Design your CDN configuration
Every CDN configuration is a deliberate trade against one number — origin RPS — paid for in the currencies of staleness, cardinality, and operational complexity.
Now that you can read the dashboard, you can design the configuration that produces a healthy one for a real workload — drop a workload card on the canvas and read the verifier as the rubric.
Scene 12
Design your CDN configuration
- Watch
- Try it
- Predict
- Capture
Empty canvas with one preset workload card already placed (static-asset site). Watch the four workloads roll past — each canvas snaps to the honest preset and the verifier nods, citing the scene that justifies each choice.
Highlighted lines are the ones running in the diagram right now.
config = {cacheControl: f"{public_or_private}, "f"max-age={maxAgeSec}, " # browser TTLf"s-maxage={sMaxAgeSec}, " # edge TTLf"stale-while-revalidate={swrSec}, "f"{'no-store' if noStore else ''}",vary: varyAxes, # cache-key fan-outsurrogateKeys: tags, # atomic purge groupshield: shieldEnabled, # collapse the herdbypass: bypass, # never cache this routepurge: purgeStrategy, # url | surrogate | zone}
def verify(workload, config):originRps = estimateOriginRps(workload, config)hitRatio = estimateHitRatio(workload, config) # bytes for videostaleness = worstCaseStaleness(config) # max-age + swrleakRisk = perUserInSharedCache(workload, config)verdicts = []if config.vary contains 'User-Agent' or 'Cookie':verdicts += fail('cardinality explosion', scene=8)if leakRisk and not (config.bypass or config.noStore):verdicts += fail('per-user data in shared cache', scene=10)if config.swrSec > 0 and workload.stalenessIsIncident:verdicts += fail('SWR ships the bug for swrSec', scene=6)if config.purge == 'zone' and not config.shieldEnabled:verdicts += fail('cold-cache stampede on origin', scene=7)return { originRps, hitRatio, staleness, leakRisk, verdicts }
workloads = {'static': slo(p95Ms=50, metric='requestHitRatio',leakRisk=False, stalenessIsIncident=False),'authApi': slo(p95Ms=200, metric='originRps',leakRisk=True, stalenessIsIncident=False),'video': slo(p95Ms=200, metric='byteHitRatio',leakRisk=False, stalenessIsIncident=False),'realtime': slo(p95Ms=200, metric='originRps',leakRisk=False, stalenessIsIncident=True),}# the verifier reads workload.metric to know which dial# to weigh — request hit ratio for static, BYTE hit ratio# for video, staleness for realtime, leakRisk for authApi.
- docCloudflare Learning Center — full CDN reference
- docFastly Documentation Hub
- RFCRFC 9111 — HTTP Caching (the contract)
- RFCRFC 5861 — stale-while-revalidate / stale-if-error
- blogCloudflare: Cache Reserve (persistent tier behind Tiered Cache)
- talkFastly: Caching at the Edge tech talks
- blogIlya Grigorik — High Performance Browser Networking, Ch. 11 (HTTP Caching)
Where this sits in Build a CDN
Scene 12 of 13, in the Design act — Workload-driven CDN configuration.. Capstone: pick TTL, Vary, purge strategy, shield, and bypass for static / authenticated API / video / real-time workloads — verifier traces every choice back to a scene.