Skip to content

Full private VNet option (no public app endpoint) #16

Description

@troyscott

Description

Add Option 1 architecture: fully private App Service behind a private endpoint, accessible only via Tailscale.

Additional resources

  • Private endpoint for App Service itself
  • VNet /23 instead of /24 to accommodate AzureBastionSubnet (optional)
  • Config flag: NETWORK_MODE=public|private

Acceptance criteria

  • Config toggle between public and private mode
  • App Service private endpoint created in private mode
  • Tailscale is the only way to reach the app in private mode
  • Both modes documented with architecture diagrams

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    infraInfrastructure and Azure resource scriptssecuritySecurity, auth, and networkingtailscaleTailscale integration and VPN

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions