Skip to content

Dual-stack forwarding

This guide covers upstream egress — which local address Conduit uses when forwarding to backends. Bind and timeout fields are in Reference: forward; per-pool source overrides are in Reference: pools. For pool and backend layout, see Pools and backends; for the query path, see Architecture and packet path.

Global and per-pool sources

Configure local bind addresses under:

  • forward.sources_v4 / forward.sources_v6 — defaults for all pools
  • pools[].sources_v4 / pools[].sources_v6 — override for a specific pool when non-empty

When a pool list is empty, Conduit uses the global forward.sources_* list. See Reference: pools for limits and validation.

At Forward, Conduit picks a source using forward.source_selection (round-robin) unless a per-query override is set.

Choosing an egress source

Use this order of preference:

Need Mechanism
Same source for every query to a pool Pool sources_v4 / sources_v6 (or global forward.sources_*)
Source depends on query match, fixed IP Request rules — set_source_v4 / set_source_v6 (Rules and actions)
Different egress only on retry (outcome-driven) Request or response rules — set_retry_source_v4 / set_retry_source_v6; pair with retry / retry_now or Rhai txn.request_retry()
Logic, tables, or multi-step policy Rhai — txn.set_source_v4() / txn.set_source_v6() on the request hook; txn.set_retry_source_*() on either hook

Declarative set_source_* actions and Rhai share the same transaction overrides and the same allowed-set check at Forward. If an override is not permitted for the selected pool, Conduit does not fail the query — it falls back to ordinary round-robin among configured sources.

When a rule sets both pool and source, list set_pool before set_source_v4 / set_source_v6 on the same rule. Details: Action order on one rule.

IPv4 clients, IPv6 backends (and the reverse)

Conduit selects the source address family to match the backend address (IPv4 backend → v4 source list; IPv6 backend → v6 source list). Cross-family forwarding is determined by your pool/backend layout and source lists — validate end-to-end in a lab before production.