Not Full AirGapped is possible with IPI mode.
The issue is that inside of the VNet, the Machine-Config-Operator is not able to reach the API of the Azure Resource Manager through an internal IP or DNS, because it's ONLY available in a Public IP / DNS resolution. Not a Virtual Private Endpoint is available for this internal VNET <-> Azure Resource Manager connection
- NOTE: No MachineSet are allowed in this mode. The issue is that inside of the VNet, the Machine-Config-Operator is not able to reach the API of the Azure Resource Manager through an internal IP or DNS, because it's ONLY available in a Public IP / DNS resolution.
Not a Virtual Private Endpoint is available for this internal VNET <-> Azure Resource Manager connection