<!-- llms-explorer concept facts · https://llms-explorer.com/tree/node-js-http-networking/ · pack 2026-09-08 · ~8191 tokens -->

# Node.js HTTP & Networking

> This reference is the networking + HTTP core of Node plus the modern HTTP client:

Parent: [JavaScript and Node.js](https://llms-explorer.com/tree/javascript-and-node-js/) · 17 facets · 94 facts · page: https://llms-explorer.com/tree/node-js-http-networking/

## Overview

- This reference is the networking + HTTP core of Node plus the modern HTTP client: the layered stack from raw TCP/UDP sockets up through HTTP/1.1, HTTP/2, TLS, and the fetch/undici client. It is the "talk to the network correctly and keep the sockets healthy" companion to three siblings that own neighbouring layers: — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#overview)
  - nodejs-backend-frameworks owns the framework layer (Express/Fastify/NestJS/Hono, routing, middleware, framework selection). This file is the primitives those frameworks are built on - http.Server, the Agent, timeouts, TLS. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#overview)
  - nodejs-concurrency-internals owns the libuv event-loop phase model and stream backpressure (highWaterMark, pipe vs pipeline flow control). This file uses streams (request/response bodies are streams) but defers the backpressure mechanics there. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#overview)
  - http-security-headers owns CSP/HSTS/CORS and mTLS hardening posture. This file covers the TLS plumbing (SNI, ALPN, session resumption); the security headers go there. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#overview)
- The mental model has four layers: net/dgram (TCP/UDP sockets) → tls (encryption, SNI, ALPN) → http / http2 / https (framing) → fetch/undici (the high-level pooled, retrying client). Most production incidents here are timeout and socket-pool problems, not protocol problems - so the timeout knobs and Agent/Pool sizing get the most attention below. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#overview)

## 1. `node:http` — server lifecycle, IncomingMessage/ServerResponse, request & Agent

- http.createServer([options][, requestListener]) returns an http.Server. The lifecycle is event-driven, and the events you actually wire up are: — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#1-nodehttp-server-lifecycle-incomingmessageserverresponse-request-agent)
  - 'request' (req, res) - the normal path; req is an IncomingMessage (a readable stream: req.method, req.url, req.headers, req.on('data'|'end')), res is a ServerResponse (a writable stream: res.writeHead(status, headers), res.setHeader, res.getHeader, res.flushHeaders(), res.write, res.end). — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#1-nodehttp-server-lifecycle-incomingmessageserverresponse-request-agent)
  - 'connection' (socket) - a new TCP socket (pre-parse); 'clientError' (err, socket) - malformed request or header overflow. The default clientError handler replies 400 Bad Request, or 431 on HPE_HEADER_OVERFLOW; override it but always check socket.writable and ignore ECONNRESET. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#1-nodehttp-server-lifecycle-incomingmessageserverresponse-request-agent)
  - 'upgrade' (req, socket, head) - protocol upgrade (WebSocket handshake lives here). — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#1-nodehttp-server-lifecycle-incomingmessageserverresponse-request-agent)
- Client side: http.request(options|url[, callback]) returns a writable ClientRequest; http.get is the same but auto-end()s and is GET-only. Key options: hostname/host, port (default 80), method (default GET), path, headers, agent, timeout. Header size is capped by --max-http-header-size (default 16 KiB), readable as http.maxHeaderSize. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#1-nodehttp-server-lifecycle-incomingmessageserverresponse-request-agent)
- The http.Agent manages the socket pool for outbound requests (the default is http.globalAgent, which historically has keepAlive: false). Construct your own to reuse connections. Options and defaults: — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#1-nodehttp-server-lifecycle-incomingmessageserverresponse-request-agent)

## 2. `node:http` — server & socket timeouts (the anti-slowloris knobs)

- These four properties are the most operationally important thing in the module. Misconfigured, they cause hung requests, leaked sockets, and the infamous 502 behind a load balancer: — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#2-nodehttp-server-socket-timeouts-the-anti-slowloris-knobs)
  - server.headersTimeout (default 60000 ms) - max time to receive the complete request headers. Defeats slowloris header-dribbling. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#2-nodehttp-server-socket-timeouts-the-anti-slowloris-knobs)
  - server.requestTimeout (default 300000 ms / 5 min) - max time from socket connect to the full request being received. Defeats slow-body attacks. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#2-nodehttp-server-socket-timeouts-the-anti-slowloris-knobs)
  - server.keepAliveTimeout (default 5000 ms) - how long an idle keep-alive socket stays open between requests. Must be larger than the upstream load-balancer / proxy idle timeout, or the LB reuses a socket Node just closed → ECONNRESET surfaces as a 502. (AWS ALB idle is 60s; set Node's keepAliveTimeout above that.) — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#2-nodehttp-server-socket-timeouts-the-anti-slowloris-knobs)
  - server.maxRequestsPerSocket (default unlimited) - close a keep-alive socket after N requests. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#2-nodehttp-server-socket-timeouts-the-anti-slowloris-knobs)
  - server.timeout (legacy socket inactivity timeout) and server.setTimeout() still exist but the three above are the modern, attack-aware controls. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#2-nodehttp-server-socket-timeouts-the-anti-slowloris-knobs)

## 3. `node:http2` — secure/insecure servers, sessions, streams, ALPN, compatibility API

- http2.createServer() = cleartext h2c (rarely used by browsers); http2.createSecureServer({ key, cert }) = h2 over TLS and the one browsers speak - it advertises ALPN 'h2' automatically. allowHTTP1: true lets a secure server fall back to HTTP/1.1 for non-h2 clients. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#3-nodehttp2-secureinsecure-servers-sessions-streams-alpn-compatibility-api)
- Streams, not connections. A single TCP connection (Http2Session) multiplexes many Http2Streams. Server side: server.on('stream', (stream, headers) => { stream.respond({ ':status': 200 }); stream.end(body); }). Client: http2.connect(authority) returns a ClientHttp2Session; session.request(headers) returns a ClientHttp2Stream that emits 'response'. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#3-nodehttp2-secureinsecure-servers-sessions-streams-alpn-compatibility-api)
- Pseudo-headers (:method, :path, :scheme, :authority, :status) replace the request line. session.settings() tunes initialWindowSize (default 65535), maxConcurrentStreams, enablePush. Sessions emit 'goaway' (graceful shutdown) and 'frameError'. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#3-nodehttp2-secureinsecure-servers-sessions-streams-alpn-compatibility-api)
- Server push (stream.pushStream) is deprecated - RFC 9113 removed it and Chrome/modern browsers no longer support it. Prefer 103 Early Hints (res.writeEarlyHints) for preloading. Stream priority signaling is likewise deprecated. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#3-nodehttp2-secureinsecure-servers-sessions-streams-alpn-compatibility-api)
- Compatibility API: Http2ServerRequest/Http2ServerResponse mimic http's IncomingMessage/ServerResponse so Express-style (req, res) handlers run on h2 with minimal change. respondWithFile/respondWithFD stream a file/FD directly. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#3-nodehttp2-secureinsecure-servers-sessions-streams-alpn-compatibility-api)

## 4. `node:https` + `node:tls` — secure context, SNI, ALPN, session resumption

- node:https is HTTP semantics carried over node:tls: https.createServer(options, listener) and https.request take the same shape as their http counterparts plus TLS options. There is a dedicated https.Agent, which additionally keeps a client-side TLS session cache (keyed by host) so reconnections can resume the TLS session and skip a round trip - a meaningful win for a keep-alive-light, many-origins client (maxCachedSessions bounds it). — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#4-nodehttps-nodetls-secure-context-sni-alpn-session-resumption)
- The real depth is node:tls: — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#4-nodehttps-nodetls-secure-context-sni-alpn-session-resumption)
  - tls.createSecureContext({ key, cert, ca, pfx, passphrase, minVersion, maxVersion, ciphers }) - the reusable cert/key bundle. ca overrides the default trust store; minVersion: 'TLSv1.2' is the sane floor. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#4-nodehttps-nodetls-secure-context-sni-alpn-session-resumption)
  - SNI (one server, many certs): server option SNICallback(servername, cb) or **server.addContext('*.example.com', ctx) picks the cert by requested hostname. Client: servername** sets the SNI hostname. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#4-nodehttps-nodetls-secure-context-sni-alpn-session-resumption)
  - ALPN: ALPNProtocols: ['h2', 'http/1.1'] on server and client negotiates the protocol; read the result from socket.alpnProtocol (false if none). This is exactly how h2-vs-h1.1 is chosen. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#4-nodehttps-nodetls-secure-context-sni-alpn-session-resumption)
  - Session resumption (skip the full handshake on reconnect), two mechanisms: session IDs (server caches state; 'newSession'/'resumeSession' events) and TLS tickets (server encrypts state into a ticket the client returns; no server cache, and ticketKeys / getTicketKeys/setTicketKeys let a fleet share keys behind a load balancer). Client saves the 'session' event buffer and passes it back as session: to tls.connect. sessionTimeout bounds it. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#4-nodehttps-nodetls-secure-context-sni-alpn-session-resumption)

## 5. `node:net` — the TCP connection model, allowHalfOpen, Nagle, keep-alive

- node:net is the TCP/IPC layer everything above sits on. net.createServer([opts][, listener]) emits 'connection' (socket); net.connect/net.createConnection open a client net.Socket (a Duplex stream emitting 'data', 'end', 'close', 'error', 'timeout', 'ready'). The socket controls you reach for: — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#5-nodenet-the-tcp-connection-model-allowhalfopen-nagle-keep-alive)
  - socket.setNoDelay(true) disables Nagle's algorithm (send small writes immediately instead of coalescing) - important for low-latency request/response and chatty protocols. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#5-nodenet-the-tcp-connection-model-allowhalfopen-nagle-keep-alive)
  - socket.setKeepAlive(true, delay) enables TCP-level keep-alive probes (detect dead peers). — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#5-nodenet-the-tcp-connection-model-allowhalfopen-nagle-keep-alive)
  - socket.setTimeout(ms) fires 'timeout' on inactivity (it does not auto-close - you must socket.destroy() in the handler). — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#5-nodenet-the-tcp-connection-model-allowhalfopen-nagle-keep-alive)
  - allowHalfOpen (default false): when the remote sends FIN (readable 'end'), Node by default also ends the writable side; set true to keep writing after the peer is done reading. pauseOnConnect lets you hand a socket to another process before data flows. net.BlockList (addAddress/addRange/addSubnet) does IP allow/deny lists. (Backpressure mechanics of the socket stream live in nodejs-concurrency-internals.) — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#5-nodenet-the-tcp-connection-model-allowhalfopen-nagle-keep-alive)

## 6. `node:dgram` — UDP sockets (brief)

- Connectionless UDP. dgram.createSocket('udp4'|'udp6') → a socket you bind([port]) and read via the 'message' (msg, rinfo) event; socket.send(msg, port, address) to transmit (no connection, no delivery guarantee). socket.connect(port, address) pins a default remote so you can send(msg) without re-specifying it. Multicast: addMembership/dropMembership, setMulticastTTL, setMulticastLoopback; broadcast: setBroadcast(true). Used for DNS, mDNS/SSDP discovery, metrics (StatsD), and as the substrate under QUIC/HTTP-3. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#6-nodedgram-udp-sockets-brief)

