Skip to main content

Resource hierarchy

Definitions

The customer and billing boundary. An account can belong to multiple organizations with a different role in each.
The resource and authorization boundary inside an organization. A project owns its API keys, quotas, CDN resources, DNS resources, Cloud Shield configuration, and TLS certificates.
A non-human credential containing an access key, a secret, a status, and project permissions. The Gateway resolves the project from the key.
One or more sources from which a Cloud CDN distribution retrieves content. Origins can be primary or backup and can use failover conditions.
A Cloud CDN delivery resource with an edge hostname, an origin group, and configuration for cache, network, TLS, headers, origin behavior, security, and images.
An authoritative Cloud DNS namespace such as example.com. It contains SOA settings and record sets.
Records sharing the same owner name and type, plus a TTL, routing pickers, optional health-check metadata, and one or more resource records.

Console and API context

Browser requests select an organization and project. The console sends Aptranet-Organization-ID and selects the project through the project query parameter on project-scoped requests. API-key requests do not send these headers: the project is bound to the key at creation time.
Product API paths use /cloud-cdn, /cloud-dns, /shield, and /tls-manager. The older /cdn and /dns aliases exist for compatibility, but new integrations should use the canonical paths.