Skip to content

Commit baf202e

Browse files
authored
Sync release-aks-ee-feb with main
Sync release-aks-ee-feb with main
2 parents a8e59c9 + c0ca692 commit baf202e

File tree

12 files changed

+245
-30
lines changed

12 files changed

+245
-30
lines changed

.openpublishing.publish.config.json

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@
66
"build_output_subfolder": "adaptive-cloud",
77
"locale": "en-us",
88
"monikers": [],
9+
"moniker_ranges": [],
910
"open_to_public_contributors": false,
1011
"type_mapping": {
1112
"Conceptual": "Content"
@@ -29,14 +30,12 @@
2930
"template_folder": "_themes"
3031
},
3132
{
32-
"docset_name": "AzureLocal",
33-
"build_source_folder": "azure-local",
34-
"build_output_subfolder": "AzureLocal",
33+
"docset_name": "azure-managed-lustre",
34+
"build_source_folder": "azure-managed-lustre",
35+
"build_output_subfolder": "azure-managed-lustre",
3536
"locale": "en-us",
3637
"monikers": [],
37-
"moniker_ranges": [
38-
">=azloc-2408"
39-
],
38+
"moniker_ranges": [],
4039
"open_to_public_contributors": true,
4140
"type_mapping": {
4241
"Conceptual": "Content"
@@ -45,12 +44,14 @@
4544
"template_folder": "_themes"
4645
},
4746
{
48-
"docset_name": "azure-managed-lustre",
49-
"build_source_folder": "azure-managed-lustre",
50-
"build_output_subfolder": "azure-managed-lustre",
47+
"docset_name": "AzureLocal",
48+
"build_source_folder": "azure-local",
49+
"build_output_subfolder": "AzureLocal",
5150
"locale": "en-us",
5251
"monikers": [],
53-
"moniker_ranges": [],
52+
"moniker_ranges": [
53+
">=azloc-2408"
54+
],
5455
"open_to_public_contributors": true,
5556
"type_mapping": {
5657
"Conceptual": "Content"

azure-local/concepts/compare-vm-management-capabilities.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ The following table compares the management capabilities for Arc VMs, Arc-enable
8787
| - Extended Security Updates | ✅ <br>[3](#3) | ✅ <br>[3](#3) ||
8888
| **Windows management** |
8989
| - Windows Admin Center ||✅ <br>[1](#1) and [2](#2) ||
90-
| - Best Practices Assessment ||✅ <br>[1](#1) and [2](#2) ||
90+
| - Best Practices Assessment ||✅ <br>[1](#1) and [2](#2) ||
9191
| **Monitoring** |
9292
| - Azure Monitor ||||
9393
| - Insights||||
@@ -114,4 +114,4 @@ The following table compares the management capabilities for Arc VMs, Arc-enable
114114

115115
## Next steps
116116

117-
- Review [Azure Arc VM management prerequisites](../manage/azure-arc-vm-management-prerequisites.md).
117+
- Review [Azure Arc VM management prerequisites](../manage/azure-arc-vm-management-prerequisites.md).

azure-local/concepts/system-requirements-23h2.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: alkohli
66
ms.topic: how-to
77
ms.service: azure-local
88
ms.custom: references_regions
9-
ms.date: 02/14/2025
9+
ms.date: 02/21/2025
1010
---
1111

1212
# System requirements for Azure Local
@@ -47,8 +47,8 @@ Before you begin, make sure that the physical machine and storage hardware used
4747

4848
|Component|Minimum|
4949
|--|--|
50-
|Number of machines| 1 to 16 machines are supported. <br> Each machine must be the same model, manufacturer, have the same network adapters, and have the same number and type of storage drives.|
51-
|CPU|A 64-bit Intel Nehalem grade or AMD EPYC or later compatible processor with second-level address translation (SLAT).|
50+
|Number of machines| 1 to 16 machines are supported. <br> Each machine must be the same model, manufacturer, have the same processor types, have the same network adapters, and have the same number and type of storage drives.|
51+
|CPU|A 64-bit Intel Nehalem grade or AMD EPYC or later compatible processor with second-level address translation (SLAT). <br> All the Azure Local machines used to form an Azure Local instance must have the same processor types. |
5252
|Memory|A minimum of 32-GB RAM per machine with Error-Correcting Code (ECC). <br> If you can't meet the memory and the ECC requirements, opt for a [Virtual deployment](../deploy/deployment-virtual.md).|
5353
|Host network adapters|At least two network adapters listed in the Windows Server Catalog. Or dedicated network adapters per intent, which does require two separate adapters for storage intent. For more information, see [Windows Server Catalog](https://www.windowsservercatalog.com/).|
5454
|BIOS|Intel VT or AMD-V must be turned on.|

