Private endpoint DNS: keep the service hostname and prove the resolver path
A private IP in a portal blade is only one part of the connection. Trace the hostname from the workload to the linked private zone.
ReadMeFeed / Community knowledge
Practical guides, fresh perspectives and ideas worth trying.
A private IP in a portal blade is only one part of the connection. Trace the hostname from the workload to the linked private zone.
In this article, you'll learn how to configure a Virtual Machine Scale Set with an existing Azure Load Balancer. With an existing virtual network and standard sku load balancer, you can deploy a Virtual Machine Scale Set with a few clicks in the Azure portal, or with a few lines of code in the Azure
Azure Standard Load Balancer supports global load balancing, which you can use for geo-redundant high availability scenarios such as: Incoming traffic originating from multiple regions. Instant global failover to the next optimal regional deployment. Load distribution across regions to the closest A
For users with Azure Enterprise (EA) agreements, a combination of permissions granted in the Azure portal define a user's level of access to Cost Management data. For users with other Azure account types, defining a user's level of access to Cost Management data is simpler by using Azure role-based
kubectl is the primary command-line tool for communicating with a Kubernetes cluster. This page provides an overview of kubectl and its role in the Kubernetes ecosystem. Kubernetes provides a command line tool for communicating with a Kubernetes cluster's control plane , using the Kubernetes API. Th
Migrating data and storage-intensive workloads to Azure enables access to scalable and secure cloud storage, enabling rapid innovation and growth. This document provides clear, practical guidance to help you achieve seamless migration of block, file, and object storage. It outlines various considera
Azure Load Balancer supports the following distribution modes for routing connections to instances in the backend pool: Distribution mode Hash based Session persistence: Client IP Session persistence: Client IP and protocol Overview Traffic from the same client IP routed to any healthy instance in t
Kubernetes can be configured to use swap memory on a node , allowing the kernel to free up physical memory by swapping out pages to backing storage. This is useful for multiple use-cases. For example, nodes running workloads that can benefit from using swap, such as those that have large memory foot
The Kubernetes API server stores objects, relying on an etcd-compatible backing store (often, the backing storage is etcd itself). Each object is serialized using a particular version of that API type; for example, the v1 representation of a ConfigMap. Kubernetes uses the term storage version to des
Some Azure REST operations run asynchronously because the operation can't be completed quickly. This article describes how to track the status of asynchronous operations through values returned in the response. Status codes for asynchronous operations An asynchronous operation initially returns an H
Work through the supported reactivation path without posting a product key or using unofficial activation tools.
A connection string includes the authorization information required for your application to access data in an Azure Storage account at runtime using Shared Key authorization. You can configure connection strings to: Connect to the Azurite storage emulator. Access a storage account in Azure. Access s
To bring the rich set of Azure network capabilities to containers, you can use the same software-defined networking stack that powers virtual machines. The Azure Virtual Network container network interface (CNI) plug-in installs in an Azure virtual machine. The plug-in assigns IP addresses from a vi
Gateway Load Balancer is a SKU of the Azure Load Balancer portfolio designed for high performance and high availability scenarios with third-party Network Virtual Appliances (NVAs). By using Gateway Load Balancer, you can easily deploy, scale, and manage NVAs. Chaining a Gateway Load Balancer to you
In the landscape of enterprise integration, Azure Logic Apps (Standard) represents a significant architectural shift from its multi-tenant Consumption predecessor. By moving to a single-tenant…
The kubectl command-line tool supports several different ways to create and manage Kubernetes objects . This document provides an overview of the different approaches. Read the Kubectl book for details of managing objects by Kubectl. Management techniques Warning: A Kubernetes object should be manag
Feature state: Stable since Kubernetes v1.24 When you run a Pod on a Node, the Pod itself takes an amount of system resources. These resources are additional to the resources needed to run the container(s) inside the Pod. In Kubernetes, Pod Overhead is a way to account for the resources consumed by
Use connection timing, effective network rules, boot diagnostics and guest evidence to choose the smallest recovery action.
Azure Public DNS is a hosting service for DNS domains that provides name resolution by using Microsoft Azure infrastructure. By hosting your domains in Azure, you can manage your DNS records by using the same credentials, APIs, tools, and billing as your other Azure services. You can't use Azure Pub
Large enterprises often centrally manage Azure services or resources. However, different internal departments or business units use them. Typically, the centrally managing team wants to reallocate the cost of the shared services back out to the internal departments or organizational business units w
Feature state: Stable since Kubernetes v1.20 This page describes the RuntimeClass resource and runtime selection mechanism. RuntimeClass is a feature for selecting the container runtime configuration. The container runtime configuration is used to run a Pod's containers. Motivation You can set a dif
Azure Load Balancer is Azure's most performant Load Balancer all while keeping latency ultra-low. To learn more about Azure Load Balancer, visit Azure Load Balancer overview or Azure Load balancer components . Azure Load Balancer uses a tuple-based hashing as the load-balancing algorithm. Load balan
Azure DNS allows you to host a DNS domain and manage the DNS zone records. To host your domain in Azure, the zone must be created in Azure and delegated to Azure's authoritative DNS servers with a domain registrar. Azure DNS isn't the domain registrar. This article explains how domain delegation wor
In the dynamic landscape of cloud computing, Microsoft Azure stands as a formidable platform, offering a vast array of services designed to meet the diverse…
Microsoft Entra Facebook Google GitHub X OpenID Connect provider Sign in with Apple (preview) This article shows you how to configure Azure App Service or Azure Functions to use Google as an authentication provider. To complete the procedure, you must have a Google account that has a verified email
Azure DNS alias records are qualifications on a DNS record set. They can reference other Azure resources from within your DNS zone. For example, you can create an alias record set that references an Azure public IP address instead of an A record. Your alias record set points to an Azure public IP ad
An extension resource is a resource that adds to another resource's capabilities. For example, resource lock is an extension resource. You apply a resource lock to another resource to prevent it from being deleted or modified. It doesn't make sense to create a resource lock by itself. You always app
Use the actual caller, bucket and operation to separate missing allows from explicit denies, endpoint restrictions and KMS access.
Important As of July 28, 2025, changes to App Service Managed Certificates (ASMC) impact how certificates are issued and renewed in certain scenarios. While most customers don’t need to take action, we recommend reviewing our ASMC detailed blog post for more information. You can restrict access to y
Foundry Agent Service can call an App Service OpenAPI endpoint anonymously or with managed identity. Use managed identity when App Service authentication protects the endpoint. This scenario contains two independent managed identity directions: When App Service calls Foundry, the caller is the App S
This article provides an overview of DNS resolver policy and Threat intelligence feed. For more information about configuration of DNS resolver policy and Threat intelligence feed, see the following how-to guides: Secure and view DNS traffic . Secure your VNet with Threat intelligence feed . What is
This article explains how to install and use the Cost Management Power BI app. The app helps you analyze and manage your Azure costs in Power BI. You can use the app to monitor costs, usage trends, and identify cost optimization options to reduce your expenditures. The Cost Management Power BI app c
Important On September 30, 2025, Basic Load Balancer was retired. For more information, see the official announcement . If you're currently using Basic Load Balancer, upgrade to Standard Load Balancer as soon as possible. For guidance on upgrading, see Upgrading from Basic Load Balancer - Guidance .
You can use Azure DNS to host your DNS domain and manage your DNS records. By hosting your domains in Azure, you can manage your DNS records using the same credentials, APIs, tools, and billing as your other Azure services. Suppose you buy the domain contoso.com from a domain name registrar and then
For security reasons, storage administrators might want to limit the environments from which data can be copied to storage accounts. Limiting the scope of permitted copy operations helps prevent the infiltration of unwanted data from untrusted tenants or virtual networks. This article shows you how
This page describes device taints and tolerations in DRA, which let drivers and admins keep Pods off specific devices, or evict Pods already using them. Device taints and tolerations Feature state: Stable since Kubernetes v1.37 More information about this feature This is a stable feature in Kubernet
Azure Service Tags were introduced in 2018 to simplify network security management in Azure. A service tag represents groups of IP address prefixes associated with specific Azure services and can be used in Network Security Groups (NSGs), Azure Firewall, and User-Defined Routes (UDR). While the inte
When you specify a Pod , you can optionally specify how much of each resource a container needs. The most common resources to specify are CPU and memory (RAM); there are others. When you specify the resource request for containers in a Pod, the kube-scheduler uses this information to decide which no
A resource provider is a collection of REST operations that enables functionality for an Azure service. Each resource provider has a namespace in the format of company-name.service-label . This article shows the resource providers for Azure services. If you don't know the resource provider, see Find
The new Premium v4 pricing tier provides faster processors, NVMe local storage, and memory-optimized options. It offers up to double the memory-to-core ratio of previous tiers. This performance advantage can save money by running apps on fewer instances. This article explains how to create or scale
In Kubernetes, scheduling refers to making sure that Pods are matched to Nodes so that Kubelet can run them. Scheduling overview A scheduler watches for newly created Pods that have no Node assigned. For every Pod that the scheduler discovers, the scheduler becomes responsible for finding the best N
A container image represents binary data that encapsulates an application and all its software dependencies. Container images are executable software bundles that can run standalone and that make very well-defined assumptions about their runtime environment. You typically create a container image of
Billing tags are metadata elements that you can apply to Microsoft Customer Agreement MCA billing entities including billing profiles and invoice sections. Just like Azure tags, billing tags are key-value pairs that are used to identify the entities. For example, to identify an invoice section with
Learn how to use the Microsoft Azure Network Adapter (MANA) component of Azure Boost to improve the performance and availability of virtual machines (VMs) in Azure. MANA is a next-generation network interface that provides stable forward-compatible device drivers for Windows and Linux operating syst
You can use an Azure network security group to filter network traffic between Azure resources in Azure virtual networks. A network security group contains security rules that allow or deny inbound network traffic to, or outbound network traffic from, several types of Azure resources. This article ex
This article provides an overview of how reverse DNS works, and scenarios in which reverse DNS is supported in Azure. What is reverse DNS? Conventional DNS records map a DNS name to an IP address. For example, assume that www.contoso.com resolves to 203.0.113.100. Reverse DNS does the opposite by tr
This article shows how to delete resource groups and resources. It describes how Azure Resource Manager orders the deletion of resources when you delete a resource group. Note To delete a resource group, you must first remove any underlying resource locks and backup data. How Resource Manager determ
When you create a virtual machine (VM), you create a virtual network or use an existing one. Decide how your virtual machines are intended to be accessed on the virtual network. It's important to plan before creating resources and make sure you understand the limits of networking resources . In the
Kubernetes runs your workload by placing containers into Pods to run on Nodes . A node may be a virtual or physical machine, depending on the cluster. Each node is managed by the control plane and contains the services necessary to run Pods . Typically you have several nodes in a cluster; in a learn
This article explains how to use Azure Private Link to restrict access for managing resources in your subscriptions. Private links enable you to access Azure services over a private endpoint in your virtual network. When you combine private links with Azure Resource Manager's operations, you allow u