Curated documentation updates, feature announcements, community blogs, release highlights, and more.
Welcome to the August 2026 edition of the AKS Newsletter.
This month brings 7 features reaching General Availability and 2 new Preview announcements. Here are some of the highlights:
Let's dive in.
Generally Available: Control plane metrics collection for AKS with Managed Prometheus: The general availability of control plane metrics collection for AKS, powered by Azure Monitor Managed Service for Prometheus, provides engineers with native observability into critical control plane components. This enhancement is crucial for maintaining optimal performance and troubleshooting within AKS environments.
Generally Available: Connect to AKS clusters using Azure Bastion: Azure Bastion's integration with AKS is now generally available, allowing secure and seamless access to AKS clusters without the need for public IPs. This development simplifies network security management and enhances the security posture of Kubernetes deployments.
Node Auto Provisioning – now generally available: Node Auto Provisioning can now be activated on clusters with restricted publicNetworkAccess, including those with private API server VNet integration using UDR, provided AKS-wide networking guardrails are met. This feature is vital for dynamic scaling and resource optimization in secure environments.
Automatic availability zone placement – now generally available: Automatic availability zone placement is now globally enabled, allowing AKS to automatically distribute nodes across availability zones for improved resilience and fault tolerance. This feature simplifies cluster setup and enhances reliability without manual configuration.
Long Term Support (LTS) – now generally available: AKS now offers Long Term Support (LTS) for clusters, provided the version skew policy is adhered to. This ensures stability and extended support for critical workloads, making it easier for teams to plan upgrades and maintenance.
AKS Node pool Rollback – now generally available: The AKS Node pool Rollback feature is now generally available, allowing engineers to revert node pool versions in case of issues during upgrades. This capability is essential for maintaining cluster stability and minimizing downtime during updates.
Encryption in Transit – now generally available: Encryption in Transit for Azure Files using the Azure File CSI driver is now generally available, along with workload identity access. This enhancement is critical for securing data as it moves between services, ensuring compliance and data integrity.
Prepared Image Specification (PIS) (preview): This feature introduces a new way to define and manage container images in AKS, streamlining the deployment process by allowing pre-defined image configurations. It's a game-changer for teams looking to standardize deployments and reduce image pull times.
Capacity Reservation Group with an existing node pool (preview): This preview feature allows AKS users to associate capacity reservation groups with existing node pools, ensuring that critical workloads have guaranteed resource availability. It's essential for maintaining performance and reliability in environments with fluctuating demand.
SSH node access: Configuration changes now trigger an immediate node reimage, ensuring that any SSH access adjustments are applied promptly, enhancing security and compliance.
IMDS restriction: Implementing a network-isolated bootstrap profile or altering the cluster outbound type will now cause an immediate node reimage, which is crucial for maintaining isolation and security standards.
rolling upgrade behaviors: Updated to include new options for customizing the number of unavailable nodes during upgrades, providing more control over application availability and resource management during rolling updates.
managed identity: Changes to managed identities now trigger node reimages across node pools, ensuring that identity configurations are consistently applied and reducing potential security risks.
'Configure rolling upgrade settings': Updated to provide detailed guidance on configuring rolling upgrade settings, allowing for more precise control over upgrade processes and minimizing downtime.
Istio Gateway API: Deployments now default to automountServiceAccountToken set to false, enhancing security by preventing unnecessary token exposure and aligning with Azure Policies that enforce stricter security measures.
GPU MIG: Adjustments ensure that instance profile slice widths are compatible with VM SKU capacities, preventing the acceptance of unsupported MIG profiles on lower-capacity GPU SKUs, thus avoiding resource allocation issues.
Application Gateway for Containers ALB add-on: Now aligned with AKS minor versions, ensuring compatibility and reducing the risk of integration issues during updates.
Entra ID SSH: Configuration changes on AzureContainerLinux node pools are critical as the extension is incompatible with immutable OS nodes, which can lead to nodes becoming unreachable, highlighting the importance of compatibility checks.
Deploy CanIPull to an Azure Kubernetes Service (AKS) cluster: This guide enhances the deployment process of CanIPull on AKS, focusing on DNS resolution and the Azure Container Registry token exchange. Essential for engineers looking to streamline container registry interactions.
Use Virtual Machines Node Pools in Azure Kubernetes Service (AKS): Updated to include guidance on integrating multiple VM types within a node pool, providing flexibility in resource management and cost optimization for AKS deployments.
Zero-Downtime Migration to Azure Kubernetes Service (AKS): This documentation now includes strategies for zero-downtime application releases, crucial for maintaining service continuity during migrations or updates.
Network security best practices for Azure Kubernetes Service (AKS): Refreshed with improved strategies for network exposure management, this guide is vital for securing AKS clusters against unauthorized access and data breaches.
Best practices for scheduler features in Azure Kubernetes Service (AKS): Enhanced with examples of dedicated AKS node pools, this update aids in optimizing resource allocation and workload distribution using advanced scheduling features.
Create and Manage Persistent Volumes with Azure Files in Azure Kubernetes Service (AKS): Now includes a general-purpose Azure Files CSI example, this documentation is key for implementing scalable storage solutions in AKS environments.
Use Confidential Virtual Machines (CVMs) in Azure Kubernetes Service (AKS): Updated to correct the default OS version for Ubuntu, this guide ensures secure and compliant deployment of CVM node pools in AKS.
Reduce Time to Deployment with Artifact Streaming on Azure Kubernetes Service (AKS): This update, featuring a header change for clarity, highlights how Artifact Streaming can significantly cut deployment times and reduce idle compute costs.
