Front Door Premium failure

Ahmed KOUHLANI 0 Points de réputation
2026-07-29T14:29:46.0766667+00:00

We are experiencing an issue with Azure Front Door Premium.

Configuration:

  • Azure Front Door Premium
  • One endpoint:xxxxxxxxxxxxxxxa02.azurefd.net
  • One route: default-route (/*)
  • One origin group: default-origin-group
  • Origin: xxxxxxxxxxxxxxxxxxx.northeurope.azurecontainerapps.io
  • Origin connected through Private Link
  • Health probes enabled (HTTPS, GET /)
  • Route status: Enabled
  • Origin group status: Provisioned successfully
  • Front Door endpoint status: Enabled

Issue:

The Front Door public endpoint is no longer accessible

Could someone please help us understand the root cause of this issue?

We would also like to know whether there are any specific requirements, prerequisites, or best practices that should be taken into consideration when configuring Azure Front Door with Azure Container Apps over Private Link, in order to avoid such connectivity problems in the future.

Azure Container Apps
Azure Container Apps

Service Azure qui fournit une plateforme de conteneur serverless à usage général.

0 commentaires Aucun commentaire

1 réponse

  1. Gursimran Singh 570 Points de réputation Personnel externe Microsoft Modérateur
    2026-07-29T15:47:18.0266667+00:00

    Hi @Ahmed KOUHLANI ,

    Since your question was posted in English, I am providing the response in English to ensure clarity and consistency.

    Based on the information provided, the Azure Front Door Premium configuration appears to be correctly provisioned, as the Front Door endpoint, route, origin group, and origin are all in an enabled/provisioned state. However, the current details are not sufficient to identify a confirmed root cause. The issue is most likely related to one of the following areas:

    • The Azure Front Door Private Endpoint connection is no longer in an active and approved state.
    • Health probes are failing, causing the origin to be marked unhealthy and preventing traffic from being routed.
    • The Azure Container App is unavailable, unhealthy, or not returning a successful response on the configured probe path.
    • A TLS/host header configuration issue is preventing Azure Front Door from successfully connecting to the origin. [Secure you...soft Learn | Learn.Microsoft.com], [Use Azure...soft Learn | Learn.Microsoft.com], [docs.azure.cn]

    To further isolate the issue, please verify:

    1. The Private Endpoint connection status from the Azure Container Apps environment and confirm it is Approved and Connected. [Use Azure...soft Learn | Learn.Microsoft.com], [Secure you...soft Learn | Learn.Microsoft.com]
    2. The Origin Health status in Azure Front Door and whether health probes are succeeding. Azure Front Door considers an origin healthy only when it receives a successful response from the configured probe endpoint. [docs.azure.cn]
    3. The Container App revision health and application logs to confirm the application is running and responding successfully. [Unable to...rosoft Q&A | Learn.Microsoft.com]
    4. The origin hostname, host header, and backend certificate configuration to ensure HTTPS connectivity can be established successfully. [Failing to...rosoft Q&A | Learn.Microsoft.com]

    Best Practices for Azure Front Door Premium with Azure Container Apps over Private Link:

    To determine the exact root cause, please share the Front Door endpoint error (404/502/503/timeout), current Origin Health status, and the Private Endpoint connection status from the Azure Container Apps environment.Based on the information provided, the Azure Front Door Premium configuration appears to be correctly provisioned, as the Front Door endpoint, route, origin group, and origin are all in an enabled/provisioned state. However, the current details are not sufficient to identify a confirmed root cause. The issue is most likely related to one of the following areas:

    • The Azure Front Door Private Endpoint connection is no longer in an active and approved state.
    • Health probes are failing, causing the origin to be marked unhealthy and preventing traffic from being routed.
    • The Azure Container App is unavailable, unhealthy, or not returning a successful response on the configured probe path.
    • A TLS/host header configuration issue is preventing Azure Front Door from successfully connecting to the origin. [Secure you...soft Learn | Learn.Microsoft.com], [Use Azure...soft Learn | Learn.Microsoft.com], [docs.azure.cn]

    To further isolate the issue, please verify:

    1. The Private Endpoint connection status from the Azure Container Apps environment and confirm it is Approved and Connected. [Use Azure...soft Learn | Learn.Microsoft.com], [Secure you...soft Learn | Learn.Microsoft.com]
    2. The Origin Health status in Azure Front Door and whether health probes are succeeding. Azure Front Door considers an origin healthy only when it receives a successful response from the configured probe endpoint. [docs.azure.cn]
    3. The Container App revision health and application logs to confirm the application is running and responding successfully. [Unable to...rosoft Q&A | Learn.Microsoft.com]
    4. The origin hostname, host header, and backend certificate configuration to ensure HTTPS connectivity can be established successfully. [Failing to...rosoft Q&A | Learn.Microsoft.com]

    Best Practices for Azure Front Door Premium with Azure Container Apps over Private Link:

    To determine the exact root cause, please share the Front Door endpoint error (404/502/503/timeout), current Origin Health status, and the Private Endpoint connection status from the Azure Container Apps environment.

    Please "upvote" if the information helped you. This will help us and others in the community as well.

    Cette réponse a-t-elle été utile ?

    0 commentaires Aucun commentaire

Votre réponse

Les réponses peuvent être marquées comme « Acceptées » par l’auteur de la question et « Recommandées » par les modérateurs, ce qui aide les utilisateurs à savoir que la réponse a résolu le problème de l’auteur.