What changed
On October 9, 2026 Cloudflare introduced on-demand CPU and heap-allocation profiling for deployed Workers and Durable Objects. Developers can request a capture through the dashboard, Cloudflare CLI or API, view interactive flamegraphs, and download pprof-compatible output. Captures target live loaded isolates and can select a specific named Durable Object. Official documentation permits capture windows of 1–50 seconds. Previously, profiling was limited to local DevTools sessions that could not reproduce production traffic conditions.
Why it matters
A deployed Worker can hit CPU or 128MB memory limits because of workload patterns invisible to local tests. Function-level profiling lets teams identify actual hot paths and allocation sources rather than guessing from aggregate usage metrics. Cloudflare's internal examples report a 2.7x improvement in one wasteful JSON function and a memory fix that lowered p999 usage from 133MB to 118MB, but these are vendor examples rather than universal performance gains. The feature is distinct from Cloudflare Traces, which follows request paths across services.
Profiling targets running production code
Developers select a Worker version or named Durable Object, request CPU or heap allocation profiling and inspect the resulting flamegraph. The CLI and API return pprof-compatible data for external analysis. Capturing does not start a new isolate, so the target must be actively receiving traffic.
Heap profiles measure allocations, not retained memory
Cloudflare samples allocation stack traces every 512KB allocated during the capture. It is not a heap snapshot and cannot determine which objects remain live. Startup allocations or rare failures outside the requested window will not appear.
Short capture windows and rate limits shape use
Documentation allows 1,000–50,000ms captures. The API rate-limits profiling requests with HTTP 429 and Retry-After; low-traffic Workers may have no loaded isolate to profile. Source maps should be enabled for readable TypeScript function names.
Cloudflare's own fixes demonstrate the debugging boundary
Cloudflare says its R2 binding team found redundant recursive JSON traversal and optimized that function by 2.7x. Another team used heap allocation profiles to remove disabled-but-still-running Prometheus instrumentation, reducing p999 memory from 133MB to 118MB. These are internal cases, not independent benchmarks.