By default, Azure VMware Tanzu Kubernetes Grid (TKG) management and workload clusters are public facing. They can be configure to be private, which means their API server utilises an Azure internal load balancer (ILB) and is therefore only accessible from within the cluster’s own VNet or peered VNets. I've documented the journey I went through deploying a private VMware TKG onto Azure, which includes: