Showing 1–20 of 58 dossiers

Cloudflare Containers can now let each Durable Object choose its own runtime — and snapshot its filesystem

The architectural shift is from application-wide container configuration toward individually managed stateful compute. A Durable Object can now start its own image and size, keep an independent lifecycle and restore filesystem state without treating every instance as part of one rollout.

Cloudflare Containers exposed previous tenants’ disk data through unzeroed blocks

This was not a Firecracker escape or access to a live victim disk. It was a storage-isolation failure underneath the sandbox: researchers recovered foreign directory structures, database pages and complete SQLite databases from reused blocks, and Cloudflare had to fix allocation plus retire existing disks and cached snapshots.

Cloudflare Worker Previews gives every Git branch its own isolated runtime

Branch previews are common for frontend code, but Worker Previews extends the boundary to the runtime itself. Each branch can have independent bindings, state and logs, making parallel human and agent work safer while preserving a production-like execution path.

Cloudflare makes Python Workers GA — with Hyperdrive and first-class platform bindings

The Hyperdrive integration was the practical database unlock; the larger September 21 change is that Python Workers themselves are now GA. Cloudflare is explicitly positioning Python as a production language on Workers, with native platform bindings and framework support rather than an experimental compatibility layer.

Cloudflare Browser Run can now hard-limit agent sessions to approved hostnames

The useful change is containment rather than another browser-agent feature. Teams can let an agent operate a real browser while constraining its HTTP and HTTPS reach to the site and dependencies the task actually needs, reducing the blast radius of prompt injection, bad tool decisions or untrusted page content.

Vercel Sandbox expands from four regions to all 20 — with ordered failover

For agent and untrusted-code workloads, the useful change is not simply lower latency. Sandbox location becomes an explicit execution policy, so teams can align code execution with nearby data and avoid a resilience fallback quietly moving work outside an allowed region.

Kubernetes 1.37 moves more cluster operations into the core platform

The release consolidates several recurring cluster-management jobs into core APIs and controllers. HPA scale-to-zero is now default-on Beta, storage-version migration and Pod Certificates are Stable, DRA can satisfy existing extended-resource requests, and large etcd reads gain a streaming path that reduces peak memory pressure.

Cloud platforms offer broad capability, but the important details are spread across service pages, regional tables, quotas and pricing calculators. A new service may reduce engineering work, create a fresh dependency or simply rename a capability that already existed elsewhere.

BTN follows major platform developments when they change an architectural or commercial decision. Coverage connects announcements with documentation, limits, regional availability and credible operating experience. It is written for teams that need the useful consequence rather than a tour of every product keynote. The goal is to understand what becomes possible, what it will cost and which trade-offs remain after the launch presentation ends.

Provider strategy matters when a convenient service becomes the default path into a broader ecosystem. BTN watches portability, deprecation and the points where discounts or credits hide the steady-state bill. A managed service can still be the right choice; the dependency should simply be understood before it becomes difficult to unwind.