Skip to content
Get Started for Free

Tutorials

Step-by-step walkthroughs against the LocalStack Azure emulator, currently focused on Azure Kubernetes Service: event-driven autoscaling with KEDA, network policy with Calico and Cilium, the Managed Gateway API, the AKS Cloud Controller Manager, Key Vault secret mounting via the Azure Key Vault provider for Secrets Store CSI Driver, provisioning a full cluster with Bicep and Terraform, and more.

Most tutorials provide numbered shell scripts that use the Azure CLI to create the cluster and the Azure resources it needs, together with the Kubernetes manifests that deploy the workload. The tutorials about infrastructure as code provide Bicep templates and Terraform modules instead. Most add a script that verifies the result, and several add one that removes everything again. Every tutorial has been tested against Azure as well as against the local emulator.

Each tutorial is maintained in the aks-samples repository alongside the numbered scripts and manifests it uses, so the instructions and the code never drift apart. The cards link straight to the source.


11 tutorials

AKS cluster with tags, labels and taints using Bicep

AKS cluster with tags, labels and taints using Bicep architecture
Azure Kubernetes ServiceContainer RegistryKey VaultLog AnalyticsVirtual Network+1

Deploy a full AKS stack with Bicep — OIDC issuer, workload identity, Azure RBAC, the Key Vault Secrets Provider, VPA, the managed Gateway API and Container Insights — and validate agent-pool tags, node labels and taints.

View on GitHub →

AKS cluster with tags, labels and taints using Terraform

AKS cluster with tags, labels and taints using Terraform architecture
Azure Kubernetes ServiceContainer RegistryKey VaultLog AnalyticsVirtual Network+1

The same AKS stack in Terraform, module for module, including the azapi provider for the managed Gateway API that azurerm does not yet expose.

View on GitHub →

Calico network policy

Calico network policy architecture
Azure Kubernetes Service

Apply a cluster-wide default-deny posture on AKS with Calico, then open specific ingress and egress paths with NetworkPolicy.

View on GitHub →

Cilium DNS-aware egress policy

Cilium DNS-aware egress policy architecture
Azure Kubernetes Service

Control egress from AKS pods by DNS name with Cilium's FQDN-aware network policies.

View on GitHub →

Cilium L3, L4 and L7 ingress policy

Cilium L3, L4 and L7 ingress policy architecture
Azure Kubernetes Service

Apply L3, L4 and L7 ingress policy on AKS with Cilium, using the Star Wars demo application.

View on GitHub →

Cloud controller manager load balancers

Cloud controller manager load balancers architecture
Azure Kubernetes ServiceVirtual Network

Exercise the Azure cloud-controller-manager on AKS: public and internal load balancers, source IP ranges, nodeIP backend pools and an NGINX ingress controller.

View on GitHub →

Event Hubs autoscaling with KEDA

Event Hubs autoscaling with KEDA architecture
Azure Kubernetes ServiceEvent HubsStorage Account

Scale a consumer on Event Hubs checkpoint lag with the KEDA azure-eventhub scaler and a blob checkpoint store.

View on GitHub →

Key Vault secrets with the Secrets Store CSI Driver

Key Vault secrets with the Secrets Store CSI Driver architecture
Azure Kubernetes ServiceKey VaultWorkload IdentityManaged Identity

Mount Key Vault secrets into AKS pods with the Secrets Store CSI Driver, using either Entra Workload ID or a user-assigned managed identity.

View on GitHub →

Kubernetes Gateway API with NGINX Gateway Fabric

Kubernetes Gateway API with NGINX Gateway Fabric architecture
Azure Kubernetes Service

Enable the managed Gateway API CRDs on AKS, install NGINX Gateway Fabric, and route traffic with Gateway and HTTPRoute resources.

View on GitHub →

Service Bus autoscaling with KEDA

Service Bus autoscaling with KEDA architecture
Azure Kubernetes ServiceService BusWorkload Identity

Scale a consumer on Service Bus queue depth with the KEDA azure-servicebus scaler and Entra Workload ID.

View on GitHub →

Storage Queue autoscaling with KEDA and Entra Workload ID

Storage Queue autoscaling with KEDA and Entra Workload ID architecture
Azure Kubernetes ServiceQueue StorageStorage AccountWorkload Identity

Scale a consumer on Storage queue depth with the KEDA azure-queue scaler. The scaler and both applications authenticate with workload identity, so there is no connection string and no Kubernetes Secret anywhere.

View on GitHub →
Was this page helpful?