if you can, i would consider moving to a different, non-cloudflare cdn (or just turning off cloudfla
if you can, i would consider moving to a different, non-cloudflare cdn (or just turning off cloudflare, if your DDOS protection doesn't rely on it)
__cf_bm cookie for bot tracking, etc. Within the same zone (call it example.com), any requests from workers (https://example.com -> worker subrequest fetch() -> https://proxy.example.com) do not receive the __cf_bm cookie from the "proxy". Great!__cf_bm cookie. That's all well and good, until you realize that tiered cache will not cache anything with a Set-Cookie header (cache status NONE). We're specifically calling the fetch() to enable tiered cache from our worker, to the reverse proxy. 
__cf_bm__cf_bm__cf_bm