Storage
A cache tier serves the cache from object storage in the deployment’s account: S3 Express on AWS, Cloud Storage on GCP.- Capacity follows the bucket. There are no disks to size or shards to rebalance; you size the tier’s throughput, as a fixed size or scaling between bounds you set.
- Retention is yours to set. Longer retention raises the hit rate on rarely-touched targets and stores more bytes.
- Data stays in the account. Self-hosted, the bucket is in your AWS account or GCP project, under your policies.
Data transfer
CI runners and remote execution workers reach the cache on the deployment’s private network, so the traffic between them, the bulk of a build’s bytes, never crosses the internet and keeps cloud data transfer charges to a minimum. That’s why we recommend running CI on the deployment’s own runners.The external endpoint
Developer machines, and CI you run outside the deployment, reach the cache and remote execution through the external endpoint,remote.<your-domain>, over the internet. Clients sign in through the deployment’s identity provider with , which also serves Bazel’s credential helper. The endpoint runs in one of two modes:
In the shared mode, developers set
--noremote_upload_local_results so their machines don’t upload results of actions they run locally; results of remotely executed actions are written by the workers. See who writes to the cache.
Networks that can’t reach the internet use a private endpoint (AWS PrivateLink or GCP Private Service Connect) or, self-hosted, VPC peering or your VPN. See network topology.
