We recommend using Azure Native.
published on Wednesday, Sep 2, 2026 by Pulumi
We recommend using Azure Native.
published on Wednesday, Sep 2, 2026 by Pulumi
Manages a Managed Kubernetes Automatic Cluster (a special SKU of AKS / Azure Kubernetes Service)
Note: Due to the fast-moving nature of AKS, we recommend using the latest version of the Azure Provider when using AKS - you can find the latest version of the Azure Provider here.
Note: All arguments including the client secret will be stored in the raw state as plain-text. Read more about sensitive data in state.
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as azure from "@pulumi/azure";
const example = new azure.core.ResourceGroup("example", {
name: "example-resources",
location: "West Europe",
});
const exampleAutomaticCluster = new azure.containerservice.AutomaticCluster("example", {
name: "example-aks1",
location: example.location,
resourceGroupName: example.name,
identity: {
type: "SystemAssigned",
},
tags: {
Environment: "Production",
},
});
export const clientCertificate = exampleAutomaticCluster.kubeConfigs[0].clientCertificate;
export const kubeConfig = exampleAutomaticCluster.kubeConfigRaw;
import pulumi
import pulumi_azure as azure
example = azure.core.ResourceGroup("example",
name="example-resources",
location="West Europe")
example_automatic_cluster = azure.containerservice.AutomaticCluster("example",
name="example-aks1",
location=example.location,
resource_group_name=example.name,
identity={
"type": "SystemAssigned",
},
tags={
"Environment": "Production",
})
pulumi.export("clientCertificate", example_automatic_cluster.kube_configs[0].client_certificate)
pulumi.export("kubeConfig", example_automatic_cluster.kube_config_raw)
package main
import (
"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/containerservice"
"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/core"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
example, err := core.NewResourceGroup(ctx, "example", &core.ResourceGroupArgs{
Name: pulumi.String("example-resources"),
Location: pulumi.String("West Europe"),
})
if err != nil {
return err
}
exampleAutomaticCluster, err := containerservice.NewAutomaticCluster(ctx, "example", &containerservice.AutomaticClusterArgs{
Name: pulumi.String("example-aks1"),
Location: example.Location,
ResourceGroupName: example.Name,
Identity: &containerservice.AutomaticClusterIdentityArgs{
Type: pulumi.String("SystemAssigned"),
},
Tags: pulumi.StringMap{
"Environment": pulumi.String("Production"),
},
})
if err != nil {
return err
}
ctx.Export("clientCertificate", exampleAutomaticCluster.KubeConfigs.ApplyT(func(kubeConfigs []containerservice.AutomaticClusterKubeConfig) (*string, error) {
return kubeConfigs[0].ClientCertificate, nil
}).(pulumi.StringPtrOutput))
ctx.Export("kubeConfig", exampleAutomaticCluster.KubeConfigRaw)
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Azure = Pulumi.Azure;
return await Deployment.RunAsync(() =>
{
var example = new Azure.Core.ResourceGroup("example", new()
{
Name = "example-resources",
Location = "West Europe",
});
var exampleAutomaticCluster = new Azure.ContainerService.AutomaticCluster("example", new()
{
Name = "example-aks1",
Location = example.Location,
ResourceGroupName = example.Name,
Identity = new Azure.ContainerService.Inputs.AutomaticClusterIdentityArgs
{
Type = "SystemAssigned",
},
Tags =
{
{ "Environment", "Production" },
},
});
return new Dictionary<string, object?>
{
["clientCertificate"] = exampleAutomaticCluster.KubeConfigs.Apply(kubeConfigs => kubeConfigs[0].ClientCertificate),
["kubeConfig"] = exampleAutomaticCluster.KubeConfigRaw,
};
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.azure.core.ResourceGroup;
import com.pulumi.azure.core.ResourceGroupArgs;
import com.pulumi.azure.containerservice.AutomaticCluster;
import com.pulumi.azure.containerservice.AutomaticClusterArgs;
import com.pulumi.azure.containerservice.inputs.AutomaticClusterIdentityArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var example = new ResourceGroup("example", ResourceGroupArgs.builder()
.name("example-resources")
.location("West Europe")
.build());
var exampleAutomaticCluster = new AutomaticCluster("exampleAutomaticCluster", AutomaticClusterArgs.builder()
.name("example-aks1")
.location(example.location())
.resourceGroupName(example.name())
.identity(AutomaticClusterIdentityArgs.builder()
.type("SystemAssigned")
.build())
.tags(Map.of("Environment", "Production"))
.build());
ctx.export("clientCertificate", exampleAutomaticCluster.kubeConfigs().applyValue(_kubeConfigs -> _kubeConfigs[0].clientCertificate()));
ctx.export("kubeConfig", exampleAutomaticCluster.kubeConfigRaw());
}
}
resources:
example:
type: azure:core:ResourceGroup
properties:
name: example-resources
location: West Europe
exampleAutomaticCluster:
type: azure:containerservice:AutomaticCluster
name: example
properties:
name: example-aks1
location: ${example.location}
resourceGroupName: ${example.name}
identity:
type: SystemAssigned
tags:
Environment: Production
outputs:
clientCertificate: ${exampleAutomaticCluster.kubeConfigs[0].clientCertificate}
kubeConfig: ${exampleAutomaticCluster.kubeConfigRaw}
pulumi {
required_providers {
azure = {
source = "pulumi/azure"
}
}
}
resource "azure_core_resourcegroup" "example" {
name = "example-resources"
location = "West Europe"
}
resource "azure_containerservice_automaticcluster" "example" {
name = "example-aks1"
location = azure_core_resourcegroup.example.location
resource_group_name = azure_core_resourcegroup.example.name
identity = {
type = "SystemAssigned"
}
tags = {
"Environment" = "Production"
}
}
output "clientCertificate" {
value = azure_containerservice_automaticcluster.example.kube_configs[0].client_certificate
}
output "kubeConfig" {
value = azure_containerservice_automaticcluster.example.kube_config_raw
}
Bring your own networking example
import * as pulumi from "@pulumi/pulumi";
import * as azure from "@pulumi/azure";
const example = new azure.core.ResourceGroup("example", {
name: "example-resources",
location: "West Europe",
});
const exampleVirtualNetwork = new azure.network.VirtualNetwork("example", {
name: "example-vnet",
addressSpaces: ["10.1.0.0/16"],
location: example.location,
resourceGroupName: example.name,
});
const node = new azure.network.Subnet("node", {
name: "example-node-subnet",
resourceGroupName: example.name,
virtualNetworkName: exampleVirtualNetwork.name,
addressPrefixes: ["10.1.0.0/24"],
});
const api = new azure.network.Subnet("api", {
name: "example-api-subnet",
resourceGroupName: example.name,
virtualNetworkName: exampleVirtualNetwork.name,
addressPrefixes: ["10.1.1.0/24"],
delegations: [{
name: "aks-delegation",
serviceDelegation: {
actions: ["Microsoft.Network/virtualNetworks/subnets/join/action"],
name: "Microsoft.ContainerService/managedClusters",
},
}],
});
const systemnode = new azure.network.Subnet("systemnode", {
name: "example-systemnode-subnet",
resourceGroupName: example.name,
virtualNetworkName: exampleVirtualNetwork.name,
addressPrefixes: ["10.1.2.0/24"],
});
const exampleUserAssignedIdentity = new azure.authorization.UserAssignedIdentity("example", {
resourceGroupName: example.name,
location: example.location,
name: "example_identity",
});
const network = new azure.authorization.Assignment("network", {
scope: exampleVirtualNetwork.id,
roleDefinitionName: "Network Contributor",
principalId: exampleUserAssignedIdentity.principalId,
});
const exampleAutomaticCluster = new azure.containerservice.AutomaticCluster("example", {
name: "example-aks",
location: example.location,
resourceGroupName: example.name,
hostedSystem: {
nodeSubnetId: node.id,
systemNodeSubnetId: systemnode.id,
},
identity: {
type: "UserAssigned",
identityIds: [exampleUserAssignedIdentity.id],
},
apiServerAccess: {
subnetId: api.id,
},
});
import pulumi
import pulumi_azure as azure
example = azure.core.ResourceGroup("example",
name="example-resources",
location="West Europe")
example_virtual_network = azure.network.VirtualNetwork("example",
name="example-vnet",
address_spaces=["10.1.0.0/16"],
location=example.location,
resource_group_name=example.name)
node = azure.network.Subnet("node",
name="example-node-subnet",
resource_group_name=example.name,
virtual_network_name=example_virtual_network.name,
address_prefixes=["10.1.0.0/24"])
api = azure.network.Subnet("api",
name="example-api-subnet",
resource_group_name=example.name,
virtual_network_name=example_virtual_network.name,
address_prefixes=["10.1.1.0/24"],
delegations=[{
"name": "aks-delegation",
"service_delegation": {
"actions": ["Microsoft.Network/virtualNetworks/subnets/join/action"],
"name": "Microsoft.ContainerService/managedClusters",
},
}])
systemnode = azure.network.Subnet("systemnode",
name="example-systemnode-subnet",
resource_group_name=example.name,
virtual_network_name=example_virtual_network.name,
address_prefixes=["10.1.2.0/24"])
example_user_assigned_identity = azure.authorization.UserAssignedIdentity("example",
resource_group_name=example.name,
location=example.location,
name="example_identity")
network = azure.authorization.Assignment("network",
scope=example_virtual_network.id,
role_definition_name="Network Contributor",
principal_id=example_user_assigned_identity.principal_id)
example_automatic_cluster = azure.containerservice.AutomaticCluster("example",
name="example-aks",
location=example.location,
resource_group_name=example.name,
hosted_system={
"node_subnet_id": node.id,
"system_node_subnet_id": systemnode.id,
},
identity={
"type": "UserAssigned",
"identity_ids": [example_user_assigned_identity.id],
},
api_server_access={
"subnet_id": api.id,
})
package main
import (
"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/authorization"
"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/containerservice"
"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/core"
"github.com/pulumi/pulumi-azure/sdk/v6/go/azure/network"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
example, err := core.NewResourceGroup(ctx, "example", &core.ResourceGroupArgs{
Name: pulumi.String("example-resources"),
Location: pulumi.String("West Europe"),
})
if err != nil {
return err
}
exampleVirtualNetwork, err := network.NewVirtualNetwork(ctx, "example", &network.VirtualNetworkArgs{
Name: pulumi.String("example-vnet"),
AddressSpaces: pulumi.StringArray{
pulumi.String("10.1.0.0/16"),
},
Location: example.Location,
ResourceGroupName: example.Name,
})
if err != nil {
return err
}
node, err := network.NewSubnet(ctx, "node", &network.SubnetArgs{
Name: pulumi.String("example-node-subnet"),
ResourceGroupName: example.Name,
VirtualNetworkName: exampleVirtualNetwork.Name,
AddressPrefixes: pulumi.StringArray{
pulumi.String("10.1.0.0/24"),
},
})
if err != nil {
return err
}
api, err := network.NewSubnet(ctx, "api", &network.SubnetArgs{
Name: pulumi.String("example-api-subnet"),
ResourceGroupName: example.Name,
VirtualNetworkName: exampleVirtualNetwork.Name,
AddressPrefixes: pulumi.StringArray{
pulumi.String("10.1.1.0/24"),
},
Delegations: network.SubnetDelegationArray{
&network.SubnetDelegationArgs{
Name: pulumi.String("aks-delegation"),
ServiceDelegation: &network.SubnetDelegationServiceDelegationArgs{
Actions: pulumi.StringArray{
pulumi.String("Microsoft.Network/virtualNetworks/subnets/join/action"),
},
Name: pulumi.String("Microsoft.ContainerService/managedClusters"),
},
},
},
})
if err != nil {
return err
}
systemnode, err := network.NewSubnet(ctx, "systemnode", &network.SubnetArgs{
Name: pulumi.String("example-systemnode-subnet"),
ResourceGroupName: example.Name,
VirtualNetworkName: exampleVirtualNetwork.Name,
AddressPrefixes: pulumi.StringArray{
pulumi.String("10.1.2.0/24"),
},
})
if err != nil {
return err
}
exampleUserAssignedIdentity, err := authorization.NewUserAssignedIdentity(ctx, "example", &authorization.UserAssignedIdentityArgs{
ResourceGroupName: example.Name,
Location: example.Location,
Name: pulumi.String("example_identity"),
})
if err != nil {
return err
}
_, err = authorization.NewAssignment(ctx, "network", &authorization.AssignmentArgs{
Scope: exampleVirtualNetwork.ID().ToIDOutput().ToStringOutput(),
RoleDefinitionName: pulumi.String("Network Contributor"),
PrincipalId: exampleUserAssignedIdentity.PrincipalId,
})
if err != nil {
return err
}
_, err = containerservice.NewAutomaticCluster(ctx, "example", &containerservice.AutomaticClusterArgs{
Name: pulumi.String("example-aks"),
Location: example.Location,
ResourceGroupName: example.Name,
HostedSystem: &containerservice.AutomaticClusterHostedSystemArgs{
NodeSubnetId: node.ID().ToIDOutput().ToStringOutput(),
SystemNodeSubnetId: systemnode.ID().ToIDOutput().ToStringOutput(),
},
Identity: &containerservice.AutomaticClusterIdentityArgs{
Type: pulumi.String("UserAssigned"),
IdentityIds: pulumi.StringArray{
exampleUserAssignedIdentity.ID().ToIDOutput().ToStringOutput(),
},
},
ApiServerAccess: &containerservice.AutomaticClusterApiServerAccessArgs{
SubnetId: api.ID().ToIDOutput().ToStringOutput(),
},
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Azure = Pulumi.Azure;
return await Deployment.RunAsync(() =>
{
var example = new Azure.Core.ResourceGroup("example", new()
{
Name = "example-resources",
Location = "West Europe",
});
var exampleVirtualNetwork = new Azure.Network.VirtualNetwork("example", new()
{
Name = "example-vnet",
AddressSpaces = new[]
{
"10.1.0.0/16",
},
Location = example.Location,
ResourceGroupName = example.Name,
});
var node = new Azure.Network.Subnet("node", new()
{
Name = "example-node-subnet",
ResourceGroupName = example.Name,
VirtualNetworkName = exampleVirtualNetwork.Name,
AddressPrefixes = new[]
{
"10.1.0.0/24",
},
});
var api = new Azure.Network.Subnet("api", new()
{
Name = "example-api-subnet",
ResourceGroupName = example.Name,
VirtualNetworkName = exampleVirtualNetwork.Name,
AddressPrefixes = new[]
{
"10.1.1.0/24",
},
Delegations = new[]
{
new Azure.Network.Inputs.SubnetDelegationArgs
{
Name = "aks-delegation",
ServiceDelegation = new Azure.Network.Inputs.SubnetDelegationServiceDelegationArgs
{
Actions = new[]
{
"Microsoft.Network/virtualNetworks/subnets/join/action",
},
Name = "Microsoft.ContainerService/managedClusters",
},
},
},
});
var systemnode = new Azure.Network.Subnet("systemnode", new()
{
Name = "example-systemnode-subnet",
ResourceGroupName = example.Name,
VirtualNetworkName = exampleVirtualNetwork.Name,
AddressPrefixes = new[]
{
"10.1.2.0/24",
},
});
var exampleUserAssignedIdentity = new Azure.Authorization.UserAssignedIdentity("example", new()
{
ResourceGroupName = example.Name,
Location = example.Location,
Name = "example_identity",
});
var network = new Azure.Authorization.Assignment("network", new()
{
Scope = exampleVirtualNetwork.Id,
RoleDefinitionName = "Network Contributor",
PrincipalId = exampleUserAssignedIdentity.PrincipalId,
});
var exampleAutomaticCluster = new Azure.ContainerService.AutomaticCluster("example", new()
{
Name = "example-aks",
Location = example.Location,
ResourceGroupName = example.Name,
HostedSystem = new Azure.ContainerService.Inputs.AutomaticClusterHostedSystemArgs
{
NodeSubnetId = node.Id,
SystemNodeSubnetId = systemnode.Id,
},
Identity = new Azure.ContainerService.Inputs.AutomaticClusterIdentityArgs
{
Type = "UserAssigned",
IdentityIds = new[]
{
exampleUserAssignedIdentity.Id,
},
},
ApiServerAccess = new Azure.ContainerService.Inputs.AutomaticClusterApiServerAccessArgs
{
SubnetId = api.Id,
},
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.azure.core.ResourceGroup;
import com.pulumi.azure.core.ResourceGroupArgs;
import com.pulumi.azure.network.VirtualNetwork;
import com.pulumi.azure.network.VirtualNetworkArgs;
import com.pulumi.azure.network.Subnet;
import com.pulumi.azure.network.SubnetArgs;
import com.pulumi.azure.network.inputs.SubnetDelegationArgs;
import com.pulumi.azure.network.inputs.SubnetDelegationServiceDelegationArgs;
import com.pulumi.azure.authorization.UserAssignedIdentity;
import com.pulumi.azure.authorization.UserAssignedIdentityArgs;
import com.pulumi.azure.authorization.Assignment;
import com.pulumi.azure.authorization.AssignmentArgs;
import com.pulumi.azure.containerservice.AutomaticCluster;
import com.pulumi.azure.containerservice.AutomaticClusterArgs;
import com.pulumi.azure.containerservice.inputs.AutomaticClusterHostedSystemArgs;
import com.pulumi.azure.containerservice.inputs.AutomaticClusterIdentityArgs;
import com.pulumi.azure.containerservice.inputs.AutomaticClusterApiServerAccessArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var example = new ResourceGroup("example", ResourceGroupArgs.builder()
.name("example-resources")
.location("West Europe")
.build());
var exampleVirtualNetwork = new VirtualNetwork("exampleVirtualNetwork", VirtualNetworkArgs.builder()
.name("example-vnet")
.addressSpaces("10.1.0.0/16")
.location(example.location())
.resourceGroupName(example.name())
.build());
var node = new Subnet("node", SubnetArgs.builder()
.name("example-node-subnet")
.resourceGroupName(example.name())
.virtualNetworkName(exampleVirtualNetwork.name())
.addressPrefixes("10.1.0.0/24")
.build());
var api = new Subnet("api", SubnetArgs.builder()
.name("example-api-subnet")
.resourceGroupName(example.name())
.virtualNetworkName(exampleVirtualNetwork.name())
.addressPrefixes("10.1.1.0/24")
.delegations(SubnetDelegationArgs.builder()
.name("aks-delegation")
.serviceDelegation(SubnetDelegationServiceDelegationArgs.builder()
.actions("Microsoft.Network/virtualNetworks/subnets/join/action")
.name("Microsoft.ContainerService/managedClusters")
.build())
.build())
.build());
var systemnode = new Subnet("systemnode", SubnetArgs.builder()
.name("example-systemnode-subnet")
.resourceGroupName(example.name())
.virtualNetworkName(exampleVirtualNetwork.name())
.addressPrefixes("10.1.2.0/24")
.build());
var exampleUserAssignedIdentity = new UserAssignedIdentity("exampleUserAssignedIdentity", UserAssignedIdentityArgs.builder()
.resourceGroupName(example.name())
.location(example.location())
.name("example_identity")
.build());
var network = new Assignment("network", AssignmentArgs.builder()
.scope(exampleVirtualNetwork.id())
.roleDefinitionName("Network Contributor")
.principalId(exampleUserAssignedIdentity.principalId())
.build());
var exampleAutomaticCluster = new AutomaticCluster("exampleAutomaticCluster", AutomaticClusterArgs.builder()
.name("example-aks")
.location(example.location())
.resourceGroupName(example.name())
.hostedSystem(AutomaticClusterHostedSystemArgs.builder()
.nodeSubnetId(node.id())
.systemNodeSubnetId(systemnode.id())
.build())
.identity(AutomaticClusterIdentityArgs.builder()
.type("UserAssigned")
.identityIds(exampleUserAssignedIdentity.id())
.build())
.apiServerAccess(AutomaticClusterApiServerAccessArgs.builder()
.subnetId(api.id())
.build())
.build());
}
}
resources:
example:
type: azure:core:ResourceGroup
properties:
name: example-resources
location: West Europe
exampleVirtualNetwork:
type: azure:network:VirtualNetwork
name: example
