Q: Your AKS cluster hosts internet-facing APIs that require OWASP Top 10 protection, centralized SSL termination, and direct pod IP routing without kube-proxy double-hops. How do you implement Azure Application Gateway Ingress Controller (AGIC) with WAF v2, and tune false-positive WAF rule blocks during API releases?
Production guide for deploying and hardening Application Gateway Ingress Controller (AGIC) on AKS with WAF v2 CRS 3.2 rule tuning, cookie-based affinity, and SSL termination.
Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Provision Application Gateway WAF v2 & Subnet
Deploy dedicated Application Gateway v2 infrastructure with auto-scaling:
- Subnet Allocation: Allocated dedicated subnet (
/24) in the AKS VNet with no other resources:az network vnet subnet create -g rg-aks -n appgw-subnet --vnet-name aks-vnet --address-prefixes 10.240.2.0/24. - WAF v2 Instance: Provisioned App Gateway with WAF_v2 tier, min capacity 2, max capacity 20:
az network application-gateway create -g rg-aks -n appgw-prod --sku WAF_v2 --capacity 2 --autoscale-max 20.
Deploy AGIC via AKS Add-on or Helm with Pod Identity
Install the ingress controller that translates Kubernetes Ingress resources directly into App Gateway configurations:
- Enable AKS Add-on: Enabled native add-on via
az aks enable-addons -n aks-prod -g rg-aks -a ingress-appgw --appgw-id $APPGW_ID. - Direct Pod Routing: AGIC discovers pod IPs directly via Azure CNI and configures them as backend pool members, eliminating NodePort overhead.
Tune WAF v2 Rules & Manage False-Positive Exclusions
Prevent legitimate customer API requests from being blocked by OWASP Core Rule Set (CRS 3.2):
- Detection Mode First: Configured WAF policy in Detection mode initially to audit production requests in Azure Log Analytics:
AGWAccessLogsandAGWFirewallLogs. - Rule Exclusion Rules: Identified false positives on SQL Injection rule
942100on multipart file upload endpoints; created targeted exclusion rules scoped to request header and body path.
Integrate Azure Key Vault for Automated TLS Certificate Renewal
Centralize SSL/TLS certificates without exposing private keys in Kubernetes secrets:
- Key Vault Binding: Bound Application Gateway User-Assigned Managed Identity to Key Vault with secret/certificate get permissions.
- Auto-Sync: App Gateway periodically checks Key Vault for certificate updates, enabling zero-downtime automated certificate renewal.
- Deploy Application Gateway WAF_v2 with autoscale enabled in a dedicated subnet.
- Install AGIC to dynamically synchronize Kubernetes Ingress resources with App Gateway backend pools.
- Tune WAF CRS 3.2 rules using targeted exclusions to eliminate false positives before Prevention mode.
- Mount TLS certificates directly from Azure Key Vault for automated, secure renewals.