Production Web

Production Web Apps Series

Production patterns for web apps: caching, rate limiting, webhooks, queues, cron jobs, and idempotency.

4 chapters · about 106 min end to end

  1. Caching, Properly — The Four Caches Your App Uses and How They InteractMost apps under-cache or over-cache because nobody ever explains which of the four layered caches is doing what. This chapter walks the whole stack — the browser cache, the Cloudflare CDN cache, the Workers Cache API, and KV-as-cache — what each one is good for, how Cache-Control / ETag / 304 actually work, the read-through pattern that turns a $0.40/M-ops KV bucket into a millisecond-latency database cache, when to use which (with a decision table), and three real Worker snippets you can copy. Builds on the existing Cloudflare KV chapter.Intermediate · 26 min
  2. Rate Limiting & Abuse Prevention — Token Buckets, 429s, and Keeping Your Cloudflare Bill SaneThe complete production rate-limiting playbook for a Cloudflare-stacked app. The four algorithms (fixed window, sliding window, token bucket, leaky bucket) and which to pick when, Cloudflare's three native options (Rate Limiting Rules, Workers Rate Limiting API, and DIY Durable Objects) compared, what to identify by (IP vs JWT vs API key — and the CF-Connecting-IP trap), the right way to return 429 + Retry-After, per-route limit tiering (login much stricter than read), and a complete Durable-Object-backed limiter you can drop in. Builds on the JWT and KV chapters.Intermediate · 28 min
  3. Webhooks That Don't Lose Data — HMAC, Idempotency, Retries, and the Raw-Body TrapThe production webhook receiver pattern, end to end. The four things that go wrong (no signature check, double-processing, slow handlers, bad data) and the four fixes (HMAC + constant-time compare, idempotency keys, 2xx-fast + ctx.waitUntil, dead-letter). The raw-body trap explained — why `JSON.parse(body)` before signature verification silently breaks Stripe's HMAC. Real Worker code for Stripe, GitHub, and Cloudflare webhook senders, plus a Queues-backed pattern for slow processing. Anchored in the JWT/HMAC machinery from web Ch 11.Intermediate · 26 min
  4. Cron Triggers + Workers Queues — Scheduled Work and Async Fan-OutThe two Cloudflare primitives every production app eventually needs. Workers Cron Triggers for time-based work (nightly cleanup, hourly aggregation, daily digest emails) — set up in wrangler.toml with standard cron syntax and a `scheduled()` handler. Workers Queues for async fan-out — producer/consumer with built-in retries, exponential backoff, batch consumption, and a dead-letter queue for poison messages. The exact pricing math (~3 ops per delivered message, $0.40 per million after 1M free, no egress charge), 5,000 msg/sec/queue throughput, 250 concurrent consumers, the cron-vs-queue decision table, and a full end-to-end example: nightly cron finds expiring subscriptions → enqueues reminder emails → consumer sends them with retries.Intermediate · 26 min

Read next

Ultimate Web Development SeriesCloudflare Feature FocusModern Delivery Pipeline