Skip to main content

AI-Driven CI/CD Pipeline Automation for Secure .NET Applications in Azure Kubernetes Services

Abstract

The increasing pace of the evolution of cloud-native systems and microservices in business propositions has increased the intricacy of deployment of secure to both business and IT space.NET applications. The proposed pipeline in the experiment suggests the Automation system needed to enhance speed in deployments, security and reliability with several unique focus behaviors by deploying the Azure Kubernetes Services (AKS) using AI. The proposed architecture with the aid of containers offers machine learning adaptable deployment schemes, automatic verification of the vulnerability scanners and code verification code analysis. With the help of AI, the pipeline will be self-driving and know where the particular failures are likely to occur within the pipeline, optimize resource usage, and follow the best practices in the security development lifecycle. The architecture is made up of the modular steps of monitor code commit, automated test, work on container images, security check and coordinated launch in AKS clusters. Each step requires an AI-infused decision-making procedure to a point that it does not require human interventions, errors in requirements and automatically identifies security risks. A POC implementation will demonstrate tremendous time saving during implementation, error reduction, security threat, contrasting to traditional CI/CD. Through performance measures, performance has been achieved by 35-percent deployment efficiency and post-deployment security incidents have been achieved by 40-percent. The experiment proves the applicability of AI to CI/CD pipelines as the way to streamline the delivery of software and improve the security posture of cloud-based.NET applications. The research findings do hold some valuable findings to organizations when it comes to the endeavor of implementing intelligent automation with an intention of provision of cloud-native, secure, scalable and resilient applications.

References

1. Octopus Deploy, “CI/CD Overview,” Octopus.com. [Online]. Available: https://octopus.com/devops/ci-cd.
2. Microsoft Azure Blog, “Azure Pipelines is the CI/CD solution for any language, any platform, any cloud,” Azure.Microsoft.com. [Online]. Available: https://azure.microsoft.com/en-us/blog/azure-pipelines-is-the-ci-cd-solution-for-any-language-any-platform-any-cloud/.
3. IBM, “CI/CD Pipeline,” IBM.com. [Online]. Available: https://www.ibm.com/think/topics/ci-cd-pipeline.
4. Microsoft Learn, “Azure Kubernetes Service (AKS),” Learn.Microsoft.com. [Online]. Available: https://learn.microsoft.com/en-us/azure/aks/.
5. Microsoft Learn, “AKS Security Concepts,” Learn.Microsoft.com. [Online]. Available: https://learn.microsoft.com/en-us/azure/aks/concepts-security.
6. Cloud Security Alliance, “The Evolution of DevSecOps with AI,” CloudSecurityAlliance.org. [Online]. Available: https://cloudsecurityalliance.org/blog/2024/11/22/the-evolution-of-devsecops-with-ai.
7. OpenSSF, “ML Security in DevSecOps Whitepaper,” OpenSSF.org. [Online]. Available: https://openssf.org/wp-content/uploads/2025/08/OpenSSF_MLSecOps_Whitepaper.pdf.
8. Checkmarx, “DevSecOps Best Practices in the Age of AI,” Checkmarx.com. [Online]. Available: https://checkmarx.com/learn/ai-security/devsecops-best-practices-in-the-age-of-ai/.
9. Wikipedia, “DevOps Research and Assessment,” Wikipedia.org. [Online]. Available: https://en.wikipedia.org/wiki/DevOps_Research_and_Assessment.
10. Wiz.io, “AKS Security Best Practices,” Wiz.io. [Online]. Available: https://www.wiz.io/academy/container-security/aks-security-best-practices.