CDN system design case: client → DNS (anycast) → edge PoP (cache + WAF + Worker) → tiered cache (regional + origin shield) → customer origin, with global control plane (config, purge, logs). 5 scenarios: edge cache hit, tiered miss fetch, global purge fan-out, DDoS absorption, video chunked streaming. 2 ADRs: anycast vs GeoDNS, push vs pull CDN. Capacity hints on every node.
This design separates four concerns that are often collapsed into one box: DNS answers, anycast routing, network-layer protection, and HTTP caching. A DNS answer supplies an address. If that address is anycast, BGP selects a site according to routing policy; it is not a per-packet latency oracle and does not guarantee the geographically closest or lowest-RTT PoP. Route convergence and withdrawal are operational processes, not an instant failover primitive.
Vary dimension. Authorization, cookies, locale, compression, and device variants must not be accidentally coalesced.Responses containing private or per-user data are not shared unless an explicit, reviewed policy makes that safe. Cache-Control: private, no-store, authorization rules, and Vary are correctness controls, not tuning hints. Conditional validation with ETag or Last-Modified can turn an expired entry into a small 304 exchange, but it still reaches origin.
Let peak demand be 1,000,000 requests/s, mean public response size be 200 decimal kB, and reusable-cache hit ratio be 95%.
1,000,000 * 200,000 * 8 = 1.6 Tb/s before protocol overhead.1,000,000 * (1 - 0.95) = 50,000 requests/s before conditional validation and request collapse.50,000 * 200,000 * 8 = 80 Gb/s if every miss returns a full body.The origin load is not zero. Hit ratio is workload- and cache-key-specific; personalized traffic, one-hit objects, churn, purges, and revalidation can dominate. A global percentage also hides hot PoPs and hot keys, so capacity planning uses per-PoP and per-key distributions plus origin shielding.
Concurrent misses for the same cache key are collapsed to one fill. Collapse scope must include all variant dimensions, otherwise one representation can be delivered to another caller. The fill leader is not a lock on business state: the origin still needs its own concurrency controls.
Freshness follows HTTP cache semantics. stale-while-revalidate and stale-if-error are bounded permissions, not permission to serve arbitrary old data. Security-sensitive or personalized responses fail closed when validation cannot complete. Immutable, content-addressed asset URLs reduce dependence on global purge completion; HTML and other mutable indexes keep shorter, explicitly chosen freshness windows.
Purge events are authenticated, idempotent, sequenced, and observable. Delivery can be partial, so the control plane tracks acknowledgements and lag. Versioned URLs make a delayed purge a bounded cleanup problem instead of a correctness dependency.
The normal miss is not rendered as an error. Only actual timeout, partial control-plane delivery, abusive traffic rejection, and unsafe early-data rejection use failure styling. Responses traverse the same physical connections in reverse; there are no synthetic reverse edges or origin-bypass shortcuts.
DNS resolution is an explore diagram, so it is linked as a normal viewer route rather than a course directive.
[CASE]video-hostingVary, authorization, freshness, validation, and stale response rules.Введите числа или выберите пресет