I wonder what the security is like for that layer, if that layer can access stuff not assigned to it
I wonder what the security is like for that layer, if that layer can access stuff not assigned to it. Sounds like a bountyable thing to dig into

Sometimes, though, Cloudflare does decide to schedule a Worker in its own private process. Cloudflare does this if the Worker uses certain features that needs an extra layer of isolation. For example, when a developer uses the devtools debugger to inspect their Worker, Cloudflare runs that Worker in a separate process
You've requested a page on a website (bar.foo.com) that is on the Cloudflare network. The page could not be rendered due to a temporary fault.