Blogs›Cloudflare Feature Trails
See how major capabilities shipped, upgraded, and evolved across Cloudflare's engineering blog.
Publishing pulse
2010–2026 · peak 2022
2.7K posts mapped

Cloudflare's commitment to data privacy and protection has evolved significantly, driven by regulatory changes and a core mission to build a better internet. This evolution includes transparent policy updates, GDPR compliance measures, and the development of privacy-enhancing solutions like the Data Localization Suite (DLS). The DLS allows customers to use Cloudflare's global network and security measures while keeping data local, addressing concerns around encryption keys, regional service terms. Cloudflare for Government has achieved FedRAMP Class D (High) certification, building on its existing FedRAMP Moderate authorization. This new certification signifies a substantial increase in security requirements, enabling Cloudflare to handle the nation's most sensitive unclassified data. The FedRAMP High offering is built on Cloudflare's single, global network, leveraging the Data Localization Suite to ensure traffic inspection and processing occurs exclusively within U.S. data centers. This unified platform provides federal agencies with the same cutting-edge technologies as commercial enterprise customers, including Zero Trust security tools, application performance, and new developer features. The systems developed for FedRAMP High will also form the foundation for pursuing U.S. Department of Defense Impact Level 4 (DoD IL4) authorization.
Timeline

Cloudflare's website security and threat management has evolved from basic IP blocking to sophisticated, configurable WAF and advanced traffic control. This includes leveraging community-driven threat data, automated learning, and re-architecting the WAF. Recent advancements include enhanced botnet protection, automated phishing abuse reporting, improved bot management flexibility, the introduction of cryptographic mechanisms like HTTP Message Signatures and request mTLS to verify legitimate req. The Web Integrity & Trust team is developing strategies to assess and manage 'agentic' internet traffic, distinguishing between beneficial and malicious automated behaviors. This involves a 'Trust' framework, moving beyond simple risk assessment, and leveraging continuous session analysis with tools like Precursor. BotBase is being updated to track all known bots, not just good ones, and a new 'Adaptive Intelligence' engine for bot detection is being developed to continuously learn and self-adjust. Advanced mitigations are being designed to influence bot behavior through unpredictability and AI Labyrinth.
Timeline

Cloudflare's engagement with Artificial Intelligence (AI) has evolved from discussions about its potential impact to its deep integration across various domains. This includes developing sophisticated ML Ops platforms, leveraging AI for core services like WAF and bot management, and introducing specialized AI security solutions. The platform is expanding to address the challenges of deploying AI workloads in production, aiming to provide tools for accessing models, offering an inference gateway, and now, enabling natural language querying of complex datasets through tools like Radar Researcher.
Timeline

Cloudflare Workers has evolved into a powerful edge computing platform, enabling developers to run serverless code globally. This includes durable execution, dynamic code execution, a durable filesystem, and dynamic workflows via the Agents SDK. The platform now offers extended execution times with Workers Unbound, allowing for up to 30 seconds for HTTP requests and a private beta for Cron Triggers up to 15 minutes, enabling more intensive workloads at the edge. Pricing has also been optimized w. This evolution now includes the ability to inject a WebMCP bridge script at the edge, enabling websites to expose tools for AI agents without modifying origin code. This bridge registers tool packs, such as Content Credentials and Site MCP Server, which run entirely in the browser or communicate with an origin MCP server. Future packs will leverage Workers AI and AI Search.
Timeline

Cloudflare is evolving its platform to offer a unified 'connectivity cloud' that integrates security, performance, and developer services. This approach aims to simplify complex IT environments by providing deep integration with the internet and enterprise networks, programmability for customization, platform intelligence through traffic analysis, and a simplified user experience with a single pane of glass. This vision is realized through the consolidation of various services to address customer needs, including advanced AI agent security, post-quantum cryptography integration across all major on- and off-ramps, and a composable, programmable SASE platform that leverages Cloudflare Workers for custom logic. The platform aims to provide a unified codebase with truly unified control, data, and infrastructure planes, enabling rapid deployment of new use cases and secure adoption of AI technologies.
Timeline

Cloudflare's account management and access control capabilities have evolved from basic identity-based rules to a comprehensive zero-trust platform, aligning with industry standards like NIST's Zero Trust Architecture (ZTA). This evolution now extends to securing SaaS applications by integrating with their SAML authentication flows, allowing for consistent security controls, consolidated logging, and the enforcement of device posture and Gateway protection. The acquisition of BastionZero further enables a new Agent Access Model (AAM) that shrinks the trust boundary from the application to the individual action, making authorization decisions at machine speed. AAM enforces short-lived, task-scoped, sender-constrained credentials, with enforcement in the harness and network, exceptional human oversight for approvals, grants reviewed from evidence, and capability state moving in one direction via a Trust Ratchet. This model addresses the challenges of ephemeral agents acting at machine speed, composing authority across hops, and the limitations of prompt-based security.
Timeline

Cloudflare Registrar has evolved to offer a programmatic API for domain search, availability checks, and registration. This API is designed for integration into developer workflows, including AI agents and automation tools, allowing for seamless domain acquisition directly within development environments. The API aims to provide at-cost domain registration, mirroring the dashboard experience, and will expand to cover domain lifecycle management like transfers and renewals. This integration with Cloudflare Wallets enables agentic commerce by providing a stable identity and payment mechanism for domain registration and other services.
Timeline

Cloudflare is building a comprehensive observability platform to provide deep insights into network performance, application availability, and user experience. This evolution includes the introduction of Digital Experience Monitoring (DEM) with Synthetic Application Monitoring for proactive application performance testing and Zero Trust Fleet Status for real-time insights into device connectivity and security posture within the Cloudflare One SASE offering. Magic Network Monitoring, now generally available, provides network flow data. Cloudflare One Observability is being developed to unify data from various Cloudflare One functions into a single experience, simplifying troubleshooting for network connectivity, security policies, and performance issues across enterprise and cloud networks. It aims to automate data collection and aggregation, enabling users to visualize bandwidth usage, assess network vulnerabilities, and troubleshoot performance issues more efficiently by leveraging Cloudflare's integrated platform and single-pass inspection architecture. The platform is built on Cloudflare's global network and leverages advanced data tools like Instant Logs and ABR for real-time data delivery and large-scale analysis.
Timeline

Cloudflare R2 has introduced Event Notifications for triggering Cloudflare Workers based on data changes, Super Slurper for migrating data from Google Cloud Storage, and an Infrequent Access storage tier for cost-effective storage of less frequently accessed data. Event Notifications enable event-driven workflows by sending messages to queues when R2 data changes. Super Slurper now supports migrations from GCS to R2, complementing existing S3 migration capabilities. The Infrequent Access tier offers lower storage costs for data not accessed often, with data retrieval charges applied when accessed, and continues to uphold Cloudflare's zero egress fee policy. Future plans include automatic storage class optimization.
Timeline

Cloudflare's video streaming capabilities have evolved significantly, starting with Cloudflare Stream for simplified video delivery and addressing complexities like live video latency, programmatic watermarking, and ingest/delivery protocols. This evolution has expanded to include support for modern streaming protocols like SRT and WebRTC for live streaming with sub-second latency, AV1 codec support for enhanced efficiency, automated storage management through scheduled deletion, high-definition capabilities, and now the introduction of Cloudflare Realtime and RealtimeKit, which provide a suite of products and SDKs for building real-time voice, video, and AI applications, abstracting WebRTC complexities and integrating AI capabilities.
Timeline

Cloudflare's cdnjs platform has evolved its security posture and operational architecture by migrating its entire ecosystem to Cloudflare's Developer Platform. This includes leveraging R2 for single source of truth file storage, KV for metadata, Workers Cache for tiered caching, and Cloudflare Workflows for a robust, durable ingestion pipeline. The migration addresses previous pain points in observability, storage split-brain, pipeline orchestration, and GitHub repository limitations, leading to a more secure, scalable, and maintainable system. The platform now supports larger file types and offers improved resilience and debugging capabilities.
Timeline

Cloudflare's commitment to security has evolved from foundational measures to advanced cryptographic research and implementation, including post-quantum cryptography (PQC) and the standardization of Hybrid Public Key Encryption (HPKE). This evolution addresses future threats, particularly from quantum computing, by focusing on long-term resilience. The company is actively researching and adopting PKE for key agreement and signatures to protect data against future decryption. NIST has announced t
Timeline

Cloudflare is developing and open-sourcing tools to simplify the debugging and operation of privacy-preserving protocols. This includes the 'privacy-client' (pvcli) CLI tool, which supports protocols like Oblivious HTTP (OHTTP) by handling complex binary encoding, encryption, and multi-party communication steps. The tool aims to reduce friction in development and incident response for privacy products.
Timeline

Cloudflare's global network expansion has continued to grow, with the team working diligently to double the capacity of its global network over a six-month period. This involved upgrades and installations in numerous data centers across North America, Europe, and Asia, often under challenging circumstances such as equipment delays, carrier issues, and customs strikes. The focus remains on improving latency and performance for users worldwide, with plans for further expansion into Latin America. The addition of Belgrade, Serbia, marks the 107th data center and expands the European network to 30 cities.
Timeline

Cloudflare's cache management has evolved from basic CDN functionality and Page Rules to advanced performance optimization strategies. This evolution includes a hybrid memory-SSD storage system for intelligent asset placement and improved cache hit tail latency. The introduction of Tiered Cache, initially with a generic topology, allowed some data centers to serve as caches for others, reducing origin requests. Cache Reserve has been introduced as an ultimate upper-tier cache, leveraging R2 storage. This post details a benchmarking experiment using Real User Measurement (RUM) data to compare Cloudflare's network performance against Akamai, Amazon CloudFront, Fastly, and Google, focusing on TCP connection time, TTFB, and TTLB across various network segments (ASNs). The results indicate Cloudflare's #1 position in most performance metrics, driving further optimization efforts.
Timeline

Cloudflare's DNS infrastructure has evolved significantly, from handling traditional DNS records and security to exploring and building solutions for the emerging distributed web. This includes optimizing DNS resolution, drastically improving DNS record build and propagation speed, and actively participating in the AS112 project to manage misdirected DNS queries for private IP addresses. The introduction of Foundation DNS represents a major leap forward in authoritative DNS, enhancing reliabilit. Android Pie now supports Private DNS mode, enabling DNS over TLS (DoT) for encrypted DNS queries between devices and resolvers, enhancing privacy and security. This feature simplifies the configuration of custom secure DNS resolvers on Android, with Cloudflare's 1.1.1.1 resolver being a primary example. The post also touches upon the complexities of DNS in an IPv6 world, including the use of hostnames for Private DNS and the role of DNS64 and NAT64 in dual-stack environments.
Timeline

Cloudflare's database offerings have evolved to support global applications. Initially, D1 provided serverless relational database capabilities with SQLite compatibility and snapshot isolation consistency, leveraging Durable Objects for global uniqueness. The evolution now focuses on enabling globally-distributed applications through asynchronous read replication and zero-latency storage. This post introduces Hyperdrive, which acts as a global proxy and cache for existing databases, dramatically improving performance. The partnership with PlanetScale further enhances this by allowing direct creation and billing of Postgres and MySQL databases from the Cloudflare dashboard, integrated with Hyperdrive for optimized connectivity and placement hints for Workers.
Timeline

Cloudflare Workflows has evolved into a production-ready, serverless durable execution engine for building long-running, multi-step applications on Workers. It implements a step-based architecture with automatic retries and state persistence, ideal for complex business processes and coordinating between systems. The new `waitForEvent` API allows Workflows to pause execution and wait for external events, such as human approvals or webhooks, enabling more sophisticated human-in-the-loop scenarios. This post introduces the development of a serverless chatbot using Cloudflare Workers and Workers KV for managing service ownership, demonstrating reduced operational overhead and development time through serverless architecture and a command pattern for handling chatbot interactions.
Timeline

Cloudflare has developed sophisticated strategies and tooling for managing long-running processes, particularly focusing on the challenge of performing graceful upgrades without service interruption. This has evolved from exploring fundamental concepts of process replacement and socket management for TCP to developing robust, open-source libraries like 'tableflip' for Go and leveraging systemd for Rust applications. The 'Code Orange: Fail Small' initiative introduces a critical new phase, focusin
Timeline

Cloudflare's Apps program has evolved from offering simple integrations to a robust platform for third-party tools and services. Initially focused on enhancing websites, it expanded to include a more organized dashboard and acquired Eager. The program has now integrated with Cloudflare Workers, enabling developers to build and package serverless applications, creating the world's first serverless Apps platform. This evolution includes enabling codeless integrations for complex security solutions. The initial launch included VigLink, Apture Highlights, and Google Analytics, with plans for further expansion.
Timeline

Cloudflare's engagement with email infrastructure has evolved from promoting foundational security protocols like SPF, DKIM, and DMARC to offering a comprehensive Email Routing service and advanced threat protection through its Area 1 product. This evolution now includes the launch of Email Sending, a new capability for developers to send transactional emails directly from Cloudflare Workers, integrated with Email Routing to form a unified Cloudflare Email Service. The DMARC Management tool has been enhanced to provide insights into email security trends, including the analysis of Top-Level Domains (TLDs) associated with spam and malicious emails, identifying emerging threats from new gTLDs and established domains.
Timeline

Cloudflare's capabilities for securely exposing and managing internal services have evolved significantly, addressing the complexities of enterprise networking and the emergence of AI agents. Initially, Cloudflare Tunnel provided secure connectivity for private services, enabling remote workers to access internal applications and offering DDoS protection and access control. This has expanded to include Spectrum, which extends Cloudflare's security and acceleration to any TCP port and protocol, p
Timeline

Cloudflare's engineering blog has explored advanced programming techniques, particularly focusing on compile-time code generation and metaprogramming. This thread began with an in-depth look at Rust's powerful macro system, demonstrating how to implement complex logic like Reverse Polish Notation (RPN) evaluation directly at compile time. This capability allows for significant performance optimizations and the creation of highly specialized code without runtime overhead. More recently, Cloudflare has explored augmenting Nginx with Lua for custom modules, leveraging LuaJIT for performance and its asynchronous model. This enables the creation of powerful applications directly within Nginx, reducing the need for external services and offering a more integrated approach to extending web server functionality.
Timeline

Cloudflare's hardware infrastructure and performance optimization efforts have evolved significantly, moving from an exclusive reliance on Intel components to a more diversified approach including AMD EPYC processors and the strategic use of Arm architecture. This evolution is driven by a continuous effort to optimize cost, performance, and security. Recent advancements include the deployment of Gen 10 servers featuring AMD EPYC Rome processors, offering improved performance per watt and increased throughput by enabling Simultaneous Multi-Threading (SMT) and Core Performance Boost (CPB). Experiments have quantified the performance gains and power efficiency of these features, leading to informed decisions about their enablement in production environments.
Timeline

Cloudflare Pages build experience has been significantly improved with a new build infrastructure that drastically reduces build initialization time to 2-3 seconds by using pre-warmed machines and gVisor for secure sandboxing. Build logs are now streamable for faster debugging. Users gain control over branch builds, allowing specification of branches for automatic deployments and the use of 'CI Skip' commands. Future improvements include incremental builds, caching of external dependencies, up. This post introduces native support for custom headers and enhanced redirects, allowing developers to configure SEO, security, and CORS headers directly within their projects via `_headers` and `_redirects` files. The underlying matching engine is modeled after the URLPattern specification, with plans for full implementation in the Workers runtime.
Timeline

Cloudflare's approach to content management has evolved from traditional project-based work to treating content as a product, with a dedicated focus on content design and data-driven improvements. This shift involves adopting product development mindsets, agile methodologies adapted for content, and leveraging open-source platforms. The introduction of EmDash, a new open-source, serverless CMS built on TypeScript and Astro, represents a significant advancement. EmDash aims to be a spiritual successor to the example CMS built on the Cloudflare stack, which demonstrated the power of Workers, Workers KV, Cloudflare for SaaS, and Rate Limiting, with subsequent additions of Pages and Durable Objects. The example CMS progressed through phases, starting with a robust JSON API built on Workers and Workers KV, and evolving to include a Svelte-based dashboard hosted on Cloudflare Pages, demonstrating full-stack development capabilities and best practices for testing, deployment, and organization.
Timeline

Cloudflare Queues has evolved to offer enhanced consumer concurrency and explicit message acknowledgment, improving throughput and developer control. Future developments include R2 as a direct consumer and an HTTP pull API for external infrastructure integration. The service has seen its message throughput quadruple, with ongoing efforts to further increase this rate. This post introduces Cloudflare Queues as a global message queuing service integrated with Cloudflare Workers, offering at-least-once delivery and improved compression support.
Timeline

Cloudflare has evolved its API definition strategy from JSON Hyper-Schema to the industry-standard OpenAPI, significantly enhancing developer experience and accelerating development cycles. This evolution includes the development of automated conversion tools and the use of Stoplight Elements for better internal API maintenance and external tooling. The introduction of Scout, a Python-based automated testing system leveraging Pytest and OpenAPI schemas, further strengthens API reliability and de
Timeline

Cloudflare is increasingly adopting Infrastructure as Code (IaC) principles, primarily through the use of Terraform, to manage its vast and complex internal configurations. This shift from manual dashboard changes to code-driven management ensures consistency, auditability, and self-service for internal teams. The adoption of Terraform extends to managing DNS, WAF, Zero Trust, Email Security, Workers, and experimental features, enabling peer-reviewed changes, automated deployments via CI/CD pipe
Timeline

Cloudflare has a deep and reciprocal relationship with the open source community. Initially, the company relied heavily on open source software for its core infrastructure, including nginx and PostgreSQL. This evolved into actively contributing back to these projects, releasing their own open source tools and libraries, such as Red October, Lua Resty Shcache, Lua Resty Core, Go Libs, BM, Lua Raven, Lua Resty Logger Socket, conf, Lua Resty Kyoto Tycoon, Go LZ4, Aho Corasick, kt-fdw, Lua Resty Coo. This post details the company's use of open source software like nginx and PostgreSQL, their contributions to projects like Go's log/syslog module, and their sponsorship of LuaJIT. It also highlights their practice of open-sourcing their own components and the benefits of this approach, including attracting talent and fostering trust.
Timeline

Cloudflare's engagement with blockchain technology and decentralization has evolved from exploring fundamental concepts and their potential to remove intermediaries to actively integrating and supporting decentralized web protocols like IPFS and exploring specific blockchain protocols like Tezos. This evolution also includes addressing challenges in upgrading decentralized systems and promoting more trustworthy internet infrastructure through cryptographic advancements. The introduction of public gateways for IPFS has been a key development, with improvements focusing on cache management, custom domain integration via Orange-to-Orange (O2O), subdomain-based gateways for enhanced security and immutability, session affinity for improved performance, and persistent connections with pinning services like Pinata.
Timeline

Cloudflare is developing methods to detect Carrier-Grade Network Address Translation (CGNAT) to mitigate collateral effects of IP-based security mechanisms. This involves building supervised learning classifiers trained on network measurement techniques like distributed traceroutes to distinguish CGNAT IPs from other IP sharing technologies and single-subscriber IPs. The goal is to enable fairer treatment of users behind CGNAT IPs and reduce unintentional bias, particularly in developing regions. This post details the development of a multi-user IP address detection system that leverages internal and public data sources, including TCP connection source port counts and user agent analysis, to identify /24 IP prefixes likely to contain multi-user IPs. It also discusses the use of PeeringDB and IRR data to infer AS types and refine CGNAT detection, and validation methods using RIPE Atlas traceroutes and ISP partnerships.
Timeline

Cloudflare has a history of leveraging its scale for unique internal projects and data analysis. This began with ambitious, large-scale data collection and analysis efforts, such as the 'Internet Mince Pie Database' which, while seemingly whimsical, demonstrated the company's ability to mobilize resources for structured data gathering and review. This has evolved to more technically focused initiatives like optimizing data infrastructure for analytics, improving system-level operations, and developing rigorous methodologies for Internet measurement. This post details the scientific practice of Internet measurement, emphasizing its opacity, the importance of methodology (data curation, modeling, validation), ethics, and representation. It introduces active vs. passive and direct vs. indirect measurement techniques, using examples like HTTP traffic spikes in Lviv and packet pair bandwidth estimation. The measurement lifecycle is presented as a core pattern for generating predictive insights.
Timeline

Cloudflare's Load Balancing service has evolved from core functionality and UI improvements to a robust, stateless, and highly available solution for internal backend services. This evolution now extends to optimizing traffic at the IP layer with Argo for Packets, enhancing products like Magic Transit, Magic WAN, and Cloudflare for Offices by dynamically choosing the best possible path throughout Cloudflare's global network, leading to significant latency reductions and improved performance for users. The service now offers near-instant failover for proxied traffic, surpassing traditional DNS-based load balancing in responsiveness. It also provides active and passive monitoring to alert users of origin connectivity issues. The service is now available to all customers, not just Enterprise, with a focus on ease of setup and affordability.
Timeline

This thread tracks the discovery and analysis of bugs within the Go compiler, specifically focusing on issues that manifest in production environments due to scale. It includes detailed investigations into race conditions, stack unwinding errors, and segmentation faults, as well as the process of identifying root causes and contributing fixes upstream. This post introduces godebug, a cross-platform debugger for Go that rewrites source code to inject function calls for debugging, enabling single-binary, zero-dependencies debugging.
Timeline

Cloudflare for SaaS has evolved from SSL for SaaS to a comprehensive solution for SaaS providers. This includes enhanced capabilities for custom hostnames, such as Apex Proxying, Bring Your Own IPs (BYOIP) for granular IP allocation, and custom origin support for routing traffic to different origins based on customer needs. TLS certificate management has been improved with CSR support and the ability for customers to upload their own certificates. Custom metadata and Workers enable per-hostname
Timeline

Cloudflare's engagement with startups has evolved from initial pilot programs and a robust Startup Plan v2.0 to a comprehensive ecosystem that now includes physical office spaces for collaboration. This expansion aims to foster innovation and address the loneliness of building a company, particularly for remote-first startups. The program leverages underutilized office capacity to provide coworking spaces, complementing existing technical enablement and go-to-market resources. The Cloudflare for Startups Program now offers four credit tiers ($5,000, $25,000, $100,000, $250,000) to better match startups at every stage of their journey, supporting AI applications, real-time experiences, and durable multi-step applications.
Timeline

Cloudflare's certificate authority chain management has evolved to proactively address industry shifts and enhance security. This includes transitioning from Let's Encrypt's cross-signed IdenTrust chain to its ISRG Root X1 chain to prepare for the expiration of the former. This change aims to improve the agility of the Public Key Infrastructure (PKI) ecosystem, enabling broader adoption of new security standards and protocols by encouraging clients and browsers to support adaptable trust stores. This post details an incident where allegations of a compromise at GlobalSign, a CA partner, temporarily suspended new SSL certificate issuance, highlighting the importance of CA trust and Cloudflare's ability to automatically reissue and deploy certificates across its network in response to such events.
Timeline

Cloudflare is actively working to improve the security and reliability of its infrastructure by implementing automated security patching for the Linux kernel. This includes a rigorous process for testing and deploying new kernel versions, as well as developing tools like Reboau to manage custom reboot logic for control plane workloads. The company is committed to meeting CISA's Secure-by-Design pledge goals, with a focus on delivering faster security patches to customers. This post details the i
Timeline

Cloudflare actively combats patent litigation abuse by crowdsourcing prior art through initiatives like Project Jengo, aiming to invalidate overbroad patents and protect innovators. This has led to significant wins, including the voluntary cancellation of Sable Networks' '932 patent and encouraging other companies like Coinbase to adopt similar anti-troll strategies. The program continues to offer bounties for prior art submissions, fostering a community effort against patent trolls. The recent win against Sable Networks' '932 patent via IPR demonstrates the effectiveness of this strategy.
Timeline

Cloudflare is actively working to reduce entire classes of vulnerabilities in its software development lifecycle. This includes enhancing static analysis tools with custom rulesets to proactively detect and block injection vulnerabilities and secrets in code. The company leverages automation, secure defaults, and developer training to prevent these issues from reaching production, aiming to meet CISA's 'Secure by Design' pledge goals.
Timeline

Cloudflare is exploring and implementing Multi-Path TCP (MPTCP) to leverage multiple network paths for enhanced connectivity. This involves understanding and configuring MPTCP subflows, path managers, and schedulers on both client and server sides, particularly for Linux and iOS/macOS. The goal is to improve aggregation and mobility use cases, such as maintaining persistent SSH sessions across network interface changes and aggregating bandwidth from multiple network interfaces.
Timeline

Cloudflare has been actively working to internationalize its products and services, starting with the Cloudflare dashboard. This effort involves externalizing all user-facing strings, managing dynamic data within translations, handling pluralization, and incorporating rich text elements like links. The company has developed a repeatable process for internationalization and localization, aiming to make its platform accessible to a global and diverse customer base in their native languages. This post marks the initial step by adding direct support for International Domain Names (IDNs) in the UI and backend, allowing users to register and manage domains using non-Latin characters, and upgrading the entire UI to support the UTF8 character set.
Timeline

Cloudflare is leveraging KubeVirt to run virtual machines alongside containerized workloads within its multi-tenant Kubernetes clusters. This enables teams requiring deep integration with the Linux kernel, such as for build infrastructure and network simulation, to do so securely and efficiently. KubeVirt integrates with Kubernetes primitives and CRDs, allowing for scalable VM deployment and management. Use cases include Kubernetes scalability testing, development environments, kernel and iPXE testing. This post details the development of Sciuro, an open-source replacement for Node Problem Detector, which synchronizes Kubernetes node conditions with firing alerts in Alertmanager, enabling automated remediation of issues like excessive CNI network interfaces on self-managed bare-metal Kubernetes nodes.
Timeline

Cloudflare's founding vision is to democratize performance and security by building a global network and a platform that makes any website faster, safer, and better. This vision is realized through a deliberate approach to innovation, driven by cultivating curiosity within its team, leveraging its own technology (eating its own dog food) for product development, and deeply engaging with its vast free customer base for testing and insights. This iterative, customer-centric approach allows for rapid development and deployment of new features and products, as exemplified by the recent Birthday Week releases including email security, expanded office building network presence, and Web3 initiatives. The company's use of its own Workers platform as an abstraction layer enables massive development velocity and rapid global rollout of innovations. Smaller, focused teams, including dedicated Emerging Technology and Incubation and Research teams, are empowered to explore new products and define new standards. The company ships software in a consumer-like iterative process, rolling out initial concepts to subsets of users to gather feedback and guide development. This approach, combined with cost-effective network infrastructure, allows for significant savings passed on to customers, including free services. The vast free customer base serves as a critical testing ground for new capabilities, providing the scale and diversity of traffic and threat patterns needed to refine products before broad rollout. This iterative, customer-centric approach allows for rapid development and deployment of new features and products, as exemplified by the recent Birthday Week releases including email security, expanded office building network presence, and Web3 initiatives. The company's use of its own Workers platform as an abstraction layer enables massive development velocity and rapid global rollout of innovations. Smaller, focused teams, including dedicated Emerging Technology and Incubation and Research teams, are empowered to explore new products and define new standards. The company ships software in a consumer-like iterative process, rolling out initial concepts to subsets of users to gather feedback and guide development. This approach, combined with cost-effective network infrastructure, allows for significant savings passed on to customers, including free services. The vast free customer base serves as a critical testing ground for new capabilities, providing the scale and diversity of traffic and threat patterns needed to refine products before broad rollout.
Timeline

Cloudflare's fleet management has evolved from manual YAML file management to a robust, in-house system called Zinc. Zinc models logical and physical infrastructure assets (servers, network devices, data centers) in a strongly-typed system, providing APIs and interfaces for efficient fleet management. It integrates with other systems for workload assignment, maintenance scheduling, repair management, and diagnostics. Zinc offers a native web interface and CLI tooling for engineers, with features for automated maintenance window determination using sinusoidal wave fitting on traffic patterns to minimize customer impact during reboots.
Timeline

Cloudflare is actively involved in standardizing and implementing privacy-preserving technologies. This includes contributing to the Distributed Aggregation Protocol (DAP) for private aggregation and enhancing it with differential privacy to provide a stronger guarantee against data leakage. The company is developing an open-source implementation of DAP and a service to support partners, aiming to protect user privacy in various applications like telemetry and exposure notification systems. The focus is on rigorously quantifying privacy guarantees through the epsilon parameter and ensuring graceful degradation of privacy under various attack scenarios.
Timeline

Cloudflare has actively engaged with and partnered with web hosting and service providers to extend its reach and value proposition. This includes collaborations with companies like (mt) Media Temple, DreamHost, Verio, and UK2 Group, focusing on enhancing their offerings for small businesses and customers. The strategy involves acquiring complementary services and integrating them to provide a more comprehensive solution, encompassing website creation, performance, security, and marketing services. The partnership with DreamHost, announced in 2012, marked a significant step in offering one-click integration of Cloudflare services to their customers, including a custom 'Cloudflare Plus' plan with features like image optimization and SSL. This partnership model has been a cornerstone of Cloudflare's growth, enabling widespread adoption of its performance and security solutions.
Timeline

Cloudflare, in partnership with Vercel, Shopify, and core contributors to Node.js and Deno, has established the Web-interoperable Runtimes Community Group (WinterCG) under W3C. This group aims to standardize web APIs for non-browser JavaScript environments, ensuring code portability and consistency across runtimes like Cloudflare Workers, Node.js, and Deno. Key initiatives include defining a Minimum Common Web Platform API, developing specifications for Web Cryptography Streams to address limitations in streaming cryptographic operations, and creating a subset of the fetch() API tailored for server environments, acknowledging the differences from browser implementations regarding concepts like 'origin' and cookie stores. The group's work will be submitted to existing W3C/WHATWG work streams, with the potential to develop its own specifications if web browser needs are not met.
Timeline

Cloudflare is actively working to reduce its environmental impact by optimizing its global network infrastructure for energy efficiency. This includes leveraging renewable energy, focusing on data centers with low PUE, and implementing waste diversion and energy efficiency measures. A key aspect of this evolution is the strategic adoption of hardware, such as Arm CPUs, to significantly improve performance per watt and reduce overall energy consumption. This also encourages broader industry shift.
Timeline

Cloudflare is exploring and implementing advanced debugging capabilities for WebAssembly (Wasm) within its Cloudflare Workers runtime. This includes investigating the potential for Wasm core dumps, a critical feature for post-mortem debugging of application crashes. While the core Wasm specification for core dumps is still experimental and not yet fully supported in the Cloudflare Workers runtime (workerd), the company is actively researching and developing polyfilling techniques using tools like wasm-coredump-rewriter to enable this functionality. This effort aims to significantly improve the developer experience for debugging Rust and Wasm applications deployed on the edge, addressing the current reliance on printf-style debugging.
Timeline

Cloudflare is actively involved in securing Network Time Protocol (NTP) through the development and promotion of Network Time Security (NTS). This includes operating a time service that supports NTS on its officially assigned port (4460), contributing to the standardization process, releasing source code for specialized servers, and working with implementers to resolve bugs. The goal is to improve the security of time synchronization, which is foundational for other security protocols like TLS. This post details how Go programs on Linux leverage the vDSO mechanism for efficient time retrieval via clock_gettime, significantly improving performance compared to traditional system calls.
Timeline

Cloudflare's dashboard has evolved to manage an ever-increasing number of products and features. To address this complexity, Cloudflare has introduced 'quick search,' a cross-dashboard search tool designed to speed up common interactions by allowing users to quickly find and navigate to specific pages, website-specific products, and account-wide services. The new dashboard also introduces a more organized app-based navigation metaphor, moving away from the 'My Websites' page and organizing features into distinct 'apps' and 'modules' for a more consistent and scalable user experience. This redesign also prioritizes responsive design for mobile accessibility and a cleaner visual identity.
Timeline

Cloudflare is developing Oxy, a next-generation, Rust-based proxy framework designed to handle high-load scenarios and support a wide array of communication protocols. This includes exploring and implementing MASQUE (Multiplexing And Secure Communication over QUIC Express) to enable efficient tunneling of UDP traffic over QUIC, building on the DATAGRAM frame extension and extended CONNECT requests. This allows for proxying of protocols like HTTP/3 and other UDP-based applications, with consideration for advanced features like IP packet information control for UDP.
Timeline

Cloudflare is actively investigating and addressing issues related to TCP memory management and buffer allocation. This includes understanding and fixing unbounded memory usage by TCP receive buffers, which can lead to performance degradation and connection timeouts. The focus is on identifying root causes within the Linux kernel's TCP stack, such as how autotuning limits are handled and the behavior of TCP collapse processing, and developing robust solutions to ensure efficient and reliable network performance, particularly for mobile connections. This involves optimizing TCP congestion control algorithms and kernel parameters to better handle the lossy and high-latency characteristics of mobile networks, moving beyond default configurations that are ill-suited for these conditions.
Timeline

Cloudflare is developing Pingora, an in-house proxy, and its associated libraries. The pingora-limits library provides efficient mechanisms for counting inflight events and estimating event rates over time. This is crucial for protecting infrastructure from malicious or misbehaving requests. The library utilizes Count-Min Sketch (CM sketch) for space-efficient and lock-free event counting, offering significant performance and memory advantages over traditional hash table approaches, especially at scale.
Timeline

Cloudflare is exploring and implementing the Linux Kernel Crypto API for user applications to enhance security and performance. This involves understanding the API's system call interface, cryptographic parameter negotiation via /proc/crypto, and leveraging hardware acceleration like AES-NI. The focus is on evaluating the performance trade-offs between kernel-space cryptography and user-space libraries like OpenSSL, particularly for AES-CTR encryption. This exploration extends to integrating the Go programming language with these kernel-level cryptographic capabilities, including the development of assembly implementations for performance-critical algorithms like AES-GCM and Elliptic Curves (P256) to match or exceed the performance of state-of-the-art libraries like OpenSSL. This fork of Go aims to bring these performance improvements to the wider community.
Timeline

Cloudflare's DDoS mitigation architecture has evolved beyond traditional scrubbing centers to a distributed, always-on system integrated into its core network. This approach leverages commodity hardware, global network capacity, and custom software, including iptables and kernel bypass techniques like Solarflare EF_VI interface. The system distributes attacks across data centers and servers, allowing for continuous mitigation without downtime and improving the overall software delivery process. In Q1 2023, Cloudflare observed an increase in hyper-volumetric attacks, with the largest peaking above 71 million requests per second, and a 1.3 Tbps attack targeting a South American Telecommunications provider. The company also noted a shift towards VPS-based botnets and continued collaboration with cloud providers to dismantle them. Ransom DDoS attacks remained steady at 16% of reported incidents, with Internet companies, Marketing and Advertising, and Computer Software being top targeted industries.
Timeline

Cloudflare's BGP traffic engineering capabilities have been demonstrated to automatically reroute traffic around undersea cable failures, ensuring service continuity. The platform leverages BGP to seamlessly switch to backup paths, such as from Paris to Jersey when the direct London to Jersey path is disrupted, highlighting the resilience and adaptability of the global network. This post details an incident where packet loss on a major transit provider (Telia Carrier) necessitated manual intervention, and analyzes a significant outage experienced by Virgin Media (AS5089) due to BGP withdrawals and announcements, impacting DNS resolution and overall connectivity.
Timeline

Cloudflare is actively investigating and addressing issues related to TCP memory management and buffer allocation within the Linux kernel's networking stack, specifically focusing on AF_XDP. This includes debugging corrupt packets caused by descriptors being inserted into AF_XDP rings twice, leading to data corruption. The investigation involves detailed packet analysis, state machine tracking of descriptor transitions, and potential kernel bug identification. This post details a specific instance of using eBPF to extract IP TTL values from TCP connections to determine hop distance, bypassing limitations of traditional socket options and raw sockets. The approach involves attaching an eBPF program to a socket via SO_ATTACH_BPF to read TTL values and store them in an eBPF map for userspace analysis, demonstrating a novel method for network introspection.
Timeline

Cloudflare has enhanced its secure boot capabilities for Arm-based servers by implementing a Single Domain Secure Boot (SDSB) mechanism. This builds upon the Arm Trusted Firmware (ATF) Secure Boot process, allowing for cryptographic validation of the UEFI firmware using a hardware root of trust stored in eFuses. This provides a more robust security chain for Arm servers, similar to their existing solutions for x86 platforms.
Timeline

Cloudflare Workers has evolved into a powerful edge computing platform, enabling developers to run serverless code globally. Initially focused on bringing compute closer to users for reduced latency, it has expanded to support complex applications and foster community engagement. This includes enabling client-side A/B testing by hoisting critical logic to the edge, avoiding browser bottlenecks and FOUC. Furthermore, Workers are being used for server-side experimentation and feature flagging. Recent advancements include the introduction of Deployments, which allow developers to track changes to their Worker code, configuration, and bindings, providing an audit log and laying the groundwork for automated deployments and rollbacks.
Timeline

Cloudflare's security posture has been significantly bolstered by its strategic adoption of BoringSSL, a fork of OpenSSL maintained by Google. This decision has proven critical in mitigating the impact of high-risk vulnerabilities like CVE-2014-0160 (Heartbleed), which affected OpenSSL 1.0.1. The company's internal systems, which rely on BoringSSL, were not impacted, demonstrating the effectiveness of this architectural choice in isolating the organization from widespread third-party library vulns. Further analysis of the Heartbleed vulnerability revealed that the OpenSSL implementation itself was susceptible to leaking private keys due to memory management issues, specifically the improper handling and cleansing of prime numbers used in RSA private keys. Cloudflare's investigation identified that OpenSSL would create temporary copies of these primes during cryptographic operations, and these copies were not always securely erased from memory, making them discoverable via the Heartbleed exploit. Patches were developed to address these memory cleansing issues in OpenSSL.
Timeline

Cloudflare is leveraging eBPF within Linux Security Modules (LSM) to implement granular security policies without requiring kernel module modifications or extensive configuration. This approach is being used to address specific security risks, such as preventing unprivileged users from escalating privileges via USER namespaces using the `unshare` syscall. The LSM BPF framework allows for dynamic policy enforcement at specific kernel hook points, offering a flexible and robust security mechanism.
Timeline

Cloudflare's exploration of low-level hardware behaviors and their impact on system performance has evolved to include the analysis of dynamic voltage and frequency scaling (DVFS) and its data-dependent nature. This vulnerability, Hertzbleed, demonstrates how CPU power consumption variations, influenced by data characteristics like Hamming weight and Hamming distance, can lead to data-dependent CPU frequencies and execution times. This has implications for cryptographic software security, partic
Timeline

Cloudflare has a history of adopting and supporting emerging internet protocols to democratize performance and security. This includes early adoption of SPDY, HTTP/2, and TLS 1.3. As newer, standardized protocols like HTTP/2 have gained widespread adoption, Cloudflare has strategically deprecated older protocols like SPDY to streamline its infrastructure, reduce engineering overhead, and focus on maintaining modern standards. This process involves analyzing adoption trends, assessing the impact. This post details the publication of new RFCs for HTTP semantics, caching, HTTP/1.1, HTTP/2, and HTTP/3, and analyzes traffic trends showing the increasing adoption of HTTP/3 across browsers and the slower adoption by search engine bots.
Timeline

Cloudflare is enhancing the security and manageability of its server fleet by adopting OpenBMC, an open-source firmware for Baseboard Management Controllers (BMCs). This move aims to provide greater transparency, faster patching, and more control over firmware, including the integration of TLS certificates and fine-grained credential management. Furthermore, Cloudflare is extending its secure boot capabilities to the BMC itself, leveraging hardware root-of-trust and security co-processors to validate BMC firmware signatures, thereby reducing the impact of malicious implants and ensuring a more robust security chain from system power-on.
Timeline

Cloudflare's offerings have expanded to encompass website backup and recovery solutions, including tools and services that enable website owners to safeguard their digital assets. This has evolved to include passive origin monitoring, which proactively notifies customers when their origin servers are down, allowing them to take action to restore their sites and reduce the impact of downtime. Standalone Health Checks provide active monitoring with configurable checks and analytics. Health Check A, and now includes the integration of CodeGuard, a service that provides automatic website backups based on code changes and offers "Undo Power" for recovery.
Timeline

Cloudflare's research and development approach has evolved from a specialized Cryptography Research team to a broader Cloudflare Research initiative, driven by a hybrid model that embeds research engineers into product and operations teams for practical problem-solving. This is further strengthened by a structured Visiting Researcher program, which fosters collaborations with academia, bringing in external expertise for periods of three to 12 months. The company actively explores and publishes on topics including security and privacy, cryptography, internet measurement, low-level networking and operating systems, and emerging networking paradigms.
Timeline

Cloudflare is exploring and detailing the internal workings of io_uring, a high-performance asynchronous I/O API in the Linux kernel. This includes understanding how io_uring manages its worker thread pools for different types of I/O requests (bounded vs. unbounded), how to monitor and control these pools, and the implications for network I/O performance. The company is investigating the tracepoints and kernel mechanisms involved in worker creation and management to optimize its use of io_uring. This post also explores SOCKMAP, a new eBPF machinery for socket splicing, which aims to achieve zero-copy and zero-wakeup data forwarding purely in the kernel, though initial benchmarks showed it to be slower than other methods.
Timeline

Cloudflare has developed BoringTun, a userspace implementation of the WireGuard protocol written in Rust, aiming for a fast, safe, and cross-platform VPN solution. WARP, a mobile app utilizing this technology, secures all of a phone's internet traffic. The technical challenges in building WARP involved addressing issues with diverse phone and operating system versions, varied network conditions, and Cloudflare's own infrastructure. Key technical hurdles included managing ECMP routing with dynami The Cloudflare agent, built with a shared Rust daemon and leveraging BoringTun for its WireGuard implementation, has achieved feature parity across Windows, macOS, ChromeOS, Linux, iOS, and Android. New deployment and configuration options include domain-based and include-only split tunneling, improved private domain DNS resolution, and upcoming posture-only mode. Deployment is further streamlined through APIs and Terraform provider integration, with future plans for user/group-specific settings and dashboard management.
Timeline

Cloudflare is actively involved in securing RPKI validation software, addressing vulnerabilities in implementations like OctoRPKI. This includes developing and releasing patches for issues such as arbitrary file writes and resource exhaustion attacks, contributing to the overall security and reliability of BGP route validation. The post highlights the passing of the two hundred thousand ROA threshold, the launch of isbgpsafeyet.com, and the growth of RPKI Origin Validation deployment across netw
Timeline

Cloudflare's approach to engineering management and onboarding has evolved to be adaptable and inclusive, particularly in response to external crises. Initially focusing on structured in-person onboarding for new Engineering Managers and Solutions Engineers, the company has demonstrated a strong commitment to maintaining and even expanding internship programs during challenging times. This includes rapidly adapting to virtual onboarding processes, doubling internship class sizes, and providing comprehensive support for interns, with a recent significant expansion targeting 1,111 interns in 2026 to drive AI innovation.
Timeline

Cloudflare's software delivery process has evolved to accommodate diverse team needs, moving beyond a single methodology. The company emphasizes high-level concepts like 'SHIPs' (customer-facing changes) and 'EPICs' (work items, including technical initiatives) managed through a transparent 'SHIP-board'. Planning occurs quarterly, with a focus on continuous delivery and pragmatic date management. Strict rules govern code deployment to ensure safety and reliability, balancing team autonomy with organizational security requirements.
Timeline

