Application routing
Application routing is the AKS add-on that runs NGINX ingress controllers which Microsoft operates and patches, together with a DNS integration that writes records for ingress hosts. The Azure Web App Blueprint uses it for every ingress of its clusters: the API origin behind Front Door and the internal hosts such as ArgoCD.
What it does
Each controller is declared as an NginxIngressController custom resource: it gets its own ingress class, its own load balancer described by service annotations (internal or public, subnet, Private Link Service) and a replica range. An Ingress object selects a controller through its class. The add-on can also run a default controller, and its DNS integration creates the records for ingress hosts in the Azure DNS or private DNS zones it is given.
How BuiltForProd uses it
The AKS module turns the add-on on with the default controller off, so every controller and every annotation is in the repository. The ingress unit (module nginx-ingress-controllers) declares the controllers, and their exposure follows the stage's Front Door SKU:
| Controller | Stages | Load balancer | Replicas | Serves |
|---|---|---|---|---|
nginx-internal | All | Internal Standard load balancer in snet-ingress; in staging and prod also the Private Link Service <prefix>-ingress-pls in snet-pls | 2 to 10; 3 to 10 in staging and prod | The API origin on Front Door Premium; ArgoCD |
nginx-public | dev only | Public load balancer on the static IP <prefix>-ingress-pip; the node network security group admits only the AzureFrontDoor.Backend service tag | 2 to 6 | The API origin on Front Door Standard |
Azure Front Door Premium reaches nginx-internal through the Private Link Service, so in staging and prod the API has no public address at all; Front Door's connection request to it is approved after each deployment. Front Door Standard in dev has no Private Link, so nginx-public takes its traffic and the API also checks the X-Azure-FDID header. The code comments price the Private Link Service at ~$7.30/month plus $0.01/GB and the dev public IP at ~$3.65/month. See Private Link for the other private paths.
DNS. The add-on is given the internal zone internal.company.com, and its identity holds Private DNS Zone Contributor on that zone, so it writes the records of internal hosts such as argocd.dev.internal.company.com. Public names belong to Front Door and Azure DNS.
TLS and isolation. TLS terminates at the controller with certificates from cert-manager: a Let's Encrypt certificate for the API host, which Front Door validates, and an internal-CA certificate for ArgoCD. The controllers run in the app-routing-system namespace, and the application's NetworkPolicy admits TCP 8080 from that namespace only.
Terms you will see
| Term | Meaning |
|---|---|
| NginxIngressController | The add-on's resource that declares one managed NGINX controller. |
| Ingress class | The name an Ingress uses to pick its controller: nginx-internal or nginx-public. |
| Exposure | private_link with Front Door Premium, public_locked with Front Door Standard. |
| Private Link Service | The private entry to the internal load balancer that Front Door Premium connects to. |
AzureFrontDoor.Backend | The service tag of Front Door's origin-facing addresses. |
Where to read more
- Azure Web App Blueprint overview for the request path end to end.
- Azure Front Door for the edge in front of the controllers.
- Kubernetes for the NetworkPolicy behind them.