## 7. The global `fetch` **is** undici — Dispatcher, Client, Pool, Agent

- Node's global fetch/Request/Response/Headers (stable since v21) is implemented by undici, Node's from-scratch HTTP/1.1 client. Understanding undici is understanding fetch's performance. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#7-the-global-fetch-is-undici-dispatcher-client-pool-agent)
  - Dispatcher is the base abstraction; everything is a dispatcher with a .dispatch() (and the higher-level request/stream/pipeline/connect/upgrade methods). The concrete types: — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#7-the-global-fetch-is-undici-dispatcher-client-pool-agent)
    - Client - a single keep-alive connection to one origin. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#7-the-global-fetch-is-undici-dispatcher-client-pool-agent)
    - Pool - a pool of Clients to one origin (option connections); this is what gives you parallelism to a single host. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#7-the-global-fetch-is-undici-dispatcher-client-pool-agent)
    - BalancedPool - spreads load across multiple upstream origins. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#7-the-global-fetch-is-undici-dispatcher-client-pool-agent)
    - Agent - the default dispatcher: opens a Pool per origin on demand (this backs fetch). — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#7-the-global-fetch-is-undici-dispatcher-client-pool-agent)
  - undici.request(url, opts) returns { statusCode, headers, body } where body is a stream with convenience readers (body.json(), body.text()); it's lower-overhead than fetch when you don't need the WHATWG semantics. undici.stream/pipeline are for zero-copy piping. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#7-the-global-fetch-is-undici-dispatcher-client-pool-agent)
  - setGlobalDispatcher(dispatcher) / getGlobalDispatcher() swap the dispatcher that global fetch uses - the supported way to set client-wide pool size, timeouts, TLS (connect options), or a proxy for all fetch calls in a process. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#7-the-global-fetch-is-undici-dispatcher-client-pool-agent)
  - Interceptors compose behaviour onto a dispatcher: dispatcher.compose(interceptor, ...) with built-ins for redirect, retry, dns, and cache (the modern replacement for the older maxRedirections option style). RetryAgent wraps a dispatcher with a RetryHandler (backoff, idempotent-method retries). ProxyAgent / EnvHttpProxyAgent route through an HTTP(S) proxy (the latter reads HTTP_PROXY/HTTPS_PROXY/NO_PROXY). MockAgent + setGlobalDispatcher intercepts requests in tests without a real network. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#7-the-global-fetch-is-undici-dispatcher-client-pool-agent)

## 8. undici keep-alive & timeout options (the client-side mirror of §2)

- Client/Pool constructor options and their current defaults (verify against your undici version - these changed historically): — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#8-undici-keep-alive-timeout-options-the-client-side-mirror-of-2)
  - pipelining - default off (effectively 1 in-flight per connection); HTTP/1.1 pipelining is off because of head-of-line blocking. Set higher only against servers you control. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#8-undici-keep-alive-timeout-options-the-client-side-mirror-of-2)
  - keepAliveTimeout - default 4 s; keepAliveMaxTimeout - default 10 min (caps how far a server keep-alive hint can extend it); keepAliveTimeoutThreshold trims a safety margin. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#8-undici-keep-alive-timeout-options-the-client-side-mirror-of-2)
  - headersTimeout - default 30 s (wait for response headers); bodyTimeout - default 30 s (max gap between body chunks). A connection-establishment timeout (~10 s) is configured as a Connector option (connect: { timeout }), not a top-level Client default. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#8-undici-keep-alive-timeout-options-the-client-side-mirror-of-2)
  - connect: { ... } carries TLS options (ca, rejectUnauthorized, servername, ALPN) for HTTPS origins; maxRequestsPerClient recycles a connection after N requests. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#8-undici-keep-alive-timeout-options-the-client-side-mirror-of-2)

## Methodology / practical patterns

- Always set client keep-alive. A bare http.request with the default globalAgent (keepAlive: false) opens and tears down a TCP+TLS connection per request. Use a shared new http.Agent({ keepAlive: true, maxSockets: <bounded> }), or for fetch call setGlobalDispatcher(new Agent({ connections: N })) once at startup. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#methodology-practical-patterns)
- Order the timeout sandwich correctly: Node server.keepAliveTimeout > upstream LB idle timeout, and give headersTimeout/requestTimeout finite values so a stuck client can't pin a socket forever. Mirror it on the client with undici headersTimeout/bodyTimeout. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#methodology-practical-patterns)
- Bound maxSockets/connections. Infinity (the default) means a downstream slowdown lets pending requests open unbounded sockets → fd exhaustion. Size the pool to the downstream's capacity. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#methodology-practical-patterns)
- Pick the protocol deliberately: HTTP/2 (createSecureServer + ALPN 'h2') for many concurrent streams to one origin; HTTP/1.1 + a Pool of connections when the server isn't h2. Don't enable HTTP/1.1 pipelining on the open internet. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#methodology-practical-patterns)
- Reuse a SecureContext across connections instead of re-reading PEM per request; enable session resumption (tickets + shared ticketKeys behind an LB) to cut handshake round-trips. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#methodology-practical-patterns)
- Test with MockAgent, not a live network: const mock = new MockAgent(); setGlobalDispatcher(mock); mock.get(origin).intercept({ path }).reply(200, body). — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#methodology-practical-patterns)

## Anti-patterns

- No timeouts anywhere. A fetch/http.request with no bodyTimeout/headersTimeout to a slow peer hangs forever and holds a socket; a server with the defaults removed is a slowloris target. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#anti-patterns)
- keepAliveTimeout below the LB idle timeout → the LB reuses a socket Node already closed → ECONNRESET → intermittent 502s that look random. The #1 Node-behind-ALB bug. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#anti-patterns)
- maxSockets: Infinity / unbounded connections → socket & file-descriptor exhaustion under load (EMFILE), often mistaken for a memory leak. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#anti-patterns)
- A fresh Agent/Pool/Client per request → you've thrown away pooling entirely; create it once and share it. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#anti-patterns)
- Enabling HTTP/1.1 pipelining to arbitrary servers → head-of-line blocking and corruption with non-compliant intermediaries; that's why undici ships it off. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#anti-patterns)
- Relying on HTTP/2 server push → removed from browsers and deprecated in RFC 9113; use 103 Early Hints instead. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#anti-patterns)
- Disabling rejectUnauthorized to "fix" a TLS error → silently disables cert validation (MITM). Fix the trust chain via ca: instead. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#anti-patterns)

## Troubleshooting

- Intermittent 502 / ECONNRESET behind a proxy → raise server.keepAliveTimeout above the upstream idle timeout; confirm with curl -v keep-alive reuse. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#troubleshooting)
- fetch is slow / opens too many connections → you're on the default per-origin pool; install a tuned Agent via setGlobalDispatcher and check keepAlive is in effect. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#troubleshooting)
- socket hang up / UND_ERR_HEADERS_TIMEOUT / UND_ERR_BODY_TIMEOUT → the server didn't respond within undici's 30 s header/body timeout; raise the relevant option or fix the upstream. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#troubleshooting)
- EMFILE: too many open files → unbounded maxSockets/connections (or leaked sockets that never end); bound the pool and ulimit -n. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#troubleshooting)
- HPE_HEADER_OVERFLOW / 431 → headers exceed --max-http-header-size (16 KiB); raise the flag or shrink cookies/headers. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#troubleshooting)
- HTTP/2 client gets HTTP/1.1 → ALPN didn't negotiate 'h2'; check ALPNProtocols on both ends and read socket.alpnProtocol to confirm. — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#troubleshooting)
- TLS handshake slow under load → no session resumption; wire up tickets/ticketKeys and reuse a single SecureContext. (Event-loop lag while throughput is fine is a different problem - profile the loop; see nodejs-concurrency-internals.) — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#troubleshooting)

## References

- Node.js - node:http (Server, IncomingMessage/ServerResponse, http.request/get, http.Agent, headersTimeout/requestTimeout/keepAliveTimeout/maxRequestsPerSocket, clientError, maxHeaderSize): https://nodejs.org/api/http.html — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#references)
- Node.js - CLI options (--max-http-header-size): https://nodejs.org/api/cli.html — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#references)
- Node.js - node:http2 (createServer/createSecureServer, http2.connect, Http2Session/Http2Stream, pushStream deprecation, ALPN, settings, compatibility API): https://nodejs.org/api/http2.html — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#references)
- Node.js - node:tls (createSecureContext, SNICallback/addContext, ALPNProtocols/alpnProtocol, session resumption - IDs vs tickets, ticketKeys, sessionTimeout): https://nodejs.org/api/tls.html — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#references)
- Node.js - node:https (createServer/request, https.Agent + TLS session cache): https://nodejs.org/api/https.html — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#references)
- Node.js - node:net (createServer, net.Socket, allowHalfOpen, setNoDelay/Nagle, setKeepAlive, setTimeout, BlockList): https://nodejs.org/api/net.html — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#references)
- Node.js - node:dgram (UDP createSocket, send/bind, 'message', multicast addMembership, connected UDP): https://nodejs.org/api/dgram.html — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#references)
- Node.js - global fetch / WHATWG fetch backed by undici: https://nodejs.org/api/globals.html#fetch — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#references)
- undici - Dispatcher/Client/Pool/BalancedPool/Agent, request/stream/pipeline, setGlobalDispatcher, interceptors, RetryAgent/ProxyAgent/EnvHttpProxyAgent/MockAgent: https://undici.nodejs.org/ — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#references)
- undici - Client API options & defaults (pipelining, keepAliveTimeout 4s, keepAliveMaxTimeout 10min, headersTimeout 30s, bodyTimeout 30s): https://github.com/nodejs/undici/blob/main/docs/docs/api/Client.md — [source](https://llms-explorer.com/sources/mdb-context-hub/nodejs-http-networking/#references)

## Where this helps

- Debugging intermittent 502s or ECONNRESET errors behind a load balancer, the classic mismatch between Node's server.keepAliveTimeout and the upstream load balancer's idle timeout. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Tuning an outbound HTTP client that talks to one or many origins at high concurrency, choosing between a bare fetch, a tuned undici Agent/Pool, or HTTP/2 multiplexed streams. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Setting up TLS termination for a multi-tenant server, using SNI for multiple certificates, or negotiating HTTP/2 vs HTTP/1.1 via ALPN. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Hardening a public-facing HTTP server against slowloris-style attacks using headersTimeout, requestTimeout, and keepAliveTimeout together. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Project ideas

- Build a shared, bounded http.Agent, or an undici Agent set via setGlobalDispatcher, with keepAlive enabled and a sized connection pool, replacing the default globalAgent that opens a fresh TCP+TLS connection per request. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Build a TLS session-resumption setup across a fleet of servers behind a load balancer, sharing ticketKeys so reconnecting clients skip the full handshake. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Build a timeout sandwich for a production server, setting server.keepAliveTimeout above the upstream load balancer's idle timeout and giving headersTimeout/requestTimeout finite values so a stuck client can't pin a socket forever. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Build a test suite for an HTTP client layer using undici's MockAgent instead of hitting the live network, intercepting requests by path and origin. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Common mistakes

- Setting server.keepAliveTimeout below the upstream load balancer's idle timeout: the load balancer reuses a socket Node already closed, producing intermittent ECONNRESET/502s that look random; the pack calls this the number one Node-behind-ALB bug. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Leaving maxSockets or undici's connections option unbounded: a downstream slowdown lets pending requests open unbounded sockets, leading to file-descriptor exhaustion that's often mistaken for a memory leak. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Creating a fresh Agent, Pool, or Client per request instead of one shared instance: this throws away connection pooling entirely and pays a full TCP+TLS handshake on every call. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Disabling rejectUnauthorized to fix a TLS error: this silently disables certificate validation and opens the connection to a man-in-the-middle attack; the trust chain should be fixed via the ca option instead. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Known issues

- HTTP/2 server push (stream.pushStream) is deprecated: RFC 9113 removed it and modern browsers no longer support it, and 103 Early Hints is the replacement for preloading. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- socket.setTimeout(ms) fires a timeout event on inactivity but does not auto-close the socket; the handler must explicitly call socket.destroy() or the connection stays open. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- HTTP/1.1 pipelining is off by default in undici, and shouldn't be turned on against arbitrary servers, because non-compliant intermediaries can cause head-of-line blocking and response corruption. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Node's default http.globalAgent historically has keepAlive set to false, so a bare http.request without an explicit shared Agent opens and tears down a new TCP+TLS connection on every single request. — [source](https://llms-explorer.com/tree/node-js-http-networking/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Context files

- [Node.js HTTP & Networking](https://llms-explorer.com/downloads/sources/mdb-context-hub/nodejs-http-networking.md)
