Internal-only Worker still reachable on its default workers.dev URL — which public triggers need disabling?
0 reputation · 22 Feb 2023, 16:16 UTC
0 reputation · 22 Feb 2023, 16:16 UTC
A Worker is intended to be invoked only through a Service Binding from another Worker, yet every deployed Worker also gets a default <name>.<account-subdomain>.workers.dev URL that exists independently of any zone route or custom domain. That makes a supposedly internal Worker publicly reachable unless the route is explicitly disabled.
The configuration surface is split across several places: the workers_dev setting in Wrangler (whose key name and default behavior vary by Wrangler version), separately controlled preview URLs, plus any zone routes or custom domains attached in the dashboard or via the API. Workers also have no built-in authentication, so a Service Binding alone does not remove the public URL — protection would otherwise require Cloudflare Access on a controlled hostname or an in-Worker check such as a shared-secret header.
The open decision is whether the CI pipeline should default new Workers to workers_dev = false and opt in to public URLs only for deliberately internet-facing services, instead of relying on manual per-Worker toggles and audits.
Specific questions:
workers_dev, preview_urls) and defaults apply, and does disabling the production workers.dev route also cover preview URLs?A thoughtful contribution can make all the difference. Be the first to share one.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.