sni_router
Routes TCP connections by SNI hostname.
On this page
Routes TCP connections by SNI hostname.
Configuration Notes
Performs exact-match lookup first, then longest-suffix wildcard match. Case-insensitive per RFC 4343.
Connections without SNI or with no matching route use default_upstream if configured, otherwise receive a TLS alert rejection.
Bare wildcards (*), IP addresses as server names, and duplicate server names across routes are rejected at config validation.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
default_upstream | string | no | Fallback upstream when no route matches. |
routes | SniRouteEntry[] | yes | Route entries mapping server names to upstreams. |
routes[].server_names | string[] | yes | Server name patterns (exact or wildcard like *.example.com). |
routes[].upstream | string | yes | Upstream address for matching connections. |
Example
filter: sni_router
routes:
- server_names: ["api.example.com"]
upstream: "10.0.0.1:443"
- server_names: ["*.example.com"]
upstream: "10.0.0.2:443"
default_upstream: "10.0.0.3:443"