Skip to main content
OPTIONS applies to every request for the hostname. RULES overrides that behavior where the URI matches a path or a regular expression, and only for the options placed on the rule. Anything the rule does not mention stays as set under OPTIONS.

OPTIONS

General

Files are pulled from an origin group. Origin pull sets the protocol to HTTP, HTTPS, or both, and selects the group. The sources in the group are edited in origin groups.
Content availability, origin pull protocol, and origin group
To keep every edge from calling that origin, Origin Shielding places one precache server in front of it. A hit is served from the shield, and the origin is contacted on a miss. Brotli, under Content, has no effect until the shield is enabled. Connection timeouts limit how long an edge waits to open a connection to the origin, and how long it waits for the next bytes of the response. Content availability is the switch for delivery. While it is on, content is available to customers. The name viewers request is fixed after the resource is created: a custom domain, or a name in the gcdn.co zone. They reach it with a Let’s Encrypt certificate, which renews automatically, or with a custom certificate. HTTP/3 applies only while HTTPS is on. DNS-01 matters only when the HTTP challenge cannot reach the hostname.

Cache

CDN caching is the edge lifetime. Browser caching is the lifetime in the viewer’s browser. Changing one leaves the other as it was. A different lifetime for one path belongs on a rule.
CDN caching, redirection from origin, and browser caching
The same file with a different query string, or with a Set-Cookie header, can be stored once or many times. Ignoring the query string or Set-Cookie keeps one object. The cache key names the request parts that must be stored apart, and changing that key drops the copies already stored. A redirect from the origin is stored and returned as a redirect. Origin redirects follow the selected codes and store the target instead. When the origin cannot return a fresh object, Always online can serve one that is already cached.

Access

Access policies filter by country, referrer, IP address, or user agent. Allow by default rejects only the listed values. Block by default accepts only those values. A secure token goes further and ties the URL to a time limit or to an allowed IP address.
Country access policy, referrer access policy, and redirect from HTTP to HTTPS
HTTP requests can follow an HTTPS redirect. Methods the hostname should not serve are limited under HTTP methods. SNI hostname and TLS versions sit together and apply to different ends of the path. SNI is the name sent to the origin during its handshake, and only when the pull uses HTTPS. Dynamic follows the Host header. Custom sends a name set for the origin. TLS versions limit what a viewer may use to reach the hostname.

Content

A status code can replace the origin response for every request. The same replacement for one path is a rule.
Status code, Gzip compression, and Brotli compression
Uncompressed text can be compressed at the edge. Edge compression does that with Gzip or Brotli, and Brotli requires Origin Shielding. On the resource, or inside one rule, that compression cannot run together with Fetch compressed, which pulls files the origin already compressed, or with large files, which delivers big objects in parts. The path the origin sees can differ from the path the viewer used. Rewrite changes it before the fetch, or returns a redirect. WebSockets proxy an open connection to the origin. A token on a playlist does not reach the files inside it on its own. Query forwarding copies the query parameters onto those URLs.

HTTP headers

On the way to the origin, the CDN can add request headers and can set which site a shared server should answer. That site is the host header: the hostname the viewer requested, or one fixed value on every origin request.
Request headers, CORS header support, and response headers
The response back to the viewer is a separate edit. A CORS header lets the browser accept the response from this hostname. Response headers can be added on that response, or hidden when the origin sent them.

Network limits

A large file can occupy a connection for the whole transfer. Download speed holds each connection to a lower rate, either one rate for every connection or a rate taken from the request.
Download speed limit

Optimization

Image Stack can change the quality, format, or size of a JPG or PNG on the way to the viewer. The file on the origin stays as it was. Enabling it for every request conflicts with Rewrite when the origin also serves other files. A rule can limit the processing to image paths.
Image Stack

Security

WAAP inspects requests and can block malicious ones before they reach the origin. The switch stays disabled until a WAAP plan is active. Rate limiting, marked BETA, only caps how many requests one IP address can send. Bot protection is a paid control on the same form.
WAAP, rate limiting, and bot protection

FastEdge apps

FastEdge applications run during CDN processing and can change the request or the response. Each stage of that processing accepts one application.
FastEdge apps

RULES

A path that should not follow the resource settings needs a rule. The rule matches a URI path or a regular expression, and its pull protocol can stay inherited or be set to HTTP, HTTPS, or both. When several rules match one URI, the rule listed first applies. Create rule starts blank or from a template. A template already holds a path, a pull protocol, and the options to override. Rule templates include system presets for playlists, video segments, static content, the Let’s Encrypt HTTP-01 challenge, and Image Stack. A system template opens as a read-only view of that preset.
System rule templates