Track Google with a free Huntertech account. Get outage alerts, watchlists, and cross-vendor monitoring in one place.
Google updates
Release notes and changelog entries from the vendor feed. Refine with filters, then choose All, Recent to focus the list.
Product updates
All updates
Backup and DR
Feature
You can now change the backup plan associated with a Cloud SQL instance. This allows you to switch an instance to a different backup plan, provided the new plan uses the same backup vault and is in the same region as the instance. This feature is available through the Google Cloud console and gcloud CLI. To learn more, see Change the associated backup plan for a Cloud SQL instance.
BigQuery
Feature
You can now use cross-cloud connections to query data in AWS, Azure, and Salesforce Data 360 from all BigQuery regions. These connections let you use more BigQuery features and are more cost efficient than standard connections that use BigQuery Omni. This feature is in Preview.
Feature
The JDBC driver for BigQuery now supports OpenTelemetry for tracing and logging, which helps you monitor the performance of your database interactions and troubleshoot issues. Automatic exports to Google Cloud Observability are also available. This feature is generally available (GA).
Announcement
Support for hybrid search (using the VECTOR_SEARCH function to combine a
semantic search with a lexical (keyword) search) has been restored. Using
HYBRID mode in the AI.SEARCH function has also been restored.
Cloud SQL for MySQL
Change
You can change the backup plan for your Cloud SQL enhanced backups without first removing the existing plan. For more information, see Change your instance's associated backup plan.
Cloud SQL for PostgreSQL
Change
You can change the backup plan for your Cloud SQL enhanced backups without first removing the existing plan. For more information, see Change your instance's associated backup plan.
Cloud SQL for SQL Server
Change
You can change the backup plan for your Cloud SQL enhanced backups without first removing the existing plan. For more information, see Change your instance's associated backup plan.
Cloud Workstations
Change
Updated the following JetBrains preconfigured base images to version 2026.x:
- CLion 2026.1
- GoLand 2026.2
- IntelliJ Ultimate 2026.1
- PhpStorm 2026.2
- WebStorm 2026.1
- RubyMine 2026.1
- PyCharm 2026.1
- Rider 2026.1
Google Kubernetes Engine
Feature
TPU Subslicing (also known as Dynamic Subslicing) is now generally available for Ironwood (TPU7x). This feature enables you to incrementally provision node pools for a cube or litepod, breaking them into smaller slices (subslices) to run workloads requiring smaller topologies. Updates in this GA release include:
- Dynamic sub-slicing (topologies smaller than
4x4x4, such as2x2x1,2x2x2,2x2x4, and2x4x4): Supported in GKE version1.36.0-gke.3712000or later. - Dynamic super-slicing (topologies
4x4x4or larger): Supported in GKE version1.35.2-gke.1842000or later. - Partition Health Labels: The partition state label is updated to
cloud.google.com/gke-tpu-partition-[shape]-stateto specify smaller subslice shapes. It also introducesUNSETandINCOMPLETEstates. Support for theDEGRADEDstate only applies to the top-level4x4x4topology, and not for smaller sub-slicing topologies.
For more information, see About GKE dynamic slicing.
Google SecOps
Feature
[Spotlight Feature] Threat Hunt Agent
The Threat Hunt Agent is now available in Public Preview for Google SecOps Enterprise Plus customers. Powered by Gemini and grounded in Google Threat Intelligence (GTI), Mandiant frontline expertise, and the MITRE ATT&CK® framework, the Threat Hunt Agent autonomously automates proactive threat hunting across your historical security telemetry. For more information, see Threat Hunt Agent.
Key capabilities include:
- Autonomous hunt planning: Generates structured hunting plans tailored to specific threat actors, campaigns, malware families, software toolkits, or MITRE ATT&CK techniques.
- Automated case creation and determinations: Synthesizes findings into summaries, assigns a verdict (Substantial Evidence, Evidence Found, or Threat Not Found), and automatically creates a dedicated case in Case Management.
- Automated query translation and execution: Converts investigative hypotheses into YARA-L 2.0 search queries and executes against historical security telemetry.
- AI-driven evidence extraction: Filters out routine background noise to isolate high-fidelity forensic evidence (hostnames, user accounts, and command lines).
Google SecOps SIEM
Feature
[Spotlight Feature] Analyze feed activity with Cloud Logging
This feature is in public preview. You can now monitor, debug, and troubleshoot Google SecOps SIEM ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.
This visibility into push- and pull-based ingestion mechanisms lets you use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console. Additionally, you can use the Debug with logs option on the Feed management page to open Logs Explorer pre-filtered for a specific feed.
For more information, see Analyze feed activity with Cloud Logging.
Security Command Center
Feature
For the Security Command Center Standard tier, AI Protection is supported for both projects and organizations.
Project-level activations for the Standard tier include access to the AI security dashboard, basic inventory view (excluding Gemini models), and baseline security findings.
Some features of AI Protection are only available for the Premium and Enterprise tiers or for organization-level activations. For more information, see Configure AI Protection.
VPC Service Controls
Feature
Preview stage support for the following integration:
Virtual Private Cloud
Feature
Preview: You can create v2 IPv4 public advertised prefixes for bring your own IP addresses (BYOIP) that use Standard Tier IP addresses. For more information, see Network Service Tiers.
Google SecOps SOAR
Announcement
Release 6.3.96 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Google Cloud VMware Engine
Feature
Preview: Google Cloud VMware Engine capacity allocations are available in preview. A capacity allocation is a global reservation of physical nodes for your Cloud Billing account. Your reserved nodes are organized into placement groups (PGs), which represent the specific physical hardware and location of your reserved capacity.
Google Cloud VMware Engine capacity allocations let you do the following: * Use a capacity allocation during private cloud creation by selecting a PG. * Use a capacity allocation when adding a cluster. * Configure a hybrid private cloud across multiple PGs.
For more information, see Manage capacity allocations.
Google SecOps SOAR
Announcement
Release 6.3.95 is now available for all regions.
Apigee hybrid
Announcement
v1.15.7
On July 31, 2026 we released an updated version of the Apigee hybrid software, v1.15.7.
- For information on upgrading, see Upgrading Apigee hybrid to version v1.15.7.
- For information on new installations, see The big picture.
Feature
Runtime rollout strategy configuration
In this release, you can configure the rollout strategy used when updating runtime (message processor) ReplicaSets by setting the runtime.release.strategy property (with options rolling, scale-down-first, or none) or per-environment with envs[].components.runtime.release.strategy in your overrides configuration file. The property defaults to rolling.
Security
Various security and CVE fixes are included in this release.
Cloud Load Balancing
Feature
Cloud Load Balancing introduces a new version of the Network Load Balancer—the global external passthrough Network Load Balancer, which is the global variant of the regional external passthrough Network Load Balancer. The load balancer is available in Preview.
This load balancer variant solves use cases for Security Service Edge (SSE), DNS hosting, Adtech (real-time bidding), real-time communications (RTC), live streaming, and online gaming, among others.
Global external passthrough Network Load Balancers are Layer 4 passthrough load balancers that distribute external traffic among backends (instance groups or network endpoint groups) that can reside in multiple Google Cloud regions. By using Google's global anycast IP routing, the global external passthrough Network Load Balancer steers user traffic to the closest region with healthy backends and available capacity, delivering ultra-low latency and dynamic cross-region failover to ensure resilience to regional outages.
The load balancer provides you with two external IP addresses, each served by a disjoint and isolated global load balancing control and data plane server infrastructure (also known as an availability group) to provide high availability.
The load balancer supports TCP, UDP, ESP, GRE, ICMP, and ICMPv6 traffic and can handle both IPv4 and IPv6 traffic. You can deploy your backends in any of the following Google Cloud regions:
- North America:
us-west1,us-west4,us-east4,us-east5 - Europe:
europe-west2,europe-west3 - Asia:
asia-southeast1,asia-south1,asia-northeast1 - South America:
southamerica-east1 - Africa:
africa-south1 - Australia:
australia-southeast1
Note that this release doesn't support GKE backends for the global external passthrough Network Load Balancer.
For details on the new load balancer, see Global external passthrough Network Load Balancer overview.
Cloud SQL for MySQL
Change
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
Feature
QueryData adds support for parameterized secure views (PSVs) to help secure applications that use natural language queries. For more information, see Secure and control access to application data.
This feature is in Preview.
Cloud SQL for PostgreSQL
Change
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
Cloud SQL for SQL Server
Change
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
Feature
Cloud SQL for SQL Server now supports executing SQL statements using the Cloud SQL Data API.
Confidential VM
Security
Support for Intel TDX on c4-standard-* machine types is
available in Preview.
Contact Center AI Insights
Feature
Customer Experience Insights offers data tracing in Quality AI. This feature uses system events and metadata in conversation analysis to enhance the accuracy of Quality AI scorecards.
Dataflow
Feature
You can now pause a Dataflow batch job using the pause_on_failure
service option. This feature lets you preserve the state of your batch pipeline
job, address external issues, and resume processing without losing completed
work. You can use this option to automatically pause a job on failure, or use
this feature to manually pause a job when you chose to. For more information,
see Pause a Dataflow job.
Datastream
Feature
You can now replicate change data from Workday with Datastream. For more information, see Stream data from Workday.
This feature is in Preview.
Google Cloud Managed Service for Apache Kafka
Feature
You can generate synthetic data for a Managed Service for Apache Kafka cluster by using Dataflow. For more information, see Generate synthetic data for a Managed Service for Apache Kafka cluster.
Memorystore for Valkey
Feature
You can use custom organization policies to improve the security, compliance, and governance of your Memorystore for Valkey instances by enforcing consistent configurations and restrictions for the instances. This ensures that your instances adhere to security best practices and regulatory requirements. This feature is Generally Available.
Security Command Center
Feature
Organizations that are enrolled in the data residency Preview program can update their organization's data residency and data encryption configuration. For more information, see Modify data residency or data encryption configuration.
Feature
Agent Platform Vulnerability Assessment (Preview) scans for plaintext secrets, such as credentials, access tokens, and API keys, in customer-deployed Gemini Enterprise Agent Platform containers. For more information, see Agent Platform Vulnerability Assessment.
BigQuery
Feature
You can add tables, views, data sources, and data quality tests as tasks to BigQuery pipelines. For more information, see Add a pipeline task. This feature is generally available.
Feature
You can audit when users download query results by using the BigQuery
console. Data Access audit logs for the tabledata.list method now include a
uiDownloadRequest
field to indicate whether the request was triggered by a UI download.
This feature is
generally available
(GA).
Bigtable
Feature
You can use Bigtable as a remote storage backend for LMCache. By storing the large language model (LLM) key-value (KV) cache externally in Bigtable, multiple AI serving instances can share and reuse precomputed attention tensors. This reduces compute overhead and significantly improves time-to-first-token (TTFT) for repeated prompts and shared documents. This feature is in Preview.
Config Connector
Announcement
Config Connector version 1.154.1 is now available.
Feature
New Alpha Resources (Direct Reconciler):
ApigeeApiProduct- Manage Apigee API products to bundle APIs and make them available to developers.
ApigeeRegistryApi- Manage Apigee Registry APIs to catalog and manage APIs.
ApigeeRegistryArtifact- Manage Apigee Registry artifacts associated with APIs, versions, or specs.
APIHubExternalAPI- Manage API Hub external APIs to track APIs hosted outside of Google Cloud.
APIHubInstance- Manage API Hub instances to enable enterprise API management.
AppOptimizeReport- Manage App Hub Optimize reports.
ArtifactRegistryVPCSCConfig- Manage Artifact Registry VPC Service Controls configurations to secure repository access.
BigQueryMigrationMigrationWorkflow- Manage BigQuery Migration workflows to orchestrate data migration to BigQuery.
BlockchainNodeEngineBlockchainNode- Manage Blockchain Node Engine blockchain nodes to deploy and manage dedicated blockchain nodes.
CCInsightsConversation- Manage Contact Center Insights conversations to analyze customer interactions.
CCInsightsIssueModel- Manage Contact Center Insights issue models to categorize conversation topics.
CCInsightsPhraseMatcher- Manage Contact Center Insights phrase matchers to detect specific phrases in conversations.
CESAppCloudBuildConnection- Manage Cloud Build 2nd gen connections to integrate external source repositories.
CloudSecurityComplianceFrameworkConnectorsConnection- Manage Integration Connectors connections to connect to SaaS, databases, and enterprise systems.
ContentWarehouseDocument- Manage Document AI Warehouse documents.
ContentWarehouseRuleSet- Manage Document AI Warehouse rule sets to enforce document policies.
ContentWarehouseSynonymSet- Manage Document AI Warehouse synonym sets to expand search queries.
DatabaseMigrationPrivateConnection- Manage Database Migration Service private connections to securely connect source databases to Google Cloud.
DataformFolder- Manage Dataform folders in Dataform repositories.
DataformTeamFolder- Manage Dataform team folders to organize repository assets.
DataLabelingDataset- Manage AI Platform Data Labeling datasets for annotating training data.
DataLabelingEvaluationJob- Manage AI Platform Data Labeling evaluation jobs to assess model quality.
DataLineageProcess- Manage Dataplex Data Lineage processes to track data origin and movement.
DataplexAspectType- Manage Dataplex aspect types to define metadata schemas.
DataplexDataAttributeBinding- Manage Dataplex data attribute bindings to map security and governance attributes to assets.
DataplexDataScan- Manage Dataplex data scans for data profiling and quality.
DataplexDataTaxonomy- Manage Dataplex data taxonomies to organize business metadata.
DataplexGlossary- Manage Dataplex business glossaries for consistent vocabulary.
DataplexMetadataJob- Manage Dataplex metadata jobs for metadata extraction.
DevConnectConnection- Manage Developer Connect connections to securely link third-party Git hosts.
DialogflowConversationDataset- Manage Dialogflow conversation datasets for agent training.
DialogflowSecuritySettings- Manage Dialogflow security settings for data redaction and access control.
DialogflowSipTrunk- Manage Dialogflow SIP trunks for telecom integration.
DiscoveryEngineControl- Manage Discovery Engine controls to boost or filter search results.
DiscoveryEngineSampleQuerySet- Manage Discovery Engine sample query sets to evaluate search performance.
DLPConnectionDLPDiscoveryConfig- Manage Sensitive Data Protection (DLP) discovery configurations for profiling data assets.
EventarcGoogleApiSource- Manage Eventarc Google API sources to configure event routing.
GeminiDataAnalyticsConversationGKEBackupBackupChannel- Manage Backup for GKE backup channels.
LiveStreamAsset- Manage Live Stream assets for processing live video.
ManagedKafkaConnectClusterMigrationCenterGroup- Manage Migration Center groups to organize assets for migration assessment.
NetworkSecurityAddressGroup- Manage Network Security address groups to define reusable network criteria.
NetworkSecurityAuthzPolicy- Manage Network Security authorization policies to secure network paths.
NetworkSecurityFirewallEndpoint- Manage Network Security firewall endpoints for Cloud Firewall Plus threat inspection.
NetworkSecurityFirewallEndpointAssociation- Manage Network Security firewall endpoint associations to apply threat inspection to networks.
NetworkSecurityGatewaySecurityPolicy- Manage Network Security gateway security policies for Secure Web Proxy configurations.
NetworkSecurityPartnerSSEGatewayNetworkSecurityPartnerSSERealmNetworkSecuritySecurityProfile- Manage Network Security security profiles to group threat prevention policies.
NetworkSecurityTLSInspectionPolicy- Manage Network Security TLS inspection policies to inspect encrypted traffic.
NetworkServicesAuthzExtension- Manage Network Services authorization extensions to integrate third-party callouts.
NotebooksSchedule- Manage Vertex AI Workbench schedules to run automated notebooks.
RedisClusterEndpointRunWorkerPool- Manage Cloud Run worker pools for long-running non-HTTP workloads.
SaasServiceMgmtRelease- Manage SaaS Service Management releases.
SQLAdminBackup- Manage Cloud SQL backups (read-only/reference representation).
StorageInsightsDatasetConfig- Manage Storage Insights dataset configurations to generate storage inventories.
TestingDeviceSessionTranslateAdaptiveMtDatasetVectorSearchCollectionVertexAIFeatureGroup- Manage Vertex AI Feature Store feature groups to organize features.
VertexAIFeatureOnlineStore- Manage Vertex AI Feature Store feature online stores for low-latency serving.
VertexAIPipelineJob- Manage Vertex AI pipeline jobs to run machine learning pipelines.
VertexAISpecialistPool- Manage Vertex AI specialist pools for human labeling.
VertexAIStudy- Manage Vertex AI Vizier studies for hyperparameter tuning.
VertexAITuningJob- Manage Vertex AI model tuning jobs for model customization.
VideoStitcherCDNKey- Manage Video Stitcher CDN keys to authenticate to external CDNs.
VisionProduct- Manage Cloud Vision products for product search cataloging.
VMwareEnginePrivateConnection- Manage VMware Engine private connections to connect private clouds to other services.
Feature
New Fields:
ComputeSubnetwork- Added
spec.reservedInternalRangefield.
- Added
NetworkConnectivityInternalRange- Added
spec.allocationOptionsfield.
- Added
ComputeNetwork- Added
spec.networkProfilefield.
- Added
ComputeSecurityPolicy- Added
spec.regionfield.
- Added
DNSRecordSet- Added support for routing policy
healthCheckRefandrrdatasRefsfields.
- Added support for routing policy
ComputeAddress- Added
spec.ipCollectionfield.
- Added
ComputeURLMap- Added
spec.defaultCustomErrorResponsePolicyfield. - Added
spec.test[].expectedOutputUrlandspec.test[].expectedRedirectResponseCodefields.
- Added
RedisCluster- Added
spec.crossClusterReplicationConfigfield.
- Added
MonitoringAlertPolicy- Added
spec.conditions[].conditionSqlfield (SQL Condition).
- Added
StorageBucket- Added
spec.ipFilterfield.
- Added
PubSubTopic- Added
spec.messageStoragePolicy.enforceInTransitfield.
- Added
ComputeRouterNAT- Added Private NAT feature support.
Change
Reconciliation Improvements:
We have added support for direct reconciliation to more resources, with opt-in behaviour. The API is unchanged. To use the direct reconciler, add the cnrm.cloud.google.com/reconciler: direct annotation to the corresponding Config Connector object.
BigQueryReservationCapacityCommitmentBigtableGCPolicyBillingBudgetsBudgetCertificateManagerCertificateMapCertificateManagerCertificateMapEntryComputeAddressComputeAutoscalerComputeBackendServiceSignedURLKeyComputeDiskComputeDiskResourcePolicyAttachmentComputeExternalVPNGatewayComputeFirewallComputeFirewallPolicyComputeHTTPHealthCheckComputeHTTPSHealthCheckComputeImageComputeInstanceComputeInstanceGroupComputeInstanceGroupManagerComputeNetworkComputeNodeTemplateComputeRouteComputeRouterComputeRouterInterfaceComputeRouterNATComputeSSLPolicyComputeSecurityPolicyComputeTargetHTTPSProxyComputeURLMapDataflowJobDataprocAutoscalingPolicyDataprocClusterDNSResponsePolicyKMSCryptoKeyKMSKeyRingLoggingLogExclusionMonitoringAlertPolicyNetworkServicesGatewayPrivateCACertificateAuthorityPrivateCACertificateTemplatePubSubSubscriptionRecaptchaEnterpriseKeyRedisInstanceServiceDirectoryEndpointServiceDirectoryNamespaceServiceServiceIdentity
Fixed
Bug Fixes:
ComposerEnvironment: Fix storageConfig.bucketRef mapping.MemorystoreInstance: Prevent infinite reconciliation drift loop by aligning connections list length.MemorystoreInstance: Prevent false drift and update attempts on unspecified immutable fields.ComputeBackendService: Fix config-connector export tool to exportbackendfield.KMSAutokeyConfig: Clean up and improve autokey config identity and deletion resolution.BigQuery: Fix perpetual diff on tables inheriting dataset encryption.NotebooksInstance: Fix direct controller for NotebookInstance to resolve references.
Cortex Framework
Announcement
Release 7.0.0-GA (General Availability)
Feature
Google Cloud Cortex Framework version 7 is now generally available. Version 7 introduces a modular deployment architecture, simplified data orchestration via Dataform, and AI-ready data products with BigQuery and Knowledge Catalog integration. This enables enterprises to build, extend, and deploy data assets and pipelines for advanced analytics and agentic use cases with less risk, complexity, and cost.
New features and enhancements
additional to those released in preview
AI, discovery, and governance:
- New agentic data product builder skills: Automate the creation and customization of data products using natural language.
- New Knowledge Catalog integration: Automatically synchronize deployed Cortex Framework data products and enriched metadata directly into Knowledge Catalog for discovery and governance.
Expanded data product content and integrations:
- New data products available for SAP ERP: Access an expanded number of Cortex Framework delivered data products for SAP ECC and SAP S/4HANA.
- New support for SAP Business Data Cloud data products: Register your SAP BDC data products with Cortex Framework for expanded use case opportunities on top.
- New solution samples features: Consumption data product samples for SAP ERP and SAP BDC can now be easily deployed on top of Cortex Framework managed data products.
- New v6 compatibility for SAP reporting: Provides an option to use Cortex Framework version 6 delivered SAP BigQuery data models within the version 7 architecture to support customers looking to migrate while continuing to use v6 delivered Looker reports.
Supportability:
- New observability features: Enhanced error reporting and pipeline monitoring.
Change
Google Cloud Cortex Framework version 7 includes telemetry to capture anonymized deployment statistics. This data helps the solution build team focus on improving modules with high adoption. Telemetry is enabled by default, but you can opt out at any time.
Data Studio
Feature
Conversational Analytics is generally available
Conversational Analytics in Data Studio is now generally available. You can now filter your data agents by the Google Cloud project to which they belong. Agents that require additional permissions are now displayed with an Unavailable label.
Feature
Email notifications when sharing Conversational Analytics data agents
When you share data agents that were created in BigQuery with Data Studio users, you can opt to send an email to notify those users of their access to the agent.
Google Cloud Contact Center as a Service
Announcement
Google Cloud CCaaS 5.2
We've released version 5.2 of Google Cloud CCaaS.
The timing of the update to your instance depends on the deployment schedule that you have chosen. For more information, see Deployment schedules.
Feature
Answering machine detection for progressive campaigns
Answering machine detection (AMD) is now supported for progressive outbound campaigns. When enabled, Contact Center AI Platform analyzes call audio in the background to determine whether a call reaches a live person, or whether it reaches an answering machine or voicemail. If an answering machine or voicemail is detected, the call ends and the dialer proceeds to the next contact.
Administrators: In the Settings > Campaigns > Dialer Modes pane, there's a new Enable Answering Machine Detection toggle.
User experience change: When CCAI Platform detects voicemail or an answering machine, a green banner appears in the call adapter to indicate this.
For more information, see Answering machine detection for progressive campaigns.
Feature
New endpoints for getting email sessions and messages
Two new read-only endpoints are now available, allowing external systems to retrieve the parsed contents of an email interaction. This includes the sender, recipients, subject, body, and attachment metadata. Here are the endpoints:
/apps/api/v1/email/sessions/EMAIL_SUPPORT_ID: Returns email session summary information and a list of message IDs with metadata./apps/api/v1/email/messages/EMAIL_THREAD_ID: Returns the full content of a single message.
For more information, see Get email sessions and messages.
Feature
Email forwarding with attachments
Agents can now forward emails to external recipients directly from the email adapter. When forwarding, all attachments from the original email are automatically included. Agents can remove attachments before sending, if needed. The original email remains in its assigned queue with its status unchanged.
User experience change: A new Forward button is available in the email adapter.
For more information, see Forward an email.
Feature
Smart disposition
Smart disposition is a new AI-powered capability that automatically suggests a disposition code at the end of a session. This reduces manual work for agents and improves data consistency.
Administrators: There's a new Smart Disposition toggle in the following locations:
The Settings > Operation Management > Wrap-up > Automatic wrap-up for inbound calls > Disposition Codes & Notes for calls > Disposition Codes section.
The Settings > Operation Management > Wrap-up > Automatic wrap-up for outbound calls > Disposition Codes & Notes for calls > Disposition Codes section.
The Settings > Operation Management > Wrap-up > Automatic wrap-up for chats > Disposition Codes & Notes for chats > Disposition Codes section.
User experience change: When smart disposition is turned on, a suggested disposition displays in the Disposition field of the Wrap-up screen in the agent adapter.
For more information, see Smart disposition.
Fixed
This release addresses the following issues:
Fixed an issue where voice calls became stuck in a virtual agent state after a session ended abnormally or an escalation handoff didn't complete.
Fixed an issue where using invalid sorting parameters on agent activity logs caused a server error.
Fixed an issue where canceling a warm transfer to a queue at overcapacity caused the caller to become stranded in an automated menu loop.
Fixed an issue where the agent activity logs API allowed unbounded time ranges, which led to system performance degradation and gateway timeouts.
Fixed an issue where the team and menu endpoints experienced performance delays.
Fixed an issue where calls transferred to a queue with overcapacity deflection (OCD) enabled didn't redirect, causing callers to hear indefinite ringing.
Fixed an issue where the call duration in the call adapter and in the in-call status timer of the agent desktop didn't match for outbound calls.
Fixed an issue where the Agent Activity dashboard displayed time zones inconsistently.
Fixed an issue where the inactivity timer didn't force a session to end if the agent closed the browser or browser tab before the inactivity timer expired.
Fixed an issue where the All Call History and Individual Call History reports displayed incorrect cascade group numbers for transferred calls and chats.
Fixed an issue where the sentiment score appeared in the Call Details panel of the agent desktop despite sentiment analysis being turned off in the conversation profile.
Fixed an issue with IVR calls routed through Nexmo, where the virtual agent missed the first several seconds of caller audio, forcing callers to repeat themselves.
Fixed an issue where chats became stuck in the queue after a deltacast routing projection expired or an agent didn't connect.
Fixed an issue where reordering queues in the CCAI Platform portal caused significant latency and required a manual page refresh to display the changes.
Fixed an issue with Salesforce integrations where adding a third party to a call incorrectly displayed their contact name in the customer field in the agent desktop Participants panel.
Fixed an issue where direct inbound SMS chats that were sent to an unavailable agent expired and failed instead of being rerouted.
Fixed an issue where anonymous inbound calls incorrectly displayed an agent's contact information instead of indicating an unknown caller.
Fixed an issue where database deadlocks caused transactions to run against the wrong database, causing failed lookups and chat sessions getting stuck.
Fixed an issue where manual status changes to Available after an automatic wrap-up were incorrectly attributed to the system instead of the agent in activity reports.
Fixed an issue where retrieving large datasets using the manager API caused connection timeouts and incomplete data synchronization for downstream systems.
Fixed an issue where the Agent Assist Hub incorrectly displayed
The Agent Assist Hub feature is not enabledduring voice sessions despite the Agent Assist Hub being enabled.Fixed a web SDK issue where navigating between pages on the host website during an active chat resulted in a duplicate session being created.
Fixed an issue where the AgentSystemData historical report incorrectly showed zero login time for agents who were actively handling calls.
Fixed an issue where Dialogflow agents incorrectly escalated or disconnected calls when responding with only pre-recorded audio.
Fixed an issue where transfer completion events appeared twice in the agent desktop session data feed when a user was transferred to a task virtual agent.
Fixed an issue where virtual agent interactions failed and escalated prematurely.
Fixed an issue where a single wrap-up event was incorrectly dispatched twice to Dialogflow on bidirectional-enabled voice calls.
Fixed an issue where session summarization sections weren't displayed in the order that they were configured.
Fixed an issue where sensitive information in the CC and BCC fields of email requests was visible in system logs.
Fixed an issue where the email adapter displayed a blank gray screen when an agent attempted to transfer emails between queues.
Fixed an issue in Kustomer integrations where abandoned or failed calls weren't finalized, leaving records in the
Call In Progressstate.Fixed an issue in ServiceNow integrations where starting a chat from a queue caused duplicate cases for a single chat ID.
Fixed an issue where mobile chat sessions ended unexpectedly after successfully escalating to a human agent.
Fixed an issue where chat transcript PDF headers remained in English for non-English queues.
Fixed an issue where placeholder text (
Content cards displayed here) didn't appear in the agent adapter or live chat view when content cards weren't supported.Fixed an issue where agents received duplicate SMS messages from end-users.
Fixed an issue where the inactivity timeout didn't trigger for chats waiting in a transfer queue.
Fixed an issue where chats waiting in a transfer queue remained open indefinitely and created duplicate metadata files.
Fixed an issue where chat transcripts were missing from data exports when a CRM ticket wasn't created.
Fixed an issue where chats escalated from a virtual agent remained in queued status after being assigned to an agent.
Fixed an issue where calls escalated from a virtual agent to a holiday-closed queue bypassed the holiday message and played the after-hours deflection message.
Fixed an issue where call recording URLs weren't saved or synced to the CRM for calls with multiple audio segments, such as those involving an IVR followed by an agent conference.
Fixed an issue where voice calls remained in an assigned state without progressing or requeueing if a system error occurred during the assignment process.
Fixed an issue where callers were disconnected from voicemail greetings after an agent completed their wrap-up following a call transfer.
Fixed an issue where manual wrap-up session data was incorrectly recorded across multiple sessions, leading to inflated duration reports.
Fixed an issue where duplicate call recording files with an
.Nsuffix were created in external storage.Fixed an issue where calls prematurely disconnected or experienced audio loss during the hangup process.
Fixed an issue where Telnyx VoIP calls silently dropped without notification if the connection was interrupted.
Improved internal instrumentation to diagnose poor call quality scores and improve call reliability.
Fixed an issue where agents configured for Deltacast and auto-answer received unexpected multicast call offers.
Fixed an issue where the agent desktop didn't save call-related settings such as mute status.
Fixed an issue where queue-level automatic wrap-up settings were unexpectedly disabled.
Fixed an issue where the switch to chat button wasn't accessible from the keyboard.
Fixed an issue where an agent ended the wrap-up session of another agent.
Fixed an issue where agents experienced delays of up to 30 seconds when transitioning from "Wrap" to "Available" status.
Fixed an issue where an
An error has occurredmessage incorrectly appeared when a user created a direct access point for instances without a configured CRM.Fixed an issue where message timestamps weren't visible to supervisors and administrators when monitoring active chats in the CCAI Platform portal.
Fixed an issue where historical data syncs to Calabrio failed.
Fixed an issue where the bulk user upload process allowed unauthorized role assignments.
Fixed an issue where deleting a notification rule removed all associated historical notifications without warning.
Fixed an issue where call events in timeline reports appeared out of chronological order.
Fixed an issue where technical connection timeouts during call offers weren't correctly tracked as skipped interactions.
Fixed an issue where chats remained in the queue following a virtual agent escalation.
Fixed an issue where importing a contact list CSV for a native power dial campaign failed if the file contained malformed rows or encoding issues.
Google Cloud Marketplace Partners
Change
We've added the city field to Customer Insights reports and Detailed
Disbursements reports.
For more information, see Customer Insights report fields and Detailed Disbursements report fields.
Google Kubernetes Engine
Change
(2026-R32) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters.
The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.
Rapid channel
- Version 1.36.2-gke.2064000 is now the default version for cluster creation in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.33.13-gke.1109000
- 1.34.9-gke.1322000
- 1.35.6-gke.1258000
- 1.35.6-gke.1638000 is deprecated in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.2-gke.1498000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1269000
- 1.33 to 1.34.9-gke.1610000
- 1.34 to 1.35.6-gke.1641000
- 1.35 to 1.36.2-gke.2064000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1269000
- 1.34 to 1.34.9-gke.1610000
- 1.35 to 1.35.6-gke.1641000
- 1.36 to 1.36.2-gke.2064000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Regular channel
- Version 1.35.6-gke.1250000 is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.33.13-gke.1011000
- 1.34.9-gke.1131000
- 1.35.6-gke.1127000
- 1.36.0-gke.4447000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.4681000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1101000
- 1.33 to 1.34.9-gke.1287000
- 1.34 to 1.35.6-gke.1250000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1101000
- 1.34 to 1.34.9-gke.1287000
- 1.35 to 1.35.6-gke.1250000
- 1.36 to 1.36.2-gke.1346000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Stable channel
- Version 1.34.9-gke.1065000 is now the default version for cluster creation in the Stable channel.
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.33.12-gke.1165000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.34.8-gke.1278000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.12-gke.1270000
- 1.33 to 1.34.9-gke.1065000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.12-gke.1270000
- 1.34 to 1.34.9-gke.1065000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Extended channel
- Version 1.35.6-gke.1250000 is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
- The following versions are no longer available in the Extended channel:
- 1.30.14-gke.2846000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2437000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.2137000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.33.13-gke.1011000
- 1.34.9-gke.1131000
- 1.35.6-gke.1127000
- 1.36.0-gke.4447000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.4681000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1101000
- 1.34 to 1.34.9-gke.1287000
- 1.35 to 1.35.6-gke.1250000
- 1.36 to 1.36.2-gke.1346000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
No channel (deprecated)
- Version 1.35.6-gke.1250000 is now the default version for cluster creation.
- The following versions are now available:
- The following node versions are now available:
- The following versions are no longer available:
- 1.33.12-gke.1165000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.34.8-gke.1126000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.35.6-gke.1049000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.35.6-gke.1638000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.4447000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.4681000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1101000
- 1.33 to 1.34.9-gke.1065000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1101000
- 1.34 to 1.34.9-gke.1065000
- 1.35 to 1.35.6-gke.1250000
- 1.36 to 1.36.2-gke.1346000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R32) Version updates
- Version 1.34.9-gke.1065000 is now the default version for cluster creation in the Stable channel.
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.33.12-gke.1165000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.34.8-gke.1278000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.12-gke.1270000
- 1.33 to 1.34.9-gke.1065000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.12-gke.1270000
- 1.34 to 1.34.9-gke.1065000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R32) Version updates
- Version 1.35.6-gke.1250000 is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.33.13-gke.1011000
- 1.34.9-gke.1131000
- 1.35.6-gke.1127000
- 1.36.0-gke.4447000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.4681000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1101000
- 1.33 to 1.34.9-gke.1287000
- 1.34 to 1.35.6-gke.1250000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1101000
- 1.34 to 1.34.9-gke.1287000
- 1.35 to 1.35.6-gke.1250000
- 1.36 to 1.36.2-gke.1346000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R32) Version updates
- Version 1.36.2-gke.2064000 is now the default version for cluster creation in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.33.13-gke.1109000
- 1.34.9-gke.1322000
- 1.35.6-gke.1258000
- 1.35.6-gke.1638000 is deprecated in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.2-gke.1498000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1269000
- 1.33 to 1.34.9-gke.1610000
- 1.34 to 1.35.6-gke.1641000
- 1.35 to 1.36.2-gke.2064000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1269000
- 1.34 to 1.34.9-gke.1610000
- 1.35 to 1.35.6-gke.1641000
- 1.36 to 1.36.2-gke.2064000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R32) Version updates
- Version 1.35.6-gke.1250000 is now the default version for cluster creation.
- The following versions are now available:
- The following node versions are now available:
- The following versions are no longer available:
- 1.33.12-gke.1165000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.34.8-gke.1126000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.35.6-gke.1049000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.35.6-gke.1638000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.4447000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.4681000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1101000
- 1.33 to 1.34.9-gke.1065000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1101000
- 1.34 to 1.34.9-gke.1065000
- 1.35 to 1.35.6-gke.1250000
- 1.36 to 1.36.2-gke.1346000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R32) Version updates
- Version 1.35.6-gke.1250000 is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
- The following versions are no longer available in the Extended channel:
- 1.30.14-gke.2846000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2437000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.2137000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.33.13-gke.1011000
- 1.34.9-gke.1131000
- 1.35.6-gke.1127000
- 1.36.0-gke.4447000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.4681000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1101000
- 1.34 to 1.34.9-gke.1287000
- 1.35 to 1.35.6-gke.1250000
- 1.36 to 1.36.2-gke.1346000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
Google SecOps Marketplace
Change
Google Chronicle: Version 91.0
Updated Wiz Defend alert naming format in the following connector:
- Google Chronicle - Chronicle Alerts Connector
Looker
Announcement
From July 27 through July 30, 2026, the following features will be automatically enabled for Looker (original) instances running Looker 26.12.
Feature
Looker admins now have the ability to configure a Looker instance to require multi-factor authentication (MFA) whenever a user tries to log in by using an email and a password. This feature is enabled by default.
Feature
The custom calendar feature is now generally available.
Feature
The Expression Assistant is now generally available.
Feature
The Enhanced search feature is now generally available.
Feature
Looker Continuous Integration (CI) now supports email alerts. When you create or edit a CI suite, you can enable the Enable email alerts toggle to specify email recipients and select which run statuses will trigger emails (Failed, Error, Passed, or Cancelled). For more information, see Set up alerting.
Feature
The LookML Projects page has been updated with a more performant tabbed layout, which features three tabs: Models and Projects, Pending Projects, and Marketplace Projects.
Feature
Now available in preview, the new Modern User Interface feature enables modernized layouts and design alongside new configuration settings for visualizations and dashboards. When this preview feature is enabled, users can apply a Modern visualization theme that features updated typography and modern, accessible color palettes for improved data legibility. Additionally, a new Modern dashboard style provides a high-density, streamlined design that optimizes data viewing and aligns with Google's latest design standards.
Feature
Now available in preview, verified queries (also referred to as golden queries) are predefined pairs of natural language questions and their exact, corresponding Looker Explore queries that act as verified standards of truth to teach your Explore data agent how to handle complex business requests without guessing.
To enable verified queries, a Looker admin must turn on the Verified Queries setting on the Gemini in Looker admin page. The Conversational Analytics setting must also be enabled for verified queries to be used.
Change
When you chat in Gemini Enterprise with data agents that you create in Looker, agent responses now include charts and visualizations.
Change
The Insight Assistant now displays the process the assistant uses to generate the response, showing key details in your data that it used to generate the response, and listing the fields from your Explore that it used.
Announcement
Complimentary Data Studio Pro licenses aren't available for Looker instances that are affiliated with Looker contracts that are signed after August 1, 2026.
Managed Service for Apache Spark
Announcement
- 3.5-dataproc-28
Key updates in this image version include:
- Conda channels: The new
3.5-dataproc-28subminor image version doesn't have preconfigured Conda channels, and is mapped to default aliases (such as3.5andlatest).- Impact: When creating clusters with
3.5-dataproc-28or using default aliases (3.5,latest), packages cannot be installed using Conda unless channels are manually configured during cluster initialization. - Mitigation: If your workloads require preconfigured Conda channels, pin your clusters to the previous image versions before August 25, 2026.
- Default change schedule: All workloads must transition to image versions without preconfigured Conda channels after August 25, 2026 since the use of prior subminor versions with preconfigured Conda channels will be disallowed.
- Impact: When creating clusters with
You may need to delete and replace existing clusters After August 25, 2026, existing clusters created with images that have preconfigured Conda channels (even if cluster jobs don't use Conda to install packages) need to be deleted and replaced with new clusters created or recreated with images that don't have preconfigured Conda channels.
Oracle Database@Google Cloud
Feature
Oracle Database@Google Cloud supports customer-managed encryption keys (CMEK) for Exascale VM Clusters. You can enable CMEK on Exascale VM Clusters. This feature is generally available (GA).
Virtual Private Cloud
Feature
General Availability: You can use the Resolve subnet mask setting on a
subnet to configure all attached Compute Engine instances with the same netmask
as the subnet (instead of /32). Configuring larger instance netmasks lets
compute instances discover the MAC addresses of other machines within the same
subnet and directly communicate with them by using destination MAC addresses.
For more information, see Compute instance netmasks.
App Engine standard environment Go
Feature
Support for enabling only needed legacy bundled services using the
app_engine_bundled_services
field is in General Availability.
App Engine standard environment Java
Feature
Support for enabling only needed legacy bundled services using the
app_engine_bundled_services
field is in General Availability.
App Engine standard environment PHP
Feature
Support for enabling only needed legacy bundled services using the
app_engine_bundled_services
field is in General Availability.
App Engine standard environment Python
Feature
Support for enabling only needed legacy bundled services using the
app_engine_bundled_services
field is in General Availability.
BigQuery
Feature
The BigQuery Data Transfer Service now supports incremental data transfers when transferring data from Klaviyo to BigQuery. This feature is supported in Preview.
Bigtable
Feature
You can use the Google Cloud console to manage row key schemas for your Bigtable tables. This feature is in Preview.
Cloud Key Management Service
Feature
Cloud KMS Autokey with same-project key storage (formerly known as Autokey for delegated key management) is generally available. Autokey with same-project key storage can be used on its own or alongside Autokey with dedicated-project key storage (formerly known as Autokey for centralized key management).
For more information, see Enable Cloud KMS Autokey. To learn how to set guardrails to constrain how Autokey is used in your organization, see Control Autokey usage.
Cloud SQL for MySQL
Feature
Cloud SQL for MySQL now supports significantly faster re-encryption of instances and replicas protected by customer-managed encryption keys (CMEKs), and re-encryption now completes with zero downtime. The steps to re-encrypt your instances and replicas are unchanged, but the operation now re-encrypts the underlying disks in-place, without creating re-encryption backups.
For more information, see Re-encrypt an existing CMEK-enabled instance or replica.
Cloud SQL for PostgreSQL
Feature
Cloud SQL for PostgreSQL now supports significantly faster re-encryption of instances and replicas protected by customer-managed encryption keys (CMEKs), and re-encryption now completes with zero downtime. The steps to re-encrypt your instances and replicas are unchanged, but the operation now re-encrypts the underlying disks in-place, without creating re-encryption backups.
For more information, see Re-encrypt an existing CMEK-enabled instance or replica.
Cloud SQL for SQL Server
Feature
Cloud SQL for SQL Server now supports significantly faster re-encryption of instances and replicas protected by customer-managed encryption keys (CMEKs), and re-encryption now completes with zero downtime. The steps to re-encrypt your instances and replicas are unchanged, but the operation now re-encrypts the underlying disks in-place, without creating re-encryption backups.
For more information, see Re-encrypt an existing CMEK-enabled instance or replica.
Cloud Scheduler
Change
Cloud Scheduler is available in the following locations:
europe-west8(Milan, Italy)europe-west9(Paris, France)us-south1(Dallas, United States)
Cloud Service Mesh
Feature
For the clusters using TRAFFIC_DIRECTOR implementation,
IP auto-allocation
with DNS Proxy is now supported in Rapid release channel.
Confidential VM
Feature
Confidential VM instances with AMD SEV on C3D and C4D machine types now support configurations with more than 255 vCPUs.
Datastream
Feature
You can now create a Datastream stream directly from the instance or database overview page in Spanner using the automated flow.
For more information, see Create a Spanner stream using the automated flow.
Google SecOps
Change
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- Airlock Digital Application Allowlisting (
AIRLOCK_DIGITAL) - AIX system (
AIX_SYSTEM) - Akamai DataStream 2 (
AKAMAI_DATASTREAM_2) - Akamai SIEM Connector (
AKAMAI_SIEM_CONNECTOR) - Apache (
APACHE) - Arcsight CEF (
ARCSIGHT_CEF) - Armis Alerts (
ARMIS_ALERTS) - Aruba Switch (
ARUBA_SWITCH) - Atlassian Cloud Admin Audit (
ATLASSIAN_AUDIT) - Linux Auditing System (AuditD) (
AUDITD) - Avaya Aura Experience Portal (
AVAYA_AURA) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS Control Tower (
AWS_CONTROL_TOWER) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Azure AD (
AZURE_AD) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure Application Gateway (
AZURE_GATEWAY) - Azure Key Vault logging (
AZURE_KEYVAULT_AUDIT) - Microsoft Azure Resource (
AZURE_RESOURCE_LOGS) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - BeyondTrust (
BOMGAR) - Cato Networks (
CATO_NETWORKS) - Check Point (
CHECKPOINT_FIREWALL) - Check Point Harmony (
CHECKPOINT_HARMONY) - Chrome Management (
CHROME_MANAGEMENT) - ChromeOS XDR (
CHROMEOS_XDR) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco FireSIGHT Management Center (
CISCO_FIRESIGHT) - Cisco ISE (
CISCO_ISE) - Cisco Router (
CISCO_ROUTER) - Cisco Switch (
CISCO_SWITCH) - Cisco UCM (
CISCO_UCM) - Claroty Xdome (
CLAROTY_XDOME) - Claude Compliance Logs (
CLAUDE_COMPLIANCE_LOGS) - HP Aruba (ClearPass) (
CLEARPASS) - Cloudflare (
CLOUDFLARE) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR) - CrowdStrike Falcon (
CS_EDR) - Darktrace (
DARKTRACE) - EfficientIP DDI (
EFFICIENTIP_DDI) - F5 ASM (
F5_ASM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - Fastly CDN (
FASTLY_CDN) - FireEye eMPS (
FIREEYE_EMPS) - FireEye HX (
FIREEYE_HX) - FireEye NX (
FIREEYE_NX) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet FortiClient (
FORTINET_FORTICLIENT) - Fortinet Switch (
FORTINET_SWITCH) - GCP Cloud Audit (
GCP_CLOUDAUDIT) - Security Command Center External Exposure (
GCP_SECURITYCENTER_EXTERNAL_EXPOSURE) - Gitlab (
GITLAB) - Google Threat Intelligence IOC (
GTI_IOC) - AWS GuardDuty (
GUARDDUTY) - Huawei Switches (
HUAWEI_SWITCH) - IBM Security Access Manager (
IBM_SAM) - Microsoft IIS (
IIS) - Illumio Core (
ILLUMIO_CORE) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Infoblox (
INFOBLOX) - Infoblox DHCP (
INFOBLOX_DHCP) - Jamf pro context (
JAMF_PRO_CONTEXT) - Mobile Endpoint Security (
LOOKOUT_MOBILE_ENDPOINT_SECURITY) - Apple macOS (
MACOS) - McAfee IPS (
MCAFEE_IPS) - Micro Focus iManager (
MICROFOCUS_IMANAGER) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft Sentinel (
MICROSOFT_SENTINEL) - Microsoft SQL Server (
MICROSOFT_SQL) - Mimecast URL Logs (
MIMECAST_URL_LOGS) - MISP Threat Intelligence (
MISP_IOC) - NetApp ONTAP (
NETAPP_ONTAP) - Netskope V2 (
NETSKOPE_ALERT_V2) - Unix system (
NIX_SYSTEM) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Onapsis (
ONAPSIS) - OpenVPN (
OPEN_VPN) - Oracle Fusion (
ORACLE_FUSION) - Ping Identity (
PING) - Proofpoint Sendmail Sentrion (
PROOFPOINT_SENDMAIL_SENTRION) - SailPoint IAM (
SAILPOINT_IAM) - Salesforce (
SALESFORCE) - Sendmail (
SENDMAIL) - Sentinelone Alerts (
SENTINELONE_ALERT) - ServiceNow Audit (
SERVICENOW_AUDIT) - ServiceNow CMDB (
SERVICENOW_CMDB) - ServiceNow Security (
SERVICENOW_SECURITY) - SonicWall (
SONIC_FIREWALL) - STIX Threat Intelligence (
STIX) - Tanium Threat Response (
TANIUM_THREAT_RESPONSE) - Thinkst Canary (
THINKST_CANARY) - ThreatConnect IOC V3 (
THREATCONNECT_IOC_V3) - ThreatLocker Platform (
THREATLOCKER) - Varonis (
VARONIS) - VMware ESXi (
VMWARE_ESX) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - wiz.io (
WIZ_IO) - Workspace Activities (
WORKSPACE_ACTIVITY) - Zoom Operation Logs (
ZOOM_OPERATION_LOGS)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Adobe Experience Platform (
ADOBE_EXPERIENCE_PLATFORM) - AudioCodes Session Border Controller (
AUDIOCODES_SBC) - Azure Application Gateway for Containers (
AZURE_GATEWAY_CONTAINERS) - Azure Logic Apps (
AZURE_LOGIC_APPS) - Azure NAT Gateway Flow (
AZURE_NATGW_FLOW) - Broadcom DX NetOps Spectrum (
BROADCOM_DX_NETOPS_SPECTRUM) - Carto Activity (
CARTO_ACTIVITY) - Claude Code Observability (
CLAUDE_CODE_OBSERVABILITY) - Cyble Attack Surface Management (
CYBLE_ASM) - Cyble Brand Intelligence & Protection (
CYBLE_BIP) - Darkweb IQ (
DARKWEB_IQ) - Ellio Threat Intelligence (
ELLIO_THREAT_INTEL) - Exeon NDR (
EXEON_NDR) - Gravitee (
GRAVITEE) - Kaspersky anti targeted attack (
KASPERSKY_ANTI_TARGETED_ATTACK) - Microsoft Copilot Interaction (
MICROSOFT_COPILOT_INTERACTION) - OSTTRA MarkitWire (
OSTTRA_MARKITWIRE) - Proofpoint Adaptive Email Security (
PROOFPOINT_ADAPTIVE_EMAIL_SECURITY) - Secomea GateManager (
SECOMEA_GATEMANAGER) - Trend Micro Vision One Risk Event (
TRENDMICRO_VISION_ONE_RISK_EVENT) - TXOne EdgeIPS (
TXONE_EDGEIPS) - Vectra Respond UX (
VECTRA_RUX) - Zoho CRM (
ZOHO_CRM)
Feature
View prebuilt parser version content
You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is inactive, you can still see the content of the new preview version for this parser.
Google SecOps Marketplace
Change
Active Directory: Version 44.0
Added optional
Connection TimeoutandReceive Timeoutparameters to configure network connectivity limits in the following action:- Enrich Entities
Change
Anomali ThreatStream: Version 18.0
Updated API output handling in the following action:
- Enrich Entities
Change
Google Threat Intelligence: Version 20.0
Added support for
CHILDHASHandPARENTHASHentity types in the following action:- Enrich Entities
Added
Entity Type Filterparameter to allow configuring entity types for notifications in the following connector:- Google Threat Intelligence - Livehunt Connector
Change
Microsoft 365 Defender: Version 28.0
Updated case syncing logic in the following action:
- Sync Alerts
Updated alert processing logic in the following connector:
- Microsoft 365 Defender - Incidents Connector
Change
Siemplify: Version 112.0
Added
Update Enabled Connectors Onlyfiltering option in the following job:- Response Integration & Connector Upgrade Job
Change
Vertex AI: Version 8.0
- Added support for multi-region endpoints across the integration configuration.
Google SecOps SIEM
Change
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- Airlock Digital Application Allowlisting (
AIRLOCK_DIGITAL) - AIX system (
AIX_SYSTEM) - Akamai DataStream 2 (
AKAMAI_DATASTREAM_2) - Akamai SIEM Connector (
AKAMAI_SIEM_CONNECTOR) - Apache (
APACHE) - Arcsight CEF (
ARCSIGHT_CEF) - Armis Alerts (
ARMIS_ALERTS) - Aruba Switch (
ARUBA_SWITCH) - Atlassian Cloud Admin Audit (
ATLASSIAN_AUDIT) - Linux Auditing System (AuditD) (
AUDITD) - Avaya Aura Experience Portal (
AVAYA_AURA) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS Control Tower (
AWS_CONTROL_TOWER) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Azure AD (
AZURE_AD) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure Application Gateway (
AZURE_GATEWAY) - Azure Key Vault logging (
AZURE_KEYVAULT_AUDIT) - Microsoft Azure Resource (
AZURE_RESOURCE_LOGS) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - BeyondTrust (
BOMGAR) - Cato Networks (
CATO_NETWORKS) - Check Point (
CHECKPOINT_FIREWALL) - Check Point Harmony (
CHECKPOINT_HARMONY) - Chrome Management (
CHROME_MANAGEMENT) - ChromeOS XDR (
CHROMEOS_XDR) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco FireSIGHT Management Center (
CISCO_FIRESIGHT) - Cisco ISE (
CISCO_ISE) - Cisco Router (
CISCO_ROUTER) - Cisco Switch (
CISCO_SWITCH) - Cisco UCM (
CISCO_UCM) - Claroty Xdome (
CLAROTY_XDOME) - Claude Compliance Logs (
CLAUDE_COMPLIANCE_LOGS) - HP Aruba (ClearPass) (
CLEARPASS) - Cloudflare (
CLOUDFLARE) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR) - CrowdStrike Falcon (
CS_EDR) - Darktrace (
DARKTRACE) - EfficientIP DDI (
EFFICIENTIP_DDI) - F5 ASM (
F5_ASM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - Fastly CDN (
FASTLY_CDN) - FireEye eMPS (
FIREEYE_EMPS) - FireEye HX (
FIREEYE_HX) - FireEye NX (
FIREEYE_NX) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet FortiClient (
FORTINET_FORTICLIENT) - Fortinet Switch (
FORTINET_SWITCH) - GCP Cloud Audit (
GCP_CLOUDAUDIT) - Security Command Center External Exposure (
GCP_SECURITYCENTER_EXTERNAL_EXPOSURE) - Gitlab (
GITLAB) - Google Threat Intelligence IOC (
GTI_IOC) - AWS GuardDuty (
GUARDDUTY) - Huawei Switches (
HUAWEI_SWITCH) - IBM Security Access Manager (
IBM_SAM) - Microsoft IIS (
IIS) - Illumio Core (
ILLUMIO_CORE) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Infoblox (
INFOBLOX) - Infoblox DHCP (
INFOBLOX_DHCP) - Jamf pro context (
JAMF_PRO_CONTEXT) - Mobile Endpoint Security (
LOOKOUT_MOBILE_ENDPOINT_SECURITY) - Apple macOS (
MACOS) - McAfee IPS (
MCAFEE_IPS) - Micro Focus iManager (
MICROFOCUS_IMANAGER) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft Sentinel (
MICROSOFT_SENTINEL) - Microsoft SQL Server (
MICROSOFT_SQL) - Mimecast URL Logs (
MIMECAST_URL_LOGS) - MISP Threat Intelligence (
MISP_IOC) - NetApp ONTAP (
NETAPP_ONTAP) - Netskope V2 (
NETSKOPE_ALERT_V2) - Unix system (
NIX_SYSTEM) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Onapsis (
ONAPSIS) - OpenVPN (
OPEN_VPN) - Oracle Fusion (
ORACLE_FUSION) - Ping Identity (
PING) - Proofpoint Sendmail Sentrion (
PROOFPOINT_SENDMAIL_SENTRION) - SailPoint IAM (
SAILPOINT_IAM) - Salesforce (
SALESFORCE) - Sendmail (
SENDMAIL) - Sentinelone Alerts (
SENTINELONE_ALERT) - ServiceNow Audit (
SERVICENOW_AUDIT) - ServiceNow CMDB (
SERVICENOW_CMDB) - ServiceNow Security (
SERVICENOW_SECURITY) - SonicWall (
SONIC_FIREWALL) - STIX Threat Intelligence (
STIX) - Tanium Threat Response (
TANIUM_THREAT_RESPONSE) - Thinkst Canary (
THINKST_CANARY) - ThreatConnect IOC V3 (
THREATCONNECT_IOC_V3) - ThreatLocker Platform (
THREATLOCKER) - Varonis (
VARONIS) - VMware ESXi (
VMWARE_ESX) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - wiz.io (
WIZ_IO) - Workspace Activities (
WORKSPACE_ACTIVITY) - Zoom Operation Logs (
ZOOM_OPERATION_LOGS)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Adobe Experience Platform (
ADOBE_EXPERIENCE_PLATFORM) - AudioCodes Session Border Controller (
AUDIOCODES_SBC) - Azure Application Gateway for Containers (
AZURE_GATEWAY_CONTAINERS) - Azure Logic Apps (
AZURE_LOGIC_APPS) - Azure NAT Gateway Flow (
AZURE_NATGW_FLOW) - Broadcom DX NetOps Spectrum (
BROADCOM_DX_NETOPS_SPECTRUM) - Carto Activity (
CARTO_ACTIVITY) - Claude Code Observability (
CLAUDE_CODE_OBSERVABILITY) - Cyble Attack Surface Management (
CYBLE_ASM) - Cyble Brand Intelligence & Protection (
CYBLE_BIP) - Darkweb IQ (
DARKWEB_IQ) - Ellio Threat Intelligence (
ELLIO_THREAT_INTEL) - Exeon NDR (
EXEON_NDR) - Gravitee (
GRAVITEE) - Kaspersky anti targeted attack (
KASPERSKY_ANTI_TARGETED_ATTACK) - Microsoft Copilot Interaction (
MICROSOFT_COPILOT_INTERACTION) - OSTTRA MarkitWire (
OSTTRA_MARKITWIRE) - Proofpoint Adaptive Email Security (
PROOFPOINT_ADAPTIVE_EMAIL_SECURITY) - Secomea GateManager (
SECOMEA_GATEMANAGER) - Trend Micro Vision One Risk Event (
TRENDMICRO_VISION_ONE_RISK_EVENT) - TXOne EdgeIPS (
TXONE_EDGEIPS) - Vectra Respond UX (
VECTRA_RUX) - Zoho CRM (
ZOHO_CRM)
Feature
View prebuilt parser version content
You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is inactive, you can still see the content of the new preview version for this parser.
Managed Service for Apache Airflow
Announcement
A new Managed Service for Apache Airflow release has started on July 29, 2026. Get ready for upcoming changes and features as we roll out the new release to all regions. This release is in progress at the moment. Listed changes and features might not be available in some regions yet.
Feature
Airflow 3.2.2 is available in Managed Airflow (Gen 3).
Change
(Airflow 3.2.2) The
Multi-Team
Airflow feature isn't available. The [core]multi_team Airflow configuration
option is set to False and it isn't possible to override it.
Fixed
(Airflow 3.2.2) Backported
#69877 to restore the ability
to deliver failure and retry alerts through a pluggable email backend
(configured through the [email]email_backend Airflow configuration option).
Change
(Managed Airflow Gen 3 with Airflow 2) Default triggerer resources are changing to 1 vCPU and 2 GB memory to match Airflow 3 defaults. This change is available in the Google Cloud CLI, Terraform, and Cloud Composer API and is gradually rolling out in the Google Cloud console.
Fixed
A correct error message is now generated when an environment creation request fails because of malformed network and subnetwork identifiers.
Fixed
(Available without upgrading) The correct default task priority weight of 1
is now shown for tasks in the Google Cloud console.
Change
New Airflow builds are available in Managed Airflow (Gen 3):
- composer-3-airflow-3.2.2-build.0
- composer-3-airflow-3.1.8-build.2
- composer-3-airflow-2.11.1-build.13 (default)
- composer-3-airflow-2.10.5-build.46
Change
New images are available in Managed Airflow (Gen 2):
Deprecated
The following Managed Airflow versions and builds have reached their end of support period: composer-3-airflow-2.10.5-build.10, composer-3-airflow-2.9.3-build.30, composer-2.13.8-airflow-2.9.3, and composer-2.13.8-airflow-2.10.5.
reCAPTCHA
Feature
The Agent overview dashboard is available on the Google Cloud Fraud Defense home page. This dashboard helps you monitor and analyze automated agent traffic on your site by distinguishing verified agents from suspected agents.
For more information, see Monitor agent traffic.
AlloyDB for PostgreSQL
Feature
IAM group authentication for AlloyDB is available in Preview for new clusters running PostgreSQL 15 and later. This feature simplifies database user management by allowing access management at the group level, where group members inherit database roles and permissions. To use this feature, enable the alloydb.iam_authentication and alloydb.iam_group_authentication database flags.
For more information, see IAM group authentication and Manage IAM authentication.
Compute Engine
Feature
Hyperdisk Balanced volumes on C4D instances have increased maximum throughput limits for these machine types:
c4d-*-96: 3,125 MiB/s (up from 2,800 MiB/s).c4d-*-192: 6,250 MiB/s (up from 4,800 MiB/s).c4d-*-384: 12,500 MiB/s (up from 10,000 MiB/s).
For detailed performance limits, see Hyperdisk Balanced performance limits when attached to an instance.
Confidential VM
Issue
Starting August 2026, Confidential VM instances using AMD SEV-SNP might have longer boot times and performance changes due to a guest kernel migration and security updates. This issue is expected to be resolved by November 2026. Confidential VM instances using AMD SEV or Intel TDX aren't affected.
Container Optimized OS
Change
cos-129-19506-299-60
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.12.94 | v27.5.1 | v2.2.5 | See List |
Fixed
Updated udev rule for protected_stateful_partition
Fixed
Upgraded app-admin/fluent-bit to v4.2.7.
Security
Fixed CVE-2026-29111 in sys-apps/systemd
Security
Fixed CVE-2026-3644 in dev-lang/python
Security
Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.
Security
Fixed CVE-2026-53381 in the Linux kernel.
Security
Fixed CVE-2026-53385 in the Linux kernel.
Security
Fixed CVE-2026-53388 in the Linux kernel.
Security
Fixed CVE-2026-53391 in the Linux kernel.
Security
Fixed CVE-2026-53392 in the Linux kernel.
Security
Fixed CVE-2026-53393 in the Linux kernel.
Security
Fixed CVE-2026-53394 in the Linux kernel.
Security
Fixed CVE-2026-53397 in the Linux kernel.
Security
Fixed CVE-2026-53398 in the Linux kernel.
Security
Fixed CVE-2026-53400 in the Linux kernel.
Security
Fixed CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and CVE-2026-60002 in openssh.
Security
Fixed CVE-2026-6019 in dev-lang/python
Security
Fixed CVE-2026-63795 in the Linux kernel.
Security
Fixed CVE-2026-63800 in the Linux kernel.
Security
Fixed CVE-2026-63802 in the Linux kernel.
Security
Fixed CVE-2026-63806 in the Linux kernel.
Security
Fixed CVE-2026-63807 in the Linux kernel.
Security
Fixed CVE-2026-63809 in the Linux kernel.
