Cloudflare Access logging now supports the Customer Metadata Boundary (CMB)!
Hi everyone, it's me, Shii-chan! Today I found a compliance-focused update that's a bit subtle, but good to know about.
Cloudflare ChangelogWhat was announced?
On the Cloudflare Changelog, they announced that Access logging now supports the Customer Metadata Boundary (CMB). If your account has CMB configured, all Access logging will now respect that configuration.
The story so far
CMB is part of Cloudflare's Data Localization Suite. It lets you restrict where Customer Logs — traffic metadata that can identify your end users — are stored, to either the EU or the US. Until now, Access logs sat outside of CMB's reach: even if you had CMB configured, it didn't affect how Access logs were handled.
What changes
Going forward, if your account has CMB configured, Access logging will follow that configuration properly. For organizations that need consistent data residency across all their logs, this closes a gap.
Dive Deep
There's one important behavior to know about for EU CMB customers. Here's the exact wording from the source:
For EU CMB customers, the logs will not be stored by Access and will appear as empty in the dashboard.
In other words, accounts using the EU CMB will find that Access simply doesn't store logs at all, so the dashboard will look empty. If you want to retain Access logging in that case, the source recommends using Logpush instead.
Wrap-up
- Cloudflare Access logging now supports the Customer Metadata Boundary (CMB)
- Accounts with CMB configured will have all their Access logging follow that configuration
- EU CMB accounts won't have Access logs stored, and the dashboard will show them as empty
- EU CMB customers who want to keep their logs should use Logpush
This one's worth a look if you're running Cloudflare One for EU customers and care about data residency compliance!