Cloudflare devant un site déjà en ligne
Le CV de Walid Moultamiss cite Cloudflare parmi les outils, avec Vercel et OVHcloud. Aucune page de réalisation ne dit que tel produit est derrière Cloudflare. Écrire à Casablanca si un site déjà en ligne doit être joint, protégé, ou servi avec un certificat, sans changer l'application.
Ce que le CV dit, et ce qu'il ne dit pas
La fiche publie la liste : React, Next.js, TypeScript, Node.js, GraphQL, MongoDB, WordPress, WooCommerce, PHP, Vercel, OVHcloud et Cloudflare. Cloudflare y est un outil de livraison et de bordure, pas le nom d'un produit. YourSoft Run décrit DNS, SSL et des migrations sur des hébergements OVHcloud. Ce n'est pas écrit comme un mandat Cloudflare.
Coller Cloudflare sur Coco Inbox, Proche de moi ou Dealkhir serait inventer le chemin réseau. Leurs pages disent la ville, l'année et le problème. Elles ne disent pas le proxy.
À quoi sert la bordure
Cloudflare se discute quand le nom de domaine, le certificat et le cache devant l'origine doivent être réglés sans toucher au code du produit. Le site ou l'application reste l'origine. La bordure ne devient pas le logiciel.
Le DNS et le certificat font déjà partie de l'hébergement : mise en ligne, certificat, sauvegardes, nom de domaine. Cloudflare est un moyen parmi d'autres, choisi pour le projet, pas une ville de serveur imposée. Les comptes remis reviennent au client.
Schéma
Le chemin d'une requête
Illustration. Pas un test du réseau, et pas une mesure de ce site.
Le visiteur joint l'origine. Le DNS public peut publier l'adresse du serveur. Sur ce chemin, pas de cache, pas de filtrage, et le certificat est celui de l'origine.
La requête s'arrête d'abord au proxy. L'origine n'est appelée que si la réponse n'est pas déjà en cache. Pour un enregistrement proxifié, le DNS public répond avec les adresses de Cloudflare, pas avec l'origine. Le certificat vu par le visiteur peut être celui du proxy. Cela ne garantit pas que l'origine reste introuvable : un sous-domaine laissé en DNS seulement, un ancien enregistrement, ou un autre service peuvent encore la montrer.
Comment Cloudflare décrit le proxy
Le schéma montre le choix. Le message utile donne le domaine et l'endroit où le site tourne.
Ce qu'on ne promet pas
Pas de pourcentage de disponibilité. Pas de chiffre de performance copié d'un tableau de bord. On dit ce qui est surveillé, et on corrige quand la page ne répond plus. La maintenance est la page de ce suivi.
Aucun prix. Premier échange de trente minutes, gratuit. Bureau au Technopark, boulevard Dammam, Aïn Chock, 20001 Casablanca.
DNS
Un enregistrement, deux choix
Zone d'exemple, exemple.ma. L'adresse 203.0.113.10 est réservée à la documentation. Ce n'est pas la zone de byteforce.ma.
Proxifié : le DNS public ne publie plus 203.0.113.10. Il publie des adresses du proxy. L'origine reste celle que le compte connaît. Masquer l'adresse dans la réponse DNS ne promet pas qu'aucun autre chemin ne la montre.
Scénario
Ce que le code HTTP raconte
Réponses possibles du proxy. Aucune n'est une mesure de byteforce.ma.
- Code
- 200
- cf-cache-status
- HIT
- Origine
- Pas appelée pour cette réponse.
Les six lectures
- 200. La ressource est en cache au proxy. Cette réponse n'a pas besoin de l'origine. Tout ne se cache pas : une page différente pour chaque visiteur reste souvent dynamique.
- 200. Rien de frais en cache. Le proxy va chercher la réponse à l'origine, puis ne la garde que si les en-têtes d'origine le permettent.
- 521. Le proxy a joint l'adresse d'origine, et rien n'a accepté la connexion. Le serveur web est arrêté, ou il n'écoute pas le port attendu.
- 522. La connexion vers l'origine n'a pas abouti dans le délai. Le serveur met trop longtemps à accepter, ou un pare-feu laisse tomber les paquets du proxy.
- 525. Le proxy n'a pas pu négocier TLS avec l'origine. Le mode SSL du compte et le certificat du serveur ne s'accordent pas.
