this is, as the kids say, a *MOAT*. you could leak the entire source of cloudflare and cloudflare's value would be unaffected.
Debating exactly how many data centers one needs to be "edge" instead of "cloud" is pretty silly. Ask what latency you need between your software and the customer, and then ask what providers can supply that.
(Of course, AWS egress transfer rates may be too costly, but that's not about "edge". https://blog.cloudflare.com/aws-egregious-egress/)
For an average site, that just wants basic CDN facilities (cache assets; maybe do some rule processing to control cache of "dynamic" pages etc) there are dozens.
The issue comes in a few of the niche uses.
A client of mine has been using CF for the public site for several years, but until recently used S3 + Cloudfront for content that users download (essentially purchased digital files). That content is now also served via Cloudflare, using tokens (similar to pre-signed URLs for Cloudfront, so the cache can validate that a user should have access to a file).
CF don't cache all the downloadable content (anything over 512MB is excluded from caching unless you pay for Enterpri$e level plan) but they also don't have per-{m,g,t}byte transfer pricing either.
This is obviously not a problem for a lot of use-cases, but for anyone offering downloadable content, or large volumes of network traffic, it's going to be hard to find a CDN that can compete on price with Cloudflare.
They're definitely more than a CDN these days.
This means that to prevent all of the issues, you need a huge overprovisioned network. So to make economics work, you'd have to become one of the largest networks in the world, and thus serve lots of clients, making you again a "centralized" service.
That said, wikipedia documents its CDN setup which is all open source at https://wikitech.wikimedia.org/wiki/Caching_overview which might be of interest to you.
It's an excellent resource for anyone curious to learn about their systems. I wish more organizations would embrace transparency and open-source principles as much as Wikimedia does.
The value proposition of a CDN is being physically closer to customers around the world, which means renting space in (often) expensive carrier hotels.
Yes yes all the major CDNs have loads of developer and infrastructure wizbangs to keep you on their platform but that’s not the fundamental value.
Yes, you can hack up a storage container and a pump with "open source" bits, but that's not what makes it useful.
What makes it useful is the fact that there is a $chain Gas Station in every nook and cranny. And that's not something openness can change.
Openness helps kill off rent seekers. This might be the deeper concept that sits behind the original authors question.
I thought about this for a solid 15 minutes. What really is an open source of version of Cloudflare? That leads into the question of what is really Cloudflare.
An enterprise that has built something so huge that the idea it represents can not be separated from the service (as a whole) they provide. That is like saying what is the open source alternative to I don't know....Intel or Oracle. It not only covers a suite of offering that is impossible to replicate, but rather the complexity of each component of their entire service suite.
How the heck are you supposed to do open source CDN?
Then you take a step back and the question again, which still doesn't make any sense. "Open source alternative to Cloudflare". The question is supposed to be "What represents the open source alternative to what Cloudflare's XYZ does".
CDN, a network that is designed to deliver content... and needs to be open source. P2P systems? Torrenting? Some weird blockchain stuff? Are they CDN? I have no clue. You end up compromising in the definition of the service Cloudflare provides to pick something because it is supposed to be Open Source. You go down the list of each service Cloudflare with your own Open Source twist and you end up with a web service that more and more represents the Web 1.0 and arguably not reliable. What are you compromising at that point? Open source becomes an agenda rather than a solution.
Cloudflare isn't a software company, you are essentially paying them for the hardware they are carrying in their network/portfolio. They are not Open Source-able.
Then we have their chip architecture, I think RISC-V at least gives us an open ISA but I am not aware of fully open implementations. Then there is the various software Intel provides, everything from drivers to MKL. There are some open source versions of them here and there.
So can we have an open source Intel? Yes, but not in this world. Mostly because they do physical things. And I think that loops us back to CDNs because thats the point with them too.
[1]
Quick, how many products/services does AWS have?
Free-as-in-beer to use everything, shaggy underdog social status, community of free-as-in-beer contributors to leech off of, keeping your teeth clean with some of that floss, and bonus points if you can stick trendy words like "federated" and "AI" in there.
Openresty with a few Nginx modules and Lua scripts can go a long way for many use-cases mentioned:
- ModSecurity for WAF: https://github.com/SpiderLabs/ModSecurity
- L7 Rate limiting: https://github.com/openresty/lua-resty-limit-traffic
- Cache: https://github.com/ledgetech/ledge . Or use varnish which gives you VCL for high configurability
- Load balancing: https://github.com/openresty/lua-resty-balancer
- CDN: https://github.com/taythebot/lightpath . This project seems to be a WIP which you can use as a starting point for your needs. You will also need to find good enough "edge" locations for your CDN.
Similarly, HAProxy does a lot of stuff with the correct config and is also extensible using Lua:
- Some basic DOS protection: https://www.sysbee.net/blog/haproxy-sysadmins-swiss-army-kni...
- L7 DDoS protection: https://github.com/mora9715/haproxy_ddos_protector
You can run your own authoritative DNS server using either djbdns or nsd. Or use AWS Route 53.
Ultimately, it will involve (a lot of) glue code/config depending on what solution you go ahead with.
This might be of interest to some: https://www.modsecurity.org/
> Trustwave is announcing the End-of-Life (EOL) of our support for ModSecurity effective July 1, 2024. We will then hand over the maintenance of ModSecurity code back to the open-source community.
Probably not too big of a deal, though.
Also, this might be useful: https://owasp.org/www-project-modsecurity-core-rule-set/
Though there has been some critique of ModSecurity and that ruleset in the past, as something dated and with false positives.
Anyone have any good alternatives?
