Term Kind Topic What it is
Anycast concept Networking Advertising the same IP address from many locations, so the network routes each client to the topologically nearest one.
Anycast Routing protocol Routing & BGP Announcing the same IP address from many locations so that network routing delivers each client to the topologically nearest one.
Bandwidth-Delay Product concept Network Performance Bandwidth multiplied by round-trip time — the amount of data that must be in flight to keep a link fully utilised.
BGP Border Gateway Protocol protocol Routing & BGP The protocol by which autonomous systems advertise which address ranges they can reach, determining how traffic finds any destination on the internet.
Cache Key Completeness practice Reverse Proxies The requirement that a cache key capture every input varying the response - the property whose violation turns a caching bug into a data leak.
Cache-Control protocol Content Delivery Networks The HTTP header directing how a response may be cached and for how long, by browsers, proxies and CDNs.
Certificate Chain Chain of Trust concept TLS & Certificates The sequence from a server's certificate through one or more intermediate CAs to a root the client already trusts.
Certificate Lifecycle Management practice TLS & Certificates Issuing, deploying, monitoring and renewing certificates automatically, because manual tracking reliably produces outages.
CIDR Planning practice VPC Design Allocating non-overlapping address ranges across an estate in advance, because ranges cannot be resized and overlaps prevent connectivity.
Connection Fan-In Ephemeral Client Problem, Serverless Connection Storm concept Network Performance The problem created when many short-lived compute instances each require a connection to a stateful dependency that can only support a small number - and the intermediary pattern that resolves it.
Connection Migration Session Continuity, Seamless Handover concept WebSockets & Realtime Keeping a logical session alive when the underlying network path changes - either in the transport, or reconstructed by the application after a reconnect.
Content Delivery Network CDN tool Networking A geographically distributed cache that serves content from a location near the user instead of from the origin.
Content Pre-Positioning Proactive Fill, Push CDN, Predictive Caching pattern Content Delivery Networks Pushing predicted-demand content to edge caches during off-peak hours rather than fetching it on first request, converting an unpredictable peak-time origin fetch into a scheduled transfer when capacity is free.
Content Purge Path Takedown Propagation, Cache Purge SLA practice Content Delivery Networks A separate, fast, fail-closed mechanism for removing content from every cache tier, which is what allows long TTLs everywhere else without making removal impossible.
Cost-Weighted Rate Limiting Compute Units, Weighted Quotas pattern API Gateways Limiting callers by the resources their requests consume rather than by request count, because on any API where request cost varies by orders of magnitude, counting requests protects nothing.
Data Plane Proxy Envoy, Sidecar Proxy concept Service Mesh Networking The per-workload proxy that actually carries mesh traffic, applying mTLS, retries, timeouts, routing and telemetry outside the application.
Default Deny practice Firewalls & Security Groups A firewall posture in which nothing is permitted unless explicitly allowed, as opposed to blocking known-bad traffic.
DNS Domain Name System protocol Networking The distributed directory that resolves names to addresses, and a surprisingly load-bearing part of most architectures.
DNS Resolution Chain concept DNS The sequence of lookups from browser cache through OS cache, recursive resolver, root, TLD and authoritative server that turns a name into an address.
DNS TTL concept DNS The time a DNS record may be cached, and a value that resolvers, operating systems and applications honour inconsistently.
DNS TTL Strategy practice DNS Choosing record lifetimes to balance failover speed against query volume, knowing that resolvers and clients do not reliably honour them.
ECMP Flow Pinning Flow Hashing, Per-Flow Path Selection concept Network Performance Because a router picks one of several equal-cost paths by hashing a flow's five-tuple, one connection is confined to one link, so aggregate capacity is never per-connection capacity.
Fan-Out Amplification Broadcast Multiplication, Subscriber Amplification concept WebSockets & Realtime The property that one input event becomes as many output events as there are subscribers, making the workload proportional to audience size rather than to event rate - and the reason broadcast paths cannot sha…
Firewalls and Security Groups concept Firewalls & Security Groups Network-level access control, its real value as a second layer, and why the perimeter model stopped being sufficient.
Flow Logs tool Network Troubleshooting Records of accepted and rejected network connections, giving a queryable history of what actually talked to what.
Gateway Offloading pattern API Gateways Moving cross-cutting concerns — TLS termination, authentication, rate limiting, compression, logging — from every service into the gateway.
Gateway Timeout Chain concept API Gateways The sequence of timeouts from client through load balancer, gateway and service, which must decrease inward or produce confusing failures.
Global Map Serving: Precomputed Tiles at Planet Scale Map Tiles, Tile Pyramid case-study Content Delivery Networks Rendering a map view on demand is impossible at global scale, so the world is precomputed into a pyramid of cacheable tiles addressed by coordinate and zoom.
gRPC as a Transport protocol gRPC Transport A binary contract-first RPC protocol over HTTP/2 — efficient and strongly typed for internal service-to-service calls, awkward at the browser edge.
gRPC Streaming concept gRPC Transport Four call patterns — unary, server streaming, client streaming and bidirectional — built on HTTP/2 streams.
Happy Eyeballs Connection Racing, Dual-Stack Attempt Ordering protocol Networking Starting a second connection attempt on the other address family a few hundred milliseconds after the first, so a broken IPv6 or IPv4 path costs the user a short delay instead of a connection timeout.
Head-of-Line Blocking concept HTTP/1.1, HTTP/2 & HTTP/3 One delayed item stalling everything queued behind it, even when the rest could have been processed - the failure mode that ordering guarantees create.
Health Check Configuration concept Layer 4 vs Layer 7 The interval, timeout, and healthy/unhealthy thresholds that together determine how quickly a failed backend leaves rotation.
HTTP Protocol Versions HTTP/1.1, HTTP/2, HTTP/3, QUIC protocol HTTP/1.1, HTTP/2 & HTTP/3 What each HTTP version changed, which problem it solved, and where the benefit actually shows up.
HTTP/2 Multiplexing protocol HTTP/1.1, HTTP/2 & HTTP/3 Carrying many concurrent request/response streams over a single TCP connection, removing the need for multiple connections per origin.
Idle Connection Race Keep-Alive Race, Idle Pool Reset concept HTTP/1.1, HTTP/2 & HTTP/3 The unavoidable window where a server closes a pooled connection just as a client sends a request on it, producing a small error floor that is worst when traffic is lightest.
Invisible Resource Exhaustion Silent Limit, Unattributed Failure concept NAT & Egress A class of failure where a shared finite resource outside the application's view is exhausted, producing intermittent unexplained errors while every local metric looks healthy.
Layer 4 vs Layer 7 Load Balancing concept Networking Balancing on connection metadata (IP and port) versus on the content of the request (path, host, headers).
Load Balancer Types concept Layer 4 vs Layer 7 Layer 4 against layer 7, the algorithms that distribute requests, and why "least connections" is usually better than round robin.
Load Balancing Algorithm concept Layer 4 vs Layer 7 The rule deciding which backend receives a request — round robin, least connections, least response time, or hash-based.
Meta 2021: The Outage That Locked Out Its Own Engineers Facebook October 2021 Outage case-study Routing & BGP A backbone configuration command withdrew Facebook's BGP routes globally, and the tools needed to fix it depended on the network that had just disappeared.
Mutual TLS mTLS, Client Certificate Authentication protocol TLS & Certificates TLS in which both ends present certificates, so the server authenticates the client cryptographically rather than by a shared secret.
NAT Gateway Network Address Translation tool Networking A managed device that lets instances in a private subnet make outbound connections without being reachable inbound.
NAT Gateways tool NAT & Egress The component that lets private instances reach the internet, and one of the most reliably surprising line items on a cloud bill.
Netflix Open Connect case-study Networking Netflix built its own CDN and placed appliances inside ISP networks, turning the most expensive part of its cost structure into hardware it controls.
Network API Gateways tool API Gateways The ingress component that terminates external connections and routes into the estate — considered from the network rather than the API-management angle.
Network Performance concept Network Performance Latency is bounded by physics and bandwidth is bought — so architectural performance work is mostly about reducing round trips and moving data closer.
Origin Shield Shield Tier, Mid-Tier Cache, Request Collapsing Tier pattern Reverse Proxies An intermediate caching tier between edge caches and the origin that collapses many simultaneous misses into a single origin fetch - which is what makes multi-CDN and live streaming survivable for the origin.
Origin Shield Parent Cache, Mid-Tier Cache practice Content Delivery Networks An intermediate cache tier between edge locations and origin, so that hundreds of simultaneous edge misses become a handful of origin requests.
Path MTU Discovery PMTUD concept Network Troubleshooting The mechanism by which a sender discovers the largest packet size a path supports, and a common cause of connections that establish and then hang.
Path MTU Discovery Failure MTU Black Hole, PMTUD Blackhole concept Network Troubleshooting Large packets silently discarded because the ICMP messages that would report the size limit are blocked - producing the signature "small requests work, large transfers hang".
Port Exhaustion concept NAT & Egress Running out of available source ports for outbound connections through a NAT device, causing new connections to fail while everything appears healthy.
Private Connectivity PrivateLink, Private Endpoint, Service Endpoint concept Private Connectivity Reaching a cloud or partner service over private address space rather than the public internet, without exposing the consumer's network in return.
Private Endpoint PrivateLink, VPC Endpoint concept Private Connectivity A private network address inside your VPC that reaches a managed service directly, without traversing the internet or a NAT gateway.
Progressive Media Materialisation Lazy Transcoding, On-Demand Rendition pattern Content Delivery Networks Generating only a baseline media rendition on upload and producing higher-quality variants on first demand - trading a slower first view of unpopular content for a large reduction in transcoding and storage cost.
Protocol Buffers Protobuf protocol gRPC Transport A binary serialisation format with a schema definition language, generating typed code and enforcing explicit compatibility rules through field numbering.
Proxy Buffering concept Reverse Proxies Whether a reverse proxy accumulates a response before forwarding it, which protects the backend from slow clients but breaks streaming.
QUIC HTTP/3 protocol HTTP/1.1, HTTP/2 & HTTP/3 A transport built on UDP that provides streams, encryption and congestion control, removing TCP's head-of-line blocking and reducing connection setup latency.
Reconnect Storm Thundering Herd on Reconnect, Connection Stampede, Recovery Amplification concept WebSockets & Realtime The synchronised burst of clients re-establishing connections after a disruption, which is far more expensive than steady-state traffic and routinely turns a brief network fault into a prolonged self-sustainin…
Reverse Proxy pattern Networking A server that receives client requests on behalf of one or more backends, forwarding them and returning the response.