The ingress receives a browser request before the application does. This track follows that handoff through trusted forwarding, hostname selection, healthy upstream admission, and bounded request-body or retry behavior. A broken boundary can misroute private traffic or duplicate a write even when the application handler is correct.
Topics in this track
- Trusted Proxy Hops and Forwarded Client Identity — Accept client address and scheme metadata only from an authenticated, known proxy path.
- Host Authority Routing and Default Deny — Bind hostnames, TLS names, and application routes without sending unknown authorities to a privileged default.
- Ingress Health, Readiness, and Connection Drain — Distinguish process liveness from traffic readiness and drain long-lived requests during rollout.
- Proxy Body Budgets, Timeouts, and Retry Ownership — Align ingress limits with application deadlines and prevent ambiguous retries of side-effecting requests.
Prerequisite paths
Edge Request Normalization and Origin Trust; Network Transport and Domain Operations; Request Deadlines, Retries, and Backoff.
Practice and check
Build Project: permit ingress cutover and safe retry and review Web Development: ingress and upstream contracts quiz.
Further connections
Node HTTP Drain, Readiness, and Graceful Shutdown.
