"In August, we introduced the billable usage dashboard and API which lets non-Enterprise customers see how much they’ve spent and download their consumption data to use offline directly or through third-party tools like Vantage. We also introduced budget alerts, which are on by default to prevent unpleasant billing surprises. We're prototyping hard spending caps now, with early availability in Q4 2026."
The feature I don't want to pay for but would be nice to have: deeper level proxied wildcards.
> If you want to proxy a wildcard DNS record on a deeper level like .www.mycoolwebpage.xyz you can subscribe to Cloudflare Advanced Certificate Manager and get a certificate that is covering that wildcard ¹ ²
When building out services in my smart home, I started with something like 'home.domain.com'. I used Let's Encrypt for services like 'smart.home.domain.com' (and I think Cloudflare proxied these for free?) but realized I was losing some privacy since the subdomains were describing my network services. I also wasn't aware SSL certificates are a permanent record (though what isn't these days) and I had to be careful what names I was using.
I realized instead I could use Let's Encrypt wildcard feature '.home.domain.com' and at least limit the private details potentially leaked in certificate history. But because Cloudflare doesn't proxy deeper wildcard subdomains for free, I'd have to manually create each subdomain in Cloudflare DNS - defeating the privacy objective.
For now, instead of wildcards, I'm just using URL path prefixes. For example 'smart.home.domain.com' becomes 'home.domain.com/smart/'. This works pretty easily in a docker host with traefik handling domains, paths, and certificates. Some apps don't work under path prefixes without a lot of tweaks. And it works fine if it's one-to-one server to subdomain - but if I want to host another server at home I have to come up with another subdomain like 'app-home.domain.com'.
I could also move everything into something like tailscale. Then at least the domains are private. Right now I use an oauth2 proxy infront of my services - but most of them don't need direct internet access. The issue is, for the services that do need the convenience of direct access, tailscale funnel doesn't support custom domains.³ And even if eventually they do, maybe they'll also limit subdomain depth or wildcards.
Anyway for privacy reasons it'd be swell if deeper level subdomain certificates were part of the free tier.
I have set up let's encrypt with DNS challenge running a wildcard in on a subdomain. Its not a recursive wildcard, but for me, it works good enough. Some of the software I host in my home network expects to run as the root on a web server.
The DNS wildcard points to a 192.168.xxx.xxx address. I don't really care that the IP adres of my home server is public :)
How would any DNS service proxy wildcards? Is that something that’s actually supported as part of DNS? What actually gets resolved in that case? I’ve always had to register every domain/subdomain that should get proxied.
Tarvis allows people to self host apps without managing servers. Each workspace gets their wild card cert at *.weightedreply.tarvis.site.
Then when any app is installed by user in their workspace, they get subdomians under that wildcard without leaking what apps are running there. N8n app gets n8n.weightedreply.tarvis.site and hermes gets hermes.weightedreply.tarvis.site.
The proxy and auth is handled by self hosted pomerium so no dns records are published for any app subdomians under that workspace url.
I am using Google certificate manager which is free to generate and manage these wildcard certs. I know Google is not preferred but that's the only free service I could find to do this.
Reminder: Cloudflare doesn't have limits on these server so one day they hit you with a "Hey, you're using more than you should, pay $x,000 or we'll shut you down within 48 hours"
That's for paying customers. Free customers have no spending caps, they'll only tell you how much you have to pay them immediately after you're past their secret internal caps.
"In August, we introduced the billable usage dashboard and API which lets non-Enterprise customers see how much they’ve spent and download their consumption data to use offline directly or through third-party tools like Vantage. We also introduced budget alerts, which are on by default to prevent unpleasant billing surprises. We're prototyping hard spending caps now, with early availability in Q4 2026."
Yes! Yes! Hard caps please
Need more beta testing and advocates :)
The feature I don't want to pay for but would be nice to have: deeper level proxied wildcards.
> If you want to proxy a wildcard DNS record on a deeper level like .www.mycoolwebpage.xyz you can subscribe to Cloudflare Advanced Certificate Manager and get a certificate that is covering that wildcard ¹ ²
When building out services in my smart home, I started with something like 'home.domain.com'. I used Let's Encrypt for services like 'smart.home.domain.com' (and I think Cloudflare proxied these for free?) but realized I was losing some privacy since the subdomains were describing my network services. I also wasn't aware SSL certificates are a permanent record (though what isn't these days) and I had to be careful what names I was using.
I realized instead I could use Let's Encrypt wildcard feature '.home.domain.com' and at least limit the private details potentially leaked in certificate history. But because Cloudflare doesn't proxy deeper wildcard subdomains for free, I'd have to manually create each subdomain in Cloudflare DNS - defeating the privacy objective.
For now, instead of wildcards, I'm just using URL path prefixes. For example 'smart.home.domain.com' becomes 'home.domain.com/smart/'. This works pretty easily in a docker host with traefik handling domains, paths, and certificates. Some apps don't work under path prefixes without a lot of tweaks. And it works fine if it's one-to-one server to subdomain - but if I want to host another server at home I have to come up with another subdomain like 'app-home.domain.com'.
I could also move everything into something like tailscale. Then at least the domains are private. Right now I use an oauth2 proxy infront of my services - but most of them don't need direct internet access. The issue is, for the services that do need the convenience of direct access, tailscale funnel doesn't support custom domains.³ And even if eventually they do, maybe they'll also limit subdomain depth or wildcards.
Anyway for privacy reasons it'd be swell if deeper level subdomain certificates were part of the free tier.
¹ https://blog.cloudflare.com/wildcard-proxy-for-everyone/ ² https://developers.cloudflare.com/ssl/edge-certificates/adva... ³ https://github.com/tailscale/tailscale/issues/11563
I have set up let's encrypt with DNS challenge running a wildcard in on a subdomain. Its not a recursive wildcard, but for me, it works good enough. Some of the software I host in my home network expects to run as the root on a web server.
The DNS wildcard points to a 192.168.xxx.xxx address. I don't really care that the IP adres of my home server is public :)
How would any DNS service proxy wildcards? Is that something that’s actually supported as part of DNS? What actually gets resolved in that case? I’ve always had to register every domain/subdomain that should get proxied.
I implemented similar feature in my app https://tarvis.io
Tarvis allows people to self host apps without managing servers. Each workspace gets their wild card cert at *.weightedreply.tarvis.site.
Then when any app is installed by user in their workspace, they get subdomians under that wildcard without leaking what apps are running there. N8n app gets n8n.weightedreply.tarvis.site and hermes gets hermes.weightedreply.tarvis.site.
The proxy and auth is handled by self hosted pomerium so no dns records are published for any app subdomians under that workspace url.
I am using Google certificate manager which is free to generate and manage these wildcard certs. I know Google is not preferred but that's the only free service I could find to do this.
thank you, but no thank you.
Reminder: Cloudflare doesn't have limits on these server so one day they hit you with a "Hey, you're using more than you should, pay $x,000 or we'll shut you down within 48 hours"
> We're prototyping hard spending caps now, with early availability in Q4 2026
That's for paying customers. Free customers have no spending caps, they'll only tell you how much you have to pay them immediately after you're past their secret internal caps.