Internal cache Pro
imgproxy Pro provides an internal cache that stores processed images on disk or in cloud storage. This cache can act as both a primary and a secondary cache, serving as a fallback when your CDN cache misses.
While putting a CDN in front of imgproxy is and will always be a best practice, the internal cache provides long-term storage for cases that require an additional caching layer.
Why use internal cache?
The internal cache provides long-term persistent storage for processed images, unlike CDNs, which typically delete rarely accessed content. It stores images in a single location rather than across multiple edge stores, eliminating cache misses when requests hit different edges. The cache is designed specifically for imgproxy, working seamlessly with features like modern image format detection and client hints support that generic external caches don't understand by default.
The cache is protected by the same security measures as imgproxy itself, including URL signatures and processing restrictions. Importantly, URL signatures are not part of the cache key, so you can rotate keys or use multiple key/salt pairs without invalidating cached images. You maintain full control over where the cache is stored and how it integrates with your infrastructure.
Configuration
You need to define the following config variables to enable the internal cache:
IMGPROXY_CACHE_USE: the cache storage adapter to use. Can befs,s3,gcs,abs(Azure Blob Storage), orswift(OpenStack Swift). When blank, the cache is disabled. Default: blankIMGPROXY_CACHE_PATH_PREFIX: (optional) a path prefix for the cache files. This can be useful to organize cache files in a specific directory structure. Default: blankIMGPROXY_CACHE_BUCKET: (optional) the bucket name for cloud storage adapters (S3, GCS, ABS, Swift). When using the filesystem adapter, this can be used as an additional path component. Default: blankIMGPROXY_CACHE_KEY_HEADERS: (optional) a list of HTTP request headers (comma-separated) to include in the cache key. This allows caching different versions of the same image based on request headers. Default: blankIMGPROXY_CACHE_KEY_COOKIES: (optional) a list of HTTP request cookies (comma-separated) to include in the cache key. This allows caching different versions of the same image based on cookies. Default: blankIMGPROXY_CACHE_REPORT_ERRORS: Whentrue, imgproxy will report cache errors instead of silently falling back to processing without cache. Default:falseIMGPROXY_CACHE_SHUTDOWN_TIMEOUT: (optional) the maximum time imgproxy will wait for pending background cache writes to complete during a graceful shutdown. Default:5sIMGPROXY_CACHE_PROCESSING_ENABLED: (optional) whentrue, imgproxy will cache processed images. Default:trueIMGPROXY_CACHE_INFO_ENABLED: (optional) whentrue, imgproxy will cache/infoendpoint responses. Default:trueIMGPROXY_CACHE_SOURCE_ENABLE: (optional) whentrue, imgproxy caches downloaded source images in addition to processed results. Default:false
Source image caching
In addition to caching processed results, imgproxy can cache the raw bytes of downloaded source images. Set IMGPROXY_CACHE_SOURCE_ENABLE to true to enable it. This is useful when you request the same source image with many different processing options. Instead of re-downloading the source for every variant, imgproxy fetches it once and serves subsequent requests from the cache.
Storage configuration
The internal cache supports all the storage backends that imgproxy can read source images from: local filesystem, Amazon S3 and compatible services (Cloudflare R2, DigitalOcean Spaces, MinIO, etc.), Google Cloud Storage, Microsoft Azure Blob Storage, and OpenStack Swift.
Configure the storage backend using IMGPROXY_CACHE_* variables:
- For filesystem cache, see Cache storage: Local filesystem.
- For S3 cache, see Cache storage: Amazon S3.
- For GCS cache, see Cache storage: Google Cloud Storage.
- For Azure Blob Storage cache, see Cache storage: Azure Blob Storage.
- For Swift cache, see Cache storage: OpenStack Object Storage ("Swift").
Cache key
The cache key for processed images and /info responses is generated based on:
- Source image URL
- Processing options
- Output format
- Optional: Request headers specified in
IMGPROXY_CACHE_KEY_HEADERS - Optional: Request cookies specified in
IMGPROXY_CACHE_KEY_COOKIES
URL signature is not part of the cache key, allowing key rotation without invalidating the cache.
Source cache key
When source image caching is enabled, cached sources use their own separate key, based on:
- Source image URL
- Optional: Request headers specified in
IMGPROXY_CACHE_KEY_HEADERS - Optional: Request cookies specified in
IMGPROXY_CACHE_KEY_COOKIES
Unlike the processed-image cache key, it doesn’t include processing options or the output format because it stores the downloaded source image, not a processed variant. It also doesn’t include the cachebuster value, so busting the processed-image cache doesn't invalidate the cached source.
Cache tags
imgproxy Pro can attach cache tags to a cache entry using the cache_tags processing option:
cache_tags:%tag1:%tag2:...:%tagN
ct:%tag1:%tag2:...:%tagN
Each tag can be up to 256 characters long and must consist of visible ASCII characters (character codes 33-126), excluding commas. We consider at most 50 tags per request; any beyond that are silently dropped.
The tags are also written to the response headers, so a CDN in front of imgproxy can use them for tag-based cache invalidation. Use the IMGPROXY_CACHE_TAGS_FORMAT config to choose which format(s) the tags are written in — CloudFront, Cloudflare, both (the default), or neither.
Bypassing the cache
imgproxy Pro can bypass the internal cache for a single request using the bypass_cache processing option:
bypass_cache:%bypass
bc:%bypass
When enabled for a request, imgproxy skips reading and writing the cache entirely—including the source cache, if enabled—and processes and fetches everything from the source image. Because this lets a client bypass your cache, it’s not allowed unless the IMGPROXY_ALLOW_BYPASS_CACHE config is set to true.
Limitations
- No manual cache invalidation: Currently, imgproxy doesn't provide a built-in means to invalidate the cache. However, imgproxy includes the cachebuster in the cache key, so you can use it to force cache invalidation when needed. Most storage offerings also support object expiration, so you can set a reasonable expiration time for cached images.
How it works
When a request comes in:
- imgproxy checks the URL signature (if enabled).
- imgproxy generates the cache key from the request parameters.
- imgproxy checks if a cached processed image exists in the configured storage.
- If the cached image exists and is valid, imgproxy serves it directly.
- If not, and source image caching is enabled, imgproxy checks the source cache (using its own separate key) before downloading the source image:
- On a hit, imgproxy uses the cached source bytes instead of re-downloading them.
- On a miss, imgproxy downloads the source image and caches it in the background.
- imgproxy processes the image, serves the result, and stores it in the cache in the background — the response isn't delayed while it waits for the cache write to finish.
Cache writes (both processed-image and source) always happen in the background this way. On a graceful shutdown, imgproxy waits up to IMGPROXY_CACHE_SHUTDOWN_TIMEOUT for any still-pending writes to finish before exiting.