Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

The latest wire

Publisher updates

A useful brief, clear publisher credit, and a direct link to every full article.

Cloud
Conceptual illustration of a cloud above connected islands of computing infrastructure.
AI-generated illustration Conceptual artwork

Workers - Python and JavaScript Workers can now call each other via RPC

From the publisher

You can now call methods between Python and JavaScript Workers using Workers RPC. This works through Service bindings without extra dependencies, schema definitions, or serialization code. Cross-language RPC calls behave like ordinary function calls. Exceptions propagate to the call site. You can pass structured cloneable types ↗︎ as parameters or return values, and Pyodide Foreign Function Interface (FFI) automatically converts types between languages.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Infrastructure

Kubernetes v1.37 Sneak Peek

From the publisher

As we get closer to the release date for Kubernetes v1.37, the project develops and matures, features may be deprecated, removed, or replaced with better ones for the project's overall health. This blog outlines some of the planned changes for the Kubernetes v1.37 release that the release team feels you should be aware of for the continued maintenance of your Kubernetes environment and keeping up to date with the latest changes. The information below reflects the current status of the v1.37 release and may change before the actual release date. Deprecations and removals for Kubernetes v1.37Kubectl: kubectl run --filename/-f to be deprecated The --filename (or -f) flag for kubectl run is being deprecated as the generated pod is always built purely from CLI arguments like NAME and --image. See kubernetes/kubernetes#138671 for the original issue and discussion.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Workers, Durable Objects - Inspect Worker startup performance with Wrangler

From the publisher

wrangler check startup now reports your Worker's raw and compressed bundle sizes. It also summarizes local CPU activity during startup directly in your terminal. Large bundles and costly startup work can introduce cold-start latency, so use this command to find code and large dependencies that slow your Worker before it handles requests. The summary includes sampled, active, garbage collection, and idle time. Wrangler continues to save a .cpuprofile file for detailed flamegraph analysis in Chrome DevTools or VS Code. ⛅️ wrangler 4.116.0 ─────────────────────────────────────────────── ├ Building your Worker │ Worker Built!

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Workers - Node.js 24 is now the default for Workers Builds

From the publisher

Workers Builds now uses Node.js 24.18.0 by default. The build image preinstalls Node.js 22.23.2 and 24.18.0. You can continue to override the default with the NODE_VERSION environment variable, an .nvmrc file, or a .node-version file. For more information, refer to Override default versions.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Infrastructure

How the controller-runtime Cache Actually Works, and Why Your Controller Does Not Crash the API Server

From the publisher

This article has been revised since it was first published, to correct several significant technical inaccuracies in the original text. Kubernetes has long been the default platform for distributed workloads, and writing your own controller for it is now a matter of a few hours. The common path — Golang, using kubebuilder on top of controller-runtime — gives you a project scaffold, types, and a reconciler. For typical scenarios that is more than enough. But as soon as load grows or the controller starts behaving in ways you did not expect, a whole class of edge cases shows up. Most of them trace back to the same root cause: a fuzzy mental model of how controller-runtime works inside. If you write Kubernetes controllers in Go, this article should help you build a coherent picture and avoid expensive surprises in production.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Workers - Workers tracing — write custom spans with new startActiveSpan() and span.end() runtime APIs

From the publisher

The Workers runtime now provides built-in tracing.startActiveSpan() and span.end() APIs, allowing you to write custom spans for operations that last beyond a single callback — for example, instrumenting a stream pipeline where the span should stay open until the stream is fully consumed. This augments the existing API for writing custom spans, tracing.enterSpan(), which automatically ends a span when its callback is returned.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
AI
Conceptual illustration of connected computing systems and artificial intelligence.
AI-generated illustration Conceptual artwork

Workers AI - Select models now require the Workers Paid plan

From the publisher

We are limiting Workers Free plan access to a few resource-intensive models so we can prioritize capacity for the broader Workers AI user base. This helps everyone get a more reliable inference experience, with fewer 429 and 3040 (Out of Capacity) errors. The following models now require the Workers Paid plan: @cf/moonshotai/kimi-k2.6 @cf/moonshotai/kimi-k2.7-code @cf/zai-org/glm-5.2 On the Workers Free plan, requests to these models now return a 403 HTTP error (internal error 5035) prompting you to upgrade. The Workers Paid plan starts at $5 per month and still includes the 10,000 free Neurons per day allocation, with usage beyond that billed at each model's pricing. Many models remain available on the Workers Free plan, including: @cf/zai-org/glm-4.7-flash @cf/google/gemma-4-26b-a4b-it @cf/nvidia/nemotron-3-120b-a12b For the full list, refer to the Workers AI model catalog.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
AI

Agents, Workers - Cloudflare MCP servers support the new MCP 2026-07-28 Specification

From the publisher

Cloudflare's product-specific MCP servers now support the new MCP 2026-07-28 Specification. Each request runs on a fresh stateless server without an MCP protocol session or protocol-specific Durable Object. The /mcp endpoint also accepts stateless requests from 2025 Streamable HTTP clients. Most clients can reconnect without configuration changes. Use /mcp for new connections. Historical /sse URLs continue to work as aliases for the same Streamable HTTP handler, but they no longer serve the deprecated HTTP+SSE transport. If a client forces SSE transport, change it to Streamable HTTP or automatic transport detection.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Workers - Run integration tests against your Worker's production build

From the publisher

Wrangler now provides createTestHarness(), an API for running integration tests against Workers built with Wrangler or the Cloudflare Vite plugin from any Node.js test runner. The test harness starts a local Worker server with helpers for dispatching requests, resetting storage, and inspecting runtime logs.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
AI

Agents, Workers - Agents SDK adds MCP Specification 2026-07-28 support

From the publisher

Agents SDK v0.20.0 adds client and server support for the MCP 2026-07-28 release candidate ↗︎. Workers can serve tools, prompts, resources, and elicitation without an MCP transport session or Durable Object. Agents can connect to both MCP 2026-07-28 servers and existing legacy servers. Client support The MCP client manager now uses @modelcontextprotocol/client. For each connection, it probes for MCP 2026-07-28 support with server/discover. If the server does not support the stateless protocol, the client continues with the legacy initialize handshake on the same connection. Existing addMcpServer calls do not need a protocol-version setting or separate clients for each protocol generation. For stateless requests, elicitation uses input_required through multi-round-trip requests (MRTR). The legacy path uses the same form and URL handlers for pushed requests.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Workers, Durable Objects - Filter Durable Object logs and traces by instance ID

From the publisher

Workers Logs and OpenTelemetry spans for Durable Object requests include the Durable Object instance ID. Use $workers.durableObjectId to filter logs for a specific instance. Root and child spans include the same ID in cloudflare.durable_object.id. Use these fields to isolate a specific instance and correlate its logs and traces. For more information, refer to Durable Objects metrics and analytics and Workers tracing spans and attributes.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

2026-009: Critical Vulnerabilities in Microsoft SharePoint

From the publisher

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
AI
Conceptual illustration of connected computing systems and artificial intelligence.
AI-generated illustration Conceptual artwork

Agents, Workers - Agents SDK reduces MCP schema conversion, adds exposure controls for MCP in Think and Code Mode SDK adds direct host APIs

From the publisher

This release reduces repeated MCP schema conversion and adds an opt-out for Think's automatic MCP tool exposure. It also lets non-AI-SDK hosts invoke the durable Code Mode runtime directly. Control direct MCP tool exposure in Think Agents SDK MCP clients now reuse converted input and output schemas while a live connection keeps the same tool catalog. This avoids converting every MCP JSON Schema to Zod again for each model turn. @cloudflare/think also adds includeMcpTools.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Billing, Workers - Budget alerts now on by default for Pay-as-you-go accounts

From the publisher

We are turning on budget alerts by default for eligible Pay-as-you-go accounts. If your account does not already have a budget alert, Cloudflare will create one for you with a $10 account-level threshold. Your default alert will enable at the turn of your next billing cycle, so it will not fire based on usage you have already incurred. We are rolling this out in cohorts over the coming weeks, so eligible accounts may see their default alert appear at different times. The default alert behaves exactly like an alert you would create yourself. When your cumulative usage-based spend this cycle reaches the threshold, you receive an email notification. The alert is informational only. It does not cap your usage or impact your account in any way. Usage is processed once per day for the prior day's activity, so budget alerts fire the day after the threshold is reached rather than in real time.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Durable Objects, Workers - View total SQLite storage for Durable Object namespaces

From the publisher

You can now monitor the total SQLite storage used by a Durable Object namespace over time in the Cloudflare dashboard. The new Total storage chart shows the maximum storage reported during each hour. This helps you identify storage growth, validate data cleanup, and investigate unexpected usage. Go to Durable Objects ↗ The chart appears only for SQLite-backed Durable Object namespaces. It does not appear for namespaces that use the legacy key-value storage backend. Viewing storage for individual Durable Objects by ID or name is not supported. For more information, refer to Metrics and analytics.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Sonicwall Secure Mobile Access (15 juillet 2026)

From the publisher

Le 14 juillet 2026, Sonicwall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-15409 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Infrastructure

Building a Custom Metrics Exporter for Kubernetes

From the publisher

Kubernetes ships with built-in awareness of CPU and memory, but most real-world scaling decisions depend on signals that live entirely outside that narrow window: how many messages are waiting in a queue, how long the last batch job took, how many active WebSocket connections a pod is holding. When the built-in metrics are not enough, a metrics exporter bridges that gap. This post walks through writing one from scratch, packaging it as a container, and wiring it into a cluster so that Prometheus — and ultimately the HorizontalPodAutoscaler — can consume it. What a metrics exporter actually does An exporter is a small HTTP server with a single responsibility: expose application state as text on a /metrics endpoint. Prometheus scrapes that endpoint on a regular interval, stores the time-series data, and makes it available for queries, alerts, and autoscaling rules.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Workers - Platforms can now create Temporary Accounts via the Cloudflare API

From the publisher

Platforms can now create temporary preview accounts through the Cloudflare REST API. This lets your platform deploy a live Worker before the user signs in to Cloudflare. With the Temporary Accounts API, coding agents, AI app builders, and other platforms can build a similar flow for generated Workers and supported resources. Your platform can keep users in its onboarding flow while they generate, deploy, and test an application. Users do not need an existing Cloudflare account, and your platform does not need write access to one. The API returns a claim URL that lets the user make the temporary account and its resources permanent. Cloudflare Drop ↗︎ demonstrates this preview-and-claim pattern for static sites. Someone can upload a site, test and share it for one hour, then sign in or create an account only when they want to keep it.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
AI
Conceptual illustration of connected computing systems and artificial intelligence.
AI-generated illustration Conceptual artwork

Operating AI/ML Workloads on Kubernetes: A Headlamp Plugin for Kubeflow

From the publisher

Kubernetes has quietly become the default platform for AI and machine learning. Whether you run notebook servers for data scientists, schedule distributed training jobs, tune hyperparameters, or orchestrate multi-step ML pipelines, those workloads increasingly land on a Kubernetes cluster. Kubeflow is one of the most popular ways to assemble that stack, and it does so the Kubernetes-native way: every capability is exposed as a Custom Resource Definition (CRD). That design is a gift to cluster operators, because it means ML workloads can be observed and managed with the same primitives as everything else in the cluster. But in practice the specialized ML dashboards that ship with these platforms hide the Kubernetes layer underneath. When a notebook is stuck or a training run fails, the operator is often left dropping back to kubectl to find out what actually happened at the Pod level.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Infrastructure

Kubernetes Dashboard to Headlamp: A Step-by-Step Guide

From the publisher

1. Before you start: know what is changing Kubernetes Dashboard and Headlamp both show what is running in a cluster, but they work differently. When Headlamp runs on the desktop, it uses your existing kubeconfig to connect to one or more clusters and can be extended with plugins. When Headlamp runs inside a cluster, it uses a Kubernetes ServiceAccount to access the API and follow RBAC rules. Kubernetes Dashboard, in contrast, only runs in-cluster and always relies on service account tokens. Understanding these models early helps you choose the right setup and permissions. 1.1 How Kubernetes Dashboard works Dashboard is a web app that runs inside your cluster. You install it in the cluster, often with Helm. You usually run one Dashboard per cluster. You often reach it with kubectl port-forward or an ingress. You log in with a Bearer token. That token is often from a service account.

Source KubernetesCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
AI

Agents, Workers - Agents can respond to MCP elicitation requests

From the publisher

Agents connected to Model Context Protocol (MCP) servers with addMcpServer can now handle elicitation ↗︎ requests. Elicitation lets an MCP server request user input while it handles a tool call. Form mode collects structured, non-sensitive data. URL mode asks for consent before opening an out-of-band flow, such as third-party authorization or payment.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
AI

Workers AI - Plain text output for Markdown Conversion

From the publisher

The Markdown Conversion service now supports a new output conversion option that controls the format of the converted content. Set output.format to text to receive plain text with Markdown syntax removed. The default value is markdown, so existing conversions are unchanged. Use the env.AI binding: await env.AI.toMarkdown( { name: "page.html", blob: new Blob([html]) }, { conversionOptions: { output: { format: "text" }, }, }, ); await env.AI.toMarkdown( { name: "page.html", blob: new Blob([html]) }, { conversionOptions: { output: { format: "text" }, }, }, ); Or call the REST API: curl https://api.cloudflare.com/client/v4/accounts/{ACCOUNT_ID}/ai/tomarkdown \ -H 'Authorization: Bearer {API_TOKEN}' \ -F 'files=@index.html' \ -F 'conversionOptions={"output": {"format": "text"}}' When you request text output, the format field of each result is set to text.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Durable Objects, Workers - New Durable Object namespaces must use the SQLite storage backend

From the publisher

If your account does not already have a key-value (KV) backed Durable Object namespace, you can no longer create new ones. New Durable Object namespaces must use the SQLite storage backend, which has been recommended for all new Durable Objects since it became generally available ↗︎ in 2024. Create a new class with a new_sqlite_classes migration: { "$schema": "./node_modules/wrangler/config-schema.json", "migrations": [ { "tag": "v1", "new_sqlite_classes": [ "MyDurableObject" ] } ] } [[migrations]] tag = "v1" new_sqlite_classes = ["MyDurableObject"] SQLite-backed Durable Objects have feature parity with the key-value backend — including the key-value storage API — and additionally support relational SQL queries and point-in-time recovery to restore an object's storage to any point in the past 30 days.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Cloud

Workers - Send npm package dependency metadata with Worker uploads

From the publisher

Wrangler now collects npm package dependency information from your project's package.json during wrangler deploy and wrangler versions upload, and includes it in the upload metadata sent to the Cloudflare API. This data, each dependency's name, declared version range, and exact installed version, enables dependency analytics and future supply chain security features such as vulnerability alerting. To opt out, set dependencies_instrumentation.enabled to false in your Wrangler configuration file: { "dependencies_instrumentation": { "enabled": false } } [dependencies_instrumentation] enabled = false For more details, refer to Wrangler configuration.

Source Cloudflare DevelopersCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.