1. Registry
  2. Packages
  3. Azure Classic
  4. API Docs
  5. containerservice
  6. AutomaticCluster

We recommend using Azure Native.

Viewing docs for Azure v6.40.0
published on Wednesday, Sep 2, 2026 by Pulumi
azure logo

We recommend using Azure Native.

Viewing docs for Azure v6.40.0
published on Wednesday, Sep 2, 2026 by Pulumi

    Manages a Managed Kubernetes Automatic Cluster (a special SKU of AKS / Azure Kubernetes Service)

    Note: Due to the fast-moving nature of AKS, we recommend using the latest version of the Azure Provider when using AKS - you can find the latest version of the Azure Provider here.

    Note: All arguments including the client secret will be stored in the raw state as plain-text. Read more about sensitive data in state.

    Example Usage

    import * as pulumi from "@pulumi/pulumi";
    import * as azure from "@pulumi/azure";
    
    const example = new azure.core.ResourceGroup("example", {
        name: "example-resources",
        location: "West Europe",
    });
    const exampleAutomaticCluster = new azure.containerservice.AutomaticCluster("example", {
        name: "example-aks1",
        location: example.location,
        resourceGroupName: example.name,
        identity: {
            type: "SystemAssigned",
        },
        tags: {
            Environment: "Production",
        },
    });
    export const clientCertificate = exampleAutomaticCluster.kubeConfigs[0].clientCertificate;
    export const kubeConfig = exampleAutomaticCluster.kubeConfigRaw;
    
    import pulumi
    import pulumi_azure as azure
    
    example = azure.core.ResourceGroup("example",
        name="example-resources",
        location="West Europe")
    example_automatic_cluster = azure.containerservice.AutomaticCluster("example",
        name="example-aks1",
        location=example.location,
        resource_group_name=example.name,
        identity={
            "type": "SystemAssigned",
        },
        tags={
            "Environment": "Production",
        })
    pulumi.export("clientCertificate", example_automatic_cluster.kube_configs[0].client_certificate)
    pulumi.export("kubeConfig", example_automatic_cluster.kube_config_raw)
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/containerservice"
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/core"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		example, err := core.NewResourceGroup(ctx, "example", &core.ResourceGroupArgs{
    			Name:     pulumi.String("example-resources"),
    			Location: pulumi.String("West Europe"),
    		})
    		if err != nil {
    			return err
    		}
    		exampleAutomaticCluster, err := containerservice.NewAutomaticCluster(ctx, "example", &containerservice.AutomaticClusterArgs{
    			Name:              pulumi.String("example-aks1"),
    			Location:          example.Location,
    			ResourceGroupName: example.Name,
    			Identity: &containerservice.AutomaticClusterIdentityArgs{
    				Type: pulumi.String("SystemAssigned"),
    			},
    			Tags: pulumi.StringMap{
    				"Environment": pulumi.String("Production"),
    			},
    		})
    		if err != nil {
    			return err
    		}
    		ctx.Export("clientCertificate", exampleAutomaticCluster.KubeConfigs.ApplyT(func(kubeConfigs []containerservice.AutomaticClusterKubeConfig) (*string, error) {
    			return kubeConfigs[0].ClientCertificate, nil
    		}).(pulumi.StringPtrOutput))
    		ctx.Export("kubeConfig", exampleAutomaticCluster.KubeConfigRaw)
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Azure = Pulumi.Azure;
    
    return await Deployment.RunAsync(() => 
    {
        var example = new Azure.Core.ResourceGroup("example", new()
        {
            Name = "example-resources",
            Location = "West Europe",
        });
    
        var exampleAutomaticCluster = new Azure.ContainerService.AutomaticCluster("example", new()
        {
            Name = "example-aks1",
            Location = example.Location,
            ResourceGroupName = example.Name,
            Identity = new Azure.ContainerService.Inputs.AutomaticClusterIdentityArgs
            {
                Type = "SystemAssigned",
            },
            Tags = 
            {
                { "Environment", "Production" },
            },
        });
    
        return new Dictionary<string, object?>
        {
            ["clientCertificate"] = exampleAutomaticCluster.KubeConfigs.Apply(kubeConfigs => kubeConfigs[0].ClientCertificate),
            ["kubeConfig"] = exampleAutomaticCluster.KubeConfigRaw,
        };
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.azure.core.ResourceGroup;
    import com.pulumi.azure.core.ResourceGroupArgs;
    import com.pulumi.azure.containerservice.AutomaticCluster;
    import com.pulumi.azure.containerservice.AutomaticClusterArgs;
    import com.pulumi.azure.containerservice.inputs.AutomaticClusterIdentityArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var example = new ResourceGroup("example", ResourceGroupArgs.builder()
                .name("example-resources")
                .location("West Europe")
                .build());
    
            var exampleAutomaticCluster = new AutomaticCluster("exampleAutomaticCluster", AutomaticClusterArgs.builder()
                .name("example-aks1")
                .location(example.location())
                .resourceGroupName(example.name())
                .identity(AutomaticClusterIdentityArgs.builder()
                    .type("SystemAssigned")
                    .build())
                .tags(Map.of("Environment", "Production"))
                .build());
    
            ctx.export("clientCertificate", exampleAutomaticCluster.kubeConfigs().applyValue(_kubeConfigs -> _kubeConfigs[0].clientCertificate()));
            ctx.export("kubeConfig", exampleAutomaticCluster.kubeConfigRaw());
        }
    }
    
    resources:
      example:
        type: azure:core:ResourceGroup
        properties:
          name: example-resources
          location: West Europe
      exampleAutomaticCluster:
        type: azure:containerservice:AutomaticCluster
        name: example
        properties:
          name: example-aks1
          location: ${example.location}
          resourceGroupName: ${example.name}
          identity:
            type: SystemAssigned
          tags:
            Environment: Production
    outputs:
      clientCertificate: ${exampleAutomaticCluster.kubeConfigs[0].clientCertificate}
      kubeConfig: ${exampleAutomaticCluster.kubeConfigRaw}
    
    pulumi {
      required_providers {
        azure = {
          source = "pulumi/azure"
        }
      }
    }
    
    resource "azure_core_resourcegroup" "example" {
      name     = "example-resources"
      location = "West Europe"
    }
    resource "azure_containerservice_automaticcluster" "example" {
      name                = "example-aks1"
      location            = azure_core_resourcegroup.example.location
      resource_group_name = azure_core_resourcegroup.example.name
      identity = {
        type = "SystemAssigned"
      }
      tags = {
        "Environment" = "Production"
      }
    }
    output "clientCertificate" {
      value = azure_containerservice_automaticcluster.example.kube_configs[0].client_certificate
    }
    output "kubeConfig" {
      value = azure_containerservice_automaticcluster.example.kube_config_raw
    }
    

    Bring your own networking example

    import * as pulumi from "@pulumi/pulumi";
    import * as azure from "@pulumi/azure";
    
    const example = new azure.core.ResourceGroup("example", {
        name: "example-resources",
        location: "West Europe",
    });
    const exampleVirtualNetwork = new azure.network.VirtualNetwork("example", {
        name: "example-vnet",
        addressSpaces: ["10.1.0.0/16"],
        location: example.location,
        resourceGroupName: example.name,
    });
    const node = new azure.network.Subnet("node", {
        name: "example-node-subnet",
        resourceGroupName: example.name,
        virtualNetworkName: exampleVirtualNetwork.name,
        addressPrefixes: ["10.1.0.0/24"],
    });
    const api = new azure.network.Subnet("api", {
        name: "example-api-subnet",
        resourceGroupName: example.name,
        virtualNetworkName: exampleVirtualNetwork.name,
        addressPrefixes: ["10.1.1.0/24"],
        delegations: [{
            name: "aks-delegation",
            serviceDelegation: {
                actions: ["Microsoft.Network/virtualNetworks/subnets/join/action"],
                name: "Microsoft.ContainerService/managedClusters",
            },
        }],
    });
    const systemnode = new azure.network.Subnet("systemnode", {
        name: "example-systemnode-subnet",
        resourceGroupName: example.name,
        virtualNetworkName: exampleVirtualNetwork.name,
        addressPrefixes: ["10.1.2.0/24"],
    });
    const exampleUserAssignedIdentity = new azure.authorization.UserAssignedIdentity("example", {
        resourceGroupName: example.name,
        location: example.location,
        name: "example_identity",
    });
    const network = new azure.authorization.Assignment("network", {
        scope: exampleVirtualNetwork.id,
        roleDefinitionName: "Network Contributor",
        principalId: exampleUserAssignedIdentity.principalId,
    });
    const exampleAutomaticCluster = new azure.containerservice.AutomaticCluster("example", {
        name: "example-aks",
        location: example.location,
        resourceGroupName: example.name,
        hostedSystem: {
            nodeSubnetId: node.id,
            systemNodeSubnetId: systemnode.id,
        },
        identity: {
            type: "UserAssigned",
            identityIds: [exampleUserAssignedIdentity.id],
        },
        apiServerAccess: {
            subnetId: api.id,
        },
    });
    
    import pulumi
    import pulumi_azure as azure
    
    example = azure.core.ResourceGroup("example",
        name="example-resources",
        location="West Europe")
    example_virtual_network = azure.network.VirtualNetwork("example",
        name="example-vnet",
        address_spaces=["10.1.0.0/16"],
        location=example.location,
        resource_group_name=example.name)
    node = azure.network.Subnet("node",
        name="example-node-subnet",
        resource_group_name=example.name,
        virtual_network_name=example_virtual_network.name,
        address_prefixes=["10.1.0.0/24"])
    api = azure.network.Subnet("api",
        name="example-api-subnet",
        resource_group_name=example.name,
        virtual_network_name=example_virtual_network.name,
        address_prefixes=["10.1.1.0/24"],
        delegations=[{
            "name": "aks-delegation",
            "service_delegation": {
                "actions": ["Microsoft.Network/virtualNetworks/subnets/join/action"],
                "name": "Microsoft.ContainerService/managedClusters",
            },
        }])
    systemnode = azure.network.Subnet("systemnode",
        name="example-systemnode-subnet",
        resource_group_name=example.name,
        virtual_network_name=example_virtual_network.name,
        address_prefixes=["10.1.2.0/24"])
    example_user_assigned_identity = azure.authorization.UserAssignedIdentity("example",
        resource_group_name=example.name,
        location=example.location,
        name="example_identity")
    network = azure.authorization.Assignment("network",
        scope=example_virtual_network.id,
        role_definition_name="Network Contributor",
        principal_id=example_user_assigned_identity.principal_id)
    example_automatic_cluster = azure.containerservice.AutomaticCluster("example",
        name="example-aks",
        location=example.location,
        resource_group_name=example.name,
        hosted_system={
            "node_subnet_id": node.id,
            "system_node_subnet_id": systemnode.id,
        },
        identity={
            "type": "UserAssigned",
            "identity_ids": [example_user_assigned_identity.id],
        },
        api_server_access={
            "subnet_id": api.id,
        })
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/authorization"
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/containerservice"
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/core"
    	"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/network"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		example, err := core.NewResourceGroup(ctx, "example", &core.ResourceGroupArgs{
    			Name:     pulumi.String("example-resources"),
    			Location: pulumi.String("West Europe"),
    		})
    		if err != nil {
    			return err
    		}
    		exampleVirtualNetwork, err := network.NewVirtualNetwork(ctx, "example", &network.VirtualNetworkArgs{
    			Name: pulumi.String("example-vnet"),
    			AddressSpaces: pulumi.StringArray{
    				pulumi.String("10.1.0.0/16"),
    			},
    			Location:          example.Location,
    			ResourceGroupName: example.Name,
    		})
    		if err != nil {
    			return err
    		}
    		node, err := network.NewSubnet(ctx, "node", &network.SubnetArgs{
    			Name:               pulumi.String("example-node-subnet"),
    			ResourceGroupName:  example.Name,
    			VirtualNetworkName: exampleVirtualNetwork.Name,
    			AddressPrefixes: pulumi.StringArray{
    				pulumi.String("10.1.0.0/24"),
    			},
    		})
    		if err != nil {
    			return err
    		}
    		api, err := network.NewSubnet(ctx, "api", &network.SubnetArgs{
    			Name:               pulumi.String("example-api-subnet"),
    			ResourceGroupName:  example.Name,
    			VirtualNetworkName: exampleVirtualNetwork.Name,
    			AddressPrefixes: pulumi.StringArray{
    				pulumi.String("10.1.1.0/24"),
    			},
    			Delegations: network.SubnetDelegationArray{
    				&network.SubnetDelegationArgs{
    					Name: pulumi.String("aks-delegation"),
    					ServiceDelegation: &network.SubnetDelegationServiceDelegationArgs{
    						Actions: pulumi.StringArray{
    							pulumi.String("Microsoft.Network/virtualNetworks/subnets/join/action"),
    						},
    						Name: pulumi.String("Microsoft.ContainerService/managedClusters"),
    					},
    				},
    			},
    		})
    		if err != nil {
    			return err
    		}
    		systemnode, err := network.NewSubnet(ctx, "systemnode", &network.SubnetArgs{
    			Name:               pulumi.String("example-systemnode-subnet"),
    			ResourceGroupName:  example.Name,
    			VirtualNetworkName: exampleVirtualNetwork.Name,
    			AddressPrefixes: pulumi.StringArray{
    				pulumi.String("10.1.2.0/24"),
    			},
    		})
    		if err != nil {
    			return err
    		}
    		exampleUserAssignedIdentity, err := authorization.NewUserAssignedIdentity(ctx, "example", &authorization.UserAssignedIdentityArgs{
    			ResourceGroupName: example.Name,
    			Location:          example.Location,
    			Name:              pulumi.String("example_identity"),
    		})
    		if err != nil {
    			return err
    		}
    		_, err = authorization.NewAssignment(ctx, "network", &authorization.AssignmentArgs{
    			Scope:              exampleVirtualNetwork.ID().ToIDOutput().ToStringOutput(),
    			RoleDefinitionName: pulumi.String("Network Contributor"),
    			PrincipalId:        exampleUserAssignedIdentity.PrincipalId,
    		})
    		if err != nil {
    			return err
    		}
    		_, err = containerservice.NewAutomaticCluster(ctx, "example", &containerservice.AutomaticClusterArgs{
    			Name:              pulumi.String("example-aks"),
    			Location:          example.Location,
    			ResourceGroupName: example.Name,
    			HostedSystem: &containerservice.AutomaticClusterHostedSystemArgs{
    				NodeSubnetId:       node.ID().ToIDOutput().ToStringOutput(),
    				SystemNodeSubnetId: systemnode.ID().ToIDOutput().ToStringOutput(),
    			},
    			Identity: &containerservice.AutomaticClusterIdentityArgs{
    				Type: pulumi.String("UserAssigned"),
    				IdentityIds: pulumi.StringArray{
    					exampleUserAssignedIdentity.ID().ToIDOutput().ToStringOutput(),
    				},
    			},
    			ApiServerAccess: &containerservice.AutomaticClusterApiServerAccessArgs{
    				SubnetId: api.ID().ToIDOutput().ToStringOutput(),
    			},
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Azure = Pulumi.Azure;
    
    return await Deployment.RunAsync(() => 
    {
        var example = new Azure.Core.ResourceGroup("example", new()
        {
            Name = "example-resources",
            Location = "West Europe",
        });
    
        var exampleVirtualNetwork = new Azure.Network.VirtualNetwork("example", new()
        {
            Name = "example-vnet",
            AddressSpaces = new[]
            {
                "10.1.0.0/16",
            },
            Location = example.Location,
            ResourceGroupName = example.Name,
        });
    
        var node = new Azure.Network.Subnet("node", new()
        {
            Name = "example-node-subnet",
            ResourceGroupName = example.Name,
            VirtualNetworkName = exampleVirtualNetwork.Name,
            AddressPrefixes = new[]
            {
                "10.1.0.0/24",
            },
        });
    
        var api = new Azure.Network.Subnet("api", new()
        {
            Name = "example-api-subnet",
            ResourceGroupName = example.Name,
            VirtualNetworkName = exampleVirtualNetwork.Name,
            AddressPrefixes = new[]
            {
                "10.1.1.0/24",
            },
            Delegations = new[]
            {
                new Azure.Network.Inputs.SubnetDelegationArgs
                {
                    Name = "aks-delegation",
                    ServiceDelegation = new Azure.Network.Inputs.SubnetDelegationServiceDelegationArgs
                    {
                        Actions = new[]
                        {
                            "Microsoft.Network/virtualNetworks/subnets/join/action",
                        },
                        Name = "Microsoft.ContainerService/managedClusters",
                    },
                },
            },
        });
    
        var systemnode = new Azure.Network.Subnet("systemnode", new()
        {
            Name = "example-systemnode-subnet",
            ResourceGroupName = example.Name,
            VirtualNetworkName = exampleVirtualNetwork.Name,
            AddressPrefixes = new[]
            {
                "10.1.2.0/24",
            },
        });
    
        var exampleUserAssignedIdentity = new Azure.Authorization.UserAssignedIdentity("example", new()
        {
            ResourceGroupName = example.Name,
            Location = example.Location,
            Name = "example_identity",
        });
    
        var network = new Azure.Authorization.Assignment("network", new()
        {
            Scope = exampleVirtualNetwork.Id,
            RoleDefinitionName = "Network Contributor",
            PrincipalId = exampleUserAssignedIdentity.PrincipalId,
        });
    
        var exampleAutomaticCluster = new Azure.ContainerService.AutomaticCluster("example", new()
        {
            Name = "example-aks",
            Location = example.Location,
            ResourceGroupName = example.Name,
            HostedSystem = new Azure.ContainerService.Inputs.AutomaticClusterHostedSystemArgs
            {
                NodeSubnetId = node.Id,
                SystemNodeSubnetId = systemnode.Id,
            },
            Identity = new Azure.ContainerService.Inputs.AutomaticClusterIdentityArgs
            {
                Type = "UserAssigned",
                IdentityIds = new[]
                {
                    exampleUserAssignedIdentity.Id,
                },
            },
            ApiServerAccess = new Azure.ContainerService.Inputs.AutomaticClusterApiServerAccessArgs
            {
                SubnetId = api.Id,
            },
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.azure.core.ResourceGroup;
    import com.pulumi.azure.core.ResourceGroupArgs;
    import com.pulumi.azure.network.VirtualNetwork;
    import com.pulumi.azure.network.VirtualNetworkArgs;
    import com.pulumi.azure.network.Subnet;
    import com.pulumi.azure.network.SubnetArgs;
    import com.pulumi.azure.network.inputs.SubnetDelegationArgs;
    import com.pulumi.azure.network.inputs.SubnetDelegationServiceDelegationArgs;
    import com.pulumi.azure.authorization.UserAssignedIdentity;
    import com.pulumi.azure.authorization.UserAssignedIdentityArgs;
    import com.pulumi.azure.authorization.Assignment;
    import com.pulumi.azure.authorization.AssignmentArgs;
    import com.pulumi.azure.containerservice.AutomaticCluster;
    import com.pulumi.azure.containerservice.AutomaticClusterArgs;
    import com.pulumi.azure.containerservice.inputs.AutomaticClusterHostedSystemArgs;
    import com.pulumi.azure.containerservice.inputs.AutomaticClusterIdentityArgs;
    import com.pulumi.azure.containerservice.inputs.AutomaticClusterApiServerAccessArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var example = new ResourceGroup("example", ResourceGroupArgs.builder()
                .name("example-resources")
                .location("West Europe")
                .build());
    
            var exampleVirtualNetwork = new VirtualNetwork("exampleVirtualNetwork", VirtualNetworkArgs.builder()
                .name("example-vnet")
                .addressSpaces("10.1.0.0/16")
                .location(example.location())
                .resourceGroupName(example.name())
                .build());
    
            var node = new Subnet("node", SubnetArgs.builder()
                .name("example-node-subnet")
                .resourceGroupName(example.name())
                .virtualNetworkName(exampleVirtualNetwork.name())
                .addressPrefixes("10.1.0.0/24")
                .build());
    
