Caching Patterns
A well-placed cache is the cheapest way to buy speed. A misplaced cache is the most expensive way to buy bugs.
Cache Strategies
| Strategy |
How It Works |
When to Use |
| Cache-Aside (Lazy) |
App checks cache → miss → reads DB → writes to cache |
Default choice — general purpose |
| Read-Through |
Cache fetches from DB on miss automatically |
ORM-integrated caching, CDN origin fetch |
| Write-Through |
Writes go to cache AND DB synchronously |
Read-heavy with strong consistency |
| Write-Behind |
Writes go to cache, async flush to DB |
High write throughput, eventual consistency OK |
| Refresh-Ahead |
Cache proactively refreshes before expiry |
Predictable access patterns, low-latency critical |
Cache-Aside Flow:
App ──► Cache ──► HIT? ──► Return data
│
▼ MISS
Read DB ──► Store in Cache ──► Return data
Cache Invalidation
| Method |
Consistency |
When to Use |
| TTL-based |
Eventual (up to TTL) |
Simple data, acceptable staleness |
| Event-based |
Strong (near real-time) |
Inventory, profile updates |
| Version-based |
Strong |
Static assets, API responses, config |
| Tag-based |
Strong |
CMS content, category-based purging |
TTL Guidelines
| Data Type |
TTL |
Rationale |
| Static assets (CSS/JS/images) |
1 year + cache-busting hash |
Immutable by filename |
| API config / feature flags |
30–60 seconds |
Fast propagation needed |
| User profile data |
5–15 minutes |
Tolerable staleness |
| Product catalog |
1–5 minutes |
Balance freshness vs load |
| Session data |
Match session timeout |
Security requirement |
HTTP Caching
Cache-Control Directives
| Directive |
Meaning |
max-age=N |
Cache for N seconds |
s-maxage=N |
CDN/shared cache max age (overrides max-age) |
no-cache |
Must revalidate before using cached copy |
no-store |
Never cache anywhere |
must-revalidate |
Once stale, must revalidate |
private |
Only browser can cache, not CDN |
public |
Any cache can store |
immutable |
Content will never change (within max-age) |
stale-while-revalidate=N |
Serve stale for N seconds while fetching fresh |
Common Recipes
# Immutable static assets (hashed filenames)
Cache-Control: public, max-age=31536000, immutable
# API response, CDN-cached, background refresh
Cache-Control: public, s-maxage=60, stale-while-revalidate=300
# Personalized data, browser-only
Cache-Control: private, max-age=0, must-revalidate
ETag: "abc123"
# Never cache (auth tokens, sensitive data)
Cache-Control: no-store
Conditional Requests
| Mechanism |
Request Header |
Response Header |
How It Works |
| ETag |
If-None-Match: "abc" |
ETag: "abc" |
Hash-based — 304 if match |
| Last-Modified |
If-Modified-Since: <date> |
Last-Modified: <date> |
Date-based — 304 if unchanged |
Prefer ETag over Last-Modified — ETags detect content changes regardless of timestamp granularity.
Application Caching
| Solution |
Speed |
Shared Across Processes |
When to Use |
| In-memory LRU |
Fastest |
No |
Single-process, bounded memory, hot data |
| Redis |
Sub-ms (network) |
Yes |
Production default — TTL, pub/sub, persistence |
| Memcached |
Sub-ms (network) |
Yes |
Simple key-value at extreme scale |
| SQLite |
Fast (disk) |
No |
Embedded apps, edge caching |
Redis vs Memcached
| Feature |
Redis |
Memcached |
| Data structures |
Strings, hashes, lists, sets, sorted sets |
Strings only |
| Persistence |
AOF, RDB snapshots |
None |
| Pub/Sub |
Yes |
No |
| Max value size |
512 MB |
1 MB |
| Verdict |
Default choice |
Pure cache at extreme scale |
Distributed Caching
| Concern |
Solution |
| Partitioning |
Consistent hashing — minimal reshuffling on node changes |
| Replication |
Primary-replica — writes to primary, reads from replicas |
| Failover |
Redis Sentinel or Cluster auto-failover |
Rule of thumb: 3 primaries + 3 replicas minimum for production Redis Cluster.
Cache Eviction Policies
| Policy |
How It Works |
When to Use |
| LRU |
Evicts least recently accessed |
Default — general purpose |
| LFU |
Evicts least frequently accessed |
Skewed popularity distributions |
| FIFO |
Evicts oldest entry |
Simple, time-ordered data |
| TTL |
Evicts after fixed duration |
Data with known freshness window |
Redis default is noeviction. Set maxmemory-policy to allkeys-lru or volatile-lru for production.
Caching Layers
Browser Cache → CDN → Load Balancer → App Cache → DB Cache → Database
| Layer |
What to Cache |
Invalidation |
| Browser |
Static assets, API responses |
Versioned URLs, Cache-Control |
| CDN |
Static files, public API responses |
Purge API, surrogate keys |
| Application |
Computed results, DB queries, external API |
Event-driven, TTL |
| Database |
Query plans, buffer pool, materialized views |
ANALYZE, manual refresh |
Cache Stampede Prevention
When a hot key expires, hundreds of requests simultaneously hit the database.
| Technique |
How It Works |
| Mutex / Lock |
First request locks, fetches, populates; others wait |
| Probabilistic early expiration |
Random chance of refreshing before TTL |
| Request coalescing |
Deduplicate in-flight requests for same key |
| Stale-while-revalidate |
Serve stale, refresh asynchronously |
Cache Warming
| Strategy |
When to Use |
| On-deploy warm-up |
Predictable key set, latency-sensitive |
| Background job |
Reports, dashboards, catalog data |
| Shadow traffic |
Cache migration, new infrastructure |
| Priority-based |
Limited warm-up time budget |
Cold start impact: A full cache flush can increase DB load 10–100x. Always warm gradually or use stale-while-revalidate.
Monitoring
| Metric |
Healthy Range |
Action if Unhealthy |
| Hit rate |
> 90% |
Low → cache too small, wrong TTL, bad key design |
| Eviction rate |
Near 0 steady state |
High → increase memory or tune policy |
| Latency (p99) |
< 1ms (Redis) |
High → network issue, large values, hot key |
| Memory usage |
< 80% of max |
Approaching max → scale up or tune eviction |
NEVER Do
- NEVER cache without a TTL or invalidation plan — data rots; every entry needs an expiry path
- NEVER treat cache as durable storage — caches evict, crash, and restart; always fall back to source of truth
- NEVER cache sensitive data (tokens, PII) without encryption — cache breaches expose everything in plaintext
- NEVER ignore cache stampede on hot keys — one expired popular key can take down your database
- NEVER use unbounded in-memory caches in production — memory grows until OOM-killed
- NEVER cache mutable data with
immutable Cache-Control — browsers will never re-fetch
- NEVER skip monitoring hit/miss rates — you won't know if your cache is helping or hurting
1---2name: caching3description: Caching strategies, invalidation, eviction policies, HTTP caching, distributed caching, and anti-patterns. Use when designing cache layers, choosing eviction policies, debugging stale data, or optimizing read-heavy workloads.4---5
6# Caching Patterns
7
8> A well-placed cache is the cheapest way to buy speed. A misplaced cache is the most expensive way to buy bugs.
9
10## Cache Strategies
11
12| Strategy | How It Works | When to Use |
13|----------|-------------|-------------|
14| **Cache-Aside (Lazy)** | App checks cache → miss → reads DB → writes to cache | **Default choice** — general purpose |
15| **Read-Through** | Cache fetches from DB on miss automatically | ORM-integrated caching, CDN origin fetch |
16| **Write-Through** | Writes go to cache AND DB synchronously | Read-heavy with strong consistency |
17| **Write-Behind** | Writes go to cache, async flush to DB | High write throughput, eventual consistency OK |
18| **Refresh-Ahead** | Cache proactively refreshes before expiry | Predictable access patterns, low-latency critical |
19
20```
21Cache-Aside Flow:
22
23 App ──► Cache ──► HIT? ──► Return data
24 │
25 ▼ MISS
26 Read DB ──► Store in Cache ──► Return data
27```
28
29---
30
31## Cache Invalidation
32
33| Method | Consistency | When to Use |
34|--------|-------------|-------------|
35| **TTL-based** | Eventual (up to TTL) | Simple data, acceptable staleness |
36| **Event-based** | Strong (near real-time) | Inventory, profile updates |
37| **Version-based** | Strong | Static assets, API responses, config |
38| **Tag-based** | Strong | CMS content, category-based purging |
39
40### TTL Guidelines
41
42| Data Type | TTL | Rationale |
43|-----------|-----|-----------|
44| Static assets (CSS/JS/images) | 1 year + cache-busting hash | Immutable by filename |
45| API config / feature flags | 30–60 seconds | Fast propagation needed |
46| User profile data | 5–15 minutes | Tolerable staleness |
47| Product catalog | 1–5 minutes | Balance freshness vs load |
48| Session data | Match session timeout | Security requirement |
49
50---
51
52## HTTP Caching
53
54### Cache-Control Directives
55
56| Directive | Meaning |
57|-----------|---------|
58| `max-age=N` | Cache for N seconds |
59| `s-maxage=N` | CDN/shared cache max age (overrides max-age) |
60| `no-cache` | Must revalidate before using cached copy |
61| `no-store` | Never cache anywhere |
62| `must-revalidate` | Once stale, must revalidate |
63| `private` | Only browser can cache, not CDN |
64| `public` | Any cache can store |
65| `immutable` | Content will never change (within max-age) |
66| `stale-while-revalidate=N` | Serve stale for N seconds while fetching fresh |
67
68### Common Recipes
69
70```
71# Immutable static assets (hashed filenames)
72Cache-Control: public, max-age=31536000, immutable
73
74# API response, CDN-cached, background refresh
75Cache-Control: public, s-maxage=60, stale-while-revalidate=300
76
77# Personalized data, browser-only
78Cache-Control: private, max-age=0, must-revalidate
79ETag: "abc123"
80
81# Never cache (auth tokens, sensitive data)
82Cache-Control: no-store
83```
84
85### Conditional Requests
86
87| Mechanism | Request Header | Response Header | How It Works |
88|-----------|---------------|-----------------|-------------|
89| **ETag** | `If-None-Match: "abc"` | `ETag: "abc"` | Hash-based — 304 if match |
90| **Last-Modified** | `If-Modified-Since: <date>` | `Last-Modified: <date>` | Date-based — 304 if unchanged |
91
92Prefer ETag over Last-Modified — ETags detect content changes regardless of timestamp granularity.
93
94---
95
96## Application Caching
97
98| Solution | Speed | Shared Across Processes | When to Use |
99|----------|-------|------------------------|-------------|
100| **In-memory LRU** | Fastest | No | Single-process, bounded memory, hot data |
101| **Redis** | Sub-ms (network) | Yes | **Production default** — TTL, pub/sub, persistence |
102| **Memcached** | Sub-ms (network) | Yes | Simple key-value at extreme scale |
103| **SQLite** | Fast (disk) | No | Embedded apps, edge caching |
104
105### Redis vs Memcached
106
107| Feature | Redis | Memcached |
108|---------|-------|-----------|
109| Data structures | Strings, hashes, lists, sets, sorted sets | Strings only |
110| Persistence | AOF, RDB snapshots | None |
111| Pub/Sub | Yes | No |
112| Max value size | 512 MB | 1 MB |
113| **Verdict** | **Default choice** | Pure cache at extreme scale |
114
115---
116
117## Distributed Caching
118
119| Concern | Solution |
120|---------|----------|
121| **Partitioning** | Consistent hashing — minimal reshuffling on node changes |
122| **Replication** | Primary-replica — writes to primary, reads from replicas |
123| **Failover** | Redis Sentinel or Cluster auto-failover |
124
125**Rule of thumb:** 3 primaries + 3 replicas minimum for production Redis Cluster.
126
127---
128
129## Cache Eviction Policies
130
131| Policy | How It Works | When to Use |
132|--------|-------------|-------------|
133| **LRU** | Evicts least recently accessed | **Default** — general purpose |
134| **LFU** | Evicts least frequently accessed | Skewed popularity distributions |
135| **FIFO** | Evicts oldest entry | Simple, time-ordered data |
136| **TTL** | Evicts after fixed duration | Data with known freshness window |
137
138> Redis default is `noeviction`. Set `maxmemory-policy` to `allkeys-lru` or `volatile-lru` for production.
139
140---
141
142## Caching Layers
143
144```
145Browser Cache → CDN → Load Balancer → App Cache → DB Cache → Database
146```
147
148| Layer | What to Cache | Invalidation |
149|-------|--------------|--------------|
150| **Browser** | Static assets, API responses | Versioned URLs, Cache-Control |
151| **CDN** | Static files, public API responses | Purge API, surrogate keys |
152| **Application** | Computed results, DB queries, external API | Event-driven, TTL |
153| **Database** | Query plans, buffer pool, materialized views | `ANALYZE`, manual refresh |
154
155---
156
157## Cache Stampede Prevention
158
159When a hot key expires, hundreds of requests simultaneously hit the database.
160
161| Technique | How It Works |
162|-----------|-------------|
163| **Mutex / Lock** | First request locks, fetches, populates; others wait |
164| **Probabilistic early expiration** | Random chance of refreshing before TTL |
165| **Request coalescing** | Deduplicate in-flight requests for same key |
166| **Stale-while-revalidate** | Serve stale, refresh asynchronously |
167
168---
169
170## Cache Warming
171
172| Strategy | When to Use |
173|----------|-------------|
174| **On-deploy warm-up** | Predictable key set, latency-sensitive |
175| **Background job** | Reports, dashboards, catalog data |
176| **Shadow traffic** | Cache migration, new infrastructure |
177| **Priority-based** | Limited warm-up time budget |
178
179> **Cold start impact:** A full cache flush can increase DB load 10–100x. Always warm gradually or use stale-while-revalidate.
180
181---
182
183## Monitoring
184
185| Metric | Healthy Range | Action if Unhealthy |
186|--------|--------------|---------------------|
187| **Hit rate** | > 90% | Low → cache too small, wrong TTL, bad key design |
188| **Eviction rate** | Near 0 steady state | High → increase memory or tune policy |
189| **Latency (p99)** | < 1ms (Redis) | High → network issue, large values, hot key |
190| **Memory usage** | < 80% of max | Approaching max → scale up or tune eviction |
191
192---
193
194## NEVER Do
195
1961. **NEVER cache without a TTL or invalidation plan** — data rots; every entry needs an expiry path
1972. **NEVER treat cache as durable storage** — caches evict, crash, and restart; always fall back to source of truth
1983. **NEVER cache sensitive data (tokens, PII) without encryption** — cache breaches expose everything in plaintext
1994. **NEVER ignore cache stampede on hot keys** — one expired popular key can take down your database
2005. **NEVER use unbounded in-memory caches in production** — memory grows until OOM-killed
2016. **NEVER cache mutable data with `immutable` Cache-Control** — browsers will never re-fetch
2027. **NEVER skip monitoring hit/miss rates** — you won't know if your cache is helping or hurting