Skip to content

Commit 1125a1f

Browse files
Merge pull request #18456 from MicrosoftDocs/main
Auto Publish – main to live - 2025-07-16 17:00 UTC
2 parents 3156d5a + 756466c commit 1125a1f

File tree

1 file changed

+24
-25
lines changed

1 file changed

+24
-25
lines changed

AKS-Arc/arc-gateway-aks-arc.md

Lines changed: 24 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -2,25 +2,24 @@
22
title: Simplify network configuration requirements with Azure Arc gateway (preview)
33
description: Learn how to enable Arc gateway on AKS Arc clusters to simplify network configuration requirements
44
ms.topic: how-to
5-
ms.date: 11/18/2024
5+
ms.date: 07/15/2025
66
author: sethmanheim
7-
ms.author: sethm
8-
ms.reviewer: abha
9-
ms.lastreviewed: 11/18/2024
10-
7+
ms.author: sethm
8+
ms.reviewer: srikantsarwa
9+
ms.lastreviewed: 07/15/2025
1110
---
1211

13-
# Simplify network configuration requirements with Azure Arc Gateway (preview)
12+
# Simplify network configuration requirements with AKS Arc Gateway (preview)
1413

1514
If you use enterprise proxies to manage outbound traffic, Azure Arc gateway can help simplify the process of enabling connectivity.
1615

17-
The Azure Arc gateway (currently in preview) lets you:
16+
The AKS Arc gateway (currently in preview) lets you:
1817

1918
- Connect to Azure Arc by opening public network access to only seven fully qualified domain names (FQDNs).
2019
- View and audit all traffic that the Arc agents send to Azure via the Arc gateway.
2120

2221
> [!IMPORTANT]
23-
> Azure Arc gateway is currently in preview.
22+
> AKS Arc gateway is currently in preview.
2423
>
2524
> See the [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) for legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
2625
@@ -29,7 +28,7 @@ The Azure Arc gateway (currently in preview) lets you:
2928
The Arc gateway works by introducing two new components:
3029

3130
- The **Arc gateway resource** is an Azure resource that serves as a common front end for Azure traffic. The gateway resource is served on a specific domain/URL. You must create this resource by following the steps described in this article. After you successfully create the gateway resource, this domain/URL is included in the success response.
32-
- The **Arc Proxy** is a new component that runs as its own pod (called *Azure Arc Proxy*). This component acts as a forward proxy used by Azure Arc agents and extensions. There is no configuration required on your part for the Azure Arc Proxy.
31+
- The **Arc Proxy** is a new component that runs as its own pod (called _Azure Arc Proxy_). This component acts as a forward proxy used by Azure Arc agents and extensions. There is no configuration required on your part for the Azure Arc Proxy.
3332

3433
For more information, see [how the Azure Arc gateway works](/azure/azure-arc/kubernetes/arc-gateway-simplify-networking?tabs=azure-cli).
3534

@@ -52,36 +51,36 @@ For more information, see [how the Azure Arc gateway works](/azure/azure-arc/kub
5251

5352
## Confirm access to required URLs
5453

55-
Ensure your Arc gateway URL and all of the URLs below are allowed through your enterprise firewall:
54+
Ensure your Arc gateway URL and all of the following URLs are allowed through your enterprise firewall:
5655

57-
|URL |Purpose |
58-
|---------|---------|
59-
|`[Your URL prefix].gw.arc.azure.com`| Your gateway URL. You can obtain this URL by running `az arcgateway list` after you create the resource. |
60-
|`management.azure.com` |Azure Resource Manager endpoint, required for the Azure Resource Manager control channel. |
61-
|`<region>.obo.arc.azure.com` |Required when `az connectedk8s proxy` is used. |
62-
|`login.microsoftonline.com`, `<region>.login.microsoft.com` | Microsoft Entra ID endpoint, used for acquiring identity access tokens. |
63-
|`gbl.his.arc.azure.com`, `<region>.his.arc.azure.com` |The cloud service endpoint for communicating with Arc Agents. Uses short names; for example `eus` for East US. |
64-
|`mcr.microsoft.com`, `*.data.mcr.microsoft.com` |Required to pull container images for Azure Arc agents. |
56+
| URL | Purpose |
57+
| ----------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- |
58+
| `[Your URL prefix].gw.arc.azure.com` | Your gateway URL. You can obtain this URL by running `az arcgateway list` after you create the resource. |
59+
| `management.azure.com` | Azure Resource Manager endpoint, required for the Azure Resource Manager control channel. |
60+
| `<region>.obo.arc.azure.com` | Required when `az connectedk8s proxy` is used. |
61+
| `login.microsoftonline.com`, `<region>.login.microsoft.com` | Microsoft Entra ID endpoint, used for acquiring identity access tokens. |
62+
| `gbl.his.arc.azure.com`, `<region>.his.arc.azure.com` | The cloud service endpoint for communicating with Arc Agents. Uses short names; for example, `eus` for East US. |
63+
| `mcr.microsoft.com`, `*.data.mcr.microsoft.com` | Required to pull container images for Azure Arc agents. |
6564

66-
## Create an AKS Arc cluster with Arc gateway enabled
65+
## Create an AKS Arc cluster with AKS Arc gateway enabled
6766

68-
Run the following command to create an AKS Arc cluster with the Arc gateway enabled:
67+
Run the following command to create an AKS Arc cluster with the AKS Arc gateway enabled:
6968

7069
```azurecli
7170
az aksarc create -n $clusterName -g $resourceGroup --custom-location $customlocationID --vnet-ids $arcVmLogNetId --aad-admin-group-object-ids $aadGroupID --gateway-id $gatewayId --generate-ssh-keys
7271
```
7372

74-
## Update an AKS Arc cluster and enable Arc gateway
73+
## Update an AKS Arc cluster and enable the AKS Arc gateway
7574

76-
Run the following command to update an AKS Arc cluster to enable Arc gateway:
75+
Run the following command to update an AKS Arc cluster to enable the AKS Arc gateway:
7776

7877
```azurecli
7978
az aksarc update -n $clusterName -g $resourceGroup --gateway-id $gatewayId
8079
```
8180

82-
## Disable Arc gateway on an AKS Arc cluster
81+
## Disable the AKS Arc gateway on an AKS Arc cluster
8382

84-
Run the following command to disable Arc gateway:
83+
Run the following command to disable the AKS Arc gateway:
8584

8685
```azurecli
8786
az aksarc update -n $clusterName -g $resourceGroup --disable-gateway
@@ -92,7 +91,7 @@ az aksarc update -n $clusterName -g $resourceGroup --disable-gateway
9291
To audit your gateway traffic, view the gateway router logs:
9392

9493
1. Run `kubectl get pods -n azure-arc`.
95-
1. Identify the Arc Proxy pod (its name will begin with `arc-proxy-`).
94+
1. Identify the Arc Proxy pod (its name begins with `arc-proxy-`).
9695
1. Run `kubectl logs -n azure-arc <Arc Proxy pod name>`.
9796

9897
## Other scenarios

0 commit comments

Comments
 (0)