CDN Glossary
Comprehensive definitions of CDN terminology, caching concepts, and industry jargon.
A
AAAA Record
An AAAA record (DNS type 28, spoken "quad-A") maps a hostname to one 128-bit IPv6 address, the IPv6 counterpart of the A record's 32-bit address. Publish it alongside the A record for dual-stack delivery; without it, IPv6-only clients reach you only through a NAT64/DNS64 translator.
DNSABR (Adaptive Bitrate)
ABR encodes one video as several renditions and lets the player choose, segment by segment, which to fetch for the current network and device. It is a technique, not a protocol or codec: HLS and DASH carry it, the client decides, and the CDN caches every rendition separately.
StreamingAccess Time
Access time is how long a storage device takes to locate and return data, excluding the transfer itself. A random read costs roughly 13 ms on a 7,200 RPM disk, tens of microseconds on SSD and about 100 ns in RAM. On a CDN cache hit it sets the floor under TTFB.
PerformanceACME (Automated Certificate Management)
ACME (Automatic Certificate Management Environment) is the IETF protocol in RFC 8555 that automates issuing, renewing and revoking TLS certificates: a client proves control of a domain to a CA's ACME server, which issues a domain-validated certificate. It is the protocol behind Let's Encrypt.
SecurityAge Header
The Age response header is a cache's estimate, in seconds, of how long ago the origin generated or last validated the response being served. Caches generate it, not the origin, and the value accumulates across every cache in the path. A response is stale once Age reaches its freshness lifetime.
CachingALPN (Application-Layer Protocol Negotiation)
A TLS extension (RFC 7301): the client lists the application protocols it supports in the ClientHello and the server returns exactly one, so the protocol is settled inside the TLS handshake with no extra round trip. Common identifiers are h2, http/1.1, h3 over QUIC and acme-tls/1.
ProtocolAnycast
Anycast announces one IP address from many locations at once; the routing system, usually BGP, delivers each packet to whichever instance it computes as closest. It is not DNS-based server selection and not a load balancer, and routing-closest is not the same as lowest latency.
NetworkingAPI Gateway
An API gateway is the single front door for API traffic: a reverse proxy that authenticates callers, applies quotas, routes each request to the right backend service, and can transform and cache responses. It is an architecture pattern, not one product. CDNs run parts of it at the edge.
ArchitectureA Record
An A record is the DNS record type that maps a hostname to one 32-bit IPv4 address, such as 192.0.2.53. RFC 1035 defines it as type 1, 'a host address'. It is data, not an alias like a CNAME, and it is IPv4 only - IPv6 uses AAAA. CDN routing in DNS ends in the A record a resolver returns.
DNSAutonomous System (AS)
An Autonomous System (AS) is a connected group of IP prefixes run by one or more operators under a single, clearly defined routing policy, identified by a globally unique AS number (ASN) and joined to other ASes by BGP. CDNs, ISPs and multi-homed enterprises each run their own AS.
NetworkingB
Bandwidth
Bandwidth is the maximum rate a network link can carry data, in bits per second (Mbps, Gbps). It is capacity, not traffic: throughput is the rate that actually moves, latency is trip time, and on an invoice “bandwidth” usually means the bytes you transferred.
PerformanceBBR (Bottleneck Bandwidth and RTT)
A congestion control algorithm from Google that measures a path's bottleneck bandwidth and minimum round-trip time, then paces data at that modelled rate instead of raising the rate until packets drop. Sender-side only, implemented for TCP and QUIC. It keeps queues shallow rather than full.
NetworkingBGP (Border Gateway Protocol)
BGP (Border Gateway Protocol, currently BGP-4) is the internet's inter-autonomous-system routing protocol: networks announce the IP prefixes they can reach and choose the path traffic takes between them. It carries no latency or load data, but it is what makes CDN anycast work.
NetworkingBrotli
Brotli is a lossless compression format from Google, specified in IETF RFC 7932 and carried on the web as the "br" HTTP content coding. Google measured a 13-21% higher compression ratio than deflate at equal quality, paid for in encoder time, not decode speed. Every current major browser accepts it.
CompressionByte Range Request
An HTTP GET whose Range header asks for part of a resource, not the whole body — the basis of video seeking, resumable downloads and parallel chunk downloads. A server that honours it replies 206 Partial Content with a Content-Range slice; 416 if nothing is satisfiable, 200 if it ignores Range.
ProtocolC
Cache Busting
Giving a web asset a new URL whenever its content changes, so every cache treats it as a new object and fetches it. It deletes nothing: a version query string (?v=2) or, more reliably, a content hash in the filename (style.a1b2c3.css) simply stops matching the old cache entry.
CachingCache-Control
Cache-Control is the HTTP header field, defined in RFC 9111, that carries caching directives to browsers, proxies and CDNs: whether a response may be stored, by which caches, how long it stays fresh, and what a cache must do once it goes stale.
CachingCache Fill
A cache fill is the fetch-and-store after a cache miss: the cache pulls the resource from upstream (origin or shield tier) and stores it so a later request is a hit. The miss is not the fill, and a 304 revalidation is not a fill. Fills are the traffic that still costs origin bandwidth and latency.
CachingCache Hit Ratio (CHR)
The share of requests a cache answers from its own stored copies instead of fetching from the origin: hits ÷ (hits + misses). A cache hit ratio of 95 percent means 95 requests in 100 never reached the origin. It measures offload and cost, not how close to the user a response was served.
CachingCache Key
The cache key is the identifier a cache derives from a request to decide which stored response, if any, may serve it. HTTP composes it from the request method and target URI, extended by the fields a response’s Vary header names; CDNs add or drop query parameters, headers and cookies on top.
CachingCache Miss Types
A cache miss is a request an edge node cannot answer from its own cache. Practitioners name four causes: never fetched (cold/compulsory), evicted for space (capacity), purged or expired (invalidation), or cached at another PoP (fragmentation). Each needs a different fix.
CachingCache Stampede
A self-inflicted flood of origin requests: a hot cached object expires or is evicted, every concurrent request for it misses at the same moment, and the origin takes that object's whole request rate in one burst. Request coalescing and stale-while-revalidate prevent it.
CachingCDN (Content Delivery Network)
A geographically distributed network of edge servers that cache copies of a site's content close to users and answer each request from a nearby node. It cuts latency, offloads the origin and can absorb spikes and attacks. It is not a web host: the origin keeps the definitive copy.
ArchitectureCMAF (Common Media Application Format)
CMAF (ISO/IEC 23000-19) is the MPEG standard for packaging segmented media so one set of fragmented-MP4 objects serves both HLS and DASH: encode, store and cache once, and two manifests point at the same files. Not a protocol and not a codec; its chunks underpin low-latency live streaming.
StreamingCNAME
A DNS record that makes one hostname an alias of another: its value is the canonical name, always a domain name and never an IP address. CDNs use it to hand resolution of your hostname to the provider. It may share its name with no other record type, so it cannot sit at the zone apex.
DNSCold Cache
A cold cache holds no reusable stored responses, so requests miss and go to the origin until misses refill it. New edges and POPs, restarts of volatile storage, purges and evictions cause it; while cold, origin load and latency rise. A transient state of one store, not a failure.
CachingCompression
An HTTP content coding that shrinks a message body, almost always a response body, so the same content crosses the network in fewer bytes and the recipient decodes it back exactly. gzip, Brotli and zstd are the common codings. Text gains a lot; already-compressed media gains little.
CompressionConsistent Hashing
Consistent hashing assigns cache keys to nodes on a hash ring so that most assignments survive a change in the node set: adding or removing one node in a pool of N remaps roughly 1/N of the keys instead of nearly all of them. CDNs use it to shard caches and keep them warm across resizes.
ArchitectureContent-Encoding
The HTTP header naming the content codings applied to a body (gzip, br, zstd), which the recipient must undo to recover the media type in Content-Type. Chosen by Accept-Encoding negotiation; not Transfer-Encoding; cached variants stay apart only via Vary: Accept-Encoding.
CompressionContent Negotiation
The HTTP mechanism that lets one URL serve several representations of a resource: the client advertises what it accepts in Accept, Accept-Encoding and Accept-Language, and the server selects one. Shared caches such as CDNs must key on the headers named in the response's Vary.
ProtocolCORS
Cross-Origin Resource Sharing: the browser-enforced protocol in the WHATWG Fetch Standard by which a server opts in to letting scripts on other origins read its responses, chiefly via Access-Control-Allow-Origin. It constrains the browser, not the server, so it is not access control.
SecurityCSAI (Client-Side Ad Insertion)
CSAI (client-side ad insertion) is ad serving where the player, not the server, fetches and plays each ad: at a cue it pauses the content, requests an ad over HTTP (usually VAST), plays it in a separate ad element, then resumes. The CDN serves the same stream to all viewers. Counterpart of SSAI.
StreamingCSP (Content Security Policy)
CSP (Content Security Policy) is an HTTP response header telling the browser which origins a page may load each resource type from and what script may execute. Browser-enforced defence-in-depth against XSS and content injection — not a WAF, and no replacement for output encoding.
SecurityCWND (Congestion Window)
The congestion window (cwnd) is the TCP sender’s own limit on how much unacknowledged data it may have in flight. It is not the receiver’s advertised window — the smaller of the two governs — and because throughput is roughly cwnd ÷ RTT, it caps how fast one connection can go.
NetworkingD
DASH (Dynamic Adaptive Streaming over HTTP)
DASH (MPEG-DASH) is the open ISO/IEC 23009-1 standard for adaptive bitrate streaming: an XML manifest, the MPD, lists the quality levels, and the player fetches media segments — in practice fragmented MP4 — over ordinary HTTP. The vendor-neutral counterpart to Apple's HLS.
StreamingDDoS (Distributed Denial of Service)
A DDoS attack makes a site unavailable by aiming more traffic or work at it than it can handle, from many sources at once. It is not a data breach: the goal is downtime, not theft. CDNs scatter the flood across their anycast edge and filter it there, so only clean traffic reaches your origin.
SecurityDNS (Domain Name System)
The distributed, hierarchical naming system that resolves names like example.com to addresses. A query-response lookup service, not a routing protocol. For a CDN it is also the steering plane: the authoritative nameserver picks which edge address to return, and the TTL caps how fast that changes.
DNSDNSSEC (DNS Security Extensions)
DNSSEC is a set of DNS extensions that sign zone data so a validating resolver can prove an answer came from the zone that owns the name and was not altered. It stops spoofing and cache poisoning, but only where the zone is signed and the resolver validates; it does not encrypt queries.
DNSDNS TTL
The number of seconds a DNS record may be cached before the source must be consulted again. Set by the zone administrator, it is a maximum, not a purge: lowering it never clears copies already cached. Not HTTP cache TTL (Cache-Control max-age).
DNSDoH (DNS over HTTPS)
DNS over HTTPS (DoH), defined in RFC 8484, carries each DNS query and answer inside an HTTPS request to a resolver URL instead of a plaintext port-53 packet, encrypting and authenticating the stub-to-recursive hop. It hides lookups from on-path devices; unlike DNSSEC it does not sign them.
DNSDoT (DNS over TLS)
DNS over TLS (DoT) carries ordinary DNS messages inside a TLS connection on TCP port 853, per RFC 7858 as updated by RFC 8310. It encrypts only the stub-to-resolver hop, so it is not end-to-end, gives no answer integrity, and your resolver still sees every query.
DNSDVR Window
The DVR window is how far back from the live edge a viewer can seek in a live stream. It is whatever the manifest still lists: a sliding HLS media playlist, or a DASH time shift buffer of MPD@timeShiftBufferDepth. Every segment inside it must stay fetchable, so it sizes the CDN's live footprint.
StreamingE
ECDHE (Elliptic Curve Diffie-Hellman Ephemeral)
ECDHE is TLS key agreement over an elliptic curve using a fresh, ephemeral key pair per handshake, so a later leak of the server's long-term private key cannot decrypt sessions recorded earlier: forward secrecy. Every TLS 1.3 certificate handshake uses it; TLS 1.2 signs it with RSA or ECDSA.
SecurityECDSA (Elliptic Curve Digital Signature Algorithm)
ECDSA is the elliptic-curve digital signature algorithm standardised in FIPS 186-5, used to authenticate TLS certificates and handshakes. It only signs and verifies: it never encrypts or exchanges keys. P-256 gives 128-bit security with far smaller keys than RSA-3072, and signs far more cheaply.
SecurityECMP (Equal-Cost Multi-Path)
Equal-Cost Multi-Path (ECMP) is a forwarding technique: where a router holds several next hops of equal cost to one destination, it hashes a packet's flow fields to pick one, so every flow keeps one path. It turns existing path diversity into capacity and failover in the router, not a load balancer.
NetworkingEdge Function
Serverless code a CDN runs on its edge servers, inside the request path, instead of at the origin. It rewrites requests and responses, authorises users, normalises cache keys, and can answer a request at the edge. Each CDN ships its own runtime, so code rarely ports unchanged.
ArchitectureEdge Server
An edge server is one of the caching reverse-proxy machines inside a CDN Point of Presence: it terminates the visitor's TLS connection, answers what it can from its own cache and fetches the rest from the origin. It is not the origin, not the whole PoP, and not the CDN itself.
ArchitectureEgress
Egress is the volume of data leaving a network, metered per gigabyte in volume-stepped tiers as "data transfer out" (AWS) or "internet egress" (Azure). It is not bandwidth (a rate, not a volume) and not ingress (inbound, listed free). A CDN splits it across two or three separate meters.
NetworkingESI
Edge Side Includes: a declarative XML markup language, published as a W3C Note in 2001, that lets a CDN edge server assemble one page from separately fetched fragments. Each fragment keeps its own TTL, so a mostly static page stays cacheable and only its dynamic fragments reach the origin.
ArchitectureETag
An HTTP response header carrying an entity tag: an opaque validator identifying one version of one representation. A client or CDN sends it back in If-None-Match, and a match returns 304 Not Modified instead of the body. Strong tags mean byte-identical, weak tags (W/) only equivalent.
CachingF
Failover
Failover is the automatic switch to a backup server, origin, or CDN provider once a health check decides the primary has failed. It is the switch itself, not the standby that waits, and not load balancing, which spreads traffic over every healthy server all the time.
ArchitectureForward Proxy
A server a client chooses to send its outbound HTTP requests through, configured in the browser, the OS or a PAC file, so one intermediary can filter, log, authenticate and cache traffic for a whole organization. Not a CDN: a CDN is a reverse proxy that works for the origin.
ArchitectureG
Geo DNS
Geo DNS is authoritative DNS that returns a different answer per query location: the name server maps the query's source address — the resolver's, or the client's prefix when EDNS Client Subnet is present — to a region and returns that region's record. It steers the answer, not the packet.
DNSGzip
Gzip is the HTTP content coding that wraps a DEFLATE stream (LZ77 plus Huffman coding) in a header and a CRC-32 trailer, defined by RFC 1952. RFC 1951 puts the gain at a factor of 2.5 to 3 for English text. It is HTTP's universal fallback coding; Brotli and Zstandard compress tighter.
CompressionH
HAR (HTTP Archive)
A HAR (HTTP Archive) file is a JSON record of every HTTP request and response a browser made during a page load, with status, headers, sizes and per-phase timings. It is the de-facto way to share a network trace: not a published standard, and only ever the client's view.
PerformanceHLS (HTTP Live Streaming)
HLS (HTTP Live Streaming) is Apple's adaptive-bitrate streaming protocol, published as RFC 8216: an encoder cuts media into short segments, a playlist file lists them, and the player fetches the rendition its connection sustains over plain HTTP. A delivery format, not a codec and not DRM.
StreamingHSTS
HTTP Strict Transport Security. A header a site sends over HTTPS to order a conforming browser to use only HTTPS for that host for a set time. It blocks protocol downgrade and redirect tampering on later visits; it encrypts nothing itself and cannot protect a first visit unless preloaded.
SecurityHTTP/1.1
HTTP/1.1 is the text-based version of HTTP, first published in January 1997 and defined today by RFC 9112. It adds persistent connections, chunked transfer coding and a mandatory Host header, but carries one response at a time per connection. CDNs still use it on the hop to origin.
ProtocolHTTP/2
Version of HTTP that carries many concurrent request/response streams over one TCP connection and compresses header fields with HPACK, so clients no longer need parallel connections. HTTP semantics are unchanged and TCP head-of-line blocking remains. RFC 9113; ALPN token "h2" over TLS.
ProtocolHTTP/3
HTTP/3 is the third major version of HTTP (RFC 9114, June 2022). It runs on QUIC over UDP instead of TCP, with TLS 1.3 or later built in. Connection-wide head-of-line blocking is gone, setup usually takes one round trip, and a live connection survives a change of network.
ProtocolHTTP Redirects
A 3xx response that sends the client to a different URL, named in the Location header, instead of returning the content it asked for. Each redirect costs a full round trip, and a chain pays that cost once per hop before anything renders.
ProtocolI
Image Optimization
Image optimization is delivering each image in the fewest bytes that still look right: re-encoding to a modern format such as WebP or AVIF, resizing to the size the page displays, tuning encoder quality, and stripping metadata. A CDN keeps one master and derives a cached copy per request.
PerformanceInternet Exchange Point (IXP)
An Internet Exchange Point (IXP) is a neutral facility where many networks connect to a shared Layer 2 switching fabric and peer directly, cutting out transit providers. The IXP does not route traffic itself. CDNs peer at IXPs to reach many ISPs over one port, lowering latency and cost.
NetworkingIOps (I/O Operations Per Second)
IOPS (I/O operations per second) is the rate at which a storage device completes read and write operations. It counts operations, not bytes: throughput equals IOPS times the I/O size. It binds small random access, where a 7,200 rpm HDD is rated in the hundreds and datacentre NVMe above a million.
PerformanceIPv4
IPv4 is version 4 of the Internet Protocol (RFC 791): 32-bit addresses written as four dotted decimal octets, such as 192.0.2.1, giving 2^32 (about 4.3 billion) values. Exhaustion of the free pools forced address sharing, so one public IPv4 address no longer means one user.
NetworkingIPv6
Internet Protocol version 6, the successor to IPv4 (RFC 8200). Addresses are 128 bits, written in hex like 2001:db8::1, so scarcity and address-conserving NAT fall away. A CDN publishes them as AAAA records so IPv6-only clients reach the edge directly instead of through a NAT64 translator.
NetworkingJ
Jitter
Jitter is variation in packet delay across a path — the spread of one-way delays, not their size. Standards call it packet delay variation. It is not latency, loss or throughput. Receivers absorb it in a jitter buffer, trading variation for added fixed delay that low-latency streams cannot afford.
PerformanceJWT (JSON Web Token)
A compact, URL-safe format (RFC 7519) for carrying a set of signed, or optionally encrypted, claims between two parties. Because the claims travel inside the token, an edge, API gateway or origin can verify the signature and the expiry locally, with no call back to the issuer.
SecurityK
Keep-Alive
Reusing one TCP connection for many HTTP request/response exchanges instead of opening a new connection per request. The default in HTTP/1.1, it saves the TCP and TLS handshakes on every request after the first. Not the TCP keep-alive probe, and not pipelining.
ProtocolKeyless SSL
A TLS deployment pattern where a CDN edge terminates TLS for a site without ever holding its private key: the key stays on a key server the customer runs, and the edge sends it only the one private-key operation each full handshake needs.
SecurityL
L4 Load Balancing
L4 load balancing spreads a service's connections across several servers, choosing each backend from the transport-layer header alone: source and destination IP and port, plus protocol. It never reads the payload, so it cannot route by URL, header or cookie, and one connection stays on one server.
NetworkingL7 Load Balancing
Load balancing at layer 7 of the OSI model, the application layer: the balancer parses each HTTP request and picks a backend by content (path, host, headers, query, cookies) rather than by IP and port. It terminates the client connection and proxies to an origin, so it costs more CPU than L4.
NetworkingLast Mile
The last mile is the final access link between a service provider and the user's premises: copper, coaxial, fibre or radio. It is typically the bandwidth bottleneck of a path and the one segment a CDN cannot widen; behind a CDN it runs from the user to the nearest edge, not to the origin.
NetworkingLatency
Latency is the time data takes to travel from one point on a network to another, in milliseconds; in practice it is quoted as round-trip time. It is delay, not capacity: distance and the number of round trips set it, so a nearby edge cuts it and extra bandwidth does not.
PerformanceLL-DASH (Low-Latency DASH)
Low-latency mode of DASH, not a separate protocol: each CMAF segment is cut into small chunks and streamed in one HTTP/1.1 chunked response while it is still being written, so the player decodes before the segment is complete. Takes glass-to-glass latency from tens of seconds to a few.
StreamingLL-HLS (Low-Latency HLS)
Apple's low-latency mode for HLS. The packager publishes sub-second partial segments (EXT-X-PART) that players render before the parent segment is finished, and preload hints plus blocking playlist reloads replace polling, cutting live delay from 18-30 seconds to roughly 3-5.
StreamingLRU Cache
LRU (least recently used) is a cache eviction policy: when the cache is full, it discards the object that has gone longest without a request. It decides which object leaves when space runs out, not whether a copy is still fresh, so an LRU eviction can drop an object whose TTL has hours left.
CachingM
Manifest File
A manifest file is a stream's table of contents, fetched before any media: it lists the quality variants, segment URLs, codecs, timing and where to get decryption keys. HLS calls it a playlist (.m3u8), DASH a Media Presentation Description (.mpd). Without a valid manifest, playback cannot start.
Streamingmax-age
max-age is a Cache-Control response directive giving the seconds a stored response may be reused before it is stale, counted from when the origin generated it. It binds every cache in the chain — browser, CDN, reverse proxy — and permits reuse; it is not an eviction timer.
CachingMiddle Mile
The network path between a CDN's edge and the origin, plus the hops between the CDN's own sites. It is crossed only when the edge cannot answer, so it governs cache misses and uncacheable traffic. Not the last mile to the user, and not the origin itself.
NetworkingmTLS
Mutual TLS: a TLS handshake in which the server also asks the client for a certificate, so both ends prove their identity with an X.509 certificate instead of only the server. CDNs use it edge-to-origin, so only the CDN can fetch from the origin, and viewer-to-edge to authenticate API clients.
SecurityMulti-CDN
Multi-CDN is delivering one property's content through two or more independent CDN providers, with a steering layer choosing which provider answers each request. It is not one CDN with more capacity, and not failover alone: two contracts without steering are two single-CDN setups.
Architecturemust-revalidate
must-revalidate is a Cache-Control response directive (RFC 9111): once a stored response goes stale, any cache — browser or CDN — must revalidate it with the origin before reusing it, and must return an error (normally 504) rather than fall back to the stale copy if the origin is unreachable.
CachingO
OCSP Stapling
OCSP stapling has the TLS server fetch a CA-signed proof that its certificate is not revoked and attach it to the handshake, so the client never contacts the CA: no extra connection, no privacy leak. It only works if the issuing CA still publishes OCSP.
SecurityOrigin
The server, or group of servers, that holds the authoritative copy of your content. CDN edge servers cache its responses and only fetch from it on a cache miss or for content that cannot be cached. Also called the origin server or the backend.
ArchitectureOrigin Health Check
An origin health check is a probe a CDN repeats at a set interval against an origin, usually an HTTP GET or HEAD to a path such as /health, to decide whether that origin is fit to receive traffic. It yields one bit of routing state, healthy or unhealthy, not a measure of user-visible performance.
ArchitectureOrigin Shield
A cache tier a CDN places between its edge servers and its origin. Cache misses from many POPs converge on one designated node, so the origin can see as few as one request per object instead of one per POP. Opt-in and billable. Also called shielding, a parent cache or a mid-tier cache.
ArchitectureP
P2P Hybrid Streaming
P2P hybrid streaming adds a viewer-to-viewer mesh to a CDN: once a device holds a video segment it re-uploads it to other viewers over WebRTC data channels, so one edge fetch serves many. The CDN edge stays seed and fallback. It pays off on concurrency, not on long-tail VOD.
ArchitectureP95/P99 Percentiles
P95 and P99 are latency percentiles: the times 95% and 99% of requests beat, so the slowest 5% and 1% exceed them. They are order statistics read off the sorted list of response times, not an average, a rate, or a maximum. They describe the slow tail an average hides.
PerformancePeering
Peering is a voluntary direct interconnection between two autonomous systems, letting them exchange traffic without paying a transit provider. It is usually settlement-free, over a public Internet exchange fabric or a private cross-connect. CDNs peer to shorten the path to ISPs and cut cost.
NetworkingPoint of Presence (PoP)
A Point of Presence (PoP) is one location where a network keeps its own servers, routers and interconnects so it can exchange traffic with other networks — for a CDN, the edge site serving a city or region. It is not a single machine, not the whole data centre, and not the origin.
ArchitecturePreconnect
Preconnect is a resource hint that asks the browser to open a connection (DNS, TCP and, for HTTPS, TLS) to a cross-origin host before the first request needs it, so that request skips the setup round trips. The browser may do only part of it, or skip it. Same-origin requests gain nothing.
PerformancePrefetch
Prefetch is a resource hint that tells the browser to fetch a resource it will probably need on a later navigation, at low priority behind the current page's own requests, and keep it in the HTTP cache so the next navigation is served locally instead of over the network.
Performanceproxy-revalidate
proxy-revalidate is a Cache-Control response directive: once a shared cache's stored copy is stale, that cache must have the origin validate it before reuse, and may not fall back to the stale copy. It does not apply to private caches, so a disconnected browser may still serve its old copy.
CachingPull Zone / Push Zone
A pull zone points the CDN at your origin and the edge fetches each file on a cache miss. A push zone has you upload files into the CDN's own storage, which the CDN then serves as its origin. Pull caches on demand; push pre-stages content inside the CDN.
ArchitecturePURGE
PURGE is an operator- or API-triggered invalidation that removes cached objects from a CDN edge before their TTL ends, so the next request misses and refetches from origin. Scopes run from one URL or cache tag to a prefix or the whole cache. It is not a standard HTTP method.
CachingR
Rate Limiting
Rate limiting caps how many requests one client may make in a given period, keyed to an IP address, API key, cookie or path, and refuses the excess, conventionally with HTTP 429. It counts requests without inspecting them, so it sits beside a WAF and bot management rather than replacing them.
