All Products
Search
Document Center

ApsaraVideo VOD:Private bucket back-to-origin

Last Updated:Jun 20, 2026

This topic describes how to authorize and configure back-to-origin of a private bucket.

Background

A CDN domain name requires authorization and an enabled back-to-origin configuration to access content in a private bucket. You can also use features provided by ApsaraVideo VOD, such as referer-based hotlink protection and URL authentication, to enhance the security of your resources.

Important
  • After you authorize and enable this feature for a CDN domain name, the domain name can access all resources in your private bucket. Use this feature with caution. If the content in the private bucket is unsuitable as a CDN origin, do not authorize or enable this feature.

  • If your CDN domain name is using a private bucket as its origin, do not disable the back-to-origin of private bucket feature.

  • If your website is at risk of attacks, purchase Anti-DDoS Pro. Do not authorize or enable this feature.

Procedure

  1. Log in to the ApsaraVideo VOD console.

  2. In the left-side navigation pane, under Configuration Management, click CDN Configuration > Domain Names.

  3. Find the domain name that you want to configure and click Configure in the Actions column.

  4. Authorize access. If access is already authorized, skip this step.

    1. Click the Back-to-Origin tab. In the Back-to-Origin of Private Bucket section, click Authorize.

    2. Click Confirm Authorization Policy.

      On the Resource Access Authorization page, the system automatically creates the AliyunCDNAccessingPrivateOSSRole role. This role grants the CDN read-only access to your private OSS bucket.

  5. Click the Back-to-Origin tab and turn on the Back-to-Origin of Private Bucket switch, completing the configuration.