// the find
Azure/application-gateway-kubernetes-ingress
This is an ingress controller that can be run on Azure Kubernetes Service (AKS) to allow an Azure Application Gateway to act as the ingress for an AKS cluster.
AGIC is Microsoft's ingress controller for AKS. It runs as a pod in the cluster, watches Ingress and related Kubernetes resources, and translates them into configuration on an Azure Application Gateway. It is for teams that already run AKS and want Application Gateway's L7 features, such as WAF, SSL termination, and cookie affinity, in front of their services.
The Helm chart has snapshot tests, and there is a functional test suite that runs against real gateways, which is more verification than most controllers of this type get. The CRDs (AzureApplicationGatewayRewrite, LoadDistributionPolicy, AzureIngressProhibitedTarget) expose Application Gateway features that the Ingress spec cannot express, and they are documented with examples. The pkg/brownfield package and the prevent-agic-from-overwriting how-to show the maintainers know many people adopt AGIC onto gateways that already exist, and that is the hard case.
Every change goes through an ARM deployment against the gateway, so config propagation is slow and you are exposed to ARM throttling when many Ingresses change at once. AGIC rewrites the gateway's configuration as a whole, so any manual change made in the portal gets clobbered, which is why that how-to exists. Much of the non-standard feature set lives in annotations, which are stringly typed and fail quietly when misspelled, and docs/annotations.md is the only place to check them. The troubleshooting folder has entries for the aad-pod-identity breaking change and for addon identity not found, which is a fair sign that identity setup has been a recurring source of breakage.