CLOUDFLARE outlines its audacious move to post-quantum readiness, aiming for full PQ migration by 2029. The piece explains that, while many products have already switched to post-quantum encryption over TLS 1.3, there remains work in post-quantum authentication and broader platform-wide readiness. To tackle the enormity of the task, Cloudflare has developed CryptoLabe, an internal AI-assisted cryptography discovery tool.
CryptoLabe is designed to locate cryptographic usage across Cloudflare’s vast codebase, understand how each instance operates, and map a path to upgrade, with the goal of giving customers confidence that traffic is future-proofed against quantum adversaries.
CryptoLabe operates in two stages: discovery and deep analysis. In discovery, it maps repositories and searches for cryptographic activity across code, configurations and documentation, producing raw observations. In the analysis stage, the tool re-checks findings in the runtime context, determines the repository’s role, and checks for dependencies or overrides that could affect migration.
It classifies findings with categories such as PQ-ready hybrid key exchange and PQ-ready, and flags entries requiring more evidence or external dependencies. The approach also recognises hard cases—custom or hardware-bound cryptography and protocols lacking PQ standards—where additional prerequisites block immediate upgrades.
Cloudflare demonstrates its end-to-end orchestration using a two-Worker architecture, Durable Objects for coordination, and Cloudflare Workflows for persistent, retryable tasks, all while keeping code snapshots isolated in sandboxed environments. While CryptoLabe remains internal and not customer-facing, Cloudflare shares prompts and lessons to help other organisations plan their own PQ migrations.