<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CloudRunbook | Practical Cloud Engineering</title><description>Practical cloud engineering runbooks, patterns, and weekly change notes with a UK voice.</description><link>https://cloudrunbook.com/</link><item><title>Defender for Cloud baseline: plan coverage, auto-provisioning, and turning recommendations into guardrails</title><link>https://cloudrunbook.com/blog/defender-for-cloud-baseline/</link><guid isPermaLink="true">https://cloudrunbook.com/blog/defender-for-cloud-baseline/</guid><description>A practical Defender for Cloud baseline for Azure landing zones: plan coverage decisions, auto-provisioning, and closing the loop with policy-backed guardrails.</description><pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Private Endpoints + DNS baseline: stop outages before they happen</title><link>https://cloudrunbook.com/blog/private-endpoints-dns-baseline/</link><guid isPermaLink="true">https://cloudrunbook.com/blog/private-endpoints-dns-baseline/</guid><description>A practical baseline for Azure Private Endpoints and DNS: ownership, zone design, resolver routing, and onboarding patterns that prevent midnight outages.</description><pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Identity-first Azure: the baseline every landing zone should start with</title><link>https://cloudrunbook.com/blog/identity-first-azure-baseline/</link><guid isPermaLink="true">https://cloudrunbook.com/blog/identity-first-azure-baseline/</guid><description>A practical identity baseline for secure Azure architecture: admin separation, PIM, Conditional Access, workload identities, and secrets. Written as a runbook you can implement.</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Secure Azure networking baseline: a practical foundation for landing zones</title><link>https://cloudrunbook.com/blog/secure-azure-networking-baseline/</link><guid isPermaLink="true">https://cloudrunbook.com/blog/secure-azure-networking-baseline/</guid><description>A runbook-style secure networking baseline for Azure: hub/spoke vs vWAN, DNS ownership, private endpoints, egress control, and inbound protection. Built to scale.</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Azure Landing Zones: the practical guide (secure-by-default, engineer-friendly)</title><link>https://cloudrunbook.com/blog/secure-landing-zone/</link><guid isPermaLink="true">https://cloudrunbook.com/blog/secure-landing-zone/</guid><description>A hands-on walkthrough of Azure Landing Zones (ALZ): what they are, why they matter, and a runbook-style path to deploying a secure platform foundation.</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Azure Change (Jan 2026): VPN Gateway portal migration for Basic IP on Active-Active</title><link>https://cloudrunbook.com/blog/weekly-azure-change-2026-01-vpn-gateway-basic-ip-migration/</link><guid isPermaLink="true">https://cloudrunbook.com/blog/weekly-azure-change-2026-01-vpn-gateway-basic-ip-migration/</guid><description>Azure VPN Gateway introduces portal-based migration for Basic Public IP on active-active gateways (planned Jan 2026). What it means, who’s affected, and the runbook to prepare.</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate></item></channel></rss>