Skip to content

feat(cloudflare): Add cacheClient to reuse the client across invocations - #23151

Open
JPeer264 wants to merge 14 commits into
developfrom
jp/cacheclient
Open

feat(cloudflare): Add cacheClient to reuse the client across invocations#23151
JPeer264 wants to merge 14 commits into
developfrom
jp/cacheclient

Conversation

@JPeer264

@JPeer264 JPeer264 commented Aug 7, 2026

Copy link
Copy Markdown
Member

closes #23083
closes #22545
closes #21950

What

This PR is reusing the client, instead of creating a new one. This is also only possible because of #22969 (as now we have the correct isolation scopes per request).

To still have an escape hatch and keep the old behavior there is the cacheClient: false option, that just creates a new client per request, as before.

Why

There are more and more issues coming in, that .dispose is leading to errors, which makes sense as in DurableObjects data can flow in after a request happened and it stays alive. Since we created a new client on each request, we also had to clean it up - the best point in time was after a request, which was too early for e.g. #22545. Since there is not a perfect time to dispose the client the only option is to reuse the client and not dispose at all (this is then also aligned with how other SDK machinery works).

Issues and how they're solved

Timing

In CF, timers are usually 0 and therefore our 5 second auto flush wouldn't work. In order to still retrieve all the data we need to have point in times (hooks) where it is safe to flush. In our case we have a request and flush after a request, like before. Events that come in a later point in time are then captured with the hooks added in #23136 (most important one is the afterEnvelope).

We start listening to the hooks once flushPointReached is set to true - which is AFTER a request, the time where we have no control anymore about flushing manually otherwise.

waitUntil

Keeping the correct waitUntil is important, as each request needs its own waitUntil to properly flush. To still keep the correct waitUntil this is now bound onto the scope directly. I tried using setSDKProcessingMetadata on the scope, but it just didn't work properly on deployed workers. Instead this is bound onto the scope directly with a Symbol - that works like a charm. This is the INVOCATION_STATE #namingishard

flushLock

The flush lock would wait for all spans to be finished and then flush. This would just not work, as we only have one client. So we skip this entirely and get rid of that hack. We keep this in order to have the escape hatch cacheClient: false in case something goes sideways.

Bonuses

Bonus 1

Because we are now reusing the client we are saving valuable CPU cycles per request. With cacheClient: true we gain up to ~14-21% per request, which is loads. Also on top of the CPU wins we also retrieve more events, which would have been dropped before.

Bonus 2

In v12 (or any other major) we could get rid of all the flushLock hacks and the rest of hacks we did

Bonus 3

Dedupe integration works now as intended. Because we created a new client and the dedupeIntegration only deduplicated per integration, which was a new one on every client, we only deduped it per request, not for all requests.

Sidenotes

During the implementation I thought about having multiple clients, which are cached in one global map - in case the isolations would get reused from other deployments or other bindings. After some excessive tests it seems that new deployments are getting a fresh isolate, different bindings have their own isolate, only ExportedHandlers and WorkerEntrypoints share one isolate, which makes sense to some degree, as they're isolated within each request anyways (they're getting a fresh isolate on a new deployment though). Because this is the case only one client is being created instead of checking if the config differs between clients.

@JPeer264 JPeer264 self-assigned this Aug 7, 2026
@JPeer264

JPeer264 commented Aug 7, 2026

Copy link
Copy Markdown
Member Author

bugbot run

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 28.57 kB - -
@sentry/browser - with treeshaking flags 26.92 kB - -
@sentry/browser - with treeshaking flags tracing without tracing 26.82 kB - -
@sentry/browser (incl. Tracing) 48.33 kB - -
@sentry/browser (incl. Tracing + Span Streaming) 48.35 kB - -
@sentry/browser (incl. Tracing, Profiling) 51.24 kB - -
@sentry/browser (incl. Tracing, Replay) 87.73 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 77.19 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 92.44 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 105.12 kB - -
@sentry/browser (incl. Feedback) 45.81 kB - -
@sentry/browser (incl. sendFeedback) 33.36 kB - -
@sentry/browser (incl. FeedbackAsync) 38.47 kB - -
@sentry/browser (incl. Metrics) 29.52 kB - -
@sentry/browser (incl. Logs) 29.8 kB - -
@sentry/browser (incl. Metrics & Logs) 30.45 kB - -
@sentry/react 30.33 kB - -
@sentry/react (incl. Tracing) 50.51 kB - -
@sentry/vue 35.4 kB - -
@sentry/vue (incl. Tracing) 50.31 kB - -
@sentry/svelte 28.6 kB - -
CDN Bundle 30.32 kB - -
CDN Bundle (incl. Tracing) 48.87 kB - -
CDN Bundle (incl. Logs, Metrics) 32.54 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 50.74 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 72.91 kB - -
CDN Bundle (incl. Tracing, Replay) 86.33 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 88.16 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 92.07 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 94 kB - -
CDN Bundle - uncompressed 89.94 kB - -
CDN Bundle (incl. Tracing) - uncompressed 146.13 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 96.23 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 151.81 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 225.18 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 265.4 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 271.07 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 279.09 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 284.76 kB - -
@sentry/nextjs (client) 53.05 kB - -
@sentry/sveltekit (client) 48.74 kB - -
@sentry/core/server 64.95 kB - -
@sentry/core/browser 52.11 kB - -
@sentry/node 117.49 kB +0.03% +24 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection) 85.18 kB - -
@sentry/node - without tracing 82.03 kB +0.03% +24 B 🔺
@sentry/aws-serverless 91.46 kB +0.03% +20 B 🔺
@sentry/cloudflare (withSentry) - minified 197.06 kB +1.23% +2.38 kB 🔺
@sentry/cloudflare (withSentry) 489.28 kB +1.66% +7.95 kB 🔺

View base workflow run

Comment thread packages/cloudflare/src/client.ts Outdated
Comment thread packages/cloudflare/src/client.ts
Comment thread packages/cloudflare/src/client.ts Outdated
Comment thread packages/cloudflare/src/client.ts
@JPeer264
JPeer264 force-pushed the jp/cacheclient branch 2 times, most recently from d081c44 to a362f65 Compare August 7, 2026 13:09
@JPeer264

JPeer264 commented Aug 7, 2026

Copy link
Copy Markdown
Member Author

bugbot run

Comment thread packages/cloudflare/src/sdk.ts Outdated
Comment thread packages/cloudflare/src/flush.ts
Comment thread packages/cloudflare/src/client.ts
Comment thread dev-packages/cloudflare-integration-tests/suites/cache-client/test.ts Outdated
@JPeer264
JPeer264 force-pushed the jp/cacheclient branch 2 times, most recently from 8869481 to 0ba7c00 Compare August 7, 2026 14:15
JPeer264 added a commit that referenced this pull request Aug 10, 2026
Adds tests to check if `enableDedupes` is really disabled for workflows

original trigger:
#23151 (comment)

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@JPeer264

Copy link
Copy Markdown
Member Author

bugbot run

Comment thread packages/cloudflare/src/client.ts Outdated
@JPeer264

JPeer264 commented Aug 11, 2026

Copy link
Copy Markdown
Member Author

bugbot approve

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 71b3f5f. Configure here.

@JPeer264
JPeer264 marked this pull request as ready for review August 11, 2026 07:46
@JPeer264
JPeer264 requested a review from a team as a code owner August 11, 2026 07:46
@JPeer264
JPeer264 requested review from andreiborza, isaacs, mydea and nicohrubec and removed request for a team and isaacs August 11, 2026 07:46

@andreiborza andreiborza left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems like a lot of extra, hard-to-maintain code that's working around the way client flushing works in our SDKs. Are you sure the perf gains are worth it? I'm a bit concerned, but your call.

* scope, which is shared by every invocation in the isolate.
*/
export function setInvocationState(scope: Scope, state: InvocationState): void {
(scope as ScopeWithInvocationState)[INVOCATION_STATE] = state;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

m: Let's add a check here to only set this if scope !== getDefaultIsolationScope(), wdyt?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good guard. Added in ed8d910

Comment thread packages/cloudflare/src/baseSdk.ts Outdated
options: CloudflareOptions,
getDefaultIntegrationsImpl: (options: CloudflareOptions) => Integration[],
): CloudflareClient | undefined {
const cacheEnabled = options.cacheClient !== false && Boolean(options.dsn);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

q: Why the check on dsn?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Uff that was a left over from before where I cached multiple clients per isolate. This should be removed

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved in ed948f9

Comment thread packages/cloudflare/src/client.ts Outdated
Comment thread packages/cloudflare/src/client.ts
Comment thread packages/cloudflare/src/client.ts
Comment thread packages/cloudflare/src/client.ts Outdated

// If no more pending spans, resolve the completion promise
if (this._pendingSpans.size === 0 && this._resolveSpanCompletion) {
DEBUG_BUILD && debug.log('[CloudflareClient] All spans completed, resolving promise');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

l: This doesn't seem to add much value to the user, what promise is resolving? I think we prob don't need to log here, wdyt?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Before, per client we needed a way to know WHEN to flush, as there is no timer. The only way to know when to flush is when potentially no spans are open anymore (this was super hacky, but worked somehow - but ofc not for all usecases - this is why we don't rely on it anymore).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sure, but I mean the debug log itself. What would I do with this as a user? 🤔

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah true - I can refine that a little. I change it to

Suggested change
DEBUG_BUILD && debug.log('[CloudflareClient] All spans completed, resolving promise');
DEBUG_BUILD && debug.log('[CloudflareClient] All spans completed, preparing to flush');

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved in ed948f9

Comment thread packages/cloudflare/src/client.ts Outdated
Comment thread packages/cloudflare/src/client.ts Outdated
Comment thread packages/cloudflare/src/transport.ts
Comment thread .size-limit.js Outdated
Comment thread packages/cloudflare/src/client.ts Outdated
@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @nicohrubec — Please review this PR when you get a chance!

