The best Cloudflare alternatives depend on which part of Cloudflare you actually use. Bunny.net and Fastly replace the CDN, Vercel and Netlify replace Pages-style hosting, Tailscale and Pangolin replace tunnels and private access, and Caddy with BunkerWeb replaces the proxy and firewall layer on servers you control.
Cloudflare is a bundle of services, so this guide is organised by job: CDN, edge hosting, tunnels and zero-trust access, and self-hosted proxies and web application firewalls. The table shows live licence, self-hosting, pricing and GitHub data for the main picks.
| Tool | Type | Category | Self-host | Pricing | GitHub |
|---|---|---|---|---|---|
| SaaS | Networking & VPN | No | Free | Closed source | |
| SaaS | Hosting & PaaS | No | Paid | Closed source | |
| SaaS | Networking & VPN | No | Free plan | Closed source | |
| SaaS | Networking & VPN | No | Free plan · from $15/mo | Closed source | |
| SaaS | Hosting & PaaS | No | Free plan · from $20/mo per seat | Closed source | |
| SaaS | Hosting & PaaS | No | Free plan · from $9/mo | Closed source | |
| SaaS | Networking & VPN | No | Free plan · from $8/mo per seat | Closed source | |
| Open source | Networking & VPN | Yes | Free · cloud from $4/mo per seat | ★ 23k | |
| frp | Open source | Networking & VPN | Yes | Free (open source) | ★ 110k |
| Open source | Networking & VPN | Yes | Free (open source) | ★ 76k | |
| Open source | Networking & VPN | Yes | Free (open source) | ★ 65k | |
| Open source | Security | Yes | Free (open source) | ★ 11k |
Live data from Enlisted: GitHub stats sync daily; pricing comes from each vendor's pricing page.
Why people look for Cloudflare alternatives
Cloudflare is a global edge platform that sits in front of websites and applications. Its core services are a content delivery network, DNS, unmetered DDoS protection, universal SSL certificates and a web application firewall, managed from one dashboard, and it also sells a Zero Trust suite and a compute and storage platform. Common reasons to compare it with other tools:
- You only need one piece. If the real job is hosting a front end, tunnelling to a home server or filtering bad requests, a focused tool can be simpler than a platform with dozens of products.
- Plan tiers gate features. The catalogue lists Free, Pro, Business and custom Contract plans, and the higher website plans add features such as lossless image optimisation, PCI DSS 4.0 compliance and an uptime SLA. Compute, storage and AI are priced on usage.
- It is closed source and hosted only. Enlisted lists no self-hosted version, and traffic for a proxied site passes through Cloudflare's network.
- One account holds DNS, caching and security rules. Some teams prefer to spread those across vendors or keep parts on their own infrastructure.
- Zero Trust is a separate product with its own pricing. Cloudflare's Zero Trust has a free tier up to a user cap, then per-user pricing, which is a different model from the open-source options below.
How we picked
A tool made this list if it replaces at least one job Cloudflare does: CDN, edge hosting, tunnelled access, reverse proxying or web application firewalling. Open-source projects needed a clear licence and recent GitHub activity, and Enlisted shows whether each can be self-hosted. Published pricing and a free plan are what brought the hosted products in. Catalogue data and vendor documentation supply the facts, and nothing was run or measured for this guide. See how Enlisted ranks tools.
Which part of Cloudflare are you replacing?
Name the job first, because the answer changes completely.
- CDN and caching: copies of your content served from locations near visitors. Bunny.net, Fastly and Amazon CloudFront are hosted CDNs.
- Edge hosting and functions: running a site or code on a managed platform. Vercel, Netlify and Deno Deploy do this.
- Tunnels and zero-trust access: reaching a private service without opening ports, or giving staff identity-based access. Tailscale, Pangolin and frp cover this, and the Tailscale alternatives guide goes deeper.
- Reverse proxy and WAF: software that terminates HTTPS, routes requests and blocks attacks on your own server. Caddy, Traefik and BunkerWeb fit here.
- DNS: hosted DNS from a cloud provider such as Amazon Route 53, or software such as PowerDNS you run yourself.
Self-hosted software cannot copy one thing a CDN sells: servers in many places. A proxy on your own machine runs where you put it, so keep a hosted CDN or upstream protection if distribution or flood resistance matters.
1. Bunny.net: best pay-as-you-go CDN with storage and DNS
Bunny.net is a content delivery network with edge storage, DNS, image optimisation, video streaming and edge compute, sold on a pay-as-you-go basis. Where Cloudflare packages plans by tier, Bunny's catalogue entry lists CDN traffic billed per gigabyte by region with no request fees and a free trial rather than a free plan.
