Design your CDN configuration

Every CDN configuration is a deliberate trade against one number — origin RPS — paid for in the currencies of staleness, cardinality, and operational complexity.

Previously

Now that you can read the dashboard, you can design the configuration that produces a healthy one for a real workload — drop a workload card on the canvas and read the verifier as the rubric.

Scene 12

Design your CDN configuration

  1. Watch
  2. Try it
  3. Predict
  4. Capture
PALETTEcache-control · vary · keysCACHE-CONTROLpublic, max-age=60, s-maxage=86400,stale-while-revalidate=600publicstore okswr=600VARYAccept-Encodi…SURROGATE-KEYSrelease:v42asset:logoORIGIN PROTECTIONshieldbypassPURGEURLsurrogatezoneWORKLOADstaticstaticStatic-asset sitetraffic: 1B requests/day · logos, JS, CSSSLO: p95 < 50 ms worldwide; origin RPSbounded by release cadence.DATAFLOWuserbrowserGETPOP / edge cachePOP (max-age=60)missshield POPorigin protectionfilloriginfills on missVERIFIERscores · verdictsORIGIN RPS✓GOODP95 LATENCY✓GOODHIT RATIO✓GOODWORST STALENESS✓GOODVERDICTS✓TTL: max-age=60,s-maxage=86400 — shortscene 4✓Vary: Accept-Encoding only— 3 entries per URL, noscene 8✓Surrogate-key purge(release:v42) — atomicscene 7✓Shield ON — viral assetnever stampedes origin onscene 9static-asset site: long edge TTL, surrogate keys per release, shield absorbs the herd.
What to watch for

Empty canvas with one preset workload card already placed (static-asset site). Watch the four workloads roll past — each canvas snaps to the honest preset and the verifier nods, citing the scene that justifies each choice.

Continue unlocks when the animation finishes.
Implementation

Highlighted lines are the ones running in the diagram right now.

Config.build
the CDN-config DSL — one knob per earlier scene
config = {
cacheControl: f"{public_or_private}, "
f"max-age={maxAgeSec}, " # browser TTL
f"s-maxage={sMaxAgeSec}, " # edge TTL
f"stale-while-revalidate={swrSec}, "
f"{'no-store' if noStore else ''}",
vary: varyAxes, # cache-key fan-out
surrogateKeys: tags, # atomic purge group
shield: shieldEnabled, # collapse the herd
bypass: bypass, # never cache this route
purge: purgeStrategy, # url | surrogate | zone
}
Verifier.verify
scores a config against the workload's SLO; cites scenes
def verify(workload, config):
originRps = estimateOriginRps(workload, config)
hitRatio = estimateHitRatio(workload, config) # bytes for video
staleness = worstCaseStaleness(config) # max-age + swr
leakRisk = perUserInSharedCache(workload, config)
verdicts = []
if config.vary contains 'User-Agent' or 'Cookie':
verdicts += fail('cardinality explosion', scene=8)
if leakRisk and not (config.bypass or config.noStore):
verdicts += fail('per-user data in shared cache', scene=10)
if config.swrSec > 0 and workload.stalenessIsIncident:
verdicts += fail('SWR ships the bug for swrSec', scene=6)
if config.purge == 'zone' and not config.shieldEnabled:
verdicts += fail('cold-cache stampede on origin', scene=7)
return { originRps, hitRatio, staleness, leakRisk, verdicts }
Workload.slo
what number the verifier should weigh for this workload
workloads = {
'static': slo(p95Ms=50, metric='requestHitRatio',
leakRisk=False, stalenessIsIncident=False),
'authApi': slo(p95Ms=200, metric='originRps',
leakRisk=True, stalenessIsIncident=False),
'video': slo(p95Ms=200, metric='byteHitRatio',
leakRisk=False, stalenessIsIncident=False),
'realtime': slo(p95Ms=200, metric='originRps',
leakRisk=False, stalenessIsIncident=True),
}
# the verifier reads workload.metric to know which dial
# to weigh — request hit ratio for static, BYTE hit ratio
# for video, staleness for realtime, leakRisk for authApi.

Where this sits in Build a CDN

Scene 12 of 13, in the Design act — Workload-driven CDN configuration.. Capstone: pick TTL, Vary, purge strategy, shield, and bypass for static / authenticated API / video / real-time workloads — verifier traces every choice back to a scene.

All 13 scenes in Build a CDN · Every curriculum

Built with Arqly
Every scene in Build a CDN builds on the one before it.All 13 Build a CDN scenes