5 ms·
CloudFlare free-tier is incredibly useful for sticking in front of the cheapest bargain basement VPS WordPress host you can find and miraculously still ending u
by 22c 3y ago
CloudFlare free-tier is incredibly useful for sticking in front of the cheapest bargain basement VPS WordPress host you can find and miraculously still ending up with a somewhat functional small-business website.
It'd be even better if there were competition in this space, but there aren't too many options outside of cloud providers who are likely relying on the fact you might accidentally slip up one day so they can charge your credit card.
- sph 3y agoWith all the politeness and calm I can muster: you do not need Cloudflare for your small-business website. Again: you do not need Cloudflare for your small-business website. Do you have any idea of how many requests can a shitty unoptimised website serve on commodity hardware? Judging by comments like yours, which seem to be the majority, I wonder if anyone with less that 15 years of experience is still able to write a website serving 10k users a day (1 request every 8 seconds) on a 2 core VPS without needing a CDN. Let me spoil the black magic only greybeard seem to know: STOP. OVERENGINEERING. You don't need Cloudflare. No one cares about DDosing your website, you're not Reddit for Heaven's sake. If you overengineer, at least quit all rushing to give your custom to the same company, making Cloudflare a de facto monopoly.
- bombcar 3y agoPeople stick cloud flare on the front less for the CDN/DDoS protection and more for the web application firewall, because their small business website is almost certainly some incredibly out of date Wordpress install with more vulnerabilities than you can shake a stick at. Wordpress should integrate one of those "Wordpress to static site" plugins as the default because that's all 80% of the users need.
- 22c 3y agoYes and let's also not put it past an unscrupulous operator to be willing to pay a few dollars online to take down the website of one of their small-business competitors. It can and does happen. Folks pointing out that their Raspberry Pi self-hosted static site résumé can handle 500 requests per second are missing the point.
- xp84 3y agoSeriously. The Wordpress approach of dynamically composing every page server-side made sense: * Before AJAX made personalizing the 'logged-in experience' easy even on a mainly static site * When CPUs were so slow that regenerating, say, 1000 static HTML files just because you updated your footer or your "top stories" sidebar would take an annoying amount of time instead of what, 4 seconds now? * Before spambots essentially made it impossible to host a comments section, and Disqus and the Facebook plugin became the defacto choice for anyone still brave enough to try. Due to the above, I can't imagine using PHP or even some sexier-today technology to dynamically just-in-time assemble HTML pages that 99-100% of the audience will be viewing statically.
- francisofascii 3y agoUsing a CDN is actually the opposite of overengineering. Using a CDN is an easy, low cost way to outsource any performance concerns. Overengineering is trying to handle all the potential performance issues yourself, with custom caching, database indexes, code optimization, better hardware, etc. For many sites it is simply an insurance policy. Most drivers don't need auto insurance, until that one day you do.
- mattferderer 3y agoExactly this. The amount of cost & time to make a (WordPress/Drupal/random database backed CMS website) site run well on a cheap VM is significantly higher than Cloudflare's free & paid options. Those aren't my first choice in CMS these days but a lot of the small business web still run them & migrating isn't cheap from a technical or user training perspective. If you happen to have a popular CMS like WordPress on a cheap VM, odds are you are going to get DDoS all the time, even if you only have 100 legit views/day. Cloudflare will reduce this dramatically. I would guess any site not using Cloudflare (or someone similar) is more likely overengineering. As always though, every case is unique & it depends.
- johnklos 3y agoAbsolutely bull poop. First, setting up anything using some third party service like Cloudflare is already too much work and doesn't even work for many people in parts of the world Cloudflare has determined are undesirable. Second, I can, have and do host popular CMSes on hardware much more modest than Raspberry Pi performance. Third, "odds are you are going to get DDoS all the time"? Are you a Cloudflare shill? This is nothing but wildly hyperbolic. In a quarter of a century of hosting, I've had to deal with one specific DDoS actor. One. How are you going to claim that "odds are you are going to get DDoS all the time"? Go ahead, provide evidence, although I'm sure you can't and won't.
- mattferderer 3y agoNot sure how using Cloudflare is more work than setting up your own LAMP VM or installing WordPress on a SaaS even. People put up fake WordPress logins as honey pots. I'm not sure what to say to this. If you host a WordPress site you're going to get lots of traffic trying to take your website down unless your provider is helping you block it. If you go outside on a summer day, the sun is going to be shining. I have never had a WordPress site that didn't get a ton of bad traffic. If it lived on a cheap VM with a MySQL database, PHP & WordPress, it was going to be under stress at least a few times a year. Tossing Cloudflare on it takes less than 10 minutes & a few years ago was the 1 of the easiest/cheapest ways to get SSL on it. In my quarter of a century of hosting, I have had a lot of DDoS attacks & none of those sites got over 100k legit users a month. Most also didn't care about users outside their own country. It doesn't matter to me if you use Cloudflare or someone else. I don't make money off it but I will admit it is one of my favorite providers by far. I do also really like how the executive team is personal, handles themselves online & reaches out to devs.
- datavirtue 3y agoOur company was knocked offline by a DDOS attack. It continued all day unabated until we signed up for a free cloudflare account. That was easy. Flash forward about 8 years and I find myself using cloudflare to stave off the immense suffering of Azure/AWS by using R2 and Pages. As soon as more people find out how easy Cloudflare is and how much it can lube a product deployment, I expect a lot more of the internet to end up there by choice. Cloudflare deployed my app better/easier than Microsoft was able to deploy it to Azure (Microsoft owns GitHub and Azure and still didn't have their shit ironed out...Cloudflare just works). I had to tweak them both but Azure took hours and cloudflare was a quick, cleanly documented change. I wish they offered a service to host my nodejs APIs.
- mattferderer 3y agoI like Azure, GitHub, AWS for a lot of things but Cloudflare has it's niches that are just better. I haven't read into why Open AI uses Cloudflare instead of Azure services but I find it very interesting considering their Microsoft arrangement.
- rs999gti 3y ago> STOP. OVERENGINEERING. Please tell this to every junior/cloud developer/architect when it comes to microservices.
- sophacles 3y agoOn the other side of the coin - launching an attack that would overwhelm that vps has never been easier. Even if you're serving static pages and your 2 cores can fill the 10G nic with compute to spare, the pipe can be filled with enough inbound garbage that legit requests have their packets dropped. This isn't that hard in 2023. There are dozens of booter services for hire, and if you really are scraping the bottom of the barrel of hosting, some pissed off kid can probably convince their discord buddies to generate enough traffic to knock your site over.
- jbotdev 3y agoFortunately there are so many cheap options nowadays for fully managed small-business websites which include all the CDN/WAF stuff for you (Squarespace, managed WordPress, etc.). The setup/maintenance time for running your own web server doesn’t make sense unless you already have an “IT” person on the payroll.