What is cloudflare's endgame for investors? For some reason I don't think there are enough enterprise customers for cloudflare to become a multi billion dollar company.
I love cloudflare and am a happy customer but I'm really interested to know what these investors are thinking before they put up 100s of millions in investment.
I agree, but I think there's an implicit additional $100MM investment in CloudFlare, for qualifying companies.
This seems analogous to when FB neutered FP Games from NewsFeed, Zynga took a nosedive and Zynga didn't seem to thrive outside of the FB App ecosystem.
What is cloudflare's endgame for investors? For some reason I don't think there are enough enterprise customers for cloudflare to become a multi billion dollar company.
Why not?
Also, Cloudflare has literally millions of web sites, APIs, applications using it. We are not limited to enterprise deals at all.
There's no lack of governments and non-governments who'll gladly pay for access to the plaintext web traffic hitting the literally millions of web sites, APIs and applications on CloudFlare.
"At its core a Cloudflare app is set of JavaScript and/or CSS files which run on a website, and an install.json file which instructs tools like Cloudflare Apps how to use those files."
Sounds like all of your code executes in the browser then, somewhat like tampermonkey user scripts or basic browser web extensions.
Your "code" looks VERY similar to the code you would write for a chrome web extension. The delivery mechanism for the code is the MITM capability...looks very much like edge-side-includes.
This is the result of Cloudflare's eager.io acquisition. You might remember eager from some of their really awesome blog posts on the histories of various techs [1][2].
EDIT: a little pre-debate warmup for anybody that wants to get into it. Point 1: Users have the right to block. Counter-point: Content provider have the right to deny access. Point 2: Ads are bad for users. Counter-point: there is none, ads are bad for users.
It's super tempting to label something "noadblock" because it sounds like money to publishers (I know this because I've been trying like crazy to get publishers to use proxy level middleware), but you're right.
The reality is, you can inject advertisements into content at the proxy level that are better for peoples' privacy, keep pages fast, and are less disruptive for readers.
The thing is, publishers have a ton of unsellable inventory that you can blame on ad blockers, but it's really the end result of shitty advertising and privacy overreaches. Doing better ads will get them around ad blockers, but doing better ads from the beginning may have prevented the rise of ad blockers at all.
Actual counter-point: blocking all ads is shortsighted. As more and more people do it, the sites you are currently blocking from showing you ads will have to switch to a paid model, with many probably failing.
Only a select few news sources will survive. Local news in non-metropolitan areas will be even worse than it is now. People will start consuming news exclusively from the one or two (maximum) sources they pay for, whereas now they probably read at least one article from 50+ sources every month.
Elections will happen, but very few people will actually have enough information. All political oversight will seize, because actual behaviour is no longer tied to re-election. But, at least, most politicians will have very nice names.
Alternative scenario: smart blocking: start with allowing all, then blacklist individual ads based on the publisher, content/behaviour of the ad, and reputation of the ad network. That would incentive ads to actually get better.
I'm glad you replied; I'm interested in this debate.
I agree that content monetization is an important problem that ought to be solved in order to maintain quality of information.
I disagree that current advertising models have elevated the quality of content. Fake news websites (literally - a made-up .coms that have BS stories, the equivalent of tabloids) exist specifically because advertising monetizes clicks/eyeballs, and so clickbait is the optimal strategy.
I disagree that moderating ads will produce better ads, because I believe ads run counter to a well-functioning information system. An example: HN is an information system that's designed to put high quality links in front of the user. A paid placement makes it possible to skip the votes mechanism, thereby skipping the system's regulatory structure. If your link deserves to be at the top, it will get there the same way all other links do.
I disagree that advertising or paywall are the only two options, though I will concede those are the only two that have happened so far.
I'd be very wary about investing my time and resources on a platform with such a corrupt CEO. Just a few months ago he was blatantly lying* about the massive security issues they were having.
Most likely relying on second-hand info that was just wrong. I doubt he based that post entirely on searching the caches himself. That whole incident was a mess though, tying up a lot of peoples' time who didn't work for CloudFlare. Centralization of services is always painful when things go wrong, and that may be a reason to avoid CloudFlare.
The only other beef I can think of against CloudFlare is how they play both sides of the DDoS game, hosting the sites selling them (free speech!) and charging the victims for protection.
PS. CloudFlare does deserve some flak / second thoughts for the whole Cloudbleed thing, but I don't think your response is quite on target.
