Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
78 changes: 45 additions & 33 deletions src/content/docs/r2/buckets/public-buckets.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -12,10 +12,12 @@ Public Bucket is a feature that allows users to expose the contents of their R2
Public buckets can be set up in either one of two ways:

- Expose your bucket as a custom domain under your control.
- Expose your bucket as a Cloudflare-managed subdomain under `https://r2.dev`.
- Expose your bucket using a Cloudflare-managed `https://r2.dev` subdomain for non-production use cases.

To configure WAF custom rules, caching, access controls, or bot management for your bucket, you must do so through a custom domain.
Using a custom domain does not require enabling `r2.dev`.
These options can be used independently or together, enabling custom domains does not require enabling `r2.dev` access.

To use features like WAF custom rules, caching, access controls, or bot management, you must configure your bucket behind a custom domain.
These capabilities are not available when using the `r2.dev` development url.

:::note

Expand All @@ -33,7 +35,8 @@ Configure your cache to use [Smart Tiered Cache](/cache/how-to/tiered-cache/#sma

:::note

By default, only certain file types are cached. To cache all files in your bucket, you must set a Cache Everything page rule. For more information on default Cache behavior and how to customize it, refer to [Default Cache Behavior](/cache/concepts/default-cache-behavior/#default-cached-file-extensions)
By default, only certain file types are cached. To cache all files in your bucket, you must set a Cache Everything page rule.
For more information on default Cache behavior and how to customize it, refer to [Default Cache Behavior](/cache/concepts/default-cache-behavior/#default-cached-file-extensions)

:::

Expand All @@ -46,14 +49,23 @@ To restrict access to your custom domain's bucket, use Cloudflare's existing sec

:::caution

Disable public access to your [`r2.dev` subdomain](#disable-managed-public-access) when using products like WAF or Cloudflare Access. If you do not disable public access, your bucket will remain publicly available through your `r2.dev` subdomain.
Disable public access to your [`r2.dev` subdomain](#disable-public-development-url) when using products like WAF or Cloudflare Access. If you do not disable public access, your bucket will remain publicly available through your `r2.dev` subdomain.

:::

### Minimum TLS Version

To specify the minimum TLS version of a custom hostname of an R2 bucket, you can issue an API call to edit [R2 custom domain settings](/api/resources/r2/subresources/buckets/subresources/domains/subresources/custom/methods/update/).

## Add your domain to Cloudflare

The domain being used must have been added as a [zone](/fundamentals/setup/accounts-and-zones/#zones) in the same account as the R2 bucket.

- If your domain is already managed by Cloudflare, you can proceed to Connect a bucket to a custom domain.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Connect a bucket to a custom domain

Is this a reference to a component on the dashboard? I wasn't 100% sure which page I needed to be looking at here

- If your domain is not managed by Cloudflare, you’ll need to set it up using a [partial (CNAME) setup](/dns/zone-setups/partial-setup/) to add it to your account.

Once the domain exists in your Cloudflare account (regardless of setup type), you can link it to your bucket.

## Connect a bucket to a custom domain

<Render file="custom-domain-steps" />
Expand All @@ -62,14 +74,11 @@ To view the added DNS record, select **...** next to the connected domain and se

:::note

If the zone is on an Enterprise plan, make sure that you [release the zone hold](/fundamentals/setup/account/account-security/zone-holds/#release-zone-holds) before adding the custom domain. A zone hold would prevent the custom subdomain from activating.
If the zone is on an Enterprise plan, make sure that you [release the zone hold](/fundamentals/setup/account/account-security/zone-holds/#release-zone-holds) before adding the custom domain.
A zone hold would prevent the custom subdomain from activating.

:::

### Restrictions

There is a restriction when using custom domains to access R2 buckets. The domain being used must have been added as a [zone](/fundamentals/setup/accounts-and-zones/#zones) in the same account as the R2 bucket.

## Disable domain access

Disabling a domain will turn off public access to your bucket through that domain. Access through other domains or the managed `r2.dev` subdomain are unaffected.
Expand All @@ -78,57 +87,60 @@ The specified domain will also remain connected to R2 until you remove it or del
To disable a domain:

1. In **R2**, select the bucket you want to modify.
2. On the bucket page, Select **Settings**.
3. Under **Public access** > **Custom Domains**, select **Connect Domain**.
4. Next to the domain you want to disable, select **...** and **Disable domain**.
5. The badge under **Access to Bucket** will update to **Not allowed**.
2. On the bucket page, Select **Settings**, go to **Custom Domains**.
3. Next to the domain you want to disable, select **...** and **Disable domain**.
4. The badge under **Access to Bucket** will update to **Not allowed**.

## Remove domain

Removing a domain will remove custom domain configuration that you have set up on the dashboard. Your bucket will still be publicly accessible.
Removing a custom domain will disconnect it from your bucket and delete its configuration from the dashboard.
Your bucket will remain publicly accessible through any other enabled access method, but the domain will no longer appear in the connected domains list.

To remove a domain:

1. In **R2**, select the bucket you want to modify.
2. On the bucket page, select **Settings**.
3. Under **Public access** > **Custom Domains**, select **Connect Domain**.
4. Next to the domain you want to disable, select **...** and **Remove domain**.
5. Select ‘Remove domain’ in the confirmation window. The CNAME record pointing to the domain will also be removed as part of this step. You can always add the domain again.

The domain is no longer connected to your bucket and will no longer appear in the connected domains list.
2. On the bucket page, Select **Settings**, go to **Custom Domains**.
3. Next to the domain you want to disable, select **...** and **Remove domain**.
4. Select ‘Remove domain’ in the confirmation window. The CNAME record pointing to the domain will also be removed as part of this step. You can always add the domain again.

## Enable managed public access
## Public Development URL

When you enable managed public access for your bucket, the content of your bucket is available to the Internet through a Cloudflare-managed `r2.dev` subdomain.
Expose the contents of this R2 bucket to the internet through a Cloudflare-managed r2.dev subdomain.
This endpoint is intended for non-production traffic.

:::note

Public access through `r2.dev` subdomains are rate limited and should only be used for development purposes.

To enable access management, Cache and bot management features, you must set up a custom domain when enabling public access to your bucket.

Avoid creating a CNAME record pointing to the `r2.dev` subdomain. This is an **unsupported access path**, and we cannot guarantee consistent reliability or performance.
For production use, [add your domain to Cloudflare](#add-your-domain-to-cloudflare) instead.
:::

### Enable public development url

When you enable public development URL access for your bucket, its contents become available on the internet through a Cloudflare-managed `r2.dev` subdomain.

To enable access through `r2.dev` for your buckets:

1. In **R2**, select the bucket you want to modify.
2. On the bucket page, select **Settings**.
3. In **Settings**, go to **Public Access**.
4. Under **R2.dev subdomain**, select **Allow Access**.
5. In **Allow Public Access?**, confirm your choice by typing ‘allow’ to confirm and select **Allow**.
6. You can now access the bucket and its objects using the Public Bucket URL.
3. Under **Public Development URL**, select **Enable**.
4. In **Allow Public Access?**, confirm your choice by typing ‘allow’ to confirm and select **Allow**.
5. You can now access the bucket and its objects using the Public Bucket URL.

You can review if your bucket is publicly accessible by going to your bucket and checking that **Public URL Access** states **Allowed**.
To verify that your bucket is publicly accessible, check that **Public URL Access** shows **Allowed** in you bucket settings.

## Disable managed public access
### Disable public development url

Your bucket will not be exposed to the Internet as an `r2.dev` subdomain after you disable public access. If you have connected other domains, the bucket will remain accessible on those domains.
Disabling public development URL access removes your bucket’s exposure through the `r2.dev` subdomain.
The bucket and its objects will no longer be accessible via the Public Bucket URL.
If you’ve connected other domains, the bucket will remain accessible through those.

To disable public access for your bucket:

1. In **R2**, select the bucket you want to modify.
2. On the bucket page, select **Settings**.
3. Under **Bucket Details** > **R2.dev subdomain**, select **Disallow Access**.
3. Under **Public Development URL**, select **Disable**.
4. In **Disallow Public Access?**, type ‘disallow’ to confirm and select **Disallow**.

Your bucket and its objects can no longer be accessed using the Public Bucket URL.
4 changes: 2 additions & 2 deletions src/content/docs/r2/data-migration/sippy.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ Before getting started, you will need:

1. From the Cloudflare dashboard, select **R2** from the sidebar.
2. Select the bucket you'd like to migrate objects to.
3. Switch to the **Settings** tab, then scroll down to the **Incremental migration** card.
3. Switch to the **Settings** tab, then scroll down to the **On Demand Migration** card.
4. Select **Enable** and enter details for the AWS / GCS bucket you'd like to migrate objects from. The credentials you enter must have permissions to read from this bucket. Cloudflare also recommends scoping your credentials to only allow reads from this bucket.
5. Select **Enable**.

Expand Down Expand Up @@ -122,7 +122,7 @@ You can optionally select a time window to query. This defaults to the last 24 h

1. From the Cloudflare dashboard, select **R2** from the sidebar.
2. Select the bucket you'd like to disable Sippy for.
3. Switch to the **Settings** tab and scroll down to the **Incremental migration** card.
3. Switch to the **Settings** tab and scroll down to the **On Demand Migration** card.
4. Press **Disable**.

### Wrangler
Expand Down
5 changes: 2 additions & 3 deletions src/content/partials/r2/custom-domain-steps.mdx
Original file line number Diff line number Diff line change
@@ -1,12 +1,11 @@
---
{}

---

1. Go to **R2** and select your bucket.
2. On the bucket page, select **Settings**.
3. Under **Public access** > **Custom Domains**, select **Connect Domain**.
3. Under **Custom Domains**, select **Add**.
4. Enter the domain name you want to connect to and select **Continue**.
5. Review the new record that will be added to the DNS table and select **Connect Domain**.

Your domain is now connected. The status takes a few minutes to change from **Initializing** to **Active**, and you may need to refresh to review the status update. If the status has not changed, select the *...* next to your bucket and select **Retry connection**.
Your domain is now connected. The status takes a few minutes to change from **Initializing** to **Active**, and you may need to refresh to review the status update. If the status has not changed, select the _..._ next to your bucket and select **Retry connection**.
Loading