Azure Container Apps
Tested with: Azure CLI 2.65 · Container Apps (consumption + dedicated) · Key Vault · PostgreSQL 17
-
Reference the credential from Key Vault using the app’s managed identity.
shell az keyvault secret set --vault-name acme-kv --name databasezy-pg-prod \--value 'postgresql://app:<password>@pg-7f3k.us-east.databasezy.com:5432/app?sslmode=verify-full'az containerapp secret set --name api --resource-group prod \--secrets "database-url=keyvaultref:https://acme-kv.vault.azure.net/secrets/databasezy-pg-prod,identityref:system"az containerapp update --name api --resource-group prod \--set-env-vars DATABASE_URL=secretref:database-url -
Put the environment in your VNet and attach a NAT Gateway with a public IP for stable egress (workload profiles environments), then allow it.
shell az network public-ip create -g prod -n aca-egress --sku Standardaz network nat gateway create -g prod -n aca-nat --public-ip-addresses aca-egressaz network vnet subnet update -g prod --vnet-name main -n aca --nat-gateway aca-natzb api PUT /v1/orgs/{org}/instances/pg-7f3k/network -d '{"allow_cidrs": ["20.0.0.15/32"]}' # replaces the list -
Run migrations as a Container Apps Job triggered from the pipeline.
shell az containerapp job create --name migrate --resource-group prod --environment prod-env \--trigger-type Manual --image acme.azurecr.io/api:1.4.2 --command npx prisma migrate deploy \--secrets "database-url=keyvaultref:https://acme-kv.vault.azure.net/secrets/databasezy-pg-prod,identityref:system" \--env-vars DATABASE_URL=secretref:database-urlaz containerapp job start --name migrate --resource-group prod
- Consumption-only environments have no NAT Gateway; egress addresses change and the allow-list needs
0.0.0.0/0. - Npgsql reads the Windows/Linux trust store;
SSL Mode=VerifyFullneeds noRoot Certificateon Container Apps.