Add Microsoft Entra ID OIDC SSO to Harbor on AKS
Configure Harbor on AKS for Microsoft Entra ID single sign-on with Terraform-managed OIDC groups, role mapping, and a secure break-glass path.
Configure Harbor on AKS for Microsoft Entra ID single sign-on with Terraform-managed OIDC groups, role mapping, and a secure break-glass path.
Forward Harbor audit events into Azure Log Analytics with a small Fluent Bit syslog bridge, reusing Container Insights so no new Azure resources are required.
What happens when you deploy AKS with networkPlugin: none, when customer-managed Cilium is justified over Azure CNI Powered by Cilium, and how to operate its eBPF dataplane, policies, and Hubble observability.
What Advanced Container Networking Services (ACNS) actually gives you on AKS — eBPF-powered network observability with Hubble, domain-based egress filtering, and HTTP-aware Layer 7 policies — explained through a hands-on demo you can run yourself.
NGINX Ingress is retired. This guide walks through migrating AKS workloads to the App Routing add-on with Istio-based Gateway API, including GatewayClass, HTTPRoute, TLS from Key Vault, canary traffic splits, and header-based routing.
A complete walkthrough of the Argo CD cluster extension for AKS — what Argo CD is, the components behind it, and how to wire up App Routing ingress, TLS from Key Vault, and Microsoft Entra ID single sign-on with workload identity and group-based RBAC.
A practical walkthrough of wiring open-source Falco to Microsoft Sentinel for real-time Kubernetes runtime security: install, configure, ingest, and investigate threats — all with Infrastructure as Code.