Kubesense

Single Subscription Setup

Connect one Azure subscription to KubeSense for read-only inventory and Azure Monitor metrics.

Before you start

Complete the collection setup first: an App Registration with Reader and Monitoring Reader on the subscription, and its tenant ID, client ID and client secret value to hand.

Use this path for one subscription, or a few you would rather add by hand. If your estate spans many subscriptions, Multi-Subscription Setup enrols them automatically instead.

Connect the subscription

Settings → Integrations → Azure → Add New Azure Account → Single Subscription:

FieldWhat to enter
NameA friendly label for this subscription in KubeSense, e.g. azure-prod.
Azure Subscription IDThe subscription GUID from the portal.
Directory (Tenant) IDYour Entra ID tenant GUID.
Application (Client) IDFrom the App Registration.
Client Secret ValueThe Value, not the Secret ID. Stored encrypted and never displayed again.
Default Azure RegionA region slug such as eastus. A label only — see the note below.
Collection SettingsWhich services to collect, and how deep.

Select Connect. KubeSense verifies the credential immediately — it reads the subscription from ARM — and the next screen reports success or the exact error Azure returned.

About Default Azure Region: Unlike some clouds this does not narrow what is collected: ARM lists resources across the whole subscription regardless. It is a label, used as the fallback region for a resource that does not report one of its own.

Every resource type starts disabled: A subscription connected with nothing selected authenticates correctly and then collects nothing — which reads as broken rather than unconfigured. Choose your resource types on this screen; you can change them at any time from the integration's settings, and a change takes effect on the next collection cycle.

This path requires a client secret — both the client ID and secret are mandatory here — so workload identity is selectable only on the Multi Subscription path. You can still use it for a single subscription by naming just that one subscription there.

Verify

  1. The credential resolves. The screen after Connect reports this, and the message on failure is Azure's own.
  2. Resources appear. Open the integration from Settings → Integrations → Azure. Within a minute or two it shows a count per resource type.
  3. Metrics arrive. Allow up to 10 minutes for the first metric cycle, then open any discovered resource and confirm its charts are populated.

Troubleshooting

SymptomLikely causeAction
"Azure rejected these credentials"The secret is wrong or expired, or the tenant ID belongs to a different tenant than the App RegistrationConfirm you copied the secret's Value, not its Secret ID
Connected, but nothing is collectedNo resource types selectedOpen the integration's settings and enable the types you want
Resources appear but their charts are emptyMonitoring Reader is missing on that subscriptionReader alone lists resources but cannot read metrics
An AKS cluster appears but has almost no metricsExpected — cluster-level metrics from Azure Monitor are deliberately fewDeploy the KubeSense sensor to that cluster for in-cluster depth
Everything worked, then collection stoppedThe client secret expiredCreate a new secret on the App Registration and update the integration