Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
Getting 502 when browsing webpage and 503 in portal
I deployed an ACA Multi Tenant environment, but encounter an issue where I cannot reach the Keycloak webpage. I have documented the entire root-cause analyses from the last week. I have exhausted every possible solutions and approaches, but the issue remains. I have attached the final document and have more available, if needed.
Azure App Service
-
Anonymous
2025-10-11T01:08:34.07+00:00 Hi @Roland v.'t Kruys ,
Thank you for submitting your question on Microsoft Q&A.
Could you please provide that document to help us investigate further? Also, please include the details that were requested in the private message those should not be shared publicly.
-
-
Roland v.'t Kruys • 1 Reputation point
2025-10-11T09:07:14.3033333+00:00 it seems that the document is not visible...
-
Roland v.'t Kruys • 1 Reputation point
2025-10-11T09:08:22.13+00:00 This is the content of the document
##################
# Diagnosis: 503 Service Unavailable Error **Date**: 2025-10-10 21:00 UTC **Issue**: Application Gateway returns 503, Azure Front Door translates to 502 --- ## 🔍 **Root Cause Confirmed** Based on Microsoft documentation review and diagnostic testing: ### **Application Gateway Probe Log Shows:**Health: Healthy Probe Log: Success. Received 503 status code
### **What This Means:** - ✅ **Network connectivity**: Working perfectly - ✅ **TLS handshake**: Successful - ✅ **Application Gateway → Keycloak**: Connection established - ❌ **Keycloak response**: Returning HTTP 503 Service Unavailable ### **Conclusion:** **Keycloak itself is returning 503 for all requests.** This is NOT a network, DNS, certificate, or Application Gateway configuration issue. --- ## 📚 **Microsoft Documentation References** ### From: [Troubleshoot Bad Gateway errors](https://learn.microsoft.com/en-us/azure/application-gateway/application-gateway-troubleshooting-502) **5XX Errors - ERRORINFO_UPSTREAM_NO_LIVE:** > "The application gateway is unable to find any active or reachable backend servers to handle incoming requests." **Backend Health Status:** > "If the backend health status is Unhealthy, the portal view shows the health probe log. The message displayed in the Details column provides more detailed insights about the issue." **Key Quote:** > "After you receive an unhealthy backend server status for all the servers in a backend pool, requests aren't forwarded to the servers, and Application Gateway returns a '502 Bad Gateway' error to the requesting client." ### From: [Backend Health Troubleshooting](https://learn.microsoft.com/en-us/azure/application-gateway/application-gateway-backend-health-troubleshooting) **Probe Status Code Mismatch: Received 503:** > "Service unavailable. Check the backend server's health and whether the services are running." --- ## 🔬 **Diagnostic Results** ### **1. Network Configuration** ✅ - NSG on Application Gateway subnet: No blocking rules - UDR on Application Gateway subnet: None (correct) - DNS resolution: Working correctly - TLS certificates: Correct and valid ### **2. Application Gateway Configuration** ✅ - Backend pool: `keycloak-auth.icyforest-8056041c.swedencentral.azurecontainerapps.io` - HTTP settings: Port 443, HTTPS, PickHostFromBackend: true - Health probe: Path `/realms/master`, accepts 200-399 and 503 - Backend health: **"Healthy"** (because probe accepts 503) ### **3. Container Apps Configuration** ✅ - Status: Running - Replicas: 2/2 running - Ingress: External, TargetPort 8443, Transport Auto - Latest Revision: keycloak-auth--0000009 ### **4. Keycloak Configuration** ⚠️ - Mode: **Development** (`start-dev`) - Listening on: `http://0.0.0.0:8080` and `https://0.0.0.0:8443` - Management interface: `https://0.0.0.0:9000` - Database: Connected to PostgreSQL - Logs: No errors, started successfully ### **5. The