How a request travels from client to app pod through the NGINX + ModSecurity WAF, F5 Big-IP L4 passthrough, and OpenShift routers — and where each TLS leg terminates. Click any node for detail, or isolate a single flow below.
End user • oc CLI
*.apps resolution
OWASP CRS • 850 rules
TLS terminate & re-encrypt
modsec_audit.log
RelevantOnly • logrotate 14d
Layer 4 Passthrough
TCP forward only
Layer 4 Passthrough
Control-plane traffic
haproxy
haproxy
console • oauth
monitoring • downloads
kube-apiserver • 3x control plane