Follow us
Breaking
Web Hosting

Common mistakes with Cloudflare R2 bucket permissions

Developers face security friction due to R2's lack of IAM JSON policies and customer-managed KMS keys. Additionally, over 2,000 phishing emails were identified using r2.dev subdomains, highlighting the need to disable public access for development URLs when using custom domains.

Share

API compatibility gaps

R2 uses Cloudflare API tokens instead of IAM JSON policies. This difference creates friction when you try to replicate security models that rely on resource ARNs, conditions, or principals. Many S3 features like x-amz-expected-bucket-owner or x-amz-grant-read do not work on R2. I see developers struggle with CORS errors when they use presigned POST requests from origins like localhost:3000 even after they set the CORS policy. You should check your CORS settings before deployment.

I find the S3 API compatibility often trips up developers.

R2 lacks support for customer-managed KMS keys. It uses Cloudflare-managed keys for encryption at rest. For checksums, R2 supports SHA-256 and CRC-32 for composite objects, but it does not support CRC-64/NVME. R2 PutObject calls also do not support x-amz-acl or x-amz-grant-full-control headers. While Cloudflare provides R2 as a way to avoid egress fees, the platform still lacks support for customer-managed KMS keys or the complex IAM JSON policies that many AWS users rely on for security.

Feature Cloudflare R2 Amazon S3
Egress Fees $0 Tiered rates
Storage Tiers Standard, Infrequent Access 7 classes
IAM Policies Cloudflare API Tokens JSON-based IAM
KMS Support Cloudflare-managed Customer-managed (KMS)

Public access pitfalls

Buckets are private by default. You can enable a custom domain or use the r2.dev subdomain. Using r2.dev exposes contents to the internet. Phishers use URLs starting with https://pub- to lure victims. In a 60-day period, we saw more than 2,000 phishing emails using r2.dev links. If you enable a custom domain, your bucket remains public through the r2.dev subdomain unless you disable public access for that development URL. You should use a custom domain to access WAF rules or Bot Management.

Avoid r2.dev.

The phishing URL structure usually follows https://pub-{32 Hexadecimal String}.r2.dev/. This method allows attackers to host fake login pages for services like Microsoft Excel. I find that users often forget that enabling a custom domain does not automatically disable the r2.dev access. To use WAF, you must configure the bucket behind a custom domain. You can connect a domain by navigating to the R2 object storage page, selecting the bucket, and choosing Settings.

Can R2 ever match the granular permission depth of AWS IAM?

Regional write performance

Local Uploads (in open beta) writes data close to the client first. This reduces Time to Last Byte by up to 75%. For example, a request in a different region might drop from 2s to 500ms. This feature is not for buckets with jurisdiction restrictions like FedRAMP or EU settings. The replication task uses Cloudflare Queues to manage the copy job.

It works well.

The R2 Gateway Worker handles authentication and routing. A Durable Object Metadata Service manages object metadata. The replication process follows a pull model where a centralized polling service pulls tasks from regional queues. This service dispatches jobs to the Gateway Worker. The worker reads data from the source, writes to the destination, and updates metadata in the Durable Object. The replication task marker is keyed by timestamp to control when the task enters the queue. The pending replica key contains the number of replication tasks and the destination location.

Share

Technewsdaily

Senior tech writer covering AI, gadgets and cybersecurity. Breaking down the news that matters, every day.