Skip to content

Changelog

New updates and improvements at Cloudflare.

Create and deploy Workers from Git repositories

Import repo or choose template

You can now create a Worker by:

  • Importing a Git repository: Choose an existing Git repo on your GitHub/GitLab account and set up Workers Builds to deploy your Worker.
  • Deploying a template with Git: Choose from a brand new selection of production ready examples ↗︎ to help you get started with popular frameworks like Astro ↗︎, Remix ↗︎ and Next ↗︎ or build stateful applications with Cloudflare resources like D1 databases, Workers AI or Durable Objects! When you're ready to deploy, Cloudflare will set up your project by cloning the template to your GitHub/GitLab account, provisioning any required resources and deploying your Worker.

With every push to your chosen branch, Cloudflare will automatically build and deploy your Worker.

To get started, go to the Workers dashboard ↗︎.

These new features are available today in the Cloudflare dashboard to a subset of Cloudflare customers, and will be coming to all customers in the next few weeks. Don't see it in your dashboard, but want early access? Add your Cloudflare Account ID to this form ↗︎.

Block files that are password-protected, compressed, or otherwise unscannable.

Gateway HTTP policies can now block files that are password-protected, compressed, or otherwise unscannable.

These unscannable files are now matched with the Download and Upload File Types traffic selectors for HTTP policies:

  • Password-protected Microsoft Office document
  • Password-protected PDF
  • Password-protected ZIP archive
  • Unscannable ZIP archive

To get started inspecting and modifying behavior based on these and other rules, refer to HTTP filtering.

Revamped Workers Metrics

We've revamped the Workers Metrics dashboard ↗︎.

Workers Metrics dashboard

Now you can easily compare metrics across Worker versions, understand the current state of a gradual deployment, and review key Workers metrics in a single view. This new interface enables you to:

  • Drag-and-select using a graphical timepicker for precise metric selection.
Workers Metrics graphical timepicker
  • Use histograms to visualize cumulative metrics, allowing you to bucket and compare rates over time.
  • Focus on Worker versions by directly interacting with the version numbers in the legend.
Workers Metrics legend selector
  • Monitor and compare active gradual deployments.
  • Track error rates across versions with grouping both by version and by invocation status.
  • Measure how Smart Placement improves request duration.

Learn more about metrics.

Transform HTML quickly with streaming content

You can now transform HTML elements with streamed content using HTMLRewriter.

Methods like replace, append, and prepend now accept Response and ReadableStream values as Content.

This can be helpful in a variety of situations. For instance, you may have a Worker in front of an origin, and want to replace an element with content from a different source. Prior to this change, you would have to load all of the content from the upstream URL and convert it into a string before replacing the element. This slowed down overall response times.

Now, you can pass the Response object directly into the replace method, and HTMLRewriter will immediately start replacing the content as it is streamed in. This makes responses faster.

index.jsjs
class ElementRewriter {
	async element(element) {
		// able to replace elements while streaming content
		// the fetched body is not buffered into memory as part
		// of the replace
		let res = await fetch("https://upstream-content-provider.example");
		element.replace(res);
	}
}

export default {
	async fetch(request, env, ctx) {
		let response = await fetch("https://site-to-replace.com");
		return new HTMLRewriter()
			.on("[data-to-replace]", new ElementRewriter())
			.transform(response);
	},
};
index.tsts
class ElementRewriter {
	async element(element: any) {
		// able to replace elements while streaming content
		// the fetched body is not buffered into memory as part
		// of the replace
		let res = await fetch('https://upstream-content-provider.example');
		element.replace(res);
	}
}

export default {
	async fetch(request, env, ctx): Promise<Response> {
		let response = await fetch('https://site-to-replace.com');
		return new HTMLRewriter().on('[data-to-replace]', new ElementRewriter()).transform(response);
	},
} satisfies ExportedHandler<Env>;

For more information, see the HTMLRewriter documentation.

Support for Node.js DNS, Net, and Timer APIs in Workers

When using a Worker with the nodejs_compat compatibility flag enabled, you can now use the following Node.js APIs:

node:net

You can use node:net ↗︎ to create a direct connection to servers via a TCP sockets with net.Socket ↗︎.

index.jsjs
import net from "node:net";

const exampleIP = "127.0.0.1";

export default {
	async fetch(req) {
		const socket = new net.Socket();
		socket.connect(4000, exampleIP, function () {
			console.log("Connected");
		});

		socket.write("Hello, Server!");
		socket.end();

		return new Response("Wrote to server", { status: 200 });
	},
};
index.tsts
import net from "node:net";

const exampleIP = "127.0.0.1";

export default {
  async fetch(req): Promise<Response> {
    const socket = new net.Socket();
    socket.connect(4000, exampleIP, function () {
      console.log("Connected");
    });

    socket.write("Hello, Server!");
    socket.end();

    return new Response("Wrote to server", { status: 200 });
  },
} satisfies ExportedHandler;

Additionally, you can now use other APIs including net.BlockList ↗︎ and net.SocketAddress ↗︎.

