TopicsNetworking
Networking
TCP, TLS, load balancers, and why the p99 lives in the handshake.
Common tags: tcp, tls, lb
- Networking
TLS — Handshake, Certs, mTLS & Termination
Cluster · HTTP — Versions, TLS & Connection Lifecycle
TLS gives HTTP confidentiality, integrity, and server authentication, plus client authentication when you ask for mTLS. Backend interviews are about handshake cost, certificate fields, and where the session ends.
Open study →- networking
- http
- http2
- http3
- quic
- tls
- connections
- interview
- Networking
HTTP/3 & QUIC — UDP, Migration, 0-RTT & HOL Fixes
Cluster · HTTP — Versions, TLS & Connection Lifecycle
HTTP/3 runs on QUIC over UDP, with TLS 1.3 inside the transport. Loss stays on one stream, a connection can survive an IP change, and 0-RTT early data can be replayed.
Open study →- networking
- http
- http2
- http3
- quic
- tls
- connections
- interview
- Networking
HTTP/2 — Multiplexing, Streams, HPACK & Push Tradeoffs
Cluster · HTTP — Versions, TLS & Connection Lifecycle
HTTP/2 is a binary framed protocol. Many streams share one TCP and TLS connection, HPACK compresses headers, and server push is a dead end in browsers. TCP loss still stalls every stream.
Open study →- networking
- http
- http2
- http3
- quic
- tls
- connections
- interview
- Networking
HTTP/1.1 — Keep-Alive, Pipelining & Head-of-Line Blocking
Cluster · HTTP — Versions, TLS & Connection Lifecycle
HTTP/1.1 made persistent connections the default so TCP and TLS are amortized. Pipelining failed in practice because responses stay in order, which is application head-of-line blocking.
Open study →- networking
- http
- http2
- http3
- quic
- tls
- connections
- interview
- Networking
HTTP — Versions, TLS & Connection Lifecycle
Cluster · HTTP — Versions, TLS & Connection Lifecycle
HTTP is a versioned application protocol on TCP or QUIC, almost always under TLS. This hub maps HTTP/1.1, HTTP/2, and HTTP/3, plus where TLS ends and how pools, timeouts, and retries fail.
Open study →- networking
- http
- http2
- http3
- quic
- tls
- connections
- interview
- Networking
Connections at Scale — Pooling, Timeouts, Retries & Failure Modes
Cluster · HTTP — Versions, TLS & Connection Lifecycle
At scale the HTTP version matters less than the pool, the deadlines, and the retry policy. Wrong defaults cause reset storms, double writes, and tail latency that no cipher suite will fix.
Open study →- networking
- http
- http2
- http3
- quic
- tls
- connections
- interview
- Networking
VPC Fundamentals — Subnets, Route Tables, Security Groups & NACLs
Cluster · Private Networking
Public versus private is a route, not a checkbox. A public subnet sends 0.0.0.0/0 to an internet gateway. Security groups are stateful ENI allow lists. NACLs are stateless subnet filters. Plan non-overlapping CIDRs before you peer.
Open study →- networking
- vpc
- cidr
- security-groups
- nacl
- privatelink
- Networking
Tunneling — VPN, WireGuard, SSH tunnels, Cloudflare Tunnel / ngrok patterns
Cluster · Private Networking
Tunnels connect people, CI, and datacenters to private networks without publishing every service. Site-to-site routes CIDRs. Client VPN and WireGuard attach users. Reverse tunnels and SSH remote forwards invert the firewall and need an identity gate.
Open study →- networking
- vpn
- wireguard
- cloudflare-tunnel
- ssh-tunnel
- Networking
Secure Access Without SSH — AWS SSM Session Manager, Bastions & Alternatives
Cluster · Private Networking
Session Manager gives a shell and supported port forwarding without inbound SSH or a public IP. The agent dials Systems Manager outbound. IAM authorizes the operator. A private subnet still needs NAT or interface endpoints, and logging is not automatic.
Open study →- networking
- ssm
- session-manager
- bastion
- iam
- Networking
Private Networking — VPC, NAT, SSM, Tunnels & Ingress
Cluster · Private Networking
Private networking decides who can reach what, by which path, and under whose control. This hub maps VPC addressing, NAT egress, SSM access, tunnels, and north-south ingress. Sidecar/mesh and CDN stay in their own clusters.
Open study →- networking
- vpc
- nat
- ssm
- tunnels
- ingress
- private-networking
- Networking
NAT Gateways & Egress — Private Subnets, NAT vs NAT Instance, Egress Control
Cluster · Private Networking
A private subnet has no direct internet-gateway route. NAT lets IPv4 workloads start outbound flows. It is not a firewall and not inbound publishing. Prefer endpoints when the destination is a supported AWS API, and one NAT gateway per AZ when you pay for resilience.
Open study →- networking
- nat
- egress
- vpc-endpoints
- cost
- Networking
Ingress Controllers & North-South — K8s Ingress/Gateway API, L7 vs L4, TLS
Cluster · Private Networking
North-south is traffic entering or leaving a cluster. Ingress and Gateway API configure that entry and need an implementation. L4 forwards connections. L7 routes on host and path. TLS termination is a trust boundary. A service mesh is a different problem.
Open study →- networking
- ingress
- gateway-api
- alb
- nlb
- tls
- Networking
Sidecar Pattern & Service Mesh — Out-of-Process Proxies, Architecture & Tradeoffs
Cluster · Sidecar & Service Mesh
A sidecar is an out-of-process data plane next to the app: the workload speaks plain HTTP/gRPC, the proxy owns identity, retries, telemetry, and traffic policy. This hub maps mechanics, proxy choices, control-plane discovery, cloud equivalents, and when not to mesh.
Open study →- sidecar
- service-mesh
- data-plane
- control-plane
- out-of-process-proxy
- networking
- interview
- Networking
Sidecar Mechanics — Transparent Proxy, iptables/eBPF Capture & Container Lifecycle
Cluster · Sidecar & Service Mesh
A sidecar only works if app traffic actually hits it. Transparent capture (redirect without app config) and pod lifecycle (init, ready, drain) are where interviews get concrete. Envoy, nginx, and Linkerd-proxy all need a capture story and a start/stop story.
Open study →- sidecar
- iptables
- ebpf
- transparent-proxy
- pod-lifecycle
- networking
- interview
- Networking
Mesh vs Library vs Gateway — Latency Tax, Blast Radius & Migration
Cluster · Sidecar & Service Mesh
Cross-cutting policy has three classic homes: in-process library, per-pod sidecar/mesh, and edge gateway. Ambient/eBPF is a fourth. Each shifts latency, failure blast radius, and who upgrades what. This page ties the cluster together — and repeats when not to mesh.
Open study →- mesh
- sidecar
- service-mesh
- gateway
- ambient
- latency
- blast-radius
- networking
- interview
- Networking
Control Plane & Discovery — xDS-style Config, Endpoints & Convergence
Cluster · Sidecar & Service Mesh
Sidecars are useless with stale config. The control plane discovers endpoints, compiles routes and listeners, and pushes them until the fleet converges. Envoy xDS is the best-known API shape — the ideas apply to any mesh.
Open study →- xds
- control-plane
- eds
- cds
- discovery
- sidecar
- service-mesh
- networking
- interview
- Networking
Data-Plane Proxies — Envoy, nginx, Linkerd-proxy & What They Own
Cluster · Sidecar & Service Mesh
The data plane is the process that touches every request. Envoy, nginx, and Linkerd-proxy play the same role with different L7 depth, memory, and ops. Interviews want what lives in the proxy vs the app — not an Envoy product tutorial.
Open study →- envoy
- nginx
- linkerd-proxy
- data-plane
- sidecar
- mtls
- retries
- networking
- interview
- Networking
Cloud Equivalents — App Mesh, ALB/NLB, VPC Lattice & When Not to Mesh
Cluster · Sidecar & Service Mesh
On AWS and peers you can buy pieces of the mesh story without running your own control plane. App Mesh is managed Envoy sidecars; ALB/NLB cover north-south; VPC Lattice is a service network. Interviews want honest tradeoffs and a clear when-not-to-mesh.
Open study →- app-mesh
- alb
- nlb
- vpc-lattice
- cloud-map
- sidecar
- service-mesh
- networking
- interview
- Networking
Sticky Sessions vs Stateless — Affinity Tradeoffs & Consistent Hashing at the Edge
Cluster · Load balancing
Cookie affinity and source-IP hash hurt scale/failover; prefer JWT/session store; when sticky is forced (WebSocket); consistent hash for cache locality without sticky sessions.
Open study →- sticky-sessions
- stateless
- jwt
- redis
- consistent-hashing
- websocket
- Networking
Load Balancing — L4 vs L7, Algorithms & Health Checks
Cluster · Load balancing
What an LB owns (VIP, backends, health, drain); L4 vs L7 matrix; algorithm zoo; health/drain; global LB; sticky vs stateless — comparative tradeoffs for senior interviews.
Open study →- load-balancing
- l4
- l7
- system-design
- interview
- Networking
L4 vs L7 Proxies — Connection Routing, TLS Termination & Protocol Awareness
Cluster · Load balancing
TCP/UDP passthrough vs HTTP/gRPC routing; TLS terminate vs passthrough; SNI; HTTP/2 multiplexing implications; when L4 is enough; gRPC/WebSocket affinity needs.
Open study →- l4
- l7
- tls
- envoy
- nginx
- alb
- nlb
- grpc
- websocket
- Networking
Health Checks, Slow Start & Connection Draining
Cluster · Load balancing
Active vs passive health; HTTP vs TCP checks; thresholds; slow start after recover; connection draining / deregistration delay; fail-open vs fail-closed.
Open study →- health-checks
- slow-start
- connection-draining
- fail-open
- fail-closed
- Networking
Global Load Balancing — DNS, Anycast & Multi-Region Failover
Cluster · Load balancing
DNS geo/latency, Anycast, health-aware DNS; active-active vs active-passive; split-brain; RTO vs RPO confusion.
Open study →- dns
- anycast
- multi-region
- route53
- failover
- rto
- Networking
Balancing Algorithms — Round-Robin, Least-Conn, Maglev & Power-of-Two Choices
Cluster · Load balancing
RR, WRR, least-conn, least-time, Maglev, P2C + bounded load; skew/hot-key behavior; when each wins.
Open study →- round-robin
- least-conn
- maglev
- p2c
- consistent-hashing
- Networking
TLS Termination & Anycast Edge
Cluster · CDN & edge cache
Edge TLS plus Anycast cuts handshake RTT and shares one VIP worldwide. Trade-off: anycast can flap, keys live at the edge, and origin still needs a private path (mTLS).
Open study →- networking
- cdn
- Networking
SWR & stale-if-error
Cluster · CDN & edge cache
max-age is hard freshness; stale-while-revalidate hides revalidation; stale-if-error keeps serving through origin 5xx. Together they are a latency and availability tool, not a correctness tool.
Open study →- networking
- cdn
- Networking
Request Collapsing / Coalescing
Cluster · CDN & edge cache
When N waiters miss the same key, one fetch goes upstream. Collapsing is local; origin shield is topological. You still need single-flight at every tier or a popular expiry looks like a DDoS.
Open study →- networking
- cdn
- Networking
Purge & Generation Tokens
Cluster · CDN & edge cache
Instant purge races with shields; soft purge plus generation tokens / surrogate keys make invalidation deterministic. Double-purge or bump the token when the shield can refill stale.
Open study →- networking
- cdn
- Networking
Cache Keys & Vary
Cluster · CDN & edge cache
The cache key is the identity of a variant. Cookie in Vary or raw query strings explode cardinality; normalize host/path and put only true content axes in the key.
Open study →- networking
- cdn
- Networking
CDNs, Cache Hierarchy & Origin Shielding
Cluster · CDN & edge cache
Edge→mid-tier→shield→origin; s-maxage/SWR; cache keys; purge races; request collapsing.
Open study →- networking
- cdn
- performance