Proposed Pull Request Change

title description ms.topic ms.author author ms.service services ms.date
Configure secure Azure Service Fabric cluster connections Learn how to use Visual Studio to configure secure connections that are supported by the Azure Service Fabric cluster. how-to tomcassidy tomvcassidy azure-service-fabric service-fabric 08/25/2026
πŸ“„ Document Links
GitHub View on GitHub Microsoft Learn View on Microsoft Learn
⚠ Content Truncation Detected
The generated rewrite appears to be incomplete.
Original lines: -
Output lines: -
Ratio: -
Raw New Markdown
Generating updated version of doc...
Rendered New Markdown
Generating updated version of doc...
+0 -0
+0 -0
--- title: Configure secure Azure Service Fabric cluster connections description: Learn how to use Visual Studio to configure secure connections that are supported by the Azure Service Fabric cluster. ms.topic: how-to ms.author: tomcassidy author: tomvcassidy ms.service: azure-service-fabric services: service-fabric ms.date: 08/25/2026 # Customer intent: "As a developer using Visual Studio, I want to configure secure connections to an Azure Service Fabric cluster, so that I can deploy applications securely and ensure proper access control during the publishing process." --- # Configure secure connections to a Service Fabric cluster from Visual Studio Learn how to use Visual Studio to securely access an Azure Service Fabric cluster with access control policies configured. ## Cluster connection types Azure Service Fabric clusters support two types of connections: **non-secure** connections and **x509 certificate-based** secure connections. (For Service Fabric clusters hosted on-premises, **Windows** authentication is also supported.) You configure the cluster connection type when you create the cluster. After creation, you can't change the connection type. The Visual Studio Service Fabric tools support all authentication types for connecting to a cluster for publishing. See [Setting up a Service Fabric cluster from the Azure portal](service-fabric-cluster-creation-via-portal.md) for instructions on how to set up a secure Service Fabric cluster. ## Configure cluster connections in publish profiles If you publish a Service Fabric project from Visual Studio, use the **Publish Service Fabric Application** dialog box to choose an Azure Service Fabric cluster. Under **Connection endpoint**, select an existing cluster under your subscription. ![The **Publish Service Fabric Application** dialog box is used to configure a Service Fabric connection.][publishdialog] The **Publish Service Fabric Application** dialog box automatically validates the cluster connection. If prompted, sign in to your Azure account. If validation passes, it means that your system has the correct certificates installed to connect to the cluster securely, or your cluster is non-secure. Validation failures can be caused by network issues or by not having your system correctly configured to connect to a secure cluster. ![The **Publish Service Fabric Application** dialog box validates an existing, correctly configured Service Fabric cluster connection.][selectsfcluster] ### To connect to a secure cluster 1. Make sure you can access one of the client certificates that the destination cluster trusts. The certificate is usually shared as a Personal Information Exchange (.pfx) file. See [Setting up a Service Fabric cluster from the Azure portal](service-fabric-cluster-creation-via-portal.md) for how to configure the server to grant access to a client. 2. Install the trusted certificate. To do this, double-click the .pfx file, or use the PowerShell script Import-PfxCertificate to import the certificates. Install the certificate to **Cert:\LocalMachine\My**. It's OK to accept all default settings while importing the certificate. 3. Choose the **Publish...** command on the shortcut menu of the project to open the **Publish Azure Application** dialog box and then select the target cluster. The tool automatically resolves the connection and saves the secure connection parameters in the publish profile. 4. Optional: You can edit the publish profile to specify a secure cluster connection. Since you're manually editing the Publish Profile XML file to specify the certificate information, be sure to note the certificate store name, store location, and certificate thumbprint. You'll need to provide these values for the certificate's store name and store location. See [How to: Retrieve the Thumbprint of a Certificate](https://azure.microsoft.com/blog/product/azure-service-fabric/) for more information. You can use the *ClusterConnectionParameters* parameters to specify the PowerShell parameters to use when connecting to the Service Fabric cluster. Valid parameters are any that are accepted by the Connect-ServiceFabricCluster cmdlet. See [Connect-ServiceFabricCluster](/powershell/module/servicefabric/connect-servicefabriccluster) for a list of available parameters. If you’re publishing to a remote cluster, you need to specify the appropriate parameters for that specific cluster. The following is an example of connecting to a non-secure cluster: `<ClusterConnectionParameters ConnectionEndpoint="mycluster.westus.cloudapp.azure.com:19000" />` Here’s an example for connecting to an x509 certificate-based secure cluster: ```xml <ClusterConnectionParameters ConnectionEndpoint="mycluster.westus.cloudapp.azure.com:19000" X509Credential="true" ServerCertThumbprint="AA11BB22CC33DD44EE55FF66AA77BB88CC99DD00" FindType="FindByThumbprint" FindValue="9876543210987654321098765432109876543210" StoreLocation="CurrentUser" StoreName="My" /> ``` 5. Edit any other necessary settings, such as upgrade parameters and Application Parameter file location, and then publish your application from the **Publish Service Fabric Application** dialog box in Visual Studio. ## Next steps For more information about accessing Service Fabric clusters, see [Visualizing your cluster by using Service Fabric Explorer](service-fabric-visualizing-your-cluster.md). <!--Image references--> [publishdialog]:./media/service-fabric-visualstudio-configure-secure-connections/publishdialog.png [selectsfcluster]:./media/service-fabric-visualstudio-configure-secure-connections/selectsfcluster.png
Success! Branch created successfully. Create Pull Request on GitHub
Error: