Azure Front Door
A global, edge-based entry point that provides Layer 7 load balancing, SSL offloading, and CDN caching across multiple Azure regions, routing users to the closest healthy backend for low-latency global applications.
Azure Front Door
Front Door operates at Microsoft's global edge network, routing users to the nearest healthy regional backend and failing over automatically if a region goes down.
Why It Matters in Production
Hotstar fronts its global CDN endpoints with Azure Front Door so international users during a cricket match are routed to the nearest edge location, with automatic failover if the primary region's backend becomes unhealthy.
az afd endpoint create --resource-group hotstar-prod-rg \ --profile-name hotstar-frontdoor --endpoint-name hotstar-globalRememberFront Door is for global, multi-region HTTP(S) traffic — use Traffic Manager for simpler DNS-based routing without Front Door's caching and WAF features.
Frequently Asked Questions
How is Azure Front Door different from Application Gateway?
Application Gateway operates within a single region, load balancing across backends inside that region. Front Door operates at Azure's global edge network, routing users to the nearest healthy backend across multiple regions worldwide, combined with CDN caching for static content. Use Application Gateway for regional Layer 7 routing and WAF; use Front Door when you need global routing, multi-region failover, and edge caching together.
What's a common mistake when setting up Azure Front Door?
Misconfiguring health probes so Front Door doesn't correctly detect when a regional backend goes unhealthy, meaning traffic keeps routing to a failed region instead of failing over automatically. Also, caching rules need care — caching dynamic, user-specific content at the edge by mistake can serve one user's personalized response to another, so cache rules must explicitly exclude non-cacheable paths.