Add Microsoft Entra ID OIDC SSO to Harbor on AKS
Configure Harbor on AKS for Microsoft Entra ID single sign-on with Terraform-managed OIDC groups, role mapping, and a secure break-glass path.
Practical guides and insights on cloud infrastructure, DevOps, and modern engineering practices.
Configure Harbor on AKS for Microsoft Entra ID single sign-on with Terraform-managed OIDC groups, role mapping, and a secure break-glass path.
Provision an AKS cluster with Terraform and install Harbor behind Traefik, with cert-manager issuing Let's Encrypt certificates through Azure DNS DNS-01 and Workload Identity.
Forward Harbor audit events into Azure Log Analytics with a small Fluent Bit syslog bridge, reusing Container Insights so no new Azure resources are required.
What happens when you deploy AKS with networkPlugin: none, when customer-managed Cilium is justified over Azure CNI Powered by Cilium, and how to operate its eBPF dataplane, policies, and Hubble observability.
Collect Harbor 2.15 metrics with an Azure-specific ServiceMonitor, verify ingestion in Azure Monitor managed Prometheus, and build a Harbor dashboard in Azure Managed Grafana.
What Advanced Container Networking Services (ACNS) actually gives you on AKS — eBPF-powered network observability with Hubble, domain-based egress filtering, and HTTP-aware Layer 7 policies — explained through a hands-on demo you can run yourself.