3 minute read
Gardener allows you to create a Kubernetes cluster on different infrastructure providers. This tutorial will guide you through the process of creating a cluster on Azure.
- You have created an Azure account.
- You have access to the Gardener dashboard and have permissions to create projects.
- You have an Azure Service Principal assigned to your subscription.
Go to the Gardener dashboard and create a Project.
Get the properties of your Azure AD tenant, Subscription and Service Principal.
Before you can provision and access a Kubernetes cluster on Azure, you need to add the Azure service principal, AD tenant and subscription credentials in Gardener. Gardener needs the credentials to provision and operate the Azure infrastructure for your Kubernetes cluster.
Ensure that the Azure service principal has the actions defined here within your Subscription assigned. If no fine-grained permission/actions are required then simply the buildin
Contributorrole can be assigned.
To find your TenantID, follow this guide.
To find your SubscriptionID, search for and select Subscriptions.
After that, copy the SubscriptionID from your subscription of choice.
Service Principal (SPN)
A service principal consist of a
ApplicationID) and a Client Secret. For more information, see here. You need to obtain the:
Access the Azure Portal and navigate to the
Active Directoryservice. Within the service navigate to
App registrationsand select your service principal. Copy the ClientID you see there.
Secrets for the Azure Account/Service Principal can be generated/rotated via the Azure Portal. After copying your ClientID, in the
Detailview of your Service Principal navigate to
Certificates & secrets. In the section, you can generate a new secret.
Choose Secrets, then the plus icon and select Azure.
Create your secret.
- Type the name of your secret.
- Copy and paste the
SubscriptionIDand the Service Principal credentials (
- Choose Add secret.
After completing these steps, you should see your newly created secret in the Infrastructure Secrets section.
Register resource providers for your subscription.
- go to your azure dashboard
- go to subscriptions -> <your_subscription>
- pick resource providers from the sidebar
- register microsoft.Network
- register microsoft.Compute
To create a new cluster, choose Clusters and then the plus sign in the upper right corner.
In the Create Cluster section:
- Select Azure in the Infrastructure tab.
- Type the name of your cluster in the Cluster Details tab.
- Choose the secret you created before in the Infrastructure Details tab.
- Choose Create.
Wait for your cluster to get created.
After completing the steps in this tutorial, you will be able to see and download the kubeconfig of your cluster.