Skip to main content
Origin Shield adds a cache layer between Cloud CDN delivery nodes and your origin. It is configured per distribution and billed as an add-on to the organization’s Cloud CDN subscription.

Enable and configure

Open the distribution’s Origin Shield page. Review the current price and billing terms, select an available location, and confirm activation. You need Modify distribution permission, available project quota, and an eligible active billing configuration. Choose a location based on your origin and workload. The API returns the available locations; do not hard-code a location ID from another account or environment.

Billing and cancellation

Enabling can create a prorated charge for the remainder of the billing period, followed by recurring charges. Review the price shown before confirming. Cancellation schedules removal at the billing period’s end; protection remains enabled until that date. Resume a scheduled cancellation when you want the add-on to renew again. Origin Shield also enables delivery features that depend on this cache layer, including Brotli configuration where supported. Review dependent rules before cancelling it.

API

Read /cloud-cdn/distributions/shield?distribution=42 for enabled state, location, available locations, price text, cancellation date, and billing-period end when available. PUT the same endpoint with enabled, location_id, and optional resume to change it. Refresh state after every successful change. Cloud Shield provides application security and has its own plan and configuration.