Initial Guide — AKS: จาก cluster เปล่า ถึง state ปัจจุบัน

จุดประสงค์: หลัง provision AKS cluster ขึ้นมาแล้ว ต้อง config อะไรต่อ เพื่อให้ SuperApp รันได้เหมือน state ปัจจุบัน ตรวจสอบกับของจริงเมื่อ: 2026-09-21 — cluster aks-SupperApp-dev (RG sua-azure-nonprd, subscription 501c116b-493a-452e-a823-c7c0f443d01a, region southeastasia) GitOps repo: https://dev.azure.com/eximth/SuperApp/_git/Backend_Iac branch development

การอ่าน tag ท้าย bullet:

⚠️ ข้อจำกัดของข้อมูล [repo]: อ่านจาก local checkout fdd50179 ซึ่ง ตามหลัง origin/development อยู่ 1042 commit จุดที่รู้ว่าต่างถูกระบุไว้แล้ว แต่ก่อนใช้งานจริงให้ git fetch origin && git checkout origin/development ก่อนเสมอ

ไม่พบ bicep/terraform ที่ provision cluster นี้ใน repo ที่มีในเครื่อง (SuperApp/IaC เป็นชุด manifest รุ่นเก่า ไม่มี Microsoft.ContainerService) → ค่าใน §2–§3 ได้มาจาก az aks show ของ cluster ที่รันอยู่ ไม่ใช่จาก source of truth


0. ขอบเขต


1. Prerequisite นอก cluster (ต้องมีก่อน ไม่งั้น node pull image ไม่ได้)


2. ค่า cluster ปัจจุบัน (ใช้เป็น target ตอน provision)

หัวข้อ ค่าจริง tag
Kubernetes 1.34.10, SKU Base / tier Standard [live]
Auto-upgrade channel patch, node OS NodeImage [live]
Network plugin azure + overlay (networkPluginMode: overlay), dataplane azure, policy azure [live]
Pod CIDR / Service CIDR / DNS IP 100.64.0.0/16 / 10.100.0.0/16 / 10.100.0.10 [live]
Identity UserAssigned (id-aks-SupperApp-dev-cp) + kubelet identity aks-SupperApp-dev-agentpool [live]
AAD managed AAD + Azure RBAC เปิด (enableAzureRbac: true) [live]
Node RG MC_sua-azure-nonprd_aks-SupperApp-dev_southeastasia [live]

Node pools [live]


3. เปิด addon / feature ของ cluster (ลำดับนี้ก่อน deploy อะไรทั้งสิ้น)

คำสั่งอ้างอิง — แยกคนละคำสั่ง (--enable-addons ไม่ใช่ flag ของ az aks update):

RG=sua-azure-nonprd; AKS=aks-SupperApp-dev

# identity
az aks update -g $RG -n $AKS --enable-oidc-issuer --enable-workload-identity

# key vault CSI + rotation
az aks enable-addons -g $RG -n $AKS -a azure-keyvault-secrets-provider \
  --enable-secret-rotation --rotation-poll-interval 1h

# policy
az aks enable-addons -g $RG -n $AKS -a azure-policy

# container insights
az aks enable-addons -g $RG -n $AKS -a monitoring \
  --workspace-resource-id /subscriptions/.../workspaces/log-SupperApp-dev

# managed prometheus + defender
az aks update -g $RG -n $AKS --enable-azure-monitor-metrics
az aks update -g $RG -n $AKS --enable-defender \
  --defender-config <path-or-workspace-id>

# app routing (คำสั่งแยกกลุ่ม)
az aks approuting enable -g $RG -n $AKS

ถ้าทีมมี bicep/terraform สำหรับ provision cluster ให้ยึดไฟล์นั้นเป็นหลักแทนคำสั่งชุดนี้ (ตอนตรวจ 2026-09-21 หาไม่เจอในเครื่อง)


4. Azure Policy / Gatekeeper — รู้ก่อนว่ามันไม่ block


5. ผูก identity / RBAC (ทำก่อน deploy app)


6. Ingress layer

DEV — managed NGINX ผ่าน App Routing CRD [repo] + [live]

UAT — Kong (Helm) [live]

Ingress ของ service [repo]


7. Namespace + ServiceAccount


8. Seed Key Vault (ขั้นนี้ห้ามข้าม — ทำก่อน ArgoCD sync)


9. ติดตั้ง ArgoCD


10. Manifest ของ service (ArgoCD sync ให้เอง)

โครงต่อ 1 service ใน src/yamls/<env>/superapp/ [repo]


11. Observability


12. Namespace security (optional แต่ของจริงมี)


13. CI/CD ที่ทำให้ image เปลี่ยน


14. ⚠️ Gotcha ที่เจอจริงใน cluster ปัจจุบัน


15. Verification checklist

# 1. node + pool
kubectl get nodes -o wide
kubectl get nodes -L workload-type

# 2. addon พร้อม
kubectl get pods -n kube-system | grep -E 'wi-webhook|secrets-store|ama-|azure-policy'

# 3. workload identity ใช้ได้จริง (ต้องเห็น K8s Secret ถูกสร้าง)
kubectl get secretproviderclass -n superappdev
kubectl get secret -n superappdev | head

# 4. ingress ชั้น network
kubectl get ingressclass
kubectl get svc -A | grep LoadBalancer
kubectl get ingress -A

# 5. GitOps
kubectl get applications -n argocd \
  -o custom-columns='NAME:.metadata.name,SYNC:.status.sync.status,HEALTH:.status.health.status'

# 6. workload
kubectl get deploy -n superappdev
kubectl get pods -n superappdev --field-selector=status.phase!=Running

# 7. policy ไม่ block
kubectl get constraints -o custom-columns='KIND:.kind,ACTION:.spec.enforcementAction'

# 8. end-to-end ผ่าน ingress (รันจากใน VNet)
curl -H 'Host: api.sua-az-dev.internal' http://172.29.88.5/api/user-service/health

16. ลำดับสรุป (TL;DR)

  1. Networking + firewall (UDR egress) + subnet 3 ตัว → ACR / KV / MI / Log Analytics
  2. Provision cluster: private, azure CNI overlay, Azure RBAC, 2 node pool (taint/label ตาม §2)
  3. เปิด addon: OIDC + Workload Identity + KV CSI (rotation 1h) + azure-policy + Defender + monitoring + managed Prometheus + app-routing
  4. Role assignment: kubelet→AcrPull, centralize MI→KV/Storage/Redis
  5. สร้าง namespace ทั้งหมด → apply ServiceAccount → สร้าง federated credential ต่อ namespace
  6. Seed Key Vault ให้ครบตาม objectName ใน SecretProviderClass
  7. Apply NginxIngressController (dev) / ติดตั้ง Kong chart (uat)
  8. ติดตั้ง ArgoCD v3.3.9 (server.insecure=true) → repo secret → AppProject → ingress → notifications
  9. Apply umbrella Application หรือ ApplicationSet (เลือกอย่างเดียว) → รอ auto-sync
  10. Observability + security namespace
  11. เดิน checklist §15