Dev News Daily ENDE

Cloudflare adds Vary support to Cache Rules, with per-header control

Cloudflare now supports the HTTP Vary response header in Cache Rules on every plan, it announced on 22 September. Vary tells a cache which request headers may change the response for a URL - the language, the image format, the compression scheme - so that one client does not receive a response meant for another. The feature lets the origin keep declaring what may vary, while the customer decides how much of that variation the cache should treat as meaningful.

The blog post explains why this is hard. Vary says which headers may matter, not which differences in them do. An origin serving only English, French and German may map thousands of distinct Accept-Language values to three responses, but a cache comparing raw values cannot assume two different headers are equivalent, so identical responses scatter across many entries that are rarely reused. With several varying headers, the combinations multiply. Cloudflare says an analysis of more than 120 million responses from nearly 50,000 popular sites found almost 3,000 sites varying on four or more fields, and some on 10, 23 or even 47.

Under the new design, the origin returns Vary to name the relevant headers, and a Cache Rule chooses one of three actions for each: normalise known negotiation headers such as Accept and Accept-Language so equivalent requests share an entry; pass exact values through when small differences matter; or bypass the cache when variation is too unpredictable. If the origin does not return Vary, responses are cached normally.

Cloudflare adds Vary support to Cache Rules, with per-header control
Cloudflare adds Vary support to Cache Rules, with per-header control — Dev News Daily

What it means

Content negotiation has always forced a choice between correctness and cache efficiency: honour Vary literally and fragment the cache, or ignore it and risk serving HTML to an API client. Moving the "which differences matter" decision into configuration, next to the origin's declaration, is a cleaner split than reproducing negotiation logic in custom cache keys or Workers.

For site operators, the post doubles as a checklist. Every header named in Vary multiplies cache variants, and headers like User-Agent or cookies can make a cache correct but permanently cold. Auditing what an origin actually varies on is worth doing before turning the feature on.

Primary source
Cloudflare Blog
https://blog.cloudflare.com/vary-support/
Written by Victoria Shinder.