Streamline: custom video pipelines with Cloudflare Stream and Workers

Cloudflare Stream is a powerful broadcasting platform that, for many of our customers, just works. But what if you wanted to render dynamic annotations on a livestream or create an alternate version of a hosted video with burned-in subtitles? You would need to run a custom video pipeline.

Today, we’re releasing a new developer playground, Streamline, that demonstrates how you can build a system to deliver these bespoke video experiences on Cloudflare’s Developer Platform. We’ll walk you through how Streamline leverages Workers, Containers, and several media protocols to modify video — and immediately publish that output as livestream or new hosted video. You’ll also have the opportunity to try it for your projects.

A processing pipeline needs a durable, long-running environment that can run specialized, compiled code with predictable memory and CPU capacity. Video streams can run for minutes or hours, so the media process needs a lifecycle independent of the request that started it. An application should be able to start a pipeline, send its input, inspect it, and stop it without needing to keep a single request open for the entire duration.

Cloudflare provides the primitives we need. Containers are long-lived runtimes suitable for media processing. Durable Objects Continue reading

HIPAA Wasn’t Written for AI Agents. It Applies to Them Anyway

In short, healthcare is adopting AI agents faster than almost any other industry. More than 85% of Epic’s customers already use Epic AI, Epic’s Agent Factory will let every health system build agents of its own from 2027, and 43% of health systems were piloting agentic AI at the start of this year. Every one of those agents runs next to Protected Health Information (PHI), and PHI comes with rules that were not written for autonomous software but land on it anyway: minimum necessary access, audit controls, business associate agreements, a 60-day breach clock. This post maps those rules onto what agent infrastructure must provide (identity, per-request authorization, live inventory, an audit trail across every hop), then shows where Tigera Lynx fits and what it does not do. It is written for the platform and security leaders who will be asked to produce the record.

Healthcare was supposed to be the cautious one. Regulated to the bone, allergic to unvetted vendors, still running a fax machine somewhere in the basement. Instead, it is adopting AI agents faster than almost anyone.

At HIMSS in March 2026, Epic previewed Agent Factory, a visual builder for health systems to create, customize, and Continue reading

Introducing Web Search API via AI Gateway

Fun fact: when you use an agent and it needs to fetch a live web page, the agent usually just guesses the URL of the page and then makes a tool call to curl it. This is why you’ll sometimes see web fetches come back with a 404 Not Found, which happens if the agent incorrectly guesses the URL of that information. As you can imagine, it’s not super efficient to randomly guess URLs all the time.

There is a better way. What if your agent can actually browse the Internet, just like how humans start with a search engine query when we’re looking for information? This is what web search is designed to do — it enables agents to search for relevant data on the Internet and grounds an agent’s responses based on live information.

Today, we’re announcing Cloudflare’s partnership with web search providers to bring you grounded intelligence via AI Gateway. We’re kicking off this launch with our partners from Ceramic.ai, Exa, and Linkup.

What can I do with the Web Search API?

AI models are only as good as the context you feed them. Models are typically trained and then frozen at a point in time, operating only on Continue reading

8 major updates to Cloudflare Observability

Today, we’re launching eight major updates that bring your logs, traces, analytics, alerts, dashboards, and exporting into one observability platform, with simpler and more predictable pricing.

Here's what's launching:

One observability platform for all of Cloudflare

Understanding an issue often requires data from more than one Cloudflare product. A spike in 5xx responses could come from a Worker, from your origin, or from Cloudflare failing to connect to your origin globally or regionally. But investigating it today requires knowing which product owns each signal and how to query it.

Observability should be a platform-wide capability: it should reflect how applications actually behave and give you the complete context needed to resolve an issue. Over the coming months, you’ll see more Cloudflare products, datasets, and workflows become part of Continue reading

Introducing Cloudflare Traces: follow requests through our entire platform

Today, we’re introducing Cloudflare Traces in open beta, extending automatic tracing beyond Workers to the rest of the request path. In one trace, you can see supported security rules, transformations, cache decisions, routing, Worker execution, and origin handling, then continue that trace through services running on Cloudflare, at your origin, or elsewhere in your stack. This is a long-term investment in OpenTelemetry and in making Cloudflare the most observable part of your stack.

