Rendered at 19:59:58 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
z0al 9 hours ago [-]
"In August, we introduced the billable usage dashboard and API which lets non-Enterprise customers see how much they’ve spent and download their consumption data to use offline directly or through third-party tools like Vantage. We also introduced budget alerts, which are on by default to prevent unpleasant billing surprises. We're prototyping hard spending caps now, with early availability in Q4 2026."
Yes! Yes! Hard caps please
weightedreply 6 hours ago [-]
The feature I don't want to pay for but would be nice to have: deeper level proxied wildcards.
> If you want to proxy a wildcard DNS record on a deeper level like .www.mycoolwebpage.xyz you can subscribe to Cloudflare Advanced Certificate Manager and get a certificate that is covering that wildcard ¹ ²
When building out services in my smart home, I started with something like 'home.domain.com'. I used Let's Encrypt for services like 'smart.home.domain.com' (and I think Cloudflare proxied these for free?) but realized I was losing some privacy since the subdomains were describing my network services. I also wasn't aware SSL certificates are a permanent record (though what isn't these days) and I had to be careful what names I was using.
I realized instead I could use Let's Encrypt wildcard feature '
.home.domain.com' and at least limit the private details potentially leaked in certificate history. But because Cloudflare doesn't proxy deeper wildcard subdomains for free, I'd have to manually create each subdomain in Cloudflare DNS - defeating the privacy objective.
For now, instead of wildcards, I'm just using URL path prefixes. For example 'smart.home.domain.com' becomes 'home.domain.com/smart/'. This works pretty easily in a docker host with traefik handling domains, paths, and certificates. Some apps don't work under path prefixes without a lot of tweaks. And it works fine if it's one-to-one server to subdomain - but if I want to host another server at home I have to come up with another subdomain like 'app-home.domain.com'.
I could also move everything into something like tailscale. Then at least the domains are private. Right now I use an oauth2 proxy infront of my services - but most of them don't need direct internet access. The issue is, for the services that do need the convenience of direct access, tailscale funnel doesn't support custom domains.³ And even if eventually they do, maybe they'll also limit subdomain depth or wildcards.
Anyway for privacy reasons it'd be swell if deeper level subdomain certificates were part of the free tier.
Tarvis allows people to self host apps without managing servers. Each workspace gets their wild card cert at *.weightedreply.tarvis.site.
Then when any app is installed by user in their workspace, they get subdomians under that wildcard without leaking what apps are running there. N8n app gets n8n.weightedreply.tarvis.site and hermes gets hermes.weightedreply.tarvis.site.
The proxy and auth is handled by self hosted pomerium so no dns records are published for any app subdomians under that workspace url.
I am using Google certificate manager which is free to generate and manage these wildcard certs. I know Google is not preferred but that's the only free service I could find to do this.
lukevp 2 hours ago [-]
How would any DNS service proxy wildcards? Is that something that’s actually supported as part of DNS? What actually gets resolved in that case? I’ve always had to register every domain/subdomain that should get proxied.
subscribed 10 hours ago [-]
Need more beta testing and advocates :)
mediumsmart 13 hours ago [-]
thank you, but no thank you.
rolymath 9 hours ago [-]
Reminder: Cloudflare doesn't have limits on these server so one day they hit you with a "Hey, you're using more than you should, pay $x,000 or we'll shut you down within 48 hours"
fakedang 9 hours ago [-]
> We're prototyping hard spending caps now, with early availability in Q4 2026
rolymath 7 hours ago [-]
That's for paying customers. Free customers have no spending caps, they'll only tell you how much you have to pay them immediately after you're past their secret internal caps.
Yes! Yes! Hard caps please
> If you want to proxy a wildcard DNS record on a deeper level like .www.mycoolwebpage.xyz you can subscribe to Cloudflare Advanced Certificate Manager and get a certificate that is covering that wildcard ¹ ²
When building out services in my smart home, I started with something like 'home.domain.com'. I used Let's Encrypt for services like 'smart.home.domain.com' (and I think Cloudflare proxied these for free?) but realized I was losing some privacy since the subdomains were describing my network services. I also wasn't aware SSL certificates are a permanent record (though what isn't these days) and I had to be careful what names I was using.
I realized instead I could use Let's Encrypt wildcard feature '
.home.domain.com' and at least limit the private details potentially leaked in certificate history. But because Cloudflare doesn't proxy deeper wildcard subdomains for free, I'd have to manually create each subdomain in Cloudflare DNS - defeating the privacy objective.For now, instead of wildcards, I'm just using URL path prefixes. For example 'smart.home.domain.com' becomes 'home.domain.com/smart/'. This works pretty easily in a docker host with traefik handling domains, paths, and certificates. Some apps don't work under path prefixes without a lot of tweaks. And it works fine if it's one-to-one server to subdomain - but if I want to host another server at home I have to come up with another subdomain like 'app-home.domain.com'.
I could also move everything into something like tailscale. Then at least the domains are private. Right now I use an oauth2 proxy infront of my services - but most of them don't need direct internet access. The issue is, for the services that do need the convenience of direct access, tailscale funnel doesn't support custom domains.³ And even if eventually they do, maybe they'll also limit subdomain depth or wildcards.
Anyway for privacy reasons it'd be swell if deeper level subdomain certificates were part of the free tier.
¹ https://blog.cloudflare.com/wildcard-proxy-for-everyone/ ² https://developers.cloudflare.com/ssl/edge-certificates/adva... ³ https://github.com/tailscale/tailscale/issues/11563
Tarvis allows people to self host apps without managing servers. Each workspace gets their wild card cert at *.weightedreply.tarvis.site.
Then when any app is installed by user in their workspace, they get subdomians under that wildcard without leaking what apps are running there. N8n app gets n8n.weightedreply.tarvis.site and hermes gets hermes.weightedreply.tarvis.site.
The proxy and auth is handled by self hosted pomerium so no dns records are published for any app subdomians under that workspace url.
I am using Google certificate manager which is free to generate and manage these wildcard certs. I know Google is not preferred but that's the only free service I could find to do this.