Live data from Hacker News

Cloudflare had a partial outage

cloudflare.com

271–280 of 448 posts

Re: Cloudflare had a partial outage

#271
post #102

Earlier quoted context omitted.

I'm on Linode. Linode is down because Cloudflare is down. Can't login to their control panel, etc. You'd need to go fully independent and roll your own, with zero dependencies, to really make this work.

Yeah, they'd also be dependent on their ISP still if they're "fully independent". Good luck dealing with massive traffic spikes on a single bare-metal box and good luck maintaining a similar uptime to cloudflare's 98.84% uptime lol

Most (or at least many) colo facilities have multiple transit ISPs, some are big enough to have decent peering as well.

I'm assuming 98.84% uptime is a joke? Less than 4+ days of downtime is something I could manage from a home connection most years, if I had a static IP.

Re: Cloudflare had a partial outage

#272
post #24

This should hopefully drive home the idea of why HN shouldn't be cheering on Cloudflare's slow takeover of the internet.

CLoudflare just offer great services. Its straight up fact that even their free model is extremely generous. There is no big conspiracy to 'take over the internet' but when the product is good, the product is good.

This. I used Cloudflare for 10 years as a free customer. Now I pay them at least $5k a month. Freemium works when the services are good.

Re: Cloudflare had a partial outage

#273
post #102

Earlier quoted context omitted.

I'm on Linode. Linode is down because Cloudflare is down. Can't login to their control panel, etc. You'd need to go fully independent and roll your own, with zero dependencies, to really make this work.

Yeah, they'd also be dependent on their ISP still if they're "fully independent". Good luck dealing with massive traffic spikes on a single bare-metal box and good luck maintaining a similar uptime to cloudflare's 98.84% uptime lol

98.84? that a real number? that's pretty low

Re: Cloudflare had a partial outage

#274
post #265

It's time to start discussing a fail-open option for us CF users. Most of my sites are using CF for global performance rather than DDoS protection and security. I'd be fine with them changing DNS to point to the origin (or any other user defined IPs) in case of issues (even if it would take hours to return to normal). This is also important for countries with limited connectivity to the Internet, if the PoP in that c…

Wouldn't this expose the origin IPs to attack?

Yes, but I'd wager that most sites experience cloudflare outages more often than they experience bona fide attacks.

Re: Cloudflare had a partial outage

#275
post #225
post #198

Earlier quoted context omitted.

The comment on HN had more useful information (that the issue was understood and a fix coming) before that status page then updated. I think that's their point. Prior to that, it was some time (in the "all my sites are wrecked" timescale) before the status page had any indication of an outage.

The way I read their complaint was that they should have something on their website to indicate they were down. Anyway, at the time they complained, the status page also already said that the issue was identified and a fix was being rolled out.

Their post was saying that the dedicated status domain should be the first place to get useful information. There were multiple new threads on HN before the status page was updated at all. I'm sure there are legal reasons, but it's not ideal.

Then there was the CTO's (appreciated!) comment prior to the status page's second update with information suggesting this would be resolved soon (which IMO is the information everyone needs to report back to clients, bosses, etc).

That the status page was subsequently updated prior to OP's complaint isn't really relevant. It's still a point of discussion, whether someone comments immediately or later, right?

Re: Cloudflare had a partial outage

#276
post #265

Earlier quoted context omitted.

Wouldn't this expose the origin IPs to attack?

I'm talking about this as an option for users like me, that don't have an attack surface, but need the global performance gains of CF.

Probably not many users who need the performance and can handle unexpected failover. There would also be the issue of setting the policy defaults effectively. Most users wouldn’t benefit from this footgun.

If you’re serious, you could probably automate this right now with your DNS provider and uptime monitoring.

Re: Cloudflare had a partial outage

#277
post #265

It's time to start discussing a fail-open option for us CF users. Most of my sites are using CF for global performance rather than DDoS protection and security. I'd be fine with them changing DNS to point to the origin (or any other user defined IPs) in case of issues (even if it would take hours to return to normal). This is also important for countries with limited connectivity to the Internet, if the PoP in that c…

Wouldn't this expose the origin IPs to attack?

Yes, but he says in his second sentence that he doesn’t mind and mainly uses CF for performance.

Re: Cloudflare had a partial outage

#278

It's time to start discussing a fail-open option for us CF users. Most of my sites are using CF for global performance rather than DDoS protection and security. I'd be fine with them changing DNS to point to the origin (or any other user defined IPs) in case of issues (even if it would take hours to return to normal). This is also important for countries with limited connectivity to the Internet, if the PoP in that c…

You’d need to have TLS certs on origin ready to go for this scenario to work. Additionally, you’d need to make sure to test it and ensure that there’s nothing wrong in this event. On top of that, depending on your scale, can you take all the traffic on origin that Cloudflare currently offloads?

No issue for me. This is obviously a power-user option. It's kind-of implemented for Enterprise users were you don't have to let CF have full control over the domain.

Re: Cloudflare had a partial outage

#280
post #265

Earlier quoted context omitted.

Wouldn't this expose the origin IPs to attack?

Yes, but he says in his second sentence that he doesn’t mind and mainly uses CF for performance.

Plenty of commenters also seem to miss the most important word in the first sentence: "option".
Post reply on HN