Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (35%)
- Domains (25%)
- Web Tools (20%)
- E-mail (10%)
- Hosting (10%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 7 days ago |
|
|
Cloud Services | 8 days ago |
|
|
Cloud Services | 24 days ago |
|
|
Hosting | 27 days ago |
|
|
Domains | 2 months ago |
|
|
Cloud Services | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Nam Dinh (@namd1nh) reportedCloudflare just shipped a browser built only for AI agents. Kitesurf drops tabs, themes, and extensions entirely, and runs on Cloudflare's own serverless Workers platform, free in beta through Browser Run. Chromium was never built for agent work like screenshots or page extraction, and it shows up in the compute bill. Kitesurf claims meaningfully lower CPU and memory consumption for those same jobs. A team building browser agents can swap it in directly, without writing custom browser tooling of their own.
-
ruqqq (@ruqqq) reportedSelf-hosting Nadi outside of Cloudflare will soon be an option thanks to celld! This is an early port. D1 + KV needed an adapter to swap out for an equivalent: just another DO for now when deployed on celld. Multi-node failover support is also still missing. Pretty much still a work in progress. But very exciting!
-
mRr3b00t (@UK_Daniel_Card) reportedDaniel's Daily Threat Intel & CVE Briefing — Fri 7 Aug 2026 Top of the stack: Today is CISA's federal remediation due date for the N-able N-central / Langflow / Tomcat KEV batch — and the N-central bug is the one that matters: CVE-2026-18577, an auth-bypass that is a bypass of the incomplete fix for CVE-2026-18556, is being exploited in the wild since Aug 1 to seize admin on RMM servers and pivot into managed endpoints. If you or clients run N-central, patch to 2026.3.1 Hotfix 1 (2026.3.1.7) and hunt for post-compromise activity before anything else today. 1. CISA KEV / actively exploited (lead) CVE-2026-18577 — N-able N-central, all versions ≤ 2026.3.1 (pre-Hotfix 1). Unauth auth-bypass → full admin. Exploited in the wild from Aug 1; added to KEV Aug 3. Post-exploit TTPs: abuse of the Take Control feature to reach managed endpoints + Cloudflare Tunnel for persistent backdoor. Fix: 2026.3.1.7. So what: RMM = one box to own the whole estate; treat any unpatched N-central as presumed-compromised. CVE-2026-18556 — N-able N-central auth-bypass (the incompletely-patched precursor to 18577), CVSS 8.2. KEV, federal due date today. CVE-2026-9198 — Langflow (open-source AI app-dev platform), CVSS 9.8, unauth code-injection → RCE. Fixed 1.10.1. Repeatedly weaponized in recent months; KEV, due today. So what: internet-exposed AI/LLM tooling is now a routine initial-access target. CVE-2026-34486 — Apache Tomcat, CVSS 7.5, EncryptInterceptor cluster-messaging bypass. Fixed 11.0.21 / 10.1.54 / 9.0.117. Tied to SNOWLIGHT malware campaign; KEV, due today. CVE-2026-63077 — JetBrains TeamCity deserialization flaw, added to KEV this week. Verify your CI/CD estate isn't exposing TeamCity to untrusted networks. 2. Edge / network gear CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) 7.0–7.7 / 10.0. Static credentials for a low-priv account → unauth remote access to sensitive data; actively exploited as a zero-day (disclosed Jul 30). Base CVSS only 5.3 but Cisco rates SIR High because it's chainable for privilege escalation. So what: not the headline score, but it's live and it's your firewall manager — patch and rotate. Fortinet/Ivanti criticals (FortiSandbox CVE-2026-25089 9.8; Ivanti Sentry CVE-2026-10520 10.0 / CVE-2026-10523 9.9) are from the June 10 cycle — no new exploitation reported in the last 24–48h; flagged only in case anything remains unpatched. 