All Products
Search
Document Center

Edge Security Acceleration:CreateCacheRule

Last Updated:Jun 25, 2026

Creates a cache rule for a site.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

esa:CreateCacheRule

create

*Site

acs:esa:{#regionId}:{#accountId}:site/{#SiteId}

None None

Request parameters

Parameter

Type

Required

Description

Example

SiteId

integer

Yes

Site ID. Call ListSites to obtain this ID.

340035003106221

SiteVersion

integer

No

Site configuration version. For sites with version management enabled, specifies which version this configuration applies to.

1

RuleName

string

No

Rule name. Not required for global configurations.

rule_example

RuleEnable

string

No

Whether to enable the rule. Not required for global configurations. Valid values:

  • on: Enables the rule.

  • off: Disables the rule.

on

Rule

string

No

Rule content, a conditional expression that matches user requests. Not required for global configurations.

  • To match all requests, set the value to true.

  • To match specific requests, set the value to a custom expression, such as (http.host eq "video.example.com").

(http.host eq \"video.example.com\")

BypassCache

string

No

Bypass cache mode. Valid values:

  • cache_all: Caches all requests.

  • bypass_all: Bypasses the cache for all requests.

cache_all

BrowserCacheMode

string

No

Browser cache mode. Valid values:

  • no_cache: Disables browser caching.

  • follow_origin: Follows the origin server cache policy.

  • override_origin: Overrides the origin server cache policy.

follow_origin

BrowserCacheTtl

string

No

Browser cache TTL in seconds.

300

EdgeCacheMode

string

No

Edge cache mode. Valid values:

  • follow_origin: Follows origin cache policy if present; otherwise uses default cache policy.

  • no_cache: Disables caching on the edge node.

  • override_origin: Overrides the origin server cache policy.

  • follow_origin_bypass: Follows origin cache policy if present; otherwise does not cache.

  • follow_origin_override: Follows origin cache policy if present; otherwise uses custom edge cache TTL.

follow_origin

EdgeCacheTtl

string

No

Edge cache TTL in seconds.

300

EdgeStatusCodeCacheTtl

string

No

Status code cache TTL in seconds.

  • Set cache TTL for a specific status code. Example: 404=10 caches 404 responses for 10 seconds.

  • Set cache TTL for a status code series (4xx, 5xx). Example: 4xx=10 caches all 4xx responses for 10 seconds.

  • Specify multiple status code TTLs separated by commas (,).

5xx=0,404=10

SortQueryStringForCache

string

No

Whether to sort query strings. Disabled by default. Valid values:

  • on: Enables sorting.

  • off: Disables sorting.

on

QueryStringMode

string

No

Query string processing mode for cache key generation. Valid values:

  • ignore_all: Ignores all query strings.

  • exclude_query_string: Excludes specified query strings.

  • reserve_all: Includes all query strings (the default).

  • include_query_string: Includes only specified query strings.

reserve_all

QueryString

string

No

Query strings to include or exclude from the cache key. Separate multiple values with spaces.

example

IncludeHeader

string

No

Headers to include in the cache key. Both names (case-insensitive) and values are included. Separate multiple names with spaces. Allowed characters:

  • Symbols: ! # $ % & ' * + - . ^ _ | ~

  • Digits: 0-9

  • Letters: a-z (lowercase)

headername1 headername2

IncludeCookie

string

No

Cookies to include in the cache key. Both names (case-insensitive) and values are included. Separate multiple names with spaces. Allowed characters:

  • Symbols: ! # $ % & ' * + - . ^ _ | ~

  • Digits: 0-9

  • Letters: a-z (lowercase)

cookiename1 cookiename2

CacheReserveEligibility

string

No

Whether requests bypass cache reservation nodes during origin fetch. Valid values:

  • bypass_cache_reserve: The request bypasses cache reservation.

  • eligible_for_cache_reserve: The request is eligible for cache reservation.

bypass_cache_reserve

CheckPresenceHeader

string

No

Headers checked for presence in the cache key. If a listed header exists, its name (case-insensitive) is added to the key. Separate names with spaces. Allowed characters:

  • Symbols: ! # $ % & ' * + - . ^ _ | ~

  • Digits: 0-9

  • Letters: a-z (lowercase)

headername1 headername2

CheckPresenceCookie

string

No

Cookies checked for presence in the cache key. If a listed cookie exists, its name (case-insensitive) is added to the key. Separate names with spaces. Allowed characters:

  • Symbols: ! # $ % & ' * + - . ^ _ | ~

  • Digits: 0-9

  • Letters: a-z (lowercase)

cookiename1 cookiename2

UserDeviceType

string

No

Whether to include client device type in the cache key. Valid values:

  • on: Includes the client device type.

  • off: Does not include the client device type.

on

UserGeo

string

No

Whether to include client geographic location in the cache key. Valid values:

  • on: Includes the geographic location.

  • off: Does not include the geographic location.

on

UserLanguage

string

No

Whether to include client language in the cache key. Valid values:

  • on: Includes the language.

  • off: Does not include the language.

on

ServeStale

string

No

Whether to serve stale content. When enabled, edge nodes serve expired cached content if the origin is unavailable. Valid values:

  • on: Enables serving stale content.

  • off: Disables serving stale content.

on

AdditionalCacheablePorts

string

No

  • Specifies additional ports on which caching is enabled.

  • Valid values: 8880, 2052, 2082, 2086, 2095, 2053, 2083, 2087, and 2096.

  • Specify multiple ports separated by commas (,).

8880,2052,2086

CacheDeceptionArmor

string

No

Whether to enable cache deception defense. When enabled, only validated content is cached. Valid values:

  • on: Enables the defense.

  • off: Disables the defense.

on

Sequence

integer

No

Rule execution order. Lower values indicate higher priority.

1

PostCache

string

No

Whether to enable POST request caching.

on

PostBodySizeLimit

string

No

Maximum request body size for POST caching, in KB. Valid values: 1 to 8. Default: 8 KB.

1

PostBodyCacheKey

string

No

How to process the request body when generating a cache key for POST requests. Valid values:

  • md5: Calculates the MD5 hash of the request body and adds the hash value to the cache key.

  • ignore: Ignores the request body when the cache key is generated.

ignore

Response elements

Element

Type

Description

Example

object

Response object.

RequestId

string

Request ID.

04F0F334-1335-436C-A1D7-6C044FE73368

ConfigId

integer

Configuration ID.

352816096987136

Examples

Success response

JSON format

{
  "RequestId": "04F0F334-1335-436C-A1D7-6C044FE73368\n",
  "ConfigId": 352816096987136
}

Error codes

HTTP status code

Error code

Error message

Description

400 MissingParameter The specified ArgName is required for this function. A required parameter is missing for the specified function.
400 CanNotSetSequence Non-regular configuration, you cannot set Sequence parameters. Sequence parameter is not allowed in global configuration.
400 CacheReserveSiteExceedLimit The number of binding sites of the cache reserve instance exceeds the limit. The number of binding sites of a single cache reserve instance is limited. Please see the document for the limit. The number of sites bound to the cache reserve instance exceeds the limit.
400 CompileRuleError Rule compilation failed, please check the rule information passed in to ensure that the rule is written according to the syntax described in the document. Rule compilation failed. Verify that the rule follows the syntax described in the API documentation.
400 SiteConfigLengthExceedLimit The overall configuration size of the site exceeds the limit, and the total size of all functional configurations of the site cannot exceed 512K. The total site configuration size exceeds the 512 KB limit.
400 ConfigConflicts Configuration conflicts, usually when multiple configurations are configured under the same function of the same site, such as duplicate rule names between multiple configurations. The parameter uniqueness check failed. Check for duplicate parameter values.
400 FunctionConflict The feature configuration conflicts. Sites with version management enabled cannot configure this feature. The configured feature conflicts with other features. Delete the conflicting configurations first.
400 RuleRegexQuotaCheckFailed When configuring rules, rules with regular expressions are not allowed in this plan. Please check the relevant documentation of the plan or upgrade the plan. The current plan does not support regex rules. Check the plan description or upgrade your plan.
400 NestedRuleQuotaCheckFailed The nesting level of rules allowed by the plan failed to be verified. Please modify the nesting level of rules or upgrade the plan. The number of nested sub-conditions in the rule exceeds the plan limit. Check the plan description or upgrade your plan.
400 ArgQuotaCheckFailed The passed-in parameter value failed to verify the validity of the plan. Please check the plan document to obtain the range of parameters that can be configured for the site plan. The current plan does not support the specified restricted parameters. Check the input parameters.
400 FunctionQuotaCheckFailed The quota verification for this function fails. It may be that the configuration of this function exceeds the limit of the site plan. Please check the plan introduction document corresponding to this site. The current plan does not support the specified feature. Check the plan description.
400 ConfExceedLimit The number of function configurations exceeds the limit. Please check the interface document to see the number of configurations that can be supported by a single function. The number of configurations for this feature exceeds the system limit.
400 ServiceInvokeFailed The call to the internal service failed. The engineer is resolving the problem. Please wait a moment before trying, or contact customer service for details. Failed to call the service. Try again later or contact customer service.
400 SpecifiedVersionReadOnly The specified version number is read-only and cannot be modified. The specified version number is read-only and cannot be modified.
400 VersionNotValid The site does not have version management enabled, or the version number passed in does not exist. The site does not have version management enabled, or the version number passed in does not exist.
400 InternalException Failed to call the service. Try again later or contact technical support. Failed to call the service. Try again later or contact technical support.
400 InvalidParameter.ArgName Invalid ArgName. Check your website configuration parameters and make sure that they match the supported features and parameter names listed in the official documentation. Invalid ArgName. Check your website configuration parameters and make sure that they match the supported features and parameter names listed in the official documentation.
400 InvalidParameter.ArgValue Invalid parameter value. Check whether the value format and length meet the requirements. Invalid parameter value. Check whether the value format and length meet the requirements.
400 InvalidParameter.Configs Invalid parameter configurations. Check whether your feature configurations are in the valid format and comply with relevant requirements. Invalid parameter configurations. Check whether your feature configurations are in the valid format and comply with relevant requirements.
400 InstanceNotExist The instance does not exist. Check whether the specified instance ID is correct or whether the instance belongs to your account. The instance does not exist. Check whether the specified instance ID is correct or whether the instance belongs to your account.
400 LockFailed The system is handling requests you previously submitted. Try again later. The system is handling requests you previously submitted. Try again later.
400 Instance.NotOnline Your plan is unavailable due to an overdue payment. Complete the payment first. Your plan is unavailable due to an overdue payment. Complete the payment first.
400 IllegalOperation.VersionManagement The version management operation failed because incompatible features or environment settings are configured. Adjust your configurations and try again. The version management operation failed because incompatible features or environment settings are configured. Adjust your configurations and try again.
400 QuotaCheckFailed.VersionManagement Insufficient quota for version management. Contact technical support. Insufficient quota for version management. Contact technical support.
400 FunctionArgError Failed to check the configured function parameters. Failed to check the configured function parameters
404 SiteNotFound The website does not exist or does not belong to you. The website does not exist or does not belong to you.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.