Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.629
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Developer Platform von Cloudflare

Dynamic Workers jetzt in der offenen Beta

Dynamic Workers sind jetzt für alle zahlenden Workers-Nutzer in der Open Beta und ermöglichen es, zur Laufzeit weitere Workers zur Codeausführung in einer abgesicherten Sandbox zu starten.

Dynamic Workers are now in open beta ↗︎ for all paid Workers users. You can now have a Worker spin up other Workers, called Dynamic Workers, at runtime to execute code on-demand in a secure, sandboxed environment. Dynamic Workers start in milliseconds, making them well suited for fast, secure code execution at scale.

Use Dynamic Workers for

  • Code Mode: LLMs are trained to write code. Run tool-calling logic written in code instead of stepping through many tool calls, which can save up to 80% in inference tokens and cost.
  • AI agents executing code: Run code for tasks like data analysis, file transformation, API calls, and chained actions.
  • Running AI-generated code: Run generated code for prototypes, projects, and automations in a secure, isolated sandboxed environment.
  • Fast development and previews: Load prototypes, previews, and playgrounds in milliseconds.
  • Custom automations: Create custom tools on the fly that execute a task, call an integration, or automate a workflow.

Executing Dynamic Workers

Dynamic Workers support two loading modes:

  • load(code) — for one-time code execution (equivalent to calling get() with a null ID). …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Performance von Cloudflare

Neue Cache Response Rules für Ursprungsantworten

Cache Response Rules ermöglichen es, Cache-Control-Direktiven und Header von Ursprungsantworten zu ändern, bevor sie in den Cache gelangen, ohne den Ursprung anzupassen.

You can now control how Cloudflare handles origin responses without changing your origin. Cache Response Rules let you modify Cache-Control directives, manage cache tags, and strip headers like Set-Cookie from origin responses before they reach Cloudflare's cache. Whether traffic is cached or passed through dynamically, these rules give you control over origin response behavior that was previously out of reach.

What changed

Cache Rules previously only operated on request attributes. Cache Response Rules introduce a new response phase that evaluates origin responses and lets you act on them before caching. You can now:

  • Modify Cache-Control directives: Set or remove individual directives like no-store, no-cache, max-age, s-maxage, stale-while-revalidate, immutable, and more. For example, remove a no-cache directive your origin sends so Cloudflare can cache the asset, or set an s-maxage to control how long Cloudflare stores it.
  • Set a different browser Cache-Control: Send a different Cache-Control header downstream to browsers and other clients than what Cloudflare uses internally, giving you independent control over edge and browser caching strategies. …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Erweiterte WAF-Anpassung für AI-Crawl-Control

AI Crawl Control unterstützt jetzt benutzerdefinierte Änderungen an der zugrunde liegenden WAF-Regel, die bei Aktualisierungen der Crawler-Aktionen erhalten bleiben.

AI Crawl Control now supports extending the underlying WAF rule with custom modifications. Any changes you make directly in the WAF custom rules editor — such as adding path-based exceptions, extra user agents, or additional expression clauses — are preserved when you update crawler actions in AI Crawl Control.

If the WAF rule expression has been modified in a way AI Crawl Control cannot parse, a warning banner appears on the Crawlers page with a link to view the rule directly in WAF.

For more information, refer to WAF rule management.

Originalquelle(öffnet in neuem Tab)Problem melden

Network Security von Cloudflare

Interconnects unter Connectors

Die Interconnects-Seite im Dashboard wurde entfernt und ist jetzt unter Connectors > Interconnects verfügbar; bestehende Konfigurationen bleiben unverändert.

The top-level Interconnects page in the Cloudflare dashboard has been removed. Interconnects are now located under Connectors > Interconnects.

Your existing configurations and functionality remain the same.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workflow-Instanzmethoden in lokaler Entwicklung verfügbar

Die Workflow-Instanzmethoden pause(), resume(), restart() und terminate() stehen jetzt auch in der lokalen Entwicklung mit wrangler dev zur Verfügung.

Workflow instance methods pause(), resume(), restart(), and terminate() are now available in local development when using wrangler dev.

You can now test the full Workflow instance lifecycle locally:

const instance = await env.MY_WORKFLOW.create({
	id: "my-instance-id",
});

await instance.pause(); // pauses a running workflow instance
await instance.resume(); // resumes a paused instance
await instance.restart(); // restarts the instance from the beginning
await instance.terminate(); // terminates the instance immediately

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Agents SDK v0.8.0: lesbarer State, typisierter AgentClient, Zod 4

Agents SDK Version 0.8.0 macht den Agent-State bei useAgent und AgentClient als Eigenschaft lesbar, verhindert doppelte Schedule-Einträge nach Durable-Object-Neustarts, bringt volle TypeScript-Inferenz für AgentClient und migriert auf Zod 4.

The latest release of the Agents SDK ↗︎ exposes agent state as a readable property, prevents duplicate schedule rows across Durable Object restarts, brings full TypeScript inference to AgentClient, and migrates to Zod 4.

Readable state on useAgent and AgentClient

Both useAgent (React) and AgentClient (vanilla JS) now expose a state property that reflects the current agent state. Previously, reading state required manually tracking it through the onStateUpdate callback.

React (useAgent)

const agent = useAgent({
	agent: "game-agent",
	name: "room-123",
});

// Read state directly — no separate useState + onStateUpdate needed
return <div>Score: {agent.state?.score}</div>;

// Spread for partial updates
agent.setState({ ...agent.state, score: (agent.state?.score ?? 0) + 10 });
const agent = useAgent<GameAgent, GameState>({
	agent: "game-agent",
	name: "room-123",
});

// Read state directly — no separate useState + onStateUpdate needed
return <div>Score: {agent.state?.score}</div>;

// Spread for partial updates
agent.setState({ ...agent.state, score: (agent.state?.score ?? 0) + 10 });

agent.state is reactive — the component re-renders when state changes from either the server or a client-side setState() call.

Vanilla JS (AgentClient)

const client = new AgentClient({
	agent: "game-agent",
	name: "room-123", …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

AI Search: Neue REST-API-Endpunkte für /search und /chat/completions

AI Search bietet neue REST-API-Endpunkte für Suche und Chat im OpenAI-kompatiblen Format mit messages-Array, über das sich auch frühere Nachrichten einer Sitzung übergeben lassen.

AI Search now offers new REST API endpoints for search and chat that use an OpenAI compatible format. This means you can use the familiar messages array structure that works with existing OpenAI SDKs and tools. The messages array also lets you pass previous messages within a session, so the model can maintain context across multiple turns.

Endpoint

Path

Chat Completions

POST /accounts/{account_id}/ai-search/instances/{name}/chat/completions

Search

POST /accounts/{account_id}/ai-search/instances/{name}/search

Here is an example request to the Chat Completions endpoint using the new messages array format:

curl https://api.cloudflare.com/client/v4/accounts/{ACCOUNT_ID}/ai-search/instances/{NAME}/chat/completions \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer {API_TOKEN}" \
  -d '{
    "messages": [
      {
        "role": "system",
        "content": "You are a helpful documentation assistant."
      },
      {
        "role": "user",
        "content": "How do I get started?"
      }
    ]
  }'

For more details, refer to the AI Search REST API guide.

Migration from existing AutoRAG API (recommended)

…

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

AI Search: UI-Snippets, öffentliche Endpunkte und MCP-Unterstützung

AI Search unterstützt jetzt öffentliche Endpunkte ohne API-Authentifizierung, einbettbare UI-Snippets für Such- und Chat-Komponenten sowie MCP.

AI Search now supports public endpoints, UI snippets, and MCP, making it easy to add search to your website or connect AI agents.

Public endpoints allow you to expose AI Search capabilities without requiring API authentication. To enable public endpoints:

  1. Go to AI Search in the Cloudflare dashboard. Go to AI Search ↗
  2. Select your instance, and turn on Public Endpoint in Settings. For more details, refer to Public endpoint configuration.

UI snippets

UI snippets are pre-built search and chat components you can embed in your website. Visit search.ai.cloudflare.com ↗︎ to configure and preview components for your AI Search instance.

Example of the search-modal-snippet component

To add a search modal to your page:

<script
	type="module"
	src="https://<PUBLIC_ENDPOINT_ID>.search.ai.cloudflare.com/assets/v0.0.25/search-snippet.es.js"
></script>

<search-modal-snippet
	api-url="https://<PUBLIC_ENDPOINT_ID>.search.ai.cloudflare.com/"
	placeholder="Search..."
>
</search-modal-snippet>
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

AI Search: Filterung nach benutzerdefinierten Metadaten

AI Search erlaubt nun, bis zu 5 eigene Metadatenfelder (text, number oder boolean) pro Instanz zu definieren und Suchergebnisse danach zu filtern.

AI Search now supports custom metadata filtering, allowing you to define your own metadata fields and filter search results based on attributes like category, version, or any custom field you define.

Define a custom metadata schema

You can define up to 5 custom metadata fields per AI Search instance. Each field has a name and data type (text, number, or boolean):

curl -X POST https://api.cloudflare.com/client/v4/accounts/{ACCOUNT_ID}/ai-search/instances \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer {API_TOKEN}" \
  -d '{
    "id": "my-instance",
    "type": "r2",
    "source": "my-bucket",
    "custom_metadata": [
      { "field_name": "category", "data_type": "text" },
      { "field_name": "version", "data_type": "number" },
      { "field_name": "is_public", "data_type": "boolean" }
    ]
  }'

Add metadata to your documents

How you attach metadata depends on your data source:

  • R2 bucket: Set metadata using S3-compatible custom headers (x-amz-meta-*) when uploading objects. Refer to R2 custom metadata for examples. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

R2 SQL: Über 190 neue Funktionen, Ausdrücke und komplexe Typen

R2 SQL unterstützt eine erweiterte SQL-Grammatik mit CASE-Ausdrücken, Spaltenaliasen, 163 Skalar- und 33 Aggregatfunktionen, EXPLAIN, CTEs sowie vollem Zugriff auf Struct-, Array- und Map-Typen.

R2 SQL now supports an expanded SQL grammar so you can write richer analytical queries without exporting data. This release adds CASE expressions, column aliases, arithmetic in clauses, 163 scalar functions, 33 aggregate functions, EXPLAIN, Common Table Expressions (CTEs),and full struct/array/map access. R2 SQL is Cloudflare's serverless, distributed, analytics query engine for querying Apache Iceberg ↗︎ tables stored in R2 Data Catalog. This page documents the supported SQL syntax.

Highlights

  • Column aliases — SELECT col AS alias now works in all clauses
  • CASE expressions — conditional logic directly in SQL (searched and simple forms)
  • Scalar functions — 163 new functions across math, string, datetime, regex, crypto, encoding, and type inspection categories
  • Aggregate functions — statistical (variance, stddev, correlation, regression), bitwise, boolean, and positional aggregates join the existing basic and approximate functions
  • Complex types — query struct fields with bracket notation, use 46 array functions, and extract map keys/values
  • Common table expressions (CTEs) — use WITH ... AS to define named temporary result sets. Chained CTEs are supported. All CTEs must reference the same single table. …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

API Shield: Web-Assets-Felder in GraphQL-Analytics-API verfügbar

Die GraphQL-Analytics-API bietet für Web Assets nun die Felder webAssetsOperationId und webAssetsLabelsManaged, um pro Anfrage die passende Operation und verwaltete Labels zu ermitteln.

Two new fields are now available in the httpRequestsAdaptive and httpRequestsAdaptiveGroups GraphQL Analytics API datasets:

  • webAssetsOperationId — the ID of the saved endpoint that matched the incoming request.
  • webAssetsLabelsManaged — the managed labels mapped to the matched operation at the time of the request (for example, cf-llm, cf-log-in). At most 10 labels are returned per request.

Both fields are empty when no operation matched. webAssetsLabelsManaged is also empty when no managed labels are assigned to the matched operation.

These fields allow you to determine, per request, which Web Assets operation was matched and which managed labels were active. This is useful for troubleshooting downstream security detection verdicts — for example, understanding why AI Security for Apps did or did not flag a request.

Refer to Endpoint labeling service for GraphQL query examples.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Release 2026-03-23: Verbesserte Erkennungsabdeckung

Das WAF-Release vom 23. März 2026 verbessert bestehende Regeln und führt neue generische Erkennungen für Command Injection sowie eine Zusammenlegung einer PHP-vBulletin-Regel ein.

This week's release focuses on new improvements to enhance coverage.

Key Findings

  • Existing rule enhancements have been deployed to improve detection resilience against broad classes of web attacks and strengthen behavioral coverage.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...97321c6c

N/A

Command Injection - Generic 9 - URI Vector

Log

Disabled

This is a new detection.

Cloudflare Managed Ruleset

...1eb7a999

N/A

Command Injection - Generic 9 - Header Vector

Log

Disabled

This is a new detection.

Cloudflare Managed Ruleset

...0677175f

N/A

Command Injection - Generic 9 - Body Vector

Log

Disabled

This is a new detection.

Cloudflare Managed Ruleset

...479da68f

N/A

PHP, vBulletin, jQuery File Upload - Code Injection, Dangerous File Upload - CVE:CVE-2018-9206, CVE:CVE-2019-17132 (beta)

Log

Block

This rule has been merged into the original rule "PHP, vBulletin, jQuery File Upload - Code Injection, Dangerous File Upload - CVE:CVE-2018-9206, CVE:CVE-2019-17132" (ID: ...824b817c)

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Managed OAuth für Cloudflare Access

Cloudflare Access unterstützt Managed OAuth, womit sich Nicht-Browser-Clients wie CLIs, KI-Agenten, SDKs und Skripte per OAuth-2.0-Authorization-Code-Flow an geschützten Anwendungen anmelden können; die Funktion ist für bestehende Anwendungen optional.

Cloudflare Access supports managed OAuth, which allows non-browser clients — such as CLIs, AI agents, SDKs, and scripts — to authenticate with Access-protected applications using a standard OAuth 2.0 authorization code flow.

Previously, non-browser clients that attempted to access a protected application received a 302 redirect to a login page they could not complete. The established workaround was cloudflared access curl, which required installing additional tooling.

With managed OAuth, clients instead receive a 401 response with a WWW-Authenticate header that points to Access's OAuth discovery endpoints (RFC 8414 ↗︎ and RFC 9728 ↗︎). The client opens the end user's browser to the Access login page. The end user authenticates with their identity provider, and the client receives an OAuth access token for subsequent requests.

Access enforces the same policies as a browser login; the OAuth layer is a new transport mechanism, not a separate authentication path.

Managed OAuth can be enabled on any self-hosted Access application or MCP server portal. It is opt-in for existing applications to avoid interfering with those that run their own OAuth servers and rely on their own WWW-Authenticate headers.

Note …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

MCP-Portal-Traffic über Cloudflare Gateway leiten

MCP server portals können Traffic jetzt über Cloudflare Gateway routen, was detailliertere HTTP-Logs und DLP-Scans für Daten an Upstream-MCP-Server ermöglicht; die Option wird in den AI controls des Portals aktiviert.

MCP server portals can now route traffic through Cloudflare Gateway for richer HTTP request logging and data loss prevention (DLP) scanning.

When Gateway routing is turned on, portal traffic appears in your Gateway HTTP logs. You can create Gateway HTTP policies with DLP profiles to detect and block sensitive data sent to upstream MCP servers.

Note

DLP AI prompt profiles do not apply to MCP server portal traffic.

To enable Gateway routing, go to Access controls > AI controls, edit the portal, and turn on Route traffic through Cloudflare Gateway under Basic information.

Route MCP server portal traffic through Cloudflare Gateway …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Cloudflare Tunnel: Logs mehrerer Replicas gleichzeitig streamen

Die Übersichtsseite eines Cloudflare Tunnel zeigt im Dashboard nun alle Replicas an und erlaubt es, die Logs mehrerer Replicas gleichzeitig zu streamen, statt wie zuvor nur eines.

In the Cloudflare One dashboard, the overview page for a specific Cloudflare Tunnel now shows all replicas of that tunnel and supports streaming logs from multiple replicas at once.

View replicas and stream logs from multiple connectors

Previously, you could only stream logs from one replica at a time. With this update:

  • Replicas on the tunnel overview — All active replicas for the selected tunnel now appear on that tunnel's overview page under Connectors. Select any replica to stream its logs.
  • Multi-connector log streaming — Stream logs from multiple replicas simultaneously, making it easier to correlate events across your infrastructure during debugging or incident response. To try it out, log in to Cloudflare One ↗︎ and go to Networks > Connectors > Cloudflare Tunnels. Select View logs next to the tunnel you want to monitor. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers VPC: Observability für VPC Services

Jeder VPC Service hat jetzt im Dashboard einen Tab „Metrics“ mit Verbindungen, Latenz und Fehlern sowie einen Settings-Tab zur Ansicht und Bearbeitung von Konfiguration, Host-Details und Ports.

Each VPC Service now has a Metrics tab so you can monitor connection health and debug failures without leaving the dashboard.

Workers VPC Metrics dashboard showing connections, latency, and errors charts

  • Connections — See successful and failed connections over time, broken down by what is responsible: your origin (Bad Upstream), your configuration (Client), or Cloudflare (Internal).
  • Latency — Track connection and DNS resolution latency trends.
  • Errors — Drill into specific error codes grouped by category, with filters to isolate upstream, client, or internal failures.

You can also view and edit your VPC Service configuration, host details, and port assignments from the Settings tab.

For a full list of error codes and what they mean, refer to Troubleshooting.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Performance von Cloudflare

DNS-Analysen für EU-Metadaten-Grenze verfügbar

DNS Analytics und DNS Firewall Analytics sind jetzt für Kunden mit Customer Metadata Boundary in der EU verfügbar, wobei die Daten in der EU gespeichert und abgefragt werden.

DNS Analytics is now available for customers with Customer Metadata Boundary (CMB) set to EU. Query your DNS analytics data while keeping metadata stored in the EU region.

This update includes:

  • DNS Analytics — Access the same DNS analytics experience for zones in CMB=EU accounts.
  • EU data residency — Analytics data is stored and queried from the EU region, meeting data localization requirements.
  • DNS Firewall Analytics — DNS Firewall analytics is now supported for CMB=EU customers.

Availability

Available to customers with the Data Localization Suite who have Customer Metadata Boundary configured for the EU region.

Where to find it

  • Authoritative DNS: In the Cloudflare dashboard, select your zone and go to the Analytics page.

    Go to Analytics ↗

  • DNS Firewall: In the Cloudflare dashboard, go to the DNS Firewall Analytics page.

    Go to Analytics ↗

For more information, refer to DNS Analytics and DNS Firewall Analytics.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Gleichzeitiges Log-Streaming mehrerer Tunnel-Replikate

Die Übersichtsseite eines Cloudflare Tunnels zeigt nun alle Replikate und erlaubt das gleichzeitige Streaming von Logs aus mehreren Replikaten zur Ereigniskorrelation.

In the Cloudflare One dashboard, the overview page for a specific Cloudflare Tunnel now shows all replicas of that tunnel and supports streaming logs from multiple replicas at once.

View replicas and stream logs from multiple connectors

Previously, you could only stream logs from one replica at a time. With this update:

  • Replicas on the tunnel overview — All active replicas for the selected tunnel now appear on that tunnel's overview page under Connectors. Select any replica to stream its logs.
  • Multi-connector log streaming — Stream logs from multiple replicas simultaneously, making it easier to correlate events across your infrastructure during debugging or incident response. To try it out, log in to Cloudflare One ↗︎ and go to Networks > Connectors > Cloudflare Tunnels. Select View logs next to the tunnel you want to monitor. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Hyperdrive unterstützt eigene TLS/SSL-Zertifikate für MySQL

Hyperdrive unterstützt jetzt für MySQL-Datenbanken benutzerdefinierte TLS/SSL-Zertifikate, darunter Serverzertifikatsprüfung mit VERIFY_CA oder VERIFY_IDENTITY sowie Client-Zertifikate (mTLS).

Hyperdrive now supports custom TLS/SSL certificates for MySQL databases, bringing the same certificate options previously available for PostgreSQL to MySQL connections.

You can now configure:

  • Server certificate verification with VERIFY_CA or VERIFY_IDENTITY SSL modes to verify that your MySQL database server's certificate is signed by the expected certificate authority (CA).
  • Client certificates (mTLS) for Hyperdrive to authenticate itself to your MySQL database with credentials beyond username and password.

Create a Hyperdrive configuration with custom certificates for MySQL:

# Upload a CA certificate
npx wrangler cert upload certificate-authority --ca-cert your-ca-cert.pem --name your-custom-ca-name

# Create a Hyperdrive with VERIFY_IDENTITY mode
npx wrangler hyperdrive create your-hyperdrive-config \
  --connection-string="mysql://user:password@hostname:port/database" \
  --ca-certificate-id <CA_CERT_ID> \
  --sslmode VERIFY_IDENTITY

For more information, refer to SSL/TLS certificates for Hyperdrive and MySQL TLS/SSL modes.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Cloudflare Tunnels mit Wrangler verwalten

Mit den neuen, experimentellen wrangler tunnel-Befehlen lassen sich Cloudflare Tunnels direkt im Terminal erstellen, auflisten, anzeigen, löschen und ausführen, inklusive Quick Tunnels ohne Account.

You can now manage Cloudflare Tunnels directly from Wrangler, the CLI for the Cloudflare Developer Platform. The new wrangler tunnel commands let you create, run, and manage tunnels without leaving your terminal.

Wrangler tunnel commands demo

Available commands:

  • wrangler tunnel create — Create a new remotely managed tunnel.
  • wrangler tunnel list — List all tunnels in your account.
  • wrangler tunnel info — Display details about a specific tunnel.
  • wrangler tunnel delete — Delete a tunnel.
  • wrangler tunnel run — Run a tunnel using the cloudflared daemon.
  • wrangler tunnel quick-start — Start a free, temporary tunnel without an account using Quick Tunnels.

Wrangler handles downloading and managing the cloudflared binary automatically. On first use, you will be prompted to download cloudflared to a local cache directory.

These commands are currently experimental and may change without notice. …

Originalquelle(öffnet in neuem Tab)Problem melden