Skip to main content

Azure Kubernetes Service

Azure Kubernetes Service (AKS) is Microsoft's managed Kubernetes: Azure runs the control plane, and the cluster's nodes are virtual machines in your subscription. The Azure Web App Blueprint runs one private AKS cluster per stage, <prefix>-aks such as acme-eus2-prd-aks, in the stage subscription.

What it does​

The control plane (API server, scheduler, etcd) is managed by Azure; its SKU tier decides whether it carries an uptime SLA. Nodes come from node pools or from Node Auto Provisioning. A private cluster gives the API server a private address only. With Microsoft Entra integration and Azure RBAC for Kubernetes, every kubectl call is authorized by Azure role assignments, and the OIDC issuer with Workload ID lets pods exchange their service-account token for Entra tokens. The network plugin places pods; the outbound type decides how nodes reach the internet. Managed add-ons and auto-upgrade channels keep the cluster and the node images current inside maintenance windows.

How BuiltForProd uses it​

The aks unit (module aks) builds the cluster from the stage file's values and the landing-zone contract the Baseline publishes in the stage's contract vault.

AspectSetting
Control planeSKU tier Free in dev; Standard (~$73/month, uptime SLA and cost analysis) in staging and prod; Kubernetes 1.36 at creation
API serverPrivate, registered in privatelink.eastus2.azmk8s.io in acme-core-network; reached from the Container Apps runners and the VPN
System poolsystem, Azure Linux, Standard_D2as_v5 (~$63/month per node) in zones 1 to 3; 2 to 3 nodes in dev, 3 to 4 in staging and prod; tainted CriticalAddonsOnly
Application nodesNode Auto Provisioning, with no built-in pools
NetworkAzure CNI Overlay with the Cilium data plane and network policy; nodes in snet-aks; pod and service ranges reserved by the landing zone and never routed in the VNet
OutbounduserDefinedRouting through the hub firewall, or userAssignedNATGateway in the spoke NAT egress mode
Sign-inLocal accounts disabled; Microsoft Entra ID with Azure RBAC for Kubernetes; OIDC issuer and Workload ID on
Add-onsApplication routing, Container Insights to the stage application workspace, Azure Policy with Deployment Safeguards in Warn, image cleaner every 48 hours
Upgradespatch auto-upgrade channel and NodeImage OS channel, each in a weekly four-hour window from Sunday 02:00 UTC

Egress. The cluster reads the contract secret network--firewall-private-ip. An address means the hub firewall carries egress and the spoke route table holds the default route; none means a NAT gateway on snet-aks. A cluster with Node Auto Provisioning cannot change its outbound type after creation, so the egress mode is chosen before the first deployment.

Identities. The control-plane identity id-<prefix>-aks holds Network Contributor on the spoke VNet, its route table and the cluster's resource group, Managed Identity Operator on the kubelet identity, and Private DNS Zone Contributor on the API server's zone. The kubelet identity id-<prefix>-aks-kubelet holds AcrPull on the shared Azure Container Registry. The deployer that applies the stage holds RBAC Cluster Admin and the Cluster User Role on the cluster, because the later units install Helm releases with it.

People. Human access comes from the Baseline's access matrix, not from the blueprint: the lead groups are cluster admins on every stage, Platform Engineers are cluster admins and the other engineering groups write below prod, and on prod everyone else reads with RBAC Reader plus the Cluster User Role, which az aks get-credentials needs. Azure RBAC has the full table. The prod stage file names only ACME_PlatformLeads and ACME_DevOpsLeads as the cluster's admin groups.

Operating it. az aks command invoke stays enabled (run_command_enabled), so kubectl can run inside the cluster with the caller's own Kubernetes rights even without a network path to the API server. Managed Prometheus (enable_managed_prometheus, ~$0.16 per million samples) and deployment_safeguards_level = "Enforce" are @optional: lines in the unit file.

Terms you will see​

TermMeaning
System poolThe fixed node pool for cluster add-ons, tainted so application pods stay off it.
Outbound typeHow nodes reach the internet; it follows the hub's egress mode and is fixed at creation.
Azure RBAC for KubernetesKubernetes authorization through Azure role assignments such as RBAC Cluster Admin.
Workload IDFederation of a Kubernetes service account with a managed identity.
Deployment SafeguardsAzure Policy checks of workloads against AKS best practices, here in Warn mode.
Auto-upgrade channelThe cadence at which AKS applies Kubernetes patches and node images.

Where to read more​