[kenkilty/aks-anyscale-private-cluster-sample]: confirm the Private Link endpoint approval, private DNS resolution, and the anyscale_platform operator_control_plane_url setting. Private Blob and DFS endpoints resolve and route inside the VNet, so run proof uploads from the Linux jump host rather than the workstation. If bootstrap steps fail, verify the managed identity is present in the configured AKS admin principal map before chasing Terraform errors.

Context: In a private AKS cluster the Anyscale Operator must reach the control plane through Private Link. A silent connectivity gap stops everything.

## Matched source
Source: Source: https://github.com/kenkilty/aks-anyscale-private-cluster-sample/blob/HEAD/docs/modules/module-3-lab-workload.md
Original query: "Anyscale private cluster: Operator cannot reach the control plane over Private Link"
Key terms: anyscale, cannot, cluster, control, link, operator, over, plane, private, reach
