In HTTPS, all the headers are encrypted except the hostname:
https://en.wikipedia.org/wiki/Server_Name_Indication
SSL termination is always done on our customers' servers.
https://en.wikipedia.org/wiki/Server_Name_Indication
SSL termination is always done on our customers' servers.
From a comment above, it seems like Hakuna requires a FQDN of each AWS server it's serving traffic to, so if you're not MITM'ing traffic, this FQDN I'm guessing sits in with SNI and is used for routing rather than serving certificates. I don't think I've personally dealt with this use case on SNI, but it makes sense.