Skip to content

Commit 9f300b3

Browse files
author
Andrew
committed
Updates based on feedback.
1 parent 9c852fe commit 9f300b3

7 files changed

+173
-203
lines changed
Lines changed: 77 additions & 68 deletions
Original file line numberDiff line numberDiff line change
@@ -1,70 +1,79 @@
11
{
2-
"redirections": [
3-
{
4-
"source_path": "howto-monitoring-aks-h-cluster.md",
5-
"redirect_url": "howto-monitor-naks-cluster",
6-
"redirect_document_id": false
7-
},
8-
{
9-
"source_path": "howto-monitoring-virtualized-network-functions-virtual-machines.md",
10-
"redirect_url": "howto-monitor-virtualized-network-functions-virtual-machines",
11-
"redirect_document_id": false
12-
},
13-
{
14-
"source_path": "quickstart-network-fabric-controller-cluster-manager-create.md",
15-
"redirect_url": "howto-azure-operator-nexus-prerequisites",
16-
"redirect_document_id": false
17-
},
18-
{
19-
"source_path": "quickstarts-platform-deployment.md",
20-
"redirect_url": "howto-configure-cluster",
21-
"redirect_document_id": false
22-
},
23-
{
24-
"source_path": "quickstarts-platform-prerequisites.md",
25-
"redirect_url": "howto-platform-prerequisites",
26-
"redirect_document_id": false
27-
},
28-
{
29-
"source_path": "howto-baremetal-review-read-output.md",
30-
"redirect_url": "howto-baremetal-run-read",
31-
"redirect_document_id": false
32-
},
33-
{
34-
"source_path": "troubleshoot-aks-hybrid-cluster.md",
35-
"redirect_url": "troubleshoot-isolation-domain",
36-
"redirect_document_id": false
37-
},
38-
{
39-
"source_path": "how-to-apply-access-control-list-to-network-to-network-interconnects.md",
40-
"redirect_url": "howto-apply-access-control-list-to-network-to-network-interconnects",
41-
"redirect_document_id": false
42-
},
43-
{
44-
"source_path": "howto-use-azure-policy-for-aks-cluster-security.md",
45-
"redirect_url": "howto-use-azure-policy",
46-
"redirect_document_id": false
47-
},
48-
{
49-
"source_path": "troubleshoot-enable-node-down-cleaner.md",
50-
"redirect_url": "concepts-storage",
51-
"redirect_document_id": false
52-
},
53-
{
54-
"source_path": "troubleshoot-bmm-node-reboot.md",
55-
"redirect_url": "troubleshoot-vm-error-after-reboot",
56-
"redirect_document_id": false
57-
},
58-
{
59-
"source_path": "reference-operator-nexus-fabric-skus.md",
60-
"redirect_url": "reference-operator-nexus-skus",
61-
"redirect_document_id": false
62-
},
63-
{
64-
"source_path": "reference-operator-nexus-network-cloud-skus-us.md",
65-
"redirect_url": "reference-operator-nexus-skus",
66-
"redirect_document_id": false
67-
}
68-
69-
]
2+
"redirections": [
3+
{
4+
"source_path": "howto-monitoring-aks-h-cluster.md",
5+
"redirect_url": "howto-monitor-naks-cluster",
6+
"redirect_document_id": false
7+
},
8+
{
9+
"source_path": "howto-monitoring-virtualized-network-functions-virtual-machines.md",
10+
"redirect_url": "howto-monitor-virtualized-network-functions-virtual-machines",
11+
"redirect_document_id": false
12+
},
13+
{
14+
"source_path": "quickstart-network-fabric-controller-cluster-manager-create.md",
15+
"redirect_url": "howto-azure-operator-nexus-prerequisites",
16+
"redirect_document_id": false
17+
},
18+
{
19+
"source_path": "quickstarts-platform-deployment.md",
20+
"redirect_url": "howto-configure-cluster",
21+
"redirect_document_id": false
22+
},
23+
{
24+
"source_path": "quickstarts-platform-prerequisites.md",
25+
"redirect_url": "howto-platform-prerequisites",
26+
"redirect_document_id": false
27+
},
28+
{
29+
"source_path": "howto-baremetal-review-read-output.md",
30+
"redirect_url": "howto-baremetal-run-read",
31+
"redirect_document_id": false
32+
},
33+
{
34+
"source_path": "troubleshoot-aks-hybrid-cluster.md",
35+
"redirect_url": "troubleshoot-isolation-domain",
36+
"redirect_document_id": false
37+
},
38+
{
39+
"source_path": "how-to-apply-access-control-list-to-network-to-network-interconnects.md",
40+
"redirect_url": "howto-apply-access-control-list-to-network-to-network-interconnects",
41+
"redirect_document_id": false
42+
},
43+
{
44+
"source_path": "howto-use-azure-policy-for-aks-cluster-security.md",
45+
"redirect_url": "howto-use-azure-policy",
46+
"redirect_document_id": false
47+
},
48+
{
49+
"source_path": "troubleshoot-enable-node-down-cleaner.md",
50+
"redirect_url": "concepts-storage",
51+
"redirect_document_id": false
52+
},
53+
{
54+
"source_path": "troubleshoot-bmm-node-reboot.md",
55+
"redirect_url": "troubleshoot-vm-error-after-reboot",
56+
"redirect_document_id": false
57+
},
58+
{
59+
"source_path": "reference-operator-nexus-fabric-skus.md",
60+
"redirect_url": "reference-operator-nexus-skus",
61+
"redirect_document_id": false
62+
},
63+
{
64+
"source_path": "reference-operator-nexus-network-cloud-skus-us.md",
65+
"redirect_url": "reference-operator-nexus-skus",
66+
"redirect_document_id": false
67+
},
68+
{
69+
"source_path": "howto-create-cluster-with-user-assigned-managed-identity.md",
70+
"redirect_url": "howto-managed-identity-user-provided-resources.md",
71+
"redirect_document_id": true
72+
},
73+
{
74+
"source_path": "howto-managed-identity-user-provided-resources.md",
75+
"redirect_url": "howto-cluster-managed-identity-user-provided-resources.md",
76+
"redirect_document_id": true
77+
}
78+
]
7079
}

articles/operator-nexus/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -148,7 +148,7 @@
148148
- name: Cluster
149149
href: howto-configure-cluster.md
150150
- name: Cluster Managed Identity and User Provided Resources
151-
href: howto-managed-identity-user-provided-resources.md
151+
href: howto-cluster-managed-identity-user-provided-resources.md
152152
- name: Cluster Template JSON Example
153153
href: cluster-jsonc-example.md
154154
- name: Cluster Parameters JSON Example

articles/operator-nexus/how-to-credential-manager-key-vault.md

Lines changed: 3 additions & 41 deletions
Original file line numberDiff line numberDiff line change
@@ -27,54 +27,16 @@ Azure Operator Nexus utilizes secrets and certificates to manage component secur
2727
> [!NOTE]
2828
> The managed identity functionality for Key Vault and Cluster managed identity exists with the 2024-10-01-preview API and will be available with the 2025-02-01 GA API.
2929
30-
See [Azure Operator Nexus Cluster support for managed identities and user provided resources](./howto-managed-identity-user-provided-resources.md)
30+
See [Azure Operator Nexus Cluster support for managed identities and user provided resources](./howto-cluster-managed-identity-user-provided-resources.md)
3131

3232
## Configure Key Vault Using Managed Identity for Cluster Manager
3333

3434
> [!NOTE]
3535
> This method is deprecated with the roll out of the 2025-02-01 GA API. A transition period is in place to support migration, but existing users should look to migrate to using the Cluster managed identity.
3636
37-
Beginning with the 2024-06-01-public-preview API version, managed identities in the Cluster Manager are used for write access to deliver rotated credentials to a key vault. The Cluster Manager identity can be system-assigned or [user-assigned](/entra/identity/managed-identities-azure-resources/how-manage-user-assigned-managed-identities), and can be managed directly via APIs or via CLI.
37+
Beginning with the 2024-07-01 API version, managed identities in the Cluster Manager are used for write access to deliver rotated credentials to a key vault. The Cluster Manager identity can be system-assigned or [user-assigned](/entra/identity/managed-identities-azure-resources/how-manage-user-assigned-managed-identities), and can be managed directly via APIs or via CLI.
3838

39-
These examples describe how to configure a managed identity for a Cluster Manager.
40-
41-
- Create or update Cluster Manager with system-assigned identity
42-
43-
```
44-
az networkcloud clustermanager create --name "clusterManagerName" --location "location" \
45-
--analytics-workspace-id "/subscriptions/subscriptionId/resourceGroups/resourceGroupName/providers/microsoft.operationalInsights/workspaces/logAnalyticsWorkspaceName" \
46-
--fabric-controller-id "/subscriptions/subscriptionId/resourceGroups/resourceGroupName/providers/Microsoft.ManagedNetworkFabric/networkFabricControllers/fabricControllerName" \
47-
--managed-resource-group-configuration name="my-managed-rg" --tags key1="myvalue1" key2="myvalue2" --resource-group "resourceGroupName" --mi-system-assigned
48-
```
49-
50-
<br/>
51-
52-
- Create or update Cluster Manager with user-assigned identity
53-
54-
```
55-
az networkcloud clustermanager create --name <Cluster Manager Name> --location <Location> \
56-
--analytics-workspace-id "/subscriptions/subscriptionId/resourceGroups/resourceGroupName/providers/microsoft.operationalInsights/workspaces/logAnalyticsWorkspaceName" \
57-
--fabric-controller-id "/subscriptions/subscriptionId/resourceGroups/resourceGroupName/providers/Microsoft.ManagedNetworkFabric/networkFabricControllers/fabricControllerName" \
58-
--managed-resource-group-configuration name="my-managed-rg" --tags key1="myvalue1" key2="myvalue2" \
59-
--resource-group <Resource Group Name> --mi-user-assigned "/subscriptions/subscriptionId/resourceGroups/resourceGroupName/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myUAI"
60-
```
61-
62-
<br/>
63-
64-
- Add system-assigned identity to Cluster Manager
65-
66-
```
67-
az networkcloud clustermanager update --name <Cluster Manager Name> --resource-group <Resource Group Name> --mi-system-assigned
68-
```
69-
70-
<br/>
71-
72-
- Add user-assigned identity to Cluster Manager
73-
74-
```
75-
az networkcloud clustermanager update --name <Cluster Manager Name> --resource-group <Resource Group Name> \
76-
--mi-user-assigned "/subscriptions/subscriptionId/resourceGroups/resourceGroupName/providers/Microsoft.ManagedIdentity/userAssignedIdentities/myUAI"
77-
```
39+
For information on assigning managed identities to the Cluster Manager, see [Cluster Manager Identity](./howto-cluster-manager#cluster-manager-identity)
7840

7941
### Configure Nexus Cluster Secret Archive
8042

articles/operator-nexus/howto-baremetal-run-data-extract.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ The command produces an output file containing the results of the data extract.
2424

2525
## Send command output to a user specified storage account
2626

27-
See [Azure Operator Nexus Cluster support for managed identities and user provided resources](./howto-managed-identity-user-provided-resources.md)
27+
See [Azure Operator Nexus Cluster support for managed identities and user provided resources](./howto-cluster-managed-identity-user-provided-resources.md)
2828

2929
### Clear the cluster's CommandOutputSettings
3030

articles/operator-nexus/howto-baremetal-run-read.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ The command produces an output file containing the results of the run-read comma
2424

2525
## Send command output to a user specified storage account
2626

27-
See [Azure Operator Nexus Cluster support for managed identities and user provided resources](./howto-managed-identity-user-provided-resources.md)
27+
See [Azure Operator Nexus Cluster support for managed identities and user provided resources](./howto-cluster-managed-identity-user-provided-resources.md)
2828

2929
### Clear the cluster's CommandOutputSettings
3030

0 commit comments

Comments
 (0)