This article is two years old - think it’s been well established that sites need https, if for no other reason then browsers and search engines punish you in a variety of ways for not having it. Certificates are free with let’s encrypt so there is no excuse not to anymore.
In the case of Cloudflare (or any CDN) best practice is to reject requests not from the CDN. Cloudflare doesn’t support AWS S3 compatible storage directly - it won’t make signed requests - but you can write IAM policy that only responds to certain IP.