Azure Kubernetes Chronicles 10: Kubernetes at the Edge with k3s

Azure Kubernetes Chronicles 10: Kubernetes at the Edge with k3s From Raspberry Pi retail stores to 5G towers — the hidden force reshaping enterprise IT This article is part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. When most people think of Kubernetes, they imagine large clusters humming inside hyperscale cloud regions, backed by the weight of Azure, AWS, or Google. However, the future of Kubernetes is increasingly not limited to vast data centers, but also extends to much smaller, more distributed locations, such as retail stores, factory floors, hospital wards, or 5G towers. At the core of this movement is k3s, a lightweight Kubernetes distribution that is small enough to run on a Raspberry Pi but robust enough to support enterprise workloads. ...

October 13, 2025 · 5 min · 932 words · Jurgen Allewijn

Running Containers the Apple Way: A First Look into Apple Container on macOS

Running Containers the Apple Way: A First Look into Apple Container on macOS For years, running containers on macOS has involved compromises. Docker Desktop used HyperKit to virtualize Linux, which was simple to use but resource-intensive. Alternatives like Rancher Desktop and OrbStack improved on this by being lighter, faster, and more developer-friendly, yet they all depended on the same core approach: emulating or virtualizing Linux within macOS. Apple has now entered this space with a native solution: Apple Container, an OCI-compliant container runtime explicitly designed for Apple Silicon and macOS 15/16 and later. It is not simply a re-skin of Docker or a clone of Lima or Colima. Instead, it represents Apple’s unique approach to how containers should operate on macOS, using the Virtualization and Network frameworks that power iOS simulators and macOS sandboxing. ...

October 8, 2025 · 6 min · 1216 words · Jurgen Allewijn

Azure Kubernetes Security Demystified: From Nodes to Pods

Azure Kubernetes Security Demystified: From Nodes to Pods Introduction Kubernetes has become the standard for hosting containerized applications, with Azure Kubernetes Service (AKS) being one of the most popular managed options. AKS simplifies management by handling the control plane, but securing the environment remains the customer’s responsibility. The shared responsibility model requires you to focus on strengthening worker nodes, controlling cluster access, and ensuring that workloads and pods operate with the least privileges. Security in Kubernetes involves multiple layers. The base layer is the host security of the virtual machines in the node pools. Next is the cluster layer, where identity, networking, and governance must be carefully established and maintained. At the top, securing pods and containers that run your business logic is crucial to prevent privilege escalation or unauthorized communication. This approach, known as “defense in depth,” emphasizes addressing security across various boundaries instead of relying on a single tool or configuration for full protection. ...

October 6, 2025 · 10 min · 1927 words · Jurgen Allewijn

Azure Kubernetes Chronicles 9: EKS in the Enterprise

Why Amazon’s Kubernetes service is a compliance lever, not just duplication This article is part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. Whenever companies discuss Kubernetes in Azure, AKS naturally comes up because it’s the go-to managed service for those within Microsoft’s ecosystem. However, across Europe, another name is gaining attention: Amazon Elastic Kubernetes Service, or EKS. For many organizations, EKS isn’t just another option; it’s become a vital part of their strategic planning. ...

October 1, 2025 · 4 min · 847 words · Jurgen Allewijn

Azure Kubernetes Chronicles 8: Fleet in Focus

Azure Kubernetes Chronicles 8: Fleet in Focus Azure’s multi-cluster powerhouse — and where it falls short This article is part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. When Microsoft introduced Azure Kubernetes Fleet Manager, it was met with both excitement and curiosity. For years, platform teams running multiple AKS clusters had been piecing together governance with scripts, policies, and half-baked federation approaches. Fleet arrived with the promise of simplification: a central way to govern clusters, propagate policies, and even distribute workloads across Azure regions. ...

September 24, 2025 · 4 min · 793 words · Jurgen Allewijn

Azure Kubernetes Chronicles 7: The Multi-Cluster Reality

From the dream of one perfect cluster to the messy truth of enterprise sprawl This episode is part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. When Kubernetes first entered the enterprise, many platform teams envisioned a single, perfect cluster; a hub where all workloads could reside, scale smoothly, and be governed consistently. The reality turned out very different. Today, almost no enterprise runs just one cluster. Instead, organizations find themselves managing multiple clusters scattered across regions, cloud providers, and even edge sites. This isn’t random chaos; it’s the result of regulatory demands, business continuity strategies, performance requirements, and the rise of edge computing. ...

September 18, 2025 · 5 min · 956 words · Jurgen Allewijn

Azure Kubernetes Chronicles: Multi-Cluster Edition

From Fleet to Edge — navigating Kubernetes across clouds and continents When Kubernetes first entered the enterprise, many architects imagined a single, perfect cluster: one hub for all workloads, scalable, resilient, and secure. Reality had other plans. Enterprises today run multiple clusters across regions, providers, and even at the edge: • AKS in Azure for mainline production. • EKS in AWS to meet regulatory or resilience mandates. • k3s clusters on Raspberry Pi or NUCs powering retail stores, factories, and hospitals. ...

September 12, 2025 · 3 min · 487 words · Jurgen Allewijn

Azure Kubernetes Chronicles 6:

Introduction: Why Centralized Management of AKS Clusters Matters Kubernetes adoption in enterprises has skyrocketed. What begins as a single proof-of-concept cluster often grows into dozens across various teams, environments, and regions. For organizations using Azure Kubernetes Service (AKS), this growth is even more common: different business units create clusters for their workloads, data residency rules require data to stay in specific locations, and production systems need failover capabilities across regions. ...

September 3, 2025 · 19 min · 3972 words · Jurgen Allewijn

Digital Sovereignty and the Public Cloud:

Digital Sovereignty and the Public Cloud: Navigating Azure in a European context Introduction: Why digital sovereignty matters Over the past decade, cloud adoption has shifted from an optional innovation to the standard approach for many. In Europe, Microsoft Azure, Amazon Web Services, and Google Cloud are the foundation of digital infrastructure. However, a key question has arisen: who really controls your data and workloads? This is the heart of digital sovereignty, the ability of a state, organization, or individual to shape their digital future. It’s not just about where data is stored, but also about who can access it, under what laws, and with what safeguards in place. For cloud engineers and DevOps professionals, sovereignty may have seemed abstract until it began to affect core architecture decisions, such as encryption, multi-cloud strategy, and operational governance. ...

August 27, 2025 · 11 min · 2158 words · Jurgen Allewijn

Harnessing Chaos: Implementing Chaos Engineering with Azure Chaos Studio and Gremlin on AKS

Harnessing Chaos: Implementing Chaos Engineering with Azure Chaos Studio and Gremlin on AKS Chaos Engineering is a crucial practice for modern cloud operations, enabling teams to identify hidden weaknesses and potential failures in complex systems before they become a problem. By deliberately causing failures in a controlled setting, you can observe how your system responds, measure its resilience, and ultimately strengthen its robustness. This practice really stands out in cloud-native environments like Azure Kubernetes Service (AKS), where the details and interconnections can sometimes obscure vulnerabilities. Azure Chaos Studio is a set of cloud-native tools designed explicitly for Azure environments, seamlessly integrating, scaling, and providing insights directly within the Azure ecosystem. When paired with Gremlin — a widely used chaos engineering platform — organizations can craft thorough chaos engineering strategies that enhance system reliability, security, and operational performance. This blog will discuss the architecture, practical setup steps, scripts, and validation techniques, all closely aligned with the principles outlined in Azure’s Well-Architected Framework. Through real examples and tested scripts, you’ll discover how to leverage the power of controlled chaos to build resilient and dependable cloud solutions. ...

July 1, 2025 · 14 min · 2850 words · Jurgen Allewijn

Stay up to date

Practical insights on Azure, Kubernetes, cloud security, and digital sovereignty. No spam—just occasional technical deep dives and lessons from the field.