How a CDN works
CloudFront edge delivery
StreamHub production architecture (AWS)
CDN flow
- User requests
cdn.streamhub.com/segments/v_9182/720p/004.ts. - DNS resolves to the nearest edge PoP (point of presence).
- Cache HIT — edge serves file from local SSD; origin never contacted.
- Cache MISS — edge fetches from origin (S3 or origin shield), caches per TTL, serves user.
What to put on a CDN
| Asset type | Cache strategy | StreamHub example |
|---|---|---|
| Video segments (.ts, .m4s) | Long TTL, immutable URLs | HLS/DASH chunks |
| Thumbnails / posters | Medium TTL, purge on update | creator avatars, video posters |
| JS / CSS bundles | Long TTL + content hash in filename | app.v3f2a1.js |
| API responses | Short TTL or no cache | Only public, read-heavy endpoints |
Video segments (.ts, .m4s)
Cache strategyLong TTL, immutable URLsStreamHub exampleHLS/DASH chunksThumbnails / posters
Cache strategyMedium TTL, purge on updateStreamHub examplecreator avatars, video postersJS / CSS bundles
Cache strategyLong TTL + content hash in filenameStreamHub exampleapp.v3f2a1.jsAPI responses
Cache strategyShort TTL or no cacheStreamHub exampleOnly public, read-heavy endpoints
Never cache personalised or authenticated API responses at the CDN without careful Vary headers and cache-key design.
Cache control headers
GET /static/app.v3f2a1.js HTTP/1.1
Host: cdn.streamhub.com
HTTP/1.1 200 OK
Content-Type: application/javascript
Cache-Control: public, max-age=31536000, immutable
ETag: "3f2a1b9c"
GET /segments/v_9182/720p/004.ts HTTP/1.1
HTTP/1.1 200 OK
Cache-Control: public, max-age=86400
Content-Type: video/mp2t
Immutable tells browsers and CDNs the URL will never change content — safe to cache forever. Versioned filenames (app.v3f2a1.js) enable this pattern.
CDN vs origin architecture
StreamHub stores master files in S3. CloudFront (or equivalent) sits in front:
origin:
domain: streamhub-media-prod.s3.amazonaws.com
origin_access_control: enabled # S3 not public; CDN has OAC role
behaviors:
- path_pattern: /segments/*
ttl_min: 3600
ttl_max: 86400
compress: false # video already compressed
- path_pattern: /thumbs/*
ttl_default: 3600
compress: true
| Aspect | Without CDN | With CDN |
|---|---|---|
| Latency (Tokyo user) | 200+ ms to US origin | < 20 ms from APAC PoP |
| Origin load | Every view hits S3 | ~95% served from edge |
| Egress cost | High cross-region S3 egress | CDN bulk pricing |
| DDoS resilience | Origin exposed | CDN absorbs volumetric attack |
Latency (Tokyo user)
Without CDN200+ ms to US originWith CDN< 20 ms from APAC PoPOrigin load
Without CDNEvery view hits S3With CDN~95% served from edgeEgress cost
Without CDNHigh cross-region S3 egressWith CDNCDN bulk pricingDDoS resilience
Without CDNOrigin exposedWith CDNCDN absorbs volumetric attack
Cache invalidation
When a creator replaces a thumbnail, stale edge copies must go.
Invalidation strategies
- Versioned URLs —
thumb_v2.jpginstead of purgingthumb.jpg(preferred). - API purge —
POST /purgewith path list (propagation takes minutes). - Short TTL — accept brief staleness for non-critical assets.
- Surrogate keys — tag related objects; purge by tag (Fastly, Cloudflare).
# CloudFront invalidation (expensive — use sparingly)
aws cloudfront create-invalidation \
--distribution-id E1234567890 \
--paths "/thumbs/u_42/*"
Dynamic content at the edge
Modern CDNs support edge compute (CloudFront Functions, Workers, Lambda@Edge) for:
- A/B routing and geo redirects.
- Token validation before serving premium video.
- Request header normalisation.
Keep edge logic tiny — cold starts and debugging are harder than in central regions.
Measuring CDN effectiveness
Metrics to track:
- cache_hit_ratio (target > 90% for static/video)
- origin_bandwidth (should drop after CDN enable)
- p95 time_to_first_byte by geography
- invalidation count (high = wrong URL strategy)
StreamHub's cache hit ratio on video segments exceeds 94% globally after tuning segment URL immutability.
Quick recall
Everything you need if you only revisit this box.
- CDNs cache content at edge PoPs close to users, reducing latency and origin load.
- Cache immutable assets with long TTL and versioned filenames; purge is a last resort.
- StreamHub serves video segments and static assets from CDN; S3 remains origin.
- Cache-Control headers drive CDN and browser caching behaviour.
- CDNs reduce egress cost and absorb volumetric traffic at the edge.
- Target > 90% cache hit ratio for static and video workloads.
Test yourself
Answer these before moving on — recall is what makes it stick.