The WAF is great, but recent events have made it obvious that having a single point of failure entirely defeats the purpose of DNS being a distributed/decentralized service.
Is anyone doing anything creative here? We like the features that the WAF provides - but not at the expense of global outages. If you have a 3 9s availability SLA, you've just blown 90% of your allotted downtime because of Cloudflare's WAF.
open-appsec (by checkpoint), their proxy/gateway integration and your favorite firewall daemon:
https://docs.openappsec.io/getting-started/start-with-linux
appsec (by crowdsec), their proxy/gateway integration and your favorite firewall daemon:
https://docs.crowdsec.net/u/getting_started/installation/lin...
You can balance traffic to external networks or clouds with it too.