If you're determimed, though, you just null route, or block, etc, everything other than Cloudflare inbound.
If one is concerned about DDoS, one should work with their ISPs on the plan of action for various scenarios. Finding out their procedures when ones' hair is on fire is not fun.
Just change your IP address, and tell CloudFlare the new one.
Sure the DDOSers could find your new IP, but it's not like changing your public DNS, it would be difficult for them to find it.
I don't think your SSL certs would show the new IP on the website in the blogpost very quickly if you changed IP.