upvote
To add to this, some organizations just prefer using one provider for their cloud service. So if they build on Azure/Google Cloud/AWS, then everything needs to be on there. Cloudflare probably wants to offer the same here, where everything can be built on Cloudflare.
reply
Not sure where the trust claim lands, but the first two are now exceedingly trivial with code agents. A little more work perhaps, but not hard at all. I’ve done this myself (not with those providers) with several search platforms.
reply
CloudFlare AI Gateway was quite convenient for me - I wanted to give my zeroclaw instance a limited budget to services like Image generation/Replicate/Fal.ai, which would mean for each service I'd have to run my own proxy that stores the keys and cuts off the real calls if we go over the limits. Easy to do but still extra thing to build and maintain.

Instead I put my API keys to cloudflare, set limits, and gave the agent the CloudFlare token, and in minutes it could contact tens of services.

edit: not to mention instead of loading balance to each service I could just keep balance on cloudflare that covers them all

reply
> A little more work perhaps, but not hard at all

Extremely hard to verify it's been done properly across a large organization.

reply
Curious what other people’s experience is with cloudflare billing. When you go through an AE, everything seems made up anyways.
reply
Why would anyone trust Cloudflare?
reply
Same way people trust Microsoft: "We already use them, and using them for this additional service exposes no data they wouldn't already have access to from all the other services we buy from them"
reply
I trust Cloudflare more than I trust some other players in the arena. They have a decent track record of being neutral infrastructure provider. They seem technically strong, deploying Rust widely and caring about performance in a way that most firms do not. They're likely covertly funded by intelligence services so they don't have economic incentives to enshitify their offerings or deliberately screw me over.

Put it this way: I'd rather Cloudflare owns the Internet than Google, Meta, Amazon or Alibaba.

reply
> or deliberately screw me over.

Cloudflare is however known to deliberately screw over some of their clients.

> I'd rather Cloudflare owns the Internet

I'd rather no one does, certainly not a firm that feeds into the NSA.

reply
>I'd rather no one does, certainly not a firm that feeds into the NSA.

The government always wins this given enough time.

reply
Citation? The only case I'm aware of is when they removed DDoS protection for the Daily Stormer[0], and tbqh that made me feel more positively toward them. Yes, it was an impulsive, emotionally-motivated choice but that was relatable to me.

[0] https://blog.cloudflare.com/why-we-terminated-daily-stormer/

reply
It wasn't an impulsive decision. They kept the Daily Stormer's account active up until Andrew Anglin said CF kept offering him their services because they quietly agreed with him.

> Our terms of service reserve the right for us to terminate users of our network at our sole discretion. The tipping point for us making this decision was that the team behind Daily Stormer made the claim that we were secretly supporters of their ideology.

> Our team has been thorough and have had thoughtful discussions for years about what the right policy was on censoring. Like a lot of people, we’ve felt angry at these hateful people for a long time but we have followed the law and remained content neutral as a network. We could not remain neutral after these claims of secret support by Cloudflare.

https://blog.cloudflare.com/why-we-terminated-daily-stormer/

reply
Yes, you are quoting from the exact same blog I linked, but you're wrong. It was an impulsive decision[0]

Per Matthew Prince:

"This was my decision. Our terms of service reserve the right for us to terminate users of our network at our sole discretion. My rationale for making this decision was simple: the people behind the Daily Stormer are assholes and I’d had enough.

Let me be clear: this was an arbitrary decision. It was different than what I’d talked talked with our senior team about yesterday. I woke up this morning in a bad mood and decided to kick them off the Internet. I called our legal team and told them what we were going to do. I called our Trust & Safety team and had them stop the service. It was a decision I could make because I’m the CEO of a major Internet infrastructure company."

This is one of the best, most honest things I've seen a tech CEO write. Contrast this with Zuckerberg's mealy-mouthed weaseling about "policies"[1]. I wish more tech overlords had the honesty to say, "No, we are not a court. We are booting you because we don't like you."

[0] https://gizmodo.com/cloudflare-ceo-on-terminating-service-to...

[1] https://www.newsweek.com/read-mark-zuckerbergs-full-statemen...

reply
Cloudflare is known to extort customers.

https://news.ycombinator.com/item?id=44150898 (2025)

https://news.ycombinator.com/item?id=40481808 (2024)

https://robindev.substack.com/p/cloudflare-took-down-our-web...

Reddit comments report more such incidents, with Cloudflare demanding an upgrade to Enterprise. This has also come up for other sites, such as gambling sites.

Also, Cloudflare implicitly screws over everyone by leaking data to the NSA.

reply
> Also, Cloudflare implicitly screws over everyone by leaking data to the NSA

I have always operated under the assumption that every cloud provider and telco does this, so this claim has always seemed very silly to me.

reply
Huh. When you don't use a man-in-the-middle service, you don't have this problem. When you host on a cloud vendor, you don't have this problem because you control the HTTPS certificate and don't leak it to the MITM. The assumption as such seems silly to me.
reply
Your DNS lookups and IPs in use provide a lot of info. It's not always the data inside an encryption layer that is the most important.

That said, these are US companies subject to FISA court orders and NSLs or National Security Letters. If they want your data, they can just pull it from memory in real time or pull it directly from the hypervisor and dump it wherever they're instructed to. Any idea that your data is protected because you're not even using a provider WAF or doing TLS termination for load balancing is a fantasy.

reply
> Your DNS lookups

I control which DNS server I use. It is not relevant to the matter at hand.

> If they want your data, they can just pull it from memory in real time or pull it directly from the hypervisor and dump it wherever they're instructed to.

You're confusing bulk data collection with highly selective court-ordered data collection. The two are not alike. Attempting to equate them is a dumb attempt at deception on your part. There is no obligation for a firm to share bulk web data with the NSA.

reply
>impulsive, emotionally-motivated

Yes that's precisely how I want infrastructure to operate.

reply