English
Cloudflare Access
Cloudflare Access is optional: IPA Harbor’s deployment scripts configure Access policies.
The following explains which paths need a Bypass in Cloudflare (allow without Access login) when Access protects the whole site by default, and why.
Paths that need Bypass
The iOS / iPadOS OTA install service requests the manifest and ipa file directly. It cannot show the Cloudflare Access login page like a browser.
Add Bypass rules in Access for the routes below (match syntax depends on the Cloudflare dashboard; the table lists IPA Harbor’s actual paths):
| Path (example) | Why bypass |
|---|---|
/v1/ipa/install-package/*/manifest.plist | Device fetches the OTA manifest.plist. IPA Harbor validates a short-lived ticket, not an admin session. |
/v1/ipa/getpackage/*/* | Device downloads the ipa from the URL in the manifest. Same ticket validation and expiry. |
/v1/app/icon/* (if needed) | If manifest icon URLs point at IPA Harbor instead of Apple’s CDN, the device must GET icons without Access. |
If OTA is disabled, or you only download ipa files from a desktop browser, you usually do not need these Bypass rules—keep Access on the entire hostname.
Related
- Deploy scripts — Linux server + Cloudflare Tunnel
- When Cloudflare proxies IPA Harbor, set
TRUST_PROXY=1— see Environment variables