Release note filtrate e modellate per automatismi IaC β ordine cronologico, piΓΉ recenti in cima:
General Availability: Cloud NAT gateways for Private NAT support IPv6 to IPv4 network address translation. For more information, see NAT64 in Private NAT.
Network Connectivity Center supports site-to-site data transfer in the following country:
Network Services Monitoring is available in Preview.
Network Services Monitoring visualizes communication paths and network metrics for Google Kubernetes Engine services and workloads with ambient networking enabled.
Cloud Network Insights supports using Google Cloud CLI commands to download Microsoft Azure and Amazon Web Services (AWS) Monitoring Point installation bundles.
VPC Service Controls feature: Support for using Google Cloud folders and organizations as resources in ingress and egress rules is generally available.
With this update, you can create rules that allow access to and from the resources protected by service perimeters and bypass common resource size limitations.
For more information, see Ingress and egress rules.
VPC Service Controls feature: Folder membership support in VPC Service Controls service perimeters is generally available. You can configure Google Cloud folders as members in service perimeters to automatically protect all projects and subfolders within that folder hierarchy.
For more information, see Folder support in service perimeters and Configure folders in service perimeters.
Preview stage support for the following integration:
A new quota system governing the configuration size of Application Load Balancers is now generally available. This update increases the individual URL map size limit from 64Β KB and 128Β KB to 1Β MB. For more information, see URL map size and quota units.
Key aspects of this feature include:
For more information on increasing your limit, please contact Google Cloud Support.
Network Connectivity Center (NCC) support for Partner Cross-Cloud Interconnect for Amazon Web Services (AWS) is Generally Available.
Billing for Partner Cross-Cloud Interconnect for Amazon Web Services (AWS) is going to commence over the next 30 days following General Availability. For the most current billing information, see Network Connectivity Center pricing.
Preview: Cloud NAT gateways for Private NAT support source-based NAT rules for IPv4 addresses.
Zonal network endpoint groups (NEGs) with GCE_VM_IP and GCE_VM_IP_PORT
endpoints support IPv6-only endpoints that reference IPv6-only or dual-stack
Compute Engine VM network interfaces.
This feature is available in Preview.
For more information, see Zonal network endpoint groups overview.
Cloud Service Mesh support for the in-cluster ISTIOD control plane on Google
Kubernetes Engine (GKE) on Google Cloud is deprecated as of September 28, 2026,
and support will end on March 1, 2028. After March 1, 2028, in-cluster
control plane components on GKE will not receive updates, security patches, or
support from Google Cloud.
Cloud Service Mesh with the in-cluster ISTIOD control plane on Google
Distributed Cloud (software only) continues to be supported as described in
Supported platforms.
You must migrate your clusters to managed Cloud Service Mesh by March 1, 2028.
review the Supported features
to confirm feature compatibility, and follow the
migration guide
to transition to managed Cloud Service Mesh with the TRAFFIC_DIRECTOR control
plane.
For more details on the deprecation schedule, see Deprecations.
Cloud Service Mesh support for the managed ISTIOD control plane on Google
Kubernetes Engine (GKE) on Google Cloud is deprecated as of September 28, 2026,
and support will end on March 1, 2028. After March 1, 2028, managed ISTIOD
control plane components on GKE on Google Cloud will not receive updates,
security patches, or support from Google Cloud, and workload sidecars on
unmodernized clusters will fail and be unable to receive or send requests.
Google Cloud is transitioning managed Cloud Service Mesh with Istio APIs to the
TRAFFIC_DIRECTOR control plane implementation using Istio APIs. As part of
this transition, support will also end for any features that are incompatible
with the TRAFFIC_DIRECTOR control plane.
To continue using managed Cloud Service Mesh on GKE, you must modernize your clusters by March 1, 2028:
TRAFFIC_DIRECTOR control plane
and evaluate a fleet's compatibility for control plane modernization.For more details on the transition, see Managed control plane documentation and monitor the release notes for ongoing updates.
GKE ambient networking is now available in Preview through an allowlist.
GKE ambient networking provides a simplified, sidecarless deployment model for a service mesh with Layer 4 capabilities. By moving proxy functionality to node-level components integrated into GKE Dataplane V2, ambient networking reduces resource overhead, eliminates workload restarts for proxy updates, and simplifies mesh lifecycle management.
The Preview release supports single-cluster Layer 4 mesh capabilities using the Gateway API, which includes mutual TLS (mTLS), service discovery, Layer 4 traffic management, and Layer 4 telemetry.
For more information, see Ambient networking overview and Prepare GKE ambient networking.
GKE ambient networking is now available in Preview through an allowlist.
GKE ambient networking provides a simplified, sidecarless deployment model for a service mesh with Layer 4 capabilities. By moving proxy functionality to node-level components integrated into GKE Dataplane V2, ambient networking reduces resource overhead, eliminates workload restarts for proxy updates, and simplifies mesh lifecycle management.
The Preview release supports single-cluster Layer 4 mesh capabilities using the Gateway API, which includes mutual TLS (mTLS), service discovery, Layer 4 traffic management, and Layer 4 telemetry.
For more information, see Ambient networking overview and Prepare GKE ambient networking.
Support for route and traffic extensions that use plugins is generally available (GA) for regional external Application Load Balancers and regional internal Application Load Balancers.
For more information, see Supported Application Load Balancers for user-managed extensions.
Support for route and traffic extensions that use plugins is generally available (GA) for regional external Application Load Balancers and regional internal Application Load Balancers.
For more information, see Supported Application Load Balancers for user-managed extensions.
1.30.4-asm.14 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.30.4-asm.14 uses Envoy v1.38.5-dev.
Patch 1.30.4-asm.14 contains the fix for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2022-31045 | Yes | Yes | Yes | Yes | Medium (9.8) |
| CVE-2026-5450 | No | No | Yes | No | Low (9.8) |
| CVE-2026-84304 | Yes | Yes | Yes | Yes | High (8.7) |
| CVE-2026-84445 | Yes | Yes | Yes | Yes | High (8.7) |
| CVE-2026-54371 | Yes | Yes | No | Yes | Medium (8.4) |
| CVE-2019-14993 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2021-39155 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2021-39156 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2022-23635 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-5928 | No | No | Yes | No | Low (7.5) |
| CVE-2026-59847 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-59850 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-59843 | Yes | Yes | No | Yes | Medium (6.5) |
| CVE-2026-84303 | Yes | Yes | Yes | Yes | Medium (6.3) |
| CVE-2026-13757 | Yes | Yes | No | Yes | Medium (6.2) |
| CVE-2026-18938 | Yes | Yes | No | Yes | Medium (6.2) |
| CVE-2024-2236 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-59845 | Yes | Yes | No | Yes | Medium (5.9) |
| CVE-2026-27171 | Yes | Yes | No | Yes | Low (5.5) |
| CVE-2026-13595 | Yes | Yes | No | Yes | Medium (5.3) |
| CVE-2026-59848 | Yes | Yes | No | Yes | Medium (5.3) |
| CVE-2025-6141 | Yes | Yes | No | Yes | Low (4.8) |
| CVE-2026-27456 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-5278 | Yes | Yes | No | Yes | Low (4.4) |
| CVE-2026-59846 | Yes | Yes | No | Yes | Medium (3.9) |
| CVE-2026-19499 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-19542 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-41990 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-42250 | Yes | Yes | No | Yes | Low (0.0) |
| CVE-2026-53612 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53613 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53614 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53615 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53910 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-57062 | Yes | Yes | No | Yes | Low (0.0) |
| CVE-2026-6368 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-6791 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-77117 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-80489 | Yes | Yes | No | Yes | Medium (0.0) |
1.29.7-asm.18 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.29.7-asm.18 uses Envoy v1.37.6.
Patch 1.29.7-asm.18 contains the fix for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2022-31045 | No | Yes | Yes | Yes | Medium (9.8) |
| CVE-2026-11856 | No | Yes | No | Yes | Medium (9.8) |
| CVE-2026-5450 | No | No | Yes | No | Low (9.8) |
| CVE-2026-57433 | No | Yes | No | Yes | Medium (9.8) |
| CVE-2026-12087 | No | Yes | No | Yes | Medium (9.1) |
| CVE-2026-13221 | No | Yes | No | Yes | Medium (9.1) |
| CVE-2026-75803 | No | Yes | No | Yes | Low (9.1) |
| CVE-2026-84304 | No | Yes | Yes | Yes | High (8.7) |
| CVE-2026-84445 | No | Yes | Yes | Yes | High (8.7) |
| CVE-2026-54371 | No | Yes | No | Yes | Medium (8.4) |
| CVE-2026-57432 | No | Yes | No | Yes | Medium (8.4) |
| CVE-2019-14993 | No | Yes | Yes | Yes | High (7.5) |
| CVE-2021-39155 | No | Yes | Yes | Yes | High (7.5) |
| CVE-2021-39156 | No | Yes | Yes | Yes | High (7.5) |
| CVE-2022-23635 | No | Yes | Yes | Yes | High (7.5) |
| CVE-2026-42151 | No | Yes | No | No | High (7.5) |
| CVE-2026-42154 | No | Yes | No | No | High (7.5) |
| CVE-2026-48959 | No | Yes | No | Yes | Medium (7.5) |
| CVE-2026-54874 | No | Yes | No | Yes | Low (7.5) |
| CVE-2026-5928 | No | No | Yes | No | Low (7.5) |
| CVE-2026-59847 | No | Yes | No | Yes | Medium (7.5) |
| CVE-2026-59850 | No | Yes | No | Yes | Medium (7.5) |
| CVE-2026-63072 | No | Yes | No | Yes | Medium (7.5) |
| CVE-2026-63076 | No | Yes | No | Yes | Medium (7.5) |
| CVE-2026-8932 | No | Yes | No | Yes | Low (7.5) |
| CVE-2026-9538 | No | Yes | No | Yes | Medium (7.5) |
| CVE-2026-48962 | No | Yes | No | Yes | Medium (7.3) |
| CVE-2026-7017 | No | Yes | No | Yes | Medium (7.1) |
| CVE-2026-59843 | No | Yes | No | Yes | Medium (6.5) |
| CVE-2026-84303 | No | Yes | Yes | Yes | Medium (6.3) |
| CVE-2026-13757 | No | Yes | No | Yes | Medium (6.2) |
| CVE-2026-18938 | No | Yes | No | Yes | Medium (6.2) |
| CVE-2026-40179 | No | Yes | No | No | Medium (6.1) |
| CVE-2026-44903 | No | Yes | No | No | Medium (6.1) |
| CVE-2024-2236 | No | Yes | No | Yes | Low (5.9) |
| CVE-2026-59845 | No | Yes | No | Yes | Medium (5.9) |
| CVE-2026-63074 | No | Yes | No | Yes | Low (5.9) |
| CVE-2025-15649 | No | Yes | No | Yes | Medium (5.5) |
| CVE-2026-27171 | No | Yes | No | Yes | Low (5.5) |
| CVE-2026-13595 | No | Yes | No | Yes | Medium (5.3) |
| CVE-2026-59848 | No | Yes | No | Yes | Medium (5.3) |
| CVE-2025-6141 | No | Yes | No | Yes | Low (4.8) |
| CVE-2026-27456 | No | Yes | No | Yes | Medium (4.7) |
| CVE-2025-5278 | No | Yes | No | Yes | Low (4.4) |
| CVE-2026-59846 | No | Yes | No | Yes | Medium (3.9) |
| CVE-2026-19499 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-19542 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-41990 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-42250 | No | Yes | No | Yes | Low (0.0) |
| CVE-2026-53612 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53613 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53614 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53615 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53910 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-57062 | No | Yes | No | Yes | Low (0.0) |
| CVE-2026-6368 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-6791 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-77117 | No | Yes | No | Yes | Medium (0.0) |
| CVE-2026-80489 | No | Yes | No | Yes | Medium (0.0) |
1.28.10-asm.40 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.10-asm.40 uses Envoy v1.36.10-dev.
Patch 1.28.10-asm.40 contains the fix for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2022-31045 | Yes | Yes | Yes | Yes | Medium (9.8) |
| CVE-2026-11856 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-5450 | No | No | Yes | No | Low (9.8) |
| CVE-2026-57433 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-12087 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-13221 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-75803 | Yes | Yes | No | Yes | Low (9.1) |
| CVE-2026-84304 | Yes | Yes | Yes | Yes | High (8.7) |
| CVE-2026-84445 | Yes | Yes | Yes | Yes | High (8.7) |
| CVE-2026-54371 | Yes | Yes | No | Yes | Medium (8.4) |
| CVE-2026-57432 | Yes | Yes | No | Yes | Medium (8.4) |
| CVE-2019-14993 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2021-39155 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2021-39156 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2022-23635 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-42151 | No | Yes | No | No | High (7.5) |
| CVE-2026-42154 | No | Yes | No | No | High (7.5) |
| CVE-2026-48959 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-54874 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-5928 | No | No | Yes | No | Low (7.5) |
| CVE-2026-59847 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-59850 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-63072 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-63076 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-8932 | Yes | Yes | No | Yes | Low (7.5) |
| CVE-2026-9538 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-48962 | Yes | Yes | No | Yes | Medium (7.3) |
| CVE-2026-7017 | Yes | Yes | No | Yes | Medium (7.1) |
| CVE-2026-59843 | Yes | Yes | No | Yes | Medium (6.5) |
| CVE-2026-84303 | Yes | Yes | Yes | Yes | Medium (6.3) |
| CVE-2026-13757 | Yes | Yes | No | Yes | Medium (6.2) |
| CVE-2026-18938 | Yes | Yes | No | Yes | Medium (6.2) |
| CVE-2026-40179 | No | Yes | No | No | Medium (6.1) |
| CVE-2026-44903 | No | Yes | No | No | Medium (6.1) |
| CVE-2024-2236 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2026-59845 | Yes | Yes | No | Yes | Medium (5.9) |
| CVE-2026-63074 | Yes | Yes | No | Yes | Low (5.9) |
| CVE-2025-15649 | Yes | Yes | No | Yes | Medium (5.5) |
| CVE-2026-27171 | Yes | Yes | No | Yes | Low (5.5) |
| CVE-2026-13595 | Yes | Yes | No | Yes | Medium (5.3) |
| CVE-2026-59848 | Yes | Yes | No | Yes | Medium (5.3) |
| CVE-2025-6141 | Yes | Yes | No | Yes | Low (4.8) |
| CVE-2026-27456 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-5278 | Yes | Yes | No | Yes | Low (4.4) |
| CVE-2026-59846 | Yes | Yes | No | Yes | Medium (3.9) |
| CVE-2026-19499 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-19542 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-41990 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-42250 | Yes | Yes | No | Yes | Low (0.0) |
| CVE-2026-53612 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53613 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53614 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53615 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-53910 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-57062 | Yes | Yes | No | Yes | Low (0.0) |
| CVE-2026-6368 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-6791 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-77117 | Yes | Yes | No | Yes | Medium (0.0) |
| CVE-2026-80489 | Yes | Yes | No | Yes | Medium (0.0) |
| GHSA-gcjh-h69q-9w9g | No | Yes | No | No | Medium (0.0) |
You can now use Cloud NGFW Enterprise advanced threat prevention with cross-region internal Application Load Balancers (Preview).
You can configure global network firewall policies with security profile groups to inspect incoming traffic targeting load balancer forwarding rules. This integration supports intrusion detection and prevention service and Advanced malware sandbox (WildFire) to protect workloads and backends.
For more information, see Supported load balancers. This feature is available in Preview.
Connectivity Tests analyzes firewall policy rules that use Google Threat Intelligence data.
Connectivity Tests analyzes firewall policy rules that use Google Threat Intelligence data.
Managed workload identity for backend mTLS is generally available for the following Application Load Balancers:
The key benefits are as follows:
Streamline certificate management: Automated certificate and trust management for backend mTLS through seamless integration with Certificate Authority Service and Certificate Manager.
Eliminate operational toil: Certificates are automatically rotated based on the workload identity pool's configuration, removing the complexity and manual bottleneck of private key provisioning and maintenance.
Improve visibility and governance: Gain visibility into communication between distributed services and proactively apply governance to workloads across environments.
For more information, see Backend mTLS with managed workload identity overview
Managed workload identity for backend mTLS is generally available for the following Application Load Balancers:
The key benefits are as follows:
Streamline certificate management: Automated certificate and trust management for backend mTLS through seamless integration with Certificate Authority Service and Certificate Manager.
Eliminate operational toil: Certificates are automatically rotated based on the workload identity pool's configuration, removing the complexity and manual bottleneck of private key provisioning and maintenance.
Improve visibility and governance: Gain visibility into communication between distributed services and proactively apply governance to workloads across environments.
For more information, see Backend mTLS with managed workload identity overview
Cloud Armor managed rulesets protect your backend services and APIs from a wide range of web application threats using threat signatures which are automatically kept up-to-date. For more information, see Managed rules overview. This feature is available in Preview.
Secure Web Proxy now supports distributed tracing by integrating with Cloud Trace. With distributed tracing, you can track the lifecycle of outbound requests from internal workloads through your Secure Web Proxy gateways to external endpoints. This integration helps you detect latency bottlenecks and troubleshoot connectivity errors.
This feature is available in Preview.
Secure Web Proxy now supports distributed tracing by integrating with Cloud Trace. With distributed tracing, you can track the lifecycle of outbound requests from internal workloads through your Secure Web Proxy gateways to external endpoints. This integration helps you detect latency bottlenecks and troubleshoot connectivity errors.
This feature is available in Preview.
Cloud Armor managed rulesets protect your backend services and APIs from a wide range of web application threats using threat signatures which are automatically kept up-to-date. For more information, see Managed rules overview. This feature is available in Preview.
General Availability: You can add Dynamic NICs to the same VPC network used by other network interfaces of a Compute Engine instance. For more information, see Multiple network interfaces.
General Availability: VPC Flow Logs supports logging for App Engine resources that are configured with Direct VPC egress. For more information, see Serverless flows and ServerlessDetails field format.
General Availability: VPC Flow Logs adds the following metadata annotations for Private Service Connect:
src_psc_interface and dest_psc_interfacepsc.consumer_connectionpsc.psc_endpoint.namepsc.psc_attachment.nameFor more information, see Record format.
General Availability: You can add Dynamic NICs to the same VPC network used by other network interfaces of a Compute Engine instance. For more information, see Multiple network interfaces.
General Availability: VPC Flow Logs supports logging for App Engine resources that are configured with Direct VPC egress. For more information, see Serverless flows and ServerlessDetails field format.
General Availability: VPC Flow Logs adds the following metadata annotations for Private Service Connect:
src_psc_interface and dest_psc_interfacepsc.consumer_connectionpsc.psc_endpoint.namepsc.psc_attachment.nameFor more information, see Record format.
When adding a new Google Cloud Compute Engine, container, or VM Monitoring Point, Cloud Network Insights lets you generate Google Cloud CLI commands in the Google Cloud console to download Monitoring Point installation bundles.
When adding a new Google Cloud Compute Engine, container, or VM Monitoring Point, Cloud Network Insights lets you generate Google Cloud CLI commands in the Google Cloud console to download Monitoring Point installation bundles.
Support for global Google APIs for endpoint propagation through Network Connectivity Center is available in Preview.
