Back to news

Cloudflare Opens Private-Origin Routing Beta; AWS Expands FSx Tiering

Two infrastructure updates this week lower the bar for connecting public traffic to private networks and managing file storage costs at scale.

Cloudflare Opens Private-Origin Routing Beta; AWS Expands FSx Tiering

What happened

Cloudflare launched a closed beta for Application Services for Private Origins, a capability that maps public hostnames directly to private IP addresses over existing network tunnels — including IPsec, GRE, CNI, or Cloudflare Mesh — without requiring public IP addresses or additional connector software on the origin side. Separately, Amazon Web Services expanded the availability of its FSx for OpenZFS Intelligent-Tiering storage class to eight more regions spanning the United States, Europe, Asia Pacific, and South America. The tiering feature automatically shifts data across three storage tiers based on access patterns, targeting workloads such as file shares, media libraries, archives, and on-premises HDD migrations.

Why it matters for your business

For teams running internally hosted applications — whether on-premises or in a private cloud segment — Cloudflare's closed beta removes the historically painful requirement of exposing a public IP or deploying dedicated reverse-proxy software just to serve traffic through a CDN or security layer. Organizations already using IPsec or GRE tunnels for site connectivity can now layer application delivery on top of that same infrastructure, reducing both cost and attack surface. On the storage side, the broader regional footprint for FSx Intelligent-Tiering means companies with data residency requirements in newly covered regions can now automate cost management on file workloads without manually moving cold data to cheaper tiers. The practical takeaway: both announcements reduce operational overhead — one by simplifying network topology for application delivery, the other by automating storage lifecycle decisions.

What to watch next

Cloudflare's private-origin routing feature is currently invite-only, so organizations interested in early access should apply directly through the Cloudflare dashboard or contact their account team. As the feature moves toward general availability, expect closer integration with Cloudflare's Zero Trust and Access products, which could make it a compelling alternative to traditional application proxies. On the AWS side, further regional expansion of FSx Intelligent-Tiering and potential deeper integration with AWS DataSync or Backup services would be logical next steps to watch.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp