azion.config.js
Reference for azion.config.js, the project file the Azion CLI reads to build and deploy: every key, its type, and the values it accepts.
azion.config.js is the project configuration file that the Azion CLI reads to build and deploy a project. It is a JavaScript module whose default export, optionally wrapped in defineConfig(...), declares the build settings and the resources the project needs on Azion, such as applications, workloads, connectors, functions, and firewalls. azion build builds the project with it, azion deploy deploys it, and azion dev runs it locally.
File names and where the CLI reads them
The CLI looks for the configuration file in the project folder under seven names, in this order, and reads the first one it finds: azion.config.ts, azion.config.mts, azion.config.cts, azion.config.js, azion.config.mjs, azion.config.cjs, and azion.config.json. The file can therefore be TypeScript, an ES module, a CommonJS module, or JSON.
The CLI commands that set up a project write the file for you, and the extension depends on the command and the preset:
| Command | File it writes |
|---|---|
azion init with the JavaScript preset | azion.config.mjs |
azion link with --preset html | azion.config.cjs |
azion init, then azion build, with the Angular or Docusaurus preset | azion.config.cjs |
azion init, then azion build, with the Astro preset | azion.config.mjs |
azion sync --iac | azion.config.mjs, built from the project’s resources on Azion, even when an azion.config.cjs file exists |
When a project holds both azion.config.mjs and azion.config.cjs, azion deploy reads and updates azion.config.mjs.
azion deploy also writes into the file it reads. A generated file holds placeholders such as $APPLICATION_NAME and $WORKLOAD_NAME, and the first deploy replaces each one with the project name. On a static site, every deploy replaces the storage prefix with another value and prints the change:
defineConfig
defineConfig comes from the @aziontech/config package, which the generated files name: install it as a development dependency with npm install -D @aziontech/config. The function takes your configuration object and returns the same object unchanged. It gives your editor the configuration types for completion and type checking, and it does not check the values.
This file declares a JavaScript build through defineConfig:
The check happens in the build. Before it writes .edge/manifest.json, the build runs validateConfig, from the same package, on the configuration it read. The check names the property path of each value it refuses, such as /applications/0/rules/request/0/criteria/0.
The azion package also exports defineConfig (import { defineConfig } from 'azion'). That package is deprecated in favor of the @aziontech/* packages, and its firewall behavior types differ from the ones the build accepts, so type your file with @aziontech/config.
Configuration reference
The configuration object takes twelve top-level keys, each optional. Every table below lists the properties of one key, with the type the @aziontech/config type declarations give it. A dotted name such as browser.maxAgeSeconds is a property of a nested object; Yes in the Required column then means required whenever the parent object is present.
| Key | Type | Description |
|---|---|---|
build | AzionBuild | How the CLI builds the project. |
applications | AzionApplication[] | The applications of the project, with their cache settings, rules, and function instances. |
functions | AzionFunction[] | The functions of the project. |
connectors | AzionConnector[] | The connectors that applications send requests to. |
storage | AzionBucket[] | The Object Storage buckets that hold the project’s files. |
firewall | AzionFirewall[] | The firewalls of the project, with their rules. |
networkList | AzionNetworkList[] | The network lists that firewall rules match against. |
purge | AzionPurge[] | The URLs, cache keys, or wildcards to purge. |
waf | AzionWaf[] | The Web Application Firewall (WAF) configurations. |
workloads | AzionWorkload[] | The workloads that serve the applications on domains. |
customPages | AzionCustomPage[] | The custom error pages. |
kv | AzionKV[] | The KV Store namespaces. |
build
The build object sets how the project is bundled before it is deployed.
| Property | Type | Required | Description |
|---|---|---|---|
bundler | 'webpack' | 'esbuild' | No | The bundler to use. |
entry | string | string[] | Record<string, string> | No | The entry file, a list of entry files, or a map of entry names to files. |
preset | string | AzionBuildPreset | No | The preset to use, by name or as a custom preset object. |
polyfills | boolean | No | Whether the build adds polyfills. |
worker | boolean | No | Whether the build produces a worker. |
extend | (context) => context | No | Function that receives the bundler configuration, webpack or esbuild, and returns it extended. |
memoryFS.injectionDirs | string[] | Yes | Folders whose files the build injects into the in-memory file system. |
memoryFS.removePathPrefix | string | Yes | Path prefix removed from the injected file paths. |
Custom preset
A custom preset is an AzionBuildPreset object passed in build.preset. It carries its own configuration and the functions that run around the build.
| Property | Type | Required | Description |
|---|---|---|---|
config | AzionConfig | Yes | The configuration the preset provides. |
metadata.name | string | Yes | The name of the preset. |
metadata.registry | string | No | The registry of the preset. |
metadata.ext | string | No | The file extension the preset uses. |
handler | AzionRuntimeModule | No | A custom handler. |
prebuild | (config, ctx) => Promise<void | AzionPrebuildResult> | No | Function that runs before the build. |
postbuild | (config, ctx) => Promise<void> | No | Function that runs after the build. |
applications
Each entry of applications declares one application, the resource that holds the delivery settings of a site or an API.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the application. |
active | boolean | No | Whether the application is active. |
debug | boolean | No | Whether debug mode is on for the application’s rules. |
edgeCacheEnabled | boolean | No | Whether Cache is on. |
functionsEnabled | boolean | No | Whether Functions is on. |
applicationAcceleratorEnabled | boolean | No | Whether Application Accelerator is on. |
imageProcessorEnabled | boolean | No | Whether Image Processor is on. |
cache | AzionCache[] | No | The cache settings of the application. |
rules | AzionRules | No | The rules of the application: request holds the rules of the request phase, and response the rules of the response phase. Each is an AzionRule[]. |
deviceGroups | AzionDeviceGroup[] | No | The device groups of the application. |
functionsInstances | AzionFunctionInstance[] | No | The function instances of the application. |
Application cache settings
Each entry of an application’s cache declares one cache setting, which a rule applies with the set_cache_policy behavior.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the cache setting. |
stale | boolean | No | Whether stale content may be served. |
queryStringSort | boolean | No | Whether query string parameters are sorted. |
tieredCache.enabled | boolean | Yes | Whether Tiered Cache is on. |
tieredCache.topology | 'nearest-region' | 'br-east-1' | 'us-east-1' | No | The Tiered Cache topology. |
methods.post | boolean | No | Whether POST requests are cached. |
methods.options | boolean | No | Whether OPTIONS requests are cached. |
browser.maxAgeSeconds | number | string | Yes | Maximum age of the content in the browser cache, in seconds. |
edge.maxAgeSeconds | number | string | Yes | Maximum age of the content in Azion’s cache, in seconds. |
cacheByCookie.option | 'ignore' | 'all' | 'allowlist' | 'denylist' | Yes | Which cookies vary the cache. |
cacheByCookie.list | string[] | No | The cookies the allowlist or denylist option names. |
cacheByQueryString.option | 'ignore' | 'all' | 'allowlist' | 'denylist' | Yes | Which query string parameters vary the cache. |
cacheByQueryString.list | string[] | No | The parameters the allowlist or denylist option names. |
Application rules
Each entry of rules.request or rules.response declares one rule of the application’s Rules Engine. A rule runs its behaviors when its criteria match.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the rule. |
description | string | No | A description of the rule. |
active | boolean | No | Whether the rule is active. |
criteria | AzionRuleCriteria[][] | Yes | The criteria, as an array of groups. Each group is an array of 1 to 10 criteria. |
behaviors | AzionRuleBehavior[] | Yes | The behaviors the rule runs, in order. |
Rule criteria
Each criterion of an application rule compares a variable with a value. The variables an application rule accepts are in Rule variables, and the operators in Comparison operators.
| Property | Type | Required | Description |
|---|---|---|---|
variable | string | Yes | The variable to evaluate, wrapped in ${}, such as ${uri}. |
conditional | 'if' | 'and' | 'or' | Yes | How the criterion joins the criteria before it. |
operator | string | Yes | The comparison operator. |
argument | string | Yes, with an operator that takes a value | The value to compare with. Omit it with exists and does_not_exist. |
Rule behaviors
Each behavior of an application rule is an object with a type and, for most types, an attributes object. A value that takes a name or an ID refers to a resource declared in the same file by its name, or to an existing resource by its ID.
type | Phase | attributes | Description |
|---|---|---|---|
deliver | Request and response | — | Delivers the content. |
enable_gzip | Request and response | — | Turns on GZIP compression. |
redirect_to_301 | Request and response | { value: string } | Redirects to value with a 301 status. |
redirect_to_302 | Request and response | { value: string } | Redirects to value with a 302 status. |
run_function | Request and response | { value: string | number } | Runs the function value names, by name or ID. |
capture_match_groups | Request and response | { regex: string; subject: string; captured_array: string } | Matches regex against subject and stores the captured groups in the array that captured_array names, 1 to 10 characters long. |
deny | Request | — | Denies the request. |
no_content | Request | — | Returns no content. |
finish_request_phase | Request | — | Ends the request phase. |
forward_cookies | Request | — | Forwards cookies. |
optimize_images | Request | — | Optimizes images. |
bypass_cache | Request | — | Bypasses the cache. |
redirect_http_to_https | Request | — | Redirects HTTP requests to HTTPS. |
rewrite_request | Request | { value: string } | Rewrites the request URI to value. |
set_cache_policy | Request | { value: string | number } | Applies the cache setting value names, by name or ID. |
set_connector | Request | { value: string | number } | Sends the request to the connector value names, by name or ID. |
set_origin | Request | { value: string | number } | Sets the origin, by name or ID. |
add_request_header | Request | { value: string } | Adds the header in value, written as Name: value, to the request. |
filter_request_header | Request | { value: string } | Removes the header value names from the request. |
add_request_cookie | Request | { value: string } | Adds a cookie to the request. |
filter_request_cookie | Request | { value: string } | Removes a cookie from the request. |
add_response_header | Response | { value: string } | Adds the header in value, written as Name: value, to the response. |
filter_response_header | Response | { value: string } | Removes the header value names from the response. |
set_cookie | Response | { value: string } | Sets a cookie on the response. |
filter_response_cookie | Response | { value: string } | Removes a cookie from the response. |
Device groups
Each entry of an application’s deviceGroups declares one device group.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the device group. |
userAgent | string | Yes | The regular expression the User-Agent header must match. |
Function instances
Each entry of an application’s functionsInstances attaches a function to the application, so that a run_function behavior can run it.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the function instance. |
ref | string | number | Yes | The function, by its name in functions or by its ID. |
args | Record<string, unknown> | No | The arguments of this instance. |
active | boolean | No | Whether the instance is active. |
functions
Each entry of functions declares one function and the file that holds its code.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the function. |
path | string | Yes | Path to the function file. |
runtime | 'azion_js' | No | The runtime of the function. |
defaultArgs | Record<string, unknown> | No | The default arguments passed to the function. |
executionEnvironment | 'application' | 'firewall' | No | Whether the function runs in an application or in a firewall. |
active | boolean | No | Whether the function is active. |
bindings.storage.bucket | string | Yes | The bucket bound to the function, by name or ID. |
bindings.storage.prefix | string | No | The prefix inside the bound bucket. |
connectors
Each entry of connectors declares one connector. The type selects the shape of attributes: http and live_ingest take addresses and connection options, and storage takes a bucket.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the connector. |
active | boolean | No | Whether the connector is active. |
type | 'http' | 'storage' | 'live_ingest' | Yes | The kind of connector: HTTP, Object Storage, or Live Ingest. |
attributes | object | Yes | The settings of the connector, in one of the two shapes below. |
HTTP and Live Ingest connector attributes
An http or live_ingest connector takes the same attributes object.
| Property | Type | Required | Description |
|---|---|---|---|
addresses | ConnectorAddress[] | Yes | The addresses the connector sends requests to. |
connectionOptions | ConnectorConnectionOptions | Yes | How the connector connects to the addresses. |
modules | ConnectorModules | Yes | The load balancer and origin shield settings. The type marks it optional, but the build refuses an http or live_ingest connector without it. |
Connector addresses
Each entry of attributes.addresses is one address of an http or live_ingest connector.
| Property | Type | Required | Description |
|---|---|---|---|
address | string | Yes | An IPv4 or IPv6 address, or a CNAME. |
active | boolean | No | Whether the address is active. |
httpPort | number | No | The HTTP port. |
httpsPort | number | No | The HTTPS port. |
modules | object | null | No | Address modules. The type declares no properties for this object. |
Connection options
The attributes.connectionOptions object of an http or live_ingest connector sets how it connects to its addresses.
| Property | Type | Required | Description |
|---|---|---|---|
dnsResolution | 'both' | 'force_ipv4' | No | The DNS resolution policy. |
transportPolicy | 'preserve' | 'force_https' | 'force_http' | No | The transport policy. |
httpVersionPolicy | 'http1_1' | No | The HTTP version policy. |
host | string | No | A custom Host value. |
pathPrefix | string | No | A path prefix added to the requests. |
followingRedirect | boolean | No | Whether the connector follows redirects. |
realIpHeader | string | No | The name of the header that carries the client IP. |
realPortHeader | string | No | The name of the header that carries the client port. |
Connector modules
The attributes.modules object of an http or live_ingest connector turns the load balancer and origin shield on or off.
| Property | Type | Required | Description |
|---|---|---|---|
loadBalancer.enabled | boolean | Yes | Whether the load balancer is on. |
loadBalancer.config | object | null | Yes | The load balancer settings, or null. |
loadBalancer.config.method | 'round_robin' | 'least_conn' | 'ip_hash' | No | The load balancing method. |
loadBalancer.config.maxRetries | number | No | The maximum number of retries. |
loadBalancer.config.connectionTimeout | number | No | The connection timeout, in seconds. |
loadBalancer.config.readWriteTimeout | number | No | The read and write timeout, in seconds. |
originShield.enabled | boolean | Yes | Whether origin shield is on. |
originShield.config | object | null | Yes | The origin shield settings, or null. |
originShield.config.originIpAcl.enabled | boolean | No | Whether the origin IP access control list is on. |
originShield.config.hmac.enabled | boolean | No | Whether HMAC authentication is on. |
originShield.config.hmac.config.type | 'aws4_hmac_sha256' | Yes | The HMAC type. |
originShield.config.hmac.config.attributes.region | string | Yes | The AWS region. |
originShield.config.hmac.config.attributes.service | string | No | The AWS service. |
originShield.config.hmac.config.attributes.accessKey | string | Yes | The access key. |
originShield.config.hmac.config.attributes.secretKey | string | Yes | The secret key. |
Storage connector attributes
A storage connector reads from an Object Storage bucket.
| Property | Type | Required | Description |
|---|---|---|---|
bucket | string | Yes | The name of the bucket. |
prefix | string | Yes | The prefix of the objects in the bucket. The type marks it optional, but the build refuses a storage connector without it. |
storage
Each entry of storage declares one Object Storage bucket and the local folder whose files go into it.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the bucket. |
dir | string | Yes | The local folder that holds the files, such as ./www. |
prefix | string | Yes | The prefix the files are stored under in the bucket. |
workloadsAccess | 'read_only' | 'read_write' | 'restricted' | No | The access that workloads have to the bucket. |
firewall
Each entry of firewall declares one firewall.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the firewall. |
active | boolean | No | Whether the firewall is active. |
functions | boolean | No | Whether Functions is on for the firewall. |
networkProtection | boolean | No | Whether Network Shield is on. |
waf | boolean | No | Whether WAF is on. |
debugRules | boolean | No | Whether debug mode is on for the firewall’s rules. |
rules | AzionFirewallRule[] | No | The rules of the firewall. |
functionsInstances | AzionFirewallFunctionsInstance[] | No | The function instances of the firewall. |
Firewall rules
Each entry of a firewall’s rules declares one rule of the firewall’s Rules Engine. Unlike an application rule, a firewall rule takes a flat array of criteria.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the rule. |
description | string | No | A description of the rule. |
active | boolean | No | Whether the rule is active. |
criteria | AzionFirewallCriteria[] | No | The criteria of the rule. |
match | string | No | A match expression, the older alternative to criteria. |
variable | string | No | The variable that match applies to. |
behaviors | AzionFirewallBehaviorItem[] | Yes | The behaviors the rule runs, in order. |
Firewall rule criteria
Each criterion of a firewall rule compares a firewall variable with a value. The variables a firewall rule accepts are in Firewall rule variables.
| Property | Type | Required | Description |
|---|---|---|---|
variable | string | Yes | The firewall variable to evaluate, with or without ${}, such as ${request_uri}. |
conditional | 'if' | 'and' | 'or' | Yes | How the criterion joins the criteria before it. |
operator | string | Yes | The comparison operator. |
argument | string | number | Yes, with an operator that takes a value | The value to compare with. Omit it with exists and does_not_exist. |
Firewall rule behaviors
Each behavior of a firewall rule is an object with a type and, for most types, an attributes object.
type | attributes | Description |
|---|---|---|
deny | — | Denies the request. |
drop | — | Drops the request. |
run_function | { value: string | number } | Runs the function value names, by name or ID. |
set_waf | { mode: 'learning' | 'blocking'; wafId: string | number } | Applies the WAF wafId names, by name or ID, in the mode mode sets. |
set_rate_limit | { type: 'second' | 'minute'; limitBy: 'client_ip' | 'global'; averageRateLimit: string; maximumBurstSize: string } | Limits the request rate per second or per minute, for each client IP or for all clients. |
set_custom_response | { statusCode: number | string; contentType: string; contentBody: string } | Returns a response with the status, content type, and body you set. statusCode takes a value from 200 to 499. |
Firewall function instances
Each entry of a firewall’s functionsInstances attaches a function to the firewall.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the function instance. |
ref | string | number | Yes | The function, by its name in functions or by its ID. |
args | Record<string, string> | No | The arguments of this instance. |
active | boolean | No | Whether the instance is active. |
networkList
Each entry of networkList declares one network list.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the network list. |
type | 'ip_cidr' | 'asn' | 'countries' | Yes | The kind of items the list holds. |
items | string[] | Yes | The IP addresses or CIDR ranges, ASNs, or countries of the list. |
active | boolean | No | Whether the network list is active. |
purge
Each entry of purge declares one purge of cached content.
| Property | Type | Required | Description |
|---|---|---|---|
type | 'url' | 'cachekey' | 'wildcard' | Yes | The kind of purge. |
items | string[] | Yes | The URLs, cache keys, or wildcard expressions to purge. |
layer | 'cache' | 'tiered_cache' | No | The cache layer to purge. |
waf
Each entry of waf declares one Web Application Firewall (WAF) configuration, which a firewall rule applies with the set_waf behavior.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the WAF. |
productVersion | string | No | The product version. |
engineSettings.engineVersion | '2021-Q3' | Yes | The engine version. |
engineSettings.type | 'score' | Yes | The engine type. |
engineSettings.attributes.rulesets | 1[] | Yes | The rule sets. |
engineSettings.attributes.thresholds | WafThreshold[] | Yes | The sensitivity for each threat type. |
Threat thresholds
Each entry of engineSettings.attributes.thresholds sets how sensitive the WAF is to one threat type. For what the levels mean, refer to Scoring and modes.
| Property | Type | Required | Description |
|---|---|---|---|
threat | 'cross_site_scripting' | 'directory_traversal' | 'evading_tricks' | 'file_upload' | 'identified_attack' | 'remote_file_inclusion' | 'sql_injection' | 'unwanted_access' | Yes | The threat type. |
sensitivity | 'lowest' | 'low' | 'medium' | 'high' | 'highest' | Yes | The sensitivity level. |
workloads
Each entry of workloads declares one workload, which serves an application on its domains.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the workload. |
active | boolean | No | Whether the workload is active. |
infrastructure | 1 | 2 | No | The infrastructure type: 1 for Standard, 2 for High Performance. |
domains | string[] | No | The domains of the workload. |
workloadDomainAllowAccess | boolean | No | Whether the workload domain that Azion assigns also serves the workload. |
tls.certificate | number | null | No | The ID of the certificate. |
tls.ciphers | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | null | No | The cipher suite. |
tls.minimumVersion | '' | 'tls_1_0' | 'tls_1_1' | 'tls_1_2' | 'tls_1_3' | null | No | The minimum TLS version. |
protocols.http.versions | ('http1' | 'http2' | 'http3')[] | Yes | The HTTP versions served. |
protocols.http.httpPorts | number[] | Yes | The HTTP ports. |
protocols.http.httpsPorts | number[] | Yes | The HTTPS ports. |
protocols.http.quicPorts | number[] | null | No | The QUIC ports. |
mtls.enabled | boolean | Yes | Whether mutual TLS (mTLS) is on. |
mtls.config.verification | 'enforce' | 'permissive' | Yes | The mTLS verification mode. |
mtls.config.certificate | number | null | No | The ID of the trusted CA certificate. |
mtls.config.crl | number[] | null | No | The IDs of the certificate revocation lists. |
deployments | AzionWorkloadDeployment[] | No | The deployments of the workload. |
Workload deployments
Each entry of a workload’s deployments sets which application, firewall, and custom page the workload serves.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the deployment. |
current | boolean | No | Whether this is the current deployment. |
active | boolean | No | Whether the deployment is active. |
strategy.type | string | Yes | The deployment strategy. The generated files use default. |
strategy.attributes.application | string | number | Yes | The application, by name or ID. |
strategy.attributes.firewall | string | number | null | No | The firewall, by name or ID. |
strategy.attributes.customPage | string | number | null | No | The custom page, by name or ID. |
customPages
Each entry of customPages declares one set of custom pages, the pages Azion returns in place of an error response.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the custom page set. |
active | boolean | No | Whether the set is active. |
pages | AzionCustomPageEntry[] | Yes | One entry per error code. |
Custom page entries
Each entry of a custom page set’s pages maps one error code to a page that a connector serves.
