Configure HTTP and HTTPS ports
Choose the HTTP and HTTPS ports a workload listens on, and send each port to an origin port, from Azion Console, the Azion CLI, or the API.
You can choose the ports a workload listens on for HTTP and HTTPS, and send the requests of each port to an origin port, from Azion Console, the Azion CLI, or the API. For the TLS version and the cipher suite of the HTTPS ports, refer to Set the TLS cipher suite.
Two ports take part in every request. The delivery port is the port your users connect to, and the workload sets it. The origin port is the port Azion connects to on your origin, and the connector of the application sets it. Each one has a default, 80 for HTTP and 443 for HTTPS, and you can change either one without the other.
This table shows the combinations, with an example request and the setting each one changes:
| Combination | Origin URL | Delivery URL | What to change |
|---|---|---|---|
| Default origin port, default delivery port | https://origin.example.com:443 | https://www.example.com:443 | Nothing |
| Default origin port, other protocol than the delivery port | http://origin.example.com:80 | https://www.example.com:443 | The protocol policy of the connector |
| Default origin port, custom delivery port | http://origin.example.com:80 | http://www.example.com:8080 | The ports of the workload |
| Custom origin port, default delivery port | https://origin.example.com:9443 | https://www.example.com:443 | The ports of the connector |
| Custom origin port, custom delivery port | https://origin.example.com:8443 | https://www.example.com:9443 | The ports of the workload and of the connector, and one rule per custom delivery port |
An account that runs on API v3 sets its delivery ports on the application instead. For more information, refer to Main Settings and API v4 Migration.
Select an interface. The prerequisites and the steps of each task follow your choice.
Prerequisites
- A workload whose deployment names an application. To create both, refer to Workloads quickstart.
- For a custom origin port, a connector to your origin that the application’s rules can name. To create a connector and a rule, refer to Applications quickstart.
- Access to Azion Console. For more information, refer to How to access Azion Console.
Set the ports the workload listens on
The HTTP and HTTPS ports of a workload are two lists in its protocols.http object. HTTP ports come from four values: 80, 8008, 8080, and 8880. HTTPS ports come from twelve: 443, 8443, 9440, 9441, 9442, 9443, 7777, 8888, 9553, 9653, 8035, and 8090. A new workload listens on 80 and 443.
To set the ports with the Azion CLI, save a JSON file with the workload ID and the whole protocols.http object, here as ports.json. This example listens on 80 and 8080 for HTTP, and on 443 and 8443 for HTTPS:
The versions list in this file leaves out HTTP/3. To keep HTTP/3, add http3 to versions and an HTTP/3 port to quic_ports, as Workload settings describes.
Update the workload with the file:
The command prints the ID of the workload it updated:
To confirm the change, describe the workload:
This excerpt of the output shows the ports in protocols.http:
Two refusals stop the change. An HTTP port outside the four values is refused with Invalid choices for multiple choices field: [80, 8008, 8080, 8880]. A versions list that holds http3 without http1 and http2 is refused with Missing required choices for multiple choices field: ['http1', 'http2']. For every refusal and its fix, refer to Workload settings.
A workload change takes several minutes to reach all of Azion’s distributed infrastructure, and requests can receive the old or the new ports meanwhile. Repeat a request until the answers agree.
Set the origin port on the connector
The origin port belongs to the connector that a rule of the application names, not to the workload. Each address of a connector carries two origin ports: http_port, 80 by default, and https_port, 443 by default. For an origin that listens on another port, set that port on the address when you create or edit the connector.
The connector’s transport_policy decides whether Azion connects to the origin over HTTP or HTTPS. For example, force_https makes every connection to the origin use HTTPS, whatever protocol the user’s request used. For each policy and the protocol it uses, refer to Connector settings.
When two delivery ports need different origin ports, create one connector per origin port. Then route each delivery port to its connector with a rule, as Route a custom port to its connector shows.
Route a custom port to its connector
A rule on the application can send the requests of one delivery port to the connector of one origin port. The rule runs in the request phase. Its criterion compares ${server_port}, the port of the server that receives the request, with the delivery port. Its behavior, Set Connector, names the connector. For the variables and the behavior, refer to Rules Engine for Applications.
This example sends the requests that arrive on delivery port 8080 to a connector whose address uses the origin port you want.
To create the rule with the Azion CLI, keep the rule in a file: on a command line, the shell would expand ${server_port}. Save this body as rule.json, and replace <connector-id> with the ID of the connector:
Create the rule in the request phase of your application. Replace <application-id> with the ID of your application:
The command prints the ID of the rule it created:
Once the rule propagates, a request that arrives on delivery port 8080 reaches your origin on the port of the connector the rule names. For each other custom delivery port, create one more rule with that port as the argument and its own connector.