Core Platform Updates & Release Notes

Follow

154 updates curated from 1 source by the Releasebot Team. Last updated: Oct 2, 2026

Get this feed:
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Analytics - 30 days of analytics data on every plan

    Core Platform now gives every plan at least 30 days of analytics data and brings domain analytics into one place across the dashboard, Custom Dashboards, and GraphQL API. Free and Pro domains keep at least 31 days for key adaptive datasets, with shared time ranges and filters.

    Every plan now gets at least 30 days of analytics data. Adaptive analytics datasets, such as HTTP requests, security events, and DNS analytics, retain at least 31 days of data for Free and Pro domains, and you can query up to 30 days in a single request. Previously, Free and Pro domains could see between 24 hours and 8 days of history depending on the dataset.

    A full month of history lets you investigate an issue after it happens, compare today with the same day in previous weeks, and tell a one-time spike from a longer trend. The change applies in the Cloudflare dashboard, in Custom Dashboards, and through the GraphQL Analytics API.

    Domain analytics also now live in one place. In the Cloudflare dashboard, select a domain and go to Analytics to see Traffic, Performance, Security, Cache, Origin, DNS, and Visitors as tabs that share one time range and one set of filters. Account-level analytics are under Observability > Analytics.

    This change does not alter which datasets or fields your plan can access. Aggregated datasets, such as httpRequests1hGroups, keep their existing per-plan limits. To check the exact retention and query window for a zone or account, query the settings for each dataset.

    For plan-specific limits, refer to Security Analytics, Security Events, and GraphQL Analytics API limits.

    Original source
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Analytics - Workers Observability logs and traces in Custom Dashboards

    Core Platform adds Workers Observability data to Custom Dashboards, letting users chart logs, traces, errors, CPU, wall time and more alongside HTTP traffic and security events. It also raises the dashboard limit to 100 per account.

    You can now build Custom Dashboards charts from Workers Observability data. Two new datasets, Workers Observability — Logs and Workers Observability — Traces (OTel), let you chart Worker invocations, log levels, errors, CPU and wall time, span counts, and durations next to HTTP traffic, security events, and other analytics datasets.

    This gives you one dashboard for an application that spans Cloudflare's network and your Workers. For example, you can put request volume, WAF blocks, and Worker error rates on the same view, filter all three by time range, and spot whether a spike in errors lines up with a change in traffic.

    The datasets are available for every Worker in your account that has Workers Logs or Workers Traces turned on. Custom Dashboards also now allow up to 100 dashboards for every account.

    To get started, refer to Workers Observability data in Custom Dashboards.

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Cloudflare and hundreds of other software products.

    Create account
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Rules - hash_in_range() is globally available for HTTP products

    Core Platform adds global hash_in_range() support for HTTP products on all plans, making it easier to select portions of requests and control rollout percentages with custom metadata for Cloudflare for SaaS.

    hash_in_range() is globally available for HTTP products on all plans. It hashes fields into an integer within a specified range. Use this result to select a portion of requests.

    Use cf.random_seed to select approximately 10% of requests at random:

    hash_in_range(0, 100, cf.random_seed) < 10
    

    With Cloudflare for SaaS, use custom metadata to control rollout progression. Define rollout_pct as a custom key for each hostname. Set its value to an integer from 0 to 100. The expression selects approximately that percentage of requests:

    hash_in_range(0, 100, cf.random_seed) < coalesce(lookup_json_integer(cf.hostname.metadata, "rollout_pct"), 0)
    

    If rollout_pct is missing, coalesce() supplies 0. The rule then matches no requests.

    For details, refer to the hash_in_range() function reference.

    Original source
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Cloudflare Tunnel - Protect Quick Tunnels with email authentication

    Core Platform adds protected Quick Tunnels in cloudflared, letting users restrict access by email with one-time PIN authentication. It now supports single addresses, multiple recipients, or full domains, while keeping sharing simple without a Cloudflare account or domain setup.

    You can now restrict who can access a Quick Tunnel. Use the new --allowed-mail flag in cloudflared to require visitors to authenticate with a one-time PIN sent to their email before they reach your local service.

    cloudflared tunnel --url http://localhost:8080 --allowed-mail [email protected]
    

    Previously, anyone with a trycloudflare.com URL could access the service behind it. Protected Quick Tunnels let you share a local development server, webhook receiver, or demo with specific people without creating a Cloudflare account or configuring a domain.

    You can allow:

    Visitors do not need a Cloudflare account. Access ends for everyone when you stop the cloudflared process.

    To get started, update cloudflared to the latest version and refer to Restrict access by email.

    Original source
  • Oct 1, 2026
    • Date parsed from source:
      Oct 1, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Cloudflare Fundamentals - Account members can self-serve create Account API tokens

    Core Platform expands Account API token creation beyond Super Administrators, letting members with the API Token Provisioning role create tokens in the Dashboard, API, Terraform, or CF CLI. It also adds creator attribution, scoped permissions, and clearer token visibility.

    Account API token creation is no longer limited to Super Administrators. Members with the API Token Provisioning role can now create Account API tokens via the Dashboard, API, Terraform, or CF CLI, making it easier for developers and platform teams to provision credentials without depending on a Super Administrator for Account API Token Provisioning.

    What's new

    • Delegated creation: Members with the API Token Provisioning role can create Account API tokens from the dashboard. Administrators can grant this role through the dashboard, API, or Terraform.
    • OAuth support for token creation: OAuth clients that request the account_api_tokens:create scope, starting with Cloudflare CLI, can create Account API tokens.
    • Account API token permissions limited to the creator’s access at creation time: Members can only create an Account API Token using the permissions they already have. For OAuth-created tokens, permissions are also limited to the scopes granted during authorization.
    • Creator attribution and visibility: Account API tokens now include creator metadata. Super Administrators and Administrators can view all Account API tokens in an account, while members with the API Token Provisioning role can only view tokens they created.

    For more information, refer to Account API tokens, Create tokens via API, and Roles.

    Original source
  • Similar to Core Platform with recent updates:

  • Oct 1, 2026
    • Date parsed from source:
      Oct 1, 2026
    • First seen by Releasebot:
      Oct 1, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Rules - Handle missing values with coalesce()

    Core Platform adds coalesce() for fallback values in rule expressions.

    The coalesce() function returns the first argument that is not nil. Use it to provide a fallback in rule expressions:

    http.request.uri.path eq coalesce(http.request.uri.args["expected_path"][0], "/")
    

    For details, refer to the coalesce() function reference.

    Original source
  • Oct 1, 2026
    • Date parsed from source:
      Oct 1, 2026
    • First seen by Releasebot:
      Oct 1, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Rules - Compare dynamic values in Rules expressions

    Core Platform adds dynamic value comparisons in Rules expressions for richer request matching.

    Cloudflare Rules expressions now support dynamic values on both sides of equality and ordering comparisons. You can compare request fields or function results with one another.

    For example, compare the current request path with its original value:

    http.request.uri.path ne raw.http.request.uri.path
    

    For supported operators and examples, refer to Compare dynamic values.

    Original source
  • Sep 30, 2026
    • Date parsed from source:
      Sep 30, 2026
    • First seen by Releasebot:
      Oct 1, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    logpush, Logs - Logpush is now available on all plans with usage-based pricing

    Core Platform adds Logpush to Free, Pro, Business, and Enterprise plans with usage-based pricing and self-service setup for smaller plans. Logpush Transformers are now generally available, with included monthly usage and destination-based rates.

    Cloudflare Logpush is now available on Free, Pro, Business, and Enterprise plans with usage-based pricing. Free, Pro, and Business customers can enable Logpush through self-service. Enterprise customers continue to work with their account team. Logpush Transformers are also now generally available.

    Each account receives included monthly usage before charges apply:

    • Internal exports: 25 GB per month, then $0.03 per additional GB.
    • External exports: 25 GB per month, then $0.10 per additional GB.
    • Transformations: 1 GB per month, then $0.04 per additional GB.

    R2 and Pipelines use the internal destination rate. All other destinations use the external destination rate.

    Existing Enterprise contracts retain their current Logpush pricing through renewal. Workers Logpush for Workers Trace Events retains request-based pricing, and OpenTelemetry destinations retain event-based Workers Observability pricing.

    For complete rates, measurement details, and billing examples, refer to Logpush pricing.

    Original source
  • Sep 30, 2026
    • Date parsed from source:
      Sep 30, 2026
    • First seen by Releasebot:
      Oct 1, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    logpush, Logs - Transformers are now generally available

    Core Platform adds generally available Transformers for supported Logpush datasets, letting users filter, reshape, redact, enrich, and add metadata with SQL before delivery. The feature is available on Free through Enterprise plans and can be managed in Transformer Studio or the Cloudflare API.

    Transformers are now generally available for supported Logpush datasets on Free, Pro, Business, and Enterprise plans. Use SQL to filter records, reshape fields, redact sensitive values, compute new fields, or add metadata before Logpush delivers each batch.

    Create and preview Transformers in Transformer Studio or through the Cloudflare API, then attach them to eligible account-scoped or zone-scoped Logpush jobs that use NDJSON output. Cloudflare validates each query against the dataset schema before saving it.

