· · 1 min · infrastructure · by the wire desk

Cloudflare leaked BGP prefixes from Miami. The internet noticed.

A February 20 routing incident took BYOIP customers off the map. The cause was an automated policy change, which is the year's refrain.

On February 20, a subset of Cloudflare customers using its Bring Your Own IP service watched their routes to the internet get withdrawn. The company's post-mortem attributes the incident to an automated routing policy configuration error that unintentionally leaked BGP prefixes from a router in its Miami data center.

BGP incidents have a particular cruelty: the failure is not that your service goes down but that the internet forgets where you are. For BYOIP customers, whose whole arrangement is "our addresses, your network," a prefix withdrawal is the vendor misplacing the customer's own name.

The cause deserves filing next to the winter's other incidents. Automated policy change, configuration error, blast radius wider than the change's intent: the same triad pattern analysts keep flagging across providers. Automation did not create the config-change failure mode. It compressed the interval between mistake and global effect to roughly zero.

The builder's read: if your addresses ride BYOIP on any provider, this is the week to ask what your detection looks like when your prefixes vanish, because the provider's dashboard was green while your routes were not. Externally hosted route monitoring is cheap. February was the advertisement.

tags: #cloudflare #bgp #outage #networking