Menu
InfoQ Architecture·October 10, 2026

Cloudflare Traces: Distributed Tracing for Proxy Layers with OpenTelemetry

Cloudflare Traces extends automatic distributed tracing to the proxy layer, transforming security rules, cache decisions, and routing into OpenTelemetry spans without manual instrumentation. This bridges a critical visibility gap in distributed systems, providing a unified request-level timeline. The service supports W3C trace context propagation and flexible sampling rules, enhancing observability for complex cloud architectures.

Read original on InfoQ Architecture

Bridging the Observability Gap at the Edge

Cloudflare Traces introduces a significant advancement in distributed system observability by automatically generating OpenTelemetry spans for actions occurring within its proxy layer. Traditionally, distributed traces would jump from a client directly to an application, leaving a 'black box' around critical intermediate steps like CDN caching, WAF rules, and routing decisions. Cloudflare Traces illuminates this black box, providing granular insights into the performance and behavior of requests at the edge infrastructure level.

Key Architectural Features and System Design Implications

  • Automatic Span Generation: Security rules, transformations, cache decisions, routing, Worker execution, and origin handling are automatically converted into OpenTelemetry spans.
  • W3C Trace Context Propagation: Traces accept and forward W3C traceparent headers, allowing Cloudflare spans to seamlessly integrate into existing distributed traces that span multiple services and environments. This is crucial for end-to-end visibility across heterogeneous systems.
  • Configurable Sampling Rules: Teams can define baseline sampling rates and create specific Trace Rules to override these rates for matching traffic (e.g., specific hostnames, IPs, or debug headers). This allows for targeted tracing during investigations without overwhelming the observability backend.
  • OpenTelemetry Export: Spans are exported over OTLP to any compatible backend, reinforcing Cloudflare's commitment to open standards and data portability across different observability tools.
💡

Why Proxy Layer Tracing Matters

Understanding the latency and behavior within infrastructure components like CDNs, WAFs, and API Gateways is vital for troubleshooting performance issues, identifying security bottlenecks, and optimizing resource utilization in distributed systems. Without it, diagnosing problems often devolves into correlating disparate logs and guessing at root causes. This capability significantly improves MTTR (Mean Time To Resolution).

The shift to volume-based pricing rather than span-based pricing encourages more intelligent sampling strategies, directly tying costs to the amount of data ingested and retained. This incentivizes architects to design effective sampling policies that capture critical data during investigations while minimizing costs during normal operations. Future enhancements include broader instrumentation across the HTTP request path, authenticated context propagation, and OpenTelemetry API support in Workers for custom span attributes, further enhancing its utility in complex system designs.

Example: Decomposing a Request with Cloudflare Traces

json
[
  {
    "span_name": "cloudflare_request",
    "attributes": {"http.method": "GET", "http.url": "/api/data"}
  },
  {
    "span_name": "cloudflare_security_rules",
    "parent_id": "cloudflare_request",
    "attributes": {"rule_id": "X-WAF-001", "decision": "allow", "duration_ms": 10}
  },
  {
    "span_name": "cloudflare_cache_lookup",
    "parent_id": "cloudflare_request",
    "attributes": {"cache.hit": false, "duration_ms": 5}
  },
  {
    "span_name": "cloudflare_origin_fetch",
    "parent_id": "cloudflare_request",
    "attributes": {"http.status_code": 200, "duration_ms": 527}
  },
  {
    "span_name": "application_service_a",
    "parent_id": "cloudflare_origin_fetch",
    "attributes": {"service.name": "UserService", "operation": "getUserProfile"}
  }
]
observabilitydistributed tracingOpenTelemetryCloudflareAPMproxyCDNmonitoring

Comments

Loading comments...