From 6491dfab625b86a89783510be9356d84d27ccd3c Mon Sep 17 00:00:00 2001 From: Mohammad Rafi Date: Mon, 29 Jun 2026 13:55:16 +0530 Subject: [PATCH 1/5] chore: update CODEOWNERS handles Replace @Vinay-Microsoft -> @VinaySh-Microsoft and @Prajwal-Microsoft -> @Prajwal1-Microsoft --- .github/CODEOWNERS | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index f7ce875e..b044f081 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -2,4 +2,4 @@ # Each line is a file pattern followed by one or more owners. # These owners will be the default owners for everything in the repo. -* @Avijit-Microsoft @Roopan-Microsoft @Prajwal-Microsoft @dongbumlee @Vinay-Microsoft @aniaroramsft @toherman-msft @nchandhi @dgp10801 +* @Avijit-Microsoft @Roopan-Microsoft @Prajwal1-Microsoft @dongbumlee @VinaySh-Microsoft @aniaroramsft @toherman-msft @nchandhi @dgp10801 From 74fd0097cd91cd76a9bc0e06edb234c7bad5ed2b Mon Sep 17 00:00:00 2001 From: Shubhangi-Microsoft Date: Thu, 16 Jul 2026 10:43:06 +0530 Subject: [PATCH 2/5] Fix DKM deployment: gpt-5-mini model, disable AKS zones, D4ds_v6 VM size - Replace deprecated gpt-4.1-mini (2025-04-14) with gpt-5-mini (2025-08-07) in main.bicep/main.json, CI.yml, quota scripts and docs - Set AKS agent pool availabilityZones=[] to avoid AvailabilityZoneNotSupported in regions/subs without zones - Change AKS VM size Standard_D4ds_v5 -> Standard_D4ds_v6 (v5 not allowed in subscription) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .github/workflows/CI.yml | 4 ++-- Deployment/checkquota.ps1 | 2 +- Deployment/quota_check_params.sh | 2 +- docs/AVMPostDeploymentGuide.md | 2 +- docs/CustomizingAzdParameters.md | 4 ++-- docs/QuotaCheck.md | 10 +++++----- infra/main.bicep | 13 ++++++++----- infra/main.json | 11 ++++++----- 8 files changed, 26 insertions(+), 22 deletions(-) diff --git a/.github/workflows/CI.yml b/.github/workflows/CI.yml index 10b57780..90a3bb2c 100644 --- a/.github/workflows/CI.yml +++ b/.github/workflows/CI.yml @@ -211,9 +211,9 @@ jobs: location=${{ env.AZURE_LOCATION }} \ azureAiServiceLocation=${{ env.AZURE_LOCATION }} \ deploymentType="GlobalStandard" \ - gptModelName="gpt-4.1-mini" \ + gptModelName="gpt-5-mini" \ gptDeploymentCapacity=${{ env.GPT_CAPACITY }} \ - gptModelVersion="2025-04-14" \ + gptModelVersion="2025-08-07" \ embeddingModelName="text-embedding-3-large" \ embeddingDeploymentCapacity=${{ env.TEXT_EMBEDDING_CAPACITY }} \ embeddingModelVersion="1" \ diff --git a/Deployment/checkquota.ps1 b/Deployment/checkquota.ps1 index c16a0b85..b8265ad9 100644 --- a/Deployment/checkquota.ps1 +++ b/Deployment/checkquota.ps1 @@ -41,7 +41,7 @@ Write-Host "✅ Azure subscription set successfully." # Define models and their minimum required capacities $MIN_CAPACITY = @{ - "OpenAI.GlobalStandard.gpt4.1-mini" = $GPT_MIN_CAPACITY + "OpenAI.GlobalStandard.gpt-5-mini" = $GPT_MIN_CAPACITY "OpenAI.GlobalStandard.text-embedding-3-large" = $TEXT_EMBEDDING_MIN_CAPACITY } diff --git a/Deployment/quota_check_params.sh b/Deployment/quota_check_params.sh index 28b78981..0e0c7574 100644 --- a/Deployment/quota_check_params.sh +++ b/Deployment/quota_check_params.sh @@ -47,7 +47,7 @@ log_verbose() { } # Default Models and Capacities (Comma-separated in "model:capacity" format) -DEFAULT_MODEL_CAPACITY="gpt4.1-mini:150,text-embedding-3-large:100" +DEFAULT_MODEL_CAPACITY="gpt-5-mini:150,text-embedding-3-large:100" # Convert the comma-separated string into an array IFS=',' read -r -a MODEL_CAPACITY_PAIRS <<< "$DEFAULT_MODEL_CAPACITY" diff --git a/docs/AVMPostDeploymentGuide.md b/docs/AVMPostDeploymentGuide.md index 3a92ddaa..cd3539ea 100644 --- a/docs/AVMPostDeploymentGuide.md +++ b/docs/AVMPostDeploymentGuide.md @@ -147,7 +147,7 @@ Upon successful completion, you'll see a success message with important informat | Model Name | Recommended TPM | Minimum TPM | |------------------------|----------------|-------------| -| gpt-4.1-mini | 100K TPM | 10K TPM | +| gpt-5-mini | 100K TPM | 10K TPM | | text-embedding-3-large | 200K TPM | 50K TPM | > **⚠️ Warning**: Insufficient quota will cause failures during document upload and processing. Ensure adequate capacity before proceeding. diff --git a/docs/CustomizingAzdParameters.md b/docs/CustomizingAzdParameters.md index eeed5166..e0abc960 100644 --- a/docs/CustomizingAzdParameters.md +++ b/docs/CustomizingAzdParameters.md @@ -12,9 +12,9 @@ By default this template will use the environment name as the prefix to prevent | `AZURE_LOCATION` | string | `` | Location of the Azure resources. Controls where the infrastructure will be deployed. | | `AZURE_ENV_AI_SERVICE_LOCATION` | string | `` | Location for Azure OpenAI resources. Can be different from AZURE_LOCATION for optimized AI service placement. | | `AZURE_ENV_MODEL_DEPLOYMENT_TYPE` | string | `GlobalStandard` | Defines the deployment type for the AI model (e.g., Standard, GlobalStandard). | -| `AZURE_ENV_GPT_MODEL_NAME` | string | `gpt-4.1-mini` | Specifies the name of the GPT model to be deployed. | +| `AZURE_ENV_GPT_MODEL_NAME` | string | `gpt-5-mini` | Specifies the name of the GPT model to be deployed. | | `AZURE_ENV_GPT_MODEL_CAPACITY` | int | `100` | Sets the GPT model capacity (in thousands of tokens per minute). | -| `AZURE_ENV_GPT_MODEL_VERSION` | string | `2025-04-14` | Version of the GPT model to be used for deployment. | +| `AZURE_ENV_GPT_MODEL_VERSION` | string | `2025-08-07` | Version of the GPT model to be used for deployment. | | `AZURE_ENV_EMBEDDING_MODEL_NAME` | string | `text-embedding-3-large` | Sets the name of the embedding model to use. | | `AZURE_ENV_EMBEDDING_MODEL_VERSION` | string | `1` | Version of the embedding model to be used for deployment. | | `AZURE_ENV_EMBEDDING_DEPLOYMENT_CAPACITY` | int | `100` | Capacity for embedding model deployment (in thousands of tokens per minute). | diff --git a/docs/QuotaCheck.md b/docs/QuotaCheck.md index ca0f5e01..973317d6 100644 --- a/docs/QuotaCheck.md +++ b/docs/QuotaCheck.md @@ -1,7 +1,7 @@ ## Check Quota Availability Before Deployment Before deploying the accelerator, **ensure sufficient quota availability** for the required model. -> **For Global Standard | gpt4.1-mini - increase the capacity to at least 150K tokens for optimal performance.** +> **For Global Standard | gpt-5-mini - increase the capacity to at least 150K tokens for optimal performance.** ### Login if you have not done so already ``` @@ -11,7 +11,7 @@ azd auth login ### 📌 Default Models & Capacities: ``` -gpt4.1-mini:150, text-embedding-3-large:100 +gpt-5-mini:150, text-embedding-3-large:100 ``` ### 📌 Default Regions: ``` @@ -37,7 +37,7 @@ eastus, uksouth, eastus2, northcentralus, swedencentral, westus, westus2, southc ``` ✔️ Check specific model(s) in default regions: ``` - ./quota_check_params.sh --models gpt4.1-mini:150,text-embedding-3-large:100 + ./quota_check_params.sh --models gpt-5-mini:150,text-embedding-3-large:100 ``` ✔️ Check default models in specific region(s): ``` @@ -45,11 +45,11 @@ eastus, uksouth, eastus2, northcentralus, swedencentral, westus, westus2, southc ``` ✔️ Passing Both models and regions: ``` - ./quota_check_params.sh --models gpt4.1-mini:150 --regions eastus,westus2 + ./quota_check_params.sh --models gpt-5-mini:150 --regions eastus,westus2 ``` ✔️ All parameters combined: ``` - ./quota_check_params.sh --models gpt4.1-mini:150,text-embedding-3-large:100 --regions eastus,westus --verbose + ./quota_check_params.sh --models gpt-5-mini:150,text-embedding-3-large:100 --regions eastus,westus --verbose ``` ### **Sample Output** diff --git a/infra/main.bicep b/infra/main.bicep