CoolStrike Edge Hydrographic Office

Sheet 2 · Station fit-out · Edition 2026.1

What is inside a station.

All sixteen are built to one fit-out, so a request behaves the same in Dublin as it does in Tallinn. Here is what that means when you have to operate around it.

Fit-out 01

Bare metal, tuned per site

Debian stable on hardware we own. Nothing else shares the forwarding path — no other tenant's traffic, no hypervisor between the NIC and the cache.

The kernel network stack is tuned to the traffic each site actually carries: a station fronting a media library does not want the socket buffers of one fronting a JSON API. We publish the sysctl set we run, and we will run yours instead if you have a reason for it.

Operating system
Debian 13, unattended security upgrades
Cache tier
NVMe, 24–96 TB per station
Uplink
2 × 100 GbE minimum, 4 × at core sites
Peering
Present at the local IX at every station

Fit-out 02

Certificates that renew themselves

A SAN certificate is issued as soon as your domain validates, and renewed thirty days before expiry at every station at once. Nobody has to hold a calendar reminder.

TLS 1.3 is the default and 1.2 stays available until you turn it off. If your policy needs a particular chain, upload the PEM bundle — it reaches all sixteen stations in under a minute, and the dashboard shows you which ones have it.

Protocols
TLS 1.3, 1.2 optional
Renewal
Automatic, 30 days before expiry
Custom chain
PEM upload, < 60 s to propagate
Stapling
OCSP stapled, refreshed hourly

Fit-out 03

Absorbed at the shore

Volumetric floods are dropped at the station that receives them. That is the useful side effect of anycast: an attack aimed at one address arrives spread across sixteen sites rather than concentrated on one, and each site only has to survive its own share.

Layer 7 filtering runs inline on the same box. Real requests are never parked in a queue while traffic is diverted to a scrubbing centre somewhere else and a decision is made about them.

L3/L4 capacity
11.2 Tbit/s, network-wide
Time to mitigate
Automatic, no ticket required
Layer 7
Inline rules, per-route rate limits
After the event
Per-attack report within the hour

Fit-out 04

Origins, weighted and watched

Health checks run from every station rather than from one central prober. A region that cannot reach your origin stops sending to it while the rest of the network carries on — which is usually what you want, because the fault is often the path, not the server.

Weighting is geographic by default and can be pinned by hand. Draining an origin is one change and takes effect at the edge within seconds, so you can patch a box during the day.

Check interval
5 s from each station
Failover
2 consecutive failures
Algorithms
Geographic, round-robin, weighted
Drain
Immediate, no connection cut short

Standard fit-out

The same at every station.

Where a station differs, it differs upward — core sites carry more uplink and more cache, never less of anything below.

Minimum specification, applied network-wide.
ItemStandardCore sites
Uplink2 × 100 GbE4 × 100 GbE
Cache tier24 TB NVMe96 TB NVMe
Egress capacity400 Gbit/s1600 Gbit/s
HTTPHTTP/2, HTTP/3 (QUIC)HTTP/2, HTTP/3 (QUIC)
CompressionBrotli, gzip, on the flyBrotli, gzip, on the fly
PurgeBy URL, prefix or tagBy URL, prefix or tag
Purge propagation< 3 s< 3 s
LogsReal-time stream or S3 deliveryReal-time stream or S3 delivery

Come alongside

See it carry your own traffic.

A trial runs on the same fit-out as everything above. Nothing is held back for paying accounts.