CDN migrations fail on DNS and cache policy, not on the first byte of a test file. The origin can stay where it is. The public hostname should move only after the distribution has been proven.
Leave production DNS alone until the last step
Create a Cloud CDN distribution that pulls your existing origin over HTTPS. Confirm assets, HTML and a login or checkout flow on an Aptranet hostname. Do not change the customer-facing name yet.
This is the rehearsal. Certificates, cache bypasses and origin TLS get fixed here, not during a live TTL window.
Lower TTLs days before the cutover
If the apex TTL is 24 hours, you have already agreed to a 24-hour rollback. Cloud DNS supports a one-second minimum TTL. Even on another DNS host, drop the relevant records ahead of the window.
Keep MX and verification TXT untouched. You are moving the website name, not mail.
Restrict the origin as you cut over
Once the public hostname points at Cloud CDN, clients should not be able to skip the edge. Restrict origin access and validate origin TLS so the old IP is not a back door.
Watch hit ratio and origin bandwidth for the first hours. Prefetch if a campaign starts the same day.
Have a rollback that is also DNS
Rollback is pointing the name back, plus a TTL that is still low. If you raised TTL immediately after cutover, you have closed the door.
Raise TTLs only when the distribution has been boring for a while.
