finds.dev← search

// the find

mspnp/aks-baseline

★ 751 · Bicep · MIT · updated Oct 2026

This is the Azure Kubernetes Service (AKS) Baseline Cluster reference implementation as produced by the Microsoft Azure Architecture Center.

Microsoft's Patterns & Practices reference implementation of an AKS baseline cluster on a hub-spoke network, written in Bicep and tied to the Azure Architecture Center article of the same name. It is for platform and networking teams who want to understand each layer before they automate one, not for anyone who wants a one-click deploy.

The networking and identity choices are the parts worth reading: Azure Firewall handles managed egress from the hub, Entra ID-backed Kubernetes RBAC with local accounts disabled, managed identities throughout, and Azure CNI Overlay for pod addressing. The deployment docs are split by team responsibility (prerequisites, network, cluster, workload, validation), so you can see who owns each piece. The README also says plainly what it leaves out, including GitOps lifecycle, container security, Windows node pools, and scale-to-zero, which makes it easier to judge what it covers.

The workload is a stock ASP.NET Core sample that the README calls purposefully uninteresting, so the only things it really exercises are ingress and identity wiring. Deployment is a manual walkthrough of CLI and portal steps, which is good for learning and poor as a template; anything repeatable is sent to a separate automation repo. Several dependencies are AKS preview features the README describes as 'Shipped & Improving', so expect some steps to drift as those features reach GA or change. Azure Firewall and Application Gateway WAF carry fixed hourly charges, and the docs do not give a cost estimate, so a learning run can get expensive before you finish the walkthrough.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →