<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Ricardo Martins — Cloud Architecture, Azure, Kubernetes &amp; AI</title>
    <link>https://rmmartins.com/</link>
    <description>Recent content on Ricardo Martins — Cloud Architecture, Azure, Kubernetes &amp; AI</description>
    <image>
      <title>Ricardo Martins — Cloud Architecture, Azure, Kubernetes &amp; AI</title>
      <url>https://rmmartins.com/images/profile.png</url>
      <link>https://rmmartins.com/images/profile.png</link>
    </image>
    <generator>Hugo</generator>
    <language>en-US</language>
    <lastBuildDate>Sun, 09 Aug 2026 22:58:05 -0400</lastBuildDate>
    <atom:link href="https://rmmartins.com/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Building a personal AI assistant on Azure, step by step</title>
      <link>https://rmmartins.com/building-a-personal-ai-assistant-on-azure/</link>
      <pubDate>Mon, 03 Aug 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/building-a-personal-ai-assistant-on-azure/</guid>
      <description>A complete personal AI assistant vertical slice with FastAPI, Azure OpenAI, Azure AI Search, managed identity, approval-gated tools, Container Apps, and Application Insights.</description>
    </item>
    <item>
      <title>Azure AI Foundry: from zero to production</title>
      <link>https://rmmartins.com/azure-ai-foundry-zero-to-production/</link>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://rmmartins.com/azure-ai-foundry-zero-to-production/</guid>
      <description>What I cover when a customer asks how to go from playground to production with Azure AI Foundry: model selection, Standard vs Priority vs PTU, spillover architecture, APIM as AI Gateway, and production checklist.</description>
    </item>
    <item>
      <title>From reactive firefighting to proactive operations: custom skills for Azure SRE Agent</title>
      <link>https://rmmartins.com/azure-sre-agent-proactive-skills/</link>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://rmmartins.com/azure-sre-agent-proactive-skills/</guid>
      <description>How I built an open-source pack of 8 custom skills that transform Azure SRE Agent from reactive incident response to proactive platform engineering.</description>
    </item>
    <item>
      <title>How MCP works: the protocol connecting agents to the world</title>
      <link>https://rmmartins.com/how-mcp-works-the-protocol-connecting-agents-to-the-world/</link>
      <pubDate>Wed, 29 Jul 2026 18:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/how-mcp-works-the-protocol-connecting-agents-to-the-world/</guid>
      <description>A deep dive into MCP&amp;#39;s wire format, JSON-RPC messages, transport layers, capability discovery, and security model, explained for infrastructure engineers who want to understand what&amp;#39;s actually on the wire.</description>
    </item>
    <item>
      <title>Agent Governance on Microsoft Foundry</title>
      <link>https://rmmartins.com/agent-governance-microsoft-foundry/</link>
      <pubDate>Tue, 28 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/agent-governance-microsoft-foundry/</guid>
      <description>How Microsoft Foundry handles identity, RBAC, tool catalogs, and policy enforcement for AI agents at organizational scale.</description>
    </item>
    <item>
      <title>Multi-Agent Orchestration: Correlating AKS and Azure OpenAI</title>
      <link>https://rmmartins.com/multi-agent-orchestration-aks-openai-correlation/</link>
      <pubDate>Tue, 21 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/multi-agent-orchestration-aks-openai-correlation/</guid>
      <description>An orchestrator that combines the AKS diagnostics agent with the token watchdog to answer &amp;#39;did someone deploy something?&amp;#39; automatically.</description>
    </item>
    <item>
      <title>From Script to Agent: Giving the Watchdog Decision Autonomy</title>
      <link>https://rmmartins.com/agentic-watchdog-decision-autonomy-guardrails/</link>
      <pubDate>Tue, 14 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/agentic-watchdog-decision-autonomy-guardrails/</guid>
      <description>Adding a reasoning layer to the 429 watchdog so it can tell a benign batch spike from a runaway agent, with explicit guardrails.</description>
    </item>
    <item>
      <title>Platform Engineering on Azure: governance, observability and security for your IDP (Part 2)</title>
      <link>https://rmmartins.com/platform-engineering-azure-governance-observability-security-part-2/</link>
      <pubDate>Mon, 13 Jul 2026 11:30:00 -0400</pubDate>
      <guid>https://rmmartins.com/platform-engineering-azure-governance-observability-security-part-2/</guid>
      <description>Azure Policy as guardrails, out-of-the-box observability with Managed Grafana, Workload Identity for zero secrets, and golden paths with GitHub Actions.</description>
    </item>
    <item>
      <title>Platform Engineering on Azure: building an Internal Developer Platform with AKS and Bicep (Part 1)</title>
      <link>https://rmmartins.com/platform-engineering-azure-internal-developer-platform-part-1/</link>
      <pubDate>Mon, 13 Jul 2026 11:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/platform-engineering-azure-internal-developer-platform-part-1/</guid>
      <description>Build an IDP on Azure with Dev Center, Deployment Environments, multi-tenant AKS, and Bicep. Self-service provisioning for developers with security and governance.</description>
    </item>
    <item>
      <title>Postmortems on Azure: automation with Azure DevOps and learning metrics (Part 2)</title>
      <link>https://rmmartins.com/postmortems-azure-automation-devops-metrics-part-2/</link>
      <pubDate>Mon, 13 Jul 2026 10:30:00 -0400</pubDate>
      <guid>https://rmmartins.com/postmortems-azure-automation-devops-metrics-part-2/</guid>
      <description>Integrate postmortems with Azure DevOps, measure effectiveness with MTTD/MTTR metrics, build Workbooks dashboards, and connect to the complete SRE cycle.</description>
    </item>
    <item>
      <title>Postmortems on Azure: implementing blameless incident analysis with Azure Monitor (Part 1)</title>
      <link>https://rmmartins.com/postmortems-azure-blameless-incident-analysis-part-1/</link>
      <pubDate>Mon, 13 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/postmortems-azure-blameless-incident-analysis-part-1/</guid>
