Skip to content
Notifications
Clear all

Migrated from Cloudflare to Fastly WAF - 6 month report on performance

2 Posts
2 Users
0 Reactions
3 Views
(@devops_rookie_2025)
Reputable Member
Joined: 2 months ago
Posts: 203
Topic starter   [#18578]

Hey everyone! 👋 I'm still pretty new to the whole DevOps/WAF scene, so I wanted to share our team's experience and maybe get some clarifications on what we saw.

We switched from Cloudflare's WAF/Proxy to Fastly about six months ago. Our main goal was better performance for our API endpoints in the EU. The config change itself was a bit daunting for me. Here's a simplified snippet of how we set up a basic rule in Fastly compared to the old Cloudflare way:

**Cloudflare (via Dashboard):**
We just clicked to create a rule like "URI path contains /api and rate > 100 req/5 min".

**Fastly (VCL snippet):**
```vcl
if (req.url.path ~ "^/api" && req.rate > 100/300s) {
error 618 "Rate limit exceeded";
}
```
I found the VCL learning curve steep! 😅

The performance results were interesting. Our p95 latency for EU users dropped by about 40ms on average, which was great. But I was surprised that our origin server load didn't decrease as much as I expected. Maybe our Cloudflare config wasn't optimal? I'd love a beginner-friendly explanation on why that might happen.

Big thanks to this community – I've learned a ton just reading posts here!



   
Quote
(@gregm)
Estimable Member
Joined: 6 days ago
Posts: 83
 

gregm here. I work as a security lead for a 200-person SaaS shop handling financial data, so PCI-DSS and audit logs are my daily life. We've had both Cloudflare and Fastly in front of different services over the last three years.

Here's a blunt breakdown from someone who's had to sign off on the compliance paperwork for both.

1. **Target Audience & Fit**: Cloudflare is the SMB-to-mid-market default that gets you 80% there fast. Fastly is for the mid-market team that's already knee-deep in DevOps and needs fine-grained control, willing to trade a dashboard for VCL. If your team doesn't have a dedicated infra person, Cloudflare is the only sane choice.
2. **Real Pricing & Hidden Costs**: Cloudflare's Pro tier (~$20/mo/site) is predictable. Fastly's consumption model (bandwidth + requests) looks good until you get a burst of uncacheable POST traffic to your API. I've seen bills swing 30% month-to-month. The real hidden cost is engineering hours: debugging custom VCL isn't free.
3. **Deployment & Operational Effort**: Cloudflare rules are a 5-minute dashboard job. Fastly requires a VCL pipeline, testing in a staging service, and a deployment ceremony. For a simple rate limit, that's a 10x time multiplier. Your origin load didn't drop because Fastly doesn't proxy-cache non-GET/HEAD by default unless you explicitly code for it; Cloudflare's WAF/CDN often does more "out of the box" caching.
4. **Where It Clearly Breaks**: Fastly's logging is powerful but a beast to integrate with your SIEM. Cloudflare's logs are simpler but less granular. If you need a perfect audit trail for GDPR right-to-erasure requests, Fastly gives you the control to build it. Cloudflare makes you hope their system complies.

I'd pick Fastly only if you have a specific, high-performance API endpoint pattern you can tune in VCL and a team to support it. For the other 95% of use cases, especially if compliance is a concern, Cloudflare is the less risky bet. Tell us your team size and if you have any compliance requirements (like SOC2 or GDPR) and the call gets a lot easier.


Trust but verify


   
ReplyQuote