From 54a4367438bde3d580abe5641ca692ec9cf3423f Mon Sep 17 00:00:00 2001 From: Lineska Date: Tue, 21 Jul 2026 12:35:49 +0100 Subject: [PATCH 1/2] fix: Broken link and typos in NGINXaaS docs --- content/nginxaas/google/glossary.md | 2 +- content/nginxaas/google/known-issues.md | 2 +- .../google/monitoring/enable-monitoring.md | 2 +- .../google/monitoring/enable-nginx-logs.md | 2 +- content/nginxaas/google/overview.md | 18 +++++++++--------- 5 files changed, 13 insertions(+), 13 deletions(-) diff --git a/content/nginxaas/google/glossary.md b/content/nginxaas/google/glossary.md index cab953f2b..3e22ba33d 100644 --- a/content/nginxaas/google/glossary.md +++ b/content/nginxaas/google/glossary.md @@ -15,7 +15,7 @@ This document provides definitions for terms and acronyms commonly used in F5 NG | Term | Description | | ------------------------ | -------------------------------------------------------------------------------------| | Authorized Domains | The list of domains allowed to authenticate into the NGINXaaS Account using Google authentication.
- This can be used to restrict access to Google identities within your Google Cloud Organization or Google Workspace, or other known, trusted Workspaces. For example, your Google Cloud Organization may have users created under the `example.com` domain. By setting the Authorized Domains in your NGINXaaS Account to only allow `example.com`, users attempting to log in with the same email associated with `alternative.net` Google Workspace would not be authenticated. | -| Geographical Controller (GC)| Geographical Controller (GC) is a control plane that serves users in a given geographical boundary while taking into account concerns relating to data residency and localization. Example: A US geographical controller serves US customers. See the [Supported Regions]({{< ref "/nginxaas/google/overview.md#supported-regions" >}}) documentation for the full list of geographies where NGINXaaS for Google is available. | +| Geographical Controller (GC)| Geographical Controller (GC) is a control plane that serves users in a given geographical boundary while taking into account concerns relating to data residency and localization. Example: A US geographical controller serves US customers. See the [Supported Regions]({{< ref "/nginxaas/google/overview.md#supported-regions" >}}) documentation for the full list of geographies where NGINXaaS for Google Cloud is available. | | NGINXaas Account | Represents a Google Cloud procurement with an active Marketplace NGINXaaS subscription, linked to a billing account. To create an account, see the signup documentation in [prerequisites]({{< ref "/nginxaas/google/deploy/prerequisites.md" >}}). | | NGINXaaS User | NGINXaaS Users are granted access to all resources in the NGINXaaS Account. User authentication is performed securely via Google Cloud, requiring a matching identity. Individuals can be added as users to multiple NGINXaaS Accounts, and can switch between them using the steps documented below. | | VPC network | A Virtual Private Cloud (VPC) network is a virtual version of a physical network, implemented within Google Cloud. It provides networking functionality for your Google Cloud resources. [More information](https://cloud.google.com/vpc/docs/vpc). | diff --git a/content/nginxaas/google/known-issues.md b/content/nginxaas/google/known-issues.md index 7f5377054..d3198e602 100644 --- a/content/nginxaas/google/known-issues.md +++ b/content/nginxaas/google/known-issues.md @@ -12,4 +12,4 @@ List of known issues in the latest release of F5 NGINXaaS for Google Cloud (NGIN _There are currently no known issues._ -{{< call-out class="note" >}} You may also want to be familiar with the documented [NGINXaaS limitations]({{< ref "nginxaas/google/overview.md#limitations" >}}). {{< /call-out >}} \ No newline at end of file +{{< call-out class="note" >}} You may also want to be familiar with the documented [NGINXaaS limitations]({{< ref "nginxaas/google/overview.md#current-limitations" >}}). {{< /call-out >}} \ No newline at end of file diff --git a/content/nginxaas/google/monitoring/enable-monitoring.md b/content/nginxaas/google/monitoring/enable-monitoring.md index a59bc00c7..d087ba981 100644 --- a/content/nginxaas/google/monitoring/enable-monitoring.md +++ b/content/nginxaas/google/monitoring/enable-monitoring.md @@ -27,7 +27,7 @@ To enable sending metrics to your desired Google Cloud project, you must specify 1. On the navigation menu, select **Deployments**. 1. Select the deployment you want to update and select **Edit**. -1. Enter the project you want metrics to be send to under **Metric Project ID**. +1. Enter the project you want metrics to be sent to under **Metric Project ID**. 1. Select **Update**. ## View NGINXaaS metrics in Google Cloud Monitoring diff --git a/content/nginxaas/google/monitoring/enable-nginx-logs.md b/content/nginxaas/google/monitoring/enable-nginx-logs.md index cf9c95d67..4c61ff931 100644 --- a/content/nginxaas/google/monitoring/enable-nginx-logs.md +++ b/content/nginxaas/google/monitoring/enable-nginx-logs.md @@ -34,7 +34,7 @@ To enable sending logs to your desired Google Cloud project, you must specify th 1. On the left menu, select **Deployments**. 1. Select the deployment you want to update and select **Edit**. -1. Enter the project you want metrics to be send to under **Log Project ID**. +1. Enter the project you want metrics to be sent to under **Log Project ID**. 1. Select **Update**. ## View NGINX logs in Google Cloud Logging diff --git a/content/nginxaas/google/overview.md b/content/nginxaas/google/overview.md index 65973f60a..db3df7e2c 100644 --- a/content/nginxaas/google/overview.md +++ b/content/nginxaas/google/overview.md @@ -12,7 +12,7 @@ f5-product: NGINXaaS for Google Cloud F5 NGINXaaS for Google Cloud is a SaaS offering that is tightly integrated into Google Cloud and its ecosystem of services, making applications fast, efficient, -and reliable bringing advanced traffic services enabled with the commercial version of NGINX, without any of the operational toil. +and reliable. It brings advanced traffic management capabilities from the commercial version of NGINX, without any of the operational toil. [NGINX Plus](https://www.nginx.com/products/nginx/) powers NGINXaaS for Google Cloud, which extends NGINX Open Source with advanced functionality and provides customers with a complete application delivery solution. @@ -52,11 +52,11 @@ The key capabilities of NGINXaaS for Google Cloud are: - NGINXaaS supports request tracing. See the [Application Performance Management with NGINX Variables](https://www.f5.com/company/blog/nginx/application-tracing-nginx-plus) blog to learn more about tracing. - Supports HTTP to HTTPS, HTTPS to HTTP, and HTTP to HTTP redirects. NGINXaaS also provides the ability to create new rules for redirecting. See [How to Create NGINX Rewrite Rules | NGINX](https://blog.nginx.org/blog/creating-nginx-rewrite-rules) for more details. -### Service Frontend +### Service frontend The service frontend of an NGINXaaS deployment controls how client ingress traffic reaches your deployment. There are two frontend types: managed public endpoint and private endpoint. -#### Managed Public Endpoint +#### Managed public endpoint A managed public endpoint frontend allows client access over the internet through a public DNS name created by NGINXaaS in its network. @@ -79,7 +79,7 @@ Access control list (ACL) rules control traffic to a managed public endpoint dep - If you don’t specify a port range, traffic is allowed from any port - Required when you specify a protocol -#### Private Endpoint +#### Private endpoint A private endpoint frontend allows client access through your network by using Google’s [Private Service Connect (PSC)](https://cloud.google.com/vpc/docs/private-service-connect). To set up connectivity, create either a [PSC endpoint](https://docs.cloud.google.com/vpc/docs/private-service-connect#endpoints) for internal traffic or a [PSC backend](https://cloud.google.com/vpc/docs/private-service-connect#backends) for external traffic. This approach brings the NGINXaaS deployment into your client network through an NGINXaaS-created service attachment, so application clients can connect directly into your network. For step-by-step instructions, see [Set up connectivity]({{< ref "/nginxaas/google/deploy/create-deployment/deploy-console.md#set-up-connectivity-private-endpoint-only" >}}). @@ -99,7 +99,7 @@ NGINXaaS uses Google [Private Service Connect](https://cloud.google.com/vpc/docs A [PSC interface](https://cloud.google.com/vpc/docs/private-service-connect#interfaces) brings the deployment into your application network and supports secure connectivity to your applications. By using your own networking resources, you control traffic flow and can apply your preferred security controls. -To connect the NGINXaaS PSC interface to your network, you must create a [network attachment](https://cloud.google.com/vpc/docs/about-network-attachments). For steps, see {{< ref "/nginxaas/google/deploy/create-deployment/deploy-console.md#create-a-network-attachment" >}}. +To connect the NGINXaaS PSC interface to your network, you must create a [network attachment](https://cloud.google.com/vpc/docs/about-network-attachments). For steps, see [Create a network attachment]({{< ref "/nginxaas/google/deploy/create-deployment/deploy-console.md#create-a-network-attachment" >}}). #### Connection draining @@ -110,19 +110,19 @@ During scaling, some connections older than 60 seconds might be reset. The servi An NGINX Capacity Unit (NCU) quantifies the capacity of an NGINX deployment based on its underlying compute resources. This abstraction lets you specify capacity in NCUs without considering hardware differences between regions. You can reserve a minimum capacity for your deployment. The deployment automatically scales up or down based on traffic demand and makes sure it never drops below the reserved minimum. -### Geographical Controllers +### Geographical controllers -NGINXaaS for Google has a global presence, with management requests served by regional controllers. A geographical controller (GC) is a control plane that serves users within a defined geographic boundary while addressing data residency and localization requirements. For example, a US geographical controller serves customers in the United States. NGINXaaS currently operates in three geographies: US, EU, and Asia Pacific (APAC). +NGINXaaS for Google Cloud has a global presence, with management requests served by regional controllers. A geographical controller (GC) is a control plane that serves users within a defined geographic boundary while addressing data residency and localization requirements. For example, a US geographical controller serves customers in the United States. NGINXaaS currently operates in three geographies: US, EU, and Asia Pacific (APAC). ### Supported regions {{< include "/nginxaas/google/supported-regions.md" >}} -## Current Limitations +## Current limitations We are committed to enhancing NGINXaaS for Google Cloud and welcome your feedback to help shape the future of our service. If there are features you'd like to see prioritized, we encourage you to submit a [support ticket]({{< ref "/nginxaas/google/support.md" >}}) to share your suggestions. -Here are the current constraints you should be aware of when while using NGINXaaS for Google Cloud: +Here are the current constraints you should be aware of while using NGINXaaS for Google Cloud: - NGINXaaS is [supported in a limited number of regions]({{< ref "/nginxaas/google/overview.md#supported-regions" >}}). We are continually working to expand support across additional regions. - We only support authentication via Google acting as an identity provider. From 18728b454afff2728d5ed4338fd4bf046889da7a Mon Sep 17 00:00:00 2001 From: Lineska Date: Sat, 5 Sep 2026 14:32:58 +0100 Subject: [PATCH 2/2] fix: Typos and style guide violations in NGINXaaS Azure certificates doc --- .../security-controls/certificates.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/content/nginxaas-azure/quickstart/security-controls/certificates.md b/content/nginxaas-azure/quickstart/security-controls/certificates.md index 1f18040fc..116b4e019 100644 --- a/content/nginxaas-azure/quickstart/security-controls/certificates.md +++ b/content/nginxaas-azure/quickstart/security-controls/certificates.md @@ -40,7 +40,7 @@ If you do not have an NGINXaaS deployment, follow the steps in [Deploy using the ## Add an SSL/TLS certificate to your key vault -Next, you can add an SSL/TLS certificate to your key vault by following [Azure's documentation to import an existing certificiate](https://learn.microsoft.com/en-us/azure/key-vault/certificates/tutorial-import-certificate?tabs=azure-portal), or you can generate a certificate. This tutorial will generate a self-signed certificate to quickly get started. +Next, you can add an SSL/TLS certificate to your key vault by following [Azure's documentation to import an existing certificate](https://learn.microsoft.com/en-us/azure/key-vault/certificates/tutorial-import-certificate?tabs=azure-portal), or you can generate a certificate. This tutorial will generate a self-signed certificate to quickly get started. 1. Go to your key vault, `nginxaas-kv`. 1. Select **Certificates** in the left menu. @@ -61,7 +61,7 @@ Next, you can add an SSL/TLS certificate to your key vault by following [Azure's ## Assign a managed identity to your NGINXaaS deployment -In order for your NGINXaaS deployment to access your key vault, it must have an assinged managed idenity with the `Key Vault Secrets User` role. For more information, see [Assign Managed Identities]({{< ref "/nginxaas-azure/getting-started/managed-identity-portal.md" >}}) and [Prerequisites for adding SSL/TLS certificates]({{< ref "/nginxaas-azure/getting-started/ssl-tls-certificates/ssl-tls-certificates-portal.md#prerequisites" >}}). +In order for your NGINXaaS deployment to access your key vault, it must have an assigned managed identity with the `Key Vault Secrets User` role. For more information, see [Assign Managed Identities]({{< ref "/nginxaas-azure/getting-started/managed-identity-portal.md" >}}) and [Prerequisites for adding SSL/TLS certificates]({{< ref "/nginxaas-azure/getting-started/ssl-tls-certificates/ssl-tls-certificates-portal.md#prerequisites" >}}). 1. Go to your NGINXaaS deployment. 1. Select **Identity** in the left menu. @@ -88,7 +88,8 @@ Now, you can add your SSL/TLS certificate from your key vault to your NGINXaaS d 1. Go to your NGINXaaS deployment. 1. Select **NGINX certificates** in the left menu. 1. Select {{< icon "plus">}}**Add certificate** and provide the following information: - {{< table >}} + + {{< table >}} | Field | Description | |---------------------------- | ---------------------------- | | Name | A unique name for the certificate. For this tutorial, we use `my-cert`. | @@ -98,7 +99,7 @@ Now, you can add your SSL/TLS certificate from your key vault to your NGINXaaS d 1. Select **Select certificate** and provide the following information: - {{< table >}} + {{< table >}} | Field | Description | |----------------------- | ---------------------------- | | Key vault | Select `nginxaas-kv`. | @@ -136,7 +137,7 @@ http { For more information on using NGINX for SSL/TLS termination, see [NGINX SSL Termination](https://docs.nginx.com/nginx/admin-guide/security-controls/terminating-ssl-http/). -### Use case 2: Securing traffic to upstream servers +### Use case 2: Secure traffic to upstream servers NGINXaaS supports backend encryption by encrypting traffic between your NGINXaaS deployment and your upstream servers. @@ -160,8 +161,7 @@ http { For more information on using NGINX to secure traffic to upstream servers, refer to [Securing HTTP Traffic to Upstream Servers](https://docs.nginx.com/nginx/admin-guide/security-controls/securing-http-traffic-upstream/) and [Securing TCP Traffic to Upstream Servers](https://docs.nginx.com/nginx/admin-guide/security-controls/securing-tcp-traffic-upstream/). - -## Restrict Public Access to Key Vault +## Restrict public access to Key Vault If you want to restrict public access to your key vault, you can configure: @@ -173,7 +173,7 @@ If you want to restrict public access to your key vault, you can configure: ### Configure Network Security Perimeter (NSP) -1. Follow [Azure's documentation on prerequisites](https://learn.microsoft.com/en-us/azure/private-link/create-network-security-perimeter-portal#prerequisites) to ensure you are registed to create an NSP. +1. Follow [Azure's documentation on prerequisites](https://learn.microsoft.com/en-us/azure/private-link/create-network-security-perimeter-portal#prerequisites) to ensure you are registered to create an NSP. 1. In the Search box, enter **Network Security Perimeters** and select **Network Security Perimeters** from the search results. 1. Select {{< icon "plus">}}**Create**. 1. In the **Basics** tab, provide the following information: @@ -198,7 +198,7 @@ If you want to restrict public access to your key vault, you can configure: {{< /table >}} 1. Select **Review + Create** and then **Create**. -By default, the key vault will be associated to the NSP in [Learning mode](https://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-concepts#access-modes-in-network-security-perimeter). This means traffic will be evaluated first based on the NSP's access rules. If no rules apply, evaluation will fall back to the key vault's firewall configuration. To fully secure public access, it is reccommended to [transition to Enforced mode](https://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-transition#transition-to-enforced-mode-for-existing-resources). +By default, the key vault will be associated to the NSP in [Learning mode](https://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-concepts#access-modes-in-network-security-perimeter). This means traffic will be evaluated first based on the NSP's access rules. If no rules apply, evaluation will fall back to the key vault's firewall configuration. To fully secure public access, it is recommended to [transition to Enforced mode](https://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-transition#transition-to-enforced-mode-for-existing-resources). 1. Go to resource `nginxaas-nsp`. 1. Select **Associated resources** in the left menu.