How a CDN works

Without a CDN every request goes straight to the origin server, even when the visitor is 5,000 km from the data centre. A CDN solves that with a network of points of presence: the visitor is served from the node closest to them.

The sequence:

  1. The visitor requests a product image
  2. DNS resolves to the nearest CDN edge server
  3. If the file is in the cache — a cache hit — it is returned immediately
  4. If it is not — a cache miss — the edge fetches it from the origin, caches it and returns it

What a CDN speeds up in e-commerce

Asset Without a CDN With a CDN
Product images Served from a single origin region From the nearest edge (under 50 ms)
JS and CSS bundles One access point Served in parallel worldwide
The personalization platform’s JS snippet Slow widget initialisation Fast load, less flicker
Video reviews Heavy load on the origin Streamed from the edge

CDN and security

Modern CDN platforms — Cloudflare, Akamai, Amazon CloudFront — are not only about speed:

  • DDoS protection — malicious traffic is filtered before it reaches the origin
  • TLS termination — the HTTPS connection ends at the edge, and the origin can speak plain HTTP inside the perimeter
  • WAF (web application firewall) — known attacks are blocked at edge level

CDN and personalization

Important: a CDN and personalization are awkward neighbours. A CDN keeps one version of a page for everybody. Personalization requires different answers for different people.

The ways round it:
– Fragment caching — cache the page shell and load the personalized blocks asynchronously
– Edge functions — run the A/B test and personalization logic at the edge itself, with no trip to the origin
– Vary headers — cache separate versions keyed on the test group cookie (with care: it cuts the cache hit rate sharply)

Common mistakes

  • Caching pages that contain the basket — the visitor sees somebody else’s basket
  • No cache busting — when JS or CSS is updated the old file stays in the CDN cache
  • One TTL for everything — images and API responses need fundamentally different settings