Skip to content

chore(deps): update terraform cloudflare to v5.26.0 - #402

Open
renovate[bot] wants to merge 1 commit into
developfrom
feature/renovate-cloudflare-5.x-lockfile
Open

renovate[bot] wants to merge 1 commit into
developfrom
feature/renovate-cloudflare-5.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
cloudflare (source) required_provider minor 5.23.0 → 5.26.0

Release Notes

cloudflare/terraform-provider-cloudflare (cloudflare)

v5.26.0

Compare Source

Full Changelog: v5.25.0...v5.26.0

Features
New Resources
  • cloudflare_field_extractor: Field Extractor
  • cloudflare_magic_wan_bgp_filter_profile: Magic WAN BGP Filter Profile
  • cloudflare_zero_trust_casb_policy: Zero Trust CASB Policy
  • cloudflare_zero_trust_casb_webhook: Zero Trust CASB Webhook
  • cloudflare_zero_trust_connectivity_settings: Zero Trust Connectivity Settings
  • cloudflare_zone_tracing: Zone Tracing
  • cloudflare_zone_tracing_rules: Zone Tracing Rules
New Data Sources
  • cloudflare_field_extractor: Field Extractor
  • cloudflare_magic_wan_bgp_filter_profile: Magic WAN BGP Filter Profile
  • cloudflare_magic_wan_bgp_filter_profiles: Magic WAN BGP Filter Profiles (list)
  • cloudflare_zero_trust_casb_policy: Zero Trust CASB Policy
  • cloudflare_zero_trust_casb_policies: Zero Trust CASB Policies (list)
  • cloudflare_zero_trust_casb_webhook: Zero Trust CASB Webhook
  • cloudflare_zero_trust_casb_webhooks: Zero Trust CASB Webhooks (list)
  • cloudflare_zero_trust_connectivity_settings: Zero Trust Connectivity Settings
  • cloudflare_zone_tracing: Zone Tracing
  • cloudflare_zone_tracing_rules: Zone Tracing Rules
New Attributes
  • cloudflare_magic_wan_gre_tunnel, cloudflare_magic_wan_ipsec_tunnel
    • bgp.import_filter_id: ID of the BGP filter profile applied to routes received from the customer
    • bgp.export_filter_id: ID of the BGP filter profile applied to routes advertised to the customer
Bug Fixes
  • custom_ssl: mark private_key optional to unblock setting custom_csr_id
  • email_routing_settings: add missing support_subaddress to resource schema
  • load_balancer_monitor: correctly resolve ambiguous version-zero state during v4 to v5 migration
  • page_rule: raise edge_cache_ttl maximum to allow one-year values
  • provider: send user_agent_operator_suffix unquoted and read fallback from environment variable
  • ruleset: normalize legacy query string wildcards during v4 to v5 migration
  • zone_lockdown: drop UseNonNullStateForUnknown on created_on to prevent perpetual diff

