Review App Service HTTP/2 settings

Evaluate HTTP/2 against client compatibility and transport requirements.

Description

HTTP/2 can improve web transport efficiency through features such as multiplexing. Disabling it does not imply missing encryption or authentication; HTTP/1.1 can also be protected with HTTPS. Check whether the service requires HTTP/2 and whether clients support it.

Potential impact

A service that needs HTTP/2 may not meet its expected transfer efficiency or protocol requirements when it is disabled.

Remediation

Set site_config.http2_enabled = true where needed and test actual client connections. Manage HTTPS-only settings, minimum TLS versions, and certificates separately. When using client certificates, check compatibility with modes or exclusion paths that require TLS renegotiation.

Examples

These excerpts use the legacy AzureRM 3.x azurerm_app_service resource. Current Linux and Windows Web App resources also support the HTTP/2 option.

Before

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  app_settings = {
    "SOME_KEY" = "some-value"
  }
}

After

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  app_settings = {
    "SOME_KEY" = "some-value"
  }

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
    min_tls_version          = 1.2
    http2_enabled            = true
  }
}

The revision enables HTTP/2 and specifies a TLS 1.2 minimum. Verify that clients negotiate HTTP/2; these settings alone do not block plaintext HTTP.

References