Skip to content

Azure Container Apps

Tested with: Azure CLI 2.65 · Container Apps (consumption + dedicated) · Key Vault · PostgreSQL 17

  1. Reference the credential from Key Vault using the app’s managed identity.

    shell
    az keyvault secret set --vault-name acme-kv --name databasezy-pg-prod \
    --value 'postgresql://app:<password>@pg-7f3k.us-east.databasezy.com:5432/app?sslmode=verify-full'
    az containerapp secret set --name api --resource-group prod \
    --secrets "database-url=keyvaultref:https://acme-kv.vault.azure.net/secrets/databasezy-pg-prod,identityref:system"
    az containerapp update --name api --resource-group prod \
    --set-env-vars DATABASE_URL=secretref:database-url
  2. Put the environment in your VNet and attach a NAT Gateway with a public IP for stable egress (workload profiles environments), then allow it.

    shell
    az network public-ip create -g prod -n aca-egress --sku Standard
    az network nat gateway create -g prod -n aca-nat --public-ip-addresses aca-egress
    az network vnet subnet update -g prod --vnet-name main -n aca --nat-gateway aca-nat
    zb api PUT /v1/orgs/{org}/instances/pg-7f3k/network -d '{"allow_cidrs": ["20.0.0.15/32"]}' # replaces the list
  3. Run migrations as a Container Apps Job triggered from the pipeline.

    shell
    az containerapp job create --name migrate --resource-group prod --environment prod-env \
    --trigger-type Manual --image acme.azurecr.io/api:1.4.2 --command npx prisma migrate deploy \
    --secrets "database-url=keyvaultref:https://acme-kv.vault.azure.net/secrets/databasezy-pg-prod,identityref:system" \
    --env-vars DATABASE_URL=secretref:database-url
    az containerapp job start --name migrate --resource-group prod
  • Consumption-only environments have no NAT Gateway; egress addresses change and the allow-list needs 0.0.0.0/0.
  • Npgsql reads the Windows/Linux trust store; SSL Mode=VerifyFull needs no Root Certificate on Container Apps.