Service | Microsoft Docs article | Related commit history on GitHub | Change details |
---|---|---|---|
ai-services | Studio Quickstart | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/ai-services/content-safety/studio-quickstart.md | In this quickstart, get started with the Azure AI Content Safety service using C * An active Azure account. If you don't have one, you can [create one for free](https://azure.microsoft.com/free/cognitive-services/). * A [Content Safety](https://aka.ms/acs-create) Azure resource.-* Assign `Cognitive Services User` role to your account to ensure the studio experience. Go to [Azure portal](https://portal.azure.com/), navigate to your Content Safety resource or Azure AI Services resource, and select **Access Control** in the left navigation bar, then click **+ Add role assignment**, choose the `Cognitive Services User` role and select the member of your account that you need to assign this role to, then review and assign. It might take few minutes for the assignment to take effect. +* Assign `Cognitive Services User` role to your account. Go to the [Azure Portal](https://portal.azure.com/), navigate to your Content Safety resource or Azure AI Services resource, and select **Access Control** in the left navigation bar, then select **+ Add role assignment**, choose the `Cognitive Services User` role and select the member of your account that you need to assign this role to, then review and assign. It might take few minutes for the assignment to take effect. * Sign in to [Content Safety Studio](https://contentsafety.cognitive.azure.com) with your Azure subscription and Content Safety resource. +> [!IMPORTANT] +> * You must assign the `Cognitive Services User` role to your Azure account to use the studio experience. Go to the [Azure Portal](https://portal.azure.com/), navigate to your Content Safety resource or Azure AI Services resource, and select **Access Control** in the left navigation bar, then select **+ Add role assignment**, choose the `Cognitive Services User` role and select the member of your account that you need to assign this role to, then review and assign. It might take few minutes for the assignment to take effect. + ## Analyze text content The [Moderate text content](https://contentsafety.cognitive.azure.com/text) page provides capability for you to quickly try out text moderation. |
ai-services | Models | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/ai-services/openai/concepts/models.md | For more information on Provisioned deployments, see our [Provisioned guidance]( - eastus ++### Global batch model availability ++### Region and model support ++The following models support global batch: ++| Model | Version | Input format | +||| +|`gpt-4o` | 2024-05-13 |text + image | +|`gpt-4` | turbo-2024-04-09 | text | +|`gpt-4` | 0613 | text | +| `gpt-35-turbo` | 0125 | text | +| `gpt-35-turbo` | 1106 | text | +| `gpt-35-turbo` | 0613 | text | ++Global batch is currently supported in the following regions: ++- East US +- West US +- Sweden Central + ### GPT-4 and GPT-4 Turbo model availability #### Public cloud regions These models can only be used with Embedding API requests. | `gpt-35-turbo` (1106) | East US2 <br> North Central US <br> Sweden Central <br> Switzerland West | Input: 16,385<br> Output: 4,096 | Sep 2021| | `gpt-35-turbo` (0125) | East US2 <br> North Central US <br> Sweden Central <br> Switzerland West | 16,385 | Sep 2021 | | `gpt-4` (0613) <sup>**1**</sup> | North Central US <br> Sweden Central | 8192 | Sep 2021 |+| `gpt-4o-mini` <sup>**1**</sup> (2024-07-18) | North Central US <br> Sweden Central | Input: 128,000 <br> Output: 16,384 <br> Training example context length: 64,536 | Oct 2023 | -**<sup>1</sup>** GPT-4 fine-tuning is currently in public preview. See our [GPT-4 fine-tuning safety evaluation guidance](/azure/ai-services/openai/how-to/fine-tuning?tabs=turbo%2Cpython-new&pivots=programming-language-python#safety-evaluation-gpt-4-fine-tuningpublic-preview) for more information. +**<sup>1</sup>** GPT-4 and GPT-4o mini fine-tuning is currently in public preview. See our [GPT-4 & GPT-4o mini fine-tuning safety evaluation guidance](/azure/ai-services/openai/how-to/fine-tuning?tabs=turbo%2Cpython-new&pivots=programming-language-python#safety-evaluation-gpt-4-fine-tuningpublic-preview) for more information. ### Whisper models |
ai-services | Batch | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/ai-services/openai/how-to/batch.md | + + Title: 'How to use global batch processing with Azure OpenAI Service' ++description: Learn how to use global batch with Azure OpenAI Service ++++ Last updated : 08/04/2024+++recommendations: false +zone_pivot_groups: openai-fine-tuning-batch +++# Getting started with Azure OpenAI global batch deployments (preview) ++The Azure OpenAI Batch API is designed to handle large-scale and high-volume processing tasks efficiently. Process asynchronous groups of requests with separate quota, with 24-hour target turnaround, at [50% less cost than global standard](https://azure.microsoft.com/pricing/details/cognitive-services/openai-service/). With batch processing, rather than send one request at a time you send a large number of requests in a single file. Global batch requests have a separate enqueued token quota avoiding any disruption of your online workloads. ++Key use cases include: ++* **Large-Scale Data Processing:** Quickly analyze extensive datasets in parallel. ++* **Content Generation:** Create large volumes of text, such as product descriptions or articles. ++* **Document Review and Summarization:** Automate the review and summarization of lengthy documents. ++* **Customer Support Automation:** Handle numerous queries simultaneously for faster responses. ++* **Data Extraction and Analysis:** Extract and analyze information from vast amounts of unstructured data. ++* **Natural Language Processing (NLP) Tasks:** Perform tasks like sentiment analysis or translation on large datasets. ++* **Marketing and Personalization:** Generate personalized content and recommendations at scale. ++> [!IMPORTANT] +> We aim to process batch requests within 24 hours; we do not expire the jobs that take longer. You can [cancel](#cancel-batch) the job anytime. When you cancel the job, any remaining work is cancelled and any already completed work is returned. You will be charged for any completed work. +> +> Data stored at rest remains in the designated Azure geography, while data may be processed for inferencing in any Azure OpenAI location. [Learn more about data residency](https://azure.microsoft.com/explore/global-infrastructure/data-residency/).  ++## Global batch support ++### Region and model support ++Global batch is currently supported in the following regions: ++- East US +- West US +- Sweden Central ++The following models support global batch: ++| Model | Version | Supported | +||| +|`gpt-4o` | 2024-05-13 |Yes (text + vision) | +|`gpt-4` | turbo-2024-04-09 | Yes (text only) | +|`gpt-4` | 0613 | Yes | +| `gpt-35-turbo` | 0125 | Yes | +| `gpt-35-turbo` | 1106 | Yes | +| `gpt-35-turbo` | 0613 | Yes | +++Refer to the [models page](../concepts/models.md) for the most up-to-date information on regions/models where global batch is currently supported. ++### API Versions ++- `2024-07-01-preview` ++### Not supported ++The following aren't currently supported: ++- Integration with the Assistants API. +- Integration with Azure OpenAI On Your Data feature. ++### Global batch deployment ++In the Studio UI the deployment type will appear as `Global-Batch`. +++> [!TIP] +> Each line of your input file for batch processing has a `model` attribute that requires a global batch **deployment name**. For a given input file, all names must be the same deployment name. This is different from OpenAI where the concept of model deployments does not exist. ++++++++++++## Batch object ++|Property | Type | Definition| +|||| +| `id` | string | | +| `object` | string| `batch` | +| `endpoint` | string | The API endpoint used by the batch | +| `errors` | object | | +| `input_file_id` | string | The ID of the input file for the batch | +| `completion_window` | string | The time frame within which the batch should be processed | +| `status` | string | The current status of the batch. Possible values: `validating`, `failed`, `in_progress`, `finalizing`, `completed`, `expired`, `cancelling`, `cancelled`. | +| `output_file_id` | string |The ID of the file containing the outputs of successfully executed requests. | +| `error_file_id` | string | The ID of the file containing the outputs of requests with errors. | +| `created_at` | integer | A timestamp when this batch was created (in unix epochs). | +| `in_progress_at` | integer | A timestamp when this batch started progressing (in unix epochs). | +| `expires_at` | integer | A timestamp when this batch will expire (in unix epochs). | +| `finalizing_at` | integer | A timestamp when this batch started finalizing (in unix epochs). | +| `completed_at` | integer | A timestamp when this batch started finalizing (in unix epochs). | +| `failed_at` | integer | A timestamp when this batch failed (in unix epochs) | +| `expired_at` | integer | A timestamp when this batch expired (in unix epochs).| +| `cancelling_at` | integer | A timestamp when this batch started `cancelling` (in unix epochs). | +| `cancelled_at` | integer | A timestamp when this batch was `cancelled` (in unix epochs). | +| `request_counts` | object | Object structure:<br><br> `total` *integer* <br> The total number of requests in the batch. <br>`completed` *integer* <br> The number of requests in the batch that have been completed successfully. <br> `failed` *integer* <br> The number of requests in the batch that have failed. +| `metadata` | map | A set of key-value pairs that can be attached to the batch. This property can be useful for storing additional information about the batch in a structured format. | ++## Frequently asked questions (FAQ) ++### Can images be used with the batch API? ++This capability is limited to certain multi-modal models. Currently only GPT-4o support images as part of batch requests. Images can be provided as input either via [image url or a base64 encoded representation of the image](#input-format). Images for batch are currently not supported with GPT-4 Turbo. ++### Can I use the batch API with fine-tuned models? ++This is currently not supported. ++### Can I use the batch API for embeddings models? ++This is currently not supported. ++### Does content filtering work with Global Batch deployment? ++Yes. Similar to other deployment types, you can create content filters and associate them with the Global Batch deployment type. ++### Can I request additional quota? ++Yes, from the quota page in the Studio UI. Default quota allocation can be found in the [quota and limits article](../quotas-limits.md#global-batch-quota). ++### What happens if the API doesn't complete my request within the 24 hour time frame? ++We aim to process these requests within 24 hours; we don't expire the jobs that take longer. You can cancel the job anytime. When you cancel the job, any remaining work is cancelled and any already completed work is returned. You'll be charged for any completed work. ++### How many requests can I queue using batch? ++There's no fixed limit on the number of requests you can batch, however, it will depend on your enqueued token quota. Your enqueued token quota includes the maximum number of input tokens you can enqueue at one time. ++Once your batch request is completed, your batch rate limit is reset, as your input tokens are cleared. The limit depends on the number of global requests in the queue. If the Batch API queue processes your batches quickly, your batch rate limit is reset more quickly. ++## Troubleshooting ++A job is successful when `status` is `Completed`. Successful jobs will still generate an error_file_id, but it will be associated with an empty file with zero bytes. ++When a job failure occurs, you'll find details about the failure in the `errors` property: ++```json +"value": [ + { + "cancelled_at": null, + "cancelling_at": null, + "completed_at": "2024-06-27T06:50:01.6603753+00:00", + "completion_window": null, + "created_at": "2024-06-27T06:37:07.3746615+00:00", + "error_file_id": "file-f13a58f6-57c7-44d6-8ceb-b89682588072", + "expired_at": null, + "expires_at": "2024-06-28T06:37:07.3163459+00:00", + "failed_at": null, + "finalizing_at": "2024-06-27T06:49:59.1994732+00:00", + "id": "batch_50fa47a0-ef19-43e5-9577-a4679b92faff", + "in_progress_at": "2024-06-27T06:39:57.455977+00:00", + "input_file_id": "file-42147e78ea42488682f4fd1d73028e72", + "errors": { + "object": “list”, + "data": [ + { + “code”: “empty_file”, + “message”: “The input file is empty. Please ensure that the batch contains at least one request.” + } + ] + }, + "metadata": null, + "object": "batch", + "output_file_id": "file-22d970b7-376e-4223-a307-5bb081ea24d7", + "request_counts": { + "total": 10, + "completed": null, + "failed": null + }, + "status": "Failed" + } +``` ++### Error codes ++|Error code | Definition| +||| +|`invalid_json_line`| A line (or multiple) in your input file wasn't able to be parsed as valid json.<br><br> Please ensure no typos, proper opening and closing brackets, and quotes as per JSON standard, and resubmit the request.| +| `too_many_tasks` |The number of requests in the input file exceeds the maximum allowed value of 100,000.<br><br>Please ensure your total requests are under 100,000 and resubmit the job.| +| `url_mismatch` | Either a row in your input file has a URL that doesn’t match the rest of the rows, or the URL specified in the input file doesn’t match the expected endpoint URL. <br><br>Please ensure all request URLs are the same, and that they match the endpoint URL associated with your Azure OpenAI deployment.| +|`model_not_found`|The Azure OpenAI model deployment name that was specified in the `model` property of the input file wasn't found.<br><br> Please ensure this name points to a valid Azure OpenAI model deployment.| +| `duplicate_custom_id` | The custom ID for this request is a duplicate of the custom ID in another request. | +|`empty_batch` | Please check your input file to ensure that the custom ID parameter is unique for each request in the batch.| +|`model_mismatch`| The Azure OpenAI model deployment name that was specified in the `model` property of this request in the input file doesn't match the rest of the file.<br><br>Please ensure that all requests in the batch point to the same AOAI model deployment in the `model` property of the request.| +|`invalid_request`| The schema of the input line is invalid or the deployment SKU is invalid. <br><br>Please ensure the properties of the request in your input file match the expected input properties, and that the Azure OpenAI deployment SKU is `globalbatch` for batch API requests.| ++### Known issues ++- Resources deployed with Azure CLI won't work out-of-box with Azure OpenAI global batch. This is due to an issue where resources deployed using this method have endpoint subdomains that don't follow the `https://your-resource-name.openai.azure.com` pattern. A workaround for this issue is to deploy a new Azure OpenAI resource using one of the other common deployment methods which will properly handle the subdomain setup as part of the deployment process. +++## See also ++* Learn more about Azure OpenAI [deployment types](./deployment-types.md) +* Learn more about Azure OpenAI [quotas and limits](../quotas-limits.md) |
ai-services | Deployment Types | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/ai-services/openai/how-to/deployment-types.md | Our global deployments will be the first location for all new models and feature Azure OpenAI offers three types of deployments. These provide a varied level of capabilities that provide trade-offs on: throughput, SLAs, and price. Below is a summary of the options followed by a deeper description of each. -| **Offering** | **Global-Standard** | **Standard** | **Provisioned** | -||:|:|:| -| **Best suited for** | Applications that don’t require data residency. Recommended starting place for customers. | For customers with data residency requirements. Optimized for low to medium volume. | Real-time scoring for large consistent volume. Includes the highest commitments and limits.| -| **How it works** | Traffic may be routed anywhere in the world | | | -| **Getting started** | [Model deployment](./create-resource.md) | [Model deployment](./create-resource.md) | [Provisioned onboarding](./provisioned-throughput-onboarding.md) | -| **Cost** | [Global deployment pricing](https://azure.microsoft.com/pricing/details/cognitive-services/openai-service/) | [Regional pricing](https://azure.microsoft.com/pricing/details/cognitive-services/openai-service/) | May experience cost savings for consistent usage | -| **What you get** | Easy access to all new models with highest default pay-per-call limits.<br><br> Customers with high volume usage may see higher latency variability | Easy access with [SLA on availability](https://azure.microsoft.com/support/legal/sl#estimate-provisioned-throughput-and-cost) | -| **What you don’t get** |❌Data processing guarantee<br> <br> Data might be processed outside of the resource's Azure geography, but data storage remains in its Azure geography. [Learn more about data residency](https://azure.microsoft.com/explore/global-infrastructure/data-residency/) | ❌High volume w/consistent low latency | ❌Pay-per-call flexibility | -| **Per-call Latency** | Optimized for real-time calling & low to medium volume usage. Customers with high volume usage may see higher latency variability. Threshold set per model | Optimized for real-time calling & low to medium volume usage. Customers with high volume usage may see higher latency variability. Threshold set per model | Optimized for real-time. | -| **Sku Name in code** | `GlobalStandard` | `Standard` | `ProvisionedManaged` | -| **Billing model** | Pay-per-token | Pay-per-token | Monthly Commitments | +| **Offering** | **Global-Batch** | **Global-Standard** | **Standard** | **Provisioned** | +||:|:|:|:| +| **Best suited for** | Offline scoring <br><br> Workloads that are not latency sensitive and can be completed in hours.<br><br> For use cases that do not have data processing residency requirements.| Recommended starting place for customers. <br><br>Global-Standard will have the higher default quota and larger number of models available than Standard. <br><br> For production applications that do not have data processing residency requirements. | For customers with data residency requirements. Optimized for low to medium volume. | Real-time scoring for large consistent volume. Includes the highest commitments and limits.| +| **How it works** | Offline processing via files |Traffic may be routed anywhere in the world | | | +| **Getting started** | [Global-Batch](./batch.md) | [Model deployment](./create-resource.md) | [Model deployment](./create-resource.md) | [Provisioned onboarding](./provisioned-throughput-onboarding.md) | +| **Cost** | [Least expensive option](https://azure.microsoft.com/pricing/details/cognitive-services/openai-service/) <br> 50% less cost compared to Global Standard prices. Access to all new models with larger quota allocations. | [Global deployment pricing](https://azure.microsoft.com/pricing/details/cognitive-services/openai-service/) | [Regional pricing](https://azure.microsoft.com/pricing/details/cognitive-services/openai-service/) | May experience cost savings for consistent usage | +| **What you get** |[Significant discount compared to Global Standard](https://azure.microsoft.com/pricing/details/cognitive-services/openai-service/) | Easy access to all new models with highest default pay-per-call limits.<br><br> Customers with high volume usage may see higher latency variability | Easy access with [SLA on availability](https://azure.microsoft.com/support/legal/sl#estimate-provisioned-throughput-and-cost) | +| **What you don’t get** |❌Real-time call performance <br><br>❌Data processing guarantee<br> <br> Data stored at rest remains in the designated Azure geography, while data may be processed for inferencing in any Azure OpenAI location. [Learn more about data residency](https://azure.microsoft.com/explore/global-infrastructure/data-residency/) |❌Data processing guarantee<br> <br> Data stored at rest remains in the designated Azure geography, while data may be processed for inferencing in any Azure OpenAI location. [Learn more about data residency](https://azure.microsoft.com/explore/global-infrastructure/data-residency/) | ❌High volume w/consistent low latency | ❌Pay-per-call flexibility | +| **Per-call Latency** | Not Applicable (file based async process) | Optimized for real-time calling & low to medium volume usage. Customers with high volume usage may see higher latency variability. Threshold set per model | Optimized for real-time calling & low to medium volume usage. Customers with high volume usage may see higher latency variability. Threshold set per model | Optimized for real-time. | +| **Sku Name in code** | `GlobalBatch` | `GlobalStandard` | `Standard` | `ProvisionedManaged` | +| **Billing model** | Pay-per-token |Pay-per-token | Pay-per-token | Monthly Commitments | ## Provisioned Standard deployments are optimized for low to medium volume workloads with high ## Global standard > [!IMPORTANT]-> Data might be processed outside of the resource's Azure geography, but data storage remains in its Azure geography. [Learn more about data residency](https://azure.microsoft.com/explore/global-infrastructure/data-residency/). +> Data stored at rest remains in the designated Azure geography, while data may be processed for inferencing in any Azure OpenAI location. [Learn more about data residency](https://azure.microsoft.com/explore/global-infrastructure/data-residency/). Global deployments are available in the same Azure OpenAI resources as non-global deployment types but allow you to leverage Azure's global infrastructure to dynamically route traffic to the data center with best availability for each request. Global standard provides the highest default quota and eliminates the need to load balance across multiple resources. Customers with high consistent volume may experience greater latency variability. The threshold is set per model. See the [quotas page to learn more](./quota.md). For applications that require the lower latency variance at large workload usage, we recommend purchasing provisioned throughput. +## Global batch ++> [!IMPORTANT] +> Data stored at rest remains in the designated Azure geography, while data may be processed for inferencing in any Azure OpenAI location. [Learn more about data residency](https://azure.microsoft.com/explore/global-infrastructure/data-residency/). ++[Global batch](./batch.md) is designed to handle large-scale and high-volume processing tasks efficiently. Process asynchronous groups of requests with separate quota, with 24-hour target turnaround, at [50% less cost than global standard](https://azure.microsoft.com/pricing/details/cognitive-services/openai-service/). With batch processing, rather than send one request at a time you send a large number of requests in a single file. Global batch requests have a separate enqueued token quota avoiding any disruption of your online workloads. ++Key use cases include: ++* **Large-Scale Data Processing:** Quickly analyze extensive datasets in parallel. ++* **Content Generation:** Create large volumes of text, such as product descriptions or articles. ++* **Document Review and Summarization:** Automate the review and summarization of lengthy documents. ++* **Customer Support Automation:** Handle numerous queries simultaneously for faster responses. ++* **Data Extraction and Analysis:** Extract and analyze information from vast amounts of unstructured data. ++* **Natural Language Processing (NLP) Tasks:** Perform tasks like sentiment analysis or translation on large datasets. ++* **Marketing and Personalization:** Generate personalized content and recommendations at scale. + ### How to disable access to global deployments in your subscription Azure Policy helps to enforce organizational standards and to assess compliance at-scale. Through its compliance dashboard, it provides an aggregated view to evaluate the overall state of the environment, with the ability to drill down to the per-resource, per-policy granularity. It also helps to bring your resources to compliance through bulk remediation for existing resources and automatic remediation for new resources. [Learn more about Azure Policy and specific built-in controls for AI services](/azure/ai-services/security-controls-policy). You can use the following policy to disable access to Azure OpenAI global standa To learn about creating resources and deploying models refer to the [resource creation guide](./create-resource.md). +## Retrieve batch job output file +++ ## See also - [Quotas & limits](./quota.md) |
ai-services | Fine Tuning | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/ai-services/openai/how-to/fine-tuning.md | |
ai-services | Quotas Limits | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/ai-services/openai/quotas-limits.md | The following sections provide you with a quick guide to the default quotas and [!INCLUDE [Quota](./includes/model-matrix/quota.md)] + ## gpt-4o rate limits `gpt-4o` and `gpt-4o-mini` have rate limit tiers with higher limits for certain customer types. |
ai-services | Whats New | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/ai-services/openai/whats-new.md | recommendations: false This article provides a summary of the latest releases and major documentation updates for Azure OpenAI. +## August 2024 ++### Global batch deployments are now available ++The Azure OpenAI Batch API is designed to handle large-scale and high-volume processing tasks efficiently. Process asynchronous groups of requests with separate quota, with 24-hour target turnaround, at [50% less cost than global standard](https://azure.microsoft.com/pricing/details/cognitive-services/openai-service/). With batch processing, rather than send one request at a time you send a large number of requests in a single file. Global batch requests have a separate enqueued token quota avoiding any disruption of your online workloads. ++Key use cases include: ++* **Large-Scale Data Processing:** Quickly analyze extensive datasets in parallel. ++* **Content Generation:** Create large volumes of text, such as product descriptions or articles. ++* **Document Review and Summarization:** Automate the review and summarization of lengthy documents. ++* **Customer Support Automation:** Handle numerous queries simultaneously for faster responses. ++* **Data Extraction and Analysis:** Extract and analyze information from vast amounts of unstructured data. ++* **Natural Language Processing (NLP) Tasks:** Perform tasks like sentiment analysis or translation on large datasets. ++* **Marketing and Personalization:** Generate personalized content and recommendations at scale. ++For more information on [getting started with global batch deployments](./how-to/batch.md). + ## July 2024 +### GPT-4o mini is now available for fine-tuning ++GPT-4o mini fine-tuning is [now available in public preview](./concepts/models.md#fine-tuning-models) in Sweden Central and in North Central US. + ### Assistants File Search tool is now billed The [file search](./how-to/file-search.md) tool for Assistants now has additional charges for usage. See the [pricing page](https://azure.microsoft.com/pricing/details/cognitive-services/openai-service/) for more information. |
ai-studio | Concept Synthetic Data | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/ai-studio/concepts/concept-synthetic-data.md | -In this article - - [Synthetic data generation](#synthetic-data-generation) - - [Next Steps](#next-steps) +In Azure AI Studio, you can use synthetic data generation to efficiently produce predictions for your datasets. In this article, you're introduced to the concept of synthetic data generation and how it can be used in machine learning. -In Azure AI Studio, you can leverage synthetic data generation to efficiently produce predictions for your datasets. ## Synthetic data generation Synthetic data generation involves creating artificial data that mimics the statistical properties of real-world data. This data is generated using algorithms and machine learning techniques, and it can be used in various ways, such as computer simulations or by modeling real-world events. -In machine learning, synthetic data is particularly valuable for several reasons: +In machine learning, synthetic data is valuable for several reasons: **Data Augmentation:** It helps in expanding the size of training datasets, which is crucial for training robust machine learning models. This is especially useful when real-world data is scarce or expensive to obtain. You can use the sample notebook available at this [link](https://aka.ms/meta-lla - [What is Azure AI Studio?](../what-is-ai-studio.md) - [Learn more about deploying Meta Llama models](../how-to/deploy-models-llama.md) -- [Azure AI FAQ article](../faq.yml)+- [Azure AI FAQ article](../faq.yml) |
ai-studio | Deploy Models Serverless Availability | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/ai-studio/how-to/deploy-models-serverless-availability.md | Title: Region availability for models in Serverless API endpoints -description: Learn about the regions where each model is available for deployment in serverless API endpoints. +description: Learn about the regions where each model is available for deployment in serverless API endpoints via Azure AI Studio. -# Region availability for models in serverless API endpoints | Azure AI Studio +# Region availability for models in serverless API endpoints In this article, you learn about which regions are available for each of the models supporting serverless API endpoint deployments. |
analysis-services | Analysis Services Async Refresh | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/analysis-services/analysis-services-async-refresh.md | https://westus.asazure.windows.net/servers/myserver/models/AdventureWorks/refres All calls must be authenticated with a valid Microsoft Entra ID (OAuth 2) token in the Authorization header and must meet the following requirements: - The token must be either a user token or an application service principal.-- The token must have the audience set to exactly `https://*.asazure.windows.net`. Note that `*` isn't a placeholder or a wildcard, and the audience must have the `*` character as the subdomain. Specifying an invalid audience results in authentication failure.+- The token must have the audience set to exactly `https://*.asazure.windows.net`. Note that `*` isn't a placeholder or a wildcard, and the audience must have the `*` character as the subdomain. Custom audiences, such as https://customersubdomain.asazure.windows.net, are not supported. Specifying an invalid audience results in authentication failure. - The user or application must have sufficient permissions on the server or model to make the requested call. The permission level is determined by roles within the model or the admin group on the server. > [!IMPORTANT] |
analysis-services | Analysis Services Logging | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/analysis-services/analysis-services-logging.md | This article describes how to set up, view, and manage [Azure Monitor resource l You can select **Engine**, **Service**, and **Metrics** log categories. For a listing of what's logged for each category, see [Supported resource logs for Microsoft.AnalysisServices/servers](monitor-analysis-services-reference.md#supported-resource-logs-for-microsoftanalysisservicesservers). -## Set up diagnostics logging +## Set up diagnostic settings -### Azure portal --1. In [Azure portal](https://portal.azure.com) > server, click **Diagnostic settings** in the left navigation, and then click **Turn on diagnostics**. -- ![Screenshot showing Turn on diagnostics in the Azure portal.](./media/analysis-services-logging/aas-logging-turn-on-diagnostics.png) --2. In **Diagnostic settings**, specify the following options: -- * **Name**. Enter a name for the logs to create. -- * **Archive to a storage account**. To use this option, you need an existing storage account to connect to. See [Create a storage account](/azure/storage/common/storage-account-create). Follow the instructions to create a Resource Manager, general-purpose account, then select your storage account by returning to this page in the portal. It may take a few minutes for newly created storage accounts to appear in the drop-down menu. - * **Stream to an event hub**. To use this option, you need an existing Event Hub namespace and event hub to connect to. To learn more, see [Create an Event Hubs namespace and an event hub using the Azure portal](/azure/event-hubs/event-hubs-create). Then return to this page in the portal to select the Event Hub namespace and policy name. - * **Send to Azure Monitor (Log Analytics workspace)**. To use this option, either use an existing workspace or [create a new workspace](/azure/azure-monitor/logs/quick-create-workspace) resource in the portal. For more information on viewing your logs, see [View logs in Log Analytics workspace](#view-logs-in-log-analytics-workspace) in this article. -- * **Engine**. Select this option to log xEvents. If you're archiving to a storage account, you can select the retention period for the resource logs. Logs are autodeleted after the retention period expires. - * **Service**. Select this option to log service level events. If you are archiving to a storage account, you can select the retention period for the resource logs. Logs are autodeleted after the retention period expires. - * **Metrics**. Select this option to store verbose data in [Metrics](analysis-services-monitor.md#server-metrics). If you are archiving to a storage account, you can select the retention period for the resource logs. Logs are autodeleted after the retention period expires. --3. Click **Save**. -- If you receive an error that says "Failed to update diagnostics for \<workspace name>. The subscription \<subscription id> is not registered to use microsoft.insights." follow the [Troubleshoot Azure Diagnostics](../azure-monitor/essentials/resource-logs.md) instructions to register the account, then retry this procedure. -- If you want to change how your resource logs are saved at any point in the future, you can return to this page to modify settings. --### PowerShell --Here are the basic commands to get you going. If you want step-by-step help on setting up logging to a storage account by using PowerShell, see the tutorial later in this article. --To enable metrics and resource logging by using PowerShell, use the following commands: --- To enable storage of resource logs in a storage account, use this command:-- ```powershell - Set-AzDiagnosticSetting -ResourceId [your resource id] -StorageAccountId [your storage account id] -Enabled $true - ``` -- The storage account ID is the resource ID for the storage account where you want to send the logs. --- To enable streaming of resource logs to an event hub, use this command:-- ```powershell - Set-AzDiagnosticSetting -ResourceId [your resource id] -ServiceBusRuleId [your service bus rule id] -Enabled $true - ``` -- The Azure Service Bus rule ID is a string with this format: -- ```powershell - {service bus resource ID}/authorizationrules/{key name} - ``` --- To enable sending resource logs to a Log Analytics workspace, use this command:-- ```powershell - Set-AzDiagnosticSetting -ResourceId [your resource id] -WorkspaceId [resource id of the log analytics workspace] -Enabled $true - ``` --- You can obtain the resource ID of your Log Analytics workspace by using the following command:-- ```powershell - (Get-AzOperationalInsightsWorkspace).ResourceId - ``` --You can combine these parameters to enable multiple output options. --### REST API --Learn how to [change diagnostics settings by using the Azure Monitor REST API](/rest/api/monitor/). --### Resource Manager template --Learn how to [enable diagnostics settings at resource creation by using a Resource Manager template](../azure-monitor/essentials/resource-manager-diagnostic-settings.md). +To learn how to set up diagnostic settings using the Azure portal, Azure CLI, PowerShell, or Azure Resource Manager, see [Create diagnostic settings in Azure Monitor](/azure/azure-monitor/essentials/create-diagnostic-settings). ## Manage your logs |
analysis-services | Monitor Analysis Services Reference | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/analysis-services/monitor-analysis-services-reference.md | See [Monitor Azure Analysis Services](monitor-analysis-services.md) for details ### Supported metrics for Microsoft.AnalysisServices/servers The following table lists the metrics available for the Microsoft.AnalysisServices/servers resource type. [!INCLUDE [horz-monitor-ref-metrics-tableheader](~/reusable-content/ce-skilling/azure/includes/azure-monitor/horizontals/horz-monitor-ref-metrics-tableheader.md)] [!INCLUDE [horz-monitor-ref-metrics-dimensions-intro](~/reusable-content/ce-skilling/azure/includes/azure-monitor/horizontals/horz-monitor-ref-metrics-dimensions-intro.md)] [!INCLUDE [horz-monitor-ref-metrics-dimensions](~/reusable-content/ce-skilling/azure/includes/azure-monitor/horizontals/horz-monitor-ref-metrics-dimensions.md)] Analysis Services metrics have the dimension `ServerResourceType`. [!INCLUDE [horz-monitor-ref-resource-logs](~/reusable-content/ce-skilling/azure/includes/azure-monitor/horizontals/horz-monitor-ref-resource-logs.md)] ### Supported resource logs for Microsoft.AnalysisServices/servers When you set up logging for Analysis Services, you can select **Engine** or **Service** events to log. |
analysis-services | Monitor Analysis Services | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/analysis-services/monitor-analysis-services.md | For a list of available metrics for Analysis Services, see [Analysis Services mo [!INCLUDE [horz-monitor-resource-logs](~/reusable-content/ce-skilling/azure/includes/azure-monitor/horizontals/horz-monitor-resource-logs.md)] - For the available resource log categories, associated Log Analytics tables, and the logs schemas for Analysis Services, see [Analysis Services monitoring data reference](monitor-analysis-services-reference.md#resource-logs).+ ## Analysis Services resource logs +To learn how to set up diagnostics logging, see [Set up diagnostic logging](analysis-services-logging.md). + When you set up logging for Analysis Services, you can select **Engine** or **Service** events to log, or select **AllMetrics** to log metrics data. For more information, see [Supported resource logs for Microsoft.AnalysisServices/servers](monitor-analysis-services-reference.md#supported-resource-logs-for-microsoftanalysisservicesservers). [!INCLUDE [horz-monitor-activity-log](~/reusable-content/ce-skilling/azure/includes/azure-monitor/horizontals/horz-monitor-activity-log.md)] |
api-center | Use Vscode Extension | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-center/use-vscode-extension.md | description: Build, discover, try, and consume APIs from your Azure API center u Previously updated : 07/15/2024 Last updated : 08/01/2024 # Customer intent: As a developer, I want to use my Visual Studio Code environment to build, discover, try, and consume APIs in my organization's API center. To build, discover, try, and consume APIs in your [API center](overview.md), you * [Visual Studio Code](https://code.visualstudio.com/) * [Azure API Center extension for Visual Studio Code](https://marketplace.visualstudio.com/items?itemName=apidev.azure-api-center)++ > [!NOTE] + > Where noted, certain features are available only in the extension's pre-release version. When installing the extension from the [Visual Studio Code Marketplace](https://marketplace.visualstudio.com/items?itemName=apidev.azure-api-center&ssr=false#overview), you can choose to install the release version or a pre-release version. Switch between the two versions at any time by using the extension's **Manage** button context menu in the Extensions view. The following Visual Studio Code extensions are optional and needed only for certain scenarios as indicated: Visual Studio Code will open a diff view between the two API specifications. Any ## Generate OpenAPI specification file from API code -Use the power of GitHub Copilot with the Azure API Center extension for Visual Studio Code to create an OpenAPI specification file from your API code. Right click on the API code, select **Copilot** from the options, and select **Generate API documentation**. This will create an OpenAPI specification file. +Use the power of GitHub Copilot with the Azure API Center extension for Visual Studio Code to create an OpenAPI specification file from your API code. Right-click on the API code, select **Copilot** from the options, and select **Generate API documentation**. This will create an OpenAPI specification file. ++> [!NOTE] +> This feature is available in the pre-release version of the API Center extension. :::image type="content" source="media/use-vscode-extension/generate-api-documentation.gif" alt-text="Animation showing how to use GitHub Copilot to generate an OpenAPI spec from code." lightbox="media/use-vscode-extension/generate-api-documentation.gif"::: You can view the documentation for an API definition in your API center and try > Depending on the API, you might need to provide authorization credentials or an API key to try the API. > [!TIP]- > You can also use the extension to generate API documentation in Markdown, a format that's easy to maintain and share with end users. Right-click on the definition, and select **Generate Markdown**. + > Using the pre-release version of the extension, you can generate API documentation in Markdown, a format that's easy to maintain and share with end users. Right-click on the definition, and select **Generate Markdown**. ## Generate HTTP file |
api-management | Api Management Capacity | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-capacity.md | |
api-management | Api Management Gateways Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-gateways-overview.md | The API Management *gateway* (also called *data plane* or *runtime*) is the serv API Management offers both managed and self-hosted gateways: -* **Managed** - The managed gateway is the default gateway component that is deployed in Azure for every API Management instance in every service tier. With the managed gateway, all API traffic flows through Azure regardless of where backends implementing the APIs are hosted. +* **Managed** - The managed gateway is the default gateway component that is deployed in Azure for every API Management instance in every service tier. A standalone managed gateway can also be associated with a [workspace](workspaces-overview.md) in an API Management instance. With the managed gateway, all API traffic flows through Azure regardless of where backends implementing the APIs are hosted. > [!NOTE] > Because of differences in the underlying service architecture, the gateways provided in the different API Management service tiers have some differences in capabilities. For details, see the section [Feature comparison: Managed versus self-hosted gateways](#feature-comparison-managed-versus-self-hosted-gateways). The following tables compare features available in the following API Management * **V2** - the managed gateway available in the Basic v2 and Standard v2 tiers * **Consumption** - the managed gateway available in the Consumption tier * **Self-hosted** - the optional self-hosted gateway available in select service tiers+* **Workspace** - the managed gateway available in a [workspace](workspaces-overview.md) in select service tiers > [!NOTE] > * Some features of managed and self-hosted gateways are supported only in certain [service tiers](api-management-features.md) or with certain [deployment environments](self-hosted-gateway-overview.md#packaging) for self-hosted gateways. The following tables compare features available in the following API Management ### Infrastructure -| Feature support | Classic | V2 | Consumption | Self-hosted | +| Feature support | Classic | V2 | Consumption | Self-hosted | Workspace | | | | -- | -- | - |-| [Custom domains](configure-custom-domain.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| [Built-in cache](api-management-howto-cache.md) | ✔️ | ✔️ | ❌ | ❌ | -| [External Redis-compatible cache](api-management-howto-cache-external.md) | ✔️ | ✔️ |✔️ | ✔️ | -| [Virtual network injection](virtual-network-concepts.md) | Developer, Premium | ❌ | ❌ | ✔️<sup>1,2</sup> | -| [Inbound private endpoints](private-endpoint.md) | Developer, Basic, Standard, Premium | ❌ | ❌ | ❌ | -| [Outbound virtual network integration](integrate-vnet-outbound.md) | ❌ | Standard V2 | ❌ | ❌ | -| [Availability zones](zone-redundancy.md) | Premium | ❌ | ❌ | ✔️<sup>1</sup> | -| [Multi-region deployment](api-management-howto-deploy-multi-region.md) | Premium | ❌ | ❌ | ✔️<sup>1</sup> | -| [CA root certificates](api-management-howto-ca-certificates.md) for certificate validation | ✔️ | ✔️ | ❌ | ✔️<sup>3</sup> | -| [Managed domain certificates](configure-custom-domain.md?tabs=managed#domain-certificate-options) | Developer, Basic, Standard, Premium | ❌ | ✔️ | ❌ | -| [TLS settings](api-management-howto-manage-protocols-ciphers.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| **HTTP/2** (Client-to-gateway) | ✔️<sup>4</sup> | ✔️<sup>4</sup> |❌ | ✔️ | -| **HTTP/2** (Gateway-to-backend) | ❌ | ❌ | ❌ | ✔️ | -| API threat detection with [Defender for APIs](protect-with-defender-for-apis.md) | ✔️ | ✔️ | ❌ | ❌ | +| [Custom domains](configure-custom-domain.md) | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | +| [Built-in cache](api-management-howto-cache.md) | ✔️ | ✔️ | ❌ | ❌ | ✔️ | +| [External Redis-compatible cache](api-management-howto-cache-external.md) | ✔️ | ✔️ |✔️ | ✔️ | ❌ | +| [Virtual network injection](virtual-network-concepts.md) | Developer, Premium | ❌ | ❌ | ✔️<sup>1,2</sup> | ✔️ | +| [Inbound private endpoints](private-endpoint.md) | Developer, Basic, Standard, Premium | ❌ | ❌ | ❌ | ❌ | +| [Outbound virtual network integration](integrate-vnet-outbound.md) | ❌ | Standard V2 | ❌ | ❌ | ✔️ | +| [Availability zones](zone-redundancy.md) | Premium | ✔️<sup>3</sup> | ❌ | ✔️<sup>1</sup> | ✔️<sup>3</sup> | +| [Multi-region deployment](api-management-howto-deploy-multi-region.md) | Premium | ❌ | ❌ | ✔️<sup>1</sup> | ❌ | +| [CA root certificates](api-management-howto-ca-certificates.md) for certificate validation | ✔️ | ✔️ | ❌ | ✔️<sup>4</sup> | ❌ | +| [Managed domain certificates](configure-custom-domain.md?tabs=managed#domain-certificate-options) | Developer, Basic, Standard, Premium | ❌ | ✔️ | ❌ | ❌ | +| [TLS settings](api-management-howto-manage-protocols-ciphers.md) | ✔️ | ✔️ | ✔️ | ✔️ | ❌ | +| **HTTP/2** (Client-to-gateway) | ✔️<sup>5</sup> | ✔️<sup>5</sup> |❌ | ✔️ | ❌ | +| **HTTP/2** (Gateway-to-backend) | ❌ | ❌ | ❌ | ✔️ | ❌ | +| API threat detection with [Defender for APIs](protect-with-defender-for-apis.md) | ✔️ | ✔️ | ❌ | ❌ | ❌ | <sup>1</sup> Depends on how the gateway is deployed, but is the responsibility of the customer.<br/> <sup>2</sup> Connectivity to the self-hosted gateway v2 [configuration endpoint](self-hosted-gateway-overview.md#fqdn-dependencies) requires DNS resolution of the endpoint hostname.<br/>-<sup>3</sup>CA root certificates for self-hosted gateway are managed separately per gateway<br/> -<sup>4</sup> Client protocol needs to be enabled. +<sup>3</sup> Two zones are enabled by default; not configurable.<br/> +<sup>4</sup> CA root certificates for self-hosted gateway are managed separately per gateway<br/> +<sup>5</sup> Client protocol needs to be enabled. ### Backend APIs -| Feature support | Classic | V2 | Consumption | Self-hosted | -| | | -- | -- | - | -| [OpenAPI specification](import-api-from-oas.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| [WSDL specification](import-soap-api.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| WADL specification | ✔️ | ✔️ | ✔️ | ✔️ | -| [Logic App](import-logic-app-as-api.md) | ✔️ | ✔️ | ✔️ |✔️ | -| [App Service](import-app-service-as-api.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| [Function App](import-function-app-as-api.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| [Container App](import-container-app-with-oas.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| [Service Fabric](../service-fabric/service-fabric-api-management-overview.md) | Developer, Premium | ❌ |❌ | ❌ | -| [Pass-through GraphQL](graphql-apis-overview.md) | ✔️ | ✔️ |✔️ | ✔️ | -| [Synthetic GraphQL](graphql-apis-overview.md)| ✔️ | ✔️ | ✔️<sup>1</sup> | ✔️<sup>1</sup> | -| [Pass-through WebSocket](websocket-api.md) | ✔️ | ✔️ | ❌ | ✔️ | -| [Pass-through gRPC](grpc-api.md) | ❌ | ❌ | ❌ | ✔️ | -| [OData](import-api-from-odata.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| [Azure OpenAI](azure-openai-api-from-specification.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| [Circuit breaker in backend](backends.md#circuit-breaker) | ✔️ | ✔️ | ❌ | ✔️ | -| [Load-balanced backend pool](backends.md#load-balanced-pool) | ✔️ | ✔️ | ✔️ | ✔️ | +| Feature support | Classic | V2 | Consumption | Self-hosted | Workspace | +| | | -- | -- | - | -- | +| [OpenAPI specification](import-api-from-oas.md) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | +| [WSDL specification](import-soap-api.md) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | +| WADL specification | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | +| [Logic App](import-logic-app-as-api.md) | ✔️ | ✔️ | ✔️ |✔️ | ✔️ | +| [App Service](import-app-service-as-api.md) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | +| [Function App](import-function-app-as-api.md) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | +| [Container App](import-container-app-with-oas.md) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | +| [Service Fabric](../service-fabric/service-fabric-api-management-overview.md) | Developer, Premium | ❌ |❌ | ❌ | ❌ | +| [Pass-through GraphQL](graphql-apis-overview.md) | ✔️ | ✔️ |✔️ | ✔️ | ✔️ | +| [Synthetic GraphQL](graphql-apis-overview.md)| ✔️ | ✔️ | ✔️<sup>1</sup> | ✔️<sup>1</sup> | ❌ | +| [Pass-through WebSocket](websocket-api.md) | ✔️ | ✔️ | ❌ | ✔️ | ❌ | +| [Pass-through gRPC](grpc-api.md) | ❌ | ❌ | ❌ | ✔️ | ❌ | +| [OData](import-api-from-odata.md) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | +| [Azure OpenAI](azure-openai-api-from-specification.md) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | +| [Circuit breaker in backend](backends.md#circuit-breaker) | ✔️ | ✔️ | ❌ | ✔️ | ✔️ | +| [Load-balanced backend pool](backends.md#load-balanced-pool) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | <sup>1</sup> Synthetic GraphQL subscriptions (preview) aren't supported. The following tables compare features available in the following API Management Managed and self-hosted gateways support all available [policies](api-management-policies.md) in policy definitions with the following exceptions. -| Feature support | Classic | V2 | Consumption | Self-hosted<sup>1</sup> | -| | | -- | -- | - | -| [Dapr integration](api-management-policies.md#integration-and-external-communication) | ❌ | ❌ |❌ | ✔️ | -| [GraphQL resolvers](api-management-policies.md#graphql-resolvers) and [GraphQL validation](api-management-policies.md#content-validation)| ✔️ | ✔️ |✔️ | ❌ | -| [Get authorization context](get-authorization-context-policy.md) | ✔️ | ✔️ |✔️ | ❌ | -| [Quota and rate limit](api-management-policies.md#rate-limiting-and-quotas) | ✔️ | ✔️<sup>2</sup> | ✔️<sup>3</sup> | ✔️<sup>4</sup> | +| Feature support | Classic | V2 | Consumption | Self-hosted<sup>1</sup> | Workspace | +| | | -- | -- | - | -- | +| [Dapr integration](api-management-policies.md#integration-and-external-communication) | ❌ | ❌ |❌ | ✔️ | ❌ | +| [GraphQL resolvers](api-management-policies.md#graphql-resolvers) and [GraphQL validation](api-management-policies.md#content-validation)| ✔️ | ✔️ |✔️ | ❌ | ❌ | +| [Get authorization context](get-authorization-context-policy.md) | ✔️ | ✔️ |✔️ | ❌ | ❌ | +| [Quota and rate limit](api-management-policies.md#rate-limiting-and-quotas) | ✔️ | ✔️<sup>2</sup> | ✔️<sup>3</sup> | ✔️<sup>4</sup> | ✔️ | <sup>1</sup> Configured policies that aren't supported by the self-hosted gateway are skipped during policy execution.<br/> <sup>2</sup> The quota by key policy isn't available in the v2 tiers.<br/> Managed and self-hosted gateways support all available [policies](api-management For details about monitoring options, see [Observability in Azure API Management](observability.md). -| Feature support | Classic | V2 | Consumption | Self-hosted | -| | | -- | -- | - | -| [API analytics](howto-use-analytics.md) | ✔️ | ✔️<sup>1</sup> | ❌ | ❌ | -| [Application Insights](api-management-howto-app-insights.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| [Logging through Event Hubs](api-management-howto-log-event-hubs.md) | ✔️ | ✔️ | ✔️ | ✔️ | -| [Metrics in Azure Monitor](api-management-howto-use-azure-monitor.md#view-metrics-of-your-apis) | ✔️ | ✔️ |✔️ | ✔️ | -| [OpenTelemetry Collector](how-to-deploy-self-hosted-gateway-kubernetes-opentelemetry.md) | ❌ | ❌ | ❌ | ✔️ | -| [Request logs in Azure Monitor and Log Analytics](api-management-howto-use-azure-monitor.md#resource-logs) | ✔️ | ✔️ | ❌ | ❌<sup>2</sup> | -| [Local metrics and logs](how-to-configure-local-metrics-logs.md) | ❌ | ❌ | ❌ | ✔️ | -| [Request tracing](api-management-howto-api-inspector.md) | ✔️ | ❌<sup>3</sup> | ✔️ | ✔️ | +| Feature support | Classic | V2 | Consumption | Self-hosted | Workspace | +| | | -- | -- | - | -- | +| [API analytics](howto-use-analytics.md) | ✔️ | ✔️<sup>1</sup> | ❌ | ❌ | ❌ | +| [Application Insights](api-management-howto-app-insights.md) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | +| [Logging through Event Hubs](api-management-howto-log-event-hubs.md) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | +| [Metrics in Azure Monitor](api-management-howto-use-azure-monitor.md#view-metrics-of-your-apis) | ✔️ | ✔️ |✔️ | ✔️ | ❌ | +| [OpenTelemetry Collector](how-to-deploy-self-hosted-gateway-kubernetes-opentelemetry.md) | ❌ | ❌ | ❌ | ✔️ | ❌ | +| [Request logs in Azure Monitor and Log Analytics](api-management-howto-use-azure-monitor.md#resource-logs) | ✔️ | ✔️ | ❌ | ❌<sup>2</sup> | ❌ | +| [Local metrics and logs](how-to-configure-local-metrics-logs.md) | ❌ | ❌ | ❌ | ✔️ | ❌ | +| [Request tracing](api-management-howto-api-inspector.md) | ✔️ | ❌<sup>3</sup> | ✔️ | ✔️ | ❌ | <sup>1</sup> The v2 tiers support Azure Monitor-based analytics.<br/> <sup>2</sup> The self-hosted gateway currently doesn't send resource logs (diagnostic logs) to Azure Monitor. Optionally [send metrics](how-to-configure-cloud-metrics-logs.md) to Azure Monitor, or [configure and persist logs locally](how-to-configure-local-metrics-logs.md) where the self-hosted gateway is deployed.<br/> For details about monitoring options, see [Observability in Azure API Management Managed and self-hosted gateways support all available [API authentication and authorization options](authentication-authorization-overview.md) with the following exceptions. -| Feature support | Classic | V2 | Consumption | Self-hosted | -| | | -- | -- | - | -| [Credential manager](credentials-overview.md) | ✔️ | ✔️ | ✔️ | ❌ | +| Feature support | Classic | V2 | Consumption | Self-hosted | Workspace | +| | | -- | -- | - | -- | +| [Credential manager](credentials-overview.md) | ✔️ | ✔️ | ✔️ | ❌ | ❌ | ## Gateway throughput and scaling For estimated maximum gateway throughput in the API Management service tiers, se * In environments such as [Kubernetes](how-to-self-hosted-gateway-on-kubernetes-in-production.md), add multiple gateway replicas to handle expected usage. * Optionally [configure autoscaling](how-to-self-hosted-gateway-on-kubernetes-in-production.md#autoscaling) to meet traffic demands. +### Workspace gateway ++Scale capacity by adding and removing scale [units](upgrade-and-scale.md) in the workspace gateway. + ## Related content - Learn more about [API Management in a Hybrid and multicloud World](https://aka.ms/hybrid-and-multi-cloud-api-management) |
api-management | Api Management Howto App Insights | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-howto-app-insights.md | You can easily integrate Azure Application Insights with Azure API Management. A * Walk through Application Insights integration into API Management. * Learn strategies for reducing performance impact on your API Management service instance. +> [!NOTE] +> In an API Management [workspace](workspaces-overview.md), a workspace owner can independently integrate Application Insights and enable Application Insights logging for the workspace's APIs. The general guidance to integrate a workspace with Application Insights is similar to the guidance for an API Management instance; however, configuration is scoped to the workspace only. Currently, you must integrate Application Insights in a workspace by configuring an instrumentation key or connection string. + ## Prerequisites * You need an Azure API Management instance. [Create one](get-started-create-service-instance.md) first. The following are high level steps for this scenario. You can create a connection between Application Insights and your API Management using the Azure portal, the REST API, or related Azure tools. API Management configures a *logger* resource for the connection. > [!NOTE]- > If your Application Insights resource is in a different tenant, then you must create the logger using the [REST API](/rest/api/apimanagement/current-ga/logger/create-or-update). + > If your Application Insights resource is in a different tenant, then you must create the logger using the [REST API](#create-a-connection-using-the-rest-api-bicep-or-arm-template) as shown in a later section of this article. > [!IMPORTANT] > Currently, in the portal, API Management only supports connections to Application Insights using an Application Insights instrumentation key. To use an Application Insights connection string or an API Management managed identity, use the REST API, Bicep, or ARM template to create the logger. [Learn more](../azure-monitor/app/sdk-connection-string.md) about Application Insights connection strings. The Application Insights connection string appears in the **Overview** section o #### [REST API](#tab/rest) -Use the API Management [REST API](/rest/api/apimanagement/current-preview/logger/create-or-update) with the following request body. +Use the API Management [Logger - Create or Update](/rest/api/apimanagement/current-preview/logger/create-or-update) REST API with the following request body. ++If you are configuring the logger for a workspace, use the [Workspace Logger - Create or Update](/rest/api/apimanagement/workspace-logger/create-or-update?view=rest-apimanagement-2023-09-01-preview&preserve-view=true) REST API. ```JSON { See the [prerequisites](#prerequisites) for using an API Management managed iden #### [REST API](#tab/rest) -Use the API Management [REST API](/rest/api/apimanagement/current-preview/logger/create-or-update) with the following request body. +Use the API Management [Logger - Create or Update](/rest/api/apimanagement/current-preview/logger/create-or-update) REST API with the following request body. ```JSON { See the [prerequisites](#prerequisites) for using an API Management managed iden #### [REST API](#tab/rest) -Use the API Management [REST API](/rest/api/apimanagement/current-preview/logger/create-or-update) with the following request body. +Use the API Management [Logger - Create or Update](/rest/api/apimanagement/current-preview/logger/create-or-update) REST API with the following request body. ```JSON { To improve performance issues, skip: Addressing the issue of telemetry data flow from API Management to Application Insights: + Investigate whether a linked Azure Monitor Private Link Scope (AMPLS) resource exists within the VNet where the API Management resource is connected. AMPLS resources have a global scope across subscriptions and are responsible for managing data query and ingestion for all Azure Monitor resources. It's possible that the AMPLS has been configured with a Private-Only access mode specifically for data ingestion. In such instances, include the Application Insights resource and its associated Log Analytics resource in the AMPLS. Once this addition is made, the API Management data will be successfully ingested into the Application Insights resource, resolving the telemetry data transmission issue. -## Next steps +## Related content + Learn more about [Azure Application Insights](../azure-monitor/app/app-insights-overview.md). + Consider [logging with Azure Event Hubs](api-management-howto-log-event-hubs.md). |
api-management | Api Management Howto Autoscale | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-howto-autoscale.md | The article walks through the process of configuring autoscale and suggests opti > [!NOTE] > * In service tiers that support multiple scale units, you can also [manually scale](upgrade-and-scale.md) your API Management instance. > * An API Management service in the **Consumption** tier scales automatically based on the traffic - without any additional configuration needed.+> * Currently, autoscale is not supported for the [workspace gateway](workspaces-overview.md#workspace-gateway) in API Management workspaces. ## Prerequisites |
api-management | Api Management Howto Ca Certificates | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-howto-ca-certificates.md | The article shows how to manage CA certificates of an Azure API Management servi CA certificates uploaded to API Management can only be used for certificate validation by the managed API Management gateway. If you use the [self-hosted gateway](self-hosted-gateway-overview.md), learn how to [create a custom CA for self-hosted gateway](#create-custom-ca-for-self-hosted-gateway), later in this article. + [!INCLUDE [updated-for-az](~/reusable-content/ce-skilling/azure/includes/updated-for-az.md)] |
api-management | Api Management Howto Cache External | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-howto-cache-external.md | Using an external cache allows you to overcome a few limitations of the built-in For more detailed information about caching, see [API Management caching policies](api-management-policies.md#caching) and [Custom caching in Azure API Management](api-management-sample-cache-by-key.md). + ![Bring your own cache to APIM](media/api-management-howto-cache-external/overview.png) What you'll learn: |
api-management | Api Management Howto Log Event Hubs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-howto-log-event-hubs.md | This article describes how to log API Management events using Azure Event Hubs. Azure Event Hubs is a highly scalable data ingress service that can ingest millions of events per second so that you can process and analyze the massive amounts of data produced by your connected devices and applications. Event Hubs acts as the "front door" for an event pipeline, and once data is collected into an event hub, it can be transformed and stored using any real-time analytics provider or batching/storage adapters. Event Hubs decouples the production of a stream of events from the consumption of those events, so that event consumers can access the events on their own schedule. + ## Prerequisites * An API Management service instance. If you don't have one, see [Create an API Management service instance](get-started-create-service-instance.md). |
api-management | Api Management Howto Manage Protocols Ciphers | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-howto-manage-protocols-ciphers.md | By default, API Management enables TLS 1.2 for client and backend connectivity a > [!NOTE] > * If you're using the self-hosted gateway, see [self-hosted gateway security](self-hosted-gateway-overview.md#security) to manage TLS protocols and cipher suites. > * The following tiers don't support changes to the default cipher configuration: **Consumption**, **Basic v2**, **Standard v2**. +> * In [workspaces](workspaces-overview.md), the managed gateway doesn't support changes to the default protocol and cipher configuration. ## Prerequisites |
api-management | Api Management Howto Properties | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-howto-properties.md | Using key vault secrets is recommended because it helps improve API Management s ### Prerequisites for key vault integration + - If you don't already have a key vault, create one. For steps to create a key vault, see [Quickstart: Create a key vault using the Azure portal](../key-vault/general/quick-create-portal.md). To create or import a secret to the key vault, see [Quickstart: Set and retrieve a secret from Azure Key Vault using the Azure portal](../key-vault/secrets/quick-create-portal.md). |
api-management | Api Management Howto Use Azure Monitor | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-howto-use-azure-monitor.md | |
api-management | Api Management Howto Use Managed Service Identity | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-howto-use-managed-service-identity.md | You can grant two types of identities to an API Management instance: > [!NOTE] > Managed identities are specific to the Microsoft Entra tenant where your Azure subscription is hosted. They don't get updated if a subscription is moved to a different directory. If a subscription is moved, you'll need to recreate and configure the identities. + ## Create a system-assigned managed identity ### Azure portal |
api-management | Api Management In Workspace | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-in-workspace.md | - Title: Use a workspace in Azure API Management -description: Members of a workspace in Azure API Management can collaborate to manage and productize their own APIs. ---- Previously updated : 03/10/2023---# Manage APIs and other resources in your API Management workspace ---This article is an introduction to managing APIs, products, subscriptions, and other API Management resources in a *workspace*. A workspace is a place where a development team can own, manage, update, and productize their own APIs, while a central API platform team manages the API Management infrastructure. Learn about the [workspace features](workspaces-overview.md) --> [!NOTE] -> * Workspaces are a preview feature of API Management and subject to certain [limitations](workspaces-overview.md#preview-limitations). -> * Workspaces are supported in API Management REST API version 2022-09-01-preview or later. -> * For pricing considerations, see [API Management pricing](https://azure.microsoft.com/pricing/details/api-management/). --## Prerequisites --* An API Management instance. If needed, ask an administrator to [create one](get-started-create-service-instance.md). -* A workspace. If needed, ask an administrator of your API Management instance to [create one](how-to-create-workspace.md). -* Permissions to collaborate in the workspace. If needed, ask an administrator of your API Management instance to assign you appropriate [roles](api-management-role-based-access-control.md#built-in-workspace-roles) in the service and the workspace. --## Go to the workspace - portal --1. Sign in to the [Azure portal](https://portal.azure.com), and navigate to your API Management instance. --1. In the left menu, select **Workspaces** (preview), and select the name of your workspace. -- :::image type="content" source="media/api-management-in-workspace/workspace-in-portal.png" alt-text="Screenshot of workspaces in API Management instance in the portal." lightbox="media/api-management-in-workspace/workspace-in-portal-expanded.png"::: - -1. The workspace appears. The available resources and settings appear in the menu on the left. -- :::image type="content" source="media/api-management-in-workspace/workspace-menu.png" alt-text="Screenshot of API Management workspace menu in the portal." lightbox="media/api-management-in-workspace/workspace-menu-expanded.png"::: ---## Get started with your workspace --Depending on your role in the workspace, you might have permissions to create APIs, products, subscriptions, and other resources, or you might have read-only access to some or all of them. --To get started managing, protecting, and publishing APIs in your workspaces, see the following guidance. ----|Resource |Guide | -||| -|APIs | [Tutorial: Import and publish your first API](import-and-publish.md) | -|Products | [Tutorial: Create and publish a product](api-management-howto-add-products.md) | -|Subscriptions | [Subscriptions in Azure API Management](api-management-subscriptions.md)<br/><br/>[Create subscriptions in API Management](api-management-howto-create-subscriptions.md) | -|Policies | [Tutorial: Transform and protect your API](transform-api.md)<br/><br/>[Policies in Azure API Management](api-management-howto-policies.md)<br/><br/>[Set or edit API Management policies](set-edit-policies.md) | -|Named values | [Manage secrets using named values](api-management-howto-properties.md) | -|Policy fragments | [Reuse policy configurations in your API Management policy definitions](policy-fragments.md) | -| Schemas | [Validate content](validate-content-policy.md) | -| Groups | [Create and use groups to manage developer accounts](api-management-howto-create-groups.md) -| Notifications | [How to configure notifications and notification templates](api-management-howto-configure-notifications.md) ----## Next steps --* Learn more about [workspaces](workspaces-overview.md) - |
api-management | Api Management Policy Expressions | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-policy-expressions.md | The `context` variable is implicitly available in every policy [expression](api- |Context Variable|Allowed methods, properties, and parameter values| |-|-|-|`context`|[`Api`](#ref-context-api): [`IApi`](#ref-iapi)<br /><br /> [`Deployment`](#ref-context-deployment)<br /><br /> Elapsed: `TimeSpan` - time interval between the value of `Timestamp` and current time<br /><br /> [`GraphQL`](#ref-context-graphql)<br /><br />[`LastError`](#ref-context-lasterror)<br /><br /> [`Operation`](#ref-context-operation)<br /><br /> [`Request`](#ref-context-request)<br /><br /> `RequestId`: `Guid` - unique request identifier<br /><br /> [`Response`](#ref-context-response)<br /><br /> [`Subscription`](#ref-context-subscription)<br /><br /> `Timestamp`: `DateTime` - point in time when request was received<br /><br /> `Tracing`: `bool` - indicates if tracing is on or off <br /><br /> [User](#ref-context-user)<br /><br /> [`Variables`](#ref-context-variables): `IReadOnlyDictionary<string, object>`<br /><br /> `void Trace(message: string)`| -|<a id="ref-context-api"></a>`context.Api`|`Id`: `string`<br /><br /> `IsCurrentRevision`: `bool`<br /><br /> `Name`: `string`<br /><br /> `Path`: `string`<br /><br /> `Revision`: `string`<br /><br /> `ServiceUrl`: [`IUrl`](#ref-iurl)<br /><br /> `Version`: `string` <br /><br /> `Workspace`: [`IWorkspace`](#ref-iworkspace) | +|`context`|[`Api`](#ref-context-api): [`IApi`](#ref-iapi)<br /><br /> [`Deployment`](#ref-context-deployment)<br /><br /> Elapsed: `TimeSpan` - time interval between the value of `Timestamp` and current time<br /><br /> [`GraphQL`](#ref-context-graphql)<br /><br />[`LastError`](#ref-context-lasterror)<br /><br /> [`Operation`](#ref-context-operation)<br /><br /> [`Request`](#ref-context-request)<br /><br /> `RequestId`: `Guid` - unique request identifier<br /><br /> [`Response`](#ref-context-response)<br /><br /> [`Subscription`](#ref-context-subscription)<br /><br /> `Timestamp`: `DateTime` - point in time when request was received<br /><br /> `Tracing`: `bool` - indicates if tracing is on or off <br /><br /> [User](#ref-context-user)<br /><br /> [`Variables`](#ref-context-variables): `IReadOnlyDictionary<string, object>`<br /><br /> `void Trace(message: string)` <br /><br /> [`Workspace`](#ref-context-workspace) | +|<a id="ref-context-api"></a>`context.Api`|`Id`: `string`<br /><br /> `IsCurrentRevision`: `bool`<br /><br /> `Name`: `string`<br /><br /> `Path`: `string`<br /><br /> `Revision`: `string`<br /><br /> `ServiceUrl`: [`IUrl`](#ref-iurl)<br /><br /> `Version`: `string` | |<a id="ref-context-deployment"></a>`context.Deployment`|[`Gateway`](#ref-context-gateway)<br /><br /> `GatewayId`: `string` (returns 'managed' for managed gateways)<br /><br /> `Region`: `string`<br /><br /> `ServiceId`: `string`<br /><br /> `ServiceName`: `string`<br /><br /> `Certificates`: `IReadOnlyDictionary<string, X509Certificate2>`| |<a id="ref-context-gateway"></a>`context.Deployment.Gateway`|`Id`: `string` (returns 'managed' for managed gateways)<br /><br /> `InstanceId`: `string` (returns 'managed' for managed gateways)<br /><br /> `IsManaged`: `bool`| |<a id="ref-context-graphql"></a>`context.GraphQL`|`GraphQLArguments`: `IGraphQLDataObject`<br /><br /> `Parent`: `IGraphQLDataObject`<br/><br/>[Examples](configure-graphql-resolver.md#graphql-context)| |<a id="ref-context-lasterror"></a>`context.LastError`|`Source`: `string`<br /><br /> `Reason`: `string`<br /><br /> `Message`: `string`<br /><br /> `Scope`: `string`<br /><br /> `Section`: `string`<br /><br /> `Path`: `string`<br /><br /> `PolicyId`: `string`<br /><br /> For more information about `context.LastError`, see [Error handling](api-management-error-handling-policies.md).| |<a id="ref-context-operation"></a>`context.Operation`|`Id`: `string`<br /><br /> `Method`: `string`<br /><br /> `Name`: `string`<br /><br /> `UrlTemplate`: `string`|-|<a id="ref-context-product"></a>`context.Product`|`ApprovalRequired`: `bool`<br /><br /> `Groups`: `IEnumerable<`[`IGroup`](#ref-igroup)`>`<br /><br /> `Id`: `string`<br /><br /> `Name`: `string`<br /><br /> `State`: `enum ProductState {NotPublished, Published}`<br /><br /> `SubscriptionsLimit`: `int?`<br /><br /> `SubscriptionRequired`: `bool`<br /><br /> `Workspace`: [`IWorkspace`](#ref-iworkspace)| +|<a id="ref-context-product"></a>`context.Product`|`ApprovalRequired`: `bool`<br /><br /> `Groups`: `IEnumerable<`[`IGroup`](#ref-igroup)`>`<br /><br /> `Id`: `string`<br /><br /> `Name`: `string`<br /><br /> `State`: `enum ProductState {NotPublished, Published}`<br /><br /> `SubscriptionsLimit`: `int?`<br /><br /> `SubscriptionRequired`: `bool`| |<a id="ref-context-request"></a>`context.Request`|`Body`: [`IMessageBody`](#ref-imessagebody) or `null` if request doesn't have a body.<br /><br /> `Certificate`: `System.Security.Cryptography.X509Certificates.X509Certificate2`<br /><br /> [`Headers`](#ref-context-request-headers): `IReadOnlyDictionary<string, string[]>`<br /><br /> `IpAddress`: `string`<br /><br /> `MatchedParameters`: `IReadOnlyDictionary<string, string>`<br /><br /> `Method`: `string`<br /><br /> `OriginalUrl`: [`IUrl`](#ref-iurl)<br /><br /> `Url`: [`IUrl`](#ref-iurl)<br /><br /> `PrivateEndpointConnection`: [`IPrivateEndpointConnection`](#ref-iprivateendpointconnection) or `null` if request doesn't come from a private endpoint connection.| |<a id="ref-context-request-headers"></a>`string context.Request.Headers.GetValueOrDefault(headerName: string, defaultValue: string)`|`headerName`: `string`<br /><br /> `defaultValue`: `string`<br /><br /> Returns comma-separated request header values or `defaultValue` if the header isn't found.| |<a id="ref-context-response"></a>`context.Response`|`Body`: [`IMessageBody`](#ref-imessagebody)<br /><br /> [`Headers`](#ref-context-response-headers): `IReadOnlyDictionary<string, string[]>`<br /><br /> `StatusCode`: `int`<br /><br /> `StatusReason`: `string`| |<a id="ref-context-response-headers"></a>`string context.Response.Headers.GetValueOrDefault(headerName: string, defaultValue: string)`|`headerName`: `string`<br /><br /> `defaultValue`: `string`<br /><br /> Returns comma-separated response header values or `defaultValue` if the header isn't found.| |<a id="ref-context-subscription"></a>`context.Subscription`|`CreatedDate`: `DateTime`<br /><br /> `EndDate`: `DateTime?`<br /><br /> `Id`: `string`<br /><br /> `Key`: `string`<br /><br /> `Name`: `string`<br /><br /> `PrimaryKey`: `string`<br /><br /> `SecondaryKey`: `string`<br /><br /> `StartDate`: `DateTime?`| |<a id="ref-context-user"></a>`context.User`|`Email`: `string`<br /><br /> `FirstName`: `string`<br /><br /> `Groups`: `IEnumerable<`[`IGroup`](#ref-igroup)`>`<br /><br /> `Id`: `string`<br /><br /> `Identities`: `IEnumerable<`[`IUserIdentity`](#ref-iuseridentity)`>`<br /><br /> `LastName`: `string`<br /><br /> `Note`: `string`<br /><br /> `RegistrationDate`: `DateTime`|+|<a id="ref-context-workspace"></a>`context.Workspace`| `Id`: `string`<br /><br /> `Name`: `string`| |<a id="ref-iapi"></a>`IApi`|`Id`: `string`<br /><br /> `Name`: `string`<br /><br /> `Path`: `string`<br /><br /> `Protocols`: `IEnumerable<string>`<br /><br /> `ServiceUrl`: [`IUrl`](#ref-iurl)<br /><br /> `SubscriptionKeyParameterNames`: [`ISubscriptionKeyParameterNames`](#ref-isubscriptionkeyparameternames)| |<a id="ref-igraphqldataobject"></a>`IGraphQLDataObject`|TBD<br /><br />| |<a id="ref-igroup"></a>`IGroup`|`Id`: `string`<br /><br /> `Name`: `string`| The `context` variable is implicitly available in every policy [expression](api- |<a id="ref-isubscriptionkeyparameternames"></a>`ISubscriptionKeyParameterNames`|`Header`: `string`<br /><br /> `Query`: `string`| |<a id="ref-iurl-query"></a>`string IUrl.Query.GetValueOrDefault(queryParameterName: string, defaultValue: string)`|`queryParameterName`: `string`<br /><br /> `defaultValue`: `string`<br /><br /> Returns comma-separated query parameter values or `defaultValue` if the parameter isn't found.| |<a id="ref-iuseridentity"></a>`IUserIdentity`|`Id`: `string`<br /><br /> `Provider`: `string`|-|<a id="ref-iworkspace"></a>`IWorkspace`|`Id`: `string`<br /><br /> `Name`: `string`| |<a id="ref-context-variables"></a>`T context.Variables.GetValueOrDefault<T>(variableName: string, defaultValue: T)`|`variableName`: `string`<br /><br /> `defaultValue`: `T`<br /><br /> Returns variable value cast to type `T` or `defaultValue` if the variable isn't found.<br /><br /> This method throws an exception if the specified type doesn't match the actual type of the returned variable.| |`BasicAuthCredentials AsBasic(input: this string)`|`input`: `string`<br /><br /> If the input parameter contains a valid HTTP Basic Authentication authorization request header value, the method returns an object of type `BasicAuthCredentials`; otherwise the method returns null.| |`bool TryParseBasic(input: this string, result: out BasicAuthCredentials)`|`input`: `string`<br /><br /> `result`: `out BasicAuthCredentials`<br /><br /> If the input parameter contains a valid HTTP Basic Authentication authorization value in the request header, the method returns `true` and the result parameter contains a value of type `BasicAuthCredentials`; otherwise the method returns `false`.| |
api-management | Api Management Role Based Access Control | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/api-management-role-based-access-control.md | Title: How to use Role-Based Access Control in Azure API Management | Microsoft Docs + Title: How to use role-based access control in Azure API Management | Microsoft Docs description: Learn how to use the built-in roles and create custom roles in Azure API Management Previously updated : 02/15/2023 Last updated : 07/10/2024 The following table provides brief descriptions of the built-in roles. You can a API Management provides the following built-in roles for collaborators in [workspaces](workspaces-overview.md) in an API Management instance. -A workspace collaborator must be assigned both a workspace-scoped role and a service-scoped role. -+A workspace collaborator must be assigned both a workspace-scoped role and a service-scoped role. |Role |Scope |Description | |||| A workspace collaborator must be assigned both a workspace-scoped role and a ser | API Management Service Workspace API Developer | service | Has read access to tags and products and write access to allow: <br/><br/> ▪️ Assigning APIs to products<br/> ▪️ Assigning tags to products and APIs<br/><br/> This role should be assigned on the service scope. | | API Management Service Workspace API Product Manager | service | Has the same access as API Management Service Workspace API Developer as well as read access to users and write access to allow assigning users to groups. This role should be assigned on the service scope. | +Depending on how workspace collaborators use or manage the workspace, we recommend also assigning one of the following Azure-provided RBAC roles at the scope of the [workspace gateway](workspaces-overview.md#workspace-gateway): **Reader**, **Contributor**, or **Owner**. ++## Built-in developer portal roles ++|Role |Scope |Description | +|||| +|API Management Developer Portal Content Editor | service | Can customize the developer portal, edit its content, and publish it using Azure Resource Manager APIs. | ## Custom roles |
api-management | Authentication Basic Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/authentication-basic-policy.md | Use the `authentication-basic` policy to authenticate with a backend service usi - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Authentication Certificate Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/authentication-certificate-policy.md | +- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Examples |
api-management | Authentication Managed Identity Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/authentication-managed-identity-policy.md | Both system-assigned identity and any of the multiple user-assigned identities c ## Usage - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound-- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation+- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, product, API, operation - [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted ## Examples |
api-management | Azure Openai Api From Specification | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/azure-openai-api-from-specification.md | This article shows two options to import an [Azure OpenAI Service](/azure/ai-ser ## Option 1. Import API from Azure OpenAI Service -You can import an Azure OpenAI API directly to API Management from the Azure OpenAI Service. When you import the API, API Management automatically configures: +You can import an Azure OpenAI API directly to API Management from the Azure OpenAI Service. +++When you import the API, API Management automatically configures: * Operations for each of the Azure OpenAI [REST API endpoints](/azure/ai-services/openai/reference). * A system-assigned identity with the necessary permissions to access the Azure OpenAI resource. |
api-management | Azure Openai Emit Token Metric Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/azure-openai-emit-token-metric-policy.md | The `azure-openai-emit-token-metric` policy sends metrics to Application Insight - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Azure Openai Enable Semantic Caching | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/azure-openai-enable-semantic-caching.md | |
api-management | Azure Openai Semantic Cache Lookup Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/azure-openai-semantic-cache-lookup-policy.md | Use the `azure-openai-semantic-cache-lookup` policy to perform cache lookup of r - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound-- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation+- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, product, API, operation - [**Gateways:**](api-management-gateways-overview.md) v2 ### Usage notes |
api-management | Azure Openai Semantic Cache Store Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/azure-openai-semantic-cache-store-policy.md | The `azure-openai-semantic-cache-store` policy caches responses to Azure OpenAI ## Usage - [**Policy sections:**](./api-management-howto-policies.md#sections) outbound-- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation+- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, product, API, operation - [**Gateways:**](api-management-gateways-overview.md) v2 ### Usage notes |
api-management | Azure Openai Token Limit Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/azure-openai-token-limit-policy.md | By relying on token usage metrics returned from the OpenAI endpoint, the policy - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, self-hosted, workspace ### Usage notes |
api-management | Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/breaking-changes/overview.md | The following table lists all the upcoming breaking changes and feature retireme | [API version retirements][api2023] | June 1, 2024 | | [Deprecated (legacy) portal retirement][devportal2023] | October 31, 2023 | | [Self-hosted gateway v0/v1 retirement][shgwv0v1] | October 1, 2023 |-| [Workspaces breaking changes][workspaces2024] | June 14, 2024 | +| [Workspaces preview breaking changes][workspaces2024] | June 14, 2024 | | [stv1 platform retirement][stv12024] | August 31, 2024 |+| [Workspaces preview breaking changes, part 2][workspaces2025march] | March 31, 2025 | | [Git repository retirement][git2025] | March 15, 2025 | | [Direct management API retirement][mgmtapi2025] | March 15, 2025 | | [ADAL-based Microsoft Entra ID or Azure AD B2C identity provider retirement][msal2025] | September 30, 2025 | The following table lists all the upcoming breaking changes and feature retireme [analytics2027]: ./analytics-dashboard-retirement-march-2027.md [mgmtapi2025]: ./direct-management-api-retirement-march-2025.md [workspaces2024]: ./workspaces-breaking-changes-june-2024.md+[workspaces2025march]: ./workspaces-breaking-changes-march-2025.md |
api-management | Workspaces Breaking Changes June 2024 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/breaking-changes/workspaces-breaking-changes-june-2024.md | Title: Azure API Management workspaces - breaking changes (June 2024) | Microsoft Docs + Title: Azure API Management workspaces preview - breaking changes (June 2024) | Microsoft Docs description: Azure API Management is updating the workspaces (preview) with breaking changes. If your service uses workspaces, you may need to update workspace configurations. -After 14 June 2024, as part of our development of [workspaces](../workspaces-overview.md) (preview) in Azure API Management, we're introducing several breaking changes. +> [!IMPORTANT] +> If you created workspaces after the generally available release of workspaces in July 2024, your workspaces shouldn't be affected by these changes. +> ++After 14 June 2024, as part of our development of [workspaces](../workspaces-overview.md) in Azure API Management, we're introducing several breaking changes. After 14 June 2024, your workspaces and APIs managed in them may stop working if they still rely on the capabilities set to change. APIs and resources managed outside workspaces aren't affected by this change. If you have questions, get answers from community experts in [Microsoft Q&A](htt ## More information * [Workspaces overview](../workspaces-overview.md)+* [Workspaces breaking changes, part 2 (March 2025)](workspaces-breaking-changes-march-2025.md) ++ ## Related content |
api-management | Workspaces Breaking Changes March 2025 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/breaking-changes/workspaces-breaking-changes-march-2025.md | + + Title: Azure API Management workspaces preview - breaking changes (March 2025) +description: Azure API Management is removing support for preview workspaces. If your service uses preview workspaces, migrate your workspaces to the generally available version. ++++ Last updated : 07/10/2024++++# Workspaces breaking changes, part 2 (March 2025) +++> [!IMPORTANT] +> These breaking changes apply only to *preview* workspaces in Azure API Management. If you created workspaces after the generally available release in July 2024 and use workspaces with workspace gateways, your workspaces shouldn't be affected by these changes. +> ++Azure API Management [workspaces](../workspaces-overview.md) are now generally available, and we introduced several feature updates with that release. As part of our continued development of workspaces, we're removing support for preview workspaces (created before July 2024). If you created preview workspaces in Azure API Management and want to continue using them, you need to migrate your workspaces to the generally available version. ++After 31 March 2025, your preview workspaces and APIs managed in them may stop working if you haven't migrated to the latest workspace capabilities. APIs and resources managed outside workspaces aren't affected by this change. ++## Is my service affected by these changes? ++Your service may be affected by these changes if you created preview workspaces in your API Management instance, before the generally available release of workspaces in July 2024. Workspaces created after the generally available release date that use workspace gateways for API runtime aren't affected by the breaking changes. ++## Breaking changes ++The following are breaking changes that require you to take action to migrate your preview workspaces to the generally available version: ++* **Workspace API gateway is required** - Each workspace must be associated with a workspace API gateway that isolates the workspace's runtime traffic. In preview, workspaces shared a gateway with the service. +* **Service-level managed identities are not supported** - To improve the security of workspaces, system-assigned and user-assigned managed identities enabled at the service level can't be used in workspaces. Currently, related API Management features that depend on managed identities, such as storing named values and certificates in Azure Key Vault, and using the `authentication-managed-identity` policy, aren't supported in workspaces. ++> [!NOTE] +> These breaking changes are in addition to the [June 2024 breaking changes](workspaces-breaking-changes-june-2024.md) for preview workspaces that were announced previously. ++## What is the deadline for the change? ++The breaking changes will be enforced in preview workspaces after 31 March 2025. We strongly recommend that you make all required changes to the configuration of your preview workspaces before that date. ++## What do I need to do? ++If your workspaces are affected by these changes, you need to migrate your workspaces to align with the generally available capabilities. The following sections provide guidance on how to migrate your workspaces. ++### Use Premium tier for your API Management instance ++Ensure that your API Management instance is running in the **Premium** tier to continue using workspaces. As announced [previously](workspaces-breaking-changes-june-2024.md), if your instance is in the **Standard** or **Developer** tier, you need to upgrade to the **Premium** tier. ++### Confirm the region for your instance ++Adding a workspace gateway to a workspace requires that the gateway is in the same region as your instance. Currently, workspace gateways are supported in a [subset of regions](../workspaces-overview.md#workspace-gateway) in which API Management is available. The regions with support for workspace gateways will be updated over time. ++To determine if a preview workspace is in a supported region: ++1. In the [Azure portal](https://portal.azure.com), navigate to your API Management instance. +1. In the left menu, under **APIs**, select **Workspaces**, and select a workspace. +1. If your workspace is in a region that doesn't support workspace gateways, you'll see a message in the portal similar to "Workspaces are currently unavailable in the region of your API Management service". + * If you see this message, you can [move your API Management instance](../api-management-howto-migrate.md) to a supported region. + * If you don't see this message, your workspace is in a supported region and you can proceed to add a workspace gateway. ++### Add a workspace gateway to your workspace ++The following are abbreviated steps to add a workspace gateway to a workspace. For gateway networking options, prerequisites, and detailed instructions, see [Create and manage a workspace](../how-to-create-workspace.md). ++> [!NOTE] +> * The workspace gateway incurs additional charges. For more information, see [API Management pricing](https://aka.ms/apimpricing). +> * API Management currently supports a dedicated gateway per workspace only. If this is impacting your migration plans, see the workspaces roadmap in the [workspaces GA announcement](https://aka.ms/apim/workspaces/ga-announcement). ++1. In the [Azure portal](https://portal.azure.com), navigate to your API Management instance. +1. In the left menu, under **APIs**, select **Workspaces**. +1. Select a workspace. +1. In the left menu, under **Deployment + infrastructure**, select **Gateways** > **+ Add**. +1. Complete the wizard to create a gateway. Currently, provisioning of the gateway can take from several minutes to up to 3 hours or longer. +1. After your gateway is provisioned, go to the gateway's **Overview** page. Note the value of **Runtime hostname**. Use this value to update your client apps that call your workspace's APIs. +1. Repeat the preceding steps for your remaining workspaces. ++### Update client apps to use the new gateway hostname ++After adding a gateway to your workspace, you need to update your client apps that call the workspace's APIs to use the new gateway hostname instead of the gateway hostname of your API Management instance. ++> [!NOTE] +> To help you migrate your workspaces, APIs in workspaces can still be accessed at runtime through October 2024 using the gateway hostname of your API Management instance, even if a workspace gateway is associated with a workspace. We strongly recommend that you complete migration before this date. If your workspace gateways are configured with private inbound access and private outbound access, make sure that connectivity to your API Management instance's built-in gateway is also secured. ++### Update dependencies on service-level managed identities ++If you're using service-level managed identities in the configuration of workspace entities (for example, named values or certificates), you need to update the configurations. Recommended steps vary depending on the entity. Example: Update named values to use secret values instead of secrets stored in Azure Key Vault. ++## Help and support ++If you have questions, get answers from community experts in [Microsoft Q&A](https://aka.ms/apim/azureqa/change/captcha-2022). If you have a support plan and you need technical help, create a [support request](https://portal.azure.com/#view/Microsoft_Azure_Support/HelpAndSupportBlade/~/overview). ++## More information ++* [Workspaces overview](../workspaces-overview.md) +* [Workspaces breaking changes (June 2024)](workspaces-breaking-changes-june-2024.md) ++## Related content ++See all [upcoming breaking changes and feature retirements](overview.md). |
api-management | Cache Lookup Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/cache-lookup-policy.md | Use the `cache-lookup` policy to perform cache lookup and return a valid cached - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Cache Lookup Value Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/cache-lookup-value-policy.md | Use the `cache-lookup-value` policy to perform cache lookup by key and return a - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Cache Remove Value Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/cache-remove-value-policy.md | The `cache-remove-value` deletes a cached item identified by its key. The key ca - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Cache Store Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/cache-store-policy.md | The `cache-store` policy caches responses according to the specified cache setti - [**Policy sections:**](./api-management-howto-policies.md#sections) outbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Cache Store Value Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/cache-store-value-policy.md | The `cache-store-value` performs cache storage by key. The key can have an arbit - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Check Header Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/check-header-policy.md | Use the `check-header` policy to enforce that a request has a specified HTTP he - **[Policy sections:](./api-management-howto-policies.md#sections)** inbound - **[Policy scopes:](./api-management-howto-policies.md#scopes)** global, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Choose Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/choose-policy.md | The `choose` policy must contain at least one `<when/>` element. The `<otherwise - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Examples |
api-management | Configure Custom Domain | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/configure-custom-domain.md | When you create an Azure API Management service instance in the Azure cloud, Azu >* The Gateway's default domain name >* Any of the Gateway's configured custom domain names +> [!NOTE] +> Currently, custom domain names aren't supported in a [workspace gateway](workspaces-overview.md#workspace-gateway). + ## Prerequisites - An API Management instance. For more information, see [Create an Azure API Management instance](get-started-create-service-instance.md). |
api-management | Configure Graphql Resolver | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/configure-graphql-resolver.md | |
api-management | Cors Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/cors-policy.md | The `cors` policy adds cross-origin resource sharing (CORS) support to an operat - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes * You may configure the `cors` policy at more than one scope (for example, at the product scope and the global scope). Ensure that the `base` element is configured at the operation, API, and product scopes to inherit needed policies at the parent scopes. |
api-management | Credentials Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/credentials-overview.md | To help you manage access to backend APIs, your API Management instance includes > * Currently, you can use credential manager to configure and manage connections (formerly called *authorizations*) for backend OAuth 2.0 APIs. > * No breaking changes are introduced with credential manager. OAuth 2.0 credential providers and connections use the existing API Management [authorization](/rest/api/apimanagement/authorization) APIs and resource provider. + ## Managed connections for OAuth 2.0 APIs Using credential manager, you can greatly simplify the process of authenticating and authorizing users, groups, and service principals across one or more backend or SaaS services that use OAuth 2.0. Using API Management's credential manager, easily configure OAuth 2.0, consent, acquire tokens, cache tokens in a credential store, and refresh tokens without writing a single line of code. Use access policies to delegate authentication to your API Management instance, service principals, users, or groups. For background about the OAuth 2.0, see [Microsoft identity platform and OAuth 2.0 authorization code flow](/entra/identity-platform/v2-oauth2-auth-code-flow). |
api-management | Cross Domain Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/cross-domain-policy.md | |
api-management | Developer Portal Wordpress Plugin | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/developer-portal-wordpress-plugin.md | In this step, add the Microsoft Entra app registration as an identity provider f > Do not use the version 2.0 endpoint for the issuer URL (URL ending in `/v2.0`). 1. In **Allowed token audiences**, enter the **Application ID URI** from the app registration. Example: `api://<app-id>`. 1. Under **Additional checks**, select values appropriate for your environment, or use the default values.-1. Accept the default values for the remaining settings and select **Add**. +1. Configure your desired the values for the remaining settings, or use the default values. Select **Add**. + > [!NOTE] + > If you want to allow guest users as well as signed-in users to access the developer portal on WordPress, you can enable unauthenticated access. In **Restrict access**, select **Allow unauthenticated access**. [Learn more](../app-service/overview-authentication-authorization.md#authorization-behavior) The identity provider is added to the app service. Add a custom stylesheet for the API Management developer portal. ## Step 9: Sign into the API Management developer portal deployed on WordPress -Sign into the WordPress site to see your new API Management developer portal deployed on WordPress and hosted on App Service. +Access the WordPress site to see your new API Management developer portal deployed on WordPress and hosted on App Service. ++1. In a new browser window, navigate to your WordPress site, substituting the name of your app service in the following URL: `https://<yourapp-service-name>.azurewebsites.net`. +1. When prompted, sign in using Microsoft Entra ID credentials for a developer account. If unauthenticated access to the developer portal is enabled, select **Sign in** on the home page of the developer portal. > [!NOTE] > You can only sign in to the developer portal on WordPress using Microsoft Entra ID credentials. Basic authentication isn't supported. -1. In a new browser window, navigate to your WordPress site, substituting the name of your app service in the following URL: `https://<yourapp-service-name>.azurewebsites.net` -1. When prompted, sign in using Microsoft Entra ID credentials for a developer account. -- You can now use the following features of the API Management developer portal: * Sign into the portal |
api-management | Emit Metric Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/emit-metric-policy.md | The `emit-metric` policy sends custom metrics in the specified format to Applica - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Find And Replace Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/find-and-replace-policy.md | The `find-and-replace` policy finds a request or response substring and replaces - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Forward Request Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/forward-request-policy.md | The `forward-request` policy forwards the incoming request to the backend servic - [**Policy sections:**](./api-management-howto-policies.md#sections) backend - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Examples |
api-management | Get Authorization Context Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/get-authorization-context-policy.md | class Authorization ## Usage - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound-- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation+- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, product, API, operation - [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption ### Usage notes |
api-management | Graphql Schema Resolve Api | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/graphql-schema-resolve-api.md | Last updated 05/31/2023 [!INCLUDE [api-management-graphql-intro.md](../../includes/api-management-graphql-intro.md)] + In this article, you'll: > [!div class="checklist"] > * Import a GraphQL schema to your API Management instance |
api-management | How To Create Workspace | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/how-to-create-workspace.md | Title: Set up a workspace in Azure API Management -description: Learn how to create a workspace in Azure API Management. Workspaces allow decentralized API development teams to own and productize their own APIs. +description: Learn how to create a workspace and a workspace gateway in Azure API Management. Workspaces allow decentralized API development teams to own and productize their own APIs. Previously updated : 03/07/2023 Last updated : 07/10/2024 -# Set up a workspace +# Create and manage a workspace in Azure API Management [!INCLUDE [api-management-availability-premium](../../includes/api-management-availability-premium.md)] -Set up a [workspace](workspaces-overview.md) (preview) to enable a decentralized API development team to manage and productize their own APIs, while a central API platform team maintains the API Management infrastructure. After you create a workspace and assign permissions, workspace collaborators can create and manage their own APIs, products, subscriptions, and related resources. +Set up a [workspace](workspaces-overview.md) to enable an API team to manage and productize their own APIs, while providing the API platform team with the tools to observe, govern, and maintain the API Management platform. After you create a workspace and assign permissions, workspace collaborators can create and manage their own APIs, products, subscriptions, and related resources. +++Follow the steps in this article to: ++* Create an API Management workspace and a workspace gateway using the Azure portal +* Optionally, isolate the workspace gateway in an Azure virtual network +* Assign permissions to the workspace > [!NOTE]-> * Workspaces are a preview feature of API Management and subject to certain [limitations](workspaces-overview.md#preview-limitations). -> * Workspaces are supported in API Management REST API version 2022-09-01-preview or later. -> * For pricing considerations, see [API Management pricing](https://azure.microsoft.com/pricing/details/api-management/). +> Currently, creating a workspace gateway is a long-running operation that can take up to 3 hours or more to complete. ## Prerequisites -* An API Management instance. If you need to, [create one](get-started-create-service-instance.md). -+* An API Management instance. If you need to, [create one](get-started-create-service-instance.md) in a supported tier. +* **Owner** or **Contributor** role on the resource group where the API Management instance is deployed, or equivalent permissions to create resources in the resource group. +* (Optional) An existing or new Azure virtual network and subnet to isolate the workspace gateway's inbound and outbound traffic. For configuration options and requirements, see [Network resource requirements for workspace gateways](virtual-network-workspaces-resources.md). + ## Create a workspace - portal 1. Sign in to the [Azure portal](https://portal.azure.com), and navigate to your API Management instance. -1. In the left menu, select **Workspaces** (preview) > **+ Add**. - -1. In the **Create workspace** window, enter a descriptive **Name**, resource **Id**, and optional **Description** for the workspace. Select **Save**. +1. In the left menu, under **APIs**, select **Workspaces** > **+ Add**. ++1. On the **Basics** tab, enter a descriptive **Display name**, resource **Name**, and optional **Description** for the workspace. Select **Next**. ++1. On the **Gateway** tab, configure settings for the workspace gateway: -The new workspace appears in the list on the **Workspaces** page. Select the workspace to manage its settings and resources. + * In **Gateway details**, enter a gateway name and select the number of scale **Units**. The gateway costs are based on the number of units you select. For more information, see [API Management pricing](https://aka.ms/apimpricing). + * In **Network**, select a **Network configuration** for your workspace gateway. ++ > [!IMPORTANT] + > Plan your workspace's network configuration carefully. You can't change the network configuration after you create the workspace. ++ * If you select a network configuration that includes private inbound or private outbound network access, select a **Virtual network** and **Subnet** to isolate the workspace gateway, or create a new one. For network requirements, see [Network resource requirements for workspace gateways](virtual-network-workspaces-resources.md). ++1. Select **Next**. After validation completes, select **Create**. ++It can take from several minutes to up to several hours to create the workspace, workspace gateway, and related resources. To track the deployment progress in the Azure portal, go to the gateway's resource group. In the left menu, under **Settings**, select **Deployments**. ++After the deployment completes, the new workspace appears in the list on the **Workspaces** page. Select the workspace to manage its settings and resources. ++> [!NOTE] +> * To view the gateway runtime hostname and other gateway details, select the workspace in the portal. Under **Deployment + infrastructure**, select **Gateways**, and select the name of the workspace's gateway. +> * While the workspace gateway is being created, runtime calls to the workspace's APIs won't succeed. ## Assign users to workspace - portal After creating a workspace, assign permissions to users to manage the workspace's resources. Each workspace user must be assigned both a service-scoped workspace RBAC role and a workspace-scoped RBAC role, or granted equivalent permissions using custom roles. +To manage the workspace gateway, we recommend also assigning workspace users an Azure-provided RBAC role scoped to the workspace gateway. + > [!NOTE] > For easier management, set up Microsoft Entra groups to assign workspace permissions to multiple users. > After creating a workspace, assign permissions to users to manage the workspace' ### Assign a workspace-scoped role -1. In the menu for your API Management instance, select **Workspaces (preview)** > the name of the workspace that you created. +1. In the menu for your API Management instance, under **APIs**, select **Workspaces** > the name of the workspace that you created. 1. In the **Workspace** window, select **Access control (IAM)**> **+ Add**. -1. Assign one of the following workspace-scoped roles to the workspace members to manage workspace APIs and other resources. +1. Assign one of the following workspace-scoped roles to the workspace members so that they can manage workspace APIs and other resources. * **API Management Workspace Reader** * **API Management Workspace Contributor** * **API Management Workspace API Developer** * **API Management Workspace API Product Manager** -## Migrate resources to a workspace +### Assign a gateway-scoped role ++1. Sign in to the [Azure portal](https://portal.azure.com), and navigate to your API Management instance. ++1. In the left menu, under **APIs**, select **Workspaces** > the name of your workspace. ++1. In the left menu of the workspace, select **Gateways**, and select the workspace gateway. ++1. In the left menu, select **Access control (IAM)** > **+ Add**. ++1. Assign one of the following roles to each member of the workspace. At minimum, we recommend assigning the **Reader** role to view the gateway's settings. **Owners** and **Contributors** can manage the gateway's settings including scaling the gateway. + + * **Owner** + * **Contributor** + * **Reader** ++## Get started with your workspace ++Depending on their role in the workspace, users might have permissions to create APIs, products, subscriptions, and other resources, or they might have read-only access to some or all of them. ++To get started managing, protecting, and publishing APIs in a workspace, see the following guidance. +++|Resource |Guide | +||| +|APIs | [Tutorial: Import and publish your first API](import-and-publish.md) | +|Products | [Tutorial: Create and publish a product](api-management-howto-add-products.md) | +|Subscriptions | [Subscriptions in Azure API Management](api-management-subscriptions.md)<br/><br/>[Create subscriptions in API Management](api-management-howto-create-subscriptions.md) | +|Policies | [Tutorial: Transform and protect your API](transform-api.md)<br/><br/>[Policies in Azure API Management](api-management-howto-policies.md)<br/><br/>[Set or edit API Management policies](set-edit-policies.md) | +|Named values | [Manage secrets using named values](api-management-howto-properties.md) | +| Backends | [Use backends in Azure API Management](backends.md) | +|Policy fragments | [Reuse policy configurations in your API Management policy definitions](policy-fragments.md) | +| Schemas | [Validate content](validate-content-policy.md) | +| Groups | [Create and use groups to manage developer accounts](api-management-howto-create-groups.md) | +| Notifications | [How to configure notifications and notification templates](api-management-howto-configure-notifications.md) | -The open source [Azure API Management workspaces migration tool](https://github.com/Azure-Samples/api-management-workspaces-migration) can help you with the initial setup of resources in the workspace. Use the tool to migrate selected service-level APIs with their dependencies from an Azure API Management instance to a workspace. -## Next steps +## Related content -* Workspace collaborators can get started [managing APIs and other resources in their API Management workspace](api-management-in-workspace.md) +* Learn more about [workspaces in Azure API Management](workspaces-overview.md). +* [Use a virtual network to secure inbound or outbound traffic for Azure API Management](virtual-network-concepts.md) |
api-management | Howto Use Analytics | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/howto-use-analytics.md | Azure API Management provides analytics for your APIs so that you can analyze th :::image type="content" source="media/howto-use-analytics/analytics-report-portal.png" alt-text="Screenshot of API analytics in the portal." lightbox="media/howto-use-analytics/analytics-report-portal.png"::: ## About API analytics |
api-management | Http Data Source Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/http-data-source-policy.md | |
api-management | Import App Service As Api | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/import-app-service-as-api.md | -> [!NOTE] -> You can use the API Management Extension for Visual Studio Code to import and manage your APIs. Follow the [API Management Extension tutorial](visual-studio-code-tutorial.md) to install and get started. In this article, you learn how to: |
api-management | Import Container App With Oas | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/import-container-app-with-oas.md | -This article shows how to import an Azure Container App to Azure API Management and test the imported API using the Azure portal. In this article, you learn how to: +This article shows how to import an Azure Container App to Azure API Management and test the imported API using the Azure portal. +++In this article, you learn how to: > [!div class="checklist"] > * Import a Container App that exposes a Web API |
api-management | Import Function App As Api | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/import-function-app-as-api.md | |
api-management | Import Logic App As Api | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/import-logic-app-as-api.md | |
api-management | Include Fragment Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/include-fragment-policy.md | The policy inserts the policy fragment as-is at the location you select in the p - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Invoke Dapr Binding Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/invoke-dapr-binding-policy.md | The policy assumes that Dapr runtime is running in a sidecar container in the sa ## Usage - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, on-error-- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation+- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, product, API, operation - [**Gateways:**](api-management-gateways-overview.md) self-hosted ### Usage notes |
api-management | Ip Filter Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/ip-filter-policy.md | The `ip-filter` policy filters (allows/denies) calls from specific IP addresses - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Json To Xml Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/json-to-xml-policy.md | The `json-to-xml` policy converts a request or response body from JSON to XML. - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Jsonp Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/jsonp-policy.md | The `jsonp` policy adds JSON with padding (JSONP) support to an operation or an - [**Policy sections:**](./api-management-howto-policies.md#sections) outbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Limit Concurrency Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/limit-concurrency-policy.md | The `limit-concurrency` policy prevents enclosed policies from executing by more - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Log To Eventhub Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/log-to-eventhub-policy.md | The `log-to-eventhub` policy sends messages in the specified format to an event ## Usage - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error-- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation+- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, product, API, operation - [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted ### Usage notes |
api-management | Mock Response Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/mock-response-policy.md | The `mock-response` policy, as the name implies, is used to mock APIs and operat - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Observability | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/observability.md | The table below summarizes all the observability capabilities supported by API M > | Tool | Useful for | Data lag | Retention | Sampling | Data kind | Supported Deployment Model(s) | |:- |:-|:- |:-|:- |: |:- |-| **[API Inspector](api-management-howto-api-inspector.md)** | Testing and debugging | Instant | Last 100 traces | Turned on per request | Request traces | Managed, Self-hosted, Azure Arc | +| **[API Inspector](api-management-howto-api-inspector.md)** | Testing and debugging | Instant | Last 100 traces | Turned on per request | Request traces | Managed, Self-hosted, Azure Arc, Workspace | | **[Built-in Analytics](howto-use-analytics.md)** | Reporting and monitoring | Minutes | Lifetime | 100% | Reports and logs | Managed | | **[Azure Monitor Metrics](api-management-howto-use-azure-monitor.md)** | Reporting and monitoring | Minutes | 90 days (upgrade to extend) | 100% | Metrics | Managed, Self-hosted<sup>2</sup>, Azure Arc | | **[Azure Monitor Logs](api-management-howto-use-azure-monitor.md)** | Reporting, monitoring, and debugging | Minutes | 31 days/5GB (upgrade to extend) | 100% (adjustable) | Logs | Managed<sup>1</sup>, Self-hosted<sup>3</sup>, Azure Arc<sup>3</sup> |-| **[Azure Application Insights](api-management-howto-app-insights.md)** | Reporting, monitoring, and debugging | Seconds | 90 days/5GB (upgrade to extend) | Custom | Logs, metrics | Managed<sup>1</sup>, Self-hosted<sup>1</sup>, Azure Arc<sup>1</sup> | +| **[Azure Application Insights](api-management-howto-app-insights.md)** | Reporting, monitoring, and debugging | Seconds | 90 days/5GB (upgrade to extend) | Custom | Logs, metrics | Managed<sup>1</sup>, Self-hosted<sup>1</sup>, Azure Arc<sup>1</sup>, Workspace<sup>1</sup> | | **[Logging through Azure Event Hubs](api-management-howto-log-event-hubs.md)** | Custom scenarios | Seconds | User managed | Custom | Custom | Managed<sup>1</sup>, Self-hosted<sup>1</sup>, Azure Arc<sup>1</sup> | | **[OpenTelemetry](how-to-deploy-self-hosted-gateway-kubernetes-opentelemetry.md#introduction-to-opentelemetry)** | Monitoring | Minutes | User managed | 100% | Metrics | Self-hosted<sup>2</sup> | |
