> If there exists a solution to either not using cloudflare,
> or some option hidden away that allows me to tell clouflare
> o fuck off with how it treats traffic, I'd love to know.
The method I use to avoid CloudFlare altogether (probably wrong as it's bespoke) is to do the following before "handling" the request:
* Store all connecting IPs, last request time and the rate at which requests are being made in a serviced-buffer. If the request rate becomes too high, give them a timeout (return a very small page telling them to come back in a few minutes).
* If database hits are high, drop non-important requests first, starting with views, then up/down votes, comments and then user security. Views and votes can fail silently and most people won't be any of the wiser.
* If static content requests are high, drop generated content first, followed by large files (all JS, most CSS, images, etc). For the generated content, you can use a recently generic cached view.
* Lastly, if all else fails, just return a redirect to some static server hosted somewhere strong (like GitHub pages for example), explaining that demand is high at this current time.
This approach has worked for me so far. Under high load, you need to handle requests as soon as possible, even if it means not returning something. Holding onto a connection is what will sink your ship.
In general most sites seem to die because they spend too long dealing with individual requests. especially when the database is hit. As soon as you overload a WordPress database for example, it's screwed. And this is just for displaying content to the website!