Connectors
Connect your applications to the origins that hold your content, balance requests across addresses, and protect and sign origin requests.
A reverse proxy answers clients on behalf of a server you run, called the origin. When the proxy cannot answer from what it already holds, it opens its own connection to the origin and forwards the request. On that connection, it decides how to address the origin: the hostname in the Host header, the path, the protocol, and the port. Clients never connect to the origin, so you can move or protect the origin without any change on the client side.
Connectors is the Platform Resource that holds those decisions on Azion. A connector is an object of its own: it stores the address of your origin and the settings that shape every request to it, and a rule in an application sends requests to it with the Set Connector behavior. Several applications can reuse one connector, so the connection settings of an origin live in one place. Use Connectors to send traffic to a cloud server or a server in your data center, serve objects from an Object Storage bucket, spread requests across several servers, keep clients from reaching your origin directly, or deliver a live stream.
Quickstart Connector settingsConnector object
A connector is one JSON object. This body creates a connector of type http that sends requests to httpbin.org over HTTPS:
typedecides what the connector reaches:httpfor a server you run,storagefor an Object Storage bucket, orlive_ingestfor a live stream.addresseslists the origin servers, each a hostname or an IP address with no protocol and no port. Every address takes the ports80and443unless you set others.connection_optionsshapes each request to the origin. Here,force_httpsconnects over HTTPS only, andhostsends the origin its own name instead of the hostname the client requested, which is the default${host}.- Every key left out takes its default, and Load Balancer and Origin Shield stay off.
Sent to POST /v4/workspace/connectors, this body answers 202 with "state": "pending" and the full object, every default filled in. If you know an upstream from another proxy, a connector is that object, stored apart from the rules that send traffic to it. For every field and its default, refer to Connector settings.
Request path
Creating a connector does not send traffic to it. A connector receives requests only from an application rule that names it, and the application itself serves only the hostnames of a workload whose deployment names that application.
- A client requests a hostname of a workload, and the workload’s deployment hands the request to the application.
- The application runs its Request Phase rules in order. A matching rule with the Set Connector behavior names one connector.
- When a cache setting applies and a valid copy is stored, Azion answers from cache, and the request never reaches the connector.
- Otherwise, the connector opens a connection to its address and sends the request with its
Hostheader, path prefix, and protocol. - The origin answers the connector, the application runs its Response Phase rules, and the client receives the response.
A rule names the connector by its ID, so every rule that names it, in any application, follows a change to the connector without an edit of its own. The dependency also runs the other way: the API refuses to delete a connector that a rule still names. For each step of the path, refer to How Connectors works. For a request that fails along it, refer to Troubleshoot Connectors.
Resources
Load Balancer and Origin Shield act on a connector of type http once you enable them on the connector. Live Ingest acts through a connector of its own type, live_ingest.
Load Balancer
Load Balancer spreads the requests of one connector across up to 15 addresses, so your content stays available when one origin server fails and no single server carries all the load. A balancing method, Round Robin, Least Connections, or IP Hash, chooses the address for each request, and the weight and server role of each address shape that choice. The rules that name the connector still decide which requests are balanced.
For how each method chooses an address, refer to Balancing methods, and to enable it on your first connector, refer to the Load Balancer quickstart.
Origin Shield
Origin Shield protects the origin of a connector of type http in two ways. With Origin IP ACL, your origin’s firewall accepts only the IPv4 and IPv6 prefixes of the Azion Origin Shield network list, a perimeter at layers 3 and 4 that refuses every connection from another source. With HMAC, the connector signs each request with the credentials of an S3-compatible storage provider, so a private bucket answers it. Turn it on when clients must not reach your origin directly, or when the origin serves only signed requests.
For how each defense works and how the list is updated, refer to Origin IP ACL and HMAC. To serve a private bucket through a signed connector, refer to Sign origin requests with HMAC.
Live Ingest
Live Ingest takes a live stream that your encoder pushes over RTMP, in the region of a connector of type live_ingest, and converts it to HLS. An application then delivers the stream to viewers through that connector. Use it for live events, e-sports matches, and educational broadcasts.
For how the stream reaches Azion and the viewers, refer to Ingestion and delivery.
Scope and limits
- Connector types: a connector of type
httpreaches servers you run by hostname or IP address, such as a cloud server, a server in your data center, or an S3-compatible endpoint. It is the only type with addresses, connection options, Load Balancer, and Origin Shield. A connector of typestoragereads a bucket of Object Storage in your account, narrowed to a prefix, and a connector of typelive_ingesttakes a live stream in one of five regions. Azion Console offers the three as the Connector Type cards HTTP, Object Storage, and Live Ingest. For the fields of each, refer to Connector settings. - Interfaces: you create and manage connectors on the Connectors page of Azion Console, through the Azion API at
/v4/workspace/connectors, and with theazion_connectorresource of Terraform. Azion CLI takes no flag per setting:azion create connector --type http --file my-connector.jsonreads the JSON body from a file and printsCreated Connector with ID <connector-id>. - Limits: a connector holds one address, or up to 15 with Load Balancer on, and its
nametakes 1 to 255 characters. For every bound and the error past it, refer to Connectors limits. - Timeouts: a connector without Load Balancer has no configurable timeout and follows the platform defaults listed in How Connectors works. With Load Balancer on, the connection timeout, the read and write timeout, and the retries on a connection failure become settings.
- Rule precedence: when several matching rules carry the Set Connector behavior, only the last one runs. One application can therefore send
/images/to a connector of typestorageand every other path to a connector of typehttp. To write the rules, refer to Rules Engine for Applications. - Propagation: a connector change takes effect without another deployment, and it reaches Azion’s distributed infrastructure in several minutes, with data centers applying it at different times. Until then, requests can meet the old or the new settings. For how to plan a change around it, refer to Connectors best practices.
- Testing: a connector receives only the requests of the rules that name it. A rule that matches one path sends that path alone to the connector you are trying, while every other path keeps its current origin, as the Connectors quickstart does.
- DNS-level balancing: Load Balancer chooses among the addresses of one connector, after the request reaches Azion. Weighted DNS records that split traffic between IP addresses at resolution time belong to Edge DNS, as How to perform a load balance between DNS records shows.
- Origin offload: Origin Shield protects the origin with an allowlist and request signing. A second cache layer between Azion’s cache and your origin, which cuts the requests that reach it, is Tiered Cache, turned on per cache setting of the application.
- SNI Check: on an HTTPS request, Azion compares the hostname the client requests with the names the workload’s certificate covers, and answers
421 Misdirected Requestwhen the certificate cannot cover it. For the decision steps, refer to SNI Check. - API v4: on API v3, the origins of an application carried the role of a connector, and Connectors replaces them on API v4. For an account that still runs API v3, refer to Origins, and for the mapping between the two models, refer to API v4 Migration.
- Observability: Data Stream records the origin leg of each request in its
$upstream_*variables, such as$upstream_status, the HTTP status code of the origin, and$upstream_response_time, the time to receive the origin’s response. A cached response carries-in both. - Billing: every plan includes Single Origin, a connector with one address. Load Balancer is billed on Data Transfer, Origin Shield on Shielded Connectors, and Live Ingest on Data Ingestion. For the amounts each plan includes, refer to Connectors limits, and for the rates, refer to Pricing.
- Terms: the Connectors glossary defines the words these pages give a specific meaning, such as address, server role, path prefix, and Single Origin.