Repository navigation
Releases: Azure/azure-iot-operations
Release list
v0.7.31
Release Notes
OPC UA Connector
- New Features
- Schema registry
- Support for Cloud Events
MQTT Broker
- Breaking Changes
BrokerAuthenticationconfiguration syntax updated.- Added "settings" suffix to each method configuration object name.
x509Credentialsrenamed tox509Settings.
- New Features
- Support for configuration via Azure portal.
- Fixes
- Fixed issue preventing
BrokerAuthenticationdeployment via ARM. - Fixed bugs in
BrokerListenerconfiguration preventing certain advanced cert-manager properties.
- Fixed issue preventing
- General
- New default service name:
aio-broker. - New pod names:
aio-broker-frontend-0andaio-broker-backend-0. - New default broker listener port: 18883 for AIO internal communication to vacate common user ports 1883 and 8883, avoiding conflicts or misconfiguration.
- New Kubernetes service account audience:
aio-internalfor default broker authentication, used by other AIO components. - Performance improvements.
- New default service name:
Dataflows
- Breaking Changes
- CRD and ARM API; fields renamed
- Integration
- Schema registry for reserialization and transformation.
- New Features
- Configuration via IoT Operations Experience portal.
- Sending data to Fabric OneLake, ADLSv2, and Azure Data Explorer.
- Use MQTT message properties in map transformations.
- Get last-known-value in transformations.
- Compatibility with Cloud Events attributes.
- Auto-determine system-assigned managed identity audience.
- Use user-assigned managed identity with dataflow endpoints via workload identity federation.
- Default Settings
- Auto-generated
DataflowEndpoint(nameddefault) with each AIO deployment. - Default
DataflowProfilerenamed todefault.
- Auto-generated
- Fixes
- Deploying dataflows via ARM.
- Clarified supported authentication methods for each endpoint type.
- Authentication configuration moved inside endpoint-type-specific settings (e.g.
mqttSettings). - Scaling up instance count beyond 1.
- Default values for MQTT endpoint types to built-in MQTT broker.
- General
- Performance improvements.
Akri
- Breaking Changes
- Removed Akri agent and UDF discovery support where Akri instance
akriiCRs are created for discovered OPC UA assets. - Discovered Asset and Discovered Asset Endpoint Profile using mPRC (the end-to-end flow is not yet supported).
- Removed Akri agent and UDF discovery support where Akri instance
- General
- Automatic asset discovery is NOT being deprecated - it will return with a new and improved version in the next refresh.
- Note: You will still see Akri deployed on your cluster as a part of Azure IoT Operations.
Unified AIO Arc Extension
- New Feature
- Ability to upgrade has been implemented in this release - Customers will be able to upgrade to the next version of the AIO arc extension without needing to redeploy everything.
- Integration of Cert manager and Trust Manager for setting up secure communications internally among pods and between pods and external endpoints.
Azure Portal
- New Features
- AIO Install/Deployment based on customer need.
- "Test Setting": Simpler deployment for testing purposes.
- "Secure Setting": Deployment for production use cases, includes support for User Assigned Managed Identity and Secret management.
- Ability to select an existing schema registry or create a new one from the AIO Install wizard.
- Optional dependencies deployment
- MQTT: listeners, authentication and authorization
- AIO Install/Deployment based on customer need.
- Breaking Changes
- CLI command changes in portal automation screen for Edge Storage Accelerator (ESA), Schema registry, Workload identity federation, and
az iot ops initvscreate.
- CLI command changes in portal automation screen for Edge Storage Accelerator (ESA), Schema registry, Workload identity federation, and
Azure IoT Operations Experience
- New Features
- Dataflows - A dataflow can subscribe to an MQTT topic and forward the messages to an event hub in your Azure Event Hubs namespace.
- Integrate with Schema Registry RP and use Schema Registry ARG.
- Dataflow Endpoints - A dataflow endpoint is the connection point for the dataflow.
- Dataflow Endpoints – access token AKV and Azure Secret Store integration.
- Breaking Changes
- Asset endpoint profile – username/password AKV and Azure Secret Store integration.
ADR and Schema Registry
- New Features
- Schema Registry
- Synchronization of message schemas between cloud and edge.
- Ability for OPC UA Connector to store message schemas in Schema Registry.
- Ability for Dataflows to consume message schemas in dataflows.
- Ability for upload user-generated message schemas in Operations Experience.
- Ability to author Dataflows with schemas in Operations experience.
- Asset and Asset Endpoint Profile
- Added reference to message schemas.
- Ability to define dataset.
- Add ability to set MQTT topic and retain flag on a per asset, and per dataset basis.
- Schema Registry
- Breaking changes
- Changes to Asset + Asset Endpoint Profile ARM & CR field names and structure.
Azure IoT Operations CLI
- New Features
- Deployment of Azure IoT Operations are now broken into two phases:
- Deploy AIO dependencies via
init - Creation of AIO instance via
create
- Deploy AIO dependencies via
- Updated
deleteto delete AIO instances by default created bycreate, append--include-depsflag to undoinit. - Added
identitycommand group for general management of workload identity. - Added
secretsynccommand group for secret sync configurations of Azure IoT Operations instance. - Added
data flowtocheckcommand.
- Deployment of Azure IoT Operations are now broken into two phases:
Identity
- New Features
- Support of User Assigned Managed Identity for northbound connections.
Secret Management
- New Features
- Ability to automatically sync secrets from Azure Key Vault down to edge using Operations Studio.
- Ability to use secrets for southbound and northbound connections.
- Ability to delete synced secrets from edge.
- Ability to add new synced secrets to edge.
Validated Environments
- This release has been validated on the latest September update of AKS Edge Essentials (version 1.8.202.0).
v0.6.0-preview
Release Notes
OPC UA Broker
- Bug fixes and security improvements
- Reduced memory load by optimizing logging by OPC UA Stack
- Reduced memory consumption during DTDL generation
MQ
Broker CR Updates
- Removed Diagnostic service CR, and consolidated all Diagnostic settings in the Diagnostic section.
- Created a new "advanced" settings section with new settings for MQTT subscriptions, internal traffic encryption, and node tolerations.
- Removed temporary resource limits section, and moved some of those settings to the "advanced" settings section.
- Container image fields are no longer mandatory.
BrokerListener CR Redesign
- Now supports multiple ports per listener, functioning similarly to a Kubernetes service.
Authentication Changes
- BrokerAuthentication CR now allows direct inline specification of X.509 attributes, eliminating the need for a TOML file.
- Discontinued username/password authentication.
- Immediately disconnect clients with expired credentials.
Authorization Updates
- Revised BrokerAuthorization CR syntax for State store authorization configuration.
- Removed support for AKV CSI driver extension.
Dataflows
- New component that replaces the previous cloud connector with additional data processing features.
- Transformations can be applied within dataflow to process the message payload, with capabilities including compute new properties, rename properties, remove properties, convert units, standardize values, and contextualize data.
- Configurable via custom resource YAML files.
- Endpoints supported: MQ (MQTT broker), Azure Events Grid, Azure Events Hub, Fabric Real-time. Note: support for sending data to ADX, ADLSv2, and Fabric OneLake are not available in this release. Support for these endpoints will be added back in an upcoming preview release.
Unified AIO Arc Extension
- Introduced a new Azure resource type called "instance" that represents the bundle of Azure IoT Operations services that are installed in the cluster.
- Introduced a single AIO arc extension in lieu of separate service arc extensions for each AIO component. This arc extension installs a unified controller that is responsible for monitoring and acting on the Azure IoT Operations instance custom resource.
Azure IoT Operations Experience
- Activity Logs are available to view at the instance level or for a specific asset, asset endpoint, or data pipeline.
Azure IoT Operations CLI
- Detailed release notes, describing features, fixes, and improvements are available in the Azure IoT Operations CLI Extension Releases.
Validated Environments
- This release has been validated on the latest AKS-EE release version 1.7.639.0 and K3s 1.28.3. View AKS-Edge releases here: AKS-Edge Releases.
Known Issues
Detailed list of known issues are available in the Azure IoT Operations public documentation
v0.5.1-preview
This release makes Data Processor an optional component. By default, the az iot ops init command doesn't deploy the Data Processor component. To deploy Data Processor, add the --include-dp argument.
v0.5.0-preview
Release notes
MQ:
- Added support for MQTT over Websockets
- Bug fixes and stability improvements
Cloud connector:
- Added support for sending to Azure Data Explorer
OPC-UA Broker, Data Processor and AKRI:
- Bug fixes and stability improvements
Azure IoT Operations Portal:
-
Streamlined navigation experience to specific sites and across multiple sites
-
Improvements to maintain context through long running operations
Azure IoT Operations CLI:
- Detailed release notes, describing features, fixes and improvements are available in the CLI github repo.
v0.4.0-preview
Release notes
This update implements logging and transmission functionalities for non-personal logs, facilitating proactive health investigations.
Data Processor:
- Dependency on NFS has been removed, users no longer need to install NFS on their host machines before deployment.
- Support for Managed Identity based authentication has been added to MySQL source and Fabric Lakehouse, Azure data explorer destination.
- Ability to read from Influx DB.
- Ability to write to an HTTP endpoint as a destination.
- Ability to write to Azure Blob Storage.
- Ability to configure retries within pipeline.
OPC UA Broker:
- The intermittent token expiration issue has been fixed.
- ARC extension has been added.
- Support for enterprise grade certificate management.
- Topic structure for telemetry has changed. Telemetry of an Asset is now published in topic "azure-iot-operations/data/
Digital Operations Experience:
- Support for Asset Metadata/custom properties.
- The intermittent token expiration issue has been fixed.
- Internationalization support: Users can customize UI with their language preference
Validated Environments
- This release has been validated on latest AKS-EE release version AksEdge-K3s-1.26.10-1.6.384.0
v0.3.0-preview
Release Notes
AIO Arc Extension:
- Support for outbound proxy has been added to Azure IoT Operations arc extension.
Data Processor:
- Support for outbound proxy has been added to Data processor arc extension.
Azure CLI:
- Added deployment pre-checks to reduce deployment failures.
Digital Operations Experience:
- UX improvements
- Logs and metrics improvements
- Support of different AIO Extension versions
v0.2.0-preview
Release Notes
Data Processor:
- Service account token expiration causing data communication loss between MQ and data processor has been fixed.
MQ
- The issue of service account token expiration, which caused a loss of connection between IoT MQ and other pods, has been resolved.
- These observability metrics are now available:
- aio_mq_backend_replicas
- aio_mq_backend_replicas_current
- aio_mq_frontend_replicas
- aio_mq_frontend_replicas_current
OPC-UA Broker
- Akri OPC UA asset discovery now works on the first run after AIO deployment.
- Deletion and modification of assets in the Digital Operations Experience portal works as expected.
- Telemetry encoding does not switch to gzip occasionally.
v0.1.0-preview
Overview:
Azure IoT Operations is a suite of Azure Arc-enabled Kubernetes services that provide wide-ranging and secure functionality. Azure IoT Operation enables:
- Workload orchestration with simplified deployment, configuration, and management on the Arc Enabled Kubernetes clusters from the cloud.
- Projection and management of industrial assets on the Edge as Azure-native resources in the cloud.
- Simplified and secured real-time data transfer from OPC-UA servers using an industrial grade OPC-UA broker.
- Spec-compliant MQTT data plane via an industrial-grade, distributed and scalable broker.
- North-bound cloud data plane connectors that enable bi-directional or uni-directional data flow from the edge broker to services like Azure Event Hub (Kafka), Azure Event Grid MQTT, and Azure Data Lake storage.
- Seamless support for Dapr programming model (pub/sub and statestore) to integrate custom workloads like ML inferencing, interface with existing databases etc.
- Read raw data from various data sources and assets, normalize and contextualize in near real time. Write the clean data to various edge and cloud destinations to obtain true value out of industrial data.
- Manage assets, subscribe to asset data, and configure your data processing pipelines from Azure cloud using Azure IoT Operations experience.
- Secure communication between devices and the cloud through isolated network environments based on the ISA-95/Purdue Network architecture.
- Upload clean data to Microsoft Fabric and get insights using a wide variety of big data platforms in the cloud.
- Discovery of devices and data sources at the edge which are exposed as resources in your local cluster namespace using Akri.
- Observability of the platform health and metrics through curated dashboards.
Release Notes:
- Integration with Azure key vault for seamless secret management.
- Ability to ingest data from Microsoft SQL Server & HTTP Endpoint.
- Ability to configure asset events from Azure IoT Operations experience, a flexible and efficient way to signal state changes and lay foundation for alarm systems.
- Ability to manage and create asset endpoint profiles, includes OPCUA server metadata, user/secret, and server transport certificate references, from the Azure IoT Operations experience.
- Ability to paginate in Azure IoT Operations experience pages that contain lists.
- Ability to view asset details from Azure portal.
Validated Environments
Azure Iot Operations ships as a set of Azure Arc-enabled Kubernetes services and is intended for use with CNCF conformant Arc validated partner products. Currently, Microsoft has validated Azure IoT Operations against the following fixed-set of infrastructures and environments:
| Environment | Version |
|---|---|
| AKS-EE on Windows 11 IoT Enterprise on a single-node AMD Ryzen-7 (8 core, 3.3 GHz), 16-GB RAM | AksEdge-K3s-1.26.6-1.4.109.0 |
| K3s on Ubuntu 22.04.2 on a single-node AMD Ryzen-7 (8 core, 3.3 GHz), 16-GB RAM | K3s version 1.27.3 |
See also the Azure Arc-enabled Kubernetes system requirements.