Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yuuuuup.

We once had a cloudflare outage. My CEO asked "mitigate it" I hit him back with, okay, but that'll take me weeks/months potentially, since we're tiny, do you really want to take away that many resources just to mitigate a once every few years half the internet is down issue?

He got it really quickly.

I did mitigate certain issues that were just too common not to, but when it comes to this sort of thing, you gotta ask "is it worth it"

Edit: If you're so small, cloudflare isn't needed, then you don't care if you go down if half the internet does. If you're so big that you need cloudflare, you don't wanna build that sort of feature set. The perfect problem.



Is it removing cf as the middleman temporally such a big deal?


I think that really depends on feature usage. You can use Argo/Cloudflare tunnels to route to private backends that are normally unroutable. In such a setup, it might be quite difficult to remove Cloudflare since then you have no edge network and no ability to reach your servers without another proxy/tunnel product.

If you're using other features like page rules you may need to stand up additional infrastructure to handle things like URI rewrites.

If you're using CDN, your backend might not be powerful enough to serve static assets without Cloudflare.

If your using all of the above, you're work to temporarily disable becomes fairly complicated.


It depends. The site is up, but now you're pumping 10x/100x the traffic. What are you scaling up?

Suddenly you're not blocking bots or malicious traffic. How many spam submissions or fake sales or other kinds of abuse are you dealing with? Is the rest of your organization ready to handle that?


Afaik, Cloudflare is mostly used for anonymity and privacy, not for scale.

DDoS protection is one nice side effect of privacy, but I'd imagine there are others too.


> Cloudflare is mostly used for anonymity and privacy, not for scale

I have never heard this before. Anonymity from what? From people knowing your Hetzner ip? I don't know what you're keeping private.


I self-host my blog on a server in my home. Instead of opening a port to my home network, I'm using Cloudflare Tunnel to expose the blog to the internet.


That's not really anonymity or privacy in all likelihood, though. Your residential IP is already anonymous. Knowing it tells me nothing other than your general region. The benefit there is that you don't need to have a static IP.

And besides, Cloudflare Tunnel is distinct from (though it integrates with) the cdn product.


I would like to know why this comment seems to have been down voted. It's true AFAIK.


> Your residential IP is already anonymous

It certainly isn't.

In fact, IPv4 is the de-facto authorization and authentication system of the Internet. It's stupid but it is what it is.

Cloudflare is the "bitcoin mixer" for laundering IPv4's.


> From people knowing your Hetzner ip?

Yes. You don't really want people to know your IP address. It's like giving your phone number to spammers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: