Cloud Armor release notes

This page contains release notes for features and updates to Google Cloud Armor.

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

October 15, 2025

Feature

Cloud Armor's Hierarchical security policies that facilitate centralized control, enhanced consistency, operational efficiency, and effective delegation of security policy management is Generally Available.

September 24, 2025

Feature

Cloud Armor's support for Autonomous System Numbers (ASNs) in globally scoped edge security policies for Media CDN edge cache services is Generally Available.

Feature

Cloud Armor's support for Network Threat Intelligence (NTI) in globally scoped edge security policies for Media CDN edge cache services is Generally Available.

September 16, 2025

Feature

Cloud Armor support for organization-scoped address groups for security policies is Generally Available.

August 08, 2025

Feature

Cloud Armor supports Autonomous System Numbers (ASNs) in globally scoped edge security policies for Media CDN edge cache services in Preview.

July 23, 2025

Feature

Cloud Armor supports internal service security policies for the service mesh to enforce global server-side rate limiting per client in Preview.

July 08, 2025

Change

Cloud Armor preconfigured WAF rules can now inspect up to the first 64kB (either 8kB, 16kB, 32kB, 48kB, or 64kB) of the POST or PATCH request body content in Preview.

June 27, 2025

Feature

Cloud Armor's Hierarchical security policies facilitate centralized control, enhanced consistency, operational efficiency, and effective delegation of security policy management in Preview.

June 24, 2025

Feature

Cloud Armor supports organization-scoped address groups for security policies in Preview.

June 18, 2025

Feature

Cloud Armor supports Network Threat Intelligence (NTI) in globally scoped edge security policies for Media CDN edge cache services in Preview.

June 09, 2025

Change

Cloud Armor support for JA4 rate limiting key is Generally Available. For more information, see Configure rate limiting.

July 17, 2024

Feature

Granular models for Cloud Armor Adaptive Protection are now Generally Available. For more information, see the Adaptive Protection overview.

February 13, 2024

Feature

The following new NTI feeds are now available:

  • iplist-vpn-providers
  • iplist-anon-proxies
  • iplist-crypto-miners

For more information about Network Threat Intelligence, see the overview.

January 25, 2024

Feature

The following features are now Generally Available:

  • Parsing of the GraphQL content-type
  • Support for User IP request headers
  • Support for JA3 fingerprints

For more information about parsing GraphQL content, see Apply parsing on custom Content-Type header values. For more information about User IP request headers and JA3, see Configure custom rules language attributes.

March 21, 2023

Feature

Preview mode is now Generally Available for advanced network DDoS protection, allowing you to receive all the logging and telemetry about the detected attack without enforcing the mitigation.

December 28, 2022

Feature

The rule signature 942550-sqli, which covers the vulnerability in which malicious attackers can bypass WAF by appending JSON syntax to SQL injection payloads, is now available. For more information, see the WAF rules overview.

December 16, 2022

Feature

Advanced network DDoS protection is now Generally Available for network load balancers, protocol forwarding, and VMs with public IP addresses. Metering and billing of Managed Protection Plus protected resources and the data processing fee for the endpoint covered by advanced Network DDoS protection will begin on Jan 31, 2023. For more information, see Configure advanced DDoS protection and the Cloud armor pricing page.

November 29, 2022

Feature

Three new rate limiting keys are now Generally Available:

  • HTTP-PATH
  • SNI
  • REGION-CODE

For more information about using rate limiting keys, see the Rate limiting overview.

October 24, 2022

Feature

Default security policies are now Generally Available. You can configure a default rate-limiting security policy when you use the Google Cloud Console to set up your load balancer. For more information, see the Rate limiting overview.

June 30, 2021

Feature

Google Cloud Armor now supports parsing of the JSON content of POST bodies when preconfigured WAF rules are evaluated. JSON parsing must be enabled on a per-security-policy basis. In addition, you can enable verbose request logging to provide more details about why a particular rule was triggered. These features are Generally Available.

April 14, 2021

Change

Managed Protection Plus subscribers are also eligible to receive reactive or proactive DDoS response support from Google's DDoS mitigation experts to help triage and mitigate ongoing attacks, as well as DDoS bill protection to provide credits for some bill spikes caused by increased Google Cloud usage as a result being target by a DDoS attack.

For more information, see the public docs.

December 06, 2018

Feature

Google Cloud Armor monitoring is available in GA.

December 03, 2018

Feature
Feature

Google Cloud Armor security policies cannot be attached to backend services that are configured to use the HTTP/2 protocol.