      <description>Learn how to implement blameless postmortems on Azure: complete template, KQL queries for timeline reconstruction, and Logic Apps automation for data collection.</description>
    </item>
    <item>
      <title>Building a Deterministic 429 Watchdog for Azure OpenAI</title>
      <link>https://rmmartins.com/deterministic-429-watchdog-azure-openai/</link>
      <pubDate>Wed, 08 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/deterministic-429-watchdog-azure-openai/</guid>
      <description>An MCP server that detects token consumption trends before the 429 happens, with no LLM required, just metrics and a cron job.</description>
    </item>
    <item>
      <title>Context engineering: the art of feeding LLMs</title>
      <link>https://rmmartins.com/context-engineering-the-art-of-feeding-llms/</link>
      <pubDate>Sun, 05 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/context-engineering-the-art-of-feeding-llms/</guid>
      <description>Most of an LLM application&amp;#39;s quality comes from how you assemble the input. Here&amp;#39;s how to design context, prompts, tools, and token budgets like an infrastructure engineer.</description>
    </item>
    <item>
      <title>Visual glossary infra ↔ AI: your Rosetta Stone</title>
      <link>https://rmmartins.com/visual-glossary-infra-ai-your-rosetta-stone/</link>
      <pubDate>Sun, 05 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/visual-glossary-infra-ai-your-rosetta-stone/</guid>
      <description>Every AI term mapped to an infrastructure concept you already know. From &amp;#39;model&amp;#39; to &amp;#39;ZeRO&amp;#39;, with practical analogies and context for when each one shows up in your work.</description>
    </item>
    <item>
      <title>From prompt engineering to frontier company: why the model is no longer the differentiator</title>
      <link>https://rmmartins.com/from-prompt-engineering-to-frontier-company/</link>
      <pubDate>Thu, 02 Jul 2026 18:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/from-prompt-engineering-to-frontier-company/</guid>
      <description>Models became a commodity. The real differentiator is the system around them: harness engineering, context engineering, governance. How the conversation evolved in 3 years and where we are today.</description>
    </item>
    <item>
      <title>How RAG works: from theory to pipeline</title>
      <link>https://rmmartins.com/how-rag-works-from-theory-to-pipeline/</link>
      <pubDate>Thu, 02 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/how-rag-works-from-theory-to-pipeline/</guid>
      <description>RAG is search plus an LLM. Here’s how retrieval, chunking, embeddings, hybrid search, and Azure AI Search fit together in a practical production pipeline.</description>
    </item>
    <item>
      <title>AI adoption framework: from enthusiasm to governance</title>
      <link>https://rmmartins.com/ai-adoption-framework-from-enthusiasm-to-governance/</link>
      <pubDate>Wed, 01 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/ai-adoption-framework-from-enthusiasm-to-governance/</guid>
      <description>Enthusiasm without a framework is expensive chaos. The 6 adoption phases, readiness scorecard, anti-patterns that kill AI projects, and how not to become another company with shadow AI.</description>
    </item>
    <item>
      <title>MCP and AI Agents 101 for Infrastructure Engineers</title>
      <link>https://rmmartins.com/mcp-and-agents-101-for-infra-engineers/</link>
      <pubDate>Wed, 01 Jul 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/mcp-and-agents-101-for-infra-engineers/</guid>
      <description>What MCP is, how AI agents work, and what changes operationally, explained for infra/SRE engineers with a real AKS example.</description>
    </item>
    <item>
      <title>AI use cases for infra teams: AIOps and beyond</title>
      <link>https://rmmartins.com/ai-use-cases-for-infra-teams-aiops-and-beyond/</link>
      <pubDate>Sat, 27 Jun 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/ai-use-cases-for-infra-teams-aiops-and-beyond/</guid>
      <description>AI isn&amp;#39;t just for data scientists. Log analysis with LLMs, anomaly detection, predictive capacity planning, IaC generation, and how to use AI to improve your own infra work.</description>
    </item>
    <item>
      <title>Troubleshooting playbook: incidents that will wake you at 2AM</title>
      <link>https://rmmartins.com/troubleshooting-playbook-incidents-that-will-wake-you-at-2am/</link>
      <pubDate>Tue, 23 Jun 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/troubleshooting-playbook-incidents-that-will-wake-you-at-2am/</guid>
      <description>NVIDIA driver crash, CUDA OOM, pods stuck in Pending, 429 storm, and latency spikes. Symptoms, diagnosis, root cause, and prevention for each real-world scenario.</description>
    </item>
    <item>
      <title>Azure OpenAI in production: tokens, throughput, and high availability</title>
      <link>https://rmmartins.com/azure-openai-in-production-tokens-throughput-and-high-availability/</link>
      <pubDate>Fri, 19 Jun 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/azure-openai-in-production-tokens-throughput-and-high-availability/</guid>
      <description>HTTP 429 isn&amp;#39;t a bug, it&amp;#39;s bad capacity planning. Deployment types, PTU vs Standard, multi-region, retry patterns, and how not to take down your chatbot on launch day.</description>
    </item>
    <item>
      <title>Platform ops: building a self-service AI platform</title>
      <link>https://rmmartins.com/platform-ops-building-a-self-service-ai-platform/</link>
      <pubDate>Mon, 15 Jun 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/platform-ops-building-a-self-service-ai-platform/</guid>
      <description>You&amp;#39;ve become the bottleneck. Multi-tenancy, GPU scheduling, Kueue, quotas, priority classes, and how to stop being a help desk and become a platform engineer.</description>
    </item>
    <item>
      <title>Cost engineering for AI: when idle GPUs cost more than your car</title>
      <link>https://rmmartins.com/cost-engineering-for-ai-when-idle-gpus-cost-more-than-your-car/</link>
