Building blocks
Design goal
Host an App Service workload with deliberate inbound exposure, private access to dependencies, controlled outbound routing, and centralized security telemetry.
Architecture
Public traffic can terminate at Azure Front Door/WAF while the application uses App Service networking controls. Outbound dependency access uses VNet Integration and private endpoints where appropriate.
Architecture decisions
Separate inbound and outbound patterns
WhyPrivate Endpoint controls private inbound access; VNet Integration provides outbound access from App Service into the virtual network.
Trade-offThe separation gives precise control over exposure and egress, but adds DNS, subnet, routing, and troubleshooting complexity compared with an all-public design.
Protect the origin
WhyWhere required, use a front-door/WAF pattern and restrict direct origin access.
Trade-offFront-door and WAF controls reduce direct exposure, but add another availability, certificate, routing, and cost layer in front of the application.
Networking
Make the traffic path explicit. Use App Service networking features according to direction: inbound private access with Private Endpoint, outbound VNet access with VNet Integration.
Security
Protect the control and data paths deliberately. Use managed identity, Key Vault, private endpoints, TLS, WAF policy, least-privilege access, and centralized diagnostics.
Availability
Design for the failure domain that must be survived. Use App Service scale-out and zone-redundancy options where supported by the selected plan and region.
Disaster recovery
Treat regional recovery as a separate operating state. For regional DR, replicate application configuration, dependencies, secrets, and data; use global routing only when the recovery design requires it.
Cost drivers
- App Service plan
- Front Door/WAF
- Private Link
- Key Vault transactions
- SQL/Storage dependencies
- logging
Design assumptions
- Application supports App Service
- Required outbound destinations are known
- DNS for private endpoints is planned
Implementation plan
- Select an App Service tier that supports the required scale, networking, and zone capabilities in the target region.
- Choose the inbound access model—public through Front Door/WAF or private through Private Endpoint—and document how direct origin access is restricted.
- Configure VNet Integration for the outbound subnets, routes, and private dependencies the application actually needs.
- Create Private Endpoints for selected data and platform services, then configure the required Private DNS zones and links.
- Enable Managed Identity for supported service-to-service access and keep unavoidable secrets in Key Vault.
- Send application, platform, WAF, and dependency diagnostics to the intended monitoring workspace and test each network path.
Validate the design
- Confirm the App Service origin cannot be reached through an unintended public path.
- Verify application and administration paths resolve private endpoints to the expected private addresses.
- Test application access to every required private dependency and confirm the traffic follows the intended VNet route.
- Send a controlled request that triggers a WAF/logging event and confirm it appears in the intended monitoring destination.