AWS
AWS holds the databases and the out-of-band credential and recovery stores. It runs on a separate identity plane from Cloudflare, which is deliberate: a Cloudflare-side incident must not lock away the material needed to rebuild it.
Services
Section titled “Services”Secrets Manager is the system of record for database credentials and for the identity-provider recovery codes that rebuild Cloudflare Zero Trust if the upstream IdP fails. KMS-encrypted, IAM-gated, CloudTrail-audited.
Other services
Section titled “Other services”RDS and Aurora MySQL hold the console, aggregate, and billing databases, reached from Workers through Hyperdrive over the Tunnel. EC2 with Auto Scaling runs the cloudflared tunnel daemons. Each gets its own page here as its standard is written.