Envoy routing
Strict timeouts, connection limits, health checks and last-known-good configuration.
Cloudflare for SaaS supplies global ingress and volumetric protection. Envoy and Coraza apply service-specific controls without a central database or AI call in the request path.
Each function has a narrow operating boundary and a state derived from evidence.
Strict timeouts, connection limits, health checks and last-known-good configuration.
OWASP CRS runs out of process over a private Unix socket and remains shadow-first.
Bounded metadata enters the case and threat pipelines without delaying the visitor.
The visitor path remains short while control, evidence and rollback stay explicit.
Cloudflare serves eligible static assets before they reach AegiFlow.
Envoy and Coraza make bounded request decisions on the edge host.
The control plane correlates events and proposes reversible action.
Every traffic activation requires ownership, certificate, origin and rollback checks.