@github-actions

Copy link
Copy Markdown
Contributor

👋 @logaretm, @andreiborza, @getsentry/team-javascript-sdks, @getsentry/team-javascript-sdks-framework — Please review this PR when you get a chance!

@github-actions

Copy link
Copy Markdown
Contributor

👋 @mydea, @nicohrubec — Please review this PR when you get a chance!

@github-actions

Copy link
Copy Markdown
Contributor

👋 @logaretm, @andreiborza, @getsentry/team-javascript-sdks, @getsentry/team-javascript-sdks-framework — Please review this PR when you get a chance!

@isaacs isaacs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a pretty big set of changes. I haven't checked the stated perf gains (some kind of benchmark would maybe be good for that?) but the correctness wins in fixing the reported issues would make it worthwhile even if it's a slight perf regression, imo, so as long as it's not making things worse, that's fine.

Re @andreiborza's comment, it is definitely a lot of extra code. The cacheClient: false escape hatch guarantees both delivery pathways live in the tree indefinitely: the flush lock, the span-tracking promise machinery, dispose(), and their tests all stay, and now a second set maintained alongside them. Nothing exercises the false path, so that can potentially rot.

We can delete a lot of the new machinery, though. Some parts are redundant or collapse if the eager drains are gated on flushPointReached the same way span delivery already is. That is imo the highest-value simplification.

Maybe we could either drop the cacheClient: false option now, or file the v12 removal issue and link it from the option's JSDoc so the dual pathway has an expiration date.

We could also push the concept into core, not Cloudflare. The issue is that Client has no notion of an invocation lifetime when it outlives a single request. Vercel Edge and Deno Deploy need the same thing, so a core "delivery scope" could replace InvocationState, the symbol-on-scope trick, and the narrow flushTraceSpans hook. That might be too big for now, but could be a good follow-up PR to simplify things further.

Comment thread packages/cloudflare/src/baseSdk.ts Outdated

const client = initAndBind(CloudflareClient, clientOptions) as CloudflareClient;

if (cacheEnabled && client && options.dsn) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we don't have a DSN, then it looks like this will leak a client and a global console.log instrumentation.

Because we set cacheClient unconditionally on line 120, if options.dsn is falsey here (eg, preview deploys or just a missing env), then:

  • builds a fresh client (nothing is cached),
  • gets isCachedClient === true, so packages/cloudflare/src/flush.ts line 146 skips dispose(),
  • and dispose() is what runs the cleanup callbacks registered by consoleIntegration (packages/core/src/integrations/console.ts line 56), which pushes into the module-local handler list in packages/core/src/instrument/console.ts line 28.

I think we can fix it by either removing the options.dsn check here, or making line 120 be cacheClient: cacheEnabled && !!options.dsn, so that it's setting based on whether the client will actually be cached here.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems like this is also an artifact from my previous cache to have multiple clients per isolate. Now this is trimmed to 1. I'll remove that options.dsn check entirely. Done in: 486b480aee53e538a4c40bc840c1f39008dd8d1b

Comment thread packages/cloudflare/src/baseSdk.ts
Comment thread packages/cloudflare/src/client.ts Outdated
Comment thread packages/cloudflare/src/clientCache.ts
Comment thread packages/cloudflare/src/client.ts Outdated
Comment thread dev-packages/cloudflare-integration-tests/suites/cache-client/test.ts Outdated
Comment thread packages/cloudflare/src/client.ts
Comment thread packages/cloudflare/src/transport.ts
Base automatically changed from jp/cacheclient-add-hooks to develop August 24, 2026 13:01
JPeer264 and others added 13 commits August 24, 2026 16:25
Building and disposing a client per invocation costs real time on every request, and in
a Durable Object it also loses data: there is no `waitUntil` boundary that dependably
extends execution, so anything captured after the handler returned went to a client that
had already been disposed.

Enabled by default, this caches one client per isolate. The first initialization wins
for the isolate's lifetime: a later init with different options reuses that client, and
a new deployment always starts fresh isolates, so clients are always built from the
current version's options. A cached client is flushed but not disposed at an invocation
boundary, and it is re-bound to the current scope on every invocation — otherwise
`initialScope` would apply only to an isolate's first invocation, and a client disposed
by a competing init would keep being handed out. A cached client whose transport is gone
is evicted rather than returned.

Because a reused client never reaches an end-of-invocation flush, delivery is eager: the
new `afterEnvelope` hook on the core client drains the transport buffer as soon as an
envelope has been accepted, and logs and metrics drain on a debounced hook so they are
batched rather than sent one at a time. Spans that end after the invocation's flush
point are delivered through core's `flushTraceSpans` hook, which flushes only that
trace's bucket from the span streaming buffer. The per-invocation flush lock and span
tracking are skipped, since binding a client that outlives the invocation to one
invocation's lock would make later flushes wait on that invocation's work forever.

A shared client also shares integration state, so dedupe works across invocations: the
same error raised by two separate requests is reported only once.

Uncached behavior is unchanged; pass `cacheClient: false` to restore it.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Andrei <168741329+andreiborza@users.noreply.github.com>
Comment on lines +146 to +150
this._inBoundaryFlush = true;
try {
return await super.flush(timeout);
} finally {
this._inBoundaryFlush = false;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Concurrent calls to flush() can cause a race condition with the shared _inBoundaryFlush flag, leading to incorrect eager envelope delivery.
Severity: MEDIUM

Suggested Fix

Replace the boolean _inBoundaryFlush flag with a more robust concurrency control mechanism, such as a counter that is incremented upon entering the flush operation and decremented in the finally block. The check should then be based on whether the counter is greater than zero.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.

Location: packages/cloudflare/src/client.ts#L146-L150

Potential issue: A race condition exists in the `flush()` method due to the shared
`_inBoundaryFlush` flag. In a concurrent environment, two requests can call `flush()` on
the same client instance. One request can complete its `await super.flush(timeout)` and
execute its `finally` block, setting `_inBoundaryFlush` to `false`. This can happen
while a second request is still awaiting its own `super.flush()`. If an `afterEnvelope`
event fires for the second request during this time, it will incorrectly see
`_inBoundaryFlush` as `false` and trigger eager envelope delivery when it should be
suppressed, as a flush is still in progress for that request's context.

@JPeer264

Copy link
Copy Markdown
Member Author

We can delete a lot of the new machinery, though. Some parts are redundant or collapse if the eager drains are gated on flushPointReached the same way span delivery already is. That is imo the highest-value simplification.

And that was true, a lot of extra machinery is gone now thanks to you 👍

Maybe we could either drop the cacheClient: false option now, or file the v12 removal issue and link it from the option's JSDoc so the dual pathway has an expiration date.

I'll create a ticket once this lands. Goal is for now to just have an escape hatch in case something goes totally south.

We could also push the concept into core, not Cloudflare. The issue is that Client has no notion of an invocation lifetime when it outlives a single request. Vercel Edge and Deno Deploy need the same thing, so a core "delivery scope" could replace InvocationState, the symbol-on-scope trick, and the narrow flushTraceSpans hook. That might be too big for now, but could be a good follow-up PR to simplify things further.

Is that true for Vercel Edge and Deno Deploy? As everything which happens here is mostly because timers are usually 0 - otherwise we could use the client almost as is (and ofc the waitUntil which is bound to requests). Not sure if this is then really true for the other two.

@JPeer264
JPeer264 requested a review from isaacs August 24, 2026 13:38
Comment on lines 186 to 188
// life. Mirrors the same reset in the Node client.
_INTERNAL_clearAiProviderSkips();
super._setupIntegrations();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: With client caching, AI provider skips from one request incorrectly persist and affect subsequent requests, as the _INTERNAL_clearAiProviderSkips() cleanup function is no longer called per-request.
Severity: HIGH

Suggested Fix

Ensure that the _INTERNAL_clearAiProviderSkips() function is called at the beginning of each request, even when a cached client is being used. This might involve invoking it from a different part of the request lifecycle that runs for every request, regardless of client caching.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.

Location: packages/cloudflare/src/client.ts#L186-L188

Potential issue: With client caching enabled by default (`cacheClient: true`), the
`init()` and `_setupIntegrations()` methods are not called when a cached client is
reused. This prevents `_INTERNAL_clearAiProviderSkips()` from running on subsequent
requests. As a result, if a higher-level integration marks an AI provider to be skipped
in one request, that provider will remain skipped for all future requests in the same
isolate that use the cached client. This leads to the incorrect suppression of
`env.AI.run` spans, causing a loss of monitoring data.

@isaacs

isaacs commented Aug 24, 2026

Copy link
Copy Markdown
Member

Is that true for Vercel Edge and Deno Deploy? As everything which happens here is mostly because timers are usually 0 - otherwise we could use the client almost as is (and ofc the waitUntil which is bound to requests). Not sure if this is then really true for the other two.

Oh, I might've overstated this then, because I'm not sure about their timer behavior. I think that might be a cf-only behavior, actually. Probably not worth doing now, in any event, but might be good to keep in mind as a possible DRY fix if we do need to duplicate the logic in those runtimes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

3 participants