Repository navigation
Releases: Azure/azure-iot-operations
Release list
2509 Update
AIO2509 (v1.2.72) Public Preview Release Notes
Summary
The 2509 release introduces several enhancements now available in public preview, focused on simplifying deployment and improving edge-to-cloud observability. Key updates include:
- Secret Management: Integrated Secret Picker with Azure Key Vault for secure, in-portal secret selection.
- Telemetry Connectors: New connectors stream HTTP events and OTEL telemetry to MQTT/state stores and Azure Monitor.
- Modular Dataflows: Dataflow graphs and import/export capabilities streamline edge automation and configuration.
- CLI Improvements: Deprecated extensions removed, asset migration command added, and Python 3.13 proxy compatibility patched.
Server-Sent Events (SSE) Connector
Introducing the Server-Sent Events (SSE) connector, now in public preview. This connector enables integration with HTTP(S) endpoints that expose SSE streams, allowing real-time event ingestion into Azure IoT Operations.
Key Features:
- Samples SSE events from configured HTTP(S) endpoints.
- Automatically generates message schemas for each dataset/event and registers them with Schema Registry and Azure Device Registry.
- Forwards event data to designated destinations.
- Implements automatic retries on sampling failures.
- Integrates with OpenTelemetry for enhanced observability.
- Supports device endpoints and namespace assets.
- Infers schema from JSON payloads.
- Offers multiple authentication methods:
- Username/password
- x.509 certificates
- Anonymous access
- Certificate trust list/bundle
OPC UA Connector
Introducing enhancements to the OPC UA Connector, now available in public preview. These updates expand integration capabilities with shop floor systems and improve semantic data synchronization for edge intelligence.
Key Features:
-
OPC UA Call Support: Define management actions of type Call and Write, and invoke them via the MQTT RPC API:
. The connector auto-generates JSON Schema Draft 7 definitions for request and response messages, simplifying interaction with OPC UA assets./asset-operations/ / / -
Property Synchronization to DSS: Semantic properties modeled in the OPC UA address space (e.g., metadata on variable nodes) are now synchronized into the AIO MQTT Distributed State Store (DSS). Properties are added under the ID:
{AioNamespace}.{AssetName}.{DatasetName}.{DataPointName}.{PropertyName}. This enables enriched dataflows and dynamic routing based on asset metadata.
Breaking Changes:
-
MQTT Path for Dataset Write: Updated from:
to:/asset-operations/ / . This aligns with management group conventions./asset-operations/ /builtin/ -
MQTT Path for Dataset Telemetry: Updated from:
to:/data/ / . This change supports more granular dataflow definitions./data/ /
Fixed Bugs:
- Support for multiple inbound endpoints of type
Microsoft.OpcUawithin a single device. - Custom MQTT destinations per dataset now function as expected.
- Resolved Invalid Cast Exception during asset discovery when OPC UA address space browsing fails.
Azure Portal Enhancements
- Secret Picker Integration: The Azure IoT Operations instance blade now features a streamlined Secret Picker experience, enabling secure browsing, selection, and management of secrets directly from Azure Key Vault.
- Server-Side Events Connector: Supports real-time streaming of HTTP events to MQTT or state stores, simplifying integration with edge systems.
Azure IoT Operations Experience
- OTEL Connector: Streams structured telemetry (logs, metrics, traces) from edge assets to observability platforms like Azure Monitor for real-time diagnostics and fleet-wide insights.
- Modular Dataflow Graphs: Enables OT teams to build resilient, near real-time edge intelligence workflows.
- Import/Export Capabilities: Facilitates seamless migration and scaling by allowing import/export of tags, datapoints, events, and management actions.
- Server-Side Events Connector: Also available within the operations experience for HTTP-to-MQTT/state store streaming.
Azure IoT Operations CLI Updates
- Deployment Changes:
- Updated arc extension versions for
ops initandops create. ops initno longer deploys the ACSA extension or supports extension config.ops upgradeexcludes the ACSA extension.ops initskips AIO Platform extension deployment when--user-trustis specified.
- Updated arc extension versions for
- Deprecated Parameters:
- Removed from
ops create:--enable-rsync,--runtime-socket, and--kubernetes-distro. - Removed from
ops broker persist update:--user-keyand--user-value.
- Removed from
- New Command:
az iot ops migrate-assets: Migrates root assets to namespace assets.
- Python 3.13 Compatibility Patch:
- Applied to cluster-side commands (
ops check,ops init --check-cluster,ops support create-bundle) to address proxy certificate issues withconnectedk8son Python 3.13 (non-conformance to RFC 5280).
- Applied to cluster-side commands (
2508 Update
AIO2508 (v1.1.69) Release Notes
Bug fixes, performance improvements and security updates.
2507 Update
AIO2507 (v1.2.36) Public Preview Release Notes
Summary of 2507
Connector Templates: Create reusable templates to streamline connector configuration and deployment across Azure IoT Operations clusters.
ADR Namespaces: Enable logical isolation and security boundaries for managing assets and devices at scale.
Devices: Support for devices with inbound endpoints, including cross-connector capabilities.
ONVIF Connector: Integrate ONVIF-compliant cameras and devices for video and surveillance scenarios.
Media Connector: Ingest and process media streams from diverse sources with enhanced flexibility.
REST Connector: Connect to any RESTful endpoint, enabling seamless integration with external systems and APIs.
Enrich: Enhance incoming data with contextual metadata from REST endpoints to support advanced analytics.
Discovery of Devices and Assets: Automatically detect and onboard devices and assets, reducing manual configuration.
Regional Expansion: Azure IoT Operations is now deployable to Arc-connected clusters in the Germany West Central region. This support is available in the latest preview and backported to GA version 1.1.59
OPC UA Connector
Breaking Changes
- JSON Schema Update: Each dataset and event now generates a JSON schema with the
$iddefined only at the root level, using the HTTP schema format. - Schema Referencing: OPC UA-specific types are now referenced using partial JSON pointers within the document.
New Features
- OPC UA Write Support: Customers can now write datapoints—both simple and complex types—within a dataset using the MQTT RPC API. This highly requested feature enables direct influence back into the shop floor.
- Address Space Browsing: The connector now supports browsing the OPC UA server address space via MQTT RPC API, improving visibility and control.
- Advanced Event Filtering: Full event filtering is now supported, allowing customers to select and shape events directly on the OPC UA server. This reduces data processing costs and improves efficiency.
Bug Fixes
- Schema Correction: Removed incorrect
const: 0values from OPC UA-specific types in the JSON schema. - Asset Change Detection: Resolved issues where changes to assets were not consistently detected. Updates are now reliably handled.
Media Connector
Breaking Changes
- Lifecycle Management: Media Connector's lifecycle is now managed by Akri and no longer by the AIO Connectors supervisor.
- Configuration Model Update: Support for
AssetEndpointProfileCRs andAssetCRs Datasets has been removed. Configuration is now handled exclusively through Namespaced Device CRs and Namespaced Asset CRs. - Dataset to Stream Migration: Media Connector's operation is now defined in the Streams section of an Asset CR, instead of the Datasets section.
New Features
- Downstream Server Authentication: Authentication is now supported for downstream media servers in the stream-to-RTSP task.
- TLS Support: Media Connector now supports TLS encryption for both media endpoints and downstream media server connections.
ONVIF Connector
Breaking Changes
- Lifecycle Management: ONVIF Connector's lifecycle is now managed by the Akri Operator and no longer by the AIO Connectors supervisor.
- Configuration Model Update: Support for
AssetEndpointProfileCRs andAssetCRs Datasets has been removed. Configuration is now handled exclusively via Namespaced Device CRs and Namespaced Asset CRs. - Endpoint Discovery Redesign: The connector no longer creates individual
DiscoveredAssetEndpointProfileCRs for each media endpoint. Instead, it creates inbound endpoints within aDiscoveredDeviceCR, allowing them to be processed by DOE.
New Features
- Media Metadata Exposure: Resolution and framerate information for discovered media endpoints are now published as attributes in the
DiscoveredDeviceCR. - Management Group Support: ONVIF Connector now supports management groups.
- TLS Support: TLS encryption is now supported for connections to ONVIF devices.
REST / HTTP Connector
New Features
- Public Preview Launch: The REST/HTTP Connector is now available in Public Preview! This connector allows you to connect to external REST/HTTP endpoints and create Assets that send data to the MQTT broker or Broker State Store, enabling richer data enrichment and contextualization. 📘Learn more: Configure the connector for REST/HTTP.
- Configurable Sampling: The connector supports data sampling at configurable intervals from REST/HTTP endpoints.
- Flexible Data Routing: Forward sampled data to multiple destinations, including the MQTT broker and the State Store, for advanced observability and processing.
- Authentication Support: Multiple authentication methods are supported, including username/password, x509 certificates, certificate trust bundles, and anonymous access (for testing).
MQTT Broker
New Features
- MQTT Data Persistence (Preview): Data can now be persisted to disk, ensuring durability across broker restarts. Granular configuration is supported for different data types. 📘Learn more: Configure MQTT broker persistence.
- Azure Device Registry Integration (Preview): The broker now supports X.509 authentication backed by Azure's Device Registry. Devices must be pre-registered, and you can disable clients by disabling their corresponding registry entries. 📘Learn more: Configure MQTT broker authentication.
Bug Fixes
- Broker Crash Fix: Resolved an issue where the broker would crash if the trusted client CA certificate was missing in a configured
BrokerAuthentication.
DataFlows
New Features
- WebAssembly Support (Preview): You can now deploy custom business logic and data transformations using WebAssembly (WASM) modules embedded within data flows. 📘Learn more: Use WebAssembly (WASM) with data flow graphs.
- OpenTelemetry Endpoint Integration (Preview): Data flows now support sending data directly to OpenTelemetry collectors or Azure Monitor, enabling seamless observability integration. 📘Learn more: Configure OpenTelemetry data flow endpoints.
- Dynamic Destination Topics: Define dynamic topics using variables like
${inputTopic}, allowing destination topics to reuse source topic segments for flexible routing. 📘Learn more: Configure data destination.
Bug Fixes
- Retry Logic Fix: Resolved an issue where control plane operations were not retried adequately, improving reliability.
Akri
New Features
- Revamped Akri Services (Public Preview): The Akri component has been completely rearchitected and is now available in public preview! 📘Learn more: What are Akri Services?
- Connector Lifecycle Management: Akri now manages the deployment and lifecycle of both 1P Akri Connectors (e.g., ONVIF, Media, REST/HTTP) and 3P custom connectors built using the Azure IoT Operations SDKs.
- Device & Asset Discovery Backend: Akri handles the backend services for asset detection and device discovery—especially for ONVIF and media devices.
- Azure Portal Integration: Akri configuration can now be done via the Azure portal, enabling protocol selection and tracking configuration changes directly in your Azure IoT Operations instance.
- Secure Registry Access: Akri exposes an API that allows Akri Connectors to securely access Devices and Assets from the Azure Device Registry.
Known Issues
- Connector Template Limitations: The Connector Template ARM Resource/CRD currently supports only Image-based deployment. While it exposes fields for StatefulSet and Helm-based deployment, those options are not yet functional and will be supported in future releases.
- Secret Sync Conflict: When using Secret Sync, ensure that secret names are globally unique. If a local secret with the same name exists, connectors may fail to retrieve the intended secret.
AIO Observability
New Features
- Inline Observability Configuration: Observability can now be configured by providing the
--ops-configparameter during a standard upgrade command, making it easier to enable or modify observability at any point. 📘Learn more: Deploy observability resources.
ADR & Schema Registry
New Features
- Namespace Enforcement: All Azure IoT Operations instances are now tied to a namespace. Resources created for an instance will reside within its associated namespace, introducing stricter logical isolation and security boundaries.
- Device Resource Supersession: The new
Namespace Deviceresource replaces asset endpoint profiles for namespace assets. While endpoint profiles remain for backward compatibility, future development should target the new device model. - Names...
2506 Update
AIO2506 (v1.1.59) Release Notes
New Features
- Tanzu Kubernetes Grid Multi-cloud is now a validated and supported Kubernetes distribution for running Azure IoT Operations.
- Introduced OPC UA certificate management via the Operations Portal. Users can now upload certificates to Azure Key Vault and synchronize them to the edge to establish trust with on-premises servers.
- Launched a new Formula Catalog to simplify data transformation. This curated library provides access to industry-standard calculations for direct use in dataflows.
- Enabled creation of Fabric RTI dataflow endpoints using system-assigned managed identities for authentication.
- General stability improvements and bug fixes.
Bug Fixes
- General stability improvements and bug fixes across the board.
- Specifically in Azure IoT Operations Experience
- Resolved an issue where legacy tag imports failed to process Finnish characters correctly.
- Fixed a bug that prevented saving assets when modifying the publishing interval.
- Corrected behavior where applying a tag filter resulted in an incorrect saved state.
Azure IoT Operations CLI
Breaking Changes
- Dropped support for
Python 3.8. - The
az iot ops secretsync enablenow raises an error (instead of a warning) if the logged-in principal lacks permission to assign roles between a user-assigned managed identity and the target Key Vault.
New Features
-
CLI now supports deployment of
AIO 2506. -
az iot ops initincludes a new optional--check-clusterflag to validate minimum deployment requirements. -
Introduced new dataflow endpoint command groups
az iot ops dataflow endpoint createandaz iot ops dataflow endpoint updatesupportingadls,adx,custom-kafka,custom-mqtt,eventgrid,eventhub,fabric-onelake,fabric-realtime,local-mqtt, andlocalstorage. -
Added
az iot ops dataflow applyandaz iot ops dataflow deletecommands. -
Introduced
az iot ops rsynccommand group for post-deployment edge-to-cloud resource hydration adding the following commands:az iot ops rsync enableaz iot ops rsync disableaz iot ops rsync list
-
az iot ops upgradenow uses provisioning state to determine if re-application of the same version is needed. -
Enhanced
az iot ops connector opcuawith certificate validation. -
az iot ops secretsync enablenow supports--tagsand--custom-role-id. -
az iot ops support create-bundlenow allows custom bundle names via--bundle-name. -
az iot ops schema registry createnow supports skipping role assignment with--skip-ra. -
Deprecated
--enable-rsyncinaz iot ops createin favor ofaz iot ops rsync enable.
General
- Minimum Azure CLI version required is now
2.62.0.
2504 Update
AIO2504 (v1.1.19) Release Notes
MQTT Broker
- Fixes
- Fixed issue that sometimes disconnects subscribers with persistent sessions erroneously
Dataflows
- Fixes
- Fixed issue where data flows may encounter errors sending messages to Kafka destinations if there's mismatched producer ID when network disruption occurs.
- Fixed issue that resulted in disconnections when using control characters in Kafka headers.
Unified AIO Arc Extension
- New Features
- Selectively deploy Preview Features: Users can now opt in to selectively deploy new Azure IoT Operations features (such as Onvif and Media Broker Connectors) that are in public preview.
- Fixes
- AIO Update bug: Resolved a known issue that could cause Azure IoT Operations updates to get stuck.
Akri
- New Features
- OPC UA Asset Detection: OPC UA Asset Detection is now available in public preview! Simply create an Asset Endpoint Profile and the OPC UA connector will detect the associated Discovered Assets with Akri. From there, you can modify and review before importing it as an Asset into the Azure Device Registry. This allows for a much more seamless Asset onboarding experience through our Azure IoT Operations Experience portal.
- General
- Vulnerability fixes and security improvements.
Azure Portal
- New Features
- Support for additional data flow profiles: Users can now create and manage additional data flow profiles (after configuring the default during instance deployment).
- Selective deployment of components: Users can now optionally choose to enable/disable preview components, such as the ONVIF and media connectors. They can do this during or after instance deployment.
- Fixes
- Various bug fixes and performance improvements: The user experience is now more intuitive, seamless, and secure.
Azure IoT Operations Experience
- New Features
- [Public Preview] Automatic asset discovery: Users can now automatically discover OPC UA assets and tags for more streamlined and accurate onboarding. In doing so, they can browse available assets and tags.
- Support for additional data flow profiles: Users can now leverage additional data flow profiles to configure their data flows, tailoring them to specific use cases and operational requirements.
- Import/export functionality: Users can now import/export assets, asset endpoints, data flows, and dataflow endpoints for more flexible and efficient resource management.
- Automatic schema generation: Users no longer need to upload output schemas for storage-based data flow endpoints, such as Azure Data Lake Storage v2 and Azure Data Explorer. These schemas are now automatically generated.
- Fixes
- Various bug fixes and performance improvements: The user experience is now more intuitive, seamless, and secure
Media Broker
- Fixes
- Resolved the issue of insufficient output for clips being saved to the file system in certain cases.
ADR and Schema Registry
- New Features
- Onboarded as a trusted Microsoft service, enabling customers to securely connect the Schema Registry with their Azure Storage account without exposing a public endpoint
Azure IoT Operations CLI
- New Features
- Updated deployment: Users can now deploy the latest version of AIO through the init and create commands.
- Selective deployment of components: Users can now optionally choose to enable/disable preview components, such as the ONVIF and media connectors. They can do this during or after instance deployment via --feature parameter. A single config key is supported for this: connectors.settings.preview.
- MQTT broker configuration: Users can now leverage the following new commands to manage listener, authentication (authn), and authorization (authz) configurations of an instance's MQTT broker:
- az iot ops broker listener apply
- az iot ops broker listener port add
- az iot ops broker listener port remove
- az iot ops broker authn apply
- az iot ops broker authn method add
- az iot ops broker authz apply
- Auto-derived OPC UA cert parameters: Users no longer need to provide the --application-uri or --subject-name parameters to the connector opcua client add command, as they will be automatically derived from the target certificate. These parameters are now optional, so, if provided, they will be used for validation.
- Improved support bundle: Every support bundle now captures data from AIO Observability, a new component that streamlines the flow of observability data for AIO. Conversely, it no longer captures data from Open Service Mesh or the OPC UA connector assettype custom resource.
- Fixes
- Various bug fixes and performance improvements: The user experience is now more intuitive, seamless, and secure.
Identity
- New Features
- Custom roles: Documentation has been added to facilitate customers to build and assign custom roles for role-based access for AIO features.
Certificate Management
- New Features
- Auto-derived OPC UA cert parameters: Through Azure CLI, users no longer need to provide the --application-uri or --subject-name parameters to the connector opcua client add command, as they will be automatically derived from the target certificate. These parameters are now optional, so, if provided, they will be used for validation.
2503 Update
Release Notes
Bug fixes, performance improvements and security updates.
2502 Update
Release Notes
Bug fixes, performance improvements and security updates.
2501 Update
Release Notes
Bug Fixes and Security Updates.
2411 Update
Release Notes
Azure IoT Operations and Azure Device Registry: Now Generally Available
Azure IoT Operations enables customers to collect edge data, process it, and transfer it to the cloud. Following the adaptive cloud approach, all controls for data collection, processing, and transfer are managed through configuration interfaces located alongside the customer's cloud service interfaces. Once configured, Azure IoT Operations sends processed data to cloud data services like Microsoft Fabric, making it accessible in the common data lake that supports the company's data estate. Learn more
To support Azure IoT Operations, Azure Device Registry is an integral product offering that enables asset management.
v0.8.32
Release Notes
MQTT Broker
- New Features
- Added feature to help prevent inadvertent service name conflicts which lets you leave a BrokerListener's serviceName as null, and the service name will automatically be set to match the name of the BrokerListener instead of a static value.
- Add support for version upgrades.
- Fixes
- Fixed issue where updating a broker listener doesn't work.
- Fixed issue where generating resource requests like CPU limit wasn't working properly.
- General
- Added support for Kubernetes admission webhook to help avoid inadvertent misconfiguration.
Dataflows
- New Features
- Added support for version upgrades.
- Fixes
- Fixed issue where you can't use anonymous authentication for MQTT and Kafka endpoints when deploying dataflow endpoints via the portal.
- Fixed issue where it was possible to set empty values for dataSource and dataDestinations which led to crashes.
- Fixed issue where client ID prefix wasn't working.
- Fixed issue where MQTT messages were limited to 10KB in size as opposed to the correct 256MB.
- Fixed issue where updating a dataflow with new source MQTT topics didn't work properly.
- Fixed issue where scaling up or down a dataflow profile via instance count resulted in unexpected message loss or duplication.
- General
- Added support for Kubernetes admission webhook to help avoid inadvertent misconfiguration.
Unified AIO Arc Extension
- Breaking Changes
- The AIO instance resource has a breaking change in this release from the last release. Specifically, the schema registry parameter has changed in the AIO RP version 2024-09-15-preview from
schemaRegistryNamespacetoschemaRegistryRef { resourceID:.}
- The AIO instance resource has a breaking change in this release from the last release. Specifically, the schema registry parameter has changed in the AIO RP version 2024-09-15-preview from
- New Features
- Upgrade: AIO can be upgraded in place from the previous version (0.7.x) to this version (0.8.x) using the AIO CLI.
- Fixes/General
- Implemented various bug fixes to enhance stability and performance.
Akri
- Fixes
- Metrics TLS and fixes
- Security fixes and updated dependencies
- General
- Automatic asset discovery is NOT being deprecated - it will return with a new and improved version in the next refresh.
- Note: You will still see Akri deployed on your cluster as a part of Azure IoT Operations.
Azure Portal
- New Features
- Upgrade AIO: Upgrade to the latest version without the need for redeployment.
- Dataflow list: Read-only views.
- Instance Overview: Display metrics of instance resources for better monitoring.
- Cluster type selection: Choose between single node and multi-node configurations with recommended settings.
- Fixes/General
- Implemented various bug fixes to enhance stability, performance, and user experience.
Azure IoT Operations Experience
- New Features
- Instance overview: View details of an IoT Operations instance.
- New data transform operations: Rename datapoints in and/or add new properties to a dataflow.
- New storage-based dataflow endpoints: Connect dataflows to storage-based endpoints, including Azure Data Explorer, Azure Data Lake Storage (2nd generation) and local storage.
- Fixes/General
- Various bug fixes and performance improvements
ADR and Schema Registry
- New Features
- Outbound proxy support
- Improved reliability and resiliency
- Security improvements
- Arc Gateway support
- Outbound proxy support
Azure IoT Operations CLI
- New Features
- Support a new command
upgradeto perform in-place upgrade from M2 builds - Ability to inject certificate when creating Asset endpoint profile with OPC UA
- Support a new command
- General
- Schema registry parameter changes from the last release. (Schema registry ID param
--sr-resource-idnow part ofcreate)
- Schema registry parameter changes from the last release. (Schema registry ID param