5 ms·
Pub/Sub, Workers, KV, Durable Objects, R2... yes, these all sounds promising. Awesome tool for developers. But there is one huge obstacle in the middle that pre
by shikivi 4y ago
Pub/Sub, Workers, KV, Durable Objects, R2... yes, these all sounds promising. Awesome tool for developers. But there is one huge obstacle in the middle that prevents most to actually try this stack.
Logs and Account Access control.
Cloudflare is a very powerful platform, you can't let everyone be Admin.
If you run anything, you need to be able to see logs it to ship it somewhere.
For some reason, Cloudflare thinks that these are enterprise feature. I got news for you, these are basic features for anyone who wants to build more than just a simple script for individual use.
You work so hard to build these features but let only a small subset of users really do anything meaningful with it
- sitkack 4y agoHonest question, not a snark attack. But would it be possible to build those things on top of Cloudflare itself, esp the logging? For access control, you would have to have a separate process controlling the CF api for configuration.
- okaybuy 4y agoNot so simple when a lot of the tooling that facilitates easy development is tied to CF API, are you meant to build your own cloudflared and wrangler just so you dont have to grant everyone in the org super admin? This is where AWS wins, AWS gives you everything from $0/month, IAM in the above case, but you don't stay at $0 for long, where as CF gives you partial bits but you remain at $0-low/pm for longer Its actually really ironic the same company that says SAML for all for free, can't even get basic RAC on their own admin controls
- jplevine 4y agoWe just announced something called the Workers Analytics Engine today: https://blog.cloudflare.com/workers-analytics-engine/ https://blog.cloudflare.com/workers-analytics-engine/ More coming soon! Happy to chat more - jpl at cloudflare dot com
- imobbscf 4y agoWhat would you like to see? Disclaimer: Engineer on the IAM team at Cloudflare
- manigandham 4y agoIAM/RBAC for members of an organization to control who can change settings, deploy scripts, add domains, etc.
- sieabahlpark 4y agoJust provide an Aws IAM type interface and everyone would be happy. Also don't charge for it, because that just states your systems literally were not designed with authorization in mind.
- okaybuy 4y agoYes, fully agree, just to give Fred access to develop a worker in dev environment we have to grant them access to the whole account, it's batshit insane. We created acmecorpx.com for dev and put this on a seperate CF account but it still sucks