# Fundamentals

A web platform is a service you build on instead of a stack you operate. You write the application and describe how it should behave, and the provider runs it on infrastructure it owns, filters the traffic that reaches it, and shows you what happened to every request. The servers, the routing, and the scaling stop being your work.

**Azion Platform** is that service on Azion's globally distributed infrastructure: the integrated technology and the interfaces where you build, secure, and scale applications, which includes operating and monitoring them. Use Azion Platform to run an application close to its users, block the traffic it should not receive, store the data it reads, and watch every request it serves.

---

## Platform resources topology

Everything that serves traffic on Azion is a set of Platform Resources bound to one another, with what you enable listed inside the resource it attaches to. The diagram shows how they connect: what the workload binds, what each resource holds, where the application fetches from, and what a function can call. Select a card to open it and read what it is and what it holds.

1. **Workload** (Required): Receives traffic. [Domains](/en/documentation/platform/workloads/domains.md), [Certificate Manager](/en/documentation/platform/workloads.md#certificate-manager). [Read the reference](/en/documentation/platform/workloads.md).

2. **Firewall** (Optional): Filters requests. [WAF](/en/documentation/platform/firewall.md#waf), [DDoS Protection](/en/documentation/platform/workloads.md#ddos-protection), [Bot Manager](/en/documentation/platform/firewall.md#bot-manager), [Network Shield](/en/documentation/platform/firewall.md#network-shield). [Read the reference](/en/documentation/platform/firewall.md).

   **Application** (Required): Serves content. [Functions](/en/documentation/platform/functions.md), [Rules Engine](/en/documentation/platform/applications/rules-engine.md), [Cache](/en/documentation/platform/applications.md#cache), [Image Processor](/en/documentation/platform/applications.md#image-processor). [Read the reference](/en/documentation/platform/applications.md).

   **Custom Pages** (Optional): Error pages. [Read the reference](/en/documentation/platform/workloads.md#custom-pages).

3. **Connector** (Required): HTTP or storage. [Storage connector](/en/documentation/platform/connectors/settings.md#storage), [Load Balancer](/en/documentation/platform/connectors.md#load-balancer), [Origin Shield](/en/documentation/platform/connectors.md#origin-shield). [Read the reference](/en/documentation/platform/connectors.md).

   **Store** (Optional): Data and files. [SQL Database](/en/documentation/platform/sql-database.md), [KV Store](/en/documentation/platform/kv-store.md), [Object Storage](/en/documentation/platform/object-storage.md).

   **AI** (Optional): Runs models. [AI Inference](/en/documentation/platform/ai-inference.md).

4. **Origin**: Your server. On-premises, Cloud, Colocation. [Read the reference](/en/documentation/platform/connectors.md).

1) A [workload](/en/documentation/platform/workloads/) receives the traffic for its domains. It holds the [domains](/en/documentation/platform/workloads/domains/) and the certificate from [Certificate Manager](/en/documentation/platform/workloads/#certificate-manager), and it binds, side by side, a firewall, an application, and a custom page set.
2) A [firewall](/en/documentation/platform/firewall/) inspects each request before the application. You apply a [WAF](/en/documentation/platform/firewall/#waf) rule set, [Bot Manager](/en/documentation/platform/firewall/#bot-manager), [Network Shield](/en/documentation/platform/firewall/#network-shield) lists, and functions to it. [DDoS Protection](/en/documentation/platform/workloads/#ddos-protection) is always on, with or without a firewall.
3) An [application](/en/documentation/platform/applications/) serves the content. Its [Rules Engine](/en/documentation/platform/applications/rules-engine/) applies behaviors, [Cache](/en/documentation/platform/applications/#cache) answers repeat requests from a stored copy, [Image Processor](/en/documentation/platform/applications/#image-processor) resizes images on the way, and [Functions](/en/documentation/platform/functions/) run your code in the request path.
4) A [custom page set](/en/documentation/platform/workloads/#custom-pages) replaces the default error responses with pages you control.
5) When the cache cannot answer, the application fetches the content through a [connector](/en/documentation/platform/connectors/): an HTTP connector reaches your origin server, and a [storage connector](/en/documentation/platform/connectors/settings/#storage) reads an Object Storage bucket. [Load Balancer](/en/documentation/platform/connectors/#load-balancer) and [Origin Shield](/en/documentation/platform/connectors/#origin-shield) are enabled on the connector.
6) Functions call what the Store card holds, [SQL Database](/en/documentation/platform/sql-database/), [KV Store](/en/documentation/platform/kv-store/), and [Object Storage](/en/documentation/platform/object-storage/), and what the AI card holds, [AI Inference](/en/documentation/platform/ai-inference/).

To move an application that already runs elsewhere onto this chain, refer to [Migrate to Azion](/en/documentation/fundamentals/migrate-to-azion/).

## Interfaces

You create and manage every resource in the chain through the Platform's interfaces. [Azion Console](/en/documentation/guides/platform/account-and-billing/getting-to-know-azion-console/) is the web interface, [Azion CLI](/en/documentation/devtools/cli/) drives the same operations from a terminal, the [Azion API](https://api.azion.com/) exposes them over HTTPS for integrations, and the [Azion Terraform Provider](/en/documentation/devtools/terraform/) declares them as code. Azion's catalog groups what you enable on those resources into four categories: Build, Store, Secure, and Observe. For the request path and the table of what each resource holds, refer to [How Azion works](/en/documentation/fundamentals/how-it-works/).

---

## Your account

Everything you build on Azion lives inside an [account](/en/documentation/fundamentals/account-settings/). The account holds the resources, the people who work on them, the billing profile, and the security controls that apply to every sign-in. Each person signs in as a user of the account. The account owner creates teams and sets their permissions, and each user belongs to one or more teams that decide which resources they can view or change. A Group account also holds [client accounts](/en/documentation/fundamentals/accounts/), each with its own owner. Usage is metered per account and becomes an invoice on the [Billing](/en/documentation/fundamentals/billing-and-subscriptions/) page.

If you do not have an account yet, refer to [Create an account](/en/documentation/fundamentals/creating-account/). For the full model, refer to [Accounts, teams, and users](/en/documentation/fundamentals/accounts-teams-and-users/).

---

## Next steps

- [First deploy](/en/documentation/fundamentals/first-deploy.md): Put an application on Azion in a few minutes.
- [How Azion works](/en/documentation/fundamentals/how-it-works.md): Follow a request through Azion's distributed infrastructure to your origin.
- [Accounts, teams, and users](/en/documentation/fundamentals/accounts-teams-and-users.md): Find out where each setting lives and who can change it.
- [Members and permissions](/en/documentation/fundamentals/teams-permissions.md): Add people to the account and control what each of them can do.
