<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:confidential-space-release-notes</id>
  <title>Confidential Space - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/confidential-space-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-03-24T00:00:00-07:00</updated>

  <entry>
    <title>March 24, 2026</title>
    <id>tag:google.com,2016:confidential-space-release-notes#March_24_2026</id>
    <updated>2026-03-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#March_24_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>A new Confidential Space image (260300) is available.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>February 20, 2026</title>
    <id>tag:google.com,2016:confidential-space-release-notes#February_20_2026</id>
    <updated>2026-02-20T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#February_20_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>A new Confidential Space image (260200) is available.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>January 20, 2026</title>
    <id>tag:google.com,2016:confidential-space-release-notes#January_20_2026</id>
    <updated>2026-01-20T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#January_20_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>A new Confidential Space image (260100) is available.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>December 16, 2025</title>
    <id>tag:google.com,2016:confidential-space-release-notes#December_16_2025</id>
    <updated>2025-12-16T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#December_16_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>A new Confidential Space image (251200) is available.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 03, 2025</title>
    <id>tag:google.com,2016:confidential-space-release-notes#October_03_2025</id>
    <updated>2025-10-03T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#October_03_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>New Confidential Space images (251000 and 251001) are available.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 02, 2025</title>
    <id>tag:google.com,2016:confidential-space-release-notes#September_02_2025</id>
    <updated>2025-09-02T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#September_02_2025"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>A new Confidential Space image (250800) is available.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 31, 2025</title>
    <id>tag:google.com,2016:confidential-space-release-notes#March_31_2025</id>
    <updated>2025-03-31T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#March_31_2025"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>Confidential Space now allows adding specific Linux capabilities, including CAP_SYS_ADMIN, and provides a namespaced read or write cgroup.</p>
<h3>Feature</h3>
<p>Support for Confidential Space on Intel CPUs (C3 machine family) with Intel TDX is now <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<h3>Announcement</h3>
<p>New Confidential Space images (250300 and 250301) are now available.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 28, 2025</title>
    <id>tag:google.com,2016:confidential-space-release-notes#March_28_2025</id>
    <updated>2025-03-28T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#March_28_2025"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>AWS token support for Confidential Space is now <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<p>You can now integrate Confidential Space with AWS resources. For more information, see <a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/connect-external-resources#integrate-aws">Integrate AWS resources</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>February 05, 2025</title>
    <id>tag:google.com,2016:confidential-space-release-notes#February_05_2025</id>
    <updated>2025-02-05T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#February_05_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p>Update go-sev-guest to v.0.12.1.</p>
<h3>Announcement</h3>
<p>A new Confidential Space image (250101) is now available.</p>
<h3>Change</h3>
<p>Update the verifier API version to include a new principal tag token type.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>January 14, 2025</title>
    <id>tag:google.com,2016:confidential-space-release-notes#January_14_2025</id>
    <updated>2025-01-14T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#January_14_2025"/>
    <content type="html"><![CDATA[<h3>Fixed</h3>
<p>Added retry logic when pulling the workload image and calling the Confidential Computing API.</p>
<h3>Change</h3>
<p>Changed the default OOM score for the workload container.</p>
<h3>Announcement</h3>
<p>A new Confidential Space image (250100) is now available.</p>
<h3>Change</h3>
<p>Updated default TPM Dictionary Lockout parameters. This change should significantly reduce the chance for users to get into the TPM lockout state.</p>
<h3>Feature</h3>
<p>Improved the logging and monitoring experience. Added CPU metric monitoring to the image.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 21, 2024</title>
    <id>tag:google.com,2016:confidential-space-release-notes#October_21_2024</id>
    <updated>2024-10-21T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#October_21_2024"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>A new Confidential Space image (241000) is now available. This image version adds IPv6 ingress traffic support.</p>
<p>The following Confidential Space images were also previously released:</p>
<ul>
<li>September 2, 2024 (240900):
<ul>
<li>Added <code>tmpfs</code> mount support for Confidential Space workloads</li>
<li>Added configurable <code>/dev/shm</code> size for Confidential Space workloads</li>
<li>Added retry capability to the container signature fetch.</li>
<li>Minor bug fixes.</li>
</ul></li>
<li>August 5, 2024 (240800):
<ul>
<li>Moved to COS-113 as the base image.</li>
<li>Patched OpenSSH vulnerability CVE-2024-6387 in the debug image.</li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>July 01, 2024</title>
    <id>tag:google.com,2016:confidential-space-release-notes#July_01_2024</id>
    <updated>2024-07-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#July_01_2024"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>A new Confidential Space image (240700) is now available. This image provides the following fixes:</p>
<ul>
<li>Fixed a bug that caused attestation token refreshing to fail.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 30, 2024</title>
    <id>tag:google.com,2016:confidential-space-release-notes#May_30_2024</id>
    <updated>2024-05-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#May_30_2024"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>A new Confidential Space image (240500) is now available. This image provides the following fixes:</p>
<ul>
<li>Fixed an issue where default service account credentials would expire after 1 hour, causing <code>Failed to fetch signatures from the target repo</code> errors.</li>
<li>Fixed a concurrent TPM access issue.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 01, 2024</title>
    <id>tag:google.com,2016:confidential-space-release-notes#May_01_2024</id>
    <updated>2024-05-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#May_01_2024"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>A new Confidential Space image (240402) is now available. This image provides support for automatically resizing the boot disk stateful partition. See <a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/create-customize-workloads#disk-memory-limits">disk and memory limits</a> for more information.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>February 28, 2024</title>
    <id>tag:google.com,2016:confidential-space-release-notes#February_28_2024</id>
    <updated>2024-02-28T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#February_28_2024"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>Data collaborators can now <a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/reference/attestation-assertions?tab=vm-assertions#instance_memory_monitoring_enabled">check if memory monitoring is enabled</a> on a Confidential VM running a Confidential Space workload.</p>
<h3>Announcement</h3>
<p>A new Confidential Space image (240200) is now available. This image provides support for data collaborators to add memory monitoring as part of their attestation assertions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>December 18, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#December_18_2023</id>
    <updated>2023-12-18T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#December_18_2023"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>A workload operator can now <a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/deploy-workloads#tee-monitoring-memory-enable">enable memory monitoring</a> on the Confidential VM running the workload. This must be <a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/create-customize-workloads#monitoring-memory-allow">permitted by the workload author</a>.</p>
<h3>Announcement</h3>
<p>A new Confidential Space image (231201) is now available. This image provides support for Confidential VM memory monitoring.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>December 05, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#December_05_2023</id>
    <updated>2023-12-05T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#December_05_2023"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>A new Confidential Space image (231200) is now available. This image provides support for <a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/connect-external-resources">custom attestation tokens</a>.</p>
<h3>Feature</h3>
<p>You can now use <a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/connect-external-resources">custom attestation tokens</a> to authenticate a workload to relying parties outside of Google Cloud. External relying parties can use authentication to help establish trust and exchange sensitive data securely.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>November 22, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#November_22_2023</id>
    <updated>2023-11-22T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#November_22_2023"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>You can now <a href="https://docs.cloud.google.com/confidential-computing/docs/split-trust-encryption-tool">use the Split-Trust Encryption Tool (STET) with Confidential Space</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>November 20, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#November_20_2023</id>
    <updated>2023-11-20T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#November_20_2023"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Support for VPC Service Controls is released to <a href="https://cloud.google.com/products#product-launch-stages">General Availability</a>.</p>
<p>You can now protect Confidential Space using VPC Service Controls perimeters. For more information, see <a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_confidential_space">VPC Service Controls supported products</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>November 08, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#November_08_2023</id>
    <updated>2023-11-08T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#November_08_2023"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>Support for VPC Service Controls is released to <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>You can now protect Confidential Space using VPC Service Controls perimeters. For more information, see <a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_confidential_space">VPC Service Controls supported products</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>November 03, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#November_03_2023</id>
    <updated>2023-11-03T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#November_03_2023"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<p>A new Confidential Space image (231001) is now available. This image provides support for signing container images.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 04, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#October_04_2023</id>
    <updated>2023-10-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#October_04_2023"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>A new Confidential Space image (230901) is now available. This image provides improved logging capabilities and increases the file descriptor limits.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 30, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#June_30_2023</id>
    <updated>2023-06-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#June_30_2023"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>A new Confidential Space image (230600) is now available. This image provides support for opening ports for inbound network traffic to your workload.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 09, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#June_09_2023</id>
    <updated>2023-06-09T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#June_09_2023"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/create-customize-workloads#inbound-ports">Ports can now be opened</a> for ingress network traffic when using Confidential Space image version 230600 and above.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 28, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#March_28_2023</id>
    <updated>2023-03-28T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#March_28_2023"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/confidential-space-overview">Confidential Space</a> is now <strong>generally available</strong>.</p>
<p>Confidential Space is designed to let parties share sensitive data with a mutually agreed upon workload, while they retain confidentiality and ownership of that data. Such data might include personally identifiable information (PII), protected health information (PHI), intellectual property, cryptographic secrets, and more. Confidential Space helps create isolation so that data is only visible to the workload and the original owners of the data.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 27, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#March_27_2023</id>
    <updated>2023-03-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#March_27_2023"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p>The <code>assertion.submods.confidential_space.support_attributes</code> assertion can  be used to verify the support status of the Confidential Space image being used. It can be used, for example, to ensure that the workload is running on the latest version of the Confidential Space image.</p>
<h3>Change</h3>
<p>The <code>assertion.swversion</code> <a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/reference/attestation-assertions?tab=image-assertions#swversion">attestation assertion</a> now verifies the Confidential Space image version number the workload is being run on, with the result returned as a list. Previously the assertion was used to determine whether the workload was running on a production or debug Confidential Space image, and the result was returned as an integer. You now determine if a production or debug image is being used with the <code>assertion.dbgstat</code> assertion.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>February 28, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#February_28_2023</id>
    <updated>2023-02-28T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#February_28_2023"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>A new Confidential Space image (2302-0) is now available. This image provides support for the following features and fixes:</p>
<ul>
<li>Attestation is now run in the same location as your workload.</li>
<li>The launcher and workload return codes are now recorded in logs.</li>
<li>A bug that prevented Docker from pulling images has been fixed.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>February 27, 2023</title>
    <id>tag:google.com,2016:confidential-space-release-notes#February_27_2023</id>
    <updated>2023-02-27T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#February_27_2023"/>
    <content type="html"><![CDATA[<h3>Breaking</h3>
<p>The service account attached to a Confidential Space workload VM now requires the <code>confidentialcomputing.workloadUser</code> role to generate an attestation token. If you receive a permission denied message for <code>confidentialcomputing.locations.list</code> on your existing workload, add the role to the VM service account.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>December 02, 2022</title>
    <id>tag:google.com,2016:confidential-space-release-notes#December_02_2022</id>
    <updated>2022-12-02T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/release-notes#December_02_2022"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>Preview</strong>: <a href="https://docs.cloud.google.com/confidential-computing/confidential-space/docs/confidential-space-overview">Confidential Space</a> is designed to let parties share sensitive data with a mutually agreed upon workload, while they retain confidentiality and ownership of that data. Such data might include personally identifiable information (PII), protected health information (PHI), intellectual property, cryptographic secrets, and more. Confidential Space helps create isolation so that data is only visible to the workload and the original owners of the data.</p>
]]>
    </content>
  </entry>

</feed>
