Skip to content
Castreon
Delivery

Castreon behind a CDN (HLS push)

Updated 08 Oct 2026

Castreon can upload a channel's HLS to a CDN or to a storage service on its own. Your viewers then read from the CDN, not from your server: the server only writes, however many viewers there are, and nothing has to be opened towards it from the internet.

Available from Castreon 1.1.0, on the Pro and Enterprise plans.

When it helps

  • You have many viewers, or viewers in several countries, and you don't want to run your own delivery servers.
  • The transcoding server sits in a closed network (an office, a data centre with no open ports) — push only sends data out.
  • You want traffic problems to stay away from transcoding: the CDN takes all viewer requests.

If you already run your own delivery servers that read HLS from Castreon (pull), you don't need push — a CDN can also read the channel's HLS address directly.

Supported destinations

Destination For
HTTP PUT / WebDAV a CDN's storage (access with a header, e.g. AccessKey) or a WebDAV server (user + password)
S3 (compatible) any S3-compatible storage; the CDN reads from the bucket

Setup

  1. Open the channel → Edit → under Outputs, Add output → type CDN push (HLS).
  2. Choose the Destination:
    • HTTP PUT / WebDAV — Upload address (the storage address, including the zone), then Authentication: None, User + password or Header (name + value) — your provider gives you the name and value (e.g. the AccessKey header with the storage zone password).
    • S3 (compatible) — S3 endpoint (without the bucket), the bucket, Region (empty = auto), Access Key ID and Secret Access Key. Leave Path-style addresses on for almost every storage.
  3. Path at the destination — live/{slug}/ by default. {slug} is the channel's identifier, {id} its id; the real path is shown below the field.
  4. Playback address (optional) — the CDN address you give to viewers, with {slug}, for example https://cdn.your-domain.com/live/{slug}/index.m3u8. It appears under Delivery as CDN · HLS.
  5. Test the connection — Castreon writes a small test file under the channel's path and deletes it. You see the time taken or the destination's exact error.
  6. Save.

Passwords, header values and secret keys are kept on the server and never shown again: after saving, the field shows “•••••••• saved”. Leave the field empty to keep it, or type a new value. They never appear in API responses, in the audit log or in the diagnostic report.

The channel doesn't need a separate HLS output: if it has none, Castreon adds one, because push uploads the channel's HLS.

How it uploads

  • Order: first the segment, then the variant playlist, then the master playlist (with several qualities). A player never sees a segment in the playlist that isn't at the CDN yet.
  • Segment names never repeat, not even after a channel or server restart. A CDN can't serve an old segment from cache instead of a new one.
  • A channel restart shows up in the playlist as a proper discontinuity; players carry on without stopping.
  • Cache: segments are sent with Cache-Control: public, max-age=31536000, immutable, playlists with a cache time of half a segment's duration.
  • Old segments are deleted at the destination once they have been out of the playlist for one more full window (players that fell behind still find them). Turn off Delete old segments at the destination if the storage deletes them itself.
  • On a network error each file is tried up to 3 times. Access errors (401, 403) are not retried — the message shows up right away on the channel page.

CDN settings

  • Playlist caching: with HTTP PUT, many CDN storages don't keep the Cache-Control header Castreon sends. Add a CDN rule for .m3u8 files: 1–2 seconds in cache. Without it, viewers may get an old playlist and the picture stops. Segments can stay cached for a long time.
  • With S3, Cache-Control is stored as metadata on every object, and the CDN in front of the bucket usually uses it on its own.
  • CORS for browser players: allow GET and HEAD from any origin for .m3u8, .ts, .m4s and .mp4.
  • Viewer access is decided by the CDN (for example signed URLs at the CDN). The node's access token does not apply to CDN addresses.

On the channel page

The CDN push card shows, for every output: the state (uploading, waiting for the channel, error, not licensed), the destination, the playback address, the last upload (when, which file, how many milliseconds), how many segments and MB were sent, how many were deleted, and the last error.

/metrics contains castreon_cdn_push_up, castreon_cdn_push_segments_total, castreon_cdn_push_bytes_total, castreon_cdn_push_errors_total and castreon_cdn_push_upload_seconds — see Metrics and Grafana.

Limits

  • HLS is uploaded (TS or fMP4 segments, all qualities). LL-HLS is not uploaded.
  • AES-128 encrypted HLS can't be uploaded: the key stays on the server.
  • An On demand channel can't use push: it doesn't see the CDN's viewers and would stop.
  • Without the right license the output stays saved but uploads nothing (state not licensed).

Common problems

  • HTTP 401 / HTTP 403: the credentials are wrong or have no write access to that zone / bucket. With S3, SignatureDoesNotMatch usually means a wrong secret key or a wrong endpoint.
  • HTTP 404 on the test: the upload address or the bucket doesn't exist.
  • The picture stops for viewers although the card says “uploading”: check the CDN cache rule for .m3u8 (1–2 seconds).
  • The browser player won't start, but VLC works: CORS is missing at the CDN.
  • The last upload takes long (the milliseconds on the card grow): the destination is slow or far from the server. Pick a storage zone close to the server.

Privacy

Cookies & local storage

Strictly necessary cookies are always active. Analytics and marketing use Google services and only start if you accept them — until then nothing is sent to Google. You can withdraw your consent here at any time.

Strictly necessary

Without them, sign-in, forms and your chosen language don’t work. They don’t require consent (§ 25(2) no. 2 TDDDG).

Always active
Name Purpose Duration Type
castreon-session Keeps your session: sign-in and chosen language 2 hours, renewed on every visit Cookie
XSRF-TOKEN Protects forms against forged requests 2 hours, renewed on every visit Cookie
remember_web_… Only if you tick “Remember me” at sign-in Until you sign out, max. 400 days Cookie
__cf_bm Cloudflare: tells visitors and bots apart, only when traffic is being checked 30 minutes Cookie · Cloudflare
castreon:consent Remembers your cookie choice 12 months Local storage
theme Customer account appearance: light, dark or system Until you change it Local storage

Analytics

Google Analytics 4 (Google Ireland Ltd.): which pages are visited, where visits come from and on which type of device — with pseudonymous identifiers, without storing your IP address. Helps us improve the website.

Name Purpose Duration Type
_ga Google Analytics: recognises the visitor (pseudonymous ID) 13 months Cookie · Google Analytics
_ga_VHWQRPHPEF Google Analytics: keeps the state of the visit 13 months Cookie · Google Analytics

Marketing

Google Ads (Google Ireland Ltd.): measures whether visits from Google ads lead to a trial or a plan, and allows Castreon ads to be shown on other websites (remarketing).

Name Purpose Duration Type
_gcl_au, _gcl_aw Google Ads: links the visit to the ad click (conversions) 90 days Cookie · Google Ads
IDE, test_cookie Google Ads: remarketing and ad measurement, on Google domains (doubleclick.net) Up to 13 months Cookie · Google (third party)