In this article, you learn how to attach a cross-subscription backend to an Azure Load Balancer by creating a cross-subscription backend pool and attaching cross-subscription network interfaces to the backend pool of the load balancer. A cross-subscription load balancer can reference a virtual netwo
Azure Load Balancer is a networking service that distributes inbound traffic across a group of backend resources to improve the scalability and availability of your applications. Understanding its components helps you configure how the load balancer distributes traffic, monitor the health of backend
This page explains proxies used with Kubernetes. Proxies There are several different proxies you may encounter when using Kubernetes: The kubectl proxy : runs on a user's desktop or in a pod proxies from a localhost address to the Kubernetes apiserver client to proxy uses HTTP proxy to apiserver use
Automatically provision and consolidate the Nodes in your cluster to adapt to demand and optimize cost. In order to run workloads in your cluster, you need Nodes . Nodes in your cluster can be autoscaled -
dynamically provisioned , or consolidated to provide needed
capacity while optimizing cost. Au
This page describes the Kubernetes API kinds that dynamic resource allocation
(DRA) uses to categorize, request, and allocate devices. DRA terminology DRA uses the following Kubernetes API kinds to provide the core allocation
functionality. All of these API kinds are included in the resource.k8s.io/
Feature state: Beta since Kubernetes v1.36; enabled by default Kubernetes 1.37 includes a beta feature that lets an API Server proxy resource requests to other peer API servers. It also lets clients get
a holistic view of resources served across the entire cluster through discovery.
This is useful w
Microsoft Entra Facebook Google GitHub X OpenID Connect provider Sign in with Apple (preview) This article shows how to configure Azure App Service or Azure Functions to use Facebook as an authentication provider. To complete the procedure in this article, you need a Facebook account that has a veri
Azure Load Balancer supports multiple frontend IP configurations on a single resource. Each frontend provides an independent entry point for inbound traffic, so you can expose multiple services, domains, or protocols through one load balancer. This article explains when multiple frontends are useful
Azure Standard Load Balancer helps you load-balance all protocol flows on all ports simultaneously when you use an internal load balancer with high availability (HA) ports. HA ports are a type of load-balancing rule that provides an easy way to load-balance all flows that arrive on all ports of an i
In a Kubernetes cluster, a node can be shut down in a planned graceful way or unexpectedly because of reasons such
as a power outage or something else external. A node shutdown could lead to workload
failure if the node is not drained before the shutdown. A node shutdown can be
either graceful or no
Understand how to gain end-to-end visibility of a Kubernetes cluster through the collection of metrics, logs, and traces. In Kubernetes, observability is the process of collecting and analyzing metrics, logs, and traces—often referred to as the three pillars of observability—in order to obtain a bet
The cloud computing landscape is no longer a nascent frontier but a mature, complex ecosystem where providers vie for dominance through an ever-expanding array of…
Azure Storage is retiring the legacy blob storage account storage account type. This article explains what this change means for your legacy blob storage workloads and how to prepare for the transition to general-purpose v2 (GPv2) storage accounts. Why legacy blob storage accounts are being retired
Azure Load Balancer supports cross-subscription load balancing, where the frontend IP and backend pool instances can be in different subscriptions from the Azure Load Balancer. This article provides an overview of cross-subscription load balancing with Azure Load Balancer, and the scenarios it suppo
Microsoft Azure Storage Explorer enables you to easily work with Azure Storage data safely and securely on Windows, macOS, and Linux. By following these guidelines, you can ensure your data stays protected. General Always use the latest version of Storage Explorer. Storage Explorer releases might co
Azure Storage encrypts all data in a storage account at rest. By default, data is encrypted with Microsoft-managed keys. For additional control over encryption keys, you can manage your own keys. Customer-managed keys must be stored in an Azure Key Vault or in an Azure Key Vault Managed Hardware Sec
Feature state: Beta since Kubernetes v1.37; disabled by default More information about this feature To use this feature, you (or a cluster administrator) will need to enable the PodLevelResourceManagers feature gate for all relevant components in your cluster. See Enable Or Disable Feature Gates for
This article describes common errors you might encounter in Cost Management experiences and provides information about self-serve solutions. When you use Cost Management in the Azure portal and encounter an error that you don't understand or can't resolve, find the error code below and try to use th
Microsoft Entra Facebook Google GitHub X OpenID Connect provider Sign in with Apple (preview) This article shows you how to configure Azure App Service or Azure Functions to use Sign in with Apple as an authentication provider. To complete the procedure in this article, you must enroll in the Apple
Select another authentication provider to jump to it. Microsoft Entra Facebook Google GitHub X OpenID Connect provider Sign in with Apple (preview) This article shows you how to configure authentication for Azure App Service or Azure Functions so that your app signs in users with the Microsoft ident
Azure operations can be divided into two categories - control plane and data plane. This article describes the differences between those two types of operations. You use the control plane to manage resources in your subscription. You use the data plane to use capabilities exposed by your instance of
Azure DNS is a hosted DNS management and name resolution service. You can use it to create public DNS names for other applications and services that you deploy in Azure. Creating a name for an Azure service in your custom domain is simple. You just add a record of the correct type for your service.
