VergeCloud CDN AcademyVisit VergeCloud
THE ENGINEER'S CDN PLAYBOOK

Understand the edge.
Master the stack.

Learn how modern CDNs deliver, protect, and accelerate every request—from DNS resolution to the edge and origin.

Practical mental models Commands you can run
TLS 1.3 DNSSEC valid WAF active
OriginYour application
EdgeNearest PoP
UserBrowser
Encrypted connectionEdge cache HIT

What is a CDN?

A Content Delivery Network is a distributed group of edge servers that receives requests near users. It can serve cached content immediately or securely fetch it from your origin.

UserDNSEdgeOrigin

One request. Six layers.

Start with the request lifecycle, then zoom into each layer. Every module answers: what it is, why it exists, and how to verify it.

Follow one HTTPS request

Choose a step to see which system is responsible and what can go wrong.

STEP 02

TLS handshake

The browser connects to the edge. The certificate must cover the hostname, chain to a trusted CA, and be within its validity period.

Engineer’s checkCheck SNI, certificate chain, issuer, SANs and expiry.
openssl s_client -connect example.com:443 -servername example.com

CDN: a reverse proxy at global scale

A CDN sits in front of the origin. DNS routes the hostname to the platform; an edge server terminates the client connection, applies policy, checks cache, and only then talks to the origin when necessary.

01Edge / PoP

A point of presence close to users. It reduces network distance and absorbs work.

02Origin

The source application or storage system. It remains authoritative when content is not cached.

03Cache HIT / MISS

A HIT is served at the edge. A MISS needs an origin fetch before it can be stored.

04Full vs partial setup

A full setup delegates DNS nameservers. A partial setup commonly points a hostname by CNAME.

SSL is the old name. TLS is the protocol.

In everyday speech people still say SSL certificate, but modern HTTPS uses TLS. A certificate binds a public key to one or more hostnames through a trusted Certificate Authority (CA).

01Edge certificate

Presented by the CDN to the visitor. Its SAN must cover the requested hostname.

02Origin certificate

Used on the separate edge-to-origin connection when HTTPS is enabled upstream.

03DNS-01 validation

The CA checks a temporary DNS TXT record. Useful when the CDN controls authoritative DNS.

04HTTP-01 validation

The CA requests a token under /.well-known/acme-challenge/. The path must reach the validation responder.

Issuance is a proof-of-control ceremony

  1. OrderThe platform asks a CA for a certificate covering the hostname.
  2. ChallengeThe CA provides DNS-01 or HTTP-01 proof requirements.
  3. ValidateThe CA independently checks the proof from the public Internet.
  4. Issue & deployThe signed chain and private key are installed at the edge.
  5. RenewAutomation repeats the process before expiration.

Never confuse the two TLS hops

User → Edge and Edge → Origin are separate connections. One can succeed while the other fails.

UserTLS #1EdgeTLS #2Origin

DNSSEC proves that an answer is authentic

DNSSEC adds digital signatures to DNS data. It does not encrypt queries and it does not make an incorrect record correct; it lets a validating resolver detect forged or modified answers.

01DNSKEY

Publishes zone public keys. A ZSK commonly signs record sets; a KSK signs the DNSKEY set.

02RRSIG

The signature attached to a record set, with algorithm, signer and validity dates.

03DS

A digest of the child zone’s KSK, published by the parent to create the chain of trust.

04NSEC / NSEC3

Cryptographic proof that a requested name or record type does not exist.

Validation walks down from a trust anchor

Roottrusted DNSKEY
.comparent DS
example.comDNSKEY + RRSIG
Validated answer
dig +dnssec example.com DNSKEY

Operational rule: publish the child DNSKEY first, then the DS at the registrar. Removing or rotating keys in the wrong order can make the entire zone appear bogus.

A firewall rule is match + action + order

A CDN firewall evaluates HTTP and network attributes at the edge before unwanted requests reach the application. Precise rules reduce risk without blocking legitimate traffic.

01Expression

The condition: IP, country, method, URI, header, bot signal, JA3/JA4 fingerprint or another field.

02Action

Allow, block, challenge, log, rate-limit or skip a later security layer.

03Priority

Defines evaluation order. Document whether processing stops after a terminal action.

04Observability

Rule ID, request ID, matched value and action should be available for investigation.

Read policy like code

Block requests to the admin path unless they come from the office network.

IF http.request.uri.path starts_with "/admin"
AND NOT ip.src in {203.0.113.0/24}
THEN BLOCK
1 Start in log mode2 Test exceptions3 Watch false positives4 Add expiry/owner

OWASP CRS detects patterns; your WAF enforces policy

The OWASP Core Rule Set is a generic collection of ModSecurity-compatible rules for common web attacks. In anomaly-scoring mode, matching rules add points; the request is blocked when the configured threshold is reached.

01Phases

Rules can inspect request headers, request body, response headers and response body at different processing phases.

02Anomaly score

Several weak signals may combine into one confident block decision. Lower thresholds are stricter.

03Paranoia level

PL1 has fewer false positives. Higher levels add stricter rules and require more tuning.

04Exclusions

Narrowly remove a rule for a parameter or path after confirming a false positive—do not disable broad protection first.

Signals accumulate

SQL injection pattern+5
Suspicious encoding+3
Protocol violation+2
Total anomaly score10
Blocking threshold: 5REQUEST BLOCKED

Comodo can mean three different security things

Context matters. Engineers often use “Comodo” to refer to a certificate issuer, an older ModSecurity ruleset, or the broader cybersecurity company. These are related historically but are not interchangeable.

01Comodo CA → Sectigo

Comodo CA changed its name to Sectigo. When discussing public TLS certificates today, Sectigo is usually the precise name.

02Comodo WAF rules

A legacy commercial ModSecurity rule collection. Do not assume it is the same as OWASP CRS.

03Comodo Cybersecurity

The broader vendor also offers endpoint, network and website security products.

04Certificate chain

Always identify the actual issuer shown in the certificate rather than relying on a historical product nickname.

What is VergeCloud?

VergeCloud is a cloud platform built around delivery and protection at the edge. In a typical setup, a domain points to VergeCloud, where the edge can terminate TLS, apply firewall/WAF policy, cache eligible responses, and proxy traffic to the customer’s origin.

Explore vergecloud.com
DNSRoute and authenticate names
CDNCache and accelerate
TLSEncrypt both hops
SecurityFilter abusive traffic

This academy explains standard CDN architecture and practical VergeCloud context. Exact dashboard names, plan entitlements and operational behavior should always be confirmed against current VergeCloud product documentation.

Debug from the outside in

Do not jump straight to the origin. Identify the layer that failed.

1ResolveDoes public DNS return the expected edge address?
2ConnectCan TCP port 443 and the TLS handshake complete?
3Inspect edgeDid a firewall, WAF or rate-limit rule act?
4Inspect cacheWas it a HIT, MISS, stale object or bypass?
5Reach originCan the edge resolve, connect and validate upstream TLS?
6CorrelateUse timestamp, hostname and request ID across logs.

Glossary

Anycast

One IP announced from multiple locations; routing selects a nearby path.

Cache key

The normalized values that identify one cached object.

Origin pull

The edge retrieves an object from the origin on demand.

PoP

A physical or logical edge location serving nearby traffic.

SNI

The TLS hostname sent by a client so the server selects the right certificate.

TTL

How long data may be treated as fresh before revalidation.

WAF

A web application firewall inspecting HTTP traffic.

Zero trust

A security approach that continuously verifies access rather than trusting location.