GKE release notes

This page documents production updates to Google Kubernetes Engine (GKE). You can periodically check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.

This page includes release notes for all channels and releases.

Current versions

The following table lists the current versions for each release channel. To learn more about the designations in this table, see What versions are available in a channel. For general information on versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

GKE Release Channel Rapid Regular Stable Extended No Channel (deprecated)
Available minor versions 1.34 to 1.37 1.34 to 1.36 1.34 to 1.35 1.31 to 1.36 1.34 to 1.36
Recommended auto-upgrade target 1.36.4-gke.1247000 1.35.8-gke.1036000 1.35.6-gke.1250000 1.32.13-gke.2337000 1.35.6-gke.1250000
Auto-upgrade targets
  • 1.34.11-gke.1056000
  • 1.35.8-gke.1380000
  • 1.36.4-gke.1247000
  • 1.37.0-gke.3165000
  • 1.34.10-gke.1328000
  • 1.35.8-gke.1036000
  • 1.36.3-gke.1767000
  • 1.34.9-gke.1655001
  • 1.35.6-gke.1250000
  • 1.31.14-gke.2630000
  • 1.32.13-gke.2337000
  • 1.33.13-gke.1547000
  • 1.34.10-gke.1328000
  • 1.35.8-gke.1036000
  • 1.36.3-gke.1767000
  • 1.34.10-gke.1328000
  • 1.35.6-gke.1250000
  • 1.36.3-gke.1767000
Default patch version for cluster creation 1.36.4-gke.1247000 1.35.8-gke.1036000 1.35.6-gke.1250000 1.35.8-gke.1036000 1.35.8-gke.1036000
COS version of default patch version cos-129-19506-448-8 cos-125-19216-532-123 cos-125-19216-395-109 cos-125-19216-532-123 cos-125-19216-532-123

For information on the current minor versions rollout and support schedule, see the GKE release schedule. To find all the patch versions available in a channel, check available and default versions.

This table also lists the Container-Optimized OS version that corresponds to the channel's default patch version. To upgrade a cluster to a specific image version, see Map Container-Optimized OS node image versions to GKE patch versions.

Other resources

For more detailed information about security-related known issues, see the security bulletin page.

To view release notes for versions prior to 2020, see the Release notes archive.

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

September 17, 2026

Change

(2026-R39) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

  • Version 1.35.8-gke.1036000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1236000
    • 1.35.7-gke.1222000
    • 1.36.3-gke.1640000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • Version 1.34.10-gke.1236000 is now available in the Stable channel.
  • Version 1.34.10-gke.1106000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

No channel (deprecated)

Security

(2026-R39) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.37.0-gke.3503000 cos-129-19506-299-82 cos-129-19506-299-82 release notes

September 11, 2026

Feature

Agent Substrate on GKE is now available for evaluation and non-production use. Production support is offered on an allowlist basis under a limited GA program.

Agent Substrate runs agentic workloads at scale on GKE clusters. To reduce resource usage, Agent Substrate suspends idle agents and takes a snapshot of the agent's active memory (RAM) and local files. When a suspended agent is triggered, the system restores the agent's state onto an available sandbox with sub-second latency.

Agent Substrate improves on the capabilities of Agent Sandbox by bypassing the bottlenecks of the standard Kubernetes control plane to run significantly more concurrent agents per machine.

For more information, see About GKE Substrate.

September 08, 2026

Change

(2026-R38) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

  • Version 1.35.7-gke.1222000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1106000
    • 1.35.7-gke.1150000
    • 1.36.3-gke.1537000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • Version 1.34.10-gke.1106000 is now available in the Stable channel.
  • Version 1.34.10-gke.1079000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.

Extended channel

  • Version 1.35.7-gke.1222000 is now the default version for cluster creation in the Extended channel.
  • The following versions are now available in the Extended channel:
  • The following versions are no longer available in the Extended channel:
    • 1.31.14-gke.2667000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.2393000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.13-gke.1613000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.10-gke.1106000
    • 1.35.7-gke.1150000
    • 1.36.3-gke.1537000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

No channel (deprecated)

Security

(2026-R38) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2689000 cos-117-18613-731-2 cos-117-18613-731-2 release notes
1.36.4-gke.1247000 cos-129-19506-448-8 cos-129-19506-448-8 release notes
1.37.0-gke.3165000 cos-129-19506-299-82 cos-129-19506-299-82 release notes

September 04, 2026

Announcement

Kubernetes 1.37 is available

Kubernetes 1.37 is now available in the Rapid channel. For more information about the content of Kubernetes 1.37, read the Kubernetes 1.37 Release Notes and Kubernetes 1.37 Release Blog.

Deprecated

Removed in 1.37

Feature

New features in 1.37

Change

Other changes in 1.37

  • Starting with GKE version 1.37.0-gke.2100000, newly created clusters default to using control plane node creation, which improves cluster security by having the control plane manage node registration instead of kubelet self-registration. Existing clusters are not affected. If your workloads require legacy kubelet self-registration, you can opt out during cluster creation by specifying --node-creation-mode=KUBELET. For more information, see Disable control plane node creation.
  • In version 1.37 and later, newly created node pools use an improved formula to calculate the default system reservation for CPU and memory resources on each node. This updated reservation algorithm reduces the system memory reservation by 10% to 15% when compared to the algorithm that's used in version 1.36 and earlier.
  • The updated default reservation algorithm applies only to new node pools that are created on version 1.37 and later. Existing node pools that you upgrade to 1.37 or later from version 1.36 or earlier don't use the updated algorithm.
  • Additionally, any new or existing node pool that runs GKE version 1.37 and later can modify the amount of CPU and memory that's reserved for system workloads in node pools by using the reservedResourcesConfig option in the node system configuration file.

September 03, 2026

Feature

GKE support for using the c3-standard-*-lssd machine types as Confidential GKE Nodes with Intel TDX is generally available. For more information, see the following:

September 02, 2026

Change

(2026-R37) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

  • Version 1.35.7-gke.1150000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1079000
    • 1.35.7-gke.1027000
    • 1.36.2-gke.2064000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • Version 1.34.10-gke.1079000 is now available in the Stable channel.
  • Version 1.34.9-gke.1610001 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
    • GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
    • GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:

Extended channel

No channel (deprecated)

Security

(2026-R37) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2667000 cos-117-18613-675-64 cos-117-18613-675-64 release notes
1.32.13-gke.2393000 cos-121-18867-584-3 cos-121-18867-584-3 release notes
1.35.8-gke.1225000 cos-125-19216-532-135 cos-125-19216-532-135 release notes
1.36.4-gke.1082000 cos-129-19506-299-161 cos-129-19506-299-161 release notes
1.37.0-gke.2155000 cos-129-19506-299-82 cos-129-19506-299-82 release notes

September 01, 2026

Feature

The bare metal machine types from the C3 machine series are now generally available with GKE clusters. You can now provision machine types such as c3-standard-192-metal in Standard mode with any available GKE version.

To use these machine types with Autopilot mode, ComputeClasses, and node pool auto-creation, you must specify the exact machine type using a custom ComputeClass and use GKE version 1.35.3-gke.1389000 or later.

Change

GKE version 1.35.1-gke.1031000 and later include the following changes to automatically created firewall rules for Services:

  • Changes the priority of multiple existing firewall rules for Services from 1000 to 999.
  • Creates additional firewall rules to deny traffic that is not explicitly allowed by other auto-created firewall rules.

If you use custom firewall rules to override GKE firewall rules for Services, these changes might cause unexpected behavior. Before you upgrade your clusters to version 1.35.1-gke.1031000 or later, do the following:

  • If you have custom firewall rules that allow or deny traffic with a priority of 1000, change the priority of those rules to a numerically lower value (such as 999 or lower) to maintain their precedence.
  • Verify that the new auto-created deny rules do not block required traffic for load balancers that use external IP addresses.

August 31, 2026

Feature

Session affinity support using GCPTrafficDistributionPolicy for GKE Gateway is generally available. This release currently supports single-cluster GKE Gateway load balancers using the following GatewayClasses:

  • gke-l7-rilb
  • gke-l7-regional-external-managed
  • gke-l7-global-external-managed

In addition to the session affinity types available in Preview, you can now use the STRONG_COOKIE_AFFINITY type, which provides the most persistent session stickiness among the session affinity types available in Google Cloud Application Load Balancers.

The session affinity types require the following minimum GKE versions:

  • CLIENT_IP, HEADER_FIELD, GENERATED_COOKIE, and HTTP_COOKIE: version 1.35.2-gke.1269001 or later
  • STRONG_COOKIE_AFFINITY: version 1.36.3-gke.1767000 or later

For more information, see Configure session affinity using GCPTrafficDistributionPolicy.

August 27, 2026

Feature

Network Endpoint Group (NEG) pre-provisioning is now available in Preview. With this feature, you can force the creation of empty zonal GCE_VM_IP_PORT NEGs in specified zones (or all zones within a region) during Service creation, regardless of whether the cluster has nodes in those zones. By extending the cloud.google.com/neg Service annotation with a custom zones parameter, you can seamlessly automate infrastructure deployments (such as attaching NEGs to backend services) without waiting for workloads to deploy. For more information, see Pre-provisioning empty NEGs.

August 26, 2026

Change

(2026-R36) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

  • Version 1.35.7-gke.1027000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.9-gke.1655001
    • 1.35.6-gke.1710000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • Version 1.34.9-gke.1655001 is now available in the Stable channel.
  • Version 1.34.9-gke.1322001 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
    • GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
    • GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:

Extended channel

No channel (deprecated)

Security

(2026-R36) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2630000 cos-117-18613-675-56 cos-117-18613-675-56 release notes
1.34.10-gke.1328000 cos-125-19216-532-123 cos-125-19216-532-123 release notes
1.35.8-gke.1026000 cos-125-19216-532-123 cos-125-19216-532-123 release notes
1.37.0-gke.2034000+preview cos-129-19506-299-82 cos-129-19506-299-82 release notes

Feature

In GKE version 1.36 and later, GCPAuthzPolicy and GCPAuthzExtension resources for GKE Gateway are now available in Preview. You can use these resources to enforce identity-based access control and zero-trust authorization on incoming traffic at the Gateway layer. These capabilities are supported on the following GatewayClasses:

  • gke-l7-global-external-managed
  • gke-l7-regional-external-managed
  • gke-l7-rilb

For more information, see Configure the GCPAuthzExtension resource.

August 25, 2026

Fixed

Fixed the issue in which GPUDirect-TCPX for a3-highgpu-8g machine types was incompatible with the Linux kernel version that was used by Container-Optimized OS in GKE version 1.34 and later. To prevent errors, GKE blocked creating or upgrading node pools that used the a3-highgpu-8g machine type to version 1.34 or later. For more information about this issue, see GKE known issues.

You can now create or upgrade node pools that use the a3-highgpu-8g machine type to any of the following GKE versions. Automatic upgrades of these node pools from version 1.33 to version 1.34 or later are no longer blocked.

  • For minor version 1.34, use patch version 1.34.5-gke.1153000 or later.
  • For minor version 1.35, use patch version 1.35.2-gke.1485000 or later.
  • For minor version 1.36 and later, use any available patch version.

In GKE version 1.34 and later, you must use version 3.1.9 or later of the GPUDirect-TCPX installer and version 2.0.12 or later of the GPUDirect-TCPX sidecar. If you previously installed these components, verify that the container images use these versions or later. To avoid degraded performance or workload failures, update your installer and sidecar image versions before the a3-highgpu-8g node pools are manually or automatically upgraded to version 1.34 or later. These container image versions correspond to the upstream definitions maintained in the gpudirect-tcpx GitHub repository.

August 21, 2026

Change

Per the June 10, 2026 release note, the configuration option to not enroll your cluster in a release channel is deprecated, and will be removed on June 14, 2027. In alignment with this deprecation, creating new clusters not enrolled in a release channel is now only allowed for existing customers. New customers can use a release channel, where you can achieve the same functionality as not enrolling your cluster in a release channel. For more information, see Clusters not enrolled in a release channel.

