az - Azure command-line interface
az <group> [<subgroup>...] <command> [--resource-group/-g RG] [--name/-n NAME] [--output/-o FORMAT] [--query JMESPATH] [--subscription SUB]
Options you will use
-o, --output FORMAT- json (default, keys sorted), jsonc, table, tsv, yaml, none. Table transformers only apply when there is no --query; with --query the table uses your own keys (first letter upper-cased). Keys named id, type and etag are always left out, also from your own query: rekey them ({Id:id, Type:type}). Nested objects, arrays and null values are left out too.
--query EXPR- JMESPath evaluated client-side over the JSON: field.sub, [0], [-1], [] flatten, [*] projection, [?filter], {Name:name} multiselect, length(), contains(), starts_with(), sort_by(), | pipe. Quote it in single quotes so bash leaves it alone.
-g, --resource-group RG- Resource group.
az config set defaults.group=RGmakes it optional. --subscription SUB- Run against another subscription without switching (
az account set). @file- Any argument value starting with @ is read from that file:
--analytics-query @q.kql. -o tsv- Unquoted, tab separated values. The way to get one value into a shell variable:
ID=$(az ... --query id -o tsv). -n, --name NAME- Name of the object the command acts on (cluster, vault, secret, subnet, blob...).
-l, --location LOCATION- Location (region), e.g. westeurope.
az account list-locationslists them. --ids IDS- One or more full resource IDs (space-delimited). Replaces the name + resource-group arguments.
--tags TAGS- Space-separated tags: key[=value]. On update, "" clears them.
-y, --yes- Do not prompt for confirmation.
--no-wait- Do not wait for the long-running operation to finish.
--set KEY=VALUE- Generic update: set a property path to a value, e.g.
--set tags.env=dev. --add PROPERTY- Generic update: add an object to a list property (path then key=value pairs).
--remove PATH- Generic update: remove a property or a list element.
--only-show-errors- Only show errors, suppressing warnings.
--debug- Increase logging verbosity to show all debug logs (HTTP requests included).
--verbose- Increase logging verbosity. Use --debug for full debug logs.
-h, --help- Show this help message and exit.
Examples
$ az login --use-device-codeSign in from a machine without a browser.
$ az account list -o tableSubscriptions you can see; the default one has IsDefault True.
$ az group list --query "[?location=='westeurope'].name" -o tsvJMESPath filter plus projection.
$ az aks nodepool list -g rg-oncall-lab --cluster-name aks-sysop -o tableNode pools, counts, max pods.
$ az role assignment list --assignee <principalId> --all -o tableEverything a principal can do, at every scope.
$ az keyvault secret show --vault-name kv -n name --query value -o tsvRead a secret (needs a data-plane role).
$ az monitor log-analytics query -w <customerId> --analytics-query @q.kql -o tableRun KQL. -w is the workspace GUID, not its name.
Gotchas
- Control plane vs data plane: Owner/Contributor manage the Key Vault or storage account (ARM) but cannot read secrets or blobs. That needs a data role such as Key Vault Secrets User or Storage Blob Data Reader.
- Role assignments inherit downwards: management group > subscription > resource group > resource.
az role assignment listwith no scope only shows subscription-level ones; use --all or --scope ... --include-inherited. - Azure reserves 5 addresses in every subnet (.0 network, .1 gateway, .2 and .3 Azure DNS, the last one broadcast). The first address you get is .4.
- Azure CNI (node subnet, "legacy") pre-allocates maxPods+1 addresses per node. Default maxPods is 30 there, 250 on Azure CNI Overlay (the default when --network-plugin is omitted), 110 on kubenet.
Taught in
- 22.3 Output formats: json, table, tsv, yaml
- 22.4 JMESPath: --query properly
- 22.8 Entra ID: users, apps, service principals
- 22.9 Managed identities: system-assigned vs user-assigned
- 22.13 Azure RBAC: roles, scopes, inheritance
- 22.23 Key Vault: two permission models, one data plane
- 22.27 From Key Vault into a pod: the Secrets Store CSI driver
- 22.29 Storage accounts, blobs, and who is allowed in
Try az in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.