Upgrading Azure Kubernetes Service (AKS) clusters and node pools

An Azure Kubernetes Service (AKS) cluster needs to be periodically updated to ensure security and compatibility with the latest features. There are two components of an AKS cluster that are necessary to maintain:

  • Cluster Kubernetes version: As part of the AKS cluster lifecycle, perform upgrades to the latest Kubernetes version. Upgrade to apply the latest security releases and to get access to the latest Kubernetes features. Stay within the AKS support window.
  • Node image version: AKS regularly provides new node images with the latest operating system (OS) and runtime updates. Regularly upgrade your node images to ensure support for the latest AKS features and to apply essential security patches and hotfixes.

For Linux nodes, you can apply node image security patches and hotfixes without your initiation as unattended updates. These updates are automatically applied, but AKS doesn't automatically reboot your Linux nodes to complete the update process. You need to use a tool like kured or node image upgrade to reboot the nodes and complete the cycle.

Component upgrade overview

Component name Frequency Planned maintenance Supported methods (Standard) Multi-cluster support Learn more
Cluster Kubernetes version (minor) Roughly every three months Yes Automatic, Manual Automatic, Manual Upgrade an AKS cluster, Multi-cluster upgrade
Cluster Kubernetes version (patch) Approximately weekly. To determine the latest applicable version in your region, see the AKS release tracker Yes Automatic, Manual Manual Upgrade an AKS cluster, Multi-cluster upgrade
Node OS image (Linux) Weekly Yes Automatic, Manual Automatic, Manual AKS node image upgrade
Node OS image (Windows) Monthly Yes Automatic, Manual Automatic, Manual AKS node image upgrade
Security patches and hotfixes As needed N/A N/A Unsupported AKS node security patches

Advanced upgrade strategies

See AKS production upgrade strategies for detailed implementation guidance on these patterns.

Multi-cluster upgrade orchestration

When managing multiple AKS clusters, following consistent deployment and testing patterns is critical for minimizing disruptions:

  • Test first, deploy second: Always test upgrades in a development or test environment before production to identify compatibility issues, bugs, or performance impacts.
  • Consistent versioning across regions: Maintain consistent Kubernetes and node OS image versions across clusters in different regions to simplify operations and troubleshooting.

Azure Kubernetes Fleet Manager provides built-in orchestration for multi-cluster upgrades with:

  • Customizable upgrade ordering across clusters
  • Validation gates between upgrade stages
  • Automatic or scheduled update coordination
  • Consistent node OS image versions across regions

For AKS Standard clusters, see Multi-cluster upgrade orchestration for step-by-step guidance.

Automatic upgrades

You can configure automatic upgrades through multiple methods:

  • Auto upgrade channels: AKS Standard clusters can choose from release channels (patch, stable, rapid) or rapid N-1 for earlier access to new versions.
  • GitHub Actions: Automate node upgrades through CI/CD pipelines.
  • Azure Kubernetes Fleet Manager: Automatic multi-cluster upgrades with coordinated deployment across your fleet and testing and validation gates.

Planned maintenance

Planned maintenance allows you to schedule weekly maintenance windows that will update your control plane and your kube-system pods, helping to minimize workload impact.

Planned maintenance for AKS Standard

For AKS Standard clusters, planned maintenance windows help align upgrades with your operational schedule and reduce unexpected disruptions.

Service level agreement (SLA) guarantees for upgrades

AKS Standard SLAs

AKS Standard clusters can optionally enable:

  • Uptime SLA: 99.95% availability of the Kubernetes API server (optional, available at Standard or Premium tiers).

Troubleshooting upgrade issues

If you encounter errors during manual upgrades or on AKS Standard clusters, review the following troubleshooting guides: