Live data from Hacker News

Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

blog.cloudflare.com

141–150 of 168 posts

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#141

Earlier quoted context omitted.

Support and also all-around enterprise readiness. Even on the enterprise tier, their permissions management is a pale shadow of what IAM grants you on AWS or GCP, to the point where you will put your compliance as risk. No documentation on setting up SAML/SSO for their management console. It's very, very clear that their internal growth engines are set to ludicrous growth rates (to try and justify their outrageous st…

I think they made their permission system much more fine grained during developer week. Is your info still up to date? ( I'm not following this topic too much, but I do remember some things passing by). --- Additionally, most of their investors are companies and not private. There's a lot going on. One of the improvements that they did was in the sales department. If those previous sales that were severely underperfo…

Yeah, for example, you can grant Edit permissions on Cloudflare Workers overall within an account, but you cannot grant permissions on a single Cloudflare Workers deployment. Any developer who has permissions in, say, a development Cloudflare Workers deployment will thus have full permissions to the production Cloudflare Workers deployment, or permissions to deployments owned by other teams.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#143
post #6
post #4

It's a seemingly simple and obvious way to lazily migrate your data, but if using Sippy means one less thing for the application code to worry about, and (I assume) is a free add-on, then it provides a ton of value. I have to admit that Cloudflare has been killing it recently with DevX / OpsX. If I wasn't against that company's role in modern internet (as a user of Tor, their firewall is annoying to no end), I would…

This, CF is the only service that I find amazing, and that I do not use for anything. Compared to AWS, I think I prefer the "we're your unopinionated infra provider, if you want a WAF we have that too", vs the CF "block the world, especially the developing world, give zero craps about it". I fundamentally would be unhappy as their customer even if their service were stellar because I do not want my apps to be associa…

> and that I do not use for anything

Let's try. I suppose you know 1.1.1.1 but:

- Their WebAnalytics

- Flexible SSL ( instead of letsencrypt)

- Their free Hugo setup ( for your blog) -> Cloudflare Pages

- Buy DNS domains at cost

- 500 Cloudflare worker scripts for 5€ / month. Or 100 Cloudflare worker scripts for free

- Cloudflare tunnel - instead of ngrok or others. You can link it to your subdomain, other options have a paid option if you want to link a subdomain.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#144
post #94

Earlier quoted context omitted.

$5k/month is just Cloudflare's opening bid. In Enterprise sales, you are expected to negotiate for a discount. Common rule of thumb is that Enterprise sales (in general, across vendors) start at ~$2k/month (this is what's necessary to pay for salespeople's salaries) and savvy negotiators will end up close to that figure for bare-bones plans.

In what world does 2k/month pay a sales persons salary? And what enterprise sales person is OK selling something for $2k/month/$24k/year when they carry a quota 20-50x that amount? Enterprise deals start at 100-200k/year, minimum, IME.

I'm not including some full Solutions Engineer / Customer Success Engineer kind of integration work on part of the vendor - I'm talking about, you go to the vendor's website, you see some feature you need (like SSO) is under "Contact Us" pricing, usually the barebones for that is $2k/month. This represents meeting with Sales for 15 minute calls a handful of times so they can qualify you, understand your usecase, present you with a quote for more than you need, then negotiate down.

Enterprise salespeople working in that segment understand you're small-fry and they'll kick you a small contract not because they're going to get rich off the commission but because they know that depending solely on whales is a high-risk approach that sooner or later gets them fired. Small contracts pad them out and provide more reliable monthly numbers as long as the sales process doesn't turn into a tarpit that isn't worth the money.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#145

9 cents a gigabyte downloaded versus 0 cents a gigabyte downloaded is a pretty good deal. There’s not much AWS can do about it because they must make untold billions from those sweet, sweet S3 egress fees. I’d be willing to bet S3 egress fees make up about 60% of all AWS revenue.

S3 egress and inter-AZ traffic. The way they advertise multi-AZ should honestly be illegal, or at least include warnings about charges. Like when you set up an RDS instance, the “prod” template defaults to multi-AZ (a good idea tbf), but completely elides the fact that if your app is in a different AZ, you’re going to start racking up $0.02/GB. Same with NLBs and cross-AZ routing. Sure, it can be helpful, but yeesh.…

Or NAT prices... there's a good reason why there's FCK-nat. Those nat prices are terrible

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#147

Google cloud storage support plz. Also warning to people to use R2 from the get go otherwise you will be stuck with weird architectures like this using both paying for both

Just a note.

Google Cloud is already in the bandwidth alliance, while AWS is not.

So you can send your files already to cloudflare at a discounted rate.

https://www.cloudflare.com/bandwidth-alliance/

Additionally, there are reasons to keep your data duplicate within AWS. There's no one-size-fits-all here.

The point is to make use of cloudflare free eggres to get your data where you need it ( since others have egress costs, but no ingress costs)

Eg. Train ml models in AWS, GCE or Azure ( where compute is cheapest) and make use of cloudflare to provide them with the data.

This should create a huge cost saving, since there's no eggres anywhere.

Example: https://blog.cloudflare.com/cloudflare-r2-mosaicml-train-llm...

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#148

Earlier quoted context omitted.

>Blocking Tor is purely a customer configuration ...that's on by default and so used by the vast majority of Cloudflare customers making it effectively a Cloudflare configuration.

I'm pretty sure it is not on by default and cloudflare also provides onion routing by default so it even helps legitimate Tor users.

They may not block them by "default" but when all the onion browsers automatically have a high threat score for not running cloudflare's invasive javascript it's the same thing. Especially combined with the high "threat score" they attribute to almost all out node IPs. I don't even use tor and they still block my browser when I'm trying to read science journal articles because my browser cannot run their bleeding edge features they use in their spying javascript.

And everyone knows it because that's what the lived experience of trying to access cloudflare blocked sites on tor browser (or any other browser that's not made by a megacorp). It doesn't matter what cloudflare's intentionally ambiguous and probably disingenuous wording might try to imply. The only people who think otherwise have never actually tried using tor to surf the web.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#149

Great to finally see this here! Cloudflare is the 4th major cloud platform that (almost) nobody is seeing coming, and I believe that they will even surpass Google Cloud Platform's sooner than expected. The only problem that remains is their support... I'm writing a book about Cloudflare (launching very soon) where I share this and many other things to scale faster all while saving big on your cloud bills. You can joi…

Support and also all-around enterprise readiness. Even on the enterprise tier, their permissions management is a pale shadow of what IAM grants you on AWS or GCP, to the point where you will put your compliance as risk. No documentation on setting up SAML/SSO for their management console. It's very, very clear that their internal growth engines are set to ludicrous growth rates (to try and justify their outrageous st…

please find the docs for SSO setup for the CF dashboard here: https://developers.cloudflare.com/cloudflare-one/application...

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#150
post #65

Earlier quoted context omitted.

It’s so annoying when I travel and I can’t access login to my Utility provider’s website to pay my bill. I understand they don’t want get hacked but believe it or not, customers travel.

I found out a few months ago that my router has a built-in VPN that I just had to turn on. Now it doesn't matter where in the world I am, it can always look like I'm not only in the US, I'm actually on my home network. That might be worth considering if you're traveling a lot: it's about as benign-looking to providers as is possible.

I'd be afraid of doing that, knowing how insecure most home routers are. Seems like a zero day (or really even a "zero year", considering how behind updates can be) away from having your home router become part of a botnet...
Post reply on HN