Azure Kubernetes Service (AKS) Skill
This skill provides expert guidance for Azure Kubernetes Service (AKS). Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.
How to Use This Skill
IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g.,
L35-L120), useread_filewith the specified lines. For categories with file links (e.g.,[security.md](security.md)), useread_fileon the linked reference file
IMPORTANT for Agent: If
metadata.generated_atis more than 3 months old, suggest the user pull the latest version from the repository. Ifmcp_microsoftdocstools are not available, suggest the user install it: Installation Guide
This skill requires network access to fetch documentation content:
- Preferred: Use
mcp_microsoftdocs:microsoft_docs_fetchwith query stringfrom=learn-agent-skill. Returns Markdown. - Fallback: Use
fetch_webpagewith query stringfrom=learn-agent-skill&accept=text/markdown. Returns Markdown.
Category Index
| Category | Lines | Description |
|---|---|---|
| Troubleshooting | L37-L65 | Troubleshooting AKS clusters, networking, upgrades, workloads, GPU/Windows nodes, Fleet, encryption, DNS, logging, and add-ons using tools like ACNS, Desktop Insights, CanIPull, and NPD. |
| Best Practices | L66-L116 | Operational best practices for AKS: upgrades, scaling, cost optimization, security/compliance, networking, storage, GPUs, multi-tenancy, and workload reliability/resiliency. |
| Decision Making | L117-L171 | Guidance for planning and decision-making on AKS migrations, networking, scaling, upgrades, cost optimization, platform/tier choices, compliance (PCI), and comparing AKS with other platforms. |
| Architecture & Design Patterns | L172-L200 | Designing resilient, compliant AKS architectures: HA/DR patterns, multi-region and PCI designs, networking/ingress choices, GPU and node pool layouts, Fleet multi-cluster rollout and placement. |
| Limits & Quotas | L201-L227 | AKS capacity, limits, SLAs, and support policies: quotas, node/pod/network constraints, autoscaling behavior, Istio/KEDA performance, version/LTS lifecycle, and system node pool/load balancer scaling. |
| Security | L228-L311 | Securing AKS clusters: identity and access control, network isolation, encryption, compliance (CIS/PCI), policies, managed identities, certificate/secret management, and secure node/workload configs. |
| Configuration | L312-L468 | Configuring AKS clusters, networking, storage, GPUs, autoscaling, security, and add-ons (Istio, CNI, App Config, Fleet, etc.), plus infra patterns for databases, Kafka, Ray, and monitoring. |
| Integrations & Coding Patterns | L469-L495 | Patterns and code for integrating AKS with AI toolchains, KAITO, Ray, storage, secrets, observability, autoscaling, dev tools, and external services (MCP, Istio, KEDA, Key Vault, etc.). |
| Deployment | L496-L548 | Deploying and upgrading AKS clusters and apps, including CI/CD, service meshes, autoscaling, storage and networking migrations, AI/ML and Wasm workloads, and cross-cloud app migration. |