Cloudflare is leveraging AI to build an internal tool, CryptoLabe, to manage their massive post-quantum cryptography migration by 2029. This system is designed to discover cryptographic usages in their vast codebase, analyze their runtime behavior and dependencies, and provide actionable reports to engineering and product teams. The architecture utilizes Cloudflare's Developer Platform components like Workers, D1, Durable Objects, Workflows, and R2 for scalable and isolated code scanning and analysis.
Read original on Cloudflare BlogCloudflare faces the monumental task of migrating its entire infrastructure to post-quantum (PQ) cryptography by 2029. Given the foundational role of cryptography in their services, this "PQ everything!" approach necessitates a systematic method to identify, analyze, and update cryptographic implementations across their massive codebase. To address this, they developed CryptoLabe, an internal AI-powered tool designed to automate and orchestrate this complex migration.
The scale of Cloudflare's operations presents several challenges for cryptography discovery. Their centralized codebase spans numerous repositories, making a simple grep insufficient. Cryptography often "hides" in shared libraries, protocol defaults (e.g., TLS 1.3 key exchange configurations), or distant configuration files, making direct pattern matching unreliable. Furthermore, understanding *how* cryptography is used (e.g., an ECDSA signature in JWT, IPsec, TLS, or SSH) is crucial, as each context demands a different migration strategy. AI is employed to overcome these limitations by performing deep code analysis, following evidence across files, and enriching findings with internal documentation.
CryptoLabe's scanning process is divided into two main stages: Discovery and Analysis. The Discovery Stage maps a repository and searches for cryptographic use across source code, configuration, manifests, lockfiles, scripts, tests, and documentation, generating "raw observations." The Analysis Stage then re-checks observations, investigates runtime usage, identifies dependencies, and inspects related code in other repositories. It then classifies findings (e.g., Classical encryption, PQ-ready hybrid key exchange) and generates detailed reports for product managers and engineers.
CryptoLabe is built on Cloudflare's Developer Platform, leveraging several key components: A scanner Worker performs the actual scans, while an inventory Worker handles the dashboard, API, and stores data in a D1 database. Service Bindings facilitate communication between these Workers. Scan orchestration is managed by Durable Objects, with each repository having a persistent coordinator. Cloudflare Workflows are used to persist progress and manage retries for the discovery, deep analysis, merge, and publish stages. For isolated code access, repositories are snapshotted into R2 storage and restored into ephemeral Cloudflare Sandboxes for analysis.
Scalable AI Model Invocation
To handle large-scale AI model requests across many repositories without hitting rate limits, Cloudflare implemented a single, global Durable Object. This DO paces all model requests, ensuring that when any scan experiences a rate limit, the cooldown is shared, and all concurrent scans back off together, optimizing shared capacity rather than competing for it. Requests are routed through an AI Gateway to cost-effective open-weight models on Workers AI.