Changelog
Subscribe to all Changelog posts via RSS.
Unless otherwise noted, all dates refer to the release date of the change.
Hyperdrive
Increased configuration limits
You can now create up to 25 Hyperdrive configurations per account, up from the previous maximum of 10.
Refer to Limits to review the limits that apply to Hyperdrive.
AI Gateway
AI Gateway is now GA
AI Gateway is moving from beta to GA.
beacon.min.js
Introducing new metric fields, transferSize and decodedBodySize are included.
Hyperdrive
Driver performance improvements
Compatibility improvements to how Hyperdrive interoperates with the popular Postgres.js driver have been released. These improvements allow queries made via Postgres.js to be correctly cached (when enabled) in Hyperdrive.
Developers who had previously set prepare: false can remove this configuration when establishing a new Postgres.js client instance.
Read the documentation on supported drivers to learn more about database driver interoperability with Hyperdrive.
Wrangler
3.57.1
- #5859 - f2ceb3aThanks @w-kuhn! - fix: queue consumer max_batch_timeout should accept a 0 value
- #5862 - 441a05fThanks @CarmenPopoviciu! - fix:- wrangler pages deployshould fail if deployment was unsuccessful- If a Pages project fails to deploy, - wrangler pages deploywill log an error message, but exit successfully. It should instead throw a- FatalError.
- #5812 - d5e00e4Thanks @thomasgauvin! - fix: remove Hyperdrive warning for local development.- Hyperdrive bindings are now supported when developing locally with Hyperdrive. We should update our logs to reflect this. 
- #5626 - a12b031Thanks @RamIdeas! - chore: ignore workerd output (error: CODE_MOVED) not intended for end-user devs
Digital Experience Monitoring
Last seen ISP
Admins can view the last ISP seen for a device by going to My Team > Devices. Requires setting up a traceroute test.
Workers AI
Add OpenAI compatible API endpoints
Added OpenAI compatible API endpoints for /v1/chat/completions and /v1/embeddings. For more details, refer to Configurations.
Wrangler
3.57.0
- #5696 - 7e97ba8Thanks @geelen! - feature: Improved- d1 execute --file --remoteperformance & added support for much larger SQL files within a single transaction.
- #5819 - 63f7acbThanks @CarmenPopoviciu! - fix: Show feedback on Pages project deployment failure- Today, if uploading a Pages Function, or deploying a Pages project fails for whatever reason, there’s no feedback shown to the user. Worse yet, the shown message is misleading, saying the deployment was successful, when in fact it was not: - ✨ Deployment complete!- This commit ensures that we provide users with: - the correct feedback with respect to their Pages deployment
- the appropriate messaging depending on the status of their project’s deployment status
- the appropriate logs in case of a deployment failure
 
- #5814 - 2869e03Thanks @CarmenPopoviciu! - fix: Display correct global flags in- wrangler pages --help- Running - wrangler pages --helpwill list, amongst others, the following global flags:- -j, --experimental-json-config -c, --config -e, --env -h, --help -v, --version- This is not accurate, since flags such as - --config,- --experimental-json-config, or- envare not supported by Pages.- This commit ensures we display the correct global flags that apply to Pages. 
- #5818 - df2daf2Thanks @WalshyDev! - chore: Deprecate usage of the deployment object on the unsafe metadata binding in favor of the new version_metadata binding.- If you’re currently using the old binding, please move over to the new version_metadata binding by adding: [version_metadata]binding = "CF_VERSION_METADATA"- and updating your usage accordingly. You can find the docs for the new binding here: https://developers.cloudflare.com/workers/runtime-apis/bindings/version-metadata 
- #5838 - 609debdThanks @petebacondarwin! - fix: update undici to the latest version to avoid a potential vulnerability
- #5832 - 86a6e09Thanks @petebacondarwin! - fix: do not allow non-string values in bulk secret uploads- Prior to Wrangler 3.4.0 we displayed an error if the user tried to upload a JSON file that contained non-string secrets, since these are not supported by the Cloudflare backend. - This change reintroduces that check to give the user a helpful error message rather than a cryptic - workers.api.error.invalid_script_configerror code.
Rules
Page Rules deprecation
Page Rules are now deprecated. You should start using modern Rules features instead of Page Rules. Refer to the Page Rules migration guide for more information.
Wrangler
3.56.0
- #5712 - 151bc3dThanks @penalosa! - feat: Support- mtls_certificatesand- browserbindings when using- wrangler.tomlwith a Pages project
- #5813 - 9627cefThanks @GregBrimble! - fix: Upload Pages project assets with more grace- Reduces the maximum bucket size from 50 MiB to 40 MiB.
- Reduces the maximum asset count from 5000 to 2000.
- Allows for more retries (with increased sleep between attempts) when encountering an API gateway failure.
 
Digital Experience Monitoring
DEX alerts
Admins can now set DEX alerts using Cloudflare Notifications. Three new DEX alert types:
- Device connectivity anomaly
- Test latency
- Test low availability
Rules
New Configuration Rules setting for Web Analytics (RUM)
You can now turn off Cloudflare Web Analytics, also known as Real User Monitoring (RUM), for specific requests using a configuration rule.
Zero Trust WARP Client
Cloudflare One Agent for Android (version 1.7)
A new GA release for the Android Cloudflare One Agent is now available in the Google Play Store. This release fixes an issue where the user was not prompted to select the client certificate in the browser during Access registration.
AI Gateway
- Added new endpoints to the REST API.
Zero Trust WARP Client
Crowdstrike posture checks for online status
Two new Crowdstrike attributes, Last Seen and State, are now available to be used as selectors in the Crowdstrike service provider integration.
Wrangler
3.55.0
- #5570 - 66bdad0Thanks @sesteves! - feature: support delayed delivery in the miniflare’s queue simulator.- This change updates the miniflare’s queue broker to support delayed delivery of messages, both when sending the message from a producer and when retrying the message from a consumer. 
- #5740 - 97741dbThanks @WalshyDev! - chore: log “Version ID” in- wrangler deploy,- wrangler deployments list,- wrangler deployments viewand- wrangler rollbackto support migration from the deprecated “Deployment ID”. Users should update any parsing to use “Version ID” before “Deployment ID” is removed.
- #5754 - f673c66Thanks @RamIdeas! - fix: when using custom builds, the- wrangler devproxy server was sometimes left in a paused state- This could be observed as the browser loading indefinitely, after saving a source file (unchanged) when using custom builds. This is now fixed by ensuring the proxy server is unpaused after a short timeout period. 
Zero Trust WARP Client
WARP client for macOS (version 2024.3.444.0)
A new GA release for the macOS WARP client is now available in the App Center. This releases fixes an issue with how the WARP client sets macOS firewall rules and addresses the TunnelVision ( CVE-2024-3661) vulnerability.
Workers
- Fixed RPC to/from Durable Objects not honoring the output gate.
- The internal_stream_byob_return_viewcompatibility flag can be used to improve the standards compliance of theReadableStreamBYOBReaderimplementation when working with BYOB streams provided by the runtime (like inresponse.bodyorrequest.body). The flag ensures that the final read result will always include avaluefield whose value is set to an emptyUint8Arraywhose underlyingArrayBufferis the same memory allocation as the one passed in on the call toread().
- The Web platform standard reportError(err)global API is now available in workers. The reported error will first be emitted as an ’error’ event on the global scope then reported in both the console output and tail worker exceptions by default.
Zaraz
- Dashboard: Add setting for Google Consent mode default
- Bugfix: Cookie values are now decoded
- Bugfix: Ensure context enricher worker can access the context.system.consentobject
- Google Ads Managed Component: Add conversion linker on pageviews without sending a pageview event
- Pinterest Conversion Api Managed Component: Bugfix handling of partial e-commerce event payloads
Wrangler
3.53.1
- #5091 - 6365c90Thanks @Cherry! - fix: better handle dashes and other invalid JS identifier characters in- wrangler typesgeneration for vars, bindings, etc.- Previously, with the following in your - wrangler.toml, an invalid types file would be generated:[vars]some-var = "foobar"- Now, the generated types file will be valid: interface Env {"some-var": "foobar";}
- #5748 - 27966a4Thanks @penalosa! - fix: Load sourcemaps relative to the entry directory, not cwd.
- #5746 - 1dd9f7eThanks @petebacondarwin! - fix: suggest trying to update Wrangler if there is a newer one available after an unexpected error
- #5226 - f63e7a5Thanks @DaniFoldi! - fix: remove second Wrangler banner from- wrangler dispatch-namespace rename
D1
D1 alpha databases will stop accepting live SQL queries on August 1, 2024
Previously deprecated alpha D1 databases need to be migrated by August 1, 2024 to accept new queries.
Refer to alpha database migration guide to migrate to the new, generally available, database architecture.
Wrangler
3.53.0
- #5604 - 327a456Thanks @dario-piotrowicz! - feat: add support for environments in- getPlatformProxy- allow - getPlatformProxyto target environments by allowing users to specify an- environmentoption- Example usage: const { env } = await getPlatformProxy({environment: "production",});
- #5705 - 4097759Thanks @G4brym! - Add- stagingflag to AI binding
Rules
New Configuration Rules setting for Cloudflare Fonts
You can now turn on or off Cloudflare Fonts for specific requests using a configuration rule.
Access
Add option to bypass CORS to origin server
Access admins can defer all CORS enforcement to their origin server for specific Access applications.
Page Shield
Suggestions for the default directive
When creating a policy in the dashboard, default directive aggregates suggestions of monitored scripts and connections data, enabling defining default directive easier.
Workers
- Updated v8 to version 12.4.
Wrangler
3.52.0
- #5666 - 81d9615Thanks @CarmenPopoviciu! - fix: Fix Pages config validation around Durable Objects- Today Pages cannot deploy Durable Objects itself. For this reason it is mandatory that when declaring Durable Objects bindings in the config file, the - script_nameis specified. We are currently not failing validation if- script_nameis not specified but we should. These changes fix that.
- #5610 - 24840f6Thanks @SuperchupuDev! - Mark- ts-json-schema-generatoras a dev dependency
- #5669 - a7e36d5Thanks @dario-piotrowicz! - fix: fix broken Durable Object local proxying (when no- cfproperty is present)- A regression was introduced in wrangler 3.46.0 ( https://github.com/cloudflare/workers-sdk/pull/5215) which made it so that missing - Request#cfproperties are serialized as- "undefined", this in turn throws a syntax parse error when such values are parsed via- JSON.parsebreaking the communication with Durable Object local proxies. Fix such issue by serializing missing- Request#cfproperties as- "{}"instead.
