Notes on Cloudflare Access
Cloudflare is now in the AWS zone: it has a long tail of useful but under-examined little services that haven't quite entered the zeitgeist the way the flagships have. One that we've recently started using — and quite admire — is Cloudflare Access.
The UX is very simple. If you have a domain backed by Cloudflare DNS, and that domain runs through a DNS proxy, you can put a one-click authentication wall in front of it. Delightful.Free up to fifty users, at which point it's seven dollars per user per month — worth knowing before you wall off something with a big team behind it.
Obviously, this is not useful for everything, or even for most things. But we found two good use cases. The first is our admin site, which obviously needs to be protected — but doesn't need a broader authentication mechanism, or any real knowledge of a user model. The second is our internal tooling. We have an internal file-sharing tool, for instance; putting it behind the same access policy isn't a game-changer, but it's genuinely nice, and it's genuinely neat.
What I admire most is that it feels like an obvious case of vertical integration used for good. I think that's very cool. It gives me a glimpse of a world — perhaps not too distant — where Cloudflare is a much more serious contender in infrastructure. Which is not to say they aren't already one.
If you squint a little, there's a lot of tooling and adjacency that becomes much easier to build and sell once you already sit on a user's DNS. Historically, the answers have been kind of boring: email, web hosting, and so on. But with sufficient skill and ingenuity, that's just the tip of the iceberg.
The biggest downside, obviously, is lock-in — to which I have no salient or interesting answer, besides that the switching costs of using such a service are outweighed by the utility it provides. That could certainly become untrue in the future. But it isn't today.