Cache Service
Repo: o-apps/cache-service (fluxcd app directory: cache-api) · Port: 8080 (HTTP), 9090 (gRPC)
A thin wrapper around Redis, exposed over both HTTP and gRPC, so no other service needs a direct Redis client dependency. If Redis is unavailable or unconfigured, it transparently falls back to an in-memory backend — useful for local dev, but rate limits and cached values then don't survive a restart or apply across replicas.
Why This Exists
Several services (auth-service for login rate limiting, others for general caching) need a shared cache without each one importing and configuring a Redis client directly. cache-service centralizes that: the backend (Redis vs. in-memory) is chosen once, here, behind a ports.CacheRepository interface — consumers only ever see a small HTTP/gRPC API.
Key Capabilities
- Basic cache operations — get/set/delete by key, with TTL
- Atomic increment-with-expiry —
IncrementWithExpiryis a sliding-window counter (each call resets the TTL), the primitiveauth-service's login/register rate limiter is built on - Dual interface — the same operations are available over HTTP (for services that don't want a gRPC client) and gRPC (lower overhead for high-frequency callers)
Auth
All /cache/* routes require an X-Api-Key matching the shared API_KEY secret; /health is public. Introduced after an audit found cache-service's counters (including rate-limit state) were resettable by anyone with network access.
REST API
| Method | Path | Description |
|---|---|---|
GET | /cache/{key} | Get a value |
POST | /cache | Set a value (body includes key, value, TTL) |
DELETE | /cache/{key} | Delete a value |
POST | /cache/{key}/increment | Atomic increment with TTL reset (sliding window) |
GET | /health | Health check (unauthenticated) |
Environment Variables
| Variable | Description |
|---|---|
REDIS_ADDR | Redis address, e.g. redis:6379; falls back to in-memory if unreachable |
REDIS_PASS | Redis password (optional) |
REDIS_DB | Redis logical DB number (default: 0) |
API_KEY | Shared secret the X-Api-Key middleware validates against |
HTTP_PORT / GRPC_PORT | HTTP and gRPC ports (defaults: 8080 / 9090) |