
Fastly Keys
CertifiedBatch purge surrogate keys from a Fastly service
Fastly Keys
Batch purge surrogate keys from a Fastly service
Sends a single API call to purge multiple surrogate keys from a specific Fastly service.
Prefer this over calling Key in a loop — it is more efficient and counts as one API call.
The response contains a per-key purge ID map for traceability.
type: io.kestra.plugin.fastly.purge.KeysExamples
Batch purge surrogate keys for a content update
id: invalidate_articles
namespace: company.cms
inputs:
- id: article_ids
type: ARRAY
itemType: STRING
tasks:
- id: purge_articles
type: io.kestra.plugin.fastly.purge.Keys
apiToken: "{{ secret('FASTLY_API_TOKEN') }}"
serviceId: "{{ secret('FASTLY_SERVICE_ID') }}"
surrogateKeys: "{{ inputs.article_ids }}"
soft: true
- id: log_result
type: io.kestra.plugin.core.log.Log
message: "Soft-purged {{ inputs.article_ids | length }} articles"
Properties
apiToken *Requiredstring
Fastly API token
Your Fastly API token. Create one in the Fastly console under Account > API tokens.
Required scopes depend on the operation: URL and surrogate key purges require purge_select;
purge-all requires purge_all; stats endpoints require global: read.
serviceId *Requiredstring
Service ID
The Fastly service identifier to purge against.
surrogateKeys *Requiredarray
Surrogate keys
List of surrogate keys to purge in a single batch request.
baseUrl string
https://api.fastly.comFastly API base URL
Base URL for the Fastly API. Override this only for testing.
options Non-dynamic
HTTP client options
Optional advanced HTTP settings such as timeouts or proxy configuration.
io.kestra.core.http.client.configurations.HttpConfiguration
falseIf true, allow a failed response code (response code >= 400)
List of response code allowed for this request
The authentication to use.
io.kestra.core.http.client.configurations.BasicAuthConfiguration
The password for HTTP basic authentication.
The username for HTTP basic authentication.
io.kestra.core.http.client.configurations.BearerAuthConfiguration
The token for bearer token authentication.
io.kestra.core.http.client.configurations.DigestAuthConfiguration
The password for HTTP Digest authentication.
The username for HTTP Digest authentication.
The password for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
The username for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
durationThe time allowed to establish a connection to the server before failing.
durationThe time an idle connection can remain in the client's connection pool before being closed.
UTF-8The default charset for the request.
java.nio.charset.Charset
trueWhether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).
Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.
trueWhether redirects should be followed automatically.
ALLTRACEDEBUGINFOWARNERROROFFNOT_SPECIFIEDThe log level for the HTTP client.
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODYThe enabled log.
The maximum content length of the response.
The proxy configuration.
io.kestra.core.http.client.configurations.ProxyConfiguration
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTDIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
durationThe time allowed for a read connection to remain idle before closing it.
durationThe maximum time allowed for reading data from the server before failing.
The SSL request options
io.kestra.core.http.client.configurations.SslOptions
Whether to disable checking of the remote SSL certificate.
Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.
The timeout configuration.
io.kestra.core.http.client.configurations.TimeoutConfiguration
The time allowed to establish a connection to the server before failing.
PT5MThe time allowed for a read connection to remain idle before closing it.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
soft booleanstring
falseSoft purge
When true, marks cached content as stale instead of removing it immediately. Stale content is served while Fastly re-fetches fresh content from the origin. Defaults to false (hard purge).
Outputs
purgeIds object
Purge IDs by key
Map of surrogate key to its corresponding purge request ID, as returned by Fastly.