Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (33%)
- Cloud Services (29%)
- Web Tools (17%)
- Hosting (13%)
- E-mail (8%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 6 hours ago |
|
|
Cloud Services | 1 day ago |
|
|
Cloud Services | 17 days ago |
|
|
Hosting | 20 days ago |
|
|
Domains | 1 month ago |
|
|
Cloud Services | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
FiP MrMarki (@MrMarkilys) reported@SnowApe84586 @TrvthfvlTreason Cloudflare has allowed CP sites to be run whilst being protected by their DDoS protections. But the doxing* site are the bad guys. Doxing literally is public info, retard.
-
27 — floofy/acc 🦝📈🚀 (@happysmash27) reported@mhartl @NickCalabs Did Cloudflare go down or something?? I get the main reference, but haven't heard any news about Cloudflare yet.
-
Sulfur (@sulfurscales) reportedhere's how to BUILD a phone farm for tiktok that costs under a cent per post instead of $0.5-3 per piece 10 old iphones running locally off a mac, iphone 7 through iphone 11. 2-3M views a month across 20 accounts, 30-40 posts a day, all targeting the us while running physically outside it. best single post hit 1.1M, median sits around 5000. 2000 views turning into 1 install, 5% of those installs converting to paid, best days pulling 80 installs and 5 new customers the problem being solved: every slideshow tool on the market charges per piece, reelfarm and the rest land around $0.5-3. at 40 posts a day that's $500+/month before you even know which angle works. a proper testing phase at that rate runs $2-3k before you get any signal, and none of those tools guarantee quality even with good prompts the fix: build the generator yourself. python scripts, settings files per phone, no database, no cloud, no saas. runs entirely off a laptop the pipeline breaks into a few agents. a parser that pulls content across the niche and ocr's it. a reference builder that turns that into reusable angles. a slide and video generator that mixes pre built pieces with new hooks and captions, no llm needed for the actual generation. a daily poster that pushes content to each phone through shortcuts so there's no manual airdrop, content lands straight in the clipboard ready to paste. a calendar and analytics scraper once excel stopped being enough past 20-30 accounts phones were $50 each, bought old. an iphone 7 on ios 15 matched an iphone 11 on ios 26 for performance, newer hardware didn't move the needle at all. the actual variable is content, not device each phone runs 30+ settings from an internal library before it touches tiktok, and the exact list differs slightly per model and ios version. dns leaks patched, webrtc leaks closed, ip tied to a specific location so the account can't be traced back to a base photos get run through a module that rewrites exif data to match a real iphone camera roll. camera dimensions, mb size, live photo data, geo tag matching that specific phone's ip, dozens of parameters layered in. this is the part that actually moves rankings, tiktok ranks native capture higher than obvious stock or ai output, and none of it triggers an ai generated label after posting video repurposing works too, same clip with a different hook counts as a new video to tiktok once it's run through the pipeline posting 20 slides across accounts takes 35 minutes total with shortcuts handling the transfer running cost: $40/month proxies, $40/month llm subscriptions, hosting free on cloudflare. one time setup was ~$300 for hardware plus ~$300 for courses, on top of $500 for the phones themselves. total spend so far sits around $1k, three months to build, now running at 2 hours a day android was tested and dropped. cloud androids passing google's full integrity check cost more per month than buying a used iphone outright, and still underperformed, the cheaper android tiers did worse. rented androids also couldn't run a second account on the same device, which killed the option outright account health has been mostly clean on ios, androids were the ones getting banned. one attempt at running tiktok on a jailbroken ios 16 device got logged out fast, no ban, but enough of a signal to not push jailbreak further until there's a way to test it without burning dozens of accounts first what's still unexplained: two accounts running nearly identical content and setup, one hits 1M on post 3, the other barely moves. same hook photos with minor crop or filter changes keep working, no clean read on whether that step is even necessary. one of the best performing accounts doesn't have us dns at all and still pulls more us traffic than accounts that do. no clean answer for any of it, just logged as unresolved and moved on next step is pushing toward phones running 24/7, automated swiping included, and expanding past tiktok into instagram reels
-
The SaaStronaut | AEO/SEO & Reddit Marketing (@TheSaastronaut) reportedHad a $8k/mo client freak out recently bc someone cloned their website, started impersonating them, and was phishing prospects to do God knows what. This clone was ranking page 1 too bc of the name match Client sends the duplicate site to me asking if it was us doing some SEO trick, I said no He said Okay, but was visibly worried This was a rare and unconventional situation And handling client impersonation isn't in a typical SEO's wheelhouse, contract, or scope of work... We had no contractual obligation to look into this or try and fix this But the issue was in search results, and we were the search visibility partner. I saw it as our responsibility whether it was explicitly written or not So, I had the team: 1) Preserve full technical evidence, screenshots, source code, DNS records, forms, hosting details, and timestamps. 2) Sent a takedown notice to the origin host, Omegatech. 3) Submitted abuse reports to Cloudflare and NameSilo. 4) Reported the domain to Google Safe Browsing and Microsoft SmartScreen as an impersonation/phishing site. After our reports, the site was taken down I've done soooo much out of scope work for clients and never ever mention it to them. If you're my client, we're going to take care of you. That's why average client lifecycle with Kingmaker is 2+ years
-
Vinny (@hot_town) reportedDamn. Cloudflare just became 100x cooler for me.
-
Lockendrik (@Lockendrik41) reportedSomeone has to notify Cloudflare (SoyBooru's registrar) about the SoyBooru's current state. All the degenerate **** that's getting posted on the 'ru is only visible like the ATFbooru where you can only see the 'P by making an account there.
-
SPEKULATOR (@__spekulator__) reported@KennyJohnsonATX @Cloudflare oauth pre-registration is a real unlock for cloudflare's mcp server support. they can now hit slack and github without waiting on dcr support from them.
-
Albert Clownstein (@ClownYouAllDay) reported@NotNordgaren What ******** is this thread? Doesn’t everyone know you have to call cloudflare for localhost issues if using cloudflare dns settings on your pc so they can issue a new certificate for it?
-
U N C L E BIGBAY ✨ (@unclebigbay143) reportedEvery external service increases your blast radius. Redis Stripe Cloudflare OpenAI Email providers The more services your request depends on, the more ways it can fail. Always ask: "If this service disappears for an hour, does my product still work?"
-
Mike Clarke (@mikeclarke) reportedwrote about our experience building the Modem MCP server. we're trying a thing where we avoid a bunch of `get_<object>` tools and instead commit to a general-purpose `search_modem` tool that efficiently retrieves data based on natural language search (inspired by the @getsentry and @Cloudflare MCPs among others) it turns out synthesizing data from a constellation of customer feedback sources is also way more token efficient, cool to see.
-
John Spurlock (@johnspurlock) reported@CherryJimbo @Cloudflare @CloudflareDev growing in terms of customer usage etc
-
Med (@medhansh) reportedHow to make every Mac, server & cloud worker you own feel like one computer: ====== NETWORKING ====== - Tailscale: Connects all your machines into one private network. SSH into your home desktop from anywhere with no port forwarding and nothing exposed publicly - Thunderbolt Bridge: Connects two nearby Macs directly through a Thunderbolt cable. You get tens of Gbps and sub-ms latency without buying networking gear - 2.5/10GbE: The wired alternative when Thunderbolt isn’t practical. Use it when normal gigabit networking becomes the bottleneck - Cloudflare Tunnel: Gives a local service a public URL without opening a port on your router. Useful for websites, APIs and dashboards other people need to reach - ngrok: Creates a temporary public URL in seconds. Perfect for testing webhooks against something running locally ====== REMOTE ACCESS ====== - SSH + `~/.ssh/config`: Lets you create short names and reusable settings for remote machines. Type `ssh studio` instead of remembering usernames, IP addresses and ports - `ControlMaster auto`: Keeps one SSH connection open and reuses it. New terminals connect instantly instead of negotiating a fresh session every time - Mosh: SSH that survives your Wi-Fi dropping. Close the laptop, open it on a train, switch networks and the same terminal session reconnects - tmux: Keeps programs running after you disconnect. Start a long agent job, close your laptop and reconnect to it later - tmux-resurrect + continuum: Saves and restores your tmux sessions after the machine itself reboots - VS Code / Cursor Remote SSH: The editor runs on your laptop while the code, terminal and language server run on the remote machine. It feels local without syncing files - code-server: Runs VS Code inside a browser. Useful when you need to work from an iPad or a computer without your development setup - macOS Screen Sharing: Built-in remote control between Macs. On the same network it’s fast enough for normal desktop work - Sunshine + Moonlight: Streams a remote desktop using game-streaming technology. Use it when you need much lower latency than normal screen sharing ====== SERVING ====== - Tailscale Serve: Gives a local service a private HTTPS URL that only devices on your Tailscale network can open - Tailscale Funnel: Takes that private service and makes it reachable from the public internet. Useful for receiving webhooks on a home machine - Caddy: A web server and reverse proxy that gets HTTPS certificates automatically. Two lines of config, real certificates, no Let’s Encrypt homework - Cloudflare Tunnel: Better when you want public traffic to pass through Cloudflare before reaching your machine ====== FILES ====== - ***: Tracks changes, understands conflicts and lets each agent work on a separate branch. Use *** for code that agents edit, not a generic sync tool - *** worktrees: Opens multiple branches from the same repository as separate folders. Every agent gets its own workspace without cloning the repo again - Jujutsu (`jj`): A ***-compatible version-control system designed around easier rebasing, undoing and concurrent work. Worth trying when many agents produce branches at once - SMB: Shares a folder from one machine so another can mount it like a local drive. The easiest answer for two Macs on the same network - NFS: The same basic idea as SMB, with more setup and generally better performance - Mutagen: Continuously mirrors a local project to a remote machine while respecting ignored files. Use it when you want to edit locally but run remotely - Syncthing: Automatically syncs folders directly between machines. Great for notes, assets and scratch files - Don’t use Syncthing for code multiple agents edit. It syncs files but doesn’t understand branches or conflicts - rsync: Copies files or folders once, usually over SSH. Fast, scriptable and already installed almost everywhere - rclone: rsync for cloud storage. Moves files between your machines and S3, R2, B2, Google Drive and dozens of other services - pnpm: Stores each package once and hardlinks it into every project. Fourteen worktrees can share one copy instead of downloading fourteen ====== ENVIRONMENT ====== - mise: Installs and switches Node, Python, Go and Ruby versions per project. Replaces nvm, pyenv, rbenv and asdf with one fast tool - direnv: Loads the correct environment variables the moment you enter a folder, then unloads them when you leave - OrbStack: A drop-in Docker Desktop replacement for Mac. The same Docker commands with a fraction of the RAM and battery usage - Homebrew + Brewfile: Records the apps and CLI tools installed on your Mac. A new machine can recreate the setup with one command - Devcontainers: Defines the development environment in code. Anyone opening the project gets the same operating system packages, runtimes and tools - Nix / devenv: Reproduces an environment extremely precisely across machines. Powerful, but only worth the learning curve when that level of determinism matters ====== SECRETS ====== - 1Password CLI: Injects secrets into a command at runtime. Your `.env` becomes a template you can safely commit because the real values stay in 1Password - `op run`: Starts a command with the required secrets available only to that process. Nothing sensitive needs to be copied into plaintext files - 1Password Service Accounts: Give headless servers access to specific vaults without attaching them to your personal login - SOPS + age: Encrypts secret files before they enter ***. The repository stores ciphertext and approved machines decrypt it at runtime - Tailscale SSH: Uses your Tailscale identity to authorize SSH access. You stop copying and rotating public keys across every machine ====== TERMINAL ====== - Atuin: Your shell history, synced and searchable across every machine. That command from last Tuesday on the server is available on your laptop - zoxide: Learns which folders you use. Type `z api` instead of `cd ../../../services/api` - fzf: Adds fuzzy search to almost anything. Use it for files, command history, *** branches, processes and SSH hosts - ripgrep (`rg`): Searches an entire codebase in milliseconds and skips files in `.gitignore` automatically - fd: `find` with syntax you can actually remember. Type `fd config` instead of assembling a collection of flags - bat: `cat` with syntax highlighting, line numbers and *** changes - dust: Shows which folders are consuming disk space as a readable chart instead of a wall of numbers - lazygit: A full *** interface inside the terminal. Stage individual lines, inspect diffs, rebase, cherry-pick and resolve conflicts visually - btop: A readable live view of CPU, memory, disks, networks and running processes ====== CONSISTENCY ====== - just: One file containing every project command. `just dev` means the same thing on every machine and every teammate’s laptop - chezmoi: Keeps your dotfiles in *** and adapts them per machine. You get the same shell, aliases and settings across macOS and Linux - Brewfile + mise + chezmoi + just: Together these recreate your installed tools, runtime versions, personal configuration and project commands ====== ISOLATION ====== - Containers: Give each workload its own filesystem, dependencies and permissions. One broken agent can’t interfere with everything else on the machine - One container per client: An agent cannot read another client’s files if those files were never mounted into its container - Colima: A free, CLI-only way to run Docker containers on Mac - Podman: Runs containers without a permanent root-level daemon. Useful when stronger rootless isolation matters - ****: Creates and manages macOS and Linux virtual machines on Apple Silicon - UTM / Parallels: Full desktop virtual machines for workloads that need a complete graphical operating system - Firecracker: Starts tiny virtual machines in under a second. Useful when you’re building a platform that needs an isolated machine for every agent run ====== AGENT ORCHESTRATION ====== - tmux + *** worktrees: The simplest fleet manager. Every agent gets a terminal, branch and folder you can inspect directly - Claude Code hooks: Run commands automatically before or after specific Claude Code events. Useful for validation, formatting, notifications and cleanup - Claude Code subagents: Hand focused tasks to separate agents without manually opening another terminal for each one - Claude Agent SDK: Starts, steers and streams agent sessions from your own code. Use it when a terminal workflow needs to become part of a product - Inngest / Trigger .dev: Turns agent runs into durable jobs. If a process crashes, the job can retry instead of disappearing with the terminal - BullMQ / Graphile Worker: Adds a straightforward job queue backed by Redis or Postgres - launchd: Starts Mac workers after reboot and restarts them when they crash - systemd: The Linux equivalent of launchd - Temporal: Stores every step of a long workflow so it can resume after failures. Powerful, but unnecessary until durable execution becomes a real problem ====== RENTED COMPUTE ====== - Hetzner dedicated: Cheap, persistent Linux machines with lots of CPU and RAM. Good for workers that run all day - Hetzner Server Auction: Older dedicated servers sold for less. Useful when price matters more than having current hardware - DigitalOcean / Vultr / Linode: More expensive per GB, but nearby regions can make interactive SSH and remote editing feel much faster - Fly .io: Small machines that start quickly and can shut down when idle. Good for temporary workers - GitHub Actions self-hosted runners: Sends CI and batch jobs to hardware you already own instead of GitHub’s machines - Depot: Runs builds remotely and shares the cache between machines. Useful when Docker or application builds become the bottleneck - Modal / RunPod / Lambda: Rent GPUs by the hour instead of owning hardware that sits idle - MacStadium / Scaleway Apple Silicon: Rent real Macs remotely. Only worth it when the workload genuinely requires macOS ====== BROWSER AUTOMATION ====== - Playwright + `storageState`: Saves cookies and login state to a file that can move between machines. Much safer and more portable than syncing an entire Chrome profile - Puppeteer: A smaller Chrome-focused alternative when you don’t need Playwright’s multi-browser support - Chrome DevTools MCP: Lets an agent inspect and control a real Chrome session through developer tools - browser-use: Gives agents a higher-level way to navigate websites, fill forms and complete browser tasks - Browserbase / Browserless / Steel: Hosts and manages browsers for you. Useful when one local Chrome instance becomes fifty concurrent sessions - Residential proxies: Routes browser traffic through consumer IP addresses. Use them when websites block traffic from cloud servers ====== SAFETY ====== - restic + Backblaze B2: Encrypted, deduplicated, automatic offsite backups for roughly $6/TB/month. You’ll need it exactly once - Time Machine: Keeps local versions of your Mac files and makes accidental deletion easy to undo. Necessary, but not enough by itself - Carbon Copy Cloner / SuperDuper: Creates a bootable copy of your drive so a dead SSD doesn’t mean rebuilding the machine from zero - Netdata: One command installs a full metrics dashboard. Finally see which process has been eating your RAM - `memory_pressure`: Shows whether your Mac is actually running out of usable memory - `vm_stat`: Shows detailed memory usage and paging activity - `sysctl vm.swapusage`: Shows exactly how much SSD space macOS is using as emergency memory - asitop: Shows Apple Silicon CPU clusters, GPU usage, power consumption and temperatures - Uptime Kuma: Checks whether your machines and services are online and sends an alert when they aren’t - Grafana + Prometheus: Stores metrics over time and turns them into dashboards and alerts. Worth adding once you have several machines A backup isn’t real because the command succeeded It’s real when you’ve restored from it successfully ====== THE 80/20 STACK ====== Tailscale SSH + Mosh + tmux *** worktrees SMB 1Password CLI mise + direnv OrbStack pnpm just + chezmoi restic + B2 Netdata Atuin + zoxide + fzf Start here Add another tool only when you can clearly explain what problem it solves
-
Rosed (@RosedInqually) reportedCan X and Cloudflare stfu already I genuinely can't stand "Verify your age" just to click the same button over and over again and NEVER be able to actually verify, this **** sickens me.
-
The intern (@intern_11) reportedHonestly, if it were not for the Model Context Protocol going stateless, we would probably still be dealing with clunky session handshakes and sticky sessions for every AI integration. MCP 2.0 dropped July 28. No more initialize handshake. No more protocol sessions. Every request is now independent. GitHub removed Redis session storage, eliminated a database write on every call and a read on every request. Cloudflare runs each MCP request on a fresh stateless server. Manufact cut its SDK package size by 83% and made it 25% faster. MCP servers now behave like any other HTTP service. Simon Willison built three MCP tools this week alone. The protocol just became the default for AI-to-system integration. Are you building on MCP yet?
-
Turing (@turingops) reportedhi @KentonVarda I can’t overstate the usability improvements to CloudFlare dashboard over the past few years, but I’m having problems with the agent on mobile (iPhone) - could you maybe assign a worker to making the entry text more accessible? It scrolls below the view window.
-
nc (@encyapps) reported@onlinedopamine I had this issue too but i ended up setting up a deep link since i had my own domain. codex one shotted it with the cloudflare mcp, it opens straight to the App Store instead of in ig
-
Melek Turkoglu - Ekrem İmamoğlu’nu Serbest Bırakın (@AvukatMeleknur) reported@certbund We need urgent assistance regarding active financial cybercrime hosted on a German network. @Hetzner_Online claims under Ticket [AbuseID:1200CC6:30] that they do not host the reported phishing target. However, Cloudflare officially identified Hetzner as the active origin server.
-
Reem (@DreamySenora) reported@Medifi @Cloudflare a lot of infrastructure problems today are really trust problem
-
RejectNova (@RejectNova1917) reported@yeusep3 What actually happened with it? Is it just linked to the platform you're trying to upload it to?... another note, why ******** dose cloudflare exist anyway, seems like a "useful" but also completely useless service.
-
🟥🟥⬛️ ProCyclingStats.com (@ProCyclingStats) reported@longterm_inv @Kevin_LTR @Cloudflare If everyone preferred a paid API over scraping, we wouldn't have a scraping problem. Unfortunately, our experience has been the opposite.
-
Warya Wayne (@WaryaWayne) reported4000 telegram messages notifying me that the sites are down every 180 seconds when they are not down. This must be a glitch with cloudflare or something. It happens on some schedule where the worker is probably glitching or something. How can a fetch to a homepage return 503?
-
EzQ (@__EzX__) reported@eastdakota @yusukebe @Cloudflare Please fix workers AI now they are unusable
-
Dane Knecht 🦭 (@dok2001) reportedTwice in nine days. OpenAI's models chained a zero-day to get out of an eval environment. Anthropic just found three incidents of the same shape. This is what capable models do. Every reachable path is an invitation. Credit to both for publishing. We rebuilt Cloudflare OS, our internal agent platform, assuming exactly this. Sandboxes have no network path out. Agents don't get every MCP tool up front, each workspace gets only what it needs. And instead of stopping for every approval until someone gives up and enables auto-approve, the platform simulates pending actions so the agent keeps working, then queues the real ones for review at the end. The app side goes further. Apps carry no auth code at all, the sandbox provides it, so there is no auth logic to get wrong. Multi-document apps are isolated per document, so a bug can't leak between separately shared items. Anyone viewing an app must have direct permission to each of its data sources, so a dashboard on sensitive data can't overshare. Actions need the user's own permission or an approval from someone who has it, so an app can't escalate its author's privileges. And everything an app does is logged, even when the service it calls doesn't support logging. Most companies are about to point agents at real systems. Build for what the models actually do. We will open source this next week!
-
Kush (@kushbhuwalka) reportedbrowser agents are failing the problem is - today coding agents use CDP (chrome DevTools protocol) because it lets the agent read from the DOM, inspect element etc. programmatically. thats an issue because its super easy to detect, so cloudflare instantly blocks you by sending you a heinous captcha or simply just saying 'you're not human'. So what you want is a browser ecosystem for AI agents which is similar to a human browser. They have access to all the programmatic tools but they behave more human-like and pass undetected. I'm guessing this is what companies like @AsideAI did. It's definitely cool but what i really want is for my local agent to have its own browser and drive it really well. in other words, I want aside AI for my own agent.
-
chaskin.eth (@jchaskin22) reported@auryn_macmillan Agreed It also feels a bit weird to celebrate 100% uptime when most users still access Ethereum through centralized RPCs that go offline when something like cloudflare goes down We’re starting to work on this at the EF, but today the chain’s uptime and users ability to access it are still very different things
-
nupjas (@nupjas) reported@rbayuokt @CloudflareHelp @Cloudflare seemed cf was down shortly but now working again for me
-
Kimera2345 (@Kimera2345_) reportedI love getting randomly dinged as supposedly being a bot for no given reason. I assume it's because I was setting up a second account on another device and it freaked whatever AI **** they have out. (I was jailed in Cloudflare hell)
-
LilRhodySpecial (@rhody_special) reported@Cloudflare The MoQ relay architecture concentrates massive amounts of metadata collection capability in a single corp. Surveillance surface: control plane logs, connection metadata, token management audit trails, and cross-service correlation @RealAlexJones the Catch all almost complete
-
feranmi (@_bumblebee7_) reported@vxnuaj @treejordan @LemonLime_AI i wouldn’t say hopeless tbh. it’s just a tough world out there. being a cs major is tough. cloudflare got 1 million applications for internship spots of about 1000 people. the field is so densely packed. not everyone goes to waterloo or a big tech school where the names can speak for you. it’s easy to say “put in the work” but that can only come from someone who’s blind and insensitive. students are asked to send cold emails upon cold emails to people who don’t care. “your cold email must make my middle finger twitch before you get a response”. it’s tough working your *** off with no results or anyone noticing you. a good number of cs majors are also immigrants who don’t have a network or know anyone. most of them just came to the U.S. with dreams and ambitions to help support those back at home. so when they see opportunities like this, sure, it looks so bad and you wonder “why would they do it?”. but when you’re in a pool where all hope seems to be lost, you happily take any rope thrown at you even if the person offering it is the devil himself. it’s a tough world out there. anyone who doesn’t have to experience it should be grateful.
-
🜑 (@1casie) reported> be me > macbook air is bricked, needs a reinstall > no second mac to build a bootable installer > find a github actions workflow that builds macOS installers for free, no mac required > perfect.jpg > trigger a build, artifact is a 17.6GB .dmg.img > click download > kb/s > literal kb/s > theoretical connection is 10MB/s > discover artifact lives on azure blob, signed URL expires in 10 min > write a bash script that resolves the azure SAS url fresh, hands it to aria2c with 16 parallel streams > 16 connections, still kb/s > mfw it's a per-IP throttle, not per-connection > repo author literally has a line in the workflow: "Enable Cloudflare WARP for faster download" > install Cloudflare WARP on my ubuntu box > single stream jumps 20KB/s -> 1.6MB/s > aria2c 16x -> 10MB/s, pinned to my ceiling > 17.6GB in ~an hour, sha256 matches github's published digest > oknowweiscooking.webp > dd it to a USB SSD > paranoid it won't boot apple silicon because it was built on an intel runner > boots apple silicon just fine, i was wrong, shut up > installer runs, reinstall chugs along > STOPS > "OS Personalization" PREFLIGHT_PERSONALIZE portioncomplete:0.15000 estimatedtimeremaining:-1 > 70000 log lines of stalled:NO > the mac can ping apple/com > it can ping cupertino > but personalization "no connections witnessed" > i don't ******* get it > try to sniff the wifi to see what it's talking to > can't > WPA2 isn't a hub, it's a switch, i can't decrypt the mac's traffic as a third client > feel stupid > dig into it > test apple's personalization signing servers from my box > gs/apple/com -> 000 > gsp-ssl/apple/com -> 000 > albert/apple/com -> 403 (works) > gs/apple/com is the signing server and it's IPv4-ONLY > my ISP (DIGI, romania) has broken IPv4 routing to apple's 17.0.0.0/8 > ICMP works, IPv6 works, CDN works, the ONE /8 macOS needs to sign firmware is a black hole > that's why it could "ping cupertino" but personalization silently died > fix: repoint the mac's IPv4 default gateway from the router to my ubuntu pc > my pc has IP forwarding + NAT masquerade + Cloudflare WARP > mac's IPv4 now tunnels through cloudflare, bypassing my ISP's broken path > watch the signing handshake complete in tcpdump, SYN -> SYN-ACK -> ClientHello -> kilobytes of signed data > portioncomplete climbs past 0.15 > weactuallydidit.jpg > STOPS AGAIN at 0.29 > silent on IPv4 > oh > the mac's IPv6 still goes straight to the router, bypassing my box > i literally cannot see it > disable IPv6 on the mac so everything falls back to the working IPv4 path > it reboots > flashes the apple logo 4 times > i'm dying > it boots > it works > 29 hours > i had to MITM my own home network because my ISP couldn't route to one (1) /8 > the mac is back > i'm buying a framework >text still isn't green