Cloudflare has grown from a CDN and DDoS mitigation service into a broad infrastructure platform. For hosting providers, sysadmins, and developers managing web properties, understanding which features deliver real value versus marketing noise is essential. This guide reviews Cloudflare's current feature set, identifies what's genuinely useful for common infrastructure challenges, and highlights newer capabilities worth adopting.
Core CDN and Caching
Cloudflare's content delivery network remains its foundation. Traffic routes through their global network of data centers, caching static assets closer to visitors and absorbing attack traffic before it reaches your origin server.
What Works Well
The CDN layer handles static asset caching automatically once you proxy DNS through Cloudflare. HTML is not cached by default, but you can control caching behavior with Page Rules or Cache Rules. For most WordPress sites and applications, the free tier provides sufficient caching and bandwidth.
Cache purge operations are fast. You can purge by URL, tag, hostname, or prefix. Tags are particularly useful when building your own cache invalidation logic—add Cache-Tag headers to responses, then purge by tag when content updates.
# Purge by cache tag via API
curl -X POST "https://api.cloudflare.com/client/v4/zones/{zone_id}/purge_cache" \
-H "Authorization: Bearer {api_token}" \
-H "Content-Type: application/json" \
--data '{"tags":["product-123"]}'
Argo Smart Routing, a paid feature, routes traffic through less-congested paths in Cloudflare's network. It reduces latency by an average of a few dozen milliseconds. Useful for global applications where every millisecond counts, but not essential for most use cases.
Cache Rules vs Page Rules
Page Rules are the legacy approach to controlling cache behavior, rate limiting, and other edge logic. They're limited to three rules on the free plan and work on a path-matching basis.
Cache Rules, introduced more recently, offer finer control over cache TTL, cache keys, and eligibility. They support complex matching logic based on headers, cookies, query strings, and request methods. If you're setting up new caching policies, use Cache Rules. They're more powerful and easier to troubleshoot.
DDoS Protection and Security
Cloudflare's DDoS protection is unmetered and included in all plans. It operates at both the network layer (L3/L4) and application layer (L7), automatically detecting and mitigating attacks without manual intervention.
How It Protects Your Origin
Once you proxy DNS through Cloudflare, attack traffic hits their edge network first. Most attacks never reach your origin server. The system analyzes traffic patterns and blocks malicious requests based on threat intelligence, rate, and behavior.
For hosting providers, this is the primary reason to use Cloudflare. A volumetric DDoS attack that would saturate your upstream bandwidth and crash your servers is absorbed transparently. The effectiveness depends on keeping your origin IP address hidden—if attackers discover your real IP, they can bypass Cloudflare entirely.
Web Application Firewall (WAF)
The WAF inspects HTTP requests and blocks common attack patterns: SQL injection, XSS, command injection, and more. Managed rulesets are enabled by default and updated automatically. You can supplement these with custom rules to block specific user agents, IP ranges, or request patterns.
WAF Custom Rules let you write conditions using Cloudflare's expression language. For example, block requests with suspicious query strings:
(http.request.uri.query contains "union select") or
(http.request.uri.query contains "../../../")
False positives happen. Monitor your Security Events dashboard and create exceptions when legitimate traffic gets blocked. The WAF is most effective when tuned to your application's traffic patterns.
Bot Management
Bot Management is available on higher-tier plans. It uses machine learning and behavioral analysis to distinguish human visitors from bots. You can allow good bots (search engine crawlers), block bad bots (scrapers, credential stuffers), and challenge suspicious traffic with CAPTCHAs or JavaScript challenges.
The free tier includes basic bot protection—legacy challenge pages that are effective but create friction for legitimate users. The paid Bot Management feature is more sophisticated and less disruptive, but the cost is significant. Evaluate whether bot traffic is actually harming your infrastructure before investing.
Cloudflare Workers
Workers are serverless functions that run at the edge, executing JavaScript (or WebAssembly) before requests hit your origin server. They're useful for request manipulation, A/B testing, authentication, API aggregation, and building lightweight applications without traditional servers.
Practical Use Cases
Request Routing and Rewrites: Route requests to different origins based on headers, cookies, or geolocation without touching your origin server.
addEventListener('fetch', event => {
event.respondWith(handleRequest(event.request))
})
async function handleRequest(request) {
const country = request.cf.country
if (country === 'CN') {
return fetch('https://cn-origin.example.com' + new URL(request.url).pathname)
}
return fetch(request)
}
Authentication and Authorization: Validate JWT tokens or session cookies at the edge, rejecting unauthorized requests before they reach your backend.
HTML Rewriting: Modify response bodies on the fly—inject analytics scripts, remove sensitive data, or implement feature flags without deploying backend code.
API Aggregation: Combine multiple backend API calls into a single edge response, reducing latency and client complexity.
Performance and Limits
Workers execute in under a millisecond in most cases. The free tier includes a generous daily request allowance. Paid plans lift CPU time limits and add durable storage via Workers KV and Durable Objects.
Workers KV is a globally-replicated key-value store with eventual consistency. Reads are fast and happen at the edge. Writes propagate globally within seconds. Use it for configuration data, feature flags, or cached API responses—not for data requiring strong consistency.
Durable Objects provide strongly consistent storage and coordination primitives. Each object is a single-threaded execution context with attached storage. Useful for collaborative editing, real-time features, or maintaining session state across requests.
Cloudflare Tunnel
Cloudflare Tunnel (formerly Argo Tunnel) creates an outbound-only connection from your origin server to Cloudflare's network. Traffic flows through the tunnel without exposing your origin IP or opening inbound firewall ports.
Why Use It
Traditional setups require your server to accept inbound connections on ports 80 and 443. Attackers who discover your origin IP can bypass Cloudflare and attack you directly. Tunnel eliminates this risk.
The cloudflared daemon runs on your origin server and establishes encrypted connections to Cloudflare. Incoming requests arrive through the tunnel. Your server never exposes its IP publicly.
# Install cloudflared
wget https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64.deb
sudo dpkg -i cloudflared-linux-amd64.deb
# Authenticate
cloudflared tunnel login
# Create a tunnel
cloudflared tunnel create my-app
# Configure routing
cloudflared tunnel route dns my-app app.example.com
# Run the tunnel
cloudflared tunnel run my-app
You configure routing in the Cloudflare dashboard or via YAML. The tunnel can proxy to multiple services on different ports—useful for exposing internal services without VPNs or port forwarding.
Trade-offs
Tunnel adds a small amount of latency (typically under 10ms). For most applications this is negligible. The benefit is complete origin IP protection and simplified firewall rules.
You'll need to keep the cloudflared daemon running and monitor its health. Use systemd or another process manager to ensure it restarts after crashes or reboots.
DNS and Load Balancing
Cloudflare's authoritative DNS service is fast and free. It supports standard record types plus Cloudflare-specific features like proxied records (orange cloud) and CNAME flattening.
Load Balancing
Load Balancing is a paid feature that distributes traffic across multiple origin servers based on health checks, geographic proximity, or custom steering policies. Each load balancer performs active health checks against your origins and removes unhealthy targets automatically.
You define pools (groups of origin servers) and configure failover rules. Traffic steers based on latency, geography, or round-robin.
# Example pool configuration
pool_1:
origins:
- address: 203.0.113.10
weight: 1
- address: 203.0.113.11
weight: 1
health_check:
interval: 60s
timeout: 5s
path: /health
For high-availability setups with multiple origins, Load Balancing eliminates single points of failure. The cost scales with the number of queries, so it's most cost-effective for critical applications.
Email Security
Cloudflare provides DNS-based email security tools: SPF, DKIM, and DMARC record management, plus Email Routing for receiving mail without running your own mail server.
Email Routing
Email Routing forwards incoming mail to your existing mailbox. Configure MX records to point to Cloudflare, then create forwarding rules in the dashboard. Useful for custom domain email without paying for Google Workspace or managing Postfix.
It's receive-only. You still need an SMTP provider for sending. Many hosting setups combine Email Routing for receiving with an authenticated SMTP relay (SendGrid, Mailgun, or your hosting provider) for sending.
