Bypass — when caching is wrong, the CDN still earns its keep
Auth-required and per-user routes must bypass the cache (Cache-Control: private, no-store), and the CDN still pays for itself on those routes through TLS termination at the POP, anycast routing, and DDoS absorption.
Shield helps the cacheable traffic — but plenty of traffic is per-user and should never be cached at all; what does the CDN do for those routes? Some routes — like /api/me — should NEVER be cached because the response is per-user; the CDN must instead route them straight through to origin. That straight-through pattern is called bypass.
Scene 10
Bypass — when caching is wrong, the CDN still earns its keep
- Watch
- Try it
- Predict
- Capture
Two requests in parallel: /static/logo.png hits cache and returns in 5 ms; /api/me bypasses cache and returns in 80 ms; both go through the same POP. Notice the chips on the POP — TLS termination, anycast routing, and DDoS filtering happen on EVERY request, not just cacheable ones.
Highlighted lines are the ones running in the diagram right now.
def shouldCache(req, response):cc = parse(response.headers['Cache-Control'])# 'private' = shared caches MUST NOT storeif 'private' in cc: return Falseif 'no-store' in cc: return False# explicit bypass rule (e.g. /api/*, /admin/*)if matches_bypass_rule(req.path): return False# 'public' overrides the auth-skip defaultif 'public' in cc: return Trueif 'Authorization' in req.headers: return Falsereturn cc.max_age is not None
def handle(connection):# 1. terminate TLS at the edge — saves an origin RTTreq = tls.terminate(connection)# 2. anycast already routed the user to THIS POP via BGP# 3. volumetric DDoS filter runs before any app logicif ddos.shouldDrop(req): returncached = cache.lookup(cache_key(req))if cached and not cached.expired:return cached.response # HITresponse = origin.fetch(req) # bypass / MISS pathif shouldCache(req, response):cache.store(cache_key(req), response)return response
def cache_key(req):# default: method + scheme + host + path + queryparts = [req.method, req.url]# cookies / auth enter the key only via explicit Varyfor axis in response.headers.get('Vary', []):parts.append(req.headers.get(axis, ''))return hash(parts)# misconfigured-public on /api/me:# user A -> store(key('/api/me'), A.profile)# user B -> lookup(key('/api/me')) -> A.profile # LEAK
- RFCRFC 9111 §3.5 — Storing Responses to Authenticated Requests
- docMDN: Cache-Control — private vs public
- codeSidekiq issue #5936 — cookie leaking via CDN
- codeHackerOne: ThisData insecure Cache-Control
- docCloudflare: Bypass cache on cookie
- docCloudflare: DDoS protection overview
- bloggbHackers: Cache deception attack
Where this sits in Build a CDN
Scene 10 of 13, in the Operating act — Shield, bypass routes, and the hit-ratio dashboard.. Auth and per-user routes must bypass the cache, and the CDN still pays for itself there: TLS termination at the POP, anycast routing, DDoS absorption.
Up next. Every lever we have moves one number — origin RPS — and the headline that summarizes them all is hit ratio.