Zum Inhalt springen

Cloudflare Release Notes

1.135 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

workers-auth 0.12.0: Neue OAuth-Scopes für zone-observability

Neue cf-OAuth-Logins fordern zusätzlich die Scopes zone-observability.read und zone-observability.write an, bestehende Sitzungen müssen sich dafür erneut authentifizieren.

Minor Changes

  • #16009 f23dcb3 Thanks @NuroDev! - Allow cf to request the zone observability OAuth scopes

    New cf OAuth logins request zone-observability.read and zone-observability.write. Existing sessions must authenticate again to receive them.

Patch Changes

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Workers SDK von Cloudflare

config 0.23.0: Container-Jurisdiktion "us" ergänzt

Container-Platzierungsregeln akzeptieren in Wrangler und der typisierten Cloudflare-Konfiguration nun constraints.jurisdiction: "us" zusätzlich zu "eu" und "fedramp".

Minor Changes

  • #15928 7f57b1c Thanks @ichernetsky-cf! - Allow "us" as a jurisdiction for Container applications

    Container placement constraints now accept constraints.jurisdiction: "us" in Wrangler and typed Cloudflare configuration. This makes the US jurisdiction available alongside "eu" and "fedramp".

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

30 Tage Analytics-Daten in jedem Tarif

Jeder Tarif erhält mindestens 30 Tage Analytics-Daten (Free und Pro bisher 24 Stunden bis 8 Tage), und die Domain-Analytics sind im Dashboard unter „Analytics“ als Tabs mit gemeinsamem Zeitraum und Filtern zusammengefasst.

Analytics

Every plan now gets at least 30 days of analytics data. Adaptive analytics datasets, such as HTTP requests, security events, and DNS analytics, retain at least 31 days of data for Free and Pro domains, and you can query up to 30 days in a single request. Previously, Free and Pro domains could see between 24 hours and 8 days of history depending on the dataset.

A full month of history lets you investigate an issue after it happens, compare today with the same day in previous weeks, and tell a one-time spike from a longer trend. The change applies in the Cloudflare dashboard, in Custom Dashboards, and through the GraphQL Analytics API.

Domain analytics also now live in one place. In the Cloudflare dashboard, select a domain and go to Analytics to see Traffic, Performance, Security, Cache, Origin, DNS, and Visitors as tabs that share one time range and one set of filters. Account-level analytics are under Observability > Analytics. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Analytics von Cloudflare

Workers-Observability-Logs und -Traces in Custom Dashboards

In Custom Dashboards lassen sich jetzt Diagramme aus den neuen Datasets „Workers Observability — Logs“ und „Traces (OTel)“ erstellen, und pro Account sind bis zu 100 Dashboards erlaubt.

Analytics

You can now build Custom Dashboards charts from Workers Observability data. Two new datasets, Workers Observability — Logs and Workers Observability — Traces (OTel), let you chart Worker invocations, log levels, errors, CPU and wall time, span counts, and durations next to HTTP traffic, security events, and other analytics datasets.

This gives you one dashboard for an application that spans Cloudflare's network and your Workers. For example, you can put request volume, WAF blocks, and Worker error rates on the same view, filter all three by time range, and spot whether a spike in errors lines up with a change in traffic.

The datasets are available for every Worker in your account that has Workers Logs or Workers Traces turned on. Custom Dashboards also now allow up to 100 dashboards for every account.

To get started, refer to Workers Observability data in Custom Dashboards.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare AI von Cloudflare

Web Search API jetzt in der Beta verfügbar

Die Web Search API ist als Beta verfügbar und lässt KI-Agenten und Anwendungen über AI Gateway mit den Anbietern Ceramic.ai, Exa oder Linkup im Internet suchen, abgerechnet über AI-Gateway-Guthaben ohne Aufschlag.

AI Gateway Web Search API

Web Search API is now available in beta. Web Search API lets your AI agents and applications search the Internet and ground their responses in live information, instead of guessing URLs or relying on a model's training cutoff.

At launch, you can choose between three search providers: Ceramic.ai, Exa, and Linkup. All three support Zero Data Retention for requests made through Cloudflare, and all have committed to Cloudflare's verified bot crawling standards.

Web Search API runs through AI Gateway, so search requests appear in your gateway logs and are billed to your AI Gateway credits at each provider's list API price, with no additional markup. You can also bring your own provider API key.

Call Web Search API with the REST API:

curl https://api.cloudflare.com/client/v4/accounts/$CLOUDFLARE_ACCOUNT_ID/ai/websearch/ \
  --request POST \
  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
  --header "Content-Type: application/json" \
  --data '{
    "query": "What are some fun things to do in Salt Lake City as fall approaches?",
    "provider": "ceramic",
    "limit": 5, …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

30 Tage Analytics-Daten in jedem Tarif

Jeder Tarif erhält mindestens 30 Tage Analytics-Daten, und die Domain-Analysen sind im Dashboard unter Analytics als Tabs mit gemeinsamem Zeitraum und Filtern zusammengefasst.

Every plan now gets at least 30 days of analytics data. Adaptive analytics datasets, such as HTTP requests, security events, and DNS analytics, retain at least 31 days of data for Free and Pro domains, and you can query up to 30 days in a single request. Previously, Free and Pro domains could see between 24 hours and 8 days of history depending on the dataset.

A full month of history lets you investigate an issue after it happens, compare today with the same day in previous weeks, and tell a one-time spike from a longer trend. The change applies in the Cloudflare dashboard, in Custom Dashboards, and through the GraphQL Analytics API.

Domain analytics also now live in one place. In the Cloudflare dashboard, select a domain and go to Analytics to see Traffic, Performance, Security, Cache, Origin, DNS, and Visitors as tabs that share one time range and one set of filters. Account-level analytics are under Observability > Analytics.

This change does not alter which datasets or fields your plan can access. Aggregated datasets, such as httpRequests1hGroups, keep their existing per-plan limits. To check the exact retention and query window for a zone or account, query the settings for each dataset. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Workers Observability-Logs und -Traces in Custom Dashboards

In Custom Dashboards lassen sich mit den neuen Datasets Workers Observability — Logs und Traces (OTel) nun Diagramme erstellen, und pro Account sind bis zu 100 Dashboards erlaubt.

You can now build Custom Dashboards charts from Workers Observability data. Two new datasets, Workers Observability — Logs and Workers Observability — Traces (OTel), let you chart Worker invocations, log levels, errors, CPU and wall time, span counts, and durations next to HTTP traffic, security events, and other analytics datasets.

This gives you one dashboard for an application that spans Cloudflare's network and your Workers. For example, you can put request volume, WAF blocks, and Worker error rates on the same view, filter all three by time range, and spot whether a spike in errors lines up with a change in traffic.

The datasets are available for every Worker in your account that has Workers Logs or Workers Traces turned on. Custom Dashboards also now allow up to 100 dashboards for every account.

To get started, refer to Workers Observability data in Custom Dashboards.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Organizations unterstützen höhere Account- und Zone-Limits

Cloudflare Organizations unterstützen nun bis zu 20.000 Accounts und 200.000 Zones, bei Sub-Organizations gelten die Limits an der Root Organization.

Cloudflare Organizations now support up to 20,000 accounts and 200,000 zones. For MSSP/Distributors using sub-organizations, these limits are applied at the root Organization.

If you require a higher limit, reach out to your account team. The new limits apply to enterprise and MSSP/Distributor Organizations. Legacy reseller partner and brand partner tenants retain their existing quota behavior.

For more information, refer to Account and zone limits.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

hash_in_range() ist für HTTP-Produkte global verfügbar

Die Funktion hash_in_range() ist in allen Tarifen für HTTP-Produkte verfügbar und hasht Felder in einen Integer innerhalb eines Bereichs, etwa um einen Anteil der Requests auszuwählen.

hash_in_range() is globally available for HTTP products on all plans. It hashes fields into an integer within a specified range. Use this result to select a portion of requests.

Use cf.random_seed to select approximately 10% of requests at random:

hash_in_range(0, 100, cf.random_seed) < 10

With Cloudflare for SaaS, use custom metadata to control rollout progression. Define rollout_pct as a custom key for each hostname. Set its value to an integer from 0 to 100. The expression selects approximately that percentage of requests:

hash_in_range(0, 100, cf.random_seed) < coalesce(lookup_json_integer(cf.hostname.metadata, "rollout_pct"), 0)

If rollout_pct is missing, coalesce() supplies 0. The rule then matches no requests.

For details, refer to the hash_in_range() function reference.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Quick Tunnels per E-Mail-Authentifizierung schützen

Mit dem neuen Flag --allowed-mail in cloudflared müssen Besucher eines Quick Tunnels sich per einmaliger PIN per E-Mail authentifizieren, ohne dass ein Cloudflare-Account nötig ist.

You can now restrict who can access a Quick Tunnel. Use the new --allowed-mail flag in cloudflared to require visitors to authenticate with a one-time PIN sent to their email before they reach your local service.

cloudflared tunnel --url http://localhost:8080 --allowed-mail alice@example.com

Protected Quick Tunnel demo

Previously, anyone with a trycloudflare.com URL could access the service behind it. Protected Quick Tunnels let you share a local development server, webhook receiver, or demo with specific people without creating a Cloudflare account or configuring a domain.

You can allow:

  • A single email address: --allowed-mail alice@example.com
  • Multiple email addresses, by repeating the flag or using a comma-separated list: --allowed-mail 'alice@example.com,bob@example.com'
  • Every address on a domain: --allowed-mail '*@example.com'

Visitors do not need a Cloudflare account. Access ends for everyone when you stop the cloudflared process.

To get started, update cloudflared to the latest version and refer to Restrict access by email.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Docs Collections von Cloudflare

Höhere Account- und Zone-Limits für Organizations

Cloudflare Organizations unterstützen nun bis zu 20.000 Accounts und 200.000 Zones, wobei die Limits bei Sub-Organizations von MSSP/Distributoren auf die Root-Organisation angewendet werden.

Cloudflare Fundamentals Organizations

Cloudflare Organizations now support up to 20,000 accounts and 200,000 zones. For MSSP/Distributors using sub-organizations, these limits are applied at the root Organization.

If you require a higher limit, reach out to your account team. The new limits apply to enterprise and MSSP/Distributor Organizations. Legacy reseller partner and brand partner tenants retain their existing quota behavior.

For more information, refer to Account and zone limits.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access for Infrastructure: Vereinfachte Berechtigungen zum Taggen von Targets

Zum Taggen von Targets mit Access for Infrastructure über die API genügt jetzt die Token-Berechtigung „Zero Trust Write“, während „Tag Write“ dafür nicht mehr nötig ist.

You can now tag targets using only the Zero Trust Write API token permission. Previously, tagging targets through the API required both Zero Trust Write and Tag Write permissions on the API token.

This change applies to inline target tagging through the Infrastructure Access Targets API. Tagging resources through the general Resource Tagging API still requires the Tag Admin, Tag Write, or equivalent role.

For more information, refer to Tag targets.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Clef: Cloudflares erste Open-Source-Entscheidungsmodelle auf Workers AI

Mit @cf/cloudflare/clef und @cf/cloudflare/clef-flash sind Cloudflares erste selbst trainierte Open-Source-Entscheidungsmodelle (Apache 2.0) auf Workers AI verfügbar, die Wahrscheinlichkeiten für vorgegebene Antworten statt Freitext liefern.

Meet @cf/cloudflare/clef and @cf/cloudflare/clef-flash, the first models trained by the Cloudflare Workers AI team, available on Workers AI today.

Clef is a decision model, in the same family as Typesafe's Jev ↗︎. Instead of generating text, it reads an input state and a set of typed questions, then returns a probability for every allowed answer. Your agent gets a structured decision it can act on immediately, for example: route the ticket, block the request, or escalate to a human. There is no free-form output to parse and no reasoning tokens to wait for.

Both models are hosted on Workers AI as Clef and Clef-flash. We are also open-sourcing the weights under the Apache 2.0 license on Hugging Face: Clef ↗︎ and Clef-flash ↗︎. Read the launch blog post ↗︎ for the full story, including how we trained them. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Workers OAuth Provider v1 mit geteilter API und MCP-2026-07-28-Unterstützung

@cloudflare/workers-oauth-provider ist jetzt v1 und trennt Authorization Server und Resource Server (MCP-Server) per Service Binding auf, unterstützt die MCP-Autorisierungsspezifikation 2026-07-28 samt Client ID Metadata Documents und Issuer Identification, bleibt mit älteren Clients (Dynamic Client Registration) kompatibel und bietet mit insufficientScope() Step-up-Autorisierung in einer Zeile.

@cloudflare/workers-oauth-provider ↗︎ is now v1, with a new split API. One Worker acts as the authorization server: it signs users in and issues tokens. Your MCP server acts as the resource server, and can run in another Worker. It validates each token with the authorization server over a Service Binding, without crossing the public Internet.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

AI Search ist allgemein verfügbar

AI Search ist allgemein verfügbar, nutzt standardmäßig Hybrid Search, schließt Workers AI Embeddings und Reranking im Preis ein und rechnet ab dem 1. November 2026 nutzungsbasiert ab.

AI Search is now generally available. Usage-based billing begins on November 1, 2026, with included monthly ingestion, storage, semantic query, and full-text query usage. Cloudflare will send a reminder email the week before billing begins.

Refer to Limits & pricing for rates and included usage.

Hybrid search is on by default

New AI Search instances use hybrid search by default. Hybrid search combines semantic vector retrieval with full-text matching. You can choose a different index method when you create an instance.

Refer to Hybrid search for details.

Workers AI embeddings and reranking are included

Workers AI embedding and reranking calls made by AI Search are included in AI Search pricing. These calls no longer appear on your Workers AI bill or in your AI Gateway logs. Generation, query rewriting, and external providers continue to use your account and gateway.

Refer to Limits & pricing for details.

Multimodal model and image support

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Artifacts ist jetzt in der offenen Beta

Artifacts, das versionierte Dateisystem mit Git-Unterstützung, ist in der offenen Beta und bietet unter anderem Deployment zu Workers, Binding-Verwaltung, Event-Abos, Datenlokalisierung in US oder EU und Nutzungsmetriken.

Artifacts, Cloudflare's versioned file system that speaks Git, is now in open beta. Artifacts is built for scale, so you can create a repository per project, user, session, or task.

With Artifacts, you can:

  • Deploy repositories to Workers — Connect an Artifacts repository through Workers Builds. Pushes to the production branch deploy the updated Worker, while other branches create or update Worker Previews.
  • Programmatically manage repositories — Use an Artifacts binding from a Worker to create or fork repos, inspect files and commits, read files by path, and issue repo-scoped Git tokens.
  • React to repository changes — Subscribe to events when a repository is created, imported, forked, deleted, pushed to, cloned, or fetched.
  • Control where repository data is stored — Choose to store and process your data in the US or EU.
  • Monitor repository usage — View total operations, pulls, pushes, errors, and error rates in the Cloudflare dashboard or via API for analytics.…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Basin Pipelines: Aufnahmelimit auf 1 GB/s erhöht

Jeder Basin Pipelines Stream kann nun bis zu 1 GB/s statt bisher 5 MB/s aufnehmen.

Each Basin Pipelines stream can now ingest up to 1 GB/s, increased from 5 MB/s.

The higher per-stream limit gives high-volume application events, telemetry, and logs more room to grow without splitting ingestion across streams solely to stay within the previous limit.

For the full list of stream, sink, and pipeline limits, refer to Basin Pipelines limits.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Cloudflare Basin ist allgemein verfügbar

Basin, früher Cloudflare Data Platform, ist allgemein verfügbar und umfasst Basin Pipelines, Basin Catalog (früher R2 Data Catalog) und Basin SQL für Datenerfassung und Analyse.

Basin, formerly the Cloudflare Data Platform, is now generally available. Basin brings an end-to-end analytics platform to the Developer Platform, enabling you to collect data from a variety of sources, such as apps, infrastructure, devices, and other Cloudflare services, then query it to answer analytical questions.

Basin Pipelines

Basin Pipelines, formerly Cloudflare Pipelines, ingests events from Workers, HTTP endpoints, and Cloudflare Logpush. It transforms events with SQL and ingests them into Iceberg tables or files on R2. With Basin Pipelines you can:

  • Ingest application and device events through HTTP endpoints or Workers bindings.
  • Filter and reshape Cloudflare logs before storing them as Iceberg tables, Parquet, or JSON.
  • Catch schema mismatches with typed bindings and investigate dropped events in the dashboard.

Basin Catalog

Basin Catalog, formerly R2 Data Catalog, manages and automatically maintains Apache Iceberg tables ↗︎ to keep them fast, cost-efficient, and accessible to any compatible query engine. With Basin Catalog you can:

  • Connect DuckDB, Spark, Snowflake, or PyIceberg to the same tables. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Durable Objects: Laufende Arbeit auch ohne verbundenen Client

Durable Objects bleiben nun auch ohne verbundenen Client aktiv, solange etwa Service-Binding-Anfragen, RPC- oder fetch()-Aufrufe, waitUntil()-Promises oder Timer ausstehen, standardmäßig ab Compatibility Date 2026-10-01.

Durable Objects remain active while handling a request from a connected client. This change applies when no client is connected, such as when an agent continues a submitted job after its client disconnects.

This behavior is the default for Workers with a compatibility date of 2026-10-01 or later. To use it with an earlier date, add the durable_object_io_tasks_prevent_eviction compatibility flag. To opt out, add the durable_object_io_tasks_do_not_prevent_eviction flag.

Pending service binding requests now keep Durable Objects running while they wait for a response. Pending calls to another Durable Object through remote procedure call (RPC) or fetch(), as well as this.ctx.container.monitor(), now also keep the Durable Object running.

Promises passed to this.ctx.waitUntil() and pending setTimeout() and setInterval() timers also receive this protection.

Previously, Cloudflare could shut down an idle Durable Object while one of these operations remained pending without a connected client. This could stop unfinished work. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Workers Web Crypto unterstützt ML-KEM und ML-DSA

Die Workers Web Crypto API unterstützt per Compatibility Flag webcrypto_modern_algorithms nun ML-KEM-768, ML-KEM-1024, ML-DSA-44, ML-DSA-65 und ML-DSA-87 samt neuen Methoden.

The Workers Web Crypto API now supports ML-KEM-768, ML-KEM-1024, ML-DSA-44, ML-DSA-65, and ML-DSA-87. ML-KEM establishes shared secrets, while ML-DSA signs and verifies data.

The opt-in API also adds key encapsulation and decapsulation methods, getPublicKey(), SubtleCrypto.supports(), and JSON Web Keys (JWKs) with the AKP key type.

Turn on the webcrypto_modern_algorithms compatibility flag to use these features:

{
  "$schema": "./node_modules/wrangler/config-schema.json",
  "compatibility_flags": [
    "webcrypto_modern_algorithms"
  ]
}
compatibility_flags = ["webcrypto_modern_algorithms"]

This example uses ML-KEM-768 to establish the same shared secret on both sides:

src/index.jsjs

const keyPair = await crypto.subtle.generateKey("ML-KEM-768", false, [
	"encapsulateBits",
	"decapsulateBits",
]);

if (!("publicKey" in keyPair)) {
	throw new Error("Expected an ML-KEM key pair");
}

const { sharedKey, ciphertext } = await crypto.subtle.encapsulateBits(
	"ML-KEM-768",
	keyPair.publicKey,
);

const recoveredSharedKey = await crypto.subtle.decapsulateBits(
	"ML-KEM-768",
	keyPair.privateKey,
	ciphertext,
);

src/index.tsts

const keyPair = await crypto.subtle.generateKey("ML-KEM-768", false, [
	"encapsulateBits",
	"decapsulateBits",
]);

if (!("publicKey" in keyPair)) {
	throw new Error("Expected an ML-KEM key pair");
}

const { sharedKey, ciphertext } = await crypto.subtle.encapsulateBits(
	"ML-KEM-768",
	keyPair.publicKey,
); …

Originalquelle(öffnet in neuem Tab)Problem melden