Controlflare comes with no warranty.
Please read this before you rely on Controlflare to protect a budget. It is a safety net with holes in it, and it is important that you know where they are.
No liability for your bill
Controlflare is provided as is, without warranty of any kind, express or implied. The creators and contributors of Controlflare accept no liability whatsoever for any inaccuracy, bug, outage, missed enforcement, unintended pause or any other behaviour of this software, and no liability for any cost, charge, invoice or financial loss that results from it, whether or not such loss was foreseeable.
This includes, without limitation, a bill that is larger than you expected, a cap that did not fire, a cap that fired late, a cap that fired when it should not have, and any revenue or data loss caused by a Worker being paused.
Your Cloudflare invoice is the only authoritative number. Everything Controlflare shows you is an estimate, computed from Cloudflare usage analytics and published list prices. Estimates drift from invoices for many reasons: analytics are sampled and delayed, prices change, your plan or contract may differ from list, and some billable dimensions are not exposed by any public dataset.
Pausing does not stop every charge
When a cap is reached, Controlflare removes every way traffic reaches each Worker and detaches its D1, KV, R2 and Durable Object bindings. That stops most of what costs money on a typical account. It does not stop all of it.
Workloads that can keep costing you money after a pause include:
- Stored data. R2 objects, KV entries, D1 databases and Durable Object storage keep billing for as long as they exist. Controlflare never deletes your data, so storage charges continue.
- Durable Object alarms. An alarm scheduled inside a Durable Object runs inside that object. Removing a caller's binding does not cancel it.
- Workers that are not paused. Only a paused Worker loses its bindings. Anything still running keeps its own, and keeps billing through them.
- Products Controlflare does not touch. Queues, Vectorize, Hyperdrive, Workers AI, Images, Stream, Pages, Workflows, Containers, Browser Rendering, Logpush, Zero Trust seats, domain registrations and your Cloudflare subscription itself are all outside its scope, and several of them are outside its estimate too.
- Anything invoked outside a route. A paused Worker is unroutable, not switched off. Service bindings from other Workers, Durable Object alarms and Queue consumers can still run it.
In short: Controlflare can reduce a runaway bill, and it may reduce it a great deal, but it cannot guarantee a ceiling on what Cloudflare charges you.
It depends on things outside its control
Enforcement runs on a schedule, not instantly, so spend can cross your cap between checks. It depends on the Cloudflare API being reachable and on the permissions of the API token you configured. It depends on the cost agent you deployed into your own account being present, current and working. If any of those fail, your cap is not enforced, and Controlflare may not be able to tell you so.
You remain responsible for your account
Controlflare is a convenience layer over your own Cloudflare account. You remain solely responsible for that account, for the charges it incurs, for the credentials you give Controlflare, and for deciding whether a pause is an acceptable outcome for your production traffic. Set Cloudflare's own notifications and billing alerts as well; do not make this your only control.
Not affiliated with Cloudflare
Controlflare is an independent tool. It is not affiliated with, endorsed by, sponsored by or supported by Cloudflare, Inc. Cloudflare, Workers, D1, R2 and Durable Objects are trademarks of Cloudflare, Inc.