System design · Edge caching and the launch stampede

How to design Netflix's video delivery (CDN)

Designing video delivery for a streaming service is a senior-level system design interview favourite. Almost all of the traffic is video bytes, almost all of those bytes should come from a cache close to the viewer, and the failure that interviewers probe for is the cold-cache stampede when a new show launches to millions of viewers at once.

Updated · 5 min read

Run it: click through the fixes and watch the numbers change

Live simulationFailing
no cdnUsers20,000 req/sAPI Server×820,000 req/scapacity 8,000 req/sCache8,000 req/scapacity 100,000 req/sDatabase×4800 req/sreads 3,000 · writes 1,000 req/s
p99 latency
274ms
Errors
60.0%
Cost
$1,348/mo

The API tier can serve 8,000 req/s but is receiving 20,000. 60% of requests fail. More API servers behind a load balancer would share the load.

Real simulator engine, not an animation.Edit in the playgroundTrigger a cache stampede in the playground
Embed this simulation in your blog, docs or course

Free to embed. Paste this HTML anywhere that accepts an iframe.

Requirements

  • Functional: a viewer presses play and the video starts quickly, then keeps playing without rebuffering; quality adapts to the viewer's connection.
  • Non-functional: start-up time of a couple of seconds, very low rebuffering, and a system that survives a launch where a large share of viewers start the same title in the same hour.
  • Scope the question: delivery of video bytes, not recommendations, billing or the upload pipeline - unless the interviewer asks.

Capacity estimates

QuantityAssumptionResult
Concurrent viewers at peak10 million-
Average bitrate5 Mbit/s (HD)10M × 5 Mbit/s = 50 Tbit/s of egress
Catalogue10,000 titles × 20 encodings × 5 GB≈ 1 PB of encoded video
One origin server≈ 40 Gbit/s of egress> 1,000 servers if every byte came from origin

The numbers make the architecture obvious: no central data centre can push 50 Tbit/s to the world. Bytes must be served from caches close to viewers, and the origin should see only a small fraction of requests.

How video is served

  • Encode each title into a ladder of resolutions and bitrates, then split each encoding into small segments of a few seconds.
  • The player fetches a manifest (HLS or DASH) listing the segments, then downloads segments one by one over plain HTTP.
  • Adaptive bitrate: the player measures throughput and picks the next segment's quality, so a slow connection drops to a lower bitrate instead of stalling.
  • Because segments are immutable files fetched over HTTP, they are perfect for caching at the edge with long TTLs.

High-level design

The control plane and the data plane are separate. The control plane (API servers in a cloud region) handles login, browsing and "play", and returns a manifest whose segment URLs point at the best edge cache for that viewer. The data plane is the CDN: edge servers inside ISPs and internet exchange points that serve the segments.

  • Viewer → API (control plane) → manifest with edge URLs.
  • Viewer → nearest edge cache → on miss, a regional cache or origin shield → origin storage.
  • Netflix runs its own CDN, Open Connect, placing cache appliances inside ISP networks; many other services use commercial CDNs.

Where it breaks: the cold-cache stampede

A cache only protects the origin when it already holds the content. When a new title launches, the edge caches are cold: every viewer's first request misses, and all of those misses go to the origin at the same moment. In the simulation above, switching the CDN to a cold cache sends the full 20,000 requests per second back to an API tier that can serve 8,000, and 60% of requests fail.

The same thing happens after a cache flush, a deploy that changes cache keys, or a TTL that expires for a hot object at the same instant everywhere.

Preventing the stampede

  • Pre-position content: push a title to edge caches before launch, during off-peak hours, based on predicted popularity. Netflix's Open Connect fills its appliances this way.
  • Origin shield: put a regional caching tier between the edges and the origin, so a thousand edge misses for the same segment become one origin request.
  • Request coalescing: when many requests miss on the same object at once, let one fetch it and the rest wait for that result.
  • Staggered TTLs: add jitter to expiry times so hot objects don't all expire at the same moment.
  • Multiple CDNs and steering: route viewers to another CDN or edge when one is overloaded or down.

Hit ratio is the lever

Every point of cache hit ratio removes load from everything behind the edge. At a 70% hit ratio the origin serves 30% of requests; at 95% it serves 5% - six times less. Viewing is highly concentrated on a small share of popular titles, which is what makes very high hit ratios achievable for streaming. In the simulation, pre-warming the CDN from 70% to 95% cuts origin traffic from 6,000 to 1,000 requests per second.

What interviewers look for

  • You estimated egress bandwidth and concluded that edge caching is mandatory.
  • You separated the control plane from the data plane.
  • You explained segments, manifests and adaptive bitrate.
  • You raised the cold-cache stampede and gave several defences: pre-positioning, origin shield, coalescing and TTL jitter.
  • You reasoned about hit ratio quantitatively.

Frequently asked questions

What is a cache stampede or thundering herd?

+

A cache stampede happens when many requests miss the cache at the same time - after a cold start, a flush or a simultaneous expiry - and all of them hit the origin at once, overwhelming it. Pre-warming, request coalescing, origin shields and TTL jitter prevent it.

How does a CDN reduce load on the origin?

+

It caches content at edge locations close to viewers. With a high hit ratio, most requests are served from the edge and never reach the origin, which cuts latency for viewers and load on the origin at the same time.

What is origin shield?

+

An extra caching layer between edge servers and the origin. Many edge misses for the same object are collapsed into a single request to the origin, which protects it during misses and stampedes.

What is adaptive bitrate streaming?

+

Video is encoded at several bitrates and split into short segments. The player measures its download speed and chooses the bitrate of each next segment, so playback continues at lower quality instead of stalling when the connection slows.

Does Netflix use a CDN?

+

Yes. Netflix operates its own CDN called Open Connect, with cache appliances installed inside internet service providers and at internet exchange points. Popular content is pushed to those appliances ahead of demand.

Now break one yourself.

The first challenge takes about two minutes. No signup.