Skip to main content
Frontline routes a request by looking up its hostname, selecting a healthy instance of the target deployment, and proxying locally or forwarding to another region. Key components:

Flow: route request

Routing decisions

  • Frontline looks up the route by FQDN in the database and parses the deployment’s policies.
  • If the deployment has a running instance in the current region, it proxies locally, trying instances in shuffled order.
  • If not, it selects the nearest region with a running instance using the region proximity list.

Cross-region forwarding

When forwarding to another region, Frontline targets:
The original hostname is preserved so the remote Frontline can perform TLS termination, policy evaluation, and instance selection.

Hop limits

Frontline enforces a maximum hop count to prevent routing loops. When the X-Unkey-Frontline-Hops header reaches max_hops, the request is rejected. Hop header: X-Unkey-Frontline-Hops.

TLS certificate selection

Frontline selects TLS certificates per SNI. It attempts an exact hostname match first, then falls back to the immediate wildcard (for example *.example.com). If no certificate is found, the TLS handshake falls back to a default certificate.