Google Cloud

Content Delivery — Cloud CDN & Cloud Armor

Cache at Google's edge and filter hostile traffic before it reaches the origin.

Cloud CDN is a checkbox on the global external load balancer rather than a separate product.

Local depots along a private motorway. Common stock is held nearby, everything else travels on roads nobody else is using, and a gatehouse turns away known trouble before it arrives.

Key Concepts

1
    user -> Google edge (anycast) -> [hit]  served at the edge
                                  -> [miss] -> backend service
2
That coupling is the point. The same global load balancer that routes your traffic also caches it, so there is no separate CDN hostname or origin configuration to keep in step.
3
Cache modes decide what is stored.
    CACHE_ALL_STATIC    static content types and anything with
                        explicit Cache-Control. The usual choice.
    USE_ORIGIN_HEADERS  obey the origin exactly
    FORCE_CACHE_ALL     cache everything, including responses the
                        origin marked private -- dangerous
4
FORCE_CACHE_ALL is how user data leaks. It overrides Cache-Control: private, so one user's personalised page can be served to another. Use it only for provably static backends.
Cache-Control: private
5
The cache key is tunable, and the default includes the full query string. Dropping the parameters that do not change the response — tracking parameters especially — raises the hit rate immediately.
6
Negative caching stores error responses briefly, so a backend returning 404s is not hammered for each one.
7
Invalidation is the escape hatch. It is eventually consistent and best avoided as routine; versioned filenames are better because a new name is a new object.
8
Cloud Armor is the WAF, attached to the same backend service:
9
    preconfigured rules   OWASP top 10, SQLi, XSS
    rate limiting         per client IP or per header
    geo rules             allow or deny by country
    Adaptive Protection   ML-based layer-7 DDoS detection
10
Always run new rules in preview first. A managed rule set applied straight to live traffic blocks legitimate requests, and the resulting outage is self-inflicted.
11
Edge TLS and HTTP/3 terminate at the edge, and Google's backbone carries the traffic from there — which is where a lot of the latency benefit comes from even on a cache miss.
12
Media CDN is the separate product for large-scale video streaming, built on the same edge.
13
What the interviewer is probing.1. "How is Cloud CDN enabled?" Probing: the coupling with the load balancer. Stalls: "As a separate service." Moves up: it is a setting on the global load balancer's backend service, so there is no separate origin configuration to keep in step.
14
2. "What is the danger of FORCE_CACHE_ALL?" Probing: the data leak. Stalls: "It caches more." Moves up: it overrides Cache-Control private, so one user's personalised page can be served to another.
15
3. "Your hit rate is near zero on static assets. Why?" Probing: the cache key. Stalls: "Not enough traffic." Moves up: the default key includes the whole query string, so tracking parameters make every request unique; allowlist only the parameters that change the response.
16
4. "How do you roll out Cloud Armor rules safely?" Probing: preview mode. Stalls: "Enable the managed rules." Moves up: run them in preview first — managed rule sets block legitimate traffic, and the resulting outage is self-inflicted.