Connect an application to an origin
Create a connector to an HTTP origin, then send the requests of an application to it with a Rules Engine rule, from Azion Console or the API.
You can connect an application to an origin with a connector and a Rules Engine rule that sets it. The origin, also called the backend, is the server Azion retrieves your content from. It can be an object storage service, a cloud server, or other infrastructure that hosts your application’s assets or data. You create both from Azion Console or the API.
To serve the objects of a bucket, refer to Use a bucket as an application origin. To spread requests across several addresses, refer to Balance traffic across multiple origins. An account that has not migrated to API v4 configures origins in the legacy Origins of the application. For more information, refer to Origins.
Choose the interface you work in. The prerequisites and the procedures change with your choice.
Prerequisites
- An application served by a workload. To create both, refer to Applications quickstart.
- Access to Azion Console. To sign in, refer to Access Azion Console.
Create a connector to the origin
A connector holds the address of the origin and the options Azion uses to connect to it. In Azion Console, you set up connectors in the Connectors menu, not in a tab of the application. For each field of that form, refer to Connector settings. The connector in this section reaches httpbin.org over HTTPS.
To create the connector with the API, send a POST request to the connectors endpoint:
The body sets four values:
| Key | What it sets |
|---|---|
type | http connects to an HTTP or HTTPS origin. |
addresses | The address of the origin. A connector to a single origin carries one address. |
transport_policy | force_https makes Azion connect to the origin over HTTPS, whatever protocol the user’s request used. |
host | The value Azion sends in the Host header to the origin. |
The API answers 202 and returns the connector:
The response fills in what the body left out. The connector and its address are active, the address uses port 80 for HTTP and 443 for HTTPS, and Load Balancer and Origin Shield are disabled under modules. Copy the value of data.id: the rule that sends requests to the connector names it by this ID.
Address, path, and Host header
Enter the address as a domain name or an IPv4 or IPv6 address, without http:// or https://. The transport_policy key sets the protocol instead. When the content sits under a path, such as https://bucket.s3.amazonaws.com/applications/your-app, split the URL. The hostname, bucket.s3.amazonaws.com, goes in the address, and the path, /applications/your-app, goes in the connector’s path prefix, path_prefix. An address that carries the path makes the requests to the origin fail.
The host key takes a fixed domain name or the ${host} variable. Azion sends a fixed name, such as httpbin.org, whatever domain the user requested. Use a fixed name when the origin serves a single virtualhost, or answers a virtualhost at an address other than the one in DNS. A fixed name also fits an origin that needs a specific hostname for routing, certificate matching, or access control. ${host}, the default, forwards the Host header of the user’s request, for an origin that serves several virtualhosts from one address. An empty value is refused.
An origin that requires HMAC authentication, such as a private object storage bucket, needs a valid region, access key, and secret key on the connector. Without valid credentials the origin refuses the request: the S3 endpoint of Azion Object Storage answers an unsigned request with 401 and UnauthorizedAccess. A change to the address or the Host header of a connector reaches every rule that sets it. Review those rules before you change a connector that serves production traffic.
Send requests to the connector
A connector receives no request until a rule sets it. The rule in this section runs in the Request Phase of the application. Its criterion matches every path, with the ${uri} variable, the starts_with operator, and / as the argument, and its behavior sets the connector. An application starts with no rules, so this rule is what sends its requests to the origin.
To send a single path instead, such as /httpbin, use the is_equal operator with that path as the argument. With that rule alone, a request to any other path receives 404.
The ${uri} variable works on every application. A criterion on ${request_uri} needs Application Accelerator on the application. For every variable and operator, refer to Rules Engine for Applications.
To create the rule with the API, send a POST request to the request_rules endpoint of the application. Replace <application-id> with the ID of your application, and <connector-id> with the ID of the connector:
The API answers 202 and returns the rule:
The rule is the first of the application’s Request Phase, at order 0.
The same rule with ${request_uri} in place of ${uri}, on an application without Application Accelerator, is refused with 400:
The error points at the variable in source.pointer and names the missing Product in meta.missing_required_modules.
For the behavior and its attributes, refer to Set Connector.
Confirm that the application reaches the origin
The rule takes a few minutes to propagate. Until then, the application answers as it did before the rule existed.
To confirm the route, send a request to the domain of your workload, with that domain in place of <your-workload-domain>:
The response is the one httpbin.org returns for /. A workload’s domain ends in .map.azionedge.net, and the API returns it in workload_domain when it creates the workload. If the response does not come from the origin yet, send the request again until it does. If it never does, refer to Troubleshoot Applications.