Key Concepts:
- App Gateway for Containers (AGC)
- Web Application Firewall (WAF)
- Application Load Balancer (ALB) Controller
- Default Rule Set (DRS)
- Custom Rules
- Bot Rule Set
- Kubernetes YAML
- Azure Resource Manager (ARM)
- Azure Service Operator
- Security Policy
- HTTP Routes
- Listeners
- Access Logs
- Firewall Logs
1. Introduction to WAF for App Gateway for Containers
- The video introduces the new Web Application Firewall (WAF) capability for App Gateway for Containers (AGC).
- AGC was designed specifically for containerized workloads in Kubernetes, unlike the original App Gateway which was designed for VMs.
- The key benefit of AGC is that it offloads traffic inspection and protection outside the Kubernetes cluster, preventing attacks from overwhelming the cluster resources.
2. Architecture and Components
- Kubernetes Cluster: Contains the control plane and application pods.
- Application Load Balancer (ALB) Controller: Resides within the Kubernetes cluster and reconciles Kubernetes configurations (ingress, gateway) with the Azure control plane.
- App Gateway for Containers: A separate component outside the Kubernetes nodes that handles request routing and health checks.
- The ALB Controller propagates configurations from Kubernetes to the AGC component.
- The architecture ensures that the Kubernetes cluster is not directly exposed to external attacks.
3. WAF Policy Configuration
- A WAF policy must be created before it can be associated with an AGC instance.
- WAF policies can be created using the Azure portal or ARM templates.
- Default Rule Set (DRS): The required rule set for WAF policies used with AGC. DRS includes Microsoft's additional rules and modifications for better security and reduced false positives.
- DRS is a superset of CRS (Core Rule Set), an open-source rule set.
- Microsoft is moving away from CRS in favor of DRS due to its enhanced features.
- Bot Rule Set: An optional rule set for bot protection.
- Custom Rules: Can be added to the WAF policy for specific requirements.
- Limitations: CRS 3.2 and integration with Microsoft Security Copilot are not supported.
4. Logging
- Access Logs: Provide basic information about client requests, including hostname, path, query string, and IP address.
- Firewall Logs: Provide detailed information about matched rules, blocked requests, and allowed requests.
- The firewall log format is consistent with other WAF implementations.
5. Kubernetes Integration
- The goal is to enable Kubernetes administrators to manage WAF policies using Kubernetes primitives (YAML files).
- The Kubernetes YAML file is used to reference the existing WAF policy.
- A new
Web Application Firewall Policycomponent is created in the YAML file. - The YAML file defines the scope of the policy (gateway, listener, HTTP routes, or path) and the resource ID of the WAF policy.
- Azure Service Operator: Can be used to create Azure resources (including WAF policies) directly from Kubernetes.
6. Deployment and Reconciliation
- When the YAML file is applied to Kubernetes, the ALB Controller reconciles the configuration.
- The ALB Controller relays the configuration to the Azure Resource Manager (ARM).
- A
security policyis created in Azure to map the AGC instance to the WAF policy. This is an internal association for the Azure control plane. - The ALB Controller programs the AGC directly via a "fast path" to enable high-velocity updates.
- The scope defined in the YAML file determines which part of the AGC configuration the policy is applied to.
7. Pricing Model
- The WAF for AGC uses a consumption-based pricing model.
- There is no special SKU required for AGC to use WAF.
- The pricing is based on two meters:
- A flat consumption charge for the time a policy is associated with the AGC instance.
- The number of client requests processed per million.
- If the Bot Rule Set is enabled, client requests are processed twice (once by DRS and once by the Bot Rule Set), resulting in double the billing for those requests.
- There is no additional charge for custom rules.
8. Conclusion
- App Gateway for Containers is the recommended solution for Kubernetes workloads.
- The new WAF capability provides native protection for containerized applications.
- WAF for AGC is integrated with Kubernetes primitives for ease of use.
- The pricing model is consumption-based and differs from traditional App Gateway and Azure Front Door.
Notable Quotes:
- "So, long story short, if I'm running containers and I want that layer 7 load balancing solution, I want to be using App Gateway for containers instead of regular App Gateway."
- "The whole goal of app gateway for containers is I as a Kubernetes developer, as an administrator can focus on Kubernetes primitives."
Technical Terms:
- Layer 7 Load Balancing: Load balancing based on application-level data (e.g., HTTP headers, URLs).
- Ingress: A Kubernetes resource that manages external access to services in a cluster.
- Gateway: A Kubernetes resource that provides a more advanced and flexible way to manage traffic routing.
- Pods: The smallest deployable units in Kubernetes, containing one or more containers.
- YAML: A human-readable data serialization language commonly used for configuration files.
- ARM Template: A JSON file that defines the infrastructure and configuration for an Azure deployment.
- Resource ID: A unique identifier for an Azure resource.
Synthesis/Conclusion:
The video provides a detailed overview of the new WAF capability for App Gateway for Containers. It highlights the architectural benefits, configuration process, and pricing model. The key takeaway is that AGC with WAF offers a Kubernetes-native solution for protecting containerized applications with a consumption-based pricing model. The integration with Kubernetes primitives simplifies management for Kubernetes administrators, while the "fast path" updates ensure high-velocity configuration changes.
AI summaries can miss context or contain errors. Check important details against the original video.





