mepa8
Vendor catalog · Full tier

How to cap your Cloudflare bill

Workers and D1 are cheap until a single import on one project burns the daily write quota for every database on the account. Here is what Cloudflare bills, what it did to us, and the cap that stops it.

By Ryan Bolden with NousPublished Updated

Cloudflare is a hosting and network vendor whose Workers platform runs code at the edge and whose D1 service is a small SQL database. For a team of 1 to 10 people building AI products, it is usually the cheapest line on the bill. That is why nobody watches it. We host 5 sites on it, and the one surprise we had did not come from a big number. It came from a limit shared across the whole account.

What Cloudflare actually bills you for

Workers has two plans. The Free plan allows 100,000 requests a day and 10 ms of CPU time per invocation, with no charge for duration, according to the Workers pricing page. The Paid plan starts at $5 a month and includes 10 million requests, then $0.30 per additional million, plus 30 million CPU milliseconds, then $0.02 per additional million.

D1 is where the free tier bites. On the Free plan you get 5 million rows read a day, 100,000 rows written a day and 5 GB of storage, per the D1 pricing page. The Paid plan includes 25 billion reads a month and then $0.001 per million, 50 million writes a month and then $1.00 per million, and 5 GB of storage before $0.75 per GB-month.

The sentence that matters is on the same page. Free limits reset daily at 00:00 UTC, and the monthly included limits reset on your subscription renewal date. Daily means a bad hour costs you the rest of the day, not the rest of the month. See the Workers limits page for the per-invocation caps that sit on top of the price list.

What happened to us

On October 5, 2026, we imported a national utility map into D1 for one client site: 60,624 ZIP-to-utility rows plus 1,194 utility records. That is more than the 100,000 writes a day the Free plan allows, once you count the index writes. The import succeeded. Then an unrelated product on the same account, one with paying customers, stopped being able to save anything for the rest of the day.

The fix took 5 minutes and $5 a month: switch the account to Workers Paid. The lesson took longer to accept. The quota is counted per account, not per database. Our own note from that evening reads:

“100k row writes/day across ALL databases; a bulk import on one DB breaks every production DB on the account.”Mepa8 engineering note, October 5, 2026

Nothing in the dashboard warned us before the import. Nothing told us during it. We found out from a customer-facing error on a different product.

How Mepa8 watches Cloudflare

Cloudflare sits in the Full tier of the Mepa8 catalog, with one honest caveat. Today the connector checks every site we host on it: 5 domains, each fetched twice a run, with a health alert when one stops answering. Cost does not come from an API yet. It comes from the monthly receipt in the billing inbox, because Cloudflare's billing endpoints are not wired into the connector. The board shows the $5 base plus whatever the last receipt said.

The kill is two steps and reversible. Propose it, get a single-use token, confirm it. For Cloudflare the kill means disabling the Worker route in the dashboard, which takes the site offline without deleting anything. Restore re-enables the route. Nothing is ever killed automatically, and no alert can fire the kill on its own.

The alert that would have saved our October 5 is now in the plan: D1 rows written today against the 100,000 daily limit, counted across the account. At 80% you get a text. At 100% the board turns red and names the database that spent it.

Set a cap in five minutes

  1. Create an API token in the Cloudflare dashboard with read-only scope: Account Analytics Read and Zone Read. Mepa8 never needs a write scope to watch.
  2. Add Cloudflare in Mepa8 and type the token's environment variable name, such as env:CF_READ_TOKEN. The registry stores names, never values.
  3. Set the budget. For a small shop on Workers Paid, $25 a month covers the $5 base and normal overage.
  4. If you are on the Free plan and you run imports, move to Paid first. The $5 is cheaper than one afternoon of a blocked product.
  5. Write the kill recipe on the vendor card: which Worker route to disable, and which sites go dark when you do.

Questions people ask

Does Cloudflare have an account-level spend cap?

Not on Workers Paid as of October 2026. The pricing page lists per-unit overage rates, $0.30 per million requests and $1.00 per million D1 writes, but no setting that stops spend at a number you choose. Mepa8's budget alert is the cap.

Is the D1 free tier a hard limit?

Yes. When an account passes 100,000 rows written in a day on the Free plan, writes fail until the reset at 00:00 UTC, per the D1 pricing page. It is enforced per account, which is how one import on October 5, 2026 blocked a second product of ours.

What does Mepa8 kill when I kill Cloudflare?

The Worker route you named on the vendor card, nothing more. The card lists the blast radius, in our case 5 sites, and the restore step turns the route back on. The kill is proposed, then confirmed with a single-use token, and it is logged with who did it and when.

Sources

  1. Cloudflare Workers pricing — plans, included requests and CPU time, overage rates
  2. Cloudflare D1 pricing — free and paid read, write and storage limits
  3. Cloudflare Workers limits — per-invocation caps

Change log: October 9, 2026 — First published from our own October 2026 accounts.