Hotfix 7
Hotfix 6
Firewall
- Added support for custom
ZoneProtectionProfileresources, allowing infrastructure operators to configure scan detection thresholds and define exempt source IP addresses to prevent legitimate traffic from being erroneously blocked by firewall reconnaissance protection. Using theZoneProtectionProfilecustom resource (zoneprotectionprofiles.firewall.private.gdc.goog/v1alpha2), operators can customize scan thresholds, define IP address allow lists (exclusionIPs), change protection actions (alert,allow,block,block-ip), or selectively disable scan protections (enabled: false).
Operating system
- Improved File Access Policy Daemon (
fapolicyd) performance by increasing cache sizes and optimizing the trust database, preventing high system load averages and container execution delays on cluster nodes.
Vulnerability management
Fixed an issue where leftover plugin feed files weren't deleted after vulnerability scanner plugin updates, preventing disk space exhaustion on the security scanner server.
Renamed the vulnerability management service entry resource to prevent resource conflicts with existing licenses during upgrades. Newer versions of Nessus are shipped with a perpetual license, removing the step for Nessus activation.
Increased resource allocations for database clusters to prevent PostgreSQL issues in Tenable Enclave.
Hotfix 5
Hotfix 4
AI services
- Fixed bugs and made improvements to the Inference Stack.
Gemini
- Upgraded dependent libraries for the Inference Stack.
Vertex AI
- Fixed an issue with Gemini enablement in the GDC console.
Hotfix 3
AI services
Updated the Inference Gateway certificate size to be configurable.
Fixed bugs and made improvements to the customer IO Dashboard.
Documentation
- Updated the hotfix documentation and related upgrade procedures to indicate hotfixes for 1.16.1 aren't cumulative. A 1.16 hotfix only provides the specific fixes released as part of that independent hotfix.
Vertex AI:
- Fixed an issue where the
vai-dp-certprivate key size can't be configured, preventing organization onboarding when using certificates with specific public key infrastructure (PKI) requirements.
Hotfix 2
Hotfix 1
Documentation
- Updated infrastructure operator runbooks and deployment documentation, and platform administrator and application operator documentation for the latest product updates.
Observability
- Fixed various Observability platform bugs across several customer workflows.
Operating system
- Fixed an issue where containerd failed to start due to
Failed to run CRI serviceerrors.