All skills
microsoft avatar

/azure-kubernetes

@a8f19b4
by microsoftmicrosoft/skills3.1k stars
351

Plan, create, and configure production-ready Azure Kubernetes Service (AKS) clusters. Covers Day-0 checklist, SKU selection (Automatic vs Standard), networking options (private API server, Azure CNI Overlay, egress configuration), security, and operations (autoscaling, upgrade strategy, cost analysis). WHEN: create AKS environment, provision AKS, enable AKS observability, design AKS networking, choose AKS SKU, secure AKS, optimize AKS, AKS spot nodes, AKS cluster-autoscaler, rightsize AKS pod, pod rightsizing, over-provisioned AKS pod, pod resource requests and limits, Vertical Pod Autoscaler, VPA recommendations.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-kubernetes

This session only. Nothing lands on disk.

azure-kubernetes-automatic-readinessreferencesmigration-guide-summary.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

AKS Automatic Migration Guide

Loaded when user asks about migration steps or after assessment is complete.


Migration Checklist

Phase 1 — Assessment (this skill)

  • Run the AKS Automatic compatibility assessment (via mcp_azure_mcp_aks({ action: "discover" }) then the assessment action returned, or the offline manifest scan)
  • Resolve all incompatible findings — these are hard blockers
  • Apply all requiresChanges fixes — these will be denied at admission
  • Review autoFixed items — understand what AKS Automatic will mutate at runtime
  • Address cluster-level Day-0 config issues (see below)

Phase 2 — Create AKS Automatic Cluster (use azure-kubernetes skill)

az aks create \
  --resource-group <resource-group> \
  --name <new-cluster-name> \
  --sku automatic \
  --location <location> \
  --generate-ssh-keys

💡 Tip: AKS Automatic auto-enables: OIDC issuer, workload identity, Azure CNI Overlay, NAP, VPA, Azure Monitor Container Insights, Deployment Safeguards, and Pod Security Standards (Baseline). No manual configuration needed for these.

Phase 3 — Validate on New Cluster

# Get credentials
az aks get-credentials \
  --resource-group <resource-group> \
  --name <new-cluster-name>

# Dry-run server-side apply — catches admission policy rejections
kubectl apply --dry-run=server -f <manifests-directory>/

# Deploy to a staging namespace first
kubectl create namespace staging
kubectl apply -f <manifests-directory>/ -n staging

# Watch pod startup
kubectl get pods -n staging -w

# Check events for admission rejections
kubectl get events -n staging --sort-by=.lastTimestamp | grep -i "denied\|error\|failed"

⚠️ Keep the old cluster running for a rollback window (recommended: 48 hours minimum) while you validate workloads on the new AKS Automatic cluster.

Phase 4 — Decommission Old Cluster

# Only after confirming workloads are stable on AKS Automatic
az aks delete \
  --resource-group <resource-group> \
  --name <old-cluster-name> \
  --yes --no-wait

Day-0 Decisions — Cluster-Level Configuration Requirements

Some settings require creating a new cluster; others can be enabled on existing clusters. Route to azure-kubernetes skill for cluster creation.

Requirement AKS Automatic default What to do
API Server VNet Integration Required, auto-enabled Requires a new cluster
Network plugin Azure CNI Overlay Requires a new cluster if currently on kubenet
System node pool OS Azure Linux Recreate system node pool (user pools unaffected)
OIDC Issuer Auto-enabled Can be enabled on existing: az aks update --enable-oidc-issuer
Workload Identity Auto-enabled Can be enabled on existing: az aks update --enable-workload-identity

What AKS Automatic Auto-Enables

No manual setup needed for these — show this list when user asks "what do I get for free":

Feature Benefit
Node Auto Provisioning (NAP) Replaces cluster autoscaler; right-sizes node pools automatically
Vertical Pod Autoscaler (VPA) Auto-tunes resource requests after deployment
Azure Monitor Container Insights Logs, metrics, and dashboards out of the box
Deployment Safeguards 25 active deny policies + 2 webhook mutators at admission (resource-requests defaults + anti-affinity/topology-spread)
Pod Security Standards (Baseline) Enforced cluster-wide; Restricted available opt-in
Managed OIDC Issuer Required for workload identity
Azure Key Vault CSI Driver Secret injection without static credentials
Ephemeral OS disks Faster node provisioning by default
Azure Linux node OS Smaller footprint, faster boot times

Post-Migration Verification Commands

# Verify all pods running
kubectl get pods -A | grep -v Running | grep -v Completed

# Check for pods stuck in Pending (may indicate resource quota or node issues)
kubectl get pods -A --field-selector status.phase=Pending

# Check Deployment Safeguards are active
kubectl get constrainttemplate -A

# Verify VPA is running
kubectl get vpa -A

# Check NAP node pools
az aks nodepool list \
  --resource-group <resource-group> \
  --cluster-name <cluster-name> \
  --query "[].{name:name, mode:mode, osType:osType, count:count}" \
  -o table

# View Container Insights metrics
az aks show \
  --resource-group <resource-group> \
  --name <cluster-name> \
  --query addonProfiles.omsagent.enabled

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill provides comprehensive, production-grade guidance for Azure Kubernetes Service (AKS) with a strong emphasis on security best practices, including Workload Identity, hardened container configurations, and automated readiness assessments.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at a8f19b4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "1.2.2"
}

README badge

README badge for microsoft/skills/azure-kubernetes