How Azion works
Follow a request from the user through Azion's distributed infrastructure to your origin, and see what each resource on the path adds along the way.
A request for your application does not travel to a server you run. It reaches the data center of Azion’s distributed infrastructure with the best route to it, and the configuration you saved decides what happens next: whether the request is blocked, answered from cache, handled by your code, or forwarded to your origin. Azion Platform is the integrated technology and the set of interfaces where that configuration lives, and where you build, secure, and scale applications, which includes operating and monitoring them.
Azion includes content delivery and caching, but it is broader than a CDN. The same infrastructure runs application code with no server to provision, filters the traffic that reaches your applications and APIs, stores the data they read, and reports every request in real time. This page covers where the platform runs, the path a request takes, what you enable on each resource of that path, and the interfaces you manage it through.
Distributed infrastructure
Azion runs your configuration in data centers spread across the world, and each request is served by the data center with the best route to it. The route is chosen by latency, network conditions, and load at the moment the request arrives, so two users in different countries requesting the same page are each served nearby, from the same configuration. Compute and data sit close to the user, which reduces latency and improves reliability. Deploys are fast, functions run with no cold starts, and visibility into traffic is real time. For the list of data centers, refer to Our Network.
Request path
The diagram shows the path of one request, from the user to your origin and back. Inside Azion Platform, the request is routed to a data center, where the resources you configured run, and content that the data center cannot answer is fetched through the delivery layer:
Requests travel from left to right. Responses return along the same path.
- The user’s request reaches Azion. Azion selects the best route and forwards the request to the nearest data center, based on latency, network conditions, and load.
- At that data center, Azion applies your configuration and logic: the workload that owns the domain, the security policies of its firewall, the caching behavior and rules of its application, and the code of the functions they run.
- When the cache cannot answer the request, the application fetches the content from your origin through its connector. Tiered Cache adds a second cache layer between the data centers and your origin, and Load Balancer spreads the fetch across several addresses.
- The response is delivered to the user, and the request appears in your metrics, events, and streams.
The resources on that path bind to one another: a workload binds a firewall, an application, and a custom page set, and the application fetches through a connector. For the interactive diagram and what each resource attaches to, refer to Platform resources topology.
Platform resources on the request path
Everything you enable or create lives on the resources of the request path. Some of it is enabled on a resource you already have, such as a rule set applied to the firewall or a switch on the application; the rest are resources you create on their own, such as a bucket or a DNS zone. The table lists each one by the resource it attaches to, with a link to its reference:
| Resource | What you enable or create on it | Reference |
|---|---|---|
| Workload | The TLS certificate bound to the workload, and DDoS mitigation, which applies to every workload with nothing to enable. | Certificate Manager, DDoS Protection |
| Firewall | A WAF rule set applied to the firewall, a Bot Manager instance running on it, and the network lists its rules reference. | WAF, Bot Manager, Network Shield |
| Application | Cache settings, the Application Accelerator and Image Processor switches, the functions instantiated on the application, and the custom page set assigned to it. | Cache, Application Accelerator, Image Processor, Custom Pages |
| Connector | Load balancing across several addresses, and Origin Shield, which lets only Azion’s IP ranges reach the origin. | Load Balancer, Origin Shield |
| Resources you create on their own | Functions, buckets, databases, key-value namespaces, DNS zones, streams, and the infrastructure you run yourself with Orchestrator. | Functions, Object Storage, SQL Database, KV Store, Edge DNS, Data Stream, Orchestrator |
| Inside a function | The models your code calls, and the adapters you fine-tune for them. | AI Inference, LoRA Fine-Tune |
| Everything above | The raw events, metrics, and real-user measurements that report what the platform did with each request. | Real-Time Events, Real-Time Metrics, Edge Pulse |
Every control in the table can be automated through the API and infrastructure as code. Azion’s catalog groups everything in the table into four categories, Build, Store, Secure, and Observe; the pricing page is organized that way.
What you can build
The same chain of resources serves very different workloads. Azion organizes them into five solutions, and the use cases below are the ones teams most often start from. Each one links to the architecture that implements it, or, where no architecture is published yet, to the reference it starts from.
Build and run applications
Improve application performance and reliability
- Keep an application online when an origin fails
- Optimize images for websites and mobile apps
- Monitor website and API performance
Build and run AI workloads
Secure applications and networks
- Protect web applications from OWASP Top 10 and zero-day attacks
- Protect public APIs from abuse
- Block account takeover on login and checkout flows
Deliver media and streaming content
Templates and integrations give many of these a deployable starting point, the guides cover frameworks and step-by-step tasks, and Migrate to Azion covers moving an application that already runs elsewhere.
Interfaces
You manage the Platform yourself, through interfaces that expose the same resources. Azion Console configures resources, provisioning, billing, and permissions in the browser. Azion CLI manages services from the terminal and is open source, written in Go. The Azion API is a REST API over HTTPS for integration and automation, and the Azion Terraform Provider manages Azion resources as code.
Some origins accept connections only from known addresses. To allow Azion’s data centers through your origin’s firewall, refer to How to retrieve Azion IP ranges for origin server allowlisting.
For the fundamentals of distributed architectures, watch the Introduction to Platform Foundations playlist.