Cloudflare 2019 Routing Incident

BGP gone wrong.

Overview

The Cloudflare 2019 routing incident was a multi-hour outage triggered by a BGP route leak from a regional ISP. The lessons that emerged reshaped how teams think about BGP propagation, peer filtering, and cryptographic origin validation.

The approach

Defence against BGP misadventure is layered. RPKI handles the cryptographic origin proof; AS-level filtering catches what RPKI does not; monitoring catches what filtering misses.

Why this compounds

Each architecture review that applies the Cloudflare lessons hardens one more network. The compounding works because BGP defence is collective: each operator’s filtering benefits every operator’s reachability.