Stop telling caches the moving aliases never change

latest.apk and latest-linux.tar.gz are symlinks the release script
repoints, and latest.apk matched the `\.apk$` rule that serves
`immutable, max-age=1y`. So the one URL people are handed was the one URL
a browser or proxy could pin to an old release for a year.

Exact-match locations win over the regex in nginx, so the two aliases now
carry no-cache and the versioned artifacts — which genuinely never change,
because a release is a new filename — keep the immutable header. The
regex also covers .tar.gz now; it only ever mentioned .apk.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Richard 2026-09-06 19:04:20 +02:00
parent b38be1014d
commit 2b0caa3a38

View file

@ -16,7 +16,19 @@ server {
location = /manifest.json {
add_header Cache-Control "no-cache";
}
location ~ \.apk$ {
# The `latest` aliases MOVE they are symlinks the release script
# repoints so they must never be cached as immutable. Exact-match
# locations win over the regex below in nginx, which is what keeps a
# one-year immutable header off the one URL people are told to use.
location = /latest.apk {
add_header Cache-Control "no-cache";
}
location = /latest-linux.tar.gz {
add_header Cache-Control "no-cache";
}
# A versioned artifact never changes: a new release is a new filename.
location ~ \.(apk|tar\.gz)$ {
add_header Cache-Control "public, max-age=31536000, immutable";
}