Google Cloud release notes

The following release notes cover the most recent changes over the last 60 days. For a comprehensive list of product-specific release notes, see the individual product release note pages.

You can also see and filter all release notes in the Google Cloud console or you can programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

September 18, 2026

Cloud Load Balancing
Feature

Managed workload identity for backend mTLS is generally available for the following Application Load Balancers:

  • Global external Application Load Balancers
  • Regional external Application Load Balancers
  • Cross-region internal Application Load Balancers
  • Regional internal Application Load Balancers

The key benefits are as follows:

  • Streamline certificate management: Automated certificate and trust management for backend mTLS through seamless integration with Certificate Authority Service and Certificate Manager.

  • Eliminate operational toil: Certificates are automatically rotated based on the workload identity pool's configuration, removing the complexity and manual bottleneck of private key provisioning and maintenance.

  • Improve visibility and governance: Gain visibility into communication between distributed services and proactively apply governance to workloads across environments.

For more information, see Backend mTLS with managed workload identity overview

Cloud Scheduler
Change

Cloud Scheduler is available in the following location:

  • asia-southeast3 (Bangkok, Thailand)
Gemini Enterprise
Feature

Gemini Enterprise: Support for new actions (Public Preview)

Support for new actions is available in Public Preview for the following data stores:

  • Microsoft OneDrive: Copy folder, move file, move folder, rename file, rename folder, share file or folder, and update file properties.
  • Microsoft Outlook: Create calendar, RSVP to event, and update calendar.
  • Microsoft SharePoint: Create list item, discard check out document, get list fields, get list item, list lists, share resource, update file properties, update list, update list item, and update page.
  • Microsoft Teams: Add member to channel, create channel, create chat, create schedule, create time off entry, update channel, update channel message, update chat, update chat message, and update time off entry.

For more information, see Connect a third-party data source.

Gemini Enterprise Agent Platform
Feature

xAI's Grok 4.6 is generally available

Grok 4.6 is now generally available (GA) and available for production use on the global endpoint and the US multi-region endpoint.

Breaking

Agent Platform SDK for Python version 2.0.1 is available

Version 2.0.1 of the Agent Platform SDK for Python (google-cloud-agentplatform) is now available. This release migrates generative AI modules to the Google Gen AI SDK, decouples the agent surface from google-cloud-aiplatform into a dedicated package, and introduces restructured namespaces.

For details and migration instructions from google-cloud-aiplatform, see the Agent Platform SDK for Python version 2.0.1 migration guide.

Google Cloud Contact Center as a Service
Fixed

This release addresses the following issues:

  • Fixed an issue where session metadata and data feed files were missing from external storage for chats that ended before the first message from the end-user.

  • Fixed an issue with Kustomer integrations where the caller's information didn't appear on the Incoming call page of the call adapter for direct-line inbound calls.

  • Fixed an issue with inbound mobile calls where the end-user leg of the call failed, returning Unknown error, while the agent leg connected normally.

  • Fixed an agent desktop issue where live call and chat data were lost.

  • Fixed an issue that occurred when the receiving agent in an agent-to-agent transfer didn't answer the call. The receiving agent was marked as active on the call indefinitely, even after the call ended.

  • Fixed an issue where the Dismiss button remained active after an agent sent a message, resulting in a 409 error when clicked.

  • Fixed an issue where duplicate "chat finished" events were reported when the end-user left a chat session at nearly the same time that the agent ended the chat session.

  • Fixed an issue where deflected calls were missing from the All Call History and Voice Inbound (IVR) History reports.

  • Fixed an issue that occurred when a direct inbound call was deflected to the agent's overcapacity queue, then that queue redirected to a SIP URI. The SIP redirect didn't include the custom SIP headers.

  • Fixed an issue where an in-queue announcement interval of several minutes for inbound IVR calls was incorrectly reduced to approximately 60 seconds.

  • Fixed an issue where calls that agents were unable to answer due to microphone failures were incorrectly reported as "picked up" in the Agent Activity Timeline report.

  • Fixed an issue where the system incorrectly marked agents as still being on a call after it ended, which either prevented them from changing their status to Available or silently blocked them from receiving new calls.

  • Fixed an issue where processing delays for ended calls caused timeout errors.

  • Fixed an issue where a sudden spike in calls bypassed capacity limits, causing agent availability to drop below required minimums.

  • Fixed an issue where the Agent Activity Timeline report incorrectly attributed manual agent logins and logouts to System instead of the appropriate agents.

  • Fixed an issue where calls with a missed offer became permanently stuck in the queue, preventing them from being routed to other available agents. This occurred with queues configured with multicast fallback disabled.

  • Fixed an issue where manual or cascade outbound calls that were canceled before connecting were missing from team-filtered Call History reports.

  • Fixed an issue that prevented over-capacity deflection from triggering when an agent warm-transferred an outbound call to a queue.

  • Fixed an issue where calls weren't correctly routed to the top-ranked agent when using agent priority overrides.

  • Fixed an issue where escalated voice calls were incorrectly reported as both answered and abandoned.

  • Fixed an issue where calls were missing from the All Call History and Voice Inbound History reports if the caller hung up before leaving a voicemail.

  • Fixed an issue where Salesforce click-to-dial outbound calls were incorrectly associated with the most recent open case instead of the case from which the call was initiated.

  • Fixed an issue where email accounts remained disconnected indefinitely after a temporary authentication failure.

  • Fixed an issue in Agent Assist where long periods of silence during calls caused connection timeouts, triggering false-positive error alerts.

  • Fixed an issue where the arrow-down-icon and arrow-up-icon arrows on the Agents > Filter Settings page were rendered at an incorrect scale.

  • Fixed an issue where incoming calls incorrectly created duplicate Salesforce accounts instead of linking to existing accounts.

  • Fixed an issue where the outbound call queue list displayed stale information, potentially causing calls to be placed in a queue that didn't match the agent's selected language.

  • Fixed an issue where the menus for transferring calls and forwarding calls to voicemail appeared in English instead of the agent's selected language.

  • Fixed an issue where the wrap-up disposition panel froze after a network reconnection even though the submission had completed successfully.

  • Fixed an issue where outbound, click-to-dial calls initiated in Salesforce incorrectly linked to and reassigned ownership of other cases associated with the same phone number.

  • Fixed an issue where the agent adapter went blank and prevented new calls from reaching the agent if an end-user hung up immediately after the agent received the call notification.

  • Fixed an issue where calls that failed to connect got stuck in a silent 'connecting' state in the call adapter.

  • Fixed an issue where Salesforce CRM connections dropped for organizations enforcing OAuth Refresh Token Rotation.

  • Fixed an issue where part of an agent's audio was dropped from recordings when a virtual task assistant ran in the middle of a call.

  • Fixed a web SDK issue where menus in the pre-chat and chat screens didn't comply with WAI-ARIA keyboard navigation standards.

  • Fixed a web SDK issue where screen readers couldn't identify the purpose of the Text size options for the chat screen.

Announcement

Advanced reporting dashboards 6.4

We've released version 6.4 of the advanced reporting dashboards.

Feature

Real-time Agent Monitoring dashboard: new Active call ID(s) column

The Real-time Agent Monitoring dashboard now has an Active Call ID(s) column in the Live Agent Data table. The column displays the call ID(s) for any call in a connecting, connected, or reconnecting state for the agent. If an agent is handling multiple concurrent calls, the call IDs appear in a comma-separated list. The Active Call ID(s) column reduces the number of steps required for supervisors to identify active calls during live monitoring.

Feature

Improved filtering by team

We made the following changes to team-based filtering:

  • Renamed the Teams filter to Agent Teams to clarify that it filters by the agent team handling the interactions. This change is in the Real-time Queue Monitoring - Calls, Real-time Queue Monitoring - Chats, Real-time Connected - Calls, and Real-time Connected - Chats dashboards. For more information, see Queue monitoring dashboards, Real-time Connected - Calls dashboard, and Real-time Connected - Chats dashboard.

  • Added a Queue Teams filter to the Real-time Queued - Calls and Real-time Queued - Chats dashboards. This lets you filter queued interactions by the team assigned to the queue.

Feature

Improved the Real-time Calls and Real-time Chats dashboards

We made the following dashboard improvements:

  • Real-time Calls - Calls Connected dashboard. Added the following columns to the Connected Calls table:

    • Total Consumer Talk Time. Total time since the call first connected to a virtual agent or a human agent.

    • Total Hold Time. Total time the call has spent on hold so far, including a hold currently in progress.

  • Real-time Chats - Chats Connected dashboard. Added the following column to the Connected Chats table:

    • Total Consumer Chat Time. Total time since the chat first connected to a virtual agent or a human agent.
Feature

Real-time Calls - Calls Queued dashboard: new Projecting column

The Real-time Calls - Calls Queued dashboard has a new Projecting column in the Call Queued table. Indicates whether the routing engine (deltacast) is currently projecting this queued call to an available agent.

Feature

Advanced reporting available in French Canadian

All advanced reporting dashboards and Explores are now available in French Canadian. When you select French Canadian as your profile language in the CCAI Platform portal, these dashboards and Explores display in that language.

Administrators: There's a new Français (CAN) option when you click Admin > Change Language in the CCAI Platform portal.

Fixed

This release addresses the following issues:

  • Fixed an issue where the formatting of numeric values was inconsistent across tiles.

  • Fixed an issue where column headers, filter labels, and tile titles didn't immediately switch to a newly selected language.

  • Fixed an issue where the Productive Agents column in the tables of the Queue Group Performance - All dashboard didn't display values appropriate to the queue group settings.

  • Fixed an issue in the Call Queue Metrics (Historical) Explore where filtering by Agent Name without including it as a visible column resulted in zero rows being returned.

  • Fixed an issue that affected calls to a sub-menu that were deflected using Custom After Hours Deflection to a message. These calls were incorrectly attributed to the parent menu in the All Queued Interactions report.

  • Fixed the effectiveness of the Direction filter in the following dashboards:

    • Agent Performance. The Agent Productivity Detailed – Calls and Agent Productivity Detailed – Chats tables correctly reflect the filter setting.

    • Real-time Agent Monitoring. The Agent Performance table and historical metrics tiles correctly reflect the filter setting.

    • All Interactions – Calls and All Interactions – Chats. The IVR Interactions (calls only) and Virtual Agent Interactions tables correctly reflect the filter setting.

  • Fixed an issue with the Queue Performance - Calls dashboard when short abandons were present in the specified date range. The Avg Queue Time column in the Queue Summary table incorrectly displayed the raw sum of queue durations instead of a true average.

  • Fixed an issue where team filters didn't apply correctly when generating the Individual Call History Report and the Individual Chat History Report. This resulted in the inclusion of data from unmanaged queues.

  • Fixed an issue where French Canadian translations for several dashboard metrics and labels were incorrect, incomplete, or missing.

  • Fixed the following issues with the Real-time Calls - Calls Queued dashboard:

    • The Total Queued Now metric didn't include callers who were returned to the queue after an automated-answer detection miss.

    • The Current Max Queue Wait Time (H:M:S) and Current Avg Queue Wait Time (H:M:S) metrics mistakenly measured from a caller's original entry into the queue, rather than from their most recent return to the queue.

  • Fixed an issue where a gray bar appeared at the bottom of the advanced reporting dashboards, preventing a full view of the dashboards.

Memorystore for Valkey Model Armor
Feature

Filter version v4 is available and set as the default for the Latest alias. Filter version v3 is promoted to the Stable alias in all supported regions except the following:

  • In asia-northeast3, v1 remains the Stable version.
  • In australia-southeast2, v3 becomes the Stable version on September 25, 2026.

If your templates use the Stable alias, they automatically upgrade to v3 when v3 becomes Stable in that region.

Filter versions v1 (except in asia-northeast3, and starting September 25, 2026 in australia-southeast2) and v2 transition to Legacy status and retire on December 17, 2026. If your templates are explicitly configured with v1 or v2 in regions where those versions are in Legacy status, you must migrate them to v3 or the Stable alias before December 17, 2026.

For more information, see Version release timeline and Model Armor filter version history.

September 17, 2026

Apigee hybrid
Announcement

v1.16.10

On September 17, 2026 we released an updated version of the Apigee hybrid software, v1.16.10.

Fixed

Fixed in this release

Bug ID Description
556750755 Fixed an issue where EventFlow (Server-Sent Events) dropped or truncated events following a large (>16 KB) event under load on the http-adaptor datapath.
547712217 Fixed an issue where EventFlow (Server-Sent Events) responses larger than 16 KB could be truncated or corrupted across socket reads.
519729209 Fixed a SAML XML Signature Wrapping (XSW) vulnerability in the ValidateSAMLAssertion policy.
514384893 Hardened the Script policy to block server-side request forgery (SSRF) to link-local addresses.
505645076 Fixed a security issue in the OAuthV2 policy to prevent unauthorized token injection via HTTP form parameters.
505543289 Fixed thread-safety issues in the Netty client connection pool and channel lifecycle.
503817773 Improved security in the OAuthV2 policy implicit grant redirect_uri validation.
502268966 Apigee hybrid now supports optional decoding of percent-encoded path separators (%2F and %5C) before flow selection via the request.path.decode.encoded.separators proxy property.
480770263 Fixed an issue in the SpikeArrest policy to handle edge cases that previously caused NullPointerException and 500 errors.
472526232 Improved SAML assertion validation in the ValidateSAMLAssertion policy against entity and comment injection.
470375542 Fixed a memory leak in WSFrameDecoder that could result in a spike in 503 responses with no_healthy_upstream errors.
449228485 Apigee hybrid now supports configuring custom Kubernetes PodDisruptionBudget (minAvailable or maxUnavailable) values for Apigee hybrid components in your overrides.yaml file.
402250928 Apigee hybrid now supports routing outbound calls from AI policies, such as the Model Armor and semantic caching policies, through an HTTP forward proxy.
Feature

Kubernetes 1.36 support

Apigee hybrid v1.16.10 adds support for Kubernetes 1.36 on Google Kubernetes Engine (GKE), Google Distributed Cloud Virtual for VMware (vSphere), Google Distributed Cloud Virtual for bare metal, Amazon EKS, Azure AKS, and Rancher Kubernetes Engine (RKE2).

For more information, see Supported platforms.

Feature

Forward proxy support for AI policies

Apigee hybrid v1.16.10 adds forward proxy support for AI policies, such as the Model Armor and semantic caching policies. Outbound calls from these policies can now be routed through an HTTP forward proxy.

For more information, see Configure a forward proxy, Get started with the Model Armor policies, and Get started with semantic caching policies.

Security
Bug ID Description
N/A Security fixes for apigee-asm-ingress.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-asm-istiod.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-connect-agent.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-fluent-bit.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra-client.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-mart-server.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-mint-task-scheduler.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-open-telemetry-collector.
This addresses the following vulnerability:
N/A Security fixes for apigee-operators.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-prom-prometheus.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-prometheus-adapter.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-redis.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-runtime.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-synchronizer.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-watcher.
This addresses the following vulnerabilities:
BigQuery
Feature

You can add unit tests to pipelines to validate your SQL transformation logic against mock datasets. Unit tests for pipelines are generally available (GA).

Cloud Asset Inventory
Feature

The following resource type is publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, and Feed APIs.

  • Cloud TPU API
    • tpu.googleapis.com/QueuedResource
Cloud SQL for MySQL
Change

Cloud SQL for MySQL now automatically enables point-in-time recovery (PITR) in a separate, asynchronous operation after disaster recovery (DR) switchover and replica failover operations complete. Because PITR enablement no longer blocks switchover and replica failover, these operations complete faster, helping you reduce your recovery time.

For more information, see Use advanced disaster recovery (DR).

Cloud SQL for PostgreSQL
Change

Cloud SQL for PostgreSQL now automatically enables point-in-time recovery (PITR) in a separate, asynchronous operation after disaster recovery (DR) switchover and replica failover operations complete. Because PITR enablement no longer blocks switchover and replica failover, these operations complete faster, helping you reduce your recovery time.

For more information, see Use advanced disaster recovery (DR).

Compute Engine
Feature

Generally available: The storage-optimized Z4D machine series is generally available for Compute Engine. Powered by AMD EPYC Turin processors and Titanium offload processors, Z4D instances are purpose-built for low core usage and high storage density workloads such as:

  • SQL, NoSQL, and vector databases
  • Data analytics and data warehouses
  • Search
  • Parallel file systems for AI/ML

The Z4D machine series delivers up to 3 TB of memory and 42,000 GiB of local Titanium SSD capacity. Z4D also supports up to 400 Gbps of network bandwidth using two physical NICs. Z4D instances are available in predefined standardlssd and highlssd machine shapes.

For more information, see Storage-optimized machine family.

Container Optimized OS
Change

cos-beta-133-19999-44-44

Kernel Docker Containerd GPU Drivers
COS-6.18.48 v29.4.3 v2.3.4 See List
Change

cos-129-19506-448-36

Kernel Docker Containerd GPU Drivers
COS-6.12.105 v27.5.1 v2.2.7 See List
Change

Fixed CVE-2026-56391 in sys-apps/coreutils.

Security

Fixed CVE-2026-56391 in sys-apps/coreutils.

Security

Fixed CVE-2026-58470 in net-misc/wget.

Security

Fixed CVE-2026-80590 in the Linux kernel.

Security

Fixed CVE-2026-59890 in dev-python/setuptools.

Security

Fixed CVE-2026-80737 in the Linux kernel.

Security

Upgraded net-libs/nghttp2 to 1.69.0 and fixed CVE-2026-58055.

Security

Fixed CVE-2026-80788 in the Linux kernel.

Security

Fixed CVE-2026-80789 in the Linux kernel.

Security

Fixed CVE-2026-80791 in the Linux kernel.

Security

Fixed CVE-2026-80792 in the Linux kernel.

Security

Fixed CVE-2026-80793 in the Linux kernel.

Security

Fixed CVE-2026-80805 in the Linux kernel.

Security

Fixed CVE-2026-80806 in the Linux kernel.

Security

Fixed CVE-2026-80808 in the Linux kernel.

Security

Fixed CVE-2026-80837 in the Linux kernel.

Security

Fixed CVE-2026-80838 in the Linux kernel.

Security

Fixed CVE-2026-80839 in the Linux kernel.

Security

Fixed CVE-2026-80842 in the Linux kernel.

Security

Fixed CVE-2026-80843 in the Linux kernel.

Security

Fixed CVE-2026-80845 in the Linux kernel.

Security

Fixed CVE-2026-80852 in the Linux kernel.

Security

Fixed CVE-2026-80854 in the Linux kernel.

Security

Fixed CVE-2026-80855 in the Linux kernel.

Security

Fixed CVE-2026-80856 in the Linux kernel.

Security

Fixed CVE-2026-80862 in the Linux kernel.

Security

Fixed CVE-2026-80916 in the Linux kernel.

Security

Fixed CVE-2026-80917 in the Linux kernel.

Change

cos-125-19216-655-28

Kernel Docker Containerd GPU Drivers
COS-6.12.105 v27.5.1 v2.2.7 See List
Feature

Fixed a performance issue in the GVE driver on multi-NUMA systems.

Fixed

Upgraded net-libs/libnftnl to v1.2.9.

Security

Fixed CVE-2026-80590 in the Linux kernel.

Security

Fixed CVE-2026-80737 in the Linux kernel.

Security

Fixed CVE-2026-80788 in the Linux kernel.

Security

Fixed CVE-2026-80789 in the Linux kernel.

Security

Fixed CVE-2026-80791 in the Linux kernel.

Security

Fixed CVE-2026-80792 in the Linux kernel.

Security

Fixed CVE-2026-80793 in the Linux kernel.

Security

Fixed CVE-2026-80805 in the Linux kernel.

Security

Fixed CVE-2026-80806 in the Linux kernel.

Security

Fixed CVE-2026-80808 in the Linux kernel.

Security

Fixed CVE-2026-80837 in the Linux kernel.

Security

Fixed CVE-2026-80838 in the Linux kernel.

Security

Fixed CVE-2026-80839 in the Linux kernel.

Security

Fixed CVE-2026-80842 in the Linux kernel.

Security

Fixed CVE-2026-80843 in the Linux kernel.

Security

Fixed CVE-2026-80845 in the Linux kernel.

Security

Fixed CVE-2026-80852 in the Linux kernel.

Security

Fixed CVE-2026-80854 in the Linux kernel.

Security

Fixed CVE-2026-80855 in the Linux kernel.

Security

Fixed CVE-2026-80856 in the Linux kernel.

Security

Fixed CVE-2026-80862 in the Linux kernel.

Security

Fixed CVE-2026-80916 in the Linux kernel.

Security

Fixed CVE-2026-80917 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068

Change

cos-117-18613-731-21

Kernel Docker Containerd GPU Drivers
COS-6.6.153 v24.0.9 v1.7.34 See List
Security

Fixed CVE-2026-80590 in the Linux kernel.

Security

Fixed CVE-2026-80737 in the Linux kernel.

Security

Fixed CVE-2026-80788 in the Linux kernel.

Security

Fixed CVE-2026-80789 in the Linux kernel.

Security

Fixed CVE-2026-80791 in the Linux kernel.

Security

Fixed CVE-2026-80792 in the Linux kernel.

Security

Fixed CVE-2026-80793 in the Linux kernel.

Security

Fixed CVE-2026-80805 in the Linux kernel.

Security

Fixed CVE-2026-80806 in the Linux kernel.

Security

Fixed CVE-2026-80808 in the Linux kernel.

Security

Fixed CVE-2026-80842 in the Linux kernel.

Security

Fixed CVE-2026-80843 in the Linux kernel.

Security

Fixed CVE-2026-80852 in the Linux kernel.

Security

Fixed CVE-2026-80854 in the Linux kernel.

Security

Fixed CVE-2026-80855 in the Linux kernel.

Security

Fixed CVE-2026-80856 in the Linux kernel.

Security

Fixed CVE-2026-80916 in the Linux kernel.

Security

Fixed CVE-2026-80917 in the Linux kernel.

Change

cos-121-18867-584-23

Kernel Docker Containerd GPU Drivers
COS-6.6.153 v27.5.1 v2.0.10 See List
Security

Fixed CVE-2026-80590 in the Linux kernel.

Security

Fixed CVE-2026-80737 in the Linux kernel.

Security

Fixed CVE-2026-80788 in the Linux kernel.

Security

Fixed CVE-2026-80789 in the Linux kernel.

Security

Fixed CVE-2026-80791 in the Linux kernel.

Security

Fixed CVE-2026-80792 in the Linux kernel.

Security

Fixed CVE-2026-80793 in the Linux kernel.

Security

Fixed CVE-2026-80805 in the Linux kernel.

Security

Fixed CVE-2026-80806 in the Linux kernel.

Security

Fixed CVE-2026-80808 in the Linux kernel.

Security

Fixed CVE-2026-80842 in the Linux kernel.

Security

Fixed CVE-2026-80843 in the Linux kernel.

Security

Fixed CVE-2026-80852 in the Linux kernel.

Security

Fixed CVE-2026-80854 in the Linux kernel.

Security

Fixed CVE-2026-80855 in the Linux kernel.

Security

Fixed CVE-2026-80856 in the Linux kernel.

Security

Fixed CVE-2026-80917 in the Linux kernel.

Dataform
Feature

You can use unit tests to test Dataform actions against mock data with an expected result set. Dataform unit tests are generally available (GA).

Gemini Enterprise
Announcement

Gemini Enterprise: Gemini Code Assist availability update for subscriptions

If you're getting a new Gemini Enterprise Standard or Plus subscription or renewing an existing subscription online, the subscription no longer includes access to Gemini Code Assist features. Existing subscriptions that include Gemini Code Assist features can still access the features until the end of their subscription term.

Instead of Gemini Code Assist, you can use Antigravity for IDEs with AI developer tools. For more information, see AI developer tools overview.

If you're still looking to use Gemini Code Assist with your Gemini Enterprise licenses, you can obtain a new Gemini Enterprise subscription that includes Gemini Code Assist by contacting Google Cloud sales.

Feature

Gemini Enterprise: Voice input for the chat box

You can speak your queries and prompts to Gemini Enterprise. Use the microphone button to record your voice, review and edit the transcribed text, and then submit the text.

This feature is generally available (GA). To make voice input available to users, a Gemini Enterprise administrator must turn on the Enable speech-to-text toggle in the Google Cloud console.

For more information, see the following:

Gemini Enterprise Agent Platform
Feature

Gemini Omni Flash supports stateful and streaming video generation (Preview)

Gemini Omni Flash supports stateful (store: true) and server-sent event (SSE) streaming (stream: true) video generation in the Interactions API in Preview. You can temporarily store generated videos and interaction state on the server, stream status updates and final outputs over an SSE connection, or retrieve completed asynchronous interactions using unary or streaming GET requests.

For more information, see Generate videos from text.

Google Cloud Armor
Feature

Cloud Armor managed rulesets protect your backend services and APIs from a wide range of web application threats using threat signatures which are automatically kept up-to-date. For more information, see Managed rules overview. This feature is available in Preview.

Google Distributed Cloud (software only) for VMware
Announcement

Google Distributed Cloud (software only) for VMware 1.34.900-gke.135 is now available for download. To upgrade, see Upgrade a cluster. Google Distributed Cloud 1.34.900-gke.135 runs on Kubernetes v1.34.7-gke.200.

If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.

After a release, it takes approximately 7 to 14 days for the version to become available for use with GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

Fixed

The following issues were fixed in 1.34.900-gke.135:

  • Fixed vulnerabilities listed in Vulnerability fixes.
  • Fixed an issue where user clusters repeatedly alternated between Reconciling and Running states if the management cluster configured a different pod density than the user cluster.
  • Updated etcd to v3.5.33-0-gke.3 to address security vulnerabilities CVE-2026-46595 and CVE-2026-39821.
  • Fixed an issue where gkectl diagnose and preflight validations failed to locate PersistentVolume datastores for user clusters deployed in a separate vSphere datacenter from the admin cluster (cpNodesInAdminDatacenter: true).
  • Fixed an issue where deleting a cluster could get stuck because the node pool controller attempted to recreate machine resources while deletion was in progress.
Google Distributed Cloud (software only) for bare metal
Announcement

Google Distributed Cloud (software only) for bare metal 1.34.900-gke.135 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud for bare metal 1.34.900-gke.135 runs on Kubernetes v1.34.7-gke.200.

After a release, it takes approximately 7 to 14 days for the version to become available for installations or upgrades with the GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.

