Google Cloud CDN
by Google Cloud
Google Cloud’s content delivery network, integrated with Cloud Load Balancing (Google’s description: caching at Google’s edge).
See https://cloud.google.com/cdn
Features
- Global edge caching on Google’s network (Anycast; latency benefit not measured here)
- Tight integration with global external Application Load Balancer
- Cache modes and fine-grained cache key configuration (path, query string, headers)
- Time-to-Live (TTL) controls and cache-control header support
- Cache invalidation / purge API
- Negative caching for common error responses (e.g., 404)
- SSL/TLS termination and support for managed certificates
- Logging and telemetry via Cloud Logging and Cloud Monitoring
- Integration with Cloud Armor (DDoS protection claim not verified)
- Support for origins on GCP (Cloud Storage, Compute Engine, GKE) and external origins (hybrid/multi-cloud)
- Signed URLs and signed cookies for access control
Claimed strengths (vendor positioning; opinion)
- Enabled per backend of a global external Application Load Balancer.
- Google states it uses its global network and Anycast routing (latency and reliability gains vs other CDNs not verified).
- Serverless NEG backends (Cloud Run, Cloud Functions, App Engine) and Cloud Storage origins are listed as supported in the draft (not re-verified).
- Cache hit ratio, origin fetch and latency metrics in Cloud Monitoring (draft; not re-verified).
AI features
None in the Cloud CDN overview (checked 2026-10-05). Service Extensions allow custom request processing at the edge; Cloud Armor adds security policies.
Typical use cases
- Static asset delivery (images, JS/CSS, video) from Cloud Storage
- Dynamic site acceleration with cacheable responses
- Global API acceleration (cacheable GET responses)
- Hybrid origin acceleration where origin lives on-prem or in another cloud
- Protecting origins from traffic spikes (opinion)
Cache control and behavior (practical notes)
- Cache respects Cache-Control and Expires headers by default; you can override behavior with CDN cache modes.
- Configure TTLs appropriate to content: long TTLs for immutable assets, short or revalidate for rapidly changing content.
- Use cache keys to vary cache by query string, selected headers, or cookies when needed, but avoid over-variation which reduces hit ratio.
- Use negative caching to avoid repeated origin hits for missing resources.
- Purge (invalidate) content programmatically when you need immediate updates; propagation time is not verified here.
Security and access
- Use HTTPS with managed certificates or bring-your-own certs.
- Protect applications with Cloud Armor (WAF), rate limiting, and IP-based access controls.
- Use signed URLs / signed cookies for private content distribution.
Monitoring & troubleshooting
- Enable Cloud Logging to get request logs routed from load balancer/edge.
- Key metrics: cache hit ratio, cache egress, cache fill (origin fetches), latency, HTTP error rates.
- Use Cloud Monitoring dashboards and create alerts on low cache-hit ratios or high origin egress to detect misconfiguration.
Pricing (summary)
- Pricing components (per draft, not verified) include: load balancing charges, CDN cache egress (dependent on region), cache fill (egress from origin to edge), and operations (invalidations, requests).
- Always consult the official pricing page for up-to-date regional rates: https://cloud.google.com/cdn/pricing
Integration notes
- Google Cloud CDN is enabled at the backend service level of an global external Application Load Balancer.
- Works with Cloud Storage buckets (public or private with signed URLs) as origins, Compute Engine instance groups, GKE backends, and Serverless NEGs.
- Supports hybrid origins via External Backends or by using Cloud CDN with Cloud Load Balancing configured to reach on-prem origins over Interconnect or VPN.
Limitations & gotchas
- Per Google’s overview, Cloud CDN works only with the global external Application Load Balancer or the classic Application Load Balancer; other load balancer types are not supported.
- Highly dynamic responses that change per-request may be poor candidates for caching unless you implement fine-grained cache keys or cache bypass logic.
- Opinion: varying the cache key on many headers can reduce hit ratio.
References
- Google Cloud CDN overview: https://cloud.google.com/cdn
- CDN guides (cache keys, invalidation, negative caching): https://cloud.google.com/cdn/docs
- Pricing: https://cloud.google.com/cdn/pricing
Related: Cloud Load Balancing, Cloud Storage, Cloud Run, App Engine.
Sources
Fetched 2026-10-05.
- Cloud CDN overview: https://docs.cloud.google.com/cdn/docs/overview
- Pricing: https://cloud.google.com/cdn/pricing
Open items
- Media CDN (Google’s separate media-delivery product) was not covered or verified.
- Cache-mode names, invalidation propagation behaviour and DDoS statements are carried over from the original draft; the overview confirms cache modes, signed URLs, Cloud Armor and Service Extensions.