=== ORIGIN: AZURE-SIM (NON-AWS) === remote_addr (TCP peer): 64.252.76.35 X-Forwarded-For: '216.73.217.62' X-Amz-Cf-Id: '3Kpb86Wd3O_QJio_OAI9VvSHrExxXuCnsJFd40_Pl3bGVryaftsf-g==' Host: origin-azure.cf-saas.demotw.com SNI: origin-azure.cf-saas.demotw.com TLS: TLSv1.3 / TLS_AES_128_GCM_SHA256 Time: 2026-08-14T02:21:32+00:00 This is Origin B (Azure simulation). In production this would be an Azure App Gateway, on-prem F5, or any public HTTPS endpoint. CloudFront routes here by tenant hostname. No proxy tier, no NAT GW, no special config — just a public FQDN.