            var api = new Subnet("api", SubnetArgs.builder()
                .name("example-api-subnet")
                .resourceGroupName(example.name())
                .virtualNetworkName(exampleVirtualNetwork.name())
                .addressPrefixes("10.1.1.0/24")
                .delegations(SubnetDelegationArgs.builder()
                    .name("aks-delegation")
                    .serviceDelegation(SubnetDelegationServiceDelegationArgs.builder()
                        .actions("Microsoft.Network/virtualNetworks/subnets/join/action")
                        .name("Microsoft.ContainerService/managedClusters")
                        .build())
                    .build())
                .build());
    
            var systemnode = new Subnet("systemnode", SubnetArgs.builder()
                .name("example-systemnode-subnet")
                .resourceGroupName(example.name())
                .virtualNetworkName(exampleVirtualNetwork.name())
                .addressPrefixes("10.1.2.0/24")
                .build());
    
            var exampleUserAssignedIdentity = new UserAssignedIdentity("exampleUserAssignedIdentity", UserAssignedIdentityArgs.builder()
                .resourceGroupName(example.name())
                .location(example.location())
                .name("example_identity")
                .build());
    
            var network = new Assignment("network", AssignmentArgs.builder()
                .scope(exampleVirtualNetwork.id())
                .roleDefinitionName("Network Contributor")
                .principalId(exampleUserAssignedIdentity.principalId())
                .build());
    
            var exampleAutomaticCluster = new AutomaticCluster("exampleAutomaticCluster", AutomaticClusterArgs.builder()
                .name("example-aks")
                .location(example.location())
                .resourceGroupName(example.name())
                .hostedSystem(AutomaticClusterHostedSystemArgs.builder()
                    .nodeSubnetId(node.id())
                    .systemNodeSubnetId(systemnode.id())
                    .build())
                .identity(AutomaticClusterIdentityArgs.builder()
                    .type("UserAssigned")
                    .identityIds(exampleUserAssignedIdentity.id())
                    .build())
                .apiServerAccess(AutomaticClusterApiServerAccessArgs.builder()
                    .subnetId(api.id())
                    .build())
                .build());
    
        }
    }
    
    resources:
      example:
        type: azure:core:ResourceGroup
        properties:
          name: example-resources
          location: West Europe
      exampleVirtualNetwork:
        type: azure:network:VirtualNetwork
        name: example
        properties:
          name: example-vnet
          addressSpaces:
            - 10.1.0.0/16
          location: ${example.location}
          resourceGroupName: ${example.name}
      node:
        type: azure:network:Subnet
        properties:
          name: example-node-subnet
          resourceGroupName: ${example.name}
          virtualNetworkName: ${exampleVirtualNetwork.name}
          addressPrefixes:
            - 10.1.0.0/24
      api:
        type: azure:network:Subnet
        properties:
          name: example-api-subnet
          resourceGroupName: ${example.name}
          virtualNetworkName: ${exampleVirtualNetwork.name}
          addressPrefixes:
            - 10.1.1.0/24
          delegations:
            - name: aks-delegation
              serviceDelegation:
                actions:
                  - Microsoft.Network/virtualNetworks/subnets/join/action
                name: Microsoft.ContainerService/managedClusters
      systemnode:
        type: azure:network:Subnet
        properties:
          name: example-systemnode-subnet
          resourceGroupName: ${example.name}
          virtualNetworkName: ${exampleVirtualNetwork.name}
          addressPrefixes:
            - 10.1.2.0/24
      exampleUserAssignedIdentity:
        type: azure:authorization:UserAssignedIdentity
        name: example
        properties:
          resourceGroupName: ${example.name}
          location: ${example.location}
          name: example_identity
      network:
        type: azure:authorization:Assignment
        properties:
          scope: ${exampleVirtualNetwork.id}
          roleDefinitionName: Network Contributor
          principalId: ${exampleUserAssignedIdentity.principalId}
      exampleAutomaticCluster:
        type: azure:containerservice:AutomaticCluster
        name: example
        properties:
          name: example-aks
          location: ${example.location}
          resourceGroupName: ${example.name}
          hostedSystem:
            nodeSubnetId: ${node.id}
            systemNodeSubnetId: ${systemnode.id}
          identity:
            type: UserAssigned
            identityIds:
              - ${exampleUserAssignedIdentity.id}
          apiServerAccess:
            subnetId: ${api.id}
    
    pulumi {
      required_providers {
        azure = {
          source = "pulumi/azure"
        }
      }
    }
    
    resource "azure_core_resourcegroup" "example" {
      name     = "example-resources"
      location = "West Europe"
    }
    resource "azure_network_virtualnetwork" "example" {
      name                = "example-vnet"
      address_spaces      = ["10.1.0.0/16"]
      location            = azure_core_resourcegroup.example.location
      resource_group_name = azure_core_resourcegroup.example.name
    }
    resource "azure_network_subnet" "node" {
      name                 = "example-node-subnet"
      resource_group_name  = azure_core_resourcegroup.example.name
      virtual_network_name = azure_network_virtualnetwork.example.name
      address_prefixes     = ["10.1.0.0/24"]
    }
    resource "azure_network_subnet" "api" {
      name                 = "example-api-subnet"
      resource_group_name  = azure_core_resourcegroup.example.name
      virtual_network_name = azure_network_virtualnetwork.example.name
      address_prefixes     = ["10.1.1.0/24"]
      delegations {
        name = "aks-delegation"
        service_delegation = {
          actions = ["Microsoft.Network/virtualNetworks/subnets/join/action"]
          name    = "Microsoft.ContainerService/managedClusters"
        }
      }
    }
    resource "azure_network_subnet" "systemnode" {
      name                 = "example-systemnode-subnet"
      resource_group_name  = azure_core_resourcegroup.example.name
      virtual_network_name = azure_network_virtualnetwork.example.name
      address_prefixes     = ["10.1.2.0/24"]
    }
    resource "azure_authorization_userassignedidentity" "example" {
      resource_group_name = azure_core_resourcegroup.example.name
      location            = azure_core_resourcegroup.example.location
      name                = "example_identity"
    }
    resource "azure_authorization_assignment" "network" {
      scope                = azure_network_virtualnetwork.example.id
      role_definition_name = "Network Contributor"
      principal_id         = azure_authorization_userassignedidentity.example.principal_id
    }
    resource "azure_containerservice_automaticcluster" "example" {
      name                = "example-aks"
      location            = azure_core_resourcegroup.example.location
      resource_group_name = azure_core_resourcegroup.example.name
      hosted_system = {
        node_subnet_id        = azure_network_subnet.node.id
        system_node_subnet_id = azure_network_subnet.systemnode.id
      }
      identity = {
        type         = "UserAssigned"
        identity_ids = [azure_authorization_userassignedidentity.example.id]
      }
      api_server_access = {
        subnet_id = azure_network_subnet.api.id
      }
    }
    

    API Providers

    This resource uses the following Azure API Providers:

    • Microsoft.ContainerService - 2026-04-01

    Create AutomaticCluster Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new AutomaticCluster(name: string, args: AutomaticClusterArgs, opts?: CustomResourceOptions);
    @overload
    def AutomaticCluster(resource_name: str,
                         args: AutomaticClusterArgs,
                         opts: Optional[ResourceOptions] = None)
    
    @overload
    def AutomaticCluster(resource_name: str,
                         opts: Optional[ResourceOptions] = None,
                         identity: Optional[AutomaticClusterIdentityArgs] = None,
                         resource_group_name: Optional[str] = None,
                         api_server_access: Optional[AutomaticClusterApiServerAccessArgs] = None,
                         hosted_system: Optional[AutomaticClusterHostedSystemArgs] = None,
                         location: Optional[str] = None,
                         name: Optional[str] = None,
                         private_cluster: Optional[AutomaticClusterPrivateClusterArgs] = None,
                         service_mesh: Optional[AutomaticClusterServiceMeshArgs] = None,
                         tags: Optional[Mapping[str, str]] = None,
                         web_app_routing_ingress: Optional[AutomaticClusterWebAppRoutingIngressArgs] = None)
    func NewAutomaticCluster(ctx *Context, name string, args AutomaticClusterArgs, opts ...ResourceOption) (*AutomaticCluster, error)
    public AutomaticCluster(string name, AutomaticClusterArgs args, CustomResourceOptions? opts = null)
    public AutomaticCluster(String name, AutomaticClusterArgs args)
    public AutomaticCluster(String name, AutomaticClusterArgs args, CustomResourceOptions options)
    
    type: azure:containerservice:AutomaticCluster
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "azure_containerservice_automatic_cluster" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args AutomaticClusterArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args AutomaticClusterArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args AutomaticClusterArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args AutomaticClusterArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args AutomaticClusterArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var automaticClusterResource = new Azure.ContainerService.AutomaticCluster("automaticClusterResource", new()
    {
        Identity = new Azure.ContainerService.Inputs.AutomaticClusterIdentityArgs
        {
            Type = "string",
            IdentityIds = new[]
            {
                "string",
            },
            PrincipalId = "string",
            TenantId = "string",
        },
        ResourceGroupName = "string",
        ApiServerAccess = new Azure.ContainerService.Inputs.AutomaticClusterApiServerAccessArgs
        {
            AuthorizedIpRanges = new[]
            {
                "string",
            },
            SubnetId = "string",
        },
        HostedSystem = new Azure.ContainerService.Inputs.AutomaticClusterHostedSystemArgs
        {
            NodeSubnetId = "string",
            SystemNodeSubnetId = "string",
        },
        Location = "string",
        Name = "string",
        PrivateCluster = new Azure.ContainerService.Inputs.AutomaticClusterPrivateClusterArgs
        {
            PrivateDnsZoneId = "string",
            PublicFullyQualifiedDomainNameEnabled = false,
        },
        ServiceMesh = new Azure.ContainerService.Inputs.AutomaticClusterServiceMeshArgs
        {
            Revisions = new[]
            {
                "string",
            },
            CertificateAuthority = new Azure.ContainerService.Inputs.AutomaticClusterServiceMeshCertificateAuthorityArgs
            {
                CertificateChainObjectName = "string",
                CertificateObjectName = "string",
                KeyObjectName = "string",
                KeyVaultId = "string",
                RootCertificateObjectName = "string",
            },
            ExternalIngressGatewayEnabled = false,
            InternalIngressGatewayEnabled = false,
            ProxyRedirectMechanism = "string",
        },
        Tags = 
        {
            { "string", "string" },
        },
        WebAppRoutingIngress = new Azure.ContainerService.Inputs.AutomaticClusterWebAppRoutingIngressArgs
        {
            DefaultNginxController = "string",
            DnsZoneIds = new[]
            {
                "string",
            },
            IstioEnabled = false,
            WebAppRoutingIdentities = new[]
            {
                new Azure.ContainerService.Inputs.AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentityArgs
                {
                    ClientId = "string",
                    ObjectId = "string",
                    UserAssignedIdentityId = "string",
                },
            },
        },
    });
    
    example, err := containerservice.NewAutomaticCluster(ctx, "automaticClusterResource", &containerservice.AutomaticClusterArgs{
    	Identity: &containerservice.AutomaticClusterIdentityArgs{
    		Type: pulumi.String("string"),
    		IdentityIds: pulumi.StringArray{
    			pulumi.String("string"),
    		},
    		PrincipalId: pulumi.String("string"),
    		TenantId:    pulumi.String("string"),
    	},
    	ResourceGroupName: pulumi.String("string"),
    	ApiServerAccess: &containerservice.AutomaticClusterApiServerAccessArgs{
    		AuthorizedIpRanges: pulumi.StringArray{
    			pulumi.String("string"),
    		},
    		SubnetId: pulumi.String("string"),
    	},
    	HostedSystem: &containerservice.AutomaticClusterHostedSystemArgs{
    		NodeSubnetId:       pulumi.String("string"),
    		SystemNodeSubnetId: pulumi.String("string"),
    	},
    	Location: pulumi.String("string"),
    	Name:     pulumi.String("string"),
    	PrivateCluster: &containerservice.AutomaticClusterPrivateClusterArgs{
    		PrivateDnsZoneId:                      pulumi.String("string"),
    		PublicFullyQualifiedDomainNameEnabled: pulumi.Bool(false),
    	},
    	ServiceMesh: &containerservice.AutomaticClusterServiceMeshArgs{
    		Revisions: pulumi.StringArray{
    			pulumi.String("string"),
    		},
    		CertificateAuthority: &containerservice.AutomaticClusterServiceMeshCertificateAuthorityArgs{
    			CertificateChainObjectName: pulumi.String("string"),
    			CertificateObjectName:      pulumi.String("string"),
    			KeyObjectName:              pulumi.String("string"),
    			KeyVaultId:                 pulumi.String("string"),
    			RootCertificateObjectName:  pulumi.String("string"),
    		},
    		ExternalIngressGatewayEnabled: pulumi.Bool(false),
    		InternalIngressGatewayEnabled: pulumi.Bool(false),
    		ProxyRedirectMechanism:        pulumi.String("string"),
    	},
    	Tags: pulumi.StringMap{
    		"string": pulumi.String("string"),
    	},
    	WebAppRoutingIngress: &containerservice.AutomaticClusterWebAppRoutingIngressArgs{
    		DefaultNginxController: pulumi.String("string"),
    		DnsZoneIds: pulumi.StringArray{
    			pulumi.String("string"),
    		},
    		IstioEnabled: pulumi.Bool(false),
    		WebAppRoutingIdentities: containerservice.AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentityArray{
    			&containerservice.AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentityArgs{
    				ClientId:               pulumi.String("string"),
    				ObjectId:               pulumi.String("string"),
    				UserAssignedIdentityId: pulumi.String("string"),
    			},
    		},
    	},
    })
    
    resource "azure_containerservice_automatic_cluster" "automaticClusterResource" {
      lifecycle {
        create_before_destroy = true
      }
      identity = {
        type         = "string"
        identity_ids = ["string"]
        principal_id = "string"
        tenant_id    = "string"
      }
      resource_group_name = "string"
      api_server_access = {
        authorized_ip_ranges = ["string"]
        subnet_id            = "string"
      }
      hosted_system = {
        node_subnet_id        = "string"
        system_node_subnet_id = "string"
      }
      location = "string"
      name     = "string"
      private_cluster = {
        private_dns_zone_id                        = "string"
        public_fully_qualified_domain_name_enabled = false
      }
      service_mesh = {
        revisions = ["string"]
        certificate_authority = {
          certificate_chain_object_name = "string"
          certificate_object_name       = "string"
          key_object_name               = "string"
          key_vault_id                  = "string"
          root_certificate_object_name  = "string"
        }
        external_ingress_gateway_enabled = false
        internal_ingress_gateway_enabled = false
        proxy_redirect_mechanism         = "string"
      }
      tags = {
        "string" = "string"
      }
      web_app_routing_ingress = {
        default_nginx_controller = "string"
        dns_zone_ids             = ["string"]
        istio_enabled            = false
        web_app_routing_identities = [{
          client_id                 = "string"
          object_id                 = "string"
          user_assigned_identity_id = "string"
        }]
      }
    }
    
    var automaticClusterResource = new AutomaticCluster("automaticClusterResource", AutomaticClusterArgs.builder()
        .identity(AutomaticClusterIdentityArgs.builder()
            .type("string")
            .identityIds("string")
            .principalId("string")
            .tenantId("string")
            .build())
        .resourceGroupName("string")
        .apiServerAccess(AutomaticClusterApiServerAccessArgs.builder()
            .authorizedIpRanges("string")
            .subnetId("string")
            .build())
        .hostedSystem(AutomaticClusterHostedSystemArgs.builder()
            .nodeSubnetId("string")
            .systemNodeSubnetId("string")
            .build())
        .location("string")
        .name("string")
        .privateCluster(AutomaticClusterPrivateClusterArgs.builder()
            .privateDnsZoneId("string")
            .publicFullyQualifiedDomainNameEnabled(false)
            .build())
        .serviceMesh(AutomaticClusterServiceMeshArgs.builder()
            .revisions("string")
            .certificateAuthority(AutomaticClusterServiceMeshCertificateAuthorityArgs.builder()
                .certificateChainObjectName("string")
                .certificateObjectName("string")
                .keyObjectName("string")
                .keyVaultId("string")
                .rootCertificateObjectName("string")
                .build())
            .externalIngressGatewayEnabled(false)
            .internalIngressGatewayEnabled(false)
            .proxyRedirectMechanism("string")
            .build())
        .tags(Map.of("string", "string"))
        .webAppRoutingIngress(AutomaticClusterWebAppRoutingIngressArgs.builder()
            .defaultNginxController("string")
            .dnsZoneIds("string")
            .istioEnabled(false)
            .webAppRoutingIdentities(AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentityArgs.builder()
                .clientId("string")
                .objectId("string")
                .userAssignedIdentityId("string")
                .build())
            .build())
        .build());
    
    automatic_cluster_resource = azure.containerservice.AutomaticCluster("automaticClusterResource",
        identity={
            "type": "string",
            "identity_ids": ["string"],
            "principal_id": "string",
            "tenant_id": "string",
        },
        resource_group_name="string",
        api_server_access={
            "authorized_ip_ranges": ["string"],
            "subnet_id": "string",
        },
        hosted_system={
            "node_subnet_id": "string",
            "system_node_subnet_id": "string",
        },
        location="string",
        name="string",
        private_cluster={
            "private_dns_zone_id": "string",
            "public_fully_qualified_domain_name_enabled": False,
        },
        service_mesh={
            "revisions": ["string"],
            "certificate_authority": {
                "certificate_chain_object_name": "string",
                "certificate_object_name": "string",
                "key_object_name": "string",
                "key_vault_id": "string",
                "root_certificate_object_name": "string",
            },
            "external_ingress_gateway_enabled": False,
            "internal_ingress_gateway_enabled": False,
            "proxy_redirect_mechanism": "string",
        },
        tags={
            "string": "string",
        },
        web_app_routing_ingress={
            "default_nginx_controller": "string",
            "dns_zone_ids": ["string"],
            "istio_enabled": False,
            "web_app_routing_identities": [{
                "client_id": "string",
                "object_id": "string",
                "user_assigned_identity_id": "string",
            }],
        })
    
    const automaticClusterResource = new azure.containerservice.AutomaticCluster("automaticClusterResource", {
        identity: {
            type: "string",
            identityIds: ["string"],
            principalId: "string",
            tenantId: "string",
        },
        resourceGroupName: "string",
        apiServerAccess: {
            authorizedIpRanges: ["string"],
            subnetId: "string",
        },
        hostedSystem: {
            nodeSubnetId: "string",
            systemNodeSubnetId: "string",
        },
        location: "string",
        name: "string",
        privateCluster: {
            privateDnsZoneId: "string",
            publicFullyQualifiedDomainNameEnabled: false,
        },
        serviceMesh: {
            revisions: ["string"],
            certificateAuthority: {
                certificateChainObjectName: "string",
                certificateObjectName: "string",
                keyObjectName: "string",
                keyVaultId: "string",
                rootCertificateObjectName: "string",
            },
            externalIngressGatewayEnabled: false,
            internalIngressGatewayEnabled: false,
            proxyRedirectMechanism: "string",
        },
        tags: {
            string: "string",
        },
        webAppRoutingIngress: {
            defaultNginxController: "string",
            dnsZoneIds: ["string"],
            istioEnabled: false,
            webAppRoutingIdentities: [{
                clientId: "string",
                objectId: "string",
                userAssignedIdentityId: "string",
            }],
        },
    });
    
    type: azure:containerservice:AutomaticCluster
    properties:
        apiServerAccess:
            authorizedIpRanges:
                - string
            subnetId: string
        hostedSystem:
            nodeSubnetId: string
            systemNodeSubnetId: string
        identity:
            identityIds:
                - string
            principalId: string
            tenantId: string
            type: string
        location: string
        name: string
        privateCluster:
            privateDnsZoneId: string
            publicFullyQualifiedDomainNameEnabled: false
        resourceGroupName: string
        serviceMesh:
            certificateAuthority:
                certificateChainObjectName: string
                certificateObjectName: string
                keyObjectName: string
                keyVaultId: string
                rootCertificateObjectName: string
            externalIngressGatewayEnabled: false
            internalIngressGatewayEnabled: false
            proxyRedirectMechanism: string
            revisions:
                - string
        tags:
            string: string
        webAppRoutingIngress:
            defaultNginxController: string
            dnsZoneIds:
                - string
            istioEnabled: false
            webAppRoutingIdentities:
                - clientId: string
                  objectId: string
                  userAssignedIdentityId: string
    

    AutomaticCluster Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The AutomaticCluster resource accepts the following input properties:

    Identity AutomaticClusterIdentity
    An identity block as defined below.
    ResourceGroupName string
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    ApiServerAccess AutomaticClusterApiServerAccess
    An apiServerAccess block as defined below.
    HostedSystem AutomaticClusterHostedSystem
    A hostedSystem block as defined below.
    Location string
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    Name string
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    PrivateCluster AutomaticClusterPrivateCluster
    A privateCluster block as defined below.
    ServiceMesh AutomaticClusterServiceMesh
    A serviceMesh block as defined below.
    Tags Dictionary<string, string>
    A mapping of tags to assign to the resource.
    WebAppRoutingIngress AutomaticClusterWebAppRoutingIngress
    A webAppRoutingIngress block as defined below.
    Identity AutomaticClusterIdentityArgs
    An identity block as defined below.
    ResourceGroupName string
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    ApiServerAccess AutomaticClusterApiServerAccessArgs
    An apiServerAccess block as defined below.
    HostedSystem AutomaticClusterHostedSystemArgs
    A hostedSystem block as defined below.
    Location string
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    Name string
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    PrivateCluster AutomaticClusterPrivateClusterArgs
    A privateCluster block as defined below.
    ServiceMesh AutomaticClusterServiceMeshArgs
    A serviceMesh block as defined below.
    Tags map[string]string
    A mapping of tags to assign to the resource.
    WebAppRoutingIngress AutomaticClusterWebAppRoutingIngressArgs
    A webAppRoutingIngress block as defined below.
    identity object
    An identity block as defined below.
    resource_group_name string
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    api_server_access object
    An apiServerAccess block as defined below.
    hosted_system object
    A hostedSystem block as defined below.
    location string
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    name string
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    private_cluster object
    A privateCluster block as defined below.
    service_mesh object
    A serviceMesh block as defined below.
    tags map(string)
    A mapping of tags to assign to the resource.
    web_app_routing_ingress object
    A webAppRoutingIngress block as defined below.
    identity AutomaticClusterIdentity
    An identity block as defined below.
    resourceGroupName String
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    apiServerAccess AutomaticClusterApiServerAccess
    An apiServerAccess block as defined below.
    hostedSystem AutomaticClusterHostedSystem
    A hostedSystem block as defined below.
    location String
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    name String
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    privateCluster AutomaticClusterPrivateCluster
    A privateCluster block as defined below.
    serviceMesh AutomaticClusterServiceMesh
    A serviceMesh block as defined below.
    tags Map<String,String>
    A mapping of tags to assign to the resource.
    webAppRoutingIngress AutomaticClusterWebAppRoutingIngress
    A webAppRoutingIngress block as defined below.
    identity AutomaticClusterIdentity
    An identity block as defined below.
    resourceGroupName string
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    apiServerAccess AutomaticClusterApiServerAccess
    An apiServerAccess block as defined below.
    hostedSystem AutomaticClusterHostedSystem
    A hostedSystem block as defined below.
    location string
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    name string
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    privateCluster AutomaticClusterPrivateCluster
    A privateCluster block as defined below.
    serviceMesh AutomaticClusterServiceMesh
    A serviceMesh block as defined below.
    tags {[key: string]: string}
    A mapping of tags to assign to the resource.
    webAppRoutingIngress AutomaticClusterWebAppRoutingIngress
    A webAppRoutingIngress block as defined below.
    identity AutomaticClusterIdentityArgs
    An identity block as defined below.
    resource_group_name str
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    api_server_access AutomaticClusterApiServerAccessArgs
    An apiServerAccess block as defined below.
    hosted_system AutomaticClusterHostedSystemArgs
    A hostedSystem block as defined below.
    location str
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    name str
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    private_cluster AutomaticClusterPrivateClusterArgs
    A privateCluster block as defined below.
    service_mesh AutomaticClusterServiceMeshArgs
    A serviceMesh block as defined below.
    tags Mapping[str, str]
    A mapping of tags to assign to the resource.
    web_app_routing_ingress AutomaticClusterWebAppRoutingIngressArgs
    A webAppRoutingIngress block as defined below.
    identity Property Map
    An identity block as defined below.
    resourceGroupName String
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    apiServerAccess Property Map
    An apiServerAccess block as defined below.
    hostedSystem Property Map
    A hostedSystem block as defined below.
    location String
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    name String
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    privateCluster Property Map
    A privateCluster block as defined below.
    serviceMesh Property Map
    A serviceMesh block as defined below.
    tags Map<String>
    A mapping of tags to assign to the resource.
    webAppRoutingIngress Property Map
    A webAppRoutingIngress block as defined below.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the AutomaticCluster resource produces the following output properties:

    CurrentKubernetesVersion string
    The current version running on the Azure Kubernetes Managed Cluster.
    FullyQualifiedDomainName string
    The FQDN of the Azure Kubernetes Managed Cluster.
    Id string
    The provider-assigned unique ID for this managed resource.
    KubeConfigRaw string
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    KubeConfigs List<AutomaticClusterKubeConfig>
    A kubeConfig block as defined below.
    NodeResourceGroupId string
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    OidcIssuerUrl string
    The OIDC issuer URL that is associated with the cluster.
    PortalFullyQualifiedDomainName string
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    PrivateFullyQualifiedDomainName string
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    CurrentKubernetesVersion string
    The current version running on the Azure Kubernetes Managed Cluster.
    FullyQualifiedDomainName string
    The FQDN of the Azure Kubernetes Managed Cluster.
    Id string
    The provider-assigned unique ID for this managed resource.
    KubeConfigRaw string
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    KubeConfigs []AutomaticClusterKubeConfig
    A kubeConfig block as defined below.
    NodeResourceGroupId string
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    OidcIssuerUrl string
    The OIDC issuer URL that is associated with the cluster.
    PortalFullyQualifiedDomainName string
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    PrivateFullyQualifiedDomainName string
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    current_kubernetes_version string
    The current version running on the Azure Kubernetes Managed Cluster.
    fully_qualified_domain_name string
    The FQDN of the Azure Kubernetes Managed Cluster.
    id string
    The provider-assigned unique ID for this managed resource.
    kube_config_raw string
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    kube_configs list(object)
    A kubeConfig block as defined below.
    node_resource_group_id string
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    oidc_issuer_url string
    The OIDC issuer URL that is associated with the cluster.
    portal_fully_qualified_domain_name string
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    private_fully_qualified_domain_name string
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    currentKubernetesVersion String
    The current version running on the Azure Kubernetes Managed Cluster.
    fullyQualifiedDomainName String
    The FQDN of the Azure Kubernetes Managed Cluster.
    id String
    The provider-assigned unique ID for this managed resource.
    kubeConfigRaw String
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    kubeConfigs List<AutomaticClusterKubeConfig>
    A kubeConfig block as defined below.
    nodeResourceGroupId String
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    oidcIssuerUrl String
    The OIDC issuer URL that is associated with the cluster.
    portalFullyQualifiedDomainName String
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    privateFullyQualifiedDomainName String
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    currentKubernetesVersion string
    The current version running on the Azure Kubernetes Managed Cluster.
    fullyQualifiedDomainName string
    The FQDN of the Azure Kubernetes Managed Cluster.
    id string
    The provider-assigned unique ID for this managed resource.
    kubeConfigRaw string
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    kubeConfigs AutomaticClusterKubeConfig[]
    A kubeConfig block as defined below.
    nodeResourceGroupId string
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    oidcIssuerUrl string
    The OIDC issuer URL that is associated with the cluster.
    portalFullyQualifiedDomainName string
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    privateFullyQualifiedDomainName string
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    current_kubernetes_version str
    The current version running on the Azure Kubernetes Managed Cluster.
    fully_qualified_domain_name str
    The FQDN of the Azure Kubernetes Managed Cluster.
    id str
    The provider-assigned unique ID for this managed resource.
    kube_config_raw str
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    kube_configs Sequence[AutomaticClusterKubeConfig]
    A kubeConfig block as defined below.
    node_resource_group_id str
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    oidc_issuer_url str
    The OIDC issuer URL that is associated with the cluster.
    portal_fully_qualified_domain_name str
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    private_fully_qualified_domain_name str
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    currentKubernetesVersion String
    The current version running on the Azure Kubernetes Managed Cluster.
    fullyQualifiedDomainName String
    The FQDN of the Azure Kubernetes Managed Cluster.
    id String
    The provider-assigned unique ID for this managed resource.
    kubeConfigRaw String
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    kubeConfigs List<Property Map>
    A kubeConfig block as defined below.
    nodeResourceGroupId String
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    oidcIssuerUrl String
    The OIDC issuer URL that is associated with the cluster.
    portalFullyQualifiedDomainName String
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    privateFullyQualifiedDomainName String
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.

    Look up Existing AutomaticCluster Resource

    Get an existing AutomaticCluster resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

    public static get(name: string, id: Input<ID>, state?: AutomaticClusterState, opts?: CustomResourceOptions): AutomaticCluster
    @staticmethod
    def get(resource_name: str,
            id: str,
            opts: Optional[ResourceOptions] = None,
            api_server_access: Optional[AutomaticClusterApiServerAccessArgs] = None,
            current_kubernetes_version: Optional[str] = None,
            fully_qualified_domain_name: Optional[str] = None,
            hosted_system: Optional[AutomaticClusterHostedSystemArgs] = None,
            identity: Optional[AutomaticClusterIdentityArgs] = None,
            kube_config_raw: Optional[str] = None,
            kube_configs: Optional[Sequence[AutomaticClusterKubeConfigArgs]] = None,
            location: Optional[str] = None,
            name: Optional[str] = None,
            node_resource_group_id: Optional[str] = None,
            oidc_issuer_url: Optional[str] = None,
            portal_fully_qualified_domain_name: Optional[str] = None,
            private_cluster: Optional[AutomaticClusterPrivateClusterArgs] = None,
            private_fully_qualified_domain_name: Optional[str] = None,
            resource_group_name: Optional[str] = None,
            service_mesh: Optional[AutomaticClusterServiceMeshArgs] = None,
            tags: Optional[Mapping[str, str]] = None,
            web_app_routing_ingress: Optional[AutomaticClusterWebAppRoutingIngressArgs] = None) -> AutomaticCluster
    func GetAutomaticCluster(ctx *Context, name string, id IDInput, state *AutomaticClusterState, opts ...ResourceOption) (*AutomaticCluster, error)
    public static AutomaticCluster Get(string name, Input<string> id, AutomaticClusterState? state, CustomResourceOptions? opts = null)
    public static AutomaticCluster get(String name, Output<String> id, AutomaticClusterState state, CustomResourceOptions options)
    resources:  _:    type: azure:containerservice:AutomaticCluster    get:      id: ${id}
    import {
      to = azure_containerservice_automatic_cluster.example
      id = "${id}"
    }
    
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    resource_name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    The following state arguments are supported:
    ApiServerAccess AutomaticClusterApiServerAccess
    An apiServerAccess block as defined below.
    CurrentKubernetesVersion string
    The current version running on the Azure Kubernetes Managed Cluster.
    FullyQualifiedDomainName string
    The FQDN of the Azure Kubernetes Managed Cluster.
    HostedSystem AutomaticClusterHostedSystem
    A hostedSystem block as defined below.
    Identity AutomaticClusterIdentity
    An identity block as defined below.
    KubeConfigRaw string
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    KubeConfigs List<AutomaticClusterKubeConfig>
    A kubeConfig block as defined below.
    Location string
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    Name string
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    NodeResourceGroupId string
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    OidcIssuerUrl string
    The OIDC issuer URL that is associated with the cluster.
    PortalFullyQualifiedDomainName string
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    PrivateCluster AutomaticClusterPrivateCluster
    A privateCluster block as defined below.
    PrivateFullyQualifiedDomainName string
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    ResourceGroupName string
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    ServiceMesh AutomaticClusterServiceMesh
    A serviceMesh block as defined below.
    Tags Dictionary<string, string>
    A mapping of tags to assign to the resource.
    WebAppRoutingIngress AutomaticClusterWebAppRoutingIngress
    A webAppRoutingIngress block as defined below.
    ApiServerAccess AutomaticClusterApiServerAccessArgs
    An apiServerAccess block as defined below.
    CurrentKubernetesVersion string
    The current version running on the Azure Kubernetes Managed Cluster.
    FullyQualifiedDomainName string
    The FQDN of the Azure Kubernetes Managed Cluster.
    HostedSystem AutomaticClusterHostedSystemArgs
    A hostedSystem block as defined below.
    Identity AutomaticClusterIdentityArgs
    An identity block as defined below.
    KubeConfigRaw string
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    KubeConfigs []AutomaticClusterKubeConfigArgs
    A kubeConfig block as defined below.
    Location string
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    Name string
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    NodeResourceGroupId string
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    OidcIssuerUrl string
    The OIDC issuer URL that is associated with the cluster.
    PortalFullyQualifiedDomainName string
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    PrivateCluster AutomaticClusterPrivateClusterArgs
    A privateCluster block as defined below.
    PrivateFullyQualifiedDomainName string
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    ResourceGroupName string
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    ServiceMesh AutomaticClusterServiceMeshArgs
    A serviceMesh block as defined below.
    Tags map[string]string
    A mapping of tags to assign to the resource.
    WebAppRoutingIngress AutomaticClusterWebAppRoutingIngressArgs
    A webAppRoutingIngress block as defined below.
    api_server_access object
    An apiServerAccess block as defined below.
    current_kubernetes_version string
    The current version running on the Azure Kubernetes Managed Cluster.
    fully_qualified_domain_name string
    The FQDN of the Azure Kubernetes Managed Cluster.
    hosted_system object
    A hostedSystem block as defined below.
    identity object
    An identity block as defined below.
    kube_config_raw string
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    kube_configs list(object)
    A kubeConfig block as defined below.
    location string
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    name string
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    node_resource_group_id string
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    oidc_issuer_url string
    The OIDC issuer URL that is associated with the cluster.
    portal_fully_qualified_domain_name string
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    private_cluster object
    A privateCluster block as defined below.
    private_fully_qualified_domain_name string
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    resource_group_name string
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    service_mesh object
    A serviceMesh block as defined below.
    tags map(string)
    A mapping of tags to assign to the resource.
    web_app_routing_ingress object
    A webAppRoutingIngress block as defined below.
    apiServerAccess AutomaticClusterApiServerAccess
    An apiServerAccess block as defined below.
    currentKubernetesVersion String
    The current version running on the Azure Kubernetes Managed Cluster.
    fullyQualifiedDomainName String
    The FQDN of the Azure Kubernetes Managed Cluster.
    hostedSystem AutomaticClusterHostedSystem
    A hostedSystem block as defined below.
    identity AutomaticClusterIdentity
    An identity block as defined below.
    kubeConfigRaw String
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    kubeConfigs List<AutomaticClusterKubeConfig>
    A kubeConfig block as defined below.
    location String
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    name String
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    nodeResourceGroupId String
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    oidcIssuerUrl String
    The OIDC issuer URL that is associated with the cluster.
    portalFullyQualifiedDomainName String
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    privateCluster AutomaticClusterPrivateCluster
    A privateCluster block as defined below.
    privateFullyQualifiedDomainName String
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    resourceGroupName String
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    serviceMesh AutomaticClusterServiceMesh
    A serviceMesh block as defined below.
    tags Map<String,String>
    A mapping of tags to assign to the resource.
    webAppRoutingIngress AutomaticClusterWebAppRoutingIngress
    A webAppRoutingIngress block as defined below.
    apiServerAccess AutomaticClusterApiServerAccess
    An apiServerAccess block as defined below.
    currentKubernetesVersion string
    The current version running on the Azure Kubernetes Managed Cluster.
    fullyQualifiedDomainName string
    The FQDN of the Azure Kubernetes Managed Cluster.
    hostedSystem AutomaticClusterHostedSystem
    A hostedSystem block as defined below.
    identity AutomaticClusterIdentity
    An identity block as defined below.
    kubeConfigRaw string
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    kubeConfigs AutomaticClusterKubeConfig[]
    A kubeConfig block as defined below.
    location string
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    name string
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    nodeResourceGroupId string
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    oidcIssuerUrl string
    The OIDC issuer URL that is associated with the cluster.
    portalFullyQualifiedDomainName string
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    privateCluster AutomaticClusterPrivateCluster
    A privateCluster block as defined below.
    privateFullyQualifiedDomainName string
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    resourceGroupName string
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    serviceMesh AutomaticClusterServiceMesh
    A serviceMesh block as defined below.
    tags {[key: string]: string}
    A mapping of tags to assign to the resource.
    webAppRoutingIngress AutomaticClusterWebAppRoutingIngress
    A webAppRoutingIngress block as defined below.
    api_server_access AutomaticClusterApiServerAccessArgs
    An apiServerAccess block as defined below.
    current_kubernetes_version str
    The current version running on the Azure Kubernetes Managed Cluster.
    fully_qualified_domain_name str
    The FQDN of the Azure Kubernetes Managed Cluster.
    hosted_system AutomaticClusterHostedSystemArgs
    A hostedSystem block as defined below.
    identity AutomaticClusterIdentityArgs
    An identity block as defined below.
    kube_config_raw str
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    kube_configs Sequence[AutomaticClusterKubeConfigArgs]
    A kubeConfig block as defined below.
    location str
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    name str
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    node_resource_group_id str
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    oidc_issuer_url str
    The OIDC issuer URL that is associated with the cluster.
    portal_fully_qualified_domain_name str
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    private_cluster AutomaticClusterPrivateClusterArgs
    A privateCluster block as defined below.
    private_fully_qualified_domain_name str
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    resource_group_name str
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    service_mesh AutomaticClusterServiceMeshArgs
    A serviceMesh block as defined below.
    tags Mapping[str, str]
    A mapping of tags to assign to the resource.
    web_app_routing_ingress AutomaticClusterWebAppRoutingIngressArgs
    A webAppRoutingIngress block as defined below.
    apiServerAccess Property Map
    An apiServerAccess block as defined below.
    currentKubernetesVersion String
    The current version running on the Azure Kubernetes Managed Cluster.
    fullyQualifiedDomainName String
    The FQDN of the Azure Kubernetes Managed Cluster.
    hostedSystem Property Map
    A hostedSystem block as defined below.
    identity Property Map
    An identity block as defined below.
    kubeConfigRaw String
    Raw Kubernetes config to be used by kubectl and other compatible tools.
    kubeConfigs List<Property Map>
    A kubeConfig block as defined below.
    location String
    The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
    name String
    The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
    nodeResourceGroupId String
    The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
    oidcIssuerUrl String
    The OIDC issuer URL that is associated with the cluster.
    portalFullyQualifiedDomainName String
    The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    privateCluster Property Map
    A privateCluster block as defined below.
    privateFullyQualifiedDomainName String
    The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
    resourceGroupName String
    Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
    serviceMesh Property Map
    A serviceMesh block as defined below.
    tags Map<String>
    A mapping of tags to assign to the resource.
    webAppRoutingIngress Property Map
    A webAppRoutingIngress block as defined below.

    Supporting Types

    AutomaticClusterApiServerAccess, AutomaticClusterApiServerAccessArgs

    AuthorizedIpRanges List<string>
    Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
    SubnetId string
    The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
    AuthorizedIpRanges []string
    Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
    SubnetId string
    The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
    authorized_ip_ranges list(string)
    Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
    subnet_id string
    The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
    authorizedIpRanges List<String>
    Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
    subnetId String
    The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
    authorizedIpRanges string[]
    Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
    subnetId string
    The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
    authorized_ip_ranges Sequence[str]
    Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
    subnet_id str
    The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
    authorizedIpRanges List<String>
    Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
    subnetId String
    The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.