For information about the new quota for propagated global Google APIs, see NCC quotas.
Preview: Propagated connections support Private Service Connect endpoints that access global Google APIs. With propagated connections, endpoints that access global Google APIs in one consumer VPC spoke can be privately accessed by other consumer VPC spokes that are connected to the same Network Connectivity Center hub.
You can deploy Monitoring Points optimized for Amazon Web Services (AWS) or Microsoft Azure cloud infrastructure from Cloud Network Insights.
You can deploy Monitoring Points optimized for Amazon Web Services (AWS) or Microsoft Azure cloud infrastructure from Cloud Network Insights.
GKE version 1.35.1-gke.1031000 and later include the following changes to automatically created firewall rules for Services:
1000 to 999.If you use custom firewall rules to override GKE firewall rules for Services, these changes might cause unexpected behavior. Before you upgrade your clusters to version 1.35.1-gke.1031000 or later, do the following:
1000, change the priority of those rules to a numerically lower value (such as 999 or lower) to maintain their precedence.The bare metal machine types from the C3 machine
series are now generally
available with GKE clusters. You can now provision machine types such as
c3-standard-192-metal in Standard mode with any available GKE version.
To use these machine types with Autopilot mode, ComputeClasses, and node pool auto-creation, you must specify the exact machine type using a custom ComputeClass and use GKE version 1.35.3-gke.1389000 or later.
GKE version 1.35.1-gke.1031000 and later include the following changes to automatically created firewall rules for Services:
1000 to 999.If you use custom firewall rules to override GKE firewall rules for Services, these changes might cause unexpected behavior. Before you upgrade your clusters to version 1.35.1-gke.1031000 or later, do the following:
1000, change the priority of those rules to a numerically lower value (such as 999 or lower) to maintain their precedence.The bare metal machine types from the C3 machine
series are now generally
available with GKE clusters. You can now provision machine types such as
c3-standard-192-metal in Standard mode with any available GKE version.
To use these machine types with Autopilot mode, ComputeClasses, and node pool auto-creation, you must specify the exact machine type using a custom ComputeClass and use GKE version 1.35.3-gke.1389000 or later.
Managed Cloud Service Mesh will start using proxy version csm_mesh_proxy.20260819_RC00 for Gateway API on GKE clusters. This proxy version maps closest to Envoy version 1.37. This change is rolling out to all release channels and contains the fix for the managed Cloud Service Mesh security vulnerabilities listed in GCP-2026-057.
General Availability: You can create Compute Engine instances that have multiple virtual network interfaces (vNICs) in the same VPC network. For more information, see Multiple network interfaces in the same VPC network.
General Availability: You can create Compute Engine instances that have multiple virtual network interfaces (vNICs) in the same VPC network. For more information, see Multiple network interfaces in the same VPC network.
Session affinity support using GCPTrafficDistributionPolicy for GKE Gateway is generally available. This release currently supports single-cluster GKE Gateway load balancers using the following GatewayClasses:
gke-l7-rilbgke-l7-regional-external-managedgke-l7-global-external-managedIn addition to the session affinity types available in Preview, you can now use
the STRONG_COOKIE_AFFINITY type, which provides the most persistent session
stickiness among the session affinity types available in Google Cloud
Application Load Balancers.
The session affinity types require the following minimum GKE versions:
CLIENT_IP, HEADER_FIELD, GENERATED_COOKIE, and HTTP_COOKIE:
version 1.35.2-gke.1269001 or laterSTRONG_COOKIE_AFFINITY: version 1.36.3-gke.1767000 or laterFor more information, see Configure session affinity using GCPTrafficDistributionPolicy.
IPv6 dynamic routes support for include and exclude spoke filters for hybrid spokes is available in Preview.
Export filters control which subnets or routes a spoke can send to the hub. Import filters control which subnets or routes can be accepted by a spoke from the hub.
IPv6 dynamic routes support for include and exclude spoke filters for hybrid spokes is available in Preview.
Export filters control which subnets or routes a spoke can send to the hub. Import filters control which subnets or routes can be accepted by a spoke from the hub.
Session affinity support using GCPTrafficDistributionPolicy for GKE Gateway is generally available. This release currently supports single-cluster GKE Gateway load balancers using the following GatewayClasses:
gke-l7-rilbgke-l7-regional-external-managedgke-l7-global-external-managedIn addition to the session affinity types available in Preview, you can now use
the STRONG_COOKIE_AFFINITY type, which provides the most persistent session
stickiness among the session affinity types available in Google Cloud
Application Load Balancers.
The session affinity types require the following minimum GKE versions:
CLIENT_IP, HEADER_FIELD, GENERATED_COOKIE, and HTTP_COOKIE:
version 1.35.2-gke.1269001 or laterSTRONG_COOKIE_AFFINITY: version 1.36.3-gke.1767000 or laterFor more information, see Configure session affinity using GCPTrafficDistributionPolicy.
1.30.4-asm.1 is now available for in-cluster Cloud Service Mesh.
You can now download 1.30.4-asm.1 for in-cluster Cloud Service Mesh. It includes the features of Istio 1.30.4 subject to the list of supported features.
The following are not supported:
ENABLE_WILDCARD_HOST_SERVICE_ENTRIES_FOR_TLSCUSTOM external authorization providers per workloadDEBUG_ENDPOINT_AUTH_ALLOWED_NAMESPACES flagFor details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh version 1.30.4-asm.1 uses Envoy v1.38.4-dev.
In-cluster Cloud Service Mesh 1.27 is no longer supported. For more information and to view the earliest end-of-life dates for other versions, see Supported versions.
Cloud Armor supports advanced match conditions to include attributes for inspecting request body content and parameters in Preview. This lets you write custom CEL rules to filter traffic based on raw body content, structured data (JSON, Form Data, GraphQL), and query parameters. For more information, see Configure custom rules language attributes.
General Availability: VPC Flow Logs generates log records for dropped traffic. For more information, see Records for dropped traffic.
General Availability: You can reserve static external IPv6 addresses from
bring your own IP addresses (BYOIP) sub-prefixes that are in
EXTERNAL_IPV6_FORWARDING_RULE_CREATION mode.
You can assign these addresses to forwarding rules for external passthrough Network Load Balancers and external protocol forwarding. You can also promote ephemeral IPv6 BYOIP addresses that are used by external forwarding rules to reserved static IP addresses.
For more information, see Create external forwarding rules.
Network Endpoint Group (NEG) pre-provisioning is now available in Preview. With
this feature, you can force the creation of empty zonal GCE_VM_IP_PORT NEGs in
specified zones (or all zones within a region) during Service creation,
regardless of whether the cluster has nodes in those zones. By extending the
cloud.google.com/neg Service annotation with a custom zones parameter, you can
seamlessly automate infrastructure deployments (such as attaching NEGs to
backend services) without waiting for workloads to deploy. For more information,
see Pre-provisioning empty
NEGs.
For regional external passthrough Network Load Balancers, reserving specific or automatically allocated bring your own IP (BYOIP) IPv6 addresses before creating a load balancer, and promoting an ephemeral BYOIP IPv6 address in use by a load balancer to a reserved static IP address, is generally available (GA).
For more information, see the following documentation:
Cloud SQL now makes it easier to configure Private Service Connect for your Cloud SQL instance. When you create an instance that's enabled with Private Service Connect, you can choose to automatically create the service connection policy and endpoint in the VPC network that you want to use with Private Service Connect.
For more information, see Configure Private Service Connect.
The rollout of the following extension upgrades is complete:
pg_partman is upgraded from 5.2.4 to 5.4.3.pgfincore is upgraded from 1.3.1 to 1.4.pgvector is upgraded from 0.8.1 to 0.8.5.For more information, see Configure PostgreSQL extensions.
Cloud SQL now makes it easier to configure Private Service Connect for your Cloud SQL instance. When you create an instance that's enabled with Private Service Connect, you can choose to automatically create the service connection policy and endpoint in the VPC network that you want to use with Private Service Connect.
For more information, see Configure Private Service Connect.
Cloud SQL now makes it easier to configure Private Service Connect for your Cloud SQL instance. When you create an instance that's enabled with Private Service Connect, you can choose to automatically create the service connection policy and endpoint in the VPC network that you want to use with Private Service Connect.
For more information, see Configure Private Service Connect.
The following images are now rolling out for managed Cloud Service Mesh:
These versions resolve the security vulnerabilities listed in Security Bulletin GCP-2026-057.
SSL policy cross-project referencing is now available for Application Load Balancers and proxy Network Load Balancers in Preview. You can use cross-project referencing to define and maintain a central SSL policy in an administrative project and reference it from target HTTPS proxies or target SSL proxies in different projects.
Cross-project referencing is supported for global and regional SSL policies. You can use cross-project referencing with the following load balancers:
For more information, see Cross-project SSL policy referencing.
1.29.7-asm.2 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.29.7-asm.2 uses Envoy v1.35.14.
This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057.
Patch 1.29.7-asm.2 contains the fix for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
1.28.10-asm.24 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.10-asm.24 uses Envoy v1.36.10.
This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057.
Patch 1.28.10-asm.24 contains the fix for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
1.27.9-asm.34 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.34 uses Envoy v1.35.14.
This release resolves the security vulnerabilities listed in Security Bulletin GCP-2026-057.
Patch 1.27.9-asm.34 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-10536 | Yes | Yes | No | Yes | Low (9.8) |
| CVE-2026-42151 | No | No | No | Yes | High (7.5) |
| CVE-2026-42154 | No | No | No | Yes | High (7.5) |
| CVE-2026-40179 | No | No | No | Yes | Medium (6.1) |
| CVE-2026-44903 | No | No | No | Yes | Medium (6.1) |
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
For clusters using the TRAFFIC_DIRECTOR implementation, configuring the trace
sampling rate with randomSamplingPercentage with the Telemetry API is now
supported in the Rapid release channel. For more information, see
Accessing Cloud Trace.
Network Security Integration in-band integration now supports the direct internet egress deployment model. In this model, the network security appliance in the producer VPC network inspects outbound traffic and sends it directly to the internet through its external network interface. The appliance then sends the internet response packet directly to the consumer VM using GENEVE, bypassing the return hop to the consumer VPC network.
For more information, see Direct internet egress.
Global Front End is a unified offering that combines Service Extensions, global external Application Load Balancer, Google Cloud Armor, and Cloud CDN into one solution to help deliver, scale, and secure your internet-facing applications. Service Extensions is included in the Global Front End Enterprise billing tier. This feature is available in Preview.
For more information, see the Global Front End section on the Service Extensions overview page.
Secure Web Proxy now supports the local intermediate CA signing certificate issuance mode for TLS inspection. By using this mode, Secure Web Proxy caches a single intermediate certificate authority (CA) certificate from your CA pool to sign leaf certificates locally for requested domains, reducing certificate issuance requests and transaction costs. To use this certificate issuance mode, you must make sure that your CA pool is configured to issue intermediate CA certificates.
For more information, see Certificate issuance modes and Configure a local intermediate CA signing. This feature is generally available (GA).
Network Security Integration in-band integration now supports the direct internet egress deployment model. In this model, the network security appliance in the producer VPC network inspects outbound traffic and sends it directly to the internet through its external network interface. The appliance then sends the internet response packet directly to the consumer VM using GENEVE, bypassing the return hop to the consumer VPC network.
For more information, see Direct internet egress.
Global Front End is a unified offering that combines Service Extensions, global external Application Load Balancer, Google Cloud Armor, and Cloud CDN into one solution to help deliver, scale, and secure your internet-facing applications. Service Extensions is included in the Global Front End Enterprise billing tier. This feature is available in Preview.
For more information, see the Global Front End section on the Service Extensions overview page.
Global Front End is a unified offering that combines Service Extensions, global external Application Load Balancer, Google Cloud Armor, and Cloud CDN into one solution to help deliver, scale, and secure your internet-facing applications. Service Extensions is included in the Global Front End Enterprise billing tier. This feature is available in Preview.
For more information, see the Global Front End section on the Service Extensions overview page.
Secure Web Proxy now supports the local intermediate CA signing certificate issuance mode for TLS inspection. By using this mode, Secure Web Proxy caches a single intermediate certificate authority (CA) certificate from your CA pool to sign leaf certificates locally for requested domains, reducing certificate issuance requests and transaction costs. To use this certificate issuance mode, you must make sure that your CA pool is configured to issue intermediate CA certificates.
For more information, see Certificate issuance modes and Configure a local intermediate CA signing. This feature is generally available (GA).
The guidance for using proxy image types (default and distroless) with
Managed Cloud Service Mesh has been updated:
TRAFFIC_DIRECTOR implementation
use distroless proxy images by default, and other image types are not
supported.ISTIOD to TRAFFIC_DIRECTOR) default
to default images, but can opt in to distroless images via MeshConfig or
the sidecar.istio.io/proxyImageType: distroless Pod annotation.For more information, see Distroless proxy images and Identify the proxy image type used in the cluster.
