Leanpub Header

Skip to main content

Cloudflare and the Modern CDN

How the Internet Edge Actually Works

Cloudflare and the Modern CDN
This book is 100% completeLast updated on 2026-09-08

A practical look at how the modern Internet edge really works. Explore DNS, BGP, TLS, HTTP/3 and the architecture behind content delivery, then apply that knowledge to building, securing and optimizing Cloudflare in production. No marketing fluff, just the engineering behind the edge.

Minimum price

$25.00

$35.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
WEB
APP
206
Pages
About

About

About the Book

This book explains how the modern Internet edge works and how Cloudflare fits into it. You will learn the underlying protocols and architectures that power content delivery, from DNS and BGP routing to TLS and HTTP/3. Then you will learn how to configure, operate, secure and optimize Cloudflare deployments in real production environments. The book is written for engineers who need to understand not just which buttons to click, but why the edge works the way it does and how to make sound architectural decisions. No marketing fluff, no hand-holding tutorials. Just engineering depth.

Bundle

Bundles that include this book

Author

About the Author

Steve Publications

Steve is a technology professional with more than 20 years of experience in software development, server infrastructure, cybersecurity, vulnerability research and reverse engineering. Throughout his career, he has designed, secured, analyzed and tested complex software and infrastructure, with a particular focus on understanding how systems fail and how they can be made more secure.

Outside of work, Steve enjoys sharing knowledge with the technology community. He collaborates with researchers, industry experts and technology professionals to write practical books covering software development, cybersecurity, cloud computing, networking, DevOps, artificial intelligence and enterprise technologies. His books focus on practical learning through clear explanations, real-world examples and hands-on exercises. With more than two decades of industry experience, his goal is to help IT professionals, students and technology enthusiasts build useful skills and stay current in a rapidly changing industry.

We believe readers deserve to know how our books are created. Most of our authors are not native English speakers, so we use AI to help translate, proofread manuscripts, fix grammar, improve sentence structure and make technical explanations easier to read. AI is used as an editing tool only. It does not replace the research, technical knowledge or hands-on experience behind our books. Some of our authors also prefer to remain anonymous for privacy or professional reasons. In those cases, we publish their work under a different name. The author's name may be different, but the quality of the content and our review process remain the same.

Every book is written, reviewed and maintained by experienced technology professionals, with contributions from our private technical community of more than 420 engineers and researchers. We spend far more time validating technical accuracy and keeping our content up to date than generating text. We are always interested in working with experienced professionals who have deep expertise in a particular technology or domain. If you would like to publish a book with us or help review an existing manuscript, we'd love to hear from you. Send us a message describing your area of expertise. We are especially interested in niche technologies, specialized skills and emerging topics that are underrepresented in existing technical literature.

If you look through the contents of our books, you'll see practical examples, detailed explanations and material that is regularly updated. Our goal is to publish books that professionals can actually rely on, not low-effort AI-generated content. If you ever feel that one of our books does not meet that standard, Leanpub offers a 60-day money-back guarantee. Feel free to request a refund if you are not satisfied with your purchase.

Contents

Table of Contents

How the Internet Edge Actually Works

Introduction

Chapter 1: The Shape of the Modern Internet Edge

  1. The Latency Problem: Why Distance Still Matters
  2. A Request’s Journey: From Click to Response
  3. What Is an Edge Network?
  4. Centralized Origins vs. Distributed Edges
  5. Why CDNs Changed Everything
  6. Chapter Summary

Chapter 2: How DNS Actually Works

  1. The DNS Hierarchy: Root, TLD, and Authoritative
  2. Recursive Resolution and the Stub Resolver
  3. Authoritative DNS and Zone Files
  4. Caching, TTLs, and Propagation Myths
  5. Key Record Types: A, AAAA, CNAME, MX, TXT, SRV, and Beyond
  6. DNSSEC: Trust in the Name System
  7. Chapter Summary

Chapter 3: Routing the Internet: BGP, Anycast, and IP Transit

  1. Autonomous Systems and the BGP Protocol
  2. Route Announcement, Prefixes, and Path Selection
  3. What Anycast Is and Why CDNs Depend on It
  4. IP Transit, Peering, and Internet Exchanges
  5. When Routing Goes Wrong: Leaks, Hijacks, and Outages
  6. Chapter Summary

Chapter 4: Transport and Application Protocols at the Edge

  1. TCP Connections: Handshake, Retransmit, and Congestion Control
  2. TLS: Encryption, Handshake Costs, and Session Resumption
  3. HTTP/1.1: Pipelining, Keep-Alive, and Head-of-Line Blocking
  4. HTTP/2: Multiplexing, Frames, and Server Push
  5. HTTP/3 and QUIC: UDP-Based Transport with Built-In TLS
  6. Protocol Negotiation: ALPN and the Actual User Experience
  7. Chapter Summary

