Infrastructure
Design CDN
01
Requirements
Requirements
- Pull-through cache for customer HTTP content (images, CSS/JS, videos, API responses)
- Customer-configurable cache rules (TTL, cache key, bypass conditions)
- Fresh-on-write: purge cache entry globally within seconds of API call
- TLS termination at the edge with customer certs (SNI)
- Optional: WAF rules, bot management, DDoS mitigation, image resize
- Real-time analytics: req/sec, bytes served, cache hit ratio per customer
- Edge compute (Workers / Lambda@Edge) for request-path JS execution
- RTT < 50 ms to end-user from nearest PoP (p95)
- Cache hit ratio > 90% for static assets
- Purge propagation < 5 seconds globally
- 99.99% availability — outages affect huge swaths of the internet
- Survive DDoS up to tens of millions of req/sec per target
- No single PoP's death should impact serving
02
Scale Estimation
Scale Estimation
03
API Design
API Design
Two API surfaces: the data plane — HTTP(S) requests from end-users hitting edge PoPs — and the control plane — customer-facing API for configuring rules, purging cache, reading analytics.
End-user HTTP request. Anycast routes to nearest PoP. Cache check → serve or fetch from origin. TLS term at edge using customer cert.
Purge specific URLs, tags, or the entire zone. Body: {files: [URLs], tags: [cache_tag_1, ...], purge_everything: true}. Propagated to all PoPs within seconds.
Configure cache rules, page rules, WAF rules, workers. Changes propagate to edge via config sync (seconds).
Returns time-series metrics per zone: requests, bytes, hit ratio, status codes, countries, threats blocked.
Deploy edge compute (JavaScript/WASM). Uploads script bundle to all edge PoPs; runs in an isolate on every request to the configured routes.
04
Architecture
Architecture
Three tiers: edge PoPs (close to users, serve 90%+ of requests), regional tier (fewer, larger, act as a mid-cache + origin shield), and origin (customer's server). Requests cascade upward only on cache miss. A control plane in a few central regions handles config + purge + analytics rollup.
05
Deep Dive — Anycast + Cache Hierarchy + Purge
Deep Dive — Anycast + Cache Hierarchy + Purge
Anycast routing. All CDN PoPs announce the same IP address (typically a single /24 per service) via BGP. Internet routers naturally prefer the topologically closest announcement. A user in London gets routed to the London PoP; a user in Tokyo to the Tokyo PoP — without DNS games. If a PoP dies, its BGP announcement is withdrawn and traffic reroutes to the next-closest.
This is dramatically simpler than DNS-based geographic routing (which is the Akamai-era approach): no TTL games, no resolver location guesses, no DNS caching issues. Cloudflare popularized Anycast-for-CDN; now industry standard.
Cache hierarchy with tiered cache. Problem: 300 PoPs × 100 TB each is 30 PB of storage — but cumulative customer content is far more than that. Each PoP can only hold a subset. Result: cold content causes repeated fetches from origin, hammering customer servers.
Solution: regional tier between edge and origin. A PoP miss queries its regional tier. The regional tier has more storage, sees more traffic, and has better hit ratio. Only regional-tier misses hit origin. Net: origin load drops 10× compared to flat-edge.
sequenceDiagram
participant U as User
participant E as Edge PoP
participant R as Regional
participant O as Origin
U->>E: GET /foo.jpg
E->>E: cache lookup
alt HIT (90% of the time)
E-->>U: serve from NVMe (p50 ~5 ms)
else MISS at edge
E->>R: fetch /foo.jpg
alt HIT at regional
R-->>E: bytes + cache-control
E-->>U: serve + populate edge cache
else MISS at regional
R->>O: fetch /foo.jpg
O-->>R: bytes
R-->>E: bytes
E-->>U: serve + populate both caches
end
end
Cache key. Default is (host, URL-path, query-string). Customer can override — strip tracking params, normalize case, include Vary headers (Accept-Encoding, device type). Mis-configured cache keys are a top source of inexplicable "why isn't my site caching?" support tickets.
Purge / invalidation. Two flavors: URL-based (specific URLs) and tag-based (arbitrary label applied to responses at cache-time, then "purge all cached items with tag X"). Purge flow:
- Customer API call hits control plane.
- Control plane writes purge message to a global pub/sub bus (Kafka / internal multicast).
- Every PoP subscribes; consumes message.
- Each PoP invalidates matching entries in local cache (usually by writing a tombstone so serves return miss).
Total time: seconds. Not instant — but predictable. "Purge everything" zone-wide is much slower (hours) because it invalidates millions of keys.
Stampede prevention. If 1M users request a newly-popular image simultaneously and edge cache misses, all 1M requests would forward to the regional/origin. Protection: request coalescing — concurrent requests for the same key at a single PoP collapse into one upstream fetch. Only the first miss goes upstream; others wait for its response. One-request-in-flight invariant per key per PoP.
"Anycast BGP routing sends users to the nearest PoP. Each PoP runs nginx/envoy with NVMe-backed cache, TLS termination with SNI-indexed certs, WAF, and workers. Cache misses cascade to a regional tier (origin shield) before ever hitting the customer's origin, cutting origin load 10×. Purge is global pub/sub from a control plane — seconds to propagate to all PoPs. Stampede protection via per-key request coalescing so only one upstream fetch runs for concurrent misses. Real-time logs stream to a central analytics pipeline."
06
Tradeoffs & Design Choices
Tradeoffs & Design Choices
- Anycast vs DNS-based routing. Anycast is simpler, faster to fail over, no TTL dependencies. DNS-based allows policy ("send premium customers to better PoPs") but is brittle. Cloudflare-style = Anycast; Akamai = historically DNS. New CDNs default to Anycast.
- Flat-edge vs tiered cache. Flat (no regional) is simpler but hammers origin on misses. Tiered requires another hop but preserves origin. Modern default is tiered; "flat-edge" survives only in smallest deployments.
- Pull vs push cache. Pull = first request populates cache (lazy). Push = pre-populate before launch (eager, for known-popular events). Pull is default; push is opt-in for live-streaming Superbowl-style events.
- Shared vs per-customer caches. Shared cache (all customers share PoP capacity) is more efficient but creates noisy-neighbor risk. Per-customer quotas prevent one customer filling the cache. Some products isolate premium customers into dedicated capacity.
- TLS cert distribution. Every PoP needs the cert for every customer on it. Options: replicate all certs to all PoPs (wastes storage), fetch on-demand (slow first-request), or SNI-based lazy pull with LRU. Cloudflare uses combination of Keyless SSL + selective pre-stage.
07
Failure Modes
Failure Modes
08
Interview Tips
Interview Tips
- Anycast first, not DNS. Modern CDN answer. Explain the mechanism in one sentence.
- Tiered cache beats flat-edge. Without it, your origin burns. Mention by name; it's a load-reducing design choice that shows sophistication.
- Purge is not magic. It's pub/sub with seconds of propagation. Don't say "instant cache invalidation."
- Request coalescing for stampedes. One-request-in-flight per key. Classic pattern that many candidates forget.
- Analytics + logs. CDN's real product is observability. Mention shipping edge logs → central analytics; it's half the value customers pay for.
- Stale-while-revalidate. One line, massive impact. Shows you know the production-grade answer.
09
Evolution
Evolution
MVP — DNS-based geo routing, few PoPs
GeoDNS sends user to nearest PoP. Simple Varnish/nginx cache at each PoP. Origin fetch on miss. Works for small scale.
Anycast routing + 50+ PoPs
BGP-Anycast IP replaces GeoDNS. Failover automatic via BGP. Hundreds of thousands of req/sec per PoP.
Regional tier + origin shield
Regional mid-cache absorbs PoP misses. Origin load drops 10×. Tiered cache becomes default for all customers.
Edge compute + bot management
Customer-provided JS runs in V8 isolates at every PoP (Cloudflare Workers / Lambda@Edge). Bot management, WAF, A/B-splitting all at edge.
CDN as platform (DB / KV / pub-sub at edge)
Cloudflare Durable Objects, KV, R2 (object storage). Edge becomes an application platform — full apps shippable with no origin. Still evolving (2024+).
Watch and read
References & Videos
Try next
Free to read · better with Enzo
Whiteboard this with Enzo
Enzo runs it as a live system design round on the whiteboard and grades your trade-offs.