將使用的 VM 大小,例如 'Standard_E4s_v3'、'Standard_E16s_v3' 或 'Standard_D16s_v5'。 字串

AzureKeyVaultKms

Name Description Value
enabled 是否啟用 Azure Key Vault 鍵管理服務。 默認值為 false。 bool
keyId Azure Key Vault key 的識別碼。 詳情請參見 key identifier format。 啟用 Azure Key Vault 金鑰管理服務時,此欄位為必填且必須為有效的金鑰識別碼。 當 Azure Key Vault 的金鑰管理服務被停用時,請保持欄位空。 字串
keyVaultNetworkAccess key vault的access網絡。 key vault的網絡access。 可能的值為 Public 和 Private。 Public 表示key vault允許所有網路的公開access。 Private 表示key vault會停用公共access並啟用private link。 預設值為 Public。 'Private'
'Public'
keyVaultResourceId key vault 的資源 ID。 當keyVaultNetworkAccess為 Private時,此字段是必要的,而且必須是有效的資源標識符。 當keyVaultNetworkAccess為 Public時,請將字段保留空白。 字串

堡壘簡介

Name Description Value
enabled 顯示是否啟用管理堡壘。 bool
公共 IpAddressId 與管理堡壘相關的公共 IP 位址的資源 ID。

在建立時提供時,管理堡壘會參考這個現有的公共 IP 位址,而不是建立新的。
所參考的公共 IP 位址必須與受管理叢集在同一訂閱和區域內。

若建立時未提供,AKS 會自動建立新的公開 IP 位址。

此欄位無法更新。 若要在建立後更改 IP 位址,請停用並重新啟用管理的堡壘,並使用新的公共 IP 位址。
字串
scaleUnits 管理堡壘的比例單位。 預設值為 2。 int

Constraints:
最小值 = 2
最大值 = 50
sku 管理堡壘的SKU。

僅支援標準版和高級版 SKU。
SKU 不允許降級。 要降級 SKU,請先停用再重新啟用管理堡壘並使用新的 SKU。

如需詳細資訊,請參閱 https://aka.ms/aks/BastionSKUs。
'Premium'
'Standard'

ClusterUpgradeSettings

Name Description Value
overrideSettings 覆寫的設定。 UpgradeOverrideSettings

ContainerServiceLinuxProfile

Name Description Value
adminUsername 要用於 Linux VM 的系統管理員用戶名稱。 string

Constraints:
模式 = ^[A-Za-z][-A-Za-z0-9_]*$ (必要)
ssh 這是針對在 Azure 上運行的 Linux 虛擬機的 SSH 配置。 ContainerServiceSshConfiguration (必需)

ContainerServiceNetworkProfile

Name Description Value
advancedNetworking 在叢集上啟用可檢視性和安全性功能套件的進階網路配置檔。 如需詳細資訊,請參閱 aka.ms/aksadvancednetworking。 AdvancedNetworking
堡壘簡介 與管理叢集相關的堡壘主機側寫。
如需詳細資訊,請參閱 https://aka.ms/aks/BastionConnect。
堡壘簡介
dnsServiceIP 指派給 Kubernetes DNS 服務的 IP 位址。 它必須位於 serviceCidr 中指定的 Kubernetes 服務地址範圍內。 string

Constraints:
圖案 = ^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$
ipFamilies 用來指定叢集可用IP版本的IP系列。 IP 系列可用來判斷單一堆疊或雙堆棧叢集。 對於單一堆棧,預期的值為IPv4。 針對雙堆棧,預期的值為IPv4和IPv6。 包含任何的字串數組:
'IPv4'
'IPv6'
kubeProxyConfig 保留 kube-proxy 的組態自定義。 未定義的任何值都會使用 kube-proxy 預設行為。 請參閱 https://v<version.docs.kubernetes.io/docs/reference/command-line-tools-reference/kube-proxy/ 版本,其中>版本<是以>主要版本<>次要版本<字串>表示。 Kubernetes 1.23 版會是 '1-23'。 ContainerServiceNetworkProfileKubeProxyConfig
loadBalancerProfile 叢集 load balancer 的設定檔。 ManagedClusterLoadBalancerProfile
loadBalancerSku 管理叢集的 load balancer sku。 默認值為 『standard』。 欲了解load balancer SKU 差異,請參見 Azure Load Balancer SKUs。 'basic'
「服務」
'standard'
natGatewayId 當 outboundType 為 'userAssignedNATGateway'(使用 StandardV2 公有 IP)時,NAT 閘道器用於叢集啟動時的Azure資源 ID,後端池類型為 podIP,負載平衡器類型為服務 SKU。 這個形式為:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/natGateways/{natGatewayName}'. 使用受管理的 NATGateway 時,這個欄位會自動填入。 如需詳細資訊,請參閱 https://aka.ms/aks/container-native-slb 字串
natGatewayProfile 叢集 NAT 閘道的配置檔。 ManagedClusterNATGatewayProfile
networkDataplane Kubernetes 叢集中所使用的網路數據平面。 「azure」
'cilium'
networkMode Azure CNI 所設定的網路模式。 如果 networkPlugin 不是 'azure',則無法指定這個功能。 'bridge'
'transparent'
networkPlugin 用於建置 Kubernetes 網路的網路外掛程式。 「azure」
'kubenet'
'none'
networkPluginMode 網路外掛程式應該使用的模式。 'overlay'
networkPolicy 用於建置 Kubernetes 網路的網路原則。 「azure」
'calico'
'cilium'
'none'
outboundType 輸出 (輸出) 路由方法。 這隻能在叢集建立期間設定,且稍後無法變更。 更多資訊請參見出口類型。 'loadBalancer'
'managedNATGateway'
'none'
'userAssignedNATGateway'
'userDefinedRouting'
podCidr 使用 kubenet 時,要從中指派 Pod IP 的 CIDR 表示法 IP 範圍。 string

Constraints:
圖案 = ^([0-9]{1,3}\.){3}[0-9]{1,3}(\/([0-9]|[1-2][0-9]|3[0-2]))?$
podCidrs 要從中指派 Pod IP 的 CIDR 表示法IP範圍。 單一堆棧網路應該會有一個 IPv4 CIDR。 兩個 CIDR,每個 IP 系列一個 (IPv4/IPv6),預期雙堆棧網路。 string[]
podLinkLocalAccess 定義 access to special link local addresss (Azure Instance Metadata Service,簡稱 IMDS),適用於 hostNetwork=false 的 pods。 如果未指定,則預設值為 『IMDS』。 'IMDS'
'None'
serviceCidr 要從中指派服務叢集IP的CIDR表示法IP範圍。 它不得與任何子網IP範圍重疊。 string

Constraints:
圖案 = ^([0-9]{1,3}\.){3}[0-9]{1,3}(\/([0-9]|[1-2][0-9]|3[0-2]))?$
serviceCidrs 要從中指派服務叢集IP的CIDR表示法IP範圍。 單一堆棧網路應該會有一個 IPv4 CIDR。 兩個 CIDR,每個 IP 系列一個 (IPv4/IPv6),預期雙堆棧網路。 它們不得與任何子網IP範圍重疊。 string[]
staticEgressGatewayProfile 靜態輸出閘道附加元件配置檔。 如需靜態輸出閘道的詳細資訊,請參閱 https://aka.ms/aks/static-egress-gateway。 ManagedClusterStaticEgressGatewayProfile

ContainerServiceNetworkProfileKubeProxyConfig

Name Description Value
enabled 是否要在叢集上的 kube-proxy 上啟用 (如果沒有 'kubeProxyConfig' 存在,預設會在 AKS 中啟用 kube-proxy,而不需要這些自定義專案)。 bool
ipvsConfig 保留IPVS的組態自定義。 只有在 'mode' 設定為 'IPVS' 時,才能指定。 ContainerServiceNetworkProfileKubeProxyConfigIpvsConfig
mode 指定要使用的 Proxy 模式 ('IPTABLES'、'IPVS' 或 'NFTABLES') 'IPTABLES'
'IPVS'
「NFTABLES」

ContainerServiceNetworkProfileKubeProxyConfigIpvsConfig

Name Description Value
scheduler 如需詳細資訊,請參閱 http://www.linuxvirtualserver.org/docs/scheduling.htmlIPVS排程器。 'LeastConnection'
'RoundRobin'
tcpFinTimeoutSeconds 在收到 FIN 後,用於 IPVS TCP 工作階段的逾時值,以秒為單位。 必須是正整數值。 int
tcpTimeoutSeconds 用於閑置IPVS TCP會話的逾時值,以秒為單位。 必須是正整數值。 int
udpTimeoutSeconds 用於IPVS UDP 封包的逾時值,以秒為單位。 必須是正整數值。 int

ContainerServiceSshConfiguration

Name Description Value
publicKeys 用來向Linux型VM進行驗證的SSH公鑰清單。 最多可以指定1個索引鍵。 ContainerServiceSshPublicKey[](必需)

ContainerServiceSshPublicKey

Name Description Value
keyData 用來透過 SSH 向 VM 進行驗證的憑證公鑰。 憑證必須採用 PEM 格式,且不含標頭。 字串 (必要)

CreationData

Name Description Value
sourceResourceId 這是要用來建立目標物件的來源物件的 ARM 識別碼。 字串

DelegatedResource

Name Description Value
位置 來源資源位置 - 僅供內部使用。 字串
referralResource 轉介委派的委派標識碼 (選擇性) - 僅供內部使用。 字串
resourceId 委派資源的 ARM 資源識別碼 - 僅供內部使用。 字串
tenantId 委派資源的租用戶標識碼 - 僅供內部使用。 string

Constraints:
最小長度 = 36
最大長度 = 36
圖案 = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$

DranetProfile

Name Description Value
mode 特工池的DRANET模式。 'Managed'
'Unmanaged'

ExtendedLocation

Name Description Value
name 擴充位置的名稱。 字串
型別 擴充位置的類型。 'EdgeZone'

GPUProfile

Name Description Value
driver 是否要安裝 GPU 驅動程式。 未指定時,預設值為 [安裝]。 'Install'
'None'
driverType 指定建立 Windows 代理程式集區時要安裝的 GPU 驅動程式類型。 如果未提供,AKS 會根據系統相容性選取驅動程式。 建立 AgentPool 之後,就無法變更此專案。 這無法在Linux AgentPools上設定。 針對Linux AgentPools,會根據系統相容性來選取驅動程式。 'CUDA'
'GRID'
nvidia NVIDIA 專用的 GPU 設定。 NvidiaGPUProfile

硬驅逐門檻

Name Description Value
記憶體可用 可使用記憶體的門檻低於該區域會觸發 pod 驅逐。 接受絕對值(例如「500英里」)或百分比值(例如「5%」)。 絕對值必須大於或等於100英里。 百分比值必須大於或等於2%。 字串
nodeFsAvailable 可用節點檔案系統空間的門檻,低於此範圍觸發 pod 驅逐。 接受絕對值(例如「1Gi」)或百分比值(例如「10%」)。 必須大於或等於系統預設值 10%。 字串
nodeFsInodesFree 節點檔案系統中可用 inode 的閾值,低於此閾值會觸發 pod 驅逐。 接受絕對 inode 計數(例如「100000」)或百分比值(例如「5%」)。 百分比值必須大於或等於系統預設的5%。 字串

IPTag

Name Description Value
ipTagType IP 標籤類型。 範例:RoutingPreference。 字串
加標籤 與公用IP相關聯的IP標籤。 範例:因特網。 字串

IstioCertificateAuthority

Name Description Value
plugin Service Mesh 的外掛程式憑證資訊。 IstioPluginCertificateAuthority

IstioComponents

Name Description Value
egressGateways Istio 輸出閘道。 IstioEgressGateway[]
ingressGateways Istio 輸入閘道。 IstioIngressGateway[]
proxyRedirectionMechanism 流量重新導向的模式。 “CNIChaining”
「初始容器」

IstioEgressGateway

Name Description Value
enabled 是否啟用輸出閘道。 布林 (必要)
gatewayConfigurationName Istio 附加元件輸出閘道的閘道組態自定義資源名稱。 啟用 Istio 輸出閘道時必須指定。 必須部署在 Istio 輸出閘道部署所在的相同命名空間中。 字串
name Istio 附加元件輸出閘道的名稱。 string

Constraints:
模式 = [a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)* (必要)
命名空間 Istio 附加元件輸出閘道應該部署在 的命名空間。 如果未指定,則預設值為 aks-istio-egress。 字串

IstioIngressGateway

Name Description Value
enabled 是否要啟用輸入閘道。 布林 (必要)
mode 輸入閘道的模式。 'External'
“內部”(必填)

IstioPluginCertificateAuthority

Name Description Value
certChainObjectName Azure Key Vault 中的 Certificate chain object name. 字串
certObjectName Azure Key Vault 中的 Intermediate certificate object name. 字串
keyObjectName Azure Key Vault 中的中介憑證私鑰物件名稱。 字串
keyVaultId 金鑰保存庫 的資源 ID。 字串
rootCertObjectName Azure Key Vault 中的根憑證物件名稱。 字串

IstioServiceMesh

Name Description Value
certificateAuthority Istio Service Mesh 證書頒發機構單位 (CA) 組態。 目前,我們僅支援外掛程式憑證,如這裡所述 https://aka.ms/asm-plugin-ca IstioCertificateAuthority
components Istio 元件設定。 IstioComponents
revisions Istio 控制平面的修訂清單。 升級未進行時,這會保留一個值。 當 Canary 升級正在進行時,這隻能保留兩個連續值。 欲了解更多資訊,請參閱:/azure/aks/istio-upgrade string[]

KubeletConfig

Name Description Value
allowedUnsafeSysctls 允許的不安全 sysctls 或 unsafe sysctl 模式清單(結尾為 *)。 string[]
containerLogMaxFiles 容器可存在的容器記錄檔數目上限。 數字必須≥ 2。 int

Constraints:
最小值 = 2
containerLogMaxSizeMB 容器記錄檔的大小上限(例如 10Mi)在輪替之前。 int
cpuCfsQuota 如果針對指定 CPU 限制的容器啟用 CPU CFS 配額強制執行。 默認值為 true。 bool
cpuCfsQuotaPeriod CPU CFS 配額期間值。 默認值為 『100 毫秒』。 有效值是具有選擇性分數和單位後綴的十進位數序列。 例如:『300ms』、『2h45m』。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 字串
cpuManagerPolicy 要使用的 CPU 管理員原則。 預設值為 『none』。 如需詳細資訊 ,請參閱 Kubernetes CPU 管理原則 。 允許的值為 『none』 和 『static』。 字串
驅逐MaxPodGracePeriodInSeconds 軟性驅逐期間,Pods終止的最大寬限期(秒數);限制艙終止寬限期秒數。 預設值為 60,當叢集 enableNodeHardening 的性質為真時會套用。 只適用於 Linux 節點池。 int

Constraints:
最小值 = 0
failSwapOn 如果設定為 true,當節點上啟用交換時,Kubelet 將無法啟動。 bool
硬驅逐閾值 Kubelet 的硬性驅逐門檻。 當未設定閾值時,系統預設值會被使用。 有關計算出的預設值,請參見 AKS 節點資源預留 。 只適用於 Linux 節點池。 硬驅逐門檻
imageGcHighThreshold 磁碟使用量的百分比,之後映射垃圾收集一律會執行。 若要停用映射垃圾收集,請將 設定為100。 預設值為85% int
imageGcLowThreshold 永遠不會執行映射垃圾收集的磁碟使用量百分比。 這無法設定高於 imageGcHighThreshold。 預設值為 80% int
kubeReserved kubelet 的保留值。 當未設定值時,會使用系統根據虛擬機大小計算的預設值。 有關計算出的預設值,請參見 AKS 節點資源預留 。 只適用於 Linux 節點池。 KubeReserved
podMaxPids 每個 Pod 的進程數目上限。 int
seccompDefault 指定套用至所有工作負載的預設 seccomp 設定檔。 如果未指定,預設會使用 『Unconfined』。 'RuntimeDefault'
'Unconfined'
soft驅逐寬限期 軟性驅逐信號的寬限期——在淘汰前必須維持多久門檻。 預設和配對規則和 softEvictionThreshold 一樣。 數值為圍棋式的持續時間字串(例如「1分30秒」);支援單位包括「NS」、「US」、「MS」、「S」、「M」及「H」。 只適用於 Linux 節點池。 軟驅逐寬限期
soft驅逐門檻 Kubelet 的軟性驅逐門檻。 當被交叉時,膠囊會在配對的 softEvictionGracePeriod 後被淘汰。 當叢集 enableNodeHardening 屬性為真時,系統預設值會生效;否則不會設定軟性驅逐。 對於每個訊號(memoryAvailable、nodeFsAvailable、nodeFsInodesFree),softEvictionThreshold 和 softEvictionGracePeriod 中的條目必須處於相同狀態:兩者皆為省略(預設)、皆非空(覆寫),或兩串皆為空(選擇退出該訊號)。 只適用於 Linux 節點池。 參見 https://kubernetes.io/docs/concepts/scheduling-eviction/node-pressure-eviction/#soft-eviction-thresholds。 軟驅逐門檻
topologyManagerPolicy 要使用的拓撲管理員原則。 如需詳細資訊,請參閱 Kubernetes 拓撲管理員。 預設值為 『none』。 允許的值為 'none'、'best-effort'、'restricted'和 'single-numa-node'。 字串

KubeReserved

Name Description Value
cpuMillicores 為 Kubernetes 系統守護程式預留的 CPU 數量,以毫核計算。 必須大於或等於140。 例如,值為 200 代表 200 公尺(0.2 CPU 核心)。 int
記憶體MB Kubernetes 系統守護程序所保留的記憶體量,以 MiB 計算。 必須大於或等於750。 int

KubernetesResourceObjectEncryptionProfile

Name Description Value
基礎設施加密 是否使用服務託管金鑰啟用 Kubernetes 資源物件的靜態加密。 有關這方面的更多資訊,請參閱 https://aka.ms/aks/kubernetesResourceObjectEncryption。 'Disabled'
'Enabled'

LinuxOSConfig

Name Description Value
swapFileSizeMB 將在每個節點上建立之交換檔案 MB 的大小。 int
sysctls Linux 代理程序節點的 Sysctl 設定。 SysctlConfig
transparentHugePageDefrag 核心是否應該積極使用記憶體壓縮,讓更多的大量頁面可供使用。 有效值為 'always'、'defer'、'defer+madvise'、'madvise' 和 'never'。 默認值為 「瘋狂」。 如需詳細資訊,請參閱 Transparent Hugepages。 字串
transparentHugePageEnabled 是否啟用透明巨頁。 有效值為 『always』、『madvise』和 『never』。 默認值為 『always』。 如需詳細資訊,請參閱 Transparent Hugepages。 字串

本地DNS虛擬

Name Description Value
cacheDurationInSeconds 緩存最大 TTL(以秒為單位)。 有關更多資訊,請參閱 緩存外掛程式 。 int
forwardDestination 要從 localDNS 轉發的 DNS 查詢的目標伺服器。 'ClusterCoreDNS'
'VnetDNS'
forwardPolicy 用於選擇上游 DNS 伺服器的轉發策略。 有關更多資訊,請參閱 forward plugin 。 '隨機'
'RoundRobin'
'Sequential'
maxConcurrent 最大併發查詢數。 有關更多資訊,請參閱 forward plugin 。 int
通訊協定 對於從 localDNS 到上游 DNS 伺服器的連接,強制執行 TCP 或首選 UDP 協定。 'ForceTCP'
'PreferUDP'
queryLogging localDNS 中 DNS 查詢的日誌級別。 'Error'
'Log'
serveStale 用於提供過時數據的策略。 有關更多資訊,請參閱 緩存外掛程式 。 'Disable'
'Immediate'
'Verify'
serveStaleDurationInSeconds 提供過時的持續時間(以秒為單位)。 有關更多資訊,請參閱 緩存外掛程式 。 int

LocalDNSProfile

Name Description Value
kubeDNSOverrides KubeDNS 覆蓋適用於來自 dnsPolicy:ClusterFirst 的 Pod 的 DNS 流量(稱為 KubeDNS 流量)。 LocalDNSProfileKubeDNSOverrides
mode localDNS 的啟用模式。 'Disabled'
'Preferred'
'Required'
vnetDNSOverrides VnetDNS 覆蓋適用於來自 dnsPolicy:default 或 kubelet 的 Pod 的 DNS 流量(稱為 VnetDNS 流量)。 LocalDNSProfileVnetDNSOverrides

LocalDNSProfileKubeDNSOverrides

Name Description Value

LocalDNSProfileVnetDNSOverrides

Name Description Value

ManagedClusterAADProfile

Name Description Value
adminGroupObjectIDs 具有叢集管理員角色的 AAD 群組物件標識符清單。 string[]
clientAppID (已淘汰)用戶端 AAD 應用程式識別碼。 了解更多資訊,請至 https://aka.ms/aks/aad-legacy。 字串
enableAzureRBAC 是否要啟用 Azure RBAC 以進行 Kubernetes 授權。 bool
Managed 是否要啟用受控 AAD。 bool
serverAppID (已淘汰)伺服器 AAD 應用程式識別碼。 了解更多資訊,請至 https://aka.ms/aks/aad-legacy。 字串
serverAppSecret (已淘汰)伺服器 AAD 應用程式秘密。 了解更多資訊,請至 https://aka.ms/aks/aad-legacy。 string

Constraints:
敏感性值。 以安全參數的形式傳入。
tenantID 要用於驗證的 AAD 租使用者識別碼。 如果未指定,將會使用部署訂用帳戶的租使用者。 字串

ManagedClusterAddonProfile

Name Description Value
config 用於設定附加元件的關鍵/值組。 ManagedClusterAddonProfileConfig
enabled 是否啟用附加元件。 布林 (必要)

ManagedClusterAddonProfileConfig

Name Description Value

ManagedClusterAgentPoolProfile

Name Description Value
artifactStreamingProfile 在 AKS 上使用成品串流的設定。 AgentPoolArtifactStreamingProfile
availabilityZones 節點可用的 Availability zones 清單。 只有在 AgentPoolType 屬性是 'VirtualMachineScaleSets' 時,才能指定這個值。 string[]
capacityReservationGroupID 容量保留群組的完全限定資源 ID,用於從保留的 虛擬機器 群組提供 virtual machines。 此形式為:'/subscriptions/{subscriptionId}/resourcegroups/{resourceGroupName}/providers/Microsoft.Compute/capacityreservationgroups/{capacityReservationGroupName}' 客戶會用它建立包含指定 CRG 的代理池。 更多資訊請參見 Capacity Reservation 字串
count 裝載 Docker 容器的代理程式 (VM) 數目。 允許的值必須介於使用者集區的 0 到 1000(含)範圍內,且系統集區的範圍為 1 到 1000(含)。 預設值為 1。 int
creationData 如果節點集區將會使用快照集建立/升級,則用來指定來源快照集標識符的 CreationData。 CreationData
enableAutoScaling 是否要啟用自動調整程式 bool
enableEncryptionAtHost 是否要啟用主機型 OS 和數據磁碟驅動器加密。 這只支援特定虛擬機大小和特定 Azure 區域。 欲了解更多資訊,請參閱:/azure/aks/enable-host-encryption bool
enableFIPS 是否要使用已啟用 FIPS 的 OS。 詳情請參見 Add a enabled FIPS node pool。 bool
enableNodePublicIP 每個節點是否配置自己的公用IP。 某些案例可能需要節點集區中的節點接收自己的專用公用IP位址。 常見的案例是遊戲工作負載,其中控制台需要直接連線到雲端虛擬機,以將躍點降到最低。 更多資訊請參見為節點分配公共 IP。 默認值為 false。 bool
enableOSDiskFullCaching 是否啟用完整快取臨時作業系統磁碟功能。 啟用此功能後,整個作業系統會被本地快取於臨時作業系統磁碟,防止因網路故障引發的 E17 事件。 bool
enableUltraSSD 是否要啟用 UltraSSD bool
gatewayProfile 閘道模式中受控代理程式集區特有的配置檔。 如果代理程式集區模式不是閘道,則無法設定此欄位。 AgentPoolGatewayProfile
gpuInstanceProfile 要用來為支援的 GPU VM SKU 指定 GPU MIG 實例設定檔的 GPUInstanceProfile。 'MIG1g'
'MIG2g'
'MIG3g'
'MIG4g'
'MIG7g'
gpuProfile 代理程式集區的 GPU 設定。 GPUProfile
hostGroupID 專用主機群組的完全限定資源 ID,用於配置virtual machines,僅用於建立情境,且設定後不得更改。 這是格式:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Compute/hostGroups/{hostGroupName}。 欲了解更多資訊,請參見 Azure dedicated hosts。 字串
kubeletConfig 代理程式集區節點上的 Kubelet 組態。 KubeletConfig
kubeletDiskType 決定空 Dir 卷的放置位置、容器執行時資料根,以及 Kubelet 臨時儲存(ephemeral storage)。 'OS'
'Temporary'
linuxOSConfig Linux 代理程序節點的 OS 組態。 LinuxOSConfig
localDNSProfile 使用 VnetDNS 和 KubeDNS 覆蓋配置每個節點的本地 DNS。 LocalDNS 有助於提高 AKS 群集中 DNS 解析的性能和可靠性。 有關更多詳細資訊,請參閱 aka.ms/aks/localdns。 LocalDNSProfile
maxCount 自動調整的節點數目上限 int
maxPods 可在節點上執行的 Pod 數目上限。 int
messageOfTheDay Linux 節點當天的訊息,base64 編碼。 base64 編碼的字串,將在譯碼之後寫入 /etc/motd。 這允許自定義 Linux 節點當天的訊息。 它不得指定給 Windows 節點。 它必須是靜態字串(也就是將列印為未經處理,而不是以腳本的形式執行)。 字串
minCount 自動調整的節點數目下限 int
mode 代理程式集區的模式。 叢集必須隨時至少有一個「系統」代理程式集區。 欲了解更多關於代理池限制與最佳實務的資訊,請參閱:/azure/aks/use-system-pools 'Gateway'
'Machines'
'ManagedSystem'
'System'
'User'
name 訂用帳戶和資源群組內容中代理程式集區配置檔的唯一名稱。 Windows 代理程式集區名稱必須是 6 個字元或更少。 string

Constraints:
模式 = ^[a-z][a-z0-9]{0,11}$ (必要)
networkProfile 代理程式集區的網路相關設定。 AgentPoolNetworkProfile
nodeImageVersion (節點映射版本) 節點映像的版本。 設定此值會觸發 agentPool 回滾。
只允許輸入 的 recentlyUsedVersions 值。
字串
nodeInitializationTaints 建立期間在節點上新增的Taints不會由AKS協調。 這些污點不會由 AKS 協調,而且可以使用 kubectl 呼叫移除。 建立節點集區之後,即可修改此字段,但在需要重新建立另一項作業(例如節點映射升級)之前,節點將不會以新的污點重新建立。 這些污點允許在節點準備好接受工作負載之前執行必要的設定,例如 『key1=value1:NoSchedule』,然後可以使用 移除 kubectl taint nodes node1 key1=value1:NoSchedule- string[]
nodeLabels 要跨代理程式集區中所有節點保存的節點標籤。 ManagedClusterAgentPoolProfilePropertiesNodeLabels
nodePublicIPPrefixID VM 節點應該使用IP的公用IP前置詞標識碼。 格式如下:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/publicIPPrefixes/{publicIPPrefixName} 字串
nodeTaints 節點集區建立和調整期間新增至新節點的污點。 例如,key=value:NoSchedule。 string[]
orchestratorVersion 使用者指定的 Kubernetes 版本。 支援修補程式版本 <major.minor.patch> (例如 1.20.13)和 <major.minor> (例如 1.20)。 指定 major.minor< 時>,會自動選擇最新支援的 GA 修補程式版本。 在建立叢集之後,以相同的 <major.minor> 更新叢集(例如 1.14.x -> 1.14)將不會觸發升級,即使有較新的修補程式版本也一樣。 最佳做法是,您應該將 AKS 叢集中的所有節點集區升級為相同的 Kubernetes 版本。 節點集區版本必須與控制平面具有相同的主要版本。 節點集區次要版本必須位於控制平面版本的兩個次要版本內。 節點集區版本不能大於控制平面版本。 更多資訊請參見升級節點池。 字串
osDiskSizeGB OS 磁碟大小 GB,用來指定主要/代理程式集區中每部計算機的磁碟大小。 如果您指定 0,它會根據指定的 vmSize 套用預設 osDisk 大小。 int

Constraints:
最小值 = 0
最大值 = 2048
osDiskType 要用於代理程式集區中機器的 OS 磁碟類型。 如果 VM 支援,且快取磁碟大於要求的 OSDiskSizeGB,則預設值為 「暫時」。 否則,預設為 「受控」。 建立之後可能不會變更。 更多資訊請參見 Ephemeral OS。 'Ephemeral'
'Managed'
osSKU 指定代理程式集區所使用的 OS SKU。 如果OSType為Linux,則預設值為Ubuntu。 當 Kubernetes <= 1.24 或 Windows2022 時,如果 OSType >為 Windows,則預設值為 Windows2019。 'AzureContainerLinux'
'AzureLinux'
'AzureLinux3'
'CBLMariner'
“平車”
'Mariner'
'Ubuntu'
'Ubuntu2204'
'Ubuntu2404'
「Ubuntu2604」
'Windows2019'
'Windows2022'
“窗戶2025”
'WindowsAnnual'
osType 作系統類型。 預設值為Linux。 'Linux'
'Windows'
podIPAllocationMode Pod IP 分配模式。 代理程式集區中 Pod 的 IP 配置模式。 必須與 podSubnetId 搭配使用。 預設值為 『DynamicIndividual』。 'DynamicIndividual'
'StaticBlock'
podSubnetID 啟動時,Pod 會加入之子網的標識碼。 如果省略,則會在節點子網上靜態指派 Pod IP(如需詳細資訊,請參閱 vnetSubnetID)。 格式如下:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/virtualNetworks/{virtualNetworkName}/subnets/{subnetName} 字串
powerState 代理程式集區正在執行或停止。 第一次建立代理程式集區時,它一開始會執行。 您可以將此欄位設定為 [已停止] 來停止代理程式集區。 已停止的代理程式集區會停止其所有 VM,而不會產生計費費用。 只有在執行中且布建狀態為 [成功] 時,才能停止代理程式集區 PowerState
preparedImageSpecificationProfile 設定用以確定用於配置池中節點的已準備映像規格。 PreparedImageSpecificationProfile
proximityPlacementGroupID 鄰近放置群組的標識碼。 字串
scaleDownMode 調整代理程式集區時要使用的相應減少模式。 這也會影響叢集自動調整程序的行為。 如果未指定,則預設為 Delete。 'Deallocate'
'Delete'
scaleSetEvictionPolicy 虛擬機器擴展集收回原則。 驅逐政策會明確說明當虛擬機被驅逐時to do什麼。 預設值為刪除。 欲了解更多驅逐資訊,請參見 spot VMs 'Deallocate'
'Delete'
scaleSetPriority 虛擬機擴展集優先順序。 'Regular'
'Spot'
securityProfile 代理程式集區的安全性設定。 AgentPoolSecurityProfile
spotMaxPrice 您願意為現成實例支付的最高價格(以美元為單位)。 可能的值為大於零或 -1 的任何十進位值,表示依需求 up-to 默認價格。 可能的值為大於零或 -1 的任何十進位值,表示願意支付任何隨選價格。 欲了解更多現貨價格,請參閱 spot VMs 價格 int
狀態 包含代理程式集區的唯讀資訊。 AgentPoolStatus
tags 要保存在代理程式集區虛擬機擴展集上的標記。 ManagedClusterAgentPoolProfilePropertiesTags
型別 Agent 集區的類型。 'AvailabilitySet'
「FlexNodes」
'VirtualMachines'
'VirtualMachineScaleSets'
upgradeSettings 升級代理程式集池的設定 AgentPoolUpgradeSettings
升級設定藍綠 代理程式集區上 Blue-Green 升級的設定。 當升級策略設定為 BlueGreen 時適用。 AgentPoolBlueGreenUpgradeSettings
升級策略 定義代理程式集區的升級策略。 預設值為滾動。 “藍綠”
'Rolling'
virtualMachineNodesStatus VirtualMachines 代理程式集區中的節點狀態。 VirtualMachineNodes[]
virtualMachinesProfile VirtualMachines 代理程式集區的規格。 VirtualMachinesProfile
vmSize 代理程式集區 VM 的大小。 VM 大小可用性會因區域而異。 如果節點包含計算資源不足(記憶體、cpu 等)Pod 可能無法正確執行。 欲了解更多關於受限虛擬機大小的細節,請參閱:/azure/aks/quotas-skus-regions 字串
vnetSubnetID 代理程式集區節點和選擇性 Pod 將在啟動時加入的子網標識碼。 如果未指定此專案,則會產生及使用 VNET 和子網。 如果未指定 podSubnetID,這會套用至節點和 Pod,否則只會套用至節點。 格式如下:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/virtualNetworks/{virtualNetworkName}/subnets/{subnetName} 字串
windowsProfile Windows 代理程式集區的特定配置檔。 AgentPoolWindowsProfile
workloadRuntime 決定節點可執行的工作負載類型。 'KataMshvVmIsolation'
“KataVm隔離”
'OCIContainer'
'WasmWasi'

ManagedClusterAgentPoolProfilePropertiesNodeLabels

Name Description Value

ManagedClusterAgentPoolProfilePropertiesTags

Name Description Value

ManagedClusterAIToolchainOperatorProfile

Name Description Value
enabled 是否為集群啟用 AI toolchain Operator。 指出 AI 工具鏈運算子是否啟用。 bool

ManagedClusterAPIServerAccessProfile

Name Description Value
authorizedIPRanges 授權access Kubernetes API 伺服器的 IP 範圍。 IP 範圍以 CIDR 格式指定,例如 137.117.106.88/29。 此功能不相容於使用公共 IP 逐節點的叢集,或使用 Basic Load Balancer 的叢集。 欲了解更多資訊,請參閱 API 伺服器授權 IP 範圍。 string[]
disableRunCommand 是否要停用叢集的執行命令。 bool
enablePrivateCluster 是否要將叢集建立為私人叢集。 更多細節請參見 建立私人 AKS 叢集。 bool
enablePrivateClusterPublicFQDN 是否要為私人叢集建立其他公用 FQDN。 bool
enableVnetIntegration 是否要啟用叢集的apiserver vnet整合。 有關詳細資訊,請參閱 aka.ms/AksVnetIntegration。 bool
privateDNSZone 叢集的 private DNS 區域模式。 預設值為 System。 更多細節請參見 configure private DNS zone。 允許的值為 'system' 和 'none'。 字串
subnetId 啟用apiserver vnet整合時要使用的子網。 使用 BYO Vnet 創建新集群時,或者更新現有集群以啟用 apiserver vnet 集成時,需要它。 字串

ManagedClusterAppRoutingIstio

Name Description Value
mode 是否要啟用 Istio 作為 Gateway API 實作,用於管理式的 App 路由。 'Disabled'
'Enabled'

ManagedClusterAutoUpgradeProfile

Name Description Value
nodeOSUpgradeChannel 節點作系統升級通道。 更新節點上OS的方式。 預設值為 NodeImage。 'NodeImage'
'None'
'SecurityPatch'
'Unmanaged'
upgradeChannel 自動升級的升級通道。 預設值為 『none』。 更多資訊請參見 setting AKS 叢集自動升級通道。 'node-image'
'none'
'patch'
'rapid'
'stable'

ManagedClusterAzureMonitorProfile

Name Description Value
appMonitoring Kubernetes 應用程式容器的應用程式監視配置檔。 透過使用 Azure 監視器 OpenTelemetry 基礎的 SDK 自動監控應用程式,收集應用程式日誌、度量與追蹤資料。 如需概觀,請參閱 aka.ms/AzureMonitorApplicationMonitoring。 ManagedClusterAzureMonitorProfileAppMonitoring
containerInsights 設定此為啟用並設定叢集的 Azure 監視器 Container Insights,該叢集會收集 Kubernetes 事件、庫存,以及容器的標準與測試日誌。 如需概觀,請參閱 aka.ms/AzureMonitorContainerInsights。 ManagedClusterAzureMonitorProfileContainerInsights
計量 適用於 Prometheus 附加元件之 Azure 監視器受控服務的計量配置檔。 收集開箱即用的 Kubernetes 基礎架構指標,傳送至 Azure 監視器 工作區,並為自訂目標設定額外的爬蟲功能。 如需概觀,請參閱 aka.ms/AzureManagedPrometheus。 ManagedClusterAzureMonitorProfileMetrics

ManagedClusterAzureMonitorProfileAppMonitoring

Name Description Value
autoInstrumentation 應用監控 AKS 自動儀器化。 部署一個 webhook,自動與 Microsoft OpenTelemetry 發行版進行工作負載的測量,以收集 OpenTelemetry 的指標、日誌與追蹤資料。 請參閱 https://aka.ms/AKSAppMonitoringDocs 及 https://aka.ms/AzureMonitorApplicationMonitoring 以了解整體概覽。 ManagedClusterAzureMonitorProfileAppMonitoringAutoInstrumentation
開放遙測日誌與追蹤 應用程式監控 OpenTelemetry 的 AKS 日誌與追蹤設定檔。 利用 Azure 監視器 OpenTelemetry 基礎的 SDK 收集 OpenTelemetry 日誌與應用程式的追蹤資料。 請參閱 https://aka.ms/AKSAppMonitoringDocs 及 https://aka.ms/AzureMonitorApplicationMonitoring 以了解整體概覽。 ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryLogsAndTraces
openTelemetryMetrics 應用程式監控 OpenTelemetry 指標設定檔用於 AKS。 利用 Azure 監視器 OpenTelemetry 基礎的 SDK 收集應用程式的 OpenTelemetry 指標。 請參閱 https://aka.ms/AKSAppMonitoringDocs 及 https://aka.ms/AzureMonitorApplicationMonitoring 以了解整體概覽。 ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryMetrics

ManagedClusterAzureMonitorProfileAppMonitoringAutoInstrumentation

Name Description Value
enabled 指示是否啟用應用程式監控自動儀器。 bool

ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryLogsAndTraces

Name Description Value
enabled 指示是否啟用應用程式監控 OpenTelemetry 日誌與追蹤功能。 bool
grpcPort OpenTelemetry GRPC 的主機埠是日誌與追蹤。 若未指定,預設埠口為 28332。 int
httpPort OpenTelemetry HTTP/PROTOBUF 日誌與追蹤的主機埠。 如果未指定,預設埠為 28331。 int

ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryMetrics

Name Description Value
enabled 指示是否啟用應用程式監控 OpenTelemetry Metrics。 bool
grpcPort OpenTelemetry GRPC 指標的主機埠。 如果未指定,預設埠口為 28334。 int
httpPort OpenTelemetry HTTP/PROTOBUF 指標的主機埠。 如果未指定,預設埠為 28333。 int

ManagedClusterAzureMonitorProfileContainerInsights

Name Description Value
containerNetworkLogs 容器網路日誌 用 Azure 監視器 配置容器網路日誌的攝取。 所攝取的日誌類型由相關的CRD控制;若未指定,則預設為 Disabled。 詳情請參閱 https://aka.ms/ContainerNetworkLogsDoc 及https://aka.ms/acns/howtoenablecnl 'Disabled'
'Enabled'
disablePrometheusMetricsScraping 指出是否停用 prometheus 計量擷取。 若未指定,預設為 false,也就是說 prometheus 抓取已被啟用。 bool
enabled 指示是否啟用 Azure 監視器 容器 Insights Logs 外掛。 bool
logAnalyticsWorkspaceResourceId Azure Log Analytics Workspace 的完全合格 ARM 資源 ID 用於儲存 Azure 監視器 容器 Insights Logs. 字串
syslogPort syslog 主機埠。 如果未指定,預設埠為 28330。 int

ManagedClusterAzureMonitorProfileKubeStateMetrics

Name Description Value
metricAnnotationsAllowList 將在資源標籤量中使用的 Kubernetes 批註索引鍵逗號分隔清單(範例:'namespaces=[kubernetes.io/team,...],pods=[kubernetes.io/team],...')。 根據預設,計量只包含資源名稱和命名空間標籤。 字串
metricLabelsAllowlist 將用於資源標籤計量的其他 Kubernetes 標籤索引鍵逗號分隔清單(範例:'namespaces=[k8s-label-1,k8s-label-n,...],pods=[app],...')。 根據預設,計量只包含資源名稱和命名空間標籤。 字串

ManagedClusterAzureMonitorProfileMetrics

Name Description Value
controlPlane的 Control plane metrics collection profile for the Azure Managed Prometheus addon. 配置來自受管理控制平面元件(如 kube-apiserver、etcd 等)的運作執行時指標收集。 請參見 aka.ms/aks/controlplane-metrics 以了解整體概覽。 ManagedClusterAzureMonitorProfileMetricsControlPlane
enabled 是否啟用或停用 Azure Managed Prometheus 外掛以監控 Prometheus。 如需啟用和停用的詳細資訊,請參閱 aka.ms/AzureManagedPrometheus-aks-enable。 布林 (必要)
kubeStateMetrics Azure 受控 Prometheus 附加元件 Kube 狀態計量配置檔。 這些選擇性設定適用於使用附加元件部署的 kube-state-metrics Pod。 如需詳細資訊,請參閱 aka.ms/AzureManagedPrometheus-optional-parameters。 ManagedClusterAzureMonitorProfileKubeStateMetrics

ManagedClusterAzureMonitorProfileMetricsControlPlane

Name Description Value
enabled 是否啟用或停用 Azure Managed Prometheus 外掛的控制平面指標收集。 預設為停用。 詳情請參見 aka.ms/aks/controlplane-metrics。 bool

ManagedClusterBootstrapProfile

Name Description Value
artifactSource 成品來源。 下載這些 artifacts 的來源。 'Cache'
'Direct'
containerRegistryId The resource ID of Azure Container Registry. 登錄檔必須具備私有網路access、高級 SKU 及區域冗餘。 字串

ManagedClusterControlPlaneScalingProfile

Name Description Value
縮放大小 控制平面的縮放尺寸。 縮放規模提供保證容量與可預測的 Kubernetes 效能,超越標準預設。 較大的H尺寸能提供更高的性能保證。 請參閱 https://aka.ms/aks/hyperscale 各尺寸的效能指標細節。 「H2」
「H4」
「H8」(必填)

ManagedClusterCostAnalysis

Name Description Value
enabled 是否啟用成本分析。 受控叢集 sku.tier 必須設定為 「標準」或「進階」,才能啟用此功能。 啟用此功能後,Kubernetes 命名空間與部署細節會加入 Azure portal 的成本分析檢視。 如果未指定,則預設值為 false。 如需詳細資訊,請參閱 aka.ms/aks/docs/cost-analysis。 bool

ManagedClusterHealthMonitorProfile

Name Description Value
啟用持續控制平面與附加監控器 是否啟用連續控制平面和附加元件監控。 bool
enableOnDemandMonitor 是否啟用隨選監控。 bool

ManagedClusterHosted系統設定檔

Name Description Value
enabled 是否要為叢集啟用託管系統附加元件。 bool
nodeSubnetID 由 node auto provisioner 管理的工作節點加入的子網 ID,用於在租戶中執行工作負載 Pod。 這必須與 systemNodeSubnetID 和 apiserverAccessProfile.subnetId一起提供,且三個子網 ID 必須在同一個 VNet 中。 如果你沒特別指定,AKS 會在管理資源群組中用預設的 /16 CIDR 建立一個子網路。 字串
systemNodeSubnetID 由 AKS 管理並託管的系統節點加入的子網 ID,用於執行關鍵系統附加元件。 此 ID 必須與 nodeSubnetIDapiserverAccessProfile.subnetId及 一同提供,且三個子網 ID 必須屬於同一個 VNet。 如果你沒特別指定,AKS 會在管理資源群組中用預設的 /26 CIDR 建立子網路。 字串

ManagedClusterHttpProxyConfig

Name Description Value
enabled 是否開啟 HTTP 代理。 若停用,指定的代理設定將不會被設定在 pods 和節點上。 如果未指定,則預設值為 true。 bool
httpProxy 要使用的 HTTP Proxy 伺服器端點。 字串
httpsProxy 要使用的 HTTPS Proxy 伺服器端點。 字串
noProxy 不應該通過 Proxy 的端點。 string[]
trustedCa 用來連線到 Proxy 伺服器的替代 CA 憑證。 字串

ManagedClusterIdentity

Name Description Value
delegatedResources 指派給此受控叢集的委派身分識別資源。 這只能由其他 Azure 資源提供者設定,而受管理叢集只接受一個委派的身份資源。 僅供內部使用。 ManagedClusterIdentityDelegatedResources
型別 用於受控叢集的身分識別類型。 欲了解更多資訊,請參閱 AKS 中的 use 管理身份。 'None'
'SystemAssigned'
'UserAssigned'
userAssignedIdentities 與受控叢集相關聯的使用者身分識別。 此身分識別將用於控制平面。 只允許一個使用者指派的身分識別。 密鑰必須是 ARM 資源識別符,格式為:『/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'。 ManagedClusterIdentityUserAssignedIdentities

ManagedClusterIdentityDelegatedResources

Name Description Value

ManagedClusterIdentityUserAssignedIdentities

Name Description Value

ManagedClusterIngressDefaultDomainProfile

Name Description Value
enabled 是否啟用預設網域。 bool

ManagedClusterIngressProfile

Name Description Value
applicationLoadBalancer 管理式 Application Load Balancer 安裝設定 ManagedClusterIngressProfileApplicationLoadBalancer
閘道API 託管閘道 API 安裝的設置 ManagedClusterIngressProfileGateway配置
webAppRouting 輸入設定檔的應用程式路由設定。 你可以在 /azure/aks/app-routing?tabs=default%2Cdeploy-app-default 找到此功能的概述與入職指南。 ManagedClusterIngressProfileWebAppRouting

ManagedClusterIngressProfileApplicationLoadBalancer

Name Description Value
enabled 是否啟用 Application Load Balancer。 bool

ManagedClusterIngressProfileGateway配置

Name Description Value
安裝 託管閘道 API 安裝的配置。 如果未指定,則預設值為“禁用”。 如需詳細資訊,請參閱 https://aka.ms/k8s-gateway-api。 'Disabled'
'Standard'

ManagedClusterIngressProfileNginx

Name Description Value
defaultIngressControllerType 默認 NginxIngressController 自訂資源的輸入類型 'AnnotationControlled'
'External'
'Internal'
'None'

ManagedClusterIngressProfileWebAppRouting

Name Description Value
預設網域 預設網域的設定。 這是一個唯一的自動生成域,帶有簽名的 TLS 證書,允許安全的 HTTPS。 更多說明 請參閱預設網域文件 。 ManagedClusterIngressDefaultDomainProfile
dnsZoneResourceIds 要與應用程式路由附加元件相關聯的 DNS 區域資源識別碼。 只有在啟用應用程式路由附加元件時才使用。 公有與 private DNS 區域可以屬於不同的資源群組,但所有公共 DNS 區域必須屬於同一資源群組,且所有 private DNS 區域必須在同一資源群組中。 string[]
enabled 是否要啟用應用程式路由附加元件。 bool
gatewayAPIImplementations 閘道 API 提供者用於管理式 App Routing 的設定。 欲了解更多關於閘道 API(Gateway API)的資訊,請參閱 https://aka.ms/k8s-gateway-api 此處。 ManagedClusterWebAppRoutingGatewayAPIImplementations
nginx 默認 NginxIngressController 的組態。 詳情請見 /azure/aks/app-routing-nginx-configuration#the-default-nginx-ingress-controller。 ManagedClusterIngressProfileNginx

ManagedClusterLoadBalancerProfile

Name Description Value
allocatedOutboundPorts 每個 VM 所需配置的 SNAT 埠數目。 允許的值介於 0 到 64000 的範圍內(含)。 預設值是 0,這會導致 Azure 動態分配埠口。 int

Constraints:
最小值 = 0
最大值 = 64000
backendPoolType 受管理的入站 Load Balancer BackendPool 類型。 'NodeIP'
'NodeIPConfiguration'
「PodIP」
clusterServiceLoadBalancerHealthProbeMode 外部流量原則叢集服務的健全狀況探查行為。 'ServiceNodePort'
“共用”
enableMultipleStandardLoadBalancers 為每個 AKS 叢集啟用多個標準負載平衡器。 bool
idleTimeoutInMinutes 所需的輸出流程閑置逾時,以分鐘為單位。 允許的值介於 4 到 120 之間(含)。 預設值為 30 分鐘。 int

Constraints:
最小值 = 4
最大值 = 120
managedOutboundIPs 叢集load balancer想要的託管外站 IP。 ManagedClusterLoadBalancerProfileManagedOutboundIPs
outboundIPPrefixes 叢集load balancer的期望外撥 IP 前綴資源。 ManagedClusterLoadBalancerProfileOutboundIPPrefixes
outboundIPs 叢集load balancer的期望外撥 IP 資源。 ManagedClusterLoadBalancerProfileOutboundIPs

ManagedClusterLoadBalancerProfileManagedOutboundIPs

Name Description Value
count Azure為叢集建立/管理的 IPv4 外站 IP 數量load balancer。 允許的值必須介於 1 到 100 的範圍內(含)。 預設值為 1。 int

Constraints:
最小值 = 1
最大值 = 100
countIPv6 Azure為叢集建立/管理的 IPv6 外撥 IP 數量load balancer。 允許的值必須介於 1 到 100 的範圍內(含)。 單一堆棧的預設值為0,雙堆疊的預設值為1。 int

Constraints:
最小值 = 0
最大值 = 100

ManagedClusterLoadBalancerProfileOutboundIPPrefixes

Name Description Value
publicIPPrefixes 公用IP前置資源的清單。 ResourceReference[]

ManagedClusterLoadBalancerProfileOutboundIPs

Name Description Value
publicIPs 公用IP資源的清單。 ResourceReference[]

ManagedClusterManagedOutboundIPProfile

Name Description Value
count Azure 建立/管理的期望出站 IP 數量。 允許的值必須介於 1 到 16 的範圍內(含)。 預設值為 1。 int

Constraints:
最小值 = 1
最大值 = 16
countIPv6 Azure 所建立/管理的 IPv6 外站 IP 數量。 允許的值必須介於 1 到 16 的範圍內(含)。 int

Constraints:
最小值 = 1
最大值 = 16

ManagedClusterMetricsProfile

Name Description Value
costAnalysis 每個 Kubernetes 資源成本分析的詳細設定。 ManagedClusterCostAnalysis

ManagedClusterNATGatewayProfile

Name Description Value
idleTimeoutInMinutes 所需的輸出流程閑置逾時,以分鐘為單位。 允許的值介於 4 到 120 之間(含)。 預設值為 4 分鐘。 int

Constraints:
最小值 = 4
最大值 = 120
managedOutboundIPProfile 叢集 NAT 閘道的受控輸出 IP 資源設定檔。 ManagedClusterManagedOutboundIPProfile
outboundIPPrefixes 管理 NAT 閘道所需的外撥 IP 前綴資源。 僅相容於 NAT Gateway V2。 ManagedClusterNATGatewayProfileOutboundIPPrefixes
outboundIPs 管理 NAT 閘道器的期望外站 IP 資源。 ManagedClusterNATGatewayProfileOutboundIPS
sku 管理叢集 NAT 閘道器的 SKU。 預設為「StandardV2」(區域區域適用),否則為「Standard」。 'Standard'
'StandardV2'

ManagedClusterNATGatewayProfileOutboundIPPrefixes

Name Description Value
publicIPPrefixes 公用IP前置資源的清單。 string[]

ManagedClusterNATGatewayProfileOutboundIPS

Name Description Value
publicIPs 公用IP資源的清單。 string[]

ManagedClusterNodeProvisioningProfile

Name Description Value
defaultNodePools 為節點預置配置的預設 Karpenter 節點池 (CRD) 集。 除非mode為 'Auto',否則此欄位無效。 警告:在現有集群上將其從 Auto 更改為 None 將導致預設的 Karpenter NodePools 被刪除,這將耗盡並刪除與這些池關聯的節點。 強烈建議不要這樣做,除非有空閒節點準備好接收該作驅逐的 Pod。 如果未指定,則預設值為 Auto。有關更多資訊,請參閱 aka.ms/aks/nap#node-pools。 'Auto'
'None'
mode 節點布建模式。 如果未指定,則預設值為Manual。 'Auto'
'Manual'

ManagedClusterNodeResourceGroupProfile

Name Description Value
restrictionLevel 套用至叢集節點資源群組的限制層級。 如果未指定,預設值為 'Unrestricted' 'ReadOnly'
'Unrestricted'

ManagedClusterOidcIssuerProfile

Name Description Value
enabled 是否啟用 OIDC 簽發者。 bool

ManagedClusterPodIdentity

Name Description Value
bindingSelector 要用於 AzureIdentityBinding 資源的系結選取器。 字串
身分識別 使用者指派的身分識別詳細數據。 UserAssignedIdentity (必需)
name Pod 身分識別的名稱。 字串 (必要)
命名空間 Pod 身分識別的命名空間。 字串 (必要)

ManagedClusterPodIdentityException

Name Description Value
name Pod 身分識別例外狀況的名稱。 字串 (必要)
命名空間 Pod 身分識別例外狀況的命名空間。 字串 (必要)
podLabels 要比對的 Pod 標籤。 ManagedClusterPodIdentityExceptionPodLabels (必需)

ManagedClusterPodIdentityExceptionPodLabels

Name Description Value

ManagedClusterPodIdentityProfile

Name Description Value
allowNetworkPluginKubenet 是否允許Pod身分識別在具有 Kubenet 網路的叢集上執行。 根據預設,在 Kubenet 中執行會因為 AAD Pod 身分識別的安全性相關本質和 IP 詐騙的風險而停用。 更多資訊請參閱 using Kubenet network plugin with AAD Pod Identity。 bool
enabled 是否啟用Pod身分識別附加元件。 bool
userAssignedIdentities 叢集中要使用的Pod身分識別。 ManagedClusterPodIdentity[]
userAssignedIdentityExceptions 允許的Pod身分識別例外狀況。 ManagedClusterPodIdentityException[]

ManagedClusterProperties

Name Description Value
aadProfile Azure Active Directory配置。 ManagedClusterAADProfile
addonProfiles 受控叢集附加元件配置檔。 ManagedClusterPropertiesAddonProfiles
agentPoolProfiles 代理程式集區屬性。 ManagedClusterAgentPoolProfile[]
aiToolchainOperatorProfile 適用於整個叢集的 AI 工具鏈作員設定。 ManagedClusterAIToolchainOperatorProfile
apiServerAccessProfile 管理叢集 API 伺服器的 access 設定檔。 ManagedClusterAPIServerAccessProfile
autoScalerProfile 啟用時要套用至叢集自動調整程序的參數 ManagedClusterPropertiesAutoScalerProfile
autoUpgradeProfile 自動升級組態。 ManagedClusterAutoUpgradeProfile
azureMonitorProfile Azure 監視器 外掛配置檔用於監控受管理叢集。 ManagedClusterAzureMonitorProfile
bootstrapProfile 叢集啟動程式組態的配置檔。 ManagedClusterBootstrapProfile
controlPlaneScalingProfile 提供可擴展且具效能保證的控制平面容量,以在高負載下提供穩定效能的配置檔。 需要 Kubernetes 版本 1.33.0 或更新版本。 ManagedClusterControlPlaneScalingProfile
creationData 如果叢集是使用快照集建立/升級,則用來指定來源快照集標識符的 CreationData。 CreationData
disableLocalAccounts 如果應該在受控叢集上停用本機帳戶。 如果設定為 true,將會停用此叢集的靜態認證。 這隻能在已啟用 AAD 的受控叢集上使用。 更多詳情請參見 disable local accounts。 bool
diskEncryptionSetID 要用來啟用待用加密之磁碟加密的資源標識符。 這是格式:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Compute/diskEncryptionSets/{encryptionSetName}' 字串
dnsPrefix 受控叢集的 DNS 前置詞。 建立受控叢集之後,就無法更新此專案。 字串
enableFIPS 是否要在叢集層級啟用 FIPS 模式。 啟用時,此設定會強制所有 AKS 管理元件(如節點作業系統、外掛及 受管理容器化元件)符合 FIPS 規範。 詳情請參見 啟用叢集範圍 FIPS 。 啟用此功能後,叢集中所有節點池也必須啟用 FIPS。 bool
enableNamespaceResources 啟用 namespace as Azure 資源。 預設值為 false。 您可以在建立和更新受控叢集時啟用/停用它。 如需命名空間作為 ARM 資源的詳細資訊,請參閱 https://aka.ms/NamespaceARMResource 。 bool
enableNodeHardening 是否要在叢集層級啟用節點強化。 啟用後,AKS 會對叢集中所有 Linux 節點池套用軟驅逐閾值、kube 保留及系統保留的硬化預設值。 每個節點池的 kubeletConfig 設定優先於強化預設值。 在運行 Kubernetes 1.37 或更新版本的代理池中,節點強化預設是啟用且無法關閉的;將此欄位設為 false 對這些池子沒有影響。 bool
enableRBAC 是否啟用 Kubernetes Role-Based 存取控制。 bool
fqdnSubdomain 私有叢集的 FQDN 子網域,並擁有自訂的 private dns 區域。 建立受控叢集之後,就無法更新此專案。 字串
健康監測檔案 管理叢集的健康監控設定檔。 ManagedClusterHealthMonitorProfile
hosted系統設定檔 託管系統插件的設置。 如需詳細資訊,請參閱https://aka.ms/aks/automatic/systemcomponents。 ManagedClusterHosted系統設定檔
httpProxyConfig 使用 HTTP Proxy 伺服器布建叢集的組態。 ManagedClusterHttpProxyConfig
identityProfile 與受控叢集相關聯的使用者身分識別。 kubelet 會使用此身分識別。 只允許一個使用者指派的身分識別。 唯一接受的密鑰是 “kubeletidentity”,值為 “resourceId”:“/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}”。 ManagedClusterPropertiesIdentityProfile
ingressProfile 受控叢集的輸入配置檔。 ManagedClusterIngressProfile
kubernetesVersion 使用者指定的 Kubernetes 版本。 支援修補程式版本 <major.minor.patch> (例如 1.20.13)和 <major.minor> (例如 1.20)。 指定 major.minor< 時>,會自動選擇最新支援的 GA 修補程式版本。 在建立叢集之後,以相同的 <major.minor> 更新叢集(例如 1.14.x -> 1.14)將不會觸發升級,即使有較新的修補程式版本也一樣。 當您升級支援的 AKS 叢集時,無法略過 Kubernetes 次要版本。 所有升級都必須依主要版本號碼循序執行。 例如,允許在 1.14.x -> 1.15.x 或 1.15.x - 1.16.x 之間升級,但不允許 1.14.x ->> 1.16.x。 更多細節請參見 升級 AKS 叢集。 字串
linuxProfile 受控叢集中Linux VM的配置檔。 ContainerServiceLinuxProfile
metricsProfile 選擇性叢集計量組態。 ManagedClusterMetricsProfile
networkProfile 網路組態配置檔。 ContainerServiceNetworkProfile
nodeDisruptionProfile 管理叢集的節點中斷設定檔。 節點破壞剖面
nodeProvisioningProfile 套用至整個叢集的節點布建設定。 ManagedClusterNodeProvisioningProfile
nodeResourceGroup 包含代理程式集區節點的資源群組名稱。 字串
nodeResourceGroupProfile 節點資源群組組態的配置檔。 ManagedClusterNodeResourceGroupProfile
oidcIssuerProfile 受控叢集的 OIDC 簽發者配置檔。 ManagedClusterOidcIssuerProfile
podIdentityProfile 受控叢集的Pod身分識別配置檔。 欲了解更多關於 AAD 莢果身份整合的細節,請參見 use AAD pod identity。 ManagedClusterPodIdentityProfile
privateLinkResources 與叢集相關的 Private link 資源。 PrivateLinkResource[]
publicNetworkAccess PublicNetworkAccess 的 PublicNetworkAccess 中。 允許或拒絕 AKS 的公共網路 access 'Disabled'
'Enabled'
“SecuredByPerimeter”
schedulerProfile 設定檔包含排程器相關的設定,例如每個排程器的設定模式,由 AKS 管理。 參見 https://aka.ms/aks/scheduler-profile。 SchedulerProfile
securityProfile 受控叢集的安全性配置檔。 ManagedClusterSecurityProfile
serviceMeshProfile 受控叢集的服務網格配置檔。 ServiceMeshProfile
servicePrincipalProfile 關於叢集用來操作 Azure API 的服務主體身份資訊。 ManagedClusterServicePrincipalProfile
狀態 包含受控叢集的唯讀資訊。 ManagedClusterStatus
storageProfile 管理叢集的 Storage 設定檔。 ManagedClusterStorageProfile
supportPlan 受控叢集的支持計劃。 如果未指定,則預設值為 『KubernetesOfficial』。 'AKSLongTermSupport'
'KubernetesOfficial'
upgradeSettings 升級叢集的設定。 ClusterUpgradeSettings
windowsProfile 受控叢集中 Windows VM 的配置檔。 ManagedClusterWindowsProfile
workloadAutoScalerProfile 受控叢集的工作負載自動調整程式配置檔。 ManagedClusterWorkloadAutoScalerProfile

ManagedClusterPropertiesAddonProfiles

Name Description Value

ManagedClusterPropertiesAutoScalerProfile

Name Description Value
balance-similar-node-groups 偵測相似的節點集區,並平衡其間的節點數目。 有效值為 'true' 和 'false' 字串
daemonset-eviction-for-empty-nodes DaemonSet Pod 將從空節點正常終止。 如果設定為 true,則會在刪除節點之前收回空白節點上的所有精靈集 Pod。 如果無法收回精靈集 Pod,則會選擇另一個節點進行調整。 如果設定為 false,則會刪除節點,而不會確保刪除或收回精靈集 Pod。 bool
daemonset-eviction-for-occupied-nodes DaemonSet Pod 將從非空節點正常終止。 如果設定為 true,則會先收回已佔用節點上的所有精靈集 Pod,再刪除節點。 如果無法收回精靈集 Pod,則會選擇另一個節點進行調整。 如果設定為 false,則會刪除節點,而不會確保刪除或收回精靈集 Pod。 bool
expander 縱向擴展時要使用的擴展器。 如果未指定,則預設值為 『random』。 更多資訊請參見擴展器。 'least-waste'
'most-pods'
'priority'
'random'
ignore-daemonsets-utilization CA 在計算縮減的資源利用率時是否應該忽略 DaemonSet Pod。 如果設定為 true,精靈集所使用的資源會在做出相應減少決策時納入考慮。 bool
max-empty-bulk-delete 可以同時刪除的空白節點數目上限。 這必須是正整數。 預設值為 10。 字串
max-graceful-termination-sec 叢集自動調整程式在嘗試相應減少節點時等候Pod終止的最大秒數。 預設值為 600。 字串
max-node-provision-time 自動調整程式等候布建節點的最大時間。 預設值為 『15m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
max-total-unready-percentage 叢集中未讀取節點的最大百分比。 超過此百分比之後,叢集自動調整程式會停止作業。 預設值為 45。 最大值為 100,最小值為 0。 字串
new-pod-scale-up-delay 在某個年齡之前,請忽略未排程的 Pod。 針對高載/批次規模等案例,您不希望 CA 在 kubernetes 排程器排程所有 Pod 之前採取行動,您可以告訴 CA 在排程特定年齡之前忽略未排程的 Pod。 預設值為 『0s』。 值必須是整數,後面接著單位(秒的 's'、'm' 代表分鐘數、'h' 等。 字串
ok-total-unready-count 允許的未讀取節點數目,不論 total-total-unready-percentage。 這必須是整數。 預設值為 3。 字串
scale-down-delay-after-add 擴大後需要多長時間才能繼續進行縮小評估。 預設值為 『10m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-delay-after-delete 節點刪除後再繼續進行縮小評估的時間長度。 預設值為掃描間隔。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-delay-after-failure 縮小失敗後再繼續進行縮小評估的時間長度。 預設值為 『3m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-unneeded-time 節點在符合相應減少資格之前,應該不需要多久的時間。 預設值為 『10m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-unready-time 未就緒的節點在符合縮減條件之前應不需要多長時間。 默認值為 『20m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-utilization-threshold 節點使用率層級,定義為要求資源的總和除以容量,而節點可考慮相應減少。 預設值為 『0.5』。 字串
scan-interval 重新評估叢集以相應增加或減少的頻率。 預設值為 『10』。 值必須是整數秒數。 字串
跳過節點與本地storage 如果叢集自動縮放器會跳過刪除帶有本地 storage 的 pod 節點,例如 EmptyDir 或 HostPath。 默認值為 true。 字串
skip-nodes-with-system-pods 如果集群自動擴縮器會跳過從 kube-system 中刪除帶有 Pod 的節點(DaemonSet 或鏡像 Pod 除外)。 默認值為 true。 字串

ManagedClusterPropertiesIdentityProfile

Name Description Value

ManagedClusterSecurityProfile

Name Description Value
azureKeyVaultKms Azure Key Vault key management service 安全設定檔的設定。 AzureKeyVaultKms
customCATrustCertificates 最多 10 個 base64 編碼 CA 的清單,這些 CA 將會新增至叢集中所有節點上的信任存放區。 欲了解更多資訊,請參閱 Custom CA Trust Certificates。 any[]
defender Microsoft Defender 的安全設定檔設定。 ManagedClusterSecurityProfileDefender
imageCleaner 安全性配置檔的影像清除器設定。 ManagedClusterSecurityProfileImageCleaner
imageIntegrity 影像完整性是一項與 Azure 原則 合作,透過簽章驗證影像完整性的功能。 除非使用 Azure 原則 強制執行映像簽章,否則此方法不會有影響。 如需如何透過原則使用這項功能,請參閱 https://aka.ms/aks/image-integrity 。 ManagedClusterSecurityProfileImageIntegrity
kubernetesResourceObjectEncryptionProfile 對 Kubernetes 資源物件進行靜態加密。 有關這方面的更多資訊,請訪問 https://aka.ms/aks/kubernetesResourceObjectEncryption KubernetesResourceObjectEncryptionProfile
nodeRestriction Node Restriction 安全設定檔。 ManagedClusterSecurityProfileNodeRestriction
serviceAccountImagePullProfile 定義基於服務帳號的圖片拉取設定。 ServiceAccountImagePullProfile
workloadIdentity 安全性配置檔的工作負載身分識別設定。 工作負載身份讓 Kubernetes 應用程式能透過 Azure AD 安全access Azure雲端資源。 如需詳細資訊,請參閱 https://aka.ms/aks/wi。 ManagedClusterSecurityProfileWorkloadIdentity

ManagedClusterSecurityProfileDefender

Name Description Value
logAnalyticsWorkspaceResourceId 與 Microsoft Defender 關聯的日誌分析工作區資源 ID。 啟用 Microsoft Defender 時,此欄位為必填且必須為有效的工作空間資源 ID。 當 Microsoft Defender 被停用時,請將欄位留空。 字串
securityGating Microsoft Defender 的安全閘控設定。 此測試驗證容器映像檔是否符合部署資格,基於 Defender for Containers 的安全發現。 利用 Admission Controller,它會審核或阻止部署不符合安全標準的映像檔。 如需詳細資訊,請參閱https://aka.ms/KubernetesDefenderAuditRule。 ManagedClusterSecurityProfileDefenderSecurityGating
securityMonitoring Microsoft Defender 威脅偵測,用於雲端安全設定檔。 ManagedClusterSecurityProfileDefenderSecurityMonitoring

ManagedClusterSecurityProfileDefenderSecurityGating

Name Description Value
allowSecretAccess 僅在登錄檔存取由秘密身份而非管理身份授予時使用。 設定是否授予 Defender 門控代理存取叢集機密以從登錄檔拉取影像。 若秘密存取被拒絕且登錄檔要求拉取秘密,該外掛將不會執行映像驗證。 預設值為 False。 bool
enabled 是否要啟用Defender安全性管制。 啟用後,閘控功能會掃描容器映像檔,並審核或阻擋不符合安全標準的映像檔部署,並依照配置的安全規則。 如需詳細資訊,請參閱https://aka.ms/KubernetesDefenderAuditRule。 bool
身分識別 允許存取控制者用來從登錄庫拉取安全產物的身份列表。 這些是叢集用來提取容器映像的相同身分識別。 欲了解更多關於配置此身份的資訊,請參閱 /azure/defender-for-cloud/gated-deployment-infrastructure-as-code。 ManagedClusterSecurityProfileDefenderSecurityGatingIdentity[]

ManagedClusterSecurityProfileDefenderSecurityGatingIdentity

Name Description Value
azureContainerRegistry 將使用身分識別的容器登錄;此處指定的身分識別應該附加同盟身分識別認證。 字串
身分識別 用於access登錄檔的身份物件 UserAssignedIdentity

ManagedClusterSecurityProfileDefenderSecurityMonitoring

Name Description Value
enabled 是否啟用Defender威脅偵測 bool

ManagedClusterSecurityProfileImageCleaner

Name Description Value
enabled 是否要在 AKS 叢集上啟用影像清除器。 bool
intervalHours 影像清除程序掃描間隔以小時為單位。 int

ManagedClusterSecurityProfileImageIntegrity

Name Description Value
enabled 是否要啟用映像完整性。 預設值為 false。 bool

ManagedClusterSecurityProfileNodeRestriction

Name Description Value
enabled 是否啟用節點限制 bool

ManagedClusterSecurityProfileWorkloadIdentity

Name Description Value
enabled 是否要啟用工作負載身分識別。 bool

ManagedClusterServicePrincipalProfile

Name Description Value
clientId 服務主體的標識碼。 字串 (必要)
密碼 純文本中與服務主體相關聯的秘密密碼。 string

Constraints:
敏感性值。 以安全參數的形式傳入。

ManagedClusterSKU

Name Description Value
name 受控叢集 SKU 的名稱。 'Automatic'
'Base'
分層 受控叢集 SKU 的層。 如果未指定,則預設值為 『Free』。 詳情請參見 AKS 定價層級。 'Free'
'Premium'
'Standard'

ManagedClusterStaticEgressGatewayProfile

Name Description Value
enabled 啟用 Static Egress Gateway 外掛程式。 指出是否啟用靜態輸出閘道附加元件。 bool

ManagedClusterStatus

Name Description Value

ManagedClusterStorageProfile

Name Description Value
blobCSIDriver AzureBlob CSI 驅動程式設定中的 storage 設定檔。 ManagedClusterStorageProfileBlobCSIDriver
diskCSIDriver AzureDisk CSI 驅動程式設定中 storage profile 的設定。 ManagedClusterStorageProfileDiskCSIDriver
fileCSIDriver AzureFile CSI 驅動程式設定中的 storage 設定檔。 ManagedClusterStorageProfileFileCSIDriver
snapshotController storage profile 的快照控制器設定。 ManagedClusterStorageProfileSnapshotController

ManagedClusterStorageProfileBlobCSIDriver

Name Description Value
enabled 是否要啟用 AzureBlob CSI 驅動程式。 預設值為 false。 bool

ManagedClusterStorageProfileDiskCSIDriver

Name Description Value
enabled 是否要啟用 AzureDisk CSI 驅動程式。 預設值為 True。 bool

ManagedClusterStorageProfileFileCSIDriver

Name Description Value
enabled 是否要啟用 AzureFile CSI 驅動程式。 預設值為 True。 bool

ManagedClusterStorageProfileSnapshotController

Name Description Value
enabled 是否要啟用快照控制器。 預設值為 True。 bool

ManagedClusterWebAppRoutingGatewayAPIImplementations

Name Description Value
appRoutingIstio 設定使用 Sidecar 無邊車的 Istio 控制平面,透過 Gateway API 與 App 路由進行管理式入口。 請參閱 https://aka.ms/gateway-on-istio 有關使用 Istio 透過閘道 API 進入的資訊。 ManagedClusterAppRoutingIstio

ManagedClusterWindowsProfile

Name Description Value
adminPassword 指定系統管理員帳戶的密碼。

長度下限: 8 個字元

長度上限: 123 個字元

複雜性需求:需要滿足下列 4 個條件中的 3 個
字元較低
具有大字元
具有數位
具有特殊字元 (Regex match [\W_])

不允許的值: “abc@123”、“P@$$w 0rd”、“P@ssw0rd”、“P@ssword123”、“Pa$$word”、“pass@word1”、“Password!”、“Password1”、“Password22”、“iloveyou!”
string

Constraints:
敏感性值。 以安全參數的形式傳入。
adminUsername 指定系統管理員帳戶的名稱。

限制: 不能以 “” 結尾。

不允許的值: “administrator”、“admin”、“user”、“user1”、“test”、“user2”、“test1”、“user3”、“admin1”、“1” “123”、“a”、“actuser”、“adm”、“admin2”、“aspnet”、“backup”、“console”、“david”、“guest”、“john”、“owner”、“root”、“server”、“sql”、“support”、“support_388945a0”、“sys”、“test2”、“test3”、“user4”、“user5”。

最小長度: 1 個字元

長度上限: 20 個字元
字串 (必要)
enableCSIProxy 是否要啟用 CSI Proxy。 欲了解更多 CSI 代理的詳細資訊,請參閱 CSI 代理 GitHub repo。 bool
gmsaProfile 受控叢集中的 Windows gMSA 配置檔。 WindowsGmsaProfile
licenseType 要用於 Windows VM 的授權類型。 詳情請參見 Azure 混合用戶優勢。 'None'
'Windows_Server'

ManagedClusterWorkloadAutoScalerProfile

Name Description Value
keda 適用於工作負載自動調整程式配置檔的KEDA (Kubernetes 事件驅動自動調整) 設定。 ManagedClusterWorkloadAutoScalerProfileKeda
verticalPodAutoscaler 工作負載自動調整程式設定檔的 VPA (垂直 Pod 自動調整程式) 設定。 ManagedClusterWorkloadAutoScalerProfileVerticalPodAutoscaler

ManagedClusterWorkloadAutoScalerProfileKeda

Name Description Value
enabled 是否要啟用 KEDA。 布林 (必要)

ManagedClusterWorkloadAutoScalerProfileVerticalPodAutoscaler

Name Description Value
addonAutoscaling 是否啟用 VPA 附加元件,並設定為調整 AKS 管理的附加元件。 'Disabled'
'Enabled'
enabled 是否要啟用 VPA。 預設值為 False。 布林 (必要)

ManagedServiceIdentityUserAssignedIdentitiesValue

Name Description Value

ManualScaleProfile

Name Description Value
count 節點數目。 int
size AKS 在建立和調整時將使用的 VM 大小,例如 'Standard_E4s_v3'、'Standard_E16s_v3' 或 'Standard_D16s_v5'。 字串

節點破壞剖面

Name Description Value
nodeDisruptionPolicy 政策設定,允許需要節點重映像並觸發重新部署的特定操作。 例如,有些操作,例如更新 .properties 的檔案。在現有受管理叢集上設置 ManagedClusterSecurityProfile.customCATrustCertificates 欄位,觸發節點的滾動更新。 此設定允許控制何時接受此類更新。 預設是「允許」。 完整涵蓋作業清單請參見 aka.ms/aks/nodedisruptionpolicy」。 '允許'
「允許維護期間」
'阻止'

NvidiaGPUProfile

Name Description Value
駕駛模式 NVIDIA GPU 資源配置模式。 DevicePlugin 會安裝 NVIDIA
Kubernetes 裝置外掛。 DRA 安裝 NVIDIA DRA 驅動程式。
「裝置插件」
「DRA」
管理模式 管理式GPU體驗會在GPU驅動程式之上安裝額外元件,例如資料中心GPU管理器(DCGM)指標以監控。 想了解更多安裝內容,請參考 aka.ms/aks/managed-gpu。 'Managed'
'Unmanaged'
mig策略 設定用於管理型 MIG 支援的 MIG(多實例 GPU)策略。 欲了解更多不同策略資訊,請造訪 aka.ms/aks/managed-gpu。 未指定時,預設為無。 “喜憂參半”
'None'
'Single'

PortRange

Name Description Value
portEnd 範圍中包含的最大埠。 它的範圍應從 1 到 65535,且大於或等於 portStart。 int

Constraints:
最小值 = 1
最大值 = 65535
portStart 範圍中包含的最小埠。 它的範圍應從 1 到 65535,且小於或等於 portEnd。 int

Constraints:
最小值 = 1
最大值 = 65535
通訊協定 埠的網路通訊協定。 'TCP'
'UDP'

PowerState

Name Description Value
字碼 告知叢集是否正在執行或已停止 'Running'
'Stopped'

PreparedImageSpecificationProfile

Name Description Value
preparedImageSpecificationId 準備好的影像規範資源的資源 ID。 這可以包含一個版本。 省略該版本將使用最新版本的已準備影像規範。 字串

PrivateLinkResource

Name Description Value
groupId 資源的群組標識碼。 字串
id private link 資源的 ID。 字串
name private link 資源的名稱。 詳情請參見 命名規則 。 字串
requiredMembers 資源的 RequiredMembers string[]
型別 資源類型。 字串

ResourceReference

Name Description Value
id 完全合格的 Azure 資源 ID。 字串

ScaleProfile

Name Description Value
自動縮放 如何自動調整預先定義大小範圍內的 VirtualMachines 代理程式集區規格。
每個配置檔針對特定的虛擬機 SKU 進行獨立評估。
跨設定檔的縮放決策由叢集自動縮放擴展器控制,
可透過 ManagedCluster.properties.autoScalerProfile.expander.
AutoScaleProfile[]
manual 如何將 VirtualMachines 代理程式集區調整為固定大小的規格。 ManualScaleProfile[]

SchedulerInstanceProfile

Name Description Value
schedulerConfigMode 由 AKS 管理的排程器使用。 'Default'
'ManagedByCRD'

SchedulerProfile

Name Description Value
上游 與上游變體 kube-scheduler 相關的設定檔(https://github.com/kubernetes/kubernetes/tree/master/pkg/scheduler)。 SchedulerInstanceProfile

ServiceAccountImagePullProfile

Name Description Value
defaultManagedIdentityId 選擇性。 叢集層級用於影像拉取的預設管理身份資源 ID。 設定時,若 Pod 的服務帳號未明確指定拉取圖片的身份,則使用此身份。 若未設定且服務帳號層級未指定身份,映像檔將透過匿名驗證被拉取。 字串
enabled 表示是否啟用了基於服務帳號的映像拉取,此時需要身份綁定才能使用受管理身份進行認證。 如需詳細資訊,請參閱https://aka.ms/aks/identity-binding-docs。 bool

ServiceMeshProfile

Name Description Value
istio Istio 服務網格設定。 IstioServiceMesh
mode 服務網格的模式。 'Disabled'
'Istio'(必填)

軟驅逐寬限期

Name Description Value
記憶體可用 memoryAvailable 軟驅逐訊號的寬限期,以 Go 風格的持續時間字串表示(例如 '30s', '1m30s')。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 必須大於或等於「30」分。 預設是「30多」。 字串
nodeFsAvailable nodeFsAvailable 軟驅逐訊號的寬限期,以 Go 風格的持續時間字串表示(例如 '30s', '1m30s')。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 必須大於或等於「30」分。 預設是「2m」。 字串
nodeFsInodesFree nodeFsInodesFree 軟驅逐訊號的寬限期,以 Go 風格的持續時間字串表示(例如 '30s', '1m30s')。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 必須大於或等於「30」分。 預設是「2m」。 字串

軟驅逐門檻

Name Description Value
記憶體可用 軟莢艙被觸發的可用記憶體閾值。 接受絕對值(例如「500英里」)或百分比值(例如「5%」)。 絕對最低距離為100英里;最低百分比為2%。 預設採用基於容量的階梯:500Mi 用於 <=8GiB,750Mi 為 16GiB,1024Mi(1Gi)為 >=32GiB。 也必須大於有效 hardEvictionThreshold.memoryAvailable。 字串
nodeFsAvailable 軟莢莢被觸發的可用節點檔案系統空間閾值。 接受絕對值(例如「1Gi」)或百分比值(例如「10%」)。 預設是「12%」。 必須大於或等於 10%,且大於有效 hardEvictionThreshold.nodeFsAvailable。 字串
nodeFsInodesFree 節點檔案系統中可用 inode 的門檻,低於此閾值會觸發軟莢驅逐。 接受絕對 inode 計數(例如「100000」)或百分比值(例如「5%」)。 預設是「7%」。 百分比值必須大於或等於 5%,且大於有效 hardEvictionThreshold.nodeFsInodesFree。 字串

SysctlConfig

Name Description Value
fsAioMaxNr Sysctl 設定 fs.aio-max-nr。 int
fsFileMax Sysctl 設定 fs.file-max。 int
fsInotifyMaxUserWatches Sysctl 設定fs.inotify.max_user_watches。 int
fsNrOpen Sysctl 設定fs.nr_open。 int
kernelThreadsMax Sysctl 設定 kernel.threads-max。 int
netCoreNetdevMaxBacklog Sysctl 設定net.core.netdev_max_backlog。 int
netCoreOptmemMax Sysctl 設定net.core.optmem_max。 int
netCoreRmemDefault Sysctl 設定net.core.rmem_default。 int
netCoreRmemMax Sysctl 設定net.core.rmem_max。 int
netCoreSomaxconn Sysctl 設定 net.core.somaxconn。 int
netCoreWmemDefault Sysctl 設定net.core.wmem_default。 int
netCoreWmemMax Sysctl 設定net.core.wmem_max。 int
netIpv4IpLocalPortRange Sysctl 設定net.ipv4.ip_local_port_range。 字串
netIpv4NeighDefaultGcThresh1 Sysctl 設定net.ipv4.neigh.default.gc_thresh1。 int
netIpv4NeighDefaultGcThresh2 Sysctl 設定net.ipv4.neigh.default.gc_thresh2。 int
netIpv4NeighDefaultGcThresh3 Sysctl 設定net.ipv4.neigh.default.gc_thresh3。 int
netIpv4TcpFinTimeout Sysctl 設定net.ipv4.tcp_fin_timeout。 int
netIpv4TcpkeepaliveIntvl Sysctl 設定net.ipv4.tcp_keepalive_intvl。 int

Constraints:
最小值 = 10
最大值 = 90
netIpv4TcpKeepaliveProbes Sysctl 設定net.ipv4.tcp_keepalive_probes。 int
netIpv4TcpKeepaliveTime Sysctl 設定net.ipv4.tcp_keepalive_time。 int
netIpv4TcpMaxSynBacklog Sysctl 設定net.ipv4.tcp_max_syn_backlog。 int
netIpv4TcpMaxTwBuckets Sysctl 設定net.ipv4.tcp_max_tw_buckets。 int
netIpv4TcpTwReuse Sysctl 設定net.ipv4.tcp_tw_reuse。 bool
netNetfilterNfConntrackBuckets Sysctl 設定net.netfilter.nf_conntrack_buckets。 int

Constraints:
最小值 = 65536
最大值 = 524288
netNetfilterNfConntrackMax Sysctl 設定net.netfilter.nf_conntrack_max。 int

Constraints:
最小值 = 131072
最大值 = 2097152
vmMaxMapCount Sysctl 設定vm.max_map_count。 int
vmSwappiness Sysctl 設定 vm.swappiness。 int
vmVfsCachePressure Sysctl 設定vm.vfs_cache_pressure。 int

TrackedResourceTags

Name Description Value

UpgradeOverrideSettings

Name Description Value
forceUpgrade 是否要強制升級叢集。 請注意,此選項會指示升級作業略過升級保護,例如檢查已淘汰的 API 使用量。 請謹慎啟用此選項。 bool
until 直到覆寫生效為止。 請注意,這隻會符合升級的開始時間,即使升級 until 繼續進行時到期,升級的有效性也不會變更。 預設不會設定此欄位。 必須設定覆寫才會生效。 字串

UserAssignedIdentity

Name Description Value
clientId 使用者指派身分識別的用戶端標識碼。 字串
objectId 使用者指派身分識別的物件標識碼。 字串
resourceId 使用者指派身分識別的資源標識碼。 字串

VirtualMachineNodes

Name Description Value
count 節點數目。 int
size 用來裝載此節點群組之代理程式的 VM 大小。 字串

VirtualMachinesProfile

Name Description Value
級別 如何調整 VirtualMachines 代理程式集區的規格。 ScaleProfile

WindowsGmsaProfile

Name Description Value
dnsServer 指定 Windows gMSA 的 DNS 伺服器。

如果您已在用來建立受控叢集的 vnet 中設定 DNS 伺服器,請將它設定為空白。
字串
enabled 是否要啟用 Windows gMSA。 指定是否要在受控叢集中啟用 Windows gMSA。 bool
rootDomainName 指定 Windows gMSA 的根功能變數名稱。

如果您已在用來建立受控叢集的 vnet 中設定 DNS 伺服器,請將它設定為空白。
字串

ARM 樣本資源定義

managedClusters 資源類型可以使用目標作業來部署:

使用範例

Azure Quickstart templates

以下的 Azure 快速起始範本部署此資源類型。

Template Description
AKS 叢集,包含 NAT 閘道和 Application Gateway

部署至Azure
本範例展示了如何部署一個 AKS 叢集,NAT 閘道用於出站連線,使用 Application Gateway 進行入站連線。
AKS 叢集搭配 Application Gateway 入口控制器

部署至Azure
本範例展示了如何部署包含 Application Gateway、Application Gateway Ingress Controller、Azure Container Registry、Log Analytics 及 金鑰保存庫 的 AKS 叢集
Azure 貨櫃服務(AKS)

部署至Azure
Deploy a managed cluster with Azure Container Service (AKS) using Azure Linux container hosts
Azure 貨櫃服務(AKS)

部署至Azure
Deploy a managed cluster with Azure Container Service (AKS)
Azure 貨櫃服務(AKS)配備 Helm

部署至Azure
Deploy a managed cluster with Azure Container Service (AKS) with Helm
Azure Kubernetes Service (AKS)

部署至Azure
Deploying a managed cluster with Azure Kubernetes Service (AKS) using Azure Linux with OS Guard
Azure Kubernetes Service (AKS)

部署至Azure
Deploys a managed Kubernetes cluster through Azure Kubernetes Service (AKS)
Azure Machine Learning端對端安全設置

部署至Azure
這組 Bicep 範本示範如何在安全環境中端對端設定 Azure Machine Learning。 此參考實作包括工作區、計算叢集、計算實例和附加的私人 AKS 叢集。
Azure Machine Learning端對端安全設定(舊有)

部署至Azure
這組 Bicep 範本示範如何在安全環境中端對端設定 Azure Machine Learning。 此參考實作包括工作區、計算叢集、計算實例和附加的私人 AKS 叢集。
CI/CD 在 Azure 容器服務(AKS)上使用 Jenkins

部署至Azure
容器可讓您輕鬆地持續建置和部署應用程式。 透過在 Azure Container Service 中使用 Kubernetes 協調這些容器的部署,你可以實現可複製且易於管理的容器叢集。 藉由設定持續組建來產生容器映像和協調流程,您可以提高部署的速度和可靠性。
建立私人 AKS 叢集

部署至Azure
此範例展示了如何在virtual network中建立私有的 AKS 叢集,並搭配跳板虛擬機。
建立一個私有 AKS 叢集,並設置公共 DNS 區域

部署至Azure
此範例示範如何使用公用 DNS 區域部署私人 AKS 叢集。
用 Prometheus 和 Grafana 用 privae 連結

部署至Azure
這將建立 Azure grafana、AKS,並在 Azure Kubernetes Service(AKS)叢集上安裝 Prometheus,一個開源的監控與警示工具包。 接著你使用 Azure 受控 Grafana 的受控私人端點連接到這個 Prometheus 伺服器,並在 Grafana 儀表板中顯示 Prometheus 資料
部署管理型Kubernetes Cluster (AKS)

部署至Azure
此 ARM 範本展示了將具備先進網路功能的 AKS 實例部署至現有 virtual network 中。 此外,所選的服務主體會針對包含 AKS 叢集的子網指派網路參與者角色。
部署一個管理型 Kubernetes 叢集,使用 AAD (AKS)

部署至Azure
此 ARM 範本展示了將具備先進網路功能的 AKS 實例部署至現有 virtual network 及 Azure AD 整數系統。 此外,所選的服務主體會針對包含 AKS 叢集的子網指派網路參與者角色。
部署 AKS 叢集以支援 Azure ML

部署至Azure
此範本允許您部署符合企業標準的 AKS 叢集,並可附加至 Azure ML
min.io Azure 閘道

部署至Azure
完全私有的 min.io Azure Gateway 部署,提供符合 S3 規範的 storage API,並由 blob storage

資源格式

若要建立 Microsoft.ContainerService/managedClusters 資源,請將下列 JSON 新增至範本。

{
  "type": "Microsoft.ContainerService/managedClusters",
  "apiVersion": "2026-06-02-preview",
  "name": "string",
  "extendedLocation": {
    "name": "string",
    "type": "string"
  },
  "identity": {
    "delegatedResources": {
      "{customized property}": {
        "location": "string",
        "referralResource": "string",
        "resourceId": "string",
        "tenantId": "string"
      }
    },
    "type": "string",
    "userAssignedIdentities": {
      "{customized property}": {
      }
    }
  },
  "kind": "string",
  "location": "string",
  "properties": {
    "aadProfile": {
      "adminGroupObjectIDs": [ "string" ],
      "clientAppID": "string",
      "enableAzureRBAC": "bool",
      "managed": "bool",
      "serverAppID": "string",
      "serverAppSecret": "string",
      "tenantID": "string"
    },
    "addonProfiles": {
      "{customized property}": {
        "config": {
          "{customized property}": "string"
        },
        "enabled": "bool"
      }
    },
    "agentPoolProfiles": [
      {
        "artifactStreamingProfile": {
          "enabled": "bool"
        },
        "availabilityZones": [ "string" ],
        "capacityReservationGroupID": "string",
        "count": "int",
        "creationData": {
          "sourceResourceId": "string"
        },
        "enableAutoScaling": "bool",
        "enableEncryptionAtHost": "bool",
        "enableFIPS": "bool",
        "enableNodePublicIP": "bool",
        "enableOSDiskFullCaching": "bool",
        "enableUltraSSD": "bool",
        "gatewayProfile": {
          "publicIPPrefixSize": "int"
        },
        "gpuInstanceProfile": "string",
        "gpuProfile": {
          "driver": "string",
          "driverType": "string",
          "nvidia": {
            "driverMode": "string",
            "managementMode": "string",
            "migStrategy": "string"
          }
        },
        "hostGroupID": "string",
        "kubeletConfig": {
          "allowedUnsafeSysctls": [ "string" ],
          "containerLogMaxFiles": "int",
          "containerLogMaxSizeMB": "int",
          "cpuCfsQuota": "bool",
          "cpuCfsQuotaPeriod": "string",
          "cpuManagerPolicy": "string",
          "evictionMaxPodGracePeriodInSeconds": "int",
          "failSwapOn": "bool",
          "hardEvictionThreshold": {
            "memoryAvailable": "string",
            "nodeFsAvailable": "string",
            "nodeFsInodesFree": "string"
          },
          "imageGcHighThreshold": "int",
          "imageGcLowThreshold": "int",
          "kubeReserved": {
            "cpuMillicores": "int",
            "memoryMB": "int"
          },
          "podMaxPids": "int",
          "seccompDefault": "string",
          "softEvictionGracePeriod": {
            "memoryAvailable": "string",
            "nodeFsAvailable": "string",
            "nodeFsInodesFree": "string"
          },
          "softEvictionThreshold": {
            "memoryAvailable": "string",
            "nodeFsAvailable": "string",
            "nodeFsInodesFree": "string"
          },
          "topologyManagerPolicy": "string"
        },
        "kubeletDiskType": "string",
        "linuxOSConfig": {
          "swapFileSizeMB": "int",
          "sysctls": {
            "fsAioMaxNr": "int",
            "fsFileMax": "int",
            "fsInotifyMaxUserWatches": "int",
            "fsNrOpen": "int",
            "kernelThreadsMax": "int",
            "netCoreNetdevMaxBacklog": "int",
            "netCoreOptmemMax": "int",
            "netCoreRmemDefault": "int",
            "netCoreRmemMax": "int",
            "netCoreSomaxconn": "int",
            "netCoreWmemDefault": "int",
            "netCoreWmemMax": "int",
            "netIpv4IpLocalPortRange": "string",
            "netIpv4NeighDefaultGcThresh1": "int",
            "netIpv4NeighDefaultGcThresh2": "int",
            "netIpv4NeighDefaultGcThresh3": "int",
            "netIpv4TcpFinTimeout": "int",
            "netIpv4TcpkeepaliveIntvl": "int",
            "netIpv4TcpKeepaliveProbes": "int",
            "netIpv4TcpKeepaliveTime": "int",
            "netIpv4TcpMaxSynBacklog": "int",
            "netIpv4TcpMaxTwBuckets": "int",
            "netIpv4TcpTwReuse": "bool",
            "netNetfilterNfConntrackBuckets": "int",
            "netNetfilterNfConntrackMax": "int",
            "vmMaxMapCount": "int",
            "vmSwappiness": "int",
            "vmVfsCachePressure": "int"
          },
          "transparentHugePageDefrag": "string",
          "transparentHugePageEnabled": "string"
        },
        "localDNSProfile": {
          "kubeDNSOverrides": {
            "{customized property}": {
              "cacheDurationInSeconds": "int",
              "forwardDestination": "string",
              "forwardPolicy": "string",
              "maxConcurrent": "int",
              "protocol": "string",
              "queryLogging": "string",
              "serveStale": "string",
              "serveStaleDurationInSeconds": "int"
            }
          },
          "mode": "string",
          "vnetDNSOverrides": {
            "{customized property}": {
              "cacheDurationInSeconds": "int",
              "forwardDestination": "string",
              "forwardPolicy": "string",
              "maxConcurrent": "int",
              "protocol": "string",
              "queryLogging": "string",
              "serveStale": "string",
              "serveStaleDurationInSeconds": "int"
            }
          }
        },
        "maxCount": "int",
        "maxPods": "int",
        "messageOfTheDay": "string",
        "minCount": "int",
        "mode": "string",
        "name": "string",
        "networkProfile": {
          "allowedHostPorts": [
            {
              "portEnd": "int",
              "portStart": "int",
              "protocol": "string"
            }
          ],
          "applicationSecurityGroups": [ "string" ],
          "dranet": {
            "mode": "string"
          },
          "nodePublicIPPrefixIDs": [ "string" ],
          "nodePublicIPTags": [
            {
              "ipTagType": "string",
              "tag": "string"
            }
          ],
          "secondaryNetworkInterfaces": [
            {
              "enableAcceleratedNetworking": "bool",
              "publicIPAddressConfiguration": {
                "ipTags": [
                  {
                    "ipTagType": "string",
                    "tag": "string"
                  }
                ],
                "publicIPAddressVersion": "string",
                "publicIPPrefixID": "string"
              },
              "type": "string",
              "vnetSubnetId": "string"
            }
          ]
        },
        "nodeImageVersion": "string",
        "nodeInitializationTaints": [ "string" ],
        "nodeLabels": {
          "{customized property}": "string"
        },
        "nodePublicIPPrefixID": "string",
        "nodeTaints": [ "string" ],
        "orchestratorVersion": "string",
        "osDiskSizeGB": "int",
        "osDiskType": "string",
        "osSKU": "string",
        "osType": "string",
        "podIPAllocationMode": "string",
        "podSubnetID": "string",
        "powerState": {
          "code": "string"
        },
        "preparedImageSpecificationProfile": {
          "preparedImageSpecificationId": "string"
        },
        "proximityPlacementGroupID": "string",
        "scaleDownMode": "string",
        "scaleSetEvictionPolicy": "string",
        "scaleSetPriority": "string",
        "securityProfile": {
          "enableSecureBoot": "bool",
          "enableVTPM": "bool",
          "sshAccess": "string"
        },
        "spotMaxPrice": "int",
        "status": {
        },
        "tags": {
          "{customized property}": "string"
        },
        "type": "string",
        "upgradeSettings": {
          "drainTimeoutInMinutes": "int",
          "maxBlockedNodes": "string",
          "maxSurge": "string",
          "maxUnavailable": "string",
          "nodeSoakDurationInMinutes": "int",
          "undrainableNodeBehavior": "string"
        },
        "upgradeSettingsBlueGreen": {
          "batchSoakDurationInMinutes": "int",
          "drainBatchSize": "string",
          "drainTimeoutInMinutes": "int",
          "finalSoakDurationInMinutes": "int"
        },
        "upgradeStrategy": "string",
        "virtualMachineNodesStatus": [
          {
            "count": "int",
            "size": "string"
          }
        ],
        "virtualMachinesProfile": {
          "scale": {
            "autoscale": [
              {
                "maxCount": "int",
                "minCount": "int",
                "size": "string"
              }
            ],
            "manual": [
              {
                "count": "int",
                "size": "string"
              }
            ]
          }
        },
        "vmSize": "string",
        "vnetSubnetID": "string",
        "windowsProfile": {
          "disableOutboundNat": "bool"
        },
        "workloadRuntime": "string"
      }
    ],
    "aiToolchainOperatorProfile": {
      "enabled": "bool"
    },
    "apiServerAccessProfile": {
      "authorizedIPRanges": [ "string" ],
      "disableRunCommand": "bool",
      "enablePrivateCluster": "bool",
      "enablePrivateClusterPublicFQDN": "bool",
      "enableVnetIntegration": "bool",
      "privateDNSZone": "string",
      "subnetId": "string"
    },
    "autoScalerProfile": {
      "balance-similar-node-groups": "string",
      "daemonset-eviction-for-empty-nodes": "bool",
      "daemonset-eviction-for-occupied-nodes": "bool",
      "expander": "string",
      "ignore-daemonsets-utilization": "bool",
      "max-empty-bulk-delete": "string",
      "max-graceful-termination-sec": "string",
      "max-node-provision-time": "string",
      "max-total-unready-percentage": "string",
      "new-pod-scale-up-delay": "string",
      "ok-total-unready-count": "string",
      "scale-down-delay-after-add": "string",
      "scale-down-delay-after-delete": "string",
      "scale-down-delay-after-failure": "string",
      "scale-down-unneeded-time": "string",
      "scale-down-unready-time": "string",
      "scale-down-utilization-threshold": "string",
      "scan-interval": "string",
      "skip-nodes-with-local-storage": "string",
      "skip-nodes-with-system-pods": "string"
    },
    "autoUpgradeProfile": {
      "nodeOSUpgradeChannel": "string",
      "upgradeChannel": "string"
    },
    "azureMonitorProfile": {
      "appMonitoring": {
        "autoInstrumentation": {
          "enabled": "bool"
        },
        "openTelemetryLogsAndTraces": {
          "enabled": "bool",
          "grpcPort": "int",
          "httpPort": "int"
        },
        "openTelemetryMetrics": {
          "enabled": "bool",
          "grpcPort": "int",
          "httpPort": "int"
        }
      },
      "containerInsights": {
        "containerNetworkLogs": "string",
        "disablePrometheusMetricsScraping": "bool",
        "enabled": "bool",
        "logAnalyticsWorkspaceResourceId": "string",
        "syslogPort": "int"
      },
      "metrics": {
        "controlPlane": {
          "enabled": "bool"
        },
        "enabled": "bool",
        "kubeStateMetrics": {
          "metricAnnotationsAllowList": "string",
          "metricLabelsAllowlist": "string"
        }
      }
    },
    "bootstrapProfile": {
      "artifactSource": "string",
      "containerRegistryId": "string"
    },
    "controlPlaneScalingProfile": {
      "scalingSize": "string"
    },
    "creationData": {
      "sourceResourceId": "string"
    },
    "disableLocalAccounts": "bool",
    "diskEncryptionSetID": "string",
    "dnsPrefix": "string",
    "enableFIPS": "bool",
    "enableNamespaceResources": "bool",
    "enableNodeHardening": "bool",
    "enableRBAC": "bool",
    "fqdnSubdomain": "string",
    "healthMonitorProfile": {
      "enableContinuousControlPlaneAndAddonMonitor": "bool",
      "enableOnDemandMonitor": "bool"
    },
    "hostedSystemProfile": {
      "enabled": "bool",
      "nodeSubnetID": "string",
      "systemNodeSubnetID": "string"
    },
    "httpProxyConfig": {
      "enabled": "bool",
      "httpProxy": "string",
      "httpsProxy": "string",
      "noProxy": [ "string" ],
      "trustedCa": "string"
    },
    "identityProfile": {
      "{customized property}": {
        "clientId": "string",
        "objectId": "string",
        "resourceId": "string"
      }
    },
    "ingressProfile": {
      "applicationLoadBalancer": {
        "enabled": "bool"
      },
      "gatewayAPI": {
        "installation": "string"
      },
      "webAppRouting": {
        "defaultDomain": {
          "enabled": "bool"
        },
        "dnsZoneResourceIds": [ "string" ],
        "enabled": "bool",
        "gatewayAPIImplementations": {
          "appRoutingIstio": {
            "mode": "string"
          }
        },
        "nginx": {
          "defaultIngressControllerType": "string"
        }
      }
    },
    "kubernetesVersion": "string",
    "linuxProfile": {
      "adminUsername": "string",
      "ssh": {
        "publicKeys": [
          {
            "keyData": "string"
          }
        ]
      }
    },
    "metricsProfile": {
      "costAnalysis": {
        "enabled": "bool"
      }
    },
    "networkProfile": {
      "advancedNetworking": {
        "enabled": "bool",
        "observability": {
          "enabled": "bool"
        },
        "performance": {
          "accelerationMode": "string"
        },
        "security": {
          "advancedNetworkPolicies": "string",
          "enabled": "bool",
          "transitEncryption": {
            "type": "string"
          }
        }
      },
      "bastionProfile": {
        "enabled": "bool",
        "publicIpAddressId": "string",
        "scaleUnits": "int",
        "sku": "string"
      },
      "dnsServiceIP": "string",
      "ipFamilies": [ "string" ],
      "kubeProxyConfig": {
        "enabled": "bool",
        "ipvsConfig": {
          "scheduler": "string",
          "tcpFinTimeoutSeconds": "int",
          "tcpTimeoutSeconds": "int",
          "udpTimeoutSeconds": "int"
        },
        "mode": "string"
      },
      "loadBalancerProfile": {
        "allocatedOutboundPorts": "int",
        "backendPoolType": "string",
        "clusterServiceLoadBalancerHealthProbeMode": "string",
        "enableMultipleStandardLoadBalancers": "bool",
        "idleTimeoutInMinutes": "int",
        "managedOutboundIPs": {
          "count": "int",
          "countIPv6": "int"
        },
        "outboundIPPrefixes": {
          "publicIPPrefixes": [
            {
              "id": "string"
            }
          ]
        },
        "outboundIPs": {
          "publicIPs": [
            {
              "id": "string"
            }
          ]
        }
      },
      "loadBalancerSku": "string",
      "natGatewayId": "string",
      "natGatewayProfile": {
        "idleTimeoutInMinutes": "int",
        "managedOutboundIPProfile": {
          "count": "int",
          "countIPv6": "int"
        },
        "outboundIPPrefixes": {
          "publicIPPrefixes": [ "string" ]
        },
        "outboundIPs": {
          "publicIPs": [ "string" ]
        },
        "sku": "string"
      },
      "networkDataplane": "string",
      "networkMode": "string",
      "networkPlugin": "string",
      "networkPluginMode": "string",
      "networkPolicy": "string",
      "outboundType": "string",
      "podCidr": "string",
      "podCidrs": [ "string" ],
      "podLinkLocalAccess": "string",
      "serviceCidr": "string",
      "serviceCidrs": [ "string" ],
      "staticEgressGatewayProfile": {
        "enabled": "bool"
      }
    },
    "nodeDisruptionProfile": {
      "nodeDisruptionPolicy": "string"
    },
    "nodeProvisioningProfile": {
      "defaultNodePools": "string",
      "mode": "string"
    },
    "nodeResourceGroup": "string",
    "nodeResourceGroupProfile": {
      "restrictionLevel": "string"
    },
    "oidcIssuerProfile": {
      "enabled": "bool"
    },
    "podIdentityProfile": {
      "allowNetworkPluginKubenet": "bool",
      "enabled": "bool",
      "userAssignedIdentities": [
        {
          "bindingSelector": "string",
          "identity": {
            "clientId": "string",
            "objectId": "string",
            "resourceId": "string"
          },
          "name": "string",
          "namespace": "string"
        }
      ],
      "userAssignedIdentityExceptions": [
        {
          "name": "string",
          "namespace": "string",
          "podLabels": {
            "{customized property}": "string"
          }
        }
      ]
    },
    "privateLinkResources": [
      {
        "groupId": "string",
        "id": "string",
        "name": "string",
        "requiredMembers": [ "string" ],
        "type": "string"
      }
    ],
    "publicNetworkAccess": "string",
    "schedulerProfile": {
      "upstream": {
        "schedulerConfigMode": "string"
      }
    },
    "securityProfile": {
      "azureKeyVaultKms": {
        "enabled": "bool",
        "keyId": "string",
        "keyVaultNetworkAccess": "string",
        "keyVaultResourceId": "string"
      },
      "customCATrustCertificates": [ {} ],
      "defender": {
        "logAnalyticsWorkspaceResourceId": "string",
        "securityGating": {
          "allowSecretAccess": "bool",
          "enabled": "bool",
          "identities": [
            {
              "azureContainerRegistry": "string",
              "identity": {
                "clientId": "string",
                "objectId": "string",
                "resourceId": "string"
              }
            }
          ]
        },
        "securityMonitoring": {
          "enabled": "bool"
        }
      },
      "imageCleaner": {
        "enabled": "bool",
        "intervalHours": "int"
      },
      "imageIntegrity": {
        "enabled": "bool"
      },
      "kubernetesResourceObjectEncryptionProfile": {
        "infrastructureEncryption": "string"
      },
      "nodeRestriction": {
        "enabled": "bool"
      },
      "serviceAccountImagePullProfile": {
        "defaultManagedIdentityId": "string",
        "enabled": "bool"
      },
      "workloadIdentity": {
        "enabled": "bool"
      }
    },
    "serviceMeshProfile": {
      "istio": {
        "certificateAuthority": {
          "plugin": {
            "certChainObjectName": "string",
            "certObjectName": "string",
            "keyObjectName": "string",
            "keyVaultId": "string",
            "rootCertObjectName": "string"
          }
        },
        "components": {
          "egressGateways": [
            {
              "enabled": "bool",
              "gatewayConfigurationName": "string",
              "name": "string",
              "namespace": "string"
            }
          ],
          "ingressGateways": [
            {
              "enabled": "bool",
              "mode": "string"
            }
          ],
          "proxyRedirectionMechanism": "string"
        },
        "revisions": [ "string" ]
      },
      "mode": "string"
    },
    "servicePrincipalProfile": {
      "clientId": "string",
      "secret": "string"
    },
    "status": {
    },
    "storageProfile": {
      "blobCSIDriver": {
        "enabled": "bool"
      },
      "diskCSIDriver": {
        "enabled": "bool"
      },
      "fileCSIDriver": {
        "enabled": "bool"
      },
      "snapshotController": {
        "enabled": "bool"
      }
    },
    "supportPlan": "string",
    "upgradeSettings": {
      "overrideSettings": {
        "forceUpgrade": "bool",
        "until": "string"
      }
    },
    "windowsProfile": {
      "adminPassword": "string",
      "adminUsername": "string",
      "enableCSIProxy": "bool",
      "gmsaProfile": {
        "dnsServer": "string",
        "enabled": "bool",
        "rootDomainName": "string"
      },
      "licenseType": "string"
    },
    "workloadAutoScalerProfile": {
      "keda": {
        "enabled": "bool"
      },
      "verticalPodAutoscaler": {
        "addonAutoscaling": "string",
        "enabled": "bool"
      }
    }
  },
  "sku": {
    "name": "string",
    "tier": "string"
  },
  "tags": {
    "{customized property}": "string"
  }
}

屬性值

Microsoft.ContainerService/managedClusters

Name Description Value
apiVersion API 版本 『2026-06-02-預覽』
extendedLocation 虛擬機的擴充位置。 ExtendedLocation
身分識別 如果已設定,則為受控叢集的身分識別。 ManagedClusterIdentity
kind 這主要用來在入口網站中針對不同類型公開不同的UI體驗 字串
位置 資源所在的地理位置 字串 (必要)
name 資源名稱 string

Constraints:
最小長度 = 1
最大長度 = 63
模式 = ^[a-zA-Z0-9]$|^[a-zA-Z0-9][-_a-zA-Z0-9]{0,61}[a-zA-Z0-9]$ (必要)
properties 受控叢集的屬性。 ManagedClusterProperties
sku 受控叢集 SKU。 ManagedClusterSKU
tags 資源標籤 標記名稱和值的字典。 請參考模板中的標籤
型別 資源類型 'Microsoft.ContainerService/managedClusters'

AdvancedNetworking

Name Description Value
enabled 表示啟用 AKS 叢集上可檢視性和安全性的進階網路功能。 當此設定為 true 時,除非明確停用,否則所有可檢視性和安全性功能都會設定為啟用。 如果未指定,則預設值為 false。 bool
可檢視性 可檢視性配置檔,可啟用具有歷程記錄內容的進階網路計量和流量記錄。 AdvancedNetworkingObservability
效能 設定檔可啟用使用 Azure CNI 由 Cilium 驅動的叢集的效能提升功能。 進階網路效能
安全性 安全性配置檔,以在 cilium 型叢集上啟用安全性功能。 AdvancedNetworkingSecurity

AdvancedNetworkingObservability

Name Description Value
enabled 表示在叢集上啟用進階網路可檢視性功能。 bool

進階網路效能

Name Description Value
加速模式 啟用進階網路加速選項。 這允許用戶使用 BPF 主機路由配置加速。 這只能透過 Cilium 資料平面啟用。 如果未指定,預設值為 None (無加速)。 加速模式可以在預先存在的叢集上變更。 詳細說明見https://aka.ms/acnsperformance “BpfVeth”
'None'

AdvancedNetworkingSecurity

Name Description Value
advancedNetworkPolicies 啟用高級網路策略。 這可讓用戶設定第 7 層網路原則(FQDN、HTTP、Kafka)。 原則本身必須透過 Cilium 網路原則資源進行設定,請參閱 https://docs.cilium.io/en/latest/security/policy/index.html。 這隻能在 cilium 型叢集上啟用。 如果未指定,如果 security.enabled 設定為 true,則預設值為 FQDN。 'FQDN'
'L7'
'None'
enabled 此功能可讓使用者根據 DNS (FQDN) 名稱來設定網路原則。 它只能在 cilium 型叢集上啟用。 如果未指定,則預設值為 false。 bool
transitEncryption 基於 Cilium 的集群的加密配置。 啟用后,Cilium 託管的 Pod 之間的所有流量在離開節點邊界時都將被加密。 AdvancedNetworkingSecurityTransitEncryption

AdvancedNetworkingSecurityTransitEncryption

Name Description Value
型別 配置 Pod 到 Pod 加密。 這隻能在 Cilium 型叢集上啟用。 如果未指定,預設值為 None。 「mTLS」
'None'
'WireGuard'

AgentPoolArtifactStreamingProfile

Name Description Value
enabled 成品串流可透過隨選映射載入,加速節點上容器的冷啟動。 若要使用這項功能,容器映像也必須在 ACR 上啟用成品串流。 如果未指定,則預設值為 false。 bool

AgentPoolBlueGreenUpgradeSettings

Name Description Value
batchSoakDurationInMinutes 清空一批節點後的浸泡持續時間,即清空一批節點後等待的時間量(以分鐘為單位),然後再繼續下一個批次。 如果未指定,則預設值為 15 分鐘。 int

Constraints:
最小值 = 0
最大值 = 1440
drainBatch大小 藍綠升級期間要批次清空的節點數目或百分比。 必須是非零數字。 這可以設定為整數(例如 '5')或百分比(例如 '50%')。 如果指定百分比,則它是起始升級作業的藍色節點總數百分比。 針對百分比,小數節點會四捨五入。 如果未指定,則預設值為 10%。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
drainTimeoutInMinutes 節點的清空逾時,即等待 Pod 收回和每個節點正常終止的時間量 (以分鐘為單位)。 此收回等候時間會接受等候 Pod 中斷預算。 如果超過這個時間,升級就會失敗。 如果未指定,則預設值為 30 分鐘。 int

Constraints:
最小值 = 1
最大值 = 1440
finalSoak持續時間在分鐘 節點集區的浸泡持續時間,即在移除舊節點之前,所有舊節點清空後等待的時間量 (以分鐘為單位)。 如果未指定,則預設值為 60 分鐘。 僅適用於藍綠升級策略。 int

Constraints:
最小值 = 0
最大值 = 10080

AgentPoolGatewayProfile

Name Description Value
publicIPPrefixSize 網關代理程式集區會為每個靜態輸出閘道建立一個公用IPPrefix的關聯,以提供公用輸出。 用戶應該選取公用IPPrefix的大小。 代理程式集區中的每個節點都會從IPPrefix指派一個IP。 因此,IPPrefix 大小會做為閘道代理程式集區大小的上限。 由於 Azure 公開 IPPrefix 大小限制,有效值範圍為 [28, 31](/31 = 2 節點/IP,/30 = 4 節點/IP,/29 = 8 節點/IP,/28 = 16 節點/IP)。 預設值為 31。 int

Constraints:
最小值 = 28
最大值 = 31

代理池網路介面

Name Description Value
enableAcceleratedNetworking 這個次要網卡是否啟用了加速網路。 若省略,則僅在代理池虛擬機 SKU 支援加速網路時,此設定才會自動為 true。 若驗證在不支援的 SKU 或 NIC 配置上啟用,則驗證將失敗。 bool
publicIPAddress配置 這個次要網卡的公共 IP 設定。 只有當 type 是 時 Standard才有效。 設定 publicIPAddressVersion 為為每個虛擬機的實例層級公共 IP 配置 NIC,然後可選擇性地以 ipTags 或 publicIPPrefixID來塑造。 若省略,則不會設定公共 IP。 閒置逾時是無法設定的。 如需詳細資訊,請參閱 https://aka.ms/aks/multi-nic AgentPoolNICPublicIPAddressConfiguration
型別 虛擬機上要配置的網卡類型。 “動態”
'Standard'
vnetSubnetId 將連接至次級網路介面的子網資源 ID。 當 type 是 Standard時 必須;必須是空字串(),""或當 是 type時省略。Dynamic 字串

AgentPoolNetworkProfile

Name Description Value
allowedHostPorts 允許 access 的埠範圍。 允許指定的範圍重疊。 PortRange[]
applicationSecurityGroups 應用程式安全組的標識碼,代理程式集區會在建立時產生關聯。 string[]
德拉內特 DRANET 代理池的設定。 DranetProfile
nodePublicIPPrefixIDs 節點公共 IP 前綴的資源 ID。 最多只能指定一個 IPv4 和一個 IPv6 前綴。 順序不重要;RP 則從參考資源的 publicIPAddressVersion 決定 IP 版本。 需要 enableNodePublicIP 在代理池上為真。 與頂層 nodePublicIPPrefixID 屬性互斥。 節點池建立後不可變。 要更改前綴,請刪除並重新建立節點池。 如需詳細資訊,請參閱 https://aka.ms/aks/ipv6-ilpip string[]
nodePublicIPTags 實例層級公用IP的IPTag。 IPTag[]
次要網路介面 代理池中每個虛擬機的次級網路介面設定。 每個條目都是一個範本:每個條目會在每個虛擬實例上配置一個實體網卡。 這些介面是在代理池建立時建立,且是不可變的。 清單長度必須小於網卡容量減去代理池虛擬機大小的 1(AKS 管理主要網卡)。 例如,Standard_D8a_v4虛擬機最多支援 4 個網卡,因此最多允許的次要介面數為 3 個。 對於混合 SKU VM 池,有效容量為所有 SKU 的最小值:count(次要網路介面)+ 1 <= min(maxNIC)。 如需詳細資訊,請參閱 https://aka.ms/aks/multi-nic 代理池網路介面[]

AgentPoolNICPublicIPAddressConfiguration

Name Description Value
ip標籤 IP 標籤要附加到該 NIC 分配的公共 IP。 每個標籤 ipTagType 必須是 FirstPartyUsage、 NetworkDomain或 RoutingPreference。 與 publicIPPrefixID互斥。 IPTag[]
publicIPAddress版本 為此網卡配置的公共 IP 版本。 必要條件:其存在是啟用公共 IP 配置的關鍵,因此空設定不會分配任何資料。 IPv4 是唯一被接受的值。 「IPv4」(必填)
publicIPPrefixID 公共 IP 前綴的資源 ID,用來擷取該網卡的公共 IP。 與 ipTags互斥。 字串

AgentPoolSecurityProfile

Name Description Value
enableSecureBoot 安全開機是受信任的啟動功能,可確保只有已簽署的作系統和驅動程式才能開機。 如需詳細資訊,請參閱 aka.ms/aks/trustedlaunch。 如果未指定,則預設值為 false。 bool
enableVTPM vTPM 是受信任的啟動功能,用於設定節點上本機所保留密鑰和度量的專用安全保存庫。 如需詳細資訊,請參閱 aka.ms/aks/trustedlaunch。 如果未指定,則預設值為 false。 bool
sshAccess 代理池的 SSH access 方法。 'Disabled'
“EntraId”
'LocalUser'

AgentPoolStatus

Name Description Value

AgentPoolUpgradeSettings

Name Description Value
drainTimeoutInMinutes 節點的耗盡超時。 等待收回 Pod 的時間量,以及每個節點的正常終止時間。 此收回等候時間會接受等候 Pod 中斷預算。 如果超過這個時間,升級就會失敗。 如果未指定,則預設值為 30 分鐘。 int

Constraints:
最小值 = 1
最大值 = 1440
maxBlockedNodes 當無法解析的節點行為為 Cordon 時,在代理程式集區中允許封鎖的額外節點數目或百分比上限。 這可以設定為整數(例如 '5')或百分比(例如 '50%')。 如果指定了百分比,則它是升級時代理程式集區大小總計的百分比。 針對百分比,小數節點會四捨五入。 如果未指定,預設值為 maxSurge。 這一律必須大於或等於 maxSurge。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
maxSurge 升級期間激增的節點數目或百分比上限。 這可以設定為整數(例如 '5')或百分比(例如 '50%')。 如果指定了百分比,則它是升級時代理程式集區大小總計的百分比。 針對百分比,小數節點會四捨五入。 如果未指定,則預設值為 10%。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
maxUnavailable 升級期間可以同時無法使用的節點數目或百分比上限。 這可以設定為整數(例如 '1')或百分比(例如 '5%')。 如果指定了百分比,則它是升級時代理程式集區大小總計的百分比。 針對百分比,小數節點會四捨五入。 如果未指定,則預設值為 0。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
nodeSoakDurationInMinutes 節點的soak持續時間。 清空節點並重新製作映射並移至下一個節點之前,等待的時間量(以分鐘為單位)。 如果未指定,則預設值為0分鐘。 int

Constraints:
最小值 = 0
最大值 = 30
undrainableNodeBehavior 定義升級期間無法透支節點的行為。 無法透支節點最常見的原因是 Pod 中斷預算 (PDB),但其他問題,例如 Pod 終止寬限期超過剩餘的個別節點清空逾時,或 Pod 仍在執行中狀態,也可能導致無法執行的節點。 'Cordon'
'Schedule'

AgentPoolWindowsProfile

Name Description Value
disableOutboundNat 是否在 Windows 節點中禁用 OutboundNAT。 預設值為 false。 只有在叢集 outboundType 是 NAT 閘道,且 Windows 代理程式集區未啟用節點公用 IP 時,才能停用輸出 NAT。 bool

AutoScaleProfile

Name Description Value
maxCount 指定大小的節點數目上限。 int
minCount 指定大小的節點數目下限。 int
size AKS 在建立和調整時將使用的 VM 大小,例如 'Standard_E4s_v3'、'Standard_E16s_v3' 或 'Standard_D16s_v5'。 字串

AzureKeyVaultKms

Name Description Value
enabled 是否啟用 Azure Key Vault 鍵管理服務。 默認值為 false。 bool
keyId Azure Key Vault key 的識別碼。 詳情請參見 key identifier format。 啟用 Azure Key Vault 金鑰管理服務時,此欄位為必填且必須為有效的金鑰識別碼。 當 Azure Key Vault 的金鑰管理服務被停用時,請保持欄位空。 字串
keyVaultNetworkAccess key vault的access網絡。 key vault的網絡access。 可能的值為 Public 和 Private。 Public 表示key vault允許所有網路的公開access。 Private 表示key vault會停用公共access並啟用private link。 預設值為 Public。 'Private'
'Public'
keyVaultResourceId key vault 的資源 ID。 當keyVaultNetworkAccess為 Private時,此字段是必要的,而且必須是有效的資源標識符。 當keyVaultNetworkAccess為 Public時,請將字段保留空白。 字串

堡壘簡介

Name Description Value
enabled 顯示是否啟用管理堡壘。 bool
公共 IpAddressId 與管理堡壘相關的公共 IP 位址的資源 ID。

在建立時提供時,管理堡壘會參考這個現有的公共 IP 位址,而不是建立新的。
所參考的公共 IP 位址必須與受管理叢集在同一訂閱和區域內。

若建立時未提供,AKS 會自動建立新的公開 IP 位址。

此欄位無法更新。 若要在建立後更改 IP 位址,請停用並重新啟用管理的堡壘,並使用新的公共 IP 位址。
字串
scaleUnits 管理堡壘的比例單位。 預設值為 2。 int

Constraints:
最小值 = 2
最大值 = 50
sku 管理堡壘的SKU。

僅支援標準版和高級版 SKU。
SKU 不允許降級。 要降級 SKU,請先停用再重新啟用管理堡壘並使用新的 SKU。

如需詳細資訊,請參閱 https://aka.ms/aks/BastionSKUs。
'Premium'
'Standard'

ClusterUpgradeSettings

Name Description Value
overrideSettings 覆寫的設定。 UpgradeOverrideSettings

ContainerServiceLinuxProfile

Name Description Value
adminUsername 要用於 Linux VM 的系統管理員用戶名稱。 string

Constraints:
模式 = ^[A-Za-z][-A-Za-z0-9_]*$ (必要)
ssh 這是針對在 Azure 上運行的 Linux 虛擬機的 SSH 配置。 ContainerServiceSshConfiguration (必需)

ContainerServiceNetworkProfile

Name Description Value
advancedNetworking 在叢集上啟用可檢視性和安全性功能套件的進階網路配置檔。 如需詳細資訊,請參閱 aka.ms/aksadvancednetworking。 AdvancedNetworking
堡壘簡介 與管理叢集相關的堡壘主機側寫。
如需詳細資訊,請參閱 https://aka.ms/aks/BastionConnect。
堡壘簡介
dnsServiceIP 指派給 Kubernetes DNS 服務的 IP 位址。 它必須位於 serviceCidr 中指定的 Kubernetes 服務地址範圍內。 string

Constraints:
圖案 = ^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$
ipFamilies 用來指定叢集可用IP版本的IP系列。 IP 系列可用來判斷單一堆疊或雙堆棧叢集。 對於單一堆棧,預期的值為IPv4。 針對雙堆棧,預期的值為IPv4和IPv6。 包含任何的字串數組:
'IPv4'
'IPv6'
kubeProxyConfig 保留 kube-proxy 的組態自定義。 未定義的任何值都會使用 kube-proxy 預設行為。 請參閱 https://v<version.docs.kubernetes.io/docs/reference/command-line-tools-reference/kube-proxy/ 版本,其中>版本<是以>主要版本<>次要版本<字串>表示。 Kubernetes 1.23 版會是 '1-23'。 ContainerServiceNetworkProfileKubeProxyConfig
loadBalancerProfile 叢集 load balancer 的設定檔。 ManagedClusterLoadBalancerProfile
loadBalancerSku 管理叢集的 load balancer sku。 默認值為 『standard』。 欲了解load balancer SKU 差異,請參見 Azure Load Balancer SKUs。 'basic'
「服務」
'standard'
natGatewayId 當 outboundType 為 'userAssignedNATGateway'(使用 StandardV2 公有 IP)時,NAT 閘道器用於叢集啟動時的Azure資源 ID,後端池類型為 podIP,負載平衡器類型為服務 SKU。 這個形式為:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/natGateways/{natGatewayName}'. 使用受管理的 NATGateway 時,這個欄位會自動填入。 如需詳細資訊,請參閱 https://aka.ms/aks/container-native-slb 字串
natGatewayProfile 叢集 NAT 閘道的配置檔。 ManagedClusterNATGatewayProfile
networkDataplane Kubernetes 叢集中所使用的網路數據平面。 「azure」
'cilium'
networkMode Azure CNI 所設定的網路模式。 如果 networkPlugin 不是 'azure',則無法指定這個功能。 'bridge'
'transparent'
networkPlugin 用於建置 Kubernetes 網路的網路外掛程式。 「azure」
'kubenet'
'none'
networkPluginMode 網路外掛程式應該使用的模式。 'overlay'
networkPolicy 用於建置 Kubernetes 網路的網路原則。 「azure」
'calico'
'cilium'
'none'
outboundType 輸出 (輸出) 路由方法。 這隻能在叢集建立期間設定,且稍後無法變更。 更多資訊請參見出口類型。 'loadBalancer'
'managedNATGateway'
'none'
'userAssignedNATGateway'
'userDefinedRouting'
podCidr 使用 kubenet 時,要從中指派 Pod IP 的 CIDR 表示法 IP 範圍。 string

Constraints:
圖案 = ^([0-9]{1,3}\.){3}[0-9]{1,3}(\/([0-9]|[1-2][0-9]|3[0-2]))?$
podCidrs 要從中指派 Pod IP 的 CIDR 表示法IP範圍。 單一堆棧網路應該會有一個 IPv4 CIDR。 兩個 CIDR,每個 IP 系列一個 (IPv4/IPv6),預期雙堆棧網路。 string[]
podLinkLocalAccess 定義 access to special link local addresss (Azure Instance Metadata Service,簡稱 IMDS),適用於 hostNetwork=false 的 pods。 如果未指定,則預設值為 『IMDS』。 'IMDS'
'None'
serviceCidr 要從中指派服務叢集IP的CIDR表示法IP範圍。 它不得與任何子網IP範圍重疊。 string

Constraints:
圖案 = ^([0-9]{1,3}\.){3}[0-9]{1,3}(\/([0-9]|[1-2][0-9]|3[0-2]))?$
serviceCidrs 要從中指派服務叢集IP的CIDR表示法IP範圍。 單一堆棧網路應該會有一個 IPv4 CIDR。 兩個 CIDR,每個 IP 系列一個 (IPv4/IPv6),預期雙堆棧網路。 它們不得與任何子網IP範圍重疊。 string[]
staticEgressGatewayProfile 靜態輸出閘道附加元件配置檔。 如需靜態輸出閘道的詳細資訊,請參閱 https://aka.ms/aks/static-egress-gateway。 ManagedClusterStaticEgressGatewayProfile

ContainerServiceNetworkProfileKubeProxyConfig

Name Description Value
enabled 是否要在叢集上的 kube-proxy 上啟用 (如果沒有 'kubeProxyConfig' 存在,預設會在 AKS 中啟用 kube-proxy,而不需要這些自定義專案)。 bool
ipvsConfig 保留IPVS的組態自定義。 只有在 'mode' 設定為 'IPVS' 時,才能指定。 ContainerServiceNetworkProfileKubeProxyConfigIpvsConfig
mode 指定要使用的 Proxy 模式 ('IPTABLES'、'IPVS' 或 'NFTABLES') 'IPTABLES'
'IPVS'
「NFTABLES」

ContainerServiceNetworkProfileKubeProxyConfigIpvsConfig

Name Description Value
scheduler 如需詳細資訊,請參閱 http://www.linuxvirtualserver.org/docs/scheduling.htmlIPVS排程器。 'LeastConnection'
'RoundRobin'
tcpFinTimeoutSeconds 在收到 FIN 後,用於 IPVS TCP 工作階段的逾時值,以秒為單位。 必須是正整數值。 int
tcpTimeoutSeconds 用於閑置IPVS TCP會話的逾時值,以秒為單位。 必須是正整數值。 int
udpTimeoutSeconds 用於IPVS UDP 封包的逾時值,以秒為單位。 必須是正整數值。 int

ContainerServiceSshConfiguration

Name Description Value
publicKeys 用來向Linux型VM進行驗證的SSH公鑰清單。 最多可以指定1個索引鍵。 ContainerServiceSshPublicKey[](必需)

ContainerServiceSshPublicKey

Name Description Value
keyData 用來透過 SSH 向 VM 進行驗證的憑證公鑰。 憑證必須採用 PEM 格式,且不含標頭。 字串 (必要)

CreationData

Name Description Value
sourceResourceId 這是要用來建立目標物件的來源物件的 ARM 識別碼。 字串

DelegatedResource

Name Description Value
位置 來源資源位置 - 僅供內部使用。 字串
referralResource 轉介委派的委派標識碼 (選擇性) - 僅供內部使用。 字串
resourceId 委派資源的 ARM 資源識別碼 - 僅供內部使用。 字串
tenantId 委派資源的租用戶標識碼 - 僅供內部使用。 string

Constraints:
最小長度 = 36
最大長度 = 36
圖案 = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$

DranetProfile

Name Description Value
mode 特工池的DRANET模式。 'Managed'
'Unmanaged'

ExtendedLocation

Name Description Value
name 擴充位置的名稱。 字串
型別 擴充位置的類型。 'EdgeZone'

GPUProfile

Name Description Value
driver 是否要安裝 GPU 驅動程式。 未指定時,預設值為 [安裝]。 'Install'
'None'
driverType 指定建立 Windows 代理程式集區時要安裝的 GPU 驅動程式類型。 如果未提供,AKS 會根據系統相容性選取驅動程式。 建立 AgentPool 之後,就無法變更此專案。 這無法在Linux AgentPools上設定。 針對Linux AgentPools,會根據系統相容性來選取驅動程式。 'CUDA'
'GRID'
nvidia NVIDIA 專用的 GPU 設定。 NvidiaGPUProfile

硬驅逐門檻

Name Description Value
記憶體可用 可使用記憶體的門檻低於該區域會觸發 pod 驅逐。 接受絕對值(例如「500英里」)或百分比值(例如「5%」)。 絕對值必須大於或等於100英里。 百分比值必須大於或等於2%。 字串
nodeFsAvailable 可用節點檔案系統空間的門檻,低於此範圍觸發 pod 驅逐。 接受絕對值(例如「1Gi」)或百分比值(例如「10%」)。 必須大於或等於系統預設值 10%。 字串
nodeFsInodesFree 節點檔案系統中可用 inode 的閾值,低於此閾值會觸發 pod 驅逐。 接受絕對 inode 計數(例如「100000」)或百分比值(例如「5%」)。 百分比值必須大於或等於系統預設的5%。 字串

IPTag

Name Description Value
ipTagType IP 標籤類型。 範例:RoutingPreference。 字串
加標籤 與公用IP相關聯的IP標籤。 範例:因特網。 字串

IstioCertificateAuthority

Name Description Value
plugin Service Mesh 的外掛程式憑證資訊。 IstioPluginCertificateAuthority

IstioComponents

Name Description Value
egressGateways Istio 輸出閘道。 IstioEgressGateway[]
ingressGateways Istio 輸入閘道。 IstioIngressGateway[]
proxyRedirectionMechanism 流量重新導向的模式。 “CNIChaining”
「初始容器」

IstioEgressGateway

Name Description Value
enabled 是否啟用輸出閘道。 布林 (必要)
gatewayConfigurationName Istio 附加元件輸出閘道的閘道組態自定義資源名稱。 啟用 Istio 輸出閘道時必須指定。 必須部署在 Istio 輸出閘道部署所在的相同命名空間中。 字串
name Istio 附加元件輸出閘道的名稱。 string

Constraints:
模式 = [a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)* (必要)
命名空間 Istio 附加元件輸出閘道應該部署在 的命名空間。 如果未指定,則預設值為 aks-istio-egress。 字串

IstioIngressGateway

Name Description Value
enabled 是否要啟用輸入閘道。 布林 (必要)
mode 輸入閘道的模式。 'External'
“內部”(必填)

IstioPluginCertificateAuthority

Name Description Value
certChainObjectName Azure Key Vault 中的 Certificate chain object name. 字串
certObjectName Azure Key Vault 中的 Intermediate certificate object name. 字串
keyObjectName Azure Key Vault 中的中介憑證私鑰物件名稱。 字串
keyVaultId 金鑰保存庫 的資源 ID。 字串
rootCertObjectName Azure Key Vault 中的根憑證物件名稱。 字串

IstioServiceMesh

Name Description Value
certificateAuthority Istio Service Mesh 證書頒發機構單位 (CA) 組態。 目前,我們僅支援外掛程式憑證,如這裡所述 https://aka.ms/asm-plugin-ca IstioCertificateAuthority
components Istio 元件設定。 IstioComponents
revisions Istio 控制平面的修訂清單。 升級未進行時,這會保留一個值。 當 Canary 升級正在進行時,這隻能保留兩個連續值。 欲了解更多資訊,請參閱:/azure/aks/istio-upgrade string[]

KubeletConfig

Name Description Value
allowedUnsafeSysctls 允許的不安全 sysctls 或 unsafe sysctl 模式清單(結尾為 *)。 string[]
containerLogMaxFiles 容器可存在的容器記錄檔數目上限。 數字必須≥ 2。 int

Constraints:
最小值 = 2
containerLogMaxSizeMB 容器記錄檔的大小上限(例如 10Mi)在輪替之前。 int
cpuCfsQuota 如果針對指定 CPU 限制的容器啟用 CPU CFS 配額強制執行。 默認值為 true。 bool
cpuCfsQuotaPeriod CPU CFS 配額期間值。 默認值為 『100 毫秒』。 有效值是具有選擇性分數和單位後綴的十進位數序列。 例如:『300ms』、『2h45m』。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 字串
cpuManagerPolicy 要使用的 CPU 管理員原則。 預設值為 『none』。 如需詳細資訊 ,請參閱 Kubernetes CPU 管理原則 。 允許的值為 『none』 和 『static』。 字串
驅逐MaxPodGracePeriodInSeconds 軟性驅逐期間,Pods終止的最大寬限期(秒數);限制艙終止寬限期秒數。 預設值為 60,當叢集 enableNodeHardening 的性質為真時會套用。 只適用於 Linux 節點池。 int

Constraints:
最小值 = 0
failSwapOn 如果設定為 true,當節點上啟用交換時,Kubelet 將無法啟動。 bool
硬驅逐閾值 Kubelet 的硬性驅逐門檻。 當未設定閾值時,系統預設值會被使用。 有關計算出的預設值,請參見 AKS 節點資源預留 。 只適用於 Linux 節點池。 硬驅逐門檻
imageGcHighThreshold 磁碟使用量的百分比,之後映射垃圾收集一律會執行。 若要停用映射垃圾收集,請將 設定為100。 預設值為85% int
imageGcLowThreshold 永遠不會執行映射垃圾收集的磁碟使用量百分比。 這無法設定高於 imageGcHighThreshold。 預設值為 80% int
kubeReserved kubelet 的保留值。 當未設定值時,會使用系統根據虛擬機大小計算的預設值。 有關計算出的預設值,請參見 AKS 節點資源預留 。 只適用於 Linux 節點池。 KubeReserved
podMaxPids 每個 Pod 的進程數目上限。 int
seccompDefault 指定套用至所有工作負載的預設 seccomp 設定檔。 如果未指定,預設會使用 『Unconfined』。 'RuntimeDefault'
'Unconfined'
soft驅逐寬限期 軟性驅逐信號的寬限期——在淘汰前必須維持多久門檻。 預設和配對規則和 softEvictionThreshold 一樣。 數值為圍棋式的持續時間字串(例如「1分30秒」);支援單位包括「NS」、「US」、「MS」、「S」、「M」及「H」。 只適用於 Linux 節點池。 軟驅逐寬限期
soft驅逐門檻 Kubelet 的軟性驅逐門檻。 當被交叉時,膠囊會在配對的 softEvictionGracePeriod 後被淘汰。 當叢集 enableNodeHardening 屬性為真時,系統預設值會生效;否則不會設定軟性驅逐。 對於每個訊號(memoryAvailable、nodeFsAvailable、nodeFsInodesFree),softEvictionThreshold 和 softEvictionGracePeriod 中的條目必須處於相同狀態:兩者皆為省略(預設)、皆非空(覆寫),或兩串皆為空(選擇退出該訊號)。 只適用於 Linux 節點池。 參見 https://kubernetes.io/docs/concepts/scheduling-eviction/node-pressure-eviction/#soft-eviction-thresholds。 軟驅逐門檻
topologyManagerPolicy 要使用的拓撲管理員原則。 如需詳細資訊,請參閱 Kubernetes 拓撲管理員。 預設值為 『none』。 允許的值為 'none'、'best-effort'、'restricted'和 'single-numa-node'。 字串

KubeReserved

Name Description Value
cpuMillicores 為 Kubernetes 系統守護程式預留的 CPU 數量,以毫核計算。 必須大於或等於140。 例如,值為 200 代表 200 公尺(0.2 CPU 核心)。 int
記憶體MB Kubernetes 系統守護程序所保留的記憶體量,以 MiB 計算。 必須大於或等於750。 int

KubernetesResourceObjectEncryptionProfile

Name Description Value
基礎設施加密 是否使用服務託管金鑰啟用 Kubernetes 資源物件的靜態加密。 有關這方面的更多資訊,請參閱 https://aka.ms/aks/kubernetesResourceObjectEncryption。 'Disabled'
'Enabled'

LinuxOSConfig

Name Description Value
swapFileSizeMB 將在每個節點上建立之交換檔案 MB 的大小。 int
sysctls Linux 代理程序節點的 Sysctl 設定。 SysctlConfig
transparentHugePageDefrag 核心是否應該積極使用記憶體壓縮,讓更多的大量頁面可供使用。 有效值為 'always'、'defer'、'defer+madvise'、'madvise' 和 'never'。 默認值為 「瘋狂」。 如需詳細資訊,請參閱 Transparent Hugepages。 字串
transparentHugePageEnabled 是否啟用透明巨頁。 有效值為 『always』、『madvise』和 『never』。 默認值為 『always』。 如需詳細資訊,請參閱 Transparent Hugepages。 字串

本地DNS虛擬

Name Description Value
cacheDurationInSeconds 緩存最大 TTL(以秒為單位)。 有關更多資訊,請參閱 緩存外掛程式 。 int
forwardDestination 要從 localDNS 轉發的 DNS 查詢的目標伺服器。 'ClusterCoreDNS'
'VnetDNS'
forwardPolicy 用於選擇上游 DNS 伺服器的轉發策略。 有關更多資訊,請參閱 forward plugin 。 '隨機'
'RoundRobin'
'Sequential'
maxConcurrent 最大併發查詢數。 有關更多資訊,請參閱 forward plugin 。 int
通訊協定 對於從 localDNS 到上游 DNS 伺服器的連接,強制執行 TCP 或首選 UDP 協定。 'ForceTCP'
'PreferUDP'
queryLogging localDNS 中 DNS 查詢的日誌級別。 'Error'
'Log'
serveStale 用於提供過時數據的策略。 有關更多資訊,請參閱 緩存外掛程式 。 'Disable'
'Immediate'
'Verify'
serveStaleDurationInSeconds 提供過時的持續時間(以秒為單位)。 有關更多資訊,請參閱 緩存外掛程式 。 int

LocalDNSProfile

Name Description Value
kubeDNSOverrides KubeDNS 覆蓋適用於來自 dnsPolicy:ClusterFirst 的 Pod 的 DNS 流量(稱為 KubeDNS 流量)。 LocalDNSProfileKubeDNSOverrides
mode localDNS 的啟用模式。 'Disabled'
'Preferred'
'Required'
vnetDNSOverrides VnetDNS 覆蓋適用於來自 dnsPolicy:default 或 kubelet 的 Pod 的 DNS 流量(稱為 VnetDNS 流量)。 LocalDNSProfileVnetDNSOverrides

LocalDNSProfileKubeDNSOverrides

Name Description Value

LocalDNSProfileVnetDNSOverrides

Name Description Value

ManagedClusterAADProfile

Name Description Value
adminGroupObjectIDs 具有叢集管理員角色的 AAD 群組物件標識符清單。 string[]
clientAppID (已淘汰)用戶端 AAD 應用程式識別碼。 了解更多資訊,請至 https://aka.ms/aks/aad-legacy。 字串
enableAzureRBAC 是否要啟用 Azure RBAC 以進行 Kubernetes 授權。 bool
Managed 是否要啟用受控 AAD。 bool
serverAppID (已淘汰)伺服器 AAD 應用程式識別碼。 了解更多資訊,請至 https://aka.ms/aks/aad-legacy。 字串
serverAppSecret (已淘汰)伺服器 AAD 應用程式秘密。 了解更多資訊,請至 https://aka.ms/aks/aad-legacy。 string

Constraints:
敏感性值。 以安全參數的形式傳入。
tenantID 要用於驗證的 AAD 租使用者識別碼。 如果未指定,將會使用部署訂用帳戶的租使用者。 字串

ManagedClusterAddonProfile

Name Description Value
config 用於設定附加元件的關鍵/值組。 ManagedClusterAddonProfileConfig
enabled 是否啟用附加元件。 布林 (必要)

ManagedClusterAddonProfileConfig

Name Description Value

ManagedClusterAgentPoolProfile

Name Description Value
artifactStreamingProfile 在 AKS 上使用成品串流的設定。 AgentPoolArtifactStreamingProfile
availabilityZones 節點可用的 Availability zones 清單。 只有在 AgentPoolType 屬性是 'VirtualMachineScaleSets' 時,才能指定這個值。 string[]
capacityReservationGroupID 容量保留群組的完全限定資源 ID,用於從保留的 虛擬機器 群組提供 virtual machines。 此形式為:'/subscriptions/{subscriptionId}/resourcegroups/{resourceGroupName}/providers/Microsoft.Compute/capacityreservationgroups/{capacityReservationGroupName}' 客戶會用它建立包含指定 CRG 的代理池。 更多資訊請參見 Capacity Reservation 字串
count 裝載 Docker 容器的代理程式 (VM) 數目。 允許的值必須介於使用者集區的 0 到 1000(含)範圍內,且系統集區的範圍為 1 到 1000(含)。 預設值為 1。 int
creationData 如果節點集區將會使用快照集建立/升級,則用來指定來源快照集標識符的 CreationData。 CreationData
enableAutoScaling 是否要啟用自動調整程式 bool
enableEncryptionAtHost 是否要啟用主機型 OS 和數據磁碟驅動器加密。 這只支援特定虛擬機大小和特定 Azure 區域。 欲了解更多資訊,請參閱:/azure/aks/enable-host-encryption bool
enableFIPS 是否要使用已啟用 FIPS 的 OS。 詳情請參見 Add a enabled FIPS node pool。 bool
enableNodePublicIP 每個節點是否配置自己的公用IP。 某些案例可能需要節點集區中的節點接收自己的專用公用IP位址。 常見的案例是遊戲工作負載,其中控制台需要直接連線到雲端虛擬機,以將躍點降到最低。 更多資訊請參見為節點分配公共 IP。 默認值為 false。 bool
enableOSDiskFullCaching 是否啟用完整快取臨時作業系統磁碟功能。 啟用此功能後,整個作業系統會被本地快取於臨時作業系統磁碟,防止因網路故障引發的 E17 事件。 bool
enableUltraSSD 是否要啟用 UltraSSD bool
gatewayProfile 閘道模式中受控代理程式集區特有的配置檔。 如果代理程式集區模式不是閘道,則無法設定此欄位。 AgentPoolGatewayProfile
gpuInstanceProfile 要用來為支援的 GPU VM SKU 指定 GPU MIG 實例設定檔的 GPUInstanceProfile。 'MIG1g'
'MIG2g'
'MIG3g'
'MIG4g'
'MIG7g'
gpuProfile 代理程式集區的 GPU 設定。 GPUProfile
hostGroupID 專用主機群組的完全限定資源 ID,用於配置virtual machines,僅用於建立情境,且設定後不得更改。 這是格式:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Compute/hostGroups/{hostGroupName}。 欲了解更多資訊,請參見 Azure dedicated hosts。 字串
kubeletConfig 代理程式集區節點上的 Kubelet 組態。 KubeletConfig
kubeletDiskType 決定空 Dir 卷的放置位置、容器執行時資料根,以及 Kubelet 臨時儲存(ephemeral storage)。 'OS'
'Temporary'
linuxOSConfig Linux 代理程序節點的 OS 組態。 LinuxOSConfig
localDNSProfile 使用 VnetDNS 和 KubeDNS 覆蓋配置每個節點的本地 DNS。 LocalDNS 有助於提高 AKS 群集中 DNS 解析的性能和可靠性。 有關更多詳細資訊,請參閱 aka.ms/aks/localdns。 LocalDNSProfile
maxCount 自動調整的節點數目上限 int
maxPods 可在節點上執行的 Pod 數目上限。 int
messageOfTheDay Linux 節點當天的訊息,base64 編碼。 base64 編碼的字串,將在譯碼之後寫入 /etc/motd。 這允許自定義 Linux 節點當天的訊息。 它不得指定給 Windows 節點。 它必須是靜態字串(也就是將列印為未經處理,而不是以腳本的形式執行)。 字串
minCount 自動調整的節點數目下限 int
mode 代理程式集區的模式。 叢集必須隨時至少有一個「系統」代理程式集區。 欲了解更多關於代理池限制與最佳實務的資訊,請參閱:/azure/aks/use-system-pools 'Gateway'
'Machines'
'ManagedSystem'
'System'
'User'
name 訂用帳戶和資源群組內容中代理程式集區配置檔的唯一名稱。 Windows 代理程式集區名稱必須是 6 個字元或更少。 string

Constraints:
模式 = ^[a-z][a-z0-9]{0,11}$ (必要)
networkProfile 代理程式集區的網路相關設定。 AgentPoolNetworkProfile
nodeImageVersion (節點映射版本) 節點映像的版本。 設定此值會觸發 agentPool 回滾。
只允許輸入 的 recentlyUsedVersions 值。
字串
nodeInitializationTaints 建立期間在節點上新增的Taints不會由AKS協調。 這些污點不會由 AKS 協調,而且可以使用 kubectl 呼叫移除。 建立節點集區之後,即可修改此字段,但在需要重新建立另一項作業(例如節點映射升級)之前,節點將不會以新的污點重新建立。 這些污點允許在節點準備好接受工作負載之前執行必要的設定,例如 『key1=value1:NoSchedule』,然後可以使用 移除 kubectl taint nodes node1 key1=value1:NoSchedule- string[]
nodeLabels 要跨代理程式集區中所有節點保存的節點標籤。 ManagedClusterAgentPoolProfilePropertiesNodeLabels
nodePublicIPPrefixID VM 節點應該使用IP的公用IP前置詞標識碼。 格式如下:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/publicIPPrefixes/{publicIPPrefixName} 字串
nodeTaints 節點集區建立和調整期間新增至新節點的污點。 例如,key=value:NoSchedule。 string[]
orchestratorVersion 使用者指定的 Kubernetes 版本。 支援修補程式版本 <major.minor.patch> (例如 1.20.13)和 <major.minor> (例如 1.20)。 指定 major.minor< 時>,會自動選擇最新支援的 GA 修補程式版本。 在建立叢集之後,以相同的 <major.minor> 更新叢集(例如 1.14.x -> 1.14)將不會觸發升級,即使有較新的修補程式版本也一樣。 最佳做法是,您應該將 AKS 叢集中的所有節點集區升級為相同的 Kubernetes 版本。 節點集區版本必須與控制平面具有相同的主要版本。 節點集區次要版本必須位於控制平面版本的兩個次要版本內。 節點集區版本不能大於控制平面版本。 更多資訊請參見升級節點池。 字串
osDiskSizeGB OS 磁碟大小 GB,用來指定主要/代理程式集區中每部計算機的磁碟大小。 如果您指定 0,它會根據指定的 vmSize 套用預設 osDisk 大小。 int

Constraints:
最小值 = 0
最大值 = 2048
osDiskType 要用於代理程式集區中機器的 OS 磁碟類型。 如果 VM 支援,且快取磁碟大於要求的 OSDiskSizeGB,則預設值為 「暫時」。 否則,預設為 「受控」。 建立之後可能不會變更。 更多資訊請參見 Ephemeral OS。 'Ephemeral'
'Managed'
osSKU 指定代理程式集區所使用的 OS SKU。 如果OSType為Linux,則預設值為Ubuntu。 當 Kubernetes <= 1.24 或 Windows2022 時,如果 OSType >為 Windows,則預設值為 Windows2019。 'AzureContainerLinux'
'AzureLinux'
'AzureLinux3'
'CBLMariner'
“平車”
'Mariner'
'Ubuntu'
'Ubuntu2204'
'Ubuntu2404'
「Ubuntu2604」
'Windows2019'
'Windows2022'
“窗戶2025”
'WindowsAnnual'
osType 作系統類型。 預設值為Linux。 'Linux'
'Windows'
podIPAllocationMode Pod IP 分配模式。 代理程式集區中 Pod 的 IP 配置模式。 必須與 podSubnetId 搭配使用。 預設值為 『DynamicIndividual』。 'DynamicIndividual'
'StaticBlock'
podSubnetID 啟動時,Pod 會加入之子網的標識碼。 如果省略,則會在節點子網上靜態指派 Pod IP(如需詳細資訊,請參閱 vnetSubnetID)。 格式如下:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/virtualNetworks/{virtualNetworkName}/subnets/{subnetName} 字串
powerState 代理程式集區正在執行或停止。 第一次建立代理程式集區時,它一開始會執行。 您可以將此欄位設定為 [已停止] 來停止代理程式集區。 已停止的代理程式集區會停止其所有 VM,而不會產生計費費用。 只有在執行中且布建狀態為 [成功] 時,才能停止代理程式集區 PowerState
preparedImageSpecificationProfile 設定用以確定用於配置池中節點的已準備映像規格。 PreparedImageSpecificationProfile
proximityPlacementGroupID 鄰近放置群組的標識碼。 字串
scaleDownMode 調整代理程式集區時要使用的相應減少模式。 這也會影響叢集自動調整程序的行為。 如果未指定,則預設為 Delete。 'Deallocate'
'Delete'
scaleSetEvictionPolicy 虛擬機器擴展集收回原則。 驅逐政策會明確說明當虛擬機被驅逐時to do什麼。 預設值為刪除。 欲了解更多驅逐資訊,請參見 spot VMs 'Deallocate'
'Delete'
scaleSetPriority 虛擬機擴展集優先順序。 'Regular'
'Spot'
securityProfile 代理程式集區的安全性設定。 AgentPoolSecurityProfile
spotMaxPrice 您願意為現成實例支付的最高價格(以美元為單位)。 可能的值為大於零或 -1 的任何十進位值,表示依需求 up-to 默認價格。 可能的值為大於零或 -1 的任何十進位值,表示願意支付任何隨選價格。 欲了解更多現貨價格,請參閱 spot VMs 價格 int
狀態 包含代理程式集區的唯讀資訊。 AgentPoolStatus
tags 要保存在代理程式集區虛擬機擴展集上的標記。 ManagedClusterAgentPoolProfilePropertiesTags
型別 Agent 集區的類型。 'AvailabilitySet'
「FlexNodes」
'VirtualMachines'
'VirtualMachineScaleSets'
upgradeSettings 升級代理程式集池的設定 AgentPoolUpgradeSettings
升級設定藍綠 代理程式集區上 Blue-Green 升級的設定。 當升級策略設定為 BlueGreen 時適用。 AgentPoolBlueGreenUpgradeSettings
升級策略 定義代理程式集區的升級策略。 預設值為滾動。 “藍綠”
'Rolling'
virtualMachineNodesStatus VirtualMachines 代理程式集區中的節點狀態。 VirtualMachineNodes[]
virtualMachinesProfile VirtualMachines 代理程式集區的規格。 VirtualMachinesProfile
vmSize 代理程式集區 VM 的大小。 VM 大小可用性會因區域而異。 如果節點包含計算資源不足(記憶體、cpu 等)Pod 可能無法正確執行。 欲了解更多關於受限虛擬機大小的細節,請參閱:/azure/aks/quotas-skus-regions 字串
vnetSubnetID 代理程式集區節點和選擇性 Pod 將在啟動時加入的子網標識碼。 如果未指定此專案,則會產生及使用 VNET 和子網。 如果未指定 podSubnetID,這會套用至節點和 Pod,否則只會套用至節點。 格式如下:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/virtualNetworks/{virtualNetworkName}/subnets/{subnetName} 字串
windowsProfile Windows 代理程式集區的特定配置檔。 AgentPoolWindowsProfile
workloadRuntime 決定節點可執行的工作負載類型。 'KataMshvVmIsolation'
“KataVm隔離”
'OCIContainer'
'WasmWasi'

ManagedClusterAgentPoolProfilePropertiesNodeLabels

Name Description Value

ManagedClusterAgentPoolProfilePropertiesTags

Name Description Value

ManagedClusterAIToolchainOperatorProfile

Name Description Value
enabled 是否為集群啟用 AI toolchain Operator。 指出 AI 工具鏈運算子是否啟用。 bool

ManagedClusterAPIServerAccessProfile

Name Description Value
authorizedIPRanges 授權access Kubernetes API 伺服器的 IP 範圍。 IP 範圍以 CIDR 格式指定,例如 137.117.106.88/29。 此功能不相容於使用公共 IP 逐節點的叢集,或使用 Basic Load Balancer 的叢集。 欲了解更多資訊,請參閱 API 伺服器授權 IP 範圍。 string[]
disableRunCommand 是否要停用叢集的執行命令。 bool
enablePrivateCluster 是否要將叢集建立為私人叢集。 更多細節請參見 建立私人 AKS 叢集。 bool
enablePrivateClusterPublicFQDN 是否要為私人叢集建立其他公用 FQDN。 bool
enableVnetIntegration 是否要啟用叢集的apiserver vnet整合。 有關詳細資訊,請參閱 aka.ms/AksVnetIntegration。 bool
privateDNSZone 叢集的 private DNS 區域模式。 預設值為 System。 更多細節請參見 configure private DNS zone。 允許的值為 'system' 和 'none'。 字串
subnetId 啟用apiserver vnet整合時要使用的子網。 使用 BYO Vnet 創建新集群時,或者更新現有集群以啟用 apiserver vnet 集成時,需要它。 字串

ManagedClusterAppRoutingIstio

Name Description Value
mode 是否要啟用 Istio 作為 Gateway API 實作,用於管理式的 App 路由。 'Disabled'
'Enabled'

ManagedClusterAutoUpgradeProfile

Name Description Value
nodeOSUpgradeChannel 節點作系統升級通道。 更新節點上OS的方式。 預設值為 NodeImage。 'NodeImage'
'None'
'SecurityPatch'
'Unmanaged'
upgradeChannel 自動升級的升級通道。 預設值為 『none』。 更多資訊請參見 setting AKS 叢集自動升級通道。 'node-image'
'none'
'patch'
'rapid'
'stable'

ManagedClusterAzureMonitorProfile

Name Description Value
appMonitoring Kubernetes 應用程式容器的應用程式監視配置檔。 透過使用 Azure 監視器 OpenTelemetry 基礎的 SDK 自動監控應用程式,收集應用程式日誌、度量與追蹤資料。 如需概觀,請參閱 aka.ms/AzureMonitorApplicationMonitoring。 ManagedClusterAzureMonitorProfileAppMonitoring
containerInsights 設定此為啟用並設定叢集的 Azure 監視器 Container Insights,該叢集會收集 Kubernetes 事件、庫存,以及容器的標準與測試日誌。 如需概觀,請參閱 aka.ms/AzureMonitorContainerInsights。 ManagedClusterAzureMonitorProfileContainerInsights
計量 適用於 Prometheus 附加元件之 Azure 監視器受控服務的計量配置檔。 收集開箱即用的 Kubernetes 基礎架構指標,傳送至 Azure 監視器 工作區,並為自訂目標設定額外的爬蟲功能。 如需概觀,請參閱 aka.ms/AzureManagedPrometheus。 ManagedClusterAzureMonitorProfileMetrics

ManagedClusterAzureMonitorProfileAppMonitoring

Name Description Value
autoInstrumentation 應用監控 AKS 自動儀器化。 部署一個 webhook,自動與 Microsoft OpenTelemetry 發行版進行工作負載的測量,以收集 OpenTelemetry 的指標、日誌與追蹤資料。 請參閱 https://aka.ms/AKSAppMonitoringDocs 及 https://aka.ms/AzureMonitorApplicationMonitoring 以了解整體概覽。 ManagedClusterAzureMonitorProfileAppMonitoringAutoInstrumentation
開放遙測日誌與追蹤 應用程式監控 OpenTelemetry 的 AKS 日誌與追蹤設定檔。 利用 Azure 監視器 OpenTelemetry 基礎的 SDK 收集 OpenTelemetry 日誌與應用程式的追蹤資料。 請參閱 https://aka.ms/AKSAppMonitoringDocs 及 https://aka.ms/AzureMonitorApplicationMonitoring 以了解整體概覽。 ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryLogsAndTraces
openTelemetryMetrics 應用程式監控 OpenTelemetry 指標設定檔用於 AKS。 利用 Azure 監視器 OpenTelemetry 基礎的 SDK 收集應用程式的 OpenTelemetry 指標。 請參閱 https://aka.ms/AKSAppMonitoringDocs 及 https://aka.ms/AzureMonitorApplicationMonitoring 以了解整體概覽。 ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryMetrics

ManagedClusterAzureMonitorProfileAppMonitoringAutoInstrumentation

Name Description Value
enabled 指示是否啟用應用程式監控自動儀器。 bool

ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryLogsAndTraces

Name Description Value
enabled 指示是否啟用應用程式監控 OpenTelemetry 日誌與追蹤功能。 bool
grpcPort OpenTelemetry GRPC 的主機埠是日誌與追蹤。 若未指定,預設埠口為 28332。 int
httpPort OpenTelemetry HTTP/PROTOBUF 日誌與追蹤的主機埠。 如果未指定,預設埠為 28331。 int

ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryMetrics

Name Description Value
enabled 指示是否啟用應用程式監控 OpenTelemetry Metrics。 bool
grpcPort OpenTelemetry GRPC 指標的主機埠。 如果未指定,預設埠口為 28334。 int
httpPort OpenTelemetry HTTP/PROTOBUF 指標的主機埠。 如果未指定,預設埠為 28333。 int

ManagedClusterAzureMonitorProfileContainerInsights

Name Description Value
containerNetworkLogs 容器網路日誌 用 Azure 監視器 配置容器網路日誌的攝取。 所攝取的日誌類型由相關的CRD控制;若未指定,則預設為 Disabled。 詳情請參閱 https://aka.ms/ContainerNetworkLogsDoc 及https://aka.ms/acns/howtoenablecnl 'Disabled'
'Enabled'
disablePrometheusMetricsScraping 指出是否停用 prometheus 計量擷取。 若未指定,預設為 false,也就是說 prometheus 抓取已被啟用。 bool
enabled 指示是否啟用 Azure 監視器 容器 Insights Logs 外掛。 bool
logAnalyticsWorkspaceResourceId Azure Log Analytics Workspace 的完全合格 ARM 資源 ID 用於儲存 Azure 監視器 容器 Insights Logs. 字串
syslogPort syslog 主機埠。 如果未指定,預設埠為 28330。 int

ManagedClusterAzureMonitorProfileKubeStateMetrics

Name Description Value
metricAnnotationsAllowList 將在資源標籤量中使用的 Kubernetes 批註索引鍵逗號分隔清單(範例:'namespaces=[kubernetes.io/team,...],pods=[kubernetes.io/team],...')。 根據預設,計量只包含資源名稱和命名空間標籤。 字串
metricLabelsAllowlist 將用於資源標籤計量的其他 Kubernetes 標籤索引鍵逗號分隔清單(範例:'namespaces=[k8s-label-1,k8s-label-n,...],pods=[app],...')。 根據預設,計量只包含資源名稱和命名空間標籤。 字串

