改进面向公有云区域的 Smart Tiered Cache
Smart Tiered Cache 允许根据客户提供的云区域提示,为托管在 AWS、GCP、Azure 和 Oracle Cloud 上的源站进行精确的上层缓存层级选择。
Improving Smart Tiered Cache for Public Cloud Regions
详细说明
Blog Cache CDN Performance +3 Show 3 more tags
6 Tags Show 6 tags
Product News Smart Shield Tiered Cache
Cache CDN Performance Product News Smart Shield Tiered Cache
July 10, 2026
- Selected Tags
- Cache CDN Performance Product News Smart Shield Tiered Cache
- All tags
- Matching tags
- No tags found
- 1.1.1.1
- 2FA
- Abuse
- Access
- Access Control Lists (ACLs)
- Accessibility
- Account Takeover
- Acquisitions
- Addressing
- Advanced Certificate Manager
- Advanced DDoS
- Advertising
- Aegis
- Africa
- Afroflare
- Agent Readiness
- Agents
- Agents Week
- AI
- AI Bots
- AI Gateway
- AI Search
- AI-SPM
- AI WAF
- AI Week
- Alertmanager
- Always Online
- AMD
- AMP
- Analytics
- Anonymous
- Anti Malware
- Anycast
- API
- API Gateway
- API Security
- API Shield
- APJC
- Apple
- Application Security
- Application Services
- Area 1 Security
- Argo Smart Routing
- ASCII
- Asia
- Athenian Project
- Atlassian
- Attacks
- Audit Logs
- Austin
- Australia
- Authentication
- Authy
- Automatic HTTPS
- Automatic Platform Optimization
- Automation
- AutoMinify
- Auto Rag
- Awards
- AWS
- Baidu
- Bandwidth Alliance
- Bandwidth Costs
- Best Practices
- Beta
- Better Internet
- BGP
- Birthday Week
- Blackbird
- Black Friday
- Bot Fight Mode
- Bot Management
- Botnet
- Bots
- BPF
- Brand
- Brand Protection
- Brazil
- Browser Insights
- Browser Rendering
- Browser Run
- Bug Bounty
- Bugs
- BYOIP
- Cache
- Cache Purge
- Cache Reserve
- Cache Rules
- California
- Canada
- Cap'n Proto
- CAPTCHA
- Careers
- CASB
- Categories
- CDN
- CDNJS
- Certificate Authority
- Certificate Pinning
- Certificate Transparency
- Certification
- CFSSL
- Challenge Page
- ChatGPT
- China
- China Network
- Christmas
- Chrome
- CIO Week
- CISA
- Claire
- CLI
- ClickHouse
- Clientless
- Clientless Web Isolation
- Cloud Connector
- Cloud Email Security
- Cloudflare Access
- Cloudflare Apps
- Cloudflare Area 1
- Cloudflare Calls
- Cloudflare Email Service
- Cloudflare for Campaigns
- Cloudflare for SaaS
- Cloudflare for Startups
- Cloudflare Gateway
- Cloudflare History
- Cloudflare Images
- Cloudflare Media Platform
- Cloudflare Meetups
- Cloudflare Network
- Cloudflare One
- Cloudflare One Client
- Cloudflare One User Risk Score
- Cloudflare One Week
- Cloudflare Pages
- Cloudflare Polish
- Cloudflare Queues
- Cloudflare Realtime
- Cloudflare Stream
- Cloudflare Tunnel
- Cloudflare TV
- Cloudflare Workers
- Cloudflare Workers KV
- Cloudflare Workers KV (ES)
- Cloudflare Workers (PT)
- Cloudflare Zero Trust
- Cloudforce One
- Cloudy
- Code Orange
- Coinbase
- Colombia
- Community
- Compliance
- Compression
- Config Rules
- Configuration Management
- Congestion Control
- Connectivity
- Connectivity Cloud
- Consumer Services
- Containers
- Content Independence Day
- Content Scanning
- Context
- Core
- COVID-19
- Crawler Hints
- CrowdStrike
- Cryptography
- Crypto Week
- CSAM Reporting
- Customers
- Customer Success
- Customer Zero
- CVE
- CVE-2023-50387
- Cyber Readiness
- Cybersecurity
- D1
- Dashboard
- Data
- Database
- Data Catalog
- Data Center
- Data Localization
- Data Localization Suite
- Data Loss
- Data Loss Prevention
- Data Platform
- Data Privacy Day
- Data Protection
- Data Sovereignty
- Data Transfer Bucket
- DDoS
- DDoS Alerts
- DDoS Reports
- Debugging
- Deep Dive
- Descaler
- Design
- Deskope
- Developer Documentation
- Developer Platform
- Developers
- Developer Spotlight
- Developers Storage
- Developer Week
