Global load balancing, automatic SSL, DDoS mitigation, private networking, and edge caching. Included on every plan. Zero configuration.
No Cloudflare in front. No nginx to configure. No cert-manager to debug.
Traffic distributed across all healthy instances using weighted round-robin. Automatic failover across regions. No configuration needed.
Every domain gets a Let's Encrypt certificate provisioned in under 60 seconds. Auto-renewed 30 days before expiry. Wildcard domains supported.
Network-level DDoS protection is always on at the edge. Volumetric attacks absorbed before they reach your instances. No action required.
All services in a project share an encrypted private network. Internal traffic never touches the public internet. Reference services by name: api.internal:8080.
Static assets cached at 40+ edge locations. Cacheable API responses with configurable TTLs. Purge by path or globally with rf cdn purge.
Persistent connections with no timeout. Sticky sessions enabled by default. Scale WebSocket apps across multiple instances with Redis pub/sub.
HTTP/3 (QUIC) enabled on all web services for faster connections. gRPC services with native health checking and load balancing.
Built-in web application firewall rules. Per-path rate limiting at the load balancer level. Geo-blocking and bot protection.
Unlimited custom domains with automatic SSL. CNAME or A record. Wildcard support. Assign domains per environment — production, staging, preview.
One command. SSL provisioned in under 60 seconds. Wildcard domains, apex domains (A record), and subdomains all supported.
Requests hit the nearest edge location, then route to the nearest healthy instance. Multi-region failover is automatic.
Static assets cached at 40+ locations. Configure per-path TTLs for API responses. Purge instantly from the CLI.
Request rates, cache hit ratios, bandwidth, latency percentiles. All visible in rf metrics and the dashboard.
Defaults work for 90% of apps. Customize when you have specific requirements.
Round-robin (default), least connections, or IP hash. Sticky sessions for WebSocket and stateful apps.
Protect login endpoints at 5 req/s while allowing product pages at 500 req/s. Rate limiting happens at the edge before hitting your app.
Cache static assets automatically. Add per-path TTLs for API responses. Vary by headers (Accept, Accept-Language) for content negotiation.
Block SQL injection, XSS, and common attacks. Geo-blocking by country code. Bot detection. All configurable in YAML or CLI.
Restrict access to specific IP ranges per service. Block known bad actors. Combine with rate limiting for defense in depth.
Internal services are never exposed. Only web services get public URLs.
Yes. Every domain gets automatic SSL via Let's Encrypt. Custom domains get certificates provisioned in under 60 seconds. Auto-renewed.
Network-level mitigation is always on at the edge. Volumetric attacks are absorbed before they reach your instances. No configuration.
Yes. Unlimited custom domains with automatic SSL. CNAME or A record. Wildcard domains supported. Assign per environment.
Yes. Global edge caching at 40+ locations. Static assets cached automatically. Per-path TTLs for API responses. Purge via CLI.
Yes. All services share an encrypted private network. Internal traffic never touches the public internet. Use service.internal hostnames.
No. RaidFrame includes load balancing, SSL, CDN, DDoS protection, and WAF. Adding Cloudflare is unnecessary and adds latency.
SSL, load balancing, and DDoS protection included on every plan.