Azure Kubernetes Chronicles 11: Governing the Chaos

Azure Kubernetes Chronicles 11: Governing the Chaos Unifying identity, policy, networking, and observability across clouds and edge This article is part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. Governance pain points By the time enterprises have stretched Kubernetes across Azure, AWS, and the edge, the real problem is no longer the technology itself. It is governance. What began as a strategy to increase resilience and satisfy compliance quickly turns into a patchwork of identity systems, policy frameworks, networking models, and monitoring stacks. The result is fragmentation. Platform teams are left trying to stitch together three or more worlds, often with tools that were never designed to coexist. ...

October 21, 2025 · 5 min · 987 words · Jurgen Allewijn

Azure Kubernetes Chronicles 10: Kubernetes at the Edge with k3s

Azure Kubernetes Chronicles 10: Kubernetes at the Edge with k3s From Raspberry Pi retail stores to 5G towers — the hidden force reshaping enterprise IT This article is part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. When most people think of Kubernetes, they imagine large clusters humming inside hyperscale cloud regions, backed by the weight of Azure, AWS, or Google. However, the future of Kubernetes is increasingly not limited to vast data centers, but also extends to much smaller, more distributed locations, such as retail stores, factory floors, hospital wards, or 5G towers. At the core of this movement is k3s, a lightweight Kubernetes distribution that is small enough to run on a Raspberry Pi but robust enough to support enterprise workloads. ...

October 13, 2025 · 5 min · 932 words · Jurgen Allewijn

Azure Kubernetes Security Demystified: From Nodes to Pods

Azure Kubernetes Security Demystified: From Nodes to Pods Introduction Kubernetes has become the standard for hosting containerized applications, with Azure Kubernetes Service (AKS) being one of the most popular managed options. AKS simplifies management by handling the control plane, but securing the environment remains the customer’s responsibility. The shared responsibility model requires you to focus on strengthening worker nodes, controlling cluster access, and ensuring that workloads and pods operate with the least privileges. Security in Kubernetes involves multiple layers. The base layer is the host security of the virtual machines in the node pools. Next is the cluster layer, where identity, networking, and governance must be carefully established and maintained. At the top, securing pods and containers that run your business logic is crucial to prevent privilege escalation or unauthorized communication. This approach, known as “defense in depth,” emphasizes addressing security across various boundaries instead of relying on a single tool or configuration for full protection. ...

October 6, 2025 · 10 min · 1927 words · Jurgen Allewijn

Azure Kubernetes Chronicles 9: EKS in the Enterprise

Why Amazon’s Kubernetes service is a compliance lever, not just duplication This article is part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. Whenever companies discuss Kubernetes in Azure, AKS naturally comes up because it’s the go-to managed service for those within Microsoft’s ecosystem. However, across Europe, another name is gaining attention: Amazon Elastic Kubernetes Service, or EKS. For many organizations, EKS isn’t just another option; it’s become a vital part of their strategic planning. ...

October 1, 2025 · 4 min · 847 words · Jurgen Allewijn

Azure Kubernetes Chronicles 8: Fleet in Focus

Azure Kubernetes Chronicles 8: Fleet in Focus Azure’s multi-cluster powerhouse — and where it falls short This article is part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. When Microsoft introduced Azure Kubernetes Fleet Manager, it was met with both excitement and curiosity. For years, platform teams running multiple AKS clusters had been piecing together governance with scripts, policies, and half-baked federation approaches. Fleet arrived with the promise of simplification: a central way to govern clusters, propagate policies, and even distribute workloads across Azure regions. ...

September 24, 2025 · 4 min · 793 words · Jurgen Allewijn

Azure Kubernetes Chronicles 7: The Multi-Cluster Reality

From the dream of one perfect cluster to the messy truth of enterprise sprawl This episode is part of the Azure Kubernetes Chronicles: Multi-Cluster Edition. Read the series introduction here. When Kubernetes first entered the enterprise, many platform teams envisioned a single, perfect cluster; a hub where all workloads could reside, scale smoothly, and be governed consistently. The reality turned out very different. Today, almost no enterprise runs just one cluster. Instead, organizations find themselves managing multiple clusters scattered across regions, cloud providers, and even edge sites. This isn’t random chaos; it’s the result of regulatory demands, business continuity strategies, performance requirements, and the rise of edge computing. ...

September 18, 2025 · 5 min · 956 words · Jurgen Allewijn

Azure Kubernetes Chronicles: Multi-Cluster Edition

From Fleet to Edge — navigating Kubernetes across clouds and continents When Kubernetes first entered the enterprise, many architects imagined a single, perfect cluster: one hub for all workloads, scalable, resilient, and secure. Reality had other plans. Enterprises today run multiple clusters across regions, providers, and even at the edge: • AKS in Azure for mainline production. • EKS in AWS to meet regulatory or resilience mandates. • k3s clusters on Raspberry Pi or NUCs powering retail stores, factories, and hospitals. ...

September 12, 2025 · 3 min · 487 words · Jurgen Allewijn

Azure Kubernetes Chronicles 6:

Introduction: Why Centralized Management of AKS Clusters Matters Kubernetes adoption in enterprises has skyrocketed. What begins as a single proof-of-concept cluster often grows into dozens across various teams, environments, and regions. For organizations using Azure Kubernetes Service (AKS), this growth is even more common: different business units create clusters for their workloads, data residency rules require data to stay in specific locations, and production systems need failover capabilities across regions. ...

September 3, 2025 · 19 min · 3972 words · Jurgen Allewijn

Harnessing Chaos: Implementing Chaos Engineering with Azure Chaos Studio and Gremlin on AKS

Harnessing Chaos: Implementing Chaos Engineering with Azure Chaos Studio and Gremlin on AKS Chaos Engineering is a crucial practice for modern cloud operations, enabling teams to identify hidden weaknesses and potential failures in complex systems before they become a problem. By deliberately causing failures in a controlled setting, you can observe how your system responds, measure its resilience, and ultimately strengthen its robustness. This practice really stands out in cloud-native environments like Azure Kubernetes Service (AKS), where the details and interconnections can sometimes obscure vulnerabilities. Azure Chaos Studio is a set of cloud-native tools designed explicitly for Azure environments, seamlessly integrating, scaling, and providing insights directly within the Azure ecosystem. When paired with Gremlin — a widely used chaos engineering platform — organizations can craft thorough chaos engineering strategies that enhance system reliability, security, and operational performance. This blog will discuss the architecture, practical setup steps, scripts, and validation techniques, all closely aligned with the principles outlined in Azure’s Well-Architected Framework. Through real examples and tested scripts, you’ll discover how to leverage the power of controlled chaos to build resilient and dependable cloud solutions. ...

July 1, 2025 · 14 min · 2850 words · Jurgen Allewijn

Azure Kubernetes Chronicles part 5:

Azure Kubernetes Chronicles part 5: Autoscaling with KEDA Autoscaling is a transformative approach for modern cloud-native application architectures, particularly within Kubernetes and microservices environments. As the adoption of these technologies accelerates, implementing automated workload adjustments based on real-time demand becomes imperative. This capability enhances user experience and ensures continuous high availability and cost efficiency. Consider the diverse applications: whether deploying a customer-facing web application, processing extensive data sets, or orchestrating backend task queues, the proficiency in automating workload scaling is essential for operational success and resource optimization. ...

May 7, 2025 · 19 min · 3921 words · Jurgen Allewijn

Stay up to date

Practical insights on Azure, Kubernetes, cloud security, and digital sovereignty. No spam—just occasional technical deep dives and lessons from the field.