All Products
Search
Document Center

Edge Security Acceleration:UpdateCacheRule

Last Updated:Jun 25, 2026

Modifies a cache rule for a website.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

esa:UpdateCacheRule

update

*Site

acs:esa:{#regionId}:{#accountId}:site/{#SiteId}

None None

Request parameters

Parameter

Type

Required

Description

Example

SiteId

integer

Yes

The ID of the site. To get this ID, call the ListSites operation.

123456****

ConfigId

integer

Yes

The configuration ID.

35281609698****

RuleName

string

No

The rule name. Optional for global configurations.

rule_example

RuleEnable

string

No

Specifies whether to enable the rule. Optional for global configurations. Valid values:

  • on: Enables the rule.

  • off: Disables the rule.

on

Rule

string

No

A conditional expression that matches user requests. Optional for global configurations. Two scenarios are supported:

  • To match all incoming requests, set the value to true.

  • To match specific requests, set the value to a custom expression, for example, (http.host eq "video.example.com").

(http.host eq \"video.example.com\")

BypassCache

string

No

The cache bypass mode. Valid values:

  • cache_all: Caches all requests.

  • bypass_all: Bypasses the cache for all requests.

cache_all

BrowserCacheMode

string

No

The browser cache mode. Valid values:

  • no_cache: Does not cache content in the browser.

  • follow_origin: Follows the caching policy of the origin server.

  • override_origin: Overrides the caching policy of the origin server.

no_cache

BrowserCacheTtl

string

No

The browser cache TTL (Time to Live), in seconds.

300

EdgeCacheMode

string

No

The cache mode for the edge node. Valid values:

  • follow_origin: Follows the origin server's caching policy. If the origin server has no policy, the default policy is used.

  • no_cache: Does not cache content.

  • override_origin: Overrides the caching policy of the origin server.

  • follow_origin_bypass: Follows the caching policy of the origin server, if one exists. Otherwise, content is not cached.

  • follow_origin_override: Follows the caching policy of the origin server, if one exists. Otherwise, a custom cache TTL is used.

follow_origin

EdgeCacheTtl

string

No

The edge node cache TTL (Time to Live), in seconds.

300

EdgeStatusCodeCacheTtl

string

No

The cache TTL for specific status codes, in seconds.

  • You can set the cache TTL for a specific status code. For example, 404=10 caches responses with a 404 status code for 10 seconds.

  • You can set the cache TTL for 4xx and 5xx status code ranges. For example, 4xx=10 caches all responses with a 4xx status code for 10 seconds.

  • Separate multiple status code settings with commas.

5xx=0,404=10

SortQueryStringForCache

string

No

Specifies whether to sort query string parameters when generating the cache key. Valid values:

  • on: Enables sorting.

  • off: Disables sorting.

on

QueryStringMode

string

No

Specifies how query strings are used to generate the cache key. Valid values:

  • ignore_all: Ignores all query strings.

  • exclude_query_string: Removes specified query strings.

  • reserve_all: Retains all query strings. This is the default value.

  • include_query_string: Retains only specified query strings.

ignore_all

QueryString

string

No

The query string parameters to include in or exclude from the cache key. Separate multiple parameters with spaces.

example1 example2

IncludeHeader

string

No

The headers to include in the cache key. Both the header names (case-insensitive) and their values are used. Separate multiple headers with spaces. Header names can contain the following characters:

  • Symbols: ! # $ % & ' * + - . ^ _ | ~

  • Digits: 0-9

  • Lowercase letters: a-z

headername1 headername2

IncludeCookie

string

No

The cookies to include in the cache key. Both the cookie names (case-insensitive) and their values are used. Separate multiple cookies with spaces. Cookie names can contain the following characters:

  • Symbols: ! # $ % & ' * + - . ^ _ | ~

  • Digits: 0-9

  • Lowercase letters: a-z

cookiename1 cookiename2

CacheReserveEligibility

string

No

Specifies whether requests bypass the cache reserve node during an origin-pull. Valid values:

  • bypass_cache_reserve: The request bypasses the cache reserve.

  • eligible_for_cache_reserve: The request is eligible for cache reserve.

bypass_cache_reserve

CheckPresenceHeader

string

No

The headers to check for. If a specified header is present in the request, its name (case-insensitive) is added to the cache key. Separate multiple headers with spaces. Header names can contain the following characters:

  • Symbols: ! # $ % & ' * + - . ^ _ | ~

  • Digits: 0-9

  • Lowercase letters: a-z

headername1 headername2

CheckPresenceCookie

string

No

The cookies to check for. If a specified cookie is present in the request, its name (case-insensitive) is added to the cache key. Separate multiple cookies with spaces. Cookie names can contain the following characters:

  • Symbols: ! # $ % & ' * + - . ^ _ | ~

  • Digits: 0-9

  • Lowercase letters: a-z

cookiename1 cookiename2

UserDeviceType

string

No

Specifies whether to include the client device type in the cache key. Valid values:

  • on: Enables this feature.

  • off: Disables this feature.

on

UserGeo

string

No

Specifies whether to include the client geographic location in the cache key. Valid values:

  • on: Enables this feature.

  • off: Disables this feature.

on

UserLanguage

string

No

Specifies whether to include the client language in the cache key. Valid values:

  • on: Enables this feature.

  • off: Disables this feature.

on

ServeStale

string

No

Specifies whether to serve stale content. If enabled, an edge node serves expired cached content when the origin server is unavailable. Valid values:

  • on: Enables this feature.

  • off: Disables this feature.

on

AdditionalCacheablePorts

string

No

  • Enables caching on the specified ports.

  • Valid values: 8880, 2052, 2082, 2086, 2095, 2053, 2083, 2087, 2096

  • Separate multiple ports with commas.

8880,2052,2086

CacheDeceptionArmor

string

No

Defends against Web Cache Deception attacks by caching only validated content. Valid values:

  • on: Enables the feature.

  • off: Disables the feature.

on

Sequence

integer

No

The execution priority of the rule. A smaller value indicates a higher priority.

1

PostCache

string

No

Specifies whether to cache responses to POST requests.

on

PostBodySizeLimit

string

No

The maximum request body size for POST caching, in KB. Valid values: 1 to 8. Default value: 8.

1

PostBodyCacheKey

string

No

Specifies how the request body is used to generate the cache key for POST requests. Valid values:

  • md5: Calculates the MD5 hash of the request body and includes the hash in the cache key.

  • ignore: Ignores the request body when generating the cache key.

ignore

Response elements

Element

Type

Description

Example

object

The response data.

RequestId

string

The request ID.

36af3fcc-43d0-441c-86b1-428951dc8225

Examples

Success response

JSON format

{
  "RequestId": "36af3fcc-43d0-441c-86b1-428951dc8225"
}

Error codes

HTTP status code

Error code

Error message

Description

400 CanNotSetSequence Non-regular configuration, you cannot set Sequence parameters. Sequence parameters is not allowed in global configuration.
400 CacheReserveSiteExceedLimit The number of binding sites of the cache reserve instance exceeds the limit. The number of binding sites of a single cache reserve instance is limited. Please see the document for the limit. The number of sites for which the cache reserve instance bindings exceeds the limit.
400 CompileRuleError Rule compilation failed, please check the rule information passed in to ensure that the rule is written according to the syntax described in the document. Rule compilation failed. Check the incoming rule configuration. For details, see the rule configuration format described in the interface document.
400 SiteConfigLengthExceedLimit The overall configuration size of the site exceeds the limit, and the total size of all functional configurations of the site cannot exceed 512K. The size of the site configuration exceeds the limit, and the total size cannot exceed 512K.
400 ConfigConflicts Configuration conflicts, usually when multiple configurations are configured under the same function of the same site, such as duplicate rule names between multiple configurations. The parameter uniqueness check failed. Check for duplicate parameter values.
400 RuleRegexQuotaCheckFailed When configuring rules, rules with regular expressions are not allowed in this plan. Please check the relevant documentation of the plan or upgrade the plan. The current plan does not support the configuration of a rule engine with a regular expression. Please check the plan description and upgrade your plan.
400 NestedRuleQuotaCheckFailed The nesting level of rules allowed by the plan failed to be verified. Please modify the nesting level of rules or upgrade the plan. The number of embedded sub-conditions in the rule exceeds the plan limit. Please check the plan description and upgrade your plan.
400 ServiceInvokeFailed The call to the internal service failed. The engineer is resolving the problem. Please wait a moment before trying, or contact customer service for details. Failed to call the service. Please try again later or contact customer service for details.
400 FunctionConflict The feature configuration conflicts. Sites with version management enabled cannot configure this feature. The currently configured function conflicts with other functions. If you need to configure, delete the conflicting function configurations first.
400 SpecifiedVersionReadOnly The specified version number is read-only and cannot be modified. The specified version number is read-only and cannot be modified.
400 VersionNotValid The site does not have version management enabled, or the version number passed in does not exist. The site does not have version management enabled, or the version number passed in does not exist.
400 InternalException Failed to call the service. Try again later or contact technical support. Failed to call the service. Try again later or contact technical support.
400 InvalidParameter.ArgName Invalid ArgName. Check your website configuration parameters and make sure that they match the supported features and parameter names listed in the official documentation. Invalid ArgName. Check your website configuration parameters and make sure that they match the supported features and parameter names listed in the official documentation.
400 InvalidParameter.ArgValue Invalid parameter value. Check whether the value format and length meet the requirements. Invalid parameter value. Check whether the value format and length meet the requirements.
400 InvalidParameter.Configs Invalid parameter configurations. Check whether your feature configurations are in the valid format and comply with relevant requirements. Invalid parameter configurations. Check whether your feature configurations are in the valid format and comply with relevant requirements.
400 InstanceNotExist The instance does not exist. Check whether the specified instance ID is correct or whether the instance belongs to your account. The instance does not exist. Check whether the specified instance ID is correct or whether the instance belongs to your account.
400 LockFailed The system is handling requests you previously submitted. Try again later. The system is handling requests you previously submitted. Try again later.
400 IllegalOperation.VersionManagement The version management operation failed because incompatible features or environment settings are configured. Adjust your configurations and try again. The version management operation failed because incompatible features or environment settings are configured. Adjust your configurations and try again.
400 QuotaCheckFailed.VersionManagement Insufficient quota for version management. Contact technical support. Insufficient quota for version management. Contact technical support.
400 InvalidConfigId The input configuration ID: ConfigId it does not exist, query the existing configuration and its valid ConfigId through the ListSiteFunction. The ConfigId does not exist.
400 Instance.NotOnline Your plan is unavailable due to an overdue payment. Complete the payment first. Your plan is unavailable due to an overdue payment. Complete the payment first.
400 FunctionQuotaCheckFailed The quota verification for this function fails. It may be that the configuration of this function exceeds the limit of the site plan. Please check the plan introduction document corresponding to this site. The current plan does not support the configuration of restricted functions, please check the plan related function description.
400 QuotaCheckFailed.FunctionArg The specified feature parameter is not allowed in your plan, or the feature parameter configurations have reached the upper limit in your plan. The specified feature parameter is not allowed in your plan, or the feature parameter configurations have reached the upper limit in your plan.
400 MissingParameter The specified ArgName is required for this function. When configuring a specific function, the required parameter is missing.
400 FunctionArgError Failed to check the configured function parameters. Failed to check the configured function parameters
404 SiteNotFound The website does not exist or does not belong to you. The website does not exist or does not belong to you.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.