# How Azion works

A request for your application does not travel to a server you run. It reaches the data center of Azion's distributed infrastructure with the best route to it, and the configuration you saved decides what happens next: whether the request is blocked, answered from cache, handled by your code, or forwarded to your origin. **Azion Platform** is the integrated technology and the set of interfaces where that configuration lives, and where you build, secure, and scale applications, which includes operating and monitoring them.

Azion includes content delivery and caching, but it is broader than a CDN. The same infrastructure runs application code with no server to provision, filters the traffic that reaches your applications and APIs, stores the data they read, and reports every request in real time. This page covers where the platform runs, the path a request takes, what you enable on each resource of that path, and the interfaces you manage it through.

---

## Distributed infrastructure

Azion runs your configuration in data centers spread across the world, and each request is served by the data center with the best route to it. The route is chosen by latency, network conditions, and load at the moment the request arrives, so two users in different countries requesting the same page are each served nearby, from the same configuration. Compute and data sit close to the user, which reduces latency and improves reliability. Deploys are fast, functions run with no cold starts, and visibility into traffic is real time. For the list of data centers, refer to [Our Network](https://www.azion.com/en/products/our-network/).

## Request path

The diagram shows the path of one request, from the user to your origin and back. Inside Azion Platform, the request is routed to a data center, where the resources you configured run, and content that the data center cannot answer is fetched through the delivery layer:

```mermaid
flowchart LR
  user([User]) --> routing[Routing]
  subgraph platform [Azion Platform]
    routing --> dc
    subgraph dc [Data center]
      firewall[Firewall]
      applications[Applications]
      cache[Cache]
      accelerator[Application Accelerator]
      functions[Functions]
      image[Image Processor]
    end
    dc --> delivery[Tiered Cache and Load Balancer]
  end
  delivery --> origin[(Origin)]
```

Requests travel from left to right. Responses return along the same path.

1. The user's request reaches Azion. Azion selects the best route and forwards the request to the nearest data center, based on latency, network conditions, and load.
2. At that data center, Azion applies your configuration and logic: the workload that owns the domain, the security policies of its firewall, the caching behavior and rules of its application, and the code of the functions they run.
3. When the cache cannot answer the request, the application fetches the content from your origin through its connector. [Tiered Cache](/en/documentation/platform/applications/#cache) adds a second cache layer between the data centers and your origin, and [Load Balancer](/en/documentation/platform/connectors/#load-balancer) spreads the fetch across several addresses.
4. The response is delivered to the user, and the request appears in your metrics, events, and streams.

The resources on that path bind to one another: a workload binds a firewall, an application, and a custom page set, and the application fetches through a connector. For the interactive diagram and what each resource attaches to, refer to [Platform resources topology](/en/documentation/fundamentals/#platform-resources-topology).

---

## Platform resources on the request path

Everything you enable or create lives on the resources of the request path. Some of it is enabled on a resource you already have, such as a rule set applied to the firewall or a switch on the application; the rest are resources you create on their own, such as a bucket or a DNS zone. The table lists each one by the resource it attaches to, with a link to its reference:

| Resource                          | What you enable or create on it                                                                                                                                  | Reference                                                                                                                                                                                                                                                                                                                                                                                        |
| --------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Workload                          | The TLS certificate bound to the workload, and DDoS mitigation, which applies to every workload with nothing to enable.                                          | [Certificate Manager](/en/documentation/platform/workloads/#certificate-manager), [DDoS Protection](/en/documentation/platform/workloads/#ddos-protection)                                                                                                                                                                                                                                       |
| Firewall                          | A WAF rule set applied to the firewall, a Bot Manager instance running on it, and the network lists its rules reference.                                         | [WAF](/en/documentation/platform/firewall/#waf), [Bot Manager](/en/documentation/platform/firewall/#bot-manager), [Network Shield](/en/documentation/platform/firewall/#network-shield)                                                                                                                                                                                                          |
| Application                       | Cache settings, the Application Accelerator and Image Processor switches, the functions instantiated on the application, and the custom page set assigned to it. | [Cache](/en/documentation/platform/applications/#cache), [Application Accelerator](/en/documentation/platform/applications/#application-accelerator), [Image Processor](/en/documentation/platform/applications/#image-processor), [Custom Pages](/en/documentation/platform/workloads/#custom-pages)                                                                                            |
| Connector                         | Load balancing across several addresses, and Origin Shield, which lets only Azion's IP ranges reach the origin.                                                  | [Load Balancer](/en/documentation/platform/connectors/#load-balancer), [Origin Shield](/en/documentation/platform/connectors/#origin-shield)                                                                                                                                                                                                                                                     |
| Resources you create on their own | Functions, buckets, databases, key-value namespaces, DNS zones, streams, and the infrastructure you run yourself with Orchestrator.                              | [Functions](/en/documentation/platform/functions/), [Object Storage](/en/documentation/platform/object-storage/), [SQL Database](/en/documentation/platform/sql-database/), [KV Store](/en/documentation/platform/kv-store/), [Edge DNS](/en/documentation/platform/edge-dns/), [Data Stream](/en/documentation/platform/data-stream/), [Orchestrator](/en/documentation/platform/orchestrator/) |
| Inside a function                 | The models your code calls, and the adapters you fine-tune for them.                                                                                             | [AI Inference](/en/documentation/platform/ai-inference/), [LoRA Fine-Tune](/en/documentation/platform/ai-inference/lora-fine-tune/)                                                                                                                                                                                                                                                              |
| Everything above                  | The raw events, metrics, and real-user measurements that report what the platform did with each request.                                                         | [Real-Time Events](/en/documentation/platform/real-time-events/), [Real-Time Metrics](/en/documentation/platform/real-time-metrics/), [Edge Pulse](/en/documentation/platform/edge-pulse/)                                                                                                                                                                                                       |

Every control in the table can be automated through the API and infrastructure as code. Azion's catalog groups everything in the table into four categories, Build, Store, Secure, and Observe; the [pricing page](/en/documentation/fundamentals/pricing/) is organized that way.

## What you can build

The same chain of resources serves very different workloads. Azion organizes them into five solutions, and the use cases below are the ones teams most often start from. Each one links to the architecture that implements it, or, where no architecture is published yet, to the reference it starts from.

### Build and run applications

- [Build REST and GraphQL APIs](/en/documentation/use-cases/build-and-run-applications/build-rest-and-graphql-apis.md)
- [Build e-commerce storefronts](/en/documentation/use-cases/build-and-run-applications/build-e-commerce-storefronts.md)
- [Deploy frontend applications](/en/documentation/use-cases/build-and-run-applications/deploy-frontend-applications.md)

### Improve application performance and reliability

- [Keep an application online when an origin fails](/en/documentation/use-cases/improve-performance-and-reliability/keep-an-application-online-when-an-origin-fails.md)
- [Optimize images for websites and mobile apps](/en/documentation/use-cases/improve-performance-and-reliability/optimize-images-for-websites-and-mobile-apps.md)
- [Monitor website and API performance](/en/documentation/use-cases/improve-performance-and-reliability/monitor-website-and-api-performance.md)

### Build and run AI workloads

- [Build and run customer support AI assistants](/en/documentation/use-cases/build-and-run-ai-workloads/build-and-run-customer-support-ai-assistants.md)
- [Add AI features to existing applications](/en/documentation/use-cases/build-and-run-ai-workloads/add-ai-features-to-existing-applications.md)
- [Build AI agents](/en/documentation/use-cases/build-and-run-ai-workloads/build-ai-agents.md)

### Secure applications and networks

- [Protect web applications from OWASP Top 10 and zero-day attacks](/en/documentation/use-cases/secure-applications-and-networks/protect-web-applications-from-owasp-top-10-and-zero-day-attacks.md)
- [Protect public APIs from abuse](/en/documentation/use-cases/secure-applications-and-networks/protect-public-apis-from-abuse.md)
- [Block account takeover on login and checkout flows](/en/documentation/use-cases/secure-applications-and-networks/block-account-takeover-on-login-and-checkout-flows.md)

### Deliver media and streaming content

- [Stream live events to large audiences](/en/documentation/use-cases/deliver-media-and-streaming/stream-live-events-to-large-audiences.md)
- [Deliver an on-demand video library](/en/documentation/use-cases/deliver-media-and-streaming/deliver-an-on-demand-video-library.md)

[Templates and integrations](/en/documentation/platform/marketplace/) give many of these a deployable starting point, the [guides](/en/documentation/guides/) cover frameworks and step-by-step tasks, and [Migrate to Azion](/en/documentation/fundamentals/migrate-to-azion/) covers moving an application that already runs elsewhere.

---

## Interfaces

You manage the Platform yourself, through interfaces that expose the same resources. [Azion Console](/en/documentation/guides/platform/account-and-billing/getting-to-know-azion-console/) configures resources, provisioning, billing, and permissions in the browser. [Azion CLI](/en/documentation/devtools/cli/) manages services from the terminal and is open source, written in Go. The [Azion API](https://api.azion.com/) is a REST API over HTTPS for integration and automation, and the [Azion Terraform Provider](/en/documentation/devtools/terraform/) manages Azion resources as code.

Some origins accept connections only from known addresses. To allow Azion's data centers through your origin's firewall, refer to [How to retrieve Azion IP ranges for origin server allowlisting](/en/documentation/support/retrieve-azion-ip-ranges/).

For the fundamentals of distributed architectures, watch the [Introduction to Platform Foundations](https://www.youtube.com/watch?v=ZBC8h-0l1FQ\&list=PL02NW2s3y10N0SQ-2mWL9WN-RWHE8atMp) playlist.

---

## Related resources

- [Create an account](/en/documentation/fundamentals/creating-account.md): Open the account that holds every resource you create.
- [First deploy](/en/documentation/fundamentals/first-deploy.md): Put an application on the request path in a few minutes.
- [Migrate to Azion](/en/documentation/fundamentals/migrate-to-azion.md): Bring an existing application and its infrastructure to Azion.