      <pubDate>Thu, 11 Jun 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/cost-engineering-for-ai-when-idle-gpus-cost-more-than-your-car/</guid>
      <description>Idle GPU time can turn into a serious Azure bill fast. Spot VMs, PTU vs pay-per-token, right-sizing, tagging, and FinOps to keep the CFO happy without killing innovation.</description>
    </item>
    <item>
      <title>Security for AI: threats your firewall won&#39;t catch</title>
      <link>https://rmmartins.com/security-for-ai-threats-your-firewall-wont-catch/</link>
      <pubDate>Sun, 07 Jun 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/security-for-ai-threats-your-firewall-wont-catch/</guid>
      <description>Prompt injection is the SQL injection of the AI world. Managed identities, private endpoints, Key Vault, RBAC, and the defenses you need beyond a traditional WAF.</description>
    </item>
    <item>
      <title>Monitoring and observability for AI: when the green dashboard lies</title>
      <link>https://rmmartins.com/monitoring-and-observability-for-ai/</link>
      <pubDate>Wed, 03 Jun 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/monitoring-and-observability-for-ai/</guid>
      <description>Healthy infra doesn&amp;#39;t mean a working model. Model drift, GPU metrics, Azure OpenAI throttling, and the 6 dimensions of observability you need to cover.</description>
    </item>
    <item>
      <title>MLOps: model lifecycle for infra engineers</title>
      <link>https://rmmartins.com/mlops-model-lifecycle-for-infra-engineers/</link>
      <pubDate>Sat, 30 May 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/mlops-model-lifecycle-for-infra-engineers/</guid>
      <description>A data scientist sends you model_final_v2_FIXED.pt and says &amp;#39;put it in production&amp;#39;. Sound familiar? MLOps is the same CI/CD you already know, applied to ML models.</description>
    </item>
    <item>
      <title>Infrastructure as Code for AI: automating GPU clusters</title>
      <link>https://rmmartins.com/infrastructure-as-code-for-ai-automating-gpu-clusters/</link>
      <pubDate>Tue, 26 May 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/infrastructure-as-code-for-ai-automating-gpu-clusters/</guid>
      <description>A typo in a VM SKU cost $4,000 in three days. IaC isn&amp;#39;t nice-to-have for AI infra. It&amp;#39;s survival. Terraform, Bicep, and CI/CD for GPU clusters.</description>
    </item>
    <item>
      <title>GPU deep dive: what happens inside the silicon</title>
      <link>https://rmmartins.com/gpu-deep-dive-what-happens-inside-the-silicon/</link>
      <pubDate>Fri, 22 May 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/gpu-deep-dive-what-happens-inside-the-silicon/</guid>
      <description>Why doesn&amp;#39;t a 14 GB model fit on a 40 GB GPU? How to read nvidia-smi like a pro? Understand GPU architecture, memory hierarchy, multi-GPU strategies, and troubleshooting.</description>
    </item>
    <item>
      <title>Compute for AI: choosing the right hardware (and connecting it properly)</title>
      <link>https://rmmartins.com/compute-for-ai-choosing-the-right-hardware/</link>
      <pubDate>Mon, 18 May 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/compute-for-ai-choosing-the-right-hardware/</guid>
      <description>The difference between a two-day training job and a 90-minute one isn&amp;#39;t a faster GPU. It&amp;#39;s knowing which GPU to use and how to connect them. A complete guide to GPU VMs on Azure.</description>
    </item>
    <item>
      <title>Data and storage for AI workloads: the bottleneck nobody sees</title>
      <link>https://rmmartins.com/data-and-storage-for-ai-workloads/</link>
      <pubDate>Thu, 14 May 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/data-and-storage-for-ai-workloads/</guid>
      <description>Expensive GPUs sitting idle waiting for slow disk is the #1 problem in AI infrastructure. Learn how to diagnose data starvation, choose the right storage, and build a pipeline that keeps GPUs fed.</description>
    </item>
    <item>
      <title>AI for infrastructure engineers: why AI needs you</title>
      <link>https://rmmartins.com/ai-for-infrastructure-engineers-why-ai-needs-you/</link>
      <pubDate>Sun, 10 May 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/ai-for-infrastructure-engineers-why-ai-needs-you/</guid>
      <description>You don&amp;#39;t need to become a data scientist to work with AI. Your infrastructure skills already prepare you more than you think for the age of artificial intelligence.</description>
    </item>
    <item>
      <title>Something My Manager Said Today That Stayed With Me</title>
      <link>https://rmmartins.com/something-my-manager-said-today-that-stayed-with-me/</link>
      <pubDate>Tue, 24 Mar 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/something-my-manager-said-today-that-stayed-with-me/</guid>
      <description>&lt;p&gt;Had a 1:1 last week. Nothing unusual, just a regular conversation, catching up on things. But there was one moment that stayed with me after the call ended.&lt;/p&gt;
&lt;p&gt;At some point he said he usually thinks about people in four different ways. Not as an official framework or anything like that, just how he personally sees it. And I don&amp;rsquo;t know, the way he explained it felt simple, but it kind of stuck.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Responsibility, Trade-Offs, and Learning at AI Scale</title>
      <link>https://rmmartins.com/responsibility-trade-offs-and-learning-at-ai-scale/</link>
      <pubDate>Mon, 09 Feb 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/responsibility-trade-offs-and-learning-at-ai-scale/</guid>
      <description>&lt;p&gt;Over the past year, I&amp;rsquo;ve been working closely with some of the bigger and more visible AI customers in Microsoft&amp;rsquo;s ecosystem.
Large platforms. Fast-moving teams. High expectations. High stakes.&lt;/p&gt;
&lt;p&gt;On paper, that kind of visibility sounds exciting.
In reality, it comes with a weight that&amp;rsquo;s hard to explain unless you&amp;rsquo;ve been there.&lt;/p&gt;
&lt;p&gt;Because being close to impact also means being close to consequence.&lt;/p&gt;
&lt;h2 id=&#34;visibility-changes-everything&#34;&gt;Visibility changes everything&lt;/h2&gt;
&lt;p&gt;When you work with smaller teams or early-stage projects, mistakes are usually contained.
You can recover. You can explain. You can iterate.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why Azure Feels Harder Than AWS</title>
      <link>https://rmmartins.com/why-azure-feels-harder-than-aws/</link>
      <pubDate>Tue, 03 Feb 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/why-azure-feels-harder-than-aws/</guid>
      <description>&lt;h2 id=&#34;and-why-thats-not-an-accident&#34;&gt;&amp;hellip;and why that&amp;rsquo;s not an accident.&lt;/h2&gt;
&lt;p&gt;If you have worked with both Azure and AWS long enough, you have probably felt it.&lt;/p&gt;
&lt;p&gt;AWS feels straightforward.
Azure feels… heavier.&lt;/p&gt;
&lt;p&gt;Not worse. Not broken. Just harder to reason about.&lt;/p&gt;
&lt;p&gt;The console feels denser.
The mental model feels less obvious.
The number of &amp;ldquo;extra&amp;rdquo; concepts feels higher.&lt;/p&gt;
&lt;p&gt;This is not a beginner problem.
Senior engineers feel it too.&lt;/p&gt;
&lt;p&gt;And the most interesting part is this: &lt;strong&gt;that friction is not accidental&lt;/strong&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud Maturity Is Not About Being 100% Cloud</title>
      <link>https://rmmartins.com/cloud-maturity-is-not-about-being-100-cloud/</link>
      <pubDate>Fri, 23 Jan 2026 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/cloud-maturity-is-not-about-being-100-cloud/</guid>
      <description>&lt;p&gt;For years, &amp;ldquo;cloud-first&amp;rdquo; has been treated as a badge of honor. Companies proudly announce that everything is in the cloud, architects optimize for migrations instead of outcomes, and teams equate progress with how little infrastructure they still own.&lt;/p&gt;
&lt;p&gt;But after working with dozens of real systems, across different industries and at different scales, one thing becomes clear.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Cloud maturity is not about being 100% cloud.&lt;/strong&gt;
It is about knowing &lt;em&gt;why&lt;/em&gt; each workload is where it is.&lt;/p&gt;</description>
    </item>
    <item>
      <title>No One Is Layoff-Proof: How Intellectual Capital Can Be Your Best Protection</title>
      <link>https://rmmartins.com/no-one-is-layoff-proof-how-intellectual-capital-can-ne-your-best-protection/</link>
      <pubDate>Tue, 14 Oct 2025 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/no-one-is-layoff-proof-how-intellectual-capital-can-ne-your-best-protection/</guid>
      <description>&lt;p&gt;&lt;img loading=&#34;lazy&#34; src=&#34;https://rmmartins.com/wp-content/uploads/2025/10/image-1024x683.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;Throughout my career, I&amp;rsquo;ve had countless conversations about career paths with colleagues, mentees, and professionals in transition. In those talks, I often share practices that have helped me personally along the way.&lt;/p&gt;
&lt;p&gt;But this article is different. It&amp;rsquo;s transparent and honest.
Although I&amp;rsquo;ve spoken about parts of my story with people close to me, this is the first time I&amp;rsquo;m sharing it so openly, including my mistakes, lessons, and reflections in a public space.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Who Are You Without the Company&#39;s Last Name?</title>
      <link>https://rmmartins.com/who-are-you-without-the-companys-last-name/</link>
      <pubDate>Wed, 14 May 2025 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/who-are-you-without-the-companys-last-name/</guid>
      <description>&lt;p&gt;It&amp;rsquo;s easy, even comforting, to blend in with your badge.
We introduce ourselves with our name followed by the company.
We join meetings carrying that title.
We post with the credibility it gives.&lt;/p&gt;
&lt;p&gt;But at the end of the day, the company is just where you are, not who you are.&lt;/p&gt;
&lt;p&gt;You are what you&amp;rsquo;ve built.
What you&amp;rsquo;ve learned, and taught.
You are the reputation that stands when your name shows up alone.
You are the value that stays when the badge is gone.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Private ARO Cluster with Access via JumpHost</title>
      <link>https://rmmartins.com/private-aro-cluster-with-access-via-jumphost/</link>
      <pubDate>Tue, 21 Jan 2025 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/private-aro-cluster-with-access-via-jumphost/</guid>
      <description>&lt;p&gt;&lt;em&gt;This article was originally published at &lt;a href=&#34;https://cloud.redhat.com/experts/aro/private-cluster/&#34;&gt;https://cloud.redhat.com/experts/aro/private-cluster/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;A Quickstart guide to deploying a Private Azure Red Hat OpenShift cluster.&lt;/p&gt;
&lt;h2 id=&#34;prerequisites&#34;&gt;Prerequisites&lt;/h2&gt;
&lt;h3 id=&#34;azure-cli&#34;&gt;Azure CLI&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;Obviously you&amp;rsquo;ll need to have an Azure account to configure the CLI against.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;MacOS&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;See &lt;a href=&#34;https://docs.microsoft.com/en-us/cli/azure/install-azure-cli-macos&#34;&gt;Azure Docs&lt;/a&gt; for alternative install options.&lt;/em&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Install Azure CLI using homebrew&lt;/li&gt;
&lt;/ol&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;brew update &lt;span class=&#34;o&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; brew install azure-cli
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ol start=&#34;2&#34;&gt;
&lt;li&gt;Install sshuttle using homebrew&lt;/li&gt;
&lt;/ol&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;brew install sshuttle
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Linux&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;See &lt;a href=&#34;https://docs.microsoft.com/en-us/cli/azure/install-azure-cli-linux?pivots=dnf&#34;&gt;Azure Docs&lt;/a&gt; for alternative install options.&lt;/em&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Import the Microsoft Keys&lt;/li&gt;
&lt;/ol&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo rpm --import https://packages.microsoft.com/keys/microsoft.asc
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ol start=&#34;2&#34;&gt;
&lt;li&gt;Add the Microsoft Yum Repository&lt;/li&gt;
&lt;/ol&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cat &lt;span class=&#34;s&#34;&gt;&amp;lt;&amp;lt; EOF | sudo tee /etc/yum.repos.d/azure-cli.repo
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;s&#34;&gt;[azure-cli]
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;s&#34;&gt;name=Azure CLI
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;s&#34;&gt;baseurl=https://packages.microsoft.com/yumrepos/azure-cli
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;s&#34;&gt;enabled=1
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;s&#34;&gt;gpgcheck=1
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;s&#34;&gt;gpgkey=https://packages.microsoft.com/keys/microsoft.asc
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;s&#34;&gt;EOF&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ol start=&#34;3&#34;&gt;
&lt;li&gt;Install Azure CLI&lt;/li&gt;
&lt;/ol&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;sudo dnf install -y azure-cli sshuttle
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id=&#34;prepare-azure-account-for-azure-openshift&#34;&gt;Prepare Azure Account for Azure OpenShift&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Log into the Azure CLI by running the following and then authorizing through your Web Browser&lt;/li&gt;
&lt;/ol&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;az login
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ol start=&#34;2&#34;&gt;
&lt;li&gt;Make sure you have enough Quota (change the location if you&amp;rsquo;re not using East US)&lt;/li&gt;
&lt;/ol&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;az vm list-usage --location &lt;span class=&#34;s2&#34;&gt;&amp;#34;East US&amp;#34;&lt;/span&gt; -o table
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;See &lt;a href=&#34;#adding-quota-to-aro-account&#34;&gt;Addendum – Adding Quota to ARO account&lt;/a&gt; if you have less than 36 Quota left for Total Regional CPUs&lt;/p&gt;</description>
    </item>
    <item>
      <title>Creating a Lightweight Jump Host in Azure with sshuttle (No VPN Required)</title>
      <link>https://rmmartins.com/creating-a-lightweight-jump-host-in-azure-with-sshuttle-no-vpn-required/</link>
      <pubDate>Fri, 04 Oct 2024 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/creating-a-lightweight-jump-host-in-azure-with-sshuttle-no-vpn-required/</guid>
      <description>&lt;p&gt;When working with development or test environments in Azure, a common need is secure access to internal resources without exposing them directly to the internet. While VPN solutions are a robust way to achieve this, they can often be overkill for simple use cases, especially when you just want to access a few VMs or services for testing. A jump host combined with sshuttle offers a simple, VPN-like solution that can be quickly deployed and used to tunnel traffic to your Azure resources—without the overhead of setting up a full VPN.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Deploying Advanced Cluster Management and OpenShift Data Foundation for ARO Disaster Recovery</title>
      <link>https://rmmartins.com/deploying-advanced-cluster-management-and-openshift-data-foundation-for-aro-disaster-recovery/</link>
      <pubDate>Fri, 04 Oct 2024 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/deploying-advanced-cluster-management-and-openshift-data-foundation-for-aro-disaster-recovery/</guid>
      <description>&lt;p&gt;&lt;em&gt;This article was originally published at &lt;a href=&#34;https://cloud.redhat.com/experts/aro/acm-odf-aro/&#34;&gt;https://cloud.redhat.com/experts/aro/acm-odf-aro/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;A guide to deploying Advanced Cluster Management (ACM) and OpenShift Data Foundation (ODF) for Azure Red Hat OpenShift (ARO) Disaster Recovery.&lt;/p&gt;
&lt;h2 id=&#34;overview&#34;&gt;Overview&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;VolSync is not supported for ARO in ACM: &lt;a href=&#34;https://access.redhat.com/articles/7006295&#34;&gt;https://access.redhat.com/articles/7006295&lt;/a&gt; so if you run into issues and file a support ticket, you will receive the information that ARO is not supported.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;In today&amp;rsquo;s fast-paced and data-driven world, ensuring the resilience and availability of your applications and data has never been more critical. The unexpected can happen at any moment, and the ability to recover quickly and efficiently is paramount. That&amp;rsquo;s where OpenShift Advanced Cluster Management (ACM) and OpenShift Data Foundation (ODF) come into play. In this guide, we will explore the deployment of ACM and ODF for disaster recovery (DR) purposes, empowering you to safeguard your applications and data across multiple clusters.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Configure ARO to Use Microsoft Entra ID Group Claims</title>
      <link>https://rmmartins.com/configure-aro-to-use-microsoft-entra-id-group-claims/</link>
      <pubDate>Thu, 03 Oct 2024 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/configure-aro-to-use-microsoft-entra-id-group-claims/</guid>
      <description>&lt;p&gt;&lt;em&gt;This article was originally published at &lt;a href=&#34;https://cloud.redhat.com/experts/idp/group-claims/aro/&#34;&gt;Configure ARO to use Microsoft Entra ID Group Claims | Red Hat Cloud Experts&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This guide demonstrates how to utilize the OpenID Connect group claim functionality implemented in OpenShift 4.10. This functionality allows an identity provider to provide a user&amp;rsquo;s group membership for use within OpenShift. This guide will walk through the creation of an Azure Active Directory (Azure AD) application, configure the necessary Azure AD groups, and configure Azure Red Hat OpenShift (ARO) to authenticate and manage authorization using Azure AD.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ARO with Nvidia GPU Workloads</title>
      <link>https://rmmartins.com/aro-with-nvidia-gpu-workloads/</link>
      <pubDate>Thu, 08 Aug 2024 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/aro-with-nvidia-gpu-workloads/</guid>
      <description>&lt;p&gt;&lt;em&gt;This article was originally published at &lt;a href=&#34;https://cloud.redhat.com/experts/aro/gpu/&#34;&gt;ARO with Nvidia GPU Workloads | Red Hat Cloud Experts&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;ARO guide to running Nvidia GPU workloads.&lt;/p&gt;
&lt;h2 id=&#34;prerequisites&#34;&gt;Prerequisites&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;oc cli&lt;/li&gt;
&lt;li&gt;Helm&lt;/li&gt;
&lt;li&gt;jq, moreutils, and gettext package&lt;/li&gt;
&lt;li&gt;An &lt;a href=&#34;https://cloud.redhat.com/experts/aro/terraform-install&#34;&gt;ARO 4.14 cluster&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; If you need to install an ARO cluster, please read our &lt;a href=&#34;https://cloud.redhat.com/experts/aro/terraform-install&#34;&gt;ARO Terraform Install Guide&lt;/a&gt;. Please be sure if you&amp;rsquo;re installing or using an existing ARO cluster that it is 4.14.x or higher.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Please ensure your ARO cluster was created with a valid pull secret (to verify make sure you can see the Operator Hub in the cluster&amp;rsquo;s console). If not, you can follow &lt;a href=&#34;https://cloud.redhat.com/experts/aro/pull-secret&#34;&gt;these&lt;/a&gt; instructions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>What to Consider When Using Azure AD as IDP</title>
