7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Alternatives

Best Cloudflare Alternatives in 2026: CDN, Edge Hosting, Tunnels and Self-Hosted Proxies

Cloudflare alternatives by job: CDN, edge hosting, tunnels and zero trust, or a self-hosted proxy and WAF. Compare Bunny.net, Fastly, Pangolin, Caddy and more.

By , founder of NQM Studio LTDUpdated 11 min read

The best Cloudflare alternatives depend on which part of Cloudflare you actually use. Bunny.net and Fastly replace the CDN, Vercel and Netlify replace Pages-style hosting, Tailscale and Pangolin replace tunnels and private access, and Caddy with BunkerWeb replaces the proxy and firewall layer on servers you control.

Cloudflare is a bundle of services, so this guide is organised by job: CDN, edge hosting, tunnels and zero-trust access, and self-hosted proxies and web application firewalls. The table shows live licence, self-hosting, pricing and GitHub data for the main picks.

ToolTypeCategorySelf-hostPricingGitHub
CloudflareSaaSNetworking & VPNNoFreeClosed source
Bunny.netSaaSHosting & PaaSNoPaidClosed source
FastlySaaSNetworking & VPNNoFree planClosed source
Amazon CloudFrontSaaSNetworking & VPNNoFree plan · from $15/moClosed source
VercelSaaSHosting & PaaSNoFree plan · from $20/mo per seatClosed source
NetlifySaaSHosting & PaaSNoFree plan · from $9/moClosed source
TailscaleSaaSNetworking & VPNNoFree plan · from $8/mo per seatClosed source
PangolinOpen sourceNetworking & VPNYesFree · cloud from $4/mo per seat★ 23k
frpOpen sourceNetworking & VPNYesFree (open source)★ 110k
CaddyOpen sourceNetworking & VPNYesFree (open source)★ 76k
TraefikOpen sourceNetworking & VPNYesFree (open source)★ 65k
BunkerWebOpen sourceSecurityYesFree (open source)★ 11k

Live data from Enlisted: GitHub stats sync daily; pricing comes from each vendor's pricing page.

Why people look for Cloudflare alternatives

Cloudflare is a global edge platform that sits in front of websites and applications. Its core services are a content delivery network, DNS, unmetered DDoS protection, universal SSL certificates and a web application firewall, managed from one dashboard, and it also sells a Zero Trust suite and a compute and storage platform. Common reasons to compare it with other tools:

  • You only need one piece. If the real job is hosting a front end, tunnelling to a home server or filtering bad requests, a focused tool can be simpler than a platform with dozens of products.
  • Plan tiers gate features. The catalogue lists Free, Pro, Business and custom Contract plans, and the higher website plans add features such as lossless image optimisation, PCI DSS 4.0 compliance and an uptime SLA. Compute, storage and AI are priced on usage.
  • It is closed source and hosted only. Enlisted lists no self-hosted version, and traffic for a proxied site passes through Cloudflare's network.
  • One account holds DNS, caching and security rules. Some teams prefer to spread those across vendors or keep parts on their own infrastructure.
  • Zero Trust is a separate product with its own pricing. Cloudflare's Zero Trust has a free tier up to a user cap, then per-user pricing, which is a different model from the open-source options below.

How we picked

A tool made this list if it replaces at least one job Cloudflare does: CDN, edge hosting, tunnelled access, reverse proxying or web application firewalling. Open-source projects needed a clear licence and recent GitHub activity, and Enlisted shows whether each can be self-hosted. Published pricing and a free plan are what brought the hosted products in. Catalogue data and vendor documentation supply the facts, and nothing was run or measured for this guide. See how Enlisted ranks tools.

Which part of Cloudflare are you replacing?

Name the job first, because the answer changes completely.

  • CDN and caching: copies of your content served from locations near visitors. Bunny.net, Fastly and Amazon CloudFront are hosted CDNs.
  • Edge hosting and functions: running a site or code on a managed platform. Vercel, Netlify and Deno Deploy do this.
  • Tunnels and zero-trust access: reaching a private service without opening ports, or giving staff identity-based access. Tailscale, Pangolin and frp cover this, and the Tailscale alternatives guide goes deeper.
  • Reverse proxy and WAF: software that terminates HTTPS, routes requests and blocks attacks on your own server. Caddy, Traefik and BunkerWeb fit here.
  • DNS: hosted DNS from a cloud provider such as Amazon Route 53, or software such as PowerDNS you run yourself.

Self-hosted software cannot copy one thing a CDN sells: servers in many places. A proxy on your own machine runs where you put it, so keep a hosted CDN or upstream protection if distribution or flood resistance matters.

1. Bunny.net: best pay-as-you-go CDN with storage and DNS

Bunny.net is a content delivery network with edge storage, DNS, image optimisation, video streaming and edge compute, sold on a pay-as-you-go basis. Where Cloudflare packages plans by tier, Bunny's catalogue entry lists CDN traffic billed per gigabyte by region with no request fees and a free trial rather than a free plan.

Beyond Bunny CDN, the catalogue lists SSD-backed storage, Bunny DNS, an image Optimizer, Bunny Stream for video with DRM, Edge Scripting, Magic Containers, a SQLite-compatible database and Bunny Shield for security. It is proprietary and vendor-hosted.

  • Best for: websites, downloads and video delivery that want simple, usage-based CDN billing.
  • Watch out for: there is no free plan in Enlisted's data, and you should compare Bunny Shield with the WAF and DDoS controls you depend on.

2. Fastly: best programmable CDN for teams that want edge control

Fastly is an edge cloud platform that combines a programmable CDN with security, serverless compute and observability. It is aimed at teams that want to control caching and logic at the edge instead of only at the origin server.

Its areas are Deliver, Secure, Deploy and Observe, and it also sells a managed CDN deployed inside a customer's own network, managed WAF, bot and DDoS protection. Pricing is usage-based with free monthly allowances on most products, while security products are quoted. See the Fastly alternatives page for comparisons.

  • Best for: engineering-led teams and media companies that need programmable delivery.
  • Watch out for: usage-based pricing across several products takes modelling, and security is sold on quote.

3. Amazon CloudFront: best CDN if your stack already runs on AWS

Amazon CloudFront is the content delivery network from AWS that caches static and dynamic content at AWS edge locations and forwards cache misses to an origin such as an S3 bucket or web server. It integrates with AWS WAF, AWS Shield, AWS Certificate Manager, CloudFront Functions and Lambda@Edge.

The catalogue lists flat-rate plans per distribution with a free tier, plus custom and pay-as-you-go options. DNS is a separate service, Amazon Route 53, so a Cloudflare setup becomes several AWS services.

  • Best for: sites and APIs already hosted on AWS that want one bill and one set of permissions.
  • Watch out for: you assemble CDN, DNS and firewall from separate AWS services, and it is closed and hosted only.

4. Vercel: best replacement for hosting a front end on the edge

Vercel is a cloud platform for deploying web applications, from the company that maintains Next.js, with a global CDN, serverless compute and Git-based deployments. If you used Cloudflare Pages or Workers to host a front end, Vercel covers a similar job with deploys tied to your Git repository.

Its catalogue entry lists Fluid Compute for functions, observability and security tools, and AI tooling. There is a free Hobby plan, and Pro is priced per developer seat with usage credit.

  • Best for: Next.js and React teams that want deploys and a CDN handled together.
  • Watch out for: per-seat pricing plus usage, and no self-hosted edition. See the Heroku alternatives guide for other app hosting.

5. Netlify: best for deploy previews and static or Jamstack sites

Netlify is a web hosting and deployment platform with deploy previews, serverless functions, a built-in database option and an edge network. It targets marketing sites, ecommerce stores, web apps and internal tools.

The catalogue shows a free plan with a monthly credit limit, then Personal and Pro plans and a custom Enterprise tier. It replaces the hosting side of Cloudflare, not DNS filtering or Zero Trust.

  • Best for: teams that review every change through a deploy preview.
  • Watch out for: usage is metered in credits on the free plan, and it is closed and hosted only.

6. Deno Deploy: best edge hosting for JavaScript and TypeScript on Deno

Deno Deploy is an edge hosting service from the creators of the Deno runtime that runs JavaScript and TypeScript applications on globally distributed infrastructure without servers to manage. It overlaps with Cloudflare Workers for projects built on Deno.

A free plan covers personal projects, with paid tiers above it. It is proprietary, with no self-hosted edition, and Deno documents current features and limits on its own site.

  • Best for: projects that already use Deno and want a deploy target at the edge.
  • Watch out for: it fits the Deno ecosystem, so code written for another runtime may need changes.

7. Tailscale: best for private access to servers and devices

Tailscale is a mesh VPN and zero-trust network built on WireGuard that connects devices and services with identity-based access. For Cloudflare Tunnel and Zero Trust users who mostly need private access, it lets you reach services privately instead of publishing them.

Use cases include a business VPN, Kubernetes networking and CI/CD connectivity. Enlisted lists the hosted product as proprietary, with a separate listing for the open-source client, and there is a free Personal plan. The full set of options is in the Tailscale alternatives guide.

  • Best for: reaching servers, homelabs and internal apps without opening inbound ports.
  • Watch out for: it connects private networks and does not act as a CDN or web application firewall for public sites.

8. Pangolin: best open-source tunnelled access with a reverse proxy

Pangolin is an open-source access platform on WireGuard that combines a zero-trust VPN, a zero-trust reverse proxy, privileged access control and an identity-aware AI gateway. The project compares its idea to Cloudflare One, Zscaler and Prisma, and argues that it is open and light enough to self-host.

It can run self-hosted or as Pangolin Cloud, with a free tier for small teams. The README describes dual licensing under AGPL-3 and a commercial licence, so read the terms for your use.

  • Best for: exposing self-hosted and internal services through identity-aware tunnels, as a Cloudflare Tunnel replacement.
  • Watch out for: the dual licence needs checking for commercial use, and self-hosting means running the server that terminates the tunnels.

9. frp: best simple open-source reverse tunnel

frp is an open-source reverse proxy, written in Go under Apache-2.0, that makes a machine behind a NAT or firewall reachable from the internet over TCP, UDP, HTTP and HTTPS. It also offers a peer-to-peer connect mode and routes internal web apps to custom domains.

Typical setups include SSH into a home or office machine, sharing a local development server and publishing a homelab service through a public server. Configuration is by files, with a server dashboard and Prometheus support.

  • Best for: developers and homelab users who want a small tunnel they control.
  • Watch out for: you need a public server to run the frp server, and there is no built-in CDN, WAF or DDoS protection.

10. Caddy: best self-hosted web server with automatic HTTPS

Caddy is an extensible web server and reverse proxy written in Go under Apache-2.0 that obtains and renews TLS certificates through Let's Encrypt and ZeroSSL automatically. It serves HTTP/1.1, 2 and 3 by default and covers the HTTPS termination side of what Cloudflare does for an origin.

Configuration can use a simple Caddyfile or native JSON with a JSON API for dynamic changes, and Caddy can run a local certificate authority for internal names. It ships as a single binary for macOS, Linux and Windows.

  • Best for: small teams and homelabs that want HTTPS and routing with little setup.
  • Watch out for: it runs where you install it, so there is no global edge network or flood absorption.

11. Traefik: best reverse proxy for Docker and Kubernetes

Traefik is a cloud-native reverse proxy and load balancer, written in Go under MIT, that configures itself from orchestrators. It listens to Docker, Docker Swarm, Kubernetes, Consul, Etcd, Rancher v2 and Amazon ECS and creates routes as services change, without restarts.

