The feature I don't want to pay for but would be nice to have: deeper level proxied wildcards.
> If you want to proxy a wildcard DNS record on a deeper level like .www.mycoolwebpage.xyz you can subscribe to Cloudflare Advanced Certificate Manager and get a certificate that is covering that wildcard ¹ ²
When building out services in my smart home, I started with something like 'home.domain.com'. I used Let's Encrypt for services like 'smart.home.domain.com' (and I think Cloudflare proxied these for free?) but realized I was losing some privacy since the subdomains were describing my network services. I also wasn't aware SSL certificates are a permanent record (though what isn't these days) and I had to be careful what names I was using.
I realized instead I could use Let's Encrypt wildcard feature '.home.domain.com' and at least limit the private details potentially leaked in certificate history. But because Cloudflare doesn't proxy deeper wildcard subdomains for free, I'd have to manually create each subdomain in Cloudflare DNS - defeating the privacy objective.
For now, instead of wildcards, I'm just using URL path prefixes. For example 'smart.home.domain.com' becomes 'home.domain.com/smart/'. This works pretty easily in a docker host with traefik handling domains, paths, and certificates. Some apps don't work under path prefixes without a lot of tweaks. And it works fine if it's one-to-one server to subdomain - but if I want to host another server at home I have to come up with another subdomain like 'app-home.domain.com'.
I could also move everything into something like tailscale. Then at least the domains are private. Right now I use an oauth2 proxy infront of my services - but most of them don't need direct internet access. The issue is, for the services that do need the convenience of direct access, tailscale funnel doesn't support custom domains.³ And even if eventually they do, maybe they'll also limit subdomain depth or wildcards.
Anyway for privacy reasons it'd be swell if deeper level subdomain certificates were part of the free tier.
"In August, we introduced the billable usage dashboard and API which lets non-Enterprise customers see how much they’ve spent and download their consumption data to use offline directly or through third-party tools like Vantage. We also introduced budget alerts, which are on by default to prevent unpleasant billing surprises. We're prototyping hard spending caps now, with early availability in Q4 2026."
Reminder: Cloudflare doesn't have limits on these server so one day they hit you with a "Hey, you're using more than you should, pay $x,000 or we'll shut you down within 48 hours"
That's for paying customers. Free customers have no spending caps, they'll only tell you how much you have to pay them immediately after you're past their secret internal caps.
The feature I don't want to pay for but would be nice to have: deeper level proxied wildcards.
> If you want to proxy a wildcard DNS record on a deeper level like .www.mycoolwebpage.xyz you can subscribe to Cloudflare Advanced Certificate Manager and get a certificate that is covering that wildcard ¹ ²
When building out services in my smart home, I started with something like 'home.domain.com'. I used Let's Encrypt for services like 'smart.home.domain.com' (and I think Cloudflare proxied these for free?) but realized I was losing some privacy since the subdomains were describing my network services. I also wasn't aware SSL certificates are a permanent record (though what isn't these days) and I had to be careful what names I was using.
I realized instead I could use Let's Encrypt wildcard feature '.home.domain.com' and at least limit the private details potentially leaked in certificate history. But because Cloudflare doesn't proxy deeper wildcard subdomains for free, I'd have to manually create each subdomain in Cloudflare DNS - defeating the privacy objective.
For now, instead of wildcards, I'm just using URL path prefixes. For example 'smart.home.domain.com' becomes 'home.domain.com/smart/'. This works pretty easily in a docker host with traefik handling domains, paths, and certificates. Some apps don't work under path prefixes without a lot of tweaks. And it works fine if it's one-to-one server to subdomain - but if I want to host another server at home I have to come up with another subdomain like 'app-home.domain.com'.
I could also move everything into something like tailscale. Then at least the domains are private. Right now I use an oauth2 proxy infront of my services - but most of them don't need direct internet access. The issue is, for the services that do need the convenience of direct access, tailscale funnel doesn't support custom domains.³ And even if eventually they do, maybe they'll also limit subdomain depth or wildcards.
Anyway for privacy reasons it'd be swell if deeper level subdomain certificates were part of the free tier.
¹ https://blog.cloudflare.com/wildcard-proxy-for-everyone/ ² https://developers.cloudflare.com/ssl/edge-certificates/adva... ³ https://github.com/tailscale/tailscale/issues/11563
"In August, we introduced the billable usage dashboard and API which lets non-Enterprise customers see how much they’ve spent and download their consumption data to use offline directly or through third-party tools like Vantage. We also introduced budget alerts, which are on by default to prevent unpleasant billing surprises. We're prototyping hard spending caps now, with early availability in Q4 2026."
Yes! Yes! Hard caps please
Need more beta testing and advocates :)
thank you, but no thank you.
Reminder: Cloudflare doesn't have limits on these server so one day they hit you with a "Hey, you're using more than you should, pay $x,000 or we'll shut you down within 48 hours"
> We're prototyping hard spending caps now, with early availability in Q4 2026
That's for paying customers. Free customers have no spending caps, they'll only tell you how much you have to pay them immediately after you're past their secret internal caps.