Build1 publisher2 min readPublished
Cloudflare Traces records edge rule, cache and routing decisions as OpenTelemetry spans
Cloudflare has put Traces into open beta, recording each supported step a request takes through its edge as an OpenTelemetry span. The spans export to any OTLP endpoint, so edge decisions can sit in the tracing backend a team already runs.
The Engineer · Build desk

What happened
- Security rule spans record how long custom or managed rules took to evaluate and what action they took, and name the rule behind a block or challenge in span events.
- Tracing is switched on per domain in the dashboard, and Cloudflare generates the spans without any instrumentation, config or plugins from the customer.
- Cloudflare's example trace shows a cache miss that spent 527ms of its 539ms total getting a response from the origin.
- Traces builds on Workers Tracing, launched last year to auto-instrument Worker invocations and their calls to KV, R2, D1, Durable Objects and other Workers.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- capability A ticket about a challenged request can be answered from one timeline that names the acting rule next to the origin's timing, without matching up separate edge and origin logs by timestamp.
- constraint The post describes only W3C traceparent propagation, so teams that pass trace context in another header format have to confirm support or translate headers at the boundary before edge spans join their traces.
- cost Every traced request adds a span per supported edge step to whichever OTLP backend receives it, so the baseline rate is a budget setting as well as a debugging one.
Each supported step on the request path becomes a span with its timing, outcome and attributes [6]. The spans are specific. The `http_request_transform` span lists each change a Transform Rule made, the part of the request it touched and the rule responsible. It also shows where the rewrite happened relative to routing and origin handling [8]. The `workers_routing` span records whether a route matched, which routing type was used and the route pattern that matched [9].
If you have ever lined up a firewall log against an origin access log by timestamp, you know how that afternoon goes. Cloudflare presents the spans as the replacement for rebuilding a request from separate logs and configuration [6].
Propagation is what puts the edge inside someone else's trace. Cloudflare accepts and forwards W3C traceparent headers [3]. It says a trace can continue through services running on Cloudflare, at the origin, or elsewhere in the stack [16].
The post's cache-miss example is a useful sanity check. The origin accounts for all but 12ms of that request [1], or about 2% of the total [2]. That is one request, picked to show the view. On another site the split depends on cache hit rate and origin latency. A per-request trace shows that split for each request.
Sampling controls the cost. A baseline rate applies to the domain, and Trace Rules override it for matching traffic [5]. Cloudflare suggests tracing 1% of requests during normal operation [12]. At that rate, 99 of every 100 requests produce no trace [3]. A challenge that fires on one path a few times an hour will rarely land in a 1% sample. The workable setup is a low baseline plus a Trace Rule that raises the rate on the path you are investigating.
Coverage is the open question for the beta. When Cloudflare's own teams debug, they use internal traces that often hold thousands of spans for a single request, generated by dozens of services and features [14]. The public product covers supported security rules, transformations, cache decisions, routing, Worker execution and origin handling [2]. That list is shorter than the internal one.
I think the design is right. It emits standard spans, it propagates context in a standard header, and it needs no code from the customer [11]. Cloudflare wrote that the product is "a long-term investment in OpenTelemetry and in making Cloudflare the most observable part of your stack" [15].
What to watch
- Whether Cloudflare's sampler honors the sampled flag on an incoming traceparent, which decides whether edge and origin sampling decisions agree.
- Pricing for traced requests and OTLP export once Cloudflare Traces leaves open beta.
- Which of the operations behind Cloudflare's internal thousand-span traces join the supported set during the beta.