Description
HTTP/2 can improve web transport efficiency through features such as multiplexing. Disabling it does not imply missing encryption or authentication; HTTP/1.1 can also be protected with HTTPS. Check whether the service requires HTTP/2 and whether clients support it.
Potential impact
A service that needs HTTP/2 may not meet its expected transfer efficiency or protocol requirements when it is disabled.
Remediation
Set site_config.http2_enabled = true where needed and test actual client connections. Manage HTTPS-only settings, minimum TLS versions, and certificates separately. When using client certificates, check compatibility with modes or exclusion paths that require TLS renegotiation.
Examples
These excerpts use the legacy AzureRM 3.x azurerm_app_service resource. Current Linux and Windows Web App resources also support the HTTP/2 option.
Before
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
app_settings = {
"SOME_KEY" = "some-value"
}
}
After
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
app_settings = {
"SOME_KEY" = "some-value"
}
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
min_tls_version = 1.2
http2_enabled = true
}
}
The revision enables HTTP/2 and specifies a TLS 1.2 minimum. Verify that clients negotiate HTTP/2; these settings alone do not block plaintext HTTP.