8 ms·
CloudFront vs. Cloudflare, and how to reduce response times for both (2021)
- alberth 4y agoIf you host on Cloudflare Pages, does enabling Argo have any benefit?
- LukeLambert 4y agoNo, Argo optimizes the route of traffic from the edge (your closest Cloudflare data center) to the origin (the server hosting your website). With Pages, everything is served from the edge.
- cagenut 4y agonow do fastly
- bushbaba 4y agoNow that CloudFront has greatly improved its performance, what's the pitch for using CloudFlare over it?
- k__ 4y agoThey don't shut you off if you're alt right, lol.
- babelfish 4y agoBut they should.
- eastdakota 4y agoWanna bet? https://www.buzzfeednews.com/amphtml/johnpaczkowski/amazon-parler-aws https://www.buzzfeednews.com/amphtml/johnpaczkowski/amazon-p... https://amp.theguardian.com/media/2010/dec/01/wikileaks-website-cables-servers-amazon https://amp.theguardian.com/media/2010/dec/01/wikileaks-webs... Etc etc…
- stevewatson301 4y agoExcept for the fact that hosting Wikileaks and Parler with the content in question was always legally contentious. What Kiwifarms or The Daily Stormer hosted was sufficiently odious (in my view at least), it is disingenuous to suggest that the content is at the same level as what Amazon took action against.
- sophacles 4y agoSo why aren't those sites on Amazon right now? Seriously, if Amazon is such an amazing bastion of allowing that disgusting content, why are KiwiFarms and the Daily Stormer not happily up and running on AWS with CloudFront?
- stevewatson301 4y ago
- shitlord 4y agoAll of those sites are toxic customers. Continuing to host them will draw the government's ire. For Parler, the Jan 6 Committee would have inundated Amazon with subpoenas for internal documents and demanded testimony from executives. It's understandable why Parler was deplatformed so many times: because nobody likes government scrutiny. The risk is clearly greater than the reward. I'm not saying that this was the right decision for society, but I understand where they're coming from, and these companies should be transparent about their motivations.
- ceejayoz 4y agoCloudflare's significantly cheaper in many cases.
- nixcraft 4y agoPrice is the main difference between AWS CloudFront/Fastly and CF. In most cases, CF prices are fixed, like $200 for business or $20 for the pro plan. If you like fixed prices VMs from Linode or DO, chances are high that you will like Cloudflare too. Of course, advanced addons features like CF Argo and CF Bot management cost more money at Cloudflare too.
- hnov 4y agoWhile that lasts, you can't be charging a flat $200 in a world where the other players are charging 5-10¢/GB of egress.
- dustymcp 4y agoAlot of the companies who bought cloudflare would probably rather pay the 200$ than deal with migrating everything.
- NavinF 4y agoI said the opposite ("cloud providers can't keep charging 5-10¢/GB egress") a few years ago, but I guess I was wrong. I still think their pricing is absolutely insane in a world where even the smallest companies can colo a server and get wholesale transit that works out to <$0.005/GB. But I guess nobody's really pushing traffic so nobody cares about $/GB.
- yamtaddle 4y ago> I still think their pricing is absolutely insane in a world where even the smallest companies can colo a server and get wholesale transit that works out to <$0.005/GB. Their pricing's insane in a world where you can get prices not too far from that wholesale rate for CDN service (which is a whole different beast from having one or two colo'd servers). And anyway, nobody pushing serious bits is paying public rates, anywhere. Those discounts can be huge. In fact I wouldn't be surprised if part of the reason cloud providers have such high rates is so they can give their counterparts an easy, very impressive-looking "win" in negotiations.
- stevewatson301 4y agoOrigin shield is quite pricey; Argo tiered caching is free. (The article discusses Argo smart routing, but in my experience Argo tiered caching has lead to the same kind of performance gains this article talks about).
- is_true 4y agoThe numbers of zeros after the dot/comma (depending on your locale)
- itslennysfault 4y ago
- hnav 4y agoTLDR, adding an "edge" in front of your application incurs a connection setup cost which can be 2-3x RTT and is especially noticeable when you don't have a large QPS and are in a region like APAC where geographically close networks often have high latencies between each other. Both Argo and OriginShield seem to pool more aggressively, often going cross-datacenter to avoid hitting origin which sometimes saves this setup cost by coalescing onto warm connections, but only sometimes (notice how spiky their Argo graphs are, the p90 request is probably no faster than before).
- collaborative 4y agoSurely the cost is offset by cached responses?