Fixed

The following issues were fixed in 1.34.900-gke.135:

  • Fixed vulnerabilities listed in Vulnerability fixes.
  • Fixed an issue where the status for Ingress resources was not updated when using bundled Ingress.
  • Fixed an issue where user clusters repeatedly alternated between reconciling and running states if the management cluster had a different pod density configuration than the user cluster.
  • Updated etcd to v3.5.33-0-gke.3 to address security vulnerabilities CVE-2026-46595 and CVE-2026-39821.
  • Fixed an issue where deleting a cluster could get stuck because the node pool controller attempted to recreate machine resources while cluster deletion was in progress.
Google Kubernetes Engine
Change

(2026-R39) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

  • Version 1.35.8-gke.1036000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1236000
    • 1.35.7-gke.1222000
    • 1.36.3-gke.1640000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • Version 1.34.10-gke.1236000 is now available in the Stable channel.
  • Version 1.34.10-gke.1106000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

No channel (deprecated)

Security

(2026-R39) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.37.0-gke.3503000 cos-129-19506-299-82 cos-129-19506-299-82 release notes

Change

(2026-R39) Version updates

  • Version 1.34.10-gke.1236000 is now available in the Stable channel.
  • Version 1.34.10-gke.1106000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Change

(2026-R39) Version updates

  • Version 1.35.8-gke.1036000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1236000
    • 1.35.7-gke.1222000
    • 1.36.3-gke.1640000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Change

(2026-R39) Version updates

Change

(2026-R39) Version updates

Change

(2026-R39) Version updates

Looker
Announcement

Looker 26.18 will roll out to Looker (original) instances on the following schedule:

  • Expected deployment start: Monday, September 21, 2026
  • Expected final deployment and download available: Sunday, October 4, 2026

Looker 26.18 is expected to include the following changes, features, and fixes.

Fixed

An issue has been fixed where custom content theme fonts were improperly applied to the Look edit mode bar. This feature now performs as expected.

Fixed

An issue has been fixed where downloading a dashboard as a CSV or ZIP file could result in a 500 error if any dashboard elements lacked an explicit title. This feature now performs as expected.

Fixed

An issue has been fixed where links created using the LookML link parameter could return a 500 error if no label was specified. This feature now performs as expected.

Fixed

An issue has been fixed where dashboard filter token chips didn't display an active highlighted background when a filter value was selected. This feature now performs as expected.

Fixed

An issue has been fixed where the Git connection test could fail to recognize Git credentials as sufficient if a branch protection rule on the Git provider restricted temporary branches. This feature now performs as expected.

Fixed

An issue has been fixed where analytic models that referenced cross-database, schema-qualified, or dot-delimited table names failed to compile in BigQuery and Snowflake DDL generation. This feature now performs as expected.

Fixed

An issue has been fixed where custom tooltips in Single Record visualizations appeared at the bottom of the Explore panel rather than directly beneath the selected row. This feature now performs as expected.

Fixed

An issue has been fixed where dashboard filter tokens and popover menus could fail to inherit fonts from custom themes. This feature now performs as expected.

Fixed

An issue has been fixed where dragging series between Y-axes on pivoted Cartesian charts could cause the Explore page to crash or prevent visualization configurations from being saved. This feature now performs as expected.

Fixed

An issue has been fixed in Explores where you couldn't scroll within the Chart Config Editor dialog when editing JSON visualization configurations. This feature now performs as expected.

Fixed

An issue has been fixed where scheduled PDF deliveries to Cloud Storage could produce corrupted files and unexpectedly replace spaces in filenames with underscores. This feature now performs as expected.

Fixed

An issue has been fixed where attempting to visualize pivoted query results in SQL Runner resulted in a TypeError configuration error. This feature now performs as expected.

Fixed

API requests that target a LookML project whose files or directories aren't found on the instance now return a 404 Not Found error instead of a 500 Internal Server Error.

Fixed

In Conversational Analytics, the Open in Explore button and sidebar exploration links are now hidden or disabled with explanatory tooltips when you lack explore permissions for the underlying model.

Fixed

The embed preload page now supports custom theming using the theme URL query parameter.

Fixed

Donut Multiples visualizations now automatically hide overlapping value labels.

Fixed

An issue has been fixed in self-service analytics where CSV and Excel uploads to BigQuery and Snowflake could fail or corrupt data when files contained multiline headers, leading numeric characters, UTF-8 BOM markers, or special characters. This feature now performs as expected.

Fixed

An issue has been fixed where creating a shared branch based on the production branch in a bare repository project could initialize from stale remote commits, causing the Looker IDE to immediately report the branch as being behind production. This feature now performs as expected.

Fixed

An issue has been fixed where scheduled deliveries intermittently failed with permission errors such as Cannot send all results because user permissions were incorrectly cached across scheduled jobs on worker threads. This feature now performs as expected.

NetApp Volumes
Feature

Organization Policy Service custom constraints are available for Google Cloud NetApp Volumes. You can use custom constraints to control how NetApp Volumes is used in your organization. For example, you can restrict storage pool or volume capacity, or enforce that storage pools are created only with Premium or Extreme service levels.

For more information, see Custom organization policy constraints.

Oracle Database@Google Cloud
Feature

For Exadata Database Service, Oracle Database@Google Cloud is available in europe-west12 (Turin, Italy) region.

For a list of supported locations, see Supported regions and zones.

Spanner
Feature

Spanner queues are generally available (GA). Spanner queues provide transactional messaging to help you manage asynchronous work. The feature pairs this capability with the scalability and reliability of Spanner, letting you build event-driven applications. For more information, see the Spanner queues overview.

September 16, 2026

Backup and DR
Feature

You can now use auto-protection policies and resource labels to automatically protect Compute Engine instances and Persistent Disks at scale in Backup and DR. This feature allows you to automatically assign a backup plan to qualifying resources across projects based on user-defined labels. This feature is in Preview. For more information, see Automate resource protection.

BigQuery
Feature

You can use the migration lineage service to visualize the data flow and connections in your source database and help you plan a BigQuery data warehouse migration. This feature is in Preview.

Cloud Number Registry
Breaking
Datastream
Feature

Datastream now supports MongoDB extended JSON canonical mode as the default format for new streams from MongoDB sources to BigQuery destinations.

Canonical mode provides higher data fidelity by explicitly labeling every BSON type to prevent precision loss during data exchange.

For more information, see the following:

Filestore
Feature

Small capacity Filestore instances for the Regional service tier are generally available (GA). Small capacity instances start at 100 GiB and scale in 1 GiB increments, providing an option for development, testing, and applications with low traffic or basic storage needs.

For more information, see Small capacity instances.

Gemini Enterprise Agent Platform
Feature

CodeMender updates (v0.8.0)

This release introduces updates to CodeMender:

  • Gemini 3.8 Flash default: Gemini 3.8 Flash (gemini-3.8-flash) is now supported and enabled as the default model for CodeMender CLI sessions, delivering faster inference and improved reasoning. A one-time notice in the CLI informs users when the new default is active.
  • Tool payload guardrails: Introduced safe output limits for file reading (2 MiB) and codebase grep search (512 KiB) with centered match context windows, eliminating payload overflow errors and improving stability during large repository scans.
  • Bug fixes:
    • Fixed an issue where shell detection and command execution on Windows could fail during repository resets and exploit verification when Git Bash was installed in standard registry or non-PATH locations.
    • Fixed an issue in cm verify where verified findings could report "not found" or fail to persist confidence and status upon session completion or resumption.
    • Fixed syntax errors in generated verification scripts caused by invalid regex escaping in grep assertions during cm verify.
    • Prevented HTTP 409 lease conflict errors during long-running sessions by ensuring streaming HTTP connections are promptly released.

For more information, see CodeMender documentation.

Secure Source Manager
Feature

Secure Source Manager webhooks now support Pull request comment trigger events. You can configure webhooks to trigger notifications whenever a comment is added, edited, or deleted on a pull request.

For more information, see the Pull request comment event payload in the Webhooks overview.

Security Command Center
Feature

You can use the following MCP server endpoints to enable LLM agents to perform investigative and management tasks in Security Command Center.

This feature is in Preview.

Virtual Private Cloud
Feature

General Availability: You can add Dynamic NICs to the same VPC network used by other network interfaces of a Compute Engine instance. For more information, see Multiple network interfaces.

Feature

General Availability: VPC Flow Logs supports logging for App Engine resources that are configured with Direct VPC egress. For more information, see Serverless flows and ServerlessDetails field format.

Feature

General Availability: VPC Flow Logs adds the following metadata annotations for Private Service Connect:

  • src_psc_interface and dest_psc_interface
  • psc.consumer_connection
  • psc.psc_endpoint.name
  • psc.psc_attachment.name

For more information, see Record format.

September 15, 2026

Artifact Registry
Feature

Artifact Registry support for managing Conda packages with Artifact Registry repositories is in Preview. For more information, see Get started with Conda packages.

Batch
Issue
Carbon Footprint
Change

For the July 2026 data release (published mid-September 2026), we have upgraded the carbon model to version 17 and implemented the following updates:

Updating Scope 1 & 3 Emissions from Google's Corporate Footprint

Updating Inputs for Scope 2 Market-Based Emissions Calculations

  • Updated annual renewable electricity allocation percentages in accordance with the 2026 Google Environmental Report.
  • Refreshed background annual emissions factors using updated government data sources across Scope 1, Scope 2, and Scope 3. Note that Scope 2 location-based emissions continue to be calculated using hourly greenhouse gas emission factors. Learn more in the Scope 2 market-based allocation documentation.
  • Incorporated marketplace purchases of Granular Certificates (Type B certificates / T-EACs) covering a significant portion of electricity load across carbon-intensive regions.
  • Granular certificate purchases represent market-based accounting allocations. Customers seeking to minimize emissions are encouraged to prioritize regions with high Carbon Free Energy (CFE) scores for new workloads.

Regional Accounting & Boundary Updates

  • Aligned European clean energy matching boundaries with updated RE100 criteria.
  • Corrected country mapping configurations in annual emission factor scripts to resolve historical data discrepancies across select Asian market regions (e.g., asia-east2, asia-northeast3).

To correct your July emissions data, schedule a manual data backfill for the month.

Cloud Asset Inventory
Feature

The following resource type is publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, and Feed APIs.

  • Network Management API
    • networkmanagement.googleapis.com/VpcFlowLogsConfig
Compute Engine
Feature

Public preview: Network-optimized C4N machine type with 375 GiB to 12,000 GiB of attached Titanium SSD are now available in Preview. You don't have to request allowlist approval.

For more information, see C4N machine series.

Confidential Space
Announcement

A new Confidential Space image (260800) is available. Support for Confidential Space on H100 GPU (a3-highgpu-1g machine family) with Intel Trust Authority (ITA) attestation is generally available.

Gemini Enterprise Agent Platform
Feature

Reinforcement learning fine-tuning in the Google Cloud console (Preview)

You can create, monitor, and test reinforcement learning fine-tuning jobs for Gemini models in the Google Cloud console (Preview). From the Models > Tuning page, you can configure Python code or model-based reward functions, test reward logic against sample prompts before launching a job, track training and evaluation metrics in real time, and test tuned checkpoints in Agent Studio.

For more information, see Quick start: Reinforcement learning fine-tuning using the console.

Google Cloud Contact Center as a Service
Announcement

Mobile SDKs 2.16.2

We've released version 2.16.2 of the mobile SDKs.

Feature

Chat check-in for the Mobile SDKs

Chat check-in is now available for the mobile SDKs. Chat check-in ensures that end-users are present and ready to engage before the system connects them to a human agent. This decreases the average agent handle time by eliminating the time lost when agents wait for end-users who have abandoned a chat.

For more information, see:

Feature

New "is typing" indicator in the Mobile SDKs

The mobile SDKs now display an "is typing" indicator to the end-user when an agent is typing.

Fixed

We've addressed the following issues.

Android and iOS SDKs:

  • Fixed an issue that occurred after force-closing a mobile app while the check-in timeout dialog was displayed. When the app was relaunched, the check-in dialog didn't reappear.

  • Fixed an issue where mobile inbound calls didn't connect.

iOS SDK only:

  • Fixed an issue where end-users received duplicate end-of-chat notifications when a virtual agent ended a conversation.

  • Fixed an issue where a virtual agent's final message appeared out of order during a chat escalation.

  • Fixed an issue where apps didn't upload logs when the server returned a relative URL.

Android SDK only:

  • Fixed an issue where a five-second delay occurred between session creation and the initial chat fetch, significantly delaying when the message appeared.
Google Distributed Cloud (software only) for VMware
Announcement

Google Distributed Cloud (software only) for VMware 1.33.1200-gke.83 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud 1.33.1200-gke.83 runs on Kubernetes v1.33.11-gke.100.

If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.

After a release, it takes approximately 7 to 14 days for the version to become available for use with GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

Fixed

The following issues were fixed in 1.33.1200-gke.83:

Google Distributed Cloud (software only) for bare metal
Announcement

Google Distributed Cloud (software only) for bare metal 1.33.1200-gke.83 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud for bare metal 1.33.1200-gke.83 runs on Kubernetes v1.33.11-gke.100.

After a release, it takes approximately 7 to 14 days for the version to become available for installations or upgrades with the GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.

Fixed

The following issues were fixed in 1.33.1200-gke.83:

Google SecOps
Feature

Grok filter match_all option in parser syntax

The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all non-overlapping pattern occurrences within a field, rather than returning only the first match.

For more information, see Parser syntax reference.

Google SecOps SIEM
Feature

Grok filter match_all option in parser syntax

The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all non-overlapping pattern occurrences within a field, rather than returning only the first match.

For more information, see Parser syntax reference.

NetApp Volumes
Announcement

Effective September 15, 2026, you can't create new Flex File storage pools, but existing pools remain supported. Support for the Flex File service level of Google Cloud NetApp Volumes ends on June 15, 2027. You must migrate your data from Flex File to the Flex Unified service level. For more information, see Migration to Flex Unified service level.

Policy Intelligence
Feature

Policy Troubleshooter now supports troubleshooting access for agent identities. You can troubleshoot IAM allow policies, deny policies, and principal access boundary policies for agents acting under their own authority by entering the agent's principal identifier or by troubleshooting with an error ID from an access denial event. To learn more, see Troubleshooting access.

September 14, 2026

Apigee hybrid
Announcement

hybrid v1.17.0

On September 14, 2026 we released an updated version of the Apigee hybrid software, 1.17.0.

Feature

Model Context Protocol (MCP) support

Apigee hybrid now supports Model Context Protocol (MCP), an open protocol that lets agentic AI applications use your APIs as tools through managed MCP endpoints. Apigee hybrid routes, authorizes, and secures these MCP tool calls the same way it manages your other APIs, so you don't need to run or maintain your own MCP servers.

MCP support is an optional feature that is not enabled by default. You must explicitly enable it in your Apigee hybrid configuration.

For more information, see Model Context Protocol (MCP) overview, Enable MCP for Apigee hybrid, and the MCP quickstart.

Feature

Root CA certificate rotation

Apigee hybrid v1.17.0 lets you rotate the root certificate authority (CA) certificate that anchors trust for TLS communication between your runtime components. You can now replace the root CA before it expires, without downtime.

For more information, see Rotate the root CA.

Feature

TLS 1.3 support

Apigee hybrid v1.17.0 adds support for TLS 1.3, a newer version of the Transport Layer Security (TLS) protocol that offers faster connection handshakes and stronger security than earlier TLS versions.

For information about configuring TLS on the ingress gateway, see Configuring TLS and mTLS on the Apigee ingress gateway.

Feature

Forward proxy support for AI policies

Apigee hybrid v1.17.0 adds forward proxy support for AI policies, such as the Model Armor and semantic caching policies. Outbound calls from these policies can now be routed through an HTTP forward proxy.

For more information, see Configure a forward proxy, Get started with the Model Armor policies, and Get started with semantic caching policies.

Feature

Semantic cache Private Service Connect (PSC) endpoint support

Apigee hybrid v1.17.0 adds Private Service Connect (PSC) endpoint support for semantic caching. The semantic caching policies can now reach their backing services over a Private Service Connect endpoint, which keeps that traffic on your private network.

For more information, see Configure semantic caching over Private Service Connect.

Feature

Semantic cache distance measure support

Apigee hybrid v1.17.0 adds support for non-default Vertex AI Vector Search distance measures in the SemanticCacheLookup policy. A new optional <DistanceMeasureType> element accepts DOT_PRODUCT_DISTANCE (the default, and the existing behavior), COSINE_DISTANCE, SQUARED_L2_DISTANCE, and L1_DISTANCE. The policy compares <Threshold> in the direction the declared measure implies, so declaring a non-default measure requires re-tuning the threshold in the same edit.

For more information, see SemanticCacheLookup policy.

Feature

Reduced service account permissions

Apigee hybrid v1.17.0 reduces the Google Cloud IAM permissions that Apigee service accounts require. Service accounts that use Cloud Storage now require only the storage.objects.get and storage.objects.create permissions rather than the broader Storage Admin (roles/storage.admin) role. The Cassandra components also no longer run with the privileged: true security context.

For more information about service accounts, see Create service accounts.

Security

Various security and CVE fixes are included in this release.

Backup and DR
Feature

You can now monitor restore jobs for Filestore instances directly from the Backup and DR Jobs page in the Google Cloud console. When you trigger a restore on a Filestore instance, Backup and DR automatically tracks the job progress and status.

For more information, see Restore a Filestore instance from a backup vault and Monitor backup and restore jobs in Google Cloud console.

BigQuery
Change

An updated version of the Simba ODBC driver for BigQuery is now available.

Feature

Metadata for BigQuery Graph is automatically ingested and searchable in Knowledge Catalog. This feature is available in preview.

Feature

You can now include a WHERE clause inside of an aggregate function call to filter your aggregate function input using a boolean expression. This feature is in Preview.

Bigtable
Feature

You can use the Google Cloud console to create, list, and query parameterized views for your Bigtable instances. You can also configure view parameters and run queries in Bigtable Studio. This feature is generally available (GA). For more information, see Create and manage parameterized views.

Cloud Logging
Feature

Starting with version 2.71.0, you can use an Ops Agent configuration option to export your metrics, logs, and traces by using the OpenTelemetry-based Telemetry API rather than by using the Cloud Monitoring API, Logging API, or Trace API For more information, see Use the Telemetry API.

Cloud Monitoring
Feature

Starting with version 2.71.0, you can use an Ops Agent configuration option to export your metrics, logs, and traces by using the OpenTelemetry-based Telemetry API rather than by using the Cloud Monitoring API, Logging API, or Trace API For more information, see Use the Telemetry API.

Cloud SQL for PostgreSQL
Feature

You can use the pg_textsearch extension in Cloud SQL for PostgreSQL to perform full-text search using the industry-standard BM25 (Best Matching 25) scoring algorithm for highly accurate relevance scoring.

This extension requires PostgreSQL 17 or later and is supported on PostgreSQL release R20260712.01_06 or later.

For more information, see Full-text search using pg_textsearch.

Cloud SQL for SQL Server
Deprecated

Beginning April 12, 2027, you won't be able to create new instances of Cloud SQL for SQL Server 2017. Starting on October 13, 2027, SQL Server 2017 will reach end of life (EOL) and Microsoft will stop releasing security updates. Cloud SQL for SQL Server will stop supporting SQL Server 2017 after this date.

For more information, see Database versions and version policies.

Cloud Workstations
Feature

Cloud Workstations supports customizing provisioned IOPS and throughput for Hyperdisk Balanced High Availability disks. This customization feature is in Preview.

Compute Engine
Feature

Preview: You can create regional disks, including Hyperdisk Balanced High Availability volumes, from custom and public OS images.

For more information, see Create and manage regional disks.

Gemini Enterprise Agent Platform
Deprecated

Gemini model deprecation and retirement date updates

The retirement and deprecation dates for the following Gemini models have been updated:

  • Gemini 2.5 Flash Image (gemini-2.5-flash-image): Deprecated and scheduled for retirement on March 15, 2027 (extended from October 2, 2026). Migrate to Gemini 3.1 Flash-Lite Image (gemini-3.1-flash-lite-image).
  • Gemini 3.1 Flash-Lite Image (gemini-3.1-flash-lite-image): Retirement date is scheduled for June 28, 2027 or later.

For more information, see Gemini model versions and lifecycle.

Fixed

CodeMender updates (v0.7.0)

This release introduces updates to CodeMender:

  • Network stream resilience: Improved CLI session stability with automatic reconnection and transient error recovery during long-running scans and remediation workflows.
  • Configuration uniformity: Standardized directory exclusion rules across configuration files and CLI scanning flags under scan_config.exclude_dirs.
  • Bug fixes:
    • Fixed an issue where cm report incorrectly categorized DISMISSED findings as OPEN in the summary table.
    • Resolved sandbox permission denial errors by preventing child worker processes from attempting to create internal session logs on disk.
    • Hardened sandbox command policy to prevent directory traversal and file inspection outside the designated repository root into adjacent directories.

For more information, see CodeMender documentation.

Feature

Cyber Verification Program for Claude is available in Preview

Anthropic's Cyber Verification Program (CVP) is available in Preview on Gemini Enterprise Agent Platform. CVP enables verified organizations to use supported Claude models (Claude Opus 4.7, Claude Opus 4.8, Claude Sonnet 5, and Claude Opus 5) for legitimate defensive cybersecurity tasks with default dual-use restrictions lifted.

For more information, see Cyber Verification Program for Claude.

Google SecOps
Feature

[Spotlight Feature] GoogleSQL query support in Search

This feature is in public preview. You can now use GoogleSQL in Search to query your security data in Google SecOps, offering a flexible and powerful industry-standard alternative to YARA-L 2.0. GoogleSQL is optimized for broad data exploration, statistical aggregation, and deep-dive ad hoc investigations. You can query telemetry tables including but not limited to UDM events, entity graphs, detection rules, and case management data—using either standard declarative SQL or the linear, sequential Piped SQL syntax.

For more information, see Get started with GoogleSQL.

Deprecated

MANDIANT_ACTIVE_BREACH_IOC,MANDIANT_FUSION_IOC, andOPEN_SOURCE_INTEL_IOC` feeds are being removed

The MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds are deprecated in favor of the GTI_IOC feed. After March 18, 2027, we will be removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds. For more information on how to migrate, see Migrate Mandiant legacy feeds to GTI.

Google SecOps SIEM
Deprecated

MANDIANT_ACTIVE_BREACH_IOC,MANDIANT_FUSION_IOC, andOPEN_SOURCE_INTEL_IOC` feeds are being removed

The MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds are deprecated in favor of the GTI_IOC feed. After March 18, 2027, we will be removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds. For more information on how to migrate, see Migrate Mandiant legacy feeds to GTI.

Knowledge Catalog
Feature

Metadata for BigQuery Graph is now automatically ingested and searchable in Knowledge Catalog. This feature is available in preview.

For more information, see Knowledge Catalog overview.

Network Intelligence Center
Feature

When adding a new Google Cloud Compute Engine, container, or VM Monitoring Point, Cloud Network Insights lets you generate Google Cloud CLI commands in the Google Cloud console to download Monitoring Point installation bundles.

Secret Manager
Feature

Parameter Manager supports CRC32C checksums to verify data integrity when you add or access parameter versions.

For more information, see Data integrity assurance.

Security Command Center
Deprecated

Data Security Posture Management is deprecated. It will be shut down on February 1, 2027. Learn more about the controls and alternative detection capabilities.

Vertex AI Search
Feature

Agent Search: Search query add-ons for configurable pricing (GA)

Search query add-on specifications (searchAddonSpec) for configurable pricing are generally available (GA) in the v1 API. You can use searchAddonSpec when you want to save money by turning off add-ons for individual search requests made programmatically.

For more information, see About controlling which add-ons apply to a search request and REST, per search request in Manage configurable pricing for search query add-ons.

September 13, 2026

Agent Platform Workbench
Change

20260911.00_p0 Release

Change

20260913.00_p0 Release

Change

Installed latest packages from upstream dependencies.

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

Change

20260913-2230-rc0 Release

Change

20260913-2230-rc0 Release

Change

Installed latest packages from upstream dependencies.

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed an issue where the notebook-disable-nbconvert metadata flag was ignored in custom containers.

Change

The obsolete google-cloud-sdk transitional package is no longer installed. The Google Cloud CLI itself is unchanged; it was already provided by the google-cloud-cli package.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

Fixed

Fixed an issue where the notebook-disable-nbconvert metadata flag was ignored in custom containers.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

Change

20260913-2130-rc0 Release

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

Change

M149 Release

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed the %%bigquery notebook cell magic, which returned an error instead of query results in JupyterLab 4.

September 11, 2026

API Gateway
Feature

Enable Model Context Protocol (MCP)

You can now configure API Gateway to act as a remote Model Context Protocol (MCP) server. This Public Preview feature allows you to expose your existing REST APIs to AI agents as tools, without requiring changes to your backend services. You can enable MCP by annotating your OpenAPI 3.x specification using custom Google extensions.

For more information, see Model Context Protocol overview and Configure Model Context Protocol.

AlloyDB for PostgreSQL
Feature

You can now monitor the status, throughput, and backlog of the audit logging pipeline for your AlloyDB for PostgreSQL instances and nodes using Cloud Monitoring.

For more information, see Monitor audit log pipeline status.

Cluster Toolkit
Security

Google addressed multiple security vulnerabilities in Slurm that affect Cluster Toolkit. For more information, see the security bulletin.

Compute Engine
Feature

Preview: You can view Workload Manager rule findings directly on the Compute Engine Overview page in the Google Cloud console. The Workload Manager findings tile lets you identify configuration risks for your compute instances and resources against best practices for reliability and security.

For more information, see View Workload Manager rule findings in Compute Engine.

Google Cloud Contact Center as a Service
Announcement

Google Cloud CCaaS 6.12

We've released version 6.12 of Google Cloud CCaaS.

The timing of the update to your instance depends on the deployment schedule that you have chosen. For more information, see Deployment schedules.

Feature

Cold transfers auto-resume

When an agent performs a cold transfer, the call now resumes at the moment the receiving agent answers the call. The receiving agent no longer needs to manually take the caller off hold. This eliminates the silence that previously occurred between an agent answering a call and taking the caller off hold.

For more information, see Cold transfers.

Feature

Hubspot: Configure Do Not Call by phone number

In HubSpot integrations, you can now configure Do Not Call for specific phone numbers instead of for an entire contact or company record. Opt-out matching is no longer case-sensitive.

Administrators: There's a new Do Not Call Configuration section in the CRM pane, located at Settings > Developer Settings (with HubSpot selected).

For more information, see Configure Do Not Call for HubSpot.

Feature

Agent desktop: New network diagnostics tool

The agent desktop has a new network diagnostics tool in the navigation menu that displays network strength and diagnostics information. This tool can help you quickly assess your network's health and troubleshoot connection issues.

For more information, see Get network diagnostic information.

Feature

Agent desktop: Open from the CCaaS portal

You can now access the Agent Desktop using the new Apps menu. In the CCaaS portal, click Apps > Agent Desktop to open the Agent Desktop in a new browser tab. This lets you move between the portal and the Agent Desktop without ending your portal session.

For more information, see Open the agent desktop.

Fixed

This release addresses the following issues:

  • Fixed an issue where SmartAction statuses were incorrectly marked as "failed" when a call ended before a photo or video upload completed.

  • Fixed an issue where loading the outbound numbers list timed out or caused significant delays for organizations with large teams and custom roles.

  • Fixed an issue where estimated wait times of less than one minute were incorrectly rounded down to zero, preventing the system from accurately triggering over-capacity actions.

  • Fixed an issue where sudden spikes in call volume bypassed a team's capacity protections and reduced the team's agent availability to below configured minimums.

  • Fixed an issue where nested object values in custom data were incorrectly displayed as [object Object] in the agent desktop session data feed.

  • Fixed an agent desktop issue where the navigation bar in the Previous Interactions page of the call adapter was overlapped by summary text and didn't stay fixed while scrolling.

  • Fixed an issue where answered voice calls triggered a second, unrequested callback after the end-user hung up.

  • Fixed an issue where intermittent IMAP connection rejections caused email fetch workers to enter an extended backoff loop, resulting in several hours of mailbox downtime.

  • Fixed an issue where inbound voice call recordings weren't exported to external storage when a virtual agent escalation was deflected to voicemail due to over-capacity.

  • Fixed an issue where manual wrap-up sessions were incorrectly attributed to the most recent call in the Agent Activity Timeline and in raw data exports, even when the wrap-up was unrelated to that call.

  • Fixed an issue where the "agent leg" of a call connection stalled in a connecting state for the full timeout duration before failing silently and moving the agent to an available status.

  • Fixed an issue where custom form responses weren't exported to external storage for instances without an external CRM integration.

  • Fixed an issue where a queue name saved in the SLA thresholds for queues dialog didn't persist after saving.

  • Fixed an issue where virtual agent voice calls triggered a session error during wrap-up.

  • Fixed an issue during high-capacity redirections where voicemails weren't saved.

  • Fixed an issue where completed call transfers generated duplicate queue duration records, leading to inflated reporting for queue volume and SLA metrics.

  • Fixed an agent desktop issue where the sentiment banner in the call adapter didn't immediately appear at the start of a call.

  • Fixed an issue where saving the Upload audio recording for Language Selection option of the Languages dialog didn't persist and switched to Text-to-speech.

  • Fixed an issue where inefficient database queries caused high CPU utilization and performance degradation across all communication channels.

  • Fixed an issue where transient connection errors during Twilio ICE token fetching caused agent call setup to fail or take longer to connect.

  • Fixed an issue where temporary connection drops during chat webhook delivery caused unnecessary delays.

  • Fixed an issue where work time and wait time durations overlapped in reporting metrics.

  • Fixed an issue where the agent adapter call history incorrectly displayed English queue names for French-Canadian calls.

  • Fixed an issue where agents were assigned calls from secondary queues even when their primary queue fell below the minimum availability threshold.

  • Fixed an issue where canceled virtual-agent-to-human escalations incorrectly reported negative queue durations and inaccurate SLA metrics in chat session data and reports.

  • Fixed an issue where creating or updating queues failed and returned a timeout error.

  • Fixed an agent desktop issue where an outbound call canceled by an agent while connecting was recorded as an unknown failure instead of an agent cancellation.

  • Fixed an issue where clicking the rewind and forward buttons on the voicemail page of the call adapter restarted the voicemail from the beginning.

  • Fixed an agent desktop issue where the chat adapter displayed a loading progress indicator instead of the chat transcript when a chat session was assigned.

  • Fixed an issue where a disposition prompt didn't appear in the call adapter after a disconnected call, even when mandatory disposition was configured.

  • Fixed an issue where Agent Assist real-time transcription didn't start on Vonage BYOC calls.

  • Fixed an issue where changes made outside of browser-originated HTTP requests (such as from API clients or background jobs) failed to generate audit log records.

  • Fixed an issue where over-capacity phone deflection didn't activate for direct agent calls, resulting in an error message or callers waiting indefinitely.

  • Fixed an issue where transient network connection failures during call and chat DAP lookups caused inbound calls to route to default queues or prevented chat sessions from starting.

  • Fixed a web SDK issue where static, non-interactive text within the chat widget incorrectly received keyboard focus, disrupting the navigation flow for keyboard and screen reader users.

  • Fixed an issue where temporary asset errors during deployments were cached by the CDN, leading to web SDK initialization failures.

  • Fixed an agent desktop issue where incomplete configuration settings prevented call control buttons from updating or rendering properly.

  • Fixed an issue where the audio for an over-capacity deflection played in the source queue's language instead of the destination queue's language following a cross-language transfer.

  • Fixed an issue where waiting chats weren't immediately offered to available agents who became eligible for a queue through a team membership update or direct queue assignment.

Google Kubernetes Engine
Feature

Agent Substrate on GKE is now available for evaluation and non-production use. Production support is offered on an allowlist basis under a limited GA program.

Agent Substrate runs agentic workloads at scale on GKE clusters. To reduce resource usage, Agent Substrate suspends idle agents and takes a snapshot of the agent's active memory (RAM) and local files. When a suspended agent is triggered, the system restores the agent's state onto an available sandbox with sub-second latency.

Agent Substrate improves on the capabilities of Agent Sandbox by bypassing the bottlenecks of the standard Kubernetes control plane to run significantly more concurrent agents per machine.

For more information, see About GKE Substrate.

Google SecOps
Deprecated

Deprecation of write permissions from the chronicle.readonly OAuth scope

Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it strictly to read operations. You can continue using chronicle.readonly for read operations. Make sure you update any workflows performing write operations to use the chronicle OAuth scope.

Google SecOps SIEM
Deprecated

Deprecation of write permissions from the chronicle.readonly OAuth scope

Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it strictly to read operations. You can continue using chronicle.readonly for read operations. Make sure you update any workflows performing write operations to use the chronicle OAuth scope.

Spanner
Feature

Spanner Graph supports the following enhancements for CREATE PROPERTY GRAPH:

  • Semantic options for labels and properties: You can configure OPTIONS (description and synonyms) on labels and properties to provide context and improve discoverability for natural language querying interfaces.
  • Element key uniqueness validation option: You can configure the validate_element_key_uniqueness option in the property graph OPTIONS clause to control whether Spanner Graph validates element key uniqueness at schema creation time.

For more information, see CREATE PROPERTY GRAPH statement and Disabled key validation.

September 10, 2026

Apigee X
Fixed

Addendum to Apigee release notes dated August 27, 2026 (1-18-0-apigee-4).

Bug ID Description
502540992 Fixed an issue where the SemanticCacheLookup policy was incompatible with Vertex AI Vector Search Private Service Connect (PSC) endpoints.
BigQuery
Feature

Conversational analytics in BigQuery now supports the ML.CORRELATION function to calculate statistical correlations between a target column and one or more metric columns in a table. This feature is in Preview.

Feature

You can now use the ML.METRICS function to compute evaluation metrics for machine learning classification or regression tasks on any table or query that contains actual and predicted values. This function lets you evaluate predictions without needing to create or reference a stored model. This feature is in Preview.

Feature

You can use the AI.CAUSAL_EFFECT function to quantify the impact of specific interventions on time series data. This feature is in Preview.

Feature

The Data Engineering Agent now integrates with BigQuery Graph to provide additional context between your data source and destination schema, and improves schema mapping accuracy for your data engineering pipelines.

This feature is generally available (GA).

Cloud SQL for MySQL
Breaking

Appending sqlcommenter tags using the sql_commenter_enabled parameter when executing SQL queries on a Cloud SQL remote MCP server is temporarily disabled.

For more information, see sqlcommenter tags.

Cloud SQL for PostgreSQL
Breaking

Appending sqlcommenter tags using the sql_commenter_enabled parameter when executing SQL queries on a Cloud SQL remote MCP server is temporarily disabled.

For more information, see sqlcommenter tags.

Cloud Storage
Feature

Storage Intelligence advisor is now generally available. Storage Intelligence advisor lets you monitor and manage your Cloud Storage environment at scale across organizations, folders, and projects. For more information, see About Storage Intelligence advisor.

Gemini Enterprise
Feature

Gemini Enterprise: Pay-as-you-go edition and AI developer tools available for all invoiced Cloud Billing accounts

Subscribing to the Gemini Enterprise Pay-as-you-go edition and accessing AI developer tools is available to all projects linked to an invoiced Cloud Billing account. Previously, only customers who received an email with the subject line [Billing Update] New Gemini Enterprise overage billing controls launching Aug 17, 2026 could access AI developer tools. This restriction no longer applies.

For more information, see:

Feature

Gemini Enterprise: Support for channel mentions and multi-turn conversations in the Gemini Enterprise app for Slack

The Gemini Enterprise app for Slack has the following new capabilities:

  • Channel mentions: You can @mention the Gemini Enterprise app directly in Slack channels and conversational threads. The app returns responses privately so you can review them before choosing to share.
  • Multi-turn conversations: The Gemini Enterprise app remembers the context of your current session in direct messages. You can ask follow-up questions and refine previous responses. You can clear the context and start over by clicking New chat.

To enable these features, your Slack administrator must reinstall the Gemini Enterprise app. For more information, see Install the Gemini Enterprise app for Slack in your Slack workspace. After the administrator reinstalls the app, end users must authorize the Slack connector. For more information, see User authorization. If you don't reinstall and re-authorize the Gemini Enterprise app, your Slack workspace retains the legacy experience.

These features are generally available (GA). For more information, see Configure the Gemini Enterprise app for Slack.

Gemini Enterprise Agent Platform
Feature

Provisioned Throughput: Support for multiple pending orders and change requests

Provisioned Throughput now directly supports from the self service console the ability to schedule multiple new orders at the same time and change requests across multiple orders within the same project.

For more information, see Purchase Provisioned Throughput.

Google Cloud Managed Service for Apache Kafka
Feature

You can configure a Managed Service for Apache Kafka cluster as a public cluster to let client applications connect over the public internet. For more information, see Connect clients to a public cluster.

Identity and Access Management
Feature

The Identity and Access Management (IAM) Model Context Protocol (MCP) server is generally available. You can connect to the IAM remote MCP server from AI applications to inspect and manage custom roles and deny policies across your resources.

For more information, see the following documentation:

Looker
Feature

The Looker extension for VS Code is now generally available, enabling local LookML development and AI-assisted "vibe coding" using the Model Context Protocol (MCP). This update introduces an interactive onboarding walkthrough, support for populating workspaces from bare repositories, and enhanced synchronization between local Git branches and Looker Development Mode. Additional improvements include support for OAuth with the Kiro IDE and more secure storage of API client secrets.

Network Connectivity Center
Feature

Support for global Google APIs for endpoint propagation through Network Connectivity Center is available in Preview.

For information about the new quota for propagated global Google APIs, see NCC quotas.

Virtual Private Cloud
Feature

Preview: Propagated connections support Private Service Connect endpoints that access global Google APIs. With propagated connections, endpoints that access global Google APIs in one consumer VPC spoke can be privately accessed by other consumer VPC spokes that are connected to the same Network Connectivity Center hub.

September 09, 2026

Apigee X
Feature

SemanticCacheLookup policy supports non-default Vector Search distance measures

Available in Apigee 1-18-0-apigee-4 and later. A new optional <DistanceMeasureType> element accepts DOT_PRODUCT_DISTANCE (the default, and the existing behavior), COSINE_DISTANCE, SQUARED_L2_DISTANCE and L1_DISTANCE. The policy now compares <Threshold> in the direction the declared measure implies, so declaring a non-default measure requires re-tuning the threshold in the same edit. The 0-to-1 restriction on <Threshold> is also removed.

BigQuery
Feature

BigQuery generative AI functions now support the following Gemini models:

  • gemini-3.5-flash-lite
  • gemini-3.6-flash
  • gemini-3.7-flash
Cloud Monitoring
Feature

A chart on a dashboard can override the dashboard's time-range setting. This feature lets you view trends over a long period or metric data with low sampling rates alongside charts that show only recent data, and is Generally Available (GA).

For more information, see the following documents:

Gemini Enterprise
Breaking

Gemini Notebook Enterprise: Website URL ingestion blocked by VPC Service Controls

Projects with VPC Service Controls enabled can't add website URLs as notebook sources in Gemini Notebook Enterprise.

This is because direct website ingestion performs a live web crawl, generating outbound traffic beyond Google networks, which would violate VPC Service Controls perimeter policies.

Other source types, such as Google Docs and YouTube URLs, remain supported in projects with VPC Service Controls enabled.

Gemini Enterprise Agent Platform
Feature

Computer Use and Shell sandboxes are generally available

Computer Use and Shell sandboxes in Gemini Enterprise Agent Platform are now generally available (GA). This release also includes the following new features for Agent Platform sandboxes:

  • Shell sandboxes: Run untrusted shell commands, install packages, and manipulate files in an isolated Linux container using direct API /exec calls. For more information, see the Shell sandbox quickstart.

  • VPC Service Controls & Private Service Connect: Protect sandbox data and isolate network boundaries with VPC Service Controls, private ingress endpoints (PSC-E), and private egress routing (PSC-I). For more information, see Configure VPC Service Controls and Private Service Connect with sandboxes.

  • Customer-Managed Encryption Keys (CMEK): Protect sandbox data at rest, including disk storage and snapshot checkpoints, using Cloud KMS keys. For more information, see Configure customer-managed encryption keys (CMEK) for sandboxes.

  • Pausing and resuming sandboxes: Deschedule compute resources for idle sandboxes while preserving file system state and connection identity, and resume them in seconds. For more information, see Manage sandboxes.

Feature

Priority PayGo now supports the US and EU multi-region endpoints

You can send Priority PayGo requests to the us and eu multi-region endpoints, in addition to the global endpoint.

For more information, see Priority PayGo.

Feature

Agent Gateway supports multiple Agent Registry instances

Agent Gateway now lets you associate up to two Agent Registry instances (one global registry and one regional or multi-region registry) with a single Agent Gateway instance. For more information, see Register your agents and destination resources.

Feature

Agent Gateway supports VPC Service Controls

Agent Gateway now enforces VPC Service Controls perimeter rules for agent communications. When you configure Agent Gateway with VPC connectivity, agent traffic is routed through your private VPC network, ensuring that your organization's VPC-SC perimeter rules are applied to all agent traffic as well.

Note that setting up VPC connectivity is required to enable VPC Service Controls perimeter enforcement for Agent Gateway deployments. The connectivity template must be configured in ALL_TRAFFIC egress mode.

Google SecOps Marketplace
Feature

Google Chronicle: Version 95.0

  • The following new action has been added:

    • Is Value In Data Table Async
Change

Microsoft 365 Defender: Version 31.0

  • Updated alert tracking logic, extracted alert object metadata, and improved the pagination and timeout handling mechanism in the following connector:

    • Microsoft 365 Defender - Incidents Connector
Change

Google Chronicle: Version 95.0

  • Integration: Improved OAuth 2.0/JWT authentication logging, validation diagnostics, and error messaging.
Change

Trend Vision One: Version 12.0

  • Made the Description parameter mandatory in the following actions:

    • Isolate Endpoint

    • Unisolate Endpoint

Identity and Access Management
Feature

You can get IAM role suggestions from Gemini programmatically by using the Policy Assist API (Preview).

For more information, see the following documentation:

Looker
Deprecated

The deprecation of the Looker Mobile (Legacy) application has been postponed to January 31, 2027. Starting on January 31, 2027, support for the Looker Mobile (Legacy) app will be discontinued and the app will be unavailable for download from the App Store or Play Store. Although users will still be able to use the Looker Mobile (Legacy) app if they already have it installed, we recommend that you install the non-legacy Looker mobile app.

NetApp Volumes
Announcement

Google Cloud NetApp Volumes now supports the Flex Unified service level in the following regions:

  • asia-east1 (Taiwan)

  • australia-southeast2 (Melbourne)

  • europe-southwest1 (Madrid)

For more information about available regions, see Supported regions.

Network Intelligence Center
Feature

You can deploy Monitoring Points optimized for Amazon Web Services (AWS) or Microsoft Azure cloud infrastructure from Cloud Network Insights.

Policy Intelligence
Feature

The Policy Assist remote MCP server is available in Preview. To learn about using the Policy Assist remote MCP server to let external AI agents and applications suggest IAM roles, see Use the Policy Assist remote MCP server and the Policy Assist MCP reference.

Feature

The Policy Assist REST API is available in Preview. Policy Assist lets you get IAM role suggestions for individual principals with AI assistance.

To learn about using the Policy Assist API to get role suggestions programmatically, see the Policy Assist REST reference.

September 08, 2026

Agent Platform Workbench
Fixed

Scheduled upgrade metadata is validated

The value of the notebook-upgrade-schedule metadata key is now validated when you create or update an Agent Platform Workbench instance. The value must be a single-line unix-cron format schedule. For more information, see Manage features through metadata.

Assured Workloads
Feature

The EU Data Boundary with Access Justifications supports the following products:

  • AlloyDB for PostgreSQL
  • Apigee
  • Eventarc
BigQuery
Feature

Conversational analytics now supports predictive modeling questions using the AI.PREDICT function. This feature is in Preview.

Cloud Run
Feature

To take advantage of reduced pricing for Cloud Run jobs, you can delay job execution to defer non-urgent tasks for up to 12 hours (Preview).

Cloud SQL for MySQL
Feature

Regional endpoints (REP) are now generally available (GA) for the Cloud SQL for MySQL Admin API.

Regional endpoints let you interact with Cloud SQL for MySQL instances using regionalized URLs (such as sqladmin.{region}.rep.googleapis.com) rather than through a single global endpoint.

Regional endpoints provide regional frontend and load balancing infrastructure that improves data residency by keeping network traffic within the same region as the instance. This reduces the instance's dependency on global frontend infrastructure.

Regional endpoints have strong regional isolation, so the failure of a load balancer or frontend in one region doesn't affect any other region. Regional service load balancers have a separate, regionally isolated control plane.

Regional endpoints are designed to meet stringent data residency and sovereignty standards, such as ITAR and Assured Workloads Regions, ensuring data in transit remains within the committed region.

Certificate management and TLS termination occurs within each region, on the regional load balancer, so data remains encrypted until it reaches its destination region and stays within that region while being processed there.

Cloud SQL for PostgreSQL
Feature

Regional endpoints (REP) are now generally available (GA) for the Cloud SQL for PostgreSQL Admin API.

Regional endpoints let you interact with Cloud SQL for PostgreSQL instances using regionalized URLs (such as sqladmin.{region}.rep.googleapis.com) rather than through a single global endpoint.

Regional endpoints provide regional frontend and load balancing infrastructure that improves data residency by keeping network traffic within the same region as the instance. This reduces the instance's dependency on global frontend infrastructure.

Regional endpoints have strong regional isolation, so the failure of a load balancer or frontend in one region doesn't affect any other region. Regional service load balancers have a separate, regionally isolated control plane.

Regional endpoints are designed to meet stringent data residency and sovereignty standards, such as ITAR and Assured Workloads Regions, ensuring data in transit remains within the committed region.

Certificate management and TLS termination occurs within each region, on the regional load balancer, so data remains encrypted until it reaches its destination region and stays within that region while being processed there.

Cloud SQL for SQL Server
Feature

Regional endpoints (REP) are now generally available (GA) for the Cloud SQL for SQL Server Admin API.

Regional endpoints let you interact with Cloud SQL for SQL Server instances using regionalized URLs (such as sqladmin.{region}.rep.googleapis.com) rather than through a single global endpoint.

Regional endpoints provide regional frontend and load balancing infrastructure that improves data residency by keeping network traffic within the same region as the instance. This reduces the instance's dependency on global frontend infrastructure.

Regional endpoints have strong regional isolation, so the failure of a load balancer or frontend in one region doesn't affect any other region. Regional service load balancers have a separate, regionally isolated control plane.

Regional endpoints are designed to meet stringent data residency and sovereignty standards, such as ITAR and Assured Workloads Regions, ensuring data in transit remains within the committed region.

Certificate management and TLS termination occurs within each region, on the regional load balancer, so data remains encrypted until it reaches its destination region and stays within that region while being processed there.

Cloud Trace
Feature

The Observability API supports VPC Service Controls. This integration is generally available.

For more information, see the following:

Compute Engine
Feature

Generally available: You can convert a single-project reservation into a shared reservation, or a shared reservation into a single-project reservation. Modify the share type for a reservation to share your reserved resources with other projects in your Google Cloud organization, or to restrict access to only the reservation's owner project. For more information, see Modify the share type for a reservation.

Config Connector
Announcement

Config Connector version 1.156.0 is now available.

Feature

New Alpha Resources (Direct Reconciler):

Feature

New Fields:

Feature

New Features:

  • Optional NAT IP Allocate Option: Made natIpAllocateOption an optional field in ComputeRouterNat to support dynamic allocation.
  • Preview Summary CLI Improvements: Added namespace and current status to the preview summary report.
Change

Reconciliation Improvements:

We have added support for direct reconciliation to more resources, with opt-in behavior. The API is unchanged. To use the direct reconciler, add the alpha.cnrm.cloud.google.com/reconciler: direct annotation to the corresponding Config Connector object. The following resources now have direct reconciliation support:

  • VertexAITensorboard
    • Support direct reconciliation (opt-in).
Container Optimized OS
Change

cos-beta-133-19999-44-28

Kernel Docker Containerd GPU Drivers
COS-6.18.48 v29.4.3 v2.3.4 See List
Change

cos-129-19506-448-20

Kernel Docker Containerd GPU Drivers
COS-6.12.105 v27.5.1 v2.2.7 See List
Change

cos-dev-138-20098-0-0

Kernel Docker Containerd GPU Drivers
COS-6.18.49 v29.4.3 v2.3.2 See List
Change

Updated containerd and containerd-test to v2.3.4.

Fixed

Updated the Linux kernel to v6.18.48.

Fixed

Fixed CVE-2026-33186 in app-containers/docker.

Change

Updated the Linux kernel to v6.18.48.

Fixed

Fixed docker cp failure when copying to/from containers with symlinked bind mounts.

Change

Updated the Linux kernel to v6.18.49.

Fixed

Fixed CVE-2026-33186 in app-admin/extensions-manager.

Fixed

Updated sys-devel/binutils to v2.40.

Fixed

Fixed CVE-2026-33186 in app-admin/google-osconfig-agent.

Security

Update dev-go/net to v0.55.0 to fix CVE-2026-25680.

Fixed

Fixed CVE-2026-33186 in app-admin/node-problem-detector.

Fixed

Fixed CVE-2026-33186 in app-containers/containerd.

Fixed

Fixed CVE-2026-33186 in app-emulation/kubernetes.

Fixed

Upgraded app-containers/docker-credential-helpers to v0.9.9.

Fixed

Upgraded dev-db/sqlite to v3.53.4.

Fixed

Upgraded dev-libs/expat to v2.8.4.

Fixed

Upgraded dev-libs/xxhash to v0.8.3-r2.

Fixed

Upgraded net-libs/libnftnl to v1.2.9.

Fixed

Fixed CVE-2026-6238 in sys-libs/glibc.

Security

Updated dev-go/net to v0.55.0 to fix CVE-2026-25680.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068

Change

cos-117-18613-731-6

Kernel Docker Containerd GPU Drivers
COS-6.6.153 v24.0.9 v1.7.34 See List
Fixed

Fixed docker cp failure when copying to/from containers with symlinked bind mounts.

Fixed

Upgraded app-admin/google-guest-configs to v20260819.00.

Fixed

Upgraded app-arch/zstd to v1.5.7-r1.

Fixed

Upgraded app-containers/docker-credential-helpers to v0.9.9.

Fixed

Upgraded app-shells/dash to v0.5.13.5.

Fixed

Upgraded dev-db/sqlite to v3.53.4.

Fixed

Upgraded dev-libs/expat to v2.8.3.

Fixed

Upgraded dev-libs/libverto to v0.3.2-r1.

Fixed

Upgraded dev-libs/popt to v1.19-r1.

Fixed

Upgraded dev-libs/xxhash to v0.8.3-r2.

Fixed

Upgraded net-libs/libnftnl to v1.2.9.

Fixed

Upgraded sys-apps/acl to v2.4.0-r2.

Fixed

Upgraded sys-auth/passwdqc to v2.0.3-r1.

Fixed

Upgraded sys-process/lsof to v4.99.7.

Security

Fixed CVE-2026-6238 in sys-libs/glibc.

Security

Updated dev-go/net to v0.55.0 to fix CVE-2026-25680.

Change

cos-121-18867-584-7

Kernel Docker Containerd GPU Drivers
COS-6.6.153 v27.5.1 v2.0.10 See List
Fixed

Fixed docker cp failure when copying to/from containers with symlinked bind mounts.

Fixed

Upgraded app-admin/google-guest-configs to v20260819.00.

Fixed

Upgraded app-containers/docker-credential-helpers to v0.9.9.

Fixed

Upgraded dev-db/sqlite to v3.53.4.

Fixed

Upgraded net-libs/libnftnl to v1.2.9.

Fixed

Upgraded sys-auth/passwdqc to v2.0.3-r1.

Security

Fixed CVE-2026-6238 in sys-libs/glibc.

Security

Updated dev-go/net to v0.55.0 to fix CVE-2026-25680.

Change

cos-125-19216-655-12

Kernel Docker Containerd GPU Drivers
COS-6.12.105 v27.5.1 v2.2.7 See List
Fixed

Added support for NVIDIA driver v595.91.07.

Fixed

Fixed docker cp failure when copying to/from containers with symlinked bind mounts.

Fixed

Upgraded dev-db/sqlite to v3.53.4.

Security

Fixed CVE-2026-6238 in sys-libs/glibc.

Security

Updated dev-go/net to v0.55.0 to fix CVE-2026-25680.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068

Gemini Enterprise
Feature

Gemini Enterprise: Semantic search support in Google Cloud Marketplace (Preview)

The agent search in Google Cloud Marketplace now supports semantic search, allowing you to find agents by describing their functionality (for example, "generate reports" or "translate text") without needing exact keyword matches.

For more information, see Add and manage A2A agents from Google Cloud Marketplace.

Gemini Enterprise Agent Platform
Feature

Agent connectivity templates for VPC connectivity in Agent Gateway

Agent Gateway now uses agent connectivity templates (agentConnectivityTemplate) to configure and manage egress connectivity to VPC networks. Connectivity templates let you choose whether to route all outbound agent traffic (ALL_TRAFFIC) or only traffic to certain private IP address ranges (PRIVATE_RANGES_ONLY) into your VPC network. For more information, see Set up VPC connectivity for Agent Gateway.

Google Kubernetes Engine
Change

(2026-R38) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

  • Version 1.35.7-gke.1222000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1106000
    • 1.35.7-gke.1150000
    • 1.36.3-gke.1537000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • Version 1.34.10-gke.1106000 is now available in the Stable channel.
  • Version 1.34.10-gke.1079000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.

Extended channel

  • Version 1.35.7-gke.1222000 is now the default version for cluster creation in the Extended channel.
  • The following versions are now available in the Extended channel:
  • The following versions are no longer available in the Extended channel:
    • 1.31.14-gke.2667000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.2393000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.13-gke.1613000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.10-gke.1106000
    • 1.35.7-gke.1150000
    • 1.36.3-gke.1537000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

No channel (deprecated)

Security

(2026-R38) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2689000 cos-117-18613-731-2 cos-117-18613-731-2 release notes
1.36.4-gke.1247000 cos-129-19506-448-8 cos-129-19506-448-8 release notes
1.37.0-gke.3165000 cos-129-19506-299-82 cos-129-19506-299-82 release notes

Change

(2026-R38) Version updates

  • Version 1.34.10-gke.1106000 is now available in the Stable channel.
  • Version 1.34.10-gke.1079000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
Change

(2026-R38) Version updates

  • Version 1.35.7-gke.1222000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1106000
    • 1.35.7-gke.1150000
    • 1.36.3-gke.1537000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Change

(2026-R38) Version updates

Change

(2026-R38) Version updates

Change

(2026-R38) Version updates

  • Version 1.35.7-gke.1222000 is now the default version for cluster creation in the Extended channel.
  • The following versions are now available in the Extended channel:
  • The following versions are no longer available in the Extended channel:
    • 1.31.14-gke.2667000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.2393000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.13-gke.1613000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.10-gke.1106000
    • 1.35.7-gke.1150000
    • 1.36.3-gke.1537000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Secret Manager
Feature

Parameter Manager supports using tags to group and organize parameters and conditionally manage access control using Identity and Access Management (IAM) policies.

For more information, see Create and manage tags.

Sovereign Controls by Partners
Feature

The France Data Boundary by S3NS supports the following products:

  • AlloyDB for PostgreSQL
  • Apigee
  • Eventarc
Feature

The Italy Data Boundary by PSN supports the following products:

  • AlloyDB for PostgreSQL
  • Apigee
  • Eventarc
Feature

The Germany Data Boundary by T-Systems supports the following products:

  • AlloyDB for PostgreSQL
  • Apigee
  • Eventarc
VPC Service Controls
Feature

General availability support for the following integration:

September 07, 2026

AI Hypercomputer
Security

Google addressed a security vulnerability (CVE-2026-65107) that affects Slurm clusters. Based on the Google Cloud product that you used to create your Slurm cluster, see one of the following to mitigate the vulnerability:

Access Approval
Feature

Privileged Access Manager is generally available (GA).

Access Transparency
Feature

Privileged Access Manager is generally available (GA).

Cluster Toolkit
Feature

Cluster Toolkit version v1.103.0 is available. This release simplifies the gcluster job configuration workflow, adds dynamic catalog fallback for system node pools, increases the maximum system node pool limit to 150 nodes, and replaces deprecated e2 instances with n2d across daily tests and configurations. This release also upgrades Slurm to version 25.11.8 to address multiple security vulnerabilities. For more information about the vulnerabilities, see the security bulletin and the release announcement on GitHub.

Security

Google addressed a security vulnerability (CVE-2026-65107) in the Slurm sbcast tool that affects Cluster Toolkit. For more information, see the security bulletin.

Knowledge Catalog
Feature

Data domains in Knowledge Catalog allow you to logically organize the resources within the enterprise to discover and curate your data at scale. This feature is available in Preview.

For more information, see About data domains.

September 06, 2026

Google SecOps
Feature

[Spotlight Feature] Case playbooks

This feature is in preview. Google SecOps now supports case playbooks. You can run playbooks or execute manual actions across an entire case container rather than individual alerts, consolidating response tasks and reducing redundant operations during investigations.

For more information, see Case playbooks overview.

Feature

[Spotlight Feature] Reaction triggers

This feature is in preview. Google SecOps now supports reaction triggers. As post-ingestion triggers, they allow playbooks to automatically fire in response to real-time case or alert updates during active investigations, such as changes to the case assignee, case tags, alert priority, or newly added entities.

For more information, see Use reaction triggers in playbooks.

Google SecOps SOAR
Announcement

Release 6.3.100 is being rolled out to the first phase of regions as listed here.

This release contains internal and customer bug fixes.

Feature

Reaction triggers

This feature is in preview. Google SecOps now supports reaction triggers. As post-ingestion triggers, they allow playbooks to automatically fire in response to real-time case or alert updates during active investigations, such as changes to the case assignee, case tags, alert priority, or newly added entities.

For more information, see Use reaction triggers in playbooks.

Feature

Case playbooks

This feature is in preview. Google SecOps now supports case playbooks. You can run playbooks or execute manual actions across an entire case container rather than individual alerts, consolidating response tasks and reducing redundant operations during investigations.

For more information, see Case playbooks overview.

September 05, 2026

Google SecOps SOAR
Announcement

Release 6.3.99 is now available for all regions.

September 04, 2026

Audit Manager
Feature

The remote Model Context Protocol (MCP) server for Audit Manager is generally available (GA).

Cloud Billing
Change

Introducing the Incentives page, for tracking spend-based milestone credits, RaMP, and other conditional incentives

If you have a custom pricing contract, you might be enrolled in conditional incentives, where you earn credits or discounts for spending specific amounts on Google Cloud.

The Incentives page replaces the Spend-based Milestones tab that was located in the Credits page. The Incentives page provides a consolidated and enhanced experience for tracking your progress towards conditional incentives, including spend-based milestone credits and Rapid Migration & Modernization Program (RaMP) credits and discounts.

Learn more about tracking conditional incentives.

Cloud SQL for MySQL
Feature

The C4 machine series is now available for Cloud SQL for MySQL Enterprise Plus instances in the following regions:

  • africa-south1 — Johannesburg
  • asia-northeast3 — Seoul
  • asia-south2 — Delhi
  • europe-west6 — Zürich
  • southamerica-west1 — Santiago
  • us-west3 — Salt Lake City

The C4 machine series provides the following benefits:

  • Supports fifth and sixth generation Intel Xeon Scalable processors.
  • Offers a price-performance balance that makes it suitable for high-demand workloads.
Feature

Cloud SQL supports in-place upgrades and downgrades to your instance's infrastructure. You can change all of the following in place:

  • The edition that your Cloud SQL instance uses.
  • The machine type.
  • The storage type.
  • The database version.

Making in-place changes is the most direct and least error-prone way to reconfigure an instance.

For more information about in-place upgrades and downgrades, see Upgrade in place.

Cloud SQL for PostgreSQL
Feature

The C4 machine series is now available for Cloud SQL for PostgreSQL Enterprise Plus instances in the following regions:

  • africa-south1 — Johannesburg
  • asia-northeast3 — Seoul
  • asia-south2 — Delhi
  • europe-west6 — Zürich
  • southamerica-west1 — Santiago
  • us-west3 — Salt Lake City

The C4 machine series provides the following benefits:

  • Supports fifth and sixth generation Intel Xeon Scalable processors.
  • Offers a price-performance balance that makes it suitable for high-demand workloads.
Feature

Cloud SQL supports in-place upgrades and downgrades to your instance's infrastructure. You can change all of the following in place:

  • The edition that your Cloud SQL instance uses.
  • The machine type.
  • The storage type.
  • The database version.

Making in-place changes is the most direct and least error-prone way to reconfigure an instance.

For more information about in-place upgrades and downgrades, see Upgrade in place.

Cloud SQL for SQL Server
Feature

Cloud SQL for SQL Server supports the sp_help_revlogin stored procedure in the msdb database. You can enable this stored procedure by configuring the cloud sql enable sp_help_revlogin database flag to export SQL Server logins, password hashes, and security identifiers (SIDs) when migrating databases or synchronizing logins.

For more information, see Export SQL Server logins and Configure database flags.

Feature

Cloud SQL for SQL Server now supports connecting to instances with write endpoints using the Cloud SQL Auth Proxy or Cloud SQL language connectors. When you configure the proxy or a language connector with a write endpoint DNS name, connections are redirected automatically to the new primary instance during replica failover or switchover.

For more information, see Connect to an instance using a write endpoint.

Feature

The C4 machine series is now available for Cloud SQL for SQL Server Enterprise Plus instances in the following regions:

  • africa-south1 — Johannesburg
  • asia-northeast3 — Seoul
  • asia-south2 — Delhi
  • europe-west6 — Zürich
  • southamerica-west1 — Santiago
  • us-west3 — Salt Lake City

The C4 machine series provides the following benefits:

  • Supports fifth and sixth generation Intel Xeon Scalable processors.
  • Offers a price-performance balance that makes it suitable for high-demand workloads.
Feature

Cloud SQL supports in-place upgrades and downgrades to your instance's infrastructure. You can change all of the following in place:

  • The edition that your Cloud SQL instance uses.
  • The machine type.
  • The storage type.
  • The database version.

Making in-place changes is the most direct and least error-prone way to reconfigure an instance.

For more information about in-place upgrades and downgrades, see Upgrade in place.

Firestore
Feature

The Security Rules simulator is now available in the Google Cloud console for Firestore (Standard and Enterprise editions). You can test draft security rules against simulated database requests and evaluate authentication tokens before deploying rules.

For more information, see Test rules with the rules simulator or Test rules in the Google Cloud console.

Gemini
Announcement

New subscriptions for Gemini Code Assist can no longer be purchased through the Google Cloud console using billing accounts that don't have an active Gemini Code Assist subscription. Billing accounts that currently have an active Gemini Code Assist subscription are unaffected.

For billing accounts that don't have an active Gemini Code Assist subscription, you can obtain a new Gemini Code Assist subscription by contacting Google Cloud sales. For alternative AI developer tools, use Antigravity, which is available through eligible Gemini Enterprise subscriptions and through Gemini Enterprise Agent Platform.

Announcement

New subscriptions for Gemini Code Assist can no longer be purchased through the Google Cloud console using billing accounts that don't have an active Gemini Code Assist subscription. Billing accounts that currently have an active Gemini Code Assist subscription are unaffected.

For billing accounts that don't have an active Gemini Code Assist subscription, you can obtain a new Gemini Code Assist subscription by contacting Google Cloud sales. For alternative AI developer tools, use Antigravity, which is available through eligible Gemini Enterprise subscriptions and through Gemini Enterprise Agent Platform.

Gemini Enterprise
Feature

Gemini Enterprise: Monday federated data store (GA)

Connecting a Monday data source with Gemini Enterprise using data federation is generally available (GA). You can use the Gemini Enterprise app assistant to search across your Monday boards, items, updates, and docs, and get answers grounded in that content without needing to ingest the data.

For more information, see Set up a Monday data store.

Feature

Gemini Enterprise: Create and manage projects

You can create and manage projects in the Gemini Enterprise web app to build a dedicated knowledge base for your own work or to collaborate with your team. Within a project, you can upload files and chat privately with the assistant to get answers grounded in your project files and web search.

This feature is generally available (GA). To make projects available to users, a Gemini Enterprise administrator must turn on the Enable projects toggle in the Google Cloud console.

For more information, see the following:

Feature

Gemini Enterprise: New data stores and support for new actions (Preview)

The following data stores are available in Public Preview in Gemini Enterprise:

You can search and read data from these data stores, and perform actions using natural language.

Google Kubernetes Engine
Announcement

Kubernetes 1.37 is available

Kubernetes 1.37 is now available in the Rapid channel. For more information about the content of Kubernetes 1.37, read the Kubernetes 1.37 Release Notes and Kubernetes 1.37 Release Blog.

Deprecated

Removed in 1.37

Change

Other changes in 1.37

  • Starting with GKE version 1.37.0-gke.2100000, newly created clusters default to using control plane node creation, which improves cluster security by having the control plane manage node registration instead of kubelet self-registration. Existing clusters are not affected. If your workloads require legacy kubelet self-registration, you can opt out during cluster creation by specifying --node-creation-mode=KUBELET. For more information, see Disable control plane node creation.
  • In version 1.37 and later, newly created node pools use an improved formula to calculate the default system reservation for CPU and memory resources on each node. This updated reservation algorithm reduces the system memory reservation by 10% to 15% when compared to the algorithm that's used in version 1.36 and earlier.
  • The updated default reservation algorithm applies only to new node pools that are created on version 1.37 and later. Existing node pools that you upgrade to 1.37 or later from version 1.36 or earlier don't use the updated algorithm.
  • Additionally, any new or existing node pool that runs GKE version 1.37 and later can modify the amount of CPU and memory that's reserved for system workloads in node pools by using the reservedResourcesConfig option in the node system configuration file.
Feature

New features in 1.37

Google SecOps Marketplace
Change

Google Chronicle: Version 94.0

  • Reverted the execution mode to synchronous in the following action:

    • Is Value in Data Table
Looker
Announcement

Looker 26.16 will roll out to Looker (original) instances on the following schedule:

  • Expected deployment start: Tuesday, September 8, 2026
  • Expected final deployment and download available: Sunday, September 20, 2026

Looker 26.16 is expected to include the following changes, features, and fixes.

Fixed

An issue has been fixed where logging in with a Google Cloud Workforce Identity within an embedded iframe could fail as a result of frame restrictions or because the authentication popup closed before session cookies were established. This feature now performs as expected.

Fixed

An issue has been fixed where switching to a histogram visualization in an Explore could fail or revert unexpectedly. Additionally, stack resolution on pivoted histograms has been improved. This feature now performs as expected.

Fixed

An issue has been fixed where the alert creation and edit modal displayed Method instead of defaulting to Email as the notification method. This feature now performs as expected.

Fixed

An issue has been fixed where embedded dashboards with numerous filters caused horizontal container overflow, prevented filters from wrapping across rows, and resulted in clipped tiles during PDF and PNG exports.

Fixed

An issue has been fixed where custom themes configured as the instance default were not applied to dashboards in view-only mode or during dashboard navigation. This feature now performs as expected.

Fixed

An issue has been fixed where LookML dashboard URLs that were opened from the search page contained encoded colons (%3A%3A), which prevented filter interactions from updating URL query parameters. This feature now performs as expected.

Fixed

An issue has been fixed where Single Value visualizations and KPI visualizations would not allow creating a comparison against a non-measure table calculation. This feature now performs as expected.

Fixed

An issue has been fixed where visualization-level filters could not be edited or deleted because of missing popover menus. This feature now performs as expected.

Fixed

An issue has been fixed where resizing an Explore that contained a Word Cloud visualization could cause the Explore to crash. This feature now performs as expected.

Fixed

An issue has been fixed where generating LookML for analytic models without selecting any database tables could cause Looker to create views for all database tables and to drop certain properties because of identifier case sensitivity. This feature now performs as expected.

Fixed

An issue has been fixed where filter context banners and timezone settings were not preserved when generating PNG downloads from drill menus. This feature now performs as expected.

Fixed

An issue has been fixed where applying pivots to merge queries could cause visualization errors and blank column headers in the results table. This feature now performs as expected.

Fixed

An issue has been fixed where standalone tile exports from embedded dashboards with filter context could render off-screen or with clipped visualizations in PDF and PNG formats. This feature now performs as expected.

Fixed

An issue has been fixed where clearing all text from a dashboard note tile failed to persist upon page refresh. This feature now performs as expected.

Fixed

The BigQuery High Throughput API has been disabled by default to prevent connection errors for environments without bigquery.readsessions.create permissions. Additionally, required JVM flags for JDK 11 environments have been added. This feature now performs as expected.

Fixed

An issue has been fixed where multi-line prompt text in dashboard chat views caused action buttons (such as the Thinking toggle and Send button) and vertical scrollbars to be misaligned. This feature now performs as expected.

Fixed

An issue has been fixed where pinned Looks on boards generated broken URLs that redirected to the home page and failed to dynamically reflect title updates. This feature now performs as expected.

Fixed

An issue has been fixed where selecting a suggestion could reset the dropdown to a loading spinner. This feature now performs as expected.

Fixed

An issue has been fixed where collapsible navigation items in the Admin panel and the main navigation pane rendered rectangular focus outlines rather than rounded focus indicators during keyboard navigation. This feature now performs as expected.

Fixed

An issue has been fixed where typed search strings persisted after you selected an autocomplete suggestion in multi-select filters. This feature now performs as expected.

Fixed

When you duplicate a user-defined dashboard, associated Looker data agent instructions, configurations, and sources are now preserved on the copied dashboard.

Fixed

Self-service models have been restricted to only their assigned user database connections, preventing unintended instance-wide database connection access.

Fixed

Boxplot visualizations now render transparent median dividers and borders properly in inverted and dark theme layouts.

Fixed

An issue has been fixed where IAM administrators on Looker (Google Cloud core) instances failed authentication when the auth_requires_role and strict Group Role Mapping were enabled. This feature now performs as expected.

Feature

The Semantic Search feature is now generally available.

Feature

Now available in preview, the Admin Assistant helps you use natural language to manage Looker roles.

Managed Service for Apache Spark
Announcement

New Managed Service for Apache Spark (formerly Dataproc on Compute Engine) subminor cluster image versions:

  • 2.1.119-debian11, 2.1.119-rocky8, 2.1.119-ubuntu20, 2.1.119-ubuntu20-arm
  • 2.2.87-debian12, 2.2.87-rocky9, 2.2.87-ubuntu22, 2.2.87-ubuntu22-arm
  • 2.3.36-debian12, 2.3.36-ml-ubuntu22, 2.3.36-rocky9, 2.3.36-ubuntu22, 2.3.36-ubuntu22-arm
  • 3.0.2-debian13, 3.0.2-ml-ubuntu24, 3.0.2-rocky9, 3.0.2-ubuntu24

Key updates in these image versions include:

  • Feature updates:
    • Apache Hudi: Added support for the Apache Hudi optional component in 3.0 images. Version 1.2.0 is available in 3.0 images.
    • Parquet footer caching: Enabled Parquet footer caching by default for Lightning Engine (Velox). If executor out-of-memory (OOM) or task failure spikes on tiny files are observed, these can be mitigated by setting spark.gluten.sql.columnar.backend.velox.cacheParquetFooters=false.
    • Apache Iceberg 1.10: Added support for Apache Iceberg 1.10 in 2.2 images. Users can opt-in by setting the cluster property, dataproc:dataproc.iceberg.version=1.10.
    • Lakehouse catalog: Lakehouse catalog auto-loading is supported for image versions 2.2 and later.
  • Library updates:
    • Cloud Storage connector: Upgraded the Cloud Storage connector to 4.0.4 in 3.0 images.
    • OpenLineage: Upgraded OpenLineage to 1.49 in 3.0 images to support lineage for tables created using the Lakehouse Runtime catalog.
Breaking

Managed Service for Apache Spark (formerly Dataproc on Compute Engine):

  • Preconfigured Conda channels removed: Preconfigured conda channels (such as conda-forge) have been removed from configurations. All image version aliases now point to the latest image without conda channel configuration. Support for earlier images with conda channels configuration to be announced in upcoming release notes. Recommendation: Migrate to the latest image versions as soon as possible.
    • Affected image versions: 1.3.96+, 1.4.81+, 1.5.92+, 2.0.161+, 2.1.119+, 2.2.87+, and 2.3.36+.
    • Impact: Additional conda package installation using the dataproc:conda.packages cluster property or direct conda install <package> command will fail.
    • Workaround:
      • Use the <channel>::<package>==<version> specification for the dataproc:conda.packages property (for example: dataproc:conda.packages=conda-forge::pip==24.0).
      • Specify the channel name on the command line when running conda install (for example: conda install <packages> -c conda-forge).
  • google-guest-agent upgraded: Upgraded google-guest-agent on Debian and Rocky Linux images (remediating CVE-2026-33186).
  • SSH metadata restriction: Stricter SSH metadata restrictions are enforced by default; metadata SSH keys mapped directly to root are ignored. Connect using a standard non-root user (such as dataproc) with sudo, or use Google Cloud OS Login.
Fixed

Managed Service for Apache Spark (formerly Dataproc on Compute Engine): Fixed a segmentation fault when OpenLineage parses complex SQL query strings with the Lakehouse Runtime catalog.

Model Armor
Feature

Clarification: August 5, 2026 release note for Melbourne and Seoul

In Melbourne (australia-southeast2) and Seoul (asia-northeast3), only the Sensitive Data Protection filter is supported when data residency is enforced. To use other Model Armor features in these regions, disable data residency enforcement in the template.

For information about available Model Armor features for each region, see Supported features by region.

September 03, 2026

API Gateway
Change

New model routing gateways might use a gateway.dev default hostname

If you create a gateway that uses model routing on or after September 3, 2026, it might receive a gateway.dev default hostname instead of a run.app one, in the form https://GATEWAY_ID-PROJECT_NUMBER.REGION.gateway.dev — for example, https://my-gateway-123456789012.us-central1.gateway.dev. This is a second gateway.dev format; other gateways keep the existing one.

To get a gateway's URL, read its defaultHostname property.

For more information, see Deploy an API to a gateway.

BigQuery
Feature

Conversational analytics now supports questions about market basket analysis. This feature is generally available (GA).

Cloud Healthcare API
Feature

General availability: Filtered export of DICOM data using filterConfig is now generally available (GA) in Cloud Healthcare API v1. You can supply a Cloud Storage URI (resourcePathsGcsUri) containing a newline-delimited list of DICOMweb resource paths (studies/<studyUID>[/series/<seriesUID>[/instances/<instanceUID>]]) in projects.locations.datasets.dicomStores.export to export targeted subsets of DICOM data rather than the entire DICOM store. For more information, see Exporting DICOM instances using filters.

Cloud Storage
Feature

You can use Storage batch operations to do the following:

  • Select objects dynamically across a project by using Common Expression Language (CEL) filters based on metadata in your Storage Insights datasets, without manual CSV manifests or BigQuery export queries.
  • Target objects across up to 1,000 buckets in a single batch job.
  • Transition objects in bulk to different storage classes.
  • Patch object access control lists (ACLs) in bulk to update or remove permissions.
  • Use dry run to validate job configurations across multiple buckets, and create jobs directly from a dry run to process the same validated objects.

For more information, see Storage batch operations overview and Create and manage batch operations jobs.

Gemini Enterprise
Feature

Gemini Enterprise: Latency and error rate views for agents

To monitor operational telemetry for your agents, use the two new views on the Observability tab:

  • Latency: Shows response times for your agents. This view displays p50 (median) and p95 (95th percentile) metrics for Time to First Token (TTFT), Time to First Answer (TTFA), and Time to Last Token (TTLT). TTFT counts the first token of any kind, including the model's thinking, while TTFA counts only the first token of the answer itself. You can also compare latencies by specific agent features, such as web search, media generation, or parametric interactions.
  • Error rate: Shows how your agent's requests resolve by tracking request volume and error rates. This view groups results by response class (OK, client errors, server errors, and canceled) and displays the associated client and server error codes.

This feature is generally available (GA). For more information, see Access metrics.

Feature

Gemini Enterprise: General availability of Workflow Builder (formerly Agent Designer)

Workflow Builder (formerly known as Agent Designer) is generally available (GA) in Gemini Enterprise.

Workflow Builder enables users across your organization to build multi-step automated workflows to streamline tasks and connect to enterprise data.

Key capabilities in this release include:

  • Workflows and on-demand execution: Build multi-step workflows that can run on an automated schedule, trigger manually on demand, or execute via @-mention directly within Gemini Enterprise chat conversations.
  • Chat agents: Call chat agents from chat conversations using @-mention.
  • In conversation: Call workflows from a chat conversation using @-mention.
  • Agent import: Import existing A2A and ADK agents into Gemini Enterprise for centralized management, sharing, and enterprise governance.
  • Enterprise connectors: Connect workflows to enterprise data and applications—including Google Workspace (Gmail, Google Calendar, Google Chat, Google Drive) and third-party tools (Slack, Jira, ServiceNow, Confluence, Microsoft OneDrive, SharePoint, and Outlook)—to search data and execute actions.
  • Enhanced Agent Gallery: Discover and organize organization-wide and Google-created agents using keyword search, filter chips, and pinned items.
  • Administrative controls: Administrators can manage feature availability org-wide in the Google Cloud console, including dedicated toggles for workflows and chat agents.

For more information, see Workflow Builder.

Google Cloud Contact Center as a Service
Announcement

Google Cloud CCaaS 6.9

We've released version 6.9 of Google Cloud CCaaS.

The timing of the update to your instance depends on the deployment schedule that you have chosen. For more information, see Deployment schedules.

Feature

Agent desktop supports email

The agent desktop now supports email. Agents can handle email interactions using the email adapter in a desktop layout.

Administrators: There's a new Email Adapter checkbox in the following locations:

  • The Desktop Layout Builder dialog at Settings > Operation Management > Agent Desktop > Manage Desktop Layout Lists > Add desktop layout.

  • The Desktop Layout Builder at Settings > Operation Management > Agent Desktop > Manage Desktop Layout Lists > Add desktop layout > Next.

User experience change: There's a new new emails menu in the menu bar of the agent desktop.

For more information, see Create a desktop layout and Handle an email.

Fixed

This release addresses the following issues:

  • Fixed an issue where agents couldn't send new outbound emails.

  • Fixed an issue where the disposition panel in the call adapter was incorrectly hidden or visible due to inconsistent state updates.

  • Fixed an issue where direct inbound voicemails appeared multiple times in the History tab of the call adapter.

  • Fixed an issue where voice callbacks were canceled at the end of operating hours instead of rolling over to the next day.

  • Fixed an issue where using click-to-dial from a Salesforce case incorrectly overwrote the parent account's mobile phone number with the dialed number.

  • Fixed an issue where ending a call resulted in significant latency or connection errors in the instance.

  • Fixed an issue where hold music in call recordings overlapped live conversation.

  • Fixed an issue where the deletion of a custom hours of operation group didn't appear in the Audit Dashboard.

  • Fixed an issue in Zendesk integrations where the system mistakenly navigated from the active ticket tab to the customer profile page when a voice call ended.

Google Kubernetes Engine
Feature

GKE support for using the c3-standard-*-lssd machine types as Confidential GKE Nodes with Intel TDX is generally available. For more information, see the following:

Google SecOps
Feature

Self-service Bindplane Enterprise license download

This feature is currently in Preview for Google Security Operations tenants in the US and EU regions. Google Security Operations Enterprise Plus and Google Unified Security (GUS) customers can now download their Bindplane Enterprise (Google Edition) license key directly from the platform console under SIEM Settings > Collection Agents.

For more information, see Bindplane Enterprise (Google Edition).

Google SecOps Marketplace
Feature

Google Chronicle: Version 93.0

  • Added the following new action:

    • Execute UDM Query Async
Change

ServiceNow: Version 72.0

  • Added the ability to authenticate using client credentials without a refresh token to the following connector:

    • Sync Incidents
Change

FireEye ETP: Version 11.0

  • Updated ontology mapping rules and fixed missing alert details and event data for v2 API issue in the following connector:

    • FireEye ETP - Email Alerts Connector
Google SecOps SIEM
Feature

Self-service Bindplane Enterprise license download

This feature is currently in Preview for Google Security Operations tenants in the US and EU regions. Google Security Operations Enterprise Plus and Google Unified Security (GUS) customers can now download their Bindplane Enterprise (Google Edition) license key directly from the platform console under SIEM Settings > Collection Agents.

For more information, see Bindplane Enterprise (Google Edition).

Memorystore for Redis
Feature

You can use client-side metrics to troubleshoot why your application might experience high latency. This feature is generally available.

Spanner
Feature

Spanner supports the following PostgreSQL-dialect database operators:

  • ILIKE (~~*)
  • NOT ILIKE (!~~*)

Spanner supports the following PostgreSQL-dialect database functions:

  • pg.ilike
  • pg.not_ilike

For more information, see Pattern matching operators and Functions.

VPC Service Controls
Feature

VPC Service Controls feature (Status: Preview): VPC Service Controls supports retrieving and updating service perimeters that contain deleted IAM principals. When you enable this feature, you can manage perimeters that contain deleted user, group, or service account identities without triggering the The email address is invalid or non-existent error.

For more information, see Supported identities for ingress and egress rules.

September 02, 2026

AlloyDB for PostgreSQL
Feature

AlloyDB real-time data access to BigQuery (in Preview) now offers limit pushdown and runtime projects:

  • Limit pushdown: when you query foreign tables, some LIMIT and OFFSET clauses are automatically pushed down to BigQuery, reducing network transfer and improving query response times. For more information, see Access to real-time data in BigQuery overview.
  • Runtime projects: you can specify an optional runtime project at either the foreign server or foreign table level to execute queries and manage compute costs independently of the project that stores your data. For more information, see Configure access to real-time data in BigQuery.

Consider using least-privilege security controls to restrict foreign server usage. For more information, see Secure BigQuery data access using the foreign data wrapper.

Apigee Edge for Private Cloud
Announcement

Apigee Edge for Private Cloud release notes are now published on Google Cloud documentation.

Release notes and patch announcements for Apigee Edge for Private Cloud are published on the Apigee Edge for Private Cloud release notes page from September 2026 onward. You can subscribe to that page with a feed reader to be notified when a new release or patch is published.

Release notes published before September 2026 remain available in the Apigee Edge release notes archive.

Apigee Edge for Public Cloud
Announcement

Apigee Edge for Public Cloud release notes are now published on Google Cloud documentation.

Release notes for Apigee Edge for Public Cloud, including its Edge UI, SSO, Message Processor, and integrated portal components, are published on the Apigee Edge for Public Cloud release notes page from September 2026 onward. You can subscribe to that page with a feed reader to be notified when a new release is published.

Release notes published before September 2026 remain available in the Apigee Edge release notes archive.

Application Design Center
Feature

Application Design Center supports the following components in General Availability:

  • Firebase AI Logic
  • Firebase AI Logic Prompt Template
  • Firebase App Check
  • Firebase Authentication
  • Firebase Multi-Platform App
  • Firestore Security Rules
BigQuery
Change

An updated version of the Simba JDBC driver for BigQuery is now available.

Cloud SQL for MySQL
Feature

Cloud SQL supports Workforce Identity Federation authentication. This lets you authenticate to your Cloud SQL instance using identities from an external identity provider such as Microsoft Active Directory or Okta. For more information, see Workforce Identity Federation authentication.

Cloud SQL for PostgreSQL
Feature

Cloud SQL supports Workforce Identity Federation authentication. This lets you authenticate to your Cloud SQL instance using identities from an external identity provider such as Microsoft Active Directory or Okta. For more information, see Workforce Identity Federation authentication.

Confidential VM
Feature

Support for Intel TDX on c3-standard-*-lssd machine types is generally available (GA).

Cortex Framework
Announcement

Release 7.0.6

Fixed
  • Added support for logical SAP table remapping in SAP Data Foundation.
  • Added custom/ directory scaffolding across all developer skills for local extensions.
Gemini Enterprise
Feature

Gemini Enterprise: Gemini 3.8 Flash available in Global, US, and EU regions

Gemini 3.8 Flash is generally available (GA) in the global, us, and eu regions.

For more information, see:

Gemini Enterprise Agent Platform
Feature

Gemini 3.8 Flash is generally available

Gemini 3.8 Flash is now generally available (GA) and available for production use.

For more information on 3.8 Flash, see the model page.

Feature

Provisioned Throughput support for Gemini Omni

Provisioned Throughput supports Gemini Omni. To learn more, see supported models.

Feature

Deferred tier for autonomous agent scheduling (Preview)

The deferred tier is available in Preview. The deferred tier automatically queues non-latency-sensitive background agent workloads and schedules them to execute during off-peak hours.

Key capabilities and benefits include:

  • 50% token discount: Receive a 50% discount on consumed tokens for deferred workloads.
  • Reduced rate limiting: Mitigate resource exhaustion (429) errors and infrastructure pressure during long-running background tasks.
  • Supported agents:
    • Deep Research Agent: Pass service_tier="deferred" in the Python SDK or "service_tier": "deferred" in REST API interaction requests.

For more information, see Autonomous agent scheduling.

Fixed

CodeMender updates (v0.6.0)

This release introduces updates to CodeMender:

  • Machine-readable metrics: Added the --json flag to cm stats to export aggregate and per-session metrics (CACHE_HIT%, THINK_RATIO%, TOOL_CALLS, DURATION).
  • Session drill-down: Added cm stats --session <id> to inspect turn-by-turn token consumption for specific sessions.
  • Bug fixes:
    • Improved codebase search reliability by skipping binary archives and non-regular files during traversal.
    • Fixed an issue where cm report import failed on native JSON reports or findings referencing new files.
    • Fixed an issue where preview mode could create empty directories on disk before user confirmation.
    • Prevented erroneous verification verdicts when workspace reset fails.

For more information, see CodeMender documentation.

Google Kubernetes Engine
Change

(2026-R37) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

  • Version 1.35.7-gke.1150000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1079000
    • 1.35.7-gke.1027000
    • 1.36.2-gke.2064000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • Version 1.34.10-gke.1079000 is now available in the Stable channel.
  • Version 1.34.9-gke.1610001 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
    • GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
    • GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:

Extended channel

No channel (deprecated)

Security

(2026-R37) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2667000 cos-117-18613-675-64 cos-117-18613-675-64 release notes
1.32.13-gke.2393000 cos-121-18867-584-3 cos-121-18867-584-3 release notes
1.35.8-gke.1225000 cos-125-19216-532-135 cos-125-19216-532-135 release notes
1.36.4-gke.1082000 cos-129-19506-299-161 cos-129-19506-299-161 release notes
1.37.0-gke.2155000 cos-129-19506-299-82 cos-129-19506-299-82 release notes

Change

(2026-R37) Version updates

  • Version 1.34.10-gke.1079000 is now available in the Stable channel.
  • Version 1.34.9-gke.1610001 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
    • GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
    • GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
Change

(2026-R37) Version updates

  • Version 1.35.7-gke.1150000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.10-gke.1079000
    • 1.35.7-gke.1027000
    • 1.36.2-gke.2064000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Change

(2026-R37) Version updates

Change

(2026-R37) Version updates

Change

(2026-R37) Version updates

Looker
Deprecated

OpenJDK 11 will no longer be supported as of January 14, 2027. Customer-hosted instances must upgrade to OpenJDK 21.

Managed Service for Apache Airflow
Announcement

A new Managed Service for Apache Airflow release has started on September 02, 2026. Get ready for upcoming changes and features as we roll out the new release to all regions. This release is in progress at the moment. Listed changes and features might not be available in some regions yet.

Feature

Managed Airflow (Gen 3) environments now provide Out-of-Memory (OOM) event logs to help troubleshoot and diagnose memory exhaustion.

Change

Improved Airflow task resilience against transient Kubernetes pod connection issues.

Change

Improved Airflow web server update process during environment upgrade operations.

Change

New images are available in Managed Airflow (Gen 2):

Model Armor
Feature

Filter version v3 will be promoted to the Stable alias on or before September 25, 2026. On the same date, filter versions v1 and v2 transition to Legacy status and retire on November 29, 2026.

If your templates use the Stable alias, they will automatically upgrade to v3 when it is promoted. If your templates use explicit version numbers (v1 or v2), migrate them to v3 or the Stable alias before November 29, 2026.

For more information, see Set the filter version for a template.

Spanner
Feature

Spanner supports using the TABLESAMPLE operator in PostgreSQL-dialect databases to select a random sample of a dataset.

For more information, see TABLESAMPLE operator.

September 01, 2026

Apigee UI
Announcement

On September 1, 2026, we released an updated version of the Apigee UI.

Fixed
Bug ID Description
547582067

Revisions can now be imported for API proxies and shared flows in a space

Importing a revision in the Apigee UI now works for an API proxy or shared flow that is associated with a space.

Previously, the Apigee UI did not include the space when it uploaded the revision bundle, so the import request was rejected and the new revision was not created. This affected both API proxies and shared flows.

The earlier workaround of removing the API proxy or shared flow from its space, importing the revision, and then adding it back to the space is no longer needed.

App Engine flexible environment Go
Feature
App Engine standard environment Go
Feature
Backup and DR
Feature

Backup vault support for AlloyDB for PostgreSQL instances encrypted with customer-managed encryption keys (CMEK) is generally available (GA), providing immutable and indelible storage with enforced retention. For more information, see Encrypt AlloyDB for PostgreSQL cluster backups.

Announcing the general availability (GA) of cross-region backups for AlloyDB for PostgreSQL clusters. You can now protect AlloyDB for PostgreSQL clusters against regional outages by storing backups in a distinct secondary region of your choice. To learn more, see Backup vaults for immutable and indelible backups.

BigQuery
Feature
Bigtable
Feature

You can use the Google Cloud console to create and manage aggregate column families for your Bigtable tables. You can also view and query aggregate column families in Bigtable Studio. This feature is generally available (GA). For more information, see Create and manage tables and Manage your data using Bigtable Studio.

Cloud Monitoring
Feature

You can opt out of alert notifications from an SMS notification channel by sending a text message to the phone number associated with the notification channel. For more information, see Opt out of SMS notifications.

Cloud Run
Feature
Feature

Configure Agent Platform features on your Cloud Run services and jobs to securely authenticate AI agents and MCP servers using system-managed Agent Identities. This support also includes automatic registration in the Agent Registry (Preview).

Cloud Run functions
Feature
Cloud Service Mesh
Security

Managed Cloud Service Mesh will start using proxy version csm_mesh_proxy.20260819_RC00 for Gateway API on GKE clusters. This proxy version maps closest to Envoy version 1.37. This change is rolling out to all release channels and contains the fix for the managed Cloud Service Mesh security vulnerabilities listed in GCP-2026-057.

Cortex Framework
Announcement

Release 7.0.5

Fixed
  • Removed obsolete review items checklist from tests.
Developer Connect
Announcement

Developer Connect account connectors is now generally available.

Gemini
Other

Bug fixes in IntelliJ

Various bug fixes and minor product enhancements.

Gemini Enterprise
Feature

Gemini Enterprise: Overage controls available for all invoiced Cloud Billing accounts

Configuring overage controls in Gemini Enterprise is available to all projects linked to an invoiced Cloud Billing account. Previously, customers that received an email with the subject line [Billing Update] New Gemini Enterprise overage billing controls launching Aug 17, 2026 couldn't enable overages despite having an invoiced Cloud Billing account. This restriction no longer applies.

For more information, see Overview of overages and spend controls.

Gemini Enterprise Agent Platform
Feature

Anthropic's Claude Fable 5.1 is now available

Claude Fable 5.1 is available in Model Garden.

Change

Embedding SKUs are changing

Memory bank uses the following embedding model SKUs:

  • 6E46-5623-C0B6
  • C15D-A68F-5C1E
  • 2D07-D52C-A93B

For detailed information about individual SKUs, see Google Cloud Platform SKUs.

Change

Pricing updates for agent metering

Session and memory bank compute metering is in effect for the Agent Platform compute SKU. For more information, see Gemini Agent Platform Pricing.

Google Kubernetes Engine
Change

GKE version 1.35.1-gke.1031000 and later include the following changes to automatically created firewall rules for Services:

  • Changes the priority of multiple existing firewall rules for Services from 1000 to 999.
  • Creates additional firewall rules to deny traffic that is not explicitly allowed by other auto-created firewall rules.

If you use custom firewall rules to override GKE firewall rules for Services, these changes might cause unexpected behavior. Before you upgrade your clusters to version 1.35.1-gke.1031000 or later, do the following:

  • If you have custom firewall rules that allow or deny traffic with a priority of 1000, change the priority of those rules to a numerically lower value (such as 999 or lower) to maintain their precedence.
  • Verify that the new auto-created deny rules do not block required traffic for load balancers that use external IP addresses.
Feature

The bare metal machine types from the C3 machine series are now generally available with GKE clusters. You can now provision machine types such as c3-standard-192-metal in Standard mode with any available GKE version.

To use these machine types with Autopilot mode, ComputeClasses, and node pool auto-creation, you must specify the exact machine type using a custom ComputeClass and use GKE version 1.35.3-gke.1389000 or later.

Managed Service for Apache Spark
Feature

Managed Service for Apache Spark (formerly Dataproc on Compute Engine): Lightning Engine with Native Query Execution (NQE) is now supported on ARM for image version 2.3 clusters (2.3-ubuntu22-arm), enabling accelerated vectorized query execution on Google Axion (C4A) instances for Apache Spark SQL, Cloud Storage Parquet, Apache Iceberg, and Delta Lake workloads.

Policy Intelligence
Feature

The Policy Analyzer MCP server is generally available. To learn about using the Policy Analyzer MCP server to let agents and AI applications analyze and audit IAM configurations, see Use the Policy Analyzer remote MCP server.

reCAPTCHA
Change

Fraud Defense Mobile SDK v18.9.3 is available for Android. This version includes detection and performance enhancements.

August 31, 2026

BigQuery
Feature

You can now create, store, and manage pipelines in Git folders. This feature is in Preview.

Feature

BigQuery now supports TabFM, Google's pre-trained foundation model for tabular data. TabFM enables zero-shot regression and classification through in-context learning. It delivers high-accuracy predictions on structured data without requiring model training or hyperparameter tuning. You can use TabFM directly through the AI.PREDICT function and evaluate model performance by using the AI.EVALUATE function. This feature is in Preview.

Fixed

Support for configuring daily token quotas for BigQuery generative AI functions has been restored.

Feature

You can now create an identity column, sometimes referred to as an auto-incrementing column, on a table. You can use identity columns to create and maintain primary keys on your tables. When you insert a row into a table that has an identity column, BigQuery generates a unique integer value for that column. This feature is in Preview.

Feature

BigQuery Graph is generally available (GA).

BigQuery Graph now includes support for the CALL graph query statement, and the following path inspection GQL functions:

  • IS_ACYCLIC
  • IS_SIMPLE
  • IS_TRAIL.
Cloud SQL for PostgreSQL
Feature

You can use the pgAudit extension to prevent string literals that might indicate sensitive information, such as passwords and secrets, from appearing in your log query results.

This pgAudit extension capability is supported on [PostgreSQL version].R20260712.01_06 or later.

For more information, see Audit for PostgreSQL using pgAudit.

Cloud Service Mesh
Announcement

1.30.4-asm.1 is now available for in-cluster Cloud Service Mesh.

You can now download 1.30.4-asm.1 for in-cluster Cloud Service Mesh. It includes the features of Istio 1.30.4 subject to the list of supported features.

The following are not supported:

  • Failover Priority support for DNS clusters
  • ENABLE_WILDCARD_HOST_SERVICE_ENTRIES_FOR_TLS
  • Multiple CUSTOM external authorization providers per workload
  • The DEBUG_ENDPOINT_AUTH_ALLOWED_NAMESPACES flag

For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh version 1.30.4-asm.1 uses Envoy v1.38.4-dev.

Announcement

In-cluster Cloud Service Mesh 1.27 is no longer supported. For more information and to view the earliest end-of-life dates for other versions, see Supported versions.

Cloud Trace
Breaking

Starting August 31, 2026, you can no longer create or edit trace sinks. Trace sinks were deprecated on February 18, 2026. For more information, see Export trace spans with sinks deprecation.

For information about how to analyze your trace data using SQL, see the following documents:

Container Optimized OS
Change

cos-beta-133-19999-44-21

Kernel Docker Containerd GPU Drivers
COS-6.18.46 v29.4.3 v2.3.2 See List
Change

cos-129-19506-448-8

Kernel Docker Containerd GPU Drivers
COS-6.12.105 v27.5.1 v2.2.7 See List
Change

cos-dev-138-20085-0-0

Kernel Docker Containerd GPU Drivers
COS-6.18.46 v29.4.3 v2.3.2 See List
Change

LTS Refresh from main-R133-cos-6.18 to release-R133-cos-6.18

Change

Updated containerd and containerd-test to v2.2.7.

Change

Updated cos-gpu-installer to v2.7.7.

Change

Updated cos-gpu-installer to v2.7.7.

Fixed

LTS Refresh from main-R129-cos-6.12 to release-R129-cos-6.12

Change

Updated the Linux kernel to v6.18.46.

Change

Updated the Linux kernel to v6.18.45.

Fixed

Upgraded app-admin/fluent-bit to v4.2.8.

Fixed

Added support for net-fs/lustre-client-drivers v2.14.0_p259.

Change

Updated the Linux kernel to v6.18.46.

Fixed

Upgraded app-arch/unzip to v6.0_p31.

Fixed

Updated cos-gpu-installer to v2.7.6.

Fixed

Added support for net-fs/lustre-client-drivers v2.14.0_p259.

Fixed

Upgraded app-shells/dash to v0.5.13.5.

Fixed

Updated net-misc/openssh to version 10.4_p1.

Fixed

Updated cos-gpu-installer to v2.7.6.

Fixed

Upgraded dev-libs/libverto to v0.3.2-r1.

Fixed

Upgraded app-admin/google-guest-configs to v20260819.00.

Fixed

Updated net-misc/openssh to version 10.4_p1.

Fixed

Upgraded dev-libs/popt to v1.19-r1.

Fixed

Upgraded app-admin/oslogin to v20260814.00.

Fixed

Upgraded app-admin/fluent-bit to v4.2.8.

Fixed

Upgraded sys-apps/acl to v2.4.0-r2.

Fixed

Upgraded app-arch/zstd to v1.5.7-r1.

Fixed

Upgraded app-admin/google-guest-configs to v20260819.00.

Fixed

Upgraded sys-auth/passwdqc to v2.0.3-r1.

Fixed

Upgraded app-containers/docker-credential-helpers to v0.9.9.

Fixed

Upgraded app-admin/node-problem-detector to v0.8.25.

Security

Fixed CVE-2026-68293 in the Linux kernel.

Fixed

Upgraded app-shells/dash to v0.5.13.5.

Fixed

Upgraded app-admin/oslogin to v20260814.00.

Security

Upgraded dev-libs/libxml2 to v2.15.3. This fixes CVE-2026-0989, CVE-2026-0990, and CVE-2026-0992.

Fixed

Upgraded chromeos-base/chromeos-dbus-bindings to v0.0.1-r2802.

Fixed

Upgraded app-admin/sosreport to v4.12.0.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068

Fixed

Upgraded chromeos-base/power_manager-client to v0.0.1-r2975.

Fixed

Upgraded app-arch/unzip to v6.0_p31.

Fixed

Upgraded chromeos-base/session_manager-client to v0.0.1-r2837.

Fixed

Upgraded app-containers/docker-credential-helpers to v0.9.9.

Fixed

Upgraded dev-db/sqlite to v3.53.4.

Fixed

Upgraded app-containers/docker-registry-test to v2.8.3.

Fixed

Upgraded dev-lang/luajit to v2.1.1780076327.

Fixed

Upgraded app-shells/dash to v0.5.13.5.

Fixed

Upgraded dev-libs/expat to v2.8.3.

Fixed

Upgraded dev-db/sqlite to v3.53.4.

Fixed

Upgraded dev-libs/gmp to v6.3.0-r2.

Fixed

Upgraded sys-apps/acl to v2.4.0-r2.

Fixed

Upgraded dev-libs/inih to v62.

Fixed

Upgraded sys-apps/xemu to v0.0.10.

Fixed

Upgraded dev-libs/libaio to v0.3.113_p8.

Fixed

Upgraded sys-auth/passwdqc to v2.0.3-r1.

Fixed

Upgraded dev-libs/libgpg-error to v1.61.

Fixed

Upgraded sys-fs/e2fsprogs to v1.47.4.

Fixed

Upgraded dev-libs/libltdl to v2.5.4.

Fixed

Upgraded sys-libs/libcap-ng to v0.9.5-r1.

Fixed

Upgraded dev-libs/libpcre2 to v10.47.

Fixed

Upgraded sys-process/lsof to v4.99.7.

Fixed

Upgraded dev-libs/libverto to v0.3.2-r1.

Security

Fixed CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, and CVE-2026-46598 in dev-go/crypto.

Fixed

Upgraded dev-libs/popt to v1.19-r1.

Security

Upgraded dev-libs/libxml2 to v2.15.3. This fixes CVE-2026-0989, CVE-2026-0990, and CVE-2026-0992.

Fixed

Upgraded dev-libs/userspace-rcu to v0.15.6.

Fixed

Upgraded dev-python/oauthlib to v3.3.1.

Fixed

Upgraded net-dns/c-ares to v1.34.8.

Fixed

Upgraded net-libs/nghttp2 to v1.70.0.

Fixed

Upgraded sys-apps/acl to v2.4.0-r2.

Fixed

Upgraded sys-apps/ethtool to v7.0.

Fixed

Upgraded sys-apps/pciutils to v3.15.0.

Fixed

Upgraded sys-apps/xemu to v0.0.10.

Fixed

Upgraded sys-auth/passwdqc to v2.1.0-r1.

Fixed

Upgraded sys-libs/libcap-ng to v0.9.5-r1.

Fixed

Upgraded sys-process/lsof to v4.99.7.

Security

Upgraded dev-libs/libxml2 to v2.15.3. This fixes CVE-2026-0989, CVE-2026-0990, and CVE-2026-0992.

Security

Upgraded vim & vim-core to version 9.2.0280. This fixes CVE-2026-35177.

Change

cos-125-19216-655-6

Kernel Docker Containerd GPU Drivers
COS-6.12.105 v27.5.1 v2.2.7 See List
Fixed

LTS Refresh from main-R125-cos-6.12 to release-R125-cos-6.12

Fixed

Upgraded app-arch/zstd to v1.5.7-r1.

Fixed

Upgraded app-containers/cni-plugins to v1.9.1.

Fixed

Upgraded dev-libs/libverto to v0.3.2-r1.

Fixed

Upgraded dev-libs/popt to v1.19-r1.

Fixed

Upgraded dev-libs/xxhash to v0.8.3-r2.

Fixed

Upgraded sys-auth/passwdqc to v2.0.3-r1.

Security

Fixed CVE-2026-68293 in the Linux kernel.

Security

Upgraded dev-libs/libxml2 to v2.15.3. This fixes CVE-2026-0989, CVE-2026-0990, and CVE-2026-0992.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068

Change

cos-121-18867-584-3

Kernel Docker Containerd GPU Drivers
COS-6.6.153 v27.5.1 v2.0.10 See List
Change

Updated cos-gpu-installer to v2.7.7.

Fixed

LTS Refresh from main-R121-cos-6.6 to release-R121-cos-6.6

Security

Fixed CVE-2026-64371 in the Linux kernel.

Security

Fixed CVE-2026-68142 in the Linux kernel.

Security

Fixed CVE-2026-68142 in the Linux kernel.

Security

Fixed CVE-2026-68432 in the Linux kernel.

Security

Upgraded dev-libs/libxml2 to v2.15.3. This fixes CVE-2026-0989, CVE-2026-0990, and CVE-2026-0992.

Change

cos-117-18613-731-2

Kernel Docker Containerd GPU Drivers
COS-6.6.153 v24.0.9 v1.7.34 See List
Fixed

LTS Refresh from main-R117-cos-6.6 to release-R117-cos-6.6

Security

Fixed CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and CVE-2026-60002 in openssh.

Security

Fixed CVE-2026-68142 in the Linux kernel.

Security

Fixed CVE-2026-68142 in the Linux kernel.

Security

Fixed CVE-2026-68432 in the Linux kernel.

Security

Upgraded dev-libs/libxml2 to v2.15.3. This fixes CVE-2026-0989, CVE-2026-0990, and CVE-2026-0992.

Datastream
Feature

You can now create a Datastream stream directly from the overview page of your Cloud SQL instances using the automated flow.

For more information, see Create a Cloud SQL stream using the automated flow.

Gemini Enterprise
Feature

Gemini Enterprise: Support for federated data stores in Assured Workloads with FedRAMP High compliance

Gemini Enterprise now supports connecting Google Workspace and third-party federated data stores to projects inside Assured Workloads folders, which automatically enforce security and compliance controls on your Google Cloud resources to meet FedRAMP High standards. This feature is generally available (GA). For more information, see

Feature

Gemini Enterprise: Gemini 3.5 Flash regional availability in Canada

Gemini 3.5 Flash is available in Canada (ca) with in-region at-rest data residency (DRZ) and machine learning processing (MLP).

For more information, see Locations.

Feature

Gemini Enterprise: Gemini 3.1 Flash image available in US and EU multi-regions

Gemini 3.1 Flash image (Nano Banana 2) for image generation is generally available in the us and eu multi-regions.

For more information, see:

Feature

Gemini Enterprise: Protect sensitive data with content policies

You can apply Sensitive Data Protection content policies to your Gemini Enterprise connectors, apps, and Gemini Notebook Enterprise notebooks.

Content policies inspect data for violating or unwanted content and block it. Content policies can block Gemini Enterprise apps from presenting sensitive or inappropriate material to users and can stop end users from uploading files that contain sensitive or inappropriate material.

This feature is generally available (GA). For more information, see Protect sensitive data in sources and Protect sensitive data in NotebookLM Enterprise sources.

Gemini Enterprise Agent Platform
Feature

Gemini 3.1 Flash Image and Gemini 3 Pro Image updates

This release introduces feature updates and expanded endpoint availability for Gemini 3.1 Flash Image and Gemini 3 Pro Image:

For more information, see the following:

Feature

IAM Unified Access Policies are generally available (GA)

IAM Unified Access Policies (Access policies) for Gemini Enterprise Agent Platform are generally available (GA). Agent Gateway uses Identity-Aware Proxy and Access policies to govern agentic communication between agent principals and destination resources, such as Model Context Protocol (MCP) servers, other agents, and registered or unregistered endpoints.

Key capabilities include:

  • Multiple allow and deny rules within a single Access policy to establish fine-grained behavioral guardrails.
  • Common Expression Language (CEL) conditions in rules to enforce access criteria based on tool names, read-only constraints, HTTP methods, and URL path attributes.
  • Dry-run and enforcement modes to validate and audit policy evaluation before blocking agent traffic.
  • End-to-end agent identity authentication and authorization using mutual TLS (mTLS) and Context-Aware Access (CAA) with Demonstrating Proof of Possession (DPoP).

For more information, see IAM access policies overview.

Google Kubernetes Engine
Feature

Session affinity support using GCPTrafficDistributionPolicy for GKE Gateway is generally available. This release currently supports single-cluster GKE Gateway load balancers using the following GatewayClasses:

  • gke-l7-rilb
  • gke-l7-regional-external-managed
  • gke-l7-global-external-managed

In addition to the session affinity types available in Preview, you can now use the STRONG_COOKIE_AFFINITY type, which provides the most persistent session stickiness among the session affinity types available in Google Cloud Application Load Balancers.

The session affinity types require the following minimum GKE versions:

  • CLIENT_IP, HEADER_FIELD, GENERATED_COOKIE, and HTTP_COOKIE: version 1.35.2-gke.1269001 or later
  • STRONG_COOKIE_AFFINITY: version 1.36.3-gke.1767000 or later

For more information, see Configure session affinity using GCPTrafficDistributionPolicy.

Google SecOps
Feature

[Spotlight Feature] Customizable schedules for multi-event rules general availability

The customizable schedules for multi-event rules feature is now in General Availability (GA).

