When you're hosting apps in Azure Container Apps, you may not want to publish them directly to the internet. Instead, you can protect your Container Apps by only making them accessible through a Web Application Firewall to protect them from common exploits and vulnerabilities. Azure Front Door provides global routing and WAF capabilities to protect our Container Apps.
In this video, I show you how you can configure Azure Container Apps to use Azure Front Door WAF in Bicep, and how you can protect your Container Apps via a WAF Policy.
0:00 Introduction
1:00 Architecture overview
3:20 Creating a Private Link Service using Bicep
9:00 Creating a Subnet for our Private Link Service in Bicep
11:49 Deploying our verifying our Private Link Service
12:18 Creating our Azure Front Door resources in Bicep
21:20 Verifying our AFD Deployment
21:45 Creating our WAF and Security Policies in Bicep
27:03 Approving our Private Link Service and accessing our Container App
29:26 Wrap Up
Grab the code for this video 👩💻🧑💻
Azure Container Apps with Azure Front Door WAF: https://github.com/willvelida/azure-s...
Learn more! 🧠
Networking in Azure Container Apps environment: https://learn.microsoft.com/en-us/azu...
Connect with me! 🤝
Twitter: / willvelida
GitHub: https://github.com/willvelida
Bluesky: https://bsky.app/profile/willvelida.b...