All skills
lukemurraynz avatar

/aks-cluster-architecture

@2cc2455

AKS cluster architecture decisions for new Azure Kubernetes Service projects: AKS Automatic vs Standard, networking topology, dual-stack (IPv4/IPv6), Kubernetes version and OS currency, node pool strategy, identity, production NetworkPolicy, namespaces, autoscaling, ingress and Gateway API, observability, operations, resilience, GPU and AI workloads, GPU partitioning (MIG, time-slicing, MPS), batch scheduling (Kueue), AKS on bare metal, AI Runway and KAITO model serving, AKS MCP server access, kars (Agent Reference Stack for Kubernetes) for agent isolation, Kata MicroVM pod sandboxing, Azure Kubernetes Fleet Manager, multi-cluster governance, update orchestration, resource placement, cross-cluster networking, and cost. WHEN: designing new AKS clusters, reviewing production readiness, choosing CNI or outbound connectivity, planning node pools, defining namespace, network and security controls, evaluating Fleet Manager, deploying AI agent runtimes on AKS, or making hard-to-reverse infrastructure decisions.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/aks-cluster-architecture

This session only. Nothing lands on disk.

referencesglossary.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Glossary

Standalone glossary for the AKS cluster architecture skill. Short AKS-flavoured definitions only - consult the relevant bundle for context and trade-offs.

Acronym Expansion AKS context
ACR Azure Container Registry Private registry for AKS image pulls; pair with Workload Identity and Private Link.
ACNS Container Networking Services AKS networking add-on for network policy, FQDN/L7 controls, and observability on Cilium-backed clusters. --enable-acns alone enables only FQDN filtering; L7 policy requires the additional --acns-advanced-networkpolicies L7 flag.
AGC Application Gateway for Containers Azure-managed L7/WAF/Gateway API entry point; strategic ingress target for new AKS clusters using App Routing.
AGIC Application Gateway Ingress Controller Legacy Ingress API controller for Application Gateway; treat as migration path toward AGC for new designs.
ALZ Azure Landing Zone Enterprise-scale Azure baseline (management groups, hub-spoke, policy) that AKS clusters land into.
CNI Container Network Interface Pod networking plugin; default for new AKS is Azure CNI Overlay Powered by Cilium.
CRD Custom Resource Definition Kubernetes extension type; storage versions need migration planning across upgrades.
CSI Container Storage Interface Driver model for persistent volumes; AKS ships managed CSI drivers for Azure Disk, Azure Files, Blob.
CVM Confidential Virtual Machine Hardware-isolated VM family; AKS confidential node pools use CVM SKUs.
Dual-stack IPv4 + IPv6 (dual IP family) --ip-families ipv4,ipv6; Permanent at cluster creation; requires Azure CNI Overlay/Cilium overlay; IPv6-only not supported for nodes/pods; standard NAT Gateway not supported.
DCGM NVIDIA Data Center GPU Manager Source of GPU metrics for Managed Prometheus, KEDA GPU scaling, and capacity dashboards.
FQDN Fully Qualified Domain Name Egress allow-list anchor for Azure Firewall, ACNS FQDN policy, or Cilium L7 policy.
GitOps Git as source of truth for cluster state Flux or Argo CD reconciles manifests into AKS; break-glass changes must reconcile back to Git.
HPA Horizontal Pod Autoscaler Scales replicas from CPU/memory/custom metrics; requires resource requests and reliable metrics.
KAITO Kubernetes AI Toolchain Operator AKS add-on for self-hosted open-source model inference; verify model presets and GPU SKU support.
KEDA Kubernetes Event-Driven Autoscaling AKS-managed add-on for queue/stream/scheduled/external-metric scaling; pair scalers with Workload Identity.
KMS Key Management Service Envelope encryption for Kubernetes secrets backed by Azure Key Vault on AKS.
Kueue Kubernetes batch admission control Open-source job queuing system (ClusterQueue + LocalQueue) for batch/AI training; AKS-documented but excluded from AKS SLA.
KVStoreMesh Cilium Cluster Mesh KV-store mode Scalability/isolation mode for Cilium Cluster Mesh; an exception, not an AKS default.
LTS Long-Term Support Extended Kubernetes minor support track on AKS; use intentionally, not by default.
MCP Model Context Protocol Tool-exposure protocol for AI agents; the AKS MCP server connects agents to Azure and Kubernetes operations.
MI Managed Identity Azure AD identity attached to AKS control plane, kubelet, or workloads via Workload Identity.
MIG Multi-Instance GPU NVIDIA hardware GPU partitioning (A100/H100/H200, up to 7 isolated instances); static at node-pool level on AKS.
MPS Multi-Process Service NVIDIA CUDA-level GPU multiplexing; user-managed via GPU Operator; experimentation for low-latency inference.
NAP Node Auto Provisioning AKS-managed Karpenter implementation; verify regional support and unsupported combinations before adopting.
OIDC OpenID Connect Issuer required on the cluster for Workload Identity federation with Microsoft Entra.
PDB PodDisruptionBudget Constrains voluntary eviction during drains and upgrades; does not protect against crashes.
PSA Pod Security Admission Namespace-scoped enforcement of restricted / baseline / privileged profiles; set on every production namespace.
RBAC Role-Based Access Control Azure RBAC for Kubernetes is the AKS default; Kubernetes RBAC still used for fine-grained service-account scoping.
SBOM Software Bill of Materials Image content inventory; produced in CI and consumed at admission for supply-chain checks.
SIEM Security Information and Event Management Sentinel or equivalent; consumes AKS audit, ContainerLogV2, and Defender for Cloud signals.
SLO Service Level Objective Quantitative reliability target that drives replica counts, PDB sizing, autoscaling minimums, and alerts.
SLSA Supply-chain Levels for Software Artifacts Build-provenance framework; align ACR signing/attestation policies with the target SLSA level.
UDR User-Defined Route Subnet route table used to send AKS egress through Azure Firewall or NVAs in ALZ hub-spoke designs.
VHD Virtual Hard Disk AKS node image format; node OS auto-upgrade channel replaces VHDs on a 90-day validity window.
VPA Vertical Pod Autoscaler Rightsizes container requests; start in recommender mode in production, never combine Auto with HPA on the same metric without testing.

Cross-reference: SKILL.md Glossary.

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The skill is a comprehensive architecture and configuration guide for Azure Kubernetes Service (AKS). it emphasizes security best practices, including RBAC, NetworkPolicy, workload identity, and kernel-level isolation for AI agents. No malicious patterns or security risks were detected.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
metadata
{
  "last_verified": "2026-08-26"
}
Other metadata
argument-hint
workload=<type>; region=<azure-region>; availability=<SLO>; network=<hub-spoke|standalone>; scope=<new-cluster|production-review|fleet>

README badge

README badge for lukemurraynz/hve-agent-skills/aks-cluster-architecture