It'd be even better if there were competition in this space, but there aren't too many options outside of cloud providers who are likely relying on the fact you might accidentally slip up one day so they can charge your credit card.
It'd be even better if there were competition in this space, but there aren't too many options outside of cloud providers who are likely relying on the fact you might accidentally slip up one day so they can charge your credit card.
Again: you do not need Cloudflare for your small-business website.
Do you have any idea of how many requests can a shitty unoptimised website serve on commodity hardware? Judging by comments like yours, which seem to be the majority, I wonder if anyone with less that 15 years of experience is still able to write a website serving 10k users a day (1 request every 8 seconds) on a 2 core VPS without needing a CDN.
Let me spoil the black magic only greybeard seem to know: STOP. OVERENGINEERING. You don't need Cloudflare. No one cares about DDosing your website, you're not Reddit for Heaven's sake.
If you overengineer, at least quit all rushing to give your custom to the same company, making Cloudflare a de facto monopoly.
If you happen to have a popular CMS like WordPress on a cheap VM, odds are you are going to get DDoS all the time, even if you only have 100 legit views/day. Cloudflare will reduce this dramatically.
I would guess any site not using Cloudflare (or someone similar) is more likely overengineering. As always though, every case is unique & it depends.
First, setting up anything using some third party service like Cloudflare is already too much work and doesn't even work for many people in parts of the world Cloudflare has determined are undesirable.
Second, I can, have and do host popular CMSes on hardware much more modest than Raspberry Pi performance.
Third, "odds are you are going to get DDoS all the time"? Are you a Cloudflare shill? This is nothing but wildly hyperbolic. In a quarter of a century of hosting, I've had to deal with one specific DDoS actor. One.
How are you going to claim that "odds are you are going to get DDoS all the time"? Go ahead, provide evidence, although I'm sure you can't and won't.
People put up fake WordPress logins as honey pots. I'm not sure what to say to this. If you host a WordPress site you're going to get lots of traffic trying to take your website down unless your provider is helping you block it. If you go outside on a summer day, the sun is going to be shining. I have never had a WordPress site that didn't get a ton of bad traffic. If it lived on a cheap VM with a MySQL database, PHP & WordPress, it was going to be under stress at least a few times a year. Tossing Cloudflare on it takes less than 10 minutes & a few years ago was the 1 of the easiest/cheapest ways to get SSL on it. In my quarter of a century of hosting, I have had a lot of DDoS attacks & none of those sites got over 100k legit users a month. Most also didn't care about users outside their own country.
It doesn't matter to me if you use Cloudflare or someone else. I don't make money off it but I will admit it is one of my favorite providers by far. I do also really like how the executive team is personal, handles themselves online & reaches out to devs.
I have no idea how people putting up Wordpress honeypots is related to this discussion, but for everything else, you're advocating treating symptoms and ignoring the problem.
If you, or anyone else, want to run a Wordpress site and you expect a firewall or DDoS service to protect you from stupidity, it might work for a time, but it's not the best idea. If you don't rename your wp-login.php, that's on you. If you install 27 plugins that you don't really need then ignore the fact that they'll need constant updates, that's on you. But those are common sense things - again, the root issue should be addressed, so the symptoms never happen.
Also, if bots banging on your wp-login.php and/or "ton of bad traffic" are what you consider a DDoS, perhaps you really should consider basic site security. We call "a ton of bad traffic" normal.
I'd much rather a site that has fundamentally fewer problems than a poorly configured one that's "protected" by Cloudflare.
Oh - and what does "most also didn't care about users outside their own country" have to do with it? You're advocating FOR the idea of stratifying the Internet? Then I guess you really are a fan of what Cloudflare is doing!
Wordpress should integrate one of those "Wordpress to static site" plugins as the default because that's all 80% of the users need.
Folks pointing out that their Raspberry Pi self-hosted static site résumé can handle 500 requests per second are missing the point.
The Wordpress approach of dynamically composing every page server-side made sense:
* Before AJAX made personalizing the 'logged-in experience' easy even on a mainly static site
* When CPUs were so slow that regenerating, say, 1000 static HTML files just because you updated your footer or your "top stories" sidebar would take an annoying amount of time instead of what, 4 seconds now?
* Before spambots essentially made it impossible to host a comments section, and Disqus and the Facebook plugin became the defacto choice for anyone still brave enough to try.
Due to the above, I can't imagine using PHP or even some sexier-today technology to dynamically just-in-time assemble HTML pages that 99-100% of the audience will be viewing statically.
Please tell this to every junior/cloud developer/architect when it comes to microservices.
Flash forward about 8 years and I find myself using cloudflare to stave off the immense suffering of Azure/AWS by using R2 and Pages. As soon as more people find out how easy Cloudflare is and how much it can lube a product deployment, I expect a lot more of the internet to end up there by choice.
Cloudflare deployed my app better/easier than Microsoft was able to deploy it to Azure (Microsoft owns GitHub and Azure and still didn't have their shit ironed out...Cloudflare just works).
I had to tweak them both but Azure took hours and cloudflare was a quick, cleanly documented change.
I wish they offered a service to host my nodejs APIs.
I haven't read into why Open AI uses Cloudflare instead of Azure services but I find it very interesting considering their Microsoft arrangement.