Service Azure qui fournit une plateforme de conteneur serverless à usage général.
Hi @Ahmed KOUHLANI ,
Since your question was posted in English, I am providing the response in English to ensure clarity and consistency.
Based on the information provided, the Azure Front Door Premium configuration appears to be correctly provisioned, as the Front Door endpoint, route, origin group, and origin are all in an enabled/provisioned state. However, the current details are not sufficient to identify a confirmed root cause. The issue is most likely related to one of the following areas:
- The Azure Front Door Private Endpoint connection is no longer in an active and approved state.
- Health probes are failing, causing the origin to be marked unhealthy and preventing traffic from being routed.
- The Azure Container App is unavailable, unhealthy, or not returning a successful response on the configured probe path.
- A TLS/host header configuration issue is preventing Azure Front Door from successfully connecting to the origin. [Secure you...soft Learn | Learn.Microsoft.com], [Use Azure...soft Learn | Learn.Microsoft.com], [docs.azure.cn]
To further isolate the issue, please verify:
- The Private Endpoint connection status from the Azure Container Apps environment and confirm it is Approved and Connected. [Use Azure...soft Learn | Learn.Microsoft.com], [Secure you...soft Learn | Learn.Microsoft.com]
- The Origin Health status in Azure Front Door and whether health probes are succeeding. Azure Front Door considers an origin healthy only when it receives a successful response from the configured probe endpoint. [docs.azure.cn]
- The Container App revision health and application logs to confirm the application is running and responding successfully. [Unable to...rosoft Q&A | Learn.Microsoft.com]
- The origin hostname, host header, and backend certificate configuration to ensure HTTPS connectivity can be established successfully. [Failing to...rosoft Q&A | Learn.Microsoft.com]
Best Practices for Azure Front Door Premium with Azure Container Apps over Private Link:
- Use a dedicated health probe endpoint (for example,
/health) that always returns HTTP 200. [docs.azure.cn] - Regularly monitor Origin Health status in Azure Front Door. [docs.azure.cn]
- Ensure all Azure Front Door Private Endpoint connection requests are approved from the Container Apps environment. [Use Azure...soft Learn | Learn.Microsoft.com], [Secure you...soft Learn | Learn.Microsoft.com]
- Configure multiple Private Link-enabled origins where redundancy is required. [Secure you...soft Learn | Learn.Microsoft.com]
- Ensure all Azure Container Apps prerequisites for Front Door Private Link integration are met, including the use of a supported workload profile environment and proper ingress configuration. [Access an...soft Learn | Learn.Microsoft.com]
To determine the exact root cause, please share the Front Door endpoint error (404/502/503/timeout), current Origin Health status, and the Private Endpoint connection status from the Azure Container Apps environment.Based on the information provided, the Azure Front Door Premium configuration appears to be correctly provisioned, as the Front Door endpoint, route, origin group, and origin are all in an enabled/provisioned state. However, the current details are not sufficient to identify a confirmed root cause. The issue is most likely related to one of the following areas:
- The Azure Front Door Private Endpoint connection is no longer in an active and approved state.
- Health probes are failing, causing the origin to be marked unhealthy and preventing traffic from being routed.
- The Azure Container App is unavailable, unhealthy, or not returning a successful response on the configured probe path.
- A TLS/host header configuration issue is preventing Azure Front Door from successfully connecting to the origin. [Secure you...soft Learn | Learn.Microsoft.com], [Use Azure...soft Learn | Learn.Microsoft.com], [docs.azure.cn]
To further isolate the issue, please verify:
- The Private Endpoint connection status from the Azure Container Apps environment and confirm it is Approved and Connected. [Use Azure...soft Learn | Learn.Microsoft.com], [Secure you...soft Learn | Learn.Microsoft.com]
- The Origin Health status in Azure Front Door and whether health probes are succeeding. Azure Front Door considers an origin healthy only when it receives a successful response from the configured probe endpoint. [docs.azure.cn]
- The Container App revision health and application logs to confirm the application is running and responding successfully. [Unable to...rosoft Q&A | Learn.Microsoft.com]
- The origin hostname, host header, and backend certificate configuration to ensure HTTPS connectivity can be established successfully. [Failing to...rosoft Q&A | Learn.Microsoft.com]
Best Practices for Azure Front Door Premium with Azure Container Apps over Private Link:
- Use a dedicated health probe endpoint (for example,
/health) that always returns HTTP 200. [docs.azure.cn] - Regularly monitor Origin Health status in Azure Front Door. [docs.azure.cn]
- Ensure all Azure Front Door Private Endpoint connection requests are approved from the Container Apps environment. [Use Azure...soft Learn | Learn.Microsoft.com], [Secure you...soft Learn | Learn.Microsoft.com]
- Configure multiple Private Link-enabled origins where redundancy is required. [Secure you...soft Learn | Learn.Microsoft.com]
- Ensure all Azure Container Apps prerequisites for Front Door Private Link integration are met, including the use of a supported workload profile environment and proper ingress configuration. [Access an...soft Learn | Learn.Microsoft.com]
To determine the exact root cause, please share the Front Door endpoint error (404/502/503/timeout), current Origin Health status, and the Private Endpoint connection status from the Azure Container Apps environment.
Please "upvote" if the information helped you. This will help us and others in the community as well.