index 7fb16a4d..9825f989 100644 --- a/infra/main.bicep +++ b/infra/main.bicep @@ -34,12 +34,12 @@ param deploymentType string = 'GlobalStandard' @minLength(1) @description('Optional. Name of the GPT model to deploy:') @allowed([ - 'gpt-4.1-mini' + 'gpt-5-mini' ]) -param gptModelName string = 'gpt-4.1-mini' +param gptModelName string = 'gpt-5-mini' @description('Optional. Version of the GPT model to deploy.') -param gptModelVersion string = '2025-04-14' +param gptModelVersion string = '2025-08-07' @description('Optional. Capacity of the GPT model deployment:') @minValue(10) @@ -95,7 +95,7 @@ param enableScalability bool = false azd: { type: 'location' usageName: [ - 'OpenAI.GlobalStandard.gpt4.1-mini,150' + 'OpenAI.GlobalStandard.gpt-5-mini,150' 'OpenAI.GlobalStandard.text-embedding-3-large,100' ] } @@ -976,7 +976,7 @@ module managedCluster 'br/public:avm/res/container-service/managed-cluster:0.13. primaryAgentPoolProfiles: [ { name: 'agentpool' - vmSize: 'Standard_D4ds_v5' + vmSize: 'Standard_D4ds_v6' count: 2 osType: 'Linux' mode: 'System' @@ -984,6 +984,9 @@ module managedCluster 'br/public:avm/res/container-service/managed-cluster:0.13. minCount: 1 maxCount: 2 + // Disable zonal placement; not all regions/subscriptions expose availability zones for the agent pool SKU + availabilityZones: [] + // WAF aligned configuration for Private Networking enableAutoScaling: true scaleSetEvictionPolicy: 'Delete' diff --git a/infra/main.json b/infra/main.json index df6a00d0..69c83018 100644 --- a/infra/main.json +++ b/infra/main.json @@ -48,9 +48,9 @@ }, "gptModelName": { "type": "string", - "defaultValue": "gpt-4.1-mini", + "defaultValue": "gpt-5-mini", "allowedValues": [ - "gpt-4.1-mini" + "gpt-5-mini" ], "minLength": 1, "metadata": { @@ -59,7 +59,7 @@ }, "gptModelVersion": { "type": "string", - "defaultValue": "2025-04-14", + "defaultValue": "2025-08-07", "metadata": { "description": "Optional. Version of the GPT model to deploy." } @@ -177,7 +177,7 @@ "azd": { "type": "location", "usageName": [ - "OpenAI.GlobalStandard.gpt4.1-mini,150", + "OpenAI.GlobalStandard.gpt-5-mini,150", "OpenAI.GlobalStandard.text-embedding-3-large,100" ] }, @@ -52353,13 +52353,14 @@ "value": [ { "name": "agentpool", - "vmSize": "Standard_D4ds_v5", + "vmSize": "Standard_D4ds_v6", "count": 2, "osType": "Linux", "mode": "System", "type": "VirtualMachineScaleSets", "minCount": 1, "maxCount": 2, + "availabilityZones": [], "enableAutoScaling": true, "scaleSetEvictionPolicy": "Delete", "scaleSetPriority": "Regular", From e85d8d24c72a28ade8a333eb1d9ab9a51c72064d Mon Sep 17 00:00:00 2001 From: "Niraj Chaudhari (Persistent Systems Limited)" Date: Thu, 16 Jul 2026 12:34:26 +0530 Subject: [PATCH 3/5] Update Owners ID for Vinay and Prajwal --- .github/CODEOWNERS | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index b044f081..f7ce875e 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -2,4 +2,4 @@ # Each line is a file pattern followed by one or more owners. # These owners will be the default owners for everything in the repo. -* @Avijit-Microsoft @Roopan-Microsoft @Prajwal1-Microsoft @dongbumlee @VinaySh-Microsoft @aniaroramsft @toherman-msft @nchandhi @dgp10801 +* @Avijit-Microsoft @Roopan-Microsoft @Prajwal-Microsoft @dongbumlee @Vinay-Microsoft @aniaroramsft @toherman-msft @nchandhi @dgp10801 From 5f2a78b412636369c76a18d59589ca4dd6b43917 Mon Sep 17 00:00:00 2001 From: Shubhangi-Microsoft Date: Thu, 16 Jul 2026 17:24:51 +0530 Subject: [PATCH 4/5] Codeowners list update and main.bicep rebuild --- .github/CODEOWNERS | 2 +- infra/avm/modules/compute/kubernetes.bicep | 170 +++++++++++++++++++++ infra/main.json | 4 +- 3 files changed, 173 insertions(+), 3 deletions(-) create mode 100644 infra/avm/modules/compute/kubernetes.bicep diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index b044f081..f7ce875e 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -2,4 +2,4 @@ # Each line is a file pattern followed by one or more owners. # These owners will be the default owners for everything in the repo. -* @Avijit-Microsoft @Roopan-Microsoft @Prajwal1-Microsoft @dongbumlee @VinaySh-Microsoft @aniaroramsft @toherman-msft @nchandhi @dgp10801 +* @Avijit-Microsoft @Roopan-Microsoft @Prajwal-Microsoft @dongbumlee @Vinay-Microsoft @aniaroramsft @toherman-msft @nchandhi @dgp10801 diff --git a/infra/avm/modules/compute/kubernetes.bicep b/infra/avm/modules/compute/kubernetes.bicep new file mode 100644 index 00000000..6f5a4136 --- /dev/null +++ b/infra/avm/modules/compute/kubernetes.bicep @@ -0,0 +1,170 @@ +// ============================================================================ +// Module: Azure Kubernetes Service (AKS) +// Description: AVM wrapper for Azure Kubernetes Service Managed Cluster +// AVM Module: avm/res/container-service/managed-cluster:0.13.1 +// ============================================================================ + +@description('Solution name suffix used to derive the resource name.') +param solutionName string + +@description('Name of the AKS cluster.') +param name string = 'aks-${solutionName}' + +@description('Azure region for the resource.') +param location string + +@description('Tags to apply to the resource.') +param tags object = {} + +@description('Kubernetes version for the cluster.') +param kubernetesVersion string = '1.34' + +@description('Agent pool configurations. Each entry requires name, vmSize, count, mode (System/User).') +param agentPools array = [ + { + name: 'agentpool' + vmSize: 'Standard_D4ds_v5' + count: 2 + minCount: 1 + maxCount: 2 + enableAutoScaling: true + osType: 'Linux' + mode: 'System' + type: 'VirtualMachineScaleSets' + scaleSetEvictionPolicy: 'Delete' + scaleSetPriority: 'Regular' + } +] + +@description('Enable Kubernetes RBAC.') +param enableRBAC bool = true + +@description('Disable local accounts (enforce AAD-only).') +param disableLocalAccounts bool = false + +@description('Network plugin for the cluster.') +@allowed(['azure', 'kubenet', 'none']) +param networkPlugin string = 'azure' + +@description('Network policy for the cluster.') +@allowed(['azure', 'calico', '']) +param networkPolicy string = 'azure' + +@description('DNS prefix for the cluster.') +param dnsPrefix string = '' + +@description('SKU tier for the cluster.') +@allowed(['Free', 'Standard', 'Premium']) +param skuTier string = 'Standard' + +@description('Service CIDR for Kubernetes services.') +param serviceCidr string = '10.20.0.0/16' + +@description('DNS service IP (must be within serviceCidr).') +param dnsServiceIP string = '10.20.0.10' + +@description('Auto-upgrade channel for the cluster.') +@allowed(['none', 'patch', 'rapid', 'stable', 'node-image']) +param autoUpgradeChannel string = 'stable' + +@description('Log Analytics workspace resource ID for monitoring.') +param logAnalyticsWorkspaceResourceId string = '' + +// --- WAF: Networking --- +@description('Public network access setting.') +@allowed(['Enabled', 'Disabled']) +param publicNetworkAccess string = 'Enabled' + +@description('Enable private cluster (API server not publicly accessible).') +param enablePrivateCluster bool = false + +@description('Subnet resource ID for the agent pool (for VNet integration).') +param agentPoolSubnetId string = '' + +@description('Enable Microsoft Defender for Containers.') +param enableDefender bool = false + +@description('Diagnostic settings for monitoring.') +param diagnosticSettings array = [] + +@description('Role assignments for the cluster.') +param roleAssignments array = [] + +@description('Enable Azure telemetry