Deployment and Cluster Reliability Best Practices for Azure Kubernetes Service (AKS): Now includes reliability checklists, this documentation is critical for maintaining robust and dependable AKS deployments.
Use Microsoft Entra ID Authorization for the Kubernetes API in Azure Kubernetes Service (AKS): Updated with the latest Entra ID authorization methods, this guide is essential for secure API access management in AKS.
Secure Pod Traffic with Network Policies in Azure Kubernetes Service (AKS): Enhanced with updated network policies, this documentation is crucial for implementing least privilege access and securing pod communications.
Monitor Azure Kubernetes Service (AKS): Updated to provide a comprehensive overview of AKS monitoring capabilities, integrating Azure services for enhanced performance insights.
Managed Identities in Azure Kubernetes Service (AKS) Overview: This overview now includes updated information on managed identities, crucial for secure identity management and role assignments in AKS.
Set up GPU profiling on Azure Kubernetes Service (AKS) (Preview): Now includes instructions for using Azure Blob Storage as a Pyroscope backend, this guide is vital for optimizing GPU resource usage in AKS.
Monitor AKS Control Plane Metrics: Corrected code block formatting enhances the clarity of this guide, which is essential for monitoring and maintaining AKS control plane health.
Configure Azure CNI Powered by Cilium in Azure Kubernetes Service (AKS): Updated to include the latest Cilium versions, this documentation is crucial for implementing advanced networking configurations in AKS.
Establish network connectivity to a private Azure Kubernetes Service (AKS) cluster: Expanded guidance on private AKS VM access provides essential information for securely connecting to private clusters.
AKS Scaling Overview — HPA, VPA, Cluster Autoscaler, and KEDA: Improved retrievability of scaling options helps engineers choose the optimal scaling method for their specific workload requirements.
Azure Policy Regulatory Compliance controls for Azure Kubernetes Service (AKS): Fixes to policy paths ensure accurate compliance management, providing a reliable framework for maintaining regulatory standards in AKS.
Manage SSH access on Azure Kubernetes Service cluster nodes: Updated to reflect limitations on Entra ID SSH access, this guide is crucial for secure SSH management on AKS nodes.
Configure rolling upgrades for Azure Kubernetes Service (AKS) node pools: Clarifications on max surge settings and removal of redundancy enhance this guide, essential for managing rolling upgrades in AKS node pools.
Configure Azure DNS and TLS with the Application Routing Gateway API Implementation: Updated to reference the App Routing Gateway API implementation on Istio, this documentation is key for managing DNS and TLS configurations in AKS.
Simplify AKS observability with Azure Native New Relic Service: This post introduces the Azure Native New Relic Service, streamlining observability for AKS environments. By integrating New Relic's intelligent observability directly into Azure, platform engineers can achieve more seamless monitoring and diagnostics, enhancing operational efficiency.
Beyond Deployment: What It Really Takes to Run GitHub Actions Runners on AKS: This article explores the complexities of running GitHub Actions Runners on AKS beyond initial deployment. It highlights the challenges of scaling, security, and maintenance, providing insights crucial for engineers aiming to transition from a demo to a robust production environment.
Container Network Insights Agent (CNIA): Your AI Teammate for AKS Networking Incidents: The CNIA is introduced as an AI-powered tool for managing AKS networking incidents. This agent aids engineers by providing real-time insights and diagnostics, significantly reducing the time to resolution for network-related issues.
Accelerate Inference on AKS with Azure Blob Storage and NVIDIA Dynamo: This blog discusses leveraging Azure Blob Storage and NVIDIA Dynamo to accelerate machine learning inference on AKS. By optimizing data access and processing speeds, engineers can enhance the performance of AI workloads, making AKS a more powerful platform for ML applications.
Evoluindo a Resposta a Incidentes em AKS com Azure SRE Agent - Parte 1: Part one of this series delves into improving incident response in AKS using the Azure SRE Agent. It provides a detailed look at integrating the agent into your AKS environment to streamline incident management and improve overall system reliability.
Cloud-Native Multi-Agent: Running Agents Safely on Kubernetes with Kars: This post explores the use of Kars for running multiple agents securely on Kubernetes. By enabling encrypted communication across different frameworks, engineers can manage diverse agent ecosystems efficiently, from local development to production-grade AKS deployments.
MVP Spotlight: Richard Hooper on AKS Service mesh, Multi-cluster management and Open source: Join Jorge Arteiro as he talks to Richard Hooper about Azure Kubernetes Service (AKS). They discuss various topics such as Service Mesh, multi-cluster management & open source projects and community contributions.
MVP Spotlight: Tobias Fenster on AKS Windows Containers and AI Runway: Join Jorge Arteiro talks to Tobias Fenster about Azure Kubernetes Service (AKS) Windows Containers and AI Runway.
AKS Community Calls - August 2026: Agenda - August 2026
Troubleshoot Outbound connectivity Issues with Ping He: AKS Troubleshooting Series: Azure Kubernetes: In today's episode, we talk to Ping He to understand how we can troubleshoot scaling issues with Azure Kubernetes Service (AKS) clusters.
AKS desktop: Deploy, Manage, & Scale Apps on Kubernetes in Minutes: This walkthrough shows how AKS desktop simplifies deploying, managing, and scaling Kubernetes applications.
August 2026 brought 9 platform announcements alongside updates to operations, documentation, and the AKS community.
The strongest threads in this edition were Networking capabilities, Observability and monitoring, Security and identity, AI and GPU workloads, Scaling and node management, Storage, and Multi-cluster and fleet management.
The supporting coverage spans behavioral changes, documentation improvements, and hands-on videos, giving platform teams both the product changes and the context to act on them.
Use this edition as a starting point for reviewing the changes most relevant to your AKS environments before the next monthly update.