3. Microsoft / Windows / AD Quiet in the last 24h. No new in-the-wild Windows/AD/Exchange/Entra items surfaced. August Patch Tuesday lands Aug 11 — July's record 622-flaw cycle (2 zero-days under active attack) should already be deployed; if not, that's your gap. 4. Web / cloud / DevOps CVE-2026-66066 — Rails Active Storage (< 7.2.3.2, 8.0.x < 8.0.5.1, 8.1.x < 8.1.3.1; 6.x only if configured off-default). Critical; unauth arbitrary file read → potential RCE via libvips ("KindaRails2Shell", pivots on the app master key). Public PoC available (disclosed Aug 1). Mitigation: upgrade Rails/Active Storage, libvips ≥ 8.13, ruby-vips ≥ 2.2.1. CVE-2026-63030 + CVE-2026-60137 — WordPress core "wp2shell" chain (REST batch-route confusion + author__not_in SQLi). Unauth RCE on default installs 6.9.0–6.9.4 / 7.0.0–7.0.1. Public exploits on GitHub; watchTowr reports in-the-wild exploitation. Fixed 6.9.5 / 7.0.2 (forced auto-update pushed). Slightly older (Jul 18) but still actively exploited — worth a scan sweep. Watch / developing Oracle out-of-band Security Alert CVE-2026-35273 surfaced this week — details thin, worth confirming scope. Senserva notes ~30 KEV entries this month with 2 tied to ransomware campaigns (Microsoft/Fortinet/Cisco most-affected) — watch for ransomware operators folding the N-central and Langflow bugs into their access-broker playbooks. Sign-off: 7 items flagged actively exploited today (N-central ×2, Langflow, Tomcat, TeamCity, Cisco FMC, WordPress wp2shell); the single must-do is patching N-central before CISA's due date closes. Sources: CISA — Adds Three KEVs (Aug 4) CISA — Adds One KEV (Aug 3) The Hacker News — CISA flags Langflow, Tomcat, N-central Rapid7 — CVE-2026-18577 N-central exploited in the wild N-able — N-central Security Update (Aug 2) The Hacker News — Cisco FMC zero-day actively exploited BleepingComputer — Rails Active Storage RCE (CVE-2026-66066) BleepingComputer — WordPress wp2shell RCE public exploits SecurityWeek — Fortinet/Ivanti critical patches Senserva — CISA KEV additions this week One caveat worth noting for your own verification: NVD detail pages were unreachable during this run, so severities above are corroborated against vendor advisories, CISA, and reputable trackers rather than NVD directly — the Langflow 9.8 and Cisco 5.3 figures each have two independent sources, but confirm against NVD before citing formally.
-
John Rush (@johnrush) reportedI pay for 116 products, $730k a year. It’s insane 😵💫 Are there cheaper alternatives? 1. HOSTING & CLOUD DigitalOcean - $101.94 AWS - $2,938.64 Hetzner - $1,190.10 Heroku - $25 MonoVM - $10 Google Cloud - $4,125.34 Vercel - $46.29 Supabase - $25 MongoDB Atlas - $3,286.55 Azure - $1,462.31 Fly . io - $22.14 Hostinger - $9.99 Clerk - $25 Docker - $11 Cloudflare - $233.24 2. WEB, DESIGN & DEVELOPER TOOLS Apify - $39 Notion - $91.20 Figma - $258.71 Canva - $15 Excalidraw - $10 BunnyCDN - $10 Twilio - $358.70 SendGrid - $20 Sensorpro - $20 Float UI - $0 Imgix - $500 ScreenshotOne - $79 Uploadcare - $25 ScrapingBee - $99.99 Firecrawl - $599 3tsoftware - $998 Atlassian - $938.72 Cursor - $20 Gamma - $10 JetBrains - $63 Lordicon - $16 Webflow - $26.50 Zapier - $33.11 Zoho - $46.24 3. AI & LLMS Google AI - $3,000 OpenAI - $10,000 Codex - $200 Anthropic - $20,000 Claude Code - $200 Azure OpenAI - $50 Pinecone - $70.05 Exa . ai - $1,000 Groq - $0.53 Higgsfield - $49 OpenRouter - $105.50 Perplexity AI - $552 xAI - $20 4. TESTING & MONITORING Sentry - $232.56 StatusCake - $20 UptimeRobot - $7 Ghost Inspector - $49 LambdaTest - $35 Qase - $90 5. COMMUNICATION & COLLABORATION Zoom - $18.75 Loom - $15 Mailjet - $22.45 Skype - $3 Slack - $176.96 Teams - $6 Google Workspace - $151.79 1Password - $21.73 Hubstaff - $700.69 360dialog - $57.39 Cake . com - $335.16 Google One - $26.62 Manychat - $25 StreamYard - $88.99 Typefully - $16 6. MARKETING, SALES & PAYMENTS Gumroad - $100 FirstPromoter - $84.15 Crisp - $400 Intercom - $78 Mailtrap - $15 Stripe - $0.30+ per transaction Paddle - $0.30+ per transaction Ahrefs - $249 DataForSEO - $100 Meta Ads - $25 Google Ads - $50 Mailgun - $27.62 PayPal - $316.85 Seo Gets - $29 Tolt - $3,044.29 TrustMRR - $50 TwitterAPI . io - $20 Vidalytics - $28.50 Webshare - $59.03 Devuap LLC - $19.99 KRAKEN - $ 7. LEGAL, ACCOUNTING, BANKING PandaDoc - $70 QuickBooks - $75 Mercury - $0 Carta - $100 Apple - $99 eSIM . net - $6 Metapay - $0 8. OTHER ProxySell - $50 TLDR - $5 Veed - $108 Grammarly - $12 X - $84 GoDaddy - $69.57 Namecheap - $10 iPostal - $10 Appliku - $10 AWS SES - $0.10+ per 1,000 emails Loops - $49 Google Play - $2.08 Apple Developer Account - $8.25 Black Magic - $5 Zenvoice - $10 Fibery - $10 ChatGPT - $50 Serper - $50 Indie Hackers - $10 Startups .com - $100 9. MY PRODUCTS Unicorn Platform - $19/mo SEObot - $99/mo ListingBott - $99/mo IndexRusher - $199 once AdBot & Tinyadz - $49/mo * the list is made with ai from my last 90 days of bank transactions. may miss yearly payments and include small errors.
-
Aaron (@stockswithaaron) reported🏁 WEEK CLOSING BELL – Friday, August 7, 2026 The market just rang the final bell on a strong week. Today’s Close Dow Jones: +0.31% to 54,051.65 S&P 500: +0.56% to ≈7,753 Nasdaq Composite: +1.18% to ≈26,661 Stocks climbed after a surprisingly soft July jobs report (payrolls fell 23k vs. +80k expected, though the unemployment rate dropped to 4.1%). Investors took the weaker hiring as a signal that could keep the Fed more patient on rate hikes. Full Week Scoreboard All three major indexes finished higher for the week: Nasdaq led with solid gains (strongest performance among the big three) S&P 500 and Dow both posted healthy advances The week featured big earnings moves (Atlassian, Cloudflare, etc.), the SpaceX lockup test, and Friday’s jobs data as the final catalyst Bottom line: The bulls closed out the week with a win. Soft jobs data + resilient tech/software names helped the market finish on the front foot heading into the weekend. Enjoy the break, see you Monday!!!
-
Erdal (@ErdalToprak) reportedNever expose your network, tailscale/headscale only and some selected apps with cloudflare tunnel/zero trust You can avoid 99.99% of issues with that simple trick
-
Houmark (@lhoumark) reported@CloudflareDev It looks like there's some type of issue with the Lima colocation and DNS lookups. It seems to be stale and uses old data. Since almost two hours ago, I moved a domain to Cloudflare and also switched the A record to point to an internal Cloudflare worker.
-
sam (@samgoodwin89) reported@K4y1s @nebiusai @Cloudflare Env vars are standardized with Output<T> const getter = yield* someOutput The runtime implements support, but it looks the same for all bindings. AWS bindings are good examples of this.
