How to connect to Azure Container Apps via private endpoint

Pham Ngoc Trung 186 Reputation points
2026-05-31T13:54:02.71+00:00

I have one VM, one Container App, and one Container Apps Environment. All three resources are in the same virtual network. They are configured as follows:

3)The VM has only a private IP address. Its NSG contains only the three default Azure rules for both inbound and outbound traffic.

2)For the Container Apps Environment, the networking configuration is as follows:

  • Public Network Access is disabled.
  • The virtual network is configured to use the subnet that contains the Container Apps.
  • Private Endpoint: one private endpoint is configured.
  1. For the Container App, the networking configuration is as follows:
  • Ingress: Enabled
  • Ingress traffic: Limited to Container Apps Environment
  • Ingress type: HTTP
  • Client certificate mode: Ignore
  • Transport: Auto
  • Insecure connections: Enabled
  • Target port: the application port
  • IP Restrictions: Allow all traffic

I would like to know what additional configuration is required so that I can access the web application deployed on the Container App from the VM. The application is running on the configured target port.

Azure Container Apps
Azure Container Apps

An Azure service that provides a general-purpose, serverless container platform.


Answer accepted by question author

AI answer

2026-05-31T13:54:25.6166667+00:00

To reach the Container App from the VM over a private endpoint, the missing piece is DNS/private DNS configuration for the Container Apps environment and the private endpoint.

From the provided configuration:

  • The VM and Container Apps environment are in the same VNet.
  • Public network access is disabled on the environment.
  • A private endpoint is configured.

To actually resolve and reach the Container App over that private endpoint from the VM, configure DNS as follows.

  1. Create the required private DNS zone
    • For private endpoints to Azure Container Apps, a private DNS zone is required:
      • Zone name: privatelink.{regionName}.azurecontainerapps.io
    • This is the zone used by Azure Private Link for Container Apps environments.
  2. Link the private DNS zone to the VNet
    • Link the VNet that contains the VM to this private DNS zone so that the VM can resolve the Container App endpoint to the private endpoint IP.
  3. Ensure records point to the private endpoint IP
    • In the private DNS zone, configure the A record(s) so that the Container Apps environment default domain (and any relevant hostnames) resolve to the private endpoint’s private IP address.
    • This ensures that when the VM resolves the Container App endpoint, it gets the private IP from the private endpoint, not a public IP.
  4. Verify name resolution and connectivity from the VM
    • From the VM (for example, via Bastion), run:
      • nslookup <CONTAINER_APP_ENDPOINT>
    • Expected result: the name resolves to an address in the VNet (the private endpoint IP), with an alias similar to:
      • <ENVIRONMENT_DEFAULT_DOMAIN>.privatelink.<LOCATION>.azurecontainerapps.io
    • Then browse to http://<CONTAINER_APP_ENDPOINT> from the VM’s browser and confirm the application responds.

Additional notes based on the context:

  • Private endpoints require public network access to be disabled on the Container Apps environment, which is already done.
  • The VM must be in a subnet/VNet that is associated with the private DNS zone so that DNS resolution works.
  • No extra NSG rules are needed on the VM beyond allowing outbound HTTP/HTTPS, since the connection is outbound from the VM to the Container App’s private IP.

Once the private DNS zone and VNet link are in place and the records point to the private endpoint IP, the VM can access the Container App over the private endpoint using the Container App’s endpoint URL.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

2 people found this answer helpful.

2 additional answers

Sort by: Newest
  1. Rakesh Mishra 11,350 Reputation points Microsoft External Staff Moderator
    2026-06-01T11:21:17.73+00:00

    Hello Pham,

    Based on your configuration, you have correctly isolated your Azure Container Apps Environment by setting public network access to disabled and establishing a Private Endpoint. Since the VM and the Container Apps Environment reside within the same Virtual Network, the missing capability is private name resolution.

    When public network access is disabled, Azure's default public DNS records cannot be used to bridge your traffic internally without a corresponding private DNS mapping.

    As stated in the official Microsoft documentation on Private endpoints and DNS for virtual networks in Azure Container Apps environments:

    "To connect to your container apps through a private endpoint, you must configure a private DNS zone.

    Service Subresource: Private DNS zone name:
    Azure Container Apps (Microsoft.App/ManagedEnvironments) managedEnvironment privatelink.{regionName}.azurecontainerapps.io

    To resolve the connection issue from your VM, please apply the following configurations:

    1. Configure the Private DNS Zone
      • Create a new Azure Private DNS Zone named exactly: privatelink.{regionName}.azurecontainerapps.io (replace {regionName} with your environment's deployment region, e.g., eastus).
      • Navigate to the newly created Private DNS Zone, select Virtual network links under settings, and click Add. Link this zone to the Virtual Network where your VM is hosted.
    2. Create the DNS A Record
      Azure Container Apps maps public FQDNs to Private Links via a CNAME chain that points to the environment prefix.
      • Obtain the Default Domain string of your Container Apps Environment (found on the Overview page of the environment). It will look like <unique-id>.<region>.azurecontainerapps.io. Extract the first part, which is the <unique-id> (e.g., witty-island-12345).
      • Obtain the Private IP address allocated to your Container Apps Environment's Private Endpoint.
      • In your Private DNS Zone (privatelink.{regionName}.azurecontainerapps.io), add an A record:
        • Name: <unique-id> (the environment prefix extracted above)
        • TTL: 3600
        • IP address: Your Private Endpoint's private IP address.
    3. Verifying and Connecting from the VM
      Because Azure Container Apps routes traffic to individual containers sharing the same infrastructure using the Host header, you must use the container app's full FQDN when making web requests, and you must use standard HTTP/HTTPS ports (80/443) rather than the container's internal target port.
      • From your VM command-line interface, verify resolution first:
             nslookup <app-name>.<unique-id>.<region>.azurecontainerapps.io
        
        Expected output: The lookup should resolve successfully to the private IP address of your Private Endpoint.
      • Test HTTP connectivity to the web application:
             curl -I http://<app-name>.<unique-id>.<region>.azurecontainerapps.io
        

    Please try above and let me know in comments if it works or any other issues.

    Note: This response is drafted with the help of AI systems.

    Was this answer helpful?

    0 comments No comments

  2. kagiyama yutaka 5,570 Reputation points
    2026-05-31T23:03:45.1733333+00:00

    I think make the VM resolve the Container App FQDN to the Private Endpoint private IP.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.