This topic explains how to prepare Microsoft Azure for running Tanzu Kubernetes Grid.
If you are installing Tanzu Kubernetes Grid on Azure VMware Solution (AVS), you are installing to a vSphere environment. See Preparing Azure VMware Solution on Microsoft Azure in Prepare a vSphere Management as a Service Infrastructure to prepare your environment and Prepare to Deploy Management Clusters to vSphere to deploy management clusters.
The following diagram shows the high-level steps for installing a Tanzu Kubernetes Grid management cluster on Azure, and the interfaces you use to perform them.
These steps include the preparations listed below plus the procedures described in either Deploy Management Clusters with the Installer Interface or Deploy Management Clusters from a Configuration File.
devplan: 4 vCPU (1 main, 1 worker)
prodplan: 8 vCPU (3 main , 1 worker)
devplan: 4 vCPU (1 main, 1 worker)
prodplan: 12 vCPU (3 main , 3 worker)
|Plan||Workload Clusters||vCPU for Workload||vCPU for Management||Total vCPU|
LoadBalancer, 1 Public IP address is required.
~/.config/tanzu/tkg/bom/, and its name includes the Tanzu Kubernetes Grid version. For example,
imageRepositoryvalues to find their CNAMEs.
(Optional) A VNET with:
If you do not use an existing VNET, the installation process creates a new one.
The Azure CLI installed locally. See Install the Azure CLI in the Microsoft Azure documentation.
*Or see Prepare an Internet-Restricted Environment for installing without external network access.
Tanzu Kubernetes Grid management and workload clusters on Azure require the following Network Security Groups (NSGs) to be defined on their VNET:
If you do not specify a VNET when deploying a management cluster, the deployment process creates a new VNET along with the NSGs required for the management cluster. If you optionally create a VNET for Tanzu Kubernetes Grid before deploying a management cluster, you must also create these NSGs as described in the General Requirements above.
For each workload cluster that you deploy later, you need to create a worker NSG named
CLUSTER-NAME is the name of the workload cluster. This worker NSG must have the same VNET and region as its management cluster.
Tanzu Kubernetes Grid manages Azure resources as a registered client application that accesses Azure through a service principal. The following steps register your Tanzu Kubernetes Grid application with Azure Active Directory, create a client secret for authenticating communications, and record information needed later to deploy a management cluster.
Log in to the Azure Portal.
Record your Tenant ID by hovering over your account name at upper-right, or else browse to Azure Active Directory > <Your Azure Org> > Properties > Tenant ID. The value is a GUID, for example
Browse to Active Directory > App registrations and click + New registration.
Enter a display name for the app, such as
tkg, and select who else can use it. You can leave the Redirect URI (optional) field blank.
Click Register. This registers the application with an Azure service principal account as described in How to: Use the portal to create an Azure AD application and service principal that can access resources in the Azure documentation.
An overview pane for the app appears. Record its Application (client) ID value, which is a GUID.
From the Azure Portal top level, browse to Subscriptions. At the bottom of the pane, select one of the subscriptions you have access to, and record its Subscription ID. Click the subscription listing to open its overview pane.
Select to Access control (IAM) and click Add a role assignment.
In the Add role assignment pane:
tkg. It appears under Selected Members.
From the Azure Portal > Azure Active Directory > App Registrations, select your
tkg app under Owned applications. The app overview pane opens.
From Certificates & secrets > Client secrets click + New client secret.
In the Add a client secret popup, enter a Description, choose an expiration period, and click Add.
Azure lists the new secret with its generated value under Client Secrets. Record the value.
To run management cluster VMs on Azure, accept the license for their base Kubernetes version and machine OS.
Sign in to the Azure CLI as your
tkg client application.
az login --service-principal --username AZURE_CLIENT_ID --password AZURE_CLIENT_SECRET --tenant AZURE_TENANT_ID
AZURE_TENANT_ID are your
tkg app's client ID and secret and your tenant ID, as recorded in Register Tanzu Kubernetes Grid as an Azure Client App.
az vm image terms accept command, specifying the
--plan and your Subscription ID.
In Tanzu Kubernetes Grid v1.4.0, the default cluster image
--plan value is
k8s-1dot21dot2-ubuntu-2004, based on Kubernetes version 1.21.2 and the machine OS, Ubuntu 20.04. Run the following command:
az vm image terms accept --publisher vmware-inc --offer tkg-capi --plan k8s-1dot21dot2-ubuntu-2004 --subscription AZURE_SUBSCRIPTION_ID
AZURE_SUBSCRIPTION_ID is your Azure subscription ID.
You must repeat this to accept the base image license for every version of Kubernetes or OS that you want to use when you deploy clusters, and every time that you upgrade to a new version of Tanzu Kubernetes Grid.
You deploy management clusters from a machine referred to as the bootstrap machine, using the Tanzu CLI. To connect to Azure, the bootstrap machine must provide the public key part of an SSH key pair. If your bootstrap machine does not already have an SSH key pair, you can use a tool such as
ssh-keygen to generate one.
On your bootstrap machine, run the following
ssh-keygen -t rsa -b 4096 -C "firstname.lastname@example.org"
Enter file in which to save the key (/root/.ssh/id_rsa):press Enter to accept the default.
Add the private key to the SSH agent running on your machine, and enter the password you created in the previous step.
Open the file
.ssh/id_rsa.pub in a text editor so that you can easily copy and paste it when you deploy a management cluster.
Use this checklist to make sure you are prepared to deploy a Tanzu Kubernetes Grid management cluster to Azure:
Tanzu CLI installed
tanzu version. The output should list
Azure CLI installed
az version. The output should list the current version of the Azure CLI as listed in Install the Azure CLI, in the Microsoft Azure documentation.
tkgapp is listed as configured in Register Tanzu Kubernetes Grid as an Azure Client App above, and with a current certificate.
Base VM image license accepted
az vm image terms show --publisher vmware-inc --offer tkg-capi --plan k8s-1dot21dot2-ubuntu-2004. The output should contain
For production deployments, it is strongly recommended to enable identity management for your clusters. For information about the preparatory steps to perform before you deploy a management cluster, see Prepare External Identity Management.
If you are using Tanzu Kubernetes Grid in an environment with an external internet connection, once you have set up identity management, you are ready to deploy management clusters to Azure.