Cloudflare launches app development platform, announces $100M investment fund
techcrunch.com
techcrunch.com
The initial goal of Apps is to make it possible for everyone to use all the tools technical people find and use on Github and npm everyday. Our long term goal is to make it possible for developers to make a living building tools which make the web better. As an engineer myself, the moment I will personally enjoy the most is when a developer makes $1MM on the store meaning it has truly changed their lives. That will be when this experiment is proven a success and we can't wait!
UPDATE: I found a visualization that Teffen Ellis on our team made of every commit throughout the history of the project: https://drive.google.com/file/d/0B6EsMIhQjoQYT2pmS05hU1RuUTQ...
1) What were the interesting technical challenges of evolving the Eager codebase and integrating with Cloudflare since the acquisition?
2) What has surprised you so far in the feedback about developer experience?
The challenges are probably pretty obvious, you have to take this codebase and application which were meant to live on its own and conform it to the way another system works. In the process you have to adapt your deployment, auth, style, etc. to work in this alternative reality. At times it can seem like you spend months working just to get back to the feature set you started with. At others you get to see the vision of an integration you sketched on a whiteboard six months ago become reality and you're blown away that this crazy idea could ever actually work. The definition of 'you' also changed a lot in that process, we went from being a small team to getting support and assistance from dozens of passionate people. It's a very different world where your resources can scale to your vision, instead of having to compromise what you want to build at every turn.
Particularly when you work at a company with as sweeping a vision as Cloudflare, you also get a chance to expand your vision itself. At Eager it was a romantic dream to think we would get on a hundred thousand sites. With our launch today we reach six million. The idea of a $100mm apps fund, or having 60 apps in the store before we even launched, were not things which startup-Eager could have pulled off.
My biggest surprise is gonna be a little silly but it's it's when someone builds a really great app without any help or guidance. As much work as you put into the API or docs it's always a little shocking when someone builds something from scratch on the platform you work on every day, and it works well, out of the box.
This headline made me think that Cloudflare had finally done what I first assumed Akamai did back in the noughties, before I learned they didn't really have magic tech. :/
Anyway: here's some indirect feedback. It doesn't really apply to your project (which I'm sure will be super useful to other people). I would expect Cloudflare to take the lead in... let's call it widely-distributed-computation. All I want is my code running on your nodes all around the world with an end-to-end ping that is less than 10 ms to the average client.
Interesting idea. jgc AT cloudflare to tell me more.
As someone who tried building this for the unwashed masses, wait until you have something along the lines of Google Spanner. Developers see amazing gains from edge compute because ZOMG LATENCY, then actually flesh out their apps and start making uncached database calls back to AWS anyway.
EDIT: Yes they lack pricing transparency. Akamai is expensive. As I pointed out, in real world experience less than 5% of the developers I talked to actually could lower response times by moving closer to the client. It's something everyone thinks they need, but the devil is in the implementation details. Akamai hand holds you a lot for your money.
Cloudflare will need to hire a sandboxing expert for that.
Wait...
I'm guessing you guys have lots of code review todo!
Anything we can do to help speed the process up? Specific types of unit tests maybe?
Also, a couple of suggestions:
More complicated installer options are a sort of want of mine. It would be nice if I could drop down to custom functions to make the install process more dynamic and user friendly dependent on input.
Also, slight pet peeve, the slider input option seems to have no way of displaying the slider value to the user.
The only other beef I can think of against CloudFlare is how they play both sides of the DDoS game, hosting the sites selling them (free speech!) and charging the victims for protection.
PS. CloudFlare does deserve some flak / second thoughts for the whole Cloudbleed thing, but I don't think your response is quite on target.
It's unusual to see someone accused of blatantly lying on HN and I put my alternative interpretation out there to hopefuly temper that opinion a bit.
As you mentioned, the end result is pretty much equivalent since all we have is the completely wrong output.
I would differentiate that from lying, and fairly, he gets to deal with the consequences either way because he is the CEO.
What if a booter site advertises itself and says "you must confirm you have legal authority to run an attack test against this site"? What if it's legal in <some jurisdiction>?
CF should only take down sites after getting a direct court order to stop services (even then jurisdiction is an issue).
Your comment seems to fairly accurately reflect CloudFlare's position: Thoughts on Abuse | https://blog.cloudflare.com/thoughts-on-abuse/ (2012)
Here is a semi-recent take from one of their more vocal opponents: Spreading the DDoS Disease and Selling the Cure | https://krebsonsecurity.com/2016/10/spreading-the-ddos-disea... (2016)
Here is how it works out in practice for a few fellow HN-er's: The New Normal: 200-400 Gbps DDoS Attacks | https://news.ycombinator.com/item?id=7242377 (2014)
So this jurisdiction issue actually goes both ways.
I would have been happy to give him the benefit of the doubt and still would. To me it seems to me he continually repeated these claims over the whole incident and ignored people who pointed out that what he was saying was obviously false. I only pointed to the most egregious example.
To be clear, I'm not super worried about companies just screwing up, shit happens. However, I have a personal bias against dealing with people who are dishonest when that happens.
Thanks for following up!
When Anonymous ran some anti-ISIS operation, they accused CloudFlare of "hosting" dozens of pro-ISIS sites[1]. It turns out Anonymous was entirely wrong about the CloudFlare customer sites (confirmed by DHS) and hypocritical (because CloudFlare tried to remain content-indifferent and, as such, protects lots of Anonymous sites). But their image took a spanking for it in the news, despite (1) investigating the claims, (2) contacting DHS to confirm they were in the right, (3) having a rational counterargument (even if it wasn't as simply as "TERRORISTS!!!!1!!1one").
