DRQ · data residency quarantine

Guarded Worker Cache API

Use residentCache from @comms-id/data-residency/cloudflare/workers around a native Cloudflare Cache instance. It checks Australian execution before every match, put and delete, using the existing Worker observer. Missing, malformed or foreign execution evidence prevents the native operation. Native cache results and Error failures otherwise keep their normal meaning.

import { requireResident, residentCache } from "@comms-id/data-residency/cloudflare/workers";

// Inside the authenticated application request, before reading protected data:
await requireResident();
const cache = residentCache(await caches.open("application-v1"));
const hit = await cache.match(key);
// On a miss, read through the application's existing verified R2/D1 binding.
// Cache only that application's authorised response, with an explicit native TTL.
await cache.put(key, new Response(bytes, { headers: { "Cache-Control": "max-age=60" } }));
// Invalidation is local to the current data centre:
await cache.delete(key);

Authenticate before lookup and scope keys to the authorised resource or principal. Keep authoritative data in qualified storage; a miss or eviction is normal. The wrapper neither fetches a source nor changes native TTL, conditional request, or response-header semantics.

Set Cache-Control: no-store on responses sent to clients, including cache hits, and remove conflicting CDN cache headers. The TTL on the response passed to cache.put describes the internal cache copy; it must not become permission for downstream response caching. Disable separate Worker response caching, fetch caching, CDN/tiered caching and provider logs for the protected path. The existing plan policy checks declared bindings/logging; it cannot prove that application code uses this runtime wrapper or sanitises its client responses.

Cloudflare documents the Cache API as local to its originating data centre, without replication to other data centres. This composition relies on that documented property and the existing runtime location observer; it is not a provider storage attestation or qualification of every cache product. Native KV, Queues, Workflows, Static Assets and provider logs retain their separate service status.

Bounded operator probe

Authenticated POST /cache-probe?city=SYD|MEL|AKL|SIN on the existing ledger entry forwards only a fixed request to the corresponding private control Worker. It does not call the ledger objects, read stock, change events, or forward the caller's body. The private Worker checks its own Australian execution before opening drq-probe-184; a foreign execution refuses before cache access.

The fixed guarded-cache-api-v1 probe writes two random synthetic keys, checks cold/hot/miss/delete/expiry, and attempts bounded cleanup. It uses native Cache API operations only, with 30-second and one-second TTLs. Probe replies use no-store; an incomplete operation or cleanup cannot produce success. The requested routing label does not establish the actual execution city.

Local integration uses a native-cache test double and the real ledger relay, private handler, observer and wrapper. The finite live acceptance set passed: SYD and MEL completed the native protocol in those observed cities; SIN refused before cache access. Each route was called once. This supports the guarded composition described above; local results alone do not establish provider behaviour.