MicrosoftDocs/architecture-center/docs/microservices

Last 20 commits touching this section.

498e83a

PNP Edit: [FRESHNESS] Scheduler agent supervisor - ph4 (#16773) * first draft * Apply engineering review fixes: WAF service guide links, consolidate alternatives, lint fix * Address reviewer feedback: fix blank first line, dangling Process Manager reference, add missing links, remove duplicate Implementation-in-Azure section, de-technologize two notes * Apply batched suggestions from code review Co-authored-by: learn-build-service-prod-01[bot] <274427437+learn-build-service-prod-01[bot]@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Apply batched suggestions from code review Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Some minor changes as part of review * Adjust solution a bit and dedup * Final touches before review * Update metadata * Apply batched suggestions from code review Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Enhance documentation on Agent and Scheduler behavior Clarified the Agent's behavior regarding retry logic and handling of timeouts. Added details on how the Scheduler and Supervisor manage steps that have timed out or failed. Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Typo fix * convert * edits * edits * touchups * fix dupe headings * peer review cx * edit * add line ending to force display? * fix * some edits * fix * Update docs/patterns/scheduler-agent-supervisor.md * Update docs/patterns/scheduler-agent-supervisor.md Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> --------- Co-authored-by: Anastasia Harris <61602255+anaharris-ms@users.noreply.github.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com> Co-authored-by: learn-build-service-prod-01[bot] <274427437+learn-build-service-prod-01[bot]@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com>

8f5f5d0

PnP edit: Gateway Offloading pattern (#16762) * first draft * Apply suggestion from @jluocsa Co-authored-by: John CSA <103165870+jluocsa@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Apply suggestion from @learn-build-service-prod-10[bot] Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Remove Nginx configuration and update links Removed Nginx TLS offloading configuration example and updated related resources link. * Update gateway-offloading-content.md * Address review feedback: replace mermaid with SVG, TLS to backend, intro wording * Address Gateway Offloading review feedback and update TLS diagrams * Enhance WAF policy with ZZ country code handling Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Use TLS re-encryption diagram in Gateway Offloading pattern * Adjust images * Apply batched suggestions from code review Co-authored-by: Chad Kittel <chad.kittel@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Apply batched suggestions from code review Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Update author * SSL reference * Update gateway offloading content for clarity Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * convert to md only * fix links * edits * edits * edits * edits * edits * edits --------- Co-authored-by: Anastasia Harris <61602255+anaharris-ms@users.noreply.github.com> Co-authored-by: John CSA <103165870+jluocsa@users.noreply.github.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com> Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

e1fb268

Use lightboxes where it helps Align image lightbox usage with the width of the displayed image, using a threshold of >688px. - Added lightbox to 6 images wider than 688px. - Removed lightbox from 10 images at or under 688px. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

bc6388b

Apply suggestion from @ckittel

f44f0fd

Clarify Azure DocumentDB recommendation Co-authored-by: ckittel <671075+ckittel@users.noreply.github.com>

f69851e

PnP edit - Microservices CI/CD pipeline on Kubernetes with Azure DevOps and helm (#16233) * docs: update CI/CD Kubernetes article with modern best practices - Add authentication and authorization section (Workload ID, OIDC, ACR integration) - Add supply chain security section (image signing, SBOM, vulnerability scanning) - Update master -> main branch references throughout - Add isolation best practices (network policies, resource quotas, Entra ID RBAC) - Fix Helm v2 -> v3 syntax (release name positional arg, helm list output) - Update .NET Core 3.1 -> .NET 8 references and Dockerfile publish path - Add SAST step to CI pipeline - Update deployment.extensions -> deployment.apps (deprecated API) - Add GitOps context (Flux, Argo CD) to alternatives section - Fix all relative links to absolute /en-us/azure/... paths - Add GitHub Actions as a first-class alternative alongside Azure Pipelines - Replace deprecated Pod Security Policies with Pod Security Standards Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * freshness: update ms.date to 03/27/2026 for CI/CD Kubernetes article Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * freshness: update author, ms.author to raykao, ms.date to 03/27/2026 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * freshness: update author, ms.author to raykao, ms.date to 03/27/2026 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update links to remove 'en-us' from URLs * Fixing links * Apply suggestion from @ShannonLeavitt Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com> * Update image signing link for Azure Key Vault Use absolute path to URL instead of relative * Clean up initial blank lines in CI/CD documentation Removed unnecessary blank lines at the beginning of the document. * Add contributors section to CI/CD Kubernetes content Added contributors section with details about the principal author. * Apply suggestions from code review Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Use site-relative link for image signing tutorial Convert the Notation with Azure Key Vault link from an absolute learn.microsoft.com/en-us URL to the site-relative form per Microsoft Learn link conventions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * De-dup GitHub Actions alternative section Remove the OIDC authentication and starter workflows bullets, which restate guidance already covered in the Alternatives section and the Authentication and authorization section. Cross-reference that earlier content and keep only the GitHub-specific capabilities (environments and protection rules, marketplace scanning actions). Addresses review feedback from @ckittel. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Clarify single shared ACR assumption Clarify that all microservices share a single Azure Container Registry instance, with a separate repository per microservice. Addresses review feedback from @ckittel. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Run SAST earlier in the PR CI build Move static application security testing (SAST) to run right after unit tests, before building and scanning the container image. SAST analyzes source code and has no dependency on the image, so running it earlier follows shift-left security practices and gives faster feedback. Addresses review feedback from @ckittel. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix malformed Azure DevOps build pipeline task list Split two list items that were merged onto single lines so the build pipeline tasks render as a clean nine-step ordered list. SAST runs before the container image is built and scanned, consistent with the CI flow described earlier in the article. Addresses review feedback from @ckittel. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Link to namespace-level RBAC with Entra ID Replace the stale /azure/aks/managed-azure-ad link and split the bullet into authentication and authorization. Reference the current control plane authentication doc and the Kubernetes RBAC with Microsoft Entra ID tutorial, which covers namespace-scoped Roles and RoleBindings. Addresses review feedback from @ckittel. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update stale Azure DevOps Helm task link Replace the old /pipelines/tasks/deploy/helm-deploy link, which redirects, with the current HelmDeploy@1 task reference and matching anchor text. Addresses review feedback from @ckittel. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Restructure auth/secrets guidance and add github product - Add the github product to the .yml metadata so GitHub appears in the article's product categories (the manual product line was removed). - Lead pipeline authentication with Azure Pipelines, then GitHub Actions, to match the article's AzDO-first framing. - Reframe the Microsoft Entra Workload ID bullet to make its CI/CD connection explicit (workloads the pipeline deploys). - Move the AKS-to-ACR integration guidance to the release pipeline section, where image pull happens, instead of the auth section. - Fold the long-lived credentials note into the Secrets management section. Addresses review feedback from @ckittel and @ShannonLeavitt. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Integrate supply chain security into pipeline steps Dissolve the standalone Supply chain security section and distribute its guidance into the steps where each practice belongs: - SBOM generation at the runtime container build step. - Vulnerability scanning now notes it gates publishing (de-duplicates the former standalone bullet). - A new image signing step after the image is pushed to the registry. - Admission control (Azure Policy for AKS) at the production deploy step. Addresses review feedback from @ckittel. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update two stale redirecting doc links Final link-staleness audit found two links that 200 only via redirect to a renamed page. Point them at the current canonical URLs: - Prometheus metrics overview moved from /azure-monitor/essentials/ to /azure-monitor/metrics/. - The Azure Pipelines CI/CD baseline architecture moved to /azure/devops/pipelines/architectures/devops-pipelines-baseline-architecture. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> * convert to md only * links * edits * images * edits * edit * edit * edit * edit * feedback * Update docs/microservices/ci-cd-kubernetes.md * fixing list formatting --------- Co-authored-by: Ray Kao <raykao@github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com> Co-authored-by: Ray Kao <ray.kao@microsoft.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com> Co-authored-by: Ray Kao <raykao@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com> Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>

4587bbd

Pipeline: [Refresh][Cloud Pattern] Queue-Based Load Leveling pattern (#15947) * Refresh * Articles Review * Update docs/patterns/queue-based-load-leveling-content.md Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Update docs/patterns/queue-based-load-leveling-content.md Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Update docs/patterns/queue-based-load-leveling-content.md Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Update docs/patterns/queue-based-load-leveling-content.md Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Update docs/patterns/queue-based-load-leveling-content.md Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Update docs/patterns/queue-based-load-leveling-content.md Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * Addressing PR comments * Apply suggestions from code review Co-authored-by: Chad Kittel <chad.kittel@gmail.com> * yml to md * edits * copilot suggestions * edits --------- Co-authored-by: Federico Arambarri <v-federicoar@microsoft.com> Co-authored-by: Chad Kittel <chad.kittel@gmail.com>

6d6f8fe

Merge branch 'main' into 15654

4691d47

PR review: Correct IP allowlist terminology to IP allow list Acrolinx Terminology fixes.

b9838c9

Merge pull request #15711 from Court72/anti-corruption-edits Pipeline: [Refresh][Cloud Pattern] Anti corruption layer

780d6ff

Merge pull request #15834 from jmart1428/edit-throttling Pipeline: [Freshness] Throttling pattern

2b5c235

Update gateway-content.md

dc4ab18

Clarify gateway + service mesh (customer feedback)

613186d

Apply suggestion from @ckittel

9622be6

use italics instead

3c1ab06

No PSP anymore

5be585b

update link references

6b295a0

convert MD+YML pair to MD

93dbc1d

Merge branch 'main' of https://github.com/MicrosoftDocs/architecture-center-pr into anti-corruption-edits

eb86803

Apply suggestion from @jmart1428