Educational — Cloud egress & data-transfer cost guides. FinOps-lite estimators. Not a quote, broker, or savings guarantee. Launching soon where incomplete.
cdn-origin · Educational

Cloud egress: CloudFront vs Cloudflare CDN origin path

Updated

CDN logos are not interchangeable meters — map edge transfer versus origin fill before comparing CloudFront and Cloudflare paths.

Path matrix: CloudFront vs Cloudflare CDN edge and origin meters (educational)
Meter / pathAmazon CloudFront (typical)Cloudflare CDN (typical)Watch
Edge / Internet deliveryRegional edge DT tiersPlan / product bandwidth rulesPlan cliffs ≠ list $/GB
Origin fill on missOrigin may bill S3/EC2 egress or CF origin feesOrigin pull may bill origin provider + CF rulesWho owns the origin?
Cache hit ratio (CHR)Misses drive origin bytesSame physics; product cache defaults differMeasure per path
Shield / tiered cacheRegional shield patternsTiered cache / Argo nuancesArchitecture diagrams
Workers / Functions at edgeCloudFront Functions / Lambda@EdgeWorkers / Pages FunctionsCPU + request SKUs separate

Provider source footnotes

  1. AWS CloudFront pricing — as-of Unknown until verified
  2. Cloudflare pricing / CDN docs — as-of Unknown until verified
  3. Cloudflare Cache / tiered cache docs — as-of Unknown until verified

Dated starting points only — Unknown until verified means no invented $/GB. PipeToll does not scrape private consoles or guarantee figures.

Compare origin paths, not brand slides. Both CloudFront and Cloudflare CDN can deliver bytes at the edge; FinOps risk lives in miss-driven origin fill, plan cliffs, and request/CPU add-ons. Educational only — FinOps-lite, not a broker.

Path templates to model

Common traps

Assuming “CDN = zero origin egress.” Comparing only CloudFront regional $/GB to a Cloudflare plan headline without measuring CHR. Blending Workers/Lambda@Edge CPU into egress lines. Treating shield/tiered cache as free HA without byte accounting. No scorecrowns from Incomplete cells — keep Unknown until verified.

FinOps checklist

  1. Export client GB and CHR (or miss ratio) by cache policy for 30–90 days.
  2. Name the origin owner (S3, R2, compute) and which bill moves on misses.
  3. Estimate fill with Mode C (?mode=origin&path=cf-cloudflare).
  4. Cross-read CDN origin fill and S3 vs CloudFront origin.
  5. Date-stamp rates via methodology; do not invent $/GB.

FinOps-lite Unknown until verified

Worked example (educational): 12 TB client downloads at 82% CHR

Users pull 12,000 GB via CDN. At 0.82 CHR, origin fill ≈ 2,160 GB. Price edge delivery and origin fill as separate lines — Mode C for fill, Mode A for edge if you have a verified edge $/GB. Placeholder rates stay Unknown. Enabling either CDN is not a guaranteed savings claim.

Open calculator

FAQ on this path

Does Cloudflare always mean $0 origin egress?

No. Origin fill still moves bytes from whatever hosts the origin (S3, R2, VPS, etc.). Marketing for edge bandwidth is not the same as zero origin bill.

When is CloudFront simpler to model on AWS?

When origin is already S3/EC2 in-account and you want AWS-native OAC/OAI patterns — simplicity ≠ guaranteed lower spend.

What metric first?

Client download GB, CHR by path, and which invoice line (CDN vs origin storage/compute) moves when misses rise.