54 lines
2.1 KiB
TypeScript
54 lines
2.1 KiB
TypeScript
import type { Plugin } from 'payload'
|
|
import { s3Storage } from '@payloadcms/storage-s3'
|
|
|
|
/**
|
|
* Cloudflare R2 media storage — configured from environment variables (agency
|
|
* infrastructure, not per-project panel data). R2 is S3-compatible, so we use
|
|
* @payloadcms/storage-s3 pointed at the R2 endpoint.
|
|
*
|
|
* Storage is infrastructure (like the database or PAYLOAD_SECRET): it binds at
|
|
* boot, and its credentials are agency-owned — so it lives in .env, not the
|
|
* panel. See docs/storage.md for the required variables.
|
|
*
|
|
* Returns the storage plugin when all R2 vars are present; otherwise returns a
|
|
* no-op passthrough so the project falls back to Payload's default local disk
|
|
* storage (useful in dev without R2). This mirrors how mailAdapter degrades
|
|
* gracefully when a transport isn't configured.
|
|
*
|
|
* @param collections - slugs of upload collections to offload to R2 (e.g. ['media'])
|
|
*/
|
|
export const buildR2Storage = (collections: string[] = ['media']): Plugin => {
|
|
const bucket = process.env.R2_BUCKET
|
|
const endpoint = process.env.R2_ENDPOINT
|
|
const accessKeyId = process.env.R2_ACCESS_KEY_ID
|
|
const secretAccessKey = process.env.R2_SECRET_ACCESS_KEY
|
|
|
|
// Any missing → skip R2, fall back to local disk. Warn so it's not silent.
|
|
if (!bucket || !endpoint || !accessKeyId || !secretAccessKey) {
|
|
return (config) => {
|
|
// Only warn when SOME vars are set (partial config = likely a mistake).
|
|
if (bucket || endpoint || accessKeyId || secretAccessKey) {
|
|
console.warn(
|
|
'[ipal] R2 storage: incomplete env (need R2_BUCKET, R2_ENDPOINT, ' +
|
|
'R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY). Falling back to local disk.',
|
|
)
|
|
}
|
|
return config
|
|
}
|
|
}
|
|
|
|
const collectionsConfig = Object.fromEntries(collections.map((slug) => [slug, true]))
|
|
|
|
return s3Storage({
|
|
collections: collectionsConfig,
|
|
bucket,
|
|
config: {
|
|
endpoint,
|
|
region: 'auto', // R2 uses 'auto'
|
|
credentials: { accessKeyId, secretAccessKey },
|
|
// R2 requires path-style addressing for S3 compatibility.
|
|
forcePathStyle: true,
|
|
},
|
|
})
|
|
}
|