Skip to content

Layer 7 Edge Caching

A managed caching reverse proxy and web application firewall for WordPress, built on Varnish, Traefik and CrowdSec.

Layer 7 Edge Caching™ sits between your visitors and your WordPress origin. Anonymous page views are answered from a dedicated Varnish cache, attacks are filtered before they reach PHP, and TLS is terminated and renewed for you. Your hosting stays exactly as it is: you only point DNS to the platform.

Caching and invalidation

Full-page caching for anonymous traffic in a Varnish instance dedicated to each site. The WordPress plugin purges only the URLs affected by a change, so the cache stays warm.

Always Online

When the origin is down or returns server errors, expired pages keep being served from cache for up to 48 hours while you fix the problem.

Web application firewall

CrowdSec IP reputation and behavioral bans, virtual patching for known vulnerabilities, and per-site rules for XML-RPC, geo blocking and WordPress hardening.

TLS and domains

Let’s Encrypt certificates issued once DNS is verified and renewed automatically, or your own certificate. www handling, alias domains and Multisite included.

Routing

Send specific paths to other backends, strip path prefixes or override the Host header, with first-match ordering you control.

Observability

Hit rate, bandwidth and request volume per site, live request logs, and email alerts when the origin stops responding.

  1. Add the site in the admin panel with its domain and the IPv4 address of your origin. It is deployed immediately, over HTTP, so you can test it with a hosts file entry before switching any traffic.

  2. Point your DNS to the platform. The DNS page shows each record to create and checks it live. HTTPS is enabled automatically as soon as every record resolves correctly.

  3. Install the WordPress plugin with the site’s API key, found under Settings → Access. From then on, publishing or editing content purges exactly the pages that changed.

Read the full guide to adding a site →

Every request follows the same path: load balancer, Traefik, CrowdSec, the site’s Varnish instance, then your origin over HTTPS. Configuration changes are compiled to VCL and hot-loaded without a restart, so cached content survives every settings change.

Layer Component Role
Edge proxy Traefik v3 TLS termination, HSTS, routing, redirects
Firewall CrowdSec IP bans, community blocklist, AppSec virtual patching
Cache Varnish 9 One instance per site, VCL generated from your settings
Orchestration Docker Swarm Multi-node cluster, rolling updates

Explore the architecture →