You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/confidential-computing/quick-create-confidential-vm-arm.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -216,7 +216,7 @@ Use this example to create a custom parameter file for a Linux-based confidentia
216
216
217
217
1. Create a new key using Azure Key Vault. For how to use an Azure Managed HSM instead, see the next step.
218
218
219
-
1. Prepare and download the [key release policy](https://cvmprivatepreviewsa.blob.core.windows.net/cvmpublicpreviewcontainer/skr-policy.json) to your local disk.
219
+
1. Prepare and download the key release policy to your local disk.
220
220
1. Create a new key.
221
221
222
222
```azurecli-interactive
@@ -232,7 +232,7 @@ Use this example to create a custom parameter file for a Linux-based confidentia
1. Deploy a Disk Encryption Set (DES) using a [DES ARM template](https://cvmprivatepreviewsa.blob.core.windows.net/cvmpublicpreviewcontainer/deploymentTemplate/deployDES.json) (`deployDES.json`).
235
+
1. Deploy a Disk Encryption Set (DES) using a DES ARM template (`deployDES.json`).
236
236
237
237
```azurecli-interactive
238
238
$desName = <name of DES>
@@ -260,7 +260,7 @@ Use this example to create a custom parameter file for a Linux-based confidentia
260
260
```
261
261
262
262
1. (Optional) Create a new key from an Azure Managed HSM.
263
-
1. Prepare and download the [key release policy](https://cvmprivatepreviewsa.blob.core.windows.net/cvmpublicpreviewcontainer/skr-policy.json) to your local disk.
263
+
1. Prepare and download the key release policy to your local disk.
264
264
1. Create the new key.
265
265
266
266
```azurecli-interactive
@@ -302,7 +302,7 @@ Use this example to create a custom parameter file for a Linux-based confidentia
302
302
$desID = (az disk-encryption-set show -n $desName -g $resourceGroup --query [id] -o tsv)
303
303
```
304
304
305
-
1. Deploy your confidential VM using a confidential VM ARM template for [AMD SEV-SNP](https://cvmprivatepreviewsa.blob.core.windows.net/cvmpublicpreviewcontainer/deploymentTemplate/deployCPSCVM_cmk.json) or Intel TDX and a [deployment parameter file](#example-windows-parameter-file) (for example, `azuredeploy.parameters.win2022.json`) with the customer-managed key.
305
+
1. Deploy your confidential VM using a confidential VM ARM template for Intel TDX and a [deployment parameter file](#example-windows-parameter-file) (for example, `azuredeploy.parameters.win2022.json`) with the customer-managed key.
Copy file name to clipboardExpand all lines: articles/operator-nexus/concepts-storage.md
+25-6Lines changed: 25 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -53,7 +53,7 @@ status:
53
53
54
54
### StorageClass: nexus-shared
55
55
56
-
In situations where a shared file system is required, the *nexus-shared* storage class is available. This storage class provides a highly available shared storage solution by enabling multiple pods in the same Nexus Kubernetes cluster to concurrently access and share the same volume. The *nexus-shared* storage class is backed by a highly available NFS storage service. This NFS storage service (storage pool currently limited to a maximum size of 1TiB) is available per Cloud Service Network (CSN). The NFS storage service is deployed automatically on creation of a CSN resource. Any Nexus Kubernetes cluster attached to the CSN can provision persistent volumes from this shared storage pool. Nexus-shared supports both Read Write Once (RWO) and Read Write Many (RWX) access modes. What that means is that the workload applications can make use of either of these access modes to access the shared storage.
56
+
In situations where a shared file system is required, the *nexus-shared* storage class is available. This storage class provides a highly available shared storage solution by enabling multiple pods in the same Nexus Kubernetes cluster to concurrently access and share the same volume. The *nexus-shared* storage class is backed by a highly available NFS storage service. This NFS storage service (storage pool currently limited to a maximum size of 1 TiB) is available per Cloud Service Network (CSN). The NFS storage service is deployed automatically on creation of a CSN resource. Any Nexus Kubernetes cluster attached to the CSN can provision persistent volumes from this shared storage pool. Nexus-shared supports both Read Write Once (RWO) and Read Write Many (RWX) access modes. What that means is that the workload applications can make use of either of these access modes to access the shared storage.
:::image type="content" source="media/nexus-shared-volume.png" alt-text="Diagram depicting how nexus-shared provisions a volume for a workload in Nexus Kubernetes Cluster":::
@@ -64,7 +64,7 @@ Although the performance and availability of *nexus-shared* are sufficient for m
64
64
65
65
#### Read Write Once (RWO)
66
66
67
-
In Read Write Once (RWO) mode, the nexus-shared volume can be mounted by only one node or claimant at a time. ReadWriteOnce access mode still allows multiple pods to access the volume when the pods are running on the same node.
67
+
In Read Write Once (RWO) mode, only one node or claimant can mount the nexus-shared volume at a time. ReadWriteOnce access mode still allows multiple pods to access the volume when the pods are running on the same node.
68
68
```
69
69
apiVersion: v1
70
70
items:
@@ -92,7 +92,7 @@ items:
92
92
93
93
#### Read Write Many (RWX)
94
94
95
-
In Read Write Many (RWX) mode, the nexus-shared volume can be mounted by multiple nodes or claimants at the same time.
95
+
In the Read Write Many (RWX) mode, multiple nodes or claimants can mount the nexus-shared volume at the same time.
96
96
```
97
97
apiVersion: v1
98
98
items:
@@ -119,7 +119,7 @@ items:
119
119
```
120
120
### Examples
121
121
#### Read Write Once (RWO) with nexus-volume storage class
122
-
The below manifest creates a StatefulSet with PersistentVolumeClaimTemplate using nexus-volume storage class in ReadWriteOnce mode.
122
+
This example manifest creates a StatefulSet with PersistentVolumeClaimTemplate using nexus-volume storage class in ReadWriteOnce mode.
123
123
```
124
124
apiVersion: apps/v1
125
125
kind: StatefulSet
@@ -158,7 +158,7 @@ spec:
158
158
storage: 10Gi
159
159
storageClassName: nexus-volume
160
160
```
161
-
Each pod of the StatefulSet will have one PersistentVolumeClaim created.
161
+
Each pod of the StatefulSet has one PersistentVolumeClaim created.
162
162
```
163
163
# kubectl get pvc
164
164
NAME STATUS VOLUME CAPACITY ACCESS MODES STORAGECLASS AGE
@@ -247,7 +247,7 @@ spec:
247
247
claimName: test-volume-rwx
248
248
...
249
249
```
250
-
Once applied, there will be three replicas of the deployment sharing the same PVC.
250
+
Once applied, there are three replicas of the deployment sharing the same PVC.
251
251
```
252
252
# kubectl get pvc
253
253
NAME STATUS VOLUME CAPACITY ACCESS MODES STORAGECLASS AGE
@@ -281,6 +281,25 @@ Thu Nov 9 21:51:41 UTC 2023 -- test-deploy-rwx-fdb8f49c-wdgw7
281
281
Thu Nov 9 21:51:42 UTC 2023 -- test-deploy-rwx-fdb8f49c-86pv4
282
282
```
283
283
284
+
## Volume size limits and capacity management
285
+
286
+
PVCs created using the nexus-volume and nexus-shared have minimum and maximum claim sizes.
287
+
288
+
| Storage Class | Minimum PVC Size | Maximum PVC Size |
> Volumes that reach their consumption limit will cause out of disk space errors on the workloads that consume them. You must make sure that you provision suitable volume sizes for your workload requirements. You must monitor both the storage appliance and all NFS servers for their percentage storage consumption. You can do this using the metrics documented in the [list of available metrics](./list-of-metrics-collected.md).
295
+
296
+
- Both nexus-volume and nexus-shared PVCs have their requested storage capacity enforced as a consumption limit. A volume can't consume more storage than the associated PVC request.
297
+
- All physical volumes are thin-provisioned. You must monitor the total storage consumption on your storage appliance and perform maintenance operations to free up storage space if necessary.
298
+
- A nexus-volume PVC provisioning request fails if the requested size is less than the minimum or more than the maximum supported volume size.
299
+
- Nexus-shared volumes are logically thin-provisioned on the backing NFS server. This NFS server has a fixed capacity of 1 TiB.
300
+
- A nexus-shared PVC can be provisioned despite requesting more than 1 TiB of storage, however, only 1 TiB can be consumed.
301
+
- It is possible to provision a set of PVCs where the sum of capacity requests is greater than 1 TiB. However, the consumption limit of 1 TiB applies; the set of associated PVs may not consume more than 1 TiB of storage.
302
+
284
303
## Storage appliance status
285
304
286
305
The following properties reflect the operational state of a storage appliance:
| Volume orchestration connectivity is TLS encrypted | Beginning from 1.28.9-1, 1.28.0-5, 1.27.9-1, 1.27.3-5, 1.26.12-1, 1.26.6-5, 1.25.11-5 and 1.25.6-7 ||
101
101
| Cluster nodes are Azure Arc-enabled | Beginning from 1.25.6-4, 1.25.11-2, 1.26.3-4, 1.26.6-2, 1.27.1-4, 1.27.3-2 and 1.28.0-2 ||
102
+
| nexus-shared volumes have their capacity attribute enforced as a volume size limit | Beginning from v1.27.13-3, v1.27.9-5, v1.28.11-4, v1.28.12-3, v1.29.6-4, v1.29.7-3, v1.30.3-1 ||
102
103
103
104
## Upgrading Kubernetes versions
104
105
@@ -233,7 +234,7 @@ Nexus Kubernetes clusters don't support direct upgrades between LTS versions. To
233
234
234
235
### How does Microsoft notify me of new Kubernetes versions?
235
236
236
-
This document is updated periodically with planned dates of the new Kubernetes versions.
237
+
This document is updated periodically with planned dates of the new Kubernetes versions.
237
238
238
239
### How often should I expect to upgrade Kubernetes versions to stay in support?
Copy file name to clipboardExpand all lines: articles/sentinel/unified-connector-syslog-device.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -68,7 +68,7 @@ This data connector was developed using Cisco Stealthwatch version 7.3.2
68
68
>
69
69
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's first line.
70
70
>
71
-
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **CiscoUCS**. Alternatively, directly load the [function code](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cisco%20UCS/Parsers/CiscoUCS.txt). It might take about 15-minutes post-installation to update.
71
+
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **CiscoUCS**. Alternatively, directly load the [function code](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cisco%20UCS/Parsers/CiscoUCS.yaml). It might take about 15-minutes post-installation to update.
72
72
73
73
## Cisco Web Security Appliance (WSA)
74
74
@@ -90,7 +90,7 @@ Configure Citrix ADC (former NetScaler) to forward logs via Syslog.
90
90
5. For more information, see the [Citrix ADC (former NetScaler) documentation](https://docs.netscaler.com/).
91
91
92
92
> [!NOTE]
93
-
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation. To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **CitrixADCEvent**. Alternatively, you can directly load the [function code](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Citrix%20ADC/Parsers/CitrixADCEvent.txt). It might take about 15 minutes post-installation to update.
93
+
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation. To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **CitrixADCEvent**. Alternatively, you can directly load the [function code](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Citrix%20ADC/Parsers/CitrixADCEvent.yaml). It might take about 15 minutes post-installation to update.
94
94
>
95
95
> This parser requires a watchlist named `Sources_by_SourceType`.
96
96
>
@@ -161,7 +161,7 @@ This data connector was developed using Forescout Syslog Plugin version: v3.6
161
161
> [!NOTE]
162
162
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation.
163
163
>
164
-
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **Infoblox**. Alternatively, you can directly load the [function code](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Infoblox%20NIOS/Parser/Infoblox.txt). It might take about 15 minutes post-installation to update.
164
+
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **Infoblox**. Alternatively, you can directly load the [function code](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Infoblox%20NIOS/Parsers/Infoblox.yaml). It might take about 15 minutes post-installation to update.
165
165
>
166
166
> This parser requires a watchlist named **`Sources_by_SourceType`**.
167
167
>
@@ -315,7 +315,7 @@ This data connector was developed using RSA SecurID Authentication Manager versi
315
315
>
316
316
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's first line.
317
317
>
318
-
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **SymantecVIP**. Alternatively, directly load the [function code](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Symantec%20VIP/Parsers/SymantecVIP.txt). It might take about 15 minutes post-installation to update.
318
+
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **SymantecVIP**. Alternatively, directly load the [function code](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Symantec%20VIP/Parsers/SymantecVIP.yaml). It might take about 15 minutes post-installation to update.
Copy file name to clipboardExpand all lines: articles/virtual-desktop/session-host-update-configure.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ ms.author: daknappe
7
7
ms.date: 10/01/2024
8
8
---
9
9
10
-
# Update session hosts in host pool with a session host configuration using session host update in Azure Virtual Desktop (preview)
10
+
# Update session hosts using session host update in Azure Virtual Desktop (preview)
11
11
12
12
> [!IMPORTANT]
13
13
> Session host update for Azure Virtual Desktop is currently in PREVIEW. This limited preview is provided as-is, with all faults and as available, and are excluded from the service-level agreements (SLAs) or any limited warranties Microsoft provides for Azure services in general availability. To register for the limited preview, complete this form: [https://forms.office.com/r/ZziQRGR1Lz](https://forms.office.com/r/ZziQRGR1Lz).
0 commit comments