A cache can hold a static asset for a long time safely when the asset's path changes whenever its bytes change. A content-derived filename gives that identity; overwriting bytes at the same path breaks the contract. The HTML document that selects an asset version needs a much shorter freshness policy so a rollout and rollback can switch references. A purge is an operational fallback, not a replacement for correct naming.
Versioned edge assets: make long cache lifetimes safe through content identity
Operational decision
A receipt portal publishes a new JavaScript bundle. Produce a filename that includes a content digest, upload that exact object to the edge, verify its bytes and content type, then deploy the document that references it. The policy fragment distinguishes the two response classes. Keep the old digest object through the rollback window, since clients holding the previous document will still request it. Roll back by serving the previous document reference rather than replacing bytes under the new filename. Test from two edge locations and a browser profile with an old document: both asset versions should remain fetchable. If the document is cached longer than planned, users may run old code against a new API, so maintain an API compatibility window. Track missing-asset responses and document age during rollout.
Versioned receipt bundle: public, max-age=31536000, immutable
Receipt document: no-cache
Release order: upload and verify bundle, then change document reference
Rollback: restore prior document reference; retain prior bundleCost and verification
Long-lived immutable assets improve cache hit rate and lower origin load, but keeping old versions costs storage. Short-lived documents create revalidation traffic and can raise origin pressure during a large launch. A purge may propagate at different speeds across edge locations. Measure cache hit ratio, old-document prevalence, missing digest objects, and compatibility failures. The digest path is a release dependency, so promotion evidence should include it alongside the application image.
Common Mistakes
- Do not overwrite a content-named asset after publication.
- Do not delete the prior bundle before old documents and rollback paths expire.
- Do not set a long immutable policy on the document that chooses the bundle.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Immutable artifacts and release provenance
- API compatibility windows: release consumers and producers safely
- Rollback image retention: keep every approved fallback pullable
- Cache stampedes: bound origin work when popular keys expire
