Description
Without the required logs and metrics, it is harder to understand the state of AKS nodes and containers and diagnose problems. Container Insights improves operational visibility, but enabling it does not automatically collect every Kubernetes API server audit log.
Potential impact
- Failures or rising resource use may take longer to notice.
- Container logs and historical metrics needed for investigations may be unavailable.
Remediation
- Where Azure Monitor is used, enable
addon.monitoringand connect the actual Log Analytics workspace. - Collect the required control plane logs separately through diagnostic settings.
- Verify collection scope, retention, alerts and actual log delivery.
Examples
These excerpts compare monitoring settings. Supply a supported Kubernetes version and a real workspace ID, and configure the remaining cluster settings, including node pools and authentication, separately.
Before
- name: AKS 생성
azure_rm_aks:
name: myAKS
resource_group: myResourceGroup
location: eastus
dns_prefix: akstest
kubernetes_version: "{{ kubernetes_version }}"
enable_rbac: yes
No monitoring integration is shown. If another collection tool is used, verify that it provides the required logs and metrics.
After
- name: AKS 생성
azure_rm_aks:
name: myAKS
resource_group: myResourceGroup
location: eastus
dns_prefix: akstest
kubernetes_version: "{{ kubernetes_version }}"
enable_rbac: yes
addon:
monitoring:
log_analytics_workspace_resource_id: "{{ log_analytics_workspace_resource_id }}"
enabled: yes
The monitoring integration is enabled and a workspace is specified. Verify that the collection settings and permissions take effect and data reaches the workspace.