Skip to main content

Update Domain

An Update Domain is a logical grouping Azure uses within an Availability Set to ensure that planned maintenance (host OS updates, patching) is rolled out to VMs in batches rather than all at once, so at least one instance of a redundant application stays running during platform maintenance. Azure updates one Update Domain at a time, waiting a grace period between domains before proceeding to the next.

Update Domain

Update domains control the order Azure applies planned maintenance in. Only one update domain is rebooted at a time, so the rest of your Availability Set keeps serving traffic.

Why It Matters in Production

When Azure schedules host OS patching, CRED's API-gateway VMs (spread across 5 update domains) never all restart together — at most 20% of capacity is offline during any single maintenance window.

az vm availability-set show --name api-gateway-avset
--resource-group cred-prod-rg --query platformUpdateDomainCount

Common Mistake

Assuming update domains protect against unplanned hardware failure — that's the fault domain's job.

Frequently Asked Questions

How many Update Domains does Azure use by default, and can you control that?

An Availability Set has 5 Update Domains by default, configurable up to 20 at creation time. Azure assigns VMs to Update Domains round-robin as you add them, and during planned maintenance it patches one Update Domain at a time, waiting roughly 30 minutes between domains before moving to the next — giving your redundant instances in other domains time to absorb traffic while one batch reboots.

Why don't Update Domains alone guarantee zero-downtime maintenance?

Update Domains only protect against planned host maintenance being applied simultaneously — they say nothing about unplanned hardware failure, which is what Fault Domains address instead (a separate grouping in the same Availability Set). A common mistake is deploying only 2 VMs across 5 Update Domains and assuming full redundancy, when a Fault Domain outage could still take out both if they land on the same Fault Domain. For workloads needing both, use an Availability Set with adequate Fault Domain spread, or Availability Zones for datacenter-level resilience.