> I don't really understand why the decentralized internet folks harp on CDNs
Personally, although i'm not dogmatic about it, i'm rather opposed to CDNs for two reasons:
1) For performance reasons: unless you're distributing video, removing bloat from your webpage makes it faster to load from anywhere (including bad connection on the other side of the world) than to add a CDN on top ; i've already got a TCP route to your server so if you stay under 1MB that's much faster than to resolve a new domain and open a new route
2) For security reasons: CDNs are often used to distribute scripts, which are the #1 entrypoint for infecting users with malware. Also, as you pointed out, "anti-DDOS" reverse-proxies like CloudFlare are yet another case and should not be used in 99.99% of cases, because TLS will be terminated on their side and they can read all your users passwords!
I believe the web would be a much better place if content was served from a single origin (i believe it was not done originally because most of us didn't have enough bandwidth to consider the option). For shared content across origins, there's much better solutions than CDNs in the form of Content-Addressed Storage (eg. Bittorrent/IPFS/DAT). Whether you download it from a single trusted source (eg. your ISP), or in a p2p fashion is your choice... but a location-addressed protocol like HTTP is not well-suited for distributing static content across the world.
If only browser vendors (read: Google) were not too busy destroying our URL bars or inventing new tracking systems for advertisements that would be a fixed problem by now. But no, who needs reliable content distribution for smaller websites when you can have WebGL and a Battery API to better track users and make it harder for competitors to implement browsers?! I guess it also doesn't help that Google who develops for ~90% market share is the biggest 3rd party origin today with Google Fonts, Google Analytics, Firebase, etc.