ManagedClusterAzureMonitorProfileMetrics

Name Description Value
controlPlane的 Control plane metrics collection profile for the Azure Managed Prometheus addon. 配置來自受管理控制平面元件(如 kube-apiserver、etcd 等)的運作執行時指標收集。 請參見 aka.ms/aks/controlplane-metrics 以了解整體概覽。 ManagedClusterAzureMonitorProfileMetricsControlPlane
enabled 是否啟用或停用 Azure Managed Prometheus 外掛以監控 Prometheus。 如需啟用和停用的詳細資訊,請參閱 aka.ms/AzureManagedPrometheus-aks-enable。 布林 (必要)
kubeStateMetrics Azure 受控 Prometheus 附加元件 Kube 狀態計量配置檔。 這些選擇性設定適用於使用附加元件部署的 kube-state-metrics Pod。 如需詳細資訊,請參閱 aka.ms/AzureManagedPrometheus-optional-parameters。 ManagedClusterAzureMonitorProfileKubeStateMetrics

ManagedClusterAzureMonitorProfileMetricsControlPlane

Name Description Value
enabled 是否啟用或停用 Azure Managed Prometheus 外掛的控制平面指標收集。 預設為停用。 詳情請參見 aka.ms/aks/controlplane-metrics。 bool

ManagedClusterBootstrapProfile

Name Description Value
artifactSource 成品來源。 下載這些 artifacts 的來源。 'Cache'
'Direct'
containerRegistryId The resource ID of Azure Container Registry. 登錄檔必須具備私有網路access、高級 SKU 及區域冗餘。 字串

ManagedClusterControlPlaneScalingProfile

Name Description Value
縮放大小 控制平面的縮放尺寸。 縮放規模提供保證容量與可預測的 Kubernetes 效能,超越標準預設。 較大的H尺寸能提供更高的性能保證。 請參閱 https://aka.ms/aks/hyperscale 各尺寸的效能指標細節。 「H2」
「H4」
「H8」(必填)

ManagedClusterCostAnalysis

Name Description Value
enabled 是否啟用成本分析。 受控叢集 sku.tier 必須設定為 「標準」或「進階」,才能啟用此功能。 啟用此功能後,Kubernetes 命名空間與部署細節會加入 Azure portal 的成本分析檢視。 如果未指定,則預設值為 false。 如需詳細資訊,請參閱 aka.ms/aks/docs/cost-analysis。 bool

ManagedClusterHealthMonitorProfile

Name Description Value
啟用持續控制平面與附加監控器 是否啟用連續控制平面和附加元件監控。 bool
enableOnDemandMonitor 是否啟用隨選監控。 bool

ManagedClusterHosted系統設定檔

Name Description Value
enabled 是否要為叢集啟用託管系統附加元件。 bool
nodeSubnetID 由 node auto provisioner 管理的工作節點加入的子網 ID,用於在租戶中執行工作負載 Pod。 這必須與 systemNodeSubnetID 和 apiserverAccessProfile.subnetId一起提供,且三個子網 ID 必須在同一個 VNet 中。 如果你沒特別指定,AKS 會在管理資源群組中用預設的 /16 CIDR 建立一個子網路。 字串
systemNodeSubnetID 由 AKS 管理並託管的系統節點加入的子網 ID,用於執行關鍵系統附加元件。 此 ID 必須與 nodeSubnetIDapiserverAccessProfile.subnetId及 一同提供,且三個子網 ID 必須屬於同一個 VNet。 如果你沒特別指定,AKS 會在管理資源群組中用預設的 /26 CIDR 建立子網路。 字串

ManagedClusterHttpProxyConfig

Name Description Value
enabled 是否開啟 HTTP 代理。 若停用,指定的代理設定將不會被設定在 pods 和節點上。 如果未指定,則預設值為 true。 bool
httpProxy 要使用的 HTTP Proxy 伺服器端點。 字串
httpsProxy 要使用的 HTTPS Proxy 伺服器端點。 字串
noProxy 不應該通過 Proxy 的端點。 string[]
trustedCa 用來連線到 Proxy 伺服器的替代 CA 憑證。 字串

ManagedClusterIdentity

Name Description Value
delegatedResources 指派給此受控叢集的委派身分識別資源。 這只能由其他 Azure 資源提供者設定,而受管理叢集只接受一個委派的身份資源。 僅供內部使用。 ManagedClusterIdentityDelegatedResources
型別 用於受控叢集的身分識別類型。 欲了解更多資訊,請參閱 AKS 中的 use 管理身份。 'None'
'SystemAssigned'
'UserAssigned'
userAssignedIdentities 與受控叢集相關聯的使用者身分識別。 此身分識別將用於控制平面。 只允許一個使用者指派的身分識別。 密鑰必須是 ARM 資源識別符,格式為:『/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'。 ManagedClusterIdentityUserAssignedIdentities

ManagedClusterIdentityDelegatedResources

Name Description Value

ManagedClusterIdentityUserAssignedIdentities

Name Description Value

ManagedClusterIngressDefaultDomainProfile

Name Description Value
enabled 是否啟用預設網域。 bool

ManagedClusterIngressProfile

Name Description Value
applicationLoadBalancer 管理式 Application Load Balancer 安裝設定 ManagedClusterIngressProfileApplicationLoadBalancer
閘道API 託管閘道 API 安裝的設置 ManagedClusterIngressProfileGateway配置
webAppRouting 輸入設定檔的應用程式路由設定。 你可以在 /azure/aks/app-routing?tabs=default%2Cdeploy-app-default 找到此功能的概述與入職指南。 ManagedClusterIngressProfileWebAppRouting

ManagedClusterIngressProfileApplicationLoadBalancer

Name Description Value
enabled 是否啟用 Application Load Balancer。 bool

ManagedClusterIngressProfileGateway配置

Name Description Value
安裝 託管閘道 API 安裝的配置。 如果未指定,則預設值為“禁用”。 如需詳細資訊,請參閱 https://aka.ms/k8s-gateway-api。 'Disabled'
'Standard'

ManagedClusterIngressProfileNginx

Name Description Value
defaultIngressControllerType 默認 NginxIngressController 自訂資源的輸入類型 'AnnotationControlled'
'External'
'Internal'
'None'

ManagedClusterIngressProfileWebAppRouting

Name Description Value
預設網域 預設網域的設定。 這是一個唯一的自動生成域,帶有簽名的 TLS 證書,允許安全的 HTTPS。 更多說明 請參閱預設網域文件 。 ManagedClusterIngressDefaultDomainProfile
dnsZoneResourceIds 要與應用程式路由附加元件相關聯的 DNS 區域資源識別碼。 只有在啟用應用程式路由附加元件時才使用。 公有與 private DNS 區域可以屬於不同的資源群組,但所有公共 DNS 區域必須屬於同一資源群組,且所有 private DNS 區域必須在同一資源群組中。 string[]
enabled 是否要啟用應用程式路由附加元件。 bool
gatewayAPIImplementations 閘道 API 提供者用於管理式 App Routing 的設定。 欲了解更多關於閘道 API(Gateway API)的資訊,請參閱 https://aka.ms/k8s-gateway-api 此處。 ManagedClusterWebAppRoutingGatewayAPIImplementations
nginx 默認 NginxIngressController 的組態。 詳情請見 /azure/aks/app-routing-nginx-configuration#the-default-nginx-ingress-controller。 ManagedClusterIngressProfileNginx

ManagedClusterLoadBalancerProfile

Name Description Value
allocatedOutboundPorts 每個 VM 所需配置的 SNAT 埠數目。 允許的值介於 0 到 64000 的範圍內(含)。 預設值是 0,這會導致 Azure 動態分配埠口。 int

Constraints:
最小值 = 0
最大值 = 64000
backendPoolType 受管理的入站 Load Balancer BackendPool 類型。 'NodeIP'
'NodeIPConfiguration'
「PodIP」
clusterServiceLoadBalancerHealthProbeMode 外部流量原則叢集服務的健全狀況探查行為。 'ServiceNodePort'
“共用”
enableMultipleStandardLoadBalancers 為每個 AKS 叢集啟用多個標準負載平衡器。 bool
idleTimeoutInMinutes 所需的輸出流程閑置逾時,以分鐘為單位。 允許的值介於 4 到 120 之間(含)。 預設值為 30 分鐘。 int

Constraints:
最小值 = 4
最大值 = 120
managedOutboundIPs 叢集load balancer想要的託管外站 IP。 ManagedClusterLoadBalancerProfileManagedOutboundIPs
outboundIPPrefixes 叢集load balancer的期望外撥 IP 前綴資源。 ManagedClusterLoadBalancerProfileOutboundIPPrefixes
outboundIPs 叢集load balancer的期望外撥 IP 資源。 ManagedClusterLoadBalancerProfileOutboundIPs

ManagedClusterLoadBalancerProfileManagedOutboundIPs

Name Description Value
count Azure為叢集建立/管理的 IPv4 外站 IP 數量load balancer。 允許的值必須介於 1 到 100 的範圍內(含)。 預設值為 1。 int

Constraints:
最小值 = 1
最大值 = 100
countIPv6 Azure為叢集建立/管理的 IPv6 外撥 IP 數量load balancer。 允許的值必須介於 1 到 100 的範圍內(含)。 單一堆棧的預設值為0,雙堆疊的預設值為1。 int

Constraints:
最小值 = 0
最大值 = 100

ManagedClusterLoadBalancerProfileOutboundIPPrefixes

Name Description Value
publicIPPrefixes 公用IP前置資源的清單。 ResourceReference[]

ManagedClusterLoadBalancerProfileOutboundIPs

Name Description Value
publicIPs 公用IP資源的清單。 ResourceReference[]

ManagedClusterManagedOutboundIPProfile

Name Description Value
count Azure 建立/管理的期望出站 IP 數量。 允許的值必須介於 1 到 16 的範圍內(含)。 預設值為 1。 int

Constraints:
最小值 = 1
最大值 = 16
countIPv6 Azure 所建立/管理的 IPv6 外站 IP 數量。 允許的值必須介於 1 到 16 的範圍內(含)。 int

Constraints:
最小值 = 1
最大值 = 16

ManagedClusterMetricsProfile

Name Description Value
costAnalysis 每個 Kubernetes 資源成本分析的詳細設定。 ManagedClusterCostAnalysis

ManagedClusterNATGatewayProfile

Name Description Value
idleTimeoutInMinutes 所需的輸出流程閑置逾時,以分鐘為單位。 允許的值介於 4 到 120 之間(含)。 預設值為 4 分鐘。 int

Constraints:
最小值 = 4
最大值 = 120
managedOutboundIPProfile 叢集 NAT 閘道的受控輸出 IP 資源設定檔。 ManagedClusterManagedOutboundIPProfile
outboundIPPrefixes 管理 NAT 閘道所需的外撥 IP 前綴資源。 僅相容於 NAT Gateway V2。 ManagedClusterNATGatewayProfileOutboundIPPrefixes
outboundIPs 管理 NAT 閘道器的期望外站 IP 資源。 ManagedClusterNATGatewayProfileOutboundIPS
sku 管理叢集 NAT 閘道器的 SKU。 預設為「StandardV2」(區域區域適用),否則為「Standard」。 'Standard'
'StandardV2'

ManagedClusterNATGatewayProfileOutboundIPPrefixes

Name Description Value
publicIPPrefixes 公用IP前置資源的清單。 string[]

ManagedClusterNATGatewayProfileOutboundIPS

Name Description Value
publicIPs 公用IP資源的清單。 string[]

ManagedClusterNodeProvisioningProfile

Name Description Value
defaultNodePools 為節點預置配置的預設 Karpenter 節點池 (CRD) 集。 除非mode為 'Auto',否則此欄位無效。 警告:在現有集群上將其從 Auto 更改為 None 將導致預設的 Karpenter NodePools 被刪除,這將耗盡並刪除與這些池關聯的節點。 強烈建議不要這樣做,除非有空閒節點準備好接收該作驅逐的 Pod。 如果未指定,則預設值為 Auto。有關更多資訊,請參閱 aka.ms/aks/nap#node-pools。 'Auto'
'None'
mode 節點布建模式。 如果未指定,則預設值為Manual。 'Auto'
'Manual'

ManagedClusterNodeResourceGroupProfile

Name Description Value
restrictionLevel 套用至叢集節點資源群組的限制層級。 如果未指定,預設值為 'Unrestricted' 'ReadOnly'
'Unrestricted'

ManagedClusterOidcIssuerProfile

Name Description Value
enabled 是否啟用 OIDC 簽發者。 bool

ManagedClusterPodIdentity

Name Description Value
bindingSelector 要用於 AzureIdentityBinding 資源的系結選取器。 字串
身分識別 使用者指派的身分識別詳細數據。 UserAssignedIdentity (必需)
name Pod 身分識別的名稱。 字串 (必要)
命名空間 Pod 身分識別的命名空間。 字串 (必要)

ManagedClusterPodIdentityException

Name Description Value
name Pod 身分識別例外狀況的名稱。 字串 (必要)
命名空間 Pod 身分識別例外狀況的命名空間。 字串 (必要)
podLabels 要比對的 Pod 標籤。 ManagedClusterPodIdentityExceptionPodLabels (必需)

ManagedClusterPodIdentityExceptionPodLabels

Name Description Value

ManagedClusterPodIdentityProfile

Name Description Value
allowNetworkPluginKubenet 是否允許Pod身分識別在具有 Kubenet 網路的叢集上執行。 根據預設,在 Kubenet 中執行會因為 AAD Pod 身分識別的安全性相關本質和 IP 詐騙的風險而停用。 更多資訊請參閱 using Kubenet network plugin with AAD Pod Identity。 bool
enabled 是否啟用Pod身分識別附加元件。 bool
userAssignedIdentities 叢集中要使用的Pod身分識別。 ManagedClusterPodIdentity[]
userAssignedIdentityExceptions 允許的Pod身分識別例外狀況。 ManagedClusterPodIdentityException[]

ManagedClusterProperties

Name Description Value
aadProfile Azure Active Directory配置。 ManagedClusterAADProfile
addonProfiles 受控叢集附加元件配置檔。 ManagedClusterPropertiesAddonProfiles
agentPoolProfiles 代理程式集區屬性。 ManagedClusterAgentPoolProfile[]
aiToolchainOperatorProfile 適用於整個叢集的 AI 工具鏈作員設定。 ManagedClusterAIToolchainOperatorProfile
apiServerAccessProfile 管理叢集 API 伺服器的 access 設定檔。 ManagedClusterAPIServerAccessProfile
autoScalerProfile 啟用時要套用至叢集自動調整程序的參數 ManagedClusterPropertiesAutoScalerProfile
autoUpgradeProfile 自動升級組態。 ManagedClusterAutoUpgradeProfile
azureMonitorProfile Azure 監視器 外掛配置檔用於監控受管理叢集。 ManagedClusterAzureMonitorProfile
bootstrapProfile 叢集啟動程式組態的配置檔。 ManagedClusterBootstrapProfile
controlPlaneScalingProfile 提供可擴展且具效能保證的控制平面容量,以在高負載下提供穩定效能的配置檔。 需要 Kubernetes 版本 1.33.0 或更新版本。 ManagedClusterControlPlaneScalingProfile
creationData 如果叢集是使用快照集建立/升級,則用來指定來源快照集標識符的 CreationData。 CreationData
disableLocalAccounts 如果應該在受控叢集上停用本機帳戶。 如果設定為 true,將會停用此叢集的靜態認證。 這隻能在已啟用 AAD 的受控叢集上使用。 更多詳情請參見 disable local accounts。 bool
diskEncryptionSetID 要用來啟用待用加密之磁碟加密的資源標識符。 這是格式:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Compute/diskEncryptionSets/{encryptionSetName}' 字串
dnsPrefix 受控叢集的 DNS 前置詞。 建立受控叢集之後,就無法更新此專案。 字串
enableFIPS 是否要在叢集層級啟用 FIPS 模式。 啟用時,此設定會強制所有 AKS 管理元件(如節點作業系統、外掛及 受管理容器化元件)符合 FIPS 規範。 詳情請參見 啟用叢集範圍 FIPS 。 啟用此功能後,叢集中所有節點池也必須啟用 FIPS。 bool
enableNamespaceResources 啟用 namespace as Azure 資源。 預設值為 false。 您可以在建立和更新受控叢集時啟用/停用它。 如需命名空間作為 ARM 資源的詳細資訊,請參閱 https://aka.ms/NamespaceARMResource 。 bool
enableNodeHardening 是否要在叢集層級啟用節點強化。 啟用後,AKS 會對叢集中所有 Linux 節點池套用軟驅逐閾值、kube 保留及系統保留的硬化預設值。 每個節點池的 kubeletConfig 設定優先於強化預設值。 在運行 Kubernetes 1.37 或更新版本的代理池中,節點強化預設是啟用且無法關閉的;將此欄位設為 false 對這些池子沒有影響。 bool
enableRBAC 是否啟用 Kubernetes Role-Based 存取控制。 bool
fqdnSubdomain 私有叢集的 FQDN 子網域,並擁有自訂的 private dns 區域。 建立受控叢集之後,就無法更新此專案。 字串
健康監測檔案 管理叢集的健康監控設定檔。 ManagedClusterHealthMonitorProfile
hosted系統設定檔 託管系統插件的設置。 如需詳細資訊,請參閱https://aka.ms/aks/automatic/systemcomponents。 ManagedClusterHosted系統設定檔
httpProxyConfig 使用 HTTP Proxy 伺服器布建叢集的組態。 ManagedClusterHttpProxyConfig
identityProfile 與受控叢集相關聯的使用者身分識別。 kubelet 會使用此身分識別。 只允許一個使用者指派的身分識別。 唯一接受的密鑰是 “kubeletidentity”,值為 “resourceId”:“/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}”。 ManagedClusterPropertiesIdentityProfile
ingressProfile 受控叢集的輸入配置檔。 ManagedClusterIngressProfile
kubernetesVersion 使用者指定的 Kubernetes 版本。 支援修補程式版本 <major.minor.patch> (例如 1.20.13)和 <major.minor> (例如 1.20)。 指定 major.minor< 時>,會自動選擇最新支援的 GA 修補程式版本。 在建立叢集之後,以相同的 <major.minor> 更新叢集(例如 1.14.x -> 1.14)將不會觸發升級,即使有較新的修補程式版本也一樣。 當您升級支援的 AKS 叢集時,無法略過 Kubernetes 次要版本。 所有升級都必須依主要版本號碼循序執行。 例如,允許在 1.14.x -> 1.15.x 或 1.15.x - 1.16.x 之間升級,但不允許 1.14.x ->> 1.16.x。 更多細節請參見 升級 AKS 叢集。 字串
linuxProfile 受控叢集中Linux VM的配置檔。 ContainerServiceLinuxProfile
metricsProfile 選擇性叢集計量組態。 ManagedClusterMetricsProfile
networkProfile 網路組態配置檔。 ContainerServiceNetworkProfile
nodeDisruptionProfile 管理叢集的節點中斷設定檔。 節點破壞剖面
nodeProvisioningProfile 套用至整個叢集的節點布建設定。 ManagedClusterNodeProvisioningProfile
nodeResourceGroup 包含代理程式集區節點的資源群組名稱。 字串
nodeResourceGroupProfile 節點資源群組組態的配置檔。 ManagedClusterNodeResourceGroupProfile
oidcIssuerProfile 受控叢集的 OIDC 簽發者配置檔。 ManagedClusterOidcIssuerProfile
podIdentityProfile 受控叢集的Pod身分識別配置檔。 欲了解更多關於 AAD 莢果身份整合的細節,請參見 use AAD pod identity。 ManagedClusterPodIdentityProfile
privateLinkResources 與叢集相關的 Private link 資源。 PrivateLinkResource[]
publicNetworkAccess PublicNetworkAccess 的 PublicNetworkAccess 中。 允許或拒絕 AKS 的公共網路 access 'Disabled'
'Enabled'
“SecuredByPerimeter”
schedulerProfile 設定檔包含排程器相關的設定,例如每個排程器的設定模式,由 AKS 管理。 參見 https://aka.ms/aks/scheduler-profile。 SchedulerProfile
securityProfile 受控叢集的安全性配置檔。 ManagedClusterSecurityProfile
serviceMeshProfile 受控叢集的服務網格配置檔。 ServiceMeshProfile
servicePrincipalProfile 關於叢集用來操作 Azure API 的服務主體身份資訊。 ManagedClusterServicePrincipalProfile
狀態 包含受控叢集的唯讀資訊。 ManagedClusterStatus
storageProfile 管理叢集的 Storage 設定檔。 ManagedClusterStorageProfile
supportPlan 受控叢集的支持計劃。 如果未指定,則預設值為 『KubernetesOfficial』。 'AKSLongTermSupport'
'KubernetesOfficial'
upgradeSettings 升級叢集的設定。 ClusterUpgradeSettings
windowsProfile 受控叢集中 Windows VM 的配置檔。 ManagedClusterWindowsProfile
workloadAutoScalerProfile 受控叢集的工作負載自動調整程式配置檔。 ManagedClusterWorkloadAutoScalerProfile

ManagedClusterPropertiesAddonProfiles

Name Description Value

ManagedClusterPropertiesAutoScalerProfile

Name Description Value
balance-similar-node-groups 偵測相似的節點集區,並平衡其間的節點數目。 有效值為 'true' 和 'false' 字串
daemonset-eviction-for-empty-nodes DaemonSet Pod 將從空節點正常終止。 如果設定為 true,則會在刪除節點之前收回空白節點上的所有精靈集 Pod。 如果無法收回精靈集 Pod,則會選擇另一個節點進行調整。 如果設定為 false,則會刪除節點,而不會確保刪除或收回精靈集 Pod。 bool
daemonset-eviction-for-occupied-nodes DaemonSet Pod 將從非空節點正常終止。 如果設定為 true,則會先收回已佔用節點上的所有精靈集 Pod,再刪除節點。 如果無法收回精靈集 Pod,則會選擇另一個節點進行調整。 如果設定為 false,則會刪除節點,而不會確保刪除或收回精靈集 Pod。 bool
expander 縱向擴展時要使用的擴展器。 如果未指定,則預設值為 『random』。 更多資訊請參見擴展器。 'least-waste'
'most-pods'
'priority'
'random'
ignore-daemonsets-utilization CA 在計算縮減的資源利用率時是否應該忽略 DaemonSet Pod。 如果設定為 true,精靈集所使用的資源會在做出相應減少決策時納入考慮。 bool
max-empty-bulk-delete 可以同時刪除的空白節點數目上限。 這必須是正整數。 預設值為 10。 字串
max-graceful-termination-sec 叢集自動調整程式在嘗試相應減少節點時等候Pod終止的最大秒數。 預設值為 600。 字串
max-node-provision-time 自動調整程式等候布建節點的最大時間。 預設值為 『15m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
max-total-unready-percentage 叢集中未讀取節點的最大百分比。 超過此百分比之後,叢集自動調整程式會停止作業。 預設值為 45。 最大值為 100,最小值為 0。 字串
new-pod-scale-up-delay 在某個年齡之前,請忽略未排程的 Pod。 針對高載/批次規模等案例,您不希望 CA 在 kubernetes 排程器排程所有 Pod 之前採取行動,您可以告訴 CA 在排程特定年齡之前忽略未排程的 Pod。 預設值為 『0s』。 值必須是整數,後面接著單位(秒的 's'、'm' 代表分鐘數、'h' 等。 字串
ok-total-unready-count 允許的未讀取節點數目,不論 total-total-unready-percentage。 這必須是整數。 預設值為 3。 字串
scale-down-delay-after-add 擴大後需要多長時間才能繼續進行縮小評估。 預設值為 『10m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-delay-after-delete 節點刪除後再繼續進行縮小評估的時間長度。 預設值為掃描間隔。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-delay-after-failure 縮小失敗後再繼續進行縮小評估的時間長度。 預設值為 『3m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-unneeded-time 節點在符合相應減少資格之前,應該不需要多久的時間。 預設值為 『10m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-unready-time 未就緒的節點在符合縮減條件之前應不需要多長時間。 默認值為 『20m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-utilization-threshold 節點使用率層級,定義為要求資源的總和除以容量,而節點可考慮相應減少。 預設值為 『0.5』。 字串
scan-interval 重新評估叢集以相應增加或減少的頻率。 預設值為 『10』。 值必須是整數秒數。 字串
跳過節點與本地storage 如果叢集自動縮放器會跳過刪除帶有本地 storage 的 pod 節點,例如 EmptyDir 或 HostPath。 默認值為 true。 字串
skip-nodes-with-system-pods 如果集群自動擴縮器會跳過從 kube-system 中刪除帶有 Pod 的節點(DaemonSet 或鏡像 Pod 除外)。 默認值為 true。 字串

ManagedClusterPropertiesIdentityProfile

Name Description Value

ManagedClusterSecurityProfile

Name Description Value
azureKeyVaultKms Azure Key Vault key management service 安全設定檔的設定。 AzureKeyVaultKms
customCATrustCertificates 最多 10 個 base64 編碼 CA 的清單,這些 CA 將會新增至叢集中所有節點上的信任存放區。 欲了解更多資訊,請參閱 Custom CA Trust Certificates。 any[]
defender Microsoft Defender 的安全設定檔設定。 ManagedClusterSecurityProfileDefender
imageCleaner 安全性配置檔的影像清除器設定。 ManagedClusterSecurityProfileImageCleaner
imageIntegrity 影像完整性是一項與 Azure 原則 合作,透過簽章驗證影像完整性的功能。 除非使用 Azure 原則 強制執行映像簽章,否則此方法不會有影響。 如需如何透過原則使用這項功能,請參閱 https://aka.ms/aks/image-integrity 。 ManagedClusterSecurityProfileImageIntegrity
kubernetesResourceObjectEncryptionProfile 對 Kubernetes 資源物件進行靜態加密。 有關這方面的更多資訊,請訪問 https://aka.ms/aks/kubernetesResourceObjectEncryption KubernetesResourceObjectEncryptionProfile
nodeRestriction Node Restriction 安全設定檔。 ManagedClusterSecurityProfileNodeRestriction
serviceAccountImagePullProfile 定義基於服務帳號的圖片拉取設定。 ServiceAccountImagePullProfile
workloadIdentity 安全性配置檔的工作負載身分識別設定。 工作負載身份讓 Kubernetes 應用程式能透過 Azure AD 安全access Azure雲端資源。 如需詳細資訊,請參閱 https://aka.ms/aks/wi。 ManagedClusterSecurityProfileWorkloadIdentity

ManagedClusterSecurityProfileDefender

Name Description Value
logAnalyticsWorkspaceResourceId 與 Microsoft Defender 關聯的日誌分析工作區資源 ID。 啟用 Microsoft Defender 時,此欄位為必填且必須為有效的工作空間資源 ID。 當 Microsoft Defender 被停用時,請將欄位留空。 字串
securityGating Microsoft Defender 的安全閘控設定。 此測試驗證容器映像檔是否符合部署資格,基於 Defender for Containers 的安全發現。 利用 Admission Controller,它會審核或阻止部署不符合安全標準的映像檔。 如需詳細資訊,請參閱https://aka.ms/KubernetesDefenderAuditRule。 ManagedClusterSecurityProfileDefenderSecurityGating
securityMonitoring Microsoft Defender 威脅偵測,用於雲端安全設定檔。 ManagedClusterSecurityProfileDefenderSecurityMonitoring

ManagedClusterSecurityProfileDefenderSecurityGating

Name Description Value
allowSecretAccess 僅在登錄檔存取由秘密身份而非管理身份授予時使用。 設定是否授予 Defender 門控代理存取叢集機密以從登錄檔拉取影像。 若秘密存取被拒絕且登錄檔要求拉取秘密,該外掛將不會執行映像驗證。 預設值為 False。 bool
enabled 是否要啟用Defender安全性管制。 啟用後,閘控功能會掃描容器映像檔,並審核或阻擋不符合安全標準的映像檔部署,並依照配置的安全規則。 如需詳細資訊,請參閱https://aka.ms/KubernetesDefenderAuditRule。 bool
身分識別 允許存取控制者用來從登錄庫拉取安全產物的身份列表。 這些是叢集用來提取容器映像的相同身分識別。 欲了解更多關於配置此身份的資訊,請參閱 /azure/defender-for-cloud/gated-deployment-infrastructure-as-code。 ManagedClusterSecurityProfileDefenderSecurityGatingIdentity[]

ManagedClusterSecurityProfileDefenderSecurityGatingIdentity

Name Description Value
azureContainerRegistry 將使用身分識別的容器登錄;此處指定的身分識別應該附加同盟身分識別認證。 字串
身分識別 用於access登錄檔的身份物件 UserAssignedIdentity

ManagedClusterSecurityProfileDefenderSecurityMonitoring

Name Description Value
enabled 是否啟用Defender威脅偵測 bool

ManagedClusterSecurityProfileImageCleaner

Name Description Value
enabled 是否要在 AKS 叢集上啟用影像清除器。 bool
intervalHours 影像清除程序掃描間隔以小時為單位。 int

ManagedClusterSecurityProfileImageIntegrity

Name Description Value
enabled 是否要啟用映像完整性。 預設值為 false。 bool

ManagedClusterSecurityProfileNodeRestriction

Name Description Value
enabled 是否啟用節點限制 bool

ManagedClusterSecurityProfileWorkloadIdentity

Name Description Value
enabled 是否要啟用工作負載身分識別。 bool

ManagedClusterServicePrincipalProfile

Name Description Value
clientId 服務主體的標識碼。 字串 (必要)
密碼 純文本中與服務主體相關聯的秘密密碼。 string

Constraints:
敏感性值。 以安全參數的形式傳入。

ManagedClusterSKU

Name Description Value
name 受控叢集 SKU 的名稱。 'Automatic'
'Base'
分層 受控叢集 SKU 的層。 如果未指定,則預設值為 『Free』。 詳情請參見 AKS 定價層級。 'Free'
'Premium'
'Standard'

ManagedClusterStaticEgressGatewayProfile

Name Description Value
enabled 啟用 Static Egress Gateway 外掛程式。 指出是否啟用靜態輸出閘道附加元件。 bool

ManagedClusterStatus

Name Description Value

ManagedClusterStorageProfile

Name Description Value
blobCSIDriver AzureBlob CSI 驅動程式設定中的 storage 設定檔。 ManagedClusterStorageProfileBlobCSIDriver
diskCSIDriver AzureDisk CSI 驅動程式設定中 storage profile 的設定。 ManagedClusterStorageProfileDiskCSIDriver
fileCSIDriver AzureFile CSI 驅動程式設定中的 storage 設定檔。 ManagedClusterStorageProfileFileCSIDriver
snapshotController storage profile 的快照控制器設定。 ManagedClusterStorageProfileSnapshotController

ManagedClusterStorageProfileBlobCSIDriver

Name Description Value
enabled 是否要啟用 AzureBlob CSI 驅動程式。 預設值為 false。 bool

ManagedClusterStorageProfileDiskCSIDriver

Name Description Value
enabled 是否要啟用 AzureDisk CSI 驅動程式。 預設值為 True。 bool

ManagedClusterStorageProfileFileCSIDriver

Name Description Value
enabled 是否要啟用 AzureFile CSI 驅動程式。 預設值為 True。 bool

ManagedClusterStorageProfileSnapshotController

Name Description Value
enabled 是否要啟用快照控制器。 預設值為 True。 bool

ManagedClusterWebAppRoutingGatewayAPIImplementations

Name Description Value
appRoutingIstio 設定使用 Sidecar 無邊車的 Istio 控制平面,透過 Gateway API 與 App 路由進行管理式入口。 請參閱 https://aka.ms/gateway-on-istio 有關使用 Istio 透過閘道 API 進入的資訊。 ManagedClusterAppRoutingIstio

ManagedClusterWindowsProfile

Name Description Value
adminPassword 指定系統管理員帳戶的密碼。

長度下限: 8 個字元

長度上限: 123 個字元

複雜性需求:需要滿足下列 4 個條件中的 3 個
字元較低
具有大字元
具有數位
具有特殊字元 (Regex match [\W_])

不允許的值: “abc@123”、“P@$$w 0rd”、“P@ssw0rd”、“P@ssword123”、“Pa$$word”、“pass@word1”、“Password!”、“Password1”、“Password22”、“iloveyou!”
string

Constraints:
敏感性值。 以安全參數的形式傳入。
adminUsername 指定系統管理員帳戶的名稱。

限制: 不能以 “” 結尾。

不允許的值: “administrator”、“admin”、“user”、“user1”、“test”、“user2”、“test1”、“user3”、“admin1”、“1” “123”、“a”、“actuser”、“adm”、“admin2”、“aspnet”、“backup”、“console”、“david”、“guest”、“john”、“owner”、“root”、“server”、“sql”、“support”、“support_388945a0”、“sys”、“test2”、“test3”、“user4”、“user5”。

最小長度: 1 個字元

長度上限: 20 個字元
字串 (必要)
enableCSIProxy 是否要啟用 CSI Proxy。 欲了解更多 CSI 代理的詳細資訊,請參閱 CSI 代理 GitHub repo。 bool
gmsaProfile 受控叢集中的 Windows gMSA 配置檔。 WindowsGmsaProfile
licenseType 要用於 Windows VM 的授權類型。 詳情請參見 Azure 混合用戶優勢。 'None'
'Windows_Server'

ManagedClusterWorkloadAutoScalerProfile

Name Description Value
keda 適用於工作負載自動調整程式配置檔的KEDA (Kubernetes 事件驅動自動調整) 設定。 ManagedClusterWorkloadAutoScalerProfileKeda
verticalPodAutoscaler 工作負載自動調整程式設定檔的 VPA (垂直 Pod 自動調整程式) 設定。 ManagedClusterWorkloadAutoScalerProfileVerticalPodAutoscaler

ManagedClusterWorkloadAutoScalerProfileKeda

Name Description Value
enabled 是否要啟用 KEDA。 布林 (必要)

ManagedClusterWorkloadAutoScalerProfileVerticalPodAutoscaler

Name Description Value
addonAutoscaling 是否啟用 VPA 附加元件,並設定為調整 AKS 管理的附加元件。 'Disabled'
'Enabled'
enabled 是否要啟用 VPA。 預設值為 False。 布林 (必要)

ManagedServiceIdentityUserAssignedIdentitiesValue

Name Description Value

ManualScaleProfile

Name Description Value
count 節點數目。 int
size AKS 在建立和調整時將使用的 VM 大小,例如 'Standard_E4s_v3'、'Standard_E16s_v3' 或 'Standard_D16s_v5'。 字串

節點破壞剖面

Name Description Value
nodeDisruptionPolicy 政策設定,允許需要節點重映像並觸發重新部署的特定操作。 例如,有些操作,例如更新 .properties 的檔案。在現有受管理叢集上設置 ManagedClusterSecurityProfile.customCATrustCertificates 欄位,觸發節點的滾動更新。 此設定允許控制何時接受此類更新。 預設是「允許」。 完整涵蓋作業清單請參見 aka.ms/aks/nodedisruptionpolicy」。 '允許'
「允許維護期間」
'阻止'

NvidiaGPUProfile

Name Description Value
駕駛模式 NVIDIA GPU 資源配置模式。 DevicePlugin 會安裝 NVIDIA
Kubernetes 裝置外掛。 DRA 安裝 NVIDIA DRA 驅動程式。
「裝置插件」
「DRA」
管理模式 管理式GPU體驗會在GPU驅動程式之上安裝額外元件,例如資料中心GPU管理器(DCGM)指標以監控。 想了解更多安裝內容,請參考 aka.ms/aks/managed-gpu。 'Managed'
'Unmanaged'
mig策略 設定用於管理型 MIG 支援的 MIG(多實例 GPU)策略。 欲了解更多不同策略資訊,請造訪 aka.ms/aks/managed-gpu。 未指定時,預設為無。 “喜憂參半”
'None'
'Single'

PortRange

Name Description Value
portEnd 範圍中包含的最大埠。 它的範圍應從 1 到 65535,且大於或等於 portStart。 int

Constraints:
最小值 = 1
最大值 = 65535
portStart 範圍中包含的最小埠。 它的範圍應從 1 到 65535,且小於或等於 portEnd。 int

Constraints:
最小值 = 1
最大值 = 65535
通訊協定 埠的網路通訊協定。 'TCP'
'UDP'

PowerState

Name Description Value
字碼 告知叢集是否正在執行或已停止 'Running'
'Stopped'

PreparedImageSpecificationProfile

Name Description Value
preparedImageSpecificationId 準備好的影像規範資源的資源 ID。 這可以包含一個版本。 省略該版本將使用最新版本的已準備影像規範。 字串

PrivateLinkResource

Name Description Value
groupId 資源的群組標識碼。 字串
id private link 資源的 ID。 字串
name private link 資源的名稱。 詳情請參見 命名規則 。 字串
requiredMembers 資源的 RequiredMembers string[]
型別 資源類型。 字串

ResourceReference

Name Description Value
id 完全合格的 Azure 資源 ID。 字串

ScaleProfile

Name Description Value
自動縮放 如何自動調整預先定義大小範圍內的 VirtualMachines 代理程式集區規格。
每個配置檔針對特定的虛擬機 SKU 進行獨立評估。
跨設定檔的縮放決策由叢集自動縮放擴展器控制,
可透過 ManagedCluster.properties.autoScalerProfile.expander.
AutoScaleProfile[]
manual 如何將 VirtualMachines 代理程式集區調整為固定大小的規格。 ManualScaleProfile[]

SchedulerInstanceProfile

Name Description Value
schedulerConfigMode 由 AKS 管理的排程器使用。 'Default'
'ManagedByCRD'

SchedulerProfile

Name Description Value
上游 與上游變體 kube-scheduler 相關的設定檔(https://github.com/kubernetes/kubernetes/tree/master/pkg/scheduler)。 SchedulerInstanceProfile

ServiceAccountImagePullProfile

Name Description Value
defaultManagedIdentityId 選擇性。 叢集層級用於影像拉取的預設管理身份資源 ID。 設定時,若 Pod 的服務帳號未明確指定拉取圖片的身份,則使用此身份。 若未設定且服務帳號層級未指定身份,映像檔將透過匿名驗證被拉取。 字串
enabled 表示是否啟用了基於服務帳號的映像拉取,此時需要身份綁定才能使用受管理身份進行認證。 如需詳細資訊,請參閱https://aka.ms/aks/identity-binding-docs。 bool

ServiceMeshProfile

Name Description Value
istio Istio 服務網格設定。 IstioServiceMesh
mode 服務網格的模式。 'Disabled'
'Istio'(必填)

軟驅逐寬限期

Name Description Value
記憶體可用 memoryAvailable 軟驅逐訊號的寬限期,以 Go 風格的持續時間字串表示(例如 '30s', '1m30s')。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 必須大於或等於「30」分。 預設是「30多」。 字串
nodeFsAvailable nodeFsAvailable 軟驅逐訊號的寬限期,以 Go 風格的持續時間字串表示(例如 '30s', '1m30s')。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 必須大於或等於「30」分。 預設是「2m」。 字串
nodeFsInodesFree nodeFsInodesFree 軟驅逐訊號的寬限期,以 Go 風格的持續時間字串表示(例如 '30s', '1m30s')。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 必須大於或等於「30」分。 預設是「2m」。 字串

軟驅逐門檻

Name Description Value
記憶體可用 軟莢艙被觸發的可用記憶體閾值。 接受絕對值(例如「500英里」)或百分比值(例如「5%」)。 絕對最低距離為100英里;最低百分比為2%。 預設採用基於容量的階梯:500Mi 用於 <=8GiB,750Mi 為 16GiB,1024Mi(1Gi)為 >=32GiB。 也必須大於有效 hardEvictionThreshold.memoryAvailable。 字串
nodeFsAvailable 軟莢莢被觸發的可用節點檔案系統空間閾值。 接受絕對值(例如「1Gi」)或百分比值(例如「10%」)。 預設是「12%」。 必須大於或等於 10%,且大於有效 hardEvictionThreshold.nodeFsAvailable。 字串
nodeFsInodesFree 節點檔案系統中可用 inode 的門檻,低於此閾值會觸發軟莢驅逐。 接受絕對 inode 計數(例如「100000」)或百分比值(例如「5%」)。 預設是「7%」。 百分比值必須大於或等於 5%,且大於有效 hardEvictionThreshold.nodeFsInodesFree。 字串

