Cloudflare: your domain and public files
Two choices on Cloudflare affect what visitors see: the address the site answers at, and where its public files (photos, posters, the logo) come from. This page is for whoever deploys to Cloudflare, after Deploy to Cloudflare Workers.
Use your own domain
-
The domain's DNS zone must be on the same Cloudflare account as the Worker. If the domain is registered elsewhere, add it to Cloudflare as a site and change its name servers first.
-
In
wrangler.toml, set a route withcustom_domain = true:routes = [{ pattern = "choir.example.org", custom_domain = true }] -
Set
SITE_URL = "https://choir.example.org"in[vars]. -
Deploy:
npx wrangler deploy.
Cloudflare serves the Worker at that name and manages the certificate. In the dashboard, the domain appears in the Worker's Settings, under Domains & Routes.
Send www to the bare domain
A custom_domain route covers exactly one name. To make www.choir.example.org go to choir.example.org, add a redirect rule to the zone: in the Cloudflare dashboard open the domain, then Rules, and make a redirect from the www host to https://choir.example.org with the path kept. The www name must exist in DNS (a proxied record) for the rule to see the request.
Public files
Files of two kinds are stored: public ones (the gallery, posters, the logo and other pictures) and private ones (member files and rehearsal tracks). Public files can reach browsers in one of two ways.
By the Worker (the default)
With nothing set, the Worker serves public files itself at /files/<key> on your own address. This needs no bucket configuration, works with every provider, and is fine for most choirs.
Straight from R2
To take the file traffic off the Worker, serve the public bucket from its own address:
-
In the Cloudflare dashboard open R2, then the
choir-publicbucket. -
Open Settings, then Public access, then Custom domains, and add a domain you control on this account, such as
files.choir.example.org. -
In
wrangler.toml[vars], set:PUBLIC_FILES_URL = "https://files.choir.example.org" -
Deploy again.
Pages then link to that address for public files. The database holds file keys, not addresses, so you can switch back by removing the setting. See Public file addresses and upload limits.
Never make the private bucket public
Never give the private bucket (choir-private) a public address, a custom domain or a public-access setting. It holds member files and rehearsal tracks. The Worker serves them only after checking that the person asking is a logged-in member or an admin. A public address would let anyone with the link, or who guesses it, download them with no check at all.
If you use the R2 S3-compatible interface instead of the binding, see R2 on Cloudflare.