설명
HTTP/2는 요청 다중화 등으로 웹 전송 효율을 높일 수 있습니다. 비활성화 자체가 암호화나 인증의 부재를 뜻하지는 않으며, HTTP/1.1도 HTTPS로 보호할 수 있습니다. 서비스에서 HTTP/2를 요구하는지와 클라이언트 호환성을 함께 확인하세요.
잠재적 영향
HTTP/2가 필요한 서비스에서 비활성화하면 기대한 전송 효율이나 프로토콜 요구를 충족하지 못할 수 있습니다.
해결 방법
필요한 앱에 site_config.http2_enabled = true를 설정하고 실제 클라이언트 연결을 시험하세요. HTTPS 전용 설정, 최소 TLS 버전과 인증서는 별도로 관리하세요. 클라이언트 인증서를 쓴다면 TLS 재협상을 요구하는 모드나 예외 경로와의 호환성도 확인하세요.
예시
AzureRM 3.x의 기존 azurerm_app_service 발췌입니다. 현재 Linux·Windows Web App에도 HTTP/2 옵션이 제공됩니다.
변경 전
hcl
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
app_settings = {
"SOME_KEY" = "some-value"
}
}
변경 후
hcl
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
app_settings = {
"SOME_KEY" = "some-value"
}
site_config {
dotnet_framework_version = "v4.0"
scm_type = "LocalGit"
min_tls_version = 1.2
http2_enabled = true
}
}
변경 후에는 HTTP/2를 켜고 최소 TLS 1.2를 지정합니다. 클라이언트가 HTTP/2를 협상하는지 확인해야 하며, 이 설정만으로 평문 HTTP가 차단되지는 않습니다.