DEV Community

Cover image for Part 3: Deploying a Container App with Managed Identity, Service Bus, and HTTP Scaling
Rahimah Sulayman
Rahimah Sulayman

Posted on

Part 3: Deploying a Container App with Managed Identity, Service Bus, and HTTP Scaling

Introduction

Employers want engineers who can take an app from a registry to a running, secure, scalable service.

The scenario: At Fabrikam Inc., the registry is secured and the DevOps team is ready to deploy. The container app must run inside the virtual network, pull its image from Azure Container Registry, connect to Service Bus without a stored password, and scale to a maximum of two replicas to control costs.

In Part 3, I deploy the container app to VNET1/ACASubnet, attach a user-assigned managed identity, connect it to Service Bus, and configure an HTTP scale rule. I then verify everything with the Azure CLI.

In this exercise, you will deploy a container app from an image in the Azure Container Registry to the Azure Container Apps platform.

The following Azure resources must be available in your Resource group named RG1:

  • A Container registry instance that contains one image.
  • A Virtual network with subnets.
  • A Service Bus Namespace
  • A Managed Identity
  • A Private endpoint

You've been asked to configure a container app that meets the following requirements:

  • Is deployed to VNET1/ACASubnet.
  • Pulls an image from a container registry.
  • Authenticates using a user-assigned managed identity (uai-az2003).
  • Uses Container App to connect to a Service Bus instance using the .NET client type.
  • The app can run up to two replicas that are added whenever there are 10,000 HTTP concurrent requests.

You complete the following tasks during this exercise:

1.Create a container app that uses an ACR image

2.Configure the container app to authenticate using the user assigned identity

3.Configure a connection between the container app and Service Bus

4.Configure HTTP scale rules

5.Verify the configuration

Create a container app that uses an ACR image

Complete the following steps to create a container app that uses an ACR image.

1.Open your Azure portal.

2.On the top search bar, in the Search textbox, enter container app

aca

3.In the search results under Services, select Container Apps.

4.Select Create.

aca

5.On the Basics tab, specify the following:

  • Subscription: Specify the Azure subscription that you're using for this guided project.

  • Resource group: RG1

  • Container app name: aca-az2003

  • Region: Select the Region specified for VNET1 (Central US).

The container app needs to be in the same region/location as the virtual network so you can choose VNET1 for the managed environment. For this guided project, keep all of your resources in the region/location specified for your resource group.

  • Container Apps Environment: Select Create new.

createnew

6.On the Create Container Apps Environment page, select the Networking tab, and then specify the following:

  • Use your own virtual network: Select Yes.
  • Virtual network: Select VNET1.
  • Infrastructure subnet: ACASubnet.

Note

If the ACASubnet subnet is not listed, open your virtual network resource, adjust the subnet address range to 10.0.2.0/23 and retry the steps to create the Container App.

7.On the Create Container Apps Environment page, select Create.

capage

8.On the Create Container App page, select the Container tab, and then specify the following:

  • Use quickstart image: Ensure that this setting is not selected. If it is selected, uncheck this setting.
  • Name: Enter aca-az2003
  • Image source: Ensure that Azure Container Registry is selected.
  • Registry: Select your container registry. For example: acraz2003cah.azurecr.io
  • Image: Select aspnetcorecontainer
  • Image tag: Select latest

9.Select Review + create.

reviewncreate

10.Once verification has Passed, select Create.

create

11.Wait for the deployment to complete.

Note

This deployment normally takes 3-5 minutes to complete, but may take up to 10 minutes.

Configure the container app to authenticate using the user assigned identity

Complete the following steps to configure the container app to authenticate using the user assigned identity.

1.On the Azure portal, open the Container App that you created.

2.Under Security, select Identity.

3.Select the tab for User assigned.

4.Select Add user assigned managed identity.

uami

5.On the Add user assigned managed identity page, select uai-az2003, and then select Add.

add

Note

Support for Service Connector (preview) on Azure Container Apps ended on March 30, 2026, and after that date new service connections aren't available.

Configure a connection between the container app and Service Bus

Complete the following steps to configure a connection between the container app and Service Bus.

1.On the Azure portal, ensure that you have your Container App open.

2.Under Settings, select Service Connector (Preview).

3.Select Connect to your Services.

4.On the Create connection page, specify the following:

  • Service type: Select Services Bus.
  • Client type: Select .NET.

5.Select Next: Authentication.

6.On the Authentication tab, select User assigned managed identity.

7.Ensure that the correct subscription and user assigned managed identity are selected.

Subscription: The Azure subscription that you're using for this guided project. User assigned managed identity: uai-az2003

8.To change tabs, select Review + Create.

9.Once the Validation passed message appears, select Create.

10.Wait for the connection to be created.

It can take a minute before the Service Connector page updates with the new connection.

Configure HTTP scale rules

1.Ensure that your Container App is open in the portal.

2.On the left-side menu under Application, select Revisions and replicas.

3.Notice the Name assigned to your active revision.

active

4.On the left-side menu under Application, select Containers.

5.To the right of Based on revision, ensure that your active revision is selected.

basedonrevision

6.On the left-side menu under Application, select Scale.

7.Configure the Min / max replicas as follows:

  • Set Min replicas: 0
  • Set Max replicas: 2

8.Under Scale rule, select + Add.

add

9.On the Add scale rule page, specify the following:

  • Rule name: Enter scalerule-http
  • Type: Select HTTP scaling.
  • Concurrent requests: Set the value to 10,000.

10.On the Add scale rule page, select Add scale rule.

scalerule

11.On the Create and deploy new revision page, select Create.

12.Ensure that your new scale rule is displayed.

scalerule

Check your work

In this task, you verify that your configuration meets the specified requirements.

1.In the Azure portal, ensure that your Container App resource is open.

2.On the left-side menu, under Settings, select Deployment.

3.At the top of the page, ensure that the Continuous deployment tab is selected.

4.Verify that the expected Registry settings are reported:

  • Repository source: Azure Container Registry
  • Registry: the name of your Container Registry (for example: acraz2003cah)
  • Image: aca-az2003

image

5.Close the Container App page.

ca

6.Open your Container Apps Environment resource.

7.Verify that your Container App uses the proper subnet as follows:

  • On the Overview page, verify that Virtual Network is set to VNET1.
  • On the Overview page, verify that Infrastructure subnet is set to ACASubnet.

vnet

8.In the Azure portal, open the Cloud Shell and the switch to PowerShell.

Run the following command:

az containerapp connection show --connection servicebus_b2a10 --name aca-az2026 --resource-group RG1

I ran this instead because there's no container app connection yet. I used az containerapp connection create servicebus with these parameters:

Parameter Value
--connection sb_az2026_rah
--resource-group RG1
--name aca-az2026
--target-resource-group RG1
--namespace sb-az2026-rah
--user-identity client-id=<your-client-id> subs-id=<your-subscription-id>
--container aca-az2026
--client-type dotnet

succeeded

The connection was created. The output shows "provisioningState": "Succeeded", and the connection is named sb_az2026_rah on aca-az2026.

Note:

The connection added two environment variables to your container:
AZURE_SERVICEBUS_FULLYQUALIFIEDNAMESPACE = sb-az2026-rah.servicebus.windows.net
AZURE_SERVICEBUS_CLIENTID = your identity's client ID (a55ff84a-...)

This means the app can use these to reach Service Bus with the managed identity, with no connection string or password.

10.Verify that the targetService properties match the specified configuration.

To confirm it's healthy, run:

az containerapp connection validate --connection sb_az2026_rah --name aca-az2026 --resource-group RG1

validated
The results should show success for each check.

To confirm the identity has permission on the Service Bus. The connection normally grants this automatically, but the output shows "roles": null, so it's worth a quick look:You should see a Service Bus role, such as Azure Service Bus Data Owner, on sb-az2026-rah. If there's none, your app will get authorization errors when it tries to send or receive messages.

Run:

az role assignment list --assignee a55ff84a-54e6-4b57-8db0-c20de0e3effb --all -o table
Enter fullscreen mode Exit fullscreen mode

role

Permissions are in place. The identity has both roles it needs on sb-az2026-rah:

Azure Service Bus Data Sender lets your app send messages.
Azure Service Bus Data Receiver lets your app receive messages.

The AcrPull role is a separate permission that lets the app pull its image from your container registry, so it's fine to have too.

Your setup is complete: the identity is attached to aca-az2026, the connection sb_az2026_rah succeeded, and the roles are assigned.

To verify your HTTP scale rule, you would need to run testing software that's able to simulate 10,000 concurrent HTTP requests and ensure that container replicas are created.

Summary

Cloud and DevOps practitioner building hands-on Azure skills through a five-part series on Azure Container Apps.

Part 3 covers deploying and connecting the container app:

Deployed a container app from an Azure Container Registry image into VNET1/ACASubnet
Attached a user-assigned managed identity for passwordless authentication
Connected the app to Service Bus using the .NET client type, with no connection string
Configured an HTTP scale rule (0 to 2 replicas, 10,000 concurrent requests)
Verified the connection and role assignments (Service Bus Data Sender and Receiver) with the Azure CLI

Skills practiced:

Azure Container Apps, Managed Identity, Service Bus, Service Connector, Azure CLI, Autoscaling, Azure RBAC

Top comments (2)

Collapse
 
rahimah_dev profile image
Rahimah Sulayman •

One of the steps in this guided project relied on the Service Connector portal page, which Microsoft has retired for Azure Container Apps. Instead of stopping there, I created the Service Bus connection from the Azure CLI, confirmed it with the validate command, and documented the workaround so others aren't stuck. I enjoy troubleshooting changes like this in cloud tooling. I'm looking for DevOps and cloud opportunities, so feel free to reach out.

Collapse
 
rahimah_dev profile image
Rahimah Sulayman •

Part 3 brings together what I care about in cloud deployments: the app runs inside a private network, authenticates to Service Bus with a managed identity (no stored passwords), and scales between 0 and 2 replicas to control cost. I verified each piece with the Azure CLI rather than assuming it worked. Two more parts to go. Connect with me if you're hiring for cloud or DevOps roles.