Per-team AKS clusters provisioned with inconsistent configuration. No central image registry policy. Cluster networking varies (public clusters, private clusters, mixed). Defender for Containers not in scope. Cost attribution per cluster manual. No paved-road template.
Typical concerns
- ·Inconsistent security posture across clusters
- ·Image supply-chain unaudited
- ·Network configuration drift
- ·Production clusters without SLO owners
- ·Cost growth without attribution
Capability gaps
- ·Paved-road AKS template
- ·Azure Policy at management-group level
- ·ACR with vulnerability scanning
- ·Defender for Containers tenant-wide
- ·Cluster-cost attribution