sni_router

Routes TCP connections by SNI hostname.
On this page

Routes TCP connections by SNI hostname.

Configuration Notes

Performs exact-match lookup first, then longest-suffix wildcard match. Case-insensitive per RFC 4343.

Connections without SNI or with no matching route use default_upstream if configured, otherwise receive a TLS alert rejection.

Bare wildcards (*), IP addresses as server names, and duplicate server names across routes are rejected at config validation.

Configuration

FieldTypeRequiredDescription
default_upstreamstringnoFallback upstream when no route matches.
routesSniRouteEntry[]yesRoute entries mapping server names to upstreams.
routes[].server_namesstring[]yesServer name patterns (exact or wildcard like *.example.com).
routes[].upstreamstringyesUpstream address for matching connections.

Example

filter: sni_router
routes:
  - server_names: ["api.example.com"]
    upstream: "10.0.0.1:443"
  - server_names: ["*.example.com"]
    upstream: "10.0.0.2:443"
default_upstream: "10.0.0.3:443"