<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:gcp-release-notes</id>
  <title>Google Cloud Platform (GCP) - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/gcp-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-08-04T00:00:00-07:00</updated>

  <entry>
    <title>August 04, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#August_04_2026</id>
    <updated>2026-08-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#August_04_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Cloud CDN</h2>
<h3>Feature</h3>
<p>Cloud CDN supports native image optimization at the Google network edge
for global external Application Load Balancers. This feature offloads
compute-intensive image transformations, such as resizing, cropping,
and format conversion to reduce origin server load and egress costs.
This feature is in <strong>Preview</strong>.</p>
<aside class="note"><strong>Note:</strong><span> During the Preview phase, image optimization is available free of charge.
Charges will apply once it becomes Generally Available (GA).</span></aside>
<p>For more information, see <a href="https://docs.cloud.google.com/cdn/docs/imageoptimization">Optimize images with Cloud CDN</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 03, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#August_03_2026</id>
    <updated>2026-08-03T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#August_03_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">API Gateway</h2>
<h3>Feature</h3>
<p><strong>Route LLM requests with model routing</strong></p>
<p>You can now use model routing in API Gateway as a managed traffic management layer to accept OpenAI-compatible prompt requests, transcode them in-flight, and route them to specific foundation models in Vertex AI Model Garden (including Gemini, Anthropic Claude, and OpenAI GPT models).</p>
<p>Key benefits and capabilities include:</p>
<ul>
<li><strong>Centralized traffic management</strong>: Consolidate AI traffic routing and lifecycle management at the network edge without hosting standalone client-side proxies.</li>
<li><strong>In-flight transcoding</strong>: Standardize client applications on an OpenAI-compatible REST interface while dynamically dispatching requests to diverse underlying Vertex AI Model Garden endpoints.</li>
<li><strong>OpenAPI 3.x configuration</strong>: Define model routing tables, explicit routing rules, and default model fallbacks using the new <code>x-google-api-management.ai.models.routing</code> and <code>x-google-model-router</code> OpenAPI 3.x extensions.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/api-gateway/docs/model-routing-overview">Overview of model routing</a> and <a href="https://docs.cloud.google.com/api-gateway/docs/model-routing-configure">Configure model routing</a>.</p>
<h2 class="release-note-product-title">Backup and DR</h2>
<h3>Feature</h3>
<p>You can now change the backup plan associated with a Cloud SQL instance. This allows you to switch an instance to a different backup plan, provided the new plan uses the same backup vault and is in the same region as the instance. This feature is available through the Google Cloud console and <a href="https://docs.cloud.google.com/sdk/gcloud">gcloud CLI</a>. To learn more, see <a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/cloud-console/sql/csql-backup#change-plan">Change the associated backup plan for a Cloud SQL instance</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can now use
<a href="https://docs.cloud.google.com/bigquery/docs/cross-cloud-connections">cross-cloud connections</a> to query data
in AWS, Azure, and Salesforce Data 360 from all BigQuery regions. These
connections let you use more BigQuery features and are more cost efficient than
standard connections that use BigQuery Omni. This feature is in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>The JDBC driver for BigQuery now supports
<a href="https://docs.cloud.google.com/bigquery/docs/jdbc-for-bigquery#opentelemetry">OpenTelemetry</a> for tracing and
logging, which helps you monitor the performance of your database interactions
and troubleshoot issues.
<a href="https://docs.cloud.google.com/bigquery/docs/jdbc-for-bigquery#zero-config-gcp-telemetry">Automatic exports to Google Cloud Observability</a>
are also available. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Announcement</h3>
<p>Support for hybrid search (using the <code>VECTOR_SEARCH</code> function to combine a
semantic search with a lexical (keyword) search) has been restored. Using
<code>HYBRID</code> mode in the <code>AI.SEARCH</code> function has also been restored.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Change</h3>
<p>You can change the backup plan for your
<a href="https://docs.cloud.google.com/sql/docs/mysql/backup-recovery/manage-enhanced-backups">Cloud SQL enhanced backups</a>
without first removing the existing plan.
For more information, see
<a href="https://docs.cloud.google.com/sql/docs/mysql/backup-recovery/manage-enhanced-backups#change-plan">Change your instance's associated backup plan</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Change</h3>
<p>You can change the backup plan for your
<a href="https://docs.cloud.google.com/sql/docs/postgres/backup-recovery/manage-enhanced-backups">Cloud SQL enhanced backups</a>
without first removing the existing plan.
For more information, see
<a href="https://docs.cloud.google.com/sql/docs/postgres/backup-recovery/manage-enhanced-backups#change-plan">Change your instance's associated backup plan</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Change</h3>
<p>You can change the backup plan for your
<a href="https://docs.cloud.google.com/sql/docs/sqlserver/backup-recovery/manage-enhanced-backups">Cloud SQL enhanced backups</a>
without first removing the existing plan.
For more information, see
<a href="https://docs.cloud.google.com/sql/docs/sqlserver/backup-recovery/manage-enhanced-backups#change-plan">Change your instance's associated backup plan</a>.</p>
<h2 class="release-note-product-title">Cloud Workstations</h2>
<h3>Change</h3>
<p>Updated the following
<a href="https://docs.cloud.google.com/workstations/docs/preconfigured-base-images#list_of_preconfigured_base_images">JetBrains preconfigured base images</a>
to version 2026.x:</p>
<ul>
<li><a href="https://youtrack.jetbrains.com/articles/CPP-A-230654453/CLion-2026.1">CLion 2026.1</a></li>
<li><a href="https://youtrack.jetbrains.com/articles/GO-A-231736055/GoLand-2026.2">GoLand 2026.2</a></li>
<li><a href="https://youtrack.jetbrains.com/articles/IDEA-A-2100662608/IntelliJ-IDEA-2026.1-Latest-Builds">IntelliJ Ultimate 2026.1</a></li>
<li><a href="https://youtrack.jetbrains.com/articles/WI-A-231736318/PhpStorm-2026.2">PhpStorm 2026.2</a></li>
<li><a href="https://youtrack.jetbrains.com/articles/WEB-A-233538705/WebStorm-2026.1">WebStorm 2026.1</a></li>
<li><a href="https://youtrack.jetbrains.com/articles/RUBY-A-220365320/RubyMine-2026.1">RubyMine 2026.1</a></li>
<li><a href="https://youtrack.jetbrains.com/articles/PY-A-233538506/PyCharm-2026.1">PyCharm 2026.1</a></li>
<li><a href="https://youtrack.jetbrains.com/issues?q=project:%20Rider%20%7B2026.1%7D">Rider 2026.1</a></li>
</ul>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Advanced reporting dashboards prerelease notes</strong></p>
<p>Here are the pre-release notes for updates to the advanced reporting dashboards.
When we release these updates, we expect the new capabilities to be as shown
here.</p>
<h3>Feature</h3>
<p><strong>Sub teams are included when top-level teams are selected in the Team filter</strong></p>
<p>When you select a team in a <strong>Team</strong> filter on a dashboard, the data for that
team's sub-teams is now included.</p>
<h3>Feature</h3>
<p><strong>The Agent Performance dashboard contains the average chat concurrency metric</strong></p>
<p>The <strong>Agent Performance</strong> dashboard now contains the average chat concurrency
metric to capture concurrency trends for agents, teams, and queues.</p>
<h3>Feature</h3>
<p><strong>Metrics for warm transfers and agent consultations</strong></p>
<p>The <strong>Transfers - Calls</strong> and <strong>Transfers - Chats</strong> dashboards now have the
following metrics in the <strong>Call Transfers</strong> and <strong>Chat Transfers</strong> tables:</p>
<ul>
<li><p><strong>Agent Connection Time (H:M:S)</strong>. Reports the time spent consulting with
another agent and then warm transferring to that agent.</p></li>
<li><p><strong>Agent Consult Time (H:M:S)</strong>. Reports the time spent consulting with
another agent before returning to the call.</p></li>
</ul>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where the <strong>This Week</strong> and <strong>This Month</strong> per-hour figures
on the <strong>Performance Overview</strong> and <strong>Agent Performance</strong> dashboards were
inaccurate.</p></li>
<li><p>Fixed an issue where the <strong>Queue Abandons</strong> and <strong>Abandon %</strong> fields on the
<strong>Queue Group Performance - All</strong> and <strong>Queue Group Performance - Chats</strong>
dashboards always displayed <code>0</code> for chats.</p></li>
<li><p>Fixed an issue where the virtual agent call metrics on the <strong>Virtual Agent -
Calls</strong>, <strong>All Interactions - Calls</strong>, and <strong>Performance Overview</strong>
dashboards were incorrect.</p></li>
<li><p>Fixed an issue where agents appeared under <strong>Assigned Agent</strong> for calls that
they weren't connected to.</p></li>
<li><p>Fixed an issue where exporting data from dashboards using date ranges
greater than seven days failed.</p></li>
<li><p>Fixed an issue in the <strong>Real-time Queue Monitoring</strong> and <strong>Queued Calls</strong>
dashboards where transferred calls were incorrectly displayed as <strong>Queued</strong>
when they were active with an agent.</p></li>
<li><p>Fixed an issue where queue groups that were turned off remained visible in
advanced reporting dashboards.</p></li>
<li><p>Fixed an issue where the <strong>Queue Time</strong> filter on the <strong>All Interactions</strong>
dashboard wasn't displaying data.</p></li>
<li><p>Fixed an issue where the <strong>SLA Target</strong> field in the <strong>Queue Group
Performance - All</strong> dashboard was empty.</p></li>
<li><p>Fixed an issue where the <strong>No</strong> checkbox of the <strong>Child Queues</strong> filter
disappeared when cleared. No child queues is the default for this filter, so
we removed the <strong>No</strong> checkbox, leaving only the <strong>Yes</strong> checkbox.</p></li>
<li><p>Fixed an issue where the <strong>Available Agents</strong> field overstated real capacity.</p></li>
<li><p>Fixed an issue on the <strong>Queue Groups - Calls</strong> and <strong>Queue Groups - Chats</strong>
dashboards where the <strong>Ave Current Queue Time</strong> metric displayed incorrect
data.</p></li>
<li><p>For time-related exports, there's now a column that displays time in
HH:MM:SS format (in addition to seconds). You can't apply conditional
formatting to this format in an Explore.</p></li>
<li><p>Fixed an issue where <strong>Max Queue Wait Time</strong>, <strong>Max Speed To Answer</strong>, and
<strong>Max Queue Abandon Time</strong> displayed incorrect data in Explores.</p></li>
<li><p>Fixed an issue where changes to an agent's availability preferences in the
agent adapter weren't reflected in the <strong>Agent Activity</strong> dashboard.</p></li>
<li><p>Updated the labels in the <strong>Agent Metrics (Historical)</strong> Explore to be
channel-agnostic for metrics that include both calls and chats.</p></li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>TPU Subslicing (also known as Dynamic Subslicing) is now generally available for
Ironwood (TPU7x). This feature enables you to incrementally provision node pools
for a cube or litepod, breaking them into smaller slices (subslices) to run
workloads requiring smaller topologies. Updates in this GA release include:</p>
<ul>
<li><strong>Dynamic sub-slicing</strong> (topologies smaller than <code>4x4x4</code>, such as <code>2x2x1</code>,
<code>2x2x2</code>, <code>2x2x4</code>, and <code>2x4x4</code>): Supported in GKE version
<code>1.36.0-gke.3712000</code> or later.</li>
<li><strong>Dynamic super-slicing</strong> (topologies <code>4x4x4</code> or larger): Supported in GKE
version <code>1.35.2-gke.1842000</code> or later.</li>
<li><strong>Partition Health Labels</strong>: The partition state label is updated to
<code>cloud.google.com/gke-tpu-partition-[shape]-state</code> to specify smaller
subslice shapes. It also introduces <code>UNSET</code> and <code>INCOMPLETE</code> states. Support
for the <code>DEGRADED</code> state only applies to the top-level <code>4x4x4</code> topology, and
not for smaller sub-slicing topologies.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/dynamic-slicing">About GKE dynamic slicing</a>.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Threat Hunt Agent</strong></p>
<p>The Threat Hunt Agent is now available in Public Preview for Google SecOps Enterprise Plus customers. Powered by Gemini and grounded in Google Threat Intelligence (GTI), Mandiant frontline expertise, and the MITRE ATT&amp;CK® framework, the Threat Hunt Agent autonomously automates proactive threat hunting across your historical security telemetry. For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/detection/threat-hunt-agent">Threat Hunt Agent</a>.</p>
<p>Key capabilities include:</p>
<ul>
<li><strong>Autonomous hunt planning:</strong> Generates structured hunting plans tailored to specific threat actors, campaigns, malware families, software toolkits, or MITRE ATT&amp;CK techniques.</li>
<li><strong>Automated case creation and determinations:</strong> Synthesizes findings into summaries, assigns a verdict (Substantial Evidence, Evidence Found, or Threat Not Found), and automatically creates a dedicated case in Case Management.</li>
<li><strong>Automated query translation and execution:</strong> Converts investigative hypotheses into YARA-L 2.0  search queries and executes against historical security telemetry.</li>
<li><strong>AI-driven evidence extraction:</strong> Filters out routine background noise to isolate high-fidelity forensic evidence (hostnames, user accounts, and command lines).</li>
</ul>
<h3>Announcement</h3>
<p>The deadline for Stage 2 of the SOAR migration to Google Cloud has been extended from September 30th to November 30th, 2026.
For more information, refer to the <a href="https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/migrate-to-gcp">SOAR migration guide</a>.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Analyze feed activity with Cloud Logging</strong></p>
<p>This feature is in public preview. You can now monitor, debug, and troubleshoot Google SecOps SIEM ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.</p>
<p>This visibility into push- and pull-based ingestion mechanisms lets you use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console. Additionally, you can use the <strong>Debug with logs</strong> option on the <strong>Feed management</strong> page to open <strong>Logs Explorer</strong> pre-filtered for a specific feed.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/analyze-feed-activity-with-cloud-logging">Analyze feed activity with Cloud Logging</a>.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>The deadline for Stage 2 of the SOAR migration to Google Cloud has been extended from September 30th to November 30th, 2026.
For more information, refer to the <a href="https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/migrate-to-gcp">SOAR migration guide</a>.</p>
<h2 class="release-note-product-title">Identity and Access Management</h2>
<h3>Feature</h3>
<p>Organization Policy Service custom constraints are available for
Privileged Access Manager (PAM). You can use custom constraints to restrict how users create
and modify entitlements and grants. This feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/iam/docs/pam-custom-constraints">Use custom organization policies for
Privileged Access Manager</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p>For the Security Command Center Standard tier,
<a href="https://docs.cloud.google.com/security-command-center/docs/ai-protection-overview">AI Protection</a> is supported
for both projects and organizations.</p>
<p>Project-level activations for the Standard tier include access to the <a href="https://docs.cloud.google.com/security-command-center/docs/assess-risk#ai-protection">AI security
dashboard</a>, basic inventory view (excluding Gemini models), and
baseline security findings.</p>
<p>Some features of AI Protection are only available for the Premium
and Enterprise tiers or for organization-level activations. For more information, see
<a href="https://docs.cloud.google.com/security-command-center/docs/configure-ai-protection">Configure AI Protection</a>.</p>
<h2 class="release-note-product-title">VPC Service Controls</h2>
<h3>Feature</h3>
<p><a href="https://cloud.google.com/products#product-launch-stages">Preview stage</a> support for the following integration:</p>
<ul>
<li><a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_gemini_enterprise_antigravity">Google Antigravity in Gemini Enterprise</a></li>
</ul>
<h2 class="release-note-product-title">Virtual Private Cloud</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: You can create v2 IPv4 public advertised prefixes for
bring your own IP addresses (BYOIP) that use
<a href="https://docs.cloud.google.com/network-tiers/docs/overview#standard_tier">Standard Tier</a> IP addresses.
For more information, see <a href="https://docs.cloud.google.com/vpc/docs/bring-your-own-ip#service-tiers">Network Service Tiers</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 02, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#August_02_2026</id>
    <updated>2026-08-02T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#August_02_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.96 is being rolled out to the first phase of regions as listed
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 01, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#August_01_2026</id>
    <updated>2026-08-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#August_01_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: Google Cloud VMware Engine capacity allocations are available in preview. A capacity
allocation is a global reservation of physical nodes for your Cloud Billing account.
Your reserved nodes are organized into placement groups (PGs), which represent the specific physical
hardware and location of your reserved capacity.</p>
<p>Google Cloud VMware Engine capacity allocations let you do the following:
*   Use a capacity allocation during private cloud creation by selecting a PG.
*   Use a capacity allocation when adding a cluster.
*   Configure a hybrid private cloud across multiple PGs.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/vmware-engine/docs/private-clouds/howto-manage-capacity-allocations">Manage capacity allocations</a>.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_26_2026">Release 6.3.95</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 31, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_31_2026</id>
    <updated>2026-07-31T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_31_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1157">v1.15.7</h3>
<p>On July 31, 2026 we released an updated version of the Apigee hybrid software, v1.15.7.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.7</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Runtime rollout strategy configuration</strong></p>
<p>In this release, you can configure the rollout strategy used when updating runtime (message processor) ReplicaSets by setting the <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/config-prop-ref#runtime-release-strategy"><code>runtime.release.strategy</code></a> property (with options <code>rolling</code>, <code>scale-down-first</code>, or <code>none</code>) or per-environment with <code>envs[].components.runtime.release.strategy</code> in your overrides configuration file. The property defaults to <code>rolling</code>.</p>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>Cloud Load Balancing introduces a new version of the Network Load
Balancer—the global external passthrough Network Load Balancer, which is the global variant of the
regional external passthrough Network Load Balancer. The load balancer is available in <strong>Preview</strong>.</p>
<p>This load balancer variant solves use cases for Security Service Edge (SSE), DNS
hosting, Adtech (real-time bidding), real-time communications (RTC), live
streaming, and online gaming, among others.</p>
<p>Global external passthrough Network Load Balancers are Layer 4 passthrough load balancers that
distribute external traffic among backends (instance groups or network endpoint
groups) that can reside in multiple Google Cloud regions. By using
Google's global anycast IP routing, the global external passthrough Network Load Balancer steers
user traffic to the closest region with healthy backends and available capacity,
delivering ultra-low latency and dynamic cross-region failover
to ensure resilience to regional outages.</p>
<p>The load balancer provides you with two external IP addresses, each served by a
disjoint and isolated global load balancing control and data plane server
infrastructure (also known as an <em>availability group</em>) to provide high
availability.</p>
<p>The load balancer supports 
TCP, UDP, ESP, GRE, ICMP, and ICMPv6
 traffic and can
handle both IPv4 and IPv6 traffic. You can deploy your
backends in any of the following Google Cloud regions:</p>
<ul>
<li>North America: <code>us-west1</code>, <code>us-west4</code>, <code>us-east4</code>, <code>us-east5</code></li>
<li>Europe: <code>europe-west2</code>, <code>europe-west3</code></li>
<li>Asia: <code>asia-southeast1</code>, <code>asia-south1</code>, <code>asia-northeast1</code></li>
<li>South America: <code>southamerica-east1</code></li>
<li>Africa: <code>africa-south1</code></li>
<li>Australia: <code>australia-southeast1</code></li>
</ul>
<p>Note that this release doesn't support GKE backends
for the global external passthrough Network Load Balancer.</p>
<p>For details on the new load balancer, see <a href="https://docs.cloud.google.com/load-balancing/docs/network/global-networklb-architecture">Global external passthrough Network Load Balancer overview</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Change</h3>
<p>Starting on August 1, 2026, when you create or clone a Cloud SQL instance
enabled with Private Service Connect, or when you enable Private Service Connect
for an existing instance, then <a href="https://docs.cloud.google.com/vpc/docs/about-controlling-access-published-services#connection-reconciliation">connection reconciliation</a>
behavior is enabled by default and can't be disabled.</p>
<p>When you remove a project from the list of allowed projects, all existing
Private Service Connect connections from the removed project are immediately
closed (reconciled). This means that applications using Private Service
Connect endpoints in those removed projects can't continue to connect to the
Cloud SQL instance using those endpoints.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/mysql/about-private-service-connect#allowed-psc-projects">Allowed Private Service Connect projects</a>.</p>
<h3>Feature</h3>
<p>QueryData adds support for parameterized secure views (PSVs) to help secure
applications that use natural language queries. For more information, see <a href="https://docs.cloud.google.com/gemini/data-agents/querydata/sql-mysql/secure-app-data-parameterized-secure-views-qd">Secure
and control access to application data</a>.</p>
<p>This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Change</h3>
<p>Starting on August 1, 2026, when you create or clone a Cloud SQL instance
enabled with Private Service Connect, or when you enable Private Service Connect
for an existing instance, then <a href="https://docs.cloud.google.com/vpc/docs/about-controlling-access-published-services#connection-reconciliation">connection reconciliation</a>
behavior is enabled by default and can't be disabled.</p>
<p>When you remove a project from the list of allowed projects, all existing
Private Service Connect connections from the removed project are immediately
closed (reconciled). This means that applications using Private Service
Connect endpoints in those removed projects can't continue to connect to the
Cloud SQL instance using those endpoints.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/postgres/about-private-service-connect#allowed-psc-projects">Allowed Private Service Connect projects</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Change</h3>
<p>Starting on August 1, 2026, when you create or clone a Cloud SQL instance
enabled with Private Service Connect, or when you enable Private Service Connect
for an existing instance, then <a href="https://docs.cloud.google.com/vpc/docs/about-controlling-access-published-services#connection-reconciliation">connection reconciliation</a>
behavior is enabled by default and can't be disabled.</p>
<p>When you remove a project from the list of allowed projects, all existing
Private Service Connect connections from the removed project are immediately
closed (reconciled). This means that applications using Private Service
Connect endpoints in those removed projects can't continue to connect to the
Cloud SQL instance using those endpoints.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/sqlserver/about-private-service-connect#allowed-psc-projects">Allowed Private Service Connect projects</a>.</p>
<h3>Feature</h3>
<p>Cloud SQL for SQL Server now supports executing SQL statements using the
<a href="https://docs.cloud.google.com/sql/docs/sqlserver/executesql-instance">Cloud SQL Data API</a>.</p>
<h2 class="release-note-product-title">Confidential VM</h2>
<h3>Security</h3>
<p>Support for <a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/supported-configurations#machine-type-cpu-zone">Intel TDX on <code>c4-standard-*</code> machine types</a> is
available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Contact Center AI Insights</h2>
<h3>Feature</h3>
<p>Customer Experience Insights offers <a href="https://docs.cloud.google.com/contact-center/insights/docs/qai-best-practices">data tracing</a> in Quality AI. This feature uses system events and metadata in conversation analysis to enhance the accuracy of Quality AI scorecards.</p>
<h2 class="release-note-product-title">Dataflow</h2>
<h3>Feature</h3>
<p>You can now pause a Dataflow batch job using the <code>pause_on_failure</code>
service option. This feature lets you preserve the state of your batch pipeline
job, address external issues, and resume processing without losing completed
work. You can use this option to automatically pause a job on failure, or use
this feature to manually pause a job when you chose to. For more information,
see <a href="https://docs.cloud.google.com/dataflow/docs/guides/pause-job">Pause a Dataflow job</a>.</p>
<h2 class="release-note-product-title">Datastream</h2>
<h3>Feature</h3>
<p>You can now replicate change data from Workday with Datastream.
For more information, see
<a href="https://docs.cloud.google.com/datastream/docs/sources-workday">Stream data from Workday</a>.</p>
<p>This feature is in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Google Cloud Managed Service for Apache Kafka</h2>
<h3>Feature</h3>
<p>You can generate synthetic data for a Managed Service for Apache Kafka cluster by using Dataflow. For more information, see <a href="https://docs.cloud.google.com/managed-service-for-apache-kafka/docs/quickstart-synthetic-data">Generate synthetic data for a Managed Service for Apache Kafka cluster</a>.</p>
<h2 class="release-note-product-title">Memorystore for Valkey</h2>
<h3>Feature</h3>
<p>You can use <a href="https://docs.cloud.google.com/memorystore/docs/valkey/use-custom-org-policies">custom organization policies</a> to improve the security, compliance, and governance of your Memorystore for Valkey instances by enforcing consistent configurations and restrictions for the instances. This ensures that your instances adhere to security best practices and regulatory requirements. This feature is <a href="https://docs.cloud.google.com/products#product-launch-stages">Generally Available</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p>Organizations that are enrolled in the data residency Preview program can update their organization's <a href="https://docs.cloud.google.com/security-command-center/docs/data-residency-support">data residency</a> and <a href="https://docs.cloud.google.com/security-command-center/docs/cmek">data encryption</a> configuration.
For more information, see
<a href="https://docs.cloud.google.com/security-command-center/docs/modify-data-residency-encryption">Modify data residency or data encryption configuration</a>.</p>
<h3>Feature</h3>
<p>Agent Platform Vulnerability Assessment (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>) scans for plaintext secrets, such as
credentials, access tokens, and API keys, in customer-deployed Gemini Enterprise Agent Platform containers. For more information,
see <a href="https://docs.cloud.google.com/security-command-center/docs/concepts-security-sources#aevs">Agent Platform Vulnerability Assessment</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 30, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_30_2026</id>
    <updated>2026-07-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_30_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can add tables, views, data sources, and data quality tests as tasks to
BigQuery pipelines. For more information, see
<a href="https://docs.cloud.google.com/bigquery/docs/create-pipelines#add_a_pipeline_task">Add a pipeline task</a>.
This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<h3>Feature</h3>
<p>You can audit when users download query results by using the BigQuery
console. Data Access audit logs for the <code>tabledata.list</code> method now include a
<a href="https://docs.cloud.google.com/bigquery/docs/reference/auditlogs/rest/Shared.Types/BigQueryAuditMetadata.html#BigQueryAuditMetadata.TableDataRead.FIELDS.ui_download_request"><code>uiDownloadRequest</code></a>
field to indicate whether the request was triggered by a UI download.
This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>You can use Bigtable as a remote storage backend for
<a href="https://docs.lmcache.ai/kv_cache/storage_backends/bigtable.html">LMCache</a>. By
storing the large language model (LLM) key-value (KV) cache externally in
Bigtable, multiple AI serving instances can share and reuse precomputed
attention tensors. This reduces compute overhead and significantly improves
time-to-first-token (TTFT) for repeated prompts and shared documents. This
feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Config Connector</h2>
<h3>Announcement</h3>
<p>Config Connector version 1.154.1 is now available.</p>
<h3>Feature</h3>
<p>New Alpha Resources (Direct Reconciler):</p>
<ul>
<li><code>ApigeeApiProduct</code>
<ul>
<li>Manage <a href="https://cloud.google.com/apigee/docs/api-platform/publish/what-api-product">Apigee API products</a> to bundle APIs and make them available to developers.</li>
</ul></li>
<li><code>ApigeeRegistryApi</code>
<ul>
<li>Manage <a href="https://cloud.google.com/apigee/docs/api-hub/registry-overview">Apigee Registry APIs</a> to catalog and manage APIs.</li>
</ul></li>
<li><code>ApigeeRegistryArtifact</code>
<ul>
<li>Manage <a href="https://cloud.google.com/apigee/docs/api-hub/registry-overview">Apigee Registry artifacts</a> associated with APIs, versions, or specs.</li>
</ul></li>
<li><code>APIHubExternalAPI</code>
<ul>
<li>Manage <a href="https://cloud.google.com/apigee/docs/api-hub/api-hub-overview">API Hub external APIs</a> to track APIs hosted outside of Google Cloud.</li>
</ul></li>
<li><code>APIHubInstance</code>
<ul>
<li>Manage <a href="https://cloud.google.com/apigee/docs/api-hub/api-hub-overview">API Hub instances</a> to enable enterprise API management.</li>
</ul></li>
<li><code>AppOptimizeReport</code>
<ul>
<li>Manage <a href="https://cloud.google.com/app-hub/docs/overview">App Hub Optimize reports</a>.</li>
</ul></li>
<li><code>ArtifactRegistryVPCSCConfig</code>
<ul>
<li>Manage <a href="https://cloud.google.com/artifact-registry/docs/vpc-sc">Artifact Registry VPC Service Controls configurations</a> to secure repository access.</li>
</ul></li>
<li><code>BigQueryMigrationMigrationWorkflow</code>
<ul>
<li>Manage <a href="https://cloud.google.com/bigquery/docs/migration-intro">BigQuery Migration workflows</a> to orchestrate data migration to BigQuery.</li>
</ul></li>
<li><code>BlockchainNodeEngineBlockchainNode</code>
<ul>
<li>Manage <a href="https://cloud.google.com/blockchain-node-engine/docs">Blockchain Node Engine blockchain nodes</a> to deploy and manage dedicated blockchain nodes.</li>
</ul></li>
<li><code>CCInsightsConversation</code>
<ul>
<li>Manage <a href="https://cloud.google.com/contact-center/insights/docs">Contact Center Insights conversations</a> to analyze customer interactions.</li>
</ul></li>
<li><code>CCInsightsIssueModel</code>
<ul>
<li>Manage <a href="https://cloud.google.com/contact-center/insights/docs">Contact Center Insights issue models</a> to categorize conversation topics.</li>
</ul></li>
<li><code>CCInsightsPhraseMatcher</code>
<ul>
<li>Manage <a href="https://cloud.google.com/contact-center/insights/docs">Contact Center Insights phrase matchers</a> to detect specific phrases in conversations.</li>
</ul></li>
<li><code>CESApp</code>
<ul>
<li>Manage <a href="https://cloud.google.com/ces/docs">Consumer Experience Suite (CES) applications</a>.</li>
</ul></li>
<li><code>CloudBuildConnection</code>
<ul>
<li>Manage <a href="https://cloud.google.com/build/docs/submitting-builds/git-repos/connect-repo-github">Cloud Build 2nd gen connections</a> to integrate external source repositories.</li>
</ul></li>
<li><code>CloudSecurityComplianceFramework</code>
<ul>
<li>Manage <a href="https://cloud.google.com/security-command-center/docs/compliance-standards">Cloud Security Compliance frameworks</a>.</li>
</ul></li>
<li><code>ConnectorsConnection</code>
<ul>
<li>Manage <a href="https://cloud.google.com/integration-connectors/docs">Integration Connectors connections</a> to connect to SaaS, databases, and enterprise systems.</li>
</ul></li>
<li><code>ContentWarehouseDocument</code>
<ul>
<li>Manage <a href="https://cloud.google.com/document-ai/docs/warehouse">Document AI Warehouse documents</a>.</li>
</ul></li>
<li><code>ContentWarehouseRuleSet</code>
<ul>
<li>Manage <a href="https://cloud.google.com/document-ai/docs/warehouse">Document AI Warehouse rule sets</a> to enforce document policies.</li>
</ul></li>
<li><code>ContentWarehouseSynonymSet</code>
<ul>
<li>Manage <a href="https://cloud.google.com/document-ai/docs/warehouse">Document AI Warehouse synonym sets</a> to expand search queries.</li>
</ul></li>
<li><code>DatabaseMigrationPrivateConnection</code>
<ul>
<li>Manage <a href="https://cloud.google.com/database-migration/docs">Database Migration Service private connections</a> to securely connect source databases to Google Cloud.</li>
</ul></li>
<li><code>DataformFolder</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dataform/docs">Dataform folders</a> in Dataform repositories.</li>
</ul></li>
<li><code>DataformTeamFolder</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dataform/docs">Dataform team folders</a> to organize repository assets.</li>
</ul></li>
<li><code>DataLabelingDataset</code>
<ul>
<li>Manage <a href="https://cloud.google.com/ai-platform/data-labeling/docs">AI Platform Data Labeling datasets</a> for annotating training data.</li>
</ul></li>
<li><code>DataLabelingEvaluationJob</code>
<ul>
<li>Manage <a href="https://cloud.google.com/ai-platform/data-labeling/docs">AI Platform Data Labeling evaluation jobs</a> to assess model quality.</li>
</ul></li>
<li><code>DataLineageProcess</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dataplex/docs/data-lineage">Dataplex Data Lineage processes</a> to track data origin and movement.</li>
</ul></li>
<li><code>DataplexAspectType</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dataplex/docs">Dataplex aspect types</a> to define metadata schemas.</li>
</ul></li>
<li><code>DataplexDataAttributeBinding</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dataplex/docs">Dataplex data attribute bindings</a> to map security and governance attributes to assets.</li>
</ul></li>
<li><code>DataplexDataScan</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dataplex/docs/data-profile-overview">Dataplex data scans</a> for data profiling and quality.</li>
</ul></li>
<li><code>DataplexDataTaxonomy</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dataplex/docs">Dataplex data taxonomies</a> to organize business metadata.</li>
</ul></li>
<li><code>DataplexGlossary</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dataplex/docs">Dataplex business glossaries</a> for consistent vocabulary.</li>
</ul></li>
<li><code>DataplexMetadataJob</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dataplex/docs">Dataplex metadata jobs</a> for metadata extraction.</li>
</ul></li>
<li><code>DevConnectConnection</code>
<ul>
<li>Manage <a href="https://cloud.google.com/developer-connect/docs">Developer Connect connections</a> to securely link third-party Git hosts.</li>
</ul></li>
<li><code>DialogflowConversationDataset</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dialogflow/cx/docs">Dialogflow conversation datasets</a> for agent training.</li>
</ul></li>
<li><code>DialogflowSecuritySettings</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dialogflow/cx/docs">Dialogflow security settings</a> for data redaction and access control.</li>
</ul></li>
<li><code>DialogflowSipTrunk</code>
<ul>
<li>Manage <a href="https://cloud.google.com/dialogflow/cx/docs">Dialogflow SIP trunks</a> for telecom integration.</li>
</ul></li>
<li><code>DiscoveryEngineControl</code>
<ul>
<li>Manage <a href="https://cloud.google.com/generative-ai-app-builder/docs">Discovery Engine controls</a> to boost or filter search results.</li>
</ul></li>
<li><code>DiscoveryEngineSampleQuerySet</code>
<ul>
<li>Manage <a href="https://cloud.google.com/generative-ai-app-builder/docs">Discovery Engine sample query sets</a> to evaluate search performance.</li>
</ul></li>
<li><code>DLPConnection</code>
<ul>
<li>Manage <a href="https://cloud.google.com/security-command-center/docs/sensitive-data-protection">Sensitive Data Protection (DLP) connections</a>.</li>
</ul></li>
<li><code>DLPDiscoveryConfig</code>
<ul>
<li>Manage <a href="https://cloud.google.com/security-command-center/docs/sensitive-data-protection">Sensitive Data Protection (DLP) discovery configurations</a> for profiling data assets.</li>
</ul></li>
<li><code>EventarcGoogleApiSource</code>
<ul>
<li>Manage <a href="https://cloud.google.com/eventarc/docs">Eventarc Google API sources</a> to configure event routing.</li>
</ul></li>
<li><code>GeminiDataAnalyticsConversation</code>
<ul>
<li>Manage <a href="https://cloud.google.com/gemini/docs">Gemini Data Analytics conversations</a>.</li>
</ul></li>
<li><code>GKEBackupBackupChannel</code>
<ul>
<li>Manage <a href="https://cloud.google.com/kubernetes-engine/docs/add-on/backup-for-gke">Backup for GKE backup channels</a>.</li>
</ul></li>
<li><code>LiveStreamAsset</code>
<ul>
<li>Manage <a href="https://cloud.google.com/livestream/docs">Live Stream assets</a> for processing live video.</li>
</ul></li>
<li><code>ManagedKafkaConnectCluster</code>
<ul>
<li>Manage <a href="https://cloud.google.com/managed-kafka/docs">Apache Kafka for BigQuery connections</a>.</li>
</ul></li>
<li><code>MigrationCenterGroup</code>
<ul>
<li>Manage <a href="https://cloud.google.com/migration-center/docs">Migration Center groups</a> to organize assets for migration assessment.</li>
</ul></li>
<li><code>NetworkSecurityAddressGroup</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vpc/docs/configure-firewall-policies-address-groups">Network Security address groups</a> to define reusable network criteria.</li>
</ul></li>
<li><code>NetworkSecurityAuthzPolicy</code>
<ul>
<li>Manage <a href="https://cloud.google.com/secure-web-proxy/docs">Network Security authorization policies</a> to secure network paths.</li>
</ul></li>
<li><code>NetworkSecurityFirewallEndpoint</code>
<ul>
<li>Manage <a href="https://cloud.google.com/firewall/docs/about-cloud-firewall-plus">Network Security firewall endpoints</a> for Cloud Firewall Plus threat inspection.</li>
</ul></li>
<li><code>NetworkSecurityFirewallEndpointAssociation</code>
<ul>
<li>Manage <a href="https://cloud.google.com/firewall/docs/about-cloud-firewall-plus">Network Security firewall endpoint associations</a> to apply threat inspection to networks.</li>
</ul></li>
<li><code>NetworkSecurityGatewaySecurityPolicy</code>
<ul>
<li>Manage <a href="https://cloud.google.com/secure-web-proxy/docs">Network Security gateway security policies</a> for Secure Web Proxy configurations.</li>
</ul></li>
<li><code>NetworkSecurityPartnerSSEGateway</code>
<ul>
<li>Manage <a href="https://cloud.google.com/secure-web-proxy/docs">Network Security partner Secure Service Edge (SSE) gateways</a>.</li>
</ul></li>
<li><code>NetworkSecurityPartnerSSERealm</code>
<ul>
<li>Manage <a href="https://cloud.google.com/secure-web-proxy/docs">Network Security partner Secure Service Edge (SSE) realms</a>.</li>
</ul></li>
<li><code>NetworkSecuritySecurityProfile</code>
<ul>
<li>Manage <a href="https://cloud.google.com/firewall/docs/about-cloud-firewall-plus">Network Security security profiles</a> to group threat prevention policies.</li>
</ul></li>
<li><code>NetworkSecurityTLSInspectionPolicy</code>
<ul>
<li>Manage <a href="https://cloud.google.com/secure-web-proxy/docs/configure-tls-inspection">Network Security TLS inspection policies</a> to inspect encrypted traffic.</li>
</ul></li>
<li><code>NetworkServicesAuthzExtension</code>
<ul>
<li>Manage <a href="https://cloud.google.com/service-extensions/docs">Network Services authorization extensions</a> to integrate third-party callouts.</li>
</ul></li>
<li><code>NotebooksSchedule</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vertex-ai/docs/workbench">Vertex AI Workbench schedules</a> to run automated notebooks.</li>
</ul></li>
<li><code>RedisClusterEndpoint</code>
<ul>
<li>Manage <a href="https://cloud.google.com/memorystore/docs/cluster">Google Cloud Memorystore for Redis Cluster endpoints</a>.</li>
</ul></li>
<li><code>RunWorkerPool</code>
<ul>
<li>Manage <a href="https://cloud.google.com/run/docs">Cloud Run worker pools</a> for long-running non-HTTP workloads.</li>
</ul></li>
<li><code>SaasServiceMgmtRelease</code>
<ul>
<li>Manage <a href="https://cloud.google.com/service-infrastructure/docs">SaaS Service Management releases</a>.</li>
</ul></li>
<li><code>SQLAdminBackup</code>
<ul>
<li>Manage <a href="https://cloud.google.com/sql/docs">Cloud SQL backups</a> (read-only/reference representation).</li>
</ul></li>
<li><code>StorageInsightsDatasetConfig</code>
<ul>
<li>Manage <a href="https://cloud.google.com/storage/docs/insights/using-storage-insights">Storage Insights dataset configurations</a> to generate storage inventories.</li>
</ul></li>
<li><code>TestingDeviceSession</code>
<ul>
<li>Manage <a href="https://firebase.google.com/docs/test-lab">Firebase Test Lab device sessions</a>.</li>
</ul></li>
<li><code>TranslateAdaptiveMtDataset</code>
<ul>
<li>Manage <a href="https://cloud.google.com/translate/docs/adaptive-mt">Cloud Translation adaptive machine translation datasets</a>.</li>
</ul></li>
<li><code>VectorSearchCollection</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vertex-ai/docs/vector-search">Vertex AI Vector Search collections</a>.</li>
</ul></li>
<li><code>VertexAIFeatureGroup</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vertex-ai/docs/featurestore/overview">Vertex AI Feature Store feature groups</a> to organize features.</li>
</ul></li>
<li><code>VertexAIFeatureOnlineStore</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vertex-ai/docs/featurestore/overview">Vertex AI Feature Store feature online stores</a> for low-latency serving.</li>
</ul></li>
<li><code>VertexAIPipelineJob</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vertex-ai/docs/pipelines">Vertex AI pipeline jobs</a> to run machine learning pipelines.</li>
</ul></li>
<li><code>VertexAISpecialistPool</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vertex-ai/docs">Vertex AI specialist pools</a> for human labeling.</li>
</ul></li>
<li><code>VertexAIStudy</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vertex-ai/docs/vizier">Vertex AI Vizier studies</a> for hyperparameter tuning.</li>
</ul></li>
<li><code>VertexAITuningJob</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vertex-ai/docs">Vertex AI model tuning jobs</a> for model customization.</li>
</ul></li>
<li><code>VideoStitcherCDNKey</code>
<ul>
<li>Manage <a href="https://cloud.google.com/video-stitcher/docs">Video Stitcher CDN keys</a> to authenticate to external CDNs.</li>
</ul></li>
<li><code>VisionProduct</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vision/product-search/docs">Cloud Vision products</a> for product search cataloging.</li>
</ul></li>
<li><code>VMwareEnginePrivateConnection</code>
<ul>
<li>Manage <a href="https://cloud.google.com/vmware-engine/docs">VMware Engine private connections</a> to connect private clouds to other services.</li>
</ul></li>
</ul>
<h3>Feature</h3>
<p>New Fields:</p>
<ul>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computesubnetwork"><code>ComputeSubnetwork</code></a>
<ul>
<li>Added <code>spec.reservedInternalRange</code> field.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/networkconnectivity/networkconnectivityinternalrange"><code>NetworkConnectivityInternalRange</code></a>
<ul>
<li>Added <code>spec.allocationOptions</code> field.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computenetwork"><code>ComputeNetwork</code></a>
<ul>
<li>Added <code>spec.networkProfile</code> field.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computesecuritypolicy"><code>ComputeSecurityPolicy</code></a>
<ul>
<li>Added <code>spec.region</code> field.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/dns/dnsrecordset"><code>DNSRecordSet</code></a>
<ul>
<li>Added support for routing policy <code>healthCheckRef</code> and <code>rrdatasRefs</code> fields.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeaddress"><code>ComputeAddress</code></a>
<ul>
<li>Added <code>spec.ipCollection</code> field.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeurlmap"><code>ComputeURLMap</code></a>
<ul>
<li>Added <code>spec.defaultCustomErrorResponsePolicy</code> field.</li>
<li>Added <code>spec.test[].expectedOutputUrl</code> and <code>spec.test[].expectedRedirectResponseCode</code> fields.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/redis/rediscluster"><code>RedisCluster</code></a>
<ul>
<li>Added <code>spec.crossClusterReplicationConfig</code> field.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/monitoring/monitoringalertpolicy"><code>MonitoringAlertPolicy</code></a>
<ul>
<li>Added <code>spec.conditions[].conditionSql</code> field (SQL Condition).</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/storage/storagebucket"><code>StorageBucket</code></a>
<ul>
<li>Added <code>spec.ipFilter</code> field.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/pubsub/pubsubtopic"><code>PubSubTopic</code></a>
<ul>
<li>Added <code>spec.messageStoragePolicy.enforceInTransit</code> field.</li>
</ul></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computerouternat"><code>ComputeRouterNAT</code></a>
<ul>
<li>Added Private NAT feature support.</li>
</ul></li>
</ul>
<h3>Change</h3>
<p>Reconciliation Improvements:</p>
<p>We have added support for direct reconciliation to more resources, with opt-in behaviour. The API is unchanged. To use the direct reconciler, add the <code>cnrm.cloud.google.com/reconciler: direct</code> annotation to the corresponding Config Connector object.</p>
<ul>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/bigqueryreservation/bigqueryreservationcapacitycommitment"><code>BigQueryReservationCapacityCommitment</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/bigtable/bigtablegcpolicy"><code>BigtableGCPolicy</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/billingbudgets/billingbudgetsbudget"><code>BillingBudgetsBudget</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/certificatemanager/certificatemanagercertificatemap"><code>CertificateManagerCertificateMap</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/certificatemanager/certificatemanagercertificatemapentry"><code>CertificateManagerCertificateMapEntry</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeaddress"><code>ComputeAddress</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeautoscaler"><code>ComputeAutoscaler</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computebackendservicesignedurlkey"><code>ComputeBackendServiceSignedURLKey</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computedisk"><code>ComputeDisk</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computediskresourcepolicyattachment"><code>ComputeDiskResourcePolicyAttachment</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeexternalvpngateway"><code>ComputeExternalVPNGateway</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computefirewall"><code>ComputeFirewall</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computefirewallpolicy"><code>ComputeFirewallPolicy</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computehttphealthcheck"><code>ComputeHTTPHealthCheck</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computehttpshealthcheck"><code>ComputeHTTPSHealthCheck</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeimage"><code>ComputeImage</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeinstance"><code>ComputeInstance</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeinstancegroup"><code>ComputeInstanceGroup</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeinstancegroupmanager"><code>ComputeInstanceGroupManager</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computenetwork"><code>ComputeNetwork</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computenodetemplate"><code>ComputeNodeTemplate</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeroute"><code>ComputeRoute</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computerouter"><code>ComputeRouter</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computerouterinterface"><code>ComputeRouterInterface</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computerouternat"><code>ComputeRouterNAT</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computesslpolicy"><code>ComputeSSLPolicy</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computesecuritypolicy"><code>ComputeSecurityPolicy</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computetargethttpsproxy"><code>ComputeTargetHTTPSProxy</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/compute/computeurlmap"><code>ComputeURLMap</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/dataflow/dataflowjob"><code>DataflowJob</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/dataproc/dataprocautoscalingpolicy"><code>DataprocAutoscalingPolicy</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/dataproc/dataproccluster"><code>DataprocCluster</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/dns/dnsresponsepolicy"><code>DNSResponsePolicy</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/kms/kmscryptokey"><code>KMSCryptoKey</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/kms/kmskeyring"><code>KMSKeyRing</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/logging/logginglogexclusion"><code>LoggingLogExclusion</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/monitoring/monitoringalertpolicy"><code>MonitoringAlertPolicy</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/networkservices/networkservicesgateway"><code>NetworkServicesGateway</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/privateca/privatecacertificateauthority"><code>PrivateCACertificateAuthority</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/privateca/privatecacertificatetemplate"><code>PrivateCACertificateTemplate</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/pubsub/pubsubsubscription"><code>PubSubSubscription</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/recaptchaenterprise/recaptchaenterprisekey"><code>RecaptchaEnterpriseKey</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/redis/redisinstance"><code>RedisInstance</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/servicedirectory/servicedirectoryendpoint"><code>ServiceDirectoryEndpoint</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/servicedirectory/servicedirectorynamespace"><code>ServiceDirectoryNamespace</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/serviceusage/service"><code>Service</code></a></li>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/serviceusage/serviceidentity"><code>ServiceIdentity</code></a></li>
</ul>
<h3>Fixed</h3>
<p>Bug Fixes:</p>
<ul>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/11001"><code>ComposerEnvironment</code></a>: Fix storageConfig.bucketRef mapping.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/11547"><code>MemorystoreInstance</code></a>: Prevent infinite reconciliation drift loop by aligning connections list length.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/11559"><code>MemorystoreInstance</code></a>: Prevent false drift and update attempts on unspecified immutable fields.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/11800"><code>ComputeBackendService</code></a>: Fix config-connector export tool to export <code>backend</code> field.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/9658"><code>KMSAutokeyConfig</code></a>: Clean up and improve autokey config identity and deletion resolution.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/9623"><code>BigQuery</code></a>: Fix perpetual diff on tables inheriting dataset encryption.</li>
<li><a href="https://github.com/GoogleCloudPlatform/k8s-config-connector/pull/9810"><code>NotebooksInstance</code></a>: Fix direct controller for NotebookInstance to resolve references.</li>
</ul>
<h2 class="release-note-product-title">Cortex Framework</h2>
<h3>Announcement</h3>
<h3 id="release_7_0_0">Release 7.0.0-GA (General Availability)</h3>
<aside class="note">
<b>Note: Important upgrade considerations for Version 7</b>
<ul>
<li><b>Upgrading from v6:</b> Because v7 is a new major version it implies breaking changes with no automatic migration path. For v6 customers looking to adopt v7, we provide <a href="https://docs.cloud.google.com/cortex/docs/v6-compatibility">v6 compatibility content for SAP reporting.</a></li>
<li><b>Upgrading from a v7 Preview:</b> Due to configuration model improvements, you must recreate your configuration files and re-deploy</li>
</ul>
</aside>
<h3>Feature</h3>
<p>Google Cloud Cortex Framework version 7 is now generally available. Version 7 introduces a modular deployment architecture, simplified data orchestration via <a href="https://cloud.google.com/dataform/docs">Dataform</a>, and AI-ready data products with <a href="https://cloud.google.com/bigquery/docs">BigQuery</a> and <a href="https://cloud.google.com/products/knowledge-catalog">Knowledge Catalog</a> integration. This enables enterprises to build, extend, and deploy data assets and pipelines for advanced analytics and agentic use cases with less risk, complexity, and cost.</p>
<p><strong>New features and enhancements</strong></p>
<p><em>additional to those released in preview</em></p>
<p>AI, discovery, and governance:</p>
<ul>
<li><strong><a href="https://docs.cloud.google.com/cortex/docs/agentic-skills-for-data-product-building">New agentic data product builder skills</a></strong>: Automate the creation and customization of data products using natural language.</li>
<li><strong><a href="https://docs.cloud.google.com/cortex/docs/knowledge-catalog">New Knowledge Catalog integration</a></strong>: Automatically synchronize deployed Cortex Framework data products and enriched metadata directly into Knowledge Catalog for discovery and governance.</li>
</ul>
<p>Expanded data product content and integrations:</p>
<ul>
<li><strong><a href="https://docs.cloud.google.com/cortex/docs/data-product#available_data_products">New data products available for SAP ERP</a></strong>: Access an expanded number of Cortex Framework delivered data products for SAP ECC and SAP S/4HANA.</li>
<li><strong><a href="https://docs.cloud.google.com/cortex/docs/source-system-integration/sap-bdc">New support for SAP Business Data Cloud data products</a></strong>: Register your SAP BDC data products with Cortex Framework for expanded use case opportunities on top.</li>
<li><strong><a href="https://docs.cloud.google.com/cortex/docs/solution-samples/overview">New solution samples features</a></strong>: Consumption data product samples for SAP ERP and SAP BDC can now be easily deployed on top of Cortex Framework managed data products.</li>
<li><strong><a href="https://docs.cloud.google.com/cortex/docs/v6-compatibility">New v6 compatibility for SAP reporting</a></strong>: Provides an option to use Cortex Framework version 6 delivered SAP BigQuery data models within the version 7 architecture to support customers looking to migrate while continuing to use v6 delivered Looker reports.</li>
</ul>
<p>Supportability: </p>
<ul>
<li><strong><a href="https://docs.cloud.google.com/cortex/docs/observability">New observability features</a></strong>: Enhanced error reporting and pipeline monitoring. </li>
</ul>
<h3>Change</h3>
<p>Google Cloud Cortex Framework version 7 includes <a href="https://docs.cloud.google.com/cortex/docs/telemetry">telemetry</a>
to capture anonymized deployment statistics. This data helps the solution build
team focus on improving modules with high adoption. Telemetry is enabled by
default, but you can opt out at any time.</p>
<h2 class="release-note-product-title">Data Studio</h2>
<h3>Feature</h3>
<p><strong>Conversational Analytics is generally available</strong></p>
<p>Conversational Analytics in Data Studio is now generally available. You can now filter your <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-data-agents#start-a-conversation-with-an-agent">data agents</a> by the Google Cloud project to which they belong. Agents that require additional permissions are now displayed with an <strong>Unavailable</strong> label.</p>
<h3>Feature</h3>
<p><strong>Email notifications when sharing Conversational Analytics data agents</strong></p>
<p>When you <a href="https://docs.cloud.google.com/bigquery/docs/create-data-agents#share-data-studio-users">share data agents</a> that were created in BigQuery with Data Studio users, you can opt to send an email to notify those users of their access to the agent.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 5.2</strong></p>
<p>We've released version 5.2 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Feature</h3>
<p><strong>Answering machine detection for progressive campaigns</strong></p>
<p>Answering machine detection (AMD) is now supported for progressive outbound
campaigns. When enabled, Contact Center AI Platform analyzes call audio in the background
to determine whether a call reaches a live person, or whether it reaches an
answering machine or voicemail. If an answering machine or voicemail is
detected, the call ends and the dialer proceeds to the next contact.</p>
<p>Administrators: In the <strong>Settings <span aria-label="and then">&gt;</span> Campaigns <span aria-label="and then">&gt;</span> Dialer
Modes</strong> pane, there's a new <strong>Enable Answering Machine Detection</strong> toggle.</p>
<p>User experience change: When CCAI Platform detects voicemail or an
answering machine, a green banner appears in the call adapter to indicate this.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/campaign-progressive-amd">Answering machine detection for progressive
campaigns</a>.</p>
<h3>Feature</h3>
<p><strong>New endpoints for getting email sessions and messages</strong></p>
<p>Two new read-only endpoints are now available, allowing external systems to
retrieve the parsed contents of an email interaction. This includes the sender,
recipients, subject, body, and attachment metadata. Here are the endpoints:</p>
<ul>
<li><p><code>/apps/api/v1/email/sessions/<var>EMAIL_SUPPORT_ID</var></code>: Returns
email session summary information and a list of message IDs with metadata.</p></li>
<li><p><code>/apps/api/v1/email/messages/<var>EMAIL_THREAD_ID</var></code>: Returns the
full content of a single message.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/get-email-sessions-and-messages">Get email sessions and
messages</a>.</p>
<h3>Feature</h3>
<p><strong>Email forwarding with attachments</strong></p>
<p>Agents can now forward emails to external recipients directly from the email
adapter. When forwarding, all attachments from the original email are
automatically included. Agents can remove attachments before sending, if needed.
The original email remains in its assigned queue with its status unchanged.</p>
<p>User experience change: A new <strong>Forward</strong> button is available in the email
adapter.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/email-adapter#forward-an-email">Forward an
email</a>.</p>
<h3>Feature</h3>
<p><strong>Smart disposition</strong></p>
<p>Smart disposition is a new AI-powered capability that automatically suggests a
disposition code at the end of a session. This reduces manual work for agents
and improves data consistency.</p>
<p>Administrators: There's a new <strong>Smart Disposition</strong> toggle in the following
locations:</p>
<ul>
<li><p>The <strong>Settings <span aria-label="and then">&gt;</span> Operation Management <span aria-label="and then">&gt;</span> Wrap-up
<span aria-label="and then">&gt;</span> Automatic wrap-up for inbound calls <span aria-label="and then">&gt;</span> Disposition
Codes &amp; Notes for calls <span aria-label="and then">&gt;</span> Disposition Codes</strong> section.</p></li>
<li><p>The <strong>Settings <span aria-label="and then">&gt;</span> Operation Management <span aria-label="and then">&gt;</span> Wrap-up
<span aria-label="and then">&gt;</span> Automatic wrap-up for outbound calls <span aria-label="and then">&gt;</span> Disposition
Codes &amp; Notes for calls <span aria-label="and then">&gt;</span> Disposition Codes</strong> section.</p></li>
<li><p>The <strong>Settings <span aria-label="and then">&gt;</span> Operation Management <span aria-label="and then">&gt;</span> Wrap-up
<span aria-label="and then">&gt;</span> Automatic wrap-up for chats <span aria-label="and then">&gt;</span> Disposition Codes &amp;
Notes for chats <span aria-label="and then">&gt;</span> Disposition Codes</strong> section.</p></li>
</ul>
<p>User experience change: When smart disposition is turned on, a suggested
disposition displays in the <strong>Disposition</strong> field of the <strong>Wrap-up</strong> screen in
the agent adapter.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/smart-disposition">Smart
disposition</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where voice calls became stuck in a virtual agent state after
a session ended abnormally or an escalation handoff didn't complete.</p></li>
<li><p>Fixed an issue where using invalid sorting parameters on agent activity logs
caused a server error.</p></li>
<li><p>Fixed an issue where canceling a warm transfer to a queue at overcapacity
caused the caller to become stranded in an automated menu loop.</p></li>
<li><p>Fixed an issue where the agent activity logs API allowed unbounded time
ranges, which led to system performance degradation and gateway timeouts.</p></li>
<li><p>Fixed an issue where the team and menu endpoints experienced performance
delays.</p></li>
<li><p>Fixed an issue where calls transferred to a queue with overcapacity
deflection (OCD) enabled didn't redirect, causing callers to hear indefinite
ringing.</p></li>
<li><p>Fixed an issue where the call duration in the call adapter and in the
in-call status timer of the agent desktop didn't match for outbound calls.</p></li>
<li><p>Fixed an issue where the <strong>Agent Activity</strong> dashboard displayed time zones
inconsistently.</p></li>
<li><p>Fixed an issue where the inactivity timer didn't force a session to end if
the agent closed the browser or browser tab before the inactivity timer
expired.</p></li>
<li><p>Fixed an issue where the <strong>All Call History</strong> and <strong>Individual Call
History</strong> reports displayed incorrect cascade group numbers for transferred
calls and chats.</p></li>
<li><p>Fixed an issue where the sentiment score appeared in the <strong>Call Details</strong>
panel of the agent desktop despite sentiment analysis being turned off in
the conversation profile.</p></li>
<li><p>Fixed an issue with IVR calls routed through Nexmo, where the virtual agent
missed the first several seconds of caller audio, forcing callers to repeat
themselves.</p></li>
<li><p>Fixed an issue where chats became stuck in the queue after a deltacast
routing projection expired or an agent didn't connect.</p></li>
<li><p>Fixed an issue where reordering queues in the CCAI Platform portal caused
significant latency and required a manual page refresh to display the
changes.</p></li>
<li><p>Fixed an issue with Salesforce integrations where adding a third party to a
call incorrectly displayed their contact name in the customer field in the
agent desktop <strong>Participants</strong> panel.</p></li>
<li><p>Fixed an issue where direct inbound SMS chats that were sent to an
unavailable agent expired and failed instead of being rerouted.</p></li>
<li><p>Fixed an issue where anonymous inbound calls incorrectly displayed an
agent's contact information instead of indicating an unknown caller.</p></li>
<li><p>Fixed an issue where database deadlocks caused transactions to run against
the wrong database, causing failed lookups and chat sessions getting stuck.</p></li>
<li><p>Fixed an issue where manual status changes to <strong>Available</strong> after an
automatic wrap-up were incorrectly attributed to the system instead of the
agent in activity reports.</p></li>
<li><p>Fixed an issue where retrieving large datasets using the manager API caused
connection timeouts and incomplete data synchronization for downstream
systems.</p></li>
<li><p>Fixed an issue where the <strong>Agent Assist Hub</strong> incorrectly displayed <code>The
Agent Assist Hub feature is not enabled</code> during voice sessions despite the
<strong>Agent Assist Hub</strong> being enabled.</p></li>
<li><p>Fixed a web SDK issue where navigating between pages on the host website
during an active chat resulted in a duplicate session being created.</p></li>
<li><p>Fixed an issue where the <strong>AgentSystemData</strong> historical report incorrectly
showed zero login time for agents who were actively handling calls.</p></li>
<li><p>Fixed an issue where Dialogflow agents incorrectly escalated or
disconnected calls when responding with only pre-recorded audio.</p></li>
<li><p>Fixed an issue where transfer completion events appeared twice in the agent
desktop session data feed when a user was transferred to a task virtual
agent.</p></li>
<li><p>Fixed an issue where virtual agent interactions failed and escalated
prematurely.</p></li>
<li><p>Fixed an issue where a single wrap-up event was incorrectly dispatched twice
to Dialogflow on bidirectional-enabled voice calls.</p></li>
<li><p>Fixed an issue where session summarization sections weren't displayed in the
order that they were configured.</p></li>
<li><p>Fixed an issue where sensitive information in the CC and BCC fields of email
requests was visible in system logs.</p></li>
<li><p>Fixed an issue where the email adapter displayed a blank gray screen when an
agent attempted to transfer emails between queues.</p></li>
<li><p>Fixed an issue in Kustomer integrations where abandoned or failed calls
weren't finalized, leaving records in the <code>Call In Progress</code> state.</p></li>
<li><p>Fixed an issue in ServiceNow integrations where starting a chat from a queue
caused duplicate cases for a single chat ID.</p></li>
<li><p>Fixed an issue where mobile chat sessions ended unexpectedly after
successfully escalating to a human agent.</p></li>
<li><p>Fixed an issue where chat transcript PDF headers remained in English for
non-English queues.</p></li>
<li><p>Fixed an issue where placeholder text (<code>Content cards displayed here</code>)
didn't appear in the agent adapter or live chat view when content cards
weren't supported.</p></li>
<li><p>Fixed an issue where agents received duplicate SMS messages from end-users.</p></li>
<li><p>Fixed an issue where the inactivity timeout didn't trigger for chats waiting
in a transfer queue.</p></li>
<li><p>Fixed an issue where chats waiting in a transfer queue remained open
indefinitely and created duplicate metadata files.</p></li>
<li><p>Fixed an issue where chat transcripts were missing from data exports when a
CRM ticket wasn't created.</p></li>
<li><p>Fixed an issue where chats escalated from a virtual agent remained in queued
status after being assigned to an agent.</p></li>
<li><p>Fixed an issue where calls escalated from a virtual agent to a
holiday-closed queue bypassed the holiday message and played the after-hours
deflection message.</p></li>
<li><p>Fixed an issue where call recording URLs weren't saved or synced to the CRM
for calls with multiple audio segments, such as those involving an IVR
followed by an agent conference.</p></li>
<li><p>Fixed an issue where voice calls remained in an assigned state without
progressing or requeueing if a system error occurred during the assignment
process.</p></li>
<li><p>Fixed an issue where callers were disconnected from voicemail greetings
after an agent completed their wrap-up following a call transfer.</p></li>
<li><p>Fixed an issue where manual wrap-up session data was incorrectly recorded
across multiple sessions, leading to inflated duration reports.</p></li>
<li><p>Fixed an issue where duplicate call recording files with an <code>.N</code> suffix were
created in external storage.</p></li>
<li><p>Fixed an issue where calls prematurely disconnected or experienced audio
loss during the hangup process.</p></li>
<li><p>Fixed an issue where Telnyx VoIP calls silently dropped without notification
if the connection was interrupted.</p></li>
<li><p>Improved internal instrumentation to diagnose poor call quality scores and
improve call reliability.</p></li>
<li><p>Fixed an issue where agents configured for Deltacast and auto-answer
received unexpected multicast call offers.</p></li>
<li><p>Fixed an issue where the agent desktop didn't save call-related settings
such as mute status.</p></li>
<li><p>Fixed an issue where queue-level automatic wrap-up settings were
unexpectedly disabled.</p></li>
<li><p>Fixed an issue where the switch to chat button wasn't accessible from the
keyboard.</p></li>
<li><p>Fixed an issue where an agent ended the wrap-up session of another agent.</p></li>
<li><p>Fixed an issue where agents experienced delays of up to 30 seconds when
transitioning from "Wrap" to "Available" status.</p></li>
<li><p>Fixed an issue where an <code>An error has occurred</code> message incorrectly appeared
when a user created a direct access point for instances without a configured
CRM.</p></li>
<li><p>Fixed an issue where message timestamps weren't visible to supervisors and
administrators when monitoring active chats in the CCAI Platform portal.</p></li>
<li><p>Fixed an issue where historical data syncs to Calabrio failed.</p></li>
<li><p>Fixed an issue where the bulk user upload process allowed unauthorized role
assignments.</p></li>
<li><p>Fixed an issue where deleting a notification rule removed all associated
historical notifications without warning.</p></li>
<li><p>Fixed an issue where call events in timeline reports appeared out of
chronological order.</p></li>
<li><p>Fixed an issue where technical connection timeouts during call offers
weren't correctly tracked as skipped interactions.</p></li>
<li><p>Fixed an issue where chats remained in the queue following a virtual agent
escalation.</p></li>
<li><p>Fixed an issue where importing a contact list CSV for a native power dial
campaign failed if the file contained malformed rows or encoding issues.</p></li>
</ul>
<h2 class="release-note-product-title">Google Cloud Marketplace Partners</h2>
<h3>Change</h3>
<p>We've added the <code>city</code> field to Customer Insights reports and Detailed
Disbursements reports.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/marketplace/docs/partners/reports/report-customer-insight#report_fields">Customer Insights report fields</a>
and
<a href="https://docs.cloud.google.com/marketplace/docs/partners/reports/report-detailed-disbursement#report_fields">Detailed Disbursements report fields</a>.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r32-version-updates">(2026-R32) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1329000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1655000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1710000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2281000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.13-gke.1109000</li>
<li>1.34.9-gke.1322000</li>
<li>1.35.6-gke.1258000</li>
<li>1.35.6-gke.1638000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.2-gke.1498000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1269000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1610000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1641000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1269000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1610000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1641000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.13-gke.1011000</li>
<li>1.34.9-gke.1131000</li>
<li>1.35.6-gke.1127000</li>
<li>1.36.0-gke.4447000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.4681000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.12-gke.1165000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1278000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2866000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2456000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.2175000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2846000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2437000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.2137000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.13-gke.1011000</li>
<li>1.34.9-gke.1131000</li>
<li>1.35.6-gke.1127000</li>
<li>1.36.0-gke.4447000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.4681000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1329000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1655000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1710000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2281000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2866000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2456000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.2175000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1329000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1655000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1710000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2281000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.12-gke.1165000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1126000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.6-gke.1049000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.6-gke.1638000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.4447000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.4681000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Change</h3>
<h4 id="2026-r32-version-updates">(2026-R32) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.12-gke.1165000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1278000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r32-version-updates">(2026-R32) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.13-gke.1011000</li>
<li>1.34.9-gke.1131000</li>
<li>1.35.6-gke.1127000</li>
<li>1.36.0-gke.4447000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.4681000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r32-version-updates">(2026-R32) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1329000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1655000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1710000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2281000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.13-gke.1109000</li>
<li>1.34.9-gke.1322000</li>
<li>1.35.6-gke.1258000</li>
<li>1.35.6-gke.1638000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.2-gke.1498000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1269000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1610000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1641000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1269000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1610000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1641000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r32-version-updates">(2026-R32) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1329000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1655000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1710000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2281000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2866000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2456000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.2175000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1329000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1655000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1710000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2281000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.12-gke.1165000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1126000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.6-gke.1049000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.6-gke.1638000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.4447000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.4681000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r32-version-updates">(2026-R32) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2866000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2456000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.2175000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2846000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2437000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.2137000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.13-gke.1011000</li>
<li>1.34.9-gke.1131000</li>
<li>1.35.6-gke.1127000</li>
<li>1.36.0-gke.4447000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.4681000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 91.0</p>
<ul>
<li><p>Updated Wiz Defend alert naming format in the following connector:</p>
<ul>
<li><strong>Google Chronicle - Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Looker</h2>
<h3>Announcement</h3>
<p>From July 27 through July 30, 2026, the following features will be automatically enabled for Looker (original) instances running Looker 26.12.</p>
<h3>Feature</h3>
<p>Looker admins now have the ability to configure a Looker instance to require <a href="https://docs.cloud.google.com/looker/docs/admin-panel-authentication-two-factor">multi-factor authentication (MFA)</a> whenever a user tries to <a href="https://docs.cloud.google.com/looker/docs/admin-panel-authentication-password">log in by using an email and a password</a>. This feature is enabled by default.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/custom-calendars">custom calendar</a> feature is now generally available.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/gemini-expression-asst">Expression Assistant</a> is now generally available.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/finding-content#searching_for_saved_content">Enhanced search</a> feature is now generally available.</p>
<h3>Feature</h3>
<p>Looker Continuous Integration (CI) now supports email alerts. When you create or edit a CI suite, you can enable the <strong>Enable email alerts</strong> toggle to specify email recipients and select which run statuses will trigger emails (<strong>Failed</strong>, <strong>Error</strong>, <strong>Passed</strong>, or <strong>Cancelled</strong>). For more information, see <a href="https://docs.cloud.google.com/looker/docs/ci-create-suite#alerting">Set up alerting</a>.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/manage-projects">LookML Projects page</a> has been updated with a more performant tabbed layout, which features three tabs: <strong>Models and Projects</strong>, <strong>Pending Projects</strong>, and <strong>Marketplace Projects</strong>.</p>
<h3>Feature</h3>
<p>Now available in preview, the new <a href="https://docs.cloud.google.com/looker/docs/admin-panel-general-preview-features#modern_user_interface"><strong>Modern User Interface</strong> feature</a> enables <a href="https://docs.cloud.google.com/looker/docs/modern-ui">modernized layouts and design</a> alongside new configuration settings for visualizations and dashboards. When this preview feature is enabled, users can apply a <strong>Modern</strong> visualization theme that features updated typography and modern, accessible color palettes for improved data legibility. Additionally, a new <strong>Modern</strong> dashboard style provides a high-density, streamlined design that optimizes data viewing and aligns with Google's latest design standards.</p>
<h3>Feature</h3>
<p>Now available in preview, <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents#define-verified-queries">verified queries</a> (also referred to as <em>golden queries</em>) are predefined pairs of natural language questions and their exact, corresponding Looker Explore queries that act as verified standards of truth to teach your Explore data agent how to handle complex business requests without guessing.</p>
<p>To enable verified queries, a Looker admin must turn on the <strong>Verified Queries</strong> setting on the <strong>Gemini in Looker</strong> admin page. The <strong>Conversational Analytics</strong> setting must also be enabled for verified queries to be used.</p>
<h3>Change</h3>
<p>When you <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents#chat-agent-ge">chat in Gemini Enterprise with data agents that you create in Looker</a>, agent responses now include charts and visualizations.</p>
<h3>Change</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/gemini-insight-asst">Insight Assistant</a> now displays the process the assistant uses to generate the response, showing key details in your data that it used to generate the response, and listing the fields from your Explore that it used.</p>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/looker/docs/admin-panel-platform-dsp">Complimentary Data Studio Pro licenses</a> aren't available for Looker instances that are affiliated with Looker contracts that are signed after August 1, 2026.</p>
<h2 class="release-note-product-title">Managed Service for Apache Spark</h2>
<h3>Announcement</h3>
<p>New <a href="https://docs.cloud.google.com/managed-spark/docs/guides/dpgke/gke-versions"><strong>Managed Service for Apache Spark on Google Kubernetes Engine</strong> (formerly Dataproc on Google Kubernetes Engine) subminor image version</a>:</p>
<ul>
<li>3.5-dataproc-28</li>
</ul>
<p>Key updates in this image version include:</p>
<ul>
<li><strong>Conda channels</strong>: The new <code>3.5-dataproc-28</code> subminor image version doesn't have preconfigured Conda channels, and is mapped to default aliases (such as <code>3.5</code> and <code>latest</code>).
<ul>
<li><strong>Impact:</strong> When creating clusters with <code>3.5-dataproc-28</code> or using default aliases (<code>3.5</code>, <code>latest</code>), packages cannot be installed using Conda unless channels are manually configured during cluster initialization.</li>
<li><strong>Mitigation:</strong> If your workloads require preconfigured Conda channels, pin your clusters to the previous image versions before August 25, 2026.</li>
<li><strong>Default change schedule:</strong> All workloads must transition to image versions without preconfigured Conda channels after August 25, 2026 since the use of prior subminor versions with preconfigured Conda channels will be disallowed.</li>
</ul></li>
</ul>
<p><strong>You may need to delete and replace existing clusters</strong> After August 25, 2026,
existing clusters created with images that have preconfigured Conda channels
(even if cluster jobs don't use Conda to install packages) need to be deleted
and replaced with new
<a href="https://docs.cloud.google.com/managed-spark/docs/guides/dpgke/quickstarts/gke-quickstart-create-cluster#create-dpgke-cluster">clusters created</a>
or <a href="https://docs.cloud.google.com/managed-spark/docs/guides/dpgke/gke-recreate-cluster#recreate-gke-cluster">recreated</a>
with images that don't have preconfigured Conda channels.</p>
<h2 class="release-note-product-title">Oracle Database@Google Cloud</h2>
<h3>Feature</h3>
<p>Oracle Database@Google Cloud supports <a href="https://docs.cloud.google.com/oracle/database/docs/cmek">customer-managed encryption keys (CMEK)</a> for Exascale VM Clusters. You can <a href="https://docs.cloud.google.com/oracle/database/docs/use-cmek#cmek-for-exascale-cluster">enable CMEK on Exascale VM Clusters</a>. This feature is <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.</p>
<h2 class="release-note-product-title">Virtual Private Cloud</h2>
<h3>Feature</h3>
<p><strong>General Availability</strong>: You can use the <strong>Resolve subnet mask</strong> setting on a
subnet to configure all attached Compute Engine instances with the same netmask
as the subnet (instead of <code>/32</code>). Configuring larger instance netmasks lets
compute instances discover the MAC addresses of other machines within the same
subnet and directly communicate with them by using destination MAC addresses.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/vpc/docs/compute-instance-netmasks">Compute instance netmasks</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 29, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_29_2026</id>
    <updated>2026-07-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_29_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">App Engine standard environment Go</h2>
<h3>Feature</h3>
<p>Support for enabling only needed legacy bundled services using the
<a href="https://docs.cloud.google.com/appengine/docs/standard/reference/app-yaml?tab=go#app_engine_bundled_services"><code>app_engine_bundled_services</code></a>
field is in <a href="https://cloud.google.com/products/#product-launch-stages">General Availability</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Java</h2>
<h3>Feature</h3>
<p>Support for enabling only needed legacy bundled services using the
<a href="https://docs.cloud.google.com/appengine/docs/standard/java-gen2/config/appref-xml#app_engine_apis"><code>app_engine_bundled_services</code></a>
field is in <a href="https://cloud.google.com/products/#product-launch-stages">General Availability</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment PHP</h2>
<h3>Feature</h3>
<p>Support for enabling only needed legacy bundled services using the
<a href="https://docs.cloud.google.com/appengine/docs/standard/reference/app-yaml?tab=php#app_engine_bundled_services"><code>app_engine_bundled_services</code></a>
field is in <a href="https://cloud.google.com/products/#product-launch-stages">General Availability</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Python</h2>
<h3>Feature</h3>
<p>Support for enabling only needed legacy bundled services using the
<a href="https://docs.cloud.google.com/appengine/docs/standard/reference/app-yaml?tab=python#app_engine_bundled_services"><code>app_engine_bundled_services</code></a>
field is in <a href="https://cloud.google.com/products/#product-launch-stages">General Availability</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>The BigQuery Data Transfer Service now supports <a href="https://docs.cloud.google.com/bigquery/docs/klaviyo-transfer-intro#full_or_incremental_transfers">incremental data transfers</a>
when transferring data from Klaviyo to BigQuery. This feature is supported in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>You can use the Google Cloud console to <a href="https://docs.cloud.google.com/bigtable/docs/manage-row-key-schemas">manage row key schemas</a>
for your Bigtable tables. This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Key Management Service</h2>
<h3>Feature</h3>
<p>Cloud KMS Autokey with same-project key storage (formerly known as Autokey for
delegated key management) is generally available. Autokey with same-project key
storage can be used on its own or alongside Autokey with dedicated-project key
storage (formerly known as Autokey for centralized key management).</p>
<p>For more information, see <a href="https://docs.cloud.google.com/kms/docs/enable-autokey">Enable Cloud KMS Autokey</a>.
To learn how to set guardrails to constrain how Autokey is used in your
organization, see <a href="https://docs.cloud.google.com/kms/docs/control-autokey-usage">Control Autokey usage</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>Cloud SQL for MySQL now supports significantly faster re-encryption of
instances and replicas protected by customer-managed encryption keys (CMEKs),
and re-encryption now completes with zero downtime. The steps to re-encrypt your
instances and replicas are unchanged, but the operation now re-encrypts the
underlying disks in-place, without creating re-encryption backups.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/mysql/configure-cmek#reencrypt">Re-encrypt an existing CMEK-enabled instance or
replica</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>Cloud SQL for PostgreSQL now supports significantly faster re-encryption of
instances and replicas protected by customer-managed encryption keys (CMEKs),
and re-encryption now completes with zero downtime. The steps to re-encrypt your
instances and replicas are unchanged, but the operation now re-encrypts the
underlying disks in-place, without creating re-encryption backups.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/postgres/configure-cmek#reencrypt">Re-encrypt an existing CMEK-enabled instance or
replica</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for SQL Server</h2>
<h3>Feature</h3>
<p>Cloud SQL for SQL Server now supports significantly faster re-encryption of
instances and replicas protected by customer-managed encryption keys (CMEKs),
and re-encryption now completes with zero downtime. The steps to re-encrypt your
instances and replicas are unchanged, but the operation now re-encrypts the
underlying disks in-place, without creating re-encryption backups.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/sqlserver/configure-cmek#reencrypt">Re-encrypt an existing CMEK-enabled instance or
replica</a>.</p>
<h2 class="release-note-product-title">Cloud Scheduler</h2>
<h3>Change</h3>
<p>Cloud Scheduler is available in the following <a href="https://docs.cloud.google.com/scheduler/docs/locations">locations</a>:</p>
<ul>
<li><code>europe-west8</code> (Milan, Italy)</li>
<li><code>europe-west9</code> (Paris, France)</li>
<li><code>us-south1</code> (Dallas, United States)</li>
</ul>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Feature</h3>
<p>For the clusters using <code>TRAFFIC_DIRECTOR</code> implementation,
<a href="https://docs.cloud.google.com/service-mesh/docs/operate-and-maintain/dns-proxy#ip_auto-allocation_for_serviceentry">IP auto-allocation</a>
with DNS Proxy is now supported in Rapid release channel.</p>
<h2 class="release-note-product-title">Confidential VM</h2>
<h3>Feature</h3>
<p>Confidential VM instances with AMD SEV on C3D and C4D machine types now support
configurations with more than 255 vCPUs.</p>
<h2 class="release-note-product-title">Datastream</h2>
<h3>Feature</h3>
<p>You can now create a Datastream stream directly from the instance or
database overview page in Spanner using the automated flow.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/datastream/docs/create-spanner-stream-automated">Create a Spanner stream using the automated flow</a>.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Change</h3>
<p>Google SecOps has updated the list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.</p>
<p>The following supported default parsers have been updated. Each parser is listed by product name and <code>log_type</code> value, where applicable. This list includes both released default parsers and pending parser updates.</p>
<ul>
<li>Airlock Digital Application Allowlisting (<code>AIRLOCK_DIGITAL</code>)</li>
<li>AIX system (<code>AIX_SYSTEM</code>)</li>
<li>Akamai DataStream 2 (<code>AKAMAI_DATASTREAM_2</code>)</li>
<li>Akamai SIEM Connector (<code>AKAMAI_SIEM_CONNECTOR</code>)</li>
<li>Apache (<code>APACHE</code>)</li>
<li>Arcsight CEF (<code>ARCSIGHT_CEF</code>)</li>
<li>Armis Alerts (<code>ARMIS_ALERTS</code>)</li>
<li>Aruba Switch (<code>ARUBA_SWITCH</code>)</li>
<li>Atlassian Cloud Admin Audit (<code>ATLASSIAN_AUDIT</code>)</li>
<li>Linux Auditing System (AuditD) (<code>AUDITD</code>)</li>
<li>Avaya Aura Experience Portal (<code>AVAYA_AURA</code>)</li>
<li>AWS Cloudtrail (<code>AWS_CLOUDTRAIL</code>)</li>
<li>AWS CloudWatch (<code>AWS_CLOUDWATCH</code>)</li>
<li>AWS Control Tower (<code>AWS_CONTROL_TOWER</code>)</li>
<li>Microsoft Azure Activity (<code>AZURE_ACTIVITY</code>)</li>
<li>Azure AD (<code>AZURE_AD</code>)</li>
<li>Azure AD Organizational Context (<code>AZURE_AD_CONTEXT</code>)</li>
<li>Azure Application Gateway (<code>AZURE_GATEWAY</code>)</li>
<li>Azure Key Vault logging (<code>AZURE_KEYVAULT_AUDIT</code>)</li>
<li>Microsoft Azure Resource (<code>AZURE_RESOURCE_LOGS</code>)</li>
<li>Blue Coat Proxy (<code>BLUECOAT_WEBPROXY</code>)</li>
<li>BeyondTrust (<code>BOMGAR</code>)</li>
<li>Cato Networks (<code>CATO_NETWORKS</code>)</li>
<li>Check Point (<code>CHECKPOINT_FIREWALL</code>)</li>
<li>Check Point Harmony (<code>CHECKPOINT_HARMONY</code>)</li>
<li>Chrome Management (<code>CHROME_MANAGEMENT</code>)</li>
<li>ChromeOS XDR (<code>CHROMEOS_XDR</code>)</li>
<li>Cisco ASA (<code>CISCO_ASA_FIREWALL</code>)</li>
<li>Cisco Email Security (<code>CISCO_EMAIL_SECURITY</code>)</li>
<li>Cisco Firepower NGFW (<code>CISCO_FIREPOWER_FIREWALL</code>)</li>
<li>Cisco FireSIGHT Management Center (<code>CISCO_FIRESIGHT</code>)</li>
<li>Cisco ISE (<code>CISCO_ISE</code>)</li>
<li>Cisco Router (<code>CISCO_ROUTER</code>)</li>
<li>Cisco Switch (<code>CISCO_SWITCH</code>)</li>
<li>Cisco UCM (<code>CISCO_UCM</code>)</li>
<li>Claroty Xdome (<code>CLAROTY_XDOME</code>)</li>
<li>Claude Compliance Logs (<code>CLAUDE_COMPLIANCE_LOGS</code>)</li>
<li>HP Aruba (ClearPass) (<code>CLEARPASS</code>)</li>
<li>Cloudflare (<code>CLOUDFLARE</code>)</li>
<li>Palo Alto Cortex XDR Alerts (<code>CORTEX_XDR</code>)</li>
<li>CrowdStrike Falcon (<code>CS_EDR</code>)</li>
<li>Darktrace (<code>DARKTRACE</code>)</li>
<li>EfficientIP DDI (<code>EFFICIENTIP_DDI</code>)</li>
<li>F5 ASM (<code>F5_ASM</code>)</li>
<li>F5 BIGIP LTM (<code>F5_BIGIP_LTM</code>)</li>
<li>Fastly CDN (<code>FASTLY_CDN</code>)</li>
<li>FireEye eMPS (<code>FIREEYE_EMPS</code>)</li>
<li>FireEye HX (<code>FIREEYE_HX</code>)</li>
<li>FireEye NX (<code>FIREEYE_NX</code>)</li>
<li>Forcepoint Proxy (<code>FORCEPOINT_WEBPROXY</code>)</li>
<li>FortiGate (<code>FORTINET_FIREWALL</code>)</li>
<li>Fortinet FortiAnalyzer (<code>FORTINET_FORTIANALYZER</code>)</li>
<li>Fortinet FortiClient (<code>FORTINET_FORTICLIENT</code>)</li>
<li>Fortinet Switch (<code>FORTINET_SWITCH</code>)</li>
<li>GCP Cloud Audit (<code>GCP_CLOUDAUDIT</code>)</li>
<li>Security Command Center External Exposure (<code>GCP_SECURITYCENTER_EXTERNAL_EXPOSURE</code>)</li>
<li>Gitlab (<code>GITLAB</code>)</li>
<li>Google Threat Intelligence IOC (<code>GTI_IOC</code>)</li>
<li>AWS GuardDuty (<code>GUARDDUTY</code>)</li>
<li>Huawei Switches (<code>HUAWEI_SWITCH</code>)</li>
<li>IBM Security Access Manager (<code>IBM_SAM</code>)</li>
<li>Microsoft IIS (<code>IIS</code>)</li>
<li>Illumio Core (<code>ILLUMIO_CORE</code>)</li>
<li>Imperva SecureSphere Management (<code>IMPERVA_SECURESPHERE</code>)</li>
<li>Infoblox (<code>INFOBLOX</code>)</li>
<li>Infoblox DHCP (<code>INFOBLOX_DHCP</code>)</li>
<li>Jamf pro context (<code>JAMF_PRO_CONTEXT</code>)</li>
<li>Mobile Endpoint Security (<code>LOOKOUT_MOBILE_ENDPOINT_SECURITY</code>)</li>
<li>Apple macOS (<code>MACOS</code>)</li>
<li>McAfee IPS (<code>MCAFEE_IPS</code>)</li>
<li>Micro Focus iManager (<code>MICROFOCUS_IMANAGER</code>)</li>
<li>Microsoft Defender for Endpoint (<code>MICROSOFT_DEFENDER_ENDPOINT</code>)</li>
<li>Microsoft Defender for Office 365 (<code>MICROSOFT_DEFENDER_MAIL</code>)</li>
<li>Microsoft Graph API Alerts (<code>MICROSOFT_GRAPH_ALERT</code>)</li>
<li>Microsoft Sentinel (<code>MICROSOFT_SENTINEL</code>)</li>
<li>Microsoft SQL Server (<code>MICROSOFT_SQL</code>)</li>
<li>Mimecast URL Logs (<code>MIMECAST_URL_LOGS</code>)</li>
<li>MISP Threat Intelligence (<code>MISP_IOC</code>)</li>
<li>NetApp ONTAP (<code>NETAPP_ONTAP</code>)</li>
<li>Netskope V2 (<code>NETSKOPE_ALERT_V2</code>)</li>
<li>Unix system (<code>NIX_SYSTEM</code>)</li>
<li>Office 365 (<code>OFFICE_365</code>)</li>
<li>Okta (<code>OKTA</code>)</li>
<li>Onapsis (<code>ONAPSIS</code>)</li>
<li>OpenVPN (<code>OPEN_VPN</code>)</li>
<li>Oracle Fusion (<code>ORACLE_FUSION</code>)</li>
<li>Ping Identity (<code>PING</code>)</li>
<li>Proofpoint Sendmail Sentrion (<code>PROOFPOINT_SENDMAIL_SENTRION</code>)</li>
<li>SailPoint IAM (<code>SAILPOINT_IAM</code>)</li>
<li>Salesforce (<code>SALESFORCE</code>)</li>
<li>Sendmail (<code>SENDMAIL</code>)</li>
<li>Sentinelone Alerts (<code>SENTINELONE_ALERT</code>)</li>
<li>ServiceNow Audit (<code>SERVICENOW_AUDIT</code>)</li>
<li>ServiceNow CMDB (<code>SERVICENOW_CMDB</code>)</li>
<li>ServiceNow Security (<code>SERVICENOW_SECURITY</code>)</li>
<li>SonicWall (<code>SONIC_FIREWALL</code>)</li>
<li>STIX Threat Intelligence (<code>STIX</code>)</li>
<li>Tanium Threat Response (<code>TANIUM_THREAT_RESPONSE</code>)</li>
<li>Thinkst Canary (<code>THINKST_CANARY</code>)</li>
<li>ThreatConnect IOC V3 (<code>THREATCONNECT_IOC_V3</code>)</li>
<li>ThreatLocker Platform (<code>THREATLOCKER</code>)</li>
<li>Varonis (<code>VARONIS</code>)</li>
<li>VMware ESXi (<code>VMWARE_ESX</code>)</li>
<li>Windows DNS (<code>WINDOWS_DNS</code>)</li>
<li>Windows Event (<code>WINEVTLOG</code>)</li>
<li>Windows Event (XML) (<code>WINEVTLOG_XML</code>)</li>
<li>wiz.io (<code>WIZ_IO</code>)</li>
<li>Workspace Activities (<code>WORKSPACE_ACTIVITY</code>)</li>
<li>Zoom Operation Logs (<code>ZOOM_OPERATION_LOGS</code>)</li>
</ul>
<p>The following log types were added without a default parser. Each parser is listed by product name and <code>log_type</code> value, where applicable.</p>
<ul>
<li>Adobe Experience Platform (<code>ADOBE_EXPERIENCE_PLATFORM</code>)</li>
<li>AudioCodes Session Border Controller (<code>AUDIOCODES_SBC</code>)</li>
<li>Azure Application Gateway for Containers (<code>AZURE_GATEWAY_CONTAINERS</code>)</li>
<li>Azure Logic Apps (<code>AZURE_LOGIC_APPS</code>)</li>
<li>Azure NAT Gateway Flow (<code>AZURE_NATGW_FLOW</code>)</li>
<li>Broadcom DX NetOps Spectrum (<code>BROADCOM_DX_NETOPS_SPECTRUM</code>)</li>
<li>Carto Activity (<code>CARTO_ACTIVITY</code>)</li>
<li>Claude Code Observability (<code>CLAUDE_CODE_OBSERVABILITY</code>)</li>
<li>Cyble Attack Surface Management (<code>CYBLE_ASM</code>)</li>
<li>Cyble Brand Intelligence &amp; Protection (<code>CYBLE_BIP</code>)</li>
<li>Darkweb IQ (<code>DARKWEB_IQ</code>)</li>
<li>Ellio Threat Intelligence (<code>ELLIO_THREAT_INTEL</code>)</li>
<li>Exeon NDR (<code>EXEON_NDR</code>)</li>
<li>Gravitee (<code>GRAVITEE</code>)</li>
<li>Kaspersky anti targeted attack (<code>KASPERSKY_ANTI_TARGETED_ATTACK</code>)</li>
<li>Microsoft Copilot Interaction (<code>MICROSOFT_COPILOT_INTERACTION</code>)</li>
<li>OSTTRA MarkitWire (<code>OSTTRA_MARKITWIRE</code>)</li>
<li>Proofpoint Adaptive Email Security (<code>PROOFPOINT_ADAPTIVE_EMAIL_SECURITY</code>)</li>
<li>Secomea GateManager (<code>SECOMEA_GATEMANAGER</code>)</li>
<li>Trend Micro Vision One Risk Event (<code>TRENDMICRO_VISION_ONE_RISK_EVENT</code>)</li>
<li>TXOne EdgeIPS (<code>TXONE_EDGEIPS</code>)</li>
<li>Vectra Respond UX (<code>VECTRA_RUX</code>)</li>
<li>Zoho CRM (<code>ZOHO_CRM</code>)</li>
</ul>
<h3>Feature</h3>
<p><strong>View prebuilt parser version content</strong></p>
<p>You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is inactive, you can still see the content of the new preview version for this parser.</p>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>Active Directory</strong>: Version 44.0</p>
<ul>
<li><p>Added optional <code>Connection Timeout</code> and <code>Receive Timeout</code> parameters to configure network connectivity limits in the following action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Anomali ThreatStream</strong>: Version 18.0</p>
<ul>
<li><p>Updated API output handling in the following action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 20.0</p>
<ul>
<li><p>Added support for <code>CHILDHASH</code> and <code>PARENTHASH</code> entity types in the following action:</p>
<ul>
<li><strong>Enrich Entities</strong></li>
</ul></li>
<li><p>Added <code>Entity Type Filter</code> parameter to allow configuring entity types for notifications in the following connector:</p>
<ul>
<li><strong>Google Threat Intelligence - Livehunt Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft 365 Defender</strong>: Version 28.0</p>
<ul>
<li><p>Updated case syncing logic in the following action:</p>
<ul>
<li><strong>Sync Alerts</strong></li>
</ul></li>
<li><p>Updated alert processing logic in the following connector:</p>
<ul>
<li><strong>Microsoft 365 Defender - Incidents Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 112.0</p>
<ul>
<li><p>Added <code>Update Enabled Connectors Only</code> filtering option in the following job:</p>
<ul>
<li><strong>Response Integration &amp; Connector Upgrade Job</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Vertex AI</strong>: Version 8.0</p>
<ul>
<li>Added support for multi-region endpoints across the integration configuration.</li>
</ul>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Change</h3>
<p>Google SecOps has updated the list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.</p>
<p>The following supported default parsers have been updated. Each parser is listed by product name and <code>log_type</code> value, where applicable. This list includes both released default parsers and pending parser updates.</p>
<ul>
<li>Airlock Digital Application Allowlisting (<code>AIRLOCK_DIGITAL</code>)</li>
<li>AIX system (<code>AIX_SYSTEM</code>)</li>
<li>Akamai DataStream 2 (<code>AKAMAI_DATASTREAM_2</code>)</li>
<li>Akamai SIEM Connector (<code>AKAMAI_SIEM_CONNECTOR</code>)</li>
<li>Apache (<code>APACHE</code>)</li>
<li>Arcsight CEF (<code>ARCSIGHT_CEF</code>)</li>
<li>Armis Alerts (<code>ARMIS_ALERTS</code>)</li>
<li>Aruba Switch (<code>ARUBA_SWITCH</code>)</li>
<li>Atlassian Cloud Admin Audit (<code>ATLASSIAN_AUDIT</code>)</li>
<li>Linux Auditing System (AuditD) (<code>AUDITD</code>)</li>
<li>Avaya Aura Experience Portal (<code>AVAYA_AURA</code>)</li>
<li>AWS Cloudtrail (<code>AWS_CLOUDTRAIL</code>)</li>
<li>AWS CloudWatch (<code>AWS_CLOUDWATCH</code>)</li>
<li>AWS Control Tower (<code>AWS_CONTROL_TOWER</code>)</li>
<li>Microsoft Azure Activity (<code>AZURE_ACTIVITY</code>)</li>
<li>Azure AD (<code>AZURE_AD</code>)</li>
<li>Azure AD Organizational Context (<code>AZURE_AD_CONTEXT</code>)</li>
<li>Azure Application Gateway (<code>AZURE_GATEWAY</code>)</li>
<li>Azure Key Vault logging (<code>AZURE_KEYVAULT_AUDIT</code>)</li>
<li>Microsoft Azure Resource (<code>AZURE_RESOURCE_LOGS</code>)</li>
<li>Blue Coat Proxy (<code>BLUECOAT_WEBPROXY</code>)</li>
<li>BeyondTrust (<code>BOMGAR</code>)</li>
<li>Cato Networks (<code>CATO_NETWORKS</code>)</li>
<li>Check Point (<code>CHECKPOINT_FIREWALL</code>)</li>
<li>Check Point Harmony (<code>CHECKPOINT_HARMONY</code>)</li>
<li>Chrome Management (<code>CHROME_MANAGEMENT</code>)</li>
<li>ChromeOS XDR (<code>CHROMEOS_XDR</code>)</li>
<li>Cisco ASA (<code>CISCO_ASA_FIREWALL</code>)</li>
<li>Cisco Email Security (<code>CISCO_EMAIL_SECURITY</code>)</li>
<li>Cisco Firepower NGFW (<code>CISCO_FIREPOWER_FIREWALL</code>)</li>
<li>Cisco FireSIGHT Management Center (<code>CISCO_FIRESIGHT</code>)</li>
<li>Cisco ISE (<code>CISCO_ISE</code>)</li>
<li>Cisco Router (<code>CISCO_ROUTER</code>)</li>
<li>Cisco Switch (<code>CISCO_SWITCH</code>)</li>
<li>Cisco UCM (<code>CISCO_UCM</code>)</li>
<li>Claroty Xdome (<code>CLAROTY_XDOME</code>)</li>
<li>Claude Compliance Logs (<code>CLAUDE_COMPLIANCE_LOGS</code>)</li>
<li>HP Aruba (ClearPass) (<code>CLEARPASS</code>)</li>
<li>Cloudflare (<code>CLOUDFLARE</code>)</li>
<li>Palo Alto Cortex XDR Alerts (<code>CORTEX_XDR</code>)</li>
<li>CrowdStrike Falcon (<code>CS_EDR</code>)</li>
<li>Darktrace (<code>DARKTRACE</code>)</li>
<li>EfficientIP DDI (<code>EFFICIENTIP_DDI</code>)</li>
<li>F5 ASM (<code>F5_ASM</code>)</li>
<li>F5 BIGIP LTM (<code>F5_BIGIP_LTM</code>)</li>
<li>Fastly CDN (<code>FASTLY_CDN</code>)</li>
<li>FireEye eMPS (<code>FIREEYE_EMPS</code>)</li>
<li>FireEye HX (<code>FIREEYE_HX</code>)</li>
<li>FireEye NX (<code>FIREEYE_NX</code>)</li>
<li>Forcepoint Proxy (<code>FORCEPOINT_WEBPROXY</code>)</li>
<li>FortiGate (<code>FORTINET_FIREWALL</code>)</li>
<li>Fortinet FortiAnalyzer (<code>FORTINET_FORTIANALYZER</code>)</li>
<li>Fortinet FortiClient (<code>FORTINET_FORTICLIENT</code>)</li>
<li>Fortinet Switch (<code>FORTINET_SWITCH</code>)</li>
<li>GCP Cloud Audit (<code>GCP_CLOUDAUDIT</code>)</li>
<li>Security Command Center External Exposure (<code>GCP_SECURITYCENTER_EXTERNAL_EXPOSURE</code>)</li>
<li>Gitlab (<code>GITLAB</code>)</li>
<li>Google Threat Intelligence IOC (<code>GTI_IOC</code>)</li>
<li>AWS GuardDuty (<code>GUARDDUTY</code>)</li>
<li>Huawei Switches (<code>HUAWEI_SWITCH</code>)</li>
<li>IBM Security Access Manager (<code>IBM_SAM</code>)</li>
<li>Microsoft IIS (<code>IIS</code>)</li>
<li>Illumio Core (<code>ILLUMIO_CORE</code>)</li>
<li>Imperva SecureSphere Management (<code>IMPERVA_SECURESPHERE</code>)</li>
<li>Infoblox (<code>INFOBLOX</code>)</li>
<li>Infoblox DHCP (<code>INFOBLOX_DHCP</code>)</li>
<li>Jamf pro context (<code>JAMF_PRO_CONTEXT</code>)</li>
<li>Mobile Endpoint Security (<code>LOOKOUT_MOBILE_ENDPOINT_SECURITY</code>)</li>
<li>Apple macOS (<code>MACOS</code>)</li>
<li>McAfee IPS (<code>MCAFEE_IPS</code>)</li>
<li>Micro Focus iManager (<code>MICROFOCUS_IMANAGER</code>)</li>
<li>Microsoft Defender for Endpoint (<code>MICROSOFT_DEFENDER_ENDPOINT</code>)</li>
<li>Microsoft Defender for Office 365 (<code>MICROSOFT_DEFENDER_MAIL</code>)</li>
<li>Microsoft Graph API Alerts (<code>MICROSOFT_GRAPH_ALERT</code>)</li>
<li>Microsoft Sentinel (<code>MICROSOFT_SENTINEL</code>)</li>
<li>Microsoft SQL Server (<code>MICROSOFT_SQL</code>)</li>
<li>Mimecast URL Logs (<code>MIMECAST_URL_LOGS</code>)</li>
<li>MISP Threat Intelligence (<code>MISP_IOC</code>)</li>
<li>NetApp ONTAP (<code>NETAPP_ONTAP</code>)</li>
<li>Netskope V2 (<code>NETSKOPE_ALERT_V2</code>)</li>
<li>Unix system (<code>NIX_SYSTEM</code>)</li>
<li>Office 365 (<code>OFFICE_365</code>)</li>
<li>Okta (<code>OKTA</code>)</li>
<li>Onapsis (<code>ONAPSIS</code>)</li>
<li>OpenVPN (<code>OPEN_VPN</code>)</li>
<li>Oracle Fusion (<code>ORACLE_FUSION</code>)</li>
<li>Ping Identity (<code>PING</code>)</li>
<li>Proofpoint Sendmail Sentrion (<code>PROOFPOINT_SENDMAIL_SENTRION</code>)</li>
<li>SailPoint IAM (<code>SAILPOINT_IAM</code>)</li>
<li>Salesforce (<code>SALESFORCE</code>)</li>
<li>Sendmail (<code>SENDMAIL</code>)</li>
<li>Sentinelone Alerts (<code>SENTINELONE_ALERT</code>)</li>
<li>ServiceNow Audit (<code>SERVICENOW_AUDIT</code>)</li>
<li>ServiceNow CMDB (<code>SERVICENOW_CMDB</code>)</li>
<li>ServiceNow Security (<code>SERVICENOW_SECURITY</code>)</li>
<li>SonicWall (<code>SONIC_FIREWALL</code>)</li>
<li>STIX Threat Intelligence (<code>STIX</code>)</li>
<li>Tanium Threat Response (<code>TANIUM_THREAT_RESPONSE</code>)</li>
<li>Thinkst Canary (<code>THINKST_CANARY</code>)</li>
<li>ThreatConnect IOC V3 (<code>THREATCONNECT_IOC_V3</code>)</li>
<li>ThreatLocker Platform (<code>THREATLOCKER</code>)</li>
<li>Varonis (<code>VARONIS</code>)</li>
<li>VMware ESXi (<code>VMWARE_ESX</code>)</li>
<li>Windows DNS (<code>WINDOWS_DNS</code>)</li>
<li>Windows Event (<code>WINEVTLOG</code>)</li>
<li>Windows Event (XML) (<code>WINEVTLOG_XML</code>)</li>
<li>wiz.io (<code>WIZ_IO</code>)</li>
<li>Workspace Activities (<code>WORKSPACE_ACTIVITY</code>)</li>
<li>Zoom Operation Logs (<code>ZOOM_OPERATION_LOGS</code>)</li>
</ul>
<p>The following log types were added without a default parser. Each parser is listed by product name and <code>log_type</code> value, where applicable.</p>
<ul>
<li>Adobe Experience Platform (<code>ADOBE_EXPERIENCE_PLATFORM</code>)</li>
<li>AudioCodes Session Border Controller (<code>AUDIOCODES_SBC</code>)</li>
<li>Azure Application Gateway for Containers (<code>AZURE_GATEWAY_CONTAINERS</code>)</li>
<li>Azure Logic Apps (<code>AZURE_LOGIC_APPS</code>)</li>
<li>Azure NAT Gateway Flow (<code>AZURE_NATGW_FLOW</code>)</li>
<li>Broadcom DX NetOps Spectrum (<code>BROADCOM_DX_NETOPS_SPECTRUM</code>)</li>
<li>Carto Activity (<code>CARTO_ACTIVITY</code>)</li>
<li>Claude Code Observability (<code>CLAUDE_CODE_OBSERVABILITY</code>)</li>
<li>Cyble Attack Surface Management (<code>CYBLE_ASM</code>)</li>
<li>Cyble Brand Intelligence &amp; Protection (<code>CYBLE_BIP</code>)</li>
<li>Darkweb IQ (<code>DARKWEB_IQ</code>)</li>
<li>Ellio Threat Intelligence (<code>ELLIO_THREAT_INTEL</code>)</li>
<li>Exeon NDR (<code>EXEON_NDR</code>)</li>
<li>Gravitee (<code>GRAVITEE</code>)</li>
<li>Kaspersky anti targeted attack (<code>KASPERSKY_ANTI_TARGETED_ATTACK</code>)</li>
<li>Microsoft Copilot Interaction (<code>MICROSOFT_COPILOT_INTERACTION</code>)</li>
<li>OSTTRA MarkitWire (<code>OSTTRA_MARKITWIRE</code>)</li>
<li>Proofpoint Adaptive Email Security (<code>PROOFPOINT_ADAPTIVE_EMAIL_SECURITY</code>)</li>
<li>Secomea GateManager (<code>SECOMEA_GATEMANAGER</code>)</li>
<li>Trend Micro Vision One Risk Event (<code>TRENDMICRO_VISION_ONE_RISK_EVENT</code>)</li>
<li>TXOne EdgeIPS (<code>TXONE_EDGEIPS</code>)</li>
<li>Vectra Respond UX (<code>VECTRA_RUX</code>)</li>
<li>Zoho CRM (<code>ZOHO_CRM</code>)</li>
</ul>
<h3>Feature</h3>
<p><strong>View prebuilt parser version content</strong></p>
<p>You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is inactive, you can still see the content of the new preview version for this parser.</p>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Announcement</h3>
<p>A new Managed Service for Apache Airflow release has started on
<strong>July 29, 2026</strong>. Get ready for upcoming changes and features as we roll out
the new release to all regions. This release is in progress at the moment.
Listed changes and features might not be available in some regions yet.</p>
<h3>Feature</h3>
<p><strong>Airflow 3.2.2</strong> is available in Managed Airflow (Gen 3).</p>
<h3>Change</h3>
<p><em>(Airflow 3.2.2)</em> The
<a href="https://airflow.apache.org/docs/apache-airflow/stable/core-concepts/multi-team.html">Multi-Team</a>
Airflow feature isn't available. The <code>[core]multi_team</code> Airflow configuration
option is set to <code>False</code> and it isn't possible to override it.</p>
<h3>Fixed</h3>
<p><em>(Airflow 3.2.2)</em> Backported
<a href="https://github.com/apache/airflow/pull/69877">#69877</a> to restore the ability
to deliver failure and retry alerts through a pluggable email backend
(configured through the <code>[email]email_backend</code> Airflow configuration option).</p>
<h3>Change</h3>
<p><em>(Managed Airflow Gen 3 with Airflow 2)</em> Default triggerer resources are
changing to 1 vCPU and 2 GB memory to match Airflow 3 defaults. This change is
available in the Google Cloud CLI, Terraform, and Cloud Composer API and is
gradually rolling out in the Google Cloud console.</p>
<h3>Fixed</h3>
<p>A correct error message is now generated when an environment creation request
fails because of malformed network and subnetwork identifiers.</p>
<h3>Fixed</h3>
<p><em>(Available without upgrading)</em> The correct default task priority weight of <code>1</code>
is now shown for tasks in the Google Cloud console.</p>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-3">Airflow builds</a>
are available in Managed Airflow (Gen 3):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-3-2-2-build-0">composer-3-airflow-3.2.2-build.0</a></li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-3-1-8-build-2">composer-3-airflow-3.1.8-build.2</a></li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-11-1-build-13">composer-3-airflow-2.11.1-build.13</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-10-5-build-46">composer-3-airflow-2.10.5-build.46</a></li>
</ul>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-2">images</a>
are available in Managed Airflow (Gen 2):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-8-airflow-2-11-1">composer-2.17.8-airflow-2.11.1</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-8-airflow-2-10-5">composer-2.17.8-airflow-2.10.5</a></li>
</ul>
<h3>Deprecated</h3>
<p>The following Managed Airflow versions and builds have reached their
<a href="https://docs.cloud.google.com/composer/docs/composer-versioning-overview#version-deprecation-and-support">end of support period</a>:
composer-3-airflow-2.10.5-build.10, composer-3-airflow-2.9.3-build.30,
composer-2.13.8-airflow-2.9.3, and composer-2.13.8-airflow-2.10.5.</p>
<h2 class="release-note-product-title">reCAPTCHA</h2>
<h3>Feature</h3>
<p>The Agent overview dashboard is available on the Google Cloud Fraud Defense home page. This dashboard helps you monitor and analyze automated agent traffic on your site by distinguishing verified agents from suspected agents.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/recaptcha/docs/monitor-agents">Monitor agent traffic</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 28, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_28_2026</id>
    <updated>2026-07-28T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_28_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<aside class="note"><strong>Note:</strong><span> IAM group authentication is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>
for new AlloyDB clusters. To enable this feature on an existing cluster,
contact your Google Cloud account team.</span></aside>
<p>IAM group authentication for AlloyDB is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a> for new clusters running PostgreSQL 15 and later. This feature simplifies database user management by allowing access management at the group level, where group members inherit database roles and permissions. To use this feature, enable the <code>alloydb.iam_authentication</code> and <code>alloydb.iam_group_authentication</code> database flags.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/database-users/iam-authentication#group-auth">IAM group authentication</a> and <a href="https://docs.cloud.google.com/alloydb/docs/database-users/manage-iam-auth#group">Manage IAM authentication</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p>Hyperdisk Balanced volumes on C4D instances have increased maximum throughput
limits for these machine types:</p>
<ul>
<li><code>c4d-*-96</code>: 3,125 MiB/s (up from 2,800 MiB/s).</li>
<li><code>c4d-*-192</code>: 6,250 MiB/s (up from 4,800 MiB/s).</li>
<li><code>c4d-*-384</code>: 12,500 MiB/s (up from 10,000 MiB/s).</li>
</ul>
<p>For detailed performance limits, see
<a href="https://docs.cloud.google.com/compute/docs/disks/hd-types/hyperdisk-balanced#perf-limits">Hyperdisk Balanced performance limits when attached to an instance</a>.</p>
<h2 class="release-note-product-title">Confidential VM</h2>
<h3>Issue</h3>
<p>Starting August 2026, Confidential VM instances using AMD SEV-SNP might
have longer boot times and performance changes due to a guest
kernel migration and security updates. This issue is expected to be resolved
by November 2026. Confidential VM instances using AMD SEV or Intel TDX aren't
affected.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-129-19506-299-60_">cos-129-19506-299-60 <a id='"cos-arm64-129-19506-299-60"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/1028c7249687e9528c5a2ec2ac154416ad9d8c50
">COS-6.12.94</a></td>
<td>v27.5.1</td>
<td>v2.2.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.299.60/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Updated udev rule for protected_stateful_partition</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/fluent-bit to v4.2.7.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-29111 in sys-apps/systemd</p>
<h3>Security</h3>
<p>Fixed CVE-2026-3644 in dev-lang/python</p>
<h3>Security</h3>
<p>Fixed CVE-2026-40355 and CVE-2026-40356 in
app-crypt/mit-krb5.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53381 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53385 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53388 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53391 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53393 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53394 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53397 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53398 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53400 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and
CVE-2026-60002 in openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6019 in dev-lang/python</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63795 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63800 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63802 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63806 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63807 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63809 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63810 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63823 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63824 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63827 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63828 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63829 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63830 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63833 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-64187 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-64189 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-125-19216-532-42_">cos-125-19216-532-42 <a id='"cos-arm64-125-19216-532-42"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/9afaeb55aac96322f3e70cd0cf09eb12fcd168f1
">COS-6.12.94</a></td>
<td>v27.5.1</td>
<td>v2.1.9</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.532.42/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Fixed an important bug for xfs file system users.</p>
<h3>Fixed</h3>
<p>Updated udev rule for protected_stateful_partition</p>
<h3>Security</h3>
<p>Fixed CVE-2026-29111 in sys-apps/systemd</p>
<h3>Security</h3>
<p>Fixed CVE-2026-3644 in dev-lang/python</p>
<h3>Security</h3>
<p>Fixed CVE-2026-40355 and CVE-2026-40356 in
app-crypt/mit-krb5.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53381 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53385 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53388 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53391 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53393 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53394 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53397 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53398 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53400 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and
CVE-2026-60002 in openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6019 in dev-lang/python</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63795 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63800 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63802 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63806 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63807 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63809 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63810 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63823 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63824 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63827 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63828 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63829 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63830 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63833 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-64187 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-64189 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-675-28_">cos-117-18613-675-28 <a id='"cos-arm64-117-18613-675-28"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/f4a21a19d7b0db90cb357d9082c589fbede7f6fd
">COS-6.6.143</a></td>
<td>v24.0.9</td>
<td>v1.7.34</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.675.28/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded net-fs/cifs-utils to v7.7, Upgraded sys-libs/talloc to v2.4.4-r1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-29111 in sys-apps/systemd</p>
<h3>Security</h3>
<p>Fixed CVE-2026-40355 and CVE-2026-40356 in
app-crypt/mit-krb5.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53381 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53385 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53388 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53391 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53397 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53398 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6019 in dev-lang/python</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63794 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63795 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63800 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63802 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63807 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63809 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63823 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63824 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63827 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63828 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-63830 in the Linux kernel.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Microsoft Teams federated connector is generally available (GA)</strong></p>
<p>The Microsoft Teams federated data store is generally available (GA) in Gemini Enterprise. Connect Microsoft Teams to query channels, chats, teams, and messages, and execute supported actions directly from the assistant.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/ms-teams">Connect Microsoft Teams</a>.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>GKE now supports opting out of the default <code>kubernetes.io/arch=arm64:NoSchedule</code>
taint on Arm nodes in Standard node pools and in custom ComputeClasses. To opt
out of the default taint, set the <code>--node-architecture-taint-behavior</code> gcloud
CLI flag to <code>NONE</code> for a node pool or set the
<code>taintConfig.architectureTaintBehavior</code> field to <code>NONE</code> for a ComputeClass. By
configuring this behavior, you allow workloads that lack explicit Arm
tolerations to be scheduled on Arm-based machine families (such as N4A and C4A).
