skip to content

Networking & Proxy Concepts

The vendor-neutral half of this tree: what a proxy actually does, how traffic gets routed, balanced, secured and kept alive, and what a service mesh buys and costs. Interviewers start here because your answer has to hold whether you run nginx, Envoy, HAProxy or a managed load balancer — every product below is just one implementation of these ideas.

on this pageshow

questions

page 2 of 2

A layer-4 proxy routes incoming HTTPS connections to different backends without ever decrypting them. What information in the TLS ClientHello makes that possible, and which routing decisions remain off the table?

level: middleimportance: nice to knowfreq 40%

basics

~20 s

The ClientHello is sent before encryption begins, so a proxy can read its Server Name Indication and ALPN list — the hostname the client asked for and the protocols it offers — and pick a backend from those. Anything inside the encrypted session, such as the URL path, headers or cookies, stays invisible.

open as a page

A backend instance that a load balancer had ejected is now passing its health checks again and is about to rejoin the pool. Why can handing it an immediate equal share of traffic break it a second time, and what does a slow-start or warm-up ramp do about that?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

A returning instance is cold: empty caches, no warm connection pools, unoptimised runtime. Worse, load-aware algorithms see an idle host as the most attractive target and send it a burst above its fair share. A slow-start ramp raises its weight gradually so it warms under partial load.

open as a page

Why can a request-level (layer 7) proxy retry a failed attempt on a different backend when a connection-level (layer 4) proxy generally cannot, and what must the layer 7 proxy do to make that retry possible?

level: seniorimportance: nice to knowfreq 38%

basics

~20 s

A layer 7 proxy owns the request as a unit — it parsed it, can hold the body, and opened the upstream connection itself — so it can send the same request to another backend before the client sees anything. A layer 4 proxy forwards an uninterpreted byte stream and has kept nothing to resend.

open as a page

Several independent proxies balance to the same backend pool, each using least-connection. Why can one backend still be overwhelmed, and what do power-of-two-choices and latency-aware (EWMA) balancing do about it?

level: seniorimportance: nice to knowfreq 26%

basics

~20 s

Each proxy sees only its own in-flight counts, so all of them can identify the same backend as least loaded and stampede it. Power-of-two-choices samples two backends and takes the better, avoiding the herd; EWMA scores backends by observed latency rather than counts.

open as a page

A load balancer forwards raw TCP without parsing the traffic — or passes an encrypted stream straight through — so there is no request in which to write a forwarded-address header. How does the PROXY protocol get the original client address to the backend, and what must be true on both ends for it to work?

level: seniorimportance: nice to knowfreq 26%

basics

~20 s

The PROXY protocol prepends a short preamble to the forwarded TCP connection, before any application bytes, carrying the original source and destination addresses and ports. Both ends must be configured for it: an unaware backend reads that preamble as application data.

open as a page

Your edge proxy tier carries long-lived connections — WebSockets and gRPC streams that can last hours — and the tier has to be deployed weekly. How would you decide a drain window and a maximum connection lifetime, and what are you trading off?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Connections that never end cannot be waited out, so pick a bounded drain window and cap connection lifetime deliberately. Capping spreads reconnects continuously instead of concentrating them at deploy time; the cost is constant reconnect churn and a hard client-side reconnect requirement.

open as a page

Your platform already gives every service a stable internal DNS name that resolves to a health-checked virtual IP. A team proposes running a dedicated service registry alongside it. How would you decide whether that registry is redundant here or genuinely justified?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Decide by naming the capability the virtual IP structurally cannot provide — off-platform members, instance-aware per-request balancing, or routing metadata. Absent one of those, a second registry mainly adds a second, disagreeing answer to who is healthy.

open as a page

You operate a sidecar-based service mesh across several clusters and dozens of teams, and the control plane supports only a narrow version skew with the proxies. How would you plan and de-risk upgrading the mesh, given that every proxy in the fleet has to change version?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

Because a sidecar's version is fixed when its pod is created, upgrading the mesh means recreating every workload inside a supported skew window. Run two control-plane versions side by side and migrate namespace by namespace on each team's own deploy cadence.

open as a page

showing 31–38 of 38