Skip to main content

Request and response headers

Do not place secrets in static request headers when console users without secret-handling responsibility can read distribution configuration.

Compression

  • Gzip compresses eligible content for compatible clients.
  • Brotli requires a MIME type list and, in this platform configuration, Origin Shield.
  • Pull pre-compressed content retrieves prebuilt compressed variants from the origin.
Brotli cannot be combined with pull pre-compressed content. When Brotli is enabled, include text/html in its MIME type list.

Protocols and methods

Explicitly enable allowed HTTP methods. GET, HEAD, and OPTIONS cover most delivery workloads. Enable write methods only when the origin and cache policy are designed for them. WebSocket support permits connection upgrades. gRPC passthrough permits gRPC traffic where the origin and hostname configuration support it.

Bandwidth limiting

Static limits use configured speed and buffer values. Dynamic limits derive behavior from query parameters. Validate that a client cannot bypass or amplify a dynamic policy by modifying the URL.