CloudFlare was launched as a stupid-simple CDN, but DDoS mitigation and bot reduction are actually valuable features for many websites. Sure, CF isn't the only business in this space, but most of their rivals are large enough to be in the S&P500 / Russell 2000, so it's not like garage startups are competing for this business.
"Was meant to be"
This isn't a law of physics. This was a starry-eyed hope by techno-utopians and academics when the internet was still 100% funded by Uncle Sam. When the internet moved out of its parents' basement, it had to grow up and get a job to pay the bills. Some people are fine with a SquareSpace webpage instead of running their own custom Apache httpd website on bare metal in a colo like it's 2005. The cost of maintenance and cognitive load is a cost we shouldn't ignore.
It turns out that economies of scale exist. The Internet doesn't need 10,000 small CDNs and they would all be inefficient and expensive if that was the distribution. Instead, there are a few large ones that can afford to colo in many geographically dispersed data centers and who negotiated bandwidth peering contracts for advantageous pricing.
> DDoS-for-hire cost only a few dollars per minute
I imagine those two are closely related. If not for Cloudflare and similar offers, we would spend more effort & resources on non-symptomatic treatment of internet-scale bad actors and its enablers (lately, more under-maintained "smart" devices than dumb modems, I hear). Every unresolved-for-years botnet is excellent advertising for CF, and they are not even paying for it. (We are all paying for it, dearly.)
Surprise! It's on crimeflare.
It was meant to be resilient and have multipath capability to route around damage. Having command authority sourced from multiple places was never part of the goal, and, indeed, in the client/server model that has prevailed the entire time the internet has existed, nothing about the design of the internet has been explicitly created to allow for server or data redundancy or distribution.
decentralized != distributed
Indeed, on the "modern internet" (aka the last 25+ years), everyone uses NAT, which means that end to end connectivity is not needed or wanted by most users and engineers. This idea that "every host should have a public IP, and every host should be a server as well as a client" is just fantasy that has no basis in reality, either in intent, or in practice.