The platform

Six capability groups. Seven real services.

Edge Cloud is a product front over GA shared services — not a greenfield stack chasing parity. Each group below is a real service with a contracted API; open any card for the sub-capabilities, the real endpoints and a worked example.

6 capability groups7 shared services287 operations1420 of platform ops

Capability map

Every capability is a real, contracted endpoint set.

Edge Cloud fronts 7 GA shared services (287 application operations) out of the platform's 60 services / 1,420 operations. Nothing here is greenfield — every capability is a real, contracted endpoint.

SS-02 DBaaSheadline

Object storage — S3/R2

RustFS, productized as public S3/R2 — with zero-egress-to-edge accounting.

  • Buckets, versioning & lifecycle
  • Objects & prefix/delimiter listing
  • Multipart uploads
  • Access keys & presigned URLs
58 operationsDeep-dive →
SS-27 Edge

Edge compute & CDN

Functions with immutable versions, rollback and a real WASM datapath — plus tiered cache and edge WAF.

  • Functions & immutable versions
  • Routes & triggers
  • PoP placement & staged rollout
  • Bindings (r2 / kv / env)
45 operationsDeep-dive →
SS-25 DNS

DNS & traffic steering

Signed zones, health-based steering, and 99.999% serve-stale through an origin incident.

  • Zones & records
  • DNSSEC lifecycle
  • Health-based steering
  • Atomic publish & serve-stale
14 operationsDeep-dive →
SS-26 Network

SASE / network security

Mesh overlay, native WireGuard, full SASE and SD-WAN — unified by the UPO policy compiler.

  • Mesh overlay & native WireGuard
  • Tailnet (Tailscale-style access)
  • SASE — SWG, CASB, DLP, FWaaS, ZTNA
  • SD-WAN
82 operationsDeep-dive →
SS-07 Gateway · SS-28 SecOps

Security & WAF

Gateway admission and edge WAF at the perimeter; detections-as-code and guard-railed containment behind it.

  • Gateway admission & entitlements (SS-07)
  • Edge WAF & DDoS scrubbing (SS-27)
  • Detections-as-code (SS-28)
  • Sensors & hunts
65 operationsDeep-dive →
SS-57 CloudPoP

PoP / anycast control

PoPs, BGP sessions, anycast policies and failover drills — the GitOps-managed footprint the edge runs on.

  • PoPs, blueprints & providers
  • BGP sessions & routes
  • Anycast & traffic policies
  • GitOps change control
23 operationsDeep-dive →

How it fits together

One request, the whole plane.

A single edge request touches most of the suite in order — and every hop is on one sovereign control plane, one identity, one tenancy.

1
SS-25

DNS resolves

GeoDNS + health steering points the client at the nearest healthy PoP.

2
SS-57

Anycast lands it

The PoP fleet — BGP sessions, anycast policies — accepts the connection.

3
SS-07 · SS-27

Security admits

Gateway admission + edge WAF and DDoS scrubbing screen the request.

4
SS-27

Edge compute runs

The owning function executes on the WASM datapath, cache class applied.

5
SS-02

Object served

Bound R2 bucket serves the bytes — intra-edge, zero-rated egress.

SS-26 (SASE / Zero Trust) governs private access to the same plane in parallel, and SS-28 SecOps observes all of it. Cloudflare can match individual boxes; it cannot put origin and edge on one plane.

Next

See it running, or read the endpoints.