---
title: Deployment of Litmus Edge Manager on Azure Kubernetes Service (AKS)
slug: edgemanager/deployment-of-litmus-edge-manager-on-azure-kubernetes-service-aks
docTags: 
createdAt: 2025-09-02T20:41:37.898Z
---

You can deploy Litmus Edge Manager on **Azure Kubernetes Service (AKS)**. You deploy with the following steps:

- [Step 1: Set up your AKS Cluster](docId:8RhqJWbbMvu1pTv95zfjj)
- [Step 2: Connect to Your Cluster](docId:8RhqJWbbMvu1pTv95zfjj)
- [Step 3: Execute Kubectl and Helm Commands](docId:8RhqJWbbMvu1pTv95zfjj)
- [Step 4: Upgrade the Helm Chart](docId:8RhqJWbbMvu1pTv95zfjj)
- [Step 5: Access the Litmus Edge Manager UI using the obtained IP address](docId:8RhqJWbbMvu1pTv95zfjj)

# Before You Begin

Before you begin, make sure that you have:

- A valid [Microsoft Azure](https://azure.microsoft.com/en-us/pricing/purchase-options/azure-account) subscription with permissions to create and manage Kubernetes clusters. See the [Azure Kubernetes Service (AKS)](https://learn.microsoft.com/en-us/azure/aks/) documentation for more details.
- Familiarity with the [Azure Portal](https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-overview) and [Azure CLI](https://learn.microsoft.com/en-us/cli/azure/?view=azure-cli-latest).
- Installed [Azure CLI](https://learn.microsoft.com/en-us/cli/azure/install-azure-cli?view=azure-cli-latest) on your local machine.
- Installed [HELM CLI](https://helm.sh/docs/intro/install/) and [kubectl](https://kubernetes.io/docs/tasks/tools/install-kubectl-linux/) on your local machine.
- Available Litmus Google registry credential key file (for example, `LEM_pull_Key_file.json`).

# Minimum Virtual Machine Requirements

You can meet virtual machine requirements using a single node or multiple smaller nodes. Recommended specifications for production environments depend on your individual use cases.

The minimum virtual machine (VM) requirements are:

- Recommended node size: 8 CPU and 20 GB memory
- Storage Configuration: 100 GB local storage
- Suggested node pool strategy:
  - Single node, for example Standard\_D8s\_v3 or Standard\_D8as\_v\*
  - Multi-node with smaller nodes where combined resources meet or exceed 8 CPU cores and 20 GB RAM






# Step 1: Set up your AKS Cluster in your Azure Portal account

1. Log in to your Azure account.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/-w6tANuXEHbLZujPrcANO_image-20250818-164218.png" size="80" width="1933" height="947" position="flex-start" showCaption="false" indent="2"}

2. Open Azure Kubernetes Service.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/6OJSgOXebfHUDgZh8WBRw_image-20250818-164402.png" size="80" width="1247" height="627" position="center" showCaption="false" indent="2"}

3. Select your subscription and plan: **Azure Kubernetes Service (AKS)**. Click **Create**.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/UXZGgxAIIbuKW2Oqwxam9_image-20250818-164736.png" size="80" width="1400" height="783" position="flex-start" showCaption="false" indent="2"}

4. In **Create Kubernetes cluster** > **Basics**, set the following:
   - **Subscription**
     Your subscription is selected already.
   - **Resource Group&#x20;**&#xA;Create a new resource group to contain the cluster resources.
   - **Cluster preset configuration**
     Select `Dev/Test`.
   - **Kubernetes cluster name**
     Set any desired name for the cluster.
   - **Region**
     Set any or `(US) East US`.
   - **Kubernetes version**
     Set any or `1.32.6 (default)`.
   - **Authentication and Authorization**
     Local accounts with Kubernetes RBAC.
   - **Other options**
     Leave default values or modify as required.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/cU-EqtOymRf7PXgYV9YIb_image-20250818-170252.png" size="80" width="1245" height="1163" position="flex-start" showCaption="false" indent="3"}

5. In the **Node Pools** tab:
   1. Confirm that the `agentpool` node pool is created for you already.
   2. Make sure the node pool is using `Ubuntu Linux` and the minimum node count is `2`.
   3. Optionally, create a custom node pool by clicking on **Add node pool**.
      **Note:&#x20;**&#x50;ay attention to the `maximum `node count. The deployment will fail if this is set to `2` and the **Max pods per node** is set to `40` or below. In this case, the cluster would need an additional node (3) to distribute all the pods.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/Fu5m0bdsyboVobtG7hI-R_image-20250818-171738.png" size="80" width="1041" height="997" position="flex-start" showCaption="false" indent="3"}

6. Set the following in the **Networking** tab:
   - **Enable private cluster**
     Leave this unselected.
   - **Set authorized IP ranges**
     Leave this unselected.
   - **Network configuration**
     Azure CNI Overlay.
   - **DNS name prefix**
     Set your custom DNS name prefix.
   - **Network policy**
     None or modify is needed.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/G71_2vkCi0dRaR92V8wdZ_image-20250815-130041.png" size="80" width="1406" height="1035" position="flex-start" showCaption="false" indent="3"}

7. In the **Integrations** tab, use the default values.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/IQSuay_7tpaH4qEpfZ-jp_image-20250819-072905.png" size="80" width="1156" height="876" position="flex-start" showCaption="false" indent="2"}

8. In the **Monitoring** tab:
   1. Select **Enable Prometheus metrics**.
   2. **Azure Monitor workspace**
      Your workspace is already selected.
   3. Select **Enable recommended alert rule**.
   4. **Alert rules**
      Review details and confirm the email for alerts.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/fH7H1B8yKqgvlUjz6j54k_image-20250819-073634.png" size="80" width="1156" height="876" position="flex-start" showCaption="false" indent="3"}

9. Use the default values in the **Security** and **Advanced** tabs.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/u3KJCfure0xXDCSrha-b-_image-20250819-073855.png" size="100" isUploading="false" width="1057" height="878" showCaption="false" indent="2"}

10. In the **Tags** tab:
    1. Add your tags as desired.
    2. Add the tags to all resources.
    3. Click **Review + create**.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/XctgWSbIhuiaREpu7wsEW_image-20250819-074630.png" size="100" width="1200" height="878" darkWidth="800" darkHeight="585" position="flex-start" showCaption="false" indent="3"}

11. In **Review + create**:
    1. Review your settings.

:::hint{type="info" indent="3"}
**Note:** Double-check the following minimum VM requirements:

- The nodes use Ubuntu Linux OS
- Architecture is AMD64
- VM: 8 CPU cores and 20 GB Memory
:::

:::Paragraph{listStyleType="decimal" listStart="2" indent="2"}
Ensure that the validation passes.
:::

:::hint{type="info" indent="3"}
**Note**: If you see `Validation failed. Required information is missing or not valid.` return to that tab and add or correct the required information.
:::

:::Paragraph{listStyleType="decimal" listStart="3" indent="2"}
Click **Create**.
:::

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/aRGOjhP2ZpLiLpE-I3wG6_image-20250819-075005.png" size="100" width="1081" height="294" darkWidth="800" darkHeight="217" position="flex-start" showCaption="false" indent="3"}

:::hint{type="info"}
**Note:** Creating a cluster takes a few minutes depending on the settings you choose. Check the status or notifications for the latest information about your cluster.
:::

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/Kw6bTKEUhnV7WMfqjyGp1_image-20250819-075710.png" size="80" width="1489" height="882" position="flex-start" showCaption="false"}

# Step 2: Connect to Your Cluster

Open your terminal and log in with Azure CLI.

1. In the Terminal window, type in `az login`.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/GX8L2YvIJR5ZM-cxjAQ8H_image-20250819-084832.png" size="80" width="1075" height="755" position="flex-start" showCaption="false" indent="2"}

2. In the **Auth UI dialog**, select the Microsoft Azure account that has access to the AKS service. Enter your credentials.
3. In the Terminal window, select a subscription and tenant. Make sure you select the subscription where your AKS cluster is created.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/GPMRv3wGbnYfTEPDBMmty_image-20250819-084549.png" size="80" width="1463" height="310" position="flex-start" showCaption="false" indent="2"}

Next, connect to your cluster.

1. Open the Azure portal and navigate to **Kubernetes services**.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/YFvfFK8lOgkI95egGhtIJ_image-20250819-085204.png" size="100" isUploading="false" width="1669" height="601" showCaption="false" indent="2"}

2. In **Kubernetes services**, select your cluster.
3. In the cluster page, click **Connect**.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/EHIXurITiwYM6hdg-4pX3_image-20250819-085829.png" size="80" width="1879" height="774" position="flex-start" showCaption="false" indent="2"}

4. In the **Cloud shell** tab, copy the second command:

:::CodeblockTabs{indent="2"}
```bash
az aks get-credentials --resource-group <my-resource-group> --name <my-dev-cluster> --overwrite-existing
```
:::

5. In the Terminal window, paste the command with updated values for `<my-resource-group>` and `<my-dev-cluster>`.
6. Submit the command.

You should see similar output in your terminal:

:::BlockQuote
Merged "my-dev-cluster" as current context in C:\Users\user\\.kube\config
:::

The cluster setup is now complete.

# Step 3: Execute Kubectl and Helm Commands in your Terminal

In this section you create an `lem` namespace and pull secret, configure the load balancer and install Helm.

1. Create an `lem` namespace.

:::CodeblockTabs{indent="2"}
```bash
kubectl create ns lem
```
:::

2. Create a pull secret. Change the command accordingly based on the location of your pull key file on the local machine.

:::CodeblockTabs{indent="2"}
```bash
kubectl create secret docker-registry lem-helm-secret \
--docker-server=us-east1-docker.pkg.dev \
--docker-username=_json_key \
--docker-password="$(cat LEM_pull_Key_file.json)" -n lem
--docker-email=any@email.com -n lem
```
:::

3. Next specify values to configure the load balancer, where:
   - `lem.platform: aks` specifies the AKS annotation set.
   - `lem.loadbalancer.internal:` true or false specifies whether the chart injects the AKS `internal LB` annotation.
   - `lem.loadbalancer.ip.frontend` and `.remote` enable you to assign static IPs for the two LB services (nginx + remote).

:::CodeblockTabs{indent="2"}
```bash
# values-aks.yaml
lem:
  platform: aks
  loadbalancer:
    internal: false        # set true for internal/private LB
    ip:
      frontend: ""         # optional: reserved static IP for nginx LB
      remote: ""           # optional: reserved static IP for UDP 51820 LB
```
:::

4. Install Litmus Edge Manager using the following command, where `<lemversion>` is the LEM version that you are installing, for example `--version 2.31.0`

:::CodeblockTabs{indent="2"}
```bash
helm install lem oci://us-east1-docker.pkg.dev/litmus-public/lem-chart-ga/lem \
  --version <lem_version> \
  -n lem \
  -f values-aks.yaml
```
:::

:::hint{type="info"}
**Note:&#x20;**

- The command initiates the pull of the required container images. This process may take several minutes.
- Make sure the secret name is `lem-helm-secret` and that you don’t override it with `--set "imagePullSecrets[0].name`.
- After the deployment is completed, wait approximately five minutes before applying the Litmus Edge Manager (LEM) URLs and credentials.
- Instructions for accessing these URLs and credentials print for you in the console.
:::

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/XJtWQ91VOhu2v1sMQ8JzV_image-20250819-110531.png" size="80" width="1788" height="581" position="flex-start" showCaption="false"}

To get URLs and credentials for Litmus Edge Manager:

1. In case you need URLs and credentials after the deployment, execute the following:

:::CodeblockTabs{indent="2"}
```bash
helm get notes lem -n lem
```
:::

2. To get Litmus Edge Manager's external IP, run the following, where `<release_name>-nginx` is your service name:

:::CodeblockTabs{indent="2"}
```bash
kubectl get svc lem-nginx -o jsonpath='{.status.loadBalancer.ingress[0].ip}' -n lem
```
:::

3. To get the LEM username and password, run:

:::CodeblockTabs{indent="2"}
```bash
# username
kubectl get secret --namespace lem lem-secret -o jsonpath="{.data.lem-user}" | base64 --decode

# password
kubectl get secret --namespace lem lem-secret -o jsonpath="{.data.lem-password}" | base64 --decode
```
:::

# Step 4: Upgrading the Helm Chart

If you are upgrading Litmus Edge Manager to a new version, first upgrade the Helm chart.

1. Before the upgrade, scale down Prometheus:

:::CodeblockTabs{indent="2"}
```console
kubectl -n lem scale deployment lem-prometheus-server --replicas=0
```
:::

2. If upgrading from a version before 2.31.1, delete EMQX resources:

:::CodeblockTabs{indent="2"}
```console
kubectl -n lem delete statefulset lem-emqx
kubectl -n lem delete configmap lem-emqx-acl
kubectl -n lem delete configmap lem-emqx-env
kubectl -n lem delete configmap lem-emqx-loaded-modules
kubectl -n lem delete configmap lem-emqx-loaded-plugins
kubectl -n lem delete service lem-emqx
kubectl -n lem delete service lem-emqx-headless
```
:::

3. Run the Helm upgrade. Use the actual chart version instead of the `<LEM_VERSION>` placeholder.

:::CodeblockTabs{indent="2"}
```console
helm upgrade lem oci://us-east1-docker.pkg.dev/litmus-public/lem-chart-ga/lem --version <LEM_VERSION> --namespace lem
```
:::

4. After the upgrade, scale Prometheus back up:

# Step 5: Access the Litmus Edge Manager UI using the obtained IP address

See [Access Litmus Edge Manager](docId\:w3uHZQ4tSrH7OLjhuLt0A) for details.

:::hint{type="info"}
**Note:** Get the Site License key from your Litmus account executive to activate your license.
:::

Litmus Edge Manager is now deployed and operational on your AKS cluster. You can now access the manager’s UI using the external IP address and perform any additional configuration through the admin console, such as license activation.
