CloudFront vs CloudFlare
cloud.dzone.com
cloud.dzone.com
CloudFlare does have a single file purge option available: http://blog.cloudflare.com/introducing-single-file-purge
Single file purge is also available via our API here: http://www.cloudflare.com/docs/client-api.html#s4.5
I have mentioned this correction to the author as well.
Cloudflare makes websites unavailable if you use services like unblock-us.com (see below)
High amount of 404 I get from cloudflare when browsing /r/pics makes me wonder who is to blame.
Cloudflare is short on locations.
Cloudfront is cheaper if you use SSL.
============
➜ ~ dig cloudflare.com
; <<>> DiG 9.8.3-P1 <<>> cloudflare.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 3675 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION: ;cloudflare.com. IN A
;; Query time: 4847 msec ;; SERVER: 208.122.23.22#53(208.122.23.22) ;; WHEN: Sat Dec 1 18:42:43 2012 ;; MSG SIZE rcvd: 32
; <<>> DiG 9.8.3-P1 <<>> @208.122.23.22 cloudflare.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12445 ;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION: ;cloudflare.com. IN A
;; ANSWER SECTION: cloudflare.com. 300 IN A 173.245.60.249 cloudflare.com. 300 IN A 173.245.60.250 cloudflare.com. 300 IN A 173.245.61.248 cloudflare.com. 300 IN A 173.245.61.249 cloudflare.com. 300 IN A 173.245.61.250
;; Query time: 61 msec ;; SERVER: 208.122.23.22#53(208.122.23.22) ;; WHEN: Sun Dec 2 01:24:29 2012 ;; MSG SIZE rcvd: 112
No they don't. CloudFlare just has a security mechanism where known bad or risky IPs are presented with a captcha. However on sites with "max" security, I believe it simply blocks them entirely.
http://news.ycombinator.com/item?id=4235893
The blog post is titled "When 'Dumb Pipes' Get Too Smart"
Also fails to mention that if the CDN gives you an IP that is the same as a Kiddy Porn site, or a pirate site that you could have Law Enforcement on your doorstep (worst case) or be delisted by Google, or blocked by NetFilters.
CloudFlare is not worth the headache. Put a squid on Azure, Rack, AWS, or Google Cloud Compute and you can have nearly the same features, for nearly the same price. And not have any of the negatives.
And I'm not buying into that you could have law enforcement on your doorstep. How on earth would they tie it to you? The IP-adress is registered to CloudFlare, not you. If they have the means to find a "kiddy porn"-site, they also have the knowledge to see that it's distributed by a Content Delivery Network.
Are you really comparing a globally distributed content delivery network with a squid installed at one location on one provider?
CloudFlare might not be worth the headache, but for entirely different reasons than you have listed.
Cloudflare displays a cloudflare-branded error page when anything goes wrong. That happens quite often, and as far as I know you can not turn that off. Oftentimes Cloudflare claims the "the backend is down" when the backend is, in fact, serving fine (which I've verified on more than one occasion).
Furthermore Cloudflare significantly degraded both latency and availability outside the US when we tested them, versus using the US origin. We've seen their error-page and 'connection refused' errors spike into the 10% range multiple times a day. Latency variance was pretty wild, with europe spiking into the 500ms(!) range.
The only other CDN I've seen similarly atrocious performance from was MaxCDN.
If you're looking for a CDN to speed your site up (duh!) then I'd recommend to go with one of the more established players. Cedexis provides a nice report that tells you which CDNs perform best in your market; http://www.cedexis.com/country-reports (I'm not affiliated with them, take their figures with a grain of salt, do your own testing on an evaluation account!)
Either way, given their performance we were not interested to upgrade. Cedexis currently shows CloudFlare with 22.9% error rate and 1123ms slowest avg response time, in the USA.
If you can tolerate that kind of performance in a primary market then you don't need a CDN to begin with.
I assume Cloudflare is having a temporary problem right now, their figures don't normally look this bad (last I checked they were in the top10 on cedexis).
However, this mirrors what we observed in our lengthy evaluation. Performance was extremely variable, up to the point of some regions becoming effectively unavailable for hours at a time. Today might be such a time...
As someone who uses CloudFlare on a site that depends on Google traffic (~800K/month directly from G), this is simply not true.
I do wish they supported taking authority of a subdomain, or simply required a CNAME like many CDNs.
Note: For this CDN HTTPS to be useful, you also need to have your main site URL have it, say, via a certificate from StartCom and a VPS or a good shared hosting site. It is a good deed to offer HTTPS even on static sites because it helps protect users' privacy (if they are using WiFi, Tor, or a sketchy ISP; which is likely). If you're distributing software or code, having some sort of signing -- HTTPS and/or GPG -- is critical to protect your users from malicious MITMs; more users are going to verify HTTPS because they don't have a choice about that one.
CloudFlare takes over your domain and reverse proxies your site, to your control. They cache resources for you, selectively, to your complete control. They have some security features, like presenting captchas to dodgy IPs. The base service is completely free, albeit restrictive, but there are no bandwidth caps. They also have "apps" that provide extra features, like asynchronous JS loading, automatically adding Google Analytics to every page, email scrambling, etc. Everything is customisable - if you want, you can completely disable the security features, caching, apps, in fact, you can also disable the reverse proxying for subdomains (which of course removes all the CF benefits).
My web app, http://ponyplace.ajf.me/, has benefited greatly from being on CloudFlare, since it has relieved the burden of serving most static content from my server. It's a really great service, especially for the price. My only complaint is that SSL usage on CloudFlare is pretty pricey.
Cloudflare are disrupting a very established and lucrative industry. Companies like Prolexic charge a lot more for a lot less. Not to mention the whole "Are you currently under attack?" bullshit they pull where they charge you significantly more if you are currently a DDOS victim.
CloudFront is a content delivery network, CloudFlare is part content delivery network, part front-end optimisation service.
What CloudFlare do it optimise the content so that it loads faster e.g. by minifying JS/CSS, merging files etc. i.e. many of Steve Souders rules.
There are other services around which do much the same thing Google's PageSpeedService, Strangeloop Networks, Torbit etc.
You could perhaps achieve much the same thing using mod_pagespeed, or Aptimize etc. on your webserver and a CDN in front.
If you chose a CDN that allows you to push your dynamic pages through it e.g. Fastly, then even the HTML delivery can be speeded up in many cases (even if the CDN doesn't cache the HTML, which perhaps it could for many sites)
Real challenge that the article doesn't cover is where do CloudFront, and CloudFlare have slow performance e.g. due to peering arrangements etc. That's where multi-CDN providers (ala TurboBytes) can help
4TB of bandwidth saved in the last 30 days for a measly $20.
I do have small issues that arise, mostly false positives and occasional outages, but nothing too bad at all.
Compared with the costs of any other CDN and I would be looking at a rather large bill.
What if they have negotiated contracts with wholesale data providers where they get a revenue share for any traffic they bring into the network? This would mean that the more sites they have hosted, the more money they bring in for their carrier (which they bill the downstream for) and in turn, the more they make.
I dont not work for Cloudflare and have never worked in the carrier/hosting biz, so this is just a theory. I am however, a very happy enterprise customer.