Google Cloud CDN

by Google Cloud

Google Cloud’s content delivery network, integrated with Cloud Load Balancing (Google’s description: caching at Google’s edge).

See https://cloud.google.com/cdn

Features

  • Global edge caching on Google’s network (Anycast; latency benefit not measured here)
  • Tight integration with global external Application Load Balancer
  • Cache modes and fine-grained cache key configuration (path, query string, headers)
  • Time-to-Live (TTL) controls and cache-control header support
  • Cache invalidation / purge API
  • Negative caching for common error responses (e.g., 404)
  • SSL/TLS termination and support for managed certificates
  • Logging and telemetry via Cloud Logging and Cloud Monitoring
  • Integration with Cloud Armor (DDoS protection claim not verified)
  • Support for origins on GCP (Cloud Storage, Compute Engine, GKE) and external origins (hybrid/multi-cloud)
  • Signed URLs and signed cookies for access control

Claimed strengths (vendor positioning; opinion)

  • Enabled per backend of a global external Application Load Balancer.
  • Google states it uses its global network and Anycast routing (latency and reliability gains vs other CDNs not verified).
  • Serverless NEG backends (Cloud Run, Cloud Functions, App Engine) and Cloud Storage origins are listed as supported in the draft (not re-verified).
  • Cache hit ratio, origin fetch and latency metrics in Cloud Monitoring (draft; not re-verified).

AI features

None in the Cloud CDN overview (checked 2026-10-05). Service Extensions allow custom request processing at the edge; Cloud Armor adds security policies.

Typical use cases

  • Static asset delivery (images, JS/CSS, video) from Cloud Storage
  • Dynamic site acceleration with cacheable responses
  • Global API acceleration (cacheable GET responses)
  • Hybrid origin acceleration where origin lives on-prem or in another cloud
  • Protecting origins from traffic spikes (opinion)

Cache control and behavior (practical notes)

  • Cache respects Cache-Control and Expires headers by default; you can override behavior with CDN cache modes.
  • Configure TTLs appropriate to content: long TTLs for immutable assets, short or revalidate for rapidly changing content.
  • Use cache keys to vary cache by query string, selected headers, or cookies when needed, but avoid over-variation which reduces hit ratio.
  • Use negative caching to avoid repeated origin hits for missing resources.
  • Purge (invalidate) content programmatically when you need immediate updates; propagation time is not verified here.

Security and access

  • Use HTTPS with managed certificates or bring-your-own certs.
  • Protect applications with Cloud Armor (WAF), rate limiting, and IP-based access controls.
  • Use signed URLs / signed cookies for private content distribution.

Monitoring & troubleshooting

  • Enable Cloud Logging to get request logs routed from load balancer/edge.
  • Key metrics: cache hit ratio, cache egress, cache fill (origin fetches), latency, HTTP error rates.
  • Use Cloud Monitoring dashboards and create alerts on low cache-hit ratios or high origin egress to detect misconfiguration.

Pricing (summary)

  • Pricing components (per draft, not verified) include: load balancing charges, CDN cache egress (dependent on region), cache fill (egress from origin to edge), and operations (invalidations, requests).
  • Always consult the official pricing page for up-to-date regional rates: https://cloud.google.com/cdn/pricing

Integration notes

  • Google Cloud CDN is enabled at the backend service level of an global external Application Load Balancer.
  • Works with Cloud Storage buckets (public or private with signed URLs) as origins, Compute Engine instance groups, GKE backends, and Serverless NEGs.
  • Supports hybrid origins via External Backends or by using Cloud CDN with Cloud Load Balancing configured to reach on-prem origins over Interconnect or VPN.

Limitations & gotchas

  • Per Google’s overview, Cloud CDN works only with the global external Application Load Balancer or the classic Application Load Balancer; other load balancer types are not supported.
  • Highly dynamic responses that change per-request may be poor candidates for caching unless you implement fine-grained cache keys or cache bypass logic.
  • Opinion: varying the cache key on many headers can reduce hit ratio.

References

Related: Cloud Load Balancing, Cloud Storage, Cloud Run, App Engine.

Sources

Fetched 2026-10-05.

Open items

  • Media CDN (Google’s separate media-delivery product) was not covered or verified.
  • Cache-mode names, invalidation propagation behaviour and DDoS statements are carried over from the original draft; the overview confirms cache modes, signed URLs, Cloud Armor and Service Extensions.