Synthetic Industry

Inspectable example · updated 2026-10-11

Example: redirect-loop trace and cache-header table, before and after a fix

A synthetic trace of an HTTPS redirect loop and a header table for five page types, each shown before and after a fix. It shows the kind of evidence a repair should return; no client site is shown.

An example, not a customer case study. Scope and evidence limitations are described below.

What this example is

This is a synthetic worked example for the invented domain larkbakery.example. Nothing here was measured on a live site, and no customer or delivery is claimed. It shows the evidence a redirect-loop repair and a caching repair should hand back: a hop-by-hop trace, a before and after table of response headers, and the setting that changed.

Before: the loop, hop by hop

The CDN encryption mode is Flexible, so the CDN asks the host over plain HTTP. The host redirects every plain-HTTP request to HTTPS, which sends the visitor back to the CDN, which asks over plain HTTP again. The trace stops after ten redirects.

  • The two settings that disagree: the CDN mode, and the host's force-HTTPS rule.
  • A trace that ends in an error is the evidence; a screenshot of the browser message is not enough.

If the matrix is wider than the box, scroll horizontally to read every column. Keyboard: focus the matrix and use Left/Right.

$ curl -sSIL --max-redirs 10 -o /dev/null -w "%{url_effective} %{http_code} %{num_redirects}\n" http://larkbakery.example
hop 1  http://larkbakery.example/      301 -> https://larkbakery.example/
hop 2  https://larkbakery.example/     301 -> https://larkbakery.example/
hop 3  https://larkbakery.example/     301 -> https://larkbakery.example/
...
hop 10 https://larkbakery.example/     301 -> https://larkbakery.example/
curl: (47) Maximum (10) redirects followed

After: one place enforces HTTPS

With a valid certificate at the host, the CDN mode is changed to one that connects to the host over HTTPS, and the host's redirect is left as the single place that enforces HTTPS. The previous mode is recorded so it can be put back.

  • Changed: CDN encryption mode, previous value recorded.
  • Named place that enforces HTTPS: the host's force-HTTPS setting.

If the matrix is wider than the box, scroll horizontally to read every column. Keyboard: focus the matrix and use Left/Right.

http://larkbakery.example/       301 -> https://larkbakery.example/   (1 redirect)
https://larkbakery.example/      200                                   (0 redirects)
http://www.larkbakery.example/   301 -> https://larkbakery.example/   (1 redirect)
https://www.larkbakery.example/  301 -> https://larkbakery.example/   (1 redirect)
log-in page after sign-in        200, second page view 200            (no loop)

Cache headers for five page types

A second synthetic case: a broad cache rule made the account and basket pages eligible for cache and told Cloudflare to ignore the origin's cache-control header, so stored copies were served. The before column shows a stored copy served with a long age. After the fix, the account page is excluded by a Bypass cache rule, and the basket page is still eligible but the rule now follows the origin's cache-control header, which says private. The statuses follow the meanings in Cloudflare's documentation: HIT is a stored copy served, MISS is an eligible page that is not stored yet, DYNAMIC means the page was not eligible, and BYPASS means it was eligible but the origin's response said not to cache it.

  • A personal page should never show HIT.
  • The first request after a purge is normally a MISS, because nothing is stored yet; the request after it is a HIT.
  • The edit-and-purge test and the two-session test are recorded separately.

If the matrix is wider than the box, scroll horizontally to read every column. Keyboard: focus the matrix and use Left/Right.

page type        address              before                       after
public page      /                    HIT, age 5400                HIT, age 120 (cached on purpose)
blog post        /news/spring/        HIT, age 86000 (stale)       MISS on the first request after purge (shows edit), then HIT
account page     /account/            HIT, age 1800  <- wrong      DYNAMIC (Bypass cache rule added)
basket           /basket/             HIT, age 600   <- wrong      BYPASS (origin sends cache-control private, rule follows it)
admin area       /wp-admin/           DYNAMIC                      DYNAMIC

What this example does not show

It does not show how fast a site becomes after the fix, and it does not show a real customer outcome. Which settings exist and what they are called depends on your account and plan. A real engagement records the actual headers, the actual rule that changed and the actual previous value.

Sources and limits

  • Cloudflare: Too many redirects Checked 2026-10-11.
    • Flexible mode with an origin that redirects HTTP to HTTPS causes a loop.
  • Cloudflare: Cache responses Checked 2026-10-11.
    • The cf-cache-status header values HIT, MISS, EXPIRED, BYPASS, DYNAMIC and NONE or UNKNOWN have defined meanings: MISS is an eligible response not yet in the cache, DYNAMIC is not eligible for cache, and BYPASS is eligible but the origin response was not cacheable.
  • Cloudflare: Cache rule settings Checked 2026-10-11.
    • A Bypass cache setting is for requests that should not be cached, and the Edge TTL mode that ignores the cache-control header completely ignores any cache-control header on the response; another mode follows the header if it is present.