PnP edit - Microservices CI/CD pipeline on Kubernetes with Azure DevOps and helm (#16233)
* docs: update CI/CD Kubernetes article with modern best practices
- Add authentication and authorization section (Workload ID, OIDC, ACR integration)
- Add supply chain security section (image signing, SBOM, vulnerability scanning)
- Update master -> main branch references throughout
- Add isolation best practices (network policies, resource quotas, Entra ID RBAC)
- Fix Helm v2 -> v3 syntax (release name positional arg, helm list output)
- Update .NET Core 3.1 -> .NET 8 references and Dockerfile publish path
- Add SAST step to CI pipeline
- Update deployment.extensions -> deployment.apps (deprecated API)
- Add GitOps context (Flux, Argo CD) to alternatives section
- Fix all relative links to absolute /en-us/azure/... paths
- Add GitHub Actions as a first-class alternative alongside Azure Pipelines
- Replace deprecated Pod Security Policies with Pod Security Standards
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* freshness: update ms.date to 03/27/2026 for CI/CD Kubernetes article
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* freshness: update author, ms.author to raykao, ms.date to 03/27/2026
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* freshness: update author, ms.author to raykao, ms.date to 03/27/2026
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Update links to remove 'en-us' from URLs
* Fixing links
* Apply suggestion from @ShannonLeavitt
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
* Update image signing link for Azure Key Vault
Use absolute path to URL instead of relative
* Clean up initial blank lines in CI/CD documentation
Removed unnecessary blank lines at the beginning of the document.
* Add contributors section to CI/CD Kubernetes content
Added contributors section with details about the principal author.
* Apply suggestions from code review
Co-authored-by: Chad Kittel <chad.kittel@gmail.com>
* Use site-relative link for image signing tutorial
Convert the Notation with Azure Key Vault link from an absolute
learn.microsoft.com/en-us URL to the site-relative form per Microsoft
Learn link conventions.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* De-dup GitHub Actions alternative section
Remove the OIDC authentication and starter workflows bullets, which
restate guidance already covered in the Alternatives section and the
Authentication and authorization section. Cross-reference that earlier
content and keep only the GitHub-specific capabilities (environments and
protection rules, marketplace scanning actions).
Addresses review feedback from @ckittel.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Clarify single shared ACR assumption
Clarify that all microservices share a single Azure Container Registry
instance, with a separate repository per microservice.
Addresses review feedback from @ckittel.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Run SAST earlier in the PR CI build
Move static application security testing (SAST) to run right after unit
tests, before building and scanning the container image. SAST analyzes
source code and has no dependency on the image, so running it earlier
follows shift-left security practices and gives faster feedback.
Addresses review feedback from @ckittel.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Fix malformed Azure DevOps build pipeline task list
Split two list items that were merged onto single lines so the build
pipeline tasks render as a clean nine-step ordered list. SAST runs
before the container image is built and scanned, consistent with the CI
flow described earlier in the article.
Addresses review feedback from @ckittel.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Link to namespace-level RBAC with Entra ID
Replace the stale /azure/aks/managed-azure-ad link and split the bullet
into authentication and authorization. Reference the current control
plane authentication doc and the Kubernetes RBAC with Microsoft Entra ID
tutorial, which covers namespace-scoped Roles and RoleBindings.
Addresses review feedback from @ckittel.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Update stale Azure DevOps Helm task link
Replace the old /pipelines/tasks/deploy/helm-deploy link, which
redirects, with the current HelmDeploy@1 task reference and matching
anchor text.
Addresses review feedback from @ckittel.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Restructure auth/secrets guidance and add github product
- Add the github product to the .yml metadata so GitHub appears in the
article's product categories (the manual product line was removed).
- Lead pipeline authentication with Azure Pipelines, then GitHub Actions,
to match the article's AzDO-first framing.
- Reframe the Microsoft Entra Workload ID bullet to make its CI/CD
connection explicit (workloads the pipeline deploys).
- Move the AKS-to-ACR integration guidance to the release pipeline
section, where image pull happens, instead of the auth section.
- Fold the long-lived credentials note into the Secrets management
section.
Addresses review feedback from @ckittel and @ShannonLeavitt.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Integrate supply chain security into pipeline steps
Dissolve the standalone Supply chain security section and distribute its
guidance into the steps where each practice belongs:
- SBOM generation at the runtime container build step.
- Vulnerability scanning now notes it gates publishing (de-duplicates the
former standalone bullet).
- A new image signing step after the image is pushed to the registry.
- Admission control (Azure Policy for AKS) at the production deploy step.
Addresses review feedback from @ckittel.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Update two stale redirecting doc links
Final link-staleness audit found two links that 200 only via redirect to a
renamed page. Point them at the current canonical URLs:
- Prometheus metrics overview moved from /azure-monitor/essentials/ to
/azure-monitor/metrics/.
- The Azure Pipelines CI/CD baseline architecture moved to
/azure/devops/pipelines/architectures/devops-pipelines-baseline-architecture.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Apply suggestions from code review
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Apply suggestions from code review
Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com>
* convert to md only
* links
* edits
* images
* edits
* edit
* edit
* edit
* edit
* feedback
* Update docs/microservices/ci-cd-kubernetes.md
* fixing list formatting
---------
Co-authored-by: Ray Kao <raykao@github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
Co-authored-by: Ray Kao <ray.kao@microsoft.com>
Co-authored-by: Chad Kittel <chad.kittel@gmail.com>
Co-authored-by: Ray Kao <raykao@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com>
Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>