<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>AKS Newsletter</title>
    <link>https://aksnewsletter.com</link>
    <description>Monthly curated updates on Azure Kubernetes Service — docs, features, blogs, releases, and more.</description>
    <language>en-us</language>
    <atom:link href="https://aksnewsletter.com/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>AKS Newsletter – June 2026</title>
      <link>https://aksnewsletter.com/2026/2026-06.html</link>
      <guid isPermaLink="true">https://aksnewsletter.com/2026/2026-06.html</guid>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
      <description>65 curated items covering documentation updates, feature announcements, community blogs, and more.</description>
      <content:encoded><![CDATA[
<p>Welcome to the June 2026 edition of the AKS Newsletter.</p>
<p>This month brings <strong>7 features reaching General Availability</strong> and <strong>2 new Preview announcements</strong>. Here are some of the highlights:</p>
<ul>
<li><strong>Generally available: Managed system node pools in AKS Automatic</strong> is now generally available</li>
<li><strong>Application Gateway for Containers</strong> is now generally available</li>
<li><strong>Ubuntu 22.04 node pools with FIPS 140-3 compliance</strong> is now generally available</li>
<li><strong>Anyscale on Azure</strong> enters public preview</li>
<li><strong>Application Gateway for Containers – Inference gateway</strong> enters public preview</li>
</ul>
<p>Let&#39;s dive in.</p>
<hr>
<h2>✅ General Availability Announcements</h2>
<ul>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/562919/?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Generally available: Managed system node pools in AKS Automatic</a></strong>: Managed system node pools are now generally available, simplifying the operational overhead of scaling, patching, and maintaining system-critical workloads. This feature ensures higher availability and reduced manual intervention for platform engineers.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/application-gateway/for-containers/overview?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Application Gateway for Containers – now generally available</a></strong>: Application Gateway for Containers is now fully supported, offering a managed ingress solution tailored for containerized workloads. This enables advanced traffic routing, SSL termination, and security features directly integrated with AKS.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/fips?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Ubuntu 22.04 node pools with FIPS 140-3 compliance – now generally available</a></strong>: Ubuntu 22.04 node pools with FIPS 140-3 compliance are now GA, providing enhanced security for workloads requiring strict cryptographic standards. This is particularly relevant for regulated industries like finance and government.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/gpu-cluster?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Managed GPUs – now generally available</a></strong>: Managed GPU support in AKS is now generally available, enabling seamless provisioning and scaling of GPU-enabled node pools. This is a game-changer for teams running AI/ML workloads or other GPU-intensive applications.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/cvm?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Confidential VMs (CVM) – now generally available</a></strong>: Confidential VMs are now GA on AKS with Azure Linux, offering hardware-based encryption to protect data in use. This is a critical feature for organizations prioritizing data confidentiality and compliance.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/upgrade-windows-os-version?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Windows Server 2025 – now generally available</a></strong>: Windows Server 2025 is now supported in AKS, allowing teams to modernize their Windows-based applications while leveraging the latest OS features. This ensures better performance, security, and compatibility for Windows containers.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/azure-linux/azure-container-linux-overview?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Azure Container Linux – now generally available</a></strong>: Azure Container Linux is now a GA OS option for AKS starting with version 1.34. This lightweight, secure, and optimized Linux distribution is tailored for containerized workloads, offering a streamlined experience for AKS users.</p>
</li>
</ul>
<hr>
<h2>🧪 Preview Feature Announcements</h2>
<ul>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/562934/?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Public Preview: Anyscale on Azure</a></strong>: Introduces a managed Ray platform for scaling Python-based machine learning workloads in the cloud. This preview empowers engineers to handle massive computational tasks with improved speed and control, making it a game-changer for AI-driven applications.</p>
</li>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/566516/?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Public Preview: Application Gateway for Containers – Inference gateway</a></strong>: Expands the Application Gateway for Containers with AI inference capabilities, enabling seamless integration of machine learning models into containerized applications. This enhancement simplifies deploying and scaling AI-powered services in Kubernetes environments.</p>
</li>
</ul>
<hr>
<h2>🔁 Behavioral Changes</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/istio-gateway-api?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Istio Service Mesh with Gateway API</a></strong>: Clusters running Kubernetes 1.36 or later can now disable the default application routing add-on with Gateway API to use the Istio-based service mesh add-on with Istio CNI. This provides flexibility for teams adopting Istio while maintaining control over their networking setup.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/deployment-safeguards?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Deployment Safeguards</a></strong>: Enforce mode now applies default resource requests to DaemonSets and Jobs when those requests are missing, in addition to Deployments and StatefulSets. Additionally, with Pod Security Standards set to Baseline, pods on Automatic clusters can now read <code>/var/log</code> and <code>/hostfs</code> hostPath volumes (read-only), supporting log exporter scenarios while maintaining security.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/azure-monitor/containers/prometheus-metrics-scrape-configuration?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Custom Prometheus Metric Scraping</a></strong>: Now supports metric scraping and log collection on AKS Automatic clusters using managed system node pools. This enhances observability for teams leveraging Prometheus in managed environments.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/configure-azure-cni-static-block-allocation?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Azure CNI Static Block Allocation</a></strong>: VnetScale clusters no longer require explicit pod CIDR configuration. This simplifies network setup and reduces configuration errors for large-scale deployments.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-group-managed-service-accounts?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Windows gMSA</a></strong>: Now validates CoreDNS configurations for conflicts when using group-managed service accounts. This ensures smoother integration and prevents runtime issues.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-pod-sandboxing?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Pod Sandboxing (Kata)</a></strong>: Pod sandboxing is now supported for workload runtime node pools, and node pools using <code>Standard_DadsV7</code>-series VM sizes are now available (resolving previous nested-virtualization validation issues). This expands both the isolation scope and hardware options for teams adopting Kata containers.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/intro-aks-automatic?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">AKS Automatic</a></strong>: Managed system node pools are now available under the AKS Base SKU. This streamlines cluster management for teams leveraging AKS Automatic.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/istio-cni?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Istio CNI</a></strong>: Istio CNI integration now supports advanced networking features, enabling seamless service mesh deployment with enhanced network security and performance.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/upgrade-windows-os?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Migration Guide</a></strong>: Updated to provide detailed steps for migrating workloads to supported Windows Server versions. Essential for teams preparing for upcoming OS retirements.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/ws2019-retirement-github?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Windows Server 2019 Retirement Guide</a></strong>: Comprehensive guidance on transitioning from Windows Server 2019, which is approaching its end-of-support date. A must-read for teams running legacy Windows workloads.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/azure-linux/tutorial-migrate-azure-container-linux-aks?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Azure Container Linux for AKS</a></strong>: Introduces a migration path to Azure Container Linux for AKS users. This is a significant update for teams looking to adopt a modern, secure, and optimized container OS.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/managedsystemnodepools?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Managed System Node Pools</a></strong>: Now generally available for AKS Automatic clusters. This feature simplifies operations by offloading node pool management to Azure.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/localdns-custom?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">LocalDNS</a></strong>: LocalDNS is now set to <code>Required</code> by default for new node pools in Automatic clusters. This change improves DNS resolution performance and reliability for Kubernetes workloads.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/deployment-safeguards#excluding-namespaces?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Edit the <code>excludedNamespaces</code> Field for Deployment Safeguards</a></strong>: Teams can now control which policies apply to specific namespaces on Automatic clusters by editing the <code>excludedNamespaces</code> field. This provides greater flexibility in policy enforcement.</p>
</li>
<li><p><strong><a href="https://kubernetes.io/blog/2026/05/14/kubernetes-v1-36-deprecation-and-removal-of-service-externalips/?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Upstream Deprecation of Service externalIPs</a></strong>: Kubernetes has announced the deprecation of Service externalIPs in version 1.36. Platform engineers should evaluate their reliance on this feature and plan for alternative solutions.</p>
</li>
</ul>
<hr>
<h2>🔎 Documentation Updates</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/azure-cni-powered-by-cilium?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Configure Azure CNI Powered by Cilium in Azure Kubernetes Service (AKS)</a></strong>: Updated to reflect the inclusion of Azure CNI powered by Cilium as the default networking configuration for AKS Automatic clusters. This change simplifies networking setup while offering enhanced scalability and performance for Kubernetes workloads.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/workload-identity-overview?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Use a Microsoft Entra Workload ID on Azure Kubernetes Service (AKS)</a></strong>: Expanded with details on how Microsoft Entra Workload ID is preconfigured in AKS Automatic clusters. This update is crucial for teams looking to streamline identity management and secure application authentication.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-nvidia-gpu?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Use GPUs on Azure Kubernetes Service (AKS)</a></strong>: Refreshed with guidance on leveraging managed GPU features as the primary approach for GPU workloads, while also detailing self-managed alternatives. This ensures optimal performance for compute-intensive applications.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/node-auto-provisioning-aksnodeclass?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Configure AKSNodeClass Resources for Node Auto-Provisioning (NAP) in Azure Kubernetes Service (AKS)</a></strong>: Updated to include the latest default OS version information for Ubuntu in AKSNodeClass configurations. This is essential for teams using node auto-provisioning to ensure compatibility and security.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/configure-aks-scheduler?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Configure Scheduler Profiles on Azure Kubernetes Service (AKS) (preview)</a></strong>: Enhanced with updated instructions for configuring scheduler profiles, enabling more advanced scheduling behaviors. This is a key feature for optimizing workload placement and resource utilization.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/tutorial-kubernetes-deploy-application?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Kubernetes on Azure tutorial - Deploy an application to Azure Kubernetes Service (AKS)</a></strong>: Refined to include the latest RabbitMQ version and streamlined configurations for deploying multi-container applications. This ensures a smoother onboarding experience for new AKS users.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/intro-aks-automatic?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Introduction to Azure Kubernetes Service (AKS) Automatic</a></strong>: Updated to remove outdated limitations and provide a clearer overview of AKS Automatic features. This is a must-read for teams seeking simplified containerized application management.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-node-public-ips?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Use instance-level public IPs in Azure Kubernetes Service (AKS)</a></strong>: Clarified feature flag registration requirements for enabling dual-stack IPs. This is critical for teams managing public-facing workloads with complex networking needs.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/long-term-support?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Long-Term Support for Azure Kubernetes Service (AKS) Versions</a></strong>: Updated to document that ACC SGX is not supported for AKS Long-Term Support (LTS) versions. This ensures clarity for teams relying on LTS for stability and compliance.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/localdns-custom?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Configure LocalDNS in Azure Kubernetes Service (AKS)</a></strong>: Added a note about TCP connection caps when using LocalDNS. This update is crucial for teams optimizing DNS resolution performance and resiliency in their clusters.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/learn/quick-kubernetes-deploy-powershell?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Quickstart: Deploy an Azure Kubernetes Service (AKS) cluster using Azure PowerShell</a></strong>: Refreshed to ensure the PowerShell quickstart guide remains accurate and up-to-date. A great resource for rapidly deploying AKS clusters via scripting.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-capacity-reservation-groups?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Assign Capacity Reservation Groups to Node Pools in Azure Kubernetes Service (AKS)</a></strong>: Improved with better code block formatting and corrected author attribution. This update helps teams guarantee capacity for critical workloads.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/supported-kubernetes-versions?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Supported Kubernetes Versions in Azure Kubernetes Service (AKS)</a></strong>: Expanded with a breaking changes table for Kubernetes 1.36 component versions. This is essential for planning upgrades and avoiding disruptions.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/istio-gateway-api?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Kubernetes Gateway API Ingress for Istio Service Mesh Add-on for Azure Kubernetes Service (AKS)</a></strong>: Updated with new configurations for GatewayClass and Gateway resources. This is vital for teams using Istio with Kubernetes Gateway API for ingress management.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/app-routing-gateway-api?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Azure Kubernetes Service (AKS) application routing add-on with the Kubernetes Gateway API</a></strong>: Enhanced with notes on access logs for the application routing add-on. This helps teams monitor and troubleshoot ingress traffic more effectively.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/aks-end-of-support-notifications?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">AKS end of support notifications</a></strong>: Refined metadata and instructions for setting up alerts on Kubernetes version end-of-support notifications. This ensures teams stay ahead of deprecation timelines.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/create-node-pools?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Create Node Pools in Azure Kubernetes Service (AKS)</a></strong>: Updated with the latest guidance on configuring multiple node pools in AKS. A must-read for teams scaling their clusters efficiently.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/concepts-network-isolated?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Network isolated AKS clusters</a></strong>: Revised to address limitations related to bring-your-own Azure Container Registry (ACR) in network-isolated clusters. This is critical for teams prioritizing security and compliance in their deployments.</p>
