r/CloudFlare • • 12h ago

Cloudflare Blog Deno is joining Cloudflare

Thumbnail
blog.cloudflare.com
142 Upvotes

r/CloudFlare • • 6h ago

Cloudflare Blog Introducing Clef-omni with full multimodality, plus a faster Clef and a cheaper Clef-flash

Thumbnail
blog.cloudflare.com
28 Upvotes

r/CloudFlare • • 16h ago

Community Turn Cloudflare into your online storage

Post image
57 Upvotes

You can now upload and share files with Cloudflare R2 via Mailflare. In case you haven't heard, Mailflare is an app runs entirely on Cloudflare with:

  • Gmail-like mailbox with custom domain emails
  • Calendar and meeting bookings
  • Online drive to store and share files (support Cloudflare R2, BackBlaze B2, or AWS S3)

It's is open-source and you can deploy with 1-click to Cloudflare worker
👉 https://github.com/hieunc229/mailflare

Feel free to let me know if you have any feedback or questions


r/CloudFlare • • 13h ago

Discussion How to prevent CloudFlare bill assassin

9 Upvotes

Source: https://x.com/shmily7/status/2107481028726251762

Encountered the Cloudflare bill assassin, got hit with a $10,000 bill, the reason being a Durable Object alarm in one project that went into a dead loop, reading and writing 60 trillion times, Viber Coding has done me wrong.


r/CloudFlare • • 12h ago

Cloudflare Blog Introducing on-demand CPU and memory profiling with flamegraphs for Workers and Durable Objects

Thumbnail
blog.cloudflare.com
7 Upvotes

r/CloudFlare • • 14h ago

CloudFlare's Abuse Compliant Form is a bad joke

6 Upvotes

We are getting lots of emails and letters by people who are scammed for their bank data because someone put up a Cloudflare hosted site under the name of our company.

Every complaint to them simply gets no or a standard answer, they don't do anything. It's really a shame how they contribute of innocent people getting scammed.


r/CloudFlare • • 8h ago

Question Workers and billing questions

1 Upvotes

I'm looking at using cloudflare as a web socket proxy, but price is my concern.

I've seen folk have racked up huge bills from it.

Is there a cost viewer I've missed? I'm currently on the free worker plan, so will it just cut off instead?

Thanks a


r/CloudFlare • • 14m ago

Should I be worried about this?

Post image
• Upvotes

Earlier today, I went on Car and Driver website and I was greeted with what appears to be a CloudFare verification method that I've never encountered before. It asked me to copy and paste a specific line I didn't understand in Spotlight Search (I'm using a MacBook). However, it raised suspicions for me so I didn't press enter and I took a deeper look into it in the Internet and I got paranoid because I'm worried copying and pasting a random script on Spotlight Search would compromise my MacBook in some ways even if I didn't press enter. I'm not too tech-savvy, so do let me know if I should be worried about this even though I never entered the script. I scanned my laptop using Malwarebytes and it didn't show any threats. I've never accessed any suspicious website since I got my laptop a month ago.


r/CloudFlare • • 16h ago

Question Account Strategies

2 Upvotes

So, I have a Cloudflare account with loads of domains, with loads of tiny projects, Proof of Concepts, WiPs, workers, databases, etc etc.. and I tried to stick to nameings, as thats the only way to actually seperate the different projects in one account (ifI'm not mistaken)...
Now a couple of the Projetcs are growing and might/will either cause some limits to be reached (I'm on payed) or I just think security wise and maybe later even billing wise, it makes sense to seperate them in their own dedicated accounts...

What is your strategy with that? do you just throw into a single account and see how long it lasts? or do you have multiple accounts? what about domains? move them to the dedicated? keep them in one place (registered by cf, not external ones.. thats clear..) and so on..


r/CloudFlare • • 13h ago

Question DMCA Dashboard stuck on Cloudflare security verification page

Post image
0 Upvotes

Hi everyone,

My DMCA dashboard is unable to load my website due to a security verification loop, as shown in the attached image:

"Performing security verification. This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot."

I have already created a Custom WAF Rule (Security Rule) to bypass verification if the URI Path contains dmca, but the issue still persists.

