Configure Buck2 Remote Cache
Last updated: September 21, 2026
What is Buck2 Remote Cache
Buck2 can store and reuse metadata and output files from a shared Remote Cache for significantly faster builds using the Bazel Remote Execution gRPC API (REAPI). BuildFetch Cache acts as a fully compatible Remote Cache REAPI server for Buck2.
Remote Cache is especially useful for ephemeral CI workers, large monorepos, and teams that frequently switch branches or work across several machines.
Each CI build populates the shared cache, follow-up Buck2 builds then reuse the caches instead of spending minutes on executing the build graph.
Configure Buck2 Remote Cache
Before setting up Remote Cache, ensure you have created a BuildFetch Project and Token(s).
Cache Access
Use a cache:readonly Token by default on developer and AI agent machines. Trusted environments like CI should use a cache:readwrite Token and explicitly enable uploads.
For Token management, rotation, and Open Source guidance, see Set up BuildFetch Cache Project.
Read-only
The execution platform defaults allow_cache_uploads to false, so normal Buck2 builds only consume remote cache entries:
buck2 build //...Read-write
Enable uploads:
buck2 --config buildfetch.allow_cache_uploads=true build //...Configure Buck2 to use Remote Cache
Take the project cache host, Project ID, and generated Token from the BuildFetch Project Cache Setup tab.
Add or merge these sections into .buckconfig:
[buck2]
digest_algorithms = SHA256
[buck2_re_client]
action_cache_address = grpcs://cache.region.buildfetch.com
engine_address = grpcs://cache.region.buildfetch.com
cas_address = grpcs://cache.region.buildfetch.com
tls = true
instance_name = reapi/buck2/<PROJECT_ID>
http_headers = Authorization:Bearer $BUILDFETCH_BUCK2_REMOTE_CACHE_TOKEN
[build]
execution_platforms = root//platforms:platformsKeep the Token outside source control:
export BUILDFETCH_BUCK2_REMOTE_CACHE_TOKEN="..."Buck2 controls cache participation through the execution platform. The following configuration keeps execution local while allowing BuildFetch Cache to serve and populate the remote cache:
# platforms/defs.bzl
def _platforms(ctx):
configuration = ConfigurationInfo(
constraints = {},
values = {},
)
platform = ExecutionPlatformInfo(
label = ctx.label.raw_target(),
configuration = configuration,
executor_config = CommandExecutorConfig(
local_enabled = True,
remote_enabled = False,
remote_cache_enabled = True,
allow_cache_uploads = read_config("buildfetch", "allow_cache_uploads", "false") == "true",
),
)
return [DefaultInfo(), ExecutionPlatformRegistrationInfo(platforms = [platform])]
platforms = rule(attrs = {}, impl = _platforms)Register it from platforms/BUCK:
load(":defs.bzl", "platforms")
platforms(name = "platforms")The important settings are:
remote_cache_enabled = True— Buck2 queries the remote Action Cache and CAS.allow_cache_uploads— defaults tofalsethroughread_config, so local builds only consume remote cache entries.remote_enabled = False— BuildFetch is not used as a remote executor.instance_name = reapi/buck2/<PROJECT_ID>— identifies and isolates the BuildFetch Buck2 Project in BuildFetch Cache in conjunction with token.digest_algorithms = SHA256— matches the digest algorithm supported by the BuildFetch REAPI implementation.