CDN Cache Keys and the Vary Header

A cache key decides whether two requests may reuse the same stored response. A typical CDN starts with the request scheme, host, path, and query string. It may also include selected headers or cookies. The Vary response header is the HTTP mechanism that tells a cache which request headers selected a representation. The safe goal is simple: requests that should receive the same bytes should share a key, while requests that require different bytes must not collide. A key that is too narrow can expose the wrong response. A key that is too broad creates many variants, lowers the cache hit ratio, and increases origin traffic. ...

August 13, 2026 · CDN Handbook

CDN Delivery in Mainland China

Delivering from CDN nodes inside mainland China is a separate product and compliance decision, not just a checkbox on a global network map. Confirm current requirements with qualified local counsel and the selected service provider before launch; this page is technical guidance, not legal advice. Start with the delivery region Decide whether the requirement is: edge delivery from nodes inside mainland China; delivery from nearby locations outside the mainland, such as Hong Kong, Japan, or Singapore; or one global configuration that includes the mainland. These designs have different onboarding, performance, feature, contract, and regulatory consequences. For example, Alibaba Cloud’s current CDN documentation distinguishes mainland-only, global, and global-excluding-mainland acceleration regions. It requires an ICP filing for the first two and not for the third. See Alibaba Cloud’s acceleration-region documentation. ...

August 13, 2026 · CDN Handbook

CDN Security Advisories and Incident Sources

CDN incidents are easy to misread because a public symptom can originate in the CDN, an origin, DNS, a certificate authority, a cloud dependency, or the customer’s own configuration. Use primary sources to establish what is known before assigning cause. This page is a monitoring method and source directory. It is not a live incident feed. Start with the incident class Signal Check first Confirm with Broad availability drop Provider status page Provider incident history and your regional probes New CVE or exploited flaw Vendor advisory and CISA KEV Product/version scope and remediation text Elevated 5xx responses CDN and origin logs The 5xx ownership and diagnosis guide Certificate failures CDN certificate state and CA status TLS handshake logs and affected hostnames Cache or purge anomaly Cache-status headers and purge operation IDs The purge verification checklist Suspected attack WAF, bot, and DDoS event logs Provider advisory, indicators, and application logs Primary status sources Akamai service status AWS Health Dashboard Cloudflare status Fastly status Google Cloud service health Microsoft Azure status Subscribe to the provider’s official email, RSS, Atom, webhook, or API option where one exists. A third-party aggregator is useful for discovery, but it should not be the sole evidence for impact, cause, or resolution. ...

August 13, 2026 · CDN Handbook

Does Hetzner Have a CDN?

No. Hetzner does not provide a native content delivery network. Hetzner’s Object Storage FAQ explicitly says that Object Storage is not a CDN and recommends placing a third-party CDN in front of it for large-scale global delivery. Hetzner can still be the origin. A CDN can fetch files from Hetzner Object Storage, a cloud server, a dedicated server, or a load-balanced application and cache suitable responses at its edge locations. What Hetzner provides Hetzner provides infrastructure products such as cloud servers, dedicated servers, load balancers, DNS, and S3-compatible Object Storage. These products run applications and store content. Their data-center locations are not a globally distributed CDN cache footprint. ...

August 13, 2026 · CDN Handbook

How to Compare CDN Pricing

CDN pricing cannot be compared reliably with one advertised per-gigabyte number. A useful estimate applies each provider’s current rate card or proposal to the same traffic, cache, security, and support assumptions. Build one workload model Record a representative month and a peak event separately. At minimum include: delivered bytes by billing region; HTTP and HTTPS request counts; cache-hit ratio and bytes fetched from origins or shields; purge and configuration-change volume; log volume and destination; image, video, edge-compute, WAF, bot, and DDoS usage; committed traffic, overage, and contract term; support tier and required service level. Use measured traffic where possible. If the application is new, publish the assumptions beside the estimate and run low, expected, and high scenarios. ...

August 13, 2026 · CDN Handbook

Cache-Control & TTLs: Getting Caching Right

Caching is one of the simplest ways to improve delivery. A cache saves a copy of a response so it can be served without a round trip to the origin. The core control surface is the Cache-Control header and the time-to-live (TTL). Freshness and validation determine when a cache can reuse a stored response and when it must contact the origin. Quick answers max-age sets freshness for private and shared caches. s-maxage overrides max-age in a shared cache such as a CDN. It does not change the browser’s freshness lifetime. Vary tells a cache which request headers selected the response. Each meaningful value can create a separate representation. Vary: * prevents normal reuse because the cache cannot prove that a later request is equivalent. no-cache allows storage but requires validation before reuse. no-store prohibits storage. Freshness vs validation A cache serves a response when it is fresh. Freshness comes from an explicit lifetime such as max-age or from an older Expires date. After freshness ends, a cache either revalidates or fetches again. ...

August 15, 2025 · CDN Handbook

How to Choose a CDN

Why the choice matters A content delivery network (CDN) sits between an origin and clients. It handles caching, routing, and often security. The right provider improves performance and reliability, while the wrong fit can raise costs or limit flexibility. The choice depends on workload, geography, and operational model. Coverage and performance Global reach is uneven. A CDN strong in North America may be weaker in Africa or Southeast Asia. Map the audience by region and compare coverage there. Performance metrics such as latency and throughput matter, but so does stability under peak load. Independent measurement platforms can help validate claims. ...

CDN Handbook

HTTP/3 and QUIC: What Changes for CDNs

Why HTTP/3 matters for CDNs HTTP/3 maps HTTP semantics onto QUIC, which uses UDP instead of TCP. The transport changes connection establishment, loss recovery, connection migration, and operational measurement at a CDN edge. Latency and connection setup QUIC integrates TLS 1.3 into its transport handshake. A full handshake permits application data after one round trip. A resumed connection can send 0-RTT application data when the client has suitable state from an earlier connection and the server accepts it. ...

CDN Handbook

Purging CDN Content: Strategies and Best Practices

What purging is Purging is the process of removing cached objects from a CDN. A purge tells the edge nodes that a file should no longer be served from cache. The CDN will then fetch a fresh copy from the origin the next time a client requests it. Purging differs from TTL expiry. TTLs control how long content is considered valid by default. Purges are active interventions to remove content before it would have expired. ...

CDN Handbook