- #5616 - c6312b5Thanks @webbertakken! - fix: broken link to durable object migrations docs
- #5482 - 1b7739eThanks @DaniFoldi! - docs: show new Discord url everywhere for consistency. The old URL still works, but https://discord.cloudflare.com is preferred.
- Updated dependencies [ - 3a0d735,- 1b7739e]:- miniflare@3.20240419.0
- @cloudflare/kv-asset-handler@0.3.2
 
WAF
Scheduled changes for 2024-04-29
For more details, refer to the dedicated page for Scheduled changes.
DDoS protection
HTTP ruleset - Scheduled changes for 2024-04-29
For more details, refer to the dedicated page for HTTP ruleset - Scheduled changes.
DDoS protection
HTTP ruleset - 2024-04-19
For more details, refer to the dedicated page for HTTP ruleset - 2024-04-19.
Zaraz
- Instagram Managed Component: Improve performance of Instagram embeds
- Mixpanel Managed Component: Include gclidandfbclidvalues in Mixpanel requests if available
- Consent Management: Ensure consent platform is enabled when using IAB TCF compliant mode when there’s at least one TCF-approved vendor configured
- Bugfix: Ensure track data payload keys take priority over preset-keys when using enrich-payload feature for custom actions
beacon.min.js
Introducing new metric fields, deliveryType (dt) and navigationType (nt) are included.
CASB
Export CASB findings to CSV
You can now export all top-level CASB findings or every instance of your findings to CSV.
DDoS protection
HTTP ruleset - 2024-04-16 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2024-04-16 - Emergency.
DLP
Optical character recognition
DLP can now detect sensitive data in jpeg, jpg, and png files. This helps companies prevent the leak of sensitive data in images, such as screenshots.
Access
Zero Trust User identity audit logs
All user identity changes via SCIM or Authentication events are logged against a user’s registry identity.
Trace
Cloudflare Trace now supports Workers
Starting today, customers can use Cloudflare Trace to confirm if a request to a specific URL within their zone is routed through a Workers script.
D1
HTTP API now returns a HTTP 400 error for invalid queries
Previously, D1’s HTTP API returned a HTTP 500 Internal Server error for an invalid query. An invalid SQL query now correctly returns a HTTP 400 Bad Request error.
D1’s Workers API is unaffected by this change.
Stream
Live Instant Clipping for live broadcasts and recordings
Clipping is now available in open beta for live broadcasts and recordings. For more information, refer to Live instant clipping documentation.
Workers
- Improve Streams API spec compliance by exposing desiredSizeand other properties on stream class prototypes
- The new URL.parse(...)method is implemented. This provides an alternative to the URL constructor that does not throw exceptions on invalid URLs.
- R2 bindings objects now have a storageClassoption. This can be set on object upload to specify the R2 storage class - Standard or Infrequent Access. The property is also returned with object metadata.
Workers AI
Add AI native binding
- Added new AI native binding, you can now run models with const resp = await env.AI.run(modelName, inputs)
- Deprecated @cloudflare/ainpm package. While existing solutions using the @cloudflare/ai package will continue to work, no new Workers AI features will be supported. Moving to native AI bindings is highly recommended
Turnstile
- Added [refresh-timeout]and document new automatic interactive timeout-refresh.
Zaraz
- Consent Management: Add consentobject tocontext.systemfor finer control over consent preferences
- Consent Management: Add support for IAB-compliant consent mode
- Consent Management: Add “zarazConsentChoicesUpdated” event
- Consent Management: Modal now respects system dark mode prefs when present
- Google Analytics 4 Managed Component: Add support for Google Consent Mode v2
- Google Ads Managed Component: Add support for Google Consent Mode v2
- Twitter Managed Component: Enable tweet embeds
- Bing Managed Component: Support running without setting cookies
- Bugfix: client.getfor Custom Managed Components fixed
- Bugfix: Prevent duplicate pageviews in monitoring after consent granting
- Bugfix: Prevent Managed Component routes from blocking origin routes unintentionally
D1
D1 alpha databases are deprecated
Now that D1 is generally available and production ready, alpha D1 databases are deprecated and should be migrated for better performance, reliability, and ongoing support.
Refer to alpha database migration guide to migrate to the new, generally available, database architecture.
Gateway
Gateway file type control improvements
Gateway now offers a more extensive, categorized list of files to control uploads and downloads.
Workers
- A new JavaScript-native remote procedure call (RPC) API is now available, allowing you to communicate more easily across Workers and between Workers and Durable Objects.
DDoS protection
HTTP ruleset - 2024-04-04 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2024-04-04 - Emergency.
Page Shield
Individual threat intelligence categories
Instead of aggregating categories of URL and domain data from threat intelligence, they are now listed per type.
Workers
- There is no longer an explicit limit on the total amount of data which may be uploaded with Cache API put()per request. Other Cache API Limits continue to apply.
- The Web standard ReadableStream.from()API is now implemented. The API enables creating aReadableStreamfrom a either a sync or async iterable.
Durable Objects
Durable Objects support for Oceania region
Durable Objects can reside in Oceania, lowering Durable Objects request latency for eyeball Workers in Oceania locations.
Refer to Durable Objects to provide location hints to objects.
Workers
- When the brotli_content_encodingcompatibility flag is enabled, the Workers runtime now supports compressing and decompressing request bodies encoded using the Brotli compression algorithm. Refer to this docs section for more detail.
DDoS protection
HTTP ruleset - 2024-04-02
For more details, refer to the dedicated page for HTTP ruleset - 2024-04-02.
Workers
- You can now write Workers in Python
D1
D1 is generally available
D1 is now generally available and production ready. Read the blog post for more details on new features in GA and to learn more about the upcoming D1 read replication API.
- Developers with a Workers Paid plan now have a 10GB GB per-database limit (up from 2GB), which can be combined with existing limit of 50,000 databases per account.
- Developers with a Workers Free plan retain the 500 MB per-database limit and can create up to 10 databases per account.
- D1 databases can be exported as a SQL file.
Durable Objects
Billing reduction for WebSocket messages
Durable Objects request billing applies a 20:1 ratio for incoming WebSocket messages. For example, 1 million Websocket received messages across connections would be charged as 50,000 Durable Objects requests.
This is a billing-only calculation and does not impact Durable Objects metrics and analytics.
Hyperdrive
Hyperdrive is now Generally Available
Hyperdrive is now Generally Available and ready for production applications.
Read the announcement blog to learn more about the Hyperdrive and the roadmap, including upcoming support for MySQL databases.
Workers
- The new unwrap_custom_thenablescompatibility flag enables workers to accept custom thenables in internal APIs that expect a promise (for instance, thectx.waitUntil(...)method).
- TransformStreams created with the TransformStream constructor now have a cancel algorithm that is called when the stream is canceled or aborted. This change is part of the implementation of the WHATWG Streams standard.
- The nodejs_compatcompatibility flag now includes an implementation of theMockTrackerAPI fromnode:test. This is not an implementation of the fullnode:testmodule, and mock timers are currently not included.
- Exceptions reported to Tail Workers now include a “stack” property containing the exception’s stack trace, if available.
AI Gateway
- LLM Side Channel vulnerability fixed
- Providers: Added Anthropic, Google Vertex, Perplexity as providers.
Queues
Delay messages published to a queue
Messages published to a queue and/or marked for retry from a queue consumer can now be explicitly delayed. Delaying messages allows you to defer tasks until later, and/or respond to backpressure when consuming from a queue.
Refer to Batching and Retries to learn how to delay messages written to a queue.
Queues
Support for pull-based consumers
Queues now supports pull-based consumers. A pull-based consumer allows you to pull from a queue over HTTP from any environment and/or programming language outside of Cloudflare Workers. A pull-based consumer can be useful when your message consumption rate is limited by upstream infrastructure or long-running tasks.
Review the documentation on pull-based consumers to configure HTTP-based pull.
Turnstile
- Added more supported languages.
Rules
New TLS fields in rule expressions
Customers can now use new fields cf.tls_client_hello_length (the length of the client hello message sent in a TLS handshake), cf.tls_client_random (the value of the 32-byte random value provided by the client in a TLS handshake), and cf.tls_client_extensions_sha1 (the SHA-1 fingerprint of TLS client extensions) in various products built on Ruleset Engine.
Page Shield
Increase allowed length per policy
Now each policy supports up to 6,000 characters.
Rules
Origin Rules now allow port numbers in Host Header Override
Customers can now use arbitrary port numbers in Host Header Override in Origin Rules. Previously, only hostname was allowed as a value (for example, example.com). Now, you can set the value to hostname:port (for example, example.com:1234) as well.
Hyperdrive
Improved local development configuration
Hyperdrive now supports a WRANGLER_HYPERDRIVE_LOCAL_CONNECTION_STRING_<BINDING_NAME> environmental variable for configuring local development to use a test/non-production database, in addition to the localConnectionString configuration in wrangler.toml.
Refer to Local development for instructions on how to configure Hyperdrive locally.
Queues
Default content type now set to JSON
The default content type for messages published to a queue is now json, which improves compatibility with the upcoming pull-based queues.
Any Workers created on or after the compatibility date of 2024-03-18, or that explicitly set the queues_json_messages compatibility flag, will use the new default behaviour. Existing Workers with a compatibility date prior will continue to use v8 as the default content type for published messages.
Trace
Cloudflare Trace now supports BYOIP zones
Customers can now use Cloudflare Trace to trace HTTP/S requests through their BYOIP zones.
D1
Change in wrangler d1 execute default
As of wrangler@3.33.0, wrangler d1 execute and wrangler d1 migrations apply now default to using a local database, to match the default behavior of wrangler dev.
It is also now possible to specify one of --local or --remote to explicitly tell wrangler which environment you wish to run your commands against.
DDoS protection
Network-layer ruleset - 2024-03-12
For more details, refer to the dedicated page for Network-layer ruleset - 2024-03-12.
Trace
Cloudflare Trace now supports grey-clouded hostnames
Even if the hostname is not proxied by Cloudflare, Cloudflare Trace will now return all the configurations that Cloudflare would have applied to the request.
