Cloudflare

Cloudflare

Definition: A San Francisco-based edge network and security company, founded in 2009 by Matthew Prince, Lee Holloway, and Michelle Zatlyn out of an earlier anti-spam research project, that has grown from a CDN and DDoS-mitigation service into a full edge computing platform. It now operates one of the largest anycast networks on the internet, commonly cited as reaching 300+ cities worldwide, and routes traffic for a significant share of all internet requests. Went public on the NYSE in 2019, and has since expanded aggressively into serverless compute, object storage, Zero Trust security, and developer tooling under its broader “connectivity cloud” positioning.

Core Services & Concepts

  • CDN — Content Delivery Network (CDN) and Edge Computing, Cloudflare’s original product and still the backbone of the rest of the platform, caching content across its anycast network
  • Workers — Serverless Computing and Cold Starts, V8-isolate-based serverless functions that run at edge locations with near-zero cold start, positioned as a lighter alternative to container-based serverless
  • R2 — Cloud Storage Systems, S3-compatible object storage with no egress fees, explicitly marketed as a lower-cost alternative to AWS S3 for teams paying heavily for data transfer
  • Access / Zero Trust — identity-aware network access and secure remote access tooling that replaces traditional VPNs with per-request authentication tied to Identity and Access Management (IAM)
  • WAF & DDoS mitigation — a web application firewall and volumetric attack protection layered on top of the CDN, historically the feature that first put Cloudflare on the map
  • 1.1.1.1 — a widely used free public DNS resolver, launched partly as a privacy-focused alternative to ISP-provided DNS

How Pricing Works

  • Free tier is unusually generous for a platform this large, covering CDN, basic DDoS protection, and limited Workers/R2 usage at no cost
  • Paid plans (Pro, Business, Enterprise) scale up WAF rules, page rules, and support SLAs on a flat per-domain or per-seat basis
  • Workers and R2 are billed on usage — requests, CPU time, and stored/read/written data — separate from the core CDN plan
  • R2’s headline pricing advantage is zero egress fees, unlike S3 or GCS where data transfer out is often the largest storage-related cost
  • Enterprise pricing is custom and contract-negotiated, typically bundling security products, support, and higher rate limits together

Pros

  • Massive global edge network delivering very low latency in most regions, backed by one of the largest anycast footprints in the industry
  • Generous free tier that includes real CDN, DDoS protection, and DNS, unusual for a platform of this scale
  • No egress fees on R2, directly undercutting the pricing model of the major clouds’ object storage
  • Broad, increasingly unified product suite (CDN, Workers, R2, Zero Trust, DNS) reducing the number of vendors a team needs to stitch together
  • Strong security reputation, often the first line of defense cited when large sites survive major DDoS attacks

Cons

  • Not a full IaaS replacement, lacks the breadth of general-purpose compute, managed databases, and networking primitives that AWS/GCP/Azure offer
  • Workers have execution time and memory limits unsuited for heavy, long-running, or CPU-intensive compute
  • Support quality and responsiveness on lower tiers is a commonly cited gap relative to Enterprise-tier customers
  • Feature sprawl across dozens of products can make the dashboard and pricing model harder to reason about than more focused competitors
  • Because so much traffic routes through Cloudflare’s network, its own outages have historically had outsized internet-wide impact

Comparison: Cloudflare vs Akamai vs Fastly

CloudflareAkamaiFastly
Primary strengthLargest all-in-one edge network spanning CDN, security, and serverless computeDeepest enterprise relationships and longest-running large-scale CDN footprintFastest cache purge/invalidation and real-time configurability
Typical pricing modelGenerous free tier, self-serve usage-based paid plans, custom enterprise pricingEnterprise contract-based, sales-negotiated, rarely self-serveUsage-based, smaller free tier, pay-as-you-go plus enterprise contracts
Best fitStartups to large enterprises wanting a broad, self-serve edge/security platformLarge enterprises, broadcasters, and e-commerce needing contract-based SLAs at massive scaleMedia/news and API-heavy teams needing instant purges and fine-grained real-time control
API/product styleREST API + Workers (JS/Wasm serverless) + broad self-serve dashboardREST/Akamai API + EdgeWorkers, more enterprise-console-drivenREST API + VCL/Compute@Edge (Wasm), developer-first tooling

Best For

  • Teams wanting a single, mostly self-serve platform covering CDN, DDoS protection, DNS, and edge compute without enterprise sales calls
  • Frontend-heavy or API-heavy apps needing global low latency and protection against bot traffic and DDoS

Real Examples

  • Discord, Shopify, and a large share of the modern web use Cloudflare for CDN, DNS, and security
  • Frequently the provider behind sites that visibly survive large-scale DDoS attacks without downtime
  • Widely adopted by startups through its free and Pro tiers, then scaled into Business/Enterprise plans as traffic grows

Use Cases

  • Edge-rendered web apps and JAMstack sites needing global caching
  • DDoS mitigation and bot management for public-facing sites
  • Zero Trust network access replacing traditional corporate VPNs
  • Global API caching and acceleration
  • Low-cost object storage for teams avoiding S3-style egress fees

Integration Notes & Common Pitfalls

  • Proxying a domain through Cloudflare (the “orange cloud”) changes the visible origin IP, misconfigured DNS records left “grey-clouded” can accidentally expose the real origin server
  • Workers use a different execution model than Node.js, some npm packages relying on Node-specific APIs need compatibility shims or don’t run at all
  • Cache rules default to conservative behavior for dynamic content, teams often need to explicitly configure Page Rules or Cache Rules to get expected caching on non-static routes
  • Free and Pro tier WAF rule sets are more limited than Enterprise, teams with complex security requirements often hit a wall and need to upgrade

Code Example

// Cloudflare Worker — cache-aside pattern with R2 fallback
export default {
  async fetch(request, env) {
    const cache = caches.default;
    let response = await cache.match(request);
    if (!response) {
      const object = await env.MY_BUCKET.get("data.json");
      response = new Response(object.body, {
        headers: { "Cache-Control": "public, max-age=3600" },
      });
      await cache.put(request, response.clone());
    }
    return response;
  },
};

FAQ

Is Cloudflare only a CDN? Not anymore — while CDN and DDoS protection remain its most widely used products, Cloudflare now also offers serverless compute (Workers), object storage (R2), Zero Trust security, and DNS as part of one platform.

How is Cloudflare Workers different from AWS Lambda? Workers run on V8 isolates rather than containers, giving near-instant cold starts at the cost of stricter runtime limits, whereas Lambda supports fuller language and runtime flexibility with comparatively higher cold-start latency.

Does Cloudflare’s free tier include real DDoS protection? Yes, unmetered DDoS mitigation is included even on the free tier, a notable difference from most competitors that reserve it for paid plans.

History

  • Founded in 2009 by Matthew Prince, Lee Holloway, and Michelle Zatlyn, growing out of Project Honey Pot, an earlier anti-spam research effort
  • Launched publicly in 2010 at TechCrunch Disrupt, initially positioned mainly as a website security and performance service
  • Went public on the New York Stock Exchange in 2019
  • Expanded well beyond CDN through the 2020s with Workers, R2, and Zero Trust, reframing its overall pitch around being a “connectivity cloud”

Dig deeper