CDN for live and near-live media
Cache hierarchies, signed paths, and origin shield patterns for media.
CDN for live and near-live media
Business constraint
Live commentary clips and thumbnails hit a global audience. Origin egress is expensive and fragile.
Naive v0
Every player hits origin. Or cache forever and serve wrong clip after edit. Unsigned URLs leak.
Failure drill
Origin bandwidth cliffs. Cache stampedes on popular clip keys. Hotlinking drains budget. Stale takedown content remains public.
Evolution path
Iteration 1
CDN with short TTL + soft purge. Origin shield to collapse regional misses. Separate cache keys for variants.
Iteration 2
Signed URLs with expiry for private or licensed media. Rotate signing keys with overlap.
Iteration 3
Drill purge and stampede: ensure single-flight at origin shield.
Implementation cut
Treat CDN as part of the miss-control system. Document purge authority and signing key ops.
Numbers
Origin offload %. Purge propagation time. Unauthorized fetch rate after expiry.
Pattern tags
Self-check
- What is an origin shield for?
- Why soft TTL on media?
- How do signed URLs fail closed?
- What belongs in the cache key?
- How do you drill a takedown?
Walkthrough
Recordings will appear here when published. Until then, work the failure drill and lab locally — pause after each iteration and write the metric that moved.