私有化部署 · 企业软件授权 · 主控与节点均运行在您的基础设施中Self-hosted · licensed enterprise software · control plane and nodes run on your own infrastructure系统架构ArchitectureFAQ
自建 CDN 系统所需的核心能力,一个主控统一管理Every core capability a self-hosted CDN needs, managed from one control plane
从站点接入、缓存与回源,到安全防护、证书管理、日志分析和节点运维,均可在同一主控中统一管理,无需自行拼装多套开源组件。以下按能力领域介绍产品现有功能,以及支撑生产环境长期运行的运维与日志分析能力。From site onboarding, caching and origin pull to security, certificate management, log analytics and node operations — all managed from one control plane, with no need to assemble several open-source components yourself. Below, the product's capabilities are grouped by domain, along with the operations and log-analytics backbone that keeps production running over the long term.
六大核心领域,一站式主控管理Six core domains, one control plane to manage them all
从站点接入、缓存到安全防护、证书、日志分析与节点运维,均在同一主控中统一管理,无需自行拼装开源组件。From site onboarding and caching to security, certificates, log analytics and node operations — all managed from one control plane, no open-source assembly required.
站点接入与缓存Delivery & caching
支持域名接入、监听组、源站池负载均衡、主动健康检查和自动故障切换;提供缓存策略、缓存刷新下发,以及内存与磁盘两级缓存。Domain onboarding, listener groups, origin-pool load balancing, active health checks and automatic failover; cache rules, purge push, and a memory + disk two-tier cache.
支持 WAF 规则、IP 黑白名单和访问限速;CC 防护可在多节点间协同封禁;同时支持多种 JS Challenge、地域访问控制和慢速攻击防护。WAF rules, IP allow/deny lists and rate limiting; CC defense coordinates bans across nodes; plus multiple JS Challenge types, geo access control and slow-attack protection.
支持手动上传证书,也可通过 ACME 自动签发和续期(Let's Encrypt、ZeroSSL);提供兼容优先和性能优先两种证书策略,并支持 CNAME Target 及阿里云、Cloudflare、DNSPod 等 DNS 服务商授权。Manual certificate upload, or ACME auto-issue & renewal (Let's Encrypt, ZeroSSL); compatibility-first and performance-first cert strategies, plus CNAME targets and DNS credentials for Aliyun, Cloudflare and DNSPod.
ACMELet's EncryptZeroSSLRSA / ECDSACNAME
日志分析Log analytics
提供访问、流量、缓存、错误、回源和高可用日志;可选接入外置 ClickHouse;同时支持探测概览、CNAME / IP 可用性监控和实例审计。Access, traffic, cache, error, origin-pull and HA logs; optional external ClickHouse; plus a probe overview, CNAME / IP availability monitoring and instance audit.
统一管理边缘节点和回源中继。cdn-agent 支持签名在线升级;配置实时下发,并由节点本地缓存提供容错;同时提供健康心跳、备份恢复和任务队列。Manage edge nodes and origin relays together. cdn-agent supports signed online upgrades; config streams live with node-side cache tolerance; plus heartbeats, backup / restore and a task queue.
提供 REST API、API Token 与 OpenAPI 3.0 规范;支持边缘规则、脚本模板和 Edge KV,并隔离系统与用户命名空间;所有写操作均记录在审计日志中。REST API, API tokens and an OpenAPI 3.0 spec; edge rules, script templates and Edge KV with system / user namespace isolation; every write operation recorded in the audit log.
REST APIAPI TokenOpenAPI 3.0边缘规则Edge rulesEdge KV
03 · 运维与日志分析Operations
生产级运维保障,便于长期稳定运营Production-grade operations for long-term stability
升级、配置分发、审计和备份均采用可控、可回滚、可追溯的流程设计,便于系统在您的数据中心长期稳定运行。Upgrades, config distribution, audit and backup are designed to be controllable, reversible and traceable — so the system runs reliably in your own datacenter over the long term.
签名升级Signed upgrades
cdn-agent 下载升级包后,会校验 SHA-256 摘要与 Ed25519 签名,随后执行原子替换并重启,避免加载被篡改的二进制文件。After downloading an upgrade package, cdn-agent verifies its SHA-256 digest and Ed25519 signature, then atomically replaces and restarts — avoiding any tampered binary.
配置容错Resilient config
配置通过 gRPC Watch 增量实时下发;节点将最新配置持久化到本地。即使暂时与主控断连,也可继续使用最近一次有效配置提供服务。Config is pushed incrementally over gRPC Watch; nodes persist the latest config locally, so even when briefly disconnected from the control plane they keep serving from the last valid config.
操作审计Operation audit
所有写操作自动记录审计日志,并结合 admin、operator、viewer 三级角色权限,便于追踪操作人、操作时间和变更内容。Every write operation is recorded in the audit log, combined with admin, operator and viewer roles — making it easy to trace who changed what and when.
备份与恢复Backup & restore
支持创建和下载备份,并提供恢复前检查及回滚保留机制,使配置变更和回退过程更加可控。Create and download backups, with pre-restore checks and rollback retention — keeping configuration changes and rollbacks under control.
节点接入Node onboarding
通过安装脚本和注册令牌接入节点,利用双向 gRPC 心跳同步状态,无需向节点分发 SSH 凭据或密码。Onboard nodes with an install script and enrollment token, syncing state via bidirectional gRPC heartbeats — no SSH credentials or passwords distributed to nodes.
可选日志分析Optional log analytics
日志分析依赖可选部署的外置 ClickHouse。未接入时,相关页面显示为空状态,不影响内容分发主链路运行。Log analytics relies on an optionally deployed external ClickHouse. Without it, the related pages show an empty state and the main content-delivery path is unaffected.
把 CDN 的控制权掌握在自己手中Keep full control of your CDN
按节点数和授权站点数(以根域名 Zone 计)透明计费,可根据实际部署规模选择合适的授权档位。Transparent pricing by node count and licensed-site count (counted per root-domain Zone) — choose the licensing tier that matches your deployment.