Skip to main content

Application routing

Application routing is the AKS add-on that runs NGINX ingress controllers which Microsoft operates and patches, together with a DNS integration that writes records for ingress hosts. The Azure Web App Blueprint uses it for every ingress of its clusters: the API origin behind Front Door and the internal hosts such as ArgoCD.

What it does​

Each controller is declared as an NginxIngressController custom resource: it gets its own ingress class, its own load balancer described by service annotations (internal or public, subnet, Private Link Service) and a replica range. An Ingress object selects a controller through its class. The add-on can also run a default controller, and its DNS integration creates the records for ingress hosts in the Azure DNS or private DNS zones it is given.

How BuiltForProd uses it​

The AKS module turns the add-on on with the default controller off, so every controller and every annotation is in the repository. The ingress unit (module nginx-ingress-controllers) declares the controllers, and their exposure follows the stage's Front Door SKU:

ControllerStagesLoad balancerReplicasServes
nginx-internalAllInternal Standard load balancer in snet-ingress; in staging and prod also the Private Link Service <prefix>-ingress-pls in snet-pls2 to 10; 3 to 10 in staging and prodThe API origin on Front Door Premium; ArgoCD
nginx-publicdev onlyPublic load balancer on the static IP <prefix>-ingress-pip; the node network security group admits only the AzureFrontDoor.Backend service tag2 to 6The API origin on Front Door Standard

Azure Front Door Premium reaches nginx-internal through the Private Link Service, so in staging and prod the API has no public address at all; Front Door's connection request to it is approved after each deployment. Front Door Standard in dev has no Private Link, so nginx-public takes its traffic and the API also checks the X-Azure-FDID header. The code comments price the Private Link Service at ~$7.30/month plus $0.01/GB and the dev public IP at ~$3.65/month. See Private Link for the other private paths.

DNS. The add-on is given the internal zone internal.company.com, and its identity holds Private DNS Zone Contributor on that zone, so it writes the records of internal hosts such as argocd.dev.internal.company.com. Public names belong to Front Door and Azure DNS.

TLS and isolation. TLS terminates at the controller with certificates from cert-manager: a Let's Encrypt certificate for the API host, which Front Door validates, and an internal-CA certificate for ArgoCD. The controllers run in the app-routing-system namespace, and the application's NetworkPolicy admits TCP 8080 from that namespace only.

Terms you will see​

TermMeaning
NginxIngressControllerThe add-on's resource that declares one managed NGINX controller.
Ingress classThe name an Ingress uses to pick its controller: nginx-internal or nginx-public.
Exposureprivate_link with Front Door Premium, public_locked with Front Door Standard.
Private Link ServiceThe private entry to the internal load balancer that Front Door Premium connects to.
AzureFrontDoor.BackendThe service tag of Front Door's origin-facing addresses.

Where to read more​