4 ms·
What do I have to do to support H3 in my app? Is this like TLS, which is terminated by some reverse proxy and the application still just uses http 1? Or does it
by nikeee 2y ago
What do I have to do to support H3 in my app? Is this like TLS, which is terminated by some reverse proxy and the application still just uses http 1? Or does it have to be in the application itself? IIRC H3 requires TLS, so it might be better at the reverse proxy? But do I still get the benefits of H3 if I do that?
- Macha 2y agoSince the connection between your reverse proxy and your application server is probably much more reliable and lower latency than between your user and your reverse proxy, you should still benefit in the typical reverse proxy setup.
- ongy 2y agoThat's how I use it Envoy as TLS terminating reverse proxy, and then locally it does http2.
- theandrewbailey 2y agoNot sure if this could work for you, but I use HAProxy (not for failover, but just as a front end). It terminates TLS and supports http3. I was already using it for http2 (TLS required for that), so enabling http3 involved upgrading and editing the config a little bit. I'm pretty sure the web servers behind it use http1.1 to HAProxy, then HAProxy talks http3 to clients. https://www.haproxy.com/blog/announcing-haproxy-2-6 https://www.haproxy.com/blog/announcing-haproxy-2-6 https://haproxy.debian.net/ https://haproxy.debian.net/ Live example: https://theandrewbailey.com/ https://theandrewbailey.com/
- kdmtctl 2y agoIt will be better with a reverse proxy. Decoupling the app and the ingress is always a good practice when you can afford an extra layer. The app itself is sufficient with HTTP/1.1 if the internal network is secure and performant (which it almost always is a container network nowadays).