存储 CDN
上传到 Supabase Storage 的所有资源都会被缓存在内容分发网络(CDN)上,以提高全球用户的访问速度。CDN 是一组地理上分布的服务器或节点,用来缓存来自源服务器的内容。对于 Supabase Storage 来说,源就是运行在与你的项目相同区域的存储服务器。除了提升性能之外,CDN 还能通过减轻分布式拒绝服务(DDoS)和其他应用攻击来增强安全性和可用性。
🌐 All assets uploaded to Supabase Storage are cached on a Content Delivery Network (CDN) to improve the latency for users all around the world. CDNs are a geographically distributed set of servers or nodes which cache content from an origin server. For Supabase Storage, the origin is the storage server running in the same region as your project. Aside from performance, CDNs also help with security and availability by mitigating Distributed Denial of Service (DDoS) and other application attacks.
示例 #
🌐 Example
下面的例子展示了CDN如何帮助提升性能。
🌐 The following example shows how a CDN helps with performance.
为在新加坡启动的 Supabase 项目创建了一个新桶。所有对 Supabase 存储 API 的请求都会先路由到 CDN。
🌐 A new bucket is created for a Supabase project launched in Singapore. All requests to the Supabase Storage API are routed to the CDN first.
一个来自美国的用户请求一个对象,并被路由到美国的 CDN。这时,该 CDN 节点的缓存中没有这个对象,会向位于新加坡的源服务器发送请求。

🌐 A user from the United States requests an object and is routed to the U.S. CDN. At this point, that CDN node does not have the object in its cache and pings the origin server in Singapore.

另一个用户,也在美国,请求同样的对象,并直接从美国的 CDN 缓存中获取,而不是将请求路由回新加坡。

🌐 Another user, also in the United States, requests the same object and is served directly from the CDN cache in the United States instead of routing the request back to Singapore.

请注意,如果某个对象在特定区域长时间没有被请求,CDN 仍然可能会将其从缓存中移除。例如,如果没有美国的用户请求你的对象,即使我们设置了很长的缓存控制时间,它也会从 CDN 缓存中删除。
🌐 Note that CDNs might still evict your object from their cache if it has not been requested for a while from a specific region. For example, if no user from United States requests your object, it will be removed from the CDN cache even if we set a very long cache control duration.
某个请求的缓存状态会通过 cf-cache-status 头发送。缓存状态为 MISS 表示 CDN 节点缓存中没有该对象,需要向源服务器获取。缓存状态为 HIT 表示对象是直接从 CDN 发送的。
🌐 The cache status of a particular request is sent in the cf-cache-status header. A cache status of MISS indicates that the CDN node did not have the object in its cache and had to ping the origin to get it. A cache status of HIT indicates that the object was sent directly from the CDN.
公共桶与私有桶 #
🌐 Public vs private buckets
公共桶中的对象不需要任何授权就可以访问。这比私有桶有更好的缓存命中率。
🌐 Objects in public buckets do not require any authorization to access objects. This leads to a better cache hit rate compared to private buckets.
对于私有桶,每个对象的访问权限会按用户单独检查。比如,如果两个不同的用户从同一个区域访问私有桶里的同一个对象,由于他们可能附有不同的安全策略,会导致两个人都出现缓存未命中。另一方面,如果两个不同的用户从同一个区域访问公共桶里的同一个对象,第二个用户就会命中缓存。
🌐 For private buckets, permissions for accessing each object is checked on a per user level. For example, if two different users access the same object in a private bucket from the same region, it results in a cache miss for both the users since they might have different security policies attached to them. On the other hand, if two different users access the same object in a public bucket from the same region, it results in a cache hit for the second user.