Field Notes
All posts

Origin shielding, explained

A CDN with hundreds of locations can hammer your origin with hundreds of identical requests. A shield fixes that.

The thundering herd

A content delivery network caches responses in many locations around the world. When a cached response expires, each location independently fetches a fresh copy from your origin server. With two hundred locations, a single popular page can generate two hundred near-simultaneous requests to the origin every time its cache expires.

For a fast, well provisioned origin, that may be fine. For a database-backed origin under load, it can be the difference between a calm afternoon and an outage.

What a shield does

An origin shield is an additional cache layer placed between the edge locations and the origin. Edge locations that miss their local cache ask the shield instead of the origin. The shield, in turn, fetches from the origin only when it too misses. Two hundred edge misses become one origin request.

Benefits

  • Lower origin load, especially during cache expiry and after purges.
  • Higher overall hit ratio, because the shield accumulates a larger, shared cache.
  • Request collapsing: many shields merge concurrent identical requests into a single upstream fetch.

Costs

The shield adds one more hop for cache misses. If the shield sits far from a particular edge location, a miss there takes slightly longer than it would going directly to the origin. Choose a shield location close to the origin so that the extra hop is short.

When it matters

Shielding has the largest effect when:

  1. Cache lifetimes are short, so expiry is frequent.
  2. Traffic is global, spread across many edge locations.
  3. The origin is expensive per request, such as server-rendered pages backed by a database.
  4. Purges are common, since every purge triggers a wave of refetches.

For a small site with mostly regional traffic, the benefit is modest.

Request collapsing without a shield

Even without a shield, many CDNs collapse concurrent requests for the same uncached URL at each location, sending one request to the origin and holding the others until it returns. Check whether your provider does this by default, and whether it applies to responses that are not cacheable.

Measure the origin

The clearest way to see the effect is to graph requests reaching the origin, not requests served by the CDN. Enable shielding and compare the origin request rate over a few days. A drop of an order of magnitude is not unusual for global sites with short cache lifetimes.