Google Distributed Cloud air-gapped 1.16.2 hotfixes

Hotfix 1

Fixed
The 1.16.2-gdch.1353-1 hotfix is available. This hotfix fixes the following issues:

CLI

  • Added support for diff-based OCI package loading in the gdcloud system container-registry load-oci command to reduce download and upload sizes for hotfix releases.

Database service

  • Updated Database Service to version 0.16.6 and Database Service console UI to version 2.16.0-beta.31 to apply the latest bug fixes and stability improvements.

Documentation

  • Updated the GDC offline documentation hosted in the GDC console with the latest content.

Firewall

  • Added the ZoneProtectionProfile custom resource data model, custom profile generation and claims, validation webhooks, and reconnaissance protection support for firewall nodes.

Gemini

  • Updated the Gemini Inference Stack operator and model server templates to remove unsupported options and apply stability fixes.

Gemini App

  • Resolved issues to enable Gemini App and B300 expansion support.

Identity and access management

  • Fixed a timeout issue with rotatableSecret in Anthos Identity Service (AIS) that caused identity service reconciliation delays.

  • Enabled cookie splitting support in AIS to resolve large authentication token issues, and updated identity service container images.

Inventory

  • Fixed an issue where auto-generated passwords containing unsupported special characters caused switch provisioning and object storage bootstrap failures.

  • Updated rack and instance IDs to support identifiers with more than two characters, and removed unnecessary cable, adapter, and transceiver validations during preflight checks.

  • Added support for management IP address and CIDR expansion after decommissioning middle racks.

  • Added support for iDRAC and OCP port names in inventory webhook validation.

Logging

  • Optimized LoggingRule filter expressions to prevent high query rates (QPS) on object storage.

Monitoring

  • Fixed an issue where incorrect metrics port configurations on the EZ infrastructure controller caused high-frequency EZ-E1001, EZ-E1003, and EZ-E1004 alerts to fire erroneously.

  • Improved MonitoringTarget reconciler resilience by automatically requeueing targets after certificate retrieval failures and preventing unnecessary patches on persistent volume claims (PVCs).

  • Fixed an issue where restartedAt annotations caused unnecessary restarts during Prometheus StatefulSet comparison.

  • Removed legacy Google-Built OpenTelemetry Collector (GBOC) network policies in the monitoring namespace.

Networking

  • Fixed an issue where subnetClaimRef wasn't populated when a server was located in a different rack from its management switch.

  • Fixed an issue where device category CIDRs were missing for existing management switches during vertical expansion.

  • Added support and generic regular expression validation for B300 server management and data port naming formats (such as fe-s6p1 and ocp-s1p1).

  • Fixed JSON parsing errors in VLAN interface tables when the interface list wraps across multiple lines.

  • Added a host network stage to rollout policies to ensure reliable network staging during component updates.

  • Disabled ABM Gateway resource installation to avoid reconciliation errors in unsupported environments.

  • Fixed connectivity tests to treat media converters as passive devices during validation.

  • Improved error handling for invalid port formats during switch port connection validation.

Operating system

  • Improved file access policy daemon (fapolicyd) performance and stability on nodes by increasing cache size and optimizing trust database rules.

Security

  • Added support for multiple root certificates during package validation preflight checks.

Servers

  • Added support for Dell iDRAC and BIOS firmware downgrades for the d4-highgpu2 machine class.

Upgrade

  • Added safeguards to prevent re-execution of completed upgrades and improved client validation error handling during upgrade orchestration.

  • Added support for a new diff-download mode for hotfixes, to download only the changed artifacts compared to the base release, drastically reducing the download size.

Vertex AI

  • Updated Vertex AI Search container images and prediction_proxy to apply the latest security and stability updates.

Virtual machines

  • Added support for enabling the GPU stack on standard Kubernetes clusters.

  • Marked shared VM and virtual machine image resources as audit-relevant in AuditlogInventory to ensure comprehensive audit logging.

  • Fixed an issue in image-controller where missing cache checks caused excessive HTTP 409 conflict errors during concurrent image creation.

  • Fixed an issue affecting virtual machine image import stability.

Vulnerability management

  • Fixed vulnerability report import workflows to wait for completion before proceeding.

  • Skipped unnecessary Security Compliance Framework for Google Cloud (SCFGM) generation for Windows OIC nodes.

  • Made database CPU and memory resource allocations configurable and increased default database resource limits for the vulnerability scanning database.