Deploy to AKS
Use when: deploying a web app/API to AKS; containerizing for Kubernetes; generating manifests; AKS CI/CD; DS001–DS013 failures.
Not for: provisioning clusters (azure-kubernetes), AKS Automatic readiness (azure-kubernetes-automatic-readiness), non-AKS targets.
Workflow
Requires: existing AKS cluster, az login, kubectl configured. Follow phases/quick-deploy.md. On failure: references/rollback.md.
References
Knowledge Packs
Load knowledge-packs/frameworks/<framework>.md per detected framework. Available: spring-boot, express, nextjs, fastapi, django, nestjs, aspnet-core, go, flask
Templates
templates/ (dockerfiles/, k8s/, github-actions/, mermaid/).
Usage Notes
Treat the app-deploy workflow as a controlled production change. Confirm the
target subscription, cluster context, namespace, image registry, and rollback
point before generating or applying manifests.
Common Pattern
1. Detect the application framework, port, health endpoint, and build command.
2. Generate the smallest applicable Dockerfile and Kubernetes manifests.
3. Validate the manifests and Deployment Safeguards before changing the cluster.
4. Apply to a non-production namespace or staged environment first.
5. Verify rollout status, probes, logs, service routing, and workload identity.
6. Stop and follow references/rollback.md when verification fails.
Boundaries
- Never invent registry, cluster, subscription, namespace, or secret values.
- Do not replace a working deployment strategy without showing the proposed
manifest diff and obtaining the user's authorization.
- Keep generated credentials out of Docker build arguments, manifests, logs,
and command history.
- Prefer immutable image digests for production rollouts.
- This supplement adds repository quality and safety guidance; the upstream
Microsoft workflow and templates remain authoritative.
1---2name: azure-kubernetes-app-deploy3description: Use when deploying an existing web application or API to an already-running Azure Kubernetes Service cluster. Detects the framework, generates a Dockerfile and Kubernetes manifests, validates against AKS Deployment Safeguards, and deploys with verification. WHEN: deploy app to AKS, deploy to existing AKS cluster, containerize app for Kubernetes, generate K8s manifests for Azure, set up CI/CD for AKS, my AKS deployment is failing safeguard checks, I have a Django/Express/Spring Boot app to run on AKS. DO NOT USE FOR: creating or provisioning an AKS cluster (use azure-kubernetes), assessing migration to AKS Automatic (use azure-kubernetes-automatic-readiness), or deploying to non-AKS targets like Web Apps, Container Apps, or Functions.4license: MIT5---6
7# Deploy to AKS
8
9**Use when:** deploying a web app/API to AKS; containerizing for Kubernetes; generating manifests; AKS CI/CD; DS001–DS013 failures.
10
11**Not for:** provisioning clusters (`azure-kubernetes`), AKS Automatic readiness (`azure-kubernetes-automatic-readiness`), non-AKS targets.
12
13## Workflow
14
15Requires: existing AKS cluster, `az login`, `kubectl` configured. Follow `phases/quick-deploy.md`. On failure: `references/rollback.md`.
16
17## References
18
19- [detection.md](./references/detection.md) — framework/port/health detection
20- [safeguards.md](./references/safeguards.md) — DS001-DS013 checklist
21- [workload-identity.md](./references/workload-identity.md) — Workload Identity setup
22- [rollback.md](./references/rollback.md) — recovery procedures
23- [base-images.md](./references/base-images.md) — base image policy and `<LATEST_STABLE_*>` resolution
24
25## Knowledge Packs
26
27Load `knowledge-packs/frameworks/<framework>.md` per detected framework. Available: `spring-boot`, `express`, `nextjs`, `fastapi`, `django`, `nestjs`, `aspnet-core`, `go`, `flask`
28
29## Templates
30
31`templates/` (dockerfiles/, k8s/, github-actions/, mermaid/).
32
33<!-- LOCAL-QUALITY-SUPPLEMENT:START -->
34## Usage Notes
35
36Treat the app-deploy workflow as a controlled production change. Confirm the
37target subscription, cluster context, namespace, image registry, and rollback
38point before generating or applying manifests.
39
40## Common Pattern
41
42```text
431. Detect the application framework, port, health endpoint, and build command.
442. Generate the smallest applicable Dockerfile and Kubernetes manifests.
453. Validate the manifests and Deployment Safeguards before changing the cluster.
464. Apply to a non-production namespace or staged environment first.
475. Verify rollout status, probes, logs, service routing, and workload identity.
486. Stop and follow references/rollback.md when verification fails.
49```
50
51## Boundaries
52
53- Never invent registry, cluster, subscription, namespace, or secret values.
54- Do not replace a working deployment strategy without showing the proposed
55 manifest diff and obtaining the user's authorization.
56- Keep generated credentials out of Docker build arguments, manifests, logs,
57 and command history.
58- Prefer immutable image digests for production rollouts.
59- This supplement adds repository quality and safety guidance; the upstream
60 Microsoft workflow and templates remain authoritative.
61<!-- LOCAL-QUALITY-SUPPLEMENT:END -->