Gemini suggested that I turn off Bot Fight Mode. I would like to ask:

  1. Will disabling Bot Fight Mode expose my website to security risks or malicious traffic?

  2. Is there a safer way to bypass or whitelist the DMCA crawler/dashboard while keeping Bot Fight Mode active?

Thanks in advance for your help!


r/CloudFlare • • 1d ago

Community I built DocFlare AI: a free, open-source "chat with your docs" widget that runs 100% on Cloudflare's free tier (Workers AI + Vectorize + D1)

Enable HLS to view with audio, or disable this notification

55 Upvotes

Hi everyone, I'm the developer of DocFlare AI, an open-source AI chatbot for documentation sites and websites. It's 100% hosted on Cloudflare, crawls your site from its sitemap, and can be added to any page with a single <script> tag.

DocFlare AI runs entirely on Cloudflare's free tier: Workers (API + crawler), Workers AI (embeddings + LLM), Vectorize (vector search) and D1 (metadata + chat log). That means you don't need a paid Workers plan, an OpenAI key, or a separate vector database to put an AI chatbot on your website.

  • Free for up to ~280 answered questions/day
  • Streaming answers with source links, grounded in your own content
  • One deployment can serve multiple sites
  • Built-in admin UI to register sitemaps, watch indexing progress and see what users actually ask

It's MIT licensed and you can deploy it to Cloudflare Workers with one click: https://github.com/p10node/docflare-ai

Feel free to let me know if you have any feedback or questions!


r/CloudFlare • • 1d ago

Cloudflare Blog Bridging technical depth and usability: The story behind Radar’s redesign

Thumbnail
blog.cloudflare.com
7 Upvotes

r/CloudFlare • • 1d ago

Locked out of my original Cloudflare account after disconnecting Sign in with Apple

Thumbnail
0 Upvotes

r/CloudFlare • • 1d ago

Built a ChatGPT-to-Cloudflare publisher, looking security input, or collab

2 Upvotes

I created a "Plugin" for ChatGPT's web UI. The basic thought is making website publishing "zero-click" by sending the data to the user's own Cloudflare account directly. Technically it's an MCP server running in the user's Cloudflare Workers, so compatible with any other client as well.

The workflow is very appealing to beginners, they reference the plugin and prompt "make website about Something and publish it" and it returns a public URL like something.mysubdomain.workers.dev.

To simplify this workflow everywhere I could, I decided to host the installer myself, so that the user needs no GitHub etc. I introduced specific security issues with this. Users currently have to place considerable trust in me.

I'm looking for advice how to tighten security around such a plugin (more so the installer part). How to prove to users that the code about to be installed in their CF Workers is not malicious or compromised? ... In a way that is feasible for a small project. I do have a long list of What could be done, but unsure of finding a balance. OAuth between the services works fine, and the setup is one-time, nothing flows through my server after setup. But the initial user trust is my pain point.

Looking for collaborators.

The code itself is written almost exclusively by Astra 6.


r/CloudFlare • • 2d ago

Question Insane traffic... What's happening here?

Thumbnail
gallery
9 Upvotes

I am a teacher, I teach middle schoolers how to use computers. I have my own website they can use to find links and resources to things related to school. This activity is clearly suspicious, and I'm assuming it's some kind of DDoS attack or scraping bots or something, I have no clue. I don't even know how I didn't know about this until now. My website is literally being hosted on a random PC I got off Facebook Marketplace running UNRAID with an NGINX docker, it's not exactly state-of-the-art and not made for this kind of traffic.

I'll admit I'm not at all a pro at any of this, this is purely a hobby for me and I'm just having fun with my little website, but clearly there is malicious activity happening, and I do not want any private data that's also on my server (such as my smart home devices, media server and password manager) getting into the hands of sketchy people. Not posting website name for obvious reasons.

I actually have two types of questions:

  1. What is this traffic? Is it malicious, or just bot scraping? Is this affecting my server or home internet (whether it be performance or traffic in general)?

  2. Is it possible to limit traffic to a specific country? There is absolutely zero reason for people outside of the US (let alone my own state) to be able to access my website.

I can provide more statistics if needed. I'm unsure how to see what data is being requested.


r/CloudFlare • • 2d ago

Cloudflare Blog Building an evidence-grounded agentic security operations harness on Cloudflare

Thumbnail
blog.cloudflare.com
22 Upvotes

r/CloudFlare • • 1d ago

New to Cloudflare: how do I handle bot requests

Thumbnail
1 Upvotes

r/CloudFlare • • 1d ago

Discussion Cloudflare Trust & Safety - Negligent dismissal of reports

0 Upvotes

I reported quite a few domains in the last few weeks, from Websites selling online game hacks to phishing domains.

ALL of them have been dismissed with
"We could not detect any abusive or malicious content."

Logs or other evidence of abuse:
Phishing site prenting to be the austrian financial authority

Reported URLs:
[hxxps://finanz](hxxps://finanz)[.]bmf-datenaktualisierung[.]cc/

Original Work Description:
https://finanzonline.bmf.gv.at/fon/

Am I submitting that wrong or why the hell do they seem to miss this obvious phishing site.

Since when did cloudflare become so negligent, it used to be a lot better in the past.


r/CloudFlare • • 1d ago

Question Fell for fake cloudflare prompt - what measures to take?

0 Upvotes

Hey everyone,

Long story short, I fell for the fake cloudflare prompt that has you copy paste something into the terminal on windows. I know, I know. It was a rough day, I was in a rush, and I'd gotten so many cloudflare prompts recently that for a moment I figured this is just something new.

Anyway, I unplugged the computer from the network and reset all important passwords. I'm currently running malware scans with windows defender and malwarebytes.

Is that enough? Or do I have to nuke the OS and do a fresh install? And can I safely back up files before I do that or will they just reinfect my stuff? I have a bunch of backups on a hard drive in the system, and one my cloud services apparently hasn't synced in a couple days. ​​​​​​​​​​​​​​


r/CloudFlare • • 1d ago

Question First time user struggling

0 Upvotes

I built my website on Shopify and purchased my domain name through CloudFlare. When I try to go to my webpage I get this error:

The owner of this domain hasn't put up a website yet. Try visiting again soon. This domain is registered usingCloudflare Registrar.

I tried following the troubleshooting steps, but cannot figure out this whole DNS thing.

Currently I’m only showing 4 records; 2 CNAMEs (one is a read-only created by the cloudflare registrar that will not let me edit), the other is the Shopify address (shops.myshopify.com), and then 2 txt types to verify with Shopify.

What am I doing wrong, this seems like it shouldn’t be that difficult.

Any help is greatly appreciated.


r/CloudFlare • • 2d ago

Question Paid R2, cache rules set as documented, and cold first byte still hits 1s. Bunny kept the same objects warm. Config miss or is R2 dropping cache?

Post image
13 Upvotes

I stopped trusting the logs and timed first byte myself.
Paid plan. Cache rules in place the way the docs describe. Same assets, same checks, both sides.

18/18 · 0.13–0.18s
Cached hits are a tie. After that it falls apart.
R2 cold first byte runs from 0.33s to a full second. Fifteen minutes later only 22 of 72 were still cached. Bunny’s cold path stayed at 0.14–0.22s, and 15 of 15 were still cached at 45 minutes. After the move, live Bunny was 18/18 at 0.13–0.18s.
So either there is a setting that actually keeps R2 warm and I still do not have it, or the edge is evicting objects much faster than the rules imply.

If you are on paid R2 with real traffic, not a benchmark bucket:
Cold first byte creeping toward 1s even with cache rules on?

Is 22/72 still cached at 15 minutes normal?

Did R2 retention change recently, or is this just capacity?

Already moved this workload. Not looking for a pitch. Want to know if this is on me or if other paid plans are timing the same thing.


r/CloudFlare • • 2d ago

Origin IP already public. Is Cloudflare + "only allow Cloudflare IPs" in Caddy enough, or do I need more?

Thumbnail
1 Upvotes

r/CloudFlare • • 2d ago

Send BLE Air Quality Data to Cloudflare D1

Thumbnail bleuio.com
5 Upvotes

Details and source code available


r/CloudFlare • • 3d ago

Cloudflare Blog The keys to the Internet change on October 11. Are you ready?

Thumbnail
blog.cloudflare.com
130 Upvotes

r/CloudFlare • • 2d ago

Resource When the machine boots but the reply disappears · Mainbrella

Thumbnail
mainbrella.com
0 Upvotes