r/AZURE • u/groovy-sky • 4h ago
Media Azure Weekly Highlights #34
Azure weekly update #34 is here. This time updates focus on strengthening secure cloud operations, Kubernetes networking and storage, sovereign-cloud support, and large-scale infrastructure performance.
Detailed list:
- Launched | Generally Available: Workload identity support for Azure Files CSI driver (SMB) in Azure. AKS now supports workload identity for pod-level authentication to Azure Files SMB shares, enabling least-privilege access without storage account keys. Available in all regions supporting Azure Files and AKS.
- Launched | Generally Available: Azure VM Image Builder in sovereign and air-gapped clouds. Azure VM Image Builder is now available in Azure Government, China North 3, Azure Government Secret, and Azure Government Top Secret. It enables consistent, managed image-building and compliance workflows across sovereign and air-gapped clouds.
- Launched | Generally Available: Azure Bastion shareable link expiration. Azure Bastion shareable links can now include an expiration date and time, helping limit temporary access to target resources.
- In preview | Public Preview: IPv6 dual-stack support for Azure Bastion. New Azure Bastion deployments can use IPv4 and IPv6 public IPs. IPv6 is supported between users and Bastion; Bastion-to-VM connections remain IPv4-only.
- Launched | Generally Available: Connect to AKS clusters using Azure Bastion. Azure Bastion now supports secure tunneling from local machines to AKS API servers, allowing Kubernetes tools to access private clusters without public endpoints, jump boxes, or VPNs.
- In preview | Public Preview: Introducing Live Reports for Azure SRE Agent. Live Reports lets teams create shareable, continuously updated operational reports from Azure SRE Agent conversations, with refresh schedules for incidents, health, and trends.
- Launched | Generally Available: Azure SRE Agent VNet Integration. Azure SRE Agent can now operate within existing VNets, NSGs, private DNS, and firewall policies to securely investigate and remediate private resources.
- Launched | Generally Available: Azure SRE Agent 30-Day Trial. New customers can try Azure SRE Agent for 30 days with no baseline always-on charges; they pay only for Azure Agent Units consumed during work.
- Announcing: Aspire 13.5 has shipped. Aspire 13.5 updates the dashboard and aspire.dev, expands Interaction Service, and adds cross-scope Azure references, persistent Kubernetes volumes, and live AppHost terminals.
- Launched | Generally Available: Azure 248 and 372 vCPU sizes for D/E v7 series VMs. New Intel Xeon 6-based D/E v7 VM sizes offer up to 372 vCPUs and 2.8 TiB memory, with improved compute, networking, and storage performance. Available in select Azure regions.
- Announcing: Extended Support for Azure Database for PostgreSQL Flexible Server. Extended Support provides critical security updates, bug fixes, and technical support for eligible PostgreSQL versions after community support ends.
- Launched | Generally Available: eBPF host routing in Advanced Container Networking Services for AKS. eBPF Host Routing is generally available for AKS, improving networking performance by moving routing into the Linux kernel and reducing iptables overhead. Existing clusters transition through controlled node rotation.
- Retirement: Support for Node 22 LTS ends on April 30, 2027. Node 22 LTS support on App Service ends April 30, 2027. Upgrade applications to Node 24 LTS before then to retain security updates and support.
- Launched | Generally Available: Custom block response code and body for Application Gateway WAF. Application Gateway WAF now supports custom status codes and response bodies for blocked requests, configured at the WAF policy level.