He might not have known it was second-hand info, or could have been led to believe it was good info from a good source (we'd need the message that led him to believe that thing -- and publicly throwing a subordinate under the bus for giving you bad info will obviously not go well).
I would differentiate that from lying, and fairly, he gets to deal with the consequences either way because he is the CEO.
The moment CF stops hosting DDoS websites is the moment the censorship will burst wide open. Besides CP (which is too hot to try to defend), as soon as they start judging which businesses are allowed to host then they'll be forced to restrict their offerings all around.
What if a booter site advertises itself and says "you must confirm you have legal authority to run an attack test against this site"? What if it's legal in <some jurisdiction>?
CF should only take down sites after getting a direct court order to stop services (even then jurisdiction is an issue).
Most likely relying on second-hand info that was just wrong.
I would have been happy to give him the benefit of the doubt and still would. To me it seems to me he continually repeated these claims over the whole incident and ignored people who pointed out that what he was saying was obviously false. I only pointed to the most egregious example.
To be clear, I'm not super worried about companies just screwing up, shit happens. However, I have a personal bias against dealing with people who are dishonest when that happens.
To me, only passingly familiar with what happened, your initial comment left out too much of the detail you added later (specifically, the repeated part).
If I ever become CEO, remind me never to post online ever. People hang on every dinky statement, take it for gospel, and then try to burn your house down with it.
When Anonymous ran some anti-ISIS operation, they accused CloudFlare of "hosting" dozens of pro-ISIS sites[1]. It turns out Anonymous was entirely wrong about the CloudFlare customer sites (confirmed by DHS) and hypocritical (because CloudFlare tried to remain content-indifferent and, as such, protects lots of Anonymous sites). But their image took a spanking for it in the news, despite (1) investigating the claims, (2) contacting DHS to confirm they were in the right, (3) having a rational counterargument (even if it wasn't as simply as "TERRORISTS!!!!1!!1one").
Remaining quiet isn't the solution either. @eastdakota was actively corresponding with the HN community while his security+product teams were actively mitigating the "CloudBleed" damage.
Sometimes you will lose the news cycle, even if you are in the right and did everything right as a company should.
Yeah, don't underestimate how annoying stuff is for most people. Even partially technically-aware users are right to prefer some easy click-n-add system vs getting into details themselves. Though I'm not sure how much those users intersect with Cloudflare users...
The use case is probably not around maps but more around ads. Say you have a web project using cloudflare. There can be a single button on cloudflare called "monetise" which injects ads into the page.
Additionally I've seen that major media sites use analytics services for tagging and have a way via the tagging tool to inject javascript.. This is a pretty terrible idea but allows the tagging changes to not be coordinated with site changes as usually a different team controls the tagging. Cloudflare would be able to provide another way to inject custom analytics / tracking into pages.
How? Cloudflare doesn't host (and makes a big deal of that point); the actual app backends need to be hosted somewhere. They partner with Google (connectivity between CF and GCP), which is in the same business as AWS. A more likely reason is AWS's own anti-DDoS offering, AWS Shield.
From the looks of the demo it looks like you instruct CloudFlare to inject some code, e.g. embedded google maps into a website at a location in the DOM.
How is that different from the website owner from just putting an embed link in their website and updating the site?
Or is the idea you can add/remove these things dynamically through the CloudFlare web interface without having to touch any code?
You can get a good idea of how it works by clicking through some previews, you don't have to actually use Cloudflare yet to preview apps on a site: https://www.cloudflare.com/apps/
Or is the idea you can add/remove these things dynamically through the CloudFlare web interface without having to touch any code?
Yes. There is a fancy preview thingy which lets you visually choose where to inject the element into the DOM, and a configuration UI which supports things like provisioning OAuth credentials for APIs, etc. No code needed (on the part of the site owner; code is written by app publisher).
We will bill the user as a part of their normal Cloudflare bill, beginning on the first of the next month (prorated based on when they installed the app). We will then send you your ~70% cut via our payment provider who supports a wide variety of transfer methods.
You almost seem like you're trolling, but to clarify in case anyone else doesn't get it:
This is a low friction app ecosystem with 70/30 rev share[1] for what CloudFlare claims is 6m+ websites. Also, their VC are also willing to back companies in their app ecosystem, too.
I guess my main confusion is that I don't understand the audience who would benefit from these apps. I imagine one member of the audience is someone who runs a popular blog and want to add a widget but don't want to copy and paste code.
A quick search on Google would solve my problem, or I'd hire someone on eLance to make the change for me instead of paying a monthly subscription for an app.
I'm a lead engineer on the Cloudflare Apps team and I'd love to answer any questions. Cloudflare has been working on building apps into our platform for over six years, and I've personally been working on this codebase for over three (1200 days exactly today in fact).
The initial goal of Apps is to make it possible for everyone to use all the tools technical people find and use on Github and npm everyday. Our long term goal is to make it possible for developers to make a living building tools which make the web better. As an engineer myself, the moment I will personally enjoy the most is when a developer makes $1MM on the store meaning it has truly changed their lives. That will be when this experiment is proven a success and we can't wait!
If anyone doesn't know Eager was the company Adam Schwartz and I founded in 2014 which became the current version of Cloudflare Apps.
The challenges are probably pretty obvious, you have to take this codebase and application which were meant to live on its own and conform it to the way another system works. In the process you have to adapt your deployment, auth, style, etc. to work in this alternative reality. At times it can seem like you spend months working just to get back to the feature set you started with. At others you get to see the vision of an integration you sketched on a whiteboard six months ago become reality and you're blown away that this crazy idea could ever actually work. The definition of 'you' also changed a lot in that process, we went from being a small team to getting support and assistance from dozens of passionate people. It's a very different world where your resources can scale to your vision, instead of having to compromise what you want to build at every turn.
Particularly when you work at a company with as sweeping a vision as Cloudflare, you also get a chance to expand your vision itself. At Eager it was a romantic dream to think we would get on a hundred thousand sites. With our launch today we reach six million. The idea of a $100mm apps fund, or having 60 apps in the store before we even launched, were not things which startup-Eager could have pulled off.
My biggest surprise is gonna be a little silly but it's it's when someone builds a really great app without any help or guidance. As much work as you put into the API or docs it's always a little shocking when someone builds something from scratch on the platform you work on every day, and it works well, out of the box.
This headline made me think that Cloudflare had finally done what I first assumed Akamai did back in the noughties, before I learned they didn't really have magic tech. :/
Anyway: here's some indirect feedback. It doesn't really apply to your project
(which I'm sure will be super useful to other people). I would expect Cloudflare to take the lead in... let's call it widely-distributed-computation. All I want is my code running on your nodes all around the world with an end-to-end ping that is less than 10 ms to the average client.
As someone who tried building this for the unwashed masses, wait until you have something along the lines of Google Spanner. Developers see amazing gains from edge compute because ZOMG LATENCY, then actually flesh out their apps and start making uncached database calls back to AWS anyway.
EDIT: Yes they lack pricing transparency. Akamai is expensive. As I pointed out, in real world experience less than 5% of the developers I talked to actually could lower response times by moving closer to the client. It's something everyone thinks they need, but the devil is in the implementation details. Akamai hand holds you a lot for your money.
Akamai Edge Compute appears to be a "talk to us for pricing, and we'll then attempt to extract the maximum amount of money that we think you'll be able to pay" kind of deal. No thanks.
Hey Zack, this is awesome, what's the timeframe for approval right now?
I'm guessing you guys have lots of code review todo!
Anything we can do to help speed the process up? Specific types of unit tests maybe?
Also, a couple of suggestions:
More complicated installer options are a sort of want of mine. It would be nice if I could drop down to custom functions to make the install process more dynamic and user friendly dependent on input.
Also, slight pet peeve, the slider input option seems to have no way of displaying the slider value to the user.
I think it would be nice to have a couple of examples of the type of websites hosted by cloudflare so that as a developer I can get a sense of what apps would work best.
Further more ... if it's an app store (like) concept why does it not describe the way developers can make income just from creating an app not an app and a connected service that would require a server setup, I mean describe the revenue model and the cut that cloudflare would get and us as developers will get in the end.
What is cloudflare's endgame for investors? For some reason I don't think there are enough enterprise customers for cloudflare to become a multi billion dollar company.
I love cloudflare and am a happy customer but I'm really interested to know what these investors are thinking before they put up 100s of millions in investment.
To me, it seemed like they're putting the money into the apps that run on CloudFlare's platform and not CloudFlare itself
I agree, but I think there's an implicit additional $100MM investment in CloudFlare, for qualifying companies.
This seems analogous to when FB neutered FP Games from NewsFeed, Zynga took a nosedive and Zynga didn't seem to thrive outside of the FB App ecosystem.
What is cloudflare's endgame for investors? For some reason I don't think there are enough enterprise customers for cloudflare to become a multi billion dollar company.
Why not?
Also, Cloudflare has literally millions of web sites, APIs, applications using it. We are not limited to enterprise deals at all.
Actually, I just crunched some numbers and its not unreasonable to estimate that you are currently doing 8 figure sums monthly.
Maybe it's not a bad idea to invest in cloudflare :)
There's no lack of governments and non-governments who'll gladly pay for access to the plaintext web traffic hitting the literally millions of web sites, APIs and applications on CloudFlare.
See the "Things We Have Never Done" section: https://www.cloudflare.com/transparency/
Google went years without knowing their backhaul had been compromised.
If you think your cooperation stands in the way of the NSA using you for bulk collection, I've got a bridge to sell you.
"At its core a Cloudflare app is set of JavaScript and/or CSS files which run on a website, and an install.json file which instructs tools like Cloudflare Apps how to use those files."
Sounds like all of your code executes in the browser then, somewhat like tampermonkey user scripts or basic browser web extensions.
Distributed Lambda, which isn't far fetched since AWS' Cloudfront can run Lambda functions at the edge (with reduced functionality).
So, it's a "platform" for MITM as edge-includes in the CDN?
That's fairly accurate, as far as I can tell.
Your "code" looks VERY similar to the code you would write for a chrome web extension. The delivery mechanism for the code is the MITM capability...looks very much like edge-side-includes.
They have a sample app here: https://github.com/CloudflareApps/CornerRibbon
This is the result of Cloudflare's eager.io acquisition. You might remember eager from some of their really awesome blog posts on the histories of various techs [1][2].
1 https://eager.io/blog/a-brief-history-of-weird-scripting-lan...
2 https://eager.io/blog/history-of-email/
Now that I've said something nice, I'm going to follow that up with a big F U to this app: https://www.cloudflare.com/apps/noadblock
EDIT: a little pre-debate warmup for anybody that wants to get into it. Point 1: Users have the right to block. Counter-point: Content provider have the right to deny access. Point 2: Ads are bad for users. Counter-point: there is none, ads are bad for users.
It's super tempting to label something "noadblock" because it sounds like money to publishers (I know this because I've been trying like crazy to get publishers to use proxy level middleware), but you're right.
The reality is, you can inject advertisements into content at the proxy level that are better for peoples' privacy, keep pages fast, and are less disruptive for readers.
The thing is, publishers have a ton of unsellable inventory that you can blame on ad blockers, but it's really the end result of shitty advertising and privacy overreaches. Doing better ads will get them around ad blockers, but doing better ads from the beginning may have prevented the rise of ad blockers at all.
Actual counter-point: blocking all ads is shortsighted. As more and more people do it, the sites you are currently blocking from showing you ads will have to switch to a paid model, with many probably failing.
Only a select few news sources will survive. Local news in non-metropolitan areas will be even worse than it is now. People will start consuming news exclusively from the one or two (maximum) sources they pay for, whereas now they probably read at least one article from 50+ sources every month.
Elections will happen, but very few people will actually have enough information. All political oversight will seize, because actual behaviour is no longer tied to re-election. But, at least, most politicians will have very nice names.
Alternative scenario: smart blocking: start with allowing all, then blacklist individual ads based on the publisher, content/behaviour of the ad, and reputation of the ad network. That would incentive ads to actually get better.
I'm glad you replied; I'm interested in this debate.
I agree that content monetization is an important problem that ought to be solved in order to maintain quality of information.
I disagree that current advertising models have elevated the quality of content. Fake news websites (literally - a made-up .coms that have BS stories, the equivalent of tabloids) exist specifically because advertising monetizes clicks/eyeballs, and so clickbait is the optimal strategy.
I disagree that moderating ads will produce better ads, because I believe ads run counter to a well-functioning information system. An example: HN is an information system that's designed to put high quality links in front of the user. A paid placement makes it possible to skip the votes mechanism, thereby skipping the system's regulatory structure. If your link deserves to be at the top, it will get there the same way all other links do.
I disagree that advertising or paywall are the only two options, though I will concede those are the only two that have happened so far.
I'd be very wary about investing my time and resources on a platform with such a corrupt CEO. Just a few months ago he was blatantly lying* about the massive security issues they were having.
* https://news.ycombinator.com/item?id=13721644
Most likely relying on second-hand info that was just wrong. I doubt he based that post entirely on searching the caches himself. That whole incident was a mess though, tying up a lot of peoples' time who didn't work for CloudFlare. Centralization of services is always painful when things go wrong, and that may be a reason to avoid CloudFlare.
The only other beef I can think of against CloudFlare is how they play both sides of the DDoS game, hosting the sites selling them (free speech!) and charging the victims for protection.
PS. CloudFlare does deserve some flak / second thoughts for the whole Cloudbleed thing, but I don't think your response is quite on target.
Making claims based on unreliable second-hand info, as a CEO, is almost as bad as lying IMO.
Cloudbleed (most specifically what I will call the marketing side of the response) reflects poorly on the tech people at CloudFlare, for sure.
It's unusual to see someone accused of blatantly lying on HN and I put my alternative interpretation out there to hopefuly temper that opinion a bit.
As you mentioned, the end result is pretty much equivalent since all we have is the completely wrong output.
He might not have known it was second-hand info, or could have been led to believe it was good info from a good source (we'd need the message that led him to believe that thing -- and publicly throwing a subordinate under the bus for giving you bad info will obviously not go well).
I would differentiate that from lying, and fairly, he gets to deal with the consequences either way because he is the CEO.
The moment CF stops hosting DDoS websites is the moment the censorship will burst wide open. Besides CP (which is too hot to try to defend), as soon as they start judging which businesses are allowed to host then they'll be forced to restrict their offerings all around.
What if a booter site advertises itself and says "you must confirm you have legal authority to run an attack test against this site"? What if it's legal in <some jurisdiction>?
CF should only take down sites after getting a direct court order to stop services (even then jurisdiction is an issue).
I mentioned it as a conflict of interest to be aware of. I personally use CloudFlare for DNS for most of my personal sites.
Your comment seems to fairly accurately reflect CloudFlare's position: Thoughts on Abuse | https://blog.cloudflare.com/thoughts-on-abuse/ (2012)
Here is a semi-recent take from one of their more vocal opponents: Spreading the DDoS Disease and Selling the Cure | https://krebsonsecurity.com/2016/10/spreading-the-ddos-disea... (2016)
Here is how it works out in practice for a few fellow HN-er's: The New Normal: 200-400 Gbps DDoS Attacks | https://news.ycombinator.com/item?id=7242377 (2014)
The problem with this flawed line of argument is that CloudFlare applies their own Pro-Platforming views that might fly in the US globally.
So this jurisdiction issue actually goes both ways.
I would have been happy to give him the benefit of the doubt and still would. To me it seems to me he continually repeated these claims over the whole incident and ignored people who pointed out that what he was saying was obviously false. I only pointed to the most egregious example.
To be clear, I'm not super worried about companies just screwing up, shit happens. However, I have a personal bias against dealing with people who are dishonest when that happens.
To me, only passingly familiar with what happened, your initial comment left out too much of the detail you added later (specifically, the repeated part).
Thanks for following up!
Trump exclusively relies on second hand info. Lets not hold him accountable either.
If I ever become CEO, remind me never to post online ever. People hang on every dinky statement, take it for gospel, and then try to burn your house down with it.
That's not a winning solution either.
When Anonymous ran some anti-ISIS operation, they accused CloudFlare of "hosting" dozens of pro-ISIS sites[1]. It turns out Anonymous was entirely wrong about the CloudFlare customer sites (confirmed by DHS) and hypocritical (because CloudFlare tried to remain content-indifferent and, as such, protects lots of Anonymous sites). But their image took a spanking for it in the news, despite (1) investigating the claims, (2) contacting DHS to confirm they were in the right, (3) having a rational counterargument (even if it wasn't as simply as "TERRORISTS!!!!1!!1one").
Remaining quiet isn't the solution either. @eastdakota was actively corresponding with the HN community while his security+product teams were actively mitigating the "CloudBleed" damage.
Sometimes you will lose the news cycle, even if you are in the right and did everything right as a company should.
[1] https://www.theregister.co.uk/2015/11/18/cloudflare_ceo_rubb...
Yup. Karma wheel. Best you can do is be transparent and consistent with what you know when you know it.
Apps announcement: https://blog.cloudflare.com/cloudflare-apps-2/
Fund announcement: https://blog.cloudflare.com/developer-fund/
"Put a google map in a browser with no code"
Because copy pasting the markup / js was so difficult?
Imagine you are a dentist who has a web site for your practice.
Yeah, don't underestimate how annoying stuff is for most people. Even partially technically-aware users are right to prefer some easy click-n-add system vs getting into details themselves. Though I'm not sure how much those users intersect with Cloudflare users...
Are you saying it's going to be easier for a dentist to set up their DNS with Cloudflare and then go through these steps?
I can see this being used in large corporations to end-around a sluggish IT group.
There are developers (https://www.indiehackers.com/businesses/storemapper) who are making a significant amount of money from apps like these.
For some people 'copy pasting' is hard. Most people don't know how to code and don't want to deal with it.
The use case is probably not around maps but more around ads. Say you have a web project using cloudflare. There can be a single button on cloudflare called "monetise" which injects ads into the page.
Additionally I've seen that major media sites use analytics services for tagging and have a way via the tagging tool to inject javascript.. This is a pretty terrible idea but allows the tagging changes to not be coordinated with site changes as usually a different team controls the tagging. Cloudflare would be able to provide another way to inject custom analytics / tracking into pages.
I guess this explains the Cloudflare CEO's sudden uptick in anti-AWS tweets.
https://twitter.com/eastdakota/status/877697707464302593
https://twitter.com/eastdakota/status/876951966521348096
https://twitter.com/eastdakota/status/873041178718908416
https://twitter.com/eastdakota/status/870174216104034304
How? Cloudflare doesn't host (and makes a big deal of that point); the actual app backends need to be hosted somewhere. They partner with Google (connectivity between CF and GCP), which is in the same business as AWS. A more likely reason is AWS's own anti-DDoS offering, AWS Shield.
Maybe CF is a little tired of being the workaround for AWS egress charges too.
Again, why would that apply just to AWS? Being a "workaround" would apply to anyone offloading bandwidth - Azure, GCP, and AWS have similar pricing.
It applies mostly to AWS because of their respective marketshare in that space. Even more so specifically considering the S3 service.
Can anyone explain what this would be used for?
From the looks of the demo it looks like you instruct CloudFlare to inject some code, e.g. embedded google maps into a website at a location in the DOM.
How is that different from the website owner from just putting an embed link in their website and updating the site?
Or is the idea you can add/remove these things dynamically through the CloudFlare web interface without having to touch any code?
You can get a good idea of how it works by clicking through some previews, you don't have to actually use Cloudflare yet to preview apps on a site: https://www.cloudflare.com/apps/
Yes. There is a fancy preview thingy which lets you visually choose where to inject the element into the DOM, and a configuration UI which supports things like provisioning OAuth credentials for APIs, etc. No code needed (on the part of the site owner; code is written by app publisher).
One click to install, plus developers can charge clients using CloudFlare's payment system (70/30 rev share).
From the CloudFlare Docs site[1]:
[1] https://www.cloudflare.com/apps/developer/docs/writing-your-...
A platform that pays developers to use it is no platform at all.
Yes, there's exceptions to every rule. But I have yet to see this strategy of a platform fund ever succeed.
Better to build (or tap into) a captive audience and then sell that to developers.
You almost seem like you're trolling, but to clarify in case anyone else doesn't get it:
This is a low friction app ecosystem with 70/30 rev share[1] for what CloudFlare claims is 6m+ websites. Also, their VC are also willing to back companies in their app ecosystem, too.
[1] https://www.cloudflare.com/apps/developer/docs/writing-your-...
Thanks for clarifying.
I guess my main confusion is that I don't understand the audience who would benefit from these apps. I imagine one member of the audience is someone who runs a popular blog and want to add a widget but don't want to copy and paste code.
A quick search on Google would solve my problem, or I'd hire someone on eLance to make the change for me instead of paying a monthly subscription for an app.
I'm a lead engineer on the Cloudflare Apps team and I'd love to answer any questions. Cloudflare has been working on building apps into our platform for over six years, and I've personally been working on this codebase for over three (1200 days exactly today in fact).
The initial goal of Apps is to make it possible for everyone to use all the tools technical people find and use on Github and npm everyday. Our long term goal is to make it possible for developers to make a living building tools which make the web better. As an engineer myself, the moment I will personally enjoy the most is when a developer makes $1MM on the store meaning it has truly changed their lives. That will be when this experiment is proven a success and we can't wait!
UPDATE: I found a visualization that Teffen Ellis on our team made of every commit throughout the history of the project: https://drive.google.com/file/d/0B6EsMIhQjoQYT2pmS05hU1RuUTQ...
Hey Zack, two questions:
1) What were the interesting technical challenges of evolving the Eager codebase and integrating with Cloudflare since the acquisition?
2) What has surprised you so far in the feedback about developer experience?
If anyone doesn't know Eager was the company Adam Schwartz and I founded in 2014 which became the current version of Cloudflare Apps.
The challenges are probably pretty obvious, you have to take this codebase and application which were meant to live on its own and conform it to the way another system works. In the process you have to adapt your deployment, auth, style, etc. to work in this alternative reality. At times it can seem like you spend months working just to get back to the feature set you started with. At others you get to see the vision of an integration you sketched on a whiteboard six months ago become reality and you're blown away that this crazy idea could ever actually work. The definition of 'you' also changed a lot in that process, we went from being a small team to getting support and assistance from dozens of passionate people. It's a very different world where your resources can scale to your vision, instead of having to compromise what you want to build at every turn.
Particularly when you work at a company with as sweeping a vision as Cloudflare, you also get a chance to expand your vision itself. At Eager it was a romantic dream to think we would get on a hundred thousand sites. With our launch today we reach six million. The idea of a $100mm apps fund, or having 60 apps in the store before we even launched, were not things which startup-Eager could have pulled off.
My biggest surprise is gonna be a little silly but it's it's when someone builds a really great app without any help or guidance. As much work as you put into the API or docs it's always a little shocking when someone builds something from scratch on the platform you work on every day, and it works well, out of the box.
Hi Zack,
This headline made me think that Cloudflare had finally done what I first assumed Akamai did back in the noughties, before I learned they didn't really have magic tech. :/
Anyway: here's some indirect feedback. It doesn't really apply to your project (which I'm sure will be super useful to other people). I would expect Cloudflare to take the lead in... let's call it widely-distributed-computation. All I want is my code running on your nodes all around the world with an end-to-end ping that is less than 10 ms to the average client.
All I want is my code running on your nodes all around the world with an end-to-end ping that is less than 10 ms to the average client.
Interesting idea. jgc AT cloudflare to tell me more.
Akamai Edge Compute is what they are asking for.
As someone who tried building this for the unwashed masses, wait until you have something along the lines of Google Spanner. Developers see amazing gains from edge compute because ZOMG LATENCY, then actually flesh out their apps and start making uncached database calls back to AWS anyway.
EDIT: Yes they lack pricing transparency. Akamai is expensive. As I pointed out, in real world experience less than 5% of the developers I talked to actually could lower response times by moving closer to the client. It's something everyone thinks they need, but the devil is in the implementation details. Akamai hand holds you a lot for your money.
Akamai Edge Compute appears to be a "talk to us for pricing, and we'll then attempt to extract the maximum amount of money that we think you'll be able to pay" kind of deal. No thanks.
If you really want this now, shoot me an email (in profile) and i'll hook you up.
But... also email JGC... or me. ;)
Stay tuned.
Cloudflare will need to hire a sandboxing expert for that.
Wait...
Thanks this made me think of parasitic JavaScript and the folding at home project. I know you mean all their nodes. Not all "their" nodes.
Hey Zack, this is awesome, what's the timeframe for approval right now?
I'm guessing you guys have lots of code review todo!
Anything we can do to help speed the process up? Specific types of unit tests maybe?
Also, a couple of suggestions:
More complicated installer options are a sort of want of mine. It would be nice if I could drop down to custom functions to make the install process more dynamic and user friendly dependent on input.
Also, slight pet peeve, the slider input option seems to have no way of displaying the slider value to the user.
I think it would be nice to have a couple of examples of the type of websites hosted by cloudflare so that as a developer I can get a sense of what apps would work best.
Further more ... if it's an app store (like) concept why does it not describe the way developers can make income just from creating an app not an app and a connected service that would require a server setup, I mean describe the revenue model and the cut that cloudflare would get and us as developers will get in the end.
Thank you
Am I missing something here? I don't see any pricing model which will encourage people to post their "apps" here.