Workers
- Built-in APIs that return Promises will now produce stack traces when the Promise rejects. Previously, the rejection error lacked a stack trace.
- A new compat flag fetcher_no_get_put_deleteremoves theget(),put(), anddelete()methods on service bindings and Durable Object stubs. This will become the default as of compatibility date 2024-03-26. These methods were designed as simple convenience wrappers aroundfetch(), but were never documented.
- Updated v8 to version 12.3.
D1
Billing for D1 usage
As of 2024-03-05, D1 usage will start to be counted and may incur charges for an account’s future billing cycle.
Developers on the Workers Paid plan with D1 usage beyond included limits will incur charges according to D1’s pricing.
Developers on the Workers Free plan can use up to the included limits. Usage beyond the limits below requires signing up for the $5/month Workers Paid plan.
Account billable metrics are available in the Cloudflare Dashboard and GraphQL API.
DDoS protection
HTTP ruleset - 2024-02-26 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2024-02-26 - Emergency.
Version Management
Support for API Shield
- API Shield no longer prevents Version Management enablement and zone settings configurations.
Queues
Explicit retries no longer impact consumer concurrency/scaling.
Calling retry() or retryAll() on a message or message batch will no longer have an impact on how Queues scales consumer concurrency.
Previously, using explicit retries via retry() or retryAll() would count as an error and could result in Queues scaling down the number of concurrent consumers.
Workers
- v8 updated to version 12.2.
- You can now use Iterator helpers in Workers.
- You can now use new methods on Set, such asSet.intersectionandSet.union, in Workers.
Workers
- Sockets now support an openedattribute.
- Durable Object alarm handlers now impose a maximum wall time of 15 minutes.
Access
Access for SaaS OIDC Support
Access for SaaS applications can be setup with OIDC as an authentication method. OIDC and SAML 2.0 are now both fully supported.
Access
WARP as an identity source for Access
Allow users to log in to Access applications with their WARP session identity. Users need to reauthenticate based on default session durations. WARP authentication identity must be turned on in your device enrollment permissions and can be enabled on a per application basis.
DDoS protection
HTTP ruleset - 2024-02-19
For more details, refer to the dedicated page for HTTP ruleset - 2024-02-19.
D1
API changes to run()
A previous change (made on 2024-02-13) to the run() query statement method has been reverted.
run() now returns a D1Result, including the result rows, matching its original behaviour prior to the change on 2024-02-13.
Future change to run() to return a D1ExecResult, as originally intended and documented, will be gated behind a compatibility date as to avoid breaking existing Workers relying on the way run() currently works.
Stream
Tonemapping impovements for HDR content
In certain cases, videos uploaded with an HDR colorspace (such as footage from certain mobile devices) appeared washed out or desaturated when played back. This issue is resolved for new uploads.
Zaraz
- Single Page Applications: Introduce zaraz.spaPageview()for manually triggering SPA pageviews
- Pinterest Managed Component: Add ecommerce support
- Google Ads Managed Component: Append url and rnd params to pagead/landing endpoint
- Bugfix: Add noindex robots headers for Zaraz GET endpoint responses
- Bugfix: Gracefully handle responses from custom Managed Components without mapped endpoints
D1
API changes to raw(), all() and run()
D1’s raw(), all() and run() query statement methods have been updated to reflect their intended behaviour and improve compatibility with ORM libraries.
raw() now correctly returns results as an array of arrays, allowing the correct handling of duplicate column names (such as when joining tables), as compared to all(), which is unchanged and returns an array of objects. To include an array of column names in the results when using raw(), use raw({columnNames: true}).
run() no longer incorrectly returns a D1Result and instead returns a D1ExecResult as originally intended and documented.
This may be a breaking change for some applications that expected raw() to return an array of objects.
Refer to D1 client API to review D1’s query methods, return types and TypeScript support in detail.
DDoS protection
HTTP ruleset - 2024-02-12
For more details, refer to the dedicated page for HTTP ruleset - 2024-02-12.
DDoS protection
HTTP ruleset - 2024-02-08 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2024-02-08 - Emergency.
DDoS protection
HTTP ruleset - 2024-02-06 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2024-02-06 - Emergency.
DDoS protection
HTTP ruleset - 2024-02-05 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2024-02-05 - Emergency.
Zaraz
- Dashboard: rename “tracks” to “events” for consistency
- Pinterest Conversion API Managed Component: update parameters sent to api
- HTTP Managed Component: update _settings prefix usage handling
- Bugfix: better minification of client-side js
- Bugfix: fix bug where anchor link click events were not bubbling when using click listener triggers
- API update: begin migration support from deprecated tool.neoEventsarray totool.actionsobject config schema migration
DDoS protection
HTTP ruleset - 2024-01-26 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2024-01-26 - Emergency.
DDoS protection
HTTP ruleset - 2024-01-25
For more details, refer to the dedicated page for HTTP ruleset - 2024-01-25.
DDoS protection
HTTP ruleset - 2024-01-23
For more details, refer to the dedicated page for HTTP ruleset - 2024-01-23.
D1
Support for LIMIT on UPDATE and DELETE statements
D1 now supports adding a LIMIT clause to UPDATE and DELETE statements, which allows you to limit the impact of a potentially dangerous operation.
Vectorize
HTTP API query vectors request and response format change
Vectorize /query HTTP endpoint has the following changes:
- returnVectorsrequest body property is deprecated in favor of- returnValuesand- returnMetadataproperties.
- Response format has changed to the below format to match [Workers API change]:(/workers/configuration/compatibility-dates/#vectorize-query-with-metadata-optionally-returned)
{  "result": {    "count": 1,    "matches": [      {        "id": "4",        "score": 0.789848214,        "values": [ 75.0999984741211, 67.0999984741211, 29.899999618530273],        "metadata": {          "url": "/products/sku/418313",          "streaming_platform": "netflix"        }      }    ]  },  "errors": [],  "messages": [],  "success": true
}
DDoS protection
HTTP ruleset - 2024-01-05
For more details, refer to the dedicated page for HTTP ruleset - 2024-01-05.
Access
Unique Entity IDs in Access for SaaS
All new Access for SaaS applications have unique Entity IDs. This allows for multiple integrations with the same SaaS provider if required. The unique Entity ID has the application audience tag appended. Existing apps are unchanged.
DDoS protection
HTTP ruleset - 2023-12-19 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-12-19 - Emergency.
Zaraz
- Google Analytics 4 Managed Component: Fix Google Analytics 4 average engagement time metric.
D1
Legacy alpha automated backups disabled
Databases using D1’s legacy alpha backend will no longer run automated hourly backups. You may still choose to take manual backups of these databases.
The D1 team recommends moving to D1’s new production backend, which will require you to export and import your existing data. D1’s production backend is faster than the original alpha backend. The new backend also supports Time Travel, which allows you to restore your database to any minute in the past 30 days without relying on hourly or manual snapshots.
Turnstile
- Added Pre-Clearance mode.
Access
Default relay state support in Access for SaaS
Allows Access admins to set a default relay state on Access for SaaS apps.
DDoS protection
HTTP ruleset - 2023-12-14 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-12-14 - Emergency.
DDoS protection
HTTP ruleset - 2023-12-08 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-12-08 - Emergency.
Vectorize
Metadata filtering
Vectorize now supports metadata filtering with equals ($eq) and not equals ($neq) operators. Metadata filtering limits query() results to only vectors that fulfill new filter property.
let metadataMatches = await env.YOUR_INDEX.query(queryVector,  {    topK: 3,    filter: { streaming_platform: "netflix" },    returnValues: true,    returnMetadata: true  })
Only new indexes created on or after 2023-12-06 support metadata filtering. Currently, there is no way to migrate previously created indexes to work with metadata filtering.
Workers
- The Web Platform standard navigator.sendBeacon(...)API is now provided by the Workers runtime.
- V8 updated to 12.0.
DDoS protection
HTTP ruleset - 2023-11-29
For more details, refer to the dedicated page for HTTP ruleset - 2023-11-29.
Radar
Add more meta information’s
- Added meta.lastUpdated to all summaries and top endpoints (timeseries and timeseriesGroups already had this).
- Fix meta.dateRange to return date ranges for all requested series.
DDoS protection
HTTP ruleset - 2023-11-22
For more details, refer to the dedicated page for HTTP ruleset - 2023-11-22.
Radar
Add new Layer 3 endpoints and Layer 7 dimensions
- Added Layer 3 top origin locations and top target location.
- Added Layer 7 Summaries by http_method,http_version,ip_version,managed_rules,mitigation_product.
- Added Layer 7 Timeseries Groups by http_method,http_version,ip_version,managed_rules,mitigation_product,industry,vertical.
- Added Layer 7 Top by industry,vertical.
- Deprecated Layer 7 timeseries groups without dimension.- To continue getting this data, switch to the new timeseries group by mitigation_product endpoint.
 
- Deprecated Layer 7 summary without dimension).- To continue getting this data, switch to the new summary by mitigation_product endpoint.
 
- Added new Error codes.
DDoS protection
HTTP ruleset - 2023-11-13 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-11-13 - Emergency.
Zaraz
- HTTP Request Managed Component: Re-added __zarazTrackproperty.
DDoS protection
HTTP ruleset - 2023-11-10 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-11-10 - Emergency.
Vectorize
Metadata API changes
Vectorize now supports distinct returnMetadata and returnValues arguments when querying an index, replacing the now-deprecated returnVectors argument. This allows you to return metadata without needing to return the vector values, reducing the amount of unnecessary data returned from a query. Both returnMetadata and returnValues default to false.
For example, to return only the metadata from a query, set returnMetadata: true.
let matches = await env.YOUR_INDEX.query(queryVector, { topK: 5, returnMetadata: true })
New Workers projects created on or after 2023-11-08 or that update the compatibility date for an existing project will use the new return type.
Stream
HLS improvements for on-demand TS output
HLS output from Cloudflare Stream on-demand videos that use Transport Stream file format now includes a 10 second offset to timestamps. This will have no impact on most customers. A small percentage of customers will see improved playback stability. Caption files were also adjusted accordingly.
Radar
Add new Layer 3 direction parameter
- Added a directionparameter to all Layer 3 endpoints. Use together withlocationparameter to filter by origin or target location timeseries groups.
Zaraz
- Google Analytics 4 Managed Component: Remove debug_modekey if falsy orfalse.
Workers
- A new usage model called Workers Standard is available for Workers and Pages Functions pricing. This is now the default usage model for accounts that are first upgraded to the Workers Paid plan. Read the blog post for more information.
- The usage model set in a script’s wrangler.toml will be ignored after an account has opted-in to Workers Standard pricing. It must be configured through the dashboard (Workers & Pages > Select your Worker > Settings > Usage Model).
- Workers and Pages Functions on the Standard usage model can set custom CPU limits for their Workers
AI Gateway
- Real-time Logs: Logs are now real-time, showing logs for the last hour. If you have a need for persistent logs, please let the team know on Discord. We are building out a persistent logs feature for those who want to store their logs for longer.
- Providers: Azure OpenAI is now supported as a provider!
- Docs: Added Azure OpenAI example.
- Bug Fixes: Errors with costs and tokens should be fixed.
Zaraz
- Custom HTML: Added support for non-JavaScript script tags.
Workers
- Added the crypto_preserve_public_exponentcompatibility flag to correct a wrong type being used in the algorithm field of RSA keys in the WebCrypto API.
Zaraz
- Bing Managed Component: Fixed an issue where some events were not being sent to Bing even after being triggered.
- Dashboard: Improved welcome screen for new Zaraz users".
DDoS protection
HTTP ruleset - 2023-10-19
For more details, refer to the dedicated page for HTTP ruleset - 2023-10-19.
beacon.min.js
Manages A/B testing tags.
Workers
- The limit of 3 Cron Triggers per Worker has been removed. Account-level limits on the total number of Cron Triggers across all Workers still apply.
Workers
- A TCP Socket’s WritableStream now ensures the connection has opened before resolving the promise returned by close.
DDoS protection
HTTP ruleset - 2023-10-11
For more details, refer to the dedicated page for HTTP ruleset - 2023-10-11.
Stream
SRT Audio Improvements
In some cases, playback via SRT protocol was missing an audio track regardless of existence of audio in the broadcast. This issue is now resolved.
Tenant
New Tenant Admin UI
- Partners can now create and view accounts through the Cloudflare dashboard by going to Tenants > Managed Accounts.
AI Gateway
- Logs: Logs will now be limited to the last 24h. If you have a use case that requires more logging, please reach out to the team on Discord.
- Dashboard: Logs now refresh automatically.
- Docs: Fixed Workers AI example in docs and dash.
- Caching: Embedding requests are now cacheable. Rate limit will not apply for cached requests.
- Bug Fixes: Identical requests to different providers are not wrongly served from cache anymore. Streaming now works as expected, including for the Universal endpoint.
- Known Issues: There’s currently a bug with costs that we are investigating.
DDoS protection
HTTP ruleset - 2023-10-09 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-10-09 - Emergency.
Workers
- The Web Platform standard CustomEventclass is now available in Workers.
- Fixed a bug in the WebCrypto API where the publicExponentfield of the algorithm of RSA keys would have the wrong type. Use thecrypto_preserve_public_exponentcompatibility flag to enable the new behavior.
Queues
More queues per account - up to 10,000
Developers building on Queues can now create up to 10,000 queues per account, enabling easier per-user, per-job and sharding use-cases.
Refer to Limits to learn more about Queues’ current limits.
Notifications
- Added Traffic Anomalies Alerts to notify customers when traffic to their domain has an unexpected spike or drop.
Queues
Higher consumer concurrency limits
Queue consumers can now scale to 20 concurrent invocations (per queue), up from 10. This allows you to scale out and process higher throughput queues more quickly.
Queues with no explicit limit specified will automatically scale to the new maximum.
This limit will continue to grow during the Queues beta.
D1
Create up to 50,000 D1 databases
Developers using D1 on a Workers Paid plan can now create up to 50,000 databases as part of ongoing increases to D1’s limits.
- This further enables database-per-user use-cases and allows you to isolate data between customers.
- Total storage per account is now 50 GB.
- D1’s analytics and metrics provide per-database usage data.
If you need to create more than 50,000 databases or need more per-account storage, reach out to the D1 team to discuss.
Vectorize
Increased indexes per account limits
You can now create up to 100 Vectorize indexes per account. Read the limits documentation for details on other limits, many of which will increase during the beta period.
Zaraz
- Bugfix: Fixed an issue that prevented some server-side requests from arriving to their destination
- Google Analytics 4 Managed Component: Add support for dbgandirfields.
D1
The D1 public beta is here
D1 is now in public beta, and storage limits have been increased:
- Developers with a Workers Paid plan now have a 2 GB per-database limit (up from 500 MB) and can create 25 databases per account (up from 10). These limits will continue to increase automatically during the public beta.
- Developers with a Workers Free plan retain the 500 MB per-database limit and can create up to 10 databases per account.
Databases must be using D1’s new storage subsystem to benefit from the increased database limits.
Read the announcement blog for more details about what is new in the beta and what is coming in the future for D1.
Hyperdrive
Hyperdrive now available
Hyperdrive is now available in public beta to any developer with a Workers paid plan.
To start using Hyperdrive, visit the get started guide or read the announcement blog to learn more.
Notifications
- Added Incident Alerts.
Vectorize
Vectorize now in open beta
Vectorize, Cloudflare’s vector database, is now in open beta. Vectorize allows you to store and efficiently query vector embeddings from AI/ML models from Workers AI, OpenAI, and other embeddings providers or machine-learning workflows.
To get started with Vectorize, see the guide.
Stream
LL-HLS Beta
Low-Latency HTTP Live Streaming (LL-HLS) is now in open beta. Enable LL-HLS on your live input for automatic low-latency playback using the Stream built-in player where supported.
For more information, refer to live input and custom player docs.
DDoS protection
HTTP ruleset - 2023-09-24 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-09-24 - Emergency.
DDoS protection
HTTP ruleset - 2023-09-21 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-09-21 - Emergency.
Version Management
Support for Bot Management
- Version Management now supports versioning for Bot Management.
Access
App launcher supports tags and filters
Access admins can now tag applications and allow users to filter by those tags in the App Launcher.
Access
App launcher customization
Allow Access admins to configure the App Launcher page within Zero Trust.
Access
View active Access user identities in the dashboard and API
Access admins can now view the full contents of a user’s identity and device information for all active application sessions.
Workers
- An implementation of the node:cryptoAPI from Node.js is now available when thenodejs_compatcompatibility flag is enabled.
Pages
Support for D1’s new storage subsystem and build error message improvements
- Added support for D1’s new storage subsystem. All Git builds and deployments done with Wrangler v3.5.0 and up can use the new subsystem.
- Builds which fail due to exceeding the build time limit will return a proper error message indicating so rather than Internal error.
- New and improved error messages for other build failures
Zaraz
- Consent Management: Add support for custom button translations.
- Consent Management: Modal stays fixed when scrolling.
- Google Analytics 4 Managed Component: hideOriginalIPandga-audiencescan be set from tool event.
Zaraz
- Reddit Managed Component: Support new “Account ID” formats (e.g. “ax_xxxxx”).
Access
Custom OIDC claims for named IdPs
Access admins can now add custom claims to the existing named IdP providers. Previously this was locked to the generic OIDC provider.
Waiting Room
Waiting Room coverage for multiple hostnames and paths
- Advanced Waiting Room customers can now add multiple hostname and path combinations to a single waiting room via the UI and API.
Zaraz
- Consent Management: Consent cookie name can now be customized.
DDoS protection
HTTP ruleset - 2023-09-05 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-09-05 - Emergency.
Zaraz
- Segment Managed Component: API Endpoint can be customized.
DDoS protection
HTTP ruleset - 2023-08-30 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-08-30 - Emergency.
DDoS protection
HTTP ruleset - 2023-08-29 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-08-29 - Emergency.
DDoS protection
HTTP ruleset - 2023-08-25 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-08-25 - Emergency.
Turnstile
- Added Client-side errors.
Notifications
- Added Logo Match Alert.
Pages
Commit message limit increase
- Commit messages can now be up to 384 characters before being trimmed.
Zaraz
- TikTok Managed Component: Support setting ttpandevent_id.
- Consent Management: Accessibility improvements.
- Facebook Managed Component: Support for using “Limited Data Use” features.
D1
Row count now returned per query
D1 now returns a count of rows_written and rows_read for every query executed, allowing you to assess the cost of query for both pricing and index optimization purposes.
The meta object returned in D1’s Client API contains a total count of the rows read (rows_read) and rows written (rows_written) by that query. For example, a query that performs a full table scan (for example, SELECT * FROM users) from a table with 5000 rows would return a rows_read value of 5000:
"meta": {  "duration": 0.20472300052642825,  "size_after": 45137920,  "rows_read": 5000,  "rows_written": 0
}
Refer to D1 pricing documentation to understand how reads and writes are measured. D1 remains free to use during the alpha period.
DDoS protection
HTTP ruleset - 2023-08-16 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-08-16 - Emergency.
DDoS protection
HTTP ruleset - 2023-08-14
For more details, refer to the dedicated page for HTTP ruleset - 2023-08-14.
Radar
Deprecate old layer 3 dataset
- Added Regional Internet Registry (see field sourcein response) to get asn by id and get asn by ip endpoints.
- Stopped collecting data in the old Layer 3 data source.
- Updated Layer 3
timeseries endpoint
to start using the new Layer 3 data source by default, fetching the old data source now requires sending the parameter
metric=bytes_old.
- Deprecated Layer 3
summary endpoint, this will stop
receiving data after 2023-08-14.- To continue getting this data, switch to the new timeseries group protocol endpoint.
 
- Deprecated Layer 3
timeseries groups
endpoint, this will stop receiving data after 2023-08-14.- To continue getting this data, switch to the new timeseries group protocol endpoint.
 
DDoS protection
HTTP ruleset - 2023-08-11 - Emergency
For more details, refer to the dedicated page for HTTP ruleset - 2023-08-11 - Emergency.
D1
Bind D1 from the Cloudflare dashboard
You can now bind a D1 database to your Workers directly in the Cloudflare dashboard. To bind D1 from the Cloudflare dashboard, select your Worker project -> Settings -> Variables -> and select D1 Database Bindings.
Note: If you have previously deployed a Worker with a D1 database binding with a version of wrangler prior to 3.5.0, you must upgrade to wrangler v3.5.0 first before you can edit your D1 database bindings in the Cloudflare dashboard. New Workers projects do not have this limitation.
