Skip to content

AKS (Azure Kubernetes Service) access

By Parth_Shah, last updated on 22 August 2025.

Prerequisites

  • Optum Cloud account. (@optumcloud.com)
  • Access to Optima Azure Subscription (4cb6d6b1-b85d-4233-a61b-beb056c777e3) and necessary AKS resource.
    • AKS Cluster: optima-rulecraft-int-tst-us-c-pvt-aks
    • AKS Cluster: optima-rulecraft-int-dev-us-c-pvt-aks
    • AKS Cluster: optima-rulecraft-int-stg-us-c-pvt-aks
  • az cli command line in your local machine. AppStore link: Link
  • kubectl command line in your local machine. AppStore link: Link
  • FreeLens GUI tool installed on your local machine. AppStore link: Link

Login to Azure and get AKS contexts

  • Open a terminal and run the following command to log in to your Azure account. Select @optumcloud.com account for login.
az login
  • If you have multiple subscriptions, set the desired subscription using the following command:
az account set --subscription 4cb6d6b1-b85d-4233-a61b-beb056c777e3
  • Get AKS contexts

    • Test AKS context

      az aks get-credentials --resource-group optima-rulecraft-int-tst-us-c-rg --name optima-rulecraft-int-tst-us-c-pvt-aks --overwrite-existing
      

    • Dev AKS context

      az aks get-credentials --resource-group optima-rulecraft-int-dev-us-c-rg --name optima-rulecraft-int-dev-us-c-pvt-aks --overwrite-existing
      

    • Staging AKS context

      az aks get-credentials --resource-group optima-rulecraft-int-stg-us-c-rg --name optima-rulecraft-int-stg-us-c-pvt-aks --overwrite-existing
      

kube config updates

About kube config

  • We have to use kubeconfig files to organize information about clusters, users, namespaces, and authentication mechanisms. The kubectl command-line tool uses kubeconfig files to find the information it needs to choose a cluster and communicate with the API server of a cluster.

Identify Location of kube config file

  • Ideally it should be at ~/.kube/config but in some cases it may be at a different location.

Update kube config file

  • Open .kube/config file in a text editor.

  • Replace the cluster part of each environment (optima-rulecraft-int-tst-us-c-pvt-aks, optima-rulecraft-int-dev-us-c-pvt-aks, optima-int-stg-us-c-aks), as mentioned below:

  • It might look something like this:

    - cluster:
        certificate-authority-data: <>
        server: <>
      name: optima-rulecraft-int-tst-us-c-pvt-aks
    - cluster:
        certificate-authority-data: <>
        server: <>
      name: optima-rulecraft-int-dev-us-c-pvt-aks
    - cluster:
        certificate-authority-data: <>
        server: <>
      name: optima-rulecraft-int-stg-us-c-pvt-aks
    

  • Replace it with:

    - cluster:
        insecure-skip-tls-verify: true
        server: https://optima-test.optumrx.com/prometheus
      name: optima-rulecraft-int-tst-us-c-pvt-aks
    - cluster:
        insecure-skip-tls-verify: true
        server: https://optima-dev.optumrx.com/prometheus
      name: optima-rulecraft-int-dev-us-c-pvt-aks
    - cluster:
        insecure-skip-tls-verify: true
        server: https://optima-stage.optumrx.com/prometheus
      name: optima-rulecraft-int-stg-us-c-pvt-aks
    

Enable Proxy for local access

Note: Wait for 1-2 minutes for the proxy to be deployed.

And you are ready to access the AKS cluster in your local machine.

Important

The proxy will be enabled for a window of 30 minutes. After that, you will have to run the pipeline again to enable the proxy.