Those who are long-term subscribers would remember way back in 2016 I tried to migrate to Cloudflare. I have been hesitant to migrate from my little home server to the big world wide CDN web. That move was made, again, around a week ago.

The motivations behind this are primarily hosting of the GeoCities Archive and the ASSEMblerGames Archive. Cloudflare’s Always Online was attractive because it could fall back to cached or Internet Archive copies of some static pages when the origin was unreachable. It was not a complete mirror of every page, but it suited the archival direction of the site.

Another useful feature was Cloudflare’s CSAM Scanning Tool. It could compare content served through the Cloudflare cache against known CSAM lists, which was particularly useful for a huge inherited archive I could not manually inspect page by page.

One reason I had trouble with Cloudflare SSL before was redirect loops in the old setup. I understand the model much better now: Cloudflare terminates the visitor’s TLS connection at its edge, then makes a separate connection back to my origin. With Full (strict), the origin also needs to present a valid certificate for the requested hostname. My Let’s Encrypt certificate handles that origin side.

As I now understand the underlying mechanism through trial and error, naturally, my precious onions work. The clearnet site could sit behind Cloudflare while the .onion service remained a separate route to equivalent content. Cloudflare was not what made the onion service work; it protected and cached the public web side. Took a little while to get the configuration right but it works for now.

Everything said, it means a faster website, better uptime (in theory), I get a neat dashboard showing automated and security-related traffic, and we’re ready for Ubuntu 22.04 LTS (Jammy Jellyfish) due around late April 2022. Loaded with ddclient 3.9.1 which has Cloudflare dynamic DNS (DDNS) support baked in, it’s going to be epic. Stay tuned!

Sources