Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.629
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Developer Platform von Cloudflare

Cloudflare Tunnels mit Wrangler verwalten

Mit den neuen, experimentellen wrangler tunnel-Befehlen lassen sich Cloudflare Tunnels direkt im Terminal erstellen, auflisten, anzeigen, löschen und ausführen, inklusive Quick Tunnels ohne Account.

You can now manage Cloudflare Tunnels directly from Wrangler, the CLI for the Cloudflare Developer Platform. The new wrangler tunnel commands let you create, run, and manage tunnels without leaving your terminal.

Wrangler tunnel commands demo

Available commands:

  • wrangler tunnel create — Create a new remotely managed tunnel.
  • wrangler tunnel list — List all tunnels in your account.
  • wrangler tunnel info — Display details about a specific tunnel.
  • wrangler tunnel delete — Delete a tunnel.
  • wrangler tunnel run — Run a tunnel using the cloudflared daemon.
  • wrangler tunnel quick-start — Start a free, temporary tunnel without an account using Quick Tunnels.

Wrangler handles downloading and managing the cloudflared binary automatically. On first use, you will be prompted to download cloudflared to a local cache directory.

These commands are currently experimental and may change without notice. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Moonshot AI Kimi K2.5 jetzt auf Workers AI verfügbar

Workers AI bietet mit @cf/moonshotai/kimi-k2.5 ein erstes Open-Source-Modell im Frontier-Maßstab mit 256k Kontextfenster, Multi-Turn-Tool-Calling, Vision-Eingaben, strukturierten Ausgaben und Function Calling.

Workers AI is officially in the big models game. @cf/moonshotai/kimi-k2.5 is the first frontier-scale open-source model on our AI inference platform — a large model with a full 256k context window, multi-turn tool calling, vision inputs, and structured outputs. By bringing a frontier-scale model directly onto the Cloudflare Developer Platform, you can now run the entire agent lifecycle on a single, unified platform.

The model has proven to be a fast, efficient alternative to larger proprietary models without sacrificing quality. As AI adoption increases, the volume of inference is skyrocketing — now you can access frontier intelligence at a fraction of the cost.

Key capabilities

  • 256,000 token context window for retaining full conversation history, tool definitions, and entire codebases across long-running agent sessions
  • Multi-turn tool calling for building agents that invoke tools across multiple conversation turns
  • Vision inputs for processing images alongside text
  • Structured outputs with JSON mode and JSON Schema support for reliable downstream parsing
  • Function calling for integrating external tools and APIs into agent workflows

Prefix caching and session affinity

…

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Cloudflare Fundamentals – Service-Key-Authentifizierung veraltet

Die Service-Key-Authentifizierung für die Cloudflare-API wird als veraltet markiert und funktioniert ab dem 30. September 2026 nicht mehr; Nutzer sollen auf API-Tokens umstellen.

Service Key authentication for the Cloudflare API is deprecated. Service Keys will stop working on September 30, 2026.

API Tokens replace Service Keys with fine-grained permissions, expiration, and revocation.

What you need to do

Replace any use of the X-Auth-User-Service-Key header with an API Token scoped to the permissions your integration requires.

If you use cloudflared, update to a version from November 2022 or later. These versions already use API Tokens.

If you use origin-ca-issuer ↗︎, update to a version that supports API Token authentication.

For more information, refer to API deprecations.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Cloudflare Tunnel nun über Wrangler verwaltbar

Mit den neuen experimentellen Wrangler-Befehlen können Cloudflare-Tunnel direkt aus dem Terminal erstellt, verwaltet und ausgeführt werden.

You can now manage Cloudflare Tunnels directly from Wrangler, the CLI for the Cloudflare Developer Platform. The new wrangler tunnel commands let you create, run, and manage tunnels without leaving your terminal.

Wrangler tunnel commands demo

Available commands:

  • wrangler tunnel create — Create a new remotely managed tunnel.
  • wrangler tunnel list — List all tunnels in your account.
  • wrangler tunnel info — Display details about a specific tunnel.
  • wrangler tunnel delete — Delete a tunnel.
  • wrangler tunnel run — Run a tunnel using the cloudflared daemon.
  • wrangler tunnel quick-start — Start a free, temporary tunnel without an account using Quick Tunnels.

Wrangler handles downloading and managing the cloudflared binary automatically. On first use, you will be prompted to download cloudflared to a local cache directory.

These commands are currently experimental and may change without notice. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Media-Transformations-Binding für Workers

Über ein neues Workers-Binding lassen sich Videos mit Media Transformations skalieren, zuschneiden sowie Frames und Audio extrahieren, auch aus privaten Quellen wie R2-Buckets.

You can now use a Workers binding to transform videos with Media Transformations. This allows you to resize, crop, extract frames, and extract audio from videos stored anywhere, even in private locations like R2 buckets.

The Media Transformations binding is useful when you want to:

  • Transform videos stored in private or protected sources
  • Optimize videos and store the output directly back to R2 for re-use
  • Extract still frames for classification or description with Workers AI
  • Extract audio tracks for transcription using Workers AI

To get started, add the Media binding to your Wrangler configuration:

{
  "$schema": "./node_modules/wrangler/config-schema.json",
  "media": {
    "binding": "MEDIA"
  }
}
[media]
binding = "MEDIA"

Then use the binding in your Worker to transform videos:

export default {
	async fetch(request, env) {
		const video = await env.R2_BUCKET.get("input.mp4");

		const result = env.MEDIA.input(video.body)
			.transform({ width: 480, height: 270 })
			.output({ mode: "video", duration: "5s" });

		return await result.response();
	},
};
export default {
	async fetch(request, env) {
		const video = await env.R2_BUCKET.get("input.mp4");

		const result = env.MEDIA.input(video.body)
			.transform({ width: 480, height: 270 })
			.output({ mode: "video", duration: "5s" });

		return await result.response();
	},
};
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Security Center: Echtzeit-Vorschau für Logo-Match

Das Brand Protection Dashboard bietet jetzt eine Logo-Match-Vorschau, die vor dem Speichern Beispiel-Treffer und eine Anpassung des Ähnlichkeitswerts in Echtzeit zeigt.

We are introducing Logo Match Preview, bringing the same pre-save visibility to visual assets that was previously only available for string-based queries. This update allows you to fine-tune your brand detection strategy before committing to a live monitor.

What’s new:

  • Upload your brand logo and immediately see a sample of potential matches from recently detected sites before finalizing the query
  • Adjust your similarity score (from 75% to 100%) and watch the results refresh in real-time to find the balance between broad detection and noise reduction
  • Review the specific logos triggered by your current settings to ensure your query is capturing the right level of brand infringement

If you are ready to test your brand assets, go to the Brand Protection dashboard ↗︎ to try the new preview tool.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

SCIM-Provisioning für Authentik allgemein verfügbar

Cloudflare unterstützt jetzt SCIM-Provisioning für Authentik als Identitätsanbieter; Nutzer und Gruppen können synchronisiert und verwaltet werden.

Cloudflare dashboard SCIM provisioning now supports Authentik ↗︎ as an identity provider, joining Okta and Microsoft Entra ID as explicitly supported providers.

Customers can now sync users and group information from Authentik to Cloudflare, apply Permission Policies to those groups, and manage the lifecycle of users & groups directly from your Authentik Identity Provider.

Note

SCIM provisioning for the Cloudflare dashboard is available to Enterprise customers. You must be a Super Administrator to complete the initial setup.

For more information:

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

SCIM-Aktivitäten in Audit-Logs v2

SCIM-Provisionierungsvorgänge im Cloudflare-Dashboard werden jetzt in Audit Logs v2 erfasst und geben Einblick in Benutzer- und Gruppenänderungen.

Cloudflare dashboard SCIM provisioning operations are now captured in Audit Logs v2, giving you visibility into user and group changes made by your identity provider.

SCIM audit logging

Logged actions:

Action Type

Description

Create SCIM User

User provisioned from IdP

Replace SCIM User

User fully replaced (PUT)

Update SCIM User

User attributes modified (PATCH)

Delete SCIM User

Member deprovisioned

Create SCIM Group

Group provisioned from IdP

Update SCIM Group

Group membership or attributes modified

Delete SCIM Group

Group deprovisioned

For more details, refer to the Audit Logs v2 documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Neues Feld für Worker-Ausführungszeit in Rules

Das Feld cf.timings.worker_msec ist jetzt in der Ruleset Engine verfügbar und meldet die Wanduhrzeit in Millisekunden, die ein Worker für eine Anfrage benötigt.

The cf.timings.worker_msec field is now available in the Ruleset Engine. This field reports the wall-clock time that a Cloudflare Worker spent handling a request, measured in milliseconds.

You can use this field to identify slow Worker executions, detect performance regressions, or build rules that respond differently based on Worker processing time, such as logging requests that exceed a latency threshold.

Field details

Field

Type

Description

cf.timings.worker_msec

Integer

The time spent executing a Cloudflare Worker in milliseconds. Returns 0 if no Worker was invoked.

Example filter expression:

cf.timings.worker_msec > 500

For more information, refer to the Fields reference.

Originalquelle(öffnet in neuem Tab)Problem melden

Media von Cloudflare

Media Transformations-Binding für Workers

Stream führt ein Workers-Binding für Media Transformations ein, mit dem Videos aus beliebigen Quellen, auch privaten wie R2-Buckets, transformiert werden können.

Stream

You can now use a Workers binding to transform videos with Media Transformations. This allows you to resize, crop, extract frames, and extract audio from videos stored anywhere, even in private locations like R2 buckets.

The Media Transformations binding is useful when you want to:

  • Transform videos stored in private or protected sources
  • Optimize videos and store the output directly back to R2 for re-use
  • Extract still frames for classification or description with Workers AI
  • Extract audio tracks for transcription using Workers AI

To get started, add the Media binding to your Wrangler configuration:

{
  "$schema": "./node_modules/wrangler/config-schema.json",
  "media": {
    "binding": "MEDIA"
  }
}
[media]
binding = "MEDIA"

Then use the binding in your Worker to transform videos:

export default {
	async fetch(request, env) {
		const video = await env.R2_BUCKET.get("input.mp4");

		const result = env.MEDIA.input(video.body)
			.transform({ width: 480, height: 270 })
			.output({ mode: "video", duration: "5s" });

		return await result.response();
	},
};
export default {
	async fetch(request, env) {
		const video = await env.R2_BUCKET.get("input.mp4");

		const result = env.MEDIA.input(video.body)
			.transform({ width: 480, height: 270 })
			.output({ mode: "video", duration: "5s" });

		return await result.response();
	},
};
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

AI Gateway von Cloudflare

AI Gateway: Metadaten loggen ohne Payload-Speicherung

Der neue Header cf-aig-collect-log-payload steuert, ob Request- und Response-Bodies in Logs gespeichert werden; mit dem Wert false werden nur Metadaten wie Token-Anzahl, Modell, Anbieter, Statuscode, Kosten und Dauer protokolliert.

AI Gateway now supports the cf-aig-collect-log-payload header, which controls whether request and response bodies are stored in logs. By default, this header is set to true and payloads are stored alongside metadata. Set this header to false to skip payload storage while still logging metadata such as token counts, model, provider, status code, cost, and duration.

This is useful when you need usage metrics but do not want to persist sensitive prompt or response data.

curl https://gateway.ai.cloudflare.com/v1/$ACCOUNT_ID/$GATEWAY_ID/openai/chat/completions \
  --header "Authorization: Bearer $TOKEN" \
  --header 'Content-Type: application/json' \
  --header 'cf-aig-collect-log-payload: false' \
  --data '{
    "model": "gpt-4o-mini",
    "messages": [
      {
        "role": "user",
        "content": "What is the email address and phone number of user123?"
      }
    ]
  }'

For more information, refer to Logging.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

@cloudflare/codemode v0.2.1: MCP-Export und eigene Sandbox-Module

@cloudflare/codemode 0.2.1 ergänzt einen neuen @cloudflare/codemode/mcp-Export, entfernt ai und zod als erforderliche Peer-Dependencies des Haupteinstiegspunkts und bietet mehr Kontrolle über die Sandbox.

The latest releases of @cloudflare/codemode ↗︎ add a new MCP barrel export, remove ai and zod as required peer dependencies from the main entry point, and give you more control over the sandbox.

New @cloudflare/codemode/mcp export

A new @cloudflare/codemode/mcp entry point provides two functions that wrap MCP servers with Code Mode:

  • codeMcpServer({ server, executor }) — wraps an existing MCP server with a single code tool where each upstream tool becomes a typed codemode.* method.
  • openApiMcpServer({ spec, executor, request }) — creates search and execute MCP tools from an OpenAPI spec with host-side request proxying and automatic $ref resolution.
import { codeMcpServer } from "@cloudflare/codemode/mcp";
import { DynamicWorkerExecutor } from "@cloudflare/codemode";

const executor = new DynamicWorkerExecutor({ loader: env.LOADER });

// Wrap an existing MCP server — all its tools become
// typed methods the LLM can call from generated code
const server = await codeMcpServer({ server: upstreamMcp, executor });
import { codeMcpServer } from "@cloudflare/codemode/mcp";
import { DynamicWorkerExecutor } from "@cloudflare/codemode";

const executor = new DynamicWorkerExecutor({ loader: env.LOADER });

// Wrap an existing MCP server — all its tools become
// typed methods the LLM can call from generated code …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

AI Gateway: Metadaten loggen, ohne Payloads zu speichern

AI Gateway unterstützt den Header cf-aig-collect-log-payload; mit dem Wert false werden Request- und Response-Bodies nicht gespeichert, während Metadaten wie Token-Anzahl, Modell, Provider, Statuscode, Kosten und Dauer weiter geloggt werden.

AI Gateway now supports the cf-aig-collect-log-payload header, which controls whether request and response bodies are stored in logs. By default, this header is set to true and payloads are stored alongside metadata. Set this header to false to skip payload storage while still logging metadata such as token counts, model, provider, status code, cost, and duration.

This is useful when you need usage metrics but do not want to persist sensitive prompt or response data.

curl https://gateway.ai.cloudflare.com/v1/$ACCOUNT_ID/$GATEWAY_ID/openai/chat/completions \
  --header "Authorization: Bearer $TOKEN" \
  --header 'Content-Type: application/json' \
  --header 'cf-aig-collect-log-payload: false' \
  --data '{
    "model": "gpt-4o-mini",
    "messages": [
      {
        "role": "user",
        "content": "What is the email address and phone number of user123?"
      }
    ]
  }'

For more information, refer to Logging.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Security Overview: Neue Benutzeroberfläche mit Kritikalität und Branchenvergleich

Das Security Overview wurde mit Kritikalitätsbewertungen für alle Erkenntnisse, einem Bereich für Erkennungstools und für Enterprise-Kunden mit Branchenvergleich aus Security Reports ausgestattet.

The Security Overview has been updated to provide Application Security customers with more actionable insights and a clearer view of their security posture.

Key improvements include:

  • Criticality for all Insights: Every insight now includes a criticality rating, allowing you to prioritize the most impactful security action items first.
  • Detection Tools Section: A new section displays the security detection tools available to you, indicating which are currently enabled and which can be activated to strengthen your defenses.
  • Industry Peer Comparison (Enterprise customers): A new module from Security Reports benchmarks your security posture against industry peers, highlighting relative strengths and areas for improvement.

New Security Overview UI

For more information, refer to Security Overview.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Vectorize: Bis zu 50 Ergebnisse mit Werten oder Metadaten

Bei Vectorize-Abfragen mit returnValues: true oder returnMetadata: "all" kann topK jetzt bis zu 50 statt bisher 20 betragen.

You can now set topK up to 50 when a Vectorize query returns values or full metadata. This raises the previous limit of 20 for queries that use returnValues: true or returnMetadata: "all".

Use the higher limit when you need more matches in a single query response without dropping values or metadata. Refer to the Vectorize API reference for query options and current topK limits.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Email security: Unbegrenztes Paging in Investigations

Investigations unterstützen in Dashboard und API unbegrenztes Result-Paging ohne die frühere Grenze von 1.000 Datensätzen, und die API liefert nun bis zu 10.000 Datensätze pro Seite.

Investigations now support unlimited result paging in both the dashboard and the API, removing the previous 1,000-record cap. Security teams can page through complete result sets when searching across large mail volumes, giving SOC analysts and automated workflows deeper visibility for forensics and threat hunting.

In the dashboard, infinite paging is now supported in the Investigations view. The 1,000-record ceiling has been removed, so you can navigate through the full result set directly in the UI. The Investigations API now returns up to 10,000 records per page (up from 1,000), with no cap on total result volume across pages.

For high-volume use cases, we recommend:

  • Logpush to a SIEM for full-fidelity datasets and long-term retention.
  • SOAR playbooks against the async bulk action API for large-scale remediation. Bulk actions initiated from the dashboard remain capped at 1,000 messages per action.
  • The Investigations API for report exports larger than 1,000 results, which is the dashboard download cap.

This applies to all Email Security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Durable Object-Name über ctx.id.name abrufbar

Beim Zugriff über idFromName() oder getByName() ist der Name nun innerhalb des Durable Objects über ctx.id.name verfügbar, was etwa bei Alarms nützlich ist, und bleibt bei newUniqueId(), idFromString() und Namen über 1.024 Bytes undefined.

When your Worker accesses a Durable Object via idFromName() or getByName(), the same name is now available on ctx.id.name inside the object — no need to pass it through method arguments or persist it in storage. This brings the runtime behavior in line with the Workers runtime types.

This is especially useful for alarms, where there is no calling client to pass the name as an argument. When an alarm handler runs, ctx.id.name will hold the same name the object was originally accessed with.

import { DurableObject } from "cloudflare:workers";

export class ChatRoom extends DurableObject {
  async getRoomName() {
    // ctx.id.name returns the name passed to getByName() or idFromName()
    return this.ctx.id.name;
  }
}

// Worker
export default {
  async fetch(request, env) {
    const stub = env.CHAT_ROOM.getByName("general");
    const roomName = await stub.getRoomName();
    return new Response(`Welcome to ${roomName}!`);
  },
};

ctx.id.name is undefined in the following cases:

  • For Durable Objects created with newUniqueId().
  • When accessed via idFromString(), even if the ID was originally created from a name.
  • For names longer than 1,024 bytes. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Durable-Object-Name über ctx.id.name abrufen

Bei Zugriff über idFromName() oder getByName() steht der Name in einem Durable Object nun als ctx.id.name zur Verfügung, was besonders für Alarme nützlich ist, und ist in bestimmten Fällen wie newUniqueId() undefined.

When your Worker accesses a Durable Object via idFromName() or getByName(), the same name is now available on ctx.id.name inside the object — no need to pass it through method arguments or persist it in storage. This brings the runtime behavior in line with the Workers runtime types.

This is especially useful for alarms, where there is no calling client to pass the name as an argument. When an alarm handler runs, ctx.id.name will hold the same name the object was originally accessed with.

import { DurableObject } from "cloudflare:workers";

export class ChatRoom extends DurableObject {
  async getRoomName() {
    // ctx.id.name returns the name passed to getByName() or idFromName()
    return this.ctx.id.name;
  }
}

// Worker
export default {
  async fetch(request, env) {
    const stub = env.CHAT_ROOM.getByName("general");
    const roomName = await stub.getRoomName();
    return new Response(`Welcome to ${roomName}!`);
  },
};

ctx.id.name is undefined in the following cases:

  • For Durable Objects created with newUniqueId().
  • When accessed via idFromString(), even if the ID was originally created from a name.
  • For names longer than 1,024 bytes. …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

SSH-Zugriff auf laufende Container-Instanzen

Mit Wrangler kann man sich jetzt per wrangler containers ssh auf laufende Container-Instanzen verbinden oder einzelne Befehle ausführen, sofern wrangler_ssh aktiviert und ein ssh-ed25519-Schlüssel hinterlegt ist.

You can now SSH into running Container instances using Wrangler. This is useful for debugging, inspecting running processes, or executing one-off commands inside a Container.

To connect, enable wrangler_ssh in your Container configuration and add your ssh-ed25519 public key to authorized_keys:

{
	"containers": [
		{
			"wrangler_ssh": {
				"enabled": true
			},
			"authorized_keys": [
				{
					"name": "<NAME>",
					"public_key": "<YOUR_PUBLIC_KEY_HERE>"
				}
			]
		}
	]
}
[[containers]]
[containers.wrangler_ssh]
enabled = true

[[containers.authorized_keys]]
name = "<NAME>"
public_key = "<YOUR_PUBLIC_KEY_HERE>"

Then connect with:

wrangler containers ssh <INSTANCE_ID>

You can also run a single command without opening an interactive shell:

wrangler containers ssh <INSTANCE_ID> -- ls -al

Use wrangler containers instances <APPLICATION> to find the instance ID for a running Container.

For more information, refer to the SSH documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Container-Instanzen mit wrangler containers instances auflisten

Der neue Befehl wrangler containers instances listet alle Instanzen einer Container-Anwendung mit ID, Name, Status, Standort, Version und Erstellungszeit auf und unterstützt die Ausgabe mit --json.

A new wrangler containers instances command lists all instances for a given Container application. This mirrors the instances view in the Cloudflare dashboard.

The command displays each instance's ID, name, state, location, version, and creation time:

wrangler containers instances <APPLICATION_ID>

Use the --json flag for machine-readable output, which is also the default format in non-interactive environments such as CI pipelines.

For the full list of options, refer to the containers instances command reference.

Originalquelle(öffnet in neuem Tab)Problem melden