PageSourceSearch

https://ratify.dev/assets/js/61c42fc6.cdaa403e.js

js ratify.dev collected 2026-09-24 19:27:56 UTC 8,421 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[2150],{18721(e,i,r){r.r(i),r.d(i,{assets:()=>o,contentTitle:()=>a,default:()=>h,frontMatter:()=>c,metadata:()=>s,toc:()=>d});const s=JSON.parse('{"id":"reference/cache","title":"Caching in Ratify","description":"Ratify supports memory caches and file-based blob caching.","source":"@site/versioned_docs/version-1.0/reference/cache.md","sourceDirName":"reference","slug":"/reference/cache","permalink":"/docs/1.0/reference/cache","draft":false,"unlisted":false,"editUrl":"https://github.com/ratify-project/ratify-web/blob/main/versioned_docs/version-1.0/reference/cache.md","tags":[],"version":"1.0","frontMatter":{},"sidebar":"tutorialSidebar","previous":{"title":"Reference","permalink":"/docs/1.0/category/reference"},"next":{"title":"api-upgrade-instruction","permalink":"/docs/1.0/reference/crds/api-upgrade-instruction"}}');var t=r(74848),n=r(28453);const c={},a="Caching in Ratify",o={},d=[{value:"Memory Caches",id:"memory-caches",level:2},{value:"Ristretto (default)",id:"ristretto-default",level:3},{value:"Dapr",id:"dapr",level:3},{value:"File store based cache",id:"file-store-based-cache",level:2},{value:"Flow Diagrams",id:"flow-diagrams",level:2}];function l(e){const i={a:"a",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",img:"img",li:"li",p:"p",ul:"ul",...(0,n.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(i.header,{children:(0,t.jsx)(i.h1,{id:"caching-in-ratify",children:"Caching in Ratify"})}),"\n",(0,t.jsx)(i.p,{children:"Ratify supports memory caches and file-based blob caching."}),"\n",(0,t.jsx)(i.h2,{id:"memory-caches",children:"Memory Caches"}),"\n",(0,t.jsxs)(i.p,{children:["Ratify provides a unified cache API for cache read/write. Caching providers implement the API and are registered on ratify creation. Users can configure which cache provider to use via helm chart/cli. For high availability scenarios, reference this ",(0,t.jsx)(i.a,{href:"/docs/1.0/quickstarts/ratify-high-availability",children:"guide"}),". Here are the current cche providers supported:"]}),"\n",(0,t.jsx)(i.h3,{id:"ristretto-default",children:"Ristretto (default)"}),"\n",(0,t.jsxs)(i.p,{children:["Ristretto is a highly performant in-memory caching library. The ristretto cache is configured as LRU.\nSee ",(0,t.jsx)(i.a,{href:"https://github.com/dgraph-io/ristretto",children:"docs"}),"."]}),"\n",(0,t.jsx)(i.p,{children:"When to use Ristretto as the cache provider?"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:"using the ratify quick start"}),"\n",(0,t.jsx)(i.li,{children:"only using ratify with notation verifier configured"}),"\n",(0,t.jsx)(i.li,{children:"using ratify as a single pod"}),"\n"]}),"\n",(0,t.jsx)(i.h3,{id:"dapr",children:"Dapr"}),"\n",(0,t.jsx)(i.p,{children:"Dapr (Distributed Application Runtime) supports many different state-stores both open source and cloud specific. Redis is the prefferred state-store implementation. Redis is a memory-based key-value distributed data-store. It is atomic and highly concurrent making it a good fit for distributed applications with multiple readers and writers. Ratify uses Redis as a centralized cache shared across multiple processes (each external plugin is run as a separate process) and across mutliple ratify replicas."}),"\n",(0,t.jsxs)(i.p,{children:["Ratify REQUIRES that each Dapr state store be configured with a primary encryption key in order to guarantee confidentiality of the cached data at rest. Please see guide ",(0,t.jsx)(i.a,{href:"/docs/1.0/quickstarts/ratify-high-availability",children:"here"})," on installing Ratify with Dapr Redis integration."]}),"\n",(0,t.jsx)(i.p,{children:"The Ratify chart does NOT come with built-in installation support for Dapr or Redis. User's must manage and configure on their own."}),"\n",(0,t.jsx)(i.p,{children:"When to use Redis as the cache provider?"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:"using multiple verifiers including external plugins"}),"\n",(0,t.jsx)(i.li,{children:"using high availability ratify deployment (multiple replicas)"}),"\n"]}),"\n",(0,t.jsxs)(i.p,{children:["Here's a diagram of the relationship between the cluster resources installed with Dapr + Redis + Ratify:\n",(0,t.jsx)(i.img,{src:r(28536).A+"",width:"1424",height:"1272"})]}),"\n",(0,t.jsx)("hr",{}),"\n",(0,t.jsx)(i.p,{children:"The centralized cache is currently used in 4 different scenarios:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:["Verify Request","\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:["cache key: ",(0,t.jsx)(i.co
1de,{children:"cache_ratify_verify_handler_<INSERT_IMAGE_REF>"})]}),"\n",(0,t.jsxs)(i.li,{children:["description: Caches external data response sent by the ",(0,t.jsx)(i.code,{children:"/verify"})," handler. This cache is required when Ratify gets multiple simulataneous requests for verification of the same image. Cache items should be very short lived."]}),"\n"]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["Subject Descriptor Resolution","\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:["cache key: ",(0,t.jsx)(i.code,{children:"cache_ratify_subject_descriptor_<DIGEST>"})]}),"\n",(0,t.jsxs)(i.li,{children:["description: Digest-based fully-qualifed subject image reference key to a resolved subject descriptor. This is used by the ",(0,t.jsx)(i.code,{children:"GetSubjectDescriptor"})," ORAS store implementation. The ",(0,t.jsx)(i.code,{children:"/mutate"})," path heavily relies on this cache due to the often redundant mutate requests Ratify gets during K8s resource creation."]}),"\n"]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["Authentication Credentials","\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:["cache key: ",(0,t.jsx)(i.code,{children:"cache_ratify_oras_auth_<INSERT_REGISTRY_HOST>"})]}),"\n",(0,t.jsxs)(i.li,{children:["description: Registry host name to ",(0,t.jsx)(i.code,{children:"AuthConfig"})," credentials object returned by the auth provider"]}),"\n"]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["Subject Referrers","\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:["cache key: ",(0,t.jsx)(i.code,{children:"cache_ratify_list_referrers_<INSERT_IMAGE_REF>"})]}),"\n",(0,t.jsxs)(i.li,{children:["description: The cache implementation of ",(0,t.jsx)(i.code,{children:"ListReferrers"})," stores the list of artifact descriptors returned from the registry referrers call. (Note: the cache duration can be specified via ",(0,t.jsx)(i.code,{children:"oras.cache.ttl"})," helm value)"]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(i.h2,{id:"file-store-based-cache",children:"File store based cache"}),"\n",(0,t.jsxs)(i.p,{children:["ORAS provides an OCI layout store for caching blobs in a local file descriptor. Ratify's ORAS store implementation stores all blobs fetched from registry in an OCI store. During verification, blob-related operations (",(0,t.jsx)(i.code,{children:"GetReferenceManifest"})," & ",(0,t.jsx)(i.code,{children:"GetBlobContent"}),") check the OCI file store for blob existence before making calls to registry."]}),"\n",(0,t.jsx)(i.h2,{id:"flow-diagrams",children:"Flow Diagrams"}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.img,{src:r(29978).A+"",width:"878",height:"1010"}),"\n",(0,t.jsx)(i.img,{src:r(66486).A+"",width:"858",height:"567"}),"\n",(0,t.jsx)(i.img,{src:r(82675).A+"",width:"766",height:"447"})]})]})}function h(e={}){const{wrapper:i}={...(0,n.R)(),...e.components};return i?(0,t.jsx)(i,{...e,children:(0,t.jsx)(l,{...e})}):l(e)}},28453(e,i,r){r.d(i,{R:()=>c,x:()=>a});var s=r(96540);const t={},n=s.createContext(t);function c(e){const i=s.useContext(n);return s.useMemo(function(){return"function"==typeof e?e(i):{...i,...e}},[i,e])}function a(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:c(e.components),s.createElement(n.Provider,{value:i},e.children)}},28536(e,i,r){r.d(i,{A:()=>s});const s=r.p+"assets/images/caching-dapr-redis-05c648cabd92351606cf5cee9fd3185e.png"},29978(e,i,r){r.d(i,{A:()=>s});
1const s=r.p+"assets/images/caching-executor-265bf80fac1c7b0557c4a0490a67d8b4.png"},66486(e,i,r){r.d(i,{A:()=>s});const s=r.p+"assets/images/caching-descriptor-3564b845871e14f5b29d337668f9c395.png"},82675(e,i,r){r.d(i,{A:()=>s});const s=r.p+"assets/images/caching-verifier-122dc1c94d3e241ca7442dd6d9d1bf52.png"}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.