Beyond Bunny CDN, the catalogue lists SSD-backed storage, Bunny DNS, an image Optimizer, Bunny Stream for video with DRM, Edge Scripting, Magic Containers, a SQLite-compatible database and Bunny Shield for security. It is proprietary and vendor-hosted.
- Best for: websites, downloads and video delivery that want simple, usage-based CDN billing.
- Watch out for: there is no free plan in Enlisted's data, and you should compare Bunny Shield with the WAF and DDoS controls you depend on.
2. Fastly: best programmable CDN for teams that want edge control
Fastly is an edge cloud platform that combines a programmable CDN with security, serverless compute and observability. It is aimed at teams that want to control caching and logic at the edge instead of only at the origin server.
Its areas are Deliver, Secure, Deploy and Observe, and it also sells a managed CDN deployed inside a customer's own network, managed WAF, bot and DDoS protection. Pricing is usage-based with free monthly allowances on most products, while security products are quoted. See the Fastly alternatives page for comparisons.
- Best for: engineering-led teams and media companies that need programmable delivery.
- Watch out for: usage-based pricing across several products takes modelling, and security is sold on quote.
3. Amazon CloudFront: best CDN if your stack already runs on AWS
Amazon CloudFront is the content delivery network from AWS that caches static and dynamic content at AWS edge locations and forwards cache misses to an origin such as an S3 bucket or web server. It integrates with AWS WAF, AWS Shield, AWS Certificate Manager, CloudFront Functions and Lambda@Edge.
The catalogue lists flat-rate plans per distribution with a free tier, plus custom and pay-as-you-go options. DNS is a separate service, Amazon Route 53, so a Cloudflare setup becomes several AWS services.
- Best for: sites and APIs already hosted on AWS that want one bill and one set of permissions.
- Watch out for: you assemble CDN, DNS and firewall from separate AWS services, and it is closed and hosted only.
4. Vercel: best replacement for hosting a front end on the edge
Vercel is a cloud platform for deploying web applications, from the company that maintains Next.js, with a global CDN, serverless compute and Git-based deployments. If you used Cloudflare Pages or Workers to host a front end, Vercel covers a similar job with deploys tied to your Git repository.
Its catalogue entry lists Fluid Compute for functions, observability and security tools, and AI tooling. There is a free Hobby plan, and Pro is priced per developer seat with usage credit.
- Best for: Next.js and React teams that want deploys and a CDN handled together.
- Watch out for: per-seat pricing plus usage, and no self-hosted edition. See the Heroku alternatives guide for other app hosting.
5. Netlify: best for deploy previews and static or Jamstack sites
Netlify is a web hosting and deployment platform with deploy previews, serverless functions, a built-in database option and an edge network. It targets marketing sites, ecommerce stores, web apps and internal tools.
The catalogue shows a free plan with a monthly credit limit, then Personal and Pro plans and a custom Enterprise tier. It replaces the hosting side of Cloudflare, not DNS filtering or Zero Trust.
- Best for: teams that review every change through a deploy preview.
- Watch out for: usage is metered in credits on the free plan, and it is closed and hosted only.
6. Deno Deploy: best edge hosting for JavaScript and TypeScript on Deno
Deno Deploy is an edge hosting service from the creators of the Deno runtime that runs JavaScript and TypeScript applications on globally distributed infrastructure without servers to manage. It overlaps with Cloudflare Workers for projects built on Deno.
A free plan covers personal projects, with paid tiers above it. It is proprietary, with no self-hosted edition, and Deno documents current features and limits on its own site.
- Best for: projects that already use Deno and want a deploy target at the edge.
- Watch out for: it fits the Deno ecosystem, so code written for another runtime may need changes.
7. Tailscale: best for private access to servers and devices
Tailscale is a mesh VPN and zero-trust network built on WireGuard that connects devices and services with identity-based access. For Cloudflare Tunnel and Zero Trust users who mostly need private access, it lets you reach services privately instead of publishing them.
Use cases include a business VPN, Kubernetes networking and CI/CD connectivity. Enlisted lists the hosted product as proprietary, with a separate listing for the open-source client, and there is a free Personal plan. The full set of options is in the Tailscale alternatives guide.
- Best for: reaching servers, homelabs and internal apps without opening inbound ports.
- Watch out for: it connects private networks and does not act as a CDN or web application firewall for public sites.
