Castreon behind a CDN (HLS push)
Updated 08 Oct 2026Castreon can upload a channel's HLS to a CDN or to a storage service on its own. Your viewers then read from the CDN, not from your server: the server only writes, however many viewers there are, and nothing has to be opened towards it from the internet.
Available from Castreon 1.1.0, on the Pro and Enterprise plans.
When it helps
- You have many viewers, or viewers in several countries, and you don't want to run your own delivery servers.
- The transcoding server sits in a closed network (an office, a data centre with no open ports) — push only sends data out.
- You want traffic problems to stay away from transcoding: the CDN takes all viewer requests.
If you already run your own delivery servers that read HLS from Castreon (pull), you don't need push — a CDN can also read the channel's HLS address directly.
Supported destinations
| Destination | For |
|---|---|
| HTTP PUT / WebDAV | a CDN's storage (access with a header, e.g. AccessKey) or a WebDAV server (user + password) |
| S3 (compatible) | any S3-compatible storage; the CDN reads from the bucket |
Setup
- Open the channel → Edit → under Outputs, Add output → type CDN push (HLS).
- Choose the Destination:
- HTTP PUT / WebDAV — Upload address (the storage address, including the zone), then Authentication: None, User + password or Header (name + value) — your provider gives you the name and value (e.g. the
AccessKeyheader with the storage zone password). - S3 (compatible) — S3 endpoint (without the bucket), the bucket, Region (empty =
auto), Access Key ID and Secret Access Key. Leave Path-style addresses on for almost every storage.
- HTTP PUT / WebDAV — Upload address (the storage address, including the zone), then Authentication: None, User + password or Header (name + value) — your provider gives you the name and value (e.g. the
- Path at the destination —
live/{slug}/by default.{slug}is the channel's identifier,{id}its id; the real path is shown below the field. - Playback address (optional) — the CDN address you give to viewers, with
{slug}, for examplehttps://cdn.your-domain.com/live/{slug}/index.m3u8. It appears under Delivery as CDN · HLS. - Test the connection — Castreon writes a small test file under the channel's path and deletes it. You see the time taken or the destination's exact error.
- Save.
Passwords, header values and secret keys are kept on the server and never shown again: after saving, the field shows “•••••••• saved”. Leave the field empty to keep it, or type a new value. They never appear in API responses, in the audit log or in the diagnostic report.
The channel doesn't need a separate HLS output: if it has none, Castreon adds one, because push uploads the channel's HLS.
How it uploads
- Order: first the segment, then the variant playlist, then the master playlist (with several qualities). A player never sees a segment in the playlist that isn't at the CDN yet.
- Segment names never repeat, not even after a channel or server restart. A CDN can't serve an old segment from cache instead of a new one.
- A channel restart shows up in the playlist as a proper discontinuity; players carry on without stopping.
- Cache: segments are sent with
Cache-Control: public, max-age=31536000, immutable, playlists with a cache time of half a segment's duration. - Old segments are deleted at the destination once they have been out of the playlist for one more full window (players that fell behind still find them). Turn off Delete old segments at the destination if the storage deletes them itself.
- On a network error each file is tried up to 3 times. Access errors (401, 403) are not retried — the message shows up right away on the channel page.
CDN settings
- Playlist caching: with HTTP PUT, many CDN storages don't keep the
Cache-Controlheader Castreon sends. Add a CDN rule for.m3u8files: 1–2 seconds in cache. Without it, viewers may get an old playlist and the picture stops. Segments can stay cached for a long time. - With S3,
Cache-Controlis stored as metadata on every object, and the CDN in front of the bucket usually uses it on its own. - CORS for browser players: allow
GETandHEADfrom any origin for.m3u8,.ts,.m4sand.mp4. - Viewer access is decided by the CDN (for example signed URLs at the CDN). The node's access token does not apply to CDN addresses.
On the channel page
The CDN push card shows, for every output: the state (uploading, waiting for the channel, error, not licensed), the destination, the playback address, the last upload (when, which file, how many milliseconds), how many segments and MB were sent, how many were deleted, and the last error.
/metrics contains castreon_cdn_push_up, castreon_cdn_push_segments_total, castreon_cdn_push_bytes_total, castreon_cdn_push_errors_total and castreon_cdn_push_upload_seconds — see Metrics and Grafana.
Limits
- HLS is uploaded (TS or fMP4 segments, all qualities). LL-HLS is not uploaded.
- AES-128 encrypted HLS can't be uploaded: the key stays on the server.
- An On demand channel can't use push: it doesn't see the CDN's viewers and would stop.
- Without the right license the output stays saved but uploads nothing (state not licensed).
Common problems
HTTP 401/HTTP 403: the credentials are wrong or have no write access to that zone / bucket. With S3,SignatureDoesNotMatchusually means a wrong secret key or a wrong endpoint.HTTP 404on the test: the upload address or the bucket doesn't exist.- The picture stops for viewers although the card says “uploading”: check the CDN cache rule for
.m3u8(1–2 seconds). - The browser player won't start, but VLC works: CORS is missing at the CDN.
- The last upload takes long (the milliseconds on the card grow): the destination is slow or far from the server. Pick a storage zone close to the server.