Edge Cache and CDN Platform · View 20 of 29 · 6 · Operations
Decisions
- Shield pools live inside four tier-1 PoPs: IAD and DFW nearest the eastern origins, FRA and LHR nearest the European ones. Each pair covers for the other, so a shield failover stays on the same continent.
- JetStream voters are in both core data centres and in DFW's compute, so an acknowledged purge survives the loss of any one site. PostgreSQL uses a synchronous pair in one data centre and an asynchronous standby in the other, which meets the 5-minute RPO without cross-Atlantic synchronous writes.
- Every PoP has two transit providers and joins its local internet exchange. A PoP with one transit becomes a withdrawal whenever that transit has a bad hour.
Numbers
- 72 edge nodes, 16 shield nodes, 36 L4 hosts. At a planning ceiling of 20 Gbps per node that is about 1.4 Tbps nominal. The margin covers 2× growth to 800 Gbps, the loss of the largest PoP in a region, and anycast imbalance, which regularly sends two to three times the average share to the busiest PoP.
Assumptions
- The 20 Gbps per node ceiling is a placeholder. It is replaced by a measured figure per hardware generation at the first load test, and capacity plans use only measured figures after that.