| Property | Type | Required | Description |
|---|---|---|---|
code | string | Yes | The error code: 'default', '400', '401', '403', '404', '405', '406', '408', '409', '410', '411', '414', '415', '416', '426', '429', '431', '500', '501', '502', '503', '504', or '505'. |
page.type | 'page_connector' | No | The page type. |
page.attributes.connector | string | number | Yes | The connector that serves the page, by name or ID. |
page.attributes.ttl | number | No | How long the page is cached, in seconds. |
page.attributes.uri | string | null | No | The path of the page. |
page.attributes.customStatusCode | number | null | No | The status code returned with the page. |
kv
Each entry of kv declares one KV Store namespace.
| Property | Type | Required | Description |
|---|---|---|---|
name | string | Yes | The name of the namespace. |
Rule variables
Application rules and firewall rules evaluate different sets of variables in their criteria.
Application rule variables
An application rule criterion takes its variable wrapped in ${}, such as ${uri}; the build refuses a bare name. These variables are available in both phases:
| Variable | Description |
|---|---|
args | The request arguments. |
device_group | The device group. |
domain | The domain. |
geoip_city | The city, from GeoIP. |
geoip_city_continent_code | The continent code, from GeoIP. |
geoip_city_country_code | The country code, from GeoIP. |
geoip_city_country_name | The country name, from GeoIP. |
geoip_continent_code | The continent code. |
geoip_country_code | The country code. |
geoip_country_name | The country name. |
geoip_region | The region, from GeoIP. |
geoip_region_name | The region name, from GeoIP. |
host | The request host. |
network | The network. |
remote_addr | The remote IP address. |
remote_port | The remote port. |
remote_user | The remote user. |
request | The complete request. |
request_body | The request body. |
request_method | The HTTP method. |
request_uri | The request URI. |
scheme | The scheme, http or https. |
uri | The URI. |
These variables are available in the request phase only:
| Variable | Description |
|---|---|
server_addr | The server address. |
server_port | The server port. |
ssl_client_cert | The client SSL certificate. |
ssl_client_escaped_cert | The escaped client SSL certificate. |
ssl_client_fingerprint | The fingerprint of the client SSL certificate. |
ssl_client_i_dn | The issuer DN of the client SSL certificate. |
ssl_client_s_dn | The subject DN of the client SSL certificate. |
ssl_client_s_dn_parsed | The parsed subject DN. |
ssl_client_serial | The serial number of the client SSL certificate. |
ssl_client_v_end | The end date of the client SSL certificate’s validity. |
ssl_client_v_remain | The days left in the client SSL certificate’s validity. |
ssl_client_v_start | The start date of the client SSL certificate’s validity. |
ssl_client_verify | The SSL verification status. |
These variables are available in the response phase only:
| Variable | Description |
|---|---|
sent_http_name | The sent HTTP name. |
status | The HTTP status code. |
tcpinfo_rtt | The TCP round-trip time. |
upstream_addr | The upstream address. |
upstream_status | The upstream status. |
A variable can also name one argument, cookie, or header with a prefix followed by the name:
| Prefix | Description |
|---|---|
arg_<name> | One request argument. |
cookie_<name> | One cookie. |
http_<name> | One HTTP request header. |
sent_http_<name> | One sent HTTP header. |
upstream_cookie_<name> | One upstream cookie. |
upstream_http_<name> | One upstream HTTP header. |
Firewall rule variables
A firewall rule criterion accepts its own set of 15 variables, with or without ${}: client_certificate_validation, header_accept, header_accept_encoding, header_accept_language, header_cookie, header_origin, header_referer, header_user_agent, host, network, request_args, request_method, request_uri, scheme, and ssl_verification_status. The build refuses any other variable in a firewall rule, including remote_addr and the prefixed names.
Comparison operators
The operator of an application or firewall criterion takes one of these values. An operator that takes a value needs an argument:
| Operator | Takes a value | Description |
|---|---|---|
is_equal | Yes | Is equal to. |
is_not_equal | Yes | Is not equal to. |
starts_with | Yes | Starts with. |
does_not_start_with | Yes | Does not start with. |
matches | Yes | Matches the regular expression. |
does_not_match | Yes | Does not match the regular expression. |
is_in_list | Yes | Is in the list. |
is_not_in_list | Yes | Is not in the list. |
exists | No | Exists. |
does_not_exist | No | Does not exist. |
Examples
The two files below are the file that azion init generates for a function project and a file written by hand for azion config apply.
Function project generated by azion init
azion init with the JavaScript preset writes this azion.config.mjs. It declares a function, an application whose rule runs the function on every request, and a workload that serves the application:
After the first azion deploy, every $ placeholder in the file holds the project name, such as my-function.
Configuration applied with azion config apply
This azion.config.mjs declares an application with one cache setting and a rule that applies it, and a workload that serves the application:
Run azion config apply in the project folder to create the resources the file declares:
The command creates each resource and prints its ID:
Running azion config apply again with the same file updates the same resources: each line then reads successfully updated and keeps the same ID.
Migrate from a v3 configuration
A configuration written for API v3 keeps its resources in flat top-level keys such as origin, cache, and rules. The v4 configuration moves cache settings and rules inside each application, replaces origins with connectors, and adds workloads to serve the applications. For the platform changes behind the v4 structure, refer to API v4 migration.
Renamed keys
This table maps each v3 key to its v4 place:
| v3 key | v4 key | What changed |
|---|---|---|
origin | connectors | An origin becomes a connector with a type and an attributes object. |
cache | applications[].cache | Cache settings belong to an application. |
rules | applications[].rules | Rules belong to an application and take criteria and behaviors. |
networkLists | networkList | The key is singular, and each list takes name, type, and items in place of id, listType, and listContent. |
build.builder | build.bundler | Same values, esbuild or webpack. |
build.custom | build.extend | A function that extends the bundler configuration replaces the custom configuration object. |
purge[].urls | purge[].items | The method property is gone, and layer takes cache or tiered_cache in place of edge_caching or l2_caching. |
cacheByCookie.option, cacheByQueryString.option | Same | The values are ignore, all, allowlist, and denylist in place of ignore, varies, whitelist, and blacklist. |
Firewall criteria inputValue | argument | Same meaning. |
Firewall edgeFunctions | functions | Same meaning. |
Firewall rule behavior | behaviors | An array of { type, attributes } objects replaces one object. |
Rate limit limitBy, type | Same | limitBy takes client_ip or global, without token; type takes second or minute, without hour. |
WAF mode and threat settings | engineSettings | Thresholds per threat replace the per-threat objects; the mode moves to the firewall rule’s set_waf behavior. |
Origins to connectors
A v3 origin declared its addresses directly:
The v4 connector holds the addresses, connection options, and modules inside attributes:
Rules with criteria
A v3 rule matched one expression and ran one behavior object:
The v4 rule lives inside an application, matches with groups of criteria, and runs an array of behaviors:
Firewall behaviors
A v3 firewall rule ran one behavior object:
The v4 firewall rule takes an array, so one rule can run several behaviors:
WAF settings
A v3 WAF set a mode and one sensitivity object per threat:
The v4 WAF lists one threshold per threat in engineSettings, and the firewall rule that applies it sets the mode: