A year after Cloudflare CTO Dane Knecht announced the intent to make every Cloudflare feature available to everyone, the company reports measurable progress. The Enterprise tier originally existed to serve larger customers who needed procurement options beyond a credit card — invoices, custom contracts, dedicated support. Over time that created a two-tier system in which some of the most capable features were Enterprise-only. Every GA feature shipped this week that is available on an Enterprise plan is also available to Pay-as-you-go customers, and most reach the free tier. Where plans differ, it is in usage limits rather than capability.

Logs and analytics open up

Logpush delivers Cloudflare logs to storage, security, and analytics destinations, letting customers monitor traffic, investigate issues, and analyze data in existing tools. Once Enterprise-only, it is now available to Free, Pro, and Business customers through self-service, pay-as-you-go pricing. Available datasets keep expanding: account-scoped firewall events, WebSocket analytics, and per-zone post-quantum visibility were recently added.

Transformers is also reaching general availability for all customers. It applies SQL to filter records, redact sensitive information, enrich events, and reformat logs before delivery, avoiding a separate extraction, transformation and loading (ETL) pipeline. Custom Dashboards, which let customers build personalized views of the metrics most critical to them, are now available to all customers as well.

Managing Cloudflare at scale

RBAC and multiple accounts

Role-Based Access Control has expanded dramatically over the past year. Nearly all products now offer RBAC roles at the account and zone level. Workers recently joined R2 and Access in supporting RBAC roles at the individual resource level, so administrators decide who on a team gets specific access to individual Workers.

Fine-grained RBAC still relies on a small number of super administrators. As the number of teams and zones grows, that centralized model becomes a bottleneck and a single account gets crowded. The New Account button, launched on the dashboard last month, lets users create additional accounts directly. Thousands of customers branch into new accounts each week. Each new account is free and independently billed, so spending can be segmented across cost centers, with safeguards against fraud and abuse.

image2.png

Enterprise customers are advised to contact their account team for new accounts for now, which lets them reuse existing agreements and subscriptions; there is no preset limit on how many they can request, and self-serve provisioning is planned. Organizations then group accounts behind a single analytics and shared configuration surface. Currently in beta for Enterprise, it will be GA in October and roll out to free accounts in early 2027. Organizations provide shared administrators with unified analytics and audit logging plus shared WAF, Gateway, and Access IdP configurations. Enterprises are eligible for exactly one organization, giving executives a single view of company assets. An Enterprise super administrator can set one up directly if nobody has already created it; otherwise, other Cloudflare administrators must add the accounts, which avoids any elevation of privilege.

Infrastructure as Code and tagging

Terraform provides an auditable, repeatable path for managing accounts and resources through version-controlled code rather than dashboard clicks. Cloudflare has built its Terraform provider programmatically so it stays current with the latest API version. Like the other features described here, Terraform is available to all customers.

Resource Tagging applies key-value tags to a broad set of resources within accounts and organizations, interactively or via API, and is useful for organizing resources in the dashboard. Future plans include tags for billing and access control and management through Terraform.

image3.png

Cloudflare's own operating model

Internally, Cloudflare creates accounts per team or per service, then uses Terraform to manage account access and production configuration, giving teams a peer-reviewed, auditable change path. Narrow account scope allows broader permissions for responsible engineers while containing blast radius, so accounts grow organically without bottlenecking on central administrators and on-call response gets faster and safer. Every account lives inside Cloudflare's organization, giving the security team administrative access plus analytics, policy management, and shared configuration, which aligns accounts with security standards while preserving team autonomy. Resource Tagging is enabled internally, with teams starting to tag resources to find the WAF rule or R2 bucket they need.

image1.png

Additional releases and forward commitments

Support for the Authentik identity provider (IdP), SCIM Audit logging, and SCIM 2.0 Group Sync launched, MCP Server Portals reached general availability, and network management is going self-serve: the Network Overview page and Unified Routing both became available for all. As part of Code Orange: Fail Small, Cloudflare committed to rolling new code out by traffic cohort starting with free customers — and to introducing no new Enterprise-only features, with carve-outs for inherently Enterprise-oriented offerings such as Cloudflare for Government.

Usage visibility and budget controls

Non-Enterprise customers gained a billable usage dashboard and API in August, letting them track spend and download consumption data for offline analysis or use through third-party tools like Vantage. Budget alerts ship enabled by default to avoid surprise invoices. Hard spending caps are in prototyping, with early availability targeted for Q4 2026. Enterprise accounts are excluded from this experience for now because contract terms and payment arrangements vary so widely; an announcement is expected in 2027.

Raised limits across the platform

Limits have climbed steadily over the past year, and the defaults keep moving upward.

Compute and execution

  • Workers: startup time is now 1 second (up from 400 ms), WebSocket messages can be 32 MiB (up from 1 MiB), and a request can make up to 1 million subrequests (up from 1,000). A Worker can be up to 64 MiB uncompressed (previously 10 MB), and the concurrent connection limit has been relaxed.
  • Dynamic Workers: any paid Workers account can use them (previously prerelease access only), and each Durable Object can run ten Dynamic Workers with in-flight requests, up from four.
  • Containers: 6 TiB of memory, 1,500 vCPU, and 30 TB of disk (up from 400 GiB, 100 vCPU, and 2 TB). Custom instance sizes are open to every Containers account rather than select Enterprise accounts, and a custom instance can use up to 20 GB of disk with any supported memory size (previously 2 GB of disk per 1 GiB of memory).

Durable Objects and Workflows

  • Durable Objects: an object stays alive up to 15 minutes while it holds an active outbound connection (previously eviction was possible after 70–140 seconds without incoming traffic). The search API accepts names up to 128 characters, up from 20.
  • Workflows: 50,000 concurrent instances and 300 instance creations per second (up from 4,500 and 10), plus 2 million queued instances per Workflow (up from 1 million). Instances support up to 25,000 steps (up from 1,024) and stream output up to their instance storage limit, up from 1 MiB.

Browsers, vectors, and static assets

  • Browser Run: 200 concurrent browsers, three launches per second, and 30 Quick Actions per second (up from 30 browsers, 30 launches per minute, and 10 Quick Actions per second). REST API throughput is ten requests per second (up from three), and a session now accepts multiple concurrent clients instead of one.
  • Vectorize: 20 million vectors per index (up from 5 million), and topK returns up to 50 values (up from 20).
  • Pages: up to 100,000 static assets per project, up from 20,000.
  • AI Search: a vector supports up to 10 KiB of metadata, replacing the 500-character per-text-field limit.

Networking, rules, and security

  • Header sizes: HTTP headers can reach 128 KB, previously 32 KB.
  • Rules Engine: concat() takes up to 32 arguments, up from 16.
  • API Shield: a zone supports 32 JSON Web Token validation configurations with 16 keys each (up from four configurations with four keys each).
  • Security Insights: scans run every seven days on Free, every three days on Pro and Business, and daily on Enterprise, and on-demand scans are available on every plan rather than a subset.

Getting started

  • Create additional accounts to partition the concerns of your organization.
  • Use RBAC to define security policies at the zone and account level.
  • Enterprise customers can create an Organization and onboard those accounts; other customers will get access in early 2027.
  • Manage state across the whole organization with Terraform.
  • Cloudflare Connect next month covers everything discussed here, with the team that built it on hand.

The work remains unfinished relative to Dane's pledge from a year ago, but the direction is toward the most powerful and accessible platform for customers large and small without a contract.