⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All AWS & Cloud Architecture Interview Questions Scenario 162 of 186 in AWS & Cloud Architecture
Senior DevOps / SRE Azure & Cloud AKS & Application Delivery Ingress & WAF

Q: Your AKS cluster hosts internet-facing APIs that require OWASP Top 10 protection, centralized SSL termination, and direct pod IP routing without kube-proxy double-hops. How do you implement Azure Application Gateway Ingress Controller (AGIC) with WAF v2, and tune false-positive WAF rule blocks during API releases?

Production guide for deploying and hardening Application Gateway Ingress Controller (AGIC) on AKS with WAF v2 CRS 3.2 rule tuning, cookie-based affinity, and SSL termination.

#Azure #AKS #AGIC #Application Gateway #WAF #Ingress
🎙️ Candidate Opening & Architectural Context
"Using external load balancers with Ingress-Nginx introduced an extra network hop and required managing third-party WAF add-ons. We transitioned to Azure Application Gateway Ingress Controller (AGIC) to leverage native Azure CNI pod-level routing and managed WAF v2."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Provision Application Gateway WAF v2 & Subnet

Deploy dedicated Application Gateway v2 infrastructure with auto-scaling:

  • Subnet Allocation: Allocated dedicated subnet (/24) in the AKS VNet with no other resources: az network vnet subnet create -g rg-aks -n appgw-subnet --vnet-name aks-vnet --address-prefixes 10.240.2.0/24.
  • WAF v2 Instance: Provisioned App Gateway with WAF_v2 tier, min capacity 2, max capacity 20: az network application-gateway create -g rg-aks -n appgw-prod --sku WAF_v2 --capacity 2 --autoscale-max 20.
Pro Tip: Application Gateway v2 supports autoscale between min and max capacity, adapting dynamically to traffic spikes without pre-warming.
2️⃣

Deploy AGIC via AKS Add-on or Helm with Pod Identity

Install the ingress controller that translates Kubernetes Ingress resources directly into App Gateway configurations:

  • Enable AKS Add-on: Enabled native add-on via az aks enable-addons -n aks-prod -g rg-aks -a ingress-appgw --appgw-id $APPGW_ID.
  • Direct Pod Routing: AGIC discovers pod IPs directly via Azure CNI and configures them as backend pool members, eliminating NodePort overhead.
Pro Tip: Because AGIC routes packets directly to pod IPs, client source IP addresses are preserved and packet latency drops by 15-20%.
3️⃣

Tune WAF v2 Rules & Manage False-Positive Exclusions

Prevent legitimate customer API requests from being blocked by OWASP Core Rule Set (CRS 3.2):

  • Detection Mode First: Configured WAF policy in Detection mode initially to audit production requests in Azure Log Analytics: AGWAccessLogs and AGWFirewallLogs.
  • Rule Exclusion Rules: Identified false positives on SQL Injection rule 942100 on multipart file upload endpoints; created targeted exclusion rules scoped to request header and body path.
Pro Tip: Always run new WAF deployments in Detection mode for at least two weeks before switching to Prevention mode to avoid blocking legitimate user transactions.
4️⃣

Integrate Azure Key Vault for Automated TLS Certificate Renewal

Centralize SSL/TLS certificates without exposing private keys in Kubernetes secrets:

  • Key Vault Binding: Bound Application Gateway User-Assigned Managed Identity to Key Vault with secret/certificate get permissions.
  • Auto-Sync: App Gateway periodically checks Key Vault for certificate updates, enabling zero-downtime automated certificate renewal.
Pro Tip: Centralizing SSL certificates in Azure Key Vault guarantees that cert rotations occur without restarting AKS ingress pods.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"AGIC integrates Azure Application Gateway directly with AKS, providing direct pod-level routing, automated WAF v2 OWASP protection, and Key Vault-backed zero-downtime SSL termination."
⚡ 60-Second Elevator Pitch Talking Points
  • Deploy Application Gateway WAF_v2 with autoscale enabled in a dedicated subnet.
  • Install AGIC to dynamically synchronize Kubernetes Ingress resources with App Gateway backend pools.
  • Tune WAF CRS 3.2 rules using targeted exclusions to eliminate false positives before Prevention mode.
  • Mount TLS certificates directly from Azure Key Vault for automated, secure renewals.
Advertisement
Want more AWS & Cloud Architecture scenarios?
Explore our complete collection of scenario-based AWS & Cloud Architecture interview runbooks.
Browse All AWS & Cloud Architecture Questions →