Overview
Move your site off the orange cloud onto your own EU servers, without changing how it behaves.
flareover is an AGPL-3.0, single-binary Go engine that reads a live managed-edge zone and rebuilds the equivalent configuration for an open-source, self-hosted stack (Caddy, PowerDNS, CertMate, …) on EU-sovereign infrastructure.
Its one rule (the whole reason the project exists) is a 0% false-positive contract: it never emits configuration that silently changes behavior.
- Where it can prove an exact equivalent, it applies it (AUTO).
- Where a choice is genuinely ambiguous, it asks you one yes/no (ASK).
- Where nothing maps faithfully, it flags the item for you and never guesses (MANUAL).
That is the difference between a migration you can trust and a migration you have to re-audit by hand.
Why this exists
Section titled “Why this exists”Leaving a big managed edge means rebuilding, by hand, everything the dashboard quietly did for you (DNS, TLS certificates, redirects, firewall/WAF rules, caching) and hoping you didn’t miss something that silently breaks the site. flareover does that rebuild deterministically and tells you, honestly, exactly what it could and could not carry over.
The 30-second tour
Section titled “The 30-second tour”flareover extract example.com > zone.snapshot.json # read-only, needs CLOUDFLARE_API_TOKENflareover assess zone.snapshot.json # honest AUTO/ASK/MANUAL reportflareover resolve zone.snapshot.json --defaults > decisions.lockflareover prepare zone.snapshot.json --decisions decisions.lock \ --edge-ip 203.0.113.10 --out ./out # generate the target-stack configEverything up to the DNS flip is a review artifact you can read in git before anything goes live. See Quick Start for a full walkthrough.
What’s in the box
Section titled “What’s in the box”| Concern | Tool |
|---|---|
| Authoritative DNS | Self-hosted PowerDNS, or a managed target via --dns (see DNS Targets) |
| Reverse proxy / CDN / TLS | Caddy (native ACME, HTTP/3) |
| WAF | caddy-waf (OWASP, rate-limit, IP/ASN/country, blocklists) |
| Edge cache | souin (Caddy module) |
| Certificates | CertMate: DNS-01, wildcard, Let’s Encrypt or Actalis (EU CA) |
| Object storage | Self-hosted MinIO, or managed EU S3 (see Object Storage) |
| Sovereign origin link | WireGuard mesh (replaces the managed tunnel; origin stays inbound-free) |
| Egress shield (optional) | secure-proxy-manager (default-deny + allowlist, fail-closed) |
Where to go next
Section titled “Where to go next”- New here? → Installation → Quick Start
- Want the guarantees? → The Contract
- What actually maps? → Coverage Matrix
- Which providers? → DNS Targets · Sovereignty Tiers
- Questions? → FAQ / Q&A
Status. All five phases are implemented; the five core adapters (PowerDNS, CertMate, MinIO, WireGuard mesh, secure-proxy-manager) are proven live against real services. The managed DNS/storage backends and the Terraform edge module are verified against each vendor’s documented API and test harness (Tier B) and promoted to live-proven after a real run. Nothing claims a proof it hasn’t earned. See Coverage Matrix.