Every CDN provider gives you a "quick start" setup that caches everything based on URL and serves it until the TTL expires. This works for a brochure website. It breaks spectacularly for modern web applications with API routes, authenticated content, dynamic images, and server-rendered pages.
Common failure modes: API responses cached and served to the wrong user (because the CDN ignored the Authorization header), stale HTML served after a deployment (because cache invalidation was not wired into the deploy pipeline), images served at full resolution on mobile (because no image optimization was configured), and CORS errors on API calls (because the CDN stripped or cached Access-Control-Allow-Origin headers incorrectly).
The fix is not "disable caching." The fix is a cache policy that understands your application. Static assets (.js, .css, images with content hashes) should be cached for a year. HTML should be cached briefly or revalidated on every request. API responses should not be cached at all, or cached with Vary headers that partition by authorization state. We configure these policies per path pattern so the CDN does what you actually need.
We have deployed CDN configurations for Next.js, React SPAs, API backends, image-heavy platforms, and video streaming services. Each has different caching requirements, and we tailor the configuration accordingly.