    AutomaticClusterHostedSystem, AutomaticClusterHostedSystemArgs

    NodeSubnetId string
    The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
    SystemNodeSubnetId string
    The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
    NodeSubnetId string
    The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
    SystemNodeSubnetId string
    The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
    node_subnet_id string
    The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
    system_node_subnet_id string
    The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
    nodeSubnetId String
    The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
    systemNodeSubnetId String
    The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
    nodeSubnetId string
    The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
    systemNodeSubnetId string
    The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
    node_subnet_id str
    The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
    system_node_subnet_id str
    The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
    nodeSubnetId String
    The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
    systemNodeSubnetId String
    The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking

    AutomaticClusterIdentity, AutomaticClusterIdentityArgs

    Type string
    Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are SystemAssigned or UserAssigned. UserAssigned is required for bring your own networking
    IdentityIds List<string>

    Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.

    Note: This is required when type is set to UserAssigned.

    PrincipalId string
    The Principal ID associated with this Managed Service Identity.
    TenantId string
    The Tenant ID associated with this Managed Service Identity.
    Type string
    Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are SystemAssigned or UserAssigned. UserAssigned is required for bring your own networking
    IdentityIds []string

    Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.

    Note: This is required when type is set to UserAssigned.

    PrincipalId string
    The Principal ID associated with this Managed Service Identity.
    TenantId string
    The Tenant ID associated with this Managed Service Identity.
    type string
    Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are SystemAssigned or UserAssigned. UserAssigned is required for bring your own networking
    identity_ids list(string)

    Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.

    Note: This is required when type is set to UserAssigned.

    principal_id string
    The Principal ID associated with this Managed Service Identity.
    tenant_id string
    The Tenant ID associated with this Managed Service Identity.
    type String
    Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are SystemAssigned or UserAssigned. UserAssigned is required for bring your own networking
    identityIds List<String>

    Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.

    Note: This is required when type is set to UserAssigned.

    principalId String
    The Principal ID associated with this Managed Service Identity.
    tenantId String
    The Tenant ID associated with this Managed Service Identity.
    type string
    Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are SystemAssigned or UserAssigned. UserAssigned is required for bring your own networking
    identityIds string[]

    Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.

    Note: This is required when type is set to UserAssigned.

    principalId string
    The Principal ID associated with this Managed Service Identity.
    tenantId string
    The Tenant ID associated with this Managed Service Identity.
    type str
    Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are SystemAssigned or UserAssigned. UserAssigned is required for bring your own networking
    identity_ids Sequence[str]

    Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.

    Note: This is required when type is set to UserAssigned.

    principal_id str
    The Principal ID associated with this Managed Service Identity.
    tenant_id str
    The Tenant ID associated with this Managed Service Identity.
    type String
    Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are SystemAssigned or UserAssigned. UserAssigned is required for bring your own networking
    identityIds List<String>

    Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.

    Note: This is required when type is set to UserAssigned.

    principalId String
    The Principal ID associated with this Managed Service Identity.
    tenantId String
    The Tenant ID associated with this Managed Service Identity.

    AutomaticClusterKubeConfig, AutomaticClusterKubeConfigArgs

    ClientCertificate string
    Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
    ClientKey string
    Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
    ClusterCaCertificate string
    Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
    Host string
    The Kubernetes cluster server host.
    Password string
    A password or token used to authenticate to the Kubernetes cluster.
    Username string
    A username used to authenticate to the Kubernetes cluster.
    ClientCertificate string
    Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
    ClientKey string
    Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
    ClusterCaCertificate string
    Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
    Host string
    The Kubernetes cluster server host.
    Password string
    A password or token used to authenticate to the Kubernetes cluster.
    Username string
    A username used to authenticate to the Kubernetes cluster.
    client_certificate string
    Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
    client_key string
    Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
    cluster_ca_certificate string
    Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
    host string
    The Kubernetes cluster server host.
    password string
    A password or token used to authenticate to the Kubernetes cluster.
    username string
    A username used to authenticate to the Kubernetes cluster.
    clientCertificate String
    Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
    clientKey String
    Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
    clusterCaCertificate String
    Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
    host String
    The Kubernetes cluster server host.
    password String
    A password or token used to authenticate to the Kubernetes cluster.
    username String
    A username used to authenticate to the Kubernetes cluster.
    clientCertificate string
    Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
    clientKey string
    Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
    clusterCaCertificate string
    Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
    host string
    The Kubernetes cluster server host.
    password string
    A password or token used to authenticate to the Kubernetes cluster.
    username string
    A username used to authenticate to the Kubernetes cluster.
    client_certificate str
    Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
    client_key str
    Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
    cluster_ca_certificate str
    Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
    host str
    The Kubernetes cluster server host.
    password str
    A password or token used to authenticate to the Kubernetes cluster.
    username str
    A username used to authenticate to the Kubernetes cluster.
    clientCertificate String
    Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
    clientKey String
    Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
    clusterCaCertificate String
    Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
    host String
    The Kubernetes cluster server host.
    password String
    A password or token used to authenticate to the Kubernetes cluster.
    username String
    A username used to authenticate to the Kubernetes cluster.

    AutomaticClusterPrivateCluster, AutomaticClusterPrivateClusterArgs

    PrivateDnsZoneId string
    The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are System, None or the ID of a Private DNS Zone. Defaults to System. Changing this forces a new resource to be created.
    PublicFullyQualifiedDomainNameEnabled bool
    Provisions a Public FQDN for the private cluster. Defaults to false.
    PrivateDnsZoneId string
    The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are System, None or the ID of a Private DNS Zone. Defaults to System. Changing this forces a new resource to be created.
    PublicFullyQualifiedDomainNameEnabled bool
    Provisions a Public FQDN for the private cluster. Defaults to false.
    private_dns_zone_id string
    The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are System, None or the ID of a Private DNS Zone. Defaults to System. Changing this forces a new resource to be created.
    public_fully_qualified_domain_name_enabled bool
    Provisions a Public FQDN for the private cluster. Defaults to false.
    privateDnsZoneId String
    The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are System, None or the ID of a Private DNS Zone. Defaults to System. Changing this forces a new resource to be created.
    publicFullyQualifiedDomainNameEnabled Boolean
    Provisions a Public FQDN for the private cluster. Defaults to false.
    privateDnsZoneId string
    The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are System, None or the ID of a Private DNS Zone. Defaults to System. Changing this forces a new resource to be created.
    publicFullyQualifiedDomainNameEnabled boolean
    Provisions a Public FQDN for the private cluster. Defaults to false.
    private_dns_zone_id str
    The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are System, None or the ID of a Private DNS Zone. Defaults to System. Changing this forces a new resource to be created.
    public_fully_qualified_domain_name_enabled bool
    Provisions a Public FQDN for the private cluster. Defaults to false.
    privateDnsZoneId String
    The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are System, None or the ID of a Private DNS Zone. Defaults to System. Changing this forces a new resource to be created.
    publicFullyQualifiedDomainNameEnabled Boolean
    Provisions a Public FQDN for the private cluster. Defaults to false.

    AutomaticClusterServiceMesh, AutomaticClusterServiceMeshArgs

    Revisions List<string>

    Specify 1 or 2 Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource with revisions set to ["asm-1-27"]. To start the canary upgrade, change revisions to ["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to ["asm-1-27"]. To confirm the upgrade, change to ["asm-1-28"].

    Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.

    CertificateAuthority AutomaticClusterServiceMeshCertificateAuthority
    A certificateAuthority block as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service.
    ExternalIngressGatewayEnabled bool

    Enables Istio External Ingress Gateway. Defaults to false.

    Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster

    InternalIngressGatewayEnabled bool
    Enables Istio Internal Ingress Gateway. Defaults to false.
    ProxyRedirectMechanism string
    The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are CNIChaining and InitContainers. Defaults to InitContainers.
    Revisions []string

    Specify 1 or 2 Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource with revisions set to ["asm-1-27"]. To start the canary upgrade, change revisions to ["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to ["asm-1-27"]. To confirm the upgrade, change to ["asm-1-28"].

    Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.

    CertificateAuthority AutomaticClusterServiceMeshCertificateAuthority
    A certificateAuthority block as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service.
    ExternalIngressGatewayEnabled bool

    Enables Istio External Ingress Gateway. Defaults to false.

    Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster

    InternalIngressGatewayEnabled bool
    Enables Istio Internal Ingress Gateway. Defaults to false.
    ProxyRedirectMechanism string
    The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are CNIChaining and InitContainers. Defaults to InitContainers.
    revisions list(string)

    Specify 1 or 2 Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource with revisions set to ["asm-1-27"]. To start the canary upgrade, change revisions to ["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to ["asm-1-27"]. To confirm the upgrade, change to ["asm-1-28"].

    Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.

    certificate_authority object
    A certificateAuthority block as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service.
    external_ingress_gateway_enabled bool

    Enables Istio External Ingress Gateway. Defaults to false.

    Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster

    internal_ingress_gateway_enabled bool
    Enables Istio Internal Ingress Gateway. Defaults to false.
    proxy_redirect_mechanism string
    The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are CNIChaining and InitContainers. Defaults to InitContainers.
    revisions List<String>

    Specify 1 or 2 Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource with revisions set to ["asm-1-27"]. To start the canary upgrade, change revisions to ["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to ["asm-1-27"]. To confirm the upgrade, change to ["asm-1-28"].

    Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.

    certificateAuthority AutomaticClusterServiceMeshCertificateAuthority
    A certificateAuthority block as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service.
    externalIngressGatewayEnabled Boolean

    Enables Istio External Ingress Gateway. Defaults to false.

    Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster

    internalIngressGatewayEnabled Boolean
    Enables Istio Internal Ingress Gateway. Defaults to false.
    proxyRedirectMechanism String
    The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are CNIChaining and InitContainers. Defaults to InitContainers.
    revisions string[]

    Specify 1 or 2 Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource with revisions set to ["asm-1-27"]. To start the canary upgrade, change revisions to ["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to ["asm-1-27"]. To confirm the upgrade, change to ["asm-1-28"].

    Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.

    certificateAuthority AutomaticClusterServiceMeshCertificateAuthority
    A certificateAuthority block as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service.
    externalIngressGatewayEnabled boolean

    Enables Istio External Ingress Gateway. Defaults to false.

    Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster

    internalIngressGatewayEnabled boolean
    Enables Istio Internal Ingress Gateway. Defaults to false.
    proxyRedirectMechanism string
    The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are CNIChaining and InitContainers. Defaults to InitContainers.
    revisions Sequence[str]

    Specify 1 or 2 Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource with revisions set to ["asm-1-27"]. To start the canary upgrade, change revisions to ["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to ["asm-1-27"]. To confirm the upgrade, change to ["asm-1-28"].

    Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.

    certificate_authority AutomaticClusterServiceMeshCertificateAuthority
    A certificateAuthority block as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service.
    external_ingress_gateway_enabled bool

    Enables Istio External Ingress Gateway. Defaults to false.

    Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster

    internal_ingress_gateway_enabled bool
    Enables Istio Internal Ingress Gateway. Defaults to false.
    proxy_redirect_mechanism str
    The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are CNIChaining and InitContainers. Defaults to InitContainers.
    revisions List<String>

    Specify 1 or 2 Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource with revisions set to ["asm-1-27"]. To start the canary upgrade, change revisions to ["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to ["asm-1-27"]. To confirm the upgrade, change to ["asm-1-28"].

    Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.

    certificateAuthority Property Map
    A certificateAuthority block as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service.
    externalIngressGatewayEnabled Boolean

    Enables Istio External Ingress Gateway. Defaults to false.

    Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster

    internalIngressGatewayEnabled Boolean
    Enables Istio Internal Ingress Gateway. Defaults to false.
    proxyRedirectMechanism String
    The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are CNIChaining and InitContainers. Defaults to InitContainers.

    AutomaticClusterServiceMeshCertificateAuthority, AutomaticClusterServiceMeshCertificateAuthorityArgs

    CertificateChainObjectName string
    The certificate chain object name in Azure Key Vault.
    CertificateObjectName string
    The intermediate certificate object name in Azure Key Vault.
    KeyObjectName string

    The intermediate certificate private key object name in Azure Key Vault.

    Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,

    KeyVaultId string
    The resource ID of the Key Vault.
    RootCertificateObjectName string
    The root certificate object name in Azure Key Vault.
    CertificateChainObjectName string
    The certificate chain object name in Azure Key Vault.
    CertificateObjectName string
    The intermediate certificate object name in Azure Key Vault.
    KeyObjectName string

    The intermediate certificate private key object name in Azure Key Vault.

    Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,

    KeyVaultId string
    The resource ID of the Key Vault.
    RootCertificateObjectName string
    The root certificate object name in Azure Key Vault.
    certificate_chain_object_name string
    The certificate chain object name in Azure Key Vault.
    certificate_object_name string
    The intermediate certificate object name in Azure Key Vault.
    key_object_name string

    The intermediate certificate private key object name in Azure Key Vault.

    Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,

    key_vault_id string
    The resource ID of the Key Vault.
    root_certificate_object_name string
    The root certificate object name in Azure Key Vault.
    certificateChainObjectName String
    The certificate chain object name in Azure Key Vault.
    certificateObjectName String
    The intermediate certificate object name in Azure Key Vault.
    keyObjectName String

    The intermediate certificate private key object name in Azure Key Vault.

    Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,

    keyVaultId String
    The resource ID of the Key Vault.
    rootCertificateObjectName String
    The root certificate object name in Azure Key Vault.
    certificateChainObjectName string
    The certificate chain object name in Azure Key Vault.
    certificateObjectName string
    The intermediate certificate object name in Azure Key Vault.
    keyObjectName string

    The intermediate certificate private key object name in Azure Key Vault.

    Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,

    keyVaultId string
    The resource ID of the Key Vault.
    rootCertificateObjectName string
    The root certificate object name in Azure Key Vault.
    certificate_chain_object_name str
    The certificate chain object name in Azure Key Vault.
    certificate_object_name str
    The intermediate certificate object name in Azure Key Vault.
    key_object_name str

    The intermediate certificate private key object name in Azure Key Vault.

    Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,

    key_vault_id str
    The resource ID of the Key Vault.
    root_certificate_object_name str
    The root certificate object name in Azure Key Vault.
    certificateChainObjectName String
    The certificate chain object name in Azure Key Vault.
    certificateObjectName String
    The intermediate certificate object name in Azure Key Vault.
    keyObjectName String

    The intermediate certificate private key object name in Azure Key Vault.

    Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,

    keyVaultId String
    The resource ID of the Key Vault.
    rootCertificateObjectName String
    The root certificate object name in Azure Key Vault.

    AutomaticClusterWebAppRoutingIngress, AutomaticClusterWebAppRoutingIngressArgs

    DefaultNginxController string
    Specifies the ingress type for the default NginxIngressController custom resource. The allowed values are Internal, External and AnnotationControlled. At least one of defaultNginxController or istioEnabled must be specified.
    DnsZoneIds List<string>
    Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
    IstioEnabled bool
    Enables Istio as a Gateway API implementation. Defaults to false. At least one of defaultNginxController or istioEnabled must be specified.
    WebAppRoutingIdentities List<AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentity>
    DefaultNginxController string
    Specifies the ingress type for the default NginxIngressController custom resource. The allowed values are Internal, External and AnnotationControlled. At least one of defaultNginxController or istioEnabled must be specified.
    DnsZoneIds []string
    Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
    IstioEnabled bool
    Enables Istio as a Gateway API implementation. Defaults to false. At least one of defaultNginxController or istioEnabled must be specified.
    WebAppRoutingIdentities []AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentity
    default_nginx_controller string
    Specifies the ingress type for the default NginxIngressController custom resource. The allowed values are Internal, External and AnnotationControlled. At least one of defaultNginxController or istioEnabled must be specified.
    dns_zone_ids list(string)
    Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
    istio_enabled bool
    Enables Istio as a Gateway API implementation. Defaults to false. At least one of defaultNginxController or istioEnabled must be specified.
    web_app_routing_identities list(object)
    defaultNginxController String
    Specifies the ingress type for the default NginxIngressController custom resource. The allowed values are Internal, External and AnnotationControlled. At least one of defaultNginxController or istioEnabled must be specified.
    dnsZoneIds List<String>
    Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
    istioEnabled Boolean
    Enables Istio as a Gateway API implementation. Defaults to false. At least one of defaultNginxController or istioEnabled must be specified.
    webAppRoutingIdentities List<AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentity>
    defaultNginxController string
    Specifies the ingress type for the default NginxIngressController custom resource. The allowed values are Internal, External and AnnotationControlled. At least one of defaultNginxController or istioEnabled must be specified.
    dnsZoneIds string[]
    Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
    istioEnabled boolean
    Enables Istio as a Gateway API implementation. Defaults to false. At least one of defaultNginxController or istioEnabled must be specified.
    webAppRoutingIdentities AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentity[]
    default_nginx_controller str
    Specifies the ingress type for the default NginxIngressController custom resource. The allowed values are Internal, External and AnnotationControlled. At least one of defaultNginxController or istioEnabled must be specified.
    dns_zone_ids Sequence[str]
    Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
    istio_enabled bool
    Enables Istio as a Gateway API implementation. Defaults to false. At least one of defaultNginxController or istioEnabled must be specified.
    web_app_routing_identities Sequence[AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentity]
    defaultNginxController String
    Specifies the ingress type for the default NginxIngressController custom resource. The allowed values are Internal, External and AnnotationControlled. At least one of defaultNginxController or istioEnabled must be specified.
    dnsZoneIds List<String>
    Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
    istioEnabled Boolean
    Enables Istio as a Gateway API implementation. Defaults to false. At least one of defaultNginxController or istioEnabled must be specified.
    webAppRoutingIdentities List<Property Map>

    AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentity, AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentityArgs

    ClientId string
    The Client ID of the user-defined Managed Identity used for Web App Routing.
    ObjectId string
    The Object ID of the user-defined Managed Identity used for Web App Routing
    UserAssignedIdentityId string
    The ID of the User Assigned Identity used for Web App Routing.
    ClientId string
    The Client ID of the user-defined Managed Identity used for Web App Routing.
    ObjectId string
    The Object ID of the user-defined Managed Identity used for Web App Routing
    UserAssignedIdentityId string
    The ID of the User Assigned Identity used for Web App Routing.
    client_id string
    The Client ID of the user-defined Managed Identity used for Web App Routing.
    object_id string
    The Object ID of the user-defined Managed Identity used for Web App Routing
    user_assigned_identity_id string
    The ID of the User Assigned Identity used for Web App Routing.
    clientId String
    The Client ID of the user-defined Managed Identity used for Web App Routing.
    objectId String
    The Object ID of the user-defined Managed Identity used for Web App Routing
    userAssignedIdentityId String
    The ID of the User Assigned Identity used for Web App Routing.
    clientId string
    The Client ID of the user-defined Managed Identity used for Web App Routing.
    objectId string
    The Object ID of the user-defined Managed Identity used for Web App Routing
    userAssignedIdentityId string
    The ID of the User Assigned Identity used for Web App Routing.
    client_id str
    The Client ID of the user-defined Managed Identity used for Web App Routing.
    object_id str
    The Object ID of the user-defined Managed Identity used for Web App Routing
    user_assigned_identity_id str
    The ID of the User Assigned Identity used for Web App Routing.
    clientId String
    The Client ID of the user-defined Managed Identity used for Web App Routing.
    objectId String
    The Object ID of the user-defined Managed Identity used for Web App Routing
    userAssignedIdentityId String
    The ID of the User Assigned Identity used for Web App Routing.

    Import

    Managed Kubernetes Automatic Clusters can be imported using the resource id, e.g.

    $ pulumi import azure:containerservice/automaticCluster:AutomaticCluster cluster1 /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/group1/providers/Microsoft.ContainerService/managedClusters/cluster1
    

    To learn more about importing existing cloud resources, see Importing resources.

    Package Details

    Repository
    Azure Classic pulumi/pulumi-azure
    License
    Apache-2.0
    Notes
    This Pulumi package is based on the azurerm Terraform Provider.
    azure logo

    We recommend using Azure Native.

    Viewing docs for Azure v6.40.0
    published on Wednesday, Sep 2, 2026 by Pulumi

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial