In Container Apps, turning this on exposes an app over TCP or HTTP, either to the internet or just within its environment, and no load balancer needs creating. AKS handles it differently: Ingress resources carry rules, and an ingress controller enforces them.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Ingress in context, with comparison tables and the common traps.
Terms in this definition
- Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- TCP
A transport protocol that is connection-oriented.
- HTTP
Hypertext Transfer Protocol, which sends data in clear text; VCF interfaces and APIs instead use HTTPS.
- Azure Machine Learning environment
Versioned asset that pairs a Docker image with a pip or conda specification, so every job or deployment using it gets identical dependencies. You point to it by name plus a version number, or by name with @latest.
- ELT
Extract, load, transform: raw data lands in the target system first and is transformed there. See ETL for the opposite order.
- AKS
Short for Azure Kubernetes Service, a managed Kubernetes offering that gives full control of clusters and node pools. Scaling uses the cluster autoscaler and Horizontal Pod Autoscaler; user sign-in is not built in.
Related terms
- Application Gateway for Containers
Recent Application Gateway-based option for load balancing and ingress on AKS, offered as an alternative to AGIC.
- Application Gateway Ingress Controller
Add-on for AKS that reads Kubernetes Ingress resources and sets up an Application Gateway, WAF v2 included, to match them.
- Application routing add-on
Managed NGINX ingress for AKS, deployed and run as an add-on, integrated with Azure DNS and with certificates held in Key Vault. Its NGINX version is supported only until the end of November 2026, after which the Gateway API version takes over.
- Gateway API
Newer Kubernetes API replacing Ingress for handling incoming and layer-7 traffic. On AKS it is provided through application routing as GatewayClass approuting-istio, taking over from the managed NGINX add-on.
- HTTP application routing
AKS ingress add-on, since retired, that came without Azure WAF.
- NGINX
Open-source reverse proxy and web server underpinning the Ingress NGINX controller for AKS, which lacks Azure WAF. Upstream maintenance stopped in March 2026 and Gateway API succeeds it.
- VPN Gateway NAT
Handles overlapping prefixes between on-premises networks and VNets on site-to-site connections by translating them with ingress and egress NAT rules on the VPN gateway.