api-management | Private Endpoint | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/private-endpoint.md | You can configure an inbound [private endpoint](../private-link/private-endpoint * Only the API Management instance's Gateway endpoint supports inbound Private Link connections. * Each API Management instance supports at most 100 Private Link connections.-* Connections aren't supported on the [self-hosted gateway](self-hosted-gateway-overview.md). +* Connections aren't supported on the [self-hosted gateway](self-hosted-gateway-overview.md) or on a [workspace gateway](workspaces-overview.md#workspace-gateway). ## Prerequisites |
api-management | Protect With Defender For Apis | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/protect-with-defender-for-apis.md | |
api-management | Proxy Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/proxy-policy.md | The `proxy` policy allows you to route requests forwarded to backends via an HTT - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Publish Event Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/publish-event-policy.md | |
api-management | Publish To Dapr Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/publish-to-dapr-policy.md | The policy assumes that Dapr runtime is running in a sidecar container in the sa ## Usage - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound-- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation+- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, product, API, operation - [**Gateways:**](api-management-gateways-overview.md) self-hosted ### Usage notes |
api-management | Quota By Key Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/quota-by-key-policy.md | To understand the difference between rate limits and quotas, [see Rate limits an - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, self-hosted, workspace ### Usage notes |
api-management | Quota Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/quota-policy.md | To understand the difference between rate limits and quotas, [see Rate limits an - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) product-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Rate Limit By Key Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/rate-limit-by-key-policy.md | To understand the difference between rate limits and quotas, [see Rate limits an - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, self-hosted, workspace ### Usage notes |
api-management | Rate Limit Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/rate-limit-policy.md | To understand the difference between rate limits and quotas, [see Rate limits an - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Redirect Content Urls Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/redirect-content-urls-policy.md | The `redirect-content-urls` policy rewrites (masks) links in the response body s - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Retry Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/retry-policy.md | The `retry` policy may contain any other policies as its child elements. - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Examples |
api-management | Return Response Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/return-response-policy.md | The `return-response` policy cancels pipeline execution and returns either a def - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Rewrite Uri Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/rewrite-uri-policy.md | This policy can be used when a human and/or browser-friendly URL should be trans - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Send Request Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/send-request-policy.md | The `send-request` policy sends the provided request to the specified URL, waiti - **[Policy sections:](./api-management-howto-policies.md#sections)** inbound, outbound, backend, on-error - **[Policy scopes:](./api-management-howto-policies.md#scopes)** global, workspace, product, API, operation-- **[Gateways:](api-management-gateways-overview.md)** dedicated, consumption, self-hosted+- **[Gateways:](api-management-gateways-overview.md)** dedicated, consumption, self-hosted, workspace ### Usage notes |
api-management | Set Backend Service Dapr Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/set-backend-service-dapr-policy.md | The policy assumes that Dapr runs in a sidecar container in the same pod as the ## Usage - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound-- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation+- [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, product, API, operation - [**Gateways:**](api-management-gateways-overview.md) self-hosted ### Usage notes |
api-management | Set Backend Service Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/set-backend-service-policy.md | Referencing a backend entity allows you to manage the backend service base URL a - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, backend - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Set Body Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/set-body-policy.md | OriginalUrl. - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Set Header Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/set-header-policy.md | The `set-header` policy assigns a value to an existing HTTP response and/or requ - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Set Method Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/set-method-policy.md | The value of the element specifies the HTTP method, such as `POST`, `GET`, and s - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Set Query Parameter Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/set-query-parameter-policy.md | The `set-query-parameter` policy adds, replaces value of, or deletes request que - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, backend - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Examples |
api-management | Set Status Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/set-status-policy.md | The `set-status` policy sets the HTTP status code to the specified value. - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Set Variable Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/set-variable-policy.md | The `set-variable` policy declares a [context](api-management-policy-expressions - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Allowed types |
api-management | Sql Data Source Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/sql-data-source-policy.md | |
api-management | Trace Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/trace-policy.md | The `trace` policy adds a custom trace into the request tracing output in the te - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Upgrade And Scale | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/upgrade-and-scale.md | You can use the portal to scale your API Management instance. How you scale depe 1. Specify the new number of **Units** - use the slider, or select or type the number. 1. Select **Save**. +### Add or remove units - workspace gateway ++1. Navigate to your API Management instance in the [Azure portal](https://portal.azure.com/). +1. In the left menu, under **APIs**, select **Workspaces** > the name of your workspace. +1. In the left menu, under **Deployment + infrastructure**, select **Gateways** > the name of your gateway. +1. In the left menu, under **Deployment and infrastructure**, select **Scale**. +1. Specify the new number of **Units** - use the slider, or select or type the number. +1. Select **Save**. + ## Change your API Management service tier 1. Navigate to your API Management instance in the [Azure portal](https://portal.azure.com/). |
api-management | Validate Azure Ad Token Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/validate-azure-ad-token-policy.md | The `validate-azure-ad-token` policy enforces the existence and validity of a JS - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Validate Client Certificate Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/validate-client-certificate-policy.md | For more information about custom CA certificates and certificate authorities, s - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Validate Content Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/validate-content-policy.md | The policy validates the following content in the request or response against th - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace [!INCLUDE [api-management-validation-policy-common](../../includes/api-management-validation-policy-common.md)] |
api-management | Validate Graphql Request Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/validate-graphql-request-policy.md | Available actions are described in the following table. - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Validate Headers Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/validate-headers-policy.md | The `validate-headers` policy validates the response headers against the API sch - [**Policy sections:**](./api-management-howto-policies.md#sections) outbound, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Validate Jwt Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/validate-jwt-policy.md | The `validate-jwt` policy enforces existence and validity of a supported JSON we - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Validate Odata Request Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/validate-odata-request-policy.md | The `validate-odata-request` policy validates the request URL, headers, and para - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Validate Parameters Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/validate-parameters-policy.md | The `validate-parameters` policy validates the header, query, or path parameters - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Validate Status Code Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/validate-status-code-policy.md | The `validate-status-code` policy validates the HTTP status codes in responses a - [**Policy sections:**](./api-management-howto-policies.md#sections) outbound, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
api-management | Virtual Network Injection Resources | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/virtual-network-injection-resources.md | Title: Azure API Management virtual network integration - network resources + Title: Azure API Management virtual network injection - network resources description: Learn about requirements for network resources when you deploy (inject) your API Management instance in an Azure virtual network. |
api-management | Virtual Network Workspaces Resources | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/virtual-network-workspaces-resources.md | + + Title: Azure API Management workspace gateways - VNet integration - network resources +description: Learn about requirements for network resources when you integrate your API Management workspace gateway in an Azure virtual network. ++++ Last updated : 07/15/2024++++# Network resource requirements for integration of a workspace gateway into a virtual network +++Network isolation is an optional feature of an API Management [workspace gateway](workspaces-overview.md#workspace-gateway). This article provides network resource requirements when you integrate your gateway in an Azure virtual network. Some requirements differ depending on the desired inbound and outbound access mode. The following modes are supported: ++* Public inbound access, private outbound access (Public/Private) +* Private inbound access, private outbound access (Private/Private) ++For information about networking options in API Management, see [Use a virtual network to secure inbound or outbound traffic for Azure API Management](virtual-network-concepts.md). ++++## Network location ++* The virtual network must be in the same region and Azure subscription as the API Management instance. ++## Subnet size ++* The subnet size must be `/24` (256 IP addresses). +* The subnet can't be shared with another Azure resource, including another workspace gateway. ++## Subnet delegation ++The subnet must be delegated as follows to enable the desired inbound and outbound access. ++For information about configuring subnet delegation, see [Add or remove a subnet delegation](../virtual-network/manage-subnet-delegation.md). ++#### [Public/Private](#tab/external) +++For Public/Private mode, the subnet needs to be delegated to the **Microsoft.Web/serverFarms** service. +++> [!NOTE] +> You might need to register the `Microsoft.Web/serverFarms` resource provider in the subscription so that you can delegate the subnet to the service. ++#### [Private/Private](#tab/internal) ++For Private/Private mode, the subnet needs to be delegated to the **Microsoft.Web/hostingEnvironments** service. ++++> [!NOTE] +> You might need to register the `Microsoft.Web/hostingEnvironments` resource provider in the subscription so that you can delegate the subnet to the service. +++++## Network security group (NSG) rules ++A network security group (NSG) must be attached to the subnet to explicitly allow inbound connectivity. Configure the following rules in the NSG. Set the priority of these rules higher than that of the default rules. ++#### [Public/Private](#tab/external) ++| Source / Destination Port(s) | Direction | Transport protocol | Source | Destination | Purpose | +||--|--||-|--| +| */80 | Inbound | TCP | AzureLoadBalancer | Workspace gateway subnet range | Allow internal health ping traffic | +| */80,443 | Inbound | TCP | Internet | Workspace gateway subnet range | Allow inbound traffic | ++#### [Private/Private](#tab/internal) ++| Source / Destination Port(s) | Direction | Transport protocol | Source | Destination | Purpose | +||--|--||-|--| +| */80 | Inbound | TCP | AzureLoadBalancer | Workspace gateway subnet range | Allow internal health ping traffic | +| */80,443 | Inbound | TCP | Virtual network | Workspace gateway subnet range | Allow inbound traffic | ++++## DNS settings for Private/Private configuration ++In the Private/Private network configuration, you have to manage your own DNS to enable inbound access to your workspace gateway. ++We recommend: ++1. Configure an Azure [DNS private zone](../dns/private-dns-overview.md). +1. Link the Azure DNS private zone to the VNet into which you've deployed your workspace gateway. ++Learn how to [set up a private zone in Azure DNS](../dns/private-dns-getstarted-portal.md). +++### Access on default hostname ++When you create an API Management workspace, the workspace gateway is assigned a default hostname. The hostname is visible in the Azure portal on the workspace gateway's **Overview** page, along with its private virtual IP address. The default hostname is in the format `<gateway-name>-<random hash>.gateway.<region>-<number>.azure-api.net`. Example: `team-workspace-123456abcdef.gateway.uksouth-01.azure-api.net`. ++> [!NOTE] +> The workspace gateway only responds to requests to the hostname configured on its endpoint, not its private VIP address. ++### Configure DNS record ++Create an A record in your DNS server to access the workspace from within your VNet. Map the endpoint record to the private VIP address of your workspace gateway. ++For testing purposes, you might update the hosts file on a virtual machine in a subnet connected to the VNet in which API Management is deployed. Assuming the private virtual IP address for your workspace gateway is 10.1.0.5, you can map the hosts file as shown in the following example. The hosts mapping file is at `%SystemDrive%\drivers\etc\hosts` (Windows) or `/etc/hosts` (Linux, macOS). ++| Internal virtual IP address | Gateway hostname | +| -- | -- | +| 10.1.0.5 | `teamworkspace.gateway.westus.azure-api.net` | +++## Related content ++* [Use a virtual network to secure inbound or outbound traffic for Azure API Management](virtual-network-concepts.md) +* [Workspaces in Azure API Management](workspaces-overview.md) +++++ |
api-management | Wait Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/wait-policy.md | May contain as child elements only `send-request`, `cache-lookup-value`, and `ch - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, backend - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Websocket Api | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/websocket-api.md | |
api-management | Workspaces Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/workspaces-overview.md | Title: Workspaces in Azure API Management | Microsoft Docs -description: Learn about workspaces (preview) in Azure API Management. Workspaces allow decentralized API development teams to manage and productize their own APIs, while a central API platform team maintains the API Management infrastructure. +description: Learn about Azure API Management workspaces. With workspaces, decentralized API development teams manage and productize APIs in a common service infrastructure. - Previously updated : 01/25/2024+ Last updated : 07/19/2024 -+#customer intent: As administrator of an API Management instance, I want to learn about using workspaces to manage APIs in a decentralized way, so that I can enable my development teams to manage and productize their own APIs. + -# Workspaces in Azure API Management +# What are workspaces in Azure API Management? [!INCLUDE [api-management-availability-premium](../../includes/api-management-availability-premium.md)] -In API Management, *workspaces* allow decentralized API development teams to manage and productize their own APIs, while a central API platform team maintains the API Management infrastructure. Each workspace contains APIs, products, subscriptions, and related entities that are accessible only to the workspace collaborators. Access is controlled through Azure role-based access control (RBAC). +In API Management, *workspaces* bring a new level of autonomy to an organization's API teams, enabling them to create, manage, and publish APIs faster, more reliably, securely, and productively within an API Management service. By providing isolated administrative access and API runtime, workspaces empower API teams while allowing the API platform team to retain oversight. This includes central monitoring, enforcement of API policies and compliance, and publishing APIs for discovery through a unified developer portal. -> [!NOTE] -> * Workspaces are a preview feature of API Management and subject to certain [limitations](#preview-limitations). -> * Workspaces are supported in API Management REST API version 2022-09-01-preview or later. -> * For pricing considerations, see [API Management pricing](https://azure.microsoft.com/pricing/details/api-management/). -> * See [upcoming breaking changes](./breaking-changes/workspaces-breaking-changes-june-2024.md) for workspaces. +Workspaces function like "folders" within an API Management service: ++* Each workspace contains APIs, products, subscriptions, named values, and related resources. +* Access to resources within a workspace is managed through Azure's role-based access control (RBAC) with built-in or custom roles assignable to Microsoft Entra accounts. +* Each workspace is associated with a *workspace gateway* for routing API traffic to the backend services of APIs in the workspace. ++++## Federated API management with workspaces ++Workspaces add first-class support for a *federated model* of managing APIs in API Management, in addition to already supported centralized and siloed models. See the following table for a comparison of these models. ++|Model|Description | +||| +|**Centralized**<br/><br/>:::image type="content" source="media/workspaces-overview/centralized.png" alt-text="Diagram of the centralized model of Azure API Management." border="false" lightbox="media/workspaces-overview/centralized.png"::: |**Pros**<br/>ΓÇó Centralized API governance and observability<br/>ΓÇó Unified developer portal for effective API discovery and onboarding<br/>ΓÇó Cost-efficiency of the infrastructure<br/><br/>**Cons**<br/>ΓÇó No segregation of administrative permissions between teams<br/>ΓÇó API gateway is a single point of failure<br/>ΓÇó Inability to attribute runtime issues to specific teams<br/>ΓÇó Burden on platform team to facilitate collaboration may reduce API growth | +|**Siloed**<br/><br/>:::image type="content" source="media/workspaces-overview/siloed.png" alt-text="Diagram of the siloed model of Azure API Management." border="false" lightbox="media/workspaces-overview/siloed.png"::: |**Pros**<br/>ΓÇó Segregation of administrative permissions between teams increases productivity and security<br/>ΓÇó Segregation of API runtime between teams increases API reliability, resiliency, and security<br/>ΓÇó Runtime issues are contained and attributable to specific teams<br/><br/>**Cons**<br/>ΓÇó Lack of centralized API governance and observability<br/>ΓÇó Lack of unified developer portal<br/>ΓÇó Increased cost and harder platform managementΓÇï | +|**Federated**<br/><br/>:::image type="content" source="media/workspaces-overview/federated.png" alt-text="Diagram of the federated model of Azure API Management." border="false" lightbox="media/workspaces-overview/federated.png"::: |**Pros**<br/>ΓÇó Centralized API governance and observability<br/>ΓÇó Unified developer portal for effective API discovery and onboarding<br/>ΓÇó Segregation of administrative permissions between teams increases productivity and security<br/>ΓÇó Segregation of API runtime between teams increases API reliability, resiliency, and security<br/>ΓÇó Runtime issues are contained and attributable to specific teams<br/><br/>**Cons**<br/>ΓÇó Platform cost and management difficulty greater than in the centralized model but lower than in the siloed model | ## Example scenario overview -An organization that manages APIs using Azure API Management may have multiple development teams that develop, define, maintain, and productize different sets of APIs. Workspaces allow these teams to use API Management to manage and access their APIs separately, and independently of managing the service infrastructure. +An organization that manages APIs using Azure API Management may have multiple development teams that develop, define, maintain, and productize different sets of APIs. Workspaces allow these teams to use API Management to manage, access, and secure their APIs separately, and independently of managing the service infrastructure. The following is a sample workflow for creating and using a workspace. -1. A central API platform team that manages the API Management instance creates a workspace and assigns permissions to workspace collaborators using RBAC roles - for example, permissions to create or read resources in the workspace. +1. A central API platform team that manages the API Management instance creates a workspace and assigns permissions to workspace collaborators using RBAC roles - for example, permissions to create or read resources in the workspace. A dedicated API gateway is also created for the workspace. 1. A central API platform team uses DevOps tools to create a DevOps pipeline for APIs in that workspace. 1. Workspace members develop, publish, productize, and maintain APIs in the workspace. -1. The central API platform team manages the infrastructure of the service, such as network connectivity, monitoring, resiliency, and enforcement of all-APIs policies. +1. The central API platform team manages the infrastructure of the service, such as monitoring, resiliency, and enforcement of all-APIs policies. ++## API management in a workspace -## Workspace features +Teams manage their own APIs, products, subscriptions, backends, policies, loggers, and other resources within workspaces. See the API Management [REST API reference](/rest/api/apimanagement/workspace?view=rest-apimanagement-2023-09-01-preview&preserve-view=true) for a full list of resources and operations supported in workspaces. -The following resources can be managed in the workspaces preview. +While workspaces are managed independently from the API Management service and other workspaces, by design they can reference selected service-level resources. See [Workspaces and other API Management features](#workspaces-and-other-api-management-features), later in this article. -### APIs and policies +## Workspace gateway -* Create and manage APIs and API operations, including API version sets, API revisions, and API policies. +Each workspace can be associated with workspace gateways to enable runtime of APIs managed within the workspace. The workspace gateway is a standalone Azure resource with the same core functionality as the gateway built into your API Management service. -* Apply a policy for all APIs in a workspace. +Workspace gateways are managed independently from the API Management service and from each other. They ensure isolation of runtime between workspaces, increasing API reliability, resiliency, and security and enabling attribution of runtime issues to workspaces. -* Describe APIs with tags from the workspace level. +* For information on the cost of workspace gateways, see [API Management pricing](https://aka.ms/apimpricing). +* For a detailed comparison of API Management gateways, see [API Management gateways overview](api-management-gateways-overview.md). -* Define named values, policy fragments, and schemas for request and response validation for use in workspace-scoped policies. +### Gateway hostname ++Each association of a workspace to a workspace gateway creates a unique hostname for APIs managed in that workspace. Default hostnames follow the pattern `<workspace-name>-<hash>.gateway.<region>.azure-api.net`. Currently, custom hostnames aren't supported for workspace gateways. > [!NOTE]-> In a workspace, policy scopes are as follows: -> All APIs (service) > All APIs (workspace) > Product > API > API operation +> Through October 2024, APIs in workspaces can be accessed at runtime using the gateway hostname of your API Management instance in addition to the hostname of the workspace gateway. -### Users and groups +### Network isolation -* Organize users (from the service level) into groups in a workspace. +A workspace gateway can optionally be configured in a private virtual network to isolate inbound and/or outbound traffic. If configured, the workspace gateway must use a dedicated subnet in the virtual network. -### Products and subscriptions +For detailed requirements, see [Network resource requirements for workspace gateways](virtual-network-workspaces-resources.md). -* Publish APIs with products. APIs in a workspace can only be part of a workspace-level product. Visibility can be configured based on user membership in a workspace-level or a service-level group. -* Manage access to APIs with subscriptions. Subscriptions requested to an API or product within a workspace are created in that workspace. +### Scale capacity -* Publish APIs and products with the developer portal. +Manage gateway capacity by manually adding or removing scale units, similar to the [units](upgrade-and-scale.md) that can be added to the API Management instance in certain service tiers. The costs of a workspace gateway are based on the number of units you select. -* Manage administrative email notifications related to resources in the workspace. +### Regional availability -## RBAC roles +Workspace gateways need to be in the same Azure region and subscription as the API Management service. ++> [!NOTE] +> Starting in August 2024, workspace gateway support will be rolled out in the following regions. These regions are a subset of those where API Management is available. ++* West US +* North Central US +* UK South +* France Central +* North Europe +* East Asia +* Southeast Asia +* Australia East +* Japan East ++### Gateway constraints +The following constraints currently apply to workspace gateways: ++* A gateway can be associated only with one workspace +* A workspace can't be associated with a self-hosted gateway +* Workspace gateways don't support inbound private endpoints +* APIs in workspace gateways can't be assigned custom hostnames +* APIs in workspaces aren't covered by Defender for APIs +* Workspace gateways don't support the API Management service's credential manager +* Workspace gateways support only internal cache; external cache isn't supported +* Workspace gateways don't support synthetic GraphQL APIs and WebSocket APIs +* Workspace gateways don't support APIs created from Azure resources such as Azure OpenAI Service, App Service, Function Apps, and so on +* Request metrics can't be split by workspace in Azure Monitor; all workspace metrics are aggregated at the service level +* Azure Monitor logs are aggregated at the service level; workspace-level logs aren't available +* Workspace gateways don't support CA certificates +* Workspace gateways don't support autoscaling +* Workspace gateways don't support managed identities, including related features like storing secrets in Azure Key Vault and using the `authentication-managed-identity` policy ++## RBAC roles for workspaces Azure RBAC is used to configure workspace collaborators' permissions to read and edit entities in the workspace. For a list of roles, see [How to use role-based access control in API Management](api-management-role-based-access-control.md). -Workspace members must be assigned both a service-scoped role and a workspace-scoped role, or granted equivalent permissions using custom roles. The service-scoped role enables referencing certain service-level resources from workspace-level resources. For example, organize a user into a workspace-level group to control API and product visibility. +To manage APIs and other resources in the workspace, workspace members must be assigned roles (or equivalent permissions using custom roles) scoped to the API Management service, the workspace, and the workspace gateway. The service-scoped role enables referencing certain service-level resources from workspace-level resources. For example, organize a user into a workspace-level group to control API and product visibility. > [!NOTE] > For easier management, set up Microsoft Entra groups to assign workspace permissions to multiple users. Workspace members must be assigned both a service-scoped role and a workspace-sc ## Workspaces and other API Management features -* **Infrastructure features** - API Management platform infrastructure features are managed on the service level only, not at the workspace level. These features include: +Workspaces are designed to be self-contained to maximize segregation of administrative access and API runtime. There are several exceptions to ensure higher productivity and enable platform-wide governance, observability, reusability, and API discovery. - * Private network connectivity - - * API gateways, including scaling, locations, and self-hosted gateways - -* **Resource references** - Resources in a workspace can reference other resources in the workspace and users from the service level. They can't reference resources from another workspace. +* **Resource references** - Resources in a workspace can reference other resources in the workspace and selected resources from the service level, such as users, authorization servers, or built-in user groups. They can't reference resources from another workspace. - For security reasons, it's not possible to reference service-level resources from workspace-level policies (for example, named values) or by resource names, such as `backend-id` in the [set-backend-service](set-backend-service-policy.md) policy. + For security reasons, it's not possible to reference service-level resources from workspace-level policies (for example, named values) or by resource names, such as `backend-id` in the [set-backend-service](set-backend-service-policy.md) policy. -* **Developer portal** - Workspaces are an administrative concept and aren't surfaced as such to developer portal consumers, including through the developer portal UI and the underlying API. However, APIs and products can be published from a workspace to the developer portal. Because of this, any resource that's used by the developer portal (for example, an API, product, tag, or subscription) needs to have a unique Azure resource name in the service. There can't be any resources of the same type and with the same Azure resource name in the same workspace, in other workspaces, or on the service level. + > [!IMPORTANT] + > All resources in an API Management service (for example, APIs, products, tags, or subscriptions) need to have unique names, even if they are located in different workspaces. There can't be any resources of the same type and with the same Azure resource name in the same workspace, in other workspaces, or on the service level. + > -* **Deleting a workspace** - Deleting a workspace deletes all its child resources (APIs, products, and so on). +* **Developer portal** - Workspaces are an administrative concept and aren't surfaced as such to developer portal consumers, including through the developer portal UI and the underlying API. APIs and products within a workspace can be published to the developer portal, just like APIs and products on the service level. -## Preview limitations + > [!NOTE] + > API Management supports assigning authorization servers defined on the service level to APIs within workspaces. + > -The following resources aren't currently supported in workspaces: +## Migrate from preview workspaces -* Authorization servers (credential providers in credential manager) +If you created preview workspaces in Azure API Management and want to continue using them, migrate your workspaces to the generally available version by associating a workspace gateway with each workspace. -* Authorizations (connections to credential providers in credential manager) +For details and to learn about other changes that could affect your preview workspaces, see [Workspaces breaking changes (March 2025)](breaking-changes/workspaces-breaking-changes-march-2025.md). -* Backends +## Deleting a workspace -* Client certificates --* Current DevOps tooling for API Management --* Diagnostics --* Loggers --* Synthetic GraphQL APIs --* User-assigned managed identity --Therefore, the following sample scenarios aren't currently supported in workspaces: --* Monitoring APIs with workspace-specific configuration --* Managing API backends and importing APIs from Azure services --* Validating client certificates --* Using the credential manager (formerly called authorizations) feature --* Specifying API authorization server information (for example, for the developer portal) - -* Publishing workspace APIs to self-hosted gateways --> [!IMPORTANT] -> All resources in an API Management service need to have unique names, even if they are located in different workspaces. -> +Deleting a workspace deletes all its child resources (APIs, products, and so on) and its associated gateway, if you're deleting the workspace using the Azure portal interface. It doesn't delete the API Management instance or other workspaces. + ## Related content * [Create a workspace](how-to-create-workspace.md) * [Workspaces breaking changes - June 2024](breaking-changes/workspaces-breaking-changes-june-2024.md)+* [Workspaces breaking changes - March 2025](breaking-changes/workspaces-breaking-changes-march-2025.md) +* [Limits - API Management workspaces](../azure-resource-manager/management/azure-subscription-service-limits.md?toc=/azure/api-management/toc.json&bc=/azure/api-management/breadcrumb/toc.json#limitsapi-management-workspaces) |
api-management | Xml To Json Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/xml-to-json-policy.md | The `xml-to-json` policy converts a request or response body from XML to JSON. T - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound, on-error - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ## Example |
api-management | Xsl Transform Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/api-management/xsl-transform-policy.md | The `xsl-transform` policy applies an XSL transformation to XML in the request o - [**Policy sections:**](./api-management-howto-policies.md#sections) inbound, outbound - [**Policy scopes:**](./api-management-howto-policies.md#scopes) global, workspace, product, API, operation-- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted+- [**Gateways:**](api-management-gateways-overview.md) classic, v2, consumption, self-hosted, workspace ### Usage notes |
app-service | Migrate | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/app-service/environment/migrate.md | If your migration includes a custom domain suffix, for App Service Environment v After completing the previous steps, you should continue with migration as soon as possible. > [!IMPORTANT]-> Since scaling is blocked during the migration, you should scale your environment to the desired size before starting the migration. +> Since scaling is blocked during the migration, you should scale your environment to the desired size before starting the migration. If you have auto-scaling enabled, if a scaling event occurs before the migration starts, you have to wait until the scaling event completes before starting the migration. You should disable auto-scaling before starting the migration to avoid this issue. If you need to scale your environment after the migration, you can do so once the migration is complete. > Migration requires a three to six hour service window for App Service Environment v2 to v3 migrations. Up to a six hour service window is required depending on environment size for v1 to v3 migrations. The service window might be extended in rare cases where manual intervention by the service team is required. During migration, scaling and environment configurations are blocked and the following events occur: Ensure that there are no locks on your virtual network, resource group, resource Ensure that no Azure policies are blocking actions that are required for the migration, including subnet modifications and Azure App Service resource creations. Policies that block resource modifications and creations can cause migration to get stuck or fail. -Since scaling is blocked during the migration, you should scale your environment to the desired size before starting the migration. If you need to scale your environment after the migration, you can do so once the migration is complete. +Since scaling is blocked during the migration, you should scale your environment to the desired size before starting the migration. If you need to scale your environment after the migration, you can do so once the migration is complete. If you have auto-scaling enabled, if a scaling event occurs before the migration starts, your migration is blocked until the scaling event completes. You should disable auto-scaling before starting the migration to avoid this issue. ::: zone pivot="experience-azcli" |
app-service | Side By Side Migrate | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/app-service/environment/side-by-side-migrate.md | After completing the previous steps, you should continue with migration as soon There's no application downtime during the migration, but as in the IP generation step, you can't scale, modify your existing App Service Environment, or deploy apps to it during this process. > [!IMPORTANT]-> Since scaling is blocked during the migration, you should scale your environment to the desired size before starting the migration. +> Since scaling is blocked during the migration, you should scale your environment to the desired size before starting the migration. If you have auto-scaling enabled, if a scaling event occurs before the migration starts, you have to wait until the scaling event completes before starting the migration. You should disable auto-scaling before starting the migration to avoid this issue. If you need to scale your environment after the migration, you can do so once the migration is complete. > This step is also where you decide if you want to enable zone redundancy for your new App Service Environment v3. Zone redundancy can be enabled as long as your App Service Environment v3 is [in a region that supports zone redundancy](./overview.md#regions). Ensure that no Azure policies are blocking actions that are required for the mig Since your App Service Environment v3 is in a different subnet in your virtual network, you need to ensure that you have an available subnet in your virtual network that meets the [subnet requirements for App Service Environment v3](./networking.md#subnet-requirements). The subnet you select must also be able to communicate with the subnet that your existing App Service Environment is in. Ensure there's nothing blocking communication between the two subnets. If you don't have an available subnet, you need to create one before migrating. Creating a new subnet might involve increasing your virtual network address space. For more information, see [Create a virtual network and subnet](../../virtual-network/manage-virtual-network.yml). -Since scaling is blocked during the migration, you should scale your environment to the desired size before starting the migration. If you need to scale your environment after the migration, you can do so once the migration is complete. +Since scaling is blocked during the migration, you should scale your environment to the desired size before starting the migration. If you need to scale your environment after the migration, you can do so once the migration is complete. If you have auto-scaling enabled, if a scaling event occurs before the migration starts, your migration is blocked until the scaling event completes. You should disable auto-scaling before starting the migration to avoid this issue. Follow the steps described here in order and as written, because you're making Azure REST API calls. We recommend that you use the Azure CLI to make these API calls. For information about other methods, see [Azure REST API reference](/rest/api/azure/). |
app-service | Version Comparison | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/app-service/environment/version-comparison.md | There's a new version of App Service Environment that is easier to use and runs |Subnet delegation |Not required |Not required |[Must be delegated to `Microsoft.Web/hostingEnvironments`](networking.md#subnet-requirements) | |Subnet size|An App Service Environment v1 with no App Service plans uses 12 addresses before you create an app. If you use an ILB App Service Environment v1, then it uses 13 addresses before you create an app. As you scale out, infrastructure roles are added at every multiple of 15 and 20 of your App Service plan instances. |An App Service Environment v2 with no App Service plans uses 12 addresses before you create an app. If you use an ILB App Service Environment v2, then it uses 13 addresses before you create an app. As you scale out, infrastructure roles are added at every multiple of 15 and 20 of your App Service plan instances. |Any particular subnet has five addresses reserved for management purposes. In addition to the management addresses, App Service Environment v3 dynamically scales the supporting infrastructure, and uses between 4 and 27 addresses, depending on the configuration and load. You can use the remaining addresses for instances in the App Service plan. The minimal size of your subnet can be a /27 address space (32 addresses). | |DNS fallback |Azure DNS |Azure DNS |[Ensure that you have a forwarder to a public DNS or include Azure DNS in the list of custom DNS servers](migrate.md#in-place-migration-feature-limitations) |+|Azure Application Gateway version compatibility |[v1](../../application-gateway/overview.md), [v2](../../application-gateway/overview-v2.md) |[v1](../../application-gateway/overview.md), [v2](../../application-gateway/overview-v2.md) |[v2](../../application-gateway/overview-v2.md) | ### Scaling |
application-gateway | Application Gateway Diagnostics | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/application-gateway/application-gateway-diagnostics.md | You have the following options to store the logs in your preferred location. * [AGWFirewallLogs](/azure/azure-monitor/reference/tables/agwfirewalllogs) > [!NOTE]-> The resource specific option is currently available in all **public regions**.<br> +> The resource specific option is currently available in all **clouds**.<br> > Existing users can continue using Azure Diagnostics, or can opt for dedicated tables by switching the toggle in Diagnostic settings to **Resource specific**, or to **Dedicated** in API destination. Dual mode isn't possible. The data in all the logs can either flow to Azure Diagnostics, or to dedicated tables. However, you can have multiple diagnostic settings where one data flow is to azure diagnostic and another is using resource specific at the same time. **Selecting the destination table in Log analytics :** All Azure services eventually use the resource-specific tables. As part of this transition, you can select Azure diagnostic or resource specific table in the diagnostic setting using a toggle button. The toggle is set to **Resource specific** by default and in this mode, logs for new selected categories are sent to dedicated tables in Log Analytics, while existing streams remain unchanged. See the following example. |
application-gateway | Prometheus Grafana | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/application-gateway/for-containers/prometheus-grafana.md | + + Title: Configure Application Gateway for Containers for Prometheus and Grafana +description: Configure Application Gateway for Containers metrics to be sent to Prometheus and displayed on Grafana. +++++ Last updated : 07/09/2024++++# Configure Application Gateway for Containers for Prometheus and Grafana ++Establishing monitoring for Application Gateway for Containers is crucial part of successful operations. Firstly, it allows you to visualize how traffic is controlled, providing actionable insights that help optimize performance and troubleshoot issues promptly. Secondly, monitoring enhances security measures by providing valuable insights during investigations, ensuring that your gateway remains secure and resilient against threats. Implementing monitoring for your Application Gateway for Containers not only supports ongoing performance optimization but also strengthens your overall security posture by enabling proactive detection and response capabilities. ++You can monitor Azure Application Gateway for Containers resources in the following ways. Refer to the diagram. +- [Backend Health Metrics](../../application-gateway/for-containers/application-gateway-for-containers-metrics.md): ALB Controller's metric and backend health endpoints exposes several metrics and summary of backend health. The metrics endpoint enables exposure to Prometheus. + +- [Metrics](../../application-gateway/for-containers/application-gateway-for-containers-metrics.md): Metrics and Activity Logs are exposed through Azure Monitor to monitor the performance of your Application Gateway for Containers deployments. The metrics contain numerical values in an ordered set of time-series data. + +- [Diagnostic Logs](../../application-gateway/for-containers/diagnostics.md): Access Logs audit all requests made to Application Gateway for Containers. Logs can provide several characteristics, such as the client's IP, requested URL, request latencies, return code, and bytes in and out. An access log is collected every 60 seconds. ++[![A diagram of architecture grid.](./media/prometheus-grafana/design-arch.png)](./media/prometheus-grafana/design-arch.png#lightbox) ++## Learn About the Services +- [What is Azure Managed Prometheus?](../../azure-monitor/essentials/prometheus-metrics-overview.md) + - Why use Prometheus: Azure Prometheus offers native integration and management capabilities, simplifying the setup and management of monitoring infrastructure. +- [What is Azure Managed Grafana?](../../managed-grafan) + - Why use Grafana: Azure Managed Grafana lets you bring together all your telemetry data into one place and Built-in support for Azure Monitor and Azure Data Explorer using Microsoft Entra identities. +- [What is Azure Log Analytics Workspace?](../../azure-monitor/logs/log-analytics-workspace-overview.md) + - Why use Log Analytics Workspace: Log Analytics workspace scales with your business needs, handling large volumes of log data efficiently and detects and diagnose issues quickly. + +## Prerequisites ++- An Azure account for work or school and an active subscription. You can create an account for free. +- Active Kubernetes cluster. +- Active Application Gateway for Container deployment. +- Active Resource Group with contributor permission. + > [!TIP] + > Alternative to Contributor role, you may also want to leverage the following: + > - Custom Role with 'microsoft.monitor/accounts/write'. + > - Read access. + > - Grafana Admin. + > - Log Analytics Contributor. + > - Monitoring Contributor permissions. + > [Learn more about custom roles here](https://aka.ms/custom-roles). ++ + +## Create new Applications for Configuration ++Complete the steps to configure prometheus and grafana. +1. Sign in to the [Azure portal](https://portal.azure.com) with your Azure account. +2. In **Search resources, service, and docs**, type **Application Gateways for Containers** and select your Kubernetes Cluster name. + + [ ![A screenshot of kubernetes insights.](./media/prometheus-grafana/configure.png) ](./media/prometheus-grafana/configure.png#lightbox) + +3. Under insights and select **Configure Monitoring**. + + [ ![A screenshot of monitoring metrics.](./media/prometheus-grafana/grafana-container.png) ](./media/prometheus-grafana/grafana-container.png#lightbox) ++ Create new instances of Log analytics, Azure Monitor (Prometheus), and Managed Grafana to store current Kubernetes cluster metrics. +4. In **Search resources, service, and docs**, type **Managed Prometheus** and select. + + [ ![A screenshot of Prometheus Managed.](./media/prometheus-grafana/managed-prometheus.png) ](./media/prometheus-grafana/managed-prometheus.png#lightbox) + +5. Follow the steps to enable Azure Monitor to enable Managed Prometheus service by selecting **Create**. +6. Create Azure Monitor Workspace Instance: + 1. In the **Create** an Azure Monitor Workspace page, select a subscription and resource group. + 2. Provide a name and a region for the workspace. + 3. Select **Review + create** to create the workspace. +7. Add Prometheus Config Map to your cluster: + 1. Copy this file to notepad or Visual Studio Code: https://github.com/Azure/prometheus-collector/blob/main/otelcollector/configmaps/ama-metrics-settings-configmap.yaml. + 2. Modify line 35 to set podannotationnamespaceregex from ΓÇ£ΓÇ¥ to "azure-alb-system". + ```Bash + # Example Kusto Query + podannotationnamespaceregex = "azure-alb-system" + ``` + 3. Save the file as configprometheus.yaml. + 4. Add file into CLI (command-line interfaces) under manage files. + 5. Run the following command: + ```Bash + # Run the Following Command in Bash + kubectl apply -f configprometheus.yaml + ``` +8. [Create a managed Grafana](../../managed-grafan). + Link a Grafana Workspace: + - In **Search resources, service, and docs**, type **Azure Monitor**. + - Select your monitor workspace. + - Select **Linked Grafana Workspaces**. + ![A screenshot of Grafana Link.](./media/prometheus-grafana/grafana-link.png) +9. Select a Grafana workspace. +10. Select **Link**. +++## Configure Kubernetes cluster for logging +We created the resources and now we combine all resources and configure prometheus. ++1. Cluster configuration + 1. In **Search resources, service, and docs**, search for your kubernetes cluster. + 2. Search for insights and Select on **Configure Monitoring**. +2. Specify each instance: + - Log analytics workspace: Use the default new log analytics workspace created for you. + - Managed Prometheus: Select on **ΓÇ£Enable Prometheus metricsΓÇ¥** checkbox. + - Select on advanced setting: specify the Azure monitor workspace recently created. + - Grafana Workspace: Select on **Enable Grafana** checkbox. + - Select on advanced setting: specify the Grafana instance recently created. + - Select **ΓÇ£ConfigureΓÇ¥**. + > [!NOTE] + > Check for ama-metrics under workloads in your kubernetes cluster. + > [ ![A screenshot of Checking Config.](./media/prometheus-grafana/notes-image.png) ](./media/prometheus-grafana/notes-image.png#lightbox) + +## Enable diagnostic logs for Application Gateway for Containers +Activity logging is automatically enabled for every Resource Manager resource. For Access Logs, you must enable access logging to start collecting the data available through those logs. To enable logging, you may configure diagnostic settings in Azure Monitor. ++1. [Create a log analytics workspace](../../azure-monitor/logs/quick-create-workspace.md). +2. Send logs from Application Gateway for Containers to log analytics workspace: + 1. Enter **Application Gateway for Containers** in the search box. Select your active Application Gateway for Container resource. + 2. Search and select Diagnostic Setting under Monitoring. Add diagnostic setting. + 3. Select a name, check box **allLogs** which includes the Application Gateway for Container Access Logs, and select **Send to Log analytics Workspace** with your desired subscription and recently made log analytics workspace. + [ ![A screenshot of Application Gateway for Containers Diagnostic Setting.](./media/prometheus-grafana/logs-all.png) ](./media/prometheus-grafana/logs-all.png#lightbox) ++3. Select **Save**. ++## Access Grafana dashboard +In this section, we enter Grafana default dashboards. ++1. In **Search resources, service, and docs**, select your **Managed Grafana**. +2. Select the grafana resource used for configuring monitoring in the cluster. +3. Select on Endpoint URL in the overview. + ![A screenshot of Grafana Endpoint.](./media/prometheus-grafana/grafana-end.png) ++4. After entering your user credentials, refer to the Grafana introduction. +5. Select on the left side bar to access default dashboards under dashboards. + ![A screenshot of Dafault Grafana Dashboard.](./media/prometheus-grafana/grafana-default.png) ++## Graph Prometheus metrics on Grafana ++In this section, we visualize a sample metric from Prometheus metrics. Refer to all Prometheus metrics availabilities here: [Prometheus Metrics](../../application-gateway/for-containers/application-gateway-for-containers-metrics.md). ++1. In the right top corner, Select **Add Dashboard**. +2. Select **Add Visualization**. +3. Search for prometheus under data source. +![A screenshot of Data Source Prometheus Dashboard.](./media/prometheus-grafana/data-source-prometheus.png) +4. Select desired metric. For Example: alb_controller_total_unhealthy_endpoints that gives any unhealthy endpoints of your backend service. +5. Choose app as alb-controller. +6. Select name of the panel, type of visualization, and time range. + ![A screenshot of Prometheus Logging Test.](./media/prometheus-grafana/prometheus-grafana-viewing.png) +7. **Save + Apply** of your panel to add into your dashboard. + > [!NOTE] + > Add a custom legend by {{variable_name}}. ++## Graph access logs and metrics on Grafana ++In this section, we visualize a sample logs from Log Analytics Workspace. Refer to all diagnostic Logs availabilities here: [Diagnostic Logs](../../application-gateway/for-containers/diagnostics.md). ++### Workspace for logs ++1. In the right top corner, Select **Add + Add Dashboard**. +2. Select **Add Visualization**. +3. Search for Azure Monitor under data source + **Add**. +![A screenshot of Log Data Source.](./media/prometheus-grafana/log-data-source.png) +4. Change service as **Logs**. +5. Type: + ```kusto + // Example Kusto Query + AGCAccessLogs + | project BackendResponseLatency, TimeGenerated + ``` +6. Select a **Time Series** as a visualization. +7. Select name, description, and time range of the panel. +![A screenshot of Application Gateway for Containers Logging Example.](./media/prometheus-grafana/logging-example.png) +8. **Save + Apply** to your dashboard. ++### Workspace for metrics ++1. In the right top corner, select **Add + Add Dashboard**. +2. Select **Add Visualization**. +3. Search for Azure Monitor under data source+ **Add**. +4. Change service as Metrics. +5. Select your application gateway for containers instance. +![[A screenshot of Metrics Log Data Source.](./media/prometheus-grafana/metrics-logs-datasource.png)](./media/prometheus-grafana/metrics-logs-datasource.png#lightbox) +6. Select metric namespace as microsoft.servicenetworking/trafficcontrollers. +7. Choose a metric such as **total requests** and type of data visualization. +[ ![A screenshot of Example Metrics Log Data Source.](./media/prometheus-grafana/metrics-logs.png) ](./media/prometheus-grafana/metrics-logs.png#lightbox) +8. Select a name, description, and time range of the panel. +9. **Save + Apply** to your dashboard. ++Congratulations! You set up a monitoring service to enhance your health tracking! |
azure-functions | Functions Bindings Openai | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-functions/functions-bindings-openai.md | zone_pivot_groups: programming-languages-set-functions [!INCLUDE [preview-support](../../includes/functions-openai-support-limitations.md)] -The Azure OpenAI extension for Azure Functions implements a set of triggers and bindings that enable you to easily integrate features and behaviors of the [Azure OpenAI service](../ai-services/openai/overview.md) into your function code executions. +The Azure OpenAI extension for Azure Functions implements a set of triggers and bindings that enable you to easily integrate features and behaviors of [Azure OpenAI Service](../ai-services/openai/overview.md) into your function code executions. Azure Functions is an event-driven compute service that provides a set of [triggers and bindings](./functions-triggers-bindings.md) to easily connect with other Azure services. |
