# azion.config.js

`azion.config.js` is the project configuration file that the [Azion CLI](/en/documentation/devtools/cli/) reads to build and deploy a project. It is a JavaScript module whose default export, optionally wrapped in `defineConfig(...)`, declares the build settings and the resources the project needs on Azion, such as applications, workloads, connectors, functions, and firewalls. `azion build` builds the project with it, `azion deploy` deploys it, and `azion dev` runs it locally.

---

## File names and where the CLI reads them

The CLI looks for the configuration file in the project folder under seven names, in this order, and reads the first one it finds: `azion.config.ts`, `azion.config.mts`, `azion.config.cts`, `azion.config.js`, `azion.config.mjs`, `azion.config.cjs`, and `azion.config.json`. The file can therefore be TypeScript, an ES module, a CommonJS module, or JSON.

The CLI commands that set up a project write the file for you, and the extension depends on the command and the preset:

| Command                                                                           | File it writes                                                                                               |
| --------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ |
| [`azion init`](/en/documentation/devtools/cli/init/) with the JavaScript preset   | `azion.config.mjs`                                                                                           |
| [`azion link`](/en/documentation/devtools/cli/link-command/) with `--preset html` | `azion.config.cjs`                                                                                           |
| `azion init`, then `azion build`, with the Angular or Docusaurus preset           | `azion.config.cjs`                                                                                           |
| `azion init`, then `azion build`, with the Astro preset                           | `azion.config.mjs`                                                                                           |
| [`azion sync --iac`](/en/documentation/devtools/cli/sync/)                        | `azion.config.mjs`, built from the project's resources on Azion, even when an `azion.config.cjs` file exists |

When a project holds both `azion.config.mjs` and `azion.config.cjs`, `azion deploy` reads and updates `azion.config.mjs`.

`azion deploy` also writes into the file it reads. A generated file holds placeholders such as `$APPLICATION_NAME` and `$WORKLOAD_NAME`, and the first deploy replaces each one with the project name. On a static site, every deploy replaces the storage `prefix` with another value and prints the change:

```text
[Azion] › ℹ  info      Successfully replaced "20260101120000" with "20260101120100" (2 occurrences) in azion.config.cjs
```

---

## defineConfig

`defineConfig` comes from the `@aziontech/config` package, which the generated files name: install it as a development dependency with `npm install -D @aziontech/config`. The function takes your configuration object and returns the same object unchanged. It gives your editor the configuration types for completion and type checking, and it does not check the values.

This file declares a JavaScript build through `defineConfig`:

```javascript
import { defineConfig } from '@aziontech/config'

export default defineConfig({
  build: {
    preset: 'javascript',
    polyfills: true
  }
})
```

The check happens in the build. Before it writes `.edge/manifest.json`, the build runs `validateConfig`, from the same package, on the configuration it read. The check names the property path of each value it refuses, such as `/applications/0/rules/request/0/criteria/0`.

The `azion` package also exports `defineConfig` (`import { defineConfig } from 'azion'`). That package is deprecated in favor of the `@aziontech/*` packages, and its firewall behavior types differ from the ones the build accepts, so type your file with `@aziontech/config`.

---

## Configuration reference

The configuration object takes twelve top-level keys, each optional. Every table below lists the properties of one key, with the type the `@aziontech/config` type declarations give it. A dotted name such as `browser.maxAgeSeconds` is a property of a nested object; **Yes** in the Required column then means required whenever the parent object is present.

| Key            | Type                 | Description                                                                                |
| -------------- | -------------------- | ------------------------------------------------------------------------------------------ |
| `build`        | `AzionBuild`         | How the CLI builds the project.                                                            |
| `applications` | `AzionApplication[]` | The applications of the project, with their cache settings, rules, and function instances. |
| `functions`    | `AzionFunction[]`    | The functions of the project.                                                              |
| `connectors`   | `AzionConnector[]`   | The connectors that applications send requests to.                                         |
| `storage`      | `AzionBucket[]`      | The Object Storage buckets that hold the project's files.                                  |
| `firewall`     | `AzionFirewall[]`    | The firewalls of the project, with their rules.                                            |
| `networkList`  | `AzionNetworkList[]` | The network lists that firewall rules match against.                                       |
| `purge`        | `AzionPurge[]`       | The URLs, cache keys, or wildcards to purge.                                               |
| `waf`          | `AzionWaf[]`         | The Web Application Firewall (WAF) configurations.                                         |
| `workloads`    | `AzionWorkload[]`    | The workloads that serve the applications on domains.                                      |
| `customPages`  | `AzionCustomPage[]`  | The custom error pages.                                                                    |
| `kv`           | `AzionKV[]`          | The KV Store namespaces.                                                                   |

### build

The `build` object sets how the project is bundled before it is deployed.

| Property                    | Type                                           | Required | Description                                                                                    |
| --------------------------- | ---------------------------------------------- | -------- | ---------------------------------------------------------------------------------------------- |
| `bundler`                   | `'webpack' \| 'esbuild'`                       | No       | The bundler to use.                                                                            |
| `entry`                     | `string \| string[] \| Record<string, string>` | No       | The entry file, a list of entry files, or a map of entry names to files.                       |
| `preset`                    | `string \| AzionBuildPreset`                   | No       | The preset to use, by name or as a custom preset object.                                       |
| `polyfills`                 | `boolean`                                      | No       | Whether the build adds polyfills.                                                              |
| `worker`                    | `boolean`                                      | No       | Whether the build produces a worker.                                                           |
| `extend`                    | `(context) => context`                         | No       | Function that receives the bundler configuration, webpack or esbuild, and returns it extended. |
| `memoryFS.injectionDirs`    | `string[]`                                     | Yes      | Folders whose files the build injects into the in-memory file system.                          |
| `memoryFS.removePathPrefix` | `string`                                       | Yes      | Path prefix removed from the injected file paths.                                              |

#### Custom preset

A custom preset is an `AzionBuildPreset` object passed in `build.preset`. It carries its own configuration and the functions that run around the build.

