Zone settings
Every setting a zone has is on its page in the NOC. A switch saves the moment it is clicked; the Origin Details and Blocking boxes save with their own buttons. Every change reaches every location within about five seconds and applies to requests from then on, whatever is already cached: the one thing a cached file keeps is its lifetime, fixed when it was stored, so a new Cache Expiration Time reaches files already in the cache only when they are next fetched, or when you purge. The Origin Shield, Maintenance Mode, Blocking and Token Authentication boxes each have an article of their own.
Origin URL#
Where the zone fetches from: a scheme, a hostname or IP address, and a port if it is not the default, such as https://origin.example.com or http://203.0.113.10:8080. A path is optional: a file a viewer asks for as /videos/intro.mp4 is fetched from that path at the origin, and with https://origin.example.com/library/ from /library/videos/intro.mp4. No query string and no credentials, and an origin whose hostname contains cachegenie.com or cg-cdn.com is refused. A private, loopback or link-local address saves, but the edge will not connect to it, so every request answers the 502 page. Changing the address changes where the next fetch goes; files already cached stay as they are, so purge the zone if the new origin holds different files under the same names. On a bucket origin the field is the Bucket Endpoint; on a full site it is the Web Server Address.
Host Header#
The Host header sent to your origin. Empty, it is the hostname from the Origin URL. Set it when your origin is reached by an address but serves by name, for example an IP origin that hosts several sites. It is not used while Forward Host Header is on, because that sends each visitor's own hostname instead; the field is greyed and keeps its value for when the switch goes off. A bucket origin never reads it: the request signature covers the Host header, which has to stay the bucket's.
Origin Certificate#
A certificate we make for this zone, for you to install on your origin server. With Verify Origin SSL Certificate on, our servers trust your origin when it presents it, whatever address, port or hostnames the zone uses, so an origin with no public certificate can still be verified. It is created, reissued and revoked in its own box below Origin Details, needs an https:// origin and does not expire: Origin certificates.
Cache Expiration Time#
How long the edge keeps a file before fetching it again. Respect Origin Cache-Control follows the Cache-Control and Expires headers your origin sends, and a set of defaults by file type when it sends none; How caching works has the exact order. A fixed time overrides max-age, s-maxage and Expires from the origin, and applies to playlists too, which under Respect Origin Cache-Control are otherwise held for 10 seconds at most. What no setting overrides: a response marked no-store or private, one that sets a cookie while Strip Response Cookies is off, one with a Vary header naming anything other than Accept-Encoding, and any status other than 200 or 206 are never stored, and on a full site neither is a page marked no-cache.
| Setting | Seconds (the API value) |
|---|---|
| Respect Origin Cache-Control | -1 |
| Do Not Cache | 0 |
| 3 Minutes | 180 |
| 20 Minutes | 1200 |
| 1 Hour | 3600 |
| 3 Hours | 10800 |
| 12 Hours | 43200 |
| 1 Day | 86400 |
| 3 Days | 259200 |
| 1 Week | 604800 |
| 1 Month | 2592000 |
| 3 Months | 7776000 |
| 1 Year | 31919000 |
Do Not Cache sends every request to your origin, at the cost of an origin fetch per request. The lifetime is fixed when a file is stored, and again when an expired copy is refreshed, so changing this setting does not shorten or lengthen the life of files already in the cache.
The eight switches#
| Switch | Starts | Not used on |
|---|---|---|
| Verify Origin SSL Certificate | Off | |
| Forward Host Header | Off (a full site: On) | Buckets |
| Follow Redirects | Off | Buckets, full sites |
| Strip Response Cookies | On (a full site: Off) | |
| Block Root Path Access | Off | |
| Block POST Requests | Off | |
| Add Canonical Headers | On (a full site: Off) | Buckets, full sites |
| Add CORS Headers | On |
A switch an origin type does not use is greyed with the reason beside it, and its saved value comes back if the origin type changes.
Verify Origin SSL Certificate
On, the edge connects to your origin over HTTPS only when it presents a certificate we trust: one a public authority issued for the name we are asking for, valid and unexpired, or the zone's origin certificate. Off, the connection is still encrypted but the certificate is not checked. An origin with no public certificate can have an origin certificate and keep this on. On a full site whose address is an IP, the certificate is checked against the hostname the visitor used while Forward Host Header is on (which a full site starts with), or against the Host Header field with it off, so a site can keep this on while being reached by address.
Forward Host Header
On, the Host header sent to your origin is the hostname the visitor asked for, and each hostname on the zone is cached separately, because an origin that is told the name can answer it differently. Off, the origin is told its own name (or the Host Header above) and every hostname on the zone shares one copy of each file. Off is right for one folder of files under several names; on is right for a full site.
Follow Redirects
On, a redirect from your origin is followed at the edge, up to nine in a chain, and the file at the end is cached under the URL the viewer asked for; the viewer never sees the redirect. A longer chain, or a hop to a private address, answers the 502 page. Off, the redirect is passed to the viewer as it is, and it is never cached. Neither a bucket nor a full site follows redirects: a signed bucket request followed to a new address would fail its signature, and a redirect a website returns belongs to the visitor's browser.
Strip Response Cookies
On, every Set-Cookie header is removed from the zone's responses, and a Cookie a viewer sends is dropped before the request reaches your origin, so one visitor's session can never be cached and served to another. Off, on a standard or bucket origin, a request that carries a cookie bypasses the cache and goes to your origin, and a response that sets a cookie is never stored; on a full site a static file is served from the cache whatever cookie it carries, and only the other requests bypass. On a full site this switch starts off, and switching it on signs every visitor out, because the site can no longer set a session cookie through the CDN.
Block Root Path Access
On, a request for a directory rather than a file is answered 403: the root /, any path ending in /, and the dot forms /. and /.., for every method. On a full site it refuses the home page and every directory address, so leave it off there.
Block POST Requests
On, a POST to the zone is answered 403 and never reaches your origin. Only POST: PUT, PATCH and DELETE are passed through as before. A bucket origin refuses every method but GET and HEAD anyway, with 405. On a full site this breaks every form, login and API call that posts.
Add Canonical Headers
On, every response carries Link: <https://origin.example.com/path>; rel="canonical", naming the file at your Origin URL, so a search engine that finds the file on a CDN hostname credits the original rather than indexing a duplicate. It replaces any Link header your origin sent. Switch it off if the CDN hostname is the address you want indexed. Not used on a bucket, whose endpoint is not an address anyone can reach, nor on a full site, whose web server is not the canonical address either.
Add CORS Headers
On, files whose extension is .eot, .ttf, .woff, .woff2 or .css are sent with Access-Control-Allow-Origin: *, Access-Control-Allow-Methods: GET, HEAD, OPTIONS and Access-Control-Max-Age: 86400, replacing those three headers if your origin sent them; any other Access-Control-* header your origin sends passes through. Every other file keeps the CORS headers your origin sends, so for video, JSON or images loaded across origins, set the headers at your origin.
What a full site changes#
Saving a zone as a full site sets Forward Host Header on, Follow Redirects off, Strip Response Cookies off, Block Root Path Access off, Block POST Requests off, Add Canonical Headers off, and Cache Expiration Time to Respect Origin Cache-Control. On the zone page the save that switches the type applies all seven, Cache Expiration Time included, and says so above the button; set a fixed time again afterwards if you want one. Through the API, a value you send in the same call stands. Three switches stay live with a warning beside them, because each one breaks a website: stripping cookies, blocking the root path and blocking POST. Full site origins explains why.