Bucket CDN

Serve a bucket’s public files (article images, downloads, video posters) from edge caches close to your readers instead of from the bucket’s single origin. Tandem sets up the CDN, the DNS record and the TLS certificate, and renews the certificate for you. The CDN costs nothing extra; transfer is still counted.

Available in the portal (Project → Buckets → CDN) and over MCP (enable_bucket_cdn, disable_bucket_cdn, purge_bucket_cdn). Both use the same checks: you need the developer role or higher in the organization.

Turn it on

{ "name": "enable_bucket_cdn",
  "arguments": { "bucketId": "…", "customHostname": "media.example.com", "ttlSeconds": 86400 } }
  • customHostname (optional): a subdomain of a domain whose DNS your organization hosts on Tandem, such as media.example.com. It cannot be the bare domain (example.com), and the name must not already have DNS records. Leave it out to get a platform hostname such as my-project-media-ab12cd34.cdn.launchtandem.com.
  • ttlSeconds (optional): how long edge servers keep a copy. One of 60, 600, 3600 (default), 86400, 604800.

Setup runs in the background and usually takes a few minutes. list_buckets (or the portal) shows cdn.status:

status meaning
provisioning Edge endpoint, DNS record and certificate are being set up.
active Serving. Use cdn.baseUrl + the object key.
error Setup keeps failing (cdn.lastError says why). Tandem keeps retrying; the platform team is alerted.
disabling Being removed.

Use the hostname

An object stored at key 2026/09/flood.jpg is served at:

https://media.example.com/2026/09/flood.jpg

Put that URL in your pages. Pick the hostname you want to keep before you start saving URLs into content. URLs on the CDN hostname keep working if Tandem later moves your bucket to a different storage backend, because the hostname is yours (or Tandem’s), not the storage provider’s. Moving to a different hostname later means rewriting the URLs already saved in your content.

We recommend a custom hostname on your own domain. It keeps your content portable even if you leave Tandem.

Only public objects are served

The CDN serves only objects that were uploaded with the public-read ACL. For example, with the AWS SDK: ACL: "public-read" on PutObject, or aws s3 cp … --acl public-read. A private object returns 403 AccessDenied on the CDN hostname, just as it does on the bucket itself. Keep using pre-signed URLs for private files. The CDN never makes a private object public.

Update or delete files: purge

Edge servers keep a copy until the TTL runs out. After you overwrite or delete an object, purge it:

{ "name": "purge_bucket_cdn",
  "arguments": { "bucketId": "…", "paths": ["2026/09/flood.jpg", "thumbnails/*"] } }
  • Up to 50 object keys or directory wildcards (thumbnails/*) per call. Leave out paths, or pass ["*"], to purge everything.
  • The next request for a purged object is fetched fresh from the bucket.
  • If you replace files often, upload changed files under a new key (for example flood.v2.jpg) instead of purging. It is instant and needs no purge.

Turn it off

disable_bucket_cdn removes the CDN hostname’s DNS record, the edge endpoint and the certificate. Every URL on the CDN hostname stops working. The objects themselves stay in the bucket.

Transfer

list_buckets also reports each bucket’s month-to-date transfer (bandwidth.originGiB and bandwidth.cdnGiB), as reported by the storage backend and refreshed a few times a day. It is informational and is not billed separately today.