# Workloads quickstart

This guide instructs you through serving your application from your first [workload](/en/documentation/platform/workloads/).

- Create a workload on the production infrastructure.
- Bind the application you already have to the workload through its deployment.
- Send a request to the workload domain and get your application's response.

Four objects carry a request to your application, and each one links to the next:

1. The **workload** receives the traffic. Azion gives it a workload domain, a hostname of the form `<id>.map.azionedge.net`. The workload answers on it before you own or point any domain.
2. The **deployment** of the workload names the application that answers. A workload holds one deployment.
3. The **application** handles the request. It already exists, and the workload adds nothing to it.
4. The **request** to the workload domain reaches the workload, and the deployment sends it to your application.

A workload with no deployment has no application to send a request to. An application serves no traffic until a deployment binds it to a workload. This guide keeps the defaults of a new workload: the production infrastructure, the default TLS settings, ports `80` and `443`, and no domain of your own.

The workload this guide leaves you with is the starting point for two more quickstarts. With [Certificate Manager](/en/documentation/platform/workloads/#certificate-manager), you bind a certificate to the workload. With [Custom Pages](/en/documentation/platform/workloads/#custom-pages), you assign a custom page set in the workload's deployment to replace error responses. [DDoS Protection](/en/documentation/platform/workloads/#ddos-protection) needs no setup: the Platform mitigates DDoS attacks on every workload.

---

Select the interface you use. The prerequisites and every stage on this page follow that choice.

## Prerequisites

- An Azion account. To create one, refer to [Create an account](/en/documentation/fundamentals/creating-account/).
- An application that serves content. To create one, refer to [Applications quickstart](/en/documentation/platform/applications/quickstart/).

**Console**

- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/), installed and authorized.
- The ID of your application.

**API**

- A personal token and `curl`. To create a token, refer to [Personal tokens](/en/documentation/fundamentals/personal-tokens/).
- The ID of your application.

---

## Create the workload

A new workload runs on the production infrastructure and answers on its workload domain. The infrastructure is fixed once the workload exists. A workload created on staging cannot move to production later. The workload domain stays reachable while **Workload Domain Allow Access** is on, which is the default.

**Console**

In Azion Console, one form creates the workload and its deployment together. The **Application** field of **Deployment Settings** names your application before you select **Create**.

To create the workload in Azion Console:

1. **Open the Workloads page**

   Access [Azion Console](https://console.azion.com/) > **Workloads**.

2. **Start a new workload**

   Select **Create Workload**. The **Create Workload** page opens.

3. **Name the workload**

   Enter a name for the workload, such as `my-workload`.

4. **Select the production infrastructure**

   In **Infrastructure**, select *Production Infrastructure (All Edge Locations)*.

5. **Keep the workload domain open**

   In **Domains**, keep **Workload Domain Allow Access** turned on.

6. **Select your application**

   In **Deployment Settings**, select your application in **Application**. Leave **Firewall** and **Custom Page** empty.

7. **Select Create**

Azion Console shows the message "Your Workload has been created. After propagation the domain will be available in the Workload URL. You also can add a custom domain." To copy the workload domain that you send the request to, select **Copy Workload URL**. The workload exists, and its deployment names your application.

**CLI**

To create the workload with the Azion CLI:

```bash
azion create workload --name my-workload
```

The command prints the ID of the new workload:

```text
Created Workload with ID <workload-id>
```

Read the workload back in JSON. Replace `<workload-id>` with the ID from the previous command:

```bash
azion describe workload --workload-id <workload-id> --format json
```

The output shows the defaults of a new workload and the workload domain Azion assigned to it:

```json
{
 "active": true,
 "created_at": "2026-01-01T12:00:00.000000Z",
 "domains": [],
 "id": <workload-id>,
 "infrastructure": 1,
 "last_editor": "<your-email>",
 "last_modified": "2026-01-01T12:00:00.000000Z",
 "mtls": {
  "config": {
   "certificate": null,
   "verification": null
  },
  "enabled": false
 },
 "name": "my-workload",
 "product_version": "1.0",
 "protocols": {
  "http": {
   "http_ports": [
    80
   ],
   "https_ports": [
    443
   ],
   "quic_ports": [
    443
   ],
   "versions": [
    "http1",
    "http2",
    "http3"
   ]
  }
 },
 "tls": {
  "certificate": null,
  "ciphers": 7,
  "minimum_version": "tls_1_3"
 },
 "workload_domain": "<id>.map.azionedge.net",
 "workload_domain_allow_access": true
}
```

`infrastructure` set to `1` is the production infrastructure, and `domains` is empty. Record the `id` for the deployment and the `workload_domain` for the request. The workload exists, and it has no deployment yet.

**API**

To create the workload with the API, send a `POST` request to the workloads endpoint. `infrastructure` set to `1` selects the production infrastructure, and `workload_domain_allow_access` set to `true` keeps the workload domain open. Replace `[TOKEN VALUE]` with your personal token:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/workloads \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "my-workload",
  "active": true,
  "infrastructure": 1,
  "workload_domain_allow_access": true
}'
```

The API answers with `202`. The response carries the defaults of the new workload and the workload domain Azion assigned to it:

```json
{
  "state": "pending",
  "data": {
    "id": <workload-id>,
    "name": "my-workload",
    "active": true,
    "last_editor": "<your-email>",
    "last_modified": "2026-01-01T12:00:00.000000Z",
    "created_at": "2026-01-01T12:00:00.000000Z",
    "infrastructure": 1,
    "tls": {
      "certificate": null,
      "ciphers": 7,
      "minimum_version": "tls_1_3"
    },
    "protocols": {
      "http": {
        "versions": ["http1", "http2", "http3"],
        "http_ports": [80],
        "https_ports": [443],
        "quic_ports": [443]
      }
    },
    "mtls": {
      "enabled": false,
      "config": {
        "certificate": null,
        "crl": null,
        "verification": null
      }
    },
    "domains": [],
    "workload_domain_allow_access": true,
    "workload_domain": "<id>.map.azionedge.net",
    "product_version": "1.0"
  }
}
```

Record the `id` for the deployment and the `workload_domain` for the request. The workload exists, and it has no deployment yet.

---

## Bind your application

The deployment of a workload names the application that answers its requests, and optionally a firewall and a custom page set. A workload holds one deployment, and a second one is refused. Until the deployment names your application, the workload has nothing to send a request to.

**Console**

The **Create Workload** form already created the deployment. To check the binding in Azion Console:

1. **Open the Workloads page**

   Access [Azion Console](https://console.azion.com/) > **Workloads**.

2. **Open your workload**

   Select the workload you created. The **Edit Workload** page opens.

3. **Check the application**

   In **Deployment Settings**, check that **Application** shows your application.

The deployment of the workload names your application.

**CLI**

To bind the application with the Azion CLI, create the deployment of the workload. Replace `<workload-id>` and `<application-id>`:

```bash
azion create workload-deployment --workload-id <workload-id> \
  --name my-deployment --application-id <application-id> \
  --strategy-type default --active true --current true
```

The command prints the ID of the new deployment:

```text
Created Workload Deployment with ID <deployment-id>
```

`--current true` makes it the deployment the workload runs. List the deployment with its bindings:

```bash
azion list workload-deployment --workload-id <workload-id> --details
```

The output shows your application, and `0` for no firewall:

```text
ID               CURRENT  EDGE APPLICATION  EDGE FIREWALL
<deployment-id>  true     <application-id>  0
```

The current deployment of the workload names your application. The Azion CLI cannot change a deployment after it exists. Check the application ID before you run the command.

**API**

To bind the application with the API, send a `POST` request to the deployments of your workload. The application goes in `strategy.attributes.application`. Replace `<workload-id>` and `<application-id>`:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/workloads/<workload-id>/deployments \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "my-deployment",
  "current": true,
  "active": true,
  "strategy": {
    "type": "default",
    "attributes": {
      "application": <application-id>
    }
  }
}'
```

The API answers with `202` and `"state": "pending"`, and the response returns the new deployment. `current` set to `true` makes it the deployment the workload runs. The current deployment of the workload names your application.

---

## Send a request to the workload domain

The check is the same whichever interface created the workload. In the commands, replace `<your-workload-domain>` with the workload domain of the workload you created, of the form `<id>.map.azionedge.net`.

A new workload does not answer at once. Its deployment spreads across Azion's distributed infrastructure, and that takes several minutes, with no guaranteed duration. Until then, the workload domain answers `404` with Azion's HTML error page. While the deployment spreads, answers to the same request can alternate between that `404` and your application's response. Repeat the request until your application answers. For more information, refer to [Propagation](/en/documentation/platform/workloads/how-it-works/#propagation).

Before the deployment propagates, a header-only request gets Azion's error page:

```bash
curl -sI https://<your-workload-domain>/get
```

```text
HTTP/2 404
server: nginx
content-type: text/html
x-azion-request-id: <request-id>
x-azion-edge-location: <edge-location>
```

The `x-azion-request-id` header identifies the request. Once the deployment answers, send a request to the root path of your workload domain:

```bash
curl -i https://<your-workload-domain>/
```

The response is the one your application returns for `/`: its status, its headers, and its body. Your workload serves your application on its workload domain.

---

## Next steps

- [Certificate Manager quickstart](/en/documentation/platform/workloads/certificate-manager/quickstart.md): Upload your first certificate, bind it to your workload, and see its status turn active.
- [Custom Pages quickstart](/en/documentation/platform/workloads/custom-pages/quickstart.md): Create a custom page set, assign it in your workload's deployment, and see a 404 replaced in place.
- [Add a custom domain to a workload](/en/documentation/guides/platform/migration/configure-a-domain.md): List a domain you own on the workload and point it at the workload domain.
- [Workload settings](/en/documentation/platform/workloads/settings.md): Every field of a workload and its deployment, with its type, default, and allowed values.
