The Domain Name System (DNS) translates (resolves) a service name to an IP address. Azure DNS provides DNS hosting, resolution, and load balancing for your applications by using the Microsoft Azure infrastructure. Azure DNS supports both internet-facing DNS domains and private DNS zones. It provides
You can use Kubernetes annotations to attach arbitrary non-identifying metadata
to objects .
Clients such as tools and libraries can retrieve this metadata. Attaching metadata to objects You can use either labels or annotations to attach metadata to Kubernetes
objects. Labels can be used to select o
This article describes how to customize the API and runtime versions of the built-in authentication and authorization in App Service . There are two versions of the management API for App Service authentication. The V2 version is required for the authentication experience in the Azure portal. An app
Choose how Cloud Run receives secrets, grant access to the runtime service account, and build a rotation and rollback plan around the documented refresh behavior.
This article helps you understand and use Cost Management alerts to monitor your Azure usage and spending. Cost alerts are automatically generated based when Azure resources are consumed. Alerts show all active cost management and billing alerts together in one place. When your consumption reaches a
A Secret is an object that contains a small amount of sensitive data such as
a password, a token, or a key. Such information might otherwise be put in a Pod specification or in a container image . Using a
Secret means that you don't need to include confidential data in your
application code. Because
In Kubernetes, namespaces provide a mechanism for isolating groups of resources within a single cluster. Names of resources need to be unique within a namespace, but not across namespaces. Namespace-based scoping is applicable only for namespaced objects (e.g. Deployments, Services, etc.) and not fo
Cost Management gives you the tools to plan for, analyze and reduce your spending to maximize your cloud investment. This document provides you with a methodical approach to cost management and highlights the tools available to you as you address your organization's cost challenges. Azure makes it e
Advertised gateway prefixes let you specify summarized (aggregated) CIDR prefixes that Azure hybrid gateways advertise to on-premises networks instead of advertising all individual virtual network and spoke CIDRs. This feature helps reduce the number of advertised routes in large hub-and-spoke desig
This page describes how Kubernetes allocates devices to workloads with dynamic
resource allocation (DRA), and how pre-scheduled Pods interact with the process. How resource allocation with DRA works The following sections describe the workflow for the various types of DRA users and for the Kubernete
Tags are widely used to group costs to align with different business units, engineering environments, cost departments, and so on. Tags provide the visibility needed for businesses to manage and allocate costs across the different groups. This article explains how to use the tag inheritance setting
Feature state: Beta since Kubernetes v1.27 System component traces record the latency of and relationships between operations in the cluster. Kubernetes components emit traces using the OpenTelemetry Protocol with the gRPC exporter and can be collected and routed to tracing backends using an OpenTel
Feature state: Beta since Kubernetes v1.33; disabled by default More information about this feature To use this feature, you (or a cluster administrator) will need to enable the CoordinatedLeaderElection feature gate for all relevant components in your cluster. See Enable Or Disable Feature Gates fo
An overview of the key components that make up a Kubernetes cluster. This page provides a high-level overview of the essential components that make up a Kubernetes cluster. View source diagram: Components of Kubernetes The components of a Kubernetes cluster Core Components A Kubernetes cluster consi
Azure storage is retiring the general-purpose v1 (GPv1) storage account type. This article explains why the change is occurring, what it means for your workloads, and how to prepare for the transition to general-purpose v2 (GPv2) accounts. Reasons for retiring GPv1 GPv1 was introduced to support ear
In the dynamic landscape of cloud computing, Infrastructure as a Service (IaaS) remains a foundational element for many organizations. At the forefront of IaaS offerings,…
IBM has published separate provisioning, PaaS, and IaaS deadlines for Chennai 01. Build a dependency inventory and rehearse migration before the relevant cutoff.
An EC2 instance role is only part of the S3 authorization path. Identify the real caller, distinguish bucket and object permissions, and trace explicit denies.
Azure Storage is retiring the general purpose v1 (GPv1) with ZRS redundancy storage account configuration. This article explains what the change means for workloads using general purpose v1 (GPv1) with ZRS redundancy and how to prepare for a smooth transition to general-purpose v2 (GPv2) with modern
Storage insights provides comprehensive monitoring of your Azure Storage accounts by delivering a unified view of your Azure Storage services performance, capacity, and availability. You can observe storage capacity, and performance in two ways, view directly from a storage account or view from Azur
AWS’s September 7 roundup includes an Amazon Linux 2027 public preview, Lambda SnapStart support for container-image functions, new Redshift support for Apache Iceberg v3 tables and a new AI Business Strategist certification offering. These
Azure Resource Manager is the deployment and management service for Azure. It provides a management layer that helps you to create, update, and delete resources in your Azure account. You use management features like access control, locks, and tags to secure and organize your resources after deploym
Field selectors let you select Kubernetes objects based on the
value of one or more resource fields. Here are some examples of field selector queries: metadata.name=my-service metadata.namespace!=default status.phase=Pending This kubectl command selects all Pods for which the value of the status.pha
A ConfigMap is an API object used to store non-confidential data in key-value pairs. Pods can consume ConfigMaps as
environment variables, command-line arguments, or as configuration files in a volume . A ConfigMap allows you to decouple environment-specific configuration from your container images
Garbage collection is a collective term for the various mechanisms Kubernetes uses to clean up
cluster resources. This
allows the clean up of resources like the following: Terminated pods Completed Jobs Objects without owner references Unused containers and container images Dynamically provisioned P
This article explains how to work with existing resource management private links. It shows API operations for getting and deleting existing resources. If you need to create a resource management private link, see Use portal to create private link for managing Azure resources or Use APIs to create p
Feature state: Beta since Kubernetes v1.11 Cloud infrastructure technologies let you run Kubernetes on public, private, and hybrid clouds.
Kubernetes believes in automated, API-driven infrastructure without tight coupling between
components. The cloud-controller-manager is a Kubernetes control plane
Cost Management is natively available for direct partners that onboarded their customers to a Microsoft Customer Agreement and purchased an Azure Plan . This article explains how partners use Cost Management features to view costs for subscriptions in the Azure Plan. It also describes how partners e
Feature state: Stable since Kubernetes v1.29 Controlling the behavior of the Kubernetes API server in an overload situation
is a key task for cluster administrators. The kube-apiserver has some controls available
(i.e. the --max-requests-inflight and --max-mutating-requests-inflight command-line fla
Application logs can help you understand what is happening inside your application. The
logs are particularly useful for debugging problems and monitoring cluster activity. Most
modern applications have some kind of logging mechanism. Likewise, container engines
are designed to support logging. The
Cost Management users often want answers to questions that many others ask. This article walks you through getting results for common cost analysis tasks in Cost Management. View forecast costs Forecast costs are shown in Cost Analysis when using area and stacked column charts. The forecast is based
The DNS protocol prevents the assignment of a CNAME record at the zone apex. An example zone apex is contoso.com. This restriction presents a problem for application owners who have load-balanced applications behind Traffic Manager, because a Traffic Manager profile is normally referenced with a CNA
Cost Analysis has many grouping and filtering options. This article helps you understand when to use them. To watch a video about grouping and filtering options, watch the Cost Management reporting by dimensions and tags video. To watch other videos, visit the Cost Management YouTube channel . Group
The new Premium V3 pricing tier gives you faster processors, SSD storage, and memory-optimized options. It offers to quadruple the memory-to-core ratio of the existing pricing tiers. The memory-to-core ratio is double the Premium V2 tier. With the performance advantage, you could save money by runni
AWS has extended EBS Volume Clones to support copies into another AWS account. The practical opportunity is a cleaner separation between production storage and the environment where a team develops or tests changes. The target account can a
Azure Storage encrypts all data in a storage account at rest. By default, data is encrypted with Microsoft-managed keys. For additional control over encryption keys, you can manage your own keys. Customer-managed keys must be stored in an Azure Key Vault or in an Azure Key Vault Managed Hardware Sec
Azure DNS provides name resolution for any of your Azure resources that support custom domains, or that have a fully qualified domain name (FQDN). For example, you might have an Azure web app you want your users to access using contoso.com or www.contoso.com as the FQDN. This article walks you throu
Kubernetes (version 1.3 through to the latest 1.37, and likely onwards) lets you use Container Network Interface (CNI) plugins for cluster networking. You must use a CNI plugin that is compatible with your
cluster and that suits your needs. Different plugins are available (both open- and closed- sou
Subnet delegation in Azure virtual networks enables you to designate a specific subnet for an Azure PaaS service of your choice that needs to be injected into your virtual network. This feature provides full control to customers on managing the integration of Azure services into their virtual networ
This article shows you how to secure your Model Context Protocol (MCP) server hosted on Azure App Service using Microsoft Entra authentication. By enabling authentication, you ensure that only users authenticated with Microsoft Entra can access your MCP server through Copilot agent mode in Visual St
In this article, you learn to create a custom API for HTTP health probes using Python, FLASK, and psutil. Health checks are performed on backend instances using HTTP GET and marked as healthy or unhealthy based on the response. The custom probe in this article marks instances as unhealthy if their C
You can use Azure PowerShell to delegate a DNS subdomain. For example, if you own the contoso.com domain, you may delegate a subdomain called engineering to another separate zone that you can administer separately from the contoso.com zone. If you prefer, you can also delegate a subdomain using the
When several users or teams share a cluster with a fixed number of nodes,
there is a concern that one team could use more than its fair share of resources. Resource quotas are a tool for administrators to address this concern. A resource quota, defined by a ResourceQuota object, provides constraints
This page describes how kubelet managed Containers can use the Container lifecycle hook framework
to run code triggered by events during their management lifecycle. Overview Analogous to many programming language frameworks that have component lifecycle hooks, such as Angular,
Kubernetes provides Co
The cloud computing landscape is a dynamic and increasingly complex ecosystem, with Microsoft Azure standing as a formidable contender. Its comprehensive suite of services, spanning…
Administrative state (Admin state) is a feature of Azure Load Balancer that allows you to override the Load Balancer's health probe behavior on a per backend pool instance basis. This feature is useful in scenarios where you would like to take down your backend instance for maintenance, patching, or
Feature state: Beta since Kubernetes v1.37; disabled by default More information about this feature To use this feature, you (or a cluster administrator) will need to enable the GenericWorkload feature gate for all relevant components in your cluster. See Enable Or Disable Feature Gates for more inf
This article explains how to use Azure Private Link to restrict access for managing resources in your subscriptions. It shows how to use the Azure portal for setting up management of resources through private access. Private links enable you to access Azure services over a private endpoint in your v
Centralizing sensitive information is not a luxury; it is a fundamental architectural requirement for any cloud-native application. Azure Key Vault serves as the definitive repository…