Customizable schedules give security teams granular control and transparency over how multi-event rules execute in Google SecOps, and provide the following capabilities:

  • Configure settlement delays: Set first-run delay offsets (from 1 minute up to 48 hours) to account for log ingestion latency and reduce false negatives.
  • Leverage automated true-up runs: Automatically re-evaluate time windows at 4 hours (and optionally 30 hours for full context enrichment) to capture late-arriving logs.
  • Migrate legacy rules: Upgrade existing custom multi-event rules to customizable schedules directly from the Rules Dashboard.

To manage rule schedules with custom IAM roles, make sure your roles include chronicle.rules.modifyRules and chronicle.ruleDeployments.update. Predefined IAM roles include these permissions automatically.

For more information, see Configure customized schedules for rules and Understand rule run scheduling.

Identity-Aware Proxy
Feature

IAM Unified Access Policies for Agent Gateway are generally available (GA)

IAM Unified Access Policies (Access policies) for Agent Gateway and Identity-Aware Proxy (IAP) are generally available (GA). Identity-Aware Proxy integrates with Agent Gateway and uses Access policies to help secure and govern agentic egress communication between agent principals and destination resources, such as Model Context Protocol (MCP) servers, other agents, and registered or unregistered endpoints.

Key capabilities include:

  • Multiple allow and deny rules within a single Access policy to establish fine-grained behavioral guardrails for egress traffic.
  • Common Expression Language (CEL) condition evaluation in rules to enforce egress access criteria based on tool names, read-only constraints, HTTP methods, and URL paths.
  • Dry-run and enforcement modes to validate and audit policy evaluation before blocking egress traffic.
  • End-to-end agent identity authentication and authorization using mutual TLS (mTLS) and Context-Aware Access (CAA) with Demonstrating Proof of Possession (DPoP).

For more information, see IAM access policies overview.

Looker
Announcement

Localized data processing for European Union (EU)-based customers now applies to all Conversational Analytics data agents, including agents that are associated with Looker Explores, user-defined dashboards, and LookML dashboards. This support means that localized data processing now applies to all Conversational Analytics in Looker features.

Note: This item was added September 9, 2026.

Deprecated

The Looker Mobile (Legacy) application is no longer available for download from the App Store or Play Store and support for the app has been discontinued. Although users will still be able to use the Looker Mobile (Legacy) app if they already have it installed, we recommend that you install the non-legacy Looker mobile app.

Note: The deprecation of the Looker Mobile (Legacy) application has been postponed to January 31, 2027. This item was updated on September 9, 2026.

Managed Service for Apache Spark
Announcement

Managed Service for Apache Spark (formerly Dataproc on Compute Engine): The following subminor image versions announced on August 19, 2026 have been rolled back:

  • 2.2.86-debian12, 2.2.86-rocky9, 2.2.86-ubuntu22, 2.2.86-ubuntu22-arm
Memorystore for Redis Cluster
Feature

You can use access control list (ACL) policies to secure access to your clusters. You can enable fine-grained security by restricting user and service access to specific keys, commands, operations, and Pub/Sub channels. This feature is Generally Available.

Memorystore for Valkey
Feature

You can use access control list (ACL) policies to secure access to your instances. You can enable fine-grained security by restricting user and service access to specific keys, commands, operations, and Pub/Sub channels. This feature is Generally Available.

Network Connectivity Center
Feature

IPv6 dynamic routes support for include and exclude spoke filters for hybrid spokes is available in Preview.

Export filters control which subnets or routes a spoke can send to the hub. Import filters control which subnets or routes can be accepted by a spoke from the hub.

Sensitive Data Protection
Feature

Sensitive Data Protection content policies are in General Availability. You can use content policies to evaluate content and return an ALLOW or BLOCK verdict based on data sensitivity.

For more information about content policies, see the following:

Sensitive Data Protection content policies are integrated with Gemini Enterprise. For more information, see the following:

Service Extensions
Feature

Agent Gateway now supports Service Extensions to evaluate requests and delegate authorization decisions for agent traffic to either Google services or custom authorization services. This feature is generally available (GA).

For more information, see Integration with Agent Gateway.

Virtual Private Cloud
Feature

General Availability: You can create Compute Engine instances that have multiple virtual network interfaces (vNICs) in the same VPC network. For more information, see Multiple network interfaces in the same VPC network.

August 30, 2026

Agent Platform Workbench
Change

20260830-2330-rc0 Release

Change

20260831.01_p0 Release

Change

Installed latest packages from upstream dependencies.

Change

Installed latest packages from upstream dependencies.

Fixed

The terminal and file browser are now more responsive when working in a Cloud Storage bucket that is mounted through the file browser. Frequent background checks for non-existent files are now cached instead of repeatedly querying Cloud Storage, which previously could make actions such as listing files or running terminal commands take several seconds.

Fixed

Cloud Storage buckets that you mount through the file browser are now automatically re-mounted after the instance is restarted or is stopped and started. Previously the mounted folder could be left behind as an empty, unusable directory that had to be manually removed and re-mounted.

Change

The obsolete google-cloud-sdk transitional package is no longer installed. The Google Cloud CLI itself is unchanged; it was already provided by the google-cloud-cli package.

Change

20260830-2230-rc0 Release

Change

20260830-2230-rc0 Release

Change

Installed latest packages from upstream dependencies.

Change

Installed latest packages from upstream dependencies.

Fixed

Cloud Storage buckets that you mount through the file browser are now automatically re-mounted after the instance is restarted or is stopped and started. Previously the mounted folder could be left behind as an empty, unusable directory that had to be manually removed and re-mounted.

Fixed

The terminal and file browser are now more responsive when working in a Cloud Storage bucket that is mounted through the file browser. Frequent background checks for non-existent files are now cached instead of repeatedly querying Cloud Storage, which previously could make actions such as listing files or running terminal commands take several seconds.

Change

20260830-2154-rc1 Release

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed an issue where a notebook's cells and their outputs could be unexpectedly erased. The automatic reload of an open notebook (which keeps it in sync with changes made to its file on disk) is now restricted to run only while the Gemini CLI is in use, so notebooks are no longer overwritten at other times.

Fixed

Cloud Storage buckets that you mount through the file browser are now automatically re-mounted after the instance is restarted or is stopped and started. Previously the mounted folder could be left behind as an empty, unusable directory that had to be manually removed and re-mounted.

Fixed

The terminal and file browser are now more responsive when working in a Cloud Storage bucket that is mounted through the file browser. Frequent background checks for non-existent files are now cached instead of repeatedly querying Cloud Storage, which previously could make actions such as listing files or running terminal commands take several seconds.

Change

Agent Platform Workbench instances internal agents now honor custom CA certificates installed on the host OS (e.g. via a custom VM image), fixing TLS certificate verification failures when Google API traffic is routed through a customer-managed proxy.

Change

M148 Release

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed an issue where a notebook's cells and their outputs could be unexpectedly erased. The automatic reload of an open notebook (which keeps it in sync with changes made to its file on disk) is now restricted to run only while the Gemini CLI is in use, so notebooks are no longer overwritten at other times.

Fixed

The terminal and file browser are now more responsive when working in a Cloud Storage bucket that is mounted through the file browser. Frequent background checks for non-existent files are now cached instead of repeatedly querying Cloud Storage, which previously could make actions such as listing files or running terminal commands take several seconds.

Fixed

Cloud Storage buckets that you mount through the file browser are now automatically re-mounted after the instance is restarted or is stopped and started. Previously the mounted folder could be left behind as an empty, unusable directory that had to be manually removed and re-mounted.

Change

Agent Platform Workbench instances internal agents now honor custom CA certificates installed on the host OS (e.g. via a custom VM image), fixing TLS certificate verification failures when Google API traffic is routed through a customer-managed proxy.

Google SecOps SOAR
Announcement

Release 6.3.99 is being rolled out to the first phase of regions as listed here.

This release contains internal and customer bug fixes.

August 29, 2026

Google SecOps SOAR
Announcement

Release 6.3.98 is now available for all regions.

August 28, 2026

Application Integration
Announcement

Upcoming authorization changes for integration runs

Application Integration is updating how identities are handled for integration runs. Every run will act as either the person who triggered it or a run-as service account that you configure, and running an integration will require permission to act as that service account. Integrations that run without a person, such as those started by a schedule or an event, will need an explicitly configured run-as service account.

Action might be required before the change takes effect. For guidance on identifying affected integrations and updating them, see Prepare for upcoming authorization changes.

Cloud Build
Feature

You can now update access tokens from the Connection details page for your 2nd generation Bitbucket and 2nd generation Gitlab host connections. For more information, see the following:

Gemini Enterprise
Feature

Gemini Enterprise: New data stores and support for new actions (Preview)

The following data stores are available in Public Preview in Gemini Enterprise:

You can search and read data from these data stores using natural language.

Additionally, the following data stores support new actions in Public Preview:

Looker
Announcement

From August 24 through August 26, 2026, the following features will be automatically enabled for Looker (original) instances running Looker 26.14.

Feature

The Advanced Unused Content Cleanup feature is now generally available.

Feature

Looker Continuous Integration (CI) can be triggered from GitLab CI, Bitbucket Pipelines, and GitHub Actions workflows by using the Looker API and the official Looker Python SDK (looker-sdk). For configuration steps and sample scripts, see the Admin settings - Continuous Integration documentation.

Note: This item was added on August 28, 2026 and changed from a non-breaking change to a feature on September 9, 2026.

Feature

Now available in preview, the visual modeling canvas lets you connect to BigQuery data sources to build and edit LookML data models using an interactive, drag-and-drop canvas. With the visual modeling canvas, you can visually join tables, define dimensions and measures, preview query results in real time, and publish Explores without writing LookML code.

For more information, see the Using the visual modeling canvas documentation page.

Note: This item was added on September 9, 2026.

Feature

Conversational Analytics verified queries, also known as golden queries, are now generally available. You can also now define verified queries in Looker (Google Cloud core) instances.

Feature

Now available in preview, model localization is supported for imported projects. By default, Looker uses the locale definitions from the importing project only, if the importing project has locale definitions. However, if you want to merge the locale definitions from an imported project with the locale definitions of the importing project, you can add the import_locale_defs: yesstatement to thelocalization_settings parameter in your importing project's manifest file. See the Localizing your LookML model documentation page for more information.

Note: This item was added on August 31, 2026 and changed from a non-breaking change to a feature on September 9, 2026.

Feature

You can now configure Continuous Integration to automatically run CI suites when a dbt Cloud CI job finishes. The CI suite run verifies whether changes in your dbt models will cause SQL errors in your Looker Explores before the dbt changes are deployed.

Feature

Now available in preview, the New/Edit Roles Enhancement feature provides a modernized, step-by-step interface for creating and editing roles on the Roles page in the Users section of the Admin panel.

Feature

Now available in preview, you can define and chat with data agents on a LookML dashboard. To use this feature, the Conversational Analytics and Enable Dashboard Agents settings must be enabled on the Gemini in Looker Admin page.

Feature

Now available in preview, you can define Looker-managed, in-database analytic models directly from existing LookML Explores by using the model_source subparameter of the derived_analytic_model parameter. Looker automatically translates your Explore topology, joins that are defined with foreign_key, dimensions, and measures into in-database analytic models (such as BigQuery Graphs or Snowflake semantic views).

For more information, see the derived_analytic_model parameter reference page.

Change

The Google Maps Enhancements preview feature now includes the following features:

The Dual-axis Map option now supports points and circles. You can now specify a custom map layer by providing a URL to a TopoJSON file.

Change

When the New Looker Explore and Merge Query Experience preview features are enabled, editing a merge query tile on a dashboard now opens the Join data page directly within the dashboard edit canvas, rather than opening a new tab.

Change

The Conversational Analytics System Activity dashboard Token usage tab now includes observability information about top users and top conversations by token usage. The tab also now indicates the type of data agent in its observability metrics.

Change

When connecting Looker to your database, you can specify additional Java Database Connectivity (JDBC) parameters. To maintain security, Looker restricts the allowed values for certain parameters. For the JDBC parameters that have a restricted set of allowed values, the allowed values are listed in the "Supported JDBC parameters" section of the database configuration instructions page for your dialect.

Fixed

Dashboard parameter filters now correctly respect manually restricted option lists when determining default values. This prevents filters from reverting to base LookML defaults that were intentionally hidden from the dashboard's user interface.

Fixed

Tiles that are on dashboard tabs will now run only when the dashboard tab that they are saved on is opened.

Announcement

Looker now supports connections to MongoSQL. Although existing connections to the legacy MongoDB Connector for BI are still fully supported, Looker recommends that you update MongoDB Connector for BI connections to use the MongoSQL dialect.

See the MongoDB documentation Transition from Atlas BI Connector to MongoSQL and the Looker documentation Migrating to MongoSQL for information on migrating from the MongoDB Atlas BI Connector to the newer MongoSQL Interface.

Note: One year before the MongoDB Connector for BI is to be deprecated, customers will be sent a service announcement to that effect. The information will also be reflected in product documentation and release notes.

Managed Service for Apache Airflow
Feature

Orchestration Pipelines are now generally available (GA).

Spanner
Feature

Spanner supports creating secondary indexes based on scalar expressions that apply to one or more table columns. Expression indexes eliminate the need to create and maintain a dedicated generated column in your table for indexing purposes. For more information, see Create an index based on a scalar expression.

August 27, 2026

Apigee X
Announcement

On August 27th, 2026, we released an updated version of Apigee (1-18-0-apigee-4).

Fixed
Bug ID Description
507878328 Upgraded the Apigee runtime to run on JDK 17, while maintaining backward compatibility with JDK 11.
530965355 Added an opt-in Message Processor connection-failure back-off (CWC property HTTPClient.backoff.enabled, defaults to false) that prevents the Message Processor from consuming excessive CPU when a target is completely unavailable.
532793298 Fixed an API product bug where combining a payloadOperationGroup with a REST or llmOperationGroup rejected REST/LLM traffic with a 401.
534420582 The JSONThreatProtection policy adds a new optional child element <RejectDuplicateKeys> that rejects request bodies containing duplicate JSON keys within the same object. Defaults to false to preserve existing behavior.
N/A Updates to infrastructure and libraries.

This list is incomplete; see entries for September 9, 2026 and September 10, 2026.

Security
Bug ID Description
544570126 Security fix for Apigee. Fixed a security issue in the PythonScript policy.
N/A Security fix for Apigee infrastructure.
BigQuery
Feature
Announcement

Core graph processing for BigQuery Graph requires an Enterprise or Enterprise Plus edition reservation. Existing allowlisted users can continue to use Standard edition or on-demand billing until April 26, 2027, after which these billing models will no longer be supported for core graph processing.

Graph measures will remain available in the Enterprise and Enterprise Plus editions and for queries run using on-demand pricing. Measures are not available in Standard edition.

Feature

You can now train models using XGBoost version 2.1 by using the XGBOOST_VERSION option. BigQuery uses the XGBoost 3.1.0 library to load and make predictions on XGBoost models. This feature is generally available.

Cloud Load Balancing
Feature

For regional external passthrough Network Load Balancers, reserving specific or automatically allocated bring your own IP (BYOIP) IPv6 addresses before creating a load balancer, and promoting an ephemeral BYOIP IPv6 address in use by a load balancer to a reserved static IP address, is generally available (GA).

For more information, see the following documentation:

Cloud SQL for MySQL
Feature

Cloud SQL now makes it easier to configure Private Service Connect for your Cloud SQL instance. When you create an instance that's enabled with Private Service Connect, you can choose to automatically create the service connection policy and endpoint in the VPC network that you want to use with Private Service Connect.

For more information, see Configure Private Service Connect.

Cloud SQL for PostgreSQL
Change

The rollout of the following extension upgrades is complete:

  • pg_partman is upgraded from 5.2.4 to 5.4.3.
  • pgfincore is upgraded from 1.3.1 to 1.4.
  • pgvector is upgraded from 0.8.1 to 0.8.5.

For more information, see Configure PostgreSQL extensions.

Feature

Cloud SQL now makes it easier to configure Private Service Connect for your Cloud SQL instance. When you create an instance that's enabled with Private Service Connect, you can choose to automatically create the service connection policy and endpoint in the VPC network that you want to use with Private Service Connect.

For more information, see Configure Private Service Connect.

Cloud SQL for SQL Server
Feature

Cloud SQL now makes it easier to configure Private Service Connect for your Cloud SQL instance. When you create an instance that's enabled with Private Service Connect, you can choose to automatically create the service connection policy and endpoint in the VPC network that you want to use with Private Service Connect.

For more information, see Configure Private Service Connect.

Cloud Service Mesh
Security

The following images are now rolling out for managed Cloud Service Mesh:

  • 1.21.6-asm.71 is rolling out to the rapid release channel.
  • 1.20.8-asm.119 is rolling out to the regular release channel.
  • 1.19.10-asm.109 is rolling out to the stable release channel.

These versions resolve the security vulnerabilities listed in Security Bulletin GCP-2026-057.

Cloud Trace
Feature

The following remote MCP server automatically generates a trace span for tools/call operations.

  • Datastream

These spans can help you understand the behavior of your agentic applications. For more information, see Investigate MCP calls using Trace.

Cluster Toolkit
Feature

Cluster Toolkit version v1.102.0 is available. This release enables Multi-Tier Checkpointing (MTC) when you create GKE clusters, and adds support for Flex unified volumes to NetApp Volumes modules. This release also updates Slurm blueprints to use OS image families, enables Distributed Resilient Architecture Network (DRANET) in example blueprints for A3 Ultra, A4, Cloud TPU v7x, and Cloud TPU v6e, and updates the Go toolchain to version 1.26. In addition, this release consolidates the lifecycle and queue management for Kueue, validates authorized CIDR ranges in GKE blueprints, enables gcluster job submission with VM boot disk fixes, and lets you disable Private Google Access for IPv6. For details, see the release announcement on GitHub.

Gemini Enterprise Agent Platform
Feature

CodeMender updates (v0.5.0)

This release introduces updates to CodeMender:

  • Model support: Support for Gemini 3.6 Flash (gemini-3.6-flash) and Gemini 3.7 Flash (gemini-3.7-flash, default).
  • Unrestricted verification: Added the --unrestricted flag to cm verify to bypass command policy restrictions during exploit verification in isolated environments.
  • Bug fixes:
    • Improved reliability of long sessions.
    • Improved shell resolution across operating environments.
    • Clearer permission denied error messages.
    • Fixed an issue where the CodeMender sandbox would fail to initialize with an error due to relative paths.

For more information, see CodeMender documentation.

Feature

Gemini Omni 1.1 Flash is available in Public Preview

Gemini Omni 1.1 Flash (gemini-omni-1.1-flash-preview) is available in Preview. Gemini Omni 1.1 Flash is a multimodal model designed for video, image, and text tasks, optimized for high-speed video generation that supports audio and video editing.

Google Cloud Armor
Security

Cloud Armor supports advanced match conditions to include attributes for inspecting request body content and parameters in Preview. This lets you write custom CEL rules to filter traffic based on raw body content, structured data (JSON, Form Data, GraphQL), and query parameters. For more information, see Configure custom rules language attributes.

Google Cloud Contact Center as a Service
Announcement

Google Cloud CCaaS 6.7

We've released version 6.7 of Google Cloud CCaaS.

The timing of the update to your instance depends on the deployment schedule that you have chosen. For more information, see Deployment schedules.

Feature

Bulk email status updates

You can use the new apps/api/v1/email/update_status endpoint to change the status of multiple email sessions to the status that you specify.

The new endpoint includes the following capabilities:

  • You can optionally specify the status that you expect email sessions to be in. Email sessions that aren't in that status aren't updated.

  • For each email session, the response reports whether it was updated, required no change, or couldn't be updated (and why). This means that integrations can handle partial success and identify which sessions still need attention.

For more information, see Bulk email status endpoint.

Fixed

This release addresses the following issues:

  • Fixed an issue where blended SMS transcripts were incorrectly identified as call audio recordings when uploaded to Customer Experience Insights, causing them to appear as missing or unanalyzable data.

  • Fixed an issue where the chat text-input field was unresponsive after an agent accepted a new chat.

  • Fixed an issue where call-cascade agent availability safeguards weren't enforced for terminal queue paths, which resulted in agents being assigned calls from secondary queues even when their primary queue fell below the minimum availability threshold.

  • Fixed an issue where chats that were connected to an agent continued to appear on the Queued Chats dashboard with a status of Ongoing.

  • Fixed an issue where direct inbound and dial-by-extension calls didn't reach an agent when multiple calls were waiting in the agent's queue.

  • Fixed an issue where chat messages from supervisors were incorrectly attributed to the end-user in Customer Experience Insights transcripts.

  • Fixed an issue where changes to hours of operation didn't appear in the Audit Dashboard.

  • Fixed an issue with Salesforce integrations where outbound calls were incorrectly labeled as Inbound and didn't pass the CCAI Platform call ID into Salesforce case activity comments.

  • Fixed an issue where requests for agent activity logs resulted in high database latency and gateway timeouts.

  • Fixed an agent desktop issue where an agent sent a chat form to an end-user but the end-user didn't receive it.

  • Fixed an issue where a chat that was escalated from a virtual agent to a human agent was stuck in the queue and couldn't be successfully offered to available agents.

  • Fixed an issue where the Queue dashboard displayed {{Count}} and {{Level}} variables instead of numerals.

  • Fixed an issue where the wait times API incorrectly reported zero available agents for chat queues that had agent availability.

  • Fixed an issue where the Queues > Calls dashboard didn't load and timed out for instances with a large number of queues.

  • Fixed an agent desktop issue where the sentiment score didn't appear in the call adapter in the agent desktop or in Salesforce for calls that were escalated from a virtual agent to a human agent.

  • Fixed an issue where newly created voice queues didn't correctly inherit the global whisper and countdown settings.

  • Fixed an issue where queue duration metrics incorrectly included IVR timeout time for calls that were cold transferred into a closed queue.

  • Fixed an issue where an agent who reopened a previously read voicemail was stuck in In-call status, preventing them from accepting new contacts or changing their status.

  • Fixed an issue where an agent's assigned call ID was cleared during wrap-up, which prevented them from submitting their wrap-up disposition after refreshing the page.

Google Cloud Managed Service for Apache Kafka
Feature

You can now configure the disk capacity per broker when you create a Kafka cluster and increase it later. For more information, see Configure broker disk size.

Google Kubernetes Engine
Feature

Network Endpoint Group (NEG) pre-provisioning is now available in Preview. With this feature, you can force the creation of empty zonal GCE_VM_IP_PORT NEGs in specified zones (or all zones within a region) during Service creation, regardless of whether the cluster has nodes in those zones. By extending the cloud.google.com/neg Service annotation with a custom zones parameter, you can seamlessly automate infrastructure deployments (such as attaching NEGs to backend services) without waiting for workloads to deploy. For more information, see Pre-provisioning empty NEGs.

Google SecOps
Announcement

Scheduled maintenance

SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 30. During this window, your system will experience a brief period of downtime. You don't need to take any action.

Google SecOps SOAR
Announcement

Scheduled maintenance

SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 30. During this window, your system will experience a brief period of downtime. You don't need to take any action.

Model Armor
Feature

You can disable data residency enforcement for in-use and in-transit data in Model Armor templates. Disabling data residency enforcement allows cross-jurisdictional routing to enable Model Armor features that are otherwise unavailable in limited-support regions. Data at rest remains compliant with data residency requirements.

For more information, see Set data residency compliance and Data residency and endpoints.

Virtual Private Cloud
Feature

General Availability: VPC Flow Logs generates log records for dropped traffic. For more information, see Records for dropped traffic.

Feature

General Availability: You can reserve static external IPv6 addresses from bring your own IP addresses (BYOIP) sub-prefixes that are in EXTERNAL_IPV6_FORWARDING_RULE_CREATION mode.

You can assign these addresses to forwarding rules for external passthrough Network Load Balancers and external protocol forwarding. You can also promote ephemeral IPv6 BYOIP addresses that are used by external forwarding rules to reserved static IP addresses.

For more information, see Create external forwarding rules.

August 26, 2026

Apigee hybrid
Announcement

v1.14.8

On August 26, 2026 we released an updated version of the Apigee hybrid software, v1.14.8.

Security
Bug ID Description
N/A Security fixes for apigee-asm-ingress.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-asm-istiod.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-connect-agent.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-fluent-bit.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra-client.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-mart-server.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-mint-task-scheduler.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-operators.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-prom-prometheus.
This addresses the following vulnerability:
N/A Security fixes for apigee-prometheus-adapter.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-redis.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-runtime.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-synchronizer.
This addresses the following vulnerabilities:
N/A Security fixes for apigee-watcher.
This addresses the following vulnerabilities:
BigQuery
Security

An Improper Input Validation vulnerability was discovered in the JDBC driver in BigQuery Data Transfer Service versions prior to May 1, 2026. An authenticated attacker could use crafted JDBC connection string parameters to achieve remote code execution in the connector container and escalate privileges in the tenant project. For more information, see the GCP-2026-056 security bulletin.

Feature

You can now view real-time logs for your Python UDFs in Cloud Logging. This feature is generally available.

Cloud Load Balancing
Feature

SSL policy cross-project referencing is now available for Application Load Balancers and proxy Network Load Balancers in Preview. You can use cross-project referencing to define and maintain a central SSL policy in an administrative project and reference it from target HTTPS proxies or target SSL proxies in different projects.

Cross-project referencing is supported for global and regional SSL policies. You can use cross-project referencing with the following load balancers:

  • Global external Application Load Balancer
  • Regional external Application Load Balancer
  • Cross-region internal Application Load Balancer
  • Regional internal Application Load Balancer
  • Global external proxy Network Load Balancer

For more information, see Cross-project SSL policy referencing.

Cloud Logging
Change

VM Extension Manager extension policies for the Ops Agent are Generally Available (GA). Extension policies provide zonal and project-wide Ops Agent installation, version upgrades, and configuration management. For more information, see Install and manage the Ops Agent by using VM Extension Manager policies.

Cloud Monitoring
Change

VM Extension Manager extension policies for the Ops Agent are Generally Available (GA). Extension policies provide zonal and project-wide Ops Agent installation, version upgrades, and configuration management. For more information, see Install and manage the Ops Agent by using VM Extension Manager policies.

Cloud Service Mesh
Announcement

1.29.7-asm.2 is now available for in-cluster Cloud Service Mesh.

For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.29.7-asm.2 uses Envoy v1.35.14.

This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057.

Fixed

Patch 1.29.7-asm.2 contains the fix for the following platform CVEs:

CVE Proxy Control Plane Distroless CNI Severity
CVE-2026-5704 Yes Yes No Yes Medium (5.5)
Announcement

1.28.10-asm.24 is now available for in-cluster Cloud Service Mesh.

For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.10-asm.24 uses Envoy v1.36.10.

This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057.

Fixed

Patch 1.28.10-asm.24 contains the fix for the following platform CVEs:

CVE Proxy Control Plane Distroless CNI Severity
CVE-2026-5704 Yes Yes No Yes Medium (5.5)
Announcement

1.27.9-asm.34 is now available for in-cluster Cloud Service Mesh.

For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.34 uses Envoy v1.35.14.

This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057.

