Spotlight

Building Production-Grade Micro services on Azure Kubernetes

Dilip Kola

This article explains how to build cost-efficient microservices on AKS by classifying state as irreplaceable or regenerable, using managed PostgreSQL for critical data while self-hosting Redis, RabbitMQ, and observability tools in Kubernetes.

More articles →

Tools and utilities

  • kubecfg: kubeconfig CLI tool

    kubecfg is a CLI tool for managing Kubernetes kubeconfig files with fast context switching, namespace management, and multi-config merging through an interactive terminal UI.

  • CronJob Guardian: monitoring operator

    CronJob Guardian monitors Kubernetes CronJobs with dead-man's switch detection, SLA tracking for success rates and duration regressions, intelligent alerting via Slack/PagerDuty/webhook/email, and a built-in web dashboard with charts and metrics export.

  • Forecastle: dashboard control plane

    Forecastle is a control panel which dynamically discovers and provides a launchpad to access applications deployed on Kubernetes.

  • Benchmark Suite for Gateway API Implementations

    This tool provides a comprehensive test suite to evaluate real-world behavior (latency, scale, route propagation, traffic) of Kubernetes Gateway API implementations, beyond basic conformance.

  • Infralens: eBPF observability

    InfraLens is a zero-instrumentation observability tool that uses eBPF to automatically discover and visualize service-to-service communication in Kubernetes clusters without requiring code changes or sidecars.

More projects →

Events starting soon

Discover more events onn Kube Events →

That Time I Found a Service Account Token in my Log Files
That Time I Found a Service Account Token in my Log Files

You're integrating HashiCorp Vault into your Kubernetes cluster and adding a temporary debug log line to check whether the ServiceAccount token is being passed correctly. Three months later, that log line is still in production — and the token it prints has a 1-year expiry with no audience restrictions.

Vincent von Büren, a platform engineer at ipt in Switzerland, lived through exactly this incident. In this episode, he breaks down why default Kubernetes ServiceAccount tokens are a quiet security risk hiding in plain sight.

You will learn:

  • What's actually inside a Kubernetes ServiceAccount JWT (issuer, subject, audience, and expiry)
  • Why tokens with no audience scoping enable replay attacks across internal and external systems
  • How Vault's Kubernetes auth method and JWT auth method compare, and when to choose each
  • What projected tokens are, why they dramatically reduce blast radius, and what's holding teams back from using them
  • Practical steps for auditing which pods actually need API access and disabling auto-mounting everywhere else

Learn from production

More case studies →

Matching jobs

    • Data Engineer with Infosys Consulting Europe

    • Salary: PLN 10.39K to PLN 594K a year

    • Location: remote from

    • Tech stack: Kubernetes, AWS, Azure, GCP, Docker, SQL, SQL Server, Kafka, InfluxDB

Discover more Kubernetes jobs on Kube Careers →

Subscribe to Learn Kubernetes Weekly

Trusted by 77K engineers. Delivered 176 issues and counting.

or subscribe via

Build something

More tutorials →

Call for Papers closing soon

  1. 0

    days

    Kubernetes Community Days Czech & Slovak - Prague 2026

    The Call For Paper is open until 1 April 2026 at GMT-4. More info →
    • Location: Bratislava, SK

    • In-person conference organized by KCD Czech & Slovak.

    • The conference starts on the 21 May 2026.

    • Apply here
  2. 0

    days

    Devopsdays Kansas City

    The Call For Paper is open until 1 April 2026 at GMT-4. More info →
    • Location: Kansas City, MO, USA

    • In-person conference organized by Devopsdays.

    • The conference starts on the 28 May 2026.

    • Apply here
  3. 7

    days

    IaCConf 2026

    The Call For Paper is open until 7 April 2026 at GMT-4. More info →
    • This is a virtual event

    • Online conference organized by Spacelift.

    • The conference starts on the 14 May 2026.

    • Apply here
  4. 8

    days

    SREday Barcelona 2026

    The Call For Paper is open until 8 April 2026 at GMT-4. More info →
    • Location: Barcelona, ES

    • In-person conference organized by SREday.

    • The conference starts on the 20 April 2026.

    • Apply here
  5. 12

    days

    SREday Austin 2026

    The Call For Paper is open until 12 April 2026 at GMT-4. More info →
    • Location: Austin, TX, USA

    • In-person conference organized by SREday.

    • The conference starts on the 6 May 2026.

    • Apply here
  6. 19

    days

    Open Conf 2026

    The Call For Paper is open until 19 April 2026 at GMT-4. More info →
    • Location: Athens, GR

    • In-person conference organized by Open Conf.

    • The conference starts on the 21 November 2026.

    • Apply here
  7. 21

    days

    SREday Munich 2026

    The Call For Paper is open until 21 April 2026 at GMT-4. More info →
    • Location: Munich, DE

    • In-person conference organized by SREday.

    • The conference starts on the 15 May 2026.

    • Apply here

Thanks to our sponsors who make Kube Today possible

Find out more about being a sponsor →

More articles

Even more articles →