Being rate limited 1015 - even though security & apps is off

I run a small startup that offers image and video hosting - and we have been using Cloudflare for over 10 years.

So here’s the issue: our customers sometimes upload thousands of images.

And Cloudflare is rate limiting these customers (error 1015), causing uploads to fail and the entire site to be unavailable for them.

Which is a serious, serious issue for us.

I added page rules to “Disable security, Cache level: Bypass, Disable Apps” to our upload API endpoints.

However, I can see in firewall events, that this same URL path and host is still rate limited.
The rule ID = worker

We use logflare to log requests, but it should be disabled by the Page Rule.

We pay for workers, so we should not be limited by requests like in the free plan.

We don’t have a custom rate limiting rule active on the upload api endpoint.

So how do we unprotect our upload API for rate limiting or increase the limit?

This means that you’re running into the abuse protection for Workers, which gets triggered when there are a lot of requests coming from a single ip. This ratelimit is normally meant as abuse protection, but you can contact Cloudflare’s support to bump up this limit so you no longer run into it.

Cloudflare’s abuse protection methods do not affect well-intentioned traffic. However, if you send many thousands of requests per second from a small number of client IP addresses, you can inadvertently trigger Cloudflare’s abuse protection. If you expect to receive 1015 errors in response to traffic or expect your application to incur these errors, contact Cloudflare to increase your limit.

1 Like

There are no workers active on our API endpoints and I have disable Apps (which may invoke workers) set in a page rule to off.

It seems like a bug with page rules to be honest.

Workers as apps are still a bit of a new thing, so it’s possible that they might have overlooked something with the page rules on this.
It’s best to open a support ticket about this issue so they can take a better look at it.

2 Likes

Anyway, thanks for the help Arunesh. I’m glad some customers are willing to spend time here and try to help other customers. :+1:

1 Like

I want to update the community about my issue:

I’ve been in contact with Cloudflare support and they quickly replied to my report.
They’ve removed the worker rate limit.

I think all is good now.

Thanks!

This topic was automatically closed after 30 days. New replies are no longer allowed.