SVCB and ECH change ingress proof: resolvers read HTTPS RR before connect, while ECH hides the inner ClientHello. If dashboards merge classic SNI with ECH branches, TLS handshake p95 lies during rollout.

Companion to the Halo global ingress series: Happy Eyeballs and QUIC p95, MSS and BBR, GeoDNS matrix, split-horizon, Worker SSH routing. See pricing for PoPs that match your probes.

1) Ignored HTTPS RR priority ships the wrong PoP quietly. 2) Fast ECH key rotation beats cache, so hello shapes flap. 3) GeoDNS stickiness pins warm A records while SVCB still points at a cold canary.

Signal Primary owner Threshold to gate promotion
SVCB parse errors DNS platform plus resolver canaries < 0.5% errors for 24 h on each public resolver tier you support
ECH retry rate Edge TLS termination team < 1% retries for 15 min after config publish; rollback if above 3%
Classic SNI fallback share Client telemetry library Document expected share per region; alert on week-over-week jumps > 8 pts
GeoDNS stickiness drift Traffic steering plus TTL policy < 20% clients remain on failed PoP past two TTL windows

Synthetic clients should log resolver identity, ECH offer acceptance, inner hello success, and negotiated ALPN. Join those fields with GeoDNS steering bits in one store so reviewers separate DNS drift from edge regressions during SVCB edits without rebuilding notebooks weekly.

TLS handshake p95 acceptance: HTTPS h2 versus ECH paths

Split h2 ALPN and ECH-first handshakes into separate histograms from DNS done through ServerHello. Probes must log ECH versus classic SNI branches and tag JP, KR, HK, SG, and US West separately. Keep a control name without SVCB; pause priority bumps when experiment minus control p95 exceeds 40 ms for three canary windows.

Regional routing and GeoDNS stickiness for SVCB answers

Steer A/AAAA and HTTPS RR from one health feed. Mismatch plus long TTL is the usual phantom TLS p95 spike. Use 300 s laptops, 60 s CI, 30 s split-horizon internals; lower TTL on bots first during incidents; restore only after two green probe cycles per metro.

Failover FAQ: ECH probes, SVCB rollback, and classic SNI

Q: Prove SVCB pre-launch? A: Resolver-aware checks in JP, KR, HK, SG, US West; compare priority and target to legacy A; block release on mismatch.

Q: Rollback order? A: Drop SVCB priority first, delete HTTPS RR only after twelve quiet hours, keep ECH keys warm one more day.

Q: When is SNI fine? A: Keep it warm for stripped ECH; require fallback within one RTT of regional ECH median and zero SAN spikes.

Parameter table for TLS handshake p95 sign-off

Owner every row; sample hundreds of handshakes per region daily during SVCB or ECH changes.

Parameter Start Gate
HTTPS RR TTL 300 s prod; 120 s change Cache refreshes before second key roll
ECH publish budget < 5 min P99 to all edges No stale configs in business hours
h2 ALPN timeout Vendor default then trim Stable h2 p95 when UDP unused
Synthetic interval 30 s dual vantage per metro SVCB skew before tickets
Tip: SSH bastion hygiene from the Halo series still gates control-plane latency; TLS privacy does not replace it.
# Example: fetch HTTPS RR (replace name and resolver)
dig @1.1.1.1 HTTPS api.example +noall +answer
# Compare against A/AAAA and log priority, target, and ech= hints separately.

JP, KR, HK, SG, US West: TLS handshake p95 rows (h2 vs ECH branch)

Internal targets for artifact HTTPS on global entry; split h2 versus ECH columns when you report.

PoP h2 TLS p95 ECH p95 Note
JP < 95 ms < 110 ms US-bounced resolvers inflate both
KR < 90 ms < 115 ms Mobile adds resolver hop
HK < 85 ms < 105 ms Split guest vs office DNS
SG < 100 ms < 125 ms SEA hub defaults
US West < 110 ms < 135 ms Tag APAC VPN hairpins

Five rollout steps for SVCB and ECH together

  • 1 Shadow HTTPS RR; watch resolver errors per metro.
  • 2 Canary ECH only; chart inner hello success versus SNI fallback.
  • 3 Tie GeoDNS health to SVCB targets to kill bad stickiness.
  • 4 Split p95 dashboards by h2 and ECH for JP, KR, HK, SG, US West.
  • 5 Rehearse rollback: lower SVCB priority first, denser probes twelve hours post-cut.

Cite in reviews: SVCB parse errors reroute populations silently. Label ECH versus SNI or p95 lies. Roll back SVCB priority before deletes.

Disclaimer: Heuristics for staging sign-off, not SLAs. Crypto export rules are yours to verify.

Charts green? Pick the remote Mac PoP you measured; read help and pricing before widening rollout.

Nodes, regions, and help

Choose a PoP after TLS p95 sign-off

Map handshake results to the same metros vpshalo operates. Open purchase for the default cart, then refine with Tokyo, Seoul, Hong Kong, Singapore, or US West. Read Help for SSH and console guidance tied to your region choice.

Still deciding? Compare plans on pricing and revisit the blog Halo ingress series from the links above.

Select regional node View pricing Help center Global ingress series