Azure-Hosted Rust Service Patterns
Use this recipe when generating Rust services intended to run on Azure Container Apps, AKS, App Service containers, Functions custom handlers, or similar Azure-hosted environments.
Baseline Assumptions
- Configuration comes from environment variables, mounted files, or Azure App Configuration/Key Vault integration.
- Identity should prefer managed identity or workload identity over client secrets.
- Telemetry should use
tracingand optionally OpenTelemetry OTLP export. - Services should expose health endpoints when hosted behind Azure ingress/load balancers.
- Containers should support graceful shutdown on SIGTERM.
Configuration Shape
#[derive(Debug, Clone)]
pub struct AzureServiceConfig {
pub bind_address: std::net::SocketAddr,
pub app_config_endpoint: Option<String>,
pub key_vault_uri: Option<String>,
pub otlp_endpoint: Option<String>,
}
impl AzureServiceConfig {
pub fn from_env() -> Result<Self> {
let bind_address = std::env::var("BIND_ADDRESS")
.unwrap_or_else(|_| "0.0.0.0:8080".to_string())
.parse()
.map_err(|error| ServiceError::invalid_input(format!("BIND_ADDRESS is invalid: {error}")))?;
Ok(Self {
bind_address,
app_config_endpoint: std::env::var("AZURE_APP_CONFIG_ENDPOINT").ok(),
key_vault_uri: std::env::var("AZURE_KEY_VAULT_URI").ok(),
otlp_endpoint: std::env::var("OTEL_EXPORTER_OTLP_ENDPOINT").ok(),
})
}
}Container Readiness
For HTTP services, include health and readiness endpoints:
async fn health() -> &'static str {
"ok"
}
async fn readiness() -> Result<&'static str, ServiceError> {
// Check critical dependencies only. Keep this fast and bounded by timeouts.
Ok("ready")
}Guidance:
- Liveness should verify the process is responsive.
- Readiness should verify critical dependencies needed to receive traffic.
- Dependency checks must be bounded by short timeouts.
- Do not expose secrets or internal topology in health responses.
Managed Identity Guidance
When Azure SDK crates are used, verify the exact current crate names and APIs with Microsoft Learn or crate docs. Prefer default credential chains that support local development and managed identity in Azure.
Rules:
- Do not hard-code tenant IDs, subscription IDs, client IDs, secrets, or endpoints in code examples unless they are placeholders.
- Surface identity/config failures clearly at startup.
- Prefer environment-driven configuration for containerized deployments.
- Avoid Azure CLI shell-out from Rust services; use SDKs or REST clients.
Deployment-Ready Behavior
- Handle SIGTERM/SIGINT and shut down gracefully.
- Flush OpenTelemetry providers before exit.
- Set request timeouts and body size limits.
- Use structured JSON logs for Azure Log Analytics ingestion.
- Include version/build metadata in startup logs.