16 days ago
Can Railway’s edge perform a synchronous authorization subrequest on every GET/HEAD/range request, including cache hits, and then deliver a private bucket object without proxying its body through our service? We need current session, organization membership, public-share status, and clean-scan checks. Is there an origin-offload mechanism or supported synchronous-revalidation configuration for this?
Or like in general, How do I make bucket egress free while also keeping scoped request / authorization because right now I am serving the files from a bucket through a service just to do authorization? I know Cloudflare workers etc. does not price on the egress but want to keep on Railway and do not want to spread infra, was just wondering how people do this?
1 Replies
16 days ago
There is no edge-level authorization subrequest or origin-offload mechanism for bucket objects today. Bucket egress is already free, though, so the pattern that avoids service egress while keeping authorization is presigned URLs: your service runs the session/org/scan checks, generates a short-lived presigned URL (up to 90 days, but you would keep it short for access control), and redirects the client to fetch directly from the bucket. The object bytes never pass through your service, so no service egress is incurred. If you need a synchronous revalidation layer at the edge that goes beyond what presigned URL expiry gives you, that would be a feature request you can file at station.railway.com/roadmap.
Status changed to Awaiting User Response Railway • 16 days ago
9 days ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 9 days ago