Edge Cache and CDN Platform · View 22 of 29 · 6 · Operations
Decisions
- Nodes boot a signed, read-only A/B image built with mkosi and provisioned by Tinkerbell over the out-of-band network. Nobody logs in to configure a node, so there is no node configuration to drift.
- A node's identity comes from its TPM through SPIRE. A node that cannot attest cannot fetch keys or bundles, so a reimaged or tampered node joins nothing.
- Warm is a separate state from serve. A PoP in cold mode is announced but limited in how hard it pulls from the shield.
Numbers
- Drain window 120 s. Cold-mode shield fetch concurrency 25% of steady state until byte hit ratio passes 80%. Target of 90% of steady byte hit ratio within 4 hours.
Scalability
- Bringing a new PoP into service changes no other PoP's configuration. It is added to NetBox, provisioned, attested and put into a ring. Shield assignment is per origin, not per PoP.