Security
Fixed CVE-2026-63810 in the Linux kernel.
Security
Fixed CVE-2026-63823 in the Linux kernel.
Security
Fixed CVE-2026-63824 in the Linux kernel.
Security
Fixed CVE-2026-63827 in the Linux kernel.
Security
Fixed CVE-2026-63828 in the Linux kernel.
Security
Fixed CVE-2026-63829 in the Linux kernel.
Security
Fixed CVE-2026-63830 in the Linux kernel.
Security
Fixed CVE-2026-63833 in the Linux kernel.
Security
Fixed CVE-2026-64187 in the Linux kernel.
Security
Fixed CVE-2026-64189 in the Linux kernel.
Change
cos-125-19216-532-42
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.12.94 | v27.5.1 | v2.1.9 | See List |
Fixed
Fixed an important bug for xfs file system users.
Fixed
Updated udev rule for protected_stateful_partition
Security
Fixed CVE-2026-29111 in sys-apps/systemd
Security
Fixed CVE-2026-3644 in dev-lang/python
Security
Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.
Security
Fixed CVE-2026-53381 in the Linux kernel.
Security
Fixed CVE-2026-53385 in the Linux kernel.
Security
Fixed CVE-2026-53388 in the Linux kernel.
Security
Fixed CVE-2026-53391 in the Linux kernel.
Security
Fixed CVE-2026-53392 in the Linux kernel.
Security
Fixed CVE-2026-53393 in the Linux kernel.
Security
Fixed CVE-2026-53394 in the Linux kernel.
Security
Fixed CVE-2026-53397 in the Linux kernel.
Security
Fixed CVE-2026-53398 in the Linux kernel.
Security
Fixed CVE-2026-53400 in the Linux kernel.
Security
Fixed CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and CVE-2026-60002 in openssh.
Security
Fixed CVE-2026-6019 in dev-lang/python
Security
Fixed CVE-2026-63795 in the Linux kernel.
Security
Fixed CVE-2026-63800 in the Linux kernel.
Security
Fixed CVE-2026-63802 in the Linux kernel.
Security
Fixed CVE-2026-63806 in the Linux kernel.
Security
Fixed CVE-2026-63807 in the Linux kernel.
Security
Fixed CVE-2026-63809 in the Linux kernel.
Security
Fixed CVE-2026-63810 in the Linux kernel.
Security
Fixed CVE-2026-63823 in the Linux kernel.
Security
Fixed CVE-2026-63824 in the Linux kernel.
Security
Fixed CVE-2026-63827 in the Linux kernel.
Security
Fixed CVE-2026-63828 in the Linux kernel.
Security
Fixed CVE-2026-63829 in the Linux kernel.
Security
Fixed CVE-2026-63830 in the Linux kernel.
Security
Fixed CVE-2026-63833 in the Linux kernel.
Security
Fixed CVE-2026-64187 in the Linux kernel.
Security
Fixed CVE-2026-64189 in the Linux kernel.
Change
cos-117-18613-675-28
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.6.143 | v24.0.9 | v1.7.34 | See List |
Fixed
Upgraded net-fs/cifs-utils to v7.7, Upgraded sys-libs/talloc to v2.4.4-r1.
Security
Fixed CVE-2026-29111 in sys-apps/systemd
Security
Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.
Security
Fixed CVE-2026-53381 in the Linux kernel.
Security
Fixed CVE-2026-53385 in the Linux kernel.
Security
Fixed CVE-2026-53388 in the Linux kernel.
Security
Fixed CVE-2026-53391 in the Linux kernel.
Security
Fixed CVE-2026-53397 in the Linux kernel.
Security
Fixed CVE-2026-53398 in the Linux kernel.
Security
Fixed CVE-2026-6019 in dev-lang/python
Security
Fixed CVE-2026-63794 in the Linux kernel.
Security
Fixed CVE-2026-63795 in the Linux kernel.
Security
Fixed CVE-2026-63800 in the Linux kernel.
Security
Fixed CVE-2026-63802 in the Linux kernel.
Security
Fixed CVE-2026-63807 in the Linux kernel.
Security
Fixed CVE-2026-63809 in the Linux kernel.
Security
Fixed CVE-2026-63823 in the Linux kernel.
Security
Fixed CVE-2026-63824 in the Linux kernel.
Security
Fixed CVE-2026-63827 in the Linux kernel.
Security
Fixed CVE-2026-63828 in the Linux kernel.
Security
Fixed CVE-2026-63830 in the Linux kernel.
Gemini Enterprise
Feature
Gemini Enterprise: Microsoft Teams federated connector is generally available (GA)
The Microsoft Teams federated data store is generally available (GA) in Gemini Enterprise. Connect Microsoft Teams to query channels, chats, teams, and messages, and execute supported actions directly from the assistant.
For more information, see Connect Microsoft Teams.
Google Kubernetes Engine
Feature
GKE now supports opting out of the default kubernetes.io/arch=arm64:NoSchedule
taint on Arm nodes in Standard node pools and in custom ComputeClasses. To opt
out of the default taint, set the --node-architecture-taint-behavior gcloud
CLI flag to NONE for a node pool or set the
taintConfig.architectureTaintBehavior field to NONE for a ComputeClass. By
configuring this behavior, you allow workloads that lack explicit Arm
tolerations to be scheduled on Arm-based machine families (such as N4A and C4A).
This is useful for running multi-architecture workloads or simplifying
scheduling in mixed-mode clusters. For more information, see
Configure the default Arm architecture taint.
Feature
GKE Gateway and Inference Gateway now support Cross-Origin Resource Sharing
(CORS). You can configure a CORS filter directly on an HTTPRoute resource by
using the portable syntax standardized by
Gateway API.
This feature is available in Preview in GKE version 1.35 and later for the
following GatewayClasses:
gke-l7-rilbgke-l7-regional-external-managedgke-l7-global-external-managed
For more information, see Configure Cross-Origin Resource Sharing.
Google SecOps
Feature
[Spotlight Feature] Data RBAC for first-party (1P) cases and alerts
Availability This feature is now available in public preview for all regions.
Google SecOps now supports data role-based access control (Data RBAC) for first-party (1P) SOAR cases and alerts. This feature automatically applies SIEM data access scopes to alerts and cases ingested using the Chronicle connector, ensuring analysts only see data they are authorized to access.
For more information, see the Release Note entry for July 6th.
Security Command Center
Feature
Version 1.2.0 of the Google SCC ITSM app and version 1.3.0 of the Google SCC SIR app have been released.
To reflect this update, the ServiceNow integration guide is updated with the following changes:
- Added support for ServiceNow Yokohama, Zurich, and Australia versions.
Added the following features:
- Mute and unmute findings
- Create mute rules
- Create Configuration Item (CI) lookup rules
- View the action log
Updated setup instructions for Java KeyStore certificates.
Added additional troubleshooting steps for maximum execution time exceeded errors, data collection issues, and ECC Queue timeout errors.
For more information, see Sending Security Command Center data to ServiceNow.
Spanner
Feature
Spanner supports creating tables without defining primary keys.
When you create a table without a primary key, Spanner creates a
hidden rowid column that serves as the primary key. For more information, see
Create a table without defining a primary key.
AlloyDB for PostgreSQL
Feature
AlloyDB write endpoints are now available in Preview. Write endpoints simplify database connection management by providing a stable domain name service (DNS) name for your applications, decoupling them from instance IP addresses. During disaster recovery switchovers or failovers, AlloyDB automatically updates the endpoint to point to the new primary instance.
For more information, see Manage database connections with write endpoints.
Feature
AlloyDB now supports cross-region failover in Preview. You can optionally enable cross-region failover to automate the recreation of the original primary when a secondary cluster is promoted while maintaining your replication topology without requiring manual cluster deletion or re-creation. Cross-region failover is supported only for topologies with a single primary cluster and a single secondary cluster.
For more information, see About cross-region replication and Work with cross-region replication.
Feature
External search with AlloyDB now supports OpenSearch in Preview.
You can use the external_search_fdw extension to connect to an OpenSearch cluster and query its data directly from your database.
Anthos Config Management
Change
Upgraded bundled Helm version from v3.20.2 to v3.21.1 to pick up vulnerability fixes. To understand the changes in each release, review the changelogs.
Change
Addressed multiple Common Vulnerabilities and Exposures (CVEs) by updating dependencies.
Apigee X
Announcement
On July 27th, 2026, we released an updated version of Apigee (1-18-0-apigee-2).
Security
| Bug ID | Description |
|---|---|
| 534852923 | Security fix for Apigee. Fixed a security issue in the Java Callout policy. |
| N/A | Security fix for Apigee infrastructure. |
Fixed
| Bug ID | Description |
|---|---|
| N/A | Updates to infrastructure and libraries. |
App Engine flexible environment Node.js
Feature
Support for the Node.js 26 runtime is in Preview.
App Engine standard environment Node.js
Feature
Support for the Node.js 26 runtime is in Preview.
BigQuery
Feature
You can discover commercial BigQuery sharing listings on Google Cloud Marketplace with the Marketplace filter. For more information, see Subscribe to a Cloud Marketplace-integrated listing. This feature is generally available (GA).
Feature
You can use the APPENDS and CHANGES change history functions
to view the rows that were appended to or changed in a table during a given time
range. This feature is
generally available
(GA).
Feature
You can use the Google-developed Open Database Connectivity (ODBC) driver for BigQuery to connect your applications to BigQuery. This feature is generally available (GA).
Change
The feature formerly known as the legacy tabledata.insertAll method is now
called the
Storage Write API (REST). The
feature formerly known as the Storage Write API is now called the
Storage Write API (gRPC).
Feature
BigQuery dataset insights is generally available (GA).
BigQuery dataset insights helps you discover and visualize relationships between tables and automatically generate cross-table queries. You can run and publish these insights to Knowledge Catalog for agentic grounding use cases, or generate them on demand without publishing for quick, ad hoc dataset exploration.
Bigtable
Feature
The Bigtable remote MCP server supports the Bigtable Data API, which
provides the execute_sql tool that you can use to query Bigtable data using
natural language prompts. This feature is
generally available (GA).
For more information, see
Use the Bigtable remote MCP server.
Cloud Billing
Feature
Spend cap budgets are now available for a limited set of services (Preview)
Available in Preview for eligible services, you can now configure a spend cap budget to automatically pause usage when your spend exceeds the budget amount you set.
Spend caps are a cost control mechanism. A spend cap is enforced when usage costs exceed your budget target amount. When enforced, any new request to the eligible services, within the specified project, are paused and no further usage costs are accrued until you manually lift the spend cap.
Spend caps typically use estimated costs to trigger the alerts and caps, enforcing a cap much faster than the actual costs are processed and appear on billing reports. Even though faster than reports, the enforcement of spend caps isn't instant and any cost overages are billed as normal.
For more information about spend cap budgets, see:
- How spend cap budgets work to help you control spend
- Configure a spend cap budget
- Lift an enforced spend cap
- Limitations of spend cap budgets
Cloud Load Balancing
Feature
Service load balancing policies (serviceLbPolicy) are now supported for
regional external Application Load Balancers and regional internal Application Load Balancers. This feature enables
advanced load balancing optimizations such as custom load balancing algorithms,
auto-capacity draining, failover thresholds, and the ability to designate
preferred backends for these load balancers.
For more information, see Advanced load balancing optimizations.
This feature is in Preview.
Cloud NGFW
Breaking
Enabling WildFire in an existing firewall endpoint can cause a temporary data plane outage. As a result, the WildFire feature is temporarily removed.
Cloud Run
Feature
Support for the Node.js 26 runtime is in Preview.
Feature
Support for Budget spend caps to pause your Cloud Run workloads is in Preview.
Cloud Run functions
Feature
Support for the Node.js 26 runtime is in Preview.
Compute Engine
Feature
The maximum IOPS per GiB for Hyperdisk Balanced Storage Pools have increased from 4 IOPS per GiB. The new limits depend on the provisioning type:
- Standard performance: 30 IOPS per GiB
- Advanced performance: 6 IOPS per GiB
For more information, see Limits for Hyperdisk Storage Pools.
Dataform
Feature
Dataform deployments provide a centralized experience for creating and managing pipeline deployments connected to remote Git repositories. This feature is available in Preview.
Gemini Enterprise
Feature
Gemini Enterprise: Transparent thinking
Transparent thinking is generally available (GA). During chat interactions, the assistant shares its real-time reasoning and planning in the user interface before calling tools or data sources.
An expandable section displays the tool activity between the thinking phase and the final answer. This transparency delivers a faster time to first token (TTFT) and improves perceived latency without increasing total response time.
For more information, see Ask questions and view sources.
Google Cloud Managed Service for Apache Kafka
Feature
You can now create a Cloud SQL for PostgreSQL Source connector and a Generic PostgreSQL Source connector for Kafka Connect.
A Cloud SQL for PostgreSQL Source connector or Generic PostgreSQL Source connector is an instance of a Debezium PostgreSQL connector. It reads row-level changes from a PostgreSQL database and writes them to topics in a Managed Service for Apache Kafka cluster.
For more information, see Create a Cloud SQL for PostgreSQL Source connector, Create a Generic PostgreSQL Source connector, and Troubleshoot a PostgreSQL Source connector.
Google Kubernetes Engine
Feature
In GKE version 1.36 and later, GKE Dataplane V2 with NetworkPolicies supports up to 15,000 nodes per cluster, increased from the previous limit of 7,500 nodes. For clusters exceeding 5,000 nodes, contact Cloud Customer Care to request a quota increase. For more information, see Cluster size limits and requirements.
Feature
In version 1.36.2-gke.1498000 and later, GKE supports mixed-protocol Services of type LoadBalancer in general availability (GA). Mixed-protocol Services let both external (NetLB) and internal (ILB) passthrough Network Load Balancers handle simultaneous TCP and UDP traffic on a single IP address across IPv4, IPv6, and dual-stack environments.
Security
The general availability (GA) stage of mixed-protocol Services of type LoadBalancer fixes errors in traffic routing from stages prior to GA. This feature is in the GA stage in GKE version 1.36.2-gke.1498000 and later.
Guest Environment
Fixed
Version 20260716.00 of the guest agent
is now available for all supported operating systems. This version introduces
the following fixes:
- The
systemctl startoperations performed by the OS Login module no longer leave behind zombie processes. - The extensions monitor, which monitors the health of extensions that the guest agent manages, no longer logs an error when it reads an empty log file from an extension.
- Dependency updates address multiple high-severity CVEs, such as CVE-2026-39830 and CVE-2026-39832.
Identity and Access Management
Feature
Managed workload identities for Compute Engine are generally available.
For more information, see Configure managed workload identity authentication for Compute Engine.
Memorystore for Valkey
Feature
Added support for Valkey version 9.1. As a result, you can now upgrade the version of your Memorystore for Valkey instance to 9.1. For more information, see About upgrading the Valkey version of an instance. This feature is available in Preview.
Secret Manager
Feature
Automatic rotation of regional Cloud SQL database credentials in Secret Manager is available in Preview. This feature lets you automatically generate secure passwords, update target Cloud SQL database instances (PostgreSQL or SQL Server), and rotate secret versions on a configured schedule without custom Cloud Run functions.
For more information, see Automatic rotation of Cloud SQL secrets.
Security Command Center
Feature
For the Security Command Center Premium tier, you can enable AI Protection at the project level.
Project-level activations include access to the AI security dashboard, AI threat detection, and AI vulnerability and misconfiguration findings.
Some features of AI Protection are only available for organization-level activations. For more information, see Configure AI Protection.
Feature
For the Security Command Center Premium tier, you can enable AI Protection at the project level.
Project-level activations include access to the AI security dashboard, AI threat detection, and AI vulnerability and misconfiguration findings.
For more information, see Configure AI Protection.
Google SecOps
Feature
Customizable schedules for multi-event rules
Customizable schedules for multi-event rules are available in public preview. You can customize rule execution schedules on the Rule schedule tab to specify a first-run delay offset that accounts for data ingestion latency. The system also performs automated background true-up runs to catch late-arriving logs and process metadata enrichment without requiring manual system interventions. This gives you precise control over detection evaluation timing, reduces false negatives without missing detections, and promotes alert accuracy.
To view or modify rule schedules using custom Identity and Access Management (IAM) roles, update your IAM permissions to include the following:
chronicle.ruleDeployments.updateto update individual rule schedules using the API.chronicle.rules.modifyRulesto modify rule schedules using the web interface or in batch using the API.
If you use predefined IAM roles, such as Chronicle API Admin (roles/chronicle.admin) or Chronicle API Editor (roles/chronicle.editor), these permissions are included automatically.
Feature
[Spotlight Feature] Investigation and case management experience
This feature is in public preview. Google SecOps now includes a revamped Investigation Management experience that supports tracking raw UDM events and detections alongside alerts to accommodate new investigation types (such as retrohunt and threat hunt) and higher investigation volumes in cases. You can navigate your case queue using customizable table views, side-drawer previews, and integrated UDM Search workflows. For more information, see Investigation and case management overview.
This preview is currently supported only for single-SIEM deployments (instances where a single Google SecOps SIEM instance ingests data into SOAR) and does not support federated or MSSP environments.
Additional enhancements include:
- Attach SIEM search results to cases: Manually attach individual UDM events or detections directly from SIEM search results to new or existing cases as core evidence (supporting up to 500 detections and 5,000 UDM events per case). For details, see Attach SIEM search results to cases.
- Interactive Events Viewer: Dive directly into technical evidence from an interactive side panel. Inspect parsed UDM records, review original raw logs, pin key evidence to your case, and build detection exclusions in real time. For details, see Use the Events Viewer.
- Configure new default views: Before enabling the updated Cases experience, set up your default views under SOAR Settings > Case Data > Views. Make sure to manually copy over advanced widget configurations (such as Safe HTML Rendering or custom conditions) from the Default Alert View and Default Case View to the New Default Alert View and New Default Case View to preserve your preferred setups.
Google SecOps SOAR
Announcement
Release 6.3.95 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Apigee API hub
Feature
General availability (GA) launch of Model Context Protocol (MCP) in API hub
The API hub MCP server is Generally Available (GA). This release enables seamless integration between your AI agents and API hub, allowing your applications to discover, query, and manage your API ecosystem using natural language.
What's new in GA
- Expanded read and write capabilities: AI agents can create, update, and delete APIs, versions, specs, and deployments. They can also configure and deploy MCP discovery proxies in Apigee.
- Global endpoint routing: Connect to the API hub MCP server using the global endpoint (
apihub.googleapis.com/mcp), in addition to the supported regional endpoints. For a list of supported regions, see the API hub MCP reference. - Granular OAuth scopes: Use service-specific OAuth scopes (
apihub.readonlyandapihub.readwrite) for more secure access. - Model Armor integration: Protect MCP tool invocations from prompt-injection and other attacks by integrating with Model Armor.
For configuration details and a complete list of available tools, see API hub MCP reference.
Feature
Configure and deploy MCP servers with API hub RPC
API hub now includes a new RPC, ConfigureAndDeployServer, which enables the configuration and deployment of Model Context Protocol (MCP) servers directly to an Apigee runtime.
For more information, see Manage MCP proxies and the API hub reference.
Apigee hybrid
Announcement
v1.16.8
On July 24, 2026 we released an updated version of the Apigee hybrid software, v1.16.8.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.16.
- For information on new installations, see The big picture.
Fixed
Fixed in this release
| Bug ID | Description |
|---|---|
| 493354568 | Fixed an issue where component-specific nodeSelector configurations are ignored in Helm charts. |
Feature
Runtime rollout strategy configuration
In this release, you can configure the rollout strategy used when updating runtime (message processor) ReplicaSets by setting the runtime.release.strategy property (with options rolling, scale-down-first, or none) or per-environment with envs[].components.runtime.release.strategy in your overrides configuration file. The property defaults to rolling.
Security
Various security and CVE fixes are included in this release.
Artifact Registry
Feature
Connector repositories act as proxies for upstream sources. All requests to the repository are proxied to the upstream source and no artifacts are cached in Artifact Registry. This configuration allows for full auditability of upstream sources and supports cases where third-party policies prevent artifact caching. For more information, see Connector repositories overview.
Backup and DR
Feature
You can now use Model Context Protocol (MCP) servers with Backup and DR Service to connect AI assistants and applications—such as the Gemini CLI, ChatGPT, or Claude—with your backup environment. Using either the local or remote MCP server, you can use natural language prompts to perform and automate Backup and DR tasks, such as creating backup plans, triggering on-demand backups, and managing backup vaults. Comprehensive reference documentation is also available with detailed specifications, input and output schemas, and sample invocation commands for all available MCP tools.
For more information, see the following:
Cloud API Registry
Deprecated
As of July 30, 2026, support for Model Context Protocol (MCP) servers and tools will be shut down. You will not be able to retrieve, list, enable, and disable MCP servers and tools using the Cloud API Registry API. For more information, see Feature deprecations.
Cloud Billing
Feature
Early signals for AI workloads
For AI workloads (such as Gemini API and Vertex AI), you can now view early anomalies. Early anomalies use near real-time cost estimates to provide daily, service-level insights before finalized billing occurs. You can view these alerts on the By service (Early signals) tab on the Anomalies dashboard in the Google Cloud console. User-configured thresholds do not apply to early anomalies.
For more information, see View early anomalies for AI workloads.
Cloud SQL for PostgreSQL
Feature
Cloud SQL for PostgreSQL now supports logical replication using failover slot which you can use with advanced disaster recovery (DR) switchover and replica failover operations to ensure business continuity.
For more information, see Advanced disaster recovery (DR) with logical failover slot.
Cloud Service Mesh
Feature
The Envoy Compressor Filter is now GA in the stable release channel.
Compute Engine
Feature
You can observe real-time virtual machine (VM) distribution across zones, machine types, and instance states in your managed instance groups (MIGs) by using the GCE MIG Instance Distribution Monitoring dashboard in Cloud Monitoring. When your group uses location flexibility across zones, instance flexibility across machine types, or both, this visibility helps you monitor capacity allocation and diagnose runtime fallback behavior. For more information, see Monitor instance distribution in MIGs.
Gemini Enterprise
Feature
Gemini Enterprise: Gemini 3.6 Flash in US multi-region
If your project is on the allowlist, you can use Gemini 3.6 Flash in the US
multi-region (us) with data residency at-rest (DRZ) and machine learning
processing (MLP).
To request access to Gemini 3.6 Flash in the US multi-region, contact your Google account team.
For more information, see Data residency for Gemini Enterprise Standard and Plus Editions and Gemini Notebook Enterprise
Feature
Gemini Enterprise: Create and edit documents and slides in Canvas (GA)
The Canvas assistant is generally available within the Gemini Enterprise web app. Canvas is a dedicated, interactive tool thats allows you to create and edit AI-generated documents and presentations directly from your chats. You can then export these to Google Workspace, Microsoft Office formats, and PDF.
For more information, see Create and edit documents and slides in Canvas.
A Gemini Enterprise app administrator must turn on the Enable canvas toggle in the web app feature management settings to let users use it. For more information about feature controls, see Manage features on the web app.
Gemini Enterprise Agent Platform
Feature
Anthropic's Claude Opus 5
Claude Opus 5 is available in Model Garden.
Google Cloud Contact Center as a Service
Announcement
Google Cloud CCaaS 5.0
We've released version 5.0 of Google Cloud CCaaS.
The timing of the update to your instance depends on the deployment schedule that you have chosen. For more information, see Deployment schedules.
Feature
Disposition timing
You can now configure CCAI Platform so agents can attribute wrap-up time, disposition code, and notes to a previous interaction. You can also let agents modify the disposition code and notes of previously completed sessions.
Administrators: In the Settings > Operation Management > Wrap-up pane, a new Manual Wrap-up section is available.
User experience change: If configured, a new Previous Sessions list appears in the agent adapter.
For more information, see Configure disposition timing.
Feature
API direct access point for chat
The API direct access point (DAP) for chat lets you automatically route incoming chat sessions to a queue based on a response from an external API endpoint that you configure. This eliminates the need for end-users to select from a queue menu.
By default, this capability is inactive. Contact Google Cloud Support to turn it on for your instance.
For more information, see API direct access point for chat.
Fixed
This release addresses the following issues:
Fixed an issue where emails were stuck in a Transferring state when moved between queues.
Fixed an issue where end-users didn't receive messages from agents during web chats.
Fixed an issue where calls or chats remained in a queue without being offered to available agents.
Fixed an issue where voice calls were prematurely moved from an agent's queue during a multi-group cascade.
Fixed an issue where the disposition panel didn't appear after a call ended, leaving agents unable to change their status without signing out and signing in.
Fixed an issue where end-users were incorrectly assigned to teams and skills they weren't originally part of during bulk CSV imports.
Fixed an issue where interaction transcripts for calls in non-English languages were incorrect.
Fixed an issue in Salesforce integrations where incoming chat audio and desktop notifications didn't play for agents using the embedded CCAI Platform widget.
Fixed an issue where the inactive chat dismissal timer didn't reset after a chat was transferred from a virtual agent to a human agent.
Fixed an issue where voicemails disappeared from the queue immediately after being opened.
Fixed an issue where the reporting dashboard incorrectly displayed call and agent status during a cold transfer to another queue.
Improved rendering performance in the agent desktop mini chat adapter.
Fixed an issue where the storage path for screen recordings didn't align with the folder structure displayed in the user interface.
Fixed an issue where missing public files were incorrectly cached by the CDN for up to seven days.
Fixed an issue where agents were automatically redirected to the Closed inbox view after changing an interaction status to Closed.
Fixed an issue where the You cannot log out when in a chat notification was truncated in the chat adapter.
Fixed an issue with Salesforce integrations where rapid, concurrent data requests caused information to be lost.
Fixed an issue where duplicate call recording links were posted to Zendesk tickets for multi-segment calls.
Fixed an issue with Salesforce integrations where the UI retained settings from a previous Salesforce organization after switching to a new organization.
Fixed an issue where duplicate customer satisfaction surveys were submitted and recorded for a single live chat session.
Fixed an issue where the message field in the chat adapter was inactive when an agent accepted a new chat.
Fixed an issue where task virtual agents were incorrectly identified as Nobody when joining a conversation after a transfer from a human agent.
Fixed an issue that occurred when a chat entered a queue and the greeting message was sent before an agent was assigned. In these cases, the associated push notification crashed and logged an error, producing excessive noise in logs.
Fixed an issue where the agent's final message in a chat session appeared after This chat is ended in the chat adapter and the CRM transcript.
Fixed an issue where agents using instances without a CRM configuration received a No Account Detected warning when making outbound calls.
Fixed an issue where notification chimes played after an agent had connected to an active call.
Fixed an issue where the country code list didn't automatically update the country flag when a phone number was entered without the
+prefix.Fixed an issue where calls to an agent's personal queue didn't break through if the agent was also assigned to an inbound queue with breakthrough disabled.
Fixed an issue where outbound calls that were transferred to a queue didn't adhere to the queue's deltacast configuration.
Fixed an issue where the agent desktop became unstable or didn't load.
Fixed an issue where wrap-up time was incorrectly reported when agents exceeded the configured wrap-up time.
Fixed an issue where the IVR queues dashboard didn't load for instances with a large volume of queues.
Fixed an issue where calls to the
manager/api/v1/agent_activity_logsendpoint timed out whensort_directionwas turned off.
Google Cloud Marketplace Partners
Feature
You can now use the Cloud Commerce Producer API to programmatically create, manage, and publish private offers. The API lets you automate your private offer workflows, including configuring custom pricing models, attaching EULA or SOW documents, and determining which active offer to amend.
For more information, see Create and manage private offers using the API and Determine which offer to amend.
Google Distributed Cloud (software only) for bare metal
Fixed
A release note published on May 6, 2025 stated that each Keepalived instance
virtual router redundancy protocol (VRRP) configuration is configured with a
nopreempt flag to avoid elections when a non-master instance is restarted.
The nopreempt flag was removed in release 1.32.200 and later. For more
information, see Control plane VIP isn't moved when HAProxy is unavailable.
Google Kubernetes Engine
Change
(2026-R31) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters.
The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.
Rapid channel
- Version 1.36.2-gke.1498000 is now the default version for cluster creation in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.33.13-gke.1101000
- 1.34.9-gke.1287000
- 1.35.6-gke.1250000
- 1.36.0-gke.4681000
- 1.36.2-gke.1346000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1109000
- 1.33 to 1.34.9-gke.1322000
- 1.34 to 1.35.6-gke.1258000
- 1.35 to 1.36.2-gke.1498000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1109000
- 1.34 to 1.34.9-gke.1322000
- 1.35 to 1.35.6-gke.1258000
- 1.36 to 1.36.2-gke.1498000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Regular channel
- Version 1.35.6-gke.1127000 is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.33.12-gke.1270000
- 1.34.9-gke.1065000
- 1.35.6-gke.1049000
- 1.36.0-gke.3712000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1011000
- 1.33 to 1.34.9-gke.1131000
- 1.34 to 1.35.6-gke.1127000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1011000
- 1.34 to 1.34.9-gke.1131000
- 1.35 to 1.35.6-gke.1127000
- 1.36 to 1.36.0-gke.4447000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Stable channel
- The following versions are now available in the Stable channel:
Extended channel
- Version 1.35.6-gke.1127000 is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
- The following versions are no longer available in the Extended channel:
- 1.30.14-gke.2746000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.30.14-gke.2825000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2157000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2246000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1829000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1930000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.33.12-gke.1270000
- 1.34.9-gke.1065000
- 1.35.6-gke.1049000
- 1.36.0-gke.3712000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.29 to 1.30.14-gke.2767000
- 1.30 to 1.31.14-gke.2169000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.30 to 1.30.14-gke.2767000
- 1.31 to 1.31.14-gke.2169000
- 1.32 to 1.32.13-gke.1844000
- 1.33 to 1.33.13-gke.1011000
- 1.34 to 1.34.9-gke.1131000
- 1.35 to 1.35.6-gke.1127000
- 1.36 to 1.36.0-gke.4447000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
No channel (deprecated)
- Version 1.35.6-gke.1127000 is now the default version for cluster creation.
- The following versions are now available:
- The following node versions are now available:
- The following versions are no longer available:
- 1.35.5-gke.1241004 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.3712000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1011000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1011000
- 1.35 to 1.35.6-gke.1127000
- 1.36 to 1.36.0-gke.4447000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Security
(2026-R31) Security updates
This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.
To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:
| GKE version | Container-Optimized OS version | Details |
|---|---|---|
| 1.32.13-gke.2137000 | cos-117-18613-675-2 | cos-117-18613-675-2 release notes |
| 1.34.9-gke.1610000 | cos-125-19216-532-3 | cos-125-19216-532-3 release notes |
| 1.36.2-gke.2064000 | cos-129-19506-299-3 | cos-129-19506-299-3 release notes |
Change
(2026-R31) Version updates
- The following versions are now available in the Stable channel:
Change
(2026-R31) Version updates
- Version 1.35.6-gke.1127000 is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.33.12-gke.1270000
- 1.34.9-gke.1065000
- 1.35.6-gke.1049000
- 1.36.0-gke.3712000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1011000
- 1.33 to 1.34.9-gke.1131000
- 1.34 to 1.35.6-gke.1127000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1011000
- 1.34 to 1.34.9-gke.1131000
- 1.35 to 1.35.6-gke.1127000
- 1.36 to 1.36.0-gke.4447000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R31) Version updates
- Version 1.36.2-gke.1498000 is now the default version for cluster creation in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.33.13-gke.1101000
- 1.34.9-gke.1287000
- 1.35.6-gke.1250000
- 1.36.0-gke.4681000
- 1.36.2-gke.1346000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1109000
- 1.33 to 1.34.9-gke.1322000
- 1.34 to 1.35.6-gke.1258000
- 1.35 to 1.36.2-gke.1498000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1109000
- 1.34 to 1.34.9-gke.1322000
- 1.35 to 1.35.6-gke.1258000
- 1.36 to 1.36.2-gke.1498000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R31) Version updates
- Version 1.35.6-gke.1127000 is now the default version for cluster creation.
- The following versions are now available:
- The following node versions are now available:
- The following versions are no longer available:
- 1.35.5-gke.1241004 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.3712000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1011000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1011000
- 1.35 to 1.35.6-gke.1127000
- 1.36 to 1.36.0-gke.4447000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R31) Version updates
- Version 1.35.6-gke.1127000 is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
- The following versions are no longer available in the Extended channel:
- 1.30.14-gke.2746000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.30.14-gke.2825000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2157000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2246000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1829000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1930000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.33.12-gke.1270000
- 1.34.9-gke.1065000
- 1.35.6-gke.1049000
- 1.36.0-gke.3712000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.29 to 1.30.14-gke.2767000
- 1.30 to 1.31.14-gke.2169000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.30 to 1.30.14-gke.2767000
- 1.31 to 1.31.14-gke.2169000
- 1.32 to 1.32.13-gke.1844000
- 1.33 to 1.33.13-gke.1011000
- 1.34 to 1.34.9-gke.1131000
- 1.35 to 1.35.6-gke.1127000
- 1.36 to 1.36.0-gke.4447000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Knowledge Catalog
Feature
Governance workflows let you set up automated controls for data product access management by providing a request-review mechanism. This feature is available in preview.
For more information, see About governance workflows.
Managed Service for Apache Airflow
Announcement
Starting in September, 2026, Airflow 2.10.5 will no longer be included in new Managed Airflow images and builds. This change will not affect existing images and builds.
Announcement
Starting in September 2026, we are changing the version support policy for Managed Airflow (Gen 2) to align it with the Managed Airflow (Gen 3) policy. The changes will affect Airflow 2 versions that we release:
- In Managed Airflow (Gen 2), we will release only new images with Airflow 2.11. New Airflow 2.10.5 images will no longer be released.
- In Managed Airflow (Gen 3) we will keep releasing new builds of Airflow 3 (no changes) and will release only new Airflow 2.11 builds. New Airflow 2.10.5 builds will no longer be released.
SAP on Google Cloud
Announcement
New SAP certification for operating system: SLES 16 for SAP
For use with SAP HANA and SAP NetWeaver on Google Cloud, SAP has certified the operating system SUSE Linux Enterprise Server (SLES) 16 for SAP.
For more information about SAP-certified operating systems, see:
Service Usage
Deprecated
As of July 30, 2026, support for managing Model Context Protocol (MCP) server enablement and consumer policies using the Service Usage v2beta API will be shut down.
For more information, see Feature deprecations.
reCAPTCHA
Feature
Preview: Policy Engine, Universal keys, and challenge policies are available in Preview for Google Cloud Fraud Defense.
- Policy Engine lets you perform frontend JavaScript integration using AutoExecute and configure custom rules to selectively trigger CAPTCHA challenges based on risk score, IP addresses, user agents, ASNs, or verified bot identities.
- A new AI-resistant QR code challenge is available.
For more information about the types of challenges that are available, see Challenge types.
Agent Registry
Feature
Agent skill governance is available in Preview.
Agent Registry supports standalone skill governance, helping enable secure, enterprise-level management and governance of standalone skills for AI agents. You can register skill resources, upload and validate ZIP payload packages, track version history through immutable skill revisions, and review verified skill publishers.
This release includes the following features:
- Lifecycle and versioning: Register and manage standalone
Skillresources, lifecycle states, and version snapshots (SkillRevision). - Console support: A dedicated Skills tab in Google Cloud Console to register, update, download, and monitor skills and revisions.
- Access policy enforcement: Use policy bindings to authorize reasoning engine agents to load standalone skills.
- Semantic search: Query the registry to search and discover standalone skills.
For more information, see Register skills and Manage skills.
AlloyDB for PostgreSQL
Feature
Transparent query forwarding is now available in Preview for clusters compatible with PostgreSQL 17 and 18. With this feature, the primary node in a cluster intercepts read-only queries and selectively forwards them to read pool instances while maintaining read-your-writes consistency.
For more information, see Optimize resources and isolate read queries with transparent query forwarding.
Apigee hybrid
Announcement
v1.14.7
On July 23, 2026 we released an updated version of the Apigee hybrid software, v1.14.7.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.14.
- For information on new installations, see The big picture.
Feature
Runtime rollout strategy configuration
In this release, you can configure the rollout strategy used when updating runtime (message processor) ReplicaSets by setting the runtime.release.strategy property (with options rolling, scale-down-first, or none) or per-environment with envs[].components.runtime.release.strategy in your overrides configuration file. The property defaults to rolling.
Security
Various security and CVE fixes are included in this release.
BigQuery
Change
An updated version of the Simba ODBC driver for BigQuery is now available.
Cloud Location Finder
Feature
Model Context Protocol (MCP) integration is available in Preview. This built-in integration lets LLM-powered agents securely retrieve data using standard MCP tools (search_cloud_locations and list_cloud_locations). For more information, see Use the Model Context Protocol (MCP) with Cloud Location Finder.
Cloud Router
Feature
Cloud Router support for named sets for BGP route policies is now generally available. For more information, see BGP route policies overview.
Vertex AI Search
Feature
Agent Search: Decrease thresholds for configurable pricing
You can decrease the storage size and queries per minute (QPM) subscription thresholds for configurable pricing. Previously, you could only increase these thresholds.
Decreased thresholds take effect at the start of the next billing cycle.
For more information, see Modify subscription thresholds. This feature is generally available (GA).
Access Approval
Feature
Privileged Access Manager is available in Preview.
Access Transparency
Feature
Privileged Access Manager is available in Preview.
Gemini Enterprise
Feature
Gemini Enterprise: Support for unauthenticated Custom MCP Server data stores (Preview)
When setting up a Custom MCP Server data store, you can select No authentication if your Model Context Protocol (MCP) server doesn't require authentication.
Creating a custom MCP Server data store is in Public Preview. For more information, see Set up a custom MCP server.
Google Distributed Cloud (software only) for bare metal
Announcement
Google Distributed Cloud (software only) for bare metal 1.34.700-gke.93 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud for bare metal 1.34.700-gke.93 runs on Kubernetes v1.34.7-gke.200.
After a release, it takes approximately 7 to 14 days for the version to become available for installations or upgrades with the GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.
If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.
Feature
The following change was added in 1.34.700-gke.93:
- Removed the deprecated
csi-snapshot-validation-webhookcomponent. Upstream Kubernetes validation is now handled natively via Common Expression Language (CEL) rules within the deployed Custom Resource Definitions (CRDs). For more information, see Volume snapshots.
Fixed
The following issues were fixed in 1.34.700-gke.93:
- Fixed vulnerabilities listed in Vulnerability fixes.
Google SecOps Marketplace
Feature
Wiz: Version 14.0
Added the following action:
- Get Blue Agent Analysis
Feature
SentinelOne Singularity Operations Center: Version 1.0
- Added SentinelOne Singularity Operations Center integration.
Feature
Proofpoint Email Protection: Version 10.0
Added the following action:
- Download Quarantined Email
Change
Azure Monitor: Version 5.0
- Updated integration documentation links in the integration configuration.
Change
QRadar: Version 69.0
Updated timestamp filtering to use
last_persisted_timefor tracking modifications in the following connector:- Qradar Offenses Connector
Change
Jira: Version 60.0
Added support for the
Created Beforedate filter andCustom JQLquery parameter in the following action:- List Issues
Change
Google Chronicle: Version 90.0
Updated handling of Wiz Defend detections and ontology mapping in the following connector:
- Chronicle Alerts Connector
Looker
Security
A Cross-Site Scripting (XSS) vulnerability was discovered in Looker. An attacker could craft a malicious URL that, when opened by a Looker administrator, would allow the attacker to execute arbitrary scripts on their behalf and potentially compromise the administrator account.
Both Looker-hosted and self-hosted instances were found to be vulnerable.
This issue has already been mitigated for Looker-hosted instances.
What should I do?
For Looker-hosted instances, no action is required.
For self-hosted Looker instances, update your Looker instances as soon as possible. This vulnerability has been patched in all supported versions of Looker for self-hosted instances. The following versions have all been updated to fix this vulnerability:
- Looker 26.8.7 and all later versions
- Looker 26.6.28+
- Looker 26.4.36+
- Looker 26.2.47+
- Looker 26.0.66+
- Looker 25.18.68+
- Looker 25.12.65+
- Looker 25.6.103+
For more information, see CVE-2026-15810.
Anthos Attached Clusters
Announcement
You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:
Anthos clusters on AWS
Announcement
You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:
Anthos clusters on Azure
Announcement
You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:
Binary Authorization
Feature
To provide long-term security and address threats from future quantum computers,
Binary Authorization supports keys that use post-quantum cryptography (PQC)
algorithms. These algorithms, such as ML-DSA-65 (Dilithium3), are standardized
to be resistant to attacks from both classical and quantum computers. To learn how
to generate a PQC key pair and create an attestor, see
Create post-quantum cryptography (PQC) keys.
Cloud Service Mesh
Feature
The Envoy Lua Filter is now available as a preview feature in the stable release channel.
Cloud Tasks
Feature
Cloud Tasks support for the following is available in Preview:
- Set retry parameters when creating a task and override the queue-level retry configuration for the task.
- Create a batch of tasks and add the batch to an existing queue.
- Delete a batch of tasks from a queue.
Compute Engine
Feature
Generally available: You can configure a regional managed instance group (MIG) to allow a VM repair in an alternate zone when the MIG can't repair the VM in its original zone. Repairing a VM in an alternate zone can help to improve your application's resiliency and resource obtainability. For more information, see Repair a VM in an alternate zone.
Gemini
Other
Bug fixes in IntelliJ
Various bug fixes and minor product enhancements.
Gemini Enterprise
Feature
Gemini Enterprise: Gemini 3.6 Flash available in the Global region
Gemini 3.6 Flash is available in the global region. To make Gemini 3.6 Flash
available to users in the Gemini Enterprise app, administrators must turn on
the Gemini 3.6 Flash feature toggle.
Gemini 3.6 Flash is also available in Agent Designer workflow agents. Updates take up to a day to appear in workflow agents.
For more information, see:
- Manage features on the web app
- Data residency for Gemini Enterprise Standard and Plus Editions and Gemini Notebook Enterprise
Announcement
Gemini Enterprise: Gemini 3.5 Flash removal in the Global region
Gemini 3.5 Flash will be removed as a model from the global region in the
Gemini Enterprise app on August 4, 2026.
For more information, see Manage features on the web app.
Gemini Enterprise Agent Platform
Feature
Gemini 3.6 Flash and 3.5 Flash-Lite are generally available (GA)
Gemini 3.6 Flash and Gemini 3.5 Flash-Lite are now generally available (GA) and available for production use. These models are designed to improve upon their predecessors' capabilities, including improved token usage and improved document understanding. See the linked model information pages for more information.
This release includes some potentially breaking changes from previous Flash and Flash-Lite models:
- Sampling parameters: Custom values for temperature, top-K, and top-P are not supported and will be ignored if set.
- Penalty parameters: Custom values for frequency and presence penalty parameters are not supported. Setting these will result in an API error.
- API turn structure: API requests where the last input turn has a role of
Modelare no longer supported and will return an error:- Interactions API: Requests where the last object in the input array
has
"type": "model_output"will fail. - GenerateContent API: Requests where the last object in the contents
array has
"role": "model"will fail.
- Interactions API: Requests where the last object in the input array
has
Deprecated
Open model endpoint deprecations
The following open model endpoints are deprecated and will be retired on October 21, 2026. For more information, see Open model deprecations.
deepseek-ocr-maasdeepseek-r1-0528-maasdeepseek-v3.2-maasdeepseek-v3.1-maasglm-5-maasglm-4.7-maasgpt-oss-20b-maaskimi-k2-thinking-maasllama-3.3-70b-instruct-maasminimax-m2-maasmultilingual-e5-large-instruct-maasmultilingual-e5-small-maasqwen3-235b-a22b-instruct-2507-maasqwen3-coder-480b-a35b-instruct-maasqwen3-next-80b-a3b-instruct-maasqwen3-next-80b-a3b-thinking-maas
Looker
Deprecated
As of July 13, 2026, Looker reports have been deprecated. If you had previously enabled the preview for Looker reports, be aware of the following:
- You will no longer have the option to create new reports.
- You will lose the ability to view or edit reports that were created during the preview period.
Access to the rest of your Looker content in your instance will remain unaffected and you will continue to have access to Looker as a data source from Data Studio and Data Studio Pro.
You can create ad hoc Explores using Looker's self-service Explores feature, which lets you upload CSV, XLS, and XLSX files to Looker and then query and visualize the data in a Looker Explore without needing to configure a LookML model or set up Git version control.
Virtual Private Cloud
Feature
For Google Cloud resources that are registered as App Hub workloads or services, VPC Flow Logs records contain application-specific labels. For more information, see App Hub labels.
Batch
Breaking
Starting on the following dates, you can no longer create a job that locates its Compute Engine resources outside of the job's location.
- For projects that have successfully submitted before July 31, 2026 at least
one job that uses the
allowedLocations[]field with any region or zones outside of the job's location, changes are starting on June 30, 2027. - For all other projects, changes are starting on July 31, 2026.
If none of your jobs specify the allowedLocations[] field, then no action is
required. Otherwise, ensure that any region or zones specified in the
allowedLocations[] field are in the same region as the job's location
before these dates. For more information, see
Batch locations.
BigQuery
Issue
Lakehouse for Apache Iceberg: Data Products with special characters, such as "/" or "-", are not supported and will not be available in BigQuery even if shared from SAP BDC to BigQuery. If you share a Data Product with special characters, this could cause the refresh to stop and require re-enrollment. Known SAP systems producing these Data Products include SAP Business Warehouse (BW) sources and SAP SuccessFactors.
Feature
Lakehouse for Apache Iceberg: Cross-cloud Lakehouse now supports integration with SAP Business Data Cloud (BDC) in Preview.
This update includes the following features:
- Federation from SAP BDC: Create Delta Sharing catalogs in Lakehouse to automatically synchronize shares, schemas, and tables from SAP BDC.
- Querying SAP data: Query synchronized SAP BDC tables directly from BigQuery without data migration.
- Publishing to SAP BDC: Publish Apache Iceberg REST catalog (IRC) tables or Knowledge Catalog Data Products from Lakehouse directly to SAP BDC, allowing SAP users and applications to consume Google Cloud data directly as remote tables in SAP Datasphere without migrating data.
For more information, see Set up cross-cloud Lakehouse for SAP BDC, Query SAP BDC data, and Publish Data Products to SAP BDC.
Cloud Load Balancing
Feature
For regional external passthrough Network Load Balancers, you can reserve specific or automatically allocated bring your own IP (BYOIP) IPv6 addresses before creating a load balancer, so that the IPv6 address persists independently of the load balancer's lifecycle. You can also promote an ephemeral BYOIP IPv6 address that is in use by a load balancer to a reserved static IP address.
For more information, see the following documentation:
- Set up a regional external passthrough Network Load Balancer with a backend service.
- Set up a regional external passthrough Network Load Balancer for multiple IP protocols
- Set up a regional external passthrough Network Load Balancer with zonal NEGs
This feature is in Preview.
Cloud NGFW
Feature
You can now use the WildFire service to protect your network against unknown, novel malware, and file-based threats. WildFire integrates advanced malware sandboxing and real-time machine learning (ML) to perform deep inspection of network-routed file transfers and block zero-day malware before it reaches your workloads. WildFire is available in the Cloud Firewall Enterprise tier.
For more information, see WildFire overview and Configure WildFire in your network. This feature is available in Preview.
Cloud SQL for MySQL
Feature
Cloud SQL for MySQL now supports authentication via Secret Manager when executing SQL statements using the Data API (executeSql). You can store your database password in a regional secret in Secret Manager and pass the secret version resource name in your API request.
For more information, see Execute SQL statements on a Cloud SQL instance.
Cloud SQL for PostgreSQL
Feature
Cloud SQL for PostgreSQL now supports authentication via Secret Manager when executing SQL statements using the Data API (executeSql). You can store your database password in a regional secret in Secret Manager and pass the secret version resource name in your API request.
For more information, see Execute SQL statements on a Cloud SQL instance.
Cloud Storage
Feature
Object Lifecycle Management conditions for
sizeAboveBytes and sizeBelowBytes
let you define a minimum and maximum size threshold for lifecycle actions.
Compute Engine
Deprecated
Encrypting disks, snapshots, images, and machine images with customer-supplied encryption keys (CSEKs) is deprecated and will be disabled on July 20, 2027.
For more information and alternatives to CSEKs for your Compute Engine resources, see Deprecation of customer-supplied encryption keys (CSEK) in Compute Engine.
Container Optimized OS
Change
cos-117-18613-675-20
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.6.143 | v24.0.9 | v1.7.34 | See List |
Fixed
Fixed a bug in the XFS file system where direct I/O writes could use outdated block mappings during Copy-on-Write operations.
Fixed
Upgraded net-misc/curl to 8.21.0.
Security
Fixed CVE-2026-58013,CVE-2026-58014,CVE-2026-58015,CVE-2026-58016 in glib.
Security
Fixed CVE-2025-13462 in dev-lang/python
Security
Fixed CVE-2026-3644 in dev-lang/python
Security
Fixed CVE-2026-4224 in dev-lang/python
Security
Fixed CVE-2026-43010 in the Linux kernel.
Security
Fixed CVE-2026-46135 in the Linux kernel.
Security
Fixed CVE-2026-46331 in the Linux kernel.
Security
Fixed CVE-2026-53163 in the Linux kernel.
Security
Fixed CVE-2026-53167 in the Linux kernel.
Security
Fixed CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 in net-misc/wget.
Security
Updated containerd to v1.7.34. This resolves CVE-2026-46680 and CVE-2026-53488.
Change
cos-121-18867-528-21
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.6.143 | v27.5.1 | v2.0.10 | See List |
Fixed
Updated containerd to v2.0.10. This resolves CVE-2026-46680.
Fixed
Fixed a bug in the XFS file system where direct I/O writes could use outdated block mappings during Copy-on-Write operations.
Fixed
Upgraded net-misc/curl to 8.21.0.
Security
Fixed CVE-2026-58013,CVE-2026-58014,CVE-2026-58015,CVE-2026-58016 in glib.
Security
Fixed CVE-2026-23278 in the Linux kernel.
Security
Fixed CVE-2026-43010 in the Linux kernel.
Security
Fixed CVE-2026-46135 in the Linux kernel.
Security
Fixed CVE-2026-46331 in the Linux kernel.
Security
Fixed CVE-2026-53163 in the Linux kernel.
Security
Fixed CVE-2026-53167 in the Linux kernel.
Security
Fixed CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 in net-misc/wget.
Change
cos-129-19506-299-36
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.12.94 | v27.5.1 | v2.2.5 | See List |
Fixed
Fixed a bug in the XFS file system where direct I/O writes could use outdated block mappings during Copy-on-Write operations.
Fixed
Upgraded net-misc/curl to 8.21.0.
Security
Fixed CVE-2026-58013,CVE-2026-58014,CVE-2026-58015,CVE-2026-58016 in glib.
Security
Fixed CVE-2026-43216 in the Linux kernel.
Security
Fixed CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 in net-misc/wget.
Security
Updated containerd to v2.2.5. This resolves CVE-2026-46680,CVE-2026-50195,CVE-2026-53492,CVE-2026-53488.
Change
cos-125-19216-532-25
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.12.94 | v27.5.1 | v2.1.9 | See List |
Fixed
Upgraded net-misc/curl to 8.21.0.
Security
Fixed CVE-2026-58013,CVE-2026-58014,CVE-2026-58015,CVE-2026-58016 in glib.
Security
Fixed CVE-2026-43010 in the Linux kernel.
Security
Fixed CVE-2026-43216 in the Linux kernel.
Security
Fixed CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 in net-misc/wget.
Security
Updated containerd to v2.1.9. This resolves CVE-2026-46680,CVE-2026-50195, CVE-2026-53492,CVE-2026-53488.
Firestore
Feature
You can now view, manage, and deploy Firestore Security Rules directly in the Google Cloud console for Firestore in Native mode (Standard and Enterprise editions). You can create new rulesets and clone or restore rulesets from the timeline.
To learn more, see Manage Firestore Security Rules or Use the Google Cloud console.
Gemini
Other
Bug fixes in VS Code
Various bug fixes and minor product enhancements.
Gemini Enterprise Agent Platform
Security
Security update for Server-Side Request Forgery (SSRF) in Agent Studio
This release fixes a Server-Side Request Forgery (SSRF) vulnerability in the
auto-generated /api-proxy backend endpoint for web applications created
before July 1, 2026, using Agent Studio.
If you downloaded, generated, or deployed web application code from Agent Studio before July 1, 2026, regenerate the app from Agent Studio and deploy the new version. For more information, see Quickstart: Deploy your Agent Studio prompt as a web application
The updated backend code includes strict domain allowlist validation, ensuring
that destination hostnames for the /api-proxy endpoint end with allowed Google
Cloud domains, such as *-aiplatform.clients6.google.com
Google Distributed Cloud (software only) for bare metal
Announcement
Google Distributed Cloud (software only) for bare metal 1.35.300-gke.87 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud for bare metal 1.35.300-gke.87 runs on Kubernetes v1.35.3-gke.400.
After a release, it takes approximately 7 to 14 days for the version to become available for installations or upgrades with the GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.
If you use a third-party storage vendor, check the Google Distributed Cloud-ready storage partners document to make sure the storage vendor has already passed the qualification for this release of Google Distributed Cloud for bare metal.
Feature
The following change was added in 1.35.300-gke.87:
- Removed the deprecated
csi-snapshot-validation-webhookcomponent. Upstream Kubernetes validation is now handled natively via Common Expression Language (CEL) rules within the deployed Custom Resource Definitions (CRDs). For more information, see Volume snapshots.
Fixed
The following issues were fixed in 1.35.300-gke.87:
- Link to Vulnerability fixes for the list of security vulnerabilities addressed in this release.
Google Kubernetes Engine
Deprecated
To improve security, Ubuntu node images in GKE version 1.37 and later don't
pre-install the vulkan-tools package. If you run Vulkan diagnostic tools
(such as vulkaninfo) directly on GKE Ubuntu hosts, then you must manually
install the vulkan-tools package. This change doesn't affect containerized
GPU/Vulkan workloads.
Google SecOps
Deprecated
[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs
Google Security Operations is deprecating its legacy SIEM APIs—Backstory API (including Customer Management API) and Ingestion API—in favor of the modern Chronicle API.
Key dates
- October 26, 2026: New Google SecOps instances provisioned from this date will no longer support legacy API calls.
- July 20, 2027: All requests to legacy endpoints fail from this date because legacy APIs for all existing instances will be completely turned down.
This change applies only to custom scripts, integrations, SOAR connectors, or ingestion feeds calling legacy Backstory API or Ingestion API endpoints. Any changes impacting the Google SecOps UI are already addressed and don't call for your action.
Next steps
Audit API usage to identify any affected components that currently call legacy Backstory API or Ingestion API endpoints, and replace them with Chronicle API endpoints.
Validate and test that your updated components work properly.
For more information, see Migrate from legacy API to Chronicle API.
Google SecOps SIEM
Deprecated
[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs
Google Security Operations is deprecating its legacy SIEM APIs—Backstory API (including Customer Management API) and Ingestion API—in favor of the modern Chronicle API.
Key dates
- October 26, 2026: New Google SecOps instances provisioned from this date will no longer support legacy API calls.
- July 20, 2027: All requests to legacy endpoints fail from this date because legacy APIs for all existing instances will be completely turned down.
This change applies only to custom scripts, integrations, SOAR connectors, or ingestion feeds calling legacy Backstory API or Ingestion API endpoints. Any changes impacting the Google SecOps UI are already addressed and don't call for your action.
Next steps
Audit API usage to identify any affected components that currently call legacy Backstory API or Ingestion API endpoints, and replace them with Chronicle API endpoints.
Validate and test that your updated components work properly.
For more information, see Migrate from legacy API to Chronicle API.
Virtual Private Cloud
Feature
Preview: You can reserve static external IPv6 addresses from
bring your own IP addresses (BYOIP) sub-prefixes that are in
EXTERNAL_IPV6_FORWARDING_RULE_CREATION mode.
You can assign these addresses to forwarding rules for external passthrough Network Load Balancers and external protocol forwarding. You can also promote ephemeral IPv6 BYOIP addresses that are used by external forwarding rules to reserved static IP addresses.
For more information, see Create external forwarding rules.
Google SecOps SOAR
Announcement
Release 6.3.94 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Audit Manager
Feature
Audit Manager includes the following features in Preview:
- A new UI and report experience
- Ability to schedule audits
- Ability to run audits at an organization level
Batch
Feature
Instance flexibility is available in Preview. Instance flexibility lets you allow a job to run on multiple machine types that you specify and can optionally rank. Use instance flexibility to improve obtainability—the probability that resources are available to run your job. For example, by allowing multiple machine types, you can reduce the probability of resource availability errors and try to obtain Spot VMs that are less likely to be preempted.
To get started, see Improve resource obtainability for jobs.
Cloud Hub
Feature
The Security & compliance page in Cloud Hub has launched to General Availability.
Document AI
Feature
Custom extractor model
pretrained-foundation-model-v3.5-2026-05-26 powered by Gemini 3.5
Flash LLM is available in Preview.
This processor version has ML processing capabilities in the US and EU.
For more information about available models, see the custom extractor page.
Gemini Enterprise Agent Platform
Breaking
Gemini 3.1 Flash Image Preview and 3 Pro Image Preview are retired
The Nano Banana preview models gemini-3.1-flash-image-preview and
gemini-3-pro-image-preview have been retired and are no longer accessible.
Update your code to use either gemini-3.1-flash-image or
gemini-3-flash-image instead.
Knowledge Catalog
Feature
Data lineage control at the organization, folder, or project level is generally available for BigQuery, Managed Service for Apache Spark, and Managed Service for Apache Airflow.
For more information, see About data lineage ingestion control and Configure data lineage ingestion for a service.
Looker
Feature
Starting in Looker 26.8, Looker supports Java OpenJDK version 21. Looker-hosted instances have been upgraded to OpenJDK 21. Customer-hosted instances should upgrade to OpenJDK 21.
Looker recommends that you transition to new Java updates as they are released. Other versions of Java, Oracle JDK, and OpenJDK are not supported at this time.
Security Command Center
Announcement
Key insights from Security Command Center are available on the Security & compliance page in Cloud Hub. This feature is available in General Availability.
Apigee X
Announcement
On July 16th, 2026, we began maintenance updates of Apigee instances configured for maintenance windows.
If you set a preferred window for maintenance for your instance, and your instance version is below 1-17-0-apigee-10, your instance will be updated to 1-17-0-apigee-10 within the next seven to 21 days. A notification containing the expected date of upgrade will be sent within the next two business days.
For more information on participating in scheduled maintenance windows, see Maintenance overview and Manage Apigee instance maintenance windows.
Cloud Key Management Service
Feature
Cloud KMS supports the following post-quantum computing (PQC) signing algorithms in General Availability:
PQ_SIGN_HASH_SLH_DSA_SHA2_128S_SHA256PQ_SIGN_ML_DSA_44PQ_SIGN_ML_DSA_44_EXTERNAL_MUPQ_SIGN_ML_DSA_65PQ_SIGN_ML_DSA_65_EXTERNAL_MUPQ_SIGN_ML_DSA_87PQ_SIGN_ML_DSA_87_EXTERNAL_MUPQ_SIGN_SLH_DSA_SHA2_128S
For more information about supported algorithms, see PQC signing algorithms. For more information about PQC signing, see Post-quantum cryptography (PQC) digital signature.
Cloud SQL for MySQL
Change
Cloud SQL for MySQL 8.4.8 is upgraded to MySQL 8.4.10. For more information, see the MySQL 8.4.10 Release Notes and Cloud SQL database versions.
Compute Engine
Feature
Hyperdisk Balanced High Availability volumes on C4 instances have increased performance
limits for several machine types. For example, an instance that uses the
c4-standard-16 machine type can reach up to 1,600 MiB/s of throughput,
up from 600 MiB/s.
For detailed performance limits, see Hyperdisk Balanced High Availability performance limits when attached to an instance.
Change
Changed: The following operations on the boot disk of a Compute Engine instance
that has a service account attached no longer require the iam.serviceAccounts.actAs
permission. In the following list, the boot disk of such an instance is
referred to as the source disk.
- Creating a standard or archive snapshot of the source disk.
- Cloning the source disk.
- Creating a machine image of the instance.
- Creating a custom image of the source disk.
- Starting asynchronous replication of the source disk to another region.
- Creating a new disk when you create an instance, if the new disk is created from an instant snapshot of the source disk.
Gemini Enterprise
Feature
Gemini Enterprise: Bring Your Own Identity (BYOID) for mobile apps (GA)
The Gemini Enterprise mobile app is generally available (GA) for organizations using third-party identity providers. You can connect the mobile app to supported third-party identity providers without being on an allowlist.
For more information, see Configure the mobile app.
Change
Gemini Notebook Enterprise: NotebookLM Enterprise renamed to Gemini Notebook Enterprise
NotebookLM Enterprise is renamed to Gemini Notebook Enterprise. Despite the rebrand, the product functionality remains the same, and the APIs still use the same endpoints. See Create and manage notebooks (API).
The Gemini Enterprise web app and the admin console display the name Gemini Notebook Enterprise. However, the subscription page still displays the name NotebookLM Enterprise.
Google Kubernetes Engine
Change
(2026-R30) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters.
The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.
Rapid channel
- Version 1.36.0-gke.4681000 is now the default version for cluster creation in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.33.13-gke.1011000
- 1.34.9-gke.1131000
- 1.35.6-gke.1127000
- 1.36.0-gke.4447000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1101000
- 1.33 to 1.34.9-gke.1287000
- 1.34 to 1.35.6-gke.1250000
- 1.35 to 1.36.0-gke.4681000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1101000
- 1.34 to 1.34.9-gke.1287000
- 1.35 to 1.35.6-gke.1250000
- 1.36 to 1.36.0-gke.4681000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Regular channel
- Version 1.35.6-gke.1049000 is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.33.12-gke.1165000
- 1.34.8-gke.1278000
- 1.35.5-gke.1241004
- 1.36.0-gke.3070003 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.3302004 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.12-gke.1270000
- 1.33 to 1.34.9-gke.1065000
- 1.34 to 1.35.6-gke.1049000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.12-gke.1270000
- 1.34 to 1.34.9-gke.1065000
- 1.35 to 1.35.6-gke.1049000
- 1.36 to 1.36.0-gke.3712000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Stable channel
- Version 1.34.8-gke.1278000 is now the default version for cluster creation in the Stable channel.
- The following versions are no longer available in the Stable channel:
- 1.33.12-gke.1059000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.34.8-gke.1126000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.12-gke.1165000
- 1.33 to 1.34.8-gke.1278000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.12-gke.1165000
- 1.34 to 1.34.8-gke.1278000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Extended channel
- Version 1.35.6-gke.1049000 is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
- The following versions are no longer available in the Extended channel:
- 1.30.14-gke.2710000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.30.14-gke.2816000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2116000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2233000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1740000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1913000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.33.12-gke.1165000
- 1.34.8-gke.1278000
- 1.35.5-gke.1241004
- 1.36.0-gke.3070003 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.3302004 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.29 to 1.30.14-gke.2746000
- 1.30 to 1.31.14-gke.2157000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.30 to 1.30.14-gke.2746000
- 1.31 to 1.31.14-gke.2157000
- 1.32 to 1.32.13-gke.1829000
- 1.33 to 1.33.12-gke.1270000
- 1.34 to 1.34.9-gke.1065000
- 1.35 to 1.35.6-gke.1049000
- 1.36 to 1.36.0-gke.3712000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
No channel (deprecated)
- Version 1.35.6-gke.1049000 is now the default version for cluster creation.
- The following versions are now available:
- The following node versions are now available:
- The following versions are no longer available:
- 1.33.12-gke.1059000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.34.8-gke.1000000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.35.5-gke.1163012 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.3070003 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.3302004 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.12-gke.1270000
- 1.33 to 1.34.8-gke.1278000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.12-gke.1270000
- 1.34 to 1.34.8-gke.1278000
- 1.35 to 1.35.6-gke.1049000
- 1.36 to 1.36.0-gke.3712000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Security
(2026-R30) Security updates
This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.
To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:
| GKE version | Container-Optimized OS version | Details |
|---|---|---|
| 1.35.6-gke.1258000 | cos-125-19216-395-138 | cos-125-19216-395-138 release notes |
Change
Starting on June 30, 2026, the Filestore API
(file.googleapis.com) is enabled by default when you enable the Kubernetes
Engine API (container.googleapis.com) in a project. The Filestore API is
required for PersistentVolumes that use the ReadWriteMany access mode in
GKE.
Feature
In GKE version 1.36.0-gke.3204000 and later, when you manually or automatically
create a GKE node pool that consumes capacity reservations, you can stop GKE
from falling back to on-demand capacity if reserved capacity isn't available. To
consume any matching reservation without fallback, specify the
any-reservation-then-fail reservation affinity in your node pool creation
request, Pod specification, or ComputeClass specification. In ComputeClasses,
this reservation affinity lets GKE move on to the next priority rule instead of
creating on-demand compute resources. For more information, see Consuming
reserved zonal
resources.
Feature
GKE version 1.33 now supports the N4D machine series for node pool auto-creation and Autopilot clusters in the following patch versions and later:
- Node pool auto-creation: 1.33.12-gke.1208000 and later
- Autopilot: 1.33.13-gke.1079000 and later
Feature
In GKE version 1.36.0-gke.4447000 and later, the VerticalPodAutoscaler supports CPU startup boost, which temporarily increases CPU requests during application startup to improve startup latency and cost efficiency. This feature is available in Preview.
Change
(2026-R30) Version updates
- Version 1.34.8-gke.1278000 is now the default version for cluster creation in the Stable channel.
- The following versions are no longer available in the Stable channel:
- 1.33.12-gke.1059000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.34.8-gke.1126000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.12-gke.1165000
- 1.33 to 1.34.8-gke.1278000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.12-gke.1165000
- 1.34 to 1.34.8-gke.1278000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R30) Version updates
- Version 1.35.6-gke.1049000 is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.33.12-gke.1165000
- 1.34.8-gke.1278000
- 1.35.5-gke.1241004
- 1.36.0-gke.3070003 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.3302004 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.12-gke.1270000
- 1.33 to 1.34.9-gke.1065000
- 1.34 to 1.35.6-gke.1049000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.12-gke.1270000
- 1.34 to 1.34.9-gke.1065000
- 1.35 to 1.35.6-gke.1049000
- 1.36 to 1.36.0-gke.3712000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R30) Version updates
- Version 1.36.0-gke.4681000 is now the default version for cluster creation in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.33.13-gke.1011000
- 1.34.9-gke.1131000
- 1.35.6-gke.1127000
- 1.36.0-gke.4447000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1101000
- 1.33 to 1.34.9-gke.1287000
- 1.34 to 1.35.6-gke.1250000
- 1.35 to 1.36.0-gke.4681000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1101000
- 1.34 to 1.34.9-gke.1287000
- 1.35 to 1.35.6-gke.1250000
- 1.36 to 1.36.0-gke.4681000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R30) Version updates
- Version 1.35.6-gke.1049000 is now the default version for cluster creation.
- The following versions are now available:
- The following node versions are now available:
- The following versions are no longer available:
- 1.33.12-gke.1059000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.34.8-gke.1000000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.35.5-gke.1163012 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.3070003 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.3302004 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.12-gke.1270000
- 1.33 to 1.34.8-gke.1278000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.12-gke.1270000
- 1.34 to 1.34.8-gke.1278000
- 1.35 to 1.35.6-gke.1049000
- 1.36 to 1.36.0-gke.3712000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R30) Version updates
- Version 1.35.6-gke.1049000 is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
- The following versions are no longer available in the Extended channel:
- 1.30.14-gke.2710000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.30.14-gke.2816000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2116000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2233000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1740000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1913000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.33.12-gke.1165000
- 1.34.8-gke.1278000
- 1.35.5-gke.1241004
- 1.36.0-gke.3070003 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.36.0-gke.3302004 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.29 to 1.30.14-gke.2746000
- 1.30 to 1.31.14-gke.2157000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.30 to 1.30.14-gke.2746000
- 1.31 to 1.31.14-gke.2157000
- 1.32 to 1.32.13-gke.1829000
- 1.33 to 1.33.12-gke.1270000
- 1.34 to 1.34.9-gke.1065000
- 1.35 to 1.35.6-gke.1049000
- 1.36 to 1.36.0-gke.3712000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Managed Service for Apache Airflow
Feature
Airflow 3.1.8 is available in Managed Airflow (Gen 3).
Change
Airflow 3.1.7 is no longer included in Managed Airflow images and builds.
Fixed
(Airflow 3.1.8) Backported #64031 to fix an issue in the Airflow UI when viewing tasks in non-terminal states (scheduled, running) with "Show Gantt" enabled.
Change
(Airflow 3.1.8) The apache-airflow-providers-google package was upgraded to version 22.2.0.
For more information about changes, see the
apache-airflow-providers-google changelog.
Change
(Airflow 2.11.1) The apache-airflow-providers-google package was upgraded to version 22.2.1.
For more information about changes, see the
apache-airflow-providers-google changelog.
Change
New Airflow builds are available in Managed Airflow (Gen 3):
- composer-3-airflow-3.1.8-build.0
- composer-3-airflow-2.11.1-build.11 (default)
- composer-3-airflow-2.10.5-build.44
Change
New images are available in Managed Airflow (Gen 2):
Deprecated
The following Managed Airflow versions and builds have reached their end of support period: composer-3-airflow-2.10.5-build.9, composer-3-airflow-2.9.3-build.29, composer-2.13.7-airflow-2.9.3, composer-2.13.7-airflow-2.10.5.
Oracle Database@Google Cloud
Feature
Oracle Database@Google Cloud supports cloning for Autonomous AI Databases. You can create full, metadata, and refreshable clones using Google Cloud CLI and API. For more information, see Clone an Autonomous AI Database.
This feature is Generally Available (GA).
Apigee UI
Fixed
Apigee UI
Fixed an issue where editing a legacy API Product with a selected API Proxy could cause the Apigee UI to become unresponsive.
Apigee X
Announcement
On July 15th, 2026, we released an updated version of Apigee (1-18-0-apigee-1).
Fixed
| Bug ID | Description |
|---|---|
| 527586459 | Fixed a cache policy throttling bug (CacheThrottlerV2 key poisoning) to enhance reliability. |
| 525697701 | Fixed an issue where API proxy deployments could get stuck during basepath migrations in Apigee X. |
| N/A | Updates to infrastructure and libraries. |
Security
| Bug ID | Description |
|---|---|
| 527415966, 524656652 | Security fix for Apigee. Upgraded the Apigee ingress gateway (ASM) to patch security vulnerabilities. |
| 527956223 | Security fix for Apigee. Enhanced security in the Java Callout policy to prevent sandbox escape. |
| 519729209 | Security fix for Apigee. Fixed a SAML XML Signature Wrapping (XSW) vulnerability in the ValidateSAMLAssertion policy. |
| 530886487 | Security fix for Apigee. Upgraded the apigee-connect-agent to patch CVE-2026-25680. |
| N/A | Security fix for Apigee infrastructure. |
Apigee hybrid
Announcement
v1.15.6
On July 15, 2026 we released an updated version of the Apigee hybrid software, v1.15.6.
- For information on upgrading, see Upgrading Apigee hybrid to version v1.15.6.
- For information on new installations, see The big picture.
Security
Various security and CVE fixes are included in this release.
BigQuery
Feature
BigQuery supports data governance tags, which let you enforce column-level security and data masking. Data governance tags are a type of Resource Manager tag that you can attach to sensitive columns and use in BigQuery data policies to grant conditional access to your users. This feature is in Preview.
Cloud Data Fusion
Feature
Cloud Data Fusion version 6.11.1.4 is generally available (GA).
Fixed
Fixed in Cloud Data Fusion 6.11.1.4:
- Fixed a race condition where successfully completed Dataproc jobs were
incorrectly marked as
failedon the Dataproc console due to premature program cancellation (CDAP-21219). - Fixed an issue where the Pipeline list page would hang due to a race condition in an internal service (CDAP-21241).
- Fixed a security vulnerability in log downloads by enforcing strict validation on requested log paths and query parameters to prevent unauthorized access (CDAP-21260).
Change
Changes in Cloud Data Fusion 6.11.1.4:
- Increased the default Wrangler browsing limit to 2,000 items (CDAP-21259).
Cloud Service Mesh
Announcement
1.29.5-asm.12 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.29.5-asm.12 uses Envoy v1.35.13.
Fixed
Patch 1.29.5-asm.12 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-46595 | Yes | Yes | Yes | Yes | Critical (10.0) |
| CVE-2026-8376 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-8925 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-39830 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39831 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39832 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39833 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39834 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-42496 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-42508 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-8924 | Yes | Yes | No | Yes | Low (9.1) |
| CVE-2026-8927 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8286 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2025-69720 | Yes | Yes | No | Yes | Low (7.8) |
| CVE-2026-39822 | Yes | Yes | Yes | Yes | High (7.8) |
| CVE-2026-39829 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-41992 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-46597 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-9547 | Yes | Yes | No | Yes | Low (7.4) |
| CVE-2026-25680 | Yes | Yes | Yes | Yes | Medium (6.5) |
| CVE-2026-39827 | Yes | Yes | Yes | Yes | Medium (6.5) |
| CVE-2026-8458 | Yes | Yes | No | Yes | Low (6.5) |
| CVE-2026-39828 | Yes | Yes | Yes | Yes | Medium (6.3) |
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
| CVE-2026-58055 | Yes | Yes | No | Yes | Medium (5.4) |
| CVE-2026-39835 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-42505 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-46598 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-41991 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-45582 | Yes | Yes | No | Yes | Medium (0.0) |
Announcement
1.28.10-asm.4 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.10-asm.4 uses Envoy v1.36.9.
Fixed
Patch 1.28.10-asm.4 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-8376 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-8925 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-42496 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8924 | Yes | Yes | No | Yes | Low (9.1) |
| CVE-2026-8927 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8286 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2025-69720 | Yes | Yes | No | Yes | Low (7.8) |
| CVE-2026-39822 | Yes | Yes | Yes | Yes | High (7.8) |
| CVE-2026-41992 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-42151 | No | No | No | Yes | High (7.5) |
| CVE-2026-42154 | No | No | No | Yes | High (7.5) |
| CVE-2026-9547 | Yes | Yes | No | Yes | Low (7.4) |
| CVE-2026-8458 | Yes | Yes | No | Yes | Low (6.5) |
| CVE-2026-40179 | No | No | No | Yes | Medium (6.1) |
| CVE-2026-44903 | No | No | No | Yes | Medium (6.1) |
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
| CVE-2026-58055 | Yes | Yes | No | Yes | Medium (5.4) |
| CVE-2026-42505 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-41991 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-45582 | Yes | Yes | No | Yes | Medium (0.0) |
Announcement
1.27.9-asm.15 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.15 uses Envoy v1.35.13v.
Fixed
Patch 1.27.9-asm.15 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-8376 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-8925 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-42496 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8924 | Yes | Yes | No | Yes | Low (9.1) |
| CVE-2026-8927 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8286 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2025-69720 | Yes | Yes | No | Yes | Low (7.8) |
| CVE-2026-39822 | Yes | Yes | Yes | Yes | High (7.8) |
| CVE-2026-41992 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-9547 | Yes | Yes | No | Yes | Low (7.4) |
| CVE-2026-8458 | Yes | Yes | No | Yes | Low (6.5) |
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
| CVE-2026-58055 | Yes | Yes | No | Yes | Medium (5.4) |
| CVE-2026-42505 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-41991 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-45582 | Yes | Yes | No | Yes | Medium (0.0) |
Compute Engine
Feature
Preview: The network-optimized C4N machine series offers machine types with 375 GiB to 12,000 GiB of attached Titanium SSD.
To use C4N machine types with attached Local SSD disks, you can Request preview access.
For more information, see C4N machine series.
Datastream
Feature
You can now replicate change data from the following application sources with Datastream:
This feature is in Preview.
Gemini Enterprise
Feature
Gemini Enterprise: New data stores and support for new actions (Preview)
The following data stores are available in Public Preview:
- Aiwyn Tax
- AllTrails
- Autodesk Product Help
- AWS Marketplace
- Courtroom5
- pg-aiguide
- Taskrabbit
- Twilio Docs
- Viator
- ZoomInfo
Additionally, support for new actions is available in Public Preview for the following data stores:
- Freshservice: Update tickets.
- Zoho Desk: Update ticket comments.
- ZoomInfo: Submit feedback.
For more information, see Connect a third-party data source.
Feature
Gemini Enterprise: Action-filtering support for Jira Data Center data stores (Preview)
Filters configured on Jira Data Center federated data stores apply to both search queries and action execution. These filters let you specify which Jira projects are accessible to the Gemini Enterprise app assistant; mutations or retrievals on out-of-scope data fail or return no results.
This feature is in Public Preview. For more information, see:
Gemini Enterprise Agent Platform
Feature
Memory Bank memory profiles are generally available (GA)
Memory profiles in Memory Bank are generally available (GA). Memory profiles allow you to generate structured profiles, which are data structures with static schemas populated and updated using LLMs. By defining a fixed schema, you ensure your agents have immediate, low-latency access to evolving information without the need for expensive search operations during a session.
For details, see Memory profiles.
Google SecOps
Feature
[Spotlight Feature] Advanced Filtering in Dashboards
Advanced Filtering in dashboards is now available in Preview. This feature enhances dashboard capabilities by enabling security analysts to use query variables, also known as tokens, to inject dynamic values, complex regular expressions, or boolean logic directly into YARA-L queries at runtime.
Key aspects of Advanced Filtering include:
- Token Variable Definition: When creating an advanced filter, you can define a Token Variable. Token variable names must consist only of alphanumeric characters and underscores (
^[a-zA-Z0-9_]+$) and must be unique within the dashboard. - Filter Value Generation: Token values can be generated dynamically from YARA-L query results or entered manually as a static list.
- Customizable Wrappers: You can specify prefixes and suffixes to wrap token values, enabling specific logic such as regular expressions.
- Multi-Select Support: The ability to select multiple options for a token can be enabled, with a configurable delimiter (for example,
|) for combining values in queries.
For more information, see Advanced filtering.
Feature
Parser extensions for code snippets now support Append/Replace for Repeated Fields
You can now use append and replace functionality for repeated fields when creating code snippet extensions. Previously, this was only available for no-code extensions. This enhancement provides more granular control over how data is handled in repeated UDM fields, allowing you to either add new values or entirely replace existing ones.
For more information, see Repeated fields selector.
Google SecOps Marketplace
Change
AWS GuardDuty: Version 14.0
- Added support for Google Cloud Web Identity (OIDC) Federation authentication.
Change
SCC Enterprise: Version 22.0
- Refactored integration code to optimize underlying execution performance.
Change
Google Threat Intelligence: Version 18.0
Added an optional
Active Groupparameter to support multi-tenant organization context routing in the integration configuration and the following connector:- ASM Issues Connector
Change
Google Chronicle: Version 88.0
Added
api_rootparameter to alert extensions to expand normalization metadata options in the following connector:- Chronicle Alerts Connector
Change
Microsoft Defender ATP: Version 33.0
Updated execution processing logic to improve backend tracking stability in the following action:
- Execute Live Response Command
Change
ServiceNow: Version 68.0
Updated affected CIs processing logic to handle missing reference keys smoothly in the following job:
- Sync Incidents Job
Change
CrowdStrike Falcon: Version 78.0
Fixed pagination loop logic to prevent infinite timeouts during high-volume sweeps in the following action:
- Get Host Information
Google SecOps SIEM
Feature
Advanced Filtering in Dashboards
This feature is in public preview.
Advanced Filtering in dashboards is now available in Google SecOps. This feature enhances dashboard capabilities by enabling security analysts to use query variables, also known as tokens, to inject dynamic values, complex regular expressions, or boolean logic directly into YARA-L queries at runtime.
Key aspects of Advanced Filtering include:
- Token Variable Definition: When creating an advanced filter, you can define a Token Variable. Token variable names must consist only of alphanumeric characters and underscores (
^[a-zA-Z0-9_]+$) and must be unique within the dashboard. - Filter Value Generation: Token values can be generated dynamically from YARA-L query results or entered manually as a static list.
- Customizable Wrappers: You can specify prefixes and suffixes to wrap token values, enabling specific logic such as regular expressions.
- Multi-Select Support: The ability to select multiple options for a token can be enabled, with a configurable delimiter (for example,
|) for combining values in queries.
For more information, see Advanced filtering.
Feature
Parser extensions for code snippets now support Append/Replace for Repeated Fields
You can now use append and replace functionality for repeated fields when creating code snippet extensions. Previously, this was only available for no-code extensions. This enhancement provides more granular control over how data is handled in repeated UDM fields, allowing you to either add new values or entirely replace existing ones.
For more information, see Repeated fields selector.
Managed Service for Apache Spark
Announcement
Announcing the General Availability (GA) release of Managed Service for Apache Spark cluster
image version 3.0,
as follows:
3.0.0-debian13,3.0.0-ml-ubuntu24,3.0.0-rocky9, and3.0.0-ubuntu24.- The
3.0.0-ml-ubuntu24image extends the 3.0 base image with ML-specific libraries.
- The
Image version 3.0 is a lightweight image that contains the following
pre-installed core components, reducing exposure to Common Vulnerabilities and Exposures (CVEs):
- Apache Hadoop 3.5.0.
- Apache Hive 4.2.0
- Apache Spark 4.1.2
- Apache Tez 0.10.5
- Cloud Storage Connector 3.1.13
- Conscrypt 2.6
- Java 21
- Python 3.12
- R 4.5
- Scala 2.13.17
- Spark-BigQuery Connector 0.44.1-preview
You can add
listed optional components
when you create a 3.0 image version cluster.
Recommendation: Use the 3.0 (and later) image versions to meet security
compliance requirements.
Announcement
- 2.3.34-debian12, 2.3.34-ml-ubuntu22, 2.3.34-rocky9, 2.3.34-ubuntu22, 2.3.34-ubuntu22-arm
- 3.0.0-debian13, 3.0.0-ml-ubuntu24, 3.0.0-rocky9, 3.0.0-ubuntu24
BigQuery
Feature
Conversational analytics
now supports the
AI.AGG function.
This function is in
Preview.
Announcement
As part of Gemini in BigQuery, conversational analytics now supports HIPAA compliance.
Bigtable
Feature
AI agents can use the list_hot_tablets Model Context Protocol (MCP) tool
to programmatically query Bigtable cluster health to isolate resource-intensive
tablets (hot tablets) and detect overutilized node CPUs. This feature is
generally available (GA).
Cloud Interconnect
Feature
Partner Cross-Cloud Interconnect for Amazon Web Services (AWS) supports the following new locations:
- australia-southeast1
- europe-north2
For available locations, see Choose a paired location.
Cloud Run
Feature
Cloud Run support for importing public container images from GitHub Container Registry is in General Availability.
Cloud Tasks
Change
Cloud Tasks is available in the following locations:
me-central1(Doha, Qatar)me-central2(Dammam, Saudi Arabia)
Gemini Enterprise
Announcement
Gemini Enterprise: Idea Generation agent removal
The Idea Generation agent which was in public preview is removed starting the week of July 14, 2026. Users can brainstorm ideas directly using the assistant.
- For general brainstorming and creative thinking, use the Gemini Enterprise app assistant.
- For in-depth exploration or hypothesis generation, use Deep Research or Co-Scientist agents.
Google Kubernetes Engine
Change
GKE Dataplane V2 clusters running version 1.35.1-gke.1516000 or later now use CNI version 1.1.0 in the CNI configuration files. This change requires downstream CNI plugins to be compatible with CNI version 1.1.0.
Customers using self-managed open-source Istio or in-cluster unmanaged Cloud
Service Mesh (CSM) variant must manually upgrade their CSM CNI version to 1.23
to ensure compatibility. If you use an incompatible CNI version, nodes might
fail to reach a Ready state and might show NetworkPluginNotReady errors.
Feature
Rollout sequencing with custom stages is now generally available. This version of rollout sequencing, which is recommended if you're configuring an environment for the first time, offers a robust set of features including the following:
- Define custom stages: Sequence the rollout of a new GKE version across environments. With custom stages, you can, for example, deploy a new version on a small subset of production clusters before a wider rollout.
- Choose the scope of rollouts: Decide what types of versions that GKE rolls out in the sequence. For example, you can have GKE roll out patch versions, but not minor versions, across a sequence.
- Initiate a rollout: Create a rollout of a specific version, if you want GKE to roll out that version across your sequence.
- Manage a rollout: Pause, resume, cancel rollouts, or complete rollout stages as needed.
For more information, see About rollout sequencing with custom stages.
Sensitive Data Protection
Feature
The CRIME_STATUS infoType detector is available in all regions. For more information about all built-in infoTypes, see the InfoType detector reference.
Agent Platform Workbench
Feature
Agent Platform Workbench image release
The following Agent Platform Workbench instances image releases are available:
- 20260712-2130-rc0 (
workbench-instances-2603- Debian 12)- Installed latest packages from upstream dependencies.
- Fixed broken cupy installation.
- M144 (
workbench-instances- Debian 11)- Installed latest packages from upstream dependencies.
- Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances.
Change
M144 Release
Change
20260712-2130-rc0 Release
Change
Installed latest packages from upstream dependencies.
Change
Installed latest packages from upstream dependencies.
Fixed
Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances.
Fixed
Fixed broken cupy installation.
Feature
Secure Boot is compatible with GPUs
You can now enable Secure Boot on Agent Platform Workbench instances that have a
GPU attached. Secure Boot with GPUs is supported on the workbench-instances-2603
VM image and the workbench-container-2606 custom container, which include a
Secure Boot-signed NVIDIA GPU driver so the driver loads under Secure Boot. For
more information, see Create an
instance.
Feature
Secure Boot is compatible with GPUs
You can now enable Secure Boot on Agent Platform Workbench instances that have a
GPU attached. Secure Boot with GPUs is supported on the workbench-instances-2603
VM image and the workbench-container-2606 custom container, which include a
Secure Boot-signed NVIDIA GPU driver so the driver loads under Secure Boot. For
more information, see Create an
instance.
Feature
Secure Boot is compatible with GPUs
You can now enable Secure Boot on Agent Platform Workbench instances that have a
GPU attached. Secure Boot with GPUs is supported on the workbench-instances-2603
VM image and the workbench-container-2606 custom container, which include a
Secure Boot-signed NVIDIA GPU driver so the driver loads under Secure Boot. For
more information, see Create an
instance.
BigQuery
Feature
Table partitioning, multi-statement transactions, and advanced runtime are now generally available (GA) for Apache Iceberg managed tables.
Feature
Cross-cloud Lakehouse now supports Snowflake as a remote catalog provider (Preview). You can configure federated catalogs to query data stored in Snowflake directly from Google Cloud using BigQuery or Apache Spark without migrating data or building complex ETL pipelines.
For more information, see Set up cross-cloud Lakehouse for Snowflake.
Security
A Missing Authorization vulnerability was discovered in repositories in BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could potentially escalate permissions and perform cross-tenant repository takeover. For more information, see the GCP-2026-047 security bulletin.
Feature
Project caps (also known as scheduling policies) let you limit maximum slots and concurrency per project within a BigQuery reservation. This feature is in Preview.
Feature
The BigQuery Overview page is a hub for discovering tutorials, features, and resources to help you get the most out of BigQuery. It provides guided paths for users of all skill levels. This feature is now generally available (GA).
Feature
You can use the BigQuery Migration Service MCP server to perform SQL translation tasks, including translating SQL queries into GoogleSQL syntax, generating DDL statements from SQL input queries, and getting explanations of SQL translations.
This feature is Generally Available.
Feature
Incremental data transfers for the BigQuery Data Transfer Service for Salesforce are now generally available (GA).
Feature
You can now use the
ALTER SEARCH INDEX DDL statement
to
update the configuration
of a search index. This feature is in
Preview.
Cloud SQL for MySQL
Feature
You can now create and query parameterized secure views in Cloud SQL for MySQL. Parameterized secure views let you create MySQL views in your MySQL database that reference session variables for managing data access. By using a parameterized secure view, you can create a single view that is flexible enough to accommodate multiple queries across a predefined range of data without being required to create multiple static view definitions for different users.
To use parameterized secure views, you're required to have Cloud SQL for MySQL 8.0.43 or later and maintenance version R20260320.00_20 or later installed on your instance.
For more information, see Parameterized secure views in Cloud SQL. This feature is in Preview.
Cluster Toolkit
Feature
Cluster Toolkit v1.97.0 is available. This release integrates cluster health checks into the toolkit, adds support for collecting static node counts from blueprints, and enforces strict Google Kubernetes Engine node auto-provisioning (NAP) accelerator validation. For details, see the release announcement on GitHub.
Colab Enterprise
Security
A Missing Authorization vulnerability was discovered in repositories in BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could potentially escalate permissions and perform cross-tenant repository takeover. For more information, see the GCP-2026-047 security bulletin.
Container Optimized OS
Change
cos-129-19506-299-20
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.12.94 | v27.5.1 | v2.2.3 | See List |
Feature
Enabled CONFIG_MEMORY_FAILURE in the Linux kernel for ARM64. This should improve memory errors handling when running CUDA workloads.
Fixed
Changed google-guest-agent's plugin installation path to /var/lib/google/guest-agent.
Fixed
Upgraded app-admin/fluent-bit to v4.2.6.
Fixed
Upgraded app-containers/docker-credential-helpers to v0.9.8.
Security
Fixed CVE-2026-40225 in sys-apps/systemd.
Security
Fixed CVE-2026-43010 in the Linux kernel.
Security
Fixed CVE-2026-53167 in the Linux kernel.
Security
Fixed CVE-2026-53341 in the Linux kernel.
Security
Fixed KCTF-736b380 in the Linux kernel.
Change
cos-125-19216-532-14
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.12.94 | v27.5.1 | v2.1.7 | See List |
Feature
Enabled CONFIG_MEMORY_FAILURE in the Linux kernel for ARM64. This should improve memory errors handling when running CUDA workloads.
Fixed
Changed google-guest-agent's plugin installation path to /var/lib/google/guest-agent.
Security
Fixed CVE-2026-53341 in the Linux kernel.
Security
Fixed KCTF-736b380 in the Linux kernel.
Change
cos-117-18613-675-11
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.6.143 | v24.0.9 | v1.7.31 | See List |
Security
Fixed CVE-2026-40225 in sys-apps/systemd.
Security
Fixed CVE-2026-53362 in the Linux kernel.
Security
Fixed KCTF-7cb9a23 in the Linux kernel.
Change
cos-121-18867-528-10
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.6.143 | v27.5.1 | v2.0.8 | See List |
Security
Fixed CVE-2026-40225 in sys-apps/systemd.
Security
Fixed CVE-2026-53362 in the Linux kernel.
Dataform
Security
A Missing Authorization vulnerability was discovered in repositories in BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could potentially escalate permissions and perform cross-tenant repository takeover. For more information, see the GCP-2026-047 Dataform security bulletin.
Developer Connect
Security
For GitLab Enterprise and Bitbucket Data Center connections, Developer Connect now checks permissions on the calling principal.
When you create or update repository connections, Developer Connect uses Secret Manager
secrets to authenticate to third-party Git providers. Previously, these
referenced secrets were retrieved by the Developer Connect service agent (P4SA) on your
behalf, checking permissions only against the P4SA's credentials rather than
those of the calling principal. To adhere to the security principle of least
privilege, Developer Connect now checks permissions on both the calling principal
(using end-user credentials) and the P4SA, to ensure both have the
secretmanager.versions.access IAM permission on the referenced
secrets.
This check only affects GitLab Enterprise (GLE) and Bitbucket Data Center (BBDC) connections.
For instructions and more details, see the Developer Connect security bulletin.
Google SecOps
Feature
SOAR migration to Google Cloud validation status
You can now check if the SOAR migration was successful by going to the SOAR Settings > License Management page. After successful completion of Stage 1, it will say Google.com after the system version number. After successful completion of Stage 2 of SOAR permissions to IAM roles, it will say both Google.com and CloudIAM Enabled after the system version number.
For more information on the migration, see the SOAR migration guide
Looker
Announcement
The latest versions in the Looker (Google Cloud core) release channels are beginning deployment as follows:
- Latest version in the Rapid channel: Looker 26.12
- Latest version in the Regular channel: Looker 26.10
- Latest version in the No Channel channel: Looker 26.12
Managed Service for Apache Airflow
Issue
In Managed Airflow (Gen 3) builds with Airflow 2.11.1 starting from composer-3-airflow-2.11.1-build.7, the Airflow web server requires at least 3 GB of memory (the default amount of memory for a Small environment preset is 4 GB).
If the Airflow web server has less than 3 GB of memory, it might experience intermittent out-of-memory (OOM) issues. To resolve these issues, increase the web server memory to at least 3 GB.
Managed Service for Apache Spark
Feature
Managed Service for Apache Spark (formerly Dataproc on Compute Engine):
- The
2.1,2.2and2.3cluster image versions now support Confidential Compute for theg4-standard-48GPU machine type.
Change
Managed Service for Apache Spark (formerly Google Cloud Serverless for Apache Spark):
The 3.0 runtime now uses fewer executors, as follows:
- 0 min executors for
spark.dynamicAllocation.minExecutorsproperty - 1 min executor for
spark.executor.instancesandspark.dynamicAllocation.initialExecutorsproperties
- 0 min executors for
All runtimes now configure
spark.scheduler.listenerbus.exitTimeoutto30seconds.
Sensitive Data Protection
Change
If you leave InfoType.version unset
or set it to stable when setting the MEDICAL_ID
infoType in your InspectConfig,
Sensitive Data Protection includes MEDICAL_RECORD_NUMBER
findings as type MEDICAL_ID in the scan results.
You can still use the old functionality by setting
InfoType.version to legacy for the next 90 days.
Google SecOps
Feature
Publisher Agent Version 2.7.0
Publisher Agent Version 2.7.0 is now available for all regions.
This release includes the following updates for the remote agent:
- High Availability support: Adds applicative support for Publisher high availability.
- File transfer support: You can now upload and download files using playbooks and the SDK on agents that have been migrated to the GCOM infrastructure.
Google SecOps SOAR
Announcement
Release 6.3.93 is being rolled out to the first phase of regions as listed here.
This release contains internal and customer bug fixes.
Feature
Publisher Agent Version 2.7.0
Publisher Agent Version 2.7.0 is now available for all regions.
Secret Manager
Feature
Parameter templates are available in Preview. This feature lets you define standardized configuration blueprints and securely substitute environment-specific variables from parameter versions during deployment.
For more information, see Parameter templates overview.
Apigee Advanced API Security
Deprecated
Deprecation and shutdown of GenAI Incident Summary (generative AI Insights)
The standalone GenAI Incident Summary (generative AI Insights) feature in Apigee Advanced API Security Abuse Detection, currently in Preview, is deprecated and shut down as of July 9, 2026. This feature used Google Cloud generative AI large language models (LLMs) to provide automated summaries and mitigation guidance for security incidents identified by the Abuse Detection clustering tool.
For more information, see GenAI Incident Summary deprecation.
Apigee hybrid
Announcement
v1.16.7
On July 10, 2026 we released an updated version of the Apigee hybrid software, v1.16.7.
- For information on upgrading, see Upgrading Apigee hybrid to version v1.16.7.
- For information on new installations, see The big picture.
Security
Various security and CVE fixes are included in this release.
Backup and DR
Feature
Cloud SQL enhanced backups now supports custom on-demand backups. You can
now initiate an on-demand backup with a custom retention period. To cap this
retention period, you can specify a maximum retention limit by using the
max-custom-on-demand-retention-days field when creating a backup plan.
Additionally, you can now create a backup plan without scheduled backup
rules, provided that the custom on-demand retention period is configured.
For more information, see On-demand backups and Create a backup plan with no backup rule.
Feature
You can now change the backup plan applied to an existing AlloyDB for PostgreSQL cluster, provided that the new backup plan uses the same backup vault and is in the same region as the AlloyDB for PostgreSQL cluster. For more information, see Change a backup plan.
You can now take on-demand backups with custom retention of your AlloyDB for PostgreSQL cluster at any time, independently of your scheduled backups. For more information, see Create an on-demand backup.
Cloud Billing
Feature
Payments documents for invoiced billing accounts available on Payment status page
For Cloud Billing accounts that are paid by invoice, access to your payments documents, such as invoices and credit memos, is now available in the Cloud Billing console in the Payment status page.
The Payment status page replaces the Invoices page. Self-service (online) Cloud Billing accounts will continue to access Payments documents on the Invoices page.
The Payment status page provides a real-time and customizable view of your financial standing with your Cloud Billing account. The Payment status page is based on the Google payments Statement of account page, with your payments documents filtered by the Google payments account that is linked to the Cloud Billing account that you are viewing.
For more information about payments documents, see:
- Get a Cloud Billing document such as an invoice, statement, or receipt
- View your cost and payment history
- Google payments Statement of account
Cloud Deploy
Change
The Cloud Deploy image now uses a Google-specific fork of Skaffold. The
Skaffold version that you see if you run gcloud deploy releases describe, or
if you view the release in the Google Cloud Console, is now cd-skaffold
instead of a version number.
Google Distributed Cloud (software only) for bare metal
Announcement
Google Distributed Cloud (software only) for bare metal 1.33.1000-gke.59 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud for bare metal 1.33.1000-gke.59 runs on Kubernetes v1.33.11-gke.100.
After a release, it takes approximately 7 to 14 days for the version to become available for installations or upgrades with the GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.
If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.
Fixed
The following issues were fixed in 1.33.1000-gke.59:
- Fixed vulnerabilities listed in Vulnerability fixes.
- Fixed an issue where Certificate Authority (CA) rotation failed for self-managing clusters (admin, hybrid, and standalone). The failure occurs during the final phase of the rotation when attempting to move management resources back from the temporary bootstrap cluster to the self-managing cluster, which can leave the cluster in an unmanageable state. You must upgrade your clusters to version 1.33.1000-gke.59 before you rotate your CAs. Running a CA rotation on self-managing clusters in versions prior to 1.33.1000-gke.59 triggers this issue and can disrupt your ability to manage the cluster.
Google Kubernetes Engine
Change
(2026-R29) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters.
The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.
Rapid channel
- Version 1.36.0-gke.4447000 is now the default version for cluster creation in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.33.12-gke.1270000
- 1.34.9-gke.1065000
- 1.35.6-gke.1049000
- 1.36.0-gke.3712000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1011000
- 1.33 to 1.34.9-gke.1131000
- 1.34 to 1.35.6-gke.1127000
- 1.35 to 1.36.0-gke.4447000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1011000
- 1.34 to 1.34.9-gke.1131000
- 1.35 to 1.35.6-gke.1127000
- 1.36 to 1.36.0-gke.4447000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Regular channel
- The following versions are now available in the Regular channel:
Stable channel
- The following versions are now available in the Stable channel:
Extended channel
- The following versions are now available in the Extended channel:
- The following versions are no longer available in the Extended channel:
- 1.30.14-gke.2608000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.30.14-gke.2767000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.1986000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2169000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1729000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1844000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.29 to 1.30.14-gke.2710000
- 1.30 to 1.31.14-gke.2116000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.30 to 1.30.14-gke.2710000
- 1.31 to 1.31.14-gke.2116000
- 1.32 to 1.32.13-gke.1740000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
No channel (deprecated)
- The following versions are now available:
- The following node versions are now available:
Security
(2026-R29) Security updates
This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.
To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:
| GKE version | Container-Optimized OS version | Details |
|---|---|---|
| 1.31.14-gke.2233000 | cos-117-18613-613-77 | cos-117-18613-613-77 release notes |
| 1.32.13-gke.1913000 | cos-117-18613-613-77 | cos-117-18613-613-77 release notes |
| 1.33.13-gke.1101000 | cos-121-18867-381-201 | cos-121-18867-381-201 release notes |
| 1.34.9-gke.1287000 | cos-125-19216-395-138 | cos-125-19216-395-138 release notes |
| 1.36.0-gke.4681000 | cos-129-19506-224-80 | cos-129-19506-224-80 release notes |
Change
(2026-R29) Version updates
- The following versions are now available in the Stable channel:
Change
(2026-R29) Version updates
- The following versions are now available in the Regular channel:
Change
(2026-R29) Version updates
- Version 1.36.0-gke.4447000 is now the default version for cluster creation in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.33.12-gke.1270000
- 1.34.9-gke.1065000
- 1.35.6-gke.1049000
- 1.36.0-gke.3712000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.32 to 1.33.13-gke.1011000
- 1.33 to 1.34.9-gke.1131000
- 1.34 to 1.35.6-gke.1127000
- 1.35 to 1.36.0-gke.4447000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.33 to 1.33.13-gke.1011000
- 1.34 to 1.34.9-gke.1131000
- 1.35 to 1.35.6-gke.1127000
- 1.36 to 1.36.0-gke.4447000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Change
(2026-R29) Version updates
- The following versions are now available:
- The following node versions are now available:
Change
(2026-R29) Version updates
- The following versions are now available in the Extended channel:
- The following versions are no longer available in the Extended channel:
- 1.30.14-gke.2608000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.30.14-gke.2767000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.1986000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.31.14-gke.2169000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1729000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- 1.32.13-gke.1844000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
- 1.29 to 1.30.14-gke.2710000
- 1.30 to 1.31.14-gke.2116000
- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
- 1.30 to 1.30.14-gke.2710000
- 1.31 to 1.31.14-gke.2116000
- 1.32 to 1.32.13-gke.1740000
- GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
Network Connectivity Center
Feature
Include and exclude spoke filters for hybrid spokes are generally available.
You can use export filters to control which subnets or routes a spoke can send to the hub. Import filters control which subnets or routes can be accepted by a spoke from the hub.
SAP on Google Cloud
Announcement
New SAP certifications: M4N series of memory-optimized machine types
For use with SAP HANA scale-up (OLAP and OLTP) and SAP NetWeaver workloads, SAP has certified the Compute Engine memory-optimized M4N series machine types with the Intel Emerald Rapids CPU platform.
For more information, see:
- For SAP HANA, see M4N memory-optimized machine types
- For SAP NetWeaver, see M4N memory-optimized machine types
Data access
Unlock more updates for Google
You're seeing 28 updates from the last 7 days without signing in.
Public session
Next step: Free - 7 days history and full feed tools. No card required to start.
What you can unlock
Higher tiers unlock more history and more rows.
Recommended next step
FreeSame 7 days window · adds plan perks
- Incidents, maintenance, updates, and advisories
- Unlimited vendor monitoring
- Analytics and trends
AlertsPlan perks
- Standard
30 days history
- Everything in Free
- Analytics
- Compliance snapshots
AlertsWider window
- Pro
90 days history
- Everything in Standard
- Analytics
- REST API
Wider window