Skip to main content

Kubernetes

Kubernetes is the open-source container orchestrator that AKS runs for you. This page covers what runs inside the Azure Web App Blueprint's cluster in each stage and how the application pods are hardened, scaled and isolated.

What it does​

Workloads run as pods grouped in namespaces and managed by Deployments. A service account gives a pod its identity. Taints on nodes keep pods away unless they carry a matching toleration. A NetworkPolicy selects pods and allows only the traffic it lists. Pod Security Admission rejects pods that break a namespace's security level. A HorizontalPodAutoscaler (HPA) adds replicas under load, and a PodDisruptionBudget (PDB) keeps a minimum running while nodes are drained.

How BuiltForProd uses it​

NamespaceWhat runsInstalled by
blueprint-appThe API, service account blueprint-app-saapp-namespace unit, then ArgoCD from the chart
argocdArgoCDargocd unit (Helm)
cert-managercert-managercert-manager unit (Helm)
external-secretsExternal Secrets Operatorexternal-secrets unit (Helm)
app-routing-systemThe managed NGINX controllersThe application routing add-on
kube-system and other AKS namespacesCoreDNS, Cilium and the agents of the managed add-onsAKS

The platform components tolerate the system pool's CriticalAddonsOnly taint. The application pods do not, so they run on nodes from Node Auto Provisioning.

Pod hardening. The blueprint-app namespace enforces the Pod Security Standard restricted. The chart runs the container as the fixed non-root user 10001 with the RuntimeDefault seccomp profile, no privilege escalation, every Linux capability dropped and a read-only root filesystem; /tmp is the only writable path. The pod carries the label azure.workload.identity/use, so the Workload ID webhook injects a federated token and the API obtains Microsoft Entra tokens for its data stores; the credential chain is limited to that token.

Network isolation. The chart's NetworkPolicy denies all ingress and egress, then allows four flows, and Cilium enforces it:

  • TCP 8080 in, from the controllers in app-routing-system only.
  • DNS to CoreDNS.
  • TCP 10260 (Cosmos DB) and TCP 10000 (Managed Redis) to the stage's snet-endpoints prefix only.
  • TCP 443 to public addresses, for the Entra token endpoint and Application Insights; private ranges and the instance metadata endpoint stay blocked.

Scaling per stage. Every value comes from values-<stage>.yaml in the GitOps repository:

StageReplicasCPU and memory (request, limit)HPAPDB
dev1100m / 256Mi, 250m / 512Mioffoff
staging2250m / 256Mi, 500m / 512Mi2 to 5 at 70% CPU1 available
prod3500m / 512Mi, 1000m / 1Gi3 to 10 at 60% CPU2 available

Replicas spread across zones and nodes with a soft topology spread. The liveness probe calls /health and the readiness probe /ready.

Deployment Safeguards. The cluster's Azure Policy add-on checks every workload against the AKS best practices, such as resource requests, probes and no privileged containers, and in Warn mode reports violations as warnings at deployment time. deployment_safeguards_level = "Enforce" turns the warnings into denials.

Terms you will see​

TermMeaning
Taint, tolerationThe node mark and the pod permission that keep application pods off the system pool.
NetworkPolicyThe pod firewall; default deny with four allowed flows.
Pod Security AdmissionThe admission check that enforces the restricted standard in the namespace.
HPAHorizontalPodAutoscaler: replicas follow CPU use within a range.
PDBPodDisruptionBudget: the replicas that stay up while nodes are drained.
Topology spreadThe rule that spreads replicas across zones and nodes.

Where to read more​