# Glossary

The terms in this glossary carry a meaning of their own in [Workloads](/en/documentation/platform/workloads/) and in what works on a workload: [Certificate Manager](/en/documentation/platform/workloads/#certificate-manager), [Custom Pages](/en/documentation/platform/workloads/#custom-pages), and [DDoS Protection](/en/documentation/platform/workloads/#ddos-protection).

| Term                              | Definition                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| apex domain                       | The name other platforms give to a domain with no subdomain label, such as `example.com`, also called a root domain. Pointing your own domain at a workload takes a CNAME record, and an ANAME record for the root domain needs its nameservers migrated to Azion. For the steps, refer to [How to access addresses through a root domain (ANAME)](/en/documentation/guides/application-security/dns/access-root-domain/).                                                                                                                                                                                                                                                      |
| Azion custom domain               | The free `azion.app` hostname a workload can answer on, set with the **Custom Domain** switch and the **Azion Custom Domain** field in Azion Console. The field takes a name such as `my-custom-name`, appends `.azion.app`, and stores the full hostname in `domains`, where a workload holds at most one, a name another workload holds is refused, and a staging workload takes none. It is not the workload domain, and [Workload settings](/en/documentation/platform/workloads/settings/#domains) lists every rule it follows.                                                                                                                                            |
| Azion SAN certificate             | Azion's own TLS certificate, which lists the hostnames it covers as Subject Alternative Names (SAN). A workload with `tls.certificate` set to `null` presents it, and it covers the workload domain and the Azion custom domain at no additional cost. To present a certificate for your own domain instead, refer to [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates/).                                                                                                                                                                                                                                                                   |
| Certificate Manager               | The library of certificates and certificate revocation lists that workloads use, served in the API under `/v4/workspace/tls/` and listed in Azion Console on the **Certificate Manager** page. It holds server certificates you upload, Let's Encrypt certificates Azion requests and renews, Trusted CA certificates, and CSRs. [Certificate Manager](/en/documentation/platform/workloads/#certificate-manager) describes what it does for a workload, and the [Certificate Manager quickstart](/en/documentation/platform/workloads/certificate-manager/quickstart/) binds a first certificate.                                                                              |
| certificate revocation list (CRL) | A list of client certificates revoked before their expiration date, signed by the certificate authority that issued them. You upload it to Certificate Manager and attach it to a workload in `mtls.config.crl`, at most 100 per workload, beside the Trusted CA certificate. [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates/) documents its fields.                                                                                                                                                                                                                                                                                      |
| certificate signing request (CSR) | A request for a certificate that you create in Certificate Manager and submit to a certificate authority (CA). The **Common Name** (`common_name`) names the domain the certificate covers, and once the certificate is signed, you paste the PEM-encoded certificate into the CSR. [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates/) lists every field.                                                                                                                                                                                                                                                                                   |
| cipher suite                      | One of eight named sets of [ciphers](https://www.azion.com/en/learning/) a workload offers for TLS, chosen by number in `tls.ciphers`, from `1` (`TLSv1.2_2018`) to `8` (`Legacy_v2017Q1`). The default is `7` (`Modern_v2025Q1`), and the client and the workload negotiate one cipher from the suite for each session. [Workload settings](/en/documentation/platform/workloads/settings/#cipher-suites) lists the ciphers of each suite.                                                                                                                                                                                                                                     |
| custom domain                     | A domain you own, such as `www.example.com`, that a production workload answers on in addition to its workload domain. You list it in `domains` and point it at the workload domain with a CNAME record at your DNS provider, as [Add a custom domain to a workload](/en/documentation/guides/platform/migration/configure-a-domain/) shows. Azion Console adds it with **Add Domain** in the **Domains** section, while its **Custom Domain** switch turns on the Azion custom domain instead.                                                                                                                                                                                 |
| custom page                       | One entry of a custom page set: the response Azion serves in place of a 4xx or 5xx status code it receives from a [connector](/en/documentation/platform/connectors/), selected by its page code. A `page_connector` page fetches the document at `uri` from a connector, caches it for `ttl` seconds, and answers with `custom_status_code`, so the client is served in place and not redirected. [Custom Pages](/en/documentation/platform/workloads/custom-pages/settings/) documents every field.                                                                                                                                                                           |
| custom page set                   | The object that groups custom pages under one name, at least one per set, served in the API at `/v4/workspace/custom_pages`. Azion Console calls it a custom page, on the **Create Custom Page** page. A workload uses a set only once its deployment names it in **Custom Page**, `strategy.attributes.custom_page`, as the [Custom Pages quickstart](/en/documentation/platform/workloads/custom-pages/quickstart/) shows.                                                                                                                                                                                                                                                    |
| Custom Pages                      | Custom Pages serves your own page in place of a 4xx or 5xx response that a connector returns, through custom page sets that a workload's deployment assigns. It replaces the [Error Responses](/en/documentation/platform/workloads/custom-pages/error-responses/) of a v3 application. [Custom Pages](/en/documentation/platform/workloads/#custom-pages) describes it.                                                                                                                                                                                                                                                                                                        |
| DDoS Protection                   | The Platform feature, always on, that mitigates [distributed denial-of-service (DDoS)](https://www.azion.com/en/learning/) attacks on every workload, with nothing to create. It is unmetered, so its mitigation does not appear on billing. [Attack mitigation](/en/documentation/platform/workloads/ddos-protection/ddos-mitigation/) describes how the Platform mitigates an attack.                                                                                                                                                                                                                                                                                         |
| deployment                        | The sub-object of a workload that names the [application](/en/documentation/platform/applications/), the [firewall](/en/documentation/platform/firewall/), and the custom page set serving its traffic, in the `strategy.attributes` keys `application`, `firewall`, and `custom_page`. A workload holds one deployment, at `/v4/workspace/workloads/{workload_id}/deployments` in the API, and Azion Console edits it in the **Deployment Settings** section of the workload. A second deployment is refused with `The maximum number of deployments allowed per workload is 1.`, as [Workload settings](/en/documentation/platform/workloads/settings/#deployment) documents. |
| digital certificate               | The Azion Console and Azion CLI name for any certificate in Certificate Manager, from the **Digital Certificate** field of a workload to the `azion create digital-certificate` command. Its `type` is `edge_certificate` for a server certificate or `trusted_ca_certificate` for a Trusted CA certificate, and a Let's Encrypt certificate is one Azion requests and renews. [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates/) compares the kinds.                                                                                                                                                                                       |
| Domains                           | The v3 object that held an application's domains, its Azion domain, and its certificate, replaced on API v4 by the workload and its deployment. [Domains](/en/documentation/platform/workloads/domains/) documents it for accounts that run API v3, and [API v4 Migration](/en/documentation/fundamentals/api-v4-migration/) maps one model onto the other.                                                                                                                                                                                                                                                                                                                     |
| edge certificate                  | The API and Azion CLI value `edge_certificate` of a certificate's `type`: a server certificate and private key you upload, which a workload names in `tls.certificate` to serve HTTPS. Azion Console calls it a **Server Certificate**, and the API never returns its private key. Only this type is accepted in `tls.certificate`, so a Trusted CA certificate there returns `Invalid certificate type, MUST be an Edge Certificate.`                                                                                                                                                                                                                                          |
| edge hostname                     | The name other platforms give to the hostname that a domain's CNAME record points to. On Azion that hostname is the workload domain, `<id>.map.azionedge.net`, which Azion assigns each workload at creation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| enforce                           | The `mtls.config.verification` mode in which a workload refuses the TLS handshake of a client that presents no certificate, or one that its Trusted CA certificate did not sign. A client whose certificate the Trusted CA signed is served. [mTLS](/en/documentation/platform/workloads/mtls/) compares it with permissive.                                                                                                                                                                                                                                                                                                                                                    |
| hostname                          | A fully qualified domain name a client requests, such as `www.example.com`. A workload answers on its workload domain and on the hostnames in `domains`, where every entry must conform to RFC 1035, so a wildcard such as `*.example.com` is refused with `The domain does not conform to the format defined in RFC 1035.` [Workload settings](/en/documentation/platform/workloads/settings/#domains) lists the other rules.                                                                                                                                                                                                                                                  |
| infrastructure                    | The workload field that picks the network serving it: `1` for production infrastructure, the default, or `2` for staging infrastructure. It also sets the suffix of the workload domain, and it is fixed at creation: an update that changes it returns `The infrastructure cannot be changed after Workload creation.` [Workload settings](/en/documentation/platform/workloads/settings/#infrastructure) compares the two values.                                                                                                                                                                                                                                             |
| Let's Encrypt certificate         | A free TLS certificate signed by the Let's Encrypt certificate authority, which Azion requests and renews for you. Azion validates the domain with an HTTP-01 or DNS-01 challenge, and renewal starts 30 days before the 90-day validity ends. [Issuance and renewal](/en/documentation/platform/workloads/certificate-manager/issuance-and-renewal/) covers the challenges and the retry policy.                                                                                                                                                                                                                                                                               |
| minimum TLS version               | The lowest TLS version a workload accepts, set in `tls.minimum_version` to `tls_1_0`, `tls_1_1`, `tls_1_2`, or `tls_1_3`, the default. It is a floor, so a workload set to `tls_1_2` can still serve a session over TLS 1.3. [Workload settings](/en/documentation/platform/workloads/settings/#tls) documents the TLS fields.                                                                                                                                                                                                                                                                                                                                                  |
| mTLS                              | Mutual TLS, in which the client also presents a certificate and the workload checks it against a Trusted CA certificate. A workload turns it on in its `mtls` object, with a verification mode of enforce or permissive and optional certificate revocation lists. [mTLS](/en/documentation/platform/workloads/mtls/) documents both modes, and the [Learning Center](https://www.azion.com/en/learning/) covers the generic protocol.                                                                                                                                                                                                                                          |
| origin                            | The server a request's content comes from. A workload names no origin: its deployment names an application, and the application fetches content from the origin that a [connector](/en/documentation/platform/connectors/) sets.                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| page code                         | The HTTP status code a custom page answers for, `code` in the API and **Page Code** in Azion Console, such as `404`. Custom Pages covers codes in the 4xx and 5xx ranges only. [Custom Pages](/en/documentation/platform/workloads/custom-pages/settings/) lists the codes it accepts.                                                                                                                                                                                                                                                                                                                                                                                          |
| permissive                        | The `mtls.config.verification` mode in which a workload completes the TLS handshake with every client, with or without a certificate its Trusted CA certificate signed. The request reaches the application, so rules that read the result of the client certificate check decide whether to serve it. [mTLS](/en/documentation/platform/workloads/mtls/) compares it with enforce.                                                                                                                                                                                                                                                                                             |
| production infrastructure         | The value `1` of `infrastructure` and the default, the production option of the **Infrastructure** section in Azion Console: the Production Network, for global availability. A production workload gets a workload domain in the form `<id>.map.azionedge.net` and accepts custom domains. [Workload settings](/en/documentation/platform/workloads/settings/#infrastructure) compares it with staging infrastructure.                                                                                                                                                                                                                                                         |
| property                          | The name other platforms give to the configuration that serves a set of hostnames. On Azion that configuration has two parts: a workload holds the hostnames, the protocols, and TLS, and its deployment names the application, the firewall, and the custom page set that serve them. [How Workloads works](/en/documentation/platform/workloads/how-it-works/) follows a request through both.                                                                                                                                                                                                                                                                                |
| staging infrastructure            | The value `2` of `infrastructure`, *Staging Infrastructure* in Azion Console: the Staging Network, for testing with limited propagation. A staging workload gets a workload domain in the form `<id>.preview.azionedge.net`, takes no custom hostname, and leaves the production workload unaffected by its changes. [Workload settings](/en/documentation/platform/workloads/settings/#infrastructure) compares it with production infrastructure.                                                                                                                                                                                                                             |
| Trusted CA certificate            | The certificate of a certificate authority that you upload so a workload can verify client certificates in mTLS, `trusted_ca_certificate` in the API and **Trusted CA Certificate** in Azion Console, where intermediate certificates are accepted. A workload names it in `mtls.config.certificate`, and a server certificate there returns `Invalid certificate type, MUST be a Trusted CA.` To upload one, refer to [Configure and associate an mTLS certificate](/en/documentation/guides/application-security/tls-and-certificates/associate-an-mtls-certificate/).                                                                                                        |
| workload                          | The object that receives traffic for a set of domains on Azion's distributed infrastructure, holding the domains, the infrastructure, the HTTP versions and ports, TLS, and mTLS. Its deployment names the application, the firewall, and the custom page set that serve that traffic, and on API v4 it replaces the Domains object. [Workloads](/en/documentation/platform/workloads/) describes the resource, and the [Workloads quickstart](/en/documentation/platform/workloads/quickstart/) creates one.                                                                                                                                                                   |
| workload domain                   | The read-only hostname Azion assigns a workload at creation, `workload_domain`: `<id>.map.azionedge.net` on production and `<id>.preview.azionedge.net` on staging. Clients reach the workload on it while Workload Domain Allow Access is on, and your custom domains point at it with a CNAME record, as [Point a domain to a workload](/en/documentation/guides/platform/migration/point-domain-to-azion/) shows. It is not the Azion custom domain, which is an `azion.app` hostname you choose.                                                                                                                                                                            |
| Workload Domain Allow Access      | The workload switch, `workload_domain_allow_access` in the API, that lets clients reach the workload on its workload domain, on by default. With it off, the workload domain answers `404`, and `domains` must hold at least one hostname or the API returns `When the workload hostname access is blocked, the workload requires alternate domains or domains.` [Workload settings](/en/documentation/platform/workloads/settings/#domains) documents the field.                                                                                                                                                                                                               |
| zone                              | The name other platforms give to the DNS records of one domain and the nameservers that answer for them. On Azion a zone lives in [Edge DNS](/en/documentation/platform/edge-dns/), not in a workload: a workload holds no DNS records and answers the hostnames in `domains` wherever their zone is hosted.                                                                                                                                                                                                                                                                                                                                                                    |