- Device Security
- DevOps
- DEX
- Digital Experience Monitoring
- Digital Forensics
- Disrupt
- Distributed
- Distributed Systems
- Distributed Web
- Diversity
- DLP
- DMARC
- DNS
- DNS Filtering
- DNS Flood
- DNSSEC
- DNS Security
- Dogfooding
- DoH
- Domain Rankings
- Domain Scoped Roles
- dosd
- Drupal
- Due Process
- Durable Execution
- Durable Objects
- Early Hints
- Earth Day
- eBPF
- EC2
- eCommerce
- Edge
- Edge Computing
- Edge Database
- Edge Rules
- Education
- Egress
- Elastic
- Elections
- Election Security
- Elliptic Curves
- Email Routing
- Email Security
- Email Workers
- EmDash
- Emissions
- Employee Resource Groups
- Encrypted SNI
- Encryption
- Engineering
- Enterprise
- Entropy
- EPYC
- Ethereum
- Europe
- European Union
- Events
- Exploit
- Fancy Bear
- Fast Fonts
- FCC
- Feature Flags
- FedRAMP
- FedRAMP High
- FedRAMP Moderate
- Firefox
- Firewall
- Firmware
- Florida
- Football
- Formal Methods
- Forrester
- Fortran
- Foundation DNS
- Founders' Letter
- France
- Fraud
- Free
- Freedom of Speech
- Front End
- Full Stack
- Full Stack Week
- Fun
- Gartner
- Gatebot
- GA Week
- GDPR
- General Availability
- Generative AI
- Gen X
- Geo Key Manager
- Germany
- GitHub
- Go
- Google Analytics
- Google Cloud
- Google Workspace
- Government Innovation
- Grace Hopper
- Grafana
- GraphQL
- Green
- Grinch
- Growth
- gRPC
- Guest Post
- Hackathon
- Halloween
- Hardware
- HashiCorp
- Hertzbleed
- Heuristics
- History
- Holidays
- Holocaust
- Hong Kong
- Hosting Con
- Hostnames
- HTTP2
- HTTP3
- HTTPS
- Human Rights
- Hurricane
- Hybrid Cloud
- Hyperdrive
- IBM
- ICANN
- iCloud Private Relay
- Identity
- IETF
- IL4
- Image Optimization
- Image Recognition
- Image Resizing
- Image Storage
- Impact
- Impact Week
- I'm Under Attack Mode
- Incident Report
- Incident Response
- India
- Indicators of Compromise
- Indonesian
- Infrastructure
- Infrastructure as Code
- Insights
- Intel
- Interconnection
- Internal DNS
- Internet Performance
- Internet Quality
- Internet Regulation
- Internet Shutdown
- Internet Summit
- Internet Traffic
- Internet Trends
- Internship Experience
- Intrusion Detection
- Investors
- IoCs
- iOS
- IoT
- IPFS
- IPsec
- IPv4
- IPv6
- IRAP
- Israel
- Italy
- IWD
- JAMstack
- Japan
- JavaScript
- Jengo
- Jengo Policy
- Joomla
- Judeoflare
- Kafka
- Kernel
- Keyless SSL
- KeyTrap
- Key Value
- Killnet
- Korea
- Kubernetes
- LangChain
- Latency
- Latin America
- Latinflare
- LavaRand
- Lazarus group
- Leaked Credential Checks
- Legal
- Legal Patents Sable
- LGBTQIA+
- Life at Cloudflare
- Linux
- Lisbon
- Live Streaming
- Llama
- LLM
- Load Balancing
- Localization
- Log4J
- Log4Shell
- Logging
- Log Push
- Logs
- LUA
- Machine Learning
- Magecart
- Magic Firewall
- Magic Network Monitoring
- Magic Transit
- Magic WAN
- Magic WAN Connector
- Malicious JavaScript
- Malware
- Managed Components
- Managed Rules
- March of Cloudflare
- MASQUE
- MCP
- Meerkat
- MeetUp
- Meris
- Message Protocol
- Mexico
- Micro-frontends
- Microsoft
- Microsoft 365
- Microsoft Azure
- Middle East
- Migration Hub
- Milestones
- Miniflare
- Mirage
- Mirai
- Mitel
- Mitigation
- Mixed Content Errors
- MLops
- Mobile
- Mobile SDK
- Model Context Protocol
- Moldova
- Monitoring
- Multi-Cloud
- Multi-User
- MySQL
- NaaS
- Net Neutrality
- Network
- Networking
- Network Interconnect
- Network Performance Update
- Network Protection
- Network Services
- New Year
- NGINX
- Ninjas
- NIST
- Node.js
- North America
- Notebooks
- Notifications
- NSEC3
- OAuth
- Observability
- Oceania
- OCSP
- Offices
- Okta
- Olympics
- Onboarding
- OpenAI
- Open API
- OpenBMC
- OpenDNS
- Open Source
- OpenSSL
- OpenTelemetry
- Optimization
- Origin Rules
- Outage
- Oxy
- Pacific Northwest
- Page Rules
- Page Shield
- Parallels
- Partners
- Partnership
- Password-reuse
- Passwords
- Passwords (PT)
- Patents
- PAYGO
- Payments
- Pay Per Crawl
- PCI Certified
- Peering
- Performance
- Phishing
- php
- Phython
- Pingora
- Pipelines
- PlanetScale
- Plans
- Platform Engineering
- Platform Week
- Plesk
- Policy & Legal
- Politics
- Portugal
- Postgres
- Post Mortem
- Post-Quantum
- Precursor
- Prepared Statements
- Prisma
- Privacy
- Privacy Pass
- Privacy Week
- Private IP
- Private Network
- Product Design
- Product News
- Programming
- Programming (PT)
- Project Fair Shot
- Project Galileo
- Project Honey Pot
- Project Pangea
- Project Safekeeping
- Project Turpentine
- Prometheus
- Protocols
- Proudflare
- Proxying
- Public Sector
- Python
- Queues
- QUIC
- QUICHE
- Quicksilver
- R2
- R2 Super Slurper
- Radar
- Radar Alerts
- Radar API
- Radar Maps
- Railgun
- Randomness
- Ransom Attacks
- Rapid Reset
- Raspberry Pi
- Rate Limiting
- RC4
- RDDoS
- React
- Reading List
- Real-time
- Recruiting
- Regional Services
- Registrar
- Reliability
- Remote Browser Isolation
- Remote Desktop Protocol
- Remote Work
- Replication
- Research
- Resolver
- Restreaming
- Retreat
- Reverse Engineering
- REvil
- Risk Management
- Road to Zero Trust
- Rocket Loader
- RocksDB
- Routing
- Routing Security
- RPKI
- RRDNS
- RSA
- Russia
- Rust
- Rust Workers
- SaaS
- SAAS Security
- Sable
- Salt
- Sampling
- Sandbox
- SASE
- Save The Web
- SDK
- Search Engine
- Secrets Store
- Secure Web Gateway
- Security
- Security Analytics
- Security Center
- Security Posture
- Security Posture Management
- Security Service Edge
- security.txt
- Security Week
- SEO
- Serverless
- Serverless AI
- Serverless (PT)
- Serverless Week
- Server Push
- Servers
- SIEM
- Signed Exchanges (SXG)
- SIM
- Singapore
- Single Sign On (SSO)
- Smart Placement
- Smart Shield
- Snippets
- SOC as a Service
- South Africa
- South America
- Spain
- spdy
- Spectrum
- Speed
- Speed Brain
- Speed & Reliability
- Speed Week
- Spoofing
- Sports
- SQL
- SRE
- SSE
- SSH
- SSL
- Standards
- Startup Enterprise Plan
- Statistics
- StopTheHacker
- Storage
- Sumo Logic
- Super Bowl
- Supercloud
- Supply Chain Attacks
- Support
- Sustainability
- SWAG
- SWG
- Swift
- Switzerland
- SXSW
- SYN
- SYN Flood
- Syria
- TCP
- Team
- Teams Dashboard
- TechCrunch
- Technical Writing
- Tech Talks
- Terraform
- Testimonials
- Testing
- Texas
- Thanksgiving
- The Serverlist Newsletter
- Threat Data
- Threat Feeds
- Threat Intelligence
- Threat Operations
- Threats
- Tiered Cache
- TikTok
- TLS
- TLS 1.3
- Tools
- Tor
- Tracing
- Traffic
- Transform Rules
- Transparency
- Trends
- Trust & Safety
- TTFB
- TTL
- TURN
- TURN Server
- Turnstile
- TypeScript
- UDP
- Ukraine
- United Kingdom
- Universal SSL
- URL Scanner
- USA
- User Research
- VDI
- Vectorize
- Vetflare
- Video
- Visibility
- Vite
- VoIP
- VPC
- VPN
- Vulnerabilities
- WAF
- WAF Attack Score
- WAF Rules
- Waiting Room
- WARP
- WARP Connector
- WASM
- Web3
- Web Application Firewall
- WebAssembly
- Web Asset Discovery
- Webinars
- WebP
- WebRTC
- WebSockets
- Wildebeest
- Womenflare
- WordPress
- Workers AI
- Workers Launchpad
- Workers Logs
- Workers Observability
- Workers Sites
- Workers Unbound
- Workers VPC
- Workflows
- World IPv6 Day
- Wrangler
- x402
- Year in Review
- Z3
- Zaraz
- Zero Day Threats
- Zero Trust
- Zero Trust Week
- Zone Versioning
Improving Smart Tiered Cache for Public Cloud Regions
Chenxi Zhang
7 minute read
COPY URL
In 2021, we shipped Smart Tiered Cache . The idea: for each origin behind your site, Cloudflare picks the single best upper-tier data center to route through, based on real-time latency. Flip one switch, and we find the fastest path from our network to your origin.
That works as long as an origin IP lives in one fixed place. Public cloud origins usually don't. They sit behind anycast or regional unicast front ends, so one origin IP can look equally close to a dozen Cloudflare data centers at once — and the latency probes have nothing to lock onto. Smart Tiered Cache handles this the safe way: when there's no clear winner, it falls back to several upper tiers. Nothing breaks. You just lose the thing that made a single closest tier worth it, which is cache efficiency.
Smart Tiered Cache for Public Cloud Regions fixes this by letting you provide a cloud region hint. With that hint, Cloudflare can map public cloud origins to the right region and select better primary and fallback upper tiers, even when the origin IP itself looks anycast or ambiguous.
We made our most popular tiered cache topology smarter
Since it was launched, Smart Tiered Cache has become the most popular tiered cache topology among Cloudflare customers. It’s available to all plans, for free.
Much of our work aims to continually improve it. Over time, we’ve extended Smart Tiered Cache to handle more origin architectures, including:
Each of these improvements has shared a common goal: understand the customer’s origin infrastructure and automatically do the best thing for that infrastructure.
While we’ve been improving this system for a while, customers still had a common frustration: Smart Tiered Cache did not work when an origin is behind an anycast or regional unicast network, because this architecture prevented us from knowing where the origin is located. And this wasn’t an edge case, either. Origins hosted on public cloud providers behind anycast IPs are a growing slice of the Internet.
Today, we’re closing that gap for origins hosted on AWS, GCP, Azure, and Oracle Cloud.
- November 2024 : Smart Tiered Cache for R2 : We taught Smart Tiered Cache to automatically select the closest upper tier to where the R2 bucket actually lives, reducing latency with zero configuration.
- January 2025 : Smart Tiered Cache for Load Balancing : We extended Smart Tiered Cache to select a single optimal upper tier for an entire Load Balancing pool, so all origins in the pool share the same cache, improving hit ratios.
Why anycast cloud origins are different
Smart Tiered Cache works by measuring the latency from each Cloudflare data center to the origin’s IP address. The data center with the lowest latency becomes the upper tier: the single point through which all cache misses funnel on their way to your origin. By concentrating cache misses at one data center, you get higher cache hit ratios, fewer connections to your origin, and lower latency on origin pulls. This works well when the origin has a fixed, unicast IP address that can be reliably probed.
Many cloud providers use anycast or regional unicast networking for their load balancers, front-end services, and regional ingress points. When we probe these IPs, the origin appears to be “close” to many data centers simultaneously. That is because the IP address represents the cloud provider’s front end, not a single physical origin location. Different Cloudflare data centers may reach different nearby cloud edges for the exact same IP, and the provider then carries the request across its own network to the actual backend. So Smart Tiered Cache cannot confidently pick one best upper tier.
In practice, this could result in hairpin traffic across continents, adding a whole extra round trip. Say your origin sits in Singapore, behind an anycast IP from a cloud provider. Because of how anycast works, our Chicago data center might show the lowest probe latency to that IP. Smart Tiered Cache would then select Chicago as the upper tier. The result: a request from an end user in Asia hits a nearby Cloudflare data center, gets routed cross-continent to the upper tier in Chicago, and Chicago fetches from the origin back in Singapore, crossing the ocean twice. That hairpinning adds hundreds of milliseconds of latency, and it's one of the most consistently reported issues from customers with cloud-hosted origins.
An example of hairpinning is when traffic is routed to an upper tier in Chicago only to fetch data from an origin in Singapore, resulting in an unnecessary cross-continental round trip. To address this unnecessary back-and-forth, Smart Tiered Cache learned to detect anycast origins with a constraint from physics: the speed of light. We measure probe latencies from multiple checkpoint data centers around the world to the origin. If the combined latencies from two checkpoint data centers are faster than what light in fiber could physically travel between the two, the origin must be answering from multiple locations, not one. That means it's anycast.
We detect anycast origins by comparing probe latencies from multiple Cloudflare data centers. If two paths are faster than physically possible for a single origin location, the origin is likely answering from multiple places. When Smart Tiered Cache detects an anycast origin, it plays it safe: it won't pin that IP to a single upper tier. Instead, it falls back to a tiered cache topology with multiple upper tiers. Tiered caching still works, but spreading traffic across multiple tiers instead of one means more requests reach the origin. For some setups that’s a fine trade. But if you want one upper tier close to an origin that lives on a public cloud behind anycast IPs, there hasn't been a good option — until now.
Tell us the region
From the Cloudflare dashboard, go to Caching > Tiered Cache > Origin Configuration . Find your origin IP, click "Set Region Hint," and tell us the cloud region (for example, aws:us-east-1 or gcp:europe-west1). Smart Tiered Cache takes over from there. Note that, on the dashboard, region hints can only be set for origins whose IPs we've detected as anycast.
On the Tiered Cache page, go to the Origin Configuration table and click the edit icon next to an origin IP to set its region hint. You can set hints one IP at a time, or bulk-edit cloud regions for all your origin IPs at once. Beyond the dashboard, the same configuration is available via the API and through Terraform, so you can integrate it into your existing infrastructure-as-code workflows.
We're launching with AWS, GCP, Azure, and Oracle Cloud, with more providers coming.
How Smart Tiered Cache for Public Cloud Regions works
Every few hours, we fetch the latest IP range files from each supported cloud provider. These files map every cloud region to its current set of IP prefixes, so when a provider adds, removes, or reassigns a subnet, we pick it up.
Smart Tiered Cache for Public Cloud system diagram We match those subnets against our upper tier database, which is built from continuous latency probing refreshed every 15 minutes. For each cloud region, each matching subnet contributes a weighted vote based on its current upper-tier assignment. The upper tier with the strongest signal becomes the region’s primary upper tier. Primary and fallback always come from different points of presence (PoPs), so losing one PoP can't take out both.
Some regions don't have enough probe data, for example, perhaps the new region’s cloud provider is still rolling out, or the region has no origin onboarded to Cloudflare yet — so there’s nothing to vote on. We fall back to geography: the closest of our Tier 1 PoPs. As origins come online and probe data builds up, the region quietly switches from that geographic guess to the option backed by real data.
Try it now, and what's next
All this means that the work of selecting the optimal region for your cache — the constant probing, the algorithmic choice of each region's best upper tier, the geographic fallbacks, the failover across PoPs — runs on our side. Your job is selecting the region hint.
If your anycast origin sits on a public cloud, you can turn this on now. In the dashboard, go to Caching > Tiered Cache > Origin Configuration . Find your origin IP, click Set Region Hint, and pick your region.
Next up, we’re expanding to more providers, and continuing to teach Smart Tiered Cache to recognize more origin setups and pick the right path on its own. To learn more about how Tiered Cache can benefit your service, check out our Tiered Cache documentation .
Related tags
Cache CDN Performance Product News Smart Shield Tiered Cache
Follow on Social Media
- Cloudflare