HTTP/1.1 connections are persistent: a socket outlives the request that opened it, and each is a timer, a buffer and a file descriptor.
import { createServer } from 'node:http';
const s = createServer();
console.log(s.requestTimeout, s.headersTimeout, s.keepAliveTimeout, s.timeout);Output
300000 60000 5000 0
headersTimeout (60 s) caps the parser's wait for a complete header block — the defense against Slowloris, which trickles headers to pin sockets open — and requestTimeout (300 s) caps the whole request; both answer 408 and close. timeout is 0 — no socket inactivity timeout at all — and keepAliveTimeout (5 s) is how long an idle socket is held for reuse: the value advertised in An HTTP Server by Hand. server.close() waits for in-flight requests; an idle keep-alive socket is not one, so follow it with closeIdleConnections() (Signals and Graceful Shutdown).