Skip to content
Azure · AKS

Running AKS, without the surprises.

Azure Kubernetes Service is easy to start and full of decisions you can't walk back. These are the field notes, long-form articles and short, tactical posts, organized by the questions you'll actually face in production.

Fundamentals

The managed boundary, tenancy, and how AKS actually fits together.

AKS Fundamentals1 min read

AKS vs EKS vs GKE: The Honest Differences That Matter

The managed-Kubernetes comparison tables miss the point. The Kubernetes is the same everywhere. What differs is the cloud it's wired into, and that's the actual decision.

AzureKubernetesCloud
Jun 18, 2026Read
AKS Fundamentals2 min read

One Big Cluster or Many: The AKS Tenancy Decision

Consolidate into one cluster and you fight noisy neighbors and blast radius. Split into many and you drown in upgrade toil. The right answer isn't a number. It's an isolation boundary you can defend.

AzureKubernetesArchitecture
May 19, 2026Read
AKS Fundamentals1 min read

What 'Managed' Actually Means in AKS

Managed Kubernetes doesn't mean Azure runs your cluster. It means Azure runs the part you'd most like to ignore, and quietly hands you the rest.

AzureKubernetes
Jan 9, 2026Read

Networking

CNI choices, ingress, egress, and private clusters.

AKS Networking1 min read

Ingress on AKS: App Gateway, NGINX, or Both?

The AKS ingress debate isn't about which is better. It's about where you want your routing logic to live: in Azure, or in your cluster.

AzureKubernetes
Feb 12, 2026Read
AKS Networking1 min read

Why Your AKS Pod Can't Reach the Internet

A pod that can't curl the outside world is an AKS rite of passage. It's almost always one of three things, and none of them are the pod's fault.

AzureKubernetes
Jan 22, 2026Read

Security

Identity, RBAC, and shrinking the attack surface.

AKS Security1 min read

Private AKS Clusters: What You Gain and What Breaks

A private cluster takes your API server off the public internet, a real security win that quietly breaks half your tooling. Go in knowing both halves.

AzureKubernetes
Mar 5, 2026Read
AKS Security2 min read

Workload Identity: Killing the Last Long-Lived Secret in AKS

Every static credential in your cluster is a small bet that it never leaks. Workload Identity lets your AKS pods talk to Azure with no secret to leak at all, and the migration is more about discipline than difficulty.

AzureKubernetesPlatform Engineering
Feb 24, 2026Read
AKS Security1 min read

Stop Using the AKS Admin Kubeconfig

`az aks get-credentials --admin` is the handiest command in AKS and the one most likely to end up in an incident report. There's a better default, and switching costs nothing.

AzureKubernetes
Feb 19, 2026Read

Scaling & Cost

Node pools, autoscaling, spot, and the bill nobody forecast.

AKS Scaling & Cost2 min read

Node Pools Are an Architecture, Not a Setting

Most AKS clusters run every workload on one undifferentiated pool of VMs and call it simple. It isn't simple. It's expensive, fragile, and one bad neighbor away from an outage. Node pools are where workload intent becomes infrastructure.

AzureKubernetesPlatform Engineering
Jun 9, 2026Read
AKS Scaling & Cost1 min read

Spot Node Pools: Cheap Compute With a Catch

Spot nodes can cut a chunk of your AKS bill for the right workloads. The catch is in the word 'right': put the wrong thing there and you've architected a flaky outage.

AzureKubernetes
Mar 26, 2026Read

Day-2 Ops

Upgrades, disruption budgets, and the dashboards that matter.

AKS Day-2 Ops2 min read

The First Three Dashboards Every AKS Cluster Needs

You can drown a new AKS cluster in metrics on day one. Resist. Three dashboards answer the questions you'll actually have at 2 a.m. Start there, add the rest when you miss them.

AzureKubernetesPlatform Engineering
Jun 11, 2026Read
AKS Day-2 Ops1 min read

Your AKS Cluster Is One Version From a Bad Weekend

Kubernetes versions age out on a schedule, and AKS only supports a rolling window. Fall off the back of it and you're running unsupported infrastructure under production, usually discovered at the worst moment.

AzureKubernetes
Apr 16, 2026Read

GitOps & CI/CD

Pull-based delivery with Flux, Argo, and Kustomize.

AKS GitOps & CI/CD1 min read

Kustomize Over Helm for Cluster Config? Sometimes.

Helm became the default for everything, including jobs it's bad at. For your own cluster configuration, Kustomize is often the calmer choice, and knowing when is the whole skill.

AzureKubernetes
May 28, 2026Read
AKS GitOps & CI/CD1 min read

Flux on AKS in Twenty Minutes

GitOps sounds like a platform project. Getting your first Flux reconciliation running on AKS is closer to a coffee break, and it changes how you think about deploys immediately.

AzureKubernetes
May 14, 2026Read
AKS GitOps & CI/CD3 min read

GitOps on AKS: Why Your Cluster Should Pull, Not Be Pushed

CI pipelines that push kubectl into your cluster feel fast and quietly rot your reliability. GitOps inverts the arrow: the cluster pulls its own desired state, and 'what's deployed' stops being a mystery.

AzureKubernetesPlatform Engineering
Apr 28, 2026Read

The Clarity Brief

Every other Tuesday · unsubscribe anytime

A short, high-signal briefing on architecture, AI, observability, and engineering leadership, written to make hard things clear.

Topics you care about

We respect your inbox. Your email is used only to send the newsletter and is never sold or shared.