---
格式版本: 2
标题: "Google Cloud release notes | Google Cloud Documentation"
原文链接: "https://docs.cloud.google.com/release-notes"
发布日期: "2026-08-19"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "llm:local:original_extracted_text"
发布时间证据: "第 21 行：August 19, 2026"
发布时间校准原因: "页面为 Google Cloud release notes，正文明确标注最新更新日期 August 19, 2026，且位于标题附近，属于文章发布时间。"
发布时间校准置信度: "1"
发布时间候选数量: 20
发布时间严格候选数量: 3
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T10:44:09+08:00"
发布时间仲裁状态: "confirmed"
发布时间仲裁尝试次数: 3
发布时间仲裁耗时毫秒: 28903
发现时间: "2026-08-20T10:39:33+08:00"
入库时间: "2026-08-20T02:44:40.402Z"
来源平台: "固定入口"
搜索渠道: "fixed_url"
搜索词: "https://docs.cloud.google.com/release-notes"
匹配关键词:
  - "GPU"
  - "delivery"
  - "deployment"
  - "performance"
  - "latency"
  - "throughput"
  - "AI"
相关厂家:
  - "Google"
  - "NVIDIA"
  - "Microsoft"
  - "AWS"
  - "Oracle"
  - "OpenAI"
相关专家:
  []
内容类型: "网页"
抓取工具: "CDP Render"
清洗工具: "CDP Text + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 0
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "内容为Google Cloud通用release notes入口页，仅涉及App Engine、BigQuery、Gemini等云服务更新，与超节点/AI Rack/机柜级基础设施完全无关。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T10:44:58+08:00"
AI主题相关性: 0
AI来源权威性: 0
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "Google Cloud 8月19日发布更新，为App Engine、Cloud Run、Cloud Run functions和Buildpacks新增Go 1.27运行时预览支持。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:16:23.271Z"
采集批次: "2026年8月20日10点15分53秒"
采集批次ID: "20260820-101553-437"
去重键: "https://docs.cloud.google.com/release-notes"
---

The following release notes cover the most recent changes over the last 60 days. For a comprehensive list of product-specific release notes, see the [individual product release note pages](https://docs.cloud.google.com/release-notes/all).

You can also see and filter all release notes in the [Google Cloud console](https://console.cloud.google.com/release-notes) or you can programmatically access release notes in [BigQuery](https://console.cloud.google.com/bigquery?p=bigquery-public-data&d=google_cloud_release_notes&t=release_notes&page=table).

To get the latest product updates delivered to you, add the URL of this page to your [feed reader](https://wikipedia.org/wiki/Comparison_of_feed_aggregators), or add the [feed URL](https://docs.cloud.google.com/feeds/gcp-release-notes.xml) directly.

## August 19, 2026

**App Engine flexible environment Go** Feature

Support for the [Go 1.27 runtime](https://docs.cloud.google.com/appengine/docs/flexible/go/runtime) is in [Preview](https://cloud.google.com/products/#product-launch-stages).

Feature

Starting from Go runtime version 1.26 and later, the lifecycle support dates align more closely with the [Go community release cycle](https://go.dev/wiki/Go-Release-Cycle). For more information, see [Runtime support schedule](https://docs.cloud.google.com/appengine/docs/flexible/lifecycle/support-schedule#go).

**App Engine standard environment Go** Feature

Support for the [Go 1.27 runtime](https://docs.cloud.google.com/appengine/docs/standard/go/runtime) is in [Preview](https://cloud.google.com/products/#product-launch-stages).

Feature

Starting from Go runtime version 1.26 and later, the lifecycle support dates align more closely with the [Go community release cycle](https://go.dev/wiki/Go-Release-Cycle). For more information, see [Runtime support schedule](https://docs.cloud.google.com/appengine/docs/standard/lifecycle/support-schedule#go).

Feature

You can migrate your App Engine push queues to Cloud Tasks by updating the bundled services SDK. This method lets you upgrade your app without needing to modify your application code. For more information on how to migrate, see the [push queues migration guide](https://docs.cloud.google.com/appengine/migration-center/standard/go/migrating-push-queues-upgrade-sdk) ([Preview](https://cloud.google.com/products/#product-launch-stages)).

**App Engine standard environment Java** Feature

You can migrate your App Engine push queues to Cloud Tasks by updating the bundled services SDK. This method lets you upgrade your app without needing to modify your application code. For more information on how to migrate, see the [push queues migration guide](https://docs.cloud.google.com/appengine/migration-center/standard/java/migrating-push-queues-upgrade-sdk) ([Preview](https://cloud.google.com/products/#product-launch-stages)).

**App Engine standard environment Python** Feature

You can migrate your App Engine push queues to Cloud Tasks by updating the bundled services SDK. This method lets you upgrade your app without needing to modify your application code. For more information on how to migrate, see the [push queues migration guide](https://docs.cloud.google.com/appengine/migration-center/standard/python/migrating-push-queues-upgrade-sdk) ([Preview](https://cloud.google.com/products/#product-launch-stages)).

**Batch**

Deprecated

The Batch Debian 11 operating system (OS) image family has reached end of development due to the [end of support (EOS) for Compute Engine Debian 11 images on August 31, 2026](https://docs.cloud.google.com/compute/docs/images/os-details#debian). The last Batch Debian 11 images—any image versions with the `batch-debian-11-official` prefix—are only supported until August 31, 2026. Before then, migrate any job that uses a Batch Debian 11 image to a Batch Debian 12 image (or other image) as follows:

- For job definitions that use the `batch-debian` image prefix (which is the default image for jobs with any script runnables), the image that Batch automatically selects during job creation is gradually migrating to Debian 12 no later than August 31, 2026. For any jobs created before August 31, 2026, you can check whether the job uses Debian 11 or Debian 12 by describing the job.
- For job definitions that specify either the `batch-debian-11-official` image family or an image version with that prefix, specify a different image during job creation. For example, to migrate to Debian 12, specify either the `batch-debian-12-official` image family or an image version with that prefix.

Learn more about [OS images](https://docs.cloud.google.com/batch/docs/vm-os-environment-overview), [viewing OS images](https://docs.cloud.google.com/batch/docs/view-os-images), and [specifying OS images](https://docs.cloud.google.com/batch/docs/specify-vm-os-image).

**Buildpacks** Feature

Starting from Go runtime version 1.26 and later, the lifecycle support dates align more closely with the [Go community release cycle](https://go.dev/wiki/Go-Release-Cycle). For more information, see [Runtime support schedule](https://docs.cloud.google.com/docs/buildpacks/runtime-support#go).

**Cloud Run** Feature

Support for the [Go 1.27 runtime](https://docs.cloud.google.com/run/docs/runtime-support#go) is in [Preview](https://cloud.google.com/products/#product-launch-stages).

Feature

Starting from Go runtime version 1.26 and later, the lifecycle support dates align more closely with the [Go community release cycle](https://go.dev/wiki/Go-Release-Cycle). For more information, see [Runtime support schedule](https://docs.cloud.google.com/run/docs/runtime-support#go).

**Cloud Run functions** Feature

Support for the [Go 1.27 runtime](https://docs.cloud.google.com/functions/docs/concepts/execution-environment#go) is in [Preview](https://cloud.google.com/products/#product-launch-stages).

Feature

Starting from Go runtime version 1.26 and later, the lifecycle support dates align more closely with the [Go community release cycle](https://go.dev/wiki/Go-Release-Cycle). For more information, see [Runtime support schedule](https://docs.cloud.google.com/functions/docs/runtime-support#go).

**Gemini Enterprise**

Change

**Gemini Enterprise: Subscription seat quantity limits**

If you purchase or modify a seat-based subscription directly through the Google Cloud console, the number of seats is capped according to your Cloud Billing account type:

- Self-serve (online) and resold accounts: Up to 25 seats per account.
- Invoiced (offline) accounts: Up to 1,000 seats per account.

For more information, see [Subscription seat quantity limits](https://docs.cloud.google.com/gemini/enterprise/docs/licenses#seat-limits).

**Google Distributed Cloud (software only) for VMware** Announcement

Google Distributed Cloud (software only) for VMware 1.34.800-gke.90 is now available for download. To upgrade, see [Upgrade clusters](https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/how-to/upgrading). Google Distributed Cloud 1.34.800-gke.90 runs on Kubernetes v1.34.7-gke.200.

If you use a third-party storage vendor, check the listing of our previously-qualified [storage partners](https://docs.cloud.google.com/kubernetes-engine/enterprise/docs/resources/partner-storage).

After a release, it takes approximately 7 to 14 days for the version to become available for use with GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

Fixed

The following issues were fixed in 1.34.800-gke.90:

- Fixed vulnerabilities listed in [Vulnerability fixes](https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/vulnerabilities).
- Fixed an issue where user clusters remained stuck in a `Reconciling` state after an admin cluster upgrade. The admin cluster controller skipped reconciling legacy cluster lifecycle components during upgrades unless an initial migration annotation was set. If legacy user clusters still existed on the admin cluster, missing legacy API discovery (`cluster.k8s.io/v1alpha1`) caused controller reconciliation to stall. With this fix, the controller preserves legacy components as long as any legacy user clusters exist, and prunes them only after all user clusters have migrated to advanced clusters.
- Fixed an issue where `gkectl prepare` failed with a permission denied error when attempting to read a private registry CA certificate. The certificate file permissions are now set to `644` so non-root processes can read it.
- Fixed an issue where retrying a failed upgrade to an Advanced Cluster (such as re-running with an existing bootstrap cluster) could wipe or strip the encryption keys in the generated-key-kms-plugin-config secret, preventing the control plane from decrypting existing Kubernetes secrets in etcd.

**Google Distributed Cloud (software only) for bare metal** Announcement

Google Distributed Cloud (software only) for bare metal 1.34.800-gke.90 is now available for download. To upgrade, see [Upgrade clusters](https://docs.cloud.google.com/release-notes/how-to/upgrade). Google Distributed Cloud for bare metal 1.34.800-gke.90 runs on Kubernetes v1.34.7-gke.200.

After a release, it takes approximately 7 to 14 days for the version to become available for installations or upgrades with the GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

If you use a third-party storage vendor, check the listing of our previously-qualified [storage partners](https://docs.cloud.google.com/kubernetes-engine/enterprise/docs/resources/partner-storage).

Fixed

The following issues were fixed in 1.34.800-gke.90:

- Fixed vulnerabilities listed in [Vulnerability fixes](https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities).
- Removed `csi-snapshot-validation-webhook`, the [Snapshot validation webhook](https://kubernetes-csi.github.io/docs/snapshot-validation-webhook.html#description) component.

**Oracle Database@Google Cloud** Feature

Oracle Database@Google Cloud supports provisioning VM file system storage (VM images) and VM backups on Exascale storage for Exadata VM Clusters. This feature lets you to offload VM artifacts to Exascale, freeing up capacity and reducing dependence on local DB Server storage. For more information, see [Configure Exascale Storage Vault for Exadata Infrastructure](https://docs.cloud.google.com/oracle/database/docs/configure-exascale-storage) and [Create Exadata VM Clusters with Exascale Storage Vaults](https://docs.cloud.google.com/oracle/database/docs/create-clusters#create-cluster-using-vault).

This feature is [Generally Available (GA)](https://cloud.google.com/products#product-launch-stages).

## August 18, 2026

**App Engine standard environment Java**

Feature

**App Engine standard environment Python**

Feature

**BigQuery** Feature

The default per-project limit of user-specific [reservation assignments](https://docs.cloud.google.com/bigquery/docs/reservations-assignments#assignment-logic-and-criteria) has been increased from 10 to 100.

**Cloud SDK**

Breaking

## 581.0.0 (2026-08-18)

### Breaking Changes

- **(Cloud Services)** Removed `gcloud beta services mcp enable`, `gcloud beta services mcp disable`, and `gcloud beta services mcp list` as MCP enablement is no longer required and they have been functioning as no-ops.

### AI Platform

- Added `gcloud beta ai semantic-governance-policy-engine deprovision` command to tear down a semantic governance policy engine, including its tenant project, GKE cluster, and PSC service attachments.
- Promoted `gcloud ai semantic-governance-policies` (`create`, `describe`, `update`, `delete`, `list`) and `gcloud ai semantic-governance-policy-engine` (`describe`, `update`, `deprovision`) commands from beta to GA.

### BigQuery

- Added fields `precedence` and `condition` to the commands `bq ls --reservation_assignment` and `bq show --reservation_assignment` output.
- Added the new `AUTOMATIC_MATERIALIZED_VIEW_REFRESH` job type for users to create reservation assignments with.

### Cloud Auth

- Enabled Enterprise Certificate Proxy (ECP) HTTP Proxy by default for context-aware mTLS requests.

### Cloud Bigtable

- Rebuilt cbt cli with newer version of bigtable client for CVE-2026-39883.

### Cloud IAM

- Updated `gcloud iam workforce-pools create-cred-config` and `gcloud iam workforce-pools create-login-config` to accept short-format provider audiences (`<pool>/<provider>`).
- Added `gcloud beta iam workforce-pools providers create-saml` and `gcloud beta iam workforce-pools providers update-saml` commands.

### Cloud Services

- **API Keys**: Added `--append` flag to `gcloud services api-keys update` command to merge new application and API target restrictions with existing key restrictions instead of replacing them.

### Cluster Director

- Fixed `gcloud cluster-director clusters create` to not create default compute resources when they are overridden by the user.
- Updated `gcloud cluster-director clusters create` to default to `hyperdisk-balanced` boot disks and restrict persistent disks (PD) for non-N2 and non-CT5P machine types.
- Fixed a validation error during cluster updates that concurrently modified storage resources and Slurm node sets.

### Compute Engine

- Added `gcloud compute target-ssl-proxies test-iam-permissions` command to test IAM permissions on a Compute Engine target SSL proxy in `beta`, `preview`, and `GA`.
- Added `--max-stream-duration` flag to `gcloud compute backend-services create` and `update` commands in beta, preview, and GA.
- Added `gcloud compute packet-mirrorings test-iam-permissions` command for beta, preview and GA tracks.

### Container

- Fixed issue where `gcloud` CLI would crash on corrupted `~/.kube/config`. Now you will now get a more detailed explanation about which section and line is wrong, to make troubleshooting easier. Corrupted kubeconfig will be backed up for further troubleshooting.

### Database Migration

- Added `--reserved-public-ip` and `--reserved-public-ip-nat-ips-count` flags to `gcloud database-migration private-connections create`.
- Added `--fetch-reserved-public-ips` flag to `gcloud database-migration connection-profiles fetch-static-ips`.

### Kubernetes Engine

- Add `--enable-slice-controller` flag in `gcloud container clusters create` and `gcloud container clusters update`.

### Oracle Database

- Added `--total-vm-storage-size-gb` flag to `gcloud oracle-database cloud-exadata-infrastructures configure-exascale` and `--properties-vm-backup-storage-type`, `--properties-vm-file-system-storage-type` flags to `gcloud oracle-database cloud-vm-clusters create` to support Exascale VM storage options.

Subscribe to these release notes at [https://groups.google.com/forum/#!forum/google-cloud-sdk-announce](https://groups.google.com/forum/#!forum/google-cloud-sdk-announce).

**Gemini Enterprise** Feature

**Gemini Enterprise: Show new team member announcements on the app home page**

Gemini Enterprise can display new team member announcement cards on the app home page to welcome people who recently joined the organization. Users see people who recently joined their part of the organization.

This feature is generally available (GA). For more information, see [Show new team member announcements](https://docs.cloud.google.com/gemini/enterprise/docs/app-home-page#new-team-member).

Feature

**Gemini Enterprise: Gemini 3.6 Flash available in US and EU multi-regions**

Gemini 3.6 Flash is generally available in the `us` and `eu` multi-regions, and an allowlist is no longer required to use Gemini 3.6 Flash in the `us` multi-region. To make Gemini 3.6 Flash available to users in the Gemini Enterprise app, administrators must turn on the **Gemini 3.6 Flash** feature toggle in the Google Cloud console.

If an administrator previously turned on the **Gemini 3.6 Flash** toggle for an app in the `us` or `eu` multi-region and accepted the out-of-region routing warning, traffic for that app automatically routes to the app's location (`us` or `eu`). No action is required.

In regions where the model is not supported, administrators can still enable the model by acknowledging a warning that traffic routes to the `global` endpoint, which does not support regional data residency.

For more information, see:

- [Manage features on the web app](https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features)
- [Data residency for Gemini Enterprise Standard and Plus Editions and Gemini Notebook Enterprise](https://docs.cloud.google.com/gemini/enterprise/docs/locations)

Feature

**Gemini Enterprise: Access and configure AI developer tools**

AI developer tools is generally available (GA) for Gemini Enterprise Standard, Plus, and Pay-as-you-go editions with an invoiced Cloud Billing account. This launch includes access to Antigravity 2.0, Antigravity CLI, and Android Studio.

Key capabilities of AI developer tools include the following:

- **Administrative controls**: Turn on or turn off AI developer tools, configure security policies (such as file access and terminal command execution), and manage model availability in the Google Cloud console.
- **Usage metrics dashboard**: Monitor developer adoption, active users, token consumption, and API call volumes with integrated Cloud Monitoring and logging.

You can manage access to AI developer tools using a custom IAM role.

For more information, see the following:

- [AI developer tools overview](https://docs.cloud.google.com/gemini/enterprise/docs/ai-developer-tools-overview)
- [Configure AI developer tools settings](https://docs.cloud.google.com/gemini/enterprise/docs/ai-developer-tools-settings)
- [Create custom roles for AI developer tools](https://docs.cloud.google.com/gemini/enterprise/docs/ai-developer-tools-creating-custom-roles)
- [View AI developer tools metrics](https://docs.cloud.google.com/gemini/enterprise/docs/ai-developer-tools-metrics)

**Gemini Enterprise Agent Platform**

Feature

**CodeMender updates: Model support**

This release introduces updates to CodeMender:

- **Gemini 3 Flash removal**: Gemini 3 Flash (`gemini-3-flash-preview`) is no longer supported as a model backend for CodeMender. CodeMender supports Gemini 3.5 Flash (default) and Gemini 3.1 Pro Preview.

For more information, see [Specifying the model](https://docs.cloud.google.com/gemini-enterprise-agent-platform/codemender#specifying-the-model).

**Google Kubernetes Engine** Change

For node pools running on GKE versions 1.36.3-gke.1480000 and later, the minimum supported boot disk size is 15 GB. For earlier versions, the minimum supported boot disk size is 12 GB.

**Google SecOps** Feature

**\[Spotlight Feature\] Evaluate threat coverage and generate rules with the Detection Engineering Agent**

This feature is in public preview. You can now evaluate and strengthen your Google SecOps security posture against emerging threats using the Detection Engineering Agent. This AI-powered assistant helps you extract threat intelligence and automatically draft YARA-L detection rules, drastically improves time-to-value for custom security automation and accelerating risk mitigation. The agent is accessible using Model Context Protocol (MCP) tools operated by compatible AI clients (such as Google Antigravity or Claude Code). For more information, see [Evaluate threat coverage with the Detection Engineering Agent](https://docs.cloud.google.com/chronicle/docs/secops/agentic-detection-engineering).

Feature

**\[Spotlight Feature\] Event simulation for detection coverage evaluation**

This feature is in public preview. You can now programmatically deliver realistic threat sequences into the live ingestion pipeline using event simulation. Event simulation provides a full-funnel detection coverage evaluation framework embedded directly within Google SecOps, enabling detection engineering and SOC teams to verify the entire detection lifecycle—from UDM normalization to multi-event correlation and alerting—while preserving production SOC workflows.

As a core capability of the [Detection Engineering Agent (DEA)](https://docs.cloud.google.com/chronicle/docs/secops/agentic-detection-engineering) architecture, event simulation connects Google SecOps MCP tools with AI assistance (such as Gemini) to automate threat intel processing, synthetic telemetry generation, and YARA-L 2.0 rule coverage evaluation.

For more information, see [Use event simulation for detection coverage evaluation](https://docs.cloud.google.com/chronicle/docs/secops/event-simulation).

**Looker**

Announcement

The latest versions in the Looker (Google Cloud core) [release channels](https://docs.cloud.google.com/looker/docs/looker-core-release-process#release_channels) are beginning deployment as follows:

- Latest version in the Rapid channel: **Looker 26.14**
- Latest version in the Regular channel: **Looker 26.12**
- Latest version in the No Channel channel: **Looker 26.14**

**NetApp Volumes** Announcement

Google Cloud NetApp Volumes is now Canada Controlled Goods (CCG) compliant for the Standard, Premium, and Extreme service levels. For more information, see [Compliance](https://docs.cloud.google.com/netapp/volumes/docs/compliance).

## August 17, 2026

**AlloyDB for PostgreSQL** Feature

You can now use the [Model Context Protocol (MCP) Toolbox for Databases](https://docs.cloud.google.com/alloydb/docs/connect-ide-using-mcp-toolbox#access-advanced-query-insights) to access AlloyDB observability features and advanced query insights directly in your IDE.

**Assured Workloads** Feature

The [Data Boundary for Canada Controlled Goods Program (CGP)](https://docs.cloud.google.com/assured-workloads/docs/control-packages/canada-controlled-goods-program) control package is now generally available.

**Backup and DR** Announcement

Beginning November 1, 2026, Backup and DR Service will automatically apply a project-level lien to any project containing a backup vault with backups protected by enforced retention. To secure project liens against unauthorized removal and manage lien deletion securely, you can configure multi-party approval using Privileged Access Manager (PAM).

For more information, see [Protect project liens by using Privileged Access Manager](https://docs.cloud.google.com/backup-disaster-recovery/docs/configuration/project-liens-multi-party-approval) and [Protect projects with liens](https://docs.cloud.google.com/resource-manager/docs/project-liens).

**Cloud CDN** Feature

Cloud CDN supports the targeted `CDN-Cache-Control` HTTP response header [RFC 9213](https://www.rfc-editor.org/rfc/rfc9213). You can use this header to specify caching directives specifically for Cloud CDN edge caches without affecting browser-level caching.

For details, see [Cache control header precedence](https://docs.cloud.google.com/cdn/docs/caching#cache-control-headers).

**Cloud Database Migration Service** Announcement

Database Migration Service for MySQL homogeneous migrations now supports MySQL version 9.7. For more information, see [Supported source and destination databases](https://docs.cloud.google.com/database-migration/docs/supported-databases).

**Cloud NGFW** Feature

Support for the Advanced malware sandbox (WildFire) service is now restored. You can now use Advanced malware sandbox to perform deep inspection of network-routed file transfers and block zero-day malware before it reaches your workloads. Advanced malware sandbox is available in the Cloud Next Generation Firewall Enterprise tier.

For more information, see [Advanced malware sandbox overview](https://docs.cloud.google.com/firewall/docs/about-wildfire) and [Configure Advanced malware sandbox in your network](https://docs.cloud.google.com/firewall/docs/configure-wildfire). This feature is available in **Preview**.

**Cloud Storage** Feature

If you delete your project, buckets that have soft delete enabled are now retained for a limited amount of time before being permanently deleted. If you restore a deleted project during this time period, these buckets are restored to the state that they were in when the project was deleted.

For more information about soft delete and the restoration window, see [Soft delete](https://docs.cloud.google.com/storage/docs/soft-delete).

**Cloud Trace**

Feature

The following limits associated with the Cloud Trace API, `cloudtrace.googleapis.com`, have increased:

- Maximum attributes per span: 1,024
- Maximum attribute value size: 65,532 bytes
- Maximum attribute key size: 512 bytes
- Maximum span name length: 1,024 bytes
- Maximum events per span: 256

The new limits are consistent with those supported by the Telemetry API, which implements the [OpenTelemetry Protocol (OTLP)](https://opentelemetry.io/docs/specs/otlp).

For more information, see [Cloud Trace API quotas and limits](https://docs.cloud.google.com/trace/docs/quotas#trace-api-quotas-and-limits).

**Container Optimized OS**

Change

### cos-beta-133-19999-0-46

| Kernel | Docker | Containerd | [GPU Drivers](https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus) |
| --- | --- | --- | --- |
| [COS-6.18.39](https://cos.googlesource.com/third_party/kernel/+/597640a484f462d27f6bc35d247e63f0009a2fc0) | v29.4.3 | v2.3.2 | [See List](https://storage.googleapis.com/cos-tools/19999.0.46/lakitu/gpu_driver_versions.textproto) |

Change

### cos-129-19506-299-137

| Kernel | Docker | Containerd | [GPU Drivers](https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus) |
| --- | --- | --- | --- |
| [COS-6.12.94](https://cos.googlesource.com/third_party/kernel/+/f8942cf365df41f4179e94e9c9af498b8509984f) | v27.5.1 | v2.2.6 | [See List](https://storage.googleapis.com/cos-tools/19506.299.137/lakitu/gpu_driver_versions.textproto) |

Feature

Enabled CONFIG\_UDMABUF on x86\_64.

Feature

Enabled CONFIG\_UDMABUF on x86\_64.

Security

Fixed CVE-2026-68081 in the Linux kernel.

Security

Fixed CVE-2026-64561 in the Linux kernel.

Security

Fixed CVE-2026-64562 in the Linux kernel.

Security

Fixed CVE-2026-64567 in the Linux kernel.

Security

Fixed CVE-2026-64572 in the Linux kernel.

Security

Fixed CVE-2026-64576 in the Linux kernel.

Security

Fixed CVE-2026-64579 in the Linux kernel.

Security

Fixed CVE-2026-64590 in the Linux kernel.

Security

Fixed CVE-2026-64593 in the Linux kernel.

Security

Fixed CVE-2026-64597 in the Linux kernel.

Security

Fixed CVE-2026-64598 in the Linux kernel.

Security

Fixed CVE-2026-64604 in the Linux kernel.

Security

Fixed CVE-2026-68092 in the Linux kernel.

Security

Fixed CVE-2026-68093 in the Linux kernel.

Security

Fixed CVE-2026-68116 in the Linux kernel.

Security

Fixed CVE-2026-68119 in the Linux kernel.

Security

Fixed CVE-2026-68136 in the Linux kernel.

Security

Fixed CVE-2026-68139 in the Linux kernel.

Security

Fixed CVE-2026-68142 in the Linux kernel.

Security

Fixed CVE-2026-68145 in the Linux kernel.

Security

Fixed CVE-2026-68147 in the Linux kernel.

Security

Fixed CVE-2026-68149 in the Linux kernel.

Security

Fixed CVE-2026-68171 in the Linux kernel.

Security

Fixed CVE-2026-68184 in the Linux kernel.

Security

Fixed CVE-2026-68186 in the Linux kernel.

Security

Fixed CVE-2026-68187 in the Linux kernel.

Security

Fixed CVE-2026-68296 in the Linux kernel.

Security

Fixed CVE-2026-68299 in the Linux kernel.

Security

Fixed CVE-2026-68329 in the Linux kernel.

Security

Fixed CVE-2026-68336 in the Linux kernel.

Security

Fixed CVE-2026-68343 in the Linux kernel.

Security

Fixed CVE-2026-68386 in the Linux kernel.

Security

Fixed CVE-2026-68388 in the Linux kernel.

Security

Fixed CVE-2026-68396 in the Linux kernel.

Security

Fixed CVE-2026-68425 in the Linux kernel.

Security

Fixed CVE-2026-68428 in the Linux kernel.

Security

Fixed CVE-2026-68432 in the Linux kernel.

Security

Fixed CVE-2026-68442 in the Linux kernel.

Security

Fixed CVE-2026-68450 in the Linux kernel.

Change

Runtime sysctl changes:

- Changed: net.ipv4.udp\_mem: 188034 250715 376068 -> 188034 250714 376068

Change

### cos-125-19216-532-108

| Kernel | Docker | Containerd | [GPU Drivers](https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus) |
| --- | --- | --- | --- |
| [COS-6.12.94](https://cos.googlesource.com/third_party/kernel/+/0be1f7be3821f7cb9ad728d32f04610a53b8a3d6) | v27.5.1 | v2.1.9 | [See List](https://storage.googleapis.com/cos-tools/19216.532.108/lakitu/gpu_driver_versions.textproto) |

Feature

Enabled CONFIG\_UDMABUF on x86\_64.

Security

Fixed CVE-2026-64380 in the Linux kernel.

Security

Fixed CVE-2026-64561 in the Linux kernel.

Security

Fixed CVE-2026-64562 in the Linux kernel.

Security

Fixed CVE-2026-64567 in the Linux kernel.

Security

Fixed CVE-2026-64572 in the Linux kernel.

Security

Fixed CVE-2026-64576 in the Linux kernel.

Security

Fixed CVE-2026-64579 in the Linux kernel.

Security

Fixed CVE-2026-64580 in the Linux kernel.

Security

Fixed CVE-2026-64590 in the Linux kernel.

Security

Fixed CVE-2026-64593 in the Linux kernel.

Security

Fixed CVE-2026-64597 in the Linux kernel.

Security

Fixed CVE-2026-64598 in the Linux kernel.

Security

Fixed CVE-2026-64604 in the Linux kernel.

Security

Fixed CVE-2026-68092 in the Linux kernel.

Security

Fixed CVE-2026-68119 in the Linux kernel.

Security

Fixed CVE-2026-68136 in the Linux kernel.

Security

Fixed CVE-2026-68142 in the Linux kernel.

Security

Fixed CVE-2026-68145 in the Linux kernel.

Security

Fixed CVE-2026-68146 in the Linux kernel.

Security

Fixed CVE-2026-68147 in the Linux kernel.

Security

Fixed CVE-2026-68149 in the Linux kernel.

Security

Fixed CVE-2026-68184 in the Linux kernel.

Security

Fixed CVE-2026-68186 in the Linux kernel.

Security

Fixed CVE-2026-68187 in the Linux kernel.

Security

Fixed CVE-2026-68284 in the Linux kernel.

Security

Fixed CVE-2026-68338 in the Linux kernel.

Security

Fixed CVE-2026-68388 in the Linux kernel.

Security

Fixed CVE-2026-68396 in the Linux kernel.

Security

Fixed CVE-2026-68398 in the Linux kernel.

Security

Fixed CVE-2026-68422 in the Linux kernel.

Security

Fixed CVE-2026-68425 in the Linux kernel.

Security

Fixed CVE-2026-68428 in the Linux kernel.

Security

Fixed CVE-2026-68432 in the Linux kernel.

Security

Fixed CVE-2026-68442 in the Linux kernel.

Security

Fixed CVE-2026-68450 in the Linux kernel.

Change

### cos-121-18867-528-65

| Kernel | Docker | Containerd | [GPU Drivers](https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus) |
| --- | --- | --- | --- |
| [COS-6.6.143](https://cos.googlesource.com/third_party/kernel/+/fdc1aebadcf910bcaa07dbc287989e5b3ed46781) | v27.5.1 | v2.0.10 | [See List](https://storage.googleapis.com/cos-tools/18867.528.65/lakitu/gpu_driver_versions.textproto) |

Security

Fixed CVE-2026-64561 in the Linux kernel.

Security

Fixed CVE-2026-64562 in the Linux kernel.

Security

Fixed CVE-2026-64572 in the Linux kernel.

Security

Fixed CVE-2026-64576 in the Linux kernel.

Security

Fixed CVE-2026-64579 in the Linux kernel.

Security

Fixed CVE-2026-64580 in the Linux kernel.

Security

Fixed CVE-2026-64597 in the Linux kernel.

Security

Fixed CVE-2026-64598 in the Linux kernel.

Security

Fixed CVE-2026-64604 in the Linux kernel.

Security

Fixed CVE-2026-68093 in the Linux kernel.

Security

Fixed CVE-2026-68116 in the Linux kernel.

Security

Fixed CVE-2026-68147 in the Linux kernel.

Security

Fixed CVE-2026-68184 in the Linux kernel.

Security

Fixed CVE-2026-68186 in the Linux kernel.

Security

Fixed CVE-2026-68187 in the Linux kernel.

Security

Fixed CVE-2026-68284 in the Linux kernel.

Security

Fixed CVE-2026-68325 in the Linux kernel.

Security

Fixed CVE-2026-68336 in the Linux kernel.

Security

Fixed CVE-2026-68338 in the Linux kernel.

Security

Fixed CVE-2026-68343 in the Linux kernel.

Security

Fixed CVE-2026-68386 in the Linux kernel.

Security

Fixed CVE-2026-68398 in the Linux kernel.

Security

Fixed CVE-2026-68425 in the Linux kernel.

Security

Fixed CVE-2026-68428 in the Linux kernel.

Change

### cos-117-18613-675-56

| Kernel | Docker | Containerd | [GPU Drivers](https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus) |
| --- | --- | --- | --- |
| [COS-6.6.143](https://cos.googlesource.com/third_party/kernel/+/6c0a16f645a1b04d40574d8aa7fdd8710cf91309) | v24.0.9 | v1.7.34 | [See List](https://storage.googleapis.com/cos-tools/18613.675.56/lakitu/gpu_driver_versions.textproto) |

Security

Fixed CVE-2026-64227 in the Linux kernel.

Security

Fixed CVE-2026-64476 in the Linux kernel.

Security

Fixed CVE-2026-64561 in the Linux kernel.

Security

Fixed CVE-2026-64562 in the Linux kernel.

Security

Fixed CVE-2026-64572 in the Linux kernel.

Security

Fixed CVE-2026-64576 in the Linux kernel.

Security

Fixed CVE-2026-64579 in the Linux kernel.

Security

Fixed CVE-2026-64580 in the Linux kernel.

Security

Fixed CVE-2026-64597 in the Linux kernel.

Security

Fixed CVE-2026-64598 in the Linux kernel.

Security

Fixed CVE-2026-64604 in the Linux kernel.

Security

Fixed CVE-2026-68093 in the Linux kernel.

Security

Fixed CVE-2026-68184 in the Linux kernel.

Security

Fixed CVE-2026-68186 in the Linux kernel.

Security

Fixed CVE-2026-68187 in the Linux kernel.

Security

Fixed CVE-2026-68284 in the Linux kernel.

Security

Fixed CVE-2026-68299 in the Linux kernel.

Security

Fixed CVE-2026-68329 in the Linux kernel.

Security

Fixed CVE-2026-68336 in the Linux kernel.

Security

Fixed CVE-2026-68338 in the Linux kernel.

Security

Fixed CVE-2026-68343 in the Linux kernel.

Security

Fixed CVE-2026-68388 in the Linux kernel.

Security

Fixed CVE-2026-68398 in the Linux kernel.

Security

Fixed CVE-2026-68425 in the Linux kernel.

**Dataform** Feature

You can now use the [Dataform remote Model Context Protocol (MCP) server](https://docs.cloud.google.com/dataform/docs/use-dataform-mcp) to manage data transformation workflows through AI agents. This feature is [generally available](https://cloud.google.com/products#product-launch-stages) (GA).

**Gemini Enterprise**

Feature

**Gemini Enterprise: General availability for registering A2UI and A2A agents with Gemini Enterprise, including A2UI version v0.9 support**

Gemini Enterprise administrators can register and manage agents using [Agent to UI (A2UI)](https://a2ui.org/introduction/what-is-a2ui/) to build custom interfaces and the [Agent2Agent (A2A) Protocol](https://a2a-protocol.org/) for communication with Gemini Enterprise.

With this release:

- The feature is generally available (GA) instead of Public Preview.
- Support is added for A2UI version v0.9, in addition to v0.8 protocols. A2UI v0.9 supports the new Material Design-based components catalog.

For more information, see:

- [Register and manage agents using A2UI and A2A](https://docs.cloud.google.com/gemini/enterprise/docs/a2ui-agents/register-and-manage-an-a2ui-agent)
- [A2UI component gallery reference](https://docs.cloud.google.com/gemini/enterprise/docs/a2ui-agents/a2ui-component-gallery-reference)
- [Tutorial: Host an agent on Cloud Run](https://docs.cloud.google.com/gemini/enterprise/docs/a2ui-agents/tutorial-host-agent-cloud-run)

**Looker** Announcement

Looker's [Continuous Integration](https://docs.cloud.google.com/looker/docs/continuous-integration) is based on the legacy standalone Spectacles service. Looker will continue to integrate and evolve the Spectacles features into Looker's Continuous Integration, and the legacy standalone Spectacles service itself will be discontinued starting November 30, 2026. Existing Spectacles customers will receive an email with details. If you have any questions or require assistance, please contact us at [spectacles-support@google.com](mailto:spectacles-support@google.com).

## August 16, 2026

**Agent Platform Workbench** Security

Updated the bundled Ruby gems rexml and net-imap to patched versions, addressing known vulnerabilities.

Change

### 20260816-2330-rc0 Release

Security

Updated aiohttp, joblib and cryptography to patched versions, addressing known vulnerabilities including CVE-2022-21797 and CVE-2025-69223.

Change

Installed latest packages from upstream dependencies.

Change

Updated the CUDA base image from 12.8.1 to 12.9.2 (CUDA 12.9, cuDNN 9.10). This is a minor CUDA 12 update, binary compatible with the previous image, and also addresses known vulnerabilities in a bundled NVIDIA profiler component.

Security

Updated the bundled Ruby gems rexml and net-imap to patched versions, addressing known vulnerabilities.

Deprecated

Removed the JupyterLab 3 environment from the Python 3.12 custom container; JupyterLab 4 is now the only JupyterLab environment and is always used. The Python 3.10 images are unaffected.

Change

### 20260816-2330-rc0 Release

Security

Updated aiohttp, joblib and cryptography to patched versions, addressing known vulnerabilities including CVE-2022-21797 and CVE-2025-69223.

Change

Installed latest packages from upstream dependencies.

Change

### 20260816-2230-rc0 Release

Change

Installed latest packages from upstream dependencies.

Change

### 20260816-2230-rc0 Release

Change

Installed latest packages from upstream dependencies.

Change

### 20260816-2130-rc0 Release

Change

Installed latest packages from upstream dependencies.

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed the Git panel's grayed out buttons, which were disabled due to an issue with the Jupyter Lab's Git plugin introduced in version 0.54.0.

Change

### 20260816-2030-rc0 Release

**Google SecOps SOAR** Announcement

Release 6.3.98 is being rolled out to the first phase of regions as listed [here](https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release).

This release contains internal and customer bug fixes.

## August 15, 2026

**Gemini Enterprise Agent Platform** Feature

**Monitor semantic governance policies with built-in metrics (Preview)**

Built-in Cloud Monitoring metrics for the semantic governance policy engine are available in Preview. You can now observe request throughput, evaluation counts, latencies, verdict distribution (`ALLOW` versus `DENY`), and LLM token consumption for the policy engine directly in [Metrics Explorer](https://docs.cloud.google.com/monitoring/charts/metrics-explorer), query them through the Cloud Monitoring v3 API and PromQL, and use them in alerting policies.

For more information, see [Monitor semantic governance policies](https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/policies/monitor-semantic-governance).

Feature

**AlphaFold 3 is generally available**

AlphaFold 3 is now generally available (GA) and available for approved users for commercial research use.

AlphaFold 3 Google DeepMind's and Isomorphic Labs' deep learning model to predict the 3D structures and interactions of proteins, DNA, RNA, ligands, and ions. For more information, see [AlphaFold 3](https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/open-models/alphafold-3).

**Google SecOps SOAR** Announcement

[Release 6.3.97](https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_09_2026) is now available for all regions.

**Secure Source Manager** Feature

The Secure Source Manager Model Context Protocol (MCP) server is available in [Preview](https://docs.cloud.google.com/products#product-launch-stages). You can use the Secure Source Manager MCP server to connect AI tools and coding assistants directly to your repositories, branch rules, pull requests, and issues.

For more information, see the [Secure Source Manager MCP reference](https://docs.cloud.google.com/secure-source-manager/docs/reference/mcp).

## August 14, 2026

**App Engine flexible environment.NET** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/flexible/secure-minimum-tls).

**App Engine flexible environment Go** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/flexible/secure-minimum-tls).

**App Engine flexible environment Java** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/flexible/secure-minimum-tls).

**App Engine flexible environment Node.js** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/flexible/secure-minimum-tls).

**App Engine flexible environment PHP** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/flexible/secure-minimum-tls).

**App Engine flexible environment Python** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/flexible/secure-minimum-tls).

**App Engine flexible environment Ruby** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/flexible/secure-minimum-tls).

**App Engine flexible environment custom runtimes** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/flexible/secure-minimum-tls).

**App Engine standard environment Go** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/standard/secure-minimum-tls).

**App Engine standard environment Java** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/standard/secure-minimum-tls).

**App Engine standard environment Node.js** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/standard/secure-minimum-tls).

**App Engine standard environment PHP** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/standard/secure-minimum-tls).

**App Engine standard environment Python** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/standard/secure-minimum-tls).

**App Engine standard environment Ruby** Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see [Secure minimum TLS](https://docs.cloud.google.com/appengine/docs/standard/secure-minimum-tls).

**Carbon Footprint** Announcement

As detailed in our [2026 Environmental Report (p. 22)](https://storage.googleapis.com/gweb-mobius-cdn/sustainability/uploads/21455428735c7305f2cb5c0038fc14bb0803abb8.pdf#page=22), Google is now using Granular Certificates purchased from the marketplace to strategically match more of our load on an hourly basis. To accurately incorporate these certificates into the Cloud customers' allocation of carbon intensity calculations, the July 2026 semi-annual [methodology refresh](https://docs.cloud.google.com/carbon-footprint/docs/methodology#market-based-allocation) will be delayed by one month. We will provide further updates once the revised data is available.

**Cloud Logging** Announcement

The Telemetry API for logs ingestion is [generally available (GA)](https://docs.cloud.google.com/products#product-launch-stages). You can ingest OTLP logs into Cloud Logging by using an OpenTelemetry Collector, an OTLP exporter, and the Telemetry API. For more information, see [OTLP ingestion overview](https://docs.cloud.google.com/stackdriver/docs/otlp/overview).

**Compute Engine** Feature

**Generally available**: You can use zonal and global extension policies in VM Extension Manager to automatically install and manage extensions, such as the Ops Agent, on a fleet of VMs and to ensure consistent extension states across your project.

To improve observability of enforcement states and guest agent activities, you can [view VM extension logs](https://docs.cloud.google.com/compute/docs/vm-extensions/view-vm-extension-logs) by using Cloud Logging. These logs help you identify and troubleshoot issues with VM extensions.

For more information, see [About VM Extension Manager](https://docs.cloud.google.com/compute/docs/vm-extensions/about-vm-extension-manager).

**Cortex Framework**

Announcement

### Release 7.0.3

Fixed

- Resolved an issue where `SapBdcProductBuilder` incorrectly enforced SAP-versioned sections (ecc, s4, common) in `table_settings`.

**Gemini Enterprise**

Feature

**Gemini Enterprise: Gemini 3.7 Flash available in the mobile app**

Gemini 3.7 Flash is generally available (GA) in the Gemini Enterprise mobile app. Mobile app users can select and use the Gemini 3.7 Flash model for their conversations within the app. To make the model available, administrators must turn on the **Gemini 3.7 Flash** feature toggle in the Google Cloud console.

For more information, see:

- [Manage features on the web app](https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features)
- [Data residency for Gemini Enterprise Standard and Plus Editions and Gemini Notebook Enterprise](https://docs.cloud.google.com/gemini/enterprise/docs/locations)

**Google Kubernetes Engine**

Change

#### (2026-R34) Version updates

GKE cluster versions have been updated.

**New versions available for upgrades and new clusters.**

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see [GKE versioning and support](https://cloud.google.com/kubernetes-engine/versioning) and [About GKE cluster upgrades](https://cloud.google.com/kubernetes-engine/upgrades).

- The following versions are now available in the Rapid channel:
	- [1.33.13-gke.1462000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1106000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.7-gke.1150000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1537000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- [Alpha version](https://cloud.google.com/kubernetes-engine/versioning#alpha-versions) [1.37.0-gke.1173000+preview](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.37.md#v1370) is now available for GKE alpha clusters in the Rapid channel.
- The following versions are no longer available in the Rapid channel:
	- 1.33.13-gke.1329000
		- 1.34.9-gke.1655000
		- 1.35.6-gke.1710000
		- 1.36.3-gke.1244000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.36.3-gke.1253000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1414000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.33 to [1.34.10-gke.1079000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
				- 1.34 to [1.35.7-gke.1027000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1414000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.10-gke.1079000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
				- 1.35 to [1.35.7-gke.1027000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)

- Version [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
	- [1.33.13-gke.1329000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1655000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
		- [1.35.6-gke.1710000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
- The following versions are no longer available in the Regular channel:
	- 1.33.13-gke.1109000
		- 1.34.9-gke.1322000
		- 1.35.6-gke.1258000
		- 1.36.2-gke.1346000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.33 to [1.34.9-gke.1610000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.34 to [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.9-gke.1610000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.35 to [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
				- 1.36 to [1.36.2-gke.2064000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362)

- Version [1.35.6-gke.1250000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation in the Stable channel.
- The following versions are now available in the Stable channel:
	- [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1322000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
- The following versions are no longer available in the Stable channel:
	- 1.33.13-gke.1011000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.34.9-gke.1287000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1057002 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1163012 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1241004 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1101000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1101000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.35 to [1.35.6-gke.1250000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)

- Version [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
	- [1.31.14-gke.2456000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.31.14-gke.2579000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.32.13-gke.2175000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.32.13-gke.2268000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.33.13-gke.1329000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1655000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
		- [1.35.6-gke.1710000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
- The following versions are no longer available in the Extended channel:
	- 1.31.14-gke.2246000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.31.14-gke.2543000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.32.13-gke.1930000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.32.13-gke.2231000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.33.13-gke.1109000
		- 1.34.9-gke.1322000
		- 1.35.6-gke.1258000
		- 1.36.2-gke.1346000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.30 to [1.31.14-gke.2437000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.31 to [1.31.14-gke.2437000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
				- 1.32 to [1.32.13-gke.2137000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
				- 1.33 to [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.9-gke.1610000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.35 to [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
				- 1.36 to [1.36.2-gke.2064000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362)

- Version [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation.
- The following versions are now available:
	- [1.33.13-gke.1462000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1106000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.7-gke.1150000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1537000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- The following node versions are now available:
	- [1.31.14-gke.2579000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.32.13-gke.2268000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.33.13-gke.1462000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1106000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.7-gke.1150000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1537000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- The following versions are no longer available:
	- 1.33.13-gke.1011000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.34.8-gke.1278000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.34.9-gke.1287000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1057002 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1163012 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1241004 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.36.2-gke.1346000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.36.3-gke.1244000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.36.3-gke.1253000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.35 to [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
				- 1.36 to [1.36.2-gke.2064000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362)

Security

#### (2026-R34) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the **Security** release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

| GKE version | Container-Optimized OS version | Details |
| --- | --- | --- |
| 1.31.14-gke.2579000 | cos-117-18613-675-37 | [cos-117-18613-675-37 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-675-37_) |
| 1.32.13-gke.2268000 | cos-117-18613-675-37 | [cos-117-18613-675-37 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-675-37_) |
| 1.33.13-gke.1462000 | cos-121-18867-528-36 | [cos-121-18867-528-36 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-528-36_) |
| 1.35.7-gke.1150000 | cos-125-19216-532-62 | [cos-125-19216-532-62 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-532-62_) |
| 1.37.0-gke.1173000+preview | cos-129-19506-299-60 | [cos-129-19506-299-60 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-299-60_) |

Change

#### (2026-R34) Version updates

- Version [1.35.6-gke.1250000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation in the Stable channel.
- The following versions are now available in the Stable channel:
	- [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1322000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
- The following versions are no longer available in the Stable channel:
	- 1.33.13-gke.1011000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.34.9-gke.1287000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1057002 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1163012 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1241004 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1101000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1101000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.35 to [1.35.6-gke.1250000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)

Change

#### (2026-R34) Version updates

- Version [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
	- [1.33.13-gke.1329000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1655000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
		- [1.35.6-gke.1710000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
- The following versions are no longer available in the Regular channel:
	- 1.33.13-gke.1109000
		- 1.34.9-gke.1322000
		- 1.35.6-gke.1258000
		- 1.36.2-gke.1346000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Regular channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.33 to [1.34.9-gke.1610000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.34 to [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.9-gke.1610000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.35 to [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
				- 1.36 to [1.36.2-gke.2064000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362)

Change

#### (2026-R34) Version updates

- The following versions are now available in the Rapid channel:
	- [1.33.13-gke.1462000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1106000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.7-gke.1150000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1537000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- [Alpha version](https://cloud.google.com/kubernetes-engine/versioning#alpha-versions) [1.37.0-gke.1173000+preview](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.37.md#v1370) is now available for GKE alpha clusters in the Rapid channel.
- The following versions are no longer available in the Rapid channel:
	- 1.33.13-gke.1329000
		- 1.34.9-gke.1655000
		- 1.35.6-gke.1710000
		- 1.36.3-gke.1244000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.36.3-gke.1253000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1414000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.33 to [1.34.10-gke.1079000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
				- 1.34 to [1.35.7-gke.1027000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1414000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.10-gke.1079000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
				- 1.35 to [1.35.7-gke.1027000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)

Change

#### (2026-R34) Version updates

- Version [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation.
- The following versions are now available:
	- [1.33.13-gke.1462000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1106000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.7-gke.1150000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1537000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- The following node versions are now available:
	- [1.31.14-gke.2579000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.32.13-gke.2268000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.33.13-gke.1462000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1106000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.7-gke.1150000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1537000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- The following versions are no longer available:
	- 1.33.13-gke.1011000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.34.8-gke.1278000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.34.9-gke.1287000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1057002 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1163012 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.5-gke.1241004 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.36.2-gke.1346000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.36.3-gke.1244000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.36.3-gke.1253000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.35 to [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
				- 1.36 to [1.36.2-gke.2064000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362)

Change

#### (2026-R34) Version updates

- Version [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
	- [1.31.14-gke.2456000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.31.14-gke.2579000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.32.13-gke.2175000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.32.13-gke.2268000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.33.13-gke.1329000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1655000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
		- [1.35.6-gke.1710000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
- The following versions are no longer available in the Extended channel:
	- 1.31.14-gke.2246000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.31.14-gke.2543000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.32.13-gke.1930000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.32.13-gke.2231000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.33.13-gke.1109000
		- 1.34.9-gke.1322000
		- 1.35.6-gke.1258000
		- 1.36.2-gke.1346000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.30 to [1.31.14-gke.2437000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.31 to [1.31.14-gke.2437000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
				- 1.32 to [1.32.13-gke.2137000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
				- 1.33 to [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.9-gke.1610000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.35 to [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
				- 1.36 to [1.36.2-gke.2064000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362)

**Google SecOps**

Feature

**\[Spotlight Feature\] Monitor your data latency with the Health Hub**

This feature is in public preview. The **Health Hub** now includes two new tables to track the ingestion latency at both the source level and the log-type level. In addition, you can select a specific source or log type to open the **Data Health Deep Dive** page and view detailed information about ingestion latency. For more information, see [Monitor health of data sources](https://docs.cloud.google.com/chronicle/docs/reports/data-health-monitoring-and-troubleshooting-dashboard).

Key capabilities include:

- **Improve end-to-end visibility and reduce mean time to debug (MTTD):** Google SecOps calculates latency at both the source level and the log type level to improve end-to-end visibility and help reduce the mean time to debug (MTTD) for delayed logs.
- **Monitor ingestion latency by source:** View the ingestion latency for each individual data source.
- **Monitor ingestion latency by log type:** View the ingestion latency for each individual log type.
- **View detailed information about ingestion latency:** Select a specific source or log type to open the **Data Health Deep Dive** page and view detailed information about ingestion latency.

**Identity and Access Management** Feature

You can use custom constraints with Organization Policy to provide more granular control over specific fields for Agent Identity resources, such as `agentidentity.googleapis.com/AuthProvider`. For more information, see [Use custom organization policies for Agent Identity](https://docs.cloud.google.com/iam/docs/agent-identity-custom-constraints). This feature is in [GA](https://cloud.google.com/products#product-launch-stages).

Feature

Agent Identity VPC Service Controls (VPC Service Controls) integration is [generally available](https://cloud.google.com/products#product-launch-stages). You can add the Agent Identity API (`agentidentity.googleapis.com`) and Agent Identity Credentials API (`agentidentitycredentials.googleapis.com`) to a service perimeter and specify agent identities in ingress and egress rules.

For more information, see [Agent Identity overview](https://docs.cloud.google.com/iam/docs/agent-identity-overview).

**VPC Service Controls**

Feature

[Generally available (GA)](https://cloud.google.com/products#product-launch-stages) support for the following integrations:

- [Agent Identity API](https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_agent_identity)
- [Agent Identity Credentials API](https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_agent_identity_credentials)

## August 13, 2026

**Apigee X** Announcement

On August 13th, 2026, we began maintenance updates of Apigee instances [configured for maintenance windows](https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows).

If you set a preferred window for maintenance for your instance, and your instance version is below **1-18-0-apigee-2**, your instance will be updated to **1-18-0-apigee-2** within the next seven to 21 days. A notification containing the expected date of upgrade will be sent within the next two business days.

For more information on participating in scheduled maintenance windows, see [Maintenance overview](https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance) and [Manage Apigee instance maintenance windows](https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/maintenance-windows).

Announcement

On August 13th, 2026, we released an updated version of Apigee (1-18-0-apigee-3).

Fixed

| Bug ID | Description |
| --- | --- |
| **532147587** | To fix forward proxy support. |
| **537657987** | Fixed a bug where watcher failed to reconcile all routes if an environment was not found in the control plane. |
| **543022076** | Google Cloud BOM upgrade (protobuf 4.x, gRPC 1.81, Guava 33.5). One user-visible change: a malformed inbound gRPC request frame is now reported to the client as grpc-status INTERNAL(13) and recorded in analytics as x-apigee.grpc.status=13, where it was previously an Apigee ServiceUnavailable fault seen as UNAVAILABLE(14) with no x-apigee.grpc.status recorded. Otherwise no user facing impact, but any prod issue related to gcp, protobuf or gRPC may relate to this. |
| **542242046** | Fixed LLMTokenQuota metering the request against an arbitrary quota bucket when the API Product declared multiple models and the request carried no model. |
| **531731614** | Apigee analytics fields ai\_llm\_response\_token\_count, ai\_llm\_prompt\_token\_count, ai\_llm\_model\_name, and ai\_llm\_model\_provider are available in the Custom Report when LLMTokenQuota and PromptTokenLimit policies are used in Apigee proxies. |
| **492044413** | LLMTokenQuota resolves the model from the API Product LLM Operation when LLMModelSource is omitted and the request body has no model field. |
| **67169710** | Adds an opt-in \<DynamicClientIdSupported> boolean XML element to the OAuthV2 policy. When true, AbstractOAuthStepExecution.extractClientDetails() preserves any non-empty ClientID/ClientSecret already present on the OAuthClientContext. |
| **531731614** | Apigee auto identifies the providers and publishes them to analytics. |
| **537396574** | Added feature to rotate the apigee-ca certificate. |
| **540861752** | Aligned the ApigeeDeployment conversion hub with its v1alpha3 storage version. Internal change; no effect on existing ApigeeDeployment resources. |
| **540861752** | Aligned the ApigeeDeployment custom resource's conversion hub with its v1alpha3 storage version. This internal change does not affect existing ApigeeDeployment resources. |
| **N/A** | Updates to infrastructure and libraries. |

Security

| Bug ID | Description |
| --- | --- |
| **535928300** | **Security fix for Apigee.** Fixed a security issue in JWT refresh token revocation handling. |
| **539515020** | **Security fix for Apigee.** Fixed a security issue in the MessageValidation policy. |
| **535928530** | **Security fix for Apigee.** Fixed a security issue in the OAuthV2 policy. |
| **535683286** | **Security fix for Apigee.** Fixed a security issue in HTTP target interim-response handling. |
| **N/A** | **Security fix for Apigee infrastructure.** |

**Backup and DR** Feature

You can now configure scheduled, application-consistent backups and point-in-time recovery (PITR) workflows for self-managed databases (including IBM Db2, SAP HANA, SAP ASE, SAP IQ, SAP MaxDB, PostgreSQL, MySQL, and MariaDB) running on Compute Engine Linux instances.

This feature uses the bring-your-own-script guest-flush framework to quiesce the database before snapshot creation, ensuring transaction consistency and eliminating data corruption risks. Additionally, you can configure dedicated Persistent Disk backups for database archive logs to enable point-in-time recovery.

For more information, see [Configure application-consistent backups](https://docs.cloud.google.com/backup-disaster-recovery/docs/cloud-console/compute/application-consistent-backups-for-self-managed-databases).

**BigQuery** Feature

BigQuery pipelines now support automated metadata enrichment, allowing you to define semantic metadata directly in SQLX configurations for synchronization with Knowledge Catalog. In addition, the Data Engineering Agent proactively generates this metadata based on your intent or context. For more information, see [Metadata enrichment and data quality scorecard integration](https://docs.cloud.google.com/bigquery/docs/manage-pipelines#metadata-scorecard). This feature is in [Preview](https://cloud.google.com/products#product-launch-stages).

**Cloud SQL for MySQL**

Feature

[Cloud SQL for MySQL 9.7](https://docs.cloud.google.com/sql/docs/mysql/db-versions) is generally available ([GA](https://cloud.google.com/products#product-launch-stages)).

For more information about the differences between MySQL 9.7 and previous versions, review the [MySQL 9.7 Release Notes](https://dev.mysql.com/doc/relnotes/mysql/9.7/en/).

By default, if you specify MySQL 9.7 as the version when you create a Cloud SQL instance (either primary or replica) using the gcloud CLI, the Google Cloud console, or the REST API, then the Cloud SQL edition is Cloud SQL Enterprise Plus edition.

This release introduces support for key MySQL 9.7 capabilities, including:

- [**Vector search**](https://docs.cloud.google.com/sql/docs/mysql/vector-search#version-differences): support for the community-standard vector storage format combined with advanced approximate nearest neighbor (ANN) vector indexing in Cloud SQL.
- [**Hypergraph optimizer**](https://blogs.oracle.com/mysql/the-hypergraph-optimizer-is-now-available-in-mysql-9-7-community-edition): an alternative join-planning framework designed for complex, multi-table queries. You can enable the hypergraph optimizer using an [optimizer switch](https://dev.mysql.com/doc/refman/9.7/en/switchable-optimizations.html).
- [**JSON Duality Views**](https://dev.mysql.com/doc/refman/9.7/en/json-duality-views.html): a feature that bridges relational SQL and hierarchical JSON document models to interact with the same underlying data.
- **Upgrade and migration paths**: support for [in-place major version upgrade](https://docs.cloud.google.com/sql/docs/mysql/upgrade-major-db-version-inplace) from Cloud SQL for MySQL 8.4 and [migrations from MySQL 8.4 using the Database Migration Service (DMS)](https://docs.cloud.google.com/database-migration/docs/mysql/migration-src-and-dest#cross-version-support).

### Flag updates for MySQL 9.7

Additionally, this release introduces several database flag changes.

| MySQL database flag | Action | Details |
| --- | --- | --- |
| `activate_mandatory_roles` | Added / Supported | Exposes mandatory roles configuration. Default is ON. |
| `innodb_native_foreign_keys` | Added / Supported | Exposes SQL layer foreign key handling configuration. |
| `table_open_cache_triggers` | Added / Supported | Configures trigger cache size limits. |
| `connection_memory_status_limit` | Added / Supported | Sets limit configurations on connection memory. |
| `global_connection_memory_status_limit` | Added / Supported | Sets global limit configurations on connection memory. |
| `performance_schema_max_logger_classes` | Added / Supported | Sets limits for performance schema logger classes. |
| `caching_sha2_password_proxy_users` | Added / Supported | Configures proxy users support for caching SHA-2. |
| `caching_sha2_password_enforce_storage_format` | Added / Supported | Enforces storage format rules for caching SHA-2. |
| `caching_sha2_password_storage_format` | Added / Supported | Sets storage format defaults for caching SHA-2. |
| `innodb_log_file_size` | Removed | Flag not supported in MySQL 9.7 and later. |
| `innodb_log_files_in_group` | Removed | Flag not supported in MySQL 9.7 and later. |
| `innodb_undo_tablespaces` | Removed | Flag not supported in MySQL 9.7 and later. |
| `mysql_native_password_proxy_users` | Removed | Flag not supported in MySQL 9.7 and later. |
| `replica_parallel_type` | Removed | Flag not supported in MySQL 9.7 and later. |
| `slave_parallel_type` | Removed | Flag not supported in MySQL 9.7 and later. |
| `temptable_use_mmap` | Removed | Flag not supported in MySQL 9.7 and later. |

For more information about MySQL database flags, see [Configure database flags](https://docs.cloud.google.com/sql/docs/mysql/flags).

**Data Studio** Announcement

The following features are rolling out over the next week.

Feature

**Fullscreen charts**

You can view individual charts in fullscreen mode. Click the fullscreen button in the chart header to expand the chart. This feature is not available for scorecards and gauge charts.

Feature

**Rotate components**

You can rotate text boxes, images, and shapes in Data Studio. Report creators can rotate these components on a non-responsive canvas and can reset the rotation to 0 degrees.

Feature

**Center labels on stacked bar charts**

You can position labels in the center of stacked bar charts. If insufficient space is available to center the label within the bar, the label is displayed outside the bar.

For more information, see the [Bar chart and column chart reference](https://docs.cloud.google.com/data-studio/bar-chart-and-column-chart-reference).

Feature

**Search for settings**

You can search for settings in the **Setup** and **Style** tabs of the [properties panel](https://docs.cloud.google.com/data-studio/properties-panel).

Feature

**Copy chart as image**

You can copy a chart as a PNG image to your clipboard.

Feature

**Bubble chart border color**

You can modify the border color of bubbles in bubble charts.

**Dataform** Feature

Dataform workflows and BigQuery pipelines now support automated metadata enrichment for BigQuery tables and views, allowing you to define semantic metadata directly in SQLX configurations for synchronization with the Knowledge Catalog. For more information, see [Add metadata for Knowledge Catalog](https://docs.cloud.google.com/dataform/docs/create-tables#add-metadata). This feature is in [Preview](https://cloud.google.com/products#product-launch-stages).

**Error Reporting** Announcement

Error Reporting can report stack traces collected from Rust applications using [`std::backtrace`](https://doc.rust-lang.org/std/backtrace/index.html). To enable, set the `RUST_BACKTRACE=1` environment variable and make sure debug symbols are enabled.

For more information, see [ReportedErrorEvent](https://docs.cloud.google.com/error-reporting/reference/rest/v1beta1/projects.events/report.html?rep_location=global#reportederrorevent).

**Gemini Enterprise**

Feature

**Gemini Enterprise: Create, upload, and share custom skills**

Skills are reusable custom instructions that help the Gemini Enterprise assistant perform specific tasks. End users can create, upload, and share skills. To enable this feature, administrators must turn on the skills and skill-sharing settings in **Feature Management**. Administrators can also configure skill availability and approve skill-sharing requests.

This feature is generally available (GA). For more information, see the following:

- Learn how to [create and manage skills](https://docs.cloud.google.com/gemini/enterprise/docs/skills) as a Gemini Enterprise end user.
- Learn how to [manage skills](https://docs.cloud.google.com/gemini/enterprise/docs/manage-skills) as a Gemini Enterprise administrator.

Feature

**Gemini Enterprise: Use Gemini 3.7 Flash**

Gemini 3.7 Flash is generally available (GA) in the `global`, `us`, and `eu` regions. To make Gemini 3.7 Flash available to users in the Gemini Enterprise app, administrators must turn on the **Gemini 3.7 Flash** feature toggle in the Google Cloud console.

For in-country regions where the model isn't supported, administrators can still enable the model by confirming a warning that traffic is routed to the `global` endpoint, which doesn't support regional data residency.

Gemini 3.7 Flash is also available in Agent Designer workflow agents. Updates take up to a day to appear in workflow agents.

For more information, see:

- [Manage features on the web app](https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features)
- [Data residency for Gemini Enterprise Standard and Plus Editions and Gemini Notebook Enterprise](https://docs.cloud.google.com/gemini/enterprise/docs/locations)

Announcement

**Gemini Enterprise: Gemini 3.7 Flash availability in mobile app**

Gemini 3.7 Flash is not available in the Gemini Enterprise mobile app. A new release note will be added when the Gemini 3.7 Flash rollout for the Gemini Enterprise mobile app is complete.

**Gemini Enterprise Agent Platform** Feature

**Gemini 3.7 Flash is generally available**

[Gemini 3.7 Flash](https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-7-flash) is now generally available (GA) and available for production use. This model is our first model to enable [agentic video processing](https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/capabilities/video-understanding#agentic-video-processing) enabled by default.

For more information on 3.7 Flash, see the [model page](https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-7-flash).

Feature

**Agent Runtime: ADK telemetry metrics**

Agents deployed to Agent Runtime with Agent Development Kit (ADK) 2.6.0 or later can emit `gen_ai` application metrics that follow OpenTelemetry's generative AI semantic conventions. Set the `GOOGLE_CLOUD_AGENT_ENGINE_ENABLE_TELEMETRY` environment variable to export these metrics to Cloud Monitoring as user-defined metrics, alongside agent traces and logs.

For more information, see [Set up monitoring](https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/runtime/monitoring#adk-metrics).

**Google SecOps** Announcement

**Scheduled Maintenance**

SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 16. During this window, your system will experience a brief period of downtime. No customer action is required.

**Google SecOps SOAR** Announcement

**Scheduled Maintenance**

SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 16. During this window, your system will experience a brief period of downtime. No customer action is required.

**Memorystore for Valkey** Feature

You can [migrate workloads](https://docs.cloud.google.com/memorystore/docs/valkey/migrate-workloads) from self-managed Redis and Valkey instances running on Google Cloud to Memorystore for Valkey. This feature is [Generally Available](https://docs.cloud.google.com/products#product-launch-stages).

**Security Command Center** Feature

[AI Protection](https://docs.cloud.google.com/security-command-center/docs/ai-protection-overview) supports data residency in the Kingdom of Saudi Arabia (KSA) for all Security Command Center service tiers.

For more information, see [Planning for data residency](https://docs.cloud.google.com/security-command-center/docs/data-residency-support).

**Sensitive Data Protection** Feature

The `ANTHROPIC_API_KEY`, `GEMINI_API_KEY`, and `OPENAI_API_KEY` infoType detectors are available in all regions. For more information about all built-in infoTypes, see the [InfoType detector reference](https://cloud.google.com/dlp/docs/infotypes-reference).

**VPC Service Controls**

Feature

**VPC Service Controls feature (Status: [Preview](https://cloud.google.com/products#product-launch-stages)):** Support for optimizing service perimeters using the VPC Service Controls recommender is available.

The recommender detects architectural risks and perimeter misconfigurations, including the following:

- **Critical resources at risk of exfiltration**: Identifies active and sensitive services (such as BigQuery and Cloud Storage) operating outside service perimeters.
- **Unconfigured VPC accessible services**: Identifies perimeters that leave APIs unrestricted from within the security boundary.
- **Misconfigured VPC accessible services**: Identifies mismatches between allowed accessible APIs and restricted services inside a perimeter.

For more information, see [Optimize perimeters with recommender](https://docs.cloud.google.com/vpc-service-controls/docs/recommender).

**Vertex AI Search** Feature

**Agent Search: Gemini 3.5 Flash answer generation**

You can generate answers with the Gemini 3.5 Flash model.

For more information, see [Answer generation model versions and lifecycle](https://docs.cloud.google.com/generative-ai-app-builder/docs/answer-generation-models) and [Gemini 3.5 Flash](https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-5-flash).

## August 12, 2026

**Apigee API hub** Feature

**Configure and deploy MCP servers with gcloud CLI**

You can use the `gcloud apihub locations configure-and-deploy-server` command to configure and deploy API hub Model Context Protocol (MCP) servers to an attached Apigee runtime. Define MCP tools inline or by referencing a YAML or JSON specification file to expose your API hub operations for agent integrations.

For more information, see [gcloud CLI for API hub](https://docs.cloud.google.com/apigee/docs/apihub/gcloud-cli-apihub).

**BigQuery** Announcement

Table Explorer behavior has moved to the **Reference** panel. Table Explorer has been deprecated. For more information, see "Use the Reference panel" in [Run a query](https://docs.cloud.google.com/bigquery/docs/running-queries#use-reference-panel).

**Bigtable** Feature

You can use parameterized views in Bigtable to dynamically filter data ranges for logical views based on application context and mitigate SQL injection risks. This feature is [generally available (GA)](https://cloud.google.com/products#product-launch-stages). For more information, see [Parameterized views overview](https://docs.cloud.google.com/bigtable/docs/parameterized-views-overview).

Feature

You can use the `CLUSTER_ATTRIBUTE()` filter to restrict continuous materialized view processing to specific clusters. This function lets you isolate views within an instance. This feature is [generally available (GA)](https://cloud.google.com/products#product-launch-stages). For more information, see [Non-deterministic SQL functions](https://docs.cloud.google.com/bigtable/docs/continuous-materialized-views#non-deterministic-functions).

**Cloud Trace**

Feature

The following remote MCP servers automatically generate a trace span for `tools/call` operations. These spans can help you understand the behavior of your agentic applications. For more information, see [Investigate MCP calls using Trace](https://docs.cloud.google.com/stackdriver/docs/instrumentation/trace-remote-mcp-server-calls).

- Cloud Billing
- Personalized Service Health

Feature

Google Cloud Observability automatically generates trace exemplars for charts on custom dashboards that display the result of a SQL query when the query runs against your trace data and satisfies some constraints. The exemplars link the SQL query result to specific traces. This feature is in [Preview](https://docs.cloud.google.com/products#product-launch-stages).

For more information, see [Generate and display trace exemplars](https://docs.cloud.google.com/trace/docs/analytics-chart#show-trace-exemplars).

**Cloud Workstations** Feature

Cloud Workstations supports [Compute Engine suspend and resume](https://docs.cloud.google.com/compute/docs/instances/suspend-resume-instance) in Preview. You can configure workstation VMs to suspend when they reach their idle timeouts, referred to as auto-sleep in the Google Cloud Console, rather than shutting down and deleting the VM, by using the [IdleAction](https://docs.cloud.google.com/workstations/docs/reference/rest/v1beta/projects.locations.workstationClusters.workstationConfigs#idleaction) workstation configuration setting.

**Gemini Enterprise** Feature

**Gemini Enterprise: GitHub connector with data federation**

The GitHub connector with data federation is generally available (GA) in Gemini Enterprise. The connector lets you search and act on GitHub repositories, issues, and pull requests directly from the Gemini Enterprise agent, with tool actions such as creating branches, adding issue comments, merging pull requests, and pushing files.

For more information, see the [Connect GitHub with data federation](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/github) documentation.

Feature

**Gemini Enterprise: AlphaEvolve HPC solution**

The AlphaEvolve HPC solution provides a distributed, containerized infrastructure for running large-scale evolutionary code optimization experiments on Google Cloud. If your evaluations require specialized hardware or exceed the resource limits of a single machine, use the AlphaEvolve HPC solution.

For more information, see [AlphaEvolve for HPC use cases](https://docs.cloud.google.com/gemini/enterprise/docs/alphaevolve/developer-guide/use-alphaevolve-hpc).

**Gemini Enterprise Agent Platform**

Feature

**CodeMender CLI: Sandbox enabled by default**

This release updates the CodeMender CLI default behavior:

- **Sandbox enabled by default**: The CLI now runs commands inside the process-level sandbox by default to protect your workstation. You can disable the sandbox in your `config.yaml`, by passing `--sandbox=false` to CLI commands, or bypass it using the `--unrestricted` flag.

For more information, see [Install the CLI and configure](https://docs.cloud.google.com/gemini-enterprise-agent-platform/codemender/set-up-environment).

**Google Kubernetes Engine**

Change

#### (2026-R33) Version updates

GKE cluster versions have been updated.

**New versions available for upgrades and new clusters.**

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see [GKE versioning and support](https://cloud.google.com/kubernetes-engine/versioning) and [About GKE cluster upgrades](https://cloud.google.com/kubernetes-engine/upgrades).

- The following versions are now available in the Rapid channel:
	- [1.33.13-gke.1414000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1079000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.7-gke.1027000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1244000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
		- [1.36.3-gke.1253000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- The following versions are no longer available in the Rapid channel:
	- 1.33.13-gke.1269000
		- 1.34.9-gke.1610000
		- 1.35.6-gke.1641000
		- 1.36.2-gke.2281000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1329000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.33 to [1.34.9-gke.1655000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.34 to [1.35.6-gke.1710000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1329000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.9-gke.1655000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.35 to [1.35.6-gke.1710000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)

- Version [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
	- [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1610000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
		- [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
		- [1.36.2-gke.2064000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362)
- The following versions are no longer available in the Regular channel:
	- 1.33.13-gke.1101000
		- 1.34.9-gke.1287000
		- 1.35.6-gke.1250000
		- 1.36.2-gke.1498000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.33 to [1.34.9-gke.1322000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.34 to [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.9-gke.1322000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.35 to [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)

- The following versions are now available in the Stable channel:
	- [1.33.13-gke.1101000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1287000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
		- [1.35.5-gke.1163012](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355)
		- [1.35.5-gke.1241004](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355)
		- [1.35.6-gke.1250000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
- The following versions are no longer available in the Stable channel:
	- 1.33.12-gke.1270000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.34.9-gke.1131000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1011000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1011000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)

- Version [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
	- [1.31.14-gke.2246000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.31.14-gke.2437000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.31.14-gke.2543000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.32.13-gke.1930000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.32.13-gke.2137000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.32.13-gke.2231000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1610000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
		- [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
		- [1.36.2-gke.2064000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362)
- The following versions are no longer available in the Extended channel:
	- 1.30.14-gke.2767000
		- 1.30.14-gke.2816000
		- 1.30.14-gke.2866000
		- 1.31.14-gke.2169000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.31.14-gke.2233000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.31.14-gke.2456000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.32.13-gke.1844000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.32.13-gke.1913000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.32.13-gke.2175000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.33.13-gke.1101000
		- 1.34.9-gke.1287000
		- 1.35.6-gke.1250000
		- 1.36.2-gke.1498000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.30 to [1.31.14-gke.2246000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.31 to [1.31.14-gke.2246000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
				- 1.32 to [1.32.13-gke.1930000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
				- 1.33 to [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.9-gke.1322000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.35 to [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)

- Version [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation.
- The following versions are now available:
	- [1.33.13-gke.1414000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1079000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.5-gke.1163012](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355)
		- [1.35.5-gke.1241004](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355)
		- [1.35.7-gke.1027000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1244000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
		- [1.36.3-gke.1253000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- The following node versions are now available:
	- [1.31.14-gke.2543000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.32.13-gke.2231000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.33.13-gke.1414000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1079000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.7-gke.1027000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1244000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
		- [1.36.3-gke.1253000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- The following versions are no longer available:
	- 1.33.12-gke.1270000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.34.9-gke.1131000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.6-gke.1127000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.36.2-gke.2281000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.35 to [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)

Security

#### (2026-R33) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the **Security** release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

| GKE version | Container-Optimized OS version | Details |
| --- | --- | --- |
| 1.31.14-gke.2543000 | cos-117-18613-675-28 | [cos-117-18613-675-28 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-675-28_) |
| 1.32.13-gke.2231000 | cos-117-18613-675-28 | [cos-117-18613-675-28 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-675-28_) |
| 1.33.13-gke.1414000 | cos-121-18867-528-21 | [cos-121-18867-528-21 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-528-21_) |
| 1.34.10-gke.1079000 | cos-125-19216-532-42 | [cos-125-19216-532-42 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-532-42_) |
| 1.35.7-gke.1027000 | cos-125-19216-532-25 | [cos-125-19216-532-25 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-532-25_) |
| 1.36.3-gke.1244000 | cos-129-19506-299-60 | [cos-129-19506-299-60 release notes](https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-299-60_) |

Change

#### (2026-R33) Version updates

- The following versions are now available in the Stable channel:
	- [1.33.13-gke.1101000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1287000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
		- [1.35.5-gke.1163012](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355)
		- [1.35.5-gke.1241004](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355)
		- [1.35.6-gke.1250000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
- The following versions are no longer available in the Stable channel:
	- 1.33.12-gke.1270000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.34.9-gke.1131000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1011000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1011000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)

Change

#### (2026-R33) Version updates

- Version [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation in the Regular channel.
- The following versions are now available in the Regular channel:
	- [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1610000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
		- [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
		- [1.36.2-gke.2064000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362)
- The following versions are no longer available in the Regular channel:
	- 1.33.13-gke.1101000
		- 1.34.9-gke.1287000
		- 1.35.6-gke.1250000
		- 1.36.2-gke.1498000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.33 to [1.34.9-gke.1322000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.34 to [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.9-gke.1322000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.35 to [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)

Change

#### (2026-R33) Version updates

- The following versions are now available in the Rapid channel:
	- [1.33.13-gke.1414000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1079000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.7-gke.1027000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1244000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
		- [1.36.3-gke.1253000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- The following versions are no longer available in the Rapid channel:
	- 1.33.13-gke.1269000
		- 1.34.9-gke.1610000
		- 1.35.6-gke.1641000
		- 1.36.2-gke.2281000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Rapid channel. This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1329000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.33 to [1.34.9-gke.1655000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.34 to [1.35.6-gke.1710000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1329000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.9-gke.1655000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.35 to [1.35.6-gke.1710000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)

Change

#### (2026-R33) Version updates

- Version [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation.
- The following versions are now available:
	- [1.33.13-gke.1414000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1079000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.5-gke.1163012](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355)
		- [1.35.5-gke.1241004](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355)
		- [1.35.7-gke.1027000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1244000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
		- [1.36.3-gke.1253000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- The following node versions are now available:
	- [1.31.14-gke.2543000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.32.13-gke.2231000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.33.13-gke.1414000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.10-gke.1079000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v13410)
		- [1.35.7-gke.1027000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1357)
		- [1.36.3-gke.1244000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
		- [1.36.3-gke.1253000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1363)
- The following versions are no longer available:
	- 1.33.12-gke.1270000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.34.9-gke.1131000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.35.6-gke.1127000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.36.2-gke.2281000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support). This version will be removed in 90 days, or at the end of support, if sooner.
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.32 to [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.33 to [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.35 to [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)

Change

#### (2026-R33) Version updates

- Version [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356) is now the default version for cluster creation in the Extended channel.
- The following versions are now available in the Extended channel:
	- [1.31.14-gke.2246000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.31.14-gke.2437000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.31.14-gke.2543000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- [1.32.13-gke.1930000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.32.13-gke.2137000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.32.13-gke.2231000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
		- [1.33.13-gke.1269000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
		- [1.34.9-gke.1610000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
		- [1.35.6-gke.1641000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)
		- [1.36.2-gke.2064000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1362)
- The following versions are no longer available in the Extended channel:
	- 1.30.14-gke.2767000
		- 1.30.14-gke.2816000
		- 1.30.14-gke.2866000
		- 1.31.14-gke.2169000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.31.14-gke.2233000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.31.14-gke.2456000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.32.13-gke.1844000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.32.13-gke.1913000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.32.13-gke.2175000 is [deprecated](https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support) in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.
		- 1.33.13-gke.1101000
		- 1.34.9-gke.1287000
		- 1.35.6-gke.1250000
		- 1.36.2-gke.1498000
- Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
	- GKE upgrades clusters to the following new minor versions if there are no factors, such as [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or deprecated APIs, preventing upgrades:
		- 1.30 to [1.31.14-gke.2246000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
		- GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has [maintenance exclusions](https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions) or other factors preventing minor version upgrades:
		- 1.31 to [1.31.14-gke.2246000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114)
				- 1.32 to [1.32.13-gke.1930000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213)
				- 1.33 to [1.33.13-gke.1109000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13313)
				- 1.34 to [1.34.9-gke.1322000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1349)
				- 1.35 to [1.35.6-gke.1258000](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1356)

**Google SecOps**

Feature

**\[Spotlight Feature\] Analyze feed activity with Cloud Logging**

This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project (BYOP) Google Cloud project. You can now monitor, debug, and troubleshoot Google SecOps ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in the Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.

This visibility into push- and pull-based ingestion mechanisms provides the following capabilities:

- **Investigate telemetry**: Use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console.
- **Debug feeds**: Use the **Debug with logs** option on the **Feed management** page to open **Logs Explorer** pre-filtered for a specific feed.
- **Filter routed logs**: Configure exclusion filters in the Log Router to exclude specific logs, such as Storage Transfer Service (STS) logs, from being routed to Cloud Logging.

For more information, see [Analyze feed activity with Cloud Logging](https://docs.cloud.google.com/chronicle/docs/ingestion/analyze-feed-activity-with-cloud-logging).

**Google SecOps Marketplace**

Feature

**CyberArk Credential Provider**: Version 5.0

- The following new job has been added:
	- **Sync Integration Credentials Job**

Feature

**Microsoft Graph Mail**: Version 45.0

- The following new actions have been added:
	- **Block Domain**
		- **Block Sender**
		- **Delete Inbox Rules**
		- **List Rules**
		- **Remove Block Domain**
		- **Remove Block Sender**

Feature

**Microsoft Graph Mail Delegated**: Version 22.0

- The following new actions have been added:
	- **Block Domain**
		- **Block Sender**
		- **Delete Inbox Rules**
		- **List Rules**
		- **Remove Block Domain**
		- **Remove Block Sender**

Change

**Active Directory**: Version 45.0

- Fixed an issue in the following action where entity properties were incorrectly reset on update:
	- **Enrich Entities**

Change

**AWS WAF**: Version 14.0

- Updated integration dependencies.

Change

**Cisco Umbrella**: Version 21.0

- Fixed an issue in the following action where entity attachment failed due to a bytes object serialization error:
	- **Get Domain Security Info**

Change

**CrowdStrike Falcon**: Version 81.0

- Added the ability to use device IDs as input parameters in the following actions:
	- **Hide Hosts**
		- **Contain Endpoint**
		- **Download File**
		- **Execute Command**
		- **Get Host Information**
		- **Lift Contained Endpoint**
		- **List Host Vulnerabilities**
		- **On-Demand Scan**
		- **Run Script**

Change

**Enrichment**

- Fixed an issue in the following action where unsupported entity types were selected during enrichment:
	- **Whois**

Change

**GitSync**

- Fixed an issue in the following action where the **Include Playbook Blocks** parameter was ignored when a folder allowlist was used:
	- **Push Playbook**

Change

**Microsoft 365 Defender**: Version 30.0

- Added support for GCC High tenants by dynamically constructing API token scopes and adding a configurable **API Root** parameter in the following connector:
	- **Microsoft 365 Defender - Incidents Connector**
- Improved error handling and alert processing mechanisms in the following job:
	- **Sync Alerts**

Change

**Microsoft Graph Mail**: Version 45.0

- Fixed an issue in the following action where an unhandled exception occurred when a user mailbox was not found:
	- **Get Mailbox Account Out Of Facility Settings**

Change

**Microsoft Graph Mail Delegated**: Version 22.0

- Fixed an issue in the following action where an unhandled exception occurred when a user mailbox was not found:
	- **Get Mailbox Account Out Of Facility Settings**

**Google SecOps SIEM**

Feature

**\[Spotlight Feature\] Analyze feed activity with Cloud Logging**

This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project (BYOP) Google Cloud project. You can now monitor, debug, and troubleshoot Google SecOps SIEM ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.

This visibility into push- and pull-based ingestion mechanisms provides the following capabilities:

- **Investigate telemetry**: Use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console.
- **Debug feeds**: Use the **Debug with logs** option on the **Feed management** page to open **Logs Explorer** pre-filtered for a specific feed.
- **Filter routed logs**: Configure exclusion filters in the Log Router to exclude specific logs, such as Storage Transfer Service (STS) logs, from being routed to Cloud Logging.

For more information, see [Analyze feed activity with Cloud Logging](https://docs.cloud.google.com/chronicle/docs/ingestion/analyze-feed-activity-with-cloud-logging).

**Identity and Access Management** Change

The workflow for creating workforce identity pool providers in the Google Cloud console changed. After submitting the initial provider configuration, the console directs you to a centralized page to configure provider attributes, including attribute mappings, attribute conditions, and extra attributes.

For more information, see [Manage workforce identity pools and providers](https://docs.cloud.google.com/iam/docs/manage-workforce-identity-pools-providers).

**Managed Service for Apache Spark**

Announcement

New [**Managed Service for Apache Spark** (formerly Google Cloud Serverless for Apache Spark) subminor runtime versions](https://docs.cloud.google.com/managed-spark/docs/concepts/versions/serverless-versions#supported-dataproc-serverless-for-spark-runtime-versions):

- 1.2.86
- 2.2.86
- 2.3.39

Key updates in these runtime versions include:

- **OpenLineage updates**: In the `2.3` runtime:
	- Upgraded OpenLineage to version `1.49` to support lineage for tables created using the Lakehouse Runtime catalog.
		- Fixed a segmentation fault when OpenLineage parses complex SQL query strings.

**Network Intelligence Center** Feature

[Connectivity Tests](https://docs.cloud.google.com/network-intelligence-center/docs/connectivity-tests/concepts/overview) supports using a Cloud Run job as a source endpoint for connectivity testing.

For more information, see [Test from a Cloud Run job to a destination](https://docs.cloud.google.com/network-intelligence-center/docs/connectivity-tests/how-to/running-connectivity-tests#test-jobs).

**Secret Manager** Fixed

Parameter Manager enforces the location organization policy (`constraints/gcp.resourceLocations`) on resources in the `global` location.

If your organization policy restricts allowed resource locations, you must explicitly allow the `global` location in the policy. Otherwise, attempts to create global resources fail.

This helps ensure that Parameter Manager consistently applies the location organization policy checks to global resources.

For more information, see [Defining resource locations](https://docs.cloud.google.com/organization-policy/restrict-locations).

## August 11, 2026

**Apigee hybrid**

Announcement

### v1.16.9

On August 11, 2026 we released an updated version of the Apigee hybrid software, v1.16.9.

- For information on upgrading, see [Upgrading Apigee hybrid to version v1.16.9](https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade).
- For information on new installations, see [The big picture](https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture).

Fixed

#### Fixed in this release

| Bug ID | Description |
| --- | --- |
| **514973778** | **Fixed an issue where the `SanitizeUserPrompt` and `SanitizeModelResponse` policies failed to tolerate unknown fields while parsing responses from the Model Armor Service.** |
| **543171828** | **Fixed an issue where the `apigee-logger` DaemonSet failed to schedule on cluster nodes without custom node labels due to a default `logger.nodeSelector` in the Helm chart.** |

Security

Various security and CVE fixes are included in this release.

**BigQuery** Feature

[Query templates](https://docs.cloud.google.com/bigquery/docs/query-templates) for data clean rooms are [generally available](https://cloud.google.com/products#product-launch-stages) (GA). Query templates allow data clean room owners and publishers to share predefined queries without exposing the underlying tables and views.

Additionally, [table parameters](https://docs.cloud.google.com/bigquery/docs/table-functions#table_parameters) in table-valued functions (TVFs) are [generally available](https://cloud.google.com/products#product-launch-stages) (GA). You can use the `ANY TABLE` type as a table parameter to create generic functions that accept tables of any structure.

**Cloud Run** Feature

Cloud Run NVIDIA L4 GPU driver version 580.x.x is available for [services](https://docs.cloud.google.com/run/docs/configuring/services/gpu), [jobs](https://docs.cloud.google.com/run/docs/configuring/jobs/gpu), and [worker pools](https://docs.cloud.google.com/run/docs/configuring/workerpools/gpu).

**Compute Engine** Feature

**Generally available**: Compute flexible committed use discounts (CUDs) are available for G2 and G4 GPU accelerator-optimized machine series. The supported resources include vCPUs, memory, Local SSD disks, and GPUs.

Compute flexible CUDs are spend-based CUDs that apply to eligible Google Cloud spend across Compute Engine, GKE, and Cloud Run. For G2 and G4 machine series, compute flexible commitments provide the flexibility to switch between eligible machine series and regions depending on your workload needs. For GPUs that belong to these machine series, compute flexible commitments don't require attached reservations.

For more information, see [Compute flexible CUDs](https://docs.cloud.google.com/compute/docs/instances/committed-use-discounts-overview#spend_based).

Security

A vulnerability (CVE-2026-6726) in the Trusted Computing Group's TPM 2.0 reference implementation code was discovered and is being addressed. For more information, see the [GCP-2026-054 security bulletin](https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-054).

**Confidential VM** Security

A vulnerability affecting Intel TDX firmware was discovered and is being addressed. For more information, see the [GCP-2026-053 security bulletin](https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/security-bulletins#gcp-2026-053).

**Container Optimized OS**

Change

### cos-beta-133-19999-0-28

| Kernel | Docker | Containerd | [GPU Drivers](https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus) |
| --- | --- | --- | --- |
| [COS-6.18.39](https://cos.googlesource.com/third_party/kernel/+/a70f21557a81969b982fcfa58dc76478e5dd4cae) | v29.4.3 | v2.3.2 | [See List](https://storage.googleapis.com/cos-tools/19999.0.28/lakitu/gpu_driver_versions.textproto) |

Change

### cos-129-19506-299-116

| Kernel | Docker | Containerd | [GPU Drivers](https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus) |
| --- | --- | --- | --- |
| [COS-6.12.94](https://cos.googlesource.com/third_party/kernel/+/e55e3beb430afda0e871fbacbc825fd78ca377e6) | v27.5.1 | v2.2.6 | [See List](https://storage.googleapis.com/cos-tools/19506.299.116/lakitu/gpu_driver_versions.textproto) |

Change

### cos-dev-138-20035-0-0

| Kernel | Docker | Containerd | [GPU Drivers](https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus) |
| --- | --- | --- | --- |
| [COS-6.18.41](https://cos.googlesource.com/third_party/kernel/+/292c022b57a02a84aa84cb97e809da06a7bbd8ac) | v29.4.3 | v2.3.2 | [See List](https://storage.googleapis.com/cos-tools/20035.0.0/lakitu/gpu_driver_versions.textproto) |

Feature

Added support for installing the Vast 4.5.8 NFS client drivers with cos-dkms.

Fixed

Added kernel patch to reduce bcache garbage collection sleep interval to prevent I/O stalls.

Feature

Added support for installing the Vast 4.5.8 NFS client drivers with cos-dkms.

Fixed

Added kernel patch to reduce bcache garbage collection sleep interval to prevent I/O stalls.

Fixed

Fixed CVE-2026-33186 in google-guest-agent.

Fixed

Added kernel patch to reduce bcache garbage collection sleep interval to prevent I/O stalls.

Fixed

Mask nfttables-restore.service to address time to ssh regression.

Security

Fixed CVE-2026-64227 in the Linux kernel.

Fixed

Mask nfttables-restore.service to address time to ssh regression.

Security

Fixed KCTF-8173f7e in the Linux Kernel.

Security

Fixed CVE-2026-64279 in the Linux kernel.

Fixed

Updated app-admin/node-problem-detector to v0.8.25.

Security

Fixed CVE-2026-64286 in the Linux kernel.

Security

Fixed KCTF-8173f7e in the Linux Kernel.

Security

Fixed CVE-2026-64287 in the Linux kernel.

Security

Upgraded net-libs/nghttp2 to 1.69.0 and fixed CVE-2026-58055.

Security

Fixed CVE-2026-64352 in the Linux kernel.

Security

Fixed CVE-2026-64375 in the Linux kernel.

Security

Fixed CVE-2026-64401 in the Linux kernel.

Security

Fixed CVE-2026-64413 in the Linux kernel.

Security

Fixed CVE-2026-64416 in the Linux kernel.

Security

Fixed CVE-2026-64476 in the Linux kernel.

Security

Fixed CVE-2026-64508 in the Linux kernel.

Security

Fixed CVE-2026-64530 in the Linux kernel.

Security

Fixed CVE-2026-64532 in the Linux kernel.

Security

Fixed CVE-2026-64533 in the Linux kernel.

Security

Fixed CVE-2026-64534 in the Linux kernel.

Security

Fixed CVE-2026-64535 in the Linux kernel.

Security

Fixed CVE-2026-64538 in the Linux kernel.

Security

Fixed CVE-2026-64542 in the Linux kernel.

Security

Fixed CVE-2026-64545 in the Linux kernel.

Security

Fixed CVE-2026-64546 in the Linux kernel.

Security

Fixed CVE-2026-64548 in the Linux kernel.

Security

Fixed CVE-2026-64552 in the Linux kernel.

Security

Fixed CVE-2026-64554 in the Linux kernel.

Security

Fixed CVE-2026-64555 in the Linux kernel.

Security

Fixed KCTF-8173f7e in the Linux Kernel.

Change

Runtime sysctl changes:

- Changed: net.ipv4.udp\_mem: 188034 250714 376068 -> 188034 250715 376068

Change

### cos-121-18867-528-58

| Kernel | Docker | Containerd | [GPU Drivers](https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus) |
| --- | --- | --- | --- |
| [COS-6.6.143](https://cos.googlesource.com/third_party/kernel/+/39754e5eb6a303ec0db05e7cefac442983d8b50d) | v27.5.1 | v2.0.10 | [See List](https://storage.googleapis.com/cos-tools/18867.528.58/lakitu/gpu_driver_versions.textproto) |

Fixed

Update dev-lang/go to 1.25.12.

Security

Fixed CVE-2026-64279 in the Linux kernel.

Security

Fixed CVE-2026-64319 in the Linux kernel.

Security

Fixed CVE-2026-64352 in the Linux kernel.

Security

Fixed CVE-2026-64375 in the Linux kernel.

Security

Fixed CVE-2026-64401 in the Linux kernel.

Security

Fixed CVE-2026-64413 in the Linux kernel.

Security

Fixed CVE-2026-64474 in the Linux kernel.

Security

Fixed CVE-2026-64476 in the Linux kernel.

Security

Fixed CVE-2026-64535 in the Linux kernel.

Security

Fixed KCTF-8173f7e in the Linux Kernel.

Change

### cos-117-18613-675-48

| Kernel | Docker | Containerd | [GPU Drivers](https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus) |
| --- | --- | --- | --- |
| [COS-6.6.143](https://cos.googlesource.com/third_party/kernel/+/8e2178b6ff2c1c86c3ea021ca7b3a8427b8384bf) | v24.0.9 | v1.7.34 | [See List](https://storage.googleapis.com/cos-tools/18613.675.48/lakitu/gpu_driver_versions.textproto) |

Fixed

Update dev-lang/go to 1.25.12.

Security

Fixed CVE-2026-64279 in the Linux kernel.

Security

Fixed CVE-2026-64319 in the Linux kernel.

Security

Fixed CVE-2026-64352 in the Linux kernel.

Security

Fixed CVE-2026-64375 in the Linux kernel.

Security

Fixed CVE-2026-64401 in the Linux kernel.

Security

Fixed CVE-2026-64413 in the Linux kernel.

Security

Fixed CVE-2026-64535 in the Linux kernel.

Security

Fixed CVE-2026-64548 in the Linux kernel.

Security

Fixed CVE-2026-64556 in the Linux kernel.

Security

Fixed KCTF-8173f7e in the Linux Kernel.

**Cortex Framework**

Announcement

### Release 7.0.2

Fixed

- Resolved security vulnerabilities in transitive dependencies by updating the following corresponding direct dependencies: `google-auth`, `google-cloud-bigquery`, `google-cloud-dataform`, `google-cloud-resource-manager`, `google-cloud-service-usage` and `google-cloud-storage`.

**Firestore** Feature

Firestore now supports the `asia-southeast3` Bangkok region.

For a full list of supported locations, see [Locations](https://docs.cloud.google.com/firestore/docs/locations).

**Firestore in Datastore mode** Feature

Firestore in Datastore mode (Datastore) now supports the `asia-southeast3` Bangkok region.

For a full list of supported locations, see [Locations](https://docs.cloud.google.com/datastore/docs/locations).

**Gemini Enterprise**

Feature

**Gemini Enterprise: New data stores and support for new actions (Public Preview)**

The following data stores are available in Public Preview in Gemini Enterprise:

- [Cisco Workspaces](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/cisco-workspaces)
- [Fibery](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/fibery)
- [Gong](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/gong)
- [Guru](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/guru)
- [Hex](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/hex)
- [LegalZoom](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/legalzoom)
- [Mercury](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/mercury-mcp)
- [Miro](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/miro)
- [Ramp](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/ramp-mcp)
- [Solve Intelligence](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/solve-intelligence)
- [Vanta](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/vanta)
- [Webex Meetings](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/webex-meetings)

You can search and read data from these data stores using natural language.

Additionally, the following data stores support new actions in Public Preview:

- [Airtable](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/airtable): Update records for a table.
- [Hex](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/hex): Create threads and continue threads.
- [Miro](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/miro): Create documents and update documents.
- [Smartsheet](https://docs.cloud.google.com/gemini/enterprise/docs/connectors/smartsheet): Add rows.

Feature

**Gemini Enterprise: Manage overages, spend limits, and costs for invoiced Cloud Billing accounts**

If your project has an [invoiced Cloud Billing account](https://docs.cloud.google.com/billing/docs/concepts#billing_account_types) and at least one active, non-free-trial subscription, administrators can enable overages, configure monthly spend limits, and monitor feature usage and costs in Gemini Enterprise:

- **Enable overages**: Allow users to continue using features at pay-as-you-go rates after reaching pooled quotas. Overages are supported for Standard, Plus, and Standard Emerging Market editions for customers with an invoiced Cloud Billing account and at least one active, non-free-trial subscription.
- **Set spend limits**: Configure monthly project spending caps and budget alert thresholds in Cloud Billing to prevent unexpected charges.
- **View feature usage and costs**: Track pooled quota consumption, pay-as-you-go usage, and 30-day billing trends on the Usage & Spending page in the Gemini Enterprise console and Cloud Billing console.

For more information, see:

- [Overview of overages and spend controls](https://docs.cloud.google.com/gemini/enterprise/docs/manage-costs-overview)
- [Configure overages and spend limits](https://docs.cloud.google.com/gemini/enterprise/docs/configure-overages)
- [View feature usage](https://docs.cloud.google.com/gemini/enterprise/docs/feature-usage)
- [View costs](https://docs.cloud.google.com/gemini/enterprise/docs/view-costs)
- [View Gemini Enterprise costs in Cloud Billing reports](https://docs.cloud.google.com/billing/docs/how-to/reports/gemini-enterprise-costs)
- [Find out your Cloud Billing account type and charging cycle](https://docs.cloud.google.com/billing/docs/how-to/billing-cycle#view-your-charging-cycle)

**Google Distributed Cloud (software only) for VMware** Announcement

Google Distributed Cloud (software only) for VMware 1.35.400-gke.81 is now available for download. To upgrade, see [Upgrade clusters](https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/how-to/upgrading). Google Distributed Cloud 1.35.400-gke.81 runs on Kubernetes v1.35.3-gke.400.

If you use a third-party storage vendor, check the listing of our previously-qualified [storage partners](https://docs.cloud.google.com/kubernetes-engine/enterprise/docs/resources/partner-storage).

After a release, it takes approximately 7 to 14 days for the version to become available for use with GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

Fixed

The following issues were fixed in 1.35.400-gke.81:

- Link to [Vulnerability fixes](https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/vulnerabilities) for the list of security vulnerabilities addressed in this release.
- Fixed an issue where user clusters remained stuck in a `Reconciling` state after an admin cluster upgrade. The admin cluster controller skipped reconciling legacy cluster lifecycle components during upgrades unless an initial migration annotation was set. If legacy user clusters still existed on the admin cluster, missing legacy API discovery (`cluster.k8s.io/v1alpha1`) caused controller reconciliation to stall. With this fix, the controller preserves legacy components as long as any legacy user clusters exist, and prunes them only after all user clusters have migrated to advanced clusters.
- Fixed an issue where `gkectl prepare` failed with a `permission denied` error when authenticating against a private container registry.
- Fixed an issue where retrying a user or admin cluster upgrade to advanced clusters caused etcd secret decryption failures.

**Google Distributed Cloud (software only) for bare metal** Announcement

Google Distributed Cloud (software only) for bare metal 1.35.400-gke.81 is now available for download. To upgrade, see [Upgrade clusters](https://docs.cloud.google.com/release-notes/how-to/upgrade). Google Distributed Cloud for bare metal 1.35.400-gke.81 runs on Kubernetes v1.35.3-gke.400.

After a release, it takes approximately 7 to 14 days for the version to become available for installations or upgrades with the GKE On-Prem API clients: the Google Cloud console, the gcloud CLI, and Terraform.

If you use a third-party storage vendor, check the listing of our previously-qualified [storage partners](https://docs.cloud.google.com/kubernetes-engine/enterprise/docs/resources/partner-storage).

Fixed

The following issues were fixed in 1.35.400-gke.81:

- Link to [Vulnerability fixes](https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities) for the list of security vulnerabilities addressed in this release.

**Spanner** Feature

For DML statements, Spanner now enforces the 80,000 mutation limit (including indexes) per statement rather than cumulatively across the transaction. This allows a transaction to execute multiple DML statements that collectively exceed the limit, as long as each individual statement remains under it. For the Mutation API, the 80,000 limit applies to all mutations in the commit. All transactions are still subject to the 100 MiB commit size limit.

## August 10, 2026

**BigQuery** Feature

BigQuery now supports the `gemini-3.1-flash-lite` and `gemini-3.5-flash` GA models, which are available for the `us`, `eu`, and `global` multi-regional endpoints. You can use these models in all generative AI functions. For information about how to specify a multi-regional endpoint and how endpoints are selected, read about [locations](https://docs.cloud.google.com/bigquery/docs/generative-ai-overview#locations) in the generative AI overview.

**Bigtable**

Libraries

#### 1.52.0 (2026-08-03)

##### Features

- **bigtable:** Add AFE picker (Simple / LeastInFlight / LeastLatency) ([#20204](https://github.com/googleapis/google-cloud-go/issues/20204)) ([bcbf714](https://github.com/googleapis/google-cloud-go/commit/bcbf71431d1742e2e13a13d1cbe8b0fc0433aede))
- **bigtable:** Add ClientConfig.DisableSession to opt out of session backend ([#20297](https://github.com/googleapis/google-cloud-go/issues/20297)) ([7ee5e44](https://github.com/googleapis/google-cloud-go/commit/7ee5e44e0304c5509b9b77fe0760d97771657cd9))
- **bigtable:** Add getClientConfigDirectAccessChecker for session pools ([#20209](https://github.com/googleapis/google-cloud-go/issues/20209)) ([3b8d30a](https://github.com/googleapis/google-cloud-go/commit/3b8d30adeaf03c8452207b056d69922646d63bf2))
- **bigtable:** Add NoOpChannelPrimer for session channel pools ([#20208](https://github.com/googleapis/google-cloud-go/issues/20208)) ([d055a8a](https://github.com/googleapis/google-cloud-go/commit/d055a8a1b23980ad4b53c0cd690e291c9aa6248c))
- **bigtable:** Add per-AFE sessionList for the two-tier session pool ([#20224](https://github.com/googleapis/google-cloud-go/issues/20224)) ([dbf0c3f](https://github.com/googleapis/google-cloud-go/commit/dbf0c3f3ea37279a2aa00803ded8e489229b15c9))
- **bigtable:** Add protoRowToRow conversion helper for TableShim ([#20257](https://github.com/googleapis/google-cloud-go/issues/20257)) ([1297143](https://github.com/googleapis/google-cloud-go/commit/1297143a4fab4bf58cbd0bd6e44db4653a818c47))
- **bigtable:** Add Session debug surface (observability fields + methods) ([#20211](https://github.com/googleapis/google-cloud-go/issues/20211)) ([d8d3e16](https://github.com/googleapis/google-cloud-go/commit/d8d3e160c3e63150ef5d14e83a2ea0fd25a7e214))
- **bigtable:** Add Session lifecycle (Start, Close, ForceClose, readLoop, heartBeatLoop) ([#20215](https://github.com/googleapis/google-cloud-go/issues/20215)) ([b9e53c6](https://github.com/googleapis/google-cloud-go/commit/b9e53c6276efe28428adfcd4671d7ac8c7e8d330))
- **bigtable:** Add Session struct + state machine ([#20117](https://github.com/googleapis/google-cloud-go/issues/20117)) ([09acbb3](https://github.com/googleapis/google-cloud-go/commit/09acbb37a385d2c6fca465adb70a3eb03ea4a38e))
- **bigtable:** Add session.Config.EnableDebug to gate sessionz debug state ([#20247](https://github.com/googleapis/google-cloud-go/issues/20247)) ([ce74c31](https://github.com/googleapis/google-cloud-go/commit/ce74c315d41371b0ddf2c1ba7342446695a53900))
- **bigtable:** Add SessionClient + SessionTable + lazyPool ([#20228](https://github.com/googleapis/google-cloud-go/issues/20228)) ([ab2c96c](https://github.com/googleapis/google-cloud-go/commit/ab2c96c3ed62514dcf6526bb32259267fbe63e97))
- **bigtable:** Add SessionPoolImpl (two-tier pool + scaling + debug) ([#20225](https://github.com/googleapis/google-cloud-go/issues/20225)) ([683eda8](https://github.com/googleapis/google-cloud-go/commit/683eda8c690fd2b948bd3b56777039d28421ee7c))
- **bigtable:** Rename session pool display to \<resource-id>-\<PERM> ([#20248](https://github.com/googleapis/google-cloud-go/issues/20248)) ([35e146e](https://github.com/googleapis/google-cloud-go/commit/35e146e25d2897082f2d1b78b9273087efd855fd))
- **bigtable:** Route Client.Open()-returned \*Table through the Diverter ([#20273](https://github.com/googleapis/google-cloud-go/issues/20273)) ([2b81c7d](https://github.com/googleapis/google-cloud-go/commit/2b81c7dc2d73739f4d5f87aa43cc9a3ac031822d))
- **bigtable:** State-based classification for abnormal session close ([#20243](https://github.com/googleapis/google-cloud-go/issues/20243)) ([f2905b7](https://github.com/googleapis/google-cloud-go/commit/f2905b793d062ae597d9c39597d15a680e9e9967))
- **bigtable:** TableShim fallback to classic on session UNIMPLEMENTED ([#20269](https://github.com/googleapis/google-cloud-go/issues/20269)) ([36540af](https://github.com/googleapis/google-cloud-go/commit/36540af84ab5f7360c5c1a92bbfb5a631d4c5cc6))
- **bigtable:** TTL-on-idle cache for per-resource session.TableAPI ([#20263](https://github.com/googleapis/google-cloud-go/issues/20263)) ([00b2a49](https://github.com/googleapis/google-cloud-go/commit/00b2a49de38fe600736cf10c496f85e082ae8871))
- **bigtable:** Wire Diverter on Client and route Open\* via TableShim ([#20256](https://github.com/googleapis/google-cloud-go/issues/20256)) ([b32fbd7](https://github.com/googleapis/google-cloud-go/commit/b32fbd7d02f835e8f83b4be1926e5826c27fa8a9))

##### Bug Fixes

- **bigtable:** AFE picker latency signal — subtract poolWait and compute TransportLatency = wire − backend at source ([#20281](https://github.com/googleapis/google-cloud-go/issues/20281)) ([bb8c4d5](https://github.com/googleapis/google-cloud-go/commit/bb8c4d56bf5bb53e5e1f1d510be326821fe4ddee))
- **bigtable:** Guard NewStream OnFinish against grpc-go double-fire ([#20295](https://github.com/googleapis/google-cloud-go/issues/20295)) ([b51da29](https://github.com/googleapis/google-cloud-go/commit/b51da29536de5aa59582d2a9633a07186f8636ae))
- **bigtable:** Real per-resource pool teardown on sessionTable.Close + cache close-race gate ([#20264](https://github.com/googleapis/google-cloud-go/issues/20264)) ([599aea9](https://github.com/googleapis/google-cloud-go/commit/599aea9e67ca2526b7822eb1e873e3aaf7b5124e))
- **bigtable:** Session.durations / session.uptime — set explicit histogram bucket boundaries ([#20276](https://github.com/googleapis/google-cloud-go/issues/20276)) ([97eee22](https://github.com/googleapis/google-cloud-go/commit/97eee225c412db9288bb7813e6b9cc856e6aba44))
- **bigtable:** SessionTableHandle self-heals across cache eviction ([#20296](https://github.com/googleapis/google-cloud-go/issues/20296)) ([0dd98cd](https://github.com/googleapis/google-cloud-go/commit/0dd98cd75383bd5902f3bec936d9ae68c64e6682))
- **bigtable:** Translate ctx errors to gRPC status on session vRPC ([#20299](https://github.com/googleapis/google-cloud-go/issues/20299)) ([0f3b2a5](https://github.com/googleapis/google-cloud-go/commit/0f3b2a519e07eccdfacad1129aa0fb69bc8f06e6))
- **bigtable:** Treat PingAndWarm NotFound as a successful prime ([#20219](https://github.com/googleapis/google-cloud-go/issues/20219)) ([a1557ad](https://github.com/googleapis/google-cloud-go/commit/a1557adec2fc8a579f70cdb4de5f959ceb8d51a1))

##### Performance Improvements

- **bigtable:** Delete periodic Tick loop; sizing is event-driven ([#20285](https://github.com/googleapis/google-cloud-go/issues/20285)) ([2c096bd](https://github.com/googleapis/google-cloud-go/commit/2c096bddf6fc5353a3804d222b3683a55eda13e5))
- **bigtable:** Drop pick\_lost\_race debug tag from CheckoutSession hot path ([#20280](https://github.com/googleapis/google-cloud-go/issues/20280)) ([bd0e400](https://github.com/googleapis/google-cloud-go/commit/bd0e400948a15639546f150d5d2b1a1a7ceb5741))

**Cloud Hub** Announcement

Starting September 15, 2026, the App Topology API transitions to a usage-based billing model that includes a daily free data usage allotment. For more information, see [App Topology pricing](https://docs.cloud.google.com/hub/docs/app-topology#pricing).

**Cloud Run functions** Feature

The [Cloud Run functions upgrade tool](https://docs.cloud.google.com/functions/1stgendocs/migrating/upgrade-gen1-functions) is in [General Availability](https://cloud.google.com/products#product-launch-stages). Use this tool to upgrade 1st gen functions to Cloud Run functions.

**Confidential Space** Announcement

A new Confidential Space image (260701) is available.

**Eventarc** Change

When configuring Eventarc triggers for Cloud Run destinations (including Cloud Run functions), you can specify a single delivery attempt with no retries. For more information, see [Retries for Cloud Run destinations](https://docs.cloud.google.com/eventarc/docs/retry-events#run-targets).

**Gemini**

Other

### Bug fixes in VS Code

Various bug fixes and minor product enhancements.

**Gemini Enterprise** Feature

**Gemini Enterprise: Export user data to a CSV file**

Gemini Enterprise administrators can export user data to a comma-separated values (CSV) file to sort, filter, and analyze records offline. This feature is generally available (GA).

For more information, see [Export user data](https://docs.cloud.google.com/gemini/enterprise/docs/licenses#export-user-data).

**Google Cloud Contact Center as a Service** Announcement

**Google Cloud CCaaS 6.0**

We've released version 6.0 of Google Cloud CCaaS.

Version 6.0 updates internal Google Cloud CCaaS infrastructure. It contains no customer-facing changes from version 5.2.

The timing of the update to your instance depends on the deployment schedule that you have chosen. For more information, see [Deployment schedules](https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules).

**Managed Service for Apache Airflow** Announcement

A new Managed Service for Apache Airflow release has started on **August 10, 2026**. Get ready for upcoming changes and features as we roll out the new release to all regions. This release is in progress at the moment. Listed changes and features might not be available in some regions yet.

Change

*(Managed Airflow Gen 3)* Adjusted the formula used to calculate the number of Airflow web server workers based on allocated CPU and memory resources. This update aligns with resource consumption changes in recent Airflow versions, improving web server stability.

Change

*(Airflow 3.2.2 and 2.11.1)* The `[api]rbac_bindings` Airflow configuration option is blocked and it isn't possible to override its value.

Change

New [images](https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-2) are available in Managed Airflow (Gen 2):

- [composer-2.17.10-airflow-2.11.1](https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-10-airflow-2-11-1) (default)
- [composer-2.17.10-airflow-2.10.5](https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-10-airflow-2-10-5)

**Managed Service for Apache Spark**

Fixed

**Managed Service for Apache Spark** (formerly Dataproc on Compute Engine):

A critical bug related to Conda channels has been fixed in-place in image versions `1.4.81`, `1.5.92`, `2.1.117`, and `2.2.85`. These image versions were released without pre-configured Conda channels.

**Required customer actions:** To comply with Google requirements, recreate the following resources if they were created using these image versions on or before August 10, 2026:

- Custom images
- Clusters

**Memorystore for Valkey** Feature

You can use the Google Cloud console to secure access to your instances by using [basic token-based authentication](https://docs.cloud.google.com/memorystore/docs/valkey/manage-basic-auth). This feature is available in [Preview](https://docs.cloud.google.com/products#product-launch-stages).

**Security Command Center** Feature

The integration of Security Command Center with [Application Design Center](https://docs.cloud.google.com/application-design-center/docs/overview) for application lifecycle security assessments is generally available ([GA](https://cloud.google.com/products#product-launch-stages)). Design-time findings are sent to Security Command Center on demand during deployment. This feature lets you filter findings by App Hub application at the app-enabled folder and project levels.

For more information, see [Application lifecycle security assessments](https://docs.cloud.google.com/security-command-center/docs/concepts-security-sources#application-security-assessments).

Feature

[Vulnerability Assessment for Google Cloud](https://docs.cloud.google.com/security-command-center/docs/vulnerability-assessment-google-cloud) is available in [General Availability](https://cloud.google.com/products#product-launch-stages).

**Spanner** Feature

Dynamic channel pooling (DCP) for gRPC channels in the Spanner Go and Java client libraries is generally available ([GA](https://cloud.google.com/products#product-launch-stages)).

DCP prevents performance issues from under-provisioned or over-provisioned channels and reduces configuration overhead. DCP is disabled by default.

For more information, see [Configure the number of sessions and gRPC channels in the pools](https://docs.cloud.google.com/spanner/docs/sessions#configure_the_number_of_sessions_and_grpc_channels_in_the_pools).

## August 09, 2026

**Agent Platform Workbench** Change

Installed latest packages from upstream dependencies.

Change

### 20260809-2330-rc0 Release

Change

Installed latest packages from upstream dependencies.

Change

### 20260809-2330-rc0 Release

Fixed

Fixed the Git panel's grayed out buttons which were disabled due to an issue with the Jupyter Lab's Git plugin introduced in version 0.54.0.

Change

### 20260809-2230-rc0 Release

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed the Git panel's grayed out buttons which were disabled due to an issue with the Jupyter Lab's Git plugin introduced in version 0.54.0.

Change

### 20260809-2230-rc0 Release

Change

Installed latest packages from upstream dependencies.

Change

### 20260809-2130-rc0 Release

Change

Updated the NVIDIA GPU driver on Workbench Debian 12 images from 580.65.06 to 580.126.20 for compatibility with the Debian 12 6.1.0-52 kernel.

Change

Installed latest packages from upstream dependencies.

Fixed

Fixed the Git panel's grayed out buttons which were disabled due to an issue with the Jupyter Lab's Git plugin introduced in version 0.54.0.

**Google SecOps**

Feature

**Updated rich-text editor**

Upgraded the rich-text editor across Google SecOps, including the Cases Wall, Use Case Upload dialog, Report Template dialog, and Dashboard Editor widget.

Key changes include:

- **Simplified typography**: Choose font sizes using semantic options (Small, Normal, Large, Huge). Legacy font sizes on existing text are preserved.
- **Streamlined tables**: You can insert or remove entire tables. Formatting inside table cells is no longer supported.
- **Toolbar cleanup**: Removed the Cut, Copy, and Paste buttons from the toolbar. Standard OS keyboard shortcuts remain supported.
- **Visual alignment**: Improved visual consistency between editor content during editing and after submission.

**Google SecOps SOAR** Announcement

Release 6.3.97 is being rolled out to the first phase of regions as listed [here](https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release).

This release contains internal and customer bug fixes.

Feature

**Updated rich-text editor**

Upgraded the rich-text editor across Google SecOps, including the Cases Wall, Use Case Upload dialog, Report Template dialog, and Dashboard Editor widget.

Key changes include:

- **Simplified typography**: Choose font sizes using semantic options (Small, Normal, Large, Huge). Legacy font sizes on existing text are preserved.
- **Streamlined tables**: You can insert or remove entire tables. Formatting inside table cells is no longer supported.
- **Toolbar cleanup**: Removed the Cut, Copy, and Paste buttons from the toolbar. Standard OS keyboard shortcuts remain supported.
- **Visual alignment**: Improved visual consistency between editor content during editing and after submission.

## August 08, 2026

**Google SecOps SOAR** Announcement

[Release 6.3.96](https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_02_2026) is now available for all regions.

## August 07, 2026

**AlloyDB for PostgreSQL** Feature

You can now sync tables from BigQuery into your AlloyDB instance, either as a one-time operation or on a periodic schedule. This feature (in [Preview](https://cloud.google.com/products#product-launch-stages)) lets you enable operational analytics that benefit from low-latency, transactional access to your data lake.

For more information, see [Sync BigQuery data to AlloyDB](https://docs.cloud.google.com/alloydb/docs/sync-bigquery-data-to-alloydb).

Feature

AlloyDB integration with BigQuery lets you connect your operational and analytical data through real-time data access (lakehouse federation), periodic data synchronization, and one-time table syncs. These features are in [Preview](https://cloud.google.com/products#product-launch-stages).

For more information, see [Choose how to access BigQuery data from AlloyDB](https://docs.cloud.google.com/alloydb/docs/choose-access-bigquery-data-from-alloydb).

**Cloud Billing**

Feature

**New filter and group-by option available in Cloud Billing Reports**

In **Billing Reports**, Cloud Billing has added the **Originating products** [*filter*](https://docs.cloud.google.com/billing/docs/how-to/reports#filter-by-orig-products) and [*Group by*](https://docs.cloud.google.com/billing/docs/how-to/reports#group-by-orig-product) to provide additional options that let you analyze and understand your costs. *Originating products* are Google Cloud products that cause usage in another product. For example, Gemini Enterprise is an originating product when it causes usage in the Gemini Enterprise app.

To help you **track and analyze your *AI spend***, the *Originating products* dimension is used in the following ways:

- You can use the *Originating products* filter and group by option to configure your Cloud Billing report to track and analyze your [Gemini Enterprise subscription and consumption costs](https://docs.cloud.google.com/billing/docs/how-to/reports/gemini-enterprise-costs).
- The *Originating products* dimension supports a new [*preset report*](https://docs.cloud.google.com/billing/docs/how-to/reports#preset_views) for quick report configuration, called [Gemini Enterprise costs by SKU](https://docs.cloud.google.com/billing/docs/how-to/reports/gemini-enterprise-costs#preset-report).
- When you are viewing your costs in the Gemini Enterprise console, on the *Gemini Enterprise > Usage & Spending* page, the *Originating products* dimension supports the functionality of the costs displayed on the [Gemini Enterprise Billing tab](https://docs.cloud.google.com/gemini/enterprise/docs/view-costs).

For more information, see the following resources:

- [Learn how to view Gemini Enterprise costs in Cloud Billing reports](https://docs.cloud.google.com/billing/docs/how-to/reports/gemini-enterprise-costs)
- [Learn more about analyzing billing data and cost trends with Reports](https://docs.cloud.google.com/billing/docs/how-to/reports)
- [Learn how to view Gemini Enterprise costs in the Gemini Enterprise console](https://docs.cloud.google.com/gemini/enterprise/docs/view-costs)

**Cloud Data Fusion**

Change

The Cloud SQL for MySQL and Cloud SQL for PostgreSQL plugins, version 1.11.14, are available in Cloud Data Fusion version 6.10.x. Version 1.12.5 of these plugins is available in Cloud Data Fusion version 6.11.x.

This release includes the following feature:

- You can now configure transaction isolation levels in the Cloud SQL for MySQL and Cloud SQL for PostgreSQL plugins. This configuration applies to both batch sources and sinks, providing more precise control over data consistency and database locking ([PLUGIN-1779](https://cdap.atlassian.net/browse/PLUGIN-1779)).

Change

The Windows Share Copy Action plugin version 2.12.5 is available in Cloud Data Fusion version 6.9.1 and later. Version 2.13.2 of this plugin is available in Cloud Data Fusion version 6.11.0 and later.

This release includes the following change:

- Added support for the modern SMBv2 and SMBv3 protocols to improve connection performance and reliability, while maintaining backward compatibility with pipelines that use SMBv1 ([PLUGIN-1960](https://cdap.atlassian.net/browse/PLUGIN-1960)).

**Cloud SQL for PostgreSQL** Change

Newly created instances configured with [high availability (HA)](https://docs.cloud.google.com/sql/docs/postgres/high-availability) now have [Knowledge Catalog (formerly Dataplex Universal Catalog)](https://docs.cloud.google.com/sql/docs/postgres/dataplex-catalog-integration) enabled by default.

Cloud SQL for PostgreSQL instances running on PostgreSQL version 14.0 or later send updates and metadata to Knowledge Catalog in near real-time.

You can either verify enablement or [disabl](https://docs.cloud.google.com/sql/docs/postgres/dataplex-catalog-integration#deactivate-dataplex-catalog)
