Load Balancing TTLs and Orange vs. Grey Cloud

Cloudflare can operate in two modes - DNS only (unproxied: grey cloud") and as a HTTP proxy (orange cloud) with our security, CDN & performance features.

You can have orange-clouded and grey-clouded domains in the same Load Balancing region, but the traffic routing behavior differs as follows:
  • Traffic for orange-clouded domains is routed based on the data center associated with the user making the request, whereas
  • traffic for grey-clouded domains is routed based on the data center associated with the user’s recursive DNS resolver.

When configuring a Load Balancer, you can choose to configure it in DNS-only or HTTP proxy modes.

  • "Orange cloud" (proxied) Load Balancers have an automatic TTL - this means that Cloudflare will announce Cloudflare IP addresses externally, but will protect (mask) your origin server IP addresses. Any changes to your Load Balancer will propagate within seconds inside Cloudflare, including any failover events. The primary benefit here is that external DNS resolver caches that do not respect short (e.g. 30s) TTLs will not impact the failover speed of your Load Balancer.
  • "Grey cloud" (DNS only) Load Balancers may be configured with a TTL from 30 seconds to 10 minutes. Cloudflare will serve the addresses of the (healthy) origin servers directly, but relies on DNS resolvers respecting the short TTL in order to re-query Cloudflare's DNS for an updated list of healthy addresses.

Where possible, you should set the Load Balancer as orange clouded (proxied) mode:

  • Failover will be faster, as external DNS caches that don't respect short DNS TTLs will not impact failover performance
  • Customers on our Free, Pro & Business plans who have a Load Balancing subscription may see reduced usage on their bill as the "Automatic" TTL (5 minutes) reduces the number of authoritative queries made against Cloudflare, but without impacting failover performance.
Not finding what you need?

95% of questions can be answered using the search tool. This is the quickest way to get a response.

Powered by Zendesk