-
Nicholas Charriere (@nichochar) reportedThe actor model is winning: with cellId and the rise of serverless we’re seeing patterns emerge as most popular for modern workloads: workers, durable objects and message passing. The funny (and annoying) thing is that the perfect stack exists but isn’t being used. We’re reinventing in rust and typescript what was built already, and boy was it built well. Elixir is based on the BEAM VM, which implements actors perfectly. No shared state, immutable data, gen servers for long lived stateful processes, supervision trees for reliability Then, Elixir introduces ergonomics on top. The language is inspired by Ruby and tries really hard to make itself a delight to use. Really strong developer ergonomics (pattern matching, overloading, type hints, all-in-one build tool and linter, thoughtful keywords, strong conventions, etc…) It is quite literally overpowered. I used it at Pinterest and we would take services built in python that were maintained by a team of 20 and replace with one elixir service maintained by less than one person. Multiple times. If well designed they simply never go down and scale beautifully. We also used it at Mocha and had a 10x more reliable app than lovable or replit. In fact one of the reasons we kept competing is that we felt their apps were garbage (they have since improved a lot, which is a frustrating mistake I have since learned from). In the age of agents, elixir should absolutely be winning, and indeed the actor model is! It’s a perfect fit: long lived processes with very unreliable third party processes and humans in the loop, all orchestrated to be long lived and reliable with not too much internal state. But as I learned, unfortunately the best tech doesn’t win, capital wins. And most programming languages won because they had massive capital (think companies) pushing them forward. Rust had Mozilla, Go had Google. typescript had Microsoft (JavaScript is a bit different, it won because it’s the runtime of the biggest platform ever made: the web). This is frustrating but it is also reality, so I guess we should be happy to see great implementations (rivet in rust, workers/DO by cloudflare) becoming mature. The actor model is the best programming model for most web workflows.
-
James (@jamescoder12) reportedHe said this is the single most underrated security setting on any home router and it protects every device automatically. DNS (Domain Name System) is the system that translates website names into IP addresses. Every time you type a URL, your device sends a DNS query. By default, those queries go to your ISP unencrypted. Your ISP can see every website you visit, log it, and in many cases sell that data to advertisers. He switched the router's DNS to an encrypted, security-focused provider like Cloudflare (1.1.1.1), Quad9 (9.9.9.9), or Google (8.8.8.8). These providers offer encrypted DNS that prevents your ISP from snooping, and some like Quad9 automatically block connections to known malware and phishing domains. Router settings > Network or Internet > DNS Settings > enter the preferred DNS server addresses manually. "Their ISP's default DNS was logging every website they visited. By switching to Quad9, their DNS queries are now encrypted and every device on the network is automatically protected from connecting to known malicious domains. No software to install. No app to download. One setting change protects every phone, laptop, tablet, and smart TV in the house."
-
fb (@BinBader98) reported@tyoma_se @theo @kr0der I have the same issue from a hotel btw and let codex investigate it seems like my hotel router is blocking port 7844 which is needed for cloudflare. Solution is use tailscale i guess
-
Gate South Asia (@Gatedesi) reported🔎 Gate Stocks Analysis 🔎 Markets Await Fed Signal While ABNB & NET Surge Markets pulled back yesterday as higher oil prices pressured stocks. The Dow fell over 460 points, ending its five-day winning streak, while chip stocks gained and helped offset some losses. U.S. futures are mixed before the market opens as attention is on July jobs report for clues on the Fed's next rate. Airbnb and Cloudfare surged after the strong earning results. Global commodities saw mixed moves as oil prices rises on Hormuz concerns, while gold gained on economic uncertainty. China’s exports also beat expectations despite new U.S. tariffs. 🔹Stocks Market Performance 📈 Gainers ➤ SoundHound AI ($SOUN) +10.13% ➤ SpaceX ($SPCX) +6.11% ➤ Samsung Electronics ($005930) +0.21% ➤ Airbnb ($BNB) +9.09% (Pre-market) ➤ Cloudflare ($NET) +15.66% (Pre-market) ➤ Nasdaq Futures ($NAS100) +0.3% 📉 Decliners ➤ SK Hynix ($000660) -4.88% ➤ Sandisk ($SNDK) -6.78% ➤ Kospi -0.6% Commodities ➤ Brent Crude ($XBR) +1.3% ➤ WTI Crude ($XTI) +1.1% ➤ Gold ($XAU) +0.7%
-
Kaizen Labs (@KaizenLabsabc) reportedAI didn’t break software this week. It exposed the winners. Aug 3–7, 2026. The market split sharply between winners and losers.: - Atlassian $TEAM +35% — best day since its 2015 IPO. The name most loudly written off as coding-agent roadkill grew revenue 28%, cloud 31%. Crowded short, meet guidance raise. - Palantir $PLTR +29.5% (Tue) — US commercial revenue up 149%. Year lifted to ~$8.15B. Skeptics paid the bill. - Twilio $TWLO +24% — full-year growth guide yanked from 14-15% to 18-18.5%. That's not a beat, that's a re-underwrite. - Cloudflare $NET +16% — 36% growth, raised the year. - Airbnb $ABNB +8% — $27.2B in bookings. Travel is fine. - Datadog −19% — worst day since listing. It beat and raised. Didn't matter: its biggest AI customer dialed usage back. Consumption pricing is a two-way door. - HubSpot $HUBS −19% — worst session in ten years. Cut the year. - AppLovin $APP −19.3% — first guidance miss since going public. The multiple did the rest. - Figma $FIG −15% — beat, then flagged rising inference spend. AI just moved from the growth line to the cost line. - Trade Desk $TTD −21.9% — closed $13.80, lowest since Jan 2019. Q3 guide implies revenue shrinks ~12%. Retention is still above 95%, which is the genuinely frightening part: the customers stayed. The spend left. Something worth flagging, several of these stocks moved sharply intraday but finished the session somewhere very different: 1. Twilio traded up ~31% mid-session before closing near +24% 2. Trade Desk fell as much as 27% before finishing −21.9%.
-
Toshogu | AI (@Toshogu) reported🚨AI moves fast. Here's what you missed: 🔘 OpenAI paused development on its Astra models after the UK government caught them performing unauthorized network hacks. 🔘 Stanford researchers used 37,000 AI agents to design a lung cancer drug that Merck just confirmed for human trials. 🔘 Meta owes $567 million because a New Mexico court ruled its recommendation algorithms are a fundamental threat to children. 🔘 Mirendil secured $100 million in Google Cloud credits to avoid giving away board seats to venture capitalists. 🔘 Anthropic installed a new safety layer to stop its Fable 5 models from teaching users how to manufacture biological pathogens. 💀 🔘 GPT-5.6 is now governed by a framework that prevents the model from launching independent cyberattacks while navigating the web. 🔘 Rippling launched a tracker to calculate the exact dollar profit generated by every individual employee using AI tools. 🔘 Cloudflare built a web browser specifically for AI agents so they can navigate the internet without being hijacked by hidden text. #toshogu #AI
-
Nex AI (@Nex_AI_Official) reportedStopping the bad guys with Cloudflare: 4,167 malicious requests blocked or challenged in the last month #cloudflare
-
Ticker Report (@ticker_report) reportedShares surged +17.5% to $334.12 after Cloudflare crushed second-quarter expectations and raised its full-year outlook, vaulting the stock past its prior $305 all-time high and forcing Wall Street to recalculate whether the internet-infrastructure company can sustain the growth rate that justifies its sky-high price tag. Revenue Blew Past Forecasts by a Wide Margin Cloudflare posted Q2 revenue of $696.1 million and adjusted earnings of $0.29 per share, both beating Wall Street's $665 million and $0.27 consensus. That 4.7% revenue beat was accompanied by 34.8% billings growth to $753.5 million , a forward-looking indicator suggesting demand isn't decelerating. The company lifted full-year revenue guidance to $2.864–$2.870 billion, topping the Street's $2.81 billion average estimate , while raising its full-year adjusted EPS outlook to $1.25–$1.26, up from $1.19–$1.20 previously. For shareholders, the raised guidance signals management's confidence isn't just about one strong quarter. Big Customers Are Spending More, and AI Is the Reason Cloudflare ended Q2 with 4,698 customers paying more than $100,000 annually, up 27% year over year, adding a record 986 net large customers over the trailing twelve months. Its dollar-based net retention rate — a measure of how much existing customers increase their spending — accelerated to 120%. The company said AI-agent traffic is expanding across its network, with enterprises using its infrastructure to route and secure AI-powered applications. That uptake gives Cloudflare a growing share of AI-related internet traffic, not just traditional web security. Margin Pressure and a $151 Million Restructuring Charge Lurk Beneath the Surface GAAP gross margin fell to 71.8% from 74.9% a year ago , and GAAP net loss widened to $170 million, partly reflecting $150.7 million in restructuring charges tied to an AI-first operating overhaul. Free cash flow was $56.4 million, or 8% of revenue — respectable but modest for a stock trading at roughly 48 times trailing sales before the earnings pop. CFO Thomas Seifert sold 55,000 shares on August 4 at ~$300, reducing his stake by 32.58%. The Valuation Asks a Lot of the Future Goldman Sachs raised its price target to $389 and Oppenheimer to $380, both maintaining Buy ratings. Yet Cloudflare already traded above the average analyst target of ~$262 even before this beat. The stock now prices in years of flawless execution. Investors cheering today's numbers must ask whether 36% growth can persist long enough to justify the premium — or whether the restructuring costs and margin compression are early signs that scaling AI infrastructure costs real money. $NET
-
Jimmy Pringles (@Rat_Bag113) reported@itslivny Mate do you wanna fix your Cloudflare or something.
-
MidasAvocado (@midasavocado) reported@arjunkshah21 For my backends I use Cloudflare workers and that hasn’t given me any issues so far. The workers paid plan I use ($5/mo) gives 10 million requests/mo and $0.30/million extra requests per month… Id look into it. Might work pretty well for Supercompress.
-
dweewq (@eweqss1431) reportedAgencies charge $8,000 to $12,000 for a marketing site, three weeks of calls, two rounds of revisions, one invoice that makes you sit down. Claude Code builds the same site in an afternoon, but most people still get template output because they type "make it beautiful" and pray. Claude defaults to safe every time: Inter font, purple gradients, three feature cards. The ten thousand dollar look comes from constraints, not vibes. The fix starts before a single line of design gets written. Load actual design rules into Claude Code as skills, so it checks a ruleset before every decision instead of guessing what "premium" means. Then screenshots beat adjectives completely. Three reference sites from your niche, paired with an explicit instruction not to copy the layout, give the model an actual quality bar to hit instead of a vague adjective to interpret. The build itself is one prompt with five blocks: who the audience is, the single action every page should push toward, the references to match, the tech stack, and a banned list of every cliché you don't want showing up. First working version lands in under ten minutes, about seventy percent there, which is exactly the point, nobody ships version one. The part that actually earns the price tag is the polish pass agencies bill forty percent of the project for: typography, spacing, and motion, run as three separate messages instead of one, because asking for all three at once gets one dimension fixed well and two fixed badly. A mobile check at 375px catches what breaks, since most traffic is a phone regardless of what the desktop preview looks like. Shipping costs nothing after that. Push to GitHub, connect Cloudflare Pages, deploy. The agency was always selling three weeks of process. The process was always one afternoon.
-
Wayne Gale (@waynegale2026) reportedThe next question is: how do we solve this in the personal-computing Agent era? Do all of these Agent environments really need to live on the local machine? Could the runtime, file system, browser, terminal, caches, and other resource-heavy components be separated from the laptop and pushed into the cloud, while the local computer remains mainly the interface and control center? I think this is increasingly something products like ChatGPT need to solve at the infrastructure level, rather than leaving users to solve it simply by buying machines with more RAM. Cloudflare seems to be moving in a similar direction: pushing more of the Agent infrastructure and execution layer into the cloud. As Agents become truly parallel, the question should probably shift from “How much RAM does the user have?”to “How much compute can the product dynamically provide to each user?” @tibo — this might be an interesting problem to think about for the future of ChatGPT/Codex. $MU $SNDK $SKHY
-
Oz Wadood (@theozbuilds) reported@arvidkahl @nickgraynews have you considered rate limiting or a reverse proxy like Cloudflare in front of your API? we've had similar issues scaling Podscan-type products, and limiting by IP/API key early saved us thousands in compute costs.
-
qorvr (@adqorvr) reported@superkaicode @Cloudflare How to do that? I never ran a heavy task using cloudflare workers.
-
Aman Singh (@SinghAman21_) reportedif you are using d1 cloudflare sqlite db, how do you work locally? i already have nextjs codebase and was trying to integrate d1, but wrangler was giving me lot of issue. for dev setup how to test in **** like env, cause supa used to give string it was easy with that.
-
Tech News 24h (@TechNews24h) reportedCloudflare debuts Kitesurf, a cloud-hosted browser for AI agents built on top of its Workers serverless service, available for free while in beta in Browser Run
-
Rubens Soto (@rubenssoto_ai) reported@Divine_machine @Cloudflare What programming language are you using right now? I know Cloudflare has good support for Next.js, but I also have a Node.js backend, so I need to check whether it would be a good fit.
-
Praveen Naik (@p_naix) reportedCloudflare DevX is sooo bad. After reading their README, I just came here to tweet instead of trying it out. Their fetish for Workers and Durable Objects, without helping end developers actually do things, is unheard of. The worst part is, it keeps happening every time. Every new thing they drop → I get excited → open "How to use it" → get slapped in the face with Workers/Durable Objects instead of the actual ******* product → go back to tweeting
-
Evan Kirstel #B2B #TechFluencer (@EvanKirstel) reported@Cloudflare Cron job plus a webhook. Never going back. @techimpactTV
-
Andrew Jefferson (@EastlondonDev) reported@dok2001 @kirso_ Just becuase other clouds are bad doesn’t mean ppl shouldn’t strive to be better - but I’ll take cloudflare any day for billing
-
Warya Wayne (@WaryaWayne) reportedI have a Cloudflare worker running a fetch for the homepage for a few of my sites and I'm not sure if it's the lack of retry policy, which I fixed to 3 times now, or there are requests being dropped or super slow. It says the sites are offline and down but I click and it works?
-
BreezeOg🐉 (@BreezeOg1) reportedFor startup founders. If you're vibe coding your startup, let me show you exactly how I'd ruin your life in one night. It's not even hard. Step 1: I log into your website and hammer your backend 10,000 times a minute until your login page just... dies. Step 2: While you're scrambling to figure out what's happening, I spam your sign up form until your database is full of garbage accounts. Step 3: I find your most expensive endpoint (you already know the one that costs you the most) and I hit it over and over and over — until your API bill hits $950,000. Yes, almost a million dollars. From one endpoint. Step 4: While you're panicking about the bill, I quietly scrape all your data. You don't even notice. That's it. That's the whole attack. No genius hacking, no zero-day exploit. Just brute force against a backend nobody bothered to rate limit. Most people building fast with AI tools ship the features and skip this part entirely. Your app can look production-ready and still be a wide-open door. The fix is not complicated: 1. Rate limit EVERY endpoint, not just the "important" ones 2. Login and signup need the tightest limits because those are the first doors people try 3. Put Cloudflare in front of everything And this just takes an afternoon. Saves you from waking up to a $950k bill or an empty database.