DMARC Reporting
Cloudflare can parse DMARC reports and present them in the dashboard. This helps you monitor email authentication failures and detect spoofing attempts. Set your DMARC policy to p=none initially, review the reports, then tighten to p=quarantine or p=reject once legitimate senders are authenticated.
SSL/TLS
Cloudflare issues free SSL certificates for all proxied domains. Certificates auto-renew and support multiple SANs. The default mode is Flexible SSL, which encrypts traffic between visitors and Cloudflare but allows plain HTTP between Cloudflare and your origin.
SSL/TLS Modes
- Flexible: Visitor ↔ Cloudflare is encrypted. Cloudflare ↔ Origin is plain HTTP. Avoid this mode—it leaves your backend traffic unencrypted.
- Full: Cloudflare connects to your origin via HTTPS but doesn't validate the certificate. Acceptable if you use a self-signed cert.
- Full (strict): Cloudflare validates your origin certificate against a trusted CA. This is the recommended mode. Use Let's Encrypt or another CA to issue a valid cert for your origin.
- Strict (custom): Use a client certificate issued by Cloudflare to authenticate the connection from Cloudflare to your origin.
Enable HSTS and set the minimum TLS version to 1.2 or higher. TLS 1.0 and 1.1 are deprecated and should be disabled.
What's New in Recent Releases
Cloudflare ships features continuously. Recent additions that matter for hosting and infrastructure:
Cache Reserve
Cache Reserve is persistent cache storage backed by R2 (Cloudflare's object storage). Normal cache evicts content based on popularity. Cache Reserve keeps infrequently accessed objects cached indefinitely, reducing origin requests for long-tail content. Useful for media-heavy sites with large archives.
Turnstile
Turnstile is Cloudflare's CAPTCHA replacement. It challenges visitors with privacy-respecting puzzles that don't require image selection or audio challenges. Integrates with a simple JavaScript snippet. It's more user-friendly than legacy CAPTCHAs and works well for login pages and form submissions.
Zaraz
Zaraz is a third-party script manager that runs marketing tags, analytics, and pixels from Cloudflare Workers instead of the visitor's browser. This improves page load times and privacy by reducing the number of third-party requests.
You configure tags in the Cloudflare dashboard, and Zaraz loads them server-side. No more loading Google Tag Manager and a dozen vendor scripts in the browser.
Hyperdrive
Hyperdrive accelerates database queries from Cloudflare Workers by caching connections and maintaining persistent connection pools to your database. Useful if you're building APIs with Workers that query PostgreSQL or MySQL. It reduces query latency by eliminating connection overhead.
Which Features Are Worth Using?
For typical hosting scenarios:
Essential: - Proxied DNS for DDoS protection - Free SSL certificates - CDN and cache for static assets - Managed WAF rulesets
Recommended if you have the need: - Cloudflare Tunnel if you want origin IP protection - Cache Rules for custom caching logic - Workers for lightweight edge logic - Email Routing if you need custom domain email without a mail server
Evaluate based on cost and complexity: - Load Balancing (paid, but essential for multi-origin high availability) - Bot Management (paid, only if bot traffic causes measurable problems) - Cache Reserve (paid, useful for media-heavy sites)
Skip unless you have a specific use case: - Argo Smart Routing (marginal latency improvement at a recurring cost) - Waiting Room (paid, useful for ticket sales and limited-capacity events) - Stream and Images (competitive pricing but lock-in risk)
Conclusion
Cloudflare provides a broad set of features that solve real infrastructure problems: DDoS protection, CDN, edge compute, and secure connectivity. For hosting providers and sysadmins, the core value is defense against attacks and reduced origin load. The free tier covers most use cases. Paid features like Load Balancing, Bot Management, and Cache Reserve add capability but require cost-benefit analysis.
Start with proxied DNS, managed WAF rules, and cache configuration. Add Workers and Tunnel when you have specific needs that justify the added complexity. Monitor Security Events and Analytics to understand what's actually protecting your infrastructure versus what's just enabled by default.
Cloudflare's platform is powerful when used deliberately and with understanding. Avoid enabling features for the sake of it—every added layer introduces potential failure modes and troubleshooting complexity. Focus on the features that solve problems you're actually experiencing.
