AKS Manager delivers a complete, revision-controlled, production-grade AKS cluster — not just the cluster itself — with internal DNS, TLS, ingress, monitoring, and deployment tooling pre-integrated and kept consistent across all dev, QA, integration, UAT, and production environments via GitOps.
Native Azure tools provision a cluster. AKS Manager provisions a platform — declarative, reproducible, and identical from your laptop to production.
Azure CLI and the portal create the AKS control plane and node pools — then leave you to manually configure DNS, TLS, ingress, and monitoring. Every engineer assembles it differently every time.
These tools provision Azure resources but are not opinionated about what runs inside the cluster. You still need to separately manage ArgoCD apps, cert lifecycles, and ingress config — and keep them in sync across all environments.
Without GitOps as the source of truth, dev, QA, UAT, and production clusters drift apart. A fix applied manually in prod is never reflected in dev. AKS Manager uses ArgoCD to make every environment a declared, auditable, reproducible state.
By design, helm upgrade installs CRDs once and never touches them again — so when a component's definitions change between versions, working it out is left to you. And deleting a CRD cascades: every custom resource using it goes with it. AKS Manager sequences it — the resources are captured, the definitions replaced and the resources restored. Where deleting a definition would be unsafe, it is applied in place instead.
Microsoft's accelerator handles hub-spoke networking and policy. It does not touch ingress, internal TLS, GitOps delivery, or observability inside your clusters. AKS Manager picks up exactly where it leaves off.
AKS Manager is a least-privilege access agent — powerful enough to safely provision clusters, node pools, and vault secrets, yet scoped to eliminate the most dangerous Azure Owner permissions.
Application.ReadWrite.OwnedBy — agent can read and update only app registrations it explicitly owns. For example, when installing Headlamp, the agent reads and updates the OIDC redirect URI for that cluster without access to any other app in the tenant.Azure RBAC and Microsoft Graph API are separate permission systems. Azure Subscription Owner does not grant Entra ID directory permissions. AKS Manager uses a single Microsoft Graph application role: Application.ReadWrite.OwnedBy — which grants read and write access strictly limited to app registrations the agent has been explicitly added as an owner of, such as the Headlamp OIDC app registration created during cluster setup. No other app registration in the tenant can be accessed or modified.
Native Azure Entra ID federation. Eliminate static secrets by providing pods with short-lived tokens.
Native KMS v2 orchestration. Encrypt etcd at rest with hardware-backed security.
Full lifecycle orchestration including automated Taints and Tolerations for isolation.
Secrets versioned in vault, encrypted in etcd, with a GUI to dynamically create and update mappings.
Every component upgraded trimesterly — no manual patching, no version drift.
The core of our GitOps delivery and DAG batch processing, upgraded every trimester.
Automated lifecycle for ingress, TLS, and DNS automation refreshed trimesterly.
Modern Kubernetes UI and full-stack observability updated to latest releases.
helm upgrade does not upgrade CRDs. That is documented Helm behaviour — they are installed once and never touched again, so when a component's definitions change between versions, working it out is left to you. And deleting a CRD cascades: every custom resource using it goes with it.
AKS Manager sequences it. The custom resources are captured, the definitions replaced, and the resources restored — as part of the upgrade, not a separate exercise you have to invent.
Elasticsearch holds data, so its definitions are never deleted — they are applied server-side, leaving every Elasticsearch, Kibana and Beat resource untouched. The load balancer controller is treated the same way.
Upgrading the AKS cluster itself replaces every node. Elasticsearch is scaled down onto its retained volumes first and brought back afterwards, so the node roll never has to move or rebalance the data it holds — which is what makes it quick.
Every AKS cluster and stack component upgraded trimesterly via Azure Marketplace — with a support tier to match your team's needs.
Full stack and AKS cluster upgrades every trimester — ingress, observability, secrets and GitOps tooling moved together to a tested combination.
Best-efforts support via email. Ideal for teams evaluating the platform or running non-critical workloads.
Business hours support (Mon–Fri, CET) for teams running production workloads on AKS Manager.
Have a question about AKS Manager, or need help during your trial? Our team will get back to you shortly.
Contact Us →For licensed customers only. Use our verified support chat to connect directly with our team.
Response within 4 business hours · Mon–Fri 09:00–18:00 CET