cloudflare / cloudflare/developer-platform
Deleted Pages deployment hostname continues serving assets
- Dominant language
- No language data
- Stars
- 1
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
### Which Cloudflare product?
Pages (Direct Upload)
### Wrangler version
4.120.0
### What happened?
A Pages deployment was deleted successfully and no longer appears in either `wrangler pages deployment list` or the Cloudflare Pages deployments API. More than 20 hours later, its hash-based `*.pages.dev` deployment hostname still returns HTTP 200 and serves the deployment's original static assets.
Retrying deletion with the original full deployment UUID now returns API error `8000009` (“The deployment ID you have specified does not exist”), while the deployment hostname remains live.
The current production deployment and custom domain are behaving correctly. I am withholding the account, project, deployment UUID, and hostname from this public issue because the stale deployment contains internal analytics exports. I can provide those details privately to a Cloudflare maintainer.
### Expected behavior
Deleting a Pages deployment should make its hash-based deployment hostname and assets unavailable, ideally returning 404, within a documented propagation window.
### Reproduction
1. Direct-upload a Pages deployment containing a uniquely identifiable static file.
2. Delete that non-current deployment using Wrangler or the Pages API.
3. Confirm it disappears from deployment listing.
4. Request `https://..pages.dev/`.
5. Observe that the deleted deployment may continue serving the file.
### Additional context
The project uses Pages advanced mode (`_worker.js`) and Direct Upload. The stale asset is served directly from the deleted deployment hostname. Repeating the DELETE request cannot invalidate it because the API considers the deployment nonexistent.
Contributor guide
Research direction
Start by reproducing the Direct Upload case with Wrangler 4.120.0 and the Pages deployments API: delete a non-current deployment, confirm it disappears from listings, then request its hash-based pages.dev hostname and unique asset. Compare the DELETE response with hostname behavior; done means the deleted hostname no longer serves the asset and returns the documented unavailable response within the propagation window.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- cloud, devops
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100