Skip to main content
compliance · azure

AKS clusters with the Container insights monitoring add-on switched off

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an AKS cluster when Azure reports its Container insights add-on, listed as `omsagent` under the cluster's addon profiles, as disabled. Without it, node health, pod performance and container logs never reach a Log Analytics workspace, so capacity problems surface as outages instead of alerts. The finding carries no dollar saving.

Signal and threshold

How ZopNight evaluates AKS clusters with the Container insights monitoring add-on switched off.
Field Value
Rule IDsRC-1352
Categorycompliance
Severitymedium
Metricnone — pure configuration read
Thresholdomsagent add-on disabled
SourceZopNight
Permissions usedMicrosoft.ContainerService/managedClusters/read

What AKS gives you for free and what it does not

Azure collects AKS platform metrics and activity log entries automatically and at no charge, per the AKS monitoring overview. Those tell you the cluster exists and roughly how busy the control plane is. They do not tell you which node is out of memory, which pod is restarting, or what a crashing container printed before it died.

That view comes from Container insights, which runs a containerized Azure Monitor agent on the nodes and writes inventory, performance data and container logs to a Log Analytics workspace. In the cluster’s resource definition the add-on appears as omsagent under addonProfiles.

Checking the add-on on your clusters

Terminal window
az aks show --resource-group my-rg --name my-aks \
--query addonProfiles.omsagent.enabled

false, or no omsagent entry at all, means Container insights is not collecting from the cluster.

What has to be true for the finding

The finding fires only when Azure’s description of the cluster reports the Container insights add-on as disabled. ZopNight does not look at metrics or wait out a window: the state is read on each scan, and turning the add-on on clears the finding on the next one.

Clusters ZopNight does not flag

When the add-on’s state is missing from what Azure returned, the cluster is treated as unknown and left alone. Monitoring labels or tags you put on the cluster are not consulted. This check also says nothing about control-plane logs, which are configured separately through diagnostic settings and covered by AKS Cluster Diagnostic Logging Not Enabled.

Visibility, paid for in Log Analytics

There is no saving attached to this compliance finding. Enabling Container insights adds Log Analytics ingestion cost, which you can control: Microsoft documents data collection rule settings to choose tables, collection intervals and excluded namespaces, and the ContainerLogV2 schema supports the cheaper Basic logs tier. The risk of skipping it is that resource bottlenecks are found by users first.

Enabling Container insights

  1. Choose the Log Analytics workspace that should hold the cluster’s data.
  2. Enable the add-on on the existing cluster, as shown in Enable monitoring for AKS:
Terminal window
az aks enable-addons --addon monitoring \
--name my-aks --resource-group my-rg \
--workspace-resource-id /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.OperationalInsights/workspaces/<ws>
  1. Review the data collection settings and exclude noisy namespaces before volume builds up.
  2. Turn on the recommended alert rules for node and pod health so problems page someone.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·