properties:
name: example-vnet
addressSpaces:
- 10.1.0.0/16
location: ${example.location}
resourceGroupName: ${example.name}
node:
type: azure:network:Subnet
properties:
name: example-node-subnet
resourceGroupName: ${example.name}
virtualNetworkName: ${exampleVirtualNetwork.name}
addressPrefixes:
- 10.1.0.0/24
api:
type: azure:network:Subnet
properties:
name: example-api-subnet
resourceGroupName: ${example.name}
virtualNetworkName: ${exampleVirtualNetwork.name}
addressPrefixes:
- 10.1.1.0/24
delegations:
- name: aks-delegation
serviceDelegation:
actions:
- Microsoft.Network/virtualNetworks/subnets/join/action
name: Microsoft.ContainerService/managedClusters
systemnode:
type: azure:network:Subnet
properties:
name: example-systemnode-subnet
resourceGroupName: ${example.name}
virtualNetworkName: ${exampleVirtualNetwork.name}
addressPrefixes:
- 10.1.2.0/24
exampleUserAssignedIdentity:
type: azure:authorization:UserAssignedIdentity
name: example
properties:
resourceGroupName: ${example.name}
location: ${example.location}
name: example_identity
network:
type: azure:authorization:Assignment
properties:
scope: ${exampleVirtualNetwork.id}
roleDefinitionName: Network Contributor
principalId: ${exampleUserAssignedIdentity.principalId}
exampleAutomaticCluster:
type: azure:containerservice:AutomaticCluster
name: example
properties:
name: example-aks
location: ${example.location}
resourceGroupName: ${example.name}
hostedSystem:
nodeSubnetId: ${node.id}
systemNodeSubnetId: ${systemnode.id}
identity:
type: UserAssigned
identityIds:
- ${exampleUserAssignedIdentity.id}
apiServerAccess:
subnetId: ${api.id}
pulumi {
required_providers {
azure = {
source = "pulumi/azure"
}
}
}
resource "azure_core_resourcegroup" "example" {
name = "example-resources"
location = "West Europe"
}
resource "azure_network_virtualnetwork" "example" {
name = "example-vnet"
address_spaces = ["10.1.0.0/16"]
location = azure_core_resourcegroup.example.location
resource_group_name = azure_core_resourcegroup.example.name
}
resource "azure_network_subnet" "node" {
name = "example-node-subnet"
resource_group_name = azure_core_resourcegroup.example.name
virtual_network_name = azure_network_virtualnetwork.example.name
address_prefixes = ["10.1.0.0/24"]
}
resource "azure_network_subnet" "api" {
name = "example-api-subnet"
resource_group_name = azure_core_resourcegroup.example.name
virtual_network_name = azure_network_virtualnetwork.example.name
address_prefixes = ["10.1.1.0/24"]
delegations {
name = "aks-delegation"
service_delegation = {
actions = ["Microsoft.Network/virtualNetworks/subnets/join/action"]
name = "Microsoft.ContainerService/managedClusters"
}
}
}
resource "azure_network_subnet" "systemnode" {
name = "example-systemnode-subnet"
resource_group_name = azure_core_resourcegroup.example.name
virtual_network_name = azure_network_virtualnetwork.example.name
address_prefixes = ["10.1.2.0/24"]
}
resource "azure_authorization_userassignedidentity" "example" {
resource_group_name = azure_core_resourcegroup.example.name
location = azure_core_resourcegroup.example.location
name = "example_identity"
}
resource "azure_authorization_assignment" "network" {
scope = azure_network_virtualnetwork.example.id
role_definition_name = "Network Contributor"
principal_id = azure_authorization_userassignedidentity.example.principal_id
}
resource "azure_containerservice_automaticcluster" "example" {
name = "example-aks"
location = azure_core_resourcegroup.example.location
resource_group_name = azure_core_resourcegroup.example.name
hosted_system = {
node_subnet_id = azure_network_subnet.node.id
system_node_subnet_id = azure_network_subnet.systemnode.id
}
identity = {
type = "UserAssigned"
identity_ids = [azure_authorization_userassignedidentity.example.id]
}
api_server_access = {
subnet_id = azure_network_subnet.api.id
}
}
API Providers
This resource uses the following Azure API Providers:
Microsoft.ContainerService- 2026-04-01
Create AutomaticCluster Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new AutomaticCluster(name: string, args: AutomaticClusterArgs, opts?: CustomResourceOptions);@overload
def AutomaticCluster(resource_name: str,
args: AutomaticClusterArgs,
opts: Optional[ResourceOptions] = None)
@overload
def AutomaticCluster(resource_name: str,
opts: Optional[ResourceOptions] = None,
identity: Optional[AutomaticClusterIdentityArgs] = None,
resource_group_name: Optional[str] = None,
api_server_access: Optional[AutomaticClusterApiServerAccessArgs] = None,
hosted_system: Optional[AutomaticClusterHostedSystemArgs] = None,
location: Optional[str] = None,
name: Optional[str] = None,
private_cluster: Optional[AutomaticClusterPrivateClusterArgs] = None,
service_mesh: Optional[AutomaticClusterServiceMeshArgs] = None,
tags: Optional[Mapping[str, str]] = None,
web_app_routing_ingress: Optional[AutomaticClusterWebAppRoutingIngressArgs] = None)func NewAutomaticCluster(ctx *Context, name string, args AutomaticClusterArgs, opts ...ResourceOption) (*AutomaticCluster, error)public AutomaticCluster(string name, AutomaticClusterArgs args, CustomResourceOptions? opts = null)
public AutomaticCluster(String name, AutomaticClusterArgs args)
public AutomaticCluster(String name, AutomaticClusterArgs args, CustomResourceOptions options)
type: azure:containerservice:AutomaticCluster
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "azure_containerservice_automatic_cluster" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args AutomaticClusterArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args AutomaticClusterArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args AutomaticClusterArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args AutomaticClusterArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args AutomaticClusterArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var automaticClusterResource = new Azure.ContainerService.AutomaticCluster("automaticClusterResource", new()
{
Identity = new Azure.ContainerService.Inputs.AutomaticClusterIdentityArgs
{
Type = "string",
IdentityIds = new[]
{
"string",
},
PrincipalId = "string",
TenantId = "string",
},
ResourceGroupName = "string",
ApiServerAccess = new Azure.ContainerService.Inputs.AutomaticClusterApiServerAccessArgs
{
AuthorizedIpRanges = new[]
{
"string",
},
SubnetId = "string",
},
HostedSystem = new Azure.ContainerService.Inputs.AutomaticClusterHostedSystemArgs
{
NodeSubnetId = "string",
SystemNodeSubnetId = "string",
},
Location = "string",
Name = "string",
PrivateCluster = new Azure.ContainerService.Inputs.AutomaticClusterPrivateClusterArgs
{
PrivateDnsZoneId = "string",
PublicFullyQualifiedDomainNameEnabled = false,
},
ServiceMesh = new Azure.ContainerService.Inputs.AutomaticClusterServiceMeshArgs
{
Revisions = new[]
{
"string",
},
CertificateAuthority = new Azure.ContainerService.Inputs.AutomaticClusterServiceMeshCertificateAuthorityArgs
{
CertificateChainObjectName = "string",
CertificateObjectName = "string",
KeyObjectName = "string",
KeyVaultId = "string",
RootCertificateObjectName = "string",
},
ExternalIngressGatewayEnabled = false,
InternalIngressGatewayEnabled = false,
ProxyRedirectMechanism = "string",
},
Tags =
{
{ "string", "string" },
},
WebAppRoutingIngress = new Azure.ContainerService.Inputs.AutomaticClusterWebAppRoutingIngressArgs
{
DefaultNginxController = "string",
DnsZoneIds = new[]
{
"string",
},
IstioEnabled = false,
WebAppRoutingIdentities = new[]
{
new Azure.ContainerService.Inputs.AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentityArgs
{
ClientId = "string",
ObjectId = "string",
UserAssignedIdentityId = "string",
},
},
},
});
example, err := containerservice.NewAutomaticCluster(ctx, "automaticClusterResource", &containerservice.AutomaticClusterArgs{
Identity: &containerservice.AutomaticClusterIdentityArgs{
Type: pulumi.String("string"),
IdentityIds: pulumi.StringArray{
pulumi.String("string"),
},
PrincipalId: pulumi.String("string"),
TenantId: pulumi.String("string"),
},
ResourceGroupName: pulumi.String("string"),
ApiServerAccess: &containerservice.AutomaticClusterApiServerAccessArgs{
AuthorizedIpRanges: pulumi.StringArray{
pulumi.String("string"),
},
SubnetId: pulumi.String("string"),
},
HostedSystem: &containerservice.AutomaticClusterHostedSystemArgs{
NodeSubnetId: pulumi.String("string"),
SystemNodeSubnetId: pulumi.String("string"),
},
Location: pulumi.String("string"),
Name: pulumi.String("string"),
PrivateCluster: &containerservice.AutomaticClusterPrivateClusterArgs{
PrivateDnsZoneId: pulumi.String("string"),
PublicFullyQualifiedDomainNameEnabled: pulumi.Bool(false),
},
ServiceMesh: &containerservice.AutomaticClusterServiceMeshArgs{
Revisions: pulumi.StringArray{
pulumi.String("string"),
},
CertificateAuthority: &containerservice.AutomaticClusterServiceMeshCertificateAuthorityArgs{
CertificateChainObjectName: pulumi.String("string"),
CertificateObjectName: pulumi.String("string"),
KeyObjectName: pulumi.String("string"),
KeyVaultId: pulumi.String("string"),
RootCertificateObjectName: pulumi.String("string"),
},
ExternalIngressGatewayEnabled: pulumi.Bool(false),
InternalIngressGatewayEnabled: pulumi.Bool(false),
ProxyRedirectMechanism: pulumi.String("string"),
},
Tags: pulumi.StringMap{
"string": pulumi.String("string"),
},
WebAppRoutingIngress: &containerservice.AutomaticClusterWebAppRoutingIngressArgs{
DefaultNginxController: pulumi.String("string"),
DnsZoneIds: pulumi.StringArray{
pulumi.String("string"),
},
IstioEnabled: pulumi.Bool(false),
