Gateway Gus saysCache-Control directives tell clients and proxies how long and how to cache.
Cache-Control is the master switch: max-age=300 (cache 5 min), no-cache (revalidate before use), no-store (never cache — for sensitive data), private (browser only, not shared proxies), public (anyone). Vary tells caches which request headers affect the response (e.g. Vary: Accept-Encoding). Get these right and you cut load dramatically.
Power-ups you unlock
max-age, no-cache, no-store, private, public
no-store for sensitive data
Vary names headers that change the response
Correct directives cut server load
Timeout Titan attacks — common mistakes
no-cache vs no-store confusion
Caching personalized data as public
Forgetting Vary, serving wrong cached variants
Boss battleChoose Cache-Control for: a public logo, and a user’s account page.