TLDR it's not an attack, CF isn't a criminal, he's a CF customer and sees traffic spikes with a curl useragent.
I kinda wonder if someone's using https://workers.cloudflare.com/ to crawl their site daily. Or they just need to configure `ngx_http_realip_module` to get the originating user's IP address, if they're not currently processing the X-Forwarded-For header.
These are extraordinary claims, which require extraordinary evidence.
And from Cloudflare IPs.
The same happens with most load balancers. In Apache, you have to set up mod_rpaf or mod_remoteip. In Nginx, you have to configure ngx_http_realip_module.