Change

The Windows Server 2019 (LTSC) GKE node image doesn't receive updates after the December 2025 version. Windows Server 2019 (LTSC) is in the Extended Support period of the Microsoft fixed lifecycle policy and receives only security updates. To prevent stability issues, the GKE node image for Windows Server 2019 (LTSC) is pinned to the December 2025 version. If you use this node image, switch to Windows Server 2022 (LTSC), which is in the Mainstream Support period and receives updates from Microsoft and GKE. For more information, see Creating a cluster using Windows Server node pools.

August 20, 2026

Change

(2026-R35) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

  • Version 1.36.3-gke.1537000 is now the default version for cluster creation in the Rapid channel.
  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.33.13-gke.1414000 is deprecated in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.13-gke.1462000 is deprecated in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.10-gke.1079000
    • 1.35.7-gke.1027000
    • 1.36.2-gke.2064000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Regular channel

  • Version 1.35.6-gke.1710000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.33.13-gke.1269000
    • 1.33.13-gke.1329000
    • 1.34.9-gke.1610000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1655000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.6-gke.1641000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.13-gke.1101000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.13-gke.1109000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1065000
    • 1.34.9-gke.1322000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
    • GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
    • GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:

Extended channel

  • Version 1.35.6-gke.1710000 is now the default version for cluster creation in the Extended channel.
  • The following versions are now available in the Extended channel:
  • The following versions are no longer available in the Extended channel:
    • 1.31.14-gke.2437000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.31.14-gke.2579000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.2137000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.2268000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1610000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1655000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.6-gke.1641000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

No channel (deprecated)

Security

(2026-R35) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2613000 cos-117-18613-675-48 cos-117-18613-675-48 release notes
1.32.13-gke.2314000 cos-121-18867-528-43 cos-121-18867-528-43 release notes
1.33.13-gke.1499000 cos-121-18867-528-43 cos-121-18867-528-43 release notes
1.34.10-gke.1236000 cos-125-19216-532-62 cos-125-19216-532-62 release notes

August 18, 2026

Change

For node pools running on GKE versions 1.36.3-gke.1480000 and later, the minimum supported boot disk size is 15 GB. For earlier versions, the minimum supported boot disk size is 12 GB.

August 14, 2026

Change

(2026-R34) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

  • Version 1.35.6-gke.1250000 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.13-gke.1011000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1287000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1057002 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1163012 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1241004 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

No channel (deprecated)

  • Version 1.35.6-gke.1641000 is now the default version for cluster creation.
  • The following versions are now available:
  • The following node versions are now available:
  • The following versions are no longer available:
    • 1.33.13-gke.1011000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.8-gke.1278000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1287000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1057002 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1163012 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1241004 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.36.2-gke.1346000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.36.3-gke.1244000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.36.3-gke.1253000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Security

(2026-R34) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2579000 cos-117-18613-675-37 cos-117-18613-675-37 release notes
1.32.13-gke.2268000 cos-117-18613-675-37 cos-117-18613-675-37 release notes
1.33.13-gke.1462000 cos-121-18867-528-36 cos-121-18867-528-36 release notes
1.35.7-gke.1150000 cos-125-19216-532-62 cos-125-19216-532-62 release notes
1.37.0-gke.1173000+preview cos-129-19506-299-60 cos-129-19506-299-60 release notes

August 12, 2026

Change

(2026-R33) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.12-gke.1270000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1131000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

No channel (deprecated)

Security

(2026-R33) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2543000 cos-117-18613-675-28 cos-117-18613-675-28 release notes
1.32.13-gke.2231000 cos-117-18613-675-28 cos-117-18613-675-28 release notes
1.33.13-gke.1414000 cos-121-18867-528-21 cos-121-18867-528-21 release notes
1.34.10-gke.1079000 cos-125-19216-532-42 cos-125-19216-532-42 release notes
1.35.7-gke.1027000 cos-125-19216-532-25 cos-125-19216-532-25 release notes
1.36.3-gke.1244000 cos-129-19506-299-60 cos-129-19506-299-60 release notes

August 05, 2026

Feature

You can generate optimized GKE configurations that can improve performance for specific workloads, such as Redis and MySQL, by using the gcloud CLI. The configurations are ConfigMaps and ComputeClasses that apply performance recommendations to the workloads and the nodes. These optimizations are available in Preview for GKE version 1.31.1-gke.12000 or later. You can measure the performance improvements by using open source benchmarks. For more information, see Optimize for workloads on GKE.

Feature

In GKE version 1.36.0-gke.3302001 and later, you can run Arm workloads on the Autopilot container-optimized compute platform by using the general-purpose autopilot-arm and autopilot-arm-spot ComputeClasses. You can select these ComputeClasses in Autopilot or Standard clusters. GKE runs the workloads that select these ComputeClasses in Autopilot mode. This compute platform improves Pod scheduling latency, especially during autoscaling operations. For more information, see the following documents:

August 03, 2026

Feature

TPU Subslicing (also known as Dynamic Subslicing) is now generally available for Ironwood (TPU7x). This feature enables you to incrementally provision node pools for a cube or litepod, breaking them into smaller slices (subslices) to run workloads requiring smaller topologies. Updates in this GA release include:

  • Dynamic sub-slicing (topologies smaller than 4x4x4, such as 2x2x1, 2x2x2, 2x2x4, and 2x4x4): Supported in GKE version 1.36.0-gke.3712000 or later.
  • Dynamic super-slicing (topologies 4x4x4 or larger): Supported in GKE version 1.35.2-gke.1842000 or later.
  • Partition Health Labels: The partition state label is updated to cloud.google.com/gke-tpu-partition-[shape]-state to specify smaller subslice shapes. It also introduces UNSET and INCOMPLETE states. Support for the DEGRADED state only applies to the top-level 4x4x4 topology, and not for smaller sub-slicing topologies.

For more information, see About GKE dynamic slicing.

July 30, 2026

Change

(2026-R32) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

  • Version 1.34.9-gke.1065000 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.12-gke.1165000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.8-gke.1278000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

  • Version 1.35.6-gke.1250000 is now the default version for cluster creation in the Extended channel.
  • The following versions are now available in the Extended channel:
  • The following versions are no longer available in the Extended channel:
    • 1.30.14-gke.2846000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.31.14-gke.2437000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.2137000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.13-gke.1011000
    • 1.34.9-gke.1131000
    • 1.35.6-gke.1127000
    • 1.36.0-gke.4447000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.36.0-gke.4681000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

No channel (deprecated)

July 28, 2026

Feature

GKE now supports opting out of the default kubernetes.io/arch=arm64:NoSchedule taint on Arm nodes in Standard node pools and in custom ComputeClasses. To opt out of the default taint, set the --node-architecture-taint-behavior gcloud CLI flag to NONE for a node pool or set the taintConfig.architectureTaintBehavior field to NONE for a ComputeClass. By configuring this behavior, you allow workloads that lack explicit Arm tolerations to be scheduled on Arm-based machine families (such as N4A and C4A). This is useful for running multi-architecture workloads or simplifying scheduling in mixed-mode clusters. For more information, see Configure the default Arm architecture taint.

Feature

GKE Gateway and Inference Gateway now support Cross-Origin Resource Sharing (CORS). You can configure a CORS filter directly on an HTTPRoute resource by using the portable syntax standardized by Gateway API. This feature is available in Preview in GKE version 1.35 and later for the following GatewayClasses:

  • gke-l7-rilb
  • gke-l7-regional-external-managed
  • gke-l7-global-external-managed

For more information, see Configure Cross-Origin Resource Sharing.

July 27, 2026

Feature

In GKE version 1.36 and later, GKE Dataplane V2 with NetworkPolicies supports up to 15,000 nodes per cluster, increased from the previous limit of 7,500 nodes. For clusters exceeding 5,000 nodes, contact Cloud Customer Care to request a quota increase. For more information, see Cluster size limits and requirements.

Feature

In version 1.36.2-gke.1498000 and later, GKE supports mixed-protocol Services of type LoadBalancer in general availability (GA). Mixed-protocol Services let both external (NetLB) and internal (ILB) passthrough Network Load Balancers handle simultaneous TCP and UDP traffic on a single IP address across IPv4, IPv6, and dual-stack environments.

Security

The general availability (GA) stage of mixed-protocol Services of type LoadBalancer fixes errors in traffic routing from stages prior to GA. This feature is in the GA stage in GKE version 1.36.2-gke.1498000 and later.

July 24, 2026

Change

(2026-R31) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

Extended channel

No channel (deprecated)

Security

(2026-R31) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.32.13-gke.2137000 cos-117-18613-675-2 cos-117-18613-675-2 release notes
1.34.9-gke.1610000 cos-125-19216-532-3 cos-125-19216-532-3 release notes
1.36.2-gke.2064000 cos-129-19506-299-3 cos-129-19506-299-3 release notes

July 20, 2026

Deprecated

To improve security, Ubuntu node images in GKE version 1.37 and later don't pre-install the vulkan-tools package. If you run Vulkan diagnostic tools (such as vulkaninfo) directly on GKE Ubuntu hosts, then you must manually install the vulkan-tools package. This change doesn't affect containerized GPU/Vulkan workloads.

July 16, 2026

Change

(2026-R30) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

  • Version 1.34.8-gke.1278000 is now the default version for cluster creation in the Stable channel.
  • The following versions are no longer available in the Stable channel:
    • 1.33.12-gke.1059000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.8-gke.1126000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

No channel (deprecated)

Security

(2026-R30) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.35.6-gke.1258000 cos-125-19216-395-138 cos-125-19216-395-138 release notes

Change

Starting on June 30, 2026, the Filestore API (file.googleapis.com) is enabled by default when you enable the Kubernetes Engine API (container.googleapis.com) in a project. The Filestore API is required for PersistentVolumes that use the ReadWriteMany access mode in GKE.

Feature

In GKE version 1.36.0-gke.3204000 and later, when you manually or automatically create a GKE node pool that consumes capacity reservations, you can stop GKE from falling back to on-demand capacity if reserved capacity isn't available. To consume any matching reservation without fallback, specify the any-reservation-then-fail reservation affinity in your node pool creation request, Pod specification, or ComputeClass specification. In ComputeClasses, this reservation affinity lets GKE move on to the next priority rule instead of creating on-demand compute resources. For more information, see Consuming reserved zonal resources.

Feature

GKE version 1.33 now supports the N4D machine series for node pool auto-creation and Autopilot clusters in the following patch versions and later:

  • Node pool auto-creation: 1.33.12-gke.1208000 and later
  • Autopilot: 1.33.13-gke.1079000 and later
Feature

In GKE version 1.36.0-gke.4447000 and later, the VerticalPodAutoscaler supports CPU startup boost, which temporarily increases CPU requests during application startup to improve startup latency and cost efficiency. This feature is available in Preview.

July 14, 2026

Feature

Rollout sequencing with custom stages is now generally available. This version of rollout sequencing, which is recommended if you're configuring an environment for the first time, offers a robust set of features including the following:

  • Define custom stages: Sequence the rollout of a new GKE version across environments. With custom stages, you can, for example, deploy a new version on a small subset of production clusters before a wider rollout.
  • Choose the scope of rollouts: Decide what types of versions that GKE rolls out in the sequence. For example, you can have GKE roll out patch versions, but not minor versions, across a sequence.
  • Initiate a rollout: Create a rollout of a specific version, if you want GKE to roll out that version across your sequence.
  • Manage a rollout: Pause, resume, cancel rollouts, or complete rollout stages as needed.

For more information, see About rollout sequencing with custom stages.

Change

GKE Dataplane V2 clusters running version 1.35.1-gke.1516000 or later now use CNI version 1.1.0 in the CNI configuration files. This change requires downstream CNI plugins to be compatible with CNI version 1.1.0.

