Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

271–280 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#271
I get it... but you can pry my cloudflare-tunnel from my cold dead hands.

I'm no stranger to hosting things 'the hard way', but I am not going back from my happy casual hosting where I just spin up a docker container, and point the cloudflare tunnel at the local port and opt out of worrying over DDOS, SSL termination and certs, and everything else that goes with it.

With tailscale, I don't even keep port 22 open to the world.

Re: Do not put your site behind Cloudflare if you don't need to

#272

Earlier quoted context omitted.

> You aren’t locked in. Did you consider and discard the eventuality that all the other ISP have gone out of business because everyone just uses cloudflare? Invasive species destroy ecosystems.

I am suggesting you host your website on your own server somewhere, and then you put it behind cloudflare. You still have your own host, just the same as you would without cloudflare. You are still providing your non-cloudflare host with the same revenue you would if you didn't use cloudflare, so I am not sure how that would hurt the ecosystem. The 'Invasive species destroy ecosystems' quote sounds good, but what exa…

> I am suggesting you host your website on your own server somewhere, and then you put it behind cloudflare

I'd rather advocate for a solution that doesn't induce centralization. Because that still does. It's a weird suggestion to pay twice. I'm assuming in your hypothetical, cloudflare not only doesn't ever go down, but also absorbs only malicious traffic, and not any organic? Why should cloudflare do that and not my primary host? I'll assume I have XX to spend on hosting, you don't see how if I have to also allocate some of that to cloudflare, in addition to the real host, how that might limit what the real host can charge? If the real host can't charge enough to fund R&D on services like basic DDoS or other traffic shaping, wouldnt that mean I've then become dependent on cloudflare? And now hey cloudflare has other service, and I don't like the extra overhead of paying multiple services... I'll just move everything to cloudflare because they're bigger and do both... and now the small host is gone.

sigh

> The 'Invasive species destroy ecosystems' quote sounds good, but what exactly does it mean in this case? What is the species, and what is it invading?

I'm comparing cloudflare to any species that enters an existing system that has developed a natural ecological balance that includes diversity. Which then proceeds to grow for the sake of growth, consuming resourcs at an unsustainable rate; destroying the diversity that previously existed.

Destroying that diversity is bad because that diversity is what gives the system as a whole resistance to catastrophic events.

Like huge parts of the Internet going down because someone wanted to ship their project before the holidays, in time for their perf review.

The argument being: we should view cloudflare's growth, and consumption and takeover of the resources of the Internet as a whole, similar to the way we view other invasive species. It destroys the good parts of an existing system in a way that is almost impossible to recover from. Resulting in a much more fragile system. One than's now vulnerable to single events that take down "everything". A healthy system would be able to absorb such an event without destabilizing the whole thing.

The invasive species is cloudflare, and it's consuming and replacing large existing sections of the Internet; which gains much of it's strength and resilience from it being distributed amongst it's peers.

Re: Do not put your site behind Cloudflare if you don't need to

#273
post #61

Earlier quoted context omitted.

It sounds like OP is describing a situation where someone persistently DDOS's them as long as it works. In which case DDOS time trivially dominates cloudflare outage time. Note that OP is posting, even now, from an anon account. This is a good essay: https://inoticeiamconfused.substack.com/p/ive-never-had-a-re...

> Note that OP is posting, even now, from an anon account. Lol I didn't even notice that my submission reached the front page. What is your evidence for that claim?

Oh sorry, not you. The OP in the chat thread, they were DDOS'ed by someone and are commenting anonymously. Maybe grandparent is the correct word for it, in any event this is the comment I was referring to when I said OP, not your article: https://news.ycombinator.com/item?id=45966683

Re: Do not put your site behind Cloudflare if you don't need to

#274

Earlier quoted context omitted.

What's the cost for someone to put their blog behind cloudflare, besides a few minutes of setup?

The posted article which you are commenting on is entirely about why you shouldn't...

It doesn't address the comment to which I was replying.

Re: Do not put your site behind Cloudflare if you don't need to

#275
post #83

Earlier quoted context omitted.

What's the cost for someone to put their blog behind cloudflare, besides a few minutes of setup?

What’s the cost of making the internet more centralised because of sheer laziness?

Do you think most people who want to start a blog are thinking about the centralization of internet services?

Re: Do not put your site behind Cloudflare if you don't need to

#277
It is mentioned in the article that round-robin DNS is an alternative to this setup, however, in reality, it is not the same thing, and that's the reason load-balancers exist, and it is not feasible to provide something very similar due to the very nature of a distributed and cached DNS system.

Re: Do not put your site behind Cloudflare if you don't need to

#278
post #269

Earlier quoted context omitted.

If you can move off of CDNs then you're not in a world where all personal blogs are centralized.

And thus, the lemmings walk straight off the cliff. There seems to be two views. One forward looking and one not. The forward looking view appropriate recognizes the threat of centralization. Centralization crushes small businesses (and small blogs), leads to censorship (see youtube et al.), and destroys competition. No one on the planet can compete with cloudflare pound for pound and thus if they decide your site is…

[deleted]

Re: Do not put your site behind Cloudflare if you don't need to

#279

Earlier quoted context omitted.

Nah, the cliche still applies there as well.

No it really doesn't. How are you the product when Cloudflare gives you free tier access? That's not their business model. You aren't the product, but you are an upsell lead for the sales team.

Sales teams don't pay for leads? If you keep me around, exclusively because the sales team wants to show me something... I'm the product.

Follow up question, if I actually start using the DDoS protection or other services... will cloudflare cut me off unless I pay? Will that charge be exorbitant? Does that behavior feel like extortion? Have they done that before?

Re: Do not put your site behind Cloudflare if you don't need to

#280

Earlier quoted context omitted.

I am suggesting you host your website on your own server somewhere, and then you put it behind cloudflare. You still have your own host, just the same as you would without cloudflare. You are still providing your non-cloudflare host with the same revenue you would if you didn't use cloudflare, so I am not sure how that would hurt the ecosystem. The 'Invasive species destroy ecosystems' quote sounds good, but what exa…

> I am suggesting you host your website on your own server somewhere, and then you put it behind cloudflare I'd rather advocate for a solution that doesn't induce centralization. Because that still does. It's a weird suggestion to pay twice. I'm assuming in your hypothetical, cloudflare not only doesn't ever go down, but also absorbs only malicious traffic, and not any organic? Why should cloudflare do that and not m…

> I'd rather advocate for a solution that doesn't induce centralization. Because that still does. It's a weird suggestion to pay twice. I'm assuming in your hypothetical, cloudflare not only doesn't ever go down, but also absorbs only malicious traffic, and not any organic? Why should cloudflare do that and not my primary host? I'll assume I have XX to spend on hosting, you don't see how if I have to also allocate some of that to cloudflare, in addition to the real host

You don't have to pay cloudflare anything at all for them to act as CDN and provide basic DDoS protections.

Post reply on HN