SecurityRequest Coalescing
A cache behaviour that serves many concurrent requests for one cache key from a single upstream fetch: the first miss goes to the origin, the rest wait on a queue and are answered from that one response. It exists to stop a cache stampede. Also called request collapsing or collapsed forwarding.
CachingRTT (Round-Trip Time)
RTT (round-trip time) is the delay from sending a packet until the response it triggers comes back, including the turnaround at the far end. It is the unit connection setup is priced in — a TCP handshake costs one RTT, a TLS 1.3 handshake one more — and it is not one-way latency or TTFB.
PerformanceRUM (Real User Monitoring)
Real User Monitoring: measuring page performance in the browsers of real visitors on the live site and reading it as a distribution. RUM reports the TTFB and Core Web Vitals that real devices, networks and locations saw — the field counterpart to a synthetic test run from machines you pick.
PerformanceS
Segment
The unit a streaming player downloads: a short, self-contained media file holding a few seconds of a stream, and the boundary at which adaptive bitrate switches renditions. Containers are MPEG-TS (.ts) or fragmented MP4/CMAF (.m4s, .mp4). A segment is not the stream and not its manifest.
Streamings-maxage
A Cache-Control response directive that sets how long a shared cache — a CDN edge, a reverse proxy — may serve a response as fresh. For shared caches it overrides max-age and Expires, and it forbids serving stale without revalidation. Private caches such as browsers ignore it and use max-age.
CachingSNI (Server Name Indication)
A TLS extension that carries the hostname the client wants inside the plaintext ClientHello, so the server can choose the matching certificate before any data flows. It is what lets one IP address serve many HTTPS sites, and it is a hint, not encryption.
SecuritySSAI (Server-Side Ad Insertion)
Server-side ad insertion (SSAI) stitches ads into a video stream on the server by rewriting the manifest, so each viewer gets a personalized playlist whose ad segments were chosen for them and the player plays one continuous stream with no separate ad call for a blocker to intercept.
StreamingStale Content
Stale content is a cached response whose freshness lifetime has passed. RFC 9111 forbids serving it unless the cache is disconnected or the client or origin permits it — which is what stale-while-revalidate and stale-if-error do, making the expired copy a resilience resource. A backstop, not a bug.
Cachingstale-if-error
stale-if-error is a Cache-Control extension directive (RFC 5861) that lets a cache serve an already-stored stale response for a set number of seconds past expiry when the fetch to the origin fails. It trades slightly old content for an error page during an origin outage.
Cachingstale-while-revalidate
A Cache-Control response directive (RFC 5861) that lets a cache keep serving a stale stored copy for a set number of seconds after max-age runs out while it revalidates in the background, so the visitor never waits on the origin. Caches that do not implement it ignore it and obey max-age alone.
CachingStrong ETag
An ETag with no W/ prefix: its value changes whenever the representation bytes change, so two responses carrying the same strong ETag are byte-for-byte identical. RFC 9110 calls it a strong validator, and it is what If-Range resumption and If-Match concurrency checks require.
CachingSurrogate Key / Cache Tag
A surrogate key, or cache tag, is a label the CDN indexes against a cached response alongside its cache key, normally set by the origin in a response header. Purging the label invalidates every object carrying it in one call. It cannot serve a request, only target content for purging.
CachingSYN Flood
A SYN flood is a denial-of-service attack on TCP: the attacker sends connection-request (SYN) packets and never completes the three-way handshake, so the server holds each as a half-open connection until its backlog fills and real clients are refused. It exhausts connection state, not bandwidth.
SecurityT
TCP
TCP is the connection-oriented transport specified in RFC 9293: it delivers application data as one reliable, in-order byte stream, numbering every byte and retransmitting losses. It is not UDP, and not HTTP/3’s transport — that is QUIC. Every connection opens with a three-way handshake.
ProtocolTCP Fast Open (TFO)
TCP Fast Open (RFC 7413) is an experimental TCP extension that carries application data in the SYN of a repeat connection, so the server can act on it before the three-way handshake finishes. It saves at most one round trip, needs a cookie from an earlier visit, and must be enabled explicitly.
ProtocolThroughput
Throughput is the rate at which data actually crosses a link in a measured interval — the achieved rate, not the rated one. It sits at or below the link's bandwidth (capacity) and falls with packet loss, round-trip time, and undersized TCP windows.
PerformanceTLS (Transport Layer Security)
TLS (Transport Layer Security) is the protocol that turns a plain byte stream into a secure channel: the server proves its identity with a certificate, traffic is encrypted, and tampering is detected. HTTP over TLS is HTTPS. TLS 1.3 is current; TLS 1.2 is still required.
SecurityToken Authentication
Token authentication gates CDN-delivered content with a signed, expiring URL, cookie or header. Your application signs the path and an expiry with a key the CDN holds; the edge recomputes the signature, checks the expiry against its own clock, and serves from cache without calling the origin.
SecurityToken Bucket
A rate limiting algorithm with two settings: tokens refill at a fixed rate up to a bucket capacity, and each request spends one token. A full bucket admits a burst as large as the capacity, while the refill rate sets the long-term average. Unlike a leaky bucket, it permits bursts.
SecurityTTFB (Time To First Byte)
TTFB is the time from the start of a request until the first byte of the response arrives. It contains redirects, DNS, connection, TLS and the server's work, so it is not page-load time and not a Core Web Vital. web.dev's rough guide: 0.8s or less is good, over 1.8s poor.
PerformanceTTL (Time To Live)
TTL (time to live) is how many seconds a cached response stays fresh before a cache must revalidate or refetch it. Origins set it with Cache-Control max-age, or s-maxage for shared caches such as a CDN edge. It is the main lever on cache hit ratio and origin load.
CachingV
Varnish (now Vinyl Cache)
An open-source HTTP caching reverse proxy you program in VCL: it fronts your origin, answers most requests from its own cache, and coalesces concurrent misses. The FOSS project renamed itself Vinyl Cache in March 2026; Varnish Software ships a separate downstream build under the old name.
CachingVary Header
Vary is the response header that names the request headers the origin used to select a representation, so caches keep one copy per distinct combination of their values (RFC 9110 section 12.5.5). Vary: * can never be matched from cache; Cookie or User-Agent shatter the hit ratio.
CachingW
WAF
Web application firewall: a reverse proxy that inspects HTTP(S) requests against rule sets and blocks application-layer attacks — SQL injection, XSS, path traversal, bot abuse — before they reach the origin. It is a layer 7 filter, not a network firewall and not volumetric DDoS defense.
SecurityWarm Cache
A cache whose store already holds the responses its current traffic asks for, so most requests are answered from the store instead of the origin. Warmth belongs to one store measured against demand, not to any single object, and it is not freshness. It cools on purge, eviction or restart.
CachingWASM at Edge
Compiling application code to WebAssembly and running it on CDN edge servers as a short, sandboxed, memory-capped request handler. Startup is near-instant because no VM or container boots per request. Fastly Compute runs Wasm natively; Cloudflare Workers runs it inside a V8 isolate.
ArchitectureWeak ETag
A weak ETag is an ETag whose value carries the case-sensitive W/ marker, as in ETag: W/"abc123". It promises that two representations sharing the value are semantically equivalent, not byte-for-byte identical, so it can earn a 304 but cannot serve as a range or If-Match precondition.
CachingWebP
An image format from Google, specified in RFC 9649 and registered as image/webp. One container, two codecs: lossy VP8 intra-frame and a lossless codec, plus transparency and animation. Google measures lossless WebP 26% smaller than PNG and lossy WebP 25-34% smaller than JPEG at equal SSIM.
CompressionWebSocket
WebSocket (RFC 6455) is a protocol that layers a full-duplex, framed message channel over one TCP connection, so either side can send at any time. An HTTP/1.1 Upgrade request opens it; after the 101 it is no longer HTTP. ws:// is plain, wss:// is the same protocol over TLS.
ProtocolX
X-Cache
X-Cache is a non-standard response header a cache adds to report how it handled a request: HIT means it answered from a stored copy, MISS means it forwarded toward origin. The name, the token set and the token order differ by vendor. RFC 9211 Cache-Status is the standardised replacement.
CachingX-Forwarded-For (XFF)
A de-facto HTTP request header that carries the originating client IP plus the IPs of earlier proxies as a comma-separated list, so a server behind proxies can still identify the visitor. It is not a standard and anyone can spoof it: only entries a trusted proxy added are reliable.
NetworkingZ
Zero Trust
Zero trust is a security model that grants no implicit trust: every request is authenticated and authorized per session, whatever network it comes from. It replaces the perimeter model and assumes the network is compromised. A CDN can enforce it at the edge and let the origin answer only the CDN.
SecurityZone Apex
The zone apex is the top node of a DNS zone: the name that must carry the zone's SOA and NS records, usually the registered domain itself (example.com). A CNAME cannot coexist with other data, so CDNs reach the apex via ALIAS/ANAME, CNAME flattening, HTTPS/SVCB aliasing, or A/AAAA records.
DNS