From 4ea6c75fd959e11b94f8fbbd4baa3d5656c333cb Mon Sep 17 00:00:00 2001 From: pat-s Date: Sun, 9 Aug 2026 10:04:54 +0000 Subject: [PATCH] fix(cdn): declare the User-Agent cache vary instead of dropping it The pull zone carries cache_vary_headers = ["User-Agent"], set before this configuration existed. Because cdn.tf never declared it, the first apply of the managed middleware would have removed it as a side effect. Keep it for now: the router's only UA-dependent responses are redirects, which are no-store, so it is redundant on paper, but it is also the second line of defence against an R 4.6 client being served the 4.5 index. Removing it is worth doing on its own once per-minor routing is confirmed live. --- cdn.tf | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/cdn.tf b/cdn.tf index fe1b25f..5e8899d 100644 --- a/cdn.tf +++ b/cdn.tf @@ -105,6 +105,21 @@ resource "bunnynet_pullzone" "cran_rpkgs_com" { request_coalescing_enabled = true block_post_requests = true + # Set on the zone since before this configuration existed; declared here so + # `tofu apply` stops silently removing it. + # + # The router makes it redundant on paper: the only UA-dependent responses it + # produces are redirects, and those carry `Cache-Control: no-store`, while + # their targets are concrete per-slot, per-minor URLs whose content depends + # only on the path. Dropping it would also be a real win, because otherwise + # every distinct R version string keys its own copy of every tarball. + # + # It stays for now anyway: it is the second line of defence against the one + # failure that would be quiet and confusing (an R 4.6 client served the 4.5 + # index), and removing it is worth doing on its own once per-minor routing is + # confirmed live, not as a side effect of enabling that routing. + cache_vary_headers = ["User-Agent"] + limit_requests = 5000 limit_connections = 1000 -- 2.54.0