# CDN & Shield

Both settings apply to every static site in the workspace and take effect on each project's next deploy. Volumetric attack protection runs at the network layer for every site and needs no setting.

## Settings

| Setting | Meaning |
| --- | --- |
| CDN cacheTtlSeconds | How long browsers and the edge keep a page (default 3,600 seconds). Turning the CDN off stops caching: every visit is served fresh. |
| Shield blockedCountries | Two-letter country codes whose visitors are refused. |

> Server apps and functions are not affected by these settings yet. Changing them needs an admin.

## Where to change them

- Dashboard → CDN and Dashboard → Shield, or `PUT /api/services/cdn` and `PUT /api/services/shield` (the body is merged over the saved settings), or an admin's AI assistant with `get_service_config` and `update_service_config`.
- A country that is not a two-letter code is refused with 400, so a typo is never shown back as a rule that blocks nobody.

## Reference

**REST**

```http
GET /api/services/cdn · PUT /api/services/cdn        { "enabled": true, "cacheTtlSeconds": 3600 }
GET /api/services/shield · PUT /api/services/shield  { "enabled": true, "blockedCountries": ["XX"] }
```
