It's seriously good value for small websites. Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much the most affordable option as well. And they have a few other things that aren't half bad to use with pretty generous freemium layers.
We used Google's CDN for the last six years or so but it's pretty annoying to deal with and you have to pay for a load balancer every month in order to properly use it. That adds up to quite a bit per year. Even if all you are doing is routing domains to some bucket with a website.
We migrated most of our gcloud stuff to Hetzner beginning of the year. That left a load balancer and a few static websites hosted in Google buckets. I migrated all of that to Cloudflare just a few months ago.
I still have a few buckets in gcloud proxied via a vm in hetzner with a proxied domain in Cloudflare. Not the most elegant route but it works. I might optimize some of that later. At this point, we pay for some Google buckets and not much else in gcloud.
Honestly, Google and AWS need to start paying attention to Cloudflare more. Their complexity is chasing people towards Cloudflare. The hoops you have to jump through with both of them to host a simple website with their CDNs is embarrassing. I've gone through the process with both of them. Although my experience with Route53 is a bit stale at this point. On Cloudflare, getting an new website up and running with a freshly registered domain takes only a few minutes.
Before I went European sovereign for my own personal stack I used Cloudflare for hosting static and somewhat dynamic websites and it has become really nice the later years. There is almost no mention of "regions" in Cloudflare. Your content and code runs globally by default. With traditional clouds you need to think about how you distribute your application. At least that is my experience. Maybe they provide global CDN for global distribution of static content. But serverless containers and databases more or less run in a single region by default. And if you wish to distribute stuff it is on you to plan the architecture behind that.
Now stuff like Cloudflare D1, the distributed SQLite based database, have its limitations. Writes are directed to a specific datacenter/region behind the scenes, so some regions might get slower writes. But this is basically something that happens behind the scenes and just works. You need to think about where your primary base of customers live when you create the database, after that you don't think about regions. R2 (S3 compatible storage) just works globally as well.
A lot of what Cloudflare offers now feels like magic in a good way. I realize they don't have everything AWS, Google Cloud and Azure have. But they have enough that you can build serious systems on top of their infrastructure. They are no longer just a CDN/proxy provider. And their offering is seriously cheap.
Currently I don’t use any CDN. I just host everything on Scaleway on VMs and serverless. Works pretty well for my use, but I imagine latency is bad for South Americans. I’ve looked into Bunny and I think that is the closest you get to Cloudflare’s offerings.
The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. Cloudflare is the LG TV of websites, but it's worse because we've known it has an always-on microphone and speech-to-text for over a decade and we still keep using it for some reason.
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers
You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?
Heck the NSA backdoored our head of states phones - if “NSA wants my data” is your threat model you are pretty much cooked everywhere. Even if you host on your own server and operate everything yourself it’s no big secret that the NSA is listening in on the node/isp level
"The “threat model” section of a security paper resembles the script for a telenovela that was written by a paranoid schizophrenic: there are elaborate narratives and grand conspiracy theories, and there are heroes and villains with fantastic (yet oddly constrained) powers that necessitate a grinding battle of emotional and technical attrition. In the real world, threat models are much simpler (see Figure 1). Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from [email protected]. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https://. If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone, and when you die of tumors filled with tumors, they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US,” and then they’re going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them." -- James Mickens
Isn’t their whole thing supposed to be spying on foreigners? They seem to be quite successful. There aren’t that many exchanges [1]. Could probably manage with cash, guns, and some know-how.
If you just look at the largest 4 of those, you'd have 100Tbps of traffic to monitor, with an average throughput of roughly half of that.
That's ~540PB ((50 Tbps / 8 bits) * 86400 seconds/day) of traffic a day with just those four. Add in the rest and you're likely talking ~Exabytes of data each day. And that has to all be processed on site.
If someone wants to argue that the NSA is in these facilities I'd be 100% onboard. But inspecting it all would be nearly impossible, let alone capturing it all and sending it back to some datacenter somewhere, which is a physical impossibility.
That's nothing a rack full of fast switches can't handle. A rack full of fast switches already does handle it - where do you think the original copy came from?
They will get a copy of the whole feed, but not store all of it - they will have heuristics for selecting interesting traffic.
Switches handle data at far faster rate than any hardware can actually inspect it, store it, process it, etc.
But yeah, just a rack of "fast switches" is all it takes to route hundreds of petabytes of data each day. You should let the data center operators know. They'd save billions.
Switches do inspect it. They also have a feature designed for wiretapping, which copies a percentage of traffic to another port. They may have a feature to copy 100% of traffic matching a certain filter. Managed switch ASICs have this feature even though it's usually not exposed in the CLI.
If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?
Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it.
Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.
One is where their hardware for storing data is. The other commenter was talking about global taps (the sources for the data), of which the Wikipedia article is not speculating the number of.
> how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?
ISP taps globally, undersea cable taps, the list goes on.
You think the politicians are going to say "The career employees made some convincing arguments about why this is impractical / immoral, guess we'll give up our unregulated power/omniscience"? Or, they will raise the military budgets and continue skipping the audits.
This is a joke. If it's electronic the NSA can hack it with impunity, including your ISP. And that's assuming your ISP won't just give them whatever they ask for (unlikely).
The NSA couldn't care less about you and your customers, nor do they have any interest whatsoever in the megaton of worthless internet traffic that goes through Cloudflare.
This article, from over a decade ago now, explains how they actually operate. Gobbling up all the traffic is a 20+ year old idea that never bore any fruit and is amazingly pointless. Instead, they might drop an implant in the SSD firmware of devices they actually care about, and they're not burning that to see if you sold X widgets to someone in Alberta.
If I was the director of an agency of the size of the NSA and was evaluating the options purely from that perspective, I'd aim at creating a file on every living citizen on earth, including their social network topology and their activities. Basically a Google search engine that includes information not publicly accessible. I'd create much larger files for persons of interest and authorize targeted surveillance of them, of course, but with today's means to collect data a complete world database on every living and many dead persons is well within the technical capabilities. It also makes sense and is rational, if you put aside moral considerations.
That's how I evaluate these things. If it makes sense and can be useful, it's likely going to be done. Notice that there is no law against this in the US if you exclude US citizens. It's perfectly legal and within their mission parameters to do it for non-US citizens. I used to think my judgments were a bit too much on the paranoid side but when Snowden published his leaks it turned out that I was roughly right about every capability the NSA had except for their internal security.
Yeah, I'm sure some system like that exists, although I'd assume that would be more in the CIA's purview. I'd be surprised if they kept a broad swath of data for most people though as the tech companies already do it and it's constantly up to date. If needed, a fed lawyer can work through the FISA court and the tech companies are obliged to provide the records.
According to the information I have, the CIA is unlikely to be involved with SIGINT of that type. It's just not their role. I agree that most of the information the NSA might collect will come from publicly available sources like data brokers, particularly if US citizens are involved. However, what I was talking about concerns real-time capabilities and predictive power, it's very different from targeted surveillance and anything involving courts.
I'm more concerned about crimeflare's own incentive to analyze our traffic that people already willingly let them MITM, and somehow sell it to the highest bidder.
If you care about security and specifically NSA, don't use US clouds (owned or hosted), period. There is not a single one they don't have full access to, why should there be one.
Or clouds in general, its all wishful thinking and pinky promises.
There’s no way a single datacenter costing a couple of billion dollars can store “all Internet traffic the NSA can access”, unless the traffic the NSA can access is a microscopic fraction of the total Internet traffic.
Think about it. The Internet runs on tens of thousands of massive datacenters. Thousands are being built as we speak. Obviously a single datacenter cannot hold an appreciable fraction of that.
BTW, the total budget of the NSA is less than the R&D budget of a FAANG company, so if you find yourself believing that they might have alien-level technology far beyond Google and AWS, you’re watching too much TV.
People said/wrote in the past that what NSA and other intelligence agencies did was to gather data and store the meta data. The actually traffic got processed for the meta data, and small amount of the traffic got sorted out and also stored.
I would suspect that today they also process the traffic for llms and thus store a bit more of the traffic as weight and biases. All that can be done distributed and to different degrees based on how much access they got and under what operational conditions.
Regarding storage, a single data center using only slow but dense storage (magnetic tapes) can store far more data than a data center providing regular web services.
“They’re not as good at violating your civil liberties as you think they are”
isn’t very comforting. They are still doing it at scale and i’m not too keen on opening the back door for them myself.
> The Internet runs on tens of thousands of massive datacenters.
"The Internet" would require 1000 times less servers if it wasn't running off Python scripts in Docker containers in VMs in a virtual overlay network. (I'm exaggerating these numbers only slightly.)
Sure. But a government agency has secretly rebuilt all the same infrastructure without Python, on a shoestring budget compared to what Big Tech is spending, yet it’s a lot more efficient than what they use, right?
Caveat: I have zero experience with USA government agencies. The spying tech from other countries I'm familiar with are beige box routers made by network engineering types with embedded firmware written in C inside.
I think spying on traffic is just a massively simpler task than generating content.
It doesn't need to store the payloads itself. It stores the metadata of connections and probably the fingerprints of the content passing through the Internet. "The headers of the whole Internet" could be physically stored in a single datacenter.
I agree it doesn't matter for most smaller entities, but it's relevant for larger entities and as the US does not anymore intend to be allied with Europe, the Western world, or anybody really, there's now actual incentive to move away from such systemic risks.
They also certainly have many heuristics running. Your corporate website is interesting because it reveals who your suppliers and customers are, and all of your passwords. They don't have the manpower to scrape this manually so they scrape it automatically
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.
That depends heavily on the kind of site you're hosting there.
I have a small site on Cloudflare that lists a brief introduction of a sawmill, its operating hours and contacts, and a map that advises which roads to take to reach it. Everything's public already. There's some very modest value in tracking who visits the site, but with popular operating systems leaking like a sieve on the client side, that fight was lost a long time ago.
It's free hosting. Push to github and changes to the website appear in 30 seconds. Even the build step for the static site is handled by Cloudflare.
And I'm satisfied with Cloudflare's explanation to the free hosting: the more sites are on Cloudflare, the more are ISPs interested in having good connections to Cloudflare. Makes sense.
Unfortunately my proposal to set up a K8s cluster to host 5 HTML pages and a dozen jpegs was not approved, so I had to make some compromises this time.
They hold your tls keys and can decrypt all your traffic. They're MITM as a service, by definition. They have to be able to in order to cache and forward appropriately.
Also to do DDoS mitigation. Being able to see the HTTP request, at least headers and path, greatly helps with distinguishing attackers from legitimate traffic.
It's a tragedy that there's no standard to allow partial decryption/nested encryption in HTTP, which would allow intermediate proxies like Cloudflare to e.g. only validate a first-level authentication token and rate-limit access to a given endpoint, but not decrypt the actual request body, backend authentication token, or response.
Also desperately missing: Authenticated static file caching (think: cdn.foo.com serves files authenticated/signed by foo.com). Subresource integrity only works for HTML use cases and is clearly not ergonomic enough to make a difference.
And the best way to get people to let you do bad things, is to offer them something good, that uses the same mechanism. If I want to MITM the whole internet, what better way than offering free caching and bot blocking?
I even get to charge the bots extra to bypass the block, and then charge the customers extra to block the bots that are paying extra to not be blocked!
Also CF adds extra waiting with checkbox and I see it more often than cookie confirmation dialog.
Also CF raise checks on pages that I opened few hours ago and reload.
I have seen this argument on HN before with respect to similar scenarios involving so-called "tech" companies acting as intermediaries
I don't think it's convincing
If this submission and this thread are any indication, it appears the "reputation" that CF customers care about has nothing to do with privacy. It relates to price, ease of use, reliability, etc.
If the design, e.g., TLS termination by a third party such as CF, allows for spying, then waiting for evidence of spying is not a good strategy to avoid spying
For example, if evidence becomes available that someone (besides CF) is spying on CF's customers,^1 then for those customers it's too late. For the network traffic that flowed through CF before the evidence became available, any privacy, secrecy or confidentiality has been lost
The damage of being spied upon, if there is any, is already done
1. It's not clear why commenters are only concerned about intelligence agencies
AWS isn't aimed at regular people, it's infrastructure as a service. You use it because you need a thousand servers, or a redundant system that can survive a data centre exploding.
