Caching and invalidation
Full-page caching for anonymous traffic in a Varnish instance dedicated to each site. The WordPress plugin purges only the URLs affected by a change, so the cache stays warm.
Layer 7 Edge Caching™ sits between your visitors and your WordPress origin. Anonymous page views are answered from a dedicated Varnish cache, attacks are filtered before they reach PHP, and TLS is terminated and renewed for you. Your hosting stays exactly as it is: you only point DNS to the platform.
Caching and invalidation
Full-page caching for anonymous traffic in a Varnish instance dedicated to each site. The WordPress plugin purges only the URLs affected by a change, so the cache stays warm.
Always Online
When the origin is down or returns server errors, expired pages keep being served from cache for up to 48 hours while you fix the problem.
Web application firewall
CrowdSec IP reputation and behavioral bans, virtual patching for known vulnerabilities, and per-site rules for XML-RPC, geo blocking and WordPress hardening.
TLS and domains
Let’s Encrypt certificates issued once DNS is verified and renewed automatically, or your own certificate. www handling, alias domains and Multisite included.
Routing
Send specific paths to other backends, strip path prefixes or override the Host header, with first-match ordering you control.
Observability
Hit rate, bandwidth and request volume per site, live request logs, and email alerts when the origin stops responding.
Add the site in the admin panel with its domain and the IPv4 address of your origin. It is deployed immediately, over HTTP, so you can test it with a hosts file entry before switching any traffic.
Point your DNS to the platform. The DNS page shows each record to create and checks it live. HTTPS is enabled automatically as soon as every record resolves correctly.
Install the WordPress plugin with the site’s API key, found under Settings → Access. From then on, publishing or editing content purges exactly the pages that changed.
Read the full guide to adding a site →
Every request follows the same path: load balancer, Traefik, CrowdSec, the site’s Varnish instance, then your origin over HTTPS. Configuration changes are compiled to VCL and hot-loaded without a restart, so cached content survives every settings change.
| Layer | Component | Role |
|---|---|---|
| Edge proxy | Traefik v3 | TLS termination, HSTS, routing, redirects |
| Firewall | CrowdSec | IP bans, community blocklist, AppSec virtual patching |
| Cache | Varnish 9 | One instance per site, VCL generated from your settings |
| Orchestration | Docker Swarm | Multi-node cluster, rolling updates |