- nhoughto 4y agodepending on your origin and your users, having TLS terminate / be negotiated at the edge should _reduce_ your connection setup cost, by reducing RTT time for the handshake to the end user (typically the slowest bit / longest tail). If you have 1 origin region/server and globally distributed users, in the data shown the RTT from Sydney could be 1000ms, so TLS negotiation of 3 roundtrips could be 3000ms. If you terminate TLS at the edge that could be order of magnitude less.. not more? depends on your setup though.
- hnov 4y agoThis is true, on average having an edge will be faster, but it is not a panacea for latency, especially if you don't move non-trivial QPS from every region.
- throwthere 4y agoThe conclusion is for an origin server halfway across the world from your users, CloudFront with Origin Shield is basically equivalent to CloudFlare with Argo (latency). The other takeaway is AWS documentation is kind of dodgy for some services. But basically everyone knows that already.
- caseydm 4y agoAnybody using Cloudflare to cache an API that serves JSON? Thinking about setting that up.
- yamtaddle 4y agoDepending on what you're doing with it, that may technically be against the TOS on any of their "self-serve" plans, including the paid ones. You might get away with it anyway, especially if your traffic is low, but you'd be rolling the dice.
- Matheus28 4y agoIf it's consumed by a web app, doesn't it make it okay? Otherwise any api behind cloudflare would be violating the TOS... > 2.8 Limitation on Serving Non-HTML Content The Services are offered primarily as a platform to cache and serve web pages and websites. Unless explicitly included as part of a Paid Service purchased by you, you agree to use the Services solely for the purpose of (i) serving web pages as viewed through a web browser or other functionally equivalent applications, including rendering Hypertext Markup Language (HTML) or other functional equivalents, and (ii) serving web APIs subject to the restrictions set forth in this Section 2.8. Use of the Services for serving video or a disproportionate percentage of pictures, audio files, or other non-HTML content is prohibited, unless purchased separately as part of a Paid Service or expressly allowed under our Supplemental Terms for a specific Service. If we determine you have breached this Section 2.8, we may immediately suspend or restrict your use of the Services, or limit End User access to certain of your resources through the Services.
- yamtaddle 4y agoProbably OK, but access it from Electron (let alone fully-native apps) and now you may not technically not be OK anymore—is that functionally equivalent to a web browser? Hard to say. And much of the benefit of web APIs, versus just serving pages and HTML fragments, is being able to serve those kinds of heterogenous clients, or to allow access to 3rd parties, and who knows what they might use to access it, so... yeah, you can push low-usefulness (browser-only, first-party-use-only) web APIs through Cloudflare and you're likely in the clear, but go beyond that and it gets murky fast. And even then, the web API thing is subject to the rest of the restrictions in that same section ("serving web APIs subject to the restrictions set forth in this Section 2.8") so "serving video or a disproportionate percentage of pictures, audio files, or other non-HTML content is prohibited" (emphasis mine) meaning that if too much of your traffic is JSON or protobufs or what have you, they could send you a nastygram or simply cut you off, though they might choose not to. Personally, I'd not rely on Cloudflare's free or $20 plans past MVP/experimentation or hobbyist use, precisely because the terms are restrictive and vague. Too risky. Then again, what can you expect for nothing-to-peanuts prices?
- rafaelturk 4y agoIMO Perfomance wise CloudFront and Cloudfront are quite similar. I've migrated from CloudFront+AWS WAF to just CloudFlare given Cloudflare's superior (100x better) WAF/Firewall/DDOS protection at a lower cost
- zoover2020 4y agoOut of curiosity, what makes Clousflare's WAF so much better?
- jedifans 4y agoThe ability to scan the whole of a request body rather than just the first 8kB.
- rafaelturk 4y agoCF have more options, filters, settings, realtime reports, rules and statistics.. Additionally CF ofers a good set of system managed WAF rules that you can simply active and CF will manage it for you. With AWS you're basically on your own. More or less is a bare bones WAF tool.
- aynsof 4y agoThis isn't accurate. AWS added Managed Rulesets several years ago: https://aws.amazon.com/marketplace/solutions/security/waf-managed-rules https://aws.amazon.com/marketplace/solutions/security/waf-ma...
- mkasu 4y ago> IMO Perfomance wise CloudFront and Cloudfront are quite similar. Yes I don't think the capitalization has too much impact.
- tux2bsd 4y agoHe made a typo. > Yes I don't think the capitalization has too much impact. You missed a comma.
- Drybones 4y agoI’d like to see more detailed comparisons between providers like Akamai, Fastly, CDN77, KeyCDN, StackPath, etc
- sigmaskipper 4y agoThis was probably the first article on hacker news that actually had some type of business impact for me, so thanks for posting!!! Have already added Origin Shield and it's made somewhat of a speed boost