Legacy D1 alpha users who had previously prefixed their database binding manually with __D1_BETA__ should remove this as part of this upgrade. Your Worker scripts should call your D1 database via env.BINDING_NAME only. Refer to the latest D1 getting started guide for best practices.
We recommend all D1 alpha users begin using wrangler 3.5.0 (or later) to benefit from improved TypeScript types and future D1 API improvements.
Stream
Scheduled Deletion
Stream now supports adding a scheduled deletion date to new and existing videos. Live inputs support deletion policies for automatic recording deletion.
For more, refer to the video on demand or live input docs.
Access
Azure AD authentication contexts
Support Azure AD authentication contexts directly in Access policies.
D1
Per-database limit now 500 MB
Databases using D1’s new storage subsystem can now grow to 500 MB each, up from the previous 100 MB limit. This applies to both existing and newly created databases.
Refer to Limits to learn about D1’s limits.
Pages
Support for newer TLDs
- Support newer TLDs such as .partyand.music.
DDoS protection
HTTP ruleset - 2023-07-31
For more details, refer to the dedicated page for HTTP ruleset - 2023-07-31.
DDoS protection
Network-layer ruleset - 2023-07-31
For more details, refer to the dedicated page for Network-layer ruleset - 2023-07-31.
Radar
Fix HTTP timeseries endpoint urls
- Updated HTTP timeseriesendpoints urls totimeseries_groups( example) due to consistency. Old timeseries endpoints are still available, but will soon be removed.
Turnstile
- Added [turnstile.isExpired].
- Added uklanguage.
D1
New default storage subsystem
Databases created via the Cloudflare dashboard and Wrangler (as of v3.4.0) now use D1’s new storage subsystem by default. The new backend can be 6 - 20x faster than D1’s original alpha backend.
To understand which storage subsystem your database uses, run wrangler d1 info YOUR_DATABASE and inspect the version field in the output.
Databases with version: beta use the new storage backend and support the Time Travel API. Databases with version: alpha only use D1’s older, legacy backend.
D1
Time Travel
Time Travel is now available. Time Travel allows you to restore a D1 database back to any minute within the last 30 days (Workers Paid plan) or 7 days (Workers Free plan), at no additional cost for storage or restore operations.
Refer to the Time Travel documentation to learn how to travel backwards in time.
Databases using D1’s new storage subsystem can use Time Travel. Time Travel replaces the snapshot-based backups used for legacy alpha databases.
beacon.min.js
Fixed ETag format in the response header.
Workers
- An implementation of the util.MIMETypeAPI from Node.js is now available when thenodejs_compatcompatibility flag is enabled.
beacon.min.js
Fixed the issue that was causing an illegal invocation error.
Pages
V2 build system enabled by default
- V2 build system is now default for all new projects.
Pages
Sped up project creation
- Sped up project creation.
Workers
- An implementation of the process.envAPI from Node.js is now available when using thenodejs_compatcompatibility flag.
- An implementation of the diagnostics_channelAPI from Node.js is now available when using thenodejs_compatcompatibility flag.
R2
- Improved performance for ranged reads on very large files. Previously ranged reads near the end of very large files would be noticeably slower than ranged reads on smaller files. Performance should now be consistently good independent of filesize.
D1
Metrics and analytics
You can now view per-database metrics via both the Cloudflare dashboard and the GraphQL Analytics API.
D1 currently exposes read & writes per second, query response size, and query latency percentiles.
Access
Custom block pages for Access applications
Allow Access admins to customize the block pages presented by Access to end users.
Workers
- Added the strict_crypto_checkscompatibility flag to enable additional Web Crypto API error and security checking.
- Fixes regression in the TCP Sockets API where connect("google.com:443")would fail with aTypeError.
R2
- Multipart ETags are now MD5 hashes.
Workers
- The TCP Sockets API now reports clearer errors when a connection cannot be established.
- Updated V8 to 11.5.
D1
Generated columns documentation
New documentation has been published on how to use D1’s support for generated columns to define columns that are dynamically generated on write (or read). Generated columns allow you to extract data from JSON objects or use the output of other SQL functions.
R2
- Fixed a bug where calling GetBucket on a non-existent bucket would return a 500 instead of a 404.
- Improved S3 compatibility for ListObjectsV1, now nextmarker is only set when truncated is true.
- The R2 worker bindings now support parsing conditional headers with multiple etags. These etags can now be strong, weak or a wildcard. Previously the bindings only accepted headers containing a single strong etag.
- S3 putObject now supports sha256 and sha1 checksums. These were already supported by the R2 worker bindings.
- CopyObject in the S3 compatible api now supports Cloudflare specific headers which allow the copy operation to be conditional on the state of the destination object.
D1
Deprecating Error.cause
As of wrangler v3.1.1 the D1 client API now returns detailed error messages within the top-level Error.message property, and no longer requires developers to inspect the Error.cause.message property.
To facilitate a transition from the previous Error.cause behaviour, detailed error messages will continue to be populated within Error.cause as well as the top-level Error object until approximately July 14th, 2023. Future versions of both wrangler and the D1 client API will no longer populate Error.cause after this date.
Workers
- AbortSignal.any()is now available.
- Updated V8 to 11.4.
- Following an update to the WHATWG URL spec, the delete()andhas()methods of theURLSearchParamsclass now accept an optional second argument to specify the search parameter’s value. This is potentially a breaking change, so it is gated behind the newurlsearchparams_delete_has_value_argandurl_standardcompatibility flags.
- Added the strict_compression_checkscompatibility flag for additionalDecompressionStreamerror checking.
Workers
- A new Hibernatable WebSockets API (beta) has been added to Durable Objects. The Hibernatable WebSockets API allows a Durable Object that is not currently running an event handler (for example, processing a WebSocket message or alarm) to be removed from memory while keeping its WebSockets connected (“hibernation”). A Durable Object that hibernates will not incur billable Duration (GB-sec) charges.
Turnstile
- Added idempotency support for POST /siteverifyrequests via theidempotency_keyparameter.
D1
New experimental backend
D1 has a new experimental storage back end that dramatically improves query throughput, latency and reliability. The experimental back end will become the default back end in the near future. To create a database using the experimental backend, use wrangler and set the --experimental-backend flag when creating a database:
$ wrangler d1 create your-database --experimental-backend
Read more about the experimental back end in the announcement blog.
D1
Location hints
You can now provide a location hint when creating a D1 database, which will influence where the leader (writer) is located. By default, D1 will automatically create your database in a location close to where you issued the request to create a database. In most cases this allows D1 to choose the optimal location for your database on your behalf.
Pages
Build error message improvement
- Builds which fail due to Out of memory (OOM) will return a proper error message indicating so rather than Internal error.
D1
Query JSON
New documentation has been published that covers D1’s extensive JSON function support. JSON functions allow you to parse, query and modify JSON directly from your SQL queries, reducing the number of round trips to your database, or data queried.
Pages
V2 build system beta
- The V2 build system is now available in open beta. Enable the V2 build system by going to your Pages project in the Cloudflare dashboard and selecting Settings > Build & deployments > Build system version.
Pages
Support for Smart Placement
- Smart placement can now be enabled for Pages within your Pages Project by going to Settings > Functions.
Stream
Multiple audio tracks now generally available
Stream supports adding multiple audio tracks to an existing video.
For more, refer to the documentation to get started.
Workers
- The new connect()method allows you to connect to any TCP-speaking services directly from your Workers. To learn more about other protocols supported on the Workers platform, visit the new Protocols documentation.
- We have added new native database integrations for popular serverless database providers, including Neon, PlanetScale, and Supabase. Native integrations automatically handle the process of creating a connection string and adding it as a Secret to your Worker.
- You can now also connect directly to databases over TCP from a Worker, starting with PostgreSQL. Support for PostgreSQL is based on the popular pgdriver, and allows you to connect to any PostgreSQL instance over TLS from a Worker directly.
- The R2 Migrator (Super Slurper), which automates the process of migrating from existing object storage providers to R2, is now Generally Available.
Workers
- Cursor, an experimental AI assistant, trained to answer questions about Cloudflare’s Developer Platform, is now available to preview! Cursor can answer questions about Workers and the Cloudflare Developer Platform, and is itself built on Workers. You can read more about Cursor in the announcement blog.
Workers
- The performance.now()andperformance.timeOriginAPIs can now be used in Cloudflare Workers. Just likeDate.now(), for security reasons time only advances after I/O.
Radar
Added IOS as an option for the OS parameter in all HTTP
- Added IOSas an option for the OS parameter in all HTTP endpoints ( example).
Workers
- The new nodeJsCompatModuletype can be used with a Worker bundle to emulate a Node.js environment. Common Node.js globals such asprocessandBufferwill be present, andrequire('...')can be used to load Node.js built-ins without thenode:specifier prefix.
- Fixed an issue where websocket connections would be disconnected when updating workers. Now, only websockets connected to Durable Object instances are disconnected by updates to that Durable Object’s code.
Workers
- The Web Crypto API now supports curves Ed25519 and X25519 defined in the Secure Curves specification.
- The global connectmethod has been moved to acloudflare:socketsmodule.
Stream
Player Enhancement Properties
Cloudflare Stream now supports player enhancement properties.
With player enhancements, you can modify your video player to incorporate elements of your branding, such as your logo, and customize additional options to present to your viewers.
For more, refer to the documentation to get started.
beacon.min.js
Reports additional LCP diagnostic information using web-vitals library’s attribution build.
Notifications
- Added Maintenance Notification Alerts.
DDoS protection
Network-layer ruleset - 2023-04-17
For more details, refer to the dedicated page for Network-layer ruleset - 2023-04-17.
Turnstile
- Added references to Turnstile Public API.
- Added references for [after-interactive-callback],[before-interactive-callback], and[unsupported-callback].
Workers
- No externally-visible changes this week.
Workers
- URL.canParse(...)is a new standard API for testing that an input string can be parsed successfully as a URL without the additional cost of creating and throwing an error.
- The Workers-specific IdentityTransformStreamandFixedLengthStreamclasses now support specifying ahighWaterMarkfor the writable-side that is used for backpressure signaling using the standardwriter.desiredSize/writer.readymechanisms.
beacon.min.js
Updated webpack configuration to output code in ECMAScript 3 (ES3) format.
R2
- GetBucket is now available for use through the Cloudflare API.
- Location hints can now be set when creating a bucket, both through the S3 API, and the dashboard.
Queues
Consumer concurrency (enabled)
Queue consumers will now automatically scale up based on the number of messages being written to the queue. To control or limit concurrency, you can explicitly define a max_concurrency for your consumer.
Workers
- Fixed a bug in Wrangler tail and live logs on the dashboard that prevented the Administrator Read-Only and Workers Tail Read roles from successfully tailing Workers.
beacon.min.js
Updated Google’s web-vitals library (version 3.1.1) and removed experimental server-timing header.
Pages
Git projects can now see files uploaded
- Files uploaded are now visible for Git projects, you can view them in the Cloudflare dashboard.
Stream
Limits for downloadable MP4s for live recordings
Previously, generating a download for a live recording exceeding four hours resulted in failure.
To fix the issue, now video downloads are only available for live recordings under four hours. Live recordings exceeding four hours can still be played but cannot be downloaded.
Pages
Notifications for Pages are now available
- Notifications for Pages events are now available in the Cloudflare dashboard. Events supported include:- Deployment started.
- Deployment succeeded.
- Deployment failed.
 
R2
- The ListParts API has been implemented and is available for use.
- HTTP2 is now enabled by default for new custom domains linked to R2 buckets.
- Object Lifecycles are now available for use.
- Bug fix: Requests to public buckets will now return the Content-Encodingheader for gzip files whenAccept-Encoding: gzipis used.
Queues
Consumer concurrency (upcoming)
Queue consumers will soon automatically scale up concurrently as a queues’ backlog grows in order to keep overall message processing latency down. Concurrency will be enabled on all existing queues by 2023-03-28.
To opt-out, or to configure a fixed maximum concurrency, set max_concurrency = 1 in your wrangler.toml file or via the queues dashboard.
To opt-in, you do not need to take any action: your consumer will begin to scale out as needed to keep up with your message backlog. It will scale back down as the backlog shrinks, and/or if a consumer starts to generate a higher rate of errors. To learn more about how consumers scale, refer to the consumer concurrency documentation.
Notifications
- Added Pages Alerts.
Workers
- No externally-visible changes.
Turnstile
- Added [execution]and[appearance].
Workers
- Workers Logpush now supports 300 characters per log line. This is an increase from the previous limit of 150 characters per line.
Notifications
- Added Brand Protection Alerts.
Queues
Explicit acknowledgement (new feature)
You can now acknowledge individual messages with a batch by calling .ack() on a message.
This allows you to mark a message as delivered as you process it within a batch, and avoids the entire batch from being redelivered if your consumer throws an error during batch processing. This can be particularly useful when you are calling external APIs, writing messages to a database, or otherwise performing non-idempotent actions on individual messages within a batch.
Queues
Higher per-queue throughput
The per-queue throughput limit has now been raised to 400 messages per second.
Turnstile
- Added the [turnstile.ready]callback.
Workers
- Fixed a bug where transferring large request bodies to a Durable Object was unexpectedly slow.
- Previously, an error would be thrown when trying to access unimplemented standard RequestandResponseproperties. Now those will be left asundefined.
Turnstile
- Added the [data-]languageparameter.
Workers
- The request.cfobject now includes two additional properties,tlsClientHelloLengthandtlsClientRandom.
R2
- R2 authentication tokens created via the R2 token page are now scoped to a single account by default.
Radar
Updated IPv6 calculation method
- IPv6 percentage started to be calculated as (IPv6 requests / requests for dual-stacked content), where as before it was calculated as (IPv6 requests / IPv4+IPv6 requests).
Workers
- Durable Objects can now use jurisdictions with idFromNamevia a new subnamespace API.
- V8 updated to 10.9.
Radar
Add new layer 3 dataset
- Added new Layer 3 data source and related endpoints.
- Updated Layer 3
timeseries endpoint
to support fetching both current and new data sources. For retro-compatibility
reasons, fetching the new data source requires sending the parameter metric=byteselse the current data source will be returned.
- Deprecated old Layer 3 endpoints TimeseriesGroups and Summary. Users should upgrade to newer endpoints.
Stream
Earlier detection (and rejection) of non-video uploads
Cloudflare Stream now detects non-video content on upload using the POST API and returns a 400 Bad Request HTTP error with code 10059.
Previously, if you or one of your users attempted to upload a file that is not a video (ex: an image), the request to upload would appear successful, but then fail to be encoded later on.
With this change, Stream responds to the upload request with an error, allowing you to give users immediate feedback if they attempt to upload non-video content.
Pages
API messaging update
Updated all API messaging to be more helpful.
Queues
sendBatch support
The JavaScript API for Queue producers now includes a sendBatch method which supports sending up to 100 messages at a time.
Queues
Increased per-account limits
Queues now allows developers to create up to 100 queues per account, up from the initial beta limit of 10 per account. This limit will continue to increase over time.
Turnstile
- POST /siteverifysupports JSON requests now.
Stream
Faster mp4 downloads of live recordings
Generating MP4 downloads of live stream recordings is now significantly faster. For more, refer to the docs.
R2
- Fix CORS preflight requests for the S3 API, which allows using the S3 SDK in the browser.
- Passing a range header to the getoperation in the R2 bindings API should now work as expected.
DDoS protection
Network-layer ruleset - 2022-12-02
For more details, refer to the dedicated page for Network-layer ruleset - 2022-12-02.
Pages
Ability to delete aliased deployments
- Aliased deployments can now be deleted. If using the API, you will need to add the query parameter force=true.
R2
- Requests with the header x-amz-acl: public-readare no longer rejected.
- Fixed issues with wildcard CORS rules and presigned URLs.
- Fixed an issue where ListObjectswould time out during delimited listing of unicode-normalized keys.
- S3 API’s PutBucketCorsnow rejects requests with unknown keys in the XML body.
- Signing additional headers no longer breaks CORS preflight requests for presigned URLs.
Stream
Multiple audio tracks (closed beta)
Stream now supports adding multiple audio tracks to an existing video upload. This allows you to:
- Provide viewers with audio tracks in multiple languages
- Provide dubbed audio tracks, or audio commentary tracks (ex: Director’s Commentary)
- Allow your users to customize the customize the audio mix, by providing separate audio tracks for music, speech or other audio tracks.
- Provide Audio Description tracks to ensure your content is accessible. ( WCAG 2.0 Guideline 1.2 1)
To request an invite to the beta, refer to this post.
Stream
VP9 support for WebRTC live streams (beta)
Cloudflare Stream now supports VP9 when streaming using WebRTC (WHIP), currently in beta.
R2
- Fixed a bug in ListObjectswherestartAfterwould skip over objects with keys that have numbers right after thestartAfterprefix.
- Add worker bindings for multipart uploads.
Pages
Deep linking to a Pages deployment
- You can now deep-link to a Pages deployment in the dashboard with :pages-deployment. An example would behttps://dash.cloudflare.com?to=/:account/pages/view/:pages-project/:pages-deployment.
Pages
Functions GA and other updates
- Pages functions are now GA. For more information, refer to the blog post.
- We also made the following updates to Functions:- Functions metrics are now available in the dashboard.
- Functions billing is now available.
- The Unbound usage model is now available for Functions.
- Secrets are now available.
- Functions tailing is now available via the dashboard or with Wrangler (wrangler pages deployment tail).
 
R2
- Unconditionally return HTTP 206 on ranged requests to match behavior of other S3 compatible implementations.
- Fixed a CORS bug where AllowedHeadersin the CORS config were being treated case-sensitively.
Pages
Service bindings now available in Functions
- Service bindings are now available in Functions. For more details, refer to the docs.
Turnstile
- Added retryandretry-intervalfor controlling retry behavior.
R2
- Copying multipart objects via CopyObjectis re-enabled.
- UploadPartCopyis re-enabled.
Stream
Reduced time to start WebRTC streaming and playback with Trickle ICE
Cloudflare Stream’s WHIP and WHEP implementations now support Trickle ICE, reducing the time it takes to initialize WebRTC connections, and increasing compatibility with WHIP and WHEP clients.
For more, refer to the docs.
Stream
Deprecating the ‘per-video’ Analytics API
The “per-video” analytics API is being deprecated. If you still use this API, you will need to switch to using the GraphQL Analytics API by February 1, 2023. After this date, the per-video analytics API will be no longer available.
The GraphQL Analytics API provides the same functionality and more, with additional filters and metrics, as well as the ability to fetch data about multiple videos in a single request. Queries are faster, more reliable, and built on a shared analytics system that you can use across many Cloudflare products.
For more about this change and how to migrate existing API queries, refer to this post and the GraphQL Analytics API docs.
Pages
Ansi color codes in build logs
Build log now supports ansi color codes.
Stream
Create an unlimited number of live inputs
Cloudflare Stream now has no limit on the number of live inputs you can create. Stream is designed to allow your end-users to go live — live inputs can be created quickly on-demand via a single API request for each of user of your platform or app.
For more on creating and managing live inputs, get started with the docs.
R2
- Multipart upload part sizes are always expected to be of the same size, but this enforcement is now done when you complete an upload instead of being done very time you upload a part.
- Fixed a performance issue where concurrent multipart part uploads would get rejected.
Turnstile
- Renamed the [data-]expired-callbackcallback to[data-]timeout-callback(called when the challenge times out).
- Added the [data-]expired-callbackcallback (called when the token expires).
R2
- Fixed ranged reads for multipart objects with part sizes unaligned to 64KiB.
Turnstile
- Added response-fieldandresponse-field-namefor controlling the input element created by Turnstile.
- Added option for changing the size of the Turnstile widget.
Stream
More accurate bandwidth estimates for live video playback
When playing live video, Cloudflare Stream now provides significantly more accurate estimates of the bandwidth needs of each quality level to client video players. This ensures that live video plays at the highest quality that viewers have adequate bandwidth to play.
As live video is streamed to Cloudflare, we transcode it to make it available to viewers at mulitple quality levels. During transcoding, we learn about the real bandwidth needs of each segment of video at each quality level, and use this to provide an estimate of the bandwidth requirements of each quality level the in HLS (.m3u8) and DASH (.mpd) manifests.
If a live stream contains content with low visual complexity, like a slideshow presentation, the bandwidth estimates provided in the HLS manifest will be lower, ensuring that the most viewers possible view the highest quality level, since it requires relatively little bandwidth. Conversely, if a live stream contains content with high visual complexity, like live sports with motion and camera panning, the bandwidth estimates provided in the HLS manifest will be higher, ensuring that viewers with inadequate bandwidth switch down to a lower quality level, and their playback does not buffer.
This change is particularly helpful if you’re building a platform or application that allows your end users to create their own live streams, where these end users have their own streaming software and hardware that you can’t control. Because this new functionality adapts based on the live video we receive, rather than just the configuration advertised by the broadcaster, even in cases where your end users’ settings are less than ideal, client video players will not receive excessively high estimates of bandwidth requirements, causing playback quality to decrease unnecessarily. Your end users don’t have to be OBS Studio experts in order to get high quality video playback.
No work is required on your end — this change applies to all live inputs, for all customers of Cloudflare Stream. For more, refer to the docs.
R2
- HeadBucketnow sets- x-amz-bucket-regionto- autoin the response.
beacon.min.js
Updated to report new metrics such as time to first byte (TTFB), interaction to next paint (INP), and first contentful paint (FCP). Additionally, it reports navigator.webdriver, server-timing header (experimental), and protocol info (nextHopProtocol).
Turnstile
- Added validation for action: /^[a-z0-9_-]{0,32}$/i
- Added validation for cData: /^[a-z0-9_-]{0,255}$/i
Turnstile
- Added turnstile.remove
R2
- Temporarily disabled UploadPartCopywhile we investigate an issue.
Pages
Deep linking to a Pages project
- You can now deep-link to a Pages project in the dashboard with :pages-project. An example would behttps://dash.cloudflare.com?to=/:account/pages/view/:pages-project.
Stream
AV1 Codec support for live streams and recordings (beta)
Cloudflare Stream now supports playback of live videos and live recordings using the AV1 codec, which uses 46% less bandwidth than H.264.
For more, read the blog post.
R2
- Fixed a CORS issue where Access-Control-Allow-Headerswas not being set for preflight requests.
R2
- Fixed a bug where CORS configuration was not being applied to S3 endpoint.
- No-longer render the Access-Control-Expose-Headersresponse header ifExposeHeaderis not defined.
- Public buckets will no-longer return the Content-Rangeresponse header unless the response is partial.
- Fixed CORS rendering for the S3 HeadObjectoperation.
- Fixed a bug where no matching CORS configuration could result in a 403response.
- Temporarily disable copying objects that were created with multipart uploads.
- Fixed a bug in the Workers bindings where an internal error was being returned for malformed ranged .getrequests.
R2
- CORS preflight responses and adding CORS headers for other responses is now implemented for S3 and public buckets. Currently, the only way to configure CORS is via the S3 API.
- Fixup for bindings list truncation to work more correctly when listing keys with custom metadata that have "or when some keys/values contain certain multi-byte UTF-8 values.
- The S3 GetObjectoperation now only returnsContent-Rangein response to a ranged request.
Stream
WebRTC live streaming and playback (beta)
Cloudflare Stream now supports live video streaming over WebRTC, with sub-second latency, to unlimited concurrent viewers.
For more, read the blog post or the get started with example code in the docs.
R2
- The R2 put()binding options can now be given anonlyIffield, similar toget(), that performs a conditional upload.
- The R2 delete()binding now supports deleting multiple keys at once.
- The R2 put()binding now supports user-specified SHA-1, SHA-256, SHA-384, SHA-512 checksums in options.
- User-specified object checksums will now be available in the R2 get()andhead()bindings response. MD5 is included by default for non-multipart uploaded objects.
Stream
Manually control when you start and stop simulcasting
You can now enable and disable individual live outputs via the API or Stream dashboard, allowing you to control precisely when you start and stop simulcasting to specific destinations like YouTube and Twitch. For more, read the docs.
Pages
Increased domain limits
Previously, all plans had a maximum of 10 custom domains per project.
Now, the limits are:
- Free: 100 custom domains.
- Pro: 250 custom domains.
- Business and Enterprise: 500 custom domains.
Pages
Support for _routes.json
- Pages now offers support for _routes.json. For more details, refer to the documentation.
R2
- The S3 CopyObjectoperation now includesx-amz-version-idandx-amz-copy-source-version-idin the response headers for consistency with other methods.
- The ETagfor multipart files uploaded until shortly after Open Beta uploaded now include the number of parts as a suffix.
Pages
Increased build log expiration time
Build log expiration time increased from 2 weeks to 1 year.
R2
- The S3 DeleteObjectsoperation no longer trims the space from around the keys before deleting. This would result in files with leading / trailing spaces not being able to be deleted. Additionally, if there was an object with the trimmed key that existed it would be deleted instead. The S3DeleteObjectoperation was not affected by this.
- Fixed presigned URL support for the S3 ListBucketsandListObjectsoperations.
Stream
Unique subdomain for your Stream Account
URLs in the Stream Dashboard and Stream API now use a subdomain specific to your Cloudflare Account: customer-{CODE}.cloudflarestream.com. This change allows you to:
- Use Content Security Policy (CSP) directives specific to your Stream subdomain, to ensure that only videos from your Cloudflare account can be played on your website. 
- Allowlist only your Stream account subdomain at the network-level to ensure that only videos from a specific Cloudflare account can be accessed on your network. 
No action is required from you, unless you use Content Security Policy (CSP) on your website. For more on CSP, read the docs.
R2
- Uploads will automatically infer the Content-Typebased on file body if one is not explicitly set in thePutObjectrequest. This functionality will come to multipart operations in the future.
Stream
Clip videos using the Stream API
You can now change the start and end times of a video uploaded to Cloudflare Stream. For more information, refer to Clip videos.
R2
- Fixed S3 conditionals to work properly when provided the LastModifieddate of the last upload, bindings fixes will come in the next release.
- If-Match/- If-None-Matchheaders now support arrays of ETags, Weak ETags and wildcard (- *) as per the HTTP standard and undocumented AWS S3 behavior.
Stream
Live inputs
The Live Inputs API now supports optional pagination, search, and filter parameters. For more information, refer to the Live Inputs API documentation.
R2
- Added dummy implementation of the following operation that mimics
the response that a basic AWS S3 bucket will return when first created: GetBucketAcl.
R2
- Added dummy implementations of the following operations that mimic the response that a basic AWS S3 bucket will return when first created: - GetBucketVersioning
- GetBucketLifecycleConfiguration
- GetBucketReplication
- GetBucketTagging
- GetObjectLockConfiguration
 
R2
- Fixed an S3 compatibility issue for error responses with MinIO .NET SDK and any other tooling that expects no xmlnsnamespace attribute on the top-levelErrortag.
- List continuation tokens prior to 2022-07-01 are no longer accepted and must be obtained again through a new listoperation.
- The list()binding will now correctly return a smaller limit if too much data would otherwise be returned (previously would return anInternal Error).
R2
- Improvements to 500s: we now convert errors, so things that were previously concurrency problems for some operations should now be TooMuchConcurrencyinstead ofInternalError. We’ve also reduced the rate of 500s through internal improvements.
- ListMultipartUploadcorrectly encodes the returned- Keyif the- encoding-typeis specified.
R2
- S3 XML documents sent to R2 that have an XML declaration are not rejected with 400 Bad Request/MalformedXML.
- Minor S3 XML compatibility fix impacting Arq Backup on Windows only (not the Mac version). Response now contains XML declaration tag prefix and the xmlns attribute is present on all top-level tags in the response.
- Beta ListMultipartUploadssupport.
R2
- Support the r2_list_honor_includecompat flag coming up in an upcoming runtime release (default behavior as of 2022-07-14 compat date). Without that compat flag/date, list will continue to function implicitly asinclude: ['httpMetadata', 'customMetadata']regardless of what you specify.
- cf-create-bucket-if-missingcan be set on a- PutObject/- CreateMultipartUploadrequest to implicitly create the bucket if it does not exist.
- Fix S3 compatibility with MinIO client spec non-compliant XML for publishing multipart uploads. Any leading and trailing quotes in CompleteMultipartUploadare now optional and ignored as it seems to be the actual non-standard behavior AWS implements.
Pages
Added support for .dev.vars in wrangler pages
Pages now supports .dev.vars in wrangler pages, which allows you to use use environmental variables during your local development without chaining --envs.
This functionality requires Wrangler v2.0.16 or higher.
R2
- Unsupported search parameters to ListObjects/ListObjectsV2are now rejected with501 Not Implemented.
- Fixes for Listing:- Fix listing behavior when the number of files within a folder exceeds the limit (you’d end up seeing a CommonPrefix for that large folder N times where N = number of children within the CommonPrefix / limit).
- Fix corner case where listing could cause objects with sharing the base name of a "folder" to be skipped.
- Fix listing over some files that shared a certain common prefix.
 
- DeleteObjectscan now handle 1000 objects at a time.
- S3 CreateBucketrequest can specifyx-amz-bucket-object-lock-enabledwith a value offalseand not have the requested rejected with aNotImplementederror. A value oftruewill continue to be rejected as R2 does not yet support object locks.
R2
- Fixed a regression for some clients when using an empty delimiter.
- Added support for S3 pre-signed URLs.
R2
- Fixed a regression in the S3 API UploadPartoperation whereTooMuchConcurrency&NoSuchUploaderrors were being returned asNoSuchBucket.
Pages
Added deltas to wrangler pages publish
Pages has added deltas to wrangler pages publish.
We now keep track of the files that make up each deployment and intelligently only upload the files that we have not seen. This means that similar subsequent deployments should only need to upload a minority of files and this will hopefully make uploads even faster.
This functionality requires Wrangler v2.0.11 or higher.
R2
- Fixed a bug with the S3 API ListObjectsV2operation not returning empty folder/s as common prefixes when using delimiters.
- The S3 API ListObjectsV2KeyCountparameter now correctly returns the sum of keys and common prefixes rather than just the keys.
- Invalid cursors for list operations no longer fail with an InternalErrorand now return the appropriate error message.
R2
- The ContinuationTokenfield is now correctly returned in the response if provided in a S3 APIListObjectsV2request.
- Fixed a bug where the S3 API AbortMultipartUploadoperation threw an error when called multiple times.
Pages
Added branch alias to PR comments
- PR comments for Pages previews now include the branch alias.
R2
- Fixed a bug where the S3 API’s PutObjector the.put()binding could fail but still show the bucket upload as successful.
