- Router (
svc/frontline/internal/router). - Proxy handler (
svc/frontline/routes/proxy).
Flow: route request
Routing decisions
- Frontline looks up the route by FQDN in the database and parses the deployment’s policies.
- If the deployment has a running instance in the current region, it proxies locally, trying instances in shuffled order.
- If not, it selects the nearest region with a running instance using the region proximity list.
Cross-region forwarding
When forwarding to another region, Frontline targets:Hop limits
Frontline enforces a maximum hop count to prevent routing loops. When theX-Unkey-Frontline-Hops header reaches max_hops, the request is rejected.
Hop header: X-Unkey-Frontline-Hops.
TLS certificate selection
Frontline selects TLS certificates per SNI. It attempts an exact hostname match first, then falls back to the immediate wildcard (for example*.example.com). If no certificate is found, the TLS handshake falls back to a default certificate.