Dated starting points only — Unknown until verified means no invented $/GB. PipeToll does not scrape private consoles or guarantee figures.
Compare origin paths, not brand slides. Both CloudFront and Cloudflare CDN can deliver bytes at the edge; FinOps risk lives in miss-driven origin fill, plan cliffs, and request/CPU add-ons. Educational only — FinOps-lite, not a broker.
Path templates to model
Browser ← CloudFront ← S3 (OAC) — edge DT + miss-driven S3/CF origin bytes; see also S3 direct vs CloudFront.
Browser ← Cloudflare ← R2 / custom origin — edge plan rules + origin provider egress on misses.
Browser ← Cloudflare ← S3 origin — cross-vendor: Cloudflare edge + AWS origin fill (source often pays).
API with short TTL — low CHR; origin fill dominates; Mode C sensitivity first.
Byte-range / video — range misses inflate fill beyond naive CHR; track media paths separately.
Common traps
Assuming “CDN = zero origin egress.” Comparing only CloudFront regional $/GB to a Cloudflare plan headline without measuring CHR. Blending Workers/Lambda@Edge CPU into egress lines. Treating shield/tiered cache as free HA without byte accounting. No scorecrowns from Incomplete cells — keep Unknown until verified.
FinOps checklist
Export client GB and CHR (or miss ratio) by cache policy for 30–90 days.
Name the origin owner (S3, R2, compute) and which bill moves on misses.
Date-stamp rates via methodology; do not invent $/GB.
FinOps-liteUnknown until verified
Worked example (educational): 12 TB client downloads at 82% CHR
Users pull 12,000 GB via CDN. At 0.82 CHR, origin fill ≈ 2,160 GB. Price edge delivery and origin fill as separate lines — Mode C for fill, Mode A for edge if you have a verified edge $/GB. Placeholder rates stay Unknown. Enabling either CDN is not a guaranteed savings claim.
No. Origin fill still moves bytes from whatever hosts the origin (S3, R2, VPS, etc.). Marketing for edge bandwidth is not the same as zero origin bill.
When is CloudFront simpler to model on AWS?
When origin is already S3/EC2 in-account and you want AWS-native OAC/OAI patterns — simplicity ≠ guaranteed lower spend.
What metric first?
Client download GB, CHR by path, and which invoice line (CDN vs origin storage/compute) moves when misses rise.