BlogsCloudflareLoad Balancing UI and Feature Enhancements

Load Balancing UI and Feature Enhancements

Load Balancing UI and Feature Enhancements

43
posts
2013–2025

Cloudflare's Load Balancing service has evolved from core functionality and UI improvements to a robust, stateless, and highly available solution for internal backend services. This evolution now extends to optimizing traffic at the IP layer with Argo for Packets, enhancing products like Magic Transit, Magic WAN, and Cloudflare for Offices by dynamically choosing the best possible path throughout Cloudflare's global network, leading to significant latency reductions and improved performance for users. The service now offers near-instant failover for proxied traffic, surpassing traditional DNS-based load balancing in responsiveness. It also provides active and passive monitoring to alert users of origin connectivity issues. The service is now available to all customers, not just Enterprise, with a focus on ease of setup and affordability.

2025

Load Balancing Monitor Groups: Multi-Service Health Checks for Resilient Applications

10/17/2025

Introduced Monitor Groups for Cloudflare Load Balancing, allowing customers to bundle multiple health monitors into a single logical entity. This feature enables defining critical monitors (`must_be_healthy`), observational probes (`monitoring_only`), and uses a quorum-based system (defaulting to >50% healthy monitors) to determine endpoint health. It also enhances Dynamic Steering by using the aggregated health score and average RTT of active monitors for traffic steering decisions. The feature is initially available via API for Enterprise customers and will be rolled out to the dashboard for all users.

Your IPs, your rules- enabling more efficient address space usage

5/19/2025

This post introduces 'Service Bindings' for Bring Your Own IP (BYOIP) prefixes, allowing customers to dynamically allocate parts of their IP address space to different Cloudflare services (CDN, Spectrum, Magic Transit) rather than being restricted to a single service per prefix. It details the technical challenges and solutions, including enhancements to Tubular (an eBPF-based IP and port binding service) and the integration with NGINX ingress proxies, to enable this dynamic reallocation at scale. The post also highlights the ongoing work to reduce the transition time for IP prefix migrations between services.

2024

Simplify cloud routing and object storage configurations with Cloud Connector

8/16/2024

This post introduces Cloud Connector, a new feature that simplifies multi-cloud routing and object storage configurations. It allows users to direct traffic for a single hostname to multiple cloud providers (AWS S3, Google Cloud Storage, Azure Blob Storage, R2) without complex workarounds, extending capabilities previously limited to Enterprise customers to all plans. The feature leverages the Ruleset Engine and introduces a new `http_request_cloud_connector` phase, with plans to support more HTTP cloud services in the future.

Eliminating hardware with Load Balancing and Cloudflare One

7/16/2024

Introduced end-to-end private traffic flows and WARP authenticated device traffic for Cloudflare Load Balancing, eliminating the need for dedicated hardware load balancers. This is achieved through enhanced integration with the Cloudflare One platform, allowing load balancers to be used for both public and private traffic directed at private networks. This includes support for private IP addresses for load balancers, integration with Magic WAN for on-premises connectivity, and WARP client integration for distributed users to reach private services securely and privately.

Extending Private Network Load Balancing load balancing to Layer 4 with Spectrum

5/31/2024

This post announces the extension of Cloudflare's load balancing capabilities to Layer 4 (TCP/UDP) for private IP addresses. Previously, private network load balancing was limited to HTTP(S) traffic. This new feature integrates Cloudflare Spectrum, Cloudflare Tunnels, and Apollo to enable load balancing of non-HTTP(S) traffic to internal servers, eliminating the need for expensive on-premise hardware and providing DDoS protection and origin IP concealment for these private services.

Magic Cloud Networking simplifies security, connectivity, and management of public clouds

3/6/2024

This post introduces Magic Cloud Networking, a new capability built on the acquisition of Nefeli Networks. It addresses the complexities of managing public cloud networks by providing a unified, automated, and secure solution. The post details the challenges of cloud networking, such as poor visibility, rapid pace, diverse technologies, new cost models, security risks, and multi-vendor environments. It positions Magic Cloud Networking as a management plane solution that leverages native cloud data plane constructs, offering end-to-end visibility and simplifying multi-cloud network management within the Cloudflare One ecosystem.

Cloudflare treats SASE anxiety for VeloCloud customers

3/6/2024

This post details Cloudflare's strategy for migrating customers from VeloCloud to Cloudflare Magic WAN, positioning Magic WAN as a superior alternative for SASE. It highlights the architectural differences between acquisition-based SASE models and Cloudflare's integrated connectivity cloud approach. The post outlines the transition process, emphasizing consultation with solutions architects, product education workshops on Magic WAN, and support from customer success teams. It also touches upon the underlying architectural principles of Cloudflare's network and its composability.

Fulfilling the promise of single-vendor SASE through network modernization

2/7/2024

This post announces significant updates to Cloudflare One, Cloudflare's SASE platform, focusing on fulfilling the promise of single-vendor SASE through network modernization. It introduces more flexible on-ramps for site-to-site connectivity (agent/proxy-based and appliance/routing-based), new WAN-as-a-service (WANaaS) capabilities for networking teams (high availability, application awareness, VM deployment, enhanced visibility), and Zero Trust connectivity for DevOps (mesh and peer-to-peer secure networking). The post details how these updates simplify SASE implementation for security, networking, and DevOps teams by offering a unified, integrated solution that avoids the fragmentation of multi-vendor approaches.

2023

Announcing General Availability for the Magic WAN Connector: the easiest way to jumpstart SASE transformation for your network

10/3/2023

This post announces the general availability of the Magic WAN Connector, a key component of Cloudflare One's SASE platform. It simplifies SASE transformation for enterprise networks by providing zero-touch connectivity between existing network hardware and Cloudflare's global network. The connector offers automated routing, traffic steering, shaping, and failover, along with integrated Zero Trust security controls (Secure Web Gateway and private network security) for all traffic. It represents a significant step in evolving beyond SD-WAN by offering a unified, single-vendor SASE solution with reduced cost and complexity.

Elevate load balancing with Private IPs and Cloudflare Tunnels: a secure path to efficient traffic distribution

9/8/2023

This post introduces Private Network Load Balancing, enabling load balancing for private IP addresses within data centers by integrating with Cloudflare Tunnels. This allows for the use of intelligent steering policies (e.g., least outstanding requests, hash steering) for internal services, removing the need for physical load balancers and simplifying configuration through the Cloudflare dashboard. It also highlights the security benefits of using Cloudflare Tunnels for establishing secure, outbound-only connections to private origins.

Lost in transit: debugging dropped packets from negative header lengths

6/26/2023

This post details the debugging and resolution of packet drops encountered after switching from Foo-over-UDP encapsulation with virtual interfaces to IPVS native Generic UDP Encapsulation (GUE). The issue stemmed from negative header lengths during encapsulation, causing packets exceeding the Internet MTU to be dropped by the traffic directors. The root cause was identified through eBPF tracing with `pwru` and `perf-probe`, revealing packet drops within the `validate_xmit_skb` function called from `ip_vs_tunnel_xmit`. The fix involved addressing the underlying kernel behavior related to header length calculation during GUE encapsulation.

Argo Smart Routing for UDP: speeding up gaming, real-time communications and more

6/20/2023

Introduced Argo Smart Routing for UDP traffic, extending the existing Argo Smart Routing product to accelerate UDP-based applications like gaming and real-time communications. This involved extending route computations to UDP and validating performance improvements through testing, showing up to 17.3% reduction in round-trip-time.

How Orpheus automatically routes around bad Internet weather

6/19/2023

This post introduces Orpheus, a system that automatically identifies and routes traffic around Internet connectivity outages in real-time, even those outside of Cloudflare's network. It leverages Cloudflare's global network to find alternative paths, preventing request failures (like 522 errors) and improving origin reachability. Orpheus builds upon the reliability features of Argo Smart Routing, making advanced routing around Internet 'weather' available to all customers for free.

