Subnet peering connects two virtual networks by linking specific subnets instead of entire virtual network address spaces. This approach gives you granular control over which subnets participate in the peering relationship between local and remote virtual networks. Subnet peering adds flexibility to
With App Service authentication , the authentication settings can be configured with a file. You may need to use file-based configuration to use certain preview capabilities of App Service authentication / authorization before they're exposed via Azure Resource Manager APIs. Important Remember that
The Kubernetes API lets you query and manipulate the state of objects in Kubernetes. The core of Kubernetes' control plane is the API server and the HTTP API that it exposes. Users, the different parts of your cluster, and external components all communicate with one another through the API server.
This article summarizes best practices for using Azure App Service . Colocation An Azure App Service solution consists of a web app and a database or storage account for holding content or data. When these resources are in different regions, the situation can have the following effects: Increased la
Application security groups in Azure Virtual Network enable you to configure network security as a natural extension of an application's structure, allowing you to group virtual machines and define network security policies based on those groups. You can reuse your security policy at scale without m
Azure App Service represents the pinnacle of Platform-as-a-Service (PaaS) offerings for web hosting, providing an abstraction layer that removes the overhead of managing underlying virtual…
Azure DNS Private Resolver is a fully managed, highly available service that enables secure and seamless DNS resolution between Azure virtual networks and on-premises environments—without the need to deploy, manage, or patch custom DNS servers. By using this service, you can resolve DNS queries for
Hardcoding sensitive credentials within application source code is not merely a novice error; it is a systemic vulnerability that compromises the entire security posture of…
This article describes how you can configure the network routing preference and route-specific endpoints for your storage account. The network routing preference specifies how network traffic is routed to your account from clients over the internet. Route-specific endpoints are new endpoints that Az
Microsoft Entra Facebook Google GitHub X OpenID Connect provider Sign in with Apple (preview) This article shows how to configure Azure App Service or Azure Functions to use GitHub as an authentication provider. To complete the procedure in this article, you need a GitHub account. To create a new Gi
Cost Management includes several tools to help you view and monitor your cloud costs. As you get started, Cost Analysis is the first one you should familiarize yourself with. And within Cost Analysis, you'll start with built-in views. This article helps you understand when to use which view, how eac
You can visualize and manage Kubernetes objects with more tools than kubectl and
the dashboard. A common set of labels allows tools to work interoperably, describing
objects in a common manner that all tools can understand. In addition to supporting tooling, the recommended labels describe applicati
Microsoft Entra Facebook Google GitHub X OpenID Connect provider Sign in with Apple (preview) This article shows you how to configure Azure App Service or Azure Functions to use a custom authentication provider that adheres to the OpenID Connect (OIDC) specification . OIDC is an industry standard th
Note The information provided in this article is only used when you migrate from the classic deployment to the Azure Resource Manager deployment. In this article, you learn about Azure Resource Manager and classic deployment models. The Resource Manager and classic deployment models represent two di
This article shows you how to customize user sign-ins and sign-outs while using the built-in authentication and authorization in Azure App Service . Use multiple sign-in providers The Azure portal configuration doesn't offer a turnkey way to present multiple sign-in providers to your users. For inst
Use kubeconfig files to organize information about clusters, users, namespaces, and
authentication mechanisms. The kubectl command-line tool uses kubeconfig files to
find the information it needs to choose a cluster and communicate with the API server
of a cluster. Note: A file that is used to confi
A service tag represents a group of IP address prefixes from a given Azure service. Microsoft manages the address prefixes encompassed by the service tag and automatically updates the service tag as addresses change, minimizing the complexity of frequent updates to network security rules. Service ta
This page describes optional DRA features for advanced use cases. Some of
these features require support from the DRA driver. Each feature notes its
maturity and the feature gate that enables it. Partitionable devices Feature state: Beta since Kubernetes v1.36; enabled by default Devices represented
The following information applies to Microsoft partners only. Often, partners don't have their own Azure subscriptions in the tenant associated with their own Microsoft Partner Agreement. Partners with a Microsoft Partner Agreement plan who are billing admins of their billing account can export and
This documentation provides details on how customers can configure Azure Resource Manager for use in a data boundary. The only data boundary configuration currently supported, aside from the default Global configuration, is for the European Union (EU). The EU Data Boundary is a geographically define
Networking is a central part of Kubernetes, but it can be challenging to
understand exactly how it is expected to work. There are 4 distinct networking
problems to address: Highly-coupled container-to-container communications: this is solved by Pods and localhost communications. Pod-to-Pod communica
Azure Virtual Network encryption is a feature of Azure Virtual Networks. Virtual network encryption allows you to seamlessly encrypt and decrypt traffic between Azure Virtual Machines by creating a DTLS tunnel. Virtual network encryption enables you to encrypt traffic between Virtual Machines and Vi