azure-functions | Openapi Apim Integrate Visual Studio | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-functions/openapi-apim-integrate-visual-studio.md | The function uses an HTTP trigger that takes two parameters: The function then calculates how much a repair costs, and how much revenue the turbine could make in a 24-hour period. Parameters are supplied either in the query string or in the payload of a POST request. -In the Function1.cs project file, replace the contents of the generated class library code with the following code: +In the Turbine.cs project file, replace the contents of the generated class library code with the following code: This function code returns a message of `Yes` or `No` to indicate whether an emergency repair is cost-effective. It also returns the revenue opportunity that the turbine represents and the cost to fix the turbine. |
azure-functions | Security Concepts | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-functions/security-concepts.md | Defender for Cloud integrates with your function app in the portal. It provides, ### Log and monitor -One way to detect attacks is through activity monitoring and logging analytics. Functions integrates with Application Insights to collect log, performance, and error data for your function app. Application Insights automatically detects performance anomalies and includes powerful analytics tools to help you diagnose issues and to understand how your functions are used. To learn more, see [Monitor Azure Functions](functions-monitoring.md). +One way to detect attacks is through activity monitoring and logging analytics. Functions integrates with Application Insights to collect log, performance, and error data for your function app. Application Insights automatically detects performance anomalies and includes powerful analytics tools to help you diagnose issues and understand how your functions are used. To learn more, see [Monitor Azure Functions](functions-monitoring.md). -Functions also integrates with Azure Monitor Logs to enable you to consolidate function app logs with system events for easier analysis. You can use diagnostic settings to configure streaming export of platform logs and metrics for your functions to the destination of your choice, such as a Logs Analytics workspace. To learn more, see [Monitoring Azure Functions with Azure Monitor Logs](functions-monitor-log-analytics.md). +Functions also integrates with Azure Monitor Logs to enable you to consolidate function app logs with system events for easier analysis. You can use diagnostic settings to configure the streaming export of platform logs and metrics for your functions to the destination of your choice, such as a Logs Analytics workspace. To learn more, see [Monitoring Azure Functions with Azure Monitor Logs](functions-monitor-log-analytics.md). For enterprise-level threat detection and response automation, stream your logs and events to a Logs Analytics workspace. You can then connect Microsoft Sentinel to this workspace. To learn more, see [What is Microsoft Sentinel](../sentinel/overview.md). HTTP endpoints that are exposed publicly provide a vector of attack for maliciou ### Require HTTPS -By default, clients can connect to function endpoints by using both HTTP or HTTPS. You should redirect HTTP to HTTPs because HTTPS uses the SSL/TLS protocol to provide a secure connection, which is both encrypted and authenticated. To learn how, see [Enforce HTTPS](../app-service/configure-ssl-bindings.md#enforce-https). +By default, clients can connect to function endpoints by using either HTTP or HTTPS. You should redirect HTTP to HTTPS because HTTPS uses the SSL/TLS protocol to provide a secure connection, which is both encrypted and authenticated. To learn how, see [Enforce HTTPS](../app-service/configure-ssl-bindings.md#enforce-https). When you require HTTPS, you should also require the latest TLS version. To learn how, see [Enforce TLS versions](../app-service/configure-ssl-bindings.md#enforce-tls-versions). APIM provides various API security options for incoming requests. To learn more, ### Permissions -As with any application or service, the goal is run your function app with the lowest possible permissions. +As with any application or service, the goal is to run your function app with the lowest possible permissions. #### User management permissions Permissions are effective at the function app level. The Contributor role is req #### Organize functions by privilege -Connection strings and other credentials stored in application settings gives all of the functions in the function app the same set of permissions in the associated resource. Consider minimizing the number of functions with access to specific credentials by moving functions that don't use those credentials to a separate function app. You can always use techniques such as [function chaining](/training/modules/chain-azure-functions-data-using-bindings/) to pass data between functions in different function apps. +Connection strings and other credentials stored in application settings give all of the functions in the function app the same set of permissions in the associated resource. Consider minimizing the number of functions with access to specific credentials by moving functions that don't use those credentials to a separate function app. You can always use techniques such as [function chaining](/training/modules/chain-azure-functions-data-using-bindings/) to pass data between functions in different function apps. #### Managed identities While it's tempting to use a wildcard that allows all sites to access your endpo ### Managing secrets -To be able to connect to the various services and resources need to run your code, function apps need to be able to access secrets, such as connection strings and service keys. This section describes how to store secrets required by your functions. +To be able to connect to the various services and resources needed to run your code, function apps need to be able to access secrets, such as connection strings and service keys. This section describes how to store secrets required by your functions. Never store secrets in your function code. By default, you store connection strings and secrets used by your function app a For example, every function app requires an associated storage account, which is used by the runtime. By default, the connection to this storage account is stored in an application setting named `AzureWebJobsStorage`. -App settings and connection strings are stored encrypted in Azure. They're decrypted only before being injected into your app's process memory when the app starts. The encryption keys are rotated regularly. If you prefer to instead manage the secure storage of your secrets, the app setting should instead be references to Azure Key Vault. +App settings and connection strings are stored encrypted in Azure. They're decrypted only before being injected into your app's process memory when the app starts. The encryption keys are rotated regularly. If you prefer to manage the secure storage of your secrets, the app settings should instead be references to Azure Key Vault secrets. -You can also encrypt settings by default in the local.settings.json file when developing functions on your local computer. For more information, see [Encrypt the local settings file](functions-run-local.md#encrypt-the-local-settings-file). +You can also encrypt settings by default in the `local.settings.json` file when developing functions on your local computer. For more information, see [Encrypt the local settings file](functions-run-local.md#encrypt-the-local-settings-file). #### Key Vault references -While application settings are sufficient for most many functions, you may want to share the same secrets across multiple services. In this case, redundant storage of secrets results in more potential vulnerabilities. A more secure approach is to a central secret storage service and use references to this service instead of the secrets themselves. +While application settings are sufficient for most functions, you may want to share the same secrets across multiple services. In this case, redundant storage of secrets results in more potential vulnerabilities. A more secure approach is to use a central secret storage service and use references to this service instead of the secrets themselves. -[Azure Key Vault](../key-vault/general/overview.md) is a service that provides centralized secrets management, with full control over access policies and audit history. You can use a Key Vault reference in the place of a connection string or key in your application settings. To learn more, see [Use Key Vault references for App Service and Azure Functions](../app-service/app-service-key-vault-references.md?toc=/azure/azure-functions/toc.json). +[Azure Key Vault](../key-vault/general/overview.md) is a service that provides centralized secrets management, with full control over access policies and audit history. You can use a Key Vault reference in place of a connection string or key in your application settings. To learn more, see [Use Key Vault references for App Service and Azure Functions](../app-service/app-service-key-vault-references.md?toc=/azure/azure-functions/toc.json). ### Identity-based connections Some Azure Functions binding extensions can be configured to access services usi ### Set usage quotas -Consider setting a usage quota on functions running in a Consumption plan. When you set a daily GB-sec limit on the sum total execution of functions in your function app, execution is stopped when the limit is reached. This could potentially help mitigate against malicious code executing your functions. To learn how to estimate consumption for your functions, see [Estimating Consumption plan costs](functions-consumption-costs.md). +Consider setting a usage quota for functions running in a Consumption plan. When you set a daily GB-sec limit on the total execution of functions in your function app, execution is stopped when the limit is reached. This could potentially help mitigate against malicious code executing your functions. To learn how to estimate consumption for your functions, see [Estimating Consumption plan costs](functions-consumption-costs.md). ### Data validation Don't assume that the data coming into your function has already been validated ### Handle errors -While it seems basic, it's important to write good error handling in your functions. Unhandled errors bubble-up to the host and are handled by the runtime. Different bindings handle processing of errors differently. To learn more, see [Azure Functions error handling](functions-bindings-error-pages.md). +While it seems basic, it's important to write good error handling in your functions. Unhandled errors bubble up to the host and are handled by the runtime. Different bindings handle the processing of errors differently. To learn more, see [Azure Functions error handling](functions-bindings-error-pages.md). ### Disable remote debugging You should also consult the guidance for any resource types your application log ## Secure deployment -Azure Functions tooling an integration make it easy to publish local function project code to Azure. It's important to understand how deployment works when considering security for an Azure Functions topology. +Azure Functions tooling integration makes it easy to publish local function project code to Azure. It's important to understand how deployment works when considering security for an Azure Functions topology. ### Deployment credentials FTP isn't recommended for deploying your function code. FTP deployments are manu When you're not planning on using FTP, you should disable it in the portal. If you do choose to use FTP, you should [enforce FTPS](../app-service/deploy-ftp.md#enforce-ftps). -### Secure the scm endpoint +### Secure the `scm` endpoint -Every function app has a corresponding `scm` service endpoint that used by the Advanced Tools (Kudu) service for deployments and other App Service [site extensions](https://github.com/projectkudu/kudu/wiki/Azure-Site-Extensions). The scm endpoint for a function app is always a URL in the form `https://<FUNCTION_APP_NAME.scm.azurewebsites.net>`. When you use network isolation to secure your functions, you must also account for this endpoint. +Every function app has a corresponding `scm` service endpoint that is used by the Advanced Tools (Kudu) service for deployments and other App Service [site extensions](https://github.com/projectkudu/kudu/wiki/Azure-Site-Extensions). The `scm` endpoint for a function app is always a URL in the form `https://<FUNCTION_APP_NAME>.scm.azurewebsites.net`. When you use network isolation to secure your functions, you must also account for this endpoint. -By having a separate scm endpoint, you can control deployments and other advanced tools functionalities for function app that are isolated or running in a virtual network. The scm endpoint supports both basic authentication (using deployment credentials) and single sign-on with your Azure portal credentials. To learn more, see [Accessing the Kudu service](https://github.com/projectkudu/kudu/wiki/Accessing-the-kudu-service). +By having a separate `scm` endpoint, you can control deployments and other Advanced Tools functionalities for function apps that are isolated or running in a virtual network. The `scm` endpoint supports both basic authentication (using deployment credentials) and single sign-on with your Azure portal credentials. To learn more, see [Accessing the Kudu service](https://github.com/projectkudu/kudu/wiki/Accessing-the-kudu-service). ### Continuous security validation Restricting network access to your function app lets you control who can access ### Set access restrictions -Access restrictions allow you to define lists of allow/deny rules to control traffic to your app. Rules are evaluated in priority order. If there are no rules defined, then your app will accept traffic from any address. To learn more, see [Azure App Service Access Restrictions](../app-service/app-service-ip-restrictions.md?toc=/azure/azure-functions/toc.json). +Access restrictions allow you to define lists of allow/deny rules to control traffic to your app. Rules are evaluated in priority order. If no rules are defined, your app will accept traffic from any address. To learn more, see [Azure App Service Access Restrictions](../app-service/app-service-ip-restrictions.md?toc=/azure/azure-functions/toc.json). ### Secure the storage account |
azure-government | Compare Azure Government Global Azure | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-government/compare-azure-government-global-azure.md | The following features of Azure OpenAI are available in Azure Government: |Feature|Azure OpenAI| |--|--|-|Models available|US Gov Arizona:<br> GPT-4o (2024-05-13) GPT-4 (1106-Preview)<br> GPT-3.5-Turbo (1106)<br> GPT-3.5-Turbo (0125)<br> text-embedding-ada-002 (version 2)<br><br>US Gov Virginia:<br> GPT-4 (1106-Preview)<br> GPT-3.5-Turbo (0125)<br> text-embedding-ada-002 (version 2)<br><br>Learn more about the different capabilities of each model in [Azure OpenAI Service models](../ai-services/openai/concepts/models.md)| +|Models available|US Gov Arizona:<br> GPT-4o (2024-05-13) GPT-4 (1106-Preview)<br> GPT-3.5-Turbo (0125) GPT-3.5-Turbo (1106)<br> text-embedding-ada-002 (version 2)<br><br>US Gov Virginia:<br> GPT-4o (2024-05-13) GPT-4 (1106-Preview)<br> GPT-3.5-Turbo (0125)<br> text-embedding-ada-002 (version 2)<br><br>Learn more about the different capabilities of each model in [Azure OpenAI Service models](../ai-services/openai/concepts/models.md)| |Virtual network support & private link support| Yes. | | Connect your data | Available in US Gov Virginia and Arizona. Virtual network and private links are supported. Deployment to a web app or a copilot in Copilot Studio is not supported. | |Managed Identity|Yes, via Microsoft Entra ID| The following features of Azure OpenAI are available in Azure Government: |Data Storage|In AOAI, customer data is only stored at rest as part of our Finetuning solution. Since Finetuning is not enabled within Azure Gov, there is no customer data stored at rest in Azure Gov associated with AOAI. However, Customer Managed Keys (CMK) can still be enabled in Azure Gov to support use of the same policies in Azure Gov as in Public cloud. Note also that if Finetuning is enabled in Azure Gov in the future, any existing CMK deployment would be applied to that data at that time.| **Next steps**-* Get started by requesting access to Azure OpenAI Service in Azure Government at [https://aka.ms/AOAIgovaccess](https://aka.ms/AOAIgovaccess) -* Request quota increases for the pay-as-you-go consumption model, please fill out a separate form at [https://aka.ms/AOAIGovQuota](https://aka.ms/AOAIGovQuota) +* To request quota increases for the pay-as-you-go consumption model, apply at [https://aka.ms/AOAIGovQuota](https://aka.ms/AOAIGovQuota) * If modified content filters are required, apply at [https://aka.ms/AOAIGovModifyContentFilter](https://aka.ms/AOAIGovModifyContentFilter) |
azure-maps | About Azure Maps | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/about-azure-maps.md | Title: Overview for Microsoft Azure Maps description: Learn about services and capabilities in Microsoft Azure Maps and how to use them in your applications.--++ Last updated 10/21/2022 |
azure-maps | Android Map Add Line Layer | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/android-map-add-line-layer.md | |
azure-maps | Android Map Events | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/android-map-events.md | |
azure-maps | Azure Maps Event Grid Integration | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/azure-maps-event-grid-integration.md | Title: React to Azure Maps events by using Event Grid description: Find out how to react to Azure Maps events involving geofences. See how to listen to map events and how to use Event Grid to reroute events to event handlers.--++ Last updated 01/08/2024 |
azure-maps | Clustering Point Data Android Sdk | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/clustering-point-data-android-sdk.md | |
azure-maps | Create Data Source Android Sdk | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/create-data-source-android-sdk.md | |
azure-maps | Data Driven Style Expressions Android Sdk | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/data-driven-style-expressions-android-sdk.md | |
azure-maps | Display Feature Information Android | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/display-feature-information-android.md | |
azure-maps | Geocoding Coverage | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/geocoding-coverage.md | Title: Geocoding coverage in Microsoft Azure Maps Search service description: See which regions Azure Maps Search covers. Geocoding categories include address points, house numbers, street level, city level, and points of interest.--++ Last updated 11/30/2021 |
azure-maps | Geofence Geojson | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/geofence-geojson.md | Title: GeoJSON data format for geofence | Microsoft Azure Maps description: Learn about Azure Maps geofence data. See how to use the GET Geofence and POST Geofence APIs when retrieving the position of coordinates relative to a geofence.--++ Last updated 02/14/2019 |
azure-maps | Geographic Coverage | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/geographic-coverage.md | Title: Geographic coverage information in Microsoft Azure Maps description: Details of where geographic data is available within Microsoft Azure Maps.--++ Last updated 6/23/2021 |
azure-maps | Geographic Scope | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/geographic-scope.md | Title: Azure Maps service geographic scope description: Learn about Azure Maps service's geographic mappings--++ Last updated 04/18/2022 |
azure-maps | Glossary | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/glossary.md | Title: Azure Maps Glossary | Microsoft Docs description: A glossary of commonly used terms associated with Azure Maps, Location-Based Services, and GIS. --++ Last updated 09/18/2018 |
azure-maps | How To Add Shapes To Android Map | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-add-shapes-to-android-map.md | |
azure-maps | How To Add Symbol To Android Map | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-add-symbol-to-android-map.md | |
azure-maps | How To Add Tile Layer Android Map | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-add-tile-layer-android-map.md | |
azure-maps | How To Create Template | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-create-template.md | Title: Create your Azure Maps account using an Azure Resource Manager template in Azure Maps description: Learn how to create an Azure Maps account using an Azure Resource Manager template.--++ Last updated 04/27/2021 |
azure-maps | How To Dev Guide Java Sdk | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-dev-guide-java-sdk.md | |
azure-maps | How To Manage Account Keys | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-manage-account-keys.md | Title: Manage your Azure Maps account in the Azure portal | Microsoft Azure Maps description: Learn how to use the Azure portal to manage an Azure Maps account. See how to create a new account and how to delete an existing account.--++ Last updated 04/26/2021 |
azure-maps | How To Manage Pricing Tier | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-manage-pricing-tier.md | Title: Manage your Azure Maps account's pricing tier description: You can use the Azure portal to manage your Microsoft Azure Maps account and its pricing tier.--++ Last updated 09/14/2023 |
azure-maps | How To Secure Sas App | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-secure-sas-app.md | |
azure-maps | How To Show Traffic Android | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-show-traffic-android.md | |
azure-maps | How To Use Android Map Control Library | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-use-android-map-control-library.md | |
azure-maps | How To Use Feedback Tool | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/how-to-use-feedback-tool.md | Title: Provide data feedback to Azure Maps description: Provide data feedback using Microsoft Azure Maps feedback tool.--++ Last updated 03/15/2024 |
azure-maps | Map Add Bubble Layer Android | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/map-add-bubble-layer-android.md | |
azure-maps | Map Add Controls Android | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/map-add-controls-android.md | |
azure-maps | Map Add Heat Map Layer Android | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/map-add-heat-map-layer-android.md | |
azure-maps | Map Add Image Layer Android | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/map-add-image-layer-android.md | |
azure-maps | Map Extruded Polygon Android | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/map-extruded-polygon-android.md | |
azure-maps | Migrate Bing Maps Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/migrate-bing-maps-overview.md | Title: Migrate from Bing Maps to Azure Maps overview description: Overview for the migration guides that show how to migrate code from Bing Maps to Azure Maps.--++ Last updated 05/16/2024 |
azure-maps | Migrate From Google Maps Android App | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/migrate-from-google-maps-android-app.md | |
azure-maps | Migrate From Google Maps | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/migrate-from-google-maps.md | Title: 'Tutorial - Migrate from Google Maps to Azure Maps | Microsoft Azure Maps' description: Tutorial on how to migrate from Google Maps to Microsoft Azure Maps. Guidance walks you through how to switch to Azure Maps APIs and SDKs.--++ Last updated 09/23/2020 |
azure-maps | Open Source Projects | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/open-source-projects.md | Title: Azure Maps community Open-source projects | Microsoft Azure Maps description: Open-source projects coordinated for the Microsoft Azure Maps platform.--++ Last updated 12/07/2020 |
azure-maps | Quick Android Map | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/quick-android-map.md | Last updated 09/22/2022 -+ zone_pivot_groups: azure-maps-android |
azure-maps | Rest Sdk Developer Guide | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/rest-sdk-developer-guide.md | |
azure-maps | Set Android Map Styles | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/set-android-map-styles.md | |
azure-maps | Supported Browsers | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/supported-browsers.md | Title: Web SDK supported browsers description: Find out how to check whether the Azure Maps Web SDK supports a browser. View a list of supported browsers. Learn how to use map services with legacy browsers.--++ Last updated 06/22/2023 |
azure-maps | Supported Languages | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/supported-languages.md | Title: Localization support in Microsoft Azure Maps description: Lists the regions Azure Maps supports with services such as maps, search, routing, weather, and traffic incidents, and shows how to set up the View parameter.--++ Last updated 01/05/2022 |
azure-maps | Supported Map Styles | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/supported-map-styles.md | Title: Supported built-in Azure Maps map styles description: Learn about the built-in map styles that Azure Maps supports, such as road, blank_accessible, satellite, satellite_road_labels, road_shaded_relief, and night.--++ Last updated 11/01/2023 |
azure-maps | Tutorial Load Geojson File Android | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/tutorial-load-geojson-file-android.md | |
azure-maps | Understanding Azure Maps Transactions | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-maps/understanding-azure-maps-transactions.md | Title: Understanding Microsoft Azure Maps Transactions description: Learn about Microsoft Azure Maps Transactions--++ Last updated 04/05/2024 |
azure-monitor | Azure Monitor Agent Data Field Differences | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-monitor/agents/azure-monitor-agent-data-field-differences.md | This table collects log data from the Internet Information Service on Window sys ### Windows event table This table collects Events from the Windows Event log. There are two other tables that are used to store Windows events, the SecurityEvent and Event tables.+ |LAW Field | Difference | Reason| Additional Information | ||||| | UserName | MMA enriches the event with the username prior to sending the event for ingestion. AMA do not do the same enrichment. | The AMA enrichment is not yet implemented. | AMA principles dictate that the event data should remain unchanged by default. Adding and enriched field adds possible processing errors and additional cost for storage. In this case, the customer demand for the field is very high and work is underway to add the username. | |
azure-monitor | Azure Monitor Agent Extension Versions | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-monitor/agents/azure-monitor-agent-extension-versions.md | We strongly recommended to always update to the latest version, or opt in to the ## Version details | Release Date | Release notes | Windows | Linux | |:|:|:|:|-| July 2024 | **Windows**<ul><li>Security hardening of Agent data folder.</li><li>Fixed credential leaks in agent logs.</li><li>Various bug fix for AzureWatson.</li><li>Added columns to the Windows Event table: Keywords, UserName, Opcode, Correlation, ProcessId, ThreadId, EventRecordId.</li><li>AMA: Support for private preview of Agent side transformation.</li><li>AMA: Support AMA Client Installer for selected partners.</li></ul>**Linux Features**<ul><li>Enable Dynamic Linking of OpenSSL 1.1 in all regions</li><li>Add Computer field to Custom Logs</li><li>Add EventHub upload support for Custom Logs </li><li>Reliability improvement for upload task scheduling</li><li>Added support for SUSE15 SP5, Ubuntu 24, and AWS 3 distributions</li></ul>**Linux Fixes**<ul><li>Fix Direct upload to storage for perf counters when no other destination is configured. You don't see perf counters If storage was the only configured destination for perf counters, they wouldn't see perf counters in their blob or table.</li><li>Fix proxy for system-wide proxy using http(s)_proxy env var </li><li>Support for syslog hostnames that are up to 255characters</li><li>Stop sending rows longer than 1MB. This exceeds ingestion limits and destabilizes the agent. Now the row is gracefully dropped and a diagnostic message is written.</li><li>Set max disk space used for rsyslog spooling to 1GB. There was no limit before which could lead to high memory usage.</li><li>Use random available TCP port when there is a port conflict with AMA port 28230 and 28330 . This resolved issues where port 28230 and 28330 were already in uses by the customer which prevented data upload to Azure.</li></ul>| 1.29 | 1.32.2 | +| July 2024 | **Windows**<ul><li>Security hardening of Agent data folder.</li><li>Fixed credential leaks in agent logs.</li><li>Various bug fix for AzureWatson.</li><li>Added columns to the Windows Event table: Keywords, UserName, Opcode, Correlation, ProcessId, ThreadId, EventRecordId.</li><li>AMA: Support for private preview of Agent side transformation.</li><li>AMA: Support AMA Client Installer for selected partners.</li></ul>**Linux Features**<ul><li>Enable Dynamic Linking of OpenSSL 1.1 in all regions</li><li>Add Computer field to Custom Logs</li><li>Add EventHub upload support for Custom Logs </li><li>Reliability improvement for upload task scheduling</li><li>Added support for SUSE15 SP5, Ubuntu 24, and AWS 3 distributions</li></ul>**Linux Fixes**<ul><li>Fix Direct upload to storage for perf counters when no other destination is configured. You don't see perf counters If storage was the only configured destination for perf counters, they wouldn't see perf counters in their blob or table.</li><li>Fluent-Bit updated to version 3.0.7. This fixes the issue with Fluent-Bit creating junk files in the root directory on process shutdown.</li><li>Fix proxy for system-wide proxy using http(s)_proxy env var </li><li>Support for syslog hostnames that are up to 255characters</li><li>Stop sending rows longer than 1MB. This exceeds ingestion limits and destabilizes the agent. Now the row is gracefully dropped and a diagnostic message is written.</li><li>Set max disk space used for rsyslog spooling to 1GB. There was no limit before which could lead to high memory usage.</li><li>Use random available TCP port when there is a port conflict with AMA port 28230 and 28330 . This resolved issues where port 28230 and 28330 were already in uses by the customer which prevented data upload to Azure.</li></ul>| 1.29 | 1.32.2 | | June 2024 |**Windows**<ul><li>Fix encoding issues with Resource ID field.</li><li>AMA: Support new ingestion endpoint for GovSG environment.</li><li>Upgrade AzureSecurityPack version to 4.33.0.1.</li><li>Upgrade Metrics Extension version to 2.2024.517.533.</li><li>Upgrade Health Extension version to 2024.528.1.</li></ul>**Linux**<ul><li>Coming Soon</li></ul>| 1.28.2 | | | May 2024 |**Windows**<ul><li>Upgraded Fluent-bit version to 3.0.5. This Fix resolves as security issue in fluent-bit (NVD - CVE-2024-4323 (nist.gov)</li><li>Disabled Fluent-bit logging that caused disk exhaustion issues for some customers. Example error is Fluentbit log with "[C:\projects\fluent-bit-2e87g\src\flb_scheduler.c:72 errno=0] No error" fills up the entire disk of the server.</li><li>Fixed AMA extension getting stuck in deletion state on some VMs that are using Arc. This fix improves reliability.</li><li>Fixed AMA not using system proxy, this issue is a bug introduced in 1.26.0. The issue was caused by a new feature that uses the Arc agentΓÇÖs proxy settings. When the system proxy as set as None the proxy was broken in 1.26.</li><li>Fixed Windows Firewall Logs log file rollover issues</li></ul>| 1.27.0 | | | April 2024 |**Windows**<ul><li>In preparation for the May 17 public preview of Firewall Logs, the agent completed the addition of a profile filter for Domain, Public, and Private Logs. </li><li>AMA running on an Arc enabled server will default to using the Arc proxy settings if available.</li><li>The AMA VM extension proxy settings override the Arc defaults.</li><li>Bug fix in MSI installer: Symptom - If there are spaces in the fluent-bit config path, AMA wasn't recognizing the path properly. AMA now adds quotes to configuration path in fluent-bit.</li><li>Bug fix for Container Insights: Symptom - custom resource ID weren't being honored.</li><li>Security issue fix: skip the deletion of files and directory whose path contains a redirection (via Junction point, Hard links, Mount point, OB Symlinks etc.).</li><li>Updating MetricExtension package to 2.2024.328.1744.</li></ul>**Linux**<ul><li>AMA 1.30 now available in Arc.</li><li>New distribution support Debian 12, RHEL CIS L2.</li><li>Fix for mdsd version 1.30.3 in persistence mode, which converted positive integers to float/double values ("3.0", "4.0") to type ulong which broke Azure stream analytics.</li></ul>| 1.26.0 | 1.31.1 | |
azure-monitor | Azure Monitor Agent Migration | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-monitor/agents/azure-monitor-agent-migration.md | A SCOM Admin Management Pack exists and can help you remove the workspace config - Sentinel: Windows Firewall logs aren't generally available (GA) yet. - SQL Assessment Solution: This is now part of SQL best practice assessment. The deployment policies require one Log Analytics Workspace per subscription, which isn't the best practice recommended by the AMA team. - Microsoft Defender for cloud: Some features for the new agent-less solution are in development. Your migration maybe impacted if you use File Integrity Monitoring (FIM), Endpoint protection discovery recommendations, OS Misconfigurations (Azure Security Benchmark (ASB) recommendations) and Adaptive Application controls.-- Container Insights: The Windows version is in public preview. ## Next steps |
azure-monitor | Logs Dedicated Clusters | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-monitor/logs/logs-dedicated-clusters.md | After you create your cluster resource, you can edit properties such as *sku*, * Deleted clusters take two weeks to be completely removed. You can have up to seven clusters per subscription and region, five active, and two deleted in past two weeks. > [!NOTE]-> Cluster creation triggers resource allocation and provisioning. This operation can take a few hours to complete. +> Creating a cluster involves multiple resources and operation typically complete in two hours. > Dedicated cluster is billed once provisioned regardless data ingestion and it's recommended to prepare the deployment to expedite the provisioning and workspaces link to cluster. Verify the following: > - A list of initial workspace to be linked to cluster is identified > - You have permissions to subscription intended for the cluster and any workspace to be linked N/A > [!NOTE] > - Linking a workspace can be performed only after the completion of the Log Analytics cluster provisioning.-> - Linking a workspace to a cluster involves syncing multiple backend components and cache hydration, which can take up to two hours. -> - When linking a Log Analytics workspace workspace, the workspace billing plan in changed to *LACluster*, and you should remove sku in workspace template to prevent conflict during workspace deployment. +> - Linking a workspace to a cluster involves syncing multiple backend components and cache hydration, which typically complete in two hours. +> - When linking a Log Analytics workspace workspace, the workspace billing plan in changed to *LACluster*, and you should remove SKU in workspace template to prevent conflict during workspace deployment. > - Other than the billing aspects that is governed by the cluster plan, all workspace configurations and query aspects remain unchanged during and after the link. You need 'write' permissions to both the workspace and the cluster resource for workspace link operation: |
azure-netapp-files | Large Volumes Requirements Considerations | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-netapp-files/large-volumes-requirements-considerations.md | The following requirements and considerations apply to large volumes. For perfor * A regular volume canΓÇÖt be converted to a large volume. * You must create a large volume at a size of 50 TiB or larger. A single volume can't exceed 1 PiB. * You can't resize a large volume to less than 50 TiB.- A large volume cannot be resized to less than 30% of its lowest provisioned size. This limit is adjustable via [a support request](azure-netapp-files-resource-limits.md#resource-limits). + A large volume cannot be resized to more than 30% of its lowest provisioned size. This limit is adjustable via [a support request](azure-netapp-files-resource-limits.md#resource-limits). * Large volumes are currently not supported with Azure NetApp Files backup. * You can't create a large volume with application volume groups. * Currently, large volumes aren't suited for database (HANA, Oracle, SQL Server, etc.) data and log volumes. For database workloads requiring more than a single volumeΓÇÖs throughput limit, consider deploying multiple regular volumes. To optimize multiple volume deployments for databases, use [application volume groups](application-volume-group-concept.md). |
azure-resource-manager | Azure Subscription Service Limits | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/azure-resource-manager/management/azure-subscription-service-limits.md | Title: Azure subscription limits and quotas description: Provides a list of common Azure subscription and service limits, quotas, and constraints. This article includes information on how to increase limits along with maximum values. Previously updated : 06/13/2024 Last updated : 07/19/2024 # Azure subscription and service limits, quotas, and constraints This section provides information about limits that apply to Azure API Managemen * [API Management classic tiers](#limitsapi-management-classic-tiers) * [API Management v2 tiers](#limitsapi-management-v2-tiers)+* [API Management workspaces](#limitsapi-management-workspaces) * [Developer portal in API Management v2 tiers](#limitsdeveloper-portal-in-api-management-v2-tiers) ### Limits - API Management classic tiers This section provides information about limits that apply to Azure API Managemen [!INCLUDE [api-management-service-limits-v2](../../../includes/api-management-service-limits-v2.md)] +### Limits - API Management workspaces +++ ### Limits - Developer portal in API Management v2 tiers [!INCLUDE [api-management-developer-portal-limits-v2](../../../includes/api-management-developer-portal-limits-v2.md)] |
communication-services | Capabilities | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/communication-services/concepts/interop/guest/capabilities.md | This article describes which capabilities Azure Communication Services SDKs supp | | [Customer managed keys](/microsoft-365/compliance/customer-key-overview) | ✔️ | | Mid-call control | Turn your video on/off | ✔️ | | | Mute/unmute mic | ✔️ |+| | Mute remote participants | ✔️ | | | Switch between cameras | ✔️ | | | Local hold/unhold | ✔️ | | | Indicator of dominant speakers in the call | ✔️ | |
communication-services | Call Transcription | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/communication-services/how-tos/calling-sdk/call-transcription.md | -zone_pivot_groups: acs-plat-ios-android-windows --#Customer intent: As a developer, I want to display the call transcription state on the client. +zone_pivot_groups: acs-plat-web-ios-android-windows # Display call transcription state on the client -> [!NOTE] -> Call transcription state is only available from Teams meetings. Currently there's no support for call transcription state for Azure Communication Services to Azure Communication Services calls. --When using call transcription you may want to let your users know that a call is being transcribe. Here's how. +You need to collect consent from all participants in the call before you can transcribe them. Microsoft Teams allows users to start transcription in the meetings or calls. You would receive event when transcription has started on you can check the transcription state, if transcription started before you joined the call or meeting. ## Prerequisites When using call transcription you may want to let your users know that a call is - A user access token to enable the calling client. For more information, see [Create and manage access tokens](../../quickstarts/identity/access-tokens.md). - Optional: Complete the quickstart to [add voice calling to your application](../../quickstarts/voice-video-calling/getting-started-with-calling.md) +## Support +The following tables define support of call transcription in Azure Communication Services. ++## Identities and call types +The following tables show support of transcription for specific call type and identity. ++|Identities | Teams meeting | Room | 1:1 call | Group call | 1:1 Teams interop call | Group Teams interop call | +|--|||-|||--| +|Communication Services user | ✔️ | | | | ✔️ | ✔️ | +|Microsoft 365 user | ✔️ | | | | ✔️ | ✔️ | ++## Operations +The following tables show support of individual APIs in calling SDK to individual identity types. ++|Operations | Communication Services user | Microsoft 365 user | +|--||-| +|Get event that transcription has started | ✔️ | ✔️ | +|Get transcription state | ✔️ | ✔️ | +|Start or stop transcription | | | ++## SDKs +The following tables show support of transcription in individual Azure Communication Services SDKs. ++| Platforms | Web | Web UI | iOS | iOS UI | Android | Android UI | Windows | +|-|--|--|--|--|||| +|Is Supported | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ++ ::: zone pivot="platform-android" [!INCLUDE [Call transcription client-side Android](./includes/call-transcription/call-transcription-android.md)] ::: zone-end |
container-apps | Aspire Dashboard | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/aspire-dashboard.md | You can enable the .NET Aspire Dashboard on any existing container app using the ```azurecli dotnet new aspire-starter azd init --location westus2-azd config set alpha.aspire.dashboard on +azd config set aspire.dashboard on azd up ``` |
container-apps | Dapr Authentication Token | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/dapr-authentication-token.md | |
container-apps | Dapr Component Connection | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/dapr-component-connection.md | |
container-apps | Dapr Component Resiliency | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/dapr-component-resiliency.md | resource myPolicyDoc 'Microsoft.App/managedEnvironments/daprComponents/resilienc ### Before you begin -Log-in to the Azure CLI: +Log in to the Azure CLI: ```azurecli az login |
container-apps | Dapr Components | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/dapr-components.md | |
container-apps | Dapr Functions Extension | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/dapr-functions-extension.md | The [Dapr extension for Azure Functions](../azure-functions/functions-bindings-d ## Set up the environment -1. In the terminal, log into your Azure subscription. +1. In the terminal, log in to your Azure subscription. ```azurecli az login |
container-apps | Dapr Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/dapr-overview.md | Title: Dapr integration with Azure Container Apps + Title: Microservice APIs powered by Dapr description: Learn more about using Dapr on your Azure Container App service to develop applications. Previously updated : 04/22/2024 Last updated : 08/05/2024 -# Dapr integration with Azure Container Apps +# Microservice APIs powered by Dapr -[Distributed Application Runtime (Dapr)][dapr-concepts] provides APIs that run as a sidecar process that helps you write and implement simple, portable, resilient, and secured microservices. Dapr works together with Azure Container Apps as an abstraction layer to provide a low-maintenance, serverless, and scalable platform. [Enabling Dapr on your container app][dapr-enable] creates a secondary process alongside your application code that simplifies application intercommunication with Dapr via HTTP or gRPC. +Azure Container Apps provides APIs powered by [Distributed Application Runtime (Dapr)][dapr-concepts] that help you write and implement simple, portable, resilient, and secured microservices. Dapr works together with Azure Container Apps as an abstraction layer to provide a low-maintenance and scalable platform. Azure Container Apps offers a selection of fully managed Dapr APIs, components, and features, catered specifically to microservice scenarios. Simply [enable and configure Dapr][dapr-enable] as usual in your container app environment. -## Dapr in Azure Container Apps +## How the microservices APIs work with your container app -Configure Dapr for your container apps environment with a [Dapr-enabled container app][dapr-enable], a [Dapr component configured for your solution][dapr-components], and a Dapr sidecar invoking communication between them. The following diagram demonstrates these core concepts related to Dapr in Azure Container Apps. +Configure microservices APIs for your container apps environment with a [Dapr-enabled container app][dapr-enable], a [Dapr component configured for your solution][dapr-components], and a Dapr sidecar invoking communication between them. The following diagram demonstrates these core concepts, using the pub/sub API as an example. :::image type="content" source="media/dapr-overview/dapr-in-aca.png" alt-text="Diagram demonstrating Dapr pub/sub and how it works in Container Apps."::: Azure Container Apps ensures compatibility with Dapr open source tooling, such a - **Actor reminders**: Require a minReplicas of 1+ to ensure reminders is always active and fires correctly. - **Jobs**: Dapr isn't supported for jobs. -## Next Steps +## Next steps - [Enable Dapr in your container app.][dapr-enable] - [Learn how Dapr components work in Azure Container Apps.][dapr-components] |
container-apps | Deploy Visual Studio Code | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/deploy-visual-studio-code.md | description: Deploy containerized .NET applications to Azure Container Apps usin -+ Last updated 10/29/2023 |
container-apps | Deploy Visual Studio | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/deploy-visual-studio.md | description: Deploy your containerized .NET applications to Azure Container Apps -+ Last updated 3/04/2022 |
container-apps | Microservices Dapr Bindings | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/microservices-dapr-bindings.md | Title: "Tutorial: Event-driven work using Dapr Bindings" -description: Deploy a sample Dapr Bindings application to Azure Container Apps. +description: Deploy a sample application to Azure Container Apps that leverages the Dapr Bindings API. Previously updated : 12/20/2023 Last updated : 08/02/2024 zone_pivot_group_filename: container-apps/dapr-zone-pivot-groups.json zone_pivot_groups: dapr-languages-set zone_pivot_groups: dapr-languages-set In this tutorial, you create a microservice to demonstrate [Dapr's Bindings API](https://docs.dapr.io/developing-applications/building-blocks/bindings/bindings-overview/) to work with external systems as inputs and outputs. You'll: > [!div class="checklist"]-> * Run the application locally. +> * Run the application locally with the Dapr CLI. > * Deploy the application to Azure Container Apps via the Azure Developer CLI with the provided Bicep. The service listens to input binding events from a system CRON and then outputs the contents of local data to a PostreSql output binding. ## Prerequisites Before deploying the application to Azure Container Apps, start by running the P ### Prepare the project -1. Clone the [sample Dapr application](https://github.com/Azure-Samples/bindings-dapr-nodejs-cron-postgres) to your local machine. +1. Clone the [sample application](https://github.com/Azure-Samples/bindings-dapr-nodejs-cron-postgres) to your local machine. ```bash git clone https://github.com/Azure-Samples/bindings-dapr-nodejs-cron-postgres.git Before deploying the application to Azure Container Apps, start by running the P cd bindings-dapr-nodejs-cron-postgres ``` -### Run the Dapr application using the Dapr CLI +### Run the application using the Dapr CLI 1. From the sample's root directory, change directories to `db`. Before deploying the application to Azure Container Apps, start by running the P npm install ``` -1. Run the JavaScript service application with Dapr. +1. Run the JavaScript service application. ```bash dapr run --app-id batch-sdk --app-port 5002 --dapr-http-port 3500 --resources-path ../components -- node index.js ``` - The `dapr run` command runs the Dapr binding application locally. Once the application is running successfully, the terminal window shows the output binding data. + The `dapr run` command runs the binding application locally. Once the application is running successfully, the terminal window shows the output binding data. #### Expected output Before deploying the application to Azure Container Apps, start by running the P docker compose stop ``` -## Deploy the Dapr application template using Azure Developer CLI +## Deploy the application template using Azure Developer CLI -Now that you've run the application locally, let's deploy the Dapr bindings application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). During deployment, we will swap the local containerized PostgreSQL for an Azure PostgreSQL component. +Now that you've run the application locally, let's deploy the bindings application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). During deployment, we will swap the local containerized PostgreSQL for an Azure PostgreSQL component. ### Prepare the project cd bindings-dapr-nodejs-cron-postgres | Azure Location | The Azure location for your resources. [Make sure you select a location available for Azure PostgreSQL](../postgresql/flexible-server/overview.md#azure-regions). | | Azure Subscription | The Azure subscription for your resources. | -1. Run `azd up` to provision the infrastructure and deploy the Dapr application to Azure Container Apps in a single command. +1. Run `azd up` to provision the infrastructure and deploy the application to Azure Container Apps in a single command. ```azdeveloper azd up Upon successful completion of the `azd up` command: ### Prepare the project -1. Clone the [sample Dapr application](https://github.com/Azure-Samples/bindings-dapr-python-cron-postgres) to your local machine. +1. Clone the [sample application](https://github.com/Azure-Samples/bindings-dapr-python-cron-postgres) to your local machine. ```bash git clone https://github.com/Azure-Samples/bindings-dapr-python-cron-postgres.git Upon successful completion of the `azd up` command: cd bindings-dapr-python-cron-postgres ``` -### Run the Dapr application using the Dapr CLI +### Run the application using the Dapr CLI Before deploying the application to Azure Container Apps, start by running the PostgreSQL container and Python service locally with [Docker Compose](https://docs.docker.com/compose/) and Dapr. Before deploying the application to Azure Container Apps, start by running the P pip install -r requirements.txt ``` -1. Run the Python service application with Dapr. +1. Run the Python service application. ```bash dapr run --app-id batch-sdk --app-port 5001 --dapr-http-port 3500 --resources-path ../components -- python3 app.py ``` - The `dapr run` command runs the Dapr binding application locally. Once the application is running successfully, the terminal window shows the output binding data. + The `dapr run` command runs the binding application locally. Once the application is running successfully, the terminal window shows the output binding data. #### Expected output Before deploying the application to Azure Container Apps, start by running the P docker compose stop ``` -## Deploy the Dapr application template using Azure Developer CLI +## Deploy the application template using Azure Developer CLI -Now that you've run the application locally, let's deploy the Dapr bindings application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). During deployment, we will swap the local containerized PostgreSQL for an Azure PostgreSQL component. +Now that you've run the application locally, let's deploy the bindings application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). During deployment, we will swap the local containerized PostgreSQL for an Azure PostgreSQL component. ### Prepare the project cd bindings-dapr-python-cron-postgres | Azure Location | The Azure location for your resources. [Make sure you select a location available for Azure PostgreSQL](../postgresql/flexible-server/overview.md#azure-regions). | | Azure Subscription | The Azure subscription for your resources. | -1. Run `azd up` to provision the infrastructure and deploy the Dapr application to Azure Container Apps in a single command. +1. Run `azd up` to provision the infrastructure and deploy the application to Azure Container Apps in a single command. ```azdeveloper azd up Upon successful completion of the `azd up` command: ### Prepare the project -1. Clone the [sample Dapr application](https://github.com/Azure-Samples/bindings-dapr-csharp-cron-postgres) to your local machine. +1. Clone the [sample application](https://github.com/Azure-Samples/bindings-dapr-csharp-cron-postgres) to your local machine. ```bash git clone https://github.com/Azure-Samples/bindings-dapr-csharp-cron-postgres.git Upon successful completion of the `azd up` command: cd bindings-dapr-csharp-cron-postgres ``` -### Run the Dapr application using the Dapr CLI +### Run the application using the Dapr CLI Before deploying the application to Azure Container Apps, start by running the PostgreSQL container and .NET service locally with [Docker Compose](https://docs.docker.com/compose/) and Dapr. Before deploying the application to Azure Container Apps, start by running the P dotnet build ``` -1. Run the .NET service application with Dapr. +1. Run the .NET service application. ```bash dapr run --app-id batch-sdk --app-port 7002 --resources-path ../components -- dotnet run ``` - The `dapr run` command runs the Dapr binding application locally. Once the application is running successfully, the terminal window shows the output binding data. + The `dapr run` command runs the binding application locally. Once the application is running successfully, the terminal window shows the output binding data. #### Expected output Before deploying the application to Azure Container Apps, start by running the P docker compose stop ``` -## Deploy the Dapr application template using Azure Developer CLI +## Deploy the application template using Azure Developer CLI -Now that you've run the application locally, let's deploy the Dapr bindings application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). During deployment, we will swap the local containerized PostgreSQL for an Azure PostgreSQL component. +Now that you've run the application locally, let's deploy the bindings application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). During deployment, we will swap the local containerized PostgreSQL for an Azure PostgreSQL component. ### Prepare the project cd bindings-dapr-csharp-cron-postgres | Azure Location | The Azure location for your resources. [Make sure you select a location available for Azure PostgreSQL](../postgresql/flexible-server/overview.md#azure-regions). | | Azure Subscription | The Azure subscription for your resources. | -1. Run `azd up` to provision the infrastructure and deploy the Dapr application to Azure Container Apps in a single command. +1. Run `azd up` to provision the infrastructure and deploy the application to Azure Container Apps in a single command. ```azdeveloper azd up azd down ## Next steps -- Learn more about [deploying Dapr applications to Azure Container Apps](./microservices-dapr.md).+- Learn more about [deploying microservices using Dapr to Azure Container Apps](./microservices-dapr.md). - [Enable token authentication for Dapr requests.](./dapr-authentication-token.md) - Learn more about [Azure Developer CLI](/azure/developer/azure-developer-cli/overview) and [making your applications compatible with `azd`](/azure/developer/azure-developer-cli/make-azd-compatible).-- [Scale your Dapr applications using KEDA scalers](./dapr-keda-scaling.md)+- [Scale your applications using KEDA scalers](./dapr-keda-scaling.md) |