      <link>https://rmmartins.com/what-to-consider-when-using-azure-ad-as-idp/</link>
      <pubDate>Fri, 24 May 2024 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/what-to-consider-when-using-azure-ad-as-idp/</guid>
      <description>&lt;p&gt;&lt;em&gt;This article was originally published at &lt;a href=&#34;https://cloud.redhat.com/experts/idp/considerations-aad-ipd/&#34;&gt;What to consider when using Azure AD as IDP? | Red Hat Cloud Experts&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;In this guide, we will discuss key considerations when using Azure Active Directory (AAD) as the Identity Provider (IDP) for your ARO or ROSA cluster. Below are some helpful references:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://cloud.redhat.com/experts/idp/azuread-aro/&#34;&gt;Configure ARO to Use Azure AD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cloud.redhat.com/experts/idp/azuread/&#34;&gt;Configuring IDP for ROSA, OSD, and ARO&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;default-access-for-all-users-in-azure-active-directory&#34;&gt;Default Access for All Users in Azure Active Directory&lt;/h2&gt;
&lt;p&gt;Once you set up AAD as the IDP for your cluster, it&amp;rsquo;s important to note that by default, all users in your Azure Active Directory instance will have access to the cluster. They can log in using their AAD credentials through the OpenShift Web Console endpoint:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Building a Secure and Scalable Foundation for Your Environment on Azure</title>
      <link>https://rmmartins.com/building-a-secure-and-scalable-foundation-for-your-environment-on-azure/</link>
      <pubDate>Mon, 20 May 2024 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/building-a-secure-and-scalable-foundation-for-your-environment-on-azure/</guid>
      <description>&lt;p&gt;Great! You just started your Azure journey and now it&amp;rsquo;s time to scale your infrastructure to meet the growing demands of your business. Microsoft Azure offers a robust cloud platform that can grow with you, but where do you begin? This article will introduce you to three fundamental building blocks for your Azure journey: Azure Subscriptions, Microsoft Entra ID (formerly Azure Active Directory), and Azure Enterprise Scale Landing Zones.&lt;/p&gt;
&lt;h2 id=&#34;understanding-the-basics&#34;&gt;Understanding the Basics&lt;/h2&gt;
&lt;h3 id=&#34;microsoft-entra-id-former-azure-active-directory&#34;&gt;Microsoft Entra ID (Former Azure Active Directory)&lt;/h3&gt;
&lt;p&gt;Microsoft Entra ID, previously known as Azure Active Directory (Azure AD), is the backbone of identity and access management in Azure. It is a cloud-based identity and access management service that provides:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Maximizing Cost Efficiency in Azure: Navigating Azure Reservations and Savings Plans</title>
      <link>https://rmmartins.com/maximizing-cost-efficiency-in-azure-navigating-azure-reservations-and-savings-plans/</link>
      <pubDate>Wed, 15 May 2024 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/maximizing-cost-efficiency-in-azure-navigating-azure-reservations-and-savings-plans/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction:&lt;/h2&gt;
&lt;p&gt;In the realm of cloud computing, optimizing costs is paramount for businesses leveraging Microsoft Azure. Azure offers two primary cost-saving mechanisms: &lt;a href=&#34;https://learn.microsoft.com/en-us/azure/cost-management-billing/reservations/save-compute-costs-reservations&#34;&gt;Azure Reservations&lt;/a&gt; and &lt;a href=&#34;https://learn.microsoft.com/en-us/azure/cost-management-billing/savings-plan/savings-plan-compute-overview&#34;&gt;Azure Savings Plans&lt;/a&gt;. Both options come with distinct advantages, disadvantages, and usage scenarios. In this comprehensive guide, we&amp;rsquo;ll explore these features, penalties, and ideal use cases to empower you in making informed decisions tailored to your business needs.&lt;/p&gt;
&lt;p&gt;&lt;img loading=&#34;lazy&#34; src=&#34;https://github.com/ricmmartins/rmmartinscom/raw/master/assets/images/cloud-costs.jpeg&#34;&gt;&lt;/p&gt;
&lt;h2 id=&#34;understanding-azure-reservations&#34;&gt;Understanding Azure Reservations:&lt;/h2&gt;
&lt;p&gt;Azure Reservations provide businesses the opportunity to commit to one-year or three-year plans for various products within the Azure ecosystem. The commitment entails a promise of usage, enabling significant discounts of up to 72% off pay-as-you-go prices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introduction to AI and Comparing OpenAI with Azure OpenAI</title>
      <link>https://rmmartins.com/introduction-to-ai-and-comparing-openai-with-azure-openai/</link>
      <pubDate>Fri, 10 May 2024 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/introduction-to-ai-and-comparing-openai-with-azure-openai/</guid>
      <description>&lt;p&gt;As I embark on my journey of learning about artificial intelligence (AI), I am discovering the fascinating world of large language models (LLMs) and their applications in various technologies. In this article, I aim to share my newfound knowledge and insights with others who are also beginning their journey in AI. We will explore OpenAI, one of the leading organizations in AI research and development, and compare its offerings with Microsoft&amp;rsquo;s Azure OpenAI service.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Real-World Applications and Ethical Implications of AI</title>
      <link>https://rmmartins.com/real-world-applications-and-ethical-implications-of-ai/</link>
      <pubDate>Fri, 10 May 2024 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/real-world-applications-and-ethical-implications-of-ai/</guid>
      <description>&lt;p&gt;As we continue our journey into artificial intelligence (AI), it&amp;rsquo;s important to understand how AI is transforming different industries and the ethical and legal challenges associated with its widespread adoption. In this new post, we will explore AI&amp;rsquo;s real-world applications and the complexities of ethical and legal concerns in detail.&lt;/p&gt;
&lt;h2 id=&#34;ai-in-healthcare&#34;&gt;AI in Healthcare&lt;/h2&gt;
