All skills
microsoft avatar

/azure-kubernetes-app-deploy

@a8f19b4
by microsoftmicrosoft/skills3.1k stars
351

Use when deploying an existing web application or API to an already-running Azure Kubernetes Service cluster. Detects the framework, generates a Dockerfile and Kubernetes manifests, validates against AKS Deployment Safeguards, and deploys with verification. WHEN: deploy app to AKS, deploy to existing AKS cluster, containerize app for Kubernetes, generate K8s manifests for Azure, set up CI/CD for AKS, my AKS deployment is failing safeguard checks, I have a Django/Express/Spring Boot app to run on AKS. DO NOT USE FOR: creating or provisioning an AKS cluster (use azure-kubernetes), assessing migration to AKS Automatic (use azure-kubernetes-automatic-readiness), or deploying to non-AKS targets like Web Apps, Container Apps, or Functions.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-kubernetes-app-deploy

This session only. Nothing lands on disk.

referencessafeguards.md

≈750 tokens on demand. Your agent reads this file only when SKILL.md points to it.

AKS Deployment Safeguards Reference

Source of truth: the Deployment Safeguards policy initiative is defined once in ../../azure-kubernetes-automatic-readiness/references/constraint-spec-v1.yaml (initiative c047ea8e-…). This file is the deploy-time checklist: which rules the app-deploy workflow auto-fixes vs. warns on, and how. When the policy set changes, update the constraint spec; only the app-deploy-specific fix behavior below is maintained here.

This checklist maps each safeguard to how the quick-deploy workflow handles it.

DS001 — Resource Limits Required (Error)

Every container needs resources.requests AND resources.limits for both cpu and memory.

DS002 — Liveness Probe Required (Warning)

Every container needs a livenessProbe. Use httpGet, tcpSocket, or exec.

DS003 — Readiness Probe Required (Warning)

Every container needs a readinessProbe.

DS004 — runAsNonRoot Required (Error)

Set at both pod and container level.

DS005 — No hostNetwork (Error)

Remove hostNetwork: true or set to false.

DS006 — No hostPID (Error)

Remove hostPID: true or set to false.

DS007 — No hostIPC (Error)

Remove hostIPC: true or set to false.

DS008 — No Privileged Containers (Error)

Remove securityContext.privileged: true or set to false.

DS009 — No :latest Image Tag (Error, NOT auto-fixable)

Use a semantic version, git SHA, or digest — never :latest or omit the tag.

DS010 — Minimum 2 Replicas (Warning)

Set spec.replicas: 2 or higher. Pair with a PodDisruptionBudget.

DS011 — allowPrivilegeEscalation: false (Error)

Every container must set securityContext.allowPrivilegeEscalation: false.

DS012 — readOnlyRootFilesystem: true (Warning)

Every container must set securityContext.readOnlyRootFilesystem: true.

If the app writes to specific paths, mount emptyDir volumes:

volumes:
  - name: tmp
    emptyDir: {}
containers:
  - volumeMounts:
      - name: tmp
        mountPath: /tmp

Common writable paths: Spring Boot /tmp, ASP.NET /tmp, Django /tmp, Express /tmp, Go /tmp.

DS013 — automountServiceAccountToken: false (Warning)

Set spec.automountServiceAccountToken: false. Set to true only if the app genuinely calls the K8s API (scope with RBAC).


Quick Reference

Rule What Severity Auto-Fix
DS001 Resource limits Error Yes
DS002 Liveness probe Warning Yes
DS003 Readiness probe Warning Yes
DS004 runAsNonRoot Error Yes
DS005 No hostNetwork Error Yes
DS006 No hostPID Error Yes
DS007 No hostIPC Error Yes
DS008 No privileged Error Yes
DS009 No :latest tag Error No
DS010 Min 2 replicas Warning Yes
DS011 No privilege escalation Error Yes
DS012 Read-only root FS Warning Yes
DS013 No SA token mount Warning Yes

Source: SKILL.md on GitHub

1 warning1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill facilitates the deployment of applications to Azure Kubernetes Service (AKS) by automating Dockerfile generation and Kubernetes manifest creation. It incorporates security best practices such as AKS Deployment Safeguards and Azure Workload Identity. No significant security considerations were identified; external resource references and tool usage align with the skill's intended deployment purpose.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: MEDIUM · 2 issues

Signed by skilld at a8f19b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "1.0.0"
}

README badge

README badge for microsoft/skills/azure-kubernetes-app-deploy