azure-local/docfx.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -85,14 +85,14 @@
8585
},
8686
"fileMetadata": {
8787
"monikerRange": {
88-
"./*.md": ">=azloc-2408 || =azloc-previous",
89-
"./*.yml": ">=azloc-2408 || =azloc-previous"
88+
"./*.md": ">=azloc-24081 || =azloc-previous",
89+
"./*.yml": ">=azloc-24081 || =azloc-previous"
9090
}
9191
},
9292
"template": [],
9393
"groups": {
9494
"version-azlocal": {
95-
"moniker_range": ">=azloc-2408 || =azloc-previous",
95+
"moniker_range": ">=azloc-24081 || =azloc-previous",
9696
"dest": "azure-local"
9797
}
9898
}

azure-local/known-issues.md

Lines changed: 80 additions & 4 deletions
Large diffs are not rendered by default.

azure-local/manage/manage-secrets-rotation.md

Lines changed: 58 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -158,6 +158,64 @@ To change the deployment service principal, follow these steps:
158158
Set-AzureStackRPSpCredential -SubscriptionID $SubscriptionId -TenantID $TenantId -AppId $AppId -NewPassword $NewPassword
159159
```
160160

161+
## Rotate internal secrets
162+
163+
This section describes how you can rotate internal secrets. Internal secrets include certificates, passwords, secure strings, and keys used by the Azure Local infrastructure. Internal secret rotation is only required if you suspect one has been compromised, or you've received an expiration alert.
164+
165+
The exact steps for secret rotation are different depending on the software version your Azure Local instance is running.
166+
167+
### Azure Local instance running 2411.2 and later
168+
169+
1. Sign in to one of the Azure Local nodes using deployment user credentials.
170+
1. Start secret rotation. Run the following PowerShell command:
171+
172+
```PowerShell
173+
Start-SecretRotation
174+
```
175+
176+
### Azure Local instance running 2411.1 to 2411.0
177+
178+
1. Sign in to one of the Azure Local nodes using deployment user credentials.
179+
1. Update the CA Certificate password in ECE store. Run the following PowerShell command:
180+
181+
```PowerShell
182+
$SecureSecretText = ConvertTo-SecureString -String "<Replace with a strong password>" -AsPlainText -Force
183+
$CACertCred = New-Object -Type PSCredential -ArgumentList "CACertUser,$SecureSecretText"
184+
Set-ECEServiceSecret -ContainerName CACertificateCred -Credential $CACertCred
185+
```
186+
187+
1. Start secret rotation. Run the following PowerShell command:
188+
189+
```PowerShell
190+
Start-SecretRotation
191+
```
192+
193+
### Azure Local instance running 2408.2 to 2405.3
194+
195+
1. Sign in to one of the Azure Local nodes using deployment user credentials.
196+
1. Update the CA Certificate password in ECE store. Run the following PowerShell command:
197+
198+
```PowerShell
199+
$SecureSecretText = ConvertTo-SecureString -String "<Replace with a strong password>" -AsPlainText -Force
200+
$CACertCred = New-Object -Type PSCredential -ArgumentList "CACertificateCred,$SecureSecretText"
201+
Set-ECEServiceSecret -ContainerName CACertificateCred -Credential $CACertCred
202+
```
203+
204+
1. Delete FCA cert from all the cluster nodes and restart FCA service. Run the following command on each node of your Azure Local instance:
205+
206+
```PowerShell
207+
$cert = Get-ChildItem -Recurse cert:\LocalMachine\My | Where-Object { $_.Subject -like "CN=FileCopyAgentKeyIdentifier*" }
208+
$cert | Remove-Item
209+
restart-service "AzureStack File Copy Agent*"
210+
```
211+
212+
1. Start secret rotation. Run the following PowerShell command:
213+
214+
```PowerShell
215+
Start-SecretRotation
216+
```
217+
218+
161219
## Next steps
162220
163221
[Complete the prerequisites and checklist and install Azure Local](../deploy/deployment-prerequisites.md).
-1.52 KB
Loading

azure-local/release-information-23h2.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ author: alkohli
55
ms.author: alkohli
66
ms.topic: conceptual
77
ms.service: azure-local
8-
ms.date: 02/10/2025
8+
ms.date: 02/19/2025
99
---
1010

1111
# Azure Local release information
@@ -62,6 +62,7 @@ The following table summarizes the release information for Azure Local across al
6262

6363
|Version| OS Build |Security update| What's new | Known issues |
6464
|------|-------|---------------|------------|--------------|
65+
| 10.2411.3.2 <br><br> Availability date: 2025-02-20 | 25398.1425 | [February OS security update](security-update/security-update.md?view=azloc-24113&preserve-view=true) | [Features and improvements](./whats-new.md?view=azloc-24113&preserve-view=true#features-and-improvements-in-24113) | [Known issues](./known-issues.md?view=azloc-24113&preserve-view=true) |
6566
| 10.2411.2.12 <br><br> Availability date: 2025-02-10 | 25398.1369 | [January OS security update](security-update/security-update.md?view=azloc-24112&preserve-view=true) | [Features and improvements](./whats-new.md?view=azloc-24112&preserve-view=true#features-and-improvements-in-24112) | [Known issues](./known-issues.md?view=azloc-24112&preserve-view=true) |
6667
| 10.2411.1.10 <br><br> Availability date: 2024-12-17 | 25398.1308 | [December OS security update](security-update/security-update.md?view=azloc-24111&preserve-view=true) | [Features and improvements](./whats-new.md?view=azloc-24111&preserve-view=true#features-and-improvements-in-24111) | [Known issues](./known-issues.md?view=azloc-24111&preserve-view=true) |
6768
| 10.2411.0.24 <br><br> Availability date: 2024-11-26 | 25398.1251 | [November OS security update](security-update/security-update.md?view=azloc-2411&preserve-view=true) | [Features and improvements](./whats-new.md?view=azloc-2411&preserve-view=true#features-and-improvements-in-2411) | [Known issues](./known-issues.md?view=azloc-2411&preserve-view=true) |

azure-local/security-update/security-update.md

Lines changed: 70 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Security updates for Azure Local, version 23H2
33
description: Security updates for Azure Local, version 23H2.
44
author: alkohli
55
ms.topic: conceptual
6-
ms.date: 01/28/2025
6+
ms.date: 02/19/2025
77
ms.author: alkohli
88
ms.reviewer: alkohli
99
---
@@ -12,6 +12,74 @@ ms.reviewer: alkohli
1212

1313
This article lists the various security updates that are available in Azure Local.
1414

15+
::: moniker range="=azloc-24113"
16+
17+
## February OS security update (KB5051980) for Azure Local
18+
19+
This article describes the OS security update for Azure Local that was released on February 11, 2025 and applies to OS build 25398.1425.
20+
21+
## Improvements
22+
23+
This security update includes quality improvements. Below is a summary of the key issues that this update addresses when you install this KB. If there are new features, it lists them as well. The bold text within the brackets indicates the item or area of the change.
24+
25+
- **[Cluster stability]** Fixed: Many machines within the same system suddenly shut down. The network is less available, and latency rises.
26+
27+
- **[Task Manager]** Fixed: The CPU index number might be wrong when you set process affinity. This occurs on servers that have two or more non-uniform memory access (NUMA) nodes.
28+
29+
- **[GB18030-2022]** This update adds support for this amendment.
30+
31+
- **[Memory leak]** Fixed: Leaks occur when predictive input ideas show.
32+
33+
- **[Windows Kernel Vulnerable Driver Blocklist file (DriverSiPolicy.p7b)]** This update adds to the list of drivers that are at risk for Bring Your Own Vulnerable Driver (BYOVD) attacks.
34+
35+
- **[Virtual machine (VM) storage pool]** Fixed: Some operations that rely on a storage pool stop working. This occurs because the virtual machine (VM)can't reclaim disk space to do task such as load balancing.
36+
37+
- **[USB cameras]** Fixed: Your device does not recognize the camera is on. This issue occurs after you install the January 2025 security update.
38+
39+
- **Digital/Analog converter (DAC)** Fixed: You might experience issues with USB audio devices. This is more likely when you use a DAC audio driver based on [USB 1.0](/windows-hardware/drivers/audio/usb-audio-class-system-driver--usbaudio-sys-). USB audio devices might stop working, which stops playback.
40+
41+
For more information about security vulnerabilities, see the [Security Update Guide](https://portal.msrc.microsoft.com/security-guidance) and the [February 2025 Security Updates](https://msrc.microsoft.com/update-guide/releaseNote/2025-Feb).
42+
43+
## Known issues
44+
45+
The following is a known issue with this update.
46+
47+
**Symptom**
48+
49+
Following the installation of the October 2024 security update, some customers report that the OpenSSH (Open Secure Shell) service fails to start, preventing SSH connections. The service fails with no detailed logging, and manual intervention is required to run the sshd.exe process.
