All skills
microsoft avatar

/azure-kubernetes

@a8f19b4
by microsoftmicrosoft/skills3.1k stars
351

Plan, create, and configure production-ready Azure Kubernetes Service (AKS) clusters. Covers Day-0 checklist, SKU selection (Automatic vs Standard), networking options (private API server, Azure CNI Overlay, egress configuration), security, and operations (autoscaling, upgrade strategy, cost analysis). WHEN: create AKS environment, provision AKS, enable AKS observability, design AKS networking, choose AKS SKU, secure AKS, optimize AKS, AKS spot nodes, AKS cluster-autoscaler, rightsize AKS pod, pod rightsizing, over-provisioned AKS pod, pod resource requests and limits, Vertical Pod Autoscaler, VPA recommendations.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-kubernetes

This session only. Nothing lands on disk.

azure-kubernetes-app-deployreferencessafeguards.md

≈750 tokens on demand. Your agent reads this file only when SKILL.md points to it.

AKS Deployment Safeguards Reference

Source of truth: the Deployment Safeguards policy initiative is defined once in ../../azure-kubernetes-automatic-readiness/references/constraint-spec-v1.yaml (initiative c047ea8e-…). This file is the deploy-time checklist: which rules the app-deploy workflow auto-fixes vs. warns on, and how. When the policy set changes, update the constraint spec; only the app-deploy-specific fix behavior below is maintained here.

This checklist maps each safeguard to how the quick-deploy workflow handles it.

DS001 — Resource Limits Required (Error)

Every container needs resources.requests AND resources.limits for both cpu and memory.

DS002 — Liveness Probe Required (Warning)

Every container needs a livenessProbe. Use httpGet, tcpSocket, or exec.

DS003 — Readiness Probe Required (Warning)

Every container needs a readinessProbe.

DS004 — runAsNonRoot Required (Error)

Set at both pod and container level.

DS005 — No hostNetwork (Error)

Remove hostNetwork: true or set to false.

DS006 — No hostPID (Error)

Remove hostPID: true or set to false.

DS007 — No hostIPC (Error)

Remove hostIPC: true or set to false.

DS008 — No Privileged Containers (Error)

Remove securityContext.privileged: true or set to false.

DS009 — No :latest Image Tag (Error, NOT auto-fixable)

Use a semantic version, git SHA, or digest — never :latest or omit the tag.

DS010 — Minimum 2 Replicas (Warning)

Set spec.replicas: 2 or higher. Pair with a PodDisruptionBudget.

DS011 — allowPrivilegeEscalation: false (Error)

Every container must set securityContext.allowPrivilegeEscalation: false.

DS012 — readOnlyRootFilesystem: true (Warning)

Every container must set securityContext.readOnlyRootFilesystem: true.

If the app writes to specific paths, mount emptyDir volumes:

volumes:
  - name: tmp
    emptyDir: {}
containers:
  - volumeMounts:
      - name: tmp
        mountPath: /tmp

Common writable paths: Spring Boot /tmp, ASP.NET /tmp, Django /tmp, Express /tmp, Go /tmp.

DS013 — automountServiceAccountToken: false (Warning)

Set spec.automountServiceAccountToken: false. Set to true only if the app genuinely calls the K8s API (scope with RBAC).


Quick Reference

Rule What Severity Auto-Fix
DS001 Resource limits Error Yes
DS002 Liveness probe Warning Yes
DS003 Readiness probe Warning Yes
DS004 runAsNonRoot Error Yes
DS005 No hostNetwork Error Yes
DS006 No hostPID Error Yes
DS007 No hostIPC Error Yes
DS008 No privileged Error Yes
DS009 No :latest tag Error No
DS010 Min 2 replicas Warning Yes
DS011 No privilege escalation Error Yes
DS012 Read-only root FS Warning Yes
DS013 No SA token mount Warning Yes

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill provides comprehensive, production-grade guidance for Azure Kubernetes Service (AKS) with a strong emphasis on security best practices, including Workload Identity, hardened container configurations, and automated readiness assessments.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at a8f19b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "1.2.2"
}

README badge

README badge for microsoft/skills/azure-kubernetes