Currently the consuming teams can use the vanity url https://*.aihub.gov.bc.ca which is public and works for workloads
but when workloads are within azure we dont need to route through internet and can be done using vnet peering.
- consult with security about keyvault rotataion , is it still needed if it is reaching privately,
- even if key rotation is needed, still reaching over private endpoints would be beneficial from cost perspective which does not put load on the app gateway
- and more to be doumented...