Azure AKS cluster build: identity, networking, and node pools in one pass
A production-grade AKS cluster in one coherent pass: managed identity, Azure CNI networking, system/user node pool split, workload identity, and monitoring. Doing these as afterthoughts means rebuilding the cluster.
az aks create -g [rg] -n [cluster] --enable-managed-identity --enable-oidc-issuer --enable-workload-identity --network-plugin azure --node-count 3 --generate-ssh-keysDecisions to make before create (most cannot change later):
- Identity.
--enable-managed-identity(never service principal; SP secrets expire and break the cluster). - Network plugin. Azure CNI (now with overlay options) for VNet integration; kubenet only for tiny dev clusters. Plugin choice is immutable.
- Node pools. System pool (taint CriticalAddonsOnly, small VMs) + user pool(s) for workloads. Separate pools let you scale/upgrade workloads without touching system pods.
- Workload identity + OIDC. Enable at create; retrofitting works but enabling day one means every workload uses it from the start.
- Private cluster?
--enable-private-clusterhides the API server. Great for security, but then CI and admin kubectl need VNet access (VPN/ExpressRoute or a jump box). Decide before CI is built. - Monitoring.
--enable-addons monitoringfor Container Insights. Retrofitting is fine, but day-one metrics make the first incident debuggable. - Upgrades. Set
--auto-upgrade-channel patchorstable; unpatched clusters age into unsupported versions and upgrades get painful.
Traps:
- Creating with the default kubenet then needing VNet features = rebuild.
- Forgetting
--enable-oidc-issuerand discovering workload identity cannot be enabled later without it (it can be enabled later via update, but do it now). - Cluster in the wrong subscription/VNet peering missing = nodes cannot reach private backends.
Verify: kubectl get nodes shows system + user pools, az aks show shows OIDC issuer URL, and a test workload with workload identity can reach its backend.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.