question

VimalK-5402 avatar image
0 Votes"
VimalK-5402 asked ·

How to invoke a service on a VM from AKS pod when VM and AKS are in different/same resource group

I have a set of VMs in a resource group
I have an AKS cluster in another resource group.

The services running on VMs can talk to each other using local IPs, and these are important services, so dont want to expose them via a gateway.

How do i access a service on the VM from AKS pod, without exposing the service in any way. Basically services on the VM can be accessed via local IPs only. How to access them from AKS?

If i put the AKS in the same resource group as VM, then can i acesss using local IPs?

azure-virtual-machinesazure-kubernetes-service
· 2
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@VimalK-5402 Apologies for the delay in response and all the inconvenience caused because of the issue.
I have reached out to our internal team on the issue and once I have an update will keep you posted on same.

Thank you for your patience over the matter.

Thanks.

0 Votes 0 ·

Please help to get the answer

0 Votes 0 ·

1 Answer

prmanhas-MSFT avatar image
0 Votes"
prmanhas-MSFT answered ·

@VimalK-5402 Below is the response I got from our internal team:

You can't move an AKS cluster across RG. [Not Supported] You can rebuild the AKS cluster in the same RG as VMs but the infra RG for AKS is going to be different. And in any case RG does not matter. Look at N/W. Are the VMs and the AKS worker nodes in the same N/W? If so they can directly access, else peer the AKS Vnet with the VM Vnet. If peering is not possible due to subnet overlap and if you are using AKS with multiple nodepool support (VMSS node pool type basically) then

1) You can add another subnet in the AKS VNet (which does not overlap with the subnet CIDR of VMs) -> Add a new system mode node pool on AKS associated with the new subnet -> Drain earlier node pool and remove it -> peer new subnet in AKS Vnet with VM Subnet.
Or

2) You can create new subnet in the VM Vnet -> create a new system mode node pool on AKS associated with the newly created subnet -> Drain the old node pool and delete it. In this case since both AKS node pool subnet and VM subnet are in the same VNet, communication over private IPs should not be a problem.

Hope it helps!!!

Please "Accept as Answer" if it helped so it can help others in community looking for help on similar topics

· 3 ·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Are you confirming that if AKS node pool subnet and VM subnet are in the same VNet, the containers on AKS can directly invoke the VM using internal IP?

0 Votes 0 ·

@VimalK-5402 Apologies for the delay in response and all the inconvenience caused because of the issue.

Yes your understanding is correct that AKS node pool subnet and VM subnet are in the same VNet, the containers on AKS can directly invoke the VM using internal IP.

Please "Accept as Answer" if it helped so it can help others in community looking for help on similar topics


0 Votes 0 ·
prmanhas-MSFT avatar image prmanhas-MSFT VimalK-5402 ·

@VimalK-5402 Just following up to check if you need any further help on this issue ?

Please "Accept as Answer" if it helped so it can help others in community looking for help on similar topics

0 Votes 0 ·