Regarding Cloudflare/fastly, you do need to make sure you're only allowing requests that originate from the proxy, either via IP-based firewall rules or something like CF's authenticated origin pulls [0]. Otherwise someone could find your origin server's IP and potentially perform this attack (and generally bypass your security settings).
0: https://support.cloudflare.com/hc/en-us/articles/204899617-A...