Cloud

DevOpsArk + Azure

AKS, virtual machines, ACR and cost

Vendor: Microsoft

Short answer

What does the DevOpsArk Azure integration do?

The DevOpsArk Azure integration connects Azure subscriptions so AKS clusters, virtual machines, Azure Container Registry, Entra ID access and cost data are managed from the same plane as your other providers.

Capabilities

What the Azure integration provides

  • Manage Azure Kubernetes Service clusters in the same inventory as EKS and GKE.
  • Inventory Azure virtual machines with patch state and configuration baseline.
  • Publish images to Azure Container Registry by immutable digest.
  • Evaluate subscription configuration against CIS Azure Foundations and your own policy.
  • Attribute Azure Cost Management data to clusters, namespaces and teams.
  • Include Azure RBAC and Entra ID in the unified effective-access model.
  • Manage Azure DNS zones through the reviewed change path.
Access

Exactly what is read, and what can be written

Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.

Read
  • AKS cluster, node pool and add-on configuration
  • Virtual machine inventory, tags and extensions
  • Azure Container Registry repositories and images
  • Entra ID role assignments and Azure RBAC
  • Azure Monitor metrics and logs
  • Azure Cost Management exports
  • Azure DNS zones and record sets
  • Virtual network and network security group configuration
Write, only if granted
  • Kubernetes workloads deployed to AKS through ArkCD
  • Container images pushed to Azure Container Registry
  • Azure DNS record changes through the reviewed change path
  • Approved remediation where write scope is granted
Setup

Connecting Azure

  1. 1
    Register an application

    Create an Entra ID application registration for DevOpsArk with the supplied reader role assignments.

  2. 2
    Assign scope

    Grant the role at management group or subscription scope depending on how much of the estate you want visible.

  3. 3
    Connect

    Register the tenant, subscription and application credentials in DevOpsArk.

  4. 4
    Attach cost exports

    Point DevOpsArk at the Cost Management export to enable attribution.

FAQ

Azure integration: frequently asked questions

Connect Azure and see your own data

Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.