Azure Front Door
Azure Front Door is Microsoft's global HTTP edge: it terminates TLS close to the user, routes to origins, caches and applies a web application firewall. The Azure Web App Blueprint puts one Front Door profile in front of each stage, with one endpoint for the single-page application (SPA) and one for the API.
What it does
A Front Door profile holds endpoints (the edge host names), custom domains with managed certificates, origin groups of origins with health probes and load balancing, routes that map a domain and path pattern to an origin group, and rule sets that rewrite requests. Routes can cache and compress. The Standard SKU reaches origins over the public internet; Premium adds Private Link origins, which connect to an origin through a private endpoint, and the Microsoft-managed WAF rule sets. A security policy binds a WAF policy to domains.
How BuiltForProd uses it
The front-door unit creates <prefix>-afd in each stage subscription, such as acme-eus2-prd-afd. The SKU is a stage setting, front_door_sku, and the ingress exposure and the SPA origin mode follow it:
| Stage | SKU (stack comment) | API origin | SPA origin |
|---|---|---|---|
| dev | Standard, ~$35/month base | The public IP of nginx-public, locked to Front Door | The storage static website, publicly readable |
| staging, prod | Premium, ~$330/month base | The Private Link Service of nginx-internal | The storage static website over Private Link (web) |
Requests and egress are billed on top of the base price.
Endpoints and routes.
blueprint-app.<stage>.company.comserves the SPA from the storage account's static website. The route redirects HTTP to HTTPS, caches while ignoring query strings, and compresses HTML, CSS, JavaScript, JSON, SVG and text. A rule set rewrites every request whose extension is not a static asset to/index.html, so client-side routes such as/items/42load the application. The origin's health probe is aHEAD /index.htmlevery 120 seconds.blueprint-api.<stage>.company.comserves the API, HTTPS only and uncached; HTTP is not redirected, because a redirect would turn other methods into GET. The health probe isGET /healthevery 30 seconds. Through Private Link, Front Door checks the origin certificate against the host name. The dev public origin is addressed by IP, so only its CA chain is checked; what keeps it Front Door-only is the API's check of theX-Azure-FDIDheader against the profile's ID and an NSG rule that admits only theAzureFrontDoor.Backendservice tag.
Certificates and DNS. Both custom domains use Front Door managed certificates with TLS 1.2 at minimum. The unit writes the _dnsauth TXT validation records and the CNAME records to the endpoints in the stage zone of Azure DNS. Validation completes 10 to 30 minutes after the TXT records exist.
WAF. The WAF policy is built from the template the Baseline publishes and bound to both domains by a security policy, in Prevention mode, with the managed rule sets on Premium; see Azure Web Application Firewall.
Logs. A diagnostic setting sends the WAF log, the log of failed health probes and all metrics to the stage application workspace in Log Analytics. The access log, one record per request (about 1 to 2 GB per million requests), follows the stage switch front_door_access_logs: on in staging and prod, off in dev.
For the code pipeline. The unit records four values in the stage's contract vault (the SPA storage account, both endpoint host names and the profile ID the API checks) and grants the web app code repository's identity CDN Profile Contributor on this profile only, so cd-frontend.yml can purge the cache after an upload. The Private Link connection requests of staging and prod are approved after deployment; until then the origin answers 502.
Terms you will see
| Term | Meaning |
|---|---|
| Profile | The Front Door resource of one stage: <prefix>-afd. |
| Endpoint | An edge host name that custom domains point to with a CNAME. |
| Origin group | The origins of one route, with their health probe and load balancing. |
| Private Link origin | An origin reached through a private endpoint; Premium only. |
| Rule set | Request rewrites applied on a route, here the SPA deep-link rewrite. |
X-Azure-FDID | The header with the profile's ID that Front Door adds and the API checks. |
Where to read more
- Azure Web App Blueprint overview for the request path end to end.
- Private Link for the private origins on Premium.
- Defense in depth for the layers in front of the API.