AivexaNewsSearch
AI news for builders and product teamsChecked every hour

Cloudflare Traces Turns the Proxy Layer into OpenTelemetry Spans, with New Volume-Based Pricing

Collected Oct 10, 2026

Cloudflare has released Traces in open beta, extending automatic tracing beyond Workers to cover the rest of the request path through its proxy. Security rules, transformations, cache decisions, routing, Worker execution and origin handling now surface as OpenTelemetry spans on a single request-level timeline, and Cloudflare says no instrumentation is required. The company also announced a pricing change that applies to the existing Workers Tracing product as well. The news was reported by Steef-Jan Wiggers.

The capability addresses a longstanding visibility gap for anyone running distributed tracing behind a proxy. A typical trace previously showed the client on one side and the application on the other, with the proxy layer in between reconstructed from logs and configuration. With Traces, each supported step appears as a span carrying its own timing, outcome and attributes. Cloudflare frames the value through the questions teams tend to ask during incidents: which security rule blocked a request and how long rule evaluation took; whether a Transform Rule rewrote the URL before the application saw it and where that happened relative to routing; which Page Rule, Snippet or Worker handled the request and which route pattern matched. One example in the announcement describes a cache miss in which 527ms of a 539ms request was spent waiting on the origin, illustrating how a single timeline can locate the dominant cost.

Context propagation is what makes the view portable rather than Cloudflare-only. Traces accept a W3C traceparent header on incoming requests, so Cloudflare-generated spans can join a trace started by an upstream service, and the system can forward a new traceparent to the origin so instrumented services continue the same trace. An incoming propagation policy decides whether Cloudflare accepts caller context at all. That control matters because blindly trusting a trace ID from any client invites noise from arbitrary or hostile traffic. In practice, teams will likely enable acceptance only for trusted callers, which is consistent with Cloudflare's stated plan to add authenticated context propagation later.

Sampling is driven by the same rules engine Cloudflare uses elsewhere in its platform. Teams set a baseline rate, for example 1% during normal operation, then add Trace Rules that override the baseline for matching traffic. Cloudflare's examples include tracing every request for one customer's hostname, source IP or identifying header while everyone else stays at the baseline, or capturing every request carrying a temporary debug header during an investigation. Rules can match on paths, methods, headers, addresses, geographies or combinations of those. Spans export over OTLP to any compatible backend, configured as an account-level destination with per-domain selection of which traffic is sent. Cloudflare presents this as a commitment to OpenTelemetry and to keeping telemetry data portable across vendors.

There is also an agent-oriented angle. Through the Cloudflare Observability MCP server, a coding agent can query traces via the SQL API, compare failed traces with successful ones to find where spans diverge, and tie those findings back to code in a repository. This follows Cloudflare's earlier agent tracing work and reflects a broader shift in which telemetry becomes something a tool reads automatically rather than a dashboard a person watches.

The pricing change is the second revision in two months and is the more consequential half of the announcement for existing customers. Earlier reporting indicated every span would become a billable event from October 1, 2026. Cloudflare has now replaced that model effective December 1, 2026, charging instead for data ingested and retained. The free plan includes 0.5GB of ingestion per day with seven-day retention and no additional usage allowance. Paid and Enterprise plans include 50GB of ingestion and 10GB-month of storage per billing cycle, with overage at $0.25 per GB ingested and $0.10 per GB-month stored. Retention of up to one year is listed as coming soon.

Charging by volume rather than per span changes how teams should think about sampling. Under a volume model, sampling decisions translate directly into cost, so the practical pattern is a low baseline plus targeted rules that raise the rate only for traffic under investigation. This suggests the design of Trace Rules is at least partly a cost-control mechanism as well as a debugging one, and that observability budgets will need to account for spikes when debug rules are left on. It also makes the choice of retention window a financial decision rather than a purely operational one, since stored gigabytes accumulate monthly.

Coverage is deliberately partial. Cloudflare lists broader automatic instrumentation as planned for the HTTP request path, including DDoS rules and Access, and for the Workers execution path, including Workflows, Queues and Pipelines. Also planned are authenticated context propagation, ad hoc tracing of a single request without altering the baseline rate, and OpenTelemetry API support in Workers so developers can add attributes to existing spans. Traces itself is available in open beta from the dashboard, the API or Terraform, on any domain, with export to an OTLP destination.

Why it matters: teams running applications behind Cloudflare gain proxy-layer spans they previously had to approximate from logs, and the W3C traceparent support means those spans can slot into existing OpenTelemetry pipelines rather than forming a separate silo. Developers already paying for Workers Tracing should model the shift to ingestion and storage billing, since volume-based pricing rewards disciplined sampling and could raise costs for verbose or long-retention setups. The gaps listed by Cloudflare, particularly Workers API attributes and authenticated propagation, are the pieces most likely to shape early adoption decisions.

Read at InfoQ · AI, ML & Data Engineering

Based on reporting from the original publisher. Visit the source for full context and later updates.

Publisher excerpt

Cloudflare has put Traces into open beta, extending automatic tracing from Workers to security rules, transformations, cache, routing and origin handling as OpenTelemetry spans. Traces accept and forward W3C traceparent headers, and Trace Rules allow targeted sampling. Pricing moves to ingestion and retention volume from December 1. By Steef-Jan Wiggers