8. Pangolin: best open-source tunnelled access with a reverse proxy
Pangolin is an open-source access platform on WireGuard that combines a zero-trust VPN, a zero-trust reverse proxy, privileged access control and an identity-aware AI gateway. The project compares its idea to Cloudflare One, Zscaler and Prisma, and argues that it is open and light enough to self-host.
It can run self-hosted or as Pangolin Cloud, with a free tier for small teams. The README describes dual licensing under AGPL-3 and a commercial licence, so read the terms for your use.
- Best for: exposing self-hosted and internal services through identity-aware tunnels, as a Cloudflare Tunnel replacement.
- Watch out for: the dual licence needs checking for commercial use, and self-hosting means running the server that terminates the tunnels.
9. frp: best simple open-source reverse tunnel
frp is an open-source reverse proxy, written in Go under Apache-2.0, that makes a machine behind a NAT or firewall reachable from the internet over TCP, UDP, HTTP and HTTPS. It also offers a peer-to-peer connect mode and routes internal web apps to custom domains.
Typical setups include SSH into a home or office machine, sharing a local development server and publishing a homelab service through a public server. Configuration is by files, with a server dashboard and Prometheus support.
- Best for: developers and homelab users who want a small tunnel they control.
- Watch out for: you need a public server to run the frp server, and there is no built-in CDN, WAF or DDoS protection.
10. Caddy: best self-hosted web server with automatic HTTPS
Caddy is an extensible web server and reverse proxy written in Go under Apache-2.0 that obtains and renews TLS certificates through Let's Encrypt and ZeroSSL automatically. It serves HTTP/1.1, 2 and 3 by default and covers the HTTPS termination side of what Cloudflare does for an origin.
Configuration can use a simple Caddyfile or native JSON with a JSON API for dynamic changes, and Caddy can run a local certificate authority for internal names. It ships as a single binary for macOS, Linux and Windows.
- Best for: small teams and homelabs that want HTTPS and routing with little setup.
- Watch out for: it runs where you install it, so there is no global edge network or flood absorption.
11. Traefik: best reverse proxy for Docker and Kubernetes
Traefik is a cloud-native reverse proxy and load balancer, written in Go under MIT, that configures itself from orchestrators. It listens to Docker, Docker Swarm, Kubernetes, Consul, Etcd, Rancher v2 and Amazon ECS and creates routes as services change, without restarts.
It supports Let's Encrypt certificates and has a web UI to inspect routes. Traefik Proxy is free and open source, while the Traefik Hub API gateway and management products are paid with prices requested from the vendor.
- Best for: container platforms where services come and go and routing should follow.
- Watch out for: it is a proxy and load balancer, not a firewall or CDN, so add a WAF if you need one.
12. BunkerWeb: best open-source WAF to put in front of your apps
BunkerWeb is an open-source web application firewall built on NGINX that acts as a reverse proxy with a web interface and a plugin system. It aims to make web services secure by default and filters requests before they reach your application. It is licensed under AGPL-3.0.
It deploys on Linux, Docker, Swarm and Kubernetes, and its repository topics mention ModSecurity, anti-bot protection, DNS blocklists and Let's Encrypt. A free open-source edition exists, with paid self-hosted plans and a managed cloud above it.
- Best for: self-hosted sites that want Cloudflare-style WAF rules on their own infrastructure.
- Watch out for: it filters at your server, so network-level floods still need your host or an upstream provider.
Other options worth a look
- Enterprise delivery and security: Akamai covers content delivery, web security and edge compute for large organisations, Imperva sells WAF, bot and DDoS protection, and F5 sells load balancing and WAF products. All are closed source and hosted or quoted. See the Akamai alternatives page.
- CDN with security: Gcore offers CDN, DNS, edge cloud and a WAAP plan with a free tier.
- Open-source security tools: SafeLine is a self-hosted WAF under GPL-3.0, CrowdSec blocks malicious IPs using a shared community blocklist, and ModSecurity is a long-standing WAF engine for Apache, IIS and Nginx.
- Bot protection: DataDome and HUMAN Security are commercial bot and fraud services.
- Web servers: NGINX is a BSD-licensed web server, reverse proxy and cache, and Nginx Proxy Manager adds a web interface and free certificates.
- DNS: PowerDNS and Technitium DNS Server are open-source DNS servers you host, and Route 53 is the AWS option.
- More tunnels and zero trust: Zrok shares services without port forwarding, Octelium is a self-hosted zero-trust platform, and Cloudflare Zero Trust is the product you may be replacing. See the Cloudflare Zero Trust alternatives page.
Which Cloudflare alternative should you choose?
| If you need | Pick |
|---|---|
| A hosted CDN with simple usage billing | Bunny.net |
| A programmable CDN and edge logic | Fastly |
| A CDN inside an AWS stack | Amazon CloudFront |
| A host for a Next.js or React front end | Vercel |
| Deploy previews for static and Jamstack sites | Netlify |
| Edge hosting for Deno apps | Deno Deploy |
| Private access to servers and devices | Tailscale |
| Open-source tunnels with identity-aware access | Pangolin |
| A small reverse tunnel for one service | frp |
| HTTPS and routing on your own server | Caddy |
| Routing for Docker or Kubernetes | Traefik |
| A WAF you host yourself | BunkerWeb or SafeLine |
Browse every Cloudflare alternative in the catalogue, or the wider networking category.
Splitting Cloudflare into parts
Replacing everything at once is rarely necessary. Many teams keep Cloudflare for DNS and CDN and move one job, such as tunnels to a home server, to Pangolin or Tailscale. Others keep their DNS with a cloud provider and put Caddy or Traefik in front of the origin.
Whichever route you take, test failover before you cut over: lower DNS time-to-live values in advance, keep a way back to the old setup, and check that your TLS certificates and firewall rules apply on the new path. For monitoring the result, see the Datadog alternatives guide.
Cloudflare alternatives: pricing compared
Plans and list prices from each vendor's pricing page. Prices change, so confirm the current price on the vendor's page before you buy.
| Tool | Free option | Paid plans | Source |
|---|---|---|---|
| Free |
| Pricing page Checked 2 Oct 2026 | |
| Free trial |
| Pricing page Checked 2 Oct 2026 | |
| Free plan |
| Pricing page Checked 2 Oct 2026 | |
| Free plan |
| Pricing page Checked 2 Oct 2026 | |
| Free planFree trial |
| Pricing page Checked 2 Oct 2026 | |
| Free plan |
| Pricing page Checked 2 Oct 2026 | |
| Free planFree trial |
| Pricing page Checked 2 Oct 2026 | |
| Free (open source)Self-hostable |
| Pricing page Checked 2 Oct 2026 | |
| frp | Free (open source)Self-hostable | No hosted version | |
| Free (open source)Self-hostable | No hosted version | ||
| Free (open source)Self-hostable |
Traefik Hub API Gateway, Traefik Hub API ManagementPrices on the vendor's page | Pricing page Checked 2 Oct 2026 | |
| Free (open source)Self-hostable |
| Pricing page Checked 2 Oct 2026 |
List prices from each vendor's public pricing page on the date shown. Annual billing is often cheaper, and taxes, usage and transaction fees aren't included. Open-source tools cost nothing to self-host beyond your own server.
Frequently asked questions
- What is the best alternative to Cloudflare?
- There is no single replacement, because Cloudflare bundles a CDN, DNS, DDoS protection, a web application firewall, Zero Trust access and edge computing. Bunny.net and Fastly replace the CDN, Vercel and Netlify replace edge hosting, Tailscale and Pangolin replace tunnels and private access, and Caddy with BunkerWeb replaces the proxy and WAF on your own servers.
- Is there a free alternative to Cloudflare?
- Caddy, Traefik and BunkerWeb's open-source edition are free to self-host, and CrowdSec is a free open-source security engine. Among hosted services, Vercel, Netlify, Deno Deploy and Amazon CloudFront list free plans, and Pangolin and Tailscale have free tiers for small teams. Free plans have usage limits, so check each vendor's current terms.
- What are the best open-source alternatives to Cloudflare?
- Caddy and Traefik are open-source reverse proxies, BunkerWeb and SafeLine are open-source web application firewalls, and CrowdSec blocks malicious IPs using a shared community blocklist. For tunnels and zero-trust access, Pangolin and frp are open source. None of them provides a global edge network on its own.
- What replaces Cloudflare Tunnel or Cloudflare Zero Trust?
- Tailscale and Pangolin are the closest alternatives, both built on WireGuard with identity-based access. NetBird, Twingate and Zrok cover similar ground, and frp is a simpler open-source reverse tunnel for reaching a service behind a firewall. Which one fits depends on whether you need private device access or public web exposure.
- Can I replace Cloudflare for DDoS protection?
- Hosted providers such as Fastly, Akamai, Gcore and Amazon CloudFront with AWS Shield sell DDoS protection at their own network edge. Open-source tools such as BunkerWeb, SafeLine and CrowdSec filter traffic at your server, which does not add network capacity. For large floods you still need an upstream provider.