Skip to content

Commit 40e777c

Browse files
committed
Merge branch '20241021' of https://github.com/rcheeran/azure-stack-docs-pr into rc10-23
2 parents 91ed6b2 + 76228f5 commit 40e777c

File tree

2 files changed

+122
-0
lines changed

2 files changed

+122
-0
lines changed

AKS-Hybrid/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -196,6 +196,8 @@
196196
href: aks-edge-howto-setup-nested-environment.md
197197
- name: Use GitOps with AKS Edge Essentials
198198
href: aks-edge-howto-use-gitops.md
199+
- name: Deploy AIO on AKS Edge Essentials
200+
href: aks-edge-howto-deploy-AIO.md
199201
- name: Offline installation
200202
href: aks-edge-howto-offline-install.md
201203
- name: Access TPM secrets
Lines changed: 120 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,120 @@
1+
---
2+
title: AIO with AKS Edge Essentials
3+
description: Learn how to use Azure IoT Operations with AKS Edge Essentials.
4+
author: rcheeran
5+
ms.author: rcheeran
6+
ms.topic: how-to
7+
ms.date: 10/21/2024
8+
ms.custom: template-how-to
9+
---
10+
11+
# Deploy Azure IoT Operations on AKS Edge Essentials
12+
13+
[Azure IoT Operations (AIO)]() requires an Arc-enabled Kubernetes cluster. You can use AKS Edge Essentials to create a Microsoft managed Kubernetes cluster and deploy AIO as a workload on it. This article describes the steps to run a handy script that creates an AKS Edge Essentials Kubernetes clusters with all the required configurations applicable for AIO.
14+
15+
> [!NOTE]
16+
> AIO is Generally Available on AKS EE when deployed on single machine clusters. Deploying clusters on multiple machines is an experimental feature.
17+
18+
## Pre-requisites for running the script
19+
20+
- An Azure subscription with either the **Owner** role or a combination of **Contributor** and **User Access Administrator** roles. You can check your access level by navigating to your subscription, selecting **Access control (IAM)** on the left-hand side of the Azure portal, and then selecting **View my access**. Read the [Azure Resource Manager documentation](/azure/azure-resource-manager/management/manage-resource-groups-portal) for more information about managing resource groups. If you don't have an Azure subscription, [create one for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F) before you begin.
21+
- Azure CLI version 2.64.0 or newer installed on your development machine. Use az --version to check your version and az upgrade to update if necessary.For more information, see [How to install the Azure CLI](https://review.learn.microsoft.com/en-us/cli/azure/install-azure-cli).
22+
- The latest version of the following extensions for Azure CLI:
23+
```bash
24+
az extension add --upgrade --name azure-iot-ops
25+
az extension add --upgrade --name connectedk8s
26+
```
27+
- Hardware requirements: Ensure that your machine has a minimum of 16-GB available RAM, 8 available vCPUs, and 52-GB free disk space reserved for Azure IoT Operations.
28+
- If you're going to deploy Azure IoT Operations to a multi-node cluster with fault tolerance enabled, review the hardware and storage requirements in [Prepare Linux for Edge Volumes](https://review.learn.microsoft.com/en-us/azure/azure-arc/container-storage/prepare-linux-edge-volumes).
29+
30+
31+
## Create an AKS EE cluster for AIO
32+
The [AksEdgeQuickStartForAio.ps1](https://github.com/Azure/AKS-Edge/blob/main/tools/scripts/AksEdgeQuickStart/AksEdgeQuickStartForAio.ps1) script automates the process of creating and connecting a cluster, and is the recommended path for deploying Azure IoT Operations on AKS Edge Essentials. Here is what the script does on your behalf:
33+
- Downloads the latest AKS EE MSI from this [repo](https://github.com/Azure/aks-edge).
34+
- Installs AKS EE and deploys to creates a single machine Kubernetes cluster on your Windows machine.
35+
- Connects to the Azure subscription and creates a resource group if it does exists already and connects the cluster to Arc to create an Arc-enabled Kubernetes cluster.
36+
- Enables the custom location feature on the Arc-enabled Kubernetes cluster.
37+
- Deploys the local path provisioning.
38+
- Configures firewall rules on the host Windows machine for the MQTT broker.
39+
- On the Linux VM, which serves as the Kubernetes control plane node:
40+
- Configures port proxy for the Kubernetes Service default IP range of 10.96.0.0/28.
41+
- Configures the IP table rules.
42+
- `sudo iptables -A INPUT -p tcp -m state --state NEW -m tcp --dport 9110 -j ACCEPT`
43+
- `sudo iptables -A INPUT -p tcp --dport (10124, 8420, 2379, 50051) -j ACCEPT`
44+
45+
Once you have downloaded the script,
46+
1. Open an elevated PowerShell window and change the directory to a working folder.
47+
1. Get the objectId of the Microsoft Entra ID application that the Azure Arc service uses in your tenant. Run the following command exactly as written, without changing the GUID value.
48+
```azurecli
49+
az ad sp show --id bc313c14-388c-4e7d-a58e-70017303ee3b --query id -o tsv
50+
```
51+
1. Run the following commands, replacing the placeholder values with your information:
52+
53+
|Placeholder|Value |
54+
|---------|---------|
55+
|SUBSCRIPTION_ID | The ID of your Azure subscription. If you don't know your subscription ID, see [Find your Azure subscription](https://review.learn.microsoft.com/en-us/azure/azure-portal/get-subscription-tenant-id#find-your-azure-subscription). |
56+
|TENANT_ID | The ID of your Microsoft Entra tenant. If you don't know your tenant ID, see [Find your Microsoft Entra tenant](https://review.learn.microsoft.com/en-us/azure/azure-portal/get-subscription-tenant-id#find-your-microsoft-entra-tenant). |
57+
|RESOURCE_GROUP_NAME | The name of an existing resource group or a name for a new resource group to be created. |
58+
|LOCATION | An Azure region close to you. For the list of currently supported Azure regions, see [Supported regions](https://review.learn.microsoft.com/en-us/azure/iot-operations/overview-iot-operations#supported-regions). |
59+
|CLUSTER_NAME | A name for the new cluster to be created. |
60+
|ARC_APP_OBJECT_ID | The object ID value that you retrieved in step 2. |
61+
62+
```powershell
63+
$url = "https://raw.githubusercontent.com/Azure/AKS-Edge/main/tools/scripts/AksEdgeQuickStart/AksEdgeQuickStartForAio.ps1"
64+
Invoke-WebRequest -Uri $url -OutFile .\AksEdgeQuickStartForAio.ps1
65+
Unblock-File .\AksEdgeQuickStartForAio.ps1
66+
Set-ExecutionPolicy -ExecutionPolicy Bypass -Scope Process -Force
67+
.\AksEdgeQuickStartForAio.ps1 -SubscriptionId "<SUBSCRIPTION_ID>" -TenantId "<TENANT_ID>" -ResourceGroupName "<RESOURCE_GROUP_NAME>" -Location "<LOCATION>" -ClusterName "<CLUSTER_NAME>" -CustomLocationOid "<ARC_APP_OBJECT_ID>"
68+
```
69+
If there are any issues during deployment, including if your machine reboots as part of this process, run the whole set of commands again.
70+
1. Run the following commands to check that the deployment was successful:
71+
```powershell
72+
Import-Module AksEdge
73+
Get-AksEdgeDeploymentInfo
74+
```
75+
In the output of the Get-AksEdgeDeploymentInfo command, you should see that the cluster's Arc status is Connected.
76+
77+
## Verify your cluster
78+
To verify that your cluster is ready for Azure IoT Operations deployment, you can use the [verify-host](https://review.learn.microsoft.com/en-us/cli/azure/iot/ops#az-iot-ops-verify-host) helper command in the Azure IoT Operations extension for Azure CLI. When run on the cluster host, this helper command checks connectivity to Azure Resource Manager and Microsoft Container Registry endpoints.
79+
```azurecli
80+
az iot ops verify-host
81+
```
82+
83+
To verify that your Kubernetes cluster is Azure Arc-enabled, run the following command:
84+
```bash
85+
kubectl get deployments,pods -n azure-arc
86+
```
87+
88+
The output looks like the following example:
89+
```output
90+
NAME READY UP-TO-DATE AVAILABLE AGE
91+
deployment.apps/clusterconnect-agent 1/1 1 1 10m
92+
deployment.apps/extension-manager 1/1 1 1 10m
93+
deployment.apps/clusteridentityoperator 1/1 1 1 10m
94+
deployment.apps/controller-manager 1/1 1 1 10m
95+
deployment.apps/flux-logs-agent 1/1 1 1 10m
96+
deployment.apps/cluster-metadata-operator 1/1 1 1 10m
97+
deployment.apps/extension-events-collector 1/1 1 1 10m
98+
deployment.apps/config-agent 1/1 1 1 10m
99+
deployment.apps/kube-aad-proxy 1/1 1 1 10m
100+
deployment.apps/resource-sync-agent 1/1 1 1 10m
101+
deployment.apps/metrics-agent 1/1 1 1 10m
102+
103+
NAME READY STATUS RESTARTS AGE
104+
pod/clusterconnect-agent-5948cdfb4c-vzfst 3/3 Running 0 10m
105+
pod/extension-manager-65b8f7f4cb-tp7pp 3/3 Running 0 10m
106+
pod/clusteridentityoperator-6d64fdb886-p5m25 2/2 Running 0 10m
107+
pod/controller-manager-567c9647db-qkprs 2/2 Running 0 10m
108+
pod/flux-logs-agent-7bf6f4bf8c-mr5df 1/1 Running 0 10m
109+
pod/cluster-metadata-operator-7cc4c554d4-nck9z 2/2 Running 0 10m
110+
pod/extension-events-collector-58dfb78cb5-vxbzq 2/2 Running 0 10m
111+
pod/config-agent-7579f558d9-5jnwq 2/2 Running 0 10m
112+
pod/kube-aad-proxy-56d9f754d8-9gthm 2/2 Running 0 10m
113+
pod/resource-sync-agent-769bb66b79-z9n46 2/2 Running 0 10m
114+
pod/metrics-agent-6588f97dc-455j8 2/2 Running 0 10m
115+
```
116+
117+
## Next steps
118+
119+
- [Deploy Azure IoT Operations](https://review.learn.microsoft.com/en-us/azure/iot-operations/deploy-iot-ops/howto-deploy-iot-operations)
120+
- [Uninstall AKS cluster](aks-edge-howto-uninstall.md)

0 commit comments

Comments
 (0)