Skip to main content

Azure Front Door

Azure Front Door is Microsoft's global HTTP edge: it terminates TLS close to the user, routes to origins, caches and applies a web application firewall. The Azure Web App Blueprint puts one Front Door profile in front of each stage, with one endpoint for the single-page application (SPA) and one for the API.

What it does​

A Front Door profile holds endpoints (the edge host names), custom domains with managed certificates, origin groups of origins with health probes and load balancing, routes that map a domain and path pattern to an origin group, and rule sets that rewrite requests. Routes can cache and compress. The Standard SKU reaches origins over the public internet; Premium adds Private Link origins, which connect to an origin through a private endpoint, and the Microsoft-managed WAF rule sets. A security policy binds a WAF policy to domains.

How BuiltForProd uses it​

The front-door unit creates <prefix>-afd in each stage subscription, such as acme-eus2-prd-afd. The SKU is a stage setting, front_door_sku, and the ingress exposure and the SPA origin mode follow it:

StageSKU (stack comment)API originSPA origin
devStandard, ~$35/month baseThe public IP of nginx-public, locked to Front DoorThe storage static website, publicly readable
staging, prodPremium, ~$330/month baseThe Private Link Service of nginx-internalThe storage static website over Private Link (web)

Requests and egress are billed on top of the base price.

Endpoints and routes.

  • blueprint-app.<stage>.company.com serves the SPA from the storage account's static website. The route redirects HTTP to HTTPS, caches while ignoring query strings, and compresses HTML, CSS, JavaScript, JSON, SVG and text. A rule set rewrites every request whose extension is not a static asset to /index.html, so client-side routes such as /items/42 load the application. The origin's health probe is a HEAD /index.html every 120 seconds.
  • blueprint-api.<stage>.company.com serves the API, HTTPS only and uncached; HTTP is not redirected, because a redirect would turn other methods into GET. The health probe is GET /health every 30 seconds. Through Private Link, Front Door checks the origin certificate against the host name. The dev public origin is addressed by IP, so only its CA chain is checked; what keeps it Front Door-only is the API's check of the X-Azure-FDID header against the profile's ID and an NSG rule that admits only the AzureFrontDoor.Backend service tag.

Certificates and DNS. Both custom domains use Front Door managed certificates with TLS 1.2 at minimum. The unit writes the _dnsauth TXT validation records and the CNAME records to the endpoints in the stage zone of Azure DNS. Validation completes 10 to 30 minutes after the TXT records exist.

WAF. The WAF policy is built from the template the Baseline publishes and bound to both domains by a security policy, in Prevention mode, with the managed rule sets on Premium; see Azure Web Application Firewall.

Logs. A diagnostic setting sends the WAF log, the log of failed health probes and all metrics to the stage application workspace in Log Analytics. The access log, one record per request (about 1 to 2 GB per million requests), follows the stage switch front_door_access_logs: on in staging and prod, off in dev.

For the code pipeline. The unit records four values in the stage's contract vault (the SPA storage account, both endpoint host names and the profile ID the API checks) and grants the web app code repository's identity CDN Profile Contributor on this profile only, so cd-frontend.yml can purge the cache after an upload. The Private Link connection requests of staging and prod are approved after deployment; until then the origin answers 502.

Terms you will see​

TermMeaning
ProfileThe Front Door resource of one stage: <prefix>-afd.
EndpointAn edge host name that custom domains point to with a CNAME.
Origin groupThe origins of one route, with their health probe and load balancing.
Private Link originAn origin reached through a private endpoint; Premium only.
Rule setRequest rewrites applied on a route, here the SPA deep-link rewrite.
X-Azure-FDIDThe header with the profile's ID that Front Door adds and the API checks.

Where to read more​