proomt

Search

Search posts, papers, and topics

All posts

Simon Willison1 min readintermediate

We just shipped support for the ugliest part of HTTP: Vary

Summary

Cloudflare now respects the Vary header for non‑image resources, allowing caches to serve different representations (HTML vs JSON) safely. The author still prefers explicit URL suffixes like .json for clarity.

  • Cloudflare's new feature stops ignoring Vary on anything other than images, preventing cache‑poisoning when using content negotiation.
  • You can now safely cache responses that vary by Accept header (e.g., HTML vs JSON) behind Cloudflare.
  • The author recommends using distinct URLs (e.g., .json) instead of relying on Vary for clearer API design.

Anyone serving dynamic content through Cloudflare should know they can now use Vary safely, or reconsider their URL design.

4/10

Related reading

  1. Cloudflare Details Its Migration from WordPress to EmDash

    Cloudflare migrated its blog from WordPress to the internally built EmDash CMS, running on Workers with multiple caching layers and a PlanetScale DB. The edge‑native setup handled up to 7k RPS and cut latency spikes, using a proxy Worker with cookie‑based routing for a zero‑downtime rollout.

    InfoQinfoq.com2 min
  2. Accelerating the borderless Lakehouse: Announcing preview of cross-cloud caching

    Google Cloud previewed cross‑cloud caching for its Borderless Lakehouse. The feature caches sub‑file Parquet blocks in Google Cloud, encrypts them with GMEK, isolates cache per tenant/region, and validates freshness via metadata checks. In tests it can reduce cross‑cloud data transfer to <5% of the original size, lowering query latency and cost for Iceberg tables stored in other clouds. BigQuery…

    Google Cloud Bloggoogle.com3 minrelease
  3. When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

    Cloudflare’s Page Shield uses a graph‑neural‑network (GNN) to model JavaScript as a syntax‑tree graph, followed by a lightweight LLM for second‑opinion triage and an ensemble of frontier models for deep analysis. This pipeline caught eight malicious payloads across four distinct affiliate‑theft and backdoor techniques that traditional scanners missed, demonstrating the need for runtime, behavior‑…

    Cloudflarecloudflare.com21 minHN2
  4. 1 points

    Saving another 100TB of RAM with math (and Rust)

    Cloudflare reduced the memory footprint of its Pingora Backend Router by re‑examining the consistent‑hashing implementation in the pingora‑ketama library. By increasing the number of virtual hash points per server from the default 1 to the standard 160 (and applying weighted hashing based on disk capacity), they cut the per‑node overhead enough to reclaim >100 TB of RAM across the fleet. The post…

    Hacker News front pagecloudflare.com13 minHN478120lobste.rs33
  5. Out-of-Order HTML Streaming Moves from JS Frameworks into the Browser

    The WICG declarative partial updates proposal adds `<template for>` and processing‑instruction markers to enable out‑of‑order HTML streaming directly in the browser. Chrome 150 ships the markup support; streaming DOM APIs (e.g., `streamHTMLUnsafe`) and `Response.textStream()` let servers push fragments that replace placeholders without blocking the rest of the page. Security is enforced by limiti…

    InfoQinfoq.com2 min