1. What It Is
When egress bandwidth or global latency is the bottleneck, we push static and cacheable content to a CDN edge. Origin servers stay authoritative; edges serve the long tail of reads close to users.
What:
A CDN is a geographically distributed network of edge servers that cache and serve content close to users.
Primary purpose:
Reduce latency and origin load by serving repeated reads from edge PoPs instead of the central datacenter.
Usually used for:
Static asset delivery (JS, CSS, images), video segment streaming, API acceleration, and DDoS protection.
2. Core Mental Model
CDNs trade replicated edge storage for lower RTT and a smaller blast radius on the origin:
π Push Content Closer
Physically reduce the distance packets travel to minimize physical round-trip times (RTT).
πΎ Trade Storage for Latency
Replicate storage capacity globally across hundreds of edge locations to bypass origin lookup times.
π‘οΈ Reduce Origin Pressure
Serve as a buffer that absorbs most read traffic so APIs and databases see only cache misses and uncacheable requests.
In the room
Candidates add a CDN box without saying what's cached. Name cacheable assets (images, JS, video segments), TTL strategy, and cache invalidation on deploy. For dynamic APIs, mention that CDNs help less unless you cache at the edge with surrogate keys.
3. Why It Matters in HLD
CDN moves bytes closer to users β essential when egress bandwidth or global latency dominates. Three lenses:
Needed When:
Users are distributed globally, media files are large (video/images), or you face sudden traffic spikes.
Avoids:
Centralized network bottlenecks, expensive cross-region database lookups, and origin server CPU exhaust.
Optimizes For:
Read latency (Time to First Byte - TTFB), bandwidth/egress costs, and central database availability.
4. Architecture & Data Flow
Walk a cache miss and hit as interview steps. Step 1 β DNS: geo-DNS or Anycast resolves to nearest edge PoP. Step 2 β Edge lookup: PoP checks local cache for the object key. Step 3 β Cache hit: serve from edge β origin never touched. Step 4 β Cache miss: edge fetches from origin shield or origin directly, stores with TTL. Step 5 β Invalidation: purge API or versioned URLs when content changes.
The Request Flow
A client request always hits the Edge PoP first. If there is a miss, it propagates through Shield caches before ever querying your origin server:
In the room
If your napkin math shows 20 GB/s egress, say CDN before drawing more app servers. Interviewers want to see you catch bandwidth walls early.
5. Key Characteristics
Cache TTL, cache key design, and dynamic vs static content determine CDN effectiveness β we compare:
- Edge PoPs: Highly distributed small data centers globally situated inside Internet Service Providers (ISPs).
- Anycast Routing: Routes users to the topologically nearest Edge PoP automatically using the same shared IP address.
- Origin Shields: A high-capacity centralized cache tier protecting the primary backend API from thundering herds.
- Optimized Cache Keys: Defining unique cache identifiers (e.g. omitting tracking tokens) to maximize hit ratios.
- TCP Edge Termination: Ends client connection handshakes close to the user, speeding up subsequent TLS connections.
- Dynamic API caching: Short-TTL edge cache on public GET endpoints (product catalog, config) when responses are identical across users β never cache personalized or auth-gated payloads without key normalization.
- Pull vs push origins: Pull CDNs fetch on first miss (simple, lazy); push CDNs pre-upload assets before traffic arrives (live events, app releases) β pick push when you know the catalog ahead of a spike.
6. Strategic Tradeoffs
Global latency and origin offload cost cache staleness and invalidation complexity β we state both:
| Benefit | Cost |
|---|---|
| Vastly Reduced Latency (TTFB goes from ~300ms to <20ms globally) | Stale Content Risks (cache invalidation lag means users may see outdated state) |
| Origin Cost Protection (offloads 99% of bandwidth and read compute from database/origin) | Additional Egress Fees (commercial CDNs charge per gigabyte of transferred data) |
| DDoS & Spikes Security (absorbs massive traffic floods at edge PoPs) | Cache Invalidation Complexity (purging millions of edge caches is expensive and tricky) |
7. Failure / Bottleneck Awareness
Cache stampede on origin, stale content after deploy, and dynamic API misuse β we volunteer fixes:
Problem: Content is modified at the origin (e.g., user changes their avatar) but Edge PoPs continue serving the old version due to active Time-To-Live (TTL) policies.
Mitigation: Implement event-driven cache purges using unique tags (Cache-Tags) or utilize immutable content-addressable URLs (like adding hashes /avatar.abc123x.png) so new content naturally maps to a new key.
Problem: When a request misses the CDN cache, the user experiences a double-penalty: the time to travel to the edge plus the full transit time to the central origin server.
Mitigation: Pre-warm caches by programmatically hitting new or popular URLs before users request them, and use stale-while-revalidate to immediately serve slightly stale content while fetching fresh data in the background.
Problem: A global purge after a deploy sends every edge miss to the origin at once and can overwhelm the backend.
Mitigation: Enforce request collapsing (locking concurrent misses into a single origin request) and deploy an Origin Shield (Mid-Tier Cache) to aggregate edge requests.
8. Common HLD Usage
Media, static assets, and cacheable API GETs are classic CDN use cases:
| Problem | Usage |
|---|---|
| YouTube Video Playback | Permanent edge-caching of video segments (chunks) near users |
| Instagram Photo Loading | High-availability caching of versioned user photos globally |
| E-commerce Product Catalogs | Edge-caching of static product descriptions and images with short TTL |
| Web App Shells (React/Vue builds) | Caching static index.html, JS bundles, and CSS stylesheet assets |
| Global Dynamic APIs | Edge routing optimization and TCP termination to reduce round-trip times |
9. Decision Signals
Reach for CDN when back-of-envelope egress math exceeds single-origin capacity:
- Your users are distributed globally, causing poor performance in distant countries.
- You are building media-heavy platforms (Netflix, Instagram, TikTok, YouTube).
- Your reads outnumber your writes by a huge ratio (e.g. 100:1 or more).
- You require robust, edge-level security filters (Web Application Firewall, WAF) to block bad bots.
- You have highly structured, public metadata that remains static for minutes to days.
11. Deep Dive (Optional)
Cache Key Normalization & Vary Headers
The primary way to optimize CDN hit ratio is normalized cache keys. If clients send varied query params (like tracking analytics tokens: ?utm_source=x), the CDN will treat each as a separate key, dropping your hit ratio to 0%.
Normalization: At the edge, the proxy rewrites incoming request keys, stripping tracking parameters and sorting the remaining arguments before checking the cache.
Vary Headers: When serving dynamic responses (like compression formats gzip vs brotli), the origin returns Vary: Accept-Encoding. This instructs the CDN to cache distinct variants for the exact same URL based on the client's capabilities.
Anycast Routing Mechanics
Anycast is a network routing technique where multiple physical machines globally advertise the exact same IP address using the BGP (Border Gateway Protocol) routing mesh. When a user requests your site, internet routers naturally forward the packets to the topologically closest hop. This ensures instant hardware-level routing near users without geo-DNS delays.
Edge Compute & Serverless Functions
Modern CDNs (Cloudflare Workers, Fastly Compute, AWS Lambda@Edge) allow running lightweight JavaScript/Rust code directly inside Edge PoPs. Rather than just returning cached files, you can execute logic at the edge: (1) authenticating API tokens, (2) performing A/B testing splits, (3) dynamically resizing images, or (4) stitching personalized HTML templates (SSI) with sub-20ms latencies.
Signed URLs & HMAC Security
For paid or private content (e.g. Netflix movies or Dropbox files), you cannot expose public URLs. CDNs secure content with Signed URLs: the origin generates a temporary access URL containing an expiration timestamp and a cryptographic HMAC signature. The Edge PoP validates the signature locally without contacting the origin, immediately blocking hotlinking or unauthorized sharing.
Review
How helpful was this walkthrough?
Click a star to rate. We actively use this feedback to refine and update our system design content.
Discussion
Share your thoughts, ask questions, or help others.