Attaching a private static ip address to Azure Container Instance

Viewed 4174

I am searching for a solution with static private IPs for my container instances. I will add the Application Gateway to it to also have a static public IP for it.

I am checking https://stackoverflow.com/a/59168070/7267638 and it looks good until "Add the private IP of the container instance into the backend pool of the application gateway". The point which is not clear to me is what to do when I restart the container and add others in the meantime - it can end up with different private IPs.

I need to have them static not only to be able to configure backend pool for the Gateway, but also for internal routing purposes. Without some kind of static config, I would need to reconfigure all services after private IP change to be able to find each other again.

Maybe can I use some kind of internal DNS or use container names or so?

3 Answers

Private static IPs for ACI is (as of today) not supported. I don't think there is a real workaround here except for checking after a container has been (re-)started if the IP has been changed.

Your best bet might be to use subnets of the minimum required size when putting ACI into a subnet - and only use one ACI per subnet. This way the chance might be lower that the IP actually changes, but still no guarantees there.

I have been having the same issue and solved it with the alternative @silent mentions. I created a 29'er subnet, which is the smallest you can create on Azure with 3 available addresses (the other 5 are reserved), per Azure Container Instance I am hosting. I register all three available addresses in the backend pool in application gateway, so that it can forward requests to the IP address of the instance. The built-in probing seems to just do this.

I have implemented the following

  • Azure Alert that monitors the ACI Restart event
  • Triggers an Azure Function
  • Azure Function keeps Azure Private DNS up-to-date with latest IP

The function calls the API and get the new IP, then updates DNS. I have a short lived TTL on private DNS. The zone is only within my VPN.

This is not a perfect solution as this can mean 5 mins of downtime. However, I also have Azure Application Gateway and 3 instances. It's unlikely that all three instances would restart at the same time, and if they did, downtime would be inevitable.

Related