Cloudflare has introduced 'Traffic Sequence,' a dashboard illustration that provides a high-level overview of how Cloudflare products interact during an HTTP request lifecycle. This feature aims to clarify the order of execution for various products, such as Firewall Rules, Workers, and Transform Rules, which has become increasingly complex with the introduction of new functionalities. Traffic Sequence is enabled by default for all zones and highlights the currently configured product area within the dashboard. Future aspirations include developing a more detailed, traceroute-like feature to show the exact path and transformations applied to user traffic.
Timeline

Cloudflare actively fosters community and developer relations through various initiatives, including providing spaces for meetups and participating in global events. This has evolved to include the launch of a dedicated Cloudflare Community forum, serving as a centralized hub for users to share expertise, ask questions, provide feedback, and participate in early access programs. The company has now launched Cloudflare TV, a 24x7 live television broadcast streamed globally via the Cloudflare network. This post highlights Cloudflare's support for the HBCU Smart Cities Challenge, offering Project Galileo to protect and accelerate their online presence, demonstrating a commitment to community engagement and bridging the digital accessibility gap.
Timeline

Cloudflare's understanding of branch prediction performance has evolved, moving beyond the general rule that predictable branches have near-zero cost. Experiments have revealed that the cost of branches, even unconditional ones, can increase significantly with their number and density. This has led to a deeper investigation into the Branch Target Buffer (BTB) and its capacity, demonstrating that performance degrades when the number of branches exceeds certain thresholds (e.g., 4096 branches). This understanding informs code optimization strategies to avoid performance penalties associated with excessive branching.
Timeline

Cloudflare has optimized memory usage by switching from glibc malloc to TCMalloc for services like Quicksilver, which uses RocksDB. This involved understanding the fragmentation issues inherent in glibc's arena-based allocation and the benefits of TCMalloc's front-end, middle-end, and back-end design for improved memory reuse across threads. The switch resulted in a 2.5x reduction in memory consumption.
Timeline

Cloudflare has adopted HashiCorp Nomad as a dynamic task scheduling system to improve the availability and resource utilization of management services across its global edge data centers. This system ensures a desired number of service instances are reliably running, regardless of the underlying physical machine, and integrates with Consul for service discovery and Prometheus for observability. Challenges in deployment, such as initramfs rootfs compatibility and resource containment, have been a focus. This post details the implementation of Apache Airflow for automating data center expansions, replacing manual SOP steps with API calls and custom operators. The system handles failure, logging, notifications, and Jinja templating, with sensors for preconditions and human intervention. Reusable DAGs and branching logic are employed for complex workflows and scaling across hundreds of data centers.
Timeline

Cloudflare's image matching capabilities have evolved to address performance bottlenecks in high-dimensional data. Initial approaches using naive quadratic algorithms and SIMD optimizations (AVX2) showed limited gains due to memory bandwidth constraints. Advanced algorithms like VP-trees struggled with the 'curse of dimensionality' in 144-dimensional spaces. Subsequent efforts focused on optimizing brute-force methods by introducing a 'short distance' variation that computes a subset of dimensions. This has now been extended to include a CSAM Scanning Tool for all customers, leveraging fuzzy hashing (PhotoDNA) to identify visually similar images even when altered, providing automated flagging, blocking, and reporting of illegal content.
Timeline

Cloudflare's analysis of the SUNBURST malware's Domain Generation Algorithm (DGA) has uncovered additional details about its encoding schemes and how it exfiltrates compromised hostnames. This includes identifying a quirk where long hostnames are split across multiple DNS queries, requiring a novel method of reassembly based on XORing GUIDs. The analysis also refines understanding of base32 encoding variants used by the malware and provides tools for matching fragmented DNS messages.
Timeline

Cloudflare's data center operations involve sophisticated power management, including the use of three-phase power distribution units (PDUs) to maximize efficiency and redundancy. This involves understanding AC power principles, Ohm's Law, Faraday's Law, and the advantages of three-phase over single-phase power for high-density computing environments. The company employs dual power supply configurations for servers and leverages PDUs with multiple circuit breakers for resilience. The implementation of redundant power systems ensures service continuity during outages, as demonstrated during the Taiwan power outage where Cloudflare's data center partner maintained operations via backup power, allowing internet services to remain available.
Timeline

Cloudflare's control plane and API availability has been a critical area of focus. Initial efforts centered on ensuring basic functionality and redundancy. Following an incident where a physical disconnection of core data center fiber links led to a significant outage of the Dashboard and API, Cloudflare has prioritized enhancing the resilience of its control plane. This includes redesigning connectivity to eliminate single points of failure, improving labeling and documentation for critical infrastructure, and analyzing Byzantine fault scenarios to improve system robustness. The incident highlighted the need for more automated steering of read-queries to secondary data centers and improvements in user session management for cross-datacenter resilience.
Timeline

Cloudflare engineers are contributing to gVisor, a Linux container runtime, by implementing the /proc/[pid]/mem file interface. This enables detailed debugging and stack trace analysis within sandboxed environments, addressing limitations in accessing process memory for debugging purposes.
Timeline

Cloudflare has been actively involved in the development and deployment of QUIC and HTTP/3 protocols. This post marks a significant milestone with the IETF Last Call for QUIC and HTTP/3 draft 32, indicating the protocols are nearing standardization. Cloudflare has been deploying HTTP/3 since September 2019 and has developed its own QUIC and HTTP/3 library, 'quiche'. The company is also exploring future extensions and use cases for QUIC, including multipath, new congestion control approaches, and.
Timeline

Cloudflare's Wrangler CLI has evolved its authentication process to improve the developer experience. Previously, users had to manually create API tokens through the Cloudflare dashboard. The new `wrangler login` command streamlines this by allowing users to authenticate directly with their Cloudflare credentials, similar to Argo Tunnel's login flow. This involves generating a public-private key pair, prompting the user to log in via the dashboard, automatically creating a Workers-scoped API token. The CLI's command structure for interacting with Workers KV has also undergone significant iteration, moving from filesystem-like commands to declarative subcommands, and finally to a colon-delimited namespacing pattern (`kv:namespace`, `kv:key`, `kv:bulk`) for improved clarity and usability. This evolution also includes leveraging the `wrangler.toml` configuration file to map human-readable binding names to KV namespace IDs, reducing the need for users to manually manage and input complex IDs.
Timeline

Cloudflare is exploring and implementing advanced sandboxing techniques in Linux, focusing on seccomp filters to restrict system call access for applications. This involves defining BPF programs to enforce policies, such as preventing network access for non-networked applications, and understanding the various penalty actions the kernel can take upon policy violation. The goal is to enhance security by isolating applications and preventing arbitrary code execution exploits without requiring code modifications.
Timeline

Cloudflare is enhancing customer support security by introducing Time-Based One-Time Passwords (TOTP) for phone authentication. This allows Enterprise customers to prove their identity over the phone using tokens generated from the dashboard or a 2FA app, without discussing sensitive account settings. The system leverages RFC 6238 for TOTP generation, with deviations for single-use tokens and dashboard-generated codes. Future work includes callback requests and integration with other authenticat
Timeline

Cloudflare's understanding and utilization of Linux's conntrack subsystem has evolved from avoiding it for simplicity to actively investigating its intricacies for new product needs. This includes understanding its state management, capacity limits, and the implications of its behavior when full, such as implicit packet drops and EPERM errors for UDP flows. The company is exploring its use in containerized environments and the nuances of its strict vs. loose modes.
Timeline

Cloudflare has been actively involved in the development and support of the Privacy Pass protocol, a privacy-preserving technology that allows clients to prove trust without revealing their identity or browsing history. This evolution includes server-side support, the development of open-source browser extensions (Chrome and Firefox), and integration with third-party services like hCaptcha. Recent advancements focus on Privacy Pass v2.0, featuring easier configuration, integration with new servi
Timeline

Cloudflare's understanding of website performance metrics has evolved to go beyond basic Time To First Byte (TTFB). This includes detailed analysis of client-side timing measurements from tools like cURL and Chrome, mapping them to network events like DNS lookup, TCP handshake, and TLS setup. The focus is shifting towards measuring the actual user experience, considering factors like page interactivity and resource loading, rather than just the initial byte arrival. Browser Insights provides Rea
Timeline

Cloudflare is developing tools to enhance debugging and visibility for its eXpress Data Path (XDP) implementations. This includes the creation of xdpcap, a replacement for tcpdump that operates within the XDP environment, and the open-sourcing of cbpfc, a compiler for converting classic BPF (cBPF) filters to eBPF. These tools enable developers to capture and analyze packets that would otherwise be invisible to traditional debugging methods, facilitating the development and troubleshooting of XDP-based network processing.
Timeline

Cloudflare is exploring and implementing the Linux AIO API for network I/O operations, moving beyond its traditional use for disk I/O. This involves understanding and leveraging `io_submit` for syscall batching and optimizing event retrieval by directly accessing the kernel's ring buffer, bypassing the `io_getevents` syscall for improved performance in high-concurrency network servers.
Timeline
Cloudflare has been involved in improving LuaJIT performance through a research project at King's College London. This project focused on developing a comprehensive benchmark suite for Lua implementations, analyzing the performance of different LuaJIT forks (original LuaJIT and RaptorJIT), and identifying areas for optimization. The work has led to a better understanding of VM warmup behavior and performance characteristics across various benchmarks.
Timeline

Cloudflare has evolved its TLS handling architecture to support early adoption of TLS 1.3. This involved implementing a custom TLS 1.3 stack in Go (tls-tris) and using SCM_RIGHTS to pass established TCP connections from an nginx-based SSL termination layer to the Go process. This allows for selective TLS version handling and rapid iteration on new TLS versions without impacting the broader stack. The implementation details for Go and Rust are provided, showcasing the use of UNIX domain sockets and the successful completion of an audit by NCC Group. The codebase is developed in the open and aims to be upstreamed to the Go project.
Timeline

Cloudflare has been offering full IPv6 support and an IPv6-to-IPv4 gateway since 2012, making it easy for customers to transition to IPv6. This includes features like IPv6 Compatibility enablement in the dashboard and Pseudo IPv4 for legacy IPv4 applications. The company actively supports emerging networking technologies and provides guidance for developers navigating IPv6-only environments, such as those mandated by Apple for iOS apps. This support aims to simplify the complex global transition. Universal SSL has been rolled out to all customers, including free tier users, doubling the number of SSL-enabled sites. This is achieved by automatically provisioning SSL certificates on Cloudflare's network, supporting both root domains and wildcard subdomains. For sites without prior SSL, Flexible SSL mode is enabled by default, encrypting traffic between browsers and Cloudflare. Full or Strict SSL modes are recommended for end-to-end encryption. The challenges of CPU load and IPv4 exhaustion were addressed by leveraging ECDSA cipher suites and Server Name Indication (SNI) for modern browsers, allowing multiple customer sites to share the same IP address. Legacy browsers, such as Internet Explorer on Windows XP and pre-Ice Cream Sandwich Android, are not supported on the free plan. Paid plans continue to support all browsers. Universal SSL also enables broader support for the SPDY protocol. Future plans include leveraging IPv6 connections for SNI-less browsers and encouraging users to upgrade to modern browsers and operating systems. A 'Better Browser' app is available to prompt users to upgrade. The decision to offer Universal SSL to all customers, even at a potential short-term revenue cost, aligns with Cloudflare's mission to build a better, encrypted internet. The rollout is ongoing, with full provisioning expected within 24 hours for most customers. Support for hosting partners will be enabled later.
Timeline

This thread tracks the debugging and resolution of issues encountered during Linux kernel upgrades, specifically focusing on performance regressions and memory allocation problems that manifest in production environments. It includes analysis of tools like `perf`, identification of kernel subsystems like RCU and memory management, and the process of bisecting to pinpoint problematic kernel versions or distribution upgrades.
Timeline

Cloudflare's DDoS mitigation capabilities have evolved to analyze and defend against increasingly sophisticated amplification attacks. This includes deep dives into protocols like NTP (specifically the MONLIST command) and DNS, understanding their vulnerabilities, and developing strategies to counter large-scale UDP floods. The focus is on identifying and mitigating new attack vectors by analyzing traffic patterns, reflector IPs, and protocol-specific weaknesses to maintain network resilience. This post details the mechanics of NTP-based amplification attacks and provides guidance for mitigating them by securing NTP servers and implementing BCP-38.
Timeline

Cloudflare is actively involved in improving password security and authentication mechanisms. This includes developing and promoting secure password hashing techniques like Argon2, BCrypt, and PBKDF2, and addressing vulnerabilities such as rainbow table attacks and brute-force attacks. The company is also contributing to solutions that eliminate password reuse, such as designing range search APIs for leaked password validation and supporting Two-Factor Authentication. Efforts are also directed towards adhering to Kerckhoff's Principle by making system details public and relying on the strength of algorithms like bcrypt for password storage security, assuming potential disclosure of hashed passwords and salts.
Timeline

Cloudflare has explored and implemented methods to use Go as a scripting language on Linux. This involves overcoming limitations of the standard `go run` command and the shebang mechanism by leveraging the Linux kernel's `binfmt_misc` module. This allows `.go` files to be executed directly as scripts, preserving proper error code propagation and enabling a seamless edit-execute cycle without requiring a separate build step for simple scripts. This approach enhances developer productivity for scripting tasks by utilizing Go's strengths like strong typing and its rich library ecosystem.
Timeline

Cloudflare's engineering blog has explored various aspects of advanced programming techniques, including the sophisticated use of Rust macros for compile-time code generation. This thread tracks the evolution of how Cloudflare engineers leverage metaprogramming to enhance code efficiency, reduce boilerplate, and enable complex computations at compile time. Early explorations focused on understanding and applying powerful macro systems like Rust's to solve specific problems, such as implementing Reverse Polish Notation evaluation at compile time. This demonstrates a commitment to pushing the boundaries of what can be achieved during the build process, leading to more optimized and robust software.
Timeline

Cloudflare has encountered and analyzed a processor bug in Intel Xeon E5-2650 v4 (Broadwell) processors that manifested as unexpected core dumps. This involved detailed post-mortem debugging using core dumps, ruling out software bugs, memory errors, and kernel issues. The investigation led to the identification of a specific hardware flaw, highlighting the importance of thorough hardware validation and analysis even for seemingly reliable components.
Timeline

Cloudflare's TCP connection handling has evolved to utilize end-to-end Keep Alives, reducing TCP overhead and latency by maintaining persistent connections to origin servers for multiple requests. This optimization improves the time to first byte and overall site snappiness, especially for sites with consistent traffic. The implementation benefits sites whose origin servers support Keep Alive connections.
Timeline

Cloudflare is evolving its Server header to simplify its identity from 'cloudflare-nginx' to a more generic 'cloudflare'. This change reflects the increasing complexity of Cloudflare's stack beyond just NGINX and anticipates future custom web serving or caching solutions. The transition is being rolled out in stages to allow dependent software to update.
Timeline

Cloudflare's engineering blog has explored various aspects of Go programming, including performance optimization and debugging. This post details an investigation into the performance impact of Go's garbage collector (GC) on multi-core machines. The author benchmarks ECDSA P256 signing operations across different numbers of goroutines, observing a performance drop with increasing goroutines due to frequent and expensive GC cycles. The post demonstrates how tuning the GOGC variable, which control
Timeline

Cloudflare's Geo Key Manager allows customers to control the physical distribution of their private SSL keys across Cloudflare's global data centers. This feature addresses geopolitical concerns and regulatory requirements by enabling customers to restrict key storage to specific regions (e.g., U.S. Only, E.U. Only) or to a subset of 'Highest Security' data centers. For connections to data centers without local key access, Cloudflare utilizes Keyless SSL, introducing minimal latency for the init
Timeline

Cloudflare's platform has evolved to address the complexities and pitfalls of IP fragmentation. This includes understanding the limitations of IPv4 and IPv6 fragmentation, the critical role of Path MTU Discovery (PMTUD) and the 'Don't Fragment' (DF) flag, and the challenges posed by network middleboxes, NAT, and load balancing techniques like ECMP and Anycast. The company actively works to mitigate issues arising from dropped ICMP 'Packet too big' messages and misconfigured routers, aiming to enable smart MTU black hole detection and broadcast ICMP MTU messages to all servers to ensure they hit the relevant server handling a flow, regardless of ECMP forwarding. They have also reduced the MTU on IPv6 to a safe value of 1,280 and are enabling RFC4821 path MTU discovery for IPv4.
Timeline

Cloudflare has developed and open-sourced a suite of command-line tools (mmsum, mmwatch, mmhistogram) to aid in data analysis and visualization. These tools provide capabilities for generating ASCII histograms, monitoring real-time rate of change for command output, and summing lists of floating-point numbers. This expands the internal tooling available for engineers to quickly understand and process data from various sources, including network traffic and system metrics.
Timeline

Cloudflare has developed PAL (Permissive Action Link), a tool to securely distribute secrets to Dockerized production applications. PAL addresses the challenge of bootstrapping service identity in containerized environments by allowing encrypted secrets to be decrypted at runtime after the service's identity has been established. It supports PGP and Red October for encryption and leverages container labels and cgroups for authorization, enabling secure access control for secrets and facilitating the deployment of secret management services.
Timeline

This thread tracks the identification and mitigation of security anti-patterns in Internet of Things (IoT) devices. It covers vulnerabilities arising from the unique characteristics of embedded systems and their internet connectivity, such as insecure publish/subscribe mechanisms, improper TLS implementation, unencrypted bootloaders, and direct database connections for inter-device communication. The focus is on educating engineers about these risks and promoting secure design practices for IoT devices.
Timeline

Cloudflare's TLS cryptographic modes and vulnerabilities management has evolved to proactively address emerging threats and improve security. This includes modifying OpenSSL to prevent the use of RC4 for TLS 1.1 and above, introducing ECDSA, and continuously evaluating cipher suites to ensure optimal security for customers, such as by utilizing Perfect Forward Secrecy. The company maintains a public GitHub repository (sslconfig) to track the history and current state of its SSL configuration, and has observed a significant decline in the use of AES-CBC cipher suites in favor of more secure and performant alternatives like AES-GCM and ChaCha20-Poly1305. The adoption of ECDSA for digital signatures has also surpassed RSA, and Perfect Forward Secrecy (PFS) is now nearly ubiquitous.
Timeline

Cloudflare's HTML parsing and modification capabilities have evolved from a complex, difficult-to-maintain Ragel-based parser to a new, faster, and more maintainable streaming parser named cf-html. This evolution aims to improve the efficiency and reliability of features that modify HTML on the fly, such as email obfuscation, server-side excludes, and automatic HTTPS rewrites. The transition to cf-html is ongoing, with a focus on migrating all functionalities to the new parser. This post introduces the Automatic HTTPS Rewrites feature, which automatically upgrades HTTP resource URLs to HTTPS to fix mixed content issues, thereby ensuring full HTTPS security for websites.
Timeline

Cloudflare is actively involved in optimizing LuaJIT performance through research and development. This includes creating tools like 'loom' to better understand JIT compilation and debugging, and contributing to the LuaJIT ecosystem by addressing 'Not Yet Implemented' (NYI) features. A key focus has been on improving the performance of table iteration functions like `next()` and `pairs()` by enabling them to be JIT-compiled, thereby removing performance bottlenecks for Lua code that relies heavily on these features.
Timeline

Cloudflare has been offering full IPv6 support and an IPv6-to-IPv4 gateway since 2012, making it easy for customers to transition to IPv6. This includes features like IPv6 Compatibility enablement in the dashboard and Pseudo IPv4 for legacy IPv4 applications. The company actively supports emerging networking technologies and provides guidance for developers navigating IPv6-only environments, such as those mandated by Apple for iOS apps. This support aims to simplify the complex global transition. The Automatic IPv6 Gateway was introduced to address the incompatibility between IPv4 and IPv6 networks, allowing users on one protocol to access websites on the other without expensive hardware gateways. This feature is provided for free to all Cloudflare users.
Timeline

Cloudflare is developing and open-sourcing tools for generating documentation from TypeScript projects. This includes leveraging TypeDoc for API reference generation and custom Handlebars templates for richer content, such as linking directly to source code. The goal is to create a robust TypeScript documentation ecosystem.
Timeline

Cloudflare is developing and utilizing static analysis tools for Go to improve code quality and ensure dependency management. This includes building custom tools to check for vendored dependencies and exploring the capabilities of Go's static analysis libraries like golang.org/x/tools/go/loader.
Timeline

Cloudflare's approach to preventing HTTP request loops has evolved from implementing RFC 7230 compliant 'Via' header checks to actively addressing non-compliant proxy services that strip or modify these headers. This involves educating the industry and collaborating on solutions to ensure robust protection against resource exhaustion and denial of service attacks caused by such loops.
Timeline

Cloudflare has fully embraced Go as a core language for its services, utilizing it for critical infrastructure components like DNS, SSL, and network compression. The company has developed and open-sourced various Go-based tools and libraries, including RRDNS for DNS infrastructure, Railgun for compression, Red October for cryptographic security, and SSL Bundler for certificate chain optimization. This adoption extends to experimentation with related technologies like CoreOS and Docker, and contr. This post details a hack for obtaining test coverage data for end-to-end tests by compiling a dummy test that executes main() and running it with coverage flags.
Timeline

Cloudflare's platform has evolved to enable innovative security solutions by leveraging DNSSEC for SSH key management. This allows for secure, centralized storage and retrieval of public keys via DNS TXT records, simplifying key distribution and revocation for administrators. This capability enhances the security posture of SSH deployments by integrating with DNSSEC's cryptographic validation, ensuring the integrity and authenticity of public keys used for authentication.
Timeline

Cloudflare's engineering blog has explored various aspects of Go programming, including performance optimization and debugging. This post details the internal workings of the Go standard library's `net/http` client, specifically focusing on its connection pooling mechanism and the concept of 'late binding' to minimize roundtrip latency. The post illustrates how the client intentionally races between dialing a new connection and retrieving an idle connection from the pool, and how this mechanism is analogous to techniques used in other systems like Chromium and Cloudflare's own Railgun.
Timeline

Cloudflare's image optimization capabilities have seen significant performance improvements through the application of SIMD instructions, particularly AVX2, to computationally expensive image processing tasks like JPEG compression. This evolution focuses on optimizing parsers and image processing algorithms to enhance website performance and reduce server load. The Polish product has been updated to use mozjpeg 2.0, which offers better compression ratios and a higher success rate in compressing images. This post introduces Polish, which automatically optimizes images by removing unnecessary bloat and applying compression (lossless or lossy) to reduce file sizes, leading to performance gains, especially for mobile devices.
Timeline

Cloudflare's ability to track and analyze adoption rates of new operating system versions and their impact on network traffic, including IPv6 adoption, has been demonstrated through detailed analysis of user agent strings. This capability allows for real-time insights into global internet trends and the impact of major technology releases.
Timeline

Cloudflare's Railgun technology, a protocol for significantly faster and less bandwidth-intensive dynamic content delivery, has seen its version 3.3.3 battle-tested on high-traffic sites and released with RPMs for popular Linux and BSD variants, as well as an AMI for AWS. Additionally, a majority of leading hosting providers have integrated Railgun support, allowing users to enable it with a single click. This post details Luxury Link's experience using Railgun, observing significant reductions in HTML size and round-trip times. The article also discusses the limitations of generic compression like gzip and explores advanced techniques like Shared Dictionary Compression (SDCH) and Edge Side Includes (ESI) for further optimization of dynamically generated web content.
Timeline

Cloudflare's DNS server (RRDNS) previously generated version information via a Makefile and sed. A new method using the Go linker's `-X` flag allows for direct embedding of version and build time information into binaries, simplifying the build process and improving maintainability. This technique is applicable to any string variable within a Go program, including those in different packages, and works with external linking scenarios.
Timeline

Cloudflare leverages low-level ASCII character manipulation techniques, such as bitwise AND operations, to optimize performance in high-throughput scenarios like DNS packet filtering. This involves understanding character set limitations and implementing efficient comparison algorithms.
Timeline

Cloudflare's engineering practices have evolved to leverage Go interfaces for enhanced testability and modularity in software development. This approach simplifies unit testing by allowing for the creation of dummy implementations of complex components, isolating the logic under test. This capability is fundamental to building robust and maintainable software systems. This post details a common pitfall when using closures with goroutines in Go, where shared loop variables can lead to unexpected behavior. It provides a solution by passing the loop variable as a parameter to the goroutine's function.
Timeline

Cloudflare's Universal SSL offering has evolved to provide automated SSL certificate deployment for millions of websites. This includes prioritizing high-traffic sites, managing user expectations during provisioning delays, and providing progress tracking mechanisms. The initial rollout leveraged modern hardware with AES-NI and CLMUL instructions, and modern algorithms like ECDSA and ECDHE for faster handshakes. Session resumption techniques (session tickets and session IDs) were enhanced to wor This post marks a significant evolution by making SSL included automatically with every paid Cloudflare account at no additional cost. It introduces a "flexible" SSL mode that encrypts traffic from visitors to Cloudflare's network, protecting against common eavesdropping and attacks. This mode allows SSL to be used even in front of services where certificates cannot be installed on the origin server, simplifying the process to a one-click ease. Paid users are automatically set up with flexible or end-to-end SSL based on backend server support, with options to override or disable it.
Timeline

Cloudflare's engineering blog has explored the intricacies of Go's runtime, focusing on how it manages goroutine stacks. Initially, segmented stacks were used, allowing stacks to grow and shrink on demand. However, the 'hot split' problem, where shrinking stacks incurred significant overhead, led to a transition to stack copying. This new method doubles the stack size when growth is needed and copies the old segment, making shrinking a free operation. The implementation relies on garbage collection information to update pointers within the stack. This evolution aims to make goroutines more efficient and cost-effective for a wide range of tasks.
Timeline

Cloudflare's approach to memory management in Go has evolved from manual buffer recycling techniques using channels and custom recyclers to leveraging Go's built-in `sync.Pool` for efficient memory management in long-running network services. This evolution aims to reduce memory overhead, improve performance, and simplify development by providing a robust mechanism for reusing objects and reducing garbage collection pressure.
Timeline

Cloudflare's TCP congestion control algorithms have evolved to be more responsive to the dynamic and often sporadic nature of network congestion, particularly on mobile networks. By analyzing real-world network data from its global network, Cloudflare tunes its algorithms on a per-network basis to optimize performance, especially for networks experiencing high loss rates. This continuous tuning based on network growth and data analysis is core to Cloudflare's mission of building a better Internet.
Timeline