WebAppRoutingIdentities: containerservice.AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentityArray{
&containerservice.AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentityArgs{
ClientId: pulumi.String("string"),
ObjectId: pulumi.String("string"),
UserAssignedIdentityId: pulumi.String("string"),
},
},
},
})
resource "azure_containerservice_automatic_cluster" "automaticClusterResource" {
lifecycle {
create_before_destroy = true
}
identity = {
type = "string"
identity_ids = ["string"]
principal_id = "string"
tenant_id = "string"
}
resource_group_name = "string"
api_server_access = {
authorized_ip_ranges = ["string"]
subnet_id = "string"
}
hosted_system = {
node_subnet_id = "string"
system_node_subnet_id = "string"
}
location = "string"
name = "string"
private_cluster = {
private_dns_zone_id = "string"
public_fully_qualified_domain_name_enabled = false
}
service_mesh = {
revisions = ["string"]
certificate_authority = {
certificate_chain_object_name = "string"
certificate_object_name = "string"
key_object_name = "string"
key_vault_id = "string"
root_certificate_object_name = "string"
}
external_ingress_gateway_enabled = false
internal_ingress_gateway_enabled = false
proxy_redirect_mechanism = "string"
}
tags = {
"string" = "string"
}
web_app_routing_ingress = {
default_nginx_controller = "string"
dns_zone_ids = ["string"]
istio_enabled = false
web_app_routing_identities = [{
client_id = "string"
object_id = "string"
user_assigned_identity_id = "string"
}]
}
}
var automaticClusterResource = new AutomaticCluster("automaticClusterResource", AutomaticClusterArgs.builder()
.identity(AutomaticClusterIdentityArgs.builder()
.type("string")
.identityIds("string")
.principalId("string")
.tenantId("string")
.build())
.resourceGroupName("string")
.apiServerAccess(AutomaticClusterApiServerAccessArgs.builder()
.authorizedIpRanges("string")
.subnetId("string")
.build())
.hostedSystem(AutomaticClusterHostedSystemArgs.builder()
.nodeSubnetId("string")
.systemNodeSubnetId("string")
.build())
.location("string")
.name("string")
.privateCluster(AutomaticClusterPrivateClusterArgs.builder()
.privateDnsZoneId("string")
.publicFullyQualifiedDomainNameEnabled(false)
.build())
.serviceMesh(AutomaticClusterServiceMeshArgs.builder()
.revisions("string")
.certificateAuthority(AutomaticClusterServiceMeshCertificateAuthorityArgs.builder()
.certificateChainObjectName("string")
.certificateObjectName("string")
.keyObjectName("string")
.keyVaultId("string")
.rootCertificateObjectName("string")
.build())
.externalIngressGatewayEnabled(false)
.internalIngressGatewayEnabled(false)
.proxyRedirectMechanism("string")
.build())
.tags(Map.of("string", "string"))
.webAppRoutingIngress(AutomaticClusterWebAppRoutingIngressArgs.builder()
.defaultNginxController("string")
.dnsZoneIds("string")
.istioEnabled(false)
.webAppRoutingIdentities(AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentityArgs.builder()
.clientId("string")
.objectId("string")
.userAssignedIdentityId("string")
.build())
.build())
.build());
automatic_cluster_resource = azure.containerservice.AutomaticCluster("automaticClusterResource",
identity={
"type": "string",
"identity_ids": ["string"],
"principal_id": "string",
"tenant_id": "string",
},
resource_group_name="string",
api_server_access={
"authorized_ip_ranges": ["string"],
"subnet_id": "string",
},
hosted_system={
"node_subnet_id": "string",
"system_node_subnet_id": "string",
},
location="string",
name="string",
private_cluster={
"private_dns_zone_id": "string",
"public_fully_qualified_domain_name_enabled": False,
},
service_mesh={
"revisions": ["string"],
"certificate_authority": {
"certificate_chain_object_name": "string",
"certificate_object_name": "string",
"key_object_name": "string",
"key_vault_id": "string",
"root_certificate_object_name": "string",
},
"external_ingress_gateway_enabled": False,
"internal_ingress_gateway_enabled": False,
"proxy_redirect_mechanism": "string",
},
tags={
"string": "string",
},
web_app_routing_ingress={
"default_nginx_controller": "string",
"dns_zone_ids": ["string"],
"istio_enabled": False,
"web_app_routing_identities": [{
"client_id": "string",
"object_id": "string",
"user_assigned_identity_id": "string",
}],
})
const automaticClusterResource = new azure.containerservice.AutomaticCluster("automaticClusterResource", {
identity: {
type: "string",
identityIds: ["string"],
principalId: "string",
tenantId: "string",
},
resourceGroupName: "string",
apiServerAccess: {
authorizedIpRanges: ["string"],
subnetId: "string",
},
hostedSystem: {
nodeSubnetId: "string",
systemNodeSubnetId: "string",
},
location: "string",
name: "string",
privateCluster: {
privateDnsZoneId: "string",
publicFullyQualifiedDomainNameEnabled: false,
},
serviceMesh: {
revisions: ["string"],
certificateAuthority: {
certificateChainObjectName: "string",
certificateObjectName: "string",
keyObjectName: "string",
keyVaultId: "string",
rootCertificateObjectName: "string",
},
externalIngressGatewayEnabled: false,
internalIngressGatewayEnabled: false,
proxyRedirectMechanism: "string",
},
tags: {
string: "string",
},
webAppRoutingIngress: {
defaultNginxController: "string",
dnsZoneIds: ["string"],
istioEnabled: false,
webAppRoutingIdentities: [{
clientId: "string",
objectId: "string",
userAssignedIdentityId: "string",
}],
},
});
type: azure:containerservice:AutomaticCluster
properties:
apiServerAccess:
authorizedIpRanges:
- string
subnetId: string
hostedSystem:
nodeSubnetId: string
systemNodeSubnetId: string
identity:
identityIds:
- string
principalId: string
tenantId: string
type: string
location: string
name: string
privateCluster:
privateDnsZoneId: string
publicFullyQualifiedDomainNameEnabled: false
resourceGroupName: string
serviceMesh:
certificateAuthority:
certificateChainObjectName: string
certificateObjectName: string
keyObjectName: string
keyVaultId: string
rootCertificateObjectName: string
externalIngressGatewayEnabled: false
internalIngressGatewayEnabled: false
proxyRedirectMechanism: string
revisions:
- string
tags:
string: string
webAppRoutingIngress:
defaultNginxController: string
dnsZoneIds:
- string
istioEnabled: false
webAppRoutingIdentities:
- clientId: string
objectId: string
userAssignedIdentityId: string
AutomaticCluster Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The AutomaticCluster resource accepts the following input properties:
- Identity
Automatic
Cluster Identity - An
identityblock as defined below. - Resource
Group stringName - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- Api
Server AutomaticAccess Cluster Api Server Access - An
apiServerAccessblock as defined below. - Hosted
System AutomaticCluster Hosted System - A
hostedSystemblock as defined below. - Location string
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- Name string
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- Private
Cluster AutomaticCluster Private Cluster - A
privateClusterblock as defined below. - Service
Mesh AutomaticCluster Service Mesh - A
serviceMeshblock as defined below. - Dictionary<string, string>
- A mapping of tags to assign to the resource.
- Web
App AutomaticRouting Ingress Cluster Web App Routing Ingress - A
webAppRoutingIngressblock as defined below.
- Identity
Automatic
Cluster Identity Args - An
identityblock as defined below. - Resource
Group stringName - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- Api
Server AutomaticAccess Cluster Api Server Access Args - An
apiServerAccessblock as defined below. - Hosted
System AutomaticCluster Hosted System Args - A
hostedSystemblock as defined below. - Location string
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- Name string
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- Private
Cluster AutomaticCluster Private Cluster Args - A
privateClusterblock as defined below. - Service
Mesh AutomaticCluster Service Mesh Args - A
serviceMeshblock as defined below. - map[string]string
- A mapping of tags to assign to the resource.
- Web
App AutomaticRouting Ingress Cluster Web App Routing Ingress Args - A
webAppRoutingIngressblock as defined below.
- identity object
- An
identityblock as defined below. - resource_
group_ stringname - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- api_
server_ objectaccess - An
apiServerAccessblock as defined below. - hosted_
system object - A
hostedSystemblock as defined below. - location string
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- name string
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- private_
cluster object - A
privateClusterblock as defined below. - service_
mesh object - A
serviceMeshblock as defined below. - map(string)
- A mapping of tags to assign to the resource.
- web_
app_ objectrouting_ ingress - A
webAppRoutingIngressblock as defined below.
- identity
Automatic
Cluster Identity - An
identityblock as defined below. - resource
Group StringName - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- api
Server AutomaticAccess Cluster Api Server Access - An
apiServerAccessblock as defined below. - hosted
System AutomaticCluster Hosted System - A
hostedSystemblock as defined below. - location String
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- name String
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- private
Cluster AutomaticCluster Private Cluster - A
privateClusterblock as defined below. - service
Mesh AutomaticCluster Service Mesh - A
serviceMeshblock as defined below. - Map<String,String>
- A mapping of tags to assign to the resource.
- web
App AutomaticRouting Ingress Cluster Web App Routing Ingress - A
webAppRoutingIngressblock as defined below.
- identity
Automatic
Cluster Identity - An
identityblock as defined below. - resource
Group stringName - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- api
Server AutomaticAccess Cluster Api Server Access - An
apiServerAccessblock as defined below. - hosted
System AutomaticCluster Hosted System - A
hostedSystemblock as defined below. - location string
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- name string
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- private
Cluster AutomaticCluster Private Cluster - A
privateClusterblock as defined below. - service
Mesh AutomaticCluster Service Mesh - A
serviceMeshblock as defined below. - {[key: string]: string}
- A mapping of tags to assign to the resource.
- web
App AutomaticRouting Ingress Cluster Web App Routing Ingress - A
webAppRoutingIngressblock as defined below.
- identity
Automatic
Cluster Identity Args - An
identityblock as defined below. - resource_
group_ strname - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- api_
server_ Automaticaccess Cluster Api Server Access Args - An
apiServerAccessblock as defined below. - hosted_
system AutomaticCluster Hosted System Args - A
hostedSystemblock as defined below. - location str
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- name str
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- private_
cluster AutomaticCluster Private Cluster Args - A
privateClusterblock as defined below. - service_
mesh AutomaticCluster Service Mesh Args - A
serviceMeshblock as defined below. - Mapping[str, str]
- A mapping of tags to assign to the resource.
- web_
app_ Automaticrouting_ ingress Cluster Web App Routing Ingress Args - A
webAppRoutingIngressblock as defined below.
- identity Property Map
- An
identityblock as defined below. - resource
Group StringName - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- api
Server Property MapAccess - An
apiServerAccessblock as defined below. - hosted
System Property Map - A
hostedSystemblock as defined below. - location String
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- name String
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- private
Cluster Property Map - A
privateClusterblock as defined below. - service
Mesh Property Map - A
serviceMeshblock as defined below. - Map<String>
- A mapping of tags to assign to the resource.
- web
App Property MapRouting Ingress - A
webAppRoutingIngressblock as defined below.
Outputs
All input properties are implicitly available as output properties. Additionally, the AutomaticCluster resource produces the following output properties:
- Current
Kubernetes stringVersion - The current version running on the Azure Kubernetes Managed Cluster.
- Fully
Qualified stringDomain Name - The FQDN of the Azure Kubernetes Managed Cluster.
- Id string
- The provider-assigned unique ID for this managed resource.
- Kube
Config stringRaw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- Kube
Configs List<AutomaticCluster Kube Config> - A
kubeConfigblock as defined below. - Node
Resource stringGroup Id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- Oidc
Issuer stringUrl - The OIDC issuer URL that is associated with the cluster.
- Portal
Fully stringQualified Domain Name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- Private
Fully stringQualified Domain Name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- Current
Kubernetes stringVersion - The current version running on the Azure Kubernetes Managed Cluster.
- Fully
Qualified stringDomain Name - The FQDN of the Azure Kubernetes Managed Cluster.
- Id string
- The provider-assigned unique ID for this managed resource.
- Kube
Config stringRaw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- Kube
Configs []AutomaticCluster Kube Config - A
kubeConfigblock as defined below. - Node
Resource stringGroup Id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- Oidc
Issuer stringUrl - The OIDC issuer URL that is associated with the cluster.
- Portal
Fully stringQualified Domain Name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- Private
Fully stringQualified Domain Name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- current_
kubernetes_ stringversion - The current version running on the Azure Kubernetes Managed Cluster.
- fully_
qualified_ stringdomain_ name - The FQDN of the Azure Kubernetes Managed Cluster.
- id string
- The provider-assigned unique ID for this managed resource.
- kube_
config_ stringraw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- kube_
configs list(object) - A
kubeConfigblock as defined below. - node_
resource_ stringgroup_ id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- oidc_
issuer_ stringurl - The OIDC issuer URL that is associated with the cluster.
- portal_
fully_ stringqualified_ domain_ name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- private_
fully_ stringqualified_ domain_ name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- current
Kubernetes StringVersion - The current version running on the Azure Kubernetes Managed Cluster.
- fully
Qualified StringDomain Name - The FQDN of the Azure Kubernetes Managed Cluster.
- id String
- The provider-assigned unique ID for this managed resource.
- kube
Config StringRaw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- kube
Configs List<AutomaticCluster Kube Config> - A
kubeConfigblock as defined below. - node
Resource StringGroup Id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- oidc
Issuer StringUrl - The OIDC issuer URL that is associated with the cluster.
- portal
Fully StringQualified Domain Name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- private
Fully StringQualified Domain Name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- current
Kubernetes stringVersion - The current version running on the Azure Kubernetes Managed Cluster.
- fully
Qualified stringDomain Name - The FQDN of the Azure Kubernetes Managed Cluster.
- id string
- The provider-assigned unique ID for this managed resource.
- kube
Config stringRaw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- kube
Configs AutomaticCluster Kube Config[] - A
kubeConfigblock as defined below. - node
Resource stringGroup Id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- oidc
Issuer stringUrl - The OIDC issuer URL that is associated with the cluster.
- portal
Fully stringQualified Domain Name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- private
Fully stringQualified Domain Name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- current_
kubernetes_ strversion - The current version running on the Azure Kubernetes Managed Cluster.
- fully_
qualified_ strdomain_ name - The FQDN of the Azure Kubernetes Managed Cluster.
- id str
- The provider-assigned unique ID for this managed resource.
- kube_
config_ strraw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- kube_
configs Sequence[AutomaticCluster Kube Config] - A
kubeConfigblock as defined below. - node_
resource_ strgroup_ id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- oidc_
issuer_ strurl - The OIDC issuer URL that is associated with the cluster.
- portal_
fully_ strqualified_ domain_ name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- private_
fully_ strqualified_ domain_ name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- current
Kubernetes StringVersion - The current version running on the Azure Kubernetes Managed Cluster.
- fully
Qualified StringDomain Name - The FQDN of the Azure Kubernetes Managed Cluster.
- id String
- The provider-assigned unique ID for this managed resource.
- kube
Config StringRaw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- kube
Configs List<Property Map> - A
kubeConfigblock as defined below. - node
Resource StringGroup Id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- oidc
Issuer StringUrl - The OIDC issuer URL that is associated with the cluster.
- portal
Fully StringQualified Domain Name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- private
Fully StringQualified Domain Name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
Look up Existing AutomaticCluster Resource
Get an existing AutomaticCluster resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: AutomaticClusterState, opts?: CustomResourceOptions): AutomaticCluster@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
api_server_access: Optional[AutomaticClusterApiServerAccessArgs] = None,
current_kubernetes_version: Optional[str] = None,
fully_qualified_domain_name: Optional[str] = None,
hosted_system: Optional[AutomaticClusterHostedSystemArgs] = None,
identity: Optional[AutomaticClusterIdentityArgs] = None,
kube_config_raw: Optional[str] = None,
kube_configs: Optional[Sequence[AutomaticClusterKubeConfigArgs]] = None,
location: Optional[str] = None,
name: Optional[str] = None,
node_resource_group_id: Optional[str] = None,
oidc_issuer_url: Optional[str] = None,
portal_fully_qualified_domain_name: Optional[str] = None,
private_cluster: Optional[AutomaticClusterPrivateClusterArgs] = None,
private_fully_qualified_domain_name: Optional[str] = None,
resource_group_name: Optional[str] = None,
service_mesh: Optional[AutomaticClusterServiceMeshArgs] = None,
tags: Optional[Mapping[str, str]] = None,
web_app_routing_ingress: Optional[AutomaticClusterWebAppRoutingIngressArgs] = None) -> AutomaticClusterfunc GetAutomaticCluster(ctx *Context, name string, id IDInput, state *AutomaticClusterState, opts ...ResourceOption) (*AutomaticCluster, error)public static AutomaticCluster Get(string name, Input<string> id, AutomaticClusterState? state, CustomResourceOptions? opts = null)public static AutomaticCluster get(String name, Output<String> id, AutomaticClusterState state, CustomResourceOptions options)resources: _: type: azure:containerservice:AutomaticCluster get: id: ${id}import {
to = azure_containerservice_automatic_cluster.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Api
Server AutomaticAccess Cluster Api Server Access - An
apiServerAccessblock as defined below. - Current
Kubernetes stringVersion - The current version running on the Azure Kubernetes Managed Cluster.
- Fully
Qualified stringDomain Name - The FQDN of the Azure Kubernetes Managed Cluster.
- Hosted
System AutomaticCluster Hosted System - A
hostedSystemblock as defined below. - Identity
Automatic
Cluster Identity - An
identityblock as defined below. - Kube
Config stringRaw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- Kube
Configs List<AutomaticCluster Kube Config> - A
kubeConfigblock as defined below. - Location string
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- Name string
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- Node
Resource stringGroup Id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- Oidc
Issuer stringUrl - The OIDC issuer URL that is associated with the cluster.
- Portal
Fully stringQualified Domain Name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- Private
Cluster AutomaticCluster Private Cluster - A
privateClusterblock as defined below. - Private
Fully stringQualified Domain Name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- Resource
Group stringName - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- Service
Mesh AutomaticCluster Service Mesh - A
serviceMeshblock as defined below. - Dictionary<string, string>
- A mapping of tags to assign to the resource.
- Web
App AutomaticRouting Ingress Cluster Web App Routing Ingress - A
webAppRoutingIngressblock as defined below.
- Api
Server AutomaticAccess Cluster Api Server Access Args - An
apiServerAccessblock as defined below. - Current
Kubernetes stringVersion - The current version running on the Azure Kubernetes Managed Cluster.
