TEDs are reachable over IPv6. Use the Load balancing when a client or network lacks IPv6 connectivity, or when a service running on TEDs requires load balancing. Load balancing operates at Layer 4: connections are proxied, but TLS is never terminated, so payloads stay end-to-end encrypted between client and TED.
SSH Proxy
An SSH proxy can provide an IPv4 endpoint that forwards traffic to port 22 of a TED.
- Open a TED and select the Network tab.
- Under SSH Proxy Access, click Proxy SSH.
- Copy the connection command shown, for example:
ssh -p <proxy-port> linux@<proxy-ipv4>The proxy port remains assigned until the proxy is removed. Traffic is forwarded at the TCP level, so the TED host key and the SSH session remain end-to-end encrypted.
Load Balancing
Load balancing distributes traffic across one or more TEDs in round robin and provides each rule with an IPv4 and an IPv6 frontend. A rule with a single TED functions as a plain proxy, which is the simplest way to publish a service to clients without IPv6.
- Open Load Balancing in the project sidebar.
- Click Create LB Endpoint and choose the type.
- Select the TEDs to balance across and enter the backend port on which the service listens.
- Click Create. The frontend port and addresses are shown once the rule is created.
Enable Proxy Protocol if the backend service requires original client address and is configured to use proxy protocol v2.
TCP vs SNI
Both types operate on TCP. A TCP rule is protocol agnostic: it forwards a whole frontend port to the backends. An SNI rule expects TLS clients and routes each connection by the domain it requests in the TLS handshake, which allows several domains to share one frontend. Neither type terminates TLS.
Authorizing an SNI Domain
An SNI rule only serves traffic for a domain that has been verified as controlled by the project. To authorize, a CNAME record must be added in the DNS zone of the domain, at the DNS provider or registrar where the domain is managed, and point to the project target:
app.example.com. IN CNAME <project-id>.<verification-suffix>.The exact record is shown in the create dialog and can be copied directly.
Apex domains such as
example.comcannot have a CNAME record. Use a subdomain.