Finally! Cloudflare and Shopify Play Nice: A Community Deep Dive into O2O Routing & Best Practices
Hey there, fellow store owners!
I’ve been watching a really insightful discussion unfold in the Shopify community forums recently, and it's brought up a topic that's been a source of confusion and frustration for many: using Cloudflare as a proxy in front of your Shopify store. For years, this was a setup many experts advised against, and for good reason. But what if I told you that the major hurdle preventing a smooth integration has finally been cleared? That’s right, the game has changed, and our community has been digging deep into what this means for you.
The Old Headache: Why Cloudflare and Shopify Used to Clash
Let’s rewind a bit. If you’ve ever tried to put Cloudflare’s proxy (those orange clouds in your DNS settings) in front of your Shopify store, you might have run into an amber warning in your Shopify domain settings, or worse, outright issues. As @wislr, who kicked off this great thread, explained, the core problem was a zone collision. Shopify itself uses Cloudflare. So, when your own Cloudflare-proxied domain pointed to Shopify, the request would arrive with two Cloudflare zones both claiming ownership. This led to nasty redirect loops and incorrect resolutions.
But the biggest headache was often with SSL certificates. Shopify uses Let’s Encrypt to automatically renew your store’s SSL certificate. This process requires a specific token to be served over plain HTTP at a path like /.well-known/acme-challenge/. When you put a proxy in front of it, especially one configured incorrectly, that path would get swallowed. Your certificate renewal would quietly fail, and weeks later, your store would suddenly show security warnings as the padlock broke. Not ideal for business, right?
The Game Changer: Cloudflare’s Orange-to-Orange Routing
Good news! Cloudflare has directly addressed this zone collision problem with something called Orange-to-Orange (O2O) routing. This feature, part of Cloudflare for SaaS, has been generally available since October 2021. What it does is clever: Cloudflare now detects that your CNAME record points to another Cloudflare customer (Shopify, in this case) and intelligently routes the request through your Cloudflare zone first, then through Shopify’s. It ensures the correct order, resolving the collision.
You can actually confirm this is working because a small Shopify icon will appear next to your DNS record in Cloudflare. Plus, Cloudflare takes extra precautions by automatically turning off Workers and Snippets on the /checkout path, ensuring nothing at your edge interferes with the critical payment process.
Getting Your Cloudflare & Shopify Setup Right: Essential Steps
Based on @wislr's testing and the collective wisdom of the community, here's the crucial configuration to make this work smoothly:
- Set up your CNAME: Create a proxied CNAME record (with the orange cloud) for your root domain and
www, pointing toshops.myshopify.com. - Connect your domain in Shopify: Go into your Shopify admin and connect this same custom domain.
- Crucial SSL Setting – Turn OFF "Always Use HTTPS" in Cloudflare: This is where many people go wrong! Shopify already handles HTTP to HTTPS redirects at its origin. If you enable "Always Use HTTPS" in Cloudflare, you'll create a second redirect layer, leading to
ERR_TOO_MANY_REDIRECTS. More importantly, it will swallow the ACME challenge path needed for SSL certificate renewals, causing your cert to eventually expire. - SSL Mode & Minimum TLS: Keep your SSL mode in Cloudflare set to Full. While you're there, set your minimum TLS version to 1.2 for better security.
- Advanced HTTPS Enforcement (Optional): If you absolutely need Cloudflare to enforce HTTPS at its edge, don't use the simple toggle. Instead, write a specific redirect rule that *excludes* the
/.well-known/acme-challenge/path. This ensures your SSL renewals can still happen.
Verifying Your Setup
To make sure everything is configured correctly, especially that crucial ACME path, you can use a curl command. As @wislr shared:
curl -svo /dev/null http://yourdomain.com/.well-known/acme-challenge/faketoken
You should expect a 404 Not Found error. This means the request successfully reached Shopify. If you get a 301 or 308 redirect, it indicates something is still eating the path, and your SSL renewal will likely fail.
Addressing Shopify’s "Not Supported" Warning
Even with O2O routing, Shopify might still show a "not supported" warning for a proxied Cloudflare setup. It’s important to understand what this means. It doesn’t mean the setup will fail; it simply means Shopify won’t guarantee or debug issues arising from a layer they don’t control. Their reasons are fair: an extra proxy can complicate SSL renewals and make it harder for Shopify to reroute traffic during incidents. However, the argument about bot detection is often debated. Cloudflare boasts one of the largest bot management networks, often providing *more* filtering at the edge than Shopify might lose in request signal.
Performance and Latency Concerns
One common worry is that adding Cloudflare will introduce latency. Interestingly, @wislr's tests showed this wasn't an issue. Both Cloudflare zones (yours and Shopify’s) already reside on the same network, so the handoff happens internally. Proxied stores performed similarly to raw Shopify endpoints. As @Hardeep and @Steve_TopNewYork rightly pointed out, if your store feels slow, you’re much more likely to find performance gains by optimizing your theme, reducing app bloat, or improving image loading.
The Big Question: Is Cloudflare Worth the Extra Layer for Your Shopify Store?
This is where the community truly converged. The unanimous sentiment from contributors like @sophia24, @Hardeep, and @Steve_TopNewYork is clear: only consider putting Cloudflare in front of Shopify if you have a specific, justifiable need for its advanced edge features.
What kind of features are we talking about? A custom Web Application Firewall (WAF) you can tune, granular rate limiting, detailed request-level logs, or deep visibility into AI crawlers like GPTBot and ClaudeBot that traditional analytics (GA4, Shopify analytics) often miss because they don't execute JavaScript. If you can’t name a specific feature you need, then the added complexity of managing an extra layer – and having to monitor that SSL renewal yourself – probably isn't worth it.
Shopify already provides excellent CDN, SSL, and DDoS protection right out of the box. For most merchants, this default setup is simpler, more stable, and avoids adding another component to troubleshoot when things go sideways. As @Steve_TopNewYork summarized, it’s a trade-off: do the additional control and security features outweigh the added complexity for your particular store?
So, while the technical hurdle has been overcome, the decision still rests on your specific business needs. The community consensus is a strong reminder: keep it simple unless you truly need that extra power at the edge. It's fantastic to see these kinds of real-world insights shared and debated openly!