Documentation

From a built directory to a cached, integrity-checked URL in three steps. Everything is addressed by version, and nothing is ever overwritten.

I.Publish a release

Install the coast command-line tool, point it at a build directory and name a version. Every file lands on an immutable path.

# one-time
npm install --global @coast/cli

# publish ./dist as sundial@2.8.1
coast publish ./dist --pkg sundial --version 2.8.1

Files become available at https://cdncoast.com/v/sundial/2.8.1/<file>. Packages already on the npm registry are mirrored automatically; the same path scheme applies.

II.Link with integrity

Each response carries its digest in the Digest header, and coast publish prints the matching integrity value. Add it, along with crossorigin, and the browser verifies every byte.

<link rel="stylesheet"
  href="https://cdncoast.com/v/sundial/2.8.1/sundial.css"
  integrity="sha384-bTzLWKeTUM1y9mj88fJrCDI7FZeGWc6drumahLEjwpC8GmvntHK2wqYY9BeSX2Eb"
  crossorigin="anonymous">
The digest above is illustrative; use the value printed at publish time.

III.Let it cache

Versioned paths are returned with Cache-Control: public, max-age=31536000, immutable. Browsers and edges keep them for a year; a new version means a new URL, never a purge.

$ curl -sI https://cdncoast.com/v/sundial/2.8.1/sundial.min.js
HTTP/2 200
content-type: text/javascript; charset=utf-8
cache-control: public, max-age=31536000, immutable
access-control-allow-origin: *
content-encoding: br
x-coast-pop: lis1
x-coast-cache: HIT
Need a moving pointer such as latest? Use a channel alias. It answers with a 302 to the current immutable path and is cached for 60 seconds, so your HTML stays stable while releases roll forward.

Cache behaviour at a glance

Path shapeCache-ControlEdge TTL
/v/<pkg>/<semver>/…immutable, 1 yearuntil evicted
/a/<pkg>/<channel> (alias)max-age=6060 s
/m/<pkg>/<semver>.json (manifest)immutable, 1 yearuntil evicted
unknown pathno-store—

Good to know

Responses send Access-Control-Allow-Origin: * so modules, fonts and WASM load cross-origin. Brotli is served to clients that advertise it, gzip otherwise. Individual files are capped at 20 MB, and a single release at 250 MB.

See where the edges are →