M3 · Gateway and ingress
Request path
22 / 61

TLS and Cloud Armor protect the request before it reaches a Pod

The managed frontend terminates TLS, evaluates edge security, chooses a route and forwards only to a healthy NEG endpoint.

1TLS handshakeCertificate Manager proves the Shopwave hostname.
2Cloud ArmorWeb application firewall and rate rules evaluate the request.
3URL mapGateway and HTTPRoute configuration choose the backend.
4Health-aware backendThe load balancer chooses a healthy zonal NEG.
5Podcheckout receives the request on its declared target port.
Edge policy reduces malicious traffic; workload authorization still decides what the caller may do.