The guidance for using proxy image types (default and distroless) with
Managed Cloud Service Mesh has been updated:
TRAFFIC_DIRECTOR implementation
use distroless proxy images by default, and other image types are not
supported.ISTIOD to TRAFFIC_DIRECTOR) default
to default images, but can opt in to distroless images via MeshConfig or
the sidecar.istio.io/proxyImageType: distroless Pod annotation.For more information, see Distroless proxy images and Identify the proxy image type used in the cluster.
Global Front End combines global external Application Load Balancers, Google Cloud Armor, Cloud CDN, and Service Extensions into one solution to help deliver, scale, and secure your internet-facing applications.
For more information, see Global Front End.
This feature is available in Preview.
Global Front End is a unified offering that simplifies billing by consolidating pricing across networking products. Cloud Armor is included in the Global Front End Enterprise billing tier. Enabling Global Front End Enterprise in a project enables specific Cloud Armor Enterprise features for your global external Application Load Balancers. For more information, see Global Front End.This feature is available in Preview.
Global Front End is a unified offering that simplifies billing by consolidating pricing across networking products, including Cloud CDN, global external Application Load Balancer, Google Cloud Armor, and Service Extensions, into one solution to help deliver, scale, and secure your internet-facing applications. Cloud CDN is included in the Global Front End Enterprise billing tier. This feature is available in Preview.
For more information, see Global Front End.
Global Front End is a unified offering that simplifies billing by consolidating pricing across networking products. Cloud Armor is included in the Global Front End Enterprise billing tier. Enabling Global Front End Enterprise in a project enables specific Cloud Armor Enterprise features for your global external Application Load Balancers. For more information, see Global Front End.This feature is available in Preview.
Cloud CDN supports the targeted CDN-Cache-Control HTTP response
header RFC 9213. You can use
this header to specify caching directives specifically for Cloud CDN edge
caches without affecting browser-level caching.
For details, see Cache control header precedence.
Support for the Advanced malware sandbox (WildFire) service is now restored. You can now use Advanced malware sandbox to perform deep inspection of network-routed file transfers and block zero-day malware before it reaches your workloads. Advanced malware sandbox is available in the Cloud Next Generation Firewall Enterprise tier.
For more information, see Advanced malware sandbox overview and Configure Advanced malware sandbox in your network. This feature is available in Preview.
VPC Service Controls feature (Status: Preview): Support for optimizing service perimeters using the VPC Service Controls recommender is available.
The recommender detects architectural risks and perimeter misconfigurations, including the following:
Critical resources at risk of exfiltration: Identifies active and sensitive services (such as BigQuery and Cloud Storage) operating outside service perimeters.
Unconfigured VPC accessible services: Identifies perimeters that leave APIs unrestricted from within the security boundary.
Misconfigured VPC accessible services: Identifies mismatches between allowed accessible APIs and restricted services inside a perimeter.
For more information, see Optimize perimeters with recommender.
Connectivity Tests supports using a Cloud Run job as a source endpoint for connectivity testing.
For more information, see Test from a Cloud Run job to a destination.
Connectivity Tests supports using a Cloud Run job as a source endpoint for connectivity testing.
For more information, see Test from a Cloud Run job to a destination.
VPC Service Controls feature: The VPC Service Controls service patterns
feature is
generally available.
You can use service patterns to explicitly configure which Google APIs (both
supported and unsupported) can be accessed from VPC networks
within a service perimeter when using the private VIP (private.googleapis.com)
or a Private Service Connect endpoint with the all-apis bundle.
For more information, see VPC Service Controls service patterns.
VPC Service Controls feature: The VPC Service Controls service patterns
feature is
generally available.
You can use service patterns to explicitly configure which Google APIs (both
supported and unsupported) can be accessed from VPC networks
within a service perimeter when using the private VIP (private.googleapis.com)
or a Private Service Connect endpoint with the all-apis bundle.
For more information, see VPC Service Controls service patterns.
Cloud CDN supports native image optimization at the Google network edge for global external Application Load Balancers. This feature offloads compute-intensive image transformations, such as resizing, cropping, and format conversion to reduce origin server load and egress costs. This feature is in Preview.
For more information, see Optimize images with Cloud CDN.
Regular expression URL rewrites (regexRewrite) for route rules in URL maps are
now available for Application Load Balancers. You can use regular expression
pattern rewrite actions to rewrite URL paths by substituting or removing URL
path components before forwarding requests to your backends.
For more information, see Regular expression URL rewrites for route rules.
This feature is in Preview.
Connectivity Tests supports testing connectivity from a Database Migration Service private connection to a Cloud SQL instance.
For more information, see Test from a Database Migration Service private connection to a Cloud SQL instance.
Preview: You can create v2 IPv4 public advertised prefixes for bring your own IP addresses (BYOIP) that use Standard Tier IP addresses. For more information, see Network Service Tiers.
Preview: You can create v2 IPv4 public advertised prefixes for bring your own IP addresses (BYOIP) that use Standard Tier IP addresses. For more information, see Network Service Tiers.
Connectivity Tests supports testing connectivity from a Database Migration Service private connection to a Cloud SQL instance.
For more information, see Test from a Database Migration Service private connection to a Cloud SQL instance.
Preview stage support for the following integration:
Cloud Load Balancing introduces a new version of the Network Load Balancerβthe global external passthrough Network Load Balancer, which is the global variant of the regional external passthrough Network Load Balancer. The load balancer is available in Preview.
This load balancer variant solves use cases for Security Service Edge (SSE), DNS hosting, Adtech (real-time bidding), real-time communications (RTC), live streaming, and online gaming, among others.
Global external passthrough Network Load Balancers are Layer 4 passthrough load balancers that distribute external traffic among backends (instance groups or network endpoint groups) that can reside in multiple Google Cloud regions. By using Google's global anycast IP routing, the global external passthrough Network Load Balancer steers user traffic to the closest region with healthy backends and available capacity, delivering ultra-low latency and dynamic cross-region failover to ensure resilience to regional outages.
The load balancer provides you with two external IP addresses, each served by a disjoint and isolated global load balancing control and data plane server infrastructure (also known as an availability group) to provide high availability.
The load balancer supports TCP, UDP, ESP, GRE, ICMP, and ICMPv6 traffic and can handle both IPv4 and IPv6 traffic. You can deploy your backends in any of the following Google Cloud regions:
us-west1, us-west4, us-east4, us-east5europe-west2, europe-west3asia-southeast1, asia-south1, asia-northeast1southamerica-east1africa-south1australia-southeast1Note that this release doesn't support GKE backends for the global external passthrough Network Load Balancer.
For details on the new load balancer, see Global external passthrough Network Load Balancer overview.
Cloud Load Balancing introduces a new version of the Network Load Balancerβthe global external passthrough Network Load Balancer, which is the global variant of the regional external passthrough Network Load Balancer. The load balancer is available in Preview.
This load balancer variant solves use cases for Security Service Edge (SSE), DNS hosting, Adtech (real-time bidding), real-time communications (RTC), live streaming, and online gaming, among others.
Global external passthrough Network Load Balancers are Layer 4 passthrough load balancers that distribute external traffic among backends (instance groups or network endpoint groups) that can reside in multiple Google Cloud regions. By using Google's global anycast IP routing, the global external passthrough Network Load Balancer steers user traffic to the closest region with healthy backends and available capacity, delivering ultra-low latency and dynamic cross-region failover to ensure resilience to regional outages.
The load balancer provides you with two external IP addresses, each served by a disjoint and isolated global load balancing control and data plane server infrastructure (also known as an availability group) to provide high availability.
The load balancer supports TCP, UDP, ESP, GRE, ICMP, and ICMPv6 traffic and can handle both IPv4 and IPv6 traffic. You can deploy your backends in any of the following Google Cloud regions:
us-west1, us-west4, us-east4, us-east5europe-west2, europe-west3asia-southeast1, asia-south1, asia-northeast1southamerica-east1africa-south1australia-southeast1Note that this release doesn't support GKE backends for the global external passthrough Network Load Balancer.
For details on the new load balancer, see Global external passthrough Network Load Balancer overview.
Cloud Load Balancing introduces a new version of the Network Load Balancerβthe global external passthrough Network Load Balancer, which is the global variant of the regional external passthrough Network Load Balancer. The load balancer is available in Preview.
This load balancer variant solves use cases for Security Service Edge (SSE), DNS hosting, Adtech (real-time bidding), real-time communications (RTC), live streaming, and online gaming, among others.
Global external passthrough Network Load Balancers are Layer 4 passthrough load balancers that distribute external traffic among backends (instance groups or network endpoint groups) that can reside in multiple Google Cloud regions. By using Google's global anycast IP routing, the global external passthrough Network Load Balancer steers user traffic to the closest region with healthy backends and available capacity, delivering ultra-low latency and dynamic cross-region failover to ensure resilience to regional outages.
The load balancer provides you with two external IP addresses, each served by a disjoint and isolated global load balancing control and data plane server infrastructure (also known as an availability group) to provide high availability.
The load balancer supports TCP, UDP, ESP, GRE, ICMP, and ICMPv6 traffic and can handle both IPv4 and IPv6 traffic. You can deploy your backends in any of the following Google Cloud regions:
us-west1, us-west4, us-east4, us-east5europe-west2, europe-west3asia-southeast1, asia-south1, asia-northeast1southamerica-east1africa-south1australia-southeast1Note that this release doesn't support GKE backends for the global external passthrough Network Load Balancer.
For details on the new load balancer, see Global external passthrough Network Load Balancer overview.
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
QueryData adds support for parameterized secure views (PSVs) to help secure applications that use natural language queries. For more information, see Secure and control access to application data.
This feature is in Preview.
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
Cloud SQL for SQL Server now supports executing SQL statements using the Cloud SQL Data API.
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
QueryData adds support for parameterized secure views (PSVs) to help secure applications that use natural language queries. For more information, see Secure and control access to application data.
This feature is in Preview.
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
Cloud SQL for SQL Server now supports executing SQL statements using the Cloud SQL Data API.
General Availability: You can use the Resolve subnet mask setting on a
subnet to configure all attached Compute Engine instances with the same netmask
as the subnet (instead of /32). Configuring larger instance netmasks lets
compute instances discover the MAC addresses of other machines within the same
subnet and directly communicate with them by using destination MAC addresses.
For more information, see Compute instance netmasks.
General Availability: You can use the Resolve subnet mask setting on a
subnet to configure all attached Compute Engine instances with the same netmask
as the subnet (instead of /32). Configuring larger instance netmasks lets
compute instances discover the MAC addresses of other machines within the same
subnet and directly communicate with them by using destination MAC addresses.
For more information, see Compute instance netmasks.
General Availability: You can use the Resolve subnet mask setting on a
subnet to configure all attached Compute Engine instances with the same netmask
as the subnet (instead of /32). Configuring larger instance netmasks lets
compute instances discover the MAC addresses of other machines within the same
subnet and directly communicate with them by using destination MAC addresses.
For more information, see Compute instance netmasks.
General Availability: You can use the Resolve subnet mask setting on a
subnet to configure all attached Compute Engine instances with the same netmask
as the subnet (instead of /32). Configuring larger instance netmasks lets
compute instances discover the MAC addresses of other machines within the same
subnet and directly communicate with them by using destination MAC addresses.
For more information, see Compute instance netmasks.
The limits for the following Cloud NGFW resources have been updated:
For more information, see Quotas and limits.
For the clusters using TRAFFIC_DIRECTOR implementation,
IP auto-allocation
with DNS Proxy is now supported in Rapid release channel.
Service load balancing policies (serviceLbPolicy) are now supported for
regional external Application Load Balancers and regional internal Application Load Balancers. This feature enables
advanced load balancing optimizations such as custom load balancing algorithms,
auto-capacity draining, failover thresholds, and the ability to designate
preferred backends for these load balancers.
For more information, see Advanced load balancing optimizations.
This feature is in Preview.
In GKE version 1.36 and later, GKE Dataplane V2 with NetworkPolicies supports up to 15,000 nodes per cluster, increased from the previous limit of 7,500 nodes. For clusters exceeding 5,000 nodes, contact Cloud Customer Care to request a quota increase. For more information, see Cluster size limits and requirements.
In version 1.36.2-gke.1498000 and later, GKE supports mixed-protocol Services of type LoadBalancer in general availability (GA). Mixed-protocol Services let both external (NetLB) and internal (ILB) passthrough Network Load Balancers handle simultaneous TCP and UDP traffic on a single IP address across IPv4, IPv6, and dual-stack environments.
The general availability (GA) stage of mixed-protocol Services of type LoadBalancer fixes errors in traffic routing from stages prior to GA. This feature is in the GA stage in GKE version 1.36.2-gke.1498000 and later.
Enabling WildFire in an existing firewall endpoint can cause a temporary data plane outage. As a result, the WildFire feature is temporarily removed.
The Envoy Compressor Filter is now GA in the stable release channel.
Cloud Router support for named sets for BGP route policies is now generally available. For more information, see BGP route policies overview.
For Google Cloud resources that are registered as App Hub workloads or services, VPC Flow Logs records contain application-specific labels. For more information, see App Hub labels.
The Envoy Lua Filter is now available as a preview feature in the stable release channel.
You can now use the WildFire service to protect your network against unknown, novel malware, and file-based threats. WildFire integrates advanced malware sandboxing and real-time machine learning (ML) to perform deep inspection of network-routed file transfers and block zero-day malware before it reaches your workloads. WildFire is available in the Cloud Firewall Enterprise tier.
For more information, see WildFire overview and Configure WildFire in your network. This feature is available in Preview.
For regional external passthrough Network Load Balancers, you can reserve specific or automatically allocated bring your own IP (BYOIP) IPv6 addresses before creating a load balancer, so that the IPv6 address persists independently of the load balancer's lifecycle. You can also promote an ephemeral BYOIP IPv6 address that is in use by a load balancer to a reserved static IP address.
For more information, see the following documentation:
This feature is in Preview.
Preview: You can reserve static external IPv6 addresses from
bring your own IP addresses (BYOIP) sub-prefixes that are in
EXTERNAL_IPV6_FORWARDING_RULE_CREATION mode.
You can assign these addresses to forwarding rules for external passthrough Network Load Balancers and external protocol forwarding. You can also promote ephemeral IPv6 BYOIP addresses that are used by external forwarding rules to reserved static IP addresses.
For more information, see Create external forwarding rules.
Preview: You can reserve static external IPv6 addresses from
bring your own IP addresses (BYOIP) sub-prefixes that are in
EXTERNAL_IPV6_FORWARDING_RULE_CREATION mode.
You can assign these addresses to forwarding rules for external passthrough Network Load Balancers and external protocol forwarding. You can also promote ephemeral IPv6 BYOIP addresses that are used by external forwarding rules to reserved static IP addresses.
For more information, see Create external forwarding rules.
1.29.5-asm.12 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.29.5-asm.12 uses Envoy v1.35.13.
Patch 1.29.5-asm.12 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-46595 | Yes | Yes | Yes | Yes | Critical (10.0) |
| CVE-2026-8376 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-8925 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-39830 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39831 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39832 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39833 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-39834 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-42496 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-42508 | Yes | Yes | Yes | Yes | Critical (9.1) |
| CVE-2026-8924 | Yes | Yes | No | Yes | Low (9.1) |
| CVE-2026-8927 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8286 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2025-69720 | Yes | Yes | No | Yes | Low (7.8) |
| CVE-2026-39822 | Yes | Yes | Yes | Yes | High (7.8) |
| CVE-2026-39829 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-41992 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-46597 | Yes | Yes | Yes | Yes | High (7.5) |
| CVE-2026-9547 | Yes | Yes | No | Yes | Low (7.4) |
| CVE-2026-25680 | Yes | Yes | Yes | Yes | Medium (6.5) |
| CVE-2026-39827 | Yes | Yes | Yes | Yes | Medium (6.5) |
| CVE-2026-8458 | Yes | Yes | No | Yes | Low (6.5) |
| CVE-2026-39828 | Yes | Yes | Yes | Yes | Medium (6.3) |
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
| CVE-2026-58055 | Yes | Yes | No | Yes | Medium (5.4) |
| CVE-2026-39835 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-42505 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-46598 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-41991 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-45582 | Yes | Yes | No | Yes | Medium (0.0) |
1.28.10-asm.4 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.10-asm.4 uses Envoy v1.36.9.
Patch 1.28.10-asm.4 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-8376 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-8925 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-42496 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8924 | Yes | Yes | No | Yes | Low (9.1) |
| CVE-2026-8927 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8286 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2025-69720 | Yes | Yes | No | Yes | Low (7.8) |
| CVE-2026-39822 | Yes | Yes | Yes | Yes | High (7.8) |
| CVE-2026-41992 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-42151 | No | No | No | Yes | High (7.5) |
| CVE-2026-42154 | No | No | No | Yes | High (7.5) |
| CVE-2026-9547 | Yes | Yes | No | Yes | Low (7.4) |
| CVE-2026-8458 | Yes | Yes | No | Yes | Low (6.5) |
| CVE-2026-40179 | No | No | No | Yes | Medium (6.1) |
| CVE-2026-44903 | No | No | No | Yes | Medium (6.1) |
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
| CVE-2026-58055 | Yes | Yes | No | Yes | Medium (5.4) |
| CVE-2026-42505 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-41991 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-45582 | Yes | Yes | No | Yes | Medium (0.0) |
1.27.9-asm.15 is now available for in-cluster Cloud Service Mesh.
For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.15 uses Envoy v1.35.13v.
Patch 1.27.9-asm.15 contains fixes for the following platform CVEs:
| CVE | Proxy | Control Plane | Distroless | CNI | Severity |
|---|---|---|---|---|---|
| CVE-2026-8376 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-8925 | Yes | Yes | No | Yes | Medium (9.8) |
| CVE-2026-42496 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8924 | Yes | Yes | No | Yes | Low (9.1) |
| CVE-2026-8927 | Yes | Yes | No | Yes | Medium (9.1) |
| CVE-2026-8286 | Yes | Yes | No | Yes | Low (8.1) |
| CVE-2025-69720 | Yes | Yes | No | Yes | Low (7.8) |
| CVE-2026-39822 | Yes | Yes | Yes | Yes | High (7.8) |
| CVE-2026-41992 | Yes | Yes | No | Yes | Medium (7.5) |
| CVE-2026-9547 | Yes | Yes | No | Yes | Low (7.4) |
| CVE-2026-8458 | Yes | Yes | No | Yes | Low (6.5) |
| CVE-2026-5704 | Yes | Yes | No | Yes | Medium (5.5) |
| CVE-2026-58055 | Yes | Yes | No | Yes | Medium (5.4) |
| CVE-2026-42505 | Yes | Yes | Yes | Yes | Medium (5.3) |
| CVE-2026-41991 | Yes | Yes | No | Yes | Medium (4.7) |
| CVE-2025-45582 | Yes | Yes | No | Yes | Medium (0.0) |
Partner Cross-Cloud Interconnect for Amazon Web Services (AWS) supports the following new locations:
For available locations, see Choose a paired location.
Include and exclude spoke filters for hybrid spokes are generally available.
You can use export filters to control which subnets or routes a spoke can send to the hub. Import filters control which subnets or routes can be accepted by a spoke from the hub.