Skip to main content

Private Link

Azure Private Link gives a platform service a private address inside your virtual network, so it can be reached without the public internet. The Azure platform puts the data stores, vaults and state of its products behind private endpoints, and the Web App Blueprint publishes its own ingress to Front Door the same way.

What it does​

A private endpoint is a network interface in a subnet that maps to one sub-resource of one service, such as the vault of a Key Vault or the blob, dfs or queue service of a storage account. A private DNS zone group on the endpoint writes its address into the matching Private Link zone, so the service's normal name resolves to the private address from every linked network. A Private Link Service works the other way round: it publishes your own internal load balancer so that a consumer, such as Azure Front Door, can connect to it privately after the connection is approved. Once the private path exists, the service's public network access can be turned off.

How BuiltForProd uses it​

Every private endpoint lands in an snet-endpoints subnet, where network policies are on so NSGs and routes apply to it, and registers its record in the central zones of Azure Private DNS in acme-core-network.

ProductNetworkEndpoints
Azure Enterprise Baselineeach stage spokeThe contract vault kv-acme-eus2-<stage>-plat (vault)
Azure Enterprise Baselinethe runner networkThe state storage account (blob) and the CI platform vault (vault), so the self-hosted runners reach both privately
Web App Blueprintthe stage spokeThe application vault (vault), Cosmos DB for MongoDB vCore (MongoCluster), Azure Managed Redis (redisEnterprise) and, on Premium, the SPA storage (blob, for uploads from the runners)
Data and ETL Blueprintthe stage spokeThe data lake's blob, dfs and queue services

The Container Registry can take private endpoints too, on the Premium SKU (private_endpoints in the acr unit, empty by default). The blueprint infrastructure identities hold Private DNS Zone Contributor on the zones' resource group, which is what lets them register their endpoints' records.

Public access. The web app's application vault, Cosmos DB and Managed Redis are private from creation: public network access is disabled. The data lake keeps its public endpoint behind default-deny rules, open only to Event Grid as a trusted service and to the Unity Catalog access connector as a resource instance, the two callers that cannot use a private endpoint. The Baseline's contract vault, CI platform vault and state storage keep public access on with Microsoft Entra authorization on every request until every reader runs on the self-hosted runners, behind public_network_access_enabled in each unit.

Front Door origins on Premium. In staging and prod the Web App Blueprint's Azure Front Door profile is Premium and reaches both origins privately. The internal NGINX ingress controller nginx-internal creates the Private Link Service <prefix>-ingress-pls with one address in snet-pls, where Private Link Service network policies are off; Front Door's API origin connects to it. The SPA origin connects to the storage account's web sub-resource, and with that path the storage account's public network access is disabled. Both connection requests are approved after deployment, and the origin answers 502 until they are. In dev, on Front Door Standard, which has no Private Link, the API is a public origin locked to Front Door and the static website stays publicly readable.

Terms you will see​

TermMeaning
Private endpointA network interface in your subnet that maps to one sub-resource of a service.
Sub-resourceThe service part an endpoint reaches: vault, blob, dfs, queue, web, MongoCluster.
Private DNS zone groupThe endpoint setting that writes its record into a Private Link zone.
Private Link ServiceYour own load balancer published for private consumers such as Front Door.
Public network accessThe service setting that allows or refuses requests over the public endpoint.

Where to read more​