Spotlight

Azure Kubernetes Service Deep Dive Into Azure CNI Pod Subnet

Tobias Massoth

This article explains the trade-offs of Azure CNI Pod Subnet in AKS with two IP allocation modes:

  • Dynamic IP Allocation, where blocks of 16 IPs are assigned dynamically
  • Static Block Allocation, where all IPs are reserved upfront.

More articles →

Tools and utilities

  • Kubernetes Orphaned Resources Finder

    Kor is a tool to discover unused Kubernetes resources.

  • Argo CD Diff Preview

    Argo CD Diff Preview is a tool that renders the diff between two branches in a Git repository, providing a clear and concise view of the changes between two branches, similar to Atlantis for Terraform.

  • Flux Operator: simplified Flux

    flux-operator simplifies the configuration of Flux multi-tenancy lockdown, sharding, horizontal and vertical scaling, persistent storage, and allows fine-tuning the Flux controllers with Kustomize patches.

  • IncidentFox: AI Incident Response

    IncidentFox automates incident investigation with AI agents using 178+ tools for Kubernetes, AWS, and Grafana, featuring RAPTOR knowledge base for runbooks, alert correlation reducing noise by 85-95%, and Slack/GitHub/PagerDuty integrations.

  • KCL: constraint-based language

    KCL allows developers to create modular, scalable, and stable configurations.

More projects →

Events starting soon

Discover more events onn Kube Events →

That Time I Found a Service Account Token in my Log Files
That Time I Found a Service Account Token in my Log Files

You're integrating HashiCorp Vault into your Kubernetes cluster and adding a temporary debug log line to check whether the ServiceAccount token is being passed correctly. Three months later, that log line is still in production — and the token it prints has a 1-year expiry with no audience restrictions.

Vincent von Büren, a platform engineer at ipt in Switzerland, lived through exactly this incident. In this episode, he breaks down why default Kubernetes ServiceAccount tokens are a quiet security risk hiding in plain sight.

You will learn:

  • What's actually inside a Kubernetes ServiceAccount JWT (issuer, subject, audience, and expiry)
  • Why tokens with no audience scoping enable replay attacks across internal and external systems
  • How Vault's Kubernetes auth method and JWT auth method compare, and when to choose each
  • What projected tokens are, why they dramatically reduce blast radius, and what's holding teams back from using them
  • Practical steps for auditing which pods actually need API access and disabling auto-mounting everywhere else

Learn from production

More case studies →

Matching jobs

    • Data Engineer with Clarity Innovations

    • Salary: $26 to $302.5K a year

    • Location: based in the office in Columbia, MD, USA

    • Tech stack: Kubernetes, Groovy, Java, Python

    • Data Engineer with Clarity Innovations

    • Salary: $54K to $286K a year

    • Location: based in the office (and remote from home) in Herndon, VA, USA

    • Tech stack: Kubernetes, Python, SQL

    • DevOps Engineer with AMOL TECHNOLOGIES

    • Salary: $1.08L to $2.75L a year

    • Location: based in the office (and remote from home) in Bengaluru, IN

    • Tech stack: Kubernetes, AWS, Azure, GCP, Helm, ArgoCD, Docker, Go, Powershell, Python

    • DevOps Engineer with Clarity Innovations

    • Salary: $117K to $297K a year

    • Location: based in the office in Herndon, VA, USA

    • Tech stack: Kubernetes, Azure, Helm, ArgoCD, Flux, Docker, Python, Terraform, Ansible, Istio

    • DevOps Engineer with Endava

    • Salary: $90K to $198K a year

    • Location: remote from

    • Tech stack: Kubernetes, AWS, Python, Terraform, Gitlab, Jenkins, Ansible, Puppet

Discover more Kubernetes jobs on Kube Careers →

Subscribe to Learn Kubernetes Weekly

Trusted by 77K engineers. Delivered 177 issues and counting.

or subscribe via

Build something

More tutorials →

Call for Papers closing soon

  1. 5

    days

    IaCConf 2026

    The Call For Paper is open until 7 April 2026 at GMT-4. More info →
    • This is a virtual event

    • Online conference organized by Spacelift.

    • The conference starts on the 14 May 2026.

    • Apply here
  2. 6

    days

    SREday Barcelona 2026

    The Call For Paper is open until 8 April 2026 at GMT-4. More info →
    • Location: Barcelona, ES

    • In-person conference organized by SREday.

    • The conference starts on the 20 April 2026.

    • Apply here
  3. 10

    days

    SREday Austin 2026

    The Call For Paper is open until 12 April 2026 at GMT-4. More info →
    • Location: Austin, TX, USA

    • In-person conference organized by SREday.

    • The conference starts on the 6 May 2026.

    • Apply here
  4. 17

    days

    Open Conf 2026

    The Call For Paper is open until 19 April 2026 at GMT-4. More info →
    • Location: Athens, GR

    • In-person conference organized by Open Conf.

    • The conference starts on the 21 November 2026.

    • Apply here
  5. 19

    days

    SREday Munich 2026

    The Call For Paper is open until 21 April 2026 at GMT-4. More info →
    • Location: Munich, DE

    • In-person conference organized by SREday.

    • The conference starts on the 15 May 2026.

    • Apply here
  6. 19

    days

    CLC26

    The Call For Paper is open until 21 April 2026 at GMT-4. More info →
    • Location: Mannheim, DE

    • In-person conference organized by Rheinwerk Verlag.

    • The conference starts on the 11 November 2026.

    • Apply here
  7. 28

    days

    Tech Fuse Des Moines 2026

    The Call For Paper is open until 30 April 2026 at GMT-4. More info →
    • Location: Des Moines, IA, USA

    • In-person conference organized by Tech Fuse DSM.

    • The conference starts on the 16 October 2026.

    • Apply here

Thanks to our sponsors who make Kube Today possible

Find out more about being a sponsor →

More articles

Even more articles →