You Are Logging Everything — And Seeing Almost Nothing

You Are Logging Everything — And Seeing Almost Nothing Part 3 of the Cloud Security series This article is the third part in a series on cloud security, based on real Azure environments rather than idealized models. The first part emphasized establishing momentum through basic improvements. The second highlighted how identity is the most underestimated yet powerful security control in the cloud. This section shifts focus to telemetry, which most platforms already possess in large quantities: logs, metrics, alerts, and signals are ubiquitous in Azure. Despite this abundance, many organizations remain largely unaware of significant security risks. ...

January 6, 2026 · 5 min · 964 words · Jurgen Allewijn

Identity Is the Perimeter You Forgot to Guard

Identity Is the Perimeter You Forgot to Guard Part 2 of the Cloud Security series Cloud security often fails not due to advanced attacks, but because of unnoticed access and unrevoked privileges. This is the second part of a series on cloud security in real-world Azure environments, which evolve over time under pressure and good intentions. The first part discussed how small, fundamental improvements can significantly improve security. In this segment, we focus on identity, as it is the critical factor determining success or failure in cloud security. ...

December 29, 2025 · 6 min · 1109 words · Jurgen Allewijn

The First Security Conversation You Have Too Late: Hardening an Existing Azure Environment

Most cloud security stories begin in the wrong place. This article launches a series on cloud security, focusing on real Azure environments rather than idealized designs. It examines platforms that have been operational for years, where identities developed naturally, workloads were deployed quickly, and security measures were gradually implemented. The series aims not to present new tools or frameworks but to analyze how security evolves in practice, identify where genuine risks arise, and highlight the most effective improvements when working with existing systems. ...

December 23, 2025 · 5 min · 856 words · Jurgen Allewijn

The Unseen Work of a Cloud Architect: A Story About Building Azure the Hard (and Right) Way

The Unseen Work of a Cloud Architect: A Story About Building Azure the Hard (and Right) Way The story of implementing an Azure cloud environment rarely starts with technology. It begins with a seemingly simple conversation: someone in the business has a goal, a team has a new initiative, or an executive has read an article promising faster innovation, better resilience, or lower operational costs. The request sounds straightforward: “We want to move to Azure.” But it’s never that simple. Not because Azure is inherently complex, though it can be, but because cloud architecture is more about managing people, expectations, culture, pressure, and an ever-changing regulatory landscape. ...

December 5, 2025 · 12 min · 2510 words · Jurgen Allewijn

Operating AKS from your workstation

Operating AKS from your workstation: Inside Microsoft’s New AKS Desktop There has long been a peculiar duality in managing Azure Kubernetes Service. The Azure portal offers abundant information but often feels disconnected from the cluster’s core functions. Meanwhile, Kubernetes is accessible through kubectl, YAML files, and dashboards like Headlamp. One exists within the Azure control plane, and the other entirely within the Kubernetes API. Operators frequently switch between these two realms multiple times daily, yet they never quite close the gap. ...

November 30, 2025 · 13 min · 2612 words · Jurgen Allewijn

Beyond the Cloud: Running Kubernetes with Talos: Comparing Talos, k3s, AKS, and EKS

Beyond the Cloud: Running Kubernetes with Talos: Comparing Talos, k3s, AKS, and EKS “If Kubernetes is the engine, Talos is the chassis built specifically for it.” Introduction: Rethinking the Kubernetes Operating System When Kubernetes first appeared, it was celebrated as the “Linux of the cloud.” But beneath every Kubernetes cluster, there’s always a traditional operating system like Ubuntu, CentOS, Flatcar, or another Linux distribution. These weren’t originally built specifically for the orchestration layer that overlays them. This historical setup has quietly influenced how we manage, patch, and secure our clusters. Even as control planes have shifted to managed services such as Azure Kubernetes Service (AKS) and Amazon Elastic Kubernetes Service (EKS), the nodes themselves still rely on an operating system that wasn’t initially designed for immutability or declarative control. ...

November 25, 2025 · 7 min · 1460 words · Jurgen Allewijn

Application Gateway for Containers: The Future of Cloud-Native Ingress

Exploring the concept behind Azure’s next-generation ingress platform When Ingress Becomes Strategic There’s a moment in every Kubernetes journey when ingress stops being just a configuration detail and becomes an architectural constraint. You start with a small cluster, maybe one or two microservices, and the standard NGINX ingress controller does exactly what you expect: simple routes, basic certificates, nothing fancy. Then the platform expands. You integrate workloads across multiple regions, extend environments with Azure Container Apps, and add a service mesh, and suddenly that “temporary ingress setup” becomes a bottleneck. ...

November 12, 2025 · 13 min · 2744 words · Jurgen Allewijn

Azure Kubernetes Chronicles 12: The Future of Multi-Cluster

Fleet, Arc, sovereign clouds, and the edge-first world of 2030 This article is the last part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. Examining today’s multi-cluster landscape, it is tempting to focus solely on the pain points: identity fragmentation, policy drift, networking complexity, and monitoring silos. But the story does not end there. Kubernetes itself has evolved from a single-cluster dream to a multi-cluster necessity, and the governance ecosystem around it is growing just as quickly. To understand where things are headed, we have to look beyond today’s tools and into the future that is already taking shape. ...

October 28, 2025 · 5 min · 857 words · Jurgen Allewijn

Using the AKS-MCP Server in Day-to-Day Operations

Azure Kubernetes Service (AKS) has long been the leading platform for containerized workloads on Microsoft Azure. While AKS offers scalability and resilience, managing it day-to-day still involves switching between various tools: Azure CLI, kubectl, ARM templates, and portal dashboards. This is where the Microsoft AKS-MCP Server, part of the Model Context Protocol (MCP) ecosystem, makes a difference. By providing a structured, secure interface for agents and tools to perform Azure and Kubernetes actions, AKS-MCP changes how engineers interact with clusters. ...

October 23, 2025 · 9 min · 1805 words · Jurgen Allewijn

Azure Kubernetes Chronicles 11: Governing the Chaos

Azure Kubernetes Chronicles 11: Governing the Chaos Unifying identity, policy, networking, and observability across clouds and edge This article is part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. Governance pain points By the time enterprises have stretched Kubernetes across Azure, AWS, and the edge, the real problem is no longer the technology itself. It is governance. What began as a strategy to increase resilience and satisfy compliance quickly turns into a patchwork of identity systems, policy frameworks, networking models, and monitoring stacks. The result is fragmentation. Platform teams are left trying to stitch together three or more worlds, often with tools that were never designed to coexist. ...

October 21, 2025 · 5 min · 987 words · Jurgen Allewijn

Stay up to date

Practical insights on Azure, Kubernetes, cloud security, and digital sovereignty. No spam—just occasional technical deep dives and lessons from the field.