Remaining quiet isn't the solution either. @eastdakota was actively corresponding with the HN community while his security+product teams were actively mitigating the "CloudBleed" damage.
Sometimes you will lose the news cycle, even if you are in the right and did everything right as a company should.
[1] https://www.theregister.co.uk/2015/11/18/cloudflare_ceo_rubb...
https://twitter.com/eastdakota/status/877697707464302593
https://twitter.com/eastdakota/status/876951966521348096
Fund announcement: https://blog.cloudflare.com/developer-fund/
Sounds like all of your code executes in the browser then, somewhat like tampermonkey user scripts or basic browser web extensions.
Your "code" looks VERY similar to the code you would write for a chrome web extension. The delivery mechanism for the code is the MITM capability...looks very much like edge-side-includes.
They have a sample app here: https://github.com/CloudflareApps/CornerRibbon
1 https://eager.io/blog/a-brief-history-of-weird-scripting-lan...
EDIT: a little pre-debate warmup for anybody that wants to get into it. Point 1: Users have the right to block. Counter-point: Content provider have the right to deny access. Point 2: Ads are bad for users. Counter-point: there is none, ads are bad for users.
The reality is, you can inject advertisements into content at the proxy level that are better for peoples' privacy, keep pages fast, and are less disruptive for readers.
The thing is, publishers have a ton of unsellable inventory that you can blame on ad blockers, but it's really the end result of shitty advertising and privacy overreaches. Doing better ads will get them around ad blockers, but doing better ads from the beginning may have prevented the rise of ad blockers at all.
Only a select few news sources will survive. Local news in non-metropolitan areas will be even worse than it is now. People will start consuming news exclusively from the one or two (maximum) sources they pay for, whereas now they probably read at least one article from 50+ sources every month.
Elections will happen, but very few people will actually have enough information. All political oversight will seize, because actual behaviour is no longer tied to re-election. But, at least, most politicians will have very nice names.
Alternative scenario: smart blocking: start with allowing all, then blacklist individual ads based on the publisher, content/behaviour of the ad, and reputation of the ad network. That would incentive ads to actually get better.
I agree that content monetization is an important problem that ought to be solved in order to maintain quality of information.
I disagree that current advertising models have elevated the quality of content. Fake news websites (literally - a made-up .coms that have BS stories, the equivalent of tabloids) exist specifically because advertising monetizes clicks/eyeballs, and so clickbait is the optimal strategy.
I disagree that moderating ads will produce better ads, because I believe ads run counter to a well-functioning information system. An example: HN is an information system that's designed to put high quality links in front of the user. A paid placement makes it possible to skip the votes mechanism, thereby skipping the system's regulatory structure. If your link deserves to be at the top, it will get there the same way all other links do.
I disagree that advertising or paywall are the only two options, though I will concede those are the only two that have happened so far.
From the looks of the demo it looks like you instruct CloudFlare to inject some code, e.g. embedded google maps into a website at a location in the DOM.
How is that different from the website owner from just putting an embed link in their website and updating the site?
Or is the idea you can add/remove these things dynamically through the CloudFlare web interface without having to touch any code?
Yes. There is a fancy preview thingy which lets you visually choose where to inject the element into the DOM, and a configuration UI which supports things like provisioning OAuth credentials for APIs, etc. No code needed (on the part of the site owner; code is written by app publisher).
One click to install, plus developers can charge clients using CloudFlare's payment system (70/30 rev share).
From the CloudFlare Docs site[1]:
> We will bill the user as a part of their normal Cloudflare bill, beginning on the first of the next month (prorated based on when they installed the app). We will then send you your ~70% cut via our payment provider who supports a wide variety of transfer methods.
[1] https://www.cloudflare.com/apps/developer/docs/writing-your-...
I love cloudflare and am a happy customer but I'm really interested to know what these investors are thinking before they put up 100s of millions in investment.
This seems analogous to when FB neutered FP Games from NewsFeed, Zynga took a nosedive and Zynga didn't seem to thrive outside of the FB App ecosystem.
Why not?
Also, Cloudflare has literally millions of web sites, APIs, applications using it. We are not limited to enterprise deals at all.
Maybe it's not a bad idea to invest in cloudflare :)
If you think your cooperation stands in the way of the NSA using you for bulk collection, I've got a bridge to sell you.
Because copy pasting the markup / js was so difficult?
For some people 'copy pasting' is hard. Most people don't know how to code and don't want to deal with it.
Additionally I've seen that major media sites use analytics services for tagging and have a way via the tagging tool to inject javascript.. This is a pretty terrible idea but allows the tagging changes to not be coordinated with site changes as usually a different team controls the tagging. Cloudflare would be able to provide another way to inject custom analytics / tracking into pages.
Yes, there's exceptions to every rule. But I have yet to see this strategy of a platform fund ever succeed.
Better to build (or tap into) a captive audience and then sell that to developers.
This is a low friction app ecosystem with 70/30 rev share[1] for what CloudFlare claims is 6m+ websites. Also, their VC are also willing to back companies in their app ecosystem, too.
[1] https://www.cloudflare.com/apps/developer/docs/writing-your-...
I guess my main confusion is that I don't understand the audience who would benefit from these apps. I imagine one member of the audience is someone who runs a popular blog and want to add a widget but don't want to copy and paste code.
A quick search on Google would solve my problem, or I'd hire someone on eLance to make the change for me instead of paying a monthly subscription for an app.
Further more ... if it's an app store (like) concept why does it not describe the way developers can make income just from creating an app not an app and a connected service that would require a server setup, I mean describe the revenue model and the cut that cloudflare would get and us as developers will get in the end.
Thank you