AKS (Azure Kubernetes Service) access¶
By Parth_Shah, last updated on 22 August 2025.
Prerequisites¶
- Optum Cloud account. (
@optumcloud.com) - Access to Optima Azure Subscription (
4cb6d6b1-b85d-4233-a61b-beb056c777e3) and necessary AKS resource.- AKS Cluster:
optima-rulecraft-int-tst-us-c-pvt-aks - AKS Cluster:
optima-rulecraft-int-dev-us-c-pvt-aks - AKS Cluster:
optima-rulecraft-int-stg-us-c-pvt-aks
- AKS Cluster:
az clicommand line in your local machine. AppStore link: Linkkubectlcommand line in your local machine. AppStore link: LinkFreeLensGUI tool installed on your local machine. AppStore link: Link
Login to Azure and get AKS contexts¶
- Open a terminal and run the following command to log in to your Azure account. Select
@optumcloud.comaccount for login.
- If you have multiple subscriptions, set the desired subscription using the following command:
-
Get AKS contexts
-
Test AKS context
-
Dev AKS context
-
Staging AKS context
-
kube config updates¶
About kube config¶
- We have to use kubeconfig files to organize information about clusters, users, namespaces, and authentication mechanisms. The
kubectlcommand-line tool uses kubeconfig files to find the information it needs to choose a cluster and communicate with the API server of a cluster.
Identify Location of kube config file¶
- Ideally it should be at
~/.kube/configbut in some cases it may be at a different location.
Update kube config file¶
-
Open .kube/config file in a text editor.
-
Replace the
clusterpart of each environment (optima-rulecraft-int-tst-us-c-pvt-aks,optima-rulecraft-int-dev-us-c-pvt-aks,optima-int-stg-us-c-aks), as mentioned below: -
It might look something like this:
-
Replace it with:
- cluster: insecure-skip-tls-verify: true server: https://optima-test.optumrx.com/prometheus name: optima-rulecraft-int-tst-us-c-pvt-aks - cluster: insecure-skip-tls-verify: true server: https://optima-dev.optumrx.com/prometheus name: optima-rulecraft-int-dev-us-c-pvt-aks - cluster: insecure-skip-tls-verify: true server: https://optima-stage.optumrx.com/prometheus name: optima-rulecraft-int-stg-us-c-pvt-aks
Enable Proxy for local access¶
- AKS clusters are Private, hence it needs a proxy to access it from local.
- Run/Execute the necessary Jenkins pipeline to enable proxy in that particular environment.
- Proxy Jenkins pipeline link (Deprecated now. Use GitHub action.): https://jenkins-optima-optumrx.optum.com/job/TestPipelines/job/optima-kube-proxy/
- Proxy GitHub action link: https://github.com/optum-rx-platformintegration/optima-platform-actions/actions/workflows/proxy.yml
Note: Wait for 1-2 minutes for the proxy to be deployed.
And you are ready to access the AKS cluster in your local machine.
Important
The proxy will be enabled for a window of 30 minutes. After that, you will have to run the pipeline again to enable the proxy.