Edge Cache and CDN Platform  ·  View 22 of 29  ·  6 · Operations

The PoP Lifecycle

The seven states a PoP passes through, and the check that must pass before it moves to the next.

Editable source SVG draw.io All views
Provision signed image · A/B Attest TPM → SPIRE Reconcile config + purge log Warm cold-mode fetch cap Serve all classes announced Drain GOAWAY · 120 s Withdrawn BGP silent PoP lifecycle image booted SVID issued caught up byte hit ratio ≥ 80% maintenance or fault window closed work done The PoP Lifecycle — Nothing Serves Until It Has Caught Up Security / platform Application we own Decision point Opportunity Risk / gap v 1.0 · owner Network Engineering · date 2026-09

Decisions

  • Nodes boot a signed, read-only A/B image built with mkosi and provisioned by Tinkerbell over the out-of-band network. Nobody logs in to configure a node, so there is no node configuration to drift.
  • A node's identity comes from its TPM through SPIRE. A node that cannot attest cannot fetch keys or bundles, so a reimaged or tampered node joins nothing.
  • Warm is a separate state from serve. A PoP in cold mode is announced but limited in how hard it pulls from the shield.

Numbers

  • Drain window 120 s. Cold-mode shield fetch concurrency 25% of steady state until byte hit ratio passes 80%. Target of 90% of steady byte hit ratio within 4 hours.

Scalability

  • Bringing a new PoP into service changes no other PoP's configuration. It is added to NetBox, provisioned, attested and put into a ring. Shield assignment is per origin, not per PoP.