Workloads limits
Check the bounds of a workload, its domains, ports, and deployment, and of the certificates, custom pages, and DDoS Protection it uses, by plan.
A workload receives traffic for a set of domains and binds the application, the firewall, and the custom page set that serve it. This page states the bounds Azion applies to a workload and to the certificates, custom pages, and DDoS Protection it uses. Each row carries the bound and the answer a call receives past it.
The page carries two kinds of value. A default limit is checked on every call, and the call fails past it. An included amount is what a service plan includes before a rate applies: it is a billing quantity, and passing it changes what the account is charged rather than what the call returns. Azion pricing compares the plans side by side. For the rates, refer to Pricing.
Workloads
A workload holds its domains, its infrastructure, its HTTP versions and ports, its TLS settings, and one deployment. The bounds in this section apply to every workload, on every service plan, unless a table names a plan.
Default limits
The API refuses a call past each bound in this table with the message in the Past the limit column. The Azion CLI prints that message inside Error: Failed to update the Workload: [...], Error: Failed to create the Workload: [...], or Error: Failed to create the Workload Deployment: [...], followed by Check your settings and try again. If the error persists, contact Azion support.
| Scope | Limit | Past the limit |
|---|---|---|
Workload name | Up to 100 characters | Ensure this field has no more than 100 characters. |
| Deployments per workload | 1 | The maximum number of deployments allowed per workload is 1. |
azion.app domains per workload | 1, whether two entries repeat one name or carry two names | Duplicated usage of suffix in alternate_domains: 'azion.app'. |
An azion.app domain another workload holds | Not available to a second workload | The custom hostname is not available. |
Format of a domains entry | A full hostname that conforms to RFC 1035; a wildcard such as *.azion.app is refused | The domain does not conform to the format defined in RFC 1035. |
| HTTP ports | 80, 8008, 8080, and 8880 only | Invalid choices for multiple choices field: [80, 8008, 8080, 8880]. |
HTTP versions with http3 | versions also holds http1 and http2 | Missing required choices for multiple choices field: ['http1', 'http2']. |
Cipher suite, tls.ciphers | 1 to 8 | "9" is not a valid choice. The message quotes the value sent. |
| Infrastructure | Fixed at creation | The infrastructure cannot be changed after Workload creation. |
| Custom domains on a staging workload | None; a staging workload answers on its workload domain only | Custom hostname is not available in the environment 'Staging Infrastructure'. |
An azion.app domain belongs to one workload in one account and cannot be shared between accounts or configurations. For example, to move an azion.app domain to a new workload, remove it from the workload that holds it first.
Four further bounds apply: a workload covers up to 50 domains, http_ports holds 1 to 4 entries, https_ports holds 1 to 12 entries, and quic_ports holds up to 12 entries. For the 12 HTTPS ports a workload accepts, refer to Workload settings.
The port bounds apply to the ports a workload listens on. An application can fetch content from an origin on any port, as long as that port exists on the origin. For the delivery and origin port combinations, refer to Configure HTTP and HTTPS ports.
The number of workloads and of certificates an account holds is bounded by support plan. The support plans are Developer, Business, Enterprise, and Mission-Critical, and they are a separate dimension from the Hobby, Pro, and Enterprise service plans in Included usage per plan.
| Scope | Developer | Business | Enterprise | Mission-Critical |
|---|---|---|---|---|
| Workloads per account | 100 | 100 | 100 | 1,000 |
| Certificates per account | 100 | 100 | 100 | 1,000 |
Azion raises these bounds and the 50 domains per workload on request, based on your plan. To request an increase, contact the technical support team.
Included usage per plan
Azion offers three service plans: Hobby, Pro, and Enterprise. Workloads is billed on three metrics, Workloads, Data Transfer, and Requests, and each plan includes an amount of each before a rate applies.
| Metric | Hobby | Pro | Enterprise |
|---|---|---|---|
| Workloads | 10 | 20 | Custom |
| Data Transfer | 1 TB per month | 2 TB per month | Custom |
| Requests | 10M per month | 20M per month | Custom |
These amounts are billing quantities, not bounds on a call. Enterprise carries a custom amount on all three metrics. For the rate that applies past an included amount, refer to Pricing.
Certificate Manager
Certificate Manager stores the server certificates a workload presents, the Trusted CA certificates and certificate revocation lists (CRLs) that mTLS checks client certificates against, and the Let’s Encrypt certificates Azion requests for you. The number of certificates an account holds is bounded by support plan, in Default limits under Workloads. Certificate Manager has no included amount per plan.
Default limits
The Azion API applies these bounds to a certificate, a private key, and a CRL:
- A certificate, server or Trusted CA, takes up to 1,000,000 characters.
- A private key takes up to 64,000 characters.
- A CRL takes up to 30,720,000 characters.
- A workload attaches up to 100 CRLs, in
mtls.config.crl. - A Let’s Encrypt certificate covers up to 50 of the workload’s domains.
The names a Let’s Encrypt certificate covers come from the workload’s domains.
Azion support for Let’s Encrypt certificates depends on the availability and the limits of the Let’s Encrypt service. For those limits, refer to the Let’s Encrypt rate limits.
Custom Pages
A custom page set replaces the response for an HTTP status code with a page you choose, and it takes effect when a workload’s deployment names it. The bounds in this section apply to the set and to each page in it.
Default limits
A custom page set holds at least one page. The API and Azion Console refuse an empty set with the message in the Past the limit column.
| Scope | Limit | Past the limit |
|---|---|---|
| Pages per custom page set | At least 1 | The API returns Ensure this field has at least 1 elements. Azion Console shows You must have at least one custom page code. |
Four further bounds apply: a set name takes 1 to 255 characters, a page ttl takes 0 to 31,536,000 seconds, a page uri takes 1 to 250 characters, and a page custom_status_code takes 100 to 599. For the fields these bounds apply to, refer to Custom page settings.
DDoS Protection
DDoS Protection is a Platform feature that is always on: the Platform mitigates Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks on every workload, and there is nothing to create. Mitigation is not billed, so no included amount applies to it.
Default limits
DDoS Protection is unmetered, which means Azion does not measure the traffic that mitigation handles.
| Scope | Limit | Past the limit |
|---|---|---|
| Bandwidth of mitigated traffic | Unmetered | Azion does not measure it, and mitigation does not appear on billing. |
For how traffic is accounted on billing, refer to Pricing.
The Security Response Team (SRT) can be contacted during or after an attack, or before one to build custom rules. The SRT is contracted in addition to an Enterprise or Mission-Critical support plan.