Networking
Topic, then cluster, then study. Recently added is the short list at the top.
Recently added
Show more- 6.Connections at Scale — Pooling, Timeouts, Retries & Failure ModesAt scale the HTTP version matters less than the pool, the deadlines, and the retry policy. Wrong defaults cause reset storms, double writes, and tail latency that no cipher suite will fix.
- 1.HTTP — Versions, TLS & Connection LifecycleHTTP is a versioned application protocol on TCP or QUIC, almost always under TLS. This hub maps HTTP/1.1, HTTP/2, and HTTP/3, plus where TLS ends and how pools, timeouts, and retries fail.
- 2.HTTP/1.1 — Keep-Alive, Pipelining & Head-of-Line BlockingHTTP/1.1 made persistent connections the default so TCP and TLS are amortized. Pipelining failed in practice because responses stay in order, which is application head-of-line blocking.
- 3.HTTP/2 — Multiplexing, Streams, HPACK & Push TradeoffsHTTP/2 is a binary framed protocol. Many streams share one TCP and TLS connection, HPACK compresses headers, and server push is a dead end in browsers. TCP loss still stalls every stream.
- 4.HTTP/3 & QUIC — UDP, Migration, 0-RTT & HOL FixesHTTP/3 runs on QUIC over UDP, with TLS 1.3 inside the transport. Loss stays on one stream, a connection can survive an IP change, and 0-RTT early data can be replayed.
- 5.TLS — Handshake, Certs, mTLS & TerminationTLS gives HTTP confidentiality, integrity, and server authentication, plus client authentication when you ask for mTLS. Backend interviews are about handshake cost, certificate fields, and where the session ends.
Networking
TCP, TLS, load balancers, and why the p99 lives in the handshake.
CDN & edge cache
6 studies- 1.CDNs, Cache Hierarchy & Origin ShieldingEdge→mid-tier→shield→origin; s-maxage/SWR; cache keys; purge races; request collapsing.
- 2.Cache Keys & VaryThe cache key is the identity of a variant. Cookie in Vary or raw query strings explode cardinality; normalize host/path and put only true content axes in the key.
- 3.SWR & stale-if-errormax-age is hard freshness; stale-while-revalidate hides revalidation; stale-if-error keeps serving through origin 5xx. Together they are a latency and availability tool, not a correctness tool.
- 4.Purge & Generation TokensInstant purge races with shields; soft purge plus generation tokens / surrogate keys make invalidation deterministic. Double-purge or bump the token when the shield can refill stale.
- 5.TLS Termination & Anycast EdgeEdge TLS plus Anycast cuts handshake RTT and shares one VIP worldwide. Trade-off: anycast can flap, keys live at the edge, and origin still needs a private path (mTLS).
- 6.Request Collapsing / CoalescingWhen N waiters miss the same key, one fetch goes upstream. Collapsing is local; origin shield is topological. You still need single-flight at every tier or a popular expiry looks like a DDoS.
- 1.HTTP — Versions, TLS & Connection LifecycleHTTP is a versioned application protocol on TCP or QUIC, almost always under TLS. This hub maps HTTP/1.1, HTTP/2, and HTTP/3, plus where TLS ends and how pools, timeouts, and retries fail.
- 2.HTTP/1.1 — Keep-Alive, Pipelining & Head-of-Line BlockingHTTP/1.1 made persistent connections the default so TCP and TLS are amortized. Pipelining failed in practice because responses stay in order, which is application head-of-line blocking.
- 3.HTTP/2 — Multiplexing, Streams, HPACK & Push TradeoffsHTTP/2 is a binary framed protocol. Many streams share one TCP and TLS connection, HPACK compresses headers, and server push is a dead end in browsers. TCP loss still stalls every stream.
- 4.HTTP/3 & QUIC — UDP, Migration, 0-RTT & HOL FixesHTTP/3 runs on QUIC over UDP, with TLS 1.3 inside the transport. Loss stays on one stream, a connection can survive an IP change, and 0-RTT early data can be replayed.
- 5.TLS — Handshake, Certs, mTLS & TerminationTLS gives HTTP confidentiality, integrity, and server authentication, plus client authentication when you ask for mTLS. Backend interviews are about handshake cost, certificate fields, and where the session ends.
- 6.Connections at Scale — Pooling, Timeouts, Retries & Failure ModesAt scale the HTTP version matters less than the pool, the deadlines, and the retry policy. Wrong defaults cause reset storms, double writes, and tail latency that no cipher suite will fix.
Load balancing
6 studies- 1.Load Balancing — L4 vs L7, Algorithms & Health ChecksWhat an LB owns (VIP, backends, health, drain); L4 vs L7 matrix; algorithm zoo; health/drain; global LB; sticky vs stateless — comparative tradeoffs for senior interviews.
- 2.L4 vs L7 Proxies — Connection Routing, TLS Termination & Protocol AwarenessTCP/UDP passthrough vs HTTP/gRPC routing; TLS terminate vs passthrough; SNI; HTTP/2 multiplexing implications; when L4 is enough; gRPC/WebSocket affinity needs.
- 3.Balancing Algorithms — Round-Robin, Least-Conn, Maglev & Power-of-Two ChoicesRR, WRR, least-conn, least-time, Maglev, P2C + bounded load; skew/hot-key behavior; when each wins.
- 4.Health Checks, Slow Start & Connection DrainingActive vs passive health; HTTP vs TCP checks; thresholds; slow start after recover; connection draining / deregistration delay; fail-open vs fail-closed.
- 5.Global Load Balancing — DNS, Anycast & Multi-Region FailoverDNS geo/latency, Anycast, health-aware DNS; active-active vs active-passive; split-brain; RTO vs RPO confusion.
- 6.Sticky Sessions vs Stateless — Affinity Tradeoffs & Consistent Hashing at the EdgeCookie affinity and source-IP hash hurt scale/failover; prefer JWT/session store; when sticky is forced (WebSocket); consistent hash for cache locality without sticky sessions.
Private Networking
6 studies- 1.Private Networking — VPC, NAT, SSM, Tunnels & IngressPrivate networking decides who can reach what, by which path, and under whose control. This hub maps VPC addressing, NAT egress, SSM access, tunnels, and north-south ingress. Sidecar/mesh and CDN stay in their own clusters.
- 2.VPC Fundamentals — Subnets, Route Tables, Security Groups & NACLsPublic versus private is a route, not a checkbox. A public subnet sends 0.0.0.0/0 to an internet gateway. Security groups are stateful ENI allow lists. NACLs are stateless subnet filters. Plan non-overlapping CIDRs before you peer.
- 3.NAT Gateways & Egress — Private Subnets, NAT vs NAT Instance, Egress ControlA private subnet has no direct internet-gateway route. NAT lets IPv4 workloads start outbound flows. It is not a firewall and not inbound publishing. Prefer endpoints when the destination is a supported AWS API, and one NAT gateway per AZ when you pay for resilience.
- 4.Secure Access Without SSH — AWS SSM Session Manager, Bastions & AlternativesSession Manager gives a shell and supported port forwarding without inbound SSH or a public IP. The agent dials Systems Manager outbound. IAM authorizes the operator. A private subnet still needs NAT or interface endpoints, and logging is not automatic.
- 5.Tunneling — VPN, WireGuard, SSH tunnels, Cloudflare Tunnel / ngrok patternsTunnels connect people, CI, and datacenters to private networks without publishing every service. Site-to-site routes CIDRs. Client VPN and WireGuard attach users. Reverse tunnels and SSH remote forwards invert the firewall and need an identity gate.
- 6.Ingress Controllers & North-South — K8s Ingress/Gateway API, L7 vs L4, TLSNorth-south is traffic entering or leaving a cluster. Ingress and Gateway API configure that entry and need an implementation. L4 forwards connections. L7 routes on host and path. TLS termination is a trust boundary. A service mesh is a different problem.
Sidecar & Service Mesh
6 studies- 1.Sidecar Pattern & Service Mesh — Out-of-Process Proxies, Architecture & TradeoffsA sidecar is an out-of-process data plane next to the app: the workload speaks plain HTTP/gRPC, the proxy owns identity, retries, telemetry, and traffic policy. This hub maps mechanics, proxy choices, control-plane discovery, cloud equivalents, and when not to mesh.
- 2.Sidecar Mechanics — Transparent Proxy, iptables/eBPF Capture & Container LifecycleA sidecar only works if app traffic actually hits it. Transparent capture (redirect without app config) and pod lifecycle (init, ready, drain) are where interviews get concrete. Envoy, nginx, and Linkerd-proxy all need a capture story and a start/stop story.
- 3.Data-Plane Proxies — Envoy, nginx, Linkerd-proxy & What They OwnThe data plane is the process that touches every request. Envoy, nginx, and Linkerd-proxy play the same role with different L7 depth, memory, and ops. Interviews want what lives in the proxy vs the app — not an Envoy product tutorial.
- 4.Control Plane & Discovery — xDS-style Config, Endpoints & ConvergenceSidecars are useless with stale config. The control plane discovers endpoints, compiles routes and listeners, and pushes them until the fleet converges. Envoy xDS is the best-known API shape — the ideas apply to any mesh.
- 5.Cloud Equivalents — App Mesh, ALB/NLB, VPC Lattice & When Not to MeshOn AWS and peers you can buy pieces of the mesh story without running your own control plane. App Mesh is managed Envoy sidecars; ALB/NLB cover north-south; VPC Lattice is a service network. Interviews want honest tradeoffs and a clear when-not-to-mesh.
- 6.Mesh vs Library vs Gateway — Latency Tax, Blast Radius & MigrationCross-cutting policy has three classic homes: in-process library, per-pod sidecar/mesh, and edge gateway. Ambient/eBPF is a fourth. Each shifts latency, failure blast radius, and who upgrades what. This page ties the cluster together — and repeats when not to mesh.