Skip to content

[AKS] Support configuring SSH for AKS nodepools - #34161

Open
Tongyao Si (norshtein) wants to merge 1 commit into
Azure:devfrom
norshtein:tosi/entraid-ssh
Open

Tongyao Si (norshtein) wants to merge 1 commit into
Azure:devfrom
norshtein:tosi/entraid-ssh

Conversation

@norshtein

Copy link
Copy Markdown
Member

Related command
az aks support configuring SSH setting for node pools.

Description
This PR add support for configuring SSH access for AKS node pool.

Testing Guide

History Notes

[AKS] az aks nodepool create/update: Add --ssh-access with localuser, disabled and entraid options to configure SSH access for the node pool.


This checklist is used to make sure that common guidelines for a pull request are followed.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 08:20
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

CI reports missing parameter help and scenario coverage, and the changes include minor style violations.

Review effort: Balanced
Findings: 6 Low severity

Open (6)
What changed in this PR

Adds configurable SSH access modes for AKS cluster and node-pool creation/update.

Changes:

  • Adds --ssh-access modes and update confirmation.
  • Applies SSH settings to agent-pool security profiles.
  • Adds decorator tests and history entries.
File Description
HISTORY.rst Documents the new options.
test_managed_cluster_decorator.py Tests cluster creation behavior.
test_agentpool_decorator.py Tests node-pool creation and updates.
managed_cluster_decorator.py Applies SSH access during cluster creation.
custom.py Exposes handler parameters.
agentpool_decorator.py Implements node-pool SSH configuration.
_params.py Registers arguments and accepted values.
_consts.py Defines SSH access constants.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

c.argument('enable_vtpm', action="store_true")
c.argument('enable_secure_boot', action="store_true")
# in creation scenario, use "localuser" as default
c.argument('ssh_access', arg_type=get_enum_type(ssh_accesses), default=CONST_SSH_ACCESS_LOCALUSER, is_preview=True)
c.argument('enable_vtpm', action='store_true')
c.argument('enable_secure_boot', action='store_true')
# in creation scenario, use "localuser" as default
c.argument('ssh_access', arg_type=get_enum_type(ssh_accesses), default=CONST_SSH_ACCESS_LOCALUSER, is_preview=True)
c.argument('enable_secure_boot', action='store_true')
c.argument('disable_secure_boot', action='store_true')
# in update scenario, use empty str as default
c.argument('ssh_access', arg_type=get_enum_type(ssh_accesses), is_preview=True)
if ssh_access is not None:
for agent_pool_profile in (mc.agent_pool_profiles or []):
if agent_pool_profile.security_profile is None:
agent_pool_profile.security_profile = self.models.AgentPoolSecurityProfile() # pylint: disable=no-member

def test_set_up_ssh_access(self):
self.common_set_up_ssh_access()

CONST_AVAILABILITY_SET,
CONST_SSH_ACCESS_LOCALUSER,
CONST_SSH_ACCESS_DISABLED,
CONST_SSH_ACCESS_ENTRAID,
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

act-observability-squad AKS az aks/acs/openshift Auto-Assign Auto assign by bot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants