Skip to main content
Cloud CDN security controls are distribution-level access policies. They supplement application authorization; they do not replace it.

Access-control lists

Country, IP, referrer, and user-agent policies support two modes:
  • Allow all except listed: block the listed values.
  • Deny all except listed: allow only the listed values.
Country values use validated country codes. IP entries should be explicit addresses or networks accepted by the configuration UI. Test deny-by-default policies from an allowed and a disallowed network before production rollout.

Signed URLs

Secure-key protection requires a signing key and token type. Token type can include or exclude the client IP from validation.
A signing key grants access to protected URLs. Generate it outside Aptranet, store it as a secret, and never expose it in client code or documentation.

Defense in depth

  • Validate authorization at the application origin.
  • Keep origin services patched and restrict direct access where possible.
  • Use HTTPS and origin certificate validation.
  • Avoid caching denial or authenticated responses under a shared key.
  • Review ACL values after network, vendor, or workforce changes.