Advertisement · 728 × 90

Posts by Joey Chen

Preview
Set up volumes accessing cross-tenant Azure Storage without account access keys in Azure Kubernetes Service - Joey Chen Learn how to create Kubernetes volumes with Azure storage in different tenant without setting up account access key in Azure Kubernetes Service (AKS).

👉 New post: Access Azure Storage across tenants in AKS—no access keys needed 🚀
Securely mount K8s volumes via BlobFuse (Workload Identity) or NFS for Azure Fileshare/Blob. Step-by-step guide with examples!

🔗 Link: blog.joeyc.dev/posts/aks-no...

#Azure #AKS #Kubernetes #DevOps #CloudSecurity

1 month ago 0 0 0 0
Access cross-tenant resources via workload identity on Azure Kubernetes Service - Joey Chen Learn how to access resources in different tenant by using Microsoft Entra Workload ID on Azure Kubernetes Service (AKS).

👉 New post: Access cross-tenant resources via workload identity on Azure Kubernetes Service 🚀

In some cases, you need to access resources in different tenant from AKS. A cross-tenant authentication and authorization process is required.

🔗 Link: blog.joeyc.dev/posts/aks-ac...

#Azure #AKS #AAD

11 months ago 0 0 0 0
Post image

My new Azure trial subscription.

11 months ago 0 0 0 0
Post image

Finally started using treadmill after leaving job.

#life

11 months ago 0 0 0 0

Thanks for blessing from Azure Vietnam AKS (Container) team.

Hope everyone will be "forever young".

#Azure

1 year ago 0 0 0 0

Today is special.
Chinese Azure CSS team gets dismissed today, due to EO 14117.
I got my compensation today.

Time to start a new life.

Goodbye, Azure.

#Azure

1 year ago 0 0 0 0
Preview
Configure an application to trust a managed identity (preview) - Microsoft Entra Workload ID Learn how to configure an application to trust a managed identity in Microsoft Entra ID.

This article is using user-assigned managed identity.

However, to make it work, the following prerequisites need to be met:
1. An app registration
2. App registration needs to be in same tenant with managed identity

(Src: learn.microsoft.com/en-us/entra/...)

1 year ago 0 0 0 0

I never expected this, honestly. Their outsourcing team cannot even set the DNS record properly. It was disheartening to realize that all my initial complex hypotheses were missing the point when the real issue was this simple but critical network misconfiguration.

1 year ago 0 0 0 0

Then, the root cause is found, unexpectedly: the old Container Registry was working because someone had manually added it to the Windows host file. Meantime, the new Container Registry failed because it had no entry in the host file.

1 year ago 0 0 1 0

My initial thought was that there might be a problem with the private link or endpoint in the hub VNet. I tried to locate it, but only to hit a dead end as I couldn't find the hub VNet.
We still engage together in a remote session after 3 days.

1 year ago 0 0 1 0
Advertisement

One old story about how it was working under a dysfunctional team.

It all started with a gov project that had been outsourced to a vendor team. When I took over the case, their old Container Registry worked fine, but new one was not functioning on their on-premise devices.

#Azure #DevOps #Network

1 year ago 0 0 2 0

I will continue to make minor contributions, but will no longer come up with original full AKS tutorials/how-to to Microsoft Learn.

I am very dejected today. This is not a fair or square for me to remove my credit (and add their owns) but take my content.

There is no respect to me.

#Azure #AKS

1 year ago 0 0 0 0
Post image

My daily mailbox.

"Issue needing attention of @Azure/aks-leads"

"This issue has been automatically marked as stale because it has not had any activity for 14 days. It will be closed if no further activity occurs within 7 days of this comment."

#Azure #AKS #Github

1 year ago 0 0 0 0

- Is this ending bit actually worth it?
- I'm sorry. It's terminal, right?

1 year ago 1 0 0 0