    Each account includes 1 GB of transformation input per month. Additional input costs $0.04 per GB. For setup instructions, supported SQL, limits, and examples, refer to Transformers. For billing details, refer to Logpush pricing.

    Original source
  • Sep 30, 2026
    • Date parsed from source:
      Sep 30, 2026
    • First seen by Releasebot:
      Sep 30, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Monetization Gateway - Monetization Gateway closed beta

    Core Platform adds Monetization Gateway in closed beta, letting sellers charge agents for access to APIs, MCP tools, sites, and datasets with payment and authorization handled in the HTTP request flow.

    Monetization Gateway is now available in closed beta. Sellers can use it to charge agents for access to APIs, Model Context Protocol (MCP) tools, sites, and datasets.

    Sellers (domain owners) define which requests require payment, the cost, and where the payment should be sent. Buyers receive the payment instructions, sign an authorization, and receive the resource after the payment has been settled. The Monetization Gateway uses the x402 protocol to handle payment authorization within the HTTP request flow.

    To learn more, request access in the Cloudflare dashboard ↗︎, review the Monetization Gateway documentation, or read the blog ↗︎.

    Original source
  • Sep 29, 2026
    • Date parsed from source:
      Sep 29, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Cloudflare Mesh, Cloudflare Tunnel, Cloudflare One, Gateway, Workers VPC - Identify Mesh, Workers VPC, and Cloudflare Tunnel replicas in network logs

    Core Platform adds clearer Zero Trust traffic logging, separating Mesh nodes and Workers VPC sessions and showing which Cloudflare Tunnel and cloudflared replica handled each session. Gateway and Network Session Logs now surface new source, destination, and replica details for easier tracing.

    You can now tell a person on a laptop apart from a Mesh node or an AI agent running on Workers, without matching on connector email addresses or Mesh IP ranges — and see exactly which Cloudflare Tunnel and cloudflared replica received each session.

    Gateway network logs and Zero Trust Network Session Logs now identify two new kinds of traffic

    Mesh — Traffic sent from or delivered to a Cloudflare Mesh node. Previously, Mesh nodes were logged the same way as devices running the Cloudflare One Client, because Mesh nodes run the client in headless mode.

    Workers VPC — Traffic sent by a Worker through a Workers VPC binding. Previously, Workers VPC sessions were not recorded in Network Session Logs.

    Gateway network logs

    To view these values in the dashboard, go to Zero Trust > Insights & Logs > Logs > Network logs, select Columns, and turn on Traffic Source and Traffic Destination. Both values also appear under Network query details when you open a log entry.

    Network Session Logs

    The zero_trust_network_sessions dataset, available through Logpush, includes the following fields:

    Field

    Description

    OnrampType
    How the session entered Cloudflare One. Values: CF1_CLIENT, MESH, WORKERS_VPC, MAGIC, OTHER.

    Offramp
    Where the session was routed. Sessions routed to a Mesh node report MESH.

    SourceName
    Name of the Worker that started the session. Only populated for Workers VPC sessions.

    SourceID
    Stable identifier of the Worker that started the session. Only populated for Workers VPC sessions.

    DestinationReplicaID
    The replica that served the session, such as a specific replica of a Mesh node or a cloudflared replica of a Cloudflare Tunnel.

    For example, OnrampType = 'WORKERS_VPC' AND Offramp = 'MESH' returns every session where a Worker reached a service behind a Mesh node, and SourceName tells you which Worker it was.

    Redeploy your Workers

    SourceName and SourceID are only populated for Workers deployed after 29 September 2026. To include them for an existing Worker, redeploy it — for example, with npx wrangler deploy. No code changes are required.

    See which tunnel and replica received a session

    With DestinationReplicaID, you can now confirm which Cloudflare Tunnel and which cloudflared replica received traffic for a specific session. Combine it with the existing DestinationTunnelID field to trace a session to an exact tunnel replica — or Mesh node replica — when you run multiple replicas for high availability. The replica ID matches the Connector ID shown in the dashboard, so you can stream that replica's logs with cloudflared tail --connector-id.

    Sessions logged before this change are not backfilled. For all available fields, refer to Zero Trust Network Session Logs.

    Original source
  • Sep 22, 2026
    • Date parsed from source:
      Sep 22, 2026
    • First seen by Releasebot:
      Sep 22, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Rules - concat() now supports up to 32 arguments

    Core Platform adds support for up to 32 arguments in Cloudflare Rules concat() expressions, making it easier to build richer dynamic values and simplify request header configurations with more context for origins.

    The concat() function in Cloudflare Rules now accepts up to 32 arguments, increased from 16. This allows you to build richer dynamic values directly in Rules expressions and simplify configurations that combine request data.

    A common use case is adding a request header that sends context to your origin. The following Rulesets API request adds a Request Header Transform Rule to an existing http_request_late_transform phase ruleset. Its 18-argument expression combines request and network information into one header value:

    curl --request POST \
    "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/rulesets/$RULESET_ID/rules" \
    --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
    --header "Content-Type: application/json" \
    --data '{
    "ref": "add_request_context_header",
    "description": "Add request context for the origin",
    "expression": "true",
    "action": "rewrite",
    "action_parameters": {
    "headers": {
    "X-Request-Context": {
    "operation": "set",
    "expression": "concat(\"ip=\", to_string(ip.src), \";country=\", ip.src.country, \";host=\", http.host, \";method=\", http.request.method, \";path=\", http.request.uri.path, \";query=\", http.request.uri.query, \";ray-id=\", cf.ray_id, \";asn=\", to_string(ip.src.asnum), \";user-agent=\", http.user_agent)"
    }
    }
    }
    }'
    

    For more information, refer to the concat() function reference and HTTP request header modification.

    Original source
  • Sep 18, 2026
    • Date parsed from source:
      Sep 18, 2026
    • First seen by Releasebot:
      Sep 21, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    logpush, Logs - Filter DDoS attack traffic from Logpush jobs

    Core Platform adds Logpush DDoS traffic exclusion to reduce attack traffic in delivered logs.

    Logpush jobs can now exclude identified distributed denial-of-service (DDoS) attack traffic. This option reduces attack traffic in delivered logs.

    It supports the http_requests, firewall_events, and network_analytics_logs datasets.

    In the dashboard, select Exclude DDoS attack traffic under Advanced Options. With the API, add this field to a job request:

    {
      "filter_attack_traffic": true
    }
    

    For more information, refer to API configuration.

    Original source
  • Sep 18, 2026
    • Date parsed from source:
      Sep 18, 2026
    • First seen by Releasebot:
      Sep 21, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Cloudflare Tunnel, Cloudflare Tunnel for SASE - cloudflared to deprecate 32-bit Windows and Intel-based macOS builds in 2027

    Core Platform announces cloudflared deprecation plans for 32-bit Windows and Intel-based macOS builds starting in 2027, aligning future releases with currently supported platforms.

    Starting in 2027, Cloudflare will deprecate 32-bit Windows and Intel-based macOS builds of cloudflared. After the deprecation takes effect, Cloudflare will no longer publish new cloudflared releases for either architecture.

    Windows 10, the last Windows release to support 32-bit systems, reached end of support in October 2025. Apple has also deprecated Intel-based Mac computers. macOS 26 Tahoe, released in September 2025, was the final macOS release to support Intel-based Macs. macOS 27, released in September 2026, no longer supports them.

    Focusing development on currently supported architectures allows cloudflared to align with operating system support and continue receiving updates on supported platforms. For available downloads and supported platforms, refer to the Cloudflare Tunnel downloads documentation.

    Original source
  • Sep 17, 2026
    • Date parsed from source:
      Sep 17, 2026
    • First seen by Releasebot:
      Sep 21, 2026
    Cloudflare logo

    Core Platform by Cloudflare

    Rules - Validate Rulesets changes before deployment

    Core Platform adds pre-deployment validation for Cloudflare Rules, helping teams catch invalid expressions, action parameters, permission issues, unavailable features, and quota limits before publishing. The dashboard and Rulesets API now support dry runs for safer rule changes.

    Cloudflare Rules now validates ruleset changes before deployment, helping you catch invalid expressions, action parameters, permission issues, unavailable features, and quota limits without publishing the configuration.

    The Cloudflare dashboard performs this validation automatically when you create or update rules from Security > Security rules or Rules > Overview.

    Supported Rulesets API mutation endpoints now also accept the dry_run=true query parameter. A dry run performs the same authorization and server-side validation checks as the requested change, but does not persist or publish it. Successful operations that normally return a 200 response return result: null. Operations that normally return 204 continue to do so.

    API example

    Add dry_run=true to a Rulesets API request to validate it without creating the ruleset:

    curl --request POST \
    "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/rulesets?dry_run=true" \
    --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
    --header "Content-Type: application/json" \
    --data '{
    "name": "Custom firewall rules",
    "kind": "zone",
    "phase": "http_request_firewall_custom",
    "rules": [
    {
    "action": "block",
    "expression": "ip.src.country eq \"GB\"",
    "description": "Block requests from the United Kingdom",
    "enabled": true
    }
    ]
    }'
    

    For more information, refer to Validate rule changes before deployment.

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.