Zum Inhalt springen

Core Platform Updates & Release Notes

46 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Core Platform, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Account Roles API veraltet, Ersatz ist die Permission Groups API

Die Account Roles API ist deprecated und wird durch die Permission Groups API ersetzt, wobei sich das Antwortschema unterscheidet und Integrationen mit gespeicherten Role-IDs ihre Zuweisungen neu zuordnen müssen; ein End-of-Life-Datum steht noch nicht fest.

The Account Roles API is deprecated and is being replaced by the Permission Groups API. An end of life date has not yet been established.

What you need to do

Review the Permission Groups API documentation; the response schema differs from the legacy Roles response.

Highlights

  • Integrations migrating to the Permission Groups API must obtain Permission Group IDs from that API and use them in the Account Members API policies request shape. Integrations that persist legacy Role IDs will need to remap their assignments.
  • The legacy Role response includes a top-level description and a permissions object keyed by resource type with edit/read flags.
  • The PermissionGroup response replaces those with a meta object containing label and scopes. Individual permissions are not returned as part of the permission group.
  • The new API supports the API Token authorization scheme. The legacy Email + API Key authorization schema is provided for backwards compatibility. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Budget-Alerts jetzt standardmäßig für Pay-as-you-go-Accounts aktiv

Für berechtigte Pay-as-you-go-Accounts ohne Budget-Alert legt Cloudflare schrittweise einen Standard-Alert mit 10-$-Schwelle an, der zum nächsten Abrechnungszyklus aktiv wird, nur per E-Mail informiert und sich anpassen oder entfernen lässt.

We are turning on budget alerts by default for eligible Pay-as-you-go accounts. If your account does not already have a budget alert, Cloudflare will create one for you with a $10 account-level threshold. Your default alert will enable at the turn of your next billing cycle, so it will not fire based on usage you have already incurred.

We are rolling this out in cohorts over the coming weeks, so eligible accounts may see their default alert appear at different times.

The default alert behaves exactly like an alert you would create yourself. When your cumulative usage-based spend this cycle reaches the threshold, you receive an email notification. The alert is informational only. It does not cap your usage or impact your account in any way.

Usage is processed once per day for the prior day's activity, so budget alerts fire the day after the threshold is reached rather than in real time.

Budget alerts only consider spend on usage-based products. Recurring subscription fees, such as the Workers Paid plan fee or other monthly plan charges, are not included in the threshold calculation.

You can change the threshold, add additional alerts, or remove the default alert entirely from Manage Account > Billing > Billable Usage, or from your Notifications settings. If you already configured your own budget alert, nothing changes.

Enterprise contract accounts are not in scope. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Partner können Organization-Mitglieder direkt verwalten

Distributor-, MSSP- und Agency-Partner können Organization-Mitglieder jetzt ohne Hilfe von Cloudflare und ohne Beta-Anmeldung selbst über Organization > Members > Add member hinzufügen, und Agency-Partner erhalten zusätzlich Zugriff auf das Organizations-Dashboard.

Distributor, MSSP, and Agency partners on Cloudflare Organizations can now add and manage Organization Members directly from the Cloudflare dashboard, without help from Cloudflare.

Previously, adding a member to a Distributor, MSSP, or Agency Organization was a manual, Cloudflare-assisted process that required a request to Cloudflare and enrollment in a closed beta, and the dashboard Add member flow was blocked for these Organizations.

Now, Organization admins can add members themselves from Organization > Members > Add member, with no beta enrollment required.

New members receive access to the Organization's accounts through the same implicit-access model already used for enterprise Organizations. The Accounts list and the account switcher classify Distributor, MSSP, and Agency Organizations consistently with enterprise Organizations, so their accounts are labeled and grouped correctly in the dashboard.

Agency partners also gain access to the Organizations dashboard, while retaining access to their existing Tenant management dashboard.

Distributor, MSSP, and Agency Organizations are currently in beta.