</li>
</ul>
<hr>
<h2>📚 Community Blogs</h2>
<ul>
<li><p><strong><a href="https://blog.aks.azure.com/2026/06/15/get-anyscale-on-azure-up-and-running-with-terraform?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Deploy Anyscale on Azure with Terraform: a step-by-step guide</a></strong>: This guide walks through deploying Anyscale on Azure using Terraform, enabling distributed AI/ML workloads with Ray on AKS. The integration with Microsoft Entra ID for SSO and the operator-based deployment model make it a compelling choice for platform engineers managing enterprise-scale AI.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/06/10/app-routing-gateway-api-ga?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">App Routing Gateway API is GA: Here&#39;s a Demo</a></strong>: The AKS App Routing add-on now fully supports the Kubernetes Gateway API with its GA release. This milestone ensures first-class support for Gateway API CRDs, controllers, and data planes, streamlining ingress management for modern Kubernetes applications.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/06/02/aks-baremetal-public-preview?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Announcing the public preview of AKS on bare metal</a></strong>: AKS expands its reach with support for bare metal, targeting edge deployments and high-performance workloads. This preview is a game-changer for teams needing Kubernetes in environments where traditional cloud infrastructure isn&#39;t viable.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/06/02/dynamo-on-aks-part-4?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Scaling multi-node LLM inference with NVIDIA Dynamo-Grove on AKS (Part 4)</a></strong>: NVIDIA engineers detail how to scale large language model (LLM) inference across multiple nodes using Dynamo-Grove on AKS. This deep dive is essential for teams working on high-demand AI applications requiring distributed GPU workloads.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/microsoftmechanicsblog/secure-containers-from-code-to-runtime-microsoft-defender/4531871?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Secure containers from code to runtime | Microsoft Defender</a></strong>: This post highlights container security best practices, from development to runtime, using Microsoft Defender. It emphasizes mitigating supply chain risks and securing workloads running on AKS.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azureobservabilityblog/accelerating-aks-troubleshooting-with-the-azure-copilot-observability-agent/4528517?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Accelerating AKS troubleshooting with the Azure Copilot Observability Agent</a></strong>: The Azure Copilot Observability Agent simplifies troubleshooting for AKS by providing unified telemetry and actionable insights. Platform engineers can leverage this tool to quickly diagnose and resolve issues in Kubernetes environments.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/closing-the-loop-on-container-security-from-code-to-runtime-in-the-ai-era/4528599?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Closing the loop on container security: From code to runtime in the AI era</a></strong>: With AI workloads increasingly running in containers, this blog explores end-to-end security strategies for AKS, EKS, and GKE. It underscores the importance of securing the entire lifecycle, from development to deployment.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azuredevcommunityblog/getting-secrets-out-of-yaml-implementing-azure-key-vault-csi-driver-on-aks-with-/4522590?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Getting Secrets Out of YAML: Implementing Azure Key Vault CSI Driver on AKS with Workload Identity</a></strong>: This blog demonstrates how to replace hardcoded secrets in YAML files with the Azure Key Vault CSI Driver and Workload Identity. It&#39;s a must-read for teams looking to enhance security and simplify secret management in AKS.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azuredevcommunityblog/token-economics-driven-architecture-hybrid-models-ai-runway-aks-kata-microvm-mcp/4524276?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Token economics–driven architecture: hybrid models, AI Runway, AKS Kata MicroVM, MCP</a></strong>: This post explores how token economics influence hybrid cloud architectures, with a focus on AKS, Kata MicroVMs, and AI Runway. It provides insights into designing cost-efficient and scalable infrastructures for modern workloads.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/anyscale-on-azure-powering-enterprise-ai-at-massive-scale-on-azure-kubernetes-se/4523806?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Anyscale on Azure: Powering Enterprise AI at Massive Scale on Azure Kubernetes Service</a></strong>: Anyscale on Azure leverages AKS to deliver robust, scalable infrastructure for enterprise AI workloads. This blog highlights its operational benefits, including managed cluster operations and enterprise-grade support.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/announcing-anyscale-on-azure-public-preview-powered-by-ray-on-aks/4523704?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Announcing Anyscale on Azure public preview: Powered by Ray on AKS</a></strong>: The public preview of Anyscale on Azure introduces a managed platform for distributed AI/ML workloads using Ray on AKS. This co-engineered solution simplifies deployment and scales seamlessly for enterprise AI needs.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/whats-new-in-azure-kubernetes-service-at-microsoft-build-2026/4524862?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">What&#39;s new in Azure Kubernetes Service at Microsoft Build 2026</a></strong>: This roundup from Microsoft Build 2026 highlights AKS updates focused on cost, latency, and reliability for AI and data workloads. Key announcements address the evolving needs of platform engineers managing large-scale Kubernetes clusters.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/kubernetes-center-security--ltsout-of-support-version-insights-now-available/4524567?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Kubernetes Center: Security &amp; LTS/Out-of-Support Version Insights Now Available</a></strong>: The Kubernetes Center now offers detailed insights into security, long-term support (LTS), and out-of-support versions across all AKS clusters. This centralized view helps teams ensure compliance and streamline cluster lifecycle management.</p>
</li>
</ul>
<hr>
<h2>🔗 Releases and Roadmap</h2>
<ul>
<li><strong><a href="https://github.com/Azure/AKS/releases/">AKS GitHub Releases</a></strong>: Stay updated with the latest AKS release notes, including new features, bug fixes, and security updates.</li>
<li><strong><a href="https://github.com/orgs/Azure/projects/685/views/1">AKS Public Roadmap</a></strong>: Track upcoming features and enhancements planned for AKS, helping you align your infrastructure roadmap with Azure&#39;s development plans.</li>
</ul>
<h3>Release Highlights</h3>
<ul>
<li><p><strong><a href="https://github.com/Azure/AKS/releases/tag/2026-06-19">Release - 2026-06-19</a></strong>: This release includes updates to five core components and addresses two critical CVEs. Platform engineers should review the CVE details to ensure their clusters remain secure and compliant.</p>
</li>
<li><p><strong><a href="https://github.com/Azure/AKS/releases/tag/2026-05-29">Release - 2026-05-29</a></strong>: Packed with 14 CVE remediations, this release underscores Microsoft&#39;s commitment to security. Teams should prioritize upgrading to safeguard their workloads against known vulnerabilities.</p>
</li>
</ul>
<h3>Announcements</h3>
<ul>
<li><p><strong><a href="https://aka.ms/aks/upgrade-windows-os-version?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06">Windows Server 2022 Retirement Extended</a></strong>: The retirement date for Windows Server 2022 has been extended to June 30, 2028. After this date, AKS will cease producing new node images and security patches, and new node pools with this OS version will no longer be supported. Plan migrations to supported OS versions to avoid operational risks.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/en-us/azure/aks/istio-support-policy#service-mesh-add-on-release-calendar?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Istio Service Mesh Add-On Deprecation</a></strong>: Revision <code>asm-1-27</code> of the Istio-based service mesh add-on is now deprecated. Upgrade to revision 1.28 or later using the <a href="https://learn.microsoft.com/azure/aks/istio-upgrade?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Istio add-on upgrade guide</a> to maintain support and access to the latest features.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/supported-kubernetes-versions?utm_source=aksnewsletter&utm_medium=website&utm_campaign=2026-06&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-06">Windows Server Annual Channel Retirement</a></strong>: Support for Windows Server Annual Channel for Containers on AKS ended on May 15, 2026. The final image (5B) is the last release for this channel. Transition to supported alternatives to ensure continued functionality and security.</p>
</li>
</ul>
<hr>
<h2>🎥 Watch &amp; Learn</h2>
<ul>
<li><p><strong><a href="https://www.youtube.com/watch?v=3yhudHJp3Vo">How we solved AKS cluster sprawl - Kube &amp; Tell - June 2026 - Azure Kubernetes Service</a></strong>: What do you do when hundreds of Kubernetes clusters are spreading across your org, each team running its own version of &quot;what good looks like,&quot; with no consistent way to stay on top of security, versions, or cost?</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=GU17M2DfD7c">eBPF Host Routing in AKS: Faster, Low-Latency Networking with Azure CNI &amp; ACNS</a></strong>: Deep dive into how eBPF Host Routing in Advanced Container Networking Services (ACNS) delivers a high-performance data path by moving routing logic into eBPF programs. Essential viewing for teams looking to reduce networking latency in their AKS clusters.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=PtsZhcijFQY">AKS Community Call - US &amp; Europe (May 2026) - Azure Kubernetes Service</a></strong>: Welcome to the AKS Community Calls!  These sessions foster direct interaction between our product teams and the AKS community.</p>
</li>
</ul>
<hr>
<h2>🧠 Closing Thoughts</h2>
<p>June 2026 showed continued investment across key areas of the AKS platform:</p>
<ul>
<li>Networking capabilities</li>
<li>AI and GPU workloads</li>
<li>Scaling and node management</li>
</ul>
<p>These updates reflect the platform&#39;s ongoing focus on production readiness, operational simplicity, and support for modern cloud-native workloads.</p>
<p>Stay tuned for next month&#39;s edition, and feel free to share feedback or suggestions for future coverage.</p>
]]></content:encoded>
    </item>
    <item>
      <title>AKS Newsletter – May 2026</title>
      <link>https://aksnewsletter.com/2026/2026-05.html</link>
      <guid isPermaLink="true">https://aksnewsletter.com/2026/2026-05.html</guid>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
      <description>70 curated items covering documentation updates, feature announcements, community blogs, and more.</description>
      <content:encoded><![CDATA[
<p>May was a packed month for AKS — headlined by a critical kernel CVE, a major shift away from Ingress NGINX, and strong momentum in GPU/AI observability. The platform continues to mature in networking, upgrade safety, and multi-cluster operations. This edition also features a full KubeCon EU 2026 Azure Pre-Day recap.</p>
<p>Let&#39;s dive in.</p>
<hr>
<h2>✅ General Availability Announcements</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/app-routing-gateway-api?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Application routing add-on with Gateway API – now generally available</a></strong>: The application routing add-on using the Kubernetes Gateway API is now GA. This is the strategic replacement for the legacy Ingress NGINX-based routing in AKS and aligns with the upstream retirement of the Ingress NGINX project. Teams should plan migration paths from Ingress to Gateway API.</p>
</li>
<li><p><strong><a href="https://github.com/Azure/AKS/issues/5667">AKS GitHub issue tracking – now generally available</a></strong>: The consolidated AKS issue tracking on GitHub is now the official channel for bug reports and feature requests. This provides a single, transparent backlog that platform teams can follow and upvote.</p>
</li>
</ul>
<hr>
<h2>🧪 Preview Feature Announcements</h2>
<ul>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/558403/">Application Gateway for Containers managed add-on + AKS Automatic</a></strong>: Application Gateway for Containers is now available as a managed add-on integrated with AKS Automatic clusters. This gives teams a turnkey L7 ingress solution with native Azure integration, without needing to manage the ALB controller lifecycle separately.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/nat-gateway?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">NAT Gateway V2</a></strong>: The next generation of NAT Gateway enters preview for AKS clusters using managed outbound. It improves scalability and reliability for SNAT-heavy workloads and addresses known limitations in the original NAT Gateway architecture.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/aks-list-skus?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">AKS List Available VM SKUs API</a></strong>: A new API allows querying which VM SKUs are available for node pool creation in a given region. This is useful for platform automation that needs to validate capacity and VM family availability before provisioning.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/monitor-gpu-metrics?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">AKS-managed GPU metrics</a></strong>: GPU metrics (utilization, memory, temperature) are now collected by default in Azure Managed Prometheus when GPU node pools are present. This removes a long-standing operational gap where teams had to deploy custom exporters to get GPU observability.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/en-us/azure/aks/upgrade-aks-node-pools-rolling#capacity-based-surge-preview?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Capacity Based Surge for node pool upgrades</a></strong>: A new surge strategy that adapts to available capacity during rolling upgrades. Instead of a fixed surge count, AKS will maximize the use of available quota, improving upgrade speed in constrained environments.</p>
</li>
</ul>
<hr>
<h2>🔁 Behavioral Changes</h2>
<ul>
<li><p><strong><a href="https://aka.ms/aks/automatic">AKS Automatic defaults to Gateway API</a></strong>: AKS Automatic clusters will now be preconfigured with the Kubernetes Gateway API via the application routing add-on, replacing Managed NGINX Ingress as the default. This is a direct consequence of the upstream Ingress NGINX retirement and affects all new AKS Automatic clusters.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/application-network/overview?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Azure Kubernetes Application Network (preview)</a></strong>: A new unified networking layer is being introduced for Kubernetes workloads on Azure. This consolidates ingress, egress, and service-to-service networking under a single umbrella, signaling a longer-term convergence of networking primitives.</p>
</li>
