certforge-connector as an Azure Container Instance (ACI) inside your VNet so it can reach F5 BIG-IP, Ribbon SBCs, and other devices on private management addresses. No inbound firewall rules are required — the connector makes outbound calls only.
Prerequisites
- Azure subscription with Contributor rights on the resource group
- An existing VNet that routes to the device management subnet
- NSG rule allowing TCP from the ACI subnet to the device management port (443 by default)
- A CertForge account with admin or operator role
Step 1 — Authenticate
The connector supports two authentication methods. mTLS is recommended — it connects directly to the CertForge agent endpoint on port 8443, bypassing Cloudflare.Option A — mTLS enrollment (recommended)
Run enrollment locally (not inside the container) on any machine withcertforge-connector installed.
In CertForge: Integrations → Connector Agents → + Enroll Agent → Connector — give it a label (e.g. azure-northcentralus) and copy the one-time token.
./azure-creds/:
Store the credentials in an Azure File Share so the container can mount them:
/etc/certforge-connector/creds.
Option B — API key (legacy)
In CertForge: Settings → API Keys → New Key (connector scope). Copy the key — shown once only. You will pass it as a secure environment variable in the steps below.Step 2 — Prepare the subnet
ACI requires a subnet delegated exclusively toMicrosoft.ContainerInstance/containerGroups. A dedicated subnet is cleaner than sharing one with other resources.
In the Azure Portal go to Virtual networks → YOUR_VNET → Subnets → + Subnet:
A delegated subnet cannot contain other resource types (VMs, load balancers). Create a dedicated one.
Step 3 — Create the Container Instance
In the Azure Portal go to Container instances → + Create. Basics tab
Networking tab
Advanced tab — mTLS auth (Option A):
Add environment variables:
Add a volume mount for the Azure File Share:
Advanced tab — API key auth (Option B, legacy):
Add two environment variables:
Set Restart policy to
Always.
Click Review + create, then Create. Deployment takes about 60–90 seconds.
Step 4 — Verify the connector is live
Once running, check the logs:Step 5 — Add the device in CertForge
With the connector inside the VNet, register the device using its private management IP:- Go to Integrations → Network Devices → Add Device
- Set Type to
f5,ribbon, or the appropriate driver - Enter the private management IP and port
- Enter credentials and configure TLS settings
- Click Query Cert to confirm connectivity
Azure CLI equivalent
mTLS auth (Option A)::latest on a running instance: