# Connectors quickstart

This guide instructs you through sending your first path to a second origin with a [connector](/en/documentation/platform/connectors/).

- Create a connector of type `http` that reaches a second origin over HTTPS and sends that origin's own `Host` header.
- Add a rule that points one path of your application at the connector with the *Set Connector* behavior.
- Request that path through your workload and get the answer of the second origin.

Four parts make the chain, listed in the order this guide uses them:

1. The **connector** holds the address of the second origin, the `Host` header it sends, and the protocol it uses to connect.
2. The **rule** on your application matches one path in the request phase. Its *Set Connector* behavior names the connector.
3. The **workload** that already serves your application receives the request. Its deployment needs no change.
4. The **request** for that path meets the rule, and the connector sends it to the second origin. Every other path still reaches the origin of your first connector.

A connector receives no traffic until a rule names it. This guide uses `httpbin.org` as the second origin, a public service that answers every request under `/anything` with a JSON copy of the request it received. The response you verify at the end therefore shows what the connector sent. To use your own origin, replace `httpbin.org` with its hostname, and `/anything` with its path, such as `/api/`.

The connector this guide leaves you with is where the Products of Connectors start. [Load Balancer](/en/documentation/platform/connectors/#load-balancer) spreads requests across up to 15 addresses of one connector. [Origin Shield](/en/documentation/platform/connectors/#origin-shield) protects the origin with an Origin IP ACL and HMAC signing. [Live Ingest](/en/documentation/platform/connectors/#live-ingest) takes a live stream in through a connector of type `live_ingest`.

---

The prerequisites and the three stages show the steps of one interface at a time. Select yours:

## Prerequisites

- An application served by a workload, with a rule that sends every request to a first connector. To create all three, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).
- The workload domain of that [workload](/en/documentation/platform/workloads/), of the form `<id>.map.azionedge.net`. This guide writes it as `<workload-domain>`.
- `curl`, to request the path through your workload.

**Console**

- Access to [Azion Console](https://console.azion.com/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/) on your machine, authorized with a personal token.
- The ID of your application.

**API**

- A personal token for the `Authorization` header.
- The ID of your application.

---

## Create a connector to your second origin

A connector of type `http` holds the address of an origin and the settings Azion uses to reach it. You create it on its own, outside any application. This connector has one address, `httpbin.org`, and connects to it over HTTPS only.

The `Host` header tells the origin which site a request is for. By default, a connector sends the host the client requested, which is your workload domain. This connector sends `httpbin.org` instead, so the origin receives its own name. For more information, refer to [Host header](/en/documentation/platform/connectors/how-it-works/#host-header).

The connector keeps the path of each request as the client sent it. To add a directory of the origin in front of every path, refer to [Path prefix](/en/documentation/platform/connectors/how-it-works/#path-prefix). To serve the objects of a bucket instead of an HTTP origin, refer to [Use a bucket as an application origin](/en/documentation/guides/application-development/data/use-bucket-as-origin/).

**Console**

To create the connector in Azion Console:

1. **Open the Connectors page**

   Access [Azion Console](https://console.azion.com/) > **Connectors**.

2. **Start a new connector**

   The **Create Connector** page opens.

3. **Name the connector**

   In **General**, enter `my-connector` as the **Name**.

4. **Select the HTTP type**

   In **Connector Type**, select *HTTP*.

5. **Enter the address of the second origin**

   Under **Address Management**, enter `httpbin.org` in **Address**, without a protocol or a port.

6. **Send the origin's own name in the Host header**

   In **Host**, enter `httpbin.org`.

7. **Connect to the origin over HTTPS only**

   In **Transport Protocol Policy**, select *Force HTTPS*.

8. **Select Create**

The connector exists in your account, and the rule you add to your application selects it.

**CLI**

To create the connector with the Azion CLI, put it in a JSON file first. Save this body as `connector.json`:

```json
{
  "name": "my-connector",
  "active": true,
  "type": "http",
  "attributes": {
    "addresses": [{ "address": "httpbin.org" }],
    "connection_options": {
      "transport_policy": "force_https",
      "host": "httpbin.org"
    }
  }
}
```

`addresses` lists the origin servers, and `connection_options.host` is the `Host` header the connector sends. `force_https` makes every connection to the origin use HTTPS.

Create the connector from the file. The command needs `--type` even though the file names the type:

```bash
azion create connector --type http --file connector.json
```

The output carries the ID of the new connector:

```text
Created Connector with ID <connector-id>
```

Read the connector back in JSON. Replace `<connector-id>` with the ID from the previous command:

```bash
azion describe connector --connector-id <connector-id> --format json
```

This excerpt of the output shows the connection options, with a value for every option the file left out:

```json
{
 "active": true,
 "attributes": {
  "addresses": [
   {
    "active": true,
    "address": "httpbin.org",
    "http_port": 80,
    "https_port": 443,
    "modules": null
   }
  ],
  "connection_options": {
   "dns_resolution": "both",
   "following_redirect": false,
   "host": "httpbin.org",
   "http_version_policy": "http1_1",
   "path_prefix": "",
   "real_ip_header": "X-Real-IP",
   "real_port_header": "X-Real-PORT",
   "transport_policy": "force_https"
  },
  …
 },
 …
 "id": <connector-id>,
 …
 "name": "my-connector",
 …
 "type": "http",
 …
}
```

`path_prefix` is empty, so the path reaches the origin unchanged. Record the `id`: the rule passes it as `<connector-id>`. The connector exists in your account.

**API**

To create the connector with the API, send a `POST` request to the connectors endpoint. Replace `[TOKEN VALUE]` with your personal token:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/connectors \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "my-connector",
  "type": "http",
  "attributes": {
    "addresses": [{ "address": "httpbin.org" }],
    "connection_options": {
      "transport_policy": "force_https",
      "host": "httpbin.org"
    }
  }
}'
```

`addresses` lists the origin servers, and `connection_options.host` is the `Host` header the connector sends. The API answers with `202`. This excerpt of the response shows the connector, with a value for every setting the request left out:

```json
{
  "state": "pending",
  "data": {
    …
    "id": <connector-id>,
    "name": "my-connector",
    …
    "active": true,
    "product_version": "1.0",
    "type": "http",
    "attributes": {
      "addresses": [
        {
          "active": true,
          "address": "httpbin.org",
          "http_port": 80,
          "https_port": 443,
          "modules": null
        }
      ],
      "connection_options": {
        "dns_resolution": "both",
        "transport_policy": "force_https",
        "http_version_policy": "http1_1",
        "host": "httpbin.org",
        "path_prefix": "",
        "following_redirect": false,
        "real_ip_header": "X-Real-IP",
        "real_port_header": "X-Real-PORT"
      },
      "modules": {
        "load_balancer": { "enabled": false, "config": null },
        "origin_shield": { "enabled": false, "config": null }
      }
    },
    …
  }
}
```

`path_prefix` is empty, so the path reaches the origin unchanged. Record the `id`: the rule passes it as `<connector-id>`. The connector exists in your account.

---

## Send a path to the connector

A rule in [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine/) pairs criteria with behaviors. This rule runs in the request phase of your application. Its criterion, `${uri}` starting with `/anything`, matches every request under that path. Its behavior, *Set Connector*, sends each matching request to the new connector. For more information, refer to [Set Connector](/en/documentation/platform/applications/rules-engine/#set-connector).

The rule from the Applications quickstart matches every path, `/anything` included. When several matching rules carry *Set Connector*, only the last one runs. Keep this rule after the catch-all rule, so it decides the connector for `/anything`. In the API, a new rule goes after the rules the application already has: the second rule of an application is stored with `order` set to `1`.

**Console**

To create the rule in Azion Console:

1. **Open the application**

   Access [Azion Console](https://console.azion.com/) > **Applications**, and select the application from the Applications quickstart.

2. **Select the Rules Engine tab**

3. **Select + Rule**

4. **Name the rule**

   In **General**, enter `send-path-to-connector` as the **Name**.

5. **Select the request phase**

   In **Phase**, select *Request Phase*. A rule's phase cannot change after you create the rule.

6. **Set the criterion**

   Under **Criteria**, select the variable `${uri}` and the operator `starts_with`, and enter `/anything` as the argument.

7. **Select the Set Connector behavior**

   Under **Behaviors**, select *Set Connector*.

8. **Select your connector**

   In **Connector**, select `my-connector`, the connector you created for the second origin.

9. **Select Save**

The rule appears in the **Rules Engine** tab, under the **Request** heading.

**CLI**

To create the rule with the Azion CLI, keep the rule in a file: on a command line, the shell would expand `${uri}`. Save this body as `rule.json`, and replace `<connector-id>` with the ID of the new connector:

