Q: Your staging App Service slot works perfectly, but after swapping to production, the application connects to the staging database. What went wrong?
Root-cause post-mortem and configuration fix for connection string bleeding when performing blue/green deployment slot swaps in Azure App Service.
#Azure #App Service #Deployment Slots #Blue Green #FinOps
🎙️ Candidate Opening & Architectural Context
"This occurs because the database connection string was configured as a 'swappable' setting rather than a 'Deployment slot setting' (sticky setting). During a slot swap, Azure swaps app settings unless they are explicitly marked as sticky."
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1
Understand Azure App Service Swap Mechanics
When you execute a slot swap, Azure swaps the virtual IP addresses and routing rules. By default, application configuration settings also swap between slots unless 'Deployment slot setting' is checked.
2
Configure Sticky Settings for Environment-Specific Configs
Flag environment-specific settings (Database connection strings, Redis caches, Key Vault URIs) as 'slot-specific' (sticky) in Azure CLI or Terraform so they remain bound to their respective slots.
# Set sticky connection string via Azure CLI
az webapp config connection-string set \
--name app-production-eus \
--resource-group rg-production \
--connection-string-type SQLAzure \
--settings DatabaseConnectionString="Server=tcp:sql-prod..." \
--slot-settings DatabaseConnectionString
3
Terraform Sticky Configuration Enforcement
In Terraform, declare the connection strings inside sticky_settings blocks in azurerm_app_service to ensure IaC prevents drift.
resource "azurerm_app_service" "app" {
# ...
sticky_settings {
connection_string_names = ["DatabaseConnectionString"]
app_setting_names = ["ENVIRONMENT", "APPINSIGHTS_INSTRUMENTATIONKEY"]
}
}
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Always mark environment-specific connection strings as 'Deployment slot settings' (sticky) to prevent staging configs from migrating to production during a slot swap."
⚡ 60-Second Elevator Pitch Talking Points
- Mark database connection strings as sticky (slot-specific) settings so they stay bound to the slot.
- Use az webapp config connection-string set --slot-settings to lock production values.
- In Terraform, specify sticky_settings { connection_string_names = [...] } to prevent drift.
- Perform warm-up pings and staging validation before initiating production swaps.
Advertisement