# How CDNs Work — Caching Strategies & CDN Design

Source: https://www.skillbyai.com/en/caching-strategies/c-how

> Explain edge locations, request routing, origin shielding and tiered caching.

## A cache in every city

A **content delivery network (CDN)** is a globally distributed set of caching servers in **points of presence (PoPs)** close to users. Users are routed to a nearby PoP by **anycast** (the same IP address announced from many locations, with the network choosing the nearest) or **DNS-based** routing. On a **cache hit**, the edge responds directly, often in a few milliseconds; on a **miss**, the edge fetches from your **origin** (a server, load balancer or storage bucket), stores the response according to its cache rules and headers, and serves it. To protect the origin, CDNs use **tiered caching** or an **origin shield**: edge PoPs fetch misses from a regional mid-tier cache rather than all going to the origin, so a popular new object causes one origin request instead of hundreds. CDNs also keep connections to the origin warm, terminate TLS near users, support HTTP/2 and HTTP/3, and compress responses. Examples include Cloudflare, Akamai, Fastly, Amazon CloudFront, Google Cloud CDN and Azure Front Door.

## Edges, shield and origin

Users hit nearby edges; misses go through a shield tier before reaching the origin.

![Many small dots on the outer ring connected to a few medium circles in the middle ring, which connect to a single central origin box.](assets/figures/caching-strategies/section-7-map.svg) — Figure 7.1 — Edge PoPs, an origin shield and the origin.

## Request flow through a tiered CDN

Only one request reaches the origin for a new popular object.

```text
user (Chennai)  -> edge PoP Chennai   MISS -> shield (Mumbai) MISS -> origin   (1 origin fetch)
user (Delhi)    -> edge PoP Delhi     MISS -> shield (Mumbai) HIT
user (Pune)     -> edge PoP Mumbai    MISS -> shield (Mumbai) HIT
user (Chennai)  -> edge PoP Chennai   HIT

without a shield, each PoP's first miss would reach the origin separately
```

## Check the cache status header

Most CDNs add a response header such as `CF-Cache-Status`, `X-Cache` or `Age` that shows hit, miss or expired. Inspect it with browser dev tools or `curl -I` when debugging why something is not cached.

**Quiz:** What is the purpose of an origin shield (tiered cache)?

- [x] Collapsing misses from many edge PoPs into fewer requests to the origin
- [ ] Encrypting data at the origin
- [ ] Blocking all bots
- [ ] Hosting the database

*Answer:* Collapsing misses from many edge PoPs into fewer requests to the origin. A shield tier absorbs edge misses so the origin sees far fewer requests.
