Cookie-based sessions have many, very reasonable, use cases.
You are also clearly neglecting the fact that proper session cookies are _always_ cryptographically signed and cannot be tampered with, if properly implemented.
You are also clearly neglecting the fact that proper session cookies are _always_ cryptographically signed and cannot be tampered with, if properly implemented.
But still, if your frontend hosts can't reach your database, you have far bigger problems than your sessions not working.