Optimizing Azure Application Gateway with the Well-Architected Framework
Azure Application Gateway is a web traffic load balancer that works on Layer 7 of the OSI model and enables you to manage traffic for your web applications. It can make routing decisions based on attributes of an HTTP request such as URI path or host headers. The service also offers great app development features like autoscaling, SSL termination, support for Web Application Firewall, and the ability to dynamically modify request and response headers and request URL.
The Microsoft Azure Well-Architected Framework provides a set of architecture best practices to help you build and deliver great solutions. The framework is divided into five pillars of architectural best practices: cost management, operational excellence, performance efficiency, reliability, and security. These pillars help you effectively and consistently optimize your workloads against Azure best practices and the specific business priorities that are relevant to you or your customers' cloud journey. In addition to the general architectural guidance organized per-pillar in the Well-Architected Framework documentation, we are now publishing service-centered guidance in the form of service review guides that enable you to systematically validate and optimize individual components in your solution. The service review guides are concise and comprehensive guides with actionable recommendations for each Well-Architected pillar, derived from real-life experience. They include a checklist of design topics to pay attention to for each pillar, as well as configuration recommendations and Azure Policies you should enable.
Azure Well-Architected Framework review for Application Gateway v2 gives you simple and direct advice to optimize Azure Application Gateway implementations. It includes service-centered design checklists for each framework pillar. And recommendations that go from practical advice of things to take into consideration to avoid common pitfalls, like avoid removing backend servers too fast after making routing changes to give the service enough time to drain existing connections, to a formula you can use during capacity planning to estimate the number of instances needed to support a given load.
Jose Varela
Principal Software Engineer, Azure Architecture Center
Jose is an experienced software developer and solution architect with over 30 years of industry experience. Jose spent 20 years in various roles in Consulting and Architect roles in the Microsoft Services organization in North America before joining the Architecture Center, building custom solutions and providing architecture advice to Microsoft’s enterprise customers.
Published on:
Learn moreRelated posts
Routing options for VMs from Private Subnets
Virtual Machines deployed in Azure used to have Default Outbound Internet Access. Until today, this allows virtual machines to connect to...
Secure, High-Performance Networking for Data-Intensive Kubernetes Workloads
The intersection of Generative AI and cloud computing has been transforming how organizations build and manage their infrastructure. The deman...
Network Connectivity for RISE with SAP S/4HANA Cloud Private Edition on Azure
In this article, we will explore different ways to connect to RISE with SAP S/4HANA Cloud Private Edition deployment on Azure, guiding yo...
Optimize Azure Landing Zone with Azure Virtual Network Manager IP Address Management
Optimize Azure Landing Zone with Azure Virtual Network Manager IP Address Management What you will learn from this blog This blog explores how...
ExpressRoute Metro is now generally available!!
We are excited to announce general availability of ExpressRoute Metro, a new private connectivity architecture designed to enhance network res...
ExpressRoute guided configuration of multi-site circuits and connections is generally available
ExpressRoute guided experience for configuring multi-site resiliency circuits and connections is generally available in Azure public cloud. Th...
Manage NSG association on Subnets via Azure Policy
In this blog article, we will cover how to deny the creation of a subnet in a Virtual Network if the subnet does not have a Network Sec...
Effortless Private Endpoint Management in Azure Landing Zones: A Streamlined and Compliant Approach
1. Challenge In Azure Landing Zones, the network infrastructure, including components like VNET Gateways and ExpressRoute circuits, is part of...
Unlocking Secure VM Connectivity with Azure Bastion
In today’s digital landscape, where security breaches are an unfortunate reality, safeguarding sensitive data and infrastructure has become mo...
Use cases of Advanced Network Observability for your Azure Kubernetes Service clusters
Introduction Advanced Network Observability is the inaugural feature of the Advanced Container Networking Services (ACNS) suite bringing...