Private Link
Azure Private Link gives a platform service a private address inside your virtual network, so it can be reached without the public internet. The Azure platform puts the data stores, vaults and state of its products behind private endpoints, and the Web App Blueprint publishes its own ingress to Front Door the same way.
What it does
A private endpoint is a network interface in a subnet that maps to one sub-resource of one service, such as the vault of a Key Vault or the blob, dfs or queue service of a storage account. A private DNS zone group on the endpoint writes its address into the matching Private Link zone, so the service's normal name resolves to the private address from every linked network. A Private Link Service works the other way round: it publishes your own internal load balancer so that a consumer, such as Azure Front Door, can connect to it privately after the connection is approved. Once the private path exists, the service's public network access can be turned off.
How BuiltForProd uses it
Every private endpoint lands in an snet-endpoints subnet, where network policies are on so NSGs and routes apply to it, and registers its record in the central zones of Azure Private DNS in acme-core-network.
| Product | Network | Endpoints |
|---|---|---|
| Azure Enterprise Baseline | each stage spoke | The contract vault kv-acme-eus2-<stage>-plat (vault) |
| Azure Enterprise Baseline | the runner network | The state storage account (blob) and the CI platform vault (vault), so the self-hosted runners reach both privately |
| Web App Blueprint | the stage spoke | The application vault (vault), Cosmos DB for MongoDB vCore (MongoCluster), Azure Managed Redis (redisEnterprise) and, on Premium, the SPA storage (blob, for uploads from the runners) |
| Data and ETL Blueprint | the stage spoke | The data lake's blob, dfs and queue services |
The Container Registry can take private endpoints too, on the Premium SKU (private_endpoints in the acr unit, empty by default). The blueprint infrastructure identities hold Private DNS Zone Contributor on the zones' resource group, which is what lets them register their endpoints' records.
Public access. The web app's application vault, Cosmos DB and Managed Redis are private from creation: public network access is disabled. The data lake keeps its public endpoint behind default-deny rules, open only to Event Grid as a trusted service and to the Unity Catalog access connector as a resource instance, the two callers that cannot use a private endpoint. The Baseline's contract vault, CI platform vault and state storage keep public access on with Microsoft Entra authorization on every request until every reader runs on the self-hosted runners, behind public_network_access_enabled in each unit.
Front Door origins on Premium. In staging and prod the Web App Blueprint's Azure Front Door profile is Premium and reaches both origins privately. The internal NGINX ingress controller nginx-internal creates the Private Link Service <prefix>-ingress-pls with one address in snet-pls, where Private Link Service network policies are off; Front Door's API origin connects to it. The SPA origin connects to the storage account's web sub-resource, and with that path the storage account's public network access is disabled. Both connection requests are approved after deployment, and the origin answers 502 until they are. In dev, on Front Door Standard, which has no Private Link, the API is a public origin locked to Front Door and the static website stays publicly readable.
Terms you will see
| Term | Meaning |
|---|---|
| Private endpoint | A network interface in your subnet that maps to one sub-resource of a service. |
| Sub-resource | The service part an endpoint reaches: vault, blob, dfs, queue, web, MongoCluster. |
| Private DNS zone group | The endpoint setting that writes its record into a Private Link zone. |
| Private Link Service | Your own load balancer published for private consumers such as Front Door. |
| Public network access | The service setting that allows or refuses requests over the public endpoint. |
Where to read more
- Azure Enterprise Baseline overview, Azure Web App Blueprint overview and Azure Data and ETL Blueprint overview.
- Azure Private DNS for how the endpoint names resolve.
- Defense in depth for why data stores have no public path.