- If conditional headers are provided to S3 API UploadObjectorCreateMultipartUploadoperations, and the object exists, a412 Precondition Failedstatus code will be returned if these checks are not met.
Stream
Picture-in-Picture support
The Stream Player now displays a button to activate Picture-in-Picture mode, if the viewer’s web browser supports the Picture-in-Picture API.
R2
- Fixed a bug when Accept-Encodingwas being used inSignedHeaderswhen sending requests to the S3 API would result in aSignatureDoesNotMatchresponse.
R2
- Fixed a bug where requests to the S3 API were not handling non-encoded parameters used for the authorization signature.
- Fixed a bug where requests to the S3 API where number-like keys were being parsed as numbers instead of strings.
R2
- Add support for S3 virtual-hosted style paths, such as <BUCKET>.<ACCOUNT_ID>.r2.cloudflarestorage.cominstead of path-based routing (<ACCOUNT_ID>.r2.cloudflarestorage.com/<BUCKET>).
- Implemented GetBucketLocationfor compatibility with external tools, this will always return aLocationConstraintofauto.
Stream
Creator ID property
During or after uploading a video to Stream, you can now specify a value for a new field, creator. This field can be used to identify the creator of the video content, linking the way you identify your users or creators to videos in your Stream account. For more, read the blog post.
R2
- S3 API GetObjectranges are now inclusive (bytes=0-0will correctly return the first byte).
- S3 API GetObjectpartial reads return the proper206 Partial Contentresponse code.
- Copying from a non-existent key (or from a non-existent bucket) to another bucket now returns the proper NoSuchKey/NoSuchBucketresponse.
- The S3 API now returns the proper Content-Type: application/xmlresponse header on relevant endpoints.
- Multipart uploads now have a -Nsuffix on the etag representing the number of parts the file was published with.
- UploadPartand- UploadPartCopynow return proper error messages, such as- TooMuchConcurrencyor- NoSuchUpload, instead of ‘internal error’.
- UploadPartcan now be sent a 0-length part.
R2
- When using the S3 API, an empty string and us-east-1will now alias to theautoregion for compatibility with external tools.
- GetBucketEncryption,- PutBucketEncryptionand- DeleteBucketEncrypotionare now supported (the only supported value currently is- AES256).
- Unsupported operations are explicitly rejected as unimplemented rather than implicitly converting them into ListObjectsV2/PutBucket/DeleteBucketrespectively.
- S3 API CompleteMultipartUploadsrequests are now properly escaped.
R2
- Pagination cursors are no longer returned when the keys in a bucket is the same as the MaxKeysargument.
- The S3 API ListBucketsoperation now acceptscf-max-keys,cf-start-afterandcf-continuation-tokenheaders behave the same as the respective URL parameters.
- The S3 API ListBucketsandListObjectsendpoints now allowper_pageto be 0.
- The S3 API CopyObjectsource parameter now requires a leading slash.
- The S3 API CopyObjectoperation now returns aNoSuchBucketerror when copying to a non-existent bucket instead of an internal error.
- Enforce the requirement for autoin SigV4 signing and theCreateBucketLocationConstraintparameter.
- The S3 API CreateBucketoperation now returns the properlocationresponse header.
R2
- The S3 API now supports unchunked signed payloads.
- Fixed .put()for the Workers R2 bindings.
- Fixed a regression where key names were not properly decoded when using the S3 API.
- Fixed a bug where deleting an object and then another object which is a prefix of the first could result in errors.
- The S3 API DeleteObjectsoperation no longer returns an error even though an object has been deleted in some cases.
- Fixed a bug where startAfterandcontinuationTokenwere not working in list operations.
- The S3 API ListObjectsoperation now correctly rendersPrefix,Delimiter,StartAfterandMaxKeysin the response.
- The S3 API ListObjectsV2now correctly honors theencoding-typeparameter.
- The S3 API PutObjectoperation now works withPOSTrequests fors3cmdcompatibility.
R2
- The S3 API DeleteObjectsrequest now properly returns aMalformedXMLerror instead ofInternalErrorwhen provided with more than 128 keys.
Stream
Analytics panel in Stream Dashboard
The Stream Dashboard now has an analytics panel that shows the number of minutes of both live and recorded video delivered. This view can be filtered by Creator ID, Video UID, and Country. For more in-depth analytics data, refer to the bulk analytics documentation.
Stream
Custom letterbox color configuration option for Stream Player
The Stream Player can now be configured to use a custom letterbox color, displayed around the video (’letterboxing’ or ‘pillarboxing’) when the video’s aspect ratio does not match the player’s aspect ratio. Refer to the documentation on configuring the Stream Player here.
Stream
Support for SRT live streaming protocol
Cloudflare Stream now supports the SRT live streaming protocol. SRT is a modern, actively maintained streaming video protocol that delivers lower latency, and better resilience against unpredictable network conditions. SRT supports newer video codecs and makes it easier to use accessibility features such as captions and multiple audio tracks.
For more, read the blog post.
Stream
Faster video quality switching in Stream Player
When viewers manually change the resolution of video they want to receive in the Stream Player, this change now happens immediately, rather than once the existing resolution playback buffer has finished playing.
Stream
Volume and playback controls accessible during playback of VAST Ads
When viewing ads in the VAST format in the Stream Player, viewers can now manually start and stop the video, or control the volume.
Stream
DASH and HLS manifest URLs accessible in Stream Dashboard
If you choose to use a third-party player with Cloudflare Stream, you can now easily access HLS and DASH manifest URLs from within the Stream Dashboard. For more about using Stream with third-party players, read the docs here.
Stream
Input health status in the Stream Dashboard
When a live input is connected, the Stream Dashboard now displays technical details about the connection, which can be used to debug configuration issues.
Stream
Live viewer count in the Stream Player
The Stream Player now shows the total number of people currently watching a video live.
Stream
Webhook notifications for live stream connections events
You can now configure Stream to send webhooks each time a live stream connects and disconnects. For more information, refer to the Webhooks documentation.
beacon.min.js
Improved site filtering.
Stream
24/7 Live streaming support
You can now use Cloudflare Stream for 24/7 live streaming.
Stream
Persistent Live Stream IDs
You can now start and stop live broadcasts without having to provide a new video UID to the Stream Player (or your own player) each time the stream starts and stops. Read the docs.
beacon.min.js
When using the automatic installation feature of the JavaScript Beacon (available only to customers proxied through Cloudflare - also known as orange-clouded customers), Subresource Integrity (SRI) is now enabled by default. SRI is a security feature that enables browsers to verify that resources they fetch are delivered without unexpected manipulation.
Stream
MP4 video file downloads for live videos
Once a live video has ended and been recorded, you can now give viewers the option to download an MP4 video file of the live recording. For more, read the docs here.
Stream
Serverless Live Streaming
Stream now supports live video content! For more information, read the blog post and get started by reading the docs.
beacon.min.js
Improved to report debugging information for Core Web Vitals.
Stream
Thumbnail previews in Stream Player seek bar
The Stream Player now displays preview images when viewers hover their mouse over the seek bar, making it easier to skip to a specific part of a video.
Stream
MP4 video file downloads (GA)
All Cloudflare Stream customers can now give viewers the option to download videos uploaded to Stream as an MP4 video file. For more, read the docs here.
Stream
Stream Connect (open beta)
You can now opt-in to the Stream Connect beta, and use Cloudflare Stream to restream live video to any platform that accepts RTMPS input, including Facebook, YouTube and Twitch.
Stream
Simplified signed URL token generation
You can now obtain a signed URL token via a single API request, without needing to generate signed tokens in your own application. Read the docs.
Stream
Stream Connect (closed beta)
You can now use Cloudflare Stream to restream or simulcast live video to any platform that accepts RTMPS input, including Facebook, YouTube and Twitch.
beacon.min.js
startsWith function replaced with indexOf function, which prevents rendering if multiple beacon scripts are loaded.
beacon.min.js
Reporting endpoint changed from /cdn-cgi/beacon/performance to /cdn-cgi/rum (for Browser Insights only).
Stream
MP4 video file downloads (beta)
You can now give your viewers the option to download videos uploaded to Stream as an MP4 video file. For more, read the docs here.
Stream
Picture quality improvements
Cloudflare Stream now encodes videos with fewer artifacts, resulting in improved video quality for your viewers.
Stream
Improved client bandwidth hints for third-party video players
If you use Cloudflare Stream with a third party player, and send the clientBandwidthHint parameter in requests to fetch video manifests, Cloudflare Stream now selects the ideal resolution to provide to your client player more intelligently. This ensures your viewers receive the ideal resolution for their network connection.
Stream
Improved client bandwidth hints for third-party video players
If you use Cloudflare Stream with a third party player, and send the clientBandwidthHint parameter in requests to fetch video manifests, Cloudflare Stream now selects the ideal resolution to provide to your client player more intelligently. This ensures your viewers receive the ideal resolution for their network connection.
Stream
Less bandwidth, identical video quality
Cloudflare Stream now delivers video using 3-10x less bandwidth, with no reduction in quality. This ensures faster playback for your viewers with less buffering, particularly when viewers have slower network connections.
Stream
Stream Player 2.0 (preview)
A brand new version of the Stream Player is now available for preview. New features include:
- Unified controls across desktop and mobile devices
- Keyboard shortcuts
- Intelligent mouse cursor interactions with player controls
- Phased out support for Internet Explorer 11
For more, refer to this post on the Cloudflare Community Forum.
Stream
Faster video encoding
Videos uploaded to Cloudflare Stream are now available to view 5x sooner, reducing the time your users wait between uploading and viewing videos.
Stream
Removed weekly upload limit, increased max video upload size
You can now upload videos up to 30GB in size to Cloudflare Stream and also now upload an unlimited number of videos to Cloudflare Stream each week
Stream
Tus support for direct creator uploads
You can now use the tus protocol when allowing creators (your end users) to upload their own videos directly to Cloudflare Stream.
In addition, all uploads to Cloudflare Stream made using tus are now faster and more reliable as part of this change.
Stream
Multiple audio track mixdown
Videos with multiple audio tracks (ex: 5.1 surround sound) are now mixed down to stereo when uploaded to Stream. The resulting video, with stereo audio, is now playable in the Stream Player.
Stream
Storage limit notifications
Cloudflare now emails you if your account is using 75% or more of your prepaid video storage, so that you can take action and plan ahead.
- © 2024 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark
- Cookie Settings