Term Kind Topic What it is
Anycast concept Networking Advertising the same IP address from many locations, so the network routes each client to the topologically nearest one.
Bandwidth-Delay Product concept Network Performance Bandwidth multiplied by round-trip time — the amount of data that must be in flight to keep a link fully utilised.
Certificate Chain Chain of Trust concept TLS & Certificates The sequence from a server's certificate through one or more intermediate CAs to a root the client already trusts.
Connection Fan-In Ephemeral Client Problem, Serverless Connection Storm concept Network Performance The problem created when many short-lived compute instances each require a connection to a stateful dependency that can only support a small number - and the intermediary pattern that resolves it.
Connection Migration Session Continuity, Seamless Handover concept WebSockets & Realtime Keeping a logical session alive when the underlying network path changes - either in the transport, or reconstructed by the application after a reconnect.
Data Plane Proxy Envoy, Sidecar Proxy concept Service Mesh Networking The per-workload proxy that actually carries mesh traffic, applying mTLS, retries, timeouts, routing and telemetry outside the application.
DNS Resolution Chain concept DNS The sequence of lookups from browser cache through OS cache, recursive resolver, root, TLD and authoritative server that turns a name into an address.
DNS TTL concept DNS The time a DNS record may be cached, and a value that resolvers, operating systems and applications honour inconsistently.
ECMP Flow Pinning Flow Hashing, Per-Flow Path Selection concept Network Performance Because a router picks one of several equal-cost paths by hashing a flow's five-tuple, one connection is confined to one link, so aggregate capacity is never per-connection capacity.
Fan-Out Amplification Broadcast Multiplication, Subscriber Amplification concept WebSockets & Realtime The property that one input event becomes as many output events as there are subscribers, making the workload proportional to audience size rather than to event rate - and the reason broadcast paths cannot sha…
Firewalls and Security Groups concept Firewalls & Security Groups Network-level access control, its real value as a second layer, and why the perimeter model stopped being sufficient.
Gateway Timeout Chain concept API Gateways The sequence of timeouts from client through load balancer, gateway and service, which must decrease inward or produce confusing failures.
gRPC Streaming concept gRPC Transport Four call patterns — unary, server streaming, client streaming and bidirectional — built on HTTP/2 streams.
Head-of-Line Blocking concept HTTP/1.1, HTTP/2 & HTTP/3 One delayed item stalling everything queued behind it, even when the rest could have been processed - the failure mode that ordering guarantees create.
Health Check Configuration concept Layer 4 vs Layer 7 The interval, timeout, and healthy/unhealthy thresholds that together determine how quickly a failed backend leaves rotation.
Idle Connection Race Keep-Alive Race, Idle Pool Reset concept HTTP/1.1, HTTP/2 & HTTP/3 The unavoidable window where a server closes a pooled connection just as a client sends a request on it, producing a small error floor that is worst when traffic is lightest.
Invisible Resource Exhaustion Silent Limit, Unattributed Failure concept NAT & Egress A class of failure where a shared finite resource outside the application's view is exhausted, producing intermittent unexplained errors while every local metric looks healthy.
Layer 4 vs Layer 7 Load Balancing concept Networking Balancing on connection metadata (IP and port) versus on the content of the request (path, host, headers).
Load Balancer Types concept Layer 4 vs Layer 7 Layer 4 against layer 7, the algorithms that distribute requests, and why "least connections" is usually better than round robin.
Load Balancing Algorithm concept Layer 4 vs Layer 7 The rule deciding which backend receives a request — round robin, least connections, least response time, or hash-based.
Network Performance concept Network Performance Latency is bounded by physics and bandwidth is bought — so architectural performance work is mostly about reducing round trips and moving data closer.
Path MTU Discovery PMTUD concept Network Troubleshooting The mechanism by which a sender discovers the largest packet size a path supports, and a common cause of connections that establish and then hang.
Path MTU Discovery Failure MTU Black Hole, PMTUD Blackhole concept Network Troubleshooting Large packets silently discarded because the ICMP messages that would report the size limit are blocked - producing the signature "small requests work, large transfers hang".
Port Exhaustion concept NAT & Egress Running out of available source ports for outbound connections through a NAT device, causing new connections to fail while everything appears healthy.
Private Connectivity PrivateLink, Private Endpoint, Service Endpoint concept Private Connectivity Reaching a cloud or partner service over private address space rather than the public internet, without exposing the consumer's network in return.
Private Endpoint PrivateLink, VPC Endpoint concept Private Connectivity A private network address inside your VPC that reaches a managed service directly, without traversing the internet or a NAT gateway.
Proxy Buffering concept Reverse Proxies Whether a reverse proxy accumulates a response before forwarding it, which protects the backend from slow clients but breaks streaming.
Reconnect Storm Thundering Herd on Reconnect, Connection Stampede, Recovery Amplification concept WebSockets & Realtime The synchronised burst of clients re-establishing connections after a disruption, which is far more expensive than steady-state traffic and routinely turns a brief network fault into a prolonged self-sustainin…
Route Propagation concept Routing & BGP Automatically inserting routes learned from a VPN or dedicated connection into a route table, rather than maintaining them by hand.
Route Table concept Subnetting The set of rules deciding where traffic leaving a subnet is sent, and the thing that actually makes a subnet public or private.
Service Mesh Networking concept Service Mesh Networking What a mesh actually does at the network level, the cost per hop, and the shift from sidecar to shared-proxy models.
Source NAT SNAT, Masquerading concept NAT & Egress Rewriting the source address of outbound packets so that many private addresses share one public address, with a translation table mapping replies back.
Stateful Packet Filtering concept Firewalls & Security Groups Filtering that tracks connection state, so return traffic for an allowed outbound connection is permitted automatically.
Subnet concept Networking A subdivision of a network's address range, used as the unit of routing and, in cloud, of availability-zone placement.
Virtual Private Cloud VPC, VNet concept Networking A logically isolated network inside a cloud provider, with an address range you control and explicit rules for what may enter and leave.
VPC Peering concept VPC Design A direct network connection between two VPCs, which is simple, cheap and non-transitive — the last property being the one that shapes topology.
VPN vs Dedicated Connection Direct Connect, ExpressRoute concept Private Connectivity Two ways to link on-premises networks to cloud — an encrypted tunnel over the internet, or a private physical circuit.
X-Forwarded-For Forwarded Header concept Reverse Proxies The header chain recording original client addresses through a series of proxies — and a value that must never be trusted without knowing the topology.