- Fully
Qualified stringDomain Name - The FQDN of the Azure Kubernetes Managed Cluster.
- Hosted
System AutomaticCluster Hosted System Args - A
hostedSystemblock as defined below. - Identity
Automatic
Cluster Identity Args - An
identityblock as defined below. - Kube
Config stringRaw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- Kube
Configs []AutomaticCluster Kube Config Args - A
kubeConfigblock as defined below. - Location string
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- Name string
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- Node
Resource stringGroup Id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- Oidc
Issuer stringUrl - The OIDC issuer URL that is associated with the cluster.
- Portal
Fully stringQualified Domain Name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- Private
Cluster AutomaticCluster Private Cluster Args - A
privateClusterblock as defined below. - Private
Fully stringQualified Domain Name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- Resource
Group stringName - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- Service
Mesh AutomaticCluster Service Mesh Args - A
serviceMeshblock as defined below. - map[string]string
- A mapping of tags to assign to the resource.
- Web
App AutomaticRouting Ingress Cluster Web App Routing Ingress Args - A
webAppRoutingIngressblock as defined below.
- api_
server_ objectaccess - An
apiServerAccessblock as defined below. - current_
kubernetes_ stringversion - The current version running on the Azure Kubernetes Managed Cluster.
- fully_
qualified_ stringdomain_ name - The FQDN of the Azure Kubernetes Managed Cluster.
- hosted_
system object - A
hostedSystemblock as defined below. - identity object
- An
identityblock as defined below. - kube_
config_ stringraw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- kube_
configs list(object) - A
kubeConfigblock as defined below. - location string
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- name string
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- node_
resource_ stringgroup_ id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- oidc_
issuer_ stringurl - The OIDC issuer URL that is associated with the cluster.
- portal_
fully_ stringqualified_ domain_ name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- private_
cluster object - A
privateClusterblock as defined below. - private_
fully_ stringqualified_ domain_ name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- resource_
group_ stringname - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- service_
mesh object - A
serviceMeshblock as defined below. - map(string)
- A mapping of tags to assign to the resource.
- web_
app_ objectrouting_ ingress - A
webAppRoutingIngressblock as defined below.
- api
Server AutomaticAccess Cluster Api Server Access - An
apiServerAccessblock as defined below. - current
Kubernetes StringVersion - The current version running on the Azure Kubernetes Managed Cluster.
- fully
Qualified StringDomain Name - The FQDN of the Azure Kubernetes Managed Cluster.
- hosted
System AutomaticCluster Hosted System - A
hostedSystemblock as defined below. - identity
Automatic
Cluster Identity - An
identityblock as defined below. - kube
Config StringRaw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- kube
Configs List<AutomaticCluster Kube Config> - A
kubeConfigblock as defined below. - location String
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- name String
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- node
Resource StringGroup Id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- oidc
Issuer StringUrl - The OIDC issuer URL that is associated with the cluster.
- portal
Fully StringQualified Domain Name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- private
Cluster AutomaticCluster Private Cluster - A
privateClusterblock as defined below. - private
Fully StringQualified Domain Name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- resource
Group StringName - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- service
Mesh AutomaticCluster Service Mesh - A
serviceMeshblock as defined below. - Map<String,String>
- A mapping of tags to assign to the resource.
- web
App AutomaticRouting Ingress Cluster Web App Routing Ingress - A
webAppRoutingIngressblock as defined below.
- api
Server AutomaticAccess Cluster Api Server Access - An
apiServerAccessblock as defined below. - current
Kubernetes stringVersion - The current version running on the Azure Kubernetes Managed Cluster.
- fully
Qualified stringDomain Name - The FQDN of the Azure Kubernetes Managed Cluster.
- hosted
System AutomaticCluster Hosted System - A
hostedSystemblock as defined below. - identity
Automatic
Cluster Identity - An
identityblock as defined below. - kube
Config stringRaw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- kube
Configs AutomaticCluster Kube Config[] - A
kubeConfigblock as defined below. - location string
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- name string
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- node
Resource stringGroup Id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- oidc
Issuer stringUrl - The OIDC issuer URL that is associated with the cluster.
- portal
Fully stringQualified Domain Name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- private
Cluster AutomaticCluster Private Cluster - A
privateClusterblock as defined below. - private
Fully stringQualified Domain Name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- resource
Group stringName - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- service
Mesh AutomaticCluster Service Mesh - A
serviceMeshblock as defined below. - {[key: string]: string}
- A mapping of tags to assign to the resource.
- web
App AutomaticRouting Ingress Cluster Web App Routing Ingress - A
webAppRoutingIngressblock as defined below.
- api_
server_ Automaticaccess Cluster Api Server Access Args - An
apiServerAccessblock as defined below. - current_
kubernetes_ strversion - The current version running on the Azure Kubernetes Managed Cluster.
- fully_
qualified_ strdomain_ name - The FQDN of the Azure Kubernetes Managed Cluster.
- hosted_
system AutomaticCluster Hosted System Args - A
hostedSystemblock as defined below. - identity
Automatic
Cluster Identity Args - An
identityblock as defined below. - kube_
config_ strraw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- kube_
configs Sequence[AutomaticCluster Kube Config Args] - A
kubeConfigblock as defined below. - location str
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- name str
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- node_
resource_ strgroup_ id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- oidc_
issuer_ strurl - The OIDC issuer URL that is associated with the cluster.
- portal_
fully_ strqualified_ domain_ name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- private_
cluster AutomaticCluster Private Cluster Args - A
privateClusterblock as defined below. - private_
fully_ strqualified_ domain_ name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- resource_
group_ strname - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- service_
mesh AutomaticCluster Service Mesh Args - A
serviceMeshblock as defined below. - Mapping[str, str]
- A mapping of tags to assign to the resource.
- web_
app_ Automaticrouting_ ingress Cluster Web App Routing Ingress Args - A
webAppRoutingIngressblock as defined below.
- api
Server Property MapAccess - An
apiServerAccessblock as defined below. - current
Kubernetes StringVersion - The current version running on the Azure Kubernetes Managed Cluster.
- fully
Qualified StringDomain Name - The FQDN of the Azure Kubernetes Managed Cluster.
- hosted
System Property Map - A
hostedSystemblock as defined below. - identity Property Map
- An
identityblock as defined below. - kube
Config StringRaw - Raw Kubernetes config to be used by kubectl and other compatible tools.
- kube
Configs List<Property Map> - A
kubeConfigblock as defined below. - location String
- The location where the Managed Kubernetes Cluster should be created. Changing this forces a new resource to be created.
- name String
- The name of the Managed Kubernetes Cluster to create. Changing this forces a new resource to be created.
- node
Resource StringGroup Id - The ID of the Resource Group containing the resources for this Managed Kubernetes Cluster.
- oidc
Issuer StringUrl - The OIDC issuer URL that is associated with the cluster.
- portal
Fully StringQualified Domain Name - The FQDN for the Azure Portal resources when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- private
Cluster Property Map - A
privateClusterblock as defined below. - private
Fully StringQualified Domain Name - The FQDN for the Kubernetes Cluster when private link has been enabled, which is only resolvable inside the Virtual Network used by the Kubernetes Cluster.
- resource
Group StringName - Specifies the Resource Group where the Managed Kubernetes Cluster should exist. Changing this forces a new resource to be created.
- service
Mesh Property Map - A
serviceMeshblock as defined below. - Map<String>
- A mapping of tags to assign to the resource.
- web
App Property MapRouting Ingress - A
webAppRoutingIngressblock as defined below.
Supporting Types
AutomaticClusterApiServerAccess, AutomaticClusterApiServerAccessArgs
- List<string>
- Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
- Subnet
Id string - The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
- []string
- Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
- Subnet
Id string - The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
- list(string)
- Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
- subnet_
id string - The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
- List<String>
- Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
- subnet
Id String - The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
- string[]
- Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
- subnet
Id string - The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
- Sequence[str]
- Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
- subnet_
id str - The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
- List<String>
- Set of authorized IP ranges to allow access to API server, e.g. ["198.51.100.0/24"].
- subnet
Id String - The ID of the Subnet where the API server endpoint is delegated to. Is required for bring your own networking.
AutomaticClusterHostedSystem, AutomaticClusterHostedSystemArgs
- Node
Subnet stringId - The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
- System
Node stringSubnet Id - The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
- Node
Subnet stringId - The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
- System
Node stringSubnet Id - The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
- node_
subnet_ stringid - The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
- system_
node_ stringsubnet_ id - The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
- node
Subnet StringId - The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
- system
Node StringSubnet Id - The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
- node
Subnet stringId - The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
- system
Node stringSubnet Id - The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
- node_
subnet_ strid - The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
- system_
node_ strsubnet_ id - The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
- node
Subnet StringId - The ID of the Subnet where the user nodes are hosted. Is required for bring your own networking
- system
Node StringSubnet Id - The ID of the Subnet where the system nodes are hosted. Changing this forces a new resource to be created. Is required for bring your own networking
AutomaticClusterIdentity, AutomaticClusterIdentityArgs
- Type string
- Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are
SystemAssignedorUserAssigned.UserAssignedis required for bring your own networking - Identity
Ids List<string> Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.
Note: This is required when
typeis set toUserAssigned.- Principal
Id string - The Principal ID associated with this Managed Service Identity.
- Tenant
Id string - The Tenant ID associated with this Managed Service Identity.
- Type string
- Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are
SystemAssignedorUserAssigned.UserAssignedis required for bring your own networking - Identity
Ids []string Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.
Note: This is required when
typeis set toUserAssigned.- Principal
Id string - The Principal ID associated with this Managed Service Identity.
- Tenant
Id string - The Tenant ID associated with this Managed Service Identity.
- type string
- Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are
SystemAssignedorUserAssigned.UserAssignedis required for bring your own networking - identity_
ids list(string) Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.
Note: This is required when
typeis set toUserAssigned.- principal_
id string - The Principal ID associated with this Managed Service Identity.
- tenant_
id string - The Tenant ID associated with this Managed Service Identity.
- type String
- Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are
SystemAssignedorUserAssigned.UserAssignedis required for bring your own networking - identity
Ids List<String> Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.
Note: This is required when
typeis set toUserAssigned.- principal
Id String - The Principal ID associated with this Managed Service Identity.
- tenant
Id String - The Tenant ID associated with this Managed Service Identity.
- type string
- Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are
SystemAssignedorUserAssigned.UserAssignedis required for bring your own networking - identity
Ids string[] Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.
Note: This is required when
typeis set toUserAssigned.- principal
Id string - The Principal ID associated with this Managed Service Identity.
- tenant
Id string - The Tenant ID associated with this Managed Service Identity.
- type str
- Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are
SystemAssignedorUserAssigned.UserAssignedis required for bring your own networking - identity_
ids Sequence[str] Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.
Note: This is required when
typeis set toUserAssigned.- principal_
id str - The Principal ID associated with this Managed Service Identity.
- tenant_
id str - The Tenant ID associated with this Managed Service Identity.
- type String
- Specifies the type of Managed Service Identity that should be configured on this Kubernetes Cluster. Possible values are
SystemAssignedorUserAssigned.UserAssignedis required for bring your own networking - identity
Ids List<String> Specifies a list of User Assigned Managed Identity IDs to be assigned to this Kubernetes Cluster.
Note: This is required when
typeis set toUserAssigned.- principal
Id String - The Principal ID associated with this Managed Service Identity.
- tenant
Id String - The Tenant ID associated with this Managed Service Identity.
AutomaticClusterKubeConfig, AutomaticClusterKubeConfigArgs
- Client
Certificate string - Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
- Client
Key string - Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
- Cluster
Ca stringCertificate - Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
- Host string
- The Kubernetes cluster server host.
- Password string
- A password or token used to authenticate to the Kubernetes cluster.
- Username string
- A username used to authenticate to the Kubernetes cluster.
- Client
Certificate string - Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
- Client
Key string - Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
- Cluster
Ca stringCertificate - Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
- Host string
- The Kubernetes cluster server host.
- Password string
- A password or token used to authenticate to the Kubernetes cluster.
- Username string
- A username used to authenticate to the Kubernetes cluster.
- client_
certificate string - Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
- client_
key string - Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
- cluster_
ca_ stringcertificate - Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
- host string
- The Kubernetes cluster server host.
- password string
- A password or token used to authenticate to the Kubernetes cluster.
- username string
- A username used to authenticate to the Kubernetes cluster.
- client
Certificate String - Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
- client
Key String - Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
- cluster
Ca StringCertificate - Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
- host String
- The Kubernetes cluster server host.
- password String
- A password or token used to authenticate to the Kubernetes cluster.
- username String
- A username used to authenticate to the Kubernetes cluster.
- client
Certificate string - Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
- client
Key string - Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
- cluster
Ca stringCertificate - Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
- host string
- The Kubernetes cluster server host.
- password string
- A password or token used to authenticate to the Kubernetes cluster.
- username string
- A username used to authenticate to the Kubernetes cluster.
- client_
certificate str - Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
- client_
key str - Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
- cluster_
ca_ strcertificate - Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
- host str
- The Kubernetes cluster server host.
- password str
- A password or token used to authenticate to the Kubernetes cluster.
- username str
- A username used to authenticate to the Kubernetes cluster.
- client
Certificate String - Base64 encoded public certificate used by clients to authenticate to the Kubernetes cluster.
- client
Key String - Base64 encoded private key used by clients to authenticate to the Kubernetes cluster.
- cluster
Ca StringCertificate - Base64 encoded public CA certificate used as the root of trust for the Kubernetes cluster.
- host String
- The Kubernetes cluster server host.
- password String
- A password or token used to authenticate to the Kubernetes cluster.
- username String
- A username used to authenticate to the Kubernetes cluster.
AutomaticClusterPrivateCluster, AutomaticClusterPrivateClusterArgs
- Private
Dns stringZone Id - The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are
System,Noneor the ID of a Private DNS Zone. Defaults toSystem. Changing this forces a new resource to be created. - Public
Fully boolQualified Domain Name Enabled - Provisions a Public FQDN for the private cluster. Defaults to
false.
- Private
Dns stringZone Id - The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are
System,Noneor the ID of a Private DNS Zone. Defaults toSystem. Changing this forces a new resource to be created. - Public
Fully boolQualified Domain Name Enabled - Provisions a Public FQDN for the private cluster. Defaults to
false.
- private_
dns_ stringzone_ id - The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are
System,Noneor the ID of a Private DNS Zone. Defaults toSystem. Changing this forces a new resource to be created. - public_
fully_ boolqualified_ domain_ name_ enabled - Provisions a Public FQDN for the private cluster. Defaults to
false.
- private
Dns StringZone Id - The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are
System,Noneor the ID of a Private DNS Zone. Defaults toSystem. Changing this forces a new resource to be created. - public
Fully BooleanQualified Domain Name Enabled - Provisions a Public FQDN for the private cluster. Defaults to
false.
- private
Dns stringZone Id - The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are
System,Noneor the ID of a Private DNS Zone. Defaults toSystem. Changing this forces a new resource to be created. - public
Fully booleanQualified Domain Name Enabled - Provisions a Public FQDN for the private cluster. Defaults to
false.
- private_
dns_ strzone_ id - The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are
System,Noneor the ID of a Private DNS Zone. Defaults toSystem. Changing this forces a new resource to be created. - public_
fully_ boolqualified_ domain_ name_ enabled - Provisions a Public FQDN for the private cluster. Defaults to
false.
- private
Dns StringZone Id - The ID of the Private DNS Zone which should be used for this Kubernetes Cluster. Possible values are
System,Noneor the ID of a Private DNS Zone. Defaults toSystem. Changing this forces a new resource to be created. - public
Fully BooleanQualified Domain Name Enabled - Provisions a Public FQDN for the private cluster. Defaults to
false.
AutomaticClusterServiceMesh, AutomaticClusterServiceMeshArgs
- Revisions List<string>
Specify
1or2Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource withrevisionsset to["asm-1-27"]. To start the canary upgrade, changerevisionsto["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to["asm-1-27"]. To confirm the upgrade, change to["asm-1-28"].Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.
-
Automatic
Cluster Service Mesh Certificate Authority - A
certificateAuthorityblock as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service. - External
Ingress boolGateway Enabled Enables Istio External Ingress Gateway. Defaults to
false.Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster
- Internal
Ingress boolGateway Enabled - Enables Istio Internal Ingress Gateway. Defaults to
false. - Proxy
Redirect stringMechanism - The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are
CNIChainingandInitContainers. Defaults toInitContainers.
- Revisions []string
Specify
1or2Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource withrevisionsset to["asm-1-27"]. To start the canary upgrade, changerevisionsto["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to["asm-1-27"]. To confirm the upgrade, change to["asm-1-28"].Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.
-
Automatic
Cluster Service Mesh Certificate Authority - A
certificateAuthorityblock as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service. - External
Ingress boolGateway Enabled Enables Istio External Ingress Gateway. Defaults to
false.Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster
- Internal
Ingress boolGateway Enabled - Enables Istio Internal Ingress Gateway. Defaults to
false. - Proxy
Redirect stringMechanism - The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are
CNIChainingandInitContainers. Defaults toInitContainers.
- revisions list(string)
Specify
1or2Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource withrevisionsset to["asm-1-27"]. To start the canary upgrade, changerevisionsto["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to["asm-1-27"]. To confirm the upgrade, change to["asm-1-28"].Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.
- object
- A
certificateAuthorityblock as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service. - external_
ingress_ boolgateway_ enabled Enables Istio External Ingress Gateway. Defaults to
false.Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster
- internal_
ingress_ boolgateway_ enabled - Enables Istio Internal Ingress Gateway. Defaults to
false. - proxy_
redirect_ stringmechanism - The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are
CNIChainingandInitContainers. Defaults toInitContainers.
- revisions List<String>
Specify
1or2Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource withrevisionsset to["asm-1-27"]. To start the canary upgrade, changerevisionsto["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to["asm-1-27"]. To confirm the upgrade, change to["asm-1-28"].Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.
-
Automatic
Cluster Service Mesh Certificate Authority - A
certificateAuthorityblock as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service. - external
Ingress BooleanGateway Enabled Enables Istio External Ingress Gateway. Defaults to
false.Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster
- internal
Ingress BooleanGateway Enabled - Enables Istio Internal Ingress Gateway. Defaults to
false. - proxy
Redirect StringMechanism - The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are
CNIChainingandInitContainers. Defaults toInitContainers.
- revisions string[]
Specify
1or2Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource withrevisionsset to["asm-1-27"]. To start the canary upgrade, changerevisionsto["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to["asm-1-27"]. To confirm the upgrade, change to["asm-1-28"].Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.
-
Automatic
Cluster Service Mesh Certificate Authority - A
certificateAuthorityblock as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service. - external
Ingress booleanGateway Enabled Enables Istio External Ingress Gateway. Defaults to
false.Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster
- internal
Ingress booleanGateway Enabled - Enables Istio Internal Ingress Gateway. Defaults to
false. - proxy
Redirect stringMechanism - The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are
CNIChainingandInitContainers. Defaults toInitContainers.
- revisions Sequence[str]
Specify
1or2Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource withrevisionsset to["asm-1-27"]. To start the canary upgrade, changerevisionsto["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to["asm-1-27"]. To confirm the upgrade, change to["asm-1-28"].Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.
-
Automatic
Cluster Service Mesh Certificate Authority - A
certificateAuthorityblock as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service. - external_
ingress_ boolgateway_ enabled Enables Istio External Ingress Gateway. Defaults to
false.Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster
- internal_
ingress_ boolgateway_ enabled - Enables Istio Internal Ingress Gateway. Defaults to
false. - proxy_
redirect_ strmechanism - The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are
CNIChainingandInitContainers. Defaults toInitContainers.
- revisions List<String>
Specify
1or2Istio control plane revisions for managing minor upgrades using the canary upgrade process. For example, create the resource withrevisionsset to["asm-1-27"]. To start the canary upgrade, changerevisionsto["asm-1-27", "asm-1-28"]. To roll back the canary upgrade, revert to["asm-1-27"]. To confirm the upgrade, change to["asm-1-28"].Note: Upgrading to a new (canary) revision does not affect existing sidecar proxies. You need to apply the canary revision label to selected namespaces and restart pods with kubectl to inject the new sidecar proxy. Learn more.
- Property Map
- A
certificateAuthorityblock as defined below. This configuration allows you to bring your own root certificate and keys for Istio CA in the Istio-based service mesh add-on for Azure Kubernetes Service. - external
Ingress BooleanGateway Enabled Enables Istio External Ingress Gateway. Defaults to
false.Note: Currently only one Internal Ingress Gateway and one External Ingress Gateway are allowed per cluster
- internal
Ingress BooleanGateway Enabled - Enables Istio Internal Ingress Gateway. Defaults to
false. - proxy
Redirect StringMechanism - The mechanism used to redirect application traffic to the Istio sidecar proxy. Possible values are
CNIChainingandInitContainers. Defaults toInitContainers.
AutomaticClusterServiceMeshCertificateAuthority, AutomaticClusterServiceMeshCertificateAuthorityArgs
- Certificate
Chain stringObject Name - The certificate chain object name in Azure Key Vault.
- Certificate
Object stringName - The intermediate certificate object name in Azure Key Vault.
- Key
Object stringName The intermediate certificate private key object name in Azure Key Vault.
Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,
- Key
Vault stringId - The resource ID of the Key Vault.
- Root
Certificate stringObject Name - The root certificate object name in Azure Key Vault.
- Certificate
Chain stringObject Name - The certificate chain object name in Azure Key Vault.
- Certificate
Object stringName - The intermediate certificate object name in Azure Key Vault.
- Key
Object stringName The intermediate certificate private key object name in Azure Key Vault.
Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,
- Key
Vault stringId - The resource ID of the Key Vault.
- Root
Certificate stringObject Name - The root certificate object name in Azure Key Vault.
- certificate_
chain_ stringobject_ name - The certificate chain object name in Azure Key Vault.
- certificate_
object_ stringname - The intermediate certificate object name in Azure Key Vault.
- key_
object_ stringname The intermediate certificate private key object name in Azure Key Vault.
Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,
- key_
vault_ stringid - The resource ID of the Key Vault.
- root_
certificate_ stringobject_ name - The root certificate object name in Azure Key Vault.
- certificate
Chain StringObject Name - The certificate chain object name in Azure Key Vault.
- certificate
Object StringName - The intermediate certificate object name in Azure Key Vault.
- key
Object StringName The intermediate certificate private key object name in Azure Key Vault.
Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,
- key
Vault StringId - The resource ID of the Key Vault.
- root
Certificate StringObject Name - The root certificate object name in Azure Key Vault.
- certificate
Chain stringObject Name - The certificate chain object name in Azure Key Vault.
- certificate
Object stringName - The intermediate certificate object name in Azure Key Vault.
- key
Object stringName The intermediate certificate private key object name in Azure Key Vault.
Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,
- key
Vault stringId - The resource ID of the Key Vault.
- root
Certificate stringObject Name - The root certificate object name in Azure Key Vault.
- certificate_
chain_ strobject_ name - The certificate chain object name in Azure Key Vault.
- certificate_
object_ strname - The intermediate certificate object name in Azure Key Vault.
- key_
object_ strname The intermediate certificate private key object name in Azure Key Vault.
Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,
- key_
vault_ strid - The resource ID of the Key Vault.
- root_
certificate_ strobject_ name - The root certificate object name in Azure Key Vault.
- certificate
Chain StringObject Name - The certificate chain object name in Azure Key Vault.
- certificate
Object StringName - The intermediate certificate object name in Azure Key Vault.
- key
Object StringName The intermediate certificate private key object name in Azure Key Vault.
Note: For more information on Istio-based service mesh add-on with plug-in CA certificates and how to generate these certificates,
- key
Vault StringId - The resource ID of the Key Vault.
- root
Certificate StringObject Name - The root certificate object name in Azure Key Vault.
AutomaticClusterWebAppRoutingIngress, AutomaticClusterWebAppRoutingIngressArgs
- Default
Nginx stringController - Specifies the ingress type for the default
NginxIngressControllercustom resource. The allowed values areInternal,ExternalandAnnotationControlled. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - Dns
Zone List<string>Ids - Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
- Istio
Enabled bool - Enables Istio as a Gateway API implementation. Defaults to
false. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - Web
App List<AutomaticRouting Identities Cluster Web App Routing Ingress Web App Routing Identity>
- Default
Nginx stringController - Specifies the ingress type for the default
NginxIngressControllercustom resource. The allowed values areInternal,ExternalandAnnotationControlled. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - Dns
Zone []stringIds - Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
- Istio
Enabled bool - Enables Istio as a Gateway API implementation. Defaults to
false. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - Web
App []AutomaticRouting Identities Cluster Web App Routing Ingress Web App Routing Identity
- default_
nginx_ stringcontroller - Specifies the ingress type for the default
NginxIngressControllercustom resource. The allowed values areInternal,ExternalandAnnotationControlled. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - dns_
zone_ list(string)ids - Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
- istio_
enabled bool - Enables Istio as a Gateway API implementation. Defaults to
false. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - web_
app_ list(object)routing_ identities
- default
Nginx StringController - Specifies the ingress type for the default
NginxIngressControllercustom resource. The allowed values areInternal,ExternalandAnnotationControlled. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - dns
Zone List<String>Ids - Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
- istio
Enabled Boolean - Enables Istio as a Gateway API implementation. Defaults to
false. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - web
App List<AutomaticRouting Identities Cluster Web App Routing Ingress Web App Routing Identity>
- default
Nginx stringController - Specifies the ingress type for the default
NginxIngressControllercustom resource. The allowed values areInternal,ExternalandAnnotationControlled. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - dns
Zone string[]Ids - Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
- istio
Enabled boolean - Enables Istio as a Gateway API implementation. Defaults to
false. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - web
App AutomaticRouting Identities Cluster Web App Routing Ingress Web App Routing Identity[]
- default_
nginx_ strcontroller - Specifies the ingress type for the default
NginxIngressControllercustom resource. The allowed values areInternal,ExternalandAnnotationControlled. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - dns_
zone_ Sequence[str]ids - Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
- istio_
enabled bool - Enables Istio as a Gateway API implementation. Defaults to
false. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - web_
app_ Sequence[Automaticrouting_ identities Cluster Web App Routing Ingress Web App Routing Identity]
- default
Nginx StringController - Specifies the ingress type for the default
NginxIngressControllercustom resource. The allowed values areInternal,ExternalandAnnotationControlled. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - dns
Zone List<String>Ids - Resource IDs of the DNS zones to be associated with the Application Routing add-on. Public and private DNS zones can be in different resource groups, but all public DNS zones must be in the same resource group and all private DNS zones must be in the same resource group.
- istio
Enabled Boolean - Enables Istio as a Gateway API implementation. Defaults to
false. At least one ofdefaultNginxControlleroristioEnabledmust be specified. - web
App List<Property Map>Routing Identities
AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentity, AutomaticClusterWebAppRoutingIngressWebAppRoutingIdentityArgs
- Client
Id string - The Client ID of the user-defined Managed Identity used for Web App Routing.
- Object
Id string - The Object ID of the user-defined Managed Identity used for Web App Routing
- User
Assigned stringIdentity Id - The ID of the User Assigned Identity used for Web App Routing.
- Client
Id string - The Client ID of the user-defined Managed Identity used for Web App Routing.
- Object
Id string - The Object ID of the user-defined Managed Identity used for Web App Routing
- User
Assigned stringIdentity Id - The ID of the User Assigned Identity used for Web App Routing.
- client_
id string - The Client ID of the user-defined Managed Identity used for Web App Routing.
- object_
id string - The Object ID of the user-defined Managed Identity used for Web App Routing
- user_
assigned_ stringidentity_ id - The ID of the User Assigned Identity used for Web App Routing.
- client
Id String - The Client ID of the user-defined Managed Identity used for Web App Routing.
- object
Id String - The Object ID of the user-defined Managed Identity used for Web App Routing
- user
Assigned StringIdentity Id - The ID of the User Assigned Identity used for Web App Routing.
- client
Id string - The Client ID of the user-defined Managed Identity used for Web App Routing.
- object
Id string - The Object ID of the user-defined Managed Identity used for Web App Routing
- user
Assigned stringIdentity Id - The ID of the User Assigned Identity used for Web App Routing.
- client_
id str - The Client ID of the user-defined Managed Identity used for Web App Routing.
- object_
id str - The Object ID of the user-defined Managed Identity used for Web App Routing
- user_
assigned_ stridentity_ id - The ID of the User Assigned Identity used for Web App Routing.
- client
Id String - The Client ID of the user-defined Managed Identity used for Web App Routing.
- object
Id String - The Object ID of the user-defined Managed Identity used for Web App Routing
- user
Assigned StringIdentity Id - The ID of the User Assigned Identity used for Web App Routing.
Import
Managed Kubernetes Automatic Clusters can be imported using the resource id, e.g.
$ pulumi import azure:containerservice/automaticCluster:AutomaticCluster cluster1 /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/group1/providers/Microsoft.ContainerService/managedClusters/cluster1
To learn more about importing existing cloud resources, see Importing resources.
Package Details
- Repository
- Azure Classic pulumi/pulumi-azure
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the
azurermTerraform Provider.
We recommend using Azure Native.
published on Wednesday, Sep 2, 2026 by Pulumi