```json
{
  "name": "send-path-to-connector",
  "active": true,
  "criteria": [
    [
      {
        "variable": "${uri}",
        "conditional": "if",
        "operator": "starts_with",
        "argument": "/anything"
      }
    ]
  ],
  "behaviors": [
    {
      "type": "set_connector",
      "attributes": { "value": <connector-id> }
    }
  ]
}
```

Create the rule in the request phase of your application. Replace `<application-id>` with the ID of your application:

```bash
azion create rules-engine --application-id <application-id> --phase request --file rule.json
```

The output carries the ID of the new rule:

```text
Created Rules Engine with ID <rule-id>
```

The rule is active on your application, and it sends every request under `/anything` to the connector.

**API**

To create the rule with the API, keep the request body in a file: on a command line, the shell would expand `${uri}`. Save this body as `rule.json`, and replace `<connector-id>` with the ID of the new connector:

```json
{
  "name": "send-path-to-connector",
  "active": true,
  "criteria": [
    [
      {
        "variable": "${uri}",
        "conditional": "if",
        "operator": "starts_with",
        "argument": "/anything"
      }
    ]
  ],
  "behaviors": [
    {
      "type": "set_connector",
      "attributes": { "value": <connector-id> }
    }
  ]
}
```

Send a `POST` request to the request-phase rules of your application. Replace `<application-id>` with the ID of your application:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/applications/<application-id>/request_rules \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data @rule.json
```

The API answers with `202` and `"state": "pending"`, and the response returns the stored rule with its `id` and its `order`. The rule is active on your application, and it sends every request under `/anything` to the connector.

---

## Verify the response

The check is the same whichever interface created the connector and the rule. In the command, replace `<workload-domain>` with the workload domain of your workload.

A new connector and a new rule take several minutes to reach Azion's distributed infrastructure, and data centers apply them at different times. Until then, a request for `/anything` can still reach the origin of your first connector. Repeat the request until the second origin answers. For more information, refer to [Propagation](/en/documentation/platform/connectors/how-it-works/#propagation).

Send a request for the path the rule matches:

```bash
curl -s https://<workload-domain>/anything
```

`httpbin.org` answers with a JSON copy of the request it received. This excerpt keeps the `Host` header and the URL:

```json
{
  …
  "headers": {
    …
    "Host": "httpbin.org",
    …
  },
  …
  "url": "https://httpbin.org/anything"
}
```

`Host` is `httpbin.org`, the value the connector sends, not your workload domain. `url` shows that the path reached the origin unchanged. A request for any other path, such as `/`, still reaches the origin of your first connector. Your application sends one path to a second origin through its own connector.

---

## Next steps

- [Load Balancer quickstart](/en/documentation/platform/connectors/load-balancer/quickstart.md): Enable Load Balancer on the connector, add a second address, and spread requests across both.
- [Origin IP ACL and HMAC](/en/documentation/platform/connectors/origin-shield/origin-ip-acl-and-hmac.md): Enable Origin Shield on the connector to allow only Azion's addresses at your origin and sign requests with HMAC.
- [Ingestion and delivery](/en/documentation/platform/connectors/live-ingest/ingestion-and-delivery.md): How a connector of type live\_ingest takes a live stream in for delivery.
- [Connector settings](/en/documentation/platform/connectors/settings.md): Every field of a connector, with its type, default, allowed values, and the errors the API returns.
