Zum Inhalt springen

Cloudflare Release Notes

1.616 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Storage von Cloudflare

R2 Data Catalog: Wartungsübersicht und manuelles Einreihen von Compaction

R2 Data Catalog bietet im Dashboard einen Maintenance-Tab mit Einstellungen, Zeitplänen und Verlauf der Wartungsläufe sowie die Möglichkeit, Compaction manuell in die Warteschlange zu stellen.

Basin Catalog Basin R2

R2 Data Catalog now provides table-level maintenance visibility and manual compaction queueing in the Cloudflare dashboard. These updates make it easier to understand when maintenance is eligible to run, inspect completed operations, and request maintenance without leaving the table view.

To view table maintenance details:

  1. In the Cloudflare dashboard, go to R2 Data Catalog.
  2. Select a catalog, then select the Explorer tab. The Explorer tab opens by default.
  3. Select a table.
  4. Select the Maintenance tab.

Maintenance tab for an R2 Data Catalog table showing schedules and recent runs

The updated dashboard includes:

  • Maintenance tab — View compaction and snapshot expiration settings, schedules, and next eligibility alongside the table's Schema and Metadata tabs.
  • Recent runs — Review a paginated audit log with job status, duration, and expandable details for manifest rewrites, compaction, and snapshot expiration. Expanded rows include operation metrics for each maintenance operation. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

Bots: JavaScript-Detections-API-Ergebnisse steuerbar

Enterprise-Bot-Management-Kunden können unter Security > Settings oder per jsd_api_results_enabled in der Bot Management API festlegen, ob Cloudflare die Ergebnisse der JavaScript Detections API für Bot-Scoring und Erkennungen nutzt.

Enterprise Bot Management customers can control whether Cloudflare uses results created through the JavaScript Detections API for bot scoring and detections.

Turn JavaScript Detections for API traffic on or off in Security > Settings. You can also configure the zone through the Bot Management API by setting jsd_api_results_enabled:

{
	"jsd_api_results_enabled": true
}

This setting is separate from zone-wide script injection. When it is off, the API script can still execute and return success to the callback, but Cloudflare does not consume the result.

For more information, refer to JavaScript Detections.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access for Infrastructure unterstützt Tags für Targets und tagbasierte Kriterien

Access for Infrastructure unterstützt jetzt Resource Tagging, sodass Targets mit Schlüssel-Wert-Tags versehen und in Richtlinien über Target-Kriterien mit include, require und exclude nach Hostname oder Tag ausgewählt werden können.

Access for Infrastructure now integrates with Resource Tagging. You can attach key-value tags to infrastructure targets and use them in access policies.

You can manage tags on targets inline when you create or edit a target or through the central Resource Tagging API. Cloudflare keeps tags in sync across both methods.

Infrastructure applications also support a target criteria model with include, require, and exclude operators. Each operator can match targets by hostname, tag, or both.

  • Include matches targets that have any of the specified values.
  • Require matches targets that have all of the specified values.
  • Exclude rejects targets that have any of the specified values.

Infrastructure application builder showing target criteria with an included tag, port 22, and SSH as the selected protocol …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Workflow-Instanz-Events mit .subscribe() streamen

Mit WorkflowInstance.subscribe() und dem Endpunkt GET /subscribe lassen sich Workflow-Instanz-Events streamen, ohne den Status abfragen zu müssen.

You can now stream Workflow instance events via WorkflowInstance.subscribe() and the GET /subscribe API endpoint. Workers and HTTP clients can react to workflow and step events, including attempts, sleeps, waits, and rollbacks, without polling for instance status.

A subscription first streams the entire event history of the Workflow instance. After streaming past events, the subscription waits for new events as the instance runs. You can use filter to receive only specific event types or cursor to start a subscription at a specific event.

Use .subscribe() to update Workflow status in user-facing dashboards, send notifications when steps complete, or trigger follow-up work for specific events.

const instance = await env.MY_WORKFLOW.get("report-123");

using subscription = await instance.subscribe();

while (true) {
	const { value, done } = await subscription.next();
	if (done) {
		break;
	}

	console.log(value.type, value);
}
const instance = await env.MY_WORKFLOW.get("report-123");

using subscription = await instance.subscribe();

while (true) {
	const { value, done } = await subscription.next();
	if (done) {
		break;
	}

	console.log(value.type, value);
}
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Zugriff auf einzelne Workers für Teammitglieder und Agents gewähren

Der Zugriff auf einzelne Workers lässt sich jetzt für Teammitglieder, Agents und CI/CD über vier Rollen steuern: Metadata Read-Only, Content Read-Only, Editor und Admin.

You can now grant access to specific Workers and choose from four roles to control the level of access you give teammates, agents, and CI/CD workflows.

Choose from four roles to control the level of access:

  • Metadata Read-Only: View settings, metrics, logs, and traces without access to Worker code or the ability to make changes.
  • Content Read-Only: Read Worker code, settings, and observability data without the ability to modify or deploy changes.
  • Editor: Update and deploy a Worker without the ability to delete it.
  • Admin: Everything in Editor, plus the ability to delete the Worker.

Permission policy form showing four roles scoped to an individual Worker

Worker-level access controls are available today for all customers. You can configure them in the Cloudflare dashboard, through the API, or with Terraform.

Roles designed for how teams build

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

WAF Release 2026-09-15: SSRF, Command Injection, Version Control

Neue Erkennungen für SSRF auf Cloud-Metadaten und Command Injection (Generic 10) wechseln von Log auf Block, zudem wird die Beta-Regel „Version Control - Information Disclosure“ in die Originalregel überführt.

This release introduces new threat detections to enhance protection against command injection attempts, Server-Side Request Forgery (SSRF) targeting cloud metadata, and information disclosure within version control history.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...ca453d31

N/A

SSRF - Cloud - 3

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...e540f17f

N/A

Version Control - Information Disclosure - Beta

Log

Block

This rule is merged into the original rule "Version Control - Information Disclosure" (ID: ...0550c529).

Cloudflare Managed Ruleset

...ba458b4b

N/A

Command Injection - Generic 10

Log

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Docs Collections von Cloudflare

Zusätzliche Free-Accounts per Dashboard und API erstellen

Kunden können zusätzliche Free-Accounts im Dashboard sowie per User-owned API Token oder OAuth Access Token anlegen, und Super Administrators können bis zu fünf Free-Accounts direkt in einer Enterprise Organization erstellen.

Cloudflare Fundamentals

We're expanding how customers create accounts across Cloudflare, making it easier to self-serve account creation in the dashboard, automate standalone account creation with user-owned API tokens or OAuth access tokens, and create Free accounts directly within Enterprise Organizations.

What's New

Dashboard account creation: All cloudflare customers can create additional Free accounts directly through self-serve flows in the Cloudflare dashboard.

Enterprise Organization account creation: Super Administrators can now create up to five Free accounts directly within an Enterprise Organization. This makes it easier to provision and manage additional accounts and directly associate them with your Organization.

API and OAuth account creation: Customers can now create standalone Free accounts programmatically via User-owned API tokens or OAuth access tokens.

For more information:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

AI Gateway von Cloudflare

AI Gateway: Unified-Billing-Fallback für BYOK-Provider verhindern

AI Gateway kann nun über die Einstellung Require provider credentials (byok_only) oder den Header cf-aig-no-wholesale verlangen, dass Zugangsdaten für Drittanbieter vorliegen, und verhindert so den Fallback auf Unified Billing, wobei Anfragen ohne Credentials HTTP 400 erhalten.

AI Gateway can now require credentials for third-party provider requests. Credentials must accompany the request or be stored on the gateway. This setting prevents fallback to Unified Billing with Cloudflare-managed credentials.

Turn on Require provider credentials in your gateway settings. To use the API, set byok_only to true in the request body of a PUT request to update the gateway:

{
	"byok_only": true
}

To require provider credentials for one third-party request, set the cf-aig-no-wholesale header to true. This header cannot relax the gateway setting.

Requests without applicable credentials then return an HTTP 400 response. Workers AI requests remain allowed, and the setting does not change their configured billing mode.

For configuration details and request-level controls, refer to Prevent Unified Billing fallback for BYOK third-party providers.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Frische Authentifizierung für SAML-Identity-Provider erzwingen

Cloudflare Access kann bei SAML-Identity-Providern für jeden Login eine frische Authentifizierung anfordern, indem „Require reauthentication“ aktiviert oder „force_authn“ auf true gesetzt wird.

Cloudflare Access can now request fresh authentication from a SAML identity provider for every login. Turn on Require reauthentication in the Cloudflare dashboard, or set force_authn to true through the API. Access will then set ForceAuthn to true in signed and unsigned SAML authentication requests.

This option is useful when an application requires users to reauthenticate at the identity provider instead of relying on an existing identity provider session. The default value is false.

For configuration details, refer to Require fresh authentication at the identity provider.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP: Passive Detection zeigt, wohin sensible Daten fließen

Passive Detection für Cloudflare DLP ist allgemein verfügbar und zeigt in einem Dashboard sensible Datentypen und deren Ziele aus gesampelten Gateway-Traffic-Daten, ohne dass eine Gateway-DLP-Policy nötig ist.

Passive Detection for Cloudflare Data Loss Prevention (DLP) lets you learn from your Gateway traffic before deciding what to log or block. Discover the sensitive data types in sampled traffic, explore their destinations, and use the findings to build policies around your organization's needs.

The dashboard brings together detections from sampled HTTP request and response bodies. Select an entry to follow its detections over time, review destinations, and check policy coverage. You do not need a Gateway DLP policy to get these insights, and existing Gateway policies continue to apply.

Passive Detection dashboard showing detection totals, data type distribution, policy coverage, and detection entries

Passive Detection is generally available. The detection entries available to your account depend on your Zero Trust plan.

To get started, refer to the Passive Detection documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

AI Gateway: Unified-Billing-Fallback für BYOK-Drittanbieter verhindern

AI Gateway kann Anbieter-Zugangsdaten für Drittanbieter-Anfragen verpflichtend machen und verhindert so den Rückfall auf Unified Billing mit von Cloudflare verwalteten Zugangsdaten.

AI Gateway can now require credentials for third-party provider requests. Credentials must accompany the request or be stored on the gateway. This setting prevents fallback to Unified Billing with Cloudflare-managed credentials.

Turn on Require provider credentials in your gateway settings. To use the API, set byok_only to true in the request body of a PUT request to update the gateway:

{
	"byok_only": true
}

To require provider credentials for one third-party request, set the cf-aig-no-wholesale header to true. This header cannot relax the gateway setting.

Requests without applicable credentials then return an HTTP 400 response. Workers AI requests remain allowed, and the setting does not change their configured billing mode.

For configuration details and request-level controls, refer to Prevent Unified Billing fallback for BYOK third-party providers.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Browser Run: Zugriff von Sitzungen auf bestimmte Hostnamen steuern

Browser Run unterstützt jetzt Guardrails, die HTTP- und HTTPS-Anfragen einer Browser-Sitzung auf erlaubte Hostnamen beschränken.

Browser Run now supports guardrails, which limit a browser session's HTTP and HTTPS requests to permitted hostnames.

Use guardrails when you need to:

  • Keep a browser workflow limited to a specific website and its subdomains.
  • Load only known third-party APIs, scripts, images, and fonts.
  • Generate a screenshot or PDF from HTML you provide while preventing it from loading external content.

Set guardrails when starting a session with Puppeteer, Playwright, or the REST API. With a browser binding named MYBROWSER, pass guardrails when launching Puppeteer:

import puppeteer from "@cloudflare/puppeteer";

export async function startGuardedSession(env) {
	return puppeteer.launch(env.MYBROWSER, {
		guardrails: {
			allowedDomains: ["example.com", "*.example.com"],
		},
	});
}
import puppeteer from "@cloudflare/puppeteer";

interface Env {
	MYBROWSER: Fetcher;
}

export async function startGuardedSession(env: Env) {
	return puppeteer.launch(env.MYBROWSER, {
		guardrails: {
			allowedDomains: ["example.com", "*.example.com"],
		},
	});
}
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Performance von Cloudflare

DNS: Warnungen für überschattete Einträge in allen Zonen

Cloudflare zeigt jetzt in allen Zonen Warnungen für Shadowed Records an, und die DNS-Records-API liefert mit include_shadow_metadata=true zusätzliche Shadow-Metadaten.

Cloudflare now displays warnings for shadowed records in all zones. A record is shadowed when a subdomain delegation gives authority for its name, or a name below it, to another set of nameservers. The record remains present, but your zone is not authoritative for it thus Cloudflare will not respond with it to matching DNS queries. These warnings help you find records that may no longer resolve from the expected zone.

Shadow metadata is also available in DNS records API responses when you set include_shadow_metadata=true. The metadata identifies the delegating NS records and, when applicable, whether an A or AAAA record is glue. For more information, refer to Shadowed records.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

Azure-Functions-Connector wird nach 2026-09-14 nicht mehr gepflegt

Da Microsoft die Unterstützung der Azure Monitor HTTP Data Collector API am 2026-09-14 beendet, pflegt Cloudflare den Azure-Functions-basierten Connector danach nicht mehr, und die Migration erfolgt über die Microsoft-Sentinel-Integrationsanleitung.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare AI von Cloudflare

AI Gateway: Unified-Billing-Fallback für BYOK-Anbieter verhindern

AI Gateway kann nun Anbieter-Zugangsdaten für Drittanbieteranfragen verlangen (Einstellung byok_only oder Header cf-aig-no-wholesale), sodass kein Fallback auf Unified Billing erfolgt und Anfragen ohne Zugangsdaten mit HTTP 400 abgelehnt werden.

AI Gateway

AI Gateway can now require credentials for third-party provider requests. Credentials must accompany the request or be stored on the gateway. This setting prevents fallback to Unified Billing with Cloudflare-managed credentials.

Turn on Require provider credentials in your gateway settings. To use the API, set byok_only to true in the request body of a PUT request to update the gateway:

{
	"byok_only": true
}

To require provider credentials for one third-party request, set the cf-aig-no-wholesale header to true. This header cannot relax the gateway setting.

Requests without applicable credentials then return an HTTP 400 response. Workers AI requests remain allowed, and the setting does not change their configured billing mode.

For configuration details and request-level controls, refer to Prevent Unified Billing fallback for BYOK third-party providers.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare AI von Cloudflare

Browser Run: Zugriff auf Hostnamen per Guardrails steuern

Browser Run unterstützt jetzt Guardrails, die HTTP- und HTTPS-Anfragen einer Browser-Session auf erlaubte Hostnamen beschränken und beim Start mit Puppeteer, Playwright oder der REST API gesetzt werden.

Browser Run

Browser Run now supports guardrails, which limit a browser session's HTTP and HTTPS requests to permitted hostnames.

Use guardrails when you need to:

  • Keep a browser workflow limited to a specific website and its subdomains.
  • Load only known third-party APIs, scripts, images, and fonts.
  • Generate a screenshot or PDF from HTML you provide while preventing it from loading external content.

Set guardrails when starting a session with Puppeteer, Playwright, or the REST API. With a browser binding named MYBROWSER, pass guardrails when launching Puppeteer:

import puppeteer from "@cloudflare/puppeteer";

export async function startGuardedSession(env) {
	return puppeteer.launch(env.MYBROWSER, {
		guardrails: {
			allowedDomains: ["example.com", "*.example.com"],
		},
	});
}
import puppeteer from "@cloudflare/puppeteer";

interface Env {
	MYBROWSER: Fetcher;
}

export async function startGuardedSession(env: Env) {
	return puppeteer.launch(env.MYBROWSER, {
		guardrails: {
			allowedDomains: ["example.com", "*.example.com"],
		},
	});
}
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Voice Agent: Latenz und Ergebnisse pro Turn einsehen

@cloudflare/voice v0.4.0 liefert pro Voice-Agent-Turn typisierte VoiceTurnMetrics mit Ergebnis und Zeitangaben zu einzelnen Phasen.

@cloudflare/voice v0.4.0 now lets you inspect where each Voice Agent turn spends time and how it ends.

client.addEventListener("turnmetrics", (turn) => {
	console.log(turn.outcome, turn.turnTotalMs);
});

About the Voice package

The @cloudflare/voice package lets you build real-time voice agents with Cloudflare Agents. It streams microphone audio to an Agent over WebSocket, transcribes speech, runs your model through onTurn(), converts the response to speech, and streams audio back to the caller.

A turn moves through several stages:

User speaks -> speech-to-text -> model -> text-to-speech -> audio

Previously, the package's four aggregate metrics covered successful, non-empty speech turns. They did not show how failed, aborted, empty, or text turns ended.

Turn metrics

Each speech or text turn now produces a typed VoiceTurnMetrics summary with:

  • A turnId for correlating events from the same turn.
  • A terminal outcome such as completed, no_output, output_limit, content_filtered, model_error, tts_error, or aborted.
  • Timings for important stages, including speech-to-final-transcript, model-to-first-text, TTS-to-first-audio, and total turn duration.

These timings can overlap and are not additive. Timings for stages that a turn did not reach are omitted. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

AI Search unterstützt R2-Objekte ohne Dateiendung mit Content-Type

AI Search kann jetzt R2-Objekte ohne Dateiendung indexieren, sofern sie unterstützte Content-Type-Metadaten besitzen.

AI Search can index R2 objects without filename extensions when they include supported Content-Type metadata. This supports object keys that do not include file extensions while preserving file-type validation during indexing.

For supported file types and Content-Type requirements, refer to R2 data sources.

Originalquelle(öffnet in neuem Tab)Problem melden