Application Insights
Application Insights is the application performance monitoring feature of Azure Monitor: request, dependency, exception and trace telemetry from an application, plus synthetic availability tests. The Azure Web App Blueprint creates one Application Insights component per stage on the stage's Log Analytics workspace.
What it does
An Application Insights component receives telemetry that an application sends with an SDK or the Azure Monitor OpenTelemetry distro, identified by its connection string. A workspace-based component stores that telemetry in a Log Analytics workspace, next to the other logs, with that workspace's access and retention. A standard availability test calls a URL on a schedule from several Azure locations and records whether it answered as expected, including the TLS certificate's remaining lifetime; a metric alert on the availability percentage turns failures into an alert.
How BuiltForProd uses it
The app-insights unit creates <prefix>-appi, such as acme-eus2-prd-appi, as a web component on the stage application workspace law-acme-eus2-<stage>-app, which the Baseline publishes in the contract. Sampling is 100%, and the component's retention is 90 days, with 30 days as the option for dev.
The connection string is written to the stage's application vault as appinsights--connection-string, so it is available to the application without being stored anywhere else. The Helm chart in the GitOps repository can map it into the API's environment as APPLICATIONINSIGHTS_CONNECTION_STRING through the External Secrets Operator: externalSecrets.appInsights in values.yaml, off by default, for an image that carries the Azure Monitor OpenTelemetry distro.
The availability test is a stage setting, enable_availability_test, off in dev and on in staging and prod:
| Setting | Value |
|---|---|
| Request | GET https://blueprint-api.<stage>.company.com/health, through Azure Front Door |
| Schedule | Every 5 minutes, from three locations (two in the United States, one in Europe), with retries |
| Passes when | HTTP 200, the body contains healthy, and the certificate has at least 14 days left |
| Alert | <prefix>-api-availability: availability below 99% over 15 minutes, severity 1 |
| Notifies | The platform action group ag-acme-security-alerts, from the contract |
Tests are billed per execution, as the stage file notes. Because the test goes through Front Door, the WAF, the ingress and the pods, a failure means a user would see one too; the test is the outside view, and Container Insights in the same workspace is the inside view.
Terms you will see
| Term | Meaning |
|---|---|
| Component | One Application Insights resource: <prefix>-appi. |
| Workspace-based | Telemetry stored in a Log Analytics workspace, here the stage application one. |
| Connection string | The value an SDK or agent needs to send telemetry to the component. |
| Standard availability test | A scheduled URL check from several locations with response validation. |
| OpenTelemetry distro | Microsoft's packaging of OpenTelemetry that sends to Application Insights. |
Where to read more
- Azure Web App Blueprint overview for the application and its stages.
- Log Analytics for the workspace that stores the telemetry.
- Azure Monitor for the alert route the test uses.