Skip to content
CDN · Domains & SSL

Domains & SSL

Managing domains

Add custom domains to your CDN deployment with automatic SSL certificate provisioning.

On this page9 sections

Adding a domain#

Each domain you add to a deployment needs to be configured with a domain name and an origin source:

  • Domain: the domain or subdomain visitors will use (e.g. cdn.yoursite.com).
  • Origin type: where the CDN fetches content from:
    • External URL: pull content from any HTTP/HTTPS endpoint: your origin server, another cloud provider’s storage, or any web-accessible URL. Example: https://your-bucket.s3.amazonaws.com.
    • Storage Bucket: use an Edge Storage bucket as your origin. No external URL is needed: select one of your buckets directly. This suits static assets, images and files. Learn more about Edge Storage.

DNS configuration#

After adding a domain, you need to configure your DNS to point to Edge CDN.

Add a CNAME record:

Text
cdn.yoursite.com.  CNAME  cdn.edge.network.

Add Domain modal with domain and origin fields

Domain status#

Domains go through several states during setup.

DNS status#

  • pending: waiting for you to configure DNS
  • verified: DNS is correctly configured
  • failed: DNS check failed; verify your CNAME record

SSL status#

  • issuing...: certificate is being issued (30–60 seconds)
  • active: a valid SSL certificate is in place
  • failed: certificate issuance failed; check DNS

Automatic SSL certificates#

Edge CDN automatically provisions free SSL certificates for all domains using Let’s Encrypt.

  • Free certificates: no cost for SSL; included with every domain
  • Auto-renewal: certificates renew automatically before expiry
  • Fast issuance: certificates issued in under 60 seconds
  • TLS 1.3: modern encryption with the latest TLS version

Editing the domain origin#

You can change the origin for any domain at any time without removing and re-adding it.

  1. Click the domain row you want to edit.
  2. The Edit Domain Origin modal opens.
  3. Select a new origin type (External URL or Storage Bucket).
  4. Enter the new origin URL or select a different bucket.
  5. Click Save Changes.

Root path behaviour#

Control what happens when visitors access the root path (/) of your CDN domain directly.

Proxy to origin (default)#

Requests to the root path are proxied to your origin as normal. Use this if your origin has content at its root.

Redirect to URL#

Redirect visitors to a URL of your choice. Useful when your CDN subdomain should redirect to your main site.

  • 301 Permanent: for permanent redirects (SEO-friendly, browsers cache it)
  • 302 Temporary: for temporary redirects (not cached)

Show Edge info page#

Display a simple branded page identifying the domain as an Edge CDN endpoint. Useful for CDN-only subdomains that shouldn’t be browsed directly.

Password protection#

Any CDN domain can be protected with a username and password (HTTP Basic Auth). Visitors are prompted for credentials by their browser before anything is served. This is useful for sharing a dev build or staging site on a public URL without making it public.

  1. Open your deployment’s Domains tab.
  2. Click the lock icon on the domain you want to protect.
  3. Enable Require a username and password and set the credentials.
  4. Click Save. Protection is live on the edge within seconds.
  • Enforced at the edge: credentials are checked before the cache and origin; protected content is never served without them, not even from cache.
  • Hashed storage: passwords are stored as bcrypt hashes; edge nodes never see the plaintext, and failed attempts are naturally rate-limited by the hash cost.
  • SSL keeps working: certificate issuance and renewal are exempt from the check, so protected domains still get automatic SSL.
  • No performance cost: verified credentials are cached at the edge, so authenticated requests are served at full CDN speed.

Removing a domain#

You can remove a domain from your deployment at any time.

  1. Click the trash icon next to the domain you want to remove.
  2. Confirm the removal in the modal.
  3. The domain and its SSL certificate are removed.

Next steps