4in6.net LLC services

Orange you glad I do CloudFlare

This is not an ad. I use cloudflare.

I use Cloudflare in my own infrastructure because it solves real problems cleanly.

DNS, tunnels, application access, reverse proxying, edge security, traffic control, and the general business of getting services safely from the inside of a network to the outside world all get easier when the edge is designed well.

That is the part I care about.

I am not interested in bolting Cloudflare onto an environment just because it is fashionable. I use it where it simplifies architecture, reduces exposed attack surface, removes unnecessary complexity, or gives a small team capabilities that would otherwise require a much larger stack of equipment and software.

Cloudflare Tunnel is a good example. Instead of punching another hole through a firewall and hoping everyone remembers why it exists three years from now, I can often build an outbound-only path, put identity and policy in front of the application, and leave the firewall doing what a firewall is supposed to do.

The same thinking applies to DNS and application delivery. A surprising number of “network problems” are really problems of ownership, visibility, naming, routing, certificates, or poorly defined boundaries between systems. Cloudflare gives me another very capable set of tools for solving those problems.

Where it makes sense, I can help with:

Cloudflare is not a replacement for good network design, good firewalls, or good systems administration.

It is a very good complement to all three.

And because I work on the network, firewall, Linux, and application-infrastructure sides of the problem, I can usually see more than just the Cloudflare dashboard.

Sometimes the right answer is a new Cloudflare configuration.

Sometimes the right answer is fixing the thing behind it.

Knowing the difference is part of the job.