Term Kind Topic What it is
Reverse Proxy in Practice pattern Reverse Proxies A server that sits in front of origins and terminates, caches, routes and protects — the cheapest place to solve several problems at once.
Round-Trip Time RTT, Latency Floor metric Network Performance The time for a packet to travel to a destination and back — a physical floor that no application optimisation can reduce.
Route Origin Validation ROV, RPKI Origin Validation practice Routing & BGP Checking a BGP announcement's origin against a signed authorisation before accepting it, so a more specific prefix announced by the wrong network is dropped instead of winning.
Route Propagation concept Routing & BGP Automatically inserting routes learned from a VPN or dedicated connection into a route table, rather than maintaining them by hand.
Route Table concept Subnetting The set of rules deciding where traffic leaving a subnet is sent, and the thing that actually makes a subnet public or private.
Security Group Firewall Rules, NSG tool Networking A stateful, instance-level firewall that allows specified traffic and denies everything else by default.
Server Name Indication SNI, TLS Host Extension protocol TLS & Certificates The cleartext hostname a client sends in its first TLS message, letting one address serve many certificates and letting a proxy route a session before it decrypts anything.
Server-Sent Events SSE, EventSource protocol WebSockets & Realtime A one-way streaming protocol over plain HTTP in which the server pushes text events to the client on a long-lived response.
Service Mesh Networking concept Service Mesh Networking What a mesh actually does at the network level, the cost per hop, and the shift from sidecar to shared-proxy models.
Source NAT SNAT, Masquerading concept NAT & Egress Rewriting the source address of outbound packets so that many private addresses share one public address, with a translation table mapping replies back.
Stateful Packet Filtering concept Firewalls & Security Groups Filtering that tracks connection state, so return traffic for an allowed outbound connection is permitted automatically.
Subnet concept Networking A subdivision of a network's address range, used as the unit of routing and, in cloud, of availability-zone placement.
Subnet Sizing practice Subnetting Choosing subnet prefix lengths with enough headroom, given that subnets cannot be resized and cloud providers reserve several addresses in each.
Subnetting and Address Planning practice Subnetting Dividing address space across zones and tiers, and the exhaustion failures that appear only at container density.
TCP Handshake protocol TCP/IP The three-way SYN / SYN-ACK / ACK exchange that establishes a TCP connection, costing one round trip before any data moves.
TCP/IP protocol Networking The layered protocol suite underneath essentially all application traffic — IP routes packets, TCP turns them into a reliable ordered stream.
TCP/IP for Architects protocol TCP/IP What an architect actually needs from the transport layer — handshake cost, congestion behaviour, head-of-line blocking, and when to abandon TCP entirely.
TLS Transport Layer Security, SSL protocol Networking The protocol that gives a network connection encryption, integrity and server authentication, underneath HTTPS and most other secure transports.
Traffic Splitting pattern Service Mesh Networking Directing a defined percentage or subset of requests to a different version of a service, configured at the routing layer rather than in application code.
Trust Boundary Classification Where mTLS Is Required, Encryption Scope practice TLS & Certificates Writing down which network segments count as trust boundaries, so that mutual TLS is applied where it changes the security posture rather than uniformly or by intuition.
Virtual Private Cloud VPC, VNet concept Networking A logically isolated network inside a cloud provider, with an address range you control and explicit rules for what may enter and leave.
VPC Design practice VPC Design How virtual networks, subnets and connectivity are structured — decisions that are cheap now and extremely expensive to change later.
VPC Peering concept VPC Design A direct network connection between two VPCs, which is simple, cheap and non-transitive — the last property being the one that shapes topology.
VPN vs Dedicated Connection Direct Connect, ExpressRoute concept Private Connectivity Two ways to link on-premises networks to cloud — an encrypted tunnel over the internet, or a private physical circuit.
WebSocket protocol Networking A protocol that upgrades an HTTP connection into a persistent, full-duplex channel so the server can push to the client without polling.
WebSocket Backplane pattern WebSockets & Realtime A shared publish/subscribe layer letting a message published on one server reach clients connected to a different server.
WebSockets protocol WebSockets & Realtime A persistent bidirectional connection over HTTP — the right tool for server-initiated updates, and a stateful component in an otherwise stateless architecture.
X-Forwarded-For Forwarded Header concept Reverse Proxies The header chain recording original client addresses through a series of proxies — and a value that must never be trusted without knowing the topology.