Skip to content

refactor(cache): let remote cache requests carry auth headers - #797

Draft
wan9chi wants to merge 1 commit into
mainfrom
claude/remote-cache-auth-hook-18e511
Draft

wan9chi wants to merge 1 commit into
mainfrom
claude/remote-cache-auth-hook-18e511

Conversation

@wan9chi

@wan9chi wan9chi commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Motivation

The self-hosted remote cache server in #718, designed in #716, serves reads to anyone but accepts a store only with a GitHub Actions OIDC token. Other servers will need other credentials. For example, a private cache behind Cloudflare Access could need headers on every request. This adds one general hook so each kind of credentials is a separate implementation, and the client doesn't need to know about any of them.

Changes

  • vt_remote_cache::auth::Auth supplies the headers for each request, given its operation: fetch, download, or store. It can use the client's HTTP client to get credentials, such as a token, and that client doesn't follow redirects. If it fails, the request isn't sent, and the operation fails with the new Error::Auth ("failed to authenticate").
  • Client::new(endpoint, auth) takes the auth. Anonymous adds no headers. vp run uses Anonymous for now, so requests don't change.

The next PR in this stack adds GitHub Actions OIDC as the first auth with credentials.

🤖 Generated with Claude Code

`vt_remote_cache::Client::new` now takes an `Auth`, which supplies the
headers for each request by operation (fetch, download, or store). It can
use the client's HTTP client to get credentials, and when it fails, the
request isn't sent and the operation fails with `Error::Auth`. `vp run`
uses `Anonymous`, which adds no headers, so requests are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@wan9chi
wan9chi added this pull request to stack #799 October 4, 2026 07:52
@wan9chi wan9chi changed the title claude/remote cache auth hook 18e511 refactor(cache): let remote cache requests carry auth headers Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

fspy benchmark

linux

dynamic/launch             change  +0.73%  [ -7.76% ..  +8.31%]  overhead  +273.41%
dynamic/access             change  +0.15%  [ -1.05% ..  +1.22%]  overhead   +13.49%
dynamic/access-relative    change  +0.11%  [ -1.26% ..  +1.39%]  overhead   +58.42%
dynamic/access-contended   change  -1.18%  [ -4.30% ..  +2.14%]  overhead   +13.68%
static/launch              change  +0.16%  [ -4.73% ..  +5.95%]  overhead  +742.36%
static/access              change  -0.15%  [ -1.38% ..  +0.91%]  overhead  +781.08%
static/access-relative     change  -0.54%  [ -1.51% ..  +0.80%]  overhead +1333.95%
static/access-contended    change  -0.43%  [ -1.57% ..  +0.97%]  overhead +3042.32%

macos

dynamic/launch             change  -0.03%  [ -3.83% ..  +3.20%]  overhead  +211.33%
dynamic/access             change  +0.39%  [ -1.57% ..  +2.00%]  overhead    +2.83%
dynamic/access-relative    change  +0.23%  [ -2.55% ..  +3.09%]  overhead  +258.64%
dynamic/access-contended   change  -0.10%  [ -4.75% ..  +3.27%]  overhead    +3.89%

windows

dynamic/launch             change  +0.33%  [ -2.07% ..  +3.23%]  overhead   +25.88%
dynamic/access             change  +0.19%  [ -1.29% ..  +1.85%]  overhead    +1.32%
dynamic/access-relative    change  +1.05%  [ -5.05% .. +28.50%]  overhead    +1.83%
dynamic/access-contended   change  +1.74%  [ -2.66% ..  +8.77%]  overhead    +3.78%

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant