# Workloads limits

A [workload](/en/documentation/platform/workloads/) receives traffic for a set of domains and binds the application, the firewall, and the custom page set that serve it. This page states the bounds Azion applies to a workload and to the certificates, custom pages, and DDoS Protection it uses. Each row carries the bound and the answer a call receives past it.

The page carries two kinds of value. A default limit is checked on every call, and the call fails past it. An included amount is what a service plan includes before a rate applies: it is a billing quantity, and passing it changes what the account is charged rather than what the call returns. [Azion pricing](https://www.azion.com/en/pricing/) compares the plans side by side. For the rates, refer to [Pricing](/en/documentation/fundamentals/pricing/#workloads).

---

## Workloads

A workload holds its domains, its infrastructure, its HTTP versions and ports, its TLS settings, and one deployment. The bounds in this section apply to every workload, on every service plan, unless a table names a plan.

### Default limits

The API refuses a call past each bound in this table with the message in the Past the limit column. The Azion CLI prints that message inside `Error: Failed to update the Workload: [...]`, `Error: Failed to create the Workload: [...]`, or `Error: Failed to create the Workload Deployment: [...]`, followed by `Check your settings and try again. If the error persists, contact Azion support.`

| Scope                                        | Limit                                                                                  | Past the limit                                                                  |
| -------------------------------------------- | -------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| Workload `name`                              | Up to 100 characters                                                                   | `Ensure this field has no more than 100 characters.`                            |
| Deployments per workload                     | 1                                                                                      | `The maximum number of deployments allowed per workload is 1.`                  |
| `azion.app` domains per workload             | 1, whether two entries repeat one name or carry two names                              | `Duplicated usage of suffix in alternate_domains: 'azion.app'.`                 |
| An `azion.app` domain another workload holds | Not available to a second workload                                                     | `The custom hostname is not available.`                                         |
| Format of a `domains` entry                  | A full hostname that conforms to RFC 1035; a wildcard such as `*.azion.app` is refused | `The domain does not conform to the format defined in RFC 1035.`                |
| HTTP ports                                   | `80`, `8008`, `8080`, and `8880` only                                                  | `Invalid choices for multiple choices field: [80, 8008, 8080, 8880].`           |
| HTTP versions with `http3`                   | `versions` also holds `http1` and `http2`                                              | `Missing required choices for multiple choices field: ['http1', 'http2'].`      |
| Cipher suite, `tls.ciphers`                  | `1` to `8`                                                                             | `"9" is not a valid choice.` The message quotes the value sent.                 |
| Infrastructure                               | Fixed at creation                                                                      | `The infrastructure cannot be changed after Workload creation.`                 |
| Custom domains on a staging workload         | None; a staging workload answers on its workload domain only                           | `Custom hostname is not available in the environment 'Staging Infrastructure'.` |

An `azion.app` domain belongs to one workload in one account and cannot be shared between accounts or configurations. For example, to move an `azion.app` domain to a new workload, remove it from the workload that holds it first.

Four further bounds apply: a workload covers up to 50 domains, `http_ports` holds 1 to 4 entries, `https_ports` holds 1 to 12 entries, and `quic_ports` holds up to 12 entries. For the 12 HTTPS ports a workload accepts, refer to [Workload settings](/en/documentation/platform/workloads/settings/#protocols-and-ports).

The port bounds apply to the ports a workload listens on. An application can fetch content from an origin on any port, as long as that port exists on the origin. For the delivery and origin port combinations, refer to [Configure HTTP and HTTPS ports](/en/documentation/guides/application-development/getting-started/configure-ports/).

The number of workloads and of certificates an account holds is bounded by support plan. The support plans are Developer, Business, Enterprise, and Mission-Critical, and they are a separate dimension from the Hobby, Pro, and Enterprise service plans in Included usage per plan.

| Scope                    | Developer | Business | Enterprise | Mission-Critical |
| ------------------------ | --------- | -------- | ---------- | ---------------- |
| Workloads per account    | 100       | 100      | 100        | 1,000            |
| Certificates per account | 100       | 100      | 100        | 1,000            |

Azion raises these bounds and the 50 domains per workload on request, based on your plan. To request an increase, contact the [technical support](/en/documentation/support/) team.

### Included usage per plan

Azion offers three service plans: Hobby, Pro, and Enterprise. Workloads is billed on three metrics, Workloads, Data Transfer, and Requests, and each plan includes an amount of each before a rate applies.

| Metric        | Hobby          | Pro            | Enterprise |
| ------------- | -------------- | -------------- | ---------- |
| Workloads     | 10             | 20             | Custom     |
| Data Transfer | 1 TB per month | 2 TB per month | Custom     |
| Requests      | 10M per month  | 20M per month  | Custom     |

These amounts are billing quantities, not bounds on a call. Enterprise carries a custom amount on all three metrics. For the rate that applies past an included amount, refer to [Pricing](/en/documentation/fundamentals/pricing/#workloads).

---

## Certificate Manager

[Certificate Manager](/en/documentation/platform/workloads/#certificate-manager) stores the server certificates a workload presents, the Trusted CA certificates and certificate revocation lists (CRLs) that mTLS checks client certificates against, and the Let's Encrypt certificates Azion requests for you. The number of certificates an account holds is bounded by support plan, in [Default limits](/en/documentation/platform/workloads/limits/#default-limits) under Workloads. Certificate Manager has no included amount per plan.

### Default limits

The Azion API applies these bounds to a certificate, a private key, and a CRL:

- A certificate, server or Trusted CA, takes up to 1,000,000 characters.
- A private key takes up to 64,000 characters.
- A CRL takes up to 30,720,000 characters.
- A workload attaches up to 100 CRLs, in `mtls.config.crl`.
- A Let's Encrypt certificate covers up to 50 of the workload's domains.

The names a Let's Encrypt certificate covers come from the workload's domains.

Azion support for Let's Encrypt certificates depends on the availability and the limits of the Let's Encrypt service. For those limits, refer to the [Let's Encrypt rate limits](https://letsencrypt.org/docs/rate-limits/).

---

## Custom Pages

A custom page set replaces the response for an HTTP status code with a page you choose, and it takes effect when a workload's deployment names it. The bounds in this section apply to the set and to each page in it.

### Default limits

A custom page set holds at least one page. The API and Azion Console refuse an empty set with the message in the Past the limit column.

| Scope                     | Limit      | Past the limit                                                                                                                  |
| ------------------------- | ---------- | ------------------------------------------------------------------------------------------------------------------------------- |
| Pages per custom page set | At least 1 | The API returns `Ensure this field has at least 1 elements.` Azion Console shows `You must have at least one custom page code`. |

Four further bounds apply: a set `name` takes 1 to 255 characters, a page `ttl` takes 0 to 31,536,000 seconds, a page `uri` takes 1 to 250 characters, and a page `custom_status_code` takes 100 to 599. For the fields these bounds apply to, refer to [Custom page settings](/en/documentation/platform/workloads/custom-pages/settings/).

---

## DDoS Protection

[DDoS Protection](/en/documentation/platform/workloads/#ddos-protection) is a Platform feature that is always on: the Platform mitigates Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks on every workload, and there is nothing to create. Mitigation is not billed, so no included amount applies to it.

### Default limits

DDoS Protection is unmetered, which means Azion does not measure the traffic that mitigation handles.

| Scope                          | Limit     | Past the limit                                                        |
| ------------------------------ | --------- | --------------------------------------------------------------------- |
| Bandwidth of mitigated traffic | Unmetered | Azion does not measure it, and mitigation does not appear on billing. |

For how traffic is accounted on billing, refer to [Pricing](/en/documentation/fundamentals/pricing/).

The Security Response Team (SRT) can be contacted during or after an attack, or before one to build custom rules. The SRT is contracted in addition to an Enterprise or Mission-Critical support plan.

---

## Related resources

- [Workload settings](/en/documentation/platform/workloads/settings.md): Every field of a workload and its deployment, with the type, the default, and the allowed values the bounds on this page apply to.
- [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates.md): The server and Trusted CA certificates and CRLs a workload uses, and how to upload or request one.
- [Custom page settings](/en/documentation/platform/workloads/custom-pages/settings.md): The fields of a custom page set and its pages, and the status codes a page can replace.
- [Pricing](/en/documentation/fundamentals/pricing.md#workloads): The rate that applies to workloads, data transfer, and requests past each included amount.
