如何在Azure应用网关中配置Basic Access Auth?(附Nginx Ingress配置参考)
Great question! When swapping out Nginx Ingress for Azure Application Gateway, setting up Basic Access Auth works a bit differently since App Gateway doesn’t rely on Ingress annotations like Nginx does. Let’s break down how to get this configured:
Option 1: Use Rewrite Rules to Enforce Basic Auth
This is the most straightforward method if you don’t have WAF enabled on your Application Gateway.
Step 1: Generate Base64-Encoded Credentials
First, you need to encode your username:password pair into a base64 string. You can do this via your terminal with:
echo -n "your-username:your-password" | base64
Save the output string—you’ll need it for the next steps.
Step 2: Create a Rewrite Rule Set
- Head to your Application Gateway in the Azure Portal.
- Under Settings, select Rewrite rules.
- Click Add rewrite rule set, give it a descriptive name (e.g.,
BasicAuth-RewriteSet), then click Add rewrite rule. - Name your rule (e.g.,
EnforceBasicAuth), set the rule type to Request routing rule. - Add a Condition:
- Condition type:
HTTP header - Header name:
Authorization - Operator:
Not equal - Value:
Basic <your-base64-string>(replace<your-base64-string>with the output from Step 1)
- Condition type:
- Add Actions:
- First action: Set status code to
401 Unauthorized- Action type:
Set status code - Status code:
401 Unauthorized
- Action type:
- Second action: Add the
WWW-Authenticateheader to prompt users for credentials- Action type:
Set response header - Header name:
WWW-Authenticate - Header value:
Basic realm="Authentication Required"
- Action type:
- First action: Set status code to
- Save the rule set, then associate it with the routing rule that handles your backend traffic.
Option 2: Use WAF Custom Rules (If You Have WAF Enabled)
If your Application Gateway has the Web Application Firewall (WAF) turned on, you can use custom rules to enforce Basic Auth as part of your security policies.
Step 1: Generate Base64-Encoded Credentials
Same as Option 1—encode your username:password pair to base64 using the terminal command provided earlier.
Step 2: Create a WAF Custom Rule
- In the Azure Portal, go to your Application Gateway and select Web application firewall under Settings.
- Navigate to Custom rules and click Add custom rule.
- Name the rule (e.g.,
BasicAuth-Enforcement), set a priority number higher than default rules (like 100, so it runs before other rules). - Add a Condition:
- Condition type:
Request header - Operator:
Does not match - Header name:
Authorization - Value:
Basic <your-base64-string>
- Condition type:
- Set the Action:
- Action:
Block - Response status code:
401 Unauthorized
- Action:
- (Optional) Pair this with a rewrite rule (from Option 1) to add the
WWW-Authenticateheader, which prompts users for login credentials.
Key Note
Unlike Nginx Ingress, Azure Application Gateway doesn’t have native built-in support for Basic Auth via simple annotations. The methods above replicate the same behavior using App Gateway’s native features—rewrite rules for flexible response handling, or WAF rules for security-focused enforcement.
内容的提问来源于stack exchange,提问作者Jerin Joy

