You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
title: New Gateway Analytics in the Cloudflare One Dashboard
3
+
description: An upgraded analytics experience for Gateway usage and metrics.
4
+
date: 2025-05-29T09:00:00Z
5
+
products:
6
+
- gateway
7
+
---
8
+
9
+
Users can now access significant enhancements to Cloudflare Gateway analytics, providing you with unprecedented visibility into your organization's DNS queries, HTTP requests, and Network sessions. These powerful new dashboards enable you to go beyond raw logs and gain actionable insights into how your users are interacting with the Internet and your protected resources.
10
+
11
+
You can now visualize and explore:
12
+
13
+
- Patterns Over Time: Understand trends in traffic volume and blocked requests, helping you identify anomalies and plan for future capacity.
14
+
- Top Users & Destinations: Quickly pinpoint the most active users, enabling better policy enforcement and resource allocation.
15
+
- Actions Taken: See a clear breakdown of security actions applied by Gateway policies, such as blocks and allows, offering a comprehensive view of your security posture.
16
+
- Geographic Regions: Gain insight into the global distribution of your traffic.
To access the new overview, log in to your Cloudflare [Zero Trust dashboard](https://one.dash.cloudflare.com/) and go to Analytics in the side navigation bar.
title: Cloudflare User Groups & Enhanced Permission Policies are now in Beta
3
+
description: Simplifying the management of users, groups, and permissions within Cloudflare.
4
+
products:
5
+
- fundamentals
6
+
date: 2025-06-02
7
+
---
8
+
9
+
We're excited to announce the Public Beta launch of **User Groups for Cloudflare Dashboard** and **System for Cross Domain Identity Management (SCIM) User Groups**, expanding our RBAC capabilities to simplify user and group management at scale.
10
+
11
+
We've also visually overhauled the **Permission Policies UI** to make defining permissions more intuitive.
12
+
13
+
**What's New**
14
+
15
+
**User Groups [BETA]**: [User Groups](/fundamentals/manage-members/user-groups/) are a new Cloudflare IAM primitive that enable administrators to create collections of account members that are treated equally from an access control perspective. User Groups can be assigned permission policies, with individual members in the group inheriting all permissions granted to the User Group. User Groups can be created manually, via our APIs, or Terraform.
16
+
17
+
**SCIM User Groups [BETA]**: Centralize & simplify your user and group management at scale by syncing memberships directly from your upstream identity provider (like Okta or Entra ID) to the Cloudflare Platform. This ensures Cloudflare stays in sync with your identity provider, letting you apply Permission Policies to those synced groups directly within the Cloudflare Dashboard.
18
+
19
+
:::note
20
+
SCIM Virtual Groups (identified by the pattern `CF-<accountID>-<Role Name>` in your IdP) are deprecated as of 06/02/25. We recommend migrating SCIM Virtual Groups implementations to use [SCIM User Groups](/fundamentals/account/account-security/scim-setup/). If you did not use Virtual Groups, no action is needed.
21
+
:::
22
+
23
+
**Revamped Permission Policies UI [BETA]**: As Cloudflare's services have grown, so has the need for precise, role-based access control. We've given the Permission Policies builder a visual overhaul to make it much easier for administrators to find and define the exact permissions they want for specific principals.
When opting into the Beta for User Groups and Permission Policies, you'll be transitioning to a new experience. Please be aware that opting out isn't currently available.
29
+
:::
30
+
31
+
For more info:
32
+
33
+
-[Get started with User Groups](/fundamentals/manage-members/user-groups/)
Copy file name to clipboardExpand all lines: src/content/docs/ai-gateway/chat-completion.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -64,7 +64,7 @@ curl -X POST https://gateway.ai.cloudflare.com/v1/{account_id}/{gateway_id}/comp
64
64
65
65
### Universal provider
66
66
67
-
You can also use this pattern with a[Universal Endpoint](/ai-gateway/universal/).
67
+
You can also use this pattern with the[Universal Endpoint](/ai-gateway/universal/) to add [fallbacks](/ai-gateway/configuration/fallbacks/) across multiple providers. When used in combination, every request will return the same standardized format, whether from the primary or fallback model. This behavior means that you do not have to add extra parsing logic to your app.
Copy file name to clipboardExpand all lines: src/content/docs/byoip/get-started.mdx
+19-27Lines changed: 19 additions & 27 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,46 +3,38 @@ title: Get started
3
3
pcx_content_type: get-started
4
4
sidebar:
5
5
order: 2
6
-
7
6
---
8
7
9
-
import { GlossaryTooltip } from"~/components"
8
+
import { GlossaryTooltip } from"~/components";
9
+
10
+
Work with your account team to understand everything you need to ensure a smooth transition during the onboarding process.
10
11
11
-
To bring your own IPs, you must work with your account team to understand everything you need to ensure a smooth transition during the onboarding process.
12
+
Cloudflare requires a service-specific configuration for your prefixes, as well as some requirements common to all BYOIP customers regardless of service type.
12
13
13
-
Cloudflare requires a service-specific configuration for your prefixes, as well as some requirements common to all BYOIP customers regardless of service type. These requirements are common to all products compatible with BYOIP, such as [Magic Transit](/magic-transit/), [Spectrum](/spectrum/), and [CDN services](/cache/).
14
+
## Requirements
14
15
15
-
## Prerequisites
16
+
The following requirements are common to all products compatible with BYOIP.
16
17
17
-
There are two major prerequisites before Cloudflare can begin onboarding your IP space.
18
+
You must verify that your [Internet Routing Registry (IRR)](/byoip/concepts/irr-entries/) records are up to date and contain:
18
19
19
-
1. Cloudflare must receive a [Letter of Agency (LOA)](/byoip/concepts/loa/) to announce your prefixes, which we will share with our transit partners as evidence that we are allowed to announce the route.
20
-
2. You must verify that your [Internet Routing Registry (IRR)](/byoip/concepts/irr-entries/) records are up to date and contain:
21
20
-`route` or `route6` objects matching the exact prefixes you want to onboard
22
21
-`origin` matching the correct ASN you want to onboard
23
22
24
23
:::caution[RPKI validation]
25
-
You are not required to use <GlossaryTooltipterm="Resource Public Key Infrastructure (RPKI)">Resource Public Key Infrastructure (RPKI)</GlossaryTooltip>. However, if you do, make sure your <GlossaryTooltipterm="Route Origin Authorization (ROA)">ROAs</GlossaryTooltip> are accurate. You can use [Cloudflare's RPKI Portal](https://rpki.cloudflare.com/?view=validator) and a second source such as [Routinator](https://rpki-validator.ripe.net/ui/) to doublecheck your prefixes.
24
+
You are not required to use <GlossaryTooltipterm="Resource Public Key Infrastructure (RPKI)">Resource Public Key Infrastructure (RPKI)</GlossaryTooltip>. However, if you do, make sure your <GlossaryTooltipterm="Route Origin Authorization (ROA)">ROAs</GlossaryTooltip> are accurate. You can use [Cloudflare's RPKI Portal](https://rpki.cloudflare.com/?view=validator) and a second source such as [Routinator](https://rpki-validator.ripe.net/ui/) to double-check your prefixes.
26
25
:::
27
26
28
-
After onboarding, [Border Gateway Protocol (BGP)](https://www.cloudflare.com/learning/security/glossary/what-is-bgp/) announcements for customer prefixes can be controlled with the [Dynamic Advertisement](/byoip/concepts/dynamic-advertisement/) API or via the Cloudflare dashboard.
29
-
30
-
## Cloudflare IPs
31
-
32
-
If you are unable to bring your own IP to Cloudflare, you can use an IP address issued by Cloudflare.
27
+
## Process overview
33
28
34
-
Using a Cloudflare IP may be a good option if you:
29
+
Overall, the steps can be summarized as follows:
35
30
36
-
* Have one or a few IPs allocated from home or business class ISPs.
37
-
* Are an online streamer who could be the target of a DoS attack if your IP is leaked.
38
-
* Are a business owner with a small number of locations with broadband Internet connections.
39
-
* Do not own an IP space with a /24 prefix length.
40
-
* Maintain a large number of locations with a combination of connectivity methods.
41
-
* Own an IP space with a /24 prefix length but do not advertise prefixes from every location.
31
+
1. You revise your [IRRs and ROAs](#requirements) (if applicable) to make sure they are correct.
32
+
2. You prepare a [Letter of Agency (LOA)](/byoip/concepts/loa/) containing both the prefix you are authorizing Cloudflare to announce and which ASN they will be announced under. Cloudflare will present this to our transit partners as evidence that we are allowed to announce the route.
33
+
3. You use the [Upload LOA Document](/api/resources/addressing/subresources/loa_documents/methods/create/) API endpoint to submit the letter under your account and the [Add Prefix](/api/resources/addressing/subresources/prefixes/methods/create/) endpoint to create the prefix in your account with the associated `loa_document_id`.
34
+
4. After receiving the LOA, Cloudflare validates the [requirements](#requirements) and provisions the IPs.
35
+
5. (Optional) You can use [prefix delegations](/byoip/concepts/prefix-delegations/) to share all or part of your prefix with another Cloudflare account.
36
+
6. You use [service bindings](/byoip/service-bindings/)[^1] and [address maps](/byoip/address-maps/)[^2] to control how your IPs are used.
37
+
7. You advertise or withdraw the BGP route for a prefix via the [BGP Prefixes API](/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/).
42
38
43
-
To protect your network using a Cloudflare IP address, contact your account manager.
44
-
45
-
:::note
46
-
47
-
When you use a Cloudflare-managed IP space, you do not need to provide a Letter of Agency (LOA) and advertise your prefixes that are associated with bringing your own IP.
48
-
:::
39
+
[^1]: Mappings that control through which pipeline traffic destined for a given IP address will be routed.
40
+
[^2]: Mappings that specify which IP addresses should be used when Cloudflare responds to DNS queries for proxied hostnames.
0 commit comments