netlify-caching
netlify/context-and-tools
在 Netlify 的 CDN 上對來自 Functions、Edge Functions 及代理伺服器的動態與靜態回應進行快取。 適用於在函式回應中新增快取或 Cache-Control 標頭、調整快取 TTL 或 stale-while-revalidate 設定、設定持久性快取、依據查詢字串/標頭/Cookie/國家/語言變更快取金鑰、依網站或快取標籤清除或失效快取,以及使用程式化 Cache API (caches.open/match/put)或 @netlify/cache 輔助函式(fetchWithCache/cacheHeaders/getCacheStatus),以及加速耗費資源的 API
...展開全部關於《netlify-caching》
這項技能是一份實用參考指南,說明如何在 Netlify 的 CDN 上對來自 Functions、Edge Functions 及代理伺服器的動態與靜態回應進行快取。它解決了動態回應預設不會被快取,以及各種 Cache-Control 標頭行為存在細微差異的問題: 本技能指示代理程式優先參考 `Netlify-CDN-Cache-Control`,說明其與 `CDN-Cache-Control` 及標準 `Cache-Control` 之間的關聯,並列出各項指令(public/private/no-store、s-maxage、max-age、stale-while-revalidate、durable)及其預設值。
文中著重探討實際應用中的陷阱:僅 GET 請求會被快取;Netlify 開發環境不會模擬 CDN 快取,因此必須透過已部署 URL 的 Cache-Status 標頭來驗證快取狀態;除非使用 Netlify-Vary 進行範圍限定,否則完整的查詢字串將成為快取金鑰;靜態資源的有效期最長可達一年; 任何頁面若啟用基本認證(basic-auth)將使整個網站停用快取,且「durable」僅適用於無伺服器架構。文檔中詳述了透過 Netlify-Vary 變更快取金鑰的方式(依查詢字串、標頭、語言、國家、Cookie), 透過 Netlify-Cache-Tag 和 Netlify-Cache-ID 進行快取標籤與退出設定,以及透過部署的函式呼叫 purgeCache、依標籤清除、從 Lambda 相容函式清除,或透過直接的 HTTP 清除 API 進行按需清除。
目標使用者為需要調整 CDN 效能、新增 ISR/按需重新驗證,或除錯回應為何被或未被快取的網頁與全端開發人員。 此技能具備安全意識:它明確指出,用於函式外清除操作的個人存取憑證應從環境變數中讀取,絕不應硬編碼;並警告勿將敏感內容排除在自動快取失效機制之外——因此此技能是安全的。
常見問題
為什麼我的動態函式回應未被快取?
動態回應預設不會被快取,且僅有 GET 請求才會被快取。您必須透過在回應中設定 `Netlify-CDN-Cache-Control` 並在 GET 路徑上公開可快取資料,才能啟用快取功能。
為何在本地測試時會出現快取未命中?
Netlify Dev 不會模擬 CDN 快取,因此預期每次在本地端都會發生快取未命中。請透過檢查 Cache-Status 標頭,在已部署的「部署預覽」或生產環境 URL 上驗證快取狀況。
如何避免每個查詢字串都建立獨立的快取項目?
若未使用 Netlify-Vary,完整的查詢字串即為快取金鑰,因此如 utm_* 之類的參數會產生不同的快取項目。請使用 Netlify-Vary: query=... 來僅列出實際會改變回應的參數。
如何清除或失效快取?
請在已部署的函式中使用 `purgeCache`(網站 ID 會自動傳入),並可選擇透過標籤,或針對特定部署別名/網域進行操作。若從 CI 或本地腳本執行,請傳入從環境變數讀取的個人存取憑證加上網站 ID,或直接呼叫 HTTP 清除 API。
是否有會完全停用快取的注意事項?
有。任何頁面若啟用基本認證(basic-auth),將使整個網站的快取失效;durable 標籤對 Edge Function 的回應無效;而舊版按需建構器(ODB)不支援這些標頭。本技能建議在新程式碼中避免使用 ODB。
Cache-control header to reach for
Dynamic responses (Functions, Edge Functions, proxies) are NOT cached by default — you must opt in. Set Netlify-CDN-Cache-Control on the response:
import type { Context } from "@netlify/functions";export default async (req: Request, context: Context) => { return new Response("Hello world", { headers: { 'Netlify-CDN-Cache-Control': 'public, durable, max-age=60, stale-while-revalidate=120' } });};
Header choice (most specific wins; CDN-Cache-Control/Cache-Control always pass downstream):
Netlify-CDN-Cache-Control— Netlify CDN only. Reach for this.CDN-Cache-Control— all CDNs that support it.Cache-Control— any CDN or the browser.
Legacy path to avoid: On-demand Builders do not support these headers or Netlify-Vary — they use a TTL pattern and key on URL path only. Don't reach for ODBs in new code.
Footguns (read first)
- Only
GETis cached. POST/PUT/etc. are never cached regardless of headers — expose cacheable data on a GET route (inputs in the URL or query string). netlify devdoes not emulate the CDN cache. A local cache miss every time is expected. Verify caching on a deployed URL (Deploy Preview or production) via itsCache-Statusheader.- Without
Netlify-Vary: query=..., the full query string is the cache key — every distinct query string (utm_*,fbclid, …) is a separate cache entry. Enumerate only the params that change the response. - Static assets are fresh for up to a year — a shorter
max-ageis ignored. They change only on a new deploy or manual purge. - basic-auth on ANY page disables caching for the ENTIRE site.
durableis serverless-only — it has no effect on Edge Function responses.- Never opt sensitive content out of automatic invalidation — it can stay publicly cached after deploys/firewall changes.
Directives
publiccache it /privatebrowser-only, not Netlify's shared cache /no-storedon't cache.s-maxage=Nseconds in Netlify's shared cache (overridesmax-agethere).max-age=Nseconds in any cache.stale-while-revalidate=Nserve stale for N seconds after expiry while revalidating in background.durable(serverless only) store in Netlify's durable cache so other edge nodes reuse it instead of re-invoking the function.
Defaults when no header is set — static: Netlify-CDN-Cache-Control: public, s-maxage=31536000, must-revalidate; dynamic: Cache-Control: public, max-age=0, must-revalidate.
Cache key variation — Netlify-Vary
Comma-delimited instructions on the response; pipe-delimited value lists:
Netlify-Vary: query=item_id|page, country=es+de|us, cookie=ab_test|is_logged_inquery=a|bsubset, or barequeryfor all params. Keys case-sensitive; param order irrelevant.header=Device-Type|App-Version— custom + most standard headers.language=en|es+pt—+groups; checked againstAccept-Languagewith quality weighting.country=us|es+pt— GeoIP, ISO 3166-1 two-letter codes;+groups.cookie=ab_test|is_logged_in— target specific keys, not the wholeCookieheader.
Cannot vary by header on: Accept*, Cache-Control, Connection, Content-Length, Cookie, Host, If-*, Range, Referer, Upgrade, User-Agent. For language/cookie/format use Vary: Accept-Language/Vary: Cookie or the specific Netlify-Vary instruction.
Consistency rule: a URL must return the same Netlify-Vary on every response — the first cached response's instructions win and later ones are ignored. Netlify-Vary + standard Vary are both respected (use Vary for format/encoding, and to pass instructions to an upstream CDN like Cloudflare).
Cache tags & opt-out
Tag responses for taggable purging:
Netlify-Cache-Tag: tag1,tag2,tag3Netlify-Cache-Tag(Netlify CDN) wins overCache-Tag(passed downstream). Some providers stripCache-Tag— set both when proxying through them.- Constraints: case-insensitive, UTF-8 only, ≤1024 chars/tag, ≤500 tags/response.
Opt a response out of automatic atomic-deploy invalidation with Netlify-Cache-ID (comma-separated; auto-registered as cache tags for purging; separate 500-ID limit):
Netlify-Cache-ID: cms-proxy,product,imageAfter opting out, purge on-demand after relevant changes (e.g. redirect/proxy or function changes behind a Netlify-Cache-ID).
On-demand invalidation (purge)
Purge from a deployed function with purgeCache (site ID is passed automatically):
import { purgeCache } from "@netlify/functions";export default async () => { await purgeCache(); // no args = purge everything for the site return new Response("Purged!", { status: 202 });};
Purge by tag, optionally targeting a deploy/subdomain:
import { purgeCache } from "@netlify/functions";export default async (req: Request) => { const cacheTag = new URL(req.url).searchParams.get("tag"); if (!cacheTag) return; await purgeCache({ tags: [cacheTag], deployAlias: "deploy-preview-11", domain: "early-access.company.com", }); return new Response("Purged!", { status: 202 });};
Ambient credentials only work inside a deployed function. From CI, local scripts, or the build, pass token (a personal access token read from an env var — never hardcoded) and siteID.
Lambda-compatible functions use the legacy module.exports.handler = async (event, context) => {…} signature and must pass context.clientContext.custom.purge_api_token:
import { purgeCache } from "@netlify/functions";module.exports.handler = async (event, context) => { const token = context.clientContext.custom.purge_api_token; await purgeCache({ tags: ["tag1", "tag2"], token }); return { body: "Purged!", statusCode: 202 };};
Direct API (from outside a function) — POST https://api.netlify.com/api/v1/purge with Authorization: Bearer <personal_access_token> and Content-Type: application/json:
curl -X POST \ -H "Content-Type: application/json" \ -H "Authorization: Bearer <personal_access_token>" \ --data '{"site_slug": "mysitename", "cache_tags": ["news"], "deploy_alias": "deploy-preview-11", "domain": "early-access.company.com"}' \ 'https://api.netlify.com/api/v1/purge'
- Purge by site:
site_idorsite_slug. By tag:cache_tags+ site. Omittingcache_tagspurges the whole site; an emptycache_tagslist purges NOTHING. - Identifier mapping: in the UI (Project configuration > General > Project details), Project ID =
site_id, Project name =site_slug. See https://docs.netlify.com/api-and-cli-guides/api-guides/get-started-with-api#get-site. - Rate limit: each tag or site can be purged only twice per 5s — exceeding returns
429.
Cache API (caches global)
Programmatic read/write of HTTP responses from Functions/Edge Functions. Use for caching individual components of a route or arbitrary fetches, alongside header-based route caching.
Scope rule: caches.open() anywhere, but match/put/delete only inside the request handler — doing them at module/global scope throws.
import type { Config, Context } from "@netlify/functions";const cache = await caches.open("my-cache"); // ok in global scopeexport default async (req: Request, context: Context) => { const request = new Request("https://example.com/expensive-api"); const cached = await cache.match(request); if (cached) return cached; const fresh = await fetch(request); if (fresh.ok) { cache.put(request, fresh.clone()).catch((error) => { console.error("Failed to add to the cache:", error); }); } return fresh;};export const config: Config = { path: "/cache-api-example" };
CacheStorage subset:
caches.match(request)→Responsefrom any cache, orundefined.caches.open(name)→Cache. Distinct names fragment the cache and lower hit ratio — use few, meaningful names.
Cache methods (all require caches.open()):
cache.match(request)→Response|undefined.cache.put(request, response)→ adds a response.cache.add(request)/cache.addAll(requests)→ fetch + store.cache.delete(request)→true.keys()is not implemented — no way to list contents.
Consistency: reads/writes strongly consistent; deletes eventually consistent (a deleted entry may still return briefly).
Cannot cache: partial responses (206), Vary: *, or non-GET methods. Responses need a cache-control header with max-age/s-maxage ≥ 1s, public (not private/no-cache/no-store), and a 2xx status — otherwise storage errors. For responses you don't control, rewrite headers with fetchWithCache.
Limits per invocation: 100 lookups, 20 insertions/deletions. Exceeding: further lookups return nothing; writes/deletes no-op. Limits are shared across edge functions in a request but separate between serverless and edge functions. Cache data is per-region (not replicated), auto-invalidated on redeploy and on max-age/s-maxage expiry.