&lt;p&gt;AI is making significant advances in healthcare, improving patient care and medical research:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Diagnostics&lt;/strong&gt;: AI-powered algorithms can analyze medical images, such as X-rays, MRIs, and CT scans, to identify diseases like cancer or fractures with high accuracy. These systems can serve as a second opinion for radiologists, improving diagnostic accuracy and efficiency.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Personalized Medicine&lt;/strong&gt;: AI enables the development of personalized treatment plans based on a patient&amp;rsquo;s unique genetic makeup. This approach can lead to more effective and targeted therapies, improving patient outcomes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Drug Discovery&lt;/strong&gt;: AI accelerates the process of discovering new drugs by analyzing vast amounts of data to identify potential compounds and predict their efficacy. This reduces the time and cost associated with bringing new drugs to market.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Remote Monitoring&lt;/strong&gt;: AI-powered wearable devices and remote monitoring tools enable healthcare providers to track patients&amp;rsquo; health in real-time, offering proactive care and reducing hospital readmissions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Administrative Efficiency&lt;/strong&gt;: AI streamlines administrative tasks such as scheduling, billing, and insurance claims processing, freeing up healthcare professionals to focus on patient care.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;ai-in-finance&#34;&gt;AI in Finance&lt;/h2&gt;
&lt;p&gt;AI is reshaping the finance industry by providing innovative solutions to complex problems:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Azure Front Door with ARO (Azure Red Hat OpenShift)</title>
      <link>https://rmmartins.com/azure-front-door-with-aro-azure-red-hat-openshift/</link>
      <pubDate>Tue, 09 Apr 2024 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/azure-front-door-with-aro-azure-red-hat-openshift/</guid>
      <description>&lt;p&gt;&lt;em&gt;This article was originally published at &lt;a href=&#34;https://cloud.redhat.com/experts/aro/frontdoor/&#34;&gt;Azure Front Door with ARO ( Azure Red Hat OpenShift ) | Red Hat Cloud Experts&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Securing exposing an Internet facing application with a private ARO Cluster.&lt;/p&gt;
&lt;p&gt;When you create a cluster on ARO you have several options in making the cluster public or private. With a public cluster you are allowing Internet traffic to the api and *.apps endpoints. With a private cluster you can make either or both the api and .apps endpoints private.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Projects</title>
      <link>https://rmmartins.com/projects/</link>
      <pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate>
      <guid>https://rmmartins.com/projects/</guid>
      <description>Open-source projects, official publications, study guides, tools and community contributions by Ricardo Martins on Azure, AI, infrastructure, Kubernetes and DevOps.</description>
    </item>
    <item>
      <title>Deploying an Application on OpenShift Local: A Beginner&#39;s Guide</title>
      <link>https://rmmartins.com/deploying-an-application-on-openshift-local-a-beginners-guide/</link>
      <pubDate>Fri, 08 Dec 2023 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/deploying-an-application-on-openshift-local-a-beginners-guide/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;
&lt;p&gt;OpenShift, developed by Red Hat, extends Kubernetes to provide a more robust platform for deploying and managing containerized applications in a complete application platform. It integrates the core features of Kubernetes with additional tools and services to enhance developer productivity and operational efficiency. This guide aims to introduce beginners to deploying applications on OpenShift Local, a streamlined method to run OpenShift clusters locally for development and testing.&lt;/p&gt;
&lt;p&gt;Using a local OpenShift environment, offers several benefits, especially for developers who are new to OpenShift or Kubernetes:&lt;/p&gt;</description>
    </item>
    <item>
      <title>DevSecOps Workshop</title>
      <link>https://rmmartins.com/devsecops-workshop/</link>
      <pubDate>Thu, 07 Dec 2023 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/devsecops-workshop/</guid>
      <description>&lt;p&gt;&lt;img loading=&#34;lazy&#34; src=&#34;https://rmmartins.com/wp-content/uploads/2025/04/image-1024x558.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;Just sharing an awesome learning resource I found recently. It will introduce you to the application development cycle leveraging OpenShift&amp;rsquo;s tooling &amp;amp; features with a special focus on securing your environment using Advanced Cluster Security for Kubernetes (ACS). You will get a brief introduction in several OpenShift features like OpenShift Pipelines, OpenShift GitOps, and OpenShift DevSpaces.&lt;/p&gt;
&lt;p&gt;Check out at &lt;a href=&#34;https://devsecops-workshop.github.io/&#34;&gt;https://devsecops-workshop.github.io/&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Have You Already Had a Chance to Think About Why You Should Consider Using UBI?</title>
      <link>https://rmmartins.com/have-you-already-had-a-chance-to-think-about-why-you-should-consider-using-ubi/</link>
      <pubDate>Thu, 07 Dec 2023 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/have-you-already-had-a-chance-to-think-about-why-you-should-consider-using-ubi/</guid>
      <description>&lt;p&gt;UBI stands for Universal Base Image. It&amp;rsquo;s a type of container-based image that Red Hat has created and maintains. UBI images are derived from Red Hat Enterprise Linux (RHEL) and are designed to be a foundation for building containerized applications. Here&amp;rsquo;s why UBI is significant and why you might consider to use it:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Compatibility with RHEL&lt;/strong&gt;: UBI is based on RHEL, which means it inherits the reliability, security, and performance of RHEL. This compatibility is crucial for organizations that already rely on RHEL for their enterprise applications.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Open and Freely Distributable&lt;/strong&gt;: Unlike RHEL, which requires a subscription, UBI can be used freely. This means you can build your container images on UBI and redistribute them without worrying about RHEL licensing, while still benefiting from the stability and security of a RHEL base.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security and Compliance&lt;/strong&gt;: UBI images benefit from Red Hat&amp;rsquo;s commitment to security and compliance. They receive regular updates and patches, which is essential for maintaining security in containerized environments.