How to put a CDN in front of a Quake AI workload
Coming from another cloud?
▸AWS·Cloudfront
This Quake AI feature maps to AWS’s Cloudfront.
▸DigitalOcean·Spaces CDN
This Quake AI feature maps to DigitalOcean’s Spaces CDN.
How to put a CDN in front of a Quake AI workload
Place a third-party content delivery network (CDN) in front of a Quake AI origin to cache static assets and absorb edge traffic. This guide covers the Quake AI origin configuration and the values your CDN provider needs.
Prerequisites
- ConsoleLogged in to the Quake AI console
- CLIOpenStack CLI installed and authenticated (
clouds.yamloropenrcsourced)
Windows: CLI examples use bash. Set up a Linux CLI environment on Windows before proceeding.
- A public origin: a floating IP on an application or reverse proxy instance, or a public object-storage container
- A domain you control, with DNS records you can edit. Follow How to point a domain at a Quake AI resource at the stage your CDN provider specifies.
- An account with a CDN provider
Choose a CDN provider#
- Cloudflare cache documentation
- Bunny.net pull zone documentation
- Fastly getting started documentation
- AWS CloudFront documentation
The provider-specific steps below show where to use the Quake AI origin values.
Configure the Quake AI origin#
Collect these values before you configure the CDN:
| Value | Where to find it |
|---|---|
| Origin hostname or IP | The floating IP from How to point a domain at a Quake AI resource |
| Origin protocol and port | HTTP on port 80 or HTTPS on port 443 for Compute origins; HTTPS for Swift or S3 endpoints |
| Host header | The hostname your web server or object storage endpoint expects |
| Origin TLS | The connection protocol and certificate hostname the origin presents |
Restrict direct origin access#
If your CDN provider publishes stable origin-facing IP ranges, restrict the origin security group to those ranges after the CDN is active. Requests sent directly to a public origin bypass the CDN cache and edge security controls.
Configure the CDN provider#
- Add your domain as a zone and proxy the hostname with an orange-cloud
AorCNAMErecord that targets your Quake AI origin. - Set SSL/TLS mode to Full (strict) when the origin serves HTTPS with a valid certificate.
- Configure cache rules for static paths. See Cloudflare cache documentation.
Verify the CDN path#
- Run
dig +short www.example.comand confirm that the result matches the edge addresses your CDN provider documents. - Run
curl -I https://www.example.comand inspect the response headers for a cache status such ascf-cache-status,X-Cache, or the provider equivalent. - Send the request again and confirm that the provider reports a cache hit when the requested path matches your cache rules.
- Tail the application logs on the instance and confirm that a cache miss reaches the origin.
See also#
- Edge reverse proxy template: regional reverse proxy with automatic TLS on a VM you operate
- How to point a domain at a Quake AI resource
- How to front a Quake AI workload with a web application firewall
- How to host a static site on object storage
- CloudFront in front of object storage
- Allocate floating IP addresses
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 01.09.2026