Spotlight

Taming Runaway AKS NAT Gateway Costs: How We Used Kyverno to Redirect MCR Image Pulls

chitender kumar

This article shows how to reduce AKS NAT Gateway costs by redirecting Microsoft Container Registry pulls through Azure Container Registry using Kyverno policies.

More articles →

Tools and utilities

More projects →

Events starting soon

Discover more events onn Kube Events →

We Broke Our EKS Cluster Autoscaler with the AL2023 Migration
We Broke Our EKS Cluster Autoscaler with the AL2023 Migration

Dilshan Wijesooriya, Senior Cloud Engineer, discusses a real incident where migrating EKS nodes to AL2023 caused the cluster autoscaler to lose AWS permissions silently.

You will learn:

  • Why AL2023 blocks pod access to instance metadata by default, breaking components that relied on node IAM roles (like cluster autoscaler, external-DNS, and AWS Load Balancer Controller)
  • How to implement IRSA correctly by configuring IAM roles, Kubernetes service accounts, and OIDC trust relationships, and why both AWS IAM and Kubernetes RBAC must be configured independently
  • The recommended migration strategy: move critical system components to IRSA before changing AMIs, test aggressively in non-production, and decouple identity changes from OS upgrades
  • How to audit which pods currently rely on node roles and clean up legacy IAM permissions to reduce attack surface after migration

Learn from production

More case studies →

Matching jobs

    • DevOps Engineer with Captivation Software

    • Salary: $130K to $270K a year

    • Location: remote from

    • Tech stack: Kubernetes, Docker, Shell, Python, Java, Javascript, Spark, Gitlab, Ansible, Prometheus

    • Platform Engineer with Twist Bioscience

    • Salary: $205.9K to $231K a year

    • Location: based in the office in South San Francisco, CA, USA

    • Tech stack: Kubernetes, AWS, Docker, Typescript, Java, Python, Javascript, Jenkins, Spinnaker

    • Software Architect with Toshiba Global Commerce Solutions - External

    • Salary: $250K to $280K a year

    • Location: remote from

    • Tech stack: Kubernetes, Azure, Docker, SQL, Java, Typescript, Python, Javascript, ARM templates, Terraform

    • Software Architect with Toshiba Global Commerce Solutions - External

    • Salary: $210K to $240K a year

    • Location: remote from

    • Tech stack: Kubernetes, Azure, Docker, SQL, Java, Typescript, Javascript, Python, Go

    • Software Engineer with Coconut Software

    • Salary: $80K to $110K a year

    • Location: remote from

    • Tech stack: Kubernetes, AWS, Docker, SQL, Javascript, PHP, PostgreSQL

Discover more Kubernetes jobs on Kube Careers →

Subscribe to Learn Kubernetes Weekly

Trusted by 77K engineers. Delivered 166 issues and counting.

or subscribe via

Build something

More tutorials →

Call for Papers closing soon

  1. 6

    days

    Observability Summit North America

    The Call For Paper is open until 26 January 2026 at GMT-5. More info →
    • Location: Minneapolis, MN, USA

    • In-person conference organized by Linux Foundation.

    • The conference starts on the 22 May 2026.

    • Apply here
  2. 11

    days

    Devopsdays Zurich

    The Call For Paper is open until 31 January 2026 at GMT-5. More info →
    • Location: Zurich, CH

    • In-person conference organized by Devopsdays.

    • The conference starts on the 6 May 2026.

    • Apply here
  3. 11

    days

    Devopsdays Prague

    The Call For Paper is open until 31 January 2026 at GMT-5. More info →
    • Location: Prague, CZ

    • In-person conference organized by Devopsdays.

    • The conference starts on the 29 April 2026.

    • Apply here
  4. 11

    days

    Devopsdays Copenhagen

    The Call For Paper is open until 31 January 2026 at GMT-5. More info →
    • Location: Copenhagen, DK

    • In-person conference organized by Devopsdays.

    • The conference starts on the 28 April 2026.

    • Apply here
  5. 12

    days

    KubeCon + CloudNativeCon India 2026

    The Call For Paper is open until 1 February 2026 at GMT-5. More info →
    • Location: Mumbai, IN

    • In-person conference organized by CNCF.

    • The conference starts on the 19 June 2026.

    • Apply here
  6. 13

    days

    Web Days Convention

    The Call For Paper is open until 2 February 2026 at GMT-5. More info →
    • Location: Aix-en-Provence, FR

    • In-person conference organized by Web Days.

    • The conference starts on the 6 February 2026.

    • Apply here
  7. 16

    days

    Cloud & AI Infrastructure London 2026

    The Call For Paper is open until 5 February 2026 at GMT-5. More info →
    • Location: London, UK

    • In-person conference organized by CloserStill.

    • The conference starts on the 5 March 2026.

    • Apply here

Thanks to our sponsors who make Kube Today possible

Find out more about being a sponsor →

More articles

Even more articles →