| Property            | Type                                                    | Required | Description                            |
| ------------------- | ------------------------------------------------------- | -------- | -------------------------------------- |
| `config`            | `AzionConfig`                                           | Yes      | The configuration the preset provides. |
| `metadata.name`     | `string`                                                | Yes      | The name of the preset.                |
| `metadata.registry` | `string`                                                | No       | The registry of the preset.            |
| `metadata.ext`      | `string`                                                | No       | The file extension the preset uses.    |
| `handler`           | `AzionRuntimeModule`                                    | No       | A custom handler.                      |
| `prebuild`          | `(config, ctx) => Promise<void \| AzionPrebuildResult>` | No       | Function that runs before the build.   |
| `postbuild`         | `(config, ctx) => Promise<void>`                        | No       | Function that runs after the build.    |

### applications

Each entry of `applications` declares one [application](/en/documentation/platform/applications/), the resource that holds the delivery settings of a site or an API.

| Property                        | Type                      | Required | Description                                                                                                                                             |
| ------------------------------- | ------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`                          | `string`                  | Yes      | The name of the application.                                                                                                                            |
| `active`                        | `boolean`                 | No       | Whether the application is active.                                                                                                                      |
| `debug`                         | `boolean`                 | No       | Whether debug mode is on for the application's rules.                                                                                                   |
| `edgeCacheEnabled`              | `boolean`                 | No       | Whether [Cache](/en/documentation/platform/applications/cache/cache-settings/) is on.                                                                   |
| `functionsEnabled`              | `boolean`                 | No       | Whether [Functions](/en/documentation/platform/functions/) is on.                                                                                       |
| `applicationAcceleratorEnabled` | `boolean`                 | No       | Whether Application Accelerator is on.                                                                                                                  |
| `imageProcessorEnabled`         | `boolean`                 | No       | Whether Image Processor is on.                                                                                                                          |
| `cache`                         | `AzionCache[]`            | No       | The cache settings of the application.                                                                                                                  |
| `rules`                         | `AzionRules`              | No       | The rules of the application: `request` holds the rules of the request phase, and `response` the rules of the response phase. Each is an `AzionRule[]`. |
| `deviceGroups`                  | `AzionDeviceGroup[]`      | No       | The device groups of the application.                                                                                                                   |
| `functionsInstances`            | `AzionFunctionInstance[]` | No       | The function instances of the application.                                                                                                              |

#### Application cache settings

Each entry of an application's `cache` declares one [cache setting](/en/documentation/platform/applications/cache/cache-settings/), which a rule applies with the `set_cache_policy` behavior.

| Property                    | Type                                             | Required | Description                                                                                |
| --------------------------- | ------------------------------------------------ | -------- | ------------------------------------------------------------------------------------------ |
| `name`                      | `string`                                         | Yes      | The name of the cache setting.                                                             |
| `stale`                     | `boolean`                                        | No       | Whether stale content may be served.                                                       |
| `queryStringSort`           | `boolean`                                        | No       | Whether query string parameters are sorted.                                                |
| `tieredCache.enabled`       | `boolean`                                        | Yes      | Whether [Tiered Cache](/en/documentation/platform/applications/cache/tiered-cache/) is on. |
| `tieredCache.topology`      | `'nearest-region' \| 'br-east-1' \| 'us-east-1'` | No       | The Tiered Cache topology.                                                                 |
| `methods.post`              | `boolean`                                        | No       | Whether `POST` requests are cached.                                                        |
| `methods.options`           | `boolean`                                        | No       | Whether `OPTIONS` requests are cached.                                                     |
| `browser.maxAgeSeconds`     | `number \| string`                               | Yes      | Maximum age of the content in the browser cache, in seconds.                               |
| `edge.maxAgeSeconds`        | `number \| string`                               | Yes      | Maximum age of the content in Azion's cache, in seconds.                                   |
| `cacheByCookie.option`      | `'ignore' \| 'all' \| 'allowlist' \| 'denylist'` | Yes      | Which cookies vary the cache.                                                              |
| `cacheByCookie.list`        | `string[]`                                       | No       | The cookies the `allowlist` or `denylist` option names.                                    |
| `cacheByQueryString.option` | `'ignore' \| 'all' \| 'allowlist' \| 'denylist'` | Yes      | Which query string parameters vary the cache.                                              |
| `cacheByQueryString.list`   | `string[]`                                       | No       | The parameters the `allowlist` or `denylist` option names.                                 |

#### Application rules

Each entry of `rules.request` or `rules.response` declares one rule of the application's [Rules Engine](/en/documentation/platform/applications/rules-engine/). A rule runs its behaviors when its criteria match.

| Property      | Type                    | Required | Description                                                                      |
| ------------- | ----------------------- | -------- | -------------------------------------------------------------------------------- |
| `name`        | `string`                | Yes      | The name of the rule.                                                            |
| `description` | `string`                | No       | A description of the rule.                                                       |
| `active`      | `boolean`               | No       | Whether the rule is active.                                                      |
| `criteria`    | `AzionRuleCriteria[][]` | Yes      | The criteria, as an array of groups. Each group is an array of 1 to 10 criteria. |
| `behaviors`   | `AzionRuleBehavior[]`   | Yes      | The behaviors the rule runs, in order.                                           |

#### Rule criteria

Each criterion of an application rule compares a variable with a value. The variables an application rule accepts are in [Rule variables](#rule-variables), and the operators in [Comparison operators](#comparison-operators).

| Property      | Type                    | Required                                 | Description                                                            |
| ------------- | ----------------------- | ---------------------------------------- | ---------------------------------------------------------------------- |
| `variable`    | `string`                | Yes                                      | The variable to evaluate, wrapped in `${}`, such as `${uri}`.          |
| `conditional` | `'if' \| 'and' \| 'or'` | Yes                                      | How the criterion joins the criteria before it.                        |
| `operator`    | `string`                | Yes                                      | The comparison operator.                                               |
| `argument`    | `string`                | Yes, with an operator that takes a value | The value to compare with. Omit it with `exists` and `does_not_exist`. |

#### Rule behaviors

Each behavior of an application rule is an object with a `type` and, for most types, an `attributes` object. A `value` that takes a name or an ID refers to a resource declared in the same file by its `name`, or to an existing resource by its ID.

| `type`                   | Phase                | `attributes`                                                 | Description                                                                                                                         |
| ------------------------ | -------------------- | ------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------- |
| `deliver`                | Request and response | —                                                            | Delivers the content.                                                                                                               |
| `enable_gzip`            | Request and response | —                                                            | Turns on GZIP compression.                                                                                                          |
| `redirect_to_301`        | Request and response | `{ value: string }`                                          | Redirects to `value` with a `301` status.                                                                                           |
| `redirect_to_302`        | Request and response | `{ value: string }`                                          | Redirects to `value` with a `302` status.                                                                                           |
| `run_function`           | Request and response | `{ value: string \| number }`                                | Runs the function `value` names, by name or ID.                                                                                     |
| `capture_match_groups`   | Request and response | `{ regex: string; subject: string; captured_array: string }` | Matches `regex` against `subject` and stores the captured groups in the array that `captured_array` names, 1 to 10 characters long. |
| `deny`                   | Request              | —                                                            | Denies the request.                                                                                                                 |
| `no_content`             | Request              | —                                                            | Returns no content.                                                                                                                 |
| `finish_request_phase`   | Request              | —                                                            | Ends the request phase.                                                                                                             |
| `forward_cookies`        | Request              | —                                                            | Forwards cookies.                                                                                                                   |
| `optimize_images`        | Request              | —                                                            | Optimizes images.                                                                                                                   |
| `bypass_cache`           | Request              | —                                                            | Bypasses the cache.                                                                                                                 |
| `redirect_http_to_https` | Request              | —                                                            | Redirects HTTP requests to HTTPS.                                                                                                   |
| `rewrite_request`        | Request              | `{ value: string }`                                          | Rewrites the request URI to `value`.                                                                                                |
| `set_cache_policy`       | Request              | `{ value: string \| number }`                                | Applies the cache setting `value` names, by name or ID.                                                                             |
| `set_connector`          | Request              | `{ value: string \| number }`                                | Sends the request to the connector `value` names, by name or ID.                                                                    |
| `set_origin`             | Request              | `{ value: string \| number }`                                | Sets the origin, by name or ID.                                                                                                     |
| `add_request_header`     | Request              | `{ value: string }`                                          | Adds the header in `value`, written as `Name: value`, to the request.                                                               |
| `filter_request_header`  | Request              | `{ value: string }`                                          | Removes the header `value` names from the request.                                                                                  |
| `add_request_cookie`     | Request              | `{ value: string }`                                          | Adds a cookie to the request.                                                                                                       |
| `filter_request_cookie`  | Request              | `{ value: string }`                                          | Removes a cookie from the request.                                                                                                  |
| `add_response_header`    | Response             | `{ value: string }`                                          | Adds the header in `value`, written as `Name: value`, to the response.                                                              |
| `filter_response_header` | Response             | `{ value: string }`                                          | Removes the header `value` names from the response.                                                                                 |
| `set_cookie`             | Response             | `{ value: string }`                                          | Sets a cookie on the response.                                                                                                      |
| `filter_response_cookie` | Response             | `{ value: string }`                                          | Removes a cookie from the response.                                                                                                 |

#### Device groups

Each entry of an application's `deviceGroups` declares one [device group](/en/documentation/platform/applications/device-groups/).

| Property    | Type     | Required | Description                                                |
| ----------- | -------- | -------- | ---------------------------------------------------------- |
| `name`      | `string` | Yes      | The name of the device group.                              |
| `userAgent` | `string` | Yes      | The regular expression the `User-Agent` header must match. |

#### Function instances

Each entry of an application's `functionsInstances` attaches a function to the application, so that a `run_function` behavior can run it.

| Property | Type                      | Required | Description                                            |
| -------- | ------------------------- | -------- | ------------------------------------------------------ |
| `name`   | `string`                  | Yes      | The name of the function instance.                     |
| `ref`    | `string \| number`        | Yes      | The function, by its name in `functions` or by its ID. |
| `args`   | `Record<string, unknown>` | No       | The arguments of this instance.                        |
| `active` | `boolean`                 | No       | Whether the instance is active.                        |

### functions

Each entry of `functions` declares one [function](/en/documentation/platform/functions/) and the file that holds its code.

| Property                  | Type                          | Required | Description                                                   |
| ------------------------- | ----------------------------- | -------- | ------------------------------------------------------------- |
| `name`                    | `string`                      | Yes      | The name of the function.                                     |
| `path`                    | `string`                      | Yes      | Path to the function file.                                    |
| `runtime`                 | `'azion_js'`                  | No       | The runtime of the function.                                  |
| `defaultArgs`             | `Record<string, unknown>`     | No       | The default arguments passed to the function.                 |
| `executionEnvironment`    | `'application' \| 'firewall'` | No       | Whether the function runs in an application or in a firewall. |
| `active`                  | `boolean`                     | No       | Whether the function is active.                               |
| `bindings.storage.bucket` | `string`                      | Yes      | The bucket bound to the function, by name or ID.              |
| `bindings.storage.prefix` | `string`                      | No       | The prefix inside the bound bucket.                           |

### connectors

Each entry of `connectors` declares one [connector](/en/documentation/platform/connectors/). The `type` selects the shape of `attributes`: `http` and `live_ingest` take addresses and connection options, and `storage` takes a bucket.

| Property     | Type                                   | Required | Description                                                    |
| ------------ | -------------------------------------- | -------- | -------------------------------------------------------------- |
| `name`       | `string`                               | Yes      | The name of the connector.                                     |
| `active`     | `boolean`                              | No       | Whether the connector is active.                               |
| `type`       | `'http' \| 'storage' \| 'live_ingest'` | Yes      | The kind of connector: HTTP, Object Storage, or Live Ingest.   |
| `attributes` | `object`                               | Yes      | The settings of the connector, in one of the two shapes below. |

#### HTTP and Live Ingest connector attributes

An `http` or `live_ingest` connector takes the same `attributes` object.

| Property            | Type                         | Required | Description                                                                                                                                      |
| ------------------- | ---------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| `addresses`         | `ConnectorAddress[]`         | Yes      | The addresses the connector sends requests to.                                                                                                   |
| `connectionOptions` | `ConnectorConnectionOptions` | Yes      | How the connector connects to the addresses.                                                                                                     |
| `modules`           | `ConnectorModules`           | Yes      | The load balancer and origin shield settings. The type marks it optional, but the build refuses an `http` or `live_ingest` connector without it. |

#### Connector addresses

Each entry of `attributes.addresses` is one address of an `http` or `live_ingest` connector.

| Property    | Type             | Required | Description                                                       |
| ----------- | ---------------- | -------- | ----------------------------------------------------------------- |
| `address`   | `string`         | Yes      | An IPv4 or IPv6 address, or a CNAME.                              |
| `active`    | `boolean`        | No       | Whether the address is active.                                    |
| `httpPort`  | `number`         | No       | The HTTP port.                                                    |
| `httpsPort` | `number`         | No       | The HTTPS port.                                                   |
| `modules`   | `object \| null` | No       | Address modules. The type declares no properties for this object. |

#### Connection options

The `attributes.connectionOptions` object of an `http` or `live_ingest` connector sets how it connects to its addresses.

| Property            | Type                                          | Required | Description                                          |
| ------------------- | --------------------------------------------- | -------- | ---------------------------------------------------- |
| `dnsResolution`     | `'both' \| 'force_ipv4'`                      | No       | The DNS resolution policy.                           |
| `transportPolicy`   | `'preserve' \| 'force_https' \| 'force_http'` | No       | The transport policy.                                |
| `httpVersionPolicy` | `'http1_1'`                                   | No       | The HTTP version policy.                             |
| `host`              | `string`                                      | No       | A custom `Host` value.                               |
| `pathPrefix`        | `string`                                      | No       | A path prefix added to the requests.                 |
| `followingRedirect` | `boolean`                                     | No       | Whether the connector follows redirects.             |
| `realIpHeader`      | `string`                                      | No       | The name of the header that carries the client IP.   |
| `realPortHeader`    | `string`                                      | No       | The name of the header that carries the client port. |

#### Connector modules

The `attributes.modules` object of an `http` or `live_ingest` connector turns the [load balancer](/en/documentation/platform/connectors/load-balancer/balancing-methods/) and [origin shield](/en/documentation/platform/connectors/origin-shield/origin-ip-acl-and-hmac/) on or off.

| Property                                               | Type                                         | Required | Description                                      |
| ------------------------------------------------------ | -------------------------------------------- | -------- | ------------------------------------------------ |
| `loadBalancer.enabled`                                 | `boolean`                                    | Yes      | Whether the load balancer is on.                 |
| `loadBalancer.config`                                  | `object \| null`                             | Yes      | The load balancer settings, or `null`.           |
| `loadBalancer.config.method`                           | `'round_robin' \| 'least_conn' \| 'ip_hash'` | No       | The load balancing method.                       |
| `loadBalancer.config.maxRetries`                       | `number`                                     | No       | The maximum number of retries.                   |
| `loadBalancer.config.connectionTimeout`                | `number`                                     | No       | The connection timeout, in seconds.              |
| `loadBalancer.config.readWriteTimeout`                 | `number`                                     | No       | The read and write timeout, in seconds.          |
| `originShield.enabled`                                 | `boolean`                                    | Yes      | Whether origin shield is on.                     |
| `originShield.config`                                  | `object \| null`                             | Yes      | The origin shield settings, or `null`.           |
| `originShield.config.originIpAcl.enabled`              | `boolean`                                    | No       | Whether the origin IP access control list is on. |
| `originShield.config.hmac.enabled`                     | `boolean`                                    | No       | Whether HMAC authentication is on.               |
| `originShield.config.hmac.config.type`                 | `'aws4_hmac_sha256'`                         | Yes      | The HMAC type.                                   |
| `originShield.config.hmac.config.attributes.region`    | `string`                                     | Yes      | The AWS region.                                  |
| `originShield.config.hmac.config.attributes.service`   | `string`                                     | No       | The AWS service.                                 |
| `originShield.config.hmac.config.attributes.accessKey` | `string`                                     | Yes      | The access key.                                  |
| `originShield.config.hmac.config.attributes.secretKey` | `string`                                     | Yes      | The secret key.                                  |

#### Storage connector attributes

A `storage` connector reads from an [Object Storage](/en/documentation/platform/object-storage/) bucket.

| Property | Type     | Required | Description                                                                                                                  |
| -------- | -------- | -------- | ---------------------------------------------------------------------------------------------------------------------------- |
| `bucket` | `string` | Yes      | The name of the bucket.                                                                                                      |
| `prefix` | `string` | Yes      | The prefix of the objects in the bucket. The type marks it optional, but the build refuses a `storage` connector without it. |

### storage

Each entry of `storage` declares one Object Storage bucket and the local folder whose files go into it.

| Property          | Type                                          | Required | Description                                             |
| ----------------- | --------------------------------------------- | -------- | ------------------------------------------------------- |
| `name`            | `string`                                      | Yes      | The name of the bucket.                                 |
| `dir`             | `string`                                      | Yes      | The local folder that holds the files, such as `./www`. |
| `prefix`          | `string`                                      | Yes      | The prefix the files are stored under in the bucket.    |
| `workloadsAccess` | `'read_only' \| 'read_write' \| 'restricted'` | No       | The access that workloads have to the bucket.           |

### firewall

Each entry of `firewall` declares one [firewall](/en/documentation/platform/firewall/).

| Property             | Type                               | Required | Description                                        |
| -------------------- | ---------------------------------- | -------- | -------------------------------------------------- |
| `name`               | `string`                           | Yes      | The name of the firewall.                          |
| `active`             | `boolean`                          | No       | Whether the firewall is active.                    |
| `functions`          | `boolean`                          | No       | Whether Functions is on for the firewall.          |
| `networkProtection`  | `boolean`                          | No       | Whether Network Shield is on.                      |
| `waf`                | `boolean`                          | No       | Whether WAF is on.                                 |
| `debugRules`         | `boolean`                          | No       | Whether debug mode is on for the firewall's rules. |
| `rules`              | `AzionFirewallRule[]`              | No       | The rules of the firewall.                         |
| `functionsInstances` | `AzionFirewallFunctionsInstance[]` | No       | The function instances of the firewall.            |

#### Firewall rules

Each entry of a firewall's `rules` declares one rule of the firewall's [Rules Engine](/en/documentation/platform/firewall/rules-engine/). Unlike an application rule, a firewall rule takes a flat array of criteria.

| Property      | Type                          | Required | Description                                              |
| ------------- | ----------------------------- | -------- | -------------------------------------------------------- |
| `name`        | `string`                      | Yes      | The name of the rule.                                    |
| `description` | `string`                      | No       | A description of the rule.                               |
| `active`      | `boolean`                     | No       | Whether the rule is active.                              |
| `criteria`    | `AzionFirewallCriteria[]`     | No       | The criteria of the rule.                                |
| `match`       | `string`                      | No       | A match expression, the older alternative to `criteria`. |
| `variable`    | `string`                      | No       | The variable that `match` applies to.                    |
| `behaviors`   | `AzionFirewallBehaviorItem[]` | Yes      | The behaviors the rule runs, in order.                   |

#### Firewall rule criteria

Each criterion of a firewall rule compares a firewall variable with a value. The variables a firewall rule accepts are in [Firewall rule variables](#firewall-rule-variables).

| Property      | Type                    | Required                                 | Description                                                                         |
| ------------- | ----------------------- | ---------------------------------------- | ----------------------------------------------------------------------------------- |
| `variable`    | `string`                | Yes                                      | The firewall variable to evaluate, with or without `${}`, such as `${request_uri}`. |
| `conditional` | `'if' \| 'and' \| 'or'` | Yes                                      | How the criterion joins the criteria before it.                                     |
| `operator`    | `string`                | Yes                                      | The comparison operator.                                                            |
| `argument`    | `string \| number`      | Yes, with an operator that takes a value | The value to compare with. Omit it with `exists` and `does_not_exist`.              |

#### Firewall rule behaviors

Each behavior of a firewall rule is an object with a `type` and, for most types, an `attributes` object.

| `type`                | `attributes`                                                                                                           | Description                                                                                                     |
| --------------------- | ---------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- |
| `deny`                | —                                                                                                                      | Denies the request.                                                                                             |
| `drop`                | —                                                                                                                      | Drops the request.                                                                                              |
| `run_function`        | `{ value: string \| number }`                                                                                          | Runs the function `value` names, by name or ID.                                                                 |
| `set_waf`             | `{ mode: 'learning' \| 'blocking'; wafId: string \| number }`                                                          | Applies the WAF `wafId` names, by name or ID, in the mode `mode` sets.                                          |
| `set_rate_limit`      | `{ type: 'second' \| 'minute'; limitBy: 'client_ip' \| 'global'; averageRateLimit: string; maximumBurstSize: string }` | Limits the request rate per second or per minute, for each client IP or for all clients.                        |
| `set_custom_response` | `{ statusCode: number \| string; contentType: string; contentBody: string }`                                           | Returns a response with the status, content type, and body you set. `statusCode` takes a value from 200 to 499. |

#### Firewall function instances

Each entry of a firewall's `functionsInstances` attaches a function to the firewall.

| Property | Type                     | Required | Description                                            |
| -------- | ------------------------ | -------- | ------------------------------------------------------ |
| `name`   | `string`                 | Yes      | The name of the function instance.                     |
| `ref`    | `string \| number`       | Yes      | The function, by its name in `functions` or by its ID. |
| `args`   | `Record<string, string>` | No       | The arguments of this instance.                        |
| `active` | `boolean`                | No       | Whether the instance is active.                        |

### networkList

Each entry of `networkList` declares one [network list](/en/documentation/platform/firewall/network-shield/network-lists/).

| Property | Type                                | Required | Description                                                      |
| -------- | ----------------------------------- | -------- | ---------------------------------------------------------------- |
| `name`   | `string`                            | Yes      | The name of the network list.                                    |
| `type`   | `'ip_cidr' \| 'asn' \| 'countries'` | Yes      | The kind of items the list holds.                                |
| `items`  | `string[]`                          | Yes      | The IP addresses or CIDR ranges, ASNs, or countries of the list. |
| `active` | `boolean`                           | No       | Whether the network list is active.                              |

### purge

Each entry of `purge` declares one [purge](/en/documentation/platform/applications/cache/real-time-purge/) of cached content.

| Property | Type                                | Required | Description                                             |
| -------- | ----------------------------------- | -------- | ------------------------------------------------------- |
| `type`   | `'url' \| 'cachekey' \| 'wildcard'` | Yes      | The kind of purge.                                      |
| `items`  | `string[]`                          | Yes      | The URLs, cache keys, or wildcard expressions to purge. |
| `layer`  | `'cache' \| 'tiered_cache'`         | No       | The cache layer to purge.                               |

### waf

Each entry of `waf` declares one Web Application Firewall (WAF) configuration, which a firewall rule applies with the `set_waf` behavior.

| Property                               | Type             | Required | Description                           |
| -------------------------------------- | ---------------- | -------- | ------------------------------------- |
| `name`                                 | `string`         | Yes      | The name of the WAF.                  |
| `productVersion`                       | `string`         | No       | The product version.                  |
| `engineSettings.engineVersion`         | `'2021-Q3'`      | Yes      | The engine version.                   |
| `engineSettings.type`                  | `'score'`        | Yes      | The engine type.                      |
| `engineSettings.attributes.rulesets`   | `1[]`            | Yes      | The rule sets.                        |
| `engineSettings.attributes.thresholds` | `WafThreshold[]` | Yes      | The sensitivity for each threat type. |

#### Threat thresholds

Each entry of `engineSettings.attributes.thresholds` sets how sensitive the WAF is to one threat type. For what the levels mean, refer to [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes/).

| Property      | Type                                                                                                                                                                             | Required | Description            |
| ------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ---------------------- |
| `threat`      | `'cross_site_scripting' \| 'directory_traversal' \| 'evading_tricks' \| 'file_upload' \| 'identified_attack' \| 'remote_file_inclusion' \| 'sql_injection' \| 'unwanted_access'` | Yes      | The threat type.       |
| `sensitivity` | `'lowest' \| 'low' \| 'medium' \| 'high' \| 'highest'`                                                                                                                           | Yes      | The sensitivity level. |

### workloads

Each entry of `workloads` declares one [workload](/en/documentation/platform/workloads/), which serves an application on its domains.

| Property                    | Type                                                             | Required | Description                                                              |
| --------------------------- | ---------------------------------------------------------------- | -------- | ------------------------------------------------------------------------ |
| `name`                      | `string`                                                         | Yes      | The name of the workload.                                                |
| `active`                    | `boolean`                                                        | No       | Whether the workload is active.                                          |
| `infrastructure`            | `1 \| 2`                                                         | No       | The infrastructure type: `1` for Standard, `2` for High Performance.     |
| `domains`                   | `string[]`                                                       | No       | The domains of the workload.                                             |
| `workloadDomainAllowAccess` | `boolean`                                                        | No       | Whether the workload domain that Azion assigns also serves the workload. |
| `tls.certificate`           | `number \| null`                                                 | No       | The ID of the certificate.                                               |
| `tls.ciphers`               | `1 \| 2 \| 3 \| 4 \| 5 \| 6 \| 7 \| 8 \| null`                   | No       | The cipher suite.                                                        |
| `tls.minimumVersion`        | `'' \| 'tls_1_0' \| 'tls_1_1' \| 'tls_1_2' \| 'tls_1_3' \| null` | No       | The minimum TLS version.                                                 |
| `protocols.http.versions`   | `('http1' \| 'http2' \| 'http3')[]`                              | Yes      | The HTTP versions served.                                                |
| `protocols.http.httpPorts`  | `number[]`                                                       | Yes      | The HTTP ports.                                                          |
| `protocols.http.httpsPorts` | `number[]`                                                       | Yes      | The HTTPS ports.                                                         |
| `protocols.http.quicPorts`  | `number[] \| null`                                               | No       | The QUIC ports.                                                          |
| `mtls.enabled`              | `boolean`                                                        | Yes      | Whether mutual TLS (mTLS) is on.                                         |
| `mtls.config.verification`  | `'enforce' \| 'permissive'`                                      | Yes      | The mTLS verification mode.                                              |
| `mtls.config.certificate`   | `number \| null`                                                 | No       | The ID of the trusted CA certificate.                                    |
| `mtls.config.crl`           | `number[] \| null`                                               | No       | The IDs of the certificate revocation lists.                             |
| `deployments`               | `AzionWorkloadDeployment[]`                                      | No       | The deployments of the workload.                                         |

#### Workload deployments

Each entry of a workload's `deployments` sets which application, firewall, and custom page the workload serves.

| Property                          | Type                       | Required | Description                                                 |
| --------------------------------- | -------------------------- | -------- | ----------------------------------------------------------- |
| `name`                            | `string`                   | Yes      | The name of the deployment.                                 |
| `current`                         | `boolean`                  | No       | Whether this is the current deployment.                     |
| `active`                          | `boolean`                  | No       | Whether the deployment is active.                           |
| `strategy.type`                   | `string`                   | Yes      | The deployment strategy. The generated files use `default`. |
| `strategy.attributes.application` | `string \| number`         | Yes      | The application, by name or ID.                             |
| `strategy.attributes.firewall`    | `string \| number \| null` | No       | The firewall, by name or ID.                                |
| `strategy.attributes.customPage`  | `string \| number \| null` | No       | The custom page, by name or ID.                             |

### customPages

Each entry of `customPages` declares one set of [custom pages](/en/documentation/platform/workloads/custom-pages/settings/), the pages Azion returns in place of an error response.

| Property | Type                     | Required | Description                      |
| -------- | ------------------------ | -------- | -------------------------------- |
| `name`   | `string`                 | Yes      | The name of the custom page set. |
| `active` | `boolean`                | No       | Whether the set is active.       |
| `pages`  | `AzionCustomPageEntry[]` | Yes      | One entry per error code.        |

#### Custom page entries

Each entry of a custom page set's `pages` maps one error code to a page that a connector serves.

| Property                           | Type               | Required | Description                                                                                                                                                                                                                           |
| ---------------------------------- | ------------------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `code`                             | `string`           | Yes      | The error code: `'default'`, `'400'`, `'401'`, `'403'`, `'404'`, `'405'`, `'406'`, `'408'`, `'409'`, `'410'`, `'411'`, `'414'`, `'415'`, `'416'`, `'426'`, `'429'`, `'431'`, `'500'`, `'501'`, `'502'`, `'503'`, `'504'`, or `'505'`. |
| `page.type`                        | `'page_connector'` | No       | The page type.                                                                                                                                                                                                                        |
| `page.attributes.connector`        | `string \| number` | Yes      | The connector that serves the page, by name or ID.                                                                                                                                                                                    |
| `page.attributes.ttl`              | `number`           | No       | How long the page is cached, in seconds.                                                                                                                                                                                              |
| `page.attributes.uri`              | `string \| null`   | No       | The path of the page.                                                                                                                                                                                                                 |
| `page.attributes.customStatusCode` | `number \| null`   | No       | The status code returned with the page.                                                                                                                                                                                               |

### kv

Each entry of `kv` declares one [KV Store](/en/documentation/platform/kv-store/) namespace.

| Property | Type     | Required | Description                |
| -------- | -------- | -------- | -------------------------- |
| `name`   | `string` | Yes      | The name of the namespace. |

---

## Rule variables

Application rules and firewall rules evaluate different sets of variables in their criteria.

### Application rule variables

An application rule criterion takes its `variable` wrapped in `${}`, such as `${uri}`; the build refuses a bare name. These variables are available in both phases:

| Variable                    | Description                     |
| --------------------------- | ------------------------------- |
| `args`                      | The request arguments.          |
| `device_group`              | The device group.               |
| `domain`                    | The domain.                     |
| `geoip_city`                | The city, from GeoIP.           |
| `geoip_city_continent_code` | The continent code, from GeoIP. |
| `geoip_city_country_code`   | The country code, from GeoIP.   |
| `geoip_city_country_name`   | The country name, from GeoIP.   |
| `geoip_continent_code`      | The continent code.             |
| `geoip_country_code`        | The country code.               |
| `geoip_country_name`        | The country name.               |
| `geoip_region`              | The region, from GeoIP.         |
| `geoip_region_name`         | The region name, from GeoIP.    |
| `host`                      | The request host.               |
| `network`                   | The network.                    |
| `remote_addr`               | The remote IP address.          |
| `remote_port`               | The remote port.                |
| `remote_user`               | The remote user.                |
| `request`                   | The complete request.           |
| `request_body`              | The request body.               |
| `request_method`            | The HTTP method.                |
| `request_uri`               | The request URI.                |
| `scheme`                    | The scheme, `http` or `https`.  |
| `uri`                       | The URI.                        |

These variables are available in the request phase only:

| Variable                  | Description                                              |
| ------------------------- | -------------------------------------------------------- |
| `server_addr`             | The server address.                                      |
| `server_port`             | The server port.                                         |
| `ssl_client_cert`         | The client SSL certificate.                              |
| `ssl_client_escaped_cert` | The escaped client SSL certificate.                      |
| `ssl_client_fingerprint`  | The fingerprint of the client SSL certificate.           |
| `ssl_client_i_dn`         | The issuer DN of the client SSL certificate.             |
| `ssl_client_s_dn`         | The subject DN of the client SSL certificate.            |
| `ssl_client_s_dn_parsed`  | The parsed subject DN.                                   |
| `ssl_client_serial`       | The serial number of the client SSL certificate.         |
| `ssl_client_v_end`        | The end date of the client SSL certificate's validity.   |
| `ssl_client_v_remain`     | The days left in the client SSL certificate's validity.  |
| `ssl_client_v_start`      | The start date of the client SSL certificate's validity. |
| `ssl_client_verify`       | The SSL verification status.                             |

These variables are available in the response phase only:

| Variable          | Description              |
| ----------------- | ------------------------ |
| `sent_http_name`  | The sent HTTP name.      |
| `status`          | The HTTP status code.    |
| `tcpinfo_rtt`     | The TCP round-trip time. |
| `upstream_addr`   | The upstream address.    |
| `upstream_status` | The upstream status.     |

A variable can also name one argument, cookie, or header with a prefix followed by the name:

| Prefix                   | Description               |
| ------------------------ | ------------------------- |
| `arg_<name>`             | One request argument.     |
| `cookie_<name>`          | One cookie.               |
| `http_<name>`            | One HTTP request header.  |
| `sent_http_<name>`       | One sent HTTP header.     |
| `upstream_cookie_<name>` | One upstream cookie.      |
| `upstream_http_<name>`   | One upstream HTTP header. |

### Firewall rule variables

A firewall rule criterion accepts its own set of 15 variables, with or without `${}`: `client_certificate_validation`, `header_accept`, `header_accept_encoding`, `header_accept_language`, `header_cookie`, `header_origin`, `header_referer`, `header_user_agent`, `host`, `network`, `request_args`, `request_method`, `request_uri`, `scheme`, and `ssl_verification_status`. The build refuses any other variable in a firewall rule, including `remote_addr` and the prefixed names.

---

## Comparison operators

The `operator` of an application or firewall criterion takes one of these values. An operator that takes a value needs an `argument`:

| Operator              | Takes a value | Description                            |
| --------------------- | ------------- | -------------------------------------- |
| `is_equal`            | Yes           | Is equal to.                           |
| `is_not_equal`        | Yes           | Is not equal to.                       |
| `starts_with`         | Yes           | Starts with.                           |
| `does_not_start_with` | Yes           | Does not start with.                   |
| `matches`             | Yes           | Matches the regular expression.        |
| `does_not_match`      | Yes           | Does not match the regular expression. |
| `is_in_list`          | Yes           | Is in the list.                        |
| `is_not_in_list`      | Yes           | Is not in the list.                    |
| `exists`              | No            | Exists.                                |
| `does_not_exist`      | No            | Does not exist.                        |

---

## Examples

The two files below are the file that `azion init` generates for a function project and a file written by hand for `azion config apply`.

### Function project generated by azion init

`azion init` with the JavaScript preset writes this `azion.config.mjs`. It declares a function, an application whose rule runs the function on every request, and a workload that serves the application:

```javascript
/**
 * This file was automatically generated based on your preset configuration.
 *
 * For better type checking and IntelliSense:
 * 1. Install azion config as dev dependency:
 *    npm install -D @aziontech/config
 *
 * 2. Use defineConfig:
 *    import { defineConfig } from '@aziontech/config'
 *
 * 3. Replace the configuration with defineConfig:
 *    export default defineConfig({
 *      // Your configuration here
 *    })
 *
 * For more configuration options, visit:
 * https://github.com/aziontech/lib/tree/main/packages/config
 */

export default {
  build: {
    preset: 'javascript',
    polyfills: true
  },
  functions: [
    {
      name: '$FUNCTION_NAME',
      path: './functions/index.js'
    }
  ],
  applications: [
    {
      name: '$APPLICATION_NAME',
      rules: {
        request: [
          {
            name: 'Execute Function',
            description: 'Execute function for all requests',
            active: true,
            criteria: [
              [
                {
                  variable: '${uri}',
                  conditional: 'if',
                  operator: 'matches',
                  argument: '^/'
                }
              ]
            ],
            behaviors: [
              {
                type: 'run_function',
                attributes: {
                  value: '$FUNCTION_NAME'
                }
              }
            ]
          }
        ]
      },
      functionsInstances: [
        {
          name: '$FUNCTION_INSTANCE_NAME',
          ref: '$FUNCTION_NAME'
        }
      ]
    }
  ],
  workloads: [
    {
      name: '$WORKLOAD_NAME',
      active: true,
      infrastructure: 1,
      deployments: [
        {
          name: '$DEPLOYMENT_NAME',
          current: true,
          active: true,
          strategy: {
            type: 'default',
            attributes: {
              application: '$APPLICATION_NAME'
            }
          }
        }
      ]
    }
  ]
}
```

After the first `azion deploy`, every `$` placeholder in the file holds the project name, such as `my-function`.

### Configuration applied with azion config apply

This `azion.config.mjs` declares an application with one cache setting and a rule that applies it, and a workload that serves the application:

```javascript
export default {
  applications: [
    {
      name: 'my-app',
      active: true,
      cache: [
        {
          name: 'my-app-cache',
          browser: { maxAgeSeconds: 600 },
          edge: { maxAgeSeconds: 600 }
        }
      ],
      rules: {
        request: [
          {
            name: 'Set cache policy',
            active: true,
            criteria: [[{ variable: '${uri}', conditional: 'if', operator: 'starts_with', argument: '/' }]],
            behaviors: [{ type: 'set_cache_policy', attributes: { value: 'my-app-cache' } }]
          }
        ]
      }
    }
  ],
  workloads: [
    {
      name: 'my-app',
      active: true,
      infrastructure: 1,
      deployments: [
        {
          name: 'my-app',
          current: true,
          active: true,
          strategy: { type: 'default', attributes: { application: 'my-app' } }
        }
      ]
    }
  ]
}
```

Run [`azion config apply`](/en/documentation/devtools/cli/config/) in the project folder to create the resources the file declares:

```bash
azion config apply
```

The command creates each resource and prints its ID:

```text
…
[Azion] [IaC] › ✔  success   Manifest generated successfully at <project-dir>/.edge/manifest.json
Reading manifest.json file
Edge Application my-app with id 1234567894 successfully created
Cache Setting my-app-cache with id 123469 successfully created
Rule Engine Set cache policy with id 123462 successfully created
Rules Engine of Application with id 1234567894 successfully ordered (request phase)
Workload my-app with id 1234567904 successfully created
Workload Deployment my-app with id 123474 successfully created
Configuration applied successfully: 3 resource(s) applied
```

Running `azion config apply` again with the same file updates the same resources: each line then reads `successfully updated` and keeps the same ID.

---

## Migrate from a v3 configuration

A configuration written for API v3 keeps its resources in flat top-level keys such as `origin`, `cache`, and `rules`. The v4 configuration moves cache settings and rules inside each application, replaces origins with connectors, and adds workloads to serve the applications. For the platform changes behind the v4 structure, refer to [API v4 migration](/en/documentation/fundamentals/api-v4-migration/).

### Renamed keys

This table maps each v3 key to its v4 place:

| v3 key                                              | v4 key                 | What changed                                                                                                              |
| --------------------------------------------------- | ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| `origin`                                            | `connectors`           | An origin becomes a connector with a `type` and an `attributes` object.                                                   |
| `cache`                                             | `applications[].cache` | Cache settings belong to an application.                                                                                  |
| `rules`                                             | `applications[].rules` | Rules belong to an application and take `criteria` and `behaviors`.                                                       |
| `networkLists`                                      | `networkList`          | The key is singular, and each list takes `name`, `type`, and `items` in place of `id`, `listType`, and `listContent`.     |
| `build.builder`                                     | `build.bundler`        | Same values, `esbuild` or `webpack`.                                                                                      |
| `build.custom`                                      | `build.extend`         | A function that extends the bundler configuration replaces the custom configuration object.                               |
| `purge[].urls`                                      | `purge[].items`        | The `method` property is gone, and `layer` takes `cache` or `tiered_cache` in place of `edge_caching` or `l2_caching`.    |
| `cacheByCookie.option`, `cacheByQueryString.option` | Same                   | The values are `ignore`, `all`, `allowlist`, and `denylist` in place of `ignore`, `varies`, `whitelist`, and `blacklist`. |
| Firewall criteria `inputValue`                      | `argument`             | Same meaning.                                                                                                             |
| Firewall `edgeFunctions`                            | `functions`            | Same meaning.                                                                                                             |
| Firewall rule `behavior`                            | `behaviors`            | An array of `{ type, attributes }` objects replaces one object.                                                           |
| Rate limit `limitBy`, `type`                        | Same                   | `limitBy` takes `client_ip` or `global`, without `token`; `type` takes `second` or `minute`, without `hour`.              |
| WAF `mode` and threat settings                      | `engineSettings`       | Thresholds per threat replace the per-threat objects; the mode moves to the firewall rule's `set_waf` behavior.           |

### Origins to connectors

A v3 origin declared its addresses directly:

```javascript
origin: [{
  name: 'my-origin',
  type: 'single_origin',
  addresses: ['origin.example.com']
}]
```

The v4 connector holds the addresses, connection options, and modules inside `attributes`:

```javascript
export default {
  connectors: [
    {
      name: 'my-origin',
      type: 'http',
      attributes: {
        addresses: [{ address: 'origin.example.com' }],
        connectionOptions: { transportPolicy: 'force_https' },
        modules: {
          loadBalancer: { enabled: false, config: null },
          originShield: { enabled: false, config: null }
        }
      }
    }
  ]
}
```

### Rules with criteria

A v3 rule matched one expression and ran one behavior object:

```javascript
rules: {
  request: [{
    name: 'My Rule',
    match: '^/api/',
    behavior: { ... }
  }]
}
```

The v4 rule lives inside an application, matches with groups of criteria, and runs an array of behaviors:

```javascript
export default {
  applications: [
    {
      name: 'my-app',
      rules: {
        request: [
          {
            name: 'My Rule',
            criteria: [[{ variable: '${uri}', conditional: 'if', operator: 'starts_with', argument: '/api/' }]],
            behaviors: [{ type: 'deliver' }]
          }
        ]
      }
    }
  ]
}
```

### Firewall behaviors

A v3 firewall rule ran one behavior object:

```javascript
behavior: {
  deny: true
}
```

The v4 firewall rule takes an array, so one rule can run several behaviors:

```javascript
export default {
  firewall: [
    {
      name: 'my-firewall',
      rules: [
        {
          name: 'Block API',
          criteria: [{ variable: '${request_uri}', conditional: 'if', operator: 'starts_with', argument: '/api/' }],
          behaviors: [{ type: 'deny' }]
        }
      ]
    }
  ]
}
```

### WAF settings

A v3 WAF set a mode and one sensitivity object per threat:

```javascript
waf: [{
  name: 'My WAF',
  mode: 'blocking',
  sqlInjection: { sensitivity: 'high' }
}]
```

The v4 WAF lists one threshold per threat in `engineSettings`, and the firewall rule that applies it sets the mode:

```javascript
export default {
  waf: [
    {
      name: 'My WAF',
      engineSettings: {
        engineVersion: '2021-Q3',
        type: 'score',
        attributes: {
          rulesets: [1],
          thresholds: [{ threat: 'sql_injection', sensitivity: 'high' }]
        }
      }
    }
  ],
  firewall: [
    {
      name: 'my-firewall',
      waf: true,
      rules: [
        {
          name: 'Apply WAF',
          criteria: [{ variable: '${request_uri}', conditional: 'if', operator: 'starts_with', argument: '/' }],
          behaviors: [{ type: 'set_waf', attributes: { mode: 'blocking', wafId: 'My WAF' } }]
        }
      ]
    }
  ]
}
```

---

## Related resources

- [Azion CLI config](/en/documentation/devtools/cli/config.md): The commands that apply the resources this file declares, or delete them.
- [Azion CLI build](/en/documentation/devtools/cli/build.md): How the build reads this file and writes the manifest the deploy uses.
- [Azion CLI deploy](/en/documentation/devtools/cli/deploy.md): How a deploy creates or updates the resources this file declares.
- [Azion Lib config](/en/documentation/devtools/azion-lib/config.md): The library that provides `defineConfig` and the configuration types.
