If your origin server is a private Object Storage Service (OSS) bucket, you must enable the private bucket origin feature and grant Dynamic Route for CDN (DCDN) permissions to access the OSS bucket. This feature can be used for access authentication and protect origin servers from unauthorized access. This topic describes how to enable and disable access to private OSS buckets.
Background information
After you grant DCDN permissions to access private OSS buckets, you can also use features such as hotlink protection and URL authentication provided by DCDN to protect resources from unauthorized access. For more information, see Configure a referer whitelist or blacklist to enable hotlink protection and Configure URL authentication.
- After you grant DCDN permissions to access private OSS buckets, DCDN is granted read-only permissions on all your OSS buckets.
- After you enable the private bucket origin feature and grant DCDN permissions to access private OSS buckets, DCDN can access all resources in your private OSS buckets by using the accelerated domain names. Proceed with caution when you use this feature. Do not enable the private bucket origin feature or grant DCDN permissions to access private OSS buckets if your private bucket is unsuitable as an origin for your domain name.
- If your website is vulnerable to attacks, we recommend that you purchase the Anti-DDoS service. Do not enable the private bucket origin feature or grant DCDN permissions to access private OSS buckets.
- The private bucket origin feature conflicts with the settings of the default homepage of the static website that is hosted on OSS. For more information about how to use the private bucket origin feature and the static website hosting feature at the same time, see Why do requests destined for my accelerated domain name trigger the error message "You are forbidden to list buckets" after access to private Object Storage Service (OSS) is enabled?
Enable access to private OSS buckets
Disable access to private OSS buckets
If you no longer need an accelerated domain name to access your private OSS buckets, you can log on to the RAM console and revoke the access permissions that are granted to DCDN.