CDN Glossary

Comprehensive definitions of CDN terminology, caching concepts, and industry jargon.

A

AAAA Record

An AAAA record (DNS type 28, spoken "quad-A") maps a hostname to one 128-bit IPv6 address, the IPv6 counterpart of the A record's 32-bit address. Publish it alongside the A record for dual-stack delivery; without it, IPv6-only clients reach you only through a NAT64/DNS64 translator.

DNS

ABR (Adaptive Bitrate)

ABR encodes one video as several renditions and lets the player choose, segment by segment, which to fetch for the current network and device. It is a technique, not a protocol or codec: HLS and DASH carry it, the client decides, and the CDN caches every rendition separately.

Streaming

Access Time

Access time is how long a storage device takes to locate and return data, excluding the transfer itself. A random read costs roughly 13 ms on a 7,200 RPM disk, tens of microseconds on SSD and about 100 ns in RAM. On a CDN cache hit it sets the floor under TTFB.

Performance

ACME (Automated Certificate Management)

ACME (Automatic Certificate Management Environment) is the IETF protocol in RFC 8555 that automates issuing, renewing and revoking TLS certificates: a client proves control of a domain to a CA's ACME server, which issues a domain-validated certificate. It is the protocol behind Let's Encrypt.

Security

Age Header

The Age response header is a cache's estimate, in seconds, of how long ago the origin generated or last validated the response being served. Caches generate it, not the origin, and the value accumulates across every cache in the path. A response is stale once Age reaches its freshness lifetime.

Caching

ALPN (Application-Layer Protocol Negotiation)

A TLS extension (RFC 7301): the client lists the application protocols it supports in the ClientHello and the server returns exactly one, so the protocol is settled inside the TLS handshake with no extra round trip. Common identifiers are h2, http/1.1, h3 over QUIC and acme-tls/1.

Protocol

Anycast

Anycast announces one IP address from many locations at once; the routing system, usually BGP, delivers each packet to whichever instance it computes as closest. It is not DNS-based server selection and not a load balancer, and routing-closest is not the same as lowest latency.

Networking

API Gateway

An API gateway is the single front door for API traffic: a reverse proxy that authenticates callers, applies quotas, routes each request to the right backend service, and can transform and cache responses. It is an architecture pattern, not one product. CDNs run parts of it at the edge.

Architecture

A Record

An A record is the DNS record type that maps a hostname to one 32-bit IPv4 address, such as 192.0.2.53. RFC 1035 defines it as type 1, 'a host address'. It is data, not an alias like a CNAME, and it is IPv4 only - IPv6 uses AAAA. CDN routing in DNS ends in the A record a resolver returns.

DNS

Autonomous System (AS)

An Autonomous System (AS) is a connected group of IP prefixes run by one or more operators under a single, clearly defined routing policy, identified by a globally unique AS number (ASN) and joined to other ASes by BGP. CDNs, ISPs and multi-homed enterprises each run their own AS.

Networking

B

Bandwidth

Bandwidth is the maximum rate a network link can carry data, in bits per second (Mbps, Gbps). It is capacity, not traffic: throughput is the rate that actually moves, latency is trip time, and on an invoice “bandwidth” usually means the bytes you transferred.

Performance

BBR (Bottleneck Bandwidth and RTT)

A congestion control algorithm from Google that measures a path's bottleneck bandwidth and minimum round-trip time, then paces data at that modelled rate instead of raising the rate until packets drop. Sender-side only, implemented for TCP and QUIC. It keeps queues shallow rather than full.

Networking

BGP (Border Gateway Protocol)

BGP (Border Gateway Protocol, currently BGP-4) is the internet's inter-autonomous-system routing protocol: networks announce the IP prefixes they can reach and choose the path traffic takes between them. It carries no latency or load data, but it is what makes CDN anycast work.

Networking

Brotli

Brotli is a lossless compression format from Google, specified in IETF RFC 7932 and carried on the web as the "br" HTTP content coding. Google measured a 13-21% higher compression ratio than deflate at equal quality, paid for in encoder time, not decode speed. Every current major browser accepts it.

Compression

Byte Range Request

An HTTP GET whose Range header asks for part of a resource, not the whole body — the basis of video seeking, resumable downloads and parallel chunk downloads. A server that honours it replies 206 Partial Content with a Content-Range slice; 416 if nothing is satisfiable, 200 if it ignores Range.

