Azure Container Apps vs Azure Kubernetes Service: When to Use Each
Choose Container Apps when: You want managed infrastructure Your team lacks Kubernetes expertise You have event driven or HTTP workloads You need rapid time…
30 articles
Choose Container Apps when: You want managed infrastructure Your team lacks Kubernetes expertise You have event driven or HTTP workloads You need rapid time…
Kubernetes cost optimization is continuous. Review these metrics weekly and adjust based on actual usage patterns.
Containerization and Kubernetes: Lessons Learned in 2022
Istio on AKS: Complete Service Mesh Implementation
Traditional Azure CNI assigns VNet IPs to pods, limiting scale. Overlay mode uses a separate address space for pods.
Calico provides enterprise grade network security for AKS with features beyond standard Kubernetes Network Policies.
Network Policies provide essential microsegmentation for Kubernetes clusters. Enable a CNI that supports policies (like Azure CNI or Calico) to enforce them.
Dockershim was a Kubernetes component that translated Docker API calls to the Container Runtime Interface (CRI). With its removal, containerd communicates…
Dockershim removal Seccomp by default Pod security admission Ephemeral containers GA Storage capacity tracking With Dockershim removed, containerd is now…
AKS costs come from several components: Virtual Machine nodes Storage (managed disks, Azure Files) Networking (load balancers, bandwidth) Container Registry…
AKS now supports managed identities natively, eliminating the need for service principals: The new workload identity feature provides pod level identity:
Most enterprises settled on managed Kubernetes. Azure Kubernetes Service (AKS) became the default choice for Azure shops: Flux and ArgoCD emerged as the…
Azure Monitor for Containers (the Container Insights feature) is the native Azure observability solution for AKS that doesn't require running your own…
Grafana is the visualisation layer that makes Prometheus metrics interpretable at a glance—and for AKS, the starting point is the community dashboards that…
Prometheus became the observability standard for Kubernetes because its data model—time-series metrics with labels—maps naturally to the dynamic…
Container Insights is the Azure Monitor feature that closes the observability gap for AKS clusters—without it, you have Kubernetes metrics available in the…
Azure AD Workload Identity is the architecture-level improvement over AAD Pod Identity that removes the NMI DaemonSet and uses Kubernetes native service…
AAD Pod Identity was the original mechanism for giving Kubernetes pods an Azure AD identity so they could access Azure resources—Key Vault secrets, Storage…
Virtual nodes in AKS enable pods to run on Azure Container Instances rather than on VM-based node pool nodes—useful for burst workloads that spike…
AKS Spot node pools are the cost reduction lever that can cut compute spend by up to 90%—at the cost of accepting that Azure may evict spot nodes with a…
Node pools are the AKS mechanism for running heterogeneous workloads on a single cluster—different VM SKUs, OS types, and node configurations within the…
AKS cluster upgrades are the operational task that feels straightforward until you do them in production and discover the nuances—node cordoning order, pod…
Helm charts provide a powerful way to package and deploy applications to AKS with Azure specific integrations. By leveraging values files for environment…
Container Insights is the built in monitoring solution for AKS: This deploys: OMS agent as DaemonSet Metrics collection Log forwarding to Log Analytics…
Many enterprises have legacy .NET Framework applications that cannot easily migrate to .NET Core. Windows containers provide a path to containerization…
AKS networking is the part of Kubernetes that looks like a detail until it becomes a blocker. "I can't reach the on-prem database from the cluster" is a…
With containers becoming the standard deployment unit for modern applications, AKS provides: Managed control plane (no cluster management overhead)…
Azure Kubernetes Service: Managed Kubernetes
"How do we deploy a new version without downtime?" That's the conversation that got me writing this post. AKS gives you the primitives, but the choice…