Failing to adjust Front Door (Premium) to talk HTTPS to private CAs via Private Link

Sleiman Bassim 30 Reputation points
2025-06-04T07:14:09.5066667+00:00

Hi,

Is it common sense to make all CAs ingress false (talk privately, so external: false, allowInsecure: false) and have Front Door connect to them without issue?

ISSUE: Setting the frontend CA SPA to external: false returns 404 with AFD and private link

**

Current process

  • Front Door handles client‐side custom domain (www > AFD) and present signed acme ECDSA cert (lets encrypt, RSA keys) at the edge (stored and accessible in key vault)
  • Front Door’s origins use the CA’s ingress azurecontainerapps.io FQDNs

Goal: Front Door HTTPS > Container App

  • Front Door will have to open an HTTPS connection to the private endpoint and complete a TLS handshake against the ingress FQDN managed certs.
  • AFD origins in bicep points to hotstName/originHostHeader by the internal*.azurecontainerapps.io
  • AFD should call the origin FQDNs over HTTPS
Azure Front Door
Azure Front Door

An Azure service that provides a cloud content delivery network with threat protection.


Answer accepted by question author
Anonymous
2025-06-05T11:51:25.6766667+00:00

Hi @Sleiman Bassim

If the nslookup resolving public address, it seems like DNS issue Ensure that the correct virtual network, where your private endpoint is configured, is linked to the private DNS zone. This will ensure that DNS resolution from the VNet will resolve the private endpoint correctly.

Make sure the Azure Front Door configuration has the origin type set to Private Link and Azure Front Door resolves DNS names using public DNS. To ensure AFD can resolve the DNS correctly through the private endpoint, you need to enable Private Link for your AFD to resolve the DNS name privately.

I tested the same in my lab environment, and it worked as expected.

container app ingress settings

User's image


ADF origin Settings

User's image User's image

Container app Environment settings


Note: Make sure to approve the private link origin request in the environment settings to provide access to AFD

User's image

Private endpoint connection

If you create a private endpoint in the container app environment, you will receive an additional endpoint request from AFD origin that needs to be approved in order to allow access from the AFD endpoint.

User's image

Nslookup result from same Vnet


User's image

After configuring all the settings, when I try to access the container app using the AFD endpoint, I am able to access it as shown below.

User's image Reference: Create a private link to an Azure Container App with Azure Front Door

I hope this is helpful! Do not hesitate to let me know if you have any other questions.

I really appreciate your feedback. It’s valuable to us. Please click Accept Answer on this post to assist other community members facing similar issues in finding the correct solution.

Was this answer helpful?

0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.