Edge Cache and CDN Platform  ·  View 20 of 29  ·  6 · Operations

Deployment

What runs where: two PoP shapes, four shield pools inside tier-1 sites, two core data centres and a witness.

Editable source SVG draw.io All views
Tier-1 PoP ×6 · IAD DFW FRA LHR SIN NRT Serving Border switches SONiC · FRR · 2× L4 hosts Katran · 2× Edge nodes 6× · 8 × 7.68 TB NVMe Shield pool · IAD DFW FRA LHR Shield nodes 4× · 16 × 7.68 TB Edge-only PoP ×12 Border switches SONiC · FRR · 2× L4 hosts Katran · 2× Edge nodes 3× · 4 × 7.68 TB NVMe Core DC East Control plane · active Control cluster RKE2 · 5 workers Control DB Patroni · sync pair JetStream voter 1 of 3 Telemetry Kafka 3 brokers ClickHouse 3 of 6 nodes Core DC EU Control plane · warm Control cluster standby Control DB standby Patroni standby JetStream voter 2 of 3 Origins · not designed here Tenant origins 40 properties JetStream voter 3 of 3 · DFW compute External probes 12 vantages, other ASNs Transit and IXPs 2 transits per PoP miss streaming Deployment — 18 PoPs, 4 Shield Pools, 2 Core Data Centres Interface / broker Application we own Security / platform Data store Queue / topic External / third party synchronous event / async Shield nodes reach origins over mTLS on the private backbone. Planning ceiling of 20 Gbps per edge node until measured: about 1.4 Tbps nominal against a 400 Gbps peak. v 1.0 · owner Infrastructure · date 2026-09

Decisions

  • Shield pools live inside four tier-1 PoPs: IAD and DFW nearest the eastern origins, FRA and LHR nearest the European ones. Each pair covers for the other, so a shield failover stays on the same continent.
  • JetStream voters are in both core data centres and in DFW's compute, so an acknowledged purge survives the loss of any one site. PostgreSQL uses a synchronous pair in one data centre and an asynchronous standby in the other, which meets the 5-minute RPO without cross-Atlantic synchronous writes.
  • Every PoP has two transit providers and joins its local internet exchange. A PoP with one transit becomes a withdrawal whenever that transit has a bad hour.

Numbers

  • 72 edge nodes, 16 shield nodes, 36 L4 hosts. At a planning ceiling of 20 Gbps per node that is about 1.4 Tbps nominal. The margin covers 2× growth to 800 Gbps, the loss of the largest PoP in a region, and anycast imbalance, which regularly sends two to three times the average share to the busiest PoP.

Assumptions

  • The 20 Gbps per node ceiling is a placeholder. It is replaced by a measured figure per hardware generation at the first load test, and capacity plans use only measured figures after that.