Improvements
resource/spectrum_application
: Add support for port ranges (#745)
- New Resource:
cloudflare_custom_hostname
(SSL for SaaS) (#746)
Improvements
resource/access_application
: Add support forallowed_idps
and restricting which Identity Providers are associated with an Application (#734)resource/access_application
: Add support forauto_redirect_to_identity
(#730)resource/access_application
: Add CORS support (#725)resource/cloudflare_custom_ssl
: Allowgeo_restrictions
to benil
and not included in the request payload (#714)datasource/cloudflare_zones
: Filtering is now performed on the server side and thename
parameter is no longer a regex. Instead,name
is a string to match on andmatch
is a regex. See the website documentation for more examples and updated references (#708)
- New Resource:
cloudflare_waf_override
(#691)
Improvements
resource/cloudflare_argo
: Allowtiered_caching
andsmart_routing
to be toggled individually allowing for entitlement differences (#703)resource/cloudflare_page_rule
: Add support forcache_ttl_by_status
(#706)resource/cloudflare_worker_script
: Add support forplain_text
andsecret_text
bindings (#710)
Fixes
resource/cloudflare_record
: UpdateTestAccCloudflareRecord_LOC
test asserted value to use less precise floats and match the API responses (#712)resource/cloudflare_record
: UpdateTestAccCloudflareRecord_Basic
testmetadata
attributes to match updated API payload (#713)
- New Resource:
cloudflare_byo_ip_prefix
(#671) - New Resource:
cloudflare_logpull_retention
(#678) - New Resource:
cloudflare_healthcheck
(#680)
Improvements:
resource/cloudflare_worker_route
: Improve documentation to mention usingaccount_id
for the underlying APIs (#669)resource/cloudflare_worker_script
: Improve documentation to mention usingaccount_id
for the underlying APIs (#670)resource/cloudflare_load_balancer_pool
: Improve documentation to mentionnotification_email
accepts a comma delimited list of emails (#687)resource/cloudflare_page_rule
: Add support forcache_key_fields
Page Rule action (#662)
Fixes:
resource/cloudflare_zone_settings_override
: Fix regression where if you didn't have universal SSL settings defined, it would error when setting them (#663)resource/cloudflare_zone
: Handle changing zone rate plan from "free" to "enterprise" (#668)resource/cloudflare_record
: Update validation to allow PTR records (9a8fd43)
Improvements:
resource/cloudflare_zone_settings_override
: Adduniversal_ssl
to control enablement of Universal SSL on a zone (#658)- provider: API keys and API tokens are now validated to help differentiate incorrect usage before making API calls (#661)
resource/cloudflare_logpush_job
: Add support for "firewall_events" dataset parameter (#660)resource/cloudflare_logpush_job
: Add support for "dataset" parameter (#649)resource/cloudflare_zone_settings_override
: Removeedge_cache_ttl
(#654)resource/cloudflare_access_group
: Allow Access conditions forinclude
/require
/exclude
to be used consistently between Access Groups and Access Policies (#646)
Fixes:
resource/cloudflare_logpush_job
: fix forstrconv.Atoi: parsing ""
error while creating Logpush job
Improvements:
resource/cloudflare_zone_settings_override
: Updateimage_resizing
options to include"open"
(#639)
Fixes:
resource/cloudflare_access_group
: Fixed misspelt Okta in JSON payload (cloudflare/cloudflare-go#440)
Improvements:
resource/cloudflare_access_policy
: Add support forservice_token
andany_valid_service_token
(#612)resource/cloudflare_waf_group
: Handle WAF group deletions in the API responses (#623)resource/cloudflare_waf_package
: Handle WAF package deletions in the API responses (#623)resource/cloudflare_waf_rule
: Handle WAF rule deletions in the API responses (#623)resource/cloudflare_access_policy
: Add support forgroup
(#626)resource/cloudflare_firewall_rule
: Add support for bypassing specificproducts
(#630)resource/cloudflare_spectrum_application
: Add support foredge_ips
,argo_smart_routing
andedge_ip_connectivity
(#631)resource/cloudflare_access_group
: Add support for using external providers (gsuite
,github
,azure
,okta
,saml
,mTLS certificate
,common name
) (#633)
Improvements:
resource/cloudflare_logpush_job
: SupportImport
on the resource (#618)
Fixes:
resource/cloudflare_record
: Missing CAA in DNS validation (#619)
Improvements:
resource/cloudflare_record
: Stricter validation for record types (#610)resource/logpush_job
: Add more verbose error handling (#564)resource/zone_settings_override
: Update documentation forcache_level
values (#606)resource/access_application
: Add documentation for available attributes (#587)resource/cloudflare_firewall_rule
: Add support for bypassing security configuration rules by URL (#568)resource/cloudflare_record_migrate
: Usezone_id
for state migration before attempting to usedomain
(#566)resource/cloudflare_load_balancer
: Updatesession_affinity
validation to allow"ip_cookie"
(#573)datasource/ip_ranges
: Update documentation to show 0.12 syntax (#617)
Fixes
resource/zone_settings_override
: Handle individual zone settings withinDelete
operations (#599)
- New Resource:
cloudflare_origin_ca_certificate
(#547)
Fixes:
resource/cloudflare_zone_settings_override
: Renamed0rtt
tozero_rtt
to conform to HCL grammar requirements (#557)
Improvements:
resource/cloudflare_access_rule
: Addip6
as valid option (#560)resource/cloudflare_spectrum_application
: Swapproxy_protocol
to string field with supporting enum values instead (#561)resource/cloudflare_waf_rule
: Addpackage_id
as valid option and exportgroup_id
(#552)
Improvements:
resource/cloudflare_zone_settings_override
: Addnon_identity
to alloweddecision
schema (#541)resource/cloudflare_zone_settings_override
: Add support for0rtt
andhttp3
settings (#542)resource/cloudflare_load_balancer_monitor
: Allow empty string forexpected_body
(#539)resource/cloudflare_worker_script
: Add support for Worker KV Namespace Bindings (#544)data_source/waf_rules
,resource/cloudflare_waf_rule
, Support allowed modes for WAF Rules (#550)
Fixes:
resource/cloudflare_spectrum_application
: Spectrum origin_port is optional (#549)
- New datasource:
cloudflare_waf_rules
(#525)
Improvements:
resource/cloudflare_zone
: Exposeverification_key
for partial setups (#532)resource/cloudflare_worker_route
: Enable API Tokens support from upstream cloudflare-go release
- New Resource:
cloudflare_access_service_tokens
(#521) - New Resource:
cloudflare_waf_package
(#475) - New Resource:
cloudflare_waf_group
(#476) - New datasource:
cloudflare_waf_groups
(#508) - New datasource:
cloudflare_waf_packages
(#509)
Fixes:
resource/cloudflare_page_rule
: Seth2_prioritization
individually not via bulk endpoint (#493)resource/cloudflare_zone_settings_override
: Setzone_id
to prevent unnecessary re-creation of resources (#502)
Improvements:
resource/cloudflare_spectrum_application
: Add support for settingtraffic_type
(#481)resource/cloudflare_zone_settings_override
: Update documentation with default values (#498)
Internals:
- Migrated to Terraform plugin SDK (#489)
Breaking changes:
provider/cloudflare
:- renamed
token
toapi_key
- renamed
org_id
toaccount_id
- removed
use_org_from_zone
, you need to explicitly specifyaccount_id
- Environment variables:
- renamed
CLOUDFLARE_TOKEN
toCLOUDFLARE_API_TOKEN
- renamed
CLOUDFLARE_ORG_ID
toCLOUDFLARE_ACCOUNT_ID
- removed
CLOUDFLARE_ORG_ZONE
, you need to explicitly specifyCLOUDFLARE_ACCOUNT_ID
- Changed the following resources to require Zone ID:
cloudflare_access_rule
cloudflare_filter
cloudflare_firewall_rule
cloudflare_load_balancer
cloudflare_page_rule
cloudflare_rate_limit
cloudflare_record
cloudflare_waf_rule
cloudflare_worker_route"
cloudflare_zone_lockdown
cloudflare_zone_settings_override
- Workers single-script support removed
Please see Version 2 Upgrade Guide for details.
Improvements:
cloudflare/resource_cloudflare_argo
: Handle errors when fetching tiered caching + smart routing settings (#477)- Various documentation updates for 0.12 syntax
Fixes:
resource/cloudflare_load_balancer
: Markzone
as Computed to allow deprecations (#462)resource/cloudflare_page_rule
: Markzone
as Computed to allow deprecations (#462)resource/cloudflare_rate_limit
: Markzone
as Computed to allow deprecations (#462)resource/cloudflare_waf_rule
: Markzone
as Computed to allow deprecations (#462)resource/cloudflare_worker_route
: Markzone
as Computed to allow deprecations (#462)resource/cloudflare_worker_script
: Markzone
as Computed to allow deprecations (#462)resource/cloudflare_zone_lockdown
: Markzone
as Computed to allow deprecations (#462)
Fixes:
resource/cloudflare_page_rule
: Fix a logic condition where settingedge_cache_ttl
action but then not updating it in subsequentapply
runs causes it to be blown away (#453)
Improvements:
- provider: You can now use API tokens to authenticate instead of user email and key (#450)
resource/cloudflare_zone_lockdown
:priority
can now be set on the resource (#445)resource/cloudflare_custom_ssl
: Updated website documentation navigation to include link for resource (#442))
Deprecations:
resource/cloudflare_access_rule
:zone
has been superseded by usingzone_id
(#452)resource/cloudflare_filter
:zone
has been superseded by usingzone_id
(#452)resource/cloudflare_firewall_rule
:zone
has been superseded by usingzone_id
(#452)resource/cloudflare_load_balancer
:zone
has been superseded by usingzone_id
(#452)resource/cloudflare_page_rule
:zone
has been superseded by usingzone_id
(#452)resource/cloudflare_rate_limit
:zone
has been superseded by usingzone_id
(#452)resource/cloudflare_waf_rule
:zone
has been superseded by usingzone_id
(#452)resource/cloudflare_worker_route
:zone
has been superseded by usingzone_id
(#452)resource/cloudflare_worker_script
:zone
has been superseded by usingzone_id
(#452)resource/cloudflare_zone_lockdown
:zone
has been superseded by usingzone_id
(#452)
Fixes:
- Partially revert [#421] deprecation messages
Removals:
resource/cloudflare_zone_settings_override
:sha1_support
has been removed due to Cloudflare no longer supporting SHA1 certificates or the API endpoint (#415)
Deprecations:
resource/cloudflare_zone_settings_override
:tls_1_2_only
has been superseded by usingmin_tls_version
instead (#405)resource/cloudflare_access_rule
:zone
has been superseded by usingzone_id
(#421)resource/cloudflare_filter
:zone
has been superseded by usingzone_id
(#421)resource/cloudflare_firewall_rule
:zone
has been superseded by usingzone_id
(#421)resource/cloudflare_load_balancer
:zone
has been superseded by usingzone_id
(#421)resource/cloudflare_page_rule
:zone
has been superseded by usingzone_id
(#421)resource/cloudflare_rate_limit
:zone
has been superseded by usingzone_id
(#421)resource/cloudflare_waf_rule
:zone
has been superseded by usingzone_id
(#421)resource/cloudflare_worker_route
:zone
has been superseded by usingzone_id
(#421)resource/cloudflare_worker_script
:zone
has been superseded by usingzone_id
(#421)resource/cloudflare_zone_lockdown
:zone
has been superseded by usingzone_id
(#421)
Improvements:
- New Resource:
cloudflare_custom_ssl
(#418) resource/cloudflare_filter
: Strip all surrounding whitespace from filter expressions to match API responses (#361)resource/cloudflare_zone
: Support unicode zone name values (#412)resource/cloudflare_page_rule
: Allow settingorigin_pull
for SSL (#430)resource/cloudflare_load_balancer_monitor
: Add TCP support for load balancer monitor (#428)
Fixes:
resource/cloudflare_logpush_job
: Update documentation (#395)resource/cloudflare_zone_lockdown
: Fix: examples in documentation (#407)resource/cloudflare_page_rule
: Set nil on changed string-based Page Rule actions
Fixes:
resource/cloudflare_page_rule
: Fix regression inbrowser_cache_ttl
where the value was sent as a string instead of an integer to the remote (#390)
Improvements:
resource/cloudflare_zone_settings_override
: Add support forh2_prioritization
andimage_resizing
(#381)resource/cloudflare_load_balancer_pool
: Update IP range for tests to not use reserved ranges (#369)
Fixes:
resource/cloudflare_page_rule
: Fix issues withbrowser_cache_ttl
defaults and when value is0
(for Enterprise users) (#379)
- The provider is now compatible with Terraform v0.12, while retaining compatibility with prior versions. (#309)
Improvements:
- New Resource:
cloudflare_argo
Manage Argo features (#304) cloudflare_zone
: Support management of partial zones (#303)cloudflare_rate_limit
: Updatemodes
documentation (#293)cloudflare_load_balancer
: Allow steering policy of "random" (#329)
Fixes:
cloudflare_page_rule
- Allow settingbrowser_cache_ttl
to 0 (#293)cloudflare_page_rule
- Swap to completely replacing rules (#338)
Improvements
- New Resource:
cloudflare_logpush_job
(#287) cloudflare_zone_settings
- Remove option to togglealways_on_ddos
(#253)cloudflare_page_rule
- Update documentation to clarify "0" usagecloudflare_zones
- Return zone ID and zone name (#275)cloudflare_load_balancer
- Addenabled
field (#208)cloudflare_record
- validators: Allow PTR DNS records (#283)
Fixes:
cloudflare_custom_pages
- Use correct casing forzone_id
lookupscloudflare_rate_limit
- Makecorrelate
optional and not flap in state management (#271)cloudflare_spectrum_application
- Fixed integration tests to work (#275)cloudflare_page_rule
- Better track field changes inactions
resource. (#107)
Improvements:
- provider: Enable request/response logging (#212)
- resource/cloudflare_load_balancer_monitor: Add validation for
port
(#213) - resource/cloudflare_load_balancer_monitor: Add
allow_insecure
andfollow_redirects
(#205) - resource/cloudflare_page_rule: Updated available actions documentation to match what is available (#228)
- provider: Swap to using go modules for dependency management (#230)
- provider: Minimum Go version for development is now 1.11 (#230)
Fixes:
- resource/cloudflare_record: Read
data
back from API correctly (#217) - resource/cloudflare_rate_limit: Read
correlate
back from API correctly (#204) - resource/cloudflare_load_balancer_monitor: Fix incorrect type cast for
port
(#213) - resource/cloudflare_load_balancer: Make
steering_policy
computed to avoid spurious diffs (#214) - resource/cloudflare_load_balancer: Read
session_affinity
back from API to make import work & detects drifts (#214)
Improvements:
- New Resource:
cloudflare_spectrum_app
(#156) - New Data Source:
cloudflare_zones
(#168) cloudflare_load_balancer_monitor
- Add optionalport
parameter (#179)cloudflare_page_rule
- Improved documentation forpriority
attribute (#182], missingexplicit_cache_control
[#185)cloudflare_rate_limit
- Addchallenge
andjs_challenge
rate-limit modes (#172)
Fixes:
cloudflare_page_rule
- Page rulezone
attribute change to trigger new resource (#183)
Improvements:
cloudflare_zone_settings_override
- Addopportunistic_onion
zone setting support (#170)cloudflare_zone
- Add ability to set zone plan (#160)
Fixes:
cloudflare_zone
- Allow zones to be properly imported (#157)cloudflare_access_policy
- Match access_policy argument requisites with reality (#158)cloudflare_filter
- Allowzone_id
to setzone
and vice versa (#162)cloudflare_firewall_rule
- Allowzone_id
to setzone
and vice versa (#174)cloudflare_access_rule
- Ensurezone
andzone_id
are always set (#175)- Minor documentation fixes
Improvements:
- New Resource:
cloudflare_access_application
(#145) - New Resource:
cloudflare_access_policy
(#145) cloudflare_load_balancer
- Add steering policy support (#147)cloudflare_load_balancer
- Supportsession_affinity
(#153)cloudflare_load_balancer_pool
- Supportweight
(#153)
Fixes:
cloudflare_record
- Compare name without the zone name (#151)- Minor documentation fixes (#149] [#152)
Improvements:
- New Resource:
cloudflare_zone
(#58) - New Resource:
cloudflare_custom_pages
(#132) cloudflare_zone_settings_override
- Allow setting SSL level to Strict (SSL-Only Origin Pull) (#122)- Update provider usage/build docs and how to update a dependency (#138)
- Improve
Building The Provider
instructions (#143) cloudflare_access_rule
- Make importable for all rule types (#141)cloudflare_load_balancer_pool
- ImplementUpdate
(#140)
Fixes:
cloudflare_rate_limit
- Documentation fixes for markdown where _ALL_ is italicized (#125)cloudflare_worker_route
- Correctly setmulti_script
on Enterprise worker imports (#124)account_member
- Ignore role ID ordering (#128)cloudflare_rate_limit
- Origin traffic isn't default anymore (#130)cloudflare_rate_limit
- Update rate limit validation to allow1
(#129)cloudflare_record
- Add validation to ensure TTL is not set whileproxied
is true (#127)- Updated code for provider version in User-Agent
cloudflare_zone_lockdown
- Fix import of zone lockdowns (#135)
Improvements:
- New Resource:
cloudflare_account_member
(#78)
Improvements:
- New Resource:
cloudflare_filter
- New Resource:
cloudflare_firewall_rule
Improvements:
- New Resource:
cloudflare_zone_lockdown
(#115)
Fixes:
- Send User-Agent header with name and version when contacting API
cloudflare_page_rule
- Fix page rule polish (off, lossless or lossy) (#116)
Improvements:
Improvements:
- New Resource:
cloudflare_access_rule
(#64)
Fixes:
cloudflare_zone_settings_override
- Change Zone Settings Override to use GetOkExists (#107)
Improvements:
- New Resource:
cloudflare_waf_rule
(#98) cloudflare_zone_settings_override
- Addoff
as Security Level setting (#99)resource_cloudflare_rate_limit
- Add nat support (#96)resource_cloudflare_zone_settings_override
- Addzrt
as a value for thetls_1_3
setting (#106)- Minor documentation improvements
Fixes:
cloudflare_record
- Setting a DNS record'sproxied
flag to false stopped working (#103)
FIXES:
cloudflare_ip_ranges
- IPv6 CIDR blocks should return IPv6 addresses (#51)cloudflare_zone_settings_override
- Allow0
forbrowser_cache_ttl
(#71)cloudflare_page_rule
-forwarding_urls
in page rules are lists (#79)cloudflare_page_rule
- The API supportsactive
anddisabled
, notpaused
(#84)
IMPROVEMENTS:
cloudflare_zone_settings_override
- Add support formin_tls_version
(#72)cloudflare_page_rule
- Add support for more settings:bypass_cache_on_cookie
,cache_by_device_type
,cache_deception_armor
,cache_on_cookie
,host_header_override
,polish
,explicit_cache_control
,origin_error_page_pass_thru
,sort_query_string_for_cache
,resolve_override
,respect_strong_etag
,response_buffering
,true_client_ip_header
,mirage
,disable_railgun
,cache_key
,waf
,rocket_loader
,cname_flattening
(#68], [#81], [#85)cloudflare_page_rule
- Addoff
setting tosecurity_level
(#81)cloudflare_record
- DNS Record improvements (#97)- Various documentation improvements
BACKWARDS INCOMPATIBILITIES / NOTES:
- resource/cloudflare_record: Changing
name
ordomain
now force a recreation of the record (#29)
FEATURES:
- New Resource:
cloudflare_rate_limit
(#30) - New Resource:
cloudflare_page_rule
(#38) - New Resource:
cloudflare_load_balancer
(#40) - New Resource:
cloudflare_load_balancer_pool
(#40) - New Resource:
cloudflare_zone_settings_override
(#41) - New Resource:
cloudflare_load_balancer_monitor
(#42) - New Data Source:
cloudflare_ip_ranges
(#28)
IMPROVEMENTS:
- resource/cloudflare_record: Validate
TXT
records (#14) - resource/cloudflare_record: Add
data
input to suppport SRV, LOC records (#29) - resource/cloudflare_record: Add computed attributes
created_on
,modified_on
,proxiable
, andmetadata
to records (#29) - resource/cloudflare_record: Support import of existing records (#36)
- New Provider configuration options for API rate limiting (#43)
- New Provider configuration options for using Organizations (#40)
NOTES:
- Same functionality as that of Terraform 0.9.8. Repacked as part of Provider Splitout