# How to put a CDN in front of a Quake AI workload

Source: https://docs.quake.ai/docs/network/how-to/front-with-cdn
Markdown: https://docs.quake.ai/docs/network/how-to/front-with-cdn.md

---

# How to put a CDN in front of a Quake AI workload

Place a third-party content delivery network (CDN) in front of a Quake AI origin to cache static assets and absorb edge traffic. This guide covers the Quake AI origin configuration and the values your CDN provider needs.



Quake AI provides origins you operate: a floating IP on an application or reverse proxy instance, or a public object storage endpoint. Your CDN provider handles edge caching, edge TLS, and optional services such as a web application firewall or image optimization. Follow the provider's documentation to configure those services.



<PrerequisiteBlock methods={["console", "cli"]}>

- A public origin: a [floating IP](/docs/network/how-to/allocate-floating-ips) on an application or reverse proxy instance, or a public object-storage container
- A domain you control, with DNS records you can edit. Follow [How to point a domain at a Quake AI resource](/docs/network/how-to/point-domain-to-quake-ai) at the stage your CDN provider specifies.
- An account with a CDN provider

</PrerequisiteBlock>

## Choose a CDN provider

- [Cloudflare cache documentation](https://developers.cloudflare.com/cache/)
- [Bunny.net pull zone documentation](https://docs.bunny.net/docs/pull-zone)
- [Fastly getting started documentation](https://www.fastly.com/documentation/guides/getting-started/)
- [AWS CloudFront documentation](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/Introduction.html)

The provider-specific steps below show where to use the Quake AI origin values.

## Configure the Quake AI origin

Collect these values before you configure the CDN:

| Value | Where to find it |
|---|---|
| Origin hostname or IP | The floating IP from [How to point a domain at a Quake AI resource](/docs/network/how-to/point-domain-to-quake-ai) |
| Origin protocol and port | HTTP on port `80` or HTTPS on port `443` for Compute origins; HTTPS for Swift or S3 endpoints |
| Host header | The hostname your web server or object storage endpoint expects |
| Origin TLS | The connection protocol and certificate hostname the origin presents |

<MethodTabs>
<Method label="Console">

1. Open **Network** > **Floating IPs** and copy the address associated with your workload.
2. Open **Network** > **Security Groups** and note which inbound rules allow HTTP (`80`) and HTTPS (`443`) from the internet or from the CDN provider's IP ranges.
3. For object storage origins, configure public read access with the CLI, API, or an S3-compatible client by following [How to grant access control on an object storage bucket](/docs/object/how-to/grant-access-control). In the Console, open **Storage** > **Object Storage** and copy the S3 or Swift endpoint from the **Access & Information** column on the container row.

</Method>
<Method label="CLI">

```bash
openstack floating ip list -f table -c "Floating IP Address" -c Port
openstack security group rule list ORIGIN_SECURITY_GROUP -f table
```

The first command shows the floating IP and its associated port. The second command shows the inbound rules for `ORIGIN_SECURITY_GROUP`.

For object storage origins, follow [How to grant access control on an object storage bucket](/docs/object/how-to/grant-access-control), then request a sample object without credentials to verify public read access.

</Method>
</MethodTabs>

### Restrict direct origin access

If your CDN provider publishes stable origin-facing IP ranges, restrict the origin security group to those ranges after the CDN is active. Requests sent directly to a public origin bypass the CDN cache and edge security controls.

## Configure the CDN provider




1. Add your domain as a zone and proxy the hostname with an orange-cloud `A` or `CNAME` record that targets your Quake AI origin.
2. Set **SSL/TLS** mode to **Full (strict)** when the origin serves HTTPS with a valid certificate.
3. Configure cache rules for static paths. See [Cloudflare cache documentation](https://developers.cloudflare.com/cache/).




1. Create a **Pull Zone** with the origin set to your Quake AI floating IP or hostname.
2. Enable **Origin Shield** or edge rules only if your traffic pattern needs them.
3. Point your domain's `CNAME` at the hostname Bunny assigns. See [Bunny pull zone docs](https://docs.bunny.net/docs/pull-zone).




1. Create a service with the origin host set to your Quake AI address.
2. Attach a TLS certificate for your domain on the Fastly service.
3. Point DNS at the hostnames Fastly assigns. See [Fastly getting started](https://www.fastly.com/documentation/guides/getting-started/).




Follow [How to put AWS CloudFront in front of object storage](/docs/object/how-to/use-cloudfront-with-buckets) when the origin is a Swift container. For compute origins, create a DNS hostname that resolves to your Quake AI floating IP. Set that hostname as the CloudFront custom origin, then configure the origin protocol policy to match your instance listener.




## Verify the CDN path

1. Run `dig +short www.example.com` and confirm that the result matches the edge addresses your CDN provider documents.
2. Run `curl -I https://www.example.com` and inspect the response headers for a cache status such as `cf-cache-status`, `X-Cache`, or the provider equivalent.
3. Send the request again and confirm that the provider reports a cache hit when the requested path matches your cache rules.
4. Tail the application logs on the instance and confirm that a cache miss reaches the origin.

## See also

- [Edge reverse proxy template](/resources/iac-templates/edge-reverse-proxy): regional reverse proxy with automatic TLS on a VM you operate
- [How to point a domain at a Quake AI resource](/docs/network/how-to/point-domain-to-quake-ai)
- [How to front a Quake AI workload with a web application firewall](/docs/network/how-to/front-with-waf)
- [How to host a static site on object storage](/docs/object/how-to/host-static-site)
- [CloudFront in front of object storage](/docs/object/how-to/use-cloudfront-with-buckets)
- [Allocate floating IP addresses](/docs/network/how-to/allocate-floating-ips)
