Origin shield — collapsing the herd

Without a shield, every POP independently misses on TTL expiry and stampedes origin in parallel; with a shield, lower-tier POPs ask one upper-tier POP first and origin sees one request instead of N.

Previously

Even with a perfect cache key, a popular object expiring across hundreds of POPs at once stampedes origin — unless we put one POP between them.

Scene 09

Origin shield — collapsing the herd

  1. Watch
  2. Try it
  3. Predict
  4. Capture
URL/products/viral-deal.htmlTTL 8s remainingORIGIN SHIELDDISABLEDORIGINsingle backend regionORIGIN RPS06120req/sec at originLOWER-TIER POPs · 12LAXHITFRAHITSYDHITGRUHITSINHITBOMHITNRTHITDXBHITJNBHITORDHITCDGHITAMSHITPOPs (12)Shield OFF · cell fresh — TTL 8s remaining on every POP.
What to watch for

Shield is OFF. The popular URL is cached at every POP and a TTL countdown is ticking on every cell. When the countdown hits zero, every POP misses at the same instant — watch what happens to the origin gauge.

Continue unlocks when the animation finishes.
Implementation

Highlighted lines are the ones running in the diagram right now.

POP.on_miss (shield OFF)
every POP fans out to origin on its own miss
def on_miss(req):
# cell expired or never populated here
upstream = origin
resp = upstream.fetch(req.url)
cache.put(
req.cache_key, resp,
ttl = resp.cache_control.max_age,
)
return resp
# at TTL boundary every POP runs this in parallel
# → origin sees N simultaneous fetches for one byte
POP.on_miss (shield ON)
lower tier asks the designated upper-tier POP first
def on_miss(req):
# ask the shield POP, not origin
upstream = shield_pop_for(req.cache_key)
resp = upstream.fetch(req.url) # +cross-region hop
cache.put(
req.cache_key, resp,
ttl = resp.cache_control.max_age,
)
return resp
ShieldPOP.fetch
request coalescing — N concurrent misses, 1 origin fetch
inflight = {} # cache_key → Future
def fetch(url):
key = cache_key(url)
if key in cache and not cache[key].stale:
return cache[key]
if key in inflight:
return inflight[key].await() # piggyback
inflight[key] = spawn(origin.fetch(url))
resp = inflight[key].await()
cache.put(key, resp)
del inflight[key]
return resp

Where this sits in Build a CDN

Scene 09 of 13, in the Operating act — Shield, bypass routes, and the hit-ratio dashboard.. Without a shield, every POP independently misses on TTL expiry and stampedes origin in parallel; with a shield, origin sees one request instead of N.

Up next. Shield helps the cacheable traffic — but plenty of traffic is per-user and should never be cached at all; what does the CDN do for those routes?

All 13 scenes in Build a CDN · Every curriculum

Built with Arqly
Every scene in Build a CDN builds on the one before it.All 13 Build a CDN scenes