Interwebs archive

Anything and everything vaguely internet related. Blogging, industry, social media: if you can find it online, I've talked about it in here.

Cloudways’ Cloudflare Enterprise integration is a crock of shit

We have a few clients with larger e-commerce (WordPress + WooCommerce) stores hosted on UK servers via Cloudways. Generally speaking, the service is fine and the cost is decent for what we get. Support isn’t always quick or knowledgeable but we rarely need it, so it’s not a massive issue. However, I’ve had two different clients on two different Cloudways products both of whom have had problems with their integrated “Cloudflare Enterprise” solution recently, so I feel obliged to moan about it (old school blogging style).

Client A was a brand new e-commerce build: large site, highly bespoke build with some complex third party integrations, but optimised AF👌 (Fantastic project and at some point I’ll write about it.) Hosted on a Vultr box via Cloudways Flexible.

Client B is an inherited WooCommerce site with Elementor, Mailchimp, multiple third party plugins; usual run of the mill ‘built by a plugin jockey’ kinda site. Hosted on Cloudways Autonomous, which is designed to grow and shrink based on the needs of your site at the time.

Client A

Within an hour of Client A’s website going live, they were hit by every scraper on the planet wanting a piece of it. We rapidly rolled out additional optimisations, cached things that weren’t already cached, implemented an atomic mutex on product filters (I hadn’t even heard of an atomic mutex prior to this) so that if multiple people loaded the same combination of filters it would pull from transients instead of rebuilding the list each time, and blocked a few repeat IPs. While that helped bring the CPU load down a smidgen, it was ultimately fruitless as the scrapers just rolled through a another batch of IPs and changed crawl behaviour to bypass blockers, overwhelming the site and bringing it down.

We spoke to Cloudways support and they eventually got back to us and suggested enabling their Cloudflare Enterprise integration at ~$5 per month per site, which would definitely solve all of the problems we were having. We managed to coordinate the client’s tech guy, the client and us to do the DNS switcheroo to route through Cloudflare Enterprise and… it made sod all difference.

I was really surprised by how limited the toolset was once the Enterprise service was enabled. When you think about how much you get in Cloudflare’s free package, it seemed utterly bizarre that we were paying for a shitter package?! We had no firewall rules, no bot detection, no country targeting, no ASIN blocking, just a basic rate throttle and a yes/no for under attack. No surprise that it didn’t make any difference to the situation, tbh.

The only way we could keep the site online at this point was by enabling ‘Under Attack’ mode, but that presented UX challenges to genuine customers and completely prevented some of our third party integrations from working: it wasn’t a sustainable solution.

We called an emergency meeting, coordinated another DNS switcheroo, turned off “Enterprise” and routed through Cloudflare properly. This opened up all the usual tools and I was able to completely resolve the problem with a handful of custom rules triggering managed challenges to questionable traffic. Problem solved, ongoing cost: $0.

Client B

Client B’s problems were similar. Scrapers and bots targeting computationally ‘expensive’ WooCommerce pages and driving CPU usage and bandwidth costs through the roof. Except, their site didn’t go down, because autonomous just allowed the server to scale to meet the “needs” of these bots.

Cloudways Autonomous has Cloudflare Enterprise enabled as standard, it’s part of the offering. No additional $5 charge, but paying over the odds (~$90pm) for space and bandwidth compared to a fixed server (~$60pm), so costing in the long run anyway (even without the overage fees). As per the fixed server integration, it has the same problem with lack of tooling though: no custom rules, no bot management, basically just an on/off switch for under attack.

I flagged the ever increasing costs to the client who raised it with Cloudways, and Cloudways’ answer? To change to a different, slightly more expensive Autonomous package. No management of the bots and scrapers, just throwing more money at it. 🤬 Considering their integration page talks about ‘real results’, ‘enterprise grade protection’, ‘everything you need’, etc this response (and the corresponding feature set) is an absolute joke.

It took some back and forth persuasion, but after the client’s hosting fees skyrocketed to over $800 for the month with no end in sight (a reminder: this should be $90 per month for the base package) they agreed to switch to a fixed cost server routed through Cloudflare free. I finally managed to execute that migration yesterday and everything was confirmed as propagated and working this morning. In the space of 6 hours, Cloudflare free has mitigated nearly 100,000 requests that would have otherwise hit the server:

Screenshot of the security analytics from the client's cloudflare account showing 99.3k requests mitigated by cloudflare

…and all for nothing, nada, zilch. This is going to be pleasant relief next month, as the total bill for Autonomous over August topped $1100 yesterday.

Enterprise schmenterprise. In future, I’ll be recommending clients stick to Cloudflare’s free package, and Cloudways can suck my proverbial.

Re: Re: An infuriating goodbye to Photoshop

I spotted Online Goddess’ blog post, Re: An Infuriating Goodbye to Photoshop, which itself is a reply to Gavin Anderegg’s An infuriating goodbye to Photoshop on Bubbles and had to add my tuppence worth. Like Gavin and OG, I’ve been using Photoshop a long time. I switched to Photoshop 5 after Corel bought Paint Shop… read full entry »

Bubbles, and the old web

I spotted Bubbles in my basic referrers this morning, and my heart lit up. A little directory, surfacing blog posts from actual bloggers, what in the old web is going on?! This isn’t the first time I’ve spotted a resurgence in indie / ‘old’ web stuff lately. Personal sites are making a comeback, bloggers are… read full entry »

The olden days

Got “recognised” by two different people on reddit yesterday as “that blogger” and god, if it hasn’t made me miss the olden days of blogging. Write any old crap that comes to mind, publish, receive immediate feedback and support from peers and friends. Do it all again a few days later. I’m not sure at… read full entry »

New Things!

New Look! Yes, as you can probably see, I’ve changed the way the site looks again. I’ve been tinkering about with this one for a while between work projects. The theme is based off the lovely Storyteller by Mauer Themes. I paid for the theme (fair’s fair) then completely re-created it so that it would… read full entry »

pipdig: Your Questions Answered

This blog post is a follow-up to yesterday’s post: Security alert: pipdig insecure, DDoSing competitors. Firstly, to re-iterate, my accusations are as follows… pipdig did knowingly and with malicious intent: used other blogger’s servers to perform a DDoS on a competitor manipulated blogger’s content to change links to competitor WordPress migration services to point to… read full entry »

Instagram isn’t the problem, you are

Forgive the click-baity title for just a minute and hear me out. I responded to Molly Forbes‘ tweet earlier today (which admittedly lacked context, so I was making a massive assumption on its intent)… https://twitter.com/mollyjforbes/status/1107661795261665283 …with the words “Sometimes I feel like I’m the only person who likes instagram.” Admittedly, my response was actually borne… read full entry »

The jemjabella Top Ten: Best of Jem

After a brief twitter conversation yesterday, I realised that I have over 17 years of blog posts on this site, but no way of distinguishing those actually worth reading from what is mostly a collection of personal old waffle. So, here’s my jemjabella all time top ten, as decided right now on no scientific basis… read full entry »