[AKS] Synchronize monitoring profiles and repair live scenarios - #34047
Draft
FumingZhang wants to merge 3 commits into
Draft
FumingZhang wants to merge 3 commits into
FumingZhang wants to merge 3 commits into
Conversation
microsoft-github-policy-service
Bot
requested review from
elvazhu521,
Julie Zhu (yanzhudd) and
Yong Zhang (yonzhan)
September 9, 2026 06:36
Collaborator
|
AKS |
Keep canonical Container Insights settings aligned with legacy monitoring addon values in SDK PUT payloads. Resume metrics setup after retried creates, wait before dependent assertions, and honor live region and capacity constraints without weakening failure checks. Validation: 91 targeted tests and 27 subtests passed with repository-pinned SDK 41.6.0; 283 live scenarios collected. Original-source regressions failed before the fixes. No AKS RP changes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Real live validation confirms enabled=false while Azure retains workspace and authentication metadata. Keep the persisted disabled-state check rather than requiring the entire addon config to disappear. Validation: affected test_aks_create_default_service_with_monitoring_addon_msi passed end-to-end in LIVE mode (674 seconds), including re-enable. No unit or mocked run substitutes for this result. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Limit the dependency retry to the exact private DNS zone whose role was just assigned. Preserve unrelated permission errors, negative tests, replay behavior, and bounded retry exhaustion. The affected private DNS scenario passed in live mode before this commit. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
FumingZhang
force-pushed
the
fix/aks-live-validation-20260909
branch
from
September 17, 2026 01:37
d987836 to
a021a44
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related command
az aks enable-addons,az aks disable-addons,az aks update, and affected AKS live scenarios.Description
Follow-up to #34037 for failures observed after the earlier runner fixes:
azureMonitorProfile.containerInsightsvalues with legacy monitoring addon settings in outgoing SDK requests.Private DNS Zone Contributor. Match the exact zone andprivateDnsZones/readerror. Unrelated permission failures, negative tests, and replay behavior remain unchanged.Rebased on the current
devbranch on 2026-09-17.Testing Guide
test_aks_private_dns_zonepassed end-to-end in live mode in 554.56 seconds. It exercised real identity, DNS zone, role assignment, and private-cluster creation. No propagation failure was injected or observed; bounded retry and rejection branches are covered separately by deterministic tests.AZURE_TEST_RUN_LIVE=trueandAZURE_CLI_TEST_RETRY_PROVISIONING_CHECK=true, with recording disabled, verified local source loading, and the existingwestus2development-location setting. No forced location was overridden.InvalidAssociation. The experimental workspace-region mapping remains uncommitted and is not part of this PR. The westus2 flow-log pass does not validate EUAP.Remaining service failures
This PR does not claim to fix scheduler-controller crash loops, NAT gateway API/internal-representation validation failures, quota/capacity exhaustion, or the separate proxy-update service timeout. A proposed Standard/V1 managed NAT test pin was rejected during live validation because V1 is not permitted in the V2-enabled region; that experiment was removed, not committed or replaced with a skip.
History Notes
[AKS]
az aks update: Fix enabling and disabling container network logs when the cluster returns an Azure Monitor Container Insights profile[AKS]
az aks enable-addons,az aks disable-addons: Fix monitoring state and workspace updates when the cluster returns an Azure Monitor Container Insights profileThis checklist is used to make sure that common guidelines for a pull request are followed.