Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Daily Azure Shit

@azureshit@mastodon.social
mastodon 4.7.0-beta.1
  • Open on mastodon.social

Daily dosis of shit experienced on Microsoft Azure.

This account is obviously not affiliated with Microsoft.

0 Followers
0 Following
20 Posts
Joined February 28, 2023
Short:
https://azsh.it
Short Example:
https://azsh.it/45

Posts

Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Apr 23, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 543. The reason why the shit from day 541 (a Key Vault resource without the "audit" log category group) breaks the the built-in #Azure Policy provided by #Microsoft is that it by design always tries to deploy a diagnostic setting for all log category groups and then sets them to enabled or disabled based on parameters you supply. If one of these disabled categories doesn't exist, the deployment always fails.

mastodon.social

Mastodon

3
0
0
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Apr 22, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 542. The shit from day 541 even breaks #Microsoft's own built-in #Azure Policies. When deploying a Key Vault in Denmark East and using the built-in policy to automatically deploy diagnostic settings, the policy evaluation will simply fail because the "audit" log category group does not exist, even when you want to enable a different category group. You cannot use this policy with Key Vaults in Denmark East.

mastodon.social

Mastodon

5
0
1
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Apr 20, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 541. While we already know that log category groups can differ from service to service, this is the first time we have seen different category groups within one service. In this example, we found that #Azure Key Vaults in Denmark East do not have the "audit" log category group while it exists in other regions. Both of these Key Vaults have been created at the same time, so this is not about age of the resource.

mastodon.social

Mastodon

6
1
5
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Apr 17, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 540. Continuing the shit from day 539, Azure CLI not being able to show built-in Azure Policy definitions has been a known issue for years. Instead of fixing it, #Microsoft support simply closed the issue and called it a day.

mastodon.social

Mastodon

4
0
0
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Apr 16, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 539. When trying to query a built-in #Azure Policy definition using the Azure CLI, the CLI will first tell you to supply a "--policy" argument and then tell you that there is no such argument.

mastodon.social

Mastodon

16
0
5
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Apr 14, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 538. To work around the shit from day 537, to log into a specific #Azure tenant in the Azure Portal without triggering any MFA flows for other directories, you can hotlink a tenant like this: "portal.azure.com/"

mastodon.social

Mastodon

6
0
1
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Mar 26, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 537. The #Azure Portal setting for startup directory applies to your whole Microsoft Account and not just the browser you are currently in. Which is kind of stupid, because if you have multiple browsers set up for multiple Azure tenants, Azure will per default always log you into the same Azure tenant, regardless of your work environment.

mastodon.social

Mastodon

3
1
1
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Mar 25, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 536. In case you are wondering, the terms "Azure tenant" and "Azure directory" largely refer to the same thing and are most often used interchangebly. They even always have the same UUID. According to #Microsoft support, there apparently is some distinction on a technical level though. Why does it always have to be this complicated?

mastodon.social

Mastodon

3
0
2
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Mar 18, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 535. Once you have associated a custom route table to your #Azure Kubernetes Cluster, you are not allowed to change that route table. That seems to be a completely arbitrary limitation since you are allowed to change all custom routes, just not the name of the route table. And while they also state it in the docs, it doesn't get explained. Want to use a new route table for your cluster? Easy, deploy a new cluster.

mastodon.social

Mastodon

7
1
1
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Mar 13, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 534. When you read the #Azure Service Principal of the Microsoft Graph application as data source in Terraform, the complete output is around 16000 lines and this data source alone will add approximately 760kB to your Terraform state. That is because this data source contains all of these application's app roles and all OAuth2 permission scopes including their descriptions.

mastodon.social

Mastodon

9
0
3
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Mar 12, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 533. Hey, that's a cool diagram we found there in the #Azure Virtual Network DNS resolution docs.

mastodon.social

Mastodon

3
0
2
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Mar 11, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 532. Does this combination of 'failed' provisioning state and 'all succeeded' status of our #Azure Virtual Machine Scale Set make any sense to you?

mastodon.social

Mastodon

6
0
3
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Feb 11, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 531. Once you have enabled a Web Application Firewall on your #Azure Application Gateway by associating a WAF policy, there is no way to disable the WAF again. The only way to get rid of the WAF is to delete the Application Gateway and recreate it again. That seems like a completely arbitrary limitation and will hit you hard once you decide you no longer want to use the WAF feature.

mastodon.social

Mastodon

9
0
2
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Feb 09, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 530. When creating an #Azure Log Analytics Workspace data export rule through #Terraform and you use a name that does not comply with the naming constraints, the Azure provider will tell you that this name is not allowed, but won't tell you what's wrong.
Tip: The names are not allowed to have an underscore.

mastodon.social

Mastodon

6
1
0
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Feb 06, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 529. When you click on this "Copy to clipboard" in the #Azure Portal in the Application Gateway overiew, it doesn't only copy the gatway's Public IP address but also the name in the brackets. How is that helpful?

mastodon.social

Mastodon

10
1
0
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Feb 05, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 528. On day 425 we showed how #Azure finally introduced a workaround for a limitation in their Private Link DNS integration concept by allowing the Azure DNS resolver to fall back to Public DNS in case a Private Link DNS zone does not have a corresponding DNS record. This could be a really useful feature for Private DNS zones in general, but for some reason you are only allowed to use it for Private Link DNS zones.

mastodon.social

Mastodon

4
0
1
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Feb 04, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 527. The only documentation you can find about supported log categories for the #Azure Application Gateway uses log table names which are for some reason different than the actual log category names. How do you find the names of these log categories to enable them using Terraform when there is no documentation? Easy, just look into the API requests the Azure Portal is doing when you enable them through the GUI.

mastodon.social

Mastodon

11
1
1
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Feb 03, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 526. Following up on the shit from day 514 where the #Azure #Terraform provider tries to read registered Azure providers even though you tell it not to. #Microsoft's response: This is expected behavior and how about you disable enhanced provider validation for ALL of your Terraform providers by setting an environment variable?

mastodon.social

Mastodon

2
0
2
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Jan 27, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 525. With 91 characters, the error "ThirdPartyPrivateLinkServiceProvidedDuringPrivateEndpointCreationDoesNotExistOrIsNotVisible" takes the record for the longest #Azure error name we have seen so far.

mastodon.social

Mastodon

8
1
1
0
Open post
azureshit
Daily Azure Shit @azureshit@mastodon.social · Jan 26, 2026
Daily Azure Shit
@azureshit@mastodon.social

Daily dosis of shit experienced on Microsoft Azure. This account is obviously not affiliated with Microsoft.

mastodon.social

Day 524. Deleting this #Azure VM disk just failed with HTTP error code "undefined".

mastodon.social

Mastodon

4
0
1
0

Remote instance

mastodon.social
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 19:15:10 UTC