Zum Inhalt springen

Cloudflare Release Notes

Einträge
1.630
Quellen
14
Zuletzt aktualisiert

Folge Cloudflare, um die Release Notes in deinen Feed zu holen.

Core Platform von Cloudflare

Neue cfWorker-Metrik im Server-Timing-Header

Der Server-Timing-Header enthält nun eine cfWorker-Metrik, die die Ausführungszeit von Cloudflare-Workern einschließlich Subrequests misst, um TTFB-Probleme besser zu diagnostizieren.

The Server-Timing header now includes a new cfWorker metric that measures time spent executing Cloudflare Workers, including any subrequests performed by the Worker. This helps developers accurately identify whether high Time to First Byte (TTFB) is caused by Worker processing or slow upstream dependencies.

Previously, Worker execution time was included in the edge metric, making it harder to identify true edge performance. The new cfWorker metric provides this visibility:

Metric

Description

edge

Total time spent on the Cloudflare edge, including Worker execution

origin

Time spent fetching from the origin server

cfWorker

Time spent in Worker execution, including subrequests but excluding origin fetch time

Example response

Server-Timing: cdn-cache; desc=DYNAMIC, edge; dur=20, origin; dur=100, cfWorker; dur=7

In this example, the edge took 20ms, the origin took 100ms, and the Worker added just 7ms of processing time.

Availability

The cfWorker metric is enabled by default if you have Real User Monitoring (RUM) enabled. Otherwise, you can enable it using Rules.

This metric is particularly useful for:

  • Performance debugging: Quickly determine if latency is caused by Worker code, external API calls within Workers, or slow origins. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Access: Vereinfachte Clientless-Browser-Isolation für private Apps

Die neue Einstellung „Allow clientless access“ erleichtert den clientlosen Zugriff auf interne Anwendungen ohne öffentliches DNS, sodass dafür kein separates Bookmark mit präfixierter Clientless-Web-Isolation-URL mehr nötig ist.

A new Allow clientless access setting makes it easier to connect users without a device client to internal applications, without using public DNS.

Allow clientless access setting in the Cloudflare One dashboard

Previously, to provide clientless access to a private hostname or IP without a published application, you had to create a separate bookmark application pointing to a prefixed Clientless Web Isolation URL (for example, https://<your-teamname>.cloudflareaccess.com/browser/https://10.0.0.1/). This bookmark was visible to all users in the App Launcher, regardless of whether they had access to the underlying application. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Access: Richtlinien für Bookmark-Anwendungen

Für Bookmark-Anwendungen lassen sich nun Access-Richtlinien zuweisen, damit Nutzer im App Launcher nur Bookmarks sehen, auf die sie laut Identität, Geräte-Posture und anderen Regeln Zugriff haben; ohne Richtlinie bleibt das Bookmark für alle sichtbar.

You can now assign Access policies to bookmark applications. This lets you control which users see a bookmark in the App Launcher based on identity, device posture, and other policy rules.

Previously, bookmark applications were visible to all users in your organization. With policy support, you can now:

  • Tailor the App Launcher to each user — Users only see the applications they have access to, reducing clutter and preventing accidental clicks on irrelevant resources.
  • Restrict visibility of sensitive bookmarks — Limit who can view bookmarks to internal tools or partner resources based on group membership, identity provider, or device posture.

Bookmarks support all Access policy configurations except purpose justification, temporary authentication, and application isolation. If no policy is assigned, the bookmark remains visible to all users (maintaining backwards compatibility).

For more information, refer to Add bookmarks.

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Umbenennung von Cloudflare-One-Netzwerkprodukten

Cloudflare benennt mehrere Netzwerkprodukte um, etwa Magic WAN in Cloudflare WAN, Magic Firewall in Cloudflare Network Firewall und Magic Network Monitoring in Network Flow, wobei Funktionen, Konfigurationen und Abrechnung unverändert bleiben.

We are updating naming related to some of our Networking products to better clarify their place in the Zero Trust and Secure Access Service Edge (SASE) journey.

We are retiring some older brand names in favor of names that describe exactly what the products do within your network. We are doing this to help customers build better, clearer mental models for comprehensive SASE architecture delivered on Cloudflare.

What's changing

  • Magic WAN → Cloudflare WAN
  • Magic WAN IPsec → Cloudflare IPsec
  • Magic WAN GRE → Cloudflare GRE
  • Magic WAN Connector → Cloudflare One Appliance
  • Magic Firewall → Cloudflare Network Firewall
  • Magic Network Monitoring → Network Flow
  • Magic Cloud Networking → Cloudflare One Multi-cloud Networking

No action is required by you — all functionality, existing configurations, and billing will remain exactly the same.

For more information, visit the Cloudflare One documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Agents SDK v0.5.0 mit Retry-Utilities und neuem @cloudflare/ai-chat v0.1.0

Das Agents SDK 0.5.0 ergänzt die Methode this.retry() mit exponentiellem Backoff und Jitter, Retry-Optionen für Aufgaben, Kontrolle über Protokollnachrichten pro Verbindung sowie ein komplett neu geschriebenes @cloudflare/ai-chat mit Data Parts und persistenter Tool-Freigabe ohne Breaking Changes.

The latest release of the Agents SDK ↗︎ adds built-in retry utilities, per-connection protocol message control, and a fully rewritten @cloudflare/ai-chat with data parts, tool approval persistence, and zero breaking changes.

Retry utilities

A new this.retry() method lets you retry any async operation with exponential backoff and jitter. You can pass an optional shouldRetry predicate to bail early on non-retryable errors.

class MyAgent extends Agent {
	async onRequest(request) {
		const data = await this.retry(() => callUnreliableService(), {
			maxAttempts: 4,
			shouldRetry: (err) => !(err instanceof PermanentError),
		});
		return Response.json(data);
	}
}
class MyAgent extends Agent {
	async onRequest(request: Request) {
		const data = await this.retry(() => callUnreliableService(), {
			maxAttempts: 4,
			shouldRetry: (err) => !(err instanceof PermanentError),
		});
		return Response.json(data);
	}
}

Retry options are also available per-task on queue(), schedule(), scheduleEvery(), and addMcpServer():

// Per-task retry configuration, persisted in SQLite alongside the task
await this.schedule(
	Date.now() + 60_000,
	"sendReport",
	{ userId: "abc" },
	{
		retry: { maxAttempts: 5 },
	},
);

// Class-level retry defaults
class MyAgent extends Agent {
	static options = {
		retry: { maxAttempts: 3 },
	};
}

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Docker-in-Docker-Unterstützung für Containers und Sandboxes

Sandboxes und Containers unterstützen nun das Ausführen von Docker innerhalb eines Containers, etwa zum Entwickeln containerisierter Anwendungen, für isolierte Testumgebungen, zum Bauen von Images in CI/CD und zum Bereitstellen von zur Laufzeit gelieferten Images.

Sandboxes and Containers now support running Docker for "Docker-in-Docker" setups. This is particularly useful when your end users or agents want to run a full sandboxed development environment.

This allows you to:

  • Develop containerized applications with your Sandbox
  • Run isolated test environments for images
  • Build container images as part of CI/CD workflows
  • Deploy arbitrary images supplied at runtime within a container

For Sandbox SDK users, see the Docker-in-Docker guide for instructions on combining Docker with the SandboxSDK. For general Containers usage, see the Containers FAQ.

Originalquelle(öffnet in neuem Tab)Problem melden

Network Security von Cloudflare

Cloudflare One: Produktnamen für Netzwerkprodukte aktualisiert

Cloudflare benennt einige Netzwerkprodukte um, z. B. wird Magic WAN zu Cloudflare WAN und Magic Firewall zu Cloudflare Network Firewall; bestehende Konfigurationen und Abrechnung bleiben unverändert.

We are updating naming related to some of our Networking products to better clarify their place in the Zero Trust and Secure Access Service Edge (SASE) journey.

We are retiring some older brand names in favor of names that describe exactly what the products do within your network. We are doing this to help customers build better, clearer mental models for comprehensive SASE architecture delivered on Cloudflare.

What's changing

  • Magic WAN → Cloudflare WAN
  • Magic WAN IPsec → Cloudflare IPsec
  • Magic WAN GRE → Cloudflare GRE
  • Magic WAN Connector → Cloudflare One Appliance
  • Magic Firewall → Cloudflare Network Firewall
  • Magic Network Monitoring → Network Flow
  • Magic Cloud Networking → Cloudflare One Multi-cloud Networking

No action is required by you — all functionality, existing configurations, and billing will remain exactly the same.

For more information, visit the Cloudflare One documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers Quick Editor: DevTools durch Log-Viewer ersetzt

Der DevTools-Inspector im Workers Quick Editor ist veraltet und wurde durch einen schlanken Log-Viewer ersetzt, der Objekte und Arrays protokolliert und das Leeren der Logs erlaubt, während ein Remote-Inspector weiterhin lokal mit Wrangler (wrangler init --from-dash) nutzbar ist.

Cloudflare has deprecated the Workers Quick Editor dev tools inspector and replaced it with a lightweight log viewer.

This aligns our logging with wrangler tail and gives us the opportunity to focus our efforts on bringing benefits from the work we have invested in observability, which would not be possible otherwise.

We have made improvements to this logging viewer based on your feedback such that you can log object and array types, and easily clear the list of logs. This does not include class instances. Limitations are documented in the Workers Playground docs.

If you do need to develop your Worker with a remote inspector, you can still do this using Wrangler locally. Cloning a project from your quick editor to your computer for local development can be done with the wrangler init --from-dash command. For more information, refer to Wrangler commands.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

WAF-Update für Zimbra und Vite

Die neue WAF-Version erkennt Schwachstellen in Zimbra Collaboration Suite (Local File Inclusion) und Vite (Path Traversal).

This week’s release introduces new detections for CVE-2025-68645 and CVE-2025-31125.

Key Findings

  • CVE-2025-68645: A Local File Inclusion (LFI) vulnerability in the Webmail Classic UI of Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 allows unauthenticated remote attackers to craft requests to the /h/rest endpoint, improperly influence internal dispatching, and include arbitrary files from the WebRoot directory.
  • CVE-2025-31125: Vite, the JavaScript frontend tooling framework, exposes content of non-allowed files via ?inline&import when its development server is network-exposed, enabling unauthorized attackers to read arbitrary files and potentially leak sensitive information.

Ruleset

Rule ID

Legacy Rule ID

Description

Previous Action

New Action

Comments

Cloudflare Managed Ruleset

...833761f7

N/A

Zimbra - Local File Inclusion - CVE:CVE-2025-68645

Log

Block

This is a new detection.

Cloudflare Managed Ruleset

...950ed8c8

N/A

Vite - WASM Import Path Traversal - CVE:CVE-2025-31125

Log

Block

This is a new detection.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Markdown for Agents: höhere Limits und Encoding-Support

Markdown for Agents unterstützt nun Antworten bis zu 2 MB, Origin-Antworten ohne content-length-Header sowie komprimierte Inhalte vom Ursprungsserver.

When AI systems request pages from any website that uses Cloudflare and has Markdown for Agents enabled, they can express the preference for text/markdown in the request: our network will automatically and efficiently convert the HTML to markdown, when possible, on the fly.

This release adds the following improvements:

  • The origin response limit was raised from 1 MB to 2 MB (2,097,152 bytes).
  • We no longer require the origin to send the content-length header.
  • We now support content encoded responses from the origin.

If you haven’t enabled automatic Markdown conversion yet, visit the AI Crawl Control ↗︎ section of the Cloudflare dashboard and enable Markdown for Agents.

Refer to our developer documentation for more details.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Neuer Best-Practices-Leitfaden für Worker

Ein neuer Leitfaden bietet Empfehlungen für den Bau schneller, zuverlässiger und sicherer Worker, unter anderem zu Kompatibilitätsdatum, Bindings und Streaming.

A new Workers Best Practices guide provides opinionated recommendations for building fast, reliable, observable, and secure Workers. The guide draws on production patterns, Cloudflare internal usage, and best practices observed from developers building on Workers.

Key guidance includes:

  • Keep your compatibility date current and enable nodejs_compat — Ensure you have access to the latest runtime features and Node.js built-in modules.
{
	"name": "my-worker",
	"main": "src/index.ts",
	// Set this to today's date
	"compatibility_date": "2026-10-11",
	"compatibility_flags": ["nodejs_compat"],
}
name = "my-worker"
main = "src/index.ts"
# Set this to today's date
compatibility_date = "2026-10-11"
compatibility_flags = [ "nodejs_compat" ]
  • Generate binding types with wrangler types — Never hand-write your Env interface. Let Wrangler generate it from your actual configuration to catch mismatches at compile time.
  • Stream request and response bodies — Avoid buffering large payloads in memory. Use TransformStream and pipeTo to stay within the 128 MB memory limit and improve time-to-first-byte.
  • Use bindings, not REST APIs — Bindings to KV, R2, D1, Queues, and other Cloudflare services are direct, in-process references with no network hop and no authentication overhead. …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Feingranulare Berechtigungen für Access-Richtlinien und Service Tokens

Zwei neue ressourcenbezogene Rollen, Cloudflare Access policy admin und Cloudflare Access service token admin, erlauben es, Berechtigungen für einzelne Access-Richtlinien bzw. Service Tokens zu vergeben; die Funktion ist als Beta verfügbar.

Fine-grained permissions for Access policies and Access service tokens are available. These new resource-scoped roles expand the existing RBAC model, enabling administrators to grant permissions scoped to individual resources.

New roles

  • Cloudflare Access policy admin: Can edit a specific Access policy in an account.
  • Cloudflare Access service token admin: Can edit a specific Access service token in an account.

These roles complement the existing resource-scoped roles for Access applications, identity providers, and infrastructure targets.

For more information:

Note

Resource-scoped roles is currently in beta.

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

GLM-4.7-Flash auf Workers AI, @cloudflare/tanstack-ai und workers-ai-provider v3.1.1

Workers AI bietet jetzt das mehrsprachige Modell GLM-4.7-Flash mit 131.072 Token Kontextfenster und Multi-Turn-Tool-Calling, dazu kommen das neue Paket @cloudflare/tanstack-ai und workers-ai-provider v3.1.1.

We're excited to announce GLM-4.7-Flash on Workers AI, a fast and efficient text generation model optimized for multilingual dialogue and instruction-following tasks, along with the brand-new @cloudflare/tanstack-ai ↗︎ package and workers-ai-provider v3.1.1 ↗︎.

You can now run AI agents entirely on Cloudflare. With GLM-4.7-Flash's multi-turn tool calling support, plus full compatibility with TanStack AI and the Vercel AI SDK, you have everything you need to build agentic applications that run completely at the edge.

GLM-4.7-Flash — Multilingual Text Generation Model

@cf/zai-org/glm-4.7-flash is a multilingual model with a 131,072 token context window, making it ideal for long-form content generation, complex reasoning tasks, and multilingual applications.

Key Features and Use Cases:

  • Multi-turn Tool Calling for Agents: Build AI agents that can call functions and tools across multiple conversation turns
  • Multilingual Support: Built to handle content generation in multiple languages effectively
  • Large Context Window: 131,072 tokens for long-form writing, complex reasoning, and processing long documents
  • Fast Inference: Optimized for low-latency responses in chatbots and virtual assistants …

Originalquelle(öffnet in neuem Tab)Problem melden

Developer Platform von Cloudflare

Workers VPC unterstützt Origin-CA-Zertifikate

Workers VPC vertraut nun auch kostenlosen Cloudflare-Origin-CA-Zertifikaten, sodass private Dienste per https ohne Zertifikate einer öffentlichen CA erreicht werden können.

Workers VPC now supports Cloudflare Origin CA certificates when connecting to your private services over HTTPS. Previously, Workers VPC only trusted certificates issued by publicly trusted certificate authorities (for example, Let's Encrypt, DigiCert).

With this change, you can use free Cloudflare Origin CA certificates on your origin servers within private networks and connect to them from Workers VPC using the https scheme. This is useful for encrypting traffic between the tunnel and your service without needing to provision certificates from a public CA.

For more information, refer to Supported TLS certificates.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Feingranulare Berechtigungen für Access-Richtlinien und -Tokens

Neue ressourcenbezogene Rollen ermöglichen Administratoren, Berechtigungen für einzelne Access-Richtlinien und Service-Tokens zu vergeben (derzeit in der Betaphase).

Fine-grained permissions for Access policies and Access service tokens are available. These new resource-scoped roles expand the existing RBAC model, enabling administrators to grant permissions scoped to individual resources.

New roles

  • Cloudflare Access policy admin: Can edit a specific Access policy in an account.
  • Cloudflare Access service token admin: Can edit a specific Access service token in an account.

These roles complement the existing resource-scoped roles for Access applications, identity providers, and infrastructure targets.

For more information:

Note

Resource-scoped roles is currently in beta.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Cloudflare Python SDK v5.0.0-beta.1 verfügbar

Das Cloudflare Python SDK v5.0.0-beta.1 enthält zahlreiche Breaking Changes durch aktualisierte OpenAPI-Definitionen und Codegen-Updates; eine Migrationsanleitung wird bereitgestellt.

Disclaimer: Please note that v5.0.0-beta.1 is in Beta and we are still testing it for stability.

Full Changelog: v4.3.1...v5.0.0-beta.1 ↗︎

In this release, you'll see a large number of breaking changes. This is primarily due to a change in OpenAPI definitions, which our libraries are based off of, and codegen updates that we rely on to read those OpenAPI definitions and produce our SDK libraries. As the codegen is always evolving and improving, so are our code bases.

There may be changes that are not captured in this changelog. Feel free to open an issue to report any inaccuracies, and we will make sure it gets into the changelog before the v5.0.0 release.

Most of the breaking changes below are caused by improvements to the accuracy of the base OpenAPI schemas, which sometimes translates to breaking changes in downstream clients that depend on those schemas.

Please ensure you read through the list of changes below and the migration guide before moving to this version - this will help you understand any down or upstream issues it may cause to your environments.

Breaking Changes

The following resources have breaking changes. See the v5 Migration Guide ↗︎ for detailed migration instructions.

  • abusereports
  • acm.totaltls
  • apigateway.configurations …

Originalquelle(öffnet in neuem Tab)Problem melden

Cloudflare One von Cloudflare

Cloudflare WAN zeigt Anycast-IPs im Dashboard an

Cloudflare WAN zeigt beim Konfigurieren von IPsec- oder GRE-Tunneln die Anycast-IP-Adressen nun direkt im Dashboard an, sodass sie nicht mehr per API-Aufruf abgerufen werden müssen.

Cloudflare WAN now displays your Anycast IP addresses directly in the dashboard when you configure IPsec or GRE tunnels.

Previously, customers received their Anycast IPs during onboarding or had to retrieve them with an API call. The dashboard now pre-loads these addresses, reducing setup friction and preventing configuration errors.

No action is required. All Cloudflare WAN customers can see their Anycast IPs in the tunnel configuration form automatically.

For more information, refer to Configure tunnel endpoints.

Originalquelle(öffnet in neuem Tab)Problem melden

Application Security von Cloudflare

Verbessertes Logo-Matching in Brand Protection

Brand Protection unterstützt nun konfigurierbare Ähnlichkeitsschwellen, visuelle Match-Scores und direkte Logo-Vorschauen zur Erkennung raffinierter Nachahmungen.

We have significantly upgraded our Logo Matching capabilities within Brand Protection. While previously limited to approximately 100% matches, users can now detect a wider range of brand assets through a redesigned matching model and UI.

What's new

  • Configurable match thresholds: Users can set a minimum match score (starting at 75%) when creating a logo query to capture subtle variations or high-quality impersonations.
  • Visual match scores: Allow users to see the exact percentage of the match directly in the results table, highlighted with color-coded lozenges to indicate severity.
  • Direct logo previews: Available in the Cloudflare dashboard — similar to string matches — to verify infringements at a glance.

Key benefits

  • Expose sophisticated impersonators who use slightly altered logos to bypass basic detection filters.
  • Faster triage of the most relevant threats immediately using visual indicators, reducing the time spent manually reviewing matches.

Ready to protect your visual identity? Learn more in our Brand Protection documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Markdown for Agents: Konvertierung in Echtzeit

Cloudflare kann HTML-Seiten für aktivierte Zonen bei Anfragen mit Accept: text/markdown automatisch in Echtzeit in Markdown umwandeln, um KI-Systemen strukturierte Inhalte zu liefern.

Cloudflare's network now supports real-time content conversion at the source, for enabled zones using content negotiation ↗︎ headers. When AI systems request pages from any website that uses Cloudflare and has Markdown for Agents enabled, they can express the preference for text/markdown in the request: our network will automatically and efficiently convert the HTML to markdown, when possible, on the fly.

Here is a curl example with the Accept negotiation header requesting this page from our developer documentation:

curl https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/ \
  -H "Accept: text/markdown"

The response to this request is now formatted in markdown:

HTTP/2 200
date: Wed, 11 Feb 2026 11:44:48 GMT
content-type: text/markdown; charset=utf-8
content-length: 2899
vary: accept
x-markdown-tokens: 725
content-signal: ai-train=yes, search=yes, ai-input=yes

---
title: Markdown for Agents · Cloudflare Agents docs
---

## What is Markdown for Agents

Markdown has quickly become the lingua franca for agents and AI systems
as a whole. The format’s explicit structure makes it ideal for AI processing,
ultimately resulting in better results while minimizing token waste.
...
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Core Platform von Cloudflare

Terraform-Provider v5.17.0 mit neuen Funktionen

Der Terraform-Provider v5.17.0 bietet neue Funktionen für KI-Suche, verbesserte Workers-Script-Platzierung und zahlreiche Fehlerbehebungen aus der Community.

In January 2025, we announced the launch of the new Terraform v5 Provider. We greatly appreciate the proactive engagement and valuable feedback from the Cloudflare community following the v5 release. In response, we have established a consistent and rapid 2-3 week cadence ↗︎ for releasing targeted improvements, demonstrating our commitment to stability and reliability.

With the help of the community, we have a growing number of resources that we have marked as stable ↗︎, with that list continuing to grow with every release. The most used resources ↗︎ are on track to be stable by the end of March 2026, when we will also be releasing a new migration tool to help you migrate from v4 to v5 with ease.

This release brings new capabilities for AI Search, enhanced Workers Script placement controls, and numerous bug fixes based on community feedback. We also begun laying foundational work for improving the v4 to v5 migration process. Stay tuned for more details as we approach the March 2026 release timeline.

Thank you for continuing to raise issues. They make our provider stronger and help us build products that reflect your needs.

Features

  • ai_search_instance: add data source for querying AI Search instances …

Originalquelle(öffnet in neuem Tab)Problem melden