You can now:

You can enable tracing in the Cloudflare dashboard on any domain or let your agent set up for you:

Updates on our pledge to make Cloudflare features accessible to everyone

A year ago, Cloudflare CTO Dane Knecht announced our intention to make every Cloudflare feature available to everyone. Cloudflare launched an Enterprise tier years ago when larger customers came to us looking for procurement options beyond a credit card, like invoices, custom contracts, and dedicated support. Those offerings met a customer need but over time, a two-tier system developed where some of our most advanced and powerful features were only available to Enterprise customers. Our goal was to close that gap.

Today, teams of every size use Cloudflare, from Fortune 100 enterprises to small businesses, open-source projects, and individuals. Across the platform, we’re committed to ensuring that every user or team can make use of all of Cloudflare’s capabilities in a way that helps their organization thrive.

The underlying philosophy is that Cloudflare should offer products suitable for our most demanding customers — and make those capabilities available to everyone. Large or small, every customer would prefer not to have to call support. Building products that are easy to buy, configure, and consume means more of our products in use and a step closer to a better Internet for everybody.

Every generally available (GA) feature we launched this week that Continue reading

Announcing Cloudflare OHTTP Gateway – expanding access to Cloudflare’s privacy-preserving infrastructure

Today, end users carry too much of the burden of online privacy. To avoid third-party trackers or targeted ads, users are instructed to use a VPN, disable cookies, or install adblockers. Meanwhile, some app developers end up knowing more about their users than they’d care to: a typical client-server exchange creates a trail of user data, like the client’s IP address or TLS fingerprint. This level of visibility can be a burden.

That’s why Cloudflare builds infrastructure that helps developers bake privacy into their apps. Oblivious HTTP (OHTTP) is an IETF standard designed to enable app backends to receive HTTP requests without seeing user IP addresses.

This fall, we’re launching the Cloudflare OHTTP Gateway. Customers will be able to enable our new OHTTP Gateway as a paid add-on to their zone and start receiving OHTTP traffic with just a few clicks. Register through our form to join our waitlist. Read on to learn more.

Expanding our OHTTP product suite

With OHTTP, requests travel through two independently-operated hops: a relay and a gateway. An OHTTP relay blindly forwards encrypted requests in order to hide client identifiers from app servers. An OHTTP gateway performs the cryptographic work of decapsulating encrypted requests and encapsulating responses Continue reading

Follow the thread: a new dashboard to investigate account abuse

Traditionally, preventing online fraud relied on point-in-time proof of identity: enter the correct password, complete a biometric verification, or pass a liveness check, and gain access. To defeat these controls, fraudsters had to steal credentials and other identity evidence from a real user, which was difficult to execute and scale. Today, widespread access to AI enables fraudsters to fabricate or imitate legitimate identities by combining exposed credentials with synthetic media designed to evade identity verification. Consequently, identity checks are no longer sufficient as they capture a moment in time. Even when someone passes a check, it does not mean the account itself can be trusted.

One convincing interaction can be faked. A consistent pattern of legitimate behavior is much harder to manufacture. Modern fraud prevention must move beyond stateless decisions toward a stateful trust model. Traditional identity verification asks, “Can this person pass the check right now?” A stateful approach additionally asks, “Does it fit what we know about this account and its established behavior?” At Cloudflare, trust is continually earned and reassessed at each interaction against historical behavioral, network, and device patterns.

Cloudflare’s Account Abuse Protection (AAP) creates stateful account overviews to help website owners detect and investigate abuse across Continue reading

Protected Quick Tunnels: simple accountless authentication for your next dev project

We launched Quick Tunnels in 2021 to give developers an easy way to share their latest service, application, or project running in their local development environment. A lot has changed since then, but the core use case remains the same.

Your coding agent has just finished the feature. The dev server is up on localhost:5173, and before you ask, the agent offers to let you try it on your phone. It runs one command and hands you a link:

That command starts a Quick Tunnel. cloudflared, Cloudflare's lightweight connector, publishes your local service at a random trycloudflare.com URL. No account, no domain, no cost. Agents now use Quick Tunnels for the same reason people do: they are the shortest path from a local port to a URL.

The catch has always been the same. Anyone with the link can open it.

Starting with cloudflared 2026.9.3, you can add --allowed-mail to the command, and your Quick Tunnel only lets in the email addresses and domains you choose. Visitors prove they own one of those addresses with a one-time PIN from Cloudflare Access. Nobody, on either side, needs a Cloudflare account.

Agents made Quick Tunnels more popular Continue reading

Building for good: How civil society organizations are automating on Cloudflare

Tracking how governments target dissidents living in exile. Helping people in crisis find mental health support. Advocating for legislation that protects free expression online. These are a few examples of how some of the world's leading organizations are building the future of non-profit work with Cloudflare.

AI is changing how people do their work. The goal of Cloudflare Impact is to help ensure that non-profit organizations are among the first to benefit. Today, we’re sharing what dozens of civil society organizations have built using our developer services with more than $7.5 million of Cloudflare credits. These stories show what is possible when AI applications are accessible, secure, and affordable to build and run.

From "keep us secure" to "help us build"

We believe a better Internet is one that allows people to express themselves online and access a diverse range of viewpoints. A key part of Cloudflare's mission has been making security services available for everyone and helping ensure that individuals and organizations working for the public interest are not forced offline by those more powerful. Today, Project Galileo, which provides free cybersecurity services to civil society organizations, protects more than 3,400 domains across more than 120 countries.

Through these Continue reading

2026 Birthday week: network performance update

Cloudflare is now the fastest provider in 74% of the 1,000 largest networks around the world, up from 60% in April 2026. This huge improvement matters because every millisecond affects how quickly users can reach the applications, APIs, and websites they rely on. In this Birthday Week performance update, we’ll review how we get our measurements, introduce a new measurement methodology using Cloudflare Challenge Pages, and discuss where these improvements have had the biggest impact for customers.

Cloudflare is fastest in 74% of top networks

In August, Cloudflare was the fastest provider in 74% of top networks, up 14 percentage points from our last update during Agents Week in April. The figure below shows the countries where Cloudflare is the fastest provider.

We improved from 60% to 74% by becoming the fastest provider in an additional 150 networks out of that top 1,000, and there are 38 additional countries where Cloudflare now ranks as the fastest. We measure this by looking at the fastest provider for users on the networks serving the largest number of users in each country.

The graphic below shows countries where Cloudflare has become the fastest provider across those networks since April.

Here you see the number Continue reading

Hedge 321: Sockets

There are many “unsung technologies” in the Internet. While we often think of TCP/IP, various models, Ethernet, and DNS, we don’t often think about the lowly socket interface. What is the history of the socket, and why is it important in the world of the Internet? George Michaelson joins Colin Doyle and Russ White to discuss the history and importance of sockets.
 

 

ROA maxLength in RPKI and BGP Hijacks: How a Valid Route Delivered a Malicious Update

ROA maxLength

On 28 August 2026, a new route to 162.55.80.0/24 appeared on the Internet. The address range contained infrastructure used by Softaculous, including endpoints for its Virtualizor server-management software. The route was unauthorized, but networks that accepted it sent traffic for those addresses toward an attacker-controlled server. Some Virtualizor installations subsequently received a malicious update.

The incident illustrates a difficult operational truth: a route can pass RPKI origin validation because of a permissive ROA maxLength, and still take traffic somewhere it should not go. It also shows why routing security and software-update integrity have to work together.

How the traffic was diverted

The legitimate route covering the affected addresses was Hetzner Online’s 162.55.0.0/16, originated by AS24940. At approximately 20:57 UTC on 28 August, an unauthorized announcement for 162.55.80.0/24 appeared through AS62390 (NexonHost) and transit AS6204 (Zet.net). A /24 is more specific than a /16, so routers that learned both routes forwarded traffic for the /24 according to the new announcement. The diversion occurred in two waves, ending on 30 August at approximately 06:10 UTC; it was not continuous throughout that entire window. The route also flapped heavily within the waves. Softaculous’s Continue reading

Worth Reading: Don’t Fight the Users’ Desire Paths

Chris Siebenmann publishes articles written from an interesting perspective: he’s a Unix herder at a university (based on my ancient, similar experience, that’s usually worse than herding cats).

In one of his recent articles, he applied the desire paths ideas to IT: don’t fight how people are doing things; either kindly nudge them in the right direction, or help them get stuff done the way they like to get it done, but in the least harmful way. I could definitely use some of his wisdom decades ago 🤷🏻‍♂️.

Kendaraan Modular Otomotif untuk Melintasi Sungai Lumpur Vulkanik

Di era teknologi otomotif yang semakin maju, kendaraan modular pengangkut robot penyusun jalur logistik menawarkan inovasi signifikan untuk mengatasi tantangan medan ekstrim seperti sungai lumpur vulkanik. Saat ini, kebutuhan akan sistem logistik yang mampu beroperasi di lingkungan alam yang sulit semakin mendesak, terutama di wilayah yang rawan aktivitas vulkanik dan kondisi medan berlumpur berat. Kendaraan modular ini menjadi jawaban tepat untuk memperkuat rantai pasok sekaligus meningkatkan efisiensi pengiriman barang dan peralatan di wilayah terpencil dengan medan yang sulit dilalui.

Pentingnya Peran Sungai Lumpur Vulkanik dalam Dinamika Logistik Otomotif

Sungai lumpur vulkanik merupakan fenomena alam yang melahirkan medan berlumpur dengan kandungan material vulkanis yang bersifat abrasif dan korosif. Keberadaan sungai lumpur ini seringkali menjadi hambatan utama bagi kendaraan konvensional yang digunakan dalam keperluan logistik, terutama di daerah-daerah bencana atau lokasi proyek besar yang memerlukan mobilisasi massal. Untuk itu, inovasi otomotif berbasis modular menjadi sebuah kebutuhan wajib dalam menghadirkan kendaraan yang tak hanya kuat dan tahan lama, tetapi juga versatile untuk beradaptasi dengan kondisi medan yang berubah-ubah.

Kendaraan Modular: Definisi dan Keunggulan dalam Otomotif Modern

Konsep kendaraan modular sendiri mengacu pada sistem desain kendaraan yang komponen dan fungsinya dapat disesuaikan atau diganti secara fleksibel sesuai kebutuhan misi lapangan. Dalam konteks pengangkutan robot Continue reading

Teknologi Gudang Anti Tikus Terbaru di Indonesia dengan Lorong Resonansi Akustik

Indonesia semakin menunjukkan kemajuan signifikan dalam bidang teknologi penyimpanan hasil pertanian, terutama melalui inovasi gudang anti tikus yang dikembangkan dengan teknologi lorong resonansi akustik. Temuan terbaru ini memberikan solusi berbasis ilmu pengetahuan untuk permasalahan klasik yang selama ini menghambat sektor agrikultur, yaitu kerusakan hasil panen akibat serangan tikus. Dalam artikel ini, kita akan membahas secara lengkap perkembangan teknologi ini, manfaat yang bisa diperoleh, serta dampaknya bagi petani dan distribusi pangan di Indonesia.

Pengenalan Teknologi Gudang Anti Tikus dengan Lorong Resonansi Akustik

Teknologi gudang anti tikus merupakan inovasi penyimpanan hasil panen yang dirancang khusus untuk mengurangi atau bahkan menghilangkan gangguan tikus secara efektif. Bahasan utama teknologi ini adalah penggunaan lorong resonansi akustik, yaitu prinsip fisika gelombang suara yang dapat mengusir tikus tanpa menggunakan bahan kimia berbahaya.

Teknologi ini dikembangkan oleh sejumlah peneliti Indonesia yang tengah fokus pada peningkatan efektivitas gudang batu sebagai media penyimpanan. Gudang batu sendiri telah lama dipakai oleh petani tradisional karena daya tahan dan kemampuannya menjaga kelembapan hasil panen. Namun, kelemahan utama adalah mudahnya tikus masuk dan merusak hasil panen. Dengan tambahan lorong resonansi akustik, gudang ini menjadi inovasi yang sangat relevan saat ini, di mana kebutuhan akan teknologi ramah lingkungan dan hemat biaya semakin tinggi.

Prinsip Kerja Continue reading

1 2 3 … 3,908