AZ-DEV-150: Azure Container Apps for .NET Microservices
Deploy production-grade .NET 10 microservices on Azure Container Apps. Cover ACA fundamentals, chiseled container builds, KEDA autoscaling, Dapr integration, Container Apps Jobs, VNet integration, Managed Identity, and a full three-service microservices capstone with blue/green revisions, mTLS, and OTel observability.
About This Course
Azure Container Apps (ACA) is Microsoft's serverless-container PaaS the modern default for running Spring Boot, FastAPI, and ASP.NET Core services in Azure. It sits between Azure Functions (function-per-request) and AKS (full Kubernetes) and gives .NET developers a way to run containerized microservices without touching Kubernetes API objects directly.This course teaches ACA from a .NET-microservices perspective. Every module builds up production capabilities: minimal-API .NET 10 services published as chiseled Ubuntu containers, KEDA event-driven scale-to-zero, Dapr sidecars for state and pub/sub, revisions with traffic-weighted blue/green, and full OpenTelemetry observability. The capstone deploys a three-service Anchorline Outdoors system with Dapr, KEDA-scaled workers, MI-authenticated downstream access, private VNet ingress, and distributed tracing across all services.By the end you can deploy .NET 10 microservices on ACA with chiseled images, wire ingress + traffic-weighted blue/green revisions, design KEDA autoscale rules for HTTP and event-driven workloads, integrate Dapr sidecars for state and pub/sub, ship Container Apps Jobs on schedules or event triggers, configure private VNet ingress, use Managed Identity end-to-end, and answer distributed-trace questions in Application Insights.
Course Curriculum
20 Lessons
AZ-DEV-150 M1L1 - Azure Container Apps fundamentals - environments, apps, revisions, ingress
Learn what Azure Container Apps is, where it fits in the compute spectrum (Functions to AKS), and the resource hierarchy - environment, app, revision, replica. This lesson covers workload profiles (Consumption vs Dedicated), ingress options, the ACA cost model, and the comparison against Functions and AKS. By the end you can pick ACA over Functions or AKS with a defensible argument on latency, cost, and operational overhead.
AZ-DEV-150 M1L2 - Deploy a .NET 10 minimal-API microservice to Azure Container Apps - Lab Exercises
Note: This lab pre-provisions an empty resource group at start — allow up to 3 minutes for it to become ready before beginning the exercises.
Provision an Azure Container Apps environment yourself using the Azure CLI — Log Analytics workspace, Azure Container Registry, and the ACA managed environment wired to your workspace (the env create alone takes ~3–5 minutes). Then publish a .NET 10 minimal API as a container using dotnet publish /t:PublishContainer, push it to your ACR, deploy as a Container App with external ingress, follow logs live, and roll a new revision.
AZ-DEV-150 M2L3 - Building images for ACA - chiseled Ubuntu, SDK containers, and ACR
Cover the modern .NET container-build stack: dotnet publish /t:PublishContainer (no Dockerfile), chiseled Ubuntu base images (smaller attack surface + faster cold start), ACR build tasks, and image scanning with Microsoft Defender for Containers. By the end you can produce a production-grade image from a minimal API without hand-writing a Dockerfile.
AZ-DEV-150 M2L4 - Build a chiseled image, compare sizes, and use az acr build - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Build the same .NET 10 minimal API two ways: chiseled Ubuntu (small) and full Ubuntu (large); measure the delta. Then use az acr build for a server-side build without a local Docker daemon. Push both images and deploy the chiseled one.
AZ-DEV-150 M3L5 - Ingress and traffic splitting - external, internal, TCP, and blue/green revisions
Container Apps ingress modes (external HTTPS, internal HTTPS, TCP, disabled), the revision model, and how to blue/green deploy by splitting traffic weights across active revisions. By the end you can promote a v2 revision from 0% to 100% and rollback with a single command.
AZ-DEV-150 M3L6 - Canary v2 rollout with traffic-weighted revisions - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Deploy v1 of the Anchorline OrderApi, deploy v2 as a new revision at 0%, gradually shift 20% then 100% traffic, then roll back to v1 by re-weighting. Along the way, watch a curl loop hit different revisions and verify the split empirically.
AZ-DEV-150 M4L7 - KEDA autoscaling - HTTP concurrency, event-driven scalers, and scale-to-zero
Container Apps' autoscale engine is KEDA. This lesson covers HTTP-concurrency scalers, event-driven scalers (Service Bus, Event Hubs, Kafka, Redis Streams), scale-to-zero mechanics, cold-start considerations, and min/max replica configuration. By the end you can pick the right scaler for a workload and configure it correctly.
AZ-DEV-150 M4L8 - Watch KEDA scale a Service Bus consumer from 0 to N and back - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Build a .NET 10 Service Bus queue consumer, deploy it with a KEDA Service Bus scaler (0 to 10 replicas triggered by queue depth), push 5000 messages and watch the replica count climb, then let it drain and confirm scale-to-zero.
AZ-DEV-150 M5L9 - Dapr integration - sidecars, state, pub/sub, and service invocation
Dapr sidecars in Container Apps: state stores (Redis, Cosmos), pub/sub (Service Bus, Redis Streams), input/output bindings, service-to-service invocation with automatic mTLS, and Dapr components. By the end you can architect two microservices communicating via Dapr pub/sub.
AZ-DEV-150 M5L10 - Wire two microservices with Dapr pub/sub and state store - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Deploy Anchorline's OrderApi (publisher) and OrderProcessor (subscriber) with Dapr sidecars. OrderApi publishes OrderCreated events via Dapr pub/sub (Service Bus backend). OrderProcessor subscribes and persists to Cosmos via Dapr state store. Verify end-to-end.
AZ-DEV-150 M6L11 - Networking - VNet-integrated environments and private ingress
Custom VNet-integrated ACA environments, workload profile requirements for VNet, private (internal-only) ingress, UDRs for egress control, and private DNS zones for private-endpoint access to downstream Azure services. By the end you can design a network topology where the ACA environment is on a private VNet reachable only from your on-prem network via ExpressRoute or VPN.
AZ-DEV-150 M6L12 - Deploy an internal-only Container App on a VNet-integrated environment - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Provision a VNet + VNet-integrated ACA environment with internal-only ingress. Deploy the Anchorline microservice, verify it's unreachable from public internet but reachable from an on-VNet jumpbox. Front it with Azure Front Door for controlled public access.
AZ-DEV-150 M7L13 - Managed Identity in Container Apps
System-assigned vs user-assigned MI on Container Apps, DefaultAzureCredential in containerized .NET, scoping MI to specific services, multi-identity apps for cross-service access. By the end you can wire an MI-backed ACA app to Cosmos, Key Vault, and Storage without any secrets on disk.
AZ-DEV-150 M7L14 - MI-authenticated ACA app calling Key Vault, Cosmos, and Storage - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Assign a User-Assigned MI to an ACA microservice. Grant it Key Vault Secrets User + Cosmos Data Contributor + Storage Blob Data Reader. Confirm all three downstream calls succeed via DefaultAzureCredential with zero secrets in code or config.
AZ-DEV-150 M8L15 - Container Apps Jobs - scheduled and event-driven batch workloads
Container Apps Jobs are the batch-workload sibling to Container Apps. This lesson covers the three trigger types (manual, scheduled via cron, event-driven via KEDA), parallelism configuration, retries, timeouts, and how Jobs compare to Azure Functions timer triggers. By the end you can pick between an ACA Job and a Function timer for a batch workload.
AZ-DEV-150 M8L16 - Ship a scheduled ACA Job and an event-driven ACA Job - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Deploy two Container Apps Jobs: one scheduled via CRON 0 2 * * * (nightly ETL) and one event-driven triggered by Service Bus queue depth. Verify both execute to completion and cost nothing between runs.
AZ-DEV-150 M9L17 - Observability - OpenTelemetry, Application Insights, and distributed tracing
Container Apps environments include a managed OpenTelemetry Collector that can send telemetry to Application Insights. This lesson covers instrumenting .NET services with OpenTelemetry.Extensions.Hosting, the ACA environment-level OTel config, distributed tracing across Dapr sidecars, and reading traces in App Insights. By the end you can answer "which service caused the slow request?" from a distributed trace.
AZ-DEV-150 M9L18 - Instrument a two-service app with OTel and read a distributed trace - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Add OpenTelemetry.Extensions.Hosting + Azure Monitor exporter to two Anchorline microservices. Wire them to Application Insights. Post an order; follow the trace end-to-end in App Insights Transaction Search.
AZ-DEV-150 M10L19 - Microservices architecture review and production readiness
Consolidate the course into architectural principles for shipping ACA microservices: bounded contexts, service-to-service auth, deploy strategies, rollback plans, capacity planning, and cost. By the end you can defend a full microservices topology and its operational plan.
AZ-DEV-150 M10L20 - Ship the Anchorline three-service microservices platform - Capstone - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.
Build the Anchorline platform end-to-end: OrderApi (external ingress, MI to Cosmos), OrderProcessor (KEDA Service Bus scale-to-zero worker), NotificationService (Dapr pub/sub subscriber), all instrumented with OTel and deployed as v1. Then blue/green promote OrderApi to v2 with traffic-weighted revisions, simulate a failure, and rollback.