Skip to main content

Deploying Containers to Azure Kubernetes Service

Learn to build a container image, push it to Azure Container Registry, and deploy it to an AKS cluster exposed through a load balancer.

Overview and What You Will Learn

In this lab, you will build a container image, push it to Azure Container Registry, create an AKS cluster wired to that registry, and deploy the container so it's reachable through a load-balanced public endpoint - the complete path from source code to a running, accessible service.

Why This Matters in Production

A team at Hotstar running several interdependent containerized services - a recommendation engine, a video metadata service, a user profile service - needs coordinated scaling, service discovery, and self-healing across all of them simultaneously. AKS provides exactly this orchestration layer, handling failures and scaling decisions that would otherwise require significant manual coordination across separate containers running independently.

Core Principles

The path from source code to a running AKS workload passes through three distinct stages.

◈ DIAGRAM
+------------------------------------------+
| Container image built locally or in CI |
+------------------------------------------+
|
v
+------------------------------------------+
| Pushed to Azure Container Registry (ACR) |
+------------------------------------------+
|
v
+------------------------------------------+
| AKS cluster pulls the image from ACR |
| and runs it as a Pod, exposed via a |
| Kubernetes Service and Load Balancer |
+------------------------------------------+

Attaching ACR directly to the AKS cluster at creation time means the cluster's nodes are automatically granted permission to pull images from that registry, with no separate credential configuration needed.

Detailed Step-by-Step Practical Lab

  1. Create a Resource Group and an Azure Container Registry:
Bash
az group create --name rg-aks-lab-mumbai --location centralindia
az acr create \
--resource-group rg-aks-lab-mumbai \
--name acraakslabrahul \
--sku Basic
  1. Build a container image directly in ACR, with no local Docker installation required:
Bash
az acr build \
--registry acraakslabrahul \
--image cart-service:v1 .
  1. Create an AKS cluster, attaching the registry so nodes can pull images from it automatically:
Bash
az aks create \
--resource-group rg-aks-lab-mumbai \
--name aks-lab-mumbai \
--node-count 2 \
--attach-acr acraakslabrahul \
--generate-ssh-keys
  1. Retrieve the cluster's credentials so kubectl can connect to it:
Bash
az aks get-credentials \
--resource-group rg-aks-lab-mumbai \
--name aks-lab-mumbai
  1. Deploy the container image as a Kubernetes Deployment:
Bash
kubectl create deployment cart-service \
--image=acraakslabrahul.azurecr.io/cart-service:v1
  1. Expose the deployment through a Kubernetes Service backed by an Azure Load Balancer, making it reachable from outside the cluster:
Bash
kubectl expose deployment cart-service \
--type=LoadBalancer \
--port=80 \
--target-port=8080
  1. Wait for the Load Balancer to receive a public IP, then confirm the service is reachable:
Bash
kubectl get service cart-service --watch
## Wait until EXTERNAL-IP shows an actual IP instead of <pending>
  1. Confirm the pod is running correctly:
Bash
kubectl get pods
  1. Clean up:
Bash
az group delete --name rg-aks-lab-mumbai --yes --no-wait

Production Best Practices & Common Pitfalls

Common Mistake

Manually managing ACR credentials as Kubernetes secrets instead of using --attach-acr at cluster creation. Manual credential management means those credentials can expire or be misconfigured, causing confusing image pull failures - attaching the registry directly grants pull access through the cluster's own managed identity instead.

Tip

Use kubectl describe pod <pod-name> immediately when a pod does not reach a Running state. It shows the exact reason - an image pull failure, insufficient node resources, or a failed readiness check - rather than requiring you to guess.

  • Reach for AKS specifically once you have multiple interdependent containerized services, not for a single simple container that Azure Container Instances could run with far less operational overhead.
  • Node count and VM size directly determine cluster capacity and cost. Start with a small node count for a lab or early-stage workload, and use the Cluster Autoscaler once real production traffic patterns are understood.

Quick Reference & Troubleshooting Commands

Command Description
az acr build Build a container image directly inside ACR
az aks create --attach-acr Create an AKS cluster with registry access pre-configured
az aks get-credentials Configure kubectl to connect to the cluster
kubectl describe pod <name> Diagnose why a pod isn't reaching Running state

Explore More in Azure Compute Services

All 6 Topics

Frequently Asked Questions

Is Deploying Containers to Azure Kubernetes Service free to learn on DevOps Network?

Yes - this topic, like everything on DevOps Network, is 100% free with no paywall or sign-up gate.

What does the Deploying Containers to Azure Kubernetes Service topic cover?

Learn to build a container image, push it to Azure Container Registry, and deploy it to an AKS cluster exposed through a load balancer.