container-apps | Microservices Dapr Pubsub | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/microservices-dapr-pubsub.md | Title: "Tutorial: Microservices communication using Dapr Publish and Subscribe" -description: Enable two sample Dapr applications to send and receive messages and leverage Azure Container Apps. +description: Enable two sample applications to send and receive messages and leverage the Dapr pub/sub API. Previously updated : 12/20/2023 Last updated : 08/05/2024 zone_pivot_group_filename: container-apps/dapr-zone-pivot-groups.json zone_pivot_groups: dapr-languages-set -# Tutorial: Microservices communication using Dapr Publish and Subscribe +# Tutorial: Microservices communication using Dapr Publish and Subscribe ++In this tutorial, you create publisher and subscriber microservices that leverage [the Dapr Pub/sub API](./dapr-overview.md#supported-dapr-apis-components-and-tooling) to communicate using messages for event-driven architectures. You'll: -In this tutorial, you'll: > [!div class="checklist"]-> * Create a publisher microservice and a subscriber microservice that leverage the [Dapr pub/sub API](https://docs.dapr.io/developing-applications/building-blocks/pubsub/pubsub-overview/) to communicate using messages for event-driven architectures. +> * Create a publisher microservice and a subscriber microservice that leverage the [Dapr pub/sub API](https://docs.dapr.io/developing-applications/building-blocks/pubsub/pubsub-overview/) to communicate using messages for event-driven architectures. > * Deploy the application to Azure Container Apps via the Azure Developer CLI with provided Bicep. The sample pub/sub project includes:-1. A message generator (publisher) `checkout` service that generates messages of a specific topic. -1. An (subscriber) `order-processor` service that listens for messages from the `checkout` service of a specific topic. +1. A message generator `checkout` service (publisher) that generates messages of a specific topic. +1. An `order-processor` service (subscriber) that listens for messages from the `checkout` service of a specific topic. ## Prerequisites Before deploying the application to Azure Container Apps, run the `order-process ### Prepare the project -1. Clone the [sample Dapr application](https://github.com/Azure-Samples/pubsub-dapr-nodejs-servicebus) to your local machine. +1. Clone the [sample application](https://github.com/Azure-Samples/pubsub-dapr-nodejs-servicebus) to your local machine. ```bash git clone https://github.com/Azure-Samples/pubsub-dapr-nodejs-servicebus.git Before deploying the application to Azure Container Apps, run the `order-process cd pubsub-dapr-nodejs-servicebus ``` -### Run the Dapr applications using the Dapr CLI +### Run the applications using the Dapr CLI -Start by running the `order-processor` subscriber service with Dapr. +Start by running the `order-processor` subscriber service. 1. From the sample's root directory, change directories to `order-processor`. Start by running the `order-processor` subscriber service with Dapr. npm install ``` -1. Run the `order-processor` service with Dapr. +1. Run the `order-processor` service. ```bash dapr run --app-port 5001 --app-id order-processing --app-protocol http --dapr-http-port 3501 --resources-path ../components -- npm run start Start by running the `order-processor` subscriber service with Dapr. npm install ``` -1. Run the `checkout` service with Dapr. +1. Run the `checkout` service. ```bash dapr run --app-id checkout --app-protocol http --resources-path ../components -- npm run start Start by running the `order-processor` subscriber service with Dapr. dapr stop --app-id order-processor ``` -## Deploy the Dapr application template using Azure Developer CLI +## Deploy the application template using Azure Developer CLI -Deploy the Dapr application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). +Deploy the application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). ### Prepare the project cd pubsub-dapr-nodejs-servicebus | Azure Location | The Azure location for your resources. | | Azure Subscription | The Azure subscription for your resources. | -1. Run `azd up` to provision the infrastructure and deploy the Dapr application to Azure Container Apps in a single command. +1. Run `azd up` to provision the infrastructure and deploy the application to Azure Container Apps in a single command. ```azdeveloper azd up Before deploying the application to Azure Container Apps, run the `order-process ### Prepare the project -1. Clone the [sample Dapr application](https://github.com/Azure-Samples/pubsub-dapr-python-servicebus) to your local machine. +1. Clone the [sample application](https://github.com/Azure-Samples/pubsub-dapr-python-servicebus) to your local machine. ```bash git clone https://github.com/Azure-Samples/pubsub-dapr-python-servicebus.git Before deploying the application to Azure Container Apps, run the `order-process cd pubsub-dapr-python-servicebus ``` -### Run the Dapr applications using the Dapr CLI +### Run the applications using the Dapr CLI -Start by running the `order-processor` subscriber service with Dapr. +Start by running the `order-processor` subscriber service. 1. From the sample's root directory, change directories to `order-processor`. Start by running the `order-processor` subscriber service with Dapr. pip3 install -r requirements.txt ``` -1. Run the `order-processor` service with Dapr. +1. Run the `order-processor` service. ```bash dapr run --app-id order-processor --resources-path ../components/ --app-port 5001 -- python3 app.py Start by running the `order-processor` subscriber service with Dapr. pip3 install -r requirements.txt ``` -1. Run the `checkout` service with Dapr. +1. Run the `checkout` service. ```bash dapr run --app-id checkout --resources-path ../components/ -- python3 app.py Start by running the `order-processor` subscriber service with Dapr. dapr stop --app-id order-processor ``` -## Deploy the Dapr application template using Azure Developer CLI +## Deploy the application template using Azure Developer CLI -Deploy the Dapr application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). +Deploy the application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). ### Prepare the project cd pubsub-dapr-python-servicebus | Azure Location | The Azure location for your resources. | | Azure Subscription | The Azure subscription for your resources. | -1. Run `azd up` to provision the infrastructure and deploy the Dapr application to Azure Container Apps in a single command. +1. Run `azd up` to provision the infrastructure and deploy the application to Azure Container Apps in a single command. ```azdeveloper azd up Before deploying the application to Azure Container Apps, run the `order-process ### Prepare the project -1. Clone the [sample Dapr application](https://github.com/Azure-Samples/pubsub-dapr-csharp-servicebus) to your local machine. +1. Clone the [sample application](https://github.com/Azure-Samples/pubsub-dapr-csharp-servicebus) to your local machine. ```bash git clone https://github.com/Azure-Samples/pubsub-dapr-csharp-servicebus.git Before deploying the application to Azure Container Apps, run the `order-process cd pubsub-dapr-csharp-servicebus ``` -### Run the Dapr applications using the Dapr CLI +### Run the applications using the Dapr CLI -Start by running the `order-processor` subscriber service with Dapr. +Start by running the `order-processor` subscriber service 1. From the sample's root directory, change directories to `order-processor`. Start by running the `order-processor` subscriber service with Dapr. dotnet build ``` -1. Run the `order-processor` service with Dapr. +1. Run the `order-processor` service. ```bash dapr run --app-id order-processor --resources-path ../components/ --app-port 7001 -- dotnet run --project . Start by running the `order-processor` subscriber service with Dapr. dotnet build ``` -1. Run the `checkout` service with Dapr. +1. Run the `checkout` service. ```bash dapr run --app-id checkout --resources-path ../components/ -- dotnet run --project . Start by running the `order-processor` subscriber service with Dapr. dapr stop --app-id order-processor ``` -## Deploy the Dapr application template using Azure Developer CLI +## Deploy the application template using Azure Developer CLI -Deploy the Dapr application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). +Deploy the application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). ### Prepare the project cd pubsub-dapr-csharp-servicebus | Azure Location | The Azure location for your resources. | | Azure Subscription | The Azure subscription for your resources. | -1. Run `azd up` to provision the infrastructure and deploy the Dapr application to Azure Container Apps in a single command. +1. Run `azd up` to provision the infrastructure and deploy the application to Azure Container Apps in a single command. ```azdeveloper azd up azd down ## Next steps -- Learn more about [deploying Dapr applications to Azure Container Apps](./microservices-dapr.md).+- Learn more about [deploying applications to Azure Container Apps](./microservices-dapr.md). - [Enable token authentication for Dapr requests.](./dapr-authentication-token.md) - Learn more about [Azure Developer CLI](/azure/developer/azure-developer-cli/overview) and [making your applications compatible with `azd`](/azure/developer/azure-developer-cli/make-azd-compatible).-- [Scale your Dapr applications using KEDA scalers](./dapr-keda-scaling.md)+- [Scale your applications using KEDA scalers](./dapr-keda-scaling.md) |
container-apps | Microservices Dapr Service Invoke | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/microservices-dapr-service-invoke.md | -# Tutorial: Microservices communication using Dapr Service Invocation +# Tutorial: Microservices communication using Dapr Service Invocation ++In this tutorial, you create and run two microservices that communicate securely using auto-mTLS and reliably using built-in retries via [the Dapr Service Invocation API](./dapr-overview.md#supported-dapr-apis-components-and-tooling). You'll: -In this tutorial, you'll: > [!div class="checklist"]-> * Create and run locally two microservices that communicate securely using auto-mTLS and reliably using built-in retries via [Dapr's Service Invocation API](https://docs.dapr.io/developing-applications/building-blocks/service-invocation/service-invocation-overview/). +> * Run the application locally. > * Deploy the application to Azure Container Apps via the Azure Developer CLI with the provided Bicep. The sample service invocation project includes:-1. A `checkout` service that uses Dapr's HTTP proxying capability on a loop to invoke a request on the `order-processor` service. -1. A `order-processor` service that receives the request from the `checkout` service. +1. A `checkout` service that uses HTTP proxying on a loop to invoke a request on the `order-processor` service. +1. An `order-processor` service that receives the request from the `checkout` service. ## Prerequisites Before deploying the application to Azure Container Apps, start by running the ` ### Prepare the project -1. Clone the [sample Dapr application](https://github.com/Azure-Samples/svc-invoke-dapr-nodejs) to your local machine. +1. Clone the [sample applications](https://github.com/Azure-Samples/svc-invoke-dapr-nodejs) to your local machine. ```bash git clone https://github.com/Azure-Samples/svc-invoke-dapr-nodejs.git Before deploying the application to Azure Container Apps, start by running the ` cd svc-invoke-dapr-nodejs ``` -### Run the Dapr applications using the Dapr CLI +### Run the applications using the Dapr CLI Start by running the `order-processor` service. Start by running the `order-processor` service. npm install ``` -1. Run the `order-processor` service with Dapr. +1. Run the `order-processor` service. ```bash dapr run --app-port 5001 --app-id order-processor --app-protocol http --dapr-http-port 3501 -- npm start Start by running the `order-processor` service. npm install ``` -1. Run the `checkout` service with Dapr. +1. Run the `checkout` service. ```bash dapr run --app-id checkout --app-protocol http --dapr-http-port 3500 -- npm start Start by running the `order-processor` service. 1. Press <kbd>Cmd/Ctrl</kbd> + <kbd>C</kbd> in both terminals to exit out of the service-to-service invocation. -## Deploy the Dapr application template using Azure Developer CLI +## Deploy the application template using Azure Developer CLI -Deploy the Dapr application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). +Deploy the application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). ### Prepare the project In a new terminal window, navigate into the sample's root directory. | Azure Location | The Azure location for your resources. | | Azure Subscription | The Azure subscription for your resources. | -1. Run `azd up` to provision the infrastructure and deploy the Dapr application to Azure Container Apps in a single command. +1. Run `azd up` to provision the infrastructure and deploy the application to Azure Container Apps in a single command. ```azdeveloper azd up Before deploying the application to Azure Container Apps, start by running the ` ### Prepare the project -1. Clone the [sample Dapr application](https://github.com/Azure-Samples/svc-invoke-dapr-python) to your local machine. +1. Clone the [sample applications](https://github.com/Azure-Samples/svc-invoke-dapr-python) to your local machine. ```bash git clone https://github.com/Azure-Samples/svc-invoke-dapr-python.git Before deploying the application to Azure Container Apps, start by running the ` cd svc-invoke-dapr-python ``` -### Run the Dapr applications using the Dapr CLI +### Run the applications using the Dapr CLI Start by running the `order-processor` service. Start by running the `order-processor` service. pip3 install -r requirements.txt ``` -1. Run the `order-processor` service with Dapr. +1. Run the `order-processor` service. ```bash dapr run --app-port 8001 --app-id order-processor --app-protocol http --dapr-http-port 3501 -- python3 app.py Start by running the `order-processor` service. pip3 install -r requirements.txt ``` -1. Run the `checkout` service with Dapr. +1. Run the `checkout` service. ```bash dapr run --app-id checkout --app-protocol http --dapr-http-port 3500 -- python3 app.py Start by running the `order-processor` service. 1. Press <kbd>Cmd/Ctrl</kbd> + <kbd>C</kbd> in both terminals to exit out of the service-to-service invocation -## Deploy the Dapr application template using Azure Developer CLI +## Deploy the application template using Azure Developer CLI -Deploy the Dapr application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). +Deploy the application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). ### Prepare the project Deploy the Dapr application to Azure Container Apps using [`azd`](/azure/develop | Azure Location | The Azure location for your resources. | | Azure Subscription | The Azure subscription for your resources. | -1. Run `azd up` to provision the infrastructure and deploy the Dapr application to Azure Container Apps in a single command. +1. Run `azd up` to provision the infrastructure and deploy the application to Azure Container Apps in a single command. ```azdeveloper azd up Before deploying the application to Azure Container Apps, start by running the ` ### Prepare the project -1. Clone the [sample Dapr application](https://github.com/Azure-Samples/svc-invoke-dapr-csharp) to your local machine. +1. Clone the [sample applications](https://github.com/Azure-Samples/svc-invoke-dapr-csharp) to your local machine. ```bash git clone https://github.com/Azure-Samples/svc-invoke-dapr-csharp.git Before deploying the application to Azure Container Apps, start by running the ` cd svc-invoke-dapr-csharp ``` -### Run the Dapr applications using the Dapr CLI +### Run the applications using the Dapr CLI -Start by running the `order-processor` callee service with Dapr. +Start by running the `order-processor` callee service. 1. From the sample's root directory, change directories to `order-processor`. Start by running the `order-processor` callee service with Dapr. dotnet build ``` -1. Run the `order-processor` service with Dapr. +1. Run the `order-processor` service. ```bash dapr run --app-port 7001 --app-id order-processor --app-protocol http --dapr-http-port 3501 -- dotnet run Start by running the `order-processor` callee service with Dapr. dotnet build ``` -1. Run the `checkout` service with Dapr. +1. Run the `checkout` service. ```bash dapr run --app-id checkout --app-protocol http --dapr-http-port 3500 -- dotnet run Start by running the `order-processor` callee service with Dapr. 1. Press <kbd>Cmd/Ctrl</kbd> + <kbd>C</kbd> in both terminals to exit out of the service-to-service invocation. -## Deploy the Dapr application template using Azure Developer CLI +## Deploy the application template using Azure Developer CLI -Deploy the Dapr application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). +Deploy the application to Azure Container Apps using [`azd`](/azure/developer/azure-developer-cli/overview). ### Prepare the project In a new terminal window, navigate into the [sample's](https://github.com/Azure- | Azure Location | The Azure location for your resources. | | Azure Subscription | The Azure subscription for your resources. | -1. Run `azd up` to provision the infrastructure and deploy the Dapr application to Azure Container Apps in a single command. +1. Run `azd up` to provision the infrastructure and deploy the application to Azure Container Apps in a single command. ```azdeveloper azd up |
container-apps | Microservices | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/microservices.md | +- [Dapr integration](./dapr-overview.md) :::image type="content" source="media/microservices/azure-container-services-microservices.png" alt-text="Container apps are deployed as microservices."::: |
container-apps | Service Discovery Resiliency | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/container-apps/service-discovery-resiliency.md | resource myPolicyDoc 'Microsoft.App/containerApps/resiliencyPolicies@2023-11-02- ### Before you begin -Log-in to the Azure CLI: +Log in to the Azure CLI: ```azurecli az login |
cost-management-billing | Direct Ea Administration | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/cost-management-billing/manage/direct-ea-administration.md | Anyone with access to view the request can view its details. In the request deta :::image type="content" source="./media/direct-ea-administration/request-details.png" alt-text="Screenshot showing request details to view Accept ownership URL." lightbox="./media/direct-ea-administration/request-details.png" ::: +> [!NOTE] +> You can now view the **Service tenant ID** for subscriptions billed to your account on the **Azure Subscriptions** page under __Cost Management + Billing.__ ## Cancel a subscription Only account owners can cancel their own subscriptions. The Azure EA customer is opted out of the extended term, and the Azure EA enroll **Transferred**<br> Enrollments where all associated accounts and services were transferred to a new enrollment appear with a transferred status.- > [!NOTE] - > Enrollments don't automatically transfer if a new enrollment number is generated at renewal. You must include your prior enrollment number in your renewal paperwork to facilitate an automatic transfer. -+> [!NOTE] +> Enrollments don't automatically transfer if a new enrollment number is generated at renewal. You must include your prior enrollment number in your renewal paperwork to facilitate an automatic transfer. ## Related content - If you need to create an Azure support request for your EA enrollment, see [How to create an Azure support request for an Enterprise Agreement issue](../troubleshoot-billing/how-to-create-azure-support-request-ea.md). |
ddos-protection | Test Through Simulations | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/ddos-protection/test-through-simulations.md | RedWolf's [DDoS Testing](https://www.redwolfsecurity.com/services/) service suit - **Attack Vectors**: Unique cloud attacks designed by RedWolf. For more information about RedWolf attack vectors, see [Technical Details](https://www.redwolfsecurity.com/redwolf-technical-details/). - **Guided Service**: Leverage RedWolf's team to run tests. For more information about RedWolf's guided service, see [Guided Service](https://www.redwolfsecurity.com/managed-testing-explained/).- - **Self Service**: Leverage RedWol to run tests yourself. For more information about RedWolf's self-service, see [Self Service](https://www.redwolfsecurity.com/self-serve-testing/). + - **Self Service**: Leverage RedWolf to run tests yourself. For more information about RedWolf's self-service, see [Self Service](https://www.redwolfsecurity.com/self-serve-testing/). ## MazeBolt |
defender-for-cloud | Concept Regulatory Compliance Standards | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/defender-for-cloud/concept-regulatory-compliance-standards.md | The following standards are available in Defender for Cloud: | Australian Government ISM Protected | AWS Foundational Security Best Practices | Brazilian General Personal Data Protection Law (LGPD)| | Canada Federal PBMM | AWS Well-Architected Framework | California Consumer Privacy Act (CCPA)| | CIS Azure Foundations | Brazilian General Personal Data Protection Law (LGPD) | CIS Controls|-| CIS Azure Kubernetes Service (AKS)| California Consumer Privacy Act (CCPA) | CIS GCP Foundations| -| CMMC | CIS AWS Foundations | CIS Google Cloud Platform Foundation Benchmark| -| FedRAMP ΓÇÿHΓÇÖ & ΓÇÿMΓÇÖ | CRI Profile | CIS Google Kubernetes Engine (GKE) Benchmark| -| HIPAA/HITRUST | CSA Cloud Controls Matrix (CCM) | CRI Profile| -| ISO/IEC 27001 | GDPR | CSA Cloud Controls Matrix (CCM)| -| New Zealand ISM Restricted | ISO/IEC 27001 | Cybersecurity Maturity Model Certification (CMMC)| -| NIST SP 800-171 | ISO/IEC 27002 | FFIEC Cybersecurity Assessment Tool (CAT)| -| NIST SP 800-53 | NIST Cybersecurity Framework (CSF) | GDPR| -| PCI DSS | NIST SP 800-172 | ISO/IEC 27001| -| RMIT Malaysia | PCI DSS | ISO/IEC 27002| -| SOC 2 | | ISO/IEC 27017| +| CIS Azure Kubernetes Service (AKS Benchmark) | California Consumer Privacy Act (CCPA) | CIS GCP Foundations| +| CMMC |CIS Amazon Elastic Kubernetes Service (EKS) Benchmark| CIS Google Cloud Platform Foundation Benchmark| +| FedRAMP ΓÇÿHΓÇÖ & ΓÇÿMΓÇÖ | CIS AWS Foundations | CIS Google Kubernetes Engine (GKE) Benchmark| +| HIPAA/HITRUST | CRI Profile | CRI Profile| +| ISO/IEC 27001 | CSA Cloud Controls Matrix (CCM) | CSA Cloud Controls Matrix (CCM)| +| New Zealand ISM Restricted | GDPR | Cybersecurity Maturity Model Certification (CMMC)| +| NIST SP 800-171 | ISO/IEC 27001 | FFIEC Cybersecurity Assessment Tool (CAT)| +| NIST SP 800-53 | ISO/IEC 27002 | GDPR| +| PCI DSS | NIST Cybersecurity Framework (CSF) | ISO/IEC 27001| +| RMIT Malaysia | NIST SP 800-172 | ISO/IEC 27002| +| SOC 2 | PCI DSS | ISO/IEC 27017| | SWIFT CSP CSCF | | NIST Cybersecurity Framework (CSF)| | UK OFFICIAL and UK NHS | | NIST SP 800-53 | | | | NIST SP 800-171| |
defender-for-iot | Dell Edge 3200 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/defender-for-iot/organizations/appliance-catalog/dell-edge-3200.md | The following image shows a view of the Dell Edge Gateway 3200 back panel: |Management|iDRAC Group Manager, Disabled | |Rack support| Wall mount/ DIN rail support | -## Dell Edge Gateway 3200 - Bill of Materials +## Dell Edge Gateway 3200 - Bill of materials |type|Description| |-|-| |
defender-for-iot | Dell Poweredge R660 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/defender-for-iot/organizations/appliance-catalog/dell-poweredge-r660.md | + + Title: Dell PowerEdge R660 for operational technology (OT) monitoring - Microsoft Defender for IoT +description: Learn about the Dell PowerEdge R660 appliance's configuration when used for OT monitoring with Microsoft Defender for IoT in enterprise deployments. Last updated : 07/29/2024++++# Dell PowerEdge R660 ++This article describes the Dell PowerEdge R660 appliance, supported for operational technology (OT) sensors in an enterprise deployment. +The Dell PowerEdge R660 is also available for the on-premises management console. ++|Appliance characteristic | Description| +||| +|**Hardware profile** | R660 | +|**Performance** | Max bandwidth: 3 Gbps<br>Max devices: 12,000 | +|**Physical Specifications** | Mounting: 1U with rail kit<br>Ports: 6x RJ45 1 GbE| +|**Status** | Supported, available as a preconfigured appliance| ++The following image shows a view of the Dell PowerEdge R660 front panel: +++The following image shows a view of the Dell PowerEdge R660 back panel: +++## Specifications ++|Component| Technical specifications| +|:-|:-| +|Chassis| 1U rack server| +|Dimensions| Height: 1.68 in / 42.8 mm <br>Width: 18.97 in / 482.0 cm<br>Depth: 23.04 in / 585.3 mm (without bezel) 23.57 in / 598.9 mm (with bezel)| +|Processor| Intel Xeon E-2434 3.4 GHz <br>8M Cache<br> 4C/8T, Turbo, HT (55 W) DDR5-4800| +|Memory| 128 GB | +|Storage| 7.2 TB Hard Drive | +|Network controller| - PowerEdge R660 Motherboard with Broadcom 5720 Dual Port 1 Gb On-Board LOM, <br>- PCIe Blank Filler, Low Profile. <br>- Intel Ethernet i350 Quad Port 1 GbE BASE-T Adapter, PCIe Low Profile, V2| +|Management|iDRAC Group Manager, Disabled| +|Rack support| ReadyRails Sliding Rails With Cable Management Arm| ++## Dell PowerEdge R660 - Bill of Materials ++### Components ++|Quantity|PN| Module| Description| +|-||-|| +|1| 210-BFUZ | Base | PowerEdge R660xs | +|1| 461-AAIG | Trusted platform module | Trusted platform module 2.0 V3 | +|1| 470-AFQI | Chassis configuration | 2.5" Chassis with up to 8 Hard Drives (SAS/SATA), 2 CPU | +|1| 338-CKVW | Processor | Intel Xeon Silver 4410T 2.7 G 10C/20T, 16 GT/s, 27 M caches, Turbo, HT (150 W) DDR5-4000 | +|1| 338-CKVW | Additional processor | Intel Xeon Silver 4410T 2.7 G 10C/20T, 16 GT/s, 27 M caches, Turbo, HT (150 W) DDR5-4000 | +|1| 379-BDCO | Additional processor | Additional processor selected | +|1| 338-CHQT | Processor thermal configuration | Heatsink for 2 CPU configuration (CPU less than or equal to 150 W)| +|1| 370-AAIP | Memory configuration type | Performance Optimized | +|1| 370-AHCL | Memory DIMM type and speed | 4800-MT/s RDIMMs | +|4| 370-AGZP | Memory capacity | 32 GB RDIMM, 4,800 MT/s dual rank | +|1| 780-BCDS | RAID configuration | unconfigured RAID | +|1| 405-AAZB | RAID controller | PERC H755 SAS Front | +|1| 750-ACFR | RAID controller | Front PERC Mechanical Parts, front load | +|6| 161-BCBX | Hard drives | 2.4 TB Hard Drive SAS ISE 12 Gbps 10k 512e 2.5in Hot Plug | +|1| 384-BBBH | BIOS and Advanced System Configuration Settings | Power Saving BIOS Settings | +|1| 387-BBEY | Advanced System Configurations | No Energy Star | +|1| 384-BDJC | Fans | Standard Fan X7 | +|1| 528-CTIC | Embedded Systems Management | iDRAC9, Enterprise 16G | +|1| 450-AKLF | Power supply | Dual, Redundant(1+1), Hot-Plug Power Supply, 1100 W MM(100-240Vac) Titanium | +|2| 450-AADY | Power cords | C13 to C14, PDU Style, 10 AMP, 6.5 Feet (2 m), Power Cord | +|1| 330-BCCE | PCIe Riser | Riser Config 6, Low profile, 1x 16 LP slots (Gen 5) + 1x8 LP Slot (Gen 5), 2 CPU | +|1| 384-BDKV | Motherboard | PowerEdge R660xs Motherboard with Broadcom 5720 Dual Port 1 Gb On-Board LOM | +|1| 540-BCOB | Network daughter card | Broadcom 5720 Quad Port 1 GbE BASE-T Adapter, OCP NIC 3.0 | +|1| 350-BCEL | Quick sync | Quick Sync 2 (At-the-box mgmt) | +|1| 379-BCSF | Password | iDRAC, Factory Generated Password | +|1| 379-BCQX | IDRAC service module | iDRAC Service Module (ISM), NOT Installed | +|1| 379-BCQV | Group manager | iDRAC group manager, Enabled | +|1| 325-BEVH | Bezel | PowerEdge 1U Standard Bezel | +|1| 350-BEUF | Bezel | Dell Luggage Tag, 0/6/8/10 | +|1| 770-BCJI | Rack rails | A11 drop-in/stab-in Combo Rails Without Cable Management Arm | +|1| 340-DLRR | Shipping | PowerEdge R660XS Shipping EMEA1 (English/French/German/Spanish/Russian/Hebrew) | +|1| 340-DFKP | Shipping material | PowerEdge R660xs, 8x2.5, Short Drive Shipping Material | +|1| 389-FBMD | Regulatory |PowerEdge R660xs HS5610 Label, CE and CCC Marking, for below 1,300 W PSU | +|1| 683-11870 | Dell ++### Software ++|Quantity|PN| Module| Description| +|-||-|| +|1| 800-BBDM | Advanced system configuration | UEFI BIOS Boot Mode with GPT Partition | +|1| 528-COYT | Embedded Systems Management | Secured Component Verification | +|1| 611-BBBF | Operating system | No operating system | +|1| 605-BBFN | OS media kits | No media required | +|1| 631-AACK | System documentation | No Systems Documentation, No OpenManage DVD Kit | ++### Service ++|Quantity|PN| Module| Description| +|-||-|| +|1| 293-10049 | Shipping Box Labels - Standard | Order Configuration Shipbox Label (Ship Date, Model, Processor Speed, HDD Size, RAM) | +|1| 865-BBLL | Dell +|1| 865-BBLM | Dell +|1| 709-BBIX | Dell ++## Install Defender for IoT software on the DELL R660 ++This procedure describes how to install Defender for IoT software on the Dell R660. ++The installation process takes about 20 minutes. During the installation, the system restarts several times. ++To install Defender for IoT software: ++1. Connect the screen and keyboard to the appliance, and then connect to the CLI. ++1. Connect an external CD or disk-on-key that contains the software you downloaded from the Azure portal. ++1. Start the appliance. ++1. Continue with the generic procedure for installing Defender for IoT software. For more information, see [Defender for IoT software installation](../how-to-install-software.md). ++## Next steps ++Continue learning about the system requirements for physical or virtual appliances. For more information, see [Which appliances do I need?](../ot-appliance-sizing.md). ++Then, use any of the following procedures to continue: ++- [Download software for an OT sensor](../ot-deploy/install-software-ot-sensor.md#download-software-files-from-the-azure-portal) +- [Download software files for an on-premises management console](../legacy-central-management/install-software-on-premises-management-console.md#download-software-files-from-the-azure-portal) |
deployment-environments | How To Configure Extensibility Bicep Container Image | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/deployment-environments/how-to-configure-extensibility-bicep-container-image.md | -In this article, you learn how to build custom Azure Resource Manager (ARM) and Bicep container images to deploy your environment definitions in Azure Deployment Environments (ADE). +In this article, you learn how to build custom Azure Resource Manager (ARM) and Bicep container images to deploy your [environment definitions](configure-environment-definition.md) in Azure Deployment Environments (ADE). An environment definition comprises at least two files: a template file, like *azuredeploy.json* or *main.bicep*, and a manifest file named *environment.yaml*. ADE uses containers to deploy environment definitions, and natively supports the ARM and Bicep IaC frameworks. -The ADE extensibility model enables you to create custom container images to use with your environment definitions. By using the extensibility model, you can create your own custom container images, and store them in a container registry like DockerHub. You can then reference these images in your environment definitions to deploy your environments. +The ADE extensibility model enables you to create custom container images to use with your environment definitions. By using the extensibility model, you can create your own custom container images, and store them in a container registry like Azure Container Registry (ACR) or Docker Hub. You can then reference these images in your environment definitions to deploy your environments. The ADE team provides a selection of images to get you started, including a core image, and an Azure Resource Manager (ARM)/Bicep image. You can access these sample images in the [Runner-Images](https://aka.ms/deployment-environments/runner-images) folder. echo "{\"outputs\": $deploymentOutput}" > $ADE_OUTPUTS ## Make the custom image accessible to ADE -You must build your Docker image and push it to your container registry to make it available for use in ADE. You can build your image using the Docker CLI, or by using a script provided by ADE. +You must build your Docker image and push it to your container registry to make it available for use in ADE. ++You can build your image using the Docker CLI, or by using a script provided by ADE. Select the appropriate tab to learn more about each approach. docker build . -t {YOUR_REGISTRY}.azurecr.io/customImage:1.0.0 ### Push the Docker image to a registry -In order to use custom images, you need to set up a publicly accessible image registry with anonymous image pull enabled. This way, Azure Deployment Environments can access your custom image to execute in our container. +In order to use custom images, you need to store them in a container registry. Azure Container Instances (ACR) is highly recommended for that. Due to its tight integration with ADE, the image can be published without allowing public anonymous pull access. ++It's also possible to store the image in a different container registry such as Docker Hub, but in that case it needs to be publicly accessible. -Azure Container Registry is an Azure offering that stores container images and similar artifacts. +> [!Caution] +> Enabling anonymous (unauthenticated) pull access makes all registry content publicly available for read (pull) actions. ++To use a custom image stored in ACR, you need to ensure that ADE has appropriate permissions to access your image. Anonymous pull access is disabled by default in ACR. To create a registry, which can be done through the Azure CLI, the Azure portal, PowerShell commands, and more, follow one of the [quickstarts](/azure/container-registry/container-registry-get-started-azure-cli). +#### Use a public registry with anonymous pull + To set up your registry to have anonymous image pull enabled, run the following commands in the Azure CLI: ```azurecli When you're ready to push your image to your registry, run the following command docker push {YOUR_REGISTRY}.azurecr.io/{YOUR_IMAGE_LOCATION}:{YOUR_TAG} ``` +#### Use ACR with secured access ++By default, access to pull or push content from an Azure Container Registry is only available to authenticated users. You can further secure access to ACR by limiting access from certain networks and assigning specific roles. ++##### Limit network access ++To secure network access to your ACR, you can limit access to your own networks, or disable public network access entirely. If you limit network access, you must enable the firewall exception *Allow trusted Microsoft services to access this container registry*. ++To disable access from public networks: ++1. [Create an ACR instance](/azure/container-registry/container-registry-get-started-azure-cli) or use an existing one. +1. In the Azure portal, go to the ACR that you want to configure. +1. On the left menu, under **Settings**, select **Networking**. +1. On the Networking page, on the **Public access** tab, under **Public network access**, select **Disabled**. ++ :::image type="content" source="media/how-to-configure-extensibility-bicep-container-image/container-registry-network-settings.png" alt-text="Screenshot of the Azure portal, showing the ACR network settings, with Public access and Disabled highlighted."::: ++1. Under **Firewall exception**, check that **Allow trusted Microsoft services to access this container registry** is selected, and then select **Save**. ++ :::image type="content" source="media/how-to-configure-extensibility-bicep-container-image/container-registry-network-disable-public.png" alt-text="Screenshot of the ACR network settings, with Allow trusted Microsoft services to access this container registry and Save highlighted."::: ++##### Assign the AcrPull role ++Creating environments by using container images uses the ADE infrastructure, including projects and environment types. Each project has one or more project environment types, which need read access to the container image that defines the environment to be deployed. To access the images within your ACR securely, assign the AcrPull role to each project environment type. ++To assign the AcrPull role to the Project Environment Type: ++1. In the Azure portal, go to the ACR that you want to configure. +1. On the left menu, select **Access Control (IAM)**. +1. Select **Add** > **Add role assignment**. +1. Assign the following role. For detailed steps, see [Assign Azure roles using the Azure portal](../role-based-access-control/role-assignments-portal.yml). ++ | Setting | Value | + | | | + | **Role** | Select **AcrPull**. | + | **Assign access to** | Select **User, group, or service principal**. | + | **Members** | Enter the name of the project environment type that needs to access the image in the container. | ++ The project environment type displays like the following example: ++ :::image type="content" source="media/how-to-configure-extensibility-bicep-container-image/container-registry-access-control.png" alt-text="Screenshot of the Select members pane, showing a list of project environment types with part of the name highlighted."::: ++In this configuration, ADE uses the Managed Identity for the PET, whether system assigned or user assigned. ++> [!Tip] +> This role assignment has to be made for every project environment type. It can be automated through the Azure CLI. +When you're ready to push your image to your registry, run the following command: ++```docker +docker push {YOUR_REGISTRY}.azurecr.io/{YOUR_IMAGE_LOCATION}:{YOUR_TAG} +``` ++ ## [Build a container image with a script](#tab/build-a-container-image-with-a-script/) [!INCLUDE [custom-image-script](includes/custom-image-script.md)] |
event-hubs | Azure Event Hubs Kafka Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/event-hubs/azure-event-hubs-kafka-overview.md | Conceptually, Kafka and Event Hubs are very similar. They're both partitioned lo ### Compression +The Kafka compression for Event Hubs is only supported in Premium and Dedicated tiers currently. + The client-side [compression](https://cwiki.apache.org/confluence/display/KAFKA/Compression) feature in Apache Kafka clients conserves compute resources and bandwidth by compressing a batch of multiple messages into a single message on the producer side and decompressing the batch on the consumer side. The Apache Kafka broker treats the batch as a special message. Kafka producer application developers can enable message compression by setting the compression.type property. Azure Event Hubs currently supports `gzip` compression. |
hdinsight-aks | Hdinsight Aks Release Notes Archive | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/hdinsight-aks/release-notes/hdinsight-aks-release-notes-archive.md | Title: Archived release notes for Azure HDInsight on AKS description: Archived release notes for Azure HDInsight on AKS. Get development tips and details for Trino, Flink, and Spark. Previously updated : 03/21/2024 Last updated : 08/05/2024 # Azure HDInsight on AKS archived release notes Azure HDInsight on AKS is one of the most popular services among enterprise customers for open-source analytics on Azure. If you would like to subscribe on release notes, watch releases on this [GitHub repository](https://github.com/Azure/HDInsight-on-aks/releases). +### Release date: March 20, 2024 ++**This release applies to the following** ++- Cluster Pool Version: 1.1 +- Cluster Version: 1.1.1 +- AKS version: 1.27 +++### New Features ++**Apache Flink Application Mode Cluster** ++Application mode clusters are designed to support dedicated resources for large and long-running jobs. When you have resource-intensive or extensive data processing tasks, you can use the [Application Mode Cluster](https://flink.apache.org/2020/07/14/application-deployment-in-flink-current-state-and-the-new-application-mode/#application-mode). This mode allows you to allocate dedicated resources for specific Apache Flink applications, ensuring that they have the necessary computing power and memory to handle large workloads effectively. ++For more information, see [Apache Flink Application Mode cluster on HDInsight on AKS](../flink/application-mode-cluster-on-hdinsight-on-aks.md). ++**Private Clusters for HDInsight on AKS** ++With private clusters, and outbound cluster settings you can now control ingress and egress traffic from HDInsight on AKS cluster pools and clusters. ++- Use Azure Firewall or Network Security Groups (NSGs) to control the egress traffic, when you opt to use outbound cluster pool with load balancer. +- Use Outbound cluster pool with User defined routing to control egress traffic at the subnet level. +- Use Private AKS cluster feature - To ensure AKS control plane, or API server has internal IP addresses. The network traffic between AKS Control plane / API server and HDInsight on AKS node pools (clusters) remains on the private network only. +- Avoid creating public IPs for the cluster. Use private ingress feature on your clusters. ++For more information, see [Control network traffic from HDInsight on AKS Cluster pools and cluster](../control-egress-traffic-from-hdinsight-on-aks-clusters.md). ++**In place Upgrade** ++Upgrade your clusters and cluster pools with the latest software updates. This means that you can enjoy the latest cluster package hotfixes, security updates, and AKS patches, without recreating clusters. For more information, see [Upgrade your HDInsight on AKS clusters and cluster pools](../in-place-upgrade.md). ++> [!IMPORTANT] +> To take benefit of all these **latest features**, you are required to create a new cluster pool with 1.1 and cluster version 1.1.1. ++### Known issues ++- **Workload identity limitation:** + - There's a known [limitation](/azure/aks/workload-identity-overview#limitations) when transitioning to workload identity. This limitation is due to the permission-sensitive nature of FIC operations. Users can't perform deletion of a cluster by deleting the resource group. Cluster deletion requests must be triggered by the application/user/principal with FIC/delete permissions. In case, the FIC deletion fails, the high-level cluster deletion also fails. + - **User Assigned Managed Identities (UAMI)** support – There's a limit of 20 FICs per UAMI. You can only create 20 Federated Credentials on an identity. In HDInsight on AKS cluster, FIC (Federated Identity Credential) and SA have one-to-one mapping and only 20 SAs can be created against an MSI. If you want to create more clusters, then you are required to provide different MSIs to overcome the limitation. + - Creation of federated identity credentials is currently not supported on user-assigned managed identities created in [these regions](/entra/workload-id/workload-identity-federation-considerations#unsupported-regions-user-assigned-managed-identities) ++ +### Operating System version ++- Mariner OS 2.0 ++**Workload versions** ++|Workload|Version| +| -- | -- | +|Trino | 426 | +|Flink | 1.17.0 | +|Apache Spark | 3.3.1 | ++**Supported Java and Scala versions** ++|Workload |Java|Scala| +| -- | -- | -- | +|Trino |Open JDK 17.0.7  |- | +|Flink |Open JDK 11.0.21 |2.12.7 | +|Spark |Open JDK 1.8.0_345  |2.12.15 | ++The preview is available in the following [regions](../overview.md#region-availability-public-preview). ++If you have any more questions, contact [Azure Support](https://ms.portal.azure.com/#view/Microsoft_Azure_Support/HelpAndSupportBlade/~/overview) or refer to the [Support options](../hdinsight-aks-support-help.md) page. If you have product specific feedback, write us on [aka.ms/askhdinsight](https://forms.office.com/pages/responsepage.aspx?id=v4j5cvGGr0GRqy180BHbR6HHTBN7UDpEhLm8BJmDhGJURDhLWEhBVE5QN0FQRUpHWDg4ODlZSDA4RCQlQCN0PWcu). ++ ### Release date: February 05, 2024 **This release applies to the following** |
hdinsight-aks | Hdinsight Aks Release Notes | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/hdinsight-aks/release-notes/hdinsight-aks-release-notes.md | Title: Release notes for Azure HDInsight on AKS description: Latest release notes for Azure HDInsight on AKS. Get development tips and details for Trino, Flink, Spark, and more. Previously updated : 03/20/2024 Last updated : 08/05/2024 # Azure HDInsight on AKS release notes You can refer to [What's new](../whats-new.md) page for all the details of the f ## Release Information -### Release date: March 20, 2024 +### Release date: Aug 05, 2024 **This release applies to the following** -- Cluster Pool Version: 1.1-- Cluster Version: 1.1.1+- Cluster Pool Version: 1.2 +- Cluster Version: 1.2.1 - AKS version: 1.27 - ### New Features -**Apache Flink Application Mode Cluster** --Application mode clusters are designed to support dedicated resources for large and long-running jobs. When you have resource-intensive or extensive data processing tasks, you can use the [Application Mode Cluster](https://flink.apache.org/2020/07/14/application-deployment-in-flink-current-state-and-the-new-application-mode/#application-mode). This mode allows you to allocate dedicated resources for specific Apache Flink applications, ensuring that they have the necessary computing power and memory to handle large workloads effectively. --For more information, see [Apache Flink Application Mode cluster on HDInsight on AKS](../flink/application-mode-cluster-on-hdinsight-on-aks.md). +**MSI based SQL authentication** +Users can now authenticate external Azure SQL DB Metastore with MSI instead of User ID password authentication. This feature helps to further secure the cluster connection with Metastore. -**Private Clusters for HDInsight on AKS** +**Configurable VM SKUs for Head node, SSH node** +This functionality allows users to choose specific SKUs for head nodes, worker nodes, and SSH nodes, offering the flexibility to select according to the use case and the potential to lower total cost of ownership (TCO). -With private clusters, and outbound cluster settings you can now control ingress and egress traffic from HDInsight on AKS cluster pools and clusters. +**Multiple MSI in cluster** +Users can configure multiple MSI for cluster admins operations and for job related resource access. This feature allows users to demarcate and control the access to the cluster and data lying in the storage account. +For example, one MSI for access to data in storage account and dedicated MSI for cluster operations. -- Use Azure Firewall or Network Security Groups (NSGs) to control the egress traffic, when you opt to use outbound cluster pool with load balancer.-- Use Outbound cluster pool with User defined routing to control egress traffic at the subnet level.-- Use Private AKS cluster feature - To ensure AKS control plane, or API server has internal IP addresses. The network traffic between AKS Control plane / API server and HDInsight on AKS node pools (clusters) remains on the private network only.-- Avoid creating public IPs for the cluster. Use private ingress feature on your clusters.+### Updated -For more information, see [Control network traffic from HDInsight on AKS Cluster pools and cluster](../control-egress-traffic-from-hdinsight-on-aks-clusters.md). +**Script action** +Script Action now can be added with Sudo user permission. Users can now install multiple dependencies including custom jars to customize the clusters as required. -**In place Upgrade** +**Library Management** +Maven repository shortcut feature added to the Library Management in this release. User can now install Maven dependencies directly from the open-source repositories. -Upgrade your clusters and cluster pools with the latest software updates. This means that you can enjoy the latest cluster package hotfixes, security updates, and AKS patches, without recreating clusters. For more information, see [Upgrade your HDInsight on AKS clusters and cluster pools](../in-place-upgrade.md). +**Spark 3.4** +Spark 3.4 update brings a range of new features includes +* API enhancements +* Structured streaming improvements +* Improved usability and developer experience > [!IMPORTANT]-> To take benefit of all these **latest features**, you are required to create a new cluster pool with 1.1 and cluster version 1.1.1. +> To take benefit of all these **latest features**, you are required to create a new cluster pool with 1.2 and cluster version 1.2.1 ### Known issues Upgrade your clusters and cluster pools with the latest software updates. This m |Workload|Version| | -- | -- |-|Trino | 426 | +|Trino | 440 | |Flink | 1.17.0 |-|Apache Spark | 3.3.1 | +|Apache Spark | 3.4 | **Supported Java and Scala versions** |Workload |Java|Scala| | -- | -- | -- |-|Trino |Open JDK 17.0.7  |- | +|Trino |Open JDK 21.0.2  |- | |Flink |Open JDK 11.0.21 |2.12.7 | |Spark |Open JDK 1.8.0_345  |2.12.15 | |
hdinsight | Hdinsight Hadoop Oms Log Analytics Tutorial | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/hdinsight/hdinsight-hadoop-oms-log-analytics-tutorial.md | For the log table mappings from the classic Azure Monitor integration to the new #### [Classic Azure Monitor experience](#tab/previous) +> [!Important] +> On 31 August 2024, Azure is retiring the Classic Azure Monitor experience on HDInsight. + ## Prerequisites * A Log Analytics workspace. You can think of this workspace as a unique Azure Monitor logs environment with its own data repository, data sources, and solutions. For the instructions, see [Create a Log Analytics workspace](../azure-monitor/vm/monitor-virtual-machine.md). |
healthcare-apis | Release Notes | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/healthcare-apis/azure-api-for-fhir/release-notes.md | +## **July 2024** ++### FHIR service ++**Bug Fixes** ++**Fixed: Exporting Data as SMART User** +Exporting data as a SMART user no longer requires write scopes. Previously, it was necessary to grant "write" privileges to a SMART user for exporting data, which implied higher privilege levels. To initiate an export job as a SMART user, ensure the user is a member of the FHIR export role in RBAC and requests the "read" SMART clinical scope. ++**Fixed: Updating Status Code from HTTP 500 to HTTP 400** +During a patch operation, if the payload requested an update for a resource type other than Parameter, an internal server error (HTTP 500) was initially thrown. This has been updated to throw an HTTP 400 error instead. + ## **May 2024** ### FHIR service |
healthcare-apis | Import Data | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/healthcare-apis/fhir/import-data.md | Content-Type:application/fhir+json | -- | -- | -- | -- | | `inputFormat`| String that represents the name of the data source format. Only FHIR NDJSON files are supported. | 1..1 | `application/fhir+ndjson` | | `mode`| Import mode value. | 1..1 | For an initial-mode import, use the `InitialLoad` mode value. For incremental-mode import, use the `IncrementalLoad` mode value. If you don't provide a mode value, the `IncrementalLoad` mode value is used by default. |+| `allowNegativeVersions`| Allows FHIR server assigning negative versions for resource records with explicit lastUpdated value and no version specified when input does not fit in contiguous space of positive versions existing in the store. | 0..1 | To enable this feature pass true. By default it is false. | | `input`| Details of the input files. | 1..* | A JSON array with the three parts described in the following table. | + | Input part name | Description | Cardinality | Accepted values | | -- | -- | -- | -- | | `type`| Resource type of the input file. | 0..1 | A valid [FHIR resource type](https://www.hl7.org/fhir/resourcelist.html) that matches the input file. This field is optional.| Content-Type:application/fhir+json }, { "name": "mode",- "valueString": "<Use "InitialLoad" for initial mode import / Use "IncrementalLoad" for incremental mode import>", + "valueString": "<Use "InitialLoad" for initial mode import / Use "IncrementalLoad" for incremental mode import>" + }, + { + "name": "allowNegativeVersions", + "valueBoolean": true }, { "name": "input", |
healthcare-apis | Release Notes 2024 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/healthcare-apis/release-notes-2024.md | It's possible for dates supplied within JSON data to be returned in a different The coercion of strings to .NET DateTime objects can be disabled using the boolean parameter `jsonDeserializationTreatDatesAsStrings`. When set to `true`, the supplied data is treated as a string and won't be modified before being supplied to the Liquid engine. +#### Import Operation enhancement +The FHIR service now allows ingestion of data without specifying a version at the resource level. The order of resources is maintained using the lastUpdated value. This enhancement introduces the "allowNegativeVersions" flag. Setting flag true allows the FHIR service to assign negative versions for resource records with an explicit lastUpdated value and no version specified. ++#### Bug Fixes +- **Fixed inclusion of soft deleted resources when using _security:not search parameter** +When using the _security:not search parameter in search operations, IDs for soft-deleted resources were being included in the search results. We have fixed the issue so that soft-deleted resources are now excluded from search results. +- **Exporting Data as SMART User** +Exporting data as a SMART user no longer requires write scopes. Previously, it was necessary to grant "write" privileges to a SMART user for exporting data, which implied higher privilege levels. To initiate an export job as a SMART user, ensure the user is a member of the FHIR export role in RBAC and requests the "read" SMART clinical scope. +Updating Status Code from HTTP 500 to HTTP 400 +- **Updating Status Code from HTTP 500 to HTTP 400** +During a patch operation, if the payload requested an update for a resource type other than parameter, an internal server error (HTTP 500) was initially thrown. This has been updated to throw an HTTP 400 error instead. ++#### Performance enhancement +Query optimization is added when searching FHIR resources with a data range. This query optimization will help with efficient querying as one combined CTE is generated. + ## May 2024 ### Azure Health Data Services |
load-balancer | Load Balancer Custom Probe Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/load-balancer/load-balancer-custom-probe-overview.md | If you don't allow the [source IP](#probe-source-ip-address) of the probe in you ## Limitations -* HTTPS probes don't support mutual authentication with a client certificate. +* HTTPS probes doesn't support mutual authentication with a client certificate. ++* HTTP probes doesn't support using hostnames to probes backends * Enabling TCP timestamps can cause throttling or other performance issues, which can then cause health probes to timeout. * A Basic SKU load balancer health probe isn't supported with a virtual machine scale set. -* HTTP probes don't support probing on the following ports due to security concerns: 19, 21, 25, 70, 110, 119, 143, 220, 993. +* HTTP probes doesn't support probing on the following ports due to security concerns: 19, 21, 25, 70, 110, 119, 143, 220, 993. ## Next steps |
logic-apps | Add Run Csharp Scripts | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/logic-apps/add-run-csharp-scripts.md | Title: Add and run C# scripts in Standard workflows description: Write and run C# scripts inline from Standard workflows to perform custom integration tasks using Inline Code operations in Azure Logic Apps.-+ ms.suite: integration |
logic-apps | Create Maps Data Transformation Visual Studio Code | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/logic-apps/create-maps-data-transformation-visual-studio-code.md | Title: Create maps for data transformation description: Create maps to transform data between schemas in Azure Logic Apps using Visual Studio Code. -+ ms.suite: integration |
logic-apps | Create Workflow With Trigger Or Action | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/logic-apps/create-workflow-with-trigger-or-action.md | Title: Create a workflow with a trigger or action description: Start building your workflow by adding a trigger or an action in Azure Logic Apps. -+ ms.suite: integration |
logic-apps | Create Integration Account | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/logic-apps/enterprise-integration/create-integration-account.md | Title: Create and manage integration accounts description: Create and manage integration accounts for building B2B enterprise integration workflows in Azure Logic Apps with the Enterprise Integration Pack. -+ ms.suite: integration |
logic-apps | Monitor Logic Apps Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/logic-apps/monitor-logic-apps-overview.md | Title: Monitor logic app workflows description: Start here to learn about monitoring workflows in Azure Logic Apps.-+ Last updated 07/11/2024 |
logic-apps | Monitor Logic Apps Reference | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/logic-apps/monitor-logic-apps-reference.md | description: This article contains important reference material you need when yo Last updated 03/19/2024 -+ # Azure Logic Apps monitoring data reference |
logic-apps | Plan Manage Costs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/logic-apps/plan-manage-costs.md | Title: Plan to manage costs for Azure Logic Apps description: Learn how to plan for and manage costs for Azure Logic Apps by using cost analysis in the Azure portal.-+ |
logic-apps | Security Controls Policy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/logic-apps/security-controls-policy.md | Title: Azure Policy Regulatory Compliance controls for Azure Logic Apps description: Lists Azure Policy Regulatory Compliance controls available for Azure Logic Apps. These built-in policy definitions provide common approaches to managing the compliance of your Azure resources. Last updated 02/06/2024 -+ # Azure Policy Regulatory Compliance controls for Azure Logic Apps |
logic-apps | Support Non Unicode Character Encoding | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/logic-apps/support-non-unicode-character-encoding.md | Title: Convert non-Unicode encoded text for compatibility description: Handle non-Unicode characters in Azure Logic Apps by converting text payloads to UTF-8 with base64 encoding and Azure Functions.-+ Last updated 01/04/2024 |
machine-learning | Azure Machine Learning Ci Image Release Notes | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/azure-machine-learning-ci-image-release-notes.md | |
machine-learning | Azure Machine Learning Glossary | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/azure-machine-learning-glossary.md | Title: Azure Machine Learning glossary description: Glossary of terms for the Azure Machine Learning platform. -+ |
machine-learning | Azure Machine Learning Release Notes Cli V2 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/azure-machine-learning-release-notes-cli-v2.md | Title: CLI (v2) release notes description: Learn about the latest updates to Azure Machine Learning CLI (v2) -+ |
machine-learning | Classification | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/classification.md | Title: "AutoML Classification" description: Learn how to use the AutoML Classification component in Azure Machine Learning to create a classifier using ML Table data. -+ |
machine-learning | Component Reference V2 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/component-reference-v2.md | Title: "Algorithm & component reference (v2)" description: Learn about the Azure Machine Learning designer components that you can use to create your own machine learning projects. (v2) -+ |
machine-learning | Forecasting | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/forecasting.md | Title: "AutoML Forecasting Component in Microsoft Azure Machine Learning Design description: Learn how to use the AutoML Forecasting component in Azure Machine Learning to create a classifier using ML Table data. -+ |
machine-learning | Image Classification Multilabel | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/image-classification-multilabel.md | Title: "AutoML Image Classification Multi-label" description: Learn how to use the AutoML Image Classification Multi-label component in Azure Machine Learning to create a classifier using ML Table data. -+ |
machine-learning | Image Classification | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/image-classification.md | Title: "AutoML Image Classification" description: Learn how to use the AutoML Image Classification component in Azure Machine Learning to create a classifier using ML Table data. -+ |
machine-learning | Image Instance Segmentation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/image-instance-segmentation.md | Title: "AutoML Image Instance Segmentation Component in Microsoft Azure Machine description: Learn how to use the AutoML Image Instance Segmentation component in Azure Machine Learning to create a classifier using ML Table data. -+ |
machine-learning | Image Object Detection | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/image-object-detection.md | Title: "AutoML Image Object Detection" description: Learn how to use the AutoML Image Object Detection component in Azure Machine Learning to create a classifier using ML Table data. -+ |
machine-learning | Regression | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/regression.md | Title: "AutoML Regression" description: Learn how to use the AutoML Regression component in Azure Machine Learning to create a classifier using ML Table data. -+ |
machine-learning | Text Classification Multilabel | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/text-classification-multilabel.md | Title: "AutoML Text Multi-label Classification" description: Learn how to use the AutoML Text Multi-label Classification component in Azure Machine Learning to create a classifier using ML Table data. -+ |
machine-learning | Text Classification | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/text-classification.md | Title: "AutoML Text Classification" description: Learn how to use the AutoML Text Classification component in Azure Machine Learning to create a classifier using ML Table data. -+ |
machine-learning | Text Ner | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference-v2/text-ner.md | Title: "AutoML Text NER (Named Entry Recognition)" description: Learn how to use the AutoML Text NER component in Azure Machine Learning to create a classifier using ML Table data. -+ |
machine-learning | Add Columns | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/add-columns.md | Title: "Add Columns: Component Reference" description: Learn how to use the Add Columns component in the drag-and-drop Azure Machine Learning designer to concatenate two datasets. -+ |
machine-learning | Add Rows | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/add-rows.md | Title: "Add Rows: Component Reference" description: Learn how to use the Add Rows component in Azure Machine Learning designer to concatenate two datasets. -+ |
machine-learning | Apply Image Transformation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/apply-image-transformation.md | Title: "Apply Image Transformation" description: Learn how to use the Apply Image Transformation component to apply an image transformation to a image directory. -+ |
machine-learning | Apply Math Operation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/apply-math-operation.md | Title: "Apply Math Operation" description: Learn how to use the Apply Math Operation component in Azure Machine Learning to apply a mathematical operation to column values in a pipeline. -+ |
machine-learning | Apply Sql Transformation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/apply-sql-transformation.md | Title: "Apply SQL Transformation" description: Learn how to use the Apply SQL Transformation component in Azure Machine Learning to run a SQLite query on input datasets to transform the data. -+ |
machine-learning | Apply Transformation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/apply-transformation.md | Title: "Apply Transformation: Component Reference" description: Learn how to use the Apply Transformation component in Azure Machine Learning to modify an input dataset based on a previously computed transformation. -+ |
machine-learning | Assign Data To Clusters | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/assign-data-to-clusters.md | Title: "Assign Data to Cluster: Component Reference" description: Learn how to use the Assign Data to Cluster component in Azure Machine Learning to score clustering model. -+ |
machine-learning | Boosted Decision Tree Regression | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/boosted-decision-tree-regression.md | Title: "Boosted Decision Tree Regression: Component Reference" description: Learn how to use the Boosted Decision Tree Regression component in Azure Machine Learning to create an ensemble of regression trees using boosting. -+ |
machine-learning | Clean Missing Data | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/clean-missing-data.md | Title: "Clean Missing Data: Component Reference" description: Learn how to use the Clean Missing Data component in Azure Machine Learning to remove, replace, or infer missing values. -+ |
machine-learning | Clip Values | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/clip-values.md | Title: "Clip Values" description: Learn how to use the Clip Values component in Azure Machine Learning to detect outliers and clip or replace their values. -+ |
machine-learning | Component Reference | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/component-reference.md | Title: "Algorithm & component reference" description: Learn about the Azure Machine Learning designer components that you can use to create your own machine learning projects. -+ |
machine-learning | Convert To Csv | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/convert-to-csv.md | Title: "Convert to CSV: Component Reference" description: Learn how to use the Convert to CSV component in Azure Machine Learning designer to convert a dataset into a CSV file that can be reused later. -+ |
machine-learning | Convert To Dataset | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/convert-to-dataset.md | Title: "Convert to Dataset: Component reference" description: Learn how to use the Convert to Dataset component in Azure Machine Learning designer to convert data input to the internal dataset format. -+ |
machine-learning | Convert To Image Directory | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/convert-to-image-directory.md | Title: "Convert to Image Directory" description: Learn how to use the Convert to Image Directory component to Convert dataset to image directory format. -+ |
machine-learning | Convert To Indicator Values | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/convert-to-indicator-values.md | Title: "Convert to Indicator Values" description: Use the Convert to Indicator Values component in Azure Machine Learning designer to convert categorical columns into a series of binary indicator columns. -+ |
machine-learning | Convert Word To Vector | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/convert-word-to-vector.md | Title: "Convert Word to Vector: Component reference" description: Learn how to use three provided Word2Vec models to extract a vocabulary and its corresponding word embeddings from a corpus of text. -+ |
machine-learning | Create Python Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/create-python-model.md | Title: "Create Python Model: Component reference" description: Learn how to use the Create Python Model component in Azure Machine Learning to create a custom modeling or data processing component. -+ |
machine-learning | Cross Validate Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/cross-validate-model.md | Title: "Cross Validate Model: Component reference" description: Use the Cross-Validate Model component in Azure Machine Learning designer to cross-validate parameter estimates for classification or regression models. -+ |
machine-learning | Decision Forest Regression | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/decision-forest-regression.md | Title: "Decision Forest Regression: Component Reference" description: Learn how to use the Decision Forest Regression component in Azure Machine Learning to create a regression model based on an ensemble of decision trees. -+ |
machine-learning | Densenet | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/densenet.md | Title: "DenseNet" description: Learn how to use the DenseNet component in Azure Machine Learning designer to create an image classification model using the DenseNet algorithm. -+ |
machine-learning | Designer Error Codes | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/designer-error-codes.md | Title: Troubleshoot designer component errors description: Learn how you can read and troubleshoot automated component error codes in Azure Machine Learning designer. -+ |
machine-learning | Edit Metadata | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/edit-metadata.md | Title: "Edit Metadata: Component reference" description: Learn how to use the Edit Metadata component in the Azure Machine Learning to change metadata that's associated with columns in a dataset. -+ |
machine-learning | Enter Data Manually | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/enter-data-manually.md | Title: "Enter Data Manually: Component reference" description: Learn how to use the Enter Data Manually component in Azure Machine Learning to create a small dataset by typing values. The dataset can have multiple columns. -+ |
machine-learning | Evaluate Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/evaluate-model.md | Title: "Evaluate Model: Component Reference" description: Learn how to use the Evaluate Model component in Azure Machine Learning to measure the accuracy of a trained model. -+ |
machine-learning | Evaluate Recommender | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/evaluate-recommender.md | Title: "Evaluate Recommender: Component reference" description: Learn how to use the Evaluate Recommender component in Azure Machine Learning to evaluate the accuracy of recommender model predictions. -+ |
machine-learning | Execute Python Script | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/execute-python-script.md | Title: "Execute Python Script: Component reference" description: Learn how to use the Execute Python Script component in Azure Machine Learning designer to run Python code. -+ |
machine-learning | Execute R Script | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/execute-r-script.md | Title: "Execute R Script: Component reference" description: Learn how to use the Execute R Script component in Azure Machine Learning designer to run custom R code. -+ |
machine-learning | Export Data | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/export-data.md | Title: "Export Data: Component Reference" description: Use the Export Data component in Azure Machine Learning designer to save results and intermediate data outside of Azure Machine Learning. -+ |
machine-learning | Extract N Gram Features From Text | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/extract-n-gram-features-from-text.md | Title: "Extract N-Gram Features from Text component reference" description: Learn how to use the Extract N-Gram component in the Azure Machine Learning designer to featurize text data. -+ |
machine-learning | Fast Forest Quantile Regression | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/fast-forest-quantile-regression.md | Title: "Fast Forest Quantile Regression: Module reference" description: Learn how to use the Fast Forest Quantile Regression component to create a regression model that can predict values for a specified number of quantiles. -+ |
machine-learning | Feature Hashing | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/feature-hashing.md | Title: "Feature Hashing component reference" description: Learn how to use the Feature Hashing component in the Azure Machine Learning designer to featurize text data. -+ |
machine-learning | Filter Based Feature Selection | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/filter-based-feature-selection.md | Title: "Filter Based Feature Selection: Component reference" description: Learn how to use the Filter Based Feature Selection component in Azure Machine Learning to identify the features in a dataset with the greatest predictive power. -+ |
machine-learning | Graph Search Syntax | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/graph-search-syntax.md | Title: "Graph search query syntax" description: Learn how to use the search query syntax in Azure Machine Learning designer to search for nodes in pipeline graph. -+ |
machine-learning | Group Data Into Bins | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/group-data-into-bins.md | Title: "Group Data into Bins: Component reference" description: Learn how to use the Group Data into Bins component to group numbers or change the distribution of continuous data. -+ |
machine-learning | Import Data | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/import-data.md | Title: "Import Data: Component Reference" description: Learn how to use the Import Data component in Azure Machine Learning to load data into a machine learning pipeline from existing cloud data services. -+ |
machine-learning | Init Image Transformation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/init-image-transformation.md | Title: "Init Image Transformationply Image Transformation" description: Learn how to use the Init Image Transformation component in Azure Machine Learning designer to initialize image transformation. -+ |
machine-learning | Join Data | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/join-data.md | Title: "Join Data: Component Reference" description: Learn how to use the Join Data component in Azure Machine Learning designer to merge two datasets together. -+ |
machine-learning | K Means Clustering | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/k-means-clustering.md | Title: "K-Means Clustering: Component Reference" description: Learn how to use the K-Means Clustering component in the Azure Machine Learning to train clustering models. -+ |
machine-learning | Latent Dirichlet Allocation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/latent-dirichlet-allocation.md | Title: "Latent Dirichlet Allocation: Component reference" description: Learn how to use the Latent Dirichlet Allocation component to group otherwise unclassified text into categories. -+ |
machine-learning | Linear Regression | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/linear-regression.md | Title: "Linear Regression: Component Reference" description: Learn how to use the Linear Regression component in Azure Machine Learning to create a linear regression model for use in a pipeline. -+ |
machine-learning | Multiclass Boosted Decision Tree | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/multiclass-boosted-decision-tree.md | Title: "Multiclass Boosted Decision Tree: Component Reference" description: Learn how to use the Multiclass Boosted Decision Tree component in Azure Machine Learning to create a classifier using labeled data. -+ |
machine-learning | Multiclass Decision Forest | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/multiclass-decision-forest.md | Title: "Multiclass Decision Forest: Component Reference" description: Learn how to use the Multiclass Decision Forest component in Azure Machine Learning to create a machine learning model based on the *decision forest* algorithm. -+ |
machine-learning | Multiclass Logistic Regression | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/multiclass-logistic-regression.md | Title: "Multiclass Logistic Regression: Component Reference" description: Learn how to use the Multiclass Logistic Regression component in Azure Machine Learning designer to predict multiple values. -+ |
machine-learning | Multiclass Neural Network | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/multiclass-neural-network.md | Title: "Multiclass Neural Network: Component Reference" description: Learn how to use the Multiclass Neural Network component in Azure Machine Learning designer to predict a target that has multi-class values. -+ |
machine-learning | Neural Network Regression | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/neural-network-regression.md | Title: "Neural Network Regression: Component Reference" description: Learn how to use the Neural Network Regression component in Azure Machine Learning to create a regression model using a customizable neural network algorithm.. -+ |
machine-learning | Normalize Data | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/normalize-data.md | Title: "Normalize Data: Component Reference" description: Learn how to use the Normalize Data component in Azure Machine Learning to transform a dataset through *normalization*.. -+ |
machine-learning | One Vs All Multiclass | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/one-vs-all-multiclass.md | Title: "One-vs-All Multiclass" description: Learn how to use the One-vs-All Multiclass component in Azure Machine Learning designer to create an ensemble of binary classification models. -+ |
machine-learning | One Vs One Multiclass | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/one-vs-one-multiclass.md | Title: "One-vs-One Multiclass" description: Learn how to use the One-vs-One Multiclass component in Azure Machine Learning to create a multiclass classification model from an ensemble of binary classification models. -+ |
machine-learning | Partition And Sample | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/partition-and-sample.md | Title: "Partition and Sample: Component reference" description: Learn how to use the Partition and Sample component in Azure Machine Learning to perform sampling on a dataset or to create partitions from your dataset. -+ |
machine-learning | Pca Based Anomaly Detection | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/pca-based-anomaly-detection.md | Title: "PCA-Based Anomaly Detection: Component reference" description: Learn how to use the PCA-Based Anomaly Detection component to create an anomaly detection model based on principal component analysis (PCA). -+ |
machine-learning | Permutation Feature Importance | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/permutation-feature-importance.md | Title: "Permutation Feature Importance: Component reference" description: Learn how to use the Permutation Feature Importance component in the designer to compute the permutation feature importance scores of feature variables. -+ |
machine-learning | Poisson Regression | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/poisson-regression.md | Title: "Poisson Regression: Component reference" description: Learn how to use the Poisson Regression component in Azure Machine Learning designer to create a Poisson regression model. -+ |
machine-learning | Preprocess Text | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/preprocess-text.md | Title: "Preprocess Text: Component Reference" description: Learn how to use the Preprocess Text component in Azure Machine Learning designer to clean and simplify text. -+ |
machine-learning | Remove Duplicate Rows | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/remove-duplicate-rows.md | Title: "Remove Duplicate Rows: Component Reference" description: Learn how to use the Remove Duplicate Rows component in Azure Machine Learning to remove potential duplicates from a dataset. -+ |
machine-learning | Resnet | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/resnet.md | Title: "ResNet" description: Learn how to create an image classification model in Azure Machine Learning designer using the ResNet algorithm. -+ |
machine-learning | Score Image Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/score-image-model.md | Title: Use the Score Image Model component description: Learn how to use the Score Image Model component in Azure Machine Learning to generate predictions using a trained image model. -+ |
machine-learning | Score Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/score-model.md | Title: "Score Model: Component Reference" description: Learn how to use the Score Model component in Azure Machine Learning to generate predictions using a trained classification or regression model. -+ |
machine-learning | Score Svd Recommender | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/score-svd-recommender.md | Title: "Score SVD Recommender: Component reference" description: Learn how to use the Score SVD Recommender component in Azure Machine Learning to score recommendation predictions for a dataset. -+ |
machine-learning | Score Vowpal Wabbit Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/score-vowpal-wabbit-model.md | Title: "Score Vowpal Wabbit Model" description: Learn how to use the Score Vowpal Wabbit Model component to generate scores for a set of input data, using an existing trained Vowpal Wabbit model. -+ |
machine-learning | Score Wide And Deep Recommender | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/score-wide-and-deep-recommender.md | Title: Use the Score Wide & Deep Recommender component description: Learn how to use the Score Wide & Deep Recommender component in Azure Machine Learning to score recommendation predictions for a dataset. -+ |
machine-learning | Select Columns In Dataset | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/select-columns-in-dataset.md | Title: "Select Columns in Dataset: Component Reference" description: Learn how to use the Select Columns in Dataset component in Azure Machine Learning to choose a subset of columns to use in downstream operations. -+ |
machine-learning | Select Columns Transform | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/select-columns-transform.md | Title: "Select Columns Transform: Component reference" description: Learn how to use the Select Columns Transform component in Azure Machine Learning designer to perform a select transformation. -+ |
machine-learning | Smote | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/smote.md | Title: "SMOTE" description: Learn how to use the SMOTE component in Azure Machine Learning to increase the number of low-incidence examples in a dataset by using oversampling. -+ |
machine-learning | Split Data | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/split-data.md | Title: "Split Data: Component reference" description: Learn how to use the Split Data component in Azure Machine Learning to divide a dataset into two distinct sets. -+ |
machine-learning | Split Image Directory | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/split-image-directory.md | Title: "Split Image Directory" description: Learn how to use the Split Image Directory component in the designer to divide the images of an image directory into two distinct sets. -+ |
machine-learning | Summarize Data | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/summarize-data.md | Title: "Summarize Data" description: Learn how to use the Summarize Data component in Azure Machine Learning to generate a basic descriptive statistics report for the columns in a dataset. -+ |
machine-learning | Train Anomaly Detection Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/train-anomaly-detection-model.md | Title: "Train Anomaly Detection Model: Component reference" description: Learn how to use the Train Anomaly Detection Model component to create a trained anomaly detection model. -+ |
machine-learning | Train Clustering Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/train-clustering-model.md | Title: "Train Clustering Model: Component Reference" description: Learn how to use the Train Clustering Model component in Azure Machine Learning to train clustering models. -+ |
machine-learning | Train Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/train-model.md | Title: "Train Model: Component Reference" description: Learn how to use the **Train Model** component in Azure Machine Learning to train a classification or regression model. -+ |
machine-learning | Train Pytorch Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/train-pytorch-model.md | Title: "Train PyTorch Model" description: Use the Train PyTorch Models component in Azure Machine Learning designer to train models from scratch, or fine-tune existing models. -+ |
machine-learning | Train Svd Recommender | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/train-svd-recommender.md | Title: "Train SVD Recommender: Component Reference" description: Learn how to use the Train SVD Recommender component in Azure Machine Learning to train a Bayesian recommender by using the SVD algorithm. -+ |
machine-learning | Train Vowpal Wabbit Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/train-vowpal-wabbit-model.md | Title: "Train Vowpal Wabbit Model" description: Learn how to use the Train Vowpal Wabbit Model component to create a machine learning model by using an instance of Vowpal Wabbit.-+ |
machine-learning | Train Wide And Deep Recommender | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/train-wide-and-deep-recommender.md | Title: Use the Train Wide & Deep Recommender component description: Learn how to use the Train Wide & Deep Recommender component in Azure Machine Learning designer to train a recommendation model. -+ |
machine-learning | Tune Model Hyperparameters | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/tune-model-hyperparameters.md | Title: "Tune Model Hyperparameters" description: Use the Tune Model Hyperparameters component in the designer to perform a parameter sweep to tune hyper-parameters. -+ |
machine-learning | Two Class Averaged Perceptron | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/two-class-averaged-perceptron.md | Title: "Two-Class Averaged Perceptron: Component Reference" description: Learn how to use the Two-Class Averaged Perceptron component in the designer to create a binary classifier. -+ |
machine-learning | Two Class Boosted Decision Tree | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/two-class-boosted-decision-tree.md | Title: "Two-Class Boosted Decision Tree: Component Reference" description: Learn how to use the Two-Class Boosted Decision Tree component in the designer to create a binary classifier. -+ |
machine-learning | Two Class Decision Forest | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/two-class-decision-forest.md | Title: "Two-Class Decision Forest: Component Reference" description: Learn how to use the Two-Class Decision Forest component in Azure Machine Learning to create a machine learning model based on the decision forests algorithm. -+ |
machine-learning | Two Class Logistic Regression | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/two-class-logistic-regression.md | |
machine-learning | Two Class Neural Network | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/two-class-neural-network.md | Title: "Two-Class Neural Network: Component Reference" description: Learn how to use the Two-Class Neural Network component in Azure Machine Learning to create a binary classifier. -+ |
machine-learning | Two Class Support Vector Machine | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/two-class-support-vector-machine.md | Title: "Two-Class Support Vector Machine: Component Reference" description: Learn how to use the Two-Class Support Vector Machine component in Azure Machine Learning to create a binary classifier. -+ |
machine-learning | Web Service Input Output | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/component-reference/web-service-input-output.md | Title: "Web Service Input/Output: Component reference" description: Learn how to use the web service components in Azure Machine Learning designer to manage inputs and outputs. -+ |
machine-learning | Concept Azure Machine Learning V2 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-azure-machine-learning-v2.md | Title: 'How Azure Machine Learning works (v2)' description: This article gives you a high-level understanding of the resources and assets that make up Azure Machine Learning (v2). -+ |
machine-learning | Concept Component | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-component.md | Title: "What is a component" description: Use Azure Machine Learning components to build machine learning pipelines. -+ |
machine-learning | Concept Designer | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-designer.md | Title: What is Designer (v2)? description: Learn about the drag-and-drop Designer UI in Machine Learning studio, and how it uses Designer v2 custom components to build and edit machine learning pipelines.-+ |
machine-learning | Concept Endpoint Serverless Availability | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-endpoint-serverless-availability.md | Title: Region availability for models in Serverless API endpoints description: Learn about the regions where each model is available for deployment in serverless API endpoints. -+ Last updated 05/09/2024 |
machine-learning | Concept Endpoints Batch | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-endpoints-batch.md | Title: What are batch endpoints? description: Learn how Azure Machine Learning uses batch endpoints to simplify machine learning deployments. -+ |
machine-learning | Concept Endpoints Online Auth | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-endpoints-online-auth.md | Title: Authentication for managed online endpoints description: Learn how authentication works for Azure Machine Learning managed online endpoints. -+ |
machine-learning | Concept Endpoints Online | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-endpoints-online.md | Title: What are online endpoints? description: Learn about online endpoints for real-time inference in Azure Machine Learning. -+ |
machine-learning | Concept Endpoints | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-endpoints.md | Title: Endpoints for inference description: Learn how Azure Machine Learning endpoints simplify deployments. -+ |
machine-learning | Concept Environments | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-environments.md | Title: About Azure Machine Learning environments description: Learn about machine learning environments, which enable reproducible, auditable, & portable machine learning dependency definitions for various compute targets. -+ |
machine-learning | Concept Expressions | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-expressions.md | Title: 'SDK and CLI v2 expressions' description: SDK and CLI v2 use expressions when a value may not be known when authoring a job or component. -+ |
machine-learning | Concept Hub Workspace | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-hub-workspace.md | Title: 'What are hub workspaces?' description: Hubs provide a central way to govern security, connectivity, and compute resources for a team with multiple workspaces. Project workspaces that are created using a hub obtain the same security settings and shared resource access. -+ |
machine-learning | Concept Onnx | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-onnx.md | Title: 'ONNX models: Optimize inference' description: Learn how using the Open Neural Network Exchange (ONNX) can help optimize the inference of your machine learning model. -+ |
machine-learning | Concept Prebuilt Docker Images Inference | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-prebuilt-docker-images-inference.md | Title: Prebuilt Docker images description: 'Prebuilt Docker images for inference (scoring) in Azure Machine Learning' -+ |
machine-learning | Concept Retrieval Augmented Generation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-retrieval-augmented-generation.md | |
machine-learning | Concept Secret Injection | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-secret-injection.md | Title: What is secret injection in online endpoints (preview)? description: Learn about secret injection as it applies to online endpoints in Azure Machine Learning. -+ |
machine-learning | Concept Secure Online Endpoint | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-secure-online-endpoint.md | Title: Network isolation with managed online endpoints description: Learn how private endpoints provide network isolation for Azure Machine Learning managed online endpoints. -+ |
machine-learning | Concept Soft Delete | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-soft-delete.md | Title: 'Workspace soft deletion' description: Soft delete allows you to recover workspace data after accidental deletion -+ |
machine-learning | Concept V2 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-v2.md | Title: 'Azure Machine Learning CLI & SDK v2' description: This article explains the difference between the v1 and v2 versions of Azure Machine Learning. -+ |
machine-learning | Concept Vector Stores | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-vector-stores.md | |
machine-learning | Concept Workspace | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/concept-workspace.md | Title: 'What is a workspace?' description: The workspace is the top-level resource for Azure Machine Learning. It keeps a history of all training runs, with logs, metrics, output, and a snapshot of your scripts. -+ |
machine-learning | Designer Accessibility | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/designer-accessibility.md | Title: Use accessibility features in the designer description: Learn about the keyboard shortcuts and screen reader accessibility features available in the designer. -+ |
machine-learning | How To Access Data Batch Endpoints Jobs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-access-data-batch-endpoints-jobs.md | Title: "Create jobs and input data for batch endpoints" description: Learn how to access data from different sources in batch endpoints jobs. -+ |
machine-learning | How To Access Resources From Endpoints Managed Identities | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-access-resources-from-endpoints-managed-identities.md | Title: Access Azure resources from an online endpoint description: Securely access Azure resources for your machine learning model deployment from an online endpoint with a system-assigned or user-assigned managed identity. -+ |
machine-learning | How To Attach Kubernetes To Workspace | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-attach-kubernetes-to-workspace.md | |
machine-learning | How To Authenticate Batch Endpoint | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-authenticate-batch-endpoint.md | Title: "Authorization on batch endpoints" description: Learn how authentication works on Batch Endpoints. -+ |
machine-learning | How To Authenticate Online Endpoint | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-authenticate-online-endpoint.md | Title: Authenticate clients for online endpoints description: Learn to authenticate clients for an Azure Machine Learning online endpoint. -+ |
machine-learning | How To Autoscale Endpoints | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-autoscale-endpoints.md | Title: Autoscale online endpoints description: Learn to scale up online endpoints. Get more CPU, memory, disk space, and extra features.-+ |
machine-learning | How To Azure Container For Pytorch Environment | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-azure-container-for-pytorch-environment.md | |
machine-learning | How To Batch Scoring Script | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-batch-scoring-script.md | Title: 'Author scoring scripts for batch deployments' description: In this article, learn how to author scoring scripts to perform batch inference in batch deployments. -+ |
machine-learning | How To Configure Environment | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-configure-environment.md | description: Set up Azure Machine Learning Python development environments in Ju -+ Last updated 04/08/2024 |
machine-learning | How To Connect Models Serverless | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-connect-models-serverless.md | Title: Consume deployed serverless API endpoints from a different workspace description: Learn how to consume a serverless API endpoint from a different workspace than the one where it was deployed. -+ Last updated 05/09/2024 |
machine-learning | How To Create Component Pipelines Cli | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-create-component-pipelines-cli.md | Title: Create and run component-based ML pipelines (CLI) description: Create and run machine learning pipelines using the Azure Machine Learning CLI. -+ |
machine-learning | How To Create Component Pipelines Ui | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-create-component-pipelines-ui.md | Title: Create and run component-based ML pipelines (UI) description: Create and run machine learning pipelines using the Azure Machine Learning studio UI. -+ |
machine-learning | How To Create Vector Index | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-create-vector-index.md | |
machine-learning | How To Debug Managed Online Endpoints Visual Studio Code | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-debug-managed-online-endpoints-visual-studio-code.md | Title: Debug online endpoints locally in Visual Studio Code description: Learn how to use Visual Studio Code to test and debug online endpoints locally before deploying them to Azure. -+ |
machine-learning | How To Debug Pipeline Failure | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-debug-pipeline-failure.md | |
machine-learning | How To Debug Pipeline Performance | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-debug-pipeline-performance.md | |
machine-learning | How To Debug Pipeline Reuse Issues | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-debug-pipeline-reuse-issues.md | Title: Debug pipeline reuse issues in Azure Machine Learning description: Learn how reuse works in pipeline and how to debug reuse issues -+ |
machine-learning | How To Deploy Automl Endpoint | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-automl-endpoint.md | Title: Deploy an AutoML model with an online endpoint description: Learn to deploy your AutoML model as a web service that's automatically managed by Azure. -+ |
machine-learning | How To Deploy Custom Container | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-custom-container.md | Title: Deploy a model in a custom container to an online endpoint description: Learn how to use a custom container with an open-source server to deploy a model in Azure Machine Learning. -+ |
machine-learning | How To Deploy Kubernetes Extension | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-kubernetes-extension.md | |
machine-learning | How To Deploy Mlflow Model Spark Jobs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-mlflow-model-spark-jobs.md | Title: Deploy and run MLflow models in Spark jobs description: Learn to deploy your MLflow model in Spark jobs to perform inference. -+ |
machine-learning | How To Deploy Mlflow Models Online Endpoints | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-mlflow-models-online-endpoints.md | Title: Deploy MLflow models to real-time endpoints description: Learn to deploy your MLflow model as a web service that's managed by Azure. -+ |
machine-learning | How To Deploy Mlflow Models Online Progressive | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-mlflow-models-online-progressive.md | Title: Progressive rollout of MLflow models to Online Endpoints description: Learn to deploy your MLflow model progressively using MLflow SDK. -+ |
machine-learning | How To Deploy Model Custom Output | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-model-custom-output.md | Title: "Customize outputs in batch deployments" description: Learn how create deployments that generate custom outputs and files. -+ |
machine-learning | How To Deploy Models Cohere Command | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-models-cohere-command.md | Title: How to deploy Cohere Command models with Azure Machine Learning studio description: Learn how to deploy Cohere Command models with Azure Machine Learning studio. -+ Last updated 04/02/2024 |
machine-learning | How To Deploy Models Cohere Embed | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-models-cohere-embed.md | Title: How to deploy Cohere Embed models with Azure Machine Learning studio description: Learn how to deploy Cohere Embed models with Azure Machine Learning studio. -+ Last updated 04/02/2024 |
machine-learning | How To Deploy Models Cohere Rerank | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-models-cohere-rerank.md | Title: How to deploy Cohere Rerank models as serverless APIs description: Learn to deploy and use Cohere Rerank models with Azure Machine Learning studio. -+ Last updated 07/24/2024 |
machine-learning | How To Deploy Models Mistral | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-models-mistral.md | Title: How to deploy Mistral family of models with Azure Machine Learning studio description: Learn how to deploy Mistral family of models with Azure Machine Learning studio. -+ Last updated 04/29/2024 |
machine-learning | How To Deploy Models Phi 3 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-models-phi-3.md | Title: How to deploy Phi-3 family of small language models with Azure Machine Le description: Learn how to deploy Phi-3 family of small language models with Azure Machine Learning. -+ Last updated 07/01/2024 |
machine-learning | How To Deploy Models Serverless | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-models-serverless.md | Title: Deploy models as serverless APIs description: Learn to deploy models as serverless APIs, using Azure Machine Learning. -+ Last updated 07/19/2024 |
machine-learning | How To Deploy Models Timegen 1 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-models-timegen-1.md | Title: How to deploy TimeGEN-1 model with Azure Machine Learning description: Learn how to deploy TimeGEN-1 with Azure Machine Learning studio. -+ Last updated 5/21/2024 |
machine-learning | How To Deploy Online Endpoint With Secret Injection | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-online-endpoint-with-secret-injection.md | Title: Access secrets from online deployment using secret injection (preview) description: Learn to use secret injection with online endpoint and deployment to access secrets like API keys. -+ |
machine-learning | How To Deploy Online Endpoints | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-online-endpoints.md | Title: Deploy machine learning models to online endpoints for inference description: Learn to deploy your machine learning model as an online endpoint in Azure. -+ |
machine-learning | How To Deploy Pipeline Component As Batch Endpoint | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-pipeline-component-as-batch-endpoint.md | |
machine-learning | How To Deploy With Rest | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-with-rest.md | Title: Deploy models by using online endpoints with REST APIs description: Learn how to deploy models by using online endpoints with REST APIs, including creation of assets, training jobs, and hyperparameter tuning sweep jobs. -+ |
machine-learning | How To Deploy With Triton | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-deploy-with-triton.md | Title: High-performance model serving with Triton description: 'Learn to deploy your model with NVIDIA Triton Inference Server in Azure Machine Learning.' -+ Last updated 11/09/2023 |
machine-learning | How To Enable Preview Features | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-enable-preview-features.md | Title: Manage preview features description: Learn about, and enable, preview features available with Azure Machine Learning. -+ |
machine-learning | How To Image Processing Batch | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-image-processing-batch.md | Title: "Image processing with batch model deployments" description: Learn how to deploy a model in batch endpoints that process images -+ |
machine-learning | How To Inference Server Http | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-inference-server-http.md | |
machine-learning | How To Kubernetes Inference Routing Azureml Fe | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-kubernetes-inference-routing-azureml-fe.md | |
machine-learning | How To Launch Vs Code Remote | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-launch-vs-code-remote.md | Title: 'Launch Visual Studio Code integrated with Azure Machine Learning (previe description: Connect to an Azure Machine Learning compute instance in Visual Studio Code to run interactive Jupyter Notebook and remote development workloads. -+ |
machine-learning | How To Manage Environments In Studio | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-environments-in-studio.md | Title: Manage environments in the studio description: Learn how to create and manage environments in the Azure Machine Learning studio. -+ |
machine-learning | How To Manage Environments V2 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-environments-v2.md | Title: 'Manage Azure Machine Learning environments with the CLI & SDK (v2)' description: Learn how to manage Azure Machine Learning environments using Python SDK and Azure CLI extension for Machine Learning.-+ |
machine-learning | How To Manage Files | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-files.md | |
machine-learning | How To Manage Hub Workspace Portal | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-hub-workspace-portal.md | Title: Manage hub workspaces in portal description: Learn how to manage Azure Machine Learning hub workspaces in the Azure portal. -+ |
machine-learning | How To Manage Inputs Outputs Pipeline | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-inputs-outputs-pipeline.md | Title: Manage inputs and outputs of a pipeline description: How to manage inputs and outputs of components and pipeline in Azure Machine Learning. -+ |
machine-learning | How To Manage Kubernetes Instance Types | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-kubernetes-instance-types.md | |
machine-learning | How To Manage Models Mlflow | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-models-mlflow.md | |
machine-learning | How To Manage Optimize Cost | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-optimize-cost.md | |
machine-learning | How To Manage Resources Vscode | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-resources-vscode.md | |
machine-learning | How To Manage Workspace Cli | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-workspace-cli.md | Title: Create workspaces with Azure CLI description: Learn how to use the Azure CLI machine learning extension to create and manage Azure Machine Learning workspaces. -+ |
machine-learning | How To Manage Workspace Powershell | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-workspace-powershell.md | Title: Create workspaces with Azure PowerShell description: Learn how to use the Azure PowerShell module to create and manage a new Azure Machine Learning workspace. -+ |
machine-learning | How To Manage Workspace | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-manage-workspace.md | Title: Manage workspaces in portal or Python SDK (v2) description: Learn how to manage Azure Machine Learning workspaces in the Azure portal or with the SDK for Python (v2). -+ |
machine-learning | How To Migrate From V1 | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-migrate-from-v1.md | Title: 'Upgrade from v1 to v2' description: Upgrade from v1 to v2 of Azure Machine Learning REST APIs, CLI extension, and Python SDK. -+ |
machine-learning | How To Mlflow Batch | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-mlflow-batch.md | Title: Deploy MLflow models in batch deployments description: Learn how to deploy MLflow models in batch deployments -+ |
machine-learning | How To Nlp Processing Batch | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-nlp-processing-batch.md | Title: "Deploy and run language models in batch endpoints" description: Learn how to use batch deployments to process text with large language models. -+ |
machine-learning | How To Package Models | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-package-models.md | Before following the steps in this article, make sure you have the following pre * Azure role-based access controls (Azure RBAC) are used to grant access to operations in Azure Machine Learning. To perform the steps in this article, your user account must be assigned the owner or contributor role for the Azure Machine Learning workspace, or a custom role. For more information, see [Manage access to an Azure Machine Learning workspace](how-to-assign-roles.md). +* A model to package. This example, uses an MLflow model registered in the workspace. ++ > [!CAUTION] + > Model packaging is not supported for models in the Azure AI model catalog, including large language models. Models in the Azure AI model catalog are optimized for inference on Azure AI deployment targets and are not suitable for packaging. ## About this example |
machine-learning | How To R Deploy R Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-r-deploy-r-model.md | Title: Deploy a registered R model to an online (real time) endpoint description: 'Learn how to deploy your R model to an online (real-time) managed endpoint'-+ Last updated 01/12/2023 |
machine-learning | How To R Interactive Development | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-r-interactive-development.md | Title: Use R interactively on Azure Machine Learning description: 'Learn how to work with R interactively on Azure Machine Learning'-+ Last updated 06/01/2023 |
machine-learning | How To R Modify Script For Production | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-r-modify-script-for-production.md | Title: Adapt your R script to run in production description: 'Learn how to modify your existing R scripts to run in production on Azure Machine Learning'-+ Last updated 01/11/2023 |
machine-learning | How To R Overview R Capabilities | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-r-overview-r-capabilities.md | Title: Bring R workloads into Azure Machine Learning description: 'Learn how to bring your R workloads into Azure Machine Learning'-+ Last updated 01/12/2023 |
machine-learning | How To R Train Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-r-train-model.md | Title: Train R models description: 'Learn how to train your machine learning model with R for use in Azure Machine Learning.'-+ Last updated 03/22/2024 |
machine-learning | How To Run Jupyter Notebooks | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-run-jupyter-notebooks.md | |
machine-learning | How To Search Assets | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-search-assets.md | Title: Search for assets description: Find your Azure Machine Learning assets with search -+ |
machine-learning | How To Secure Batch Endpoint | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-secure-batch-endpoint.md | Title: "Network isolation in batch endpoints" description: Learn how to deploy Batch Endpoints in private networks with isolation. -+ |
machine-learning | How To Secure Kubernetes Inferencing Environment | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-secure-kubernetes-inferencing-environment.md | |
machine-learning | How To Secure Rag Workflows | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-secure-rag-workflows.md | |
machine-learning | How To Setup Vs Code | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-setup-vs-code.md | |
machine-learning | How To Track Experiments Mlflow | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-track-experiments-mlflow.md | |
machine-learning | How To Train Mlflow Projects | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-train-mlflow-projects.md | |
machine-learning | How To Troubleshoot Batch Endpoints | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-troubleshoot-batch-endpoints.md | Title: Troubleshoot batch endpoints description: Learn how to troubleshoot and diagnose errors with batch endpoints jobs, including examining logs for scoring jobs and solution steps for common issues. -+ |
machine-learning | How To Troubleshoot Kubernetes Compute | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-troubleshoot-kubernetes-compute.md | |
machine-learning | How To Troubleshoot Kubernetes Extension | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-troubleshoot-kubernetes-extension.md | |
machine-learning | How To Troubleshoot Online Endpoints | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-troubleshoot-online-endpoints.md | Title: Troubleshooting online endpoints deployment description: Learn how to troubleshoot some common deployment and scoring errors with online endpoints. -+ |
machine-learning | How To Troubleshoot Protobuf Descriptor Error | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-troubleshoot-protobuf-descriptor-error.md | Title: "Troubleshoot `descriptors cannot not be created directly`" description: Troubleshooting steps when you get the "descriptors cannot not be created directly" message. -+ |
machine-learning | How To Troubleshoot Validation For Schema Failed Error | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-troubleshoot-validation-for-schema-failed-error.md | Title: Troubleshoot Validation For Schema Failed Error description: Troubleshooting steps when you get the "Validation for schema failed" error message in Azure Machine Learning v2 CLI -+ |
machine-learning | How To Use Batch Azure Data Factory | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-batch-azure-data-factory.md | Title: "Run batch endpoints from Azure Data Factory" description: Learn how to use Azure Data Factory to invoke Batch Endpoints. -+ |
machine-learning | How To Use Batch Fabric | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-batch-fabric.md | Title: "Consume models deployed in Azure Machine Learning from Fabric, using bat description: Learn to consume an Azure Machine Learning batch model deployment while working in Microsoft Fabric. -+ |
machine-learning | How To Use Batch Model Deployments | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-batch-model-deployments.md | Title: 'Deploy models for scoring in batch endpoints' description: In this article, learn how to create a batch endpoint to continuously batch score large data. -+ |
machine-learning | How To Use Batch Model Openai Embeddings | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-batch-model-openai-embeddings.md | Title: 'Run OpenAI models in batch endpoints' description: In this article, learn how to use batch endpoints with OpenAI models. -+ |
machine-learning | How To Use Batch Pipeline Deployments | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-batch-pipeline-deployments.md | Title: "Deploy pipelines with batch endpoints" description: Learn how to create a batch deploy a pipeline component and invoke it. -+ |
machine-learning | How To Use Batch Pipeline From Job | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-batch-pipeline-from-job.md | Title: How to deploy existing pipeline jobs to a batch endpoint description: Learn how to create pipeline component deployment for Batch Endpoints -+ |
machine-learning | How To Use Batch Scoring Pipeline | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-batch-scoring-pipeline.md | Title: "Operationalize a scoring pipeline on batch endpoints" description: Learn how to operationalize a pipeline that performs batch scoring with preprocessing. -+ |
machine-learning | How To Use Batch Training Pipeline | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-batch-training-pipeline.md | Title: "Operationalize a training pipeline on batch endpoints" description: Learn how to deploy a training pipeline under a batch endpoint. -+ |
machine-learning | How To Use Event Grid Batch | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-event-grid-batch.md | Title: "Run batch endpoints from Event Grid events in storage" description: Learn how to use batch endpoints to be automatically triggered when new files are generated in storage. -+ |
machine-learning | How To Use Low Priority Batch | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-low-priority-batch.md | Title: "Using low priority VMs in batch deployments" description: Learn how to use low priority VMs to save costs when running batch jobs. -+ |
machine-learning | How To Use Mlflow Azure Databricks | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-mlflow-azure-databricks.md | description: Set up MLflow with Azure Machine Learning to log metrics and artif -+ Last updated 07/01/2022 |
machine-learning | How To Use Mlflow Azure Synapse | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-mlflow-azure-synapse.md | description: Set up MLflow with Azure Machine Learning to log metrics and artif -+ Last updated 07/06/2022 |
machine-learning | How To Use Pipelines Prompt Flow | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-pipelines-prompt-flow.md | |
machine-learning | How To Use Retrieval Augmented Generation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-retrieval-augmented-generation.md | |
machine-learning | How To Use Serverless Compute | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-use-serverless-compute.md | Title: Model training on serverless compute description: You no longer need to create your own compute cluster to train your model in a scalable way. You can now use a compute cluster that Azure Machine Learning has made available for you. -+ - build-2023 |
machine-learning | How To View Online Endpoints Costs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-view-online-endpoints-costs.md | Title: View costs for managed online endpoints description: 'Learn to how view costs for a managed online endpoint in Azure Machine Learning.' -+ |
machine-learning | How To Work In Vs Code Remote | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/how-to-work-in-vs-code-remote.md | Title: 'Work in VS Code remotely connected to a compute instance (preview)' description: Details for working with Jupyter notebooks and services from a VS Code remote connection to an Azure Machine Learning compute instance. -+ |
machine-learning | Application Sharing Policy Not Supported | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/known-issues/application-sharing-policy-not-supported.md | description: Configuring the applicationSharingPolicy property for a compute ins -+ Last updated 08/14/2023 |
machine-learning | Azure Machine Learning Known Issues | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/known-issues/azure-machine-learning-known-issues.md | description: Identify issues that are affecting Azure Machine Learning features. -+ Last updated 08/04/2023 |
machine-learning | Compute A10 Sku Not Supported | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/known-issues/compute-a10-sku-not-supported.md | description: While trying to create a compute instance with A10 SKU, users encou -+ Last updated 08/14/2023 |
machine-learning | Compute Idleshutdown Bicep | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/known-issues/compute-idleshutdown-bicep.md | description: When creating an Azure Machine Learning compute instance through Bi -+ Last updated 08/04/2023 |
machine-learning | Compute Slowness Terminal Mounted Path | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/known-issues/compute-slowness-terminal-mounted-path.md | description: While using the compute instance terminal inside a mounted path of -+ Last updated 08/04/2023 |
machine-learning | Inferencing Invalid Certificate | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/known-issues/inferencing-invalid-certificate.md | description: During machine learning deployments with an AKS cluster, you may re -+ Last updated 08/04/2023 |
machine-learning | Inferencing Updating Kubernetes Compute Appears To Succeed | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/known-issues/inferencing-updating-kubernetes-compute-appears-to-succeed.md | description: Updating a Kubernetes attached compute instance using the az ml att -+ Last updated 08/04/2023 |
machine-learning | Jupyter R Kernel Not Starting | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/known-issues/jupyter-r-kernel-not-starting.md | description: When trying to launch an R kernel in JupyterLab or a notebook in a -+ Last updated 08/14/2023 |
machine-learning | Workspace Move Compute Instance Same Name | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/known-issues/workspace-move-compute-instance-same-name.md | description: After moving a workspace to a different subscription or resource gr -+ Last updated 08/14/2023 |
machine-learning | Migrate To V2 Assets Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-assets-model.md | Title: Upgrade model management to SDK v2 description: Upgrade model management from v1 to v2 of Azure Machine Learning SDK -+ |
machine-learning | Migrate To V2 Command Job | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-command-job.md | Title: 'Upgrade script run to SDK v2' description: Upgrade how to run a script from SDK v1 to SDK v2 -+ |
