Skip to content

docs(website): self-hosting on Kubernetes and AKS - #1475

Draft
Cedric Vidal (cedricvidal) wants to merge 2 commits into
mainfrom
feat/self-hosting-docs
Draft

Cedric Vidal (cedricvidal) wants to merge 2 commits into
mainfrom
feat/self-hosting-docs

Conversation

@cedricvidal

@cedricvidal Cedric Vidal (cedricvidal) commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Adds a Self-hosting section to the website covering Kubernetes deployment and AKS infrastructure provisioning, written ahead of open-sourcing the deployment descriptors and IaC into this repo.

Important

Do not merge until the Helm chart (deploy/helm/scope) and AKS IaC (infra/aks) land in this repo. Before merging, reconcile every page against the landed code.

New pages (website/src/content/docs/self-hosting/):

Page Covers
overview Where things live, choosing Helm vs Flux, architecture, workloads, prerequisites
provision-aks azd up with Bicep: modules, node pools, identities, env vars, add-ons, outputs, teardown
deploy-helm Manual path: build/push images, values file, helm upgrade --install, verify, upgrade, rollback, uninstall
deploy-flux GitOps path: GitRepository + HelmRelease with valuesFrom: infra-outputs, promotion, suspend/resume, private forks, image automation
configuration Values reference, Key Vault secrets via ESO, Entra auth, workers/KEDA, Kubedock, OTel, ASO, exposing the Portal
operations Upgrades, scaling, secret rotation, monitoring/alerts, backup, CI/CD with OIDC, troubleshooting

Also: Self-hosting sidebar group, cross-links from Access, Local development, Development guide, and Troubleshooting, and glossary entries (Helm chart, Flux, ESO, ASO, KEDA).

Assumptions to verify when the code lands

The pages are modeled on the current internal Kustomize manifests and azd/Bicep infra, adapted to a Helm chart. Everything below is assumed:

  • Paths: chart at deploy/helm/scope, IaC at infra/aks. Install is from a checkout (helm install scope ./deploy/helm/scope).
  • Release scope, namespace scoped, images at <registry>/scoped/<component>:<tag>.
  • Values keys: image.{registry,tag,repositoryPrefix}, azure.tenantId, azure.keyVault.uri, azure.workloadIdentity.{externalSecretsClientId,tokenManagerClientId}, azure.storage.{accountName,accountArmId}, azure.cosmosDb.accountArmId, auth.entra.{enabled,authority,apiClientId}, workers.<name>.{enabled,minReplicas,maxReplicas,queueLength}, <component>.replicas, kubedock.enabled, otelCollector.enabled, externalSecrets.enabled, azureServiceOperator.enabled, portal.service.{type,annotations}, portal.ingress.{enabled,className,host,tls.clusterIssuer}, mongo.database.
  • Migration Job and per-worker registration Jobs run as Helm pre-install/pre-upgrade hooks.
  • ASO resources are retained on uninstall.
  • Provisioning installs the add-ons (ESO, ASO, KEDA, cert-manager, Reloader) with Helm. DEPLOY_FLUX=true installs the Flux Operator and writes the infra-outputs ConfigMap to flux-system.
  • azd env var and output names are carried over from the internal infra (for example AZURE_KEYVAULT_URI, KV_SECRETS_OFFICER_IDENTITY_CLIENT_ID, DEPLOY_WINDOWS_CLUSTER, ALERT_EMAIL_RECIPIENTS).
  • Internal-only details are omitted: corp networking, App Service proxy, internal registries, PR preview environments.

Demos

Docs-only change. Walkthrough of the new Self-hosting pages and cross-links (headless recording, ~110 s).

Before

N/A

After

self-hosting-walkthrough.mp4

Testing

  • cd website && pnpm test passed (7/7).
  • SITE=https://microsoft.github.io BASE_PATH=/scope pnpm run build passed (224 pages, including all 6 self-hosting/* pages).
  • Script check of every site-root link and #anchor across the docs against the built HTML: 41 files, 0 broken.

Documentation and compatibility

The change is documentation only. No breaking changes.

Checklist

  • If Portal features changed, keep CLI capabilities in sync. N/A
  • If Portal components changed, update their Storybook stories. N/A
  • If database changes require a migration, include up() / down() and keep it CosmosDB-compatible. N/A
  • If dependencies changed, update the lockfile and regenerate NOTICE / NOTICE-REVIEW.txt with pnpm notice as needed. N/A
  • Video showing the behavior before the suggested change. N/A (new pages)
  • Video showing the behavior after the suggested change. See Demos

Overview, AKS provisioning with azd and Bicep, Helm and Flux deploy
paths, configuration reference, and operations.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions github-actions Bot added type: documentation Documentation additions, corrections, and improvements. language: javascript Work involving JavaScript code, tooling, or dependencies. topic: ui Portal, visual presentation, layout, and interface components. labels Oct 8, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

language: javascript Work involving JavaScript code, tooling, or dependencies. topic: ui Portal, visual presentation, layout, and interface components. type: documentation Documentation additions, corrections, and improvements.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant