Term Kind Topic What it is
Cache Key Completeness practice Reverse Proxies The requirement that a cache key capture every input varying the response - the property whose violation turns a caching bug into a data leak.
Certificate Lifecycle Management practice TLS & Certificates Issuing, deploying, monitoring and renewing certificates automatically, because manual tracking reliably produces outages.
CIDR Planning practice VPC Design Allocating non-overlapping address ranges across an estate in advance, because ranges cannot be resized and overlaps prevent connectivity.
Content Purge Path Takedown Propagation, Cache Purge SLA practice Content Delivery Networks A separate, fast, fail-closed mechanism for removing content from every cache tier, which is what allows long TTLs everywhere else without making removal impossible.
Default Deny practice Firewalls & Security Groups A firewall posture in which nothing is permitted unless explicitly allowed, as opposed to blocking known-bad traffic.
DNS TTL Strategy practice DNS Choosing record lifetimes to balance failover speed against query volume, knowing that resolvers and clients do not reliably honour them.
Origin Shield Parent Cache, Mid-Tier Cache practice Content Delivery Networks An intermediate cache tier between edge locations and origin, so that hundreds of simultaneous edge misses become a handful of origin requests.
Route Origin Validation ROV, RPKI Origin Validation practice Routing & BGP Checking a BGP announcement's origin against a signed authorisation before accepting it, so a more specific prefix announced by the wrong network is dropped instead of winning.
Subnet Sizing practice Subnetting Choosing subnet prefix lengths with enough headroom, given that subnets cannot be resized and cloud providers reserve several addresses in each.
Subnetting and Address Planning practice Subnetting Dividing address space across zones and tiers, and the exhaustion failures that appear only at container density.
Trust Boundary Classification Where mTLS Is Required, Encryption Scope practice TLS & Certificates Writing down which network segments count as trust boundaries, so that mutual TLS is applied where it changes the security posture rather than uniformly or by intuition.
VPC Design practice VPC Design How virtual networks, subnets and connectivity are structured — decisions that are cheap now and extremely expensive to change later.