Skip to content

[AKS] Synchronize monitoring profiles and repair live scenarios - #34047

Draft
FumingZhang wants to merge 3 commits into
Azure:devfrom
FumingZhang:fix/aks-live-validation-20260909
Draft

FumingZhang wants to merge 3 commits into
Azure:devfrom
FumingZhang:fix/aks-live-validation-20260909

Conversation

@FumingZhang

@FumingZhang FumingZhang commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

Related command

az aks enable-addons, az aks disable-addons, az aks update, and affected AKS live scenarios.

Description

Follow-up to #34037 for failures observed after the earlier runner fixes:

  • Synchronize canonical azureMonitorProfile.containerInsights values with legacy monitoring addon settings in outgoing SDK requests.
  • Resume metrics configuration with an explicit update after a retried create instead of accepting a successful cluster GET with incomplete monitoring setup.
  • Wait before dependent monitoring, LocalDNS, and ACNS operations; retry the precise operation-preemption error.
  • Remove unnecessary legacy monitoring solution creation from MSI workspace setup.
  • Respect the selected live-test region, avoid a restricted migration VM size, reduce the ingress-gateway footprint, and check zonal prerequisites without relocating forced-region tests or counting skips as passes.
  • Add a bounded, caller-scoped private-DNS permission-propagation retry after the test grants Private DNS Zone Contributor. Match the exact zone and privateDnsZones/read error. Unrelated permission failures, negative tests, and replay behavior remain unchanged.

Rebased on the current dev branch on 2026-09-17.

Testing Guide

  • Focused core/preview/dataprotection regression suite: 255 tests and 94 subtests passed after the rebases and follow-up changes. These are contract/unit results, not live passes.
  • 2026-09-17: the affected test_aks_private_dns_zone passed end-to-end in live mode in 554.56 seconds. It exercised real identity, DNS zone, role assignment, and private-cluster creation. No propagation failure was injected or observed; bounded retry and rejection branches are covered separately by deterministic tests.
  • Live validation used AZURE_TEST_RUN_LIVE=true and AZURE_CLI_TEST_RETRY_PROVISIONING_CHECK=true, with recording disabled, verified local source loading, and the existing westus2 development-location setting. No forced location was overridden.
  • Earlier 2026-09-09 targeted live validation: 13 selected scenarios passed and the Automatic SKU case was blocked by Graph Conditional Access. Monitoring MSI passed after correcting its stale empty-config assertion; disabled monitoring may retain metadata.
  • Additional original-EUAP ACNS attempts failed DCR association with InvalidAssociation. The experimental workspace-region mapping remains uncommitted and is not part of this PR. The westus2 flow-log pass does not validate EUAP.
  • Repository secret scanning found no secrets in the two September 17 changed files; syntax/undefined-symbol checks and diff hygiene passed. The local hook wrapper initially printed an environment error without propagating its status, so its scanner was rerun explicitly in the configured environment.
  • Final cleanup verified no run-owned resource groups or test node resource groups remain. Isolated credential copies and scratch directories were removed; logs and unrelated/global configuration were preserved.

Remaining service failures

This PR does not claim to fix scheduler-controller crash loops, NAT gateway API/internal-representation validation failures, quota/capacity exhaustion, or the separate proxy-update service timeout. A proposed Standard/V1 managed NAT test pin was rejected during live validation because V1 is not permitted in the V2-enabled region; that experiment was removed, not committed or replaced with a skip.

History Notes

[AKS] az aks update: Fix enabling and disabling container network logs when the cluster returns an Azure Monitor Container Insights profile

[AKS] az aks enable-addons, az aks disable-addons: Fix monitoring state and workspace updates when the cluster returns an Azure Monitor Container Insights profile


This checklist is used to make sure that common guidelines for a pull request are followed.

@yonzhan

Copy link
Copy Markdown
Collaborator

AKS

FumingZhang and others added 3 commits September 17, 2026 01:07
Keep canonical Container Insights settings aligned with legacy monitoring addon values in SDK PUT payloads. Resume metrics setup after retried creates, wait before dependent assertions, and honor live region and capacity constraints without weakening failure checks.

Validation: 91 targeted tests and 27 subtests passed with repository-pinned SDK 41.6.0; 283 live scenarios collected. Original-source regressions failed before the fixes. No AKS RP changes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Real live validation confirms enabled=false while Azure retains workspace and authentication metadata. Keep the persisted disabled-state check rather than requiring the entire addon config to disappear.

Validation: affected test_aks_create_default_service_with_monitoring_addon_msi passed end-to-end in LIVE mode (674 seconds), including re-enable. No unit or mocked run substitutes for this result.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Limit the dependency retry to the exact private DNS zone whose role was just assigned. Preserve unrelated permission errors, negative tests, replay behavior, and bounded retry exhaustion. The affected private DNS scenario passed in live mode before this commit.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@FumingZhang
FumingZhang force-pushed the fix/aks-live-validation-20260909 branch from d987836 to a021a44 Compare September 17, 2026 01:37

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants