Zum Inhalt springen

Cloudflare Release Notes

1.629 Einträge aus 14 Quellen. Zuletzt aktualisiert:

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Abrechnungsnutzung und Budgetwarnungen in Produkt-Seitenleisten

Pay-as-you-go-Kunden sehen in den Übersichtsseiten mehrerer Produkte wie Workers, D1, R2 und Containers nun über ein Seitenleisten-Widget die aktuellen Kosten und können dort Budgetwarnungen erstellen, wobei Enterprise-Vertragskonten noch nicht unterstützt werden.

Pay-as-you-go customers can now view billable usage and create budget alerts directly from the product overview pages for Workers & Pages, D1, R2, Workers KV, Queues, Vectorize, Durable Objects, and Containers. A new sidebar widget shows current-period spend and the billing cycle date range, alongside a button to create a budget alert.

The widget pulls from the same data as the Billable Usage dashboard and aligns to your billing cycle (or the current day on Free plans), so the numbers match your invoice. Enterprise contract accounts are not yet supported.

Billable usage widget in the Durable Objects product sidebar showing current-period spend and a breakdown by service …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Abrechenbare Nutzung und Budgetwarnungen in Produktseitenleisten

Pay-as-you-go-Kunden können jetzt abrechenbare Nutzung direkt in den Produktseiten von Workers, D1, R2, KV, Queues, Vectorize, Durable Objects und Containers einsehen und Budgetwarnungen erstellen.

Pay-as-you-go customers can now view billable usage and create budget alerts directly from the product overview pages for Workers & Pages, D1, R2, Workers KV, Queues, Vectorize, Durable Objects, and Containers. A new sidebar widget shows current-period spend and the billing cycle date range, alongside a button to create a budget alert.

The widget pulls from the same data as the Billable Usage dashboard and aligns to your billing cycle (or the current day on Free plans), so the numbers match your invoice. Enterprise contract accounts are not yet supported.

Billable usage widget in the Durable Objects product sidebar showing current-period spend and a breakdown by service …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: SAML-Assertion-Verschlüsselung für Identitätsanbieter

Cloudflare Access unterstützt jetzt die Verschlüsselung von SAML-Assertions mit einem von Cloudflare verwalteten Zertifikat, inklusive automatischer Zertifikatserzeugung, Rotation ohne Ausfallzeit und PEM-Export.

Cloudflare Access now supports SAML assertion encryption for identity provider integrations. When turned on, your identity provider encrypts SAML assertions using a Cloudflare-managed certificate before sending them through the user's browser. Only Access can decrypt these assertions, protecting sensitive identity data even after TLS termination.

Without encryption, SAML assertions are transmitted in plaintext and could be visible to browser extensions or client-side malware.

SAML encryption toggle in the identity provider configuration

SAML encryption includes built-in certificate lifecycle management:

  • Automatic certificate generation: Access generates an encryption certificate when you turn on SAML encryption for an identity provider.
  • Certificate rotation: Rotate certificates without downtime. The previous certificate remains valid until expiration, giving you time to update your IdP.
  • PEM export: Copy the certificate in PEM format for manual upload to your IdP, or point your IdP to the SAML metadata endpoint for automatic retrieval.

To get started, refer to Encrypt SAML assertions.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Neuer Bulk-Secrets-API-Endpunkt für Workers

Über den neuen Bulk-Endpunkt oder wrangler secret bulk lassen sich mehrere Secrets eines Workers in einer Anfrage anlegen, aktualisieren oder löschen, mit bis zu 100 Operationen pro Anfrage.

You can now create, update, or delete multiple secrets for your Worker in a single request using the bulk secrets endpoint.

  • Include a secret with a value to create or update.
  • Set a secret to null to delete.
  • Secrets not included in the request are left unchanged.

The following example creates API_KEY, updates the already existing DB_PASSWORD, and deletes OLD_SECRET:

{
  "secrets": {
    "API_KEY": { "type": "secret_text", "name": "API_KEY", "text": "my-api-key" },
    "DB_PASSWORD": { "type": "secret_text", "name": "DB_PASSWORD", "text": "my-db-password" },
    "OLD_SECRET": null
  }
}

You can do the same from the command line using wrangler secret bulk:

npx wrangler secret bulk < secrets.json

To delete a key, set its value to null in the JSON file. Deletion is not supported with .env files.

Each request supports up to 100 total operations (creates, updates, and deletes combined).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Wrangler kann OAuth-Zugangsdaten im OS-Schlüsselbund absichern

Mit wrangler login --use-keyring speichert Wrangler OAuth-Zugangsdaten optional in einer AES-256-GCM-verschlüsselten Datei, deren Schlüssel im Schlüsselbund des Betriebssystems liegt, während das Standardverhalten unverändert bleibt.

Wrangler can now store the OAuth credentials returned by wrangler login in an AES-256-GCM ↗︎-encrypted file, with the encryption key held in your operating system keychain. The default behavior is unchanged — credentials still live in a plaintext TOML file unless you opt in.

To opt in, run:

npx wrangler login --use-keyring

The choice is persisted across Wrangler invocations. Opt back out with npx wrangler login --no-use-keyring, or override the preference for a single command with the CLOUDFLARE_AUTH_USE_KEYRING environment variable.

wrangler whoami now reports where credentials are stored:

🔐 Credentials are stored in: Encrypted file (~/.config/.wrangler/config/default.enc) with key in macOS Keychain (service=wrangler, account=default)

Per-platform backends:

  • macOS uses the built-in Keychain via /usr/bin/security.
  • Linux uses libsecret ↗︎ via the secret-tool CLI from the libsecret-tools package.
  • Windows uses Credential Manager via @napi-rs/keyring ↗︎, installed on-demand the first time you opt in. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Docs Collections von Cloudflare

Self-Managed OAuth-Clients eingeführt

Cloudflare bietet jetzt selbstverwaltete OAuth-Clients an, mit denen Entwickler Drittanbieteranwendungen sicher über OAuth in Cloudflare integrieren können.

Cloudflare Fundamentals

Today we are launching self-managed OAuth, enabling developers to build third-party applications that integrate with Cloudflare via OAuth. This provides a more secure, user-friendly, and manageable alternative to API tokens.

OAuth lets third-party applications act on behalf of a user to access their Cloudflare account. For example, after a user grants consent, Wrangler can deploy Workers into that account.

What is new

Cloudflare Developers can now create and manage their own OAuth applications to integrate with Cloudflare.

Create an application

To create an application, go to Manage account > OAuth clients in your account on the Cloudflare dashboard.

Go to OAuth clients ↗

Select limited scopes

If you have used an API token to call Cloudflare APIs, OAuth client scopes will look familiar. Select only the scopes your application needs during application creation, and include that scope list when sending users to Cloudflare for consent.

Users can review the requested scopes before they consent.

Apps for both private and public use

Applications start with private visibility. Private applications can only be used by members of the account where the application was created.

To make an application available to any Cloudflare user, complete the prerequisites for public visibility. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Self-managed OAuth-Clients eingeführt

Entwickler können jetzt eigene OAuth-Anwendungen erstellen und verwalten, um sicherere und benutzerfreundlichere Integrationen statt API-Tokens zu ermöglichen.

Today we are launching self-managed OAuth, enabling developers to build third-party applications that integrate with Cloudflare via OAuth. This provides a more secure, user-friendly, and manageable alternative to API tokens.

OAuth lets third-party applications act on behalf of a user to access their Cloudflare account. For example, after a user grants consent, Wrangler can deploy Workers into that account.

What is new

Cloudflare Developers can now create and manage their own OAuth applications to integrate with Cloudflare.

Create an application

To create an application, go to Manage account > OAuth clients in your account on the Cloudflare dashboard.

Go to OAuth clients ↗

Select limited scopes

If you have used an API token to call Cloudflare APIs, OAuth client scopes will look familiar. Select only the scopes your application needs during application creation, and include that scope list when sending users to Cloudflare for consent.

Users can review the requested scopes before they consent.

Apps for both private and public use

Applications start with private visibility. Private applications can only be used by members of the account where the application was created. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cisco-IOS-XE-Anleitung für Cloudflare WAN aktualisiert

Die Integrationsanleitung für Cisco IOS XE mit Cloudflare WAN wurde um Post Quantum Cryptography (PQC), Policy-Based Routing (PBR) und IP Service Level Agreement (IP SLA) erweitert.

The Cisco IOS XE third-party integration guide for Cloudflare WAN has been updated to include:

  • Post Quantum Cryptography (PQC)
  • Policy-Based Routing (PBR)
  • IP Service Level Agreement (IP SLA)

This link will take you directly to the updated Cisco IOS XE guide.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Workflow-Instanzen per Cron direkt am Workflow-Binding planen

In wrangler.jsonc lassen sich Cron-Zeitpläne direkt an ein Workflow-Binding hängen, sodass jeder geplante Lauf automatisch eine neue Workflow-Instanz erzeugt, ohne einen separaten Worker mit scheduled-Handler.

You can now attach cron schedules directly to a Workflow binding in wrangler.jsonc. Each scheduled run creates a new Workflow instance automatically, so you do not need to define a separate Worker with a scheduled handler just to trigger your Workflow on an interval.

For example, you can configure hourly, every-15-minute, or weekday schedules on the same Workflow:

{
	"workflows": [
		{
			"name": "my-scheduled-workflow",
			"binding": "MY_WORKFLOW",
			"class_name": "MyScheduledWorkflow",
			"schedules": ["0 * * * *", "*/15 * * * *", "0 9 * * MON-FRI"],
		},
	],
}

Cron workloads get all the same benefits of Workflows with built-in retries, multi-step durable execution, and configurable timeouts of Workflows.

import {
	WorkflowEntrypoint,
	WorkflowEvent,
	WorkflowStep,
} from "cloudflare:workers";

// Runs automatically on each cron schedule defined for the MY_WORKFLOW binding in wrangler.jsonc.
export class MyScheduledWorkflow extends WorkflowEntrypoint<Env> {
	async run(event: WorkflowEvent, step: WorkflowStep) {
		const data = await step.do("fetch source data", async () => {
			return await fetchSourceData();
		});

		// If this step fails, only this step is retried with the custom logic below
		await step.do(
			"process and store results",
			{
				retries: { limit: 5, delay: "30 seconds", backoff: "exponential" },
				timeout: "10 minutes",
			},
			async () => {
				await processAndStore(data);
			},
		);
	}
}
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Agents SDK v0.14.0 mit Agent Skills, Messengern und geplanten Aufgaben

Das Agents SDK Version 0.14.0 bringt für @cloudflare/think experimentelle Agent Skills, Chat-Messenger (zunächst Telegram), deklarative geplante Aufgaben und dauerhafte Reasoning-Schritte in Workflows und verbessert die Wiederherstellung dauerhafter Chats deutlich.

The latest release of the Agents SDK ↗︎ adds four new ways to build with @cloudflare/think: on-demand Agent Skills, chat messengers (starting with Telegram), declarative scheduled tasks, and durable reasoning steps inside Workflows. This release also significantly hardens durable chat recovery, so turns reliably ride through deploys, evictions, and stalled model streams in production.

Agent Skills (experimental)

Give an agent a catalog of on-demand instructions, resources, and scripts. A skill source adds a catalog to the system prompt, and the model activates a skill only when a task matches — so a large library of capabilities does not bloat every prompt.

import { Think, skills } from "@cloudflare/think";
import bundledSkills from "agents:skills";

export class SkillsAgent extends Think {
	getSkills() {
		return [
			bundledSkills,
			skills.r2(this.env.SKILLS_BUCKET, { prefix: "skills/" }),
		];
	}
}
import { Think, skills } from "@cloudflare/think";
import bundledSkills from "agents:skills";

export class SkillsAgent extends Think<Env> {
	getSkills() {
		return [
			bundledSkills,
			skills.r2(this.env.SKILLS_BUCKET, { prefix: "skills/" }),
		];
	}
}
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Core Platform von Cloudflare

Neues Logpush-Dataset für Turnstile-Events

Cloudflare Logs umfasst nun ein neues Logpush-Dataset „Turnstile Events“ mit Feldern wie ASN, ClientIP, BrowserName, CountryCode und UserAgent.

Cloudflare has updated Logpush datasets:

New datasets

  • Turnstile Events: A new dataset with fields including ASN, Action, BrowserMajor, BrowserName, ClientIP, CountryCode, EventType, Hostname, OSMajor, OSName, Sitekey, Timestamp, and UserAgent.

For the complete field definitions for each dataset, refer to Logpush datasets.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.5.1155.1 (Beta)

Die neue Beta des Cloudflare One Client für macOS bringt die neue Benutzeroberfläche mit Rechtsklick-Kontextmenü und integriertem Captive-Portal-Login sowie Unterstützung für DNS-Suchsuffixe aus Geräteprofil bzw. Netzwerkrichtlinie.

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page.

This release introduces the new Cloudflare One Client UI for macOS! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Additional Changes and improvements

  • The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See DNS search suffixes for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.5.1155.1 (Beta)

Die neue Beta des Cloudflare One Client für Windows bringt die neue Benutzeroberfläche mit Rechtsklick-Kontextmenü und integriertem Captive-Portal-Login sowie Unterstützung für DNS-Suchsuffixe aus Geräteprofil bzw. Netzwerkrichtlinie.

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page.

This release introduces the new Cloudflare One Client UI for Windows! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Additional Changes and improvements

  • The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See DNS search suffixes for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Sandbox-Vorschauen über Cloudflare Tunnel teilen

Sandboxes können über den Namespace sandbox.tunnels einen im Container laufenden Dienst per cloudflared auf einer öffentlichen Vorschau-URL bereitstellen, standardmäßig als Quick Tunnel auf *.trycloudflare.com ohne Account, DNS-Eintrag oder eigene Domain.

Sandboxes can expose a service running inside the container on a public preview URL through the sandbox.tunnels namespace. The SDK uses cloudflared inside the sandbox so you can share a running service without configuring exposePort() or a custom domain.

By default, sandbox.tunnels.get(port) creates a quick tunnel ↗︎ on a zero-config *.trycloudflare.com URL — no Cloudflare account, DNS record, or custom domain required. This is perfect for quick development and for .workers.dev deployments.

import { getSandbox } from "@cloudflare/sandbox";

const sandbox = getSandbox(env.Sandbox, "my-sandbox");
await sandbox.startProcess("python -m http.server 8080");

const tunnel = await sandbox.tunnels.get(8080);
console.log(tunnel.url); // → https://random-words-here.trycloudflare.com
import { getSandbox } from "@cloudflare/sandbox";

const sandbox = getSandbox(env.Sandbox, "my-sandbox");
await sandbox.startProcess("python -m http.server 8080");

const tunnel = await sandbox.tunnels.get(8080);
console.log(tunnel.url); // → https://random-words-here.trycloudflare.com

Named tunnels

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

D1-Migrationen unterstützen verschachtelte Layouts via migrations_pattern

Mit der neuen D1-Binding-Option migrations_pattern kann wrangler d1 migrations apply per Glob auch verschachtelte Migrationsstrukturen wie die von Drizzle finden, wobei der Standardwert bestehende Projekte unverändert lässt.

You can now point wrangler d1 migrations apply at a nested migrations layout — such as the one produced by Drizzle ↗︎ (migrations/0001_init/migration.sql) — using the new migrations_pattern D1 binding config:

{
	"d1_databases": [
		{
			"binding": "DB",
			"database_name": "my-database",
			"database_id": "<UUID>",
			"migrations_dir": "migrations",
			"migrations_pattern": "migrations/*/migration.sql",
		},
	],
}

migrations_pattern is a glob (relative to your Wrangler config file) used to discover migration files. It defaults to ${migrations_dir}/*.sql, so existing projects keep working unchanged. Each migration's name is recorded in the migrations table as a path relative to migrations_dir.

To learn more, visit D1's migrations documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

Realtime WebSocket-Adapter verbindet automatisch neu und puffert Medien

Der WebSocket-Adapter von Cloudflare Realtime SFU baut die Verbindung nach kurzen Unterbrechungen oder Neustarts des Endpunkts automatisch wieder auf und puffert dabei Audio und Video.

Cloudflare Realtime SFU is a WebRTC Selective Forwarding Unit that runs on Cloudflare's global network, so you can route live audio, video, and data between WebRTC clients around the world without managing SFU infrastructure or regions.

When you use the WebSocket adapter to stream WebRTC media to a WebSocket endpoint, the adapter now auto-reconnects and buffers audio and video after brief endpoint disconnects or restarts.

Streaming WebRTC media to WebSocket endpoints

Many teams also use Realtime SFU as the media layer for backend applications, such as transcription, recording, note-taking, and agentic media-processing services. These systems often need to consume live WebRTC audio or video from the SFU in backend infrastructure, including Durable Objects, Workers, Containers, or external services, without running a WebRTC client themselves. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Developer Platform von Cloudflare

D1-Migrationen mit verschachtelten Layouts über migrations_pattern

Über die neue D1-Binding-Option migrations_pattern kann wrangler d1 migrations apply nun verschachtelte Migrationsstrukturen wie die von Drizzle verwenden, wobei der Standardwert ${migrations_dir}/*.sql bestehende Projekte unverändert lässt.

You can now point wrangler d1 migrations apply at a nested migrations layout — such as the one produced by Drizzle ↗︎ (migrations/0001_init/migration.sql) — using the new migrations_pattern D1 binding config:

{
	"d1_databases": [
		{
			"binding": "DB",
			"database_name": "my-database",
			"database_id": "<UUID>",
			"migrations_dir": "migrations",
			"migrations_pattern": "migrations/*/migration.sql",
		},
	],
}

migrations_pattern is a glob (relative to your Wrangler config file) used to discover migration files. It defaults to ${migrations_dir}/*.sql, so existing projects keep working unchanged. Each migration's name is recorded in the migrations table as a path relative to migrations_dir.

To learn more, visit D1's migrations documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Consumer Services von Cloudflare

Radar: TLS-Bug-Erkennung im Post-Quantum-Checker

Der Post-Quantum-TLS-Support-Checker in Cloudflare Radar meldet jetzt erkannte TLS-Bugs wie Split ClientHello, HRR Failure und Unknown Keyshare mit Anleitungen zur Behebung.

Radar

The Radar post-quantum TLS support checker ↗︎ now also reports TLS bugs detected during the handshake test. When a scanned host exhibits compatibility issues, the results include details on the specific bugs detected, along with guidance on how to investigate and remediate each issue. The bugs section only appears for hosts where issues are found.

The following TLS bugs are detected:

  • Split ClientHello — The connection fails with a fragmented post-quantum ClientHello but succeeds with classical handshakes. Typically caused by middleboxes or firewalls that cannot reassemble split TLS messages.
  • HRR Failure — The server sends a HelloRetryRequest but fails to complete the handshake afterward.
  • Unknown Keyshare — The server cannot handle unknown key exchange algorithms and fails instead of responding with a HelloRetryRequest as required by the TLS 1.3 specification.

TLS bug detection results in the Radar post-quantum checker

Bug detection data is available through the existing /post_quantum/tls/support endpoint. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Application Security von Cloudflare

Security Center: Häufigere Sicherheitsscans

Sicherheitsscans laufen jetzt häufiger: täglich für Enterprise, alle 3 Tage für Pro/Business und alle 7 Tage für Free, und sind standardmäßig für alle Konten aktiviert.

Security Insights scans now run more often. Cloudflare scans Free accounts every 7 days, Pro and Business accounts every 3 days, and Enterprise accounts daily.

In addition, all accounts and zones now receive scans by default. You no longer need to enable scans before Cloudflare checks your account for misconfigurations, vulnerabilities, and other security risks.

Granular on-demand scans are now available on any plan. You can trigger an on-demand scan for any zone, insight, insight type from the Cloudflare dashboard in order to quickly re-check your security posture after remediating an issue.

To learn more, refer to the Security Insights documentation.

Originalquelle(öffnet in neuem Tab)Problem melden