WebContainer COOP/COEP Header Requirements for CDN-Hosted Low-Traffic Projects
0 reputation · 04 Sept 2021, 21:36 UTC
Header Configuration for Self-Hosted WebContainer Environments
StackBlitz WebContainers enable client-side Node.js execution through WebAssembly, shifting compute costs to the browser. For low-traffic workloads, hosting static project files on a CDN eliminates persistent server infrastructure. However, the WebContainer runtime requires Cross-Origin-Embedder-Policy (COEP) and Cross-Origin-Opener-Policy (COOP) headers to enable SharedArrayBuffer, which is essential for the virtualized POSIX environment.
CDN Header Propagation Constraints
Many CDN providers either strip custom headers by default or require specific configuration to propagate COEP: require-corp and COOP: same-origin across all responses. The WebContainer boot process also initiates cross-origin requests to the StackBlitz API for environment metadata, creating a tension between the strict header requirements and typical CDN caching behaviors.
Unresolved Configuration Boundary
The documentation specifies header requirements for the primary document but does not clarify whether subresource requests (WebAssembly modules, worker scripts, API calls) must carry identical headers or if the initial document headers are sufficient for the entire WebContainer lifecycle.
- Which specific responses must include COEP/COOP headers when serving WebContainer applications from a CDN?
- Can the headers be applied only to the entry HTML document, or must they propagate to all WebAssembly and API responses?