---
name: azion-add-a-backup-origin-to-a-connector
description: >-
  Keep a standby origin out of daily traffic, and let it receive requests only when every primary address of the connector fails.
---

# Add a backup origin to a connector

You add a standby origin to a [connector](/en/documentation/platform/connectors/) as a *Backup* address of [Load Balancer](/en/documentation/platform/connectors/#load-balancer), from Azion Console, the API, or the Azion CLI. To spread live traffic across several origins with weights instead, refer to [Balance traffic across multiple origins](/en/documentation/guides/application-performance/availability/multiple-origins/).

A *Backup* address stands by out of daily traffic, and it receives requests only when every *Primary* address fails. *Primary* addresses are always preferred, so the standby carries no traffic while the primary answers. Load Balancer has no health check: no probe and no interval, so nothing tests an address between requests.

```mermaid
%%{init: {"layout": "dagre", "themeVariables": {"fontSize": "13px"}, "flowchart": {"nodeSpacing": 12, "rankSpacing": 12, "padding": 6, "wrappingWidth": 70, "minNodeWidth": 40, "useMaxWidth": true}}}%%
flowchart TD
  Rule["A Set Connector rule names the connector"] --> Role{"Does a Primary address answer?"}
  Role -->|"yes"| Primary["The Primary address receives the request"]
  Role -->|"no: every Primary address fails"| Backup["The Backup address receives the request"]
  Primary --> Client["The client receives the response"]
  Backup --> Client
```

1. A rule's *Set Connector* behavior sends the request to the connector, which has Load Balancer on.
2. While a *Primary* address answers, it receives every request, and the *Backup* address receives none.
3. When every *Primary* address fails, the *Backup* address receives the request.
4. The client receives the response from the address that served it, with no DNS change.

---

## Prerequisites

- A connector of type `http` that reaches your primary origin, and a rule whose *Set Connector* behavior sends requests to it. To create both, refer to [Connectors quickstart](/en/documentation/platform/connectors/quickstart/).
- A standby origin that holds the same content as the primary and is set up the same way for the application.
- Access to Azion Console, for the Console procedure. Refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/) and the ID of the connector, for the API procedure.
- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized, and the ID of the connector, for the CLI procedure.

The examples use `primary.example.com` for the primary origin, `standby.example.com` for the standby, and `www.example.com` for the domain. Replace them with yours.

---

## Add the standby as a backup address

A connector holds one address until Load Balancer is on, and up to 15 addresses with it on. The method is *Round Robin* or *Least Connections*, because *IP Hash* refuses a *Backup* address with `28005`. Every address is *Primary* unless you set it otherwise.

**Max Retries** sets the retry attempts when a connection to the origin fails, from 0 to 20. **Connection Timeout** limits the wait for that connection, from 1 to 300 seconds, and **Read/Write Timeout** limits the wait for data on an open connection, from 1 to 600 seconds. The client waits through every retry before it receives an answer. The Console fills in `3`, `30`, and `60`. The API and the CLI give a key the body leaves out `0`, `60`, and `120`, so a connector without `max_retries` does not retry a failed connection. The examples set the Console values in every interface.

**Console**

To add the backup address in Azion Console:

1. **Open the connector**

   Access [Azion Console](https://console.azion.com/) > **Connectors**, and select the connector of your primary origin.

2. **Turn on Load Balancer**

   In **Modules**, turn on **Load Balancer**. The form fills in **Max Retries**, **Connection Timeout**, and **Read/Write Timeout**.

3. **Select the method**

   In **Load Balancer Configuration**, set **Method** to *Round Robin*.

4. **Set the retries and timeouts**

   Enter `3` in **Max Retries**, `30` in **Connection Timeout**, and `60` in **Read/Write Timeout**.

5. **Keep the primary origin as primary**

   Under **Address Management**, on `primary.example.com`, set **Server Role** to *Primary*.

6. **Select Add Address**

7. **Enter the standby**

   In the new **Address**, enter `standby.example.com`, without a protocol or a port.

8. **Set the backup role**

   Set **Server Role** to *Backup*, and keep **Active** turned on.

9. **Select Save**

The Console shows `Connector has been updated`.

