Glossary
Standalone glossary for the AKS cluster architecture skill. Short AKS-flavoured definitions only - consult the relevant bundle for context and trade-offs.
| Acronym | Expansion | AKS context |
|---|---|---|
| ACR | Azure Container Registry | Private registry for AKS image pulls; pair with Workload Identity and Private Link. |
| ACNS | Container Networking Services | AKS networking add-on for network policy, FQDN/L7 controls, and observability on Cilium-backed clusters. --enable-acns alone enables only FQDN filtering; L7 policy requires the additional --acns-advanced-networkpolicies L7 flag. |
| AGC | Application Gateway for Containers | Azure-managed L7/WAF/Gateway API entry point; strategic ingress target for new AKS clusters using App Routing. |
| AGIC | Application Gateway Ingress Controller | Legacy Ingress API controller for Application Gateway; treat as migration path toward AGC for new designs. |
| ALZ | Azure Landing Zone | Enterprise-scale Azure baseline (management groups, hub-spoke, policy) that AKS clusters land into. |
| CNI | Container Network Interface | Pod networking plugin; default for new AKS is Azure CNI Overlay Powered by Cilium. |
| CRD | Custom Resource Definition | Kubernetes extension type; storage versions need migration planning across upgrades. |
| CSI | Container Storage Interface | Driver model for persistent volumes; AKS ships managed CSI drivers for Azure Disk, Azure Files, Blob. |
| CVM | Confidential Virtual Machine | Hardware-isolated VM family; AKS confidential node pools use CVM SKUs. |
| Dual-stack | IPv4 + IPv6 (dual IP family) | --ip-families ipv4,ipv6; Permanent at cluster creation; requires Azure CNI Overlay/Cilium overlay; IPv6-only not supported for nodes/pods; standard NAT Gateway not supported. |
| DCGM | NVIDIA Data Center GPU Manager | Source of GPU metrics for Managed Prometheus, KEDA GPU scaling, and capacity dashboards. |
| FQDN | Fully Qualified Domain Name | Egress allow-list anchor for Azure Firewall, ACNS FQDN policy, or Cilium L7 policy. |
| GitOps | Git as source of truth for cluster state | Flux or Argo CD reconciles manifests into AKS; break-glass changes must reconcile back to Git. |
| HPA | Horizontal Pod Autoscaler | Scales replicas from CPU/memory/custom metrics; requires resource requests and reliable metrics. |
| KAITO | Kubernetes AI Toolchain Operator | AKS add-on for self-hosted open-source model inference; verify model presets and GPU SKU support. |
| KEDA | Kubernetes Event-Driven Autoscaling | AKS-managed add-on for queue/stream/scheduled/external-metric scaling; pair scalers with Workload Identity. |
| KMS | Key Management Service | Envelope encryption for Kubernetes secrets backed by Azure Key Vault on AKS. |
| Kueue | Kubernetes batch admission control | Open-source job queuing system (ClusterQueue + LocalQueue) for batch/AI training; AKS-documented but excluded from AKS SLA. |
| KVStoreMesh | Cilium Cluster Mesh KV-store mode | Scalability/isolation mode for Cilium Cluster Mesh; an exception, not an AKS default. |
| LTS | Long-Term Support | Extended Kubernetes minor support track on AKS; use intentionally, not by default. |
| MCP | Model Context Protocol | Tool-exposure protocol for AI agents; the AKS MCP server connects agents to Azure and Kubernetes operations. |
| MI | Managed Identity | Azure AD identity attached to AKS control plane, kubelet, or workloads via Workload Identity. |
| MIG | Multi-Instance GPU | NVIDIA hardware GPU partitioning (A100/H100/H200, up to 7 isolated instances); static at node-pool level on AKS. |
| MPS | Multi-Process Service | NVIDIA CUDA-level GPU multiplexing; user-managed via GPU Operator; experimentation for low-latency inference. |
| NAP | Node Auto Provisioning | AKS-managed Karpenter implementation; verify regional support and unsupported combinations before adopting. |
| OIDC | OpenID Connect | Issuer required on the cluster for Workload Identity federation with Microsoft Entra. |
| PDB | PodDisruptionBudget | Constrains voluntary eviction during drains and upgrades; does not protect against crashes. |
| PSA | Pod Security Admission | Namespace-scoped enforcement of restricted / baseline / privileged profiles; set on every production namespace. |
| RBAC | Role-Based Access Control | Azure RBAC for Kubernetes is the AKS default; Kubernetes RBAC still used for fine-grained service-account scoping. |
| SBOM | Software Bill of Materials | Image content inventory; produced in CI and consumed at admission for supply-chain checks. |
| SIEM | Security Information and Event Management | Sentinel or equivalent; consumes AKS audit, ContainerLogV2, and Defender for Cloud signals. |
| SLO | Service Level Objective | Quantitative reliability target that drives replica counts, PDB sizing, autoscaling minimums, and alerts. |
| SLSA | Supply-chain Levels for Software Artifacts | Build-provenance framework; align ACR signing/attestation policies with the target SLSA level. |
| UDR | User-Defined Route | Subnet route table used to send AKS egress through Azure Firewall or NVAs in ALZ hub-spoke designs. |
| VHD | Virtual Hard Disk | AKS node image format; node OS auto-upgrade channel replaces VHDs on a 90-day validity window. |
| VPA | Vertical Pod Autoscaler | Rightsizes container requests; start in recommender mode in production, never combine Auto with HPA on the same metric without testing. |
Cross-reference: SKILL.md Glossary.