For more information, refer to Manage Organization members.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Bot-Management-Felder und ASN-Unterstützung in Cache Rules

Cache Rules unterstützen in Ausdrücken jetzt Bot-Management-Felder wie cf.bot_management.score und ip.src.asnum, sodass sich Caching-Richtlinien nach Bot-Verkehr oder ASN differenzieren lassen.

Bot management fields and ASN support in Cache Rules

Cache Rules now supports bot management fields and the ip.src.asnum field in expression filters. You can now build cache policies that differentiate between automated and human traffic, or segment caching behavior by autonomous system number (ASN).

This allows you to apply different caching strategies for verified bots, high-risk traffic, or specific network operators without affecting legitimate user requests. For example, you can set shorter cache TTLs for suspected bot traffic or bypass cache entirely for requests from specific ASNs.

New fields

The following fields are now available in Cache Rules expressions:

Field

Type

Description

cf.bot_management.score

Number

Bot score from 1 to 99, where a lower value indicates a higher likelihood that the request originates from a bot.

cf.bot_management.ja3_hash

String

JA3 fingerprint of the request, which helps identify the client making the connection.

cf.bot_management.ja4

String

JA4 fingerprint of the request, which provides a more detailed client identification than JA3.

cf.bot_management.verified_bot

Boolean

Whether the request originates from a verified bot, such as a search engine crawler.

cf.bot_management.static_resource

Boolean

Whether the request is for a static resource and therefore exempt from bot detection. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Origin Content Signals für Markdown for Agents

Markdown for Agents behält beim Konvertieren von HTML zu Markdown Sicherheits- und Caching-Header des Origins bei, berücksichtigt einen vom Origin gesetzten content-signal-Header vorrangig und löst relative Links bei Basis-URLs mit abschließendem Schrägstrich nun korrekt auf.

Markdown for Agents now preserves security- and cache-relevant response headers from your origin when converting HTML to Markdown:

  • Markdown for Agents preserves security headers such as Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-Frame-Options, Set-Cookie, and CORS headers (for example, Access-Control-Allow-Origin) on the converted response.
  • Caching headers (Cache-Control, Expires, Age) continue to pass through.

Your origin's Content Signals ↗︎ policy is now authoritative. If your origin sets a content-signal header, Markdown for Agents preserves it. When the origin does not send one, Cloudflare adds the default Content-Signal: ai-train=yes, search=yes, ai-input=yes.

This release also fixes relative link resolution for directory-style base URLs (those ending in a trailing slash). Previously, relative links such as ../page/ could resolve one path segment too high and return a 404. Links are now resolved correctly per RFC 3986 ↗︎.

Refer to our developer documentation for more details.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Zero-Trust-Route-Endpunkte und Tunnel-Feld connections entfallen am 5. Oktober 2026

Am 5. Oktober 2026 werden die CIDR-kodierten Route-Endpunkte der Zero Trust Networks API entfernt und die Tunnel-Antworten enthalten das Feld connections nicht mehr, weshalb Nutzer vorher auf die route_id-basierten Endpunkte migrieren sollten.

On October 5, 2026, two changes take effect across the Zero Trust Networks API and Cloudflare Tunnel API: the CIDR-encoded route endpoints are removed, and tunnel list and get responses no longer include the connections field. If you manage private network routes or read tunnel connection details through the API, cloudflared, Terraform, or another integration, review the changes in the following sections and migrate before the removal date.

Route endpoints

The CIDR-encoded route endpoints are deprecated in favor of the standard, route_id-based endpoints that already exist today. Both sets of endpoints route a private network through Cloudflare Tunnel or Cloudflare Mesh (the API still refers to Mesh nodes as warp_connector) — only the request shape changes.

Deprecated endpoints (removed October 5, 2026):

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform Updates & Release Notes (Cloudflare) – Oktober 2026 (Seite 3) | updatefeed