TLS terminating reverse proxy
Design a TLS-terminating reverse proxy / ingress edge for a SaaS that serves thousands of customer custom domains (vanity domains like app.customer.com) with per-domain certificates, auto-renewed. It terminates TLS, then forwards to internal services over mTLS. Explain certificate storage and selection at handshake time, how you handle 10k+ certs without bloating memory, and how you forward client identity safely to the backend.
What a strong answer looks like
Clarify scale and constraints first. Propose a clean component breakdown, then go deep on the hard parts (data model, bottlenecks, consistency, failure modes) and name the trade-offs you are making.
Clarify4:00 left
Estimate4:00 planned
Design11:30 planned
Deep dive9:30 planned
Failure6:00 planned
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.