Dev News Daily ENDE

Cloudflare Traces opens in beta, showing WAF, cache and routing as OpenTelemetry spans

Cloudflare has opened a beta of Cloudflare Traces, which extends the automatic tracing it already offered for Workers to the rest of the path a request takes through its network. It was announced on the company's blog during its Birthday Week. The feature works on any domain behind Cloudflare, not only on applications built on its developer platform.

What a trace contains. Each supported step becomes a span with its timing, outcome and attributes: evaluation of custom and managed security rules, transform rules that rewrite the URL, Page Rules, Snippets and Workers routing, cache lookups, the upstream connection and origin handling. The blog's examples are questions that today need several logs and a configuration export to answer: which rule blocked or challenged a request, whether a transform changed the path before it reached the application, and where time went on a cache miss. In the post's screenshot, 527 of 539 milliseconds were spent waiting for the origin.

Controlling volume. Tracing is switched on per domain with a baseline sampling rate, for example 1% of requests. Trace Rules, written in the same rules language as the rest of the dashboard, override that rate for matching traffic. The intended use is to trace 100% of requests for one customer's hostname, one source IP or a temporary debug header while everyone else stays at the baseline.

Joining your own traces. Cloudflare can accept an incoming W3C traceparent header, under a policy that decides whether to trust it, and can forward a new traceparent to the origin, so application spans continue the same trace. Spans can be exported over OTLP to any compatible backend from an account-level destination. The company also points to its Observability MCP server, through which a coding agent can query traces with SQL.

Price and what is missing. Traces will fall under Cloudflare's unified observability pricing, which charges by ingested data and retention rather than by span count; it applies to Cloudflare Tracing and Workers Tracing from 1 December 2026. Not yet covered and listed as planned: spans for DDoS rules and Access, Workflows, Queues and Pipelines, authenticated context propagation so only trusted callers can continue a trace, on-demand tracing of a single request, and retention of up to 365 days.

Cloudflare Traces opens in beta, showing WAF, cache and routing as OpenTelemetry spans
Cloudflare Traces opens in beta, showing WAF, cache and routing as OpenTelemetry spans — Dev News Daily

What it means

The part that changes day-to-day work is propagation. Until now a CDN was a gap in a distributed trace: the timeline started at the origin and the time spent in front of it was guessed from logs. With an incoming and outgoing traceparent, the edge becomes part of the same trace. Teams should decide early whether to accept trace context from the public internet, because the beta has no authenticated propagation yet.