OpsCanary
kubernetesoperatorsPractitioner

Feature Flags in Kubernetes: Mastering AWS AppConfig

5 min read AWS Containers BlogOct 1, 2026Reviewed for accuracy
Share
Practitioner — Hands-on experience recommended

Feature flags, also known as feature toggles, are critical in modern application development. They allow teams to decouple feature releases from container deployments, enabling more agile and controlled rollouts. In container environments, particularly with Kubernetes, managing these flags efficiently can be a challenge. AWS AppConfig addresses this by providing a robust solution that integrates directly into your containerized applications using the sidecar pattern.

The AWS AppConfig Agent runs alongside your application container, managing configuration retrieval, caching, and automatic refreshes. During the container initialization phase, the agent establishes a session with AWS AppConfig and polls for updates at a default interval of 45 seconds. You can configure essential parameters such as APPCONFIG_APP_ID, APPCONFIG_ENV_ID, and APPCONFIG_CONFIG_ID to tailor the integration to your specific application needs. This setup allows your application to read feature flags through a local HTTP call, making it simple to toggle features on or off without redeploying your containers.

In production, ensure that your deployment YAML is correctly configured to include the AppConfig agent as a sidecar container. Pay attention to resource allocation for both your application and the agent to avoid performance bottlenecks. While the integration is powerful, be cautious of the polling interval; if your application requires real-time feature toggling, you may need to adjust this setting. The official docs don't call out specific anti-patterns here. Use your judgment based on your scale and requirements.

Key takeaways

  • →Implement feature flags using AWS AppConfig to decouple feature releases from deployments.
  • →Deploy the AWS AppConfig Agent as a sidecar container in your Kubernetes pod for seamless integration.
  • →Configure parameters like APPCONFIG_APP_ID and APPCONFIG_ENV_ID to tailor the feature flag management.
  • →Monitor the polling interval of the AppConfig Agent to ensure timely updates to feature flags.
  • →Allocate appropriate resources for both the application and the AppConfig agent to maintain performance.

Why it matters

In production, the ability to toggle features without redeploying containers can significantly reduce downtime and risk during feature rollouts. This flexibility allows teams to experiment and iterate quickly, leading to better product outcomes.

Code examples

YAML
1apiVersion: apps/v1
2kind: Deployment
3metadata:
4  name: backend-deployment
5  namespace: backend
6  labels:
7    app: backend
8spec:
9  replicas: 3
10  selector:
11    matchLabels:
12      app: backend
13  template:
14    metadata:
15      labels:
16        app: backend
17      annotations:
18        prometheus.io/scrape: "true"
19        prometheus.io/port: "2772"
20        prometheus.io/path: "/metrics"
21    spec:
22      serviceAccountName: appconfig-service-account
23      terminationGracePeriodSeconds: 60
24      containers:
25      - name: backend
26        image: <ACCOUNT_ID>.dkr.ecr.us-west-2.amazonaws.com/backend:latest
27        ports:
28        - containerPort: 5000
29        env:
30        - name: APPCONFIG_APP_ID
31          value: "MyPythonApp"
32        - name: APPCONFIG_ENV_ID
33          value: "Demo"
34        - name: APPCONFIG_CONFIG_ID
35          value: "FeatureFlags"
36        - name: AWS_DEFAULT_REGION
37          value: "us-west-2"
38        - name: DYNAMODB_TABLE_NAME
39          value: "Products"
40        readinessProbe:
41          httpGet:
42            path: /api/status
43            port: 5000
44          initialDelaySeconds: 5
45          periodSeconds: 10
46        livenessProbe:
47          httpGet:
48            path: /api/status
49            port: 5000
50          initialDelaySeconds: 15
51          periodSeconds: 20
52        resources:
53          requests:
54            memory: "128Mi"
55            cpu: "100m"
56          limits:
57            memory: "256Mi"
58            cpu: "500m"
59      - name: appconfig-agent
60        image: public.ecr.aws/aws-appconfig/aws-appconfig-agent:2.x
61        ports:
62        - name: http
63          containerPort: 2772
64          protocol: TCP
65        env:
66        - name: SERVICE_REGION
67          value: us-west-2
68        imagePullPolicy: IfNotPresent
69        resources:
70          requests:
71            memory: "64Mi"
72            cpu: "50m"
73          limits:
74            memory: "128Mi"
75            cpu: "100m"
76        livenessProbe:
77          httpGet:
78            path: /
79            port: 2772
80          initialDelaySeconds: 15
81          periodSeconds: 20
JSON
1{
2    "discount_enabled": {
3        "enabled": false,
4        "discount_percentage": 15
5    }
6}
JSON
1{
2    "discount_enabled": {
3        "_variants": [
4            {
5                "name": "platinum-users",
6                "rule": "(eq $loyaltyStatus \"PLATINUM\")",
7                "enabled": true,
8                "attributeValues": { "discount_percentage": 15 }
9            },
10            {
11                "name": "new-users",
12                "rule": "(gt $joinDate \"2026-08-01\")",
13                "enabled": true,
14                "attributeValues": { "discount_percentage": 10 }
15            },
16            {
17                "name": "default",
18                "enabled": true,
19                "attributeValues": { "discount_percentage": 5 }
20            }
21        ]
22    }
23}

When NOT to use this

The official docs don't call out specific anti-patterns here. Use your judgment based on your scale and requirements.

Want the complete reference?

Read official docs

Test what you just learned

Quiz questions written from this article

Take the quiz →
Linux FoundationSponsor

Industry-standard certifications built by the people behind Linux and Kubernetes. Earn the CKA — the gold standard Kubernetes administrator cert. OpsCanary readers get 30% off year-round with code OPSCANARY3.

Get CKA certified →

Get the daily digest

One email. 5 articles. Every morning.

No spam. Unsubscribe anytime.