पाठ 17 / 25

Private Endpoints and DNS

Reach PaaS services over private IPs and resolve their names correctly.

Taking PaaS services off the public internet

Services such as Storage, Azure SQL, Key Vault and Cosmos DB have public endpoints by default. A private endpoint places a network interface with a private IP from your subnet for a specific resource, so traffic stays on Microsoft's network and you can disable public network access entirely. The tricky part is DNS: clients still use the normal name (stshopdev123.blob.core.windows.net), which must now resolve to the private IP. Azure handles this with a CNAME to a privatelink name, plus a private DNS zone such as privatelink.blob.core.windows.net linked to your VNets. Older service endpoints are simpler: they route traffic from a subnet to the service over the backbone and let the service firewall allow that subnet, but the service keeps its public IP.

Private endpoint plus private DNS zone

Without the DNS zone and the zone group, clients would still resolve the public IP.

SA_ID=$(az storage account show -n stshopdev123 -g rg-shop-dev-cin --query id -o tsv)

az network private-endpoint create -g rg-shop-dev-cin -n pe-st-blob \
  --vnet-name vnet-shop --subnet snet-data \
  --private-connection-resource-id "$SA_ID" --group-id blob --connection-name st-blob

az network private-dns zone create -g rg-shop-dev-cin -n privatelink.blob.core.windows.net
az network private-dns link vnet create -g rg-shop-dev-cin -z privatelink.blob.core.windows.net \
  -n link-shop -v vnet-shop -e false
az network private-endpoint dns-zone-group create -g rg-shop-dev-cin --endpoint-name pe-st-blob \
  -n default --private-dns-zone privatelink.blob.core.windows.net --zone-name blob

az storage account update -n stshopdev123 -g rg-shop-dev-cin --public-network-access Disabled

An internal phone extension

A private endpoint gives the service a desk extension inside your office. People still dial it by name, so the office directory (private DNS) must list the extension, otherwise calls go out to the public number.

त्वरित जाँच: After adding a private endpoint, an app still connects to the storage account's public IP. What is the most likely cause?

  • The storage tier is Cool
  • Private DNS zone is missing or not linked to the app's VNet
  • The NSG priority is 100
  • The account uses ZRS
Answer

Private DNS zone is missing or not linked to the app's VNet — Name resolution must return the private IP; that needs the privatelink DNS zone linked to the client VNet.