Skip to main content
Last Reviewed: 2026-09-29

Next-generation Global CDN

Upgrade to Next-generation GCDN with bot protection

Learn how to migrate from Pantheon's Legacy Global CDN to our Next-generation Global CDN.


Setup

Warning:
Do Not Upgrade Sites That Use AGCDN

The next-generation GCDN is becoming compatible with Advanced Global CDN (AGCDN) sites in waves. If your site uses AGCDN, do not start the upgrade from the dashboard or with terminus gcdn:upgrade until Pantheon Support or your Account Team confirms your site is compatible. Starting the upgrade automatically moves your site's platform hostnames (*.pantheonsite.io) to the next-generation GCDN.

If you've already started the upgrade on an AGCDN site, do not change your DNS records. Contact Pantheon Support for next steps.

Warning:
Important

For the best experience, be prepared to update your DNS records as soon as possible after starting the migration. Delaying DNS migration can result in inconsistent behavior, as your site will remain on the old CDN infrastructure until DNS is pointed to the new GCDN.

Warning:
Custom Domains Must Not Use CNAMEs to Platform Hostnames

Custom domains that use a CNAME record in their DNS settings that point to a Pantheon platform hostname (for example, live-yoursite.pantheonsite.io) are not supported by the next-generation GCDN and will not be supported going forward. Sites configured this way will experience interruptions when migrated.

Before activating the next-generation GCDN, check your custom domain's DNS configuration. It must resolve via A/AAAA records as shown on the site's Domains page, not via a CNAME pointed at a *.pantheonsite.io hostname. If the Domains page shows Remove this detected record next to a CNAME, remove it from your DNS provider. See Custom Domains for details.

If your custom domain currently points at a platform hostname via CNAME, contact Pantheon Support before requesting migration.

Using Cloudflare in Front of Pantheon (Orange-to-Orange)

If your domain is already proxied through your own Cloudflare zone (orange-clouded), the next-generation GCDN supports Cloudflare's Orange-to-Orange (O2O) configuration. This lets you keep your existing Cloudflare zone — including your WAF rules, Workers, and other settings — in front of Pantheon's GCDN.

Warning:
Terminus Plugin Required

O2O setup is only available through the GCDN Terminus plugin. The dashboard migration flow does not support O2O. Install the plugin and upgrade your site with terminus gcdn:upgrade (see the Terminus CLI tab in Setup) before starting the steps below.

Because your DNS is hosted in Cloudflare, the standard TXT-record verification flow does not apply. Instead, you will add a specific set of records in your Cloudflare zone. Apart from step 1 (Terminus), every step below is performed in the Cloudflare dashboard, in the zone that currently serves your domain. The order matters: do not point traffic at Pantheon until your certificate is active.

Before You Begin

  • Your site must already be upgraded to the next-generation GCDN (terminus gcdn:upgrade <site>).
  • You need access to your Cloudflare account with permission to edit DNS records and SSL/TLS settings (and, on Enterprise plans, Zone Holds).

1. Get your O2O record set

This prints the records for each domain: the hostname ownership TXT record, the DCV delegation CNAME, and the final traffic CNAME. You will only need the DCV delegation CNAME and the traffic CNAME in the steps below. The <domain> argument is optional — omit it to list records for every Cloudflare domain on the environment, or pass one to limit output to a single hostname:

2. Release your Zone Hold (Enterprise plans only)

Zone Holds are a Cloudflare Enterprise feature, enabled by default on Enterprise zones. If your Cloudflare zone is on a Free, Pro, or Business plan, it does not have a Zone Hold — skip this step and step 6.

If your zone has a Zone Hold (especially with Also prevent subdomains enabled), release it temporarily so Cloudflare can process the new custom hostname: on the zone homepage, go to Quick Actions and switch Zone Hold to Off. You will re-enable it at the end.

3. Set your SSL/TLS encryption mode to Full or Full (strict)

In your Cloudflare zone, set SSL/TLS > Overview to Full or Full (strict). Other modes (such as Flexible) cause infinite redirect loops between your Cloudflare zone and the GCDN.

4. Add the DCV delegation CNAME

In the Cloudflare dashboard, go to DNS > Records for your zone and add the CNAME from the gcdn:o2o output, set to DNS only (grey-clouded):

This delegates certificate validation to the GCDN for both initial issuance and automatic renewal. Leave this record in place permanently and keep it grey-clouded — removing it or proxying it will break certificate renewal.

Before moving to the next step, confirm the _acme-challenge CNAME has propagated using a DNS propagation checker such as DNS Checker, or from the command line:

The record has propagated when the query returns the dcv.cloudflare.com target.

5. Point traffic at the GCDN

Only after your certificate is active, update your hostname's CNAME to the GCDN edge:

Traffic routes to Pantheon as soon as this record is in place. The record can be Proxied (orange-clouded, O2O) to keep your Cloudflare zone in front, or DNS only if you want traffic to reach the GCDN directly.

6. Re-enable your Zone Hold (if applicable)

Once traffic is flowing, re-enable the Zone Hold released in step 2 to re-secure your zone.

Information:
Note

O2O requires CNAME records. Using A/AAAA records is not compatible with O2O and may result in site downtime or inaccessibility. We welcome feedback on O2O configurations in the Pantheon Community Slack.

Using a Third-Party CDN in Front of Pantheon

You can place a third-party CDN or reverse proxy in front of the next-generation GCDN, with one hard requirement: on every request it sends to Pantheon, the fronting service must present a TLS Server Name Indication (SNI) value that matches the HTTP Host header.

The next-generation GCDN routes and validates custom domains using the SNI value in the TLS handshake. Requests whose SNI does not match the Host header are rejected at the edge with a 403 response before they reach your site. This is intentional security behavior that prevents domain fronting, and it cannot be disabled for individual domains.

When configuring your CDN, for each custom domain:

  • Add the domain to your Pantheon environment and complete domain verification so a certificate is provisioned.
  • Set the CDN's origin address to the GCDN edge hostname shown in your dashboard DNS values (the fe. CNAME target).
  • Set both the origin Host header and the outbound TLS SNI to the custom domain itself (for example, www.example.com), not the fe. edge hostname.

If your CDN cannot set the outbound SNI independently of the configured origin hostname, it cannot be used in front of the next-generation GCDN. Azure Front Door currently has this limitation (see Known Limitations).

If the service in front of Pantheon is your own Cloudflare zone, use the Orange-to-Orange configuration instead.