Public Worker Provider Caching
It would be awesome if it was possible to cache TF/Tofu providers in the public worker pools, as it could quickly save up to a few minutes of run time on the init step.
I know that it’s currently available for the private worker pools, but for us that doesn’t have that option yet, then we would love to be able to do ith with the public workers.
- Workaround
- Problem
Log in to comment and vote
Comments1
Natalia Gazda
Jun 25, 2025
Thank you for this suggestion! We understand that provider download times during init can add up, especially for larger configurations.
We've carefully considered provider caching for public workers, but we've decided not to implement it - and it's actually for your protection. Public workers are shared infrastructure serving multiple customers. If we enabled provider caching, it would mean your builds could use providers downloaded by other customers, creating a serious security vulnerability. A malicious actor could potentially poison the cache with compromised providers, putting your infrastructure at risk.
This isolation between customers isn't a limitation - it's a critical security feature that protects you from supply chain attacks. Every run gets fresh, verified providers directly from their official sources.
Alternative solution: You can achieve the performance benefits you're looking for by baking commonly-used providers directly into your Docker image. This gives you pre-cached providers while maintaining complete security - you control exactly what's in your image, and there's no risk of contamination from other users.
If you need more advanced caching strategies or have performance-critical workflows, private workers give you full control over the execution environment, including provider caching.
We prioritize security first, especially on shared infrastructure. While we can't offer this specific optimization, the Docker image approach should give you the performance improvement you're seeking while keeping your infrastructure secure.