feature(aks): Harden and extend AKS for production readiness#1189
Closed
rmvangun wants to merge 1 commit into
Closed
feature(aks): Harden and extend AKS for production readiness#1189rmvangun wants to merge 1 commit into
rmvangun wants to merge 1 commit into
Conversation
The AKS module required a few enhancements to prepare it for production use. These include: * Introducing the `single` storage class for consistency with EKS * Allow toggling disk encryption * Enable azure monitor diagnostics * Enable toggling container insights * Allow configuring various k8s API access schemes * Enable multiple AZs * Use workload identity * Include image cleaner * Expand cilium configuration * Default to outbound type to use `userAssignedNATGateway` * Add `Network Contributor` role to cluster to support the custom VNet * Add disk management role so nodes can manage disks, snapshots * Allow toggling disk encryption * Default to OIDC based access to k8s api, and default to assigning an AKS admin role to the active user applying the terraform * Include kubelogin in aqua as it's required to connect to the k8s api Signed-off-by: Ryan VanGundy <85766511+rmvangun@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The AKS module required a few enhancements to prepare it for production use. These include:
singlestorage class for consistency with EKSuserAssignedNATGatewayNetwork Contributorrole to cluster to support the custom VNetSigned-off-by: Ryan VanGundy 85766511+rmvangun@users.noreply.github.com