Azure / Azure/Azure-Verified-Modules
[Module Proposal]: `avm/ptn/aks/secure-baseline`
- Dominant language
- PowerShell
- Stars
- 580
- Forks
- 161
- Avg merge
- 11h 3m
- Merged PRs (30d)
- 15
Description
### Check for previous/existing GitHub issues/module proposals
- [x] I have checked for previous/existing GitHub issues/module proposals.
### Check this module doesn't already exist in the module indexes
- [x] I have checked for that this module doesn't already exist in the module indexes.
### Bicep or Terraform?
Bicep
### Module Classification?
Pattern Module
### Module Name
avm/ptn/aks/secure-baseline
### Module Details
Deploying production workloads on AKS requires an integrated platform spanning compute, identity, networking, ingress, security, and observability.
This AVM Pattern Module provides a complete, end-to-end Azure infrastructure solution designed for AKS, including:
• An AKS managed cluster with system and user node pools
• Managed identities and required role assignments
• Virtual networks, subnets, network security groups, and controlled outbound connectivity
• NAT Gateway and public IP resources where applicable
• Azure Front Door, Web Application Firewall, and public or private ingress
• Azure Monitor, Log Analytics, diagnostics, metrics, and alerting
• Service mesh and ingress configuration
Published as a versioned, tested module in the public Bicep registry, the solution can be referenced directly from existing deployment pipelines.
Consumers provide focused inputs for cluster sizing, node pools, networking, ingress, and observability, while the module applies secure defaults and integrates the complete supporting architecture.
This maintained reference solution reduces AKS onboarding effort and avoids requiring each team to independently design and validate the same infrastructure.
### Do you want to be the owner of this module?
Yes
### Module Owner's GitHub Username (handle)
_No response_
### (Optional) Secondary Module Owner's GitHub Username (handle)
_No response_
Contributor guide
No contributing guide indexed for this repository
Research direction
The proposal names no repository files, tests, or entry points. Start by checking the module indexes and existing AKS pattern modules, then determine the repository's requirements for a Bicep module; done means a versioned, tested module covering the listed AKS, networking, ingress, security, and observability components.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, kubernetes
- Domain
- cloud, devops, infrastructure, networking, observability-sre, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100