Skip to main content
Version: latest

Internal cache Pro

imgproxy Pro provides an internal cache that stores processed images on disk or in cloud storage. This cache can act as both a primary and a secondary cache, serving as a fallback when your CDN cache misses.

tip

While putting a CDN in front of imgproxy is and will always be a best practice, the internal cache provides long-term storage for cases that require an additional caching layer.

Why use internal cache?

The internal cache provides long-term persistent storage for processed images, unlike CDNs, which typically delete rarely accessed content. It stores images in a single location rather than across multiple edge stores, eliminating cache misses when requests hit different edges. The cache is designed specifically for imgproxy, working seamlessly with features like modern image format detection and client hints support that generic external caches don't understand by default.

The cache is protected by the same security measures as imgproxy itself, including URL signatures and processing restrictions. Importantly, URL signatures are not part of the cache key, so you can rotate keys or use multiple key/salt pairs without invalidating cached images. You maintain full control over where the cache is stored and how it integrates with your infrastructure.

Configuration

You need to define the following config variables to enable the internal cache:

  • IMGPROXY_CACHE_USE: the cache storage adapter to use. Can be fs, s3, gcs, abs (Azure Blob Storage), or swift (OpenStack Swift). When blank, the cache is disabled. Default: blank
  • IMGPROXY_CACHE_PATH_PREFIX: (optional) a path prefix for the cache files. This can be useful to organize cache files in a specific directory structure. Default: blank
  • IMGPROXY_CACHE_BUCKET: (optional) the bucket name for cloud storage adapters (S3, GCS, ABS, Swift). When using the filesystem adapter, this can be used as an additional path component. Default: blank
  • IMGPROXY_CACHE_KEY_HEADERS: (optional) a list of HTTP request headers (comma-separated) to include in the cache key. This allows caching different versions of the same image based on request headers. Default: blank
  • IMGPROXY_CACHE_KEY_COOKIES: (optional) a list of HTTP request cookies (comma-separated) to include in the cache key. This allows caching different versions of the same image based on cookies. Default: blank
  • IMGPROXY_CACHE_REPORT_ERRORS: When true, imgproxy will report cache errors instead of silently falling back to processing without cache. Default: false
  • IMGPROXY_CACHE_SHUTDOWN_TIMEOUT: (optional) the maximum time imgproxy will wait for pending background cache writes to complete during a graceful shutdown. Default: 5s
  • IMGPROXY_CACHE_PROCESSING_ENABLED: (optional) when true, imgproxy will cache processed images. Default: true
  • IMGPROXY_CACHE_INFO_ENABLED: (optional) when true, imgproxy will cache /info endpoint responses. Default: true
  • IMGPROXY_CACHE_SOURCE_ENABLE: (optional) when true, imgproxy caches downloaded source images in addition to processed results. Default: false

Source image caching

In addition to caching processed results, imgproxy can cache the raw bytes of downloaded source images. Set IMGPROXY_CACHE_SOURCE_ENABLE to true to enable it. This is useful when you request the same source image with many different processing options. Instead of re-downloading the source for every variant, imgproxy fetches it once and serves subsequent requests from the cache.

Storage configuration

The internal cache supports all the storage backends that imgproxy can read source images from: local filesystem, Amazon S3 and compatible services (Cloudflare R2, DigitalOcean Spaces, MinIO, etc.), Google Cloud Storage, Microsoft Azure Blob Storage, and OpenStack Swift.

Configure the storage backend using IMGPROXY_CACHE_* variables:

Cache key

The cache key for processed images and /info responses is generated based on:

  • Source image URL
  • Processing options
  • Output format
  • Optional: Request headers specified in IMGPROXY_CACHE_KEY_HEADERS
  • Optional: Request cookies specified in IMGPROXY_CACHE_KEY_COOKIES

URL signature is not part of the cache key, allowing key rotation without invalidating the cache.

Source cache key

When source image caching is enabled, cached sources use their own separate key, based on:

  • Source image URL
  • Optional: Request headers specified in IMGPROXY_CACHE_KEY_HEADERS
  • Optional: Request cookies specified in IMGPROXY_CACHE_KEY_COOKIES

Unlike the processed-image cache key, it doesn’t include processing options or the output format because it stores the downloaded source image, not a processed variant. It also doesn’t include the cachebuster value, so busting the processed-image cache doesn't invalidate the cached source.

Cache tags

imgproxy Pro can attach cache tags to a cache entry using the cache_tags processing option:

cache_tags:%tag1:%tag2:...:%tagN
ct:%tag1:%tag2:...:%tagN

Each tag can be up to 256 characters long and must consist of visible ASCII characters (character codes 33-126), excluding commas. We consider at most 50 tags per request; any beyond that are silently dropped.

The tags are also written to the response headers, so a CDN in front of imgproxy can use them for tag-based cache invalidation. Use the IMGPROXY_CACHE_TAGS_FORMAT config to choose which format(s) the tags are written in — CloudFront, Cloudflare, both (the default), or neither.

Bypassing the cache

imgproxy Pro can bypass the internal cache for a single request using the bypass_cache processing option:

bypass_cache:%bypass
bc:%bypass

When enabled for a request, imgproxy skips reading and writing the cache entirely—including the source cache, if enabled—and processes and fetches everything from the source image. Because this lets a client bypass your cache, it’s not allowed unless the IMGPROXY_ALLOW_BYPASS_CACHE config is set to true.

Limitations

  • No manual cache invalidation: Currently, imgproxy doesn't provide a built-in means to invalidate the cache. However, imgproxy includes the cachebuster in the cache key, so you can use it to force cache invalidation when needed. Most storage offerings also support object expiration, so you can set a reasonable expiration time for cached images.

How it works

When a request comes in:

  1. imgproxy checks the URL signature (if enabled).
  2. imgproxy generates the cache key from the request parameters.
  3. imgproxy checks if a cached processed image exists in the configured storage.
  4. If the cached image exists and is valid, imgproxy serves it directly.
  5. If not, and source image caching is enabled, imgproxy checks the source cache (using its own separate key) before downloading the source image:
    • On a hit, imgproxy uses the cached source bytes instead of re-downloading them.
    • On a miss, imgproxy downloads the source image and caches it in the background.
  6. imgproxy processes the image, serves the result, and stores it in the cache in the background — the response isn't delayed while it waits for the cache write to finish.

Cache writes (both processed-image and source) always happen in the background this way. On a graceful shutdown, imgproxy waits up to IMGPROXY_CACHE_SHUTDOWN_TIMEOUT for any still-pending writes to finish before exiting.