Home/Labs/Anycast CDN Edge
All 280 Labs
INTERACTIVE LAB🌐

Anycast CDN Edge Lab (Interactive)

Sweep QPS, PoPs, and hit ratio to count origin escapes, shield the herd, purge fast. Model CDN edge caching with anycast routing, origin-shield miss collapsing, and tag-based global purge propagation.

Global CDN Edge: Hit Ratio, Origin Shield & Purge Propagation

Tune traffic and cache efficiency, then watch how many requests actually escape to the customer origin.

Edge hits9.50Mserved locally
Origin QPS50.0kshielded / survivable
Avg TTFB13.4 msSLA < 10 ms p99
Egress40 Tbps@ 500 KB avg object
Cold-URL herd1→originfrom 300 PoPs missing at once
Cache control directives (edge response)
Cache-Control: public, max-age=31536000, immutable
Surrogate-Control: max-age=3600
Surrogate-Key: product_9918 brand_nike
# purge `/images/*` or tag product_9918 -> pub/sub fan-out to all 300 PoPs

purge propagation < 150 ms global (tag-indexed invalidation, no TTL wait)

At 10M QPS and a 95% hit ratio, 50.0k requests still escape to the origin every second. With the shield on, the regional aggregator absorbs the 500.0k raw misses down to a trickle; with it off, a single cold or just-purged URL triggers a thundering herd where all 300 PoPs stampede the customer origin simultaneously. Anycast makes the routing invisible — one global IP advertised by every PoP, and BGP pulls each user to the topologically nearest node — so the two numbers that decide whether a CDN is good are the hit ratio that keeps TTFB near 0.5 ms and the shield that keeps origin load survivable.

How It Works Under the Hood

A CDN lives or dies on the cache hit ratio: at 50M ingress QPS and 95% hits, 2.5M requests per second still escape to customer origins, and a just-purged or cold URL triggers a thundering herd where all 300-plus PoPs stampede the origin at once. An Origin Shield regional aggregator collapses those cross-PoP misses so the origin sees only a fraction. Anycast — one global IP advertised by every PoP through BGP — silently routes each user to the topologically nearest node, giving sub-10 ms TTFB without DNS geofencing. Purge propagation over a pub/sub tag index must invalidate globally in under 150 ms.

Core Architectural Principles

  • Origin QPS = ingress x (1 - hit_ratio); the shield collapses cross-PoP misses about 90% before the origin.
  • Cold-URL herd: without a shield, all N PoPs fetch the same object simultaneously.
  • Tag-based purge with Surrogate-Key fans out over pub/sub and completes in under 150 ms globally.
Interview Round Script

Structure it as anycast routing, then the PoP cache hierarchy of RAM then NVMe, then origin shield, then purge. Emphasize hit ratio as the core SLA and the origin shield as thundering-herd protection. Explain tiered caching and BGP anycast for nearest-PoP without geo-DNS. Cover purge semantics of URL, wildcard, and tag, the sub-150 ms propagation SLA, and DDoS absorption at the edge.

Key Trade-Offs

Aggressive caching and origin shielding slash latency and origin load but lengthen staleness windows and complicate purge correctness.

Related Curriculum Chapter

Design a Custom Content Delivery Network (CDN)

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs