This topic describes how to authorize and configure back-to-origin of a private bucket.
Background
A CDN domain name requires authorization and an enabled back-to-origin configuration to access content in a private bucket. You can also use features provided by ApsaraVideo VOD, such as referer-based hotlink protection and URL authentication, to enhance the security of your resources.
-
After you authorize and enable this feature for a CDN domain name, the domain name can access all resources in your private bucket. Use this feature with caution. If the content in the private bucket is unsuitable as a CDN origin, do not authorize or enable this feature.
-
If your CDN domain name is using a private bucket as its origin, do not disable the back-to-origin of private bucket feature.
-
If your website is at risk of attacks, purchase Anti-DDoS Pro. Do not authorize or enable this feature.
Procedure
-
Log in to the ApsaraVideo VOD console.
-
In the left-side navigation pane, under Configuration Management, click CDN Configuration > Domain Names.
-
Find the domain name that you want to configure and click Configure in the Actions column.
-
Authorize access. If access is already authorized, skip this step.
-
Click the Back-to-Origin tab. In the Back-to-Origin of Private Bucket section, click Authorize.
-
Click Confirm Authorization Policy.
On the Resource Access Authorization page, the system automatically creates the AliyunCDNAccessingPrivateOSSRole role. This role grants the CDN read-only access to your private OSS bucket.
-
-
Click the Back-to-Origin tab and turn on the Back-to-Origin of Private Bucket switch, completing the configuration.