<li><p><strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31431">CVE-2026-31431 – kernel local privilege escalation</a></strong>: A critical kernel vulnerability (&quot;Copy Fail&quot;) allows any pod — including non-root pods with no special capabilities — to escalate to root on the underlying node. All AKS Linux nodes are affected until a node image upgrade or DaemonSet mitigation is applied. Immediate action required.</p>
</li>
<li><p><strong><a href="https://github.com/kubernetes/community/blob/master/sig-network/README.md">Ingress NGINX upstream retirement</a></strong>: Kubernetes SIG Network and the Security Response Committee announced the retirement of the Ingress NGINX project, with maintenance ending in March 2026. AKS teams still using Ingress NGINX should migrate to Gateway API or Application Gateway for Containers.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/long-term-support?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Long Term Support scope updated</a></strong>: The LTS documentation was refreshed to clarify version coverage and support timelines. Teams relying on LTS versions should review the updated lifecycle boundaries.</p>
</li>
</ul>
<hr>
<h2>🔎 Documentation Updates</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/best-practices-cost?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Best Practices for Cost Optimization</a></strong>: This guide was refreshed with current recommendations for AKS cost optimization, including guidance on AKS Automatic&#39;s built-in cost controls, FinOps practices, spot node pools, and autoscaler tuning. Directly relevant for teams reviewing cluster spend.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/upgrade-aks-node-pools-rolling?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Configure rolling upgrades for node pools</a></strong>: Updated with the new Capacity Based Surge option and clearer guidance on drain timeout, soak time, and max-unavailable settings. Critical reading for teams managing large node pools with strict SLA requirements.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/app-routing-gateway-api?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Application routing add-on with Gateway API</a></strong>: Refreshed to reflect GA status and include migration guidance from legacy Ingress NGINX. This is the primary reference for teams adopting Gateway API on AKS.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/concepts-gpu-partitioning?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">GPU Node Partitioning Strategies</a></strong>: Updated to cover AKS-managed MIG (multi-instance GPU) and time-slicing with MPS using the NVIDIA GPU Operator. Important for teams running inference or training workloads that need to share expensive GPU hardware efficiently.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/confidential-containers-overview?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Confidential Containers overview</a></strong>: Refreshed with current deployment guidance and security model details for running workloads inside encrypted, attestation-backed enclaves on AKS. Relevant for regulated industries handling sensitive data.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/upgrade-options?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Upgrade Options and Recommendations</a></strong>: A new consolidated guide covering in-place upgrades, blue-green strategies, and scenario-based recommendations for common upgrade challenges. Helps teams pick the right upgrade approach for their risk profile.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-node-auto-provisioning?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Node Auto-Provisioning (NAP)</a></strong>: Updated with current CLI and ARM template examples for enabling and disabling NAP. Important for teams using Karpenter-based provisioning at scale.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/advanced-container-networking-services-overview?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Advanced Container Networking Services overview</a></strong>: Refreshed to reflect the GA of metrics filtering and log aggregation features. This is the umbrella documentation for ACNS capabilities including Container Network Observability and Security.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/csi-migrate-in-tree-volumes?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Migrate from in-tree storage to CSI drivers</a></strong>: Updated migration guidance for moving from deprecated in-tree storage drivers to CSI. Clusters still using in-tree will face removal in upcoming Kubernetes versions.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/aks-list-skus?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">List Available VM SKUs (Preview)</a></strong>: New documentation for the VM SKU availability API, explaining how to query region-specific SKU constraints before provisioning node pools programmatically.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/istio-support-policy?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Istio service mesh add-on support policy</a></strong>: Refreshed to clarify supported Istio versions, upgrade expectations, and the boundary between managed and self-managed Istio components on AKS.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/node-images?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Node Images</a></strong>: Updated with current node OS image options including Ubuntu 24.04, Azure Linux, and Flatcar. Helps teams understand the tradeoffs between OS choices.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-cvm?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Confidential VMs (CVM)</a></strong>: Updated guidance on creating CVM-backed node pools for workloads requiring hardware-level memory encryption and attestation.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/concepts-security-vulnerability-data-api?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Vulnerability Data API</a></strong>: New documentation for the AKS Vulnerability Data API, which provides programmatic access to CVE impact data for security reviews, compliance reporting, and upgrade planning.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/virtual-machines-node-pools?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Virtual Machines Node Pools</a></strong>: Updated to explain how to mix multiple VM types of the same family in a single node pool, improving flexibility for heterogeneous workloads.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/cluster-autoscaler?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Cluster Autoscaler</a></strong>: Refreshed with current best practices for autoscaler profiles, scale-down behavior, and integration with pod disruption budgets.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/upgrade-aks-control-plane?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Upgrade the Control Plane</a></strong>: Updated with current guidance on control plane upgrade sequencing, API compatibility, and rollback options.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/supported-kubernetes-versions?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Supported Kubernetes Versions</a></strong>: Updated version table reflecting current GA and preview Kubernetes releases available in AKS, including LTS eligibility.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/long-term-support?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Long-Term Support Versions</a></strong>: Refreshed to reflect current LTS version coverage and extended support timelines.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/entra-id-control-plane-authentication?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Entra ID Authentication for the Control Plane</a></strong>: Updated integration guide for using Microsoft Entra ID as the identity provider for Kubernetes API server authentication. Important for teams enforcing centralized identity and conditional access policies.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/csi-secrets-store-driver?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Azure Key Vault Provider for Secrets Store CSI Driver</a></strong>: Refreshed with current configuration examples and best practices for injecting secrets from Key Vault into pods without application-level SDK changes.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-system-pools?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">System Node Pools</a></strong>: Updated with current sizing guidance and taint configuration to properly isolate system workloads from application pods.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/concepts-network-ingress?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Ingress Networking Concepts</a></strong>: Refreshed to reflect the Ingress NGINX deprecation and the shift toward Gateway API as the recommended ingress pattern.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-network-policies?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Network Policies</a></strong>: Updated with current guidance on Azure Network Policy Manager and Cilium-based network policies for securing pod-to-pod traffic.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/update-azure-cni?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">Update Azure CNI IPAM Mode and Data Plane</a></strong>: Updated guidance for migrating existing clusters to newer Azure CNI IPAM modes (overlay, dynamic IP allocation) and data plane technologies.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/concepts-network-cni-overview?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">CNI Networking Concepts</a></strong>: Refreshed to reflect current CNI options including Azure CNI Overlay, Azure CNI with dynamic IP, and kubenet deprecation path.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/core-aks-concepts?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-05">AKS Core Concepts</a></strong>: Refreshed foundational documentation covering cluster architecture, node pools, networking, and identity fundamentals.</p>
</li>
</ul>
<hr>
<h2>📚 Community Blogs</h2>
<ul>
<li><p><strong><a href="https://blog.aks.azure.com/2026/05/11/kernel-lpe-cve-patching-at-scale-with-fleet-manager">Apply Copy Fail and DirtyFrag CVE mitigations at-scale using Azure Kubernetes Fleet Manager</a></strong>: This post demonstrates how to use Azure Kubernetes Fleet Manager to safely roll out mitigations for CVE-2026-31431 (&quot;Copy Fail&quot;) and CVE-2026-43284 / CVE-2026-43500 (&quot;DirtyFrag&quot;) across multiple AKS clusters. The vulnerability allows container-to-root escalation and impacts all AKS Linux nodes. Practical guidance covers both node image upgrades and a DaemonSet-based mitigation for clusters that cannot upgrade immediately.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/announcing-public-preview-of-argo-cd-extension-in-aks-azure-portal-experience/4521618">Announcing Public Preview of Argo CD extension in AKS Azure Portal Experience</a></strong>: Argo CD is now available as a managed extension directly in the AKS Azure Portal. This brings GitOps deployment visibility into the portal experience without needing separate Argo CD dashboards, reducing context-switching for teams operating through the Azure console.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azurenetworkingblog/metrics-filtering-and-log-aggregation-now-ga-for-advanced-container-networking-s/4516508">Metrics Filtering and Log Aggregation Now GA for Advanced Container Networking Services</a></strong>: ACNS now offers GA-level metrics filtering and log aggregation for container networking. This allows operators to reduce noise in networking telemetry and focus on actionable signals, directly improving incident response for network-related issues.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azuredevcommunityblog/building-a-controllable-inference-platform-on-kubernetes-with-ai-runway/4520590">Building a Controllable Inference Platform on Kubernetes with AI Runway</a></strong>: AI Runway provides a practical framework for teams operating inference workloads on AKS. It bridges the gap between &quot;calling an external model API&quot; and &quot;operating an enterprise-grade inference platform&quot; with guardrails, routing, and cost controls built on Kubernetes primitives.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/getting-started-with-opensearch-on-aks-with-aks-avm-and-helm/4520392">Getting Started with OpenSearch on AKS with AKS AVM and Helm</a></strong>: A practical walkthrough for deploying OpenSearch on AKS using Azure Verified Modules (AVM) for infrastructure and Helm for the application layer. Useful for teams needing a self-hosted search and analytics platform with full control over data residency.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azuredevcommunityblog/six-coding-agents-one-production-system-a-field-guide-to-agenticops-with-aks-lab/4519916">Six Coding Agents, One Production System: A Field Guide to AgenticOps with AKS-Lab-GitHubCopilot</a></strong>: This post explores running multiple AI coding agents against a shared production-like AKS environment. It introduces &quot;AgenticOps&quot; patterns for sandboxing, observability, and safe deployment when AI agents are generating and deploying code.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/linuxandopensourceblog/decoupling-memory-from-startup-time-in-aks-sandbox-pods/4516307">Decoupling Memory from Startup Time in AKS Sandbox Pods</a></strong>: A deep dive into Kata Containers memory management on AKS, showing how to decouple memory allocation from pod startup. This is particularly relevant for teams running sandbox pods where cold start latency and memory overhead are in tension.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azure-ai-foundry-blog/nvidia-dynamo-on-aks-autoscaling-llm-inference/4499545">NVIDIA Dynamo on AKS – Autoscaling LLM Inference</a></strong>: Demonstrates using NVIDIA Dynamo&#39;s disaggregated inference engine on AKS with GPU-aware autoscaling. Addresses the challenge of scaling LLM serving workloads where traditional HPA metrics don&#39;t capture GPU saturation or request queuing depth effectively.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azurearcblog/introducing-cert-manager-for-azure-arc-enabled-kubernetes-now-in-public-preview/4514549">Introducing cert-manager for Azure Arc-enabled Kubernetes: now in Public Preview</a></strong>: cert-manager is now available as a managed extension for Arc-enabled Kubernetes, including AKS Edge. It ships with security defaults — TLS enforcement, least-privilege RBAC, and restricted pod security — making certificate lifecycle management simpler and more secure for hybrid environments.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azuredevcommunityblog/giving-the-copilot-sdk-agent-a-hardware-level-helmet-using-kata-microvm-on-aks/4518668">Giving the Copilot SDK Agent a &quot;hardware-level helmet&quot; using Kata microVM on AKS</a></strong>: Shows how to use Kata Containers (microVM isolation) on AKS to sandbox AI agents that execute untrusted code. Demonstrates that hardware-level isolation adds minimal overhead while preventing container escape scenarios in agent-driven workloads.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/azure-arc-aks-explained-run-kubernetes-beyond-azure-cloud/4518443">Azure Arc AKS Explained: Run Kubernetes Beyond Azure Cloud</a></strong>: An overview of running AKS on Azure Arc for hybrid and multi-cloud scenarios. Covers the deployment model, management plane integration, and when Arc-based AKS makes sense versus standard AKS or self-managed Kubernetes.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azurehighperformancecomputingblog/distributing-model-weights-to-your-ai-cluster-a-faster-pre-flight-on-aks-and-slu/4517294">Distributing model weights to your AI cluster: a faster pre-flight on AKS and Slurm</a></strong>: Explains techniques for distributing large model weight files across GPU nodes on AKS and Slurm clusters. Addresses the cold-start problem where model loading time dominates inference pod startup, especially for 70B+ parameter models.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azuredevcommunityblog/high-availability-testing-for-azure-kubernetes-service-in-a-single-region-with-a/4509825">High Availability Testing for Azure Kubernetes Service in a Single Region with Availability Zones</a></strong>: Provides a methodology for validating AKS high availability behavior under simulated zone failures. Covers test scenarios, expected behaviors, and common pitfalls when designing single-region HA architectures with availability zones.</p>
</li>
</ul>
<hr>
<h2>🔗 Releases and Roadmap</h2>
<ul>
<li><strong><a href="https://github.com/Azure/AKS/releases/">AKS GitHub Releases</a></strong></li>
<li><strong><a href="https://github.com/orgs/Azure/projects/685/views/1">AKS Public Roadmap</a></strong></li>
</ul>
<h3>Release Highlights</h3>
<ul>
<li><strong><a href="https://github.com/Azure/AKS/releases/tag/2026-04-28">Release 2026-04-28</a></strong>: This release includes Kubernetes patch versions 1.35.2 and 1.33.9, along with 2 CVE remediations. A maintenance release focused on security patching.</li>
</ul>
<hr>
<h2>🎥 Watch &amp; Learn</h2>
<ul>
<li><p><strong><a href="https://www.youtube.com/watch?v=47Q4JbWxlm4">Troubleshooting AKS Scaling Issues with Jameson Hearn</a></strong>: A practical walkthrough of diagnosing scaling failures in AKS — covering cluster autoscaler misconfigurations, pending pods, and quota-related issues. Useful for on-call engineers troubleshooting node scaling.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=kRmLLMblBGk">Cross-Cluster Networking for Azure Kubernetes Fleet Manager</a></strong>: Explains how Fleet Manager enables cross-cluster networking, allowing services in different AKS clusters to communicate seamlessly. Relevant for teams operating multi-cluster architectures that need east-west traffic across cluster boundaries.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=HpIq86LFOvQ">AKS Community Call – March 2026</a></strong>: Monthly community call with product team updates, roadmap signals, and live Q&amp;A. Covers networking and observability topics from this period.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=CRkf50TzYX4">AKS Community Call – April 2026</a></strong>: Monthly community call featuring discussions on Gateway API GA, Ingress NGINX retirement timeline, and security updates.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=ka-uR1IzA3E">Simplify AKS Monitoring with Datadog – Cloud Native Partner Showcase</a></strong>: A partner showcase demonstrating Datadog&#39;s AKS integration for monitoring, troubleshooting, and cost optimization. Shows how third-party observability platforms complement Azure Monitor for teams with multi-cloud tooling.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=LVgAolj3QGA">Node Auto Provisioning (NAP) with Wilson Darko</a></strong>: Deep dive into Node Auto-Provisioning best practices — covering node class selection, disruption budgets, and workload-aware scheduling. Essential viewing for teams migrating from cluster autoscaler to NAP.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=XC5MMt4MZqo">Pod CIDR Expansion on Azure CNI Overlay</a></strong>: Demonstrates how to expand pod CIDR ranges on existing Azure CNI Overlay clusters without recreation. Directly addresses the scaling constraint where clusters run out of pod IPs.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=ZBUP2WcsZWM">AKS Day EU 2026: Daniel Sol – AKS Everywhere</a></strong>: KubeCon EU Azure Pre-Day session on running AKS across cloud, edge, and hybrid environments with Azure Arc integration.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=1wqE6-oCpOU">AKS Day EU 2026: Mitch Connors – Networking</a></strong>: KubeCon EU Azure Pre-Day session covering the AKS networking roadmap, Gateway API adoption, and advanced networking features.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=Wlbr4anznUQ">AKS Day EU 2026: Anson Qian – AI Infrastructure</a></strong>: KubeCon EU Azure Pre-Day session on GPU scheduling, KAITO, and AI workload patterns on AKS.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=71RYshfhhvE">AKS Day EU 2026: Ralph Squillace – AKS AI Inference Platform</a></strong>: KubeCon EU Azure Pre-Day session on building production inference platforms with AKS, covering model serving, scaling, and cost optimization for LLM workloads.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=GUI4Kv9OBZs">AKS Day EU 2026: Jorge Palma – Keynote</a></strong>: KubeCon EU Azure Pre-Day keynote covering AKS platform strategy, investment areas, and roadmap highlights for 2026.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=rJsYZdU6tec">AKS Day EU 2026: Weinong Wang – Sovereign AKS</a></strong>: KubeCon EU Azure Pre-Day session on sovereign cloud requirements and how AKS addresses data residency, compliance, and regulatory constraints.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=PRDy-2h_r2E">Upgrade Issues 101 with Mosbah Majed</a></strong>: A troubleshooting-focused session covering common AKS upgrade failures — from version skew issues to addon compatibility problems. Practical remediation steps included.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=MaJBk_5O-nE">MVP Summit 2026: Dinant Paardenkooper on AKS Security</a></strong>: An MVP-led discussion on AKS security posture management, covering pod security standards, network policies, and secure platform operations for enterprise environments.</p>
</li>
</ul>
<hr>
<h2>🧠 Closing Thoughts</h2>
<p>May 2026 was dominated by a security imperative and a networking transition:</p>
<ul>
<li><strong>CVE-2026-31431</strong> forced immediate action across all AKS Linux nodes, and Fleet Manager proved its value for multi-cluster remediation at scale</li>
<li><strong>Gateway API reaching GA</strong> while Ingress NGINX enters retirement marks a clear inflection point — teams still on Ingress NGINX should be actively planning migration</li>
<li><strong>GPU observability and AI inference</strong> continue to mature, with managed metrics, Dynamo-based autoscaling, and model weight distribution solving real operational pain</li>
<li><strong>KubeCon EU 2026 Azure Pre-Day</strong> provided a concentrated view into AKS&#39;s 2026 strategy across networking, AI, sovereignty, and hybrid</li>
</ul>
<p>For platform teams, the immediate priorities are clear: patch CVE-2026-31431, plan the Gateway API migration, and evaluate the new GPU metrics if running inference workloads.</p>
]]></content:encoded>
    </item>
    <item>
      <title>AKS Newsletter – April 2026</title>
      <link>https://aksnewsletter.com/2026/2026-04.html</link>
      <guid isPermaLink="true">https://aksnewsletter.com/2026/2026-04.html</guid>
      <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
      <description>71 curated items covering documentation updates, feature announcements, community blogs, and more.</description>
      <content:encoded><![CDATA[
<p>April was a big month for AKS. Ten features hit General Availability, two new previews landed, and the community shipped an impressive volume of practical content — from AI inference on Arc-enabled clusters to securing Argo CD with Entra ID. There was also a notable set of behavioral changes that platform teams should review before their next upgrade cycle.</p>
<p>This month brings <strong>10 features reaching General Availability</strong> and <strong>2 new Preview announcements</strong>. Here are some of the highlights:</p>
<ul>
<li><strong>Disable HTTP proxy in AKS</strong> is now generally available</li>
<li><strong>Azure Monitor for Azure Arc-enabled Kubernetes with OpenShift and Azure Red Hat OpenShift</strong> is now generally available</li>
<li><strong>Configure AKS backup using a single Azure CLI command</strong> is now generally available</li>
<li><strong>StandardV2 NAT Gateway as an outbound type for AKS</strong> enters public preview</li>
<li><strong>NAT Gateway V2</strong> enters public preview</li>
</ul>
<p>Let&#39;s dive in.</p>
<hr>
<h2>✅ General Availability Announcements</h2>
<ul>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/557857/">Generally Available: Disable HTTP proxy in AKS</a></strong>: Organizations that use HTTP proxies to control outbound traffic can now remove or modify those settings on running clusters without recreation. This was a long-standing pain point — previously, changing proxy configuration required rebuilding the cluster, which is disruptive and operationally expensive. This GA release directly reduces operational friction for enterprise environments with evolving network requirements.</p>
</li>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/560358/">Generally Available: Azure Monitor for Azure Arc-enabled Kubernetes with OpenShift and Azure Red Hat OpenShift</a></strong>: Azure Monitor now fully supports monitoring Azure Arc-enabled Kubernetes clusters running OpenShift and Azure Red Hat OpenShift. This closes an observability gap for hybrid environments — teams running mixed AKS and OpenShift clusters can now use a single monitoring plane with consistent metrics, logs, and alerts across all their Kubernetes infrastructure.</p>
</li>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/560521/">Generally Available: Configure AKS backup using a single Azure CLI command</a></strong>: Azure Backup now provides a one-command CLI experience for configuring AKS cluster backup. Previously, setting up backup required multiple steps across different Azure services. This simplification makes it much more likely that teams will actually enable backup as part of their standard cluster provisioning workflow rather than treating it as an afterthought.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/gpu-cluster?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">MIG (multi-instance GPU) profiles – now generally available</a></strong>: Multi-instance GPU partitioning is now GA on AKS agent pools, enabling H100 GPUs to be partitioned into smaller instances (MIG1g through MIG7g). This is a significant cost optimization for AI and ML workloads — instead of dedicating an entire H100 to a single workload, teams can now share GPU resources across multiple tenants or smaller inference jobs, dramatically improving GPU utilization.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/concepts-storage#storage-classes?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">StorageClass – now generally available</a></strong>: AKS 1.35 clusters in supported regions now ship with built-in StorageClass definitions that provide sensible defaults for Premium SSD v2. This removes the need to create custom StorageClasses for common storage scenarios, reducing boilerplate and configuration drift across clusters.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/api-server-vnet-integration#availability?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">API Server VNET Integration – now generally available</a></strong>: API Server VNet Integration is now available in the Malaysia South region. This extends the regional footprint for teams that need the API server to be reachable only through their virtual network, eliminating public endpoint exposure.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/vertical-pod-autoscaler?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Vertical Pod Autoscaler (VPA) – now generally available</a></strong>: VPA now supports the <code>Recreate</code> update mode in GA. This allows VPA to automatically restart pods with updated resource requests and limits when it detects that current allocations do not match actual usage. It is a practical tool for right-sizing workloads that have unpredictable or evolving resource patterns.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/istio-about?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Istio-based service mesh – now generally available</a></strong>: Gateway proxy pods for the Istio-based service mesh add-on are now generally available. This means teams can now run full Istio gateway functionality — including ingress, egress, and east-west traffic management — as a fully supported, production-ready feature on AKS.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/http-proxy">Disable HTTP Proxy – now generally available</a></strong>: This is the companion GA announcement for the ability to disable HTTP proxy configuration on existing AKS clusters. Combined with the proxy configuration update, this provides full lifecycle management of proxy settings without requiring cluster recreation.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/troubleshoot/azure/azure-kubernetes/create-upgrade-delete/troubleshoot-apiserver-etcd?tabs=resource-specific#cause-4-aks-managed-api-server-guard-was-applied&utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">AKS Managed API Server Guard – now generally available</a></strong>: AKS Managed API Server Guard is now GA. This feature protects the API server from excessive load by automatically throttling requests that could destabilize the control plane. It is an important safety net for clusters running workloads that generate high volumes of API calls — such as controllers, operators, or CI/CD pipelines.</p>
</li>
</ul>
<hr>
<h2>🧪 Preview Feature Announcements</h2>
<ul>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/560207/">Public Preview: StandardV2 NAT Gateway as an outbound type for AKS</a></strong>: AKS now supports StandardV2 NAT Gateway as an outbound type for both managed and BYO VNets. This is a meaningful upgrade for egress-heavy workloads — StandardV2 offers higher throughput, improved reliability, and better scaling characteristics compared to the original NAT Gateway SKU. Teams designing new clusters with predictable outbound IP requirements should evaluate this option.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/nat-gateway?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">NAT Gateway V2 (preview)</a></strong>: NAT Gateway V2 support is now available in public preview across supported public Azure regions, with automatic exclusion in sovereign clouds and regions where StandardV2 is not yet available. This complements the outbound type preview and gives operators a next-generation NAT experience with improved performance characteristics.</p>
</li>
</ul>
<hr>
<h2>🔁 Behavioral Changes</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/azure-cni-powered-by-cilium?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Azure CNI Powered by Cilium</a></strong>: AKS now includes a new managed <code>cilium-fluent-bit</code> component in clusters running Azure CNI Powered by Cilium. This improves supportability by enabling better log collection and troubleshooting for the Cilium dataplane. Operators should be aware that this adds a new system component to the cluster that consumes a small amount of node resources.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/http-proxy?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">HTTP proxy configuration</a></strong>: The validation rules for HTTP proxy configuration have been relaxed, making it easier to update proxy settings on running clusters. This aligns with the new GA capability to disable and modify proxy configurations without cluster recreation.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/http-proxy">HTTP Proxy</a></strong>: AKS now enforces a limit of 20 Trusted CA Certificates for HTTP proxy configurations. Teams that manage a large number of custom CAs for outbound traffic inspection should consolidate their certificate chains to stay within this limit.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/ubuntu2204-retirement-github">Ubuntu 22.04 Retirement</a></strong>: Ubuntu 22.04 is being retired as a node OS image for AKS. Operators should plan their migration to Ubuntu 24.04, which is now the recommended LTS option. This is a routine lifecycle transition, but teams running custom node configurations or hardened images should validate their tooling against the newer OS before the retirement date.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/kubelet-serving-certificate-rotation">Kubelet Serving Certificate Rotation (KSCR)</a></strong>: Kubelet Serving Certificate Rotation is now enabled by default, regardless of the node pool tag setting. This is a security improvement — it ensures that kubelet serving certificates are automatically rotated, reducing the risk of expired certificates causing node communication failures.</p>
</li>
<li><p><strong><a href="https://github.com/Azure/acr/blob/main/docs/teleport/aks-getting-started.md">Teleport (preview)</a></strong>: The Teleport preview feature has been removed from both Azure Container Registry and AKS. Teams that were using Teleport for accelerated image pulling should migrate to standard pull mechanisms. This is a clean deprecation — the feature never reached GA and has been fully decommissioned.</p>
</li>
<li><p><strong><a href="https://opensource.microsoft.com/blog/2026/03/24/whats-new-with-microsoft-in-open-source-and-kubernetes-at-kubecon-cloudnativecon-europe-2026/">What&#39;s new with Microsoft in open source and Kubernetes at KubeCon + CloudNativeCon Europe 2026</a></strong>: This summary covers Microsoft&#39;s announcements at KubeCon Europe 2026, including several AKS features that are reflected in this month&#39;s preview and GA sections. It provides broader context for the platform direction and upstream Kubernetes contributions from Microsoft.</p>
</li>
</ul>
<hr>
<h2>🔎 Documentation Updates</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/create-volume-azure-files?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Create and Manage Persistent Volumes with Azure Files in Azure Kubernetes Service (AKS)</a></strong>: This refresh consolidates guidance on provisioning Azure Files-backed persistent volumes through the CSI driver. It is especially useful for teams running shared storage workloads such as CMS platforms, shared config stores, or legacy applications that need ReadWriteMany access across pods.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/aks-desktop-deploy-ai-assistant?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Troubleshoot Azure Kubernetes Service (AKS) Workloads with Natural Language in AKS Desktop (preview)</a></strong>: This new documentation covers the AI-powered troubleshooting assistant built into AKS Desktop. It allows engineers to diagnose Kubernetes issues using natural language queries instead of manually parsing logs and events — a significant step toward reducing mean time to resolution for less experienced operators.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/planned-maintenance?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Use Planned Maintenance to Schedule and Control Upgrades for Azure Kubernetes Service (AKS) Clusters</a></strong>: The planned maintenance documentation was refreshed to better explain how maintenance windows interact with cluster and node image upgrades. This is critical for production environments where unplanned upgrades during business hours can cause disruption.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/concepts-cluster-authentication?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Cluster authentication concepts in Azure Kubernetes Service (AKS)</a></strong>: This update clarifies how AKS authenticates Kubernetes API requests through Microsoft Entra ID and explains the implications of disabling local cluster admin accounts. Platform teams running hardened clusters should review this to ensure their authentication posture aligns with current best practices.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/learn/quick-kubernetes-deploy-cli?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Deploy an Azure Kubernetes Service (AKS) Cluster Using Azure CLI</a></strong>: The CLI quickstart was updated to reflect current defaults for networking, identity, and cluster configuration. This keeps the onboarding experience aligned with the latest recommended cluster creation paths.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/support-policies?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Support Policies for Azure Kubernetes Service (AKS)</a></strong>: The support policy page was refreshed with updated versioning expectations, lifecycle boundaries, and clarification on preview vs. GA feature support. Understanding these boundaries is essential for platform teams planning long-lived cluster lifecycles.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-system-pools?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Use system node pools in Azure Kubernetes Service (AKS)</a></strong>: This documentation was updated with current guidance on system node pool sizing, taint configuration, and workload isolation. Properly configuring system pools prevents resource contention between control-plane add-ons and application workloads.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/aks-desktop-quickstart-auto?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Quickstart: Get Started Deploying and Managing Applications using AKS Automatic with AKS Desktop</a></strong>: This new quickstart walks through deploying and managing containerized applications on AKS Automatic using AKS Desktop — no Kubernetes manifests required. It lowers the barrier to entry for teams evaluating AKS without deep Kubernetes expertise.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/aks-desktop-app?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Deploy an Application using AKS Desktop for Azure Kubernetes Service (AKS)</a></strong>: Complementing the quickstart, this guide covers the full application deployment workflow through AKS Desktop. It demonstrates how the tool abstracts away YAML authoring while still giving teams visibility into what gets deployed.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/nat-gateway?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Create a managed or user-assigned NAT gateway for your Azure Kubernetes Service (AKS) cluster</a></strong>: The NAT gateway documentation was updated to include StandardV2 NAT Gateway support. This is directly relevant for teams designing egress architectures that need higher throughput and more predictable outbound IP behavior.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/istio-gateway-api?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Kubernetes Gateway API Ingress for Istio Service Mesh Add-on for Azure Kubernetes Service (AKS) (preview)</a></strong>: This documentation explains how to configure ingresses using the Kubernetes Gateway API with the Istio service mesh add-on. For teams planning a migration from traditional Ingress controllers, this is the path forward — Gateway API offers role-oriented configuration and better multi-tenancy support.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/entra-id-authorization?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Use Microsoft Entra ID authorization for the Kubernetes API in AKS</a></strong>: This guide covers how to authorize Kubernetes API access using Microsoft Entra ID role assignments with optional ABAC conditions. It enables fine-grained, identity-driven access control that goes beyond basic Kubernetes RBAC.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/automatic/quick-automatic-custom-network?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Quickstart: Create an Azure Kubernetes Service (AKS) Automatic cluster in a custom virtual network</a></strong>: This quickstart shows how to deploy AKS Automatic into a custom VNet — a common requirement for enterprises that cannot use default networking. It bridges the gap between the simplicity of AKS Automatic and the network isolation requirements of regulated environments.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/concepts-cluster-authorization?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Cluster authorization concepts in Azure Kubernetes Service (AKS)</a></strong>: This update explains the authorization model for the Kubernetes API in AKS, covering Kubernetes RBAC, Microsoft Entra ID authorization, and Azure ABAC. It helps platform teams decide which authorization model fits their organizational structure and compliance requirements.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/external-identity-provider-authentication-configure?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Configure External Identity Providers with AKS Structured Authentication (Preview)</a></strong>: This documentation covers how to configure external identity providers using structured authentication and JWT authenticators. It is particularly important for organizations that federate identity across multiple platforms and need to integrate non-Entra identity systems with AKS.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/control-kubeconfig-access?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Limit access to kubeconfig in Azure Kubernetes Service (AKS)</a></strong>: This guide explains how to control who can retrieve kubeconfig files for cluster administrators and cluster users. Restricting kubeconfig access is a fundamental security measure that many teams overlook when hardening their clusters.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/access-control-managed-azure-ad?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Control cluster and node access using Conditional Access with Microsoft Entra integration</a></strong>: This update covers how to apply Conditional Access policies to AKS clusters integrated with Microsoft Entra ID. It enables organizations to enforce location-based, device-based, or risk-based access controls for Kubernetes API access.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/entra-id-control-plane-authentication?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Enable Microsoft Entra ID authentication for the AKS control plane</a></strong>: This guide documents how to enable and configure Microsoft Entra ID authentication for the Kubernetes API server. It is a foundational step for any production cluster that needs centralized identity management and audit trails.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/aks-service-permissions?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">AKS service permissions reference</a></strong>: This reference documents the Azure permissions required by the identity creating an AKS cluster, the cluster identity at runtime, and AKS node access. It is essential reading when designing least-privilege RBAC assignments for cluster lifecycle automation.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/concepts-identity?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Concepts - Access and identity in Azure Kubernetes Service (AKS)</a></strong>: This conceptual overview was refreshed to cover all five identity scenarios in AKS — control-plane authentication, authorization, cluster identity, node identity, and workload identity. It serves as the starting point for any identity architecture discussion around AKS.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/best-practices?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Best practices for Azure Kubernetes Service (AKS)</a></strong>: The best practices collection was updated to reflect current recommendations across cluster operations, security, networking, and developer workflows. This is the single best reference hub for teams establishing or reviewing their AKS operational standards.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/pci-malware?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">AKS Regulated Cluster for PCI DSS 4.0.1 - Malware Protection</a></strong>: This documentation provides malware protection guidance specifically for AKS clusters under PCI DSS 4.0.1 compliance requirements. It is directly applicable for financial services and e-commerce platforms running payment workloads on Kubernetes.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/cis-kubernetes?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Center for Internet Security (CIS) Kubernetes benchmark</a></strong>: This update clarifies how AKS applies the CIS Kubernetes benchmark and which controls are handled by the platform versus the operator. Understanding this mapping is critical for security audits and compliance assessments.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/best-practices-performance-scale-large?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Performance and scaling best practices for large workloads in Azure Kubernetes Service (AKS)</a></strong>: This guide consolidates performance and scaling best practices for large-scale AKS deployments. It covers node pool sizing, API server optimization, etcd considerations, and workload scheduling strategies that matter at scale.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/aks-desktop-deploy-troubleshooting?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-04">Troubleshoot an Application using Insights in AKS Desktop (preview)</a></strong>: This documentation covers the Insights feature in AKS Desktop, powered by Inspektor Gadget. It allows engineers to troubleshoot running applications with deep kernel-level observability without deploying additional tooling into the cluster.</p>
</li>
</ul>
<hr>
<h2>📚 Community Blogs</h2>
<ul>
<li><p><strong><a href="https://blog.aks.azure.com/2026/04/22/argocd-extension-with-microsoft-entra">Securing Argo CD with Microsoft Entra ID: A Step-by-Step Guide</a></strong>: With the Argo CD extension now in public preview on AKS and Azure Arc, this post walks through integrating Argo CD authentication with Microsoft Entra ID. This is essential reading for teams adopting Argo CD on AKS — centralizing GitOps authentication through Entra ID eliminates the need for separate credential management and aligns with enterprise identity policies.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/04/17/appnet-agentgateway">Control AI spend with per-application token rate limiting using Application Network and agentgateway</a></strong>: As AI workloads scale, controlling token consumption becomes a real operational challenge. This post shows how to use Application Network and agentgateway to enforce per-application token rate limits. It is highly relevant for platform teams managing shared AI inference infrastructure where cost attribution and blast radius control are critical.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/04/09/ai-inference-on-aks-arc-part-5">AI Inference on AKS enabled by Azure Arc: Generative AI using Triton and TensorRT‑LLM</a></strong>: Part 5 of the AI inference series covers deploying NVIDIA Triton Inference Server with TensorRT-LLM on Arc-enabled AKS clusters. This is the most advanced post in the series — it demonstrates how to serve generative AI models at the edge with production-grade inference infrastructure, bridging the gap between cloud and on-premises AI deployment.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/04/08/acstor-v2.1-ga">Azure Container Storage v2.1.0: Now GA with Elastic SAN</a></strong>: Azure Container Storage v2.1.0 reaches GA with Elastic SAN integration, providing higher performance and larger scale for stateful workloads. This release is significant for teams running databases, message queues, or other storage-intensive applications on AKS — Elastic SAN delivers consistent high-throughput storage without managing individual disks.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/04/08/agent-skills-for-aks">Turn your agents into AKS experts: Agent Skills for AKS</a></strong>: Agent Skills bring production-grade AKS guidance, troubleshooting checklists, and guardrails directly into AI agents. This is a novel approach to operationalizing platform knowledge — instead of relying solely on documentation, teams can embed AKS best practices into their AI-assisted workflows for faster and more consistent troubleshooting.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/04/07/ai-inference-on-aks-arc-part-4">AI Inference on AKS enabled by Azure Arc: Predictive AI using Triton and ResNet-50</a></strong>: Part 4 of the series deploys Triton Inference Server with ResNet-50 in ONNX format on Arc-enabled AKS. It demonstrates how to run predictive AI at the edge for image classification scenarios — a practical reference for manufacturing, retail, and IoT use cases where low-latency inference on on-premises hardware is required.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/04/07/ai-inference-on-aks-arc-part-3">AI Inference on AKS enabled by Azure Arc: Generative AI with Open‑Source LLM Server</a></strong>: This post covers deploying open-source LLM servers on Arc-enabled AKS for generative AI inference. It is aimed at teams that want to run LLMs on their own infrastructure without depending on cloud-hosted model APIs — a growing requirement for data-sovereign and air-gapped environments.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/04/07/ai-inference-on-aks-arc-part-2">AI Inference on AKS enabled by Azure Arc: Series Introduction and Scope</a></strong>: This post sets the scope for the AI inference series, covering the architecture, prerequisites, and design decisions behind running AI workloads on Arc-enabled AKS clusters. It is the right starting point for teams evaluating edge AI deployment strategies.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/04/07/ai-inference-on-aks-arc-part-1">AI Inference on AKS enabled by Azure Arc: Bringing AI to the Edge and On‑Premises</a></strong>: The series opener explains why running AI inference at the edge matters — latency, data residency, and compliance often make cloud-based inference impractical. It frames the entire series around real-world constraints that drive organizations to bring AI to their own infrastructure rather than relying exclusively on cloud endpoints.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/04/01/dranet-rdma-optimization-for-ai-on-aks">Optimizing RDMA performance for AI workloads on AKS with DRANET</a></strong>: RDMA is critical for high-throughput GPU-to-GPU communication in distributed AI training. This post explains how DRANET optimizes RDMA performance on AKS, directly addressing the network bottlenecks that limit large-scale AI training workloads. It is required reading for teams running multi-node GPU clusters.