Rocket.net's value is its edge, and the edge is configured in a Cloudflare account you do not control. None of it is in your site.
The WordPress install copies in an afternoon. The behaviour visitors experienced lives somewhere else entirely.
Cache rules, firewall settings and page rules are held in a Cloudflare zone belonging to the host. We inventory the behaviour and rebuild it on our edge before DNS moves.
Sites that only ever answered through a managed proxy frequently have an origin nobody hardened, because nothing could reach it. That changes the moment the proxy does.
A site tuned around an always-on edge cache for years leans on it more than anybody wrote down, so the replacement is set up and checked rather than assumed.
It exists to purge their edge. Once you are not on their edge it is a plugin issuing instructions nothing receives.
A permissive SSL mode at the old edge can hide a plain-HTTP origin, which turns into a redirect loop the instant the proxy in front of it changes.
Doing it the other way around means the first visitors after cutover meet an origin with none of the rules that were making the site fast and safe.
The point of this move is not giving up edge caching. It is having the rules somewhere you can read and change them.
These are the specific things this move needs, and nearly all of them are outside WordPress by definition.
| Setting | What we do | Why |
|---|---|---|
| Edge rules | Inventoried from the old edge and rebuilt on ours before DNS moves | Cache, firewall and page rules live in a Cloudflare zone you do not control, so no export or backup contains any of them. |
| Origin exposure | Hardened and verified before the proxy changes | An origin that only ever answered through a managed edge is usually one nobody needed to protect, right up until it is reachable. |
| Cache behaviour | Reproduced explicitly rather than assumed | Years of tuning around an always-on edge cache creates dependencies nobody documented because nobody had to. |
| Platform plugin | Removed during the copy | Its purpose is purging their edge, so after the move it issues instructions that nothing is listening for. |
| SSL mode | Verified end to end rather than trusted | A permissive mode at the old edge masks a plain-HTTP origin, and that surfaces as a redirect loop the moment the proxy in front changes. |
Every plan includes free migration, daily backups, SSL and 24/7 support.
Free migration, edge behaviour rebuilt before DNS moves, and an origin checked before it is reachable.