Cloud CNI privately connects your clouds to Cloudflare

1/13/2023

This post introduces Cloud CNI (Cloudflare Network Interconnect) which enables direct, private connections from major cloud providers (IBM Cloud, Google Cloud, Azure, OCI, AWS) into Cloudflare's network. This significantly simplifies corporate network connectivity by allowing Cloudflare to act as the central network intermediary, replacing multiple vendors and complex routing. It integrates seamlessly with existing Cloudflare One products like Magic WAN, Access, and Gateway to provide enhanced security, privacy, and simplified management for cloud-based resources.

Cloudflare Application Services for private networks: do more with the tools you already love

1/13/2023

This post significantly expands the Load Balancing feature thread by detailing the integration of Cloudflare's application services, including WAF, API security, and load balancing, with the Cloudflare One dataplane for private networks. It introduces the ability to apply WAF policies and API security to internal APIs and private applications, regardless of their network on-ramp. Furthermore, it announces upcoming capabilities for application-layer load balancing for traffic connected via various off-ramps and extending load balancing into local networks. It also highlights the automatic application of Argo Smart Routing for full-stack performance optimization of private apps and the introduction of Private DNS for unified management of internal network resources.

Announcing the Magic WAN Connector: the easiest on-ramp to your next generation network

1/10/2023

This post introduces the Magic WAN Connector, a lightweight software package designed to simplify the integration of existing physical or cloud networks into Cloudflare's global network. It acts as an easy on-ramp for adopting SASE, automating connectivity, traffic steering, and shaping. The connector provides end-to-end traffic management features like routing, load balancing, failover, and application-aware steering, and integrates seamlessly with Cloudflare One's security suite. The post also highlights the open-sourcing of the connector and expansion of Network On-Ramp partnerships.

2022

How we built Pingora, the proxy that connects Cloudflare to the Internet

9/14/2022

This post introduces Pingora, a new in-house HTTP proxy built with Rust, designed to replace NGINX for Cloudflare's core proxying needs. It details the architectural limitations of NGINX that led to this decision, such as unbalanced load distribution, poor connection reuse, and difficulties in adding custom functionality. Pingora's design leverages Rust for memory safety and performance, a multithreaded, work-stealing scheduler with Tokio for efficient resource sharing and connection pooling, and an event-based programmable interface similar to NGINX/OpenResty for extensibility. The post highlights Pingora's production performance improvements, including a 5ms reduction in median TTFB and an 80ms reduction in the 95th percentile, significant improvements in connection reuse ratios (e.g., from 87.1% to 99.92%), and the ability to add new features like HTTP/2 upstream support more rapidly.

Load Balancing with Weighted Pools

8/2/2022

Introduced Weighted Pools for Cloudflare Load Balancer, allowing customers to assign relative weights to origin pools. This feature extends the random steering policy and enables scenarios such as balancing traffic across unequally sized origin pools, disabling specific data centers by setting weights to 0, and performing network A/B testing by directing a small percentage of traffic to new pools.

Magic NAT: everywhere, unbounded, and lower cost

5/12/2022

This post introduces Magic NAT, a new service that extends Cloudflare's network capabilities by providing a globally distributed, unbounded, and cost-effective Network Address Translation (NAT) solution. It addresses the limitations of traditional NAT hardware and virtual appliances, such as geographical constraints, capacity limits, and complex pricing models, by leveraging Cloudflare's Anycast architecture and Zero Trust platform. Magic NAT supports various use cases including public NAT, private NAT for overlapping IP spaces, and IP address conservation, and integrates with other Cloudflare One security features.

A Primer on Proxies

3/19/2022

This post introduces the concept of forward proxying and details how the HTTP CONNECT method has evolved across HTTP/1.1, HTTP/2, and QUIC/HTTP/3 to establish end-to-end tunnels. It highlights Cloudflare's involvement in standardizing efficient proxy protocols like MASQUE and its application in features like iCloud Private Relay, demonstrating advancements in secure and performant data encapsulation and tunneling.

Protect all network traffic with Cloudflare

3/17/2022

This post introduces the ability to offer Cloudflare-managed IP space as a service for Magic Transit. This allows customers with smaller networks, who cannot advertise their own IP space via BGP, to leverage Magic Transit for DDoS protection, performance, and reliability. It details use cases for consistent cross-cloud security, protecting branches of any size, and protecting streamers by masking their home IP addresses.

2021

How Cloudflare Is Solving Network Interconnection for CIOs

12/11/2021

This post details Cloudflare's strategy for solving network interconnection challenges for CIOs and IT teams. It emphasizes making interconnection valuable by providing access to Cloudflare's security, reliability, and performance products with zero additional latency, and leveraging network effects from its vast customer base. It also outlines plans to expand interconnection availability to 1000 new office locations through Cloudflare for Offices and describes efforts to reduce provisioning times for network connectivity to minutes by automating BGP configurations and streamlining cross-connect provisioning with partners.

Argo for Packets is Generally Available

12/10/2021

Introduces Argo for Packets, which optimizes traffic at the IP layer by dynamically selecting the fastest and most available path through Cloudflare's global network. This is achieved by leveraging health check probes and Layer 4 traffic analytics to construct dynamic routes, resulting in an average 10% latency improvement. The post details latency reductions with specific examples for different network topologies and highlights its integration with Magic Transit, Magic WAN, and Cloudflare for Offices.

Announcing Argo for Spectrum

11/23/2021

This post announces the general availability of Argo for Spectrum, extending Cloudflare's Argo Smart Routing capabilities beyond HTTP to any TCP-based application. It highlights how Argo for Spectrum reduces latency, packet loss, and improves connectivity for protocols like SFTP, RDP, and gaming, demonstrating significant performance improvements through benchmarks and explaining the underlying 'bandwidth delay product' concept. This marks a significant expansion of Cloudflare's performance optimization services to non-HTTP traffic.

Magic makes your network faster

9/16/2021

This post details how Cloudflare's "Magic" suite of products (Magic Transit, Magic WAN, Magic Firewall) leverages Anycast architecture, global network presence, and intelligent routing decisions to improve network performance for IP traffic. It explains how Anycast tunnels simplify connectivity, how running services everywhere enables efficient traffic processing, and how the "global hub" architecture eliminates the "trombone" effect of traditional hub-and-spoke models. Performance improvements are demonstrated through comparative tests showing reduced latency and increased throughput. The post also introduces Argo Smart Routing for Packets as a further enhancement for IP traffic performance.

Argo 2.0: Smart Routing Learns New Tricks

9/14/2021

This post announces significant upgrades to Cloudflare's Argo intelligent routing. Key enhancements include extending Argo's optimization to the 'last mile' (client to Cloudflare), reducing end-user round trip times by up to 40% and overall time to first byte by 39%. It also introduces support for accelerating pure IP workloads through 'Argo Smart Routing for Packets' for Magic Transit and Magic WAN customers. This new capability leverages health check probes and Layer 4 data to determine optimal IP-level routes, achieving an average of 10% latency improvement for these workloads. The improvements are automatically deployed for existing Argo customers.

Making Magic Transit health checks faster and more responsive

8/23/2021

Introduced a new distributed health check system for Magic Transit GRE tunnels. This system replaces the previous naive approach where each server independently checked each tunnel every minute. The new system utilizes consistent hashing to assign responsibility for checking specific tunnels to individual servers within a data center. These assigned servers then send health checks more frequently and share aggregated results via multicast heartbeats. This significantly reduced CPU usage by over 70% and memory usage by nearly 85% at the edge.

Rich, complex rules for advanced load balancing

7/16/2021

Introduced a custom rule builder for Cloudflare Load Balancing, built on the open-source wirefilter execution engine. This allows users to define complex traffic steering logic using 'and'/'or' statements based on various request attributes (path, headers, query strings, cookies, IP source addresses) for both DNS and proxied load balancing. This enables advanced use cases such as segmenting high-volume e-commerce transactions based on query string values and implementing split-horizon DNS by routing based on IP source address.

Per Origin Host Header Override

4/9/2021

Introduced per-origin Host header overrides for Cloudflare Load Balancing. This feature allows users to specify a custom Host header for individual origins, addressing issues where third-party applications use different hostnames than the customer's domain. The override is automatically applied to health monitors and provides flexibility for shared web servers. Restrictions on the Host header format and domain association were also detailed.

2020

Unimog - Cloudflare’s edge load balancer

9/9/2020

Introduced Unimog, an internal Layer 4 Load Balancer (L4LB) designed for Cloudflare's edge data centers. Unimog addresses the limitations of existing load balancing solutions by running on general-purpose servers, performing dynamic load balancing based on real-time server load measurements, supporting long-lived connections, managing virtual IP address ranges, and integrating tightly with DDoS mitigation systems using XDP. It improves reliability and operational efficiency by ensuring uniform load distribution across servers.

High Availability Load Balancers with Maglev

6/10/2020

This post details the implementation of Maglev, a stateless connection scheduler, for Cloudflare's internal load balancing infrastructure. It addresses the challenges of achieving zero-downtime maintenance and preserving source IPs by leveraging consistent hashing, BGP for routing announcements, IPVS with Foo-Over-UDP encapsulation for packet forwarding, and a custom node agent for configuration. The post also discusses the complexities of MTU management and the use of iptables for access control.

Adding the Fallback Pool to the Load Balancing UI and other significant UI enhancements

3/21/2020

This post details significant UI enhancements to the Cloudflare Load Balancing dashboard. Key contributions include: the addition of a visible 'fallback pool' configuration and display, de-modaling of the main Load Balancing page and related sections (monitors, pools) for improved usability, clearer display of shared object dependencies (monitors, pools) with new columns indicating usage, confirmation modals for edits impacting shared objects, and the replacement of ambiguous icon buttons with explicit text buttons ('Edit', 'Delete') to prevent accidental deletions.

2019

Introducing Load Balancing Analytics

12/10/2019

Introduced Load Balancing Analytics, featuring a traffic flow overview, a latency map visualizing origin health and latency from Cloudflare's global network, and event logs for origin health changes. The analytics are powered by a new GraphQL Analytics API, enabling detailed data extraction and analysis of traffic steering decisions, origin performance, and request distribution.

MultiCloud... flare

6/2/2019

This post introduces Cloudflare's capabilities for multi-cloud operations, focusing on Load Balancing, Argo Tunnel, and Access Control. Load Balancing is presented as a Layer 7 solution running on Cloudflare's global network, offering features like weighting, latency-based routing, and health checks independent of cloud providers. Argo Tunnel is described as a method to establish secure, outbound tunnels from customer infrastructure to Cloudflare's edge, simplifying networking and enabling dynamic scaling across clouds and on-premise environments. Access Control is highlighted as a zero-trust solution leveraging identity providers to secure access to infrastructure regardless of its cloud location, with an example of SSH access control.

2018

Custom Load Balancing With Cloudflare Workers

10/3/2018

This post introduces the capability of using Cloudflare Workers to implement custom load balancing logic. It provides code examples for basic request interception, random host routing, fallback routing with timeouts, and geographic routing based on the CF-IPCountry header. It also demonstrates how to combine these strategies into a single worker for more sophisticated load balancing scenarios.

I Wanna Go Fast - Load Balancing Dynamic Steering

7/21/2018

Introduced Dynamic Steering for Cloudflare Load Balancing, enabling traffic to be directed to the fastest pool for a given region or colo. This was achieved by solving two key problems: 1) determining the fastest pool using Round Trip Time (RTT) measured via existing health checks and calculated using Exponential Weighted Moving Average (EWMA), and 2) distributing this decision to 151 global locations by replicating pool RTT data to an in-house key-value store on every machine serving requests. EWMA was chosen over Simple Moving Average (SMA) for its faster response to RTT changes and ability to reduce noise. The data propagated is a map of pool identifier to EWMA, replicated efficiently using the network hierarchy.

Creating a single pane of glass for your multi-cloud Kubernetes workloads with Cloudflare

2/23/2018

This post demonstrates how to use Cloudflare Load Balancer with Kubernetes to manage traffic across multiple cloud providers. It highlights the benefits of multi-cloud deployments, such as avoiding lock-in and optimizing costs. It also provides a guide for deploying an application using Kubernetes on GCP and AWS with Cloudflare Load Balancer.

2017

Living In A Multi-Cloud World

11/21/2017

This post details how Cloudflare's Load Balancing can be used to implement a multi-cloud strategy by acting as a global traffic aggregator. It highlights the configuration of multiple pools with different origins (e.g., Google Compute Engine and Amazon Web Services) and the use of active layer 7 health checks for automatic failover. The example of Billforward is used to illustrate the benefits of cost efficiencies, negotiation strength, business continuity, and experimentation enabled by this multi-cloud approach facilitated by Cloudflare's load balancing capabilities.

Introducing Argo — A faster, more reliable, more secure Internet for everyone

5/18/2017

Introduced Argo, a 'virtual backbone' for the Internet, featuring Smart Routing and Tiered Cache. Smart Routing analyzes real-time Internet traffic data (latency, packet loss) to optimize routing paths between Cloudflare PoPs and origin servers, reducing latency and connection errors. Tiered Cache utilizes the global network of PoPs to serve content from other Cloudflare locations before hitting the origin, significantly reducing cache miss rates and origin load. Argo Smart Routing tunnels requests over a secure overlay network, improving reliability and performance compared to public Internet transit.

Introducing Load Balancing & Intelligent Failover with Cloudflare

5/14/2017

This post announces the general availability of Cloudflare's Load Balancing service to all customers, previously only available to Enterprise clients. It highlights the service's ability to route requests between multiple origins for geographic optimization and improved performance. Key features emphasized include near-instant failover for proxied traffic (contrasting with slower DNS-based failover), active and passive monitoring for origin health, and resilience against DDoS attacks due to its deployment within Cloudflare's global network. The post also details the ease of setup, affordability, and the ability to share configurations across multiple sites.

2016

Cloudflare Traffic Manager: The Details

9/29/2016

Introduced Cloudflare Traffic Manager, a new product offering flexible configuration for load balancing, failover, and geo-steering. Key technical details include per-data center health checking (HTTP(S) probes, status codes, response body parsing, timeouts), rapid failover within seconds for proxied records, and leveraging Anycast DNS infrastructure. The post details three primary use cases: round robin (active-active) load balancing, failover (primary-secondary) configuration supporting multi-cloud failover, and geo-steering based on user region. It also highlights how Cloudflare uses Traffic Manager for its own website, combining failover and geo-steering.

2013

How the CloudFlare Team Got Into Bondage (It's Not What You Think)

4/8/2013

This post details the implementation of port bonding (802.3ad Dynamic Link Aggregation) on Cloudflare's Generation 3 servers to aggregate multiple 1Gbps network interfaces into a single logical interface, increasing maximum throughput. It also describes the custom configuration of IRQ handling to isolate external and internal network traffic across physical CPUs and their cores, preventing network interrupts from becoming a bottleneck during large SYN flood attacks and ensuring customer traffic isolation.

Load Balancing without Load Balancers

3/6/2013

This post details Cloudflare's architectural approach to load balancing without traditional hardware load balancers, focusing on the use of Anycast routing at both the Wide Area Network (WAN) and Local Area Network (LAN) levels. It explains how Anycast is used at the WAN level to route traffic to the closest data center based on the shortest path, and at the LAN level within data centers, where each server announces routes via BGP using the Bird software. The system is designed to handle failures gracefully, with monitors detecting process crashes and signaling Bird to withdraw routes, rerouting traffic to the next available server. The post also touches on early experiments with BGP for true load balancing, particularly for UDP traffic, and acknowledges the complexities of stateful protocols like TCP and SSL.