Fastly Terraform Provider (beta) 0.2.1
View this release on GitHub. ENHANCEMENTS: feat(docs): add intro content to the provider landing page (#151) Dependencies: build(deps): github.com/ProtonMail/go-crypto from 1.4.1 to 1.5.0 (#153)
View this release on GitHub. ENHANCEMENTS: feat(docs): add intro content to the provider landing page (#151) Dependencies: build(deps): github.com/ProtonMail/go-crypto from 1.4.1 to 1.5.0 (#153)
You can now configure DDoS Protection rules to challenge suspicious clients instead of blocking them outright. Challenging traffic helps legitimate users keep reaching your service during an attack while filtering out automated attack traffic. To use it, set a rule's action to client_challenge. The new action is also returned alongside default, block, log, and off when you list or retrieve rules.
View this release on GitHub. ENHANCEMENTS: feat(routing_config): add fastly_routing_config and fastly_routing_config_domain_link resources for managing Domain Management routing configs (automatic versioning) and linking them to domains (#1445) BUG FIXES: fix(acl-entries): clear unmanaged ACL entries from Terraform state (#1440) fix(dictionary-items): clear unmanaged dictionary items from Terrafor…
The Sustainability Dashboard metrics have been updated and independently validated: 2025 electricity emission factors are now used to calculate all Greenhouse Gas (GHG) emission metrics from January 1, 2025, onwards. The latest available Power Usage Effectiveness (PUE) data from colocation operators is now used to calculate non-IT equipment electricity consumption metrics from January 1, 2025, onw…
The Historical Stats API and the Real-Time Analytics API now support six metrics for tracking network protection. These cover packets and bytes sent via GRE tunnel, packets and bytes received for network protection, and packets and bytes dropped by the network protection firewall.
You can now configure Network Protect programmatically using the new Network Protect API. This API lets you register customer-owned IP prefixes, configure GRE delivery endpoints, manage reusable source prefix lists, and define ordered rules for filtering network-layer DDoS traffic.
View this release on GitHub. BREAKING: resource/fastly_service_vcl, resource/fastly_service_cdn_auto: renamed fastly_service_vcl to fastly_service_custom_vcl, and its corresponding nested vcl block on fastly_service_cdn_auto to custom_vcl (#127) ENHANCEMENTS: feat(docs): add a beta testing guide, and provider overview content explaining the resource families (#148) feat(logging_grafanacloudlogs):…
You can now assign multiple roles to a single automation token for fine-grained access control using the Automation Tokens API. This makes it easier to create tokens that combine permissions across different Fastly products, such as CDN management and Next-Gen WAF.
Upgraded to Golang 1.26.8 Updated base GeoIP data: September 2026
The Historical Stats API and the Real-Time Analytics API now support ten new metrics for troubleshooting Content Guard challenges. These metrics cover challenge and token creation, validation outcomes, and Private Access Token (PAT) challenges issued during Content Guard rule enforcement.
The Historical Stats API and the Real-Time Analytics API now track AI Firewall requests in AI Runtime Control via the new arc_ai_firewall_requests and arc_ai_firewall_blocked metrics.
The Product Enablement API now supports Client Challenge on our DDoS Protection product.
Breaking Changes Getters no longer throw. They will return null instead. Changed Merge in 3.x branch
The new Bot Management API lets you configure ContentGuard, which decides how Fastly responds to bot traffic. It is separate from the bot detection and rule features of the Next-Gen WAF API. Set an action for a category of bots, such as AI crawlers, search engines, or headless browsers. Any bot Fastly later adds to that category picks up the same action automatically. Override the action for an in…
You can now fetch bot time series metrics (served by ContentGuard) using the Historical Stats API. This makes it easier to analyze bot-protection data for individual services within your account.
The Historical Stats API and the Real-Time Analytics API now support ten new metrics for troubleshooting DDoS protection challenges. These metrics cover challenge and token creation, validation outcomes, and Private Access Token (PAT) challenges issued during DDoS protection rule enforcement.
View this release on GitHub. ENHANCEMENTS: feat(ai_runtime_control): add resources and data sources for managing AI Runtime Control (#1428) feat(product_enablement/ddos_protection): Add support for 'client_challenge' mode. (#1431) Dependencies build(deps): github.com/stretchr/testify from 1.11.1 to 1.12.0 (#1419) build(deps): golang.org/x/net from 0.57.0 to 0.58.0 (#1419) build(deps): github.com/f…
The Historical Stats and Real-Time Analytics APIs now track requests received by AI Runtime Control via the new arc_requests metric.
Added CoreCache.transactionLookupAsync (#1591) (8aeb1ac) Fixed Use the correct headers for the beforeSend HTTP cache hook (775c727) Use the correct headers for the beforeSend HTTP cache hook (#1590) (a4d6559)
View this release on GitHub. Enhancements: feat(service/logging): add Log Explorer and Insights commands (#1887) feat(ai-runtime-control): add support for AI Runtime Control (#1901) Dependencies: build(deps): golang.org/x/crypto from 0.54.0 to 0.55.0 (#1888) build(deps): golang.org/x/mod from 0.38.0 to 0.39.0 (#1888) build(deps): github.com/stretchr/testify from 1.11.1 to 1.12.0 (#1888) build(deps…
An unauthenticated Server-Side Template Injection (SSTI) vulnerability leading to remote code execution has been found in Adobe Commerce and Magento and has been assigned CVE-2026-75650. Fastly has created a virtual patch for it that is now available within your account. To activate it and add protection to your services, follow the steps for your control panel below. Next-Gen WAF control panel Fr…
The Event logs API now records Next-Gen WAF configuration changes no matter where they are made — through the Next-Gen WAF API, the Fastly control panel, the Next-Gen WAF control panel, or Terraform. Previously, only changes made through Fastly were recorded, so a workspace edited from the Next-Gen WAF control panel left no entry in your event log. All Next-Gen WAF event types are now documented a…
View this release on GitHub. ENHANCEMENTS: feat(logging_cloudfiles): add support for Cloudfiles Logging (#85) feat(rtsig_key): add fastly_tsig_key resource and fastly_tsig_keys data source (#83) feat(object_storage_access_keys): add resource for managing Fastly object storage access keys (#84) BUG FIXES: fix(logging): reject explicit empty string on defaulted format-like attributes (format, timest…
View this release on GitHub. BUG FIXES: resource/fastly_service_cdn_auto, resource/fastly_service_dynamic_vcl_snippet: add an optional content attribute to dynamic VCL snippet metadata (the dynamic_snippet block, and the standalone resource), seeded into the snippet on creation so a service whose main VCL includes a dynamic snippet can be created in one apply (#78).
View this release on GitHub. BUG FIXES: fix(docs): add a note to the provider index page clarifying that the -beta suffix applies only to the Registry distribution, not to resource or data source type names (#76)
View this release on GitHub. Initial beta release. Introduces the rewrite of the Fastly Terraform provider on the Plugin Framework, including: Automatic (_auto) service resources: nested config blocks with provider-managed version lifecycle (auto-clone, validate, activate on every CRUD). Service building blocks: domain, backend, ACL + ACL entries, config store + items, secret store, dictionary ite…
Fixed Close cache transaction if getOrSet handler throws (#1586) (5e7fc87) Commit cache transaction in SimpleCache.getOrSet (#1581) (7789f23)
Added Add clientSNI to FetchEvent.client (#1569) (9a85f2a) Fixed add test to verify includeBytes sandboxing (#1559) (8585d3a) Avoid arithmetic overflow in content_stream_read_then_handler (#1570) (b390de4) Avoid crashes if KV store list hostcall returns unexpected data (#1563) (e2e4c8b) Check for presence of environment variables before checking their values (#1555) (0e1779b) Cloning requests that…
fsthttp: add ComplianceRegion and RawHeaders to FastlyMeta fsthttp: fix reusing body and response handles with StatusEarlyHints internal: clean up abi type definitions fsthttp: export SendErrorDetailTag integration_tests: remove extra http requests from tests shielding: add first byte and between bytes timeouts fsthttp: add support for dynamic backend healthchecks Makefile,tools.mod: tooling upgra…
An authentication bypass vulnerability that can lead to administrative access has been found in Artifactory and has been assigned CVE-2026-82329. Fastly has created a virtual patch for it that is now available within your account. To activate it and add protection to your services, follow the steps for your control panel below. Next-Gen WAF control panel From the Rules menu, select Templated Rules…