Docs

Use a CDN

You can enable a CDN for your subdomains to serve static content from your deployments. This can improve the speed at which your content is delivered to users without needing to deploy in multiple regions, and reduce the load on your instances.

You may also choose to deliver stale content, which means your site will still be accessible even if your deployment becomes unavailable.

There is no extra cost to use a CDN with your Northflank deployment.

Click here to view your account domains page.

Enable CDN for a subdomain

Northflank's CDN requires the subdomain to route through public ingress. It cannot be enabled for a VPC-routed subdomain, even if its service port also has public exposure. Before moving a subdomain to VPC ingress, disable its CDN.

Customer-managed CDN and VPC integrations have their own connectivity requirements.

You must configure each subdomain individually to use a CDN.

Your subdomain must be linked to a deployment's port to use a CDN.

To enable CDN for a subdomain:

  1. Open your team domains page .
  2. Click the settings for the subdomain.
  3. Turn on the Northflank CDN switch.

Northflank enables CDN with the current or default configuration. The card shows its status. Enablement takes time, so wait until it shows that the CDN is active.

To change the configuration, edit the CDN fields below the switch. Click Update to save the changes.

Geographic routing requires Northflank CDN, so you cannot disable it for these subdomains.

For a subdomain with path-based routing, turn off the Northflank CDN switch to disable the CDN. Click Disable CDN in the confirmation dialog. The status and network diagram reflect the change when it finishes.

Configuring CDN settings for a subdomain in the Northflank application

Configure Fastly CDN

Logging

If enabled, Fastly logs for your services will be streamed to Northflank. Logs from Fastly can be viewed by navigating to a container in the deployment service associated with the subdomain, and selecting all containers from the observability header.

HTTP/3

You can enable connections between end users and Fastly to be upgraded to HTTP/3 (QUIC protocol). Connections between Northflank and Fastly will still use up to HTTP/2. HTTP/3 requires that all connections are secured using TLS. Learn more.

Force TLS and enable HSTS

If enabled, all requests must use TLS and will be redirected from http to https. You must set the HSTS duration, it is recommended to set this to the maximum possible value of 31557600 (1 year) for production applications.

Serve stale content on origin failure

When enabled Fastly will serve stale content to your users if your Northflank deployment cannot be reached. The Stale if Error TTL defines how long content will be served for if the origin cannot be reached. The default value is 43200 seconds, or 12 hours.

Default TTL

Set the default time-to-live (TTL) in seconds. Fastly will serve cached data for the defined TTL, and then fetch from the origin after the TTL has expired. The default value is 3600, or 1 hour.

Compression

If enabled, content sent from Fastly to end users will be compressed using the selected format (gzip or Brotli). This can potentially improve speeds as well as reduce costs.

© 2026 Northflank Ltd. All rights reserved.

northflank.com / Terms / Privacy / feedback@northflank.com