Web & Networking › TLS & Certificates
TLS Termination
Decrypting TLS at a load balancer or proxy in front of your app.
Also known as: tls termination, ssl termination, terminating tls
TLS termination ends the encrypted connection at the edge — load balancer, CDN, ingress, reverse proxy — and forwards plain HTTP to backends inside the private network. The edge holds the certificates and pays the handshake cost; backends stay simple and fast.
client ═TLS═▶ edge (decrypt) ──plain HTTP──▶ app servers (private net)
Variants: termination with re-encryption (edge→backend over a second TLS connection — still authenticated, still private), and passthrough (encrypted bytes forwarded untouched; the backend holds the certs and the edge can’t inspect). Most setups terminate at the edge and optionally re-encrypt behind it.
The classic mistakes:
- Plaintext beyond the edge without thinking. Terminated traffic crossing untrusted networks (another region, a shared fabric) should be re-encrypted. “Inside” is a trust claim — verify it.
- Losing the client’s identity. After termination, the backend sees the edge’s connection; original IP, protocol and host must be forwarded explicitly (
X-Forwarded-*, PROXY protocol) and the app must be configured to trust only the edge’s headers. - Trusting forwarded headers from anyone. If backends accept
X-Forwarded-Protofrom arbitrary clients, attackers spoof “https” and IPs. Strip and set these headers at the edge. - Certs only at the edge, forgotten behind. Re-encryption needs valid backend certs too — with their own expiry and renewal. Or terminate honestly and keep the backend network genuinely private.
- Passthrough when you need inspection. A WAF or L7 router can’t see inside passthrough TLS. Choose termination where the edge must route, filter or cache.
- Session and SNI assumptions. Passthrough preserves SNI routing naturally; termination must re-derive routing from the decrypted request. Know which your edge does.
How to decide: terminate at the trust boundary (the edge you control), re-encrypt across anything you don’t fully trust, forward client context explicitly, and manage certificates at every TLS endpoint — not just the public one.