Review Function App HTTP/2 settings

Review the need for HTTP/2 and client compatibility, and check HTTPS protection separately.

Description

HTTP/2 provides features such as multiplexing that improve web request efficiency. Disabling HTTP/2 does not establish that traffic is unencrypted: HTTP/1.1 can also use HTTPS. Choose the transport protocol according to service requirements and client support.

Potential impact

  • The application may not benefit from HTTP/2 transport efficiencies.
  • Protocol settings can differ from organizational operating standards.
  • Changing settings without compatibility checks can affect some clients.

Remediation

Where HTTP/2 is needed, set site_config.http2_enabled = true and verify client support and actual protocol negotiation. Configure HTTPS, the minimum TLS version and authentication separately. If client certificates are used, also check compatibility with settings that require TLS renegotiation.

Examples

These are excerpts of a legacy AzureRM 3.x Function App; required storage configuration is omitted. The runtime settings shown do not recommend a version for current deployment.

Before

hcl
resource "azurerm_function_app" "example" {
  name                = "test-azure-functions"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id
}

After

hcl
resource "azurerm_function_app" "example" {
  name                = "test-azure-functions"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
    http2_enabled            = true
  }
}

The before example does not enable HTTP/2. The after example sets http2_enabled = true. Actual HTTP/2 use depends on negotiation with the client, and this setting alone does not enforce HTTPS.

References