This page describes how to observe the status and health of resources that are
dynamically allocated with DRA. Observability of dynamic resources You can check the status of dynamically allocated resources by using any of the
following methods: kubelet device metrics ResourceClaim status Device heal
Azure Private DNS provides a reliable and secure DNS service for your virtual networks. Azure Private DNS manages and resolves domain names in the virtual network without the need to configure a custom DNS solution. By using private DNS zones, you can use your own custom domain name instead of the A
Azure Accelerated Networking significantly improves virtual machine networking performance by reducing latency and CPU utilization. This article describes the benefits, constraints, and supported configurations of Accelerated Networking. Accelerated Networking enables single root I/O virtualization
Feature state: Stable since Kubernetes v1.20 Kubernetes allow you to limit the number of process IDs (PIDs) that a Pod can use.
You can also reserve a number of allocatable PIDs for each node for use by the operating system and daemons (rather than by Pods). Process IDs (PIDs) are a fundamental reso
Azure Virtual Network peering enables you to seamlessly connect two or more virtual networks in Azure, making them appear as one for connectivity purposes. This powerful feature allows you to create secure, high-performance connections between virtual networks while keeping all traffic on Microsoft'
This page describes good practices when configuring a Kubernetes cluster
utilizing Dynamic Resource Allocation (DRA). These instructions are for cluster
administrators. Separate permissions to DRA related APIs DRA is orchestrated through a number of different APIs. Use authorization tools
(like RBAC
Feature state: Stable since Kubernetes v1.37 More information about this feature This is a stable feature in Kubernetes, and has been since version v1.37. It was first available in the v1.35 release. You can no longer disable or opt out of this feature or behavior (it is locked); if you explicitly s
Distributed systems often have a need for leases , which provide a mechanism to lock shared resources
and coordinate activity between members of a set.
In Kubernetes, the lease concept is represented by Lease objects in the coordination.k8s.io API Group ,
which are used for system-critical capabilit
Cost Management Labs is an experience in the Azure portal where you can get a sneak peek at what's coming in Cost Management. You can engage directly with us to share feedback and help us better understand how you use the service, so we can deliver more tuned and optimized experiences. This article
You can constrain a Pod so that it is restricted to run on particular node(s) ,
or to prefer to run on particular nodes.
There are several ways to do this and the recommended approaches all use label selectors to facilitate the selection.
Often, you do not need to set any such constraints; the sched
kube-state-metrics, an add-on agent to generate and expose cluster-level metrics. The state of Kubernetes objects in the Kubernetes API can be exposed as metrics.
An add-on agent called kube-state-metrics can connect to the Kubernetes API server and expose a HTTP endpoint with metrics generated from
Each object in your cluster has a Name that is unique for that type of resource.
Every Kubernetes object also has a UID that is unique across your whole cluster. For example, you can only have one Pod named myapp-1234 within the same namespace , but you can have one Pod and one Deployment that are e
The CRI is a plugin interface which enables the kubelet to use a wide variety of
container runtimes, without having a need to recompile the cluster components. You need a working container runtime on
each Node in your cluster, so that the kubelet can launch Pods and their containers. The Container R
Labels are key/value pairs that are attached to objects such as Pods.
Labels are intended to be used to specify identifying attributes of objects
that are meaningful and relevant to users, but do not directly imply semantics
to the core system. Labels can be used to organize and to select subsets of
Azure Blob Storage is frequently mischaracterized as a mere ‘bit bucket’ for unstructured data. In reality, it is a sophisticated, multi-tiered storage solution that requires…
This article discusses a collection of Azure best practices for your load balancer deployment. These best practices are derived from our experience with Azure networking and the experiences of customers like yourself. For each best practice, this article explains: What the best practice is Why you w
Operators are software extensions to Kubernetes that make use of custom resources to manage applications and their components. Operators follow
Kubernetes principles, notably the control loop . Motivation The operator pattern aims to capture the key aim of a human operator who
is managing a service
System component logs record events happening in cluster, which can be very useful for debugging.
You can configure log verbosity to see more or less detail.
Logs can be as coarse-grained as showing errors within a component, or as fine-grained as showing
step-by-step traces of events (like HTTP acc
This document catalogs the communication paths between the API server and the Kubernetes cluster .
The intent is to allow users to customize their installation to harden the network configuration
such that the cluster can be run on an untrusted network (or on fully public IPs on a cloud
provider). N
App Service Authentication allows you to control access to your Model Context Protocol (MCP) server by requiring MCP clients to authenticate with an identity provider. You can make your app comply with the MCP server authorization specification by following the instructions in this article. Importan
Kubernetes is designed with self-healing capabilities that help maintain the health and availability of workloads.
It automatically replaces failed containers, reschedules workloads when nodes become unavailable, and ensures that the desired state of the system is maintained. Self-Healing capabiliti
Azure Storage encrypts all data in a storage account at rest. By default, data is encrypted with Microsoft-managed keys. For more control over encryption keys, you can manage your own keys. Customer-managed keys must be stored in Azure Key Vault or Key Vault Managed Hardware Security Model (HSM). Th
Azure Storage encrypts all data in a storage account at rest. By default, Azure Storage encrypts data by using Microsoft-managed keys. For more control over encryption keys, manage your own keys. You must store customer-managed keys in Azure Key Vault or Azure Key Vault Managed HSM (Hardware Securit