machine-learning | Migrate To V2 Deploy Endpoints | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-deploy-endpoints.md | Title: Upgrade deployment endpoints to SDK v2 description: Upgrade deployment endpoints from v1 to v2 of Azure Machine Learning SDK -+ |
machine-learning | Migrate To V2 Deploy Pipelines | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-deploy-pipelines.md | Title: Upgrade pipeline endpoints to SDK v2 description: Upgrade pipeline endpoints from v1 to v2 of Azure Machine Learning SDK. -+ |
machine-learning | Migrate To V2 Execution Automl | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-execution-automl.md | Title: Upgrade AutoML to SDK v2 description: Upgrade AutoML from v1 to v2 of Azure Machine Learning SDK -+ |
machine-learning | Migrate To V2 Execution Hyperdrive | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-execution-hyperdrive.md | Title: Upgrade hyperparameter tuning to SDK v2 description: Upgrade hyperparameter tuning from v1 to v2 of Azure Machine Learning SDK -+ |
machine-learning | Migrate To V2 Execution Parallel Run Step | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-execution-parallel-run-step.md | Title: Upgrade parallel run step to SDK v2 description: Upgrade parallel run step from v1 to v2 of Azure Machine Learning SDK -+ |
machine-learning | Migrate To V2 Execution Pipeline | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-execution-pipeline.md | Title: Upgrade pipelines to SDK v2 description: Upgrade pipelines from v1 to v2 of Azure Machine Learning SDK -+ |
machine-learning | Migrate To V2 Local Runs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-local-runs.md | Title: Upgrade local runs to SDK v2 description: Upgrade local runs from v1 to v2 of Azure Machine Learning SDK -+ |
machine-learning | Migrate To V2 Managed Online Endpoints | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-managed-online-endpoints.md | Title: Upgrade steps for Azure Container Instances web services to managed onlin description: Upgrade steps for Azure Container Instances web services to managed online endpoints in Azure Machine Learning -+ |
machine-learning | Migrate To V2 Resource Datastore | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-resource-datastore.md | Title: Upgrade datastore management to SDK v2 description: Upgrade datastore management from v1 to v2 of Azure Machine Learning SDK -+ |
machine-learning | Migrate To V2 Resource Workspace | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/migrate-to-v2-resource-workspace.md | Title: Upgrade workspace management to SDK v2 description: Upgrade workspace management from v1 to v2 of Azure Machine Learning SDK -+ |
machine-learning | Overview What Is Azure Machine Learning | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/overview-what-is-azure-machine-learning.md | Title: What is Azure Machine Learning? description: 'Azure Machine Learning is a cloud service for accelerating and managing the machine learning project lifecycle: Train and deploy models, and manage MLOps.' -+ |
machine-learning | Concept Connections | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/prompt-flow/concept-connections.md | Title: Connections in Azure Machine Learning prompt flow description: Learn about how in Azure Machine Learning prompt flow, you can utilize connections to effectively manage credentials or secrets for APIs and data sources. -+ - ignite-2023 |
machine-learning | Concept Flows | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/prompt-flow/concept-flows.md | Title: What are flows in Azure Machine Learning prompt flow description: Learn about how a flow in prompt flow serves as an executable workflow that streamlines the development of your LLM-based AI application. It provides a comprehensive framework for managing data flow and processing within your application. -+ - ignite-2023 |
machine-learning | Concept Session | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/prompt-flow/concept-session.md | Title: Compute session in Azure Machine Learning prompt flow description: Learn about how in Azure Machine Learning prompt flow, the execution of flows is facilitated by using compute session. -+ - ignite-2023 |
machine-learning | Quickstart Create Resources | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/quickstart-create-resources.md | Title: "Tutorial: Create workspace resources" description: Create an Azure Machine Learning workspace and cloud resources that can be used to train machine learning models. -+ |
machine-learning | Reference Automated Ml Forecasting | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-automated-ml-forecasting.md | Title: 'CLI (v2) Automated ML Forecasting command job YAML schema' description: Reference documentation for the CLI (v2) Forecasting command job YAML schema. -+ |
machine-learning | Reference Automl Images Cli Classification | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-automl-images-cli-classification.md | Title: 'CLI (v2) Automated ML Image Classification job YAML schema' description: Reference documentation for the CLI (v2) Automated ML Image Classification job YAML schema. -+ |
machine-learning | Reference Automl Images Cli Instance Segmentation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-automl-images-cli-instance-segmentation.md | Title: 'CLI (v2) Automated ML Image Instance Segmentation job YAML schema' description: Reference documentation for the CLI (v2) Automated ML Image Instance Segmentation job YAML schema. -+ |
machine-learning | Reference Automl Images Cli Multilabel Classification | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-automl-images-cli-multilabel-classification.md | Title: 'CLI (v2) Automated ML Image Multi-Label Classification job YAML schema' description: Reference documentation for the CLI (v2) Automated ML Image Multi-Label Classification job YAML schema. -+ |
machine-learning | Reference Automl Images Cli Object Detection | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-automl-images-cli-object-detection.md | Title: 'CLI (v2) Automated ML Image Object Detection job YAML schema' description: Reference documentation for the CLI (v2) Automated ML Image Object Detection job YAML schema. -+ |
machine-learning | Reference Automl Nlp Cli Ner | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-automl-nlp-cli-ner.md | Title: 'CLI (v2) Automated ML NLP text NER job YAML schema' description: Reference documentation for the CLI (v2) automated ML NLP text NER job YAML schema. -+ |
machine-learning | Reference Automl Nlp Cli Text Classification | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-automl-nlp-cli-text-classification.md | Title: 'CLI (v2) Automated ML text classification job YAML schema' description: Reference documentation for the CLI (v2) automated ML text classification job YAML schema. -+ |
machine-learning | Reference Kubernetes | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-kubernetes.md | |
machine-learning | Reference Machine Learning Cloud Parity | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-machine-learning-cloud-parity.md | Title: Feature availability across cloud regions description: This article lists feature availability differences between public cloud and the Azure Government, Azure Germany, and Azure operated by 21Vianet regions. -+ |
machine-learning | Reference Managed Online Endpoints Vm Sku List | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-managed-online-endpoints-vm-sku-list.md | Title: Managed online endpoints VM SKU list description: Lists the VM SKUs that can be used for managed online endpoints in Azure Machine Learning. -+ |
machine-learning | Reference Migrate Sdk V1 Mlflow Tracking | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-migrate-sdk-v1-mlflow-tracking.md | Title: Migrate logging from SDK v1 to MLflow description: Comparison of SDK v1 logging APIs and MLflow tracking -+ |
machine-learning | Reference Model Inference Api | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-model-inference-api.md | Title: Azure AI Model Inference API description: Learn about how to use the Azure AI Model Inference API -+ Last updated 05/03/2024 |
machine-learning | Reference Model Inference Chat Completions | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-model-inference-chat-completions.md | Title: Azure AI Model Inference Chat Completions description: Reference for Azure AI Model Inference Chat Completions API -+ Last updated 05/03/2024 |
machine-learning | Reference Model Inference Completions | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-model-inference-completions.md | Title: Azure AI Model Inference Completions description: Reference for Azure AI Model Inference Completions API -+ Last updated 05/03/2024 |
machine-learning | Reference Model Inference Embeddings | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-model-inference-embeddings.md | Title: Azure AI Model Inference Embeddings API description: Reference for Azure AI Model Inference Embeddings API -+ Last updated 05/03/2024 |
machine-learning | Reference Model Inference Images Embeddings | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-model-inference-images-embeddings.md | Title: Azure AI Model Inference Image Embeddings description: Reference for Azure AI Model Inference Image Embeddings API -+ Last updated 05/03/2024 |
machine-learning | Reference Model Inference Info | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-model-inference-info.md | Title: Azure AI Model Inference Get Info description: Reference for Azure AI Model Inference Get Info API -+ Last updated 05/03/2024 |
machine-learning | Reference Yaml Component Command | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-component-command.md | Title: 'CLI (v2) command component YAML schema' description: Reference documentation for the CLI (v2) command component YAML schema. -+ |
machine-learning | Reference Yaml Component Pipeline | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-component-pipeline.md | Title: 'CLI (v2) pipeline component YAML schema' description: Reference documentation for the CLI (v2) pipeline component YAML schema. -+ |
machine-learning | Reference Yaml Component Spark | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-component-spark.md | Title: 'CLI (v2) Spark component YAML schema' description: Reference documentation for the CLI (v2) Spark component YAML schema. -+ |
machine-learning | Reference Yaml Compute Aml | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-compute-aml.md | Title: 'CLI (v2) compute cluster (AmlCompute) YAML schema' description: Reference documentation for the CLI (v2) compute cluster (AmlCompute) YAML schema. -+ |
machine-learning | Reference Yaml Compute Instance | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-compute-instance.md | Title: 'CLI (v2) compute instance YAML schema' description: Reference documentation for the CLI (v2) compute instance YAML schema. -+ |
machine-learning | Reference Yaml Compute Kubernetes | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-compute-kubernetes.md | Title: 'CLI (v2) Attached Kubernetes cluster (KubernetesCompute) YAML schema' description: Reference documentation for the CLI (v2) Attached Azure Arc-enabled Kubernetes cluster (KubernetesCompute) YAML schema. -+ |
machine-learning | Reference Yaml Compute Vm | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-compute-vm.md | Title: 'CLI (v2) attached Virtual Machine YAML schema' description: Reference documentation for the CLI (v2) attached Virtual Machine schema. -+ |
machine-learning | Reference Yaml Connection Ai Content Safety | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-ai-content-safety.md | Title: 'CLI (v2) AI Content Safety connection YAML schema' description: Reference documentation for the CLI (v2) AI Content Safety connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Ai Search | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-ai-search.md | Title: 'CLI (v2) AI Search connection YAML schema' description: Reference documentation for the CLI (v2) AI Search connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Ai Services | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-ai-services.md | Title: 'CLI (v2) AI Services connection YAML schema' description: Reference documentation for the CLI (v2) Azure AI Services connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Api Key | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-api-key.md | Title: 'CLI (v2) API key connection YAML schema' description: Reference documentation for the CLI (v2) API key connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Azure Openai | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-azure-openai.md | Title: 'CLI (v2) Azure OpenAI connection YAML schema' description: Reference documentation for the CLI (v2) Azure OpenAI connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Blob | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-blob.md | Title: 'CLI (v2) blob store connection YAML schema' description: Reference documentation for the CLI (v2) blob store connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Container Registry | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-container-registry.md | Title: 'CLI (v2) Azure Container Registry connection YAML schema' description: Reference documentation for the CLI (v2) Azure Container Registry connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Custom Key | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-custom-key.md | Title: 'CLI (v2) custom key connection YAML schema' description: Reference documentation for the CLI (v2) custom key connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Data Lake | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-data-lake.md | Title: 'CLI (v2) Data Lake Store Gen 2 connection YAML schema' description: Reference documentation for the CLI (v2) Azure Data Lake Store Gen 2 connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Git | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-git.md | Title: 'CLI (v2) Git connection YAML schema' description: Reference documentation for the CLI (v2) Git connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Onelake | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-onelake.md | Title: 'CLI (v2) OneLake connection YAML schema' description: Reference documentation for the CLI (v2) OneLake connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Openai | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-openai.md | Title: 'CLI (v2) OpenAI connection YAML schema' description: Reference documentation for the CLI (v2) OpenAI connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Python Feed | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-python-feed.md | Title: 'CLI (v2) Python feed connection YAML schema' description: Reference documentation for the CLI (v2) Python feed connections YAML schema. -+ |
machine-learning | Reference Yaml Connection Serp | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-serp.md | Title: 'CLI (v2) Serp connection YAML schema' description: Reference documentation for the CLI (v2) Serp connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Serverless | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-serverless.md | Title: 'CLI (v2) serverless connection YAML schema' description: Reference documentation for the CLI (v2) serverless connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Connection Speech | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-connection-speech.md | Title: 'CLI (v2) AI Speech Services connection YAML schema' description: Reference documentation for the CLI (v2) AI Speech Services connections YAML schema. -+ - build-2024 |
machine-learning | Reference Yaml Core Syntax | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-core-syntax.md | Title: 'CLI (v2) core YAML syntax' description: Overview CLI (v2) core YAML syntax. -+ |
machine-learning | Reference Yaml Deployment Batch | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-deployment-batch.md | Title: 'CLI (v2) batch deployment YAML schema' description: Reference documentation for the CLI (v2) batch deployment YAML schema. -+ |
machine-learning | Reference Yaml Endpoint Batch | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-endpoint-batch.md | Title: 'CLI (v2) batch endpoint YAML schema' description: Reference documentation for the CLI (v2) batch endpoint YAML schema. -+ |
machine-learning | Reference Yaml Environment | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-environment.md | Title: 'CLI (v2) environment YAML schema' description: Reference documentation for the CLI (v2) environment YAML schema.-+ |
machine-learning | Reference Yaml Job Command | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-job-command.md | Title: 'CLI (v2) command job YAML schema' description: Reference documentation for the CLI (v2) command job YAML schema. -+ |
machine-learning | Reference Yaml Job Parallel | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-job-parallel.md | Title: 'CLI (v2) parallel job YAML schema' description: Reference documentation for the CLI (v2) parallel job YAML schema. -+ |
machine-learning | Reference Yaml Job Pipeline | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-job-pipeline.md | Title: 'CLI (v2) pipeline job YAML schema' description: Reference documentation for the CLI (v2) pipeline job YAML schema. -+ |
machine-learning | Reference Yaml Job Spark | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-job-spark.md | Title: 'CLI (v2) Spark job YAML schema' description: Reference documentation for the CLI (v2) Spark job YAML schema. -+ |
machine-learning | Reference Yaml Job Sweep | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-job-sweep.md | Title: 'CLI (v2) sweep job YAML schema' description: Reference documentation for the CLI (v2) sweep job YAML schema. -+ |
machine-learning | Reference Yaml Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-model.md | Title: 'CLI (v2) model YAML schema' description: Reference documentation for the CLI (v2) model YAML schema. -+ |
machine-learning | Reference Yaml Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-overview.md | Title: 'CLI (v2) YAML schema overview' description: Overview and index of CLI (v2) YAML schemas. -+ |
machine-learning | Reference Yaml Registry | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-registry.md | Title: 'CLI (v2) registry YAML schema' description: Reference documentation for the CLI (v2) registry YAML schema. -+ |
machine-learning | Reference Yaml Schedule Data Import | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-schedule-data-import.md | Title: 'CLI (v2) schedule YAML schema for data import (preview)' description: Reference documentation for the CLI (v2) data import schedule YAML schema. -+ |
machine-learning | Reference Yaml Schedule | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-schedule.md | Title: 'CLI (v2) schedule YAML schema' description: Reference documentation for the CLI (v2) job schedule YAML schema. -+ |
machine-learning | Reference Yaml Workspace | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/reference-yaml-workspace.md | Title: 'CLI (v2) workspace YAML schema' description: Reference documentation for the CLI (v2) workspace YAML schema. -+ |
machine-learning | Resource Azure Container For Pytorch | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/resource-azure-container-for-pytorch.md | |
machine-learning | Resource Curated Environments | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/resource-curated-environments.md | |
machine-learning | Resource Limits Capacity | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/resource-limits-capacity.md | |
machine-learning | Samples Notebooks | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/samples-notebooks.md | Title: Example Jupyter Notebooks (v2) description: Learn how to find and use the Jupyter Notebooks designed to help you explore the SDK (v2) and serve as models for your own machine learning projects. -+ |
machine-learning | Tutorial Azure Ml In A Day | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-azure-ml-in-a-day.md | Title: "Quickstart: Get started with Azure Machine Learning" description: Use Azure Machine Learning to train and deploy a model in a cloud-based Python Jupyter Notebook. -+ |
machine-learning | Tutorial Cloud Workstation | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-cloud-workstation.md | Title: "Tutorial: Model development on a cloud workstation" description: Learn how to get started prototyping and developing machine learning models on an Azure Machine Learning cloud workstation. -+ |
machine-learning | Tutorial Deploy Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-deploy-model.md | Title: "Tutorial: Deploy a model" description: This tutorial covers how to deploy a model to production using Azure Machine Learning Python SDK v2. -+ |
machine-learning | Tutorial Develop Feature Set With Custom Source | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-develop-feature-set-with-custom-source.md | Title: "Tutorial 5: Develop a feature set with a custom source" description: This is part 5 of the managed feature store tutorial series -+ |
machine-learning | Tutorial Enable Recurrent Materialization Run Batch Inference | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-enable-recurrent-materialization-run-batch-inference.md | Title: "Tutorial 3: Enable recurrent materialization and run batch inference" description: This is part of a tutorial series on managed feature store. -+ |
machine-learning | Tutorial Experiment Train Models Using Features | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-experiment-train-models-using-features.md | Title: "Tutorial 2: Experiment and train models by using features" description: This is part of a tutorial series about managed feature store. -+ |
machine-learning | Tutorial Explore Data | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-explore-data.md | Title: "Tutorial: upload, access, and explore your data" description: Upload data to cloud storage, create an Azure Machine Learning data asset, create new versions for data assets, and use the data for interactive development -+ |
machine-learning | Tutorial Feature Store Domain Specific Language | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-feature-store-domain-specific-language.md | Title: "Tutorial 7: Develop a feature set using Domain Specific Language (previe description: This is part 7 of the managed feature store tutorial series. -+ |
machine-learning | Tutorial Get Started With Feature Store | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-get-started-with-feature-store.md | Title: "Tutorial 1: Develop and register a feature set with managed feature stor description: This is the first part of a tutorial series on managed feature store. -+ |
machine-learning | Tutorial Network Isolation For Feature Store | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-network-isolation-for-feature-store.md | Title: "Tutorial 6: Network isolation for feature store" description: This is part 6 of the managed feature store tutorial series -+ |
machine-learning | Tutorial Online Materialization Inference | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-online-materialization-inference.md | Title: "Tutorial 4: Enable online materialization and run online inference" description: This is a part of a tutorial series on managed feature store. -+ |
machine-learning | Tutorial Pipeline Python Sdk | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-pipeline-python-sdk.md | Title: "Tutorial: ML pipelines with Python SDK v2" description: Use Azure Machine Learning to create your production-ready ML project in a cloud-based Python Jupyter Notebook using Azure Machine Learning Python SDK v2. -+ |
machine-learning | Tutorial Train Deploy Image Classification Model Vscode | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-train-deploy-image-classification-model-vscode.md | Title: "Tutorial: Train image classification model: VS Code (preview)" description: Learn how to train an image classification model using TensorFlow and the Azure Machine Learning Visual Studio Code Extension -+ |
machine-learning | Tutorial Train Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/tutorial-train-model.md | Title: "Tutorial: Train a model" description: Dive in to the process of training a model -+ - build-2023 |
machine-learning | Azure Machine Learning Release Notes | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/azure-machine-learning-release-notes.md | Title: Python SDK release notes description: Learn about the latest updates to Azure Machine Learning Python SDK. -+ |
machine-learning | Concept Azure Machine Learning Architecture | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/concept-azure-machine-learning-architecture.md | Title: 'Architecture & key concepts (v1)' description: This article gives you a high-level understanding of the architecture, terms, and concepts that make up Azure Machine Learning. -+ |
machine-learning | Concept Designer | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/concept-designer.md | Title: What is Designer (v1)? description: Learn about how the drag-and-drop Designer (v1) UI in Azure Machine Learning studio enables model training and deployment tasks. -+ |
machine-learning | Concept Train Machine Learning Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/concept-train-machine-learning-model.md | Title: 'Build & train models (v1)' description: Learn how to train models with Azure Machine Learning (v1). Explore the different training methods and choose the right one for your project. -+ |
machine-learning | How To Configure Environment | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-configure-environment.md | description: Set up Azure Machine Learning (v1) Python development environments -+ Last updated 09/30/2022 |
machine-learning | How To Consume Web Service | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-consume-web-service.md | az ml service show -n <service-name> From Azure Machine Learning studio, select __Endpoints__, __Real-time endpoints__, and then the endpoint name. In details for the endpoint, the __REST endpoint__ field contains the scoring URI. The __Swagger URI__ contains the swagger URI. +> [!NOTE] +> Although you can retrieve scoring URI, swagger URI and other information from Azure Machine Learning studio (UI), using Test tab on Azure Machine Learning studio isn't supported for Azure Container Instance or Azure Kubernetes Service based web services. Instead, use code based approach to consume the web service as described in the later section of this article. To fully utilize Test tab to test the deployments, consider [migrating to v2 Managed online endpoint](../migrate-to-v2-deploy-endpoints.md). For more, see [endpoints for inferencing](../concept-endpoints.md). + The following table shows what these URIs look like: |
machine-learning | How To Create Attach Kubernetes | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-create-attach-kubernetes.md | Title: Create and attach Azure Kubernetes Service description: 'Learn how to create a new Azure Kubernetes Service cluster through Azure Machine Learning, or how to attach an existing AKS cluster to your workspace.' -+ |
machine-learning | How To Deploy Local Container Notebook Vm | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-deploy-local-container-notebook-vm.md | Title: Deploy models to compute instances description: 'Learn how to deploy your Azure Machine Learning models as a web service using compute instances.' -+ |
machine-learning | How To Deploy Local | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-deploy-local.md | Title: How to run and deploy locally description: 'This article describes how to use your local computer as a target for training, debugging, or deploying models created in Azure Machine Learning.' -+ |
machine-learning | How To Deploy Mlflow Models | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-deploy-mlflow-models.md | |
machine-learning | How To Deploy Model Cognitive Search | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-deploy-model-cognitive-search.md | Title: Deploy a model for use with Azure AI Search description: Learn how to use Azure Machine Learning to deploy a model for use with Azure AI Search. The model is used as a custom skill to enrich the search experience. -+ |
machine-learning | How To Deploy Model Designer | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-deploy-model-designer.md | Title: Use the studio to deploy models trained in the designer description: Use Azure Machine Learning studio to deploy machine learning models without writing a single line of code. -+ |
machine-learning | How To Designer Python | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-designer-python.md | Title: Execute Python Script in the designer description: Learn how to use the Execute Python Script model in Azure Machine Learning designer to run custom operations written in Python. -+ |
machine-learning | How To Log View Metrics | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-log-view-metrics.md | |
machine-learning | How To Manage Workspace Cli | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-manage-workspace-cli.md | Title: Create workspaces with Azure CLI extension v1 description: Learn how to use the Azure CLI extension v1 for machine learning to create a new Azure Machine Learning workspace. -+ |
machine-learning | How To Manage Workspace | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-manage-workspace.md | Title: Manage workspaces in portal or Python SDK (v1) description: Learn how to manage Azure Machine Learning workspaces in the Azure portal or with the SDK for Python (v1). -+ |
machine-learning | How To Save Write Experiment Files | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-save-write-experiment-files.md | |
machine-learning | How To Track Designer Experiments | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-track-designer-experiments.md | |
machine-learning | How To Train Distributed Gpu | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-train-distributed-gpu.md | description: Learn the best practices for performing distributed training with A -+ Last updated 10/21/2021 |
machine-learning | How To Train Model | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-train-model.md | Title: Train models with the Azure Machine Learning Python SDK (v1) (preview) + Title: Train models with the Azure Machine Learning Python SDK (v1) description: Add compute resources (compute targets) to your workspace to use for machine learning training and inference with SDK v1. -+ Last updated 10/21/2021 Azure Machine Learning also supports attaching an Azure Virtual Machine. The VM > > Azure Machine Learning also requires the virtual machine to have a __public IP address__. -1. **Attach**: To attach an existing virtual machine as a compute target, you must provide the resource ID, user name, and password for the virtual machine. The resource ID of the VM can be constructed using the subscription ID, resource group name, and VM name using the following string format: `/subscriptions/<subscription_id>/resourceGroups/<resource_group>/providers/Microsoft.Compute/virtualMachines/<vm_name>` - - ```python - from azureml.core.compute import RemoteCompute, ComputeTarget -- # Create the compute config - compute_target_name = "attach-dsvm" - - attach_config = RemoteCompute.attach_configuration(resource_id='<resource_id>', - ssh_port=22, - username='<username>', - password="<password>") -- # Attach the compute - compute = ComputeTarget.attach(ws, compute_target_name, attach_config) -- compute.wait_for_completion(show_output=True) - ``` -- Or you can attach the DSVM to your workspace [using Azure Machine Learning studio](../how-to-create-attach-compute-studio.md#other-compute-targets). +1. **Attach**: Attach the DSVM to your workspace [using Azure Machine Learning studio](../how-to-create-attach-compute-studio.md#other-compute-targets). > [!WARNING] > Do not create multiple, simultaneous attachments to the same DSVM from your workspace. Each new attachment will break the previous existing attachment(s). Azure HDInsight is a popular platform for big-data analytics. The platform provi After the cluster is created, connect to it with the hostname \<clustername>-ssh.azurehdinsight.net, where \<clustername> is the name that you provided for the cluster. -1. **Attach**: To attach an HDInsight cluster as a compute target, you must provide the resource ID, user name, and password for the HDInsight cluster. The resource ID of the HDInsight cluster can be constructed using the subscription ID, resource group name, and HDInsight cluster name using the following string format: `/subscriptions/<subscription_id>/resourceGroups/<resource_group>/providers/Microsoft.HDInsight/clusters/<cluster_name>` -- ```python - from azureml.core.compute import ComputeTarget, HDInsightCompute - from azureml.exceptions import ComputeTargetException -- try: - # if you want to connect using SSH key instead of username/password you can provide parameters private_key_file and private_key_passphrase -- attach_config = HDInsightCompute.attach_configuration(resource_id='<resource_id>', - ssh_port=22, - username='<ssh-username>', - password='<ssh-pwd>') - hdi_compute = ComputeTarget.attach(workspace=ws, - name='myhdi', - attach_configuration=attach_config) -- except ComputeTargetException as e: - print("Caught = {}".format(e.message)) -- hdi_compute.wait_for_completion(show_output=True) - ``` -- Or you can attach the HDInsight cluster to your workspace [using Azure Machine Learning studio](../how-to-create-attach-compute-studio.md#other-compute-targets). +1. **Attach**: Attach the HDInsight cluster to your workspace [using Azure Machine Learning studio](../how-to-create-attach-compute-studio.md#other-compute-targets). > [!WARNING] > Do not create multiple, simultaneous attachments to the same HDInsight from your workspace. Each new attachment will break the previous existing attachment(s). |
machine-learning | How To Train With Custom Image | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-train-with-custom-image.md | Title: Train a model by using a custom Docker image description: Learn how to use your own Docker images, or curated ones from Microsoft, to train models in Azure Machine Learning. -+ |
machine-learning | How To Troubleshoot Serialization Error | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-troubleshoot-serialization-error.md | Title: Troubleshoot SerializationError description: Troubleshooting steps when you get the "cannot import name 'SerializationError'" message. -+ |
machine-learning | How To Tune Hyperparameters | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-tune-hyperparameters.md | description: Automate hyperparameter tuning for deep learning and machine learni -+ Last updated 05/30/2024 |
machine-learning | How To Use Environments | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-use-environments.md | description: Create and manage environments for model training and deployment wi -+ Last updated 04/19/2022 |
machine-learning | How To Use Private Python Packages | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/how-to-use-private-python-packages.md | |
machine-learning | Introduction | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/introduction.md | Title: SDK & CLI (v1) description: Learn about Azure Machine Learning SDK & CLI (v1). -+ |
machine-learning | Reference Azure Machine Learning Cli | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/reference-azure-machine-learning-cli.md | Title: 'Install and set up the CLI (v1)' description: Learn how to use the Azure CLI extension (v1) for ML to create & manage resources such as your workspace, datastores, datasets, pipelines, models, and deployments. -+ |
machine-learning | Reference Pipeline Yaml | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/reference-pipeline-yaml.md | Title: Machine Learning pipeline YAML (v1) description: Learn how to define a machine learning pipeline using a YAML file. YAML pipeline definitions are used with the machine learning extension for the Azure CLI (v1). -+ |
machine-learning | Samples Designer | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/samples-designer.md | Title: Example pipelines & datasets for the designer description: Learn how to use samples in Azure Machine Learning designer to jumps-start your machine learning pipelines. -+ |
machine-learning | Samples Notebooks | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/samples-notebooks.md | Title: Example Jupyter Notebooks (v1) description: Learn how to find and use the Juypter Notebooks designed to help you explore the SDK (v1) and serve as models for your own machine learning projects. -+ |
machine-learning | Tutorial 1St Experiment Hello World | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/tutorial-1st-experiment-hello-world.md | Title: 'Tutorial: Get started with a Python script (v1)' description: Get started with your first Python script in Azure Machine Learning, with SDK v1. This is part 1 of a two-part getting-started series. -+ |
machine-learning | Tutorial Designer Automobile Price Deploy | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/tutorial-designer-automobile-price-deploy.md | |
machine-learning | Tutorial Designer Automobile Price Train Score | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/tutorial-designer-automobile-price-train-score.md | |
machine-learning | Tutorial Train Deploy Notebook | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/machine-learning/v1/tutorial-train-deploy-notebook.md | Title: "Tutorial: Train and deploy an example in Jupyter Notebook" description: Use Azure Machine Learning to train and deploy an image classification model with scikit-learn in a cloud-based Python Jupyter Notebook. -+ |
modeling-simulation-workbench | Modeling Simulation Workbench Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/modeling-simulation-workbench/modeling-simulation-workbench-overview.md | Last updated 03/15/2024 # What is Azure Modeling and Simulation Workbench? -The Azure Modeling and Simulation Workbench is a secure, on-demand service that provides a fully managed engineering design and simulation environment for safe and efficient user collaboration. The service incorporates many infrastructure services required to build a successful environment for engineering development, such as: workload specific VMs, scheduler, orchestration, license server, remote connectivity, high performance storage, network configurations, security, and access controls. +Azure Modeling and Simulation Workbench is a secure, on-demand service that provides a fully managed engineering design and simulation environment for safe and efficient user collaboration. The service incorporates many infrastructure services required to build a successful environment for engineering development, such as: workload specific VMs, scheduler, orchestration, license server, remote connectivity, high performance storage, network configurations, security, and access controls. - A chamber environment enables primary development teams to onboard their collaborators (customers, partners, ISVs, service/IP providers) for joint analysis/debug activity within the same chamber. - Multi-layered security and access controls allow users to monitor, scale, and optimize the compute and storage capacity as needed. |
mysql | Connect Azure Cli | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/connect-azure-cli.md | |
mysql | Connect Csharp | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/connect-csharp.md | |
mysql | Connect Nodejs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/connect-nodejs.md | |
mysql | Connect Php | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/connect-php.md | |
mysql | Connect Python | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/connect-python.md | |
mysql | How To Deploy On Azure Free Account | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/how-to-deploy-on-azure-free-account.md | |
mysql | How To Troubleshoot Common Connection Issues | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/how-to-troubleshoot-common-connection-issues.md | |
mysql | Quickstart Create Arm Template | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/quickstart-create-arm-template.md | |
mysql | Quickstart Create Bicep | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/quickstart-create-bicep.md | |
mysql | Quickstart Create Server Cli | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/quickstart-create-server-cli.md | |
mysql | Quickstart Create Terraform | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/quickstart-create-terraform.md | |
mysql | Sample Scripts Azure Cli | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/sample-scripts-azure-cli.md | |
mysql | Sample Cli Audit Logs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-audit-logs.md | |
mysql | Sample Cli Change Server Parameters | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-change-server-parameters.md | |
mysql | Sample Cli Create Connect Private Access | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-create-connect-private-access.md | |
mysql | Sample Cli Create Connect Public Access | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-create-connect-public-access.md | |
mysql | Sample Cli Monitor And Scale | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-monitor-and-scale.md | |
mysql | Sample Cli Read Replicas | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-read-replicas.md | |
mysql | Sample Cli Restart Stop Start | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-restart-stop-start.md | |
mysql | Sample Cli Restore Server | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-restore-server.md | |
mysql | Sample Cli Same Zone Ha | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-same-zone-ha.md | |
mysql | Sample Cli Slow Query Logs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-slow-query-logs.md | |
mysql | Sample Cli Zone Redundant Ha | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/scripts/sample-cli-zone-redundant-ha.md | |
mysql | Tutorial Deploy Springboot On Aks Vnet | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/tutorial-deploy-springboot-on-aks-vnet.md | |
mysql | Tutorial Php Database App | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/tutorial-php-database-app.md | |
mysql | Tutorial Simple Php Mysql App | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/tutorial-simple-php-mysql-app.md | |
mysql | Whats New | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/mysql/flexible-server/whats-new.md | This article summarizes new releases and features in the Azure Database for MySQ > [!NOTE] > This article references the term slave, which Microsoft no longer uses. When the term is removed from the software, we'll remove it from this article. +## August 2024 ++- **Major version upgrade support for Burstable compute tier** + + Azure Database for MySQL now offers major version upgrades for Burstable SKU compute tiers. This support automatically upgrades the compute tier to General Purpose SKU before performing the upgrade, ensuring sufficient resources. Customers can choose to revert back to Burstable SKU after the upgrade. Additional costs may apply. [Learn more](how-to-upgrade.md#perform-a-planned-major-version-upgrade-from-mysql-57-to-mysql-80-using-the-azure-portal-for-burstable-sku-servers) + ## July 2024 - **Move from private access (virtual network integrated) network to public access or private link** |
operator-nexus | Concepts Compute | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/operator-nexus/concepts-compute.md | -Azure Operator Nexus is built on basic constructs like compute servers, storage appliances, and network fabric devices. These compute servers, also called bare-metal machines (BMMs), represent the physical machines on the rack. They run the CBL-Mariner operating system and provide closed integration support for high-performance workloads. +Azure Operator Nexus is built on basic constructs like compute servers, storage appliances, and network fabric devices. These compute servers, also called bare-metal machines (BMMs), represent the physical machines on the rack. They run the Azure Linux (formerly CBL-Mariner) operating system and provide closed integration support for high-performance workloads. These BMMs are deployed as part of the Azure Operator Nexus automation suite. They exist as nodes in a Kubernetes cluster to serve various virtualized and containerized workloads in the ecosystem. Each BMM in an Azure Operator Nexus instance is represented as an Azure resource Nonuniform memory access (NUMA) alignment is a technique to optimize performance and resource utilization in multiple-socket servers. It involves aligning memory and compute resources to reduce latency and improve data access within a server system. -Through the strategic placement of software components and workloads in a NUMA-aware way, Operators can enhance the performance of network functions, such as virtualized routers and firewalls. This placement leads to improved service delivery and responsiveness in their telco cloud environments. +Through the strategic placement of software components and workloads in a NUMA-aware way, Operators can enhance the performance of network functions, such as virtualized routers and firewalls. This placement leads to improved service delivery and responsiveness in their cloud environments. By default, all the workloads deployed in an Azure Operator Nexus instance are NUMA aligned. Azure Operator Nexus reserves a small set of CPUs for the host operating system ### Huge page support -Huge page usage in telco workloads refers to the utilization of large memory pages, typically 2 MB or 1 GB in size, instead of the standard 4-KB pages. This approach helps reduce memory overhead and improves the overall system performance. It reduces the translation look-aside buffer (TLB) miss rate and improves memory access efficiency. +Huge page usage in workloads refers to the utilization of large memory pages, typically 2 MB or 1 GB in size, instead of the standard 4-KB pages. This approach helps reduce memory overhead and improves the overall system performance. It reduces the translation look-aside buffer (TLB) miss rate and improves memory access efficiency. -Telco workloads that involve large data sets or intensive memory operations, such as network packet processing, can benefit from huge page usage because it enhances memory performance and reduces memory-related bottlenecks. As a result, users see improved throughput and reduced latency. +Workloads that involve large data sets or intensive memory operations, such as network packet processing, can benefit from huge page usage because it enhances memory performance and reduces memory-related bottlenecks. As a result, users see improved throughput and reduced latency. All virtual machines created on Azure Operator Nexus can make use of either 2-MB or 1-GB huge pages, depending on the type of virtual machine. |
operator-nexus | Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/operator-nexus/overview.md | Here are important points about the architecture: Here are some key features of Azure Operator Nexus. -### CBL-Mariner +### Azure Linux -Azure Operator Nexus runs Microsoft's own Linux distribution called [CBL-Mariner](https://github.com/microsoft/CBL-Mariner) on the bare-metal hosts in the operator's facilities. The same Linux distribution supports Azure cloud infrastructure and edge services. It includes a small set of core packages by default. +Azure Operator Nexus runs Microsoft's own Linux distribution called [Azure Linux (formerly CBL-Mariner)](https://github.com/microsoft/azurelinux) on the bare-metal hosts in the operator's facilities. The same Linux distribution supports Azure cloud infrastructure and edge services. It includes a small set of core packages by default. -CBL-Mariner is a lightweight operating system. It consumes limited system resources and is engineered to be efficient. For example, it has a fast startup time with a small footprint and locked-down packages to reduce the threat landscape. +Azure Linux is a lightweight operating system. It consumes limited system resources and is engineered to be efficient. For example, it has a fast startup time with a small footprint and locked-down packages to reduce the threat landscape. When Microsoft identifies a security vulnerability, it makes the latest security patches and fixes available with the goal of fast turnaround time. Running the infrastructure on Linux aligns with NF needs, telecommunication industry trends, and relevant open-source communications. One important component of the service is the [cluster manager](./howto-cluster- Azure Operator Nexus includes [network fabric automation](./howto-configure-network-fabric-controller.md), which enables operators to build, operate, and manage carrier-grade network fabrics. -The reliable and distributed cloud services model supports the operators' telco network functions. Operators can interact with Azure Operator Nexus to provision the network fabric via zero-touch provisioning (ZTP). They can also perform complex network implementations via a workflow-driven API model. +The reliable and distributed cloud services model supports the operators' network functions. Operators can interact with Azure Operator Nexus to provision the network fabric via zero-touch provisioning (ZTP). They can also perform complex network implementations via a workflow-driven API model. ### Network packet broker |
operator-nexus | Reference Near Edge Compute | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/operator-nexus/reference-near-edge-compute.md | -In a near-edge environment (also known as an instance), the compute servers (also known as bare-metal machines) represent the physical machines on the rack. They run the CBL-Mariner operating system and provide support for running high-performance workloads. +In a near-edge environment (also known as an instance), the compute servers (also known as bare-metal machines) represent the physical machines on the rack. They run the Azure Linux operating system and provide support for running high-performance workloads. <!-- ## Available SKUs |
operator-nexus | Reference Nexus Kubernetes Cluster Supported Versions | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/operator-nexus/reference-nexus-kubernetes-cluster-supported-versions.md | Note the following important changes to make before you upgrade to any of the av | Kubernetes Version | Version Bundle | Components | OS components | Breaking Changes | Notes | |--|-|--|||--|-| 1.25.6 | 1 | Calico v3.24.0<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.5.1 | Azure Linux 2.0 | No breaking changes | | -| 1.25.6 | 2 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | | -| 1.25.6 | 3 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | | -| 1.25.6 | 4 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, cluster nodes are Azure Arc-enabled | -| 1.25.6 | 5 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.25.6 | 6 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.25.6 | 7 |Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | -| 1.25.11 | 1 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | | -| 1.25.11 | 2 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, cluster nodes are Azure Arc-enabled | -| 1.25.11 | 3 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.25.11 | 4 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.25.11 | 5 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | -| 1.26.3 | 1 | Calico v3.24.0<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.5.1 | Azure Linux 2.0 | No breaking changes | | -| 1.26.3 | 2 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | | -| 1.26.3 | 3 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | | -| 1.26.3 | 4 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, cluster nodes are Azure Arc-enabled | -| 1.26.3 | 5 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.26.3 | 6 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.26.3 | 7 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | -| 1.26.6 | 1 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | | -| 1.26.6 | 2 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, cluster nodes are Azure Arc-enabled | -| 1.26.6 | 3 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.26.6 | 4 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.26.6 | 5 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | -| 1.26.12 | 1 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted and cluster nodes are Azure Arc-enabled | -| 1.27.1 | 1 | Calico v3.24.0<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.5.1 | Azure Linux 2.0 | Cgroupv2 | Steps to disable cgroupv2 can be found [here](./howto-disable-cgroupsv2.md) | -| 1.27.1 | 2 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | Cgroupv2 | Steps to disable cgroupv2 can be found [here](./howto-disable-cgroupsv2.md) | -| 1.27.1 | 3 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | Cgroupv2 | Steps to disable cgroupv2 can be found [here](./howto-disable-cgroupsv2.md) | -| 1.27.1 | 4 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, cluster nodes are Azure Arc-enabled | -| 1.27.1 | 5 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.27.1 | 6 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.27.1 | 7 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | -| 1.27.3 | 1 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | Cgroupv2 | Steps to disable cgroupv2 can be found [here](./howto-disable-cgroupsv2.md) | -| 1.27.3 | 2 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, cluster nodes are Azure Arc-enabled | -| 1.27.3 | 3 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.27.3 | 4 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.27.3 | 5 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | -| 1.27.9 | 1 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted and cluster nodes are Azure Arc-enabled | -| 1.28.0 | 1 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | | -| 1.28.0 | 2 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, cluster nodes are Azure Arc-enabled | -| 1.28.0 | 3 | Calico v3.26.1<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.7.0-48<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.28.0 | 4 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | -| 1.28.0 | 5 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | | 1.28.9 | 1 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted and cluster nodes are Azure Arc-enabled |+| 1.28.0 | 5 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | +| 1.28.0 | 4 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | +| 1.27.9 | 1 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted and cluster nodes are Azure Arc-enabled | +| 1.27.3 | 5 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | +| 1.27.3 | 4 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | +| 1.26.12 | 1 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted and cluster nodes are Azure Arc-enabled | +| 1.26.6 | 5 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | +| 1.26.6 | 4 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | +| 1.25.11 | 5 | Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | +| 1.25.11 | 4 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | +| 1.25.6 | 7 |Calico v3.27.3<br>metrics-server v0.7.1<br>Multus v4.0.0<br>azure-arc-servers v1.1.0<br>CoreDNS v1.9.4<br>etcd v3.5.13<br>sriov-dp v3.11.0-68<br>Csi-nfs v4.7.0<br>csi-volume v0.1.0 | Azure Linux 2.0 | No breaking changes | Beginning with this version bundle, volume orchestration connectivity is TLS encrypted | +| 1.25.6 | 6 | Calico v3.27.2<br>metrics-server v0.6.3<br>Multus v3.8.0<br>azure-arc-servers v1.0.0<br>CoreDNS v1.9.3<br>etcd v3.5.6-5<br>sriov-dp v3.10.0-60<br>Csi-nfs v4.6.0 | Azure Linux 2.0 | No breaking changes | | ## Upgrading Kubernetes versions |
operator-nexus | Troubleshoot Hardware Validation Failure | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/operator-nexus/troubleshoot-hardware-validation-failure.md | -This article describes how to troubleshoot a failed server hardware validation. Hardware validation is run as part of cluster deploy action. +This article describes how to troubleshoot a failed server hardware validation. Hardware validation (HWV) is run as part of cluster deploy action and a bare metal replace action. HWV validates a bare metal machine (BMM) by executing test cases against the baseboard management controller (BMC). The Azure Operator Nexus platform is deployed on Dell servers. Dell servers use the integrated Dell remote access controller (iDRAC) which is the equivalent of a BMC. ## Prerequisites -- Gather the following information:- - Subscription ID - - Cluster name and resource group -- The user needs access to the Cluster's Log Analytics Workspace (LAW)+1. Collect the following information: + - Subscription ID + - Cluster name + - Resource group +2. Request access to the Cluster's Log Analytics Workspace (LAW). +3. Access to BMC webui and/or jumpbox that allows running of racadm utility. ## Locating hardware validation results 1. Navigate to cluster resource group in the subscription 2. Expand the cluster Log Analytics Workspace (LAW) resource for the cluster 3. Navigate to the Logs tab-4. Hardware validation results can be fetched with a query against the HWVal_CL table as per the following example +4. Hardware validation results can be fetched with a query against the `HWVal_CL` table as per the following example :::image type="content" source="media\hardware-validation-cluster-law.png" alt-text="Screenshot of cluster LAW custom table query." lightbox="media\hardware-validation-cluster-law.png"::: Expanding `result_detail` for a given category shows detailed results. ### System info category -* Memory/RAM related failure (memory_capacity_GB) - * Memory specs are defined in the SKU. - * Memory below threshold value indicates missing or failed DIMM(s). Failed DIMM(s) would also be reflected in the `health_info` category. +* Memory/RAM Related Failure (memory_capacity_GB) + * Memory specs are defined in the SKU. Memory below threshold value indicates missing or failed Dual In-Line Memory Module (DIMM). A failed DIMM would also be reflected in the `health_info` category. The following example shows a failed memory check. ```json { Expanding `result_detail` for a given category shows detailed results. } ``` + * To check memory information in BMC webui: ++ `BMC` -> `System` -> `Memory` ++ * To check memory information with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD hwinventory | grep SysMemTotalSize + ``` ++ * To troubleshoot a memory problem engage vendor. + * CPU Related Failure (cpu_sockets)- * CPU specs are defined in the SKU. - * Failed `cpu_sockets` check indicates a failed CPU or CPU count mismatch. + * CPU specs are defined in the SKU. Failed `cpu_sockets` check indicates a failed CPU or CPU count mismatch. The following example shows a failed CPU check. ```json { Expanding `result_detail` for a given category shows detailed results. } ``` + * To check CPU information in BMC webui: ++ `BMC` -> `System` -> `CPU` ++ * To check CPU information with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD hwinventory | grep PopulatedCPUSockets + ``` ++ * To troubleshoot a CPU problem engage vendor. + * Model Check Failure (Model)- * Failed `Model` check indicates that wrong server is racked in the slot or there's a cabling mismatch. + * Failed `Model` check indicates that wrong server is racked in the slot or there's a cabling mismatch. The following example shows a failed model check. ```json { Expanding `result_detail` for a given category shows detailed results. } ``` + * To check model information in BMC webui: ++ `BMC` -> `Dashboard` - Shows Model ++ * To check model information with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD getsysinfo | grep Model + ``` ++ * To troubleshoot this problem, ensure that server is racked in the correct location, cabled accordingly, and that the correct IP is assigned. ++* Serial Number Check Failure (Serial_Number) + * The server's serial number, also referred as the service tag, is defined in the cluster. Failed `Serial_Number` check indicates a mismatch between the serial number in the cluster and the actual serial number of the machine. The following example shows a failed serial number check. ++ ```json + { + "field_name": "Serial_Number", + "comparison_result": "Fail", + "expected": "1234567", + "fetched": "7654321" + } + ``` ++ * To check serial number information in BMC webui: ++ `BMC` -> `Dashboard` - Shows Service Tag ++ * To check serial number information with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD getsysinfo | grep "Service Tag" + ``` ++ * To troubleshoot this problem, ensure that server is racked in the correct location, cabled accordingly, and that the correct IP is assigned. ++* iDRAC License Check Failure + * All iDRACs require a perpetual/production iDRAC datacenter or enterprise license. Trial licenses are valid for only 30 days. A failed `iDRAC License Check` indicates that the required iDRAC license is missing. The following examples show a failed iDRAC license check for a trial license and missing license respectively. ++ ```json + { + "field_name": "iDRAC License Check", + "comparison_result": "Fail", + "expected": "idrac9 x5 datacenter license or idrac9 x5 enterprise license - perpetual or production", + "fetched": "iDRAC9 x5 Datacenter Trial License - Trial" + } + ``` ++ ```json + { + "field_name": "iDRAC License Check", + "comparison_result": "Fail", + "expected": "idrac9 x5 datacenter license or idrac9 x5 enterprise license - perpetual or production", + "fetched": "" + } + ``` ++ * To troubleshoot this problem engage vendor to obtain the correct license. Apply the license using the iDRAC webui in the following location: ++ `BMC` -> `Configuration` -> `Licenses` ++* Firmware Version Checks + * Firmware version checks were introduced in release 3.9. The following example shows the expected log for release versions before 3.9. ++ ```json + { + "system_info": { + "system_info_result": "Pass", + "result_log": [ + "Firmware validation not supported in release 3.8" + ] + }, + } + ``` ++ * Firmware versions are determined based on the `cluster version` value in the cluster object. The following example shows a failed check due to indeterminate cluster version. If this problem is encountered, verify the version in the cluster object. ++ ```json + { + "system_info": { + "system_info_result": "Fail", + "result_log": [ + "Unable to determine firmware release" + ] + }, + } + ``` + ### Drive info category * Disk Check Failure- * Drive specs are defined in the SKU - * Mismatched capacity values indicate incorrect drives or drives inserted in to incorrect slots. - * Missing capacity and type fetched values indicate drives that are failed, missing or inserted in to incorrect slots. + * Drive specs are defined in the SKU. Mismatched capacity values indicate incorrect drives or drives inserted in to incorrect slots. Missing capacity and type fetched values indicate drives that are failed, missing, or inserted in to incorrect slots. ```json { Expanding `result_detail` for a given category shows detailed results. } ``` + * To check disk information in BMC webui: ++ `BMC` -> `Storage` -> `Physical Disks` ++ * To check disk information with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD raid get pdisks -o -p State,Size + ``` ++ * To troubleshoot, ensure that disks are inserted in the correct slots. If the problem persists engage vendor. + ### Network info category -* NIC Check Failure - * Dell server NIC specs are defined in the SKU. - * Mismatched link status indicates loose or faulty cabling or crossed cables. - * Mismatched model indicates incorrect NIC card is inserted in to slot. - * Missing link/model fetched values indicate NICs that are failed, missing or inserted in to incorrect slots. +* Network Interface Cards (NIC) Check Failure + * Dell server NIC specs are defined in the SKU. A mismatched link status indicates loose or faulty cabling or crossed cables. A mismatched model indicates incorrect NIC card is inserted in to slot. Missing link/model fetched values indicate NICs that are failed, missing, or inserted in to incorrect slots. ```json { Expanding `result_detail` for a given category shows detailed results. } ``` + * To check NIC information in BMC webui: ++ `BMC` -> `System` -> `Network Devices` ++ * To check all NIC information with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD hwinventory NIC + ``` ++ * To check a specific NIC with racadm provide the Fully Qualified Device Descriptor (FQDD): ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD hwinventory NIC.Embedded.1-1-1 + ``` ++ * To troubleshoot, ensure that servers are cabled correctly and that ports are linked up. Bounce port on the fabric. Perform flea drain. If the problem persists engage vendor. + * NIC Check L2 Switch Information- * HW Validation reports L2 switch information for each of the server interfaces. - * The switch connection ID (switch interface MAC) and switch port connection ID (switch interface label) are informational. + * HWV reports L2 switch information for each of the server interfaces. The switch connection ID (switch interface MAC) and switch port connection ID (switch interface label) are informational. ```json { "field_name": "NIC.Slot.3-1-1_SwitchConnectionID",+ "comparison_result": "Info", "expected": "unknown",- "fetched": "c0:d6:82:23:0c:7d", - "comparison_result": "Info" + "fetched": "c0:d6:82:23:0c:7d" } ``` ```json { "field_name": "NIC.Slot.3-1-1_SwitchPortConnectionID",+ "comparison_result": "Info", "expected": "unknown",- "fetched": "Ethernet10/1", - "comparison_result": "Info" + "fetched": "Ethernet10/1" } ``` -* Release 3.6 introduced cable checks for bonded interfaces. - * Mismatched cabling is reported in the result_log. - * Cable check validates that that bonded NICs connect to switch ports with same Port ID. In the following example PCI 3/1 and 3/2 connect to "Ethernet1/1" and "Ethernet1/3" respectively on TOR, triggering a failure for HWV. +* Cabling Checks for Bonded Interfaces + * Mismatched cabling is reported in the result_log. Cable check validates that that bonded NICs connect to switch ports with same Port ID. In the following example Peripheral Component Interconnect (PCI) 3/1 and 3/2 connect to "Ethernet1/1" and "Ethernet1/3" respectively on TOR, triggering a failure for HWV. ```json { Expanding `result_detail` for a given category shows detailed results. } ], "result_log": [- "Cabling problem detected on PCI Slot 3" + "Cabling problem detected on PCI Slot 3 - server NIC.Slot.3-1-1 connected to switch Ethernet1/1 - server NIC.Slot.3-2-1 connected to switch Ethernet1/3" ] }, } ``` + * To fix the issue insert cables in to the correct interfaces. ++* iDRAC (BMC) MAC Address Check Failure + * The iDRAC MAC address is defined in the cluster for each BMM. A failed `iDRAC_MAC` check indicates a mismatch between the iDRAC/BMC MAC in the cluster and the actual MAC address retrieved from the machine. ++ ```json + { + "field_name": "iDRAC_MAC", + "comparison_result": "Fail", + "expected": "aa:bb:cc:dd:ee:ff", + "fetched": "aa:bb:cc:dd:ee:gg" + } + ``` ++ * To troubleshoot this problem, ensure that correct MAC address is defined in the cluster. If MAC is correct in the cluster object, attempt a flea drain. If problem persists ensure that server is racked in the correct location, cabled accordingly, and that the correct IP is assigned. ++* Preboot execution environment (PXE) MAC Address Check Failure + * The PXE MAC address is defined in the cluster for each BMM. A failed `PXE_MAC` check indicates a mismatch between the PXE MAC in the cluster and the actual MAC address retrieved from the machine. ++ ```json + { + "field_name": "NIC.Embedded.1-1_PXE_MAC", + "comparison_result": "Fail", + "expected": "aa:bb:cc:dd:ee:ff", + "fetched": "aa:bb:cc:dd:ee:gg" + } + ``` ++ * To troubleshoot this problem, ensure that correct MAC address is defined in the cluster. If MAC is correct in the cluster object, attempt a flea drain. If problem persists ensure that server is racked in the correct location, cabled accordingly, and that the correct IP is assigned. + ### Health info category * Health Check Sensor Failure- * Server health checks cover various hardware component sensors. - * A failed health sensor indicates a problem with the corresponding hardware component. - * The following examples indicate fan, drive and CPU failures respectively. + * Server health checks cover various hardware component sensors. A failed health sensor indicates a problem with the corresponding hardware component. The following examples indicate fan, drive, and CPU failures respectively. ```json { Expanding `result_detail` for a given category shows detailed results. } ``` -* Health Check Lifecycle Log (LC Log) Failures - * Dell server health checks fail for recent Critical LC Log Alarms. - * The hardware validation plugin logs the alarm ID, name, and timestamp. - * Recent LC Log critical alarms indicate need for further investigation. - * The following example shows a failure for a critical Backplane voltage alarm. + * To check health information in BMC webui: ++ `BMC` -> `Dashboard` - Shows Health Information ++ * To check health information with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD getsensorinfo + ``` ++ * To troubleshoot a server health failure engage vendor. ++* Health Check LifeCycle (LC) Log Failures + * Dell server health checks fail for recent Critical LC Log Alarms. The hardware validation plugin logs the alarm ID, name, and timestamp. Recent LC Log critical alarms indicate need for further investigation. The following example shows a failure for a critical backplane voltage alarm. ++ ```json + { + "field_name": "LCLog_Critical_Alarms", + "comparison_result": "Fail", + "expected": "No Critical Errors", + "fetched": "53539 2023-07-22T23:44:06-05:00 The system board BP1 PG voltage is outside of range." + } + ``` ++ * Virtual disk errors typically indicate a RAID cleanup false positive condition and are logged due to the timing of raid cleanup and system power off pre HWV. The following example shows an LC log critical error on virtual disk 238. If multiple errors are encountered blocking deployment, delete cluster, wait two hours, then reattempt cluster deployment. If the failures aren't deployment blocking, wait two hours then run BMM replace. ```json { "field_name": "LCLog_Critical_Alarms",+ "comparison_result": "Fail", "expected": "No Critical Errors",- "fetched": "53539 2023-07-22T23:44:06-05:00 The system board BP1 PG voltage is outside of range.", - "comparison_result": "Fail" + "fetched": "104473 2024-07-26T16:05:19-05:00 Virtual Disk 238 on RAID Controller in SL 3 has failed." } ``` + * To check LC logs in BMC webui: ++ `BMC` -> `Maintenance` -> `Lifecycle Log` ++ * To check LC log critical alarms with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD lclog view -s critical + ``` ++ * If `Backplane Comm` critical errors are logged, perform flea drain. Engage vendor to troubleshoot any other LC log critical failures. + * Health Check Server Power Action Failures- * Dell server health check fail for failed server power-up or failed iDRAC reset. - * A failed server control action indicates an underlying hardware issue. - * The following example shows failed power on attempt. + * Dell server health checks fail for failed server power-up or failed iDRAC reset. A failed server control action indicates an underlying hardware issue. The following example shows failed power on attempt. ```json { "field_name": "Server Control Actions",+ "comparison_result": "Fail", "expected": "Success",- "fetched": "Failed", - "comparison_result": "Fail" + "fetched": "Failed" } ``` Expanding `result_detail` for a given category shows detailed results. ] ``` + * To power server on in BMC webui: ++ `BMC` -> `Dashboard` -> `Power On System` ++ * To power server on with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD serveraction powerup + ``` ++ * To troubleshoot server power-on failure attempt a flea drain. If problem persists engage vendor. + * Health Check Power Supply Failure and Redundancy Considerations- * Dell server health checks warn when one power supply is missing or failed. - * Power supply "field_name" might be displayed as 0/PS0/Power Supply 0 and 1/PS1/Power Supply 1 for the first and second power supplies respectively. - * A failure of one power supply doesn't trigger an HW validation device failure. + * Dell server health checks warn when one power supply is missing or failed. Power supply "field_name" might be displayed as 0/PS0/Power Supply 0 and 1/PS1/Power Supply 1 for the first and second power supplies respectively. A failure of one power supply doesn't trigger an HWV device failure. ```json { "field_name": "Power Supply 1",+ "comparison_result": "Warning", "expected": "Enabled-OK",- "fetched": "UnavailableOffline-Critical", - "comparison_result": "Warning" + "fetched": "UnavailableOffline-Critical" } ``` ```json { "field_name": "System Board PS Redundancy",+ "comparison_result": "Warning", "expected": "Enabled-OK",- "fetched": "Enabled-Critical", - "comparison_result": "Warning" + "fetched": "Enabled-Critical" } ``` + * To check power supplies in BMC webui: ++ `BMC` -> `System` -> `Power` ++ * To check power supplies with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD getsensorinfo | grep PS + ``` ++ * Reseating the power supply might fix the problem. If alarms persist engage vendor. + ### Boot info category -* Boot Device Check Considerations +* Boot Device Name Check Considerations * The `boot_device_name` check is currently informational. * Mismatched boot device name shouldn't trigger a device failure. ```json {+ "field_name": "boot_device_name", "comparison_result": "Info", "expected": "NIC.PxeDevice.1-1",- "fetched": "NIC.PxeDevice.1-1", - "field_name": "boot_device_name" + "fetched": "NIC.PxeDevice.1-1" } ``` Expanding `result_detail` for a given category shows detailed results. ```json { "field_name": "pxe_device_1_name",+ "comparison_result": "Fail", "expected": "NIC.Embedded.1-1-1",- "fetched": "NIC.Embedded.1-2-1", - "comparison_result": "Fail" + "fetched": "NIC.Embedded.1-2-1" } ``` ```json { "field_name": "pxe_device_1_state",+ "comparison_result": "Fail", "expected": "Enabled",- "fetched": "Disabled", - "comparison_result": "Fail" + "fetched": "Disabled" + } + ``` ++ * To update the PXE device state and name in BMC webui, set the value then select `Apply` followed by `Apply And Reboot`: ++ `BMC` -> `Configuration` -> `BIOS Settings` -> `Network Settings` -> `PXE Device1` -> `Enabled` + `BMC` -> `Configuration` -> `BIOS Settings` -> `Network Settings` -> `PXE Device1 Settings` -> `Interface` -> `Embedded NIC 1 Port 1 Partition 1` + + * To update the PXE device state and name with racadm run the following commands: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD set bios.NetworkSettings.PxeDev1EnDis Enabled + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD set bios.PxeDev1Settings.PxeDev1Interface NIC.Embedded.1-1-1 + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD jobqueue create BIOS.Setup.1-1 + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD serveraction powercycle + ``` ++### Device login check ++* Device Login Check Considerations + * The `device_login` check fails if the iDRAC isn't accessible or if the hardware validation plugin isn't able to sign-in. ++ ```json + { + "device_login": "Fail" } ``` + * To set password in BMC webui: ++ `BMC` -> `iDRAC Settings` -> `Users` -> `Local Users` -> `Edit` ++ * To set password with racadm: ++ ```bash + racadm -r $BMC_IP -u $BMC_USER -p $CURRENT_PASSWORD set iDRAC.Users.2.Password $BMC_PWD + ``` ++ * To troubleshoot, ping the iDRAC from a jumpbox with access to the BMC network. If iDRAC pings check that passwords match. ++### Special considerations ++* Servers Failing Multiple Health and Network Checks + * Raid deletion is performed during cluster deploy and cluster delete actions for all releases inclusive of 3.12. + * If we observe servers getting powered off during hardware validation with multiple failed health and network checks, we need to reattempt cluster deployment. + * If issues persist, raid deletion needs to be performed manually on `control` nodes in the cluster. ++ * To clear raid in BMC webui: ++ `BMC` -> `Storage` -> `Virtual Disks` -> `Action` -> `Delete` -> `Apply Now` ++ * To clear raid with racadm: ++ ```bash + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD raid deletevd:Disk.Virtual.239:RAID.SL.3-1 + racadm --nocertwarn -r $IP -u $BMC_USR -p $BMC_PWD jobqueue create RAID.SL.3-1 --realtime + ``` + ## Adding servers back into the Cluster after a repair After Hardware is fixed, run BMM Replace following instructions from the following page [BMM actions](howto-baremetal-functions.md). |
payment-hsm | Certification Compliance | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/payment-hsm/certification-compliance.md | -Azure maintains the largest compliance portfolio in the industry. For details, see [Microsoft Azure Compliance Offerings](https://azure.microsoft.com/resources/microsoft-azure-compliance-offerings/). Each offering description provides an up to-date-scope statement and links to useful downloadable resources. +Azure maintains the largest compliance portfolio in the industry. For details, see [Microsoft Azure Compliance Offerings](/compliance/regulatory/offering-home). Each offering description provides an up to-date-scope statement and links to useful downloadable resources. Azure payment HSM meets following compliance standards: |
postgresql | Concepts Extensions | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/concepts-extensions.md | |
postgresql | Concepts Logging | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/concepts-logging.md | description: Describes logging configuration, storage and analysis in Azure Data Last updated 7/11/2024-+ |
postgresql | Concepts Maintenance | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/concepts-maintenance.md | |
postgresql | Concepts Major Version Upgrade | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/concepts-major-version-upgrade.md | description: Learn how to use Azure Database for PostgreSQL - Flexible Server to Last updated 7/15/2024-+ |
postgresql | Concepts Monitoring | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/concepts-monitoring.md | |
postgresql | Concepts Pgbouncer | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/concepts-pgbouncer.md | description: This article provides an overview of the built-in PgBouncer feature Last updated 06/27/2024-+ |
postgresql | Concepts Query Performance Insight | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/concepts-query-performance-insight.md | |
postgresql | Concepts Query Store | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/concepts-query-store.md | |
postgresql | Concepts Scaling Resources | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/concepts-scaling-resources.md | description: This article describes the resource scaling in Azure Database for P Last updated 07/23/2024-+ |
postgresql | Concepts Supported Versions | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/concepts-supported-versions.md | |
postgresql | Create Automation Tasks | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/create-automation-tasks.md | |
postgresql | How To Alert On Metrics | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/how-to-alert-on-metrics.md | |
postgresql | How To Configure And Access Logs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/how-to-configure-and-access-logs.md | |
postgresql | How To Configure Server Parameters Using Cli | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/how-to-configure-server-parameters-using-cli.md | |
postgresql | How To Configure Server Parameters Using Portal | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/how-to-configure-server-parameters-using-portal.md | |
postgresql | How To Cost Optimization | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/how-to-cost-optimization.md | |
postgresql | How To Perform Major Version Upgrade Cli | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/how-to-perform-major-version-upgrade-cli.md | |
postgresql | How To Server Logs Cli | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/how-to-server-logs-cli.md | |
postgresql | How To Server Logs Portal | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/how-to-server-logs-portal.md | |
postgresql | How To Stop Start Server Portal | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/how-to-stop-start-server-portal.md | |
postgresql | Overview Postgres Choose Server Options | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/overview-postgres-choose-server-options.md | |
postgresql | Release Notes | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/postgresql/flexible-server/release-notes.md | Title: Release notes for Azure DB for PostgreSQL - Flexible Server description: Release notes for Azure DB for PostgreSQL - Flexible Server, including feature additions, engine versions support, extensions, and other announcements. -+ Previously updated : 7/12/2024 Last updated : 8/5/2024 #customer intent: As a reader, I want the title and description to meet the required length and include the relevant information about the release notes for Azure DB for PostgreSQL - Flexible Server. Last updated 7/12/2024 This page provides latest news and updates regarding feature additions, engine versions support, extensions, and any other announcements relevant to Azure Database for PostgreSQL flexible server. +## Release: Aug 2024 +* General availability of [Database Size Metrics](./concepts-monitoring.md) for Azure Database for PostgreSQL flexible server. + ## Release: July 2024 * General availability of [Major Version Upgrade Support for PostgreSQL 16](concepts-major-version-upgrade.md) for Azure Database for PostgreSQL flexible server. * General availability of [Pgvector 0.7.0](concepts-extensions.md) extension. |
private-link | Private Endpoint Dns | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/private-link/private-endpoint-dns.md | For Azure services, use the recommended zone names as described in the following >| Azure SQL Managed Instance (Microsoft.Sql/managedInstances) | managedInstance | privatelink.{dnsPrefix}.database.usgovcloudapi.net | {instanceName}.{dnsPrefix}.database.usgovcloudapi.net | >| Azure Cosmos DB (Microsoft.DocumentDB/databaseAccounts) | Sql | privatelink.documents.azure.us | documents.azure.us | >| Azure Cosmos DB (Microsoft.DocumentDB/databaseAccounts) | MongoDB | privatelink.mongo.cosmos.azure.us | mongo.cosmos.azure.us |+>| Azure Cosmos DB (Microsoft.DocumentDB/databaseAccounts) | Cassandra | privatelink.cassandra.cosmos.azure.us | cassandra.cosmos.azure.us | +>| Azure Cosmos DB (Microsoft.DocumentDB/databaseAccounts) | Gremlin | privatelink.gremlin.cosmos.azure.us | gremlin.cosmos.azure.us | +>| Azure Cosmos DB (Microsoft.DocumentDB/databaseAccounts) | Table | privatelink.table.cosmos.azure.us | table.cosmos.azure.us | >| Azure Database for PostgreSQL - Single server (Microsoft.DBforPostgreSQL/servers) | postgresqlServer | privatelink.postgres.database.usgovcloudapi.net | postgres.database.usgovcloudapi.net | >| Azure Database for PostgreSQL - Flexible server (Microsoft.DBforPostgreSQL/flexibleServers) | postgresqlServer | privatelink.postgres.database.usgovcloudapi.net | postgres.database.usgovcloudapi.net | >| Azure Database for MySQL - Single Server (Microsoft.DBforMySQL/servers) | mysqlServer | privatelink.mysql.database.usgovcloudapi.net | mysql.database.usgovcloudapi.net | |
sentinel | Cef Name Mapping | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/sentinel/cef-name-mapping.md | - Title: Common Event Format (CEF) key and CommonSecurityLog field mapping -description: This article maps CEF keys to the corresponding field names in the CommonSecurityLog in Microsoft Sentinel. --- Previously updated : 11/09/2021---# CEF and CommonSecurityLog field mapping --The following tables map Common Event Format (CEF) field names to the names they use in Microsoft Sentinel's CommonSecurityLog, and may be helpful when you are working with a CEF data source in Microsoft Sentinel. --For more information, see [Connect your external solution using Common Event Format](connect-common-event-format.md). --> [!IMPORTANT] -> -> On **February 28th 2023**, we introduced changes to the CommonSecurityLog table schema. Following this change, you might need to review and update custom queries. For more details, see the [recommended actions section](https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/upcoming-changes-to-the-commonsecuritylog-table/ba-p/3643232) in this blog post. Out-of-the-box content (detections, hunting queries, workbooks, parsers, etc.) has been updated by Microsoft Sentinel. --> [!NOTE] -> A Microsoft Sentinel workspace is required in order to [ingest CEF data](connect-common-event-format.md#prerequisites) into Log Analytics. -> --## A - C --|CEF key name |CommonSecurityLog field name |Description | -|||| -| act | <a name="deviceaction"></a> DeviceAction | The action mentioned in the event. | -| app | ApplicationProtocol | The protocol used in the application, such as HTTP, HTTPS, SSHv2, Telnet, POP, IMPA, IMAPS, and so on. | -| cat | DeviceEventCategory | Represents the category assigned by the originating device. Devices often use their own categorization schema to classify event. For example: `/Monitor/Disk/Read`. | -| cnt | EventCount | A count associated with the event, showing how many times the same event was observed. | ---## D --|CEF key name |CommonSecurityLog name |Description | -|||| -|Device Vendor | DeviceVendor | String that, together with device product and version definitions, uniquely identifies the type of sending device. | -|Device Product | DeviceProduct | String that, together with device vendor and version definitions, uniquely identifies the type of sending device. | -|Device Version | DeviceVersion | String that, together with device product and vendor definitions, uniquely identifies the type of sending device. | -| destinationDnsDomain | DestinationDnsDomain | The DNS part of the fully qualified domain name (FQDN). | -| destinationServiceName | DestinationServiceName | The service that is targeted by the event. For example, `sshd`.| -| destinationTranslatedAddress | DestinationTranslatedAddress | Identifies the translated destination referred to by the event in an IP network, as an IPv4 IP address. | -| destinationTranslatedPort | DestinationTranslatedPort | Port, after translation, such as a firewall. <br>Valid port numbers: `0` - `65535` | -| deviceDirection | <a name="communicationdirection"></a> CommunicationDirection | Any information about the direction the observed communication has taken. Valid values: <br>- `0` = Inbound <br>- `1` = Outbound | -| deviceDnsDomain | DeviceDnsDomain | The DNS domain part of the full qualified domain name (FQDN) | -|DeviceEventClassID | DeviceEventClassID | String or integer that serves as a unique identifier per event type. | -| deviceExternalId | deviceExternalId | A name that uniquely identifies the device generating the event. | -| deviceFacility | DeviceFacility | The facility generating the event.| -| deviceInboundInterface | DeviceInboundInterface |The interface on which the packet or data entered the device. | -| deviceNtDomain | DeviceNtDomain | The Windows domain of the device address | -| deviceOutboundInterface | DeviceOutboundInterface |Interface on which the packet or data left the device. | -| devicePayloadId |DevicePayloadId |Unique identifier for the payload associated with the event. | -| deviceProcessName | ProcessName | Process name associated with the event. <br><br>For example, in UNIX, the process generating the syslog entry. | -| deviceTranslatedAddress | DeviceTranslatedAddress | Identifies the translated device address that the event refers to, in an IP network. <br><br>The format is an Ipv4 address. | -| dhost |DestinationHostName | The destination that the event refers to in an IP network. <br>The format should be an FQDN associated with the destination node, when a node is available. For example, `host.domain.com` or `host`. | -| dmac | DestinationMacAddress | The destination MAC address (FQDN) | -| dntdom | DestinationNTDomain | The Windows domain name of the destination address.| -| dpid | DestinationProcessId |The ID of the destination process associated with the event.| -| dpriv | DestinationUserPrivileges | Defines the destination use's privileges. <br>Valid values: `Admninistrator`, `User`, `Guest` | -| dproc | DestinationProcessName | The name of the eventΓÇÖs destination process, such as `telnetd` or `sshd.` | -| dpt | DestinationPort | Destination port. <br>Valid values: `*0` - `65535` | -| dst | DestinationIP | The destination IpV4 address that the event refers to in an IP network. | -| dtz | DeviceTimeZone | Timezone of the device generating the event | -| duid |DestinationUserId | Identifies the destination user by ID. | -| duser | DestinationUserName |Identifies the destination user by name.| -| dvc | DeviceAddress | The IPv4 address of the device generating the event. | -| dvchost | DeviceName | The FQDN associated with the device node, when a node is available. For example, `host.domain.com` or `host`.| -| dvcmac | DeviceMacAddress | The MAC address of the device generating the event. | -| dvcpid | Process ID | Defines the ID of the process on the device generating the event. | --## E - I --|CEF key name |CommonSecurityLog name |Description | -|||| -|externalId | ExternalID | An ID used by the originating device. Typically, these values have increasing values that are each associated with an event. | -|fileCreateTime | FileCreateTime | Time when the file was created. | -|fileHash | FileHash | Hash of a file. | -|fileId | FileID |An ID associated with a file, such as the inode. | -| fileModificationTime | FileModificationTime |Time when the file was last modified. | -| filePath | FilePath | Full path to the file, including the filename. For example: `C:\ProgramFiles\WindowsNT\Accessories\wordpad.exe` or `/usr/bin/zip`.| -| filePermission |FilePermission |The file's permissions. | -| fileType | FileType | File type, such as pipe, socket, and so on.| -|fname | FileName| The file's name, without the path. | -| fsize | FileSize | The size of the file. | -|Host | Computer | Host, from Syslog | -|in | ReceivedBytes |Number of bytes transferred inbound. | ---## M - P --|CEF key name |CommonSecurityLog name |Description | -|||| -|msg | Message | A message that gives more details about the event. | -|Name | Activity | A string that represents a human-readable and understandable description of the event. | -|oldFileCreateTime | OldFileCreateTime | Time when the old file was created. | -|oldFileHash | OldFileHash | Hash of the old file. | -|oldFileId | OldFileId | And ID associated with the old file, such as the inode. | -| oldFileModificationTime | OldFileModificationTime |Time when the old file was last modified. | -| oldFileName | OldFileName |Name of the old file. | -| oldFilePath | OldFilePath | Full path to the old file, including the filename. <br>For example, `C:\ProgramFiles\WindowsNT\Accessories\wordpad.exe` or `/usr/bin/zip`.| -| oldFilePermission | OldFilePermission |Permissions of the old file. | -|oldFileSize | OldFileSize | Size of the old file.| -| oldFileType | OldFileType | File type of the old file, such as a pipe, socket, and so on.| -| out | SentBytes | Number of bytes transferred outbound. | -| outcome | EventOutcome | Outcome of the event, such as `success` or `failure`.| -|proto | Protocol | Transport protocol that identifies the Layer-4 protocol used. <br><br>Possible values include protocol names, such as `TCP` or `UDP`. | ---## R - T --|CEF key name |CommonSecurityLog name |Description | -|||| -| reason | Reason | The reason an audit event was generated. For example `badd password` or `unknown user`. This could also be an error or return code. For example: `0x1234`. | -|Request | RequestURL | The URL accessed for an HTTP request, including the protocol. For example, `http://www/secure.com` | -|requestClientApplication | RequestClientApplication | The user agent associated with the request. | -| requestContext | RequestContext | Describes the content from which the request originated, such as the HTTP Referrer. | -| requestCookies | RequestCookies |Cookies associated with the request. | -| requestMethod | RequestMethod | The method used to access a URL. <br><br>Valid values include methods such as `POST`, `GET`, and so on. | -| rt | ReceiptTime | The time at which the event related to the activity was received. | -|Severity | <a name="logseverity"></a> LogSeverity | A string or integer that describes the importance of the event.<br><br> Valid string values: `Unknown` , `Low`, `Medium`, `High`, `Very-High` <br><br>Valid integer values are:<br> - `0`-`3` = Low <br>- `4`-`6` = Medium<br>- `7`-`8` = High<br>- `9`-`10` = Very-High | -| shost | SourceHostName |Identifies the source that event refers to in an IP network. Format should be a fully qualified domain name (DQDN) associated with the source node, when a node is available. For example, `host` or `host.domain.com`. | -| smac | SourceMacAddress | Source MAC address. | -| sntdom | SourceNTDomain | The Windows domain name for the source address. | -| sourceDnsDomain | SourceDnsDomain | The DNS domain part of the complete FQDN. | -| sourceServiceName | SourceServiceName | The service responsible for generating the event. | -| sourceTranslatedAddress | SourceTranslatedAddress | Identifies the translated source that the event refers to in an IP network. | -| sourceTranslatedPort | SourceTranslatedPort | Source port after translation, such as a firewall. <br>Valid port numbers are `0` - `65535`. | -| spid | SourceProcessId | The ID of the source process associated with the event.| -| spriv | SourceUserPrivileges | The source user's privileges. <br><br>Valid values include: `Administrator`, `User`, `Guest` | -| sproc | SourceProcessName | The name of the event's source process.| -| spt | SourcePort | The source port number. <br>Valid port numbers are `0` - `65535`. | -| src | SourceIP |The source that an event refers to in an IP network, as an IPv4 address. | -| suid | SourceUserID | Identifies the source user by ID. | -| suser | SourceUserName | Identifies the source user by name. | -| type | EventType | Event type. Value values include: <br>- `0`: base event <br>- `1`: aggregated <br>- `2`: correlation event <br>- `3`: action event <br><br>**Note**: This event can be omitted for base events. | ---## Custom fields --The following tables map the names of CEF keys and CommonSecurityLog fields that are available for customers to use for data that does not apply to any of the built-in fields. --### Custom IPv6 address fields --The following table maps CEF key and CommonSecurityLog names for the *IPv6* address fields available for custom data. --|CEF key name |CommonSecurityLog name | -||| -| c6a1 | DeviceCustomIPv6Address1 | -| c6a1Label | DeviceCustomIPv6Address1Label | -| c6a2 | DeviceCustomIPv6Address2 | -| c6a2Label | DeviceCustomIPv6Address2Label | -| c6a3 | DeviceCustomIPv6Address3 | -| c6a3Label | DeviceCustomIPv6Address3Label | -| c6a4 | DeviceCustomIPv6Address4 | -| c6a4Label | DeviceCustomIPv6Address4Label | -| cfp1 | DeviceCustomFloatingPoint1 | -| cfp1Label | deviceCustomFloatingPoint1Label | -| cfp2 | DeviceCustomFloatingPoint2 | -| cfp2Label | deviceCustomFloatingPoint2Label | -| cfp3 | DeviceCustomFloatingPoint3 | -| cfp3Label | deviceCustomFloatingPoint3Label | -| cfp4 | DeviceCustomFloatingPoint4 | -| cfp4Label | deviceCustomFloatingPoint4Label | ---### Custom number fields --The following table maps CEF key and CommonSecurityLog names for the *number* fields available for custom data. --|CEF key name |CommonSecurityLog name | -||| -| cn1 | DeviceCustomNumber1 | -| cn1Label | DeviceCustomNumber1Label | -| cn2 | DeviceCustomNumber2 | -| cn2Label | DeviceCustomNumber2Label | -| cn3 | DeviceCustomNumber3 | -| cn3Label | DeviceCustomNumber3Label | ---### Custom string fields --The following table maps CEF key and CommonSecurityLog names for the *string* fields available for custom data. --|CEF key name |CommonSecurityLog name | -||| -| cs1 | DeviceCustomString1 <sup>[1](#use-sparingly)</sup> | -| cs1Label | DeviceCustomString1Label <sup>[1](#use-sparingly)</sup> | -| cs2 | DeviceCustomString2 <sup>[1](#use-sparingly)</sup> | -| cs2Label | DeviceCustomString2Label <sup>[1](#use-sparingly)</sup> | -| cs3 | DeviceCustomString3 <sup>[1](#use-sparingly)</sup> | -| cs3Label | DeviceCustomString3Label <sup>[1](#use-sparingly)</sup> | -| cs4 | DeviceCustomString4 <sup>[1](#use-sparingly)</sup> | -| cs4Label | DeviceCustomString4Label <sup>[1](#use-sparingly)</sup> | -| cs5 | DeviceCustomString5 <sup>[1](#use-sparingly)</sup> | -| cs5Label | DeviceCustomString5Label <sup>[1](#use-sparingly)</sup> | -| cs6 | DeviceCustomString6 <sup>[1](#use-sparingly)</sup> | -| cs6Label | DeviceCustomString6Label <sup>[1](#use-sparingly)</sup> | -| flexString1 | FlexString1 | -| flexString1Label | FlexString1Label | -| flexString2 | FlexString2 | -| flexString2Label | FlexString2Label | ---> [!TIP] -> <a name="use-sparingly"></a><sup>1</sup> We recommend that you use the **DeviceCustomString** fields sparingly and use more specific, built-in fields when possible. -> --### Custom timestamp fields --The following table maps CEF key and CommonSecurityLog names for the *timestamp* fields available for custom data. --|CEF key name |CommonSecurityLog name | -||| -| deviceCustomDate1 | DeviceCustomDate1 | -| deviceCustomDate1Label | DeviceCustomDate1Label | -| deviceCustomDate2 | DeviceCustomDate2 | -| deviceCustomDate2Label | DeviceCustomDate2Label | -| flexDate1 | FlexDate1 | -| flexDate1Label | FlexDate1Label | ---### Custom integer data fields --The following table maps CEF key and CommonSecurityLog names for the *integer* fields available for custom data. --|CEF key name |CommonSecurityLog name | -||| -| flexNumber1 | FlexNumber1 | -| flexNumber1Label | FlexNumber1Label | -| flexNumber2 | FlexNumber2 | -| flexNumber2Label | FlexNumber2Label | ---## Enrichment fields --The following **CommonSecurityLog** fields are added by Microsoft Sentinel to enrich the original events received from the source devices, and don't have mappings in CEF keys: --### Threat intelligence fields --|CommonSecurityLog field name |Description | -||| -| **IndicatorThreatType** | The [MaliciousIP](#MaliciousIP) threat type, according to the threat intelligence feed. | -| <a name="MaliciousIP"></a>**MaliciousIP** | Lists any IP addresses in the message that correlates with the current threat intelligence feed. | -| **MaliciousIPCountry** | The [MaliciousIP](#MaliciousIP) country/region, according to the geographic information at the time of the record ingestion. | -| **MaliciousIPLatitude** | The [MaliciousIP](#MaliciousIP) longitude, according to the geographic information at the time of the record ingestion. | -| **MaliciousIPLongitude** | The [MaliciousIP](#MaliciousIP) longitude, according to the geographic information at the time of the record ingestion. | -| **ReportReferenceLink** | Link to the threat intelligence report. | -| **ThreatConfidence** | The [MaliciousIP](#MaliciousIP) threat confidence, according to the threat intelligence feed. | -| **ThreatDescription** | The [MaliciousIP](#MaliciousIP) threat description, according to the threat intelligence feed. | -| **ThreatSeverity** | The threat severity for the [MaliciousIP](#MaliciousIP), according to the threat intelligence feed at the time of the record ingestion. | ---### Additional enrichment fields --|CommonSecurityLog field name |Description | -||| -|**OriginalLogSeverity** | Always empty, supported for integration with CiscoASA. <br>For details about log severity values, see the [LogSeverity](#logseverity) field. | -|**RemoteIP** | The remote IP address. <br>This value is based on [CommunicationDirection](#communicationdirection) field, if possible. | -|**RemotePort** | The remote port. <br>This value is based on [CommunicationDirection](#communicationdirection) field, if possible. | -|**SimplifiedDeviceAction** | Simplifies the [DeviceAction](#deviceaction) value to a static set of values, while keeping the original value in the [DeviceAction](#deviceaction) field. <br>For example: `Denied` > `Deny`. | -|**SourceSystem** | Always defined as **OpsManager**. | ---## Next steps --For more information, see [Connect your external solution using Common Event Format](connect-common-event-format.md). |
sentinel | Monitor Automation Health | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/sentinel/monitor-automation-health.md | For the **Automation rule run** status, you may see the following statuses: - **Success**: rule executed successfully, triggering all actions. - **Partial success**: rule executed and triggered at least one action, but some actions failed.-- *Failure*: automation rule did not run any action due to one of the following reasons:+- **Failure**: automation rule did not run any action due to one of the following reasons: - Conditions evaluation failed. - Conditions met, but the first action failed. For the **Playbook was triggered** status, you may see the following statuses: | Error description | Suggested actions | | | -- | | **Could not add task: *\<TaskName>*.**<br>Incident/alert was not found. | Make sure the incident/alert exists and try again. |+| **Could not add task: *\<TaskName>*.**<br>Incident already contains the maximum allowed number of tasks. | If this task is required, see if there are any tasks that can be removed or consolidated, then try again. | | **Could not modify property: *\<PropertyName>*.**<br>Incident/alert was not found. | Make sure the incident/alert exists and try again. | | **Could not modify property: *\<PropertyName>*.**<br>Too many requests, exceeding throttling limits. | | | **Could not trigger playbook: *\<PlaybookName>*.**<br>Incident/alert was not found. | If the error occurred when trying to trigger a playbook on demand, make sure the incident/alert exists and try again. | |
sentinel | Collect Sap Hana Audit Logs | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/sentinel/sap/collect-sap-hana-audit-logs.md | This article explains how to collect audit logs from your SAP HANA database. > [!IMPORTANT] > Microsoft Sentinel SAP HANA support is currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability. - ## Prerequisites SAP HANA logs are sent over Syslog. Make sure that your AMA agent or your Log Analytics agent (legacy) is configured to collect Syslog files. For more information, see: For more information, see [Ingest syslog and CEF messages to Microsoft Sentinel with the Azure Monitor Agent](../connect-cef-syslog-ama.md). - ## Collect SAP HANA audit logs 1. Make sure that the SAP HANA audit log trail is configured to use Syslog, as described in *SAP Note 0002624117*, which is accessible from the [SAP Launchpad support site](https://launchpad.support.sap.com/#/notes/0002624117). For more information, see: - [SAP HANA Audit Trail - Best Practice](https://help.sap.com/docs/SAP_HANA_PLATFORM/b3ee5778bc2e4a089d3299b82ec762a7/35eb4e567d53456088755b8131b7ed1d.html?version=2.0.03) - [Recommendations for Auditing](https://help.sap.com/viewer/742945a940f240f4a2a0e39f93d3e2d4/2.0.05/en-US/5c34ecd355e44aa9af3b3e6de4bbf5c1.html)+ - [SAP HANA Security Guide for SAP HANA Platform](https://help.sap.com/docs/SAP_HANA_PLATFORM/b3ee5778bc2e4a089d3299b82ec762a7/4f7cde1125084ea3b8206038530e96ce.html) -1. Check your operating system Syslog files for any relevant HANA database events. +2. Check your operating system Syslog files for any relevant HANA database events. -1. Sign into your HANA database operating system as a user with sudo privileges. +3. Sign into your HANA database operating system as a user with sudo privileges. -1. Install an agent on your machine and confirm that your machine is connected. For more information, see: +4. Install an agent on your machine and confirm that your machine is connected. For more information, see: - [Azure Monitor Agent](/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal) - [Log Analytics Agent](../../azure-monitor/agents/agent-linux.md) (legacy) -1. Configure your agent to collect Syslog data. For more information, see: +5. Configure your agent to collect Syslog data. For more information, see: - [Azure Monitor Agent](/azure/azure-monitor/agents/data-collection-syslog) - [Log Analytics Agent](/azure/azure-monitor/agents/data-sources-syslog) (legacy) > [!TIP] > Because the facilities where HANA database events are saved can change between different distributions, we recommend that you add all facilities. Check them against your Syslog logs, and then remove any that aren't relevant.- > ## Verify your configuration -In Microsoft Sentinel, check to confirm that HANA database events are now shown in the ingested logs. For example, run the following query: +Use the following steps in both Microsoft Sentinel and your SAP HANA database to verify that your system is configured as expected. ++### Microsoft Sentinel +In Microsoft Sentinel's **Logs** page, check to confirm that HANA database events are now shown in the ingested logs. For example, run the following query: ```Kusto //generated function structure for custom log Syslog TimeGenerated = column_ifexists('TimeGenerated', '1000-01-01T00:00:00Z') T_Syslog | union isfuzzy= true (D_Syslog | where TimeGenerated != '1000-01-01T00:00:00Z') ``` +### SAP HANA ++In your SAP HANA database, check your configured audit policies. For more information on the required SQL statements, see [SAP Note 3016478](https://me.sap.com/notes/3016478/E). -## Add analytics rules for SAP HANA +## Add analytics rules for SAP HANA in Microsoft Sentinel Use the following built-in analytics rules to have Microsoft Sentinel start triggering alerts on related SAP HANA activity: For more information, see [Microsoft Sentinel solution for SAP® applications: s ## Related content +Learn more about the Microsoft Sentinel Solution for SAP BTP: ++- [Deploy Microsoft Sentinel solution for SAP® applications](deploy-sap-btp-solution.md) +- [Microsoft Sentinel Solution for SAP BTP: security content reference](sap-btp-security-content.md) + Learn more about the Microsoft Sentinel solution for SAP® applications: - [Deploy Microsoft Sentinel solution for SAP® applications](deployment-overview.md) Learn more about the Microsoft Sentinel solution for SAP® applications: Troubleshooting: - [Troubleshoot your Microsoft Sentinel solution for SAP® applications deployment](sap-deploy-troubleshoot.md)+- [HANA audit log is not generated in SYSLOG | SAP note](https://me.sap.com/notes/3305033/E) +- [How to Redirect syslog Auditing for HANA to an alternate location | SAP note](https://me.sap.com/notes/2386609) Reference files: Reference files: - [Systemconfig.ini file reference](reference-systemconfig.md) For more information, see [Microsoft Sentinel solutions](../sentinel-solutions.md).- |
sentinel | Skill Up Resources | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/sentinel/skill-up-resources.md | Title: Microsoft Sentinel skill-up training description: This article walks you through a level 400 training to help you skill up on Microsoft Sentinel. The training comprises 21 modules that present relevant product documentation, blog posts, and other resources.-+ Last updated 05/16/2024-+ |
storage | Data Protection Overview | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/data-protection-overview.md | -In the Azure Storage documentation, *data protection* refers to strategies for protecting the storage account and data within it from being deleted or modified, or for restoring data after it has been deleted or modified. Azure Storage also offers options for *disaster recovery*, including multiple levels of redundancy to protect your data from service outages due to hardware problems or natural disasters, and customer-managed failover in the event that the data center in the primary region becomes unavailable. For more information about how your data is protected from service outages, see [Disaster recovery](#disaster-recovery). +In the Azure Storage documentation, *data protection* refers to strategies for protecting the storage account and data within it from being deleted or modified, or for restoring data after it has been deleted or modified. Azure Storage also offers options for *disaster recovery*, including multiple levels of redundancy to protect your data from service outages due to hardware problems or natural disasters. Customer-managed (unplanned) failover is another disaster recovery option that allows you to fail over to a secondary region if the primary region becomes unavailable. For more information about how your data is protected from service outages, see [Disaster recovery](#disaster-recovery). ## Recommendations for basic data protection The following table summarizes the cost considerations for the various data prot Azure Storage always maintains multiple copies of your data so that it's protected from planned and unplanned events, including transient hardware failures, network or power outages, and massive natural disasters. Redundancy ensures that your storage account meets its availability and durability targets even in the face of failures. For more information about how to configure your storage account for high availability, see [Azure Storage redundancy](../common/storage-redundancy.md). -If a failure occurs in a data center, if your storage account is redundant across two geographical regions (geo-redundant), then you have the option to fail over your account from the primary region to the secondary region. For more information, see [Disaster recovery and storage account failover](../common/storage-disaster-recovery-guidance.md). +If your storage account is configured for geo-redundancy, you have the option to initiate an unplanned failover from the primary to the secondary region during a data center failure. For more information, see [Disaster recovery planning and failover](../common/storage-disaster-recovery-guidance.md#customer-managed-unplanned-failover). -Customer-managed failover isn't currently supported for storage accounts with a hierarchical namespace enabled. For more information, see [Blob storage features available in Azure Data Lake Storage Gen2](./storage-feature-support-in-storage-accounts.md). +Customer-managed failover currently supports storage accounts with a hierarchical namespace enabled in preview status only. For more information, see [Disaster recovery planning and failover](../common/storage-disaster-recovery-guidance.md#plan-for-failover). ## Next steps |
storage | Sas Service Create Dotnet Container | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/sas-service-create-dotnet-container.md | |
storage | Sas Service Create Dotnet | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/sas-service-create-dotnet.md | |
storage | Sas Service Create Java Container | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/sas-service-create-java-container.md | |
storage | Sas Service Create Java | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/sas-service-create-java.md | |
storage | Sas Service Create Javascript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/sas-service-create-javascript.md | |
storage | Sas Service Create Python Container | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/sas-service-create-python-container.md | |
storage | Sas Service Create Python | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/sas-service-create-python.md | |
storage | Secure File Transfer Protocol Known Issues | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/secure-file-transfer-protocol-known-issues.md | To learn more, see [SFTP permission model](secure-file-transfer-protocol-support - Maximum file upload size via the SFTP endpoint is 500 GB. -- Customer-managed account failover is supported at the preview level in select regions. For more information, see [Azure storage disaster recovery planning and failover](../common/storage-disaster-recovery-guidance.md#azure-data-lake-storage-gen2).+- Customer-managed account failover is supported at the preview level in select regions. For more information, see [Azure storage disaster recovery planning and failover](../common/storage-disaster-recovery-guidance.md#hierarchical-namespace-hns). - To change the storage account's redundancy/replication settings, SFTP must be disabled. SFTP may be re-enabled once the conversion has completed. |
storage | Snapshots Manage Dotnet | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/snapshots-manage-dotnet.md | |
storage | Storage Blob Account Delegation Sas Create Javascript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-account-delegation-sas-create-javascript.md | |
storage | Storage Blob Append | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-append.md | description: Learn how to append data to an append blob in Azure Storage by usin Previously updated : 09/01/2023 Last updated : 08/05/2024 ms.devlang: csharp |
storage | Storage Blob Client Management | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-client-management.md | |
storage | Storage Blob Container Create Go | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-create-go.md | |
storage | Storage Blob Container Create Java | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-create-java.md | |
storage | Storage Blob Container Create Javascript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-create-javascript.md | |
storage | Storage Blob Container Create Python | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-create-python.md | |
storage | Storage Blob Container Create Typescript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-create-typescript.md | |
storage | Storage Blob Container Create | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-create.md | |
storage | Storage Blob Container Delete Go | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-delete-go.md | |
storage | Storage Blob Container Delete Java | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-delete-java.md | |
storage | Storage Blob Container Delete Javascript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-delete-javascript.md | |
storage | Storage Blob Container Delete Python | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-delete-python.md | |
storage | Storage Blob Container Delete Typescript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-delete-typescript.md | |
storage | Storage Blob Container Delete | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-delete.md | |
storage | Storage Blob Container Lease Java | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-lease-java.md | |
storage | Storage Blob Container Lease Javascript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-lease-javascript.md | |
storage | Storage Blob Container Lease Python | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-lease-python.md | |
storage | Storage Blob Container Lease Typescript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-lease-typescript.md | |
storage | Storage Blob Container Lease | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-lease.md | |
storage | Storage Blob Container Properties Metadata Go | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-properties-metadata-go.md | |
storage | Storage Blob Container Properties Metadata Java | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-properties-metadata-java.md | |
storage | Storage Blob Container Properties Metadata Javascript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-properties-metadata-javascript.md | |
storage | Storage Blob Container Properties Metadata Python | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-properties-metadata-python.md | |
storage | Storage Blob Container Properties Metadata Typescript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-properties-metadata-typescript.md | |
storage | Storage Blob Container Properties Metadata | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-properties-metadata.md | |
storage | Storage Blob Container User Delegation Sas Create Dotnet | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-user-delegation-sas-create-dotnet.md | |
storage | Storage Blob Container User Delegation Sas Create Java | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-user-delegation-sas-create-java.md | |
storage | Storage Blob Container User Delegation Sas Create Python | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-container-user-delegation-sas-create-python.md | |
storage | Storage Blob Containers List Go | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-containers-list-go.md | |
storage | Storage Blob Containers List Java | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-containers-list-java.md | |
storage | Storage Blob Containers List Javascript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-containers-list-javascript.md | |
storage | Storage Blob Containers List Python | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-containers-list-python.md | |
storage | Storage Blob Containers List Typescript | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-containers-list-typescript.md | |
storage | Storage Blob Containers List | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-containers-list.md | |
storage | Storage Blob Copy Async Dotnet | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-copy-async-dotnet.md | description: Learn how to copy a blob with asynchronous scheduling in Azure Stor Previously updated : 04/11/2023 Last updated : 08/05/2024 ms.devlang: csharp |
storage | Storage Blob Copy Async Go | https://github.com/MicrosoftDocs/azure-docs/commits/main/articles/storage/blobs/storage-blob-copy-async-go.md | description: Learn how to copy a blob with asynchronous scheduling in Azure Stor Previously updated : 07/25/2024 Last updated : 08/05/2024 ms.devlang: golang |