Tracium
v1.2 Telemetry

Edge Proxy & DNS Configuration

Route production traffic through Tracium's Anycast edge proxy for automated bot classification, TLS 1.3 termination, and transparent origin pass-through.

Cloudflare for SaaS EngineTLS 1.3 / HTTP/3Anycast 330+ PoPsTransparent Proxying

Edge Request Lifecycle & Routing

The Tracium Edge Proxy is deployed across Cloudflare’s global Anycast edge network (330+ points of presence). When production traffic resolves to proxy.tracium.dev, the L7 proxy worker executes an asynchronous wire inspection routine:

  1. TLS Handshake: Terminates TLS 1.3 / ALPN negotiation at the edge node closest to the client.
  2. Signature Inspection: Evaluates incoming headers (User-Agent, Sec-CH-UA, Accept, CF-IPCountry, CF-Connecting-IP).
  3. Async Telemetry Emission: Asynchronously batches connection metadata to Tracium’s ingest cluster without blocking the socket.
  4. Transparent Origin Pass-Through: Multiplexes the request over HTTP/2 to your configured origin host with real client IP preservation.

DNS Record Specifications

Configure an authoritative DNS CNAME in your zone management provider (Cloudflare, AWS Route 53, Google Cloud DNS, Namecheap, Vercel):

Record TypeHostnameRDATA / ValueTTLProxy Mode
CNAMEwww (or app)proxy.tracium.devAuto / 300sDNS Only (Gray Cloud)
ALIAS / ANAME@ (zone apex)proxy.tracium.devAuto / 300sDNS Flattened
Cloudflare Zone Flattening & Gray CloudSecurity Advisory
If your authoritative DNS zone is hosted on Cloudflare, the CNAME record must have Cloudflare Proxying set to Disabled (DNS Only / Gray Cloud). Tracium operates its own enterprise SSL termination and DDoS mitigation pipeline via Cloudflare for SaaS Custom Hostnames.

Automated TLS 1.3 & Certificate Issuance

Custom domains routing to Tracium are automatically enrolled in Cloudflare’s SSL for SaaS pipeline. Certificate issuance is orchestrated through Google Trust Services and Let's Encrypt:

  • Protocols: TLS 1.2, TLS 1.3, HTTP/2, HTTP/3 (QUIC)
  • Ciphers: Modern AEAD ciphers (AES-128-GCM, CHACHA20-POLY1305)
  • Validation: Automatic HTTP-01 / SNI certificate validation with 0 manual intervention
  • Renewal: Zero-downtime automated certificate rotation 30 days prior to expiration

Header Forwarding & Wire Transparency

The edge proxy operates in strict transparent proxy mode. Upstream origin servers receive unmodified payloads and the following authoritative identification headers:

Field / AttributeWire TypeConstraintTechnical Description
CF-Connecting-IPIPv4 / IPv6REQUIREDThe authoritative client IP address connecting to the Cloudflare edge.
X-Forwarded-ForstringREQUIREDStandard proxy chain header containing client and intermediate proxy IP addresses.
CF-IPCountryISO 3166-1 alpha-2REQUIREDTwo-letter country code resolved from client IP geolocation database.
X-Tracium-Bot-Scoreinteger (0-100)OPTIONALCalculated edge crawler probability score appended to upstream request.