v5.25.0

Compare Source

Full Changelog: v5.24.0...v5.25.0

Features
New Resources
  • cloudflare_email_security_allow_policy: Cloud Email Security Allow Policy
  • cloudflare_email_security_domain: Cloud Email Security Domain
  • cloudflare_email_sending_subdomain: Email Sending Subdomain
  • cloudflare_nel_setting: Network Error Logging Zone Setting
  • cloudflare_zero_trust_resource_library_application: Zero Trust Resource Library Application
New Data Sources
  • cloudflare_email_security_allow_policy: Cloud Email Security Allow Policy
  • cloudflare_email_security_allow_policies: Cloud Email Security Allow Policies (list)
  • cloudflare_email_security_domain: Cloud Email Security Domain
  • cloudflare_email_security_domains: Cloud Email Security Domains (list)
  • cloudflare_email_sending_subdomain: Email Sending Subdomain
  • cloudflare_email_sending_subdomains: Email Sending Subdomains (list)
  • cloudflare_nel_setting: Network Error Logging Zone Setting
  • cloudflare_spectrum_protocols: Spectrum Protocols (list)
New Attributes
  • cloudflare_ai_search_instance
    • aisearch_model: Workers AI model for AI search queries
    • embedding_model: Model used to generate text embeddings
    • reranking_model: Model used to rerank search results
    • rewrite_model: Workers AI model for query rewriting
    • summarization_model: Model used to summarize search results
  • cloudflare_bot_management
    • bot_preference_sync_enabled: Sync bot preferences from AI Search, AI User, and AI Training zone settings
  • cloudflare_content_scanning_expression
    • payload: Custom content extraction expression to locate content objects in requests
  • cloudflare_email_routing_dns
    • support_subaddress: Whether plus-addressing is honored when matching routing rules
  • cloudflare_magic_transit_connector
    • primary: Whether this connector is the primary connector for the site
    • site_id: Identifier of the Magic Transit site this connector belongs to
  • cloudflare_oauth_client
    • optional_scopes: Scopes a user may decline during OAuth consent
  • cloudflare_organization
    • account_creation_applies_tenant_defaults: Whether tenant defaults apply to newly created accounts
  • cloudflare_pipeline_sink
    • format: Output data format configuration for the sink
    • schema: Schema definition for events in the data stream
  • cloudflare_pipeline_stream
    • format: Data format configuration for stream events
    • schema: Schema definition for events in the data stream
  • cloudflare_ruleset
    • origin_range_requests: Fetch large origin assets as a series of range requests
    • vary: Cache variation key configuration for set_cache_settings action
  • cloudflare_stream_live_input
    • playback: HLS and DASH manifest URLs for live stream playback
  • cloudflare_worker_version
    • identity: Enables Gateway identity for network bindings
  • cloudflare_workers_kv_namespace
    • jurisdiction: Restrict KV data storage to a specific jurisdiction at creation time
  • cloudflare_workers_script
    • files: Multipart WASM modules and binary files included in the Worker upload
  • cloudflare_workflow
    • concurrency: Concurrency limit and active instance count for the workflow
  • cloudflare_zero_trust_access_group
    • account_id: Account that owns the device posture integration (in posture sub-rules)
  • cloudflare_zero_trust_access_identity_provider
    • force_authn: Asks the IdP to reauthenticate on each SAML request
    • max_sso_url_length: Maximum URL length accepted for SSO redirect
Bug Fixes
  • bot_management: mark bot_preference_sync_enabled optional-only; Computed caused "unknown after apply" errors
  • custom_pages: Update causing inconsistent apply results
  • email_routing_dns: data source not returning any data (#​7130)
  • email_security_block_sender: mark account_id as required in data sources
  • image: fix create/update marshaling errors
  • magic_transit_connector: add missing primary and site_id fields; mark account_id as required in data sources
  • registrar_domain: mark account_id as required in list data source
  • worker_version: correct response binding order to prevent plan drift (#​7115)
  • set schema Version: 500 on new resources to enable correct state upgrade path

v5.24.0

Compare Source

Full Changelog: v5.23.0...v5.24.0

BREAKING CHANGES

The following upstream API schema changes required corresponding provider schema updates. Existing state files load without user action (the plugin framework silently drops attributes that no longer exist in the schema), but Terraform configurations that still reference removed attributes must be updated before terraform plan will succeed.

  • hostname_tls_setting: the cloudflare_hostname_tls_setting data source now requires hostname as an input parameter instead of returning it as a computed attribute. The computed id attribute has been removed; use setting_id instead. (ece27fe)
  • image_variant: the computed variant nested attribute has been removed. The API no longer returns this wrapper object; the id, options, and never_require_signed_urls fields remain available at the top level. Remove any references to cloudflare_image_variant.<name>.variant from your configurations. (738bd28)
  • organization: the computed meta.flags nested attribute has been renamed to meta.tenant_flags. Two new computed sub-attributes (enterprise_capability, member_management) have been added. Update any references from .meta.flags to .meta.tenant_flags. (ece27fe)
  • zero_trust_access_ai_controls_mcp_portal: the allow_code_mode attribute is now deprecated and no longer computed with a default of true. Use the new code_mode attribute ("off", "opt_in", "default_on", "enforced") instead. Configurations that relied on the computed default must explicitly set code_mode or allow_code_mode. (ece27fe)
  • zero_trust_access_policy: the session_duration attribute is no longer computed with a default of "24h". It is now optional-only. Existing configurations that omitted session_duration and relied on the provider default will see a plan diff; explicitly set session_duration = "24h" to preserve the previous behavior. (ae4f5a1)
  • zero_trust_organization: the allowed_authenticators enum value ssh_piv_key has been renamed to piv_key, and a new value ssh_fido2_key has been added. Configurations using "ssh_piv_key" must be updated to "piv_key". (ece27fe)
  • zero_trust_resource_library_application: the id attribute type changed from String to Int64. The computed intel_id attribute has been removed. The hostnames, ip_subnets, port_protocols, support_domains, and supported attributes changed from List to Set (element ordering is no longer significant). These changes apply to both the resource data source and the list data source. (ece27fe)
  • zero_trust_resource_library_category: the id attribute type changed from String to Int64 on both the data source and list data source. (ece27fe)
  • zero_trust_tunnel_cloudflared: the computed is_pending_reconnect attribute has been removed from connections. The upstream API no longer returns this field. Remove any references to connections[*].is_pending_reconnect from your configurations. (ece27fe)
  • zero_trust_tunnel_warp_connector: the computed is_pending_reconnect attribute has been removed from connections, matching the zero_trust_tunnel_cloudflared change above. (ece27fe)
New Resources
  • cloudflare_ct_alerting: onboard new Terraform resource for Certificate Transparency alerting (ece27fe)
  • cloudflare_precursor: onboard new Terraform resource for Precursor (ece27fe)
New Data Sources
  • cloudflare_hostname_tls_settings: add list data source for hostname TLS settings (ece27fe)
Features
  • bump Go SDK version to v7.9.0 (79c7d4f)
  • ai_gateway: add log_classification attribute and unified billing mode (ece27fe)
  • ai_search_instance: add discover_options for link-following web crawler configuration (ece27fe)
  • ai_search_namespace: add public_endpoint_params with MCP, rate limiting, custom domains, and chat completions configuration (ece27fe)
  • cloud_connector_rules: add oci_storage cloud provider type (ece27fe)
  • d1_database: add us location restriction value (ece27fe)
  • load_balancer_pool: add health_sources attribute for regional health steering (ece27fe)
  • ruleset: add vary parameter to set_cache_settings action (e9cdc20)
  • waiting_room: add Latvian (lv-LV) language support (ece27fe)
  • worker: add preview_url_suffix and url computed attributes to subdomain block (ece27fe)
  • worker_version: add messaging binding type (ece27fe)
  • zero_trust_access_ai_controls_mcp_portal: add code_mode attribute for granular Code Mode policy control (ece27fe)
  • zero_trust_access_ai_controls_mcp_server: add authentication_status computed attribute (ece27fe)
  • zero_trust_access_application: add worker destination types for Access (118fe39)
  • zero_trust_access_custom_page: add contract_version, warnings, and new type values (login, interstitial) (ece27fe)
  • zero_trust_access_service_token: add enabled attribute to control service token activation (ece27fe)
  • zero_trust_dlp_*_entry: add computed deprecated attribute to all DLP entry resources and data sources (ece27fe)
  • zero_trust_organization: add warp_auth_non_browser_401 attribute for non-browser 401 responses (ece27fe)
  • zone_setting: add webmcp_enabled and webmcp_packs setting IDs (ece27fe)
Bug Fixes
  • guard against nil pointer dereference in dynamic semantic equality (d82bbd5)
  • image_variant: fix nested variant response deserialization (738bd28)
  • port v5.23.0 regression fixes from GitHub main (ae4f5a1)
  • remove duplicate declarations causing build failures (dc360d2)
Documentation
  • image_variant: update resource documentation (bab4b71)
  • regenerate provider documentation (79c7d4f)
  • restore .md extensions on internal guide cross-links (f51c9d6)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from noahwhite as a code owner August 25, 2026 21:42
@renovate
renovate Bot force-pushed the feature/renovate-cloudflare-5.x-lockfile branch 2 times, most recently from cc74cb3 to 2ae45d3 Compare September 11, 2026 23:06
@renovate renovate Bot changed the title chore(deps): update terraform cloudflare to v5.24.0 chore(deps): update terraform cloudflare to v5.25.0 Sep 11, 2026
@renovate renovate Bot changed the title chore(deps): update terraform cloudflare to v5.25.0 chore(deps): update terraform cloudflare to v5.26.0 Sep 26, 2026
@renovate
renovate Bot force-pushed the feature/renovate-cloudflare-5.x-lockfile branch from 2ae45d3 to ba09051 Compare September 26, 2026 06:51

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant