OnCallReady

Commands

az - Azure command-line interface

az <group> [<subgroup>...] <command> [--resource-group/-g RG] [--name/-n NAME] [--output/-o FORMAT] [--query JMESPATH] [--subscription SUB]

Options you will use

-o, --output FORMAT
json (default, keys sorted), jsonc, table, tsv, yaml, none. Table transformers only apply when there is no --query; with --query the table uses your own keys (first letter upper-cased). Keys named id, type and etag are always left out, also from your own query: rekey them ({Id:id, Type:type}). Nested objects, arrays and null values are left out too.
--query EXPR
JMESPath evaluated client-side over the JSON: field.sub, [0], [-1], [] flatten, [*] projection, [?filter], {Name:name} multiselect, length(), contains(), starts_with(), sort_by(), | pipe. Quote it in single quotes so bash leaves it alone.
-g, --resource-group RG
Resource group. az config set defaults.group=RG makes it optional.
--subscription SUB
Run against another subscription without switching (az account set).
@file
Any argument value starting with @ is read from that file: --analytics-query @q.kql.
-o tsv
Unquoted, tab separated values. The way to get one value into a shell variable: ID=$(az ... --query id -o tsv).
-n, --name NAME
Name of the object the command acts on (cluster, vault, secret, subnet, blob...).
-l, --location LOCATION
Location (region), e.g. westeurope. az account list-locations lists them.
--ids IDS
One or more full resource IDs (space-delimited). Replaces the name + resource-group arguments.
--tags TAGS
Space-separated tags: key[=value]. On update, "" clears them.
-y, --yes
Do not prompt for confirmation.
--no-wait
Do not wait for the long-running operation to finish.
--set KEY=VALUE
Generic update: set a property path to a value, e.g. --set tags.env=dev.
--add PROPERTY
Generic update: add an object to a list property (path then key=value pairs).
--remove PATH
Generic update: remove a property or a list element.
--only-show-errors
Only show errors, suppressing warnings.
--debug
Increase logging verbosity to show all debug logs (HTTP requests included).
--verbose
Increase logging verbosity. Use --debug for full debug logs.
-h, --help
Show this help message and exit.

Examples

$ az login --use-device-code

Sign in from a machine without a browser.

$ az account list -o table

Subscriptions you can see; the default one has IsDefault True.

$ az group list --query "[?location=='westeurope'].name" -o tsv

JMESPath filter plus projection.

$ az aks nodepool list -g rg-oncall-lab --cluster-name aks-sysop -o table

Node pools, counts, max pods.

$ az role assignment list --assignee <principalId> --all -o table

Everything a principal can do, at every scope.

$ az keyvault secret show --vault-name kv -n name --query value -o tsv

Read a secret (needs a data-plane role).

$ az monitor log-analytics query -w <customerId> --analytics-query @q.kql -o table

Run KQL. -w is the workspace GUID, not its name.

Gotchas

Taught in

Try az in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.