Bazel remote cache
A Bazel remote cache, with no server to run
Point Bazel's --remote_cache at a CloudRepo repository. CI uploads action results and outputs, and any machine with a token can reuse them instead of running those actions again. No bazel-remote to deploy and no bucket to manage.
.bazelrc
build --remote_cache=https://[org-id].mycloudrepo.io/repositories/[repo-name]
build --credential_helper=[org-id].mycloudrepo.io=%workspace%/tools/cloudrepo-credential-helper.sh Set it up
Tested with Bazel 8.4.2. The full guide is in the documentation.
- 1
Create a repository for the cache
Create a Maven repository that holds only the cache, then turn Overwrite Protection off on it. A new repository refuses a second upload of a key it already holds with 409 Conflict, and Bazel sends such uploads whenever two actions produce the same bytes. Bazel then logs a warning and does not store that action’s result, so the action misses in every later build, while the build still succeeds. With Overwrite Protection off, the repeated upload is accepted.
- 2
Create two repository tokens
A Read + write token for CI, which fills the cache, and a Read only token for developer machines, which only read it. An upload with a read-only token is refused with 403 Forbidden. The username is the email address of the account that created the token, and the password is the token.
- 3
Add two lines to .bazelrc
Bazel speaks its HTTP cache protocol to the repository over HTTPS. The second line hands Bazel a credential helper for your CloudRepo host only.
.bazelrc
build --remote_cache=https://[org-id].mycloudrepo.io/repositories/[repo-name] build --credential_helper=[org-id].mycloudrepo.io=%workspace%/tools/cloudrepo-credential-helper.sh - 4
Save the credential helper
Save it as tools/cloudrepo-credential-helper.sh in the workspace and make it executable. It reads the username and token from CLOUDREPO_USERNAME and CLOUDREPO_TOKEN.
tools/cloudrepo-credential-helper.sh
#!/bin/sh # Bazel credential helper for CloudRepo. Bazel writes a request on stdin; this answers with a # Basic Authorization header built from two environment variables. cat > /dev/null printf '{"headers":{"Authorization":["Basic %s"]}}\n' \ "$(printf '%s:%s' "$CLOUDREPO_USERNAME" "$CLOUDREPO_TOKEN" | base64 | tr -d '\n')" - 5
Turn uploads off on developer machines
Add this line to your own ~/.bazelrc. Bazel then reads from the cache and uploads nothing.
~/.bazelrc
build --remote_upload_local_results=false
Frequently asked questions
- Can a CloudRepo repository be my Bazel remote cache?
- Yes. A hosted Maven repository with Overwrite Protection turned off stores what Bazel uploads under /ac/ and /cas/ and returns it byte for byte, so a later build in a fresh output base, on any machine with a token, restores those actions from the remote cache.
- I run bazel-remote, or a cache in front of an S3 bucket. What changes?
- You stop running it. CloudRepo serves the same HTTP cache paths Bazel already uses, so moving is a new --remote_cache URL and a credential helper, with no cache server or bucket of your own to keep up.
- Why scope the credential helper to my host?
- A helper with no host in front of it answers for every host Bazel contacts, including module registries such as bcr.bazel.build, and would hand each of them your token. The [org-id].mycloudrepo.io= prefix limits it to your CloudRepo host.
- Does CloudRepo run my actions?
- No. It is a remote cache, not remote execution: Bazel still runs actions on your machines and CI, and uploads and reuses their results through the repository.
- Do cache entries expire?
- No. Entries are kept until you delete them: nothing expires them today. They count toward your plan’s storage like any other file.
- Does cache traffic count toward my plan?
- Yes. Cache uploads and downloads count toward your plan’s monthly transfer allowance. If you exceed your monthly transfer allowance, we reach out first. Nothing is throttled, no build ever stops, and there are no automatic charges. Occasional spikes are simply fine. Sustained overage is billed at $120 per additional TB, always rounded down in your favor (2.9 TB over = 2 TB billed = $240). Storage growth is a prorated one-click plan upgrade, not per-GB fees.
Put your Bazel remote cache on CloudRepo
Create the cache repository, two tokens, two .bazelrc lines and one helper script.