Edge Proxy & DNS Configuration
Route production traffic through Tracium's Anycast edge proxy for automated bot classification, TLS 1.3 termination, and transparent origin pass-through.
Edge Request Lifecycle & Routing
The Tracium Edge Proxy is deployed across Cloudflare’s global Anycast edge network (330+ points of presence). When production traffic resolves to proxy.tracium.dev, the L7 proxy worker executes an asynchronous wire inspection routine:
- TLS Handshake: Terminates TLS 1.3 / ALPN negotiation at the edge node closest to the client.
- Signature Inspection: Evaluates incoming headers (
User-Agent,Sec-CH-UA,Accept,CF-IPCountry,CF-Connecting-IP). - Async Telemetry Emission: Asynchronously batches connection metadata to Tracium’s ingest cluster without blocking the socket.
- Transparent Origin Pass-Through: Multiplexes the request over HTTP/2 to your configured origin host with real client IP preservation.
DNS Record Specifications
Configure an authoritative DNS CNAME in your zone management provider (Cloudflare, AWS Route 53, Google Cloud DNS, Namecheap, Vercel):
| Record Type | Hostname | RDATA / Value | TTL | Proxy Mode |
|---|---|---|---|---|
| CNAME | www (or app) | proxy.tracium.dev | Auto / 300s | DNS Only (Gray Cloud) |
| ALIAS / ANAME | @ (zone apex) | proxy.tracium.dev | Auto / 300s | DNS Flattened |
Automated TLS 1.3 & Certificate Issuance
Custom domains routing to Tracium are automatically enrolled in Cloudflare’s SSL for SaaS pipeline. Certificate issuance is orchestrated through Google Trust Services and Let's Encrypt:
- Protocols: TLS 1.2, TLS 1.3, HTTP/2, HTTP/3 (QUIC)
- Ciphers: Modern AEAD ciphers (AES-128-GCM, CHACHA20-POLY1305)
- Validation: Automatic HTTP-01 / SNI certificate validation with 0 manual intervention
- Renewal: Zero-downtime automated certificate rotation 30 days prior to expiration
Header Forwarding & Wire Transparency
The edge proxy operates in strict transparent proxy mode. Upstream origin servers receive unmodified payloads and the following authoritative identification headers:
| Field / Attribute | Wire Type | Constraint | Technical Description |
|---|---|---|---|
| CF-Connecting-IP | IPv4 / IPv6 | REQUIRED | The authoritative client IP address connecting to the Cloudflare edge. |
| X-Forwarded-For | string | REQUIRED | Standard proxy chain header containing client and intermediate proxy IP addresses. |
| CF-IPCountry | ISO 3166-1 alpha-2 | REQUIRED | Two-letter country code resolved from client IP geolocation database. |
| X-Tracium-Bot-Score | integer (0-100) | OPTIONAL | Calculated edge crawler probability score appended to upstream request. |