- 526. Le proxy a refusé le certificat de l'origine : mauvais nom, certificat expiré, ou autorité non reconnue. Cela arrive quand le compte exige un certificat valide sur l'origine.
Lire une page, ou décrire le domaine
L'audit gratuit lit une page réelle : titre, indexation, images, mobile. Il n'ouvre pas le compte DNS.
Le domaine, l'endroit où le site tourne, et ce qui bloque se disent à Casablanca.
Donner le domaine et l'origine
Le message utile contient le nom de domaine, l'endroit où le site tourne aujourd'hui, et ce qui bloque : certificat, DNS, ou une page lente. On ne commence pas par le logo Cloudflare.
Écrire à Casablanca. La réponse part sous un jour ouvré.
English
Cloudflare in front of a live site
Walid Moultamiss's CV names Cloudflare among the tools, with Vercel and OVHcloud. No case-study page says a given product sits behind Cloudflare. Write to Casablanca if a live site must be joined, protected, or served with a certificate, without changing the application.
What the CV says, and what it does not
The profile publishes the list: React, Next.js, TypeScript, Node.js, GraphQL, MongoDB, WordPress, WooCommerce, PHP, Vercel, OVHcloud and Cloudflare. Cloudflare is a delivery and edge tool there, not the name of a product. YourSoft Run describes DNS, SSL and migrations on OVHcloud hosting. That is not written as a Cloudflare engagement.
Pinning Cloudflare on Coco Inbox, Proche de moi or Dealkhir would invent the network path. Their pages say the city, the year and the problem. They do not say the proxy.
What the edge is for
Cloudflare is discussed when the domain, the certificate and the cache in front of the origin must be set without touching the product code. The site or the application remains the origin. The edge does not become the software.
DNS and the certificate are already part of hosting: go-live, certificate, backups, domain name. Cloudflare is one means among others, chosen for the project, not an imposed server city. Delivered accounts return to the client.
Diagram
The path of a request
An illustration. Not a network test, and not a measurement of this site.
The visitor reaches the origin. Public DNS can publish the server address. On this path there is no cache, no filtering, and the certificate is the origin's.
The request stops at the proxy first. The origin is called only when the response is not already cached. For a proxied record, public DNS answers with Cloudflare addresses, not the origin. The certificate the visitor sees can be the proxy's. That does not guarantee the origin stays undiscoverable: a subdomain left DNS-only, an old record, or another service can still show it.
How Cloudflare describes the proxy
The diagram shows the choice. The useful note gives the domain and where the site runs.
What is not promised
No uptime percentage. No performance figure copied from a dashboard. What is watched is said, and a page that does not answer is fixed. Maintenance is the page for that care.
No price. The first thirty minutes are free. Office at Technopark, boulevard Dammam, Aïn Chock, 20001 Casablanca.
DNS
One record, two choices
Example zone, exemple.ma. The address 203.0.113.10 is reserved for documentation. This is not the byteforce.ma zone.
Proxied: public DNS no longer publishes 203.0.113.10. It publishes proxy addresses. The origin stays the one the account knows. Hiding the address in the DNS answer does not promise that no other path can show it.
Scenario
What the HTTP code says
Possible proxy responses. None of them is a measurement of byteforce.ma.
- Code
- 200
- cf-cache-status
- HIT
- Origin
- Not called for this response.
The six readings
- 200. The resource is in the proxy cache. This response does not need the origin. Not everything is cached: a page that differs per visitor often stays dynamic.
- 200. Nothing fresh is in cache. The proxy fetches the response from the origin, then keeps it only if the origin headers allow it.
- 521. The proxy reached the origin address, and nothing accepted the connection. The web server is down, or it is not listening on the expected port.
- 522. The connection to the origin did not complete in time. The server is too slow to accept, or a firewall drops the proxy's packets.
- 525. The proxy could not negotiate TLS with the origin. The account's SSL mode and the server certificate do not agree.
- 526. The proxy refused the origin certificate: wrong name, expired certificate, or an unrecognized authority. This happens when the account requires a valid certificate on the origin.
Read a page, or describe the domain
The free check reads a real page: title, indexation, images, mobile. It does not open the DNS account.
The domain, where the site runs, and what is blocked are said in Casablanca.
Give the domain and the origin
The useful note contains the domain, where the site runs today, and what is blocked: certificate, DNS, or a slow page. The work does not start from the Cloudflare logo.
Write to Casablanca. A reply goes out within one business day.