I've been loving cloudflare since the very, very, beginning, but a few little red flags the past couple years have me wanting to find an alternative as well.
Thank you for asking this.
Well yes, this is a good thing. The vast majority of human-made websites aim at serving humans, not unverified bots.
good by who's definition? because there are plenty of people who hate cloudflare for flip flopping on nazi sites and will also heap that hate on just regular SWEs who join cloudflare who dont really have anything to do with those decisions.
Cloudflare is on them edge of your infrastructure. It's not in the middle of your service's infra and the user. It's not undermining TLS security because you are explicitly sharing the decrypted data with cloudflare to let them cache and protect your site.
>They have a tendency to deny access to normal users using privacy-friendly setups (Tor, without Javascript, etc)
To protect yourself against a bad actor you will need to fingerprint them and then imposes restrictions on them. People who are using privacy friendly setups look like they are trying not to be fingerprinted or have a shady fingerprint. By getting rid of a unique fingerprint that Cloudflare can learn to trust you end up always looking suspicious. Cloudflare did develop privacy pass to give these people a better experience when accessing websites protected by Cloudflare.
>and them operating in net loss (implying that the shareholders value growth, i.e. gobbling up even more of the internet infrastructure).
There are many competing CDNs. Most web traffic doesn't even use Cloudflare. There is still plenty of room for Cloudflare to grow.
>Some people are also concerned about their emerging ability as a powerful force for censorship and surveillance
This is a problem in general with internet service providers. ISPs can just decided not to peer with you or just null route your IPs. Cloudflare is less of a problem compared to major consumer facing ISPs.
>Cloudflare threatens the nature of the web as a somewhat decentralized system
So do DDoS attacks. If the small guy can't keep a site online like the big guys can that leads to a less decentralized web.
There's actually some work being done to make CDNs not able to MITM the origin.
https://web.dev/signed-exchanges/
https://developer.chrome.com/blog/signed-exchanges/
Also, it's pretty common to use cloud X's load balancing service(/serverless product/etc) when hosting on cloud X, thus giving AWS/GoogleCloud/Azure similar MITM capabilities.
Until someone creates a well-thought decentralized CF alternative from the ground up, which solves bad actor, slow and unstable node problems, with clever incentives, et cetera et cetera, we'll be stuck with centralized solutions.
P2P is a lot of things, but latency optimized is definitely not it. Things like DHT involve lots of hops, you also can't control the quality of nodes.
I understand why you thought of blockchain when i said p2p has bad latency. Blockchain of course has latency that is beyond terrible, but that is not what i was thinking of. I was thinking of bit torrent. Bit torrent is amazingly fast for a bulk download once it gets going, but is really slow to get going. Even just figuring out which nodes have your files is unacceptably slow for this usecase with the current distributed technologies (DHT). CDN is all about serving small static files with very low latency. P2P simply involves too many layers of indirection to work for that use case. I also don't see a way around it without centralizing things.
As far as security goes. Its actually not that bad and largely a solved problem using combinations of digital signatures and hashes. (Preventing DoS is a bit trickier although i think there are solutions for that albeit probably ones that prevent using geolocated nodes)
It is solvable, but any solution that spreads resources out across many different targets in the DHT is slow. Basically anything that was inspired by BitTorrent, but isn't BitTorrent itself does this, because they get overly excited by deduplication of data.
CDNs try and solve the "speed of light is too slow" problem. To make sense they have to respond to queries faster than a central server would (or a small number of geodistributed servers would). Otherwise the CDN does not bring value.
DHT traversal is usually log(n) in number of nodes. It seems unlikely that will ever be fast enough to compete with just hosting your stuff in one central data center even if your data center is on the opposite side of the earth.
This is a use case where 20ms can determine if the solution makes sense or not.
What I haven’t seen others mention, and is a literal open source CDN, Is Coral CDN. I’m not sure if it’s a going concern anymore, but it was a plausibly useful academic project circa 2005-15. I believe to ubiquity and accessibility of very cheap commercial offerings, and the ratcheting improvements in commercial CDN tech, really put Coral “out of business” by 2013 or so. http://dsrg.pdos.csail.mit.edu/2013/07/18/coralcdn/
Disclosure: principal at AWS, used to work on CloudFront and Route 53. Opinions are my own and do not reflect my employer or any proprietary information.
and every data center has a hardware ddos protection, you don't need a service for that if you use good web or server hosting provider.
cloudflare is not really that special. the reason normal people even know the name CF is because it was free. not because of what it provided.
and after they started censoring, there is no reason to keep using their services. they screwed themselves over by doing that. sooner or later they will stop being normies favourite and become purely corporate service.
I dont think you can have any sort of DoS protection if your ISP cuts off your internet if you're beign attacked...
“Just” run ngnix on your own servers from different geo locations. ngnix is very versatile, eg, load balancing, rate limiting, rule based firewall, caching…
but one important reason why saas/api/cloud businesses exist is that people don’t want to run their own servers for every project.
You can achieve the same protection by knowing your endpoints and infrastructure and then banning anything with an unacceptable delta of traffic difference.(asp vs php, wordpress vulnerability bots, etc) If you have multiple servers you share the ufw firewall lists among them in real time unless you want to ban higher up the stack.
The DOS protection might be harder to emulate. But at that point something is out to specifically get you anyways.
Just wait it out or move to another domain or ip.
Of course evil is in the eye of the beholder, most probably it's just money dynamics and its implications.
Any idea how many companies in the Fortune 500 use, say, Akamai Prolexic instead? Or other vendors?
Not to mention the big public cloud vendors like AWS, GCP and Azure that have their own CDNs too.