AKS monitoring settings need review

Missing AKS logs and metrics can make failures and unusual activity harder to investigate.

Description

Without the required logs and metrics, it is harder to understand the state of AKS nodes and containers and diagnose problems. Container Insights improves operational visibility, but enabling it does not automatically collect every Kubernetes API server audit log.

Potential impact

  • Failures or rising resource use may take longer to notice.
  • Container logs and historical metrics needed for investigations may be unavailable.

Remediation

  • Where Azure Monitor is used, enable addon.monitoring and connect the actual Log Analytics workspace.
  • Collect the required control plane logs separately through diagnostic settings.
  • Verify collection scope, retention, alerts and actual log delivery.

Examples

These excerpts compare monitoring settings. Supply a supported Kubernetes version and a real workspace ID, and configure the remaining cluster settings, including node pools and authentication, separately.

Before

yaml
- name: AKS 생성
  azure_rm_aks:
    name: myAKS
    resource_group: myResourceGroup
    location: eastus
    dns_prefix: akstest
    kubernetes_version: "{{ kubernetes_version }}"
    enable_rbac: yes

No monitoring integration is shown. If another collection tool is used, verify that it provides the required logs and metrics.

After

yaml
- name: AKS 생성
  azure_rm_aks:
    name: myAKS
    resource_group: myResourceGroup
    location: eastus
    dns_prefix: akstest
    kubernetes_version: "{{ kubernetes_version }}"
    enable_rbac: yes
    addon:
      monitoring:
        log_analytics_workspace_resource_id: "{{ log_analytics_workspace_resource_id }}"
        enabled: yes

The monitoring integration is enabled and a workspace is specified. Verify that the collection settings and permissions take effect and data reaches the workspace.

References