Deckhouse Platform in Microsoft Azure

Only regions where Availability Zones are available are supported.

Before installation, ensure the following:

  • Cloud provider quotas for cluster deployment.
  • The cloud-init package is installed on the VMs. After the VM starts, services cloud-config.service, cloud-final.service, cloud-init.service must be running.
  • The virtual machine template contains only one disk.
  • Firewall rules and security groups allow UDP traffic between cluster nodes. A new cluster uses the Cilium CNI by default with pod traffic tunneling over VXLAN. Cilium requires Linux kernel 5.8 or newer on the nodes, and the list of ports is available in Network interaction of the platform components.

Additional requirements and notes

  • For ContainerdV2 on cluster nodes, the OS on virtual machines must meet the requirements:
    • Linux kernel version 5.8 or newer, except for the ranges 6.12.0–6.12.28 or 6.14.0–6.14.6 (these versions are affected by CVE-2025-37999 in EROFS);
    • CgroupsV2 support;
    • Systemd version 244 or newer;
    • erofs kernel module support.

    For more information, see the ClusterConfiguration resource.

  • From version 1.74, Deckhouse Platform has a module integrity control mechanism (protection against replacement and modification). It turns on automatically when the OS on the nodes supports the erofs kernel module. Without it, Deckhouse Platform runs as before but the mechanism is off — an alert will indicate it is unavailable.

Prepare the Microsoft Azure environment so that Deckhouse Platform can manage cloud resources. The full procedure is described on the environment preparation page of the cloud-provider-azure module.

To manage resources in Microsoft Azure, you need an Azure account and at least one subscription.

Create a service account for Deckhouse Platform. Run the following commands on the personal computer using the Azure CLI.

Install the Azure CLI. Log in to Azure and save the subscription ID to the SUBSCRIPTION_ID environment variable:

export SUBSCRIPTION_ID=$(az login | jq -r '.[0].id')

The command saves the ID of the first subscription of the account. If the account has several subscriptions, set the ID of the required one in the variable.

Create a service account:

az ad sp create-for-rbac --role="Contributor" --scopes="/subscriptions/$SUBSCRIPTION_ID" --name "account_name"

Use the values from the command output and the subscription ID in the provider section of the configuration:

  • appId: The clientId parameter.
  • password: The clientSecret parameter.
  • tenant: The tenantId parameter.
  • The value of the SUBSCRIPTION_ID variable: The subscriptionId parameter.

The secret in the clientSecret parameter is valid for one year and is not renewed automatically. To set a longer validity period, add the --years flag to the az ad sp create-for-rbac command. The flag is described in the Azure CLI reference.