SysctlConfig

Name Description Value
fsAioMaxNr Sysctl 設定 fs.aio-max-nr。 int
fsFileMax Sysctl 設定 fs.file-max。 int
fsInotifyMaxUserWatches Sysctl 設定fs.inotify.max_user_watches。 int
fsNrOpen Sysctl 設定fs.nr_open。 int
kernelThreadsMax Sysctl 設定 kernel.threads-max。 int
netCoreNetdevMaxBacklog Sysctl 設定net.core.netdev_max_backlog。 int
netCoreOptmemMax Sysctl 設定net.core.optmem_max。 int
netCoreRmemDefault Sysctl 設定net.core.rmem_default。 int
netCoreRmemMax Sysctl 設定net.core.rmem_max。 int
netCoreSomaxconn Sysctl 設定 net.core.somaxconn。 int
netCoreWmemDefault Sysctl 設定net.core.wmem_default。 int
netCoreWmemMax Sysctl 設定net.core.wmem_max。 int
netIpv4IpLocalPortRange Sysctl 設定net.ipv4.ip_local_port_range。 字串
netIpv4NeighDefaultGcThresh1 Sysctl 設定net.ipv4.neigh.default.gc_thresh1。 int
netIpv4NeighDefaultGcThresh2 Sysctl 設定net.ipv4.neigh.default.gc_thresh2。 int
netIpv4NeighDefaultGcThresh3 Sysctl 設定net.ipv4.neigh.default.gc_thresh3。 int
netIpv4TcpFinTimeout Sysctl 設定net.ipv4.tcp_fin_timeout。 int
netIpv4TcpkeepaliveIntvl Sysctl 設定net.ipv4.tcp_keepalive_intvl。 int

Constraints:
最小值 = 10
最大值 = 90
netIpv4TcpKeepaliveProbes Sysctl 設定net.ipv4.tcp_keepalive_probes。 int
netIpv4TcpKeepaliveTime Sysctl 設定net.ipv4.tcp_keepalive_time。 int
netIpv4TcpMaxSynBacklog Sysctl 設定net.ipv4.tcp_max_syn_backlog。 int
netIpv4TcpMaxTwBuckets Sysctl 設定net.ipv4.tcp_max_tw_buckets。 int
netIpv4TcpTwReuse Sysctl 設定net.ipv4.tcp_tw_reuse。 bool
netNetfilterNfConntrackBuckets Sysctl 設定net.netfilter.nf_conntrack_buckets。 int

Constraints:
最小值 = 65536
最大值 = 524288
netNetfilterNfConntrackMax Sysctl 設定net.netfilter.nf_conntrack_max。 int

Constraints:
最小值 = 131072
最大值 = 2097152
vmMaxMapCount Sysctl 設定vm.max_map_count。 int
vmSwappiness Sysctl 設定 vm.swappiness。 int
vmVfsCachePressure Sysctl 設定vm.vfs_cache_pressure。 int

TrackedResourceTags

Name Description Value

UpgradeOverrideSettings

Name Description Value
forceUpgrade 是否要強制升級叢集。 請注意,此選項會指示升級作業略過升級保護,例如檢查已淘汰的 API 使用量。 請謹慎啟用此選項。 bool
until 直到覆寫生效為止。 請注意,這隻會符合升級的開始時間,即使升級 until 繼續進行時到期,升級的有效性也不會變更。 預設不會設定此欄位。 必須設定覆寫才會生效。 字串

UserAssignedIdentity

Name Description Value
clientId 使用者指派身分識別的用戶端標識碼。 字串
objectId 使用者指派身分識別的物件標識碼。 字串
resourceId 使用者指派身分識別的資源標識碼。 字串

VirtualMachineNodes

Name Description Value
count 節點數目。 int
size 用來裝載此節點群組之代理程式的 VM 大小。 字串

VirtualMachinesProfile

Name Description Value
級別 如何調整 VirtualMachines 代理程式集區的規格。 ScaleProfile

WindowsGmsaProfile

Name Description Value
dnsServer 指定 Windows gMSA 的 DNS 伺服器。

如果您已在用來建立受控叢集的 vnet 中設定 DNS 伺服器,請將它設定為空白。
字串
enabled 是否要啟用 Windows gMSA。 指定是否要在受控叢集中啟用 Windows gMSA。 bool
rootDomainName 指定 Windows gMSA 的根功能變數名稱。

如果您已在用來建立受控叢集的 vnet 中設定 DNS 伺服器,請將它設定為空白。
字串

Terraform (AzAPI 提供者) 資源定義

managedClusters 資源類型可以使用目標作業來部署:

  • 資源團體 關於每個 API 版本變更屬性的清單,請參見 變更日誌。

使用範例

Terraform 範例

部署託管 Kubernetes 叢集(亦稱為 AKS / Azure Kubernetes Service)的基本範例。

terraform {
  required_providers {
    azapi = {
      source = "Azure/azapi"
    }
  }
}

provider "azapi" {
  skip_provider_registration = false
}

variable "resource_name" {
  type    = string
  default = "acctest0001"
}

variable "location" {
  type    = string
  default = "westeurope"
}

resource "azapi_resource" "resourceGroup" {
  type                      = "Microsoft.Resources/resourceGroups@2020-06-01"
  name                      = var.resource_name
  location                  = var.location
  schema_validation_enabled = false
  response_export_values    = ["*"]
}

resource "azapi_resource" "managedCluster" {
  type      = "Microsoft.ContainerService/managedClusters@2023-04-02-preview"
  parent_id = azapi_resource.resourceGroup.id
  name      = var.resource_name
  location  = var.location
  identity {
    type         = "SystemAssigned"
    identity_ids = []
  }
  body = {
    properties = {
      agentPoolProfiles = [
        {
          count  = 1
          mode   = "System"
          name   = "default"
          vmSize = "Standard_DS2_v2"
        },
      ]
      dnsPrefix = var.resource_name
    }
  }
  schema_validation_enabled = false
  response_export_values    = ["*"]
}

Azure 已驗證的模組

以下的 Azure 已驗證模組 可用於部署此資源類型。

Module Description
AKS 管理叢集 AKS 受控叢集的 AVM 資源模組

資源格式

若要建立 Microsoft.ContainerService/managedClusters 資源,請將下列 Terraform 新增至範本。

resource "azapi_resource" "symbolicname" {
  type = "Microsoft.ContainerService/managedClusters@2026-06-02-preview"
  name = "string"
  parent_id = "string"
  identity {
    type = "string"
    identity_ids = [
      "string"
    ]
  }
  location = "string"
  tags = {
    {customized property} = "string"
  }
  body = {
    extendedLocation = {
      name = "string"
      type = "string"
    }
    kind = "string"
    properties = {
      aadProfile = {
        adminGroupObjectIDs = [
          "string"
        ]
        clientAppID = "string"
        enableAzureRBAC = bool
        managed = bool
        serverAppID = "string"
        serverAppSecret = "string"
        tenantID = "string"
      }
      addonProfiles = {
        {customized property} = {
          config = {
            {customized property} = "string"
          }
          enabled = bool
        }
      }
      agentPoolProfiles = [
        {
          artifactStreamingProfile = {
            enabled = bool
          }
          availabilityZones = [
            "string"
          ]
          capacityReservationGroupID = "string"
          count = int
          creationData = {
            sourceResourceId = "string"
          }
          enableAutoScaling = bool
          enableEncryptionAtHost = bool
          enableFIPS = bool
          enableNodePublicIP = bool
          enableOSDiskFullCaching = bool
          enableUltraSSD = bool
          gatewayProfile = {
            publicIPPrefixSize = int
          }
          gpuInstanceProfile = "string"
          gpuProfile = {
            driver = "string"
            driverType = "string"
            nvidia = {
              driverMode = "string"
              managementMode = "string"
              migStrategy = "string"
            }
          }
          hostGroupID = "string"
          kubeletConfig = {
            allowedUnsafeSysctls = [
              "string"
            ]
            containerLogMaxFiles = int
            containerLogMaxSizeMB = int
            cpuCfsQuota = bool
            cpuCfsQuotaPeriod = "string"
            cpuManagerPolicy = "string"
            evictionMaxPodGracePeriodInSeconds = int
            failSwapOn = bool
            hardEvictionThreshold = {
              memoryAvailable = "string"
              nodeFsAvailable = "string"
              nodeFsInodesFree = "string"
            }
            imageGcHighThreshold = int
            imageGcLowThreshold = int
            kubeReserved = {
              cpuMillicores = int
              memoryMB = int
            }
            podMaxPids = int
            seccompDefault = "string"
            softEvictionGracePeriod = {
              memoryAvailable = "string"
              nodeFsAvailable = "string"
              nodeFsInodesFree = "string"
            }
            softEvictionThreshold = {
              memoryAvailable = "string"
              nodeFsAvailable = "string"
              nodeFsInodesFree = "string"
            }
            topologyManagerPolicy = "string"
          }
          kubeletDiskType = "string"
          linuxOSConfig = {
            swapFileSizeMB = int
            sysctls = {
              fsAioMaxNr = int
              fsFileMax = int
              fsInotifyMaxUserWatches = int
              fsNrOpen = int
              kernelThreadsMax = int
              netCoreNetdevMaxBacklog = int
              netCoreOptmemMax = int
              netCoreRmemDefault = int
              netCoreRmemMax = int
              netCoreSomaxconn = int
              netCoreWmemDefault = int
              netCoreWmemMax = int
              netIpv4IpLocalPortRange = "string"
              netIpv4NeighDefaultGcThresh1 = int
              netIpv4NeighDefaultGcThresh2 = int
              netIpv4NeighDefaultGcThresh3 = int
              netIpv4TcpFinTimeout = int
              netIpv4TcpkeepaliveIntvl = int
              netIpv4TcpKeepaliveProbes = int
              netIpv4TcpKeepaliveTime = int
              netIpv4TcpMaxSynBacklog = int
              netIpv4TcpMaxTwBuckets = int
              netIpv4TcpTwReuse = bool
              netNetfilterNfConntrackBuckets = int
              netNetfilterNfConntrackMax = int
              vmMaxMapCount = int
              vmSwappiness = int
              vmVfsCachePressure = int
            }
            transparentHugePageDefrag = "string"
            transparentHugePageEnabled = "string"
          }
          localDNSProfile = {
            kubeDNSOverrides = {
              {customized property} = {
                cacheDurationInSeconds = int
                forwardDestination = "string"
                forwardPolicy = "string"
                maxConcurrent = int
                protocol = "string"
                queryLogging = "string"
                serveStale = "string"
                serveStaleDurationInSeconds = int
              }
            }
            mode = "string"
            vnetDNSOverrides = {
              {customized property} = {
                cacheDurationInSeconds = int
                forwardDestination = "string"
                forwardPolicy = "string"
                maxConcurrent = int
                protocol = "string"
                queryLogging = "string"
                serveStale = "string"
                serveStaleDurationInSeconds = int
              }
            }
          }
          maxCount = int
          maxPods = int
          messageOfTheDay = "string"
          minCount = int
          mode = "string"
          name = "string"
          networkProfile = {
            allowedHostPorts = [
              {
                portEnd = int
                portStart = int
                protocol = "string"
              }
            ]
            applicationSecurityGroups = [
              "string"
            ]
            dranet = {
              mode = "string"
            }
            nodePublicIPPrefixIDs = [
              "string"
            ]
            nodePublicIPTags = [
              {
                ipTagType = "string"
                tag = "string"
              }
            ]
            secondaryNetworkInterfaces = [
              {
                enableAcceleratedNetworking = bool
                publicIPAddressConfiguration = {
                  ipTags = [
                    {
                      ipTagType = "string"
                      tag = "string"
                    }
                  ]
                  publicIPAddressVersion = "string"
                  publicIPPrefixID = "string"
                }
                type = "string"
                vnetSubnetId = "string"
              }
            ]
          }
          nodeImageVersion = "string"
          nodeInitializationTaints = [
            "string"
          ]
          nodeLabels = {
            {customized property} = "string"
          }
          nodePublicIPPrefixID = "string"
          nodeTaints = [
            "string"
          ]
          orchestratorVersion = "string"
          osDiskSizeGB = int
          osDiskType = "string"
          osSKU = "string"
          osType = "string"
          podIPAllocationMode = "string"
          podSubnetID = "string"
          powerState = {
            code = "string"
          }
          preparedImageSpecificationProfile = {
            preparedImageSpecificationId = "string"
          }
          proximityPlacementGroupID = "string"
          scaleDownMode = "string"
          scaleSetEvictionPolicy = "string"
          scaleSetPriority = "string"
          securityProfile = {
            enableSecureBoot = bool
            enableVTPM = bool
            sshAccess = "string"
          }
          spotMaxPrice = int
          status = {
          }
          tags = {
            {customized property} = "string"
          }
          type = "string"
          upgradeSettings = {
            drainTimeoutInMinutes = int
            maxBlockedNodes = "string"
            maxSurge = "string"
            maxUnavailable = "string"
            nodeSoakDurationInMinutes = int
            undrainableNodeBehavior = "string"
          }
          upgradeSettingsBlueGreen = {
            batchSoakDurationInMinutes = int
            drainBatchSize = "string"
            drainTimeoutInMinutes = int
            finalSoakDurationInMinutes = int
          }
          upgradeStrategy = "string"
          virtualMachineNodesStatus = [
            {
              count = int
              size = "string"
            }
          ]
          virtualMachinesProfile = {
            scale = {
              autoscale = [
                {
                  maxCount = int
                  minCount = int
                  size = "string"
                }
              ]
              manual = [
                {
                  count = int
                  size = "string"
                }
              ]
            }
          }
          vmSize = "string"
          vnetSubnetID = "string"
          windowsProfile = {
            disableOutboundNat = bool
          }
          workloadRuntime = "string"
        }
      ]
      aiToolchainOperatorProfile = {
        enabled = bool
      }
      apiServerAccessProfile = {
        authorizedIPRanges = [
          "string"
        ]
        disableRunCommand = bool
        enablePrivateCluster = bool
        enablePrivateClusterPublicFQDN = bool
        enableVnetIntegration = bool
        privateDNSZone = "string"
        subnetId = "string"
      }
      autoScalerProfile = {
        balance-similar-node-groups = "string"
        daemonset-eviction-for-empty-nodes = bool
        daemonset-eviction-for-occupied-nodes = bool
        expander = "string"
        ignore-daemonsets-utilization = bool
        max-empty-bulk-delete = "string"
        max-graceful-termination-sec = "string"
        max-node-provision-time = "string"
        max-total-unready-percentage = "string"
        new-pod-scale-up-delay = "string"
        ok-total-unready-count = "string"
        scale-down-delay-after-add = "string"
        scale-down-delay-after-delete = "string"
        scale-down-delay-after-failure = "string"
        scale-down-unneeded-time = "string"
        scale-down-unready-time = "string"
        scale-down-utilization-threshold = "string"
        scan-interval = "string"
        skip-nodes-with-local-storage = "string"
        skip-nodes-with-system-pods = "string"
      }
      autoUpgradeProfile = {
        nodeOSUpgradeChannel = "string"
        upgradeChannel = "string"
      }
      azureMonitorProfile = {
        appMonitoring = {
          autoInstrumentation = {
            enabled = bool
          }
          openTelemetryLogsAndTraces = {
            enabled = bool
            grpcPort = int
            httpPort = int
          }
          openTelemetryMetrics = {
            enabled = bool
            grpcPort = int
            httpPort = int
          }
        }
        containerInsights = {
          containerNetworkLogs = "string"
          disablePrometheusMetricsScraping = bool
          enabled = bool
          logAnalyticsWorkspaceResourceId = "string"
          syslogPort = int
        }
        metrics = {
          controlPlane = {
            enabled = bool
          }
          enabled = bool
          kubeStateMetrics = {
            metricAnnotationsAllowList = "string"
            metricLabelsAllowlist = "string"
          }
        }
      }
      bootstrapProfile = {
        artifactSource = "string"
        containerRegistryId = "string"
      }
      controlPlaneScalingProfile = {
        scalingSize = "string"
      }
      creationData = {
        sourceResourceId = "string"
      }
      disableLocalAccounts = bool
      diskEncryptionSetID = "string"
      dnsPrefix = "string"
      enableFIPS = bool
      enableNamespaceResources = bool
      enableNodeHardening = bool
      enableRBAC = bool
      fqdnSubdomain = "string"
      healthMonitorProfile = {
        enableContinuousControlPlaneAndAddonMonitor = bool
        enableOnDemandMonitor = bool
      }
      hostedSystemProfile = {
        enabled = bool
        nodeSubnetID = "string"
        systemNodeSubnetID = "string"
      }
      httpProxyConfig = {
        enabled = bool
        httpProxy = "string"
        httpsProxy = "string"
        noProxy = [
          "string"
        ]
        trustedCa = "string"
      }
      identityProfile = {
        {customized property} = {
          clientId = "string"
          objectId = "string"
          resourceId = "string"
        }
      }
      ingressProfile = {
        applicationLoadBalancer = {
          enabled = bool
        }
        gatewayAPI = {
          installation = "string"
        }
        webAppRouting = {
          defaultDomain = {
            enabled = bool
          }
          dnsZoneResourceIds = [
            "string"
          ]
          enabled = bool
          gatewayAPIImplementations = {
            appRoutingIstio = {
              mode = "string"
            }
          }
          nginx = {
            defaultIngressControllerType = "string"
          }
        }
      }
      kubernetesVersion = "string"
      linuxProfile = {
        adminUsername = "string"
        ssh = {
          publicKeys = [
            {
              keyData = "string"
            }
          ]
        }
      }
      metricsProfile = {
        costAnalysis = {
          enabled = bool
        }
      }
      networkProfile = {
        advancedNetworking = {
          enabled = bool
          observability = {
            enabled = bool
          }
          performance = {
            accelerationMode = "string"
          }
          security = {
            advancedNetworkPolicies = "string"
            enabled = bool
            transitEncryption = {
              type = "string"
            }
          }
        }
        bastionProfile = {
          enabled = bool
          publicIpAddressId = "string"
          scaleUnits = int
          sku = "string"
        }
        dnsServiceIP = "string"
        ipFamilies = [
          "string"
        ]
        kubeProxyConfig = {
          enabled = bool
          ipvsConfig = {
            scheduler = "string"
            tcpFinTimeoutSeconds = int
            tcpTimeoutSeconds = int
            udpTimeoutSeconds = int
          }
          mode = "string"
        }
        loadBalancerProfile = {
          allocatedOutboundPorts = int
          backendPoolType = "string"
          clusterServiceLoadBalancerHealthProbeMode = "string"
          enableMultipleStandardLoadBalancers = bool
          idleTimeoutInMinutes = int
          managedOutboundIPs = {
            count = int
            countIPv6 = int
          }
          outboundIPPrefixes = {
            publicIPPrefixes = [
              {
                id = "string"
              }
            ]
          }
          outboundIPs = {
            publicIPs = [
              {
                id = "string"
              }
            ]
          }
        }
        loadBalancerSku = "string"
        natGatewayId = "string"
        natGatewayProfile = {
          idleTimeoutInMinutes = int
          managedOutboundIPProfile = {
            count = int
            countIPv6 = int
          }
          outboundIPPrefixes = {
            publicIPPrefixes = [
              "string"
            ]
          }
          outboundIPs = {
            publicIPs = [
              "string"
            ]
          }
          sku = "string"
        }
        networkDataplane = "string"
        networkMode = "string"
        networkPlugin = "string"
        networkPluginMode = "string"
        networkPolicy = "string"
        outboundType = "string"
        podCidr = "string"
        podCidrs = [
          "string"
        ]
        podLinkLocalAccess = "string"
        serviceCidr = "string"
        serviceCidrs = [
          "string"
        ]
        staticEgressGatewayProfile = {
          enabled = bool
        }
      }
      nodeDisruptionProfile = {
        nodeDisruptionPolicy = "string"
      }
      nodeProvisioningProfile = {
        defaultNodePools = "string"
        mode = "string"
      }
      nodeResourceGroup = "string"
      nodeResourceGroupProfile = {
        restrictionLevel = "string"
      }
      oidcIssuerProfile = {
        enabled = bool
      }
      podIdentityProfile = {
        allowNetworkPluginKubenet = bool
        enabled = bool
        userAssignedIdentities = [
          {
            bindingSelector = "string"
            identity = {
              clientId = "string"
              objectId = "string"
              resourceId = "string"
            }
            name = "string"
            namespace = "string"
          }
        ]
        userAssignedIdentityExceptions = [
          {
            name = "string"
            namespace = "string"
            podLabels = {
              {customized property} = "string"
            }
          }
        ]
      }
      privateLinkResources = [
        {
          groupId = "string"
          id = "string"
          name = "string"
          requiredMembers = [
            "string"
          ]
          type = "string"
        }
      ]
      publicNetworkAccess = "string"
      schedulerProfile = {
        upstream = {
          schedulerConfigMode = "string"
        }
      }
      securityProfile = {
        azureKeyVaultKms = {
          enabled = bool
          keyId = "string"
          keyVaultNetworkAccess = "string"
          keyVaultResourceId = "string"
        }
        customCATrustCertificates = [
          ?
        ]
        defender = {
          logAnalyticsWorkspaceResourceId = "string"
          securityGating = {
            allowSecretAccess = bool
            enabled = bool
            identities = [
              {
                azureContainerRegistry = "string"
                identity = {
                  clientId = "string"
                  objectId = "string"
                  resourceId = "string"
                }
              }
            ]
          }
          securityMonitoring = {
            enabled = bool
          }
        }
        imageCleaner = {
          enabled = bool
          intervalHours = int
        }
        imageIntegrity = {
          enabled = bool
        }
        kubernetesResourceObjectEncryptionProfile = {
          infrastructureEncryption = "string"
        }
        nodeRestriction = {
          enabled = bool
        }
        serviceAccountImagePullProfile = {
          defaultManagedIdentityId = "string"
          enabled = bool
        }
        workloadIdentity = {
          enabled = bool
        }
      }
      serviceMeshProfile = {
        istio = {
          certificateAuthority = {
            plugin = {
              certChainObjectName = "string"
              certObjectName = "string"
              keyObjectName = "string"
              keyVaultId = "string"
              rootCertObjectName = "string"
            }
          }
          components = {
            egressGateways = [
              {
                enabled = bool
                gatewayConfigurationName = "string"
                name = "string"
                namespace = "string"
              }
            ]
            ingressGateways = [
              {
                enabled = bool
                mode = "string"
              }
            ]
            proxyRedirectionMechanism = "string"
          }
          revisions = [
            "string"
          ]
        }
        mode = "string"
      }
      servicePrincipalProfile = {
        clientId = "string"
        secret = "string"
      }
      status = {
      }
      storageProfile = {
        blobCSIDriver = {
          enabled = bool
        }
        diskCSIDriver = {
          enabled = bool
        }
        fileCSIDriver = {
          enabled = bool
        }
        snapshotController = {
          enabled = bool
        }
      }
      supportPlan = "string"
      upgradeSettings = {
        overrideSettings = {
          forceUpgrade = bool
          until = "string"
        }
      }
      windowsProfile = {
        adminPassword = "string"
        adminUsername = "string"
        enableCSIProxy = bool
        gmsaProfile = {
          dnsServer = "string"
          enabled = bool
          rootDomainName = "string"
        }
        licenseType = "string"
      }
      workloadAutoScalerProfile = {
        keda = {
          enabled = bool
        }
        verticalPodAutoscaler = {
          addonAutoscaling = "string"
          enabled = bool
        }
      }
    }
    sku = {
      name = "string"
      tier = "string"
    }
  }
}

屬性值

Microsoft.ContainerService/managedClusters

Name Description Value
extendedLocation 虛擬機的擴充位置。 ExtendedLocation
身分識別 如果已設定,則為受控叢集的身分識別。 ManagedClusterIdentity
kind 這主要用來在入口網站中針對不同類型公開不同的UI體驗 字串
位置 資源所在的地理位置 字串 (必要)
name 資源名稱 string

Constraints:
最小長度 = 1
最大長度 = 63
模式 = ^[a-zA-Z0-9]$|^[a-zA-Z0-9][-_a-zA-Z0-9]{0,61}[a-zA-Z0-9]$ (必要)
properties 受控叢集的屬性。 ManagedClusterProperties
sku 受控叢集 SKU。 ManagedClusterSKU
tags 資源標籤 標記名稱和值的字典。
型別 資源類型 「Microsoft。容器服務/managedClusters@2026-06-02-預覽」

AdvancedNetworking

Name Description Value
enabled 表示啟用 AKS 叢集上可檢視性和安全性的進階網路功能。 當此設定為 true 時,除非明確停用,否則所有可檢視性和安全性功能都會設定為啟用。 如果未指定,則預設值為 false。 bool
可檢視性 可檢視性配置檔,可啟用具有歷程記錄內容的進階網路計量和流量記錄。 AdvancedNetworkingObservability
效能 設定檔可啟用使用 Azure CNI 由 Cilium 驅動的叢集的效能提升功能。 進階網路效能
安全性 安全性配置檔,以在 cilium 型叢集上啟用安全性功能。 AdvancedNetworkingSecurity

AdvancedNetworkingObservability

Name Description Value
enabled 表示在叢集上啟用進階網路可檢視性功能。 bool

進階網路效能

Name Description Value
加速模式 啟用進階網路加速選項。 這允許用戶使用 BPF 主機路由配置加速。 這只能透過 Cilium 資料平面啟用。 如果未指定,預設值為 None (無加速)。 加速模式可以在預先存在的叢集上變更。 詳細說明見https://aka.ms/acnsperformance “BpfVeth”
'None'

AdvancedNetworkingSecurity

Name Description Value
advancedNetworkPolicies 啟用高級網路策略。 這可讓用戶設定第 7 層網路原則(FQDN、HTTP、Kafka)。 原則本身必須透過 Cilium 網路原則資源進行設定,請參閱 https://docs.cilium.io/en/latest/security/policy/index.html。 這隻能在 cilium 型叢集上啟用。 如果未指定,如果 security.enabled 設定為 true,則預設值為 FQDN。 'FQDN'
'L7'
'None'
enabled 此功能可讓使用者根據 DNS (FQDN) 名稱來設定網路原則。 它只能在 cilium 型叢集上啟用。 如果未指定,則預設值為 false。 bool
transitEncryption 基於 Cilium 的集群的加密配置。 啟用后,Cilium 託管的 Pod 之間的所有流量在離開節點邊界時都將被加密。 AdvancedNetworkingSecurityTransitEncryption

AdvancedNetworkingSecurityTransitEncryption

Name Description Value
型別 配置 Pod 到 Pod 加密。 這隻能在 Cilium 型叢集上啟用。 如果未指定,預設值為 None。 「mTLS」
'None'
'WireGuard'

AgentPoolArtifactStreamingProfile

Name Description Value
enabled 成品串流可透過隨選映射載入,加速節點上容器的冷啟動。 若要使用這項功能,容器映像也必須在 ACR 上啟用成品串流。 如果未指定,則預設值為 false。 bool

AgentPoolBlueGreenUpgradeSettings

Name Description Value
batchSoakDurationInMinutes 清空一批節點後的浸泡持續時間,即清空一批節點後等待的時間量(以分鐘為單位),然後再繼續下一個批次。 如果未指定,則預設值為 15 分鐘。 int

Constraints:
最小值 = 0
最大值 = 1440
drainBatch大小 藍綠升級期間要批次清空的節點數目或百分比。 必須是非零數字。 這可以設定為整數(例如 '5')或百分比(例如 '50%')。 如果指定百分比,則它是起始升級作業的藍色節點總數百分比。 針對百分比,小數節點會四捨五入。 如果未指定,則預設值為 10%。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
drainTimeoutInMinutes 節點的清空逾時,即等待 Pod 收回和每個節點正常終止的時間量 (以分鐘為單位)。 此收回等候時間會接受等候 Pod 中斷預算。 如果超過這個時間,升級就會失敗。 如果未指定,則預設值為 30 分鐘。 int

Constraints:
最小值 = 1
最大值 = 1440
finalSoak持續時間在分鐘 節點集區的浸泡持續時間,即在移除舊節點之前,所有舊節點清空後等待的時間量 (以分鐘為單位)。 如果未指定,則預設值為 60 分鐘。 僅適用於藍綠升級策略。 int

Constraints:
最小值 = 0
最大值 = 10080

AgentPoolGatewayProfile

Name Description Value
publicIPPrefixSize 網關代理程式集區會為每個靜態輸出閘道建立一個公用IPPrefix的關聯,以提供公用輸出。 用戶應該選取公用IPPrefix的大小。 代理程式集區中的每個節點都會從IPPrefix指派一個IP。 因此,IPPrefix 大小會做為閘道代理程式集區大小的上限。 由於 Azure 公開 IPPrefix 大小限制,有效值範圍為 [28, 31](/31 = 2 節點/IP,/30 = 4 節點/IP,/29 = 8 節點/IP,/28 = 16 節點/IP)。 預設值為 31。 int

Constraints:
最小值 = 28
最大值 = 31

代理池網路介面

Name Description Value
enableAcceleratedNetworking 這個次要網卡是否啟用了加速網路。 若省略,則僅在代理池虛擬機 SKU 支援加速網路時,此設定才會自動為 true。 若驗證在不支援的 SKU 或 NIC 配置上啟用,則驗證將失敗。 bool
publicIPAddress配置 這個次要網卡的公共 IP 設定。 只有當 type 是 時 Standard才有效。 設定 publicIPAddressVersion 為為每個虛擬機的實例層級公共 IP 配置 NIC,然後可選擇性地以 ipTags 或 publicIPPrefixID來塑造。 若省略,則不會設定公共 IP。 閒置逾時是無法設定的。 如需詳細資訊,請參閱 https://aka.ms/aks/multi-nic AgentPoolNICPublicIPAddressConfiguration
型別 虛擬機上要配置的網卡類型。 “動態”
'Standard'
vnetSubnetId 將連接至次級網路介面的子網資源 ID。 當 type 是 Standard時 必須;必須是空字串(),""或當 是 type時省略。Dynamic 字串

AgentPoolNetworkProfile

Name Description Value
allowedHostPorts 允許 access 的埠範圍。 允許指定的範圍重疊。 PortRange[]
applicationSecurityGroups 應用程式安全組的標識碼,代理程式集區會在建立時產生關聯。 string[]
德拉內特 DRANET 代理池的設定。 DranetProfile
nodePublicIPPrefixIDs 節點公共 IP 前綴的資源 ID。 最多只能指定一個 IPv4 和一個 IPv6 前綴。 順序不重要;RP 則從參考資源的 publicIPAddressVersion 決定 IP 版本。 需要 enableNodePublicIP 在代理池上為真。 與頂層 nodePublicIPPrefixID 屬性互斥。 節點池建立後不可變。 要更改前綴,請刪除並重新建立節點池。 如需詳細資訊,請參閱 https://aka.ms/aks/ipv6-ilpip string[]
nodePublicIPTags 實例層級公用IP的IPTag。 IPTag[]
次要網路介面 代理池中每個虛擬機的次級網路介面設定。 每個條目都是一個範本:每個條目會在每個虛擬實例上配置一個實體網卡。 這些介面是在代理池建立時建立,且是不可變的。 清單長度必須小於網卡容量減去代理池虛擬機大小的 1(AKS 管理主要網卡)。 例如,Standard_D8a_v4虛擬機最多支援 4 個網卡,因此最多允許的次要介面數為 3 個。 對於混合 SKU VM 池,有效容量為所有 SKU 的最小值:count(次要網路介面)+ 1 <= min(maxNIC)。 如需詳細資訊,請參閱 https://aka.ms/aks/multi-nic 代理池網路介面[]

AgentPoolNICPublicIPAddressConfiguration

Name Description Value
ip標籤 IP 標籤要附加到該 NIC 分配的公共 IP。 每個標籤 ipTagType 必須是 FirstPartyUsage、 NetworkDomain或 RoutingPreference。 與 publicIPPrefixID互斥。 IPTag[]
publicIPAddress版本 為此網卡配置的公共 IP 版本。 必要條件:其存在是啟用公共 IP 配置的關鍵,因此空設定不會分配任何資料。 IPv4 是唯一被接受的值。 「IPv4」(必填)
publicIPPrefixID 公共 IP 前綴的資源 ID,用來擷取該網卡的公共 IP。 與 ipTags互斥。 字串

AgentPoolSecurityProfile

Name Description Value
enableSecureBoot 安全開機是受信任的啟動功能,可確保只有已簽署的作系統和驅動程式才能開機。 如需詳細資訊,請參閱 aka.ms/aks/trustedlaunch。 如果未指定,則預設值為 false。 bool
enableVTPM vTPM 是受信任的啟動功能,用於設定節點上本機所保留密鑰和度量的專用安全保存庫。 如需詳細資訊,請參閱 aka.ms/aks/trustedlaunch。 如果未指定,則預設值為 false。 bool
sshAccess 代理池的 SSH access 方法。 'Disabled'
“EntraId”
'LocalUser'

AgentPoolStatus

Name Description Value

AgentPoolUpgradeSettings

Name Description Value
drainTimeoutInMinutes 節點的耗盡超時。 等待收回 Pod 的時間量,以及每個節點的正常終止時間。 此收回等候時間會接受等候 Pod 中斷預算。 如果超過這個時間,升級就會失敗。 如果未指定,則預設值為 30 分鐘。 int

Constraints:
最小值 = 1
最大值 = 1440
maxBlockedNodes 當無法解析的節點行為為 Cordon 時,在代理程式集區中允許封鎖的額外節點數目或百分比上限。 這可以設定為整數(例如 '5')或百分比(例如 '50%')。 如果指定了百分比,則它是升級時代理程式集區大小總計的百分比。 針對百分比,小數節點會四捨五入。 如果未指定,預設值為 maxSurge。 這一律必須大於或等於 maxSurge。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
maxSurge 升級期間激增的節點數目或百分比上限。 這可以設定為整數(例如 '5')或百分比(例如 '50%')。 如果指定了百分比,則它是升級時代理程式集區大小總計的百分比。 針對百分比,小數節點會四捨五入。 如果未指定,則預設值為 10%。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
maxUnavailable 升級期間可以同時無法使用的節點數目或百分比上限。 這可以設定為整數(例如 '1')或百分比(例如 '5%')。 如果指定了百分比,則它是升級時代理程式集區大小總計的百分比。 針對百分比,小數節點會四捨五入。 如果未指定,則預設值為 0。 欲了解更多資訊,包括最佳實務,請參見:/azure/aks/upgrade-cluster 字串
nodeSoakDurationInMinutes 節點的soak持續時間。 清空節點並重新製作映射並移至下一個節點之前,等待的時間量(以分鐘為單位)。 如果未指定,則預設值為0分鐘。 int

Constraints:
最小值 = 0
最大值 = 30
undrainableNodeBehavior 定義升級期間無法透支節點的行為。 無法透支節點最常見的原因是 Pod 中斷預算 (PDB),但其他問題,例如 Pod 終止寬限期超過剩餘的個別節點清空逾時,或 Pod 仍在執行中狀態,也可能導致無法執行的節點。 'Cordon'
'Schedule'

AgentPoolWindowsProfile

Name Description Value
disableOutboundNat 是否在 Windows 節點中禁用 OutboundNAT。 預設值為 false。 只有在叢集 outboundType 是 NAT 閘道,且 Windows 代理程式集區未啟用節點公用 IP 時,才能停用輸出 NAT。 bool

AutoScaleProfile

Name Description Value
maxCount 指定大小的節點數目上限。 int
minCount 指定大小的節點數目下限。 int
size AKS 在建立和調整時將使用的 VM 大小,例如 'Standard_E4s_v3'、'Standard_E16s_v3' 或 'Standard_D16s_v5'。 字串

AzureKeyVaultKms

Name Description Value
enabled 是否啟用 Azure Key Vault 鍵管理服務。 默認值為 false。 bool
keyId Azure Key Vault key 的識別碼。 詳情請參見 key identifier format。 啟用 Azure Key Vault 金鑰管理服務時,此欄位為必填且必須為有效的金鑰識別碼。 當 Azure Key Vault 的金鑰管理服務被停用時,請保持欄位空。 字串
keyVaultNetworkAccess key vault的access網絡。 key vault的網絡access。 可能的值為 Public 和 Private。 Public 表示key vault允許所有網路的公開access。 Private 表示key vault會停用公共access並啟用private link。 預設值為 Public。 'Private'
'Public'
keyVaultResourceId key vault 的資源 ID。 當keyVaultNetworkAccess為 Private時,此字段是必要的,而且必須是有效的資源標識符。 當keyVaultNetworkAccess為 Public時,請將字段保留空白。 字串

堡壘簡介

Name Description Value
enabled 顯示是否啟用管理堡壘。 bool
公共 IpAddressId 與管理堡壘相關的公共 IP 位址的資源 ID。

在建立時提供時,管理堡壘會參考這個現有的公共 IP 位址,而不是建立新的。
所參考的公共 IP 位址必須與受管理叢集在同一訂閱和區域內。

若建立時未提供,AKS 會自動建立新的公開 IP 位址。

此欄位無法更新。 若要在建立後更改 IP 位址,請停用並重新啟用管理的堡壘,並使用新的公共 IP 位址。
字串
scaleUnits 管理堡壘的比例單位。 預設值為 2。 int

Constraints:
最小值 = 2
最大值 = 50
sku 管理堡壘的SKU。

僅支援標準版和高級版 SKU。
SKU 不允許降級。 要降級 SKU,請先停用再重新啟用管理堡壘並使用新的 SKU。

如需詳細資訊,請參閱 https://aka.ms/aks/BastionSKUs。
'Premium'
'Standard'

ClusterUpgradeSettings

Name Description Value
overrideSettings 覆寫的設定。 UpgradeOverrideSettings

ContainerServiceLinuxProfile

Name Description Value
adminUsername 要用於 Linux VM 的系統管理員用戶名稱。 string

Constraints:
模式 = ^[A-Za-z][-A-Za-z0-9_]*$ (必要)
ssh 這是針對在 Azure 上運行的 Linux 虛擬機的 SSH 配置。 ContainerServiceSshConfiguration (必需)

ContainerServiceNetworkProfile

Name Description Value
advancedNetworking 在叢集上啟用可檢視性和安全性功能套件的進階網路配置檔。 如需詳細資訊,請參閱 aka.ms/aksadvancednetworking。 AdvancedNetworking
堡壘簡介 與管理叢集相關的堡壘主機側寫。
如需詳細資訊,請參閱 https://aka.ms/aks/BastionConnect。
堡壘簡介
dnsServiceIP 指派給 Kubernetes DNS 服務的 IP 位址。 它必須位於 serviceCidr 中指定的 Kubernetes 服務地址範圍內。 string

Constraints:
圖案 = ^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$
ipFamilies 用來指定叢集可用IP版本的IP系列。 IP 系列可用來判斷單一堆疊或雙堆棧叢集。 對於單一堆棧,預期的值為IPv4。 針對雙堆棧,預期的值為IPv4和IPv6。 包含任何的字串數組:
'IPv4'
'IPv6'
kubeProxyConfig 保留 kube-proxy 的組態自定義。 未定義的任何值都會使用 kube-proxy 預設行為。 請參閱 https://v<version.docs.kubernetes.io/docs/reference/command-line-tools-reference/kube-proxy/ 版本,其中>版本<是以>主要版本<>次要版本<字串>表示。 Kubernetes 1.23 版會是 '1-23'。 ContainerServiceNetworkProfileKubeProxyConfig
loadBalancerProfile 叢集 load balancer 的設定檔。 ManagedClusterLoadBalancerProfile
loadBalancerSku 管理叢集的 load balancer sku。 默認值為 『standard』。 欲了解load balancer SKU 差異,請參見 Azure Load Balancer SKUs。 'basic'
「服務」
'standard'
natGatewayId 當 outboundType 為 'userAssignedNATGateway'(使用 StandardV2 公有 IP)時,NAT 閘道器用於叢集啟動時的Azure資源 ID,後端池類型為 podIP,負載平衡器類型為服務 SKU。 這個形式為:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/natGateways/{natGatewayName}'. 使用受管理的 NATGateway 時,這個欄位會自動填入。 如需詳細資訊,請參閱 https://aka.ms/aks/container-native-slb 字串
natGatewayProfile 叢集 NAT 閘道的配置檔。 ManagedClusterNATGatewayProfile
networkDataplane Kubernetes 叢集中所使用的網路數據平面。 「azure」
'cilium'
networkMode Azure CNI 所設定的網路模式。 如果 networkPlugin 不是 'azure',則無法指定這個功能。 'bridge'
'transparent'
networkPlugin 用於建置 Kubernetes 網路的網路外掛程式。 「azure」
'kubenet'
'none'
networkPluginMode 網路外掛程式應該使用的模式。 'overlay'
networkPolicy 用於建置 Kubernetes 網路的網路原則。 「azure」
'calico'
'cilium'
'none'
outboundType 輸出 (輸出) 路由方法。 這隻能在叢集建立期間設定,且稍後無法變更。 更多資訊請參見出口類型。 'loadBalancer'
'managedNATGateway'
'none'
'userAssignedNATGateway'
'userDefinedRouting'
podCidr 使用 kubenet 時,要從中指派 Pod IP 的 CIDR 表示法 IP 範圍。 string

Constraints:
圖案 = ^([0-9]{1,3}\.){3}[0-9]{1,3}(\/([0-9]|[1-2][0-9]|3[0-2]))?$
podCidrs 要從中指派 Pod IP 的 CIDR 表示法IP範圍。 單一堆棧網路應該會有一個 IPv4 CIDR。 兩個 CIDR,每個 IP 系列一個 (IPv4/IPv6),預期雙堆棧網路。 string[]
podLinkLocalAccess 定義 access to special link local addresss (Azure Instance Metadata Service,簡稱 IMDS),適用於 hostNetwork=false 的 pods。 如果未指定,則預設值為 『IMDS』。 'IMDS'
'None'
serviceCidr 要從中指派服務叢集IP的CIDR表示法IP範圍。 它不得與任何子網IP範圍重疊。 string

Constraints:
圖案 = ^([0-9]{1,3}\.){3}[0-9]{1,3}(\/([0-9]|[1-2][0-9]|3[0-2]))?$
serviceCidrs 要從中指派服務叢集IP的CIDR表示法IP範圍。 單一堆棧網路應該會有一個 IPv4 CIDR。 兩個 CIDR,每個 IP 系列一個 (IPv4/IPv6),預期雙堆棧網路。 它們不得與任何子網IP範圍重疊。 string[]
staticEgressGatewayProfile 靜態輸出閘道附加元件配置檔。 如需靜態輸出閘道的詳細資訊,請參閱 https://aka.ms/aks/static-egress-gateway。 ManagedClusterStaticEgressGatewayProfile

ContainerServiceNetworkProfileKubeProxyConfig

Name Description Value
enabled 是否要在叢集上的 kube-proxy 上啟用 (如果沒有 'kubeProxyConfig' 存在,預設會在 AKS 中啟用 kube-proxy,而不需要這些自定義專案)。 bool
ipvsConfig 保留IPVS的組態自定義。 只有在 'mode' 設定為 'IPVS' 時,才能指定。 ContainerServiceNetworkProfileKubeProxyConfigIpvsConfig
mode 指定要使用的 Proxy 模式 ('IPTABLES'、'IPVS' 或 'NFTABLES') 'IPTABLES'
'IPVS'
「NFTABLES」

ContainerServiceNetworkProfileKubeProxyConfigIpvsConfig

Name Description Value
scheduler 如需詳細資訊,請參閱 http://www.linuxvirtualserver.org/docs/scheduling.htmlIPVS排程器。 'LeastConnection'
'RoundRobin'
tcpFinTimeoutSeconds 在收到 FIN 後,用於 IPVS TCP 工作階段的逾時值,以秒為單位。 必須是正整數值。 int
tcpTimeoutSeconds 用於閑置IPVS TCP會話的逾時值,以秒為單位。 必須是正整數值。 int
udpTimeoutSeconds 用於IPVS UDP 封包的逾時值,以秒為單位。 必須是正整數值。 int

ContainerServiceSshConfiguration

Name Description Value
publicKeys 用來向Linux型VM進行驗證的SSH公鑰清單。 最多可以指定1個索引鍵。 ContainerServiceSshPublicKey[](必需)

ContainerServiceSshPublicKey

Name Description Value
keyData 用來透過 SSH 向 VM 進行驗證的憑證公鑰。 憑證必須採用 PEM 格式,且不含標頭。 字串 (必要)

CreationData

Name Description Value
sourceResourceId 這是要用來建立目標物件的來源物件的 ARM 識別碼。 字串

DelegatedResource

Name Description Value
位置 來源資源位置 - 僅供內部使用。 字串
referralResource 轉介委派的委派標識碼 (選擇性) - 僅供內部使用。 字串
resourceId 委派資源的 ARM 資源識別碼 - 僅供內部使用。 字串
tenantId 委派資源的租用戶標識碼 - 僅供內部使用。 string

Constraints:
最小長度 = 36
最大長度 = 36
圖案 = ^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$

DranetProfile

Name Description Value
mode 特工池的DRANET模式。 'Managed'
'Unmanaged'

ExtendedLocation

Name Description Value
name 擴充位置的名稱。 字串
型別 擴充位置的類型。 'EdgeZone'

GPUProfile

Name Description Value
driver 是否要安裝 GPU 驅動程式。 未指定時,預設值為 [安裝]。 'Install'
'None'
driverType 指定建立 Windows 代理程式集區時要安裝的 GPU 驅動程式類型。 如果未提供,AKS 會根據系統相容性選取驅動程式。 建立 AgentPool 之後,就無法變更此專案。 這無法在Linux AgentPools上設定。 針對Linux AgentPools,會根據系統相容性來選取驅動程式。 'CUDA'
'GRID'
nvidia NVIDIA 專用的 GPU 設定。 NvidiaGPUProfile

硬驅逐門檻

Name Description Value
記憶體可用 可使用記憶體的門檻低於該區域會觸發 pod 驅逐。 接受絕對值(例如「500英里」)或百分比值(例如「5%」)。 絕對值必須大於或等於100英里。 百分比值必須大於或等於2%。 字串
nodeFsAvailable 可用節點檔案系統空間的門檻,低於此範圍觸發 pod 驅逐。 接受絕對值(例如「1Gi」)或百分比值(例如「10%」)。 必須大於或等於系統預設值 10%。 字串
nodeFsInodesFree 節點檔案系統中可用 inode 的閾值,低於此閾值會觸發 pod 驅逐。 接受絕對 inode 計數(例如「100000」)或百分比值(例如「5%」)。 百分比值必須大於或等於系統預設的5%。 字串

IPTag

Name Description Value
ipTagType IP 標籤類型。 範例:RoutingPreference。 字串
加標籤 與公用IP相關聯的IP標籤。 範例:因特網。 字串

IstioCertificateAuthority

Name Description Value
plugin Service Mesh 的外掛程式憑證資訊。 IstioPluginCertificateAuthority

IstioComponents

Name Description Value
egressGateways Istio 輸出閘道。 IstioEgressGateway[]
ingressGateways Istio 輸入閘道。 IstioIngressGateway[]
proxyRedirectionMechanism 流量重新導向的模式。 “CNIChaining”
「初始容器」

IstioEgressGateway

Name Description Value
enabled 是否啟用輸出閘道。 布林 (必要)
gatewayConfigurationName Istio 附加元件輸出閘道的閘道組態自定義資源名稱。 啟用 Istio 輸出閘道時必須指定。 必須部署在 Istio 輸出閘道部署所在的相同命名空間中。 字串
name Istio 附加元件輸出閘道的名稱。 string

Constraints:
模式 = [a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)* (必要)
命名空間 Istio 附加元件輸出閘道應該部署在 的命名空間。 如果未指定,則預設值為 aks-istio-egress。 字串

IstioIngressGateway

Name Description Value
enabled 是否要啟用輸入閘道。 布林 (必要)
mode 輸入閘道的模式。 'External'
“內部”(必填)

IstioPluginCertificateAuthority

Name Description Value
certChainObjectName Azure Key Vault 中的 Certificate chain object name. 字串
certObjectName Azure Key Vault 中的 Intermediate certificate object name. 字串
keyObjectName Azure Key Vault 中的中介憑證私鑰物件名稱。 字串
keyVaultId 金鑰保存庫 的資源 ID。 字串
rootCertObjectName Azure Key Vault 中的根憑證物件名稱。 字串

IstioServiceMesh

Name Description Value
certificateAuthority Istio Service Mesh 證書頒發機構單位 (CA) 組態。 目前,我們僅支援外掛程式憑證,如這裡所述 https://aka.ms/asm-plugin-ca IstioCertificateAuthority
components Istio 元件設定。 IstioComponents
revisions Istio 控制平面的修訂清單。 升級未進行時,這會保留一個值。 當 Canary 升級正在進行時,這隻能保留兩個連續值。 欲了解更多資訊,請參閱:/azure/aks/istio-upgrade string[]

KubeletConfig

Name Description Value
allowedUnsafeSysctls 允許的不安全 sysctls 或 unsafe sysctl 模式清單(結尾為 *)。 string[]
containerLogMaxFiles 容器可存在的容器記錄檔數目上限。 數字必須≥ 2。 int

Constraints:
最小值 = 2
containerLogMaxSizeMB 容器記錄檔的大小上限(例如 10Mi)在輪替之前。 int
cpuCfsQuota 如果針對指定 CPU 限制的容器啟用 CPU CFS 配額強制執行。 默認值為 true。 bool
cpuCfsQuotaPeriod CPU CFS 配額期間值。 默認值為 『100 毫秒』。 有效值是具有選擇性分數和單位後綴的十進位數序列。 例如:『300ms』、『2h45m』。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 字串
cpuManagerPolicy 要使用的 CPU 管理員原則。 預設值為 『none』。 如需詳細資訊 ,請參閱 Kubernetes CPU 管理原則 。 允許的值為 『none』 和 『static』。 字串
驅逐MaxPodGracePeriodInSeconds 軟性驅逐期間,Pods終止的最大寬限期(秒數);限制艙終止寬限期秒數。 預設值為 60,當叢集 enableNodeHardening 的性質為真時會套用。 只適用於 Linux 節點池。 int

Constraints:
最小值 = 0
failSwapOn 如果設定為 true,當節點上啟用交換時,Kubelet 將無法啟動。 bool
硬驅逐閾值 Kubelet 的硬性驅逐門檻。 當未設定閾值時,系統預設值會被使用。 有關計算出的預設值,請參見 AKS 節點資源預留 。 只適用於 Linux 節點池。 硬驅逐門檻
imageGcHighThreshold 磁碟使用量的百分比,之後映射垃圾收集一律會執行。 若要停用映射垃圾收集,請將 設定為100。 預設值為85% int
imageGcLowThreshold 永遠不會執行映射垃圾收集的磁碟使用量百分比。 這無法設定高於 imageGcHighThreshold。 預設值為 80% int
kubeReserved kubelet 的保留值。 當未設定值時,會使用系統根據虛擬機大小計算的預設值。 有關計算出的預設值,請參見 AKS 節點資源預留 。 只適用於 Linux 節點池。 KubeReserved
podMaxPids 每個 Pod 的進程數目上限。 int
seccompDefault 指定套用至所有工作負載的預設 seccomp 設定檔。 如果未指定,預設會使用 『Unconfined』。 'RuntimeDefault'
'Unconfined'
soft驅逐寬限期 軟性驅逐信號的寬限期——在淘汰前必須維持多久門檻。 預設和配對規則和 softEvictionThreshold 一樣。 數值為圍棋式的持續時間字串(例如「1分30秒」);支援單位包括「NS」、「US」、「MS」、「S」、「M」及「H」。 只適用於 Linux 節點池。 軟驅逐寬限期
soft驅逐門檻 Kubelet 的軟性驅逐門檻。 當被交叉時,膠囊會在配對的 softEvictionGracePeriod 後被淘汰。 當叢集 enableNodeHardening 屬性為真時,系統預設值會生效;否則不會設定軟性驅逐。 對於每個訊號(memoryAvailable、nodeFsAvailable、nodeFsInodesFree),softEvictionThreshold 和 softEvictionGracePeriod 中的條目必須處於相同狀態:兩者皆為省略(預設)、皆非空(覆寫),或兩串皆為空(選擇退出該訊號)。 只適用於 Linux 節點池。 參見 https://kubernetes.io/docs/concepts/scheduling-eviction/node-pressure-eviction/#soft-eviction-thresholds。 軟驅逐門檻
topologyManagerPolicy 要使用的拓撲管理員原則。 如需詳細資訊,請參閱 Kubernetes 拓撲管理員。 預設值為 『none』。 允許的值為 'none'、'best-effort'、'restricted'和 'single-numa-node'。 字串

KubeReserved

Name Description Value
cpuMillicores 為 Kubernetes 系統守護程式預留的 CPU 數量,以毫核計算。 必須大於或等於140。 例如,值為 200 代表 200 公尺(0.2 CPU 核心)。 int
記憶體MB Kubernetes 系統守護程序所保留的記憶體量,以 MiB 計算。 必須大於或等於750。 int

KubernetesResourceObjectEncryptionProfile

Name Description Value
基礎設施加密 是否使用服務託管金鑰啟用 Kubernetes 資源物件的靜態加密。 有關這方面的更多資訊,請參閱 https://aka.ms/aks/kubernetesResourceObjectEncryption。 'Disabled'
'Enabled'

LinuxOSConfig

Name Description Value
swapFileSizeMB 將在每個節點上建立之交換檔案 MB 的大小。 int
sysctls Linux 代理程序節點的 Sysctl 設定。 SysctlConfig
transparentHugePageDefrag 核心是否應該積極使用記憶體壓縮,讓更多的大量頁面可供使用。 有效值為 'always'、'defer'、'defer+madvise'、'madvise' 和 'never'。 默認值為 「瘋狂」。 如需詳細資訊,請參閱 Transparent Hugepages。 字串
transparentHugePageEnabled 是否啟用透明巨頁。 有效值為 『always』、『madvise』和 『never』。 默認值為 『always』。 如需詳細資訊,請參閱 Transparent Hugepages。 字串

本地DNS虛擬

Name Description Value
cacheDurationInSeconds 緩存最大 TTL(以秒為單位)。 有關更多資訊,請參閱 緩存外掛程式 。 int
forwardDestination 要從 localDNS 轉發的 DNS 查詢的目標伺服器。 'ClusterCoreDNS'
'VnetDNS'
forwardPolicy 用於選擇上游 DNS 伺服器的轉發策略。 有關更多資訊,請參閱 forward plugin 。 '隨機'
'RoundRobin'
'Sequential'
maxConcurrent 最大併發查詢數。 有關更多資訊,請參閱 forward plugin 。 int
通訊協定 對於從 localDNS 到上游 DNS 伺服器的連接,強制執行 TCP 或首選 UDP 協定。 'ForceTCP'
'PreferUDP'
queryLogging localDNS 中 DNS 查詢的日誌級別。 'Error'
'Log'
serveStale 用於提供過時數據的策略。 有關更多資訊,請參閱 緩存外掛程式 。 'Disable'
'Immediate'
'Verify'
serveStaleDurationInSeconds 提供過時的持續時間(以秒為單位)。 有關更多資訊,請參閱 緩存外掛程式 。 int

LocalDNSProfile

Name Description Value
kubeDNSOverrides KubeDNS 覆蓋適用於來自 dnsPolicy:ClusterFirst 的 Pod 的 DNS 流量(稱為 KubeDNS 流量)。 LocalDNSProfileKubeDNSOverrides
mode localDNS 的啟用模式。 'Disabled'
'Preferred'
'Required'
vnetDNSOverrides VnetDNS 覆蓋適用於來自 dnsPolicy:default 或 kubelet 的 Pod 的 DNS 流量(稱為 VnetDNS 流量)。 LocalDNSProfileVnetDNSOverrides

LocalDNSProfileKubeDNSOverrides

Name Description Value

LocalDNSProfileVnetDNSOverrides

Name Description Value

ManagedClusterAADProfile

Name Description Value
adminGroupObjectIDs 具有叢集管理員角色的 AAD 群組物件標識符清單。 string[]
clientAppID (已淘汰)用戶端 AAD 應用程式識別碼。 了解更多資訊,請至 https://aka.ms/aks/aad-legacy。 字串
enableAzureRBAC 是否要啟用 Azure RBAC 以進行 Kubernetes 授權。 bool
Managed 是否要啟用受控 AAD。 bool
serverAppID (已淘汰)伺服器 AAD 應用程式識別碼。 了解更多資訊,請至 https://aka.ms/aks/aad-legacy。 字串
serverAppSecret (已淘汰)伺服器 AAD 應用程式秘密。 了解更多資訊,請至 https://aka.ms/aks/aad-legacy。 string

Constraints:
敏感性值。 以安全參數的形式傳入。
tenantID 要用於驗證的 AAD 租使用者識別碼。 如果未指定,將會使用部署訂用帳戶的租使用者。 字串

ManagedClusterAddonProfile

Name Description Value
config 用於設定附加元件的關鍵/值組。 ManagedClusterAddonProfileConfig
enabled 是否啟用附加元件。 布林 (必要)

ManagedClusterAddonProfileConfig

Name Description Value

ManagedClusterAgentPoolProfile

Name Description Value
artifactStreamingProfile 在 AKS 上使用成品串流的設定。 AgentPoolArtifactStreamingProfile
availabilityZones 節點可用的 Availability zones 清單。 只有在 AgentPoolType 屬性是 'VirtualMachineScaleSets' 時,才能指定這個值。 string[]
capacityReservationGroupID 容量保留群組的完全限定資源 ID,用於從保留的 虛擬機器 群組提供 virtual machines。 此形式為:'/subscriptions/{subscriptionId}/resourcegroups/{resourceGroupName}/providers/Microsoft.Compute/capacityreservationgroups/{capacityReservationGroupName}' 客戶會用它建立包含指定 CRG 的代理池。 更多資訊請參見 Capacity Reservation 字串
count 裝載 Docker 容器的代理程式 (VM) 數目。 允許的值必須介於使用者集區的 0 到 1000(含)範圍內,且系統集區的範圍為 1 到 1000(含)。 預設值為 1。 int
creationData 如果節點集區將會使用快照集建立/升級,則用來指定來源快照集標識符的 CreationData。 CreationData
enableAutoScaling 是否要啟用自動調整程式 bool
enableEncryptionAtHost 是否要啟用主機型 OS 和數據磁碟驅動器加密。 這只支援特定虛擬機大小和特定 Azure 區域。 欲了解更多資訊,請參閱:/azure/aks/enable-host-encryption bool
enableFIPS 是否要使用已啟用 FIPS 的 OS。 詳情請參見 Add a enabled FIPS node pool。 bool
enableNodePublicIP 每個節點是否配置自己的公用IP。 某些案例可能需要節點集區中的節點接收自己的專用公用IP位址。 常見的案例是遊戲工作負載,其中控制台需要直接連線到雲端虛擬機,以將躍點降到最低。 更多資訊請參見為節點分配公共 IP。 默認值為 false。 bool
enableOSDiskFullCaching 是否啟用完整快取臨時作業系統磁碟功能。 啟用此功能後,整個作業系統會被本地快取於臨時作業系統磁碟,防止因網路故障引發的 E17 事件。 bool
enableUltraSSD 是否要啟用 UltraSSD bool
gatewayProfile 閘道模式中受控代理程式集區特有的配置檔。 如果代理程式集區模式不是閘道,則無法設定此欄位。 AgentPoolGatewayProfile
gpuInstanceProfile 要用來為支援的 GPU VM SKU 指定 GPU MIG 實例設定檔的 GPUInstanceProfile。 'MIG1g'
'MIG2g'
'MIG3g'
'MIG4g'
'MIG7g'
gpuProfile 代理程式集區的 GPU 設定。 GPUProfile
hostGroupID 專用主機群組的完全限定資源 ID,用於配置virtual machines,僅用於建立情境,且設定後不得更改。 這是格式:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Compute/hostGroups/{hostGroupName}。 欲了解更多資訊,請參見 Azure dedicated hosts。 字串
kubeletConfig 代理程式集區節點上的 Kubelet 組態。 KubeletConfig
kubeletDiskType 決定空 Dir 卷的放置位置、容器執行時資料根,以及 Kubelet 臨時儲存(ephemeral storage)。 'OS'
'Temporary'
linuxOSConfig Linux 代理程序節點的 OS 組態。 LinuxOSConfig
localDNSProfile 使用 VnetDNS 和 KubeDNS 覆蓋配置每個節點的本地 DNS。 LocalDNS 有助於提高 AKS 群集中 DNS 解析的性能和可靠性。 有關更多詳細資訊,請參閱 aka.ms/aks/localdns。 LocalDNSProfile
maxCount 自動調整的節點數目上限 int
maxPods 可在節點上執行的 Pod 數目上限。 int
messageOfTheDay Linux 節點當天的訊息,base64 編碼。 base64 編碼的字串,將在譯碼之後寫入 /etc/motd。 這允許自定義 Linux 節點當天的訊息。 它不得指定給 Windows 節點。 它必須是靜態字串(也就是將列印為未經處理,而不是以腳本的形式執行)。 字串
minCount 自動調整的節點數目下限 int
mode 代理程式集區的模式。 叢集必須隨時至少有一個「系統」代理程式集區。 欲了解更多關於代理池限制與最佳實務的資訊,請參閱:/azure/aks/use-system-pools 'Gateway'
'Machines'
'ManagedSystem'
'System'
'User'
name 訂用帳戶和資源群組內容中代理程式集區配置檔的唯一名稱。 Windows 代理程式集區名稱必須是 6 個字元或更少。 string

Constraints:
模式 = ^[a-z][a-z0-9]{0,11}$ (必要)
networkProfile 代理程式集區的網路相關設定。 AgentPoolNetworkProfile
nodeImageVersion (節點映射版本) 節點映像的版本。 設定此值會觸發 agentPool 回滾。
只允許輸入 的 recentlyUsedVersions 值。
字串
nodeInitializationTaints 建立期間在節點上新增的Taints不會由AKS協調。 這些污點不會由 AKS 協調,而且可以使用 kubectl 呼叫移除。 建立節點集區之後,即可修改此字段,但在需要重新建立另一項作業(例如節點映射升級)之前,節點將不會以新的污點重新建立。 這些污點允許在節點準備好接受工作負載之前執行必要的設定,例如 『key1=value1:NoSchedule』,然後可以使用 移除 kubectl taint nodes node1 key1=value1:NoSchedule- string[]
nodeLabels 要跨代理程式集區中所有節點保存的節點標籤。 ManagedClusterAgentPoolProfilePropertiesNodeLabels
nodePublicIPPrefixID VM 節點應該使用IP的公用IP前置詞標識碼。 格式如下:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/publicIPPrefixes/{publicIPPrefixName} 字串
nodeTaints 節點集區建立和調整期間新增至新節點的污點。 例如,key=value:NoSchedule。 string[]
orchestratorVersion 使用者指定的 Kubernetes 版本。 支援修補程式版本 <major.minor.patch> (例如 1.20.13)和 <major.minor> (例如 1.20)。 指定 major.minor< 時>,會自動選擇最新支援的 GA 修補程式版本。 在建立叢集之後,以相同的 <major.minor> 更新叢集(例如 1.14.x -> 1.14)將不會觸發升級,即使有較新的修補程式版本也一樣。 最佳做法是,您應該將 AKS 叢集中的所有節點集區升級為相同的 Kubernetes 版本。 節點集區版本必須與控制平面具有相同的主要版本。 節點集區次要版本必須位於控制平面版本的兩個次要版本內。 節點集區版本不能大於控制平面版本。 更多資訊請參見升級節點池。 字串
osDiskSizeGB OS 磁碟大小 GB,用來指定主要/代理程式集區中每部計算機的磁碟大小。 如果您指定 0,它會根據指定的 vmSize 套用預設 osDisk 大小。 int

Constraints:
最小值 = 0
最大值 = 2048
osDiskType 要用於代理程式集區中機器的 OS 磁碟類型。 如果 VM 支援,且快取磁碟大於要求的 OSDiskSizeGB,則預設值為 「暫時」。 否則,預設為 「受控」。 建立之後可能不會變更。 更多資訊請參見 Ephemeral OS。 'Ephemeral'
'Managed'
osSKU 指定代理程式集區所使用的 OS SKU。 如果OSType為Linux,則預設值為Ubuntu。 當 Kubernetes <= 1.24 或 Windows2022 時,如果 OSType >為 Windows,則預設值為 Windows2019。 'AzureContainerLinux'
'AzureLinux'
'AzureLinux3'
'CBLMariner'
“平車”
'Mariner'
'Ubuntu'
'Ubuntu2204'
'Ubuntu2404'
「Ubuntu2604」
'Windows2019'
'Windows2022'
“窗戶2025”
'WindowsAnnual'
osType 作系統類型。 預設值為Linux。 'Linux'
'Windows'
podIPAllocationMode Pod IP 分配模式。 代理程式集區中 Pod 的 IP 配置模式。 必須與 podSubnetId 搭配使用。 預設值為 『DynamicIndividual』。 'DynamicIndividual'
'StaticBlock'
podSubnetID 啟動時,Pod 會加入之子網的標識碼。 如果省略,則會在節點子網上靜態指派 Pod IP(如需詳細資訊,請參閱 vnetSubnetID)。 格式如下:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/virtualNetworks/{virtualNetworkName}/subnets/{subnetName} 字串
powerState 代理程式集區正在執行或停止。 第一次建立代理程式集區時,它一開始會執行。 您可以將此欄位設定為 [已停止] 來停止代理程式集區。 已停止的代理程式集區會停止其所有 VM,而不會產生計費費用。 只有在執行中且布建狀態為 [成功] 時,才能停止代理程式集區 PowerState
preparedImageSpecificationProfile 設定用以確定用於配置池中節點的已準備映像規格。 PreparedImageSpecificationProfile
proximityPlacementGroupID 鄰近放置群組的標識碼。 字串
scaleDownMode 調整代理程式集區時要使用的相應減少模式。 這也會影響叢集自動調整程序的行為。 如果未指定,則預設為 Delete。 'Deallocate'
'Delete'
scaleSetEvictionPolicy 虛擬機器擴展集收回原則。 驅逐政策會明確說明當虛擬機被驅逐時to do什麼。 預設值為刪除。 欲了解更多驅逐資訊,請參見 spot VMs 'Deallocate'
'Delete'
scaleSetPriority 虛擬機擴展集優先順序。 'Regular'
'Spot'
securityProfile 代理程式集區的安全性設定。 AgentPoolSecurityProfile
spotMaxPrice 您願意為現成實例支付的最高價格(以美元為單位)。 可能的值為大於零或 -1 的任何十進位值,表示依需求 up-to 默認價格。 可能的值為大於零或 -1 的任何十進位值,表示願意支付任何隨選價格。 欲了解更多現貨價格,請參閱 spot VMs 價格 int
狀態 包含代理程式集區的唯讀資訊。 AgentPoolStatus
tags 要保存在代理程式集區虛擬機擴展集上的標記。 ManagedClusterAgentPoolProfilePropertiesTags
型別 Agent 集區的類型。 'AvailabilitySet'
「FlexNodes」
'VirtualMachines'
'VirtualMachineScaleSets'
upgradeSettings 升級代理程式集池的設定 AgentPoolUpgradeSettings
升級設定藍綠 代理程式集區上 Blue-Green 升級的設定。 當升級策略設定為 BlueGreen 時適用。 AgentPoolBlueGreenUpgradeSettings
升級策略 定義代理程式集區的升級策略。 預設值為滾動。 “藍綠”
'Rolling'
virtualMachineNodesStatus VirtualMachines 代理程式集區中的節點狀態。 VirtualMachineNodes[]
virtualMachinesProfile VirtualMachines 代理程式集區的規格。 VirtualMachinesProfile
vmSize 代理程式集區 VM 的大小。 VM 大小可用性會因區域而異。 如果節點包含計算資源不足(記憶體、cpu 等)Pod 可能無法正確執行。 欲了解更多關於受限虛擬機大小的細節,請參閱:/azure/aks/quotas-skus-regions 字串
vnetSubnetID 代理程式集區節點和選擇性 Pod 將在啟動時加入的子網標識碼。 如果未指定此專案,則會產生及使用 VNET 和子網。 如果未指定 podSubnetID,這會套用至節點和 Pod,否則只會套用至節點。 格式如下:/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Network/virtualNetworks/{virtualNetworkName}/subnets/{subnetName} 字串
windowsProfile Windows 代理程式集區的特定配置檔。 AgentPoolWindowsProfile
workloadRuntime 決定節點可執行的工作負載類型。 'KataMshvVmIsolation'
“KataVm隔離”
'OCIContainer'
'WasmWasi'

ManagedClusterAgentPoolProfilePropertiesNodeLabels

Name Description Value

ManagedClusterAgentPoolProfilePropertiesTags

Name Description Value

ManagedClusterAIToolchainOperatorProfile

Name Description Value
enabled 是否為集群啟用 AI toolchain Operator。 指出 AI 工具鏈運算子是否啟用。 bool

ManagedClusterAPIServerAccessProfile

Name Description Value
authorizedIPRanges 授權access Kubernetes API 伺服器的 IP 範圍。 IP 範圍以 CIDR 格式指定,例如 137.117.106.88/29。 此功能不相容於使用公共 IP 逐節點的叢集,或使用 Basic Load Balancer 的叢集。 欲了解更多資訊,請參閱 API 伺服器授權 IP 範圍。 string[]
disableRunCommand 是否要停用叢集的執行命令。 bool
enablePrivateCluster 是否要將叢集建立為私人叢集。 更多細節請參見 建立私人 AKS 叢集。 bool
enablePrivateClusterPublicFQDN 是否要為私人叢集建立其他公用 FQDN。 bool
enableVnetIntegration 是否要啟用叢集的apiserver vnet整合。 有關詳細資訊,請參閱 aka.ms/AksVnetIntegration。 bool
privateDNSZone 叢集的 private DNS 區域模式。 預設值為 System。 更多細節請參見 configure private DNS zone。 允許的值為 'system' 和 'none'。 字串
subnetId 啟用apiserver vnet整合時要使用的子網。 使用 BYO Vnet 創建新集群時,或者更新現有集群以啟用 apiserver vnet 集成時,需要它。 字串

ManagedClusterAppRoutingIstio

Name Description Value
mode 是否要啟用 Istio 作為 Gateway API 實作,用於管理式的 App 路由。 'Disabled'
'Enabled'

ManagedClusterAutoUpgradeProfile

Name Description Value
nodeOSUpgradeChannel 節點作系統升級通道。 更新節點上OS的方式。 預設值為 NodeImage。 'NodeImage'
'None'
'SecurityPatch'
'Unmanaged'
upgradeChannel 自動升級的升級通道。 預設值為 『none』。 更多資訊請參見 setting AKS 叢集自動升級通道。 'node-image'
'none'
'patch'
'rapid'
'stable'

ManagedClusterAzureMonitorProfile

Name Description Value
appMonitoring Kubernetes 應用程式容器的應用程式監視配置檔。 透過使用 Azure 監視器 OpenTelemetry 基礎的 SDK 自動監控應用程式,收集應用程式日誌、度量與追蹤資料。 如需概觀,請參閱 aka.ms/AzureMonitorApplicationMonitoring。 ManagedClusterAzureMonitorProfileAppMonitoring
containerInsights 設定此為啟用並設定叢集的 Azure 監視器 Container Insights,該叢集會收集 Kubernetes 事件、庫存,以及容器的標準與測試日誌。 如需概觀,請參閱 aka.ms/AzureMonitorContainerInsights。 ManagedClusterAzureMonitorProfileContainerInsights
計量 適用於 Prometheus 附加元件之 Azure 監視器受控服務的計量配置檔。 收集開箱即用的 Kubernetes 基礎架構指標,傳送至 Azure 監視器 工作區,並為自訂目標設定額外的爬蟲功能。 如需概觀,請參閱 aka.ms/AzureManagedPrometheus。 ManagedClusterAzureMonitorProfileMetrics

ManagedClusterAzureMonitorProfileAppMonitoring

Name Description Value
autoInstrumentation 應用監控 AKS 自動儀器化。 部署一個 webhook,自動與 Microsoft OpenTelemetry 發行版進行工作負載的測量,以收集 OpenTelemetry 的指標、日誌與追蹤資料。 請參閱 https://aka.ms/AKSAppMonitoringDocs 及 https://aka.ms/AzureMonitorApplicationMonitoring 以了解整體概覽。 ManagedClusterAzureMonitorProfileAppMonitoringAutoInstrumentation
開放遙測日誌與追蹤 應用程式監控 OpenTelemetry 的 AKS 日誌與追蹤設定檔。 利用 Azure 監視器 OpenTelemetry 基礎的 SDK 收集 OpenTelemetry 日誌與應用程式的追蹤資料。 請參閱 https://aka.ms/AKSAppMonitoringDocs 及 https://aka.ms/AzureMonitorApplicationMonitoring 以了解整體概覽。 ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryLogsAndTraces
openTelemetryMetrics 應用程式監控 OpenTelemetry 指標設定檔用於 AKS。 利用 Azure 監視器 OpenTelemetry 基礎的 SDK 收集應用程式的 OpenTelemetry 指標。 請參閱 https://aka.ms/AKSAppMonitoringDocs 及 https://aka.ms/AzureMonitorApplicationMonitoring 以了解整體概覽。 ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryMetrics

ManagedClusterAzureMonitorProfileAppMonitoringAutoInstrumentation

Name Description Value
enabled 指示是否啟用應用程式監控自動儀器。 bool

ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryLogsAndTraces

Name Description Value
enabled 指示是否啟用應用程式監控 OpenTelemetry 日誌與追蹤功能。 bool
grpcPort OpenTelemetry GRPC 的主機埠是日誌與追蹤。 若未指定,預設埠口為 28332。 int
httpPort OpenTelemetry HTTP/PROTOBUF 日誌與追蹤的主機埠。 如果未指定,預設埠為 28331。 int

ManagedClusterAzureMonitorProfileAppMonitoringOpenTelemetryMetrics

Name Description Value
enabled 指示是否啟用應用程式監控 OpenTelemetry Metrics。 bool
grpcPort OpenTelemetry GRPC 指標的主機埠。 如果未指定,預設埠口為 28334。 int
httpPort OpenTelemetry HTTP/PROTOBUF 指標的主機埠。 如果未指定,預設埠為 28333。 int

ManagedClusterAzureMonitorProfileContainerInsights

Name Description Value
containerNetworkLogs 容器網路日誌 用 Azure 監視器 配置容器網路日誌的攝取。 所攝取的日誌類型由相關的CRD控制;若未指定,則預設為 Disabled。 詳情請參閱 https://aka.ms/ContainerNetworkLogsDoc 及https://aka.ms/acns/howtoenablecnl 'Disabled'
'Enabled'
disablePrometheusMetricsScraping 指出是否停用 prometheus 計量擷取。 若未指定,預設為 false,也就是說 prometheus 抓取已被啟用。 bool
enabled 指示是否啟用 Azure 監視器 容器 Insights Logs 外掛。 bool
logAnalyticsWorkspaceResourceId Azure Log Analytics Workspace 的完全合格 ARM 資源 ID 用於儲存 Azure 監視器 容器 Insights Logs. 字串
syslogPort syslog 主機埠。 如果未指定,預設埠為 28330。 int

ManagedClusterAzureMonitorProfileKubeStateMetrics

Name Description Value
metricAnnotationsAllowList 將在資源標籤量中使用的 Kubernetes 批註索引鍵逗號分隔清單(範例:'namespaces=[kubernetes.io/team,...],pods=[kubernetes.io/team],...')。 根據預設,計量只包含資源名稱和命名空間標籤。 字串
metricLabelsAllowlist 將用於資源標籤計量的其他 Kubernetes 標籤索引鍵逗號分隔清單(範例:'namespaces=[k8s-label-1,k8s-label-n,...],pods=[app],...')。 根據預設,計量只包含資源名稱和命名空間標籤。 字串

ManagedClusterAzureMonitorProfileMetrics

Name Description Value
controlPlane的 Control plane metrics collection profile for the Azure Managed Prometheus addon. 配置來自受管理控制平面元件(如 kube-apiserver、etcd 等)的運作執行時指標收集。 請參見 aka.ms/aks/controlplane-metrics 以了解整體概覽。 ManagedClusterAzureMonitorProfileMetricsControlPlane
enabled 是否啟用或停用 Azure Managed Prometheus 外掛以監控 Prometheus。 如需啟用和停用的詳細資訊,請參閱 aka.ms/AzureManagedPrometheus-aks-enable。 布林 (必要)
kubeStateMetrics Azure 受控 Prometheus 附加元件 Kube 狀態計量配置檔。 這些選擇性設定適用於使用附加元件部署的 kube-state-metrics Pod。 如需詳細資訊,請參閱 aka.ms/AzureManagedPrometheus-optional-parameters。 ManagedClusterAzureMonitorProfileKubeStateMetrics

ManagedClusterAzureMonitorProfileMetricsControlPlane

Name Description Value
enabled 是否啟用或停用 Azure Managed Prometheus 外掛的控制平面指標收集。 預設為停用。 詳情請參見 aka.ms/aks/controlplane-metrics。 bool

ManagedClusterBootstrapProfile

Name Description Value
artifactSource 成品來源。 下載這些 artifacts 的來源。 'Cache'
'Direct'
containerRegistryId The resource ID of Azure Container Registry. 登錄檔必須具備私有網路access、高級 SKU 及區域冗餘。 字串

ManagedClusterControlPlaneScalingProfile

Name Description Value
縮放大小 控制平面的縮放尺寸。 縮放規模提供保證容量與可預測的 Kubernetes 效能,超越標準預設。 較大的H尺寸能提供更高的性能保證。 請參閱 https://aka.ms/aks/hyperscale 各尺寸的效能指標細節。 「H2」
「H4」
「H8」(必填)

ManagedClusterCostAnalysis

Name Description Value
enabled 是否啟用成本分析。 受控叢集 sku.tier 必須設定為 「標準」或「進階」,才能啟用此功能。 啟用此功能後,Kubernetes 命名空間與部署細節會加入 Azure portal 的成本分析檢視。 如果未指定,則預設值為 false。 如需詳細資訊,請參閱 aka.ms/aks/docs/cost-analysis。 bool

ManagedClusterHealthMonitorProfile

Name Description Value
啟用持續控制平面與附加監控器 是否啟用連續控制平面和附加元件監控。 bool
enableOnDemandMonitor 是否啟用隨選監控。 bool

ManagedClusterHosted系統設定檔

Name Description Value
enabled 是否要為叢集啟用託管系統附加元件。 bool
nodeSubnetID 由 node auto provisioner 管理的工作節點加入的子網 ID,用於在租戶中執行工作負載 Pod。 這必須與 systemNodeSubnetID 和 apiserverAccessProfile.subnetId一起提供,且三個子網 ID 必須在同一個 VNet 中。 如果你沒特別指定,AKS 會在管理資源群組中用預設的 /16 CIDR 建立一個子網路。 字串
systemNodeSubnetID 由 AKS 管理並託管的系統節點加入的子網 ID,用於執行關鍵系統附加元件。 此 ID 必須與 nodeSubnetIDapiserverAccessProfile.subnetId及 一同提供,且三個子網 ID 必須屬於同一個 VNet。 如果你沒特別指定,AKS 會在管理資源群組中用預設的 /26 CIDR 建立子網路。 字串

ManagedClusterHttpProxyConfig

Name Description Value
enabled 是否開啟 HTTP 代理。 若停用,指定的代理設定將不會被設定在 pods 和節點上。 如果未指定,則預設值為 true。 bool
httpProxy 要使用的 HTTP Proxy 伺服器端點。 字串
httpsProxy 要使用的 HTTPS Proxy 伺服器端點。 字串
noProxy 不應該通過 Proxy 的端點。 string[]
trustedCa 用來連線到 Proxy 伺服器的替代 CA 憑證。 字串

ManagedClusterIdentity

Name Description Value
delegatedResources 指派給此受控叢集的委派身分識別資源。 這只能由其他 Azure 資源提供者設定,而受管理叢集只接受一個委派的身份資源。 僅供內部使用。 ManagedClusterIdentityDelegatedResources
型別 用於受控叢集的身分識別類型。 欲了解更多資訊,請參閱 AKS 中的 use 管理身份。 'None'
'SystemAssigned'
'UserAssigned'
userAssignedIdentities 與受控叢集相關聯的使用者身分識別。 此身分識別將用於控制平面。 只允許一個使用者指派的身分識別。 密鑰必須是 ARM 資源識別符,格式為:『/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}'。 ManagedClusterIdentityUserAssignedIdentities

