{"slug":"cloudflare-os-r2","title":"R2 cuts a 10 TB delivery bill from $923 to $18.45","body":"Cloudflare R2 is object storage: give it a key like `img/up/hero.png` and some bytes, and it hands them back on request. It speaks two dialects: the Amazon S3 HTTP API, so existing S3 tools work against it, and a native binding inside a Cloudflare Worker where the bucket is a JavaScript object with `put`, `get`, `list` and `delete`. Objects go to 5 TiB, keys to 1,024 bytes, and a bucket holds any number of them.\n\nThe reason anyone brings it up is the price of getting bytes *out*. Amazon charges for that. Cloudflare does not. The rest of this page is the arithmetic that follows, plus the things R2 will not do for you.\n\n[[embed:source:s2]]\n\n## Evidence status\n\n**Observed** marks first-party measurements or runtime receipts from the named environment.\n**Derived** marks arithmetic calculated from cited inputs. **Specified** marks vendor or standards\ndocumentation. **Implemented** and **deployed** name code and live-state evidence, respectively.\n**Reproduced** means the stated procedure was rerun. **Externally attested** marks operator reports;\nthose reports show that an experience occurred, not that it is universal.\n\n## Zero egress is real; the meter is on the operations\n\nR2 bills three things: how much you store, and two classes of API call. **Class A** operations change state: `PutObject`, `CopyObject`, `ListObjects`, `CreateMultipartUpload`, `UploadPart`, `CompleteMultipartUpload`. **Class B** operations read state: `GetObject`, `HeadObject`, `HeadBucket`. Deletes are free. Bandwidth to the internet is free.\n\nRates, read from the pricing page on 2026-07-26:\n\n| | Standard | Infrequent Access |\n| --- | --- | --- |\n| Storage | $0.015 / GB-month | $0.01 / GB-month |\n| Class A (writes, lists) | $4.50 / million | $9.00 / million |\n| Class B (reads) | $0.36 / million | $0.90 / million |\n| Data retrieval | none | $0.01 / GB |\n| Egress to the internet | free | free |\n| Free each month | 10 GB-month, 1M Class A, 10M Class B | none; the free tier is Standard only |\n| Minimum storage duration | none | 30 days |\n\nCloudflare rounds usage up to the next unit: 1,000,001 operations bills as two million, 1.1 GB-month bills as 2 GB-month.\n\n[[embed:source:s1]]\n\nA reader of that same page put the obvious objection plainly.\n\n[[embed:source:s21]]\n\nHe is describing the meter correctly and drawing the wrong conclusion. Price the overage. Class B beyond the free 10 million costs $0.36 per additional million. On the ten-terabyte workload computed below, the S3 egress line is $891.00. For R2's metered operations to cost that much, you would have to make **2.475 billion** Class B calls beyond the free allowance in one month: 891 ÷ 0.36 × 1,000,000. The class-ops meter is real. It is roughly three orders of magnitude away from being the thing that costs you money.\n\n## Serving 10 TB a month: $18.45 on R2, $923.00 on S3\n\nThe workload: 1,000 GB stored, average object 500 KB (so 2,000,000 objects), 200,000 new objects written during the month, and 10,000 GB served to the public internet, or 20,000,000 GET requests. S3 prices are `us-east-1`, pulled from the AWS Price List API on 2026-07-26: Standard storage $0.023/GB-month, Tier-1 requests (PUT, COPY, POST, LIST) $0.005 per 1,000, Tier-2 requests (GET and all others) $0.0004 per 1,000, data transfer out to the internet $0.09/GB for the first 10 TB beyond the 100 GB monthly free allowance.\n\n| Line | R2 arithmetic | R2 | S3 arithmetic | S3 |\n| --- | --- | --- | --- | --- |\n| Storage | (1,000 − 10 free) × $0.015 | $14.85 | 1,000 × $0.023 | $23.00 |\n| Writes | 200,000 of 1,000,000 free | $0.00 | 200,000 × $0.005/1,000 | $1.00 |\n| Reads | (20,000,000 − 10,000,000) × $0.36/M | $3.60 | 20,000,000 × $0.0004/1,000 | $8.00 |\n| Egress | 10,000 GB, unmetered | $0.00 | (10,000 − 100) × $0.09 | $891.00 |\n| **Total** | | **$18.45** | | **$923.00** |\n\nFifty times cheaper, and the ratio is almost entirely one line: egress is 96.5% of the S3 bill. The table also shows that R2's operation rates are not a gimmick to claw the egress back. Class A at $4.50/million undercuts S3's Tier-1 at $5.00/million, and Class B at $0.36/million undercuts Tier-2 at $0.40/million. R2 is 10% cheaper per call *and* free on bandwidth.\n\n[[embed:source:s15]]\n\nCloudflare's CTO stated the free-tier gap when R2 launched, and the allowances he named still hold on the page fetched today.\n\n[[embed:source:s19]]\n\nTwo published totals for real public-serving workloads, both itemised. A 33 GB WordPress plugin mirror on R2 plus Workers, and a full archive of every SEC filing served at roughly twice the SEC's own volume:\n\n[[embed:source:s24]]\n\n[[embed:source:s26]]\n\nNeither workload needed versioning, and neither was cold. That is why they land where they do.\n\n## The workload where S3 wins is the one you never read\n\nR2 has exactly two storage classes. S3 has a ladder that goes much colder. For a write-once archive that is almost never read and never leaves the cloud, the egress advantage is worth nothing and the storage floor decides.\n\nThe workload: 100,000 GB (100 TB) of compliance records, written once, read a handful of times a year, consumed inside the same cloud.\n\n| Where it sits | Rate | Monthly |\n| --- | --- | --- |\n| R2 Standard | (100,000 − 10) × $0.015 | $1,499.85 |\n| R2 Infrequent Access | 100,000 × $0.01 (no free tier applies) | $1,000.00 |\n| S3 Glacier Flexible Retrieval | 100,000 × $0.0036 | $360.00 |\n| S3 Deep Archive Access tier | 100,000 × $0.00099 | $99.00 |\n\nR2's cheapest class costs 2.8× the Glacier Flexible rate and 10.1× the Deep Archive rate. There is no colder tier to move to; Standard and Infrequent Access are the whole ladder. If your bytes are cold and captive, stay on S3.\n\n[[embed:source:s5]]\n\nThe person who ran both and stayed on AWS drew the boundary in one sentence.\n\n[[embed:source:s22]]\n\n## Infrequent Access pays only below about one read every two months\n\nInfrequent Access looks like a third off the storage price. The retrieval fee eats it almost immediately. Take a 1 GB object held for one month and read `r` times:\n\n- Standard: `$0.015 + r × $0.00000036`\n- Infrequent Access: `$0.010 + r × $0.0000009 + r × 1 GB × $0.01`\n\nSet them equal: `0.005 = 0.01000054r`, so `r ≈ 0.5`. The retrieval fee is 99.99% of the right-hand side; the operation-rate difference is noise. **A 1 GB object must be read less than once every two months for Infrequent Access to be cheaper.** Add the 30-day minimum billing duration, where you pay a full month even if you delete on day two, and the class is for backups and cold originals, nothing else.\n\nMove objects there with a lifecycle rule rather than by hand. The transition itself is billed as a Class A operation.\n\n```bash\nnpx wrangler r2 bucket lifecycle add miscsubjects-ledger \\\n  --name \"archive-old-events\" \\\n  --prefix \"events/\" \\\n  --storage-class InfrequentAccess \\\n  --transition-days 30\n```\n\nLifecycle rules also delete: an expiration rule on a prefix is how an ingest bucket stops growing forever, and how incomplete multipart uploads get cleaned up. They expire after 7 days by default. A bucket accepts up to 1,000 rules.\n\n[[embed:source:s6]]\n\n## R2 will not keep the old version of an object\n\nThis is the gap that costs people data. When you `put` to a key that already exists, the previous bytes are gone.\n\n[[embed:source:s23]]\n\nThe S3 compatibility table marks `PutBucketVersioning`, `GetBucketVersioning`, `PutObjectLockConfiguration` and `GetObjectLockConfiguration` all unsupported. Versioning and Object Lock are the two standard defences against ransomware and against a human running the wrong script; R2 offers neither in S3's form.\n\n[[embed:source:s4]]\n\nIt does have **bucket locks**, a per-prefix retention rule blocking deletion and overwriting for a fixed period or indefinitely, enforced with `10069 / ObjectLockedByBucketPolicy` and HTTP 403. That stops deletion. It does not give you \"fetch me yesterday's copy\".\n\n[[embed:source:s7]]\n\nFor that you write versioning yourself: never overwrite a key, always write a new one, keep a pointer.\n\n```js\n// Content-addressed writes: the key carries the version, so nothing is ever overwritten.\nexport async function putVersioned(env, logicalKey, body, contentType) {\n  const bytes = body instanceof ArrayBuffer ? body : new TextEncoder().encode(body);\n  const digest = await crypto.subtle.digest('SHA-256', bytes);\n  const hash = [...new Uint8Array(digest)].map(b => b.toString(16).padStart(2, '0')).join('');\n  const versionKey = `${logicalKey}/${Date.now()}-${hash.slice(0, 12)}`;\n  await env.R2.put(versionKey, bytes, { httpMetadata: { contentType } });\n  // The pointer is one small object; reading it is one Class B call.\n  await env.R2.put(`${logicalKey}/current`, versionKey, {\n    httpMetadata: { contentType: 'text/plain' },\n  });\n  return { versionKey, hash };\n}\n\nexport async function getCurrent(env, logicalKey) {\n  const ptr = await env.R2.get(`${logicalKey}/current`);\n  if (!ptr) return null;\n  return env.R2.get(await ptr.text());   // second Class B call\n}\n```\n\nThe cost of doing it this way: every read is two Class B operations instead of one, and old versions accumulate until a lifecycle rule expires them. At $0.36 per million reads, the doubled read is $0.36 per million objects fetched. That is the actual price of the missing feature.\n\n## The free-egress trust question, answered from the terms\n\nThe sharpest objection is not about the price list but about whether it is load-bearing.\n\n[[embed:source:s25]]\n\nThe worry points at a real clause, and the clause says the opposite of what it assumes. Cloudflare's Service-Specific Terms restrict the **CDN** on Free, Pro and Business plans: *\"Unless you are an Enterprise customer, Cloudflare offers specific Paid Services (e.g., the Developer Platform, Images, and Stream) that you must use in order to serve video and other large files via the CDN.\"* The Developer Platform named there is the thing R2 belongs to. Using R2 to serve large files is the compliant path, not the risky one.\n\nThe Developer Platform section carries its own limit, and it is a different kind: *\"Cloudflare may temporarily limit your storage and/or the number of requests you can make or receive using the Developer Platform if processing such requests would put an undue burden on the Cloudflare network.\"* Rate limiting, stated in advance. Not a retroactive per-GB bill.\n\nVerdict: the enforcement risk on R2 is throttling under abnormal load, not an undisclosed egress charge. The pricing page's footnote is unambiguous: *\"Egressing directly from R2, including via the Workers API, S3 API, and r2.dev domains does not incur data transfer (egress) charges and is free.\"* What it does not cover is metered services you bolt on top; those bill separately.\n\n[[embed:source:s14]]\n\n## Every call, and which meter it hits\n\nBind the bucket first. In `wrangler.toml`:\n\n```toml\n[[r2_buckets]]\nbinding = \"R2\"\nbucket_name = \"miscsubjects-ledger\"\n```\n\n`binding` is the variable name your code sees; `bucket_name` is the real bucket. Create the bucket before the first deploy, or the binding fails:\n\n```bash\nnpx wrangler r2 bucket create miscsubjects-ledger\nnpx wrangler r2 bucket list\n```\n\n| Call | What it does | Meter |\n| --- | --- | --- |\n| `env.R2.put(key, value, opts)` | Stores bytes; returns an `R2Object`. Strongly consistent: once the promise resolves, every reader worldwide sees it | Class A |\n| `env.R2.get(key, opts)` | Returns `R2ObjectBody` with `.body` as a stream, or `null` if absent | Class B |\n| `env.R2.head(key)` | Metadata only, no body, or `null` | Class B |\n| `env.R2.list(opts)` | Up to 1,000 keys, lexicographic, `opts.prefix` to scope | Class A |\n| `env.R2.delete(key or key[])` | Up to 1,000 keys per call | free |\n| `env.R2.createMultipartUpload(key)` | Starts a multipart upload | Class A |\n| `upload.uploadPart(n, body)` | One part; all non-final parts must be the same size and ≥ 5 MiB | Class A each |\n| `upload.complete(parts)` | Finishes it | Class A |\n\n[[embed:source:s3]]\n\nNote the trap in that table: **`list` is a Class A operation**, priced 12.5× a read. A paginated file browser that lists on every page view burns the expensive quota, not the cheap one.\n\nA single `put` accepts up to 5 GiB. Above that, multipart, or you get `100100 / EntityTooLarge`:\n\n```js\nconst upload = await env.R2.createMultipartUpload('big/archive.tar');\nconst parts = [];\nlet n = 1;\nfor (const chunk of chunksOf(stream, 16 * 1024 * 1024)) {   // 16 MiB, uniform\n  parts.push(await upload.uploadPart(n++, chunk));\n}\nawait upload.complete(parts);\n```\n\nFrom outside a Worker, use the S3 API against `https://<ACCOUNT_ID>.r2.cloudflarestorage.com` with `region: \"auto\"`, or hand a browser a presigned URL so it uploads straight to R2 without the bytes passing through your server:\n\n```js\nimport { AwsClient } from 'aws4fetch';\n\nconst r2 = new AwsClient({ accessKeyId: ACCESS_KEY_ID, secretAccessKey: SECRET_ACCESS_KEY });\nconst url = new URL(`https://${ACCOUNT_ID}.r2.cloudflarestorage.com/my-bucket/uploads/${name}`);\nurl.searchParams.set('X-Amz-Expires', '3600');           // seconds\nconst signed = await r2.sign(new Request(url, { method: 'PUT' }), {\n  aws: { signQuery: true, service: 's3' },\n});\n// signed.url is safe to hand to a browser; it expires in one hour.\n```\n\nTamper with any signature parameter and the request fails with `10035 / SignatureDoesNotMatch`; let it age out and you get `10018 / ExpiredRequest`.\n\n[[embed:source:s9]]\n\n## Serving an object publicly, and the header that decides your bill\n\nThree ways to make a bucket readable from the internet. A **custom domain** puts it behind a hostname on your zone, the only option that gets Cloudflare Cache, WAF rules and Bot Management. An **r2.dev subdomain** is one toggle, documented as non-production. A **Worker route** gives you the object plus whatever logic you put in front of it. The third, in nine lines:\n\n[[embed:source:s8]]\n\n```js\n// functions/img/[[path]].js: every /img/* URL is an R2 key.\nexport async function onRequestGet(context) {\n  const { params, env } = context;\n  const key = 'img/' + (Array.isArray(params.path) ? params.path.join('/') : String(params.path || ''));\n  if (!env.R2) return new Response('no R2', { status: 500 });\n  const obj = await env.R2.get(key);\n  if (!obj) return new Response('not found', { status: 404 });\n  const ct = obj.httpMetadata?.contentType || 'image/png';\n  return new Response(obj.body, { headers: { 'content-type': ct, 'cache-control': 'public, max-age=31536000' } });\n}\n```\n\nThe URL path *is* the object key: no media table, no second name for a file, and a rename is a copy.\n\n`cache-control: public, max-age=31536000` is the line that matters financially. Cached responses never reach R2, so they cost no Class B operation. Fetched live, the header comes back on the wire:\n\n```text\n$ curl -sI https://miscsubjects.com/img/up/cloudflare-os-r2-hero-card.png\nHTTP/2 200\ncontent-type: image/png\ncontent-length: 51205\ncache-control: public, max-age=31536000\ncf-cache-status: MISS\ncf-ray: a210b8bcbb715616-SJC\n```\n\nA one-year max-age is only safe because a changed image is written under a new key, never patched in place. Serve mutable objects this way and you will serve stale bytes for a year.\n\n[[embed:source:s17]]\n\nCache-hit ratio is not a rounding error on the bill:\n\n[[embed:source:s20]]\n\n## When a row outgrows D1, the bytes move to R2 and the row keeps a pointer\n\nD1, the SQLite database in the same account ([D1 as the spine](/a/cloudflare-os-d1)), has a hard per-value ceiling: **2,000,000 bytes** for any string, BLOB or row. Exceed it and every write to that row fails with `D1_ERROR: string or blob too big`, the driver's rendering of SQLite's `SQLITE_TOOBIG`.\n\nThis application hit that wall storing article revision history. Each write snapshots the previous version — full body, claims and sources — into a JSON blob on the row. One article's metadata reached **2,068,258 bytes** across 24 snapshots, 68,258 over the cap, and from then on every write to it returned HTTP 500.\n\nThe fix generalises into a rule: **when a field outgrows its row, the field moves to object storage and the row keeps a pointer plus a hash.** The pointer is small and fixed-size; the hash is what makes the pointer trustworthy.\n\nThe key format is one line in `functions/_lib/revisions_r2.js`:\n\n```js\nconst PREFIX = \"revisions/\";\nfunction r2Key(slug, n) { return `${PREFIX}${slug}/${n}.json`; }\n```\n\nSo revision 3 of this article lives at `revisions/cloudflare-os-r2/3.json`. What stays in D1 is a nine-field index entry, written by the same function:\n\n```js\nreturn {\n  n: full.n, ts: full.ts, title: full.title, status: full.status,\n  register: full.register, bytes: full.body.length,\n  prev_hash: full.prev_hash, hash: full.hash,\n  r2_key: key,\n};\n```\n\n`prev_hash` and `hash` are the point: the chain is verifiable from D1 alone, no R2 read needed to prove the history has not been edited, while the bytes are fetched only when someone asks for a specific revision. That 2,068,258-byte row became **206,362 bytes**, and the original revision is still retrievable.\n\n[[embed:source:s16]]\n\nMeasured across the bucket today: 4,930 objects under `revisions/`, 148,075,146 bytes, 1,053 distinct articles, mean 30,036 bytes per revision. The largest single history, `revisions/bpc-157/`, is 119 objects and 14,503,688 bytes — 7.25× the D1 row cap, so that article alone would be permanently unwritable under the old scheme.\n\nProof the offload preserved the history rather than truncating it:\n\n```bash\n$ curl -s \"https://miscsubjects.com/api/articles/cloudflare-os-r2?rev=0\" | jq '{rev,is_head,prev_hash,body_len:(.body|length)}'\n{ \"rev\": 0, \"is_head\": false, \"prev_hash\": \"genesis\", \"body_len\": 2878 }\n```\n\nThat body came out of R2. Nothing but the index is in the database.\n\n## Choosing between R2, S3, KV, D1 and Durable Object storage\n\n| Workload | Put it in | Why, and the limit that decides it |\n| --- | --- | --- |\n| Images, video, uploads, anything served to the public internet | **R2** | Free egress; 5 TiB per object; strongly consistent |\n| Cold archive, rarely read, consumed inside AWS | **S3 Glacier** | $0.0036–$0.00099/GB-month against R2's $0.01 floor |\n| A file with a legal retention requirement and a need to read yesterday's copy | **S3** | R2 has bucket locks but no object versioning |\n| Small values read constantly from many places — flags, prompts, rendered snapshots | **Workers KV** | Values to 25 MiB, but eventually consistent and 1 write/second per key |\n| Anything you need to query, join, filter or index | **D1** | 10 GB per database, 2 MB per value; a bucket cannot answer `WHERE` |\n| Per-entity state needing serialized writes and coordination | **Durable Object storage** | 10 GB per object, single-threaded execution ([the Workers layer](/a/cloudflare-os-workers)) |\n| A row that has outgrown 2 MB | **R2, with a pointer in D1** | The offload pattern above |\n| Blobs written and read once, under 25 MiB, with no need for a URL | **either KV or R2** | R2 unless you need sub-millisecond reads at the edge |\n\n[[embed:source:s10]]\n\n[[embed:source:s11]]\n\n[[embed:source:s12]]\n\n[[embed:source:s13]]\n\nTwo failure modes worth naming: KV used as a database (eventually consistent, so a read after a write may return the old value), and R2 used as a database (no query, only a lexicographic key scan at Class A prices).\n\n## Symptom, cause, fix\n\n| Symptom | Cause | Fix |\n| --- | --- | --- |\n| `no R2 binding` / `no R2`, HTTP 500 | The Worker deployed without the `r2_buckets` entry, or the bucket does not exist yet | `npx wrangler r2 bucket create <name>`, then confirm the `[[r2_buckets]]` block is present in every environment, including `[[env.preview.r2_buckets]]` |\n| `10006 / NoSuchBucket`, HTTP 404 | Bucket name typo, or the bucket is in a different account | `npx wrangler r2 bucket list` and compare byte for byte |\n| `get()` returns `null` instead of throwing | Not an error — the Workers API returns `null` for a missing key rather than raising `NoSuchKey` | Branch on `null`; do not wrap in `try/catch` and expect a throw |\n| `100100 / EntityTooLarge`, HTTP 400 | Single-part upload over 5 GiB | Switch to `createMultipartUpload`; parts uniform and ≥ 5 MiB |\n| `10011 / EntityTooSmall` or `10048 / InvalidPart`, HTTP 400 | A non-final part under 5 MiB, or parts of differing sizes | Every part except the last must be ≥ 5 MiB and identical in size |\n| `10058 / TooManyRequests`, HTTP 429 | More than one write per second to the same key | Shard the key, or funnel writes for that key through a Durable Object |\n| `10035 / SignatureDoesNotMatch`, HTTP 403 | A presigned URL was edited, or the secret is wrong | Regenerate; check URL encoding of the key |\n| `10069 / ObjectLockedByBucketPolicy`, HTTP 403 | A bucket lock retention rule covers that prefix | Wait out the retention period; a lock is not overridable |\n| `D1_ERROR: string or blob too big` on a write that used to work | A JSON column crossed D1's 2,000,000-byte per-value cap | Offload the heavy field to R2, keep a pointer and a hash in the row |\n| `wrangler r2 object put --file` fails with `fetch failed` | Reported against Wrangler 3.74.0 and still open | Pipe the file instead: `cat f.txt \\| npx wrangler r2 object put bucket/f.txt --pipe` |\n| Multipart `complete()` returns empty `customMetadata` in production but not in `wrangler dev` | Open bug, reported against Wrangler 3.57.2 | Re-read with `head()` after completing; the metadata is stored, only the return value drops it |\n\n## How the numbers on this page were measured\n\nFour measurements, taken 2026-07-26 against the live production bucket from a laptop served by the San Jose edge (`cf-ray` suffix `SJC`).\n\n[[embed:source:s27]]\n\n**1 — Buckets and inventory.** `npx wrangler r2 bucket list` returns three buckets: `loop-data-raw` (2026-05-31), `miscsubjects-ledger` (2026-06-09), `miscsubjects-store` (2026-06-16). The inventory of `miscsubjects-ledger` was walked through the authenticated list route, 1,000 keys per page, following the cursor:\n\n```bash\ncurl -s -H \"x-terminal-key: $TERMINAL_KEY\" \\\n  \"https://miscsubjects.com/api/r2/?list=1&limit=1000&cursor=$CURSOR\"\n```\n\n62 pages, **41,809 objects, 3,904,595,147 bytes (3.64 GiB)** — under the 10 GB free allowance, so today's storage line is $0.00. By prefix: `events/` 34,258 objects / 2,241 MB; `revisions/` 4,930 / 148 MB; `img/gen/` 387 / 765 MB; `img/up/` 191 / 432 MB; `docs/` 1,332 / 9.5 MB. The walk itself cost 62 Class A operations.\n\n**2 — Put and get latency.** A 65,536-byte JSON object written and read six times each over one reused TLS connection, at the deliberately-named temporary key `tmp/measure-2026-07-25-delete-me.json`, then deleted — `DELETE` returned `{\"ok\":true,...,\"deleted\":true}` and a follow-up list of `tmp/` returned zero objects.\n\n```bash\ncurl -s -X PUT \"https://miscsubjects.com/api/r2/tmp/measure-2026-07-25-delete-me.json\" \\\n  -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' \\\n  --data-binary @probe.json -w \"%{time_total}\\n\"\n```\n\nPUT round trips: 535, 587, 634, 737, 801, 2,471 ms — median **686 ms**. GET: 96, 104, 125, 148, 185, 192 ms — median **136 ms**. These are full client-to-edge-to-R2-to-client times through the Worker, not R2's internal service time; the first request in each series carries the TLS handshake, 86 ms and 71 ms.\n\n**3 — Public object headers.** `curl -sI https://miscsubjects.com/img/up/cloudflare-os-r2-hero-card.png` returned HTTP 200, `content-length: 51205`, `content-type: image/png`, `cache-control: public, max-age=31536000`, `cf-cache-status: MISS`. Full body fetch, 189 ms.\n\n[[embed:source:s18]]\n\n**4 — A revision read out of R2.** `curl -s \"https://miscsubjects.com/api/articles/cloudflare-os-r2?rev=0\"` returned `rev: 0`, `is_head: false`, `prev_hash: \"genesis\"`, `hash: 24915ae889f6184140a56e89d476d28a31e0cf0e28d31c0990c2aab6f7a626fc`, body length 2,878 — out of `revisions/cloudflare-os-r2/0.json`, not the database. Account identifiers are omitted throughout; the S3 endpoint appears as `<ACCOUNT_ID>.r2.cloudflarestorage.com`.\n\nThe index for the rest of this stack is [the Cloudflare account as an operating system](/a/cloudflare-os).\n","register":"essay","tags":["cloudflare","architecture","r2","cloudflare-os"],"style":{},"claims":[{"id":"c1","text":"R2 charges for stored bytes and Class A and B operations, but not internet egress.","section":"Zero egress is real; the meter is on the operations","tier":"system","source_ids":["s1","s19","s21"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c2","text":"At the published rates, the worked 1 TB stored and 10 TB served workload costs $18.45 on R2 and $923.00 on S3.","section":"Serving 10 TB a month: $18.45 on R2, $923.00 on S3","tier":"system","source_ids":["s1","s15"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c3","text":"R2 operation rates are lower than the compared S3 Standard request rates, so operations do not claw back the egress saving in the worked workload.","section":"Serving 10 TB a month: $18.45 on R2, $923.00 on S3","tier":"system","source_ids":["s1","s15","s21"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c4","text":"For a 100 TB cold archive consumed inside AWS, R2 Infrequent Access costs $1,000 monthly while S3 Glacier Flexible Retrieval costs $360 and Deep Archive costs $99.","section":"The workload where S3 wins is the one you never read","tier":"system","source_ids":["s1","s15","s22","s5"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c5","text":"For a 1 GB object, R2 Infrequent Access becomes cheaper than Standard only below about one read every two months, before considering its 30-day minimum.","section":"Infrequent Access pays only below about one read every two months","tier":"system","source_ids":["s1","s5","s6"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c6","text":"R2 does not implement S3 bucket versioning or S3 Object Lock operations; bucket locks prevent overwrite and deletion but do not retain prior versions.","section":"R2 will not keep the old version of an object","tier":"system","source_ids":["s23","s4","s7"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c7","text":"Content-addressed writes plus a current-pointer object provide application-level versioning at the cost of an extra read and retained old objects.","section":"R2 will not keep the old version of an object","tier":"system","source_ids":["s16","s3","s6"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c8","text":"Cloudflare's terms permit large-file delivery through paid Developer Platform services and reserve temporary rate limiting for undue network burden.","section":"The free-egress trust question, answered from the terms","tier":"system","source_ids":["s1","s14","s25"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c9","text":"R2 writes and deletes are strongly consistent, while listing is a Class A operation and reads are Class B.","section":"Every call, and which meter it hits","tier":"system","source_ids":["s1","s2","s3"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c10","text":"A single-part R2 upload is limited to 5 GiB; larger objects require multipart upload and top out just below 5 TiB.","section":"Every call, and which meter it hits","tier":"system","source_ids":["s10","s3"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c11","text":"Presigned URLs authorize one named operation on one object until expiry without exposing the signing credentials.","section":"Every call, and which meter it hits","tier":"system","source_ids":["s16","s9"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c12","text":"A custom domain is the production public-bucket path; r2.dev is rate-limited and documented for non-production use.","section":"Serving an object publicly, and the header that decides your bill","tier":"system","source_ids":["s10","s17","s8"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c13","text":"The production public-object handler maps the URL path to the R2 key and sends a one-year public cache lifetime.","section":"Serving an object publicly, and the header that decides your bill","tier":"system","source_ids":["s20","s27","s3"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c14","text":"Moving oversized revision payloads to R2 reduced one article's D1 revision index from 2,068,258 bytes to 206,362 bytes while preserving revision retrieval.","section":"When a row outgrows D1, the bytes move to R2 and the row keeps a pointer","tier":"system","source_ids":["s12","s27"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c15","text":"The storage choice follows the access pattern: R2 for public blobs, S3 Glacier for captive cold archives, KV for small read-mostly values, D1 for queries, and Durable Objects for serialized state.","section":"Choosing between R2, S3, KV, D1 and Durable Object storage","tier":"system","source_ids":["s10","s11","s12","s13","s22"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c16","text":"The measured production bucket held 41,809 objects and 3,904,595,147 bytes across 62 list pages on 2026-07-26.","section":"How the numbers on this page were measured","tier":"system","source_ids":["s27"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c17","text":"Six production PUTs had a 686 ms median and six GETs had a 136 ms median through the Worker from the San Jose edge.","section":"How the numbers on this page were measured","tier":"system","source_ids":["s18","s27"],"why_material":"This changes the storage choice, bill, implementation, or failure response."},{"id":"c18","text":"Published operators report a $5.35 monthly WordPress mirror and a $10.80 monthly SEC archive on R2, while another operator stays on S3 for cold and AWS-integrated workloads.","section":"Serving 10 TB a month: $18.45 on R2, $923.00 on S3","tier":"system","source_ids":["s22","s24","s26"],"why_material":"This changes the storage choice, bill, implementation, or failure response."}],"sources":[{"id":"s1","type":"publisher_documentation","url":"https://developers.cloudflare.com/r2/pricing/","title":"Cloudflare R2 pricing","quote":"There are no charges for egress bandwidth for any storage class.","summary":"The current Standard and Infrequent Access storage, operation, retrieval, free-tier and rounding rates.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c1","c2","c3","c4","c5","c8","c9"]},{"id":"s2","type":"publisher_documentation","url":"https://developers.cloudflare.com/r2/how-r2-works/","title":"How R2 works","quote":"Cloudflare R2 is an S3-compatible object storage service with no egress fees, built on Cloudflare's global network.","summary":"Defines R2, its interfaces and its strong-consistency architecture.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c9"]},{"id":"s3","type":"specification","url":"https://developers.cloudflare.com/r2/api/workers/workers-api-reference/","title":"Workers R2 API reference","quote":"R2 writes are strongly consistent. Once the Promise resolves, all subsequent read operations will see this key value pair globally.","summary":"The exact binding methods, limits and consistency contract used by the runnable examples.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c10","c13","c7","c9"]},{"id":"s4","type":"specification","url":"https://developers.cloudflare.com/r2/api/s3/api/","title":"S3 API compatibility","quote":"When using the S3 API, the region for an R2 bucket is auto","summary":"The implemented and unsupported S3 operations, including the absent versioning and Object Lock calls.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c6"]},{"id":"s5","type":"publisher_documentation","url":"https://developers.cloudflare.com/r2/buckets/storage-classes/","title":"R2 storage classes","quote":"Infrequent Access storage is ideal for data that is accessed less frequently.","summary":"Documents the retrieval fee and 30-day minimum that determine when Infrequent Access pays.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c4","c5"]},{"id":"s6","type":"publisher_documentation","url":"https://developers.cloudflare.com/r2/buckets/object-lifecycles/","title":"R2 object lifecycles","quote":"Object lifecycles determine the retention period of objects uploaded to your bucket and allow you to specify when objects should transition from Standard storage to Infrequent Access storage.","summary":"The transition and expiration rules used to control cold storage and stale multipart uploads.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c5","c7"]},{"id":"s7","type":"publisher_documentation","url":"https://developers.cloudflare.com/r2/buckets/bucket-locks/","title":"R2 bucket locks","quote":"Bucket locks prevent the deletion and overwriting of objects in an R2 bucket for a specified period — or indefinitely.","summary":"The retention control R2 offers in place of S3 Object Lock, and its exact boundary.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c6"]},{"id":"s8","type":"publisher_documentation","url":"https://developers.cloudflare.com/r2/buckets/public-buckets/","title":"R2 public buckets","quote":"Expose your bucket using a Cloudflare-managed https://r2.dev subdomain for non-production use cases.","summary":"The three public-serving paths and the non-production status of r2.dev.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c12"]},{"id":"s9","type":"specification","url":"https://developers.cloudflare.com/r2/api/s3/presigned-urls/","title":"R2 presigned URLs","quote":"Presigned URLs are generated client-side with no communication with R2, requiring only your R2 API credentials and an implementation of the AWS Signature Version 4 signing algorithm.","summary":"The exact signing model for direct browser uploads and expiring downloads.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c11"]},{"id":"s10","type":"publisher_documentation","url":"https://developers.cloudflare.com/r2/platform/limits/","title":"R2 limits","quote":"5 GiB (single-part) / 4.995 TiB (multi-part)","summary":"The current object, key, metadata, multipart and managed-public-bucket limits.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c10","c12","c15"]},{"id":"s11","type":"publisher_documentation","url":"https://developers.cloudflare.com/kv/platform/limits/","title":"Workers KV limits","quote":"25 MiB","summary":"The maximum KV value size used in the storage decision table.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c15"]},{"id":"s12","type":"publisher_documentation","url":"https://developers.cloudflare.com/d1/platform/limits/","title":"D1 limits","quote":"2,000,000 bytes (2 MB)","summary":"The exact D1 string, BLOB and row ceiling behind the R2 offload pattern.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c14","c15"]},{"id":"s13","type":"publisher_documentation","url":"https://developers.cloudflare.com/durable-objects/platform/limits/","title":"Durable Objects limits","quote":"Each SQLite-backed Durable Object has a storage limit of 10 GB on a Workers Paid plan.","summary":"The per-object storage ceiling used in the storage decision table.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c15"]},{"id":"s14","type":"publisher_documentation","url":"https://www.cloudflare.com/service-specific-terms-developer-platform/","title":"Cloudflare Developer Platform terms","quote":"Cloudflare may temporarily limit your storage and/or the number of requests you can make or receive using the Developer Platform if processing such requests would put an undue burden on the Cloudflare network","summary":"The contractual boundary for Developer Platform rate limiting.","author":"","publisher":"Cloudflare","date":"2026-07-26","claim_ids":["c8"]},{"id":"s15","type":"specification","url":"https://pricing.us-east-1.amazonaws.com/offers/v1.0/aws/AmazonS3/current/us-east-1/index.json","title":"AWS S3 us-east-1 Price List API","quote":"$0.023 per GB - first 50 TB / month of storage used","summary":"Machine-readable AWS storage and request rates used in the 1 TB plus 10 TB comparison.","author":"","publisher":"Amazon Web Services","date":"2026-07-26","claim_ids":["c2","c3","c4"]},{"id":"s16","type":"github","url":"https://github.com/cloudflare/cloudflare-docs/issues/19190","title":"Clarify presigned URL docs","quote":"I did notice that after reading through the entire documentation and those linked pages.","summary":"A repository issue showing a real presigned-URL integration failure and the documentation repair.","author":"harshil1712","publisher":"GitHub — cloudflare/cloudflare-docs","date":"2025-01-22","claim_ids":["c11","c7"]},{"id":"s17","type":"github","url":"https://github.com/cloudflare/workers-sdk/issues/3520","title":"Unable to put an object with a key containing three dots to R2","quote":"Failed to fetch /accounts/*/r2/buckets/*/objects/assets/_...slug_.abcd1234.css - 403: Forbidden","summary":"A minimal Wrangler/R2 path-handling failure, visible in the product repository issue tracker.","author":"tkngaejcpi","publisher":"GitHub — cloudflare/workers-sdk","date":"2023-06-25","claim_ids":["c12"]},{"id":"s18","type":"independent_measurement","url":"https://aimultiple.com/cloud-object-storage","title":"Cloud object storage benchmark","quote":"All tests ran from Europe against each provider’s EU-region endpoint.","summary":"An independent five-provider benchmark with geography, file sizes, throughput and latency published with its method.","author":"Sedat Dogan","publisher":"AIMultiple","date":"2026-06-16","claim_ids":["c17"]},{"id":"s19","type":"hn","url":"https://news.ycombinator.com/item?id=31314273","title":"The next chapter for Cloudflare Workers: open-source","quote":"So, with R2 you get unlimited egress, 500x the free limit on requests and flat global pricing. Oh, and the actual storage is cheaper.","summary":"Cloudflare's CTO laying out the free-tier comparison against S3 with exact numbers (10M vs 20k GETs, 1M vs 2k PUTs, unlimited vs 100GB egress). Positive, and a vendor employee speaking first-hand rather than a docs page.","author":"jgrahamc","publisher":"Hacker News","date":"2022-05-09","claim_ids":["c1"]},{"id":"s20","type":"hn","url":"https://news.ycombinator.com/item?id=36392670","title":"How Canva saves Amazon S3 costs","quote":"See the Docker x Cloudflare case study where improving cache-hit ratio by 2% (by moving to R2) decreased S3 egress fee by 66%","summary":"Cites a concrete egress number in an S3-cost thread: a 2% cache-hit-ratio improvement from moving to R2 cut Docker's S3 egress bill by 66%. Positive, with a hard percentage.","author":"ignoramous","publisher":"Hacker News","date":"2023-06-19","claim_ids":["c13"]},{"id":"s21","type":"hn","url":"https://news.ycombinator.com/item?id=41753985","title":"WordPress Plugin Mirror Downloader (Proof of Concept)","quote":"All up, it would be US$5.35/month starting costs which will rise as number of WordPress plugins and Worker usage increases as outlined here. Cloudflare CDN bandwidth is free of charge, so no need to worry about egress bandwidth fees.","summary":"Full cost breakdown for a real 33GB WordPress plugin mirror on R2 + Workers: under $0.35/month storage, Class A/B ops inside the free quota, 765K Worker requests/day at 2.1ms median CPU, total $5.35/month. Positive, with itemized numbers.","author":"3eb7988a1663","publisher":"Hacker News","date":"2024-10-06","claim_ids":["c1","c3"]},{"id":"s22","type":"hn","url":"https://news.ycombinator.com/item?id=47700966","title":"Ask HN: S3(AWS) vs R2(CF)–Which is better?","quote":"R2's zero egress pricing is genuinely compelling for anything serving large files publicly - media, assets, user uploads. If your use case is \"store stuff and serve it to users,\" R2 wins on cost.","summary":"Runs multi-region on AWS and stays on S3 because of IAM/CloudFront/ECS/Lambda integration, but says R2 wins outright when the workload is serve-to-users and bandwidth is a real line item. Mixed — a clear statement of where the egress saving does and does not pay.","author":"JoshBlythe","publisher":"Hacker News","date":"2026-04-09","claim_ids":["c15","c18","c4"]},{"id":"s23","type":"hn","url":"https://news.ycombinator.com/item?id=42257068","title":"Comparing AWS S3 with Cloudflare R2: Price, Performance and User Experience","quote":"It's not mentioned, but important to note, that R2 lacks object versioning.","summary":"Flags missing object versioning as an omission from the comparison. A downstream reply notes versioning and Object Lock are core malware/human-error protections; others say you must reimplement versioning yourself in a Worker. Negative.","author":"kevlened","publisher":"Hacker News","date":"2024-11-27","claim_ids":["c6"]},{"id":"s24","type":"hn","url":"https://news.ycombinator.com/item?id=33865229","title":"Hetzner continues its growth in the US with a new location","quote":"They claim $0 egress fees, but their free \"Class A operations (mutate state)\" and \"Class B operations (read state)\" have a mothly cap. After that you pay by the number. Isn't that an egress free?","summary":"Reader of the R2 pricing page arguing the \"$0 egress\" claim is undercut by metered Class A/B operations once the monthly free cap is exceeded. Negative — the class-ops gotcha stated plainly.","author":"Archelaos","publisher":"Hacker News","date":"2022-12-05","claim_ids":["c18"]},{"id":"s25","type":"hn","url":"https://news.ycombinator.com/item?id=42257094","title":"Comparing AWS S3 with Cloudflare R2: Price, Performance and User Experience","quote":"Is R2 egress actually free, or is it like CFs CDN egress which is \"free\" until they arbitrarily decide you're using it too much or using it for the wrong things so now you have to pay $undisclosed per GB?","summary":"Questions whether R2's free egress carries the same undisclosed enforcement risk as Cloudflare CDN bandwidth. Spawned a long subthread about Cloudflare terminating heavy or disfavoured users. Negative.","author":"jsheard","publisher":"Hacker News","date":"2024-11-27","claim_ids":["c8"]},{"id":"s26","type":"reddit","url":"https://old.reddit.com/r/CloudFlare/comments/1qhbrey/cloudflare_r2_let_me_serve_almost_twice_as_much/","title":"Cloudflare R2 let me serve almost twice as much data this month as the SEC for $10.80","quote":"I maintain an archive of every SEC filing, accessible via api. I store each filing in R2, compressed with zstandard. I cache egress.","summary":"Full SEC filing archive served from R2 with zstd compression and cached egress, total monthly cost $10.80 while serving roughly twice the SEC's own volume. Positive with a real number, the clearest R2-vs-S3-egress datapoint found.","author":"u/status-code-200","publisher":"Reddit","date":"2026-01-19","claim_ids":["c18"]},{"id":"s27","type":"runtime_receipt","url":"https://miscsubjects.com/img/up/cloudflare-os-r2-hero-card.png","title":"Live R2 object headers","quote":"cache-control: public, max-age=31536000","summary":"First-party production receipt: a 51,205-byte public object returned the cache header shown, with the command and timing published in the article.","author":"","publisher":"miscsubjects.com","date":"2026-07-26","claim_ids":["c13","c14","c16","c17"]}],"prov":{"model":"Opus 5 (Claude Code)","action":"write"}}