Image hoster pushes 1.8 PB per month through Cloudflare CDN
postimage.org
postimage.org
"Please contact us if you have a CDN that is capable and willing of serving 1.8 Petabytes of outgoing traffic per month free of charge," -PostImage
Is the company run by spoiled entitled millennials? It takes a lot of equipment and staff to create a network that can serve that and they just want it all for under $1k? You know data centers have costs too. Other startups spend years of their lives putting together a team that can assemble infrastructure to handle that and they want it for free? For their barely-cash-flow-positive project that doesn't earn them a decent living...
I can't believe they just asked that. Sorry but PostImage sounds like the biggest moocher in the web right now. If your ISP provider says "unlimited data" does that mean you can funnel the traffic of Russia through your internet connection? You want for "free" what others are paying thousands and thousands of dollars for?
What is wrong with you? Seriously? It's like you're trying to run a top-tier web company on pocket change.
I mean, yeah. Unmetered+uncapped bandwidth is a dumb idea that creates bad incentives, and anyone offering it deserve to be punished by abusers until they rescind their offer.
If people can't proxy all of Russia through your LTE data plan—or serve a billion image hotlinks per day through your caching reverse-proxy—then you should put that in the contracts you make them sign. That's what contracts are for. Say precisely where you're drawing the line, or you don't get to complain when people act as if you haven't drawn one.
I do wonder what they thought would happen. CF's ToS are very clear. Why did they think they have a project, let alone a business?
Recall the uproar of that open source project that was breaking a piece of Github's infrastructure, and even when Github explained politely how to properly architect the fix, people were upset the project was going to need to pay for a CDN for their binaries.
Amazon Cloudfront: $59770 per month
Google Cloud CDN: $50000 per month
Fastly: $144200 per month
etc etc. If they can't get together $12000 per month for Cloudflare, they sure as hell don't have a viable business model.
Look into PhoenixNAP and other similar providers that are located at non-profit peering sites and have reduced bandwidth costs.
PhoenixNAP (as the example) will lease you a mid range bare metal server with 16GB/RAM and 100TB of data/mo in the $150.00/mo - $300.00/mo range (depending on your processor needs; well optimized nginx doing just proxying should scream).
You can't exceed some unwritten bandwidth cap because you're explicitly paying extra for the 100TB of BW. For 20 caching servers firing 2PB/mo you're looking at around $3000 - $6000/mo...
Seems like you could optimize this down with fewer high powered caching servers and paying for the extra bandwidth... is the engineering time and $2500/mo really out of reach?
Best of luck.
I'm really suprised they didn't look at all the stories of people before trying to start image or video hosts on Cloudflare and getting booted, as if all the other image hosts were too stupid to use Cloudflare for $200/month instead of paying CDNs tens of thousands a month.
Watching competing projects also added some degree of assurance. Without giving out any specific names, we are aware of a number of competing projects that even now keep heavily relying on CloudFlare (although I am obviously unaware of how much they pay), so we didn't consider it an abusive behavior. In contrast, we were also aware of at least one competitor that kept pushing a considerable portion of their uploads to imgur and basically parasitizing on them for a long time until imgur's abuse team finally took notice and brought down the hammer.
This makes it sound like we are doing some monetization of low-tier customer data. We are not doing that with any data (low-tier or anything else). That would be hella creepy.
We do track abuse (DDoS attacks, etc.) whoever they hit and use that information to protect other customers. So, in that sense low-tier customers help our overall business, but it's a common lie from our competitors that we are somehow monetizing traffic. Cloudflare's business is pretty simple: work out how to operate our services as cheaply as possible, charge web site/application owners more than that amount.
Also it's super unfortunate if they go down breaking so many images hosted so many places.
If they put their website behind Cloudflare, but not their image serving domain, presumably that would be fine. Cloudflare is made for a site that serves up web pages with some content like your logo, a few images, etc. Those images can be cached and it's a small amount of data since something like the YC "Y" image is the same served for everyone on HN. A site like Postimage serves image content that's hard to cache since it's mostly different for each visitor.
Cloudflare is pretty explicit that it's not meant for a site that will be mostly serving up loads of pictures.
For an interesting counter-example: 4chan (including its image-CDN subdomain!) is served through CloudFlare. It seems that CloudFlare really is willing to host and distribute multiple petabytes of image content per month, as long as it's for the sake of something else (e.g. pages of threaded conversation) that's not an "online storage space."
Though, I think in 4chan's case it might also help that pages and their image resources both get expired off of the site quite quickly. You can create a page that hotlinks image URLs from 4chan's CDN subdomain, but the correspondent resources at those URLs won't be there five hours later, so there's little point to doing so. Unlike most image-hosts one could name.
This means the majority of their bandwidth is going to people whom:
a) Cannot be monetized via ads b) Are not on Postimage.com thus the site is breaking Section 10 of Cloudflare's services.
At best, you can get AdvanceHosters. They're Russian based but have 7 CDN pops across the US and Western Europe, they'll let you push 1.2PB for 7500 $/month
You won't get asia/oceana/australia traffic for those prices, and you certainly won't get S. American of S. African traffic for those prices.
Certainly too expensive for a small deployment which is why people buy from CDNs instead of setting up their own.
If it was as easy as just doing dns geolocation (which is awful due to geolocation failing and ISP caching), few people would bother buying from CDNs.
It is that easy. The importance of anycast is just PR, nothing more. Some very large CDNs use DNS just fine.
Anycast is essentially an SPOF. Well, not only anycast and not anycast per se, but a single AS it is under. It breaks from time to time because of various mistakes, bugs, etc. and brings down every server as a consequence. This occurs roughly every couple of years and takes hours to resolve.
So, with anycast, if you have 10 servers in different places, you get hours of downtime for 100% of users from time to time.
With DNS, on the other hand, if one server goes down, it affects only 1% or so of users of a particular server, that have incorrect TTL in the resolvers they use, others see change in DNS right away and use working server. But, those 1% of users don't all go to that server at the same time, only small percentage of them does and also sees the old record. Leaving us with let's say 10% of that 1% on 1 out of 10 servers, or 0.01% of all users unable to see the new DNS record for an hour or so. If a typical server on some random AS goes down five times a year, you get 0.01% * 5 * 10 or 0.5% of users affected for an hour per year. Now if you use round robin and let users see multiple records nothing is even going to stop working in the browser for them, just going to make them wait longer until they see a set of working records.
To summarize, anycast is 100% of users not able to reach any server for hours every couple of years, while DNS is 0.5% of users experiencing slowness for an hour per year. In other words: anycast alone cannot be reliable enough for a CDN.
EDIT: Anyway, resilience, just like security, needs a threat model to avoid wasting resources on things that don't actually work, otherwise it's all just hype.
Routers handle bgp updates much faster. Anycast routing is much more superior to geolocation which gives a completely incorrect location as high as 10% of the time. Anycast ips are also the best way to handle DDoS attacks. Attackers can easily shut down ips listed in DNS while people's ISP and browser repeatedly try to access the same dead IP for hours.
If DNS was an acceptable option, I would have gone with that instead of paying a CDN for an anycast solution.
These are all from my personal observations, they are not something I just heard from "ISP/networking people".