[{"author":"ckittel","date":"2026-10-04T07:45:48+00:00","message":"Reassign articles after org changes (#16843)\n\n* switch to clayton\n\n* Switch priyanka","sha":"978a72004fbbb1341363009d4fdd669b18a2235f","url":"https://github.com/MicrosoftDocs/architecture-center/commit/978a72004fbbb1341363009d4fdd669b18a2235f"},{"author":"v-thepet","date":"2026-09-10T21:53:16+00:00","message":"PNP Edit: [AAC] Maintenance - Hybrid-ARB | Update Azure Hybrid Options + Getting Started articles (#16585)\n\n* Azure hybrid options - Complete article rewrite\n\n* Address hybrid options review feedback\n\n* Address hybrid architecture review comments\n\n* add spacing for clarity when reading\n\n* Reduce bullet spacing\n\n* updated spacing\n\n* Clarify disconnected operations eligibility\n\n* Refresh hybrid getting started guide\n\nConvert the hybrid Getting Started article to the YAML-plus-content pattern, move conceptual guidance and its diagram from Azure hybrid options, add browse metadata and a thumbnail, update navigation and inbound references, and keep detailed selection criteria in the options article.\n\n* Improve hybrid options workload flow\n\nFrame specialized service evaluation as the next step after selecting workload placement, infrastructure, and connectivity, and broaden the heading to reflect the services covered.\n\n* Fix hybrid getting started title\n\nUse singular architecture consistently in the YAML metadata and remove the duplicate H1 from the included Markdown body.\n\n* Address hybrid options review comments\n\nAdd Azure Local operating limits and preview status, include Azure Arc-enabled Kubernetes in the decision-tree description, and preserve the intentional contributor attribution.\n\n* Update hybrid technology choices overview\n\n* Update technology choices review date\n\n* Clarify hybrid control plane options\n\n* Restore technology choices review date\n\n* Restore hybrid guide Markdown format\n\nKeep the Getting Started Architecture Guide as a standalone Markdown article, remove the YAML wrapper and its browse thumbnail, and update inbound links.\n\n* Clarify Azure IoT Operations offline limit\n\nUpdate the hybrid services diagram and accessible description to distinguish Azure Local disconnected operations from Azure IoT Operations' 72-hour offline window. Remove the redundant diagram footer.\n\n* Refine hybrid services diagram\n\nReplace the hybrid services diagram to keep Azure IoT Operations in the Edge and IoT category, clarify the Azure Local service list, and synchronize the accessible description.\n\n* Correct hybrid decision tree label\n\nChange the connected Azure Local path from \"control plan\" to \"control plane\" in the SVG and matching browse thumbnail.\n\n* Clarify Azure Local outage impact\n\nDocument immediate cloud-dependent feature limitations, the 30-day reduced-functionality threshold, and AKS certificate-expiration risk during Azure connectivity loss.\n\n* Scope Azure Local sync guidance\n\nQualify the documented 30-day synchronization and reduced-functionality behavior as applying to hyperconverged Azure Local deployments.\n\n* Apply suggestions from code review\n\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\n\n* Update images\n\n* Address hybrid architecture review feedback\n\nIncorporate reviewer guidance on portability, edge AI, workload placement, recovery objectives, service wording, preview usage, and contributors.\n\n* Refine Azure Local reliability link text\n\n* Update hybrid options article date\n\n* improvements for Resiliency and recovery\n\n* Clarify hybrid deployment and connectivity guidance\n\nCorrect Azure Local deployment taxonomy, distinguish ExpressRoute from VPN Gateway connectivity, and restore the overview article freshness date.\n\n* Update hybrid connectivity diagram label\n\nRename the decision-tree branch to \u201cConnectivity to Azure services\u201d and refresh the matching browse thumbnail.\n\n* Clarify failover testing cadence\n\nBase Azure Local test-failover frequency on workload criticality, recovery objectives, business and compliance requirements, and material changes instead of a universal monthly interval.