**API**

To add the backup address with the API, send a `PATCH` request to the connector. `addresses` replaces the list of addresses, so the body carries both:

```bash
curl --request PATCH \
  --url https://api.azion.com/v4/workspace/connectors/<connector-id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token <personal-token>' \
  --header 'Content-Type: application/json' \
  --data '{
  "attributes": {
    "addresses": [
      {
        "address": "primary.example.com",
        "modules": { "load_balancer": { "server_role": "primary", "weight": 1 } }
      },
      {
        "address": "standby.example.com",
        "modules": { "load_balancer": { "server_role": "backup", "weight": 1 } }
      }
    ],
    "modules": {
      "load_balancer": {
        "enabled": true,
        "config": { "method": "round_robin", "max_retries": 3, "connection_timeout": 30, "read_write_timeout": 60 }
      }
    }
  }
}'
```

The API answers `202` with `"state": "pending"`. A `PATCH` keeps the connection options the body leaves out.

**CLI**

The update command takes the whole connector from a file, with every field the connector keeps. To read the current settings of the connector:

```bash
azion describe connector --connector-id <connector-id> --format json
```

The command prints the full object. On a connector of type `http`, `attributes` holds `addresses`, `connection_options`, and `modules`.

Save the connector as `connector.json`, with the standby added and Load Balancer on. Replace `name` and `connection_options` with the values the command printed:

```json
{
  "name": "<connector-name>",
  "active": true,
  "type": "http",
  "attributes": {
    "addresses": [
      {
        "address": "primary.example.com",
        "modules": { "load_balancer": { "server_role": "primary", "weight": 1 } }
      },
      {
        "address": "standby.example.com",
        "modules": { "load_balancer": { "server_role": "backup", "weight": 1 } }
      }
    ],
    "connection_options": {
      "dns_resolution": "both",
      "transport_policy": "preserve",
      "host": "${host}"
    },
    "modules": {
      "load_balancer": {
        "enabled": true,
        "config": { "method": "round_robin", "max_retries": 3, "connection_timeout": 30, "read_write_timeout": 60 }
      }
    }
  }
}
```

Update the connector from the file. The command needs `--type` even though the file names the type:

```bash
azion update connector --connector-id <connector-id> --type http --file connector.json
```

The output confirms the update:

```text
Updated Connector with ID <connector-id>
```

The connector holds the primary origin and the standby, and the rule that names it needs no change. A connector change reaches Azion's distributed infrastructure over several minutes, and data centers apply it at different times.

Both addresses receive the same `Host` header, path prefix, and protocol from the connector. When the standby answers under another name than the primary, set **Host** to `${host}`, which sends the host the client requested. For the connection options, refer to [Connector settings](/en/documentation/platform/connectors/settings/#connection-options).

---

## Confirm the standby takes over

The check takes the primary out of service, so run it in a maintenance window. It reads **Upstream Addr** in the *HTTP Requests* data source of Real-Time Events, which holds the IP address and port of the server a request was sent to.

To confirm the failover:

1. **Stop the primary origin**

   Stop the web server on `primary.example.com`, or block the connections from Azion at its firewall.

2. **Send requests through your domain**

   ```bash
   curl -s -o /dev/null -w '%{http_code}\n' https://www.example.com/
   ```

   The command prints the status code of each response. Send it several times.

3. **Open Real-Time Events**

   Access [Azion Console](https://console.azion.com/) > **Products menu** > **Observe** > **Real-Time Events**, and select *HTTP Requests* in **Data Sources**.

4. **Filter by your domain**

   In **Filter by**, enter `host='www.example.com'`, and select **Refresh**.

5. **Read the upstream address**

   The newest records carry the IP address of `standby.example.com` in **Upstream Addr**.

6. **Start the primary origin again**

The standby serves the requests while the primary is down. Once the primary answers again, it takes the requests back, because *Primary* addresses are always preferred over *Backup* addresses. A data center that has not received a change yet can still answer as before, so repeat the search until the records agree. For the filter syntax, refer to [Filter events](/en/documentation/guides/platform/observability/add-filters-events/).

---

## Next steps

- [Balancing methods](/en/documentation/platform/connectors/load-balancer/balancing-methods.md#server-role): How the server role, the retries, and the timeouts decide where a request goes.
- [Show your own page when no origin answers](/en/documentation/guides/application-performance/availability/show-your-own-page-when-no-origin-answers.md): Replace Azion's error with your page when neither the primary nor the standby answers.
- [Keep an application online when an origin fails](/en/documentation/use-cases/improve-performance-and-reliability/keep-an-application-online-when-an-origin-fails.md): A primary and a standby origin in one pool, with an error page when both fail.
- [Route users to regional origins](/en/documentation/use-cases/improve-performance-and-reliability/route-users-to-regional-origins.md): A default region with a backup in another region, only where residency rules allow it.