50+
51+
This issue is affecting enterprise, IOT, and education customers, with a limited number of devices impacted. Microsoft is investigating whether consumer customers using Home or Pro editions of Windows are also affected.
52+
53+
**Workaround**
54+
55+
You can temporarily resolve this issue by updating permissions (ACLs) on the affected directories. Follow these steps:
56+
57+
1. Open PowerShell as an administrator.
58+
59+
1. Update the permissions for *C:\ProgramData\ssh* and *C:\ProgramData\ssh\logs* to allow full control for **System** and the **Administrators** group, while allowing read access for **Authenticated Users**. You can restrict read access to specific users or groups by modifying the permissions string if needed.
60+
61+
1. Use the following commands to update the permissions:
62+
63+
```azurecli
64+
$directoryPath = "C:\ProgramData\ssh" $acl = Get-Acl -Path $directoryPath $sddlString = "O:BAD:PAI(A;OICI;FA;;;SY)(A;OICI;FA;;;BA)(A;OICI;0x1200a9;;;AU)" $securityDescriptor = New-Object System.Security.AccessControl.RawSecurityDescriptor $sddlString $acl.SetSecurityDescriptorSddlForm($securityDescriptor.GetSddlForm("All")) Set-Acl -Path $directoryPath -AclObject $acl
65+
```
66+
67+
1. Repeat the above steps for *C:\ProgramData\ssh\logs*.
68+
69+
Microsoft is actively investigating the issue and will provide a resolution in an upcoming Windows update. Further communications will be provided when a resolution or addition is available.
70+
71+
## To install
72+
73+
Microsoft now combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see [Servicing stack updates](/windows/deployment/update/servicing-stack-updates) and [Servicing Stack Updates (SSU): Frequently Asked Questions](https://support.microsoft.com/topic/servicing-stack-updates-ssu-frequently-asked-questions-06b62771-1cb0-368c-09cf-87c4efc4f2fe).
74+
75+
To install the LCU on your Azure Local instance, see [Update Azure Stack Local instances](../update/about-updates-23h2.md).
76+
77+
## File list
78+
79+
For a list of the files that are provided in this update, download the file information for [Cumulative update KB 5051980](https://go.microsoft.com/fwlink/?linkid=2303533).
80+
81+
::: moniker-end
82+
1583
::: moniker range="=azloc-24112"
1684
1785
## January OS security update (KB5049984) for Azure Local
@@ -201,7 +269,7 @@ For a list of the files that are provided in this update, download the file info
201269
202270
::: moniker-end
203271
204-
::: moniker range="azloc-2408"
272+
::: moniker range="azloc-previous"
205273
206274
## August 2024 OS security update (KB 5041573) for Azure Local
207275

azure-local/whats-new.md

Lines changed: 15 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,17 +5,29 @@ ms.topic: overview
55
author: alkohli
66
ms.author: alkohli
77
ms.service: azure-local
8-
ms.date: 01/28/2025
8+
ms.date: 02/19/2025
99
---
1010

1111
# What's new in Azure Local?
1212

13-
[!INCLUDE [applies-to](./includes/hci-applies-to-23h2.md)]
1413

1514
[!INCLUDE [azure-local-banner-23h2](./includes/azure-local-banner-23h2.md)]
1615

1716
This article lists the various features and improvements that are available in Azure Local. The latest version of Azure Local solution focuses on cloud-based deployment and updates, cloud-based monitoring, new and simplified experience for Arc VM management, security, and more.
1817

18+
::: moniker range="=azloc-24113"
19+
20+
## Features and improvements in 2411.3
21+
22+
This is a baseline release with the following features and improvements:
23+
24+
- **Quality updates** - This build contains the latest quality updates and is based off the Operating system version 25398.1425.
25+
- **Updated .NET version** - This build has an updated .NET version 8.0.13.
26+
27+
For more information on improvements in this release, see the [Fixed issues in 2411.3](./known-issues.md?view=azloc-24113&preserve-view=true#fixed-issues).
28+
29+
::: moniker-end
30+
1931
::: moniker range="=azloc-24112"
2032

2133
## Features and improvements in 2411.2
@@ -135,7 +147,7 @@ This is a baseline release with the following features and improvements:
135147

136148
::: moniker-end
137149

138-
::: moniker range="=azloc-2408"
150+
::: moniker range="=azloc-previous"
139151

140152
## Features and improvements in 2408
141153

0 commit comments

Comments
 (0)