Origin shield
The origin shield puts one of our locations between your origin and the rest of the network. With a Home PoP chosen, only that location fetches from your origin; every other location fetches through it, and a file fetched once is served to all of them from its cache, so your origin sees one location instead of all of them and its traffic falls to roughly one fetch per file. The same applies to the pieces of a large file and to the background refresh of a file that has expired.
Choosing a Home PoP
Origin Shield (Home PoP), in the Connecting to your origin box on the zone page, is a toggle switch (Auto Detect or Off). Specific locations can no longer be chosen by hand: switching Origin Shield (Home PoP) on enables Auto Detect, which automatically measures and chooses the location nearest your origin for you. From the API the setting is HOME_POP: auto to turn Auto Detect on, or an empty string for off. HOME_POP_LOCATION reports the location in use (read only).
Auto Detect
Every location measures its round trip to your origin every five minutes, and the location with the shortest becomes the Home PoP. The note under the toggle names the location in use. Another location takes over only when it is clearly nearer, at least 20% and 5 milliseconds shorter, so two locations at a similar distance never trade the zone back and forth; a location that can no longer reach your origin, or that is out of service, hands the zone to the next nearest. When switched on, every location fetches from your origin directly until the first measurements arrive, within about ten minutes (or keeps the previously active location if already known). The measurement is a connection that opens and closes, three times from each location, and nothing is requested.
When the Home PoP cannot answer
If the Home PoP is offline, or a fetch through it fails or comes back with a 5xx or a 403, the location that wanted the file fetches it from your origin directly and carries on; your origin just sees more than one location until it is back. Any other answer through the Home PoP is your origin's answer, relayed: a 404 through the shield is your 404.
What goes through it
Every GET and HEAD: fetches to fill the cache, the pieces of large files, the refresh of expired files, and a request passed straight through because of a cookie or an Authorization header. Only a POST, PUT, PATCH, DELETE or OPTIONS goes to your origin directly.
What the statistics show
The zone's statistics gain an Origin Shield chart of the bytes the Home PoP sent to the other locations, with the number of requests it answered for them above it. That traffic is between our own locations and is neither counted as viewer traffic nor billed. Origin bandwidth is counted where your origin was actually fetched, which with a shield is the Home PoP.
When it helps
When your origin is far from most of your viewers, when its bandwidth is metered, or when it is a server rather than a store and would rather be asked once. It adds a hop to the first fetch of each file in every location other than the Home PoP, so for a bucket that already sits close to your viewers it can cost a few milliseconds on a cold file and save nothing. It is set per zone.