Building a Multi-Point Private CDN: Bypassing International Network Bottlenecks with Caddy Reverse Proxy on Vietnam VPS
Introduction: The Vulnerability of Global Infrastructure
In the modern digital economy, website performance is directly tied to business revenue. For enterprises targeting the Vietnamese market, relying solely on global Content Delivery Networks (CDNs) presents a hidden vulnerability: international undersea fiber optic cable disruptions. When critical cables like the AAG, APG, or IA experience faults, routing traffic to international edge servers becomes a bottleneck, causing severe latency and packet loss.
To mitigate this risk, forward-thinking engineering teams are pivoting toward a hybrid architecture by deploying a Multi-Point Private CDN. By leveraging domestic Virtual Private Servers (VPS) and configuring them as localized edge nodes, you can cache and serve content directly within the country, completely bypassing international network congestion. This technical guide provides a production-ready framework to architect, configure, and deploy a private CDN using Caddy Server as a reverse proxy across two Vietnam-based VPS providers.
---Architectural Overview: Multi-Point Private CDN
A Private CDN works on a simple yet highly effective principle: positioning reverse proxy caching servers as close to the end-user as possible. Instead of users fetching assets directly from a distant Origin Server (which might be hosted in Singapore, Japan, or the US), their requests are intercepted by domestic edge nodes.
For this architecture, we utilize two distinct Vietnam VPS providers (for example, Viettel IDC and VNPT, or FPT Hi GIO Cloud and CMC Telecom). This geographical and provider diversity ensures high availability. If one domestic network experiences localized peering issues, traffic automatically routes to the secondary domestic node.
Why Choose Caddy Server over Nginx?
While Nginx has historically been the industry standard for reverse proxying, Caddy Server has emerged as a formidable alternative for modern DevOps workflows due to several distinct advantages:
- Automatic TLS/SSL Management: Caddy natively integrates with Let's Encrypt and ZeroSSL, automatically issuing, renewing, and configuring HTTP/S certificates without requiring external cron jobs or Certbot configurations.
- Performance and Concurrency: Written in Go, Caddy utilizes modern HTTP/3 protocols out of the box, offering exceptional concurrency handling and memory safety.
- Human-Readable Configuration: The Caddyfile structure is highly intuitive, reducing human error during complex routing setups.
Prerequisites and Environment Setup
Before initiating the deployment, ensure your infrastructure meets the following baseline criteria:
- Origin Server: The central server hosting your primary web application, databases, and assets (can be located anywhere internationally).
- Edge Node 1 (VPS-VN-01): A clean Ubuntu 22.04 LTS or 24.04 LTS instance located in Vietnam (e.g., Hanoi Data Center).
- Edge Node 2 (VPS-VN-02): A clean Ubuntu 22.04 LTS or 24.04 LTS instance located in Vietnam (e.g., Ho Chi Minh City Data Center).
- DNS Management: Access to your domain's DNS zone file (Cloudflare, Route 53, or local registrars) supporting Anycast or Round-Robin routing.
Note: For optimal performance, ensure both VPS instances have at least 1 Gbps network port speed and sufficient SSD storage allocated for caching static assets.---
Step-by-Step Implementation Guide
Step 1: Installing Caddy Server on Vietnam Nodes
Perform the following commands on both VPS-VN-01 and VPS-VN-02 to install the latest stable version of Caddy Server from the official repository:
sudo apt install -y debian-keyring debian-archive-keyring apt-transport-https
curl -1sLf '[https://dl.cloudsmith.io/public/caddy/stable/gpg.key](https://dl.cloudsmith.io/public/caddy/stable/gpg.key)' | sudo gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg
curl -1sLf '[https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt](https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt)' | sudo tee /etc/apt/sources.list.details.d/caddy-stable.list
sudo apt update
sudo apt install caddyVerify that the service is active and running via systemd:
systemctl status caddyStep 2: Configuring the Caddyfile for Reverse Proxying and Caching
Navigate to the Caddy configuration directory and modify the main file. We will configure Caddy to act as an edge proxy that caches static content while dynamically passing backend requests to the origin server.
Execute sudo nano /etc/caddy/Caddyfile on both nodes and apply the following production configuration framework:
cdn.yourdomain.com {
# Enable compression for faster content delivery
encode gzip zstd
# Reverse Proxy configuration targeting your Origin Server
reverse_proxy [https://origin.yourdomain.com](https://origin.yourdomain.com) {
header_up Host {upstream_host_header}
header_up X-Real-IP {remote_host}
header_up X-Forwarded-For {remote_host}
header_up X-Forwarded-Proto {scheme}
# Health check to monitor origin stability
health_uri /health-check
health_interval 10s
health_timeout 5s
}
# Cache control overrides for static media
@static_assets {
path *.jpg *.jpeg *.png *.gif *.css *.js *.ico *.woff2 *.webp
}
header @static_assets Cache-Control "public, max-age=2592000, stale-while-revalidate=86400"
# Security Header Enhancements
header {
X-XSS-Protection "1; mode=block"
X-Content-Type-Options "nosniff"
X-Frame-Options "DENY"
Referrer-Policy "no-referrer-when-downgrade"
}
# Logging configuration for traffic analysis
log {
output file /var/log/caddy/cdn_access.log {
roll_size 10mb
roll_keep 10
roll_keep_for 216h
}
}
}Replace cdn.yourdomain.com with your target user-facing domain and [https://origin.yourdomain.com](https://origin.yourdomain.com) with the actual IP address or hostname of your central origin server. Save the file and reload the configuration:
sudo caddy reload --config /etc/caddy/CaddyfileStep 3: Optimizing Linux Kernel for High-Throughput Networking
Because these edge nodes will handle high levels of concurrent TCP connections, it is necessary to optimize the underlying Linux kernel network stack. Append the following parameters to /etc/sysctl.conf on both Vietnam VPS instances:
# Increase max file descriptors
fs.file-max = 2097152
# Maximize network buffer allocations
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
# Enable TCP BBR Congestion Control
net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr
# Increase backlog limits
net.core.netdev_max_backlog = 100000
net.ipv4.tcp_max_syn_backlog = 100000
net.ipv4.tcp_tw_reuse = 1Apply the changes instantly by executing sudo sysctl -p.
DNS Configuration for Multi-Point Routing
Now that both edge nodes are functional, you must configure your DNS provider to distribute incoming traffic across both VPS servers in Vietnam. There are two primary deployment strategies:
Method A: DNS Round-Robin (Cost-Effective)
Create two distinct A Records pointing to the same sub-domain, each referencing a different VPS IP address:
cdn.yourdomain.com-> A Record ->IP_ADDRESS_VPS_VN_01cdn.yourdomain.com-> A Record ->IP_ADDRESS_VPS_VN_02
The user's local DNS resolver will cycle through these IPs, distributing load relatively evenly across both infrastructure points.
Method B: GeoDNS / Failover Routing (Enterprise Grade)
For critical enterprise operations, implement a managed DNS solution (such as Cloudflare Advanced Traffic Manager, Route53, or NS1). Configure a policy stating that traffic originating from Northern Vietnam routes preferentially to VPS-VN-01 (Hanoi), while Southern traffic defaults to VPS-VN-02 (Ho Chi Minh City), with automated health checks to failover to the surviving node if one goes offline.
Validation and Performance Metrics
To verify that your newly constructed Private CDN is effectively caching and shielding your origin server during international fiber outages, run the following curl command from a local machine within Vietnam:
curl -I [https://cdn.yourdomain.com/assets/main.css](https://cdn.yourdomain.com/assets/main.css)Analyze the HTTP response headers. You should observe a valid SSL handshake mediated entirely by Caddy, along with the custom Cache-Control rules established in your Caddyfile. Furthermore, running a traceroute or network latency test should show server response times dropping significantly—from standard 150ms-250ms international roundtrips down to 5ms-20ms domestic responses.
Conclusion
Building a multi-point Private CDN using Caddy Server across localized Vietnam VPS providers is a strategic, high-yield infrastructure upgrade. It grants your enterprise absolute sovereignty over content delivery networks, immunizes your platform against recurring international submarine cable disruptions, and drastically enhances your localized user experience. By deploying this architecture, you insulate your digital operations from global network dependencies, ensuring that your enterprise apps stay fast, secure, and accessible no matter what happens beyond domestic borders.