It supports Let's Encrypt certificates and has a web UI to inspect routes. Traefik Proxy is free and open source, while the Traefik Hub API gateway and management products are paid with prices requested from the vendor.

  • Best for: container platforms where services come and go and routing should follow.
  • Watch out for: it is a proxy and load balancer, not a firewall or CDN, so add a WAF if you need one.

12. BunkerWeb: best open-source WAF to put in front of your apps

BunkerWeb is an open-source web application firewall built on NGINX that acts as a reverse proxy with a web interface and a plugin system. It aims to make web services secure by default and filters requests before they reach your application. It is licensed under AGPL-3.0.

It deploys on Linux, Docker, Swarm and Kubernetes, and its repository topics mention ModSecurity, anti-bot protection, DNS blocklists and Let's Encrypt. A free open-source edition exists, with paid self-hosted plans and a managed cloud above it.

  • Best for: self-hosted sites that want Cloudflare-style WAF rules on their own infrastructure.
  • Watch out for: it filters at your server, so network-level floods still need your host or an upstream provider.

Other options worth a look

  • Enterprise delivery and security: Akamai covers content delivery, web security and edge compute for large organisations, Imperva sells WAF, bot and DDoS protection, and F5 sells load balancing and WAF products. All are closed source and hosted or quoted. See the Akamai alternatives page.
  • CDN with security: Gcore offers CDN, DNS, edge cloud and a WAAP plan with a free tier.
  • Open-source security tools: SafeLine is a self-hosted WAF under GPL-3.0, CrowdSec blocks malicious IPs using a shared community blocklist, and ModSecurity is a long-standing WAF engine for Apache, IIS and Nginx.
  • Bot protection: DataDome and HUMAN Security are commercial bot and fraud services.
  • Web servers: NGINX is a BSD-licensed web server, reverse proxy and cache, and Nginx Proxy Manager adds a web interface and free certificates.
  • DNS: PowerDNS and Technitium DNS Server are open-source DNS servers you host, and Route 53 is the AWS option.
  • More tunnels and zero trust: Zrok shares services without port forwarding, Octelium is a self-hosted zero-trust platform, and Cloudflare Zero Trust is the product you may be replacing. See the Cloudflare Zero Trust alternatives page.

Which Cloudflare alternative should you choose?

If you needPick
A hosted CDN with simple usage billingBunny.net
A programmable CDN and edge logicFastly
A CDN inside an AWS stackAmazon CloudFront
A host for a Next.js or React front endVercel
Deploy previews for static and Jamstack sitesNetlify
Edge hosting for Deno appsDeno Deploy
Private access to servers and devicesTailscale
Open-source tunnels with identity-aware accessPangolin
A small reverse tunnel for one servicefrp
HTTPS and routing on your own serverCaddy
Routing for Docker or KubernetesTraefik
A WAF you host yourselfBunkerWeb or SafeLine

Browse every Cloudflare alternative in the catalogue, or the wider networking category.

Splitting Cloudflare into parts

Replacing everything at once is rarely necessary. Many teams keep Cloudflare for DNS and CDN and move one job, such as tunnels to a home server, to Pangolin or Tailscale. Others keep their DNS with a cloud provider and put Caddy or Traefik in front of the origin.

Whichever route you take, test failover before you cut over: lower DNS time-to-live values in advance, keep a way back to the old setup, and check that your TLS certificates and firewall rules apply on the new path. For monitoring the result, see the Datadog alternatives guide.

Cloudflare alternatives: pricing compared

Plans and list prices from each vendor's pricing page. Prices change, so confirm the current price on the vendor's page before you buy.

ToolFree optionPaid plansSource
CloudflareFree
  • FreeFree
Pricing page Checked 2 Oct 2026
Bunny.netFree trial
  • CDN Standard - Europe & North America$0.01usage-based
  • CDN Standard - Asia & Oceania$0.03usage-based
  • CDN Standard - South America$0.045usage-based
  • CDN Standard - Middle East & Africa$0.06usage-based
  • +1 more
Pricing page Checked 2 Oct 2026
FastlyFree plan
  • Free usage tierFree
  • Full Site Delivery requests$0.01usage-based
  • Compute requests$0.50usage-based
  • Object Storage$0.02/ mo · usage-based
  • +2 more
Pricing page Checked 2 Oct 2026
Amazon CloudFrontFree plan
  • FreeFree
  • Pro$15/ mo
  • Business$200/ mo
  • Premium$1,000/ mo
  • +1 more
Pricing page Checked 2 Oct 2026
VercelFree planFree trial
  • HobbyFree
  • Pro$20/ seat / mo
  • EnterpriseCustom
Pricing page Checked 2 Oct 2026
NetlifyFree plan
  • FreeFree
  • Personal$9/ mo
  • Pro$20/ mo
  • EnterpriseCustom
Pricing page Checked 2 Oct 2026
TailscaleFree planFree trial
  • PersonalFree
  • Standard$8/ seat / mo
  • Premium$18/ seat / mo
  • EnterpriseCustom
Pricing page Checked 2 Oct 2026
PangolinFree (open source)Self-hostable
  • BasicFree
  • Team$4/ seat / mo
  • Business$9/ seat / mo
  • EnterpriseCustom
Pricing page Checked 2 Oct 2026
frpFree (open source)Self-hostableNo hosted version
CaddyFree (open source)Self-hostableNo hosted version
TraefikFree (open source)Self-hostable
  • Traefik Proxy Open SourceFree

Traefik Hub API Gateway, Traefik Hub API ManagementPrices on the vendor's page

Pricing page Checked 2 Oct 2026
BunkerWebFree (open source)Self-hostable
  • Open Source (Free)Free
  • Shield€49/ mo
  • Fortress€149/ mo
  • SentinelCustom
  • +1 more
Pricing page Checked 2 Oct 2026

List prices from each vendor's public pricing page on the date shown. Annual billing is often cheaper, and taxes, usage and transaction fees aren't included. Open-source tools cost nothing to self-host beyond your own server.

Frequently asked questions

What is the best alternative to Cloudflare?
There is no single replacement, because Cloudflare bundles a CDN, DNS, DDoS protection, a web application firewall, Zero Trust access and edge computing. Bunny.net and Fastly replace the CDN, Vercel and Netlify replace edge hosting, Tailscale and Pangolin replace tunnels and private access, and Caddy with BunkerWeb replaces the proxy and WAF on your own servers.
Is there a free alternative to Cloudflare?
Caddy, Traefik and BunkerWeb's open-source edition are free to self-host, and CrowdSec is a free open-source security engine. Among hosted services, Vercel, Netlify, Deno Deploy and Amazon CloudFront list free plans, and Pangolin and Tailscale have free tiers for small teams. Free plans have usage limits, so check each vendor's current terms.
What are the best open-source alternatives to Cloudflare?
Caddy and Traefik are open-source reverse proxies, BunkerWeb and SafeLine are open-source web application firewalls, and CrowdSec blocks malicious IPs using a shared community blocklist. For tunnels and zero-trust access, Pangolin and frp are open source. None of them provides a global edge network on its own.
What replaces Cloudflare Tunnel or Cloudflare Zero Trust?
Tailscale and Pangolin are the closest alternatives, both built on WireGuard with identity-based access. NetBird, Twingate and Zrok cover similar ground, and frp is a simpler open-source reverse tunnel for reaching a service behind a firewall. Which one fits depends on whether you need private device access or public web exposure.
Can I replace Cloudflare for DDoS protection?
Hosted providers such as Fastly, Akamai, Gcore and Amazon CloudFront with AWS Shield sell DDoS protection at their own network edge. Open-source tools such as BunkerWeb, SafeLine and CrowdSec filter traffic at your server, which does not add network capacity. For large floods you still need an upstream provider.