The platform
Edge Cloud is a product front over GA shared services — not a greenfield stack chasing parity. Each group below is a real service with a contracted API; open any card for the sub-capabilities, the real endpoints and a worked example.
Capability map
Edge Cloud fronts 7 GA shared services (287 application operations) out of the platform's 60 services / 1,420 operations. Nothing here is greenfield — every capability is a real, contracted endpoint.
RustFS, productized as public S3/R2 — with zero-egress-to-edge accounting.
Functions with immutable versions, rollback and a real WASM datapath — plus tiered cache and edge WAF.
Signed zones, health-based steering, and 99.999% serve-stale through an origin incident.
Mesh overlay, native WireGuard, full SASE and SD-WAN — unified by the UPO policy compiler.
Gateway admission and edge WAF at the perimeter; detections-as-code and guard-railed containment behind it.
PoPs, BGP sessions, anycast policies and failover drills — the GitOps-managed footprint the edge runs on.
How it fits together
A single edge request touches most of the suite in order — and every hop is on one sovereign control plane, one identity, one tenancy.
GeoDNS + health steering points the client at the nearest healthy PoP.
The PoP fleet — BGP sessions, anycast policies — accepts the connection.
Gateway admission + edge WAF and DDoS scrubbing screen the request.
The owning function executes on the WASM datapath, cache class applied.
Bound R2 bucket serves the bytes — intra-edge, zero-rated egress.
SS-26 (SASE / Zero Trust) governs private access to the same plane in parallel, and SS-28 SecOps observes all of it. Cloudflare can match individual boxes; it cannot put origin and edge on one plane.