Note that net.Server ↗︎ is not supported.

node:dns

You can use node:dns ↗︎ for name resolution via DNS over HTTPS using Cloudflare DNS ↗︎ at 1.1.1.1.

index.jsjs
import dns from "node:dns";

let response = await dns.promises.resolve4("cloudflare.com", "NS");
index.tsts
import dns from 'node:dns';

let response = await dns.promises.resolve4('cloudflare.com', 'NS');

All node:dns functions are available, except lookup, lookupService, and resolve which throw "Not implemented" errors when called.

node:timers

You can use node:timers ↗︎ to schedule functions to be called at some future period of time.

This includes setTimeout ↗︎ for calling a function after a delay, setInterval ↗︎ for calling a function repeatedly, and setImmediate ↗︎ for calling a function in the next iteration of the event loop.

index.jsjs
import timers from "node:timers";

console.log("first");
timers.setTimeout(() => {
	console.log("last");
}, 10);

timers.setTimeout(() => {
	console.log("next");
});
index.tsts
import timers from "node:timers";

console.log("first");
timers.setTimeout(() => {
  console.log("last");
}, 10);

timers.setTimeout(() => {
  console.log("next");
});

Faster Workers Builds with Build Caching and Watch Paths

Build caching settingsBuild watch path settings

Workers Builds, the integrated CI/CD system for Workers (currently in beta), now lets you cache artifacts across builds, speeding up build jobs by eliminating repeated work, such as downloading dependencies at the start of each build.

  • Build Caching: Cache dependencies and build outputs between builds with a shared project-wide cache, ensuring faster builds for the entire team.

  • Build Watch Paths: Define paths to include or exclude from the build process, ideal for monorepos to target only the files that need to be rebuilt per Workers project.

To get started, select your Worker on the Cloudflare dashboard ↗︎ then go to Settings > Builds, and connect a GitHub or GitLab repository. Once connected, you'll see options to configure Build Caching and Build Watch Paths.

Escalate user submissions

After you triage your users' submissions (that are machine reviewed), you can now escalate them to our team for reclassification (which are instead human reviewed). User submissions from the submission alias, PhishNet, and our API can all be escalated.

Escalate

From Reclassifications, go to User submissions. Select the three dots next to any of the user submissions, then select Escalate to create a team request for reclassification. The Cloudflare dashboard will then show you the submissions on the Team Submissions tab.

Refer to User submissions to learn more about this feature.

This feature is available across these Email security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Increased transparency for phishing email submissions

You now have more transparency about team and user submissions for phishing emails through a Reclassification tab in the Zero Trust dashboard.

Reclassifications happen when users or admins submit a phish to Email security. Cloudflare reviews and - in some cases - reclassifies these emails based on improvements to our machine learning models.

This new tab increases your visibility into this process, allowing you to view what submissions you have made and what the outcomes of those submissions are.

Use the Reclassification area to review submitted phishing emails

Establish BGP peering over Direct CNI circuits

Magic WAN and Magic Transit customers can use the Cloudflare dashboard to configure and manage BGP peering between their networks and their Magic routing table when using a Direct CNI on-ramp.

Using BGP peering allows customers to:

  • Automate the process of adding or removing networks and subnets.
  • Take advantage of failure detection and session recovery features.

With this functionality, customers can:

  • Establish an eBGP session between their devices and the Magic WAN / Magic Transit service when connected via CNI.
  • Secure the session by MD5 authentication to prevent misconfigurations.
  • Exchange routes dynamically between their devices and their Magic routing table.

Refer to Magic WAN BGP peering or Magic Transit BGP peering to learn more about this feature and how to set it up.

Generate customized terraform files for building cloud network on-ramps

You can now generate customized terraform files for building cloud network on-ramps to Magic WAN.

Magic Cloud can scan and discover existing network resources and generate the required terraform files to automate cloud resource deployment using their existing infrastructure-as-code workflows for cloud automation.

You might want to do this to:

  • Review the proposed configuration for an on-ramp before deploying it with Cloudflare.
  • Deploy the on-ramp using your own infrastructure-as-code pipeline instead of deploying it with Cloudflare.

For more details, refer to Set up with Terraform.

Find security misconfigurations in your AWS cloud environment

You can now use CASB to find security misconfigurations in your AWS cloud environment using Data Loss Prevention.

You can also connect your AWS compute account to extract and scan your S3 buckets for sensitive data while avoiding egress fees. CASB will scan any objects that exist in the bucket at the time of configuration.

To connect a compute account to your AWS integration:

  1. In Cloudflare One ↗︎, go to Cloud & SaaS findings > Integrations.
  2. Find and select your AWS integration.
  3. Select Open connection instructions.
  4. Follow the instructions provided to connect a new compute account.
  5. Select Refresh.

Improved non-English keyboard support

You can now type in languages that use diacritics (like á or ç) and character-based scripts (such as Chinese, Japanese, and Korean) directly within the remote browser. The isolated browser now properly recognizes non-English keyboard input, eliminating the need to copy and paste content from a local browser or device.

Bypass caching for subrequests made from Cloudflare Workers, with Request.cache

You can now use the cache property of the Request interface to bypass Cloudflare's cache when making subrequests from Cloudflare Workers, by setting its value to no-store.

index.jsjs
export default {
	async fetch(req, env, ctx) {
		const request = new Request("https://cloudflare.com", {
			cache: "no-store",
		});
		const response = await fetch(request);
		return response;
	},
};
index.tsts
export default {
  async fetch(req, env, ctx): Promise<Response> {
		const request = new Request("https://cloudflare.com", { cache: 'no-store'});
		const response = await fetch(request);
    return response;
  }
} satisfies ExportedHandler<Environment>

When you set the value to no-store on a subrequest made from a Worker, the Cloudflare Workers runtime will not check whether a match exists in the cache, and not add the response to the cache, even if the response includes directives in the Cache-Control HTTP header that otherwise indicate that the response is cacheable.

This increases compatibility with NPM packages and JavaScript frameworks that rely on setting the cache property, which is a cross-platform standard part of the Request interface. Previously, if you set the cache property on Request, the Workers runtime threw an exception.

If you've tried to use @planetscale/database, redis-js, stytch-node, supabase, axiom-js or have seen the error message The cache field on RequestInitializerDict is not implemented in fetch — you should try again, making sure that the Compatibility Date of your Worker is set to on or after 2024-11-11, or the cache_option_enabled compatibility flag is enabled for your Worker.

Use Logpush for Email security user actions

You can now send user action logs for Email security to an endpoint of your choice with Cloudflare Logpush.

Filter logs matching specific criteria you have set or select from multiple fields you want to send. For all users, we will log the date and time, user ID, IP address, details about the message they accessed, and what actions they took.

When creating a new Logpush job, remember to select Audit logs as the dataset and filter by:

  • Field: "ResourceType"
  • Operator: "starts with"
  • Value: "email_security".
Logpush-user-actions

For more information, refer to Enable user action logs.

This feature is available across all Email security packages:

  • Enterprise
  • Enterprise + PhishGuard

Eliminate long-lived credentials and enhance SSH security with Cloudflare Access for Infrastructure

Organizations can now eliminate long-lived credentials from their SSH setup and enable strong multi-factor authentication for SSH access, similar to other Access applications, all while generating access and command logs.

SSH with Access for Infrastructure uses short-lived SSH certificates from Cloudflare, eliminating SSH key management and reducing the security risks associated with lost or stolen keys. It also leverages a common deployment model for Cloudflare One customers: WARP-to-Tunnel.

SSH with Access for Infrastructure enables you to:

  • Author fine-grained policy to control who may access your SSH servers, including specific ports, protocols, and SSH users.
  • Monitor infrastructure access with Access and SSH command logs, supporting regulatory compliance and providing visibility in case of security breach.
  • Preserve your end users' workflows. SSH with Access for Infrastructure supports native SSH clients and does not require any modifications to users’ SSH configs.
Example of an infrastructure Access application

To get started, refer to SSH with Access for Infrastructure.

Exchange user risk scores with Okta

Beyond the controls in Zero Trust, you can now exchange user risk scores with Okta to inform SSO-level policies.

First, configure Cloudflare One to send user risk scores to Okta.

  1. Set up the Okta SSO integration.
  2. In the Cloudflare dashboard ↗︎, go to Zero Trust > Integrations > Identity providers.
  3. In Your identity providers, locate your Okta integration and select Edit.
  4. Turn on Send risk score to Okta.
  5. Select Save.
  6. Upon saving, Cloudflare One will display the well-known URL for your organization. Copy the value.

Next, configure Okta to receive your risk scores.

  1. On your Okta admin dashboard, go to Security > Device Integrations.
  2. Go to Receive shared signals, then select Create stream.
  3. Name your integration. In Set up integration with, choose Well-known URL.
  4. In Well-known URL, enter the well-known URL value provided by Cloudflare One.
  5. Select Create.