Kubernetes
Kubernetes is the open-source container orchestrator that AKS runs for you. This page covers what runs inside the Azure Web App Blueprint's cluster in each stage and how the application pods are hardened, scaled and isolated.
What it does
Workloads run as pods grouped in namespaces and managed by Deployments. A service account gives a pod its identity. Taints on nodes keep pods away unless they carry a matching toleration. A NetworkPolicy selects pods and allows only the traffic it lists. Pod Security Admission rejects pods that break a namespace's security level. A HorizontalPodAutoscaler (HPA) adds replicas under load, and a PodDisruptionBudget (PDB) keeps a minimum running while nodes are drained.
How BuiltForProd uses it
| Namespace | What runs | Installed by |
|---|---|---|
blueprint-app | The API, service account blueprint-app-sa | app-namespace unit, then ArgoCD from the chart |
argocd | ArgoCD | argocd unit (Helm) |
cert-manager | cert-manager | cert-manager unit (Helm) |
external-secrets | External Secrets Operator | external-secrets unit (Helm) |
app-routing-system | The managed NGINX controllers | The application routing add-on |
kube-system and other AKS namespaces | CoreDNS, Cilium and the agents of the managed add-ons | AKS |
The platform components tolerate the system pool's CriticalAddonsOnly taint. The application pods do not, so they run on nodes from Node Auto Provisioning.
Pod hardening. The blueprint-app namespace enforces the Pod Security Standard restricted. The chart runs the container as the fixed non-root user 10001 with the RuntimeDefault seccomp profile, no privilege escalation, every Linux capability dropped and a read-only root filesystem; /tmp is the only writable path. The pod carries the label azure.workload.identity/use, so the Workload ID webhook injects a federated token and the API obtains Microsoft Entra tokens for its data stores; the credential chain is limited to that token.
Network isolation. The chart's NetworkPolicy denies all ingress and egress, then allows four flows, and Cilium enforces it:
- TCP 8080 in, from the controllers in
app-routing-systemonly. - DNS to CoreDNS.
- TCP 10260 (Cosmos DB) and TCP 10000 (Managed Redis) to the stage's
snet-endpointsprefix only. - TCP 443 to public addresses, for the Entra token endpoint and Application Insights; private ranges and the instance metadata endpoint stay blocked.
Scaling per stage. Every value comes from values-<stage>.yaml in the GitOps repository:
| Stage | Replicas | CPU and memory (request, limit) | HPA | PDB |
|---|---|---|---|---|
| dev | 1 | 100m / 256Mi, 250m / 512Mi | off | off |
| staging | 2 | 250m / 256Mi, 500m / 512Mi | 2 to 5 at 70% CPU | 1 available |
| prod | 3 | 500m / 512Mi, 1000m / 1Gi | 3 to 10 at 60% CPU | 2 available |
Replicas spread across zones and nodes with a soft topology spread. The liveness probe calls /health and the readiness probe /ready.
Deployment Safeguards. The cluster's Azure Policy add-on checks every workload against the AKS best practices, such as resource requests, probes and no privileged containers, and in Warn mode reports violations as warnings at deployment time. deployment_safeguards_level = "Enforce" turns the warnings into denials.
Terms you will see
| Term | Meaning |
|---|---|
| Taint, toleration | The node mark and the pod permission that keep application pods off the system pool. |
| NetworkPolicy | The pod firewall; default deny with four allowed flows. |
| Pod Security Admission | The admission check that enforces the restricted standard in the namespace. |
| HPA | HorizontalPodAutoscaler: replicas follow CPU use within a range. |
| PDB | PodDisruptionBudget: the replicas that stay up while nodes are drained. |
| Topology spread | The rule that spreads replicas across zones and nodes. |
Where to read more
- Azure Web App Blueprint overview for the application in context.
- Helm for the chart that holds these settings.
- Defense in depth for the layers around the pods.