<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:gcp-release-notes</id>
  <title>Google Cloud Platform (GCP) - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/gcp-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-05-16T00:00:00-07:00</updated>

  <entry>
    <title>May 16, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_16_2026</id>
    <updated>2026-05-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_16_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_03_2026">Release 6.3.84</a> is now available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 15, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_15_2026</id>
    <updated>2026-05-15T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_15_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Backup and DR</h2>
<h3>Feature</h3>
<p>Backup and DR Service now supports customer-managed encryption keys (CMEK)
  for Cloud SQL enhanced backups. This allows you to protect your
  Cloud SQL backups using the same KMS key as the source instance, with
  decoupled IAM permissions anchored to the Backup and DR Service service
  agent.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>The
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-detect-anomalies"><code>AI.DETECT_ANOMALIES</code> function</a>
supports calling the function with a single input table that holds both the
historical and target data. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Cloud Build</h2>
<h3>Feature</h3>
<p>You can now configure the <code>results</code> field in build config files. This
field allows a build step to store data and then attach that data in an
attestation within the build results after the build has completed.
For more information, see
<a href="https://docs.cloud.google.com/build/docs/build-config-file-schema#results">results</a>.</p>
<h2 class="release-note-product-title">Cloud Logging</h2>
<h3>Feature</h3>
<p>Starting with version 2.66.0, the Ops Agent can export your logs and metrics
by using the OpenTelemetry-based
<a href="https://docs.cloud.google.com/stackdriver/docs/reference/telemetry/overview">Telemetry API</a> rather than
by using the Cloud Logging API and Cloud Monitoring API. During the preview
<a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a> period, you can opt-in to using
the Telemetry API. For more information, see
<a href="https://docs.cloud.google.com/monitoring/agent/ops-agent/use-telemetry-api">Use the Telemetry API</a>.</p>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Feature</h3>
<p>Starting with version 2.66.0, the Ops Agent can export your metrics and logs
by using the OpenTelemetry-based
<a href="https://docs.cloud.google.com/stackdriver/docs/reference/telemetry/overview">Telemetry API</a> rather than
by using the Cloud Monitoring API and Cloud Logging API. During the preview
<a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a> period, you can opt-in to using
the Telemetry API. For more information, see
<a href="https://docs.cloud.google.com/monitoring/agent/ops-agent/use-telemetry-api">Use the Telemetry API</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Manage agent revisions and traffic splitting</strong></p>
<p>Agent revisions and traffic splitting are now available in public preview. You
can create immutable revisions of deployed agents, and split traffic between the
different active revisions. This enables canary deployments and safe testing of
new agent versions. For more information, see
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/runtime/manage-revisions-and-traffic">Manage revisions and traffic</a>.</p>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Announcement</h3>
<p><strong>ve1 hardware End-of-Life (EoL) migration guide:</strong> You can now refer to the public
documentation to <a href="https://docs.cloud.google.com/vmware-engine/docs/howto-migrate-ve1-hardware">migrate workloads from retiring ve1 hardware</a>. First-generation <code>ve1</code> bare metal nodes are reaching the end of their useful life on a rolling basis. When your hardware is scheduled for retirement, you receive an EoL notification containing timelines and instructions to migrate your clusters.</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Column-level lineage for Dataproc is generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
This feature enables you to track the flow of data between individual columns
in BigQuery, BigLake external tables, Cloud Storage buckets, and other
resources as reported by Dataproc clusters and Serverless for Apache Spark.
For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/about-data-lineage">About data lineage</a>.</p>
<h3>Feature</h3>
<p>The Data Lineage API is now updated with the following changes:</p>
<ul>
<li>The <code>SearchLinks</code> method  accepts multiple source and target entity references as search criteria.</li>
<li>Added support for column-level lineage information to be passed and returned from the service.</li>
<li>Process resources now report Dataflow as their origin if it is used to generate lineage.</li>
</ul>
<p>For more information, see the Data Lineage API reference for
<a href="https://docs.cloud.google.com/dataplex/docs/reference/data-lineage/rest">REST</a>
and <a href="https://docs.cloud.google.com/dataplex/docs/reference/data-lineage/rpc">RPC</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Change</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/vulnerability-assessment-google-cloud">Vulnerability Assessment for Google Cloud</a>
supports scanning GKE clusters that have
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/image-streaming">Image streaming</a> enabled.</p>
<h2 class="release-note-product-title">Vertex AI Search</h2>
<h3>Deprecated</h3>
<p><strong>Agent Search: Agent Search for healthcare is deprecated</strong></p>
<p>Agent Search for healthcare is deprecated.</p>
<p>For a comprehensive, managed
solution, consider building <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/about-generic-search">custom search
apps</a>
on Agent Search.
Or, if you require fine-grained control over the underlying
retrieval mechanisms and are prepared for a more customer-managed integration,
use Agent Retrieval (formerly known as <a href="https://docs.cloud.google.com/vertex-ai/docs/vector-search-2/overview">Vector Search
2.0</a>).</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 14, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_14_2026</id>
    <updated>2026-05-14T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_14_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Issue</h3>
<p>Support for the <code>AI.KEY_DRIVERS</code> function
<a href="https://cloud.google.com/products/#product-launch-stages">preview</a>
has been temporarily disabled. We are working to restore this feature as soon as
possible.</p>
<h2 class="release-note-product-title">Cloud Composer</h2>
<h3>Issue</h3>
<p>The <code>google-api-core</code> preinstalled package versions from 2.28.0 to 2.30.2 might
cause degraded environment performance, which can result in longer times to
execute a task and longer times to move a task from the queued to the executing
state.</p>
<p>Affected Managed Airflow (Gen 3) builds:</p>
<ul>
<li>composer-3-airflow-3.1.7-build.0 to composer-3-airflow-3.1.7-build.5</li>
<li>composer-3-airflow-3.1.0-build.5 to composer-3-airflow-3.1.0-build.10</li>
<li>composer-3-airflow-2.11.1-build.0</li>
<li>composer-3-airflow-2.10.5-build.22 to composer-3-airflow-2.10.5-build.33</li>
<li>composer-3-airflow-2.9.3-build.42 to composer-3-airflow-2.9.3-build.53</li>
</ul>
<p>Affected Managed Airflow (Gen 2) builds:</p>
<ul>
<li>composer-2.16.10-airflow-2.11.1</li>
<li>composer-2.16.0-airflow-2.10.5 to composer-2.16.10-airflow-2.10.5</li>
<li>composer-2.16.0-airflow-2.9.3 to composer-2.16.10-airflow-2.9.3</li>
</ul>
<p>We recommend to upgrade your environment to the following versions, which
contain a version of the package where the problem is fixed or isn't present:</p>
<ul>
<li>composer-3-airflow-3.1.7-build.7 and later</li>
<li>composer-3-airflow-2.11.1-build.3 and later</li>
<li>composer-3-airflow-2.10.5-build.36 and later</li>
<li>composer-3-airflow-2.9.3-build.54 (contains 2.27.0)</li>
<li>composer-2.17.0-airflow-2.11.1 and later</li>
<li>composer-2.17.0-airflow-2.10.5 and later</li>
<li>composer-2.16.11-airflow-2.11.1 (contains 2.27.0)</li>
<li>composer-2.16.11-airflow-2.10.5 (contains 2.27.0)</li>
<li>composer-2.16.11-airflow-2.9.3 (contains 2.27.0)</li>
</ul>
<p>As a workaround, you can manually install a later version of the
<code>google-api-core</code> package to an affected environment by specifying <code>&gt;=2.30.3</code>
as the required version.</p>
<h2 class="release-note-product-title">Cloud Key Management Service</h2>
<h3>Feature</h3>
<p>The Cloud KMS <strong>Encryption metrics</strong> dashboard and project-level key tracking
are generally available. You can use the <strong>Encryption metrics</strong> dashboard to
review summaries and details of your keys used in customer-managed encryption
key (CMEK) integrations and the resources that they protect. The <strong>Encryption
metrics</strong> dashboard and the key <strong>Usage tracking</strong> tab support both centralized
key management using a dedicated key project and delegated key management using
keys stored in the same projects as the resources that they protect.</p>
<p>For more information about the <strong>Encryption metrics</strong> dashboard, see <a href="https://docs.cloud.google.com/kms/docs/view-encryption-metrics">View
encryption metrics</a>. For more information
about project-level key tracking, see <a href="https://docs.cloud.google.com/kms/docs/view-key-usage">View key
usage</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>You can use three new variables in custom request and response headers for
Application Load Balancers:</p>
<ul>
<li><p><code>asn</code>: The Autonomous System Number (ASN) associated with the client's IP
address.</p></li>
<li><p><code>cloud_trace_id</code>: The trace ID extracted (or generated) from the HTTP request
header.</p></li>
<li><p><code>hostname</code>: The original hostname specified by the client in the <code>Host</code> HTTP
request header. This allows preservation of the original host header
(equivalent to <code>X-Forwarded-Host</code>).</p></li>
</ul>
<p>These variables are available for both global external Application Load Balancers
and classic Application Load Balancers.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/load-balancing/docs/https/custom-headers-global">Create custom headers in backend services</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Priority PayGo is generally available (GA)</strong></p>
<p>Priority PayGo is a consumption option that provides more consistent performance
than standard PayGo without the upfront commitment of Provisioned Throughput. It
is ideal for business-critical workloads with fluctuating or unpredictable
traffic patterns.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/priority-paygo">Priority PayGo</a>.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>GKE now supports concurrent node pool upgrades for clusters (Preview). By
default, GKE automatically upgrades one node pool at a time. To decrease the
total time required to upgrade your cluster, you can now configure the maximum
number of node pools that GKE auto-upgrades simultaneously. This feature is
supported for both Standard and Autopilot clusters. For more information, see
<a href="https://cloud.google.com/kubernetes-engine/docs/how-to/upgrading-a-cluster#concurrent-upgrades">Configure concurrent node pool
upgrades</a>.</p>
<h3>Feature</h3>
<p>Managed OpenTelemetry on GKE now supports the collection of multimodal prompts
and responses (Preview) for LangGraph and Agent Development Kit (ADK) agents.
You can view and analyze the data in the Trace Explorer and BigQuery platforms.
For more details, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/managed-otel-gke#multimodal-prompts-responses">Collect multimodal prompts and responses
data</a>.</p>
<h3>Change</h3>
<p>Container-Optimized OS (COS) milestone 129 and higher no longer include the
<code>kubectl</code> binary in the <code>/usr/bin/</code> directory.</p>
<h2 class="release-note-product-title">Spanner</h2>
<h3>Announcement</h3>
<p>The Spanner change streams default <a href="https://docs.cloud.google.com/spanner/docs/change-streams#data-retention">retention period</a> has been increased from 1 day to 7 days.
This change affects both new and existing change streams that don't have a retention period explicitly set.
You can always specify the retention period through <a href="https://docs.cloud.google.com/spanner/docs/change-streams/manage#create">create change stream</a> or <a href="https://docs.cloud.google.com/spanner/docs/change-streams/manage#modify">alter change stream</a> DDL statements to override the default.</p>
<h3>Feature</h3>
<p>You can populate new PostgreSQL dialect databases in an existing
Spanner instance from sample datasets that help you explore
Spanner capabilities.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/spanner/docs/create-manage-databases#use-datasets">Create and manage databases</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 13, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_13_2026</id>
    <updated>2026-05-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_13_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1162">v1.16.2</h3>
<p>On May 13, 2026 we released an updated version of the Apigee hybrid software, v1.16.2.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.2</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>485738013</strong></td>
<td><strong>Fixed an issue where API products with <code>LLMTokenQuota</code> operations were not enforcing model-based access restrictions, allowing requests to models not listed in the product to bypass the operations check.</strong></td>
</tr>
<tr>
<td><strong>479288727</strong></td>
<td><strong>Fixed an issue where the Apigee UI and API reported a 10+ minute delay in deployment status after performing a proxy deployment.</strong></td>
</tr>
<tr>
<td><strong>499223890</strong></td>
<td><strong>Fixed an issue where the runtime could not handle HTTP proxy passwords containing special characters in Apigee hybrid 1.16.0-hotfix-1 configurations.</strong></td>
</tr>
<tr>
<td><strong>500861814</strong></td>
<td><strong>Fixed an issue that caused excessive Message Processor (MP) upscaling and failure to downscale.</strong></td>
</tr>
<tr>
<td><strong>510438578</strong></td>
<td><strong>Fixed an ingestion-blocking issue with <code>apigee-stackdriver-prometheus-sidecar</code> in Apigee hybrid 1.16.1.</strong></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Security</h3>
<p>Proxy version csm_mesh_proxy.20260423_RC03 is rolling out to all Managed Cloud
Service Mesh release channels over the next week.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Fixed</h3>
<h3 id="agent_mode_bug_fix_in_cloud_workstations">Agent mode bug fix in Cloud Workstations</h3>
<p>Fixed a bug that prevented agent mode from working on Cloud Workstations.</p>
<h3>Other</h3>
<h3 id="bug_fixes_in_intellij">Bug fixes in IntelliJ</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h3>Fixed</h3>
<h3 id="agent_mode_bug_fix_in_cloud_workstations">Agent mode bug fix in Cloud Workstations</h3>
<p>Fixed a bug that prevented agent mode from working on Cloud Workstations.</p>
<h3>Other</h3>
<h3 id="bug_fixes_in_intellij">Bug fixes in IntelliJ</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Announcement</h3>
<p>Correction: <strong>Gemini Enterprise: EU region for Gemini 3 models is coming soon</strong></p>
<p>The availability of Gemini 3.1 Pro and 3 Flash in the EU region has
been updated to "coming soon". Previously, it was listed as currently available.</p>
<p>For more information, see: <a href="https://docs.cloud.google.com/gemini/enterprise/docs/known-limitations#using-gemini-3-preview">Using Gemini 3.1 Pro and 3 Flash in Limited Availability</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Mobile SDK for iOS version 2.15.4 patch</strong></p>
<p>This patch includes the following updates for the mobile SDK for iOS:</p>
<ul>
<li><p>Fixed an issue where the iOS app crashed during disconnections.</p></li>
<li><p>Updated the Twilio Voice and Chat SDKs.</p></li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r19-version-updates">(2026-R19) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.1759000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.11-gke.1137000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.7-gke.1321000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1737000</li>
<li>1.36.0-gke.1379000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.1575000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.10-gke.1176000</li>
<li>1.34.6-gke.1237000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.10-gke.1067000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1068000</li>
<li>1.35.2-gke.1962000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234002</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2415000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1823000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1868000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1492000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2369000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2441000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1790000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1850000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1449000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1176000</li>
<li>1.34.6-gke.1237000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2407000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2407000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1816000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1868000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1492000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.9-gke.1060000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1067000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1137000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.7-gke.1321000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1962000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1522000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r19-security-updates">(2026-R19) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.30.14-gke.2458000</td>
<td>cos-117-18613-534-110</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-110_">cos-117-18613-534-110 release notes</a></td>
</tr>
<tr>
<td>1.31.14-gke.1868000</td>
<td>cos-117-18613-534-110</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-110_">cos-117-18613-534-110 release notes</a></td>
</tr>
<tr>
<td>1.32.13-gke.1492000</td>
<td>cos-117-18613-534-110</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-110_">cos-117-18613-534-110 release notes</a></td>
</tr>
<tr>
<td>1.33.11-gke.1197000</td>
<td>cos-121-18867-381-118</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-381-118_">cos-121-18867-381-118 release notes</a></td>
</tr>
<tr>
<td>1.34.7-gke.1499000</td>
<td>cos-125-19216-220-185</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-220-185_">cos-125-19216-220-185 release notes</a></td>
</tr>
<tr>
<td>1.35.3-gke.2190000</td>
<td>cos-125-19216-220-185</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-220-185_">cos-125-19216-220-185 release notes</a></td>
</tr>
<tr>
<td>1.36.0-gke.1759000</td>
<td>cos-beta-129-19506-120-52</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-beta-129-19506-120-52_">cos-beta-129-19506-120-52 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r19-version-updates">(2026-R19) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.10-gke.1067000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1068000</li>
<li>1.35.2-gke.1962000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234002</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r19-version-updates">(2026-R19) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.10-gke.1176000</li>
<li>1.34.6-gke.1237000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r19-version-updates">(2026-R19) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.1759000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.11-gke.1137000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.7-gke.1321000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1737000</li>
<li>1.36.0-gke.1379000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.1575000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r19-version-updates">(2026-R19) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1868000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1492000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.9-gke.1060000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1067000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1137000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.7-gke.1321000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1962000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1522000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r19-version-updates">(2026-R19) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2415000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1823000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1868000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1492000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2369000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2441000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1790000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1850000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1449000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1176000</li>
<li>1.34.6-gke.1237000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2407000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2407000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1816000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 28.0</p>
<ul>
<li><strong>Integration</strong>: Updated TIPCommon to 2.3.8.</li>
</ul>
<h3>Change</h3>
<p><strong>ConnectWise</strong>: Version 22.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alerts Ticket</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>EmailV2</strong>: Version 41.0</p>
<ul>
<li><strong>Integration</strong>: Updated TIPCommon to 2.3.8 and migrated <code>EnvironmentCommon</code> imports to <code>TIPCommon.envcommon</code>.</li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 82.0</p>
<ul>
<li><strong>Integration</strong>: Improved memory efficiency to prevent OOM crashes when querying large timeframes for <strong>Lookup Similar Alerts</strong>.</li>
<li>Updated the code for the following action:
<ul>
<li><strong>Get Detection Details</strong></li>
</ul></li>
<li>Improved Dynamic List filter validation, logging, and added the <code>Validate Dynamic List Entries</code> parameter for the following connector:
<ul>
<li><strong>Google Chronicle - Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 57.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Issue</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>MITRE ATT&amp;CK</strong>: Version 19.0</p>
<ul>
<li><strong>Integration</strong>: Updated TIPCommon to 2.3.8.</li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 65.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Incident</strong></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Vertex AI Search</h2>
<h3>Feature</h3>
<p><strong>Vertex AI Search: Weight searchable fields (Preview)</strong></p>
<p>You can specify a weight for searchable fields in your schema to indicate their
relative importance in search results.</p>
<p>This feature is in Public Preview.
For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/configure-field-settings#weight-search">Weight searchable
fields</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Search: Stream answers using agentic retrieval (GA with allowlist)</strong></p>
<p>You can use agentic retrieval with the streaming answer method.</p>
<p>Agentic retrieval can return better results as compared to the standard
streaming answer method. This is
because agentic retrieval can do multi-pass searches across multiple data stores.
The agent plans and executes searches sequentially, choosing the best tools,
such as Google Search and Google Maps, for each step.
Agentic retrieval also enables multi-turn search queries (follow-up questions)
on blended search apps.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/agentic-retrieval-stream-answer">Stream answers using agentic
retrieval</a>.</p>
<p>This feature is GA with an allowlist, available for select customers.</p>
<h2 class="release-note-product-title">reCAPTCHA</h2>
<h3>Change</h3>
<p>reCAPTCHA Mobile SDK v18.9.0 is available for Android. This version
includes the following updates:</p>
<ul>
<li><p>Improvements to SDK latency and reliability.</p></li>
<li><p>Score distribution calibration improvements.</p></li>
<li><p>Removes the need for desugaring and raises the minimum supported Android API
level to 24 (Android 7.0).</p></li></ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 12, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_12_2026</id>
    <updated>2026-05-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_12_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee API hub</h2>
<h3>Feature</h3>
<p><strong>MCP tools support for Agentic AI workflows (Preview)</strong></p>
<p>API hub now exposes read-only APIs as Model Context Protocol (MCP) tools. Agentic AI applications can now use the standard MCP <code>tools/list</code> and <code>tools/call</code> methods to list and inspect API hub resources, including APIs, specs, versions, and deployments.</p>
<p>This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Public Preview</a>. For more information, see <a href="https://docs.cloud.google.com/apigee/docs/reference/apis/apihub/mcp">API hub MCP reference</a>.</p>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On May 12th, 2026, we released an updated version of Apigee (1-17-0-apigee-7).</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release began today and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.</span></aside>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>511325186, 505460952, 502250074, 491231600, 497357701, 509560467, 496969438, 495897297, 495033618, 511332617, 505183435, 500735547, 500890221</strong></td>
<td><strong>Security fix for Apigee infrastructure.</strong> <p>This addresses the following vulnerabilities: <ul> <li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42587">CVE-2026-42587</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5588">CVE-2026-5588</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34480">CVE-2026-34480</a></li><li><a href="https://github.com/advisories/GHSA-72hv-8253-57qq">GHSA-72hv-8253-57qq</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33870">CVE-2026-33870</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33871">CVE-2026-33871</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35611">CVE-2026-35611</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33170">CVE-2026-33170</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33169">CVE-2026-33169</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33176">CVE-2026-33176</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33210">CVE-2026-33210</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42499">CVE-2026-42499</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35469">CVE-2026-35469</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a></li></ul></p></td>
</tr>
</tbody>
</table>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>480260846</strong></td>
<td>Improved XML processing security to prevent external entity injection.</td>
</tr>
<tr>
<td><strong>510061670, 505723451, 503723862, 503817773</strong></td>
<td>Improved security in OAuthV2 policy.</td>
</tr>
<tr>
<td><strong>505645076</strong></td>
<td>Fixed a security issue in OAuthV2 policy to prevent unauthorized token injection.</td>
</tr>
<tr>
<td><strong>503047744, 410026138, 496021751</strong></td>
<td>Improved security isolation for PythonScript policy execution.</td>
</tr>
<tr>
<td><strong>469694040</strong></td>
<td>Fixed an issue where custom security policies could intermittently fail to apply, and improved security policy resolution to ensure correct policy selection.</td>
</tr>
<tr>
<td><strong>502971220</strong></td>
<td>Fixed a concurrency issue to improve stability under high load.</td>
</tr>
<tr>
<td><strong>509692565</strong></td>
<td>Fixed content-length header handling in external processing to prevent incorrect values.</td>
</tr>
<tr>
<td><strong>282207038</strong></td>
<td>Improved performance while listing apps on scale.</td>
</tr>
<tr>
<td><strong>501102321</strong></td>
<td>Fixed recurring fee calculation in monetization to correctly apply rate plan overrides.</td>
</tr>
<tr>
<td><strong>449729840, 502604752</strong></td>
<td>Fixed streaming response handling to prevent race conditions in bidirectional flows.</td>
</tr>
<tr>
<td><strong>507167063</strong></td>
<td>Fixed preservation of client request IDs during proxy chaining.</td>
</tr>
<tr>
<td><strong>507580304</strong></td>
<td>Improved IPv4 address normalization for consistent access control evaluation.</td>
</tr>
<tr>
<td><strong>502692267</strong></td>
<td>MCP to handle /.well-known/oauth-protected-resource/mcp resource paths.</td>
</tr>
<tr>
<td><strong>430170696</strong></td>
<td>Changed the error response from 500 to 401 for expired consumer keys.</td>
</tr>
<tr>
<td><strong>480770263</strong></td>
<td>Fixed SpikeArrest policy to handle edge cases that previously caused 500 errors.</td>
</tr>
<tr>
<td><strong>500861814</strong></td>
<td>Gracefully handle connection failures involving the forward proxy, resolving an issue where port exhaustion could trigger aggressive retry storms, excessive CPU usage, and unnecessary scaling.</td>
</tr>
<tr>
<td><strong>500313309</strong></td>
<td>Fixed SSE streaming detection logic.</td>
</tr>
<tr>
<td><strong>494304819</strong></td>
<td>Hardened message processor management ports by blocking external access to internal management endpoints.</td>
</tr>
<tr>
<td><strong>469642464</strong></td>
<td>Improved input validation in AI protection policies to prevent Server-Side Request Forgery.</td>
</tr>
<tr>
<td><strong>472526232</strong></td>
<td>Improved SAML assertion validation.</td>
</tr>
<tr>
<td><strong>494590020</strong></td>
<td>Added enforcement for product association in OAuthV2 flow. Apps without valid products are now denied.</td>
</tr>
<tr>
<td><strong>479288727</strong></td>
<td>Improved performance and reduced redundant work in ingress status watcher.</td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td>Updates to infrastructure and libraries.</td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can now use the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-count-tokens"><code>AI.COUNT_TOKENS</code> function</a>
to estimate the token count of text input that you provide. For some generative
AI functions, you can <a href="https://docs.cloud.google.com/bigquery/docs/generative-ai-overview#token_usage">view</a>
the total number of input, output, thought, and cache tokens for each modality
processed by the query. These features are in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Buildpacks</h2>
<h3>Feature</h3>
<p>The <code>latest</code> tag of <a href="https://docs.cloud.google.com/docs/buildpacks/builders#generic_builder">generic builder</a>
uses the <code>google-24</code> stack.</p>
<h2 class="release-note-product-title">Cloud Database Migration Service</h2>
<h3>Feature</h3>
<p>Gemini-powered conversion quality assessments for heterogeneous migrations
in Database Migration Service are now generally available
(<a href="https://cloud.google.com/products#product-launch-stages" track-metadata-position="releaseNotes" track-metadata-srcpg="docs/release-notes" track-name="launch-stages-GA" track-type="releaseNoteLink">GA</a>).</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/database-migration/docs/convert-sql-with-dms#quality-assessments" track-metadata-position="releaseNotes" track-metadata-srcpg="docs/release-notes" track-name="gemini-conversion-qa-core" track-type="releaseNoteLink">
Convert SQL with Gemini in Database Migration Service</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Change</h3>
<p>The command for upgrading Cloud SQL instances to the new network architecture
has been re-enabled.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/mysql/upgrade-cloud-sql-instance-new-network-architecture">Upgrade an instance to the new network architecture</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Change</h3>
<p>The command for upgrading Cloud SQL instances to the new network architecture
has been re-enabled.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/postgres/upgrade-cloud-sql-instance-new-network-architecture">Upgrade an instance to the new network architecture</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Change</h3>
<p>The command for upgrading Cloud SQL instances to the new network architecture
has been re-enabled.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/sqlserver/upgrade-cloud-sql-instance-new-network-architecture">Upgrade an instance to the new network architecture</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Security</h3>
<p>A vulnerability in AMD firmware (CVE-2025-61971, CVE-2025-61972, CVE-2024-36315) that could compromise SEV-SNP guests has been addressed.
For more information, see the <a href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-031">GCP-2026-031 security bulletin</a>.</p>
<h3>Security</h3>
<p>A vulnerability (CVE-2025-54518) about potential corruption within the micro-operation (OP) cache in Zen 2 microarchitecture processors
was discovered and has been addressed.
For more information, see the
<a href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-032">GCP-2026-032 security bulletin</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Data store for GitLab (Preview)</strong></p>
<p>You can now connect GitLab data stores to Gemini Enterprise.</p>
<p>Support for GitLab data stores is in Public Preview. For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/gitlab">Connect GitLab</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS prerelease notes</strong></p>
<p>Here are the prerelease notes for the next version of Google Cloud CCaaS. When
we release this version, we expect the new capabilities to be as shown here.</p>
<h3>Feature</h3>
<p><strong>Agent status inheritance for HubSpot users</strong></p>
<p>You can configure CCAI Platform to synchronize agent statuses with
HubSpot agent statuses in real time. You can also map HubSpot agent statuses to
Contact Center AI Platform statuses (and vice versa) to account for different agent status
naming conventions.</p>
<p>Administrators: A new <strong>Settings <span aria-label="and then">&gt;</span> Developer Settings <span aria-label="and then">&gt;</span>
Agent Status Inheritance</strong> pane is available when you set <strong>Settings
<span aria-label="and then">&gt;</span> Developer Settings <span aria-label="and then">&gt;</span> Agent Platform</strong> to <strong>HubSpot</strong>.</p>
<h3>Feature</h3>
<p><strong>For call transfers in HubSpot, the ticket owner is automatically updated</strong></p>
<p>When a call is transferred from one agent to another with a HubSpot integration,
HubSpot tickets now automatically update to reflect the new ticket owner. This
provides an accurate record of ownership throughout the interaction lifecycle.
No configuration is required.</p>
<h3>Feature</h3>
<p><strong>Agent synchronization for HubSpot</strong></p>
<p>You can now configure your instance to use the default administrator user to
synchronize CCAI Platform and HubSpot agents. CCAI Platform
can use the default administrator user to create and update HubSpot accounts and
records, even when a matching HubSpot profile can't be found for an agent.</p>
<p>Administrators: A new <strong>Default User</strong> section is available in the <strong>Settings
<span aria-label="and then">&gt;</span> Developer Settings <span aria-label="and then">&gt;</span> CRM</strong> pane.</p>
<p>User experience change: When agent synchronization is configured, a new
<strong>Authorize</strong> button appears on the agent adapter.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where launching a task virtual assistant during a chat caused
the agent's screen to freeze.</p></li>
<li><p>Fixed an issue where call transcripts from CX Agent Studio agent
conversations were added to CRM records as garbled and unreadable text, with
repeated words and incorrect turn order.</p></li>
<li><p>Fixed an issue where the <strong>Wait Time</strong> custom field on Zendesk tickets
displayed an incorrect value when using custom fields for <strong>Account</strong> and
<strong>Record</strong>.</p></li>
<li><p>Fixed an issue where agents assigned a direct SMS-capable line didn't
receive visual notifications for incoming SMS chats in the agent adapter
while their status was set to <code>Unavailable</code>.</p></li>
<li><p>Fixed an issue where some chat transcripts couldn't be downloaded from the
<strong>Completed Chats</strong> page.</p></li>
<li><p>Fixed an issue where customer calls were unexpectedly abandoned during
payment transactions when DTMF inputs were provided.</p></li>
<li><p>Fixed an issue where agents heard repeated call notification sounds during
active calls, even when no new call was assigned.</p></li>
<li><p>Fixed an issue where only English IVR queues appeared when configuring
agent-specific deflection settings, even when other language queues were
available.</p></li>
</ul>
<!--
-   Fixed an issue where sentiment analysis didn't display to agents when calls
    were escalated from a virtual agent, even though the data was generated.
-->
<ul>
<li><p>Fixed an issue where email messages in queues displayed a blank white panel
when opened.</p></li>
<li><p>Fixed an issue where chat transcript and metadata files were generated as
empty files, causing API timeouts and blocking reporting pipelines.</p></li>
<li><p>Fixed an issue where chat sessions that ended due to end-user inactivity
were marked as <strong>Disconnected by end user</strong> instead of <strong>Timeout: end user
stopped responding</strong>.</p></li>
<li><p>Fixed an issue where agents couldn't receive more than 12 concurrent chats
despite being configured for up to 30.</p></li>
<li><p>Fixed an issue where virtual agent calls were routed back to the original
queue instead of being handled as expected.</p></li>
<li><p>Fixed an issue that occurred when a third party was added to a call. After
all participants left the call, the call still appeared to be connected.</p></li>
<li><p>Fixed an issue where cascade conditions for agent queues didn't correctly
enforce the minimum number of available UK agents before allowing calls to
cascade from the US queue, resulting in calls being routed incorrectly.</p></li>
<li><p>Fixed an issue where bulk user import incorrectly limited the chat
concurrency value to the global default, preventing valid per-agent settings
from being uploaded.</p></li>
</ul>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>BigQuery Connector for SAP version 2.14</strong></p>
<p>Version 2.14 of the BigQuery Connector for SAP is generally available (GA).
To protect configuration data, this version assigns the BigQuery Connector for SAP
configuration tables to the custom authorization group <code>ZSGC</code>.
You must ensure your user roles include authorization for this group to maintain access.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sap/docs/bq-connector/whats-new#version-2-14">What's new with BigQuery Connector for SAP</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 11, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_11_2026</id>
    <updated>2026-05-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_11_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Announcement</h3>
<p>AlloyDB now offers extended support for clusters running major PostgreSQL versions that have reached their end-of-life (EOL) as defined by the PostgreSQL community. Extended support provides an additional three years of support after the end of regular support, giving you more time to plan and perform major version upgrades. For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/extended-support">Extended support for AlloyDB for PostgreSQL</a>.</p>
<h2 class="release-note-product-title">Anthos Config Management</h2>
<h3>Fixed</h3>
<p>Removed the readinessProbe and deprecated health checks for the otel-agent sidecar to align its configuration with other containers.</p>
<h3>Feature</h3>
<p>Changed <code>logLevel</code> configuration to support values as low as -10 to reduce log verbosity in Config Sync containers.</p>
<h3>Feature</h3>
<p>Added support for token-based authentication when using OCI images from third-party registries.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>Cloud SQL for MySQL now supports regional endpoints for the Cloud SQL Admin API.
This feature lets you direct your API calls to a region-specific endpoint.
Using a regional endpoint enhances data locality and helps meet strict
compliance expectations. For more information, see
<a href="https://docs.cloud.google.com/sql/docs/mysql/admin-api/rep">Cloud SQL regional endpoints</a>.</p>
<p>This feature is in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>Cloud SQL for PostgreSQL now supports regional endpoints for the Cloud SQL Admin API.
This feature lets you direct your API calls to a region-specific endpoint.
Using a regional endpoint enhances data locality and helps meet strict
compliance expectations. For more information, see
<a href="https://docs.cloud.google.com/sql/docs/postgres/admin-api/rep">Cloud SQL regional endpoints</a>.</p>
<p>This feature is in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Feature</h3>
<p>Cloud SQL for SQL Server now supports regional endpoints for the Cloud SQL Admin API.
This feature lets you direct your API calls to a region-specific endpoint.
Using a regional endpoint enhances data locality and helps meet strict
compliance expectations. For more information, see
<a href="https://docs.cloud.google.com/sql/docs/sqlserver/admin-api/rep">Cloud SQL regional endpoints</a>.</p>
<p>This feature is in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>Google Cloud Observability has expanded the supported locations for observability buckets,
which store your trace data, to include the following:</p>
<ul>
<li>asia-northeast1</li>
<li>asia-southeast1</li>
<li>me-west2</li>
<li>southamerica-east1</li>
<li>us-west4</li>
</ul>
<p>For a list of supported locations, see
<a href="https://docs.cloud.google.com/stackdriver/docs/observability/observability-bucket-locations">Locations for observability buckets</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Change</h3>
<p>You can purchase <strong>Provisioned Throughput for Gemma 4</strong>. To learn
more, see the list of <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/provisioned-throughput/supported-models#open-models">supported
open models</a>.</p>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Feature</h3>
<p>You can now use Privileged Access Manager (PAM) to <a href="https://docs.cloud.google.com/vmware-engine/docs/private-clouds/howto-manage-private-cloud#delete-cluster">delete clusters</a>
in the private clouds.</p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for VMware</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for VMware 1.34.400-gke.88 is now available
for download. To upgrade, see <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/how-to/upgrading.md">Upgrade clusters</a>.
Google Distributed Cloud 1.34.400-gke.88 runs on Kubernetes v1.34.6-gke.200.</p>
<p>If you are using a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for use with GKE On-Prem API clients: the Google Cloud console, the
gcloud CLI, and Terraform.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.34.400-gke.88:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where the <code>gkectl check-config</code> command failed
during preflight checks when bundled ingress was disabled and the
<code>loadBalancer.vips.ingressVIP</code> field was left blank. This failure
occurred because the validation process incorrectly attempted to generate a
network configuration for test VMs using the empty VIP, resulting in an
invalid command (such as <code>ip addr add /32</code>) and causing test VM
initialization to fail.
</li>
<li>Resolved an issue that caused VMware cluster upgrades from non-advanced
clusters to advanced clusters to get stuck. The system attempted to update
immutable fields in the Hub membership. With this fix, the cluster operator
preserves the original membership fields during the upgrade process instead of
attempting to overwrite them so that the migration to an advanced cluster
completes successfully.</li></ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.34.400-gke.88 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.34.400-gke.88 runs on Kubernetes v1.34.6-gke.200.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Announcement</h3>
<p>The following features were added in 1.34.400-gke.88:</p>
<ul>
<li>Added a periodic health check to detect stale mounts of Secrets and
ConfigMaps on pods. This helps identify rare scenarios where nodes serve
outdated secret data after a rotation, which can lead to authentication
failures. Currently enabled for GKE Identity Service pods, the check
runs on each node and compares the locally cached volume content with the
live data from the API server, reporting a mismatch only after a 5-minute
grace period to allow for normal update delays.</li></ul>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.34.400-gke.88:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where, during the machine initialization phase, the
<code>etcd-events</code> pod read the stale data directory when it started
and attempted to reuse the old member ID to rejoin the cluster instead of the
new one. Trying to use the old member ID to rejoin the cluster resulted in an
infinite retry loop and caused the cluster to reject the connection. The fix
ensures the <code>/var/lib/etcd-events</code> directory is
cleared upon failure, and adds retry logic to <code>kubeadm-reset</code> to improve resiliency against transient API errors.
</li>
<li>Fixed an issue where concurrent tasks on the same node failed when
<code>containerd</code> restarts. After the fix, tasks are locked and run
sequentially to ensure each task completes successfully before the next
begins. Each lock is held for up to 20 minutes or until the task reaches
success or failure. To bypass this safety mechanism, you can run tasks
concurrently by adding <code>baremetal.cluster.gke.io/concurrent-machine-update: "true"</code>
to your cluster.
</li>
<li>Fixed an issue where node upgrades could hang indefinitely and bypass the
20-minute maintenance timeout. This issue occurred when a node contained
completed pods within a namespace that was in a <code>Terminating</code>
state. Because the Kubernetes Eviction API rejects operations in terminating
namespaces, the cluster controller entered an infinite retry loop. The fix
updates the drain process to skip eviction for pods in terminal phases,
allowing the upgrade to proceed normally.</li></ul>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Change</h3>
<p>Compliance Manager can be enabled for a single project. For more
information, see
<a href="https://docs.cloud.google.com/security-command-center/docs/compliance-manager-enable">Enable Compliance Manager</a>.</p>
<h3>Change</h3>
<p>New Standard tier activations at the organization level support the enhanced
Standard tier features. New Standard tier activations at the project level continue
to support Standard-legacy tier features. For more information, see
<a href="https://docs.cloud.google.com/security-command-center/docs/migrate-standard-legacy">Standard tier enhanced and automatically activated for some customers</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 09, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_09_2026</id>
    <updated>2026-05-09T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_09_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-120-64_">cos-beta-129-19506-120-64 <a id='"cos-arm64-beta-129-19506-120-64"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/261ec2a82c20483a919d7d25c05c7138ed1859c8
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.64/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-43284 (dirtyfrag) in the Linux kernel.</p>
<h3>Change</h3>
<p>Apply hardening sysctls on cchost boards.</p>
<h3>Change</h3>
<p>Enabled mm hardening kernel cmdlines on cchost.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23255 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23302 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23458 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31614 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31694 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31700 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31708 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31716 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31733 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31738 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31752 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31774 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31781 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35385 and CVE-2026-35386 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43012 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43013 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43016 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43024 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43028 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43030 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43035 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43038 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43043 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43054 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43057 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded cos-gpu-installer to v2.6.8.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 08, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_08_2026</id>
    <updated>2026-05-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_08_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Announcement</h3>
<p>Starting August 11, 2026, the billing label for the BigQuery Data Transfer
Service SKU will be updated from <code>goog-bq-feature-type: DATA_TRANSFER_SERVICE</code>
(uppercase) to <code>goog-bq-feature-type: data_transfer_service</code> (lowercase) to
provide a more unified and complete view of your costs. This update expands the
scope of the label to cover all costs associated with the BigQuery Data Transfer
Service, including data transfer orchestration, data load operations, and data
merge operations.</p>
<p>To ensure uninterrupted cost visibility, update your billing exports,
dashboards, and reporting queries to include both these labels.</p>
<h2 class="release-note-product-title">Cloud Workstations</h2>
<h3>Feature</h3>
<p>You can configure a workstation authorization URL for workstation clusters.</p>
<p>When you specify an authorization URL, unauthorized HTTP or HTTPS requests received
by workstation VMs in the cluster are redirected to this endpoint. The endpoint
is then responsible for retrieving an access token and redirecting back to the
original hostname with the token.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-125-19216-395-4_">cos-125-19216-395-4 <a id='"cos-arm64-125-19216-395-4"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8615dfb7470816ab28b148bb67bba5f12bb4ea0b
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.4/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This is an <a href="https://docs.cloud.google.com/container-optimized-os/docs/concepts/versioning#lts_refresh_releases">LTS Refresh release.</a></p>
<h3>Security</h3>
<p>Fixed CVE-2026-43284 (dirtyfrag) in the Linux kernel.</p>
<h3>Change</h3>
<p>Apply hardening sysctls on cchost boards.</p>
<h3>Change</h3>
<p>Enabled mm hardening kernel cmdlines on cchost.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.51.2.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.7.4.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libnetfilter_conntrack to v1.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/procps to v4.0.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31693 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31694 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31700 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31708 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31716 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31738 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31752 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31774 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31781 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35385 and CVE-2026-35386 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43012 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43013 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43016 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43024 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43028 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43030 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43035 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43038 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43043 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43057 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded cos-gpu-installer to v2.6.8.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-125_">cos-121-18867-381-125 <a id='"cos-arm64-121-18867-381-125"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/cb29612e10c383e119032dbb62243c2284a7a18d
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.125/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-43284 (dirtyfrag) in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31693 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31694 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31700 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31708 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31738 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31752 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31781 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43013 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43016 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43024 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43028 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43030 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43035 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43038 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43043 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43054 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43057 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-613-5_">cos-117-18613-613-5 <a id='"cos-arm64-117-18613-613-5"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e416822ebf1c6b3a9c3304ba8d9903b55190df6d
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.5/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This is an <a href="https://docs.cloud.google.com/container-optimized-os/docs/concepts/versioning#lts_refresh_releases">LTS Refresh release.</a></p>
<h3>Security</h3>
<p>Fixed CVE-2026-43284 (dirtyfrag) in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded net-fs/cifs-utils to v7.5.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/talloc to v2.4.4.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libnetfilter_conntrack to v1.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libtirpc to v1.3.7-r2.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/acl to v2.3.2-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/procps to v4.0.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35385 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Added: net.ipv4.tcp_pingpong_thresh: 1</li>
</ul></p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code_2">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Box data store using data federation</strong></p>
<p>Connecting a Box data source with Gemini Enterprise using data federation is
generally available (GA).</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/box/set-up-data-store">Set up a Box data store</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Change</h3>
<p><strong>Gemini Distillation Service Early Access</strong></p>
<p>We're introduction Gemini Distillation Service in Early Access. For information
about requesting access, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/tuning/distillation">Gemini Distillation
Service</a>.</p>
<h3>Change</h3>
<p><strong>Improvements to the Provisioned Throughput orders page</strong> have now
made it possible to:</p>
<ul>
<li>View all scheduled orders by using the Start Date column.</li>
<li>Enable filtering and sorting of orders by using column names.</li>
<li>Download all order data to a CSV file (including across all regions).</li>
</ul>
<p>See <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/provisioned-throughput/purchase-provisioned-throughput#view-orders">View standard Provisioned Throughput
orders</a>.</p>
<h2 class="release-note-product-title">Identity and Access Management</h2>
<h3>Feature</h3>
<p>You can use the IAM recommender to remediate excessive
permissions for Google groups by transitioning from permanent role
bindings to temporary, on-demand entitlements in Privileged Access Manager (PAM). This
feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>To learn how to remediate excessive permissions, see <a href="https://docs.cloud.google.com/iam/docs/pam-remediate-iam-recommendations">Remediate excessive
permissions with Privileged Access Manager</a>.</p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Announcement</h3>
<p>Dataplex Universal Catalog is now called Knowledge Catalog. The API, client
library, CLI, and Identity and Access Management (IAM) names remain unchanged.
For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/introduction">Knowledge Catalog overview</a>.</p>
<h2 class="release-note-product-title">Policy Controller</h2>
<h3>Change</h3>
<p>Policy Controller version 1.23.2 is now available.</p>
<h2 class="release-note-product-title">Policy Intelligence</h2>
<h3>Feature</h3>
<p>You can use the IAM recommender to remediate excessive
permissions for Google groups by transitioning from permanent role
bindings to temporary, on-demand entitlements in Privileged Access Manager (PAM). This
feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>To learn how to remediate excessive permissions, see <a href="https://docs.cloud.google.com/iam/docs/pam-remediate-iam-recommendations">Remediate excessive
permissions with Privileged Access Manager</a>.</p>
<h2 class="release-note-product-title">Storage Transfer Service</h2>
<h3>Feature</h3>
<p>Storage Transfer Service now supports AWS GovCloud (US) regions, including
<code>us-gov-east-1</code> and <code>us-gov-west-1</code>. You can now transfer data from Amazon S3
buckets located in GovCloud regions using both batch and event-driven
transfers.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/storage-transfer/docs/source-amazon-s3">Configure access to a source: Amazon S3</a>
and <a href="https://docs.cloud.google.com/storage-transfer/docs/event-driven-aws">Event-driven transfers from AWS S3</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 07, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_07_2026</id>
    <updated>2026-05-07T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_07_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee API hub</h2>
<h3>Feature</h3>
<p><strong>Unified MCP Proxy Configuration in API hub (Preview)</strong></p>
<p>API hub allows you to create and deploy Model Context Protocol (MCP) discovery proxies. Select specific API operations from your registered catalog, bundle them into an MCP server, and automatically deploy them as discovery proxies in your Apigee project. This feature eliminates the need to manually author MCP specifications in Apigee.</p>
<p>This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Public Preview</a>. For more information, see <a href="https://docs.cloud.google.com/apigee/docs/apihub/manage-mcp-proxies">Manage MCP proxies</a>.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>You can use <a href="https://github.com/GoogleCloudPlatform/cloud-bigtable-ecosystem/tree/main/aerospike-bigtable-migration-tools">Aerospike migration tools</a> to migrate data from Aerospike to Bigtable with minimal or zero downtime. This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. For more information, see <a href="https://docs.cloud.google.com/bigtable/docs/migrate-aerospike-to-bigtable">Migrate Aerospike to Bigtable</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-113-18244-582-103_">cos-113-18244-582-103 <a id='"cos-arm64-113-18244-582-103"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/55acfaa0d8192e080417075465aaffd1f75df1a9
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.103/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<!-- Aggregate release notes.
Please check whether the types are correct.
Available types are:
breaking_change|non_breaking_change|deprecation|feature|fix|security_bulletin|service_announcement|issue].
Please add another service_announcement block if this is an LTS Refresh release.-->
<h3>Security</h3>
<p>Fixed CVE-2026-23411 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31738 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31752 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43013 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43024 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43028 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43030 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43035 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43038 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43043 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43054 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43057 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-121_">cos-121-18867-381-121 <a id='"cos-arm64-121-18867-381-121"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/81a1a5c044b4f62bb492acb3dc787f12de339232
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.121/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-35385 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Upgraded cos-gpu-installer to v2.6.8.</p>
<h2 class="release-note-product-title">Dialogflow</h2>
<h3>Fixed</h3>
<p>A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a project using a maliciously crafted playbook import.
This vulnerability was patched on 15 March 2026, and no customer action is needed.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Data store for Google Sites (Preview)</strong></p>
<p>You can connect Google Sites data stores to Gemini Enterprise.</p>
<p>Support for Google Sites data stores is in Public Preview. For more
information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/connect-sites">Sync from Google Sites</a>.</p>
<h3>Security</h3>
<p><strong>Gemini Enterprise: Multiple API endpoints for the Integration Platform were inadvertently exposed.</strong></p>
<p>This issue has been resolved, and access has been restricted. No action is required from external customers.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Change</h3>
<p><strong>Gemini 3.1 Flash-Lite is now generally available</strong></p>
<p>Our most cost-efficient Gemini model, <strong>3.1 Flash-Lite</strong>, is out of preview and
is now generally available. For technical information on this model, see the
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-1-flash-lite">model information card</a>.</p>
<h3>Change</h3>
<p>You can purchase <strong>Provisioned Throughput for Gemini 3.1 Flash-Lite</strong>. To learn
more, see the <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/provisioned-throughput/overview">Provisioned Throughput
overview</a>.</p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Announcement</h3>
<p><strong>Looker 26.8</strong> is expected to include the following changes, features, and fixes:</p>
<ul>
<li>Expected Looker (original) deployment start: <strong>Sunday, May 10, 2026</strong></li>
<li>Expected Looker (original) final deployment and download available: <strong>Monday, May 25, 2026</strong></li>
<li>Expected Looker (Google Cloud core) deployment start:  <strong>Monday, May 11, 2026</strong></li>
<li>Expected Looker (Google Cloud core) final deployment: <strong>Monday, May 25, 2026</strong></li>
</ul>
<h3>Feature</h3>
<p>The ability for dashboard editors to <a href="https://docs.cloud.google.com/looker/docs/editing-user-defined-dashboards#download-limit">set default row and column limits</a> for dashboard tile downloads and for dashboard viewers to choose to edit these values when downloading the tile is now generally available.</p>
<h3>Feature</h3>
<p>Available in preview, you can <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents">publish the Conversational Analytics Explore data agents</a> that you create in Looker to Gemini Enterprise. All users who have the <code>save_agents</code> permission will be granted the <code>publish_agent_externally</code> permission. <strong>Note</strong>: This feature is not yet available. This release note was updated on May 14, 2026.</p>
<h3>Feature</h3>
<p>Available in preview, you can create and use Conversational Analytics <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents-dashboards">data agents on dashboards</a>. Dashboard agents uses the <a href="https://docs.cloud.google.com/looker/docs/dev-mode-prod-mode#production_mode">Production Mode</a> of content when querying Looker dashboards. <strong>Note</strong>: This feature is not yet available. This release note was updated on May 14, 2026.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/reference/param-field-approximate"><code>approximate</code></a> parameter is now supported on Snowflake connections.</p>
<h3>Change</h3>
<p>Conversational Analytics now supports <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data">querying Looker Explores</a> in <a href="https://docs.cloud.google.com/looker/docs/dev-mode-prod-mode#development_mode">Development Mode</a>.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where queries that used <a href="https://docs.cloud.google.com/looker/docs/custom-calendars">custom calendars</a> with <a href="https://docs.cloud.google.com/looker/docs/table-options#subtotals">subtotals</a> may have produced incorrect results.
<strong>Note:</strong> This item was updated on May 12, 2026.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where Looker could use an aggregate table of incorrect granularity if the SQL of a dimension was defined by using Liquid and if aggregate awareness was enabled. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where users who don't have the <code>see_user_dashboards</code> permission could get a 404 error when viewing the Looker home page. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where only admins could use the <strong>Unlock Branch</strong> feature. This feature is now available to LookML developers.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the <code>sync_lookml_dashboard</code> API endpoint was not compatible with tabbed dashboards. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>The generic error message that Looker produces when BigQuery OAuth connections are being tested has been updated to encourage checking the correct root cause, such as context-aware access restrictions. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where enabling Admin Assistant could have no effect. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where Conversational Analytics could not be used when an IP allowlist was enabled.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where appending the string <code>/edit</code> to an Explore URL could incorrectly change the Explore UI to the legacy Explore UI. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>The <strong>Page breaks between tabs</strong> option no longer appears on dashboards that don't have any tabs. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where enabling totals on a query with a period-over-period measure could cause Looker to return a 500 error. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where Looker could incorrectly display string filter options for a <code>time</code> timeframe instead of datetime filter options. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the <strong>Select All</strong> button on dashboards filters could appear even if the filter was not populated. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where LookML projects that contained the string "self-service" were incorrectly hidden in the <strong>Manage LookML Projects</strong> UI. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where navigating dialogs with the Tab key could cause the user to unexpectedly exit the dialog. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where updating dashboard filters could fail to update linked child filters. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where Looker could fail to save Markdown files that were edited in the Looker IDE. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where clearing numeric input fields on the <strong>Content Guardrails</strong> admin page caused Looker to input a zero that would be appended to subsequent user input. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where clicking links inside an iframe could result in a 401 or 403 error when cookieless embed was enabled. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where LookML dashboards could fail to appear on the home page. This feature now performs as expected.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-code-interpreter">Conversational Analytics Advanced Analytics</a> feature, formerly known as the Code Interpreter, is now generally available.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 06, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_06_2026</id>
    <updated>2026-05-06T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_06_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can configure BigQuery sharing listings for multiple regions, which
allows you to share datasets and linked replicas across global geographies
simultaneously. For more information, see
<a href="https://docs.cloud.google.com/bigquery/docs/analytics-hub-manage-listings#create_a_listing">Create a listing</a>.
This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Breaking</h3>
<p>Starting June 1, 2026, due to changes in Google Ads data retention policies,
the BigQuery Data Transfer Service connectors for <a href="https://docs.cloud.google.com/bigquery/docs/transfer-changes#June01-google-ads">Google
Ads</a>, <a href="https://docs.cloud.google.com/bigquery/docs/transfer-changes#June01-search-ads">Search Ads
360</a>, and <a href="https://docs.cloud.google.com/bigquery/docs/transfer-changes#June01-ga4">Google Analytics
4</a> will stop populating
data for backfill runs with dates earlier than 37 months from the current date.</p>
<p>For more information about the changes to the Google Ads data retention
policies, see <a href="https://ads-developers.googleblog.com/2026/05/new-data-retention-policy-for-google.html">New Data Retention Policy for Google Ads starting June 1,
2026</a>.</p>
<h2 class="release-note-product-title">Cloud Composer</h2>
<h3>Announcement</h3>
<p>Managed Airflow (Gen 2) environments can no longer be created in
Johannesburg (africa-south1). We're switching this region to
supporting only Managed Airflow (Gen 3) environments. Existing
Managed Airflow (Gen 2) environments in this region aren't affected by this
change.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>The following remote MCP servers automatically generate a trace span for
<code>tools/call</code> operations. These spans can help you understand the behavior of
your agentic applications. For more information, see
<a href="https://docs.cloud.google.com/stackdriver/docs/instrumentation/trace-remote-mcp-server-calls">Investigate MCP calls using Trace</a>.</p>
<ul>
<li>Agent Search</li>
<li>AlloyDB for PostgreSQL</li>
<li>Google Security Operations</li>
</ul>
<h2 class="release-note-product-title">Cluster Toolkit</h2>
<h3>Feature</h3>
<p>Cluster Toolkit v1.90.0 is available. This release adds an experimental
capability to submit jobs that you can use with the <code>gcluster job</code> command. This
version also adds support for regional AI zones in Slurm by using the
<code>locationPolicy.zones</code> resource. Additionally, this release updates examples for
GKE TPU, exposes outputs for accelerator topology and slice controllers, and
fixes several Slurm issues. For details, see the <a href="https://github.com/GoogleCloudPlatform/cluster-toolkit/pull/5603">Release announcement on
GitHub</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: New data stores (Public Preview)</strong></p>
<p>The following data stores are available in Gemini Enterprise:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/mermaid_chart">Mermaid Chart</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/blockscout">Blockscout</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/open_targets">Open Targets</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/apollo-graphos">Apollo GraphOS MCP Tools</a></li>
</ul>
<p>These data stores are in Public Preview. For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/connect-third-party-data-source">Connect a third-party data source</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Fixed</h3>
<p>Fixed an issue with <strong>Audio track extraction (Gemini Embedding 2 only)</strong> where the <code>audio_track_extraction</code> feature did not work. For more information, see <a href="https://issuetracker.google.com/504505771">Issue #504505771</a>.</p>
<h3>Change</h3>
<p><strong>Agent Platform Gemini 3.1 Flash Image and Gemini 3 Pro Image</strong></p>
<p>Gemini Enterprise Agent Platform Gemini 3.1 Flash Image Preview and Gemini 3 Pro
Image Preview are introducing the following changes:</p>
<ul>
<li>Upgrades to improve 4K outputs and efficiency in both models</li>
<li>Gemini 3.1 Flash Image Preview and Gemini 3 Pro Image Preview will now
return a maximum of 1 thought image.</li>
<li>The image_size parameter for Gemini 3.1 Flash Image Preview now accepts
"512", "512p", "512P", "512PX", "512px" to generate 0.5MP resolution output
images.</li>
<li>The default thinking level for Gemini 3.1 Flash Image Preview changed to
Minimal.</li>
</ul>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Mobile SDK for iOS version 2.15.3 patch</strong></p>
<p>This patch updates the following for the mobile SDK for iOS:</p>
<ul>
<li>Fixes an issue where the iOS SDK app crashed when a user clicked <strong>End
chat</strong>.</li>
</ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for VMware</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for VMware 1.35.0-gke.525 is now available
for download. To upgrade, see <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/how-to/upgrading.md">Upgrade clusters</a>.
Google Distributed Cloud 1.35.0-gke.525 runs on Kubernetes v1.35.2-gke.300.</p>
<p>If you are using a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for use with GKE On-Prem API clients: the Google Cloud console, the
gcloud CLI, and Terraform.</p>
<h3>Announcement</h3>
<p>The following features were added in 1.35.0-gke.525:</p>
<ul>
<li><p>Platform update to Kubernetes 1.35: This release updates the underlying Kubernetes version to 1.35.</p>
<aside class="important">This release requires the use of `cgroupsv2`. Using `cgroupsv1` is no longer supported and cluster creation or upgrades will fail. A preflight check will actively block the operation if `cgroupsv1` is detected.</aside>
<ul>
<li>As part of the sunset of <code>cgroupsv1</code>, the legacy <code>ubuntu</code>, <code>ubuntu_containerd</code>, and <code>cos</code> <code>OSImageType</code> options are no longer supported in this release.</li>
<li>For more information on migrating to <code>cgroupsv2</code>, see the Kubernetes documentation on <a href="https://kubernetes.io/docs/concepts/architecture/cgroups/#migrating-cgroupv2">migrating to cgroupv2</a>.</li>
<li>This release also upgrades the container runtime, containerd, from version 2.0 to 2.1.
</li>
</ul></li>
<li><p>The Ubuntu image has been upgraded to 24.04 on all node types for 1.35.0-gke.525.
When you upgrade your control plane and node pools, the nodes are
automatically recreated with the new operating system image.
</p></li>
<li><p><code>gkectl</code> prints the Operation ID and Operation Type to the console after
cluster operations.</p></li>
<li><p>For advanced clusters, the default node pool update policy is changed to parallel
instead of sequential. This applies to all advanced clusters (both new and
existing upon upgrade). To customize or revert this behavior, use the
<code>nodePoolUpdatePolicy</code> and <code>maximumConcurrentNodePoolUpdate</code> fields in the
cluster configuration file.</p></li>
<li><p>The default Docker bridge IP for advanced clusters has been changed to <code>169.
254.123.1/24</code> instead of <code>172.17.0/16</code>. This change reduces the likelihood of
conflicts with user-configured networks. If you use the <code>172.17.0/16</code> range
for other purposes, cluster creation might fail due to this conflict.</p></li>
<li><p><code>vsphere-csi-controller</code> in advanced clusters is deployed on the user
cluster control plane nodes instead of worker nodes. This architectural
change happens automatically during upgrade and does not impact resource
sizing recommendations.</p></li>
</ul>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.35.0-gke.525:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Resolved an issue that caused VMware cluster upgrades from non-advanced
clusters to advanced clusters to get stuck. The system attempted to update
immutable fields in the Hub membership. With this fix, the cluster operator
preserves the original membership fields during the upgrade process instead of
attempting to overwrite them so that the migration to an advanced cluster
completes successfully.
</li>
<li>Fixed an issue in Advanced user clusters where the <code>cloud.google.com/
gke-nodepool</code> label for workload node pools unexpectedly included an <code>-np</code>
suffix. This caused pods using <code>nodeSelector</code> targeting the original pool
name (such as Apigee workloads) to fail to schedule. For clusters on older
versions experiencing this issue, you can work around it by manually setting
the expected label in the node pool configuration.
</li>
<li>Fixed an issue where setting the deprecated <code>stackdriver.enableVPC</code> field to
<code>true</code> in a cluster configuration file would block upgrades to an Advanced
Cluster. The <code>stackdriver.enableVPC</code> field has been deprecated and its
setting will be ignored during the upgrade validation process. For clusters on
older versions experiencing this issue, you can work around it by removing
the field or setting it to <code>false</code> in your configuration file before
upgrading.
</li>
<li>Fixed an issue where the node-problem-detector was incorrectly deployed onto
non-Advanced VMware clusters. This caused the containerd runtime to
continuously restart on affected nodes due to incompatible health check
configurations, leading to ETCD/CRI failures (such as errors connecting to
<code>/run/containerd/containerd.sock</code>) and unsuccessful cluster upgrades.
</li>
<li>Fixed an issue where leading or trailing whitespaces in the proxy.url field,
or spaces after commas in the proxy.noProxy list in the cluster configuration
file, caused advanced cluster creation or upgrades to fail. This release adds
validation to reject such malformed configurations before operations begin.
For upgrades, logic has been added to automatically handle and clean up these
spaces in the operator cluster state to prevent upgrade failures. If you are
using an older version and encounter this issue, ensure that all proxy
configuration fields are free of extraneous spaces.
</li>
<li>Fixed an issue where retrying the gkectl upgrade admin command after a
previous failure would fail with a "failed to create credential namespace in
bootstrap cluster" error. This occurred because the setup process failed to
handle resources that already existed from the previous attempt. This fix
resolves the issue described in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/troubleshooting/known-issues#gkectl-upgrade-admin-fails-on-retry-with-alreadyexists-errors-in-the-bootstrap-cluster"><code>gkectl upgrade admin</code> fails on retry with "AlreadyExists" errors in the bootstrap cluster</a>, eliminating the need to manually delete conflicting
resources from the bootstrap cluster before retrying.
</li>
<li>Fixed an issue where the system's root certificates were ignored when a
custom CA certificate was configured for a registry mirror or private
registry. This caused cluster creation or upgrades to fail with an x509:
certificate signed by unknown authority error when attempting to pull images.
The system honors both the custom CA and the system's root certificates.
</li>
<li>Fixed an issue where vSphere VM creation could hang indefinitely, with the
operation remaining stuck in the Creating phase and logs repeatedly reporting
"VM creation in progress." This fix introduces a one-hour timeout for VM
creation and ensures the machine status is updated in Kubernetes during each
reconciliation, eliminating the need to manually delete the stuck VM resource
from the temporary bootstrap cluster to recover.</li>
<li>Fixed an issue where upgrading non-advanced clusters with OIDC configuration
to advanced clusters caused users to fail to log in via Anthos Identity
Service (AIS) immediately after the upgrade.</li>
</ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.35.0-gke.525 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.35.0-gke.525 runs on Kubernetes v1.35.2-gke.300.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Announcement</h3>
<p>The following features were added in 1.35.0-gke.525:</p>
<ul>
<li><p>Platform update to Kubernetes 1.35: This release updates the underlying Kubernetes version to 1.35.</p>
<aside class="important">This release requires the use of `cgroupsv2`. Using `cgroupsv1` is no longer supported and cluster creation or upgrades will fail. A preflight check will actively block the operation if `cgroupsv1` is detected.</aside>
<ul>
<li>For customers using Red Hat Enterprise Linux (RHEL) 7 or 8, which default to <code>cgroupsv1</code>, you must manually configure your operating system to enable <code>cgroupsv2</code> before upgrading. For instructions, see the Red Hat knowledge base article on <a href="https://access.redhat.com/articles/3735611">enabling cgroup v2</a>.</li>
<li>For more information on migrating to <code>cgroupsv2</code>, see the Kubernetes documentation on <a href="https://kubernetes.io/docs/concepts/architecture/cgroups/#migrating-cgroupv2">migrating to cgroupv2</a>.</li>
<li>This release upgrades the container runtime, containerd, from version 2.0 to 2.1.
</li>
</ul></li>
<li><p>Added a periodic health check to detect stale secret and ConfigMap mounts on
Google Kubernetes Engine pods. To account for normal propagation delays, a
content mismatch is only reported as an error if the data remains stale for
more than 5 minutes.
</p></li>
<li><p>Upgraded the Ansible version to 2.18. This version requires
Python 3.9 on target nodes. For customers using Red Hat Enterprise Linux,
version 8.10 or later is required because the default Python version in
earlier Red Hat 8 releases (Python 3.6) is not supported by Ansible 2.18.</p></li>
<li><p>You can use the header section of the cluster configuration file to
specify registry mirrors for your clusters. This simplifies the management of
registry mirrors and provides a more consistent configuration experience. For
instructions on how to update or remove these settings, see the <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/installing/registry-mirror#header_section">Registry
Mirror documentation</a>.
</p></li>
<li><p><strong>Preview</strong> Added support for EgressDSCP tagging. With this feature, you can
mark IP headers with specific Differentiated Services Code Point (DSCP)
values on packets leaving the cluster to prioritize network traffic. To use
this feature, you must set <code>preview.baremetal.cluster.gke.io/traffic-selector:</code>
to <code>enable</code> in your cluster configuration and manage traffic selection using
the <code>EgressDSCP</code> and <code>TrafficSelector</code> custom resources. For more information,
see <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/how-to/egress-dscp-tagging.md">Configure EgressDSCP tagging</a>.
</p></li>
<li><p><code>bmctl</code> prints the Operation ID and OperationType to the console after
cluster installation and upgrade operations.</p></li>
</ul>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.35.0-gke.525:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where node upgrades could hang indefinitely and bypass the
20-minute maintenance timeout. This issue occurred when a node contained
completed pods within a namespace that was in a <code>Terminating</code> state. Because
the Kubernetes Eviction API rejects operations in terminating namespaces, the
cluster controller entered an infinite retry loop. The fix updates the drain
process to skip eviction for pods in terminal phases, allowing the upgrade to
proceed normally.
</li>
<li>Fixed an issue where concurrent tasks on the same node failed when containerd
restarts. After the fix, tasks are locked and run sequentially to ensure each
task completes successfully before the next begins. Each lock is held for up
to 20 minutes or until the task reaches success or failure.
To bypass this safety mechanismrun and run tasks concurrently, add the
following annotation to your cluster:
<code>baremetal.cluster.gke.io/concurrent-machine-update: "true"</code>.
</li>
<li>Fixed an issue where Metrics API operations—including <code>kubectl top</code>,
Horizontal Pod Autoscaling, and Vertical Pod Autoscaling could
fail with TLS verification errors during certificate authority rotation. This
occurred because the leaf certificate was not immediately renewed when the
certificate authority was rotated, causing a temporary mismatch between the
trusted certificate authority bundle and the certificate presented by the
metrics server.</li>
<li>Fixed an issue where Cluster CA rotation could hang indefinitely on
self-managed clusters, with the bmctl command hanging at the "Trust CA Bundle
completed in 0/X machines" stage. This occurred due to a state deadlock
during the resource pivot operation (moving resources between management and
bootstrap clusters). This fix resolves the deadlock, eliminating the need to
manually update cluster fields or remove lock ConfigMaps to recover.
</li>
<li>Fixed an issue where temporary API server connectivity failures (such as
network timeouts) caused the system to unnecessarily re-register and redeploy
the GKE Connect agent. This fix prevents these temporary errors from
resetting manual or system-applied customizations to the agent deployment,
improving cluster stability.
</li>
<li>Fixed an issue where bmctl could fail to capture the full log for
long-running operations, resulting in empty or incomplete job logs in the
workspace. This occurred because a strict internal timeout stopped log
streaming prematurely. The fix ensures that log streaming continues for the
full duration of the operation's pod lifecycle.
</li>
<li>Fixed an issue in the monitoring component of the cluster operator where
delete operations could cause the operator to crash if the resource had no
annotations. The fix ensures the system properly handles resources with empty
annotation maps, preventing the crash.
</li>
<li>Fixed an issue where the anet-operator could be scheduled to an unreachable
node and become stuck in a Pending state, eventually causing networking to
fail. This occurred due to overly permissive scheduling rules. The fix
restricts scheduling to prevent the operator from running on unreachable nodes
and explicitly places it on control plane nodes to ensure reliability.</li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r18-version-updates">(2026-R18) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1137000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1321000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.1575000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.32.13-gke.1362000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1407000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1013000</li>
<li>1.34.6-gke.1307000</li>
<li>1.35.3-gke.1522000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.32.13-gke.1258000</li>
<li>1.32.13-gke.1318000</li>
<li>1.33.10-gke.1115000</li>
<li>1.34.6-gke.1154000</li>
<li>1.35.3-gke.1234000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1068000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.32.13-gke.1059000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1205000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1060000</li>
<li>1.34.5-gke.1076000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1269001 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1068000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1352">1.35.2-gke.1962000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1816000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2320000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2415000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1723000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1823000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1115000</li>
<li>1.34.6-gke.1154000</li>
<li>1.35.3-gke.1234000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2369000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2369000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1790000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1137000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1321000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1137000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1321000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.32.13-gke.1059000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1205000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1258000</li>
<li>1.32.13-gke.1318000</li>
<li>1.32.13-gke.1362000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1407000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1026000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1076000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.1-gke.1396002 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1269001 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1485000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r18-security-updates">(2026-R18) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.30.14-gke.2441000</td>
<td>cos-117-18613-534-106</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-106_">cos-117-18613-534-106 release notes</a></td>
</tr>
<tr>
<td>1.31.14-gke.1850000</td>
<td>cos-117-18613-534-106</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-106_">cos-117-18613-534-106 release notes</a></td>
</tr>
<tr>
<td>1.32.13-gke.1449000</td>
<td>cos-117-18613-534-106</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-106_">cos-117-18613-534-106 release notes</a></td>
</tr>
<tr>
<td>1.33.11-gke.1137000</td>
<td>cos-121-18867-381-113</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-381-113_">cos-121-18867-381-113 release notes</a></td>
</tr>
<tr>
<td>1.34.7-gke.1321000</td>
<td>cos-125-19216-220-180</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-220-180_">cos-125-19216-220-180 release notes</a></td>
</tr>
<tr>
<td>1.35.3-gke.1993000</td>
<td>cos-125-19216-220-180</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-220-180_">cos-125-19216-220-180 release notes</a></td>
</tr>
<tr>
<td>1.36.0-gke.1575000</td>
<td>cos-125-19216-220-180</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-220-180_">cos-125-19216-220-180 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Fixed</h3>
<p>A fix is available for an issue that caused incomplete file reads and premature
end-of-file (EOF) errors when you used the Cloud Storage FUSE CSI driver on
ARM64 nodes that use 64 KiB page sizes, such as A4X and A4X Max instances. This
issue occurred because the kernel read-ahead mechanism triggered read requests
that exceeded the capacity of the Cloud Storage FUSE layer.</p>
<p>To resolve this issue, upgrade your cluster to one of the following versions:</p>
<ul>
<li>1.33.11-gke.1019000 or later</li>
<li>1.34.6-gke.1154000 or later</li>
<li>1.35.2-gke.1485000 or later</li>
</ul>
<h3>Feature</h3>
<p>GKE Pod Snapshots is generally available on clusters that run version
1.35.3-gke.1234000 or later. For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/pod-snapshots">About GKE Pod
snapshots</a>.</p>
<h3>Feature</h3>
<p>In GKE Standard clusters, <a href="https://docs.cloud.google.com/compute/docs/instances/live-migration-process">live
migration</a>
is now supported on Confidential GKE Nodes that use <a href="https://docs.cloud.google.com/compute/docs/general-purpose-machines#c3d_machines">C3D machine
series</a>
with <a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/confidential-vm-overview#amd_sev">AMD
SEV</a>
enabled.</p>
<h3>Change</h3>
<h4 id="2026-r18-version-updates">(2026-R18) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1068000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.32.13-gke.1059000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1205000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1060000</li>
<li>1.34.5-gke.1076000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1269001 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1068000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1352">1.35.2-gke.1962000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r18-version-updates">(2026-R18) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.32.13-gke.1258000</li>
<li>1.32.13-gke.1318000</li>
<li>1.33.10-gke.1115000</li>
<li>1.34.6-gke.1154000</li>
<li>1.35.3-gke.1234000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r18-version-updates">(2026-R18) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1137000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1321000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.1575000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.32.13-gke.1362000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1407000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1013000</li>
<li>1.34.6-gke.1307000</li>
<li>1.35.3-gke.1522000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r18-version-updates">(2026-R18) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1137000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1321000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1137000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1321000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1993000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.32.13-gke.1059000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1205000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1258000</li>
<li>1.32.13-gke.1318000</li>
<li>1.32.13-gke.1362000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1407000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1026000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1076000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.1-gke.1396002 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1269001 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1485000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r18-version-updates">(2026-R18) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1816000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2320000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2415000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1723000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1823000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1115000</li>
<li>1.34.6-gke.1154000</li>
<li>1.35.3-gke.1234000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2369000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2369000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1790000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>Tenable.io</strong>: Version 18.0</p>
<ul>
<li><p>Improved the handling of concurrent requests and API rate limits in the
following action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>SiemplifyUtilities</strong>: Version 30.0</p>
<ul>
<li><p>Added support for backticks to the following action:</p>
<ul>
<li><strong>Query Joiner</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Active Directory</strong>: Version 27.0</p>
<ul>
<li><p>Updated enrichment logic to ensure <code>id</code> is fetched when
<code>Include Last Sign In Details</code> is enabled in the following action:</p>
<ul>
<li><strong>Enrich User</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Next Gen Firewall</strong>: Version 29.0</p>
<ul>
<li><strong>Integration</strong>: Updated Manager to reuse the API token instead of generating
a new one.</li>
</ul>
<h2 class="release-note-product-title">Oracle Database@Google Cloud</h2>
<h3>Feature</h3>
<p>For Exadata Database Service on Exascale infrastructure and Base Database Service, Oracle Database@Google Cloud supports the following regions and zones:</p>
<ul>
<li><code>asia-south1-b-r1</code> (Mumbai, India)</li>
<li><code>asia-south2-b-r1</code> (Delhi, India)</li>
</ul>
<p>For a list of supported locations, see <a href="https://docs.cloud.google.com/oracle/database/docs/regions-and-zones">Supported regions and zones</a>.</p>
<h2 class="release-note-product-title">Secure Source Manager</h2>
<h3>Feature</h3>
<p>You can now use <a href="https://docs.cloud.google.com/secure-source-manager/docs/codeowners">CODEOWNERS files</a> to define required reviewers for pull requests.</p>
<h2 class="release-note-product-title">Virtual Private Cloud</h2>
<h3>Feature</h3>
<p>Organization Policy Service custom constraints are available in
<strong>General Availability</strong> for private services access connections. For more
information, see
<a href="https://docs.cloud.google.com/vpc/docs/private-services-access#org-policies">Restrict private connections with organization policies</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 05, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_05_2026</id>
    <updated>2026-05-05T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_05_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Config Connector</h2>
<h3>Announcement</h3>
<p>Config Connector version 1.149.1 is now available.</p>
<h3>Feature</h3>
<p>New Alpha Resources (Direct Reconciler):</p>
<ul>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/networkservices/networkserviceslbrouteextension"><code>NetworkServicesLBRouteExtension</code></a> <a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/6957">#6957</a>
<ul>
<li>Manage <a href="https://cloud.google.com/service-extensions/docs/optimize-proxies-lb-route-extensions">load balancing route extensions</a> which let you inject custom logic into the load balancing path.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/parametermanager/parametermanagerparameterversion"><code>ParameterManagerParameterVersion</code></a> <a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/7140">#7140</a>
<ul>
<li>Manage <a href="https://cloud.google.com/secret-manager/docs/parameter-manager">Parameter Manager parameter versions</a> which lets you to manage regional parameters.</li>
</ul></li>
</ul>
<h3>Feature</h3>
<p>New Features:</p>
<ul>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/6243">Controlled CR reconciliation</a> Added support for unmanaging specific resources through <code>resourceSettings</code> in <code>ConfigConnector</code> (global) and <code>ConfigConnectorContext</code> (per-namespace). This lets you to selectively disable reconciliation for specific Group/Kinds to save memory or manage resources differently.</li>
</ul>
<h3>Change</h3>
<p>Reconciliation Improvements:</p>
<p>Added support for direct reconciliation to more resources, with opt-in behaviour. The API is unchanged. To use the direct reconciler, add the <code>cnrm.cloud.google.com/reconciler: direct</code> annotation to the corresponding Config Connector object.</p>
<ul>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/bigquery/bigquerydatasetaccess"><code>BigQueryDatasetAccess</code></a> <a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/7000">#7000</a></li>
</ul>
<h3>Fixed</h3>
<p>Bug Fixes:</p>
<ul>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/7642">Preview Tool</a> Fixed a connection error in the Config Connector preview tool and enforced read-only access to the cluster for improved security.</li>
</ul>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Announcement</h3>
<p>The VMware Engine <a href="https://docs.cloud.google.com/vmware-engine/docs/concepts/node-types"><code>ve2</code> node type</a> is now available in the following
additional region:</p>
<ul>
<li>Eemshaven, Netherlands (<code>europe-west4-a</code>)</li></ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Change</h3>
<p>Google SecOps has updated the list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.</p>
<p>The following supported default parsers have been updated. Each parser is listed by product name and <code>log_type</code> value, where applicable. This list includes both released default parsers and pending parser updates.</p>
<ul>
<li>Akeyless Vault Platform (<code>AKEYLESS_VAULT</code>)</li>
<li>Apache Cassandra (<code>CASSANDRA</code>)</li>
<li>Aruba (<code>ARUBA_WIRELESS</code>)</li>
<li>Aruba EdgeConnect SD-WAN (<code>ARUBA_EDGECONNECT_SDWAN</code>)</li>
<li>Auth0 (<code>AUTH_ZERO</code>)</li>
<li>AWS Aurora (<code>AWS_AURORA</code>)</li>
<li>AWS EC2 VPCs (<code>AWS_EC2_VPCS</code>)</li>
<li>AWS Security Hub (<code>AWS_SECURITY_HUB</code>)</li>
<li>Azure Firewall (<code>AZURE_FIREWALL</code>)</li>
<li>Azure Front Door (<code>AZURE_FRONT_DOOR</code>)</li>
<li>Barracuda CloudGen Firewall (<code>BARRACUDA_CLOUDGEN_FIREWALL</code>)</li>
<li>Blue Coat Proxy (<code>BLUECOAT_WEBPROXY</code>)</li>
<li>Check Point (<code>CHECKPOINT_FIREWALL</code>)</li>
<li>Check Point Sandblast (<code>CHECKPOINT_EDR</code>)</li>
<li>Checkpoint SmartDefense (<code>CHECKPOINT_SMARTDEFENSE</code>)</li>
<li>Chronicle SOAR Audit (<code>CHRONICLE_SOAR_AUDIT</code>)</li>
<li>Cisco Application Centric Infrastructure (<code>CISCO_ACI</code>)</li>
<li>Cisco ASA (<code>CISCO_ASA_FIREWALL</code>)</li>
<li>Cisco FireSIGHT Management Center (<code>CISCO_FIRESIGHT</code>)</li>
<li>Cisco Internetwork Operating System (<code>CISCO_IOS</code>)</li>
<li>Cisco ISE (<code>CISCO_ISE</code>)</li>
<li>Cisco Meraki (<code>CISCO_MERAKI</code>)</li>
<li>Cisco Secure Access (<code>CISCO_SECURE_ACCESS</code>)</li>
<li>Cisco Secure Workload (<code>CISCO_SECURE_WORKLOAD</code>)</li>
<li>Cisco Switch (<code>CISCO_SWITCH</code>)</li>
<li>Cisco Umbrella Audit (<code>CISCO_UMBRELLA_AUDIT</code>)</li>
<li>Cisco WLC/WCS (<code>CISCO_WIRELESS</code>)</li>
<li>Citrix Netscaler (<code>CITRIX_NETSCALER</code>)</li>
<li>Claroty Xdome (<code>CLAROTY_XDOME</code>)</li>
<li>Cloudflare Warp (<code>CLOUDFLARE_WARP</code>)</li>
<li>CrowdStrike Alerts API (<code>CS_ALERTS</code>)</li>
<li>CrowdStrike Falcon (<code>CS_EDR</code>)</li>
<li>CyberArk (<code>CYBERARK</code>)</li>
<li>CyberArk Privileged Access Manager (PAM) (<code>CYBERARK_PAM</code>)</li>
<li>EPIC Systems (<code>EPIC</code>)</li>
<li>F5 ASM (<code>F5_ASM</code>)</li>
<li>F5 BIGIP Access Policy Manager (<code>F5_BIGIP_APM</code>)</li>
<li>F5 BIGIP LTM (<code>F5_BIGIP_LTM</code>)</li>
<li>F5 Distributed Cloud Services (<code>F5_DCS</code>)</li>
<li>FireEye eMPS (<code>FIREEYE_EMPS</code>)</li>
<li>FireEye NX (<code>FIREEYE_NX</code>)</li>
<li>FortiGate (<code>FORTINET_FIREWALL</code>)</li>
<li>Fortinet FortiEDR (<code>FORTINET_FORTIEDR</code>)</li>
<li>Fortinet Proxy (<code>FORTINET_WEBPROXY</code>)</li>
<li>GitHub (<code>GITHUB</code>)</li>
<li>Google Cloud Audit (<code>GCP_CLOUDAUDIT</code>)</li>
<li>Google Threat Intelligence IOC (<code>GTI_IOC</code>)</li>
<li>Guardicore Centra (<code>GUARDICORE_CENTRA</code>)</li>
<li>HP Aruba (ClearPass) (<code>CLEARPASS</code>)</li>
<li>Huawei Switches (<code>HUAWEI_SWITCH</code>)</li>
<li>IBM Websphere Application Server (<code>IBM_WEBSPHERE_APP_SERVER</code>)</li>
<li>IBM z/OS (<code>IBM_ZOS</code>)</li>
<li>Imperva SecureSphere Management (<code>IMPERVA_SECURESPHERE</code>)</li>
<li>Infoblox (<code>INFOBLOX</code>)</li>
<li>Juniper (<code>JUNIPER_FIREWALL</code>)</li>
<li>Kubernetes Node (<code>KUBERNETES_NODE</code>)</li>
<li>Linux Auditing System (AuditD) (<code>AUDITD</code>)</li>
<li>ManageEngine ADManager Plus (<code>ADMANAGER_PLUS</code>)</li>
<li>McAfee ePolicy Orchestrator (<code>MCAFEE_EPO</code>)</li>
<li>McAfee Web Gateway (<code>MCAFEE_WEBPROXY</code>)</li>
<li>Microsoft Defender For Cloud (<code>MICROSOFT_DEFENDER_CLOUD_ALERTS</code>)</li>
<li>Microsoft Defender for Endpoint (<code>MICROSOFT_DEFENDER_ENDPOINT</code>)</li>
<li>Microsoft Defender for Identity (<code>MICROSOFT_DEFENDER_IDENTITY</code>)</li>
<li>Microsoft Graph API Alerts (<code>MICROSOFT_GRAPH_ALERT</code>)</li>
<li>Microsoft IIS (<code>IIS</code>)</li>
<li>Mobileiron (<code>MOBILEIRON</code>)</li>
<li>Model Armor (<code>GCP_MODEL_ARMOR</code>)</li>
<li>MySQL (<code>MYSQL</code>)</li>
<li>Netskope Web Proxy (<code>NETSKOPE_WEBPROXY</code>)</li>
<li>Noname API Security (<code>NONAME_API_SECURITY</code>)</li>
<li>Office 365 (<code>OFFICE_365</code>)</li>
<li>Okta (<code>OKTA</code>)</li>
<li>Oracle Cloud Infrastructure Audit Logs (<code>OCI_AUDIT</code>)</li>
<li>Oracle NetSuite (<code>ORACLE_NETSUITE</code>)</li>
<li>Palo Alto Networks Firewall (<code>PAN_FIREWALL</code>)</li>
<li>Palo Alto Panorama (<code>PAN_PANORAMA</code>)</li>
<li>Palo Alto Prisma Access (<code>PAN_CASB</code>)</li>
<li>Palo Alto Prisma Cloud Alert payload (<code>PAN_PRISMA_CA</code>)</li>
<li>Ping Identity (<code>PING</code>)</li>
<li>PostFix Mail (<code>POSTFIX_MAIL</code>)</li>
<li>Proofpoint On Demand (<code>PROOFPOINT_ON_DEMAND</code>)</li>
<li>Proofpoint Tap Alerts (<code>PROOFPOINT_MAIL</code>)</li>
<li>Proofpoint Threat Response (<code>PROOFPOINT_TRAP</code>)</li>
<li>Radware Web Application Firewall (<code>RADWARE_FIREWALL</code>)</li>
<li>Rapid7 Insight (<code>RAPID7_INSIGHT</code>)</li>
<li>SAP Hana Audit (<code>SAP_HANA_AUDIT</code>)</li>
<li>SecureAuth (<code>SECUREAUTH_SSO</code>)</li>
<li>Security Command Center Posture Violation (<code>GCP_SECURITYCENTER_POSTURE_VIOLATION</code>)</li>
<li>Security Command Center Threat (<code>GCP_SECURITYCENTER_THREAT</code>)</li>
<li>Security Command Center Toxic Combination (<code>GCP_SECURITYCENTER_TOXIC_COMBINATION</code>)</li>
<li>SentinelOne Deep Visibility (<code>SENTINEL_DV</code>)</li>
<li>SentinelOne Singularity Cloud Funnel (<code>SENTINELONE_CF</code>)</li>
<li>Silverfort Authentication Platform (<code>SILVERFORT</code>)</li>
<li>SiteMinder Web Access Management (<code>CA_SSO_WEB</code>)</li>
<li>SonicWall (<code>SONIC_FIREWALL</code>)</li>
<li>Squid Web Proxy (<code>SQUID_WEBPROXY</code>)</li>
<li>STIX Threat Intelligence (<code>STIX</code>)</li>
<li>Suricata EVE (<code>SURICATA_EVE</code>)</li>
<li>Sysdig (<code>SYSDIG</code>)</li>
<li>Tanium Threat Response (<code>TANIUM_THREAT_RESPONSE</code>)</li>
<li>Thinkst Canary (<code>THINKST_CANARY</code>)</li>
<li>Trend Micro Apex one (<code>TRENDMICRO_APEX_ONE</code>)</li>
<li>Unix system (<code>NIX_SYSTEM</code>)</li>
<li>Vectra XDR (<code>VECTRA_XDR</code>)</li>
<li>VMware ESXi (<code>VMWARE_ESX</code>)</li>
<li>Wallix Bastion (<code>WALLIX_BASTION</code>)</li>
<li>WatchGuard (<code>WATCHGUARD</code>)</li>
<li>Windows Defender AV (<code>WINDOWS_DEFENDER_AV</code>)</li>
<li>Windows DNS (<code>WINDOWS_DNS</code>)</li>
<li>Windows Event (<code>WINEVTLOG</code>)</li>
<li>Windows Event (XML) (<code>WINEVTLOG_XML</code>)</li>
<li>wiz.io (<code>WIZ_IO</code>)</li>
<li>Zscaler Email DLP (<code>ZSCALER_EMAIL_DLP</code>)</li>
</ul>
<p>The following log types were added without a default parser. Each parser is listed by product name and <code>log_type</code> value, where applicable.</p>
<ul>
<li>Altiris Logs (<code>ALTIRIS_LOGS</code>)</li>
<li>Aruba Access Point (<code>ARUBA_AP</code>)</li>
<li>BloxOne Threat Defense DHCP (<code>BLOXONE_DHCP</code>)</li>
<li>Checkmarx One (<code>CHECKMARX_ONE</code>)</li>
<li>Cisco Nexus Dashboard Orchestrator (<code>CISCO_NDO</code>)</li>
<li>CrowdStrike Cloud Security (<code>CROWDSTRIKE_CSPM</code>)</li>
<li>F5 F5OS-A Logging (<code>F5_F5OS_A</code>)</li>
<li>GateWatcher NDR (<code>GATEWATCHER_NDR</code>)</li>
<li>Hashicorp Terraform (<code>HASHICORP_TERRAFORM</code>)</li>
<li>Jamf Protect Alerts V2 (<code>JAMF_PROTECT_V2</code>)</li>
<li>Oracle Cloud Infrastructure Web Application Firewall (<code>OCI_WAF</code>)</li>
<li>Qualys File Integrity Monitoring (<code>QUALYS_FIM</code>)</li>
<li>SailPoint IdentityNow (<code>SAILPOINT_IDENTITYNOW</code>)</li>
<li>ServiceNow Certificate Logs (<code>SERVICENOW_CERTIFICATE</code>)</li>
<li>ServiceNow User Logs (<code>SERVICENOW_USER</code>)</li>
<li>ServiceNow User Login History (<code>SERVICENOW_USER_LOGIN_HISTORY</code>)</li>
<li>SiteGuard Server (<code>SITEGUARD_SERVER</code>)</li>
<li>Tosi Hub (<code>TOSI_HUB</code>)</li>
<li>Trellix Network Detection and Response (<code>TRELLIX_NDR</code>)</li>
</ul>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Change</h3>
<p>Google SecOps has updated the list of list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.</p>
<p>The following supported default parsers have been updated. Each parser is listed by product name and <code>log_type</code> value, where applicable. This list includes both released default parsers and pending parser updates.</p>
<ul>
<li>Akeyless Vault Platform (<code>AKEYLESS_VAULT</code>)</li>
<li>Apache Cassandra (<code>CASSANDRA</code>)</li>
<li>Aruba (<code>ARUBA_WIRELESS</code>)</li>
<li>Aruba EdgeConnect SD-WAN (<code>ARUBA_EDGECONNECT_SDWAN</code>)</li>
<li>Auth0 (<code>AUTH_ZERO</code>)</li>
<li>AWS Aurora (<code>AWS_AURORA</code>)</li>
<li>AWS EC2 VPCs (<code>AWS_EC2_VPCS</code>)</li>
<li>AWS Security Hub (<code>AWS_SECURITY_HUB</code>)</li>
<li>Azure Firewall (<code>AZURE_FIREWALL</code>)</li>
<li>Azure Front Door (<code>AZURE_FRONT_DOOR</code>)</li>
<li>Barracuda CloudGen Firewall (<code>BARRACUDA_CLOUDGEN_FIREWALL</code>)</li>
<li>Blue Coat Proxy (<code>BLUECOAT_WEBPROXY</code>)</li>
<li>Check Point (<code>CHECKPOINT_FIREWALL</code>)</li>
<li>Check Point Sandblast (<code>CHECKPOINT_EDR</code>)</li>
<li>Checkpoint SmartDefense (<code>CHECKPOINT_SMARTDEFENSE</code>)</li>
<li>Chronicle SOAR Audit (<code>CHRONICLE_SOAR_AUDIT</code>)</li>
<li>Cisco Application Centric Infrastructure (<code>CISCO_ACI</code>)</li>
<li>Cisco ASA (<code>CISCO_ASA_FIREWALL</code>)</li>
<li>Cisco FireSIGHT Management Center (<code>CISCO_FIRESIGHT</code>)</li>
<li>Cisco Internetwork Operating System (<code>CISCO_IOS</code>)</li>
<li>Cisco ISE (<code>CISCO_ISE</code>)</li>
<li>Cisco Meraki (<code>CISCO_MERAKI</code>)</li>
<li>Cisco Secure Access (<code>CISCO_SECURE_ACCESS</code>)</li>
<li>Cisco Secure Workload (<code>CISCO_SECURE_WORKLOAD</code>)</li>
<li>Cisco Switch (<code>CISCO_SWITCH</code>)</li>
<li>Cisco Umbrella Audit (<code>CISCO_UMBRELLA_AUDIT</code>)</li>
<li>Cisco WLC/WCS (<code>CISCO_WIRELESS</code>)</li>
<li>Citrix Netscaler (<code>CITRIX_NETSCALER</code>)</li>
<li>Claroty Xdome (<code>CLAROTY_XDOME</code>)</li>
<li>Cloudflare Warp (<code>CLOUDFLARE_WARP</code>)</li>
<li>CrowdStrike Alerts API (<code>CS_ALERTS</code>)</li>
<li>CrowdStrike Falcon (<code>CS_EDR</code>)</li>
<li>CyberArk (<code>CYBERARK</code>)</li>
<li>CyberArk Privileged Access Manager (PAM) (<code>CYBERARK_PAM</code>)</li>
<li>EPIC Systems (<code>EPIC</code>)</li>
<li>F5 ASM (<code>F5_ASM</code>)</li>
<li>F5 BIGIP Access Policy Manager (<code>F5_BIGIP_APM</code>)</li>
<li>F5 BIGIP LTM (<code>F5_BIGIP_LTM</code>)</li>
<li>F5 Distributed Cloud Services (<code>F5_DCS</code>)</li>
<li>FireEye eMPS (<code>FIREEYE_EMPS</code>)</li>
<li>FireEye NX (<code>FIREEYE_NX</code>)</li>
<li>FortiGate (<code>FORTINET_FIREWALL</code>)</li>
<li>Fortinet FortiEDR (<code>FORTINET_FORTIEDR</code>)</li>
<li>Fortinet Proxy (<code>FORTINET_WEBPROXY</code>)</li>
<li>GitHub (<code>GITHUB</code>)</li>
<li>Google Cloud Audit (<code>GCP_CLOUDAUDIT</code>)</li>
<li>Google Threat Intelligence IOC (<code>GTI_IOC</code>)</li>
<li>Guardicore Centra (<code>GUARDICORE_CENTRA</code>)</li>
<li>HP Aruba (ClearPass) (<code>CLEARPASS</code>)</li>
<li>Huawei Switches (<code>HUAWEI_SWITCH</code>)</li>
<li>IBM Websphere Application Server (<code>IBM_WEBSPHERE_APP_SERVER</code>)</li>
<li>IBM z/OS (<code>IBM_ZOS</code>)</li>
<li>Imperva SecureSphere Management (<code>IMPERVA_SECURESPHERE</code>)</li>
<li>Infoblox (<code>INFOBLOX</code>)</li>
<li>Juniper (<code>JUNIPER_FIREWALL</code>)</li>
<li>Kubernetes Node (<code>KUBERNETES_NODE</code>)</li>
<li>Linux Auditing System (AuditD) (<code>AUDITD</code>)</li>
<li>ManageEngine ADManager Plus (<code>ADMANAGER_PLUS</code>)</li>
<li>McAfee ePolicy Orchestrator (<code>MCAFEE_EPO</code>)</li>
<li>McAfee Web Gateway (<code>MCAFEE_WEBPROXY</code>)</li>
<li>Microsoft Defender For Cloud (<code>MICROSOFT_DEFENDER_CLOUD_ALERTS</code>)</li>
<li>Microsoft Defender for Endpoint (<code>MICROSOFT_DEFENDER_ENDPOINT</code>)</li>
<li>Microsoft Defender for Identity (<code>MICROSOFT_DEFENDER_IDENTITY</code>)</li>
<li>Microsoft Graph API Alerts (<code>MICROSOFT_GRAPH_ALERT</code>)</li>
<li>Microsoft IIS (<code>IIS</code>)</li>
<li>Mobileiron (<code>MOBILEIRON</code>)</li>
<li>Model Armor (<code>GCP_MODEL_ARMOR</code>)</li>
<li>MySQL (<code>MYSQL</code>)</li>
<li>Netskope Web Proxy (<code>NETSKOPE_WEBPROXY</code>)</li>
<li>Noname API Security (<code>NONAME_API_SECURITY</code>)</li>
<li>Office 365 (<code>OFFICE_365</code>)</li>
<li>Okta (<code>OKTA</code>)</li>
<li>Oracle Cloud Infrastructure Audit Logs (<code>OCI_AUDIT</code>)</li>
<li>Oracle NetSuite (<code>ORACLE_NETSUITE</code>)</li>
<li>Palo Alto Networks Firewall (<code>PAN_FIREWALL</code>)</li>
<li>Palo Alto Panorama (<code>PAN_PANORAMA</code>)</li>
<li>Palo Alto Prisma Access (<code>PAN_CASB</code>)</li>
<li>Palo Alto Prisma Cloud Alert payload (<code>PAN_PRISMA_CA</code>)</li>
<li>Ping Identity (<code>PING</code>)</li>
<li>PostFix Mail (<code>POSTFIX_MAIL</code>)</li>
<li>Proofpoint On Demand (<code>PROOFPOINT_ON_DEMAND</code>)</li>
<li>Proofpoint Tap Alerts (<code>PROOFPOINT_MAIL</code>)</li>
<li>Proofpoint Threat Response (<code>PROOFPOINT_TRAP</code>)</li>
<li>Radware Web Application Firewall (<code>RADWARE_FIREWALL</code>)</li>
<li>Rapid7 Insight (<code>RAPID7_INSIGHT</code>)</li>
<li>SAP Hana Audit (<code>SAP_HANA_AUDIT</code>)</li>
<li>SecureAuth (<code>SECUREAUTH_SSO</code>)</li>
<li>Security Command Center Posture Violation (<code>GCP_SECURITYCENTER_POSTURE_VIOLATION</code>)</li>
<li>Security Command Center Threat (<code>GCP_SECURITYCENTER_THREAT</code>)</li>
<li>Security Command Center Toxic Combination (<code>GCP_SECURITYCENTER_TOXIC_COMBINATION</code>)</li>
<li>SentinelOne Deep Visibility (<code>SENTINEL_DV</code>)</li>
<li>SentinelOne Singularity Cloud Funnel (<code>SENTINELONE_CF</code>)</li>
<li>Silverfort Authentication Platform (<code>SILVERFORT</code>)</li>
<li>SiteMinder Web Access Management (<code>CA_SSO_WEB</code>)</li>
<li>SonicWall (<code>SONIC_FIREWALL</code>)</li>
<li>Squid Web Proxy (<code>SQUID_WEBPROXY</code>)</li>
<li>STIX Threat Intelligence (<code>STIX</code>)</li>
<li>Suricata EVE (<code>SURICATA_EVE</code>)</li>
<li>Sysdig (<code>SYSDIG</code>)</li>
<li>Tanium Threat Response (<code>TANIUM_THREAT_RESPONSE</code>)</li>
<li>Thinkst Canary (<code>THINKST_CANARY</code>)</li>
<li>Trend Micro Apex one (<code>TRENDMICRO_APEX_ONE</code>)</li>
<li>Unix system (<code>NIX_SYSTEM</code>)</li>
<li>Vectra XDR (<code>VECTRA_XDR</code>)</li>
<li>VMware ESXi (<code>VMWARE_ESX</code>)</li>
<li>Wallix Bastion (<code>WALLIX_BASTION</code>)</li>
<li>WatchGuard (<code>WATCHGUARD</code>)</li>
<li>Windows Defender AV (<code>WINDOWS_DEFENDER_AV</code>)</li>
<li>Windows DNS (<code>WINDOWS_DNS</code>)</li>
<li>Windows Event (<code>WINEVTLOG</code>)</li>
<li>Windows Event (XML) (<code>WINEVTLOG_XML</code>)</li>
<li>wiz.io (<code>WIZ_IO</code>)</li>
<li>Zscaler Email DLP (<code>ZSCALER_EMAIL_DLP</code>)</li>
</ul>
<p>The following log types were added without a default parser. Each parser is listed by product name and <code>log_type</code> value, where applicable.</p>
<ul>
<li>Altiris Logs (<code>ALTIRIS_LOGS</code>)</li>
<li>Aruba Access Point (<code>ARUBA_AP</code>)</li>
<li>BloxOne Threat Defense DHCP (<code>BLOXONE_DHCP</code>)</li>
<li>Checkmarx One (<code>CHECKMARX_ONE</code>)</li>
<li>Cisco Nexus Dashboard Orchestrator (<code>CISCO_NDO</code>)</li>
<li>CrowdStrike Cloud Security (<code>CROWDSTRIKE_CSPM</code>)</li>
<li>F5 F5OS-A Logging (<code>F5_F5OS_A</code>)</li>
<li>GateWatcher NDR (<code>GATEWATCHER_NDR</code>)</li>
<li>Hashicorp Terraform (<code>HASHICORP_TERRAFORM</code>)</li>
<li>Jamf Protect Alerts V2 (<code>JAMF_PROTECT_V2</code>)</li>
<li>Oracle Cloud Infrastructure Web Application Firewall (<code>OCI_WAF</code>)</li>
<li>Qualys File Integrity Monitoring (<code>QUALYS_FIM</code>)</li>
<li>SailPoint IdentityNow (<code>SAILPOINT_IDENTITYNOW</code>)</li>
<li>ServiceNow Certificate Logs (<code>SERVICENOW_CERTIFICATE</code>)</li>
<li>ServiceNow User Logs (<code>SERVICENOW_USER</code>)</li>
<li>ServiceNow User Login History (<code>SERVICENOW_USER_LOGIN_HISTORY</code>)</li>
<li>SiteGuard Server (<code>SITEGUARD_SERVER</code>)</li>
<li>Tosi Hub (<code>TOSI_HUB</code>)</li>
<li>Trellix Network Detection and Response (<code>TRELLIX_NDR</code>)</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 04, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_04_2026</id>
    <updated>2026-05-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_04_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1153">v1.15.3</h3>
<p>On May 4, 2026 we released an updated version of the Apigee hybrid software, v1.15.3.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.3</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33997">CVE-2026-33997</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0915">CVE-2026-0915</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0861">CVE-2026-0861</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15558">CVE-2025-15558</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15281">CVE-2025-15281</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35469">CVE-2026-35469</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33997">CVE-2026-33997</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15558">CVE-2025-15558</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-connect-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31789">CVE-2026-31789</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28387">CVE-2026-28387</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra-client</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39883">CVE-2026-39883</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34480">CVE-2026-34480</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34478">CVE-2026-34478</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21932">CVE-2026-21932</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48913">CVE-2025-48913</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mint-task-scheduler</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34480">CVE-2026-34480</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34478">CVE-2026-34478</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21932">CVE-2026-21932</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prom-prometheus</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39883">CVE-2026-39883</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34480">CVE-2026-34480</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34478">CVE-2026-34478</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21932">CVE-2026-21932</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48913">CVE-2025-48913</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-stackdriver-logging-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41316">CVE-2026-41316</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35611">CVE-2026-35611</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33210">CVE-2026-33210</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33176">CVE-2026-33176</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34481">CVE-2026-34481</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34480">CVE-2026-34480</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34478">CVE-2026-34478</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21932">CVE-2026-21932</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48913">CVE-2025-48913</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-udca</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39883">CVE-2026-39883</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34986">CVE-2026-34986</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">CVE-2026-32283</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32281">CVE-2026-32281</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">CVE-2026-32280</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29181">CVE-2026-29181</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27144">CVE-2026-27144</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27143">CVE-2026-27143</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27140">CVE-2026-27140</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35469">CVE-2026-35469</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">Cloud NGFW</h2>
<h3>Feature</h3>
<p>You can now create and configure the following organization-level Cloud NGFW
resources within a Google Cloud project:</p>
<ul>
<li>Security profiles</li>
<li>Security profile groups</li>
<li>Firewall endpoints</li>
<li>Firewall endpoint associations</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/firewall/docs/about-security-profiles">Security profile
overview</a>, <a href="https://docs.cloud.google.com/firewall/docs/about-security-profile-groups">Security profile group
overview</a>, and <a href="https://docs.cloud.google.com/firewall/docs/about-firewall-endpoints">Firewall endpoint
overview</a>. This feature is available in <strong>Public preview</strong>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Feature</h3>
<p>Cloud SQL for SQL Server now supports PolyBase (<a href="https://cloud.google.com/products/#product-launch-stages">GA</a>).</p>
<p>With PolyBase, your Cloud SQL for SQL Server instance uses Transact-SQL (T-SQL)
commands to directly query data stored in external data sources as if the data
is stored in local tables. You don't need to install separate client connection
software.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/sqlserver/about-polybase">About PolyBase</a>.</p>
<h2 class="release-note-product-title">Cloud Workstations</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/workstations/docs/preconfigured-base-images#list_of_preconfigured_base_images">JetBrains Rider preconfigured base image</a>
includes .NET 10.0 and drops .NET 6.0.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/workstations/docs/preconfigured-base-images#list_of_preconfigured_base_images">JetBrains RubyMine preconfigured base image</a>
installs Ruby using <code>ruby-build</code> instead of RVM (Ruby Version Manager).</p>
<h2 class="release-note-product-title">Confidential Space</h2>
<h3>Issue</h3>
<p>When running a Confidential Space workload with an NVIDIA H100 GPU attached, you
might see the following error message:</p>
<pre class="devsite-click-to-copy"><code>failed to get launchspec, make sure you're running inside
a GCE VM: GPU Driver installation is not supported.
</code></pre>
<p>This is a known issue with the Confidential Space image. To work around the
issue, restart the Confidential VM.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-120-52_">cos-beta-129-19506-120-52 <a id='"cos-arm64-beta-129-19506-120-52"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ab5449e6af743561ec3d078ea8fcec22a07d8e75
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.52/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Added the cos_kernel_args tool that allows manipulating kernel command line arguments of a COS image.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.1.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-21709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-39764 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-40135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68239 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23004 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23138 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23157 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23245 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23277 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23368 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23374 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23441 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23442 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31532 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31546 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31554 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31555 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31557 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31561 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31580 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31586 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31588 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31628 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31647 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31648 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31664 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31665 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31667 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31671 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31673 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31675 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31677 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31680 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31681 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31682 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/openssl to v3.5.6 to fix CVE-2026-28387,
CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31790.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
<h3>Change</h3>
<h3 id="cos-125-19216-220-185_">cos-125-19216-220-185 <a id='"cos-arm64-125-19216-220-185"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6c4905f5e0a57864e8f8d2792397d30065f6ba4b
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.185/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2025-39764 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68239 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23004 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23138 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23157 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23277 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23375 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23391 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23401 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23417 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23439 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23458 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31546 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31554 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31555 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31561 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31590 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31593 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31614 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31628 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31647 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31665 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31671 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31673 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31675 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31677 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31680 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31681 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31682 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31688 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/openssl to v3.5.6 to fix CVE-2026-28387,
CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31790.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250715  376068 -&gt; 188034    250714  376068</li>
</ul></p>
<h3>Change</h3>
<h3 id="cos-113-18244-582-100_">cos-113-18244-582-100 <a id='"cos-arm64-113-18244-582-100"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/2e246cc16ea70388d1ce7be1ce694805ccb64d3f
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.100/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-37980 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23268 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23269 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23404 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23405 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23406 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23407 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23408 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23409 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23410 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31446 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31447 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31454 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31515 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31521 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31523 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31546 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31555 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31664 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31665 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31667 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31671 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31680 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31682 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-a9b8b18 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-118_">cos-121-18867-381-118 <a id='"cos-arm64-121-18867-381-118"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/81a1a5c044b4f62bb492acb3dc787f12de339232
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.118/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.1.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22125 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23255 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23302 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23374 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23399 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23442 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31407 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31429 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31555 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31628 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31648 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31664 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31665 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31671 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31673 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31675 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31680 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31681 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31682 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31688 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded openssl to v3.0.20 to fix CVE-2026-28387,
CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31790.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-534-110_">cos-117-18613-534-110 <a id='"cos-arm64-117-18613-534-110"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3805daa9d669b5d7a32bf0655bc3bc8abb66eeb2
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.110/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22125 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23255 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23302 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23374 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23399 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31407 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31429 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31546 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31555 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31628 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31648 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31664 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31665 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31667 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31671 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31673 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31680 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31681 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31682 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31688 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded openssl to v3.0.20 to fix CVE-2026-28387,
CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31790.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.26</strong></p>
<p>We've released version 4.26 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Feature</h3>
<p><strong>Fewest Agents Routing</strong></p>
<p>Fewest Agents Routing has been added to chat Deltacast configuration. Fewest
Agents Routing keeps busy agents engaged while preserving idle agents for future
workload spikes.</p>
<p>Administrators:</p>
<ul>
<li><p>The following new settings are available at <strong>Settings <span aria-label="and then">&gt;</span>
Operation Management <span aria-label="and then">&gt;</span> Routing <span aria-label="and then">&gt;</span> Chat Routing
<span aria-label="and then">&gt;</span> Deltacast Routing Logic</strong>:</p>
<ul>
<li><p><strong>Longest Idle Routing to distribute workload equally between agents</strong>.
This is the same as the previous default routing behavior.</p></li>
<li><p><strong>Fewest Agents Routing to maximize utilization and call availability</strong>.
This is the new routing behavior that concentrates new chats on busy
agents.</p></li>
</ul></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/multicast_deltacast#deltacast-routing-logic-for-chat">Deltacast routing logic for chat</a>.</p>
<h3>Feature</h3>
<p><strong>Skip account or record creation for HubSpot</strong></p>
<p>You can configure your instance to prevent the automatic creation of accounts
and records in HubSpot while ensuring that data such as media files and
transcripts is preserved. You can configure how the system handles closed
records when a record ID is passed using the SDK.</p>
<p>Administrators:</p>
<ul>
<li><p>The following new settings are available at <strong>Settings <span aria-label="and then">&gt;</span>
Operation Management <span aria-label="and then">&gt;</span> CRM Record Creation Details</strong>:</p>
<ul>
<li><p><strong>Skip CRM account creation</strong></p></li>
<li><p><strong>Skip CRM account lookup</strong></p></li>
<li><p><strong>Skip CRM record creation</strong></p></li>
<li><p><strong>Closed record options when record ID is passed in via SDK</strong></p>
<ul>
<li><p><strong>Create new record</strong></p></li>
<li><p><strong>Reopen record</strong></p></li>
</ul></li>
</ul></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/hubspot-configure-record-creation">Configure HubSpot record creation</a>.</p>
<h3>Feature</h3>
<p><strong>Improved Agent Assist visibility during transfers</strong></p>
<p>When a chat is transferred, the originating agent and the receiving agent see
Agent Assist as it's configured for their respective teams or queues.
This behavior now also applies to transfers of direct inbound calls.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/agent-assist#configure-team-for-agent-assist">Configure Agent Assist at the team
level</a>.</p>
<h3>Feature</h3>
<p><strong>Breakthrough for wrap-up improvements</strong></p>
<p>If breakthrough is configured for <code>Wrap-up</code> and <code>Wrap-up Exceeded</code> statuses,
agents can now answer breakthrough calls even if they haven't completed the
following:</p>
<ul>
<li><p>Submitted disposition codes and notes.</p></li>
<li><p>Manually switched to <code>Available</code> status.</p></li>
</ul>
<p>Additionally, agents in <code>Wrap-up</code> status who accept breakthrough calls before
submitting disposition codes and notes can now switch between the call and the
wrap-up screen.</p>
<p>User experience changes include the following:</p>
<ul>
<li><p>The call adapter contains a switcher button that lets agents switch between
an ongoing call and the wrap-up screen for a previous call.</p></li>
<li><p>The mini-adapter on the agent desktop expands to let you switch between an
ongoing call and the wrap-up screen for a previous call.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/agent-status#breakthrough_for_wrap-up">Breakthrough for
wrap-up</a>.</p>
<h3>Feature</h3>
<p><strong>Custom field mapping for HubSpot</strong></p>
<p>You can map your web or mobile SDK custom data fields to your HubSpot
installation's custom fields. At runtime, when the SDK sends a custom data
value, the system writes the value to the mapped HubSpot custom field.</p>
<p>Administrators: On the <strong>Settings <span aria-label="and then">&gt;</span> Operation Management</strong> page,
  there's a new <strong>Custom Field Mapping</strong> pane.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/hubspot-custom-field-mapping">HubSpot custom field
mapping</a>.</p>
<h3>Feature</h3>
<p><strong>Call scheduling improvements</strong></p>
<p>We've made the following improvements to call scheduling for web SDK v3 and the
headless web SDK:</p>
<ul>
<li><p><strong>Configurable time slots</strong>. You can configure the length of call-scheduling
time slots.</p></li>
<li><p><strong>Day-based time slot selection</strong>. End-users can browse available time slots
organized by day.</p></li>
<li><p><strong>Rescheduling</strong>. If an end-user reopens the web SDK and has an existing
scheduled call, they're prompted to manage that appointment (reschedule or
cancel) before starting a new flow.</p></li>
<li><p><strong>Cancellation</strong>. End-users can cancel a previously scheduled call.</p></li>
<li><p><strong>Queue-level configuration</strong>. You can configure call scheduling at the
queue level.</p></li>
</ul>
<aside class="note"><strong>Note:</strong><span> Headless web SDK users must specify <code>useAdvancedCallScheduling: true</code> with
  calls to the <code>getTimeSlots</code> method to access these call scheduling
  improvements.</span></aside>
<p>Administrators:</p>
<ul>
<li><p>There's a new <strong>Scheduled Calls</strong> pane on the <strong>Settings <span aria-label="and then">&gt;</span>
Calls</strong> page.</p></li>
<li><p>There's a new <strong>Scheduled Calls</strong> section in the <strong>Settings <span aria-label="and then">&gt;</span>
Queue <span aria-label="and then">&gt;</span> Web <span aria-label="and then">&gt;</span> <code><var>SELECT_QUEUE</var></code></strong>
pane.</p></li>
<li><p>We moved <strong>Scheduled Call Countdown</strong> and <strong>Scheduled Call Expiration</strong> from
<strong>Settings <span aria-label="and then">&gt;</span> Calls <span aria-label="and then">&gt;</span> Call Details</strong> to <strong>Settings
<span aria-label="and then">&gt;</span> Calls <span aria-label="and then">&gt;</span> Scheduled Calls</strong>.</p></li>
<li><p>We've added the following settings to the <strong>Settings <span aria-label="and then">&gt;</span> Calls
<span aria-label="and then">&gt;</span> Scheduled Calls</strong> pane:</p>
<ul>
<li><p><strong>Consumers can schedule calls up to
<code><var>SELECT_INTEGER</var></code> day(s) in the future</strong></p></li>
<li><p><strong>Static <span aria-label="and then">&gt;</span> Maximum calls per time slot</strong></p></li>
</ul></li>
</ul>
<p>User experience changes:</p>
<ul>
<li>For <strong>Scheduled Calls</strong>, if you select <strong>Consumers can schedule calls up to
<code><var>SELECT_INTEGER</var></code> day(s) in the future</strong>, a new
<strong>Select a day</strong> screen appears to end-users who reschedule a call.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/call-settings#scheduled-calls">Scheduled
calls</a>.</p>
<h3>Feature</h3>
<p><strong>Headless web SDK updates</strong></p>
<p>We've made the following updates to the headless web SDK:</p>
<ul>
<li><p>New methods:</p>
<ul>
<li><p><strong>fetchTimeSlotAvailability</strong>. Check if time slots are available for a
given menu.</p></li>
<li><p><strong>restoreCobrowseSession</strong>. Restores a cobrowse session after the
browser window is reopened.</p></li>
<li><p><strong>getLogs</strong>. Gets the internal debug logs collected by the SDK.</p></li>
</ul></li>
<li><p>Updated signatures:</p>
<ul>
<li><p><strong>getTimeSlots</strong>. Includes the <code>GetTimeSlotsRequest</code> interface.</p></li>
<li><p><strong>updatePostSession</strong>. Includes an <code>optInSelection</code> parameter.</p></li>
</ul></li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/headless-web-api#get-time-slots">getTimeSlots</a>.</p>
<h3>Feature</h3>
<p><strong>Accessibility and design improvements</strong></p>
<p>We've made the following accessibility and design improvements to the web SDK v3
and the headless web SDK:</p>
<ul>
<li><p><strong>WCAG Compliance</strong>. Updated to comply with Web Content Accessibility
Guidelines (WCAG).</p></li>
<li><p><strong>Right-to-left support</strong>. Now supports right-to-left languages: Arabic,
Hebrew, Farsi, and Urdu.</p></li>
<li><p><strong>Improved screen reader compatibility</strong>. Improved support for screen
readers.</p></li>
<li><p><strong>Improved spacing</strong>. Uses 4px-based spacing to improve the look and feel of
page displays.</p></li>
</ul>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where the Telnyx integration attempted to reconnect
websockets after a failure, even when this behavior was not desired.</p></li>
<li><p>Fixed an issue where Agent Assist disappeared for the third agent
during consecutive queue transfers.</p></li>
<li><p>Fixed an issue where empty responses from Dialogflow were
passed through to CCAI Platform, resulting in undefined call
behavior.</p></li>
<li><p>Fixed an issue where active outbound campaigns stopped dialing when a
concurrent campaign encountered timezone restrictions, requiring manual
intervention to resume calls.</p></li>
<li><p>Fixed an issue where campaigns didn't resume after being paused,
resulting in call session failures and missing participant
information.</p></li>
<li><p>Fixed an issue where chat transfers involving multiple agents failed,
causing agents to become stuck in an "in chat" status even when no active
chats were present.</p></li>
<li><p>Fixed an issue where incoming chats were routed to newly signed-in agents
instead of agents who had been available the longest.</p></li>
<li><p>Fixed an issue where chat messages sent by end-users immediately after
starting a chat, but before an agent joined, weren't delivered to
the agent.</p></li>
<li><p>Fixed an issue where the <code>recording_url</code> field in session data wasn't
populated after calls ended.</p></li>
<li><p>Fixed an issue where call transfers were incorrectly tagged as <strong>Warm</strong>
instead of <strong>Cold</strong> when the transferring agent disconnected before the
receiving agent answered.</p></li>
<li><p>Fixed an issue where call recordings for sessions ending with a virtual
agent post-call survey were truncated. This resulted in the main human agent
conversation not being saved.</p></li>
<li><p><s>Fixed an issue where outbound call restrictions incorrectly blocked calls
to Japanese numbers, even when settings allowed them.</s></p></li>
<li><p>Fixed an issue where agents could become stuck in <strong>Wrap-up</strong> status after a
call was transferred to another agent's voicemail and the end user
disconnected during the voicemail greeting.</p></li>
<li><p>Fixed an issue where, in third-party transfer calls with <strong>Call recording
for third-party transfers</strong> set to off, redaction didn't begin immediately
after the agent disconnected.</p></li>
<li><p>Fixed an issue where calls didn't connect and re-queued, resulting in long
queue times for agents.</p></li>
<li><p>Fixed an issue where disposition lists in the call adapter didn't appear in
alphabetical order, as configured in the portal.</p></li>
<li><p>Fixed an issue where chats in the agent desktop didn't transition to the
<strong>End Wrap-Up</strong> state after the agent clicked <strong>Submit</strong>.</p></li>
<li><p>Fixed an issue where the <code>apps/api/v1/users</code> API returned only 100 records
per page, even when a higher limit was specified.</p></li>
<li><p>Fixed an issue where filtering by queue name on the <strong>Queued Chats</strong> and
<strong>Queued Calls</strong> pages didn't return accurate results.</p></li>
<li><p>Fixed an issue where updating an agent's skills from the <strong>Agents</strong> page
mistakenly removed their extension number.</p></li>
<li><p>Fixed an issue where users of the <strong>Dialer Admin</strong> role couldn't add teams
to a queue.</p></li>
<li><p>Fixed an issue where call wrap-up interactions recorded inaccurate data,
such as excessive wrap-up times, redundant instances, and incorrect
chronological sequencing.</p></li>
<li><p>Fixed an issue that occurred when an agent with Agent Assist
transferred a call to a second agent with Agent Assist. After the
transfer, the second agent no longer had access to Agent Assist.</p></li>
<li><p>Fixed an issue with Salesforce integrations in the agent desktop where
notification flags overlapped the Salesforce Utility Bar navigation, which
prevented agents from accessing navigation controls.</p></li>
<li><p>Fixed an issue where agents were incorrectly reported as <code>Available</code> for an
extended period after signing out.</p></li>
<li><p>Fixed an issue where calls waiting in a queue with no available agents
weren't connected when an agent became available.</p></li>
<li><p>Fixed an issue where the previous CCAI Insights name appeared in the portal
instead of Customer Experience Insights.</p></li>
<li><p>Fixed an issue for Alvaria users where the Agent Performance Report was
mistakenly generated and sent at 7:00 PM instead of midnight, which
resulted in incomplete 24-hour performance data.</p></li>
<li><p>Fixed an issue where agents who left a predictive campaign pool were
incorrectly left in <code>Available</code> status.</p></li>
<li><p>Fixed an issue where chat sessions returned an error during post-session
transfer if no virtual agent participant was active.</p></li>
<li><p>Fixed an issue where, after a call failure, the agent adapter displayed a
generic error message instead of an error message that included the failure
reason.</p></li>
<li><p>Fixed an issue for Telnyx users where the instance stopped responding.</p></li>
<li><p>Fixed an issue that occurred when users tried to delete a queue. A message
was returned saying that the queue was assigned as a deflection or
redirection option even though these settings weren't activated for the
queue.</p></li>
<li><p>Fixed an issue where adding multiple voice queues resulted in long loading
times, request timeouts, and incorrect concurrency errors.</p></li>
<li><p>Fixed an issue where overcapacity deflection options messages mistakenly
played twice instead of once.</p></li>
<li><p>Fixed an issue where chats escalated by a virtual agent disconnected seconds
after assignment to a human agent, which prevented the human agent and the
end-user from interacting.</p></li>
<li><p>Fixed an issue where spurious chat interactions appeared in the <strong>All
Interactions</strong> dashboard, which caused discrepancies in handled chat
reporting and incorrect failed session filtering.</p></li>
<li><p>Fixed a web SDK v3 issue where the out-of-office deflection message that
appeared in the end-user's chat window didn't match the message in the chat
transcript.</p></li>
<li><p>Fixed an issue where agents received incorrect <strong>Missed target response
time</strong> notifications in agent desktop SMS chats, even when responding
promptly.</p></li>
<li><p>Fixed an issue where agents attempting to access their contact center using
private ingress couldn't connect.</p></li>
<li><p>Fixed an issue where the <strong>Allow transfers to queues outside of hours of
operation</strong> checkbox was unexpectedly unavailable.</p></li>
<li><p>Fixed an issue where verified outbound phone numbers couldn't be added to a
queue because the selection field was empty, which prevented administrators
from assigning new phone numbers.</p></li>
<li><p>Fixed an issue where attempts to rename IVR queues using redirection data in
legacy YAML files resulted in errors.</p></li>
</ul>
<h2 class="release-note-product-title">Network Security Integration</h2>
<h3>Feature</h3>
<p>You can now enable zonal affinity for your Network Security Integration in-band
integration deployments and configure zonal interception with regional backends.
For more information, see <a href="https://docs.cloud.google.com/network-security-integration/docs/in-band/in-band-integration-overview#zonal-affinity">Zonal
affinity</a>.</p>
<h2 class="release-note-product-title">Spanner</h2>
<h3>Feature</h3>
<p>Spanner <a href="https://docs.cloud.google.com/spanner/docs/vector-indexes">vector index</a> and
<a href="https://docs.cloud.google.com/spanner/docs/find-approximate-nearest-neighbors">approximate nearest neighbor (ANN)</a>
distance functions are
<a href="https://cloud.google.com/products/#product-launch-stages">generally available</a>
(GA) for PostgreSQL databases.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 03, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_03_2026</id>
    <updated>2026-05-03T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_03_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>Enhanced "Time to respond" options for multi-choice questions</strong></p>
<p>Google SecOps now provides more granular control over playbook execution when the "time to respond" for a <strong>MultiChoiceQuestion</strong> step is exceeded. When configuring a multi-choice question, you can now choose to proceed with one of the predefined answer branches or to create a dedicated branch to handle this scenario.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/using-flows-in-playbooks#multi-choice">Add a multi-choice question flow</a>.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.84 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
<h3>Feature</h3>
<p><strong>Enhanced "Time to respond" options for multi-choice questions</strong></p>
<p>Google SecOps now provides more granular control over playbook execution when the "time to respond" for a <strong>MultiChoiceQuestion</strong> step is exceeded. When configuring a multi-choice question, you can now choose to proceed with one of the predefined answer branches or to create a dedicated branch to handle this scenario.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/using-flows-in-playbooks#multi-choice">Add a multi-choice question flow</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 02, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_02_2026</id>
    <updated>2026-05-02T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_02_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#April_12_2026">Release 6.3.83</a> is now available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 01, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_01_2026</id>
    <updated>2026-05-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_01_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>Google Cloud Observability has expanded the supported locations for observability buckets,
which store your trace data, to include the following:</p>
<ul>
<li>australia-southeast1</li>
<li>europe-central2</li>
<li>europe-north1</li>
<li>europe-southwest1</li>
<li>europe-west2</li>
<li>europe-west10</li>
<li>europe-west12</li>
<li>me-central2</li>
<li>northamerica-northeast1</li>
<li>us-east4</li>
</ul>
<p>For a list of supported locations, see
<a href="https://docs.cloud.google.com/stackdriver/docs/observability/observability-bucket-locations">Locations for observability buckets</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-120-44_">cos-beta-129-19506-120-44 <a id='"cos-arm64-beta-129-19506-120-44"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8656d3e850e89f3430c31b56ebae60096f99a71b
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.44/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the R595 Nvidia driver production branch.</p>
<h3>Change</h3>
<p>Made it so that /etc/machine-id is mounted with noexec, nosuid, and nodev.</p>
<h3>Feature</h3>
<p>Enabled CONFIG_SCHED_CLASS_EXT and CONFIG_EXT_GROUP_SCHED.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA drivers v580.126.16 and v580.126.20.</p>
<h3>Fixed</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Fixed an ext4/jbd2 performance regression on CPU Node.</p>
<h3>Fixed</h3>
<p>Optimized IOMMU reference counting using atomic64_inc_return().</p>
<h3>Fixed</h3>
<p>Serialized sequence allocation to prevent timeouts during
concurrent TLB invalidations.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23276 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23375 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23391 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23397 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23398 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23399 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23401 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23412 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23413 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23417 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23439 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23456 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23457 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23465 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23471 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31400 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31402 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31406 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31407 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31413 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31415 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31416 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31418 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31423 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31424 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31426 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31427 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31428 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31431 (copy.fail) in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31434 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31438 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31446 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31447 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31448 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31450 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31451 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31454 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31495 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31515 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31516 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31519 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31521 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31523 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31525 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31528 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31531 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32280, CVE-2026-32281, CVE-2026-32283,
CVE-2026-27140, CVE-2026-27144 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-34743 in app-arch/xz-utils.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4046 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250715  376068 -&gt; 188034    250714  376068</li>
</ul></p>
<h3>Change</h3>
<h3 id="cos-125-19216-220-180_">cos-125-19216-220-180 <a id='"cos-arm64-125-19216-220-180"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/62c8397822908f2ff448fcb9691e81a9902dfc8b
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.180/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Made it so that /etc/machine-id is mounted with noexec, nosuid, and nodev.</p>
<h3>Fixed</h3>
<p>Fixed an ext4/jbd2 performance regression on CPU Node.</p>
<h3>Fixed</h3>
<p>Optimized IOMMU reference counting using atomic64_inc_return().</p>
<h3>Fixed</h3>
<p>Serialized sequence allocation to prevent timeouts during
concurrent TLB invalidations.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31431 (copy.fail) in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31664 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-113_">cos-121-18867-381-113 <a id='"cos-arm64-121-18867-381-113"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/7241a904e8946d8c3871ed01783d66bcad649023
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.113/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Optimized IOMMU reference counting using atomic64_inc_return().</p>
<h3>Fixed</h3>
<p>Serialized sequence allocation to prevent timeouts during
concurrent TLB invalidations.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31431 (copy.fail) in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31454 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31546 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31667 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-534-106_">cos-117-18613-534-106 <a id='"cos-arm64-117-18613-534-106"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/4b597462e86bbce53ec5e8a8e452751b7c8617c2
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.106/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Optimized IOMMU reference counting using atomic64_inc_return().</p>
<h3>Fixed</h3>
<p>Serialized sequence allocation to prevent timeouts during
concurrent TLB invalidations.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31431 (copy.fail) in the Linux kernel.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Announcement</h3>
<h4 id="kubernetes_136_is_now_available_in_the_rapid_channel">Kubernetes 1.36 is now available in the Rapid channel</h4>
<p>Kubernetes 1.36 is now available in the Rapid channel. For more
information about the content of Kubernetes 1.36, see
<a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#changelog-since-v1350">Kubernetes 1.36 release notes</a>,
and <a href="https://kubernetes.io/blog/2026/04/22/kubernetes-v1-36-release/">Kubernetes 1.36 Release Blog</a>.</p>
<h3>Feature</h3>
<h4 id="new_features_in_136">New features in 1.36</h4>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/internal-load-balancing">L4 Internal Load Balancer services</a>
now use GKE subsetting by default. This change transitions the default
implementation from Instance Groups to Network Endpoint Groups (NEGs).
This NEG-based approach provides improved scalability and enhanced
performance through faster synchronization. This change applies only to
newly created Internal Load Balancer services, while existing services
remain unaffected and continue using Instance Groups.</li>
<li><a href="https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/">Mutating Admission Policies</a>
are now Generally Available. Mutating admission policies allow for
resource mutations using Common Expression Language (CEL) expressions
as a more efficient alternative to mutating admission webhooks. For more
information, see the
<a href="https://kubernetes.io/docs/reference/access-authn-authz/mutating-admission-policy/">kubernetes documentation</a>.</li>
<li>The kube-dns image switches from an implementation based on
<a href="https://github.com/kubernetes/dns">kubernetes/dns</a> to one based on
<a href="https://coredns.io/">CoreDNS</a>.
This implementation is more efficient, and it supports bigger headless
services, more upstream DNS services, and more concurrent connections.</li>
</ul>
<h2 class="release-note-product-title">reCAPTCHA</h2>
<h3>Change</h3>
<p>reCAPTCHA Mobile SDK v18.9.0 is available for iOS. This version includes
the following:</p>
<ul>
<li><p>Reliability improvements and bug fixes.</p></li>
<li><p>Score distribution calibration and improvements for better bot detection.
We recommend that you review your score threshold and adjust it if you
experience a high number of false positives.</p></li>
<li><p>Beta support for visionOS.</p></li>
<li><p>Beta support for arm64e and Enhanced Security Features.</p></li></ul>
]]>
    </content>
  </entry>

  <entry>
    <title>April 30, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_30_2026</id>
    <updated>2026-04-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_30_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Breaking</h3>
<p>Starting May 7, 2026, new transfer configurations that transfer data from Google Ads using the
BigQuery Data Transfer Service will require <a href="https://ads-developers.googleblog.com/2026/04/multi-factor-authentication-requirement.html">Multi-factor authentication (MFA)
for individual user
authentication</a>.
For more information, see <a href="https://docs.cloud.google.com/bigquery/docs/transfer-changes#May7-google-ads">May 7,
2026</a>.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>You can use Bigtable <a href="https://github.com/GoogleCloudPlatform/cloud-bigtable-ecosystem#ai-agent-skills">agent
skills</a>
to let AI agents assist with Bigtable-related tasks, such as schema design,
generating SQL queries, and infrastructure management.</p>
<h2 class="release-note-product-title">Cloud API Registry</h2>
<h3>Deprecated</h3>
<p>Support for Model Context Protocol (MCP) servers and tools is deprecated. As of
the July 30, 2026 shutdown date, you can no longer retrieve, list, enable,
and disable MCP servers and tools using the Cloud API Registry
API. For more information, see
<a href="https://docs.cloud.google.com/api-registry/docs/deprecations">Feature deprecations</a>.</p>
<h2 class="release-note-product-title">Cloud CDN</h2>
<h3>Feature</h3>
<p>Google Kubernetes Engine (GKE) Gateway supports Cloud CDN to help you cache
content closer to your users, improve application latency, and reduce origin
load. Using GKE Gateway APIs, you can configure, manage, and fine-tune caching
configurations for different segments of your traffic. This feature is <strong>Generally Available</strong>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/configure-cdn-for-gateway">Configure Cloud CDN for Gateway</a>.</p>
<h2 class="release-note-product-title">Cloud Database Migration Service</h2>
<h3>Feature</h3>
<p>Database Migration Service for heterogeneous migrations to Cloud SQL for PostgreSQL
and AlloyDB for PostgreSQL now supports PostgreSQL version 18.
For more information, see
<a href="https://docs.cloud.google.com/database-migration/docs/supported-databases" track-metadata-position="releaseNotes" track-metadata-srcpg="docs/release-notes" track-name="supported_src_dst_core" track-type="releaseNoteLink">
Supported source and destination databases</a>.</p>
<h2 class="release-note-product-title">Cloud Interconnect</h2>
<h3>Feature</h3>
<p>Managed traffic classification for Cloud Interconnect is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>This feature automates the assignment of differentiated services field codepoint (DSCP) bits in your outgoing packets. For more information, see <a href="https://docs.cloud.google.com/network-connectivity/docs/interconnect/how-to/cci/managed-traffic-classification">Configure managed traffic classification</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>Backend Cloud Storage buckets are available for regional external Application Load Balancers and
regional internal Application Load Balancers.</p>
<p>For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/https/setup-reg-ext-app-lb-backend-buckets">Set up a regional external Application Load Balancer with Cloud Storage buckets</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/l7-internal/setup-regional-internal-buckets">Set up a regional internal Application Load Balancer with Cloud Storage buckets</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/https/setting-up-reg-ext-shared-vpc-backend-buckets">Set up a regional external Application Load Balancer with Cloud Storage buckets in a Shared VPC environment</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/l7-internal/setup-regional-internal-shared-vpc-buckets">Set up a regional internal Application Load Balancer with Cloud Storage buckets in a Shared VPC environment</a></li>
</ul>
<p>This feature is in <strong>General availability</strong>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Fixed</h3>
<p>Cloud SQL has made the following enhancements to expand the list of eligible
Cloud SQL Enterprise Plus edition instances that support planned operations with
<a href="https://docs.cloud.google.com/sql/docs/mysql/availability#near-zero-downtime">near-zero downtime</a>.</p>
<ul>
<li>Instances with <a href="https://docs.cloud.google.com/sql/docs/mysql/connect-connectors#enforce">connector enforcement enabled</a>
are eligible for planned operations with near-zero downtime.</li>
<li>Instances that use <a href="https://docs.cloud.google.com/sql/docs/mysql/configure-private-services-access">private services access</a>
with a non-RFC 1918 IP address are eligible for planned operations with near-zero downtime.</li>
</ul>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Fixed</h3>
<p>Cloud SQL has made the following enhancements to expand the list of eligible
Cloud SQL Enterprise Plus edition instances that support planned operations with
<a href="https://docs.cloud.google.com/sql/docs/postgres/availability#near-zero-downtime">near-zero downtime</a>.</p>
<ul>
<li>Instances with <a href="https://docs.cloud.google.com/sql/docs/postgres/connect-connectors#enforce">connector enforcement enabled</a>
are eligible for planned operations with near-zero downtime.</li>
<li>Instances that use <a href="https://docs.cloud.google.com/sql/docs/postgres/configure-private-services-access">private services access</a>
with a non-RFC 1918 IP address are eligible for planned operations with near-zero downtime.</li>
</ul>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Feature</h3>
<p>If a specific active query is blocked or running much longer than expected, it
can block other dependent queries. Cloud SQL for SQL Server offers an optional
feature that lets you view and terminate blocking queries.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/sqlserver/monitor-active-queries#blocked-active-queries">Blocked active queries</a> (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">Cluster Toolkit</h2>
<h3>Feature</h3>
<p>Cluster Toolkit v1.89.0 is available. This release lets you
configure virtual machines (VMs) dynamically for Slurm and manage secondary
NICs by using the Networking Dynamic Resource Allocation (DRA) driver. This
release also updates the GKE A3 Mega blueprint to align with
integration tests and ensure stability. This version also adds
support to use Fractional G4 GPU instances in Slurm. For details, see the <a href="https://github.com/GoogleCloudPlatform/cluster-toolkit/discussions/5576">Release
announcement on GitHub</a>.</p>
<h2 class="release-note-product-title">Cortex Framework</h2>
<h3>Announcement</h3>
<h3 id="release_7">Release 7</h3>
<h3>Feature</h3>
<p>Cortex Framework <strong>version 7</strong> introduces a highly modular deployment architecture, simplified data orchestration via <a href="https://docs.cloud.google.com/dataform/docs">Dataform</a>, and enhanced support for the next generation of AI-ready data products with <a href="https://docs.cloud.google.com/bigquery/docs">BigQuery</a> - enabling enterprises to build, extend, and deploy robust data models and pipelines for advanced analytics and AI/agentic use cases. To request access to the GitHub repository, see <a href="https://docs.cloud.google.com/cortex/docs/request-access">Request access</a>.</p>
<ul>
<li><p><strong>Key architecture features</strong></p>
<ul>
<li><strong>Modular deployment and smart dependency resolution</strong>: Deploy exactly what you need. Simply select the desired data products, and the framework will automatically identify, retrieve, and transform the necessary tables to the data foundation layer, ensuring no unnecessary data is processed. Easily add custom fields or logic without breaking standard models.</li>
<li><strong>Native dependency graph generation</strong>: Automatically handle the order of operations for complex data models, ensuring prerequisite tables are ready before deploying data foundations and data products.</li>
<li><strong>Bring your own CDC (External data foundation)</strong>: A flexible architecture allows you to bypass built-in Change Data Capture processing and connect your own existing CDC pipelines directly to the foundation layer.</li>
<li><strong>Serverless BigQuery-native execution</strong>: Orchestration relies entirely on Google Cloud Dataform, enabling easy data transformation and processing using version-controlled SQL. No standing compute clusters or Airflow VMs are required, minimizing infrastructure overhead.</li>
<li><strong>Incremental loading</strong>: Native, incremental loading configurations ensure highly efficient processing of large enterprise datasets. Significantly reduce BigQuery processing time and costs by processing only new or changed data since the last execution.</li>
<li><strong>High data fidelity &amp; semantics</strong>: Features dynamic discovery and ingestion of custom fields, robust semantic mapping (e.g. translating cryptic table names to business-friendly terms), AI-ready metadata, and advanced logic handling (e.g. integrating the SAP TCURX table for exact currency decimal shifts).</li>
<li><strong>Multi-system SAP support</strong>: Built-in dynamic dependency resolution and logic differentiation allows seamless compilation and parallel deployment for both SAP ECC and SAP S/4HANA source systems. Seamlessly bring in data from multiple SAP ERP systems.</li>
<li><strong>Extensibility framework</strong>: Maintain a clean separation between your custom data products and Cortex Data Products using namespaces. This ensures you can benefit from the latest Cortex updates without impacting your custom work.</li>
</ul></li>
<li><p><strong>Data product accelerators</strong></p>
<p>BigQuery based <a href="https://docs.cloud.google.com/cortex/docs/data-product#data_source_specific_data_products_for_sap_erp">data product accelerators for SAP ERP</a>
(SAP ECC and S/4HANA), purpose-built for
AI-readiness with agent-friendly metadata included for all data model and
field-level descriptions.</p></li>
<li><p><strong>Solution samples for SAP ERP or SAP BDC</strong></p>
<p>Solution reference architectures and code snippets for demonstrating
how to build use cases on top of Cortex Framework data
products to address particular business needs.</p>
<ul>
<li><strong><a href="https://docs.cloud.google.com/cortex/docs/sales-performance-insights">Sales Performance Insights</a></strong>: How to accelerate
insights into sales performance health using SAP ERP or SAP BDC sourced data.</li>
<li><strong><a href="https://docs.cloud.google.com/cortex/docs/supplier-spend-analysis">Supplier Spend Analysis</a></strong>: How to accelerate insights
into supplier spend position using SAP ERP or SAP BDC sourced data.</li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Access to Gemini 3.1 Pro and 3 Flash in Limited Availability</strong></p>
<p>Gemini Enterprise users now have access to 3.1 Pro and 3 Flash in Limited Availability. This means that Gemini Enterprise app users will get the generally available Service Level Objectives (SLOs) for these models as part of the Gemini Enterprise Service while the models are in Preview. We are currently monitoring the model's performance and determining the appropriate, long-term (SLOs) and plan to offer these SLOs soon. Additionally, we currently support standard Data Location (Data Residency or "DRZ") commitments in US/EU/global multi-regions.</p>
<aside class="note"><strong>Note:</strong><span> There is a correction to this release note. See <a href="#May_13_2026">May 13, 2026</a>.</span></aside>
<p>For more information, see: <a href="https://docs.cloud.google.com/gemini/enterprise/docs/known-limitations#using-gemini-3-preview">Using Gemini 3.1 Pro and 3 Flash in Limited Availability</a>.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>VPC Service Controls for Google SecOps general availability</strong></p>
<p>VPC Service Controls is now GA. This feature helps to create perimeters and protect resources and services data from accidental or targeted action by external or insider entities. This in turn can minimize unwarranted data exfiltration risks from Google Cloud services. For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/secops/vpcsc-for-secops">Configure VPC Service Controls for Google SecOps</a> and <a href="https://docs.cloud.google.com/vpc-service-controls/docs/overview">Overview of VPC Service Controls</a>.</p>
<h2 class="release-note-product-title">Resource Manager</h2>
<h3>Feature</h3>
<p><strong>Generally Available</strong>: The Resource Manager remote MCP server is now
<a href="(https://cloud.google.com/products#product-launch-stages)">generally available</a>.
The remote MCP server lets AI agents dynamically search for and identify all
Google Cloud projects that you have the necessary permissions to access. This
ensures that agents have the correct identifiers (such as project ID, project
number, and lifecycle state) before attempting more specific resource configurations.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/resource-manager/docs/use-resourcemanager-mcp">Use the Resource Manager remote MCP server</a>.</p>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>BigQuery Connector for SAP version 2.13</strong></p>
<p>Version 2.13 of the BigQuery Connector for SAP is generally available (GA).
This version resolves an issue where data replication for partitioned
tables failed when the table schema caching feature was enabled.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sap/docs/bq-connector/whats-new#version-2-13">What's new with BigQuery Connector for SAP</a>.</p>
<h2 class="release-note-product-title">VPC Service Controls</h2>
<h3>Feature</h3>
<p><strong>VPC Service Controls feature:</strong> Support for using IAM roles in
ingress and egress rules to allow access to resources protected by a service
perimeter is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.
This feature includes the following updates:</p>
<ul>
<li><p>You can use the <a href="https://docs.cloud.google.com/vpc-service-controls/docs/configure-iam-roles#check-role"><code>gcloud access-context-manager supported-permissions describe</code></a>
command to check the support status of an IAM role.</p></li>
<li><p>You can use the <a href="https://docs.cloud.google.com/vpc-service-controls/docs/configure-iam-roles#list-permissions"><code>gcloud access-context-manager supported-permissions list</code></a>
command to retrieve the complete list of all supported permissions.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/vpc-service-controls/docs/configure-iam-roles">Configure IAM roles in ingress and egress rules</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 29, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_29_2026</id>
    <updated>2026-04-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_29_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On April 29th, 2026, we began maintenance updates of Apigee instances <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">configured for maintenance windows</a>.</p>
<p>If you set a preferred window for maintenance for your instance, and your instance version is
below <strong>1-17-0-apigee-4</strong>, your instance will be updated to <strong>1-17-0-apigee-4</strong> within the
next seven to 21 days. A notification containing the expected date of upgrade will be sent within the next two business days.</p>
<aside class="note">Note: Instances that meet either of the following two criteria will <b>not</b> be updated:
<ul>
<li>Your instance has a DNS misconfiguration, as described in <a href="https://docs.cloud.google.com/apigee/docs/release/known-issues">Known Issue 445936920</a>.</li>
<li>Your instance uses an Apigee Java Library that has been removed, as described in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_16_2025">Apigee release notes dated October 16, 2025</a>.</li>
</ul></aside>
<p>For more information on participating in scheduled maintenance windows, see <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance">Maintenance overview</a> and <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">Manage Apigee instance maintenance windows</a>.</p>
<h2 class="release-note-product-title">Application Design Center</h2>
<h3>Feature</h3>
<p>Use the following Google-provided application templates in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>:</p>
<ul>
<li><a href="https://docs.cloud.google.com/application-design-center/docs/simple-agent-platform">Simple Agent Platform</a></li>
<li><a href="https://docs.cloud.google.com/application-design-center/docs/agent-platform-with-governance">Agent Platform with governance</a></li>
</ul>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Breaking</h3>
<p><a href="https://docs.cloud.google.com/dataform/docs/strict-act-as-mode">Strict act-as mode</a>
is enforced globally for all Dataform repositories, requiring the use of a
custom service account or user credentials for running Dataform workflows,
BigQuery pipelines, notebooks, and data preparations.</p>
<h3>Feature</h3>
<p>You can now use the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/vectorindex_functions#vector_indexstatistics"><code>VECTOR_INDEX.STATISTICS</code> function</a> to calculate how much an indexed table's data has drifted between when a
vector index was created and the present. If table data has changed enough
to require a <a href="https://docs.cloud.google.com/bigquery/docs/vector-index#rebuild_a_vector_index">vector index rebuild</a>, you can use the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/data-definition-language#alter_vector_index_rebuild_statement"><code>ALTER VECTOR INDEX REBUILD</code> statement</a>
to rebuild the vector index without downtime. These features are
<a href="https://cloud.google.com/products/#product-launch-stages">generally available</a>
(GA).</p>
<h3>Feature</h3>
<p>You can now use the <code>PARTITION BY</code> clause of the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/data-definition-language#create_vector_index_statement"><code>CREATE VECTOR INDEX</code> statement</a>
to <a href="https://docs.cloud.google.com/bigquery/docs/vector-index#partitions">partition TreeAH vector indexes</a>.
Partitioning enables partition pruning and can decrease I/O costs. This feature
is <a href="https://cloud.google.com/products/#product-launch-stages">Generally Available</a>.</p>
<h2 class="release-note-product-title">Cloud Storage</h2>
<h3>Feature</h3>
<p>You can manage object contexts in the Google Cloud Console.
To learn more, see <a href="https://docs.cloud.google.com/storage/docs/use-object-contexts">Use object contexts</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: In an autoscaled managed instance group (MIG), you can monitor
individual autoscaling events and view details to understand the reasons behind
each autoscaling decision. For more information, see
<a href="https://docs.cloud.google.com/compute/docs/autoscaler/understanding-autoscaler-decisions#monitor_autoscaling_events">Monitor autoscaling events</a>.</p>
<h2 class="release-note-product-title">Confidential Space</h2>
<h3>Announcement</h3>
<p>A Confidential Space image (260400) is available. Support for Confidential
Space on H100 GPU (a3-highgpu-1g machine family) is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<h2 class="release-note-product-title">Dataform</h2>
<h3>Feature</h3>
<p>You can use custom constraints with Organization Policy to provide more
granular control over specific fields for the <code>Folder</code> and <code>TeamFolder</code>
resources. For more information, see
<a href="https://docs.cloud.google.com/dataform/docs/create-custom-constraints">Create custom organization policy constraints</a>.
This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Breaking</h3>
<p><a href="https://docs.cloud.google.com/dataform/docs/strict-act-as-mode">Strict act-as mode</a>
is enforced globally for all Dataform repositories, requiring the use of a custom service account or user credentials for running Dataform workflows, BigQuery pipelines, notebooks, and data preparations.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r17-version-updates">(2026-R17) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.1379000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.32.13-gke.1090000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1147000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1205000</li>
<li>1.32.13-gke.1258000</li>
<li>1.32.13-gke.1318000</li>
<li>1.33.9-gke.1117000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1166000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1067000</li>
<li>1.33.10-gke.1115000</li>
<li>1.33.10-gke.1176000</li>
<li>1.34.5-gke.1153000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1068000</li>
<li>1.34.6-gke.1154000</li>
<li>1.34.6-gke.1237000</li>
<li>1.35.2-gke.1485000</li>
<li>1.35.2-gke.1842000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1962000</li>
<li>1.35.3-gke.1234000</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1362000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1362000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.1379000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1318000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.32.12-gke.1127000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1059000</li>
<li>1.32.13-gke.1090000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1147000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1205000</li>
<li>1.33.8-gke.1169000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1060000</li>
<li>1.33.9-gke.1117000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1166000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1067000</li>
<li>1.34.4-gke.1193000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1076000</li>
<li>1.34.5-gke.1153000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1068000</li>
<li>1.35.1-gke.1396002</li>
<li>1.35.2-gke.1269001</li>
<li>1.35.2-gke.1485000</li>
<li>1.35.2-gke.1842000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1962000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v1339">1.33.9-gke.1060000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1205000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1068000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1352">1.35.2-gke.1962000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.32.12-gke.1026000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.12-gke.1076000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.12-gke.1127000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1026000</li>
<li>1.33.8-gke.1112000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1169000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1047000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1130000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1193000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1059000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v1339">1.33.9-gke.1060000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1059000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v1339">1.33.9-gke.1060000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1345">1.34.5-gke.1076000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2415000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1823000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1318000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2154000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2192000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2250000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2286000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2407000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1526000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1576000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1634000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1681000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1816000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.12-gke.1127000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1059000</li>
<li>1.32.13-gke.1090000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1147000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1169000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1060000</li>
<li>1.33.9-gke.1117000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1166000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1193000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1076000</li>
<li>1.34.5-gke.1153000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.1-gke.1396002</li>
<li>1.35.2-gke.1269001</li>
<li>1.35.2-gke.1485000</li>
<li>1.35.2-gke.1842000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2320000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2320000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1723000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2415000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1823000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.32.12-gke.1026000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.12-gke.1076000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.12-gke.1127000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1090000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1147000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.5-gke.2469000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1112000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1169000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1117000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1166000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1047000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1130000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1193000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1153000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1842000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v1339">1.33.9-gke.1060000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v1339">1.33.9-gke.1060000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r17-security-updates">(2026-R17) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.31.14-gke.1823000</td>
<td>cos-117-18613-534-80</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-80_">cos-117-18613-534-80 release notes</a></td>
</tr>
<tr>
<td>1.36.0-gke.1379000</td>
<td>cos-125-19216-220-130</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-220-130_">cos-125-19216-220-130 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Fixed</h3>
<p>In GKE versions earlier than 1.34.6-gke.1154000 and
1.35.2-gke.1691000, mounting Cloud Storage buckets by using the
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/cloud-storage-fuse-csi-driver">Cloud Storage FUSE CSI driver</a>
can experience significant delays. This issue typically manifests as a
<code>CreateContainer error</code> that states the following message:
<code>failed to reserve container name</code>. This error is self-healing and resolves
automatically after the underlying mount operation completes and the container
runtime releases the reservation.</p>
<p>The delay is caused by an inefficient bucket access check performed by the
CSI driver sidecar by using the <code>ListObjects</code> API method, which can take
several hours to complete on buckets that contain millions of empty folders.</p>
<p>The error occurs because the <code>kubelet</code> enforces a strict two-minute timeout
for the container creation request. If the FUSE mount process exceeds this
time limit while the sidecar is performing the initial bucket access check,
then the <code>kubelet</code> cancels the operation and retries. However, the container
runtime remains blocked on the first attempt and retains the reservation for
the container name.</p>
<p>The new GKE releases fix this issue by replacing the
<code>ListObjects</code> check with the <code>GetStorageLayout</code> API method, which performs
the same validation but returns almost instantly in most cases.</p>
<p>To resolve this issue, upgrade your cluster to one of the following versions:</p>
<ul>
<li>1.34.6-gke.1154000 or later</li>
<li>1.35.2-gke.1691000 or later</li>
</ul>
<p>For GKE version 1.33 clusters running version 1.33.5-gke.2435000
or later, you can mitigate this issue by setting the
<code>skipCSIBucketAccessCheck: "true"</code> volume attribute to bypass the check.</p>
<p>There is no supported fix for this issue in cluster versions
1.33.5-gke.2435000 and earlier.</p>
<h3>Change</h3>
<h4 id="2026-r17-version-updates">(2026-R17) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v1339">1.33.9-gke.1060000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1205000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1068000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1352">1.35.2-gke.1962000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.32.12-gke.1026000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.12-gke.1076000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.12-gke.1127000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1026000</li>
<li>1.33.8-gke.1112000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1169000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1047000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1130000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1193000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1059000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v1339">1.33.9-gke.1060000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1059000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v1339">1.33.9-gke.1060000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1345">1.34.5-gke.1076000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r17-version-updates">(2026-R17) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1318000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.32.12-gke.1127000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1059000</li>
<li>1.32.13-gke.1090000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1147000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1205000</li>
<li>1.33.8-gke.1169000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1060000</li>
<li>1.33.9-gke.1117000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1166000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1067000</li>
<li>1.34.4-gke.1193000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1076000</li>
<li>1.34.5-gke.1153000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1068000</li>
<li>1.35.1-gke.1396002</li>
<li>1.35.2-gke.1269001</li>
<li>1.35.2-gke.1485000</li>
<li>1.35.2-gke.1842000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1962000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r17-version-updates">(2026-R17) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.1379000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.32.13-gke.1090000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1147000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1205000</li>
<li>1.32.13-gke.1258000</li>
<li>1.32.13-gke.1318000</li>
<li>1.33.9-gke.1117000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1166000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1067000</li>
<li>1.33.10-gke.1115000</li>
<li>1.33.10-gke.1176000</li>
<li>1.34.5-gke.1153000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1068000</li>
<li>1.34.6-gke.1154000</li>
<li>1.34.6-gke.1237000</li>
<li>1.35.2-gke.1485000</li>
<li>1.35.2-gke.1842000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1962000</li>
<li>1.35.3-gke.1234000</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1362000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1362000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.1379000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r17-version-updates">(2026-R17) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2415000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1823000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1737000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.32.12-gke.1026000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.12-gke.1076000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.12-gke.1127000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1090000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1147000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.5-gke.2469000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1112000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1169000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1117000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1166000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1047000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1130000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1193000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1153000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.2-gke.1842000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v1339">1.33.9-gke.1060000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v1339">1.33.9-gke.1060000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r17-version-updates">(2026-R17) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2415000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1823000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1318000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2154000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2192000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2250000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2286000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2407000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1526000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1576000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1634000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1681000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1816000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.12-gke.1127000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1059000</li>
<li>1.32.13-gke.1090000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1147000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.8-gke.1169000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1060000</li>
<li>1.33.9-gke.1117000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.9-gke.1166000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.4-gke.1193000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1076000</li>
<li>1.34.5-gke.1153000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.5-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.1-gke.1396002</li>
<li>1.35.2-gke.1269001</li>
<li>1.35.2-gke.1485000</li>
<li>1.35.2-gke.1842000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2320000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2320000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1723000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>UrlScan.io</strong>: Version 30.0</p>
<ul>
<li><p>Added <code>is_risky</code> handling to the following action:</p>
<ul>
<li><strong>Url Check</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 107.0</p>
<ul>
<li><strong>Integration</strong>: Updated TIPCommon dependency.</li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 41.0</p>
<ul>
<li><p>Updated MSG attachments processing logic in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Zerofox</strong>: Version 4.0</p>
<ul>
<li><strong>Integration</strong>: Updated documentation link.</li>
</ul>
<h3>Change</h3>
<p><strong>MISP</strong>: Version 39.0</p>
<ul>
<li><p>Updated tag retrieval logic in the following actions:</p>
<ul>
<li><p><strong>Add Tag to an Attribute</strong></p></li>
<li><p><strong>Add Tag to an Event</strong></p></li>
<li><p><strong>Remove Tag from an Attribute</strong></p></li>
<li><p><strong>Remove Tag from an Event</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Anomali ThreatStream</strong>: Version 16.0</p>
<ul>
<li><p>Added <code>is_risky</code> handling to the following action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail Delegated</strong>: Version 18.0</p>
<ul>
<li><p>Updated MSG attachments processing logic in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Delegated Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Palo Alto Cortex XDR</strong>: Version 28.0</p>
<ul>
<li><p>Added the ability to ignore specific artifact types to the following
connector:</p>
<ul>
<li><strong>Palo Alto Cortex XDR Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p>Source code is now publicly available on <a href="https://github.com/chronicle/content-hub">GitHub</a>
for the following integrations:</p>
<ul>
<li><p><strong>Cisco Orbital</strong>: Version 9.0</p></li>
<li><p><strong>F5 Big IQ</strong>: Version 8.0</p></li>
<li><p><strong>FireEye EX</strong>: Version 14.0</p></li>
<li><p><strong>HCL BigFix Inventory</strong>: Version 6.0</p></li>
<li><p><strong>Illusive Networks</strong>: Version 8.0</p></li>
<li><p><strong>Lastline</strong>: Version 10.0</p></li>
<li><p><strong>McAfee ATD</strong>: Version 18.0</p></li>
<li><p><strong>McAfee Active Response</strong>: Version 10.0</p></li>
<li><p><strong>ObserveIT</strong>: Version 6.0</p></li>
<li><p><strong>Outpost24</strong>: Version 9.0</p></li>
<li><p><strong>Site24x7</strong>: Version 7.0</p></li>
<li><p><strong>Splash</strong>: Version 8.0</p></li>
<li><p><strong>Websense</strong>: Version 15.0</p></li>
</ul>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud's Agent for SAP version 3.13</strong></p>
<p>Version 3.13 of Google Cloud's Agent for SAP is generally available (GA). This
version introduces minor bug fixes, enhancements for disk snapshot based
recovery for SAP HANA, and security enhancements.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/sap/docs/agent-for-sap/whats-new">What's new with Google Cloud's Agent for SAP</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 28, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_28_2026</id>
    <updated>2026-04-28T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_28_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Change</h3>
<p>When the initial user or password is unspecified during cluster creation, a locked <a href="https://docs.cloud.google.com/alloydb/docs/database-users/overview#postgres-user"><code>postgres</code> role</a> with <code>null</code> password is created.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can now
<a href="https://docs.cloud.google.com/bigquery/docs/materialized-views-intro#cdc">create materialized views over active change data capture (CDC) enabled tables</a>.
This feature is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Cloud Asset Inventory</h2>
<h3>Feature</h3>
<p>The following resource types are publicly available through the
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/exportAssets">ExportAssets</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/listing-assets">ListAssets</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/batchGetAssetsHistory">BatchGetAssetsHistory</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/queryAssets">QueryAssets</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/feeds">Feed</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/searchAllResources">SearchAllResources</a>,
and
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/searchAllIamPolicies">SearchAllIamPolicies</a>
APIs.</p>
<ul>
<li>App Lifecycle Manager
<ul>
<li><code>saasservicemgmt.googleapis.com/Saas</code></li>
<li><code>saasservicemgmt.googleapis.com/Tenant</code></li>
<li><code>saasservicemgmt.googleapis.com/UnitKind</code></li>
<li><code>saasservicemgmt.googleapis.com/Unit</code></li>
<li><code>saasservicemgmt.googleapis.com/Release</code></li>
</ul></li>
<li>Backup and DR
<ul>
<li><code>backupdr.googleapis.com/BackupPlanRevision</code></li>
</ul></li>
<li>Parallelstore
<ul>
<li><code>parallelstore.googleapis.com/Instance</code></li>
</ul></li>
<li>Vertex AI
<ul>
<li><code>aiplatform.googleapis.com/DeploymentResourcePool</code></li></ul></li></ul>
<h2 class="release-note-product-title">Cloud Composer</h2>
<h3>Feature</h3>
<p>Managed Airflow (Gen 3) environments with Airflow 3 support
<a href="https://docs.cloud.google.com/composer/docs/composer-3/access-environments-with-workforce-identity-federation">access with external identities</a>
through workforce identity federation starting from version
composer-3-airflow-3.1.7-build.7.</p>
<h3>Change</h3>
<p>The default version of Airflow is changed to 2.11.1.</p>
<h3>Fixed</h3>
<p>Fixed an issue where DAGs were imported from snapshots even when the
"Skip copying Cloud Storage data" option was selected.</p>
<h3>Fixed</h3>
<p>The <code>GOOGLE_CLOUD_PROJECT</code> environment variable is now set on schedulers and
triggerers. It's no longer required to set the project ID explicitly when
configuring the Secret Manager backend.</p>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-3">Airflow builds</a>
are available in Managed Airflow (Gen 3):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-3-1-7-build-7">composer-3-airflow-3.1.7-build.7</a></li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-11-1-build-3">composer-3-airflow-2.11.1-build.3</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-10-5-build-36">composer-3-airflow-2.10.5-build.36</a></li>
</ul>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-2">images</a>
are available in Managed Airflow (Gen 2):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-0-airflow-2-11-1">composer-2.17.0-airflow-2.11.1</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-0-airflow-2-10-5">composer-2.17.0-airflow-2.10.5</a></li>
</ul>
<h3>Deprecated</h3>
<p>Airflow 2.9.3 is no longer included in Managed Airflow images and builds.</p>
<h3>Deprecated</h3>
<p>The following Managed Airflow versions and builds have reached their
<a href="https://docs.cloud.google.com/composer/docs/composer-versioning-overview#version-deprecation-and-support">end of support period</a>:</p>
<ul>
<li>composer-3-airflow-2.9.3-build.20</li>
<li>composer-3-airflow-2.10.2 builds from build.0 to build.13</li>
<li>composer-2.12.1-airflow-*</li>
</ul>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-125-19216-220-174_">cos-125-19216-220-174 <a id='"cos-arm64-125-19216-220-174"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/86ce3b3fe7e3b54c836775f62acff9f5218e166e
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.174/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the R595 Nvidia driver production branch.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA drivers v580.126.16 and v580.126.20.</p>
<h3>Fixed</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.1.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-40135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-70873 in dev-db/sqlite.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23245 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23255 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23276 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23302 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23368 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23374 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23397 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23398 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23399 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23412 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23413 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23441 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23442 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23456 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23457 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23465 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23471 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31400 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31402 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31406 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31407 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31415 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31416 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31418 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31423 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31424 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31426 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31427 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31428 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31434 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31438 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31446 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31447 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31448 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31450 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31451 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31454 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31495 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31515 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31516 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31519 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31521 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31523 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31525 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31528 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31531 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31557 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31648 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31667 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32280, CVE-2026-32281, CVE-2026-32283,
CVE-2026-27140, CVE-2026-27144 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-34743 in app-arch/xz-utils.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4046 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-106_">cos-121-18867-381-106 <a id='"cos-arm64-121-18867-381-106"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/cce81d8ec032eaf4a27103743c3106ca5c4f14ec
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.106/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Added support for NVIDIA drivers v580.126.16 and v580.126.20.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-70873 in dev-db/sqlite.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31430 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31446 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31447 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31450 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31451 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31495 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31515 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31521 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31523 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31525 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32280, CVE-2026-32281, CVE-2026-32283,
CVE-2026-27140, CVE-2026-27144 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-34743 in app-arch/xz-utils.</p>
<h3>Security</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-534-104_">cos-117-18613-534-104 <a id='"cos-arm64-117-18613-534-104"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6d5420309dd6902776517e31546fbd26337d2819
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.104/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Added support for NVIDIA drivers v580.126.16 and v580.126.20.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-70873 in dev-db/sqlite.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31430 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31446 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31447 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31450 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31451 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31454 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31495 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31515 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31521 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31523 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31525 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32280, CVE-2026-32281, CVE-2026-32283,
CVE-2026-27140, CVE-2026-27144 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-34743 in app-arch/xz-utils.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Custom MCP server data stores (Preview)</strong></p>
<p>You can connect your custom Model Context Protocol (MCP) server with
Gemini Enterprise to securely access your company's private data, custom
internal tools, and MCP-compliant third-party systems.</p>
<p>This feature is turned off by default. To enable it, an Organization Policy
Administrator must remove the organization constraint.</p>
<p>This feature is in Public Preview. For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/custom-mcp-server/set-up-custom-mcp-server">Set up your custom MCP server</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/custom-mcp-server/override-constraint-for-custom-mcp-data-stores">Override the organization policy for Custom MCP data stores</a></li>
</ul>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Improved transcription quality for Gemini Live API</strong></p>
<p>You can now improve transcription quality for multilingual automatic speech
recognition (ASR) by using the
<code>[input/output]_audio_transcription.language_codes</code> field.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/live-api/start-manage-session#enable-audio-transcription">Enable audio transcription for the session</a>.</p>
<h3>Feature</h3>
<p><strong>Asynchronous function calling with Live API</strong></p>
<p>Asynchronous function calling is now available in <a href="https://cloud.google.com/products#product-launch-stages">public
preview</a> in
Gemini Live API. You can run functions in parallel with conversation,
manage background processing, and handle function responses with policies
including <code>SILENT</code>, <code>WHEN_IDLE</code>, and <code>INTERRUPT</code>. For more information, see
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/live-api/asynchronous-function-calling">Asynchronous function calling with
Gemini Live API</a>.</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Announcement</h3>
<p>Cloud Composer is now called <a href="https://docs.cloud.google.com/composer/docs">Managed Service for Apache Airflow</a>. The names for associated APIs, client libraries, CLI commands, and Identity and Access Management (IAM) remain unchanged and still
reference Composer.</p>
<h3>Announcement</h3>
<p><strong>Dataproc</strong> and <strong>Google Cloud Serverless for Apache Spark</strong> are now unified
under the <a href="https://docs.cloud.google.com/dataproc/docs"><strong>Managed Service for Apache Spark</strong></a>
brand. This change consolidates our managed Spark deployment options into a
single umbrella brand that includes the full breadth of our Spark capabilities.
No existing functionality is being removed as part of this change, and there
is no impact to the Dataproc API, metastore, client library, CLI, or IAM names.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 27, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_27_2026</id>
    <updated>2026-04-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_27_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">API Gateway</h2>
<h3>Change</h3>
<p><strong>New validations on paths in API configurations</strong></p>
<p>API Gateway now enforces stricter syntax validations on templated paths when you create new API configurations and gateways.</p>
<p>See <a href="https://docs.cloud.google.com/api-gateway/docs/path-templating#syntax_rules">path templating syntax rules</a> and <a href="https://docs.cloud.google.com/api-gateway/docs/path-templating#limits">limits</a> for more information.</p>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1144">v1.14.4</h3>
<p>On April 27, 2026 we released an updated version of the Apigee hybrid software, v1.14.4.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version v1.14.4</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Sidecar authentication for Workload Identity Federation on non-GKE platforms</strong></p>
<p>Starting in version v1.14.4, you can now use a sidecar along with Workload Identity Federation on non-GKE platforms to mount security tokens from your preferred identity provider (IDP) for service account authentication. See <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/use-sidecar-for-wif">Use sidecar authentication for Workload Identity Federation on non-GKE platforms</a>.</p>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>471527485, 471173296, 471172082, 471171833</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58056">CVE-2025-58056</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li></ul></td>
</tr>
<tr>
<td><strong>471290390, 471199955, 471197958, 470990914</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58056">CVE-2025-58056</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li></ul></td>
</tr>
<tr>
<td><strong>470992132, 470991089, 470989623, 470989232, 470988977</strong></td>
<td><strong>Security fixes for <code>apigee-mart-server</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48924">CVE-2025-48924</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58056">CVE-2025-58056</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li></ul></td>
</tr>
<tr>
<td><strong>470953507, 470953254, 470952893</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40897">CVE-2022-40897</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2976">CVE-2023-2976</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47273">CVE-2025-47273</a> </li></ul></td>
</tr>
<tr>
<td><strong>451224723, 451224123</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4756">CVE-2010-4756</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3389">CVE-2011-3389</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4392">CVE-2013-4392</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3276">CVE-2015-3276</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14159">CVE-2017-14159</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17740">CVE-2017-17740</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20796">CVE-2018-20796</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5709">CVE-2018-5709</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6829">CVE-2018-6829</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010022">CVE-2019-1010022</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010023">CVE-2019-1010023</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010024">CVE-2019-1010024</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1010025">CVE-2019-1010025</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9192">CVE-2019-9192</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15719">CVE-2020-15719</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27943">CVE-2022-27943</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2953">CVE-2023-2953</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31437">CVE-2023-31437</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31438">CVE-2023-31438</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31439">CVE-2023-31439</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45853">CVE-2023-45853</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2236">CVE-2024-2236</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2379">CVE-2024-2379</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26458">CVE-2024-26458</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26461">CVE-2024-26461</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0725">CVE-2025-0725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10148">CVE-2025-10148</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27587">CVE-2025-27587</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62813">CVE-2025-62813</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9086">CVE-2025-9086</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9230">CVE-2025-9230</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9232">CVE-2025-9232</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4437">CVE-2026-4437</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4046">CVE-2026-4046</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15558">CVE-2025-15558</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15558">CVE-2025-15558</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-connect-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68121">CVE-2025-68121</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-envoy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4437">CVE-2026-4437</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4046">CVE-2026-4046</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra-client</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-mint-task-scheduler</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33871">CVE-2026-33871</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33870">CVE-2026-33870</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32287">CVE-2026-32287</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prom-prometheus</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040">CVE-2026-34040</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32023">CVE-2025-32023</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61732">CVE-2025-61732</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47907">CVE-2025-47907</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4674">CVE-2025-4674</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-stackdriver-logging-agent</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33176">CVE-2026-33176</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61594">CVE-2025-61594</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24294">CVE-2025-24294</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33953">CVE-2023-33953</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32511">CVE-2022-32511</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29181">CVE-2022-29181</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24839">CVE-2022-24839</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24836">CVE-2022-24836</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0759">CVE-2022-0759</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41817">CVE-2021-41817</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31799">CVE-2021-31799</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30560">CVE-2021-30560</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28965">CVE-2021-28965</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23214">CVE-2021-23214</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25695">CVE-2020-25695</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25694">CVE-2020-25694</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25613">CVE-2020-25613</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3881">CVE-2019-3881</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25032">CVE-2018-25032</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1115">CVE-2018-1115</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10915">CVE-2018-10915</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1058">CVE-2018-1058</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1053">CVE-2018-1053</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7546">CVE-2017-7546</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7484">CVE-2017-7484</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15098">CVE-2017-15098</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14798">CVE-2017-14798</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7954">CVE-2016-7954</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7048">CVE-2016-7048</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5424">CVE-2016-5424</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5423">CVE-2016-5423</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0766">CVE-2016-0766</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3167">CVE-2015-3167</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3166">CVE-2015-3166</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0244">CVE-2015-0244</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0243">CVE-2015-0243</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0241">CVE-2015-0241</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-udca</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li></ul></td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33186">CVE-2026-33186</a> </li></ul></td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>The AI Cost Summary Agent is now available in Preview</strong></p>
<p>You can now use the AI Cost Summary Agent to analyze your AI costs and gain
critical insights into your AI-related spend. The agent analyzes
spending related to Gemini usage, including Gemini API and
Vertex AI.</p>
<p>This feature is available as a widget on the <strong>Billing Overview</strong> page for your
Cloud Billing account.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/billing/docs/how-to/gemini/ai-cost-summary">Analyze your AI spend with the AI Cost Summary
Agent</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>A new quota system governing the configuration size of Application Load Balancer
is now available in <strong>Preview</strong>. This update increases the individual URL map
size limit from 64 KB and 128 KB to 1 MB. For more information,
see <a href="https://docs.cloud.google.com/load-balancing/docs/url-map-size-quota">URL map size and quota units</a>.</p>
<p>Key aspects of this feature include:</p>
<ul>
<li>Complexity-based quota: <em>Quota units</em> reflect URL map complexity (number of
rules, hostnames, and path matchers).</li>
<li>Scoped measurement: Quota is measured and enforced on a per-project,
per-region, or per-VPC depending on Application Load Balancer type.</li>
<li>Active consumption: Only URL maps currently referenced by forwarding rules
contribute to quota usage.</li>
<li>New URL map size limit: Projects enabled for the new quota have a new URL map
size limit increased to 1 MB for global and regional external and internal
Application Load Balancers. Classic Application Load Balancer remain
restricted to 64 KB.</li>
</ul>
<p>For more information on increasing your limit or to participate in the preview,
please contact <a href="https://cloud.google.com/support">Google Cloud Support</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Announcement</h3>
<p>Managed Cloud Service Mesh using the <code>TRAFFIC_DIRECTOR</code> implementation in the
regular channel now supports a limited implementation of the <code>EnvoyFilter</code> API.
To learn about the supported fields, extensions, and how to use <code>EnvoyFilter</code>
for features like local rate limiting see
<a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility">Data plane extensibility with <code>EnvoyFilter</code></a>.</p>
<p>To troubleshoot any issue while configuring, see
<a href="https://docs.cloud.google.com/service-mesh/docs/troubleshooting/troubleshoot-data-plane-extensibility">Resolving data plane extensibility issues</a>.</p>
<h2 class="release-note-product-title">Cloud Storage</h2>
<h3>Feature</h3>
<p>Cloud Storage now offers support for AI zones. To learn more, see
<a href="https://docs.cloud.google.com/storage/docs/ai-zones">AI zones</a>.</p>
<h2 class="release-note-product-title">Cloud TPU</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Cloud TPU now offers TPU availability in AI
zones. To learn more, see
<a href="https://docs.cloud.google.com/compute/docs/regions-zones/ai-zones">About AI zones</a>.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>Cloud Trace is a service covered by the
<a href="https://cloud.google.com/operations/sla">Cloud Observability (Monitoring, Logging, Trace) Service Level Agreement (SLA)</a>.</p>
<h2 class="release-note-product-title">Cloud Workstations</h2>
<h3>Feature</h3>
<p>Cloud Workstations UI supports additional machine series and types, including
<strong>A2</strong>, <strong>A3</strong>, <strong>C3</strong>, <strong>C4</strong>, <strong>G4</strong>, <strong>M3</strong>, <strong>N4</strong>, and <strong>Z3</strong>.
You can also select <strong>Confidential C3 standard</strong> machine types. For more
information, see <a href="https://docs.cloud.google.com/workstations/docs/available-machine-types">Available machine types</a>.</p>
<p>The <a href="https://docs.cloud.google.com/workstations/docs/preconfigured-base-images">preconfigured base images</a>
include a notification when the <code>running_timeout</code> for the workstation is
close to being reached.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Compute Engine now offers support for AI zones. To
learn more, see <a href="https://docs.cloud.google.com/compute/docs/regions-zones/ai-zones">AI zones</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-121-18867-381-95_">cos-121-18867-381-95 <a id='"cos-arm64-121-18867-381-95"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e0aeb6772ffabffa654fb3039d17167686a5d4b6
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.95/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Resolved an issue that could cause soft lockups
in stressed environments when iommu.strict=1.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/node-problem-detector to v0.8.25.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.401.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Fixed</h3>
<p>Upgraded virtual/logger to v0-r3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31415 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31416 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31418 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31423 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31424 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31426 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31427 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31428 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35414 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4046 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-a9b8b18 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded containerd to v2.0.8. This fixes CVE-2026-35469.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-534-95_">cos-117-18613-534-95 <a id='"cos-arm64-117-18613-534-95"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/db065d1e581611d7f1ef1451eb2d54ed3e1e43bc
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.95/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Resolved an issue that could cause soft lockups
in stressed environments when iommu.strict=1</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/node-problem-detector to v0.8.25.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31415 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31416 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31418 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31423 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31424 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31426 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31427 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31428 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35414 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4046 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-a9b8b18 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated spdystream to v0.5.1 for containerd. This fixed CVE-2026-35469.</p>
<h3>Change</h3>
<h3 id="cos-113-18244-582-86_">cos-113-18244-582-86 <a id='"cos-arm64-113-18244-582-86"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/5b7904f18e1dfecfd30cf5076f57f302029b6404
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.86/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23360 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23401 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31415 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31416 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31418 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31423 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31424 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31427 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31428 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated spdystream to v0.5.1 for containerd. This fixed CVE-2026-35469.</p>
<h3>Change</h3>
<h3 id="cos-125-19216-220-150_">cos-125-19216-220-150 <a id='"cos-arm64-125-19216-220-150"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/290dd196f19720702d0837eb8c03202d0f63b7ef
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.150/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Resolved an issue that could cause soft lockups
in stressed environments when iommu.strict=1</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.2.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35414 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-7e3955b in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-a9b8b18 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded containerd to v2.1.7. This fixes CVE-2026-35469.</p>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-120-15_">cos-beta-129-19506-120-15 <a id='"cos-arm64-beta-129-19506-120-15"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/494b0342b38b614242985fa139fc510253b3b81f
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.15/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-admin/fluent-bit to v4.2.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/pv to v1.10.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35414 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-7e3955b in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-a9b8b18 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgrdaed containerd to v2.2.3. This fixes CVE-2026-35469.</p>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available (GA) with an allowlist:</strong> You can now <a href="https://docs.cloud.google.com/vmware-engine/docs/private-clouds/howto-manage-private-cloud#migrate-vms">migrate VMware management VMs</a>
from their host cluster to a different cluster within the same private cloud.
This feature is available to select customers through an allowlist. To migrate
management VMs, you must have at least two clusters in your private cloud, and
the destination cluster must be a workload cluster. This operation transitions
the target workload cluster to a management cluster, and the source management
cluster becomes a workload cluster.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>Google Kubernetes Engine now offers support for AI zones. To learn more, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/configuration-overview#ai-zones">AI zones</a>.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Announcement</h3>
<p><strong>New parser documentation now available</strong></p>
<p>New parser documentation is available to help you ingest and normalize logs from the following sources:</p>
<ul>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/group-ib">Collect Group-IB Threat Intelligence logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/microsoft-scep">Collect Microsoft System Center Endpoint Protection (SCEP) logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/nagios">Collect Nagios XI logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/neo4j">Collect Neo4j Aura logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/nucleus-vulnerability">Collect Nucleus Security - Nucleus Unified Vulnerability Management logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/nyansa-events">Collect Nyansa Voyance / VMware Edge Network Intelligence logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/okera-dap">Collect Okera Dynamic Access Platform (ODAP) audit logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/okta-scaleft">Collect Okta Advanced Server Access logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/onapsis">Collect Onapsis Platform logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/oneidentity-tpam">Collect One Identity TPAM logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/oci-cloudguard">Collect Oracle Cloud Infrastructure - Oracle Cloud Guard logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/oort">Collect Cisco Identity Intelligence logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/sharepoint">Collect Microsoft SharePoint (Office 365) logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/netapp-bluexp">Collect NetApp Console (formerly BlueXP) audit logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/netwrix">Collect Netwrix Auditor logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/vitalqip">Collect Nokia VitalQIP DDI logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/openai-auditlog">Collect OpenAI Audit logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/netflow-otel">Collect OpenTelemetry Netflow Receiver logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/oracle-fusion">Collect Oracle Fusion Cloud Applications logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/net-suite">Collect Oracle NetSuite - NetSuite Applications Suite logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/oracle-netsuite">Collect Oracle NetSuite logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/vectra-alerts">Collect Vectra Alerts logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/vectra-xdr">Collect Vectra XDR logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/winevtlog-xml">Collect Windows Event logs (XML format)</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/winscp">Collect WinSCP logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/workday-user-activity">Collect Workday User Activity logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/wpengine">Collect WP Engine logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/xiting-xams">Collect XAMS by Xiting logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/yubico-otp">Collect Yubico OTP logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/zero-networks">Collect Zero Networks logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/zix-email-encryption">Collect Zix Email Encryption logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/zscaler-nss-feeds">Collect Zscaler NSS Feeds for Alerts logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/zywall">Collect ZyXEL ZyWALL logs</a></li>
</ul>
<h2 class="release-note-product-title">Guest Environment</h2>
<h3>Fixed</h3>
<p>Version <code>20260423.01</code> of the <a href="https://docs.cloud.google.com/compute/docs/images/guest-agent">guest agent</a>
is now available for all supported operating systems. This version includes
the following fixes:</p>
<ul>
<li>Updates the guest agent Go dependencies to address security vulnerabilities.</li>
<li>Ensures that the internal initialization is complete before signaling
readiness to systemd. This fix resolves an issue in version <code>20260329.00</code>
where dependent services like SSH failed to start due to missing host keys.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>April 24, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_24_2026</id>
    <updated>2026-04-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_24_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Database Center</h2>
<h3>Feature</h3>
<p>The Database Center REST and RPC APIs are available in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.
The Database Center API provides access to an organization-wide,
cross-product database fleet health platform. You can use the API to aggregate
health, security, and compliance signals from various Google Cloud
databases.</p>
<p>For more information, see the <a href="https://docs.cloud.google.com/database-center/docs/reference">Database Center API reference</a>.</p>
<h3>Feature</h3>
<p>Database Center support for Model Context Protocol (MCP) is
<a href="https://cloud.google.com/products/#product-launch-stages">generally available</a>
(GA). You can use the Database Center remote MCP server to
connect to Database Center from AI applications such as
Gemini CLI, ChatGPT, or Claude. The MCP server provides access to
Database Center tools that help you review fleet health, audit
inventory, and check for security issues.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/database-center/docs/use-database-center-mcp">Use the Database Center remote MCP server</a> and the
<a href="https://docs.cloud.google.com/database-center/docs/reference/mcp">Database Center MCP tools reference</a>.</p>
<h3>Feature</h3>
<p>Database Center fleet insights are available in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.
Fleet insights highlight inventory and performance insights
generated by Gemini. You can use these insights to identify and
understand specific issues in your database fleet.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/database-center/docs/performance#fleet-performance-insights">View the performance of your database fleet</a> and <a href="https://docs.cloud.google.com/database-center/docs/view-inventory#fleet-inventory-insights">View your fleet inventory</a>.</p>
<h3>Feature</h3>
<p>Database Center dashboard reporting is available in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.
You can configure daily, weekly, and monthly reports that summarize your fleet
inventory and health.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/database-center/docs/report">Create reports for your dashboard views</a>.</p>
<h3>Feature</h3>
<p>Database Center can monitor BigQuery resources. The resources
table shows the following for a BigQuery database:</p>
<ul>
<li><p>Datasets for a BigQuery database. For more
information, see <a href="https://docs.cloud.google.com/bigquery/docs/datasets-intro">Introduction to datasets</a>.</p></li>
<li><p>The number of reservations, which reserve resources, to process
queries.</p></li>
</ul>
<p>This feature is in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>Database Center lets you monitor active queries across your
fleet to identify and analyze query issues, such as slow queries. This feature
supports AlloyDB for PostgreSQL and Cloud SQL database products.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/database-center/docs/performance">View the performance of your database fleet</a>.</p>
<h3>Feature</h3>
<p>Monitoring the inventory, metrics, and alerts for Oracle Database@Google Cloud
databases using Database Center is
<a href="https://cloud.google.com/products/#product-launch-stages">generally available</a>
(GA). For more information, see
<a href="https://docs.cloud.google.com/database-center/docs/database-health-issues#supported-health-issues">Supported health issues</a>.</p>
<h2 class="release-note-product-title">Dataform</h2>
<h3>Announcement</h3>
<p>Cloud Composer is now called Managed Service for Apache Airflow. The names for
associated APIs, client libraries, CLI commands, and Identity and Access
Management (IAM) resources remain unchanged. For more information, see
<a href="https://docs.cloud.google.com/composer/docs/composer-2/composer-overview">Managed Airflow overview</a>.</p>
<h3>Announcement</h3>
<p>Dataplex Universal Catalog is now called Knowledge Catalog. The API, client
library, CLI, and Identity and Access Management (IAM) resources remain unchanged.
For more information, see
<a href="https://docs.cloud.google.com/dataplex/docs/introduction">Knowledge Catalog overview</a>.</p>
<h3>Announcement</h3>
<p>Vertex AI is now called Gemini Enterprise Agent Platform. The names for
associated APIs, client libraries, CLI commands, and Identity and Access
Management (IAM) resources remain unchanged. For more information, see
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/overview">Agent Platform overview</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Mobile SDK for iOS version 2.15.2 patch</strong></p>
<p>This patch updates the following for the mobile SDK for iOS:</p>
<ul>
<li>Fixed an issue with the mobile SDK on iOS 26 where the chat text field was
partially obscured because it appeared too low on the screen.</li>
</ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Announcement</h3>
<p>BigLake is now called <a href="https://docs.cloud.google.com/biglake/docs/introduction">Google Cloud Lakehouse</a>. BigLake metastore is now called the
<a href="https://docs.cloud.google.com/biglake/docs/about-blms">Lakehouse runtime catalog</a>.
The names for associated APIs, client libraries, CLI commands, and Identity and
Access Management (IAM) remain unchanged and still reference BigLake.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 23, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_23_2026</id>
    <updated>2026-04-23T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_23_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Anti Money Laundering AI</h2>
<h3>Fixed</h3>
<p>Fixed a validation error for engine versions <code>aml-commercial.default.v004.009.202603-000</code> and <code>aml-commercial.default.v004.010.202603-000</code> where the 500,000 party account limit was not correctly enforced.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Change</h3>
<p>An updated version of the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/odbc-jdbc-drivers#current_jdbc_driver">Simba JDBC driver for BigQuery</a>
is now available.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>You can use window functions with GoogleSQL in Bigtable to perform advanced
analytic operations over multiple table rows.
This feature is <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
For more information, see <a href="https://docs.cloud.google.com/bigtable/docs/reference/sql/window-functions">Window functions</a>.</p>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/monitoring/api/ref_v3_mcp/mcp">Cloud Monitoring API MCP server</a> is
generally available (GA). To learn about using the Monitoring MCP server
to let agents and AI applications interact with your metrics data, see
<a href="https://docs.cloud.google.com/monitoring/docs/use-monitoring-mcp">Use the Cloud Monitoring remote MCP server</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>The <code>cloudsql_session_read_only</code> session parameter provides a robust,
non-circumventable mechanism in Cloud SQL for PostgreSQL for preventing data
modification during a session. You can use this flag to either make a session
temporarily read-only, or make a session permanently, irreversibly
read-only.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/sql/docs/postgres/read-only-sessions">Create a read-only session in Cloud SQL for PostgreSQL</a>.</p>
<h3>Fixed</h3>
<p>Removed a <a href="https://docs.cloud.google.com/sql/docs/postgres/using-query-insights">query insights</a> limitation
for Cloud SQL Enterprise Plus edition and Cloud SQL Enterprise edition instances
that use PostgreSQL 18.</p>
<p>Instances using PostgreSQL maintenance version <code>20260319.00_RC02</code> or any
later version now store application tags when using query insights even if
a query has comment tags before the start of a SQL statement.</p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.32.1100-gke.84 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.32.1100-gke.84 runs on Kubernetes v1.32.13-gke.100.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Announcement</h3>
<p>The following features were added in 1.32.1100-gke.84:</p>
<ul>
<li>Added a periodic health check to detect stale mounts of Secrets and
ConfigMaps on pods. This helps identify rare scenarios where nodes serve
outdated secret data after a rotation, which can lead to authentication
failures. Currently enabled for GKE Identity Service pods, the check
runs on each node and compares the locally cached volume content with the
live data from the API server, reporting a mismatch only after a 5-minute
grace period to allow for normal update delays.</li></ul>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.32.1100-gke.84:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where node upgrades could hang indefinitely and bypass the
20-minute maintenance timeout. This issue occurred when a node contained
completed pods within a namespace that was in a <code>Terminating</code> state. Because
the Kubernetes Eviction API rejects operations in terminating namespaces, the
cluster controller entered an infinite retry loop. The fix updates the drain
process to skip eviction for pods in terminal phases, allowing the upgrade to
proceed normally.
</li>
<li>Fixed an issue where, during the machine initialization phase, the
<code>etcd-events</code> pod read the stale data directory when it started and attempted
to reuse the old member ID to rejoin the cluster instead of the new one.
Trying to use the old member ID to rejoin the cluster resulted in an
infinite retry loop and caused the cluster to reject the connection. The fix
ensures the <code>/var/lib/etcd-events</code> directory is
cleared upon failure, and adds retry logic to <code>kubeadm-reset</code> to improve
resiliency against transient API errors.
</li>
<li>Fixed an issue where concurrent tasks on the same node failed when <code>containerd</code>
restarts. After the fix, tasks are locked and run sequentially to ensure each
task completes successfully before the next begins. Each lock is held for up
to 20 minutes or until the task reaches success or failure.
To bypass this safety mechanismrun and run tasks concurrently, add the
following annotation to your cluster: <code>baremetal.cluster.gke.io/
concurrent-machine-update: "true"</code>.
</li>
<li>Fixed an issue on clusters running Kubernetes 1.31 and later where running
<code>kubeadm-reset</code> during an upgrade or reset could crash and enter an infinite
retry loop, blocking the operation. This occurred because the tool failed to
read cluster configuration on newer Kubernetes versions.</li></ul>
]]>
    </content>
  </entry>

  <entry>
    <title>April 22, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_22_2026</id>
    <updated>2026-04-22T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_22_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Agent Registry</h2>
<h3>Issue</h3>
<p>The following known issues affect Agent Registry:</p>
<ul>
<li><strong>Search location filtering:</strong> When calling the <code>SearchAgents</code> or <code>SearchMcpServers</code> APIs for the <code>global</code> location, the results might incorrectly include resources from <code>us</code> and <code>eu</code> multi-regions.</li>
<li><strong>URN mismatch:</strong> When searching for agents or MCP servers in the Google Cloud console, the page might display an invalid URN format in the search results list.</li>
<li><strong>Console error:</strong> Users who actively switch between tabs on the MCP server details page in the Google Cloud console might encounter an unexpected throttling error.</li></ul>
<h3>Announcement</h3>
<p>The Agent Registry remote Model Context Protocol (MCP) server is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. You can connect your AI applications to the Agent Registry MCP server to dynamically discover other agents, endpoints, and MCP servers available in your environment.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/agent-registry/use-agentregistry-mcp">Use the Agent Registry remote MCP server</a>.</p>
<h3>Announcement</h3>
<p>Agent Registry is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Agent Registry is a centralized catalog for discovering and registering agents and Model Context Protocol (MCP) servers.</p>
<p>For more information, see the <a href="https://docs.cloud.google.com/agent-registry/overview">Agent Registry overview</a>.</p>
<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/alloydb/docs/quick-start-migrations-guide">Database Migration Service quick-start migrations</a>
(in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>)
are now integrated into AlloyDB to provide a lightweight, continuous migration
flow. This feature automates setup for sources with private IPs in a VPC network,
including Cloud SQL for PostgreSQL and self-managed databases on Compute Engine.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/database-migration/docs/about-quick-start-migrations">Quick-start migrations overview</a>
in the Database Migration Service documentation.</p>
<h2 class="release-note-product-title">Application Design Center</h2>
<h3>Feature</h3>
<p>Application Design Center <a href="https://docs.cloud.google.com/application-design-center/docs/supported-resources">supports</a> the following components in <a href="https://docs.cloud.google.com/products#product-launch-stages">General Availability</a>:</p>
<ul>
<li>CA Service</li>
<li>Private Service Connect Endpoint</li>
<li>Private Service Connect Producer</li>
</ul>
<p>Application Design Center <a href="https://docs.cloud.google.com/application-design-center/docs/supported-resources">supports</a> the following components in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>:</p>
<ul>
<li>Authorization Extension</li>
<li>Authorization Policy</li>
<li>Authorization Policy Extension</li>
<li>Compute Address</li>
<li>Firebase AI Logic Prompt Template</li>
<li>Firebase Multi-Platform App</li>
<li>Routes</li>
<li>Agent Registry Agent</li>
<li>Agent Registry Binding</li>
<li>Agent Registry Endpoint</li>
<li>Agent Registry MCP Server</li>
<li>Firestore Security Rules</li>
<li>IAM Connector</li>
<li>Model Armor Floor Setting</li>
<li>Model Armor Template</li>
<li>VPC Network</li>
<li>Cloud Workflows</li>
<li>Firebase AI Logic</li>
<li>Firebase App Check</li>
<li>Firebase Authentication</li>
<li>Compute Firewall</li>
<li>Cloud KMS</li>
<li>Internal Load Balancer</li>
<li>Agent Registry Service</li>
<li>Artifact Registry</li>
<li>Cloud Run functions</li>
<li>Cloud Tasks</li>
<li>Managed Airflow</li>
<li>Cloud DNS Managed Zone</li>
<li>Cloud DNS Response Policy</li>
<li>Document AI</li>
<li>Cloud NAT</li>
<li>Cloud Router</li>
<li>Cloud Router Interface</li>
<li>Secure Web Proxy</li>
<li>Compute Instance</li>
<li>Cloud Scheduler</li>
<li>Agent Platform Runtime</li>
</ul>
<h3>Feature</h3>
<p>If your application deployment fails, you can troubleshoot and fix errors <a href="https://cloud.google.com/products#product-launch-stages">(Preview)</a>. For more information, see <a href="https://docs.cloud.google.com/application-design-center/docs/deploy-applications#troubleshoot">Troubleshoot and fix deployment issues</a>.</p>
<h3>Feature</h3>
<p>Create a composite template <a href="https://cloud.google.com/products#product-launch-stages">(Preview)</a> using multiple application templates and components. For more information, see <a href="https://docs.cloud.google.com/application-design-center/docs/design-composite-templates">Design composite templates</a>.</p>
<h3>Feature</h3>
<p>You can store templates and applications in the following regions:</p>
<ul>
<li>Tokyo, Japan (asia-northeast1)</li>
<li>Seoul, South Korea (asia-northeast3)</li>
<li>Taiwan (asia-east1)</li>
<li>Hong Kong (asia-east2)</li>
<li>Delhi, India (asia-south2)</li>
<li>Singapore (asia-southeast1)</li>
<li>Jakarta, Indonesia (asia-southeast2)</li>
<li>Melbourne, Australia (australia-southeast2)</li>
<li>Hamina, Finland (europe-north1)</li>
<li>Stockholm, Sweden (europe-north2)</li>
<li>Warsaw, Poland (europe-central2)</li>
<li>St. Ghislain, Belgium (europe-west1)</li>
<li>London, England (europe-west2)</li>
<li>Frankfurt, Germany (europe-west3)</li>
<li>Milan, Italy (europe-west8)</li>
<li>Paris, France (europe-west9)</li>
<li>Turin, Italy (europe-west12)</li>
<li>Eemshaven, Netherlands (europe-west4)</li>
<li>Zurich, Switzerland (europe-west6)</li>
<li>Madrid, Spain (europe-southwest1)</li>
<li>Columbus, Ohio (us-east5)</li>
<li>Ashburn, Virginia (us-east4)</li>
<li>The Dalles, Oregon (us-west1)</li>
<li>Los Angeles, California (us-west2)</li>
<li>Salt Lake City, Utah (us-west3)</li>
<li>Las Vegas, Nevada (us-west4)</li>
<li>Council Bluffs, Iowa (us-central1)</li>
<li>Dallas, Texas (us-south1)</li>
<li>Montréal, Canada (northamerica-northeast1)</li>
<li>Toronto, Canada (northamerica-northeast2)</li>
<li>Queretaro, Mexico (northamerica-south1)</li>
<li>São Paulo, Brazil (southamerica-east1)</li>
<li>Santiago, Chile (southamerica-west1)</li>
<li>Johannesburg, South Africa (africa-south1)</li>
<li>Doha, Qatar (me-central1)</li>
<li>Tel Aviv, Israel (me-west1)</li>
<li>Global</li>
</ul>
<p>For more information, see the following:</p>
<ul>
<li>A list of available <a href="https://docs.cloud.google.com/application-design-center/docs/locations">App Design Center locations</a>.</li>
<li>To select and manage a region, see <a href="https://docs.cloud.google.com/application-design-center/docs/manage-spaces#select-region">Select a region</a>.</li>
<li>To share a catalog between spaces, see <a href="https://docs.cloud.google.com/application-design-center/docs/manage-catalogs#share-a-catalog-with-a-space">share a catalog</a>.</li>
</ul>
<h3>Feature</h3>
<p>Use the following Google-provided application templates:</p>
<ul>
<li><a href="https://docs.cloud.google.com/application-design-center/docs/single-region-gke">Single region GKE cluster and workload</a> <a href="https://cloud.google.com/products#product-launch-stages">(Preview)</a></li>
<li><a href="https://docs.cloud.google.com/application-design-center/docs/enterprise-grade-production-gke">Enterprise-grade production GKE cluster and workload</a> <a href="https://cloud.google.com/products#product-launch-stages">(Preview)</a></li>
<li><a href="https://docs.cloud.google.com/application-design-center/docs/ai-pretrained-inference-gke-cluster-workload">AI Pre-trained Inference GKE cluster and workload</a> <a href="https://cloud.google.com/products#product-launch-stages">(Preview)</a></li>
</ul>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can now use the <a href="https://docs.cloud.google.com/bigquery/docs/graph-modeler">visual graph modeler</a> in
BigQuery Studio to define BigQuery graph nodes and edges from your
BigQuery tables and edit graph schema. This
feature is available in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Announcement</h3>
<p>Dataproc is now called <a href="https://docs.cloud.google.com/dataproc/docs/concepts/overview">Managed Service for Apache Spark</a>. The names for associated API, client
library, CLI, and Identity and Access Management (IAM) resources remain unchanged.</p>
<h3>Announcement</h3>
<p>BigLake is now called <a href="https://docs.cloud.google.com/biglake/docs/introduction">Google Cloud Lakehouse</a>.
BigLake metastore is now called the <a href="https://docs.cloud.google.com/biglake/docs/about-blms">Lakehouse runtime
catalog</a>. The names for associated APIs, client
libraries, CLI commands, and Identity and Access Management (IAM) remain
unchanged and still reference BigLake.</p>
<h3>Announcement</h3>
<p>Dataplex Universal Catalog is now called <a href="https://docs.cloud.google.com/dataplex/docs/introduction">Knowledge
Catalog</a>. The API, client library, CLI, and
Identity and Access Management (IAM) names remain unchanged. For more
information, see <a href="https://docs.cloud.google.com/dataplex/docs/introduction">Knowledge Catalog overview</a>.</p>
<h3>Announcement</h3>
<p>Looker Studio is now called <a href="https://docs.cloud.google.com/data-studio">Data Studio</a>.
The website and endpoint change from <code>lookerstudio.google.com</code> to
<code>datastudio.google.com</code>. You do not need to update your reports for this change,
as Data Studio automatically redirects to the new domain. However,
if your company uses proxies to restrict access to external sites, your IT
administrator needs to add the new domain to your access control list (ACL).
The names for associated API, client library, CLI, and Identity and Access
Management (IAM) resources remain unchanged. For more information, see <a href="https://cloud.google.com/blog/products/data-analytics/looker-studio-is-data-studio">Data Studio returns as new home for Data Cloud
assets</a>.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/graph-overview">BigQuery graphs</a> now support the following
features:</p>
<ul>
<li>You can <a href="https://docs.cloud.google.com/bigquery/docs/conversational-analytics#graphs">query graphs</a> using
natural language in Conversational Analytics.</li>
<li>You can add
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/graph-schema-statements#element_table_property_definition">descriptions and synonyms</a> to the labels and properties in your graphs.</li>
<li>For some types of graphs you can
<a href="https://docs.cloud.google.com/bigquery/docs/graph-measures">define measures</a>, which lock an aggregation
to a key to help you perform complex aggregations without overcounting. To
query measures, you transform your graph into a flattened table by using the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/graph-sql-queries#graph_expand"><code>GRAPH_EXPAND</code> TVF</a>,
and then query measures in that table with the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/aggregate_functions#agg"><code>AGG</code> function</a>.</li>
</ul>
<p>These features are in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>You can now <a href="https://docs.cloud.google.com/bigquery/docs/data-engineering-agent-pipelines">use the Data Engineering Agent</a>
to build, modify, and troubleshoot data pipelines in BigQuery. This feature is
<a href="https://cloud.google.com/products/#product-launch-stages">generally available</a> (GA).</p>
<h3>Feature</h3>
<p>You can now use the <code>gemini-embedding-2-preview</code> model in the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-embed"><code>AI.EMBED</code></a>,
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-similarity"><code>AI.SIMILARITY</code></a>,
and
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-generate-embedding"><code>AI.GENERATE_EMBEDDING</code></a>
functions to generate a single embedding from a combination of input types,
including text, image, audio, video, and PDF files.
This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>The Bigtable editions feature is <a href="https://cloud.google.com/products#product-launch-stages">generally available
(GA)</a>. Bigtable
editions introduces advanced features in performance, analytic query capability,
and resource management. You can choose between the Enterprise and Enterprise
Plus edition to select the right capabilities for your workloads. For more
information, see <a href="https://docs.cloud.google.com/bigtable/docs/editions-overview">Editions overview</a>.</p>
<h3>Feature</h3>
<p>Bigtable provides an in-memory tier as part of its hybrid storage
architecture. This tier provides sub-millisecond read latency and high
throughput for time-sensitive data with independent vertical scaling to handle
traffic surges. The in-memory tier is available only in the Enterprise Plus
<a href="https://docs.cloud.google.com/bigtable/docs/editions-overview">edition</a> in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. For more
information, see <a href="https://docs.cloud.google.com/bigtable/docs/in-memory-overview">In-memory tier overview</a>.</p>
<h3>Feature</h3>
<p>Bigtable <a href="https://docs.cloud.google.com/bigtable/docs/tiered-storage">tiered storage</a> limit increases from
32 TB to 64 TB per node. This expansion provides higher storage
density to support retention of larger volumes of infrequently accessed data and
is available only in the Enterprise Plus <a href="https://docs.cloud.google.com/bigtable/docs/editions-overview">edition</a>.
Tiered storage is available in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>As part of Bigtable <a href="https://docs.cloud.google.com/bigtable/docs/editions-overview">editions</a>, you can use
<a href="https://docs.cloud.google.com/bigtable/docs/data-boost-overview">Data Boost</a> to read data from tiered
storage and HDD clusters. This feature is available only in the Enterprise Plus
edition and is <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.</p>
<h3>Feature</h3>
<p>As part of Bigtable <a href="https://docs.cloud.google.com/bigtable/docs/editions-overview">editions</a>, you can use
<a href="https://docs.cloud.google.com/bigtable/docs/data-boost-overview">Data Boost</a> to run GoogleSQL queries. This
feature is available only in the Enterprise Plus edition and is
<a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
For more information, see <a href="https://docs.cloud.google.com/bigtable/docs/googlesql-examples#data-boost-analysis">High-throughput SQL analysis with Data Boost</a>.</p>
<h3>Feature</h3>
<p>As part of Bigtable <a href="https://docs.cloud.google.com/bigtable/docs/editions-overview">editions</a>, you can
configure which cluster in a replicated instance is used for automated backups.
This feature provides greater cost control and backup resource management. This
feature is available only in the Enterprise Plus edition and is
<a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
For more information, see <a href="https://docs.cloud.google.com/bigtable/docs/backups">Bigtable backups overview</a>.</p>
<h2 class="release-note-product-title">Cloud Composer</h2>
<h3>Feature</h3>
<p>Managed Service for Apache Airflow supports Gemini Cloud Assist Investigations
capabilities. The new troubleshooting agent can now troubleshoot failed Airflow
task instances and DAG runs. The feature is available through
Gemini Cloud Assist Investigations, which is currently accessible in
Private Preview.</p>
<h2 class="release-note-product-title">Cloud Database Migration Service</h2>
<h3>Feature</h3>
<p>You can now use
<a href="https://docs.cloud.google.com/database-migration/docs/about-quick-start-migrations" track-metadata-position="releaseNotes" track-metadata-srcpg="docs/release-notes" track-name="dms_cor_about_qs_migrations" track-type="releaseNoteLink">
quick-start migrations for homogeneous PostgreSQL migrations</a> to
Cloud SQL for PostgreSQL and AlloyDB for PostgreSQL.</p>
<p>Quick-start migrations are a lightweight continuous migration flow where Database Migration Service
can automatically set up everything you need to migrate sources that have a
private IP assigned in a VPC network, such as self-managed databases
on Compute Engine or Cloud SQL for PostgreSQL instances.
This feature is in
<a href="https://cloud.google.com/products#product-launch-stages" track-metadata-position="releaseNotes" track-metadata-srcpg="docs/release-notes" track-name="cloud_launch_stage_preview" track-type="releaseNoteLink">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Hub</h2>
<h3>Feature</h3>
<p>Cost optimization with Gemini Cloud Assist provides the following
additional features:</p>
<ul>
<li>In the Gemini Cloud Assist chat panel, get an explanation for
cost changes for supported resources.</li>
<li>On the Optimization page in Cloud Hub, get insights about recent
cost changes and related changes in resource usage.</li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/hub/docs/optimize-gemini">Optimize costs with Gemini assistance</a>.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/hub/docs/app-topology">App Topology </a> is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.
App Topology lets you query data about your resources and applications
from multiple sources, and then view the correlated data as a topology graph.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>Policy profiles in authorization policies let you define the type of
authorization being performed at the load balancer. This feature is
available in <strong>Preview</strong>.</p>
<p>You can choose from the following profile types:</p>
<ul>
<li><p>Request authorization profile (<code>REQUEST_AUTHZ</code>): Evaluates access based on
HTTP request headers. Authorization decisions can be made directly or
delegated to custom services. This is the default profile.</p></li>
<li><p>Content authorization profile (<code>CONTENT_AUTHZ</code>): Enables deep inspection of
application payloads (headers, body, and trailers). This is used for
content-based security, such as blocking prompt injection attacks and
preventing sensitive data leaks. Authorization decisions are always delegated.</p></li>
</ul>
<p>Policy profiles are supported for the following Google Cloud services:</p>
<ul>
<li>Regional external Application Load Balancers</li>
<li>Regional internal Application Load Balancers</li>
<li>Agent Gateway (<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>)</li>
<li>Secure Web Proxy</li>
</ul>
<p>To learn more about policy profiles, see  <a href="https://docs.cloud.google.com/load-balancing/docs/auth-policy/auth-policy-overview">Authorization policy overview</a>.</p>
<h2 class="release-note-product-title">Cloud Logging</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/logging/docs/reference/v2_mcp/mcp">Cloud Logging API MCP server</a> is
generally available (GA). To learn about using the Logging MCP server
to let agents and AI applications interact with your log entries, see
<a href="https://docs.cloud.google.com/logging/docs/use-logging-mcp">Use the Cloud Logging remote MCP server</a>.</p>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Feature</h3>
<p>Application Monitoring in Google Cloud provides both agent observability and
application observability. Your Application Monitoring dashboards display
performance metrics, including the error rates and token usage of your
AI resources. Those metrics can help you understand the health and performance
of your AI resources.</p>
<p>To learn more, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/agent-observability">Agent observability</a></li>
<li><a href="https://docs.cloud.google.com/monitoring/docs/about-application-monitoring">Application Monitoring overview</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/application-monitoring">Investigate applications, services, and workloads</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/application-monitoring-ai-resources">View AI resources</a></li>
</ul>
<h2 class="release-note-product-title">Cloud Number Registry</h2>
<h3>Announcement</h3>
<p><strong>Preview</strong>: <a href="https://docs.cloud.google.com/number-registry/overview">Cloud Number Registry</a>
provides IP address management (IPAM) capabilities to let you view, manage, and
plan your IP address usage in Google Cloud.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/sql/docs/postgres/quick-start-migrations-guide">Database Migration Service quick-start migrations</a>
are now integrated into Cloud SQL for PostgreSQL to provide a lightweight, continuous migration
flow. This feature automates setup for sources with private IPs in a VPC network,
including Cloud SQL for PostgreSQL instances and self-managed databases on Compute Engine.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/database-migration/docs/about-quick-start-migrations">Quick-start migrations overview</a>
in the Database Migration Service documentation.
This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: The G4 accelerator-optimized machine series now
supports the creation of virtual machine (VM) instances with less than one GPU
attached (fractional GPUs). When you create VM instances with fractional GPUs,
you can select 1/2, 1/4, or 1/8 of a G4 GPU. Fractional GPUs let you optimize
costs for workloads that don't require the resources of a full GPU.</p>
<p>For more information, see the
<a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-series">G4 machine series</a>
overview.</p>
<h2 class="release-note-product-title">Config Connector</h2>
<h3>Announcement</h3>
<p>Config Connector version 1.148.0 is now available.</p>
<h3>Feature</h3>
<p>New Alpha Resources (Direct Reconciler):</p>
<ul>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/parametermanager/parametermanagerparameterversion"><code>ParameterManagerParameterVersion</code></a>
<ul>
<li>Configure <a href="https://cloud.google.com/secret-manager/docs/parameter-manager">Parameter Manager parameter versions</a> which lets you manage regional parameters.</li>
</ul></li>
</ul>
<h3>Feature</h3>
<p>New features:</p>
<ul>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/6919">#6919</a>: <code>MultiClusterLeaseSpec</code> now supports integration with a syncer for KRM objects. This helps Config Connector take ownership of resources with service generated IDs.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/7202">#7202</a>: <code>kompanion</code>: Added a Model Context Protocol (MCP) server to the <code>kompanion</code> tool to enable AI IDEs and assistants to interact with Config Connector resources.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/7075">#7075</a>: <code>Config Connector controllers</code>: Added a <code>--skip-name-validation</code> flag to bypass duplicate controller name checks during registration, facilitating integration tests and multi-manager scenarios.</li>
</ul>
<h3>Fixed</h3>
<p>Bug Fixes:</p>
<ul>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/7145">#7145</a>: <code>SQLInstance</code>: Fixed an issue where <code>settings.dataCacheConfig</code> was incorrectly detected as different when <code>dataCacheEnabled</code> was <code>false</code>.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/7200">#7200</a>: <code>SQLInstance</code>: Updated matching functions to treat nil values in KRM as equivalent to empty or default objects in Google Cloud, preventing unnecessary re-reconciliation loops.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/6943">#6943</a>: <code>TagKey/TagValue</code>: Handle <code>ALREADY_EXISTS</code> error in TagKey and TagValue controllers by acquiring the existing resource.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/6774">#6774</a>: <code>BigQueryAnalyticsHubDataExchange</code>: Added structured reporting diff to improve visibility into resource changes and fixed reconciliation logic errors.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/7115">#7115</a>: <code>CloudBuildTrigger</code>: Restored missing descriptions in the CRD.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/6693">#6693</a>: <code>RunService</code>: Fixed a typo in environment variable values in samples and test fixtures.</li>
</ul>
<h3>Feature</h3>
<p>Documentation:</p>
<ul>
<li>Added <a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/blob/master/docs/features/controller-configuration.md">a guide for controller configuration</a>, detailing Direct, Terraform, and DCL controllers, including precedence rules and overrides.</li>
<li>Added <a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/blob/master/docs/features/containerresource.md">a guide for enabling VerticalPodAutoscaler (VPA) for Config Connector Pods</a> using <code>ControllerResource</code> and <code>NamespacedControllerResource</code>.</li>
<li>Added <a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/blob/master/docs/cli/README.md">a guide for the <code>config-connector</code> CLI and specifically for the <code>preview</code> command.</a>.</li>
</ul>
<h2 class="release-note-product-title">Dataflow</h2>
<h3>Feature</h3>
<p>Dataflow job builder now supports external Iceberg REST Catalogs as a
source. You can now ingest data from external Apache Iceberg REST catalogs (IRC)
directly into Lakehouse for Apache Iceberg tables using Dataflow's job
builder UI without writing code. For more information, see <a href="https://docs.cloud.google.com/dataflow/docs/guides/iceberg-df-lakehouse-integration">Import data from
external Iceberg catalogs to Lakehouse using
Dataflow</a>.</p>
<h2 class="release-note-product-title">Eventarc</h2>
<h3>Feature</h3>
<p>Eventarc support for
<a href="https://docs.cloud.google.com/eventarc/standard/docs/event-providers-targets#triggers">creating triggers</a>
for <a href="https://docs.cloud.google.com/eventarc/docs/reference/supported-events#gemini-cloud-assist-preview">direct events from Gemini Cloud Assist</a>
is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code_3">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Cloud Assist</h2>
<h3>Feature</h3>
<h3 id="model_context_protocol_support">Model Context Protocol support</h3>
<p>MCP support is available in Private Preview. To request access, contact your
Google Cloud account team. You can interact with Gemini Cloud Assist agents from
various surfaces, including third-party client agents and IDEs, using the Model
Context Protocol (MCP). For more information, see
<a href="https://docs.cloud.google.com/cloud-assist/configure-mcp">Integrating with MCP</a>.</p>
<h3>Feature</h3>
<h3 id="proactive_agents_for_issue_investigation">Proactive agents for issue investigation</h3>
<p>Proactive agents are available in Private Preview to Premium Support customers.
Enable Gemini Cloud Assist to autonomously investigate issues triggered by Cloud
Alerting policies or cost anomalies in the background. These investigations
don't modify or make any changes to your environment. Results and insights, such
as root cause analysis for alerts or cost spike drivers, are delivered via
Eventarc. You can view these results in the Google Cloud console. This feature requires
administrator enablement and configuration of an agent identity. For more
information, see <a href="https://docs.cloud.google.com/cloud-assist/proactive-agents-setup">Configure proactive agents</a>.</p>
<h3>Feature</h3>
<h3 id="page_context_awareness">Page context awareness</h3>
<p>Page context awareness is available in Public Preview. Gemini Cloud Assist
automatically uses the context of the content currently visible on your
Google Cloud console page to provide more relevant and accurate responses to your
prompts. For more information, see
<a href="https://docs.cloud.google.com/cloud-assist/chat-panel#page-context-sharing">Manage page context sharing</a>.</p>
<h3>Feature</h3>
<h3 id="enhanced_agent_administration_controls">Enhanced agent administration controls</h3>
<p><a href="https://docs.cloud.google.com/cloud-assist/admin-settings">Enhanced agent administration controls</a> are available in Public Preview.
Administrators have the following options in the Cloud Assist settings panel:</p>
<ul>
<li><strong>Web grounding settings:</strong> Choose how Gemini Cloud Assist uses Google Search to
ground its responses, with options for either the most comprehensive results
or stricter data residency compliance. For more information, see
<a href="https://docs.cloud.google.com/cloud-assist/configure-grounding">Configure web grounding</a>.</li>
<li><strong>Custom instructions:</strong> Define persistent system instructions to customize the
agent's persona, response formatting, and awareness of organizational
standards or business context for all users within the project. For more
information, see <a href="https://docs.cloud.google.com/cloud-assist/custom-instructions">Set custom instructions</a>.</li>
</ul>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Change</h3>
<h3 id="initial_release_of_gemini_enterprise_agent_platform">Initial release of Gemini Enterprise Agent Platform</h3>
<p>This initial release includes (but is not limited to) the following releases or
changes:</p>
<ul>
<li><span background="google-yellow" class="devsite-label">Change</span> <strong>Vertex
AI</strong> is now part of Gemini Enterprise Agent Platform. Information on model
support for Vertex AI is now under <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/overview">Gemini Enterprise Agent Platform &gt;
Models</a>.</li>
<li><span background="google-yellow" class="devsite-label">Change</span> <strong>Agent
Builder</strong> is now part of Gemini Enterprise Agent Platform. Features have
been renamed as follows:
<ul>
<li><strong>Agent Engine</strong> is now <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/runtime"><strong>Agent Runtime</strong></a>.</li>
<li><strong>Agent Builder Sessions</strong> is <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sessions"><strong>Agent Platform Sessions</strong></a>.</li>
<li><strong>Memory Bank</strong> is now <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/memory-bank"><strong>Agent Platform Memory Bank</strong></a>.</li>
</ul></li>
<li><span background="google-yellow" class="devsite-label">Change</span> <strong>Agent
Runtime</strong> now supports long-running operations (up to 7 days).</li>
<li><span background="google-yellow" class="devsite-label">Change</span> <strong>Agent
Runtime</strong> now supports sub-second cold starts.</li>
<li><span background="google-yellow" class="devsite-label">Change</span>
Provisioning for <strong>Agent Runtime</strong> has been reduced to less than 1 minute.</li>
<li><span class="devsite-label">Release</span> You can now use your own
<a href="gemini-enterprise-agent-platform/build/runtime/setup#byoc">custom-built
containers</a> when
you deploy agents with <strong>Agent Runtime</strong>.</li>
<li><span background="google-yellow" class="devsite-label">Change</span> When
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sessions/manage-with-api">creating a
Session</a>,
you can specify your own session ID.</li>
<li><span class="devsite-label">Release</span> Memory Bank now enables
continuous event streaming with automated memory generation triggered by
configurable criteria like event count or idle time. For more information,
see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/memory-bank/ingest-events">Ingest
events</a>.</li>
<li><span class="devsite-label">Release</span> Memory Bank now automatically
maintains an immutable version history of memories through revision
resources. For more information, see <a href="gemini-enterprise-agent-platform/scale/memory-bank/revisions">Memory
revisions</a>.</li>
<li><span class="devsite-label">Release</span> <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/agent-identity-overview"><strong>Agent
Identity</strong></a>
for General Availability. Agent Identity helps let your agent securely
authenticate to MCP servers, cloud resources, endpoints, and other agents,
either acting as itself or acting on behalf of the end user.</li>
<li><span class="devsite-label">Release</span> <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/gateways/agent-gateway-overview"><strong>Agent Gateway</strong></a>
for Private Preview. Agent Gateway is the networking component of the Gemini
Enterprise Agent Platform ecosystem. It secures and governs connectivity for
all agentic interactions, whether they occur between users and agents,
agents and tools, or among agents themselves.</li>
<li><span class="devsite-label">Release</span> <a href="https://docs.cloud.google.com/agent-registry/overview"><strong>Agent
Registry</strong></a> for Public Preview. Agent Registry is
a centralized, unified catalog that lets you store, discover, and govern
Model Context Protocol (MCP) servers, tools, and AI agents within Google
Cloud.</li>
<li><span class="devsite-label">Release</span> New <a href="gemini-enterprise-agent-platform/govern/policies/overview"><strong>IAM governance
policies</strong></a> are
available in Private Preview.</li>
<li><span class="devsite-label">Release</span> <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/optimize/observability/overview"><strong>Agent
Observability</strong></a>
for Preview. Agent Observability in Gemini Enterprise Agent Platform
provides comprehensive visibility into the performance, behavior, and health
of your deployed agents and Model Context Protocol (MCP) servers. By
monitoring key metrics, tracing execution paths, and observing your
multi-agent system as a whole, you can diagnose issues, optimize resource
consumption, and improve the reliability of your agents.</li>
<li><span class="devsite-label">Release</span> <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/embedding-2"><strong>Gemini Embedding
2</strong></a>
(<code>gemini-embedding-2</code>) for General Availability.</li>
<li><span class="devsite-label">Release</span> The <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/agents/deep-research"><strong>Gemini Deep Research
Agent</strong></a>, a
pre-built agent designed to help you plan, execute, and synthesize
multi-step research tasks. It uses Gemini 3.1 Pro to bridge the gap between
public web data and private enterprise context by simultaneously grounding
research across three distinct, high-fidelity data streams.</li>
<li><span class="devsite-label">Release</span> <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/reference/use-agent-platform-mcp"><strong>Agent Platform remote MCP
server</strong></a>
for General Availability. Support for Model Context Protocol (MCP) use is
available for Agent Platform.</li>
<li><span background="google-yellow" class="devsite-label">Change</span>
<strong>Google Cloud console navigation</strong>: The navigation menus under Agent
Platform (formerly Vertex AI) and Data Analytics have been updated to
centralize agentic products and features. Bookmarked links will continue to
work via automatic redirects.</li>
</ul>
<h3>Change</h3>
<h3 id="vertex_ai_to_gemini_enterprise_agent_platform_naming_changes">Vertex AI to Gemini Enterprise Agent Platform naming changes</h3>
<p>The table below lists all of the features that have been transitioned from Vertex AI and what their new names are in Agent Platform.</p>
<div>
<devsite-expandable>
<h4 class="showalways">Click to expand naming changes list</h4>
<table>
<thead>
<tr>
<th>Vertex AI name</th>
<th>Agent Platform name</th>
</tr>
</thead>
<tbody>
<tr>
<td>Vertex AI Platform</td>
<td>Agent Platform</td>
</tr>
<tr>
<td>Generative AI on Vertex AI</td>
<td>Generative AI</td>
</tr>
<tr>
<td>Vertex AI Studio</td>
<td>Agent Studio</td>
</tr>
<tr>
<td>Vertex AI API</td>
<td>Agent Platform API</td>
</tr>
<tr>
<td>Vertex AI Model Garden</td>
<td>Model Garden</td>
</tr>
<tr>
<td>Vertex AI Models as a Service (MaaS)</td>
<td>MaaS</td>
</tr>
<tr>
<td>(Gemini/Veo) on Vertex AI</td>
<td>(Gemini/Veo) on Agent Platform</td>
</tr>
<tr>
<td>(Claude/Llama/DeepSeek/etc.) on Vertex AI</td>
<td>(Claude/Llama/DeepSeek/etc.), available on Agent Platform</td>
</tr>
<tr>
<td>Pre-trained APIs on Vertex AI</td>
<td>Pre-trained APIs on Agent Platform</td>
</tr>
<tr>
<td>(Provisioned Throughput/Pay-as-you-go/etc.) on Vertex AI</td>
<td>(Provisioned Throughput/Pay-as-you-go/etc.) on Agent Platform</td>
</tr>
<tr>
<td>Gemini Live API on Vertex AI</td>
<td>Gemini Live API on Agent Platform</td>
</tr>
<tr>
<td>Vertex AI Search</td>
<td>Agent Search</td>
</tr>
<tr>
<td>Vertex AI Search for Industry</td>
<td>Agent Search for Industry</td>
</tr>
<tr>
<td>Vertex AI Search for Commerce</td>
<td>Agent Search for Commerce</td>
</tr>
<tr>
<td>Recommendations from Vertex AI Search</td>
<td>Recommendations</td>
</tr>
<tr>
<td>Vertex AI Conversation</td>
<td>Agent Conversation</td>
</tr>
<tr>
<td>Vertex AI RAG Engine</td>
<td>RAG Engine</td>
</tr>
<tr>
<td>Vertex AI Vector Search</td>
<td>Vector Search</td>
</tr>
<tr>
<td>Vertex AI Vector Search 2.0</td>
<td>Agent Retrieval</td>
</tr>
<tr>
<td>Vertex AI Agent Engine</td>
<td>Agent Runtime</td>
</tr>
<tr>
<td>Vertex AI Studio App Builder</td>
<td>App Builder in Agent Studio</td>
</tr>
<tr>
<td>Vertex AI Agent Engine Memory Bank</td>
<td>Agent Platform Memory Bank</td>
</tr>
<tr>
<td>Vertex AI Agent Engine Sessions</td>
<td>Agent Platform Sessions</td>
</tr>
<tr>
<td>Vertex AI Agent Engine Code Execution</td>
<td>Agent Platform Code Execution</td>
</tr>
<tr>
<td>Grounding with Google [...] in Vertex AI</td>
<td>Grounding with Google [...] in Agent Platform</td>
</tr>
<tr>
<td>Grounding with Google [...] in Vertex AI Search</td>
<td>Grounding with Google [...] in Agent Search</td>
</tr>
<tr>
<td>Grounding with Google [...] in Vertex AI Studio</td>
<td>Grounding with Google [...] in Agent Studio</td>
</tr>
<tr>
<td>Vertex AI Training</td>
<td>Agent Platform Managed Training</td>
</tr>
<tr>
<td>Vertex AI Serverless Training</td>
<td>Agent Platform Serverless Training</td>
</tr>
<tr>
<td>Vertex AI Training Clusters (VTC)</td>
<td>Managed Training Clusters</td>
</tr>
<tr>
<td>Ray on Vertex AI</td>
<td>Ray on Agent Platform</td>
</tr>
<tr>
<td>Reinforcement Learning from Human Feedback (RLHF)/Reinforcement Learning (RL) on Vertex AI</td>
<td>Reinforcement Learning on Agent Platform</td>
</tr>
<tr>
<td>Vertex AI Neural Architecture Search</td>
<td>Neural Architecture Search on Agent Platform</td>
</tr>
<tr>
<td>Vertex AI Prediction/Vertex AI Inference</td>
<td>Agent Platform Inference</td>
</tr>
<tr>
<td>Vertex AI Vision</td>
<td>Agent Platform Vision</td>
</tr>
<tr>
<td>Vertex AI Batch Inference</td>
<td>Agent Platform Batch Inference</td>
</tr>
<tr>
<td>Vertex AI Online Inference</td>
<td>Agent Platform Online Inference</td>
</tr>
<tr>
<td>Vertex AI Endpoints</td>
<td>Agent Platform Endpoints</td>
</tr>
<tr>
<td>Vertex AI Forecasting/Forecasting with AutoML</td>
<td>Forecasting on Agent Platform</td>
</tr>
<tr>
<td>Vertex AI Pipelines</td>
<td>Agent Platform Pipelines</td>
</tr>
<tr>
<td>Vertex AI Notebooks</td>
<td>Agent Platform Notebooks</td>
</tr>
<tr>
<td>Vertex AI Colab Enterprise</td>
<td>Agent Platform Colab Enterprise</td>
</tr>
<tr>
<td>Vertex AI Workbench</td>
<td>Agent Platform Workbench</td>
</tr>
<tr>
<td>Vertex AI Workbench Instances</td>
<td>Agent Platform Workbench Instances</td>
</tr>
<tr>
<td>Vertex AI Feature Store</td>
<td>Agent Platform Feature Store</td>
</tr>
<tr>
<td>Vertex AI Model Registry</td>
<td>Agent Platform Model Registry</td>
</tr>
<tr>
<td>Vertex AI Model Evaluation</td>
<td>Agent Platform Model Evaluation</td>
</tr>
<tr>
<td>Gen AI evaluation service on Vertex AI</td>
<td>Gen AI evals</td>
</tr>
<tr>
<td>Vertex AI AutoML (Vision/Video/Tables)</td>
<td>Agent Platform AutoML</td>
</tr>
<tr>
<td>Data Labeling on Vertex AI</td>
<td>Data Labeling</td>
</tr>
<tr>
<td>Vertex AI on GDC</td>
<td>Agent Platform on GDC</td>
</tr>
<tr>
<td>Vertex AI Experiments</td>
<td>Experiments on Agent Platform</td>
</tr>
<tr>
<td>Vertex AI Model Monitoring</td>
<td>Model Monitoring on Agent Platform</td>
</tr>
<tr>
<td>Vertex AI Media Studio</td>
<td>Agent Media Studio</td>
</tr>
<tr>
<td>Vertex AI</td>
<td>Agent Platform</td>
</tr>
<tr>
<td>Vertex AI Generative AI</td>
<td>Agent Platform Generative AI</td>
</tr>
</tbody>
</table>
</devsite-expandable>
</div>
<h3>Issue</h3>
<p>The following known issues affect Gemini Enterprise Agent Platform:</p>
<ul>
<li><strong>Audio track extraction (Gemini Embedding 2 only):</strong> The <code>audio_track_extraction</code> feature does not work. For more information, see <a href="https://issuetracker.google.com/504505771">Issue #504505771</a>.</li></ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.33.700-gke.71 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.33.700-gke.71 runs on Kubernetes v1.33.5-gke.2200.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Announcement</h3>
<p>The following features were added in 1.33.700-gke.71:</p>
<p>A health check was added to detect when secrets or config maps mounted in pods become "stale," or out-of-sync with the Kubernetes API server. This feature addresses scenarios where the Kubelet's local cache fails to update with the latest versions of configuration data. The check performs the following actions:</p>
<ul>
<li>Iterates through all running pods on the node to verify their mounts.</li>
<li>Compares the local data in the Kubelet's atomic update symlink structure
against the live objects and update timestamps in the API server.</li>
<li>Uses a 5-minute threshold to prevent false positives caused by normal
propagation delays. A mismatch is only reported as an error if the staleness
persists for more than 5 minutes.</li>
</ul>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.33.700-gke.71:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where concurrent tasks on the same node failed when <code>containerd</code>
restarts. After the fix, tasks are locked and run sequentially to ensure each
task completes successfully before the next begins. Each lock is held for up
to 20 minutes or until the task reaches success or failure.
To bypass this safety mechanismrun and run tasks concurrently, add the
following annotation to your cluster: <code>baremetal.cluster.gke.io/concurrent-machine-update: "true"</code>.
</li>
<li>Fixed an issue where, during the machine initialization phase, the
<code>etcd-events</code> pod read the stale data directory when it started and attempted
to reuse the old member ID to rejoin the cluster instead of the new one.
Trying to use the old member ID to rejoin the cluster resulted in an
infinite retry loop and caused the cluster to reject the connection. The fix
ensures that the system clears the <code>/var/lib/etcd-events</code> directory upon
failure, and adds retry logic to <code>kubeadm-reset</code> to improve
resiliency against transient API errors.</li>
<li>Fixed an issue where node upgrades could hang indefinitely and bypass the
20-minute maintenance timeout. This issue occurred when a node contained
completed pods within a namespace that was in a <code>Terminating</code> state. Because
the Kubernetes Eviction API rejects operations in terminating namespaces, the
cluster controller entered an infinite retry loop. The fix updates the drain
process to skip eviction for pods in terminal phases, allowing the upgrade to
proceed normally.</li>
<li>Fixed an issue where Metrics API operations—including <code>kubectl top</code>,
Horizontal Pod Autoscaling, and Vertical Pod Autoscaling could
fail with TLS verification errors during certificate authority rotation. This
occurred because the leaf certificate was not immediately renewed when the
certificate authority was rotated, causing a temporary mismatch between the
trusted certificate authority bundle and the certificate presented by the
metrics server.</li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r16-version-updates">(2026-R16) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1362000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<p>There are no new releases in the Stable channel.</p>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1816000</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1362000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1816000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1362000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r16-security-updates">(2026-R16) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.30.14-gke.2407000</td>
<td>cos-117-18613-534-80</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-80_">cos-117-18613-534-80 release notes</a></td>
</tr>
<tr>
<td>1.32.13-gke.1362000</td>
<td>cos-117-18613-534-80</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-80_">cos-117-18613-534-80 release notes</a></td>
</tr>
<tr>
<td>1.33.11-gke.1013000</td>
<td>cos-121-18867-381-63</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-381-63_">cos-121-18867-381-63 release notes</a></td>
</tr>
<tr>
<td>1.34.6-gke.1307000</td>
<td>cos-125-19216-220-130</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-220-130_">cos-125-19216-220-130 release notes</a></td>
</tr>
<tr>
<td>1.35.3-gke.1522000</td>
<td>cos-125-19216-220-130</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-220-130_">cos-125-19216-220-130 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r16-version-updates">(2026-R16) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<p>There are no new releases in the Stable channel.</p>
<h3>Change</h3>
<h4 id="2026-r16-version-updates">(2026-R16) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1115000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1154000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1234000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r16-version-updates">(2026-R16) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1362000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r16-version-updates">(2026-R16) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1362000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1816000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1362000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1522000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r16-version-updates">(2026-R16) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2407000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1816000</a></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Deprecated</h3>
<p>Support for the legacy Google Security Operations SIEM infrastructure will end on April 30, 2027. After this date, you will no longer have access to your Google SecOps SIEM instance on the legacy infrastructure. You need to self-migrate Google Security Operations SIEM in legacy Infrastructure to Google Cloud to align with industry standards and improve your reliability, privacy, security, compliance, and granular access controls. Follow the <a href="https://docs.cloud.google.com/chronicle/docs/administration/migrate-legacy-siem-infra">Migration guide</a> and <a href="https://security.googlecloudcommunity.com/community-blog-42/elevate-your-defense-modernizing-google-secops-for-the-agentic-soc-7087">Community post</a> to begin your transition. </p>
<p>This migration applies to you <strong>only</strong> if your SIEM instance meets <strong>one of the conditions</strong> below:</p>
<ul>
<li>Not deployed in your Google Cloud Project</li>
<li>Not using Google Cloud Authentication (Workforce Identity Federation / Cloud Identity)</li>
<li>Not using Google Cloud IAM for Feature Role based access controls.</li>
</ul>
<p>This migration <strong>does not apply</strong> to you if your SIEM instance meets <strong>all the conditions</strong> below:</p>
<ul>
<li>Is deployed in your Google Cloud project</li>
<li>Uses Workforce Identity Federation or Cloud Identity for authentication</li>
<li>Uses Google Cloud IAM to manage granular access permissions</li>
</ul>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Feature</h3>
<p><strong>Netskope</strong>: Version 17.0</p>
<ul>
<li><p>The following new actions have been added:</p>
<ul>
<li><p><strong>Add Entities to URL List</strong></p></li>
<li><p><strong>Deploy URL List Changes</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Netskope</strong>: Version 17.0</p>
<ul>
<li><p>Added a new <code>Use V2 API</code> parameter to the following actions:</p>
<ul>
<li><p><strong>List Clients</strong></p></li>
<li><p><strong>List Quarantined Files</strong></p></li>
</ul></li>
<li><p><strong>Integration</strong>: Added support for V2 API endpoints and OAuth 2.0
authentication.</p></li>
</ul>
<h3>Change</h3>
<p><strong>Qualys VM</strong>: Version 26.0</p>
<ul>
<li><strong>Integration</strong>: Migrated to the latest Qualys API endpoints.</li>
</ul>
<h3>Change</h3>
<p><strong>SCC Enterprise</strong>: Version 21.0</p>
<ul>
<li><p>Updated ticket synchronization logic in the following job:</p>
<ul>
<li><strong>Sync SCC Jira Tickets</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>McAfee Mvision EDR</strong>: Version 12.0</p>
<ul>
<li><strong>Integration</strong>: Added support for configuring the <code>Login API Root</code> as a
customizable parameter.</li>
</ul>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Deprecated</h3>
<p>Support for the legacy Google Security Operations SIEM infrastructure will end on April 30, 2027. After this date, you will no longer have access to your Google SecOps SIEM instance on the legacy infrastructure. You need to self-migrate Google Security Operations SIEM in legacy Infrastructure to Google Cloud to align with industry standards and improve your reliability, privacy, security, compliance, and granular access controls. Follow the <a href="https://docs.cloud.google.com/chronicle/docs/administration/migrate-legacy-siem-infra">Migration guide</a> and <a href="https://security.googlecloudcommunity.com/community-blog-42/elevate-your-defense-modernizing-google-secops-for-the-agentic-soc-7087">Community post</a> to begin your transition. </p>
<p>This migration applies to you <strong>only</strong> if your SIEM instance meets <strong>one of the conditions</strong> below:</p>
<ul>
<li>Not deployed in your Google Cloud Project</li>
<li>Not using Google Cloud Authentication (Workforce Identity Federation / Cloud Identity)</li>
<li>Not using Google Cloud IAM for Feature Role based access controls.</li>
</ul>
<p>This migration <strong>does not apply</strong> to you if your SIEM instance meets <strong>all the conditions</strong> below:</p>
<ul>
<li>Is deployed in your Google Cloud project</li>
<li>Uses Workforce Identity Federation or Cloud Identity for authentication</li>
<li>Uses Google Cloud IAM to manage granular access permissions</li>
</ul>
<h2 class="release-note-product-title">Identity and Access Management</h2>
<h3>Feature</h3>
<p>Privileged Access Manager supports <a href="https://docs.cloud.google.com/iam/docs/principal-identifiers#v1">agent identities</a>
as grant requesters and approvers.</p>
<p>This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/iam/docs/pam-overview#supported-identities">Privileged Access Manager overview</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Identity auth manager</strong> is available in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.
You can use Agent Identity auth manager to help securely authenticate your agents
to third-party services using 3-legged OAuth, 2-legged OAuth, or API keys.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/iam/docs/agent-identity-overview#agent-auth-manager">Agent Identity auth manager</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Identity</strong> is generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>). Agent Identity provides a strongly
attested, cryptographic identity for each agent that is tied to the lifecycle of
the resource hosting the agent.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/iam/docs/agent-identity-overview">Agent Identity overview</a>.</p>
<h2 class="release-note-product-title">Migrate to Virtual Machines</h2>
<h3>Feature</h3>
<p>Migrate to Virtual Machines now lets you use regional disks for the target
virtual machine (VM) instance.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p>When Security Command Center is activated at the project level only, you can
<a href="https://docs.cloud.google.com/security-command-center/docs/vulnerability-assessment-google-cloud">enable Vulnerability Assessment for Google Cloud</a>
on the single project.</p>
<h3>Feature</h3>
<p>Security Command Center has new predefined rules and controls:</p>
<ul>
<li><p>Additional <a href="https://docs.cloud.google.com/security-command-center/docs/predefined-security-graph-rules">predefined security graph rules</a>
to support Agent Runtime</p></li>
<li><p>Additional support in <a href="https://docs.cloud.google.com/security-command-center/docs/correlated-threats-overview">existing correlated threats rules</a>
for Agent Runtime</p></li>
<li><p>Additional <a href="https://docs.cloud.google.com/security-command-center/docs/agent-platform-threat-detection-overview#runtime-detectors">runtime detectors in Agent Platform Threat Detection</a></p></li>
<li><p>Additional <a href="https://docs.cloud.google.com/security-command-center/docs/concepts-event-threat-detection-overview#rules">Event Threat Detection rules</a> to support AI agents</p></li></ul>
<h3>Feature</h3>
<p>Security Command Center findings that are related to AI security risks are available in the
<strong>Security</strong> tab of the
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern">Gemini Enterprise Agent Platform</a>.
The feature helps provide comprehensive visibility into findings, active
threats, and attack path simulations. This feature requires Security Command Center Premium
or Enterprise.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/view-security-findings">View security
findings</a>.</p>
<h2 class="release-note-product-title">VPC Service Controls</h2>
<h3>Feature</h3>
<p><a href="https://cloud.google.com/products#product-launch-stages">Preview stage</a> support
for the following integration:</p>
<ul>
<li><a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_app_topology">App Topology</a></li>
</ul>
<h3>Feature</h3>
<p><a href="https://cloud.google.com/products#product-launch-stages">Preview stage</a> support for the following integration:</p>
<ul>
<li><a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_agent_registry">Agent Registry</a></li>
</ul>
<h2 class="release-note-product-title">Vertex AI Search</h2>
<h3>Feature</h3>
<p><strong>Agent Search: MCP server (GA)</strong></p>
<p>Agent Search has a Model Context Protocol (MCP) server hosted at the
following endpoint: <code>https://discoveryengine.googleapis.com/mcp</code></p>
<p>This feature is generally available (GA). For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/reference/mcp">MCP Reference:
discoveryengine.googleapis.com</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Search: Dense reciprocal rank for custom ranking</strong></p>
<p>You can use the dense reciprocal rank transformation function, <code>drr</code>, to
customize search result ranking. It's an improvement on the reciprocal rank
function, <code>rr</code>. Using the dense reciprocal rank function leads to higher
quality ranking when there are duplicate signal values.</p>
<p>Duplicate signal values are more common when the ranking formula contains
the following types of signal:</p>
<ul>
<li>The <code>boosting_factor</code> signal</li>
<li>The <code>geo_distance()</code> function signal</li>
<li>Categorical and integer custom signals</li>
</ul>
<p>This feature is generally available (GA).
For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/custom-ranking">Customize search results
ranking</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Search: Geodistance function for custom ranking (GA)</strong></p>
<p>The <code>geo_distance</code> function can be used in custom ranking formulas to calculate
the distance between a source location and a destination location. The function
supports query locations extracted from natural language, explicitly provided
coordinates, and addresses.</p>
<p>This feature is generally available (GA).
For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/custom-ranking#geodistance">Custom ranking: Geodistance—a derived
signal</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Search: Filter searches by document-level relevance (GA)</strong></p>
<p>When searching in your Agent Search app, you can specify
document-level relevance filters so that only the documents that meet the
filter threshold are returned as results.</p>
<p>You can specify either the relevance threshold or semantic-relevance threshold
to filter documents by relevance based on keyword and semantic search
similarity.</p>
<p>This feature is Generally Available (GA). For more information, see
<a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/filter-by-relevance">Filter searches by document-level relevance</a>.</p>
<h3>Change</h3>
<p><strong>Agent Search: Renamed from Vertex AI Search</strong></p>
<p>The Vertex AI Search product has been renamed as Agent Search in the following
contexts:</p>
<ul>
<li>The documentation set. See <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/introduction">What is Agent
Search?</a></li>
</ul>
<p>What has not changed:</p>
<ul>
<li><p>The user interface in the Google Cloud console is still referred to as Vertex
AI Search and AI Applications. See <a href="https://console.cloud.google.com/gen-app-builder">Vertex AI
Search</a>.</p></li>
<li><p>The APIs still use the Discovery Engine API endpoints. See <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/apis">APIs and
reference</a>.</p></li>
</ul>
<p>Despite the rebrand, the product functionality remains the same.</p>
<h2 class="release-note-product-title">reCAPTCHA</h2>
<h3>Feature</h3>
<p>reCAPTCHA is part of Google Cloud Fraud Defense, a suite of security products designed to protect your websites and applications from fraud and abuse.
This change does not affect existing reCAPTCHA functionality. For more information, see <a href="https://cloud.google.com/security/products/fraud-defense">Google Cloud Fraud Defense</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 21, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_21_2026</id>
    <updated>2026-04-21T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_21_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>The integration between AlloyDB for PostgreSQL and Knowledge Catalog (in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>) is now enabled by default for all new AlloyDB clusters.</p>
<p>This integration provides a unified view of your metadata to simplify data governance and analysis. Recent enhancements feature near real-time synchronization, with updates reflecting in Knowledge Catalog within minutes, as well as expanded metadata details that now include Primary Keys and Foreign Keys.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/knowledge-catalog-integration">Integrate AlloyDB for PostgreSQL with Knowledge Catalog</a>.</p>
<h3>Feature</h3>
<p>You can now use the AlloyDB columnar engine to act as a read-optimized,
in-memory cache for HNSW indexes. This
increases the number of queries per second (QPS) that your database can handle
for vector search workloads. This feature is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/ai/accelerate-with-ce">Accelerate vector search with the
columnar engine</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can now <a href="https://docs.cloud.google.com/bigquery/docs/graph-visualization#visualization-results">visualize BigQuery graph query results and graph
schemas</a> directly in
BigQuery Studio, without the need of a notebook environment. This feature is in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Asset Inventory</h2>
<h3>Feature</h3>
<p>Cloud Asset Inventory now supports
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/mcp/tools_list/list_assets">listing assets</a>
over Model Context Protocol (MCP) (<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">Developer Connect</h2>
<h3>Feature</h3>
<p>You can now create an account connector <a href="https://docs.cloud.google.com/developer-connect/docs/configure-connectors#configure-custom-oauth">using a custom OAuth client</a>.</p>
<h3>Feature</h3>
<p>You can now use Git proxy with <a href="https://docs.cloud.google.com/developer-connect/docs/configure-connectors">account connectors</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: View agent identity (Preview)</strong></p>
<p>As a Gemini Enterprise administrator, you can view an agent's identity on the
Agent details page. This is typically the agent's SPIFFE ID.</p>
<p>This feature is in Public Preview. If the SPIFFE ID is not published by the
publisher, the Agent Registry resource ID is displayed as a fallback. For more
information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/agents-overview#agent-identity">Agent identity</a>.</p>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Register agents using A2UI and A2A with Gemini Enterprise (Preview)</strong></p>
<p>Gemini Enterprise administrators can register and manage agents using <a href="https://a2ui.org/introduction/what-is-a2ui/">Agent to
UI (A2UI)</a> to build custom
interfaces and the <a href="https://a2a-protocol.org/">Agent2Agent (A2A) Protocol</a> for
communication with Gemini Enterprise.</p>
<p>This feature is in Public Preview. For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/a2ui-agents/register-and-manage-an-a2ui-agent">Register and manage agents using A2UI and A2A</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/a2ui-agents/a2ui-component-gallery-reference">A2UI component gallery reference</a></li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>For clusters running GKE version 1.35.3-gke.1389000 or later,
you can now use the <code>c4a-highmem-96-metal</code>
(<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>) machine
type from the C4A machine series with the following features:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/autopilot-overview">Autopilot</a> mode</li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/node-auto-provisioning#cluster-level-enablement">Node auto-provisioning</a></li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/about-compute-classes">ComputeClasses</a>
that auto-create node pools</li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/cluster-autoscaler">Cluster autoscaling</a></li>
</ul>
<h3>Feature</h3>
<p>Starting in GKE version 1.35.2-gke.1842000, you can install
the Slurm Operator add-on for GKE (<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>).
This managed installation of the Slurm Operator allows you to enable Slurm
scheduling capabilities on any GKE cluster. The add-on provides
the foundation to build customized AI and HPC platforms, including CPU, GPU,
and TPU machines (covering specific scenarios). For more information, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/add-on/slurm-on-gke/concepts/overview">About Slurm on GKE</a>.</p>
<h2 class="release-note-product-title">Spanner</h2>
<h3>Feature</h3>
<p>Spanner full-text search supports
<a href="https://docs.cloud.google.com/spanner/docs/full-text-search/search-query-enhancement#custom-dictionaries">custom dictionaries</a>
to create custom synonym mappings. You can use custom dictionaries with the
<code>SEARCH</code>, <code>SCORE</code>, and <code>SNIPPET</code> functions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 20, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_20_2026</id>
    <updated>2026-04-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_20_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>You can now use the <a href="https://docs.cloud.google.com/alloydb/docs/reference/mcp/databaseinsights/mcp/index">Database Insights remote MCP server</a> to analyze AlloyDB's performance and system metrics. This feature is in <a href="https://cloud.google.com/products#product-launch-stages">GA</a>.</p>
<h3>Feature</h3>
<p>The AlloyDB remote MCP server—available through the global endpoint—is now generally
available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>)
and includes support for the following:</p>
<ul>
<li>Read-only execute SQL.</li>
<li>Tools to help you update your instance, export and import data, create a
backup, and restore your cluster.</li>
<li>Public IP.</li>
<li>Private Service Connect endpoint automation.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/ai/use-alloydb-mcp">Use the AlloyDB remote MCP server</a>.</p>
<h3>Issue</h3>
<p>ChatGPT users aren't able to list or use the AlloyDB toolset provided
by the AlloyDB remote MCP server.</p>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1161">v1.16.1</h3>
<p>On April 20, 2026 we released an updated version of the Apigee hybrid software, v1.16.1.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.1</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release_2">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>469900037</strong></td>
<td><strong>Apigee hybrid now supports <code>LLMTokenQuota</code> and <code>PromptTokenLimit</code> policies.</strong></td>
</tr>
<tr>
<td><strong>502577947</strong></td>
<td><strong>Enhanced the <code>ParsePayload</code> policy to support a broader set of Model Context Protocol (MCP) methods and implemented governance bypass for essential system-level methods.</strong></td>
</tr>
<tr>
<td><strong>503029410</strong></td>
<td><strong>Removed PII from <code>ParsePayload</code> policy outputs to improve security and privacy.</strong></td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>485998102, 482978613</strong></td>
<td><strong>Security fixes for <code>apigee-runtime</code>, <code>apigee-mart-server</code>, and <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21945">CVE-2026-21945</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21932">CVE-2026-21932</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2976">CVE-2023-2976</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48174">CVE-2022-48174</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1471">CVE-2022-1471</a> </li></ul></td>
</tr>
<tr>
<td><strong>471527485, 471173296, 471172082, 471171833</strong></td>
<td><strong>Security fixes for <code>apigee-synchronizer</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67735">CVE-2025-67735</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58057">CVE-2025-58057</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58056">CVE-2025-58056</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55163">CVE-2025-55163</a> </li></ul></td>
</tr>
<tr>
<td><strong>454672970</strong></td>
<td><strong>Security fix for <code>apigee-runtime</code>.</strong> <br/>This adds strict input validation to the <code>IntegrationRegion</code> parameter in the <code>SetIntegrationRequest</code> policy to prevent potential server-side request forgery (SSRF).</td>
</tr>
<tr>
<td><strong>493067053, 493061344, 492959383, 492957334, 492359443, 492358696, 492067139, 490280970, 489908390, 489907729, 489489437, 488070159, 485580973</strong></td>
<td><strong>Security fixes for <code>apigee-hybrid-cassandra</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66566">CVE-2025-66566</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4802">CVE-2025-4802</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12183">CVE-2025-12183</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6246">CVE-2023-6246</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5156">CVE-2023-5156</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4911">CVE-2023-4911</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0687">CVE-2023-0687</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3715">CVE-2022-3715</a> </li></ul></td>
</tr>
<tr>
<td><strong>494902472, 493902764, 493747531, 493747186, 493066364, 492956556, 492812098, 492810982, 492737291, 492733739, 492067214, 491191150, 490628133, 490627481, 490279890, 490278396, 489905507, 489904404, 477290192</strong></td>
<td><strong>Security fixes for <code>apigee-kube-rbac-proxy</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24051">CVE-2026-24051</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68119">CVE-2025-68119</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61728">CVE-2025-61728</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61724">CVE-2025-61724</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61723">CVE-2025-61723</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58186">CVE-2025-58186</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58185">CVE-2025-58185</a> </li></ul></td>
</tr>
<tr>
<td><strong>494874583, 493352686, 493350530, 493065065, 492958506, 492958221, 492810419, 492734198, 492360831, 491606491, 491602959, 490628958, 490628720, 490625335, 489487288, 477290192</strong></td>
<td><strong>Security fixes for <code>apigee-watcher</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61731">CVE-2025-61731</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61725">CVE-2025-61725</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61724">CVE-2025-61724</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58188">CVE-2025-58188</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58187">CVE-2025-58187</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47912">CVE-2025-47912</a> </li></ul></td>
</tr>
<tr>
<td><strong>493904046, 493748763, 493353749, 492959837, 492959353, 492958532, 492734063, 492358967, 491163162, 489907974, 489494841, 477290192</strong></td>
<td><strong>Security fixes for <code>apigee-operators</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27139">CVE-2026-27139</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61728">CVE-2025-61728</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58181">CVE-2025-58181</a> </li></ul></td>
</tr>
<tr>
<td><strong>493940049, 493935866, 492812693, 492811208, 490847438, 490285784, 443494822, 430609333, 428036268, 428035602</strong></td>
<td><strong>Security fixes for <code>apigee-fluent-bit</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22795">CVE-2026-22795</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69419">CVE-2025-69419</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69418">CVE-2025-69418</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5709">CVE-2018-5709</a> </li></ul></td>
</tr>
<tr>
<td><strong>494873893, 492957899, 492811896, 492735230, 492734621, 492362013, 492358145, 492044636, 491192904, 491163716, 490628292, 490283689, 489908590, 489487798, 485998102, 482978613</strong></td>
<td><strong>Security fixes for <code>apigee-open-telemetry-collector</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68156">CVE-2025-68156</a> </li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47913">CVE-2025-47913</a> </li></ul></td>
</tr>
<tr>
<td><strong>495206280, 492736206, 492358267, 491606961, 491603879, 490845184, 490842872, 490626346, 490625529, 490278258, 489155677</strong></td>
<td><strong>Security fixes for <code>apigee-udca</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>492959491, 492959470, 492959266, 492812323, 492736535, 492736355, 492736200, 492734720, 492549333, 492528258, 492528186, 492361814, 492360845, 492359742, 492359020, 492039084, 490625473, 489488025, 489120498</strong></td>
<td><strong>Security fixes for <code>apigee-prometheus-adapter</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25679">CVE-2026-25679</a> </li></ul></td>
</tr>
<tr>
<td><strong>492959323, 492958717, 492813153, 492736850, 492736096, 492735265, 492360419, 492359937, 492359237, 492041473, 491604321, 491602140, 490847572, 490627493, 490282905, 489151338, 489127231</strong></td>
<td><strong>Security fixes for <code>apigee-redis</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61726">CVE-2025-61726</a> </li></ul></td>
</tr>
<tr>
<td><strong>492736867, 492735320, 492550947, 492549407, 492360316, 492359543, 492358244, 491608063, 491603446, 491169265, 490282128, 490278007, 490276323, 489127588, 489124394</strong></td>
<td><strong>Security fixes for <code>apigee-asm-ingress</code>.</strong> <br/>This addresses the following vulnerability: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15558">CVE-2025-15558</a> </li></ul></td>
</tr>
<tr>
<td><strong>492956844, 492956300, 492812417, 492811007, 492810814, 492528300, 492361776, 492360457, 492360310, 492360053, 492358006, 492037890, 491606683, 489492294, 489152529</strong></td>
<td><strong>Security fixes for <code>apigee-asm-istiod</code>.</strong> <br/>This addresses the following vulnerabilities: <ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61729">CVE-2025-61729</a> </li></ul></td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Change</h3>
<p>Starting July 25, 2026, the <a href="https://docs.cloud.google.com/bigquery/docs/facebook-ads-transfer">BigQuery Data Transfer Service for Facebook Ads
connector</a> will update the data type
mapping for the <code>ActionValue</code> field in the <code>AdInsightsActions</code> report from <code>INT</code>
to <code>FLOAT</code>.</p>
<h3>Feature</h3>
<p>The following features have been added to <a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python">Python UDFs</a>
during <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>:</p>
<ul>
<li>Vectorized UDFs with Apache Arrow. You can now create <a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python#create-vector-udf-apache">vectorized Python
UDFs</a>
using the Apache Arrow <code>RecordBatch</code> interface for improved performance.</li>
<li>Cloud Monitoring integration. Python UDFs now export
<a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python#view_python_udf_metrics">metrics</a>
to Cloud Monitoring, including CPU utilization, memory utilization, and
maximum concurrent requests per instance.</li>
<li>Container request concurrency. A new option,
<code>container_request_concurrency</code>, is available for the <code>CREATE FUNCTION</code>
statement. This option controls the maximum number of concurrent requests
per Python UDF container instance.</li>
<li>New quotas. Python UDFs are now subject to <a href="https://docs.cloud.google.com/bigquery/quotas#udf_limits">new quotas</a>
on image storage bytes (10 GiB per project per region) and mutation rate
(30 per minute per project per region).</li>
<li>Cost visibility. Python UDF costs can be seen in the
<code>external_service_costs</code> column in the <code>INFORMATION_SCHEMA.JOBS</code> view and in
the <code>ExternalServiceCosts</code> field in the <a href="https://docs.cloud.google.com/bigquery/docs/reference/rest/v2/Job#externalservicecost">Job API</a>.</li>
</ul>
<h3>Feature</h3>
<p>You can now <a href="https://docs.cloud.google.com/bigquery/docs/migration/external-metastore-lakehouse-migration">migrate metadata from external data catalogs to BigLake tables for
Apache
Iceberg</a>. This
feature supports external data catalogs such as such as Apache Hive Metastore
and Apache Iceberg REST Catalog. This feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp">BigQuery MCP server</a>
to perform a range of data-related tasks with your AI applications including:</p>
<ul>
<li>Examining BigQuery resources.</li>
<li>Generating accurate and efficient SQL queries.</li>
<li>Securely executing queries.</li>
<li>Interpreting query results.</li>
</ul>
<p>This feature is <a href="https://cloud.google.com/products#product-launch-stages">Generally Available</a>
(GA).</p>
<h3>Feature</h3>
<p>You can now publish a <a href="https://docs.cloud.google.com/bigquery/docs/create-data-agents#publish-agent-gemini-enterprise">BigQuery Conversational Analytics agent in Gemini
Enterprise</a>.
This feature is in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>You can now use the <a href="https://docs.cloud.google.com/bigquery/docs/notebooks-introduction#notebook_gallery">notebook gallery</a>
in the BigQuery web UI as your central hub for discovering and using prebuilt notebook
templates. This feature is <a href="https://cloud.google.com/products/#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/bigtable/docs/reference/admin/mcp/databaseinsights/mcp">Database Insights remote MCP server</a>
to analyze Bigtable's performance and system metrics. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.</p>
<h3>Feature</h3>
<p>Bigtable <a href="https://docs.cloud.google.com/bigtable/docs/continuous-materialized-views">continuous materialized views</a>
are <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
These views let you create precomputed tables that Bigtable automatically keeps
in sync with your source data for low-latency queries and real-time insights.</p>
<h3>Feature</h3>
<p>Bigtable free trial instances are <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
These instances let you learn and explore Bigtable features for 90 days at no
cost, providing a 1-node SSD cluster and up to 500 GB of storage. For more
information, see <a href="https://docs.cloud.google.com/bigtable/docs/free-trial-instance">Free trial instances overview</a>.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/bigtable/docs/use-bigtable-mcp">Bigtable remote MCP server</a> is
<a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
The Bigtable remote MCP server lets you interact with Bigtable instances
from LLMs, AI applications, and AI-enabled development platforms.</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>GKE workload recommenders now available in the FinOps hub</strong></p>
<p>You can now view recommendations for right-sizing overprovisioned workloads and
optimizing underprovisioned workloads for Google Kubernetes Engine (GKE)
clusters directly in the FinOps hub.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/optimize-workload-resource-utilization">Optimize workload resource utilization</a>.</p>
<h2 class="release-note-product-title">Cloud Logging</h2>
<h3>Libraries</h3>
<div><devsite-selector data-ds-scope="code-sample">
<section><h3 track-name="go">Go</h3><h4 id="v1160_2026-04-13"><a href="https://github.com/googleapis/google-cloud-go/compare/logging/v1.15.0...logging/v1.16.0" rel="noreferrer noopener">v1.16.0</a> (2026-04-13)</h4></section>
</devsite-selector></div>
<h2 class="release-note-product-title">Cloud Run</h2>
<h3>Feature</h3>
<p>Cloud Run ephemeral disk, which allows you to mount a volume that persists only for the duration of your <a href="https://docs.cloud.google.com/run/docs/configuring/services/ephemeral-disk">service</a>, <a href="https://docs.cloud.google.com/run/docs/configuring/jobs/ephemeral-disk">job</a>, or <a href="https://docs.cloud.google.com/run/docs/configuring/workerpools/ephemeral-disk">worker pool</a> instance, is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/sql/docs/mysql/reference/mcp/databaseinsights/mcp">Database Insights remote MCP server</a>
to analyze Cloud SQL for MySQL's performance and system metrics. This feature is
in <a href="https://cloud.google.com/products/#product-launch-stages">GA</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/sql/docs/postgres/reference/mcp/databaseinsights/mcp">Database Insights remote MCP server</a>
to analyze Cloud SQL for PostgreSQL's performance and system metrics. This
feature is in <a href="https://cloud.google.com/products/#product-launch-stages">GA</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/sql/docs/sqlserver/reference/mcp/databaseinsights/mcp">Database Insights remote MCP server</a>
to analyze Cloud SQL for SQL Server's performance and system metrics. This
feature is in <a href="https://cloud.google.com/products/#product-launch-stages">GA</a>.</p>
<h2 class="release-note-product-title">Cloud Storage</h2>
<h3>Feature</h3>
<p>Cloud Storage Model Context Protocol (MCP) server is <a href="https://cloud.google.com/products#product-launch-stages">generally
available</a>. You can
connect to Cloud Storage from AI applications using the server. It lets AI
applications and agents create buckets, retrieve object metadata, read and write
object data, and list buckets and objects. For more information, see <a href="https://docs.cloud.google.com/storage/docs/use-cloud-storage-mcp">Use the
Cloud Storage MCP server</a> and <a href="https://docs.cloud.google.com/storage/docs/reference/mcp">Cloud
Storage MCP reference</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: You can use the Compute Engine remote
Model Context Protocol (MCP) server to let AI agents
and AI applications manage Compute Engine resources, such as Compute Engine
instances, managed instance groups, disks, and snapshots. For more information, see
<a href="https://docs.cloud.google.com/compute/docs/use-compute-engine-mcp">Use the Compute Engine remote MCP server</a>.</p>
<h2 class="release-note-product-title">Firestore</h2>
<h3>Feature</h3>
<p>The Firestore emulator now supports Enterprise edition.
See <a href="https://docs.cloud.google.com/firestore/native/docs/emulator#starting_emulator_in_specific_edition">Start emulator in specific edition</a>.</p>
<h3>Feature</h3>
<p>Firestore Enterprise edition in Native mode and the Pipeline
operations interface are now supported at the General Availability (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>) level.</p>
<h3>Feature</h3>
<p>Firestore Enterprise edition now supports
<a href="https://docs.cloud.google.com/firestore/native/docs/text-search">Text search</a> and <a href="https://docs.cloud.google.com/firestore/native/docs/geospatial-search">Geospatial search</a>.</p>
<p>These features are in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/firestore/native/docs/use-firestore-mcp">Firestore remote MCP server</a>
is now supported at the General Availability
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>) level.</p>
<h3>Feature</h3>
<p>You can now use pipeline operations to perform joins with subqueries.
To learn more, see
<a href="https://docs.cloud.google.com/firestore/native/docs/pipeline/perform-joins-with-sub-pipelines">Perform joins with subqueries</a>.</p>
<h3>Feature</h3>
<p>Firestore Enterprise edition now supports the
<code>update(...)</code> and <code>delete()</code> pipeline operation stages.
Use these stages to <a href="https://docs.cloud.google.com/firestore/native/docs/pipeline/dml">Modify data with Pipeline operations</a>.</p>
<p>This feature is in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Firestore with MongoDB compatibility</h2>
<h3>Feature</h3>
<p>The maximum document size has been
increased to 16 MiB. To learn more, see <a href="https://docs.cloud.google.com/firestore/mongodb-compatibility/docs/behavior-differences#documents">Behavior differences</a>.</p>
<h3>Feature</h3>
<p>Support for text and geospatial search. You
can create text indexes, perform text and geospatial search queries using
the <code>$text</code> and <code>$near</code> operators, handle language settings, and calculate
relevance scores. To learn more, see <a href="https://docs.cloud.google.com/firestore/mongodb-compatibility/docs/text-query">Text search</a>
and <a href="https://docs.cloud.google.com/firestore/mongodb-compatibility/docs/geo-query">Geospatial search</a>.</p>
<p>These features are available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p><code>$lookup</code> now supports <code>let</code> and <code>pipeline</code>.</p>
<h3>Feature</h3>
<p>Support for <a href="https://docs.cloud.google.com/firestore/mongodb-compatibility/docs/change-streams">Change Streams</a>.
Change streams let applications access real-time changes (inserts, updates, and deletes) made to a
collection or to an entire database.</p>
<p>This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>Support for the <code>drop()</code> command to delete entire collections.</p>
<p>This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Request access to Google Cloud Marketplace agents (Preview)</strong></p>
<p>End users can request access to Google Cloud Marketplace agents from
Agent Gallery. Admins can configure the visibility of these agents,
view purchase requests, and manage access requests.</p>
<p>This feature is in Public Preview. For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/agent-gallery">Browse agents with Agent Gallery</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/register-and-manage-marketplace-agents">Add and manage A2A agents from Google Cloud Marketplace</a></li>
</ul>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Register ADK agents hosted on Vertex AI Agent Engine</strong></p>
<p>You can register ADK agents hosted on Vertex AI Agent Engine with
Gemini Enterprise. This includes agents running within
Vertex AI Agent Engine in a different Google Cloud project. This
feature is generally available (GA).</p>
<p>For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/register-and-manage-an-adk-agent">Register and manage ADK agents hosted on Vertex AI Agent Engine</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/configure-cross-project-adk-agents">Configure cross-project ADK agents</a></li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>Accelerator network profile is Generally Available (GA), simplifying your
AI/ML node pool setup. Accelerator network profile automates networking
configuration, including the creation of necessary VPCs and subnets, removing
the need for complex, manual steps previously required for configuring
GPU and TPU workloads. For details, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/config-auto-net-for-accelerators">Configure automated networking for accelerator VMs</a>.</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Knowledge Catalog discovers links between data assets, helping you understand how they connect and the nature of their relationships.
This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.
For more information, see <a href="https://cloud.google.com/dataplex/docs/data-relationships">View data relationships in Knowledge Catalog</a>.</p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Feature</h3>
<p>Now available in preview, the <a href="https://docs.cloud.google.com/looker/docs/getting-started-vscode-extension">Looker VS Code Extension</a> brings LookML development to local desktop IDEs like Visual Studio Code, Claude Code, and Cursor. The extension supports syntax highlighting, autocomplete, real-time file synchronization with your Looker instance, and LookML validation. With the Looker MCP server, it enables <a href="https://docs.cloud.google.com/looker/docs/ai-assisted-development-vscode">AI-assisted development</a>, allowing you to use natural language with agents like Gemini to generate and edit LookML code.</p>
<h2 class="release-note-product-title">Migrate to Virtual Machines</h2>
<h3>Feature</h3>
<p>Migrate to Virtual Machines now supports the following operating systems for
VMware, AWS, Azure, and image import sources:</p>
<ul>
<li>Red Hat Enterprise Linux 10</li>
<li>CentOS 10</li>
<li>AlmaLinux 10</li>
<li>Oracle Linux 10</li>
<li>Rocky Linux 10</li>
</ul>
<p>CentOS is not supported on ARM architecture.</p>
<h2 class="release-note-product-title">Oracle Database@Google Cloud</h2>
<h3>Feature</h3>
<p>Oracle Database@Google Cloud integrates with Database Center to provide fleet-wide insights, proactive alerts, and actionable recommendations for your Oracle Database@Google Cloud resources, including Oracle Exadata and Autonomous databases. For more information, see <a href="https://docs.cloud.google.com/oracle/database/docs/monitor-resource-health">Monitor the health of your Oracle Database@Google Cloud resources in Database Center</a>.</p>
<p>This feature is <a href="https://cloud.google.com/products#product-launch-stages">Generally Available (GA)</a>.</p>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>Google SecOps for SAP is in Preview</strong></p>
<p>Google SecOps for SAP is in Preview. This service helps you
secure your SAP applications by integrating business-critical telemetry into the
Google Security Operations platform, providing unified visibility and AI-powered
threat detection across your SAP landscape.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sap/docs/secops/overview">Google SecOps for SAP overview</a>.</p>
<h2 class="release-note-product-title">Spanner</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/spanner/docs/use-spanner-mcp">Spanner remote MCP server</a>
is generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
The Spanner remote MCP server lets you interact with
Spanner instances from LLMs, AI applications, and
AI-enabled development platforms.</p>
<h3>Feature</h3>
<p>You can use the
<a href="https://docs.cloud.google.com/spanner/docs/reference/mcp/databaseinsights/mcp">Database Insights remote MCP server</a>
to analyze Spanner's performance and system metrics.
This feature is generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<h3>Feature</h3>
<p>You can now use Spanner Studio to
<a href="https://docs.cloud.google.com/spanner/docs/graph/create-update-drop-schema-visually">visually create and manage a Spanner Graph schema</a>.
Visual modeling simplifies graph design by enabling you to map nodes and edges
through an intuitive interface instead of creating manual DDL statements. This
feature is available in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 19, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_19_2026</id>
    <updated>2026-04-19T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_19_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Announcement</h3>
<p><strong>New parser documentation now available</strong></p>
<p>New parser documentation is available to help you ingest and normalize logs from the following sources:</p>
<ul>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/group-ib">Collect Group-IB Threat Intelligence logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/microsoft-scep">Collect Microsoft System Center Endpoint Protection (SCEP) logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/nagios">Collect Nagios XI logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/neo4j">Collect Neo4j Aura logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/nucleus-vulnerability">Collect Nucleus Security - Nucleus Unified Vulnerability Management logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/nyansa-events">Collect Nyansa Voyance / VMware Edge Network Intelligence logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/okera-dap">Collect Okera Dynamic Access Platform (ODAP) audit logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/okta-scaleft">Collect Okta Advanced Server Access logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/onapsis">Collect Onapsis Platform logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/oneidentity-tpam">Collect One Identity TPAM logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/oci-cloudguard">Collect Oracle Cloud Infrastructure - Oracle Cloud Guard logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/oort">Collect Cisco Identity Intelligence logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/sharepoint">Collect Microsoft SharePoint (Office 365) logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/netapp-bluexp">Collect NetApp Console (formerly BlueXP) audit logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/netwrix">Collect Netwrix Auditor logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/vitalqip">Collect Nokia VitalQIP DDI logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/openai-auditlog">Collect OpenAI Audit logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/netflow-otel">Collect OpenTelemetry Netflow Receiver logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/oracle-fusion">Collect Oracle Fusion Cloud Applications logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/net-suite">Collect Oracle NetSuite - NetSuite Applications Suite logs</a></li>
<li><a href="https://clouddocs.devsite.corp.google.com/chronicle/docs/ingestion/default-parsers/oracle-netsuite">Collect Oracle NetSuite logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/vectra-alerts">Collect Vectra Alerts logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/vectra-xdr">Collect Vectra XDR logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/winevtlog-xml">Collect Windows Event logs (XML format)</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/winscp">Collect WinSCP logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/workday-user-activity">Collect Workday User Activity logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/wpengine">Collect WP Engine logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/xiting-xams">Collect XAMS by Xiting logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/yubico-otp">Collect Yubico OTP logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/zero-networks">Collect Zero Networks logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/zix-email-encryption">Collect Zix Email Encryption logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/zscaler-nss-feeds">Collect Zscaler NSS Feeds for Alerts logs</a></li>
<li><a href="https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/zywall">Collect ZyXEL ZyWALL logs</a></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>April 18, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_18_2026</id>
    <updated>2026-04-18T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_18_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>Newly created Cloud SQL instances are integrating with Knowledge Catalog
(formerly Dataplex Universal Catalog) for data discovery. Instances on MySQL
version 8.0 or later will have updates sent to Knowledge Catalog in near
real-time. As part of this automatic enablement, we will send metadata to
Knowledge Catalog. You can verify if your instance is enabled for integration
with Knowledge Catalog by looking at the configuration pane in the Knowledge
Catalog console. If you don't want your instance to be integrated with Knowledge
Catalog, you can <a href="https://docs.cloud.google.com/sql/docs/mysql/dataplex-catalog-integration#deactivate-dataplex-catalog">turn off this
feature</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/mysql/dataplex-catalog-integration#near-real-time">Near
real-time</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>Newly created Cloud SQL instances are integrating with Knowledge Catalog
(formerly Dataplex Universal Catalog) for data discovery. Instances on
PostgreSQL version 14.0 or later will have updates sent to Knowledge Catalog in
near real-time. As part of this automatic enablement, we will send metadata to
Knowledge Catalog. You can verify if your instance is enabled for integration
with Knowledge Catalog by looking at the configuration pane in the Knowledge
Catalog console. If you don't want your instance to be integrated with Knowledge
Catalog, you can <a href="https://docs.cloud.google.com/sql/docs/postgres/dataplex-catalog-integration#deactivate-dataplex-catalog">turn off this
feature</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/postgres/dataplex-catalog-integration#near-real-time">Near
real-time</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Feature</h3>
<p>Newly created Cloud SQL instances are integrating with Knowledge Catalog
(formerly Dataplex Universal Catalog) for data discovery. As part of this
automatic enablement, we will send metadata to Knowledge Catalog. You can verify
if your instance is enabled for integration with Knowledge Catalog by looking at
the configuration pane in the Knowledge Catalog console. If you don't want your
instance to be integrated with Knowledge Catalog, you can <a href="https://docs.cloud.google.com/sql/docs/sqlserver/dataplex-catalog-integration#deactivate-dataplex-catalog">turn off this
feature</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/sqlserver/dataplex-catalog-integration#enable-new">Create a new instance with Knowledge Catalog
integration
enabled</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 17, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_17_2026</id>
    <updated>2026-04-17T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_17_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Issue</h3>
<p>When querying your Elasticsearch data using
<a href="https://docs.cloud.google.com/alloydb/docs/elastic-search#sql-query">standard SQL queries</a> and specifying an
<code>OFFSET</code>, if the <code>OFFSET</code> gets pushed down, it gets applied twice. For example,
if your SQL query contains <code>OFFSET 5</code>, AlloyDB tries
to push the <code>OFFSET</code> down. Then, AlloyDB applies the
<code>OFFSET</code> again when the results are returned.</p>
<h3>Feature</h3>
<p>External search with AlloyDB now supports Elasticsearch in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>With this update, you can use the <code>external_search_fdw</code> extension to connect to Elasticsearch and perform hybrid searches within AlloyDB. This integration allows you to combine the capabilities of AlloyDB with Elasticsearch for advanced search scenarios. For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/elastic-search">Access Elasticsearch data from AlloyDB</a>.</p>
<h3>Announcement</h3>
<p>The following AlloyDB AI function capabilities are available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>:</p>
<ul>
<li>You can now use AI function acceleration and the new <code>AI Function Apply</code> node to run faster queries with AI functions. This feature optimizes the execution of SQL queries that use the <code>ai.if</code> and <code>ai.rank</code> functions in PostgreSQL 17. For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/ai/accelerate-ai-queries">Accelerate performance for queries with AI functions</a>.</li>
<li>You can now use optimized AI functions to accelerate your AI queries while reducing operational costs. By training a smaller, faster proxy model on a sample
of your data, AlloyDB can process most AI queries locally and only fall back to a remote LLM when necessary. For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/ai/accelerate-queries-optimized-functions">Accelerate queries using optimized functions</a>.</li>
<li><p>You can now use the sentiment analysis and summarization functions. These functions let you process and analyze unstructured data directly in your database:</p>
<ul>
<li><code>ai.analyze_sentiment</code>: classifies the emotional tone of text as positive, negative, or neutral, helping you analyze real-time customer feedback from thousands of raw, unstructured product reviews.</li>
<li><code>ai.summarize</code>: condenses lengthy text into its essential information. Use this to extract key decisions and action items from sources like meeting transcripts or technical documentation.</li>
<li><code>ai.agg_summarize</code>: an aggregate function that processes multiple rows in a column to generate a single, unified summary for a group. For instance, you can summarize all reviews for a specific seller using a <code>GROUP BY</code> clause.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/ai/evaluate-sentiment">Evaluate sentiment</a> and <a href="https://docs.cloud.google.com/alloydb/docs/ai/summarize-content">Summarize content</a>.</p></li>
</ul>
<h2 class="release-note-product-title">App Optimize API</h2>
<h3>Announcement</h3>
<p>App Optimize API is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.
App Optimize API helps you to monitor, analyze, and improve the
performance and cost-efficiency of your cloud applications.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>Using
<a href="https://docs.cloud.google.com/bigquery/docs/code-asset-folders">folders</a>
to organize and control access to single file code assets is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA). In addition, you can perform bulk move and delete operations, refresh
folder contents, and view full breadcrumb paths based on resource permissions.
For more information, see
<a href="https://docs.cloud.google.com/bigquery/docs/create-manage-folders">Create and manage folders</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Feature</h3>
<p>You can now integrate Cloud SQL for SQL Server with Vertex AI and third-party models (<a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>).</p>
<p>By integrating your Cloud SQL for SQL Server instance with Vertex AI, you can
generate vector embeddings from models hosted in Vertex AI directly from your
Cloud SQL instance.</p>
<p>Cloud SQL for SQL Server supports model endpoints from the following sources:</p>
<ul>
<li>Vertex AI</li>
<li>Hugging Face</li>
<li>OpenAI</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/sqlserver/integrate-cloud-sql-with-vertex-ai">Integrate Cloud SQL for SQL Server with Vertex AI</a>.</p>
<h2 class="release-note-product-title">Cloud Scheduler</h2>
<h3>Change</h3>
<p>Cloud Scheduler is available in the following <a href="https://docs.cloud.google.com/scheduler/docs/locations">locations</a>:</p>
<ul>
<li><code>europe-west4</code> (Eemshaven, Netherlands)</li>
<li><code>me-central1</code> (Doha, Qatar)</li>
<li><code>me-central2</code> (Dammam, Saudi Arabia)</li>
<li><code>me-west1</code> (Tel Aviv, Israel)</li>
</ul>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: You can create a Hyperdisk Balanced High Availability disk
by cloning a zonal Hyperdisk Balanced or Hyperdisk Extreme disk. This lets you
make your zonal workloads highly available by adding a replica of the data in
another zone within the same region.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/disks/clone-duplicate-disks#create-regional-clone">Create a regional disk clone from a zonal disk</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_intellij_2">Bug fixes in IntelliJ</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h3>Other</h3>
<h3 id="bug_fixes_in_intellij_2">Bug fixes in IntelliJ</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Generative AI on Vertex AI</h2>
<h3>Feature</h3>
<p><strong>RAG Cross Corpus Retrieval</strong></p>
<p>RAG Cross Corpus Retrieval is available in <a href="https://cloud.google.com/products#product-launch-stages">public preview</a>. This feature allows you to retrieve relevant contexts or generate answers from multiple RAG corpora simultaneously using the <code>AsyncRetrieveContexts</code> and <code>AskContexts</code> APIs.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/vertex-ai/generative-ai/docs/rag-engine/cross-corpus-retrieval">RAG Cross Corpus Retrieval</a>.</p>
<h2 class="release-note-product-title">Google Cloud Managed Service for Apache Kafka</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/managed-service-for-apache-kafka/docs/use-managed-service-for-apache-kafka-mcp">Managed Service for Apache Kafka remote MCP server</a>
is <a href="https://cloud.google.com/products/#product-launch-stages">generally available</a> (GA).</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Data quality now supports rule reusability. You can now define data quality
rules as templates and reuse them across multiple catalog entries to standardize
your data quality processes. You can also use a shared library of
<a href="https://docs.cloud.google.com/dataplex/docs/reuse-data-quality-rules#system-templates">system rule templates</a>
for common data validation scenarios. For more information, see
<a href="https://docs.cloud.google.com/dataplex/docs/reuse-data-quality-rules">Reuse data quality rules</a>.</p>
<h3>Feature</h3>
<p>You can now build and run a Knowledge Catalog discovery agent to get more relevant search results for complex natural language queries.</p>
<p>For more information, see <a href="https://cloud.google.com/dataplex/docs/use-discovery-agent">Build an agent to discover your data</a>.</p>
<h3>Feature</h3>
<p>To further refine lineage graphs, Knowledge Catalog lineage views include new
highlight and filter modes. This feature is available in
<a href="https://cloud.google.com/products#product-launch-stages">preview</a>.
For more information, see
<a href="https://cloud.google.com/dataplex/docs/lineage-views#lineage-filtered-view">Apply filters and highlighting for a focused view</a>.</p>
<h2 class="release-note-product-title">Memorystore for Redis</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/memorystore/docs/redis/use-memorystore-mcp">Memorystore for Redis remote MCP server</a> is <a href="https://docs.cloud.google.com/products#product-launch-stages">Generally Available</a>.</p>
<h2 class="release-note-product-title">Memorystore for Valkey</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/memorystore/docs/valkey/use-memorystore-mcp">Memorystore for Valkey remote MCP server</a> is <a href="https://docs.cloud.google.com/products#product-launch-stages">Generally Available</a>.</p>
<h3>Feature</h3>
<p>You can secure access to your instances by using <a href="https://docs.cloud.google.com/memorystore/docs/valkey/manage-basic-auth">basic token-based authentication</a>. This feature is available in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">NetApp Volumes</h2>
<h3>Feature</h3>
<p>The ONTAP-mode for the Flex Unified pools is generally available (GA). For more
information about this new mode, see <a href="https://docs.cloud.google.com/netapp/volumes/docs/ontap/overview#about_ontap-mode">About ONTAP-mode</a>.</p>
<h3>Feature</h3>
<p>Google Cloud NetApp Volumes Flex Unified service level is generally available
(GA) for NFS, SMB, and NVMe/TCP protocols. For more information,
see <a href="https://docs.cloud.google.com/netapp/volumes/docs/discover/overview#key_features">Key features</a>.</p>
<h3>Feature</h3>
<p>The large capacity volumes feature, a file-only solution with NFS and SMB
protocols for massive datasets, is generally available (GA) for the Flex Unified
service level. For more information, see <a href="https://docs.cloud.google.com/netapp/volumes/docs/configure-and-use/volumes/overview#large-capacity-volumes">Large capacity volumes</a>.</p>
<h2 class="release-note-product-title">Network Intelligence Center</h2>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/network-intelligence-center/docs/reference/networkmanagement/mcp">Network Management API</a>
remote Model Context Protocol (MCP) server to create, view, and delete
<a href="https://docs.cloud.google.com/network-intelligence-center/docs/connectivity-tests/concepts/overview">Connectivity Tests</a>.</p>
<h2 class="release-note-product-title">Oracle Database@Google Cloud</h2>
<h3>Feature</h3>
<p>You can now use the <a href="https://docs.cloud.google.com/oracle/database/docs/use-oracledatabase-mcp">Oracle Database@Google Cloud remote MCP server</a>.
The remote MCP server lets you interact easily with Oracle Database@Google Cloud resources
from LLMs, AI applications, and AI-enabled development platforms.</p>
<p>This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Pub/Sub</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/pubsub/docs/use-pubsub-mcp">Pub/Sub remote MCP server</a> is
<a href="https://cloud.google.com/products/#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p>Through the
<a href="https://docs.cloud.google.com/application-design-center/docs/overview">Application Design Center</a>,
Security Command Center helps you perform proactive security assessments (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>)
throughout your application development lifecycle. This integration shows both
design-time and runtime findings in Security Command Center. For more information, see
<a href="https://docs.cloud.google.com/security-command-center/docs/concepts-security-sources#application-security-assessments">Application lifecycle security
assessments</a>.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/dspm-data-security">Data Security Posture Management</a> has new controls in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. The controls
help you secure Cloud Storage objects and include the following:</p>
<ul>
<li>Govern the minimum retention period for Cloud Storage objects</li>
<li>Require Customer-Managed Encryption for Cloud Storage objects</li>
<li>Restrict Public Access to Cloud Storage objects</li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/security-command-center/docs/dspm-data-security#advanced-cloud-controls">Advanced data governance and security cloud controls</a>.</p>
<h2 class="release-note-product-title">Service Extensions</h2>
<h3>Feature</h3>
<p>You can use authorization extensions to insert custom services directly into
the Secure Web Proxy processing path. This feature is in <strong>Preview</strong>. For more
information, see
<a href="https://docs.cloud.google.com/service-extensions/docs/swp-extensions-overview">Callouts for Secure Web Proxy</a>.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/service-extensions/docs/lb-extensions-overview#authorization-extensions">Authorization extensions</a>
support authorization policy request and content profiles in <strong>Preview</strong>.</p>
<h2 class="release-note-product-title">Spanner</h2>
<h3>Feature</h3>
<p>Repeatable read isolation is <a href="https://docs.cloud.google.com/products#product-launch-stages">generally available</a>.
You can use it to reduce latency and transaction failure rates for workloads
that have many reads contending with fewer writes. For more information, see
<a href="https://docs.cloud.google.com/spanner/docs/isolation-levels#repeatable-read">Repeatable read isolation</a>.</p>
<h3>Feature</h3>
<p>Spanner supports Gemini Cloud Assist investigation
capabilities. You can create, run, and edit
<a href="https://docs.cloud.google.com/cloud-assist/investigations">Gemini Cloud Assist investigations</a>
only if you have a <a href="https://cloud.google.com/support/premium">Premium support contract</a>.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/spanner/docs/monitor-troubleshoot-with-ai">monitor and troubleshoot your Spanner instance with AI assistance</a>.</p>
<h3>Feature</h3>
<p>Columnar engine for Spanner is now <a href="https://cloud.google.com/products/#product-launch-stages">generally available
(GA)</a>. Columnar engine
is a storage technique used with analytical queries to make scans up to 200
times faster on live operational data without affecting transaction workloads.
This release enables support for Columnar Engine in databases that use the
<a href="https://docs.cloud.google.com/spanner/docs/configure-columnar-engine#enable-columnar-engine-postgres">Postgres interface</a>.</p>
<p>For more information, see the
<a href="https://docs.cloud.google.com/spanner/docs/configure-columnar-engine#enable-columnar-engine-postgres">Columnar engine for Spanner overview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 16, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_16_2026</id>
    <updated>2026-04-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_16_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AI Hypercomputer</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: The AI Hypercomputer documentation includes support for
the A3 Mega and A3 High machine types. The addition of A3 Mega and A3 High
expand the available compute options for training and serving large-scale AI
models on Google Kubernetes Engine (GKE) and Compute Engine.</p>
<p>To support this effort, several new pages have been added and existing pages
updated in the AI Hypercomputer documentation where relevant. These updates
provide comprehensive guidance for deploying, managing, and optimizing the A3
Mega and A3 High machine types within the AI Hypercomputer stack.</p>
<p>New documentation pages include the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/ai-hypercomputer/docs/create/create-vm-a3-high-mega">Create an AI-optimized instance with A3 High or A3 Mega</a></li>
<li><a href="https://docs.cloud.google.com/ai-hypercomputer/docs/create/create-vms-in-bulk-a3-high-mega">Create AI-optimized instances in bulk with A3 High or A3 Mega</a></li>
<li><a href="https://docs.cloud.google.com/ai-hypercomputer/docs/create/gke-ai-hypercompute-autopilot-a3-high-mega">Create GKE Autopilot clusters which use A3 Mega or A3 High</a></li>
<li><a href="https://docs.cloud.google.com/ai-hypercomputer/docs/create/gke-ai-hypercompute-standard-a3-high-mega">Create GKE Standard clusters which use A3 Mega or A3 High</a></li>
<li><a href="https://docs.cloud.google.com/ai-hypercomputer/docs/nccl/test-gke-custom-a3-mega-high">Run NCCL on custom GKE clusters that use A3 Mega and A3 High</a></li>
</ul>
<aside class="note"><strong>Note:</strong><span> <a href="https://docs.cloud.google.com/ai-hypercomputer/docs/cluster-capabilities">Cluster management capabilities</a>
aren't supported for A3 Mega or A3 High VMs that you created before October 1,
2025. To check if your A3 Mega or A3 High VMs have cluster management
capabilities, verify that the <code>deploymentType</code> field in the reservation that you
used to create the VMs is set to <a href="https://docs.cloud.google.com/ai-hypercomputer/docs/view-reserved-capacity#view-reservation">DENSE</a>.
For more information about using A3 Mega or A3 High VMs in a cluster, contact
your account team.</span></aside>
<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Announcement</h3>
<p>The following vector search improvements are now available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>:</p>
<ul>
<li>AlloyDB now supports Vector assist. Vector assist is an
AlloyDB extension that simplifies the deployment and management of your
AlloyDB vector workloads. It helps you set up production-ready vector search
capabilities, such as embedding generation, query optimization, and index
creation for vector types like HNSW. For more information about vector
assist, how it works, and its limitations, see
<a href="https://docs.cloud.google.com/alloydb/docs/ai/vector-assist-overview">Vector assist overview</a>.</li>
<li>You can now defer ScaNN index creation on an empty table or a table with
insufficient rows until the table has sufficient data. For more information,
see <a href="https://docs.cloud.google.com/alloydb/docs/ai/create-scann-index#deferred-index-creation-for-empty-tables-insufficient-rows">Create a ScaNN index</a>.</li>
<li>The <code>alloydb_scann</code> extension now supports four-level tree indexes,
providing support for tables with up to 10 billion vector rows. For more
information, see <a href="https://docs.cloud.google.com/alloydb/docs/ai/create-scann-index#create-scann-index-manual">Four-level ScaNN tree
indexes</a>.</li>
</ul>
<h3>Feature</h3>
<p>Adaptive filtering from inline filtering to pre-filtering is now generally
available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
With AlloyDB AI, you can use adaptive filtering to optimize filtered
vector searches. This feature enables the query optimizer to use cost-based
analysis to dynamically choose the most efficient filtering strategy—either
inline filtering or pre-filtering—based on real-time data distributions. This
improves filtered vector search performance without requiring manual tuning or
intervention. Note that the feature adaptive filtering from pre-filtering to inline
filtering is still in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/ai/adaptive-filtering">Understand adaptive filtering in AlloyDB AI</a>.</p>
<h3>Announcement</h3>
<p>The <code>alloydb_scann</code> extension is updated to include the following
vector search improvements. These features are generally available
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>):</p>
<ul>
<li>By default, new ScaNN vector index builds are automatically tuned.
Manually-tuned indexes can be converted to automatically-tuned indexes. For
more information, see <a href="https://docs.cloud.google.com/alloydb/docs/ai/create-scann-index">Create a ScaNN
index</a>.</li>
<li>You can now automatically maintain your ScaNN vector indexes. AlloyDB
incrementally manages your index such that when your dataset grows, AlloyDB
updates centroids and splits large outlier partitions to provide better QPS
and search results. For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/ai/maintain-vector-indexes#maintain-index-automatically">Maintain indexes
automatically</a>.</li>
</ul>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/conversational-analytics">Conversational analytics</a> now supports
querying Lakehouse tables that connect to the Apache Iceberg REST catalog or are
federated to an external catalog. For more information, see <a href="https://docs.cloud.google.com/biglake/docs/conversational-analytics">Query BigLake data
with natural language</a>.</p>
<p>This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>You can now use <a href="https://docs.cloud.google.com/bigquery/docs/colab-data-apps">Colab Data Apps</a>
to transform your data analyses from Colab notebooks into
polished, interactive applications.</p>
<p>This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>You can now use the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-key-drivers"><code>AI.KEY_DRIVERS</code> function</a>
to identify segments of data that cause statistically significant changes to a
summable metric.</p>
<p>This feature is in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>You can stream messages from <a href="https://docs.cloud.google.com/pubsub/docs/subscription-overview">Pub/Sub</a>
directly to a Bigtable table using
<a href="https://docs.cloud.google.com/pubsub/docs/bigtable-subscriptions">Bigtable subscriptions</a>. This feature lets
you write streaming messages to Bigtable without needing a separate subscriber
such as Dataflow. This feature is available in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Run</h2>
<h3>Feature</h3>
<p>Support for specifying custom CPU or concurrency targets using <a href="https://docs.cloud.google.com/run/docs/configuring/scaling-controls">scaling controls</a> is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/sql/docs/mysql/use-cloudsql-mcp">Cloud SQL remote MCP server</a>
is generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
The Cloud SQL remote MCP server lets you interact easily with Cloud SQL
instances from LLMs, AI applications, and AI-enabled development platforms.</p>
<h3>Feature</h3>
<p>You can use
<a href="https://docs.cloud.google.com/sql/docs/mysql/about-private-service-connect#dns-automation">DNS automation</a>
on Cloud SQL instances where Private Service Connect is enabled to provision
and manage per-instance DNS records automatically. On Enterprise Plus edition
instances where DNS automation is enabled, you can also enable a global write
endpoint DNS that automatically resolves to your current primary instance.</p>
<p>This feature is in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/sql/docs/postgres/use-cloudsql-mcp">Cloud SQL remote MCP server</a>
is generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
The Cloud SQL remote MCP server lets you interact easily with Cloud SQL
instances from LLMs, AI applications, and AI-enabled development platforms.</p>
<h3>Feature</h3>
<p>You can use
<a href="https://docs.cloud.google.com/sql/docs/mysql/about-private-service-connect#dns-automation">DNS automation</a>
on Cloud SQL instances where Private Service Connect is enabled to provision
and manage per-instance DNS records automatically. On Enterprise Plus edition
instances where DNS automation is enabled, you can also enable a global write
endpoint DNS that automatically resolves to your current primary instance.</p>
<p>This feature is in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/sql/docs/sqlserver/use-cloudsql-mcp">Cloud SQL remote MCP server</a>
is generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
The Cloud SQL remote MCP server lets you interact easily with Cloud SQL
instances from LLMs, AI applications, and AI-enabled development platforms.</p>
<h3>Feature</h3>
<p>You can use
<a href="https://docs.cloud.google.com/sql/docs/mysql/about-private-service-connect#dns-automation">DNS automation</a>
on Cloud SQL instances where Private Service Connect is enabled to provision
and manage per-instance DNS records automatically. On Enterprise Plus edition
instances where DNS automation is enabled, you can also enable a global write
endpoint DNS that automatically resolves to your current primary instance.</p>
<p>This feature is in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cluster Toolkit</h2>
<h3>Feature</h3>
<p>Cluster Toolkit version v1.88.0 is available. This release adds dynamic
machine configurations by using the Compute Engine API. This release also
refactors the naming convention for Helm releases within the <code>kubectl-apply</code>
module, which helps to improve the predictability and maintainability of
deployed resources. For details, see the <a href="https://github.com/GoogleCloudPlatform/cluster-toolkit/discussions/5506">Release announcement on
GitHub</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: To ensure data consistency when backing up multiple disks,
you can use consistency groups of instant snapshots to back up a group of disks at
the same point in time.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/disks/instant-snapshots">About instant snapshots</a>.</p>
<h3>Feature</h3>
<p><strong>Preview</strong>: You can specify a 120-second preemption notice duration while
creating Spot VMs. Use this feature for workloads on Spot VMs
where you want up to an additional 120 seconds for handling preemption. If you
want to migrate existing Spot VMs workloads, make sure you update
your workload to handle preemption outside of a shutdown script and test
preemption. For more information, see
<a href="https://docs.cloud.google.com/compute/docs/instances/spot#preemption-notice-duration">Spot VMs</a>
and <a href="https://docs.cloud.google.com/compute/docs/instances/create-use-spot">Create and use Spot VMs</a>.</p>
<h3>Feature</h3>
<p><strong>Generally available</strong>: You can rotate the customer-managed encryption key
(CMEK) used to encrypt a disk, standard snapshot, or archive snapshot to a new key version without
downtime.</p>
<p><strong>Generally available</strong>: You can change the CMEK used to encrypt a disk, standard
snapshot, or archive snapshot to a different key without downtime.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/disks/customer-managed-encryption#rotate_encryption">Rotate the CMEK for a disk or standard snapshot</a>
and
<a href="https://docs.cloud.google.com/compute/docs/disks/customer-managed-encryption#change-key">Change the CMEK for a disk or standard snapshot</a>.</p>
<h2 class="release-note-product-title">Dataform</h2>
<h3>Feature</h3>
<p>You can
<a href="https://docs.cloud.google.com/dataform/docs/connect-repository#dev-connect">connect Dataform repositories to third-party Git repositories using Developer Connect</a>,
removing the need for manual secrets management and enabling support for
repositories in privately hosted networks. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Datastream</h2>
<h3>Feature</h3>
<p>You can now create a Datastream stream directly from the overview page
of your AlloyDB for PostgreSQL instance using the automated flow. The
automated flow simplifies the process of moving data to BigQuery by reducing the
number of steps that you need to perform.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/datastream/docs/create-alloydb-stream-automated">Create an AlloyDB for PostgreSQL stream using the automated flow</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code_4">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Cloud Assist</h2>
<h3>Announcement</h3>
<h3 id="geminicloudassist_api_automatically_enabled_for_gemini_cloud_assist_chat_users">geminicloudassist API automatically enabled for Gemini Cloud Assist chat users</h3>
<p>As of April 16th, 2026, the <code>geminicloudassist.googleapis.com</code> API has been
automatically enabled on projects that meet <strong>all</strong> of the following criteria:</p>
<ul>
<li>Had used <a href="https://docs.cloud.google.com/cloud-assist/chat-panel">Gemini Cloud Assist chat</a> in the prior
60 days.</li>
<li>Had the <code>cloudaicompanion.googleapis.com</code> API enabled on April 16, 2026.</li>
<li>Did not have the <code>geminicloudassist.googleapis.com</code> API enabled on
April 16, 2026.</li>
</ul>
<p>The Gemini Cloud Assist chat functionality that was previously served by
<code>cloudaicompanion.googleapis.com</code> is now served by
<code>geminicloudassist.googleapis.com</code>, and both APIs are dependencies to use
Gemini Cloud Assist. This automatic API enablement ensures that users have
access to the same functionality without any loss of service.</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Data insights for unstructured data transforms dark data or
unstructured files in the form of PDFs in Cloud Storage into structured,
queryable assets. This feature is now available in
<a href="https://cloud.google.com/products#product-launch-stages">preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/data-insights-unstructured-data">About data insights for unstructured
data</a>.</p>
<h3>Feature</h3>
<p>Automated cataloging of Iceberg REST Catalog (IRC) for Google Cloud
Lakehouse runtime catalog is now generally available
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>). This includes support for
lineage, data profiling, data quality, and data insights.</p>
<p>Federated support for Databricks Unity IRC, AWS Glue Data Catalog IRC, and
Snowflake Horizon IRC is available in
<a href="https://cloud.google.com/products#product-launch-stages">preview</a>.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/dataplex/docs/catalog-overview#supported-sources">About metadata management in Knowledge Catalog</a>.</p>
<h2 class="release-note-product-title">Memorystore for Valkey</h2>
<h3>Feature</h3>
<p>You can <a href="https://docs.cloud.google.com/memorystore/docs/valkey/migrate-workloads">migrate your workloads</a> from your self-managed Redis and Valkey instances that run in Google Cloud Platform into Memorystore for Valkey. This feature is available in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/memorystore/docs/valkey/use-shared-ca">shared</a> and <a href="https://docs.cloud.google.com/memorystore/docs/valkey/use-customer-managed-ca">customer-managed</a> Certificate Authority (CA) modes are <a href="https://docs.cloud.google.com/products#product-launch-stages">Generally Available</a>.</p>
<h2 class="release-note-product-title">Pub/Sub</h2>
<h3>Feature</h3>
<p>You can stream messages from Pub/Sub directly to a
<a href="https://docs.cloud.google.com/bigtable/docs/overview">Bigtable</a> table using
<a href="https://docs.cloud.google.com/pubsub/docs/bigtable-subscriptions">Bigtable subscriptions</a>. This feature lets
you write streaming messages to Bigtable without needing a separate subscriber
such as Dataflow. This feature is available in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Secret Manager</h2>
<h3>Feature</h3>
<p>Integrated secret synchronization feature is now Generally Available (GA). You can
automatically synchronize secrets from Secret Manager into Kubernetes Secret
objects within your Google Kubernetes Engine (GKE) clusters. This process allows
applications to access secrets from Secret Manager using standard Kubernetes
methods, such as environment variables or volume mounts. Applications that are
already configured to read secrets from Kubernetes Secret object can now
seamlessly read secrets in Secret Manager.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/secret-manager/docs/sync-k8-secrets">Synchronize secrets to Kubernetes Secrets</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/ai-protection-overview">AI Protection</a> supports
agentic workloads in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>,
including <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/overview">Gemini Enterprise Agent Platform</a>
and Model Context Protocol (MCP) servers. This update includes the following:</p>
<ul>
<li><strong>Agent Platform Vulnerability Assessment</strong>: Identifies software vulnerabilities (CVEs) in agentic
workloads that are deployed with Gemini Enterprise Agent Platform.
Findings are surfaced for vulnerabilities of HIGH or CRITICAL severity that are
detected in your custom dependencies.</li>
<li><strong>Expanded detection and controls</strong>: Includes new threat detection findings
and recommended security controls for AI agents and MCP servers.</li>
<li><strong>Enhanced inventory and filtering</strong>: Provides an updated <a href="https://docs.cloud.google.com/security-command-center/docs/assess-risk#ai-protection">AI security
dashboard</a> view and new
filtering options for agentic resources in the <a href="https://docs.cloud.google.com/security-command-center/docs/work-with-resources-in-the-console">console</a>.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>April 15, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_15_2026</id>
    <updated>2026-04-15T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_15_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>The AlloyDB for PostgreSQL index advisor is enabled by default. It provides vector
search index recommendations for Scalable Nearest Neighbors (ScaNN) indexes. For
more information, see <a href="https://docs.cloud.google.com/alloydb/docs/use-index-advisor">Use the index advisor</a>.</p>
<h2 class="release-note-product-title">Artifact Registry</h2>
<h3>Feature</h3>
<p>Platform logs can record data about successful and failed requests made
to Artifact Registry repositories. For more information, see
<a href="https://docs.cloud.google.com/artifact-registry/docs/platform-logs">Access and use platform logs</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>BigQuery Apache Iceberg external tables now support
<a href="https://iceberg.apache.org/spec/#version-3-extended-types-and-capabilities">Iceberg version 3</a>,
including binary deletion vectors. For more information, see
<a href="https://docs.cloud.google.com/bigquery/docs/iceberg-external-tables">Apache Iceberg external tables</a>.
This feature is in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>BigQuery agent analytics is now <a href="https://cloud.google.com/products#product-launch-stages">generally available</a> (GA) in the Google Agent Developer Kit. <a href="https://docs.cloud.google.com/bigquery/docs/bigquery-agent-analytics">BigQuery agent analytics</a>
is an open source solution that lets you capture, analyze, and visualize
multimodal agent interaction data at scale.</p>
<h3>Announcement</h3>
<p>A known issue has been resolved where a materialized view refresh could expose could expose masked or filtered data from fine grained access control policies in error messages. No further action is needed.</p>
<h3>Feature</h3>
<p>You can now use <a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/export-statements#export_to_alloydb"><code>EXPORT DATA</code>
statements</a> to <a href="https://docs.cloud.google.com/bigquery/docs/export-to-alloydb">reverse
ETL BigQuery data to AlloyDB</a>. This feature is
in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>Dataplex Universal Catalog is now called Knowledge Catalog. The API, client
library, CLI, and Identity and Access Management (IAM) names remain unchanged.
For more information about how Bigtable metadata interacts with Knowledge
Catalog, see <a href="https://docs.cloud.google.com/bigtable/docs/manage-data-assets-using-knowledge-catalog">Manage data assets using Knowledge Catalog</a>.</p>
<h2 class="release-note-product-title">Cloud Asset Inventory</h2>
<h3>Feature</h3>
<p>The following resource type is publicly available through the
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/exportAssets">ExportAssets</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/listing-assets">ListAssets</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/batchGetAssetsHistory">BatchGetAssetsHistory</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/queryAssets">QueryAssets</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/feeds">Feed</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/searchAllResources">SearchAllResources</a>,
and
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/searchAllIamPolicies">SearchAllIamPolicies</a>
APIs.</p>
<ul>
<li>Storage Batch Operations API
<ul>
<li><code>storagebatchoperations.googleapis.com/Job</code></li></ul></li></ul>
<h2 class="release-note-product-title">Cloud Composer</h2>
<h3>Announcement</h3>
<p>To more strongly embrace the success and growing customer preference
for OSS solutions, Cloud Composer is evolving to become
<strong>Managed Service for Apache Airflow</strong>. This name change provides improved
customer understanding of our portfolio while reinforcing our
commitment to being the most open cloud ecosystem.</p>
<h3>Feature</h3>
<p><strong>Airflow 3</strong> is now generally available (GA) in Cloud Composer 3.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/composer/docs/composer-3/use-composer-mcp">Cloud Composer remote Model Context Protocol (MCP) server</a> is available
in Preview.</p>
<p>You can use Cloud Composer remote Model Context Protocol (MCP) server to
connect to Cloud Composer from AI applications such as Gemini CLI, ChatGPT,
Claude, or in AI applications that you're developing. The Cloud Composer MCP
server lets you manage Cloud Composer environments and get details about
executed DAG runs and Airflow tasks.</p>
<h2 class="release-note-product-title">Cloud Run</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/run/docs/use-cloud-run-mcp">Cloud Run remote MCP server</a>, which lets agents and AI applications deploy with Cloud Run, is in <a href="https://cloud.google.com/products#product-launch-stages">General Availability (GA)</a>.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>Your trace data can be encrypted with a customer-managed encryption key (CMEK).
To enable CMEK, set a default storage location and for that location, set a
default Cloud Key Management Service key.</p>
<p>You can set these defaults for an organization, a folder, or a project.
When set for an organization or folder, the settings apply to
that resource and to its descendants. For more information, see
<a href="https://docs.cloud.google.com/stackdriver/docs/observability/set-defaults-for-observability-buckets">Set defaults for observability buckets</a>.</p>
<h3>Feature</h3>
<p>When you configure a default storage location, you control the location of your
new observability buckets. These buckets store your trace data.</p>
<p>You can set a default storage location for an organization, a folder, or a
project. When set for an organization or folder, the setting applies to that
resource and to its descendants. For more information, see
<a href="https://docs.cloud.google.com/stackdriver/docs/observability/set-defaults-for-observability-buckets">Set defaults for observability buckets</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Announcement</h3>
<p>You can view the physical location of your Compute Engine instances in a zone
to understand your cluster topology. This information helps you reduce network
latency between your compute instances. For more information, see
<a href="https://docs.cloud.google.com/compute/docs/instances/view-instance-topology">View Compute Engine instance topology</a>.</p>
<h3>Feature</h3>
<p><strong>Generally available</strong>: You can control the physical location of the
Compute Engine instances in a MIG by using workload policies. Workload
policies help you to, for example, place your compute instances close together
to minimize network latency when running AI or ML workloads. For more
information, see
<a href="https://docs.cloud.google.com/compute/docs/instance-groups/about-workload-policies">About workload policies in MIGs</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Use Gemini Enterprise Admin and Gemini Enterprise User IAM roles</strong></p>
<p>Use the Gemini Enterprise Admin and Gemini Enterprise User roles.</p>
<p>The Gemini Enterprise Admin and Gemini Enterprise User roles still map to the
Discovery Engine admin and user roles, so existing customers do not need to make
any changes.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/access-control">IAM roles and
permissions</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.21</strong></p>
<p>We've released version 4.21 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Feature</h3>
<p><strong>Language selection support for direct calls</strong></p>
<p>End-users making direct calls to agent phone numbers and agent extension numbers
can select their language at the start of a call.</p>
<p>Administrators: The <strong>Add Number</strong> and <strong>Edit a Number</strong> dialogs, located at
<strong>Settings <span aria-label="and then">&gt;</span> Call <span aria-label="and then">&gt;</span> Phone Numbers <span aria-label="and then">&gt;</span> Phone
Number Management</strong>, have a new <strong>Set languages</strong> checkbox (when the <strong>Set as a
direct number</strong> checkbox is selected). When you select the <strong>Set languages</strong>
checkbox, the <strong>Select languages</strong> list appears.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/call-settings#create-direct-phone-number">Create a direct phone
number</a>.</p>
<h3>Feature</h3>
<p><strong>"Improved controls for predictive campaigns" is available without assistance
from the Google account team</strong></p>
<p>This feature was announced on <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/release-notes#March_24_2026">March 24,
2026</a> but
previously required the Google account team to enable it. You no longer need
assistance from the Google account team to use this capability. For more
information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/campaign-predictive">Predictive
campaigns</a>.</p>
<h3>Feature</h3>
<p><strong>Virtual agents can transfer calls to a specific human agent</strong></p>
<p>Virtual support agents can transfer calls directly to a specific human agent
using the agent ID or agent extension number. Include the <code>agent_extension</code> or
<code>agent_id</code> field in the transfer payload to direct the call to the correct
agent. Transferring directly to a human agent eliminates the intermediate step
of transferring to a queue before transferring to the agent. This can improve
wait times and customer satisfaction. For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/virtual-agent-to-human-agent-transfers">Virtual agent
to human agent
transfers</a>.</p>
<h3>Fixed</h3>
<p>The following issues were addressed in this release:</p>
<ul>
<li><p>Fixed an issue where backslash characters in chat shortcuts and chat
messages weren't displayed correctly, resulting in missing or empty message
chat bubbles.</p></li>
<li><p>Fixed an issue where virtual agent chat transcripts didn't match the actual
conversation.</p></li>
<li><p>Fixed an issue where call times in session metadata for virtual agent to
human agent escalations were shorter than the actual call times.</p></li>
<li><p>Fixed an issue where agents were able to join a conference call despite
receiving microphone permission errors.</p></li>
<li><p>Fixed an issue where direct inbound calls to Twilio numbers assigned at the
user level continuously rang without reaching the agent.</p></li>
<li><p>Fixed an issue where chat transfers from auto-answer queues to manual-answer
queues were incorrectly recorded as manual-to-manual in reporting.</p></li>
<li><p>Fixed an agent desktop issue where French (Canadian) translations were
missing or incorrect during outbound calls.</p></li>
<li><p>Fixed an issue where the <strong>All Teams</strong> filter didn't block interactions with
background elements, which could cause unintended end-user interactions with
the UI.</p></li>
<li><p>Fixed an issue where missed call volumes didn't appear on the agent
monitoring page.</p></li>
<li><p>Fixed an issue that occurred when the <strong>Display transfer history in agent
adapter</strong> capability was enabled. After a virtual agent escalation,
escalated queue names were shown in English instead of the correct target
language.</p></li>
<li><p>Fixed an issue where virtual agent audio sessions ended after 15 minutes,
causing calls to be escalated unexpectedly.</p></li>
<li><p>Fixed an issue where underscores within email addresses were incorrectly
removed in CRM transcripts.</p></li>
<li><p>Fixed an issue where chat transcript PDFs weren't generated when real-time
redaction was enabled and conversations included non-text message types such
as inline buttons or content cards.</p></li>
<li><p>Fixed an issue where content cards sent by virtual agents during
conversations were missing from the PDF chat transcript.</p></li>
<li><p>Fixed an issue where chat transcripts created through the API weren't
appearing in agent conversations.</p></li>
<li><p>Fixed an issue where voicemails disappeared from the agent's queue and
didn't appear in voicemail history or reports.</p></li>
<li><p>Fixed an issue where the agent adapter displayed <strong>Escalated Virtual Agent
Call</strong> instead of <strong>IVR Callback</strong> after connecting during a callback.</p></li>
<li><p>Fixed an issue where chat disposition selections reset during wrap-up,
particularly when Agent Assist was enabled.</p></li>
<li><p>Fixed an issue where custom fields in dialer list uploads worked only if the
column headers were in all caps.</p></li>
<li><p>Fixed an issue where the email adapter didn't start up.</p></li>
</ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.34.300-gke.59 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.34.300-gke.59 runs on Kubernetes v1.34.3-gke.400.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.34.300-gke.59:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a></li>
<li>Cluster and node pool failures are now surfaced in the <code>RecentFailures</code> field
in the cluster status. This change provides a centralized location for viewing
errors from both worker node pools and control plane nodes, improving the
troubleshooting and debugging experience.
</li>
<li>Fixed an issue where Metrics API operations—including
<code>kubectl top</code>, Horizontal Pod Autoscaling (HPA), and Vertical Pod Autoscaling
(VPA)—could fail with TLS verification errors during CA rotation.
</li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r15-version-updates">(2026-R15) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1318000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1205000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1068000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1352">1.35.2-gke.1962000</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<p>There are no new releases in the Stable channel.</p>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2369000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1790000</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1318000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2369000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1790000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1318000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r15-security-updates">(2026-R15) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.30.14-gke.2369000</td>
<td>cos-117-18613-534-62</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-62_">cos-117-18613-534-62 release notes</a></td>
</tr>
<tr>
<td>1.31.14-gke.1790000</td>
<td>cos-117-18613-534-62</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-62_">cos-117-18613-534-62 release notes</a></td>
</tr>
<tr>
<td>1.32.13-gke.1318000</td>
<td>cos-117-18613-534-62</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-534-62_">cos-117-18613-534-62 release notes</a></td>
</tr>
<tr>
<td>1.35.3-gke.1389000</td>
<td>cos-125-19216-220-106</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-220-106_">cos-125-19216-220-106 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r15-version-updates">(2026-R15) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<p>There are no new releases in the Stable channel.</p>
<h3>Change</h3>
<h4 id="2026-r15-version-updates">(2026-R15) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1205000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1067000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1068000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1352">1.35.2-gke.1962000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r15-version-updates">(2026-R15) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1318000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r15-version-updates">(2026-R15) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1318000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2369000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1790000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1318000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13310">1.33.10-gke.1176000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1237000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r15-version-updates">(2026-R15) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2369000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1790000</a></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Unified and upgraded Chronicle API</strong></p>
<p><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest?rep_location=africa-south1">Chronicle API</a> has been unified with API resources from <a href="https://docs.cloud.google.com/chronicle/docs/soar/reference/working-with-chronicle-soar-apis">legacy SOAR API</a>. In addition, we've upgraded the following Chronicle API resources from alpha to beta. This upgrade signals <a href="https://google.aip.dev/181">API Stability</a> and functional completeness, enabling customer and partner adoption for production usage. We recommend customers use Chronicle API for a more robust, secure, and extensible experience.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest?rep_location=africa-south1">Chronicle API</a>.</p>
<table>
<tr>
<td><strong>Feature</strong>
</td>
<td><strong>Chronicle API Resources upgraded to v1 Beta</strong>
</td>
</tr>
<tr>
<td>Alerts and ATIs, UEBA
   </td>
<td><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.threatCollections">ThreatCollection</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.iocs">IoC</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.coverageDetails">CoverageDetail</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances/getRiskConfig?rep_location=africa-south1">EntityRisk</a>
</td>
</tr>
<tr>
<td>Dashboards
   </td>
<td><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.nativeDashboards">NativeDashboard</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.dashboardCharts">DashboardChart</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.dashboardQueries">DashboardQuery</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.contentHub.featuredContentNativeDashboards">FeaturedContentNativeDashboard</a>
</td>
</tr>
<tr>
<td>Data Tables
   </td>
<td><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.dataTables">DataTable</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.dataTables.dataTableRows">DataTableRow</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.dataTableOperationErrors">DataTableOperationError</a>
</td>
</tr>
<tr>
<td>Ingestion
   </td>
<td><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.logTypes.logs">Logs</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.feeds">Feed</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.feedSourceTypeSchemas.logTypeSchemas">LogTypeSchema</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.feedSourceTypeSchemas">FeedSourceSchema</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.feedPacks">FeedPack</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.forwarders">Forwarder</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.forwarders.collectors">Collector</a>
</td>
</tr>
<tr>
<td>Normalization
   </td>
<td><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.logTypes">Logtype</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.logTypes.parsers">Parser</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.ingestionLogLabels">IngestionLogLabel</a>
</td>
</tr>
<tr>
<td>Detections
   </td>
<td><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.findingsRefinements">FindingsRefinement</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances/verifyRuleText">VerifyRuleText</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.contentHub.featuredContentRules">FeaturedContentRule</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.ruleExecutionErrors">RuleExecutionError</a>
</td>
</tr>
<tr>
<td>Search &amp; Investigation
   </td>
<td><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.events">Event</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.entities">Entity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.users.searchQueries">SearchQuery</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.savedColumnSets">SavedColumnSet</a>
</td>
</tr>
<tr>
<td>Exports
   </td>
<td><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.bigQueryExport">BigQueryExportService</a>
</td>
</tr>
<tr>
<td>Enrichment Controls
   </td>
<td><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.enrichmentControls">EnrichmentControl</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances/getEnrichmentCombination">EnrichmentCombination</a>
</td>
</tr>
<tr>
<td>SOAR
   </td>
<td><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases">Case</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases.caseAlerts">CaseAlert</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.caseStageDefinitions">CaseStageDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.caseTagDefinitions">CaseTagDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.caseQueueFilters">CaseQueueFilter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.caseCloseDefinitions">CaseCloseDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases.caseAlerts.connectorEvents">ConnectorEvent</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases.alerts.customFieldValues">CustomFieldValue</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases.caseAlerts.contextProperties">ContextProperty</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases.caseAlerts.involvedEntities">InvolvedEntity</a>,  <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.tasks">Task</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.webhooks">Webhook</a>
<p>
<a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases.caseComments">CaseComment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases.caseWallRecords">CaseWallRecord</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases.chatMessages">ChatMessage</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.views">View</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.ontologyRecords.visualFamilies">VisualFamily</a>,
<p>
<a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases.chatMessages.attachments">ChatMessages.attachment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.cases.customFieldValues">CustomFieldValues</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.contentHub.contentPacks">ContentPack</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.socRoles">SocRole</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.emailTemplates">EmailTemplate</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.dynamicParameters">DynamicParameter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.entitiesBlocklists">EntitiesBlocklist</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.environments">Environment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.environmentGroups">EnvironmentGroup</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations">Integration</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.actions">Integrationaction</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.legacySoarUsers.userNotifications">UserNotification</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.actions.revisions">Integrationactionrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.connectors">Connector</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.connectors.connectorInstances">ConnectorInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.remoteAgents">RemoteAgent</a>,  <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.connectors.connectorInstances.logs">Connectorlog</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.connectors.revisions">Connectorrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.integrationInstances">IntegrationInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.uniqueEntities">UniqueEntity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.jobs">Integrationsjob</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.jobs.jobInstances">JobInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.jobs.jobInstances.logs">JobInstances.log</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.jobs.revisions">Jobs.revision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.managers">Integrationmanager</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.integrations.managers.revisions">Integrationmanagerrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.alertGroupingRules">AlertGroupingRule</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.announcements">Announcement</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.legacySoarUsers.attachments">Attachment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.customLists">CustomList</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.formDynamicParameters">FormDynamicParameter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.labsExperiments">LabsExperiment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.marketplaceIntegrations">MarketplaceIntegration</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.moduleSettings">ModuleSetting</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.slaDefinitions">SlaDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.legacySoarUsers/getNotificationSettings">NotificationSetting</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.propertySchemaDefinitions">PropertySchemaDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.requestTemplates">RequestTemplate</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.soarDomains">SoarDomain</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.soarNetworks">SoarNetwork</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.legacySoarUsers.workdeskLinks">WorkdeskLink</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.systemNotifications">SystemNotification</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.legacySoarUsers.workdeskContacts">WorkdeskContact</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.legacySoarUsers.workdeskNotes">WorkdeskNote</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1beta/projects.locations.instances.legacySoarUsers/getLocalization">LegacySoarUsers.localization</a>.
   </p></p></td>
</tr>
</table>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Feature</h3>
<p><strong>SentinelOneV2</strong>: Version 50.0</p>
<ul>
<li><p>The following new job has been added:</p>
<ul>
<li><strong>Sync Threats</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>CrowdStrike Falcon</strong>: Version 76.0</p>
<ul>
<li><p>The following new job has been added:</p>
<ul>
<li><strong>Sync Alerts</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 64.0</p>
<ul>
<li><p>Added support for disabling overflow settings and updated ticket processing
and environment mapping logic in the following connector:</p>
<ul>
<li><strong>ServiceNow Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Zscaler</strong>: Version 14.0</p>
<ul>
<li><p>Added the ability to provide IOCs using input parameters to the following
actions:</p>
<ul>
<li><p><strong>Add To Blacklist</strong></p></li>
<li><p><strong>Add To Whitelist</strong></p></li>
<li><p><strong>Remove From Blacklist</strong></p></li>
<li><p><strong>Remove From Whitelist</strong></p></li>
</ul></li>
<li><p><strong>Integration</strong>: Added support for OAuth authentication.</p></li>
</ul>
<h3>Change</h3>
<p><strong>Mandiant Threat Intelligence</strong>: Version 17.0</p>
<ul>
<li><p>Optimized execution performance and entity processing logic in the following
action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Looker</h2>
<h3>Breaking</h3>
<p>Migrate your Teams webhook to "Workflows"</p>
<p>Microsoft is <a href="https://mc.merill.net/message/MC1181996">retiring</a> the legacy Office 365 Connectors in favor of Power Automate Workflows. Connectors will stop working by the end of April 2026. To ensure that your Looker alerts continue to deliver to Teams, you must replace your current webhook URL with a new "Workflow" URL. For more information, see the <a href="https://docs.cloud.google.com/looker/docs/best-practices/migrate-teams-webhook-to-workflows">Migrate your Teams webhook to "Workflows"</a> Best Practices notice.</p>
<h2 class="release-note-product-title">Memorystore for Valkey</h2>
<h3>Feature</h3>
<p>Memorystore for Valkey has new <a href="https://docs.cloud.google.com/memorystore/docs/valkey/instance-node-specification">node types</a> that you can select for your instances. This feature is <a href="https://docs.cloud.google.com/products#product-launch-stages">Generally Available</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Change</h3>
<p>When you activate Security Command Center Standard or Premium tier for a project, several
<a href="https://docs.cloud.google.com/security-command-center/docs/activate-scc-for-a-project#services">services</a> are
automatically enabled and <a href="https://docs.cloud.google.com/iam/docs/service-account-types#service-specific">service-specific service
agents</a> are provisioned with
the required IAM roles and permissions.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/security-command-center/docs/activate-scc-for-a-project#project-activation-scc-inactive-in-org">Activate for a project when Security Command Center is not active in the organization</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 14, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#April_14_2026</id>
    <updated>2026-04-14T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#April_14_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Breaking</h3>
<p>As of April 10, 2026, you can create, run, and edit
<a href="https://docs.cloud.google.com/cloud-assist/investigations">Gemini Cloud Assist investigations</a>
only if you have a <a href="https://cloud.google.com/support/premium">Premium Support contract</a>.
You can use Gemini Cloud Assist investigations to
<a href="https://docs.cloud.google.com/alloydb/docs/monitor-troubleshoot-with-ai">monitor and troubleshoot your AlloyDB for PostgreSQL instance with AI assistance</a>.</p>
<p>If you ran an investigation prior to April 10, 2026, then the results of the
investigation continue to be available to you in the Google Cloud console.</p>
<h2 class="release-note-product-title">Cloud Deploy</h2>
<h3>Change</h3>
<p>Support for <a href="https://docs.cloud.google.com/deploy/docs/run-targets">deploying Cloud Run worker pools</a> is now
generally available
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<h2 class="release-note-product-title">Cloud Hub</h2>
<h3>Feature</h3>
<p>The Deployments page supports viewing
<a href="https://docs.cloud.google.com/hub/docs/deployments#view-deployments">recent application deployments</a> to
Google Kubernetes Engine (GKE) and Cloud Run.</p>
<h2 class="release-note-product-title">Cloud Interconnect</h2>
<h3>Feature</h3>
<p>Partner Cross-Cloud Interconnect for Amazon Web Services (AWS) with VPC Network
Peering is Generally Available.</p>
<p>Network Connectivity Center (NCC) support for Partner Cross-Cloud Interconnect
for Amazon Web Services (AWS) is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/network-connectivity/docs/interconnect/concepts/partner-cci-for-aws-overview">Partner Cross-Cloud Interconnect for AWS overview</a>. For available locations, see <a href="https://docs.cloud.google.com/network-connectivity/docs/interconnect/how-to/partner-cci-for-aws/paired-locations">Choose a paired location</a>.</p>
<h2 class="release-note-product-title">Cloud Run</h2>
<h3>Feature</h3>
<p>Support for <a href="https://docs.cloud.google.com/run/docs/deploy-worker-pools">worker pools</a> is in <a href="https://cloud.google.com/products#product-launch-stages">General Availability (GA)</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Breaking</h3>
<p>As of April 10, 2026, you can create, run, and edit
<a href="https://docs.cloud.google.com/cloud-assist/investigations">Gemini Cloud Assist investigations</a> only
if you have a <a href="https://cloud.google.com/support/premium">Premium Support contract</a>.
You can use Gemini Cloud
Assist investigations to <a href="https://docs.cloud.google.com/sql/docs/mysql/monitor-troubleshoot-with-ai">monitor and troubleshoot your
Cloud SQL instance with AI assistance</a>.</p>
<p>If you ran an investigation prior to April 10, 2026,
then the results of the investigation continue to be
available to you in the Google Cloud console.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Breaking</h3>
<p>As of April 10, 2026, you can create, run, and edit
<a href="https://docs.cloud.google.com/cloud-assist/investigations">Gemini Cloud Assist investigations</a> only
if you have a <a href="https://cloud.google.com/support/premium">Premium Support contract</a>.
You can use Gemini Cloud
Assist investigations to <a href="https://docs.cloud.google.com/sql/docs/postgres/monitor-troubleshoot-with-ai">monitor and troubleshoot your
Cloud SQL instance with AI assistance</a>.</p>
<p>If you ran an investigation prior to April 10, 2026,
then the results of the investigation continue to be
available to you in the Google Cloud console.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Breaking</h3>
<p>As of April 10, 2026, you can create, run, and edit
<a href="https://docs.cloud.google.com/cloud-assist/investigations">Gemini Cloud Assist investigations</a> only
if you have a <a href="https://cloud.google.com/support/premium">Premium Support contract</a>.
You can use Gemini Cloud
Assist investigations to <a href="https://docs.cloud.google.com/sql/docs/sqlserver/monitor-troubleshoot-with-ai">monitor and troubleshoot your
Cloud SQL instance with AI assistance</a>.</p>
<p>If you ran an investigation prior to April 10, 2026,
then the results of the investigation continue to be
available to you in the Google Cloud console.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Security</h3>
<p>A vulnerability (CVE-2025-54510) about AMD SEV-SNP guest memory integrity has been addressed.
For more information, see the <a href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-019">GCP-2026-019 security bulletin</a>.</p>
<h3>Security</h3>
<p>A vulnerability affecting AMD SEV-SNP Confidential VM instances was discovered
and has been addressed. For more information, see the
<a href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-021">GCP-2026-021 security bulletin</a>.</p>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Hyperdisk ML disks are supported by the following machine
series:</p>
<ul>
<li><a href="https://docs.cloud.google.com/compute/docs/general-purpose-machines#c3_disks">C3 bare metal</a></li>
<li><a href="https://docs.cloud.google.com/compute/docs/general-purpose-machines#supported_disk_types_for_c4">C4</a>,
including bare metal instances.</li>
<li><a href="https://docs.cloud.google.com/compute/docs/general-purpose-machines#supported_disk_types_for_c4a">C4A bare metal instances</a></li>
<li><a href="https://docs.cloud.google.com/compute/docs/general-purpose-machines#supported_disk_types_for_n4a">N4A</a></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/compute/docs/disks/hd-types/hyperdisk-ml">Hyperdisk ML overview</a>.</p>
<h2 class="release-note-product-title">Confidential VM</h2>
<h3>Security</h3>
<p>A vulnerability affecting AMD SEV-SNP Confidential VM instances was discovered
and has been addressed. For more information, see the
<a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/security-bulletins#gcp-2026-020">GCP-2026-021 security bulletin</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: New data stores (Public Preview)</strong></p>
<p>The following data store are available in Gemini Enterprise:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/clinicaltrials">Clinical Trials</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/crypto">Crypto</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/excalidraw">Excalidraw</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/godaddy">GoDaddy</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/granted">Granted</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/huggingface">Hugging Face</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/invideo">Invideo</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/kiwi">Kiwi</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/lastminute">LastMinute</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/microsoft-learn">Microsoft Learn</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/trivago">Trivago</a></li>
</ul>
<p>These data stores are in Public Preview. For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/connect-third-party-data-source">Connect a
third-party data source</a>.</p>
<h2 class="release-note-product-title">Generative AI on Vertex AI</h2>
<h3>Feature</h3>
<p><strong>Anthropic's Claude Opus 4.7</strong></p>
<p><a href="https://docs.cloud.google.com/vertex-ai/generative-ai/docs/partner-models/claude/opus-4-7">Claude Opus 4.7</a>
is available in Model Garden.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Advance reporting dashboards prerelease notes</strong></p>
<p>Here are the pre-release notes for updates to the advanced reporting dashboards.
When we release these updates, we expect the new capabilities to be as shown
here.</p>
<h3>Feature</h3>
<p><strong>Added a Location filter to dashboards</strong></p>
<p>The following dashboards now include a <strong>Location</strong> filter:</p>
<ul>
<li><p><strong>Real-time Channel Performance</strong></p></li>
<li><p><strong>Transfers</strong></p></li>
<li><p><strong>Queue Interval</strong></p></li>
</ul>
<h3>Feature</h3>
<p><strong>Queue Performance dashboard improvements</strong></p>
<p>We've made the following improvements to the <strong>Queue Performance - Calls</strong> and
<strong>Queue Performance - Chats</strong> dashboards:</p>
<ul>
<li><p>Added the dashboards to the Advanced Reporting Landing Page.</p></li>
<li><p>Added a <strong>Support Phone Number</strong> filter.</p></li>
<li><p>Renamed the <strong>Total Inbound Handled</strong> tile (calls only) to <strong>Total Queue
Answered</strong>.</p></li>
<li><p>Added a <strong>Total Failed</strong> tile.</p></li>
<li><p>In the <strong>Queue Summary</strong> table, removed the <strong>Total Inbound Calls Handled</strong>
column and added the following columns: <strong>Total Queue Interactions</strong>,
<strong>Total Queue Entries</strong>, <strong>Total Queue Answered</strong>, <strong>Total Failed</strong>, and
<strong>Total Transfers</strong>.</p></li>
</ul>
<h3>Feature</h3>
<p><strong>General dashboard updates</strong></p>
<ul>
<li><p>In the <strong>Performance Overview</strong> dashboard, we renamed the following tiles:</p>
<ul>
<li><p><strong>Queued Now</strong> to <strong>Current Queued Now</strong></p></li>
<li><p><strong>Max Queue Time</strong> to <strong>Current Max Queue Time</strong></p></li>
</ul></li>
<li><p>The <strong>Real-time Connected - Calls</strong> and <strong>Real-time Connected - Chats</strong>
dashboards now include the following tiles:</p>
<ul>
<li><p><strong>Total Connected Calls</strong> (calls only)</p></li>
<li><p><strong>Total Connected Chats</strong> (chats only)</p></li>
<li><p><strong>Avg Current Sentiment Score</strong></p></li>
</ul></li>
<li><p>In the <strong>Queue Group Performance - All</strong> dashboard, we renamed the <strong>Lang</strong>
filter to <strong>Language</strong>.</p></li>
</ul>
<h3>Fixed</h3>
<p>The following issues were addressed in this release:</p>
<ul>
<li><p>Fixed an issue where the CSAT scores in the <strong>Performance Overview</strong> and
<strong>CSAT</strong> dashboards didn't match.</p></li>
<li><p>Fixed an issue where the <strong>Queue Performance</strong> dashboard incorrectly totaled
queue interactions, resulting in lower counts than expected.</p></li>
<li><p>Fixed an issue in the <strong>All Interactions - Chat</strong> dashboard where the
<strong>Virtual Agents Chats</strong> table displayed the wrong chat.</p></li>
<li><p>Fixed an issue in the <strong>All Interactions - Chat</strong> dashboard where the
<strong>Failed Interaction</strong> column of the <strong>Chat Metric Detail</strong> table displayed
<code>False</code> for a failed interaction.</p></li>
<li><p>Fixed an issue where the <strong>Chat ID</strong> filter on the <strong>Queue Performance -
Chats</strong> dashboard incorrectly displayed placeholder values.</p></li>
<li><p>Fixed an issue where scheduled exports of large queries were limited to 500
rows, causing reporting delays.</p></li>
<li><p>Fixed an issue in the <strong>Historical Data</strong> table of the <strong>Agent Activity</strong>
dashboard where the <strong>Start Time</strong> and <strong>End Time</strong> columns indicated
incorrect durations for agents belonging to multiple teams.</p></li>
<li><p>Fixed an issue where short abandoned calls and chats were incorrectly
included in the <strong>Abandons</strong> dashboard, causing inaccurate reporting of
queue abandon times.</p></li>
<li><p>Fixed an issue where dashboard windows didn't fully display their contents.</p></li>
</ul>
<h2 class="release-note-product-title">Network Connectivity Center</h2>
<h3>Feature</h3>
<p>Network Connectivity Center (NCC) support for
<a href="https://docs.cloud.google.com/network-connectivity/docs/network-connectivity-center/concepts/overview#partner-cross-cloud-interconnect-spokes">Partner Cross-Cloud Interconnect for Amazon Web Services (AWS)</a>
is available in <a href="https://cloud.google.com/products#product-launch-stages">public preview</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/cloud-run-threat-detection-overview">Cloud Run Threat Detection</a> monitors
<a href="https://docs.cloud.google.com/run/docs/resource-model#workerpools">Cloud Run worker pools</a>.
For a list of resources that Cloud Run Threat Detection monitors, see <a href="https://docs.cloud.google.com/security-command-center/docs/cloud-run-threat-detection-overview#supported-resources">Supported
resources</a>.</p>
]]>
    </content>
  </entry>

</feed>
