◤Deployment Variant M2 · azure-oidc·21 September 2026·Verified live from the AKS API server
One cluster, no Microsoft, sameplatform.
The same codebase as the on-premises estate, deployed as M2 — Azure AKS
instead of a LAN, and an in-cluster Keycloak instead of Entra ID. Nothing in
the application was forked to get here: a variant is data plus two code seams, so
everything below is the Base0 platform reading a different
profiles/azure-oidc/profile.env. Every service box on the map is a live
link.
1
AKS cluster
3
Nodes
90
Pods running
23
TLS hostnames
17/17
Scrape targets up
39
Alert rules
23
Policy modules
0
Lines forked
01
The estate
One picture of what runs where. The enclosure is the AKS cluster, each plate a namespace,
each chip a service — and every chip carrying a hostname is a link to it. Colour is an
encoding held consistent across the document. Compare it with the on-premises map and the
differences are the whole point: one cluster rather than two, Keycloak where
Entra was, Azure Files where Ceph was, and no GPU data plane at all.
Read live from the aks-gpupool-platform-oidc API server on 21 September 2026.
The on-premises estate draws two clusters, a Ceph cluster and a pool of Macs; this one draws
a single AKS cluster and buys every token from a provider. The application code is identical.
02
What happens to one request
Byte for byte the same pipeline as the on-premises estate — this is the part a variant
must not change. Every call, from the chat workspace, from Claude Code, from an agentdesk
run or the coding harness, passes the same five gates before a token is bought, and lands
in the same audit trail afterwards. Only the ends differ: sign-in arrives from Keycloak,
and there is no Mac pool to dispatch to.
Five gates, then dispatch, then the record — unchanged. The audit count is small
because this variant is young, not because it records less: the schema, the gates and the
order are the same code. What a variant is allowed to change is the ends — who signs you
in, and who sells you the tokens.
03
Every front door
The same services as on the map, as click targets. Every one of them is an HTTPS hostname
under one wildcard, behind one load balancer — there are no NodePorts on this variant,
because AKS nodes carry no public address. Rows without a hostname are reachable only from
inside the cluster and are listed so nobody hunts for a URL that does not exist.
calendar · outlook · teams · junosCorrectly ABSENT. The first three need capability m365 and junos needs lan; neither is in this profile.not deployed
04
Run sheet
How to show this variant in twenty minutes. The story is not “here is a platform”
— they have already seen that one. It is here is the same platform, on somebody
else's cloud, with somebody else's identity provider, and nothing was forked to do it.
01
Open with the sign-in, not the dashboard
Go to the dashboard and let it bounce you to Keycloak. That redirect is the whole M2 thesis in one screen: the application did not learn a new identity provider, it reads a generic OIDC issuer out of its profile. Same image as the LAN runs.
02
Show the estate is genuinely one cluster
This page, section 01. One AKS enclosure, three nodes, Azure Files where Ceph was, and a plate for Keycloak where Base0 has an arrow to Entra. Say out loud what is missing — no Ceph, no lab cluster, no Macs — because an honest map is the one they will trust later.
03
Prove the gateway is the same gateway
Open Activity and run one chat in aimo. The audit row carries the same fields as on-premises: full request, full response, the model, the decision, the cost. The gates ran in the same order for the same reasons.
04
Show a governed tool call
In aimo ask for a forecast or a document conversion. The call leaves as an MCP request through the relay, so it lands on Activity as mcp:weather or mcp:markitdown — scanned, audited and capped exactly like an inference call. Nine servers, and not one of them is reachable directly.
05
Show the training estate on the same cluster
elearn and twelve course hosts. Worth a minute because it makes the variant concrete: on the LAN this is a second Kubernetes cluster; here the profile put it in one, and no course changed.
06
Name the two differences honestly
There is no GPU data plane here, so every token is bought from a provider; and Microsoft 365 features — Teams, Outlook, the calendar — are absent because capability m365 is not in this profile. Both are decisions recorded in profile.env, not gaps discovered on stage.
07
Close on what it cost to get here
Zero application lines. A variant is profiles/azure-oidc/profile.env, a handful of manifest patches, and two code seams — lib/oidc.ts for identity and scripts/lib/profile.sh for platform. That is the reusable claim, and it is the one worth making.
aks-gpupool-platform-oidc · 3 nodeskeycloak · realm gpupoolazure files premiumazure cni overlay + ciliumFigures read live from the AKS API server, 21 September 2026. Base0 twin: the on-premises estate map.