September 2025 Summaries
20 posts from Fastly
Filter
Month:
Year:
Post Summaries
Back to Blog
APIs are essential yet challenging components of modern digital infrastructure, often plagued by management and security difficulties as they rapidly evolve and become targets for exploitation. Fastly's API Discovery aims to address these issues by providing teams with instant visibility into API traffic, eliminating the need for complex configurations or additional infrastructure. The tool automates the detection of unknown traffic and streamlines API governance, allowing developers to focus on innovation rather than troubleshooting. By leveraging Fastly's extensive edge network, API Discovery offers a simplified approach to managing and securing APIs, enhancing collaboration between platform and security teams, and supporting organizations in achieving their business objectives while maintaining compliance and data privacy standards.
Sep 30, 2025
1,439 words in the original blog post.
Climate Week NYC 2025 emphasized the continued corporate drive towards decarbonization and climate adaptation, despite less public attention, highlighting the use of AI-driven solutions to aid the transition. Acknowledging the energy demands of AI and data centers, it encouraged expedited permitting and renewable energy adoption. Fastly announced its commitment to covering 100% of its non-renewable electricity consumption with Environmental Attribute Certificates (EACs), aiming to meet both environmental responsibilities and customer climate goals. This initiative is part of Fastly's broader effort to build a sustainable internet, supported by a new sustainability dashboard for enhanced customer transparency on environmental impacts. The company plans to disclose its comprehensive greenhouse gas inventory and engage with suppliers to tackle Scope 3 emissions, marking a significant step in its ongoing sustainability journey.
Sep 29, 2025
644 words in the original blog post.
Fastly's Sustainability dashboard offers developers a tool to measure and optimize the energy use and carbon impact of their workloads, bridging a gap identified in Fastly's Green Coding Survey 2025, where many developers lack visibility into the sustainability of their code. The dashboard provides detailed data on emissions, allowing developers to track changes, identify resource-intensive services, understand geographical energy impacts, and automate data integration into existing observability pipelines. By using charts and data exports, developers can make informed decisions to enhance both performance and sustainability, aligning with Web Sustainability Guidelines to create more efficient and environmentally friendly web services.
Sep 25, 2025
541 words in the original blog post.
Fastly emphasizes the importance of resilience in content delivery networks (CDNs) to ensure reliable user experiences and protect businesses from revenue loss and brand erosion caused by latency and outages. The challenges of global content distribution, such as geographic latency, network congestion, single points of failure, and adversarial events like DDoS attacks, require a CDN to be robust and responsive. Fastly's approach to resilience involves core principles and technologies that enable fast and available content delivery, with observability being a foundational capability. This entails monitoring detailed metrics, logs, and traces to understand network behavior, diagnose issues, and facilitate proactive maintenance and rapid incident response. The substantial investment in observability infrastructure is justified by its role in maintaining system resilience, enabling data-driven capacity planning, and ensuring the network can adjust to changing conditions. Future discussions will delve into the specific pillars that support Fastly's resilient infrastructure, focusing on high availability, disruption resistance, and recovery strategies.
Sep 24, 2025
1,079 words in the original blog post.
Fastly's latest survey of 801 developers highlights the growing consideration of "green coding," with 77% focusing on energy efficiency and sustainability in their software development. However, a significant challenge remains: the lack of visibility tools to measure the impact of their sustainable coding efforts, as cited by 54% of respondents. Generative AI tools like GitHub Copilot and Google Gemini are widely used, but they come with a notable energy footprint, leading 35% of developers to limit their use due to sustainability concerns. Despite these challenges, 69% of developers believe they can significantly reduce the industry's carbon footprint, and over 80% consider sustainability when designing systems. Fastly aims to bridge the visibility gap with its new Sustainability Dashboard, providing real-time insights into the energy impact of code on its edge network, demonstrating that informed coding choices can lead to substantial energy savings, as exemplified by a Fastly engineer's collaboration with the University of Waterloo to optimize Linux kernel code, resulting in up to 30% power savings in data-center workloads.
Sep 23, 2025
660 words in the original blog post.
The JavaScript Static Publisher for Fastly Compute enables users to serve static websites directly from the network edge, bypassing traditional web hosting by utilizing a serverless application and an edge data store. This setup is particularly suitable for static sites consisting of HTML, CSS, and client-side JavaScript, such as blogs and React applications. Users can deploy sites by forking a demo project on GitHub, editing it in a codespace, and publishing with an API key, all without installing software on their local machine. The process is streamlined through simple commands, allowing users to preview, edit, and share drafts easily. For existing static sites, users can import the Static Publisher to scaffold a Compute app and use a series of npm commands to test and deploy their site to the edge. The platform also supports publishing blogs using Eleventy, providing a seamless experience for drafting, editing, and sharing content. The system is designed to simplify the deployment process and enhance the speed and accessibility of static content delivery.
Sep 18, 2025
712 words in the original blog post.
Recently, both Google and Apple introduced new user agents that allow website owners to control whether their content is used to train AI models by updating their robots.txt files. Google-Extended and Applebot-Extended are special instructions within the robots.txt file that prevent the use of website content for AI training while not affecting search rankings. This gives website owners the power to protect intellectual property by opting out of contributing to AI training data. Implementing these changes involves simple modifications to the robots.txt file, allowing for greater control over content usage. Additionally, tools like Fastly Bot Management offer insights into various bots accessing web content, providing further control and visibility.
Sep 16, 2025
471 words in the original blog post.
Tools like ChatGPT, Perplexity, and Claude are changing how digital publishers engage with audiences by generating entire answers directly from content, creating visibility challenges for companies trying to measure their influence. ScalePost has introduced tools to provide publishers and brands with insights into how their content is used in AI-generated answers, offering metrics on citations and guiding them on expanding presence. Built on Fastly's platform, which is known for its extensibility and real-time data transparency, ScalePost leverages these capabilities to give businesses detailed visibility into AI platform interactions, helping them optimize for Answer Engine Optimization (AEO) and manage AI bot traffic effectively. This allows businesses to not only track how content is cited but also to address hidden infrastructure costs associated with AI bot activity, enabling informed decisions on content optimization and monetization strategies. Fastly's real-time log streaming supports these insights without impacting human web traffic, allowing companies to manage AI interactions seamlessly.
Sep 12, 2025
893 words in the original blog post.
In recent years, the rise of AI and the debate surrounding content scraping and data usage have sparked discussions about copyright infringement, fairness, and ethical considerations. Many feel that the mechanical remixing of content by AI, often facilitated by scrapers and crawlers that ignore established web standards, resembles theft rather than homage. To address these concerns, the RSL Standard (Really Simple Licensing) has been introduced as an open, XML-based document format, allowing content creators to define machine-readable licensing and usage terms for digital assets, such as websites, music, and videos. This standard provides flexibility in licensing options, from simple attribution to charging for access, and aims to create a balanced ecosystem where digital assets can be legally accessed by users and bots for applications like AI training and web search. The RSL Standard offers solutions for compensating content creators while ensuring that their work is used under agreed terms, reflecting a broader conversation about the future of content rights in the digital age.
Sep 10, 2025
965 words in the original blog post.
Fastly's August 2025 DDoS weather report highlights the significant role of hyperscale clouds in 70% of associated attacks, emphasizing the challenges of detecting sophisticated layer 7 attacks that threaten the performance and availability of internet-facing applications and APIs. Despite Fastly's global network stopping trillions of attempted DDoS attacks at layers 3 and 4, August 1 stood out as the third-largest day of attack volume in 2025, targeting primarily Media & Entertainment enterprises. The report reveals that nearly 73,000 attacks occurred, with a notable median attack volume in Media & Entertainment, the Public Sector, and Education sectors. It also explores mitigation trends, showing that a single IP was found in 42% of rules, and 66% included a single ASN, with most ASNs linked to hyperscale cloud providers. The report advises organizations, particularly those in Media & Entertainment, to adopt application DDoS protection and automate solutions to manage the persistent threat of DDoS attacks effectively.
Sep 10, 2025
1,621 words in the original blog post.
Fastly's Security Research Team highlights the growing impact of bots, particularly AI-driven automation, on internet security and website management in their Q2 Threat Insights Report. Bots, which make up 37% of observed traffic on Fastly's global network, are reshaping how content is accessed and monetized, posing challenges for organizations to maintain security and site performance. While not all bot traffic is harmful, with 87% deemed malicious, distinguishing between beneficial and harmful bot activity is increasingly complex, especially as AI bots can disguise themselves to avoid detection. This complexity necessitates advanced bot management solutions, like Web Application Firewalls and Bot Management tools, to ensure granular visibility and control over bot traffic. The report underscores the critical need for organizations to implement these solutions to protect against security risks, performance degradation, and financial loss.
Sep 09, 2025
874 words in the original blog post.
Fastly has developed a Sustainability dashboard to help organizations track and manage their digital carbon footprint more effectively, addressing the growing need for transparency in environmental impact reporting. This dashboard provides daily refreshed, account-specific data on electricity consumption and greenhouse gas emissions, broken down by country, bandwidth, and compute, offering a granular and immediate view of Scope 2 and Scope 3 emissions. By integrating this data into existing workflows via API or exporting it as reports, companies can comply more easily with evolving regulations and make informed decisions to optimize their sustainability efforts. Fastly's advanced network and technology contribute to this transparency, providing instant visibility and facilitating the identification of carbon hotspots. The dashboard aligns with the Greenhouse Gas Protocol, ensuring credible and traceable metrics, which can help organizations build trust with stakeholders while supporting climate-aware decision-making.
Sep 09, 2025
963 words in the original blog post.
Fastly has introduced local Fanout testing for its Compute platform, enabling developers to build and test real-time services like Server-Sent Events, HTTP streaming, and WebSockets-over-HTTP without deploying to a live Fastly service. Previously, testing these features required a full deployment, but updates to the Fastly CLI and the Viceroy local testing server now allow developers to test Fanout functionality entirely on their local machines. This is facilitated by Pushpin, an open-source proxy server project that acts as a real-time message broker, maintaining long-lived connections and delivering messages as directed by the backend. The new local testing capability streamlines the development process by allowing for full end-to-end testing of Fanout features within a local environment, which includes setting up a local architecture with Viceroy and Pushpin for comprehensive simulation of production scenarios. Developers can now iterate and validate real-time behavior locally, enhancing the flexibility and efficiency of building with Fastly's event-driven architecture.
Sep 08, 2025
1,080 words in the original blog post.
Fastly's collaboration with the Python Software Foundation (PSF) aims to enhance the performance and reliability of the Python Package Index (PyPI) by using advanced network engineering techniques. PyPI, a crucial repository for Python users with over 953,000 users and 7.3 million releases, faces challenges in optimizing global traffic. Fastly's Individual Provider Anycast (IPA) technology improves upon traditional anycast methods by assigning provider-specific anycast IPs, which optimize routing through specific internet service providers, reducing latency and boosting performance. This system leverages Fastly's Wins Above Nominal (WAN) methodology to evaluate and rank provider performance, ensuring users connect through the fastest possible routes. The partnership results in significant performance gains, allowing Python users worldwide to experience faster and more reliable access to packages, even during major internet disruptions. This collaboration underscores the impact of innovative technology in supporting open-source projects and enhancing the Python ecosystem's infrastructure.
Sep 05, 2025
945 words in the original blog post.
In the realm of video content delivery and security, CDNs play a pivotal role by offering functionalities such as end-to-end encryption, token-based authentication, and video-specific anti-piracy features like DRM and watermarking, ensuring secure video playback across various platforms like OTT streaming services, live sports broadcasting, and educational libraries. CDNs also provide essential protections against scraping, credential stuffing, and CDN-bypass, with real-time analytics for detecting suspicious activity and DDoS protection to safeguard infrastructures during high-traffic events. When selecting a CDN provider, considerations include support for token authentication, DRM integration, web application firewalls, bot protection, and edge encryption. Top CDN providers such as Fastly, Cloudflare, Akamai, Amazon CloudFront, and Google Cloud CDN offer various levels of support for these features, with Fastly being highlighted for its strong performance, developer-friendly architecture, and robust media-specific capabilities that enhance video delivery performance and operational visibility.
Sep 03, 2025
1,128 words in the original blog post.
In the face of sudden viral content and traffic spikes, website owners must prioritize web performance, reliability, and security to maintain uptime and user satisfaction. A powerful Content Delivery Network (CDN) is essential for managing these challenges, as it distributes content globally, reduces latency, and absorbs traffic surges, ensuring consistent performance and security. Top CDN solutions like Fastly, Cloudflare, Akamai, and Amazon CloudFront offer features such as real-time cache invalidation, global reach, strong security measures, and seamless integration with existing infrastructures to handle viral events effectively. Businesses should consider a CDN's scalability, global presence, caching efficiency, and security capabilities when choosing a solution to guarantee a robust and uninterrupted online experience during high-traffic events.
Sep 02, 2025
955 words in the original blog post.
Akamai, a pioneer in the CDN industry, initially built its platform for an internet focused on static content delivery at scale, but modern needs have shifted towards real-time, API-driven, and application-centric solutions. Unlike traditional CDNs that emphasize stability and long-standing patterns, modern CDNs prioritize agility, enabling rapid innovation and developer control to swiftly adapt to changing traffic, threats, and user expectations. Fastly, for instance, offers a cutting-edge solution characterized by instant configurability, programmable edge logic, and deep visibility, allowing teams to make changes and respond to events in milliseconds. Similarly, Cloudflare provides an integrated platform approach with robust security services, while Amazon CloudFront and Google Cloud CDN leverage their respective cloud ecosystems to deliver reliable, scalable, and performance-oriented solutions. These modern CDNs are designed to support dynamic and personalized content, enhance developer experience through seamless integration with CI/CD workflows, offer real-time insights for optimization, and include built-in security features like DDoS mitigation and WAF, making them suitable for businesses seeking speed, agility, and comprehensive functionality.
Sep 02, 2025
1,373 words in the original blog post.
API security testing is essential for safeguarding APIs from unauthorized access, misuse, and attacks, as they are often targeted due to their role in facilitating communication between applications and handling sensitive data. Effective API security involves strong authentication practices, like OAuth 2.0, encryption of data at rest and in transit, and robust input validation to prevent malicious code injection and data breaches. Tools and strategies for API security include API scanners, fuzzers, dynamic testing tools, and runtime protection solutions, which help detect vulnerabilities and enforce security measures throughout the API lifecycle. Solutions from companies like Fastly, Cloudflare, Imperva, and Akamai focus on real-time detection, behavior analysis, and threat mitigation to protect against various threats, including those identified in the OWASP API Security Top 10. These platforms offer comprehensive visibility, automated API discovery, and edge-based protections, ensuring that only legitimate and authenticated traffic accesses APIs, thereby enhancing resilience and reducing the risk of exploitation.
Sep 01, 2025
1,150 words in the original blog post.
Bot traffic constitutes an increasingly significant portion of internet activity, with some bots having malicious intentions. To address the challenges posed by sophisticated bots, organizations can utilize content delivery networks (CDNs) for effective bot management. CDNs are strategically positioned to detect and mitigate bot attacks at the edge before they reach the origin infrastructure, thereby reducing load, latency, and the potential impact on applications. Effective CDN-based bot management involves accurate detection of malicious bots through behavioral analysis, machine learning, and fingerprinting, distinguishing them from legitimate bots to minimize false positives. Real-time responses, scalability during traffic spikes, and integration with broader security measures like WAF and DDoS protection are crucial features of top CDNs. Providers such as Fastly, Cloudflare, Akamai, and Amazon CloudFront offer varying capabilities in edge-level bot detection and mitigation, each utilizing a combination of global threat intelligence, custom rule sets, and real-time enforcement to protect web applications, APIs, and mobile traffic while maintaining user transparency and performance.
Sep 01, 2025
1,559 words in the original blog post.
The growing sophistication of Distributed Denial of Service (DDoS) attacks, particularly layer 7 attacks, has made them increasingly difficult to detect and more dangerous, posing significant threats to the performance and availability of internet-facing apps and APIs. A successful attack can lead to detrimental business impacts such as customer loss, operational disruption, reputational harm, and increased costs, making a robust DDoS mitigation solution essential. Effective solutions offer continuous uptime, automated real-time threat neutralization, secure traffic protection, and customer trust preservation. They integrate with other security tools, provide detailed analytics, and demonstrate cost efficiency and scalability. The guide examines key considerations for selecting a DDoS mitigation solution, including mitigation capacity, coverage scope, mitigation speed, and deployment models, highlighting leading providers such as Fastly, Cloudflare, Akamai, AWS Shield Advanced, Imperva, and Radware. Each provider offers unique strengths, from edge-native real-time mitigation and global anycast networks to enterprise-grade scrubbing and multi-cloud integration, catering to various organizational needs and security priorities.
Sep 01, 2025
1,993 words in the original blog post.