Bucket Egress
enesakyuz
PROOP

16 days ago

Can Railway’s edge perform a synchronous authorization subrequest on every GET/HEAD/range request, including cache hits, and then deliver a private bucket object without proxying its body through our service? We need current session, organization membership, public-share status, and clean-scan checks. Is there an origin-offload mechanism or supported synchronous-revalidation configuration for this?

Or like in general, How do I make bucket egress free while also keeping scoped request / authorization because right now I am serving the files from a bucket through a service just to do authorization? I know Cloudflare workers etc. does not price on the egress but want to keep on Railway and do not want to spread infra, was just wondering how people do this?

Solved

1 Replies

Railway
BOT

16 days ago

There is no edge-level authorization subrequest or origin-offload mechanism for bucket objects today. Bucket egress is already free, though, so the pattern that avoids service egress while keeping authorization is presigned URLs: your service runs the session/org/scan checks, generates a short-lived presigned URL (up to 90 days, but you would keep it short for access control), and redirects the client to fetch directly from the bucket. The object bytes never pass through your service, so no service egress is incurred. If you need a synchronous revalidation layer at the edge that goes beyond what presigned URL expiry gives you, that would be a feature request you can file at station.railway.com/roadmap.


Status changed to Awaiting User Response Railway • 16 days ago


Railway
BOT

9 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 9 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...