collection.') +param enableTelemetry bool = true + +// ============================================================================ +// Variables +// ============================================================================ +var effectiveDnsPrefix = !empty(dnsPrefix) ? dnsPrefix : name +var enableMonitoring = !empty(logAnalyticsWorkspaceResourceId) + +var effectiveAgentPools = [for pool in agentPools: union(pool, !empty(agentPoolSubnetId) ? { vnetSubnetResourceId: agentPoolSubnetId } : {})] + +// ============================================================================ +// AVM Module Deployment +// ============================================================================ +module aksCluster 'br/public:avm/res/container-service/managed-cluster:0.13.1' = { + name: take('avm.res.container-service.managed-cluster.${name}', 64) + params: { + name: name + location: location + tags: tags + enableTelemetry: enableTelemetry + kubernetesVersion: kubernetesVersion + primaryAgentPoolProfiles: effectiveAgentPools + enableRBAC: enableRBAC + disableLocalAccounts: disableLocalAccounts + networkPlugin: networkPlugin + networkPolicy: networkPolicy + dnsPrefix: effectiveDnsPrefix + skuTier: skuTier + serviceCidr: serviceCidr + dnsServiceIP: dnsServiceIP + publicNetworkAccess: publicNetworkAccess + apiServerAccessProfile: { + enablePrivateCluster: enablePrivateCluster + } + autoUpgradeProfile: { + upgradeChannel: autoUpgradeChannel + nodeOSUpgradeChannel: 'Unmanaged' + } + managedIdentities: { systemAssigned: true } + omsAgentEnabled: enableMonitoring + monitoringWorkspaceResourceId: enableMonitoring ? logAnalyticsWorkspaceResourceId : null + diagnosticSettings: !empty(diagnosticSettings) ? diagnosticSettings : [] + securityProfile: enableDefender && enableMonitoring ? { + defender: { + logAnalyticsWorkspaceResourceId: logAnalyticsWorkspaceResourceId + securityMonitoring: { + enabled: true + } + } + } : {} + roleAssignments: roleAssignments + } +} + +// ============================================================================ +// Outputs +// ============================================================================ +@description('Name of the AKS cluster.') +output name string = aksCluster.outputs.name + +@description('Resource ID of the AKS cluster.') +output resourceId string = aksCluster.outputs.resourceId + +@description('FQDN of the AKS cluster.') +output fqdn string = aksCluster.outputs.?fqdn ?? '' + +// ---------------------------------------------------------------------------- +// DKM SAI migration: surface identity principalIds the upstream AVM module +// already exposes but the wrapper had previously hidden. Pure additive +// change — no existing output modified. +// ---------------------------------------------------------------------------- + +@description('Object ID of the AKS kubelet system-assigned managed identity (used by pods at runtime via IMDS).') +output kubeletIdentityObjectId string = aksCluster.outputs.?kubeletIdentityObjectId ?? '' + +@description('Principal ID of the AKS control-plane system-assigned managed identity.') +output systemAssignedMIPrincipalId string = aksCluster.outputs.?systemAssignedMIPrincipalId ?? '' diff --git a/infra/main.json b/infra/main.json index 69c83018..8b6b3003 100644 --- a/infra/main.json +++ b/infra/main.json @@ -6,7 +6,7 @@ "_generator": { "name": "bicep", "version": "0.43.8.12551", - "templateHash": "9930092765515882543" + "templateHash": "5797490851931362105" } }, "parameters": { @@ -43817,8 +43817,8 @@ } }, "dependsOn": [ - "[format('avmPrivateDnsZones[{0}]', variables('dnsZoneIndex').storageBlob)]", "[format('avmPrivateDnsZones[{0}]', variables('dnsZoneIndex').storageQueue)]", + "[format('avmPrivateDnsZones[{0}]', variables('dnsZoneIndex').storageBlob)]", "userAssignedIdentity", "virtualNetwork" ] From