Every source behind this page, graded. GitHub rows were fetched in full in
this session; the rest were retrieved through in-session search, as section 1 explains.
Filter by kind.
Postmortem
Cloudflare2025-11
Cloudflare outage on November 18, 2025
A data deploy as an outage mechanism, end to end: a permissions change upstream,
duplicate rows, a file past a preallocated limit, a panic. The only document here that
compares two proxy generations failing on the same input.
Carry forwardValidate generated config at publish time, and make the consumer fail open to last-known-good.
https://blog.cloudflare.com/18-november-2025-outage/
Postmortem
Cloudflare2025-12
Cloudflare outage on December 5, 2025
The sequel, seventeen days later, and the most useful document here: Cloudflare names
which safeguards were not yet in place, namely versioning and rollback, break-glass, and
fail-open handling of configuration errors.
Carry forwardAfter an incident of this class, freeze the channel rather than the individual change.
https://blog.cloudflare.com/5-december-2025-outage/
Postmortem
Cloudflare2019-07
Details of the Cloudflare outage on July 2, 2019
The origin of the pattern: a managed WAF rule skipped progressive deployment by design
and a backtracking regex saturated CPU worldwide. The 2019 remediation list and the 2025
one are the same list.
Carry forwardBound the resources any shipped rule can consume in the request path.
https://blog.cloudflare.com/details-of-the-cloudflare-outage-on-july-2-2019
Postmortem
Cloudflare2025-07
Cloudflare 1.1.1.1 incident on July 14, 2025
The best published example of a latent configuration error: planted 6 June with no
effect, activated five weeks later by a test location added to an unrelated
non-production service. Route restoration alone did not recover service.
Carry forwardValidate config against the whole topology at write time; an inert change is a dated incident without the date.
https://blog.cloudflare.com/cloudflare-1-1-1-1-incident-on-july-14-2025
Postmortem
Cloudflare2023-11
Post mortem on the Cloudflare Control Plane and Analytics Outage
A utility event at one third-party facility removed the control plane and analytics for
two days while the data plane kept serving. The honest part is the admission that
failover did not work as expected.
Carry forwardRate the control plane by what you need during an incident, not by whether it serves traffic.
https://blog.cloudflare.com/post-mortem-on-cloudflare-control-plane-and-analytics-outage
Postmortem
Cloudflare2022-06
Cloudflare outage on June 21, 2022
A BGP policy change with misordered statements deleted required prefixes in 19 of the
busiest locations, which were exactly the sites already migrated to the newer resilient
architecture.
Carry forwardA resilience migration concentrates risk in the migrated set until its rollout tooling matures.
https://blog.cloudflare.com/cloudflare-outage-on-june-21-2022
Postmortem
Cloudflare2020-07
Cloudflare outage on July 17, 2020
A congestion fix in Atlanta routed all backbone traffic to Atlanta. Useful as the
clearest statement that configuration blast radius in a network is set by routing, not
by the operator's intent.
Carry forwardSimulate path-selection changes against live topology before commit.
https://blog.cloudflare.com/cloudflare-outage-on-july-17-2020
Postmortem
Logto2025-06
Postmortem, June 12, 2025
The most instructive non-Cloudflare document here: this customer's Worker cached region
mappings in Workers KV and threw errors rather than falling back when KV went away.
Carry forwardA cache that throws on miss is a dependency. Exercise the uncached path in production.
https://blog.logto.io/postmortem-june-12-2025
Postmortem
Squiz2025-06
Service degradation: all services behind Cloudflare
Independent record of the Workers KV incident: Cloudflare's statement that part of the
storage was backed by a third party, and a customer impact window running hours past
Cloudflare's resolution time.
Carry forwardYour provider's resolution timestamp is not your recovery time; measure your own.
https://status.squiz.cloud/incidents/ly6brlc1jm78
Source
cloudflare/pingora2026-02
Issue #805: replace excessive .unwrap() calls with robust error handling
Argued nine months before the November 2025 outage demonstrated the class: unwrap in a
long-running proxy leads to unrecoverable panics. Proposes Result returns and Clippy's
unwrap_used lint. Closed with no visible reason.
Carry forwardEnforce no-panic in input-parsing code with a lint, not with review.
https://github.com/cloudflare/pingora/issues/805
Source
cloudflare/pingora2026-06
Issue #921: avoid panics by removing unwraps in HttpPeer and HttpHealthCheck
The same class, still open, with a concrete trigger: an unreachable DNS server panics a
worker through unwrapped to_socket_addrs(). PR #920 open, so the argument is
unresolved rather than settled.
Carry forwardConstructors that can fail must return Result, especially in health-check paths.
https://github.com/cloudflare/pingora/issues/921
Source
cloudflare/pingora2026-09
Issue #1023: panic in a trace! call on non-UTF-8 bytes
Third instance of the class in ten months, and the most pointed: the panic is in the
logging path, so observability code can kill the request it is describing.
Carry forwardDiagnostics must be the most defensive code in the system, not the least.
https://github.com/cloudflare/pingora/issues/1023
Decision
cloudflare/pingora2024-10
PR #336, closed unmerged: rustls at compile time
A large external TLS refactor, marked do-not-merge at the maintainer's request,
reimplemented internally, then closed as merged. Stated reasons: review size and
limiting "how fast the library changes for production users".
Carry forwardRead an open-sourced component as downstream of an internal one unless the project says otherwise.
https://github.com/cloudflare/pingora/pull/336
Decision
cloudflare/pingora2026-07
RFC #937: a Proxy-WASM dynamic filter subsystem
Six years after Cloudflare left Lua for Rust, a contributor proposes hot-loadable
WebAssembly filters so operators can ship proxy logic without recompiling. Open,
unanswered, and exactly the code-versus-config boundary this guide is about.
Carry forwardRuntime-loadable logic buys deploy speed and re-imports the blast radius you removed.
https://github.com/cloudflare/pingora/issues/937
Source
cloudflare/pingora2026-10
pingora README and docs/user_guide/graceful.md
The scale claim (40M+ requests per second) and the code-release protocol: the new
instance takes the listening socket on SIGQUIT so no request sees a refused connection.
A designed hand-over for code, with no documented counterpart for config content.
Carry forwardCompare the care in your release path with the care in your config path; the asymmetry is the finding.
https://raw.githubusercontent.com/cloudflare/pingora/main/docs/user_guide/graceful.md
Source
cloudflare/workerd2026-10
workerd README
States that the published runtime "does not contain suitable defense-in-depth against
the possibility of implementation bugs" while the hosting service adds many more layers:
a candid statement of the gap between an open artefact and its service.
Carry forwardSelf-hosting a vendor's runtime inherits its features, not its operational hardening.
https://github.com/cloudflare/workerd
Source
cloudflare/quiche2026-10
quiche README
HTTP/3 at the edge is served by this library, separate from the open-source proxy. Read
alongside pingora issue #95, open since March 2024, asking for HTTP/3 support.
Carry forwardProtocol support in a vendor's service tells you nothing about its open components.
https://raw.githubusercontent.com/cloudflare/quiche/master/README.md
Eng blog
Cloudflare2022-09
How we built Pingora, the proxy that connects Cloudflare to the Internet
The rewrite rationale, and it is not per-request speed: NGINX's per-worker connection
pools meant a request could only reuse connections held by its own worker, producing
redundant handshakes at their volume.
Carry forwardFind the structural constraint before rewriting; "faster" is rarely the real reason.
https://blog.cloudflare.com/how-we-built-pingora-the-proxy-that-connects-cloudflare-to-the-internet/
Eng blog
Cloudflare2020-04
Introducing Quicksilver: configuration distribution at Internet scale
Why the previous store was replaced from 2015, plus the measurement that matters most
here: config read p99 degrades from about 9 ms to about 701 ms with two concurrent
writers, so distribution competes with serving.
Carry forwardConfig distribution is a tier-zero dependency with its own saturation curve, not background work.
https://blog.cloudflare.com/introducing-quicksilver-configuration-distribution-at-internet-scale/
Eng blog
Cloudflare2026
Quicksilver v2, part 1, and Workers KV Instant
Full replication to every server became too expensive, and the replacement reports a
p99 write replication of 256 ms to over 300 locations against 4.38 s for the older mode.
Faster, after three propagation outages.
Carry forwardIf you cannot slow propagation, the only remaining controls are at the content boundary.
https://blog.cloudflare.com/quicksilver-v2-evolution-of-a-globally-distributed-key-value-store-part-1/
Eng blog
Cloudflare2020-09
Unimog, Cloudflare's edge load balancer
The uniformity statement that explains the blast radius of everything else: inside a
data centre any server can handle any service on any anycast address. An eBPF and XDP
layer 4 balancer whose control plane generates the forwarding tables.
Carry forwardFleet uniformity is an efficiency win that deletes your natural bulkheads; add them deliberately.
https://blog.cloudflare.com/unimog-cloudflares-edge-load-balancer/
Eng blog
Cloudflare2018-11
Cloud Computing without Containers, and Containers on the Edge
The isolate decision and, in the companion post, its honest cost: the tooling ecosystem
for isolates was young. Together, the clearest statement of when the choice flips toward
containers.
Carry forwardPick the isolation unit by start-up cost and per-tenant memory, then budget for the ecosystem you give up.
https://blog.cloudflare.com/cloud-computing-without-containers/
Eng blog
Cloudflare2023-03
Oxy is Cloudflare's Rust-based next generation proxy framework
Names the production framework FL2 is built on, which is how you know Pingora is not
the thing applying your WAF rules.
Carry forwardIdentify which of a vendor's several proxies is actually in your path before reasoning about its failure modes.
https://blog.cloudflare.com/introducing-oxy/
Eng blog
Cloudflare2024-11
How we prevent conflicts in authoritative DNS configuration using formal verification
The company does validate configuration formally, with a custom Lisp-like language and
a verifier built on Racket and Rosette, for DNS. Nothing in the record extends the method
to rule files or feature files.
Carry forwardConfig verification applied to one subsystem is a capability, not a policy; name the other subsystems.
https://blog.cloudflare.com/tag/formal-methods
Eng blog
InfoQ2025-10
Cloudflare's Rust rewrite of its core proxy
The migration shape: new Rust modules hosted inside the old NGINX and OpenResty proxy,
to avoid two copies of product logic. Motivation given as time lost to LuaJIT bugs and
unsafe Lua.
Carry forwardHosting the new runtime inside the old one avoids duplication and keeps both failure modes live for years.
https://www.infoq.com/news/2025/10/cloudflare-rust-proxy
Eng blog
Gavin Howard2025-12
Piecemeal formal verification: Cloudflare, Java exceptions and Rust mutexes
The dissenting read: large organisations will not adopt formal methods wholesale, but
should on their most critical paths. Included because it disagrees with the conclusion
that better process alone is the answer.
Carry forwardPick the two or three paths where a wrong value is catastrophic and verify those, not everything.
https://gavinhoward.com/2025/12/piecemeal-formal-verification-cloudflare-java-exceptions-and-rust-mutexes
Paper
Cloudflare Research2024-08
Topaz: Declarative and Verifiable Authoritative DNS at CDN-Scale (SIGCOMM)
Imperatively generated query-to-IP maps hide nameserver behaviour when objectives
conflict; encoding objectives as policies in a formally verified DSL catches conflicts
before deployment. Runs at roughly one million queries per second.
Carry forwardWhere config is generated by a program, verify the program's intent, not just the output's syntax.
https://research.cloudflare.com/publications/Larisch2024
Case study
ThousandEyes2025-11
Cloudflare Outage Analysis: November 18, 2025
The only independent view in this corpus of how a global config failure looks from
outside: not regional, and not a clean on-off.
Carry forwardBuy or build an outside-in measurement, because your own telemetry rides the thing that is failing.
https://www.thousandeyes.com/blog/cloudflare-outage-analysis-november-18-2025
Talk
Kenton Varda, QCon and InfoQ2018-2019
Fine-grained sandboxing with V8 isolates
The isolate architecture defended by its author: multi-tenancy without VMs or
containers, with claimed cold starts 10 to 100 times faster. No timestamp, because the
recording could not be opened in this session.
Carry forwardThe isolate bet is a bet on per-tenant memory; model that number before choosing.
https://www.infoq.com/presentations/cloudflare-v8
Talk
Cloudflare TV2020-2021
Quicksilver: Configuration Distribution at Internet Scale
A session on the configuration distribution system itself, listed because the mechanism
is central to this guide's argument. The recording could not be opened in this session,
so no claim rests on it.
Carry forwardWhen a vendor gives a talk about its config plane, that plane is load-bearing enough to ask about.
https://cloudflare.tv/event/3U5jrbEysk9yNFCPDwuCik