Azure AKS: diagnose outbound SNAT exhaustion before adding a NAT Gateway
A production runbook for separating DNS, remote dependency, network policy, conntrack and Azure SNAT pressure on AKS before changing the cluster outbound path.
Read article
Tag
13 articles connected to this technical signal.
A production runbook for separating DNS, remote dependency, network policy, conntrack and Azure SNAT pressure on AKS before changing the cluster outbound path.
Read articleA production runbook for separating noisy metrics, miscalibrated requests, slow startup and node capacity before changing Horizontal Pod Autoscaler bounds on AKS.
Read articleA production runbook for separating pod resolver, CoreDNS, service path, upstream DNS and node-specific failures before restarting or rolling back AKS DNS.
Read articleA production runbook for proving whether AKS traffic is denied by Kubernetes or Cilium policy, using selectors, both flow directions, DNS checks, bounded evidence and rollback.
Read articleA production runbook for locating an AKS rollout stalled across Deployment, ReplicaSet, scheduling, image and readiness, then resuming or returning to a known revision with explicit stop conditions.
Read articleA production runbook for isolating a Microsoft Entra Workload ID failure across the pod, ServiceAccount, webhook, OIDC token, managed identity and RBAC, then validating or rolling back without a client secret.
Read articleA production runbook for mapping an ACR vulnerability signal to AKS pods, freezing promotion, returning to a known digest, validating the rollout, then retaining or deleting the suspect image.
Read articleA production runbook for locating telemetry loss across receivers, processors, queues and exporters, then validating capacity changes or rolling back safely.
Read articleA production runbook for diagnosing an AKS drain blocked by a PodDisruptionBudget, recovering disruption headroom, fixing capacity or readiness, then validating or postponing the upgrade without removing safeguards.
Read articleA production runbook for qualifying an Azure API Management self-hosted gateway with configuration sync, token or Workload Identity, Kubernetes, logs, backend reachability, validation and rollback before moving traffic.
Read articleBuild an operational runbook for AKS private ingress failures by separating DNS, Application Gateway, ingress controller, Kubernetes service endpoints, pod readiness and rollback evidence.
Read articleA short query to read ingress controller and application logs together when a private AKS route returns 502, timeouts or no endpoints.
Read articleA production-oriented note on AWX with the operator, including namespace design, persistence, exposure, execution environments, validation, backups, and the failure modes that appear after the first successful login.
Read article