ManagedClusterIdentityDelegatedResources

Name Description Value

ManagedClusterIdentityUserAssignedIdentities

Name Description Value

ManagedClusterIngressDefaultDomainProfile

Name Description Value
enabled 是否啟用預設網域。 bool

ManagedClusterIngressProfile

Name Description Value
applicationLoadBalancer 管理式 Application Load Balancer 安裝設定 ManagedClusterIngressProfileApplicationLoadBalancer
閘道API 託管閘道 API 安裝的設置 ManagedClusterIngressProfileGateway配置
webAppRouting 輸入設定檔的應用程式路由設定。 你可以在 /azure/aks/app-routing?tabs=default%2Cdeploy-app-default 找到此功能的概述與入職指南。 ManagedClusterIngressProfileWebAppRouting

ManagedClusterIngressProfileApplicationLoadBalancer

Name Description Value
enabled 是否啟用 Application Load Balancer。 bool

ManagedClusterIngressProfileGateway配置

Name Description Value
安裝 託管閘道 API 安裝的配置。 如果未指定,則預設值為“禁用”。 如需詳細資訊,請參閱 https://aka.ms/k8s-gateway-api。 'Disabled'
'Standard'

ManagedClusterIngressProfileNginx

Name Description Value
defaultIngressControllerType 默認 NginxIngressController 自訂資源的輸入類型 'AnnotationControlled'
'External'
'Internal'
'None'

ManagedClusterIngressProfileWebAppRouting

Name Description Value
預設網域 預設網域的設定。 這是一個唯一的自動生成域,帶有簽名的 TLS 證書,允許安全的 HTTPS。 更多說明 請參閱預設網域文件 。 ManagedClusterIngressDefaultDomainProfile
dnsZoneResourceIds 要與應用程式路由附加元件相關聯的 DNS 區域資源識別碼。 只有在啟用應用程式路由附加元件時才使用。 公有與 private DNS 區域可以屬於不同的資源群組,但所有公共 DNS 區域必須屬於同一資源群組,且所有 private DNS 區域必須在同一資源群組中。 string[]
enabled 是否要啟用應用程式路由附加元件。 bool
gatewayAPIImplementations 閘道 API 提供者用於管理式 App Routing 的設定。 欲了解更多關於閘道 API(Gateway API)的資訊,請參閱 https://aka.ms/k8s-gateway-api 此處。 ManagedClusterWebAppRoutingGatewayAPIImplementations
nginx 默認 NginxIngressController 的組態。 詳情請見 /azure/aks/app-routing-nginx-configuration#the-default-nginx-ingress-controller。 ManagedClusterIngressProfileNginx

ManagedClusterLoadBalancerProfile

Name Description Value
allocatedOutboundPorts 每個 VM 所需配置的 SNAT 埠數目。 允許的值介於 0 到 64000 的範圍內(含)。 預設值是 0,這會導致 Azure 動態分配埠口。 int

Constraints:
最小值 = 0
最大值 = 64000
backendPoolType 受管理的入站 Load Balancer BackendPool 類型。 'NodeIP'
'NodeIPConfiguration'
「PodIP」
clusterServiceLoadBalancerHealthProbeMode 外部流量原則叢集服務的健全狀況探查行為。 'ServiceNodePort'
“共用”
enableMultipleStandardLoadBalancers 為每個 AKS 叢集啟用多個標準負載平衡器。 bool
idleTimeoutInMinutes 所需的輸出流程閑置逾時,以分鐘為單位。 允許的值介於 4 到 120 之間(含)。 預設值為 30 分鐘。 int

Constraints:
最小值 = 4
最大值 = 120
managedOutboundIPs 叢集load balancer想要的託管外站 IP。 ManagedClusterLoadBalancerProfileManagedOutboundIPs
outboundIPPrefixes 叢集load balancer的期望外撥 IP 前綴資源。 ManagedClusterLoadBalancerProfileOutboundIPPrefixes
outboundIPs 叢集load balancer的期望外撥 IP 資源。 ManagedClusterLoadBalancerProfileOutboundIPs

ManagedClusterLoadBalancerProfileManagedOutboundIPs

Name Description Value
count Azure為叢集建立/管理的 IPv4 外站 IP 數量load balancer。 允許的值必須介於 1 到 100 的範圍內(含)。 預設值為 1。 int

Constraints:
最小值 = 1
最大值 = 100
countIPv6 Azure為叢集建立/管理的 IPv6 外撥 IP 數量load balancer。 允許的值必須介於 1 到 100 的範圍內(含)。 單一堆棧的預設值為0,雙堆疊的預設值為1。 int

Constraints:
最小值 = 0
最大值 = 100

ManagedClusterLoadBalancerProfileOutboundIPPrefixes

Name Description Value
publicIPPrefixes 公用IP前置資源的清單。 ResourceReference[]

ManagedClusterLoadBalancerProfileOutboundIPs

Name Description Value
publicIPs 公用IP資源的清單。 ResourceReference[]

ManagedClusterManagedOutboundIPProfile

Name Description Value
count Azure 建立/管理的期望出站 IP 數量。 允許的值必須介於 1 到 16 的範圍內(含)。 預設值為 1。 int

Constraints:
最小值 = 1
最大值 = 16
countIPv6 Azure 所建立/管理的 IPv6 外站 IP 數量。 允許的值必須介於 1 到 16 的範圍內(含)。 int

Constraints:
最小值 = 1
最大值 = 16

ManagedClusterMetricsProfile

Name Description Value
costAnalysis 每個 Kubernetes 資源成本分析的詳細設定。 ManagedClusterCostAnalysis

ManagedClusterNATGatewayProfile

Name Description Value
idleTimeoutInMinutes 所需的輸出流程閑置逾時,以分鐘為單位。 允許的值介於 4 到 120 之間(含)。 預設值為 4 分鐘。 int

Constraints:
最小值 = 4
最大值 = 120
managedOutboundIPProfile 叢集 NAT 閘道的受控輸出 IP 資源設定檔。 ManagedClusterManagedOutboundIPProfile
outboundIPPrefixes 管理 NAT 閘道所需的外撥 IP 前綴資源。 僅相容於 NAT Gateway V2。 ManagedClusterNATGatewayProfileOutboundIPPrefixes
outboundIPs 管理 NAT 閘道器的期望外站 IP 資源。 ManagedClusterNATGatewayProfileOutboundIPS
sku 管理叢集 NAT 閘道器的 SKU。 預設為「StandardV2」(區域區域適用),否則為「Standard」。 'Standard'
'StandardV2'

ManagedClusterNATGatewayProfileOutboundIPPrefixes

Name Description Value
publicIPPrefixes 公用IP前置資源的清單。 string[]

ManagedClusterNATGatewayProfileOutboundIPS

Name Description Value
publicIPs 公用IP資源的清單。 string[]

ManagedClusterNodeProvisioningProfile

Name Description Value
defaultNodePools 為節點預置配置的預設 Karpenter 節點池 (CRD) 集。 除非mode為 'Auto',否則此欄位無效。 警告:在現有集群上將其從 Auto 更改為 None 將導致預設的 Karpenter NodePools 被刪除,這將耗盡並刪除與這些池關聯的節點。 強烈建議不要這樣做,除非有空閒節點準備好接收該作驅逐的 Pod。 如果未指定,則預設值為 Auto。有關更多資訊,請參閱 aka.ms/aks/nap#node-pools。 'Auto'
'None'
mode 節點布建模式。 如果未指定,則預設值為Manual。 'Auto'
'Manual'

ManagedClusterNodeResourceGroupProfile

Name Description Value
restrictionLevel 套用至叢集節點資源群組的限制層級。 如果未指定,預設值為 'Unrestricted' 'ReadOnly'
'Unrestricted'

ManagedClusterOidcIssuerProfile

Name Description Value
enabled 是否啟用 OIDC 簽發者。 bool

ManagedClusterPodIdentity

Name Description Value
bindingSelector 要用於 AzureIdentityBinding 資源的系結選取器。 字串
身分識別 使用者指派的身分識別詳細數據。 UserAssignedIdentity (必需)
name Pod 身分識別的名稱。 字串 (必要)
命名空間 Pod 身分識別的命名空間。 字串 (必要)

ManagedClusterPodIdentityException

Name Description Value
name Pod 身分識別例外狀況的名稱。 字串 (必要)
命名空間 Pod 身分識別例外狀況的命名空間。 字串 (必要)
podLabels 要比對的 Pod 標籤。 ManagedClusterPodIdentityExceptionPodLabels (必需)

ManagedClusterPodIdentityExceptionPodLabels

Name Description Value

ManagedClusterPodIdentityProfile

Name Description Value
allowNetworkPluginKubenet 是否允許Pod身分識別在具有 Kubenet 網路的叢集上執行。 根據預設,在 Kubenet 中執行會因為 AAD Pod 身分識別的安全性相關本質和 IP 詐騙的風險而停用。 更多資訊請參閱 using Kubenet network plugin with AAD Pod Identity。 bool
enabled 是否啟用Pod身分識別附加元件。 bool
userAssignedIdentities 叢集中要使用的Pod身分識別。 ManagedClusterPodIdentity[]
userAssignedIdentityExceptions 允許的Pod身分識別例外狀況。 ManagedClusterPodIdentityException[]

ManagedClusterProperties

Name Description Value
aadProfile Azure Active Directory配置。 ManagedClusterAADProfile
addonProfiles 受控叢集附加元件配置檔。 ManagedClusterPropertiesAddonProfiles
agentPoolProfiles 代理程式集區屬性。 ManagedClusterAgentPoolProfile[]
aiToolchainOperatorProfile 適用於整個叢集的 AI 工具鏈作員設定。 ManagedClusterAIToolchainOperatorProfile
apiServerAccessProfile 管理叢集 API 伺服器的 access 設定檔。 ManagedClusterAPIServerAccessProfile
autoScalerProfile 啟用時要套用至叢集自動調整程序的參數 ManagedClusterPropertiesAutoScalerProfile
autoUpgradeProfile 自動升級組態。 ManagedClusterAutoUpgradeProfile
azureMonitorProfile Azure 監視器 外掛配置檔用於監控受管理叢集。 ManagedClusterAzureMonitorProfile
bootstrapProfile 叢集啟動程式組態的配置檔。 ManagedClusterBootstrapProfile
controlPlaneScalingProfile 提供可擴展且具效能保證的控制平面容量,以在高負載下提供穩定效能的配置檔。 需要 Kubernetes 版本 1.33.0 或更新版本。 ManagedClusterControlPlaneScalingProfile
creationData 如果叢集是使用快照集建立/升級,則用來指定來源快照集標識符的 CreationData。 CreationData
disableLocalAccounts 如果應該在受控叢集上停用本機帳戶。 如果設定為 true,將會停用此叢集的靜態認證。 這隻能在已啟用 AAD 的受控叢集上使用。 更多詳情請參見 disable local accounts。 bool
diskEncryptionSetID 要用來啟用待用加密之磁碟加密的資源標識符。 這是格式:'/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Compute/diskEncryptionSets/{encryptionSetName}' 字串
dnsPrefix 受控叢集的 DNS 前置詞。 建立受控叢集之後,就無法更新此專案。 字串
enableFIPS 是否要在叢集層級啟用 FIPS 模式。 啟用時,此設定會強制所有 AKS 管理元件(如節點作業系統、外掛及 受管理容器化元件)符合 FIPS 規範。 詳情請參見 啟用叢集範圍 FIPS 。 啟用此功能後,叢集中所有節點池也必須啟用 FIPS。 bool
enableNamespaceResources 啟用 namespace as Azure 資源。 預設值為 false。 您可以在建立和更新受控叢集時啟用/停用它。 如需命名空間作為 ARM 資源的詳細資訊,請參閱 https://aka.ms/NamespaceARMResource 。 bool
enableNodeHardening 是否要在叢集層級啟用節點強化。 啟用後,AKS 會對叢集中所有 Linux 節點池套用軟驅逐閾值、kube 保留及系統保留的硬化預設值。 每個節點池的 kubeletConfig 設定優先於強化預設值。 在運行 Kubernetes 1.37 或更新版本的代理池中,節點強化預設是啟用且無法關閉的;將此欄位設為 false 對這些池子沒有影響。 bool
enableRBAC 是否啟用 Kubernetes Role-Based 存取控制。 bool
fqdnSubdomain 私有叢集的 FQDN 子網域,並擁有自訂的 private dns 區域。 建立受控叢集之後,就無法更新此專案。 字串
健康監測檔案 管理叢集的健康監控設定檔。 ManagedClusterHealthMonitorProfile
hosted系統設定檔 託管系統插件的設置。 如需詳細資訊,請參閱https://aka.ms/aks/automatic/systemcomponents。 ManagedClusterHosted系統設定檔
httpProxyConfig 使用 HTTP Proxy 伺服器布建叢集的組態。 ManagedClusterHttpProxyConfig
identityProfile 與受控叢集相關聯的使用者身分識別。 kubelet 會使用此身分識別。 只允許一個使用者指派的身分識別。 唯一接受的密鑰是 “kubeletidentity”,值為 “resourceId”:“/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.ManagedIdentity/userAssignedIdentities/{identityName}”。 ManagedClusterPropertiesIdentityProfile
ingressProfile 受控叢集的輸入配置檔。 ManagedClusterIngressProfile
kubernetesVersion 使用者指定的 Kubernetes 版本。 支援修補程式版本 <major.minor.patch> (例如 1.20.13)和 <major.minor> (例如 1.20)。 指定 major.minor< 時>,會自動選擇最新支援的 GA 修補程式版本。 在建立叢集之後,以相同的 <major.minor> 更新叢集(例如 1.14.x -> 1.14)將不會觸發升級,即使有較新的修補程式版本也一樣。 當您升級支援的 AKS 叢集時,無法略過 Kubernetes 次要版本。 所有升級都必須依主要版本號碼循序執行。 例如,允許在 1.14.x -> 1.15.x 或 1.15.x - 1.16.x 之間升級,但不允許 1.14.x ->> 1.16.x。 更多細節請參見 升級 AKS 叢集。 字串
linuxProfile 受控叢集中Linux VM的配置檔。 ContainerServiceLinuxProfile
metricsProfile 選擇性叢集計量組態。 ManagedClusterMetricsProfile
networkProfile 網路組態配置檔。 ContainerServiceNetworkProfile
nodeDisruptionProfile 管理叢集的節點中斷設定檔。 節點破壞剖面
nodeProvisioningProfile 套用至整個叢集的節點布建設定。 ManagedClusterNodeProvisioningProfile
nodeResourceGroup 包含代理程式集區節點的資源群組名稱。 字串
nodeResourceGroupProfile 節點資源群組組態的配置檔。 ManagedClusterNodeResourceGroupProfile
oidcIssuerProfile 受控叢集的 OIDC 簽發者配置檔。 ManagedClusterOidcIssuerProfile
podIdentityProfile 受控叢集的Pod身分識別配置檔。 欲了解更多關於 AAD 莢果身份整合的細節,請參見 use AAD pod identity。 ManagedClusterPodIdentityProfile
privateLinkResources 與叢集相關的 Private link 資源。 PrivateLinkResource[]
publicNetworkAccess PublicNetworkAccess 的 PublicNetworkAccess 中。 允許或拒絕 AKS 的公共網路 access 'Disabled'
'Enabled'
“SecuredByPerimeter”
schedulerProfile 設定檔包含排程器相關的設定,例如每個排程器的設定模式,由 AKS 管理。 參見 https://aka.ms/aks/scheduler-profile。 SchedulerProfile
securityProfile 受控叢集的安全性配置檔。 ManagedClusterSecurityProfile
serviceMeshProfile 受控叢集的服務網格配置檔。 ServiceMeshProfile
servicePrincipalProfile 關於叢集用來操作 Azure API 的服務主體身份資訊。 ManagedClusterServicePrincipalProfile
狀態 包含受控叢集的唯讀資訊。 ManagedClusterStatus
storageProfile 管理叢集的 Storage 設定檔。 ManagedClusterStorageProfile
supportPlan 受控叢集的支持計劃。 如果未指定,則預設值為 『KubernetesOfficial』。 'AKSLongTermSupport'
'KubernetesOfficial'
upgradeSettings 升級叢集的設定。 ClusterUpgradeSettings
windowsProfile 受控叢集中 Windows VM 的配置檔。 ManagedClusterWindowsProfile
workloadAutoScalerProfile 受控叢集的工作負載自動調整程式配置檔。 ManagedClusterWorkloadAutoScalerProfile

ManagedClusterPropertiesAddonProfiles

Name Description Value

ManagedClusterPropertiesAutoScalerProfile

Name Description Value
balance-similar-node-groups 偵測相似的節點集區,並平衡其間的節點數目。 有效值為 'true' 和 'false' 字串
daemonset-eviction-for-empty-nodes DaemonSet Pod 將從空節點正常終止。 如果設定為 true,則會在刪除節點之前收回空白節點上的所有精靈集 Pod。 如果無法收回精靈集 Pod,則會選擇另一個節點進行調整。 如果設定為 false,則會刪除節點,而不會確保刪除或收回精靈集 Pod。 bool
daemonset-eviction-for-occupied-nodes DaemonSet Pod 將從非空節點正常終止。 如果設定為 true,則會先收回已佔用節點上的所有精靈集 Pod,再刪除節點。 如果無法收回精靈集 Pod,則會選擇另一個節點進行調整。 如果設定為 false,則會刪除節點,而不會確保刪除或收回精靈集 Pod。 bool
expander 縱向擴展時要使用的擴展器。 如果未指定,則預設值為 『random』。 更多資訊請參見擴展器。 'least-waste'
'most-pods'
'priority'
'random'
ignore-daemonsets-utilization CA 在計算縮減的資源利用率時是否應該忽略 DaemonSet Pod。 如果設定為 true,精靈集所使用的資源會在做出相應減少決策時納入考慮。 bool
max-empty-bulk-delete 可以同時刪除的空白節點數目上限。 這必須是正整數。 預設值為 10。 字串
max-graceful-termination-sec 叢集自動調整程式在嘗試相應減少節點時等候Pod終止的最大秒數。 預設值為 600。 字串
max-node-provision-time 自動調整程式等候布建節點的最大時間。 預設值為 『15m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
max-total-unready-percentage 叢集中未讀取節點的最大百分比。 超過此百分比之後,叢集自動調整程式會停止作業。 預設值為 45。 最大值為 100,最小值為 0。 字串
new-pod-scale-up-delay 在某個年齡之前,請忽略未排程的 Pod。 針對高載/批次規模等案例,您不希望 CA 在 kubernetes 排程器排程所有 Pod 之前採取行動,您可以告訴 CA 在排程特定年齡之前忽略未排程的 Pod。 預設值為 『0s』。 值必須是整數,後面接著單位(秒的 's'、'm' 代表分鐘數、'h' 等。 字串
ok-total-unready-count 允許的未讀取節點數目,不論 total-total-unready-percentage。 這必須是整數。 預設值為 3。 字串
scale-down-delay-after-add 擴大後需要多長時間才能繼續進行縮小評估。 預設值為 『10m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-delay-after-delete 節點刪除後再繼續進行縮小評估的時間長度。 預設值為掃描間隔。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-delay-after-failure 縮小失敗後再繼續進行縮小評估的時間長度。 預設值為 『3m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-unneeded-time 節點在符合相應減少資格之前,應該不需要多久的時間。 預設值為 『10m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-unready-time 未就緒的節點在符合縮減條件之前應不需要多長時間。 默認值為 『20m』。 值必須是後面接著 『m』 的整數。 不支援分鐘 (m) 以外的時間單位。 字串
scale-down-utilization-threshold 節點使用率層級,定義為要求資源的總和除以容量,而節點可考慮相應減少。 預設值為 『0.5』。 字串
scan-interval 重新評估叢集以相應增加或減少的頻率。 預設值為 『10』。 值必須是整數秒數。 字串
跳過節點與本地storage 如果叢集自動縮放器會跳過刪除帶有本地 storage 的 pod 節點,例如 EmptyDir 或 HostPath。 默認值為 true。 字串
skip-nodes-with-system-pods 如果集群自動擴縮器會跳過從 kube-system 中刪除帶有 Pod 的節點(DaemonSet 或鏡像 Pod 除外)。 默認值為 true。 字串

ManagedClusterPropertiesIdentityProfile

Name Description Value

ManagedClusterSecurityProfile

Name Description Value
azureKeyVaultKms Azure Key Vault key management service 安全設定檔的設定。 AzureKeyVaultKms
customCATrustCertificates 最多 10 個 base64 編碼 CA 的清單,這些 CA 將會新增至叢集中所有節點上的信任存放區。 欲了解更多資訊,請參閱 Custom CA Trust Certificates。 any[]
defender Microsoft Defender 的安全設定檔設定。 ManagedClusterSecurityProfileDefender
imageCleaner 安全性配置檔的影像清除器設定。 ManagedClusterSecurityProfileImageCleaner
imageIntegrity 影像完整性是一項與 Azure 原則 合作,透過簽章驗證影像完整性的功能。 除非使用 Azure 原則 強制執行映像簽章,否則此方法不會有影響。 如需如何透過原則使用這項功能,請參閱 https://aka.ms/aks/image-integrity 。 ManagedClusterSecurityProfileImageIntegrity
kubernetesResourceObjectEncryptionProfile 對 Kubernetes 資源物件進行靜態加密。 有關這方面的更多資訊,請訪問 https://aka.ms/aks/kubernetesResourceObjectEncryption KubernetesResourceObjectEncryptionProfile
nodeRestriction Node Restriction 安全設定檔。 ManagedClusterSecurityProfileNodeRestriction
serviceAccountImagePullProfile 定義基於服務帳號的圖片拉取設定。 ServiceAccountImagePullProfile
workloadIdentity 安全性配置檔的工作負載身分識別設定。 工作負載身份讓 Kubernetes 應用程式能透過 Azure AD 安全access Azure雲端資源。 如需詳細資訊,請參閱 https://aka.ms/aks/wi。 ManagedClusterSecurityProfileWorkloadIdentity

ManagedClusterSecurityProfileDefender

Name Description Value
logAnalyticsWorkspaceResourceId 與 Microsoft Defender 關聯的日誌分析工作區資源 ID。 啟用 Microsoft Defender 時,此欄位為必填且必須為有效的工作空間資源 ID。 當 Microsoft Defender 被停用時,請將欄位留空。 字串
securityGating Microsoft Defender 的安全閘控設定。 此測試驗證容器映像檔是否符合部署資格,基於 Defender for Containers 的安全發現。 利用 Admission Controller,它會審核或阻止部署不符合安全標準的映像檔。 如需詳細資訊,請參閱https://aka.ms/KubernetesDefenderAuditRule。 ManagedClusterSecurityProfileDefenderSecurityGating
securityMonitoring Microsoft Defender 威脅偵測,用於雲端安全設定檔。 ManagedClusterSecurityProfileDefenderSecurityMonitoring

ManagedClusterSecurityProfileDefenderSecurityGating

Name Description Value
allowSecretAccess 僅在登錄檔存取由秘密身份而非管理身份授予時使用。 設定是否授予 Defender 門控代理存取叢集機密以從登錄檔拉取影像。 若秘密存取被拒絕且登錄檔要求拉取秘密,該外掛將不會執行映像驗證。 預設值為 False。 bool
enabled 是否要啟用Defender安全性管制。 啟用後,閘控功能會掃描容器映像檔,並審核或阻擋不符合安全標準的映像檔部署,並依照配置的安全規則。 如需詳細資訊,請參閱https://aka.ms/KubernetesDefenderAuditRule。 bool
身分識別 允許存取控制者用來從登錄庫拉取安全產物的身份列表。 這些是叢集用來提取容器映像的相同身分識別。 欲了解更多關於配置此身份的資訊,請參閱 /azure/defender-for-cloud/gated-deployment-infrastructure-as-code。 ManagedClusterSecurityProfileDefenderSecurityGatingIdentity[]

ManagedClusterSecurityProfileDefenderSecurityGatingIdentity

Name Description Value
azureContainerRegistry 將使用身分識別的容器登錄;此處指定的身分識別應該附加同盟身分識別認證。 字串
身分識別 用於access登錄檔的身份物件 UserAssignedIdentity

ManagedClusterSecurityProfileDefenderSecurityMonitoring

Name Description Value
enabled 是否啟用Defender威脅偵測 bool

ManagedClusterSecurityProfileImageCleaner

Name Description Value
enabled 是否要在 AKS 叢集上啟用影像清除器。 bool
intervalHours 影像清除程序掃描間隔以小時為單位。 int

ManagedClusterSecurityProfileImageIntegrity

Name Description Value
enabled 是否要啟用映像完整性。 預設值為 false。 bool

ManagedClusterSecurityProfileNodeRestriction

Name Description Value
enabled 是否啟用節點限制 bool

ManagedClusterSecurityProfileWorkloadIdentity

Name Description Value
enabled 是否要啟用工作負載身分識別。 bool

ManagedClusterServicePrincipalProfile

Name Description Value
clientId 服務主體的標識碼。 字串 (必要)
密碼 純文本中與服務主體相關聯的秘密密碼。 string

Constraints:
敏感性值。 以安全參數的形式傳入。

ManagedClusterSKU

Name Description Value
name 受控叢集 SKU 的名稱。 'Automatic'
'Base'
分層 受控叢集 SKU 的層。 如果未指定,則預設值為 『Free』。 詳情請參見 AKS 定價層級。 'Free'
'Premium'
'Standard'

ManagedClusterStaticEgressGatewayProfile

Name Description Value
enabled 啟用 Static Egress Gateway 外掛程式。 指出是否啟用靜態輸出閘道附加元件。 bool

ManagedClusterStatus

Name Description Value

ManagedClusterStorageProfile

Name Description Value
blobCSIDriver AzureBlob CSI 驅動程式設定中的 storage 設定檔。 ManagedClusterStorageProfileBlobCSIDriver
diskCSIDriver AzureDisk CSI 驅動程式設定中 storage profile 的設定。 ManagedClusterStorageProfileDiskCSIDriver
fileCSIDriver AzureFile CSI 驅動程式設定中的 storage 設定檔。 ManagedClusterStorageProfileFileCSIDriver
snapshotController storage profile 的快照控制器設定。 ManagedClusterStorageProfileSnapshotController

ManagedClusterStorageProfileBlobCSIDriver

Name Description Value
enabled 是否要啟用 AzureBlob CSI 驅動程式。 預設值為 false。 bool

ManagedClusterStorageProfileDiskCSIDriver

Name Description Value
enabled 是否要啟用 AzureDisk CSI 驅動程式。 預設值為 True。 bool

ManagedClusterStorageProfileFileCSIDriver

Name Description Value
enabled 是否要啟用 AzureFile CSI 驅動程式。 預設值為 True。 bool

ManagedClusterStorageProfileSnapshotController

Name Description Value
enabled 是否要啟用快照控制器。 預設值為 True。 bool

ManagedClusterWebAppRoutingGatewayAPIImplementations

Name Description Value
appRoutingIstio 設定使用 Sidecar 無邊車的 Istio 控制平面,透過 Gateway API 與 App 路由進行管理式入口。 請參閱 https://aka.ms/gateway-on-istio 有關使用 Istio 透過閘道 API 進入的資訊。 ManagedClusterAppRoutingIstio

ManagedClusterWindowsProfile

Name Description Value
adminPassword 指定系統管理員帳戶的密碼。

長度下限: 8 個字元

長度上限: 123 個字元

複雜性需求:需要滿足下列 4 個條件中的 3 個
字元較低
具有大字元
具有數位
具有特殊字元 (Regex match [\W_])

不允許的值: “abc@123”、“P@$$w 0rd”、“P@ssw0rd”、“P@ssword123”、“Pa$$word”、“pass@word1”、“Password!”、“Password1”、“Password22”、“iloveyou!”
string

Constraints:
敏感性值。 以安全參數的形式傳入。
adminUsername 指定系統管理員帳戶的名稱。

限制: 不能以 “” 結尾。

不允許的值: “administrator”、“admin”、“user”、“user1”、“test”、“user2”、“test1”、“user3”、“admin1”、“1” “123”、“a”、“actuser”、“adm”、“admin2”、“aspnet”、“backup”、“console”、“david”、“guest”、“john”、“owner”、“root”、“server”、“sql”、“support”、“support_388945a0”、“sys”、“test2”、“test3”、“user4”、“user5”。

最小長度: 1 個字元

長度上限: 20 個字元
字串 (必要)
enableCSIProxy 是否要啟用 CSI Proxy。 欲了解更多 CSI 代理的詳細資訊,請參閱 CSI 代理 GitHub repo。 bool
gmsaProfile 受控叢集中的 Windows gMSA 配置檔。 WindowsGmsaProfile
licenseType 要用於 Windows VM 的授權類型。 詳情請參見 Azure 混合用戶優勢。 'None'
'Windows_Server'

ManagedClusterWorkloadAutoScalerProfile

Name Description Value
keda 適用於工作負載自動調整程式配置檔的KEDA (Kubernetes 事件驅動自動調整) 設定。 ManagedClusterWorkloadAutoScalerProfileKeda
verticalPodAutoscaler 工作負載自動調整程式設定檔的 VPA (垂直 Pod 自動調整程式) 設定。 ManagedClusterWorkloadAutoScalerProfileVerticalPodAutoscaler

ManagedClusterWorkloadAutoScalerProfileKeda

Name Description Value
enabled 是否要啟用 KEDA。 布林 (必要)

ManagedClusterWorkloadAutoScalerProfileVerticalPodAutoscaler

Name Description Value
addonAutoscaling 是否啟用 VPA 附加元件,並設定為調整 AKS 管理的附加元件。 'Disabled'
'Enabled'
enabled 是否要啟用 VPA。 預設值為 False。 布林 (必要)

ManagedServiceIdentityUserAssignedIdentitiesValue

Name Description Value

ManualScaleProfile

Name Description Value
count 節點數目。 int
size AKS 在建立和調整時將使用的 VM 大小,例如 'Standard_E4s_v3'、'Standard_E16s_v3' 或 'Standard_D16s_v5'。 字串

節點破壞剖面

Name Description Value
nodeDisruptionPolicy 政策設定,允許需要節點重映像並觸發重新部署的特定操作。 例如,有些操作,例如更新 .properties 的檔案。在現有受管理叢集上設置 ManagedClusterSecurityProfile.customCATrustCertificates 欄位,觸發節點的滾動更新。 此設定允許控制何時接受此類更新。 預設是「允許」。 完整涵蓋作業清單請參見 aka.ms/aks/nodedisruptionpolicy」。 '允許'
「允許維護期間」
'阻止'

NvidiaGPUProfile

Name Description Value
駕駛模式 NVIDIA GPU 資源配置模式。 DevicePlugin 會安裝 NVIDIA
Kubernetes 裝置外掛。 DRA 安裝 NVIDIA DRA 驅動程式。
「裝置插件」
「DRA」
管理模式 管理式GPU體驗會在GPU驅動程式之上安裝額外元件,例如資料中心GPU管理器(DCGM)指標以監控。 想了解更多安裝內容,請參考 aka.ms/aks/managed-gpu。 'Managed'
'Unmanaged'
mig策略 設定用於管理型 MIG 支援的 MIG(多實例 GPU)策略。 欲了解更多不同策略資訊,請造訪 aka.ms/aks/managed-gpu。 未指定時,預設為無。 “喜憂參半”
'None'
'Single'

PortRange

Name Description Value
portEnd 範圍中包含的最大埠。 它的範圍應從 1 到 65535,且大於或等於 portStart。 int

Constraints:
最小值 = 1
最大值 = 65535
portStart 範圍中包含的最小埠。 它的範圍應從 1 到 65535,且小於或等於 portEnd。 int

Constraints:
最小值 = 1
最大值 = 65535
通訊協定 埠的網路通訊協定。 'TCP'
'UDP'

PowerState

Name Description Value
字碼 告知叢集是否正在執行或已停止 'Running'
'Stopped'

PreparedImageSpecificationProfile

Name Description Value
preparedImageSpecificationId 準備好的影像規範資源的資源 ID。 這可以包含一個版本。 省略該版本將使用最新版本的已準備影像規範。 字串

PrivateLinkResource

Name Description Value
groupId 資源的群組標識碼。 字串
id private link 資源的 ID。 字串
name private link 資源的名稱。 詳情請參見 命名規則 。 字串
requiredMembers 資源的 RequiredMembers string[]
型別 資源類型。 字串

ResourceReference

Name Description Value
id 完全合格的 Azure 資源 ID。 字串

ScaleProfile

Name Description Value
自動縮放 如何自動調整預先定義大小範圍內的 VirtualMachines 代理程式集區規格。
每個配置檔針對特定的虛擬機 SKU 進行獨立評估。
跨設定檔的縮放決策由叢集自動縮放擴展器控制,
可透過 ManagedCluster.properties.autoScalerProfile.expander.
AutoScaleProfile[]
manual 如何將 VirtualMachines 代理程式集區調整為固定大小的規格。 ManualScaleProfile[]

SchedulerInstanceProfile

Name Description Value
schedulerConfigMode 由 AKS 管理的排程器使用。 'Default'
'ManagedByCRD'

SchedulerProfile

Name Description Value
上游 與上游變體 kube-scheduler 相關的設定檔(https://github.com/kubernetes/kubernetes/tree/master/pkg/scheduler)。 SchedulerInstanceProfile

ServiceAccountImagePullProfile

Name Description Value
defaultManagedIdentityId 選擇性。 叢集層級用於影像拉取的預設管理身份資源 ID。 設定時,若 Pod 的服務帳號未明確指定拉取圖片的身份,則使用此身份。 若未設定且服務帳號層級未指定身份,映像檔將透過匿名驗證被拉取。 字串
enabled 表示是否啟用了基於服務帳號的映像拉取,此時需要身份綁定才能使用受管理身份進行認證。 如需詳細資訊,請參閱https://aka.ms/aks/identity-binding-docs。 bool

ServiceMeshProfile

Name Description Value
istio Istio 服務網格設定。 IstioServiceMesh
mode 服務網格的模式。 'Disabled'
'Istio'(必填)

軟驅逐寬限期

Name Description Value
記憶體可用 memoryAvailable 軟驅逐訊號的寬限期,以 Go 風格的持續時間字串表示(例如 '30s', '1m30s')。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 必須大於或等於「30」分。 預設是「30多」。 字串
nodeFsAvailable nodeFsAvailable 軟驅逐訊號的寬限期,以 Go 風格的持續時間字串表示(例如 '30s', '1m30s')。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 必須大於或等於「30」分。 預設是「2m」。 字串
nodeFsInodesFree nodeFsInodesFree 軟驅逐訊號的寬限期,以 Go 風格的持續時間字串表示(例如 '30s', '1m30s')。 支持的單位為 『ns』、『us』、『ms』、『s』、'm'和 'h'。 必須大於或等於「30」分。 預設是「2m」。 字串

軟驅逐門檻

Name Description Value
記憶體可用 軟莢艙被觸發的可用記憶體閾值。 接受絕對值(例如「500英里」)或百分比值(例如「5%」)。 絕對最低距離為100英里;最低百分比為2%。 預設採用基於容量的階梯:500Mi 用於 <=8GiB,750Mi 為 16GiB,1024Mi(1Gi)為 >=32GiB。 也必須大於有效 hardEvictionThreshold.memoryAvailable。 字串
nodeFsAvailable 軟莢莢被觸發的可用節點檔案系統空間閾值。 接受絕對值(例如「1Gi」)或百分比值(例如「10%」)。 預設是「12%」。 必須大於或等於 10%,且大於有效 hardEvictionThreshold.nodeFsAvailable。 字串
nodeFsInodesFree 節點檔案系統中可用 inode 的門檻,低於此閾值會觸發軟莢驅逐。 接受絕對 inode 計數(例如「100000」)或百分比值(例如「5%」)。 預設是「7%」。 百分比值必須大於或等於 5%,且大於有效 hardEvictionThreshold.nodeFsInodesFree。 字串

SysctlConfig

Name Description Value
fsAioMaxNr Sysctl 設定 fs.aio-max-nr。 int
fsFileMax Sysctl 設定 fs.file-max。 int
fsInotifyMaxUserWatches Sysctl 設定fs.inotify.max_user_watches。 int
fsNrOpen Sysctl 設定fs.nr_open。 int
kernelThreadsMax Sysctl 設定 kernel.threads-max。 int
netCoreNetdevMaxBacklog Sysctl 設定net.core.netdev_max_backlog。 int
netCoreOptmemMax Sysctl 設定net.core.optmem_max。 int
netCoreRmemDefault Sysctl 設定net.core.rmem_default。 int
netCoreRmemMax Sysctl 設定net.core.rmem_max。 int
netCoreSomaxconn Sysctl 設定 net.core.somaxconn。 int
netCoreWmemDefault Sysctl 設定net.core.wmem_default。 int
netCoreWmemMax Sysctl 設定net.core.wmem_max。 int
netIpv4IpLocalPortRange Sysctl 設定net.ipv4.ip_local_port_range。 字串
netIpv4NeighDefaultGcThresh1 Sysctl 設定net.ipv4.neigh.default.gc_thresh1。 int
netIpv4NeighDefaultGcThresh2 Sysctl 設定net.ipv4.neigh.default.gc_thresh2。 int
netIpv4NeighDefaultGcThresh3 Sysctl 設定net.ipv4.neigh.default.gc_thresh3。 int
netIpv4TcpFinTimeout Sysctl 設定net.ipv4.tcp_fin_timeout。 int
netIpv4TcpkeepaliveIntvl Sysctl 設定net.ipv4.tcp_keepalive_intvl。 int

Constraints:
最小值 = 10
最大值 = 90
netIpv4TcpKeepaliveProbes Sysctl 設定net.ipv4.tcp_keepalive_probes。 int
netIpv4TcpKeepaliveTime Sysctl 設定net.ipv4.tcp_keepalive_time。 int
netIpv4TcpMaxSynBacklog Sysctl 設定net.ipv4.tcp_max_syn_backlog。 int
netIpv4TcpMaxTwBuckets Sysctl 設定net.ipv4.tcp_max_tw_buckets。 int
netIpv4TcpTwReuse Sysctl 設定net.ipv4.tcp_tw_reuse。 bool
netNetfilterNfConntrackBuckets Sysctl 設定net.netfilter.nf_conntrack_buckets。 int

Constraints:
最小值 = 65536
最大值 = 524288
netNetfilterNfConntrackMax Sysctl 設定net.netfilter.nf_conntrack_max。 int

Constraints:
最小值 = 131072
最大值 = 2097152
vmMaxMapCount Sysctl 設定vm.max_map_count。 int
vmSwappiness Sysctl 設定 vm.swappiness。 int
vmVfsCachePressure Sysctl 設定vm.vfs_cache_pressure。 int

TrackedResourceTags

Name Description Value

UpgradeOverrideSettings

Name Description Value
forceUpgrade 是否要強制升級叢集。 請注意,此選項會指示升級作業略過升級保護,例如檢查已淘汰的 API 使用量。 請謹慎啟用此選項。 bool
until 直到覆寫生效為止。 請注意,這隻會符合升級的開始時間,即使升級 until 繼續進行時到期,升級的有效性也不會變更。 預設不會設定此欄位。 必須設定覆寫才會生效。 字串

UserAssignedIdentity

Name Description Value
clientId 使用者指派身分識別的用戶端標識碼。 字串
objectId 使用者指派身分識別的物件標識碼。 字串
resourceId 使用者指派身分識別的資源標識碼。 字串

VirtualMachineNodes

Name Description Value
count 節點數目。 int
size 用來裝載此節點群組之代理程式的 VM 大小。 字串

VirtualMachinesProfile

Name Description Value
級別 如何調整 VirtualMachines 代理程式集區的規格。 ScaleProfile

WindowsGmsaProfile

Name Description Value
dnsServer 指定 Windows gMSA 的 DNS 伺服器。

如果您已在用來建立受控叢集的 vnet 中設定 DNS 伺服器,請將它設定為空白。
字串
enabled 是否要啟用 Windows gMSA。 指定是否要在受控叢集中啟用 Windows gMSA。 bool
rootDomainName 指定 Windows gMSA 的根功能變數名稱。

如果您已在用來建立受控叢集的 vnet 中設定 DNS 伺服器,請將它設定為空白。
字串