The protocol stack
Layers bottom to top
- IP (Layer 3) — addresses and routes packets between hosts; no delivery guarantee.
- TCP / UDP (Layer 4) — transport: reliability vs speed.
- TLS (Layer 4–5) — encryption and identity on top of TCP.
- HTTP/1.1, HTTP/2, HTTP/3 (Layer 7) — request/response semantics for APIs and web.
- WebSocket — full-duplex channel over HTTP upgrade (covered in a later article).
Application │ HTTP GET /api/v1/feed
TLS │ encrypted record
TCP │ segment, port 443
IP │ packet, src → dst
Network stack (StreamHub request)
TCP vs UDP
| Aspect | TCP | UDP |
|---|---|---|
| Delivery | Guaranteed, ordered | Best effort, no order guarantee |
| Connection | 3-way handshake, stateful | Connectionless |
| Overhead | Higher (retransmits, flow control) | Lower latency |
| Use cases | HTTP, APIs, databases | DNS, video streaming, gaming, VoIP |
Delivery
TCPGuaranteed, orderedUDPBest effort, no order guaranteeConnection
TCP3-way handshake, statefulUDPConnectionlessOverhead
TCPHigher (retransmits, flow control)UDPLower latencyUse cases
TCPHTTP, APIs, databasesUDPDNS, video streaming, gaming, VoIP
Default to TCP for APIs; choose UDP when loss is acceptable and latency dominates.
StreamHub uses TCP for all API traffic and metadata. Live low-latency preview streams experiment with UDP-based protocols (WebRTC) where occasional frame loss is acceptable.
HTTP versions
| Version | Key trait | Impact |
|---|---|---|
| HTTP/1.1 | One request per connection (without pipelining) | Many connections needed; head-of-line blocking |
| HTTP/2 | Multiplexed streams on one TCP connection | Fewer connections; better for asset-heavy pages |
| HTTP/3 | QUIC over UDP | Faster handshake, no TCP head-of-line blocking |
HTTP/1.1
Key traitOne request per connection (without pipelining)ImpactMany connections needed; head-of-line blockingHTTP/2
Key traitMultiplexed streams on one TCP connectionImpactFewer connections; better for asset-heavy pagesHTTP/3
Key traitQUIC over UDPImpactFaster handshake, no TCP head-of-line blocking
GET /api/v1/videos/v_9182 HTTP/2
Host: api.streamhub.com
Accept: application/json
Authorization: Bearer eyJhbG...
HTTP/2 200
content-type: application/json
cache-control: max-age=60
{"id":"v_9182","title":"Sunset timelapse","duration_sec":142}
TLS essentials
TLS provides confidentiality, integrity, and server authentication via certificates.
TLS in system design
- HTTPS everywhere — terminate TLS at LB or reverse proxy; internal mesh may use mTLS.
- Handshake cost — 1–2 RTT; mitigate with HTTP/2 connection reuse and TLS session resumption.
- Certificate management — Let's Encrypt, ACM; automate renewal.
- TLS 1.2+ — disable legacy ciphers in production.
# Inspect certificate chain
openssl s_client -connect api.streamhub.com:443 -servername api.streamhub.com </dev/null 2>/dev/null | openssl x509 -noout -dates -subject
Connection lifecycle and latency
Each new TCP + TLS connection costs round trips. At scale:
- Keep-alive — reuse connections from client pools.
- Connection pooling — app → database pools (PgBouncer, HikariCP).
- Edge termination — CDN/LB handles TLS close to users.
# NGINX keepalive toward upstream app servers
upstream streamhub_api {
server app-1:8080;
server app-2:8080;
keepalive 32;
}
Three round trips (TCP + TLS) before the first byte of HTTP can dominate p99 for small API responses.
Ports and firewalls
| Port | Protocol | Typical use |
|---|---|---|
| 80 | HTTP | Redirect to 443 or internal only |
| 443 | HTTPS | Public APIs and web |
| 5432 | TCP | Postgres (internal VPC only) |
| 6379 | TCP | Redis (internal, AUTH required) |
80
ProtocolHTTPTypical useRedirect to 443 or internal only443
ProtocolHTTPSTypical usePublic APIs and web5432
ProtocolTCPTypical usePostgres (internal VPC only)6379
ProtocolTCPTypical useRedis (internal, AUTH required)
Security groups and network ACLs restrict which ports are reachable from the internet vs internal subnets only.
Protocol choice for APIs
For REST/JSON APIs over the public internet: HTTPS on TCP (HTTP/2 or HTTP/3). gRPC uses HTTP/2 with protobuf — better for internal service mesh, less browser-friendly.
Quick recall
Everything you need if you only revisit this box.
- IP routes packets; TCP delivers reliably; UDP is faster but lossy.
- HTTP/2 multiplexes streams; HTTP/3 uses QUIC over UDP.
- TLS adds encryption and handshake cost — reuse connections and terminate at the edge.
- Connection pooling reduces per-request setup overhead for APIs and databases.
- Default public APIs to HTTPS; restrict database ports to internal networks.
- Protocol choice follows latency, reliability, and client constraints.
Test yourself
Answer these before moving on — recall is what makes it stick.