Skip to content

Cloudflare Access ​

Cloudflare Access is optional: IPA Harbor’s deployment scripts configure Access policies.

The following explains which paths need a Bypass in Cloudflare (allow without Access login) when Access protects the whole site by default, and why.

Paths that need Bypass ​

The iOS / iPadOS OTA install service requests the manifest and ipa file directly. It cannot show the Cloudflare Access login page like a browser.

Add Bypass rules in Access for the routes below (match syntax depends on the Cloudflare dashboard; the table lists IPA Harbor’s actual paths):

Path (example)Why bypass
/v1/ipa/install-package/*/manifest.plistDevice fetches the OTA manifest.plist. IPA Harbor validates a short-lived ticket, not an admin session.
/v1/ipa/getpackage/*/*Device downloads the ipa from the URL in the manifest. Same ticket validation and expiry.
/v1/app/icon/* (if needed)If manifest icon URLs point at IPA Harbor instead of Apple’s CDN, the device must GET icons without Access.

If OTA is disabled, or you only download ipa files from a desktop browser, you usually do not need these Bypass rules—keep Access on the entire hostname.