Origin shield — collapsing the herd
Without a shield, every POP independently misses on TTL expiry and stampedes origin in parallel; with a shield, lower-tier POPs ask one upper-tier POP first and origin sees one request instead of N.
Even with a perfect cache key, a popular object expiring across hundreds of POPs at once stampedes origin — unless we put one POP between them.
Scene 09
Origin shield — collapsing the herd
- Watch
- Try it
- Predict
- Capture
Shield is OFF. The popular URL is cached at every POP and a TTL countdown is ticking on every cell. When the countdown hits zero, every POP misses at the same instant — watch what happens to the origin gauge.
Highlighted lines are the ones running in the diagram right now.
def on_miss(req):# cell expired or never populated hereupstream = originresp = upstream.fetch(req.url)cache.put(req.cache_key, resp,ttl = resp.cache_control.max_age,)return resp# at TTL boundary every POP runs this in parallel# → origin sees N simultaneous fetches for one byte
def on_miss(req):# ask the shield POP, not originupstream = shield_pop_for(req.cache_key)resp = upstream.fetch(req.url) # +cross-region hopcache.put(req.cache_key, resp,ttl = resp.cache_control.max_age,)return resp
inflight = {} # cache_key → Futuredef fetch(url):key = cache_key(url)if key in cache and not cache[key].stale:return cache[key]if key in inflight:return inflight[key].await() # piggybackinflight[key] = spawn(origin.fetch(url))resp = inflight[key].await()cache.put(key, resp)del inflight[key]return resp
Where this sits in Build a CDN
Scene 09 of 13, in the Operating act — Shield, bypass routes, and the hit-ratio dashboard.. Without a shield, every POP independently misses on TTL expiry and stampedes origin in parallel; with a shield, origin sees one request instead of N.
Up next. Shield helps the cacheable traffic — but plenty of traffic is per-user and should never be cached at all; what does the CDN do for those routes?