Would could create a signed R2 URL for CAR file requests and redirect to it instead of serving the CAR. The issues could be * URL will change (due to the redirect) * expiration on redirect URL * rate limiting on R2 URL (not under our control)