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/containers/simplifying-gmsa-for-windows-containers-on-aks-open-source-tooling-now-available/4512167">Simplifying gMSA for Windows Containers on AKS: Open-Source Tooling Now Available</a></strong>: Group Managed Service Accounts (gMSA) have historically been painful to configure for Windows containers on AKS. This post introduces open-source tooling that simplifies the setup process. For teams running Active Directory-authenticated Windows workloads on Kubernetes, this removes one of the biggest operational barriers.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/autonomous-aks-incident-response-with-azure-sre-agent-from-alert-to-verified-rec/4511343">Autonomous AKS Incident Response with Azure SRE Agent: From Alert to Verified Recovery in Minutes</a></strong>: This post demonstrates how the Azure SRE Agent can autonomously handle AKS incident response — from alert detection to verified recovery. It represents a significant shift in incident management, moving from reactive human-driven triage to AI-driven automated response for common failure scenarios.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/aks-app-routing-s-next-chapter-gateway-api-with-istio/4512729">AKS App Routing&#39;s Next Chapter: Gateway API with Istio</a></strong>: With the deprecation of Ingress NGINX, this post explains how AKS App Routing is evolving to use Gateway API with Istio as the recommended ingress path. It provides the migration rationale and architectural context that teams need to plan their transition from traditional Ingress controllers.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azurenetworkingblog/introducing-the-container-network-insights-agent-for-aks-now-in-public-preview/4512197">Introducing the Container Network Insights Agent for AKS: Now in Public Preview</a></strong>: The Container Network Insights Agent brings AI-powered network troubleshooting directly into AKS. Instead of manually correlating logs and metrics across tools, engineers can use natural language to diagnose networking issues. This is a meaningful step toward reducing the expertise barrier for Kubernetes networking operations.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azuregovernanceandmanagementblog/announcing-one-command-backup-configuration-for-aks-with-azure-backup/4511852">Announcing One‑Command Backup Configuration for AKS with Azure Backup</a></strong>: This companion blog explains the one-command AKS backup experience in detail. It covers the simplified CLI workflow, what gets backed up, and how to restore. The reduction from a multi-step process to a single command makes it realistic to include backup in standard cluster provisioning pipelines.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azuredevcommunityblog/passwordless-aks-secrets-sync-azure-key-vault-with-eso-workload-identity/4509959">Passwordless AKS Secrets: Sync Azure Key Vault with ESO + Workload Identity</a></strong>: This post shows how to sync Azure Key Vault secrets into Kubernetes using External Secrets Operator (ESO) with Workload Identity — no passwords or service principal credentials required. It is a clean, modern pattern for secret management that aligns with zero-trust principles and eliminates long-lived credentials from the cluster.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/service-mesh-aware-request-tracing-in-aks-with-istio-and-application-insights/4509928">Service Mesh-Aware Request Tracing in AKS with Istio and Application Insights</a></strong>: This article explains how to enable distributed request tracing that is aware of the Istio service mesh, using Application Insights as the backend. It bridges the observability gap between mesh-level traffic routing and application-level telemetry, providing end-to-end visibility for microservice architectures.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azurearchitectureblog/secure-http-only-aks-ingress-with-azure-front-door-premium-firewall-dnat-and-pri/4508167">Secure HTTP‑Only AKS Ingress with Azure Front Door Premium, Firewall DNAT, and Private AGIC</a></strong>: This post walks through a production-grade ingress architecture using Azure Front Door Premium, Azure Firewall DNAT, and a private Application Gateway Ingress Controller. It is one of the more complex but realistic enterprise patterns for securing inbound traffic to AKS clusters while maintaining end-to-end encryption and WAF protection.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azurearchitectureblog/aks-cluster-with-agic-hits-the-azure-application-gateway-backend-pool-limit-100/4508201">AKS cluster with AGIC hits the Azure Application Gateway backend pool limit (100)</a></strong>: This post documents a real-world scaling issue where an AKS cluster using AGIC hit the 100 backend pool limit on Azure Application Gateway. It provides practical workarounds and architectural guidance for teams running large numbers of services behind AGIC — a common pain point that is poorly documented elsewhere.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/devsecops-on-aks-governance-gates-that-actually-prevent-incidents/4508415">DevSecOps on AKS: Governance Gates That Actually Prevent Incidents</a></strong>: This post focuses on implementing governance gates in AKS that go beyond policy-as-code to actually prevent production incidents. It covers deployment safeguards, admission policies, and supply chain controls — practical DevSecOps patterns that move security from reactive detection to proactive prevention.</p>
</li>
</ul>
<hr>
<h2>🔗 Releases and Roadmap</h2>
<ul>
<li><strong><a href="https://github.com/Azure/AKS/releases/">AKS GitHub Releases</a></strong>: Track the latest AKS release notes, including Kubernetes version updates, component upgrades, CVE remediations, new features, behavioral changes, and bug fixes.</li>
<li><strong><a href="https://github.com/orgs/Azure/projects/685/views/1">AKS Public Roadmap</a></strong>: View upcoming features, planned improvements, and the delivery timeline for Azure Kubernetes Service on the official public roadmap.</li>
</ul>
<h3>Release Highlights</h3>
<ul>
<li><strong><a href="https://github.com/Azure/AKS/releases/tag/2026-04-02">Release 2026-04-02</a></strong>: This release includes Kubernetes patch versions 1.35.1 and 1.33.8, along with 3 component updates. It is a maintenance release focused on keeping supported Kubernetes versions current with upstream patches.</li>
</ul>
<hr>
<h2>🎥 Watch &amp; Learn</h2>
<ul>
<li><p><strong><a href="https://www.youtube.com/watch?v=cxwq8rEchFI">Container Network Insights agent: Agentic AI network troubleshooting for Azure Kubernetes Service</a></strong>: This video demonstrates the Container Network Insights Agent in action, showing how it uses AI to diagnose Kubernetes networking issues in AKS. It is a practical walkthrough of the tool&#39;s capabilities for engineers who want to see the AI-driven troubleshooting experience before adopting it in their clusters.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=sSh5sLVoLPA">Building scalable, serverless search solution with Elastic: CN Partner Showcase: Azure Kubernetes</a></strong>: Part of the Cloud Native Partners Showcase, this video highlights how Elastic builds scalable, serverless search solutions on top of AKS. It provides insight into real partner architectures and how AKS serves as a foundation for complex stateful workloads.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=UdRzAdraWAE">Diagnose &amp; Solve with Andrew Scobie: AKS Troubleshooting Series: Azure Kubernetes Service</a></strong>: This episode of the AKS Troubleshooting Series dives into the Diagnose &amp; Solve experience in the Azure portal. Andrew Scobie walks through how to use the built-in diagnostics to identify and resolve common AKS issues without leaving the portal — a useful tool for day-2 operations that many engineers underutilize.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=kJiYUP9YgIA">Scale Azure Storage: Ultra Disk, Blob Storage, Azure Container Storage</a></strong>: This video covers how to scale Azure Storage for Kubernetes workloads using Ultra Disk, Blob Storage, and Azure Container Storage. It is directly relevant for teams running stateful workloads on AKS that need to understand the trade-offs between different storage backends at scale.</p>
</li>
</ul>
<hr>
<h2>🧠 Closing Thoughts</h2>
<p>April 2026 was one of the more significant months for AKS in recent memory. Ten GA announcements in a single month signals strong platform maturation, particularly in areas that directly impact day-to-day operations.</p>
<p>The recurring themes are clear:</p>
<ul>
<li><strong>Egress and networking</strong> are getting more flexible with StandardV2 NAT Gateway and relaxed proxy configuration</li>
<li><strong>Identity and security</strong> continue to deepen with Entra ID authorization, Conditional Access, and structured authentication for external identity providers</li>
<li><strong>AI and GPU workloads</strong> are expanding beyond cloud-only — the Arc-enabled inference series shows that edge AI on Kubernetes is becoming a first-class scenario</li>
<li><strong>Operational simplicity</strong> is a priority — from one-command backup to AKS Desktop to the SRE Agent, the platform is actively reducing the expertise barrier for common tasks</li>
<li><strong>Observability</strong> is evolving with AI-powered troubleshooting through the Container Network Insights Agent and AKS Desktop&#39;s natural language diagnostics</li>
</ul>
<p>For platform teams, the message is clear: AKS is investing in making Kubernetes operations more accessible while simultaneously expanding the platform&#39;s capabilities for advanced workloads. The balance between simplicity and power is what makes this month&#39;s updates particularly valuable.</p>
<p>Stay tuned for next month&#39;s edition, and feel free to share feedback or suggestions for future coverage.</p>
]]></content:encoded>
    </item>
    <item>
      <title>AKS Newsletter – March 2026</title>
      <link>https://aksnewsletter.com/2026/2026-03.html</link>
      <guid isPermaLink="true">https://aksnewsletter.com/2026/2026-03.html</guid>
      <pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate>
      <description>54 curated items covering documentation updates, feature announcements, community blogs, and more.</description>
      <content:encoded><![CDATA[
<p>Welcome to the March 2026 edition of the AKS Newsletter.</p>
<p>This month brings <strong>6 features reaching General Availability</strong> and <strong>9 new preview announcements</strong>. Here are some of the highlights:</p>
<ul>
<li><strong>Container network logs in AKS</strong> are now generally available  </li>
<li><strong>Container network metrics filtering for AKS</strong> is now generally available  </li>
<li><strong>Azure Container Storage v2.1.0</strong>, now with Elastic SAN integration and on-demand installation, is now generally available  </li>
<li><strong>Blue-green agent pool upgrades in AKS</strong> enter public preview  </li>
<li><strong>Cross-cluster networking in Azure Kubernetes Fleet Manager</strong> enters public preview  </li>
<li><strong>AKS managed GPU metrics in Azure Monitor</strong> enters public preview</li>
</ul>
<p>Let&#39;s dive in.</p>
<hr>
<h2>✅ General Availability Announcements</h2>
<ul>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/557892/">Generally Available: Container network logs in AKS</a></strong>: Networking issues in Kubernetes environments can be difficult to diagnose due to limited visibility into traffic flows and insufficient context around failures.</p>
</li>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/557902/">Generally Available: Container network metrics filtering for AKS</a></strong>: Network observability can generate large volumes of metrics, making it difficult for teams to focus on data that is operationally relevant.</p>
</li>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/557912/">Generally Available: Azure Container Storage v2.1.0 now with Elastic SAN integration and on demand installation</a></strong>: Containerized workloads often require higher and more consistent storage performance without managing large numbers of individual disks.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/azure-monitor/app/kubernetes-codeless?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Application Monitoring auto-instrumentation – now generally available</a></strong>:  This feature enables codeless monitoring of your Java and Node.js workloads running on AKS — no source code changes required. It works by automatically injecting the Azure Monitor OpenTelemetry Distro into your application pods, generating telemetry for distributed tracing, metrics, and logs. You can onboard entire namespaces or individual deployments via the Azure portal, CLI, or YAML custom resources. Simply enable application monitoring on your  cluster, configure an Instrumentation resource, and restart your deployments to start collecting telemetry in Application Insights.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/ai-toolchain-operator?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">AI Toolchain Operator (KAITO) add-on – now generally available</a></strong>: For running AI and ML workloads on AKS.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/configure-static-egress-gateway#static-private-ip-support?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Private IP support in Static Egress Gateway – now generally available</a></strong>:  Enables workloads to use private static IP addresses as the source for all outbound (egress) traffic from AKS clusters. By configuring a dedicated gateway node pool, you get consistent and predictable egress IPs — useful for allowlisting specific private addresses on
 downstream services or appliances</p>
</li>
</ul>
<hr>
<h2>🧪 Preview Feature Announcements</h2>
<ul>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/557862/">Public Preview: Blue-green agent pool upgrade in AKS</a></strong>: In‑place node pool upgrades can introduce risk by applying changes directly to running environments.</p>
</li>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/557877/">Public Preview: Cross-cluster networking in Azure Kubernetes Fleet Manager</a></strong>: Organizations running applications across multiple Kubernetes clusters often face challenges with performance, global service discovery, and observability due to the complexity of distributed...</p>
</li>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/557882/">Public Preview: AKS managed GPU metrics in Azure Monitor</a></strong>: Teams running GPU‑backed workloads often lack integrated visibility into GPU utilization alongside Kubernetes metrics.</p>
</li>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/557887/">Public Preview: AI Agent for container networking troubleshooting</a></strong>: Troubleshooting Kubernetes networking issues is often slowed by logs and metrics scattered across multiple tools, forcing engineers to manually correlate signals during incidents.</p>
</li>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/557922/">Public Preview: Microsoft Azure Kubernetes Application Network</a></strong>: As Kubernetes environments scale across regions and clusters, IP‑based networking becomes difficult to manage and provides limited application‑level visibility and security controls.</p>
</li>
<li><p><strong><a href="https://azure.microsoft.com/en-us/updates/557927/">Public Preview: Application routing with meshless Istio in AKS</a></strong>: Following the deprecation of ingress‑nginx, Kubernetes operators need a supported, standards‑aligned migration path for ingress without the complexity of a full service mesh.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/azure-monitor/containers/container-insights-overview?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Azure Monitor Profile OTLP gRPC support (preview)</a></strong>: Is now available in public preview, enabling OpenTelemetry Protocol gRPC endpoints for Azure Monitor metrics collection.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/advanced-container-networking-services-overview?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">ACNS (preview)</a></strong>: Preview feature is now supported on dual-stack clusters.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/node-autoprovision?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Node Auto Provisioning (preview)</a></strong>: Has been updated to Karpenter Azure provider v1.7.2.</p>
</li>
</ul>
<hr>
