Consistent Hashing Explained
How consistent hashing works, why it beats modulo hashing when servers change, how virtual nodes balance load, and where it’s used in caches and databases.
How CDNs work: edge locations, request routing, cache keys, Cache-Control headers, invalidation, origin shielding, security features and edge compute.

A content delivery network (CDN) is a network of servers spread across many locations that caches copies of your content close to users. When someone requests an image, script or page, the nearest edge server answers from its cache if it can, and only fetches from your origin server when it has to. The result is lower latency for users, far less traffic on your origin and better resilience during spikes.
https://example.com/app.js.Inside each location, load balancers spread requests across many cache servers; our guide to load balancing algorithms covers the techniques.
HTTP caching rules (RFC 9111) let your origin tell the CDN and browsers what to do:
| Directive | Meaning |
|---|---|
max-age=N | Fresh for N seconds in any cache |
s-maxage=N | Overrides max-age for shared caches such as CDNs |
no-cache | May be stored, but must be revalidated before each use |
no-store | Must not be stored at all |
private | Only the user’s browser may cache it |
stale-while-revalidate=N | Serve a stale copy for up to N seconds while refreshing in the background |
stale-if-error=N | Serve a stale copy if the origin is failing |
Revalidation saves bandwidth: with an ETag or Last-Modified header, the edge can ask the origin “has this changed?” and receive a tiny 304 Not Modified response instead of the full file.
The cache key decides which requests share a cached copy. By default it’s usually the URL. Adding query strings, headers (via Vary) or cookies to the key makes caching more precise but splits traffic into more variants and lowers the hit ratio. A classic mistake is caching a page that varies by cookie under a key that ignores cookies, which can show one user’s content to another. Never cache personalised responses in a shared cache.
app.3f9a1c.js) and cache for a year. A new deploy produces a new name, so there’s nothing to purge.The same trade-offs between freshness and load appear in application caches; see our caching strategies guide.
With hundreds of edge locations, a popular file that expires everywhere at once could send hundreds of requests to your origin. Origin shielding (or tiered caching) routes misses through a regional mid-tier cache, so the origin sees one request instead of many. It also protects the origin during a cold start after a purge.
CDNs help even with content they can’t cache:
Any design with heavy media or static assets, such as a news feed, should serve them through a CDN from object storage. Measure the cache hit ratio, origin bandwidth and latency by region; a falling hit ratio usually means a cache key or header problem. Watch what you send to the edge, too: oversized images and missing compression are common reasons a CDN-backed site still feels slow.
Often yes. It still offloads your origin, absorbs spikes and attacks, and terminates TLS closer to users, even within one country.
Yes, for public, non-personalised responses with appropriate Cache-Control headers. Personalised or authenticated responses should not be cached in shared caches.
It depends on your content. Sites with mostly static assets often see very high ratios; sites with lots of dynamic or personalised pages see lower ones. Track the trend and investigate sudden drops.
Every article is edited by a human and checked against our editorial policy. Spotted a mistake? Tell us.
How consistent hashing works, why it beats modulo hashing when servers change, how virtual nodes balance load, and where it’s used in caches and databases.
The CAP theorem and its extension PACELC explained: consistency, availability and partition tolerance, what the trade-offs mean in practice and common myths.
How distributed locks and leases work, why process pauses break naive locks, fencing tokens, Redis, ZooKeeper, etcd and database locks, and alternatives.