Fixed

Patch 1.27.9-asm.34 contains fixes for the following platform CVEs:

CVE Proxy Control Plane Distroless CNI Severity
CVE-2026-10536 Yes Yes No Yes Low (9.8)
CVE-2026-42151 No No No Yes High (7.5)
CVE-2026-42154 No No No Yes High (7.5)
CVE-2026-40179 No No No Yes Medium (6.1)
CVE-2026-44903 No No No Yes Medium (6.1)
CVE-2026-5704 Yes Yes No Yes Medium (5.5)
Feature

For clusters using the TRAFFIC_DIRECTOR implementation, configuring the trace sampling rate with randomSamplingPercentage with the Telemetry API is now supported in the Rapid release channel. For more information, see Accessing Cloud Trace.

Cloud Workstations
Feature

Cloud Workstations supports an agent-optimized development experience.

Compute Engine
Feature

Generally available: Red Hat Enterprise Linux (RHEL) images pre-configured with Logical Volume Manager (LVM) partitioning are available for Compute Engine in the Google Cloud console. LVM-enabled images let you manage volumes flexibly and size partitions dynamically on your boot disk.

For more information, see Red Hat Enterprise Linux (RHEL).

Feature

Generally available: Red Hat Enterprise Linux (RHEL) Extended Update Support (EUS) images are available for Compute Engine in the Google Cloud console. RHEL EUS images let you lock your VMs to a specific minor version while receiving critical security updates and bug fixes for up to two years.

For more information, see Red Hat Enterprise Linux (RHEL).

Cortex Framework
Announcement

Release 7.0.4

Fixed
  • Removed unused dependencies (pandas, pytest-bigquery-mock) and lockfile cleanup.
Gemini
Other

Bug fixes in VS Code

Various bug fixes and minor product enhancements.

Gemini Enterprise
Feature

Gemini Enterprise: Updates to A2UI Material catalog component properties

The A2UI component gallery reference has been updated to reflect the latest A2UI version v0.9 Material catalog component properties and schema:

  • MaterialButton: Added support for Material 3 styling properties (appearance, disableRipple, and extended), along with new variants (icon, fab, and mini-fab). Obsolete color and ARIA description properties have been removed.
  • Validation checks: Replaced the static required boolean property across input components (MaterialCheckbox, MaterialDatepicker, MaterialInput, MaterialSelect, and MaterialTimepicker) with the reactive validation checks rule array.
  • MaterialIcon and MaterialChips: Added the tooltip property on MaterialIcon and the action property on MaterialChips.
  • Layout and input types: Documented all supported justify alignment values for MaterialColumn and MaterialRow, and updated allowed input types for MaterialInput.

For more information, see A2UI component gallery reference.

Google Kubernetes Engine
Change

(2026-R36) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

  • Version 1.35.7-gke.1027000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.9-gke.1655001
    • 1.35.6-gke.1710000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • Version 1.34.9-gke.1655001 is now available in the Stable channel.
  • Version 1.34.9-gke.1322001 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
    • GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
    • GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:

Extended channel

No channel (deprecated)

Security

(2026-R36) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2630000 cos-117-18613-675-56 cos-117-18613-675-56 release notes
1.34.10-gke.1328000 cos-125-19216-532-123 cos-125-19216-532-123 release notes
1.35.8-gke.1026000 cos-125-19216-532-123 cos-125-19216-532-123 release notes
1.37.0-gke.2034000+preview cos-129-19506-299-82 cos-129-19506-299-82 release notes

Change

(2026-R36) Version updates

  • Version 1.34.9-gke.1655001 is now available in the Stable channel.
  • Version 1.34.9-gke.1322001 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
    • GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
    • GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
Change

(2026-R36) Version updates

  • Version 1.35.7-gke.1027000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.34.9-gke.1655001
    • 1.35.6-gke.1710000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Change

(2026-R36) Version updates

Change

(2026-R36) Version updates

Feature

In GKE version 1.36 and later, GCPAuthzPolicy and GCPAuthzExtension resources for GKE Gateway are now available in Preview. You can use these resources to enforce identity-based access control and zero-trust authorization on incoming traffic at the Gateway layer. These capabilities are supported on the following GatewayClasses:

  • gke-l7-global-external-managed
  • gke-l7-regional-external-managed
  • gke-l7-rilb

For more information, see Configure the GCPAuthzExtension resource.

Change

(2026-R36) Version updates

Google SecOps
Feature

[Spotlight Feature] Mandiant Frontline Threats rule packs

Curated Detections has been enhanced with additional Mandiant Frontline Threats detections for Linux, MacOS, and Google Cloud. The following rule packs have been added to the Content Hub:

Google SecOps Marketplace
Feature

FireEye HX: Version 26.0

  • Added the following new actions:
    • Get File
    • Check Containment Status
  • Added the Agent Id input parameter to the following actions:
    • Contain Host
    • Cancel Host Contain
Feature

Proofpoint Email Protection: Version 11.0

  • Added the following new actions:
    • Forward Quarantined Email
    • Release Quarantined Email
Feature

Wiz: Version 10.0

  • Added the Authentication URL parameter to support Gov (FedRAMP) and custom environments.
  • Added the following new job:
    • Wiz and Google SecOps Bi-directional Sync Job
Change

Microsoft Graph Mail: Version 46.0

  • Updated parameters and filtering options in the following actions:
    • Wait For Email From User
    • Search Emails
Change

Microsoft Graph Mail Delegated: Version 23.0

  • Updated parameters and filtering options in the following actions:
    • Wait For Email From User
    • Search Emails
Change

ServiceNow: Version 71.0

  • Added support for OAuth authentication in the following job:
    • Sync Incidents Job
Google SecOps SIEM
Feature

[Spotlight Feature] Mandiant Frontline Threats rule packs

Curated Detections has been enhanced with additional Mandiant Frontline Threats detections for Linux, MacOS, and Google Cloud. The following rule packs have been added to the Content Hub:

Knowledge Catalog
Feature

Knowledge Catalog support for importing metadata from dbt Core and MetricFlow is available in Preview.

You can use the gcloud alpha dataplex dbt metadata-jobs command to extract and import technical, semantic (MetricFlow), operational, data quality, and lineage metadata from dbt Core artifacts into Knowledge Catalog.

For more information, see Import metadata from dbt Core and About metadata connectors.

Managed Service for Apache Airflow
Feature

(Airflow 3.3.1 and 3.2.2) Environments with Airflow 3.3.1 and 3.2.2 now support loading snapshots from environments with Airflow 2.11.1. This feature lets you migrate from Airflow 2.11.1 environments to Airflow 3 using snapshots, provided that your DAGs in Airflow 2.11.1 are compatible with Airflow 3.

This feature is gradually rolling out over several releases. In this release, it's available in the following regions: europe-north1, europe-west3, us-east1, and us-west2.

Fixed

(Airflow 3.3.1) Backported #71091 to fix a warning about invalid characters for stats reporting generated by the DAG processor for every file.

Change

New images are available in Managed Airflow (Gen 2):

Deprecated

The following Managed Airflow versions and builds have reached their end of support period: composer-3-airflow-2.9.3-build.32, composer-3-airflow-2.10.5-build.12, composer-2.14.0-airflow-2.10.5, composer-2.14.0-airflow-2.9.3.

Oracle on Google Cloud Compute
Feature

Oracle on Google Cloud Compute supports running Oracle workloads on Compute Engine's M4N machine series that provides leading block storage performance with Hyperdisk Extreme. For more information, see M4N machine series and Available regions and zones.

This feature is Generally Available (GA).

Feature

Oracle on Google Cloud Compute offers in-depth documentation that describes how to deploy Oracle AI Database workloads using Google Cloud NetApp Volumes. For more information, see Overview of Oracle Database deployment using NetApp Volumes.

VPC Service Controls
Feature

Preview stage support for the following integration:

August 25, 2026

Access Approval
Feature

Gemini Data Analytics is generally available (GA).

Access Transparency
Feature

Gemini Data Analytics is generally available (GA).

BigQuery
Feature

BigQuery data governance tags are supported in Terraform. This feature is in Preview.

Cloud Run
Feature

Cloud Run instances are available in Preview. Instances are specifically designed for running long-lived and individually addressable workloads. To learn more, see the product overview, resource comparison, and instance lifecycle pages.

Cloud SQL for PostgreSQL
Feature

Use assessments (Preview) in Database Center to assess and test the performance impact of database recommendations before you apply them to your production database fleet.

The assessments workflow performs these operations:

  • Clones your database instance.
  • Runs benchmarking simulation tests on the clone.
  • Compares the baseline performance of the clone against the performance after you apply the recommended configuration changes.

For more information, see Assessments in Database Center.

Database Center
Feature

Use assessments (Preview) in Database Center to assess and test the performance impact of database recommendations before you apply them to your production database fleet.

The assessments workflow performs these operations:

  • Clones your database instance.
  • Runs benchmarking simulation tests on the clone.
  • Compares the baseline performance of the clone against the performance after you apply the recommended configuration changes.

Database Center assessments are available only for Cloud SQL for PostgreSQL instances.

For more information, see Create an assessment of a recommendation.

Google Distributed Cloud (software only) for VMware
Announcement

Google Distributed Cloud (software only) for VMware 1.36.0-gke.532 is now available for download. To upgrade, see Upgrade a cluster. Google Distributed Cloud 1.36.0-gke.532 runs on Kubernetes v1.36.0-gke.2800.

If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.

After a release, it takes approximately 7 to 14 days for the version to become available for use with GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

Feature

Google Distributed Cloud (software only) for VMware includes the following feature enhancements:

  • Updated the Kubernetes version to 1.36.
  • Upgraded containerd from 2.1 to 2.2
  • Updates vSphere support to vSphere version 9.0 and 9.1 and removes support for vSphere version 7.0.
  • Updated gkectl to perform an empty reconciliation health check prior to running the gkectl update or gkectl upgrade commands. The health check prevents starting cluster lifecycle updates when a cluster is in an unhealthy state.
  • Improved the status and conditions fields in OnPrem custom resources to provide clearer visibility into cluster reconciliation phases and state transitions during cluster management operations.
  • Updated gkectl to provide more specific error messages and actionable troubleshooting recommendations when operations encounter failures.
  • Expanded pre-upgrade validation checks to proactively identify potential configuration or cluster health blockers prior to upgrade initiation.
  • This release supports resilient, idempotent migrations to advanced clusters, enabling interrupted upgrades to safely resume without risking cluster degradation or state loss. This update also introduces preflight health checks, improves gkectl error diagnostics, and resolves key behavioral discrepancies in workload scheduling, proxy parsing, and logging.
Fixed

The following issues were fixed in 1.36.0-gke.532:

  • Fixed vulnerabilities listed in Vulnerability fixes.
  • Fixed an issue where user clusters remained stuck in a Reconciling state after an admin cluster upgrade. The admin cluster controller skipped reconciling legacy cluster lifecycle components during upgrades unless an initial migration annotation was set. If legacy user clusters still existed on the admin cluster, missing legacy API discovery (cluster.k8s.io/v1alpha1) caused controller reconciliation to stall. With this fix, the controller preserves legacy components as long as any legacy user clusters exist, and prunes them only after all user clusters have migrated to advanced clusters.
  • Fixed an issue where gkectl prepare failed with a permission denied error when attempting to read a private registry CA certificate. The certificate file permissions are now set to 644 so non-root processes can read it.
  • Fixed an issue where retrying a failed upgrade to an Advanced Cluster (such as re-running with an existing bootstrap cluster) could wipe or strip the encryption keys in the generated-key-kms-plugin-config secret, preventing the control plane from decrypting existing Kubernetes secrets in etcd.
  • Fixed an issue where upgrading a user cluster with Anthos Network Gateway (ANG) enabled to an Advanced Cluster would stall or fail. Previously, the upgrade process attempted to modify immutable spec.selector fields on existing ANG resources. The upgrade operator now preserves existing label selectors during reconciliation so that V1 to V2 cluster migrations complete successfully.
  • Updated cluster-proportional-autoscaler to address security vulnerabilities.
  • Fixed an issue where recreating a user cluster using a previously used name caused cluster provisioning to stall indefinitely in the PROVISIONING state because of a missing k8s-health-check service account.
  • Fixed an issue where gkectl diagnose failed to run on non-advanced user clusters managed by an advanced admin cluster.
  • Fixed an issue where creating a cluster on the root of a vSAN datastore failed during data disk creation because the installer used an unsupported API for top-level vSAN directory creation.
  • Fixed an issue where control plane quorum restore stalled or failed due to IP address collisions. After the fix, gkectl restore quorum recreates missing IPAddress objects for VSphereMachine resources before waiting for cluster readiness.
  • Fixed an issue where enabling generated key secrets encryption (KMSv1) during Day 2 cluster updates failed or got stuck in an infinite reconciliation loop.
  • Fixed an issue where setting stackdriver.disableVsphereResourceMetrics to true caused cluster installations or upgrades to stall because the vsphere-ca-certificate ConfigMap was deleted, but still needed.
Google Distributed Cloud (software only) for bare metal
Announcement

Google Distributed Cloud (software only) for bare metal 1.36.0-gke.532 is now available for download. To upgrade, see Upgrade clusters. Google Distributed Cloud for bare metal 1.36.0-gke.532 runs on Kubernetes v1.36.0-gke.2800.

After a release, it takes approximately 7 to 14 days for the version to become available for installations or upgrades with the GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

If you use a third-party storage vendor, check the listing of our previously-qualified storage partners.

Feature

Google Distributed Cloud (software only) for bare metal includes the following feature enhancements:

  • Upgraded the Ansible version to 2.18. This version requires Python 3.8+ on target nodes. Because RHEL 8 defaults to Python 3.6, you must have Python 3.9 installed on nodes using RHEL 8.10. RHEL 8.8 is no longer supported.
  • Updated the Kubernetes version to 1.36.
  • Upgraded containerd from 2.1 to 2.2
  • Containerd is required for new cluster installations and cluster migrations to Node Agent mode.
  • Added support for the layer 4 gateway controller.
  • bmctl backup cluster in Node Agent mode requires at least 12 GB of free space in /tmp on the admin workstation and all target nodes to buffer backup archives. You can configure a custom temporary directory by setting TMPDIR.
  • If you use Node Agent and receive an error that creating the backup fails to create an archive file, you might need 12 GBs of free space in the /tmp directory on the admin node and all target nodes. For more information, see Can't create a backup for a Node Agent node .
  • Removed the deprecated anthos-metadata-agent component that kubestore-collector replaced.
  • Removed the deprecated csi-snapshot-validation-webhook component. Upstream Kubernetes validation is now handled natively via Common Expression Language (CEL) rules within the deployed Custom Resource Definitions (CRDs). For more information, see Volume snapshots.
  • Vertical pod autoscaling is generally available. For more information, see Configure vertical Pod autoscaling
  • Unified registry mirror and private registry update behavior across all cluster types while preserving configurations.
Fixed

The following issues were fixed in 1.36.0-gke.532:

  • Fixed vulnerabilities listed in Vulnerability fixes.
  • Fixed an issue where CA certificate secrets with identical names across different namespaces stalled cluster upgrades. In this release, the system automatically prepends the target namespace prefix to all the CA certificate secret names when forwarding them to the destination namespace. The prefix makes sure each CA certificate secret name is unique so the upgrade doesn't stall.
  • Fixed an issue where Certificate Authority (CA) rotation failed for self-managing clusters (admin, hybrid, and standalone). The failure occurs during the final phase of the rotation when attempting to move management resources back from the temporary bootstrap cluster to the self-managing cluster, which can leave the cluster in an unmanageable state. You must upgrade your clusters to version 1.33.1000-gke.59 before you rotate your CAs.
  • Fixed an issue where the status for Ingress resources didn't update when using bundled ingress.
  • Fixed an issue where rolling back a node pool failed because stale Cluster API (CAPI) bootstrap secrets retained deprecated kubelet flags.
  • Updated cluster-proportional-autoscaler to address security vulnerabilities.
  • Fixed an issue where etcd-events installation entered an infinite retry loop during machine initialization due to incomplete cleanup of the data directory after a learner promotion failure.
  • Fixed an issue where the NodePool controller prematurely updated Status.ManagedFields on partial reconciliation failures, causing removed taints and labels to remain stranded on affected nodes.
  • Fixed an issue where recreating a user cluster using a previously used name caused cluster provisioning to stall indefinitely in the PROVISIONING state because of a missing k8s-health-check Service account.
  • Fixed an issue where restarting kube-apiserver during etcd encryption updates abruptly terminates the container, causing stale service endpoints and transient connection failures for in-cluster workloads.
  • Fixed an issue where the installer stalled for three minutes per control plane node during certificate rotation or etcd encryption updates because of an incorrect kube-apiserver container termination check.
Google Kubernetes Engine
Fixed

Fixed the issue in which GPUDirect-TCPX for a3-highgpu-8g machine types was incompatible with the Linux kernel version that was used by Container-Optimized OS in GKE version 1.34 and later. To prevent errors, GKE blocked creating or upgrading node pools that used the a3-highgpu-8g machine type to version 1.34 or later. For more information about this issue, see GKE known issues.

You can now create or upgrade node pools that use the a3-highgpu-8g machine type to any of the following GKE versions. Automatic upgrades of these node pools from version 1.33 to version 1.34 or later are no longer blocked.

  • For minor version 1.34, use patch version 1.34.5-gke.1153000 or later.
  • For minor version 1.35, use patch version 1.35.2-gke.1485000 or later.
  • For minor version 1.36 and later, use any available patch version.

In GKE version 1.34 and later, you must use version 3.1.9 or later of the GPUDirect-TCPX installer and version 2.0.12 or later of the GPUDirect-TCPX sidecar. If you previously installed these components, verify that the container images use these versions or later. To avoid degraded performance or workload failures, update your installer and sidecar image versions before the a3-highgpu-8g node pools are manually or automatically upgraded to version 1.34 or later. These container image versions correspond to the upstream definitions maintained in the gpudirect-tcpx GitHub repository.

Managed Service for Apache Airflow
Feature
Feature

Managed Airflow Agent is now available in Google Cloud Console. The agent can help you understand, diagnose, and resolve issues with failed Airflow tasks and DAG runs, optimize your environment's performance, identify existing or potential issues, bottlenecks, and areas for optimization.

Managed Service for Apache Spark
Announcement

New Managed Service for Apache Spark (formerly Google Cloud Serverless for Apache Spark) subminor runtime version:

  • 3.0.14 (image 3.0.20260809_212300-RC01-spark)

Key updates in this runtime version include:

  • Upgraded Cloud Storage Connector to version 3.1.16.
  • Upgraded Conda installer to Miniforge3 25.9.1.
  • Upgraded OpenLineage to version 1.49.1 to support lineage for tables created using the Lakehouse Runtime catalog, and fixed a segmentation fault when OpenLineage parses complex SQL query strings.
  • Upgraded Spark RAPIDS to version 26.04.2.
  • Upgraded Metastore Proxy to version v0.0.79.
Model Armor
Feature

Model Armor supports screening prompts and responses up to 65,536 tokens (262,144 characters) for prompt injection and jailbreak detection, responsible AI, and child sexual abuse material (CSAM) filters. Model Armor scans only the first 256 URLs found in prompts and responses.

For more information, see Token system limits.

reCAPTCHA
Change

Fraud Defense Mobile SDK v18.10.0-beta01 is available for iOS. This version includes the following:

  • Adds support for macOS desktop and tvOS.
  • Improvements to networking consumption.
  • Improvements to latency and reliability.

August 24, 2026

Anthos Config Management
Change

Addressed multiple Common Vulnerabilities and Exposures (CVEs) by updating dependencies.

Feature

You can now disable monitoring for specific custom RootSync or RepoSync objects by setting the spec.monitoring.enabled field to false. This disables metric telemetry collection and exporting for that reconciler, which can help reduce cluster resource consumption. For more information, see Disable monitoring.

Anti Money Laundering AI
Announcement

New minor engine versions released for the commercial line of business within the v004.009 and v004.010 version lines (aml-commercial.default.v004.009.202608-000 and aml-commercial.default.v004.010.202608-000). These versions extend support for the major engine version and include no significant changes compared to the previous minor versions.

Backup and DR
Feature

Backup vault support for Filestore instances encrypted with customer-managed encryption keys (CMEK) is now generally available (GA). When you back up Filestore instances to a CMEK-enabled backup vault, the backups are encrypted using the backup vault CMEK key.

For more information, see Customer-managed encryption keys (CMEK), Back up Filestore instances to a backup vault, and Restore a Filestore instance from a backup vault.

BigQuery
Feature

You can now monitor the performance, adoption, latency, and costs of your data agents and their conversations by using Google Cloud Observability in BigQuery. This feature is in Preview.

Cloud Build
Security

An Incorrect Authorization vulnerability CVE-2026-19410, in GitHub Trigger Comment Control in Cloud Build, was fixed. No customer action is needed.

Cloud Key Management Service
Feature

Cloud KMS supports deleting key rings in General Availability.

For more information about deleting Cloud KMS resources, see Delete Cloud KMS resources.

Cloud Trace
Feature

You can update the display name, description, and Cloud KMS key applied to a _Trace observability bucket.

For more information, see Update observability buckets.

Feature

You can manually create the _Trace observability bucket before your project receives trace data. When creating the bucket, you must specify a storage location. Google Cloud Observability applies the Cloud KMS key defined in your default settings unless you explicitly specify a different key in your create request.

For more information, see the following documents:

Feature

The following remote MCP servers automatically generate a trace span for tools/call operations.

  • Policy Troubleshooter
  • Managed Service for Apache Airflow

These spans can help you understand the behavior of your agentic applications. For more information, see Investigate MCP calls using Trace.

Config Controller
Change

Config Controller now uses the following versions of its included products:

Container Optimized OS
Change

cos-121-18867-528-78

Kernel Docker Containerd GPU Drivers
COS-6.6.143 v27.5.1 v2.0.10 See List
Fixed

Added support for net-fs/lustre-client-drivers v2.14.0_p259.

Fixed

Upgraded app-admin/google-guest-configs to v20260804.00.

Fixed

Upgraded app-arch/zstd to v1.5.7-r1.

Fixed

Upgraded app-shells/dash to v0.5.13.5.

Fixed

Upgraded dev-libs/expat to v2.8.3.

Fixed

Upgraded dev-libs/libverto to v0.3.2-r1.

Fixed

Upgraded dev-libs/popt to v1.19-r1.

Fixed

Upgraded dev-libs/xxhash to v0.8.3-r2.

Fixed

Upgraded sys-apps/acl to v2.4.0-r2.

Fixed

Upgraded sys-apps/xemu to v0.0.10.

Fixed

Upgraded sys-process/lsof to v4.99.7.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68129 in the linux kernel

Security

Fixed CVE-2026-68146 in the Linux kernel.

Security

Fixed CVE-2026-68149 in the Linux kernel.

Security

Fixed CVE-2026-68171 in the Linux kernel.

Security

Fixed CVE-2026-68299 in the Linux kernel.

Security

Fixed CVE-2026-68329 in the Linux kernel.

Security

Fixed KCTF-0650f1c in the Linux Kernel.

Change

cos-117-18613-675-64

Kernel Docker Containerd GPU Drivers
COS-6.6.143 v24.0.9 v1.7.34 See List
Fixed

Added support for net-fs/lustre-client-drivers v2.14.0_p259.

Fixed

Upgraded sys-apps/xemu to v0.0.10.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68116 in the Linux kernel.

Security

Fixed CVE-2026-68129 in the linux kernel

Security

Fixed CVE-2026-68146 in the Linux kernel.

Security

Fixed CVE-2026-68147 in the Linux kernel.

Security

Fixed CVE-2026-68149 in the Linux kernel.

Security

Fixed CVE-2026-68171 in the Linux kernel.

Security

Fixed CVE-2026-68325 in the Linux kernel.

Security

Fixed CVE-2026-68386 in the Linux kernel.

Security

Fixed CVE-2026-68428 in the Linux kernel.

Security

Fixed KCTF-0650f1c in the Linux Kernel.

Change

cos-129-19506-299-161

Kernel Docker Containerd GPU Drivers
COS-6.12.94 v27.5.1 v2.2.6 See List
Change

Updated cos-gpu-installer to v2.7.7.

Fixed

Added support for net-fs/lustre-client-drivers v2.14.0_p259.

Fixed

Upgraded sys-apps/xemu to v0.0.10.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68129 in the linux kernel

Security

Fixed CVE-2026-68146 in the Linux kernel.

Security

Fixed CVE-2026-68325 in the Linux kernel.

Security

Fixed CVE-2026-68338 in the Linux kernel.

Security

Fixed CVE-2026-68422 in the Linux kernel.

Security

Fixed KCTF-0650f1c in the Linux Kernel.

Change

cos-125-19216-532-135

Kernel Docker Containerd GPU Drivers
COS-6.12.94 v27.5.1 v2.2.7 See List
Change

Updated cos-gpu-installer to v2.7.7.

Fixed

Added support for net-fs/lustre-client-drivers v2.14.0_p259.

Fixed

Upgraded sys-apps/xemu to v0.0.10.

Security

Fixed CVE-2026-68093 in the Linux kernel.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68096 in the Linux kernel.

Security

Fixed CVE-2026-68129 in the linux kernel

Security

Fixed CVE-2026-68296 in the Linux kernel.

Security

Fixed CVE-2026-68386 in the Linux kernel.

Security

Fixed KCTF-0650f1c in the Linux Kernel.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068

Gemini Enterprise
Feature

Gemini Enterprise: D&B Commercial Graph data store (Preview)

The D&B Commercial Graph data store is available in Public Preview in Gemini Enterprise. You can connect D&B Commercial Graph to search and import company data using natural language.

For more information, see Connect D&B Commercial Graph.

Feature

Gemini Enterprise: Cloud Monitoring observability for data connectors

Cloud Monitoring telemetry for Gemini Enterprise data connectors (also referred to as data stores) has been updated with support for new metric dimensions and a new latency metric:

  • The discoveryengine.googleapis.com/dataconnector/request_count count metric has been updated to include three new dimensions: tool_id (the identifier of the connector tool invoked), engine_id (the Gemini Enterprise app identifier), and response_code (the gRPC response status). The existing status dimension remains supported.
  • A new latency metric, discoveryengine.googleapis.com/dataconnector/request_latencies (Beta), is available to monitor the distribution of tool invocation latency in milliseconds. It includes the dimensions status, response_code, tool_id, and engine_id.

For more information, see Access metrics.

Gemini Enterprise Agent Platform
Feature

GLM 5.2 is available in Public Preview

GLM 5.2 from Z.ai is available as a fully managed model (MaaS) in Model Garden. The model targets long-horizon agentic and coding tasks and supports a 1M-token context window.

For more information, see GLM 5.2.

Google Cloud VMware Engine
Announcement

VMware component updates: The VMware Engine operations team is updating vCenter Server and ESXi to version 8.0 Update 3k to address security vulnerabilities described in Broadcom Security Advisory VMSA-2026-0006. For details about the update and schedule, see the Latest service announcements.

Google SecOps
Feature

Unroll Processor for Data Processing Pipelines

Google SecOps data processing pipelines now support the Unroll processor (event breaking). This processor allows you to split log entries containing arrays or slices of events into multiple individual log events prior to parsing and ingestion.

Key details:

  • Event Breaking Capability: Automatically expands log arrays into discrete log events.
  • Pre-parsing Requirement: The Unroll processor requires structured data inputs. Raw string payloads must first be parsed using a Transform processor (e.g., set(body, ParseJSON(body))) positioned prior to the Unroll processor in the pipeline execution sequence.

For details on configuring data processing pipelines and processors, see Set up and manage data processing pipelines.

Feature

[Spotlight Feature] Operations in Emerging Threats Center

Google SecOps now supports Operations in the Emerging Threats Center feed to provide rapid visibility into threat activity details involving the targeting of a single organization. Operations complement global Campaigns by providing granular threat intelligence derived from frontline investigations, such as Managed Threat Defense (MTD) engagements. For more information, see Operations in Emerging Threats.

Key capabilities include:

  • Focused threat insights: Zero in on localized adversary activity and personalized attack vectors specific to individual missions.
  • Holistic threat mapping: View Operations alongside global Campaigns to see the full scope of adversary tactics, techniques, and procedures (TTPs).
Google SecOps SIEM
Feature

Unroll Processor for Data Processing Pipelines

Google SecOps data processing pipelines now support the Unroll processor (event breaking). This processor allows you to split log entries containing arrays or slices of events into multiple individual log events prior to parsing and ingestion.

Key details:

  • Event Breaking Capability: Automatically expands log arrays into discrete log events.
  • Pre-parsing Requirement: The Unroll processor requires structured data inputs. Raw string payloads must first be parsed using a Transform processor (e.g., set(body, ParseJSON(body))) positioned prior to the Unroll processor in the pipeline execution sequence.

For details on configuring data processing pipelines and processors, see Set up and manage data processing pipelines.

August 23, 2026

Agent Platform Workbench
Change

20260823-2330-rc0 Release

Change

20260823-2330-rc0 Release

Change

Installed latest packages from upstream dependencies.

Change

Installed latest packages from upstream dependencies.

Change

20260823-2230-rc0 Release

Change

20260823-2230-rc0 Release

Change

Installed latest packages from upstream dependencies.

Change

Installed latest packages from upstream dependencies.

Change

20260823-2130-rc0 Release

Fixed

Scheduled notebook executions now report their final status when the execution user's credentials stop working part way through a run, instead of continuing until the execution timeout.

Change

Installed latest packages from upstream dependencies.

Change

M147 Release

Fixed

Scheduled notebook executions now report their final status when the execution user's credentials stop working part way through a run, instead of continuing until the execution timeout.

Change

Installed latest packages from upstream dependencies.

August 22, 2026

Apigee UI
Fixed
Bug ID Description
543626585

ServiceCallout policy can now be added in the Apigee UI

Adding a ServiceCallout policy in the Apigee UI no longer leaves the Create or Add button disabled.

Previously, selecting Service Callout in the Create policy or Add policy panel could display only the Name and Display name fields and omit the required HTTP target field. With the required field missing, the form never became valid, so the Create or Add button stayed disabled no matter what you entered. This affected both API proxies and shared flows.

The earlier workaround of creating a placeholder policy and replacing its XML in the code editor is no longer needed. For more information, see ServiceCallout policy and Attach and configure policies in the UI.

Fixed
Bug ID Description
540008387

Developer custom attributes now save reliably in the Apigee UI

Saving changes to a developer in the Apigee UI in Cloud console no longer intermittently fails to persist that developer's custom attributes.

Previously, the UI reported the save as successful, but the previous attribute values reappeared when the page was reloaded. Developer updates made with the Apigee API were not affected.

Identity and Access Management
Feature

The Agent Identity auth manager and the Agent Identity APIs (agentidentity.googleapis.com and agentidentitycredentials.googleapis.com) are generally available.

Agent Identity auth manager provides a centralized credentials vault and authentication broker that simplifies outbound tool authentication for 3-legged OAuth, 2-legged OAuth, and API keys. The Agent Identity APIs replace the legacy IAM Connectors API (iamconnectors.googleapis.com) for managing auth providers and agent identities.

For more information, see the following documentation:

August 21, 2026

AI Hypercomputer
Change

AI Hypercomputer has expanded to cover all GPU machine series. Specifically, the documentation for AI Hypercomputer has been significantly updated as follows:

  • Documentation has been added for the A3 Edge, A2, G4, G2, N1+T4, and N1+V100 GPU machine series.
  • Pages are labeled based on whether they are relevant to the newly documented machine series for general GPU, the pre-existing machine series for clustered GPU, or both.

To learn more about the differences between general GPUs and clustered GPUs, see Choose your accelerator infrastructure. To view workload recommendations, see Choose between general GPUs and clustered GPUs.

Application Integration
Security

Missing authorization in QueryEngineTask (CVE-2026-12710)

A missing authorization vulnerability (CVE-2026-12710) in QueryEngineTask in Application Integration was patched on April 4, 2026, and no customer action is needed.

Assured Workloads
Feature

The Switzerland Data Boundary with Access Justifications control package is now generally available.

Feature

The Data Boundary for ITAR supports the following products:

  • Apigee
  • Artifact Analysis
  • Backup and DR Service
  • Cloud Billing API
  • Cloud Deploy
  • Spanner
  • Eventarc
  • GKE Image streaming
  • Google Cloud Managed Service for Apache Kafka
  • Vertex AI Online prediction
Cloud Storage
Feature

Rapid Cache supports prefix-level ingest-on-write filtering, allowing you to selectively ingest objects that match specific prefixes rather than ingesting all objects written to a bucket.

For more information, see Ingesting data on write.

Compute Engine
Feature

Generally available: The network- and memory-optimized M4N machine series is generally available. Powered by 5th generation Intel Xeon Scalable processors (Emerald Rapids), M4N instances are purpose-built for network and block storage-intensive workloads such as:

  • High-performance vector databases
  • Retrieval-augmented generation (RAG) data layers
  • Massive in-memory context caching
  • Real-time semantic search

The M4N machine series delivers the highest I/O performance available in Compute Engine, supporting up to 400 Gbps of network bandwidth. M4N also offers leading block storage performance with Hyperdisk Extreme that scales up to 25 GiB/s of bandwidth and 1M IOPS. M4N instances are available in predefined machine shapes, ranging in size from 16 to 224 vCPUs and up to 5,952 GB of DDR5 memory.

Gemini Enterprise
Feature

Gemini Enterprise: AI developer tools on Standard Emerging Market edition

The AI developer tools feature is available on the Gemini Enterprise Standard Emerging Market edition. Your project must be linked to an invoiced Cloud Billing account that receives an active monthly invoice to access the feature. This edition doesn't include bundled base quota or Antigravity credits.

For more information, see the following:

Feature

Gemini Enterprise: New data stores and support for new actions (Public Preview)

The following data stores are available in Public Preview in Gemini Enterprise:

You can search and read data from these data stores using natural language.

Additionally, the following data stores support new actions in Public Preview:

  • Descript: Import media, prompt project agent, and publish project.
  • Gamma: Generate Gamma.
  • Supabase: Apply migration, deploy edge function, execute SQL, pause project, and restore project.
Gemini Enterprise Agent Platform
Feature

xAI's Grok 4.6

Grok 4.6 is available in Preview in Model Garden.

Google Cloud Contact Center as a Service
Announcement

Google Cloud CCaaS 6.4

We've released version 6.4 of Google Cloud CCaaS.

The timing of the update to your instance depends on the deployment schedule that you have chosen. For more information, see Deployment schedules.

Feature

Automatic SIP parameter mapping in contact lists

Contact lists now support automatic SIP header mapping for outbound call destinations.

Administrators: In the Add Destination dialog at Settings > Call > Contact Lists > Contact list management > CREATE OR EDIT CONTACT LIST> Add Destination, toggle Pass Data Parameters to the on position to see the new Automatically Include and Pass all Inbound SIP Headers checkbox.

For more information, see Add a SIP URI address destination to a contact list.

Feature

Email OAuth profiles and Microsoft 365 client credentials

You can now create email OAuth profiles for Microsoft 365 using the client credentials grant type. This lets shared mailboxes authenticate through an app registration instead of relying on an individual user sign-in. OAuth IMAP setup is more resilient for support inboxes and other application-managed mailboxes.

For more information, see Email OAuth profiles and Microsoft 365 client credentials.

Feature

Improved connection times for predictive dialing

We reduced the connection time for predictive dialing to under two seconds to comply with CRTC and FTC regulations.

Fixed

This release addresses the following issues:

  • Fixed an issue where a long delay occurred when an agent clicked Chat Shortcuts in the chat adapter.

  • Fixed an agent desktop issue where the Session Data Feed pane displayed data from the previous chat and the chat transcript stopped updating.

  • Fixed an issue where conversation history loaded slowly for agents using the CCaaS widget embedded in Salesforce.

  • Fixed an issue where outbound calls with zero duration time were missing from Individual Call History reports that were scoped to agents and teams.

  • Fixed an issue where customers couldn't leave a voicemail during a warm transfer.

  • Fixed an issue where the Queued Calls dashboard displayed the incorrect originating queue and transferring agent for a cold-transferred call.

  • Fixed an issue where the agent desktop experienced significant loading delays.

  • Fixed an issue where calls transferred from a virtual agent directly to a human agent bypassed the Keep Waiting overcapacity setting, causing callers to be incorrectly routed to a fallback queue or to voicemail.

  • Fixed a raw data export issue where file names for the MENU_PATH_ITEMS dataset incorrectly contained path_items.

  • Fixed an issue where a parent queue was incorrectly marked as after-hours even though one or more of its child queues were in operation.

  • Fixed an issue with chats that were escalated from a virtual agent to a human agent and then reached a terminal status (canceled, finished, or failed). These chats mistakenly appeared in the Queued Chats dashboard.

  • Fixed an issue where the agent desktop froze and the Call Adapter pane displayed Call on hold after a call was terminated or dropped.

  • Fixed an issue where agents couldn't change their chat status while a call was in the wrap-up stage.

  • Fixed an issue where the call adapter displayed calls waiting when there were actually no calls waiting.

  • Fixed an issue where outbound calls that failed immediately caused the call adapter to be stuck in the In-call state with the timer running.

Google Kubernetes Engine
Change

Per the June 10, 2026 release note, the configuration option to not enroll your cluster in a release channel is deprecated, and will be removed on June 14, 2027. In alignment with this deprecation, creating new clusters not enrolled in a release channel is now only allowed for existing customers. New customers can use a release channel, where you can achieve the same functionality as not enrolling your cluster in a release channel. For more information, see Clusters not enrolled in a release channel.

Change

The Windows Server 2019 (LTSC) GKE node image doesn't receive updates after the December 2025 version. Windows Server 2019 (LTSC) is in the Extended Support period of the Microsoft fixed lifecycle policy and receives only security updates. To prevent stability issues, the GKE node image for Windows Server 2019 (LTSC) is pinned to the December 2025 version. If you use this node image, switch to Windows Server 2022 (LTSC), which is in the Mainstream Support period and receives updates from Microsoft and GKE. For more information, see Creating a cluster using Windows Server node pools.

Google SecOps
Feature

[Spotlight Feature] Relative time filtering in Google SecOps

This feature is in public preview. Google SecOps has updated how relative time filters calculate data ranges. You can now choose from three distinct, mathematically precise operators: Past, Previous, and Current. This change eliminates ambiguity between rolling windows and calendar-aligned periods, ensuring consistent behavior across all time units (like seconds, minutes, hours, days, weeks, months, years) and aligning SecOps dashboards with Search and other Google tools (such as Looker).

For more information, see the Relative time range section of the Understand search guide.

Service Health
Feature

The Personalized Service Health remote MCP server provides a secure environment that lets you send natural language prompts to your AI application so that it can retrieve incident information, audit incidents, and automate debugging on your behalf.

For more information, see Use the Personal Service Health remote MCP server.

August 20, 2026

App Engine flexible environment .NET
Feature

Starting from August 2026, to provide modern security patches and support for MySQL 8.4 and later, the App Engine flexible environment uses Cloud SQL Auth Proxy v2 as the built-in sidecar container for connections to Cloud SQL. To use the latest Cloud SQL Auth Proxy container immediately, restart your VMs or deploy a new version of your application.

App Engine flexible environment Go
Feature

Starting from August 2026, to provide modern security patches and support for MySQL 8.4 and later, the App Engine flexible environment uses Cloud SQL Auth Proxy v2 as the built-in sidecar container for connections to Cloud SQL. To use the latest Cloud SQL Auth Proxy container immediately, restart your VMs or deploy a new version of your application.

App Engine flexible environment Java
Feature

Starting from August 2026, to provide modern security patches and support for MySQL 8.4 and later, the App Engine flexible environment uses Cloud SQL Auth Proxy v2 as the built-in sidecar container for connections to Cloud SQL. To use the latest Cloud SQL Auth Proxy container immediately, restart your VMs or deploy a new version of your application.

App Engine flexible environment Node.js
Feature

Starting from August 2026, to provide modern security patches and support for MySQL 8.4 and later, the App Engine flexible environment uses Cloud SQL Auth Proxy v2 as the built-in sidecar container for connections to Cloud SQL. To use the latest Cloud SQL Auth Proxy container immediately, restart your VMs or deploy a new version of your application.

App Engine flexible environment PHP
Feature

Starting from August 2026, to provide modern security patches and support for MySQL 8.4 and later, the App Engine flexible environment uses Cloud SQL Auth Proxy v2 as the built-in sidecar container for connections to Cloud SQL. To use the latest Cloud SQL Auth Proxy container immediately, restart your VMs or deploy a new version of your application.

App Engine flexible environment Python
Feature

Starting from August 2026, to provide modern security patches and support for MySQL 8.4 and later, the App Engine flexible environment uses Cloud SQL Auth Proxy v2 as the built-in sidecar container for connections to Cloud SQL. To use the latest Cloud SQL Auth Proxy container immediately, restart your VMs or deploy a new version of your application.

App Engine flexible environment Ruby
Feature

Starting from August 2026, to provide modern security patches and support for MySQL 8.4 and later, the App Engine flexible environment uses Cloud SQL Auth Proxy v2 as the built-in sidecar container for connections to Cloud SQL. To use the latest Cloud SQL Auth Proxy container immediately, restart your VMs or deploy a new version of your application.

App Engine flexible environment custom runtimes
Feature

Starting from August 2026, to provide modern security patches and support for MySQL 8.4 and later, the App Engine flexible environment uses Cloud SQL Auth Proxy v2 as the built-in sidecar container for connections to Cloud SQL. To use the latest Cloud SQL Auth Proxy container immediately, restart your VMs or deploy a new version of your application.

BigQuery
Feature

BigQuery supports the following table-valued functions in the query editor and as part of conversational analytics to help you analyze your time series data:

These functions are in preview.

Deprecated

Starting April 26, 2027, core graph processing for BigQuery Graph will be restricted to the BigQuery Enterprise and Enterprise Plus editions. Consequently, we are deprecating support for Standard edition and on-demand billing for core graph processing.

Graph measures will remain available in the Enterprise and Enterprise Plus editions and for queries run using on-demand pricing. Measures are not available in Standard edition.

For additional details and enforcement dates regarding Standard edition and on-demand billing support, see the August 27, 2026 release note.

Feature

The run_bq_command tool exposes the bq command-line tool within the Cloud CLI remote MCP server. AI agents can now execute advanced BigQuery operations, such as job scheduling, job management, and reservation management, through a managed MCP endpoint. For more information, see Use the Cloud CLI remote MCP server. This feature is in Preview.

Bigtable
Feature

You can use the allow_incomplete_view query hint in SQL queries to read data from a continuous materialized view before its initial population finishes. This feature is generally available (GA). For more information, see Read data during initial population.

Cloud Service Mesh
Feature

The guidance for using proxy image types (default and distroless) with Managed Cloud Service Mesh has been updated:

  • Directly onboarded clusters using the TRAFFIC_DIRECTOR implementation use distroless proxy images by default, and other image types are not supported.
  • Migrated clusters (migrated from ISTIOD to TRAFFIC_DIRECTOR) default to default images, but can opt in to distroless images via MeshConfig or the sidecar.istio.io/proxyImageType: distroless Pod annotation.

For more information, see Distroless proxy images and Identify the proxy image type used in the cluster.

Feature

The guidance for using proxy image types (default and distroless) with Managed Cloud Service Mesh has been updated:

  • Directly onboarded clusters using the TRAFFIC_DIRECTOR implementation use distroless proxy images by default, and other image types are not supported.
  • Migrated clusters (migrated from ISTIOD to TRAFFIC_DIRECTOR) default to default images, but can opt in to distroless images via MeshConfig or the sidecar.istio.io/proxyImageType: distroless Pod annotation.

For more information, see Distroless proxy images and Identify the proxy image type used in the cluster.

Cluster Toolkit
Feature

Cluster Toolkit version v1.101.0 is available. This release adds support for Persistent Disk storage pools to the vm-instance module, GKE node pools, and storage. The update also optimizes dependency management to improve the user experience, and updates Cloud TPU v4 and TPU v5p shorthand mappings to use TensorCore counts. For more information, see the release announcement on GitHub.

Compute Engine
Feature

Preview: Image Builder is available in allowlist-only Preview. Image Builder is a declarative operating system (OS) image customization tool that automates the process of building, customizing, and validating custom OS images within Google Cloud by using Cloud Build. For more information about Image Builder, see About Image Builder.

To onboard your project and request access, fill out the request form.

Config Connector
Announcement

Config Connector version 1.155.1 is now available.

Feature

New Beta Resources (Direct Reconciler):

Feature

New Fields:

  • BigtableTable

    • Added spec.automatedBackupPolicy field.
  • CertificateManagerDNSAuthorization

    • Added spec.type field.
  • ComputeForwardingRule

    • Added spec.target.redisClusterServiceAttachment field.
  • ComputeURLMap

    • Added spec.tests[].expectedOutputURL field.
    • Added spec.tests[].expectedRedirectResponseCode field.
  • ContainerCluster

    • Added spec.nodeConfig.kubeletConfig.imageGcLowThresholdPercent field.
    • Added spec.nodeConfig.kubeletConfig.imageGcHighThresholdPercent field.
    • Added spec.nodeConfig.kubeletConfig.imageMinimumGcAge field.
    • Added spec.nodeConfig.kubeletConfig.imageMaximumGcAge field.
    • Added spec.nodeConfig.containerdConfig field.
    • Added spec.inTransitEncryptionConfig field.
    • Added spec.disableL4LbFirewallReconciliation field.
    • Added spec.nodeConfig.resourceManagerTags field.
    • Added spec.nodePoolAutoConfig.resourceManagerTags field.
  • ContainerNodePool

    • Added spec.nodeConfig.kubeletConfig.imageGcLowThresholdPercent field.
    • Added spec.nodeConfig.kubeletConfig.imageGcHighThresholdPercent field.
    • Added spec.nodeConfig.kubeletConfig.imageMinimumGcAge field.
    • Added spec.nodeConfig.kubeletConfig.imageMaximumGcAge field.
    • Added spec.nodeConfig.containerdConfig field.
    • Added spec.nodeConfig.resourceManagerTags field.
  • StorageBucket

    • Added spec.autoclass.terminalStorageClass field.
    • Added status.observedState.storageClass field.
Feature

New Features:

  • Configurable metrics server address: Made the manager's built-in metrics server bind address configurable.
  • Brownfield state comparison: Added a generic helper function to compare desired and actual states in brownfield resources, improving reconciliation reliability.
  • Irregular shortname pluralization: Added support for irregular shortname pluralization of "corpus" to "corpora".
Change

Reconciliation Improvements:

We have added support for direct reconciliation to more resources, with opt-in behavior. The API is unchanged. To use the direct reconciler, add the cnrm.cloud.google.com/reconciler: direct annotation to the corresponding Config Connector object.

Fixed

Bug Fixes:

  • ComposerEnvironment

    • Improved reconciliation, diffing, and update logic for ComposerEnvironment in the direct reconciler. (GitHub PR #12364)
    • Skip the update of a ComposerEnvironment when the state of the underlying Google Cloud Composer environment is not RUNNING. (GitHub PR #12365)
  • ComputeReservation

    • Ignore diff for specificReservation.inUseCount to prevent infinite/unwanted reconciliations.
  • RedisInstance

    • Marked MaintenanceSchedule field as output only to align with GCP's behavior.
  • SQLInstance

    • Fixed legacy fuzzer roundtrip mismatch for PscAutoConnectionPolicyEnabled.
  • CloudFunctions2Function

    • Declared source fields mutable-but-unreadable to avoid spurious diffs.
Container Optimized OS
Change

cos-125-19216-532-123

Kernel Docker Containerd GPU Drivers
COS-6.12.94 v27.5.1 v2.2.7 See List
Change

Updated containerd to v2.2.7.

Security

Fixed CVE-2026-68329 in the Linux kernel.

Gemini
Other

Bug fixes in IntelliJ

Various bug fixes and minor product enhancements.

Announcement

Credits for the first month of Gemini Code Assist usage are discontinued. Customers currently receiving these credits are unaffected by this change. Previously, these credits had been available to new customers with billing accounts if they had never had a Gemini Code Assist subscription.

Gemini Code Assist
Announcement

Credits for the first month of Gemini Code Assist usage are discontinued. Customers currently receiving these credits are unaffected by this change. Previously, these credits had been available to new customers with billing accounts if they had never had a Gemini Code Assist subscription.

Gemini Enterprise
Feature

Gemini Enterprise: Antigravity for IDEs available in AI developer tools

Antigravity for IDEs is available as part of AI developer tools for Gemini Enterprise Standard, Plus, and Pay-as-you-go editions linked to an invoiced Cloud Billing account that receives an active monthly invoice. Antigravity for IDEs brings the power of Antigravity AI agents directly into your integrated development environment (IDE).

For more information, see the following:

Feature

Gemini Enterprise and Gemini Notebook Enterprise: Autocomplete for sharing notebooks and agents with Okta

If you use Okta as your external identity provider (IdP) with Workforce Identity Federation, you can configure System for Cross-domain Identity Management (SCIM).

Configuring SCIM enables autocomplete when sharing Gemini Notebook Enterprise notebooks and when sharing agents in Gemini Enterprise. With autocomplete, users can quickly search and select people or groups instead of entering full email addresses or group names.

This feature is generally available (GA).

For more information, see the following:

Feature

Gemini Enterprise: Google Identity support for third-party data stores

Google Identity is supported and recommended to manage access when connecting third-party data sources to Gemini Enterprise.

  • What's new: Gemini Enterprise supports Google Identity when connecting to third-party data sources with external identity providers (such as Microsoft Entra ID or Okta) using OIDC or SAML 2.0. This includes all third-party federated connectors and ingestion connectors, with the exception of Microsoft 365 data ingestion.

  • Recommendation: Google Identity is recommended for all new setups.

  • Existing setups: Customers already using Workforce Identity Federation can choose to remain on their existing configuration.

This feature is generally available (GA). For more information, see Configure identity provider.

Google Kubernetes Engine
Change

(2026-R35) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

  • Version 1.36.3-gke.1537000 is now the default version for cluster creation in the Rapid channel.
  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.33.13-gke.1414000 is deprecated in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.13-gke.1462000 is deprecated in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.10-gke.1079000
    • 1.35.7-gke.1027000
    • 1.36.2-gke.2064000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Regular channel

  • Version 1.35.6-gke.1710000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.33.13-gke.1269000
    • 1.33.13-gke.1329000
    • 1.34.9-gke.1610000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1655000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.6-gke.1641000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Stable channel

  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.13-gke.1101000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.13-gke.1109000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1065000
    • 1.34.9-gke.1322000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
    • GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
    • GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:

Extended channel

  • Version 1.35.6-gke.1710000 is now the default version for cluster creation in the Extended channel.
  • The following versions are now available in the Extended channel:
  • The following versions are no longer available in the Extended channel:
    • 1.31.14-gke.2437000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.31.14-gke.2579000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.2137000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.2268000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1610000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1655000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.6-gke.1641000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

No channel (deprecated)

Security

(2026-R35) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2613000 cos-117-18613-675-48 cos-117-18613-675-48 release notes
1.32.13-gke.2314000 cos-121-18867-528-43 cos-121-18867-528-43 release notes
1.33.13-gke.1499000 cos-121-18867-528-43 cos-121-18867-528-43 release notes
1.34.10-gke.1236000 cos-125-19216-532-62 cos-125-19216-532-62 release notes

Change

(2026-R35) Version updates

  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.13-gke.1101000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.13-gke.1109000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1065000
    • 1.34.9-gke.1322000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
    • GKE upgrades clusters to the following new minor versions if there are no factors, such as maintenance exclusions or deprecated APIs, preventing upgrades:
    • GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has maintenance exclusions or other factors preventing minor version upgrades:
Change

(2026-R35) Version updates

  • Version 1.35.6-gke.1710000 is now the default version for cluster creation in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.33.13-gke.1269000
    • 1.33.13-gke.1329000
    • 1.34.9-gke.1610000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1655000 is deprecated in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.6-gke.1641000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Change

(2026-R35) Version updates

  • Version 1.36.3-gke.1537000 is now the default version for cluster creation in the Rapid channel.
  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.33.13-gke.1414000 is deprecated in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.33.13-gke.1462000 is deprecated in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.10-gke.1079000
    • 1.35.7-gke.1027000
    • 1.36.2-gke.2064000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Change

(2026-R35) Version updates

Change

(2026-R35) Version updates

  • Version 1.35.6-gke.1710000 is now the default version for cluster creation in the Extended channel.
  • The following versions are now available in the Extended channel:
  • The following versions are no longer available in the Extended channel:
    • 1.31.14-gke.2437000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.31.14-gke.2579000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.2137000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.32.13-gke.2268000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1610000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1655000 is deprecated in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.6-gke.1641000
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
Google SecOps
Feature

Side-by-side view on the Alerts & Detections tab in Cases

This feature is in public preview. The Alerts & Detections tab in the revamped Investigation Management experience now supports a Side-by-side view layout.

You can switch between the default List view and the Side-by-side view to inspect an alert or detection's detailed metadata, status, priority, creation date, and Gemini investigation insights in an adjacent side pane without navigating away from the main list.

For more information, see Investigation and case management overview.

Managed Service for Apache Airflow
Announcement

A new Managed Service for Apache Airflow release has started on August 20, 2026. Get ready for upcoming changes and features as we roll out the new release to all regions. This release is in progress at the moment. Listed changes and features might not be available in some regions yet.

Feature

Airflow 3.3.1 is available in Managed Airflow (Gen 3).

Change

Airflow 3.1.8 is no longer included in Managed Airflow images and builds.

Feature

Composer Local Development CLI tool now supports deployment with Podman in Linux and Windows.

Change

(Airflow 3.2.2, 3.1.8, and 2.11.1) The apache-airflow-providers-google package was upgraded to version 22.3.0. For more information about changes, see the apache-airflow-providers-google changelog.

Change

New images are available in Managed Airflow (Gen 2):

Network Security Integration
Feature

Network Security Integration in-band integration now supports the direct internet egress deployment model. In this model, the network security appliance in the producer VPC network inspects outbound traffic and sends it directly to the internet through its external network interface. The appliance then sends the internet response packet directly to the consumer VM using GENEVE, bypassing the return hop to the consumer VPC network.

For more information, see Direct internet egress.

Secure Web Proxy