Chapter 5: The CDN Architecture

  1. The Reverse Proxy Pattern
  2. Edge Nodes, Points of Presence, and Topology
  3. The Cache: Hitting, Missing, Stale, and Bypassing
  4. Origin Shielding and Tiered Caching
  5. CDN Request Lifecycle: End User to Origin and Back
  6. What a CDN Can and Cannot Accelerate
  7. Chapter Summary

Chapter 6: Cloudflare’s Architecture and Network

  1. Cloudflare’s Global Network: Data Centers and POPs
  2. Cloudflare’s Anycast IP Space and How Traffic Lands
  3. Request Flow Through Cloudflare: Edge to Origin
  4. How Cloudflare Differs from Akamai, Fastly, and Others
  5. What Is and Is Not Visible to the End User
  6. Chapter Summary

Chapter 7: Getting Started: Accounts, Zones, and Nameservers

  1. Accounts, Memberships, and Plan Tiers
  2. Adding a Site and Understanding Zone Status
  3. Transferring DNS: Nameservers and Cutover Strategy
  4. Proxied vs. DNS-Only: The Orange Cloud
  5. Verifying Your Site Is Live and Troubleshooting the Initial Setup
  6. Configuration Examples: Initial DNS Records for a Real Site
  7. Chapter Summary

Chapter 8: DNS on Cloudflare

  1. Cloudflare DNS: Authoritative, Managed, Fast
  2. Managing Records: Dashboard, API, and Terraform
  3. Split-Horizon DNS and Internal Resolvers
  4. Load Balancing DNS Records and Traffic Management
  5. DNS Automation: API Patterns and Terraform Modules
  6. Operational Considerations: Propagation, Cutover, and Rollback
  7. Chapter Summary

Chapter 9: SSL/TLS with Cloudflare

  1. The Cloudflare SSL/TLS Problem Space
  2. SSL/TLS Modes: Off, Flexible, Full, Full (Strict)
  3. Certificate Types: Universal, Custom, Dedicated, Origin CA
  4. Certificate Management and Renewal
  5. Security Trade-offs and Common Mistakes
  6. Configuration Example: Hardened TLS Setup for Production
  7. Chapter Summary

Chapter 10: Web Application Firewall and Security Rules

  1. The WAF Rule Engine: How Cloudflare Inspects Requests
  2. Managed WAF Rulesets: OWASP, Category-Based, and Threat Intelligence
  3. Custom WAF Rules and Field Operators
  4. Firewall Rules: The Legacy System and When to Use It
  5. Security Rules and Traffic Filtering
  6. Avoiding False Positives and Rule Conflicts
  7. Chapter Summary

Chapter 11: DDoS Protection, Rate Limiting, and Bot Management

  1. DDoS at the Edge: How Cloudflare Absorbs Attacks
  2. Rate Limiting Rules: Tokens, Windows, and Responses
  3. Bot Fight Mode and Advanced Bot Management
  4. Challenge Pages: JavaScript, Turnstile, and Under Attack Mode
  5. API Shield and Automated Threat Mitigation
  6. Configuration Examples: Rate Limiting and Bot Policies for Real Applications
  7. Chapter Summary

Chapter 12: Zero Trust, Access, and Private Networks

  1. Zero Trust Architecture and Cloudflare’s Approach
  2. Cloudflare Access: Identity-Based Application Access
  3. Zero Trust Gateway: Secure Web and DNS Gateways
  4. Cloudflare Tunnel: Exposing Origins Without Open Ports
  5. Integrating Identity Providers and Device Posture
  6. Architecture Example: Secure Internal App Behind Access and Tunnel
  7. Chapter Summary

Chapter 13: Caching Fundamentals in Cloudflare

  1. HTTP Caching Headers: Cache-Control, ETag, Expires
  2. How Cloudflare Decides What to Cache
  3. Cache Keys, Variants, and Query String Handling
  4. Edge TTLs and Origin Response Headers
  5. Cache Hits, Misses, Bypasses, and Stale Responses
  6. Reading and Understanding Cloudflare Cache Headers
  7. Chapter Summary

Chapter 14: Cache Rules, Page Rules, and Advanced Caching

  1. Cache Rules: The Modern Rule System
  2. Page Rules: Legacy Behavior and Migration Path
  3. Cache Reserve: Pay-For-Priority in Peak Times
  4. Tiered Caching: Two-Tier and Smart Tiered
  5. Cache Purging: Individual URLs, Tags, and Bulk
  6. Configuration Examples: Caching Strategy for a Real Application
  7. Chapter Summary

Chapter 15: Optimization Features: Compression, HTTP/2, HTTP/3, and Argo

  1. Compression: Gzip, Brotli, and Automatic Settings
  2. HTTP/2 and HTTP/3: Enable, Disable, and When It Matters
  3. Argo Smart Routing: Private Backbone and Latency Reduction
  4. Rocket Loader, Minify, and Miscellaneous Optimizations
  5. Measuring Impact: What Actually Moves the Needle
  6. Configuration Example: Performance Stack for a Dynamic Application
  7. Chapter Summary

Chapter 16: Cloudflare Workers

  1. What Workers Are: JavaScript at the Edge
  2. The Workers Runtime: V8 Isolates and Execution Model
  3. Routing: Hostnames, Patterns, and Dispatch
  4. Workers Examples: Rewrites, A/B Testing, Auth, and Transformations
  5. Limits, Quotas, and Cold Starts (Or Lack Thereof)
  6. Configuration: Wrangler, Deploy, and Environment Variables
  7. Chapter Summary

Chapter 17: Workers Data Products: KV, Durable Objects, D1, and Queues

  1. Workers KV: Global Key-Value Storage
  2. Durable Objects: Stateful Co-located Compute
  3. D1: SQLite at the Edge
  4. Queues: At-Least-Once Delivery for Background Work
  5. Choosing the Right Data Product: Comparison and Patterns
  6. Architecture Example: Worker-Powered API with KV and D1
  7. Chapter Summary

Chapter 18: Pages, R2, Stream, Images, and WebSockets

  1. Cloudflare Pages: Serverless-Style Static and Full-Stack Hosting
  2. R2: Object Storage Without Egress Fees
  3. Stream: Video Transcoding and Delivery
  4. Images: On-the-Fly Transformations
  5. WebSockets: Persistent Connections Through Cloudflare
  6. Architecture Example: Media-Rich Application on Cloudflare Platform
  7. Chapter Summary

Chapter 19: Cloudflare Load Balancing

  1. What Load Balancing Solves: Global Affinity and Failover
  2. Pools, Monitors, and Load Balancers
  3. Health Checks: HTTP, TCP, and Custom
  4. Steering Policies: Least Connections, Geolocation, and Custom
  5. Failover Behavior and Graceful Degradation
  6. Configuration Example: Multi-Region Application with Load Balancing
  7. Chapter Summary

Chapter 20: Advanced Architectures and Patterns

  1. Static Site Architecture on Cloudflare
  2. Dynamic Web Application Behind Cloudflare
  3. API-First Architecture with Edge Security
  4. Multi-Region Origins with Load Balancing and Tiered Cache
  5. Kubernetes and Containerized Backends Behind Cloudflare
  6. Private Origin Architectures with Tunnel and Access
  7. Chapter Summary

Chapter 21: Logging, Analytics, and Observability

  1. The Analytics Dashboard: Traffic, Performance, and Security
  2. Logpush: Exporting Logs to Your Systems
  3. Building Observability Pipelines with Cloudflare Data
  4. Metrics That Matter: Latency, Cache Ratio, Errors, and Threats
  5. Alerts and Notifications: Proactive Monitoring
  6. Example: Setting Up Full Observability for a Production Site
  7. Chapter Summary

Chapter 22: Troubleshooting Cloudflare Deployments

  1. The Troubleshooting Methodology: Isolate the Layer
  2. DNS and Resolution Issues
  3. SSL/TLS Errors and Misconfigurations
  4. Caching Problems: Stale Content and Unexpected Behavior
  5. Redirect Loops and Proxy Issues
  6. Worker Debugging and Routing Failures
  7. Common Configuration Mistakes and How to Avoid Them
  8. Chapter Summary

Chapter 23: Automation and Infrastructure as Code

  1. Cloudflare API: Authentication, Rate Limits, and Patterns
  2. Terraform Provider: State, Resources, and Modules
  3. CI/CD for Workers and Pages
  4. Automating Security Rules and DNS Changes
  5. GitOps and Configuration Management
  6. Example: Terraform Module for a Production Zone
  7. Chapter Summary

Chapter 24: Production Operations and Migration Strategies

  1. Migrating to Cloudflare: Strategy and Execution
  2. Cutover Strategies: Big Bang vs. Gradual
  3. Cost Management and Plan Selection
  4. Capacity, Limits, and Scaling Considerations
  5. Change Management and Rollback Procedures
  6. Running Cloudflare in Mission-Critical Environments
  7. Chapter Summary

Conclusion: The Edge as a Platform

  1. What You Know Now: The Edge Architecture Stack
  2. Choosing Cloudflare: When It Makes Sense and When It Does Not
  3. The Future of the Edge: Compute Everywhere
  4. A Practical Decision Framework
  5. Final Thoughts on Mastering the Edge

References

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub