Zum Inhalt springen

Core Platform Updates & Release Notes

46 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Core Platform, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Mehrere Cloudflare Tunnel- und Mesh-Routen gleichzeitig erstellen

Auf der Routes-Seite lassen sich nun mehrere Cloudflare Tunnel- und Cloudflare Mesh-Routen in einer Aktion anlegen, auch per kommagetrennter Liste von CIDR-Bereichen oder Hostnamen, wobei bei Fehlern nur die fehlgeschlagenen Routen erneut gesendet werden müssen.

You can now create multiple Cloudflare Tunnel and Cloudflare Mesh routes from the Routes page in a single action, instead of submitting one route at a time.

Creating multiple Cloudflare Tunnel and Cloudflare Mesh routes at once from the Routes page

When creating a route, you can now:

  • Add multiple destinations at once — Enter a comma-separated list of CIDR ranges or hostnames to create several routes of the same type and connector together.
  • Queue up multiple routes — Select Add another to stage additional routes, including different types or connectors, before creating them all in one action.
  • Retry only what failed — If some routes in a batch fail (for example, an invalid CIDR), the routes that were created successfully are removed from the form automatically, so you only need to fix and resubmit the ones that failed.

The same Routes UI already supports bulk creation for Cloudflare WAN static routes, so you can add multiple WAN destinations or queue up several WAN routes before creating them together as well.

Go to Routes ↗ …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Verbesserte Dataset-Konfiguration in Log Explorer

Log Explorer bietet im Dashboard eine überarbeitete Dataset-Konfiguration mit gruppierter Feldauswahl, Felddetails, Massenauswahl und Ingestion-Filtern.

Log Explorer has a refreshed dataset configuration experience in the Cloudflare dashboard. The new controls make it easier to choose which fields and events Log Explorer ingests.

  • Grouped field selection organizes fields by category and shows the number selected in each group.
  • Field details identify each field's data type and mark required or deprecated fields.
  • Bulk controls let you select all fields or reset the selection to the dataset defaults.
  • Ingestion filters let you ingest all events or only events that match your conditions.

These controls are available when you add a dataset or select Actions > Edit for an enabled dataset.

For more information, refer to Configure fields and filters.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Log Explorer-Datasets löschen

Account- und Zone-Datasets in Log Explorer können nun im Dashboard oder per API dauerhaft gelöscht werden, sofern der standardmäßig aktive Löschschutz zuvor deaktiviert wurde.

Cloudflare Log Explorer customers can now permanently delete account and zone datasets from the Cloudflare dashboard or API.

Deletion protection is enabled by default to prevent accidental data loss. In the dashboard, go to Manage datasets, disable deletion protection for the dataset, select Delete, and enter the dataset name to confirm.

To delete a dataset through the API, first set deletion_protection to false with the Update an account or zone dataset method. Then use the Delete an account or zone dataset method.

Dataset deletion is irreversible and runs asynchronously. You cannot recreate the same dataset while deletion is in progress.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Azure Functions-basierter Microsoft Sentinel-Connector wird eingestellt

Enterprise-Kunden müssen bis zum 14.09.2026 vom Azure Functions-basierten Microsoft Sentinel-Connector auf den Cloudflare for Microsoft Sentinel CCF-Connector migrieren, da Microsoft die Azure Monitor HTTP Data Collector API abschaltet.

Cloudflare Enterprise customers using the Azure Functions-based Microsoft Sentinel connector ↗︎ must migrate to the Cloudflare for Microsoft Sentinel Codeless Connector Framework (CCF) connector ↗︎ by 2026-09-14.

Microsoft is deprecating the Azure Monitor HTTP Data Collector API. Support for the API ends on 2026-09-14. As a result, Cloudflare will no longer maintain the Azure Functions-based connector after that date.

To migrate, follow the Microsoft Sentinel integration setup guide.

Additional resources

For more information, refer to Microsoft's Azure Monitor HTTP Data Collector API deprecation notice ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Erweiterte 403-Antworten der Cloudflare API

403-Forbidden-Antworten der Cloudflare API enthalten nun ein Feld documentation_url, das auf die Dokumentation des abgelehnten Endpunkts mit den erforderlichen Rollen verweist.

Cloudflare API 403 Forbidden responses now include a documentation_url field that links directly to the API documentation for the endpoint that was denied. This gives developers, administrators, and agents an immediate path to the relevant docs with role information instead of guessing at which role or permission they are missing for that endpoint.

What's New

Enriched 403 error responses: When a Cloudflare API request is denied, the error response now includes a documentation_url field that points to the documentation for that specific endpoint. Contextual 403 responses are now available across nearly all Cloudflare product APIs.

Faster troubleshooting: The linked API docs surface the roles required for each endpoint, making it easier to self-serve access issues.

Better support for tools and agents: Agents can use the \documentation_url` field to immediately fetch the endpoint's documentation from the 403 error response, identify the accepted permissions for the denied action, and use that context to drive third-party approval workflows.`

Example 403 response:

{
  "success": false,
  "errors": [
    {
      "code": 10000,
      "message": "Forbidden",
      "documentation_url": "https://developers.cloudflare.com/api/resources/workers/subresources/beta/subresources/workers/methods/list"
    }
  ],
  "messages": [],
  "result": null
}

For more info:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Gespeicherte Login-Profile für wiederkehrende Nutzer

Nutzer des Cloudflare Dashboards können nach der Anmeldung bis zu fünf Login-Profile pro Gerät speichern, die auf der Login-Seite die Anmeldung per Passwort, SSO oder Social Login beschleunigen.

Cloudflare Dashboard users can now save login profiles on a device for faster sign-in on future visits.

Saved login profiles for returning users

What's New

Save login profiles on a device: After a successful sign-in, users can choose to save a login profile on that device. Saved profiles store the email address, login method, and last-used profile locally in the browser.

Faster sign-in for returning users: Saved profiles appear directly on the login page. Selecting one can prefill the email field for password logins or resume the associated SSO or social login flow.

Up to five login profiles can be saved per device, and saved profiles can be removed from the profile list at any time.

For more info:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Verbesserte SCIM 2.0-Gruppensynchronisierung

Dashboard SCIM unterstützt nun das Ersetzen von Gruppen per HTTP PUT gemäß RFC 7644, sodass Identity Provider den vollständigen Gruppenzustand in einer Anfrage synchronisieren können.

Dashboard SCIM now supports replacing groups using HTTP PUT, as defined by RFC 7644 section 3.5.1 ↗︎. This allows identity providers to synchronize a group's full state, including its display name, external ID, and members, in a single request.

What's New

Group replacement via PUT: Full-state group synchronization improves compatibility with identity providers that use replacement semantics and helps keep Cloudflare groups aligned with their source identity provider.

Note

SCIM provisioning for the Cloudflare dashboard is available to Enterprise customers. You must be a Super Administrator to complete the initial setup.

For more information:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Optionale OAuth-Scopes allgemein verfügbar

OAuth-Client-Entwickler können konfigurierte Scopes nun als erforderlich oder optional markieren, und der Zustimmungsbildschirm erlaubt das Ablehnen optionaler Scopes und bietet Vorlagen und eine Suche.

We're announcing the GA of Optional OAuth Scopes.

OAuth client developers can now classify configured scopes as required or optional in the Cloudflare dashboard. By default, all configured scopes remain required .

What's New

Optional Scopes: OAuth clients can now mark configured scopes as optional, allowing applications to request them without requiring users to approve them.

Scope Selection: On the consent screen, users must grant required scopes but can decline optional scopes. This helps customers apply least-privilege access to applications, CLIs, and workloads. Optional scopes are selected by default.

Templates: The consent screen now includes Read Only and Full Access templates to make scope selection faster and easier.

Search: Users can now search scopes in the consent screen.

Learn how to select client scopes and edit optional permissions.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Neue Logpush-Datasets und aktualisierte Felder in Cloudflare Logs

Es gibt die neuen Logpush-Datasets Account Abuse Protection Events und Magic BGP Logs sowie zusätzliche Felder in den Datasets Firewall events, Gateway HTTP und HTTP requests.

Cloudflare has updated Logpush datasets:

New datasets

  • Account Abuse Protection Events: A new dataset with fields including AuthenticationIdentityProvider, AuthenticationMethod, AuthenticationStatus, BotScore, ClientASN, ClientCity, ClientCountry, ClientIP, Email, EphemeralID, EventSource, EventType, FraudEmailRisk, Host, JA4, RayID, Timestamp, UserAgent, and UserID.
  • Magic BGP Logs: A new dataset with fields including Direction, EventData, EventKind, EventTimestamp, TunnelID, and TunnelName.

Updated fields in existing datasets

  • Firewall events (added): AISecurityCustomTopicCategories, WAFRequestSignatureCategories, and WAFRequestSignatureRefs.
  • Gateway HTTP (added): ExperimentalFeatures and PackageInfo.
  • HTTP requests (added): AISecurityCustomTopicCategories, ClientTLSKeyExchangeGroup, WAFRequestSignatureCategories, and WAFRequestSignatureRefs.

For the complete field definitions for each dataset, refer to Logpush datasets.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Post-Quantum-Sichtbarkeit pro Zone in Logpush und Log Explorer

Das Logpush-Dataset http_requests enthält nun das Feld ClientTLSKeyExchangeGroup, mit dem sich pro Zone auswerten lässt, welcher Anteil des HTTPS-Traffics durch Post-Quantum-Schlüsselaustausch geschützt ist.

Cloudflare Radar ↗︎ publishes global statistics on post-quantum key agreement adoption across all Cloudflare traffic, but until now customers had no way to see the same measurement scoped to their own zones. This is now possible because the http_requests Logpush dataset — also queryable in Log Explorer — includes a new ClientTLSKeyExchangeGroup field.

The field reports the TLS key exchange group negotiated on the client-to-Cloudflare connection, by group name. Post-quantum connections appear as X25519MLKEM768, and classical connections appear as X25519, P-256, or another named group. A value of UNK means the group could not be determined, and NONE means either RSA key exchange was used or TLS was not used.

With this field, you can build per-zone reports showing what percentage of your inbound HTTPS traffic is protected by post-quantum key agreement, break the number down by hostname, path, user agent, or country, and push the data into your SIEM via any Logpush destination.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Access-Ressourcenlisten unterstützen ressourcenbezogene Rollen

Mitglieder mit ausschließlich ressourcenbezogenen Access-Rollen können nun Access-Ressourcenlisten im Dashboard und per API abrufen und sehen dabei nur die Ressourcen innerhalb ihrer Berechtigungsbereiche.

Members with only resource-scoped Access roles can now open Access resource list pages in the Cloudflare dashboard and call list endpoints in the API. They no longer need an additional account-scoped read-only role to list resources.

The dashboard and API return only resources included in the member's permission policy scopes. Filtering applies to Access applications, policies, service tokens, and identity providers. This allows administrators to delegate specific Access resources without granting account-wide visibility. Previously, the dashboard blocked these list pages and API list requests returned 403 responses.

For members with the Cloudflare Access App Admin role, policy lists include policies attached directly to the selected application. Reusable policies appear only when the member has the Cloudflare Access Policy Admin role for those policies.

For role definitions and assignment details, refer to Resource-scoped roles and Role scopes.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Origin-Anwendungseinstellungen für Cloudflare Tunnel im Dashboard

Beim Hinzufügen oder Bearbeiten einer veröffentlichten Anwendungsroute eines Cloudflare Tunnel lassen sich HTTP-, TLS- und Verbindungsparameter für die Origin-Verbindung von cloudflared nun direkt im Cloudflare-Dashboard konfigurieren.

You can now configure origin application settings directly in the Cloudflare dashboard when adding or editing a published application route for a Cloudflare Tunnel. These settings control how cloudflared connects to your origin server and were previously only available in the Cloudflare One dashboard or via local configuration files.

Configure origin application settings in the Cloudflare dashboard

When editing a published application, expand Additional application settings to configure parameters organized into three categories:

  • HTTP — Set a custom HTTP Host header or disable chunked encoding.
  • TLS — Configure origin server name, CA pool, TLS timeout, disable TLS verification, match SNI to host, or enable HTTP/2 to origin.
  • Connection — Tune connect timeout, keep-alive timeout, keep-alive connections, TCP keep-alive interval, proxy type, or disable Happy Eyeballs.

Go to Tunnels ↗

For the full list of origin parameters, refer to Origin parameters.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

WebSocket-Reporting enthält vollständige Datenübertragung und Dauer

Ein Fehler wurde behoben, durch den HTTP Traffic Analytics und HTTP-Request-Logs bei manchen WebSocket-Verbindungen nur Bytes und Dauer des anfänglichen 101 Switching Protocols-Handshakes erfassten, und sie zeigen nun die Daten und Dauer der gesamten Sitzung.

Cloudflare has fixed an issue affecting WebSocket data transfer and session duration reporting. HTTP Traffic Analytics and HTTP request logs now correctly report data transferred throughout a WebSocket connection and the duration of the full session. During the affected period, reporting captured only the bytes and duration of the initial 101 Switching Protocols handshake for some WebSocket connections.

Customers with WebSocket traffic will see the correct Data Transfer in the dashboard and EdgeResponseBytes in analytics and HTTP request logs. Reported session duration now reflects the full WebSocket session rather than only the handshake. These changes restore the accounting of existing WebSocket traffic and duration. They do not indicate an increase in traffic or alter WebSocket connection behavior.

The separate WebSocket Analytics Logpush dataset continues to provide per-connection directional byte counts, timestamps, and close details.

For more information about HTTP Traffic Analytics, refer to Zone Analytics.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Oracle Cloud Infrastructure Object Storage in Cloud Connector

Cloud Connector unterstützt nun öffentliche Oracle Cloud Infrastructure Object Storage Buckets über die Amazon S3 Compatibility API, sodass passende Anfragen ohne separate Origin-Routing-Konfiguration dorthin geleitet werden können.

Cloud Connector now supports public Oracle Cloud Infrastructure (OCI) Object Storage buckets. You can route matching requests to OCI without managing a separate origin-routing configuration.

OCI support uses the Amazon S3 Compatibility API. Both path-style and virtual-hosted endpoint formats are supported, including traditional oraclecloud.com and dedicated customer-oci.com path-style endpoints.

Public buckets only

Cloud Connector does not sign requests or provide OCI credentials. Your bucket must allow anonymous object reads. Private buckets and pre-authenticated request URLs are not supported.

API example

Set provider to oci_storage and provide a supported OCI hostname. The following rule uses a virtual-hosted endpoint:

{
	"expression": "http.request.uri.path wildcard \"/assets/*\"",
	"provider": "oci_storage",
	"description": "Route assets to OCI Object Storage",
	"enabled": true,
	"parameters": {
		"host": "<BUCKET_NAME>.vhcompat.objectstorage.<REGION>.oci.customer-oci.com"
	}
}

For endpoint formats and bucket requirements, refer to Supported cloud providers in Cloud Connector.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Neue Cloudflare Status-Seite

Die Cloudflare Status-Seite wurde neu aufgebaut und bietet unabhängige Benachrichtigungen per E-Mail, Webhook, Slack, Discord oder Google Chat, Markdown-Ausgabe für KI-Agenten sowie getrennte RSS- und Atom-Feeds für Vorfälle und Wartungen.

The Cloudflare Status page at www.cloudflarestatus.com ↗︎ has been rebuilt. It is available at the same address, and every previously documented Status API ↗︎ endpoint remains supported, so existing bookmarks, integrations, and monitoring continue to work.

Notifications that fire even when Cloudflare is down

The status page now has its own notification system, delivered independently of Cloudflare infrastructure. You can subscribe by email, webhook, Slack, Discord, or Google Chat.

The Maintenance Notification and Incident Alerts in Cloudflare Notifications remain supported, and deliver to the destinations already configured on your account.

Markdown for AI agents

Every page on the status page returns Markdown when requested with an Accept: text/markdown header, so agents can read the current status without parsing HTML:

curl -H "Accept: text/markdown" https://www.cloudflarestatus.com/locations

Separate feeds for incidents and maintenance

Incidents and maintenance are published as separate feeds, each available in RSS and Atom, so you can subscribe to one without the other:

https://www.cloudflarestatus.com/api/v3/incidents.rss …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Hostname routing allgemein verfügbar mit neuem öffentlichem IP-Bereich

Hostname routing ist für Cloudflare Tunnel und Cloudflare Mesh nun allgemein verfügbar, und der Standardbereich für initial aufgelöste IPs wechselt von einem CGNAT-Bereich auf die öffentlichen Cloudflare-Bereiche 172.64.128.0/20 und 2606:4700:0cf1:4000::/64.

Hostname routing ↗︎ is now generally available. Instead of managing static IP lists and routes, you can route traffic by hostname across multiple Cloudflare One connectors:

  • Cloudflare Tunnel: route a private hostname (for example, wiki.internal.local) to a private application behind your tunnel, or a public hostname (for example, bank.example.com) to egress through a specific tunnel and anchor traffic to a dedicated exit node.
  • Cloudflare Mesh: attract a private or public hostname's traffic to a Mesh node.

Alongside GA, the default IPv4 range used for initial resolved IPs (also called token IPs) is changing from a Carrier-Grade NAT (CGNAT) range to a public Cloudflare-owned range:

  • IPv4: 172.64.128.0/20
  • IPv6: 2606:4700:0cf1:4000::/64

This is the default range. You can configure a custom initial resolved IP range for IPv4 if it conflicts with your existing network. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Live-Logs von Cloudflare Tunnel im Dashboard streamen

Im Cloudflare-Dashboard gibt es unter Networking > Tunnels einen neuen Tab "Live logs", der Logs einzelner oder mehrerer Connectors in Echtzeit streamt und nach Log-Level, Ereignistyp und HTTP-Methode filtern lässt.

Real-time Tunnel log streaming is now available in the Cloudflare dashboard under Networking > Tunnels. This brings the same live debugging capability previously only available in the Cloudflare One dashboard, including multi-connector aggregated streaming for high-availability deployments.

Stream live logs from a tunnel in the Cloudflare dashboard

In the tunnel detail view, a new Live logs tab lets you:

  • Stream logs from single or multiple connectors — In highly available deployments with multiple cloudflared replicas, logs from all connectors are merged into a single stream grouped by hostname, making it easy to identify which host machine produced each log entry.
  • Filter by log level, event type, and HTTP method — Narrow the stream to only the events you care about (HTTP, TCP, UDP, or cloudflared internal), at any log level.

Go to Tunnels ↗

For more information, refer to Tunnel observability and Tunnel log streams.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Verbesserte Publisher-Verifizierung auf OAuth-Zustimmungsbildschirmen

OAuth-Zustimmungsbildschirme zeigen nun ein Schild-Symbol mit Erklärung, das anzeigt, wem die Anwendung gehört und ob die Domain-Inhaberschaft verifiziert ist.

OAuth consent screens now display a shield icon with explanatory text beneath the consent screen title. Each shield icon indicates who owns the application and whether its domain ownership is verified.

  • Green filled shield: Cloudflare owns and manages the application.
  • Blue outlined shield: A third-party application with verified ownership of its domain.
  • Amber filled shield: A third-party application without verified ownership of a domain.

Domain verification only confirms that the application owner controls the displayed domain.

For more information, refer to Authorizing an application.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Free-Accounts direkt im Dashboard erstellen

Über die neue Schaltfläche "Create Account" im Cloudflare-Dashboard können Nutzer mit mindestens 7 Tagen Kontoalter bis zu 5 eigenständige Free-Accounts sofort erstellen.

You can now create standalone Free accounts directly from the Cloudflare dashboard using the new Create Account button. This feature is currently available to all users.

When creating a Free account:

  • You can create up to 5 Free accounts.
  • Your user account must have at least 7 days of tenure to be eligible.
  • The account is created immediately and ready to use.

To create a Free account, go to the Cloudflare dashboard ↗︎ and select Create Account from either the account switcher in the top left (where your account name appears) or from the Accounts page.

Limitations

  • This feature can only be used to create a Cloudflare Free account. To create an Enterprise Account under your existing contract, please contact Cloudflare Support.
  • All users can create a Cloudflare Free account, however, Enterprises wish to restrict this action to only Super Administrators. We will deliver this improvement in a future release.

Next steps

After creating your Free account, you can:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Audit Logs v2: Resource History

Audit Logs v2 zeigt zu jedem Eintrag nun die Abfolge früherer Änderungen derselben Ressource samt Side-by-Side-Diff, im Dashboard über den Tab "History" und per API über den History-Endpunkt.

Audit Logs v2 now includes Resource History. For any audit log entry, you can see the sequence of previous changes to the same resource and view a side-by-side diff of what was modified.

Resource History uses the audit log entries you already have. There is no additional configuration, no backend recapture, and no changes to how audit logs are generated.

Resource History in Audit Logs v2

Dashboard:

  1. Go to Manage Account > Audit Logs.
  2. Open any audit log entry.
  3. Select the History tab to see the full history for that resource.
  4. Select any earlier entry to see a side-by-side diff of the fields that changed between it and the current entry.

API:

Use the History endpoint to retrieve the change history for any audit log entry:

GET https://api.cloudflare.com/client/v4/accounts/{account_id}/logs/audit/{id}/history

The endpoint is also available for organization-scoped audit logs at /organizations/{organization_id}/logs/audit/{id}/history.

For more information, refer to the Resource History documentation.

Originalquelle(öffnet in neuem Tab)Problem melden