---
title: "Traffic, APIs, and global entry"
chapter: "10"
---

# Traffic, APIs, and global entry

Separate global edge traffic, VPC load balancing, Kubernetes routing, and
service-to-service communication.

## Outside to inside

Route 53 answers DNS. CloudFront can cache and protect global HTTP delivery. AWS
WAF filters supported HTTP traffic and AWS Shield helps with DDoS protection.
ACM provides certificates for supported endpoints.

The AWS Load Balancer Controller creates:

- Application Load Balancers for Layer 7 HTTP/HTTPS routing.
- Network Load Balancers for high-performance Layer 4 TCP/UDP/TLS patterns.

Gateway API gives role-oriented Kubernetes routing when supported by the chosen
controller. Services provide stable discovery inside the cluster.

## Inside the platform

Use timeouts, bounded retries with jitter, circuit breaking, idempotency, and
graceful degradation. A service mesh can add traffic policy, workload identity,
and telemetry, but it also adds proxies, upgrades, latency, cost, and a new
failure surface. Adopt one only for a named requirement.

## Hybrid and SaaS integration

Use Direct Connect or VPN for designed private hybrid connectivity. Use queues
and events to protect slow ERP systems. Use PrivateLink for private service
consumption without broad network routing. Never make a user request wait
indefinitely for SAP, Salesforce, or Workday.

## Feynman check

DNS tells visitors which building. The load balancer chooses a healthy door.
The Kubernetes Service finds the right workers. Timeouts stop one slow room
from trapping everyone.
