Quest198z AndrewCi let me answer both questions here.
The main challenge you will face in this requirement is the global layer 7 service provided by Traffic Manager or Front Door. Due to their nature of being global services, they don't provide a full "only Azure" network setup.
- For standard services like Database, you will go full Private link and Internal DNS resolution
- From Front-door you can do private only routing by pointing to AKS via private link
If you are talking about an internal only landing zone, then the only component that cannot be private only is Front door and you need to look at alternative solutions. For example, private DNS, private WAF and private links but the failover will need a manual reconfiguration of the private DNS