Terminology
2185 terms, tools, patterns and metrics an architect is expected to use precisely. Each one gets a short explanation of what it is, and — where it matters — what it is commonly confused with. Search filters as you type; the column headers sort.
All areas2185
Architecture Fundamentals77
Distributed Systems107
Data Architecture110
Cloud Architecture89
Networking88
API & Integration Architecture82
Reliability & Resilience75
Observability70
Performance & Capacity Engineering72
Security Architecture81
Cost Architecture & FinOps66
Business Architecture67
Architecture Communication67
Enterprise Architecture66
Legacy Modernization66
AI-Era Architecture69
Software Architecture & Engineering71
Architecture Patterns71
Architecture Decision-Making63
The Architect's Meta-Skills61
Delivery & Release Engineering66
Platform Engineering & Developer Experience70
Testing & Quality Architecture66
Data Platform Architecture64
Streaming & Real-Time Data69
Data Governance & Semantics69
Frontend & Experience Architecture66
Edge, Mobile & IoT68
Regulatory & Data Protection Architecture65
Assurance, Audit & Model Risk64
88 terms shown.
| Term | Kind | Topic | What it is |
|---|---|---|---|
| Anycast | concept | Networking | Advertising the same IP address from many locations, so the network routes each client to the topologically nearest one. |
| Anycast Routing | protocol | Routing & BGP | Announcing the same IP address from many locations so that network routing delivers each client to the topologically nearest one. |
| Bandwidth-Delay Product | concept | Network Performance | Bandwidth multiplied by round-trip time — the amount of data that must be in flight to keep a link fully utilised. |
| BGP Border Gateway Protocol | protocol | Routing & BGP | The protocol by which autonomous systems advertise which address ranges they can reach, determining how traffic finds any destination on the internet. |
| Cache Key Completeness | practice | Reverse Proxies | The requirement that a cache key capture every input varying the response - the property whose violation turns a caching bug into a data leak. |
| Cache-Control | protocol | Content Delivery Networks | The HTTP header directing how a response may be cached and for how long, by browsers, proxies and CDNs. |
| Certificate Chain Chain of Trust | concept | TLS & Certificates | The sequence from a server's certificate through one or more intermediate CAs to a root the client already trusts. |
| Certificate Lifecycle Management | practice | TLS & Certificates | Issuing, deploying, monitoring and renewing certificates automatically, because manual tracking reliably produces outages. |
| CIDR Planning | practice | VPC Design | Allocating non-overlapping address ranges across an estate in advance, because ranges cannot be resized and overlaps prevent connectivity. |
| Connection Fan-In Ephemeral Client Problem, Serverless Connection Storm | concept | Network Performance | The problem created when many short-lived compute instances each require a connection to a stateful dependency that can only support a small number - and the intermediary pattern that resolves it. |
| Connection Migration Session Continuity, Seamless Handover | concept | WebSockets & Realtime | Keeping a logical session alive when the underlying network path changes - either in the transport, or reconstructed by the application after a reconnect. |
| Content Delivery Network CDN | tool | Networking | A geographically distributed cache that serves content from a location near the user instead of from the origin. |
| Content Pre-Positioning Proactive Fill, Push CDN, Predictive Caching | pattern | Content Delivery Networks | Pushing predicted-demand content to edge caches during off-peak hours rather than fetching it on first request, converting an unpredictable peak-time origin fetch into a scheduled transfer when capacity is free. |
| Content Purge Path Takedown Propagation, Cache Purge SLA | practice | Content Delivery Networks | A separate, fast, fail-closed mechanism for removing content from every cache tier, which is what allows long TTLs everywhere else without making removal impossible. |
| Cost-Weighted Rate Limiting Compute Units, Weighted Quotas | pattern | API Gateways | Limiting callers by the resources their requests consume rather than by request count, because on any API where request cost varies by orders of magnitude, counting requests protects nothing. |
| Data Plane Proxy Envoy, Sidecar Proxy | concept | Service Mesh Networking | The per-workload proxy that actually carries mesh traffic, applying mTLS, retries, timeouts, routing and telemetry outside the application. |
| Default Deny | practice | Firewalls & Security Groups | A firewall posture in which nothing is permitted unless explicitly allowed, as opposed to blocking known-bad traffic. |
| DNS Domain Name System | protocol | Networking | The distributed directory that resolves names to addresses, and a surprisingly load-bearing part of most architectures. |
| DNS Resolution Chain | concept | DNS | The sequence of lookups from browser cache through OS cache, recursive resolver, root, TLD and authoritative server that turns a name into an address. |
| DNS TTL | concept | DNS | The time a DNS record may be cached, and a value that resolvers, operating systems and applications honour inconsistently. |
| DNS TTL Strategy | practice | DNS | Choosing record lifetimes to balance failover speed against query volume, knowing that resolvers and clients do not reliably honour them. |
| ECMP Flow Pinning Flow Hashing, Per-Flow Path Selection | concept | Network Performance | Because a router picks one of several equal-cost paths by hashing a flow's five-tuple, one connection is confined to one link, so aggregate capacity is never per-connection capacity. |
| Fan-Out Amplification Broadcast Multiplication, Subscriber Amplification | concept | WebSockets & Realtime | The property that one input event becomes as many output events as there are subscribers, making the workload proportional to audience size rather than to event rate - and the reason broadcast paths cannot sha… |
| Firewalls and Security Groups | concept | Firewalls & Security Groups | Network-level access control, its real value as a second layer, and why the perimeter model stopped being sufficient. |
| Flow Logs | tool | Network Troubleshooting | Records of accepted and rejected network connections, giving a queryable history of what actually talked to what. |
| Gateway Offloading | pattern | API Gateways | Moving cross-cutting concerns — TLS termination, authentication, rate limiting, compression, logging — from every service into the gateway. |
| Gateway Timeout Chain | concept | API Gateways | The sequence of timeouts from client through load balancer, gateway and service, which must decrease inward or produce confusing failures. |
| Global Map Serving: Precomputed Tiles at Planet Scale Map Tiles, Tile Pyramid | case-study | Content Delivery Networks | Rendering a map view on demand is impossible at global scale, so the world is precomputed into a pyramid of cacheable tiles addressed by coordinate and zoom. |
| gRPC as a Transport | protocol | gRPC Transport | A binary contract-first RPC protocol over HTTP/2 — efficient and strongly typed for internal service-to-service calls, awkward at the browser edge. |
| gRPC Streaming | concept | gRPC Transport | Four call patterns — unary, server streaming, client streaming and bidirectional — built on HTTP/2 streams. |
| Happy Eyeballs Connection Racing, Dual-Stack Attempt Ordering | protocol | Networking | Starting a second connection attempt on the other address family a few hundred milliseconds after the first, so a broken IPv6 or IPv4 path costs the user a short delay instead of a connection timeout. |
| Head-of-Line Blocking | concept | HTTP/1.1, HTTP/2 & HTTP/3 | One delayed item stalling everything queued behind it, even when the rest could have been processed - the failure mode that ordering guarantees create. |
| Health Check Configuration | concept | Layer 4 vs Layer 7 | The interval, timeout, and healthy/unhealthy thresholds that together determine how quickly a failed backend leaves rotation. |
| HTTP Protocol Versions HTTP/1.1, HTTP/2, HTTP/3, QUIC | protocol | HTTP/1.1, HTTP/2 & HTTP/3 | What each HTTP version changed, which problem it solved, and where the benefit actually shows up. |
| HTTP/2 Multiplexing | protocol | HTTP/1.1, HTTP/2 & HTTP/3 | Carrying many concurrent request/response streams over a single TCP connection, removing the need for multiple connections per origin. |
| Idle Connection Race Keep-Alive Race, Idle Pool Reset | concept | HTTP/1.1, HTTP/2 & HTTP/3 | The unavoidable window where a server closes a pooled connection just as a client sends a request on it, producing a small error floor that is worst when traffic is lightest. |
| Invisible Resource Exhaustion Silent Limit, Unattributed Failure | concept | NAT & Egress | A class of failure where a shared finite resource outside the application's view is exhausted, producing intermittent unexplained errors while every local metric looks healthy. |
| Layer 4 vs Layer 7 Load Balancing | concept | Networking | Balancing on connection metadata (IP and port) versus on the content of the request (path, host, headers). |
| Load Balancer Types | concept | Layer 4 vs Layer 7 | Layer 4 against layer 7, the algorithms that distribute requests, and why "least connections" is usually better than round robin. |
| Load Balancing Algorithm | concept | Layer 4 vs Layer 7 | The rule deciding which backend receives a request — round robin, least connections, least response time, or hash-based. |
| Meta 2021: The Outage That Locked Out Its Own Engineers Facebook October 2021 Outage | case-study | Routing & BGP | A backbone configuration command withdrew Facebook's BGP routes globally, and the tools needed to fix it depended on the network that had just disappeared. |
| Mutual TLS mTLS, Client Certificate Authentication | protocol | TLS & Certificates | TLS in which both ends present certificates, so the server authenticates the client cryptographically rather than by a shared secret. |
| NAT Gateway Network Address Translation | tool | Networking | A managed device that lets instances in a private subnet make outbound connections without being reachable inbound. |
| NAT Gateways | tool | NAT & Egress | The component that lets private instances reach the internet, and one of the most reliably surprising line items on a cloud bill. |
| Netflix Open Connect | case-study | Networking | Netflix built its own CDN and placed appliances inside ISP networks, turning the most expensive part of its cost structure into hardware it controls. |
| Network API Gateways | tool | API Gateways | The ingress component that terminates external connections and routes into the estate — considered from the network rather than the API-management angle. |
| Network Performance | concept | Network Performance | Latency is bounded by physics and bandwidth is bought — so architectural performance work is mostly about reducing round trips and moving data closer. |
| Origin Shield Shield Tier, Mid-Tier Cache, Request Collapsing Tier | pattern | Reverse Proxies | An intermediate caching tier between edge caches and the origin that collapses many simultaneous misses into a single origin fetch - which is what makes multi-CDN and live streaming survivable for the origin. |
| Origin Shield Parent Cache, Mid-Tier Cache | practice | Content Delivery Networks | An intermediate cache tier between edge locations and origin, so that hundreds of simultaneous edge misses become a handful of origin requests. |
| Path MTU Discovery PMTUD | concept | Network Troubleshooting | The mechanism by which a sender discovers the largest packet size a path supports, and a common cause of connections that establish and then hang. |
| Path MTU Discovery Failure MTU Black Hole, PMTUD Blackhole | concept | Network Troubleshooting | Large packets silently discarded because the ICMP messages that would report the size limit are blocked - producing the signature "small requests work, large transfers hang". |
| Port Exhaustion | concept | NAT & Egress | Running out of available source ports for outbound connections through a NAT device, causing new connections to fail while everything appears healthy. |
| Private Connectivity PrivateLink, Private Endpoint, Service Endpoint | concept | Private Connectivity | Reaching a cloud or partner service over private address space rather than the public internet, without exposing the consumer's network in return. |
| Private Endpoint PrivateLink, VPC Endpoint | concept | Private Connectivity | A private network address inside your VPC that reaches a managed service directly, without traversing the internet or a NAT gateway. |
| Progressive Media Materialisation Lazy Transcoding, On-Demand Rendition | pattern | Content Delivery Networks | Generating only a baseline media rendition on upload and producing higher-quality variants on first demand - trading a slower first view of unpopular content for a large reduction in transcoding and storage cost. |
| Protocol Buffers Protobuf | protocol | gRPC Transport | A binary serialisation format with a schema definition language, generating typed code and enforcing explicit compatibility rules through field numbering. |
| Proxy Buffering | concept | Reverse Proxies | Whether a reverse proxy accumulates a response before forwarding it, which protects the backend from slow clients but breaks streaming. |
| QUIC HTTP/3 | protocol | HTTP/1.1, HTTP/2 & HTTP/3 | A transport built on UDP that provides streams, encryption and congestion control, removing TCP's head-of-line blocking and reducing connection setup latency. |
| Reconnect Storm Thundering Herd on Reconnect, Connection Stampede, Recovery Amplification | concept | WebSockets & Realtime | The synchronised burst of clients re-establishing connections after a disruption, which is far more expensive than steady-state traffic and routinely turns a brief network fault into a prolonged self-sustainin… |
| Reverse Proxy | pattern | Networking | A server that receives client requests on behalf of one or more backends, forwarding them and returning the response. |
Nothing on this page matches. Search the whole glossary.