Skip to content

How to configure APIM with Service Fabric managed cluster#301

Draft
jagilber wants to merge 26 commits intoAzure:masterfrom
jagilber:apim
Draft

How to configure APIM with Service Fabric managed cluster#301
jagilber wants to merge 26 commits intoAzure:masterfrom
jagilber:apim

Conversation

@jagilber
Copy link
Copy Markdown
Member

How to configure APIM with Service Fabric managed cluster using new domainNameLabel configuration for static cluster common name connectivity

@jagilber jagilber marked this pull request as ready for review May 21, 2025 19:24
@jagilber jagilber marked this pull request as draft August 12, 2025 17:25
jagilber and others added 12 commits January 11, 2026 09:51
…ation now supported

Major updates:
- Remove outdated limitation - migration now supported (June 2025)
- Add comprehensive 'Enabling stable FQDN on existing clusters' section
- Document Set-AzServiceFabricManagedCluster migration path with PowerShell example
- Include migration steps, retry/revert guidance, and scenario recommendations
- Add Client Certificate Configuration section (thumbprint vs common name)
- Emphasize CRITICAL EKU requirement (Client Authentication 1.3.6.1.5.5.7.3.2)
- Add Certificate Rotation section explaining server vs client cert lifecycle
- Enhance troubleshooting with EKU validation PowerShell script
- Simplify APIM certificate upload (direct approach vs Key Vault)
- Reference official Azure Service Fabric Managed TLS Solution documentation

This update reflects current capabilities as of January 2026.
…ters with static FQDN and domainNameLabelScope
…ings

- Add DNS and Network Connectivity Issues troubleshooting section
  - Documents management plane (FQDN → public IP) vs data plane (VNet routing) architecture
  - Troubleshooting table for common DNS issues (custom DNS, Internal VNet APIM, NSG)
  - Private DNS zone guidance for custom DNS server configurations
  - Notes External VNet mode requirement for SFMC public endpoint access

- Update certificate validation settings based on validated feedback
  - Changed validateCertificateChain and validateCertificateName from false to true
  - Added note: APIM Azure trusted root store includes major public CAs
  - No issuer pinning (issuerCertificateThumbprint) needed for public CA certs

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant