Azure Kubernetes Service
Azure Kubernetes Service (AKS) is Microsoft's managed Kubernetes: Azure runs the control plane, and the cluster's nodes are virtual machines in your subscription. The Azure Web App Blueprint runs one private AKS cluster per stage, <prefix>-aks such as acme-eus2-prd-aks, in the stage subscription.
What it does
The control plane (API server, scheduler, etcd) is managed by Azure; its SKU tier decides whether it carries an uptime SLA. Nodes come from node pools or from Node Auto Provisioning. A private cluster gives the API server a private address only. With Microsoft Entra integration and Azure RBAC for Kubernetes, every kubectl call is authorized by Azure role assignments, and the OIDC issuer with Workload ID lets pods exchange their service-account token for Entra tokens. The network plugin places pods; the outbound type decides how nodes reach the internet. Managed add-ons and auto-upgrade channels keep the cluster and the node images current inside maintenance windows.
How BuiltForProd uses it
The aks unit (module aks) builds the cluster from the stage file's values and the landing-zone contract the Baseline publishes in the stage's contract vault.
| Aspect | Setting |
|---|---|
| Control plane | SKU tier Free in dev; Standard (~$73/month, uptime SLA and cost analysis) in staging and prod; Kubernetes 1.36 at creation |
| API server | Private, registered in privatelink.eastus2.azmk8s.io in acme-core-network; reached from the Container Apps runners and the VPN |
| System pool | system, Azure Linux, Standard_D2as_v5 (~$63/month per node) in zones 1 to 3; 2 to 3 nodes in dev, 3 to 4 in staging and prod; tainted CriticalAddonsOnly |
| Application nodes | Node Auto Provisioning, with no built-in pools |
| Network | Azure CNI Overlay with the Cilium data plane and network policy; nodes in snet-aks; pod and service ranges reserved by the landing zone and never routed in the VNet |
| Outbound | userDefinedRouting through the hub firewall, or userAssignedNATGateway in the spoke NAT egress mode |
| Sign-in | Local accounts disabled; Microsoft Entra ID with Azure RBAC for Kubernetes; OIDC issuer and Workload ID on |
| Add-ons | Application routing, Container Insights to the stage application workspace, Azure Policy with Deployment Safeguards in Warn, image cleaner every 48 hours |
| Upgrades | patch auto-upgrade channel and NodeImage OS channel, each in a weekly four-hour window from Sunday 02:00 UTC |
Egress. The cluster reads the contract secret network--firewall-private-ip. An address means the hub firewall carries egress and the spoke route table holds the default route; none means a NAT gateway on snet-aks. A cluster with Node Auto Provisioning cannot change its outbound type after creation, so the egress mode is chosen before the first deployment.
Identities. The control-plane identity id-<prefix>-aks holds Network Contributor on the spoke VNet, its route table and the cluster's resource group, Managed Identity Operator on the kubelet identity, and Private DNS Zone Contributor on the API server's zone. The kubelet identity id-<prefix>-aks-kubelet holds AcrPull on the shared Azure Container Registry. The deployer that applies the stage holds RBAC Cluster Admin and the Cluster User Role on the cluster, because the later units install Helm releases with it.
People. Human access comes from the Baseline's access matrix, not from the blueprint: the lead groups are cluster admins on every stage, Platform Engineers are cluster admins and the other engineering groups write below prod, and on prod everyone else reads with RBAC Reader plus the Cluster User Role, which az aks get-credentials needs. Azure RBAC has the full table. The prod stage file names only ACME_PlatformLeads and ACME_DevOpsLeads as the cluster's admin groups.
Operating it. az aks command invoke stays enabled (run_command_enabled), so kubectl can run inside the cluster with the caller's own Kubernetes rights even without a network path to the API server. Managed Prometheus (enable_managed_prometheus, ~$0.16 per million samples) and deployment_safeguards_level = "Enforce" are @optional: lines in the unit file.
Terms you will see
| Term | Meaning |
|---|---|
| System pool | The fixed node pool for cluster add-ons, tainted so application pods stay off it. |
| Outbound type | How nodes reach the internet; it follows the hub's egress mode and is fixed at creation. |
| Azure RBAC for Kubernetes | Kubernetes authorization through Azure role assignments such as RBAC Cluster Admin. |
| Workload ID | Federation of a Kubernetes service account with a managed identity. |
| Deployment Safeguards | Azure Policy checks of workloads against AKS best practices, here in Warn mode. |
| Auto-upgrade channel | The cadence at which AKS applies Kubernetes patches and node images. |
Where to read more
- Azure Web App Blueprint overview for the request path end to end.
- Kubernetes for what runs inside the cluster.
- Node Auto Provisioning for the application capacity.