Hippius CDN
The Hippius CDN serves the objects of one of your S3 buckets from cache nodes close to your visitors. It is open to every account, in the console under CDN in the sidebar.
How it works
A zone is a CDN in front of one bucket, or one folder (prefix) of it. As soon as you create it, the zone is served over HTTPS on its default hostname, ZONE_ID.c.hipcdn.net. You can add your own domains to it.
- Origins. Hippius S3 buckets, public or private. Other web servers (HTTP(S) origins) aren't supported yet.
- Regions. Cache nodes serve from France (FR) and Australia (AU). Visitors in Oceania are sent to AU (or to FR if AU has no node up), everyone else to FR. The shield region of a zone is the cache the other regions fill from: pick the one nearest the bucket. FR is the default.
- Limits. 10 zones per account and 20 custom domains per zone.
Create a zone
- Open CDN in the sidebar and click New zone.
- Pick the Bucket. Optionally enter a prefix, such as
public/, to serve only the objects under it. - Give the zone a name, choose the shield region and the monthly spend cap ($20 by default, from $1 to $100,000).
- Create it. The default hostname serves right away.
A zone in front of a private bucket creates a read-only key on that bucket for the cache nodes, so creating one needs admin access to S3 as well as to CDN on a shared account.
What visitors receive
- HTTPS. Plain HTTP requests are redirected to HTTPS (301), unless you turn that off in the zone's settings.
- GET and HEAD only. Other methods get 405. Range requests work.
- Content type. Each object is served with the
Content-Typestored in S3. Only when it has none, or a generic one (application/octet-stream), is it guessed from the extension, and only for images, audio, video, fonts, CSS, JavaScript, JSON, WebAssembly and plain text. HTML, SVG and XML are never guessed: upload them with an explicitContent-Type.X-Content-Type-Options: nosniffis always sent. - HTML on the default hostname is sandboxed. On
ZONE_ID.c.hipcdn.net, HTML, SVG and other XML getContent-Security-Policy: sandbox allow-scripts. On your own domains they don't, so serve a website from a custom domain. - Headers passed through from the object:
Content-Type,Content-Length,Content-Range,Content-Encoding,Content-Language,Content-Disposition,ETag,Last-ModifiedandAccept-Ranges.
Objects uploaded from the console keep the file's type, so they are served with it, HTML included. See Uploading objects.
Use your own domain
On the zone's Hostnames tab, click Add domain and enter the name, for example www.example.com. The console then shows the DNS records to create at your DNS provider:
| Record | What it does |
|---|---|
CNAME www.example.com → the zone's default hostname | Sends visitors to the CDN and proves you own the name. |
TXT _hippius-cdn.www.example.com | Optional for a subdomain: proves ownership before you move the CNAME. |
CNAME _acme-challenge.www.example.com | Required for the HTTPS certificate. |
The domain is checked every minute for the first hour, every 10 minutes for a day, then hourly for 7 days. Check now checks it at once. Once the DNS is proven, the certificate is issued and the domain turns Active.
- A bare domain (
example.com) needs an ALIAS, ANAME or flattened CNAME record at your DNS provider, and the TXT record. Route 53 can't alias to another provider's name: redirect the bare domain towwwinstead. - CAA records. Certificates come from Let's Encrypt or Google Trust Services. If your domain or a parent domain has CAA records, they must allow both
letsencrypt.organdpki.goog, or no certificate can be issued. Without CAA records, there is nothing to do. - Wildcard domains (
*.example.com) aren't supported. - If a domain's DNS stops pointing at the zone, it stops being served. Fixing the DNS within 7 days restores it.
Cache rules and purging
By default, a zone caches successful responses (200 and 206) for 1 hour and 404s for 1 minute. Redirects (3xx) and server errors (5xx) aren't cached. Visitors get Cache-Control: public, max-age=3600. The origin's own Cache-Control and Expires are ignored. The query string isn't part of the cache key, and isn't sent to the bucket: a file is cached once per path.
The Cache rules tab holds an ordered list of up to 50 rules. Each rule matches a path prefix, a glob or a list of file extensions, and sets one or more actions: how long the cache keeps a file (edge_ttl), how long browsers keep it (browser_ttl), which query parameters are part of the cache key, whether to bypass the cache, and whether to ignore Set-Cookie. Rules are evaluated top to bottom. Click Save rules to save the list.
Cache nodes don't apply cache rules yet: until they do, every zone uses the defaults above, and the console shows a banner. Rules you save now take effect once they are switched on.
The Purge tab invalidates what you name on every cache node: paths, folders (prefixes ending in /), or everything. The next request for it is fetched from the origin. A purge usually reaches every node in under 30 seconds. You can purge up to 100 times a minute per zone, and everything once a minute.
Prices
The CDN is billed by the hour from your balance, like Compute. Nothing is free: billing starts at the first byte.
| What | Price |
|---|---|
| Data billed in FR or NL | $0.010 per GB |
| Data billed in AU | $0.060 per GB |
| Requests | $0.002 per 10,000 |
| Custom domain | $1 per domain per month, from the first one, billed by the hour while the domain and its zone are active |
The default hostname is included. Data is counted in GB of 109 bytes, headers included. Requests the CDN refuses itself, such as those of a paused zone, aren't billed.
Billing region. Each byte is billed at the cheaper of two regions: the one that served it, and your visitor's. A visitor in Oceania counts as AU, and a visitor anywhere else, or whose country is unknown, is billed at the cheapest region. So a byte served from Australia to a visitor in Europe costs the FR price, and a failover never raises your bill.
Prices can change. The console's CDN pages show the current ones, and the create form has a cost estimate. CDN lines appear in Compute Usage with the rest of your hourly usage.
Monthly spend cap
Each zone has a monthly spend cap, $20 by default. The month's spend is checked every minute.
- At 80% of the cap, you get an email.
- At the cap, the zone is paused: requests get an error, and they aren't billed. Because the spend is checked every minute, it can end slightly above the cap. Raise the cap on the zone's Settings tab and it serves again at once. Otherwise it resumes on the 1st of the next month.
Emails
The account owner is emailed when a zone reaches 80% of its cap, is paused by its cap or serves again, is suspended or blocked, when a custom domain turns active or needs action (DNS not proven after a day, certificate not issued, DNS moved), when a certificate is about to expire or has expired, and on the 1st of each month with a summary of last month's CDN usage, if there was any.
Where to next
- S3 Buckets: create the bucket that serves as your origin.
- Billing and quotas: how hourly usage is charged.
- Shared accounts: give team members access to your CDN.