msandbu

Using Azure Arc to securely connect to Kubernetes Clusters

One of the new capabilities that Microsoft has introduced for Azure Arc is something called Cluster Connect for Kubernetes, which allows us to securely connect to any Kubernetes cluster that is linked to Azure Arc. However this requires that your Kubernetes Cluster is already linked up to Azure Arc, which you can read more about …

Using Azure Arc to securely connect to Kubernetes Clusters Read More »

Getting started with Azure Defender and Azure Monitor for Kubernetes using Azure Arc

As part of Azure Arc, Microsoft provides integration with Kubernetes to provide a couple of features. Connect Kubernetes running outside of Azure for inventory, grouping, and tagging. Deploy applications and apply configuration using GitOps-based configuration management. View and monitor your clusters using Azure Monitor for containers. Enforce threat protection using Azure Defender for Kubernetes. Apply …

Getting started with Azure Defender and Azure Monitor for Kubernetes using Azure Arc Read More »

API Management and Azure Application Gateway design

In some customer projects now we been working with implementation of API Management in a Hub-and-spoke architecture where we also have Application Gateway as part of the design for secure exposure of services located in the different spokes and on-premises enviroments. One question that comes up often is, should I have my API endpoints publicly …

API Management and Azure Application Gateway design Read More »

Get started with Kasten for data protection on Azure Kubernetes Service

A while back, Veeam acquired a company called Kasten, which provides backup and disaster recovery capabilities for Kubernetes. Since I’ve been working with Veeam for a while I decided to take a closer look at the capabilities and how to deploy it against Azure Kubernetes Service (AKS). Kasten provides direct integration with different public cloud …

Get started with Kasten for data protection on Azure Kubernetes Service Read More »

What does your hybrid cloud look like? and building a cloud exit plan

With the rise of organizations moving to public cloud, many also need to understand how to build and provide disaster recovery of their services outside of the public cloud vendor. Even with more of the hyperscalers now also providing new hybrid cloud services, what is the difference and what kind of functionality do each of …

What does your hybrid cloud look like? and building a cloud exit plan Read More »

Palo Alto Prisma Cloud vs Azure Cloud Native Features

A while back Palo Alto acquired a company called Red Lock (Now called Prisma Cloud) which provides a Cloud Native Security Platform. You can integrate it with Public Cloud platform such as (Azure, AWS, GCP and Alibaba Cloud) to get overview of Governance, Monitoring and Security of the platform. (I also written about it before –> Palo …

Palo Alto Prisma Cloud vs Azure Cloud Native Features Read More »

SASE – The next generation of services we need to protect the mobile workspace?

SASE …. or Secure Access Service Edge is a term coined by Gartner and is about providing the next generation of security and optimized network access for end-users. When I first starting to read about this, my first thought was, so is this Zero-Trust? but no, it is a combination of multiple features, but Zero-Trust …

SASE – The next generation of services we need to protect the mobile workspace? Read More »

Azure WVD and Shortpath using IKEv2 VPN

Before I’ve written a bit about the Microsoft Windows Virtual Desktop architecture and how it handles traffic flow –> Windows Virtual Desktop Traffic Flow and GPU Workloads | Marius Sandbu (msandbu.org) A While back, Microsoft also introduced a new feature called WVD ShortPath which essentially allows the client to do a direct connection to the Session …

Azure WVD and Shortpath using IKEv2 VPN Read More »

Scroll to Top