I am using minio on internal upload only. For example, discourse on 192.168.1.5 and minio on 192.168.1.6:9000. When I browse in Chrome, it tries to request 192.168.1.6:9000 which will not work.
I expect it to load from cdn.example.com which like image in post.
This problem seems to happen here as well. If you upload an image, the one you see in preview is discourse-meta.s3.dualstack.us-west-1.amazonaws.com instead of meta-s3-cdn.freetls.fastly.net.
Yeah this is indeed the case, preview does not use CDN, hiding the S3 origin from clients is an unsupported setup atm, longer term I expect even more trouble when we support direct to s3 uploads
I also found out the images uploaded are allowed to view by public. If there are future updates on this, please do not set it if CDN is set. This is because it bypass the bucket policy to enforce all objects must go through CDN.
So I’m still confused here…even with my cloudfront url in the “s3 cdn url”, all uploaded images (in the preview or not) are using the s3.dualstack url and not my cloudfront/cdn url.
This seems like a bug, not a feature, as it requires you to have public ACLs for your s3 bucket. Looks like it has been reported here years ago, but not fixed: S3 CDN URL ignored when uploading into posts