Live data from Hacker News

Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

blog.cloudflare.com

111–120 of 168 posts

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#111

Earlier quoted context omitted.

The geographical blocks are not enforced by Cloudflare as a blanket ban, but are chosen by each account owner (it's a setting you configure). I've worked with a few companies that saw this as a very valuable service (like small domestic companies blocking international traffic, especially from Russia and China, because we had no presence there anyway and that cut down bot traffic by like 95%). Likewise, TOR access is…

I don’t understand the parent viewpoint. “I don’t like Cloudflare because they’re trying to centralize the Internet and block me” It’s not as though Cloudflare goes out and randomly inserts themselves in Internet traffic and has some blanket policy of ruining TOR or blocking you. Cloudflare has customers (site hosts) that have choice in the marketplace and choose them. The customer configures whether their services u…

Yeah.

I think cloudflare is even the only one that supports the "onion routing" to improve the situation for real Tor users.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#112

Does CloudFlare have an on-demand image optimization like Vercel? I love that I can specify and Vercel just took care of it for me. I am looking for something cheaper and works on native mobile apps as well.

They have an image cdn that does resizing and such, but the per-request fees are rather high.

What do you mean? Cloudflare is 25 x cheaper than Vercel

Vercel : 5$ / 1000 requests

Cloudflare : 9$ / 50.000 requests

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#113
post #95
post #75

Earlier quoted context omitted.

What's the alternative if most of tor traffic is password attempts and bad actors how do you protect yourself from tors bad actors without effecting all of tors users. I work at a company that runs a large website top 1000 websites in the world, and we don't even have to block tor exit nodes since they trigger our bot and snap blocking rules on our firewall, how do we let valid for users through without letting all t…

How would you deal with an attack though residential US proxies? Your method falls apart. How many of us deal with automated password attacks is to issue questions that only locals or people with specific knowledge could answer. Change the questions and do everything custom.

It sounds like they have behavior-oriented rules that are just always triggered on Tor because Tor traffic has a disproportionate amount of bot traffic. I see no reason why behavioral blocking breaks down when an attack comes from an IP space that is usually more benign.

> How many of us deal with automated password attacks is to issue questions that only locals or people with specific knowledge could answer. Change the questions and do everything custom.

If I'm understanding what you're saying, this sounds horrible. What if I'm visiting an area where I don't have local knowledge? What about for the year or so after I move in to a new city? What if your assessment of what locals do and don't know is just wrong? There are a ridiculous number of failure modes in this questions-oriented approach. The only place this could possibly make sense is in some sort of internal company software, but even that context has better options available.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#114

Earlier quoted context omitted.

As a business owner who geoblocks: It's not usually a benefit to a business if a customer pays upfront. Whether my customer pays by debit or credit, I get all of that money upfront before I let the transaction proceed. Some businesses, like car dealers, actually make more money if the customer buys using debt, because they get incentivized by the loan company. And lastly, the sheer scale of the US economy means that…

When I say pay "upfront", I don't mean that the upfront cash is better for business, but that usually, the credit industry is very good at letting people buy things they can't afford. Some one who pays upfront likely can afford and might have higher lifetime value. Someone to advertise to, upsell, or whatever. Secondly, I also get it, there's only so many things a business can worry about, and supporting geographies…

> Some one who pays upfront likely can afford and might have higher lifetime value. Someone to advertise to, upsell, or whatever.

100%. Richer people tend to be better customers. But that's another strike in favor of geoblocking non-US visitors.

When I was a kid growing up in Africa, I dreamt of a world where everything was accessible and purchasable and learnable everywhere, all the time, to everyone. Hopefully the internet turns out to be an equalizing factor and we get there someday.

Right now it's not really fair to expect business owners - most of whom are in non-tech businesses that require 100% focus - to keep up with the tidal wave of scams, hackers, and regulators originating from outside their sphere of concern.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#115
post #39

Earlier quoted context omitted.

That's partially why so many llm/ai apps use cloudflare. An API call can take a lot of seconds. While Cloudflare only bills cpu-time ( eg. 10 ms. ). Other providers bill those seconds too as "duration", while the CPU was just sitting idle.

I can see both sides because you are reserving that amount of RAM while your process is running. The Lambda price is also proportional to the RAM reserved.

Well.

I thought that this was possible because Cloudflare eliminated cold start delays.

So there's no RAM reserved either, I guess.

( can someone correct me if I'm wrong?)

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#116
post #75

Earlier quoted context omitted.

What's the alternative if most of tor traffic is password attempts and bad actors how do you protect yourself from tors bad actors without effecting all of tors users. I work at a company that runs a large website top 1000 websites in the world, and we don't even have to block tor exit nodes since they trigger our bot and snap blocking rules on our firewall, how do we let valid for users through without letting all t…

My take on this: if there is some DDoS taking place from same IP I am connecting from, that sucks for me but I'm willing to tolerate it (good old fail2ban). But having such a firewall all the time, even when you are getting less than 1 request per second from ToR? That's an overkill

If I occasionally get a DDoS from Tor, I'll probably just block Tor all the time, even if my current traffic loads from Tor are low. It's simply not worth the hassle of waiting until my servers start getting spammed, it's better to just keep the door shut all the time.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#118
post #62

Earlier quoted context omitted.

Really? From Custom metrics, or logs? It's pretty rare that I hear anyone use it in production, there's usually either a SaaS like Datadog/New Relic or a homegrown setup with e.g. Prometheus.

I had been running https://dockeri.co with https://arc.codes/ for pennies a month. Then, one month, I got a ~$500 bill out of no where. Docker had changed an api causing my service to return 5xx errors all month. Each error was individually logged to CloudWatch - which racked up a ~$500 bill. I moved to Cloudflare Workers that day and haven’t moved back.

Lol.

The Cloud really loves logging ( bills :p ).

It would be nice if Cloudflare implemented "Open telemetry".

It could reduce the cloud bill by at least 2. Logging is really expensive.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#119
post #40

Earlier quoted context omitted.

Nah. This is literally to have a migration path and to only occur once the Amazon eggres fees. At the end, you can still decide to migrate all data or to abandon the not-used-till-now data.

Yes, it's free/very cheap to move S3 data to a tier like Infrequent Access or Glacier with lower monthly cost and higher retrieval cost.

"higher retrieval costs"

Getting that data is really high. It should only be used if you are sure it will never be accessed.

I've read quite a few posts where they complained about the huge bill, when they needed to get their data...

Not sure how it is right now, it's still obscure on their pricing page and before, you had to check the gotchas in their FAQ .

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#120

Does CloudFlare have an on-demand image optimization like Vercel? I love that I can specify and Vercel just took care of it for me. I am looking for something cheaper and works on native mobile apps as well.

Yeah https://developers.cloudflare.com/images/image-resizing/ https://developers.cloudflare.com/images/image-resizing/url-... Example: src="/cdn-cgi/image/width=80,quality=75/uploads/avatar1.jpg About /cdn-cgi/image/ It's a fixed prefix that identifies that this is a special path handled by Cloudflare’s built-in Worker. --- Price at Cloudflare : 50,000 monthly resizing requests included with Pro, Business. $9 per add…

that is a lot cheaper than Vercel in term of store image but egress seems expensive since they charge per cache image served as well. Do you know if Cloudinary is a better option?
Post reply on HN