Skip to content

feat(cloudflare): Add cacheClient to reuse the client across invocations - #23151

Open
JPeer264 wants to merge 10 commits into
jp/cacheclient-add-hooksfrom
jp/cacheclient
Open

feat(cloudflare): Add cacheClient to reuse the client across invocations#23151
JPeer264 wants to merge 10 commits into
jp/cacheclient-add-hooksfrom
jp/cacheclient

Conversation

@JPeer264

@JPeer264 JPeer264 commented Aug 7, 2026

Copy link
Copy Markdown
Member

closes #23083
closes #22545
closes #21950

What

This PR is reusing the client, instead of creating a new one. This is also only possible because of #22969 (as now we have the correct isolation scopes per request).

To still have an escape hatch and keep the old behavior there is the cacheClient: false option, that just creates a new client per request, as before.

Why

There are more and more issues coming in, that .dispose is leading to errors, which makes sense as in DurableObjects data can flow in after a request happened and it stays alive. Since we created a new client on each request, we also had to clean it up - the best point in time was after a request, which was too early for e.g. #22545. Since there is not a perfect time to dispose the client the only option is to reuse the client and not dispose at all (this is then also aligned with how other SDK machinery works).

Issues and how they're solved

Timing

In CF, timers are usually 0 and therefore our 5 second auto flush wouldn't work. In order to still retrieve all the data we need to have point in times (hooks) where it is safe to flush. In our case we have a request and flush after a request, like before. Events that come in a later point in time are then captured with the hooks added in #23136 (most important one is the afterEnvelope).

We start listening to the hooks once flushPointReached is set to true - which is AFTER a request, the time where we have no control anymore about flushing manually otherwise.

waitUntil

Keeping the correct waitUntil is important, as each request needs its own waitUntil to properly flush. To still keep the correct waitUntil this is now bound onto the scope directly. I tried using setSDKProcessingMetadata on the scope, but it just didn't work properly on deployed workers. Instead this is bound onto the scope directly with a Symbol - that works like a charm. This is the INVOCATION_STATE #namingishard

flushLock

The flush lock would wait for all spans to be finished and then flush. This would just not work, as we only have one client. So we skip this entirely and get rid of that hack. We keep this in order to have the escape hatch cacheClient: false in case something goes sideways.

Bonuses

Bonus 1

Because we are now reusing the client we are saving valuable CPU cycles per request. With cacheClient: true we gain up to ~14-21% per request, which is loads. Also on top of the CPU wins we also retrieve more events, which would have been dropped before.

Bonus 2

In v12 (or any other major) we could get rid of all the flushLock hacks and the rest of hacks we did

Bonus 3

Dedupe integration works now as intended. Because we created a new client and the dedupeIntegration only deduplicated per integration, which was a new one on every client, we only deduped it per request, not for all requests.

Sidenotes

During the implementation I thought about having multiple clients, which are cached in one global map - in case the isolations would get reused from other deployments or other bindings. After some excessive tests it seems that new deployments are getting a fresh isolate, different bindings have their own isolate, only ExportedHandlers and WorkerEntrypoints share one isolate, which makes sense to some degree, as they're isolated within each request anyways (they're getting a fresh isolate on a new deployment though). Because this is the case only one client is being created instead of checking if the config differs between clients.


Clanker description

Building and disposing a client per invocation costs real time on every request, and in a Durable Object it also loses data: there is no waitUntil boundary that dependably extends execution, so anything captured after the handler returned went to a client that had already been disposed.

Enabled by default, this caches one client per isolate. The first initialization wins for the isolate's lifetime: a later init with different options reuses that client, and a new deployment always starts fresh isolates, so clients are always built from the
current version's options. A cached client is flushed but not disposed at an invocation boundary, and it is re-bound to the current scope on every invocation — otherwise initialScope would apply only to an isolate's first invocation, and a client disposed by a competing init would keep being handed out. A cached client whose transport is gone is evicted rather than returned.

Because a reused client never reaches an end-of-invocation flush, delivery is eager: the new afterEnvelope hook on the core client drains the transport buffer as soon as an envelope has been accepted, and logs and metrics drain on a debounced hook so they are batched rather than sent one at a time. Spans that end after the invocation's flush point are delivered through core's flushTraceSpans hook, which flushes only that trace's bucket from the span streaming buffer. The per-invocation flush lock and span tracking are skipped, since binding a client that outlives the invocation to one invocation's lock would make later flushes wait on that invocation's work forever.

A shared client also shares integration state, so dedupe works across invocations: the same error raised by two separate requests is reported only once.

@JPeer264 JPeer264 self-assigned this Aug 7, 2026
@JPeer264

JPeer264 commented Aug 7, 2026

Copy link
Copy Markdown
Member Author

bugbot run

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 30.34 kB +0.03% +7 B 🔺
@sentry/browser - with treeshaking flags 28.52 kB +0.03% +8 B 🔺
@sentry/browser - with treeshaking flags tracing without tracing 26.86 kB +0.03% +8 B 🔺
@sentry/browser (incl. Tracing) 48.57 kB +0.02% +5 B 🔺
@sentry/browser (incl. Tracing + Span Streaming) 48.58 kB +0.02% +6 B 🔺
@sentry/browser (incl. Tracing, Profiling) 51.45 kB +0.02% +6 B 🔺
@sentry/browser (incl. Tracing, Replay) 87.98 kB +0.01% +7 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 77.36 kB +0.02% +10 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas) 92.7 kB +0.02% +10 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback) 105.38 kB +0.01% +6 B 🔺
@sentry/browser (incl. Feedback) 47.66 kB +0.01% +3 B 🔺
@sentry/browser (incl. sendFeedback) 35.17 kB +0.02% +7 B 🔺
@sentry/browser (incl. FeedbackAsync) 40.32 kB +0.02% +7 B 🔺
@sentry/browser (incl. Metrics) 31.32 kB +0.03% +7 B 🔺
@sentry/browser (incl. Logs) 31.58 kB +0.03% +7 B 🔺
@sentry/browser (incl. Metrics & Logs) 32.26 kB +0.03% +7 B 🔺
@sentry/react 32.14 kB +0.03% +8 B 🔺
@sentry/react (incl. Tracing) 50.77 kB +0.02% +7 B 🔺
@sentry/vue 35.36 kB +0.04% +11 B 🔺
@sentry/vue (incl. Tracing) 50.52 kB +0.02% +7 B 🔺
@sentry/svelte 30.37 kB +0.03% +8 B 🔺
CDN Bundle 31.65 kB +0.02% +5 B 🔺
CDN Bundle (incl. Tracing) 48.9 kB +0.02% +6 B 🔺
CDN Bundle (incl. Logs, Metrics) 33.87 kB +0.03% +8 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) 50.85 kB +0.01% +3 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) 74.38 kB +0.01% +7 B 🔺
CDN Bundle (incl. Tracing, Replay) 86.49 kB +0.01% +7 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 88.35 kB +0.01% +8 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) 92.19 kB +0.01% +6 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 94.16 kB +0.01% +4 B 🔺
CDN Bundle - uncompressed 93.98 kB +0.05% +39 B 🔺
CDN Bundle (incl. Tracing) - uncompressed 146.8 kB +0.03% +39 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed 100.38 kB +0.04% +39 B 🔺
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 152.6 kB +0.03% +39 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 229.32 kB +0.02% +39 B 🔺
CDN Bundle (incl. Tracing, Replay) - uncompressed 266.06 kB +0.02% +39 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 271.84 kB +0.02% +39 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 279.76 kB +0.02% +39 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 285.53 kB +0.02% +39 B 🔺
@sentry/nextjs (client) 53.3 kB +0.02% +8 B 🔺
@sentry/sveltekit (client) 48.99 kB +0.02% +8 B 🔺
@sentry/core/server 65.46 kB +0.03% +18 B 🔺
@sentry/core/browser 51.82 kB +0.05% +21 B 🔺
@sentry/node 118 kB +0.03% +25 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection) 0 B added added
@sentry/node - without tracing 82.11 kB +0.02% +13 B 🔺
@sentry/aws-serverless 91.52 kB +0.03% +19 B 🔺
@sentry/cloudflare (withSentry) - minified 216.35 kB +1.07% +2.28 kB 🔺
@sentry/cloudflare (withSentry) 537.85 kB +1.7% +8.96 kB 🔺

View base workflow run

Comment thread packages/cloudflare/src/client.ts
Comment thread packages/cloudflare/src/client.ts
Comment thread packages/cloudflare/src/client.ts Outdated
Comment thread packages/cloudflare/src/client.ts Outdated
@JPeer264
JPeer264 force-pushed the jp/cacheclient branch 2 times, most recently from d081c44 to a362f65 Compare August 7, 2026 13:09
@JPeer264

JPeer264 commented Aug 7, 2026

Copy link
Copy Markdown
Member Author

bugbot run

Comment thread packages/cloudflare/src/sdk.ts Outdated
Comment thread packages/cloudflare/src/flush.ts
Comment thread packages/cloudflare/src/client.ts
Comment thread dev-packages/cloudflare-integration-tests/suites/cache-client/test.ts Outdated
@JPeer264
JPeer264 force-pushed the jp/cacheclient branch 2 times, most recently from 8869481 to 0ba7c00 Compare August 7, 2026 14:15
JPeer264 added a commit that referenced this pull request Aug 10, 2026
Adds tests to check if `enableDedupes` is really disabled for workflows

original trigger:
#23151 (comment)

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@JPeer264

Copy link
Copy Markdown
Member Author

bugbot run

Comment thread packages/cloudflare/src/client.ts
@JPeer264

JPeer264 commented Aug 11, 2026

Copy link
Copy Markdown
Member Author

bugbot approve

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 71b3f5f. Configure here.

@JPeer264
JPeer264 marked this pull request as ready for review August 11, 2026 07:46
@JPeer264
JPeer264 requested a review from a team as a code owner August 11, 2026 07:46
@JPeer264
JPeer264 requested review from andreiborza, isaacs, mydea and nicohrubec and removed request for a team and isaacs August 11, 2026 07:46

@andreiborza andreiborza left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems like a lot of extra, hard-to-maintain code that's working around the way client flushing works in our SDKs. Are you sure the perf gains are worth it? I'm a bit concerned, but your call.

* scope, which is shared by every invocation in the isolate.
*/
export function setInvocationState(scope: Scope, state: InvocationState): void {
(scope as ScopeWithInvocationState)[INVOCATION_STATE] = state;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Let's add a check here to only set this if scope !== getDefaultIsolationScope(), wdyt?

Comment thread packages/cloudflare/src/baseSdk.ts Outdated
options: CloudflareOptions,
getDefaultIntegrationsImpl: (options: CloudflareOptions) => Integration[],
): CloudflareClient | undefined {
const cacheEnabled = options.cacheClient !== false && Boolean(options.dsn);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Why the check on dsn?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Uff that was a left over from before where I cached multiple clients per isolate. This should be removed

Comment thread packages/cloudflare/src/client.ts
Comment thread packages/cloudflare/src/client.ts
Comment thread packages/cloudflare/src/client.ts
Comment thread packages/cloudflare/src/client.ts Outdated

// If no more pending spans, resolve the completion promise
if (this._pendingSpans.size === 0 && this._resolveSpanCompletion) {
DEBUG_BUILD && debug.log('[CloudflareClient] All spans completed, resolving promise');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

l: This doesn't seem to add much value to the user, what promise is resolving? I think we prob don't need to log here, wdyt?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Before, per client we needed a way to know WHEN to flush, as there is no timer. The only way to know when to flush is when potentially no spans are open anymore (this was super hacky, but worked somehow - but ofc not for all usecases - this is why we don't rely on it anymore).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sure, but I mean the debug log itself. What would I do with this as a user? 🤔

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah true - I can refine that a little. I change it to

Suggested change
DEBUG_BUILD && debug.log('[CloudflareClient] All spans completed, resolving promise');
DEBUG_BUILD && debug.log('[CloudflareClient] All spans completed, preparing to flush');

Comment thread packages/cloudflare/src/client.ts
Comment thread packages/cloudflare/src/client.ts Outdated
}

const DEFAULT_TRANSPORT_BUFFER_SIZE = 30;
const DEFAULT_TRANSPORT_BUFFER_SIZE = 256;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Why was this changed?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Before we had 1 transport per client = 1 client per request - ergo buffer size of 30 per request. Now we have 1 client for the entire lifetime, which mean more requests per client. Therefore the buffer needs to go up. 256 was a number I set based on the load tests I ran. We can also set it to 100 to mirror the promisbuffer.ts

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hm no it's fine, but maybe a comment explaining how we got to this number would help us in the future.

Comment thread .size-limit.js
@JPeer264

Copy link
Copy Markdown
Member Author

This seems like a lot of extra, hard-to-maintain code that's working around the way client flushing works in our SDKs. Are you sure the perf gains are worth it? I'm a bit concerned, but your call.

It is not just because of the performance gains - but it was indeed one of the motivations (I had this in my head for couple of months already). The main trigger was actually #22545 which is impossible with client disposals, as we would need to keep the client open longer in order to retrieve potential events, which might or might not arrive. This is then a clear OOM case as we only have 128MB on workers

@JPeer264
JPeer264 requested a review from andreiborza August 12, 2026 11:45
@JPeer264
JPeer264 requested review from a team as code owners August 12, 2026 11:58
@JPeer264
JPeer264 requested review from logaretm and removed request for a team August 12, 2026 11:58
Comment thread yarn.lock
JPeer264 and others added 10 commits August 12, 2026 15:41
Building and disposing a client per invocation costs real time on every request, and in
a Durable Object it also loses data: there is no `waitUntil` boundary that dependably
extends execution, so anything captured after the handler returned went to a client that
had already been disposed.

Enabled by default, this caches one client per isolate. The first initialization wins
for the isolate's lifetime: a later init with different options reuses that client, and
a new deployment always starts fresh isolates, so clients are always built from the
current version's options. A cached client is flushed but not disposed at an invocation
boundary, and it is re-bound to the current scope on every invocation — otherwise
`initialScope` would apply only to an isolate's first invocation, and a client disposed
by a competing init would keep being handed out. A cached client whose transport is gone
is evicted rather than returned.

Because a reused client never reaches an end-of-invocation flush, delivery is eager: the
new `afterEnvelope` hook on the core client drains the transport buffer as soon as an
envelope has been accepted, and logs and metrics drain on a debounced hook so they are
batched rather than sent one at a time. Spans that end after the invocation's flush
point are delivered through core's `flushTraceSpans` hook, which flushes only that
trace's bucket from the span streaming buffer. The per-invocation flush lock and span
tracking are skipped, since binding a client that outlives the invocation to one
invocation's lock would make later flushes wait on that invocation's work forever.

A shared client also shares integration state, so dedupe works across invocations: the
same error raised by two separate requests is reported only once.

Uncached behavior is unchanged; pass `cacheClient: false` to restore it.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Andrei <168741329+andreiborza@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants