Bypass — when caching is wrong, the CDN still earns its keep

Auth-required and per-user routes must bypass the cache (Cache-Control: private, no-store), and the CDN still pays for itself on those routes through TLS termination at the POP, anycast routing, and DDoS absorption.

Previously

Shield helps the cacheable traffic — but plenty of traffic is per-user and should never be cached at all; what does the CDN do for those routes? Some routes — like /api/me — should NEVER be cached because the response is per-user; the CDN must instead route them straight through to origin. That straight-through pattern is called bypass.

Scene 10

Bypass — when caching is wrong, the CDN still earns its keep

  1. Watch
  2. Try it
  3. Predict
  4. Capture
TWO PARALLEL LANES · ONE POPsame path, two policies — cacheable hits the cache · bypass routes around itPOP (edge)CACHEkeyed by URLHITSTILL DOES (every request)TLS terminatedanycast routedDDoS filtercacheorigindynamic / per-userapi.example.comuser AGET (cacheable)GET /static/logo.pngHIT · 5.0 msuser AGET (bypass)GET /api/meskips cacheproxyBYPASS · 80 msLEAKED RESPONSES0user A's data → user B
Bypass: Cache-Control: private, no-store on /api/me — POP proxies straight to origin while still terminating TLS and absorbing DDoS.
Even on the bypass lane (no cache lookup), the POP still does TLS termination, anycast routing, and DDoS filtering on every request. That's the half of the CDN's value learners forget.
What to watch for

Two requests in parallel: /static/logo.png hits cache and returns in 5 ms; /api/me bypasses cache and returns in 80 ms; both go through the same POP. Notice the chips on the POP — TLS termination, anycast routing, and DDoS filtering happen on EVERY request, not just cacheable ones.

Implementation

Highlighted lines are the ones running in the diagram right now.

POP.shouldCache
edge classifier — decide cache vs bypass per response
def shouldCache(req, response):
cc = parse(response.headers['Cache-Control'])
# 'private' = shared caches MUST NOT store
if 'private' in cc: return False
if 'no-store' in cc: return False
# explicit bypass rule (e.g. /api/*, /admin/*)
if matches_bypass_rule(req.path): return False
# 'public' overrides the auth-skip default
if 'public' in cc: return True
if 'Authorization' in req.headers: return False
return cc.max_age is not None
POP.handle
what the POP still does on every request, cache or not
def handle(connection):
# 1. terminate TLS at the edge — saves an origin RTT
req = tls.terminate(connection)
# 2. anycast already routed the user to THIS POP via BGP
# 3. volumetric DDoS filter runs before any app logic
if ddos.shouldDrop(req): return
cached = cache.lookup(cache_key(req))
if cached and not cached.expired:
return cached.response # HIT
response = origin.fetch(req) # bypass / MISS path
if shouldCache(req, response):
cache.store(cache_key(req), response)
return response
POP.cacheKey
the leak path — key is URL only unless you opt in to Vary
def cache_key(req):
# default: method + scheme + host + path + query
parts = [req.method, req.url]
# cookies / auth enter the key only via explicit Vary
for axis in response.headers.get('Vary', []):
parts.append(req.headers.get(axis, ''))
return hash(parts)
# misconfigured-public on /api/me:
# user A -> store(key('/api/me'), A.profile)
# user B -> lookup(key('/api/me')) -> A.profile # LEAK

Where this sits in Build a CDN

Scene 10 of 13, in the Operating act — Shield, bypass routes, and the hit-ratio dashboard.. Auth and per-user routes must bypass the cache, and the CDN still pays for itself there: TLS termination at the POP, anycast routing, DDoS absorption.

Up next. Every lever we have moves one number — origin RPS — and the headline that summarizes them all is hit ratio.

All 13 scenes in Build a CDN · Every curriculum

Built with Arqly
Every scene in Build a CDN builds on the one before it.All 13 Build a CDN scenes