This is useful for running multi-architecture workloads or simplifying
scheduling in mixed-mode clusters. For more information, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/prepare-arm-workloads-for-deployment#configure-default-taint">Configure the default Arm architecture taint</a>.</p>
<h3>Feature</h3>
<p>GKE Gateway and Inference Gateway now support Cross-Origin Resource Sharing
(CORS). You can configure a CORS filter directly on an <code>HTTPRoute</code> resource by
using the portable syntax standardized by
<a href="https://gateway-api.sigs.k8s.io/guides/user-guides/http-cors/">Gateway API</a>.
This feature is available in Preview in GKE version 1.35 and later for the
following GatewayClasses:</p>
<ul>
<li><code>gke-l7-rilb</code></li>
<li><code>gke-l7-regional-external-managed</code></li>
<li><code>gke-l7-global-external-managed</code></li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/deploying-gateways#configure-cors">Configure Cross-Origin Resource Sharing</a>.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Data RBAC for first-party (1P) cases and alerts</strong></p>
<p><strong>Availability</strong> This feature is now available in public preview for all regions.</p>
<p>Google SecOps now supports data role-based access control (Data RBAC) for first-party (1P) SOAR cases and alerts. This feature automatically applies SIEM data access scopes to alerts and cases ingested using the Chronicle connector, ensuring analysts only see data they are authorized to access.</p>
<p>For more information, see the <a href="https://docs.cloud.google.com/chronicle/docs/secops/release-notes#July_06_2026">Release Note entry for July 6th</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p>Version 1.2.0 of the Google SCC ITSM app and version 1.3.0 of the Google SCC SIR
app have been released.</p>
<p>To reflect this update, the ServiceNow integration guide is updated with
the following changes:</p>
<ul>
<li>Added support for ServiceNow Yokohama, Zurich, and Australia versions.</li>
<li><p>Added the following features:</p>
<ul>
<li>Mute and unmute findings</li>
<li>Create mute rules</li>
<li>Create Configuration Item (CI) lookup rules</li>
<li>View the action log</li>
</ul></li>
<li><p>Updated setup instructions for Java KeyStore certificates.</p></li>
<li><p>Added additional troubleshooting steps for maximum execution time exceeded
errors, data collection issues, and ECC Queue timeout errors.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/security-command-center/docs/how-to-configure-scc-servicenow">Sending Security Command Center data to
ServiceNow</a>.</p>
<h2 class="release-note-product-title">Spanner</h2>
<h3>Feature</h3>
<p>Spanner supports creating tables without defining primary keys.
When you create a table without a primary key, Spanner creates a
hidden <code>rowid</code> column that serves as the primary key. For more information, see
<a href="https://docs.cloud.google.com/spanner/docs/primary-key-default-value#tables-without-primary-keys">Create a table without defining a primary key</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 27, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_27_2026</id>
    <updated>2026-07-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_27_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>AlloyDB write endpoints are now available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.
Write endpoints simplify database connection management by providing a stable
domain name service (DNS) name for your applications, decoupling them from
instance IP addresses. During disaster recovery switchovers or failovers,
AlloyDB automatically updates the endpoint to point to the new primary instance.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/alloydb/docs/manage-write-endpoints">Manage database connections with write endpoints</a>.</p>
<h3>Feature</h3>
<p>AlloyDB now supports cross-region failover in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. You can
optionally enable cross-region failover to automate the recreation of the
original primary when a secondary cluster is promoted while maintaining your
replication topology without requiring manual cluster deletion or re-creation.
Cross-region failover is supported only for topologies with a single primary
cluster and a single secondary cluster.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/cross-region-replication/about-cross-region-replication">About cross-region
replication</a>
and <a href="https://docs.cloud.google.com/alloydb/docs/cross-region-replication/work-with-cross-region-replication">Work with cross-region
replication</a>.</p>
<h3>Feature</h3>
<p>External search with AlloyDB now supports <a href="https://docs.cloud.google.com/alloydb/docs/opensearch">OpenSearch</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.
You can use the <a href="https://docs.cloud.google.com/alloydb/docs/reference/extensions#external_search_fdw"><code>external_search_fdw</code></a> extension to connect to an OpenSearch cluster and query its data directly from your database.</p>
<h2 class="release-note-product-title">Anthos Config Management</h2>
<h3>Change</h3>
<p>Upgraded bundled Helm version from v3.20.2 to <a href="https://github.com/helm/helm/releases/tag/v3.21.1">v3.21.1</a> to pick up vulnerability fixes. To understand the changes in each release, review the <a href="https://github.com/helm/helm/releases">changelogs</a>.</p>
<h3>Change</h3>
<p>Addressed multiple Common Vulnerabilities and Exposures (CVEs) by updating dependencies.</p>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On July 27th, 2026, we released an updated version of Apigee (1-18-0-apigee-2).</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release began today and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.</span></aside>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>534852923</strong></td>
<td><strong>Security fix for Apigee.</strong> Fixed a security issue in the Java Callout policy.</td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fix for Apigee infrastructure.</strong></td>
</tr>
</tbody>
</table>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>N/A</strong></td>
<td>Updates to infrastructure and libraries.</td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">App Engine flexible environment Node.js</h2>
<h3>Feature</h3>
<p>Support for the <a href="https://docs.cloud.google.com/appengine/docs/flexible/nodejs/runtime">Node.js 26 runtime</a> is in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Node.js</h2>
<h3>Feature</h3>
<p>Support for the <a href="https://docs.cloud.google.com/appengine/docs/standard/nodejs/runtime">Node.js 26 runtime</a> is in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can discover commercial BigQuery sharing listings on Google Cloud Marketplace with the <strong>Marketplace</strong> filter. For more information, see <a href="https://docs.cloud.google.com/bigquery/docs/analytics-hub-cloud-marketplace#subscribe">Subscribe to a Cloud Marketplace-integrated listing</a>.
This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a> (GA).</p>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/bigquery/docs/change-history"><code>APPENDS</code> and <code>CHANGES</code> change history functions</a>
to view the rows that were appended to or changed in a table during a given time
range. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Feature</h3>
<p>You can use the Google-developed
<a href="https://docs.cloud.google.com/bigquery/docs/odbc-for-bigquery">Open Database Connectivity (ODBC) driver for BigQuery</a>
to connect your applications to BigQuery. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Change</h3>
<p>The feature formerly known as the <em>legacy <code>tabledata.insertAll</code> method</em> is now
called the
<a href="https://docs.cloud.google.com/bigquery/docs/streaming-data-into-bigquery"><em>Storage Write API (REST)</em></a>. The
feature formerly known as the <em>Storage Write API</em> is now called the
<a href="https://docs.cloud.google.com/bigquery/docs/write-api"><em>Storage Write API (gRPC)</em></a>.</p>
<h3>Feature</h3>
<p>BigQuery dataset insights is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a> (GA).</p>
<p><a href="https://docs.cloud.google.com/bigquery/docs/generate-dataset-insights">BigQuery dataset insights</a> helps you
discover and visualize relationships between tables and automatically generate
cross-table queries. You can run and publish these insights to
Knowledge Catalog for agentic grounding use cases, or
generate them on demand without publishing for quick, ad hoc dataset exploration.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>The Bigtable remote MCP server supports the Bigtable Data API, which
provides the <code>execute_sql</code> tool that you can use to query Bigtable data using
natural language prompts. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
For more information, see
<a href="https://docs.cloud.google.com/bigtable/docs/use-bigtable-mcp">Use the Bigtable remote MCP server</a>.</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>Spend cap budgets are now available for a limited set of services (Preview)</strong></p>
<p>Available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>
for
<a href="https://docs.cloud.google.com/billing/docs/how-to/budgets-spend-caps#eligible-services">eligible services</a>,
you can now configure a
<a href="https://docs.cloud.google.com/billing/docs/how-to/budgets-spend-caps"><strong>spend cap budget</strong></a>
to automatically pause usage when your spend exceeds the budget amount you set.</p>
<p>Spend caps are a cost control mechanism. A spend cap is enforced when usage
costs exceed your budget target amount. When enforced, any new request to the
eligible services, within the specified project, are paused and no further
usage costs are accrued until you manually lift the spend cap.</p>
<p>Spend caps typically use <em>estimated costs</em> to trigger the alerts and caps,
enforcing a cap much faster than the <em>actual costs</em> are processed and appear
on billing reports. Even though faster than reports, the enforcement of spend
caps isn't instant and any cost overages are billed as normal.</p>
<p>For more information about spend cap budgets, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/budgets-spend-caps#how-spend-cap-budgets-work">How spend cap budgets work to help you control spend</a></li>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/budgets-spend-caps#configure-spend-cap">Configure a spend cap budget</a></li>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/budgets-spend-caps#lift-spend-cap">Lift an enforced spend cap</a></li>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/budgets-spend-caps#limitations">Limitations of spend cap budgets</a></li>
</ul>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>Service load balancing policies (<code>serviceLbPolicy</code>) are now supported for
regional external Application Load Balancers and regional internal Application Load Balancers. This feature enables
advanced load balancing optimizations such as custom load balancing algorithms,
auto-capacity draining, failover thresholds, and the ability to designate
preferred backends for these load balancers.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/load-balancing/docs/service-lb-policy">Advanced load balancing
optimizations</a>.</p>
<p>This feature is in <strong>Preview</strong>.</p>
<h2 class="release-note-product-title">Cloud NGFW</h2>
<h3>Breaking</h3>
<p>Enabling WildFire in an existing firewall endpoint can cause a temporary
data plane outage. As a result, the WildFire feature is temporarily removed.</p>
<h2 class="release-note-product-title">Cloud Run</h2>
<h3>Feature</h3>
<p>Support for the <a href="https://docs.cloud.google.com/run/docs/runtime-support#node.js">Node.js 26 runtime</a> is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>Support for <a href="https://docs.cloud.google.com/run/docs/configuring/billing-settings#spend-caps">Budget spend caps</a> to pause your Cloud Run workloads is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Run functions</h2>
<h3>Feature</h3>
<p>Support for the <a href="https://docs.cloud.google.com/functions/docs/concepts/execution-environment#node.js">Node.js 26 runtime</a> is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p>The maximum IOPS per GiB for Hyperdisk Balanced Storage Pools have increased from
4 IOPS per GiB. The new limits depend on the provisioning type:</p>
<ul>
<li><strong>Standard performance</strong>: 30 IOPS per GiB</li>
<li><strong>Advanced performance</strong>: 6 IOPS per GiB</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/compute/docs/disks/storage-pools#hdsp-limits">Limits for Hyperdisk Storage Pools</a>.</p>
<h2 class="release-note-product-title">Dataform</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/dataform/docs/deployments">Dataform deployments</a>
provide a centralized experience for creating and managing pipeline
deployments connected to remote Git repositories. This feature is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Transparent thinking</strong></p>
<p>Transparent thinking is generally available (GA). During chat interactions,
the assistant shares its real-time reasoning and planning in the user
interface before calling tools or data sources.</p>
<p>An expandable section displays the tool activity between the thinking phase
and the final answer. This transparency delivers a faster time to first
token (TTFT) and improves perceived latency without increasing total
response time.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/assistant-chat#ask_questions_and_view_sources">Ask questions and view sources</a>.</p>
<h2 class="release-note-product-title">Google Cloud Managed Service for Apache Kafka</h2>
<h3>Feature</h3>
<p>You can now create a Cloud SQL for PostgreSQL Source connector and a Generic PostgreSQL Source connector for Kafka Connect.</p>
<p>A Cloud SQL for PostgreSQL Source connector or Generic PostgreSQL Source connector is an instance of a <a href="https://debezium.io/documentation/reference/stable/connectors/postgresql.html">Debezium PostgreSQL connector</a>. It reads row-level changes from a PostgreSQL database and writes them to topics in a Managed Service for Apache Kafka cluster.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/managed-service-for-apache-kafka/docs/connect-cluster/create-cloud-sql-postgres-source-connector">Create a Cloud SQL for PostgreSQL Source connector</a>, <a href="https://docs.cloud.google.com/managed-service-for-apache-kafka/docs/connect-cluster/create-generic-postgres-source-connector">Create a Generic PostgreSQL Source connector</a>, and <a href="https://docs.cloud.google.com/managed-service-for-apache-kafka/docs/connect-cluster/troubleshoot-postgres-source-connector">Troubleshoot a PostgreSQL Source connector</a>.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>In GKE version 1.36 and later, GKE Dataplane V2 with NetworkPolicies supports up
to 15,000 nodes per cluster, increased from the previous limit of 7,500 nodes.
For clusters exceeding 5,000 nodes, contact Cloud Customer Care to request a
quota increase. For more information, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/planning-large-clusters#clusters-5k-nodes">Cluster size limits and requirements</a>.</p>
<h3>Feature</h3>
<p>In version 1.36.2-gke.1498000 and later, GKE supports mixed-protocol Services of
type LoadBalancer in general availability (GA). Mixed-protocol Services let both
external (NetLB) and internal (ILB) passthrough Network Load Balancers handle
simultaneous TCP and UDP traffic on a single IP address across IPv4, IPv6, and
dual-stack environments.</p>
<h3>Security</h3>
<p>The general availability (GA) stage of mixed-protocol Services of type
LoadBalancer fixes errors in traffic routing from stages prior to GA. This
feature is in the GA stage in GKE version 1.36.2-gke.1498000 and later.</p>
<h2 class="release-note-product-title">Guest Environment</h2>
<h3>Fixed</h3>
<p>Version <code>20260716.00</code> of the <a href="https://docs.cloud.google.com/compute/docs/images/guest-agent">guest agent</a>
is now available for all supported operating systems. This version introduces
the following fixes:</p>
<ul>
<li>The <code>systemctl start</code> operations performed by the OS Login module no longer
leave behind zombie processes.</li>
<li>The extensions monitor, which monitors the health of extensions that the
guest agent manages, no longer logs an error when it reads an empty log file
from an extension.</li>
<li>Dependency updates address multiple high-severity CVEs, such as
<a href="https://www.cve.org/CVERecord?id=CVE-2026-39830">CVE-2026-39830</a> and
<a href="https://www.cve.org/CVERecord?id=CVE-2026-39832">CVE-2026-39832</a>.</li>
</ul>
<h2 class="release-note-product-title">Identity and Access Management</h2>
<h3>Feature</h3>
<p>Managed workload identities for Compute Engine are
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/iam/docs/create-managed-workload-identities">Configure managed workload identity authentication for Compute Engine</a>.</p>
<h2 class="release-note-product-title">Memorystore for Valkey</h2>
<h3>Feature</h3>
<p>Added <a href="https://docs.cloud.google.com/memorystore/docs/valkey/supported-versions">support</a> for Valkey version 9.1. As a result, you can now upgrade the version of your Memorystore for Valkey instance to 9.1. For more information, see <a href="https://docs.cloud.google.com/memorystore/docs/valkey/about-upgrading-version">About upgrading the Valkey version of an instance</a>. This feature is available in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Secret Manager</h2>
<h3>Feature</h3>
<p>Automatic rotation of regional Cloud SQL database credentials in Secret Manager
is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. This feature
lets you automatically generate secure passwords, update target Cloud SQL
database instances (PostgreSQL or SQL Server), and rotate secret versions on a
configured schedule without custom Cloud Run functions.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/secret-manager/regional-secrets/autorotation-of-cloudsql-secrets-rs">Automatic rotation of Cloud SQL
secrets</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p>For the Security Command Center Premium tier, you can enable
<a href="https://docs.cloud.google.com/security-command-center/docs/ai-protection-overview">AI Protection</a> at the
project level.</p>
<p>Project-level activations include access to the <a href="https://docs.cloud.google.com/security-command-center/docs/assess-risk#ai-protection">AI security
dashboard</a>, <a href="https://docs.cloud.google.com/security-command-center/docs/agent-engine-threat-detection-overview">AI threat
detection</a>, and <a href="https://docs.cloud.google.com/security-command-center/docs/ai-protection-overview#review-findings">AI
vulnerability and misconfiguration
findings</a>.</p>
<p>Some features of AI Protection are only available for
organization-level activations. For more information, see <a href="https://docs.cloud.google.com/security-command-center/docs/configure-ai-protection">Configure AI
Protection</a>.</p>
<h3>Feature</h3>
<p>For the Security Command Center Premium tier, you can enable
<a href="https://docs.cloud.google.com/security-command-center/docs/ai-protection-overview">AI Protection</a> at the
project level.</p>
<p>Project-level activations include access to the <a href="https://docs.cloud.google.com/security-command-center/docs/assess-risk#ai-protection">AI security
dashboard</a>, <a href="https://docs.cloud.google.com/security-command-center/docs/agent-engine-threat-detection-overview">AI threat
detection</a>, and <a href="https://docs.cloud.google.com/security-command-center/docs/review-ai-security#review-findings">AI
vulnerability and misconfiguration
findings</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/security-command-center/docs/configure-ai-protection">Configure AI
Protection</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 26, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_26_2026</id>
    <updated>2026-07-26T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_26_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>Customizable schedules for multi-event rules</strong></p>
<p><a href="https://docs.cloud.google.com/chronicle/docs/detection/set-customized-schedule">Customizable schedules for multi-event rules</a> are available in public preview. You can customize rule execution schedules on the <strong>Rule schedule</strong> tab to specify a first-run delay offset that accounts for data ingestion latency. The system also performs automated background true-up runs to catch late-arriving logs and process metadata enrichment without requiring manual system interventions. This gives you precise control over detection evaluation timing, reduces false negatives without missing detections, and promotes alert accuracy.</p>
<p>To view or modify rule schedules using custom Identity and Access Management (IAM) roles, update your <a href="https://docs.cloud.google.com/chronicle/docs/reference/feature-rbac-permissions-roles">IAM permissions</a> to include the following:</p>
<ul>
<li><code>chronicle.ruleDeployments.update</code> to update individual rule schedules using the API.</li>
<li><code>chronicle.rules.modifyRules</code> to modify rule schedules using the web interface or in batch using the API.</li>
</ul>
<p>If you use <a href="https://docs.cloud.google.com/chronicle/docs/onboard/configure-feature-access#predefined-roles">predefined IAM roles</a>, such as Chronicle API Admin (<code>roles/chronicle.admin</code>) or Chronicle API Editor (<code>roles/chronicle.editor</code>), these permissions are included automatically.</p>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Investigation and case management experience</strong></p>
<p>This feature is in public preview. Google SecOps now includes a revamped
Investigation Management experience that supports tracking raw UDM events and
detections alongside alerts to accommodate new investigation types (such as
retrohunt and threat hunt) and higher investigation volumes in cases. You can
navigate your case queue using customizable table views, side-drawer previews,
and integrated UDM Search workflows. For more information, see
<a href="https://docs.cloud.google.com/chronicle/docs/secops/investigate/investigation-management/investigation-management-overview">Investigation and case management overview</a>.</p>
<p>This preview is currently supported only for single-SIEM deployments (instances
where a single Google SecOps SIEM instance ingests data into SOAR) and does not
support federated or MSSP environments.</p>
<p>Additional enhancements include:</p>
<ul>
<li><strong>Attach SIEM search results to cases:</strong> Manually attach individual UDM events
or detections directly from SIEM search results to new or existing cases as core
evidence (supporting up to 500 detections and 5,000 UDM events per case). For
details, see <a href="https://docs.cloud.google.com/chronicle/docs/secops/investigate/investigation-management/create-case-from-search">Attach SIEM search results to cases</a>.</li>
<li><strong>Interactive Events Viewer:</strong> Dive directly into technical evidence from an
interactive side panel. Inspect parsed UDM records, review original raw logs,
pin key evidence to your case, and build detection exclusions in real time. For
details, see <a href="https://docs.cloud.google.com/chronicle/docs/secops/investigate/investigation-management/use-events-viewer">Use the Events Viewer</a>.</li>
<li><strong>Configure new default views:</strong> Before enabling the updated Cases experience, 
set up your default views under <strong>SOAR Settings &gt; Case Data &gt; Views</strong>. Make sure 
to manually copy over advanced widget configurations (such as 
<strong>Safe HTML Rendering</strong> or custom conditions) from the <strong>Default Alert View</strong> 
and <strong>Default Case View</strong> to the <strong>New Default Alert View</strong> and 
<strong>New Default Case View</strong> to preserve your preferred setups.</li>
</ul>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.95 is being rolled out to the first phase of regions as listed 
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 25, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_25_2026</id>
    <updated>2026-07-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_25_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_19_2026">Release 6.3.94</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 24, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_24_2026</id>
    <updated>2026-07-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_24_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee API hub</h2>
<h3>Feature</h3>
<p><strong>General availability (GA) launch of Model Context Protocol (MCP) in API hub</strong></p>
<p>The API hub MCP server is <a href="https://cloud.google.com/products#product-launch-stages">Generally Available (GA)</a>. This release enables seamless integration between your AI agents and API hub, allowing your applications to discover, query, and manage your API ecosystem using natural language.</p>
<p><strong>What's new in GA</strong></p>
<ul>
<li><strong>Expanded read and write capabilities</strong>: AI agents can create, update, and delete APIs, versions, specs, and deployments. They can also configure and deploy MCP discovery proxies in Apigee.</li>
<li><strong>Global endpoint routing</strong>: Connect to the API hub MCP server using the global endpoint (<code>apihub.googleapis.com/mcp</code>), in addition to the supported regional endpoints. For a list of supported regions, see the <a href="https://docs.cloud.google.com/apigee/docs/reference/apis/apihub/mcp#server-endpoints">API hub MCP reference</a>.</li>
<li><strong>Granular OAuth scopes</strong>: Use service-specific OAuth scopes (<code>apihub.readonly</code> and <code>apihub.readwrite</code>) for more secure access.</li>
<li><strong>Model Armor integration</strong>: Protect MCP tool invocations from prompt-injection and other attacks by integrating with Model Armor.</li>
</ul>
<p>For configuration details and a complete list of available tools, see <a href="https://docs.cloud.google.com/apigee/docs/reference/apis/apihub/mcp">API hub MCP reference</a>.</p>
<h3>Feature</h3>
<p><strong>Configure and deploy MCP servers with API hub RPC</strong></p>
<p>API hub now includes a new RPC, <code>ConfigureAndDeployServer</code>, which enables the configuration and deployment of Model Context Protocol (MCP) servers directly to an Apigee runtime.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/apigee/docs/apihub/manage-mcp-proxies">Manage MCP proxies</a> and the <a href="https://docs.cloud.google.com/apigee/docs/reference/apis/apihub/">API hub reference</a>.</p>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1168">v1.16.8</h3>
<p>On July 24, 2026 we released an updated version of the Apigee hybrid software, v1.16.8.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version 1.16</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>493354568</strong></td>
<td><strong>Fixed an issue where component-specific nodeSelector configurations are ignored in Helm charts.</strong></td>
</tr>
</tbody>
</table>
<h3>Feature</h3>
<p><strong>Runtime rollout strategy configuration</strong></p>
<p>In this release, you can configure the rollout strategy used when updating runtime (message processor) ReplicaSets by setting the <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/config-prop-ref#runtime-release-strategy"><code>runtime.release.strategy</code></a> property (with options <code>rolling</code>, <code>scale-down-first</code>, or <code>none</code>) or per-environment with <code>envs[].components.runtime.release.strategy</code> in your overrides configuration file. The property defaults to <code>rolling</code>.</p>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">Artifact Registry</h2>
<h3>Feature</h3>
<p>Connector repositories act as proxies for upstream sources. All requests to the
repository are proxied to the upstream source and no artifacts are cached in
Artifact Registry. This configuration allows for full auditability of
upstream sources and supports cases where third-party policies prevent artifact
caching. For more information, see
<a href="https://docs.cloud.google.com/artifact-registry/docs/repositories/connector-overview">Connector repositories overview</a>.</p>
<h2 class="release-note-product-title">Backup and DR</h2>
<h3>Feature</h3>
<p>You can now use Model Context Protocol (MCP) servers with Backup and DR Service to connect AI assistants and applications—such as the Gemini CLI, ChatGPT, or Claude—with your backup environment. Using either the local or remote MCP server, you can use natural language prompts to perform and automate Backup and DR tasks, such as creating backup plans, triggering on-demand backups, and managing backup vaults. Comprehensive reference documentation is also available with detailed specifications, input and output schemas, and sample invocation commands for all available MCP tools.</p>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/integrations/remote-mcp">Use the Backup and DR remote MCP server</a></li>
<li><a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/reference/mcp">Backup and DR MCP reference</a></li>
</ul>
<h2 class="release-note-product-title">Cloud API Registry</h2>
<h3>Deprecated</h3>
<p>As of July 30, 2026, support for Model Context Protocol (MCP) servers and tools
will be shut down. You will not be able to retrieve, list, enable, and disable
MCP servers and tools using the Cloud API Registry API. For more
information, see
<a href="https://docs.cloud.google.com/api-registry/docs/deprecations">Feature deprecations</a>.</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>Early signals for AI workloads</strong></p>
<p>For AI workloads (such as Gemini API and Vertex AI),
you can now view early anomalies. Early anomalies use near real-time cost
estimates to provide daily, service-level insights before finalized billing
occurs. You can view these alerts on the <strong>By service (Early signals)</strong> tab
on the Anomalies dashboard in the Google Cloud console. User-configured
thresholds do not apply to early anomalies.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/billing/docs/how-to/manage-anomalies#view-early-anomalies">View early anomalies for AI workloads</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>Cloud SQL for PostgreSQL now supports logical replication using failover slot which you can use with advanced disaster recovery (DR) switchover and replica failover operations to ensure business continuity.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/postgres/advanced-dr-logical-failover-slot">Advanced disaster recovery (DR) with logical failover slot</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility#typegoogleapiscomenvoyextensionsfiltershttpcompressorv3compressor">Envoy Compressor Filter</a>
is now GA in the stable release channel.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p>You can observe real-time virtual machine (VM) distribution across zones,
machine types, and instance states in your managed instance groups (MIGs) by
using the <strong>GCE MIG Instance Distribution Monitoring</strong> dashboard in
Cloud Monitoring. When your group uses location flexibility across zones,
instance flexibility across machine types, or both, this visibility helps you
monitor capacity allocation and diagnose runtime fallback behavior. For more
information, see
<a href="https://docs.cloud.google.com/compute/docs/instance-groups/monitor-instance-distribution">Monitor instance distribution in MIGs</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Gemini 3.6 Flash in US multi-region</strong></p>
<p>If your project is on the allowlist, you can use Gemini 3.6 Flash in the US
multi-region (<code>us</code>) with data residency at-rest (DRZ) and machine learning
processing (MLP).</p>
<p>To request access to Gemini 3.6 Flash in the US multi-region, contact
your Google account team.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/locations">Data residency for Gemini Enterprise Standard and Plus Editions and Gemini Notebook Enterprise</a></p>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Create and edit documents and slides in Canvas (GA)</strong></p>
<p>The Canvas assistant is generally available within the
Gemini Enterprise web app. Canvas is a dedicated, interactive tool thats allows 
you to create and edit AI-generated documents and presentations directly from 
your chats. You can then export these to Google Workspace, Microsoft Office 
formats, and PDF. </p>
<p>For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/assistant-canvas">Create and edit documents and slides in Canvas</a>.</p>
<p>A Gemini Enterprise app administrator must turn on the <strong>Enable canvas</strong> toggle in
the web app feature management settings to let users use it. For more
information about feature controls, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage features on the web
app</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Anthropic's Claude Opus 5</strong></p>
<p><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/partner-models/claude/opus-5">Claude Opus 5</a>
is available in Model Garden.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 5.0</strong></p>
<p>We've released version 5.0 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Feature</h3>
<p><strong>Disposition timing</strong></p>
<p>You can now configure CCAI Platform so agents can attribute wrap-up
time, disposition code, and notes to a previous interaction. You can also let
agents modify the disposition code and notes of previously completed sessions.</p>
<p>Administrators: In the <strong>Settings <span aria-label="and then">&gt;</span> Operation Management <span aria-label="and then">&gt;</span>
 Wrap-up</strong> pane, a new <strong>Manual Wrap-up</strong> section is available.</p>
<p>User experience change: If configured, a new <strong>Previous Sessions</strong> list appears
in the agent adapter.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/configure-disposition-timing">Configure disposition
timing</a>.</p>
<h3>Feature</h3>
<p><strong>API direct access point for chat</strong></p>
<p>The API direct access point (DAP) for chat lets you automatically route incoming
chat sessions to a queue based on a response from an external API endpoint that
you configure. This eliminates the need for end-users to select from a queue
menu.</p>
<p>By default, this capability is inactive. Contact Google Cloud Support to turn it on for your instance.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/api-dap-for-chat">API direct access point for
chat</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where emails were stuck in a <strong>Transferring</strong> state when
moved between queues.</p></li>
<li><p>Fixed an issue where end-users didn't receive messages from agents during
web chats.</p></li>
<li><p>Fixed an issue where calls or chats remained in a queue without being
offered to available agents.</p></li>
<li><p>Fixed an issue where voice calls were prematurely moved from an agent's
queue during a multi-group cascade.</p></li>
<li><p>Fixed an issue where the disposition panel didn't appear after a call ended,
leaving agents unable to change their status without signing out and signing
in.</p></li>
<li><p>Fixed an issue where end-users were incorrectly assigned to teams and skills
they weren't originally part of during bulk CSV imports.</p></li>
<li><p>Fixed an issue where interaction transcripts for calls in non-English
languages were incorrect.</p></li>
<li><p>Fixed an issue in Salesforce integrations where incoming chat audio and
desktop notifications didn't play for agents using the embedded
CCAI Platform widget.</p></li>
<li><p>Fixed an issue where the inactive chat dismissal timer didn't reset after a
chat was transferred from a virtual agent to a human agent.</p></li>
<li><p>Fixed an issue where voicemails disappeared from the queue immediately after
being opened.</p></li>
<li><p>Fixed an issue where the reporting dashboard incorrectly displayed call and
agent status during a cold transfer to another queue.</p></li>
<li><p>Improved rendering performance in the agent desktop mini chat adapter.</p></li>
<li><p>Fixed an issue where the storage path for screen recordings didn't align
with the folder structure displayed in the user interface.</p></li>
<li><p>Fixed an issue where missing public files were incorrectly cached by the CDN
for up to seven days.</p></li>
<li><p>Fixed an issue where agents were automatically redirected to the <strong>Closed</strong>
inbox view after changing an interaction status to <strong>Closed</strong>.</p></li>
<li><p>Fixed an issue where the <strong>You cannot log out when in a chat</strong> notification
was truncated in the chat adapter.</p></li>
<li><p>Fixed an issue with Salesforce integrations where rapid, concurrent data
requests caused information to be lost.</p></li>
<li><p>Fixed an issue where duplicate call recording links were posted to Zendesk
tickets for multi-segment calls.</p></li>
<li><p>Fixed an issue with Salesforce integrations where the UI retained settings
from a previous Salesforce organization after switching to a new
organization.</p></li>
<li><p>Fixed an issue where duplicate customer satisfaction surveys were submitted
and recorded for a single live chat session.</p></li>
<li><p>Fixed an issue where the message field in the chat adapter was inactive when
an agent accepted a new chat.</p></li>
<li><p>Fixed an issue where task virtual agents were incorrectly identified as
<strong>Nobody</strong> when joining a conversation after a transfer from a human agent.</p></li>
<li><p>Fixed an issue that occurred when a chat entered a queue and the greeting
message was sent before an agent was assigned. In these cases, the
associated push notification crashed and logged an error, producing
excessive noise in logs.</p></li>
<li><p>Fixed an issue where the agent's final message in a chat session appeared
after <strong>This chat is ended</strong> in the chat adapter and the CRM transcript.</p></li>
<li><p>Fixed an issue where agents using instances without a CRM configuration
received a <strong>No Account Detected</strong> warning when making outbound calls.</p></li>
<li><p>Fixed an issue where notification chimes played after an agent had connected
to an active call.</p></li>
<li><p>Fixed an issue where the country code list didn't automatically update the
country flag when a phone number was entered without the <code>+</code> prefix.</p></li>
<li><p>Fixed an issue where calls to an agent's personal queue didn't break through
if the agent was also assigned to an inbound queue with breakthrough
disabled.</p></li>
<li><p>Fixed an issue where outbound calls that were transferred to a queue didn't
adhere to the queue's deltacast configuration.</p></li>
<li><p>Fixed an issue where the agent desktop became unstable or didn't load.</p></li>
<li><p>Fixed an issue where wrap-up time was incorrectly reported when agents
exceeded the configured wrap-up time.</p></li>
<li><p>Fixed an issue where the IVR queues dashboard didn't load for instances with
a large volume of queues.</p></li>
<li><p>Fixed an issue where calls to the <code>manager/api/v1/agent_activity_logs</code>
endpoint timed out when <code>sort_direction</code> was turned off.</p></li>
</ul>
<h2 class="release-note-product-title">Google Cloud Marketplace Partners</h2>
<h3>Feature</h3>
<p>You can now use the Cloud Commerce Producer API to programmatically create,
manage, and publish private offers. The API lets you automate your
private offer workflows, including configuring custom pricing models,
attaching EULA or SOW documents, and determining which active offer to amend.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/marketplace/docs/partners/offers/commerce-producer-api">Create and manage private offers using the API</a>
and
<a href="https://docs.cloud.google.com/marketplace/docs/partners/offers/commerce-producer-api#determine-which-offer-to-amend">Determine which offer to amend</a>.</p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Fixed</h3>
<p>A release note published on <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/release-notes#May_06_2025">May 6, 2025</a> stated that each Keepalived instance
virtual router redundancy protocol (VRRP) configuration is configured with a
<code>nopreempt</code> flag to avoid elections when a non-master instance is restarted.</p>
<p>The <code>nopreempt</code> flag was removed in release 1.32.200 and later. For more
information, see <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/troubleshooting/known-issues#keepalived-config-issue">Control plane VIP isn't moved when HAProxy is unavailable</a>.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r31-version-updates">(2026-R31) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1269000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1610000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1638000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1641000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.13-gke.1101000</li>
<li>1.34.9-gke.1287000</li>
<li>1.35.6-gke.1250000</li>
<li>1.36.0-gke.4681000</li>
<li>1.36.2-gke.1346000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.12-gke.1270000</li>
<li>1.34.9-gke.1065000</li>
<li>1.35.6-gke.1049000</li>
<li>1.36.0-gke.3712000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2816000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2846000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2233000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2437000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1913000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.2137000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2746000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2825000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2157000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2246000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1829000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1930000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.12-gke.1270000</li>
<li>1.34.9-gke.1065000</li>
<li>1.35.6-gke.1049000</li>
<li>1.36.0-gke.3712000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2767000</a></li>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2169000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2767000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2169000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1844000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1269000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1610000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1638000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1641000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2846000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2437000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.2137000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1269000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1610000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1638000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1641000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.35.5-gke.1241004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3712000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r31-security-updates">(2026-R31) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.32.13-gke.2137000</td>
<td>cos-117-18613-675-2</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-675-2_">cos-117-18613-675-2 release notes</a></td>
</tr>
<tr>
<td>1.34.9-gke.1610000</td>
<td>cos-125-19216-532-3</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-532-3_">cos-125-19216-532-3 release notes</a></td>
</tr>
<tr>
<td>1.36.2-gke.2064000</td>
<td>cos-129-19506-299-3</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-299-3_">cos-129-19506-299-3 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r31-version-updates">(2026-R31) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r31-version-updates">(2026-R31) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.12-gke.1270000</li>
<li>1.34.9-gke.1065000</li>
<li>1.35.6-gke.1049000</li>
<li>1.36.0-gke.3712000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r31-version-updates">(2026-R31) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1269000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1610000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1638000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1641000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.13-gke.1101000</li>
<li>1.34.9-gke.1287000</li>
<li>1.35.6-gke.1250000</li>
<li>1.36.0-gke.4681000</li>
<li>1.36.2-gke.1346000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r31-version-updates">(2026-R31) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1269000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1610000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1638000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1641000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2846000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2437000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.2137000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1269000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1610000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1638000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1641000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.2064000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.35.5-gke.1241004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3712000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r31-version-updates">(2026-R31) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2816000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2846000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2233000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2437000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1913000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.2137000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2746000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2825000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2157000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2246000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1829000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1930000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.12-gke.1270000</li>
<li>1.34.9-gke.1065000</li>
<li>1.35.6-gke.1049000</li>
<li>1.36.0-gke.3712000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2767000</a></li>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2169000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2767000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2169000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1844000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Governance workflows let you set up automated controls for data product access
management by providing a request-review mechanism.
This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/about-governance-workflows">About governance workflows</a>.</p>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Announcement</h3>
<p>Starting in September, 2026, <strong>Airflow 2.10.5 will no longer be included</strong> in
new Managed Airflow images and builds. This change will not affect existing
images and builds.</p>
<h3>Announcement</h3>
<p>Starting in September 2026, we are changing the version support policy for
Managed Airflow (Gen 2) to align it with the Managed Airflow (Gen 3) policy.
The changes will <strong>affect Airflow 2 versions that we release</strong>:</p>
<ul>
<li>In Managed Airflow (Gen 2), we will
<strong>release only new images with Airflow 2.11</strong>. New Airflow 2.10.5 images
will no longer be released.</li>
<li>In Managed Airflow (Gen 3) we will keep releasing new builds of Airflow 3
(no changes) and will release only new Airflow 2.11 builds. New
Airflow 2.10.5 builds will no longer be released.</li>
</ul>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>New SAP certification for operating system: SLES 16 for SAP</strong></p>
<p>For use with SAP HANA and SAP NetWeaver on Google Cloud, SAP has certified the
operating system SUSE Linux Enterprise Server (SLES) 16 for SAP.</p>
<p>For more information about SAP-certified operating systems, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/sap/docs/sap-hana-os-support#quick_reference_table">Certified operating systems for SAP HANA</a></li>
<li><a href="https://docs.cloud.google.com/sap/docs/netweaver-os-support#quick_reference_table">Certified operating systems for SAP NetWeaver</a></li>
</ul>
<h2 class="release-note-product-title">Service Usage</h2>
<h3>Deprecated</h3>
<p>As of July 30, 2026, support for managing Model Context Protocol (MCP) server
enablement and consumer policies using the Service Usage v2beta API will be shut
down.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/service-usage/docs/deprecations">Feature deprecations</a>.</p>
<h2 class="release-note-product-title">reCAPTCHA</h2>
<h3>Feature</h3>
<p><b>Preview</b>: <a href="https://docs.cloud.google.com/recaptcha/docs/policy-engine">Policy Engine</a>, <a href="https://docs.cloud.google.com/recaptcha/docs/install-universal-keys-web-pages">Universal keys</a>, and <a href="https://docs.cloud.google.com/recaptcha/docs/challenge-policies">challenge policies</a> are available in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a> for Google Cloud Fraud Defense.</p>
<ul>
<li>Policy Engine lets you perform frontend JavaScript integration using
AutoExecute and configure custom rules to selectively trigger CAPTCHA
challenges based on risk score, IP addresses, user agents, ASNs, or verified
bot identities.</li>
<li>A new AI-resistant
<a href="https://docs.cloud.google.com/recaptcha/docs/select-challenge-types#qr-code-challenges">QR code
challenge</a> is available.</li>
</ul>
<p>For more information about the types of challenges that are available,
see <a href="https://docs.cloud.google.com/recaptcha/docs/select-challenge-types">Challenge types</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 23, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_23_2026</id>
    <updated>2026-07-23T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_23_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Agent Registry</h2>
<h3>Feature</h3>
<p>Agent skill governance is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>Agent Registry supports standalone skill governance, helping enable secure, enterprise-level management and governance of standalone skills for AI agents. You can register skill resources, upload and validate ZIP payload packages, track version history through immutable skill revisions, and review verified skill publishers.</p>
<p>This release includes the following features:</p>
<ul>
<li><strong>Lifecycle and versioning:</strong> Register and manage standalone <code>Skill</code> resources, lifecycle states, and version snapshots (<code>SkillRevision</code>).</li>
<li><strong>Console support:</strong> A dedicated <strong>Skills</strong> tab in Google Cloud Console to register, update, download, and monitor skills and revisions.</li>
<li><strong>Access policy enforcement:</strong> Use policy bindings to authorize reasoning engine agents to load standalone skills.</li>
<li><strong>Semantic search:</strong> Query the registry to search and discover standalone skills.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/agent-registry/register-skills">Register skills</a> and <a href="https://docs.cloud.google.com/agent-registry/manage-skills">Manage skills</a>.</p>
<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>Transparent query forwarding is now available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a> for clusters compatible with PostgreSQL 17 and 18. With this
feature, the primary node in a cluster intercepts read-only queries and
selectively forwards them to read pool instances while maintaining
read-your-writes consistency.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/transparent-query-forwarding">Optimize resources and isolate read queries with transparent query forwarding</a>.</p>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1147">v1.14.7</h3>
<p>On July 23, 2026 we released an updated version of the Apigee hybrid software, v1.14.7.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version 1.14</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Runtime rollout strategy configuration</strong></p>
<p>In this release, you can configure the rollout strategy used when updating runtime (message processor) ReplicaSets by setting the <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/config-prop-ref#runtime-release-strategy"><code>runtime.release.strategy</code></a> property (with options <code>rolling</code>, <code>scale-down-first</code>, or <code>none</code>) or per-environment with <code>envs[].components.runtime.release.strategy</code> in your overrides configuration file. The property defaults to <code>rolling</code>.</p>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Change</h3>
<p>An updated version of the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/odbc-jdbc-drivers#current_odbc_driver">Simba ODBC driver for BigQuery</a>
is now available.</p>
<h2 class="release-note-product-title">Cloud Location Finder</h2>
<h3>Feature</h3>
<p>Model Context Protocol (MCP) integration is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. This built-in integration lets LLM-powered agents securely retrieve data using standard MCP tools (<code>search_cloud_locations</code> and <code>list_cloud_locations</code>). For more information, see <a href="https://docs.cloud.google.com/location-finder/docs/use-cloud-location-finder-mcp">Use the Model Context Protocol (MCP) with Cloud Location Finder</a>.</p>
<h2 class="release-note-product-title">Cloud Router</h2>
<h3>Feature</h3>
<p>Cloud Router support for named sets for BGP route policies is now <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>. For more information, see
<a href="https://docs.cloud.google.com/network-connectivity/docs/router/concepts/bgp-route-policies-overview#what-are-bgp-route-policies">BGP route policies overview</a>.</p>
<h2 class="release-note-product-title">Vertex AI Search</h2>
<h3>Feature</h3>
<p><strong>Agent Search: Decrease thresholds for configurable pricing</strong></p>
<p>You can decrease the storage size and queries per minute (QPM) subscription
thresholds for configurable pricing. Previously, you could only increase these
thresholds.</p>
<p>Decreased thresholds take effect at the start of the next billing cycle.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/enable-configurable-pricing#modify-thresholds">Modify subscription
thresholds</a>.
This feature is generally available (GA).</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 22, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_22_2026</id>
    <updated>2026-07-22T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_22_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Access Approval</h2>
<h3>Feature</h3>
<p>Privileged Access Manager is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Access Transparency</h2>
<h3>Feature</h3>
<p>Privileged Access Manager is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Support for unauthenticated Custom MCP Server data stores (Preview)</strong></p>
<p>When setting up a Custom MCP Server data store, you can
select <strong>No authentication</strong> if your Model Context Protocol (MCP) server doesn't
require authentication.</p>
<p>Creating a custom MCP Server data store is in Public Preview.
For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/custom-mcp-server/set-up-custom-mcp-server">Set up a custom MCP
server</a>.</p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for VMware</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for VMware 1.35.300-gke.87 is now available
for download. To upgrade, see <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/how-to/upgrading.md">Upgrade clusters</a>.
Google Distributed Cloud 1.35.300-gke.87 runs on Kubernetes v1.35.3-gke.400.</p>
<p>If you are using a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for use with GKE On-Prem API clients: the Google Cloud console, the
gcloud CLI, and Terraform.</p>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for VMware 1.34.700-gke.93 is now available
for download. To upgrade, see <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/how-to/upgrading.md">Upgrade clusters</a>.
Google Distributed Cloud 1.34.700-gke.93 runs on Kubernetes v1.34.7-gke.200.</p>
<p>If you use a third-party storage vendor, check the listing of our
previously-qualified <a href="https://docs.cloud.google.com/kubernetes-engine/enterprise/docs/resources/partner-storage">storage partners</a>.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for use with GKE On-Prem API clients: the Google Cloud console, the
gcloud CLI, and Terraform.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.34.700-gke.93:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where upgrading a user cluster with Anthos Network Gateway (ANG) enabled to an Advanced Cluster would stall or fail. Previously, the upgrade process attempted to modify immutable <code>spec.selector</code> fields on existing ANG resources. The upgrade operator now preserves existing label selectors during reconciliation so that V1 to V2 cluster migrations complete successfully.
</li>
</ul>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.35.300-gke.87:</p>
<ul>
<li>Fixed an issue where upgrading a user cluster with Anthos Network Gateway (ANG) enabled to an Advanced Cluster would stall or fail. Previously, the upgrade process attempted to modify immutable <code>spec.selector</code> fields on existing ANG resources. The upgrade operator now preserves existing label selectors during reconciliation so that V1 to V2 cluster migrations complete successfully.
</li>
</ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.34.700-gke.93 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.34.700-gke.93 runs on Kubernetes v1.34.7-gke.200.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the listing of our
previously-qualified <a href="https://docs.cloud.google.com/kubernetes-engine/enterprise/docs/resources/partner-storage">storage partners</a>.</p>
<h3>Feature</h3>
<p>The following change was added in 1.34.700-gke.93:</p>
<ul>
<li>Removed the deprecated <code>csi-snapshot-validation-webhook</code> component. Upstream Kubernetes validation is now handled natively via Common Expression Language (CEL) rules within the deployed Custom Resource Definitions (CRDs). For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/persistent-volumes/volume-snapshots">Volume snapshots</a>.
</li>
</ul>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.34.700-gke.93:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
</ul>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Feature</h3>
<p><strong>Wiz</strong>: Version 14.0</p>
<ul>
<li><p>Added the following action:</p>
<ul>
<li><strong>Get Blue Agent Analysis</strong></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>SentinelOne Singularity Operations Center</strong>: Version 1.0</p>
<ul>
<li>Added <strong>SentinelOne Singularity Operations Center</strong> integration.</li>
</ul>
<h3>Feature</h3>
<p><strong>Proofpoint Email Protection</strong>: Version 10.0</p>
<ul>
<li><p>Added the following action:</p>
<ul>
<li><strong>Download Quarantined Email</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Azure Monitor</strong>: Version 5.0</p>
<ul>
<li>Updated integration documentation links in the integration configuration.</li>
</ul>
<h3>Change</h3>
<p><strong>QRadar</strong>: Version 69.0</p>
<ul>
<li><p>Updated timestamp filtering to use <code>last_persisted_time</code> for tracking
modifications in the following connector:</p>
<ul>
<li><strong>Qradar Offenses Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 60.0</p>
<ul>
<li><p>Added support for the <code>Created Before</code> date filter and <code>Custom JQL</code> query
parameter in the following action:</p>
<ul>
<li><strong>List Issues</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 90.0</p>
<ul>
<li><p>Updated handling of Wiz Defend detections and ontology mapping in the
following connector:</p>
<ul>
<li><strong>Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Looker</h2>
<h3>Security</h3>
<p>A Cross-Site Scripting (XSS) vulnerability was discovered in Looker. An attacker could craft a malicious URL that, when opened by a Looker administrator, would allow the attacker to execute arbitrary scripts on their behalf and potentially compromise the administrator account.</p>
<p>Both Looker-hosted and self-hosted instances were found to be vulnerable.</p>
<p>This issue has already been mitigated for Looker-hosted instances.</p>
<p><strong>What should I do?</strong></p>
<p>For Looker-hosted instances, no action is required.</p>
<p>For self-hosted Looker instances, update your Looker instances as soon as possible. This vulnerability has been patched in all supported versions of Looker for self-hosted instances. The following versions have all been updated to fix this vulnerability:</p>
<ul>
<li>Looker 26.8.7 and all later versions</li>
<li>Looker 26.6.28+</li>
<li>Looker 26.4.36+</li>
<li>Looker 26.2.47+</li>
<li>Looker 26.0.66+</li>
<li>Looker 25.18.68+</li>
<li>Looker 25.12.65+</li>
<li>Looker 25.6.103+</li>
</ul>
<p>For more information, see <a href="http://cve.org/CVERecord?id=CVE-2026-15810">CVE-2026-15810</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 21, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_21_2026</id>
    <updated>2026-07-21T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_21_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Anthos Attached Clusters</h2>
<h3>Announcement</h3>
<p>You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:</p>
<ul>
<li><a href="https://cloud.google.com/kubernetes-engine/multi-cloud/docs/attached/aks/reference/supported-versions#1350-gke1">1.35.0-gke.1</a></li>
<li><a href="https://cloud.google.com/kubernetes-engine/multi-cloud/docs/attached/aks/reference/supported-versions#1340-gke2">1.34.0-gke.2</a></li>
<li><a href="https://cloud.google.com/kubernetes-engine/multi-cloud/docs/attached/aks/reference/supported-versions#1330-gke3">1.33.0-gke.3</a></li>
</ul>
<h2 class="release-note-product-title">Anthos clusters on AWS</h2>
<h3>Announcement</h3>
<p>You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:</p>
<ul>
<li><a href="https://cloud.google.com/kubernetes-engine/multi-cloud/docs/aws/reference/supported-versions#1353-gke300">1.35.3-gke.300</a></li>
<li><a href="https://cloud.google.com/kubernetes-engine/multi-cloud/docs/aws/reference/supported-versions#1346-gke200">1.34.6-gke.200</a></li>
<li><a href="https://cloud.google.com/kubernetes-engine/multi-cloud/docs/aws/reference/supported-versions#13310-gke200">1.33.10-gke.200</a></li>
</ul>
<h2 class="release-note-product-title">Anthos clusters on Azure</h2>
<h3>Announcement</h3>
<p>You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:</p>
<ul>
<li><a href="https://cloud.google.com/kubernetes-engine/multi-cloud/docs/azure/reference/supported-versions#1353-gke300">1.35.3-gke.300</a></li>
<li><a href="https://cloud.google.com/kubernetes-engine/multi-cloud/docs/azure/reference/supported-versions#1346-gke200">1.34.6-gke.200</a></li>
<li><a href="https://cloud.google.com/kubernetes-engine/multi-cloud/docs/azure/reference/supported-versions#13310-gke200">1.33.10-gke.200</a></li>
</ul>
<h2 class="release-note-product-title">Binary Authorization</h2>
<h3>Feature</h3>
<p>To provide long-term security and address threats from future quantum computers,
Binary Authorization supports keys that use post-quantum cryptography (PQC)
algorithms. These algorithms, such as <code>ML-DSA-65</code> (Dilithium3), are standardized
to be resistant to attacks from both classical and quantum computers. To learn how
to generate a PQC key pair and create an attestor, see
<a href="https://docs.cloud.google.com/binary-authorization/docs/creating-attestors-cli#pqc-keys">Create post-quantum cryptography (PQC) keys</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility#typegoogleapiscomenvoyextensionsfiltershttpluav3lua">Envoy Lua Filter</a>
is now available as a preview feature in the stable release channel.</p>
<h2 class="release-note-product-title">Cloud Tasks</h2>
<h3>Feature</h3>
<p>Cloud Tasks support for the following is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>:</p>
<ul>
<li><a href="https://docs.cloud.google.com/tasks/docs/configure-retry-task">Set retry parameters when creating a task</a>
and override the queue-level retry configuration for the task.</li>
<li><a href="https://docs.cloud.google.com/tasks/docs/create-tasks#create-batch-tasks">Create a batch of tasks</a>
and add the batch to an existing queue.</li>
<li><a href="https://docs.cloud.google.com/tasks/docs/manage-queues-and-tasks#delete-batch-tasks">Delete a batch of tasks</a>
from a queue.</li>
</ul>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: You can configure a regional managed instance group
(MIG) to allow a VM repair in an alternate zone when the MIG can't repair the VM
in its original zone. Repairing a VM in an alternate zone can help to improve
your application's resiliency and resource obtainability. For more information,
see <a href="https://docs.cloud.google.com/compute/docs/instance-groups/repair-vm-in-alternate-zone">Repair a VM in an alternate zone</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_intellij">Bug fixes in IntelliJ</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Gemini 3.6 Flash available in the Global region</strong></p>
<p>Gemini 3.6 Flash is available in the <code>global</code> region. To make Gemini 3.6 Flash
available to users in the Gemini Enterprise app, administrators must turn on
the <strong>Gemini 3.6 Flash</strong> feature toggle.</p>
<p>Gemini 3.6 Flash is also available in Agent Designer workflow agents. Updates
take up to a day to appear in workflow agents.</p>
<p>For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage features on the web
app</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/locations">Data residency for Gemini Enterprise Standard and Plus Editions and Gemini
Notebook Enterprise</a></li>
</ul>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Gemini 3.5 Flash removal in the Global region</strong></p>
<p>Gemini 3.5 Flash will be removed as a model from the <code>global</code> region in the
Gemini Enterprise app on August 4, 2026.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage features on the web
app</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Gemini 3.6 Flash and 3.5 Flash-Lite are generally available (GA)</strong></p>
<p><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-6-flash">Gemini 3.6 Flash</a>
and <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-5-flash-lite">Gemini 3.5
Flash-Lite</a> are
now generally available (GA) and available for production use. These models are
designed to improve upon their predecessors' capabilities, including improved
token usage and improved document understanding. See the linked model
information pages for more information.</p>
<p>This release includes some potentially breaking changes from previous Flash and
Flash-Lite models:</p>
<ul>
<li><strong>Sampling parameters</strong>: Custom values for temperature, top-K, and top-P are
not supported and will be ignored if set.</li>
<li><strong>Penalty parameters</strong>: Custom values for frequency and presence penalty
parameters are not supported. Setting these will result in an API error.</li>
<li><strong>API turn structure</strong>: API requests where the last input turn has a role of
<code>Model</code> are no longer supported and will return an error:
<ul>
<li><strong>Interactions API</strong>: Requests where the last object in the input array
has <code>"type": "model_output"</code> will fail.</li>
<li><strong>GenerateContent API</strong>: Requests where the last object in the contents
array has <code>"role": "model"</code> will fail.</li>
</ul></li>
</ul>
<h3>Deprecated</h3>
<p><strong>Open model endpoint deprecations</strong></p>
<p>The following open model endpoints are deprecated and will be retired on
October 21, 2026. For more information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/deprecations/open-models">Open model
deprecations</a>.</p>
<ul>
<li><code>deepseek-ocr-maas</code></li>
<li><code>deepseek-r1-0528-maas</code></li>
<li><code>deepseek-v3.2-maas</code></li>
<li><code>deepseek-v3.1-maas</code></li>
<li><code>glm-5-maas</code></li>
<li><code>glm-4.7-maas</code></li>
<li><code>gpt-oss-20b-maas</code></li>
<li><code>kimi-k2-thinking-maas</code></li>
<li><code>llama-3.3-70b-instruct-maas</code></li>
<li><code>minimax-m2-maas</code></li>
<li><code>multilingual-e5-large-instruct-maas</code></li>
<li><code>multilingual-e5-small-maas</code></li>
<li><code>qwen3-235b-a22b-instruct-2507-maas</code></li>
<li><code>qwen3-coder-480b-a35b-instruct-maas</code></li>
<li><code>qwen3-next-80b-a3b-instruct-maas</code></li>
<li><code>qwen3-next-80b-a3b-thinking-maas</code></li>
</ul>
<h2 class="release-note-product-title">Looker</h2>
<h3>Deprecated</h3>
<p>As of July 13, 2026, Looker reports have been deprecated. If you had previously enabled the preview for Looker reports, be aware of the following:</p>
<ul>
<li>You will no longer have the option to create new reports.</li>
<li>You will lose the ability to view or edit reports that were created during the preview period.</li>
</ul>
<p>Access to the rest of your Looker content in your instance will remain unaffected and you will continue to have access to Looker as a data source from Data Studio and Data Studio Pro.</p>
<p>You can create ad hoc Explores using Looker's self-service Explores feature, which lets you upload CSV, XLS, and XLSX files to Looker and then query and visualize the data in a Looker Explore without needing to configure a LookML model or set up Git version control.</p>
<h2 class="release-note-product-title">Virtual Private Cloud</h2>
<h3>Feature</h3>
<p>For Google Cloud resources that are registered as
<a href="https://docs.cloud.google.com/app-hub/docs/overview">App Hub</a>
workloads or services, VPC Flow Logs records contain
application-specific labels. For more information, see
<a href="https://docs.cloud.google.com/vpc/docs/about-flow-logs-records#app-hub">App Hub labels</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 20, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_20_2026</id>
    <updated>2026-07-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_20_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Batch</h2>
<h3>Breaking</h3>
<p>Starting on the following dates, you can no longer create a job that locates
its Compute Engine resources outside of the job's location.</p>
<ul>
<li>For projects that have successfully submitted before July 31, 2026 at least
one job that uses the <code>allowedLocations[]</code> field with any region or zones
outside of the job's location, changes are starting on <em>June 30, 2027</em>.</li>
<li>For all other projects, changes are starting on <em>July 31, 2026</em>.</li>
</ul>
<p>If none of your jobs specify the <code>allowedLocations[]</code> field, then no action is
required. Otherwise, ensure that any region or zones specified in the
<code>allowedLocations[]</code> field are in the same region as the job's location
before these dates. For more information, see
<a href="https://docs.cloud.google.com/batch/docs/locations">Batch locations</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Issue</h3>
<p><a href="https://docs.cloud.google.com/lakehouse/docs/introduction"><em>Lakehouse for Apache Iceberg</em></a>: Data Products with
special characters, such as "/" or "-", are not supported and will not be
available in BigQuery even if shared from SAP BDC to
BigQuery. If you share a Data Product with special characters,
this could cause the refresh to stop and require
re-enrollment. Known SAP systems producing these Data Products include
SAP Business Warehouse (BW) sources and SAP SuccessFactors.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/lakehouse/docs/introduction"><em>Lakehouse for Apache Iceberg</em></a>: Cross-cloud
Lakehouse now supports integration with SAP Business Data Cloud
(BDC) in Preview.</p>
<p>This update includes the following features:</p>
<ul>
<li><strong>Federation from SAP BDC:</strong> Create Delta Sharing catalogs in
Lakehouse to automatically synchronize shares, schemas, and
tables from SAP BDC.</li>
<li><strong>Querying SAP data:</strong> Query synchronized SAP BDC tables directly from
BigQuery without data migration.</li>
<li><strong>Publishing to SAP BDC:</strong> Publish Apache Iceberg REST catalog (IRC) tables
or Knowledge Catalog Data Products from
Lakehouse directly to SAP BDC, allowing SAP users and
applications to consume Google Cloud data directly as remote tables
in SAP Datasphere without migrating data.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/lakehouse/docs/set-up-cross-cloud-lakehouse-sap-bdc">Set up cross-cloud Lakehouse for SAP
BDC</a>, <a href="https://docs.cloud.google.com/lakehouse/docs/query-sap-data">Query SAP BDC
data</a>, and <a href="https://docs.cloud.google.com/lakehouse/docs/publish-data-to-sap-bdc">Publish Data Products to SAP BDC</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>For regional external passthrough Network Load Balancers, you can reserve specific or automatically
allocated bring your own IP (BYOIP) IPv6 addresses before creating a load
balancer, so that the IPv6 address persists independently of the load balancer's lifecycle. You can also promote an ephemeral BYOIP IPv6 address that is in use
by a load balancer to a reserved static IP address.</p>
<p>For more information, see the following documentation:</p>
<ul>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/network/setting-up-network-backend-service#byoip-ipv6">Set up a regional external passthrough Network Load Balancer with a backend service</a>.</li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/network/setting-up-networklb-multiple-protocols#byoip-ipv6">Set up a regional external passthrough Network Load Balancer for multiple IP protocols</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/network/setting-up-network-zonal-neg#byoip-ipv6">Set up a regional external passthrough Network Load Balancer with zonal NEGs</a></li>
</ul>
<p>This feature is in <strong>Preview</strong>.</p>
<h2 class="release-note-product-title">Cloud NGFW</h2>
<h3>Feature</h3>
<p>You can now use the WildFire service to protect your network against unknown,
novel malware, and file-based threats. WildFire integrates advanced malware sandboxing
and real-time machine learning (ML) to perform deep inspection of
network-routed file transfers and block zero-day malware before it reaches your
workloads. WildFire is available in the Cloud Firewall Enterprise tier.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/firewall/docs/about-wildfire">WildFire overview</a> and
<a href="https://docs.cloud.google.com/firewall/docs/configure-wildfire">Configure WildFire in your network</a>. This
feature is available in <strong>Preview</strong>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>Cloud SQL for MySQL now supports authentication via Secret Manager when executing SQL statements using the Data API (<code>executeSql</code>). You can store your database password in a regional secret in Secret Manager and pass the secret version resource name in your API request.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/mysql/executesql-instance#configure-db-user">Execute SQL statements on a Cloud SQL instance</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>Cloud SQL for PostgreSQL now supports authentication via Secret Manager when executing SQL statements using the Data API (<code>executeSql</code>). You can store your database password in a regional secret in Secret Manager and pass the secret version resource name in your API request.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/postgres/executesql-instance#configure-db-user">Execute SQL statements on a Cloud SQL instance</a>.</p>
<h2 class="release-note-product-title">Cloud Storage</h2>
<h3>Feature</h3>
<p>Object Lifecycle Management conditions for
<a href="https://docs.cloud.google.com/storage/docs/lifecycle#size-above-below-bytes"><code>sizeAboveBytes</code> and <code>sizeBelowBytes</code></a>
let you define a minimum and maximum size threshold for lifecycle actions.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Deprecated</h3>
<p>Encrypting disks, snapshots, images, and machine images with customer-supplied
encryption keys (CSEKs) is deprecated and will be disabled on July 20, 2027.</p>
<p>For more information and alternatives to CSEKs for your Compute Engine resources,
see <a href="https://docs.cloud.google.com/compute/docs/deprecations/csek-deprecation-in-compute-engine">Deprecation of customer-supplied encryption keys (CSEK) in Compute Engine</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-117-18613-675-20_">cos-117-18613-675-20 <a id='"cos-arm64-117-18613-675-20"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/045443ea52af5948575258b1df0f85d66a77fd7a
">COS-6.6.143</a></td>
<td>v24.0.9</td>
<td>v1.7.34</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.675.20/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Fixed a bug in the XFS file system where direct I/O writes could use
outdated block mappings during Copy-on-Write operations.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/curl to 8.21.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-58013,CVE-2026-58014,CVE-2026-58015,CVE-2026-58016 in glib.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-13462 in dev-lang/python</p>
<h3>Security</h3>
<p>Fixed CVE-2026-3644 in dev-lang/python</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4224 in dev-lang/python</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43010 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46331 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53163 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53167 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 in net-misc/wget.</p>
<h3>Security</h3>
<p>Updated containerd to v1.7.34. This resolves CVE-2026-46680
and CVE-2026-53488.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-528-21_">cos-121-18867-528-21 <a id='"cos-arm64-121-18867-528-21"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/c4fcdba2d32933938b008b72e53252ddc6286367
">COS-6.6.143</a></td>
<td>v27.5.1</td>
<td>v2.0.10</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.528.21/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Updated containerd to v2.0.10. This resolves CVE-2026-46680.</p>
<h3>Fixed</h3>
<p>Fixed a bug in the XFS file system where direct I/O writes could use
outdated block mappings during Copy-on-Write operations.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/curl to 8.21.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-58013,CVE-2026-58014,CVE-2026-58015,CVE-2026-58016 in glib.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23278 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43010 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46331 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53163 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53167 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 in net-misc/wget.</p>
<h3>Change</h3>
<h3 id="cos-129-19506-299-36_">cos-129-19506-299-36 <a id='"cos-arm64-129-19506-299-36"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/2d3868d9c2a54dbfe692ca8ea26defa8889e6433
">COS-6.12.94</a></td>
<td>v27.5.1</td>
<td>v2.2.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.299.36/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Fixed a bug in the XFS file system where direct I/O writes could use
outdated block mappings during Copy-on-Write operations.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/curl to 8.21.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-58013,CVE-2026-58014,CVE-2026-58015,CVE-2026-58016 in glib.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43216 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 in net-misc/wget.</p>
<h3>Security</h3>
<p>Updated containerd to v2.2.5. This resolves
CVE-2026-46680,CVE-2026-50195,CVE-2026-53492,CVE-2026-53488.</p>
<h3>Change</h3>
<h3 id="cos-125-19216-532-25_">cos-125-19216-532-25 <a id='"cos-arm64-125-19216-532-25"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/2049bd2bd5fb77d15efcbc7409707051cd3205c8
">COS-6.12.94</a></td>
<td>v27.5.1</td>
<td>v2.1.9</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.532.25/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded net-misc/curl to 8.21.0.</p>
<h3>Security</h3>
<p>Fixed
CVE-2026-58013,CVE-2026-58014,CVE-2026-58015,CVE-2026-58016 in glib.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43010 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43216 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 in net-misc/wget.</p>
<h3>Security</h3>
<p>Updated containerd to v2.1.9. This resolves CVE-2026-46680,CVE-2026-50195,
CVE-2026-53492,CVE-2026-53488.</p>
<h2 class="release-note-product-title">Firestore</h2>
<h3>Feature</h3>
<p>You can now view, manage, and deploy Firestore Security Rules directly in the
Google Cloud console for Firestore in Native mode (Standard and Enterprise
editions). You can create new rulesets and clone or restore rulesets from the
timeline.</p>
<p>To learn more, see
<a href="https://docs.cloud.google.com/firestore/native/docs/using-console#manage-firestore-security-rules">Manage Firestore Security Rules</a>
or
<a href="https://docs.cloud.google.com/firestore/native/docs/security/get-started#use-the-cloud-console">Use the Google Cloud console</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Security</h3>
<p><strong>Security update for Server-Side Request Forgery (SSRF) in Agent Studio</strong></p>
<p>This release fixes a Server-Side Request Forgery (SSRF) vulnerability in the
auto-generated <code>/api-proxy</code> backend endpoint for web applications created
before July 1, 2026, using Agent Studio.</p>
<p>If you downloaded, generated, or deployed web application code from Agent Studio
before July 1, 2026, regenerate the app from Agent Studio and deploy the new
version. For more information,
see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/agent-studio/deploy-vais-prompt">Quickstart: Deploy your Agent Studio prompt as a web
application</a></p>
<p>The updated backend code includes strict domain allowlist validation, ensuring
that destination hostnames for the <code>/api-proxy</code> endpoint end with allowed Google
Cloud domains, such as <code>*-aiplatform.clients6.google.com</code></p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.35.300-gke.87 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.35.300-gke.87 runs on Kubernetes v1.35.3-gke.400.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Feature</h3>
<p>The following change was added in 1.35.300-gke.87:</p>
<ul>
<li>Removed the deprecated <code>csi-snapshot-validation-webhook</code> component. Upstream Kubernetes validation is now handled natively via Common Expression Language (CEL) rules within the deployed Custom Resource Definitions (CRDs). For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/persistent-volumes/volume-snapshots">Volume snapshots</a>.
</li>
</ul>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.35.300-gke.87:</p>
<ul>
<li>Link to <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a> for the list of security vulnerabilities addressed in this release.</li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Deprecated</h3>
<p>To improve security, Ubuntu node images in GKE version 1.37 and later don't
pre-install the <code>vulkan-tools</code> package. If you run Vulkan diagnostic tools
(such as <code>vulkaninfo</code>) directly on GKE Ubuntu hosts, then you must manually
install the <code>vulkan-tools</code> package. This change doesn't affect containerized
GPU/Vulkan workloads.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Deprecated</h3>
<p><strong>[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs</strong></p>
<p>Google Security Operations is <a href="https://docs.cloud.google.com/chronicle/docs/deprecations">deprecating</a> its legacy SIEM APIs—<a href="https://docs.cloud.google.com/chronicle/docs/reference/google-secops-api-libraries-overview#backstory_api">Backstory API</a> (including <a href="https://docs.cloud.google.com/chronicle/docs/reference/customer-management-api">Customer Management API</a>) and <a href="https://docs.cloud.google.com/chronicle/docs/reference/google-secops-api-libraries-overview#ingestion_api">Ingestion API</a>—in favor of the modern <a href="https://docs.cloud.google.com/chronicle/docs/reference/google-secops-api-libraries-overview#chronicle_api">Chronicle API</a>.</p>
<p><strong>Key dates</strong></p>
<ul>
<li><strong>October 26, 2026:</strong> New Google SecOps instances provisioned from this date will no longer support legacy API calls.</li>
<li><strong>July 20, 2027:</strong> All requests to legacy endpoints fail from this date because legacy APIs for all existing instances will be completely turned down. </li>
</ul>
<p>This change applies only to custom scripts, integrations, SOAR connectors, or ingestion feeds calling legacy Backstory API or Ingestion API endpoints. Any changes impacting the Google SecOps UI are already addressed and don't call for your action.</p>
<p><strong>Next steps</strong></p>
<ul>
<li><p>Audit API usage to identify any affected components that currently call legacy Backstory API or Ingestion API endpoints, and replace them with Chronicle API endpoints.</p></li>
<li><p>Validate and test that your updated components work properly.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/administration/migrate-from-legacy-api-to-chronicle-api">Migrate from legacy API to Chronicle API</a>.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Deprecated</h3>
<p><strong>[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs</strong></p>
<p>Google Security Operations is <a href="https://docs.cloud.google.com/chronicle/docs/deprecations">deprecating</a> its legacy SIEM APIs—<a href="https://docs.cloud.google.com/chronicle/docs/reference/google-secops-api-libraries-overview#backstory_api">Backstory API</a> (including <a href="https://docs.cloud.google.com/chronicle/docs/reference/customer-management-api">Customer Management API</a>) and <a href="https://docs.cloud.google.com/chronicle/docs/reference/google-secops-api-libraries-overview#ingestion_api">Ingestion API</a>—in favor of the modern <a href="https://docs.cloud.google.com/chronicle/docs/reference/google-secops-api-libraries-overview#chronicle_api">Chronicle API</a>.</p>
<p><strong>Key dates</strong></p>
<ul>
<li><strong>October 26, 2026:</strong> New Google SecOps instances provisioned from this date will no longer support legacy API calls.</li>
<li><strong>July 20, 2027:</strong> All requests to legacy endpoints fail from this date because legacy APIs for all existing instances will be completely turned down. </li>
</ul>
<p>This change applies only to custom scripts, integrations, SOAR connectors, or ingestion feeds calling legacy Backstory API or Ingestion API endpoints. Any changes impacting the Google SecOps UI are already addressed and don't call for your action.</p>
<p><strong>Next steps</strong></p>
<ul>
<li><p>Audit API usage to identify any affected components that currently call legacy Backstory API or Ingestion API endpoints, and replace them with Chronicle API endpoints.</p></li>
<li><p>Validate and test that your updated components work properly.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/administration/migrate-from-legacy-api-to-chronicle-api">Migrate from legacy API to Chronicle API</a>.</p>
<h2 class="release-note-product-title">Virtual Private Cloud</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: You can reserve static external IPv6 addresses from
bring your own IP addresses (BYOIP) sub-prefixes that are in
<code>EXTERNAL_IPV6_FORWARDING_RULE_CREATION</code> mode.</p>
<p>You can assign these addresses to forwarding rules for external passthrough
Network Load Balancers and external protocol forwarding. You can also promote
ephemeral IPv6 BYOIP addresses that are used by external forwarding rules
to reserved static IP addresses.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/vpc/docs/create-ipv6-sub-prefixes#create-subprefix-use">Create external forwarding rules</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 19, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_19_2026</id>
    <updated>2026-07-19T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_19_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.94 is being rolled out to the first phase of regions as listed 
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 18, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_18_2026</id>
    <updated>2026-07-18T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_18_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_12_2026">Release 6.3.93</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 17, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_17_2026</id>
    <updated>2026-07-17T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_17_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Audit Manager</h2>
<h3>Feature</h3>
<p>Audit Manager includes the following features in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>:</p>
<ul>
<li>A new <a href="https://docs.cloud.google.com/audit-manager/docs/view-audit#compliance-score">UI and report experience</a></li>
<li>Ability to <a href="https://docs.cloud.google.com/audit-manager/docs/run-audit">schedule audits</a></li>
<li>Ability to run audits at an organization level</li>
</ul>
<h2 class="release-note-product-title">Batch</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/batch/docs/create-run-job-instance-flexibility">Instance flexibility</a> is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.
Instance flexibility lets you allow a job to run on multiple machine types that
you specify and can optionally rank. Use instance flexibility to improve
<em>obtainability</em>—the probability that resources are available to run your
job. For example, by allowing multiple machine types, you can reduce the
probability of resource availability errors and try to obtain Spot VMs
that are less likely to be preempted.</p>
<p>To get started, see <a href="https://docs.cloud.google.com/batch/docs/improve-obtainability-overview">Improve resource obtainability for jobs</a>.</p>
<h2 class="release-note-product-title">Cloud Hub</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/hub/docs/security">Security &amp; compliance</a> page in Cloud Hub has
launched to <a href="https://cloud.google.com/products#product-launch-stages">General Availability</a>.</p>
<h2 class="release-note-product-title">Document AI</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/document-ai/docs/ce-with-genai">Custom extractor</a> model
<code>pretrained-foundation-model-v3.5-2026-05-26</code> powered by Gemini 3.5
Flash LLM is available in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<p>This processor version has ML processing capabilities in the US and EU.</p>
<p>For more information about available models, see the <a href="https://docs.cloud.google.com/document-ai/docs/custom-based-extraction">custom
extractor</a> page.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Breaking</h3>
<p><strong>Gemini 3.1 Flash Image Preview and 3 Pro Image Preview are retired</strong></p>
<p>The Nano Banana preview models <code>gemini-3.1-flash-image-preview</code> and
<code>gemini-3-pro-image-preview</code> have been retired and are no longer accessible.
Update your code to use either <code>gemini-3.1-flash-image</code> or
<code>gemini-3-flash-image</code> instead.</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Data lineage control at the organization, folder, or project level is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a> for BigQuery, Managed Service for Apache Spark, and Managed Service for Apache Airflow.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/control-lineage-ingestion">About data lineage ingestion control</a>
and <a href="https://docs.cloud.google.com/dataplex/docs/configure-lineage-ingestion">Configure data lineage ingestion for a service</a>.</p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Feature</h3>
<p>Starting in Looker 26.8, Looker supports Java OpenJDK version 21. Looker-hosted instances have been upgraded to OpenJDK 21. Customer-hosted instances should <a href="https://docs.cloud.google.com/looker/docs/upgrading-to-openjdk-21-customer-hosted-instance">upgrade to OpenJDK 21</a>.</p>
<aside class="note">
If you run Looker directly using the <code>java -jar</code> command (instead of using the startup script), you must include these three specific settings:

<pre class="prettyprint lang-none">
--add-opens=java.base/sun.nio.ch=ALL-UNNAMED --add-opens=java.base/java.io=ALL-UNNAMED --add-opens=java.base/java.nio=ALL-UNNAMED
</pre>
</aside>
<p>Looker recommends that you transition to new Java updates as they are released. Other versions of Java, Oracle JDK, and OpenJDK are not supported at this time.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Announcement</h3>
<p>Key insights from Security Command Center are available on the <a href="https://docs.cloud.google.com/hub/docs/security">Security &amp; compliance</a>
page in <a href="https://docs.cloud.google.com/hub/docs/overview">Cloud Hub</a>. This feature is available in
<a href="https://cloud.google.com/products#product-launch-stages">General Availability</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 16, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_16_2026</id>
    <updated>2026-07-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_16_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On July 16th, 2026, we began maintenance updates of Apigee instances <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">configured for maintenance windows</a>.</p>
<p>If you set a preferred window for maintenance for your instance, and your instance version is
below <strong>1-17-0-apigee-10</strong>, your instance will be updated to <strong>1-17-0-apigee-10</strong> within the
next seven to 21 days. A notification containing the expected date of upgrade will be sent within the next two business days.</p>
<aside class="note">Note: Instances that meet either of the following two criteria will <b>not</b> be updated:
<ul>
<li>Your instance has a DNS misconfiguration, as described in <a href="https://docs.cloud.google.com/apigee/docs/release/known-issues">Known Issue 445936920</a>.</li>
<li>Your instance uses an Apigee Java Library that has been removed, as described in <a href="https://docs.cloud.google.com/apigee/docs/release/release-notes#October_16_2025">Apigee release notes dated October 16, 2025</a>.</li>
</ul></aside>
<p>For more information on participating in scheduled maintenance windows, see <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance">Maintenance overview</a> and <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows">Manage Apigee instance maintenance windows</a>.</p>
<h2 class="release-note-product-title">Cloud Key Management Service</h2>
<h3>Feature</h3>
<p>Cloud KMS supports the following post-quantum computing (PQC) signing algorithms
in General Availability:</p>
<ul>
<li><code>PQ_SIGN_HASH_SLH_DSA_SHA2_128S_SHA256</code></li>
<li><code>PQ_SIGN_ML_DSA_44</code></li>
<li><code>PQ_SIGN_ML_DSA_44_EXTERNAL_MU</code></li>
<li><code>PQ_SIGN_ML_DSA_65</code></li>
<li><code>PQ_SIGN_ML_DSA_65_EXTERNAL_MU</code></li>
<li><code>PQ_SIGN_ML_DSA_87</code></li>
<li><code>PQ_SIGN_ML_DSA_87_EXTERNAL_MU</code></li>
<li><code>PQ_SIGN_SLH_DSA_SHA2_128S</code></li>
</ul>
<p>For more information about supported algorithms, see <a href="https://docs.cloud.google.com/kms/docs/algorithms#pqc_signing_algorithms">PQC signing
algorithms</a>. For more information
about PQC signing, see <a href="https://docs.cloud.google.com/kms/docs/digital-signatures#pqc">Post-quantum cryptography (PQC) digital
signature</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Change</h3>
<p>Cloud SQL for MySQL 8.4.8 is upgraded to MySQL 8.4.10. For more information, see
the <a href="https://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4-10.html">MySQL 8.4.10 Release Notes</a>
and <a href="https://docs.cloud.google.com/sql/docs/mysql/db-versions">Cloud SQL database versions</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p>Hyperdisk Balanced High Availability volumes on C4 instances have increased performance
limits for several machine types. For example, an instance that uses the
<code>c4-standard-16</code> machine type can reach up to 1,600 MiB/s of throughput,
up from 600 MiB/s.</p>
<p>For detailed performance limits, see
<a href="https://docs.cloud.google.com/compute/docs/disks/hd-types/hyperdisk-balanced-ha#perf-limits">Hyperdisk Balanced High Availability performance limits when attached to an instance</a>.</p>
<h3>Change</h3>
<p><strong>Changed</strong>: The following operations on the boot disk of a Compute Engine instance
that has a service account attached no longer require the <code>iam.serviceAccounts.actAs</code>
permission.  In the following list, the boot disk of such an instance is
referred to as the <em>source disk</em>.</p>
<ul>
<li>Creating a standard or archive snapshot of the source disk.</li>
<li>Cloning the source disk.</li>
<li>Creating a machine image of the instance.</li>
<li>Creating a custom image of the source disk.</li>
<li>Starting asynchronous replication of the source disk to another region.</li>
<li>Creating a new disk when you create an instance, if the new disk is created
from an instant snapshot of the source disk.</li>
</ul>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Bring Your Own Identity (BYOID) for mobile apps (GA)</strong></p>
<p>The Gemini Enterprise mobile app is generally available (GA) for
organizations using third-party identity providers. You can connect the
mobile app to supported third-party identity providers without being on an
allowlist.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/configure-mobile-app">Configure the mobile app</a>.</p>
<h3>Change</h3>
<p><strong>Gemini Notebook Enterprise: NotebookLM Enterprise renamed to Gemini Notebook Enterprise</strong></p>
<p>NotebookLM Enterprise is renamed to Gemini Notebook Enterprise.
Despite the rebrand, the product functionality remains the same, and the APIs
still use the same endpoints. See <a href="https://docs.cloud.google.com/gemini/enterprise/notebooklm-enterprise/docs/api-notebooks">Create and manage notebooks
(API)</a>.</p>
<p>The Gemini Enterprise web app and the admin console display
the name Gemini Notebook Enterprise.
However, the subscription page still displays the name NotebookLM Enterprise.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r30-version-updates">(2026-R30) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.13-gke.1011000</li>
<li>1.34.9-gke.1131000</li>
<li>1.35.6-gke.1127000</li>
<li>1.36.0-gke.4447000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.12-gke.1165000</li>
<li>1.34.8-gke.1278000</li>
<li>1.35.5-gke.1241004</li>
<li>1.36.0-gke.3070003 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3302004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.12-gke.1059000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1126000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2767000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2825000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2169000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2246000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1844000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1930000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2710000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2816000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2116000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2233000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1740000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1913000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.12-gke.1165000</li>
<li>1.34.8-gke.1278000</li>
<li>1.35.5-gke.1241004</li>
<li>1.36.0-gke.3070003 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3302004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2746000</a></li>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2157000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2746000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2157000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1829000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2825000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2246000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1930000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.12-gke.1059000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1000000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1163012 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3070003 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3302004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r30-security-updates">(2026-R30) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.35.6-gke.1258000</td>
<td>cos-125-19216-395-138</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-395-138_">cos-125-19216-395-138 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<p>Starting on June 30, 2026, the <a href="https://docs.cloud.google.com/filestore/docs/reference/rest">Filestore API</a>
(<code>file.googleapis.com</code>) is enabled by default when you enable the Kubernetes
Engine API (<code>container.googleapis.com</code>) in a project. The Filestore API is
required for PersistentVolumes that use the <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/filestore-for-gke"><code>ReadWriteMany</code> access mode in
GKE</a>.</p>
<h3>Feature</h3>
<p>In GKE version 1.36.0-gke.3204000 and later, when you manually or automatically
create a GKE node pool that consumes capacity reservations, you can stop GKE
from falling back to on-demand capacity if reserved capacity isn't available. To
consume any matching reservation without fallback, specify the
<code>any-reservation-then-fail</code> reservation affinity in your node pool creation
request, Pod specification, or ComputeClass specification. In ComputeClasses,
this reservation affinity lets GKE move on to the next priority rule instead of
creating on-demand compute resources. For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/consuming-reservations">Consuming
reserved zonal
resources</a>.</p>
<h3>Feature</h3>
<p>GKE version 1.33 now supports the N4D machine series for node pool auto-creation
and Autopilot clusters in the following patch versions and later:</p>
<ul>
<li><strong>Node pool auto-creation</strong>: 1.33.12-gke.1208000 and later</li>
<li><strong>Autopilot</strong>: 1.33.13-gke.1079000 and later</li>
</ul>
<h3>Feature</h3>
<p>In GKE version 1.36.0-gke.4447000 and later, the VerticalPodAutoscaler supports
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/verticalpodautoscaler#cpu-startup-boost">CPU startup boost</a>,
which temporarily increases CPU requests during application startup to improve
startup latency and cost efficiency. This feature is available in Preview.</p>
<h3>Change</h3>
<h4 id="2026-r30-version-updates">(2026-R30) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.12-gke.1059000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1126000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r30-version-updates">(2026-R30) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.12-gke.1165000</li>
<li>1.34.8-gke.1278000</li>
<li>1.35.5-gke.1241004</li>
<li>1.36.0-gke.3070003 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3302004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r30-version-updates">(2026-R30) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.13-gke.1011000</li>
<li>1.34.9-gke.1131000</li>
<li>1.35.6-gke.1127000</li>
<li>1.36.0-gke.4447000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r30-version-updates">(2026-R30) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2825000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2246000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1930000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1109000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1322000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1258000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1498000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.12-gke.1059000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1000000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1163012 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3070003 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3302004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r30-version-updates">(2026-R30) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2767000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2825000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2169000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2246000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1844000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1930000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2710000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2816000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2116000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2233000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1740000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1913000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.12-gke.1165000</li>
<li>1.34.8-gke.1278000</li>
<li>1.35.5-gke.1241004</li>
<li>1.36.0-gke.3070003 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3302004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2746000</a></li>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2157000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2746000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2157000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1829000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Feature</h3>
<p><strong>Airflow 3.1.8</strong> is available in Managed Airflow (Gen 3).</p>
<h3>Change</h3>
<p>Airflow 3.1.7 is no longer included in Managed Airflow images and builds.</p>
<h3>Fixed</h3>
<p><em>(Airflow 3.1.8)</em> Backported
<a href="https://github.com/apache/airflow/pull/64031">#64031</a> to fix an issue in
the Airflow UI when viewing tasks in non-terminal states (scheduled, running)
with "Show Gantt" enabled.</p>
<h3>Change</h3>
<p><em>(Airflow 3.1.8)</em> The <code>apache-airflow-providers-google</code> package was upgraded to version 22.2.0.
For more information about changes, see the
<a href="https://airflow.apache.org/docs/apache-airflow-providers-google/stable/changelog.html">apache-airflow-providers-google changelog</a>.</p>
<h3>Change</h3>
<p><em>(Airflow 2.11.1)</em> The <code>apache-airflow-providers-google</code> package was upgraded to version 22.2.1.
For more information about changes, see the
<a href="https://airflow.apache.org/docs/apache-airflow-providers-google/stable/changelog.html">apache-airflow-providers-google changelog</a>.</p>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-3">Airflow builds</a>
are available in Managed Airflow (Gen 3):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-3-1-8-build-0">composer-3-airflow-3.1.8-build.0</a></li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-11-1-build-11">composer-3-airflow-2.11.1-build.11</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-10-5-build-44">composer-3-airflow-2.10.5-build.44</a></li>
</ul>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-2">images</a>
are available in Managed Airflow (Gen 2):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-7-airflow-2-11-1">composer-2.17.7-airflow-2.11.1</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-7-airflow-2-10-5">composer-2.17.7-airflow-2.10.5</a></li>
</ul>
<h3>Deprecated</h3>
<p>The following Managed Airflow versions and builds have reached their
<a href="https://docs.cloud.google.com/composer/docs/composer-versioning-overview#version-deprecation-and-support">end of support period</a>:
composer-3-airflow-2.10.5-build.9, composer-3-airflow-2.9.3-build.29,
composer-2.13.7-airflow-2.9.3, composer-2.13.7-airflow-2.10.5.</p>
<h2 class="release-note-product-title">Oracle Database@Google Cloud</h2>
<h3>Feature</h3>
<p>Oracle Database@Google Cloud supports cloning for Autonomous AI Databases. You can create full, metadata, and refreshable clones using Google Cloud CLI and API. For more information, see <a href="https://docs.cloud.google.com/oracle/database/docs/clone-autonomous-database">Clone an Autonomous AI Database</a>.</p>
<p>This feature is <a href="https://cloud.google.com/products#product-launch-stages">Generally Available (GA)</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 15, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_15_2026</id>
    <updated>2026-07-15T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_15_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee UI</h2>
<h3>Fixed</h3>
<p><strong>Apigee UI</strong></p>
<p>Fixed an issue where editing a legacy API Product with a selected API Proxy
could cause the Apigee UI to become unresponsive.</p>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On July 15th, 2026, we released an updated version of Apigee (1-18-0-apigee-1).</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release began today and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.</span></aside>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>527586459</strong></td>
<td>Fixed a cache policy throttling bug (CacheThrottlerV2 key poisoning) to enhance reliability.</td>
</tr>
<tr>
<td><strong>525697701</strong></td>
<td>Fixed an issue where API proxy deployments could get stuck during basepath migrations in Apigee X.</td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td>Updates to infrastructure and libraries.</td>
</tr>
</tbody>
</table>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>527415966, 524656652</strong></td>
<td><strong>Security fix for Apigee.</strong> Upgraded the Apigee ingress gateway (ASM) to patch security vulnerabilities.</td>
</tr>
<tr>
<td><strong>527956223</strong></td>
<td><strong>Security fix for Apigee.</strong> Enhanced security in the Java Callout policy to prevent sandbox escape.</td>
</tr>
<tr>
<td><strong>519729209</strong></td>
<td><strong>Security fix for Apigee.</strong> Fixed a SAML XML Signature Wrapping (XSW) vulnerability in the ValidateSAMLAssertion policy.</td>
</tr>
<tr>
<td><strong>530886487</strong></td>
<td><strong>Security fix for Apigee.</strong> Upgraded the apigee-connect-agent to patch <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25680">CVE-2026-25680</a>.</td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fix for Apigee infrastructure.</strong></td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1156">v1.15.6</h3>
<p>On July 15, 2026 we released an updated version of the Apigee hybrid software, v1.15.6.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.6</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>BigQuery supports <a href="https://docs.cloud.google.com/bigquery/docs/tags#data-governance-tags">data governance tags</a>,
which let you enforce column-level security and data masking. Data governance
tags are a type of Resource Manager tag that you can attach to sensitive columns
and use in BigQuery data policies to grant conditional access to your users.
This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Data Fusion</h2>
<h3>Feature</h3>
<p>Cloud Data Fusion version 6.11.1.4 is generally available
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<h3>Fixed</h3>
<p>Fixed in Cloud Data Fusion 6.11.1.4:</p>
<ul>
<li>Fixed a race condition where successfully completed Dataproc jobs were
incorrectly marked as <code>failed</code> on the Dataproc console due to premature program
cancellation (<a href="https://cdap.atlassian.net/browse/CDAP-21219">CDAP-21219</a>).</li>
<li>Fixed an issue where the <strong>Pipeline list</strong> page would hang due to a race
condition in an internal service
(<a href="https://cdap.atlassian.net/browse/CDAP-21241">CDAP-21241</a>).</li>
<li>Fixed a security vulnerability in log downloads by enforcing strict
validation on requested log paths and query parameters to prevent
unauthorized access (<a href="https://cdap.atlassian.net/browse/CDAP-21260">CDAP-21260</a>).</li>
</ul>
<h3>Change</h3>
<p>Changes in Cloud Data Fusion 6.11.1.4:</p>
<ul>
<li>Increased the default Wrangler browsing limit to 2,000 items
(<a href="https://cdap.atlassian.net/browse/CDAP-21259">CDAP-21259</a>).</li>
</ul>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Announcement</h3>
<p><strong>1.29.5-asm.12 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.29.5-asm.12 uses Envoy v1.35.13.</p>
<h3>Fixed</h3>
<p>Patch 1.29.5-asm.12 contains fixes for the following platform CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-46595">CVE-2026-46595</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (10.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8376">CVE-2026-8376</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8925">CVE-2026-8925</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39830">CVE-2026-39830</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39831">CVE-2026-39831</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39832">CVE-2026-39832</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39833">CVE-2026-39833</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39834">CVE-2026-39834</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42496">CVE-2026-42496</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42508">CVE-2026-42508</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8924">CVE-2026-8924</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8927">CVE-2026-8927</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8286">CVE-2026-8286</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2025-69720">CVE-2025-69720</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39822">CVE-2026-39822</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39829">CVE-2026-39829</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41992">CVE-2026-41992</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-46597">CVE-2026-46597</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-9547">CVE-2026-9547</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-25680">CVE-2026-25680</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39827">CVE-2026-39827</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8458">CVE-2026-8458</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39828">CVE-2026-39828</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5704">CVE-2026-5704</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-58055">CVE-2026-58055</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39835">CVE-2026-39835</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42505">CVE-2026-42505</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-46598">CVE-2026-46598</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41991">CVE-2026-41991</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (4.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2025-45582">CVE-2025-45582</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h3>Announcement</h3>
<p><strong>1.28.10-asm.4 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/v1.28/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.28.10-asm.4 uses Envoy v1.36.9.</p>
<h3>Fixed</h3>
<p>Patch 1.28.10-asm.4 contains fixes for the following platform CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8376">CVE-2026-8376</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8925">CVE-2026-8925</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42496">CVE-2026-42496</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8924">CVE-2026-8924</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8927">CVE-2026-8927</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8286">CVE-2026-8286</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2025-69720">CVE-2025-69720</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39822">CVE-2026-39822</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41992">CVE-2026-41992</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42151">CVE-2026-42151</a></td>
<td>No</td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42154">CVE-2026-42154</a></td>
<td>No</td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-9547">CVE-2026-9547</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8458">CVE-2026-8458</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-40179">CVE-2026-40179</a></td>
<td>No</td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-44903">CVE-2026-44903</a></td>
<td>No</td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5704">CVE-2026-5704</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-58055">CVE-2026-58055</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42505">CVE-2026-42505</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41991">CVE-2026-41991</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (4.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2025-45582">CVE-2025-45582</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h3>Announcement</h3>
<p><strong>1.27.9-asm.15 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.27.9-asm.15 uses Envoy v1.35.13v.</p>
<h3>Fixed</h3>
<p>Patch 1.27.9-asm.15 contains fixes for the following platform CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8376">CVE-2026-8376</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8925">CVE-2026-8925</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42496">CVE-2026-42496</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8924">CVE-2026-8924</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8927">CVE-2026-8927</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (9.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8286">CVE-2026-8286</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2025-69720">CVE-2025-69720</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39822">CVE-2026-39822</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41992">CVE-2026-41992</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-9547">CVE-2026-9547</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-8458">CVE-2026-8458</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5704">CVE-2026-5704</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-58055">CVE-2026-58055</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42505">CVE-2026-42505</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41991">CVE-2026-41991</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (4.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2025-45582">CVE-2025-45582</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: The network-optimized C4N machine series offers machine types with
375 GiB to 12,000 GiB of attached Titanium SSD.</p>
<p>To use C4N machine types with attached Local SSD disks, you can
<a href="https://forms.gle/ehRSqssSEavKt1Fh7">Request preview access</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/compute/docs/network-optimized-machines#c4n_series">C4N machine series</a>.</p>
<h2 class="release-note-product-title">Datastream</h2>
<h3>Feature</h3>
<p>You can now replicate change data from the following application sources with
Datastream:</p>
<ul>
<li><a href="https://docs.cloud.google.com/datastream/docs/sources-servicenow">ServiceNow</a></li>
<li><a href="https://docs.cloud.google.com/datastream/docs/sources-salesforce-marketing-cloud">Salesforce Marketing Cloud</a></li>
<li><a href="https://docs.cloud.google.com/datastream/docs/sources-dataverse">Microsoft Dataverse</a></li>
</ul>
<p>This feature is in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: New data stores and support for new actions (Preview)</strong></p>
<p>The following data stores are available in Public Preview:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/aiwyn_tax">Aiwyn Tax</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/alltrails">AllTrails</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/autodesk-product-help">Autodesk Product Help</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/aws-marketplace">AWS Marketplace</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/courtroom5">Courtroom5</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/pg_aiguide">pg-aiguide</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/taskrabbit">Taskrabbit</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/twilio_docs">Twilio Docs</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/viator">Viator</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/zoominfo">ZoomInfo</a></li>
</ul>
<p>Additionally, support for new actions is available in Public Preview for the
following data stores:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/freshservice">Freshservice</a>: Update tickets.</li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/zohodesk">Zoho Desk</a>: Update ticket comments.</li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/zoominfo">ZoomInfo</a>: Submit feedback.</li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/connect-third-party-data-source">Connect a third-party data source</a>.</p>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Action-filtering support for Jira Data Center data stores (Preview)</strong></p>
<p>Filters configured on Jira Data Center federated data stores apply to both search queries and action execution. These filters let you specify which Jira projects are accessible to the Gemini Enterprise app assistant; mutations or retrievals on out-of-scope data fail or return no results.</p>
<p>This feature is in Public Preview. For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/jira-dc/set-up-data-store">Set up a Jira Data Center data store</a> and <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/jira-dc/add-filters-to-jira-data-store">Add filters to a Jira Data Center data store</a></li>
</ul>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Memory Bank memory profiles are generally available (GA)</strong></p>
<p>Memory profiles in Memory Bank are generally available (GA). Memory profiles allow you to generate structured profiles, which are data structures with static schemas populated and updated using LLMs. By defining a fixed schema, you ensure your agents have immediate, low-latency access to evolving information without the need for expensive search operations during a session.</p>
<p>For details, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/memory-bank/profiles">Memory profiles</a>.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Advanced Filtering in Dashboards</strong></p>
<p>Advanced Filtering in dashboards is now available in Preview. This feature enhances dashboard capabilities by enabling security analysts to use query variables, also known as tokens, to inject dynamic values, complex regular expressions, or boolean logic directly into YARA-L queries at runtime. </p>
<p>Key aspects of Advanced Filtering include:</p>
<ul>
<li><strong>Token Variable Definition:</strong> When creating an advanced filter, you can define a Token Variable. Token variable names must consist only of alphanumeric characters and underscores (<code>^[a-zA-Z0-9_]+$</code>) and must be unique within the dashboard.</li>
<li><strong>Filter Value Generation:</strong> Token values can be generated dynamically from YARA-L query results or entered manually as a static list.</li>
<li><strong>Customizable Wrappers:</strong> You can specify prefixes and suffixes to wrap token values, enabling specific logic such as regular expressions.</li>
<li><strong>Multi-Select Support:</strong> The ability to select multiple options for a token can be enabled, with a configurable delimiter (for example, <code>|</code>) for combining values in queries.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/reports/native-dashboards-filters#advanced_filtering">Advanced filtering</a>.</p>
<h3>Feature</h3>
<p><strong>Parser extensions for code snippets now support Append/Replace for Repeated Fields</strong></p>
<p>You can now use append and replace functionality for repeated fields when creating code snippet extensions. Previously, this was only available for no-code extensions. This enhancement provides more granular control over how data is handled in repeated UDM fields, allowing you to either add new values or entirely replace existing ones.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/event-processing/using-parser-extensions#repeated_fields_selector">Repeated fields selector</a>.</p>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>AWS GuardDuty</strong>: Version 14.0</p>
<ul>
<li>Added support for Google Cloud Web Identity (OIDC) Federation authentication.</li>
</ul>
<h3>Change</h3>
<p><strong>SCC Enterprise</strong>: Version 22.0</p>
<ul>
<li>Refactored integration code to optimize underlying execution performance.</li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 18.0</p>
<ul>
<li><p>Added an optional <code>Active Group</code> parameter to support multi-tenant 
organization context routing in the integration configuration and the following 
connector:</p>
<ul>
<li><strong>ASM Issues Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 88.0</p>
<ul>
<li><p>Added <code>api_root</code> parameter to alert extensions to expand normalization 
metadata options in the following connector:</p>
<ul>
<li><strong>Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Defender ATP</strong>: Version 33.0</p>
<ul>
<li><p>Updated execution processing logic to improve backend tracking stability in
the following action:</p>
<ul>
<li><strong>Execute Live Response Command</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 68.0</p>
<ul>
<li><p>Updated affected CIs processing logic to handle missing reference keys
smoothly in the following job:</p>
<ul>
<li><strong>Sync Incidents Job</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>CrowdStrike Falcon</strong>: Version 78.0</p>
<ul>
<li><p>Fixed pagination loop logic to prevent infinite timeouts during high-volume
sweeps in the following action:</p>
<ul>
<li><strong>Get Host Information</strong></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>Advanced Filtering in Dashboards</strong></p>
<p>This feature is in public preview.</p>
<p>Advanced Filtering in dashboards is now available in Google SecOps. This feature enhances dashboard capabilities by enabling security analysts to use query variables, also known as tokens, to inject dynamic values, complex regular expressions, or boolean logic directly into YARA-L queries at runtime. </p>
<p>Key aspects of Advanced Filtering include:</p>
<ul>
<li><strong>Token Variable Definition:</strong> When creating an advanced filter, you can define a Token Variable. Token variable names must consist only of alphanumeric characters and underscores (<code>^[a-zA-Z0-9_]+$</code>) and must be unique within the dashboard.</li>
<li><strong>Filter Value Generation:</strong> Token values can be generated dynamically from YARA-L query results or entered manually as a static list.</li>
<li><strong>Customizable Wrappers:</strong> You can specify prefixes and suffixes to wrap token values, enabling specific logic such as regular expressions.</li>
<li><strong>Multi-Select Support:</strong> The ability to select multiple options for a token can be enabled, with a configurable delimiter (for example, <code>|</code>) for combining values in queries.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/reports/native-dashboards-filters#advanced_filtering">Advanced filtering</a>.</p>
<h3>Feature</h3>
<p><strong>Parser extensions for code snippets now support Append/Replace for Repeated Fields</strong></p>
<p>You can now use append and replace functionality for repeated fields when creating code snippet extensions. Previously, this was only available for no-code extensions. This enhancement provides more granular control over how data is handled in repeated UDM fields, allowing you to either add new values or entirely replace existing ones.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/event-processing/using-parser-extensions#repeated_fields_selector">Repeated fields selector</a>.</p>
<h2 class="release-note-product-title">Managed Service for Apache Spark</h2>
<h3>Announcement</h3>
<p>Announcing the <a href="https://cloud.google.com/products#product-launch-stages">General Availability (GA)</a> release of Managed Service for Apache Spark cluster
image version <a href="https://docs.cloud.google.com/managed-spark/docs/concepts/versioning/image-release-3.0"><code>3.0</code></a>,
as follows:</p>
<ul>
<li><p><code>3.0.0-debian13</code>, <code>3.0.0-ml-ubuntu24</code>, <code>3.0.0-rocky9</code>, and <code>3.0.0-ubuntu24</code>.</p>
<ul>
<li>The <code>3.0.0-ml-ubuntu24</code> image extends the 3.0 base image with ML-specific libraries.</li>
</ul></li>
</ul>
<p>Image version <code>3.0</code> is a lightweight image that contains the following
pre-installed core components, reducing exposure to Common Vulnerabilities and Exposures (CVEs):</p>
<ul>
<li>Apache Hadoop 3.5.0.</li>
<li>Apache Hive 4.2.0</li>
<li>Apache Spark 4.1.2</li>
<li>Apache Tez 0.10.5</li>
<li>Cloud Storage Connector 3.1.13</li>
<li>Conscrypt 2.6</li>
<li>Java 21</li>
<li>Python 3.12</li>
<li>R 4.5</li>
<li>Scala 2.13.17</li>
<li>Spark-BigQuery Connector 0.44.1-preview</li>
</ul>
<p>You can add
<a href="https://docs.cloud.google.com/managed-spark/docs/concepts/versioning/image-release-3.0">listed optional components</a>
when you create a <code>3.0</code> image version cluster.</p>
<p><strong>Recommendation:</strong> Use the <code>3.0</code> (and later) image versions to meet security
compliance requirements.</p>
<h3>Announcement</h3>
<p>New <a href="https://docs.cloud.google.com/managed-spark/docs/concepts/versioning/image-version-lists#supported-dataproc-image-versions"><strong>Managed Service for Apache Spark</strong> (formerly Dataproc on Compute Engine) subminor cluster image versions</a>:</p>
<ul>
<li>2.3.34-debian12, 2.3.34-ml-ubuntu22, 2.3.34-rocky9, 2.3.34-ubuntu22, 2.3.34-ubuntu22-arm</li>
<li>3.0.0-debian13, 3.0.0-ml-ubuntu24, 3.0.0-rocky9, 3.0.0-ubuntu24</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>July 14, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_14_2026</id>
    <updated>2026-07-14T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_14_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/conversational-analytics#bigquery-ml-support">Conversational analytics</a>
now supports the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-agg"><code>AI.AGG</code> function</a>.
This function is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Announcement</h3>
<p>As part of
<a href="https://docs.cloud.google.com/bigquery/docs/gemini-security-privacy-compliance">Gemini in BigQuery</a>,
<a href="https://docs.cloud.google.com/bigquery/docs/conversational-analytics">conversational analytics</a>
now supports <a href="https://cloud.google.com/security/compliance/hipaa">HIPAA</a>
compliance.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>AI agents can use the <a href="https://docs.cloud.google.com/bigtable/docs/reference/admin/mcp/bigtable/mcp/tools_list/list_hot_tablets"><code>list_hot_tablets</code> Model Context Protocol (MCP) tool</a>
to programmatically query Bigtable cluster health to isolate resource-intensive
tablets (hot tablets) and detect overutilized node CPUs. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.</p>
<h2 class="release-note-product-title">Cloud Interconnect</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/network-connectivity/docs/interconnect/concepts/partner-cci-for-aws-overview">Partner Cross-Cloud Interconnect for Amazon Web Services (AWS)</a> supports the following new locations:</p>
<ul>
<li>australia-southeast1</li>
<li>europe-north2</li>
</ul>
<p>For available locations, see <a href="https://docs.cloud.google.com/network-connectivity/docs/interconnect/how-to/partner-cci-for-aws/paired-locations">Choose a paired location</a>.</p>
<h2 class="release-note-product-title">Cloud Run</h2>
<h3>Feature</h3>
<p>Cloud Run support for <a href="https://docs.cloud.google.com/run/docs/deploying#images">importing public container images from GitHub Container Registry</a> is in <a href="https://cloud.google.com/products#product-launch-stages">General Availability</a>.</p>
<h2 class="release-note-product-title">Cloud Tasks</h2>
<h3>Change</h3>
<p>Cloud Tasks is available in the following <a href="https://docs.cloud.google.com/tasks/docs/locations">locations</a>:</p>
<ul>
<li><code>me-central1</code> (Doha, Qatar)</li>
<li><code>me-central2</code> (Dammam, Saudi Arabia)</li>
</ul>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Idea Generation agent removal</strong></p>
<p>The Idea Generation agent which was in public preview is removed
starting the week of July 14, 2026. Users can brainstorm ideas directly
using the assistant.</p>
<ul>
<li>For general brainstorming and creative thinking, use the Gemini Enterprise
app <a href="https://docs.cloud.google.com/gemini/enterprise/docs/assistant-chat">assistant</a>.</li>
<li>For in-depth exploration or hypothesis generation, use
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/research-assistant">Deep Research</a> or
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/co-scientist-and-alphaevolve">Co-Scientist</a> agents.</li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<p>GKE Dataplane V2 clusters running version 1.35.1-gke.1516000 or later now use
CNI version 1.1.0 in the CNI configuration files. This change requires
downstream CNI plugins to be compatible with CNI version 1.1.0.</p>
<p>Customers using self-managed open-source Istio or in-cluster unmanaged Cloud
Service Mesh (CSM) variant must manually upgrade their CSM CNI version to 1.23
to ensure compatibility. If you use an incompatible CNI version, nodes might
fail to reach a <code>Ready</code> state and might show <code>NetworkPluginNotReady</code> errors.</p>
<h3>Feature</h3>
<p>Rollout sequencing with custom stages is now generally available. This version
of rollout sequencing, which is recommended if you're configuring an environment
for the first time, offers a robust set of features including the following:</p>
<ul>
<li><strong>Define custom stages</strong>: Sequence the rollout of a new GKE version across
environments. With custom stages, you can, for example, deploy a new version
on a small subset of production clusters before a wider rollout.</li>
<li><strong>Choose the scope of rollouts</strong>: Decide what types of versions that GKE
rolls out in the sequence. For example, you can have GKE roll out patch
versions, but not minor versions, across a sequence.</li>
<li><strong>Initiate a rollout</strong>: Create a rollout of a specific version, if you want
GKE to roll out that version across your sequence.</li>
<li><strong>Manage a rollout</strong>: Pause, resume, cancel rollouts, or complete rollout
stages as needed.</li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/rollout-sequencing-custom-stages/about-rollout-sequencing">About rollout sequencing with custom stages</a>.</p>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Feature</h3>
<p>The <code>CRIME_STATUS</code> infoType detector is available in all regions. For more information about all built-in infoTypes, see the <a href="https://docs.cloud.google.com/sensitive-data-protection/docs/infotypes-reference">InfoType detector reference</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 13, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_13_2026</id>
    <updated>2026-07-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_13_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Agent Platform Workbench</h2>
<h3>Feature</h3>
<p><strong>Agent Platform Workbench image release</strong></p>
<p>The following Agent Platform Workbench instances image releases are available:</p>
<ul>
<li><strong>20260712-2130-rc0 (<code>workbench-instances-2603</code> - Debian 12)</strong>
<ul>
<li>Installed latest packages from upstream dependencies.</li>
<li>Fixed broken cupy installation.</li>
</ul></li>
<li><strong>M144 (<code>workbench-instances</code> - Debian 11)</strong>
<ul>
<li>Installed latest packages from upstream dependencies.</li>
<li>Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances.</li>
</ul></li>
</ul>
<h3>Change</h3>
<h3 id="m144_release">M144 Release</h3>
<h3>Change</h3>
<h3 id="20260712-2130-rc0_release">20260712-2130-rc0 Release</h3>
<h3>Change</h3>
<p>Installed latest packages from upstream dependencies.</p>
<h3>Change</h3>
<p>Installed latest packages from upstream dependencies.</p>
<h3>Fixed</h3>
<p>Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances.</p>
<h3>Fixed</h3>
<p>Fixed broken cupy installation.</p>
<h3>Feature</h3>
<p><strong>Secure Boot is compatible with GPUs</strong></p>
<p>You can now enable Secure Boot on Agent Platform Workbench instances that have a
GPU attached. Secure Boot with GPUs is supported on the <code>workbench-instances-2603</code>
VM image and the <code>workbench-container-2606</code> custom container, which include a
Secure Boot-signed NVIDIA GPU driver so the driver loads under Secure Boot. For
more information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/notebooks/workbench/instances/create">Create an
instance</a>.</p>
<h3>Feature</h3>
<p><strong>Secure Boot is compatible with GPUs</strong></p>
<p>You can now enable Secure Boot on Agent Platform Workbench instances that have a
GPU attached. Secure Boot with GPUs is supported on the <code>workbench-instances-2603</code>
VM image and the <code>workbench-container-2606</code> custom container, which include a
Secure Boot-signed NVIDIA GPU driver so the driver loads under Secure Boot. For
more information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/notebooks/workbench/instances/create">Create an
instance</a>.</p>
<h3>Feature</h3>
<p><strong>Secure Boot is compatible with GPUs</strong></p>
<p>You can now enable Secure Boot on Agent Platform Workbench instances that have a
GPU attached. Secure Boot with GPUs is supported on the <code>workbench-instances-2603</code>
VM image and the <code>workbench-container-2606</code> custom container, which include a
Secure Boot-signed NVIDIA GPU driver so the driver loads under Secure Boot. For
more information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/notebooks/workbench/instances/create">Create an
instance</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>Table partitioning, multi-statement transactions, and advanced runtime are now
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA) for
<a href="https://docs.cloud.google.com/bigquery/docs/biglake-iceberg-tables-in-bigquery">Apache Iceberg managed tables</a>.</p>
<h3>Feature</h3>
<p><em>Cross-cloud Lakehouse</em> now supports Snowflake as a remote
catalog provider (Preview). You can configure federated catalogs to query data
stored in Snowflake directly from Google Cloud using
BigQuery or Apache Spark without migrating data or building
complex ETL pipelines.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/lakehouse/docs/set-up-cross-cloud-lakehouse-snowflake">Set up cross-cloud Lakehouse for
Snowflake</a>.</p>
<h3>Security</h3>
<p>A Missing Authorization vulnerability was discovered in repositories in
BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could
potentially escalate permissions and perform cross-tenant repository takeover.
For more information, see the
<a href="https://docs.cloud.google.com/bigquery/docs/security-bulletins#GCP-2026-047">GCP-2026-047</a> security bulletin.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/reservations-workload-management#scheduling-policies">Project caps (also known as scheduling policies)</a>
let you limit maximum slots and concurrency per project within a BigQuery
reservation. This feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>The BigQuery <a href="https://docs.cloud.google.com/bigquery/docs/bigquery-web-ui#open-overview"><strong>Overview</strong> page</a>
is a hub for discovering tutorials, features, and resources to help you get the
most out of BigQuery. It provides guided paths for users of all skill levels.
This feature is now
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-migration-mcp">BigQuery Migration Service MCP server</a>
to perform SQL translation tasks, including translating SQL queries into
GoogleSQL syntax, generating DDL statements from SQL input queries, and getting
explanations of SQL translations.</p>
<p>This feature is
<a href="https://cloud.google.com/products/#product-launch-stages">Generally Available</a>.</p>
<h3>Feature</h3>
<p>Incremental data transfers for the
<a href="https://docs.cloud.google.com/bigquery/docs/salesforce-transfer">BigQuery Data Transfer Service for Salesforce</a>
are now
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Feature</h3>
<p>You can now use the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/data-definition-language#alter_search_index_statement"><code>ALTER SEARCH INDEX</code> DDL statement</a>
to
<a href="https://docs.cloud.google.com/bigquery/docs/search-index#update_a_search_index">update the configuration</a>
of a search index. This feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>You can now create and query parameterized secure views in Cloud SQL for MySQL.
Parameterized secure views let you create MySQL views in your MySQL database
that reference session variables for managing data access. By using a
parameterized secure view, you can create a single view that is flexible enough
to accommodate multiple queries across a predefined range of data without
being required to create multiple static view definitions for different users.</p>
<p>To use parameterized secure views, you're required to have Cloud SQL for
MySQL 8.0.43 or later and
<a href="https://docs.cloud.google.com/sql/docs/mysql/maintenance-changelog">maintenance version R20260320.00_20 or later</a>
installed on your instance.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/sql/docs/mysql/parameterized-secure-views">Parameterized secure views in Cloud SQL</a>.
This feature is in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cluster Toolkit</h2>
<h3>Feature</h3>
<p>Cluster Toolkit v1.97.0 is available. This release integrates cluster
health checks into the toolkit, adds support for collecting static node counts
from blueprints, and enforces strict Google Kubernetes Engine node auto-provisioning (NAP)
accelerator validation. For details, see the <a href="https://github.com/GoogleCloudPlatform/cluster-toolkit/discussions/5945">release announcement on
GitHub</a>.</p>
<h2 class="release-note-product-title">Colab Enterprise</h2>
<h3>Security</h3>
<p>A Missing Authorization vulnerability was discovered in repositories in
BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could
potentially escalate permissions and perform cross-tenant repository takeover.
For more information, see the
<a href="https://docs.cloud.google.com/support/bulletins#gcp-2026-047">GCP-2026-047</a> security bulletin.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-129-19506-299-20_">cos-129-19506-299-20 <a id='"cos-arm64-129-19506-299-20"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/bc1d3c4eb1b1c9af6d66b58a41aa4f5c4ffe0a57
">COS-6.12.94</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.299.20/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Enabled CONFIG_MEMORY_FAILURE in the Linux kernel for ARM64. This should improve memory errors handling when running CUDA workloads.</p>
<h3>Fixed</h3>
<p>Changed google-guest-agent's plugin installation path to /var/lib/google/guest-agent.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/fluent-bit to v4.2.6.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.8.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-40225 in sys-apps/systemd.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43010 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53167 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53341 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-736b380 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-125-19216-532-14_">cos-125-19216-532-14 <a id='"cos-arm64-125-19216-532-14"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/847eb2fe7a011d36889f243da604899209354057
">COS-6.12.94</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.532.14/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Enabled CONFIG_MEMORY_FAILURE in the Linux kernel for ARM64. This should improve memory errors handling when running CUDA workloads.</p>
<h3>Fixed</h3>
<p>Changed google-guest-agent's plugin installation path to /var/lib/google/guest-agent.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53341 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-736b380 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-675-11_">cos-117-18613-675-11 <a id='"cos-arm64-117-18613-675-11"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/1a837eaf8fd49bfc926b94a27eeff3d7a266a6cc
">COS-6.6.143</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.675.11/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-40225 in sys-apps/systemd.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53362 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-7cb9a23 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-528-10_">cos-121-18867-528-10 <a id='"cos-arm64-121-18867-528-10"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/98a225b277dfcfe3429160042cb7cb70cfefe3ca
">COS-6.6.143</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.528.10/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-40225 in sys-apps/systemd.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53362 in the Linux kernel.</p>
<h2 class="release-note-product-title">Dataform</h2>
<h3>Security</h3>
<p>A Missing Authorization vulnerability was discovered in repositories in
BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could
potentially escalate permissions and perform cross-tenant repository takeover.
For more information, see the
<a href="https://docs.cloud.google.com/dataform/docs/security-bulletins#gcp-2026-047">GCP-2026-047</a>
Dataform security bulletin.</p>
<h2 class="release-note-product-title">Developer Connect</h2>
<h3>Security</h3>
<p>For GitLab Enterprise and Bitbucket Data Center connections, Developer Connect now
checks permissions on the calling principal.</p>
<p>When you create or update repository connections, Developer Connect uses Secret Manager
secrets to authenticate to third-party Git providers. Previously, these
referenced secrets were retrieved by the Developer Connect service agent (P4SA) on your
behalf, checking permissions only against the P4SA's credentials rather than
those of the calling principal. To adhere to the security principle of least
privilege, Developer Connect now checks permissions on both the calling principal
(using end-user credentials) and the P4SA, to ensure both have the
<code>secretmanager.versions.access</code> IAM permission on the referenced
secrets.</p>
<p>This check only affects GitLab Enterprise (GLE) and Bitbucket Data Center (BBDC)
connections.</p>
<p>For instructions and more details, see the
<a href="https://cloud.google.com/developer-connect/docs/security-bulletins#gcp-2026-048">Developer Connect security bulletin</a>.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>SOAR migration to Google Cloud validation status</strong></p>
<p>You can now check if the SOAR migration was successful by going to the <strong>SOAR Settings &gt; License Management</strong> page.
After successful completion of Stage 1, it will say <strong>Google.com</strong> after the system version number. 
After successful completion of Stage 2 of SOAR permissions to IAM roles, it will say both <strong>Google.com</strong> and <strong>CloudIAM Enabled</strong> after the system version number.</p>
<p>For more information on the migration, see the <a href="https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/migrate-to-gcp">SOAR migration guide</a></p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Announcement</h3>
<p>The latest versions in the Looker (Google Cloud core) <a href="https://docs.cloud.google.com/looker/docs/looker-core-release-process#release_channels">release channels</a> are beginning deployment as follows:</p>
<ul>
<li>Latest version in the Rapid channel: <strong>Looker 26.12</strong></li>
<li>Latest version in the Regular channel: <strong>Looker 26.10</strong></li>
<li>Latest version in the No Channel channel: <strong>Looker 26.12</strong></li>
</ul>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Issue</h3>
<p>In Managed Airflow (Gen 3) builds with Airflow 2.11.1 starting from
<a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-11-1-build-7">composer-3-airflow-2.11.1-build.7</a>,
the Airflow web server requires at least 3 GB of memory (the default amount of
memory for a Small environment preset is 4 GB).</p>
<p>If the Airflow web server has less than 3 GB of memory, it might experience
intermittent out-of-memory (OOM) issues. To resolve these issues,
<a href="https://docs.cloud.google.com/composer/docs/composer-3/scale-environments#web-server-parameters">increase the web server memory</a>
to at least 3 GB.</p>
<h2 class="release-note-product-title">Managed Service for Apache Spark</h2>
<h3>Feature</h3>
<p><strong>Managed Service for Apache Spark</strong> (formerly Dataproc on Compute Engine):</p>
<ul>
<li>The <code>2.1</code>, <code>2.2</code> and <code>2.3</code> cluster image versions now support
<a href="https://docs.cloud.google.com/managed-spark/docs/concepts/configuring-clusters/confidential-compute">Confidential Compute</a>
for the
<a href="https://docs.cloud.google.com/compute/docs/gpus#rtx-6000-gpus"><code>g4-standard-48</code></a>
GPU machine type.</li>
</ul>
<h3>Change</h3>
<p><strong>Managed Service for Apache Spark</strong> (formerly Google Cloud Serverless for Apache Spark):</p>
<ul>
<li><p>The <a href="https://docs.cloud.google.com/managed-spark/docs/concepts/versions/spark-runtime-3.0">3.0 runtime</a>
now uses fewer executors, as follows:</p>
<ul>
<li>0 min executors for <code>spark.dynamicAllocation.minExecutors</code> property</li>
<li>1 min executor for <code>spark.executor.instances</code> and <code>spark.dynamicAllocation.initialExecutors</code> properties</li>
</ul></li>
<li><p>All runtimes now configure <code>spark.scheduler.listenerbus.exitTimeout</code> to <code>30</code> seconds.</p></li>
</ul>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Change</h3>
<p>If you leave <code><a href="https://docs.cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/InfoType#FIELDS.version">InfoType.version</a></code> unset
or set it to <code>stable</code> when setting the <code>MEDICAL_ID</code>
infoType in your <code><a href="https://docs.cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/InspectConfig">InspectConfig</a></code>,
Sensitive Data Protection includes <code>MEDICAL_RECORD_NUMBER</code>
findings as type <code>MEDICAL_ID</code> in the scan results.</p>
<p>You can still use the old functionality by setting
<code>InfoType.version</code> to <code>legacy</code> for the next 90 days.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 12, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_12_2026</id>
    <updated>2026-07-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_12_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>Publisher Agent Version 2.7.0</strong></p>
<p>Publisher Agent Version 2.7.0 is now available for all regions.</p>
<p>This release includes the following updates for the remote agent:</p>
<ul>
<li><strong>High Availability support:</strong> Adds applicative support for Publisher high availability.</li>
<li><strong>File transfer support:</strong> You can now upload and download files using playbooks and the SDK on agents that have been migrated to the GCOM infrastructure.</li>
</ul>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.93 is being rolled out to the first phase of regions as listed
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
<h3>Feature</h3>
<p><strong>Publisher Agent Version 2.7.0</strong></p>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_05_2026">Publisher Agent Version 2.7.0</a>
is now available for all regions.</p>
<h2 class="release-note-product-title">Secret Manager</h2>
<h3>Feature</h3>
<p>Parameter templates are available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. This feature
lets you define standardized configuration blueprints and securely substitute
environment-specific variables from parameter versions during deployment.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/secret-manager/parameter-manager/docs/parameter-templates-overview">Parameter templates overview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 11, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_11_2026</id>
    <updated>2026-07-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_11_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_5_2026">Release 6.3.92</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 10, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_10_2026</id>
    <updated>2026-07-10T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_10_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee Advanced API Security</h2>
<h3>Deprecated</h3>
<p><strong>Deprecation and shutdown of GenAI Incident Summary (generative AI Insights)</strong></p>
<p>The standalone <strong>GenAI Incident Summary</strong> (generative AI Insights) feature in
Apigee Advanced API Security Abuse Detection, currently in Preview, is
deprecated and shut down as of July 9, 2026. This feature used Google Cloud
generative AI large language models (LLMs) to provide automated summaries and
mitigation guidance for security incidents identified by the Abuse Detection
clustering tool.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/apigee/docs/deprecations/genai-incident-summary">GenAI Incident Summary deprecation</a>.</p>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1167">v1.16.7</h3>
<p>On July 10, 2026 we released an updated version of the Apigee hybrid software, v1.16.7.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.7</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">Backup and DR</h2>
<h3>Feature</h3>
<p>Cloud SQL enhanced backups now supports custom on-demand backups. You can
now initiate an on-demand backup with a custom retention period. To cap this
retention period, you can specify a maximum retention limit by using the
<code>max-custom-on-demand-retention-days</code> field when creating a backup plan.
Additionally, you can now create a backup plan without scheduled backup
rules, provided that the custom on-demand retention period is configured.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/cloud-console/sql/csql-backup#on-demand-backups">On-demand backups</a> and <a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/cloud-console/backup-plan-create#create-backup-plan-with-no-backup-rule">Create a backup plan with no backup rule</a>.</p>
<h3>Feature</h3>
<ul>
<li><p>You can now change the backup plan applied to an existing AlloyDB for PostgreSQL cluster,
provided that the new backup plan uses the same backup vault and is in the same
region as the AlloyDB for PostgreSQL cluster. For more information, see
<a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/cloud-console/alloydb/alloydb-backup#change-plan">Change a backup plan</a>.</p></li>
<li><p>You can now take <strong>on-demand backups with custom retention</strong> of your AlloyDB for PostgreSQL cluster
at any time, independently of your <em>scheduled backups</em>. For more information,
see <a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/cloud-console/alloydb/alloydb-backup#create_an_on-demand_backup">Create an on-demand backup</a>.</p></li>
</ul>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>Payments documents for invoiced billing accounts available on Payment
status page</strong></p>
<p>For
<a href="https://docs.cloud.google.com/billing/docs/concepts#billing_account_types">Cloud Billing accounts that are paid by invoice</a>,
access to your payments documents, such as invoices and credit memos, is now
available in the Cloud Billing console in the <strong>Payment status</strong> page.</p>
<p>The <strong>Payment status</strong> page replaces the <strong>Invoices</strong> page. Self-service
(online) Cloud Billing accounts will continue to access Payments
documents on the <strong>Invoices</strong> page.</p>
<p>The <strong>Payment status</strong> page provides a real-time and customizable view of your
financial standing with your Cloud Billing account. The Payment status
page is based on the
<a href="https://support.google.com/paymentscenter/answer/7520537">Google payments <strong>Statement of account</strong></a>
page, with your payments documents filtered by the <em>Google payments account</em>
that is linked to the Cloud Billing account that you are viewing.</p>
<p>For more information about payments documents, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/get-invoice">Get a Cloud Billing document such as an invoice, statement, or receipt</a></li>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/view-history">View your cost and payment history</a></li>
<li><a href="https://support.google.com/paymentscenter/answer/7520537">Google payments Statement of account</a></li></ul>
<h2 class="release-note-product-title">Cloud Deploy</h2>
<h3>Change</h3>
<p>The Cloud Deploy image now uses a Google-specific fork of Skaffold. The
Skaffold version that you see if you run <code>gcloud deploy releases describe</code>, or
if you view the release in the Google Cloud Console, is now <code>cd-skaffold</code>
instead of a version number.</p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for VMware</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for VMware 1.33.1000-gke.59 is now available
for download. To upgrade, see <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/how-to/upgrading.md">Upgrade clusters</a>.
Google Distributed Cloud 1.33.1000-gke.59 runs on Kubernetes v1.33.11-gke.100.</p>
<p>If you use a third-party storage vendor, check the listing of our
previously-qualified <a href="https://docs.cloud.google.com/kubernetes-engine/enterprise/docs/resources/partner-storage">storage partners</a>.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for use with GKE On-Prem API clients: the Google Cloud console, the
gcloud CLI, and Terraform.</p>
<p>The following patches were skipped:</p>
<ul>
<li>1.33.900</li>
<li>1.34.600</li>
<li>1.35.200</li>
</ul>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.33.1000-gke.59:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed the issue preventing patch releases for GDC software only for VMware.</li>
</ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.33.1000-gke.59 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.33.1000-gke.59 runs on Kubernetes v1.33.11-gke.100.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the listing of our
previously-qualified <a href="https://docs.cloud.google.com/kubernetes-engine/enterprise/docs/resources/partner-storage">storage partners</a>.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.33.1000-gke.59:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where Certificate Authority (CA) rotation failed for
self-managing clusters (admin, hybrid, and standalone). The failure occurs
during the final phase of the rotation when attempting to move management
resources back from the temporary bootstrap cluster to the self-managing
cluster, which can leave the cluster in an unmanageable state. You must
upgrade your clusters to version 1.33.1000-gke.59 before you rotate your CAs.
Running a CA rotation on self-managing clusters in versions prior to
1.33.1000-gke.59 triggers this issue and can disrupt your ability to manage
the cluster.
</li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r29-version-updates">(2026-R29) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1270000</li>
<li>1.34.9-gke.1065000</li>
<li>1.35.6-gke.1049000</li>
<li>1.36.0-gke.3712000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3302004</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2746000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2816000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2157000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2233000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1829000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1913000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3302004</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2608000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2767000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1986000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2169000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1729000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1844000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2710000</a></li>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2116000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2710000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2116000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1740000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2816000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2233000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1913000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r29-security-updates">(2026-R29) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.31.14-gke.2233000</td>
<td>cos-117-18613-613-77</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-77_">cos-117-18613-613-77 release notes</a></td>
</tr>
<tr>
<td>1.32.13-gke.1913000</td>
<td>cos-117-18613-613-77</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-77_">cos-117-18613-613-77 release notes</a></td>
</tr>
<tr>
<td>1.33.13-gke.1101000</td>
<td>cos-121-18867-381-201</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-381-201_">cos-121-18867-381-201 release notes</a></td>
</tr>
<tr>
<td>1.34.9-gke.1287000</td>
<td>cos-125-19216-395-138</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-395-138_">cos-125-19216-395-138 release notes</a></td>
</tr>
<tr>
<td>1.36.0-gke.4681000</td>
<td>cos-129-19506-224-80</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-224-80_">cos-129-19506-224-80 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r29-version-updates">(2026-R29) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r29-version-updates">(2026-R29) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3302004</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r29-version-updates">(2026-R29) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1270000</li>
<li>1.34.9-gke.1065000</li>
<li>1.35.6-gke.1049000</li>
<li>1.36.0-gke.3712000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r29-version-updates">(2026-R29) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2816000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2233000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1913000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1101000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1287000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1250000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362">1.36.2-gke.1346000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r29-version-updates">(2026-R29) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2746000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2816000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2157000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2233000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1829000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1913000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3302004</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2608000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2767000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1986000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2169000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1729000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1844000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2710000</a></li>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2116000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2710000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2116000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1740000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Network Connectivity Center</h2>
<h3>Feature</h3>
<p>Include and exclude <a href="https://docs.cloud.google.com/network-connectivity/docs/network-connectivity-center/concepts/spoke-filters-overview">spoke filters</a>
for hybrid spokes are <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<p>You can use export filters to control which subnets or routes a spoke can
send to the hub. Import filters control which subnets or routes can be
accepted by a spoke from the hub.</p>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>New SAP certifications: M4N series of memory-optimized machine types</strong></p>
<p>For use with SAP HANA scale-up (OLAP and OLTP) and SAP NetWeaver workloads, SAP
has certified the Compute Engine memory-optimized M4N series machine types with
the Intel Emerald Rapids CPU platform.</p>
<p>For more information, see:</p>
<ul>
<li>For SAP HANA, see
<a href="https://docs.cloud.google.com/sap/docs/sap-hana-planning-guide#m4n-memory-optimized">M4N memory-optimized machine types</a></li>
<li>For SAP NetWeaver, see
<a href="https://docs.cloud.google.com/sap/docs/certifications-sap-apps#sap-certified-vms-mem-optimized-m4n">M4N memory-optimized machine types</a></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>July 09, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_09_2026</id>
    <updated>2026-07-09T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_09_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can use the BigQuery Data Transfer Service to transfer metadata from the
following data sources into Knowledge Catalog:</p>
<ul>
<li><a href="https://docs.cloud.google.com/bigquery/docs/postgresql-transfer#transfer_metadata">PostgreSQL</a></li>
<li><a href="https://docs.cloud.google.com/bigquery/docs/sqlserver-transfer#transfer_metadata">Microsoft SQL Server</a></li>
</ul>
<p>This feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/data-cloud-extension">The Data Agent Kit extension</a> is an extension for agent
coding tools, such as VS Code, Antigravity, and Cursor, that lets
you interact with BigQuery resources directly in your agent environment. You can
use this extension to browse datasets, manage pipelines, run queries, and prompt
your agent to perform other BigQuery tasks directly in your preferred IDE. This
feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>Support for hybrid search (using the <code>VECTOR_SEARCH</code> function to combine a
semantic search with a lexical (keyword) search) has been temporarily disabled.
We are working to restore this feature as soon as possible.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/bigtable/docs/reference/libraries">Bigtable client library for Go</a>
to execute read jobs and queries using <a href="https://docs.cloud.google.com/bigtable/docs/data-boost-overview">Data Boost</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: Advanced Compute Images provide high-performance images to support
your artificial intelligence (AI), machine learning (ML), and high-performance
computing (HPC) workloads on Google Cloud.</p>
<p>Advanced Compute Images provide a single source of trusted, performance-tuned
OS images that remove the need for manual image building for specialized
workloads. Each image version is pre-installed with the necessary drivers,
network fabrics, and Slurm agents to help you run your workloads.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-117-18613-675-7_">cos-117-18613-675-7 <a id='"cos-arm64-117-18613-675-7"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/5aec657e051de42c4e591b15fcf30c82947bd22a
">COS-6.6.143</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.675.7/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-admin/oslogin to v20260626.00.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.8.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.53.3.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.8.2.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/acl to v2.4.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53359 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-d82ba05 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-125-19216-532-9_">cos-125-19216-532-9 <a id='"cos-arm64-125-19216-532-9"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/5576e06b230afb3a4f89d660421d5400b443d9bc
">COS-6.12.94</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.532.9/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Added support for NVIDIA GRID driver version 580.159.03.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-40225 in sys-apps/systemd.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53167 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53359 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-d82ba05 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-129-19506-299-8_">cos-129-19506-299-8 <a id='"cos-arm64-129-19506-299-8"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/528543b74575bd46e7fc7ccc61eabc1868789e84
">COS-6.12.94</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.299.8/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Added support for NVIDIA GRID driver version 580.159.03.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53359 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-528-7_">cos-121-18867-528-7 <a id='"cos-arm64-121-18867-528-7"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/973fc67ab8454c85a6f165680dbe1459a1520353
">COS-6.6.143</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.528.7/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-53359 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-d82ba05 in the Linux kernel.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Enable skills feature management toggle is
not available</strong></p>
<p>The <strong>Enable skills</strong> feature management toggle is not available.
This feature is generally available (GA) with an allowlist in Gemini
Enterprise. After your organization is added to the allowlist, end users can
create and use skills directly in the app. To access this feature, contact your
Google account manager.</p>
<p>We will update the release notes when the <strong>Enable skills</strong> toggle for
administrators is available.</p>
<aside class="note"><strong>Note:</strong><span> This is a correction to the <a href="https://docs.cloud.google.com/gemini/enterprise/docs/release-notes#June_17_2026">June 17, 2026 release
note</a>.</span></aside>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: AlphaEvolve algorithm optimization agent (GA)</strong></p>
<p>The AlphaEvolve optimization service is generally available (GA) on the
Gemini Enterprise agent. AlphaEvolve is a code optimization
and discovery agent built on top of Gemini that helps solve the hardest algorithmic
problems for your business and research. It combines creative, server-side
LLM exploration with secure client-side code execution to autonomously
discover new, optimized solutions that surpass human-designed
baselines.</p>
<aside class="note"><strong>Note:</strong><span> AlphaEvolve does not support FedRAMP or DoD compliance
requirements. Access for environments requiring these standards is restricted
by default but can be requested through your account team.</span></aside>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/alphaevolve/developer-guide/overview">AlphaEvolve documentation</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Retirement for preview models for 2.5 Flash, 2.5 Flash-Lite, and 3.1
Flash-Lite</strong></p>
<p>The following preview model endpoints have been retired and are no longer
accessible:</p>
<ul>
<li><code>gemini-2.5-flash-lite-preview-09-2025</code></li>
<li><code>gemini-2.5-flash-preview-05-2025</code></li>
<li><code>gemini-3.1-flash-lite-preview</code></li>
</ul>
<p>See <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/migrate">Migrate to the latest Google
models</a> for information on how
to migrate your project.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-R27-version-updates">(2026-R27) Version updates</h4>
<p>There are no version updates for 2026-R27.</p>
<h3>Change</h3>
<h4 id="2026-R27-version-updates">(2026-R27) Version updates</h4>
<p>There are no version updates for 2026-R27.</p>
<h3>Change</h3>
<h4 id="2026-R27-version-updates">(2026-R27) Version updates</h4>
<p>There are no version updates for 2026-R27.</p>
<h3>Change</h3>
<h4 id="2026-R27-version-updates">(2026-R27) Version updates</h4>
<p>There are no version updates for 2026-R27.</p>
<h3>Change</h3>
<h4 id="2026-R27-version-updates">(2026-R27) Version updates</h4>
<p>There are no version updates for 2026-R27.</p>
<h3>Change</h3>
<h4 id="2026-R27-version-updates">(2026-R27) Version updates</h4>
<p>There are no version updates for 2026-R27.</p>
<h3>Change</h3>
<h4 id="2026-r28-version-updates">(2026-R28) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1284000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1324000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3302004</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.12-gke.1116000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1218000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1163012</li>
<li>1.36.0-gke.2684000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.12-gke.1000000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1000000</li>
<li>1.35.5-gke.1000004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057002</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2767000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2169000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1740000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1844000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2746000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2157000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1657000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1829000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.12-gke.1116000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1218000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1163012</li>
<li>1.36.0-gke.2684000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1729000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2767000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2169000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1844000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.12-gke.1000000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.12-gke.1116000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.12-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.7-gke.1499000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1218000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1284000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1000004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1324000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.2684000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Change</h3>
<h4 id="2026-r28-version-updates">(2026-R28) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.12-gke.1000000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1000000</li>
<li>1.35.5-gke.1000004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057002</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r28-version-updates">(2026-R28) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.12-gke.1116000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1218000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1163012</li>
<li>1.36.0-gke.2684000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r28-version-updates">(2026-R28) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1284000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1324000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.3302004</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1270000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1065000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1049000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3712000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r28-version-updates">(2026-R28) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2767000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2169000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1844000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313">1.33.13-gke.1011000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349">1.34.9-gke.1131000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356">1.35.6-gke.1127000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.4447000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.12-gke.1000000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.12-gke.1116000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.12-gke.1208000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.7-gke.1499000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1218000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1284000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1000004 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1324000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.36.0-gke.2684000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r28-version-updates">(2026-R28) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2767000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2169000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1740000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1844000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2746000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.2157000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1657000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1829000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.12-gke.1116000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.8-gke.1218000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.5-gke.1163012</li>
<li>1.36.0-gke.2684000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1729000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1165000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241004</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Knowledge Catalog connectors for importing metadata from SQL Server and
PostgreSQL data sources are available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>Knowledge Catalog connectors automatically extract metadata (technical,
operational, and business) from external data sources and import it into
Knowledge Catalog entry groups. You can schedule metadata import runs on a set
schedule.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/connectors">About database connectors</a>
and <a href="https://docs.cloud.google.com/dataplex/docs/manage-connector-jobs">Manage connector jobs</a>.</p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Announcement</h3>
<p><strong>Looker 26.12</strong> will roll out to Looker (original) instances on the following schedule:</p>
<ul>
<li>Expected deployment start: <strong>Sunday, July 12, 2026</strong></li>
<li>Expected final deployment and download available: <strong>Sunday, July 26, 2026</strong></li>
</ul>
<p>Looker 26.12 is expected to include the following changes, features, and fixes.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where accessing a folder that contained scheduled content that was configured for disabled integrations could cause Looker to crash with a <code>TypeError</code>. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where users with only the Admin via IAM role on Looker (Google Cloud Core) instances would incorrectly lack access to connections when Advanced Control Governance (ACG) was enabled. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>Layout spacing and column alignment issues have been fixed on the OIDC and SAML authentication Admin pages. These features now perform as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where clicking <strong>Reset Styles</strong> in the table visualization formatting panel would unexpectedly reset the table theme, color palette, and custom borders. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the <strong>Workflows</strong> page was not visible to users with the <code>create_alerts</code> permission. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the comparison value in a KPI visualization could be incorrectly centered when the sparkline was disabled. This feature now performs as expected.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/admin-panel-general-preview-features#kpi_visualization"><strong>KPI Visualization</strong> preview feature</a> is now enabled by default.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/admin-panel-performance-center-content-guardrails#visualization-limits"><strong>Increased Row Limit</strong></a> feature is now out of labs and generally available.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the LookML validator used a stale cache for local project dependencies when the dependencies were updated in production. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where some custom visualizations could be cut off in PDF exports. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where, if a dashboard tile contained no results, the <code>row_total</code> table calculation function could return an error, which would prevent scheduled deliveries. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the commit hash in the Deploy Manager displayed PENDING during compilation and didn't update upon refresh. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where drilling down on a value for which the custom value format contained the <code>#</code> character could cause the page to crash. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where inline button toggle filters on dashboards could be cut off or could overlap with adjacent filters. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where deleting a duplicated dashboard tab would incorrectly delete shared elements from other tabs. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the column limit could fail to apply to an Explore that used pivots. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where <code>added_params</code> metadata in streaming JSON responses could be malformed or missing. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where OAuth connections would incorrectly fail connection tests on the <strong>Self-service Explores</strong> Admin page. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the <strong>Run</strong> and <strong>Settings</strong> buttons were not correctly being displayed on embedded Explores with the <code>_theme</code> URL parameter. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the Content Validator returned a generic error message instead of returning the specific models that were affected. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where drilling into a value while in Dev mode could return a <code>500 internal server</code> error. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where API calls that were made by service account users without a configured last name failed with a <code>500 internal server</code> error. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where <code>view.field</code> references in Liquid were not correctly rendered if the field name matched a built-in Liquid variable. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where autosizing table columns didn't work as expected in drill menus. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where drill modals could repeatedly render a visualization, which would present as constant flickering in the browser. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where invalid parameters in an embed URL could result in Looker displaying an unnecessarily verbose stack trace instead of a concise error. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where editing a workflow on the <strong>Workflow Management</strong> page could load indefinitely. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where clearing the <strong>Totals Labels</strong> option for the <strong>Totals Color</strong> setting in the color picker resulted in black text in the chart. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>The OAuth interface now prohibits forward slashes in the OAuth Client ID field. Previously, the inclusion of one or more forward slashes would result in a 401 error. This feature now performs as expected.</p>
<h3>Change</h3>
<p>Looker CI Run Alert emails now include the Run ID in the subject line to prevent email threading. The email body now includes the Git branch and commit details.</p>
<h3>Feature</h3>
<p>Looker (Google Cloud core) now supports <a href="https://docs.cloud.google.com/looker/docs/looker-core-fips-mode">FIPS 140-3 level 1 compliance</a>. Existing FIPS 140-2 compliant instances will be automatically upgraded to the FIPS 140-3 standard when they're upgraded to Looker 26.12.</p>
<h3>Feature</h3>
<p>Now available in preview, the <a href="https://docs.cloud.google.com/looker/docs/admin-panel-general-preview-features#table-row-grouping"><strong>Table Row Grouping</strong> feature</a> option for table charts lets users display table chart data hierarchically in groups and customize the appearance with new <a href="https://docs.cloud.google.com/looker/docs/table-options#grouping-menu-options"><strong>Grouping</strong> menu options</a>.
This feature is enabled by default.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p>You can modify the <a href="https://docs.cloud.google.com/security-command-center/docs/data-residency-support">data residency</a>
and <a href="https://docs.cloud.google.com/security-command-center/docs/cmek">data encryption</a> configuration
on the Premium and Standard tiers after you activate Security Command Center for your
organization. For more information, see
<a href="https://docs.cloud.google.com/security-command-center/docs/modify-data-residency-encryption.md">Modify data residency or data encryption configuration</a>.</p>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Feature</h3>
<p>The <code>SWITZERLAND_PASSPORT</code> infoType detector is available in all regions. For more information about all built-in infoTypes, see the <a href="https://docs.cloud.google.com/sensitive-data-protection/docs/infotypes-reference">InfoType detector reference</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 08, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_08_2026</id>
    <updated>2026-07-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_08_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>External search with AlloyDB now supports Apache <a href="https://docs.cloud.google.com/alloydb/docs/solr-search">Solr</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.
You can use the <a href="https://docs.cloud.google.com/alloydb/docs/reference/extensions#external_search_fdw"><code>external_search_fdw</code></a> extension to connect to a Solr cluster and query its data directly from your database.</p>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Security</h3>
<p>An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allowed an authenticated attacker to exfiltrate cross-tenant data.</p>
<p>This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed. Apigee hybrid was not affected.</p>
<p>For more information, see <a href="http://cve.org/CVERecord?id=CVE-2026-12879">CVE-2026-12879</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Change</h3>
<p>An updated version of the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/odbc-jdbc-drivers#current_odbc_driver">Simba ODBC driver for BigQuery</a>
is now available.</p>
<h3>Feature</h3>
<p>You can now perform
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/aggregate-function-calls#multi_level_aggregation">multi-level aggregation</a>
in GoogleSQL, which lets you use an aggregate function as an
argument to another aggregate function. This feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Run</h2>
<h3>Feature</h3>
<p>Cloud Run sandboxes provide a fast and secure isolated environment to execute untrusted code, such as code generated by AI agents. For more information, see <a href="https://docs.cloud.google.com/run/docs/configuring/services/sandboxes">Configure sandboxes for services</a> and <a href="https://docs.cloud.google.com/run/docs/code-execution">Code execution in Cloud Run</a> (<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">Cloud Workstations</h2>
<h3>Announcement</h3>
<p>The base VM for your workstation includes the Content-Addressable Storage File
System (CASFS) kernel module, which lets you run the Android Build File System
(ABFS). For more information about the introduction of this module, see the
<a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#February_20_2026">Container-Optimized OS Milestone 129 LTS release notes</a>.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/data-cloud-extension">Data Agent Toolkit Extension</a> is installed by default in Code OSS for Cloud Workstations.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: The network-optimized C4N machine series is generally
available for Compute Engine and Google Kubernetes Engine (GKE) customers. Powered
by 5th generation Intel Xeon Scalable processors (Emerald Rapids), C4N instances
are purpose-built for network- and block storage-intensive workloads such as:</p>
<ul>
<li>Network and security appliances</li>
<li>High-performance databases</li>
<li>High-scale data analytics</li>
<li>Distributed filesystems</li>
</ul>
<p>The C4N machine series delivers the highest I/O performance available in
Compute Engine, supporting up to 400 Gbps of network bandwidth
and up to 95 million packets per second (Mpps) of sustained packet processing
performance. C4N also offers leading block storage performance with Hyperdisk Extreme that
scales up to 25 GiB/s of bandwidth and 1M IOPS. C4N instances are available
in predefined machine shapes with three different vCPU to memory ratios, ranging
in size from 2 to 192 vCPUs and up to 1,488 GB of DDR5 memory.</p>
<p>For C4N machine types with attached Local SSD disks, you can
<a href="https://forms.gle/ehRSqssSEavKt1Fh7">Request preview access</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/compute/docs/network-optimized-machines#c4n_series">C4N machine series</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Deprecated</h3>
<p><strong>Grok 4.1 models deprecation</strong></p>
<p>The Grok 4.1 model family (including <code>xai/grok-4.1-fast-reasoning</code> and <code>xai/grok-4.1-fast-non-reasoning</code>) on the Gemini Enterprise Agent Platform is deprecated and will be shut down on August 20, 2026. After this date, Google Agent Platform Model as a Service (MaaS) will no longer serve these models. Specifically, API requests directed to the <code>https://aiplatform.googleapis.com/v1/projects/&lt;your-project&gt;/locations/global/endpoints/openapi/chat/completions</code> endpoint using the Grok 4.1 model IDs will fail and return a <code>400</code> error. To maintain service, migrate your applications to newer xAI models (such as Grok 4.2 or Grok 4.3) or choose an alternative model from the Google Cloud Model Garden.</p>
<h3>Feature</h3>
<p><strong>Memory Bank support for Gemini Embedding 2</strong></p>
<p>Memory Bank supports the <code>gemini-embedding-2</code> model for similarity search configurations.</p>
<p>When you configure <code>gemini-embedding-2</code> as the embedding model, you must use one of the <code>global</code>, <code>us</code>, or <code>eu</code> endpoints in the model's resource name (for example, <code>projects/{project}/locations/us/publishers/google/models/gemini-embedding-2</code>). Memory Bank does not support using regional locations (for example, <code>us-central1</code>) for <code>gemini-embedding-2</code>.</p>
<p>For details, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/memory-bank/setup#similarity-search-config">Similarity search configuration</a>.</p>
<h3>Feature</h3>
<p><strong>Memory Bank IngestEvents is generally available (GA)</strong></p>
<p>The Memory Bank <code>IngestEvents</code> API is generally available. The <code>IngestEvents</code> API decouples event ingestion from memory generation, letting you continuously stream content to Memory Bank and configure when memory generation is triggered.</p>
<p>This GA release includes the following features:</p>
<ul>
<li><strong>Carry over context between generation windows:</strong> Use the <code>overlap_event_count</code> parameter to re-include already-processed events at the start of the next window to keep memories coherent.</li>
<li><strong>Configure memory revisions for ingested events:</strong> Use <code>revision_labels</code>, <code>revision_ttl</code>, or <code>disable_memory_revisions</code> to customize how generated revisions are managed.</li>
<li><strong>Attach metadata to memories:</strong> Use the <code>metadata</code> and <code>metadata_merge_strategy</code> configuration parameters to store structured information alongside generated memories.</li>
</ul>
<p>For details, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/memory-bank/ingest-events">Ingest events</a>.</p>
<h2 class="release-note-product-title">Google Cloud Armor</h2>
<h3>Feature</h3>
<p>Cloud Armor preconfigured rules support <a class="external" href="https://github.com/coreruleset/coreruleset/releases/tag/v4.22.0" target="github">ModSecurity Core Rule Set (CRS)
4.22</a> 
 as a rule source. For more information, see <a href="https://docs.cloud.google.com/armor/docs/rule-tuning">Tuning Google Cloud Armor WAF
rules</a>. This feature is Generally Available.</p>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: You can configure disaster recovery for Google Cloud VMware Engine by using JetStream.
Disaster recovery options include the following:</p>
<ul>
<li>Set up a Google Cloud VMware Engine private cloud as a recovery site for your on-premises VMware applications.</li>
<li>Protect workloads on a primary private cloud by using a recovery site in another Google Cloud location or on-premises environment.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/vmware-engine/docs/vmware-ecosystem/howto-disaster-recovery-jetstream">Configure disaster recovery using JetStream</a>.</p>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Google Cloud VMware Engine offers self-service management for
<a href="https://docs.cloud.google.com/vmware-engine/docs/vmware-ecosystem/howto-vsan-encryption">customer-managed encryption keys (CMEK)</a>
using the Google Cloud console and the VMware Engine API. You can enable CMEK for
your private clouds, using Cloud Key Management Service (Cloud KMS) to manage encryption keys for
vSAN and <a href="https://docs.cloud.google.com/vmware-engine/docs/vmware-ecosystem/howto-vtpm">vTPM</a>. Key features and considerations include:</p>
<ul>
<li>You can transition between CMEK and Google-owned and Google-managed encryption keys (GMEK) as
needed.</li>
<li>The "Auto-Rekey" feature integrates with Cloud KMS key rotation to perform automated key rotation
for the key encryption key (KEK), maintaining security without manual intervention or
service downtime.</li>
</ul>
<p><strong>Limitations</strong>: This self-service functionality is unavailable for private clouds
that use CMEK through service tickets.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>The network-optimized
<a href="https://docs.cloud.google.com/compute/docs/network-optimized-machines#c4n_series">C4N machine series</a> is
available with GKE clusters running 1.36.0-gke.3009002 or later. You can use
C4N machine types in Standard or Autopilot mode.</p>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>FileUtilities</strong>: Version 27.0</p>
<ul>
<li><p>Added support for extracting files from .7z archives in the following action:</p>
<ul>
<li><strong>Extract Zip Files</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Threat Intelligence</strong>: Version 17.0</p>
<ul>
<li><p>Fixed widget rendering failures by escaping raw HTML script tags within
<code>extended_response_body</code> in the following action:</p>
<ul>
<li><strong>Get ASM Entity Details</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 87.0</p>
<ul>
<li><p>Improved case and alert synchronization logic by fixing the verification
handling of valid external ID values in the following job:</p>
<ul>
<li><strong>Google Chronicle Sync Job</strong></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Network Intelligence Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/network-intelligence-center/docs/connectivity-tests/concepts/overview">Connectivity Tests</a>
analyzes Proxy Network Load Balancers that are configured with
Server Name Indication (SNI) routing for TLS traffic.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 07, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_07_2026</id>
    <updated>2026-07-07T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_07_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">App Engine standard environment Java</h2>
<h3>Feature</h3>
<p>To modernize image processing, <a href="https://docs.cloud.google.com/appengine/migration-center/standard/java/images-to-cloud-run">migrate from the App Engine Images service to
Cloud Run</a> by
routing calls to a Cloud Run image transformation service while your app
continues to run on App Engine (Preview).</p>
<h2 class="release-note-product-title">App Engine standard environment Python</h2>
<h3>Feature</h3>
<p>To modernize image processing, <a href="https://docs.cloud.google.com/appengine/migration-center/standard/python/images-to-cloud-run">migrate from the App Engine Images service to
Cloud Run</a> by
routing calls to a Cloud Run image transformation service while your app
continues to run on App Engine (Preview).</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>You can bind existing <a href="https://docs.cloud.google.com/bigtable/docs/tags">tags</a> to Bigtable instances when you
create an instance and use policies to enforce mandatory tag assignments. This
feature is <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
For more information, see <a href="https://docs.cloud.google.com/bigtable/docs/creating-instance">Create an instance</a>.</p>
<h3>Feature</h3>
<p>The Bigtable agent skill (<code>bigtable-basics</code>) is
<a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>
in the public <a href="https://github.com/google/skills/tree/main/skills/cloud/bigtable-basics">Google Agent Skills repository</a>.
This skill lets you equip AI agents with capabilities for Bigtable tasks, such as
provisioning instances and tables, designing schemas, querying data using
GoogleSQL and key-value APIs, and diagnosing performance issues or hotspots.</p>
<h3>Feature</h3>
<p>You can use Organization Policy Service custom constraints to manage specific
operations on continuous materialized views. This feature is <a href="https://cloud.google.com/products#product-launch-stages">generally available
(GA)</a>.
For more information, see <a href="https://docs.cloud.google.com/bigtable/docs/custom-constraints">Use custom organization policies</a>.</p>
<h2 class="release-note-product-title">Cloud Key Management Service</h2>
<h3>Feature</h3>
<p>The Cloud KMS overview dashboard <strong>Asymmetric PQC insights</strong> chart is generally
available. You can use the <strong>Asymmetric PQC insights</strong> chart and details view to identify how many and which of your asymmetric keys are susceptible to attacks
from future quantum computers. This information is an important input into your
quantum computing modernization planning and process.</p>
<p>For more information about the <strong>Asymmetric PQC insights</strong> chart, see <a href="https://docs.cloud.google.com/kms/docs/view-pqc-insights">View
asymmetric post-quantum cryptography (PQC)
insights</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Managed organization policy constraints for data connectors (GA)</strong></p>
<p>You can use managed organization policy constraints to secure and control
your data connectors in Gemini Enterprise.</p>
<p>With this release, the following constraints are generally available (GA):</p>
<ul>
<li><strong>Restrict allowed data sources</strong>: Use this policy to control which
external data sources (such as Jira, Box, or Confluence) are permitted
when adding a data store. For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/configure-allowed-data-sources">Configure allowed data sources</a>.</li>
<li><strong>Restrict allowed egress FQDNs</strong>: Use this policy to control the egress
fully qualified domain names (FQDNs) that your data stores can connect
to. For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/configure-allowed-egress-fqdns">Configure allowed egress FQDNs for data stores</a>.</li>
</ul>
<p>For an overview of these policies and how they interact, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/managed-policy-constraints-overview">Overview of managed policy constraints</a>.</p>
<h2 class="release-note-product-title">Google Cloud Managed Service for Apache Kafka</h2>
<h3>Feature</h3>
<p>Managed Service for Apache Kafka now supports topic compression with <code>zstd</code>.</p>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Feature</h3>
<p>Custom organization policy constraints are generally available (GA) for Google Cloud VMware Engine.
You can use custom constraints to enforce security policies and restrict configuration of your VMware Engine resources.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/vmware-engine/docs/custom-constraints">Use custom organization policies</a>.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>In GKE version 1.34 and later, you can configure Google Cloud Managed Service
for Prometheus to collect Pressure Stall Information (PSI) metrics from
cAdvisor. You can use PSI metrics to monitor CPU, memory, and I/O congestion and
stall times for your containers, Pods, and nodes. For more information, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/collect-specific-prometheus-metrics">Collect specific Prometheus metrics from Kubernetes</a>.</p>
<h3>Feature</h3>
<p>In GKE version 1.35.3-gke.1389000 and later, you can run GPU workloads on
Confidential GKE Nodes with certain G4 machine types and NVIDIA RTX PRO 6000
GPUs. This feature is available in Preview. For more information, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/gpus-confidential-nodes">Encrypt GPU workload data in use with Confidential GKE Nodes</a>.</p>
<h3>Feature</h3>
<p>In GKE version 1.36.0-gke.1601000 and later, you can enable the logging of
VerticalPodAutoscaler decisions in Cloud Logging. You can use these logs to
understand why specific vertical Pod autoscaling decisions were made. This
feature is available in Preview. For more information, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/view-vertical-pod-autoscaling-events">Collect vertical Pod autoscaler event logs</a>.</p>
<h3>Feature</h3>
<p>GKE Gateway now supports backend mutual TLS (mTLS). In addition to backend authenticated TLS, backend mTLS allows the GKE Gateway load balancer to authenticate its identity to backend Pods by presenting a client certificate. GKE Gateway configures backend mTLS using the standard Gateway API <code>spec.tls.backend.clientCertificateRef</code> field.</p>
<p>This feature is supported for the following GatewayClasses:</p>
<ul>
<li><code>gke-l7-global-external-managed</code></li>
<li><code>gke-l7-regional-external-managed</code></li>
<li><code>gke-l7-rilb</code></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/secure-gateway#configure-backend-mtls">Configure backend mutual TLS (mTLS) for a Gateway</a>.</p>
<h3>Change</h3>
<p>For GKE Standard clusters, the maximum number of nodes that you can upgrade
simultaneously by using surge upgrades (<code>maxSurge</code> + <code>maxUnavailable</code>) is now
100. Each of these settings can be set as high as 100, but their sum can be no
higher than 100. For more information, see
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/node-pool-upgrade-strategies#surge">Surge upgrades</a>.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Feature</h3>
<p><strong>SOAR migration to Google Cloud validation status</strong></p>
<p>You can now check if the SOAR migration was successful by going to the <strong>SOAR Settings &gt; License Management</strong> page.
After successful completion of Stage 1, it will say <strong>Google.com</strong> after the system version number. 
After successful completion of Stage 2 of SOAR permissions to IAM roles, it will say both <strong>Google.com</strong> and <strong>CloudIAM Enabled</strong> after the system version number.</p>
<p>For more information on the migration, see the <a href="https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/migrate-to-gcp">SOAR migration guide</a></p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Feature</h3>
<p>When you delete a Looker (Google Cloud core) instance, it is now <a href="https://docs.cloud.google.com/looker/docs/looker-core-delete#instance-delete">moved to the trash</a> for seven days before being permanently deleted. During this period, you can <a href="https://docs.cloud.google.com/looker/docs/looker-core-delete#restore">restore the instance</a> to its previous state. After seven days, the instance is permanently deleted from the trash and cannot be recovered.</p>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-3">Airflow builds</a>
are available in Managed Airflow (Gen 3):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-3-1-7-build-13">composer-3-airflow-3.1.7-build.13</a></li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-11-1-build-9">composer-3-airflow-2.11.1-build.9</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-10-5-build-42">composer-3-airflow-2.10.5-build.42</a></li>
</ul>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-2">images</a>
are available in Managed Airflow (Gen 2):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-6-airflow-2-11-1">composer-2.17.6-airflow-2.11.1</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-6-airflow-2-10-5">composer-2.17.6-airflow-2.10.5</a></li>
</ul>
<h3>Deprecated</h3>
<p>The following Managed Airflow versions and builds have reached their
<a href="https://docs.cloud.google.com/composer/docs/composer-versioning-overview#version-deprecation-and-support">end of support period</a>:
composer-3-airflow-2.9.3-build.28, composer-3-airflow-2.10.5-build.0,
composer-3-airflow-2.10.5-build.2, composer-3-airflow-2.10.5-build.3,
composer-3-airflow-2.10.5-build.4, composer-3-airflow-2.10.5-build.5,
composer-3-airflow-2.10.5-build.6, composer-3-airflow-2.10.5-build.7,
composer-3-airflow-2.10.5-build.8, composer-2.13.6-airflow-2.9.3,
and composer-2.13.6-airflow-2.10.5.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 06, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#July_06_2026</id>
    <updated>2026-07-06T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#July_06_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Agent Platform Workbench</h2>
<h3>Feature</h3>
<p><strong>Agent Platform Workbench image release</strong></p>
<p>The following Agent Platform Workbench instances image release is available:</p>
<ul>
<li><strong>20260701-2130-rc0 (<code>workbench-instances-2603</code> - Debian 12)</strong>
<ul>
<li>Installed latest packages from upstream dependencies.</li>
<li>Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances.</li>
<li>Fixed an issue where long-running requests (for example, streaming or long-poll connections) could be terminated after about 60 seconds.</li>
</ul></li>
</ul>
<h3>Change</h3>
<h3 id="20260701-2130-rc0_release">20260701-2130-rc0 Release</h3>
<h3>Change</h3>
<p>Installed latest packages from upstream dependencies.</p>
<h3>Fixed</h3>
<p>Fixed a race condition that could cause JupyterLab to be unreachable (HTTP 524) on GPU instances.</p>
<h3>Fixed</h3>
<p>Fixed an issue where long-running requests (for example, streaming or long-poll connections) could be terminated after about 60 seconds.</p>
<h2 class="release-note-product-title">Apigee UI</h2>
<h3>Announcement</h3>
<p>On July 6, 2026, we released an updated version of the Apigee UI.</p>
<h3>Feature</h3>
<p><strong>ParsePayload policy and payload operations matching in the Apigee UI</strong></p>
<p>The Apigee UI now supports the new payload operations matching feature:</p>
<ul>
<li>The new <strong>ParsePayload</strong> policy is now available in the proxy editor for API
proxy authoring. You can use it to extract logical operations from
structured payloads at runtime.</li>
<li>The API Product page now displays payload-based operations, allowing you to
configure and manage access control and quotas based on request payload
content.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/apigee/docs/api-platform/apigee-mcp/manage-mcp-tool-access">Manage MCP tool access with API
products</a>.</p>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Feature</h3>
<p><strong>Support for payload operations matching in API Products</strong></p>
<p>Apigee now supports payload operations matching (<code>payloadOperationGroup</code>) in API
Products, powered by the new <strong>ParsePayload</strong> policy.</p>
<p>Payload operations matching allows you to define API Product operations that
match fields within request payloads, such as JSON-RPC requests used by the
Model Context Protocol (MCP). Apigee can then route, monetize, authorize, and
apply distinct quota limits to traffic based on the derived payload operation.</p>
<p>This feature is available to all Apigee X customers in all supported regions
with no additional charge. For more information, see <a href="https://docs.cloud.google.com/apigee/docs/api-platform/apigee-mcp/manage-mcp-tool-access">Manage MCP tool access
with API products</a>
and the <a href="https://docs.cloud.google.com/apigee/docs/api-platform/reference/policies/parse-payload-policy">ParsePayload policy
reference</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Change</h3>
<p>For <a href="https://docs.cloud.google.com/bigquery/docs/facebook-ads-transfer">data transfers from Facebook Ads</a>,
support for the <code>AdInsightsMMM</code> report has been temporarily disabled. Existing
data transfers from Facebook Ads that include the <code>AdInsightsMMM</code> report will
continue to run, but the transfer won't include data from the <code>AdInsightsMMM</code>
report.</p>
<p>This change is due to schema changes in the Facebook Ads API.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/bigquery/docs/transfer-changes#Jul06-fb-ads">July 06, 2026</a>.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>Bigtable supports direct connectivity, which bypasses the Google frontend and
optimizes performance for application traffic that meets certain criteria. For
more information, see <a href="https://docs.cloud.google.com/bigtable/docs/performance#direct-connectivity">Direct connectivity</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility#typegoogleapiscomenvoyextensionsfiltershttpcompressorv3compressor">Envoy Compressor Filter</a>
is now GA in the regular release channel.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility#typegoogleapiscomenvoyextensionsfiltershttpluav3lua">Envoy Lua Filter</a>
is now available as a preview feature in the regular release channel.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-125-19216-532-3_">cos-125-19216-532-3 <a id='"cos-arm64-125-19216-532-3"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/68df3c124b6c1b28325aae6b20030bd6d4e87f2c
">COS-6.12.94</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.532.3/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-admin/oslogin to v20260626.00.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.8.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.53.3.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.8.2.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35388 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-40226 in sys-apps/systemd.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-52921 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-52927 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-52930 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-52942 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53122 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53134 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53154 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53156 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53168 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53180 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53181 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53184 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53189 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53191 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53199 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53207 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53212 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53218 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53219 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53220 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53223 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53229 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53230 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53232 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53233 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53236 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53239 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53249 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53264 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53265 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53266 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53267 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53268 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53269 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53270 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53275 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-129-19506-299-3_">cos-129-19506-299-3 <a id='"cos-arm64-129-19506-299-3"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/a9a6e2d52bec1f807503b02b401205a67f642d04
">COS-6.12.94</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.299.3/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.94.  It resolves CVE-2026-52908,CVE-2026-52910, CVE-2026-52912,CVE-2026-52920, CVE-2026-52921,CVE-2026-52923, CVE-2026-52925,CVE-2026-52927,CVE-2026-52928,CVE-2026-52930, CVE-2026-52933,CVE-2026-52936, CVE-2026-52942,CVE-2026-52943, CVE-2026-52946,CVE-2026-52967, CVE-2026-52969,CVE-2026-52970, CVE-2026-52972,CVE-2026-52974, CVE-2026-52977,CVE-2026-52980, CVE-2026-52981,CVE-2026-52984, CVE-2026-52986,CVE-2026-52989, CVE-2026-52990,CVE-2026-52998, CVE-2026-52999,CVE-2026-53001, CVE-2026-53002,CVE-2026-53003, CVE-2026-53006,CVE-2026-53012, CVE-2026-53013,CVE-2026-53014, CVE-2026-53021,CVE-2026-53023, CVE-2026-53031,CVE-2026-53032, CVE-2026-53033,CVE-2026-53034, CVE-2026-53035,CVE-2026-53036, CVE-2026-53038,CVE-2026-53050, CVE-2026-53053,CVE-2026-53060, CVE-2026-53061,CVE-2026-53062, CVE-2026-53063,CVE-2026-53064, CVE-2026-53069,CVE-2026-53074, CVE-2026-53075,CVE-2026-53076, CVE-2026-53080,CVE-2026-53081, CVE-2026-53083,CVE-2026-53084, CVE-2026-53085,CVE-2026-53094, CVE-2026-53096,CVE-2026-53111, CVE-2026-53115,CVE-2026-53120, CVE-2026-53122,CVE-2026-53123, CVE-2026-53126,CVE-2026-53129, CVE-2026-53132.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.94. It resolves CVE-2026-52908,CVE-2026-52910, CVE-2026-52912,CVE-2026-52920, CVE-2026-52921,CVE-2026-52923, CVE-2026-52925,CVE-2026-52927, CVE-2026-52928,CVE-2026-52930, CVE-2026-52933,CVE-2026-52936, CVE-2026-52942,CVE-2026-52943, CVE-2026-52945,CVE-2026-52946, CVE-2026-52967,CVE-2026-52969, CVE-2026-52970,CVE-2026-52972, CVE-2026-52974,CVE-2026-52977, CVE-2026-52980,CVE-2026-52981, CVE-2026-52984,CVE-2026-52986, CVE-2026-52989,CVE-2026-52990, CVE-2026-52998,CVE-2026-52999, CVE-2026-53001,CVE-2026-53002, CVE-2026-53003,CVE-2026-53006, CVE-2026-53012,CVE-2026-53013, CVE-2026-53014,CVE-2026-53021, CVE-2026-53023,CVE-2026-53031, CVE-2026-53032,CVE-2026-53033, CVE-2026-53034,CVE-2026-53035, CVE-2026-53036,CVE-2026-53038, CVE-2026-53050,CVE-2026-53053, CVE-2026-53060,CVE-2026-53061, CVE-2026-53062,CVE-2026-53063, CVE-2026-53064,CVE-2026-53069, CVE-2026-53074,CVE-2026-53075, CVE-2026-53076,CVE-2026-53080, CVE-2026-53081,CVE-2026-53083, CVE-2026-53084,CVE-2026-53085, CVE-2026-53094,CVE-2026-53096, CVE-2026-53111,CVE-2026-53115, CVE-2026-53120,CVE-2026-53122, CVE-2026-53123,CVE-2026-53126, CVE-2026-53129,CVE-2026-53132.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/oslogin to v20260626.00.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.53.3.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.8.2.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/acl to v2.4.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35388 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-40226 in sys-apps/systemd.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53122 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53134 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53154 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53156 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53168 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53180 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53181 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53184 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53189 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53191 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53199 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53212 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53218 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53219 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53220 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53223 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53229 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53230 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53232 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53235 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53236 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53239 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53249 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53261 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53264 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53265 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53266 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53267 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53268 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53269 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53270 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53275 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-528-3_">cos-121-18867-528-3 <a id='"cos-arm64-121-18867-528-3"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3a060df9faaaa8e9287e2cd1687a14f35fd7b44a
">COS-6.6.143</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.528.3/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Upgraded net-misc/rsync to v3.4.4.</p>
<h3>Change</h3>
<p>Upgraded the Linux kernel to v6.6.143. Is resolves CVE-2026-52908,CVE-2026-52910, CVE-2026-52912,CVE-2026-52920, CVE-2026-52921,CVE-2026-52923, CVE-2026-52925,CVE-2026-52927, CVE-2026-52928,CVE-2026-52930, CVE-2026-52933,CVE-2026-52936, CVE-2026-52942,CVE-2026-52943, CVE-2026-52945,CVE-2026-52946, CVE-2026-52967,CVE-2026-52969, CVE-2026-52970,CVE-2026-52972, CVE-2026-52974,CVE-2026-52975, CVE-2026-52977,CVE-2026-52981, CVE-2026-52984,CVE-2026-52986, CVE-2026-52989,CVE-2026-52998, CVE-2026-52999,CVE-2026-53001, CVE-2026-53002,CVE-2026-53003, CVE-2026-53006,CVE-2026-53012, CVE-2026-53013,CVE-2026-53021, CVE-2026-53032,CVE-2026-53033, CVE-2026-53034,CVE-2026-53035, CVE-2026-53036,CVE-2026-53050, CVE-2026-53060,CVE-2026-53061, CVE-2026-53062,CVE-2026-53063, CVE-2026-53064,CVE-2026-53069, CVE-2026-53074,CVE-2026-53075, CVE-2026-53076,CVE-2026-53080, CVE-2026-53083,CVE-2026-53094, CVE-2026-53096,CVE-2026-53111, CVE-2026-53126.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.8.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.53.3.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.8.2.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libtirpc to v1.3.7-r2.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/acl to v2.4.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31419 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35388 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-40226 in sys-apps/systemd.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-52936 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53134 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53154 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53168 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53181 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53184 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53189 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53199 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53212 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53218 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53219 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53223 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53230 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53232 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53236 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53239 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53249 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53264 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53266 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53267 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53268 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53269 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53270 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53275 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-675-2_">cos-117-18613-675-2 <a id='"cos-arm64-117-18613-675-2"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/5fdd1e8b9c34a017086bbcb058f5532b3c0298d9
">COS-6.6.143</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.675.2/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Upgraded net-misc/rsync to v3.4.4.</p>
<h3>Change</h3>
<p>Upgraded the Linux kernel to v6.6.143. It resolves CVE-2026-52908,CVE-2026-52910, CVE-2026-52912,CVE-2026-52920, CVE-2026-52921,CVE-2026-52923, CVE-2026-52925,CVE-2026-52927, CVE-2026-52928,CVE-2026-52930, CVE-2026-52933,CVE-2026-52936, CVE-2026-52942,CVE-2026-52943, CVE-2026-52945,CVE-2026-52946, CVE-2026-52967,CVE-2026-52969, CVE-2026-52970,CVE-2026-52972, CVE-2026-52974,CVE-2026-52975, CVE-2026-52977,CVE-2026-52981, CVE-2026-52984,CVE-2026-52986, CVE-2026-52989,CVE-2026-52998, CVE-2026-52999,CVE-2026-53001, CVE-2026-53002,CVE-2026-53003, CVE-2026-53006,CVE-2026-53012, CVE-2026-53013,CVE-2026-53021, CVE-2026-53032,CVE-2026-53033, CVE-2026-53034,CVE-2026-53035, CVE-2026-53036,CVE-2026-53050, CVE-2026-53060,CVE-2026-53061, CVE-2026-53062,CVE-2026-53063, CVE-2026-53064,CVE-2026-53069, CVE-2026-53074,CVE-2026-53075, CVE-2026-53076,CVE-2026-53080, CVE-2026-53083,CVE-2026-53094, CVE-2026-53096,CVE-2026-53111, CVE-2026-53126.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4-r2.</p>
<h3>Fixed</h3>
<p>Upgraded net-fs/cifs-utils to v7.6, Upgraded sys-libs/talloc to v2.4.4-r1.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35388 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-40226 in sys-apps/systemd.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-52930 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53134 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53154 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53168 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53181 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53184 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53189 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53199 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53212 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53218 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53219 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53223 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53230 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53232 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53236 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53249 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53264 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53265 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53266 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53267 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53268 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53269 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53270 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-53275 in the Linux kernel.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Support for Japan and UK regions (GA with allowlist)</strong></p>
<p>You can use the Gemini Enterprise app in the Japan (<code>asia-northeast1</code>) and
United Kingdom (<code>europe-west2</code>) regions with at-rest data residency (DRZ)
and machine learning processing (MLP) in region. You can also use the
latest Gemini 3.5 Flash model in these regions with in-region at-rest DRZ
and MLP.</p>
<p>These locations are available in GA with allowlist. To get access to these
locations for use with Gemini Enterprise or NotebookLM Enterprise,
contact your Google account team.</p>
<p>Certain limitations apply when using these regions. For more information,
see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/locations">Data residency for Gemini Enterprise Standard and Plus Editions</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>AlphaGenome released for Gemini Enterprise Agent Platform</strong></p>
<p>AlphaGenome, Google DeepMind's state-of-the-art genomics foundation model, is
now available for deployment and use with Gemini Enterprise Agent Platform.</p>
<p>Designed to decipher the functional regulatory code of the human genome,
AlphaGenome analyzes large-scale DNA sequences at single-base resolution to
predict how genetic variations affect molecular and biological mechanisms like
gene expression, chromatin accessibility, and RNA splicing. For information on
how to use AlphaGenome in Agent Platform, see the
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/open-models/alphagenome">documentation</a>.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>Data RBAC for first-party (1P) cases and alerts in public preview</strong></p>
<p><strong>Availability:</strong> This feature is available <strong>only in the following regions:</strong> europe-central2, asia-northeast1, asia-south1, australia-southeast1, northamerica-northeast2, europe-west3, europe-west6, southamerica-east1, asia-southeast1, me-central1, me-central2, me-west1, europe-west2, europe-west9, europe-west12, asia-southeast2, africa-south1, asia-east1, and asia-northeast3.</p>
<p>Google SecOps now supports data role-based access control (Data RBAC) for first-party (1P) cases and alerts in SOAR. This feature automatically applies SIEM data access scopes to alerts and cases ingested using the Chronicle connector, ensuring analysts only see data they are authorized to access.</p>
<p><strong>Key highlights</strong></p>
<ul>
<li><strong>SIEM-scope-to-SOAR inheritance:</strong> Ingested 1P SIEM alerts carry their assigned data access scopes, which are automatically inherited by their parent SOAR cases.</li>
<li><strong>Dual access enforcement:</strong> To view a case or alert, users must have access to both the assigned SOAR environment and all associated data access scopes. Global users maintain full visibility.</li>
<li><strong>Scope-to-environment mapping:</strong> Administrators can map SIEM data access scopes to SOAR environments (<strong>SOAR settings &gt; Environments</strong>) to manage alert routing and grouping. Alerts without mapped scopes are routed to a fallback environment.</li>
<li><strong>Enhanced UI visibility and filtering:</strong> Assigned data access scopes are visible next to the environment in the <strong>Case header</strong> and the <strong>List cases</strong> table, allowing for easy filtering.</li>
<li><strong>Manual case and grouping logic:</strong> When creating cases manually, analysts can only select from the intersection of their permitted data access scopes and environment mappings.</li>
</ul>
<p><strong>Prerequisites and enablement</strong></p>
<ul>
<li>Requires a unified Google SecOps instance with the <strong>Chronicle connector</strong> using the modern Chronicle API.</li>
<li>Administrators can enable this feature under <strong>SIEM settings &gt; Data access</strong> by selecting <strong>Enforce data access in SOAR</strong> (or <strong>Enforce data access</strong> if SIEM data access is not yet active).</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/administration/datarbac-impact-cases">Control access to 1P cases and alerts</a>.</p>
<h2 class="release-note-product-title">Spanner</h2>
<h3>Feature</h3>
<p>You can use Gemini in Spanner Studio to fix errors in your SQL
queries. When you run a query that contains an error, you can click <strong>Fix</strong> to
view a line-by-line comparison of your query and a recommended correction, along
with an explanation of the change. This feature is available in
<a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
]]>
    </content>
  </entry>

</feed>
