AKS nodes pull container images using this user-assigned managed identity, so AcrPull on the registry must be granted to it rather than to the control plane identity.
Also called agent pool managed identity.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Kubelet identity in context, with comparison tables and the common traps.
Terms in this definition
- AKS
Short for Azure Kubernetes Service, a managed Kubernetes offering that gives full control of clusters and node pools. Scaling uses the cluster autoscaler and Horizontal Pod Autoscaler; user sign-in is not built in.
- Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- UAMI
A user-assigned managed identity: an Azure resource of its own that can be attached to services. Mirroring Azure SQL Database requires the logical server to have a primary identity enabled, which may be its system-assigned identity or, in preview, a UAMI.
- AcrPull
Data-plane role built into Azure Container Registry that allows reading tags and pulling images. Assign it to whichever identity performs the pull.
- Control plane
Management layer used to create, configure and remove resources, as distinct from the data plane where they are used. Azure Resource Manager fills this role for Azure, and in AKS Azure operates the Kubernetes control plane on your behalf.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
Related terms
- --attach-acr
Option on
az aks createoraz aks updatethat links a container registry to an AKS cluster by assigning AcrPull to the kubelet identity, so nodes can pull its images. - Image pull secret
A Kubernetes secret containing credentials for a registry, for example a service principal, used when pulling images. It is not needed if the kubelet identity holds AcrPull.