You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

只读权限下,如何通过Azure SDK/CLI/REST API获取AKS集群K8s废弃API列表?

关于AKS集群废弃API查询及检测方式的解答

1. 通过Azure CLI/SDK/REST API查询废弃API列表

Azure CLI

使用az aks diagnostic run命令运行AKS内置的废弃API诊断检查,只读权限即可执行:

az aks diagnostic run --resource-group <你的资源组名称> --name <你的AKS集群名称> --diagnostic-name "KubernetesDeprecatedApis"

命令执行后,会返回JSON格式结果,包含当前集群中使用的废弃API详情、对应资源类型及建议的替代API版本。

Azure SDK(以Python为例)

使用azure-mgmt-containerservice包调用诊断接口,代码示例:

from azure.identity import DefaultAzureCredential
from azure.mgmt.containerservice import ContainerServiceClient

subscription_id = "<你的订阅ID>"
rg_name = "<你的资源组名称>"
aks_name = "<你的AKS集群名称>"

credential = DefaultAzureCredential()
client = ContainerServiceClient(credential, subscription_id)

result = client.managed_clusters.begin_diagnostic_run(
    resource_group_name=rg_name,
    resource_name=aks_name,
    diagnostic_name="KubernetesDeprecatedApis"
).result()

print(result.properties)

返回的properties字段包含废弃API的完整检测数据。

REST API

发送POST请求到AKS诊断端点,需携带Azure AD认证令牌:

POST https://management.azure.com/subscriptions/<订阅ID>/resourceGroups/<资源组名称>/providers/Microsoft.ContainerService/managedClusters/<AKS集群名称>/diagnostics/KubernetesDeprecatedApis/run?api-version=2023-10-01
Authorization: Bearer <你的AD认证令牌>

响应JSON中会列出集群内所有使用废弃API的资源详情。

2. Azure检测废弃API的方式

Azure通过两种核心途径发现AKS集群中的废弃API:

  • 审计日志分析:AKS集成Azure Monitor,会记录所有针对Kubernetes API服务器的请求,Azure持续分析这些日志,识别调用废弃API版本的请求(比如extensions/v1beta1类型的Ingress)。
  • 资源清单扫描:Azure定期扫描集群内已部署资源的清单文件(如Deployment、StatefulSet的YAML定义),检查其中apiVersion字段是否属于Kubernetes官方标记为废弃的版本。

两种方式结合,覆盖实时API调用和静态资源配置中的废弃API使用场景。Azure Advisor未返回相关信息,是因为该工具聚焦于资源成本优化、安全合规等通用建议,废弃API检测属于AKS专属的诊断能力范畴。

内容的提问来源于stack exchange,提问作者shaderox

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 16:03:09