只读权限下,如何通过Azure SDK/CLI/REST API获取AKS集群K8s废弃API列表?
关于AKS集群废弃API查询及检测方式的解答
1. 通过Azure CLI/SDK/REST API查询废弃API列表
Azure CLI
使用az aks diagnostic run命令运行AKS内置的废弃API诊断检查,只读权限即可执行:
az aks diagnostic run --resource-group <你的资源组名称> --name <你的AKS集群名称> --diagnostic-name "KubernetesDeprecatedApis"
命令执行后,会返回JSON格式结果,包含当前集群中使用的废弃API详情、对应资源类型及建议的替代API版本。
Azure SDK(以Python为例)
使用azure-mgmt-containerservice包调用诊断接口,代码示例:
from azure.identity import DefaultAzureCredential from azure.mgmt.containerservice import ContainerServiceClient subscription_id = "<你的订阅ID>" rg_name = "<你的资源组名称>" aks_name = "<你的AKS集群名称>" credential = DefaultAzureCredential() client = ContainerServiceClient(credential, subscription_id) result = client.managed_clusters.begin_diagnostic_run( resource_group_name=rg_name, resource_name=aks_name, diagnostic_name="KubernetesDeprecatedApis" ).result() print(result.properties)
返回的properties字段包含废弃API的完整检测数据。
REST API
发送POST请求到AKS诊断端点,需携带Azure AD认证令牌:
POST https://management.azure.com/subscriptions/<订阅ID>/resourceGroups/<资源组名称>/providers/Microsoft.ContainerService/managedClusters/<AKS集群名称>/diagnostics/KubernetesDeprecatedApis/run?api-version=2023-10-01 Authorization: Bearer <你的AD认证令牌>
响应JSON中会列出集群内所有使用废弃API的资源详情。
2. Azure检测废弃API的方式
Azure通过两种核心途径发现AKS集群中的废弃API:
- 审计日志分析:AKS集成Azure Monitor,会记录所有针对Kubernetes API服务器的请求,Azure持续分析这些日志,识别调用废弃API版本的请求(比如
extensions/v1beta1类型的Ingress)。 - 资源清单扫描:Azure定期扫描集群内已部署资源的清单文件(如Deployment、StatefulSet的YAML定义),检查其中
apiVersion字段是否属于Kubernetes官方标记为废弃的版本。
两种方式结合,覆盖实时API调用和静态资源配置中的废弃API使用场景。Azure Advisor未返回相关信息,是因为该工具聚焦于资源成本优化、安全合规等通用建议,废弃API检测属于AKS专属的诊断能力范畴。
内容的提问来源于stack exchange,提问作者shaderox
相关产品推荐
相关产品推荐