Protocol

C

Cache Busting

Giving a web asset a new URL whenever its content changes, so every cache treats it as a new object and fetches it. It deletes nothing: a version query string (?v=2) or, more reliably, a content hash in the filename (style.a1b2c3.css) simply stops matching the old cache entry.

Caching

Cache-Control

Cache-Control is the HTTP header field, defined in RFC 9111, that carries caching directives to browsers, proxies and CDNs: whether a response may be stored, by which caches, how long it stays fresh, and what a cache must do once it goes stale.

Caching

Cache Fill

A cache fill is the fetch-and-store after a cache miss: the cache pulls the resource from upstream (origin or shield tier) and stores it so a later request is a hit. The miss is not the fill, and a 304 revalidation is not a fill. Fills are the traffic that still costs origin bandwidth and latency.

Caching

Cache Hit Ratio (CHR)

The share of requests a cache answers from its own stored copies instead of fetching from the origin: hits ÷ (hits + misses). A cache hit ratio of 95 percent means 95 requests in 100 never reached the origin. It measures offload and cost, not how close to the user a response was served.

Caching

Cache Key

The cache key is the identifier a cache derives from a request to decide which stored response, if any, may serve it. HTTP composes it from the request method and target URI, extended by the fields a response’s Vary header names; CDNs add or drop query parameters, headers and cookies on top.

Caching

Cache Miss Types

A cache miss is a request an edge node cannot answer from its own cache. Practitioners name four causes: never fetched (cold/compulsory), evicted for space (capacity), purged or expired (invalidation), or cached at another PoP (fragmentation). Each needs a different fix.

Caching

Cache Stampede

A self-inflicted flood of origin requests: a hot cached object expires or is evicted, every concurrent request for it misses at the same moment, and the origin takes that object's whole request rate in one burst. Request coalescing and stale-while-revalidate prevent it.

Caching

CDN (Content Delivery Network)

A geographically distributed network of edge servers that cache copies of a site's content close to users and answer each request from a nearby node. It cuts latency, offloads the origin and can absorb spikes and attacks. It is not a web host: the origin keeps the definitive copy.

Architecture

CMAF (Common Media Application Format)

CMAF (ISO/IEC 23000-19) is the MPEG standard for packaging segmented media so one set of fragmented-MP4 objects serves both HLS and DASH: encode, store and cache once, and two manifests point at the same files. Not a protocol and not a codec; its chunks underpin low-latency live streaming.

Streaming

CNAME

A DNS record that makes one hostname an alias of another: its value is the canonical name, always a domain name and never an IP address. CDNs use it to hand resolution of your hostname to the provider. It may share its name with no other record type, so it cannot sit at the zone apex.

DNS

Cold Cache

A cold cache holds no reusable stored responses, so requests miss and go to the origin until misses refill it. New edges and POPs, restarts of volatile storage, purges and evictions cause it; while cold, origin load and latency rise. A transient state of one store, not a failure.

Caching

Compression

An HTTP content coding that shrinks a message body, almost always a response body, so the same content crosses the network in fewer bytes and the recipient decodes it back exactly. gzip, Brotli and zstd are the common codings. Text gains a lot; already-compressed media gains little.

Compression

Consistent Hashing

Consistent hashing assigns cache keys to nodes on a hash ring so that most assignments survive a change in the node set: adding or removing one node in a pool of N remaps roughly 1/N of the keys instead of nearly all of them. CDNs use it to shard caches and keep them warm across resizes.

Architecture

Content-Encoding

The HTTP header naming the content codings applied to a body (gzip, br, zstd), which the recipient must undo to recover the media type in Content-Type. Chosen by Accept-Encoding negotiation; not Transfer-Encoding; cached variants stay apart only via Vary: Accept-Encoding.

Compression

Content Negotiation

The HTTP mechanism that lets one URL serve several representations of a resource: the client advertises what it accepts in Accept, Accept-Encoding and Accept-Language, and the server selects one. Shared caches such as CDNs must key on the headers named in the response's Vary.

Protocol

CORS

Cross-Origin Resource Sharing: the browser-enforced protocol in the WHATWG Fetch Standard by which a server opts in to letting scripts on other origins read its responses, chiefly via Access-Control-Allow-Origin. It constrains the browser, not the server, so it is not access control.

