Azure / Azure/Azure-Verified-Modules

[Module Proposal]: `avm/ptn/aks/secure-baseline`

Open
#2,882 0 comments 0 reactions 0 assignees View on GitHub
Needs: Triage :mag: Type: New Module Proposal :bulb:
Dominant language
PowerShell
Stars
580
Forks
161
Avg merge
11h 3m
Merged PRs (30d)
15

Description

### Check for previous/existing GitHub issues/module proposals

- [x] I have checked for previous/existing GitHub issues/module proposals.

### Check this module doesn't already exist in the module indexes

- [x] I have checked for that this module doesn't already exist in the module indexes.

### Bicep or Terraform?

Bicep

### Module Classification?

Pattern Module

### Module Name

avm/ptn/aks/secure-baseline

### Module Details

Deploying production workloads on AKS requires an integrated platform spanning compute, identity, networking, ingress, security, and observability.

This AVM Pattern Module provides a complete, end-to-end Azure infrastructure solution designed for AKS, including:

• An AKS managed cluster with system and user node pools
• Managed identities and required role assignments
• Virtual networks, subnets, network security groups, and controlled outbound connectivity
• NAT Gateway and public IP resources where applicable
• Azure Front Door, Web Application Firewall, and public or private ingress
• Azure Monitor, Log Analytics, diagnostics, metrics, and alerting
• Service mesh and ingress configuration

Published as a versioned, tested module in the public Bicep registry, the solution can be referenced directly from existing deployment pipelines.

Consumers provide focused inputs for cluster sizing, node pools, networking, ingress, and observability, while the module applies secure defaults and integrates the complete supporting architecture.

This maintained reference solution reduces AKS onboarding effort and avoids requiring each team to independently design and validate the same infrastructure.

### Do you want to be the owner of this module?

Yes

### Module Owner's GitHub Username (handle)

_No response_

### (Optional) Secondary Module Owner's GitHub Username (handle)

_No response_

Contributor guide

No contributing guide indexed for this repository

Research direction

The proposal names no repository files, tests, or entry points. Start by checking the module indexes and existing AKS pattern modules, then determine the repository's requirements for a Bicep module; done means a versioned, tested module covering the listed AKS, networking, ingress, security, and observability components.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, kubernetes
Domain
cloud, devops, infrastructure, networking, observability-sre, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.