\n\n* Apply suggestion from @ckittel\n\n* Reference Sovereign Private Cloud in hybrid guidance\n\n* update ms.date\n\n* Reorder hybrid candidate approaches\n\n* Restore technology choices review date\n\n* Add private access selection guidance\n\n* Clarify Azure Arc machine support\n\n* Clarify VPN wording from review 5083098602\n\nAddresses feedback from https://github.com/MicrosoftDocs/architecture-center-pr/pull/16383#pullrequestreview-5083098602 by distinguishing ExpressRoute from an encrypted site-to-site VPN in the article diagram and synchronized browse thumbnail.\n\n* get started article\n\n* options\n\n* edits\n\n* edits\n\n* edits\n\n* copilot\n\n* edits\n\n* not a tree\n\n* rearrange to fit template\n\n* Revert last 2 commits\n\n* revert toc\n\n* peer review cx\n\n* make png 3-2\n\n* Apply batched suggestions from code review\n\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\n\n* Fix link\n\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\n\n* .\n\n* .\n\n* .\n\n* fix\n\n---------\n\nCo-authored-by: Neil Bird <nebird@microsoft.com>\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>","sha":"0dfe9874bb80709752839f9cda6f8a5091b0dbda","url":"https://github.com/MicrosoftDocs/architecture-center/commit/0dfe9874bb80709752839f9cda6f8a5091b0dbda"},{"author":"azure-patterns-practices-assistant","date":"2026-08-27T18:28:21+00:00","message":"Sync category get-started includes with TOC (#16484)\n\n* Sync category get-started includes with TOC subtrees\n\nReconcile all 14 managed get-started include files under docs/includes/\nso each mirrors the section structure, order, nesting, and link\nmembership of its corresponding category subtree in docs/toc.yml, while\npreserving curated non-TOC content such as prose and links to product\ndocumentation.\n\n- AI + Machine Learning: reordered AI guides section so direct links\n  precede subsections; corrected two link texts.\n- Analytics: reordered sections to match subtree (Select a service,\n  Solution ideas, Architectures, Guides); fixed several link texts.\n- Compute: restructured into Select a service, Solution ideas,\n  Architectures, Guides, and a new SAP section with its own\n  subsections; fixed link texts.\n- Containers: fully restructured into Select a service, Container\n  guides, Kubernetes-based hosting (with nested solution\n  ideas/architectures/guides and day-2 operations guide), and PaaS\n  container hosting; disambiguated duplicate Application/Infrastructure\n  headings; corrected several link texts; updated an anchor reference\n  in the parent article.\n- Databases: restructured into Select a service, Solution ideas,\n  Architectures, and Guides sections matching the subtree.\n- DevOps: reordered to Solution ideas, Architectures, Guides.\n- Identity: reordered to Solution ideas, Architectures, Guides.\n- Integration: restructured into Select a service, Solution ideas,\n  Architectures, Guides.\n- Management + Governance: reordered to Architectures, then Guides.\n- Networking: restructured into Select a service, Architectures\n  (Network topology, Network security), and Guides subsections.\n- Storage: reordered to Select a service, Solution ideas,\n  Architectures.\n- Virtual Desktop: reordered to Architectures, then Guides.\n- Web applications: reordered to Solution ideas, Architectures,\n  Guides, Hosting WordPress on Azure.\n\nIoT include already matched its subtree and needed no changes.\n\n* Apply suggestions from code review\n\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\nCo-authored-by: learn-build-service-prod-01[bot] <274427437+learn-build-service-prod-01[bot]@users.noreply.github.com>\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\n\n* Update docs/includes/analytics-get-started-include.md\n\nCo-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com>\n\n* Fix nesting order in compute and container get-started includes\n\nCo-authored-by: ckittel <671075+ckittel@users.noreply.github.com>\n\n---------\n\nCo-authored-by: azure-patterns-practices-assistant[bot] <316226753+azure-patterns-practices-assistant[bot]@users.noreply.github.com>\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\nCo-authored-by: learn-build-service-prod-01[bot] <274427437+learn-build-service-prod-01[bot]@users.noreply.github.com>\nCo-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com>\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>\nCo-authored-by: ckittel <671075+ckittel@users.noreply.github.com>","sha":"4bb6fa26528ae5fd51f40c480e87edc00c1f8244","url":"https://github.com/MicrosoftDocs/architecture-center/commit/4bb6fa26528ae5fd51f40c480e87edc00c1f8244"},{"author":"azure-patterns-practices-assistant","date":"2026-08-26T20:44:14+00:00","message":"Fix redirected links in 3 articles\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"d6ef15167b11bdd59c441e3af2068b5e86369155","url":"https://github.com/MicrosoftDocs/architecture-center/commit/d6ef15167b11bdd59c441e3af2068b5e86369155"},{"author":"anaharris-ms","date":"2026-08-25T15:26:19+00:00","message":"Centralize category get-started content in includes (#16412)","sha":"94e21ef9746fb6657c4bd81710a00d4821391d14","url":"https://github.com/MicrosoftDocs/architecture-center/commit/94e21ef9746fb6657c4bd81710a00d4821391d14"},{"author":"v-albemi","date":"2026-08-05T21:38:36+00:00","message":"PnP edit - Microservices CI/CD pipeline on Kubernetes with Azure DevOps and helm  (#16233)\n\n* docs: update CI/CD Kubernetes article with modern best practices\n\n- Add authentication and authorization section (Workload ID, OIDC, ACR integration)\n- Add supply chain security section (image signing, SBOM, vulnerability scanning)\n- Update master -> main branch references throughout\n- Add isolation best practices (network policies, resource quotas, Entra ID RBAC)\n- Fix Helm v2 -> v3 syntax (release name positional arg, helm list output)\n- Update .NET Core 3.1 -> .NET 8 references and Dockerfile publish path\n- Add SAST step to CI pipeline\n- Update deployment.extensions -> deployment.apps (deprecated API)\n- Add GitOps context (Flux, Argo CD) to alternatives section\n- Fix all relative links to absolute /en-us/azure/... paths\n- Add GitHub Actions as a first-class alternative alongside Azure Pipelines\n- Replace deprecated Pod Security Policies with Pod Security Standards\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* freshness: update ms.date to 03/27/2026 for CI/CD Kubernetes article\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* freshness: update author, ms.author to raykao, ms.date to 03/27/2026\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* freshness: update author, ms.author to raykao, ms.date to 03/27/2026\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Update links to remove 'en-us' from URLs\n\n* Fixing links\n\n* Apply suggestion from @ShannonLeavitt\n\nCo-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>\n\n* Update image signing link for Azure Key Vault\n\nUse absolute path to URL instead of relative\n\n* Clean up initial blank lines in CI/CD documentation\n\nRemoved unnecessary blank lines at the beginning of the document.\n\n* Add contributors section to CI/CD Kubernetes content\n\nAdded contributors section with details about the principal author.\n\n* Apply suggestions from code review\n\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\n\n* Use site-relative link for image signing tutorial\n\nConvert the Notation with Azure Key Vault link from an absolute\nlearn.microsoft.com/en-us URL to the site-relative form per Microsoft\nLearn link conventions.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* De-dup GitHub Actions alternative section\n\nRemove the OIDC authentication and starter workflows bullets, which\nrestate guidance already covered in the Alternatives section and the\nAuthentication and authorization section. Cross-reference that earlier\ncontent and keep only the GitHub-specific capabilities (environments and\nprotection rules, marketplace scanning actions).\n\nAddresses review feedback from @ckittel.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Clarify single shared ACR assumption\n\nClarify that all microservices share a single Azure Container Registry\ninstance, with a separate repository per microservice.\n\nAddresses review feedback from @ckittel.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Run SAST earlier in the PR CI build\n\nMove static application security testing (SAST) to run right after unit\ntests, before building and scanning the container image. SAST analyzes\nsource code and has no dependency on the image, so running it earlier\nfollows shift-left security practices and gives faster feedback.\n\nAddresses review feedback from @ckittel.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Fix malformed Azure DevOps build pipeline task list\n\nSplit two list items that were merged onto single lines so the build\npipeline tasks render as a clean nine-step ordered list. SAST runs\nbefore the container image is built and scanned, consistent with the CI\nflow described earlier in the article.\n\nAddresses review feedback from @ckittel.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Link to namespace-level RBAC with Entra ID\n\nReplace the stale /azure/aks/managed-azure-ad link and split the bullet\ninto authentication and authorization. Reference the current control\nplane authentication doc and the Kubernetes RBAC with Microsoft Entra ID\ntutorial, which covers namespace-scoped Roles and RoleBindings.\n\nAddresses review feedback from @ckittel.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Update stale Azure DevOps Helm task link\n\nReplace the old /pipelines/tasks/deploy/helm-deploy link, which\nredirects, with the current HelmDeploy@1 task reference and matching\nanchor text.\n\nAddresses review feedback from @ckittel.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Restructure auth/secrets guidance and add github product\n\n- Add the github product to the .yml metadata so GitHub appears in the\n  article's product categories (the manual product line was removed).\n- Lead pipeline authentication with Azure Pipelines, then GitHub Actions,\n  to match the article's AzDO-first framing.\n- Reframe the Microsoft Entra Workload ID bullet to make its CI/CD\n  connection explicit (workloads the pipeline deploys).\n- Move the AKS-to-ACR integration guidance to the release pipeline\n  section, where image pull happens, instead of the auth section.\n- Fold the long-lived credentials note into the Secrets management\n  section.\n\nAddresses review feedback from @ckittel and @ShannonLeavitt.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Integrate supply chain security into pipeline steps\n\nDissolve the standalone Supply chain security section and distribute its\nguidance into the steps where each practice belongs:\n\n- SBOM generation at the runtime container build step.\n- Vulnerability scanning now notes it gates publishing (de-duplicates the\n  former standalone bullet).\n- A new image signing step after the image is pushed to the registry.\n- Admission control (Azure Policy for AKS) at the production deploy step.\n\nAddresses review feedback from @ckittel.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Update two stale redirecting doc links\n\nFinal link-staleness audit found two links that 200 only via redirect to a\nrenamed page. Point them at the current canonical URLs:\n\n- Prometheus metrics overview moved from /azure-monitor/essentials/ to\n  /azure-monitor/metrics/.\n- The Azure Pipelines CI/CD baseline architecture moved to\n  /azure/devops/pipelines/architectures/devops-pipelines-baseline-architecture.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com>\n\n* convert to md only\n\n* links\n\n* edits\n\n* images\n\n* edits\n\n* edit\n\n* edit\n\n* edit\n\n* edit\n\n* feedback\n\n* Update docs/microservices/ci-cd-kubernetes.md\n\n* fixing list formatting\n\n---------\n\nCo-authored-by: Ray Kao <raykao@github.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCo-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>\nCo-authored-by: Ray Kao <ray.kao@microsoft.com>\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\nCo-authored-by: Ray Kao <raykao@users.noreply.github.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\nCo-authored-by: learn-build-service-prod-02[bot] <274428175+learn-build-service-prod-02[bot]@users.noreply.github.com>\nCo-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>","sha":"f69851e7c8b27ca6e8983e7b7d91d35e99423a73","url":"https://github.com/MicrosoftDocs/architecture-center/commit/f69851e7c8b27ca6e8983e7b7d91d35e99423a73"},{"author":"ckittel","date":"2026-07-01T20:57:03+00:00","message":"Update ms.author to pnp","sha":"8f07141d7e0fb3638649f83ffb8faf42f0433b3c","url":"https://github.com/MicrosoftDocs/architecture-center/commit/8f07141d7e0fb3638649f83ffb8faf42f0433b3c"},{"author":"v-stsavell","date":"2026-07-01T18:15:31+00:00","message":"Pipeline: Category Get Started Update: Container (#15762)\n\n* edits\n\n* Update container-get-started.md\n\n* Update container-get-started.md\n\n* Apply suggestions from code review\n\nCo-authored-by: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com>\n\n* Apply suggestion from @v-stsavell\n\n* Apply suggestion from @v-albemi\n\nCo-authored-by: Mick Alberts <v-albemi@microsoft.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: Jodi Martis <v-jodimartis@microsoft.com>\n\n* Remove 'Other resources' section from container guide\n\nRemoved the 'Other resources' section that provided information on hybrid and multicloud container solutions.\n\n* Apply suggestion from @v-stsavell\n\n* Apply suggestions from code review\n\nCo-authored-by: learn-build-service-prod-05[bot] <274429479+learn-build-service-prod-05[bot]@users.noreply.github.com>\nCo-authored-by: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com>\n\n* edits\n\n* Update container-get-started.md\n\n---------\n\nCo-authored-by: Mick Alberts <v-albemi@microsoft.com>\nCo-authored-by: Jodi Martis <v-jodimartis@microsoft.com>\nCo-authored-by: learn-build-service-prod-05[bot] <274429479+learn-build-service-prod-05[bot]@users.noreply.github.com>","sha":"81aa8f8a29fb8f4b12b037a1937ba318fa2d21de","url":"https://github.com/MicrosoftDocs/architecture-center/commit/81aa8f8a29fb8f4b12b037a1937ba318fa2d21de"},{"author":"v-stsavell","date":"2026-06-30T17:06:29+00:00","message":"Pipeline: [MAINT] AGC successor of AGIC Update (#16015)\n\n* AGC successor of AGIC Update\n\nUpdated all AGIC to AGC and update the diagram to reflect as well\n\n* Address Copilot review: fix INCLUDE syntax, AGC/AGIC consistency, deploy link, remove unused svg\n\n- aks-agic.yml: fix broken INCLUDE syntax (missing closing bracket) which caused link-out-of-scope warning\n- aks-agc-content.md: restore concrete GitHub repo link in 'Deploy this scenario' section\n- aks-firewall-content.md: clarify that AGC terminates TLS at the AGC frontend (not at an Application Gateway listener); keep AGIC mention for the listener-based pattern\n- blue-green-deployment-for-aks-content.md: align terminology - AGC is the Azure-managed L7 LB, ALB controller is the in-cluster controller; replace leftover 'we use AGIC' with AGC + ALB controller\n- Remove unused media/aks-agic-updated.svg (orphan file, triggered image-name-incomplete suggestion)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* aks-agic-updated.svg\n\nupdate this\n\n* Fix three broken Learn site links flagged by validation\n\n- aks-agc-content.md L113: '/for-containers/how-to-multiple-namespaces' (404) -> /for-containers/how-to-multiple-site-hosting-gateway-api\n- aks-agc-content.md L229: '/for-containers/how-to-configure-waf-policy-ingress-api' (404) -> /for-containers/web-application-firewall\n- blue-green-deployment-for-aks-content.md L330: '/for-containers/alb-controller' (404) -> /for-containers/quickstart-deploy-application-gateway-for-containers-alb-controller\n\nAll replacement URLs verified live (HTTP 200).\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Address Jack's review feedback: clarify AGC vs AGIC, update terminology\n\n- Clarify AGC is its own service, not dependent on Application Gateway\n- Replace AGIC-era language (listeners, ARM-applied config, CRS) with AGC-correct terminology (Gateway API, DRS 2.1)\n- Spell out 'Application Gateway for Containers' per marketing guidance\n- Correct multi-namespace claims (supported out of box)\n- Remove legally-loaded SLA percentages, link to official SLA docs\n- Switch to add-on quickstart link\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Refine descriptions for Application Gateway options\n\n* Clarify ALB controller's namespace ingestion capability\n\nRemoved redundant information about ALB controller's capability to ingest events from multiple Kubernetes namespaces.\n\n* Rename aks-agic-updated.svg to aks-agc-architecture.svg and add AGCAccessLogs query reference\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Replace App Gateway concepts with Gateway API resources in sample diagram\n\nMap AppGW concepts to Gateway API equivalents in aks-agc-sample.svg:\n- HTTP listener -> Gateway\n- Rule (Basic) -> HTTPRoute (Match)\n- Back-end pool -> Service\nAlso rename file aks-agic-sample.svg -> aks-agc-sample.svg and update reference.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Fix Microsoft.ServiceNetworking RP text overflow and update Ingress to Gateway in sample diagram\n\n- Wrap 'Microsoft.ServiceNetworking/trafficControllers resource provider' across 4 lines so text fits inside the box\n- Grow the box height downward so it no longer overlaps the Azure Resource Manager header\n- Replace remaining in-cluster Ingress boxes with Gateway (Listeners/Hostname/TLS certificate/Rules) for Gateway API alignment\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Update author and ms.author to Vyshnavi-MSFT/vnamani\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Add Vyshnavi Namani as a principal author\n\n* Address feedback: clarify Azure Firewall + AGC topology constraints\n\nAGC is always public/internet-facing today, so placing Azure Firewall in front of AGC isn't feasible. Recommend AGC in front of AzFW with AzFW between AKS and AGC via route tables, and call out that this design requires Azure CNI (not CNI Overlay).\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Fix link for Application Gateway diagnostics settings\n\nUpdated the link for enabling diagnostic settings for Application Gateway for Containers to the correct documentation page.\n\n* added feedback on frontend ip\n\n* Address John Downs review (non-multitenancy items): jumpbox/Bastion, Key Vault NOTE, drop classic AppGW, NGINX -> Gateway API, tab-link cleanup, Bicep-first, restructure Alternatives, expand ALB acronym, uptime SLA link, soften Let's Encrypt, remove Deploy section; remove find-pod-icon.js\n\nMultitenancy considerations to follow in a separate commit.\n\n* Clarify Application Gateway for Containers multitenancy framing\n\n- Clarify in the overview that Application Gateway for Containers is a single-tenant Azure resource, with multitenancy living inside the AKS cluster (namespaces, HTTPRoutes, tenant workloads).\n- Reword the taints-and-tolerations Performance Efficiency bullet to describe scheduling intent (avoid CPU/memory contention on dedicated nodes) in clearer language.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Clarify multitenancy description in AKS documentation\n\nCorrected wording for clarity regarding multitenancy in Application Gateway for Containers architecture.\n\n* Address John Downs review feedback with CELA pass\n\n- Rewrite intro to lead with Application Gateway for Containers and\n  multitenancy; keep WAF as supporting protection. State Application\n  Gateway for Containers single-tenancy explicitly.\n- Tighten multitenancy framing paragraph: remove conversational\n  asides, fold in the \"single ALB controller / multiple namespaces\"\n  callout that was previously at the end of Alternatives.\n- Potential use cases: fix \"tenant\" -> \"multitenant\", reorder bullets\n  so Namespace-scoped RBAC follows Per-tenant TLS, italicize\n  security policy resource name, replace slash with \"and\".\n- Add Deploy this scenario section with the multitenant sample\n  diagram (aks-agc-sample.svg).\n- Remove broken #multitenancy-considerations anchor reference.\n- CELA pass across the article: remove \"guarantee\", \"enhanced\",\n  \"in a more secure manner\", \"more safe / fast / reliable\", and\n  similar non-factual qualifiers. Replace \"enhanced capabilities\"\n  with the specific capabilities (Gateway API support, Azure-managed\n  data plane).\n- Fix author byline format and product name casing.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Update sample diagram and apply CELA pass to multitenancy framing\n\n- Replace aks-agc-sample.svg with updated Visio export: Gateway,\n  HTTPRoute, Service, and Secret are now inside the AKS cluster\n  boundary (not inside AGC); fix \"TLS certification\" -> \"TLS certificate\"\n- Delete redundant aks-agic-multitenancy.svg\n- Tighten the multitenancy NOTE for customer-facing voice and concision\n- CELA pass: remove \"guarantee perfectly secure\" / \"sufficient\" from\n  Kubernetes isolation paragraph\n- Replace \"shared frontend\" -> \"shared ingress\" in use case bullets to\n  avoid confusion with Azure Front Door (the Application Gateway for\n  Containers Frontend resource name is preserved in body text)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Link AGC WAF doc in Next steps\n\nReplace the Application Gateway v1/v2 WAF policy link with the Web\nApplication Firewall on Application Gateway for Containers doc, since\nthis article is Application Gateway for Containers-only.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Clarify BYO vs Kubernetes-managed: recommend BYO for shared multitenant ingress\n\nReviewer feedback: the multitenant shared-ingress pattern in this article\nrequires a single shared Application Gateway for Containers Azure resource.\nThe Kubernetes-managed model provisions one AGC per ApplicationLoadBalancer\ncustom resource, so it does not fit this scenario. Explicitly recommend BYO\nand explain why.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Reframe BYO vs ALB Controller guidance as IMPORTANT callout\n\nClarify that the multitenant architecture shares a single Application\nGateway for Containers Azure resource, and explain why the BYO management\nmodel is the right fit (vs. managed by ALB Controller, which would create\none Azure resource per tenant).\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Refine AGfC multitenant guidance and replace sample diagram\n\n- Unify terminology to \"ALB Controller-managed\" (en-dash) across BYO vs\n  managed comparison and the IMPORTANT callout\n- Replace aks-agc-sample.svg with simplified per-tenant view that\n  includes HTTPRoute boxes inside each tenant namespace\n- Quality fixes from CELA + docs review:\n  - Sentence-case headings for WAF pillars\n  - Soften absolute claim on container image sizing\n  - Fix /Azure/aks URL casing\n  - Make main architecture alt text descriptive\n  - Correct HTTP 403 status name to \"Forbidden\"\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Apply Niall's review feedback: clarity and active-voice edits\n\nCo-authored-by: Niall Glynn <glynnniall@users.noreply.github.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* edits\n\n* edits\n\n* Apply suggestions from code review\n\nCo-authored-by: Mick Alberts <v-albemi@microsoft.com>\nCo-authored-by: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com>\n\n* Apply suggestion from @v-stsavell\n\n* Apply suggestions from code review\n\nCo-authored-by: Mick Alberts <v-albemi@microsoft.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: Jodi Martis <v-jodimartis@microsoft.com>\n\n* redirect\n\n* edits\n\n---------\n\nCo-authored-by: Vyshnavi-MSFT <vnamani@microsoft.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCo-authored-by: Jodi Martis <v-jodimartis@microsoft.com>\nCo-authored-by: Niall Glynn <glynnniall@users.noreply.github.com>\nCo-authored-by: Mick Alberts <v-albemi@microsoft.com>","sha":"0a8efebff3277fb980c39ed05d5e9e07fb5fb1cb","url":"https://github.com/MicrosoftDocs/architecture-center/commit/0a8efebff3277fb980c39ed05d5e9e07fb5fb1cb"},{"author":"cdpark","date":"2026-06-25T20:50:09+00:00","message":"Update ms-service","sha":"ed3d3bba994121e98807c06c458550f479efdbf8","url":"https://github.com/MicrosoftDocs/architecture-center/commit/ed3d3bba994121e98807c06c458550f479efdbf8"},{"author":"v-stsavell","date":"2026-06-22T21:50:12+00:00","message":"Pipeline: Freshness Pass for Use Azure Firewall to help protect an AKS cluster Doc (#15982)\n\n* Update AKS Firewall documentation with correct author information and date\n\n* markdown changes before review\n\n* Enhance AKS Firewall documentation with egress configuration details and SNAT capacity planning\n\n* Apply suggestions from code review\n\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\n\n* Remove redundant DNAT rule explanation for Azure Firewall in AKS documentation\n\n* Apply suggestions from code review\n\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\n\n* Remove extranous links (again)\n\n* Clarify application reference in Azure Firewall ingress controller documentation\n\n* convert md+yml pair to md file\n\n* fix\n\n* edits\n\n* Apply suggestions from code review\n\nCo-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>\n\n* fix\n\n* Apply suggestions from code review\n\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\nCo-authored-by: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: Mick Alberts <v-albemi@microsoft.com>\nCo-authored-by: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: learn-build-service-prod-08[bot] <274430765+learn-build-service-prod-08[bot]@users.noreply.github.com>\nCo-authored-by: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: learn-build-service-prod-08[bot] <274430765+learn-build-service-prod-08[bot]@users.noreply.github.com>\nCo-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>\nCo-authored-by: Stephanie Savell <101299710+v-stsavell@users.noreply.github.com>\n\n* Update aks-firewall.md\n\n* Apply suggestions from code review\n\nCo-authored-by: Jodi Martis <v-jodimartis@microsoft.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\n\n* Update baseline-aks-content.md\n\n---------\n\nCo-authored-by: Sam Cogan <mail@samcogan.com>\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\nCo-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com>\nCo-authored-by: Mick Alberts <v-albemi@microsoft.com>\nCo-authored-by: learn-build-service-prod-08[bot] <274430765+learn-build-service-prod-08[bot]@users.noreply.github.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>\nCo-authored-by: Jodi Martis <v-jodimartis@microsoft.com>","sha":"806d28e8011e3fa77d26b1c8f66bdf0779f38890","url":"https://github.com/MicrosoftDocs/architecture-center/commit/806d28e8011e3fa77d26b1c8f66bdf0779f38890"},{"author":"v-albemi","date":"2026-06-12T22:06:27+00:00","message":"Pipeline: [Update] High availability for multitier AKS applications (#15970)\n\n* edits\n\n* edits\n\n* edits\n\n* edit\n\n* edit\n\n* edit\n\n* links\n\n* metadata\n\n* change to md\n\n* links\n\n* edits\n\n* Apply suggestions from code review\n\nCo-authored-by: Jodi Martis <v-jodimartis@microsoft.com>\n\n* svg\n\n* Apply suggestions from code review\n\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\n\n* Apply suggestion from @v-albemi\n\n---------\n\nCo-authored-by: Jodi Martis <v-jodimartis@microsoft.com>\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>","sha":"c3bdd872dbb1438b5d6e54d43a9810da3a255cf6","url":"https://github.com/MicrosoftDocs/architecture-center/commit/c3bdd872dbb1438b5d6e54d43a9810da3a255cf6"},{"author":"cdpark","date":"2026-06-11T19:54:20+00:00","message":"Pipeline: [Overcast] - Caching Best Practices (#15930)\n\n* Convert yml to md\n\n* Edit yml link in TOC\n\n* Review article\n\n* Fix anchor\n\n* Edits from proofread\n\n* Apply suggestions from code review\n\nCo-authored-by: Jodi Martis <v-jodimartis@microsoft.com>\n\n* Edits from copilot\n\n* Apply suggestions from code review\n\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>\n\n---------\n\nCo-authored-by: Jodi Martis <v-jodimartis@microsoft.com>\nCo-authored-by: Chad Kittel <chad.kittel@gmail.com>","sha":"ef79621488119c618cd3ebeb8f81443f023cc452","url":"https://github.com/MicrosoftDocs/architecture-center/commit/ef79621488119c618cd3ebeb8f81443f023cc452"},{"author":"jmart1428","date":"2026-04-29T14:21:51+00:00","message":"fix links","sha":"cbacf900582fe83cfe31028f90a162616704f58f","url":"https://github.com/MicrosoftDocs/architecture-center/commit/cbacf900582fe83cfe31028f90a162616704f58f"},{"author":"v-stsavell","date":"2026-04-24T21:50:11+00:00","message":"edits","sha":"65a7fdc33f7a944f6e2c3333f4cfee17c3353f2f","url":"https://github.com/MicrosoftDocs/architecture-center/commit/65a7fdc33f7a944f6e2c3333f4cfee17c3353f2f"},{"author":"anaharris-ms","date":"2026-04-14T14:06:31+00:00","message":"fixed headers","sha":"86cf8f3464cd18ffe543f119b4620e893b238855","url":"https://github.com/MicrosoftDocs/architecture-center/commit/86cf8f3464cd18ffe543f119b4620e893b238855"},{"author":"jmart1428","date":"2026-03-24T13:43:46+00:00","message":"Fix link for Azure Savings Plan for Compute\n\nUpdated the link for Azure Savings Plan for Compute to the correct overview page.","sha":"672fa63103e595380d482dcfde92ff771db0b43c","url":"https://github.com/MicrosoftDocs/architecture-center/commit/672fa63103e595380d482dcfde92ff771db0b43c"},{"author":"anaharris-ms","date":"2026-02-06T19:30:32+00:00","message":"edit","sha":"b2ccd4851a56d86316a5147cbb35a6dfe4daff8e","url":"https://github.com/MicrosoftDocs/architecture-center/commit/b2ccd4851a56d86316a5147cbb35a6dfe4daff8e"},{"author":"anaharris-ms","date":"2026-02-06T19:21:03+00:00","message":"edit","sha":"789c0b31508204eb071c26a0ab9aac599121de63","url":"https://github.com/MicrosoftDocs/architecture-center/commit/789c0b31508204eb071c26a0ab9aac599121de63"},{"author":"anaharris-ms","date":"2026-02-06T19:16:03+00:00","message":"edit","sha":"b55044ff07bc16be6dcda9d303243cf3256acd67","url":"https://github.com/MicrosoftDocs/architecture-center/commit/b55044ff07bc16be6dcda9d303243cf3256acd67"}]
