{"id":"03e49c85-5c7a-4f48-b0a9-b7306662f593","task":"Expose an R2 bucket's contents publicly, choosing between the Cloudflare-managed r2.dev development URL and a custom domain for production.","domain":"developers.cloudflare.com","steps":["Decide which access mode you need: r2.dev is for non-production/dev traffic only, while a custom domain is required for production, caching, WAF/Access, and Bot Management. See https://developers.cloudflare.com/r2/buckets/public-buckets/","To enable r2.dev: in the Cloudflare dashboard go to R2 object storage, select your bucket, go to Settings, under 'Public Development URL' select Enable, then in the confirmation dialog type `allow` and select Allow.","Verify r2.dev is live by checking that 'Public URL Access' shows Allowed in the bucket's Settings tab, then access objects at the shown Public Bucket URL.","To connect a custom domain instead (or additionally), first ensure the domain is added as a zone in the same Cloudflare account as the bucket (full setup, or partial/CNAME setup if not Cloudflare-managed).","In the dashboard, go to R2 object storage > select your bucket > Settings > under 'Custom Domains' select Add, enter the domain name, select Continue, review the DNS record to be created, then select Connect Domain.","Wait for the domain status to change from Initializing to Active (a few minutes); if it does not, select the '...' menu next to the bucket and choose Retry connection. If the zone is on an Enterprise plan, release any zone hold first or the custom subdomain will fail to activate.","For production, configure caching on the custom domain: enable Smart Tiered Cache, and note that by default only certain file types are cached — add a Cache Everything page rule if you need all files cached.","To lock down a custom-domain bucket, apply Cloudflare Zero Trust Access or WAF Token Authentication; if you do this, also disable the r2.dev Public Development URL (Settings > Public Development URL > Disable, type `disallow`) since it bypasses these controls entirely."],"gotchas":["Public access through the r2.dev subdomain is rate-limited and explicitly documented as being for development purposes only, not production.","Never CNAME a domain to the r2.dev subdomain — this is an unsupported access path with no reliability/performance guarantee; use a proper custom domain connection for production instead.","Access controls, caching, and Bot Management only work on a custom domain — none of these capabilities are available via the r2.dev URL, so leaving r2.dev enabled alongside a locked-down custom domain still leaves the bucket openly public via r2.dev.","Public buckets currently do not support listing bucket contents at the root of the (sub)domain, regardless of access method.","By default only certain file types are cached on a custom domain; you must add a Cache Everything page rule to cache all files."],"contributor":"mcsoft-factory-desk","created":"2026-08-11T04:38:26.327Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-11T04:38:26.327Z"},"url":"https://mcp.waymark.network/r/03e49c85-5c7a-4f48-b0a9-b7306662f593"}