5.27.0 (2026-10-03)
Full Changelog: v5.26.0...v5.27.0
⚠ BREAKING CHANGES
One change requires a configuration edit. The rest of this release's schema movement is read-only reshaping with no action required — see Schema Changes
- api_shield_operation: the
featureandwith_schemasattributes have been removed from the resource. They were never resource state — both are read-shaping query parameters on the list/get endpoints, and there is no create or update endpoint that accepts them. Remove them from anycloudflare_api_shield_operationblock; leaving them in place produces an "Unsupported argument" error. The schema version moves from 500 to 501 and an automatic state upgrader strips both fields from existing state, so no manual state editing is required. This also fixes the.with_schemas: was cty.False, but now nullerror raised when upgrading from v5.26.0.
Notes
- magic_transit_site: changing
ha_modeno longer forces replacement. The upstream API added update support, so the site is modified in place. - magic_transit_site_lan: changing
ha_linkno longer forces replacement, for the same reason. - magic_transit_site_wan:
health_check_rateis now configurable (previously read-only). - ai_search_instance:
hybrid_search_enablednow reflects the API default oftruefor newly created instances. Existing instances keep the value already in state, so upgrading does not plan a change. - zone_dns_settings:
nameservers.ns_setis now computed. It applies only to custom nameserver types and is preserved from state when the API does not return it. - zone_dns_settings:
foundation_dnsis deprecated and will be removed in a future API version. Setnameservers.typetocloudflare.advancedto turn Advanced Nameservers on, orcloudflare.standardto turn it off. - ai_gateway: the default for
spend_limits.rules.idchanged from865b4d33to00000000. Configurations that do not setidexplicitly will show a one-time diff on the next plan. - zero_trust_device_custom_profile: changing an explicitly configured
profile_typenow forces replacement. The field is set when the profile is created and cannot be changed, so an in-place update was never possible. Configurations that omitprofile_typeare unaffected.
Features
New Resources
- cloudflare_zero_trust_casb_integration: Zero Trust CASB Integration
New Data Sources
- cloudflare_zero_trust_casb_integration: Zero Trust CASB Integration
- cloudflare_zero_trust_casb_integrations: Zero Trust CASB Integrations (list)
New Attributes
- magic_transit_site_wan:
load_balance_inner_flows - zero_trust_organization:
strict_service_token_auth - zone_dns_settings:
nameservers.nameserver_set_id - ai_search_instance, ai_search_instances:
hostnamefilter - account_api_token_permission_groups, account_api_token_permission_groups_list, api_token_permission_groups_list:
categoryandis_selectable
New Accepted Values
- flagship_flag:
rules.conditions[...].operatoracceptshasandnot_has - pipeline_sink:
typeacceptsbasin_catalog - worker_version:
bindings.typeacceptsartifacts - workers_script:
bindings.typeacceptsartifacts,flagship,k2andmessaging - zone_dns_settings:
nameservers.typeacceptscloudflare.advancedandcustom
Other
- bump cloudflare-go to v7.12.0
- calls_turn_app: add support for
terraform import - zero_trust_casb_policy: reject at plan time configurations where
applies_to_all_integrationsisfalseand no integration IDs resolve. Existing policies that omitintegration_idsand retain IDs in state continue to plan normally.
Bug Fixes
- api_shield: add missing
normalizefield to v500 migration target model - bot_management: wire up AI Crawl Control fields in hand-maintained API plumbing
- bot_management: wire
ai_bots_migration_opt_outinto the API model - calls_turn_app: populate
key_idfrom the API'suidafter create, so plan, refresh, update and destroy no longer fail with "missing required key_id parameter" - d1_database: add missing fields to the v500 migration target model
- dns_record: default
include_shadow_metadatato false on import - logpush_dataset_field: deserialize the
fieldsresult map - logpush_job: add
decode_null_to_zerotofilter_attack_traffic - notification_policy: add missing
token_idto the v500 migration target model - observatory_scheduled_test: require replacement when
frequencyorregionchange, as the API has no update endpoint for scheduled tests - page_rule: send the API's
query_stringwildcard - schema_validation_schemas: default
omit_sourceto false on import - snippet_rules: remove stale and spurious top-level fields from the migration target model
- turnstile_widget: default
page/per_pageto their spec values on import - worker: remove
observability.redact_query_string - worker, worker_version: backfill author fields on create
- worker_version: exclude
exports_reconciliationfrom the v0 legacy schema - worker_version: add missing V0 fields to fix a migration test panic
- workers_kv: add missing
expiration/expiration_ttlto the v500 migration target model - workers_script: add missing
base_pathandobservability.issuesattributes - workers_script: add missing
streamattribute to the bindings schema - workers_script: add missing
forcefield to the legacy V0 migration struct - zero_trust_access_ai_controls_mcp_server: only send changed fields on update, so unrelated changes no longer resend and rotate
client_secret; redactauth_credentialsandclient_secretfrom debug logs - zero_trust_access_mtls_hostname_settings: import now takes an explicit
accounts/<account_id>orzones/<zone_id>prefix. Account and zone IDs are both 32-character hex, so the previous length-based detection always resolved to account scope and zone-scoped resources could not be imported. - zero_trust_device_custom_profile: stop split tunnel entries inheriting a mutually exclusive field from state, which caused "host and Address both cannot be present" API errors
- zero_trust_organization: add
warp_auth_non_browser_401to the v4 source model, unblocking v4 to v5 migration - zero_trust_organization: ignore
mfa_configuration_allowed/service_token_inactivityon import - zero_trust_organization: normalize
mfa_configuration_allowed,service_token_inactivity,trusted_accounts - zero_trust_organization: fix refresh-plan instability for 4 attributes
- zero_trust_tunnel_warp_connector: restore
hafrommetadata.haon import and read
Schema Changes (no action required)
Upstream Cloudflare API schema changes picked up via the cloudflare-go v7.12.0 bump. These are listed for completeness; none require a change to a working configuration.
Of the 54 removed attributes, 52 are read-only (computed): existing state files load without user action and plans are unaffected, so only configurations that reference them — in an output block or an expression — need updating. The two attributes that become Required were already mandatory server-side, so a request omitting them was always rejected; the failure simply moves from apply time to plan time. The one type change is on data sources only, and HCL converts numeric strings automatically.
- account_member, account_members, account_permission_group, account_permission_groups, account_token, account_tokens, api_token, api_tokens, user_group, user_groups: the generic
policies.permission_groups.meta.key/.valuepair has been replaced with typed fields —category,deprecated,description,editable,eol_at,label,scopes,visibility. Expressions readingmeta.key/meta.valuemust move to the named field. - hyperdrive_config, hyperdrive_configs:
integration.integrationhas been renamed tointegration.hyperdrive_config_provider. - queue, queues, queue_consumer, queue_consumers: the read-only
settings.email,settings.pagerdutyandsettings.webhooksdetail attributes are no longer surfaced on thecloudflare_queueresource or the queue data sources. Relatedly,notificationis no longer an accepted value for the read-onlyconsumers.typeattribute on those surfaces. Queue configuration is unaffected — thecloudflare_queue_consumerresource is unchanged and still accepts and manages all three settings blocks. - cloud_connector_rules:
rulesis nowRequiredinstead ofOptional. The API already rejects a request that omits it, so this moves the failure from apply time to plan time rather than breaking a working configuration. - zone_dns_settings:
nameservers.typeis nowRequiredinstead ofOptional.nameserversbecame a discriminated union upstream andtypeis its discriminator, so it was already mandatory in practice. - flagship_flag, flagship_flags:
limitchanged fromStringtoInt64and is now constrained to between 1 and 200. These are data sources only, so there is no state to migrate, and HCL converts numeric strings automatically —limit = "10"continues to work.