Google Cloud release notes

The following release notes cover the most recent changes over the last 60 days. For a comprehensive list of product-specific release notes, see the individual product release note pages.

You can also see and filter all release notes in the Google Cloud console or you can programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly: https://cloud.google.com/feeds/gcp-release-notes.xml

November 23, 2023

Application Integration

HubSpot trigger is now available in preview.

Chronicle SOAR

Release 6.2.40 is now in General Availability.

November 22, 2023

AlloyDB for PostgreSQL

Version 1.5.0 of the AlloyDB Auth Proxy client might fail to connect to AlloyDB instances created before mid-November, 2023.

To mitigate this issue, take either one of the following steps:

  • Use version 1.4.1 of the AlloyDB Auth Proxy client. You can download this version by following the instructions on Download the Auth Proxy client, replacing 1.5.0 or latest in the commands with 1.4.1.

  • Update any database flag on the affected instance. We recommend using the Google Cloud console to set and then clear a flag that doesn't require the instance to restart, such as autovacuum. For a full list of flags, see Supported database flags.

Anthos clusters on VMware

A vulnerability (CVE-2023-5717) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.

For more information, see the GCP-2023-046 security bulletin.

Chronicle SOAR

Release 6.2.41 is currently in Preview.

Jobs enhancement

The following features have been added:

  • Ability to sort the job execution table by time or status
  • Indication in the jobs queue for each failed job iteration

IDE's Live Autocomplete feature not working properly (ID #00250083)

Confidential VM Datastream

Datastream now supports SSL/TLS encryption for connections to PostgreSQL sources that don't require client certificates.

Google Kubernetes Engine

A vulnerability (CVE-2023-5717) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.

GKE clusters are impacted.

For more information, see the GCP-2023-046 security bulletin.

November 21, 2023

Anthos clusters on bare metal

Release 1.14.11

Anthos clusters on bare metal 1.14.11 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.14.11 runs on Kubernetes 1.25.

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

Application Integration Backup and DR

Backup and DR Service 11.0.8.454 is now available to update your backup/recovery appliance. Refer to these instructions to update your appliance.

SAP HANA databases running in Compute Engine instances can now be backed up as Persistent Disk snapshots of the Compute Engine instance. This feature is in Private Preview.

Added basic connector support for the following OSes. See Support matrix.

  • OEL 8.8, 9.1, and 9.2
  • RHEL 8.8 and 9.2
  • RHEL for SAP 8.8, 9.0, and 9.2
  • Rocky Linux 8.8, 9.0, 9.1, and 9.2
  • Rocky Linux Optimised for Google Cloud 8.8 and 9.2
  • SLES 15 SP5
  • SLES for SAP 15 SP5

Cloud Composer

Between January, 2024 and April, 2024 newly created Cloud Composer 2 environments will start using Python 3.11. After this change, Python 3.8 will no longer be available in new versions of Cloud Composer. If you upgrade an existing Cloud Composer 2 environment, the Python version will change to Python 3.11 as well.

The timing for Python 3.11 availability will be announced in January, 2024.

Cloud Data Loss Prevention

For BigQuery inspection jobs, when you set a sampling limit based on a percentage of the total number of table rows (rowsLimitPercent), Sensitive Data Protection can inspect more rows than expected. If you need to put a hard limit on the number of rows to scan, we recommend setting a maximum number of rows (rowsLimit) instead.

Cloud Spanner

Cloud Spanner emulator support for the PostgreSQL dialect is now generally available. To learn more about the emulator, see Emulate Cloud Spanner locally.

Cloud Storage

The Object Retention Lock feature is now available.

  • Using this feature, you can place a retention configuration on individual objects.

  • A retention configuration defines a date prior to which the object cannot be deleted or overwritten.

  • A retention configuration can optionally be locked to prevent the retention date from being shortened or removed.

Google Cloud Armor

Network edge security polices (custom rules) are now available to allowlisted users. For more information about network edge policies, see Types of security policies. In addition, you can learn how to Configure network edge security policies.

VPC Service Controls

Preview stage supported for the following integration:

November 20, 2023

Anthos clusters on VMware

Anthos clusters on VMware 1.14.10-gke.35 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.14.8-gke.37 runs on Kubernetes v1.25.13-gke.200.

The following issues are fixed in 1.14.10-gke.35:

  • Fixed the etcd hostname mismatch issue when using FQDN
  • Fixed the issue where deleting a user cluster with a volume attached stalls, in which case the cluster can't be deleted and can't be used.

The following vulnerabilities are fixed in 1.14.10-gke.35:

Anthos clusters on bare metal

Release 1.15.7

Anthos clusters on bare metal 1.15.7 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.15.7 runs on Kubernetes 1.26.

Fixed an issue where CoreDNS Pods can get stuck in an unready state.

The following container image security vulnerabilities have been fixed in 1.15.7:

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

Cloud Asset Inventory

The following resource types are now publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, Feed and Search (SearchAllResources, SearchAllIamPolicies) APIs.

  • Financial Services
    • financialservices.googleapis.com/Dataset
    • financialservices.googleapis.com/BacktestResult
    • financialservices.googleapis.com/EngineConfig
    • financialservices.googleapis.com/Model
    • financialservices.googleapis.com/PredictionResult
Cloud Storage

Regional endpoints are now available in Preview. Regional endpoints let you run your workloads in a manner that complies with data residency and data sovereignty requirements, where your request traffic is routed directly to the region specified in the endpoint.

Confidential VM

Confidential Space. Support for VPC Service Controls is released to General Availability.

You can now protect Confidential Space using VPC Service Controls perimeters. For more information, see VPC Service Controls supported products.

SAP on Google Cloud

Cloud Storage Backint agent for SAP HANA version 1.0.32

Version 1.0.32 of the Cloud Storage Backint agent for SAP HANA is available. This version updates the JRE to the latest SAP JRE 21.0.1.

For more information about the agent, see Cloud Storage Backint agent for SAP HANA overview.

VPC Service Controls

General availability support for the following integration:

Virtual Private Cloud

November 17, 2023

Apigee hybrid

On November 17, 2023 we released an updated version of the Apigee hybrid software, v1.11.0.

Helm charts management for Apigee hybrid

Starting in version v1.11.0, you have the choice of installing and managing your clusters with either Helm or apigeectl. You cannot manage a cluster with both. Apigee recommends using Helm for new hybrid installations. See Apigee hybrid Helm charts reference.

Vault integration for Cassandra credentials (preview)

Starting in version v1.11.0, you can store Cassandra credentials in Hashicorp Vault.
Note: Using Vault requires Helm management of your Apigee installation.
See Storing Cassandra credentials in Hashicorp Vault.

Vault integration is in preview as of the Apigee hybrid 1.11.0 release.

Apigee Advance API Security Actions for Apigee hybrid

Advanced API Security's new Security Actions feature is now available in Apigee hybrid.

Bug ID Description
295929616 Installation of Hybrid 1.10.x would fail on OpenShift due to out of memory issues. (Fixed in Apigee hybrid v1.10.3)
294069799 Updated the security context settings for the Apigee Hybrid Backup and Restore pod.
292571089 An error with support for CSI backup and restore for Cassandra was fixed. (Fixed in Apigee hybrid v1.10.3)
292118812 Fixed UDCA regression in Hybrid 1.10.1 where UDCA would ignore forward proxy configuration. (Fixed in Apigee hybrid v1.10.2)
289254725 Implemented a fix to prevent failure of proxy deployments that include the OASValidation policy. (Fixed in Apigee hybrid v1.10.1)
287321226 Security context has been corrected for apigee-prom-prometheus to avoid privilege escalation. (Fixed in Apigee hybrid v1.10.3)
240180122 Disable privilege escalation on the cassandra container by moving the ulimit settings to the newly introduced initContainer "apigee-cassandra-ulimit-init".

If you are using security controls with gatekeeper, ensure that apigee-cassandra-ulimit-init initContainer can runAs user, group as 0 and allow capabilities IPC_LOCK and SYS_RESOURCES. (Fixed in Apigee hybrid v1.11.0)

205666368 Fixed issue with default validation of TLS target endpoint certificates.

To enable strict SSL on southbound connections to a proxy target endpoint, add the tag <Enforce>true</Enforce> in the target <SSLInfo> block.

See About setting TLS options in a target endpoint or target server.

See also Known Issue #205666368.

(Fixed in Apigee hybrid v1.10.3-hotfix.1)
158132963 Added improvements to capture relevant target flow variables in trace and analytics in case of target timeouts. (Fixed in Apigee hybrid v1.10.2)
Bug ID Description
303292806 Set backup utility to only connect to Cassandra server pods in the apigee namespace. (Fixed in Apigee hybrid v1.10.3-hotfix.3)
300542690 Added dedicated service accounts for Apigee Connect, Redis, and UDCA to prevent Kubernetes from automatically injecting credentials for a specified ServiceAccount or the default ServiceAccount. (Fixed in Apigee hybrid v1.10.3-hotfix.3)
297938600,
297938559,
297938486,
294892344
Security fixes for apigee-diagnostics-collector. (Fixed in Apigee hybrid v1.10.3)
This addresses the following vulnerabilities:
297938498,
297938487
Security fixes for apigee-fluent-bit.(Fixed in Apigee hybrid v1.10.3)
This addresses the following vulnerabilities:
297938441 Security fixes for apigee-runtime. (Fixed in Apigee hybrid v1.10.3)
This addresses the following vulnerabilities:
297286274 Security fixes for apigee-installer. (Fixed in Apigee hybrid v1.10.3)
This addresses the following vulnerabilities:
296719459,
296719400,
296719348,
296719307,
296719306,
296719188,
296719187,
296719186,
296719115,
296719018,
296718937,
296718918,
296718917,
296718916,
296716670,
296716669,
296716472,
296716471,
296715155
Security fixes for apigee-hybrid-cassandra. (Fixed in Apigee hybrid v1.10.3)
This addresses the following vulnerabilities:
296717666,
296717283,
296716668,
296716667,
296716650,
296716635,
296716634,
296716633,
296716470,
296716234,
296715734,
296715733,
296715154,
296715153
Security fixes for apigee-hybrid-cassandra-client. (Fixed in Apigee hybrid v1.10.3)
This addresses the following vulnerabilities:
296717665,
296717664,
296717663,
296717662,
296717185,
296716666,
296716649,
296716632,
296716468,
296716467,
296716232,
296715152,
296715151,
296714218
Security fixes for apigee-cassandra-backup-utility. (Fixed in Apigee hybrid v1.10.3)
This addresses the following vulnerabilities:
295936113 Security fixes for apigee-mart-server. (Fixed in Apigee hybrid v1.10.3)
This addresses the following vulnerability:
294906706 Security fixes for apigee-prom-prometheus. (Fixed in Apigee hybrid v1.10.3)
This addresses the following vulnerabilities:
293925856 Security fixes for apigee-prometheus-adapter. (Fixed in Apigee hybrid v1.10.3)
This addresses the following vulnerabilities:
293348130 Security fixes for apigee-udca. (Fixed in Apigee hybrid v1.10.2)
This addresses the following vulnerabilities:
291994501 Security fixes for apigee-operator and apigee-watcher. (Fixed in Apigee hybrid v1.10.2)
This addresses the following vulnerabilities:
291994501 Security fixes for apigee-installer. (Fixed in Apigee hybrid v1.10.2)
This addresses the following vulnerabilities:
290829031 Security fixes for apigee-hybrid-cassandra, apigee-cassandra-client, and cassandra-backup-utility. (Fixed in Apigee hybrid v1.10.2)
This addresses the following vulnerabilities:
290829028 Security fixes for Apigee Connect and apigee-connect-agent and apigee-redis. (Fixed in Apigee hybrid v1.10.2)
This addresses the following vulnerabilities:
290068742 Security fixes for apigee-udca. (Fixed in Apigee hybrid v1.10.1)
This addresses the following vulnerability:
290067464 Security fixes for apigee-stackdriver-logging-agent. (Fixed in Apigee hybrid v1.10.1)
This addresses the following vulnerability:
290065830 Security fixes for apigee-udca. (Fixed in Apigee hybrid v1.10.1)
This addresses the following vulnerability:
281561243 Security fixes for apigee-diagnostics-collector, apigee-mart-server, apigee-mint-task-scheduler, apigee-runtime, and apigee-synchronizer.
This addresses the following vulnerability: (Fixed in Apigee hybrid v1.10.1)
N/A Security fixes for apigee-prometheus-adapter. (Fixed in Apigee hybrid hybrid v1.11)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-prom-prometheus/master. (Fixed in Apigee hybrid hybrid v1.11)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-kube-rbac-proxy. (Fixed in Apigee hybrid hybrid v1.11)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-hybrid-cassandra. (Fixed in Apigee hybrid hybrid v1.11)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-fluent-bit. (Fixed in Apigee hybrid hybrid v1.11)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-diagnostics-collector, apigee-mart-server, apigee-mint-task-scheduler, apigee-runtime, and apigee-synchronizer. (Fixed in Apigee hybrid hybrid v1.11)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-cassandra-backup-utility, apigee-hybrid-cassandra-client, and apigee-connect-agent. (Fixed in Apigee hybrid v1.11)
This addresses the following vulnerabilities:
N/A Security fixes for apigee-asm-ingress and apigee-asm-istiod. (Fixed in Apigee hybrid v1.11)
This addresses the following vulnerabilities:
App Hub

App Hub is available in Preview.

Cloud Composer

Starting December 1, 2023, in the europe-central2, northamerica-northeast1, us-west1, and us-west2 regions it will be possible to create new Cloud Composer 1 environments only in projects that already have Cloud Composer 1 environments.

In all other existing or newly created projects in these regions, it will be possible to create only Cloud Composer 2 environments. This change is a part of the preparation for Cloud Composer 1 end of support, as communicated earlier and described in the Versioning overview.

Cloud Monitoring

Observability for Google Kubernetes Engine: The Observability tab for a GKE cluster adds a dashboard for GPU metrics. The charts on this dashboard are populated only if the cluster has GPU nodes. For more information, see View observability metrics.

Cloud Run

For services with cold start times exceeding 10 seconds, requests are now queued for at least the cold start time before timing out while waiting for instances to start.

Cloud SQL for MySQL

The demote API is now available. This API demotes an existing standalone instance to be a Cloud SQL read replica for an external database server.

Cloud SQL for MySQL now supports minor version 8.0.35. To upgrade your existing instance to the new version, see Upgrade the database minor version.

Cloud SQL for PostgreSQL

The demote API is now available. This API demotes an existing standalone instance to be a Cloud SQL read replica for an external database server.

Dataflow

Dataflow supports NVIDIA® L4 and NVIDIA® A100 80 GB GPU types. For more information, see Dataflow support for GPUs.

Dataproc

New Dataproc on Compute Engine subminor image versions:

  • 2.0.84-debian10, 2.0.84-rocky8, 2.0.84-ubuntu18
  • 2.1.32-debian11, 2.1.32-rocky8, 2.1.32-ubuntu20, 2.1.32-ubuntu20-arm

Upgraded the Cloud Storage connector version to 2.2.18 in the latest 2.0 and 2.1 Dataproc on Compute Engine image versions.

In the Flink component in the latest Dataproc on Compute Engine 2.1 image version, added the following java-storage client properties:

Fixed a regression in the Zeppelin websocket rules that caused a websocket error in Zeppelin notebooks.

The Python kernel does not work in Zeppelin on the Dataproc on Compute Engine 2.1 image version. Other kernels are not impacted.

The Zeppelin REST API does not work (drops query parameters) on Dataproc on Compute Engine 2.0 and 2.1 image versions via the Component Gateway. Other Zeppelin interactions can also break as a result of dropped query parameters.

Google Kubernetes Engine

You can now run workloads on L4 GPUs in Autopilot clusters that use GKE version 1.28.3-gke.1203000 and later. For instructions, see Deploy GPU workloads in Autopilot.

(2023-R24) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters

The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.

No channel

Stable channel

  • There are no new releases in the Stable release channel.

Regular channel

  • There are no new releases in the Regular release channel.

Rapid channel

(2023-R24) Version updates

(2023-R24) Version updates

(2023-R24) Version updates

  • There are no new releases in the Stable release channel.

(2023-R24) Version updates

  • There are no new releases in the Regular release channel.
Vertex AI

Vertex AI Feature Store

The following features of the new and improved Vertex AI Feature Store are now generally available (GA):

Note that the following features of Vertex AI Feature Store are still in Preview:

For more information, see About Vertex AI Feature Store.

Workflows

Support for a Kubernetes API connector is available in Preview. The connector allows you to interact with Kubernetes objects in a Google Kubernetes Engine cluster. For more information, see Access Kubernetes API objects using a connector.

November 16, 2023

Anthos clusters on VMware

Anthos clusters on VMware 1.16.3-gke.45 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.16.1-gke.44 runs on Kubernetes 1.27.4-gke.1600.

The Prometheus and Grafana add-ons field, loadBalancer.vips.addonsVIP, is deprecated. This change is because Google Managed Service for Prometheus replaced the Prometheus and Grafana add-ons.

The following issues are fixed in 1.16.3-gke.45:

  • Fixed a Cilium issue causing egress NAT to erroneously break long-lived connections.
  • Fixed the etcd hostname mismatch issue when using a FQDN.
  • Fixed the known issue that caused admin cluster updates or upgrades to fail if the projects or locations of add-on services don't match each other.
  • Fixed the issue that external cluster snapshot won't be taken after gkectl update admin fails.
  • Fixed an issue that caused the CSI workload preflight to fail when Istio is enabled.
  • Fixed the issue that deleting a user cluster with a volume attached may be stuck forever.
  • Fixed the known issue that caused user cluster deletion to fail when using a user-managed admin workstation.

The following vulnerabilities are fixed in 1.16.3-gke.45:

Assured Workloads

The IL4 compliance program now supports the following products. See Supported products for more information:

  • Cloud DNS
  • Cloud Interconnect
  • Cloud Monitoring
  • Cloud Router
  • Cloud SQL
  • Cloud VPN
  • Pub/Sub
BigQuery

The following BigQuery ML features for Vertex AI large language models (LLMs) are now generally available (GA):

  • The SQL syntax for remote models has been updated to provide access to all text generation and text embedding LLMs (for example, text-bison-32k and textembedding-gecko-multilingual) and also to provide support for different LLM versions.

  • Region support for text-bison* LLM models has been expanded to include the following locations in addition to us and us-central1:

    • asia-northeast3
    • asia-southeast1
    • eu
    • europe-west1
    • europe-west2
    • europe-west3
    • europe-west4
    • europe-west9
    • us-west4
Chronicle SOAR

Release 6.2.40 is currently in Preview.

Playbook actions carried out by automation are not labeled as such on the case wall (ID #47525692).

This bug fix is in Preview.

Case title is not picking up information if it's in square brackets (ID #00262914).

This bug fix is in Preview.

Cloud Spanner

Cloud Spanner now supports automatic cleanup of long running transactions (in Preview). To enable this feature, use the Java or Go client library to automatically remove long running transactions that might cause session leaks and receive warning logs about problematic transactions. For more information, see Automatic cleanup of session leaks.

Cloud Spanner now supports Hibernate ORM 6.3 in GoogleSQL Hibernate dialect. For more information, see Integrate Spanner with Hibernate ORM (GoogleSQL dialect).

Dataform

Dataform is compliant with VPAT.

For more information, see Dataform compliance.

Deep Learning Containers

M113 release

  • Miscellaneous bug fixes and improvements in Python 3.10 container images.
Deep Learning VM Images

M113 release

  • Miscellaneous bug fixes and improvements in Python 3.10 images.
Google Cloud Architecture Center

Parallel file systems for HPC workloads: Added Sycomp Storage Fueled by IBM Spectrum Scale as an option for parallel file system (PFS) storage, and replaced NetApp Cloud Volumes Service with Google Cloud NetApp Volumes.

Google Cloud Deploy

You can now configure alerts for Cloud Deploy release render failures.

Network Connectivity Center

The Advanced Data Networking (ADN) traffic is accounted only for large-sized flows (approximately >20 Kbps) that cross VPC boundaries. Currently, small-sized flows are not accounted.

Vertex AI Workbench

M113 release

The M113 release of Vertex AI Workbench instances includes the following:

  • Added the Dataproc JupyterLab plugin to Vertex AI Workbench instances. To get started, see Create a Dataproc-enabled instance.
  • When using an instance's Google Cloud CLI, gcloud config is preset with the following defaults:
    • project is set to your instance's project.
    • Your compute region is set to your instance's region.
    • Your Dataproc region is set to your instance's region.
  • Fixed an issue that prevented Dataproc kernels from working.
  • Fixed a CORS (cross-origin resource sharing) error.

The M113 release of Vertex AI Workbench user-managed notebooks includes the following:

  • Miscellaneous bug fixes and improvements in Python 3.10 notebooks.

November 15, 2023

AlloyDB for PostgreSQL

IAM authentication for AlloyDB is generally available (GA).

You can now restrict an OAuth 2.0 access token so that it works only for AlloyDB authentication.

You can now configure the AlloyDB Auth Proxy to automatically authenticate IAM-based database logins. This works only with the IAM account that you use to run the proxy client.

AlloyDB Omni version 15.2.2 is available. This version resolves the previous version's issue with incremental backups, and contains various other bug fixes and improvements. For more information about upgrading AlloyDB Omni, see Upgrade AlloyDB Omni.

The AlloyDB Omni Kubernetes Operator version 0.2.0 is available in Preview. This update adds support for AlloyDB Omni version 15.2.2, and includes various bug fixes and improvements. For more information about upgrading AlloyDB using the Kubernetes operator, see Upgrade AlloyDB Omni.

Chronicle

The following supported default parsers have changed. Each is listed by product name and log_type value, if applicable.

  • Abnormal Security (ABNORMAL_SECURITY)
  • Akamai Enterprise Application Access (AKAMAI_EAA)
  • Atlassian Confluence (ATLASSIAN_CONFLUENCE)
  • Atlassian Jira (ATLASSIAN_JIRA)
  • AWS Aurora (AWS_AURORA)
  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • Bitwarden Events (BITWARDEN_EVENTS)
  • Check Point Harmony (CHECKPOINT_HARMONY)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Switch (CISCO_SWITCH)
  • Cisco Umbrella DNS (UMBRELLA_DNS)
  • Cloud Audit Logs (N/A)
  • Dell Switch (DELL_SWITCH)
  • Elastic Search (ELASTIC_SEARCH)
  • Elastic Windows Event Log Beats (ELASTIC_WINLOGBEAT)
  • F5 ASM (F5_ASM)
  • FireEye (FIREEYE_ALERT)
  • Firewall Rule Logging (N/A)
  • IBM DataPower Gateway (IBM_DATAPOWER)
  • Infoblox (INFOBLOX)
  • Jamf Protect Alerts (JAMF_PROTECT)
  • Juniper (JUNIPER_FIREWALL)
  • Lacework Cloud Security (LACEWORK)
  • Linux Sysmon (LINUX_SYSMON)
  • Medigate IoT (MEDIGATE_IOT)
  • Microsoft Sentinel (MICROSOFT_SENTINEL)
  • Netskope (NETSKOPE_ALERT)
  • Openpath (OPENPATH)
  • Palo Alto Cortex XDR Alerts (CORTEX_XDR)
  • Proofpoint Observeit (OBSERVEIT)
  • Proofpoint On Demand (PROOFPOINT_ON_DEMAND)
  • Pulse Secure (PULSE_SECURE_VPN)
  • Pulse Secure Virtual Traffic Manager (PULSE_SECURE_VTM)
  • SentinelOne EDR (SENTINEL_EDR)
  • Sophos Firewall (Next Gen) (SOPHOS_FIREWALL)
  • SpyCloud (SPYCLOUD)
  • Stealthbits Defend (STEALTHBITS_DEFEND)
  • Stealthbits PAM (STEALTHBITS_PAM)
  • STIX Threat Intelligence (STIX)
  • Symantec Endpoint Protection (SEP)
  • Symantec Event export (SYMANTEC_EVENT_EXPORT)
  • Tenable Active Directory Security (TENABLE_ADS)
  • Unix system (NIX_SYSTEM)
  • VMware vCenter (VMWARE_VCENTER)
  • Windows Event (XML) (WINEVTLOG_XML)
  • Zscaler (ZSCALER_WEBPROXY)

The following log types, without a default parser, were added. Each is listed by product name and log_type value, if applicable.

  • Aruba Orchestrator (ARUBA_ORCHESTRATOR)
  • AWS Shield (AWS_SHIELD)
  • Azure DNS logs (AZURE_DNS)
  • Backbox (BACKBOX)
  • Bitvise SSHd (BITVISE_SSHD)
  • Cylera IOT (CYLERA_IOT)
  • Druva Backup (DRUVA_BACKUP)
  • Ensono Cloud Mainframe Solution (ENSONO)
  • xtreme Networks ExtremeControl NAC Solution (EXTREME_CONTROL)
  • EzProxy (EZPROXY)
  • Github Events (GITHUB_EVENTS)
  • Glean (GLEAN)
  • ISM Xtraction (IVANTI_XTRACTION)
  • Lira (LIRA)
  • LogonBox (LOGONBOX)
  • Mandiant Custom IOC (MANDIANT_CUSTOM_IOC)
  • Monday (MONDAY)
  • Onapsis (ONAPSIS)
  • Opentelemetry (OPENTELEMETRY)
  • Opswat Kiosk (OPSWAT_KIOSK)
  • Outpost24 (OUTPOST24)
  • Pentera Leef (PENTERA_LEEF)
  • Phishlabs (PHISHLABS)
  • Portnix Audit (PORTNOX_AUDIT)
  • Portnix CEF (PORTNOX_CEF)
  • Proofpoint Sendmail Sentrion (PROOFPOINT_SENDMAIL_SENTRION)
  • SAP SM20 (SAP_SM20)
  • Splunk Attack Analyzer (SPLUNK_ATTACK_ANALYZER)
  • Stellar Cyber (STELLAR_CYBER)
  • Talon (TALON)
  • Teradici PCoIP (TERADICI_PCOIP)
  • TrendMicro Apex Central (TRENDMICRO_APEX_CENTRAL)
  • TrendMicro Webproxy DSM (TRENDMICRO_WEBPROXY_DSM)
  • Vonage (VONAGE)
  • Waterfall Data Security Manager (WATERFALL_DSM)
  • Ysoft Data Security Manager (YSOFT_DSM)
  • Zscaler Client Connector (ZSCALER_ZCC)
  • Zscaler ZDX (ZSCALER_ZDX)

For a list of supported log types and details about default parser changes, see Supported log types and default parsers.

Chronicle SOAR

Release 6.2.39 is now in General Availability.

Cloud Composer

All Cloud Composer environment's GKE clusters are set up with maintenance exclusions for the following periods:

  • From November 20, 2023 to November 29, 2023 (already configured)
  • From December 20, 2023 to January 2, 2024 (will be configured in December)

For more information, see Maintenance exclusions.

Cloud Healthcare API

A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.

Cloud SQL for SQL Server

Cloud SQL supports the bulk insert functionality of SQL Server for importing data. This functionality is supported only on SQL Server 2022.

For more information, see Use bulk insert for importing data.

Cloud Spanner

Cloud Spanner now provides an integration workflow with Vertex AI Vector Search to enable vector similarity search on data stored in Spanner. For more information, see Export embeddings from Spanner to Vector Search.

Dataproc

You can use CMEK (Customer Managed Encrytion Keys) with encrypted Dataproc cluster data, incuding persistent disk data, job arguments and queries submitted with Dataproc jobs, and cluster data saved in the cluster Dataproc staging bucket. See Use CMEK with cluster data for more information.

Eventarc

Eventarc is available in the me-central2 (Dammam, Kingdom of Saudi Arabia) region.

Google Kubernetes Engine

Dynamic Workload Scheduler support on GKE through the Provisioning Request API launched in Preview in version 1.28. Use the Dynamic Workload Scheduler to get large atomic sets of available GPU models in GKE Standard clusters. For more information, see Deploy GPUs for batch workloads with ProvisioningRequest.

Vertex AI Search and Conversation

Vertex AI Search: Autocomplete denylist (Preview with allowlist)

Importing an autocomplete denylist is available as a preview with allowlist feature. To use this feature, contact your Google account team.

For information about autocomplete denylists, see Use an autocomplete denylist.

Vertex AI Vision

Batch video and image support in Vertex AI Vision Warehouse is Generally Available. Vertex AI Vision Warehouse now supports semantic searches and similarity searches on video and images. For more information, see Vision Warehouse overview

November 14, 2023

Anthos Service Mesh

1.19.3-asm.4 is now available for in-cluster Anthos Service Mesh.

You can now download 1.19.3-asm.4 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.19.3 subject to the list of supported features. Anthos Service Mesh 1.19.3-asm.4 uses Envoy v1.27.2.

1.18.5-asm.2 is now available for in-cluster Anthos Service Mesh.

You can now download 1.18.5-asm.2 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.18.5 subject to the list of supported features. Anthos Service Mesh 1.18.5-asm.2 uses Envoy v1.26.5.

1.17.8-asm.4 is now available for in-cluster Anthos Service Mesh.

You can now download 1.17.8-asm.4 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.17.8 subject to the list of supported features. Anthos Service Mesh 1.17.8-asm.4 uses Envoy v1.25.12.

1.16.7-asm.14 is now available for in-cluster Anthos Service Mesh.

You can now download 1.16.7-asm.14 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.16.7 subject to the list of supported features. Anthos Service Mesh 1.16.7-asm.14 uses Envoy v1.24.11.

Anthos clusters on AWS

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.

  • CVE-2023-4147

For more information, see the GCP-2023-042 security bulletin.

Anthos clusters on Azure

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.

  • CVE-2023-4147

For more information, see the GCP-2023-042 security bulletin.

BigQuery

You can now see query performance insights about partition skew. This feature is in preview.

Cloud Data Fusion

You can apply a patch revision version when you create a new Cloud Data Fusion instance by adding the optional --patch_revision argument to the gcloud beta data-fusion instances create command. For more information, see Manage patch revisions for instances.

You can update the patch revision version of an instance by adding the optional --patch_revision argument to the gcloud beta data-fusion instances update command. For more information, see Manage patch revisions for instances.

Cloud Run

Cancelling a currently running job execution is now at general availability (GA).

Cloud Storage

New bandwidth quotas are now in effect.

  • Bandwidth quotas are now variable and based in part on a project's billing account history. Previously, the same default value applied to all projects.
  • For most projects, egress bandwidth quotas either remain unchanged or have increased.
  • You can view your project's egress bandwidth quotas in the Console.
Google Cloud Architecture Center

Parallel file systems for HPC workloads: Added Parallelstore and Weka Data Platform as options for parallel file system (PFS) storage.

Google Cloud VMware Engine

Google Cloud console experience for VMware Engine: You can use the Google Cloud console to manage your VMware Engine environments without opening another tab. For more information on migrating to this refreshed experience, see What's new with VMware Engine.

VMware Engine network: Further simplification of the networking architecture and experience in VMware Engine removes the need for private service networking. With VMware Engine networks, you can create multiple isolated networks within the same project and connect them as needed to consumer VPCs to deliver complex topologies.

Integrated networking: Private cloud deployment is now just one simple step. VMware Engine network and initial VPC peering to your VPC can be done at the time of private cloud creation.

Advanced VPC Peering: Virtual Private Cloud network peerings define network connectivity between VMware Engine networks, Google VPCs, and other services. You can now create a complex set of VPC peerings within the Google Cloud console.

Increase to the default VPC Peer count: Any standard VMware Engine network now supports 25 VPC Peers by default.

Integrated Cloud DNS for workloads (DNS Bindings): Bi-directional Cloud DNS capabilities that enable DNS resolution for VMware Engine workloads, delivering enterprise needs in a simplified and more streamlined manner. Cloud DNS administrators can bind the VMware Engine network just as any other VPC.

DNS Server IP: Workloads within your private cloud can now use native Cloud DNS for DNS resolution.

Management DNS for private clouds: Automatic Management DNS Peering is now Automatic Management DNS for Private Clouds. You can now view and manage the DNS bindings for the private cloud management zone.

External access rules: Control access to external IP addresses. We have simplified the rule creation process to no longer require creation of a table and attachment to a subnet. External access rules now support one or more external IP address within a single rule.

(Legacy Networks) DNS forwarding rules: Allows configuration of management appliance DNS resolution for private clouds attached to legacy VMware Engine networks.

ESXi (NSX-T Distributed Log Forwarding): You can now configure both ESXi logs, including NSX-T Distributed Firewall (DFW) Logs, to a remote syslog server.

Finer-grained access controls for additional resources: VMware Engine provides finer-grained, per-action access controls for actions performed on new resources added. To view a comprehensive list of permissions for VMware Engine, go to the Permissions reference and search for the prefix vmwareengine.

Additional Google Cloud CLI and VMware Engine API Endpoints: More capabilities delivered using VMware Engine API and Google Cloud CLI enables you to programmatically manage VMware Engine environments, including VMware Engine API and Google Cloud CLI functions for managing the new networking model, network peering, external access rules and external IP service, consumer DNS, and more.

DNS Profiles: Existing DNS Profiles will be migrated to each private cloud in which the DNS Profile was assigned. DNS forwarding rules can be configured within each private cloud.

Firewall Tables: Existing firewall tables and rules have been migrated to external access rules.

Elevate privilege option is no longer available. You can sign in using one of the solution users to perform elevated privileges actions. For details, see Elevating VMware Engine privileges.

Announced August 10, 2022: Removed ability to manage point-to-site (P2S) VPN gateways for projects with existing P2S VPN gateways. You can continue to use an alternative VPN solution. For details, see Connecting using VPN. Contact customer care for P2S VPN gateway removal.

Google Kubernetes Engine

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.

  • CVE-2023-4147

For more information, see the GCP-2023-042 security bulletin.

Memorystore for Redis Cluster

Memorystore for Redis Cluster is now Generally Available (GA).

Migrate to Virtual Machines

Preview: You can now use Customer-Managed Encryption Keys (CMEK) in Migrate to Virtual Machines to do the following:

  • Protect data stored by Migrate to Virtual Machines during the migration process.
  • Protect data of the migrated VMs created by clone and cut-over operations for all sources - AWS, Azure, and VMware.
Vertex AI Search and Conversation

Vertex AI Search: Additional languages supported

Extractive answers are now supported in the following languages:

  • Arabic
  • Chinese (Simplified)
  • Japanese

See Languages.

November 13, 2023

Anthos Config Management

Policy Controller has been updated to include a more recent build of OPA Gatekeeper (hash: a1f01f4 ).

Policy Controller bundles have been updated to the following versions: asm-policy-v0.0.1: 202310.0, cis-k8s-v1.5.1: 202310.0, cost-reliability-v2023: 202310.0-preview, nist-sp-800-190: 202310.0, nist-sp-800-53-r5: 202310.0, nsa-cisa-k8s-v1.2: 202310.0, pci-dss-v3.2.1: 202310.0, policy-essentials-v2022: 202310.0, psp-v2022: 202310.0, pss-baseline-v2022: 202310.0, pss-restricted-v2022: 202310.0. For reference, see Policy Controller bundles overview.

The constraint template library's K8sPSPAllowedUsers, K8sPSPAllowPrivilegeEscalationContainer, K8sPSPAutomountServiceAccountTokenPod, K8sPSPCapabilities, K8sPSPFlexVolumes, K8sPSPForbiddenSysctls, K8sPSPFSGroup, K8sPSPHostFilesystem, K8sPSPHostNamespace, K8sPSPHostNetworkingPorts, K8sPSPPrivilegedContainer, K8sPSPProcMount, K8sPSPReadOnlyRootFilesystem, K8sPSPSELinuxV2, K8sPSPVolumeTypes, and K8sRequiredProbes no longer raise violations during updates of existing objects for immutable fields.

Updated the Open Telemetry image from 0.86.0 to 0.87.0 to address security vulnerabilities. For more information about these changes, see the full changelog for opentelemetry-collector-contrib.

Anthos clusters on VMware

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.

  • CVE-2023-4147

For more information, see the GCP-2023-042 security bulletin.

BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigquery

2.34.2 (2023-11-07)

Dependencies
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.32.0 (#2989) (47a61a7)
  • Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.36.0 (#2990) (81c0727)

2.34.1 (2023-11-06)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.19.0 (#2986) (0d400da)
  • Update dependency org.checkerframework:checker-compat-qual to v2.5.6 (#2982) (c137f1f)
  • Update dependency org.junit.vintage:junit-vintage-engine to v5.10.1 (#2984) (a64b91c)
  • Update github/codeql-action action to v2.22.5 (#2975) (0b88846)

The following BigQuery ML point-in-time lookup functions are now generally available (GA). These functions let you specify a point-in-time cutoff when retrieving features for training a model or running inference, in order to avoid data leakage.

The following AI features in BigQuery are now in preview:

Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigtable

2.29.1 (2023-11-07)

Bug Fixes
  • Add getPageSize() to QueryPaginator (42a7e36)
Dependencies

2.25.3 (2023-11-08)

Bug Fixes

2.23.5 (2023-11-07)

Bug Fixes

2.23.4 (2023-11-06)

Bug Fixes
Cloud Monitoring

A new query interface for creating charts is now in Public Preview. The new interface provides a style update and simplifies building a query by automatically configuring your aggregation settings. For more information, see Create charts with Metrics Explorer.

Cloud Run

Deploying sidecar containers to your Cloud Run service is now at general availability (GA). Console UI and CLI are also now available for this feature.

Cloud Spanner

Managed autoscaling for compute capacity on Cloud Spanner instances is now in preview. With managed autoscaling, Spanner automatically increases or decreases compute capacity on the instance in response to changing workload or storage needs and user defined goals. For more information, see Managed autoscaling for Spanner.

Cloud TPU

Cloud TPU now supports TensorFlow 2.15.0, which adds support for PJRT. For more information see the TensorFlow 2.15.0 release notes.

Compute Engine

Preview: When creating or modifying an on-demand reservation, you can configure reservations to be automatically deleted at a specific date and time. Automatically deleting reservations makes it easier to prevent charges from unused reservations when you no longer need them.

For more information, see the documentation for creating on-demand reservations.

Dataflow

Dataflow jobs now scale to 4,000 worker VMs.

Google Cloud Architecture Center

Designing networks for migrating enterprise workloads: Adds Cross-Cloud Interconnect functionality and updates Private Service Connect information.

Google Cloud Deploy

Cloud Deploy now supports delivery pipeline automation, including automated release promotion and automated rollout phase advancement, in preview.

SAP on Google Cloud

Google Cloud's Agent for SAP version 2.7

Version 2.7 of Google Cloud's Agent for SAP is generally available (GA). This version fixes the handling of SAP HANA database passwords that contain special characters, and introduces Process Monitoring metrics related to TCP network.

For more information, see What's new with Google Cloud's Agent for SAP.

Vertex AI

Numerical filtering available in Vertex AI Vector Search

With Vector Search you can restrict results by "filtering" your index results. In addition to filtering by using categorical restrictions, you can now use numeric filtering. To learn more, see Filter vector matches.

reCAPTCHA Enterprise

reCAPTCHA Enterprise Mobile SDK v18.4.0 is now available for iOS.

This version contains the following changes:

  • Internal networking improvements.
  • Sample codes for the iOS SDK and visual reCAPTCHA in GitHub.
  • The -ObjC flag is not required when integrating with reCAPTCHA Enterprise on iOS.

November 10, 2023

Apigee Integrated Portal

On November 10, 2023 we released an updated version of Apigee integrated portal.

This release includes the public preview of integrated portal APIs which allow you to manage your integrated portal APIs and reference documentation using API calls.

The catalog items list view now uses pagination when making requests to the portals service, examples have been added to Publishing your APIs, and new reference documentation is available:

Apigee X

As of November 10, 2023, Configurable API Proxies (preview) is no longer available. For more information, see Configurable API Proxies (preview) deprecation.

On November 10, 2023 we released an updated version of Apigee.

Apigee is now available in a new region: Middle East - Dammam (me-central2).

See Apigee locations for more information about available regions.

Cloud Database Migration Service

Database Migration Service now supports data cache in Cloud SQL for PostgreSQL Enterprise Plus edition instance creation.

You can enable data cache in the destination database when you create a migration job. To learn more about data cache in Cloud SQL for PostgreSQL, see Data cache overview.

Cloud SQL for MySQL

You can now upgrade Enterprise edition instances to Enterprise Plus edition in place with minimal disruption. Similarly, you can also switch from Enterprise Plus edition to Enterprise edition in place. For more information, see Upgrade an instance by using in-place upgrade.

Cloud SQL for PostgreSQL

You can now upgrade Enterprise edition instances to Enterprise Plus edition in place with minimal disruption. Similarly, you can also switch from Enterprise Plus edition to Enterprise edition in place. For more information, see Upgrade an instance by using in-place upgrade.

Cloud Spanner

Cloud Spanner now supports batch-oriented scans. For certain queries, Spanner chooses a batch-oriented processing mode to help improve scan throughput and performance. For more information, see Optimize scans.

Compute Engine

Preview: In a managed instance group (MIG), you can turn off repairs to inspect failed and unhealthy VMs, to implement your own repair logic, or to monitor the application health without triggering repairs by MIG. For more information, see Turn off repairs in a MIG.

Dataproc

Announcing the General Availability (GA) release of Dataproc Jupyter Plugin and its availability in Vertex AI Workbench instance notebooks.

New Dataproc on Compute Engine subminor image versions:

  • 2.0.83-debian10, 2.0.83-rocky8, 2.0.83-ubuntu18
  • 2.1.31-debian11, 2.1.31-rocky8, 2.1.31-ubuntu20, 2.1.31-ubuntu20-arm
Datastream

You can now stream the following large object data types for Oracle sources:

  • BLOB
  • CLOB
  • NCLOB
Firestore

Support for Firestore point-in-time recovery (PITR) feature that provides protection against accidental deletion or writes is now generally available (GA).

Firestore in Datastore mode

Support for Firestore in Datastore mode point-in-time recovery (PITR) feature that provides protection against accidental deletion or writes is now generally available (GA).

Google Kubernetes Engine

A vulnerability (CVE-2023-4004) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes. GKE clusters are impacted. For more information, see the GCP-2023-041 security bulletin.

The Observability tab for a GKE deployment now shows application performance metrics if the metrics are available. The supported metric sources include Istio, GKE Ingress, NGINX Ingress and gRPC, and HTTP metrics collected by using Google Managed Service for Prometheus. For more information, see Use application performance metrics.

Security Command Center

Policy Controller integration now in Preview

The integration of Policy Controller for Kubernetes clusters with Security Command Center is released to Preview. Violation alerts from Policy Controller now appear in Security Command Center as misconfiguration findings.

For more information, see Policy Controller.

Vertex AI

Generative AI on Vertex AI

Security controls are available for additional Generative AI on Vertex AI features.

November 09, 2023

Chronicle SOAR

Release 6.2.39 - Preview

Dynamic mode instance support

When a playbook is built for more than one environment, you need to use dynamic mode which picks the relevant instance configuration from the target environment. When using dynamic mode within environments that contain multiple instances, the playbook needs to stop and wait for the analyst to pick the right instance by the context of the alert.

In this release, we have added a new option to the playbook designer, such that the analyst can specify an instance for the dynamic mode to use within the target environment by entering a name or a pattern in a new Specify Instance Name field. This feature is in Preview.

Jobs enhancement

The Jobs page in the platform has been enhanced to provide more information at a glance for the security analyst. The following is a list of the added features:

  • Filter jobs according to success or failure.
  • Click View Details to open a side bar with full details.
  • Export the log details in raw text format.
  • View all job iterations with extra pagination support.

This feature is in Preview.

Update SiemplifyUtils to support Python 3 (ID #45825896).

This feature is in Preview

Incorrect playbook is attached to alert when using trigger Product Name when alerts are grouped (ID #47362407).

This bug fix is in Preview.

Issues with remote agent connected to remote connector in a shared instance configuration.

This bug fix is in Preview.

SDK function result.add_html which generates HTML reports within a case ends up generating blank text (ID #47721779).

This bug fix is in Preview

Cloud Data Loss Prevention

The following changes were made to the COUNTRY_DEMOGRAPHIC infoType detector:

  • The sensitivity score was changed from HIGH to MODERATE.
  • The type category was changed from PII to DEMOGRAPHIC.
Cloud Monitoring

You can now display events, such as the crash of a GKE pod, on your dashboards. This feature is in Public Preview.

Cloud SQL for PostgreSQL

Data cache is now available for Cloud SQL for PostgreSQL Enterprise Plus edition instances.

Datastream

You can now recover a permanently failed stream. For more information, see Recover a stream.

You can now start a stream from a specific binary log position for MySQL sources using the Datastream API. For more information, see Start a stream from a specific binary log position.

Google Kubernetes Engine

(2023-R23) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters

The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.

No channel

Stable channel

  • Version 1.24.14-gke.2700 is no longer available in the Stable channel.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to 1.24.15-gke.1700 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to 1.24.15-gke.1700 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.26 to 1.26.5-gke.2700 with this release.

Regular channel

  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.24.15-gke.1700
    • 1.25.11-gke.1700
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to 1.24.16-gke.500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to 1.25.12-gke.500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to 1.25.12-gke.500 with this release.

Rapid channel

(2023-R23) Version updates

(2023-R23) Version updates

  • Version 1.24.14-gke.2700 is no longer available in the Stable channel.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to 1.24.15-gke.1700 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to 1.24.15-gke.1700 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.26 to 1.26.5-gke.2700 with this release.

(2023-R23) Version updates

  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.24.15-gke.1700
    • 1.25.11-gke.1700
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to 1.24.16-gke.500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to 1.25.12-gke.500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to 1.25.12-gke.500 with this release.

(2023-R23) Version updates

GKE Infrastructure Dashboards and Metrics Packages are now generally available for both GKE Autopilot and Standard clusters with control plane version 1.27.2-gke.1200 and later.

You can now configure your Autopilot or Standard clusters to export a predefined list of metrics emitted by GKE managed kube-state-metrics (KSM) for workloads state and persistent storage. The component will run in the GKE system namespace "gke-managed-cim" to collect the metrics using Google Cloud Managed Service for Prometheus and send them to Cloud Monitoring. You can view the metrics in the new Persistent and Workloads State dashboards in the Observability tab.

Looker

Looker (Google Cloud core) now supports the following regions:

  • asia-east2 - Hong Kong
  • asia-northeast2 - Osaka
  • asia-northeast3 - Seoul
  • europe-southwest1 - Madrid
  • europe-west6 - Zurich
  • europe-west8 - Milan
  • europe-west9 - Paris
  • northamerica-northeast2 - Toronto
  • southamerica-east1 - São Paulo
  • us-west2 - Los Angeles
Vertex AI Search and Conversation

Vertex AI Search: New model for search summarization

A better model for generating search summaries has been launched. This underlying model improves the quality of search summaries and their grounding in the provided document corpus. You might see some differences in summary output after this update.

For more information about search summaries, see Get search summaries.

Vertex AI Search: Confidence scores are changed to relevance scores (Preview with allowlist)

Confidence scores are renamed to relevance scores. Scores are returned in the relevanceScore field. Previously, they were returned in the confidenceScore field.

This feature is in preview with allowlist. For more information about relevance scores, see Get snippets and extracted content.

November 08, 2023

AlloyDB for PostgreSQL

The extension pgvector is updated to version 0.5.0.

The extension oracle_fdw is added to the extensions supported by AlloyDB. The extension provides a foreign data wrapper for accessing Oracle databases.

Anthos clusters on AWS

A vulnerability (CVE-2023-4004) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes. For more information, see the GCP-2023-041 security bulletin.

Anthos clusters on Azure

A vulnerability (CVE-2023-4004) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes. For more information, see the GCP-2023-041 security bulletin.

Anthos clusters on VMware

A vulnerability (CVE-2023-4004) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes. For more information, see the GCP-2023-041 security bulletin.

Apigee Integrated Portal

On November 8, 2023 we released an updated version of Apigee integrated portal.

Bug ID Description
305287906 Fixed links to an API product from the API details, User account details, or Team details page in the Apigee UI.
307600672 Fixed issue where the name of the documentation was not populated in the Documentation column on the Apigee UI, API catalog page.
307599975 Improved pagination through large API catalogs on the Apigee UI, API catalog page.
Batch

You might experience latency when listing jobs in projects that contain more than 10,000 jobs. For more information, see Known issues.

Documentation has been added to explain how to configure jobs to send status notifications using Pub/Sub and how to query those notifications using BigQuery.

For more information, see the following pages:

  1. To configure your project to support status notifications, see Monitor job status using Pub/Sub notifications and BigQuery.

  2. To configure a job to send status notifications, see Create and run a job that sends Pub/Sub status notifications.

Chronicle

Detection Engine has added support for rule statuses for Chronicle YARA-L rules running on live data. In addition to being in Enabled or Disabled state, rules can also have Limited or Paused status depending on their resource usage.

Cloud Bigtable

Cloud Bigtable app profiles now let you configure request priorities to prioritize certain workload data requests over others. This feature is available in Preview.

Cloud Functions

Cloud Functions now supports on-deployment security updates (1st gen and 2nd gen) and fully automatic security updates (1st gen only). For details, see Execution environment security.

Cloud Monitoring

Observability for Google Kubernetes Engine: The curated set of kube state metrics is now Generally Available. You can enable this package of metrics from the Observability tab for your GKE cluster and preview the available charts and metrics before you enable the metrics. For more information, see Package: Kube state metrics.

Cloud Run

Setting custom audiences on your Cloud Run services is now at general availability (GA).

Confidential VM

Confidential Space. Support for VPC Service Controls is released to Preview.

You can now protect Confidential Space using VPC Service Controls perimeters. For more information, see VPC Service Controls supported products.

Dataproc

Announcing the release of Workflow Template CMEK (Customer Managed Encryption Key) encryption. Use this feature to apply CMEK encryption to workflow template job arguments. For example, when this feature is enabled, the query string of a workflow template SparkSQL job is encrypted using CMEK.

You can now use Dataproc Serverless autoscaling V2 to help you manage Dataproc Serverless workloads, improve workload performance, and save costs.

Google Cloud Deploy

Configuring Google Cloud operations suite alerts is now supported in the Cloud Deploy console.

Google Kubernetes Engine

New inference-focused Cloud Tensor Processing Unit (TPU) v5e machine types are available in GKE. These single-host TPU VMs are designed for inference workloads and contain one, four, or eight TPU v5e chips. These three new TPU v5e machine types (ct5l-hightpu-1t, ct5l-hightpu-4t, and ct5l-hightpu-8t) are currently available in the us-central1-a and europe-west4-b zones.

Cloud Tensor Processing Unit (TPU) v5e is generally available in clusters running GKE version 1.27.2-gke.2100 and later.

TPU v5e is purpose-built to bring the cost-efficiency and performance required for medium- and large-scale training and inference. TPU v5e delivers up to 2x higher training performance per dollar and up to 2.5x inference performance per dollar for LLMs and gen AI models compared to Cloud TPU v4. At less than half the cost of TPU v4, TPU v5e makes it possible for more organizations to train and deploy larger, more complex AI models.

Looker

Looker 23.20 includes the following changes, features, and fixes.

Expected Looker (original) deployment start: Monday, November 13, 2023

Expected Looker (original) final deployment and download available: Thursday, November 30, 2023

Expected Looker (Google Cloud core) deployment start: Monday, November 13, 2023

Expected Looker (Google Cloud core) final deployment: Tuesday, December 05, 2023

Drilling on a scatterplot with quadrants and a size-by field shows all data points.

References to history_id are being replaced with a slug for query event tracking.

The Data history playback feature requires users to have the explore role permission in order to use it.

The default values have changed for the Persistent Sessions and Inactivity Logout settings. Persistent Sessions is now disabled by default while Inactivity Logout is now enabled by default. You can change these values on the Admin Sessions page. The behavior of these settings will not change for users who have modified the session defaults.

Users can now move dashboard tiles to the left or the right side and also resize them to standard sizes.

Quick Layout for dashboard editors has been added behind the dashboard_layout_accelerator feature flag, which is set to ON by default for all customers besides core instances.

Malformed type declarations in a dimension_group no longer crash the LookML validator and now work as expected.

The "Go to LookML" link on the Explore page now works as expected.

Custom filter expressions get pushed down into NDT queries as expected when using bind_all_filters.

Number filter of type "between" reverted to type "is" when the first number was entered. This issue has been fixed.

The Databricks JDBC driver has been updated from 2.6.27 to 2.6.32.

Previously, resizing Google Maps immediately after loading could produce an error. This issue has been fixed.

An issue with configuring an SMTP server has been fixed, and the fields (Mail Server, From, User Name, Password, Port) have been made mandatory on the UI.

Custom value formats are no longer double escaped in table charts and legacy tables.

Previously, conditional formats such as "[>=1000] $#0.00,k; $#0.00" did not properly format negative numbers in tables and legacy tables. This issue has been fixed.

AND/OR filters no longer highlight required filters in red.

AND/OR filters now improve browser performance by delaying fetching suggestions until the user interacts with the filter.

The Performant Field Picker Labs feature now defaults to a new "Any" search option that searches for matches across views, groups, and fields for Explores with fewer than 5,000 fields.

Network Connectivity Center

Connecting VPC networks by using Network Connectivity Center is now generally available.

This feature lets you connect two or more VPC networks, represented as spokes, to a hub in the same or a different project for full mesh connectivity.

Network Intelligence Center

Connectivity Tests now supports verifying connectivity between two VPC networks connected by using Network Connectivity Center. For more information, see Create and run Connectivity Tests.

Security Command Center

Support for VPC Service Controls released to Preview

You can now protect Security Command Center using VPC Service Controls perimeters. For more information, see VPC Service Controls supported products.

Traffic Director

Traffic Director advanced load balancing, which is in Preview, is updated to include failover health threshold configuration.

VPC Service Controls

Preview stage supported for the following integration:

Preview stage supported for the following integration:

November 07, 2023

BigQuery

The batch SQL translator has added enhancements when viewing SQL translation reports. You can now see a log summary of all issues during a translation job, as well as a code tab that displays a side-by-side comparison of your input and output files from a translation. This feature is in preview.

Cloud Asset Inventory

The following resource types are now publicly available through the Search APIs (SearchAllResources, SearchAllIamPolicies):

Cloud Monitoring

Observability for Google Kubernetes Engine: The Observability tab for a GKE deployment now shows application performance metrics if the metrics are available. The supported metric sources include Istio, GKE Ingress, NGINX Ingress and gRPC and HTTP metrics collected by using Google Managed Service for Prometheus. For more information, see Use application performance metrics.

Cloud Spanner

Cloud Spanner now supports the Go programming language ORM, GORM, with GoogleSQL-dialect databases. For more information, see Integrate Spanner with GORM (GoogleSQL dialect).

Cloud Workstations

Cloud Workstations is available in the asia-east2 region (Hong Kong, APAC). For more information, see Locations.

Compute Engine

Generally available: A replica recovery checkpoint of a regional Persistent Disk volume represents the most recent crash-consistent point in time of the fully replicated disk. For disks that are not fully replicated, you can use the checkpoint to create disk snapshots from an incomplete zonal replica. You can create and use these snapshots to recover disk data in the rare scenario where your synced replica goes down before your incomplete replica catches up.

Learn more about Regional Persistent Disk replica recovery checkpoints and how to use checkpoints to recover a degraded disk.

Contact Center AI Platform

Release 3.4

All release notes published on this date are part of the 3.4 release.

Campaigns, Do Not Call (DNC) list: You can now create your own Do Not Call (DNC) list for campaign calls. You can enable the Company DNC at Settings > Campaigns > Company Do Not Call (DNC) List. The DNC list is managed using the dedicated DNC API endpoints. Depending on configuration the DNC list can block direct, manual, and outbound calls as well as outbound and scheduled calls created by the Apps API.

Campaigns, time zone management: This release includes new time zone settings to simplify management of different time zones and calling time standards. You can now set up different time zone schemas and apply a specific time zone schema for each campaign. For example, you can use this feature to apply customized schemas to regions that have strict rules about when telemarketing calls are allowed.

You can configure time zone settings at Settings > Campaigns > Timezone Management.

Kustomer bi-directional agent status: The Kustomer integration now offers bi-directional agent status syncing.

Virtual Agent, signed and unsigned data parameters: You can now pass signed and unsigned (secured/unsecured) data parameters for Virtual Agent calls and chats using Mobile SDK in addition to the Web SDK.

Pass voice and chat channel parameter to Virtual Agent: Virtual Agents can now pass channel-specific parameters to CCAI Platform when invoking an Dialogflow Agent. This update applies to Voice Virtual Agents in IVR and Mobile channels.

Localization country code setting for calls: A country code based on outgoing or dialed number has been added to the dial dialog and add party dialog.

CCAI Platform has added "Virtual Agent" tags and prefixes in CCAI Insights for all Virtual Agent conversations.

CCAI Platform has added a fix for when the merge recording feature isn't working as expected.

Container Optimized OS

cos-dev-113-18041-0-0

Kernel Docker Containerd GPU Drivers
COS-6.1.60 v24.0.5 v1.7.7 v535.104.12(default, latest),v470.199.02(R470 for compatibility with K80 GPUs)

Updated google-guest-configs to 20230929.00.

Upgraded chromeos-base/system_api to v0.0.1-r5482.

Upgraded chromeos-base/chromeos-common-script to v0.0.1-r578.

Upgraded chromeos-base/debugd-client to v0.0.1-r2581.

Upgraded chromeos-base/dlcservice-client to v0.0.1-r836.

Upgraded chromeos-base/power_manager-client to v0.0.1-r2803.

Upgraded chromeos-base/update_engine-client to v0.0.1-r2335.

Upgraded chromeos-base/session_manager-client to v0.0.1-r2669.

Upgraded chromeos-base/shill-client to v0.0.1-r4104.

cos-97-16919-404-13

Kernel Docker Containerd GPU Drivers
COS-5.10.197 v20.10.24 v1.6.21 v470.199.02(default),v535.104.12(latest)

Updated google-guest-configs to 20230929.00.

Fixed CVE-2023-42754 in the Linux kernel.

Fixed CVE-2023-45863 in the Linux kernel.

Fixed CVE-2023-5717 in the Linux kernel.

cos-101-17162-336-20

Kernel Docker Containerd GPU Drivers
COS-5.15.133 v20.10.24 v1.6.24 v470.199.02(default),v535.104.12(latest)

Updated google-guest-configs to 20230929.00.

Fixed CVE-2023-42754 in the Linux kernel.

Fixed CVE-2023-5717 in the Linux kernel.

cos-105-17412-226-28

Kernel Docker Containerd GPU Drivers
COS-5.15.133 v23.0.3 v1.7.7 v470.199.02(default),v535.104.12(latest)

Updated google-guest-configs to 20230929.00.

Fixed CVE-2023-42754 in the Linux kernel.

Fixed CVE-2023-5717 in the Linux kernel.

cos-109-17800-66-19

Kernel Docker Containerd GPU Drivers
COS-6.1.58 v24.0.5 v1.7.7 v535.104.12(default, latest),v470.199.02(R470 for compatibility with K80 GPUs)

Updated google-guest-configs to 20230929.00.

Fixed CVE-2023-5717 in the Linux kernel.

Dataproc

Set spark.shuffle.mapOutput.minSizeForBroadcast=128m to fix SPARK-38101 when Dataproc Serverless Spark dynamic allocation is enabled.

Dialogflow

Dialogflow CX now has a new language code for Hebrew: he-il. For supported features, check the language reference table.

The iw Hebrew language code is now deprecated, so new agents should use the he-il language code. Existing agents using the iw language code will continue working, but the list of supported features won't be expanded.

Google Kubernetes Engine

A set of vulnerabilities (CVE-2023-4015, CVE-2023-4623, CVE-2023-4623, CVE-2023-4921) have been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.

GKE clusters are impacted.

For more information, see the following security bulletins:

GKE begins automatically upgrading clusters still running version 1.24 to version 1.25 after 1.24 reaches end of life on January 8, 2024. We extended this date from October 31, 2023 to minimize disruptions around the end-of-year holiday period, and will provide patches only for critical vulnerabilities during this extended period. To learn more about the GKE minor version lifecycle, see GKE versioning and support. GKE continues to pause automatic upgrades until January 8, 2024 for clusters still using deprecated APIs removed in version 1.25, including beta APIs and PodSecurityPolicy. We recommend that you upgrade your clusters to version 1.25 as soon as possible as GKE minor versions that have reached end of life will no longer receive security patches and bug fixes.

Policy Intelligence

You can use the Google Cloud console to analyze organization policies. This feature is available in Preview.

Resource Manager

You can use the Google Cloud console to analyze organization policies. This feature is available in Preview.

Vertex AI

Training on TPU VMs is generally available (GA).

November 06, 2023

Anthos clusters on bare metal

Release 1.14.10

Anthos clusters on bare metal 1.14.10 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.14.10 runs on Kubernetes 1.25.

Functionality changes:

  • Added NODEPOOL-NAME, NODEPOOL-NAMESPACE, and STATUS columns for the InventoryMachine resource to improve troubleshooting.

  • Removed hardcoded timeout value for the bmctl backup operation.

Fixes:

  • Fixed an issue where CoreDNS Pods can get stuck in an unready state.

  • Fixed a memory leak in Dataplane V2.

Fixes:

The following container image security vulnerabilities have been fixed in version 1.14.10:

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

App Engine flexible environment Python App Engine standard environment Python BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for bigquery/storage/apiv1beta1

1.57.1 (2023-11-01)

Bug Fixes

1.57.0 (2023-10-30)

Features
  • bigquery/biglake: Promote to GA (e864fbc)
  • bigquery/storage/managedwriter: Support default value controls (#8686) (dfa8e22)
  • bigquery: Expose Apache Arrow data through ArrowIterator (#8506) (c8e7692), refs #8100
  • bigquery: Introduce query preview features (#8653) (f29683b)
Bug Fixes
  • bigquery: Handle storage read api Recv call errors (#8666) (c73963f)
  • bigquery: Update golang.org/x/net to v0.17.0 (174da47)
  • bigquery: Update grpc-go to v1.56.3 (343cea8)
  • bigquery: Update grpc-go to v1.59.0 (81a97b0)

Python

Changes for google-cloud-bigquery

3.13.0 (2023-10-30)

Features
  • Add Model.transform_columns property (#1661) (5ceed05)
  • Add support for dataset.default_rounding_mode (#1688) (83bc768)
Bug Fixes
Documentation
  • Remove redundant bigquery_update_table_expiration code sample (#1673) (2dded33)
  • Revised create_partitioned_table sample (#1447) (40ba859)
  • Revised relax column mode sample (#1467) (b8c9276)

The BigQuery Data Transfer Service can now transfer campaign reporting and configuration data from Display & Video 360 into BigQuery. This feature is in preview.

The following BigQuery ML features for time series forecasting are now generally available (GA):

Cloud Asset Inventory Cloud Composer

The apache-airflow-providers-google package is upgraded to version 10.10.1 in images with Airflow 2.6.3 and 2.5.3. For more information about changes, see the apache-airflow-providers-google changelog from version 10.10.0 to version 10.10.1.

The apache-airflow-providers-cncf-kubernetes package was upgraded to version 7.6.0.

Cloud Composer 2.5.1 images are available:

  • composer-2.5.1-airflow-2.5.3
  • composer-2.5.1-airflow-2.6.3 (default)

Cloud Composer versions 2.0.31, 2.0.30, 1.19.14, and 1.19.13 have reached their end of full support period.

Cloud Functions

Cloud Functions now supports the Python 3.12 runtime at the General Availability release level.

Cloud Healthcare API

Configuring Blob storage settings is now available in Preview. With this feature you can do the following:

Cloud Logging

Log buckets in the following regions can now be upgraded to use Log Analytics:

  • me-central2

For more information, see Supported regions.

Cloud SQL for MySQL

Cloud SQL Enterprise Plus edition now supports asia-southeast2 (Jakarta).

Cloud SQL for PostgreSQL

Cloud SQL Enterprise Plus edition now supports asia-southeast2 (Jakarta).

Cloud Workstations

The Code-OSS preconfigured base image uses version 1.83.1.

Dataflow

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for dataflow/apiv1beta3

0.9.4 (2023-11-01)

Bug Fixes
  • dataflow: Bump google.golang.org/api to v0.149.0 (8d2ab9f)
Dataproc Metastore

The Data Catalog Sync feature is generally available (GA). With this launch, Data Catalog also now supports syncing metadata from Dataproc Metastore services using the Spanner Database.

Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-datastore

2.17.5 (2023-11-02)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.19.0 (#1226) (970ac96)
Google Cloud Architecture Center

Scalable TensorFlow inference system: Converted the Tensorflow inference system guide into a reference architecture that includes design considerations.

Secret Manager

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for secretmanager/apiv1

1.11.4 (2023-11-01)

Bug Fixes
  • secretmanager: Bump google.golang.org/api to v0.149.0 (8d2ab9f)
Speech-to-Text

Speech-to-Text has launched two models, named telephony and telephony_short. The two models are customized to recognize audio that originates from a phone call and corresponds to the most recent versions of the existing phone_call model. For more information, see Speech-to-Text supported languages.

Text-to-Speech

As of November 13 2023, speaker en-US-Studio-M will no longer be available. All requests sent to en-US-Studio-M will be routed to speaker en-US-Studio-Q. There is no action needed.

Vertex AI Search and Conversation

Vertex AI Search: Multi-region support for US and EU locations is GA

The US multi-region and the EU multi-region APIs are generally available (GA).

For more information about multi-regions including limitations, see Vertex AI Search locations.

November 03, 2023

Apigee X

On November 3, 2023, we updated the following security bulletin:

Bug ID Description
304599411 Security bulletin updated
GCP-2023-32
A Denial-of-Service (DoS) vulnerability was recently discovered in multiple implementations of the HTTP/2 protocol (CVE-2023-44487), including the Apigee Ingress (Anthos Service Mesh) server used by Apigee X. The vulnerability could lead to a DoS of Apigee API management functionality.

The shutdown of the Configurable API Proxy (Preview) feature is approaching. On or after November 10, 2023, the preview feature will no longer be available. For more information, see Configurable API proxies (preview) deprecation.

Cloud Healthcare API

Connecting to applications using SMART on FHIR in the Cloud Healthcare API is available in Preview.

Cloud Monitoring

Synthetic monitors are now GA. You can create synthetic monitors by using Terraform, the Cloud console, and the Monitoring API. You can configure your synthetic monitors to collect log data and trace data. When you use the Cloud console, the generic and Mocha templates are available:

Cloud Storage

The Autoclass feature can now be enabled for existing buckets.

  • Previously, Autoclass could only be enabled when creating a new bucket.
  • Enabling Autoclass on an existing bucket incurs additional charges.
Cloud Workstations

Support for custom domains is available in preview through the gcloud CLI and REST API. To access your workstations, you can specify a trusted, custom domain rather than using the default cloudworkstations.dev domain.

Compute Engine

The h3-node-88-352 sole-tenant node type is now Generally Available.

Confidential VM

Confidential Space. A new image (confidential-space-231001) is now available. This image provides support for signing container images. For more information, see the Changelog.

Google Cloud Architecture Center

(New guide) Google Cloud deployment archetypes: Overview and comparative analysis of the zonal, regional, multi-regional, global, hybrid, and multicloud deployment archetypes.

Google Distributed Cloud Edge

This is a patch release of Google Distributed Cloud Edge (version 1.5.1).

The following changes have been introduced in this release of Distributed Cloud Edge:

  • Cluster software version upgrades for local control plane clusters. You can now trigger a software version upgrade on a local control plane cluster to a specific version of Distributed Cloud Edge software, starting with version 1.5.1. This feature is not available for Cloud control plane clusters. For instructions, see Upgrade the software version on a local control plane cluster.

  • Cluster software version pinning for local control plane clusters. You can now pin a local control plane cluster to a specific version of Distributed Cloud Edge software, starting with version 1.5.0. A cluster pinned to a specific version does not automatically upgrade when new Distributed Cloud Software becomes available. This feature is not available for Cloud control plane clusters. For instructions, see Create a cluster.

  • Cluster status. The gcloud edge-cloud container describe command now returns the operational status of a Distributed Cloud Edge cluster.

The following issues have been resolved in this release of Distributed Cloud Edge:

  • CVE-2022-40982 "Downfall" remediation. The CVE-2022-40982 vulnerability, also known as "Downfall," has been patched.

This release of Distributed Cloud Edge contains the following known issues:

  • Cloud SDK version 450.0.0 or later is required. You must upgrade your Cloud SDK to version 450.0.0 or later to create local control plane clusters with Distributed Cloud Edge software version 1.5.0. Otherwise, creating such clusters will fail.

  • Node and machine labels are not applied when upgrading to Distributed Cloud Edge version 1.5.1. When upgrading to Distributed Cloud Edge version 1.5.1, system-required labels might not be applied to nodes and machines within existing node pools. To work around this issue, either modify the affected node pool to update its corresponding resource definition, or delete and re-add the affected nodes. For instructions, see Create and manage node pools.

Text-to-Speech

Cloud Text-to-Speech now offers en-GB Studio voices: en-GB-Studio-B and en-GB-Studio-C.

Vertex AI

The following models have been added to Model Garden:

  • ImageBind: Multimodal embedding model.
  • Vicuna v1.5: LLM finetuned based on llama2.
  • OWL-ViT v2: SoTA Open Vocabulary Object Detection model.
  • DITO: SoTA Open Vocabulary Object Detection model.
  • NLLB: Multi-language translation model.
  • Mistral-7B: SoTA LLM at small size.
  • BioGPT: LLM finetuned for biomedical domain.
  • BiomedCILP: Multimodal foundational model finetuned for biomedical domain.

To see a list of all available models, see Explore models in Model Garden.

New textembedding-gecko and textembedding-gecko-multilingual stable model versions

The following stable model versions are available in Generative AI on Vertex AI:

  • textembedding-gecko@002
  • textembedding-gecko-multilingual@001

For more information on model versions, see Model versions and lifecycle.

Model Garden

  • Improved language model serving throughput. For details, see Serving open source large language models efficiently on Model Garden. Notebooks in the relevant model cards have been updated accordingly.
  • Inference speed up to 2 times faster compared with original implementation for Stable Diffusion 1.5, 2.1, and XL models.
  • Improved the workflow of the Deploy button in all supported model cards.
  • Updated notebooks for Llama2, OpenLlama, and Falcon Instruct with suggested machine specs for model serving, and EleutherAI's evaluation harness dockers for model evaluation.

November 02, 2023

BigQuery

BigQuery now supports text analysis configuration options for the following:

BigQuery now also provides support for the following advanced processing functions:

These features are now in preview.

Chronicle

The following supported default parsers have changed. Each is listed by product name and log_type value, if applicable.

  • Akamai WAF (AKAMAI_WAF)
  • Atlassian Confluence (ATLASSIAN_CONFLUENCE)
  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • AWS EMR (AWS_EMR)
  • Azure AD Organizational Context (AZURE_AD_CONTEXT)
  • Carbon Black (CB_EDR)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Umbrella Web Proxy (UMBRELLA_WEBPROXY)
  • Cloud Load Balancing (GCP_LOADBALANCING)
  • Cloud SQL (GCP_CLOUDSQL)
  • DNSFilter (DNSFILTER)
  • Duo Auth (DUO_AUTH)
  • Elastic Windows Event Log Beats (ELASTIC_WINLOGBEAT)
  • Evision FircoSoft (EVISION_FIRCOSOFT)
  • ExtraHop RevealX (EXTRAHOP)
  • F5 ASM (F5_ASM)
  • Firewall Rule Logging (N/A)
  • Fortinet FortiClient (FORTINET_FORTICLIENT)
  • GCP_KUBERNETES_CONTEXT (GCP_KUBERNETES_CONTEXT)
  • GitHub (GITHUB)
  • Gitlab (GITLAB)
  • Hashicorp Vault (HASHICORP)
  • IBM DataPower Gateway (IBM_DATAPOWER)
  • IBM DB2 (DB2_DB)
  • IBM Security Verify SaaS (IBM_SECURITY_VERIFY_SAAS)
  • Infoblox (INFOBLOX)
  • JumpCloud Directory Insights (JUMPCLOUD_DIRECTORY_INSIGHTS)
  • Juniper Junos (JUNIPER_JUNOS)
  • Kolide Endpoint Security (KOLIDE)
  • ManageEngine ADAudit Plus (ADAUDIT_PLUS)
  • Microsoft Exchange (EXCHANGE_MAIL)
  • Microsoft IIS (IIS)
  • Office 365 (OFFICE_365)
  • Open Cybersecurity Schema Framework (OCSF) (OCSF)
  • Oracle (ORACLE_DB)
  • Oracle Cloud Infrastructure (ORACLE_CLOUD_AUDIT)
  • Proofpoint On Demand (PROOFPOINT_ON_DEMAND)
  • Qualys VM (QUALYS_VM)
  • Saiwall VPN (SAIWALL_VPN)
  • SentinelOne EDR (SENTINEL_EDR)
  • Slack Audit (SLACK_AUDIT)
  • Unix system (NIX_SYSTEM)
  • Windows Event (WINEVTLOG)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Workspace Alerts (WORKSPACE_ALERTS)
  • Workspace ChromeOS Devices (WORKSPACE_CHROMEOS)
  • Zscaler Internet Access Audit Logs (ZSCALER_INTERNET_ACCESS)

The following log types, without a default parser, were added. Each is listed by product name and log_type value, if applicable.

  • Analyst1 IOC (ANALYST1_IOC)
  • Amazon FSx for Windows File Server (AWS_FSX)
  • DealCloud (DEAL_CLOUD)
  • DomainTools Threat Intelligence (DOMAINTOOLS_THREATINTEL)
  • Farsight DNSDB (FARSIGHT_DNSDB)
  • Journald (JOURNALD)
  • Mambu (MAMBU)
  • Mattermost (MATTERMOST)
  • Mitel Communications Director (MITEL_MCD)
  • NordLayer VPN (NORD_LAYER)
  • Paxton Access Control Systems (PAXTON_ACS)

For a list of supported log types and details about default parser changes, see Supported log types and default parsers.

Cloud Healthcare API

A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.

Cloud Spanner

Table and index operations statistics are now generally available. This feature helps you get insights and monitor usages of your tables and indexes in your database. For more information, see Table operations statistics.

Document AI Warehouse

Grant the documentSchemaViewer, documentCreator, and documentViewer roles the contentwarehouse.googleapis.com/locations.getStatus permission. This change enables the UI to render correctly, and does not change the security posture of these roles.

Filestore Google Kubernetes Engine

A bug that caused failures when many concurrent operations were run on the same cluster (such as when creating multiple node pools) has been fixed.

Retail API

Retail API: Configure logging

You can configure which service logs are written to Cloud Logging. Logging configuration provides a way to set the severity levels at which to write logs, turn logging on or off, and override default logging settings for specific services. For information on how to change Logging configurations, see Configure Logging.

Vertex AI

Generative AI support on Vertex AI

Generative AI on Vertex AI can be accessed through 12 regional APIs in North America, Europe, and Asia. Regional APIs let customers control where data is stored at-rest.

November 01, 2023

Apigee Advanced API Security

On November 1, 2023 we release an updated version of Advanced API Security.

Public preview of Advanced API Security custom profiles in the Apigee UI

With this release, you can now create and edit custom security profiles in the Apigee UI. Custom profiles let you specify the security categories that your security scores are based on.

The Security scores page in the Apigee UI has been renamed to the Risk assessment page, and the page now has tabs for security scores and security profiles.

BigQuery

The following INFORMATION_SCHEMA views that show metadata for table storage usage are now in preview:

You can now use cached results from the same query issued by other users in the same project when you use Enterprise or Enterprise Plus edition. This feature is generally available (GA).

Chronicle

Chronicle Curated Detections has been enhanced with new detection content for Google Cloud threats. These new rule sets help identify Kubernetes activity associated with abuse of role-based access controls (RBAC).

Chronicle SOAR

Release Notes 6.2.38

Beta - 5th November, 2023

GA - 12th November, 2023

Custom roles denied access to Advanced Reports (ID #47668375)

In certain cases, significantly large entity graphs failed to load (ID #00250400)

Cloud Logging Cloud Shell

Duet AI for Cloud Shell is now available. Use Duet AI, your AI-powered collaborator, to accomplish tasks more effectively and efficiently. Duet AI provides contextualized responses to your prompts to help guide you on what you're trying to do with your code. It also shares source citations regarding which documentation and code samples the assistant used to generate its responses.

If you use the latest version of the Cloud Shell editor, which is Code - OSS based, you can use Duet AI for Cloud Shell. For more information, see the Duet AI in Google Cloud overview and Code with Duet AI assistance.

Cloud Workstations

Duet AI for Cloud Workstations is available. Use Duet AI, your AI-powered collaborator, to accomplish tasks more effectively and efficiently. Duet AI provides contextualized responses to your prompts to help guide you on what you're trying to do with your code. It also shares source citations regarding which documentation and code samples the assistant used to generate its responses.

If you use the Code - OSS base image, you can use Duet AI in the Cloud Workstations base editor. For more information, see the Duet AI in Google Cloud overview and Code with Duet AI assistance.

Colab Enterprise

Inline code completion with Duet AI assistance is now generally available (GA). For more information, see Write code in a Colab Enterprise notebook with Duet AI assistance.

Compute Engine

Generally available: When assigning a custom queue count for the receive and transmit queues for a vNIC, under certain conditions, you can configure a number of custom queue counts that exceeds the number of vCPUs allocated to the VM.

Dataproc

Announcing the Preview release of Dataproc Flexible VMs. This feature lets you specify prioritized lists of secondary worker VM types that Dataproc will select from when creating your cluster. Dataproc will select the VM type with sufficient available capacity while taking quotas and reservations into account.

Dialogflow

Data store agents now support additional languages and regions.

Dialogflow CX now supports the DIVIDE and MULTIPLY system functions.

Error Reporting Storage Transfer Service

Storage Transfer Service has updated transfer agent behavior when transferring to Cloud Storage. To align with Cloud Storage auto-scaling, agents now gradually ramp up the number of requests being made to Cloud Storage. Customers who transfer many small files may notice initially slower transfer speeds while the requests are ramping up, but increased performance across the duration of the transfer.

VPC Service Controls

General availability support for the following integration:

October 31, 2023

Anthos Service Mesh

1.19.3-asm.0 is now available for in-cluster Anthos Service Mesh.

You can now download 1.19.3-asm.0 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.19.3 subject to the list of supported features. Anthos Service Mesh 1.19.3-asm.0 uses Envoy v1.27.1.

After upgrading Anthos Service Mesh to version 1.19.3 for off-Google Cloud clusters, make sure to restart all Pods in order to trigger the re-injection of sidecars. Otherwise, the Anthos Service Mesh metric reports might become inconsistent between the old and new proxies in the cluster.

Managed Anthos Service Mesh 1.19 isn't rolling out to the rapid release channel at this time. You can periodically check this page for announcements regarding rapid channel rollout. See Select a managed Anthos Service Mesh release channel for more information.

Anthos clusters on VMware

Anthos clusters on VMware 1.15.6-gke.25 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.15.6-gke.25 runs on Kubernetes 1.26.9-gke.700.

The following vulnerabilities are fixed in 1.15.6-gke.25:

Artifact Registry

Artifact Registry remote repositories now support authentication to Docker Hub upstream repositories.

To create a Docker Hub remote repository, take the quickstart.

Backup for GKE

Backup for GKE now supports transformation rules that allow for the modification of resources during restore. This is an improvement over the existing substitution rules. For more information, see Modify resources during restoration.

Terraform now supports managing Backup for GKE RestorePlan resources. For more information, see google_gke_backup_restore_plan.

BigQuery

BigQuery support for change data capture (CDC) by processing and applying streamed changes in real-time to existing data using the BigQuery Storage Write API is now generally available (GA).

You can now use data manipulation language (DML) to modify rows that have been recently written by the Storage Write API. This feature is in preview.

Cloud Asset Inventory

The following resource types are now publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, and Feed APIs.

  • Identity and Access Management
    • iam.googleapis.com/PolicyV2
Cloud Run

Job overrides are now at general availability (GA). This feature lets you override the arguments, environment variables, number of tasks, and task timeouts already configured for a job when you execute a job.

Cloud Spanner

The Cloud Spanner ExecuteBatchDml API now applies optimizations to groups of statements within a batch to enable faster and more efficient data updates. For more information, see Improve latency with batch DML.

Compute Engine

Preview: Advanced maintenance control for sole-tenancy lets you control planned maintenance events for sole-tenant node groups and minimise maintenance-related disruptions. This feature is available only for sole-tenant node groups. To use this feature with your existing virtual machines, you must first move your VMs to sole-tenant node groups that have advanced maintenance control enabled.

The advanced maintenance control for sole-tenancy feature lets you:

  • Check for maintenance events scheduled for a sole-tenant node 28 days in advance.
  • Trigger maintenance immediately or schedule it for later. Note that if you trigger maintenance immediately, the maintenance takes place within 24-hours from the time you trigger the request.

For more information, see Advanced maintenance control for sole-tenancy.

Dataproc Metastore

Dataproc Metastore is available in the following multi-regional configurations, nam11 and eur5.

Google Cloud Architecture Center

PCI DSS compliance on GKE: Updated to meet the requirements of PCI DSS version 4.0, use Cloud IDS instead of a third-party IDS, and use the PodSecurity admission controller instead of PodSecurityPolicy.

Google Kubernetes Engine

GKE multi-cluster Gateway is now generally available in GKE versions 1.24 and later for GKE Standard clusters, and versions 1.26 and later for GKE Autopilot clusters. Use the Gateway API to express the intent of your inbound HTTP(S) traffic into your fleet of GKE clusters. The multi-cluster Gateway controller deploys and manages the Application Load Balancers that forward traffic to your applications. To learn more, see Enable multi-cluster Gateways. For the list of supported Cloud Load Balancers and their features, refer to GatewayClass capabilities.

Secret Manager

For more information, refer to the overview of Key Access Justifcations.

Transfer Appliance

Transfer Appliance now has alpha-level support in the gcloud CLI (gcloud alpha transfer appliances) allowing you to view in-progress transfer results, work with draft orders, clone existing orders, and more. See the reference documentation for full details.

Workflows

Workflows is available in the following additional region: europe-west10 (Berlin, Germany).

October 30, 2023

Access Transparency

Access Transparency supports Agent Assist in the GA stage.

Anthos Attached Clusters

This release includes the following Anthos attached clusters platform versions:

  • 1.25.0-gke.8
  • 1.26.0-gke.6
  • 1.27.0-gke.3

1.25.0-gke.8, 1.26.0-gke.6, and 1.27.0-gke.3

Added support for attaching any CNCF-conformant Kubernetes cluster, in addition to EKS and AKS clusters. To attach a cluster, specify the distribution type as "generic".

1.27.0-gke.3

Removed deployment of Fluent Bit when logging is disabled.

Anthos clusters on AWS

You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:

Anthos clusters on Azure

You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:

Anthos clusters on bare metal

Release 1.15.6

Anthos clusters on bare metal 1.15.6 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.15.6 runs on Kubernetes 1.26.

Functionality changes:

  • Removed hardcoded timeout value for the bmctl backup operation.

Fixes:

  • Fixed a memory leak in Dataplane V2.

  • Added direct dependencies on systemd, containerd, and kubelet over their mount point folders in /var/lib/.

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

Release 1.16.2

Anthos clusters on bare metal 1.16.2 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.16.2 runs on Kubernetes 1.27.

Functionality changes:

  • Increased the certificate time to live (TTL) for metrics-providers-ca and stackdriver-prometheus-scrape for third-party monitoring.

  • Removed hardcoded timeout value for the bmctl backup operation.

Fixes:

  • Fixed the spec.featureGates.annotationBasedApplicationMetrics feature gate in the stackdriver custom resource to enable collection of annotation-based workload metrics. This function is broken in Anthos clusters on bare metal versions 1.16.0 and 1.16.1.

  • Fixed a memory leak in Dataplane V2.

  • Fixed an issue where garbage collection deleted Source Network Address Translation (SNAT) entries for long-lived egress NAT connections, causing connection resets.

  • Fixed an issue that caused file and directory permissions to be set incorrectly after backing up and restoring a cluster.

  • Added direct dependencies on systemd, containerd, and kubelet over their mount point folders in /var/lib/.

  • Fixed an issue where etcd blocked upgrades due to an incorrect initial-cluster-state.

  • Fixed an issue that blocked upgrades to version 1.16 for clusters that have secure computing mode (seccomp) disabled.

The following container image security vulnerabilities have been fixed in release 1.16.2:

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

BigQuery

The BigQuery Data Transfer Service can now transfer data from Azure Blob Storage into BigQuery. This feature is now generally available (GA).

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigquery

2.34.0 (2023-10-26)

Features
  • Add BigLakeConfiguration Property in StandardTableDefinition.java (#2916) (1d660fa)
  • Add support for Dataset property storageBillingModel (#2913) (f452cf4)
  • Add support for preview features (#2923) (113b8f2)
Dependencies
  • Update actions/checkout action to v4.1.1 (#2950) (c556c18)
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.30.0 (#2942) (e760fca)
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.31.0 (#2967) (7ed55b5)
  • Update dependency com.google.apis:google-api-services-bigquery to v2-rev20231008-2.0.0 (#2946) (3d0da5b)
  • Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.34.0 (#2943) (18162c3)
  • Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.35.0 (#2968) (219db2c)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.18.0 (#2955) (1ee18eb)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.28 (#2956) (b03effd)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.28 (#2957) (6465e41)
  • Update github/codeql-action action to v2.22.2 (#2944) (f584e59)
  • Update github/codeql-action action to v2.22.3 (#2954) (1b2bc18)
  • Update github/codeql-action action to v2.22.4 (#2958) (de9bcee)
  • Update ossf/scorecard-action action to v2.3.1 (#2960) (855e698)

The administrative resource charts now supports the following features in preview:

Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigtable

2.29.0 (2023-10-26)

Features
Dependencies
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.28 (#1966) (8fb09e5)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.28 (#1967) (117e0ec)
  • Update shared dependencies (#1964) (bf5a9b7)
Cloud Composer

Bring your own bucket feature is now generally available (GA). You can now use a custom Cloud Storage bucket as an environment's bucket.

Directories with names ending in .py are no longer synchronized. If your environment's bucket contains such directories, please rename them.

Fixed the cause of workers and schedulers failing when Cloud Storage objects with invalid filesystem names are synchronized.

Fixed the validation of the constraints/gcp.restrictServiceUsage Organization Policy constraint. It no longer checks the non-blockable services, such as Cloud Logging and Cloud Monitoring.

The apache-airflow-providers-google package is upgraded to version 10.10.0 in images with Airflow 2.6.3 and 2.5.3. For more information about changes, see the apache-airflow-providers-google changelog from version 10.9.0 to version 10.10.0.

In December 2023, we plan to switch newly created Cloud Composer 2 environments to stop storing task logs in the environment's bucket by default:

  • Task logs will be available in Cloud Logging and Airflow UI.
  • This change will not be enabled in already existing environments, including environments upgraded to a later version of Cloud Composer that supports this feature.
  • It will be possible to enable and disable the synchronization of task logs to the environment's bucket for an existing environment.

This planned change will be announced in the Release Notes when it is rolled out.

The default version of Airflow is changed to 2.6.3.

Airflow 2.4.3 is no longer included in Cloud Composer images.

Cloud Composer 2.5.0 images are available:

  • composer-2.5.0-airflow-2.5.3
  • composer-2.5.0-airflow-2.6.3 (default)

Cloud Composer versions 2.0.29 and 1.19.12 have reached their end of full support period.

Cloud Data Fusion

The Cloud Data Fusion version 6.8.3.1 patch release is generally available (GA). It fixes a regression that causes a pipeline to fail when using Dataproc secondary workers (CDAP-20807).

The Cloud Data Fusion version 6.9.2.1 patch release is generally available (GA). It fixes a regression that causes a pipeline to fail when using Dataproc secondary workers (CDAP-20807).

Cloud Logging

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-logging

3.15.12 (2023-10-25)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.18.0 (#1454) (dc25a87)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.28 (#1455) (3080cec)
Cloud SQL for PostgreSQL

The rollout of the following items is complete:

  • The oracle_fdw extension, version 1.2
  • The minor versions, extension versions, and plugin versions listed in the September 21 release note
Cloud Spanner

A monthly digest of client library updates from across the Cloud SDK.

Go

Changes for spanner/admin/database/apiv1

1.50.0 (2023-10-03)

Features
  • spanner/spansql: Add support for aggregate functions (#8498) (d440d75)
  • spanner/spansql: Add support for bit functions, sequence functions and GENERATE_UUID (#8482) (3789882)
  • spanner/spansql: Add support for SEQUENCE statements (#8481) (ccd0205)
  • spanner: Add BatchWrite API (02a899c)
  • spanner: Allow non-default service accounts (#8488) (c90dd00)

1.51.0 (2023-10-17)

Features
  • spanner/admin/instance: Add autoscaling config to the instance proto (#8701) (56ce871)
Bug Fixes
  • spanner: Update golang.org/x/net to v0.17.0 (174da47)

Java

Changes for google-cloud-spanner

6.48.0 (2023-09-26)

Features
Bug Fixes
  • Retry aborted errors for writeAtLeastOnce (#2627) (2addb19)
Dependencies
  • Update actions/checkout action to v4 (#2608) (59f3e70)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.27 (#2574) (e804a4c)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.27 (#2575) (6fe132a)

6.49.0 (2023-09-28)

Features
  • Add session pool option for modelling a timeout around session acquisition. (#2641) (428e294)
Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.16.1 (#2637) (3f48624)
Documentation
  • Improve timeout and retry sample (#2630) (f03ce56)
  • Remove reference to returning clauses for Batch DML (#2644) (038d8ca)

6.50.0 (2023-10-09)

Features
  • Support setting core pool size for async API in system property (#2632) (e51c55d), closes #2631
Dependencies
  • Update dependency com.google.cloud:google-cloud-trace to v2.24.0 (#2577) (311c2ad)

6.50.1 (2023-10-11)

Bug Fixes
  • Noop in case there is no change in autocommit value for setAutocommit() method (#2662) (9f51b64)
Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.17.0 (#2660) (96b9dd6)
  • Update dependency commons-io:commons-io to v2.14.0 (#2649) (fa1b73c)

6.51.0 (2023-10-14)

Features
  • spanner: Add autoscaling config to the instance proto (#2674) (8d38ca3)
Bug Fixes
  • Always include default client lib header (#2676) (74fd174)

6.52.0 (2023-10-19)

Features

6.52.1 (2023-10-20)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.18.0 (#2691) (b425021)
Container Optimized OS

cos-dev-113-18026-0-0

Kernel Docker Containerd GPU Drivers
COS-6.1.60 v24.0.5 v1.7.7 v535.104.12(default, latest),v470.199.02(R470 for compatibility with K80 GPUs)

Updated the Linux kernel to v6.1.60.

Updated default and latest NVIDIA GPU drivers to v535.104.12.

Updated app-containers/runc to v1.1.9.

Updated app-containers/containerd to v1.7.7.

Upgraded sys-apps/file to v5.45-r3.

Upgraded sys-fs/xfsprogs to v6.5.0.

Upgraded dev-python/pygobject to v3.46.0.

Enable portmapper registration reporting for lsof. This also fixes an issue where lsof is missing from SOS reports.

Add compiler mitigations to mitigate memory corruption vulnerabilities.

Sequence named before nss-lookup.target.

Restore systemd-logind restart behavior when dbus restarts.

Upgraded chromeos-base/vm_protos to v0.0.1-r513.

Upgraded dev-util/bsdiff to v4.3.1-r41.

Upgraded dev-util/puffin to v1.0.0-r448.

Upgraded chromeos-base/chromeos-common-script to v0.0.1-r566.

Upgraded chromeos-base/update_engine-client to v0.0.1-r2317.

Upgraded chromeos-base/debugd-client to v0.0.1-r2568.

Upgraded chromeos-base/session_manager-client to v0.0.1-r2655.

Upgraded chromeos-base/shill-client to v0.0.1-r4043.

Upgraded chromeos-base/power_manager-client to v0.0.1-r2781.

Upgraded chromeos-base/hiberman-client to v0.0.1-r374.

Upgraded sys-devel/libtool to v2.4.6-r7.

Upgraded chromeos-base/mojo_service_manager to v0.0.1-r265.

Upgraded dev-libs/double-conversion to v3.2.1.

Upgraded net-libs/libtirpc to v1.3.4.

Upgraded sys-libs/zlib to v1.3-r1.

Upgraded net-dns/c-ares to v1.20.1.

Upgraded sys-apps/hwdata to v0.375.

Upgraded net-dns/libidn2 to v2-2.3.4-r1.

Upgraded net-fs/cifs-utils to v7.0-r1, Upgraded sys-libs/talloc to v2.4.1.

Upgraded app-arch/unzip to v6.0_p27-r1.

Upgraded sys-apps/dmidecode to v3.5-r3.

Upgraded dev-libs/nss to v3.94.

Upgraded sys-apps/pv to v1.8.0.

Updated dev-lang/go to v1.21.2. This resolves CVE-2023-39323.

Upgraded net-misc/curl to version v8.4.0. This resolves CVE-2023-38545.

Runtime sysctl changes:

  • Added: net.ipv4.tcp_shrink_window: 0
  • Added: net.ipv6.conf.all.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.default.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.docker0.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.eth0.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.lo.accept_ra_min_lft: 0

cos-109-17800-66-15

Kernel Docker Containerd GPU Drivers
COS-6.1.58 v24.0.5 v1.7.7 v535.104.12(default, latest),v470.199.02(R470 for compatibility with K80 GPUs)

This is an LTS Refresh Release

Updated the Linux kernel to v6.1.58.

Updated app-containers/containerd to v1.7.7.

Updated default and latest NVIDIA GPU drivers to v535.104.12.

Updated dev-lang/go to v1.21.2. This resolves CVE-2023-39323.

Upgraded net-misc/curl to v8.4.0. This resolves CVE-2023-38545.

Fixed CVE-2023-4244 in the Linux kernel.

Enable portmapper registration reporting for lsof. This also fixes an issue where lsof is missing from SOS reports.

Restore systemd-logind restart behavior when dbus restarts.

Runtime sysctl changes:

  • Added: net.ipv6.conf.all.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.default.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.docker0.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.eth0.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.lo.accept_ra_min_lft: 0
  • Changed: fs.file-max: 812619 -> 812608
  • Changed: kernel.threads-max: 63519 -> 63520
  • Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_recd: 0 -> 3
  • Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_sent: 0 -> 3
  • Changed: user.max_cgroup_namespaces: 31759 -> 31760
  • Changed: user.max_ipc_namespaces: 31759 -> 31760
  • Changed: user.max_mnt_namespaces: 31759 -> 31760
  • Changed: user.max_net_namespaces: 31759 -> 31760
  • Changed: user.max_pid_namespaces: 31759 -> 31760
  • Changed: user.max_time_namespaces: 31759 -> 31760
  • Changed: user.max_user_namespaces: 31759 -> 31760
  • Changed: user.max_uts_namespaces: 31759 -> 31760

cos-101-17162-336-16

Kernel Docker Containerd GPU Drivers
COS-5.15.133 v20.10.24 v1.6.24 v470.199.02(default),v535.104.12(latest)

Updated app-emulation/containerd to v1.6.24.

Enable portmapper registration reporting for lsof. This also fixes an issue where lsof is missing from SOS reports.

Fix Node restart due to kernel panic is C3D machines.

Updated dev-lang/go to v1.20.9. This resolves CVE-2023-39323.

cos-97-16919-404-9

Kernel Docker Containerd GPU Drivers
COS-5.10.197 v20.10.24 v1.6.21 v470.199.02(default),v535.104.12(latest)

Enable portmapper registration reporting for lsof. This also fixes an issue where lsof is missing from SOS reports.

Updated latest NVIDIA GPU drivers to v535.104.12.

cos-105-17412-226-23

Kernel Docker Containerd GPU Drivers
COS-5.15.133 v23.0.3 v1.7.7 v470.199.02(default),v535.104.12(latest)

Enable portmapper registration reporting for lsof. This also fixes an issue where lsof is missing from SOS reports.

Updated dev-lang/go to v1.20.9. This resolves CVE-2023-39323.

Dataflow

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for dataflow/apiv1beta3

0.9.3 (2023-10-26)

Bug Fixes
  • dataflow: Update grpc-go to v1.59.0 (81a97b0)
Dataproc

New Dataproc on Compute Engine subminor image versions:

  • 2.0.82-debian10, 2.0.82-rocky8, 2.0.82-ubuntu18
  • 2.1.30-debian11, 2.1.30-rocky8, 2.1.30-ubuntu20, 2.1.30-ubuntu20-arm

Added spark.dataproc.scaling.version=2 config to let customers control the Dataproc Serverless for Spark autoscaling version.

Increased the TTL for Dataproc on Compute Engine custom images from 60 days to 365 days.

Fixed Knox rewrite rules for Zeppelin URLs in some cases in the latest 2.0 and 2.1 Dataproc on Compute Engine image versions.

Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-datastore

2.17.4 (2023-10-23)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.18.0 (#1215) (aa82f01)
  • Update dependency com.google.errorprone:error_prone_core to v2.23.0 (#1213) (c57db43)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.28 (#1216) (ce4eff2)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.28 (#1217) (7d56b3c)
Google Cloud Deploy

Cloud Deploy support for deploy hooks is now generally available.

Google Kubernetes Engine

You can now use GKE node service account insights to troubleshoot common GKE node service account issues. These insights are available in the Network Analyzer and the Recommender API.

Migrate to Containers

On October 30, 2023 we released version 1.3.1 of the Migrate to Containers modernization plugins.

Learn how to Upgrade Migrate to Containers plugins.

The plugins for migrating Apache, JBoss, WordPress, and IBM WebSphere traditional applications to containers are now generally available. These plugins provide a streamlined and simplified experience for migrating applications based on these frameworks.

Network Intelligence Center

Network Analyzer now includes an insight that gives a summary of the Google Kubernetes Engine (GKE) node service account. This insight is already available in the Recommender API. For more information, see GKE node service account insights.

SAP on Google Cloud

Google Cloud storage manager for SAP HANA standby nodes version 2.6

Version 2.6 of the Google Cloud storage manager for SAP HANA standby nodes is now available. This version includes bug fixes and supportability improvements.

For more information about the storage manager, see Storage Manager for SAP HANA.

Secret Manager

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for secretmanager/apiv1

1.11.3 (2023-10-26)

Bug Fixes
  • secretmanager: Update grpc-go to v1.59.0 (81a97b0)
Vertex AI

Deep Learning VM Images is a set of prepackaged virtual machine images with a deep learning framework that are ready to be run out of the box. Recently, an out-of-bounds write vulnerability was discovered in the ReadHuffmanCodes() function in the libwebp library. This might impact images that use this library.

Google Cloud continuously scans its publicly published images and updates the packages to assure patched distros are included in the latest releases available for customer adoption. Deep Learning VM Images have been updated to ensure that the latest VM images include the patched distros. Customers adopting the latest VM images are not exposed to this vulnerability.

For more information, see the Vertex AI security bulletin.

October 27, 2023

Artifact Registry

Artifact Registry remote repositories are now generally available.

Remote repositories store artifacts from external sources such as Docker Hub or PyPI. A remote repository acts as a proxy for the external source so that you have more control over your external dependencies. The first time that you request a version of a package, Artifact Registry downloads and caches the package in the remote repository. The next time you request the same package version, Artifact Registry serves the cached copy.

To get started with remote repositories, try the quickstart.

Artifact Registry virtual repositories are now generally available.

Virtual repositories act as a single access point to download, install, or deploy artifacts in the same format from one or more upstream repositories. An upstream repository can be an Artifact Registry standard or remote repository.

To get started with virtual repositories, create a virtual repository, or see an example of how to use the different repository modes together in the repository overview usage example.

Assured Workloads

The Japan Regions compliance program is now generally available. For a list of Google Cloud products compliant with Japan Regions, see the Supported products page.

Chronicle

Google has added Frankfurt (Germany) and Zurich (Switzerland) as new regions for Chronicle customers. Chronicle can now store customer data in these regions. This also adds new regional endpoints for Chronicle APIs at https://europe-west3-backstory.googleapis.com and https://europe-west6-backstory.googleapis.com.

Cloud Asset Inventory

New searchable fields are now available.

The following resource types are now publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, Feed API, and Search APIs (SearchAllResources, SearchAllIamPolicies).

  • netapp.googleapis.com/StoragePool
  • netapp.googleapis.com/Volume
  • netapp.googleapis.com/Snapshot
  • netapp.googleapis.com/ActiveDirectory
  • netapp.googleapis.com/KmsConfig
  • netapp.googleapis.com/Replication
Cloud SQL for PostgreSQL

You can now specify the SSL mode of your Cloud SQL instances, which gives you more accurate SSL encryption. To use SSL mode, you must use the maintenance version [PostgreSQL version].R20230530.01_00 or newer. For more information, see Enforce SSL/TLS encryption.

Cloud Storage

Turbo replication performance monitoring in the Google Cloud console has been moved and expanded.

  • Monitoring graphs have been moved from a bucket's Configuration tab to its Observability tab.

  • A new, real-time Maximum delay in turbo replication graph is also available in the Observability tab.

Compute Engine

Preview: Hyperdisk Balanced is now available in preview with H3 VMs. Hyperdisk Balanced is a good fit for a wide range of use cases such as LOB applications, web applications, and medium-tier databases that don't require the performance of Hyperdisk Extreme. For more information, see About Hyperdisk.

Config Connector

Config Connector version 1.111.0 is now available.

Added support for ContainerAttachedCluster (v1beta1) resource.

Added support for AlloyDBCluster (v1beta1) resource.

Added support for AlloyDBInstance (v1beta1) resource.

Added support for AlloyDBBackup (v1beta1) resource.

Added name validation for ValidatingWebhookConfigurationCustomization and MutatingWebhookConfigurationCustomization CRDs.

Added validation for duplicate webhooks in spec.webhooks list of the customizable ControllerResource and NamespacedControllerResource CRDs.

Added errors on invalid webhook names into status of ValidatingWebhookConfigurationCustomization and MutatingWebhookConfigurationCustomization custom resources.

Fixed an reconciliation issue in ComputeManagedSSLCert resource. Issue #107.

Fixed issue of the retrieved maxWorkers in DataflowFlexTemplateJob resource.

Graduated ValidatingWebhookConfigurationCustomization, MutatingWebhookConfigurationCustomization, ControllerResource and NamespacedControllerResource CRDs to v1beta1.

Fixed an issue in ComputeForwardingRule resource when used with PSC. Issue #763.

Resource AlloyDBCluster(v1beta1):

  • Added spec.networkConfig field.

Resource ComputeSubnetwork(v1beta1):

  • Added status.internalIpv6Prefix field.

Resource ComputeTargetHTTPSProxy(v1beta1):

  • Added spec.serverTlsPolicyRef field.

Resource ContainerCluster(v1beta1):

  • Added spec.nodeConfig.fastSocket field.

Resource ContainerNodePool(v1beta1):

  • Added spec.nodeConfig.fastSocket field.

Resource NetworkConnectivitySpoke(v1beta1):

  • Added spec.linkedVPCNetwork field.

Resource RunJob(v1beta1):

  • Added spec.template.template.vpcAccess.networkInterfaces field.

Resource RunService(v1beta1):

  • Added spec.template.vpcAccess.networkInterfaces field.

Resource SecretManagerSecretVersion(v1beta1):

  • Added spec.isSecretDataBase64 field.
Dataform

Batch workspace deletion is available.

Dataproc Google Cloud Deploy

Cloud Deploy now uses Skaffold 2.8 as the default Skaffold version for all target types.

Vertex AI Search and Conversation

Vertex AI Search: Create media recommendations in Vertex AI Search

You can now create apps for media recommendations in Vertex AI Search. Media recommendations include content such as videos, news, and music. For more information, see Vertex AI Search.

Important: If you are using Discovery for Media for media recommendations, you need to switch to the media recommendations capability of Vertex AI Search. All of the existing data and models that you created with Discovery for Media will automatically appear in the Vertex AI Search and Conversation console, with the models appearing as apps. For more information, see Migrate from Discovery for Media to media recommendations.

October 26, 2023

Apigee Integrated Portal

On October 26, 2023 we released an updated version of Apigee integrated portal.

Bug ID Description
5400261 Improve confirmation dialog text when user clicks the button to revoke an app key from the portal UI.

This dialog is displayed when you:
  1. Select Apps from the user account drop-down in the portal.
  2. Click an app.
  3. Click the Revoke button in the API Keys row.
Apigee UI

On October 26, 2023 we released an updated version of the Apigee UI.

Bug ID Description
287028804, 291942702 Fixed issue where customers with a mismatched with Google Cloud project and Apigee organization ID would be presented with the Apigee welcome screen instead of the management UI in the Apigee UI in Google Cloud console.

The above fix requires a change in permissions for users managing Apigee through the Google Cloud console with a custom role.

Custom roles must now include the apigee.projectorganizations.get role for users who manage Apigee organizations via the Apigee UI in Cloud console. Without this role, users see a provisioning prompt in the console rather than the standard UI actions.

See UI-based Apigee management permissions for instructions.

Batch

Documentation has been added to explain how to run dsub pipelines on Batch. For more information, see Orchestrate jobs by running dsub pipelines on Batch.

Cloud Healthcare API Cloud Spanner

Cloud Spanner now supports FULL JOIN with USING in PostgreSQL-dialect databases. For information about PostgreSQL queries in Spanner, see PostgreSQL queries.

Cloud Storage

Managed folders are now available in Preview. When using managed folders, you can organize your objects by group and set IAM policies that offer more granular access control over data segments within a bucket.

Container Optimized OS

cos-105-17412-226-18

Kernel Docker Containerd GPU Drivers
COS-5.15.133 v23.0.3 v1.7.7 v470.199.02(default),v535.104.12(latest)

Sync TCPX changes to commit e34a5bbcc20d.

Dataform

File search is available in workspaces.

Workflows

A connection reset error is tagged as a ConnectionError and not a ConnectionFailedError, and it is not retried for non-idempotent requests. For more information, see Workflow errors and Retry steps.

October 25, 2023

Access Transparency

Access Transparency supports Vertex AI Workbench instances in the GA stage.

Certificate Authority Service

Certificate Authority Service is now available in the following region:

  • europe-west10

For more information, see Certificate Authority Service locations.

Chronicle SOAR

Release Notes 6.2.37

Beta - 29th October, 2023

GA - 5th November, 2023

A new Explore containing case-related fields has been added to the Advanced Reports module in the platform. This Explore allows you to find fields and build visualizations for your report. We recommend using this new Explore in new widgets.

Error when trying to log in again to Chronicle SOAR (ID #46831483)

Email HTML template shows blank page in Settings (ID #46912863)

Users filter in the Search page not displaying all the users (ID #00249930)

Active Directory Groups field removed from Settings Permission groups as it is not supported

Cloud Workstations

Cloud Workstations is available in the northamerica-northeast1 region (Montréal, Québec, North America). For more information, see Locations.

Compute Engine

Preview: Project zonal metadata is custom project metadata that you can set exclusively for VMs in a specific zone in a project. Project zonal metadata helps you with fault isolation and provides greater reliability. By setting custom project zonal metadata, you gain more control over the project metadata for your VMs and limit the impact of any incorrect metadata updates to VMs within the specific zone.

Learn more about VM metadata and how to set custom project zonal metadata.

Dataproc Dataproc Metastore

Dataproc Metastore is now available in the me-central2 (Dammam) region. For more information, see Dataproc Metastore locations.

Dialogflow

On the week of October 30, 2023, auto speech adaptation (CX, ES) will be updated for non-English agents. No major behavior changes are expected.

If you notice speech recognition issues in Dialogflow CX, you can mitigate by enabling manual speech adaptation on flows and pages experiencing issues. You can tune the adaptation as follows:

  1. On the problematic flows and pages, disable auto speech adaptation by enabling manual speech adaptation without adding phrases.

  2. If your agent is unable to recognize certain words and phrases, add those phrases to the adaptation with no boost.

  3. If your agent is still unable to recognize certain words and phrases after step 2, duplicate those phrases so that you have one without boost and one with boost.

If you notice speech recognition issues in Dialogflow ES, you can mitigate by using the speechContexts field at runtime which overrides auto speech adaptation or by updating your agent design.

SAP on Google Cloud

Cloud Storage Backint agent for SAP HANA version 1.0.31

Version 1.0.31 of the Cloud Storage Backint agent for SAP HANA is available. This version fixes client libraries to enable Cloud Logging capabilities.

For more information about the agent, see Cloud Storage Backint agent for SAP HANA overview.

Text-to-Speech

Styles are now supported in Neural2 voices through SSML. The following styles are supported

  • <google:emotion name="apologetic">
  • <google:emotion name="calm">
  • <google:emotion name="empathetic">
  • <google:emotion name="firm">
  • <google:emotion name="lively">
for the following voices:
  • en-us-Neural2-F
  • en-us-Neural2-J

October 24, 2023

Apigee UI

On October 24, 2023 we released an updated version of the Apigee UI.

Bug ID Description
301458133 Fixed an issue in which saving a previously deployed proxy or shared flow revision resulted in the error "revision revision_name is immutable." You are now prompted to create a new revision in this case.
Apigee X

On October 24, 2023, we released an updated version of Apigee (1-11-0-apigee-7).

Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.

With this release, the HeaderName element is available as a child element of Authentication. This element appears in the ServiceCallout and ExternalCallout policies, and in the TargetEndpoint proxy configuration.

By default, when an Authentication configuration is present, Apigee generates and injects a bearer token into the Authorization header, in the message sent to the target system. The new HeaderName element allows the configuration to specify the name of a different header to hold that bearer token.

Bug ID Description
294293907 Fixed issue with Google authentication for gRPC-based target servers.
292454825 Fixed issue causing Null Pointer Exception when creating or updating an API product.
291784631 Implemented fix to permit the use of hyphens (-) in flow variables used to define target URLs in <HTTPTargetConnection>.
267229604 Fixed issue where updates to a TLS truststore reference were not reflected for in-use southbound target server connections.
277353680 Fixed issue causing target server HealthMonitors to continue beyond revision or deletion of the proxy.

Target health checks are now terminated as soon as the proxy is removed from the runtime (undeployed or deleted). Note: There may be a delay between removal of the proxy and termination of the target server health checks.

N/A Upgraded infrastructure and libraries.
Chronicle SOAR

Remote Agents 1.4.4

  • Added support for all SDK calls over remote agents
  • Improved managing integrations over the remote agent leading to a more overall stable product experience
  • Publisher Python version upgraded to Python 3.11

Remote Agents 1.4.4

  • Remote agent actions do not return script results in the same way local actions return them (ID #45682680)
  • Users unable to change the remote agent environment via agent CLI
Cloud Logging

Ops Agent version 2.43.0 introduces support for Compute Engine Arm VMs that are running SLES 15 and OpenSUSE Leap 15. For more information, see Support for Compute Engine Arm VMs.

Cloud Monitoring

Ops Agent version 2.43.0 introduces support for Compute Engine Arm VMs that are running SLES 15 and OpenSUSE Leap 15. For more information, see Support for Compute Engine Arm VMs.

Config Controller

Config Controller now uses the following versions of its included products:

Container Optimized OS

cos-105-17412-226-17

Kernel Docker Containerd GPU Drivers
COS-5.15.133 v23.0.3 v1.7.7 v470.199.02(default),v535.104.12(latest)

Sync TCPX changes to commit 3cac7b2856a0

Updated app-containers/containerd to 1.7.7.

Sync TCPX changes to commit da99a91cffb1

Update latest NVIDIA GPU drivers to 535.104.12.

cos-97-16919-404-4

Kernel Docker Containerd GPU Drivers
COS-5.10.197 v20.10.24 v1.6.21 v470.199.02(default),v535.104.05(latest)

Upgraded net-misc/curl to version 8.4.0. This resolves CVE-2023-38545.

Fix CVE-2023-42756 in COS kernel.

Runtime sysctl changes:

  • Added: net.ipv4.tcp_migrate_req: 0
  • Changed: fs.file-max: 813432 -> 813422
  • Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_recd: 0 -> 3
  • Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_sent: 0 -> 3

cos-93-16623-461-42

Kernel Docker Containerd GPU Drivers
COS-5.10.177 v20.10.24 v1.6.20 v450.248.02(default),v535.104.12(latest),v470.199.02(R470 for compatibility with K80 GPUs)

Update latest NVIDIA GPU drivers to 535.104.12.

Fixed CVE-2023-42752 in the Linux kernel.

cos-101-17162-336-9

Kernel Docker Containerd GPU Drivers
COS-5.15.133 v20.10.24 v1.6.21 v470.199.02(default),v535.104.12(latest)

Update latest NVIDIA GPU drivers to 535.104.12.

Google Cloud Architecture Center

Inter-service communication in a microservices setup: Updated the architecture, design guidance, and deployment steps based on the latest demo application.

Text-to-Speech

Studio voices now support 5,000 bytes of either text or SSML input per synthesis request.

Long Audio Synthesis now supports SSML inputs.

October 23, 2023

BigQuery

Custom data masking now supports an expanded list of functions, including SHA hash functions with salt. This feature is in preview.

Cloud Billing

Control access to single-project budgets

If you are a billing account-level user and are creating a budget for a single project, you can now prevent project users such as Project Owners and Project Editors from making changes to the budget. This prevents inadvertent changes to budgets that you might be tracking at the Cloud Billing account level.

Learn more about creating Google Cloud budgets.

Budgets for project users is now Generally Available

Project users such as Project Owners, Project Editors, and Project Viewers in Google Cloud can now create budgets and stay on top of their cloud costs, without needing additional permissions to access Cloud Billing accounts. Budgets for project users enables project users to take ownership of their costs, plan for the spend in the projects that they own, and proactively manage cost exceptions.

You can now assign custom roles to users who can create, modify and delete single-project budgets for the projects they have access to.

Project users can use the Google Cloud console or the Cloud Billing Budget API to manage budgets for projects.

Cloud Data Fusion

Cloud Data Fusion supports patch revisions. These revisions apply bug fixes between major releases. For more information, see Versioning in Cloud Data Fusion.

The Cloud Data Fusion version 6.7.3.1 patch revision is generally available (GA). It introduces retries in the platform transaction layer to handle a PSQLException error thrown from broken database connections (CDAP-19949 and CDAP-20722).

Cloud Healthcare API

A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.

Cloud Monitoring

You can configure your synthetic monitors to collect log data and trace data for your outbound HTTP requests when you use the generic template. This feature is in Public Preview. For more information, see Samples for synthetic monitors.

Cloud Spanner

Cloud Spanner PostgreSQL now supports the SELECT DISTINCT statement. For more information, see SELECT.

Dataflow

The Cloud Spanner to BigQuery template for batch pipelines is available in preview.

A weekly digest of client library updates from across the Cloud SDK.

Python

Changes for google-cloud-dataflow-client

0.8.5 (2023-10-09)

Documentation
Dataform

The 2.7.0 version of the open-source Dataform framework is available. This update introduces explicitly listed column names in incremental insert statements. For more information, see the 2.7.0: Updates for Dataform GCP incremental SQL release on GitHub.

Dataproc

Dataproc now collects the dataproc.googleapis.com/job/yarn/vcore_seconds and dataproc.googleapis.com/job/yarn/memory_seconds job-level resource attribution metrics to track YARN application vcore and memory usage during job execution. These metrics are collected by default and are not chargeable to customers.

Dataproc now collects a dataproc.googleapis.com/node/yarn/nodemanager/health health metric to track the health of individual YARN node managers running on VMs. This metric is written against the gce_instance monitored resource to help you find suspect nodes. It is collected by default and is not chargeable to customers.

Dialogflow Filestore

Filestore is now available in Berlin (europe-west10 region).

Google Cloud Deploy

You can now deploy Cloud Run jobs, in addition to Cloud Run services.

Google Kubernetes Engine

The Cloud Storage FUSE CSI driver now enforces injected sidecar containers to follow the Restricted Pod security standard. This change is available in v0.1.6 of the driver, and in GKE clusters with control planes running the following versions: 1.24.17-gke.2146000, 1.25.14-gke.1466000, 1.26.9-gke.1494000, 1.27.6-gke.1506000, and 1.28.2-gke.1157000 or later.

Memorystore for Redis Cluster

Added support for Committed use discounts for Memorystore for Redis Cluster.

October 20, 2023

Cloud Domains

On September 7, 2023 Squarespace acquired all domain registrations and related customer accounts from Google Domains. For more information about how this change affects Cloud Domains, see Cloud Domains feature deprecation, Google Domains FAQ, and Cloud Domains FAQ.

Dataform Datastream

Support for the PostgreSQL ARRAY data type is now added in Datastream.

Eventarc

Eventarc support for internal HTTP endpoints as event destinations is available in Preview. For more information, see the guide and the tutorial.

Google Cloud Armor

Cloud Armor for regional HTTP(S) load balancers is now Generally Available. For more information, see the Security policy overview.

Google Kubernetes Engine

New Autopilot clusters created with versions 1.24.17-gke.2146000, 1.25.14-gke.1466000, and 1.26.9-gke.1494000 or later are now provisioned with e2-small default nodes, which are removed immediately after cluster creation. With this change, DaemonSets are guaranteed to schedule on all candidate nodes if you follow best practices for DaemonSets on Autopilot.

You can now use the GKE API to apply Resource Manager tags to your GKE resources. GKE attaches these tags to the underlying Compute Engine VMs. You can use these tags to selectively enforce Cloud Firewall network firewall policies. This feature is available in Public Preview in GKE version 1.28 and later.

October 19, 2023

Anthos Config Management

Policy Controller has been updated to include a more recent build of OPA Gatekeeper (hash: 3e66ee2).

The constraint template library includes a new template: K8sAvoidUseOfSystemMastersGroup. For reference, see the Constraint template library.

The constraint template library includes a new template: K8sPSPWindowsHostProcess. For reference, see the Constraint template library.

Policy Controller bundles have been updated to the following versions: asm-policy-v0.0.1: 202309.0, cis-k8s-v1.5.1: 202309.0, cost-reliability-v2023: 202309.0, nist-sp-800-190: 202309.0, nist-sp-800-53-r5: 202309.0, nsa-cisa-k8s-v1.2: 202309.0, pci-dss-v3.2.1: 202309.0, policy-essentials-v2022: 202309.0, psp-v2022: 202309.0, pss-baseline-v2022: 202309.0, pss-restricted-v2022: 202309.0. For reference, see Policy Controller bundles overview.

Updated the Open Telemetry image from 0.54.0 to 0.86.0 to address security vulnerabilities. otelcontribcol:v0.86.0 contains breaking changes. For more information about these changes, see the full changelog for opentelemetry-collector-contrib.

Fixed a recurring transient error in the RootSync and RepoSync API. Transient errors are retried internally and surfaced to RootSync and RepoSync if failed eventually.

Anthos clusters on VMware

Anthos clusters on VMware 1.16.2-gke.28 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.16.2-gke.28 runs on Kubernetes 1.27.4-gke.1600.

The following issue is fixed in 1.16.2-gke.28:

  • Fixed the known issue where a non-HA Controlplane V2 cluster is stuck at node deletion until it timesout.

The following vulnerabilities are fixed in 1.16.2-gke.28:

Anthos clusters on VMware 1.14.9-gke.21 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.14.9-gke.21 runs on Kubernetes 1.25.13-gke.200.

The following issues are fixed in 1.14.9-gke.21:

  • Fixed the known issue where a non-HA Controlplane V2 cluster is stuck at node deletion until it timesout.

The following vulnerabilities are fixed in 1.14.9-gke.21:

Apigee Integration

The maximum memory available for script evaluation in the Data Transformer Script task is 300 MB. For the list of all the applicable limits, see Quotas and Limits.

Apigee X

On October 19, 2023, we released an updated version of Apigee

Looker Studio Integration

This release includes the public preview of Looker Studio Integration, which connects Apigee data to Google's Looker Studio. Looker Studio is a powerful and flexible tool that you can use to display Apigee data in fully customizable dashboards and reports.

Application Integration

The maximum memory available for script evaluation in the Data Transformer Script task is 300 MB. For the list of all the applicable limits, see Quotas and Limits.

Backup and DR

Security Command Center Premium adds real-time threat detection for Google Cloud Backup and DR Service.

Event Threat Detection, a Security Command Center Premium service, released new rules for Google Cloud Backup and DR Service. Security Command Center can now do the following:

  • Detect Backup and DR actions that result in data destruction.
  • Detect Backup and DR actions that inhibit inhibit system recovery.
These new rules are available now to all Security Command Center Premium customers. For more information, see Security Command Center Premium for Backup and DR Service.

Batch

Documentation has been added to explain how to colocate the VMs for a job by using a compact placement policy. For example, use compact placement policies to reduce the latency between VMs for jobs with tightly coupled tasks, such as tasks that communicate using MPI libraries.

For more information, see Reduce latency by using compact placement policies.

BigQuery

Stored procedures for Apache Spark are now available without enrollment. This feature is in preview.

Cloud Billing

View granular cost data from Dataflow usage in Cloud Billing exports to BigQuery

You can now view granular Dataflow cost data in the Google Cloud Billing detailed export. Use the resource.name or resource.global_name field in the export to view and filter your detailed Dataflow usage.

Review the schema of the Detailed cost data export.

View granular cost data from BigQuery usage in Cloud Billing exports to BigQuery

View granular cost data from BigQuery in Cloud Billing exports to BigQuery You can now view granular BigQuery cost data in the Google Cloud Billing detailed export. Use the resource.name or resource.global_name field in the export to view and filter your BigQuery Dataset and Jobs costs.

Review the schema of the Detailed cost data export.

Google Kubernetes Engine

Compute resources can now be reserved in advance for use with GKE. Create a future reservation to request assurance of important or difficult-to-obtain capacity in advance. There are no additional costs for creating future reservation requests. You only start to pay when Compute Engine provisions the reserved resources, and you're charged at the same cost as on-demand reservations.

(2023-R22) Version updates

GKE cluster versions have been updated. There are no version updates for 2023-R21.

New versions available for upgrades and new clusters

The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.

No channel

Stable channel

  • There are no new releases in the Stable release channel.

Regular channel

  • There are no new releases in the Regular release channel.

Rapid channel

(2023-R22) Version updates

There are no version updates for 2023-R21.

(2023-R22) Version updates

There are no version updates for 2023-R21.

Security Command Center

Backup and DR Service threat detectors available in Security Command Center Premium

Event Threat Detection, a built-in service of Security Command Center, released new rules for the Google Cloud Backup and DR service to Preview. Security Command Center can now detect the following:

  • Backup and DR actions that inhibit system recovery
  • Backup and DR actions that result in data destruction

For more information, see:

October 18, 2023

Batch

Documentation has been added to explain how to securely reference sensitive data in a job by using Secret Manager secrets for encryption. For example, use secrets to protect sensitive data when defining custom environment variables or protect login credentials when accessing private container images from Docker Registry.

For more information, see Protect sensitive data using Secret Manager with Batch.

BigQuery

The BigQuery migration assessment is now available for Apache Hive in preview. You can use this feature to assess the complexity of migrating data from your Apache Hive data warehouse to BigQuery.

Chronicle

The following supported default parsers have changed. Each is listed by product name and log_type value, if applicable.

  • Azure AD Directory Audit (AZURE_AD_AUDIT)
  • Check Point (CHECKPOINT_FIREWALL)
  • Chronicle SOAR Audit (CHRONICLE_SOAR_AUDIT)
  • Cisco Internetwork Operating System (CISCO_IOS)
  • Cisco Meraki (CISCO_MERAKI)
  • Cisco Web Services Manager (CISCO_WSM)
  • Cloud Audit Logs (N/A)
  • Cloudflare (CLOUDFLARE)
  • CrowdStrike Falcon (CS_EDR)
  • ESET Threat Intelligence (ESET_IOC)
  • GitHub (GITHUB)
  • Gitlab (GITLAB)
  • Infoblox DNS (INFOBLOX_DNS)
  • JumpCloud Directory Insights (JUMPCLOUD_DIRECTORY_INSIGHTS)
  • Kolide Endpoint Security (KOLIDE)
  • McAfee ePolicy Orchestrator (MCAFEE_EPO)
  • Microsoft Azure Activity (AZURE_ACTIVITY)
  • Microsoft Azure Resource (AZURE_RESOURCE_LOGS)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • Microsoft SQL Server (MICROSOFT_SQL)
  • Netskope Web Proxy (NETSKOPE_WEBPROXY)
  • OpenSSH (OPENSSH)
  • Palo Alto Cortex XDR Alerts (CORTEX_XDR)
  • Silverfort Authentication Platform (SILVERFORT)
  • Vectra Stream (VECTRA_STREAM)
  • VMware ESXi (VMWARE_ESX)
  • VMware NSX (VMWARE_NSX)
  • Windows Applocker (WINDOWS_APPLOCKER)
  • Windows Defender ATP (WINDOWS_DEFENDER_ATP)
  • Windows DNS (WINDOWS_DNS)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • Windows Hyper-V (WINDOWS_HYPERV)
  • Workspace ChromeOS Devices (WORKSPACE_CHROMEOS)
  • Zscaler (ZSCALER_WEBPROXY)
  • ZScaler DNS (ZSCALER_DNS)

The following log types, without a default parser, were added. Each is listed by product name and log_type value, if applicable.

  • ADVA Fiber Service Platform (ADVA_FSP)
  • Bluecat Address Manager (BLUECAT_AM)
  • Fortinet Switch (FORTINET_SWITCH)
  • GCP Google Kubernetes Engine Context (GCP_KUBERNETES_CONTEXT)
  • Kion (KION)
  • Kiteworks (KITEWORKS)
  • Nokia Router (NOKIA_ROUTER)
  • Ntopng (NTOPNG)
  • Opnsense (OPNSENSE)
  • Oracle HCM Human resources platform solution (ORACLE_HCM)
  • MS Powershell Transcript (POWERSHELL_TRANSCRIPT)
  • RAD ETX (RAD_ETX)
  • Spamhaus (SPAMHAUS)
  • UpGuard (UPGUARD)
  • Vsftpd (VSFTPD)

For a list of supported log types and details about default parser changes, see Supported log types and default parsers.

Cloud Data Fusion

The Cloud Data Fusion SAP SLT No RFC Replication plugin version 0.11.0 is available in the Hub in Cloud Data Fusion enterprise edition versions 6.8.0 and later. It differs from the existing SAP SLT Replication plugin in the following ways:

  • All data and metadata file formats are in JSON.
  • No SAP RFC inbound calls occur in the SAP SLT No RFC Replication plugin. Accessing schemas and data from the SAP system no longer requires an SAP connection. Metadata and data extraction are sourced from the Cloud Storage bucket.
Cloud Tasks

Support for Customer Managed Encryption Keys (CMEK) is now available for Cloud Tasks. To learn more, see the documentation on using CMEK with Cloud Tasks.

Firestore

For documents with many fields that don't require indexing, you can now add collection-level index exemptions on all fields in a collection group. To learn more, see Add a collection-level exemption. This feature is generally available (GA).

SAP on Google Cloud

New SAP NetWeaver certification: C3D series of general-purpose machine types

For use with SAP NetWeaver, SAP has certified the Compute Engine general-purpose machine types c3d-standard and c3d-highmem.

For more information, see Certified C3D machine types for SAP NetWeaver.

Security Command Center

Container Threat Detection, a built-in service of Security Command Center Premium, has launched a new detector, Unexpected Child Shell, in Preview.

The detector monitors all process executions and generates a finding if a process that does not normally invoke shells spawns a shell process.

For more information, see Container Threat Detection detectors.

October 17, 2023

Anthos Service Mesh

Managed Anthos Service Mesh 1.17 is rolling out in the rapid channel.

Additionally, the rollout of managed Anthos Service Mesh version 1.16 to the regular channel has completed.

See Select a managed Anthos Service Mesh release channel for more information.

Apigee hybrid

hybrid v1.10.3-hotfix.3

On October 17, 2023 we released an updated version of the Apigee hybrid software, v1.10.3-hotfix.3.

Bug ID Description
303292806 Set backup utility to only connect to Cassandra server pods in the apigee namespace.
300542690 Added dedicated service accounts for Apigee Connect, Redis, and UDCA to prevent Kubernetes from automatically injecting credentials for a specified ServiceAccount or the default ServiceAccount.
Cloud Load Balancing

Service Extensions callouts are available for Google Cloud Application Load Balancers, excluding Classic.

By using this feature, you can direct your load balancers to make gRPC calls to user-managed or partner-hosted applications from within the Cloud Load Balancing data processing path. These applications can then apply various policies or functions, such as header or payload manipulation, security screening, or custom logging on the traffic before returning the traffic to the load balancer for further processing.

For details, see the following topics in the Service Extensions documentation:

Service Extensions is in Preview.

Cloud Monitoring

You can now view error groups on your custom dashboards. This feature is GA. For information when using the Cloud Console, see Display logs and errors on a custom dashboard. For information about using the API, see Dashboard with an ErrorReportingPanel widget.

Cloud SQL for MySQL

Cloud SQL supports InnoDB page compression for MySQL 5.7 and MySQL 8.0 and later.

Cloud SQL for SQL Server

You can now import transaction log backups. This can help you reduce downtime when migrating to Cloud SQL using backups.

Cloud Spanner

Query Optimizer version 6 is generally available, and is the default optimizer version.

Compute Engine

Generally available: c3d-standard, c3d-highmem, c3d-highcpu, and c3d-standard-lssd machine types for general-purpose C3D VMs are generally available.

Contact Center AI Platform

Release 3.2

All release notes published on this date are part of the 3.2 release.

Voice Virtual Agent assignment, transfers to parent queue: You can now assign voice Virtual Agent transfers to top-level queues. In the IVR, the end-user will hear all of the sub and leaf queue options below the top-level queue as long as they are active. See the Virtual Agents documentation for details.

New permissions added to call recordings and chat transcripts: A new role permission External Storage is now available. This role offers you the ability to define whether users should have access to call recordings and/or chat transcripts when they are stored in external storage and without a CRM. When inactive, users won't be able to access these files from either the Completed Calls or Chats monitoring pages or associated downloadable reports. Shared links to these files fall under the same permissions. See the Agent & team configuration page for more information.

New language support: Polish, Czech, Australian English, Hungarian is now supported for all channels. You can set up these new languages on the Settings > Languages & Messages page. See the language support page for a complete list of supported languages.

Kustomer API rate limit improvements: The API rate limits for customers integrating with Kustomer have been improved. see the Kustomer documentation for more information.

Call management: Agent status breakthrough: New feature Agent Status Breakthrough is now available. This feature allows you to to route incoming calls to agents, even when they are in a status that traditionally did not support receiving calls. This setting can be enabled at Operations Management > Agent Status. To designate a status as a breakthrough status, use the Edit function in the Agent Status List. The breakthrough status feature can be configured at the queue level as well as for specific DAPs. See the documentation for details.

Custom Notification Tones: You can now upload custom audio files for incoming call and chat notifications, as well as new chat messages. See the documentation for details.

Call recording: Third party recording without agent: You can now record calls if an agent leaves after adding a third party. This can be configured at Settings > Calls > Call Details > Call Recording. See the documentation for details.

Virtual Agent pass data parameters updates: CCAI Platform has enhanced the ability to pass session-based contextual data to Virtual Agents (VA). You can now leverage valuable real-time information during call routing and Dialogflow sessions. The following dynamic parameters are now available: DNIS / TFN (the number the user dialed), Latest Agent ID, Latest Agent Email, Queue Language, Latest Sentiment Score, and Overall Sentiment Score. Additionally, you can now configure static or dynamic CCAI Platform metadata parameters at the mobile queue level. See the data parameters page for details.

When an outbound campaign call fails during auto-dial due to telephony issues, the agent will now move into Available status rather than Wrap-up.

Fixed an issue where disabled Agent Statuses were still visible to custom roles.

Fixed an issue where agents were not moving into wrap up status after completing transfer to a queue with a Virtual Agent assigned to it.

Fixed an issue where agents were seeing calls on the Calls > Connected page that were disconnected. Calls in which no participant is detected as active will now be automatically cleared and finished.

Dataform

ssh_authentication_config and service_account fields are available in the google_dataform_repository Dataform Terraform resource.

Error Reporting

You can now view error groups on your custom dashboards. This feature is GA. For information when using the Cloud Console, see Display logs and errors on a custom dashboard. For information about using the API, see Dashboard with an ErrorReportingPanel widget.

Firestore Service Extensions

Service Extensions callouts are available for Google Cloud Application Load Balancers, excluding Classic.

With the introduction of this feature, users instruct load balancers to forward traffic from within the Cloud Load Balancing data processing path through gRPC to user-managed or partner-hosted applications. These applications can apply various policies or functions, such as header or payload manipulation, security screening, or custom logging on the traffic before returning the traffic to the load balancer for further processing.

For details, see Cloud Load Balancing extensions overview.

Service Health

Personalized Service Health supports AlloyDB for PostgreSQL and Resource Manager API.

Vertex AI

New Vertex AI Vector Search Console

Vector Search has launched a console experience in Google Cloud for creating and deploying indexes, now available in Preview. From the console, you can create indexes, and create public or VPC endpoints for your indexes, and deploy. For more information, see Manage indexes.

Vertex AI Vector Search Improvements

Vector Search has improved the initial index creation process for smaller indexes (<100MB), reducing time to build from about 1 hour to about 5 mins. To get started, see Vector Search quickstart to create an index.

October 16, 2023

App Engine flexible environment Python

Python 3.12 is now available in preview.

App Engine standard environment Python

Python 3.12 is now available in preview.

BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigquery

2.33.2 (2023-10-11)

Bug Fixes
Dependencies
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.29.0 (#2911) (052f5c2)
  • Update dependency com.google.apis:google-api-services-bigquery to v2-rev20230925-2.0.0 (#2921) (f0fb64f)
  • Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.33.0 (#2912) (e053494)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.17.0 (#2931) (25a94f1)
  • Update github/codeql-action action to v2.22.0 (#2926) (33ce4ae)
  • Update github/codeql-action action to v2.22.1 (#2934) (7ae7b99)
  • Update ossf/scorecard-action action to v2.3.0 (#2927) (93bfd8e)

You can now use DLP functions to support encryption and decryption between BigQuery and DLP, using AES-SIV. This feature is in preview.

Chronicle

The following changes are available in the Unified Data Model.

  • New enum fields were added: SecurityResult.IoCStatsType and SecurityResult.VerdictType.
  • A new field was added to EntityMetadata: feed.
  • A new field was added to Network: ip_subnet_range.
  • New fields were added to SecurityResult: last_updated_time and verdict_info.
  • A new field was added to Label: rbac_enabled.
  • A new field was added to SecurityResult.Association: region_code.
  • New fields were added to User: last_login_time, last_password_change_time, password_expiration_time, account_expiration_time, account_lockout_time, and last_bad_password_attempt_time.
  • A new value was added to the Network.ApplicationProtocol enum: GRPC.
  • The following new values were added to the Resource.ResourceType enum:

    • POD
    • CONTAINER
    • FUNCTION
    • RUNTIME
    • IP_ADDRESS
    • DISK
    • VOLUME
    • IMAGE
    • SNAPSHOT
    • REPOSITORY
    • CREDENTIAL
    • LOAD_BALANCER
    • GATEWAY
    • SUBNET

For a list of all fields in the Unified Data Model, and their descriptions, see the Unified Data Model field list.

Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigtable

2.28.0 (2023-10-12)

Features
  • Add support for Cloud Bigtable Request Priorities in App Profiles (#1954) (8822571)
  • Add test profile to push metrics to test environment (#1921) (2104315)
Dependencies
Cloud Composer

Airflow 2.6.3 is available in Cloud Composer images.

Airflow 2.6.3 consolidates the logic for handling tasks that are stuck in the queued state:

  • The [kubernetes]worker_pods_pending_timeout, [celery]stalled_task_timeout, and [celery]task_adoption_timeout Airflow configuration options are deprecated and merged into the [scheduler]task_queued_timeout option.
  • In Cloud Composer, the default value of the [scheduler]task_queued_timeout option is set to 40 minutes.
  • If your environment uses a custom value for any of the deprecated Airflow configuration options, please clear the overrides before upgrading. If the values are not cleared, the longest timeout of all deprecated options is selected upon upgrading.
  • If required, you can override the value of the [scheduler]task_queued_timeout option in your environment.
  • For more information about other changes between Airflow versions 2.5.3 and 2.6.3, see Airflow release notes.

Cloud Composer 2.4.6 images are available:

  • composer-2.4.6-airflow-2.6.3
  • composer-2.4.6-airflow-2.5.3 (default)
  • composer-2.4.6-airflow-2.4.3
Cloud Functions

Cloud Functions now supports the Python 3.12 runtime at the Preview release level.

Cloud Logging

You can now create log buckets in the us-west8 region. For a complete list of supported regions, see Supported regions.

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-logging

3.15.11 (2023-10-10)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.17.0 (#1444) (748e8a2)
Cloud Storage

Changes to the Autoclass feature that were announced on July 17, 2023 begin taking effect today.

Container Optimized OS

cos-105-17412-226-10

Kernel Docker Containerd GPU Drivers
COS-5.15.133 v23.0.3 v1.7.6 v470.199.02(default),v535.104.05(latest)

Updated app-containers/containerd to v1.7.6.

Synced TCPX changes to commit 90ce0a6aa201.

Updated cos-gpu-installer to v2.1.9.

Upgraded net-misc/curl to v8.4.0. This resolves CVE-2023-38545.

Fixed CVE-2023-38039 in net-misc/curl.

Fixed CVE-2023-4244 in the Linux kernel.

Fixed CVE-2023-5197 in the Linux kernel.

Fixed CVE-2023-42756 in COS kernel.

Fixed CVE-2023-42753 in the Linux kernel.

cos-101-17162-336-7

Kernel Docker Containerd GPU Drivers
COS-5.15.133 v20.10.24 v1.6.21 v470.199.02(default),v535.104.05(latest)

Fixed CVE-2022-48560 in dev-lang/python package.

Upgraded net-misc/curl to v8.4.0. This resolves CVE-2023-38545.

Fixed CVE-2023-38039 in net-misc/curl.

Fixed CVE-2023-5197 in the Linux kernel.

Fixed CVE-2023-42756 in COS kernel.

Fixed CVE-2023-42753 in the Linux Kernel.

Runtime sysctl changes:

  • Changed: fs.file-max: 813043 -> 813032
  • Changed: kernel.threads-max: 63551 -> 63552
  • Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_recd: 0 -> 3
  • Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_sent: 0 -> 3
  • Changed: user.max_cgroup_namespaces: 31775 -> 31776
  • Changed: user.max_ipc_namespaces: 31775 -> 31776
  • Changed: user.max_mnt_namespaces: 31775 -> 31776
  • Changed: user.max_net_namespaces: 31775 -> 31776
  • Changed: user.max_pid_namespaces: 31775 -> 31776
  • Changed: user.max_time_namespaces: 31775 -> 31776
  • Changed: user.max_user_namespaces: 31775 -> 31776
  • Changed: user.max_uts_namespaces: 31775 -> 31776

cos-97-16919-353-53

Kernel Docker Containerd GPU Drivers
COS-5.10.186 v20.10.24 v1.6.21 v470.199.02(default),v535.104.05(latest)

Updated cos-gpu-installer to v2.1.9.

Fixed CVE-2023-38039 in net-misc/curl.

Fixed CVE-2023-42753 in the Linux Kernel.

cos-93-16623-461-40

Kernel Docker Containerd GPU Drivers
COS-5.10.177 v20.10.24 v1.6.20 v450.248.02(default),v535.104.05(latest),v470.199.02(R470 for compatibility with K80 GPUs)

Upgraded net-misc/curl to v8.4.0. This resolves CVE-2023-38545.

Dataflow

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for dataflow/apiv1beta3

0.9.2 (2023-10-12)

Bug Fixes
  • dataflow: Update golang.org/x/net to v0.17.0 (174da47)
Dataproc Metastore

Dataproc Metastore now supports multi-regional configurations.

Filestore Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-datastore

2.17.3 (2023-10-10)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.17.0 (#1206) (2ad068b)
Google Cloud Architecture Center

Architecting disaster recovery for cloud infrastructure outages: Added DR guidance for Access Transparency.

Google Kubernetes Engine

Filestore Enterprise now supports backups on GKE, allowing you to make reliable copies of your data to be stored for later use. To trigger backups on Filestore Enterprise, use Kubernetes volume snapshots. Backups are currently not supported for Filestore Enterprise instances with multishares enabled.

Pub/Sub

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-pubsub

1.125.6 (2023-10-10)

Dependencies
  • Update dependency com.google.cloud:google-cloud-bigquery to v2.33.1 (#1756) (239f474)
  • Update dependency com.google.cloud:google-cloud-core to v2.25.0 (#1764) (72404ea)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.17.0 (#1765) (a447292)
  • Update dependency com.google.protobuf:protobuf-java-util to v3.24.4 (#1760) (10a64c6)

Public preview: Pub/Sub BigQuery subscriptions now support BigQuery change data capture.

Secret Manager

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for secretmanager/apiv1

1.11.2 (2023-10-12)

Bug Fixes
  • secretmanager: Update golang.org/x/net to v0.17.0 (174da47)
Text-to-Speech

The Long Audio Synthesis API now supports the following languages: English, Spanish, French, German, Japanese, Hindi, Italian, Korean, Portuguese, Thai, Vietnamese, Danish, Filipino.

There is no longer billing differentiation for Cloud Text-to-Speech Offline Custom Voice API calls. See the <ReportedUsage> documentation for more details.

October 13, 2023

Apigee X

On October 13, 2023, we released an updated version of Apigee (1-11-0-apigee-6).

Bug ID Description
304681330 Security fix for apigee-ingress.
This addresses the following vulnerability:
CVE-2023-44487
305127632 Security bulletin published.
GCP-2023-032

Description

A Denial-of-Service (DoS) vulnerability was recently discovered in multiple implementations of the HTTP/2 protocol (CVE-2023-44487), including the Apigee Ingress (Anthos Service Mesh) server used by Apigee X. The vulnerability could lead to a DoS of Apigee API management functionality.

Affected Products

Deployments of Apigee X that are accessible through a Google Cloud Network Load Balancer (Layer 4), or a custom layer 4 load balancer, are affected. A hotfix is being applied to all Apigee X instances. Your Apigee X instances will be automatically updated within the next few days.

Unaffected products

Apigee X instances which are accessed only via Google Cloud Application Load Balancers (Layer 7) are not affected. This includes deployments that have HTTP/2 enabled for gRPC proxies.

What Should I Do?

All Apigee X instances will be automatically updated within the next few days. Customers do not need to take any actions.

What Vulnerabilities Are Addressed By These Patches?

The vulnerability, CVE-2023-44487, allows an attacker to execute a denial-of-service attack on Apigee ingresses.

Apigee hybrid

hybrid v1.10.3-hotfix.2

On October 13, 2023 we released an updated version of the Apigee hybrid software, v1.10.3-hotfix.2.

Bug ID Description
304681330 Security fix for apigee-ingress.
This addresses the following vulnerability:
CVE-2023-44487
305127632 Security bulletin published.
GCP-2023-032

hybrid v1.9.4-hotfix.1

On October 13, 2023 we released an updated version of the Apigee hybrid software, v1.9.4-hotfix.1.

Bug ID Description
304681330 Security fix for apigee-ingress.
This addresses the following vulnerability:
CVE-2023-44487
305127632 Security bulletin published.
GCP-2023-032

Description

A Denial-of-Service (DoS) vulnerability was recently discovered in multiple implementations of the HTTP/2 protocol (CVE-2023-44487), including the Apigee Ingress (Anthos Service Mesh) server used by Apigee hybrid. The vulnerability could lead to a DoS of Apigee API management functionality.

Affected Products

Apigee hybrid instances that allow HTTP/2 requests to reach the Apigee Ingress are affected. Customers should verify if the load balancers fronting their Apigee hybrid ingresses allow for HTTP/2 requests to reach the Apigee Ingress service.

What Should I Do?

Apigee hybrid customers will need to upgrade to one of the following patch versions:

What Vulnerabilities Are Addressed By These Patches?

The vulnerability, CVE-2023-44487, allows an attacker to execute a denial-of-service attack on Apigee ingresses.

Compute Engine

Generally available: C3 VMs support Compute Engine flexible committed use discounts (CUDs).

Compute Engine flexible CUDs allow you to commit to a minimum hourly spend amount and use vCPUs and/or memory in any of the projects within your Cloud Billing account, across any region, and belonging to any eligible machine types. Learn more about Compute Engine Flexible CUDs and how to purchase flexible commitments.

If you want to modify a future reservation request using the Compute Engine API, the paths query parameter is deprecated. Instead, use the updateMask query parameter.

For more information, see Modify future reservation requests.

Dataform

Formatting of Dataform core and JavaScript code is available.

Dataproc Google Kubernetes Engine

(2023-R20) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters

The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.

No channel

Stable channel

  • There are no new releases in the Stable release channel.

Regular channel

  • There are no new releases in the Regular release channel.

Rapid channel

Containers running in nodes in GKE version 1.28.1-gke.201 or later don't need to have privileged mode enabled to access TPUs. When upgrading a cluster to 1.28.1-gke.201 or later, we recommend removing privileged: true from the securityContext of any TPU workload. To learn more, see Deploy TPU workloads.

Starting in GKE 1.28.1-gke.1066000, two new TPU usage metrics are available: TensorCore utilization and Memory Bandwidth utilization.

(2023-R20) Version updates

(2023-R20) Version updates

Vertex AI Search and Conversation

Vertex AI Search: Customer-managed encryption key integration for the EU

Customer-managed encryption keys (CMEK) is available in the EU as an allowlisted preview feature.

If you store your data in an EU multi-region data store, you can provide your own encryption key to protect your data at rest.

For information, see Customer-managed encryption keys.

October 12, 2023

Access Approval

Access Approval supports Access Context Manager in the GA stage.

Access Transparency

Access Transparency supports Access Context Manager in the GA stage.

Anthos clusters on VMware

Anthos clusters on VMware 1.15.5-gke.41 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.15.5-gke.41 runs on Kubernetes 1.26.7-gke.2500.

The following issues are fixed in 1.15.5-gke.41:

  • Fixed the issue that server-side preflight checks fail to validate container registry access on clusters with a private network and no private registry.
  • Fixed the known issue where a non-HA Controlplane V2 cluster is stuck at node deletion until it timesout.
  • Fixed the known issue where upgrading or updating an admin cluster with a CA version greater than 1 fails.
  • Fixed the issue where the Controlplane V1 stackdriver operator has --is-kubeception-less=true specified by mistake.
  • Fixed the known issue that causes the secrets encryption key to be regenerated when upgrading the admin cluster from 1.14 to 1.15, resulting in the upgrade being blocked.

The following vulnerabilities are fixed in 1.15.5-gke.41:

BigQuery

The following geography functions are now generally available (GA):

  • ST_LINESUBSTRING: Gets a segment of a single linestring at a specific starting and ending fraction.
  • ST_HAUSDORFFDISTANCE: Gets the discrete Hausdorff distance between two geometries.
Cloud Asset Inventory

New searchable fields are now available.

The following searchable fields are now publicly available through the resource search API (SearchAllResources).

  • effectiveTagKeys
  • effectiveTagValues
  • effectiveTagValueIds

The following search result fields are now publicly available through the resource search API (SearchAllResources).

  • tags
  • effectiveTags
Cloud Logging

You can now configure the format of the timestamp in your query results in the Logs Explorer. For more information, see Logs Explorer overview: Configure the Time column.

Cloud Storage

The Node.js and Python client libraries now have parallelized upload and download options, improving their performance.

Compute Engine

Preview: The following metrics are now available to help you monitor your Persistent Disk and Hyperdisk volume performance:

  • Average I/O latency (compute.googleapis.com/instance/disk/average_io_latency)

  • Average I/O queue depth (compute.googleapis.com/instance/disk/average_io_queue_depth)

To learn more about these metrics and how to view them, see Review disk metrics.

Dataproc

New Dataproc on Compute Engine subminor image versions:

  • 2.0.80-debian10, 2.0.80-rocky8, 2.0.80-ubuntu18
  • 2.1.28-debian11, 2.1.28-rocky8, 2.1.28-ubuntu20, 2.1.28-ubuntu20-arm
Dialogflow

Dialogflow CX generative feedback now supports more languages.

Dialogflow CX launched generative playbooks with restricted access.

Dialogflow CX spelling correction now supports all regions, but is limited to five languages.

SAP on Google Cloud

Cloud Storage Backint agent for SAP HANA version 1.0.30

Version 1.0.30 of the Cloud Storage Backint agent for SAP HANA is available. This version reverts the google-cloud-storage client library to an earlier version so that API call retries work correctly.

For more information about the agent, see Cloud Storage Backint agent for SAP HANA overview.

Storage Transfer Service

You can now transfer data from Amazon S3 via your CloudFront domain. Learn more.

October 11, 2023

AlloyDB for PostgreSQL

AlloyDB Omni is now generally available (GA).

In AlloyDB Omni version 15.2.1 and earlier, after a failover, when you promote a standby instance, incremental backups from the newly promoted instance might conflict with the existing backup files, and the backups might fail.

As a workaround, move the conflicting files into a separate directory.

The AlloyDB Omni Kubernetes Operator is now available in Preview. This extension to the Kubernetes API lets you deploy and manage AlloyDB Omni on a Kubernetes cluster.

Cloud Build

Users can now set an IP range size and starting IP address for private connections in Bitbucket Data Center using the peeredNetworkIpRange. This feature is generally available. To learn more, see Build repositories in Bitbucket Data Center in a private network.

Cloud Functions

Cloud Functions (2nd gen) now supports Shared VPC ingress at the General Availability release level. Shared VPC traffic is now considered "internal" for functions that are connected to the Shared VPC network.

Cloud Run

Shared VPC ingress is now at general availability (GA). Shared VPC traffic is now considered "internal" for Cloud Run services that are connected to the Shared VPC network.

Cloud Spanner

Cloud Spanner has made improvements that provide higher throughput for instances located in select Spanner regional and multi-region instance configurations. These improvements are available without additional cost or any configuration changes. For more information, see Performance improvements.

Colab Enterprise

Colab Enterprise is now generally available (GA). Colab Enterprise combines the popular collaborative features of Colaboratory with the security and compliance capabilities of Google Cloud. Colab Enterprise includes:

  • Sharing and collaborating functionality, with IAM access control.
  • Google-managed compute and runtime provisioning, with configurable runtime templates.
  • Integrations with Vertex AI and BigQuery.
  • Inline code completion with Duet AI (Preview) assistance.
  • End-user credential authentication for running your notebook code.
  • Idle shutdown for runtimes (Experimental).

To get started, see Introduction to Colab Enterprise or create a notebook and start coding.

Compute Engine

Generally available: You can configure stateful IP addresses in a managed instance group. Stateful IP addresses are preserved when VM instances in the group are repaired, updated, and re-created. For more information, see Configuring stateful IP addresses in MIGs.

Container Optimized OS

cos-dev-113-17965-0-0

Kernel Docker Containerd GPU Drivers
COS-6.1.55 v24.0.5 v1.7.6 v535.104.05(default, latest),v470.199.02(R470 for compatibility with K80 GPUs)

Upgraded app-containers/containerd to v1.7.6.

Upgraded cos-gpu-installer to v2.1.9.

Upgraded dev-util/gn to v2121.

Upgraded chromeos-base/google-breakpad to v2023.06.01.191934-r222.

Upgraded chromeos-base/debugd-client to v0.0.1-r2559.

Upgraded chromeos-base/shill-client to v0.0.1-r4030.

Upgraded chromeos-base/chromeos-common-script to v0.0.1-r561.

Upgraded chromeos-base/session_manager-client to v0.0.1-r2649.

Fixed CVE-2023-4911 in sys-libs/glibc.

Fixed CVE-2023-38039 in net-misc/curl.

Fixed CVE-2023-42756 in COS kernel.

Fixed CVE-2023-5345 in COS kernel.

Fixed CVE-2023-5197 in the Linux kernel.

cos-93-16623-461-39

Kernel Docker Containerd GPU Drivers
COS-5.10.177 v20.10.24 v1.6.20 v450.248.02(default),v535.104.05(latest),v470.199.02(R470 for compatibility with K80 GPUs)

Upgraded cos-gpu-installer to v2.1.9.

Fixed CVE-2023-38039 in net-misc/curl.

Fixed CVE-2023-42753 in the Linux Kernel.

cos-97-16919-353-53

Kernel Docker Containerd GPU Drivers
COS-5.10.186 v20.10.24 v1.6.21 v470.199.02(default),v535.104.05(latest)

Upgraded cos-gpu-installer to v2.1.9.

Fixed CVE-2023-38039 in net-misc/curl.

Fixed CVE-2023-42753 in the Linux Kernel.

cos-105-17412-156-69

Kernel Docker Containerd GPU Drivers
COS-5.15.120 v23.0.3 v1.7.2 v470.199.02(default),v535.104.05(latest)

Upgraded cos-gpu-installer to v2.1.9.

Fixed CVE-2023-38039 in net-misc/curl.

Fixed CVE-2023-42753 in the Linux kernel.

cos-109-17800-0-51

Kernel Docker Containerd GPU Drivers
COS-6.1.42 v24.0.5 v1.7.2 v535.104.05(default, latest),v470.199.02(R470 for compatibility with K80 GPUs)

Fixed CVE-2023-38039 in net-misc/curl.

Fixed CVE-2023-5197 in the Linux kernel.

Looker

API 3.0 and API 3.1 have been removed in Looker 23.18.

Clustrix database support has been removed. Any existing connections to a Clustrix database will fail to run in Looker 23.18.

Performance improvements have been made to query preparation time by front-loading LookML model compilation during production deployments.

To prevent confusion with SSO authentication, the SSO embed feature has been renamed Signed embed.

For LookML projects that use the New LookML Runtime, an error has been added: "Datagroup names may only include letters, numbers and underscores." Starting in Looker 23.18, datagroups will generate an error if they contain hyphens or any characters besides letters, numbers, and underscores.

The Get embed URL option from a dashboard, a Look, or an Explore can now generate a signed embed URL.

Embedded Looks now support themes, so the Get embed URL dialog now shows a theme selector for Looks.

The manage_project_connections_restricted permission lets users edit a subset of settings for new and existing connections.

The New Schedules Page Labs feature updates the interface of the Admin settings - Schedules page.

An issue with drilling for transposed tables has been fixed. Drilling for transposed tables now performs as expected.

The Box Shadow theme now performs as expected for static and tile LookML dashboards.

Fixed date field values were not being displayed correctly when referenced by Liquid in the label or html LookML parameter. This feature now performs as expected.

Unreferenced custom fields from drill URL have been removed.

Looker 23.18 includes the following changes, features, and fixes.

Expected Looker (original) deployment start: Monday, October 16, 2023

Expected Looker (original) final deployment and download available: Thursday, October 26, 2023

Expected Looker (Google Cloud core) deployment start: Monday, October 23, 2023

Expected Looker (Google Cloud core) final deployment: Friday, November 3, 2023

Public preview is now available for the Open SQL Interface. The Open SQL Interface allows access to Looker models and Explores for applications (such as Tableau) that use JDBC to connect to data sources. For Looker (original) instances, enable the SQL Interface Experimental Labs feature on the Looker instance. (Only Looker-hosted instances support this Labs feature.) For Looker (Google Cloud core) instances, fill out the Looker SQL Interface Pre-GA Agreement interest form. The Google team will enable your instance for the SQL Interface feature.

IAM permissions have been clarified and made more visible in the Looker (Google Cloud core) documentation.

The in-app support in the Help menu has been updated to integrate with the Google Cloud console. You will see in-app support only if you have purchased at least a Standard Support service with Google Cloud Customer care.

Migrate to Virtual Machines

Preview: Migrate to Virtual Machines now supports migrating VMs to the C3, H3, and M3 machine types. These machine types support non-volatile memory express (NVMe) and Google Virtual NIC (gVNIC). Before you migrate your VMs to any of these machine types, ensure that source VMs support NVMe and gVNIC. For more information on different machine types that support NVMe and gVNIC, go to the Machine series comparison section, click Choose VM properties to compare, and select Disk interface type and Network interfaces.

October 10, 2023

Anthos Service Mesh

1.18.4-asm.0 is now available for in-cluster Anthos Service Mesh.

This patch release contains the fix for the security vulnerability listed in GCP-2023-031 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.

1.17.7-asm.0 is now available for in-cluster Anthos Service Mesh.

This patch release contains the fix for the security vulnerability listed in GCP-2023-031 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.

1.16.7-asm.10 is now available for in-cluster Anthos Service Mesh.

This patch release contains the fix for the security vulnerability listed in GCP-2023-031 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.

Apigee Integration

The following new data transformer functions are available:

  • Manifest XML - Converts the specified input JSON object into an XML string.

  • Parse XML - Parses the specified input XML string into a JSON object.

IAM Conditions for fine-grained access

IAM Conditions lets you define and enforce conditional, attribute-based access control for Google Cloud resources, including Application Integration resources. For more information, see Add IAM conditions.

You can now view the detailed summary of an integration from the Integration designer. For more information, see View integration details.

Application Integration

The following new data transformer functions are available:

  • Manifest XML - Converts the specified input JSON object into an XML string.

  • Parse XML - Parses the specified input XML string into a JSON object.

IAM Conditions for fine-grained access

IAM Conditions lets you define and enforce conditional, attribute-based access control for Google Cloud resources, including Application Integration resources. For more information, see Add IAM conditions.

You can now view the detailed summary of an integration from the Integration designer. For more information, see View integration details.

Support for user-defined service account

You can now configure a service account of your choice for an integration. The option to select a service account is displayed to you during the integration creation step.

Chronicle

While creating a custom parser, you can use the preview option to view the UDM output. In the preview, you can use the statedump filter plugin to validate the internal state of a parser. For more information, see Validate data using statedump plugin.

Cloud Asset Inventory

The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning).

  • MachineImage for Compute Engine
    • compute.googleapis.com/MachineImage
Cloud Healthcare API

A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.

Cloud Interconnect Container Registry

Starting October 10, 2023, mirror.gcr.io is transitioning to being hosted on Artifact Registry. This change is taking place on a region by region basis, and doesn't require you to change your usage of mirror.gcr.io unless you are using it within a VPC service perimeter.

For information on how to use mirror.gcr.io in a VPC service perimeter after the transition to being hosted on Artifact Registry, see Using Artifact Registry with VPC Service Controls.

Deep Learning Containers

M112 release

  • Miscellaneous bug fixes and improvements.
Deep Learning VM Images

M112 release

  • CUDA 12.1 VM images are available with the following image names:
    • common-cu121-debian-11-py310
    • common-cu121-ubuntu-2004-py310
  • Miscellaneous bug fixes and improvements.
Document AI Warehouse

Deletion operation can't be successful when raw document is missing

Google Kubernetes Engine

A Denial-of-Service (DoS) vulnerability was recently discovered in multiple implementations of the HTTP/2 protocol (CVE-2023-44487), including the golang HTTP server used by Kubernetes. The vulnerability could lead to a DoS of the Google Kubernetes Engine (GKE) control plane. GKE clusters with authorized networks configured are protected by limiting network access, but all other clusters are affected. For more information, see the GCP-2023-030 security bulletin.

Migrate to Virtual Machines

Generally Available: Migrate to Virtual Machines from an Azure source lets you migrate VM instances running on Azure to Google Cloud Compute Engine.

Vertex AI Workbench

M112 release

The M112 release of Vertex AI Workbench user-managed notebooks includes the following:

  • Miscellaneous bug fixes and improvements.

October 09, 2023

Batch

Job limits have increased to 100,000 tasks per task group and 5,000 parallel tasks per job. Learn more about Quotas and limits.

BeyondCorp Enterprise

The BeyondCorp Enterprise Policy Remediator is in Preview. You can use the Policy Remediator to provide users with actionable steps that they can take to remediate access denied issues.

For more information, see Remediate denied access with the Policy Remediator.

BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for bigquery/storage/apiv1beta1

1.56.0 (2023-10-05)

Features
  • bigquery/analyticshub: Add Subscription resource and RPCs (#8612) (9992249)
  • bigquery: Add external dataset reference (#8545) (1001acf)
  • bigquery: Add media options to LoadConfig (#8640) (62baf56)
Bug Fixes
  • bigquery/storage/managedwriter: Automatic retry for multiplex test (#8601) (6ef1945)
  • bigquery: Dependency detection on proto conversion (#8566) (763ab5d)
Documentation
  • bigquery/datatransfer: Update transferConfig.name description to indicate that it supports both formats (0449518)

Python

Changes for google-cloud-bigquery

3.12.0 (2023-10-02)

Features
  • Add Dataset.storage_billing_model setter, use client.update_dataset(ds, fields=["storage_billing_model"]) to update (#1643) (5deba50)
  • Search statistics (#1616) (b930e46)
  • Widen retry predicate to include ServiceUnavailable (#1641) (3e021a4)
Bug Fixes
  • Allow storage_billing_model to be explicitly set to None to use project default value (#1665) (514d3e1)
  • Relax timeout expectations (#1645) (1760e94)
  • Use isinstance() per E721, unpin flake8 (#1659) (54a7769)
Documentation

Queries now support additional ways to work with grouping sets, which include:

This feature is in preview.

Adding descriptions to the columns of a view is now generally available (GA). Use the CREATE VIEW or ALTER COLUMN DDL statements to add descriptions.

BigQuery is now available in the Dammam (me-central2) region.

BigQuery ML is now available in the Dammam (me-central2) region.

BigQuery Data Transfer Service is now available in the Dammam (me-central2) region.

Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigtable

2.27.4 (2023-09-29)

Dependencies
  • Update dependency com.google.cloud:gapic-libraries-bom to v1.21.0 (#1942) (f8d533f)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.16.1 (#1933) (159636a)
Cloud Logging

A weekly digest of client library updates from across the Cloud SDK.

Python

Changes for google-cloud-logging

3.8.0 (2023-10-03)

Features
  • Add cloud_run_job monitored resource type. (#788) (3b310d6)

When you install the Ops Agent on a Compute Engine VM by using the Cloud Monitoring VM Instances dashboard or the Observability tab on a Compute Engine VM details page, the agent is now installed with an Ops Agent OS policy. This installation method replaces the prior set of manual steps. For more information, see Installing the agent by using the Google Cloud console.

Cloud Monitoring

When you install the Ops Agent on a Compute Engine VM by using the Cloud Monitoring VM Instances dashboard or the Observability tab on a Compute Engine VM details page, the agent is now installed with an Ops Agent OS policy. This installation method replaces the prior set of manual steps. For more information, see Installing the agent by using the Google Cloud console.

Cloud SQL for SQL Server

The cross db ownership chaining flag is deprecated for all SQL Server versions.

For cross-database access, use the Microsoft tutorial for signing stored procedures with a certificate.

Cloud Spanner

Cloud Spanner batch write is now available in Preview. You can use Spanner batch write to commit multiple mutations non-atomically in a single request with low latency. For more information, see Modify data using batch write.

Cloud Spanner Vertex AI integration now supports Vertex AI Generative AI text embeddings and the text-bison model. For more information, see Get Vertex AI text embeddings.

Compute Engine

When you install the Ops Agent on a Compute Engine VM by using the Observability tab on a Compute Engine VM details page, the agent is now installed with an Ops Agent OS policy. This installation method replaces the prior set of manual steps. For more information, see Installing the agent by using the Google Cloud console.

Generally available: H3 VMs, designed for compute-intensive high performance computing (HPC) workloads, are now generally available. For more information, see H3 machine series.

Contact Center AI Insights

You can now use the CCAI Insights API to ingest audio conversation data in bulk from a Cloud Storage bucket. Optionally, you can apply redaction prior to import and transcribe the audio using custom Speech-to-Text settings. See the documentation for details.

Dataproc Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Node.js

Changes for @google-cloud/datastore

8.2.1 (2023-10-03)

Bug Fixes
  • Make aggregation query requests run properly inside a transaction (#1166) (263804b)

8.2.0 (2023-10-02)

Features
  • Support for using multiple databases in datastore (#1090) (10ce563)
Bug Fixes
  • Allow users to set environment variable to connect to emulator running on docker (#1164) (a41741b)
  • Check property existence for exclude from indexes with wildcard (#1114) (e6b8ef7)
  • deps: Update dependency sinon to v16 (#1150) (0d8b715)

Go

Changes for datastore/admin/apiv1

1.15.0 (2023-10-06)

Features
  • datastore: Adding dynamic routing header (#8364) (d235a42)
Bug Fixes
Google Cloud Architecture Center

Best practices for running tightly coupled HPC applications: Updated to include guidance for H3 compute-optimized VMs.

Architectures for high availability of PostgreSQL clusters on Compute Engine: Added information about the write-ahead log and the Log Sequence Number.

Google Kubernetes Engine

If you are using a third generation machine series (for example, C3), GKE configures Local SSD volumes as the local ephemeral storage by default. You no longer need to specify the --ephemeral-storage-local-ssd flag when provisioning clusters or node pools. When you configure Local SSD volumes as raw block storage with the --local-nvme-ssd-block flag, specifying the count value is now optional.

Security Command Center

Cloud IDS threat detections available in Security Command Center

Threats that are detected by Cloud IDS, a Google Cloud intrusion detection service, are now included in the findings that are issued by the Event Threat Detection service of Security Command Center. This feature is available in Preview.

For more information, see:

Transfer Appliance

'ta mount' and 'ta unmount' are command line tools offering the user the ability to mount their own NFS or CIFS shares onto the appliance.

Learn more about how to mount to an appliance.

Vertex AI Search and Conversation

Vertex AI Search and Conversation: Renamed in the console and documentation

The Google Cloud console and the documentation at cloud.google.com have been updated to show the current product name for Vertex AI Search and Conversation. On the console, look for "Search and Conversation".

You might see the old name (Generative AI App Builder) in some places—for example, in the API reference.

October 06, 2023

Apigee Advanced API Security

On October 6, 2023, we released an updated version of Advanced API Security.

Public Preview of Advanced API Security Actions

Advanced API Security's new Security Actions feature lets you create security actions that define how Apigee handles detected traffic. You can create the following security actions:

  • Deny actions, which deny requests that meet specified conditions, for example, originating at an IP address that has been identified as a source of abuse.

  • Flag actions, which let requests pass through, but add headers to requests to identify them as suspicious.

  • Allow actions, which are used to override deny actions in specific cases when the request is trusted.

Backup and DR

Backup and DR Service 11.0.7.404 is now available to update your backup/recovery appliance. Refer to these instructions to update your appliance.

The new Backup and DR Service update policy requires updating all backup/recovery appliances older than version 11.0.3 to maintain product support and avoid restrictions on enabling backups for new entities. Learn more.

Added support to restore PostgreSQL database backup images to an alternate location. Learn more.

Backup and DR agent is enhanced to support Rocky Linux 8.7 operating system version. See support matrix.

Backup and DR agent now supports Rocky Linux 8.7 on Oracle 19c database. See support matrix.

Backup and DR agent now supports RHEL 8.4 on Oracle 21c database. See support matrix.

Cloud Bigtable

Cloud Bigtable instance, cluster, and table metadata is automatically synced to Data Catalog, a feature of Dataplex, for improved data discovery and governance. This feature is generally available (GA).

Cloud Healthcare API

The Cloud Healthcare API offers multi-region support in the Europe (eu) region.

Compute Engine

Generally available: NVIDIA L4 GPUs are now available in the following additional regions and zones:

  • APAC
    • Seoul, South Korea (asia-northeast3-b)
  • Europe
    • St. Ghislain, Belgium (europe-west1-b)
    • Frankfurt, Germany (europe-west3-b)
  • North America
    • Council Bluffs, Iowa: (us-central1-c)
    • Las Vegas, Nevada (us-west4-a,c)

For more information about using GPUs on Compute Engine, see GPU platforms.

Dataproc

New Dataproc on Compute Engine image version 2.2 is available for preview with upgraded components.

New Dataproc on Compute Engine subminor image versions:

  • 2.0.79-debian10, 2.0.79-rocky8, 2.0.79-ubuntu18
  • 2.1.27-debian11, 2.1.27-rocky8, 2.1.27-ubuntu20, 2.1.27-ubuntu20-arm
  • 2.2.0-RC2-debian11, 2.2.0-RC2-rocky9, 2.2.0-RC2-ubuntu22

Upgraded Hadoop version from 3.3.3 to 3.3.6 in the latest Dataproc on Compute Engine 2.1 image version.

Upgraded the Cloud Storage connector version to 2.2.17 in the latest Dataproc Serverless for Spark runtimes.

Added the gs.http.connect-timeout and gs.http.read-timeout properties in Flink to set the connection timeout and read timeout for java-storage client in the latest Dataproc on Compute Engine 2.1 image version.

Added the gs.filesink.entropy.enabled property in Flink to enable entropy injection in filesink Cloud Storage path in the latest Dataproc on Compute Engine 2.1 image version.

Google Kubernetes Engine

A previously published release note on December 14, 2022 has been updated. Support for migration of GKE Autopilot clusters' datapath provider to Dataplane V2 has been paused. We will update this release note when migration support resumes.

October 05, 2023

Access Transparency

Access Transparency supports Firebase Security Rules in the Preview stage.

Apigee Integrated Portal

On October 5, 2023 we released an updated version of Apigee integrated portal. This release includes general improvements to performance and availability.

Batch

Batch is available in the following regions:

  • australia-southeast2 (Melbourne)
  • europe-west8 (Milan)
  • europe-west12 (Turin)
  • me-west1 (Tel Aviv)
  • northamerica-northeast2 (Toronto)
  • southamerica-east1 (São Paulo)
  • us-east5 (Columbus)

For more information, see Locations.

BigQuery

The BigQuery migration assessment is now available for Snowflake in preview. You can use this feature to assess the complexity of migrating data from your Snowflake data warehouse to BigQuery.

Certificate Authority Service

Certificate Authority Service is now available in the following region:

  • me-central2

For more information, see Certificate Authority Service locations.

Chronicle

The following supported default parsers have changed. Each is listed by product name and log_type value, if applicable.

  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • Azion (AZION)
  • Azure AD Organizational Context (AZURE_AD_CONTEXT)
  • Blue Coat Proxy (BLUECOAT_WEBPROXY)
  • Cisco ACS (CISCO_ACS)
  • Cisco FireSIGHT Management Center (CISCO_FIRESIGHT)
  • Cisco ISE (CISCO_ISE)
  • Cisco Umbrella DNS (UMBRELLA_DNS)
  • Cloud Intrusion Detection System (GCP_IDS)
  • Cloudflare (CLOUDFLARE)
  • Compute Context (N/A)
  • Corelight (CORELIGHT)
  • Darktrace (DARKTRACE)
  • F5 ASM (F5_ASM)
  • FireEye (FIREEYE_ALERT)
  • HAProxy (HAPROXY)
  • Hashicorp Vault (HASHICORP)
  • HP Procurve Switch (HP_PROCURVE)
  • IBM Security Verify SaaS (IBM_SECURITY_VERIFY_SAAS)
  • Imperva (IMPERVA_WAF)
  • Ionix (IONIX)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • MISP Threat Intelligence (MISP_IOC)
  • Office 365 (OFFICE_365)
  • Oracle Cloud Infrastructure Audit Logs (OCI_AUDIT)
  • Sendmail (SENDMAIL)
  • Tanium Audit (TANIUM_AUDIT)
  • Tanium Stream (TANIUM_TH)
  • Thycotic (THYCOTIC)
  • Unix system (NIX_SYSTEM)
  • VMware ESXi (VMWARE_ESX)
  • VMware NSX (VMWARE_NSX)
  • VMware vCenter (VMWARE_VCENTER)
  • WatchGuard (WATCHGUARD)
  • Windows DNS (WINDOWS_DNS)
  • Windows Event (WINEVTLOG)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Workspace Alerts (WORKSPACE_ALERTS)
  • Zeek JSON (BRO_JSON)
  • Zscaler CASB (ZSCALER_CASB)

The following log types, without a default parser, were added. Each is listed by product name and log_type value, if applicable.

  • AWS_EMR (AWS_EMR)
  • Azure Application Gateway (AZURE_GATEWAY)
  • CloudBolt (CLOUDBOLT)
  • DNSFilter (DNSFILTER)
  • GitGuardian Enterprise (GITGUARDIAN_ENTERPRISE)
  • GoAnywhere MFT (GOANYWHERE_MFT)
  • IBM Security Identity Manager (IBM_SIM)
  • Jamf Pro MDM (JAMF_PRO_MDM)
  • MultiPay (MULTIPAY)
  • Palo Alto Networks IoT Security (PAN_IOT)
  • Raritan Dominion SX II (RARITAN_DOMINION)

For a list of supported log types and details about default parser changes, see Supported log types and default parsers.

Cloud Composer

Cloud Composer 2 is now available in Milan (europe-west8), Berlin (europe-west10), and Turin (europe-west12).

Fixed a problem where newly-created Airflow workers ignored the SIGTERM signal, which could lead to task failures.

Cloud Composer 2.4.5 images are available:

  • composer-2.4.5-airflow-2.5.3 (default)
  • composer-2.4.5-airflow-2.4.3
Cloud Monitoring

Ops Agent version 2.42.0 introduces support for Compute Engine Arm VMs that are running Ubuntu 22.04 LTS (Jammy Jellyfish). For more information, see Support for Compute Engine Arm VMs.

Dashboard-wide filters now apply to the Logs Panel widget. For more information, see Filter the log entries.

Cloud Spanner

Cloud Spanner sampled query plans are now available in GA. You can view samples of historic query plans and compare the performance of a query over time. For more information, see Sampled query plans.

Cloud TPU

Cloud TPU now supports TensorFlow 2.13.1. For more information see the TensorFlow 2.13.1 release notes.

Cloud Trace

You can now show logs and events as inline messages when exploring a trace. For more information, see Find and explore traces.

Google Kubernetes Engine

(2023-R19) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters

The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.

No channel

Stable channel

  • The following version is no longer available in the Stable channel: 1.26.5-gke.2100

Regular channel

  • There are no new releases in the Regular release channel.

Rapid channel

An issue was previously reported with running certain commands in container images when Image streaming is enabled. See the August 31, 2023 release note for details. This issue is fixed in the following minor versions:

  • 1.25 with the patch versions 1.25.14-gke.1351000 and later.
  • 1.25 with the patch versions 1.26.9-gke.1345000 and later.
  • 1.27 with the patch versions 1.27.6-gke.100 and later.
  • 1.28 with the patch version 1.28.1-gke.1157000 and later.

To receive the fix, upgrade your nodes to an applicable patch version.

(2023-R19) Version updates

(2023-R19) Version updates

  • The following version is no longer available in the Stable channel: 1.26.5-gke.2100

(2023-R19) Version updates

(2023-R19) Version updates

  • There are no new releases in the Regular release channel.
Vertex AI

Ray on Vertex AI is now available in Preview

Ray is an open-source framework for scaling AI and Python applications. Ray provides the infrastructure to perform distributed computing and parallel processing for your machine learning workflow.

You can now create Ray clusters and develop your Ray applications on Vertex AI. This feature is in Preview. For more information, see Ray on Vertex AI overview.

October 04, 2023

BigQuery

You can now copy tables across regions. This feature is now in preview.

Chronicle

Chronicle Curated Detections has been enhanced with new detection content for Google Cloud threats. These new rule sets help identify reconnaissance and exploitation behavior from open source Kubernetes tools.

The submit_parser command now has an option to skip validation if no logs are found. For more information, see the Chronicle CLI user guide.

Cloud Interconnect

Dedicated Cloud Interconnect support is available in the following colocation facilities:

  • CyrusOne Phoenix - Phoenix

For more information, see the Locations table.

Compute Engine

Generally available: NVIDIA L4 GPUs are now available in the following additional regions and zones:

  • Singapore(asia-southeast1-a)

For more information about using GPUs on Compute Engine, see GPU platforms.

Confidential VM

Confidential Space. A new image (confidential-space-230901) is now available. This image provides improved logging capabilities and increases the file descriptor limits. For more information, see the Changelog.

Google Kubernetes Engine

Log rotation is misconfigured on nodes running a COS-based image type (cos_containerd). This affects all COS-based nodes running version 1.28 or higher. As a result of this issue, your logs may fill up the disk and cause your nodes to be marked as 'Not Ready' and to be auto-repaired. As a workaround, use a privileged DaemonSet to change the logrotate path to /usr/bin/ instead of /usr/sbin/ in Systemd unit kube-logrotate.service.

Network Intelligence Center

Network Analyzer now includes an insight that gives a summary of the IP address utilization of all the subnet ranges. This insight is already available in Recommender API and Cloud Logging. For more information, see IP address utilization summary insights.

SAP on Google Cloud

ABAP SDK for Google Cloud, version 1.5 is generally available (GA)

Version 1.5 of the ABAP SDK for Google Cloud is generally available (GA). This version of the SDK offers extended ABAP client libraries to build and deploy ML and AI-driven solutions using a wide range of Google Cloud services.

This SDK also enables use of the OAuth 2.0 framework to authenticate to Google Cloud APIs using OAuth 2.0 client credentials.

For more information, see What's new with the ABAP SDK for Google Cloud.

Vertex AI

Model tuning for the textembedding-gecko model is now available in Preview

You can now use supervised fine-tuning to tune the textembedding-gecko model. This feature is in (Preview). For more information, see Tune text embeddings.

Vertex AI Prediction

You can now use C3 machine types to serve predictions.

Vertex AI Feature Store

The new and improved Vertex AI Feature Store is now available in Preview. With the new Vertex AI Feature Store you can streamline your feature management in the following ways:

  • Store and maintain your offline feature data in BigQuery, taking advantage of the data management capabilities of BigQuery. In the new Vertex AI Feature Store, BigQuery serves as the offline store. You don't need to copy or import feature data to an offline store in Vertex AI.

  • Register your feature data sources in BigQuery by creating feature groups and features.

  • Define online serving clusters called online store instances; and then serve features from one or more BigQuery data sources, by aggregating them in a feature view within an online store instance. Use Optimized online serving for ultra-low latency needs and Cloud Bigtable online serving for high data volumes.

  • Retrieve vector embeddings stored in BigQuery for real-time serving.

For more information, see About Vertex AI Feature Store.

October 03, 2023

BigQuery Chronicle

The Chronicle SIEM user interface has a new top-level navigation to help you access the most commonly used Chronicle SIEM features. It works much the same as the navigation for Chronicle Security Operations. The new navigation menu expands from the left side of the screen, replacing the 9-dot icon at the top right. It is designed to make it easier to find information and resources and to help you work more efficiently. The Chronicle homepage can be accessed by clicking the Chronicle logo at the top left of the page. Reference lists can now be found within the Search page or the Rules Editor page.

Chronicle SOAR

Release 6.2.36

GA - 14th October, 2023

Internal security fixes

Cloud Composer

Oozie to Airflow tool version 2.0 is available. The new version of the tool supports Airflow 2.

Oozie to Airflow tool converts Apache Oozie workflows into Apache Airflow DAGs. For more information, see the project's page in PyPI and the oozie-to-airflow repository on GitHub.

Container Optimized OS

cos-dev-113-17935-0-0

Kernel Docker Containerd GPU Drivers
COS-6.1.55 v24.0.5 v1.7.3 v535.104.05(default),v470.199.02(R470)

Upgraded chromeos-base/chromeos-dbus-bindings to v0.0.1-r2787.

Upgraded chromeos-base/chromeos-common-script to v0.0.1-r554.

Fixed CVE-2023-42753 in the Linux kernel.

cos-109-17800-0-47

Kernel Docker Containerd GPU Drivers
COS-6.1.42 v24.0.5 v1.7.2 v535.104.05(default),v470.199.02(R470)

Updated cos-gpu-installer to v2.1.9.

Fixed CVE-2023-42753 in the Linux kernel.

cos-93-16623-461-36

Kernel Docker Containerd GPU Drivers
COS-5.10.177 v20.10.24 v1.6.20 v450.248.02(default),v470.199.02(R470),v535.104.05

Fixes CVE-2023-2163 in the Linux Kernel.

cos-101-17162-279-57

Kernel Docker Containerd GPU Drivers
COS-5.15.120 v20.10.24 v1.6.21 v470.199.02(default),v535.104.05

Updated cos-gpu-installer to v2.1.9.

Dataplex

Dataplex BigLake integration is generally available (GA). Dataplex BigLake integration lets you upgrade a Cloud Storage bucket to managed, creating BigLake tables and Object tables instead of external tables. This allows the application of column-level, row-level, and table-level policies, enabling fine-grained security and dynamic data masking.

Managed Service for Microsoft Active Directory

Managed Microsoft AD is available in the me-central2 (Dammam) region. For more information, see Deploy domain controllers in additional regions.

Retail API

Retail Search: Facet controls

You can create facet controls that apply to search and browse operations. These help you control facets values without editing your catalog and set the ranking of facet keys.

Numerical facets have been improved: intervals are calculated but they can also be customized.

The facet controls are:

  • Ignore facet values
  • Replace facet values
  • Set numerical intervals
  • Remove facets
  • Force return facets

For more information, see Facets for search.

Vertex AI

TorchServe is used to host PyTorch machine learning models for online prediction. Vertex AI provides pre-built PyTorch model serving containers which depend on TorchServe. Vulnerabilities were recently discovered in TorchServe which would allow an attacker to take control of a TorchServe deployment if its model management API is exposed. Customers with PyTorch models deployed to Vertex AI online prediction are not affected by these vulnerabilities, since Vertex AI does not expose TorchServe's model management API. Customers using TorchServe outside of Vertex AI should take precautions to ensure their deployments are set up securely.

For more information, see the Vertex AI security bulletin.

October 02, 2023

Anthos Attached Clusters

This release includes the following Anthos attached clusters platform versions:

  • 1.25.0-gke.7
  • 1.26.0-gke.5
  • 1.27.0-gke.2

1.25.0-gke.7, 1.26.0-gke.5, and 1.27.0-gke.1

Resolved an issue affecting EKS environments in which Kubernetes resource metrics weren't successfully scraped from the kubelet when a node's name within the cluster didn't match that same node's hostname.

1.25.0-gke.7 and 1.26.0-gke.5

This release fixes the following vulnerabilities:

Anthos clusters on AWS

You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:

Anthos clusters on Azure

You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:

Anthos clusters on VMware

Upgrading an admin cluster with always-on secrets encryption enabled might fail.

An admin cluster upgrade from 1.14.x to 1.15.0 - 1.15.4 with always-on secrets encryption enabled might fail depending on whether the feature was enabled during cluster creation or during cluster update.

We recommend that you don't upgrade your admin cluster until a fix is available in 1.15.5. If you must upgrade to 1.15.0-1.15.4, do the steps in Preventing the upgrade failure before upgrading the cluster.

For information on working around an admin cluster failure because of this issue, see Upgrading an admin cluster with always-on secrets encryption enabled fails. Note that the workaround relies on you having the old encryption key backed up. If the old key is no longer available, you will have to recreate the admin cluster and all user clusters.

Bare Metal Solution

You can now use Bare Metal Solution's self-service functionality to order your resources after executing a one-time Order Form. This feature is generally available (GA). For more information, see Order Bare Metal Solution resources.

BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Node.js

Changes for @google-cloud/bigquery

7.3.0 (2023-09-28)

Features
Bug Fixes
  • Avoid TypeError if resp is undefined (#1273) (ff51c1d)
  • Updated types from API discovery doc (#1284) (1d8a2b7)
  • Updating type for test blocking dependency updates (#1282) (1dbe0fe)

Java

Changes for google-cloud-bigquery

2.33.1 (2023-09-28)

Bug Fixes
  • Dry run NPE when there is no query parameters (#2899) (8f85a4d)

2.33.0 (2023-09-27)

Features
Bug Fixes
  • Update samples snippet to write to BYTES instead of ARRAY<BYTES> (#2876) (7e040e9)
Dependencies
  • Update actions/checkout action (#2893) (e3655af)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.16.1 (#2892) (e1d9871)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.27 (#2885) (2237ca2)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.27 (#2886) (539b4e6)
  • Update github/codeql-action action to v2.21.4 (#2829) (599e3b3)
  • Update github/codeql-action action to v2.21.8 - abandoned (#2897) (ab4e1d0)
  • Update github/codeql-action action to v2.21.8 (#2889) (b568026)
  • Update github/codeql-action action to v2.21.9 (#2901) (33a729f)

BigQuery native integration in Looker Studio enables monitoring features for Looker Studio queries, improves query performance, and supports many BigQuery features. This feature is in preview.

Cloud Asset Inventory

The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning).

  • Identity and Access Management
    • iam.googleapis.com/PolicyV2
Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigtable

2.27.3 (2023-09-29)

Bug Fixes
Dependencies
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.27 (#1919) (56d6b40)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.27 (#1920) (ca1dd5b)
  • Update gapic-generator-java to 2.26.0 (#1936) (15cd486)
Cloud Healthcare API

A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.

Cloud Logging

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-logging

3.15.10 (2023-09-27)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.16.1 (#1434) (e9e9835)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.27 (#1430) (9e750a3)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.27 (#1431) (7c2aa2c)

Python

Changes for google-cloud-logging

3.7.0 (2023-09-25)

Features
  • Add ConfigServiceV2.CreateBucketAsync method for creating Log Buckets asynchronously (30f24a8)
  • Add ConfigServiceV2.CreateLink method for creating linked datasets for Log Analytics Buckets (30f24a8)
  • Add ConfigServiceV2.DeleteLink method for deleting linked datasets (30f24a8)
  • Add ConfigServiceV2.GetLink methods for describing linked datasets (30f24a8)
  • Add ConfigServiceV2.ListLinks method for listing linked datasets (30f24a8)
  • Add ConfigServiceV2.UpdateBucketAsync method for creating Log Buckets asynchronously (30f24a8)
  • Add LogBucket.analytics_enabled field that specifies whether Log Bucket's Analytics features are enabled (30f24a8)
  • Add LogBucket.index_configs field that contains a list of Log Bucket's indexed fields and related configuration data (30f24a8)
  • Log Analytics features of the Cloud Logging API (30f24a8)
Bug Fixes
  • Add async context manager return types (30f24a8)
  • Add severity to structured log write (#783) (31a7f69)
  • Handle exceptions raised when fetching Django request data (#758) (5ecf886)
  • Unintended exception omittion (#736) (022dc54)
Documentation
  • Documentation for the Log Analytics features of the Cloud Logging API (30f24a8)
  • Minor formatting (30f24a8)
Cloud Monitoring

The Metrics management page in Cloud Monitoring now lets you create alerting policies and charts for metrics that have no associated alerting policies or custom dashboards. For more information, see View and manage metric usage.

You can now import your Grafana dashboards into Cloud Monitoring. For more information, see Import Grafana dashboards into Cloud Monitoring.

You can now configure notifications for Google Chat spaces. For more information, see Create and manage notification channels.

Cloud SQL for MySQL

For Cloud SQL Enterprise edition and Cloud SQL Enterprise Plus edition, you can restore backups across instances of different editions.

Cloud SQL for PostgreSQL

For Cloud SQL Enterprise edition and Cloud SQL Enterprise Plus edition, you can restore backups across instances of different editions.

Cloud Workstations

If you use the latest preconfigured base images for JetBrains IDEs, the .vmoptions and .properties files persist across workstations. For more information, see Customize JetBrains IDE vmoptions and properties.

Dialogflow

Dialogflow CX speech adaptation can now be configured manually.

Document AI Warehouse

Support root folder filtering

Filestore Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Python

Changes for google-cloud-ndb

2.2.2 (2023-09-19)

Documentation
  • query: Document deprecation of Query.default_options (#915) (a656719), closes #880
Google Kubernetes Engine

GKE now delivers insights and recommendations if users have installed webhooks that intercept system resources or webhooks that have no available endpoints. To learn more, see Ensure control plane stability when using webhooks.

Pub/Sub

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-pubsub

1.125.5 (2023-09-28)

Dependencies
  • Update gapic-generator-java to 2.26.0 (935849c)

1.125.4 (2023-09-28)

Dependencies
  • Update dependency com.google.cloud:google-cloud-bigquery to v2.33.0 (#1750) (bcbfcd0)

1.125.3 (2023-09-27)

Dependencies
  • Update dependency com.google.cloud:google-cloud-core to v2.24.1 (#1737) (48a4432)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.16.1 (#1738) (e2cf7c1)
  • Update dependency org.apache.avro:avro to v1.11.3 (#1740) (971b35f)
  • Update dependency org.xerial.snappy:snappy-java to v1.1.10.4 security (70ba500)
  • Update dependency org.xerial.snappy:snappy-java to v1.1.10.5 (#1746) (a4b1994)
SAP on Google Cloud

Cloud Storage Backint agent for SAP HANA version 1.0.29

Version 1.0.29 of the Cloud Storage Backint agent for SAP HANA is available. This version sets the default value of the HTTP_READ_TIMEOUT parameter to -1; no timeout.

For more information about the agent, see Cloud Storage Backint agent for SAP HANA overview.

Virtual Private Cloud

Private Service Connect service connectivity automation is available in General Availability. Service connectivity automation lets service producers automate deployment and service connectivity to eligible managed services on behalf of consumers.

September 30, 2023

Cloud Firewall

Starting September 30, 2023, you will be charged for the Cloud Firewall Standard feature—fully qualified domain name (FQDN) objects. For more information about billing, see Cloud Firewall pricing.

Google Cloud VMware Engine

VMware Engine nodes are now available in the following additional zone:

  • Tel Aviv (me-west1-b)

September 29, 2023

Access Approval

Access Approval supports Vertex AI Search in the Preview stage.

Access Transparency

Access Transparency supports Vertex AI Search in the Preview stage. For the complete list of services that Access Transparency supports, see Supported services.

Anthos clusters on VMware

Anthos clusters on VMware 1.16.1-gke.45 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.16.1-gke.44 runs on Kubernetes 1.27.4-gke.1600.

The Prometheus and Grafana add-ons field, loadBalancer.vips.addonsVIP is deprecated in 1.16 and later. This change is because Google Managed Service for Prometheus replaced the Prometheus and Grafana add-ons in 1.16.

The following issues are fixed in 1.16.1-gke.45:

  • Fixed the known issue that gkectl repair admin-master returns kubeconfig unmarshall error.
  • Fixed the known issue that GARP reply sent by Seesaw doesn't set target IP
  • Fixed the known issue that Seesaw VM may be broken due to low disk space
  • Fixed the known issue that false warnings might be generated against persistent volume claims.
  • Fixed the known issue that caused CNS attachvolume tasks to appear every minute for in-tree PVC/PV after upgrading to Anthos 1.15+.

The following vulnerabilities are fixed in 1.16.1-gke.44:

Anthos clusters on VMware 1.14.8-gke.37 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.14.8-gke.37 runs on Kubernetes 1.25.12-gke.2400.

The following issues are fixed in 1.14.8-gke.37:

  • Fixed the disk full known issue on Seesaw VM due to no log rotation for fluent-bit.

The following vulnerabilities are fixed in 1.14.8-gke.37:

Anthos clusters on bare metal

Release 1.14.9

Anthos clusters on bare metal 1.14.9 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.14.9 runs on Kubernetes 1.25.

Fixes:

Fixed an issue to prevent cluster upgrades from starting on a node before either all Pods have been drained or the Pod draining timeout has been reached.

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

Apigee X

On September 29, 2023, we released an updated version of Apigee.

New attributes for Pay-as-you-go pricing are generally available (GA).

Apigee updated its Pay-as-you-go pricing model, making it possible for customers to onboard at a significantly reduced initial cost and right-size their ongoing expenses to usage.

To learn more about the updated Pay-as-you-go pricing experience, see Pay-as-you-go (updated attributes) pricing overview.

Standard and extensible API proxies are generally available (GA).

Standard and extensible API proxies are generally available for use with Apigee organizations.

For more information about standard and extensible API proxies, see API proxy types.

HTTPModifier and ReadPropertySet policies and templating support for message elements are generally available (GA).

The HTTPModifier policy can change an existing request or response message and provides a subset of the functionality already available in the AssignMessage policy. See HTTPModifier policy.

The ReadPropertySet policy reads property sets and populates flow variables with the results. See ReadPropertySet policy.

HTTPModifier and ReadPropertySet are standard policies. Proxies built exclusively with standard policies are called standard proxies and can be deployed to any environment type. See Pay-as-you-go (updated attributes) pricing overview.

With this release, template support for message elements is also generally available. See URL templating.

New environment types are generally available (GA).

With this release, Apigee introduces three distinct environments that have access to varying degrees of Apigee capabilities and costs: Base, Intermediate, and Comprehensive.

For more information, see Apigee Pay-as-you-go environment types.

Apigee API Analytics add-on for Pay-as-you-go organizations is generally available (GA).

With this release, Apigee API Analytics is available as a paid add-on capability for Pay-as-you-go organizations. The add-on can be enabled in any Apigee Intermediate or Comprehensive environment. For more information, see Manage the Apigee API Analytics add-on.

One click provisioning for Apigee Pay-as-you-go organizations is generally available (GA).

Simplify your onboarding experience with one click provisioning for new Pay-as-you-go organizations, using smart default configurations. To learn more, see Provision Apigee with one click.

Updated pricing attributes in Subscription plans are available.

To get started with subscription plans that include new pricing attributes (consistent with Pay-as-you-go pricing), contact your Google Cloud sales specialist.

For more information, see Apigee Subscription 2024 entitlements. Apigee hybrid is not available in the new subscription plan at this time.

BigQuery

As a BigQuery administrator, to monitor your organization's slots utilization and BigQuery jobs' performance over time, use can now use administrative query inspector. This feature is now generally available.

Cloud Composer

Airflow triggerer is now generally available (GA).

The cost of the environments.ExecuteAirflowCommand and environments.StopAirflowCommand operations is reduced from 100 to 25 quota units.

The apache-airflow-providers-google package is upgraded to version 10.9.0 in images with Airflow 2.5.3 and 2.4.3. For more information about changes, see the apache-airflow-providers-google changelog from version 10.7.0 to version 10.9.0.

Cloud Composer 2.4.4 images are available:

  • composer-2.4.4-airflow-2.5.3 (default)
  • composer-2.4.4-airflow-2.4.3

Cloud Composer versions 2.0.28, 2.0.27, 1.19.11, and 1.19.10 have reached their end of full support period.

Cloud Load Balancing

Cloud Load Balancing introduces the global external Proxy Network Load Balancer. The global external Proxy Network Load Balancer is implemented on globally distributed GFEs and supports advanced traffic management capabilities. This load balancer can be configured to handle either TCP or SSL traffic by using either a target TCP proxy or a target SSL proxy respectively. Global external proxy Network Load Balancers support backends such as instance groups, hybrid NEGs, and Private Service Connect NEGs.

Load balancers that are already deployed in the classic mode are renamed as classic Proxy Network Load Balancer in the console.

For details, see the External proxy Network Load Balancer overview.

To set up a global external Proxy Network Load Balancer, see the following pages:

This capability is in Preview.

With the launch of global external Proxy Network Load Balancer, we now support three deployment modes with the external Proxy Network Load Balancer—classic (General Availability), Regional (General Availability) and global (Preview). No changes have been made to the API.

For details, see the External proxy Network Load Balancer overview.

Typically with HTTPS communication, the authentication works only one way: the client verifies the identity of the server. For applications that require the load balancer to authenticate the identity of clients that connect to it, both a global external Application Load Balancer and a global external Application Load Balancer (classic) support mutual TLS (mTLS).

With mTLS, the load balancer requests that the client send a certificate to authenticate itself during the TLS handshake with the load balancer. You can configure a trust store that the load balancer uses to validate the client certificate's chain of trust.

For details, see the following:

This capability is in General Availability.

Cloud Logging

Ops Agent versions 2.39.0 and 2.40.0 crash if you use them on Compute Engine VMs with attached GPUs. Use Ops Agent version 2.38.0, or versions 2.41.0 and newer, on VMs with attached GPUs.

Cloud Monitoring

Ops Agent versions 2.39.0 and 2.40.0 crash if you use them on Compute Engine VMs with attached GPUs. Use Ops Agent version 2.38.0, or versions 2.41.0 and newer, on VMs with attached GPUs.

Config Connector

Config Connector version 1.110.0 is now available.

Added MutatingWebhookConfigurationCustomization and ValidatingWebhookConfigurationCustomization to support the customization on webhook timeouts.

Added value validation for resource requests and limits in the customizable ControllerResource and NamespacedControllerResource CRDs.

Promoted CertificateManagerCertificate, CertificateManagerCertificateMap, CertificateManagerCertificateMapEntry and CertificateManagerDNSAuthorization from v1alpha1 to v1beta1.

Promoted RunService from alpha stability to stable stability.

  • Renamed field spec.template.containerConcurrency to spec.template.maxInstanceRequestConcurrency.
  • Fixed the IAM support by removing the support of "IAM conditions" on this resource.
  • Removed field status.resourceGeneration.

Resource BigQueryTable(v1beta1):

  • Added spec.tableConstraints field.
  • Added spec.materializedView.allowNonIncrementalDefinition field.

Resource ComputeInstance(v1beta1):

  • Added spec.networkInterface.items.internalIpv6PrefixLength field.
  • Added spec.networkInterface.items.ipv6Address field.

Resource ComputeInstanceTemplate(v1beta1):

  • Added spec.networkInterface.items.internalIpv6PrefixLength field.
  • Added spec.networkInterface.items.ipv6Address field.

Resource ContainerCluster(v1beta1):

  • Added spec.enableFqdnNetworkPolicy field.
  • Added spec.nodeConfig.confidentialNodes field.

Resource ContainerNodePool(v1beta1):

  • Added spec.nodeConfig.confidentialNodes field.

Resource DialogflowCXFlow(v1alpha1):

  • Added spec.eventHandlers.items.triggerFulfillment.conditionalCases field.
  • Added spec.eventHandlers.items.triggerFulfillment.setParameterActions field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.channel field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.conversationSuccess field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.liveAgentHandoff field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.outputAudioText field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.payload field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.playAudio field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.telephonyTransferCall field.
  • Added spec.transitionRoutes.items.triggerFulfillment.conditionalCases field.
  • Added spec.transitionRoutes.items.triggerFulfillment.setParameterActions field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.channel field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.conversationSuccess field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.liveAgentHandoff field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.outputAudioText field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.payload field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.playAudio field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.telephonyTransferCall field.

Resource DialogflowCXPage(v1alpha1):

  • Added spec.entryFulfillment.conditionalCases field.
  • Added spec.entryFulfillment.setParameterActions field.
  • Added spec.entryFulfillment.messages.items.channel field.
  • Added spec.entryFulfillment.messages.items.conversationSuccess field.
  • Added spec.entryFulfillment.messages.items.liveAgentHandoff field.
  • Added spec.entryFulfillment.messages.items.outputAudioText field.
  • Added spec.entryFulfillment.messages.items.payload field.
  • Added spec.entryFulfillment.messages.items.playAudio field.
  • Added spec.entryFulfillment.messages.items.telephonyTransferCall field.
  • Added spec.eventHandlers.items.triggerFulfillment.conditionalCases field.
  • Added spec.eventHandlers.items.triggerFulfillment.setParameterActions field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.channel field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.conversationSuccess field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.liveAgentHandoff field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.outputAudioText field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.payload field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.playAudio field.
  • Added spec.eventHandlers.items.triggerFulfillment.messages.items.telephonyTransferCall field.
  • Added spec.form.parameters.items.defaultValue field.
  • Added spec.form.parameters.items.fillBehavior.repromptEventHandlers field.
  • Added spec.form.parameters.items.fillBehavior.initialPromptFulfillment.conditionalCases field.
  • Added spec.form.parameters.items.fillBehavior.initialPromptFulfillment.setParameterActions field.
  • Added spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.channel field.
  • Added spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.conversationSuccess field.
  • Added spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.liveAgentHandoff field.
  • Added spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.outputAudioText field.
  • Added spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.payload field.
  • Added spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.playAudio field.
  • Added spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.telephonyTransferCall field.
  • Added spec.transitionRoutes.items.triggerFulfillment.conditionalCases field.
  • Added spec.transitionRoutes.items.triggerFulfillment.setParameterActions field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.channel field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.conversationSuccess field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.liveAgentHandoff field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.outputAudioText field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.payload field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.playAudio field.
  • Added spec.transitionRoutes.items.triggerFulfillment.messages.items.telephonyTransferCall field.

Resource RunJob(v1beta1):

  • spec.template.template.volumes[].secret.items[].mode is now optional.

Resource SecretManagerSecret(v1beta1):

  • Added spec.replication.auto field.

Resource SecretManagerSecretVersion(v1beta1):

  • Added spec.deletionPolicy field.

Resource StorageBucket(v1beta1):

  • spec.autoclass.enabled is now mutable.

Resource VertexAIIndexEndpoint(v1alpha1):

  • Added spec.publicEndpointEnabled field.
  • Added status.publicEndpointDomainName field.
Dataplex

Dataplex is available in the following regions:

  • Delhi (asia-south2)
  • Melbourne (australia-southeast2)
  • Toronto (northamerica-northeast2)

For more information, see Locations and Pricing.

Dialogflow

Dialogflow CX launched two new integrations in preview:

Google Kubernetes Engine

This is a follow-up message to the release note regarding blue-green upgrades from September 18, 2023. You can now resume upgrading clusters with the blue-green upgrade strategy as the issue with rollback functionality has been fixed. GKE is no longer blocking automatic upgrades due to this issue.

Security Command Center

containsOnly() function released to General Availability.

You can now use the containsOnly() function to query findings with an array-type attribute or subfield that only contains values that match the specified filter, and no other values.

For more information, see The containsOnly function.

Vertex AI Search and Conversation

Vertex AI Search (Enterprise Search): Customer-managed encryption key integration

Customer-managed encryption keys (CMEK) is available as an allowlisted preview feature.

If you store your data in a US multi-region data store, you can provide your own encryption key to protect your data at rest.

For information, see Customer-managed encryption keys.

Vertex AI Search (Enterprise Search): Search tuning

Search tuning is available as an allowlisted preview feature. You provide additional training data in the form of query and segment pairs. We use this data to tune the model for your app.

For information, see Improve search results with search tuning.

Vertex AI Search (Enterprise Search): VPC Service Controls are GA

Virtual Private Cloud Service Controls support for Enterprise Search is generally available (GA).

For more information, see Supported products and limitations in the VPC Service Controls documentation. For general information about VPC Service Controls, see Overview of VPC Service Controls.

Vertex AI Search (Enterprise Search): Data location

Vertex AI Search may be configured for data location pursuant to the "Data Location" section of the Service Specific Terms.

For information about data residency in Vertex AI Search, see Enterprise Search locations.

Vertex AI Search (Enterprise Search): Support for Access Transparency

Access Transparency supports Vertex AI Search in preview.

For more information, see Enable Access Transparency in Enterprise Search.

Vertex AI Search (Enterprise Search): Citations for search with follow-ups

Citations indicate from which search results specific sentences in the summary are taken.

For more information, see Configure the summary.

Vertex AI Search (Enterprise Search): Ignore adversarial queries and non-summary seeking queries for search with follow-ups

Ignore adversarial queries can stop generation of summaries that are unsafe or violate policy.

Non-summary seeking queries stop generation of summaries that aren't helpful for some queries.

For more information, see Configure the summary.

Vertex AI Search (Enterprise Search): Additional languages supported

Search, snippets, and other features are now supported in the following languages:

  • Arabic
  • Chinese (Simplified)
  • Greek
  • Hebrew
  • Japanese
  • Korean
  • Polish
  • Russian

See Languages.

Virtual Private Cloud

Private Service Connect backends support using an external regional TCP proxy load balancer or an internal regional TCP proxy load balancer to access published services. These features are available in General Availability.

September 28, 2023

AlloyDB for PostgreSQL

AlloyDB secondary clusters now support read pool instances.

Assured Workloads

The IL2 compliance program is now generally available. For a list of IL2-compliant Google Cloud products, see the Supported products page.

BigQuery

The following BigQuery ML point-in-time lookup functions are now in preview. These functions let you specify a point-in-time cutoff when retrieving features for training a model or running inference, in order to avoid data leakage.

You can now use IAM conditions to control access to BigQuery resources. This feature is in preview.

Certificate Manager

Certificate Manager supports Mutual TLS (mTLS) authentication. This feature is generally available (GA).

Cloud Monitoring

You can now configure your alerting policy documentation with custom subject lines. For more information, see Configure the subject line of notifications.

Cloud SQL for PostgreSQL

The following pg_wait_sampling and rdkit flags are generally available:

pg_wait_sampling flags

  • cloudsql.enable_pg_wait_sampling: enable the pg_wait_sampling extension for Cloud SQL for PostgreSQL instances.
  • pg_wait_sampling.history_size: set the size of the in-memory ring buffer for history sampling, in terms of the number of samples.
  • pg_wait_sampling.history_period: set the time interval for history sampling, in milliseconds.
  • pg_wait_sampling.profile_period: set the time interval for profile sampling for wait events, in milliseconds.
  • pg_wait_sampling.profile_pid: specify whether the wait profile that accumulates samples for each process and waits event is collected for each process or for all processes.
  • pg_wait_sampling.profile_queries: specify whether the wait profile is collected for each query or for all queries.

rdkit flags

  • rdkit.tanimoto_threshold: set the threshold value for the Tanimoto similarity operator.
  • rdkit.dice_threshold: set the threshold value for the Dice similarity operator.
  • rdkit.do_chiral_sss: specify whether stereochemistry is used in substructure matching.
  • rdkit.do_enhanced_stereo_sss: specify whether enhanced stereo is used in substructure matching.
  • rdkit.sss_fp_size: set the size of the fingerprint used for substructure screening, in bits.
  • rdkit.morgan_fp_size: set the size of morgan fingerprints, in bits.
  • rdkit.featmorgan_fp_size: set the size of featmorgan fingerprints, in bits.
  • rdkit.layered_fp_size: set the size of layered fingerprints, in bits.
  • rdkit.rdkit_fp_size: set the size of rdkit fingerprints, in bits.
  • rdkit.hashed_torsion_fp_size: set the size of topological torsion bit vector fingerprints, in bits.
  • rdkit.hashed_atompair_fp_size: set the size of atom pair bit vector fingerprints, in bits.
  • rdkit.reaction_sss_fp_size: set the size of the structural chemical reaction fingerprint, in bits.
  • rdkit.reaction_difference_fp_size: set the size of the difference chemical reaction fingerprint, in bits.
  • rdkit.reaction_sss_fp_type: specify the type of structural chemical reaction fingerprint.
  • rdkit.reaction_difference_fp_type: specify the type of difference chemical reaction fingerprint.
  • rdkit.ignore_reaction_agents: specify whether agents of a chemical reaction are taken into account.
  • rdkit.agent_FP_bit_ratio: specify the weight of the impact of agents contained in a chemical reaction fingerprint.
  • rdkit.move_unmmapped_reactants_to_agents: specify whether unmapped reactant agents of a chemical reaction are taken into account.
  • rdkit.threshold_unmapped_reactant_atoms: set the ratio of allowed unmapped reactant atoms.
  • rdkit.init_reaction: specify whether the reaction is ready for use.
  • rdkit.difference_FP_weight_agents: specify the weight factor for agents compared to reactants and products in reaction difference fingerprints.
  • rdkit.difference_FP_weight_nonagents: specify the weight factor for reactants and products compared to agents in reaction difference fingerprints.
  • rdkit.avalon_fp_size: set the size of avalon fingerprints, in bits.
Cloud Storage

Beginning Oct 30, 2023, Cloud Storage will change how it enforces egress bandwidth quotas.

  • Instead of using the same default value for all projects, egress bandwidth quotas will depend on each project's history, such whether the billing account is in good standing.
  • For most projects, egress bandwidth quotas will either remain unchanged or will increase.
  • Once this change takes effect, you can view your project's egress bandwidth quotas in the Console.
Dataproc

New Dataproc on Compute Engine subminor image versions:

  • 2.0.78-debian10, 2.0.78-rocky8, 2.0.78-ubuntu18
  • 2.1.26-debian11, 2.1.26-rocky8, 2.1.26-ubuntu20, 2.1.26-ubuntu20-arm

Upgraded the Cloud Storage connector version to 2.2.17 in the latest 2.0 and 2.1 Dataproc on Compute Engine image versions.

Upgraded Hive version from 3.1.2 to 3.1.3 in the latest Dataproc on Compute Engine 2.0 image version.

Google Cloud Architecture Center

(New guide) Design secure deployment pipelines: Best practices for designing secure deployment pipelines based on your confidentiality, integrity, and availability requirements.

Google Cloud Deploy

When you create a release using the gcloud CLI version 445, 446, or 447, you might encounter an error where gcloud requires the clouddeploy.config.get permission. To fix this issue, upgrade to gcloud CLI version 448 or greater.

Policy Intelligence

After January 15, 2024, some Policy Intelligence features will only be available for customers with organization-level activations of Security Command Center. For more information, see Billing questions.

Using Policy Troubleshooter to troubleshoot deny policies is generally available.

SAP on Google Cloud

SAP HANA Fast Restart enabled using Terraform

SAP HANA Fast Restart is enabled when you deploy SAP HANA on Google Cloud using the sap_hana or sap_hana_ha Terraform module, version 202309280828 or later. The fast restart option is enabled through the enable_fast_restart Terraform argument, which by default is set to true.

For more information, see the deployment guide for your SAP HANA scenario.

VPC Service Controls

Preview stage supported for the following integration: