ConceptsNetworking, domains & TLS
Connection limits
The proxy protects itself with limits on the number of connections and on the time that each one waits.
TLS handshake. The client has 10 seconds to complete the TLS handshake.
1 / 4
The proxy protects itself with connection limits. You cannot change them.
The limits
| Limit | Value |
|---|---|
| Open connections | From the open-file limit, at most 10,000 |
| Connections for each client address | 256 |
| TLS handshake | 10 s |
| First request head, and each next one on an HTTP/1 connection | 30 s |
| Idle connection with no request in progress | 60 s (5 s while the proxy is at its connection limit) |
| Pause in a request body | 60 s, then 408 |
A timeout of the proxy never cuts an answer in progress. See WebSockets, SSE and HTTP/2.
- At startup,
ferrydraises its soft open-file limit to the hard limit. - An IPv6 client counts as its /64.
- Loopback clients are exempt from the limit for each client address.