October 2018 Summaries
25 posts from Cloudflare
Filter
Month:
Year:
Post Summaries
Back to Blog
The guest author, Manuel Meurer, discusses his experience with RubyDocs, an open-source service that generates and hosts documentation for any Ruby project. He built RubyDocs in 2013 to address the lack of similar services at the time. One challenge he faced was moving hosted docs from a subdomain to a subpath on the main domain while still benefiting from a CDN. This led him to discover Cloudflare Workers, which allowed him to proxy requests from a subpath to a subdomain without changing the RubyDocs server/CDN setup. He also used Cloudflare KV, a key-value store, to store and retrieve the latest version of each project's documentation. The author expresses gratitude to Cloudflare for supporting RubyDocs and contributing to a better internet experience.
Oct 31, 2018
1,090 words in the original blog post.
Nigeria is Africa's most populous country with 84% of its population owning a mobile device. The city of Lagos, known for its vibrancy and constant movement, has recently been connected to Cloudflare's secure facility, improving local users' connection speeds and reliability. As a mobile-first country, Nigeria is dominated by the phrase "mobile-first," with smartphone penetration growing fast. Nollywood, Nigeria's booming movie industry, produces over 1,500 movies per year and has caught the attention of Netflix. The West African region benefits from multiple undersea cables that connect to Europe and South Africa, improving inter-country connectivity at the IP backbone level. Cloudflare plans to expand its network in West Africa, including locations like Senegal, Côte d'Ivoire, and Ghana.
Oct 30, 2018
873 words in the original blog post.
Cloudflare has integrated its Spectrum service with Load Balancing, allowing traffic management of TCP connections using the same battle-tested Load Balancer that customers already use for billions of HTTP requests every day. This integration enables users to configure load balancers with TCP health checks, failover, and steering policies to dictate where traffic should flow. Health checks can be configured from multiple regions or all Cloudflare PoPs as an Enterprise customer to detect local and global connectivity issues from origins. Weights origin weights are beneficial for distributing traffic among origins of varying capacity or for unequally splitting traffic for any other reason. Steering modes available include failover, dynamic steering, and geo steering. The integration allows customers to build scalable TCP applications with minimal effort.
Oct 25, 2018
749 words in the original blog post.
On October 23, 2018, IBM announced the general availability of Cloud Internet Services (CIS) Enterprise, a significant step forward in their partnership with Cloudflare. CIS delivers security and performance to IBM Cloud customers' internet applications by integrating Cloudflare's network into IBM Cloud. This integration allows users to manage DDoS mitigation, web application firewall, smart routing, and load balancing from within the IBM Cloud user interface. The Cloudflare network is designed to handle high-volume attacks or legitimate traffic spikes with its 12x bigger capacity than the largest DDoS attack ever recorded. It can also handle modern distributed attacks targeting DNS infrastructure. This integration simplifies account management and reduces costs for IBM Cloud customers.
Oct 23, 2018
573 words in the original blog post.
On October 22, 2018, Cloudflare introduced its Peering Portal - Beta to help Internet Service Providers (ISPs) and hosting providers understand the benefits of peering with their network. Peering is a process where large networks directly interconnect to reduce bandwidth costs, improve website performance, and manage traffic more efficiently. The portal provides detailed statistics on transit data between Cloudflare and potential partners, allowing them to estimate potential cost savings, performance improvements, and available upstream bandwidth for other traffic. The Peering Portal also offers insights into time series traffic statistics, peering session statistics, prefix data, and POP relative traffic weighting.
Oct 22, 2018
912 words in the original blog post.
Cloudflare has announced support for Encrypted Server Name Indication (ESNI) TLS extension in collaboration with Mozilla. ESNI allows browsing of Cloudflare websites without leaking the plaintext SNI TLS extension to on-path observers such as ISPs, coffee-shop owners, and firewalls. To enable ESNI, users need to download and install the latest Firefox Nightly build or update their existing one. Additionally, they must enable support for DNS over HTTPS (DOH) in Firefox settings. The Browsing Experience Security Check page can be used to verify if a browser is providing a secure browsing experience by using secure DNS transport, DNSSEC validation, TLS 1.3 & ESNI. Cloudflare's test page at https://encryptedsni.com checks for these features. The Wireshark tool can also be used to see the encrypted SNI extension on the wire while visiting a website that supports ESNI.
Oct 18, 2018
1,087 words in the original blog post.
Stefan Henke has joined Cloudflare as the Head of DACH (Deutschland, Austria & Switzerland-CH) to help expand the company's demand in Germany, Austria, and Switzerland. He is excited about Cloudflare's mission to build a better internet and its focus on security, privacy, and performance for businesses and individuals. The company's global network, including data centers in seven cities in the DACH region, ensures fast, safe, and reliable internet access. Henke appreciates Cloudflare's passionate team culture and commitment to diversity. He plans to help expand the company's presence in the region by opening a new office in Munich and supporting local customers and partners.
Oct 18, 2018
571 words in the original blog post.
Lisa Retief attended the Grace Hopper Celebration (#GHC18) conference, which aimed at connecting women in technology and promoting diversity within companies. As a part of Cloudflare's team, she engaged with 22,000 attendees, held on-site interviews, and hosted a panel discussion. The event was marked by an invigorating energy among the participants, who were at various stages of their studies or careers. Lisa found it inspiring to see women in leadership positions sharing their experiences and career journeys. She also appreciated the opportunity to bond with her colleagues from different departments and locations. Overall, attending #GHC18 gave Lisa a glimpse into a future where companies can help drive positive change by embracing diversity and empowering women in technology.
Oct 17, 2018
1,137 words in the original blog post.
The article discusses website performance measurement using TTFB (Time To First Byte) and tools like cURL and Chrome. It explains how to configure cURL to measure timings such as DNS lookup, connect, appconnect, pretransfer, start transfer, total time, and size of downloaded data. It also describes the W3C Resource Timing standard used by Chrome for measurements. The article highlights that while these measurements can help diagnose problems, they may not effectively reflect real user experience on a website. To measure actual user experience, it is necessary to consider factors like loading time for images, JavaScript, and styles, as well as taking measurements from representative locations of users accessing the site.
Oct 17, 2018
747 words in the original blog post.
The author discusses how Cloudflare's Serverless Platform, Cloudflare Workers, now supports WebAssembly (WASM) within Workers. They demonstrate the process of converting a lipsum generator to use Rust and explore the developer experience. The author also highlights that WASM is not always the right tool for every task, but it serves as a good opportunity to illustrate the developer experience and tooling. They provide step-by-step instructions on how to set up the environment with wasm-pack, build with wasm-pack build, and test in a browser before uploading as a worker. The author also discusses the challenges faced while working with WASM and provides solutions for them. Finally, they share their excitement about being able to compile Rust to WASM and call it from Serverless functions woven into the very fabric of the Internet.
Oct 16, 2018
2,261 words in the original blog post.
October marks the 15th annual National Cybersecurity Awareness Month in the United States, a collaboration between the US government and industry to raise awareness about online security. This year's event is expected to have over 10,000 attendees, more than 100 events, and feature representatives from over 180 agencies, private companies, and service providers. Cloudflare is participating in D.C CyberWeek, sharing best practices, finding ways to collaborate, and working to achieve common goals. The European Union also runs a similar month-long cyber awareness campaign in October. In addition to these initiatives, Cloudflare has joined with 60 other global companies to sign on to the Cybersecurity Tech Accord, a public commitment to protect and empower civilians to take action to secure the internet. Beyond this collaboration, Cloudflare runs two initiatives designed to make the internet more secure for vulnerable groups who might lack financial or technical resources: Project Galileo and The Athenian Project.
Oct 15, 2018
777 words in the original blog post.
Optimizing HTTP/2 performance requires good support for resource prioritization across the networking stack. This article discusses interactions between web servers, Operating Systems, and networks, and how to tune a server for optimal end-user performance. On Linux 4.9 kernels and later, enabling BBR congestion control and setting tcp_notsent_lowat to 16KB can improve HTTP/2 prioritization reliability. Proper resource ordering can significantly speed up page rendering, especially on slower connections. Tuning for TCP_NOTSENT_LOWAT of 16KB and using BBR congestion control can help reduce buffering and improve end-user performance with HTTP/2.
Oct 12, 2018
2,952 words in the original blog post.
National Coming Out Day is celebrated on October 11th every year to promote a safe world for lesbian, gay, bisexual, transgender, queer and questioning (LGBTQ) individuals to live truthfully and openly. This day marks the anniversary of the 1987 march in Washington for Lesbian and Gay Rights. On this occasion, Proudflare shared seven coming out stories from its members. These stories highlight the importance of being true to oneself and the support that can be found within families and friends. The Human Rights Campaign provides resources for those who are thinking about coming out or wish to be supportive of those who come out to them.
Oct 11, 2018
2,222 words in the original blog post.
Graceful upgrades allow for the seamless replacement of a process's configuration and code without disruption, a necessity in environments lacking load balancing layers, such as Cloudflare. This process involves complex systems programming, with solutions like using the Go library tableflip, which Cloudflare plans to open-source. Graceful upgrades ensure that neither the listening socket is removed nor connections are dropped during code updates. Traditional methods like the Exec() function or using the SO_REUSEPORT flag have limitations, such as the inability to reverse the Exec() call or the risk of orphaned connections with separate sockets. Instead, models like NGINX's, which utilize a process-per-core approach along with a primary process to manage socket sharing during upgrades, offer a robust solution. This method ensures that only one upgrade is active, the new process can safely crash during initialization, and no old code persists post-upgrade. Despite existing libraries like tablecloth, beego/grace, and facebookgo/grace, none fully met Cloudflare's requirements for flexibility beyond HTTP protocols, prompting the creation of their library, tableflip, which facilitates NGINX-style upgrades in Go applications.
Oct 11, 2018
1,677 words in the original blog post.
Cloudflare has introduced its latest generation server, the G9, which features 192 Intel Skylake CPU cores and is designed for efficiency in handling high volumes of internet traffic. The company has made significant progress over the past five years in engineering and developing its tools with the latest technology. The G9 server represents a major upgrade from the previous G4 server, offering increased compute density and improved performance per watt. Key hardware components have also been upgraded for better balance and scalability.
Oct 10, 2018
1,952 words in the original blog post.
On October 10, 2018, Garrett Galow discussed the challenge of managing user access to SaaS applications as the number of services grows. He highlighted how adopting identity services allows companies to centralize employee authentication and mentioned Cloudflare Access's role in this process. The blog announces support for enterprise customers to use single sign-on (SSO) through their identity provider to access the Cloudflare dashboard, ensuring that customers can apply the same authentication policies as other critical resources. SSO is built using Cloudflare Access and Workers, with configurations managed through Access, supporting the same identity providers available in Access today, including SAML. The integration of SSO for all Cloudflare employees ensures uniform enforcement of multi-factor authentication policies for services protected by Cloudflare itself. Enterprise customers can reach out to their Customer Success Manager to learn how to start using SSO for the Cloudflare dashboard.
Oct 10, 2018
452 words in the original blog post.
Jacob Hands, creator of FactorioMaps.com, shares his experience building a community site for the game Factorio focused on sharing user creations as interactive Leaflet maps. He chose Backblaze B2 over Amazon S3 and Google Cloud Storage due to its free upload API calls, $0.00/GB egress bandwidth to Cloudflare, and lower storage costs. To improve site speed, Hands added a local SSD cache on the VPS for all except the last 1-3 zoom levels of each map, reducing latency for 66% of requests. He then implemented Cloudflare Workers to run JavaScript path rewrites and redirects, further enhancing performance. By using Google Cloud Storage (GCS) for the first few zoom levels and Backblaze B2 for the rest, Hands achieved a mean latency of <350ms for 66% of requested files while only storing 24% on GCS. He also utilized Cloudflare's Argo to reduce latency by over 50% for non-US/CA users.
Oct 10, 2018
986 words in the original blog post.
Cloudflare has released a beta command line tool to help teams transition from using VPNs to their more secure solution, Access. The new tool, called cloudflared, allows users to access server endpoints and APIs protected by Cloudflare Access directly from the command line without needing to authenticate each time. This enhances security while also improving efficiency for team members. Additionally, granular policies can be created to control who can reach specific API paths or sensitive data. The tool is currently in beta and does not yet support automated scripting or service-to-service connections.
Oct 05, 2018
869 words in the original blog post.
Cloudflare has launched a new feature called Firewall Rules, which provides customers with fine-grained control over their incoming requests. This feature is designed to help keep applications safe by allowing users to create more complex and flexible firewall rules that can match multiple attributes such as IP address and user-agent. The Firewall Rules engine consists of two components: matching and action. Matching allows users to define filters based on various properties of the HTTP request, while action determines what Cloudflare should do when a filter is matched. This feature also introduces pattern matching using Regular Expressions directly through the dashboard and API.
Oct 03, 2018
1,431 words in the original blog post.
Cloudflare has expanded its network into Mongolia by establishing a data center in Ulaanbaatar, significantly reducing latency and improving capacity for both mobile and broadband customers within the country. The process of setting up this new data center involved negotiation with local partners, ensuring security compliance, managing logistics, coordinating hardware shipping, configuring network hardware and servers, and addressing any networking issues that arose. This expansion not only enhances Cloudflare's global reach but also allows users in Mongolia to access all of the company's services and products instantly.
Oct 03, 2018
1,444 words in the original blog post.
This article discusses how to set up low-cost load balancing using Cloudflare Service Workers. It provides code examples for various scenarios such as random routing, fallback strategy, and geographic routing. The author also demonstrates combining these techniques into a single worker. The article assumes a basic understanding of JavaScript, which is used to write Cloudflare Workers.
Oct 03, 2018
749 words in the original blog post.
Cloudflare has developed a plugin that enables Single Sign-On (SSO) functionality for its hosted Atlassian tools, including Jira and Confluence. The plugin allows users to log in with their identity provider credentials, which are then mapped to user accounts within the Atlassian applications. This eliminates the need for an additional set of credentials specific to Atlassian tools, making access more convenient on both desktop and mobile devices. Cloudflare is also working with partners to expand JWT-based authentication support for other products. The company has made its SSO plugin code public so that users can review it before installation.
Oct 02, 2018
1,157 words in the original blog post.
Cloudflare is launching a bold new campaign aimed at communicating the scope of its mission to an ever-growing audience. The company, which has a global cloud network and helps build a better internet by making it faster, more reliable, and secure, is starting to experiment with provocative messaging in various formats such as wild postings, bus wraps, billboard placements, and digital takeovers. The campaign will initially be tested in San Francisco and New York City, as well as on US national publications' digital versions, social media, and other digital channels.
Oct 02, 2018
667 words in the original blog post.
Cloudflare has announced support for WebAssembly (WASM) in its Cloudflare Workers, allowing users to augment their applications with WASM at no additional cost. WebAssembly is a technology that extends the web platform to support compiled languages like C, C++, Rust, Go, and more. It can be much faster than JavaScript for certain kinds of resource-intensive tasks where JavaScript is not a good fit. With this addition, users can now use a wide range of languages in Cloudflare Workers, which lets them deploy "serverless" code directly to Cloudflare's datacenters. WASM is particularly useful for performing resource-hungry, self-contained operations like resizing an image or processing an audio stream.
Oct 01, 2018
811 words in the original blog post.
At the Cloudflare Internet Summit, John Graham-Cumming interviewed Sophie Wilson, who designed the ARM processor instruction set in the 1980s and contributed to the development of the BBC Micro computer. Despite the success of ARM, Graham-Cumming focused on the simplicity and efficiency of the BBC Micro, which allowed users to write and run code instantly. He emphasized that programmers prefer tools that minimize distractions and enable seamless transitions from brain to CPU. Virtual Machines, Containers, and serverless platforms like Cloudflare Workers have been developed to address these needs. With the release of WebAssembly on the Cloudflare Workers platform, developers can now write code in any language that compiles to WebAssembly and deploy it globally within seconds.
Oct 01, 2018
874 words in the original blog post.