What does cloudflare have to do with k8s? Maybe you're confusing it with load balancer.
To answer your question, yes, some big instances are actually using CF protection to mitigate DDoS attacks.
Production runs on Linux server. The problem is with development environment, I want to avoid Virtualbox as it would be an extra overhead to manage and affect DX.
Custom roms do improve security of an EOL device, though you're missing out the vendor security patches which aren't open source. You can read this discussion here.
What does cloudflare have to do with k8s? Maybe you're confusing it with load balancer.
To answer your question, yes, some big instances are actually using CF protection to mitigate DDoS attacks.