Azure AKS in Production: Complete Guide
Cloud

Azure AKS in Production: Complete Guide

April 7, 202511 min readAzureAKSKubernetes

Azure Kubernetes Service (AKS) is Microsoft's managed Kubernetes offering. Networking, identity, auto-scaling, monitoring, costs: everything you need to run a solid AKS cluster in production.

Why AKS Over a Self-Managed Cluster?

Azure Kubernetes Service delegates control plane management (API server, etcd, scheduler, controller manager) to Microsoft. You only pay for worker nodes — the control plane is free. In return, you get automatic upgrades, a 99.95% SLA on the API server with Availability Zones, and native integration with the Azure ecosystem (Azure AD, Azure Monitor, Azure Container Registry, Azure Load Balancer).

AKS is particularly well-suited to teams that want Kubernetes without the operational overhead of a kubeadm or kops cluster. It is available in all Azure regions, including France Central for data sovereignty requirements.

AKS Reference Architecture

A typical production AKS architecture is built around these components:

  • Dedicated VNet with a subnet for nodes and a subnet for pods (Azure CNI)
  • System node pool: 3 Standard_D4s_v5 nodes spread across 3 Availability Zones for the application control plane (CoreDNS, konnectivity)
  • User node pools: dedicated pools by workload type (general, GPU, spot)
  • Azure Container Registry (ACR): attached to the cluster with the AcrPull role on the managed identity
  • Azure Key Vault: secrets injected via the CSI driver without going through native Kubernetes secrets
  • Azure Application Gateway (AGIC) or NGINX Ingress Controller for HTTP/HTTPS exposure

Networking: Azure CNI vs Kubenet

Criterion Azure CNI Kubenet
Pod IPReal VNet IPPrivate IP (NAT)
IP planningCritical (1 IP/pod)Flexible
VNet peering✅ Native⚠️ Manual routes
Network PolicyAzure / CalicoCalico only
Recommended forProductionDev / small clusters

In production, choose Azure CNI Overlay (available since 2023), which combines Azure CNI advantages without the strict IP planning constraint — pods receive IPs from an overlay address space that is not routed in the VNet.

Identity and Security: Workload Identity

The old AAD Pod Identity approach is deprecated. In 2025, the reference is Azure Workload Identity, based on OIDC federation:

  1. AKS issues an OIDC token for each ServiceAccount
  2. An Azure Managed Identity is configured with a federated credential pointing to the AKS OIDC issuer
  3. The pod mounts the OIDC token via a projected volume
  4. The Azure SDK automatically exchanges this token for an Azure AD access token

Result: no API keys in Kubernetes secrets, no manual rotation. The pod accesses Key Vault, Blob Storage, or any Azure service with a managed identity.

Auto-Scaling: Cluster Autoscaler and KEDA

  • Horizontal Pod Autoscaler (HPA): scales pods based on CPU/memory or custom metrics
  • Cluster Autoscaler: adds or removes nodes based on pending pods. Configure --scale-down-delay-after-add=10m to avoid flapping
  • KEDA: scales on external metrics — Azure Service Bus queue length, Event Hub message count, Prometheus metrics. KEDA can scale to 0 pods (useful for batch workers)

Monitoring: Azure Monitor + Managed Prometheus

Since 2023, AKS offers Managed Prometheus (Azure Monitor Workspace) and Managed Grafana as an alternative to self-hosting. Activation is a single command, and standard Kubernetes dashboards (Nodes, Pods, Namespaces, API server) are pre-configured. For logs, Container Insights sends stdout/stderr logs to a Log Analytics Workspace with configurable retention.

Updates and Maintenance

  • Enable auto-upgrades in patch mode for automatic security patches
  • Configure a maintenance window (e.g., Sunday 2–5am) to control when upgrades apply
  • Use node image auto-upgrade separately for node OS images (CVE patches without changing the K8s version)
  • For minor version upgrades, test first on a staging cluster with the same workload profile

Cost Optimisation

  • Reserved Instances on system node pools (3 years = ~55% savings)
  • Spot Node Pools for batch workers and dev environments
  • Start/Stop cluster: shut down dev clusters outside business hours (~70% savings)
  • Enable VPA in "Off" mode (recommendations without auto-action) to identify over-provisioned pods

Conclusion

AKS is a mature Kubernetes service, particularly suited to enterprises already in the Microsoft Azure ecosystem. Its native integration with Azure AD (Workload Identity), Azure Monitor, and IaC tooling (Bicep, Terraform) makes it a solid choice for teams that want Kubernetes without compromising on security and observability.

Move2Cloud supports its clients in designing and running AKS clusters in production, from network architecture to GitOps pipeline setup with ArgoCD or Flux.

← Back to blog