DevOpsArk + Azure
AKS, virtual machines, ACR and cost
Vendor: Microsoft
What does the DevOpsArk Azure integration do?
The DevOpsArk Azure integration connects Azure subscriptions so AKS clusters, virtual machines, Azure Container Registry, Entra ID access and cost data are managed from the same plane as your other providers.
What the Azure integration provides
- Manage Azure Kubernetes Service clusters in the same inventory as EKS and GKE.
- Inventory Azure virtual machines with patch state and configuration baseline.
- Publish images to Azure Container Registry by immutable digest.
- Evaluate subscription configuration against CIS Azure Foundations and your own policy.
- Attribute Azure Cost Management data to clusters, namespaces and teams.
- Include Azure RBAC and Entra ID in the unified effective-access model.
- Manage Azure DNS zones through the reviewed change path.
Exactly what is read, and what can be written
Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.
- AKS cluster, node pool and add-on configuration
- Virtual machine inventory, tags and extensions
- Azure Container Registry repositories and images
- Entra ID role assignments and Azure RBAC
- Azure Monitor metrics and logs
- Azure Cost Management exports
- Azure DNS zones and record sets
- Virtual network and network security group configuration
- Kubernetes workloads deployed to AKS through ArkCD
- Container images pushed to Azure Container Registry
- Azure DNS record changes through the reviewed change path
- Approved remediation where write scope is granted
Connecting Azure
- 1Register an application
Create an Entra ID application registration for DevOpsArk with the supplied reader role assignments.
- 2Assign scope
Grant the role at management group or subscription scope depending on how much of the estate you want visible.
- 3Connect
Register the tenant, subscription and application credentials in DevOpsArk.
- 4Attach cost exports
Point DevOpsArk at the Cost Management export to enable attribution.
Which modules use Azure
Kubernetes
Multi-cluster Kubernetes management
Servers
Fleet inventory, patching and access
Cost Management
Cloud and Kubernetes cost attribution
Security
Posture, policy and continuous verification
IAM
Access, roles and approvals
ArkCD
Continuous delivery and progressive rollout
Azure integration: frequently asked questions
It connects Azure subscriptions so AKS clusters, virtual machines, container registries, access assignments, DNS zones and cost data appear alongside your other providers under one delivery, security and cost model.
An Entra ID application registration with Reader at the subscription or management group scope covers inventory, posture and cost. Write access is granted separately and scoped to the actions you want DevOpsArk to perform.
Yes. AKS clusters are ArkCD targets like any other Kubernetes cluster, with their own rollout strategy, configuration and approval rules.
Yes. Subscriptions across one or more tenants can be connected and are presented in a single inventory.
Cost Management export data is joined with live inventory, so node and virtual machine cost is distributed to namespaces and workloads and then to owning teams, in the same model used for AWS and Google Cloud.
Integrations that commonly go with this one
Connect Azure and see your own data
Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.