Upgrades:
In general, with any upgrade/update there is always likelihood things might fail so your team need to have multiple strategies, here are few suggestions that
1. Test upgrades on non-prod first (must)
2. AKS Upgrade API: The in-place upgrade should ideally work (easiest), one risk here is sometimes