Scale sets

A VM Scale Set (VMSS) is a fleet of identical VMs managed as one resource. The same run-command and extension rights that take over a single VM apply to the set, so one action reaches every instance, and the set's managed identity is shared across all of them.

Execute across the fleet#

bash
az vmss run-command invoke -g <rg> -n <vmss> --instance-id '*' \
  --command-id RunShellScript --scripts "id"
# or install an extension on the model so new instances inherit it
az vmss extension set -g <rg> --vmss-name <vmss> \
  --name CustomScript --publisher Microsoft.Azure.Extensions \
  --settings '{"commandToExecute":"..."}'

Exploitation notes#

  • Setting an extension on the VMSS model means every instance, including ones scaled out later, runs it: durable fleet-wide execution.
  • The scale set's managed identity token is reachable from any instance through IMDS, same as a standalone VM.

Tools#

  • Azure CLI (az vmss run-command invoke, az vmss extension set).
  • MicroBurst: bulk command execution.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more