Security in cloud architecture is frequently treated as a secondary concern, often resulting in the catastrophic practice of hardcoding credentials within source code or configuration…
This page describes the resources available to Containers in the Container environment. Container environment The Kubernetes Container environment provides several important resources to Containers: A filesystem, which is a combination of an image and one or more volumes . Information about the Cont
On Linux, control groups constrain resources that are allocated to processes. The kubelet and the
underlying container runtime need to interface with cgroups to enforce resource management for pods and containers which
includes cpu/memory requests and limits for containerized workloads. There are tw
Microsoft Cost Management is a suite of FinOps tools that help organizations analyze, monitor, and optimize their Microsoft Cloud costs. Cost Management is available to anyone with access to a billing account, subscription, resource group, or management group. You can access Cost Management within t
Network security groups (NSGs) control network traffic flow through security rules that filter traffic in and out of virtual network subnets and network interfaces. This guide shows you how to create, change, or delete network security groups to enhance your Azure virtual network security. Learn to
This article shows you how to manage OAuth tokens for built-in authentication and authorization in Azure App Service. Retrieve tokens in app code Azure App Service injects your provider-specific tokens into the request header so you can easily access them. To get the provider-specific tokens, token
A storage account contains all of your Azure Storage data objects: blobs, files, queues, and tables. The storage account provides a unique namespace for your Azure Storage data that's accessible from anywhere in the world over HTTP or HTTPS. Data in your storage account is durable, highly available,
Custom resources are instances of resource types added to Kubernetes through API extensions. This page discusses when to add a custom
resource to your Kubernetes cluster and when to use a standalone service. It describes the two
methods for adding custom resources and how to choose between them. Cus
You can use your own encryption key to protect the data in your storage account. When you specify a customer-managed key, Azure Storage uses that key to protect and control access to the key that encrypts your data. Customer-managed keys offer greater flexibility to manage access controls. You must
AWS has announced general availability of the Graviton5-based R9g and R9gd memory-optimized EC2 families. R9g uses EBS-backed storage, while R9gd adds local NVMe storage. The distinction matters for workloads that can benefit from low-laten
Node-pressure eviction is the process by which the kubelet proactively terminates
pods to reclaim resource on nodes. The kubelet monitors resources
like memory, disk space, and filesystem inodes on your cluster's nodes.
When one or more of these resources reach specific consumption levels, the
kubel
The aggregation layer allows Kubernetes to be extended with additional APIs, beyond what is
offered by the core Kubernetes APIs.
The additional APIs can either be ready-made solutions such as a metrics server , or APIs that you develop yourself. The aggregation layer is different from Custom Resourc
API-initiated eviction is the process by which you use the Eviction API to create an Eviction object that triggers graceful pod termination. You can request eviction by calling the Eviction API directly, or programmatically
using a client of the API server , like the kubectl drain command. This
crea
Recommendations for designing and deploying admission webhooks in Kubernetes. This page provides good practices and considerations when designing admission webhooks in Kubernetes. This information is intended for
cluster operators who run admission webhook servers or third-party applications
that mo
Use an Azure network security group (NSG) to filter network traffic to and from Azure resources in an Azure virtual network. Network security groups provide essential traffic filtering capabilities that help secure your cloud infrastructure by controlling which traffic can flow between resources. A
Finalizers are namespaced keys that tell Kubernetes to wait until specific
conditions are met before it fully deletes resources that are marked for deletion.
Finalizers alert controllers to clean up resources the deleted object owned. When you tell Kubernetes to delete an object that has finalizers
As an administrator, you can lock an Azure subscription, resource group, or resource to protect them from accidental user deletions and modifications. The lock overrides any user permissions. You can set locks that prevent either deletions or modifications. In the portal, these locks are called Dele
Microsoft’s recent infrastructure discussion puts attention on the yield from AI systems: how effectively hardware, software and operations become useful intelligence. For application teams, the practical lesson is to connect infrastructure
In Kubernetes, some objects are owners of other objects. For example, a ReplicaSet is the owner
of a set of Pods. These owned objects are dependents of their owner. Ownership is different from the labels and selectors mechanism that some resources also use. For example, consider a Service that
creat
In robotics and automation, a control loop is
a non-terminating loop that regulates the state of a system. Here is one example of a control loop: a thermostat in a room. When you set the temperature, that's telling the thermostat
about your desired state . The actual room temperature is the current
Microsoft has described Project Perception as a security system coordinating specialized agents for identifying potential attack paths, investigating risk and taking corrective action. The announcement frames continuous context and a feedba
You can use the Azure portal to delegate a DNS subdomain. For example, if you own the adatum.com domain, you can delegate a subdomain called engineering.adatum.com to another separate zone that you can administer separately from the adatum.com zone. You can also delegate a subdomain using Azure Powe