Security

CSAI (Client-Side Ad Insertion)

CSAI (client-side ad insertion) is ad serving where the player, not the server, fetches and plays each ad: at a cue it pauses the content, requests an ad over HTTP (usually VAST), plays it in a separate ad element, then resumes. The CDN serves the same stream to all viewers. Counterpart of SSAI.

Streaming

CSP (Content Security Policy)

CSP (Content Security Policy) is an HTTP response header telling the browser which origins a page may load each resource type from and what script may execute. Browser-enforced defence-in-depth against XSS and content injection — not a WAF, and no replacement for output encoding.

Security

CWND (Congestion Window)

The congestion window (cwnd) is the TCP sender’s own limit on how much unacknowledged data it may have in flight. It is not the receiver’s advertised window — the smaller of the two governs — and because throughput is roughly cwnd ÷ RTT, it caps how fast one connection can go.

Networking

D

DASH (Dynamic Adaptive Streaming over HTTP)

DASH (MPEG-DASH) is the open ISO/IEC 23009-1 standard for adaptive bitrate streaming: an XML manifest, the MPD, lists the quality levels, and the player fetches media segments — in practice fragmented MP4 — over ordinary HTTP. The vendor-neutral counterpart to Apple's HLS.

Streaming

DDoS (Distributed Denial of Service)

A DDoS attack makes a site unavailable by aiming more traffic or work at it than it can handle, from many sources at once. It is not a data breach: the goal is downtime, not theft. CDNs scatter the flood across their anycast edge and filter it there, so only clean traffic reaches your origin.

Security

DNS (Domain Name System)

The distributed, hierarchical naming system that resolves names like example.com to addresses. A query-response lookup service, not a routing protocol. For a CDN it is also the steering plane: the authoritative nameserver picks which edge address to return, and the TTL caps how fast that changes.

DNS

DNSSEC (DNS Security Extensions)

DNSSEC is a set of DNS extensions that sign zone data so a validating resolver can prove an answer came from the zone that owns the name and was not altered. It stops spoofing and cache poisoning, but only where the zone is signed and the resolver validates; it does not encrypt queries.

DNS

DNS TTL

The number of seconds a DNS record may be cached before the source must be consulted again. Set by the zone administrator, it is a maximum, not a purge: lowering it never clears copies already cached. Not HTTP cache TTL (Cache-Control max-age).

DNS

DoH (DNS over HTTPS)

DNS over HTTPS (DoH), defined in RFC 8484, carries each DNS query and answer inside an HTTPS request to a resolver URL instead of a plaintext port-53 packet, encrypting and authenticating the stub-to-recursive hop. It hides lookups from on-path devices; unlike DNSSEC it does not sign them.

DNS

DoT (DNS over TLS)

DNS over TLS (DoT) carries ordinary DNS messages inside a TLS connection on TCP port 853, per RFC 7858 as updated by RFC 8310. It encrypts only the stub-to-resolver hop, so it is not end-to-end, gives no answer integrity, and your resolver still sees every query.

DNS

DVR Window

The DVR window is how far back from the live edge a viewer can seek in a live stream. It is whatever the manifest still lists: a sliding HLS media playlist, or a DASH time shift buffer of MPD@timeShiftBufferDepth. Every segment inside it must stay fetchable, so it sizes the CDN's live footprint.

Streaming

E

ECDHE (Elliptic Curve Diffie-Hellman Ephemeral)

ECDHE is TLS key agreement over an elliptic curve using a fresh, ephemeral key pair per handshake, so a later leak of the server's long-term private key cannot decrypt sessions recorded earlier: forward secrecy. Every TLS 1.3 certificate handshake uses it; TLS 1.2 signs it with RSA or ECDSA.

Security

ECDSA (Elliptic Curve Digital Signature Algorithm)

ECDSA is the elliptic-curve digital signature algorithm standardised in FIPS 186-5, used to authenticate TLS certificates and handshakes. It only signs and verifies: it never encrypts or exchanges keys. P-256 gives 128-bit security with far smaller keys than RSA-3072, and signs far more cheaply.

Security

ECMP (Equal-Cost Multi-Path)

Equal-Cost Multi-Path (ECMP) is a forwarding technique: where a router holds several next hops of equal cost to one destination, it hashes a packet's flow fields to pick one, so every flow keeps one path. It turns existing path diversity into capacity and failover in the router, not a load balancer.

Networking

Edge Function

Serverless code a CDN runs on its edge servers, inside the request path, instead of at the origin. It rewrites requests and responses, authorises users, normalises cache keys, and can answer a request at the edge. Each CDN ships its own runtime, so code rarely ports unchanged.

Architecture

Edge Server

An edge server is one of the caching reverse-proxy machines inside a CDN Point of Presence: it terminates the visitor's TLS connection, answers what it can from its own cache and fetches the rest from the origin. It is not the origin, not the whole PoP, and not the CDN itself.

Architecture

Egress

Egress is the volume of data leaving a network, metered per gigabyte in volume-stepped tiers as "data transfer out" (AWS) or "internet egress" (Azure). It is not bandwidth (a rate, not a volume) and not ingress (inbound, listed free). A CDN splits it across two or three separate meters.

Networking

ESI

Edge Side Includes: a declarative XML markup language, published as a W3C Note in 2001, that lets a CDN edge server assemble one page from separately fetched fragments. Each fragment keeps its own TTL, so a mostly static page stays cacheable and only its dynamic fragments reach the origin.

Architecture

ETag

An HTTP response header carrying an entity tag: an opaque validator identifying one version of one representation. A client or CDN sends it back in If-None-Match, and a match returns 304 Not Modified instead of the body. Strong tags mean byte-identical, weak tags (W/) only equivalent.

Caching

H

HAR (HTTP Archive)

A HAR (HTTP Archive) file is a JSON record of every HTTP request and response a browser made during a page load, with status, headers, sizes and per-phase timings. It is the de-facto way to share a network trace: not a published standard, and only ever the client's view.

Performance

HLS (HTTP Live Streaming)

HLS (HTTP Live Streaming) is Apple's adaptive-bitrate streaming protocol, published as RFC 8216: an encoder cuts media into short segments, a playlist file lists them, and the player fetches the rendition its connection sustains over plain HTTP. A delivery format, not a codec and not DRM.

Streaming

HSTS

HTTP Strict Transport Security. A header a site sends over HTTPS to order a conforming browser to use only HTTPS for that host for a set time. It blocks protocol downgrade and redirect tampering on later visits; it encrypts nothing itself and cannot protect a first visit unless preloaded.

Security

HTTP/1.1

HTTP/1.1 is the text-based version of HTTP, first published in January 1997 and defined today by RFC 9112. It adds persistent connections, chunked transfer coding and a mandatory Host header, but carries one response at a time per connection. CDNs still use it on the hop to origin.

Protocol

HTTP/2

Version of HTTP that carries many concurrent request/response streams over one TCP connection and compresses header fields with HPACK, so clients no longer need parallel connections. HTTP semantics are unchanged and TCP head-of-line blocking remains. RFC 9113; ALPN token "h2" over TLS.

Protocol

HTTP/3

HTTP/3 is the third major version of HTTP (RFC 9114, June 2022). It runs on QUIC over UDP instead of TCP, with TLS 1.3 or later built in. Connection-wide head-of-line blocking is gone, setup usually takes one round trip, and a live connection survives a change of network.

Protocol

HTTP Redirects

A 3xx response that sends the client to a different URL, named in the Location header, instead of returning the content it asked for. Each redirect costs a full round trip, and a chain pays that cost once per hop before anything renders.

Protocol

I

Image Optimization

Image optimization is delivering each image in the fewest bytes that still look right: re-encoding to a modern format such as WebP or AVIF, resizing to the size the page displays, tuning encoder quality, and stripping metadata. A CDN keeps one master and derives a cached copy per request.

Performance

Internet Exchange Point (IXP)

An Internet Exchange Point (IXP) is a neutral facility where many networks connect to a shared Layer 2 switching fabric and peer directly, cutting out transit providers. The IXP does not route traffic itself. CDNs peer at IXPs to reach many ISPs over one port, lowering latency and cost.

Networking

IOps (I/O Operations Per Second)

IOPS (I/O operations per second) is the rate at which a storage device completes read and write operations. It counts operations, not bytes: throughput equals IOPS times the I/O size. It binds small random access, where a 7,200 rpm HDD is rated in the hundreds and datacentre NVMe above a million.

Performance

IPv4

IPv4 is version 4 of the Internet Protocol (RFC 791): 32-bit addresses written as four dotted decimal octets, such as 192.0.2.1, giving 2^32 (about 4.3 billion) values. Exhaustion of the free pools forced address sharing, so one public IPv4 address no longer means one user.

Networking

IPv6

Internet Protocol version 6, the successor to IPv4 (RFC 8200). Addresses are 128 bits, written in hex like 2001:db8::1, so scarcity and address-conserving NAT fall away. A CDN publishes them as AAAA records so IPv6-only clients reach the edge directly instead of through a NAT64 translator.

Networking

L

L4 Load Balancing

L4 load balancing spreads a service's connections across several servers, choosing each backend from the transport-layer header alone: source and destination IP and port, plus protocol. It never reads the payload, so it cannot route by URL, header or cookie, and one connection stays on one server.

Networking

L7 Load Balancing

Load balancing at layer 7 of the OSI model, the application layer: the balancer parses each HTTP request and picks a backend by content (path, host, headers, query, cookies) rather than by IP and port. It terminates the client connection and proxies to an origin, so it costs more CPU than L4.

Networking

Last Mile

The last mile is the final access link between a service provider and the user's premises: copper, coaxial, fibre or radio. It is typically the bandwidth bottleneck of a path and the one segment a CDN cannot widen; behind a CDN it runs from the user to the nearest edge, not to the origin.

Networking

Latency

Latency is the time data takes to travel from one point on a network to another, in milliseconds; in practice it is quoted as round-trip time. It is delay, not capacity: distance and the number of round trips set it, so a nearby edge cuts it and extra bandwidth does not.

Performance

LL-DASH (Low-Latency DASH)

Low-latency mode of DASH, not a separate protocol: each CMAF segment is cut into small chunks and streamed in one HTTP/1.1 chunked response while it is still being written, so the player decodes before the segment is complete. Takes glass-to-glass latency from tens of seconds to a few.

Streaming

LL-HLS (Low-Latency HLS)

Apple's low-latency mode for HLS. The packager publishes sub-second partial segments (EXT-X-PART) that players render before the parent segment is finished, and preload hints plus blocking playlist reloads replace polling, cutting live delay from 18-30 seconds to roughly 3-5.

Streaming

LRU Cache

LRU (least recently used) is a cache eviction policy: when the cache is full, it discards the object that has gone longest without a request. It decides which object leaves when space runs out, not whether a copy is still fresh, so an LRU eviction can drop an object whose TTL has hours left.

Caching

M

Manifest File

A manifest file is a stream's table of contents, fetched before any media: it lists the quality variants, segment URLs, codecs, timing and where to get decryption keys. HLS calls it a playlist (.m3u8), DASH a Media Presentation Description (.mpd). Without a valid manifest, playback cannot start.

Streaming

max-age

max-age is a Cache-Control response directive giving the seconds a stored response may be reused before it is stale, counted from when the origin generated it. It binds every cache in the chain — browser, CDN, reverse proxy — and permits reuse; it is not an eviction timer.

Caching

Middle Mile

The network path between a CDN's edge and the origin, plus the hops between the CDN's own sites. It is crossed only when the edge cannot answer, so it governs cache misses and uncacheable traffic. Not the last mile to the user, and not the origin itself.

Networking

mTLS

Mutual TLS: a TLS handshake in which the server also asks the client for a certificate, so both ends prove their identity with an X.509 certificate instead of only the server. CDNs use it edge-to-origin, so only the CDN can fetch from the origin, and viewer-to-edge to authenticate API clients.

Security

Multi-CDN

Multi-CDN is delivering one property's content through two or more independent CDN providers, with a steering layer choosing which provider answers each request. It is not one CDN with more capacity, and not failover alone: two contracts without steering are two single-CDN setups.

Architecture

must-revalidate

must-revalidate is a Cache-Control response directive (RFC 9111): once a stored response goes stale, any cache — browser or CDN — must revalidate it with the origin before reusing it, and must return an error (normally 504) rather than fall back to the stale copy if the origin is unreachable.

Caching

P

P2P Hybrid Streaming

P2P hybrid streaming adds a viewer-to-viewer mesh to a CDN: once a device holds a video segment it re-uploads it to other viewers over WebRTC data channels, so one edge fetch serves many. The CDN edge stays seed and fallback. It pays off on concurrency, not on long-tail VOD.