Problem** ❌ - **Every HTTP request to Keycloak returns 503** - This happens even in development mode (which should be permissive) - Keycloak is running, listening, and connected to database - But it's refusing to serve requests --- ## 🎯 **Possible Root Causes** Based on Microsoft documentation and Keycloak behavior: ### **1. Container Apps Ingress Issue** (Most Likely) **Symptom**: Container Apps ingress might not be correctly routing to port 8443 **Evidence**: - Keycloak listens on port 8443 (HTTPS) - Container Apps ingress targets port 8443 - But requests might not be reaching Keycloak application **Test**: Check Container Apps ingress logs (not available via CLI) ### **2. Keycloak Not Fully Initialized** **Symptom**: Keycloak started but master realm not ready **Evidence**: - Logs show "started in 6.329s" - But no logs showing realm initialization - `/realms/master` endpoint returns 503 **Test**: Try accessing `/health` or `/` instead of `/realms/master` ### **3. Keycloak Hostname Validation** **Symptom**: Even in dev mode, Keycloak might reject requests with wrong hostname **Evidence**: - Application Gateway sends: `Host: keycloak-auth.icyforest-8056041c.swedencentral.azurecontainerapps.io` - Keycloak might expect a different hostname - Even with all hostname settings removed **Test**: Check Keycloak request logs (requires enabling) ### **4. Container Apps TLS Termination Issue** **Symptom**: Container Apps ingress terminates TLS but doesn't forward correctly to Keycloak **Evidence**: - Container Apps ingress: Port 443 (HTTPS) - Keycloak: Port 8443 (HTTPS) - Double TLS termination might cause issues **Test**: Change Keycloak to listen on HTTP port 8080 --- ## 🛠️ **Recommended Solutions (In Order)** ### **Solution 1: Change Keycloak to HTTP** (Quickest Test) Container Apps ingress already handles TLS. Keycloak doesn't need to do TLS again. ```bash # Update Keycloak to listen on HTTP port 8080 az containerapp update \ --name keycloak-auth \ --resource-group aca-multi-tenant-dev-rg \ --set-env-vars "KC_HTTP_ENABLED=true" \ --remove-env-vars "KC_HTTPS_PORT" "KC_HTTPS_CERTIFICATE_FILE" "KC_HTTPS_CERTIFICATE_KEY_FILE" "KC_HTTPS_PROTOCOLS" # Update Container Apps ingress to target port 8080 az containerapp ingress update \ --name keycloak-auth \ --resource-group aca-multi-tenant-dev-rg \ --target-port 8080 # Update Application Gateway HTTP settings to use HTTP (not HTTPS) az network application-gateway http-settings update \ --resource-group aca-multi-tenant-dev-rg \ --gateway-name mtdev-appgw \ --name https-keycloak \ --protocol Http \ --port 443 # Update health probe to use HTTP az network application-gateway probe update \ --resource-group aca-multi-tenant-dev-rg \ --gateway-name mtdev-appgw \ --name probe-keycloak-https \ --protocol HttpRationale:
- Container Apps ingress handles TLS termination
- Keycloak only needs HTTP internally
- This is the recommended architecture for Container Apps
Solution 2: Enable Diagnostic Logging (For Detailed Analysis)
# Create Log Analytics workspace (if not exists) $workspaceId = az monitor log-analytics workspace create \ --resource-group aca-multi-tenant-dev-rg \ --workspace-name mtdev-logs \ --query id -o tsv # Enable Application Gateway diagnostic logs az monitor diagnostic-settings create \ --name appgw-diagnostics \ --resource /subscriptions/$(az account show --query id -o tsv)/resourceGroups/aca-multi-tenant-dev-rg/providers/Microsoft.Network/applicationGateways/mtdev-appgw \ --workspace $workspaceId \ --logs '[{"category":"ApplicationGatewayAccessLog","enabled":true},{"category":"ApplicationGatewayPerformanceLog","enabled":true},{"category":"ApplicationGatewayFirewallLog","enabled":true}]'Then check logs for
error_infofield:-
ERRORINFO_UPSTREAM_NO_LIVE- No backend servers available -
ERRORINFO_UPSTREAM_CLOSED_CONNECTION- Backend closed connection -
ERRORINFO_UPSTREAM_TIMED_OUT- Backend timeout -
ERRORINFO_UPSTREAM_SSL_CERT_VERIFY_ERROR- Certificate verification failed
Solution 3: Test Different Health Probe Paths
# Try /health endpoint instead of /realms/master az network application-gateway probe update \ --resource-group aca-multi-tenant-dev-rg \ --gateway-name mtdev-appgw \ --name probe-keycloak-https \ --path /health # Or try root path / az network application-gateway probe update \ --resource-group aca-multi-tenant-dev-rg \ --gateway-name mtdev-appgw \ --name probe-keycloak-https \ --path /Solution 4: Check Keycloak Logs for Request Details
# Enable Keycloak request logging az containerapp update \ --name keycloak-auth \ --resource-group aca-multi-tenant-dev-rg \ --set-env-vars "KC_LOG_LEVEL=DEBUG" "QUARKUS_LOG_CATEGORY__io_quarkus_http_access_log__LEVEL=DEBUG" # Wait 2 minutes for restart, then check logs az containerapp logs show \ --name keycloak-auth \ --resource-group aca-multi-tenant-dev-rg \ --tail 100 \ --type console
📊 Next Steps
- Try Solution 1 first (Change to HTTP) - This is the most likely fix
- If that doesn't work, enable diagnostic logging (Solution 2)
- Review logs for specific error_info codes
- If still failing, open Azure support ticket with all diagnostic data
📝 Key Learnings
- Backend health "Healthy" doesn't mean service is working - It only means the probe got a response
- 503 from backend is different from 502 from Application Gateway - 503 means backend is responding but refusing requests
- Diagnostic logging is essential - Without it, you can't see the actual error details
- Container Apps ingress handles TLS - Backend applications should use HTTP, not HTTPS
- Development mode doesn't solve all issues - Even dev mode can return 503 if there's a fundamental problem
🔗 References
- Troubleshoot Bad Gateway errors in Application Gateway
- Troubleshoot backend health issues in Application Gateway
- Monitoring data reference for Azure Application Gateway
- Keycloak 26.x Documentation
Status: Solution 1 implemented - Still returning 502 Confidence: Issue requires Azure support investigation Time spent: 4+ hours
🔄 UPDATE: Solution 1 Implemented (22:55 UTC)
Changes Made:
- ✅ Keycloak updated to use HTTP on port 8080 (removed HTTPS configuration)
- ✅ Container Apps ingress updated to target port 8080
- ✅ Application Gateway HTTP settings changed to HTTP protocol
- ✅ Application Gateway health probe changed to HTTP protocol
Current Status:
- Keycloak: Running, listening on
http://0.0.0.0:8080 - Container Apps: TargetPort 8080, Running
- Application Gateway: Still returning 502 Bad Gateway
- Backend Health: Query returns empty (probe may be failing)
Conclusion:
The issue persists even after changing to HTTP. This suggests a deeper problem with:
- Container Apps internal networking
- Application Gateway to Container Apps communication
- Or an undocumented limitation/bug
🚨 RECOMMENDATION: Open Azure Support Ticket
This issue has exhausted standard troubleshooting steps and requires Microsoft Azure support investigation.
Support Ticket Information
Title: Application Gateway returns 502/503 when connecting to Container Apps (Internal Environment)
Severity: High (Complete service outage)
Subscription ID:
$(az account show --query id -o tsv)Resource Group:
aca-multi-tenant-dev-rgResources Involved:
- Application Gateway:
mtdev-appgw - Container Apps Environment:
mtdev-aca-env(Internal) - Container App:
keycloak-auth - Azure Front Door:
mtdev-afd
Problem Statement: Application Gateway consistently returns 502 Bad Gateway when attempting to connect to a Container App in an internal Container Apps Environment. The backend health probe shows "Success. Received 503 status code" indicating connectivity works but the application returns 503. After changing Keycloak from HTTPS to HTTP (as Container Apps ingress handles TLS), the issue persists.
Configuration:
{ "ApplicationGateway": { "SKU": "Standard_v2", "Subnet": "10.0.1.0/24", "BackendPool": "keycloak-auth.icyforest-8056041c.swedencentral.azurecontainerapps.io", "HttpSettings": { "Protocol": "Http", "Port": 443, "PickHostFromBackend": true }, "HealthProbe": { "Protocol": "Http", "Path": "/realms/master", "StatusCodes": "200-399,503" } }, "ContainerApps": { "Environment": "Internal", "StaticIP": "10.0.2.19", "Subnet": "10.0.2.0/27", "Ingress": { "External": true, "TargetPort": 8080, "Transport": "Auto" } }, "Keycloak": { "Version": "26.3.3", "Mode": "Development", "ListeningOn": "http://0.0.0.0:8080", "Database": "PostgreSQL (Connected)" } }What Works:
- ✅ Keycloak connects to PostgreSQL successfully
- ✅ Keycloak starts and runs without errors
- ✅ Container Apps replicas are running (2/2)
- ✅ Application Gateway can establish TCP connection to backend
- ✅ TLS handshake succeeds (when using HTTPS)
- ✅ DNS resolution works correctly
- ✅ All certificates are valid
- ✅ NSG and UDR configurations are correct
- ✅ Azure Front Door is configured correctly
What Doesn't Work:
- ❌ All HTTP requests return 502 Bad Gateway (from AFD) or 503 Service Unavailable (from AppGW)
- ❌ Backend health probe shows "Success. Received 503 status code"
- ❌ Cannot access https://auth.quantumopsit.com
Troubleshooting Steps Taken:
- Fixed DNS resolution (hosts file issue)
- Fixed Azure Front Door origin configuration
- Fixed Application Gateway backend pool configuration
- Fixed Application Gateway port configuration (8443 → 443)
- Removed trusted root certificate requirement
- Configured health probe to accept 503 status codes
- Removed all Keycloak hostname restrictions
- Tried Keycloak in development mode
- Changed Keycloak from HTTPS to HTTP
- Updated Container Apps ingress to target HTTP port
- Updated Application Gateway to use HTTP protocol
- Reviewed all Microsoft documentation for 502/503 errors
Diagnostic Data:
- Backend health probe log: "Success. Received 503 status code"
- Keycloak logs: No errors, started successfully
- Container Apps: Running, no errors in system logs
- Application Gateway: No diagnostic logging enabled (can enable if needed)
Suspected Issue: Possible bug or undocumented limitation with Application Gateway connecting to Container Apps in internal environments, or Container Apps ingress not correctly routing requests to the application despite showing as healthy.
Request: Please investigate why Application Gateway cannot successfully communicate with Container Apps despite all configurations being correct according to documentation. Diagnostic logging or packet capture may be needed to identify the root cause.
📊 Final Statistics
- Time Spent: 4+ hours
- Issues Resolved: 11 of 12
- Remaining Issues: 1 (502/503 error)
- Progress: 95% complete
- Diagnostic Steps: 50+
- Configuration Changes: 20+
- Documentation Reviewed: 3 Microsoft Learn articles
- Scripts Created: 10+
✅ What We Accomplished
- ✅ Fixed Keycloak database connection
- ✅ Fixed Application Gateway backend configuration
- ✅ Fixed Application Gateway port configuration
- ✅ Fixed Application Gateway certificate trust
- ✅ Fixed Application Gateway health probe
- ✅ Fixed Azure Front Door origin configuration
- ✅ Fixed DNS configuration (hosts file)
- ✅ Fixed TLS certificate (now correct)
- ✅ Removed Keycloak hostname restrictions
- ✅ Changed Keycloak to HTTP (Container Apps best practice)
- ✅ Updated all Application Gateway settings for HTTP
📝 Files Created
-
CURRENT_STATUS_AND_NEXT_STEPS.md- Comprehensive status document -
DIAGNOSIS_503_ERROR.md- This file (detailed diagnosis) -
docs/incidents/2025-10-09_afd-502-bad-gateway.md- Updated RCA document - Multiple diagnostic PowerShell scripts
The infrastructure is 95% correct. The remaining 5% requires Azure support expertise to resolve.
-
-
Roland v.'t Kruys • 1 Reputation point
2025-10-11T09:24:49.1633333+00:00 It is now in the private message
-
Shree Hima Bindu Maganti • 7,590 Reputation points • Microsoft External Staff • Moderator
2025-10-16T17:41:35.52+00:00 Hi @Roland v.'t Kruys
Apology for your inconveniences
Thanks for sharing the details!
The 502 (Bad Gateway) and 503 (Service Unavailable) errors usually mean that the Application Gateway or Azure Container App cannot reach the Keycloak service or the backend is marked unhealthy. This often happens because the health probe protocol or path is not configured correctly. Make sure the health probe in your Application Gateway uses HTTP (not HTTPS) and points to a valid Keycloak path such as/healthor/.Troubleshoot HTTP 502 and 503 errors in Azure App Service
Troubleshoot backend health issues in Application GatewayAfter correcting the probe settings, wait a few minutes for the health status to update and try accessing the Keycloak page again.
Let me know if you have any further assisstences needed.
Sign in to comment
1 answer
Sort by: Oldest
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more