CDN with Origin Shield diagram template
Edge caches, a shield layer and an origin protected from simultaneous cache-miss storms.
About this design
A CDN reduces latency by serving content from a location near the user, but a cold or purged cache can send a flood of simultaneous misses to the origin. An origin shield adds a single intermediate cache layer: edge locations that miss ask the shield rather than the origin, and the shield collapses many identical requests into one. The origin therefore sees a small, predictable load even when thousands of edges are refreshing the same object. The template places users, edge locations, the shield, a load-balanced origin and its storage in a line so the layers are clear. Use it to discuss cache keys and which headers or cookies must vary them, stale-while-revalidate to hide origin slowness, purging by tag, signed URLs for private content, and the cost trade-off of the extra hop.
Diagram as text
This is the source of the diagram, in the ArchBoard diagram DSL. Paste it into Tools, Diagram from text to rebuild or change it.
title "CDN with origin shield"
direction LR
user "Visitors" -> cdn cloudfront "Edge locations" -[miss]-> cdn cloudfront "Origin shield" -[miss]-> lb "Origin LB" -> service origin "Origin"
[origin x2]
origin -> storage s3 "Assets"More reliability templates
Multi-Region Active-Passive
A warm standby region with replicated data and DNS failover for disaster recovery.
Blue-Green Deployment
Two identical environments with an instant traffic switch and a quick rollback.
Circuit Breaker
Stop calling a failing dependency, serve a fallback response and probe carefully for recovery.