Architecture

P95/P99 Percentiles

P95 and P99 are latency percentiles: the times 95% and 99% of requests beat, so the slowest 5% and 1% exceed them. They are order statistics read off the sorted list of response times, not an average, a rate, or a maximum. They describe the slow tail an average hides.

Performance

Peering

Peering is a voluntary direct interconnection between two autonomous systems, letting them exchange traffic without paying a transit provider. It is usually settlement-free, over a public Internet exchange fabric or a private cross-connect. CDNs peer to shorten the path to ISPs and cut cost.

Networking

Point of Presence (PoP)

A Point of Presence (PoP) is one location where a network keeps its own servers, routers and interconnects so it can exchange traffic with other networks — for a CDN, the edge site serving a city or region. It is not a single machine, not the whole data centre, and not the origin.

Architecture

Preconnect

Preconnect is a resource hint that asks the browser to open a connection (DNS, TCP and, for HTTPS, TLS) to a cross-origin host before the first request needs it, so that request skips the setup round trips. The browser may do only part of it, or skip it. Same-origin requests gain nothing.

Performance

Prefetch

Prefetch is a resource hint that tells the browser to fetch a resource it will probably need on a later navigation, at low priority behind the current page's own requests, and keep it in the HTTP cache so the next navigation is served locally instead of over the network.

Performance

proxy-revalidate

proxy-revalidate is a Cache-Control response directive: once a shared cache's stored copy is stale, that cache must have the origin validate it before reuse, and may not fall back to the stale copy. It does not apply to private caches, so a disconnected browser may still serve its old copy.

Caching

Pull Zone / Push Zone

A pull zone points the CDN at your origin and the edge fetches each file on a cache miss. A push zone has you upload files into the CDN's own storage, which the CDN then serves as its origin. Pull caches on demand; push pre-stages content inside the CDN.

Architecture

PURGE

PURGE is an operator- or API-triggered invalidation that removes cached objects from a CDN edge before their TTL ends, so the next request misses and refetches from origin. Scopes run from one URL or cache tag to a prefix or the whole cache. It is not a standard HTTP method.

Caching

S

Segment

The unit a streaming player downloads: a short, self-contained media file holding a few seconds of a stream, and the boundary at which adaptive bitrate switches renditions. Containers are MPEG-TS (.ts) or fragmented MP4/CMAF (.m4s, .mp4). A segment is not the stream and not its manifest.

Streaming

s-maxage

A Cache-Control response directive that sets how long a shared cache — a CDN edge, a reverse proxy — may serve a response as fresh. For shared caches it overrides max-age and Expires, and it forbids serving stale without revalidation. Private caches such as browsers ignore it and use max-age.

Caching

SNI (Server Name Indication)

A TLS extension that carries the hostname the client wants inside the plaintext ClientHello, so the server can choose the matching certificate before any data flows. It is what lets one IP address serve many HTTPS sites, and it is a hint, not encryption.

Security

SSAI (Server-Side Ad Insertion)

Server-side ad insertion (SSAI) stitches ads into a video stream on the server by rewriting the manifest, so each viewer gets a personalized playlist whose ad segments were chosen for them and the player plays one continuous stream with no separate ad call for a blocker to intercept.

Streaming

Stale Content

Stale content is a cached response whose freshness lifetime has passed. RFC 9111 forbids serving it unless the cache is disconnected or the client or origin permits it — which is what stale-while-revalidate and stale-if-error do, making the expired copy a resilience resource. A backstop, not a bug.

Caching

stale-if-error

stale-if-error is a Cache-Control extension directive (RFC 5861) that lets a cache serve an already-stored stale response for a set number of seconds past expiry when the fetch to the origin fails. It trades slightly old content for an error page during an origin outage.

Caching

stale-while-revalidate

A Cache-Control response directive (RFC 5861) that lets a cache keep serving a stale stored copy for a set number of seconds after max-age runs out while it revalidates in the background, so the visitor never waits on the origin. Caches that do not implement it ignore it and obey max-age alone.

Caching

Strong ETag

An ETag with no W/ prefix: its value changes whenever the representation bytes change, so two responses carrying the same strong ETag are byte-for-byte identical. RFC 9110 calls it a strong validator, and it is what If-Range resumption and If-Match concurrency checks require.

Caching

Surrogate Key / Cache Tag

A surrogate key, or cache tag, is a label the CDN indexes against a cached response alongside its cache key, normally set by the origin in a response header. Purging the label invalidates every object carrying it in one call. It cannot serve a request, only target content for purging.

Caching

SYN Flood

A SYN flood is a denial-of-service attack on TCP: the attacker sends connection-request (SYN) packets and never completes the three-way handshake, so the server holds each as a half-open connection until its backlog fills and real clients are refused. It exhausts connection state, not bandwidth.

Security

T

TCP

TCP is the connection-oriented transport specified in RFC 9293: it delivers application data as one reliable, in-order byte stream, numbering every byte and retransmitting losses. It is not UDP, and not HTTP/3’s transport — that is QUIC. Every connection opens with a three-way handshake.

Protocol

TCP Fast Open (TFO)

TCP Fast Open (RFC 7413) is an experimental TCP extension that carries application data in the SYN of a repeat connection, so the server can act on it before the three-way handshake finishes. It saves at most one round trip, needs a cookie from an earlier visit, and must be enabled explicitly.

Protocol

Throughput

Throughput is the rate at which data actually crosses a link in a measured interval — the achieved rate, not the rated one. It sits at or below the link's bandwidth (capacity) and falls with packet loss, round-trip time, and undersized TCP windows.

Performance

TLS (Transport Layer Security)

TLS (Transport Layer Security) is the protocol that turns a plain byte stream into a secure channel: the server proves its identity with a certificate, traffic is encrypted, and tampering is detected. HTTP over TLS is HTTPS. TLS 1.3 is current; TLS 1.2 is still required.

Security

Token Authentication

Token authentication gates CDN-delivered content with a signed, expiring URL, cookie or header. Your application signs the path and an expiry with a key the CDN holds; the edge recomputes the signature, checks the expiry against its own clock, and serves from cache without calling the origin.

Security

Token Bucket

A rate limiting algorithm with two settings: tokens refill at a fixed rate up to a bucket capacity, and each request spends one token. A full bucket admits a burst as large as the capacity, while the refill rate sets the long-term average. Unlike a leaky bucket, it permits bursts.

Security

TTFB (Time To First Byte)

TTFB is the time from the start of a request until the first byte of the response arrives. It contains redirects, DNS, connection, TLS and the server's work, so it is not page-load time and not a Core Web Vital. web.dev's rough guide: 0.8s or less is good, over 1.8s poor.

Performance

TTL (Time To Live)

TTL (time to live) is how many seconds a cached response stays fresh before a cache must revalidate or refetch it. Origins set it with Cache-Control max-age, or s-maxage for shared caches such as a CDN edge. It is the main lever on cache hit ratio and origin load.

Caching

W

WAF

Web application firewall: a reverse proxy that inspects HTTP(S) requests against rule sets and blocks application-layer attacks — SQL injection, XSS, path traversal, bot abuse — before they reach the origin. It is a layer 7 filter, not a network firewall and not volumetric DDoS defense.

Security

Warm Cache

A cache whose store already holds the responses its current traffic asks for, so most requests are answered from the store instead of the origin. Warmth belongs to one store measured against demand, not to any single object, and it is not freshness. It cools on purge, eviction or restart.

Caching

WASM at Edge

Compiling application code to WebAssembly and running it on CDN edge servers as a short, sandboxed, memory-capped request handler. Startup is near-instant because no VM or container boots per request. Fastly Compute runs Wasm natively; Cloudflare Workers runs it inside a V8 isolate.

Architecture

Weak ETag

A weak ETag is an ETag whose value carries the case-sensitive W/ marker, as in ETag: W/"abc123". It promises that two representations sharing the value are semantically equivalent, not byte-for-byte identical, so it can earn a 304 but cannot serve as a range or If-Match precondition.

Caching

WebP

An image format from Google, specified in RFC 9649 and registered as image/webp. One container, two codecs: lossy VP8 intra-frame and a lossless codec, plus transparency and animation. Google measures lossless WebP 26% smaller than PNG and lossy WebP 25-34% smaller than JPEG at equal SSIM.

Compression

WebSocket

WebSocket (RFC 6455) is a protocol that layers a full-duplex, framed message channel over one TCP connection, so either side can send at any time. An HTTP/1.1 Upgrade request opens it; after the 101 it is no longer HTTP. ws:// is plain, wss:// is the same protocol over TLS.

Protocol