NAT Gateway
Azure NAT Gateway gives the subnets it is attached to outbound internet access through its own static public address. The Azure Enterprise Baseline uses it only in the spoke NAT egress mode, where every spoke and the runner network get their own NAT gateway and no traffic passes the hub firewall.
What it does
A NAT gateway performs source network address translation (SNAT) for outbound connections from its subnets: every flow leaves with the gateway's public IP, and only replies come back in. It is zone-resilient within its region, scales its SNAT ports with its public addresses, and closes idle flows after a timeout. It inspects nothing: there are no rules and no logs of destinations. A subnet with a NAT gateway uses it for internet traffic ahead of the default outbound path.
How BuiltForProd uses it
The egress path of every spoke is one switch in network.hcl:
# Egress path for every spoke. "azure_firewall": Azure Firewall in the hub is the default route and the transit
# point (Standard SKU ~$912/month + $0.016/GB; Basic ~$288/month is the switch). "spoke_nat": a NAT Gateway per
# spoke (~$33/month each + $0.045/GB), no central egress, no inspection, spokes cannot reach each other.
# The blueprints follow the mode through the contract value network--firewall-private-ip ("none" in spoke_nat
# mode): the web app AKS cluster uses outbound type userDefinedRouting with the firewall and
# userAssignedNATGateway with the spoke NAT gateway; Databricks and Container Apps support both paths. Choose
# before the first blueprint apply: an AKS cluster with Node Auto Provisioning cannot change its outbound type,
# so switching later means recreating the stage clusters.
hub_egress = "azure_firewall" # @optional: azure_firewall | spoke_nat
hub_egress | Egress path | Between stages | Cost (switch-file comment) |
|---|---|---|---|
azure_firewall (default) | Spoke route table to the Azure Firewall in the hub | Through the firewall's isolation domains | Standard ~$912/month + $0.016/GB |
spoke_nat | A NAT gateway per spoke and per runner network | No path: spokes cannot reach each other | ~$33/month per gateway + $0.045/GB |
In the spoke_nat mode, modules/virtual-network creates <vnet-name>-natgw (Standard, 4-minute idle timeout) with one static public IP <vnet-name>-natgw-pip, and attaches it to every snet-* subnet except snet-endpoints, snet-pls and snet-ingress. That covers snet-aks for the cluster, snet-aca for Container Apps, both Databricks subnets and the runners' snet-aca-runners. The hub never has one; the firewall unit creates nothing, and the spoke route tables stay empty.
The blueprints follow the mode without their own switch. The contract secret network--firewall-private-ip holds the firewall address, or none in this mode. The Web App Blueprint's cluster reads it and uses the outbound type userAssignedNATGateway with the NAT gateway, or userDefinedRouting with the firewall. Databricks and Container Apps work on either path.
Choose the mode before the first blueprint deployment. An AKS cluster with Node Auto Provisioning cannot change its outbound type after creation, so switching later means recreating the stage clusters. The trade is plain: the NAT mode costs less and has fewer moving parts, the firewall mode inspects and logs every flow, enforces the isolation domains and gives every stage the same small set of egress addresses.
Terms you will see
| Term | Meaning |
|---|---|
| Egress mode | The hub_egress switch: azure_firewall or spoke_nat. |
| SNAT | Translation of a private source address to the gateway's public address. |
| Outbound type | How an AKS cluster's nodes reach the internet; it must match the egress mode. |
network--firewall-private-ip | The contract secret that tells the blueprints which mode is active. |
| Default outbound access | Azure's implicit internet path, switched off on every workload subnet here. |
Where to read more
- Azure Enterprise Baseline overview, Azure Web App Blueprint overview and Azure Data and ETL Blueprint overview.
- Azure Firewall for the default egress path.
- Hub-and-spoke networking for central versus per-spoke egress.