a445f56d7441670a126afcd43f3236208c0e345b Mon Sep 17 00:00:00 2001 From: Shubhangi-Microsoft Date: Fri, 17 Jul 2026 17:33:56 +0530 Subject: [PATCH 5/5] fixed copilot comments --- infra/avm/modules/compute/kubernetes.bicep | 170 --------------------- infra/main.bicep | 2 +- infra/main.json | 2 +- 3 files changed, 2 insertions(+), 172 deletions(-) delete mode 100644 infra/avm/modules/compute/kubernetes.bicep diff --git a/infra/avm/modules/compute/kubernetes.bicep b/infra/avm/modules/compute/kubernetes.bicep deleted file mode 100644 index 6f5a4136..00000000 --- a/infra/avm/modules/compute/kubernetes.bicep +++ /dev/null @@ -1,170 +0,0 @@ -// ============================================================================ -// Module: Azure Kubernetes Service (AKS) -// Description: AVM wrapper for Azure Kubernetes Service Managed Cluster -// AVM Module: avm/res/container-service/managed-cluster:0.13.1 -// ============================================================================ - -@description('Solution name suffix used to derive the resource name.') -param solutionName string - -@description('Name of the AKS cluster.') -param name string = 'aks-${solutionName}' - -@description('Azure region for the resource.') -param location string - -@description('Tags to apply to the resource.') -param tags object = {} - -@description('Kubernetes version for the cluster.') -param kubernetesVersion string = '1.34' - -@description('Agent pool configurations. Each entry requires name, vmSize, count, mode (System/User).') -param agentPools array = [ - { - name: 'agentpool' - vmSize: 'Standard_D4ds_v5' - count: 2 - minCount: 1 - maxCount: 2 - enableAutoScaling: true - osType: 'Linux' - mode: 'System' - type: 'VirtualMachineScaleSets' - scaleSetEvictionPolicy: 'Delete' - scaleSetPriority: 'Regular' - } -] - -@description('Enable Kubernetes RBAC.') -param enableRBAC bool = true - -@description('Disable local accounts (enforce AAD-only).') -param disableLocalAccounts bool = false - -@description('Network plugin for the cluster.') -@allowed(['azure', 'kubenet', 'none']) -param networkPlugin string = 'azure' - -@description('Network policy for the cluster.') -@allowed(['azure', 'calico', '']) -param networkPolicy string = 'azure' - -@description('DNS prefix for the cluster.') -param dnsPrefix string = '' - -@description('SKU tier for the cluster.') -@allowed(['Free', 'Standard', 'Premium']) -param skuTier string = 'Standard' - -@description('Service CIDR for Kubernetes services.') -param serviceCidr string = '10.20.0.0/16' - -@description('DNS service IP (must be within serviceCidr).') -param dnsServiceIP string = '10.20.0.10' - -@description('Auto-upgrade channel for the cluster.') -@allowed(['none', 'patch', 'rapid', 'stable', 'node-image']) -param autoUpgradeChannel string = 'stable' - -@description('Log Analytics workspace resource ID for monitoring.') -param logAnalyticsWorkspaceResourceId string = '' - -// --- WAF: Networking --- -@description('Public network access setting.') -@allowed(['Enabled', 'Disabled']) -param publicNetworkAccess string = 'Enabled' - -@description('Enable private cluster (API server not publicly accessible).') -param enablePrivateCluster bool = false - -@description('Subnet resource ID for the agent pool (for VNet integration).') -param agentPoolSubnetId string = '' - -@description('Enable Microsoft Defender for Containers.') -param enableDefender bool = false - -@description('Diagnostic settings for monitoring.') -param diagnosticSettings array = [] - -@description('Role assignments for the cluster.') -param roleAssignments array = [] - -@description('Enable Azure telemetry collection.') -param enableTelemetry bool = true - -// ============================================================================ -// Variables -// ============================================================================ -var effectiveDnsPrefix = !empty(dnsPrefix) ? dnsPrefix : name -var enableMonitoring = !empty(logAnalyticsWorkspaceResourceId) - -var effectiveAgentPools = [for pool in agentPools: union(pool, !empty(agentPoolSubnetId) ? { vnetSubnetResourceId: agentPoolSubnetId } : {})] - -// ============================================================================ -// AVM Module Deployment -// ============================================================================ -module aksCluster 'br/public:avm/res/container-service/managed-cluster:0.13.1' = { - name: take('avm.res.container-service.managed-cluster.${name}', 64) - params: { - name: name - location: location - tags: tags - enableTelemetry: enableTelemetry - kubernetesVersion: kubernetesVersion - primaryAgentPoolProfiles: effectiveAgentPools - enableRBAC: enableRBAC - disableLocalAccounts: disableLocalAccounts - networkPlugin: networkPlugin - networkPolicy: networkPolicy - dnsPrefix: effectiveDnsPrefix - skuTier: skuTier - serviceCidr: serviceCidr - dnsServiceIP: dnsServiceIP - publicNetworkAccess: publicNetworkAccess - apiServerAccessProfile: { - enablePrivateCluster: enablePrivateCluster - } - autoUpgradeProfile: { - upgradeChannel: autoUpgradeChannel - nodeOSUpgradeChannel: 'Unmanaged' - } - managedIdentities: { systemAssigned: true } - omsAgentEnabled: enableMonitoring - monitoringWorkspaceResourceId: enableMonitoring ? logAnalyticsWorkspaceResourceId : null - diagnosticSettings: !empty(diagnosticSettings) ? diagnosticSettings : [] - securityProfile: enableDefender && enableMonitoring ? { - defender: { - logAnalyticsWorkspaceResourceId: logAnalyticsWorkspaceResourceId - securityMonitoring: { - enabled: true - } - } - } : {} - roleAssignments: roleAssignments - } -} - -// ============================================================================ -// Outputs -// ============================================================================ -@description('Name of the AKS cluster.') -output name string = aksCluster.outputs.name - -@description('Resource ID of the AKS cluster.') -output resourceId string = aksCluster.outputs.resourceId - -@description('FQDN of the AKS cluster.') -output fqdn string = aksCluster.outputs.?fqdn ?? '' - -// ---------------------------------------------------------------------------- -// DKM SAI migration: surface identity principalIds the upstream AVM module -// already exposes but the wrapper had previously hidden. Pure additive -// change — no existing output modified. -// ---------------------------------------------------------------------------- - -@description('Object ID of the AKS kubelet system-assigned managed identity (used by pods at runtime via IMDS).') -output kubeletIdentityObjectId string = aksCluster.outputs.?kubeletIdentityObjectId ?? '' - -@description('Principal ID of the AKS control-plane system-assigned managed identity.') -output systemAssignedMIPrincipalId string = aksCluster.outputs.?systemAssignedMIPrincipalId ?? '' diff --git a/infra/main.bicep b/infra/main.bicep index 9825f989..59381049 100644 --- a/infra/main.bicep +++ b/infra/main.bicep @@ -976,7 +976,7 @@ module managedCluster 'br/public:avm/res/container-service/managed-cluster:0.13. primaryAgentPoolProfiles: [ { name: 'agentpool' - vmSize: 'Standard_D4ds_v6' + vmSize: 'Standard_D4ds_v5' count: 2 osType: 'Linux' mode: 'System' diff --git a/infra/main.json b/infra/main.json index 8b6b3003..895bf0dd 100644 --- a/infra/main.json +++ b/infra/main.json @@ -52353,7 +52353,7 @@ "value": [ { "name": "agentpool", - "vmSize": "Standard_D4ds_v6", + "vmSize": "Standard_D4ds_v5", "count": 2, "osType": "Linux", "mode": "System",