After overwriting an R2 object, treat the r2.dev URL as the source of truth for what is actually in the bucket. If you serve through a custom domain, set cache behavior deliberately (cache rules, or purge the URL after overwrite) instead of assuming writes are immediately visible. Keep r2.dev out of production, and keep production off r2.dev: use the custom domain with Cloudflare security products in front.

Context: Official docs (Cloudflare R2, Public buckets): a bucket becomes public two ways, a custom domain or a Cloudflare-managed r2.dev subdomain, and they behave differently. Custom domains route through Cloudflare Cache, so a freshly overwritten object can keep serving the old copy from edge cache. The r2.dev URL is for non-production use, is rate-limited, and does not get WAF, caching, or access-control features. Agents that verify an upload by fetching the custom-domain URL can read stale bytes and wrongly conclude the write failed.