पाठ 21 / 25

Dynamic Content, Edge Compute and Security

Cache APIs and personalised pages carefully, and use the CDN as a security layer.

Beyond static files

CDNs can do much more than serve images. Dynamic but shared content, such as API listings, product pages and search results for common queries, can be cached for seconds to minutes with s-maxage and stale-while-revalidate; even a 10-second TTL absorbs huge spikes (micro-caching). Personalised content can be split: cache the shared page shell at the edge and load the personalised parts (name, cart count) with a separate private request, or assemble fragments at the edge. Edge compute platforms (Cloudflare Workers, Fastly Compute, CloudFront Functions and Lambda@Edge, Akamai EdgeWorkers) run code at PoPs to rewrite URLs, normalise cache keys, run A/B tests, check tokens or serve responses entirely from the edge. CDNs are also a security layer: they absorb DDoS attacks, apply web application firewall rules and bot management, and hide the origin, which should accept traffic only from the CDN (by IP allow-lists, secret headers or authenticated origin pulls). Signed URLs or cookies protect paid or private content at the edge.

Micro-caching an API at the edge

A 10-second shared cache turns 5,000 requests per second into at most a few origin requests per PoP every 10 seconds.

GET /api/trending HTTP/1.1
Host: shop.example.com

HTTP/1.1 200 OK
Cache-Control: public, max-age=0, s-maxage=10, stale-while-revalidate=30, stale-if-error=300
Content-Type: application/json

# browsers always revalidate (max-age=0)
# the CDN serves one copy for 10 s, refreshes in the background for 30 s,
# and keeps serving the last good copy for 5 minutes if the origin fails

Lock the origin to the CDN

If attackers can reach the origin directly, the CDN's DDoS protection and WAF are bypassed. Restrict the origin's firewall to the CDN's published IP ranges or require an origin authentication mechanism.

त्वरित जाँच: A news site gets a sudden spike on its home page, which changes every minute. What edge setting helps most?

  • Cache-Control: no-store
  • Removing the CDN
  • Micro-caching with a short s-maxage plus stale-while-revalidate
  • Varying the cache on the User-Agent header
Answer

Micro-caching with a short s-maxage plus stale-while-revalidate — Even a few seconds of shared caching collapses a spike into a handful of origin requests.