# AKS StatefulSets on Azure | ZopNight

> Every check ZopNight runs on your AKS StatefulSets on Azure: 15 in total, across reliability, rightsizing and security.

Source: https://zop.dev/zopnight/rules/azure/aks-statefulset

---

_Azure · 15 checks_

## AKS StatefulSets on Azure, checked for you.

ZopNight runs 15 checks on your AKS StatefulSets in Azure, covering reliability, security and rightsizing. Workloads are scheduled by namespace.

- 15 — checks
- 3 — categories
- Manual — fixes, spelled out
- Yes — scheduled with its namespace

Free to start. No card. The playground just needs your work email.

## Every check, grouped by what it protects.

Each one opens with why it matters and exactly what to change.

### Rightsizing

Resources sized for headroom they never use. A smaller size runs the same workload for less.

- [CPU Over-Provisioned](https://zop.dev/zopnight/rules/cpu-over-provisioned)
- [Memory Over-Provisioned](https://zop.dev/zopnight/rules/memory-over-provisioned)

### Reliability

Production-shape issues that cause incidents and rework: single replicas, missing requests and limits, missing probes.

- [Container Image Tag Latest or Missing](https://zop.dev/zopnight/rules/container-image-tag-latest-or-missing)
- [Liveness and Readiness Share One Handler](https://zop.dev/zopnight/rules/liveness-and-readiness-share-one-handler)
- [Missing CPU/Memory Limits](https://zop.dev/zopnight/rules/missing-cpu-memory-limits)
- [Missing CPU/Memory Requests](https://zop.dev/zopnight/rules/missing-cpu-memory-requests)
- [Missing Liveness Probe](https://zop.dev/zopnight/rules/missing-liveness-probe)
- [Missing Readiness Probe](https://zop.dev/zopnight/rules/missing-readiness-probe)
- [Missing Startup Probe](https://zop.dev/zopnight/rules/missing-startup-probe)
- [StatefulSet Has No Headless Service](https://zop.dev/zopnight/rules/statefulset-has-no-headless-service)
- [StatefulSet Not Fully Ready](https://zop.dev/zopnight/rules/statefulset-not-fully-ready)
- [Workload Missing Topology Spread](https://zop.dev/zopnight/rules/workload-missing-topology-spread)

### Security

Risky configurations: privileged containers, containers running as root, host networking, ingress without TLS.

- [Container Running as Root](https://zop.dev/zopnight/rules/container-running-as-root)
- [Container with Host Network](https://zop.dev/zopnight/rules/container-with-host-network)
- [Privileged Container](https://zop.dev/zopnight/rules/privileged-container)

## Find these on your own AKS StatefulSets.

Connect a read-only role and ZopNight inventories the AKS StatefulSets you run, then runs all 15 checks against them.

[object Object]