Customers using self-managed open-source Istio or in-cluster unmanaged Cloud Service Mesh (CSM) variant must manually upgrade their CSM CNI version to 1.23 to ensure compatibility. If you use an incompatible CNI version, nodes might fail to reach a Ready state and might show NetworkPluginNotReady errors.

July 10, 2026

Change

(2026-R29) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

Extended channel

No channel (deprecated)

Security

(2026-R29) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2233000 cos-117-18613-613-77 cos-117-18613-613-77 release notes
1.32.13-gke.1913000 cos-117-18613-613-77 cos-117-18613-613-77 release notes
1.33.13-gke.1101000 cos-121-18867-381-201 cos-121-18867-381-201 release notes
1.34.9-gke.1287000 cos-125-19216-395-138 cos-125-19216-395-138 release notes
1.36.0-gke.4681000 cos-129-19506-224-80 cos-129-19506-224-80 release notes

July 09, 2026

Change

(2026-R28) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

  • Version 1.35.5-gke.1241004 is now the default version for cluster creation in the Regular channel.
  • The following versions are no longer available in the Regular channel:
    • 1.33.12-gke.1116000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.8-gke.1218000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1163012
    • 1.36.0-gke.2684000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • Version 1.34.8-gke.1126000 is now the default version for cluster creation in the Stable channel.
  • The following versions are no longer available in the Stable channel:
    • 1.33.12-gke.1000000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.8-gke.1000000
    • 1.35.5-gke.1000004 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

  • Version 1.35.5-gke.1241004 is now the default version for cluster creation in the Extended channel.
  • The following versions are now available in the Extended channel:
  • The following versions are no longer available in the Extended channel:
    • 1.30.14-gke.2746000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.31.14-gke.2157000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.1657000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.1829000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.12-gke.1116000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.8-gke.1218000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1163012
    • 1.36.0-gke.2684000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

No channel (deprecated)

Change

(2026-R27) Version updates

There are no version updates for 2026-R27.

July 08, 2026

Feature

The network-optimized C4N machine series is available with GKE clusters running 1.36.0-gke.3009002 or later. You can use C4N machine types in Standard or Autopilot mode.

July 07, 2026

Feature

In GKE version 1.34 and later, you can configure Google Cloud Managed Service for Prometheus to collect Pressure Stall Information (PSI) metrics from cAdvisor. You can use PSI metrics to monitor CPU, memory, and I/O congestion and stall times for your containers, Pods, and nodes. For more information, see Collect specific Prometheus metrics from Kubernetes.

Change

For GKE Standard clusters, the maximum number of nodes that you can upgrade simultaneously by using surge upgrades (maxSurge + maxUnavailable) is now 100. Each of these settings can be set as high as 100, but their sum can be no higher than 100. For more information, see Surge upgrades.

Feature

In GKE version 1.35.3-gke.1389000 and later, you can run GPU workloads on Confidential GKE Nodes with certain G4 machine types and NVIDIA RTX PRO 6000 GPUs. This feature is available in Preview. For more information, see Encrypt GPU workload data in use with Confidential GKE Nodes.

Feature

In GKE version 1.36.0-gke.1601000 and later, you can enable the logging of VerticalPodAutoscaler decisions in Cloud Logging. You can use these logs to understand why specific vertical Pod autoscaling decisions were made. This feature is available in Preview. For more information, see Collect vertical Pod autoscaler event logs.

Feature

GKE Gateway now supports backend mutual TLS (mTLS). In addition to backend authenticated TLS, backend mTLS allows the GKE Gateway load balancer to authenticate its identity to backend Pods by presenting a client certificate. GKE Gateway configures backend mTLS using the standard Gateway API spec.tls.backend.clientCertificateRef field.

This feature is supported for the following GatewayClasses:

  • gke-l7-global-external-managed
  • gke-l7-regional-external-managed
  • gke-l7-rilb

For more information, see Configure backend mutual TLS (mTLS) for a Gateway.

June 29, 2026

Change

(2026-R26) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

  • Version 1.34.8-gke.1000000 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.11-gke.1197000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.7-gke.1499000
    • 1.35.3-gke.2190000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

No channel (deprecated)

Security

(2026-R26) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.30.14-gke.2746000 cos-117-18613-613-61 cos-117-18613-613-61 release notes
1.31.14-gke.2157000 cos-117-18613-613-61 cos-117-18613-613-61 release notes
1.32.13-gke.1829000 cos-117-18613-613-61 cos-117-18613-613-61 release notes
1.33.12-gke.1270000 cos-121-18867-381-183 cos-121-18867-381-183 release notes
1.34.9-gke.1065000 cos-125-19216-395-109 cos-125-19216-395-109 release notes
1.35.6-gke.1049000 cos-125-19216-395-109 cos-125-19216-395-109 release notes
1.36.0-gke.3712000 cos-129-19506-224-49 cos-129-19506-224-49 release notes

June 26, 2026

Change

(2026-R25) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

  • Version 1.34.7-gke.1499000 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.11-gke.1074000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.7-gke.1055000
    • 1.35.3-gke.1389002 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

No channel (deprecated)

Change

(2026-R24) Version updates

There are no version updates for 2026-R24.

Security

(2026-R25) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.30.14-gke.2608000 cos-117-18613-613-5 cos-117-18613-613-5 release notes
1.30.14-gke.2710000 cos-117-18613-613-5 cos-117-18613-613-5 release notes
1.31.14-gke.1986000 cos-117-18613-613-7 cos-117-18613-613-7 release notes
1.31.14-gke.2116000 cos-117-18613-613-7 cos-117-18613-613-7 release notes
1.32.13-gke.1657000 cos-117-18613-534-110 cos-117-18613-534-110 release notes
1.32.13-gke.1740000 cos-117-18613-534-110 cos-117-18613-534-110 release notes
1.33.12-gke.1165000 cos-121-18867-381-125 cos-121-18867-381-125 release notes
1.33.12-gke.1208000 cos-121-18867-381-125 cos-121-18867-381-125 release notes
1.34.8-gke.1284000 cos-125-19216-395-7 cos-125-19216-395-7 release notes
1.35.5-gke.1057002 cos-125-19216-395-7 cos-125-19216-395-7 release notes
1.35.5-gke.1163012 cos-125-19216-395-7 cos-125-19216-395-7 release notes
1.35.5-gke.1241004 cos-125-19216-395-7 cos-125-19216-395-7 release notes
1.35.5-gke.1324000 cos-125-19216-395-7 cos-125-19216-395-7 release notes
1.36.0-gke.3302001 cos-129-19506-120-64 cos-129-19506-120-64 release notes

June 23, 2026

Issue

For GKE cluster version 1.34.1-gke.3899001 (sidecar mounter image version 1.21.9) and later affected versions, Cloud Storage FUSE volumes might fail to mount if the GKE metadata service isn't ready when the Cloud Storage FUSE sidecar initiates.

When this issue occurs, you might see the following error:

MountVolume.SetUp failed for volume "volume-name" : rpc error: code = Internal desc = the sidecar container terminated due to Error, exit code: 255

Additionally, the gcsfuse-sidecar container displays the following error:

Failed to fetch identity pool and identity provider details required for bucket access check, got error Failed to set up metadata service: failed to get project: Get "http://X.X.X.X/computeMetadata/v1/project/project-id": dial tcp 169.254.169.254:80: connect: connection refused for identity pool PROJECT_ID.svc.id.goog and identity provider https://container.googleapis.com/v1/projects/PROJECT_ID/locations/LOCATION/clusters/CLUSTER_NAME

Mitigation

To resolve this issue, perform one of the following mitigations:

  1. Upgrade your cluster to one of the following fixed GKE versions:

    • 1.34.8-gke.1218000 or later
    • 1.35.3-gke.2347000 or later
    • 1.36.0-gke.1266000 or later.
  2. Create an init container in your Pod that validates metadata service availability.

  3. Manually inject the sidecar to ensure the sidecar is blocked by an init container.

For more information, see the