If you just need a single server that you don't care about then it's way cheaper to just own it yourself. You probably don't need 99.999999999999999% guarantees for your data, but if you're a bank then you do need those guarantees because losing all of your documents would be disastrous.
Normal people aren't worth anything to them. A company might spend a million a month with AWS, to get that with normal people you'd need at least a hundred thousand customers. And those people are going to spam you with tickets and do silly or illegal things. They're just not worth it. They obviously won't turn money down, but it's not a growth area for them.
I 99% agree, but have conflicted felings. There's a mix of services. S3 is and was an amazing resource for normal people. Extremely reliable cloud storage for backup, for distribution, for anything, well, it's a dream. I prefer Cloudflare's offering there in every way, but AWS defined the product category (with its correspondingly ugly API like every single AWS service), and met a core need for many many people. With S3, if you need a ton of storage, it's a terrible deal, and you shouldn't use it. But for a couple hundred gigabytes, go for it.
EC2 is similarly great for normal people as long as you only need a part-time server for a short amount of time. It's hard to beat with a VPS.
Once you get into load balances, event queues, and all the rest of AWS services, well, that's all there to drive lots of money to AWS and to contractors and busy work. MAYBE RDS is a good deal for somebody who really wants to pay somebody else for a managed database. Which turns out to be a ton of users of databases!
Re: complexity. I used to find AWS unusable, then I realized I can just tell Claude Code or Codex to manage it. This makes it into an entirely different product, where "Cloudflare is easier" doesn't really matter. Now price is the only barrier.
Cloudflare can also be managed by Claude Code or Codex, so for those instances in which you will personally have to go into the console to make edits, Cloudflare is still easier.
> Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much the most affordable option as well.
You don't need to register your domain with them. Only make their DNS servers your domain name servers.
yeah, I have been amazed at what I could do for free, and then amazed at how much more powerful it got for 5 bucks a months. Cloudflare is killing it in terms of value for small websites (and features and reliability).
Registering domains on Cloudflare is great. They do it at cost as far as I can tell and more tlds have been added. I don't have to use a nasty local registrar with dark patterns anymore.
Google Cloud and AWS are complex because they're meant for hosting complex apps and infrastructure, they're not really worth it for simple static websites.
I'd argue it's even more worth it for static sites, where CDNs and buckets will vastly out-perform hosting a static site on an instance yourself because of replication, caching, and geographic routing
I also believed that, but at least for India, this doesn't work in practice. Unless you atleast do the 25$ pro plan, cloudflare routes even india-to-india, hell, even mumbai-to-mumbai and aws_mumbai-to-cloudflare_mumbai traffic via Marsaille!! Not even Singapore. The unstated reason is that indian transit is expensive, though I fail to believe its cheaper to go from mumbai to marsaille and back to mumbai.
I am guessing the real reason (and at this point I am discounting incompetence - this has been true for years, so they are aware). You switch to the pro plan for the zone and everything now routes within india, 100s of milliseconds of latency saved.
Its even worse for workers and workers AI and embedding search. I found multiple seconds of latency, all vanishing the moment the zone is on pro plan (It seems R2, workers, workers AI - none of them are deployed in an India POP - unconfirmed, of course, cause there is no way to actually communicate with cloudflare).
Now 25$/month isn't much - though it does change calculations compared to "FREE!!" - but I would have liked to know this going in, instead of discovering this after having made the commitment. Seems like a deliberate dark pattern, to force people into the pro plan.
Shame, really - I love the CF stack(workers and DO are just so fantastic to build on), but these shenanigans, plus the utter refusal to provide ANY level of support, keep souring me on them.
> The unstated reason is that indian transit is expensive, though I fail to believe its cheaper to go from mumbai to marsaille and back to mumbai.
IMHO, it's not that hard to believe.
a) Every hosting provider I've looked at prices for charges significantly more for bandwidth from their Indian locations.
b) In the US, transit providers basically never charged different rates for different destinations [1]. In Europe, it's typically rare, sometimes transit to the local incumbent telecom is more, sometimes there's a different rate for Europe or non-Europe, but there won't be a specific destination charge for India, it will be part of a blended rate. Otoh, east Asia often has separate rates for specific nearby countries and India is likely to be one of those...
Transit prices in Europe are pretty low compared to prices in India, so the blended price being less than the India direct price is not surprising to me at all.
[1] gcp premium does charge by destination, but the premium transit price is pretty close to their price for cross location traffic to something near the destination + non-premium traffic from that location... Which is more or less what their premium network egress is.
It's basically that payment flows towards the core of the network, which is Europe and America. If you're the first Indian ISP, you have to pay a European ISP for an upstream connection - they won't pay you. And that persists and becomes "just the way things are done". It can only reverse if there are significant websites in India that Europeans want to access, then the European ISPs will be getting more value than the Indian ones and the Indian ones will be able to demand payment.
Transit in some countries, like India, genuinely is that expensive. Keep in mind it doesn’t cost Cloudflare any more to serve Indian traffic from Marsaille than to serve non-peered French traffic from that colo - they aren’t paying the cost of getting traffic between India and France.
The traffic still has to flow from an india provider to the international leg and back via the domestic provider.
In anycase, then they should document it clearly that they have unacceptable insertion latency in india and the free plan is entirely unusable for india. Instead of advertising '10 pops in india!!'
> The traffic still has to flow from an india provider to the international leg and back via the domestic provider.
Right, but Cloudflare doesn't have to pay for it in that case. If Cloudflare sends you to their Indian POP, then they have to pay their Indian service provider for traffic. If they send you to their France POP, then they have to pay their French ISP for traffic. The Indian provider cannot claim any of Cloudflare's traffic in that case, because the Indian service provider wouldn't have any relationship with Cloudflare
This is very standard for places with high ISP costs, like South Korea and India. You can see a lot of discussion about it online. I agree with you that Cloudflare should be more transparent if / when they make different routing decision for Free/Pro plans based on bandwidth costs, but I don't think their decision itself is unreasonable at all. Indian bandwidth is very expensive.
You would think Cloudflare would be in a position to do something about it, like they did with several cloud services in their Bandwidth Alliance. It would be a win-win-win for networks to interconnect better in India, it just can't happen stepwise because any individual step is a lose for somebody.
> The unstated reason is that indian transit is expensive, though I fail to believe its cheaper to go from mumbai to marsaille and back to mumbai.
Your Indian ISP is paying a French ISP for both directions of that traffic, which makes it cheap at the French end. Were it India-to-India, Cloudflare would have to pay your ISP.
The trick is to use the most normal hardware, software and network connection you can think of. Which I assume you aren't doing for ideological reasons, which is fair.
My ISP seems to frequently rotate IPs with other people who can't behave, so my IPs always have garbage reputation... that probably has a lot to do with it as well.
How do I know this? I have received reports from various websites (and manually queried some public block lists/RBL/etc.) that my IP range was blocked due to all sorts of different things like open proxies, CSAM etc. even if I've never visited that site before, and I know just from being a neteng that that such traffic is not originating from my devices/router and I don't have any observably compromised devices or suspicious traffic when monitoring it.
This is common for third-world ISPs. Cloudflare would never block, say, Comcast, but they have no qualms about blocking the few largest ISPs in Brazil because who cares about Brazil? Those countries also have IP address shortages because we refused to move the whole internet to ipv6 yet, and may share just a few addresses per city.
We used Google's CDN for the last six years or so but it's pretty annoying to deal with and you have to pay for a load balancer every month in order to properly use it. That adds up to quite a bit per year. Even if all you are doing is routing domains to some bucket with a website.
We migrated most of our gcloud stuff to Hetzner beginning of the year. That left a load balancer and a few static websites hosted in Google buckets. I migrated all of that to Cloudflare just a few months ago.
I still have a few buckets in gcloud proxied via a vm in hetzner with a proxied domain in Cloudflare. Not the most elegant route but it works. I might optimize some of that later. At this point, we pay for some Google buckets and not much else in gcloud.
Honestly, Google and AWS need to start paying attention to Cloudflare more. Their complexity is chasing people towards Cloudflare. The hoops you have to jump through with both of them to host a simple website with their CDNs is embarrassing. I've gone through the process with both of them. Although my experience with Route53 is a bit stale at this point. On Cloudflare, getting an new website up and running with a freshly registered domain takes only a few minutes.