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Broad Ecosystem and Support&lt;/strong&gt;: Since UBI is based on RHEL, it has broad support from software vendors and the open-source community. This extensive ecosystem ensures compatibility with a wide range of applications and tools.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ease of Certification&lt;/strong&gt;: For software vendors, using UBI can simplify the process of certifying their applications for RHEL, as UBI containers can be run on both RHEL and non-RHEL hosts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Container Portability&lt;/strong&gt;: Containers built on UBI can run anywhere that supports container workloads, including Red Hat OpenShift, Kubernetes, and even non-Red Hat platforms. This portability is crucial for organizations adopting a hybrid or multi-cloud strategy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Consistency Across Environments&lt;/strong&gt;: UBI helps maintain consistency across development, testing, and production environments, reducing the &amp;ldquo;it works on my machine&amp;rdquo; problem.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Support for Different Architectures&lt;/strong&gt;: UBI images are available for multiple architectures, including x86_64, s390x, and others, which is important for organizations with diverse infrastructure needs.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In summary, UBI combines the reliability and security of RHEL with the flexibility and freedom of a container-based image that can be freely shared and redistributed. It&amp;rsquo;s an excellent choice for organizations looking to build containerized applications that are secure, compliant, and compatible with a wide range of environments and platforms. See &lt;a href=&#34;https://catalog.redhat.com/software/base-images&#34;&gt;more here&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Prerequisites Checklist to Deploy ARO Cluster</title>
      <link>https://rmmartins.com/prerequisites-checklist-to-deploy-aro-cluster/</link>
      <pubDate>Thu, 30 Nov 2023 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/prerequisites-checklist-to-deploy-aro-cluster/</guid>
      <description>&lt;p&gt;&lt;em&gt;This article was originally published at &lt;a href=&#34;https://cloud.redhat.com/experts/aro/prereq-list/&#34;&gt;https://cloud.redhat.com/experts/aro/prereq-list/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Before deploying an ARO cluster, ensure you meet the following prerequisites:&lt;/p&gt;
&lt;h2 id=&#34;setup-tools&#34;&gt;Setup Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Install Azure CLI&lt;/strong&gt;: Essential for managing Azure resources. Refer to the &lt;a href=&#34;https://learn.microsoft.com/cli/azure/install-azure-cli&#34;&gt;official documentation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;verify-resources&#34;&gt;Verify Resources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Core Quota&lt;/strong&gt;: &lt;a href=&#34;https://learn.microsoft.com/azure/quotas/per-vm-quota-requests&#34;&gt;Confirm availability of at least 40 cores&lt;/a&gt; to create and run an OpenShift Cluster.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;permissions&#34;&gt;Permissions&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;RBAC Settings&lt;/strong&gt;:
&lt;ul&gt;
&lt;li&gt;Ensure you have &lt;strong&gt;Contributor&lt;/strong&gt; and &lt;strong&gt;User Access Administrator&lt;/strong&gt; roles on the cluster resource group.&lt;/li&gt;
&lt;li&gt;Assign &lt;strong&gt;Network Contributor&lt;/strong&gt; role on the virtual network, if using a separate resource group.&lt;/li&gt;
&lt;li&gt;For stricter security policies, &lt;a href=&#34;https://learn.microsoft.com/azure/role-based-access-control/custom-roles&#34;&gt;create a custom role&lt;/a&gt; with necessary permissions. &lt;a href=&#34;https://docs.openshift.com/container-platform/4.14/installing/installing_azure/installing-azure-account.html#minimum-required-permissions-ipi-azure_installing-azure-account&#34;&gt;Reference link&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Entra (Former Azure AD)&lt;/strong&gt;:
&lt;ul&gt;
&lt;li&gt;Have a member user of the tenant or a guest with &lt;strong&gt;Application administrator&lt;/strong&gt; role for the tooling to create an application and service principal on your behalf for the cluster.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Terraform&lt;/strong&gt;: If you plan to use Terraform for the deployment of the cluster, &lt;a href=&#34;https://github.com/rh-mobb/terraform-aro-permissions&#34;&gt;see here&lt;/a&gt; the required permissions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;azure-integration&#34;&gt;Azure Integration&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Resource Provider&lt;/strong&gt;:
&lt;ul&gt;
&lt;li&gt;Register the &lt;code&gt;Microsoft.RedHatOpenshift&lt;/code&gt; resource provider. &lt;a href=&#34;https://learn.microsoft.com/azure/azure-resource-manager/management/resource-providers-and-types#register-resource-provider&#34;&gt;Reference link&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Red Hat Integration&lt;/strong&gt;:
&lt;ul&gt;
&lt;li&gt;Obtain a &lt;a href=&#34;https://console.redhat.com/openshift/install/azure/aro-provisioned&#34;&gt;Red Hat pull secret&lt;/a&gt; (Recommended for access to additional content like Operators and Container Registries).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;domain-configuration&#34;&gt;Domain Configuration&lt;/h2&gt;
&lt;p&gt;This step is optional since you can use the built-in domain.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Setup a VPN Connection into an ARO Cluster with OpenVPN</title>
      <link>https://rmmartins.com/setup-a-vpn-connection-into-an-aro-cluster-with-openvpn/</link>
      <pubDate>Wed, 29 Mar 2023 10:00:00 -0400</pubDate>
      <guid>https://rmmartins.com/setup-a-vpn-connection-into-an-aro-cluster-with-openvpn/</guid>
      <description>&lt;p&gt;&lt;em&gt;This article was originally published at &lt;a href=&#34;https://cloud.redhat.com/experts/aro/vpn/&#34;&gt;Setup a VPN Connection into an ARO Cluster with OpenVPN | Red Hat Cloud Experts&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;When you configure an Azure Red Hat OpenShift (ARO) cluster with a private only configuration, you will need connectivity to this private network in order to access your cluster. This guide will show you how to configure a point-to-site VPN connection so you won&amp;rsquo;t need to setup and configure Jump Boxes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>About</title>
      <link>https://rmmartins.com/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://rmmartins.com/about/</guid>
      <description>About Ricardo Martins</description>
    </item>
  </channel>
</rss>
