⚠️ Azure Key Vault + AKS integration gotchas you NEED to know.

From identity config to network policies — here's how to fix the most common integration failures.

#Azure #AKS #KeyVault #Kubernetes #CloudSecurity
🔗 https://devopstales.github.io/cloud/azure-keyvault-aks/

https://github.com/TarasKovalenko/AzVault

AzVault is a cross-platform desktop Azure Key Vault explorer

#azure #keyvault #azurekeyvault

GitHub - TarasKovalenko/AzVault: AzVault is a cross-platform desktop Azure Key Vault explorer

AzVault is a cross-platform desktop Azure Key Vault explorer - GitHub - TarasKovalenko/AzVault: AzVault is a cross-platform desktop Azure Key Vault explorer

GitHub
Our company is setting up a #HashiCorp #Vault cluster in #Azure. It's currently set up to use #KeyVault auto-unseal.
Our SOP for restoring the cluster in case of data corruption or failure is to shut down Vault and delete the data on all the instances, reinitialize on one instance, download a snapshot from Azure Storage to that instance, restore that snapshot with quorum forcing, and bring the other instances back online.
#SRE #DevOps #DevSecOps (1/3)

Updated: Azure Durable Functions and .NET 10

https://github.com/damienbod/AzureDurableFunctions

Now using .NET 10, Azurite, isolated model V4 Functions, github actions

#azure #net10 #dotnet #workflows #saas #functions #business #process #github #keyvault #secrets

GitHub - damienbod/AzureDurableFunctions: Use Azure Durable functions for workflows, business processing

Use Azure Durable functions for workflows, business processing - damienbod/AzureDurableFunctions

GitHub
312: Azure Firewall Finally Learns to Spell (FQDN Edition) "This was not the secret you were looking for..." – Azure, after leaking your KeyVault like a broken Death Star exhaust port. Trust in the cloud, you must. But audit your logs, you should. #thecloudpod #KeyVault #episode312 https://www.thecloudpod.net/?p=21154
312: Azure Firewall Finally Learns to Spell (FQDN Edition) "This was not the secret you were looking for..." – Azure, after leaking your KeyVault like a broken Death Star exhaust port. Trust in the cloud, you must. But audit your logs, you should. #thecloudpod #KeyVault #episode312 https://www.thecloudpod.net/?p=21154

If you use account keys or connection strings to access Azure resources, there is a better way!

User Assigned Managed Identities (#UAMI) are more secure and less work to "manage", because you really don't have to maintain them once they are setup.

In this demo we setup connectivity from an #AppService to an Azure #KeyVault and #StorageAccount using UAMI's, showing the .Net code changes required to successfully connect to multiple resources. It isn't difficult!

https://www.youtube.com/watch?v=1W1-1vRRId8

Connect to an Azure service via User Assigned Managed Identities

YouTube

So I've been trying to figure out the answer to a theoretical problem: what would I do if I was in a foreign country and had my phone and laptop seized / stolen?

I'm not too concerned about the shit on them, but nowadays everything is 2FA. Even my password manager needs second factor auth on a new device, and the second factor is email which... You guessed it needs a second factor. I feel like I'm one lost device from disaster.

How do you go from zero to re-equipped with your logins without access to your own desk and devices?

Would it be insane to post an encrypted binary blob in like a public git repo? Random webpage? What encryption would be sufficient to confidentiality drop an entire password vault, ssh keys, etc into a public space?

(Encryption not my area of expertise)

#2fa #encryption #passwords #keyvault #multifactor #backups #cybersecurity

【Azure】App Service 証明書の購入で注意すべき点 - Qiita

0. はじめに本記事ではApp Service 証明書の購入時の注意点をご紹介します。Azure環境でFront DoorやApplication Gatewayなどでカスタムドメインを利用する…

Qiita
Utilizing Key Vault in Azure Kubernetes Service

Janne Mattila’s blog | From programmer to programmer – Programming just for the fun of it

Janne Mattila