Sheet 2 · Station fit-out · Edition 2026.1
What is inside a station.
All sixteen are built to one fit-out, so a request behaves the same in Dublin as it does in Tallinn. Here is what that means when you have to operate around it.
Fit-out 01
Bare metal, tuned per site
Debian stable on hardware we own. Nothing else shares the forwarding path — no other tenant's traffic, no hypervisor between the NIC and the cache.
The kernel network stack is tuned to the traffic each site actually carries: a station fronting a media library does not want the socket buffers of one fronting a JSON API. We publish the sysctl set we run, and we will run yours instead if you have a reason for it.
- Operating system
- Debian 13, unattended security upgrades
- Cache tier
- NVMe, 24–96 TB per station
- Uplink
- 2 × 100 GbE minimum, 4 × at core sites
- Peering
- Present at the local IX at every station
Fit-out 02
Certificates that renew themselves
A SAN certificate is issued as soon as your domain validates, and renewed thirty days before expiry at every station at once. Nobody has to hold a calendar reminder.
TLS 1.3 is the default and 1.2 stays available until you turn it off. If your policy needs a particular chain, upload the PEM bundle — it reaches all sixteen stations in under a minute, and the dashboard shows you which ones have it.
- Protocols
- TLS 1.3, 1.2 optional
- Renewal
- Automatic, 30 days before expiry
- Custom chain
- PEM upload, < 60 s to propagate
- Stapling
- OCSP stapled, refreshed hourly
Fit-out 03
Absorbed at the shore
Volumetric floods are dropped at the station that receives them. That is the useful side effect of anycast: an attack aimed at one address arrives spread across sixteen sites rather than concentrated on one, and each site only has to survive its own share.
Layer 7 filtering runs inline on the same box. Real requests are never parked in a queue while traffic is diverted to a scrubbing centre somewhere else and a decision is made about them.
- L3/L4 capacity
- 11.2 Tbit/s, network-wide
- Time to mitigate
- Automatic, no ticket required
- Layer 7
- Inline rules, per-route rate limits
- After the event
- Per-attack report within the hour
Fit-out 04
Origins, weighted and watched
Health checks run from every station rather than from one central prober. A region that cannot reach your origin stops sending to it while the rest of the network carries on — which is usually what you want, because the fault is often the path, not the server.
Weighting is geographic by default and can be pinned by hand. Draining an origin is one change and takes effect at the edge within seconds, so you can patch a box during the day.
- Check interval
- 5 s from each station
- Failover
- 2 consecutive failures
- Algorithms
- Geographic, round-robin, weighted
- Drain
- Immediate, no connection cut short
Standard fit-out
The same at every station.
Where a station differs, it differs upward — core sites carry more uplink and more cache, never less of anything below.
| Item | Standard | Core sites |
|---|---|---|
| Uplink | 2 × 100 GbE | 4 × 100 GbE |
| Cache tier | 24 TB NVMe | 96 TB NVMe |
| Egress capacity | 400 Gbit/s | 1600 Gbit/s |
| HTTP | HTTP/2, HTTP/3 (QUIC) | HTTP/2, HTTP/3 (QUIC) |
| Compression | Brotli, gzip, on the fly | Brotli, gzip, on the fly |
| Purge | By URL, prefix or tag | By URL, prefix or tag |
| Purge propagation | < 3 s | < 3 s |
| Logs | Real-time stream or S3 delivery | Real-time stream or S3 delivery |
Come alongside
See it carry your own traffic.
A trial runs on the same fit-out as everything above. Nothing is held back for paying accounts.