Lagoon

Docs

From a built directory to a cached, integrity-checked URL. Follow the three stages left to right.

  1. 01
    Publish

    Push a release

    Upload a build output under a package and version.

  2. 02
    Link

    Add integrity

    Copy the printed digest into your markup.

  3. 03
    Cache

    Let it stick

    Immutable for a year, never purged.

01 · Push a release

Install the CLI, authenticate once, then point it at a built directory. Everything under it lands on an immutable path.

# one-time setup
npm i -g @lagoon/cli
lagoon login

# publish ./dist as tidegrid@2.4.1
lagoon publish ./dist --pkg tidegrid --tag 2.4.1

Files become available at https://cdnlagoon.com/v/tidegrid/2.4.1/<file>. Publishing the same version twice is rejected — bump the semver instead.

02 · Link with integrity

The publish output prints a sha384 digest per file. Paste it into the integrity attribute and the browser will refuse any byte that does not match.

<link rel="stylesheet"
  href="https://cdnlagoon.com/v/tidegrid/2.4.1/tidegrid.min.css"
  integrity="sha384-h7o4H/vM8Qtuxbks7IsIBvJJwTeyRDU4xYgJphsSa+q0IokWOLQNLSzkTG/JF9pN"
  crossorigin="anonymous">

<script src="https://cdnlagoon.com/v/tidegrid/2.4.1/tidegrid.min.js"
  integrity="sha384-rl7MVm85kV0+F+nfU0Jzjr7G47sVKZL/ZkAy5AOHl2vy0p+9jV9nAGnW7m0mbk+q"
  crossorigin="anonymous" defer></script>

You can recompute a digest locally at any time:

curl -s https://cdnlagoon.com/v/tidegrid/2.4.1/tidegrid.min.js \
  | openssl dgst -sha384 -binary | openssl base64 -A

03 · Let it cache

Versioned paths are returned with Cache-Control: public, max-age=31536000, immutable. Browsers and edges keep them for the full year. A new version is a new URL — never a purge.

Need a moving pointer such as latest or 2.x? Use a channel alias. It answers with a 302 to the current immutable path and is cached for five minutes, so your HTML can stay stable while builds roll forward.

Cache headers at a glance

Path shapeCache-ControlEdge TTL
/v/pkg/2.4.1/filepublic, max-age=31536000, immutable1 year
/v/pkg/2.x/filepublic, max-age=3005 min
/v/pkg/latest/filepublic, max-age=3005 min
/v/pkg/2.4.1/ (index)public, max-age=36001 hour

Response headers

Every asset ships with permissive CORS (Access-Control-Allow-Origin: *), a correct Content-Type, X-Content-Type-Options: nosniff and an ETag derived from the content hash. Compressed variants are negotiated through Accept-Encoding (br, gzip).

Browse the edge network →