An Azure service that provides a general-purpose, serverless container platform.
To reach the Container App from the VM over a private endpoint, the missing piece is DNS/private DNS configuration for the Container Apps environment and the private endpoint.
From the provided configuration:
- The VM and Container Apps environment are in the same VNet.
- Public network access is disabled on the environment.
- A private endpoint is configured.
To actually resolve and reach the Container App over that private endpoint from the VM, configure DNS as follows.
- Create the required private DNS zone
- For private endpoints to Azure Container Apps, a private DNS zone is required:
- Zone name:
privatelink.{regionName}.azurecontainerapps.io
- Zone name:
- This is the zone used by Azure Private Link for Container Apps environments.
- For private endpoints to Azure Container Apps, a private DNS zone is required:
- Link the private DNS zone to the VNet
- Link the VNet that contains the VM to this private DNS zone so that the VM can resolve the Container App endpoint to the private endpoint IP.
- Ensure records point to the private endpoint IP
- In the private DNS zone, configure the A record(s) so that the Container Apps environment default domain (and any relevant hostnames) resolve to the private endpoint’s private IP address.
- This ensures that when the VM resolves the Container App endpoint, it gets the private IP from the private endpoint, not a public IP.
- Verify name resolution and connectivity from the VM
- From the VM (for example, via Bastion), run:
-
nslookup <CONTAINER_APP_ENDPOINT>
-
- Expected result: the name resolves to an address in the VNet (the private endpoint IP), with an alias similar to:
-
<ENVIRONMENT_DEFAULT_DOMAIN>.privatelink.<LOCATION>.azurecontainerapps.io
-
- Then browse to
http://<CONTAINER_APP_ENDPOINT>from the VM’s browser and confirm the application responds.
- From the VM (for example, via Bastion), run:
Additional notes based on the context:
- Private endpoints require public network access to be disabled on the Container Apps environment, which is already done.
- The VM must be in a subnet/VNet that is associated with the private DNS zone so that DNS resolution works.
- No extra NSG rules are needed on the VM beyond allowing outbound HTTP/HTTPS, since the connection is outbound from the VM to the Container App’s private IP.
Once the private DNS zone and VNet link are in place and the records point to the private endpoint IP, the VM can access the Container App over the private endpoint using the Container App’s endpoint URL.
References:
- Use a private endpoint with an Azure Container Apps environment (azure-portal)
- Use a private endpoint with an Azure Container Apps environment (azure-cli)
- Networking in an Azure Container Apps environment
- Private endpoints and DNS for virtual networks in Azure Container Apps environments
- Use Azure Front Door Premium with a custom virtual network and Private Link
- Provide a virtual network to an Azure Container Apps environment (azure-cli)