<h2>🔁 Behavioral Changes</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/automatic/aks-automatic-managed-system-node-pools-about#restrictions-that-prevent-running-workloads-on-the-managed-system-node-pool?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">AKS Automatic clusters</a></strong>: Now enforce multiple layers of defense against remote code execution via <code>nodes/proxy</code> permissions: - A ValidatingAdmissionPolicy (VAP) restricts creation or updates of ClusterRole and Role...</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/how-to-enable-ebpf-host-routing?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">eBPF host routing</a></strong>: Nodes will be labeled with <code>kubernetes.azure.com/ebpf-host-routing=true</code>.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/api-server-service-tags?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Service tags for API server authorized IP ranges</a></strong>: Are now supported for AKS clusters with API server VNet integration.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/nat-gateway#create-an-aks-cluster-with-a-user-assigned-nat-gateway?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">configuring Standard V2 Azure NAT Gateway</a></strong>: As a user‑assigned NAT gateway for outbound (egress) traffic.</p>
</li>
<li><p><strong><a href="https://github.com/Azure/AKS/issues/5648">Flatcar Container Linux for AKS (preview)</a></strong>: Will be retired on 8 June 2026, transition to a supported alternative by that date.</p>
</li>
</ul>
<hr>
<h2>🔎 Documentation Updates</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/ai-toolchain-operator-fine-tune?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Fine-tune and deploy an AI model on Azure Kubernetes Service (AKS) with the AI toolchain operator add-on</a></strong>: Learn how to fine-tune and deploy a language model with the AI toolchain operator add-on on your AKS cluster.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/blue-green-node-pool-upgrade?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Blue-Green Node Pool Upgrades in Azure Kubernetes Service (AKS) (preview)</a></strong>: Perform upgrades of AKS node pools using a blue-green deployment strategy to ensure workload availability during updates.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/reliability-availability-zones-configure?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Configure Availability Zones in Azure Kubernetes Service (AKS)</a></strong>: Learn how to configure availability zones in Azure Kubernetes Service (AKS) to increase the availability of your applications.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/howto-deploy-java-liberty-app?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Deploy a Java application with Open Liberty/WebSphere Liberty on an Azure Kubernetes Service (AKS) cluster</a></strong>: Deploy a Java application with Open Liberty or WebSphere Liberty on an AKS cluster by using the Azure Marketplace offer, which automatically provisions resources.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/kaito-custom-inference-model?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Onboard custom models for inferencing with the AI toolchain operator (KAITO) on Azure Kubernetes Service (AKS)</a></strong>: Learn how to onboard custom models for inferencing with the AI toolchain operator (KAITO) on AKS.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/outbound-rules-control-egress?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Outbound network and FQDN rules for Azure Kubernetes Service (AKS) clusters</a></strong>: Learn what ports and addresses are required to control egress traffic in Azure Kubernetes Service (AKS)</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/virtual-nodes-cli?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Create virtual nodes in Azure Kubernetes Service (AKS) using Azure CLI</a></strong>: Learn how to use Azure CLI to create an Azure Kubernetes Services (AKS) cluster that uses virtual nodes to run pods.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/cluster-health-monitor?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Use Cluster Health Monitor checker in Azure Kubernetes Service (AKS) (preview)</a></strong>: Learn how the Cluster Health Monitor checker in Azure Kubernetes Service (AKS) runs data plane health checks and supports CoreDNS remediation.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/container-network-security-cilium-mutual-tls-how-to?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Deploy Cilium mTLS encryption with Advanced Container Networking Services</a></strong>: Get started with Cilium mTLS encryption for Advanced Container Networking Services on your AKS cluster.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/create-volume-azure-files?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Create and Manage Persistent Volumes with Azure Files in Azure Kubernetes Service (AKS)</a></strong>: Learn how to create and manage persistent volumes using Azure Files with the Container Storage Interface (CSI) driver in Azure Kubernetes Service (AKS) to provide scalable and reliable storage for...</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/supported-kubernetes-versions?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Supported Kubernetes Versions in Azure Kubernetes Service (AKS)</a></strong>: Learn the Kubernetes version support policy and lifecycle of clusters in Azure Kubernetes Service (AKS).</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/container-network-security-cilium-mutual-tls-concepts?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Cilium mutual TLS authentication and encryption with Advanced Container Networking Services (ACNS)</a></strong>: An overview of Advanced Container Networking Services&#39; Cilium mTLS encryption capabilities on Azure Kubernetes Service (AKS).</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/update-azure-cni?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Update Azure CNI IP Address Management (IPAM) Mode and Data Plane Technology</a></strong>: Learn how to update existing Azure Kubernetes Service (AKS) clusters to use the latest Azure CNI IPAM modes and data plane technologies.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/use-vertical-pod-autoscaler?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Use the Vertical Pod Autoscaler in Azure Kubernetes Service (AKS)</a></strong>: Learn how to deploy, upgrade, or disable the Vertical Pod Autoscaler on your Azure Kubernetes Service (AKS) cluster.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/security-bulletins/overview?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Security bulletins for Azure Kubernetes Service (AKS)</a></strong>: This article provides security/vulnerability related updates and troubleshooting guides for Azure Kubernetes Services (AKS).</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/egress-outboundtype?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Customize cluster egress with outbound types in Azure Kubernetes Service (AKS)</a></strong>: Learn how to define a custom egress route in Azure Kubernetes Service (AKS).</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/agentic-cli-for-aks-service-account-workload-identity-setup?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Service account creation and workload identity setup for the Agentic CLI for Azure Kubernetes Service (AKS) (Preview)</a></strong>: Learn how to create the required service account and optionally configure workload identity for the agentic CLI for AKS to enable authentication.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/app-routing-gateway-api?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-03">Azure Kubernetes Service (AKS) application routing add-on with the Kubernetes Gateway API (preview)</a></strong>: Use the application routing add-on to manage ingress traffic on Azure Kubernetes Service (AKS) using the Kubernetes Gateway API.</p>
</li>
</ul>
<hr>
<h2>📚 Community Blogs</h2>
<ul>
<li><p><strong><a href="https://blog.aks.azure.com/2026/03/18/app-routing-gateway-api">Announcing Gateway API support for App Routing (preview)</a></strong>: The AKS app routing add-on now supports the Kubernetes Gateway API via a meshless Istio control plane — the recommended path to migrate from Ingress-NGINX.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/03/16/dynamo-on-aks-part-3">Scaling multi-node LLM inference with NVIDIA Dynamo and NVIDIA GPUs on AKS (Part 3)</a></strong>: This blog post is co-authored with Nikhar Maheshwari, Anish Maddipoti, Rohan Varma, Clement Pakkam Isaac, and Stephen Mccoulough from NVIDIA.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/03/06/dra-with-vGPUs-on-aks">Dynamic Resource Allocation (DRA) with NVIDIA virtualized GPU (vGPU) on AKS</a></strong>: Recently, dynamic resource allocation (DRA) has emerged as the standard mechanism to consume GPU resources in Kubernetes. With DRA, accelerators like GPUs are no longer exposed as static extended...</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/03/03/multi-instance-gpu-with-dra-on-aks">Running more with less: Multi-instance GPU (MIG) with Dynamic Resource Allocation (DRA) on AKS</a></strong>: GPUs power a wide range of production Kubernetes workloads across industries. For example, media platforms rely on them for video encoding/transcoding, financial services firms run quantitative...</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azurearcblog/announcing-public-preview-of-argo-cd-extension-on-aks-and-azure-arc-enabled-kube/4504497">Announcing Public Preview of Argo CD extension on AKS and Azure Arc enabled Kubernetes clusters</a></strong>: Announcing Public Preview of Argo CD extension on <SPAN class="lia-search-match-lithium ">AKS</SPAN> and Azure Arc enabled Kubernetes clusters We are excited to announce public preview of the Argo...</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azurenetworkingblog/announcing-public-preview-cilium-mtls-encryption-for-azure-kubernetes-service/4504423">Announcing public preview: Cilium mTLS encryption for Azure Kubernetes Service</a></strong>: We are thrilled to announce the public preview of&nbsp;Cilium&nbsp;mTLS&nbsp;encryption in Azure Kubernetes Service (<SPAN class="lia-search-match-lithium ">AKS</SPAN>), delivered as part...</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/migrating-to-the-next-generation-of-virtual-nodes-on-azure-container-instances-a/4496565">Migrating to the next generation of Virtual Nodes on Azure Container Instances (ACI)</a></strong>: ...nfrastructure. Virtual Nodes on ACI allows you to run Kubernetes pods managed by an <SPAN class="lia-search-match-lithium ">AKS</SPAN> cluster in a serverless way on ACI instead of traditional...</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/after-ingress-nginx-migrating-to-application-gateway-for-containers/4503110">After Ingress NGINX: Migrating to Application Gateway for Containers</a></strong>: If you&#39;re running Ingress NGINX on <SPAN class="lia-search-match-lithium ">AKS</SPAN>, you&#39;ve probably seen the announcements by now. The community Ingress Nginx project is being retired, upstream...</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/microsoft-azure-at-kubecon-europe-2026-amsterdam-nl-march-23-26/4500716">Microsoft Azure at KubeCon Europe 2026 | Amsterdam, NL - March 23-26</a></strong>: ...ctivities, and ways to connect with the engineers behind <SPAN class="lia-search-match-lithium ">AKS</SPAN> and our open-source projects. Here&#39;s what&#39;s on the schedule: Azure Day with...</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/defending-container-runtime-from-malware-with-microsoft-defender-for-containers/4499264">Defending Container Runtime from Malware with Microsoft Defender for Containers</a></strong>: ...bsp;near-real-time malware detection directly into container environments.&nbsp;The antimalware feature is available via Helm&nbsp;with sensor version 0.10.2&nbsp;for &lt;SPAN...</p>
</li>
</ul>
<hr>
<h2>🔗 Releases and Roadmap</h2>
<ul>
<li><strong><a href="https://github.com/Azure/AKS/releases/">AKS GitHub Releases</a></strong>: Track the latest AKS release notes, including Kubernetes version updates, component upgrades, CVE remediations, new features, behavioral changes, and bug fixes.</li>
<li><strong><a href="https://github.com/orgs/Azure/projects/685/views/1">AKS Public Roadmap</a></strong>:  View upcoming features, planned improvements, and the delivery timeline for Azure Kubernetes Service on the official public roadmap.</li>
</ul>
<h3>Release Highlights</h3>
<ul>
<li><strong><a href="https://github.com/Azure/AKS/releases/tag/2026-03-05">Release Notes - 2026-03-05</a></strong>: This release includes Kubernetes patch versions 1.32.11, 1.34.3, 37 component updates, 52 CVE remediations.</li>
</ul>
<hr>
<h2>🎥 Watch &amp; Learn</h2>
<ul>
<li><p><strong><a href="https://www.youtube.com/watch?v=hNS9fuPo574">AI Reduces Time-To-Resolution (TTR) for your Kubernetes Cluster Issues</a></strong>: Reduce the troubleshooting time from 2. 5 hours to literally minutes with AI assisted troubleshooting on AKS using AKS MCP Server.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=IYpva6_Jo9k">Context is crucial with AI Debugging - AI Debugging Best Practices</a></strong>: Qasim Sarfaraz talks about why providing the right context is crucial when debugging with AI assistants.  He also discusses the need for independent analysis and confirming the AI findings rather...</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=RaPivLnCzRw">AKS MCP Server with Julia Yin: AKS Troubleshooting Series: Azure Kubernetes Service</a></strong>: In todays episode, we talk to Julia Yin to do a deepdive on the AKS MCP Server.  In the previous episodes, you have seen the AKS MCP Server and agentic CLI being used for troubleshooting different...</p>
</li>
</ul>
<hr>
<h2>🧠 Closing Thoughts</h2>
<p>March 2026 showed continued investment across key areas of the AKS platform:</p>
<ul>
<li>Networking capabilities</li>
<li>Observability and monitoring</li>
<li>AI and GPU workloads</li>
<li>Scaling and node management</li>
<li>Storage</li>
<li>Multi-cluster and fleet management</li>
</ul>
<p>These updates reflect the platform&#39;s ongoing focus on production readiness, operational simplicity, and support for modern cloud-native workloads.</p>
<p>Stay tuned for next month&#39;s edition, and feel free to share feedback or suggestions for future coverage.</p>
]]></content:encoded>
    </item>
    <item>
      <title>AKS Newsletter – February 2026</title>
      <link>https://aksnewsletter.com/2026/2026-02.html</link>
      <guid isPermaLink="true">https://aksnewsletter.com/2026/2026-02.html</guid>
      <pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate>
      <description>41 curated items covering documentation updates, feature announcements, community blogs, and more.</description>
      <content:encoded><![CDATA[
<p>February continued with a strong focus on AI/ML workloads, VM convergence, and platform security hardening. This edition covers new AKS Engineering Blog posts on scaling Ray workloads, deploying KubeVirt, and autoscaling KAITO inference with KEDA. The release notes bring meaningful behavioral changes including LocalDNS defaulting on for Kubernetes 1.35+, new security annotations on nodes, and important Windows Server retirement timelines. Documentation updates span storage, networking, identity bindings, and Agentic CLI support.</p>
<p>Let&#39;s dive in.</p>
<hr>
<h2>✅ General Availability Announcements</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/api-server-vnet-integration#availability?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">API Server VNET Integration – new regions</a></strong>: API Server VNET Integration is now available in eastus2, eastus3, and belgiumcentral. This expands the geographic availability for teams requiring private API server access through VNET integration.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/http-proxy?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">HTTP Proxy and Custom CA support in NAP clusters</a></strong>: HTTP Proxy and Custom Certificate Authority (CA) are now supported in Node Auto-Provisioning (NAP) enabled clusters. This removes a gap for enterprises requiring proxy-based egress control and custom certificate chains.</p>
</li>
</ul>
<hr>
<h2>🧪 Preview Feature Announcements</h2>
<ul>
<li><strong><a href="https://learn.microsoft.com/azure/aks/gpu-cluster?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Managed GPU profiles (public preview)</a></strong>: Managed GPU profiles are now available in public preview via API version 2026-01-02-preview. This simplifies GPU workload configuration by providing pre-defined profiles optimized for common AI/ML scenarios.</li>
</ul>
<hr>
<h2>🔁 Behavioral Changes</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/localdns-custom?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">LocalDNS enabled by default on Kubernetes 1.35+</a></strong>: LocalDNS is now enabled by default for clusters running Kubernetes 1.35 or newer. This is a significant operational change — teams should validate DNS resolution behavior before upgrading to 1.35.</p>
</li>
<li><p><strong>Security patch timestamp annotation on nodes</strong>: Nodes are now annotated with <code>kubernetes.azure.com/security-patch-timestamp</code> during security VHD reboot upgrades. This gives operators a unified way to verify when the last security patch was applied to each node.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/application-gateway/for-containers/quickstart-deploy-application-gateway-for-containers-alb-controller-addon?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">NSG management changes for Application Gateway for Containers</a></strong>: AKS no longer creates or updates Network Security Groups on subnets delegated for Application Gateway for Containers. This improves reliability in policy-managed environments but may require teams to manage NSG rules directly.</p>
</li>
<li><p><strong>AKS Automatic – nodes/proxy defense hardening</strong>: AKS Automatic has added multiple layers of defense against remote code execution via nodes/proxy permissions, including a ValidatingAdmissionPolicy blocking nodes/proxy grants and an authorization policy denying nodes/proxy by default.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/deployment-safeguards?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Deployment Safeguards probe policy relaxed on AKS Automatic</a></strong>: AKS Deployment Safeguards no longer deny missing startup, liveness, and readiness probe requirements on AKS Automatic clusters. The policy has been changed to warn only.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/managed-gateway-api?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Gateway API CRDs without gateway implementation</a></strong>: Gateway API CRDs can now be enabled directly without first requiring a supported gateway implementation such as the Managed Istio service mesh add-on. This reduces friction for teams adopting Gateway API incrementally.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/ws2019-retirement-github">Windows Server 2019 retirement – March 1, 2026</a></strong>: Windows Server 2019 is scheduled for retirement on March 1, 2026. After that date, AKS will no longer produce new node images or provide security patches. Teams must transition to Windows Server 2022 or newer.</p>
</li>
<li><p><strong><a href="https://aka.ms/aks/windows-annual-channel-retirement">Windows Server Annual Channel retirement – May 15, 2026</a></strong>: Windows Server Annual Channel (Preview) will be retired on May 15, 2026. Teams should transition to the Long Term Servicing Channel (LTSC).</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/istio-upgrade?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Istio add-on revision asm-1-25 deprecated</a></strong>: Istio-based service mesh add-on revision asm-1-25 has been deprecated. Revision asm-1-28 is now supported.</p>
</li>
</ul>
<hr>
<h2>🔎 Documentation Updates</h2>
<ul>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/azure-csi-driver-volume-provisioning?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Instant access snapshot support for Premium SSD v2 and Ultra Disk</a></strong>: New documentation covers how to use instant access snapshots with Premium SSD v2 and Ultra Disk in AKS. This enables faster volume snapshot and restore operations for performance-critical stateful workloads.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/best-practices-storage-nvme?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">NVMe storage best practices for AKS</a></strong>: The documentation for emptyDir volumes was updated to clarify NVMe-based usage patterns and best practices. This is relevant for teams using NVMe-backed local storage for ephemeral or scratch workloads.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/compare-container-options-with-aks?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Container comparison article added to AKS docs</a></strong>: A new article comparing container options was added to the AKS documentation. It helps teams evaluate Azure Container Apps, AKS, and other container hosting options side by side.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/migrate-from-npm-to-cilium-network-policy?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">NPM retirement documentation</a></strong>: Documentation was updated to reflect the retirement of Azure Network Policy Manager (NPM). Teams relying on NPM should plan their migration to Cilium-based or Calico-based network policies.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/upgrade-os-version?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Ubuntu 24.04 containerd 2.0 and version updates</a></strong>: The Ubuntu 24.04 documentation was refreshed with containerd 2.0 details and version consistency fixes. This is important for teams planning OS upgrades.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/identity-bindings-concepts?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Identity bindings updates for .NET, Go, and JavaScript</a></strong>: The identity bindings documentation was expanded with language-specific guidance for Go, JavaScript, and .NET. This makes it easier for application developers to adopt the new identity bindings model.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/localdns-custom?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">LocalDNS Preferred mode and node reimage impact</a></strong>: The LocalDNS documentation now clarifies Preferred mode behavior and the impact of node reimage on DNS configuration. This is important context given that LocalDNS now defaults to enabled on Kubernetes 1.35+.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/node-auto-provisioning?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Node auto-provisioning disk encryption and metrics</a></strong>: Documentation was updated to cover disk encryption support and metrics for node auto-provisioning (NAP). This fills a gap for security-conscious teams using NAP.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/aks-model-context-protocol-server?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">AKS MCP (Model Context Protocol) documentation</a></strong>: New documentation introduces the AKS MCP server and Agentic CLI. This enables AI-assisted cluster management and troubleshooting through natural language interfaces.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/managed-gateway-api?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Managed Gateway API content updates</a></strong>: The Managed Gateway API documentation received a content development review and editorial updates. Gateway API CRDs can now be enabled directly without requiring a supported gateway implementation to be installed first.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/tutorial-kubernetes-deploy-azure-container-storage?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">ACStor v2 documentation</a></strong>: The Azure Container Storage documentation was updated to reflect ACStor v2. This brings updated guidance for storage pool management and volume provisioning.</p>
</li>
<li><p><strong><a href="https://learn.microsoft.com/azure/aks/windows-annual-channel?utm_source=aksnewsletter&utm_medium=email&utm_campaign=2026-02">Windows Annual Channel retirement notice</a></strong>: A retirement notice was added for Windows Server Annual Channel (Preview), scheduled for May 15, 2026. Teams using Annual Channel should migrate to LTSC.</p>
</li>
</ul>
<hr>
<h2>📚 Community Blogs</h2>
<ul>
<li><p><strong><a href="https://blog.aks.azure.com/2026/02/13/scaling-ray-aks">Scaling Anyscale Ray Workloads on AKS</a></strong>: This post covers running Anyscale&#39;s managed Ray service on AKS with multi-cluster multi-region GPU capacity aggregation, unified BlobFuse2 storage for ML/AI pipelines, and automated service principal authentication. It is especially relevant for teams running distributed training and inference at scale across GPU-constrained regions.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/02/06/kubevirt-on-aks">Deploying KubeVirt on AKS</a></strong>: This post walks through deploying KubeVirt on AKS for running virtual machines alongside containerized workloads. It covers prerequisites including nested virtualization support, KubeVirt operator installation with AKS-specific node placement, and VM migration using Forklift. This is a key reference for organizations with legacy VM workloads exploring Kubernetes-based unified infrastructure management.</p>
</li>
<li><p><strong><a href="https://blog.aks.azure.com/2026/02/03/autoscale-inference-workloads-with-kaito">Autoscale KAITO inference workloads on AKS using KEDA</a></strong>: This post introduces the new KAITO InferenceSet CRD and KEDA KAITO Scaler for event-driven autoscaling of LLM inference workloads. It shows how to configure both time-based and metric-based scaling (using vLLM metrics like <code>num_requests_waiting</code>) to dynamically scale GPU inference instances. This directly addresses GPU cost optimization for production AI workloads.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/microsoftmissioncriticalblog/accelerating-aks-upgrades-with-fleet-manager-finding-the-right-balance/4497133">Accelerating AKS Upgrades with Fleet Manager: Finding the Right Balance</a></strong>: This post explores the trade-offs between speed and safety when orchestrating AKS upgrades at scale using Azure Fleet Manager. It covers update runs, stages, and groups, and explains why reducing stages risks blast radius while increasing parallel update groups can hit capacity constraints.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/seamless-migrations-from-self-hosted-nginx-ingress-to-the-aks-app-routing-add-on/4495630">Seamless Migrations From Self Hosted Nginx Ingress To The AKS App Routing Add-On</a></strong>: With the upstream Nginx Ingress controller retiring in March 2026, this post walks through a zero-downtime migration to the AKS App Routing add-on. It covers running both controllers in parallel with separate IngressClasses and cutting over DNS without disrupting production traffic.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/regional-endpoints-for-geo-replicated-azure-container-registries-private-preview/4496186">Regional Endpoints for Geo-Replicated Azure Container Registries (Private Preview)</a></strong>: Regional endpoints now let teams target specific ACR geo-replicated regions directly, bypassing Azure-managed routing. This enables predictable regional affinity for AKS clusters, client-side failover strategies, and easier troubleshooting of image pull behavior.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/appsonazureblog/beyond-iptables-scaling-aks-networking-with-nftables-and-project-calico/4494467">Beyond iptables: Scaling AKS Networking with nftables and Project Calico</a></strong>: This post explains the transition from iptables to nftables in AKS Ubuntu 24.04 nodes. It covers how Project Calico adapts to nftables-based dataplane rules and what operators need to know about compatibility, performance gains, and troubleshooting in the new networking stack.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/microsoftmissioncriticalblog/hardening-spring-boot-health-probes-on-aks-how-to-prevent-restart-storms-before-/4491549">Hardening Spring Boot Health Probes on AKS: How to Prevent Restart Storms Before They Start</a></strong>: This post dives into common misconfiguration patterns with Spring Boot liveness and readiness probes on AKS that can trigger cascading pod restarts under load. It provides guidance on tuning probe timing, separating health check dependencies, and avoiding restart storms in production.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/aks-tenant-migration-considerations-and-approach/4415198">AKS Tenant Migration: Considerations and Approach</a></strong>: A detailed guide on migrating AKS clusters between Azure AD tenants. It covers planning considerations, resource group moves, identity reconfiguration, and step-by-step migration procedures for clusters with managed identities and RBAC dependencies.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azurearchitectureblog/reference-architecture-for-highly-available-multi-region-azure-kubernetes-servic/4490479">Reference Architecture for Highly Available Multi-Region Azure Kubernetes Service (AKS)</a></strong>: This reference architecture post outlines a multi-region AKS deployment pattern for high availability, covering Azure Front Door for global load balancing, cross-region state management, and failover strategies for mission-critical workloads.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/azurearchitectureblog/from-ingress-to-gateway-api-a-pragmatic-path-forward-and-why-it-matters-now/4489779">From Ingress to Gateway API: A Pragmatic Path Forward</a></strong>: This post covers the evolution from Kubernetes Ingress to the Gateway API, explaining the practical benefits and migration path for AKS users. It covers HTTPRoute, TLSRoute, and how the new API model enables more expressive traffic management.</p>
</li>
<li><p><strong><a href="https://techcommunity.microsoft.com/blog/linuxandopensourceblog/retina-1-0-is-now-available/4489003">Retina 1.0 Is Now Available</a></strong>: Retina, the open-source cloud-native container networking observability platform, has reached 1.0. This release includes production-ready distributed packet captures, flow-level metrics with Hubble integration, and support for both AKS and self-managed Kubernetes clusters.</p>
</li>
</ul>
<hr>
<h2>🔗 Releases and Roadmap</h2>
<ul>
<li><strong><a href="https://github.com/Azure/AKS/releases/">AKS GitHub Releases</a></strong></li>
<li><strong><a href="https://github.com/orgs/Azure/projects/685/views/1">AKS Public Roadmap</a></strong></li>
</ul>
<h3>Release Highlights</h3>
<ul>
<li><strong><a href="https://github.com/Azure/AKS/releases/tag/2026-02-08">Release 2026-02-08</a></strong>: This release brings Kubernetes patch versions 1.34.2, 1.33.6, and 1.32.10. Key component updates include Konnectivity v0.31.4-6, Karpenter v1.6.8, Cilium updates to v1.16.16 and v1.17.9 resolving multiple CVEs, Application Routing operator v0.2.17 addressing ingress-nginx vulnerabilities, and Managed Prometheus add-on v6.24.2. The release also includes significant security hardening across etcd, kube-apiserver, and kube-egress-gateway components.</li>
</ul>
<hr>
<h2>🎥 Watch &amp; Learn</h2>
<ul>
<li><p><strong><a href="https://www.youtube.com/watch?v=YeO5zTDFtHA">Troubleshooting Disk Latency with Burak Ok – AKS Troubleshooting Series</a></strong>: This episode covers diagnosing and resolving disk latency issues in AKS clusters, including identifying bottlenecks in Azure Managed Disks and NVMe storage, and practical tooling for measuring I/O performance.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=yGc7STl48GE">AKS Community Call – US &amp; Europe (Feb 2026)</a></strong>: The February 2026 Community Call covers announcements, community content showcase, a feature deep dive on AKS networking best practices, product roadmap updates, and open Q&amp;A with the AKS team.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=whnksEP0yUI">Troubleshooting OOM failures with Claudio Godoy – AKS Troubleshooting Series</a></strong>: This episode of the AKS Troubleshooting Series covers how to diagnose and resolve out-of-memory (OOM) failures in AKS clusters. It walks through practical scenarios and tooling for identifying memory pressure at both the pod and node level.</p>
</li>
<li><p><strong><a href="https://www.youtube.com/watch?v=10IQeDOtVqo">Troubleshooting DNS Issues with Qasim Sarfaraz – AKS Troubleshooting Series</a></strong>: This episode walks through diagnosing DNS resolution failures in AKS, covering CoreDNS debugging, pod-level DNS configuration, and common pitfalls with custom DNS and LocalDNS setups.</p>
</li>
</ul>
<hr>
<h2>🧠 Closing Thoughts</h2>
<p>February was defined by three clear themes: AI/ML workload maturity, platform security hardening, and operational convergence.</p>
<p>The KAITO InferenceSet with KEDA integration, Ray on AKS with Anyscale, and managed GPU profiles all point to AKS becoming a first-class platform for AI/ML at scale. The investment in event-driven autoscaling for inference workloads directly addresses GPU cost optimization — a top concern for every team running LLMs in production.</p>
<p>On the security front, the nodes/proxy hardening in AKS Automatic, new security patch timestamp annotations, and extensive CVE remediation across Cilium, Konnectivity, and egress gateway components show a consistent push toward defense-in-depth.</p>
<p>The KubeVirt support signals that AKS is also evolving as a convergence platform for teams managing both containerized and VM-based workloads. Combined with the new MCP/Agentic CLI documentation, AKS is expanding its operational surface in meaningful ways.</p>
<p>For platform teams: pay close attention to the LocalDNS default change on Kubernetes 1.35+ and the Windows Server 2019 retirement deadline of March 1, 2026. Both require proactive planning.</p>
]]></content:encoded>
    </item>
  </channel>
</rss>