AGIC
Just to keep an eye on issues.
Alternative
This is the 'normal way to do secure AKS - https://www.starwindsoftware.com/blog/use-an-application-gateway-as-ingress-and-protect-your-aks-websites-with-a-waf
Because, the WAF has the following problem...
Slow Gateway Updates
Goood article - https://medium.com/@danieljimgarcia/the-application-gateway-ingress-controller-is-broken-6aa9eb229881
But this is the fundamental issue - The AGIC design requires AppGW to make guarantees that it simply doesn’t. The design is in itself broken.