@netlify/cache module
Install to get helpers, time constants (MINUTE/HOUR/DAY), and a caches export for local dev:
npm install @netlify/cacheLocal-dev workaround: the caches global isn't part of Node.js. Netlify provides it in its Functions/Edge runtimes (live and under netlify dev), but if you run your framework's own dev server the global is undefined and throws — import it instead:
import { caches } from "@netlify/cache";const cache = await caches.open("my-cache");
Requires Netlify CLI 20.0.3+; nothing persists locally (lookups return nothing, writes/deletes don't mutate). No functional change from the global.
cacheHeaders(settings) → header object
import { cacheHeaders, DAY } from "@netlify/cache";const headers = { "x-custom-header": "some value", ...cacheHeaders({ ttl: 2 * DAY, // s-maxage swr: HOUR, // stale-while-revalidate durable: true, tags: ["product", "sale"], overrideDeployRevalidation: ["tag"], // opt out of atomic-deploy invalidation vary: { cookie: ["ab_test_name", "ab_test_bucket"], query: ["item_id", "page"], // or true for all country: ["us", ["es", "pt"]], // nested = OR language: ["en"], header: ["Device-Type"], }, }),};
For only generic (non-Netlify) headers, use the cdn-cache-control npm module instead.
fetchWithCache(resource, options?, cacheSettings?)
Drop-in fetch that returns a cached response or fetches, stores, and returns. cacheSettings override conflicting response headers; with swr, background revalidation is handled automatically.
import { fetchWithCache, DAY } from "@netlify/cache";const response = await fetchWithCache("https://example.com/expensive-api", { ttl: 2 * DAY, tags: ["product", "sale"], vary: { cookie: ["ab_test_name"], query: ["item_id", "page"] },});
getCacheStatus(response | headers | headerString)
Returns { hit, caches: { durable: { hit, stale, stored, ttl }, edge: { hit, stale } } }.
const { hit, edge, durable } = getCacheStatus(response);
needsRevalidation(response) → boolean
Only needed when calling cache.match/cache.put directly (not with fetchWithCache+swr). True when a Cache-API response is stale within its SWR window — return it, then revalidate in context.waitUntil and cache.put the fresh copy:
if (cached) { if (needsRevalidation(cached)) { context.waitUntil( fetch(request).then((fresh) => { const response = new Response(fresh.body, { headers: { ...Object.fromEntries(fresh.headers), ...cacheHeaders({ ttl: MINUTE, swr: HOUR }) }, }); return cache.put(request, response); }) ); } return cached;}
Durable cache
Add durable (serverless only) so edge nodes lacking a local copy check the shared durable cache before invoking the function — fewer invocations, better cache-miss latency. Eventually consistent, so multiple regions may still invoke the function a few times per version. Co-located with the site's functions region. Works with Netlify-Vary, SWR, and on-demand invalidation. Next.js: Next Runtime 5.5.0+ uses the durable cache automatically.
Debugging with Cache-Status
Netlify sets Cache-Status (RFC 9211) on all responses. Check it on a deployed URL. Look for values starting "Netlify Edge" or "Netlify Durable":
"Netlify Edge"; fwd=miss— nothing cached."Netlify Edge"; hit— served from cache."Netlify Edge"; hit; fwd=stale— stale served while revalidating (SWR).- Durable stored on miss:
"Netlify Durable"; fwd=uri-miss; stored=true; ttl=3600. - Durable hit:
"Netlify Durable"; hit; ttl=1234.
ttl negative = seconds since expiry. Each request may hit a different cache instance — without production traffic or durable, expect several empty caches before a hit; repeat requests to warm one.
Netlify house rules (caching)
These are org conventions, not docs facts — merged into the rendered skill byctx-gen and never generated. Owned by the skills maintainer.
- Only
GETresponses are cached by the CDN.POST/PUT/etc. are nevercached regardless of headers — expose cacheable data on aGETroute(put the inputs in the URL or query string). - Without
Netlify-Vary: query=..., the full query string is the cache key —every distinct query string (utm_*,fbclid, ...) is a separate cacheentry. Enumerate only the params that actually change the response. netlify devdoes not emulate the CDN cache — a cache miss every timelocally is expected, not a bug. Verify caching behavior on a deployed URL(Deploy Preview or production) via itsCache-Statusheader.purgeCache()has ambient credentials only inside a deployed function.From CI, local scripts, or the build, passtoken(a personal accesstoken read from an env var, never hardcoded) andsiteID.





首頁
