Projects and deployments
Runtime and caching
How requests reach your deployment, what your server code runs with, and how caching works.
How requests are routed
Every deployment hostname and custom domain is served by the platform's edge (CloudFront). For each request, the edge looks up which deployment the hostname belongs to and sends the request to its static files or its server function:
| Request path | Served from |
|---|---|
/_next/static/… | Static files |
Ends in a file extension (/logo.svg, /robots.txt), outside /api/ | Static files |
| Anything else | The server function (Next.js) |
For static projects, a path without a file extension is served from <path>/index.html, so /about serves /about/index.html and / serves /index.html.
A Next.js route whose path ends in an extension, such as a generated /sitemap.xml or /feed.rss, is looked up as a static file and never reaches the server function. Generate those files at build time into public/, or serve them under /api/.
Your app sees the hostname the visitor used in the x-forwarded-host header; the Host header is the function's own.
Server functions
Next.js deployments run in one AWS Lambda function per deployment:
| Runtime | Node.js 22 on arm64 |
| Memory | 1,024 MB |
| Timeout | 30 seconds per request |
| Region | Resolved from the project's location when the deployment is published |
| Environment | The project's variables for the deployment's target, the platform variables, and NODE_ENV=production |
Responses are buffered: a streamed response (React streaming, server-sent events) reaches the visitor in one piece when the function finishes. AWS limits buffered responses to 6 MB.
Permissions
Each organization has one runtime role, shared by its deployments. It allows writing logs and reading and writing the organization's own databases and buckets (all of them, not only the linked ones) and the organization's part of the Next.js cache. It allows nothing else in AWS, and nothing that belongs to another organization. The AWS SDK picks up the role's credentials automatically.
Function URLs are public
The edge calls the function through a public function URL, as the platform's own apps do. That URL can also be called directly, bypassing the edge, so authenticate your sensitive endpoints in your app rather than relying on the edge.
Caching
The edge caches a response only when its Cache-Control allows it; without that header nothing is cached.
- The cache key is the hostname, path and full query string.
- Cookies aren't part of the cache key, but your function receives them. A response that depends on cookies must be
privateorno-store, or one visitor's response can be served to another. - The edge compresses responses with gzip or Brotli.
- Uploaded static files:
/_next/static/files are cached for a year (immutable); every other file is revalidated on each request (max-age=0, must-revalidate).
Next.js incremental cache
Prerendered pages and fetch cache entries are stored per deployment, so a new deployment starts from its own build's pages. The platform sets CACHE_BUCKET_NAME, CACHE_BUCKET_KEY_PREFIX and CACHE_BUCKET_REGION on the function for this, replacing project variables with the same names.
Tag-based revalidation (revalidateTag) has no tag store yet, so Next.js deployments log Failed to check stale tags. Coming soon