eBPF in Kubernetes: The Technology Behind Modern Networking
eBPF programs run in a sandboxed virtual machine within the Linux kernel, processing events without kernel modifications.
37 articles
eBPF programs run in a sandboxed virtual machine within the Linux kernel, processing events without kernel modifications.
eBPF (Extended Berkeley Packet Filter) allows running sandboxed programs in the Linux kernel without changing kernel source code, enabling efficient…
Traditional Azure CNI assigns VNet IPs to pods, limiting scale. Overlay mode uses a separate address space for pods.
Calico provides enterprise grade network security for AKS with features beyond standard Kubernetes Network Policies.
Network Policies provide essential microsegmentation for Kubernetes clusters. Enable a CNI that supports policies (like Azure CNI or Calico) to enforce them.
1. Document all forwarding rules : Maintain a central registry 2. Use redundant DNS servers : Always specify multiple targets 3. Monitor DNS query latency :…
DNS Private Resolver solves this without virtual machines.
Private Endpoint : Consume services privately (you're the client) Private Link Service : Expose services privately (you're the provider) 1. SaaS providers :…
A private endpoint: Creates a network interface with a private IP in your VNet Maps to a specific Azure resource (or sub resource) Enables DNS resolution to…
Data Flows automatically use the managed VNet when connected to private endpoints.
Traditional NSG rules use IP addresses, which creates challenges: IP addresses change when VMs are recreated Rules become hard to read with many IP ranges…
NSG rules are evaluated by priority (100 4096, lower = higher priority): Direction : Inbound or Outbound Priority : 100 4096 (lower numbers processed first)…
Azure Firewall rules are the configuration work that determines whether your network security posture is genuinely restrictive or accidentally permissive.…
Set up a private DNS zone for your organization: Complete Private DNS setup with Terraform: Create DNS zones for Azure Private Link services: Integrate…
NAT Gateway solves several problems: SNAT Port Exhaustion : Each NAT Gateway supports up to 64,000 concurrent connections per public IP Simplified…
Azure offers two SKUs: Basic : Free, limited features, no SLA Standard : Zone redundant, SLA backed, supports availability zones Set up an internet facing…
VNet peering is the network connectivity primitive I configure in almost every Azure architecture. The pitch is simple: two virtual networks, connected via…
ExpressRoute Direct offers: Direct physical connectivity to Microsoft's network 10 Gbps or 100 Gbps port pairs Support for massive data ingestion scenarios…
Application Gateway v2 is where the regional Layer 7 load balancer story became production-serious for enterprise workloads. Autoscaling means you don't…
Azure Front Door Standard/Premium is the convergence I've been waiting for since the days when you had to choose between classic Front Door (global routing…
Basic (Free) Always on traffic monitoring Automatic mitigation Protection for Azure infrastructure No SLA or customization Standard (Paid) All Basic…
AKS networking is the part of Kubernetes that looks like a detail until it becomes a blocker. "I can't reach the on-prem database from the cluster" is a…
Azure Firewall Manager provides: Hierarchical policy management Parent and child policies for inheritance Global deployment Manage firewalls across regions…
Virtual WAN simplifies enterprise networking by providing: Hub and spoke architecture Automated connectivity between hubs and spokes Branch connectivity VPN…
I keep writing about Bastion because I keep finding jump boxes I have to replace. VM with a public IP, port 3389 open, "admin" password in a sticky note in…
Private Link provides several key benefits: Private connectivity Access services over private IP addresses Data exfiltration protection Service endpoints…
Front Door's global load balancing and caching are easy to understand. The Rules Engine is the part that turns it into a real edge platform. Conditions on…
App Gateway v1 was a credible Layer 7 load balancer. v2 is the upgrade that makes it the default I reach for in front of internal AKS clusters and App…
DDoS Protection Standard provides cost credits for attack-related scaling. Azure DDoS Protection: resilience against the largest attacks.
Jump boxes are one of those legacy patterns I keep finding in environments I inherit. A Windows VM with RDP open to the internet, "for admin access only,"…
Azure Firewall: cloud-native network security without the complexity.
The hub-and-spoke topology I've drawn on whiteboards for years is what Virtual WAN turns into a deployable resource. A managed hub per region, automatic…
ExpressRoute: enterprise-grade private connectivity to Azure.
The first time a Private Endpoint refused to resolve correctly because the VNet was using Azure-provided DNS, I learned this lesson the hard way: private…
Share VPN/ExpressRoute gateway across peered VNets. VNet peering is the foundation of Azure network architecture.
"Why don't I just use Azure Load Balancer?" is the question I get most often when someone first sees Application Gateway in the architecture diagram. The…
By default, Azure PaaS services (Storage, SQL, Cosmos DB) have public endpoints. Even with firewall rules, data transits the public internet.