The following release notes cover the most recent changes over the last 60 days. For a comprehensive list of product-specific release notes, see the individual product release note pages.
You can also see and filter all release notes in the Google Cloud console or you can programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your
feed
reader, or add the feed URL directly: https://cloud.google.com/feeds/gcp-release-notes.xml
November 23, 2023
Application IntegrationHubSpot trigger is now available in preview.
Release 6.2.40 is now in General Availability.
November 22, 2023
AlloyDB for PostgreSQLVersion 1.5.0 of the AlloyDB Auth Proxy client might fail to connect to AlloyDB instances created before mid-November, 2023.
To mitigate this issue, take either one of the following steps:
Use version 1.4.1 of the AlloyDB Auth Proxy client. You can download this version by following the instructions on Download the Auth Proxy client, replacing
1.5.0
orlatest
in the commands with1.4.1
.Update any database flag on the affected instance. We recommend using the Google Cloud console to set and then clear a flag that doesn't require the instance to restart, such as
autovacuum
. For a full list of flags, see Supported database flags.
A vulnerability (CVE-2023-5717) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.
For more information, see the GCP-2023-046 security bulletin.
Release 6.2.41 is currently in Preview.
Jobs enhancement
The following features have been added:
- Ability to sort the job execution table by time or status
- Indication in the jobs queue for each failed job iteration
IDE's Live Autocomplete feature not working properly (ID #00250083)
Confidential Space: You can now use the Split-Trust Encryption Tool (STET) with Confidential Space.
Datastream now supports SSL/TLS encryption for connections to PostgreSQL sources that don't require client certificates.
A vulnerability (CVE-2023-5717) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.
GKE clusters are impacted.
For more information, see the GCP-2023-046 security bulletin.
November 21, 2023
Anthos clusters on bare metalRelease 1.14.11
Anthos clusters on bare metal 1.14.11 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.14.11 runs on Kubernetes 1.25.
Fixes:
The following container image security vulnerabilities have been fixed in 1.14.11:
Critical container vulnerabilities:
High-severity container vulnerabilities:
Medium-severity container vulnerabilities:
Low-severity container vulnerabilities:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
The following Connector Event triggers are available in preview:
Backup and DR Service 11.0.8.454 is now available to update your backup/recovery appliance. Refer to these instructions to update your appliance.
SAP HANA databases running in Compute Engine instances can now be backed up as Persistent Disk snapshots of the Compute Engine instance. This feature is in Private Preview.
Added basic connector support for the following OSes. See Support matrix.
- OEL 8.8, 9.1, and 9.2
- RHEL 8.8 and 9.2
- RHEL for SAP 8.8, 9.0, and 9.2
- Rocky Linux 8.8, 9.0, 9.1, and 9.2
- Rocky Linux Optimised for Google Cloud 8.8 and 9.2
- SLES 15 SP5
- SLES for SAP 15 SP5
Between January, 2024 and April, 2024 newly created Cloud Composer 2 environments will start using Python 3.11. After this change, Python 3.8 will no longer be available in new versions of Cloud Composer. If you upgrade an existing Cloud Composer 2 environment, the Python version will change to Python 3.11 as well.
The timing for Python 3.11 availability will be announced in January, 2024.
For BigQuery inspection jobs, when you set a sampling limit based on a percentage of the total number of table
rows
(rowsLimitPercent
),
Sensitive Data Protection can inspect more rows than expected. If you need to
put a hard limit on the number of rows to scan, we recommend setting a maximum
number of rows
(rowsLimit
)
instead.
Cloud Spanner emulator support for the PostgreSQL dialect is now generally available. To learn more about the emulator, see Emulate Cloud Spanner locally.
The Object Retention Lock feature is now available.
Using this feature, you can place a retention configuration on individual objects.
A retention configuration defines a date prior to which the object cannot be deleted or overwritten.
A retention configuration can optionally be locked to prevent the retention date from being shortened or removed.
Network edge security polices (custom rules) are now available to allowlisted users. For more information about network edge policies, see Types of security policies. In addition, you can learn how to Configure network edge security policies.
Preview stage supported for the following integration:
November 20, 2023
Anthos clusters on VMwareAnthos clusters on VMware 1.14.10-gke.35 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.14.8-gke.37 runs on Kubernetes v1.25.13-gke.200.
The following issues are fixed in 1.14.10-gke.35:
- Fixed the etcd hostname mismatch issue when using FQDN
- Fixed the issue where deleting a user cluster with a volume attached stalls, in which case the cluster can't be deleted and can't be used.
The following vulnerabilities are fixed in 1.14.10-gke.35:
High-severity container vulnerabilities:
Container-optimized OS vulnerabilities:
Ubuntu vulnerabilities:
Release 1.15.7
Anthos clusters on bare metal 1.15.7 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.15.7 runs on Kubernetes 1.26.
Fixed an issue where CoreDNS Pods can get stuck in an unready state.
The following container image security vulnerabilities have been fixed in 1.15.7:
Critical container vulnerabilities:
High-severity container vulnerabilities:
Medium-severity container vulnerabilities:
Low-severity container vulnerabilities:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
The following resource types are now publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, Feed and Search (SearchAllResources, SearchAllIamPolicies) APIs.
- Financial Services
financialservices.googleapis.com/Dataset
financialservices.googleapis.com/BacktestResult
financialservices.googleapis.com/EngineConfig
financialservices.googleapis.com/Model
financialservices.googleapis.com/PredictionResult
Regional endpoints are now available in Preview. Regional endpoints let you run your workloads in a manner that complies with data residency and data sovereignty requirements, where your request traffic is routed directly to the region specified in the endpoint.
Confidential Space. Support for VPC Service Controls is released to General Availability.
You can now protect Confidential Space using VPC Service Controls perimeters. For more information, see VPC Service Controls supported products.
Cloud Storage Backint agent for SAP HANA version 1.0.32
Version 1.0.32 of the Cloud Storage Backint agent for SAP HANA is available. This version updates the JRE to the latest SAP JRE 21.0.1.
For more information about the agent, see Cloud Storage Backint agent for SAP HANA overview.
General availability support for the following integration:
You can use Private Service Connect backends to access published services that are hosted on regional internal Application Load Balancers and regional internal proxy Network Load Balancers.
November 17, 2023
Apigee hybridOn November 17, 2023 we released an updated version of the Apigee hybrid software, v1.11.0.
- For information on upgrading, see Upgrading Apigee hybrid to version v1.11.0.
- For information on new installations, see The big picture.
Helm charts management for Apigee hybrid
Starting in version v1.11.0, you have the choice of installing and managing your clusters with either Helm or apigeectl
. You cannot manage a cluster with both. Apigee recommends using Helm for new hybrid installations. See Apigee hybrid Helm charts reference.
Vault integration for Cassandra credentials (preview)
Starting in version v1.11.0, you can store Cassandra credentials in Hashicorp Vault.
Note: Using Vault requires Helm management of your Apigee installation.
See Storing Cassandra credentials in Hashicorp Vault.
Vault integration is in preview as of the Apigee hybrid 1.11.0 release.
Apigee Advance API Security Actions for Apigee hybrid
Advanced API Security's new Security Actions feature is now available in Apigee hybrid.
Bug ID | Description |
---|---|
295929616 | Installation of Hybrid 1.10.x would fail on OpenShift due to out of memory issues. (Fixed in Apigee hybrid v1.10.3) |
294069799 | Updated the security context settings for the Apigee Hybrid Backup and Restore pod. |
292571089 | An error with support for CSI backup and restore for Cassandra was fixed. (Fixed in Apigee hybrid v1.10.3) |
292118812 | Fixed UDCA regression in Hybrid 1.10.1 where UDCA would ignore forward proxy configuration. (Fixed in Apigee hybrid v1.10.2) |
289254725 | Implemented a fix to prevent failure of proxy deployments that include the OASValidation policy. (Fixed in Apigee hybrid v1.10.1) |
287321226 | Security context has been corrected for apigee-prom-prometheus to avoid privilege escalation. (Fixed in Apigee hybrid v1.10.3) |
240180122 | Disable privilege escalation on the cassandra container by moving the ulimit settings to the newly introduced initContainer "apigee-cassandra-ulimit-init". If you are using security controls with gatekeeper, ensure that apigee-cassandra-ulimit-init initContainer can runAs user, group as 0 and allow capabilities IPC_LOCK and SYS_RESOURCES. (Fixed in Apigee hybrid v1.11.0) |
205666368 | Fixed issue with default validation of TLS target endpoint certificates. To enable strict SSL on southbound connections to a proxy target endpoint, add the tag See About setting TLS options in a target endpoint or target server. See also Known Issue #205666368. (Fixed in Apigee hybrid v1.10.3-hotfix.1) |
158132963 | Added improvements to capture relevant target flow variables in trace and analytics in case of target timeouts. (Fixed in Apigee hybrid v1.10.2) |
Bug ID | Description |
---|---|
303292806 | Set backup utility to only connect to Cassandra server pods in the apigee namespace. (Fixed in Apigee hybrid v1.10.3-hotfix.3) |
300542690 | Added dedicated service accounts for Apigee Connect, Redis, and UDCA to prevent Kubernetes from automatically injecting credentials for a specified ServiceAccount or the default ServiceAccount. (Fixed in Apigee hybrid v1.10.3-hotfix.3) |
297938600, 297938559, 297938486, 294892344 |
Security fixes for apigee-diagnostics-collector . (Fixed in Apigee hybrid v1.10.3) This addresses the following vulnerabilities: |
297938498, 297938487 |
Security fixes for apigee-fluent-bit .(Fixed in Apigee hybrid v1.10.3) This addresses the following vulnerabilities: |
297938441 | Security fixes for apigee-runtime . (Fixed in Apigee hybrid v1.10.3) This addresses the following vulnerabilities: |
297286274 | Security fixes for apigee-installer . (Fixed in Apigee hybrid v1.10.3) This addresses the following vulnerabilities: |
296719459, 296719400, 296719348, 296719307, 296719306, 296719188, 296719187, 296719186, 296719115, 296719018, 296718937, 296718918, 296718917, 296718916, 296716670, 296716669, 296716472, 296716471, 296715155 |
Security fixes for apigee-hybrid-cassandra . (Fixed in Apigee hybrid v1.10.3) This addresses the following vulnerabilities: |
296717666, 296717283, 296716668, 296716667, 296716650, 296716635, 296716634, 296716633, 296716470, 296716234, 296715734, 296715733, 296715154, 296715153 |
Security fixes for apigee-hybrid-cassandra-client . (Fixed in Apigee hybrid v1.10.3) This addresses the following vulnerabilities: |
296717665, 296717664, 296717663, 296717662, 296717185, 296716666, 296716649, 296716632, 296716468, 296716467, 296716232, 296715152, 296715151, 296714218 |
Security fixes for apigee-cassandra-backup-utility . (Fixed in Apigee hybrid v1.10.3) This addresses the following vulnerabilities: |
295936113 | Security fixes for apigee-mart-server . (Fixed in Apigee hybrid v1.10.3) This addresses the following vulnerability: |
294906706 | Security fixes for apigee-prom-prometheus . (Fixed in Apigee hybrid v1.10.3) This addresses the following vulnerabilities:
|
293925856 | Security fixes for apigee-prometheus-adapter . (Fixed in Apigee hybrid v1.10.3) This addresses the following vulnerabilities: |
293348130 | Security fixes for apigee-udca . (Fixed in Apigee hybrid v1.10.2) This addresses the following vulnerabilities: |
291994501 | Security fixes for apigee-operator and apigee-watcher . (Fixed in Apigee hybrid v1.10.2) This addresses the following vulnerabilities: |
291994501 | Security fixes for apigee-installer . (Fixed in Apigee hybrid v1.10.2) This addresses the following vulnerabilities:
|
290829031 | Security fixes for apigee-hybrid-cassandra , apigee-cassandra-client , and cassandra-backup-utility . (Fixed in Apigee hybrid v1.10.2) This addresses the following vulnerabilities: |
290829028 | Security fixes for Apigee Connect and apigee-connect-agent and apigee-redis . (Fixed in Apigee hybrid v1.10.2) This addresses the following vulnerabilities: |
290068742 | Security fixes for apigee-udca . (Fixed in Apigee hybrid v1.10.1) This addresses the following vulnerability: |
290067464 | Security fixes for apigee-stackdriver-logging-agent . (Fixed in Apigee hybrid v1.10.1) This addresses the following vulnerability: |
290065830 | Security fixes for apigee-udca . (Fixed in Apigee hybrid v1.10.1) This addresses the following vulnerability: |
281561243 | Security fixes for apigee-diagnostics-collector , apigee-mart-server , apigee-mint-task-scheduler , apigee-runtime , and apigee-synchronizer . This addresses the following vulnerability: (Fixed in Apigee hybrid v1.10.1) |
N/A | Security fixes for apigee-prometheus-adapter . (Fixed in Apigee hybrid hybrid v1.11) This addresses the following vulnerabilities: |
N/A | Security fixes for apigee-prom-prometheus/master . (Fixed in Apigee hybrid hybrid v1.11) This addresses the following vulnerabilities: |
N/A | Security fixes for apigee-kube-rbac-proxy . (Fixed in Apigee hybrid hybrid v1.11) This addresses the following vulnerabilities: |
N/A | Security fixes for apigee-hybrid-cassandra . (Fixed in Apigee hybrid hybrid v1.11) This addresses the following vulnerabilities: |
N/A | Security fixes for apigee-fluent-bit . (Fixed in Apigee hybrid hybrid v1.11) This addresses the following vulnerabilities: |
N/A | Security fixes for apigee-diagnostics-collector , apigee-mart-server , apigee-mint-task-scheduler , apigee-runtime , and apigee-synchronizer . (Fixed in Apigee hybrid hybrid v1.11) This addresses the following vulnerabilities: |
N/A | Security fixes for apigee-cassandra-backup-utility , apigee-hybrid-cassandra-client , and apigee-connect-agent . (Fixed in Apigee hybrid v1.11) This addresses the following vulnerabilities: |
N/A | Security fixes for apigee-asm-ingress and apigee-asm-istiod . (Fixed in Apigee hybrid v1.11) This addresses the following vulnerabilities: |
App Hub is available in Preview.
Starting December 1, 2023, in the europe-central2, northamerica-northeast1, us-west1, and us-west2 regions it will be possible to create new Cloud Composer 1 environments only in projects that already have Cloud Composer 1 environments.
In all other existing or newly created projects in these regions, it will be possible to create only Cloud Composer 2 environments. This change is a part of the preparation for Cloud Composer 1 end of support, as communicated earlier and described in the Versioning overview.
Observability for Google Kubernetes Engine: The Observability tab for a GKE cluster adds a dashboard for GPU metrics. The charts on this dashboard are populated only if the cluster has GPU nodes. For more information, see View observability metrics.
For services with cold start times exceeding 10 seconds, requests are now queued for at least the cold start time before timing out while waiting for instances to start.
The demote API is now available. This API demotes an existing standalone instance to be a Cloud SQL read replica for an external database server.
Cloud SQL for MySQL now supports minor version 8.0.35. To upgrade your existing instance to the new version, see Upgrade the database minor version.
The demote API is now available. This API demotes an existing standalone instance to be a Cloud SQL read replica for an external database server.
Dataflow supports NVIDIA® L4 and NVIDIA® A100 80 GB GPU types. For more information, see Dataflow support for GPUs.
New Dataproc on Compute Engine subminor image versions:
- 2.0.84-debian10, 2.0.84-rocky8, 2.0.84-ubuntu18
- 2.1.32-debian11, 2.1.32-rocky8, 2.1.32-ubuntu20, 2.1.32-ubuntu20-arm
Upgraded the Cloud Storage connector version to 2.2.18 in the latest 2.0 and 2.1 Dataproc on Compute Engine image versions.
In the Flink component in the latest Dataproc on Compute Engine 2.1 image version, added the following java-storage client properties:
gs.retry.max.attempts
property to set the max number of retry attemptsgs.retry.total.timeout
property to set the total retry timeout
Fixed a regression in the Zeppelin websocket rules that caused a websocket error in Zeppelin notebooks.
The Python kernel does not work in Zeppelin on the Dataproc on Compute Engine 2.1 image version. Other kernels are not impacted.
The Zeppelin REST API does not work (drops query parameters) on Dataproc on Compute Engine 2.0 and 2.1 image versions via the Component Gateway. Other Zeppelin interactions can also break as a result of dropped query parameters.
You can now run workloads on L4 GPUs in Autopilot clusters that use GKE version 1.28.3-gke.1203000 and later. For instructions, see Deploy GPU workloads in Autopilot.
(2023-R24) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- The following control plane and node versions are now available:
- The following control plane versions are no longer available:
- 1.24.17-gke.2198000
- 1.24.17-gke.2211000
- 1.25.15-gke.1033000
- 1.25.15-gke.1049000
- 1.26.10-gke.1024000
- 1.26.10-gke.1038000
- 1.27.7-gke.1038000
- 1.27.7-gke.1056000
Stable channel
- There are no new releases in the Stable release channel.
Regular channel
- There are no new releases in the Regular release channel.
Rapid channel
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.24.17-gke.2198000
- 1.24.17-gke.2211000
- 1.25.15-gke.1033000
- 1.25.15-gke.1049000
- 1.26.10-gke.1024000
- 1.26.10-gke.1038000
- 1.27.7-gke.1038000
- 1.27.7-gke.1056000
- 1.28.3-gke.1098000
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.17-gke.2230000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.15-gke.1115000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.26.10-gke.1073000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.10-gke.1073000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.28 to version 1.28.3-gke.1118000 with this release.
(2023-R24) Version updates
- The following control plane and node versions are now available:
- The following control plane versions are no longer available:
- 1.24.17-gke.2198000
- 1.24.17-gke.2211000
- 1.25.15-gke.1033000
- 1.25.15-gke.1049000
- 1.26.10-gke.1024000
- 1.26.10-gke.1038000
- 1.27.7-gke.1038000
- 1.27.7-gke.1056000
(2023-R24) Version updates
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.24.17-gke.2198000
- 1.24.17-gke.2211000
- 1.25.15-gke.1033000
- 1.25.15-gke.1049000
- 1.26.10-gke.1024000
- 1.26.10-gke.1038000
- 1.27.7-gke.1038000
- 1.27.7-gke.1056000
- 1.28.3-gke.1098000
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.17-gke.2230000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.15-gke.1115000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.26.10-gke.1073000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.10-gke.1073000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.28 to version 1.28.3-gke.1118000 with this release.
(2023-R24) Version updates
- There are no new releases in the Stable release channel.
(2023-R24) Version updates
- There are no new releases in the Regular release channel.
Vertex AI Feature Store
The following features of the new and improved Vertex AI Feature Store are now generally available (GA):
Feature Registry: Register your feature data sources in BigQuery by creating feature groups and features. For more information, see Create a feature group and Create a feature.
Cloud Bigtable online serving: Serve features from one or more BigQuery data sources. You can set up Cloud Bigtable online serving by defining online serving clusters called online store instances and creating feature views within the online store instances.
Note that the following features of Vertex AI Feature Store are still in Preview:
- Serve features at ultra-low latencies with Optimized online serving.
- Sync data in a feature view within an online store.
- Retrieve vector embeddings for real-time serving.
For more information, see About Vertex AI Feature Store.
Support for a Kubernetes API connector is available in Preview. The connector allows you to interact with Kubernetes objects in a Google Kubernetes Engine cluster. For more information, see Access Kubernetes API objects using a connector.
November 16, 2023
Anthos clusters on VMwareAnthos clusters on VMware 1.16.3-gke.45 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.16.1-gke.44 runs on Kubernetes 1.27.4-gke.1600.
The Prometheus and Grafana add-ons field, loadBalancer.vips.addonsVIP
, is
deprecated. This change is because
Google Managed Service for Prometheus
replaced the Prometheus and Grafana add-ons.
The following issues are fixed in 1.16.3-gke.45:
- Fixed a Cilium issue causing egress NAT to erroneously break long-lived connections.
- Fixed the etcd hostname mismatch issue when using a FQDN.
- Fixed the known issue that caused admin cluster updates or upgrades to fail if the projects or locations of add-on services don't match each other.
- Fixed the issue that external cluster snapshot won't be taken after
gkectl update admin
fails. - Fixed an issue that caused the CSI workload preflight to fail when Istio is enabled.
- Fixed the issue that deleting a user cluster with a volume attached may be stuck forever.
- Fixed the known issue that caused user cluster deletion to fail when using a user-managed admin workstation.
The following vulnerabilities are fixed in 1.16.3-gke.45:
Critical container vulnerabilities:
High-severity container vulnerabilities:
Container-optimized OS vulnerabilities:
Ubuntu vulnerabilities:
Windows vulnerabilities:
The IL4 compliance program now supports the following products. See Supported products for more information:
- Cloud DNS
- Cloud Interconnect
- Cloud Monitoring
- Cloud Router
- Cloud SQL
- Cloud VPN
- Pub/Sub
The following BigQuery ML features for Vertex AI large language models (LLMs) are now generally available (GA):
The SQL syntax for remote models has been updated to provide access to all text generation and text embedding LLMs (for example,
text-bison-32k
andtextembedding-gecko-multilingual
) and also to provide support for different LLM versions.Region support for
text-bison*
LLM models has been expanded to include the following locations in addition tous
andus-central1
:asia-northeast3
asia-southeast1
eu
europe-west1
europe-west2
europe-west3
europe-west4
europe-west9
us-west4
Release 6.2.40 is currently in Preview.
Playbook actions carried out by automation are not labeled as such on the case wall (ID #47525692).
This bug fix is in Preview.
Case title is not picking up information if it's in square brackets (ID #00262914).
This bug fix is in Preview.
Cloud Spanner now supports automatic cleanup of long running transactions (in Preview). To enable this feature, use the Java or Go client library to automatically remove long running transactions that might cause session leaks and receive warning logs about problematic transactions. For more information, see Automatic cleanup of session leaks.
Cloud Spanner now supports Hibernate ORM 6.3 in GoogleSQL Hibernate dialect. For more information, see Integrate Spanner with Hibernate ORM (GoogleSQL dialect).
Dataform is compliant with VPAT.
For more information, see Dataform compliance.
M113 release
- Miscellaneous bug fixes and improvements in Python 3.10 container images.
M113 release
- Miscellaneous bug fixes and improvements in Python 3.10 images.
Parallel file systems for HPC workloads: Added Sycomp Storage Fueled by IBM Spectrum Scale as an option for parallel file system (PFS) storage, and replaced NetApp Cloud Volumes Service with Google Cloud NetApp Volumes.
You can now configure alerts for Cloud Deploy release render failures.
The Advanced Data Networking (ADN) traffic is accounted only for large-sized flows (approximately >20 Kbps) that cross VPC boundaries. Currently, small-sized flows are not accounted.
M113 release
The M113 release of Vertex AI Workbench instances includes the following:
- Added the Dataproc JupyterLab plugin to Vertex AI Workbench instances. To get started, see Create a Dataproc-enabled instance.
- When using an instance's Google Cloud CLI,
gcloud config
is preset with the following defaults:project
is set to your instance's project.- Your compute region is set to your instance's region.
- Your Dataproc region is set to your instance's region.
- Fixed an issue that prevented Dataproc kernels from working.
- Fixed a CORS (cross-origin resource sharing) error.
The M113 release of Vertex AI Workbench user-managed notebooks includes the following:
- Miscellaneous bug fixes and improvements in Python 3.10 notebooks.
November 15, 2023
AlloyDB for PostgreSQLIAM authentication for AlloyDB is generally available (GA).
You can now restrict an OAuth 2.0 access token so that it works only for AlloyDB authentication.
You can now configure the AlloyDB Auth Proxy to automatically authenticate IAM-based database logins. This works only with the IAM account that you use to run the proxy client.
AlloyDB Omni version 15.2.2 is available. This version resolves the previous version's issue with incremental backups, and contains various other bug fixes and improvements. For more information about upgrading AlloyDB Omni, see Upgrade AlloyDB Omni.
The AlloyDB Omni Kubernetes Operator version 0.2.0 is available in Preview. This update adds support for AlloyDB Omni version 15.2.2, and includes various bug fixes and improvements. For more information about upgrading AlloyDB using the Kubernetes operator, see Upgrade AlloyDB Omni.
The following supported default parsers have changed. Each is listed by product name and log_type
value, if applicable.
- Abnormal Security (
ABNORMAL_SECURITY
) - Akamai Enterprise Application Access (
AKAMAI_EAA
) - Atlassian Confluence (
ATLASSIAN_CONFLUENCE
) - Atlassian Jira (
ATLASSIAN_JIRA
) - AWS Aurora (
AWS_AURORA
) - AWS Cloudtrail (
AWS_CLOUDTRAIL
) - Bitwarden Events (
BITWARDEN_EVENTS
) - Check Point Harmony (
CHECKPOINT_HARMONY
) - Cisco Router (
CISCO_ROUTER
) - Cisco Switch (
CISCO_SWITCH
) - Cisco Umbrella DNS (
UMBRELLA_DNS
) - Cloud Audit Logs (
N/A
) - Dell Switch (
DELL_SWITCH
) - Elastic Search (
ELASTIC_SEARCH
) - Elastic Windows Event Log Beats (
ELASTIC_WINLOGBEAT
) - F5 ASM (
F5_ASM
) - FireEye (
FIREEYE_ALERT
) - Firewall Rule Logging (
N/A
) - IBM DataPower Gateway (
IBM_DATAPOWER
) - Infoblox (
INFOBLOX
) - Jamf Protect Alerts (
JAMF_PROTECT
) - Juniper (
JUNIPER_FIREWALL
) - Lacework Cloud Security (
LACEWORK
) - Linux Sysmon (
LINUX_SYSMON
) - Medigate IoT (
MEDIGATE_IOT
) - Microsoft Sentinel (
MICROSOFT_SENTINEL
) - Netskope (
NETSKOPE_ALERT
) - Openpath (
OPENPATH
) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR
) - Proofpoint Observeit (
OBSERVEIT
) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND
) - Pulse Secure (
PULSE_SECURE_VPN
) - Pulse Secure Virtual Traffic Manager (
PULSE_SECURE_VTM
) - SentinelOne EDR (
SENTINEL_EDR
) - Sophos Firewall (Next Gen) (
SOPHOS_FIREWALL
) - SpyCloud (
SPYCLOUD
) - Stealthbits Defend (
STEALTHBITS_DEFEND
) - Stealthbits PAM (
STEALTHBITS_PAM
) - STIX Threat Intelligence (
STIX
) - Symantec Endpoint Protection (
SEP
) - Symantec Event export (
SYMANTEC_EVENT_EXPORT
) - Tenable Active Directory Security (
TENABLE_ADS
) - Unix system (
NIX_SYSTEM
) - VMware vCenter (
VMWARE_VCENTER
) - Windows Event (XML) (
WINEVTLOG_XML
) - Zscaler (
ZSCALER_WEBPROXY
)
The following log types, without a default parser, were added. Each is listed by product name and log_type
value, if applicable.
- Aruba Orchestrator (
ARUBA_ORCHESTRATOR
) - AWS Shield (
AWS_SHIELD
) - Azure DNS logs (
AZURE_DNS
) - Backbox (
BACKBOX
) - Bitvise SSHd (
BITVISE_SSHD
) - Cylera IOT (
CYLERA_IOT
) - Druva Backup (
DRUVA_BACKUP
) - Ensono Cloud Mainframe Solution (
ENSONO
) - xtreme Networks ExtremeControl NAC Solution (
EXTREME_CONTROL
) - EzProxy (
EZPROXY
) - Github Events (
GITHUB_EVENTS
) - Glean (
GLEAN
) - ISM Xtraction (
IVANTI_XTRACTION
) - Lira (
LIRA
) - LogonBox (
LOGONBOX
) - Mandiant Custom IOC (
MANDIANT_CUSTOM_IOC
) - Monday (
MONDAY
) - Onapsis (
ONAPSIS
) - Opentelemetry (
OPENTELEMETRY
) - Opswat Kiosk (
OPSWAT_KIOSK
) - Outpost24 (
OUTPOST24
) - Pentera Leef (
PENTERA_LEEF
) - Phishlabs (
PHISHLABS
) - Portnix Audit (
PORTNOX_AUDIT
) - Portnix CEF (
PORTNOX_CEF
) - Proofpoint Sendmail Sentrion (
PROOFPOINT_SENDMAIL_SENTRION
) - SAP SM20 (
SAP_SM20
) - Splunk Attack Analyzer (
SPLUNK_ATTACK_ANALYZER
) - Stellar Cyber (
STELLAR_CYBER
) - Talon (
TALON
) - Teradici PCoIP (
TERADICI_PCOIP
) - TrendMicro Apex Central (
TRENDMICRO_APEX_CENTRAL
) - TrendMicro Webproxy DSM (
TRENDMICRO_WEBPROXY_DSM
) - Vonage (
VONAGE
) - Waterfall Data Security Manager (
WATERFALL_DSM
) - Ysoft Data Security Manager (
YSOFT_DSM
) - Zscaler Client Connector (
ZSCALER_ZCC
) - Zscaler ZDX (
ZSCALER_ZDX
)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
Release 6.2.39 is now in General Availability.
All Cloud Composer environment's GKE clusters are set up with maintenance exclusions for the following periods:
- From November 20, 2023 to November 29, 2023 (already configured)
- From December 20, 2023 to January 2, 2024 (will be configured in December)
For more information, see Maintenance exclusions.
A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.
Cloud SQL supports the bulk insert functionality of SQL Server for importing data. This functionality is supported only on SQL Server 2022.
For more information, see Use bulk insert for importing data.
Cloud Spanner now provides an integration workflow with Vertex AI Vector Search to enable vector similarity search on data stored in Spanner. For more information, see Export embeddings from Spanner to Vector Search.
You can use CMEK (Customer Managed Encrytion Keys) with encrypted Dataproc cluster data, incuding persistent disk data, job arguments and queries submitted with Dataproc jobs, and cluster data saved in the cluster Dataproc staging bucket. See Use CMEK with cluster data for more information.
Eventarc is available in the me-central2
(Dammam, Kingdom of Saudi Arabia) region.
Dynamic Workload Scheduler support on GKE through the Provisioning Request API launched in Preview in version 1.28. Use the Dynamic Workload Scheduler to get large atomic sets of available GPU models in GKE Standard clusters. For more information, see Deploy GPUs for batch workloads with ProvisioningRequest.
Vertex AI Search: Autocomplete denylist (Preview with allowlist)
Importing an autocomplete denylist is available as a preview with allowlist feature. To use this feature, contact your Google account team.
For information about autocomplete denylists, see Use an autocomplete denylist.
Batch video and image support in Vertex AI Vision Warehouse is Generally Available. Vertex AI Vision Warehouse now supports semantic searches and similarity searches on video and images. For more information, see Vision Warehouse overview
November 14, 2023
Anthos Service Mesh1.19.3-asm.4 is now available for in-cluster Anthos Service Mesh.
You can now download 1.19.3-asm.4 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.19.3 subject to the list of supported features. Anthos Service Mesh 1.19.3-asm.4 uses Envoy v1.27.2.
1.18.5-asm.2 is now available for in-cluster Anthos Service Mesh.
You can now download 1.18.5-asm.2 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.18.5 subject to the list of supported features. Anthos Service Mesh 1.18.5-asm.2 uses Envoy v1.26.5.
1.17.8-asm.4 is now available for in-cluster Anthos Service Mesh.
You can now download 1.17.8-asm.4 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.17.8 subject to the list of supported features. Anthos Service Mesh 1.17.8-asm.4 uses Envoy v1.25.12.
1.16.7-asm.14 is now available for in-cluster Anthos Service Mesh.
You can now download 1.16.7-asm.14 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.16.7 subject to the list of supported features. Anthos Service Mesh 1.16.7-asm.14 uses Envoy v1.24.11.
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.
- CVE-2023-4147
For more information, see the GCP-2023-042 security bulletin.
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.
- CVE-2023-4147
For more information, see the GCP-2023-042 security bulletin.
You can now see query performance insights about partition skew. This feature is in preview.
You can apply a patch revision version when you create a new Cloud Data Fusion instance by adding the optional --patch_revision
argument to the gcloud beta data-fusion instances create
command. For more information, see Manage patch revisions for instances.
You can update the patch revision version of an instance by adding the optional --patch_revision
argument to the gcloud beta data-fusion instances update
command. For more information, see Manage patch revisions for instances.
Cancelling a currently running job execution is now at general availability (GA).
New bandwidth quotas are now in effect.
- Bandwidth quotas are now variable and based in part on a project's billing account history. Previously, the same default value applied to all projects.
- For most projects, egress bandwidth quotas either remain unchanged or have increased.
- You can view your project's egress bandwidth quotas in the Console.
Parallel file systems for HPC workloads: Added Parallelstore and Weka Data Platform as options for parallel file system (PFS) storage.
Google Cloud console experience for VMware Engine: You can use the Google Cloud console to manage your VMware Engine environments without opening another tab. For more information on migrating to this refreshed experience, see What's new with VMware Engine.
VMware Engine network: Further simplification of the networking architecture and experience in VMware Engine removes the need for private service networking. With VMware Engine networks, you can create multiple isolated networks within the same project and connect them as needed to consumer VPCs to deliver complex topologies.
Integrated networking: Private cloud deployment is now just one simple step. VMware Engine network and initial VPC peering to your VPC can be done at the time of private cloud creation.
Advanced VPC Peering: Virtual Private Cloud network peerings define network connectivity between VMware Engine networks, Google VPCs, and other services. You can now create a complex set of VPC peerings within the Google Cloud console.
Increase to the default VPC Peer count: Any standard VMware Engine network now supports 25 VPC Peers by default.
Integrated Cloud DNS for workloads (DNS Bindings): Bi-directional Cloud DNS capabilities that enable DNS resolution for VMware Engine workloads, delivering enterprise needs in a simplified and more streamlined manner. Cloud DNS administrators can bind the VMware Engine network just as any other VPC.
DNS Server IP: Workloads within your private cloud can now use native Cloud DNS for DNS resolution.
Management DNS for private clouds: Automatic Management DNS Peering is now Automatic Management DNS for Private Clouds. You can now view and manage the DNS bindings for the private cloud management zone.
External access rules: Control access to external IP addresses. We have simplified the rule creation process to no longer require creation of a table and attachment to a subnet. External access rules now support one or more external IP address within a single rule.
(Legacy Networks) DNS forwarding rules: Allows configuration of management appliance DNS resolution for private clouds attached to legacy VMware Engine networks.
ESXi (NSX-T Distributed Log Forwarding): You can now configure both ESXi logs, including NSX-T Distributed Firewall (DFW) Logs, to a remote syslog server.
Finer-grained access controls for additional resources: VMware Engine provides finer-grained, per-action access controls for actions performed on new resources added. To view a comprehensive list of permissions for VMware Engine, go to the Permissions reference and search for the prefix vmwareengine.
Additional Google Cloud CLI and VMware Engine API Endpoints: More capabilities delivered using VMware Engine API and Google Cloud CLI enables you to programmatically manage VMware Engine environments, including VMware Engine API and Google Cloud CLI functions for managing the new networking model, network peering, external access rules and external IP service, consumer DNS, and more.
DNS Profiles: Existing DNS Profiles will be migrated to each private cloud in which the DNS Profile was assigned. DNS forwarding rules can be configured within each private cloud.
Firewall Tables: Existing firewall tables and rules have been migrated to external access rules.
Elevate privilege option is no longer available. You can sign in using one of the solution users to perform elevated privileges actions. For details, see Elevating VMware Engine privileges.
Announced August 10, 2022: Removed ability to manage point-to-site (P2S) VPN gateways for projects with existing P2S VPN gateways. You can continue to use an alternative VPN solution. For details, see Connecting using VPN. Contact customer care for P2S VPN gateway removal.
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.
- CVE-2023-4147
For more information, see the GCP-2023-042 security bulletin.
Memorystore for Redis Cluster is now Generally Available (GA).
Preview: You can now use Customer-Managed Encryption Keys (CMEK) in Migrate to Virtual Machines to do the following:
Vertex AI Search: Additional languages supported
Extractive answers are now supported in the following languages:
- Arabic
- Chinese (Simplified)
- Japanese
See Languages.
November 13, 2023
Anthos Config ManagementPolicy Controller has been updated to include a more recent build of OPA Gatekeeper (hash: a1f01f4 ).
Policy Controller bundles have been updated to the following versions: asm-policy-v0.0.1
: 202310.0
, cis-k8s-v1.5.1
: 202310.0
, cost-reliability-v2023
: 202310.0-preview
, nist-sp-800-190
: 202310.0
, nist-sp-800-53-r5
: 202310.0
, nsa-cisa-k8s-v1.2
: 202310.0
, pci-dss-v3.2.1
: 202310.0
, policy-essentials-v2022
: 202310.0
, psp-v2022
: 202310.0
, pss-baseline-v2022
: 202310.0
, pss-restricted-v2022
: 202310.0
. For reference, see Policy Controller bundles overview.
The constraint template library's K8sPSPAllowedUsers
, K8sPSPAllowPrivilegeEscalationContainer
, K8sPSPAutomountServiceAccountTokenPod
, K8sPSPCapabilities
, K8sPSPFlexVolumes
, K8sPSPForbiddenSysctls
, K8sPSPFSGroup
, K8sPSPHostFilesystem
, K8sPSPHostNamespace
, K8sPSPHostNetworkingPorts
, K8sPSPPrivilegedContainer
, K8sPSPProcMount
, K8sPSPReadOnlyRootFilesystem
, K8sPSPSELinuxV2
, K8sPSPVolumeTypes
, and K8sRequiredProbes
no longer raise violations during updates of existing objects for immutable fields.
Updated the Open Telemetry image from 0.86.0 to 0.87.0 to address security vulnerabilities. For more information about these changes, see the full changelog for opentelemetry-collector-contrib.
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.
- CVE-2023-4147
For more information, see the GCP-2023-042 security bulletin.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigquery
2.34.2 (2023-11-07)
Dependencies
- Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.32.0 (#2989) (47a61a7)
- Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.36.0 (#2990) (81c0727)
2.34.1 (2023-11-06)
Dependencies
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.19.0 (#2986) (0d400da)
- Update dependency org.checkerframework:checker-compat-qual to v2.5.6 (#2982) (c137f1f)
- Update dependency org.junit.vintage:junit-vintage-engine to v5.10.1 (#2984) (a64b91c)
- Update github/codeql-action action to v2.22.5 (#2975) (0b88846)
The following BigQuery ML point-in-time lookup functions are now generally available (GA). These functions let you specify a point-in-time cutoff when retrieving features for training a model or running inference, in order to avoid data leakage.
- Use the
ML.FEATURES_AT_TIME
function to use the same point-in-time cutoff for all entities when retrieving features. - Use the
ML.ENTITY_FEATURES_AT_TIME
function to retrieve features from multiple points in time for multiple entities.
The following AI features in BigQuery are now in preview:
The ability to process documents from BigQuery object tables by doing the following:
- Creating a remote model based on the Document AI API, including specifying a document processor to use.
- Using the
ML.PROCESS_DOCUMENT
function with a Document AI-based remote model to process the documents.
Try this feature with the Process documents with theML.PROCESS_DOCUMENT
function how-to.
The ability to transcribe audio files from BigQuery object tables by doing the following:
- Creating a remote model based on the Speech-to-Text API, including specifying a speech recognizer to use.
- Using the
ML.TRANSCRIBE
function with a Speech-to-Text-based remote model to transcribe the audio files.
Try this feature with the Transcribe audio files with theML.TRANSCRIBE
function how-to.
A weekly digest of client library updates from across the Cloud SDK.
A new query interface for creating charts is now in Public Preview. The new interface provides a style update and simplifies building a query by automatically configuring your aggregation settings. For more information, see Create charts with Metrics Explorer.
Deploying sidecar containers to your Cloud Run service is now at general availability (GA). Console UI and CLI are also now available for this feature.
Managed autoscaling for compute capacity on Cloud Spanner instances is now in preview. With managed autoscaling, Spanner automatically increases or decreases compute capacity on the instance in response to changing workload or storage needs and user defined goals. For more information, see Managed autoscaling for Spanner.
Cloud TPU now supports TensorFlow 2.15.0, which adds support for PJRT. For more information see the TensorFlow 2.15.0 release notes.
Preview: When creating or modifying an on-demand reservation, you can configure reservations to be automatically deleted at a specific date and time. Automatically deleting reservations makes it easier to prevent charges from unused reservations when you no longer need them.
For more information, see the documentation for creating on-demand reservations.
The Cloud Spanner to Vertex AI Vector Search template is generally available (GA).
Dataflow jobs now scale to 4,000 worker VMs.
Designing networks for migrating enterprise workloads: Adds Cross-Cloud Interconnect functionality and updates Private Service Connect information.
Cloud Deploy now supports delivery pipeline automation, including automated release promotion and automated rollout phase advancement, in preview.
Google Cloud's Agent for SAP version 2.7
Version 2.7 of Google Cloud's Agent for SAP is generally available (GA). This version fixes the handling of SAP HANA database passwords that contain special characters, and introduces Process Monitoring metrics related to TCP network.
For more information, see What's new with Google Cloud's Agent for SAP.
Numerical filtering available in Vertex AI Vector Search
With Vector Search you can restrict results by "filtering" your index results. In addition to filtering by using categorical restrictions, you can now use numeric filtering. To learn more, see Filter vector matches.
reCAPTCHA Enterprise Mobile SDK v18.4.0 is now available for iOS.
This version contains the following changes:
- Internal networking improvements.
- Sample codes for the iOS SDK and visual reCAPTCHA in GitHub.
- The
-ObjC
flag is not required when integrating with reCAPTCHA Enterprise on iOS.
November 10, 2023
Apigee Integrated PortalOn November 10, 2023 we released an updated version of Apigee integrated portal.
This release includes the public preview of integrated portal APIs which allow you to manage your integrated portal APIs and reference documentation using API calls.
The catalog items list view now uses pagination when making requests to the portals service, examples have been added to Publishing your APIs, and new reference documentation is available:
As of November 10, 2023, Configurable API Proxies (preview) is no longer available. For more information, see Configurable API Proxies (preview) deprecation.
On November 10, 2023 we released an updated version of Apigee.
Apigee is now available in a new region: Middle East - Dammam (me-central2
).
See Apigee locations for more information about available regions.
Database Migration Service now supports data cache in Cloud SQL for PostgreSQL Enterprise Plus edition instance creation.
You can enable data cache in the destination database when you create a migration job. To learn more about data cache in Cloud SQL for PostgreSQL, see Data cache overview.
You can now upgrade Enterprise edition instances to Enterprise Plus edition in place with minimal disruption. Similarly, you can also switch from Enterprise Plus edition to Enterprise edition in place. For more information, see Upgrade an instance by using in-place upgrade.
You can now upgrade Enterprise edition instances to Enterprise Plus edition in place with minimal disruption. Similarly, you can also switch from Enterprise Plus edition to Enterprise edition in place. For more information, see Upgrade an instance by using in-place upgrade.
Cloud Spanner now supports batch-oriented scans. For certain queries, Spanner chooses a batch-oriented processing mode to help improve scan throughput and performance. For more information, see Optimize scans.
Preview: In a managed instance group (MIG), you can turn off repairs to inspect failed and unhealthy VMs, to implement your own repair logic, or to monitor the application health without triggering repairs by MIG. For more information, see Turn off repairs in a MIG.
Announcing the General Availability (GA) release of Dataproc Jupyter Plugin and its availability in Vertex AI Workbench instance notebooks.
New Dataproc on Compute Engine subminor image versions:
- 2.0.83-debian10, 2.0.83-rocky8, 2.0.83-ubuntu18
- 2.1.31-debian11, 2.1.31-rocky8, 2.1.31-ubuntu20, 2.1.31-ubuntu20-arm
You can now stream the following large object data types for Oracle sources:
BLOB
CLOB
NCLOB
Support for Firestore point-in-time recovery (PITR) feature that provides protection against accidental deletion or writes is now generally available (GA).
Support for Firestore in Datastore mode point-in-time recovery (PITR) feature that provides protection against accidental deletion or writes is now generally available (GA).
A vulnerability (CVE-2023-4004) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes. GKE clusters are impacted. For more information, see the GCP-2023-041 security bulletin.
The Observability tab for a GKE deployment now shows application performance metrics if the metrics are available. The supported metric sources include Istio, GKE Ingress, NGINX Ingress and gRPC, and HTTP metrics collected by using Google Managed Service for Prometheus. For more information, see Use application performance metrics.
Policy Controller integration now in Preview
The integration of Policy Controller for Kubernetes clusters with Security Command Center is released to Preview. Violation alerts from Policy Controller now appear in Security Command Center as misconfiguration findings.
For more information, see Policy Controller.
Generative AI on Vertex AI
Security controls are available for additional Generative AI on Vertex AI features.
November 09, 2023
Chronicle SOARRelease 6.2.39 - Preview
Dynamic mode instance support
When a playbook is built for more than one environment, you need to use dynamic mode which picks the relevant instance configuration from the target environment. When using dynamic mode within environments that contain multiple instances, the playbook needs to stop and wait for the analyst to pick the right instance by the context of the alert.
In this release, we have added a new option to the playbook designer, such that the analyst can specify an instance for the dynamic mode to use within the target environment by entering a name or a pattern in a new Specify Instance Name field. This feature is in Preview.
Jobs enhancement
The Jobs page in the platform has been enhanced to provide more information at a glance for the security analyst. The following is a list of the added features:
- Filter jobs according to success or failure.
- Click View Details to open a side bar with full details.
- Export the log details in raw text format.
- View all job iterations with extra pagination support.
This feature is in Preview.
Update SiemplifyUtils to support Python 3 (ID #45825896).
This feature is in Preview
Incorrect playbook is attached to alert when using trigger Product Name when alerts are grouped (ID #47362407).
This bug fix is in Preview.
Issues with remote agent connected to remote connector in a shared instance configuration.
This bug fix is in Preview.
SDK function result.add_html which generates HTML reports within a case ends up generating blank text (ID #47721779).
This bug fix is in Preview
The following changes were made to the COUNTRY_DEMOGRAPHIC
infoType detector:
- The sensitivity score was changed from
HIGH
toMODERATE
. - The type category was changed from
PII
toDEMOGRAPHIC
.
You can now display events, such as the crash of a GKE pod, on your dashboards. This feature is in Public Preview.
- For a list of supported events, see Events overview.
- For information about enabling events, see Show events on a dashboard.
Data cache is now available for Cloud SQL for PostgreSQL Enterprise Plus edition instances.
You can now recover a permanently failed stream. For more information, see Recover a stream.
You can now start a stream from a specific binary log position for MySQL sources using the Datastream API. For more information, see Start a stream from a specific binary log position.
(2023-R23) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- The following control plane and node versions are now available:
- The following control plane versions are no longer available:
- 1.24.14-gke.2700
- 1.27.6-gke.1506000
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.23 to version 1.24.15-gke.1700 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.24.15-gke.1700 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.26 to version 1.26.6-gke.1700 with this release.
Stable channel
- Version 1.24.14-gke.2700 is no longer available in the Stable channel.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to 1.24.15-gke.1700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to 1.24.15-gke.1700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.26 to 1.26.5-gke.2700 with this release.
Regular channel
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.24.15-gke.1700
- 1.25.11-gke.1700
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to 1.24.16-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to 1.25.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to 1.25.12-gke.500 with this release.
Rapid channel
- Version 1.27.5-gke.200 is now the default version in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.25.12-gke.500
- 1.26.7-gke.500
- 1.27.6-gke.1506000
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.24.17-gke.2198000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to 1.25.15-gke.1033000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to 1.26.10-gke.1024000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to 1.27.4-gke.900 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.28 to 1.28.3-gke.1090000 with this release.
(2023-R23) Version updates
- The following control plane and node versions are now available:
- The following control plane versions are no longer available:
- 1.24.14-gke.2700
- 1.27.6-gke.1506000
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.23 to version 1.24.15-gke.1700 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.24.15-gke.1700 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.26 to version 1.26.6-gke.1700 with this release.
(2023-R23) Version updates
- Version 1.24.14-gke.2700 is no longer available in the Stable channel.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to 1.24.15-gke.1700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to 1.24.15-gke.1700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.26 to 1.26.5-gke.2700 with this release.
(2023-R23) Version updates
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.24.15-gke.1700
- 1.25.11-gke.1700
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to 1.24.16-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to 1.25.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to 1.25.12-gke.500 with this release.
(2023-R23) Version updates
- Version 1.27.5-gke.200 is now the default version in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.25.12-gke.500
- 1.26.7-gke.500
- 1.27.6-gke.1506000
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.24.17-gke.2198000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to 1.25.15-gke.1033000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to 1.26.10-gke.1024000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to 1.27.4-gke.900 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.28 to 1.28.3-gke.1090000 with this release.
GKE Infrastructure Dashboards and Metrics Packages are now generally available for both GKE Autopilot and Standard clusters with control plane version 1.27.2-gke.1200 and later.
You can now configure your Autopilot or Standard clusters to export a predefined list of metrics emitted by GKE managed kube-state-metrics (KSM) for workloads state and persistent storage. The component will run in the GKE system namespace "gke-managed-cim" to collect the metrics using Google Cloud Managed Service for Prometheus and send them to Cloud Monitoring. You can view the metrics in the new Persistent and Workloads State dashboards in the Observability tab.
Looker (Google Cloud core) now supports the following regions:
- asia-east2 - Hong Kong
- asia-northeast2 - Osaka
- asia-northeast3 - Seoul
- europe-southwest1 - Madrid
- europe-west6 - Zurich
- europe-west8 - Milan
- europe-west9 - Paris
- northamerica-northeast2 - Toronto
- southamerica-east1 - São Paulo
- us-west2 - Los Angeles
Vertex AI Search: New model for search summarization
A better model for generating search summaries has been launched. This underlying model improves the quality of search summaries and their grounding in the provided document corpus. You might see some differences in summary output after this update.
For more information about search summaries, see Get search summaries.
Vertex AI Search: Confidence scores are changed to relevance scores (Preview with allowlist)
Confidence scores are renamed to relevance scores. Scores are returned in the relevanceScore
field. Previously, they were returned in the confidenceScore
field.
This feature is in preview with allowlist. For more information about relevance scores, see Get snippets and extracted content.
November 08, 2023
AlloyDB for PostgreSQLThe extension pgvector
is updated to version 0.5.0.
The extension oracle_fdw
is added to the extensions supported by AlloyDB. The extension provides a foreign data wrapper for accessing Oracle databases.
A vulnerability (CVE-2023-4004) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes. For more information, see the GCP-2023-041 security bulletin.
A vulnerability (CVE-2023-4004) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes. For more information, see the GCP-2023-041 security bulletin.
A vulnerability (CVE-2023-4004) has been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes. For more information, see the GCP-2023-041 security bulletin.
On November 8, 2023 we released an updated version of Apigee integrated portal.
Bug ID | Description |
---|---|
305287906 | Fixed links to an API product from the API details, User account details, or Team details page in the Apigee UI. |
307600672 | Fixed issue where the name of the documentation was not populated in the Documentation column on the Apigee UI, API catalog page. |
307599975 | Improved pagination through large API catalogs on the Apigee UI, API catalog page. |
You might experience latency when listing jobs in projects that contain more than 10,000 jobs. For more information, see Known issues.
Documentation has been added to explain how to configure jobs to send status notifications using Pub/Sub and how to query those notifications using BigQuery.
For more information, see the following pages:
To configure your project to support status notifications, see Monitor job status using Pub/Sub notifications and BigQuery.
To configure a job to send status notifications, see Create and run a job that sends Pub/Sub status notifications.
Detection Engine has added support for rule statuses for Chronicle YARA-L rules running on live data. In addition to being in Enabled or Disabled state, rules can also have Limited or Paused status depending on their resource usage.
Cloud Bigtable app profiles now let you configure request priorities to prioritize certain workload data requests over others. This feature is available in Preview.
Cloud Functions now supports on-deployment security updates (1st gen and 2nd gen) and fully automatic security updates (1st gen only). For details, see Execution environment security.
Observability for Google Kubernetes Engine: The curated set of kube state metrics is now Generally Available. You can enable this package of metrics from the Observability tab for your GKE cluster and preview the available charts and metrics before you enable the metrics. For more information, see Package: Kube state metrics.
Setting custom audiences on your Cloud Run services is now at general availability (GA).
Confidential Space. Support for VPC Service Controls is released to Preview.
You can now protect Confidential Space using VPC Service Controls perimeters. For more information, see VPC Service Controls supported products.
Announcing the release of Workflow Template CMEK (Customer Managed Encryption Key) encryption. Use this feature to apply CMEK encryption to workflow template job arguments. For example, when this feature is enabled, the query string of a workflow template SparkSQL job is encrypted using CMEK.
You can now use Dataproc Serverless autoscaling V2 to help you manage Dataproc Serverless workloads, improve workload performance, and save costs.
Configuring Google Cloud operations suite alerts is now supported in the Cloud Deploy console.
New inference-focused Cloud Tensor Processing Unit (TPU) v5e machine types are available in GKE. These single-host TPU VMs are designed for inference workloads and contain one, four, or eight TPU v5e chips. These three new TPU v5e machine types (ct5l-hightpu-1t
, ct5l-hightpu-4t
, and ct5l-hightpu-8t
) are currently available in the us-central1-a
and europe-west4-b
zones.
Cloud Tensor Processing Unit (TPU) v5e is generally available in clusters running GKE version 1.27.2-gke.2100 and later.
TPU v5e is purpose-built to bring the cost-efficiency and performance required for medium- and large-scale training and inference. TPU v5e delivers up to 2x higher training performance per dollar and up to 2.5x inference performance per dollar for LLMs and gen AI models compared to Cloud TPU v4. At less than half the cost of TPU v4, TPU v5e makes it possible for more organizations to train and deploy larger, more complex AI models.
Looker 23.20 includes the following changes, features, and fixes.
Expected Looker (original) deployment start: Monday, November 13, 2023
Expected Looker (original) final deployment and download available: Thursday, November 30, 2023
Expected Looker (Google Cloud core) deployment start: Monday, November 13, 2023
Expected Looker (Google Cloud core) final deployment: Tuesday, December 05, 2023
Drilling on a scatterplot with quadrants and a size-by field shows all data points.
References to history_id
are being replaced with a slug for query event tracking.
The Data history playback feature requires users to have the explore
role permission in order to use it.
The default values have changed for the Persistent Sessions and Inactivity Logout settings. Persistent Sessions is now disabled by default while Inactivity Logout is now enabled by default. You can change these values on the Admin Sessions page. The behavior of these settings will not change for users who have modified the session defaults.
Users can now move dashboard tiles to the left or the right side and also resize them to standard sizes.
Quick Layout for dashboard editors has been added behind the dashboard_layout_accelerator
feature flag, which is set to ON by default for all customers besides core instances.
Malformed type declarations in a dimension_group
no longer crash the LookML validator and now work as expected.
The "Go to LookML" link on the Explore page now works as expected.
Custom filter expressions get pushed down into NDT queries as expected when using bind_all_filters
.
Number filter of type "between" reverted to type "is" when the first number was entered. This issue has been fixed.
The Databricks JDBC driver has been updated from 2.6.27 to 2.6.32.
Previously, resizing Google Maps immediately after loading could produce an error. This issue has been fixed.
An issue with configuring an SMTP server has been fixed, and the fields (Mail Server, From, User Name, Password, Port) have been made mandatory on the UI.
Custom value formats are no longer double escaped in table charts and legacy tables.
Previously, conditional formats such as "[>=1000] $#0.00,k; $#0.00" did not properly format negative numbers in tables and legacy tables. This issue has been fixed.
AND/OR filters no longer highlight required filters in red.
AND/OR filters now improve browser performance by delaying fetching suggestions until the user interacts with the filter.
The Performant Field Picker Labs feature now defaults to a new "Any" search option that searches for matches across views, groups, and fields for Explores with fewer than 5,000 fields.
Connecting VPC networks by using Network Connectivity Center is now generally available.
This feature lets you connect two or more VPC networks, represented as spokes, to a hub in the same or a different project for full mesh connectivity.
Connectivity Tests now supports verifying connectivity between two VPC networks connected by using Network Connectivity Center. For more information, see Create and run Connectivity Tests.
Support for VPC Service Controls released to Preview
You can now protect Security Command Center using VPC Service Controls perimeters. For more information, see VPC Service Controls supported products.
Traffic Director advanced load balancing, which is in Preview, is updated to include failover health threshold configuration.
Preview stage supported for the following integration:
Preview stage supported for the following integration:
November 07, 2023
BigQueryThe batch SQL translator has added enhancements when viewing SQL translation reports. You can now see a log summary of all issues during a translation job, as well as a code tab that displays a side-by-side comparison of your input and output files from a translation. This feature is in preview.
The following resource types are now publicly available through the Search APIs (SearchAllResources, SearchAllIamPolicies):
Observability for Google Kubernetes Engine: The Observability tab for a GKE deployment now shows application performance metrics if the metrics are available. The supported metric sources include Istio, GKE Ingress, NGINX Ingress and gRPC and HTTP metrics collected by using Google Managed Service for Prometheus. For more information, see Use application performance metrics.
Cloud Spanner now supports the Go programming language ORM, GORM, with GoogleSQL-dialect databases. For more information, see Integrate Spanner with GORM (GoogleSQL dialect).
Cloud Workstations is available in the asia-east2
region (Hong Kong, APAC). For more information, see Locations.
Generally available: A replica recovery checkpoint of a regional Persistent Disk volume represents the most recent crash-consistent point in time of the fully replicated disk. For disks that are not fully replicated, you can use the checkpoint to create disk snapshots from an incomplete zonal replica. You can create and use these snapshots to recover disk data in the rare scenario where your synced replica goes down before your incomplete replica catches up.
Learn more about Regional Persistent Disk replica recovery checkpoints and how to use checkpoints to recover a degraded disk.
Release 3.4
All release notes published on this date are part of the 3.4 release.
Campaigns, Do Not Call (DNC) list: You can now create your own Do Not Call (DNC) list for campaign calls. You can enable the Company DNC at Settings > Campaigns > Company Do Not Call (DNC) List. The DNC list is managed using the dedicated DNC API endpoints. Depending on configuration the DNC list can block direct, manual, and outbound calls as well as outbound and scheduled calls created by the Apps API.
Campaigns, time zone management: This release includes new time zone settings to simplify management of different time zones and calling time standards. You can now set up different time zone schemas and apply a specific time zone schema for each campaign. For example, you can use this feature to apply customized schemas to regions that have strict rules about when telemarketing calls are allowed.
You can configure time zone settings at Settings > Campaigns > Timezone Management.
Kustomer bi-directional agent status: The Kustomer integration now offers bi-directional agent status syncing.
Virtual Agent, signed and unsigned data parameters: You can now pass signed and unsigned (secured/unsecured) data parameters for Virtual Agent calls and chats using Mobile SDK in addition to the Web SDK.
Pass voice and chat channel parameter to Virtual Agent: Virtual Agents can now pass channel-specific parameters to CCAI Platform when invoking an Dialogflow Agent. This update applies to Voice Virtual Agents in IVR and Mobile channels.
Localization country code setting for calls: A country code based on outgoing or dialed number has been added to the dial dialog and add party dialog.
CCAI Platform has added "Virtual Agent" tags and prefixes in CCAI Insights for all Virtual Agent conversations.
CCAI Platform has added a fix for when the merge recording feature isn't working as expected.
cos-dev-113-18041-0-0
Kernel | Docker | Containerd | GPU Drivers |
COS-6.1.60 | v24.0.5 | v1.7.7 | v535.104.12(default, latest),v470.199.02(R470 for compatibility with K80 GPUs) |
Updated google-guest-configs to 20230929.00.
Upgraded chromeos-base/system_api to v0.0.1-r5482.
Upgraded chromeos-base/chromeos-common-script to v0.0.1-r578.
Upgraded chromeos-base/debugd-client to v0.0.1-r2581.
Upgraded chromeos-base/dlcservice-client to v0.0.1-r836.
Upgraded chromeos-base/power_manager-client to v0.0.1-r2803.
Upgraded chromeos-base/update_engine-client to v0.0.1-r2335.
Upgraded chromeos-base/session_manager-client to v0.0.1-r2669.
Upgraded chromeos-base/shill-client to v0.0.1-r4104.
cos-97-16919-404-13
Kernel | Docker | Containerd | GPU Drivers |
COS-5.10.197 | v20.10.24 | v1.6.21 | v470.199.02(default),v535.104.12(latest) |
Updated google-guest-configs to 20230929.00.
Fixed CVE-2023-42754 in the Linux kernel.
Fixed CVE-2023-45863 in the Linux kernel.
Fixed CVE-2023-5717 in the Linux kernel.
cos-101-17162-336-20
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.133 | v20.10.24 | v1.6.24 | v470.199.02(default),v535.104.12(latest) |
Updated google-guest-configs to 20230929.00.
Fixed CVE-2023-42754 in the Linux kernel.
Fixed CVE-2023-5717 in the Linux kernel.
cos-105-17412-226-28
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.133 | v23.0.3 | v1.7.7 | v470.199.02(default),v535.104.12(latest) |
Updated google-guest-configs to 20230929.00.
Fixed CVE-2023-42754 in the Linux kernel.
Fixed CVE-2023-5717 in the Linux kernel.
cos-109-17800-66-19
Kernel | Docker | Containerd | GPU Drivers |
COS-6.1.58 | v24.0.5 | v1.7.7 | v535.104.12(default, latest),v470.199.02(R470 for compatibility with K80 GPUs) |
Updated google-guest-configs to 20230929.00.
Fixed CVE-2023-5717 in the Linux kernel.
Set spark.shuffle.mapOutput.minSizeForBroadcast=128m
to fix SPARK-38101
when Dataproc Serverless Spark dynamic allocation is enabled.
Dialogflow CX now has a new language code for Hebrew: he-il
. For supported features, check the language reference table.
The iw
Hebrew language code is now deprecated, so new agents should use the he-il
language code. Existing agents using the iw
language code will continue working, but the list of supported features won't be expanded.
A set of vulnerabilities (CVE-2023-4015, CVE-2023-4623, CVE-2023-4623, CVE-2023-4921) have been discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes.
GKE clusters are impacted.
For more information, see the following security bulletins:
GKE begins automatically upgrading clusters still running version 1.24 to version 1.25 after 1.24 reaches end of life on January 8, 2024. We extended this date from October 31, 2023 to minimize disruptions around the end-of-year holiday period, and will provide patches only for critical vulnerabilities during this extended period. To learn more about the GKE minor version lifecycle, see GKE versioning and support. GKE continues to pause automatic upgrades until January 8, 2024 for clusters still using deprecated APIs removed in version 1.25, including beta APIs and PodSecurityPolicy. We recommend that you upgrade your clusters to version 1.25 as soon as possible as GKE minor versions that have reached end of life will no longer receive security patches and bug fixes.
You can use the Google Cloud console to analyze organization policies. This feature is available in Preview.
You can use the Google Cloud console to analyze organization policies. This feature is available in Preview.
Training on TPU VMs is generally available (GA).
November 06, 2023
Anthos clusters on bare metalRelease 1.14.10
Anthos clusters on bare metal 1.14.10 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.14.10 runs on Kubernetes 1.25.
Functionality changes:
Added
NODEPOOL-NAME
,NODEPOOL-NAMESPACE
, andSTATUS
columns for theInventoryMachine
resource to improve troubleshooting.Removed hardcoded timeout value for the
bmctl backup
operation.
Fixes:
Fixed an issue where
CoreDNS
Pods can get stuck in an unready state.Fixed a memory leak in Dataplane V2.
Fixes:
The following container image security vulnerabilities have been fixed in version 1.14.10:
Critical container vulnerabilities:
High-severity container vulnerabilities:
Medium-severity container vulnerabilities:
Low-severity container vulnerabilities:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
Python 3.12 is now generally available.
Python 3.12 is now generally available.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for bigquery/storage/apiv1beta1
1.57.1 (2023-11-01)
Bug Fixes
1.57.0 (2023-10-30)
Features
- bigquery/biglake: Promote to GA (e864fbc)
- bigquery/storage/managedwriter: Support default value controls (#8686) (dfa8e22)
- bigquery: Expose Apache Arrow data through ArrowIterator (#8506) (c8e7692), refs #8100
- bigquery: Introduce query preview features (#8653) (f29683b)
Bug Fixes
Python
Changes for google-cloud-bigquery
3.13.0 (2023-10-30)
Features
- Add
Model.transform_columns
property (#1661) (5ceed05) - Add support for dataset.default_rounding_mode (#1688) (83bc768)
Bug Fixes
Documentation
The BigQuery Data Transfer Service can now transfer campaign reporting and configuration data from Display & Video 360 into BigQuery. This feature is in preview.
The following BigQuery ML features for time series forecasting are now generally available (GA):
Ensure forecasted values fall within specified limits. The
FORECAST_LIMIT_LOWER_BOUND
andFORECAST_LIMIT_UPPER_BOUND
options of theCREATE MODEL
statement let you set the lower and upper bounds of the forecasted values returned by the model.Try this feature with the Limit forecasted values for a time series model tutorial.
Custom holiday modeling:
CREATE MODEL
syntax lets you specify custom holiday modeling for time series models.- The
ML.HOLIDAY_INFO
function returns the list of holidays being modeled by an ARIMA_PLUS or ARIMA_PLUS_XREG time series forecasting model. - The updated
ML.EXPLAIN_FORECAST
function includes an explanation of the holiday effect for each holiday included in the model.
Try this feature with the Use custom holidays in a time-series forecasting model tutorial.
The following resource types are now publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, and Feed APIs:
The apache-airflow-providers-google
package is upgraded to version 10.10.1 in images with Airflow 2.6.3 and 2.5.3. For more information about changes, see the apache-airflow-providers-google changelog from version 10.10.0 to version 10.10.1.
The apache-airflow-providers-cncf-kubernetes
package was upgraded to version 7.6.0.
Cloud Composer 2.5.1 images are available:
- composer-2.5.1-airflow-2.5.3
- composer-2.5.1-airflow-2.6.3 (default)
Cloud Composer versions 2.0.31, 2.0.30, 1.19.14, and 1.19.13 have reached their end of full support period.
Cloud Functions now supports the Python 3.12 runtime at the General Availability release level.
Configuring Blob storage settings is now available in Preview. With this feature you can do the following:
Log buckets in the following regions can now be upgraded to use Log Analytics:
- me-central2
For more information, see Supported regions.
Cloud SQL Enterprise Plus edition now supports asia-southeast2 (Jakarta).
Cloud SQL Enterprise Plus edition now supports asia-southeast2 (Jakarta).
The Code-OSS preconfigured base image uses version 1.83.1.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for dataflow/apiv1beta3
0.9.4 (2023-11-01)
Bug Fixes
- dataflow: Bump google.golang.org/api to v0.149.0 (8d2ab9f)
The Data Catalog Sync feature is generally available (GA). With this launch, Data Catalog also now supports syncing metadata from Dataproc Metastore services using the Spanner Database.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-datastore
2.17.5 (2023-11-02)
Dependencies
Scalable TensorFlow inference system: Converted the Tensorflow inference system guide into a reference architecture that includes design considerations.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for secretmanager/apiv1
1.11.4 (2023-11-01)
Bug Fixes
- secretmanager: Bump google.golang.org/api to v0.149.0 (8d2ab9f)
Speech-to-Text has launched two models, named telephony
and telephony_short
. The two models are customized to recognize audio that originates from a phone call and corresponds to the most recent versions of the existing phone_call
model. For more information, see Speech-to-Text supported languages.
As of November 13 2023, speaker en-US-Studio-M
will no longer be available. All requests sent to en-US-Studio-M
will be routed to speaker en-US-Studio-Q
. There is no action needed.
Vertex AI Search: Multi-region support for US and EU locations is GA
The US multi-region and the EU multi-region APIs are generally available (GA).
For more information about multi-regions including limitations, see Vertex AI Search locations.
November 03, 2023
Apigee XOn November 3, 2023, we updated the following security bulletin:
Bug ID | Description |
---|---|
304599411 | Security bulletin updated GCP-2023-32 A Denial-of-Service (DoS) vulnerability was recently discovered in multiple implementations of the HTTP/2 protocol (CVE-2023-44487), including the Apigee Ingress (Anthos Service Mesh) server used by Apigee X. The vulnerability could lead to a DoS of Apigee API management functionality. |
The shutdown of the Configurable API Proxy (Preview) feature is approaching. On or after November 10, 2023, the preview feature will no longer be available. For more information, see Configurable API proxies (preview) deprecation.
Connecting to applications using SMART on FHIR in the Cloud Healthcare API is available in Preview.
Synthetic monitors are now GA. You can create synthetic monitors by using Terraform, the Cloud console, and the Monitoring API. You can configure your synthetic monitors to collect log data and trace data. When you use the Cloud console, the generic and Mocha templates are available:
- For general information, see Synthetic monitoring overview.
- For information about creating a synthetic monitor, see Create a synthetic monitor.
The Autoclass feature can now be enabled for existing buckets.
- Previously, Autoclass could only be enabled when creating a new bucket.
- Enabling Autoclass on an existing bucket incurs additional charges.
Support for custom domains is available in preview through the gcloud
CLI and REST API. To access your workstations, you can specify a trusted, custom domain rather than using the default cloudworkstations.dev
domain.
The h3-node-88-352
sole-tenant node type is now Generally Available.
Confidential Space. A new image (confidential-space-231001) is now available. This image provides support for signing container images. For more information, see the Changelog.
(New guide) Google Cloud deployment archetypes: Overview and comparative analysis of the zonal, regional, multi-regional, global, hybrid, and multicloud deployment archetypes.
This is a patch release of Google Distributed Cloud Edge (version 1.5.1).
The following changes have been introduced in this release of Distributed Cloud Edge:
Cluster software version upgrades for local control plane clusters. You can now trigger a software version upgrade on a local control plane cluster to a specific version of Distributed Cloud Edge software, starting with version 1.5.1. This feature is not available for Cloud control plane clusters. For instructions, see Upgrade the software version on a local control plane cluster.
Cluster software version pinning for local control plane clusters. You can now pin a local control plane cluster to a specific version of Distributed Cloud Edge software, starting with version 1.5.0. A cluster pinned to a specific version does not automatically upgrade when new Distributed Cloud Software becomes available. This feature is not available for Cloud control plane clusters. For instructions, see Create a cluster.
Cluster status. The
gcloud edge-cloud container describe
command now returns the operational status of a Distributed Cloud Edge cluster.
The following issues have been resolved in this release of Distributed Cloud Edge:
- CVE-2022-40982 "Downfall" remediation. The CVE-2022-40982 vulnerability, also known as "Downfall," has been patched.
This release of Distributed Cloud Edge contains the following known issues:
Cloud SDK version 450.0.0 or later is required. You must upgrade your Cloud SDK to version 450.0.0 or later to create local control plane clusters with Distributed Cloud Edge software version 1.5.0. Otherwise, creating such clusters will fail.
Node and machine labels are not applied when upgrading to Distributed Cloud Edge version 1.5.1. When upgrading to Distributed Cloud Edge version 1.5.1, system-required labels might not be applied to nodes and machines within existing node pools. To work around this issue, either modify the affected node pool to update its corresponding resource definition, or delete and re-add the affected nodes. For instructions, see Create and manage node pools.
Cloud Text-to-Speech now offers en-GB
Studio voices: en-GB-Studio-B
and en-GB-Studio-C
.
The following models have been added to Model Garden:
- ImageBind: Multimodal embedding model.
- Vicuna v1.5: LLM finetuned based on llama2.
- OWL-ViT v2: SoTA Open Vocabulary Object Detection model.
- DITO: SoTA Open Vocabulary Object Detection model.
- NLLB: Multi-language translation model.
- Mistral-7B: SoTA LLM at small size.
- BioGPT: LLM finetuned for biomedical domain.
- BiomedCILP: Multimodal foundational model finetuned for biomedical domain.
To see a list of all available models, see Explore models in Model Garden.
New textembedding-gecko
and textembedding-gecko-multilingual
stable model versions
The following stable model versions are available in Generative AI on Vertex AI:
textembedding-gecko@002
textembedding-gecko-multilingual@001
For more information on model versions, see Model versions and lifecycle.
Model Garden
- Improved language model serving throughput. For details, see Serving open source large language models efficiently on Model Garden. Notebooks in the relevant model cards have been updated accordingly.
- Inference speed up to 2 times faster compared with original implementation for Stable Diffusion 1.5, 2.1, and XL models.
- Improved the workflow of the Deploy button in all supported model cards.
- Updated notebooks for Llama2, OpenLlama, and Falcon Instruct with suggested machine specs for model serving, and EleutherAI's evaluation harness dockers for model evaluation.
November 02, 2023
BigQueryBigQuery now supports text analysis configuration options for the following:
CREATE SEARCH INDEX DDL
- Existing
LOG_ANALYZER
and newPATTERN_ANALYZER
analyzers, which are used in various functions, includingSEARCH
- New
TEXT_ANALYZE
function
BigQuery now also provides support for the following advanced processing functions:
These features are now in preview.
The following supported default parsers have changed. Each is listed by product name and log_type
value, if applicable.
- Akamai WAF (
AKAMAI_WAF
) - Atlassian Confluence (
ATLASSIAN_CONFLUENCE
) - AWS Cloudtrail (
AWS_CLOUDTRAIL
) - AWS EMR (
AWS_EMR
) - Azure AD Organizational Context (
AZURE_AD_CONTEXT
) - Carbon Black (
CB_EDR
) - Cisco Router (
CISCO_ROUTER
) - Cisco Umbrella Web Proxy (
UMBRELLA_WEBPROXY
) - Cloud Load Balancing (
GCP_LOADBALANCING
) - Cloud SQL (
GCP_CLOUDSQL
) - DNSFilter (
DNSFILTER
) - Duo Auth (
DUO_AUTH
) - Elastic Windows Event Log Beats (
ELASTIC_WINLOGBEAT
) - Evision FircoSoft (
EVISION_FIRCOSOFT
) - ExtraHop RevealX (
EXTRAHOP
) - F5 ASM (
F5_ASM
) - Firewall Rule Logging (
N/A
) - Fortinet FortiClient (
FORTINET_FORTICLIENT
) - GCP_KUBERNETES_CONTEXT (
GCP_KUBERNETES_CONTEXT
) - GitHub (
GITHUB
) - Gitlab (
GITLAB
) - Hashicorp Vault (
HASHICORP
) - IBM DataPower Gateway (
IBM_DATAPOWER
) - IBM DB2 (
DB2_DB
) - IBM Security Verify SaaS (
IBM_SECURITY_VERIFY_SAAS
) - Infoblox (
INFOBLOX
) - JumpCloud Directory Insights (
JUMPCLOUD_DIRECTORY_INSIGHTS
) - Juniper Junos (
JUNIPER_JUNOS
) - Kolide Endpoint Security (
KOLIDE
) - ManageEngine ADAudit Plus (
ADAUDIT_PLUS
) - Microsoft Exchange (
EXCHANGE_MAIL
) - Microsoft IIS (
IIS
) - Office 365 (
OFFICE_365
) - Open Cybersecurity Schema Framework (OCSF) (
OCSF
) - Oracle (
ORACLE_DB
) - Oracle Cloud Infrastructure (
ORACLE_CLOUD_AUDIT
) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND
) - Qualys VM (
QUALYS_VM
) - Saiwall VPN (
SAIWALL_VPN
) - SentinelOne EDR (
SENTINEL_EDR
) - Slack Audit (
SLACK_AUDIT
) - Unix system (
NIX_SYSTEM
) - Windows Event (
WINEVTLOG
) - Workspace Activities (
WORKSPACE_ACTIVITY
) - Workspace Alerts (
WORKSPACE_ALERTS
) - Workspace ChromeOS Devices (
WORKSPACE_CHROMEOS
) - Zscaler Internet Access Audit Logs (
ZSCALER_INTERNET_ACCESS
)
The following log types, without a default parser, were added. Each is listed by product name and log_type
value, if applicable.
- Analyst1 IOC (
ANALYST1_IOC
) - Amazon FSx for Windows File Server (
AWS_FSX
) - DealCloud (
DEAL_CLOUD
) - DomainTools Threat Intelligence (
DOMAINTOOLS_THREATINTEL
) - Farsight DNSDB (
FARSIGHT_DNSDB
) - Journald (
JOURNALD
) - Mambu (
MAMBU
) - Mattermost (
MATTERMOST
) - Mitel Communications Director (
MITEL_MCD
) - NordLayer VPN (
NORD_LAYER
) - Paxton Access Control Systems (
PAXTON_ACS
)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.
Table and index operations statistics are now generally available. This feature helps you get insights and monitor usages of your tables and indexes in your database. For more information, see Table operations statistics.
Grant the documentSchemaViewer
, documentCreator
, and documentViewer
roles the contentwarehouse.googleapis.com/locations.getStatus
permission. This change enables the UI to render correctly, and does not change the security posture of these roles.
The zonal service tier is now generally available.
A bug that caused failures when many concurrent operations were run on the same cluster (such as when creating multiple node pools) has been fixed.
Retail API: Configure logging
You can configure which service logs are written to Cloud Logging. Logging configuration provides a way to set the severity levels at which to write logs, turn logging on or off, and override default logging settings for specific services. For information on how to change Logging configurations, see Configure Logging.
Generative AI support on Vertex AI
Generative AI on Vertex AI can be accessed through 12 regional APIs in North America, Europe, and Asia. Regional APIs let customers control where data is stored at-rest.
November 01, 2023
Apigee Advanced API SecurityOn November 1, 2023 we release an updated version of Advanced API Security.
Public preview of Advanced API Security custom profiles in the Apigee UI
With this release, you can now create and edit custom security profiles in the Apigee UI. Custom profiles let you specify the security categories that your security scores are based on.
The Security scores page in the Apigee UI has been renamed to the Risk assessment page, and the page now has tabs for security scores and security profiles.
The following INFORMATION_SCHEMA
views that show metadata for table storage usage are now in
preview:
- Use the
TABLE_STORAGE_USAGE_TIMELINE
view to get total billable bytes per table per day at the project level. - Use the
TABLE_STORAGE_USAGE_TIMELINE_BY_ORGANIZATION
view to get total billable bytes per table per day at the organization level.
You can now use cached results from the same query issued by other users in the same project when you use Enterprise or Enterprise Plus edition. This feature is generally available (GA).
Chronicle Curated Detections has been enhanced with new detection content for Google Cloud threats. These new rule sets help identify Kubernetes activity associated with abuse of role-based access controls (RBAC).
Release Notes 6.2.38
Beta - 5th November, 2023
GA - 12th November, 2023
Custom roles denied access to Advanced Reports (ID #47668375)
In certain cases, significantly large entity graphs failed to load (ID #00250400)
Duet AI for Cloud Shell is now available. Use Duet AI, your AI-powered collaborator, to accomplish tasks more effectively and efficiently. Duet AI provides contextualized responses to your prompts to help guide you on what you're trying to do with your code. It also shares source citations regarding which documentation and code samples the assistant used to generate its responses.
If you use the latest version of the Cloud Shell editor, which is Code - OSS based, you can use Duet AI for Cloud Shell. For more information, see the Duet AI in Google Cloud overview and Code with Duet AI assistance.
Duet AI for Cloud Workstations is available. Use Duet AI, your AI-powered collaborator, to accomplish tasks more effectively and efficiently. Duet AI provides contextualized responses to your prompts to help guide you on what you're trying to do with your code. It also shares source citations regarding which documentation and code samples the assistant used to generate its responses.
If you use the Code - OSS base image, you can use Duet AI in the Cloud Workstations base editor. For more information, see the Duet AI in Google Cloud overview and Code with Duet AI assistance.
Inline code completion with Duet AI assistance is now generally available (GA). For more information, see Write code in a Colab Enterprise notebook with Duet AI assistance.
Generally available: When assigning a custom queue count for the receive and transmit queues for a vNIC, under certain conditions, you can configure a number of custom queue counts that exceeds the number of vCPUs allocated to the VM.
Announcing the Preview release of Dataproc Flexible VMs. This feature lets you specify prioritized lists of secondary worker VM types that Dataproc will select from when creating your cluster. Dataproc will select the VM type with sufficient available capacity while taking quotas and reservations into account.
Data store agents now support additional languages and regions.
Storage Transfer Service has updated transfer agent behavior when transferring to Cloud Storage. To align with Cloud Storage auto-scaling, agents now gradually ramp up the number of requests being made to Cloud Storage. Customers who transfer many small files may notice initially slower transfer speeds while the requests are ramping up, but increased performance across the duration of the transfer.
General availability support for the following integration:
October 31, 2023
Anthos Service Mesh1.19.3-asm.0 is now available for in-cluster Anthos Service Mesh.
You can now download 1.19.3-asm.0 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.19.3 subject to the list of supported features. Anthos Service Mesh 1.19.3-asm.0 uses Envoy v1.27.1.
After upgrading Anthos Service Mesh to version 1.19.3 for off-Google Cloud clusters, make sure to restart all Pods in order to trigger the re-injection of sidecars. Otherwise, the Anthos Service Mesh metric reports might become inconsistent between the old and new proxies in the cluster.
Managed Anthos Service Mesh 1.19 isn't rolling out to the rapid release channel at this time. You can periodically check this page for announcements regarding rapid channel rollout. See Select a managed Anthos Service Mesh release channel for more information.
Anthos clusters on VMware 1.15.6-gke.25 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.15.6-gke.25 runs on Kubernetes 1.26.9-gke.700.
The following vulnerabilities are fixed in 1.15.6-gke.25:
Critical container vulnerabilities:
High-severity container vulnerabilities:
Container-optimized OS vulnerabilities:
Ubuntu vulnerabilities:
Windows vulnerabilities:
Artifact Registry remote repositories now support authentication to Docker Hub upstream repositories.
To create a Docker Hub remote repository, take the quickstart.
Backup for GKE now supports transformation rules that allow for the modification of resources during restore. This is an improvement over the existing substitution rules. For more information, see Modify resources during restoration.
Terraform now supports managing Backup for GKE RestorePlan resources. For more information, see google_gke_backup_restore_plan.
BigQuery support for change data capture (CDC) by processing and applying streamed changes in real-time to existing data using the BigQuery Storage Write API is now generally available (GA).
You can now use data manipulation language (DML) to modify rows that have been recently written by the Storage Write API. This feature is in preview.
The following resource types are now publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, and Feed APIs.
- Identity and Access Management
iam.googleapis.com/PolicyV2
Job overrides are now at general availability (GA). This feature lets you override the arguments, environment variables, number of tasks, and task timeouts already configured for a job when you execute a job.
The Cloud Spanner ExecuteBatchDml
API now applies optimizations to groups of statements within a batch to enable faster and more efficient data updates. For more information, see Improve latency with batch DML.
Preview: Advanced maintenance control for sole-tenancy lets you control planned maintenance events for sole-tenant node groups and minimise maintenance-related disruptions. This feature is available only for sole-tenant node groups. To use this feature with your existing virtual machines, you must first move your VMs to sole-tenant node groups that have advanced maintenance control enabled.
The advanced maintenance control for sole-tenancy feature lets you:
- Check for maintenance events scheduled for a sole-tenant node 28 days in advance.
- Trigger maintenance immediately or schedule it for later. Note that if you trigger maintenance immediately, the maintenance takes place within 24-hours from the time you trigger the request.
For more information, see Advanced maintenance control for sole-tenancy.
Dataproc Metastore is available in the following multi-regional configurations, nam11
and eur5
.
PCI DSS compliance on GKE: Updated to meet the requirements of PCI DSS version 4.0, use Cloud IDS instead of a third-party IDS, and use the PodSecurity admission controller instead of PodSecurityPolicy.
GKE multi-cluster Gateway is now generally available in GKE versions 1.24 and later for GKE Standard clusters, and versions 1.26 and later for GKE Autopilot clusters. Use the Gateway API to express the intent of your inbound HTTP(S) traffic into your fleet of GKE clusters. The multi-cluster Gateway controller deploys and manages the Application Load Balancers that forward traffic to your applications. To learn more, see Enable multi-cluster Gateways. For the list of supported Cloud Load Balancers and their features, refer to GatewayClass capabilities.
For more information, refer to the overview of Key Access Justifcations.
Transfer Appliance now has alpha-level support in the gcloud CLI (gcloud alpha transfer appliances) allowing you to view in-progress transfer results, work with draft orders, clone existing orders, and more. See the reference documentation for full details.
Workflows is available in the following additional region: europe-west10
(Berlin, Germany).
October 30, 2023
Access TransparencyAccess Transparency supports Agent Assist in the GA stage.
This release includes the following Anthos attached clusters platform versions:
- 1.25.0-gke.8
- 1.26.0-gke.6
- 1.27.0-gke.3
1.25.0-gke.8, 1.26.0-gke.6, and 1.27.0-gke.3
Added support for attaching any CNCF-conformant Kubernetes cluster, in addition to EKS and AKS clusters. To attach a cluster, specify the distribution type as "generic".
1.27.0-gke.3
Removed deployment of Fluent Bit when logging is disabled.
You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:
You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:
Release 1.15.6
Anthos clusters on bare metal 1.15.6 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.15.6 runs on Kubernetes 1.26.
Functionality changes:
- Removed hardcoded timeout value for the
bmctl backup
operation.
Fixes:
Fixed a memory leak in Dataplane V2.
Added direct dependencies on systemd, containerd, and kubelet over their mount point folders in
/var/lib/
.
Fixes:
Fixed the following vulnerabilities:
Critical container vulnerabilities:
High-severity container vulnerabilities:
Medium-severity container vulnerabilities:
Low-severity container vulnerabilities:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
Release 1.16.2
Anthos clusters on bare metal 1.16.2 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.16.2 runs on Kubernetes 1.27.
Functionality changes:
Increased the certificate time to live (TTL) for
metrics-providers-ca
andstackdriver-prometheus-scrape
for third-party monitoring.Removed hardcoded timeout value for the
bmctl backup
operation.
Fixes:
Fixed the
spec.featureGates.annotationBasedApplicationMetrics
feature gate in the stackdriver custom resource to enable collection of annotation-based workload metrics. This function is broken in Anthos clusters on bare metal versions 1.16.0 and 1.16.1.Fixed a memory leak in Dataplane V2.
Fixed an issue where garbage collection deleted Source Network Address Translation (SNAT) entries for long-lived egress NAT connections, causing connection resets.
Fixed an issue that caused file and directory permissions to be set incorrectly after backing up and restoring a cluster.
Added direct dependencies on systemd, containerd, and kubelet over their mount point folders in
/var/lib/
.Fixed an issue where etcd blocked upgrades due to an incorrect initial-cluster-state.
Fixed an issue that blocked upgrades to version 1.16 for clusters that have secure computing mode (
seccomp
) disabled.
The following container image security vulnerabilities have been fixed in release 1.16.2:
High-severity container vulnerabilities:
Medium-severity container vulnerabilities:
Low-severity container vulnerabilities:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
The BigQuery Data Transfer Service can now transfer data from Azure Blob Storage into BigQuery. This feature is now generally available (GA).
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigquery
2.34.0 (2023-10-26)
Features
- Add BigLakeConfiguration Property in StandardTableDefinition.java (#2916) (1d660fa)
- Add support for Dataset property storageBillingModel (#2913) (f452cf4)
- Add support for preview features (#2923) (113b8f2)
Dependencies
- Update actions/checkout action to v4.1.1 (#2950) (c556c18)
- Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.30.0 (#2942) (e760fca)
- Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.31.0 (#2967) (7ed55b5)
- Update dependency com.google.apis:google-api-services-bigquery to v2-rev20231008-2.0.0 (#2946) (3d0da5b)
- Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.34.0 (#2943) (18162c3)
- Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.35.0 (#2968) (219db2c)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.18.0 (#2955) (1ee18eb)
- Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.28 (#2956) (b03effd)
- Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.28 (#2957) (6465e41)
- Update github/codeql-action action to v2.22.2 (#2944) (f584e59)
- Update github/codeql-action action to v2.22.3 (#2954) (1b2bc18)
- Update github/codeql-action action to v2.22.4 (#2958) (de9bcee)
- Update ossf/scorecard-action action to v2.3.1 (#2960) (855e698)
The administrative resource charts now supports the following features in preview:
- View your resource utilization chart at the project level.
- Filter your resource utilization data based on different billing models.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigtable
2.29.0 (2023-10-26)
Features
Dependencies
Bring your own bucket feature is now generally available (GA). You can now use a custom Cloud Storage bucket as an environment's bucket.
Directories with names ending in .py
are no longer synchronized. If your
environment's bucket contains such directories, please rename them.
Fixed the cause of workers and schedulers failing when Cloud Storage objects with invalid filesystem names are synchronized.
Fixed the validation of the constraints/gcp.restrictServiceUsage
Organization Policy constraint. It no longer checks the non-blockable services, such as Cloud Logging and Cloud Monitoring.
The apache-airflow-providers-google
package is upgraded to version 10.10.0 in images with Airflow 2.6.3 and 2.5.3. For more information about changes, see the apache-airflow-providers-google changelog from version 10.9.0 to version 10.10.0.
In December 2023, we plan to switch newly created Cloud Composer 2 environments to stop storing task logs in the environment's bucket by default:
- Task logs will be available in Cloud Logging and Airflow UI.
- This change will not be enabled in already existing environments, including environments upgraded to a later version of Cloud Composer that supports this feature.
- It will be possible to enable and disable the synchronization of task logs to the environment's bucket for an existing environment.
This planned change will be announced in the Release Notes when it is rolled out.
The default version of Airflow is changed to 2.6.3.
Airflow 2.4.3 is no longer included in Cloud Composer images.
Cloud Composer 2.5.0 images are available:
- composer-2.5.0-airflow-2.5.3
- composer-2.5.0-airflow-2.6.3 (default)
Cloud Composer versions 2.0.29 and 1.19.12 have reached their end of full support period.
The Cloud Data Fusion version 6.8.3.1 patch release is generally available (GA). It fixes a regression that causes a pipeline to fail when using Dataproc secondary workers (CDAP-20807).
The Cloud Data Fusion version 6.9.2.1 patch release is generally available (GA). It fixes a regression that causes a pipeline to fail when using Dataproc secondary workers (CDAP-20807).
A weekly digest of client library updates from across the Cloud SDK.
The rollout of the following items is complete:
- The
oracle_fdw
extension, version 1.2 - The minor versions, extension versions, and plugin versions listed in the September 21 release note
A monthly digest of client library updates from across the Cloud SDK.
Go
Changes for spanner/admin/database/apiv1
1.50.0 (2023-10-03)
Features
- spanner/spansql: Add support for aggregate functions (#8498) (d440d75)
- spanner/spansql: Add support for bit functions, sequence functions and GENERATE_UUID (#8482) (3789882)
- spanner/spansql: Add support for SEQUENCE statements (#8481) (ccd0205)
- spanner: Add BatchWrite API (02a899c)
- spanner: Allow non-default service accounts (#8488) (c90dd00)
1.51.0 (2023-10-17)
Features
Bug Fixes
- spanner: Update golang.org/x/net to v0.17.0 (174da47)
Java
Changes for google-cloud-spanner
6.48.0 (2023-09-26)
Features
Bug Fixes
Dependencies
- Update actions/checkout action to v4 (#2608) (59f3e70)
- Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.27 (#2574) (e804a4c)
- Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.27 (#2575) (6fe132a)
6.49.0 (2023-09-28)
Features
Dependencies
Documentation
- Improve timeout and retry sample (#2630) (f03ce56)
- Remove reference to returning clauses for Batch DML (#2644) (038d8ca)
6.50.0 (2023-10-09)
Features
Dependencies
6.50.1 (2023-10-11)
Bug Fixes
Dependencies
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.17.0 (#2660) (96b9dd6)
- Update dependency commons-io:commons-io to v2.14.0 (#2649) (fa1b73c)
6.51.0 (2023-10-14)
Features
Bug Fixes
6.52.0 (2023-10-19)
Features
6.52.1 (2023-10-20)
Dependencies
cos-dev-113-18026-0-0
Kernel | Docker | Containerd | GPU Drivers |
COS-6.1.60 | v24.0.5 | v1.7.7 | v535.104.12(default, latest),v470.199.02(R470 for compatibility with K80 GPUs) |
Updated the Linux kernel to v6.1.60.
Updated default and latest NVIDIA GPU drivers to v535.104.12.
Updated app-containers/runc to v1.1.9.
Updated app-containers/containerd to v1.7.7.
Upgraded sys-apps/file to v5.45-r3.
Upgraded sys-fs/xfsprogs to v6.5.0.
Upgraded dev-python/pygobject to v3.46.0.
Enable portmapper registration reporting for lsof. This also fixes an issue where lsof
is missing from SOS reports.
Add compiler mitigations to mitigate memory corruption vulnerabilities.
Sequence named before nss-lookup.target.
Restore systemd-logind restart behavior when dbus restarts.
Upgraded chromeos-base/vm_protos to v0.0.1-r513.
Upgraded dev-util/bsdiff to v4.3.1-r41.
Upgraded dev-util/puffin to v1.0.0-r448.
Upgraded chromeos-base/chromeos-common-script to v0.0.1-r566.
Upgraded chromeos-base/update_engine-client to v0.0.1-r2317.
Upgraded chromeos-base/debugd-client to v0.0.1-r2568.
Upgraded chromeos-base/session_manager-client to v0.0.1-r2655.
Upgraded chromeos-base/shill-client to v0.0.1-r4043.
Upgraded chromeos-base/power_manager-client to v0.0.1-r2781.
Upgraded chromeos-base/hiberman-client to v0.0.1-r374.
Upgraded sys-devel/libtool to v2.4.6-r7.
Upgraded chromeos-base/mojo_service_manager to v0.0.1-r265.
Upgraded dev-libs/double-conversion to v3.2.1.
Upgraded net-libs/libtirpc to v1.3.4.
Upgraded sys-libs/zlib to v1.3-r1.
Upgraded net-dns/c-ares to v1.20.1.
Upgraded sys-apps/hwdata to v0.375.
Upgraded net-dns/libidn2 to v2-2.3.4-r1.
Upgraded net-fs/cifs-utils to v7.0-r1, Upgraded sys-libs/talloc to v2.4.1.
Upgraded app-arch/unzip to v6.0_p27-r1.
Upgraded sys-apps/dmidecode to v3.5-r3.
Upgraded dev-libs/nss to v3.94.
Upgraded sys-apps/pv to v1.8.0.
Updated dev-lang/go to v1.21.2. This resolves CVE-2023-39323.
Upgraded net-misc/curl to version v8.4.0. This resolves CVE-2023-38545.
Runtime sysctl changes:
- Added: net.ipv4.tcp_shrink_window: 0
- Added: net.ipv6.conf.all.accept_ra_min_lft: 0
- Added: net.ipv6.conf.default.accept_ra_min_lft: 0
- Added: net.ipv6.conf.docker0.accept_ra_min_lft: 0
- Added: net.ipv6.conf.eth0.accept_ra_min_lft: 0
- Added: net.ipv6.conf.lo.accept_ra_min_lft: 0
cos-109-17800-66-15
Kernel | Docker | Containerd | GPU Drivers |
COS-6.1.58 | v24.0.5 | v1.7.7 | v535.104.12(default, latest),v470.199.02(R470 for compatibility with K80 GPUs) |
This is an LTS Refresh Release
Updated the Linux kernel to v6.1.58.
Updated app-containers/containerd to v1.7.7.
Updated default and latest NVIDIA GPU drivers to v535.104.12.
Updated dev-lang/go to v1.21.2. This resolves CVE-2023-39323.
Upgraded net-misc/curl to v8.4.0. This resolves CVE-2023-38545.
Fixed CVE-2023-4244 in the Linux kernel.
Enable portmapper registration reporting for lsof. This also fixes an issue where lsof
is missing from SOS reports.
Restore systemd-logind restart behavior when dbus restarts.
Runtime sysctl changes:
- Added: net.ipv6.conf.all.accept_ra_min_lft: 0
- Added: net.ipv6.conf.default.accept_ra_min_lft: 0
- Added: net.ipv6.conf.docker0.accept_ra_min_lft: 0
- Added: net.ipv6.conf.eth0.accept_ra_min_lft: 0
- Added: net.ipv6.conf.lo.accept_ra_min_lft: 0
- Changed: fs.file-max: 812619 -> 812608
- Changed: kernel.threads-max: 63519 -> 63520
- Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_recd: 0 -> 3
- Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_sent: 0 -> 3
- Changed: user.max_cgroup_namespaces: 31759 -> 31760
- Changed: user.max_ipc_namespaces: 31759 -> 31760
- Changed: user.max_mnt_namespaces: 31759 -> 31760
- Changed: user.max_net_namespaces: 31759 -> 31760
- Changed: user.max_pid_namespaces: 31759 -> 31760
- Changed: user.max_time_namespaces: 31759 -> 31760
- Changed: user.max_user_namespaces: 31759 -> 31760
- Changed: user.max_uts_namespaces: 31759 -> 31760
cos-101-17162-336-16
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.133 | v20.10.24 | v1.6.24 | v470.199.02(default),v535.104.12(latest) |
Updated app-emulation/containerd to v1.6.24.
Enable portmapper registration reporting for lsof. This also fixes an issue where lsof
is missing from SOS reports.
Fix Node restart due to kernel panic is C3D machines.
Updated dev-lang/go to v1.20.9. This resolves CVE-2023-39323.
cos-97-16919-404-9
Kernel | Docker | Containerd | GPU Drivers |
COS-5.10.197 | v20.10.24 | v1.6.21 | v470.199.02(default),v535.104.12(latest) |
Enable portmapper registration reporting for lsof. This also fixes an issue where lsof
is missing from SOS reports.
Updated latest NVIDIA GPU drivers to v535.104.12.
cos-105-17412-226-23
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.133 | v23.0.3 | v1.7.7 | v470.199.02(default),v535.104.12(latest) |
Enable portmapper registration reporting for lsof. This also fixes an issue where lsof
is missing from SOS reports.
Updated dev-lang/go to v1.20.9. This resolves CVE-2023-39323.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for dataflow/apiv1beta3
0.9.3 (2023-10-26)
Bug Fixes
- dataflow: Update grpc-go to v1.59.0 (81a97b0)
New Dataproc on Compute Engine subminor image versions:
- 2.0.82-debian10, 2.0.82-rocky8, 2.0.82-ubuntu18
- 2.1.30-debian11, 2.1.30-rocky8, 2.1.30-ubuntu20, 2.1.30-ubuntu20-arm
Added spark.dataproc.scaling.version=2
config to let customers control the Dataproc Serverless for Spark autoscaling version.
Increased the TTL for Dataproc on Compute Engine custom images from 60 days to 365 days.
Fixed Knox rewrite rules for Zeppelin URLs in some cases in the latest 2.0 and 2.1 Dataproc on Compute Engine image versions.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-datastore
2.17.4 (2023-10-23)
Dependencies
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.18.0 (#1215) (aa82f01)
- Update dependency com.google.errorprone:error_prone_core to v2.23.0 (#1213) (c57db43)
- Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.28 (#1216) (ce4eff2)
- Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.28 (#1217) (7d56b3c)
Cloud Deploy support for deploy hooks is now generally available.
You can now use GKE node service account insights to troubleshoot common GKE node service account issues. These insights are available in the Network Analyzer and the Recommender API.
On October 30, 2023 we released version 1.3.1 of the Migrate to Containers modernization plugins.
Learn how to Upgrade Migrate to Containers plugins.
The plugins for migrating Apache, JBoss, WordPress, and IBM WebSphere traditional applications to containers are now generally available. These plugins provide a streamlined and simplified experience for migrating applications based on these frameworks.
Network Analyzer now includes an insight that gives a summary of the Google Kubernetes Engine (GKE) node service account. This insight is already available in the Recommender API. For more information, see GKE node service account insights.
Google Cloud storage manager for SAP HANA standby nodes version 2.6
Version 2.6 of the Google Cloud storage manager for SAP HANA standby nodes is now available. This version includes bug fixes and supportability improvements.
For more information about the storage manager, see Storage Manager for SAP HANA.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for secretmanager/apiv1
1.11.3 (2023-10-26)
Bug Fixes
- secretmanager: Update grpc-go to v1.59.0 (81a97b0)
Deep Learning VM Images is a set of prepackaged virtual machine images with a deep learning framework that are ready to be run out of the box. Recently, an out-of-bounds write vulnerability was discovered in the ReadHuffmanCodes()
function in the libwebp
library. This might impact images that use this library.
Google Cloud continuously scans its publicly published images and updates the packages to assure patched distros are included in the latest releases available for customer adoption. Deep Learning VM Images have been updated to ensure that the latest VM images include the patched distros. Customers adopting the latest VM images are not exposed to this vulnerability.
For more information, see the Vertex AI security bulletin.
October 27, 2023
Artifact RegistryArtifact Registry remote repositories are now generally available.
Remote repositories store artifacts from external sources such as Docker Hub or PyPI. A remote repository acts as a proxy for the external source so that you have more control over your external dependencies. The first time that you request a version of a package, Artifact Registry downloads and caches the package in the remote repository. The next time you request the same package version, Artifact Registry serves the cached copy.
To get started with remote repositories, try the quickstart.
Artifact Registry virtual repositories are now generally available.
Virtual repositories act as a single access point to download, install, or deploy artifacts in the same format from one or more upstream repositories. An upstream repository can be an Artifact Registry standard or remote repository.
To get started with virtual repositories, create a virtual repository, or see an example of how to use the different repository modes together in the repository overview usage example.
The Japan Regions compliance program is now generally available. For a list of Google Cloud products compliant with Japan Regions, see the Supported products page.
Google has added Frankfurt (Germany) and Zurich (Switzerland) as new regions for Chronicle customers. Chronicle can now store customer data in these regions. This also adds new regional endpoints for Chronicle APIs at https://europe-west3-backstory.googleapis.com and https://europe-west6-backstory.googleapis.com.
New searchable fields are now available.
The following resource types are now publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, Feed API, and Search APIs (SearchAllResources, SearchAllIamPolicies).
netapp.googleapis.com/StoragePool
netapp.googleapis.com/Volume
netapp.googleapis.com/Snapshot
netapp.googleapis.com/ActiveDirectory
netapp.googleapis.com/KmsConfig
netapp.googleapis.com/Replication
You can now specify the SSL mode of your Cloud SQL instances, which gives you more accurate SSL encryption. To use SSL mode, you must use the maintenance version [PostgreSQL version].R20230530.01_00 or newer. For more information, see Enforce SSL/TLS encryption.
Turbo replication performance monitoring in the Google Cloud console has been moved and expanded.
Monitoring graphs have been moved from a bucket's Configuration tab to its Observability tab.
A new, real-time Maximum delay in turbo replication graph is also available in the Observability tab.
Preview: Hyperdisk Balanced is now available in preview with H3 VMs. Hyperdisk Balanced is a good fit for a wide range of use cases such as LOB applications, web applications, and medium-tier databases that don't require the performance of Hyperdisk Extreme. For more information, see About Hyperdisk.
Config Connector version 1.111.0 is now available.
Added support for ContainerAttachedCluster
(v1beta1) resource.
Added support for AlloyDBCluster
(v1beta1) resource.
Added support for AlloyDBInstance
(v1beta1) resource.
Added support for AlloyDBBackup
(v1beta1) resource.
Added name validation for ValidatingWebhookConfigurationCustomization
and MutatingWebhookConfigurationCustomization
CRDs.
Added validation for duplicate webhooks in spec.webhooks
list of the customizable ControllerResource
and NamespacedControllerResource
CRDs.
Added errors on invalid webhook names into status of ValidatingWebhookConfigurationCustomization
and MutatingWebhookConfigurationCustomization
custom resources.
Fixed an reconciliation issue in ComputeManagedSSLCert resource. Issue #107.
Fixed issue of the retrieved maxWorkers in DataflowFlexTemplateJob
resource.
Graduated ValidatingWebhookConfigurationCustomization
, MutatingWebhookConfigurationCustomization
, ControllerResource
and NamespacedControllerResource
CRDs to v1beta1.
Fixed an issue in ComputeForwardingRule
resource when used with PSC. Issue #763.
Resource AlloyDBCluster(v1beta1):
- Added
spec.networkConfig
field.
Resource ComputeSubnetwork(v1beta1):
- Added
status.internalIpv6Prefix
field.
Resource ComputeTargetHTTPSProxy(v1beta1):
- Added
spec.serverTlsPolicyRef
field.
Resource ContainerCluster(v1beta1):
- Added
spec.nodeConfig.fastSocket
field.
Resource ContainerNodePool(v1beta1):
- Added
spec.nodeConfig.fastSocket
field.
Resource NetworkConnectivitySpoke(v1beta1):
- Added
spec.linkedVPCNetwork
field.
Resource RunJob(v1beta1):
- Added
spec.template.template.vpcAccess.networkInterfaces
field.
Resource RunService(v1beta1):
- Added
spec.template.vpcAccess.networkInterfaces
field.
Resource SecretManagerSecretVersion(v1beta1):
- Added
spec.isSecretDataBase64
field.
Batch workspace deletion is available.
New Dataproc Serverless for Spark runtime versions:
- 1.1.37
- 2.0.45
- 2.1.24
Cloud Deploy now uses Skaffold 2.8 as the default Skaffold version for all target types.
Vertex AI Search: Create media recommendations in Vertex AI Search
You can now create apps for media recommendations in Vertex AI Search. Media recommendations include content such as videos, news, and music. For more information, see Vertex AI Search.
Important: If you are using Discovery for Media for media recommendations, you need to switch to the media recommendations capability of Vertex AI Search. All of the existing data and models that you created with Discovery for Media will automatically appear in the Vertex AI Search and Conversation console, with the models appearing as apps. For more information, see Migrate from Discovery for Media to media recommendations.
October 26, 2023
Apigee Integrated PortalOn October 26, 2023 we released an updated version of Apigee integrated portal.
Bug ID | Description |
---|---|
5400261 | Improve confirmation dialog text when user clicks the button to revoke an app key from the portal UI. This dialog is displayed when you:
|
On October 26, 2023 we released an updated version of the Apigee UI.
Bug ID | Description |
---|---|
287028804, 291942702 | Fixed issue where customers with a mismatched with Google Cloud project and Apigee organization ID would be presented with the Apigee welcome screen instead of the management UI in the Apigee UI in Google Cloud console. |
The above fix requires a change in permissions for users managing Apigee through the Google Cloud console with a custom role.
Custom roles must now include the apigee.projectorganizations.get
role for users who manage Apigee organizations via the Apigee UI in Cloud console. Without this role, users see a provisioning prompt in the console rather than the standard UI actions.
See UI-based Apigee management permissions for instructions.
Documentation has been added to explain how to run dsub
pipelines on Batch. For more information, see Orchestrate jobs by running dsub pipelines on Batch.
Recover FHIR resources with point-in-time recovery (PITR) is available in Preview.
Cloud Spanner now supports FULL JOIN
with USING
in PostgreSQL-dialect databases. For information about PostgreSQL queries in Spanner, see PostgreSQL queries.
Managed folders are now available in Preview. When using managed folders, you can organize your objects by group and set IAM policies that offer more granular access control over data segments within a bucket.
cos-105-17412-226-18
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.133 | v23.0.3 | v1.7.7 | v470.199.02(default),v535.104.12(latest) |
Sync TCPX changes to commit e34a5bbcc20d.
File search is available in workspaces.
A connection reset error is tagged as a ConnectionError
and not a ConnectionFailedError
, and it is not retried for non-idempotent requests. For more information, see Workflow errors and Retry steps.
October 25, 2023
Access TransparencyAccess Transparency supports Vertex AI Workbench instances in the GA stage.
Certificate Authority Service is now available in the following region:
- europe-west10
For more information, see Certificate Authority Service locations.
Release Notes 6.2.37
Beta - 29th October, 2023
GA - 5th November, 2023
A new Explore containing case-related fields has been added to the Advanced Reports module in the platform. This Explore allows you to find fields and build visualizations for your report. We recommend using this new Explore in new widgets.
Error when trying to log in again to Chronicle SOAR (ID #46831483)
Email HTML template shows blank page in Settings (ID #46912863)
Users filter in the Search page not displaying all the users (ID #00249930)
Active Directory Groups field removed from Settings Permission groups as it is not supported
Cloud Workstations is available in the northamerica-northeast1
region (Montréal, Québec, North America). For more information, see Locations.
Preview: Project zonal metadata is custom project metadata that you can set exclusively for VMs in a specific zone in a project. Project zonal metadata helps you with fault isolation and provides greater reliability. By setting custom project zonal metadata, you gain more control over the project metadata for your VMs and limit the impact of any incorrect metadata updates to VMs within the specific zone.
Learn more about VM metadata and how to set custom project zonal metadata.
Announcing the General Availability (GA) release of Dataproc Serverless GPU accelerators.
Dataproc Metastore is now available in the me-central2
(Dammam) region. For more information, see Dataproc Metastore locations.
On the week of October 30, 2023, auto speech adaptation (CX, ES) will be updated for non-English agents. No major behavior changes are expected.
If you notice speech recognition issues in Dialogflow CX, you can mitigate by enabling manual speech adaptation on flows and pages experiencing issues. You can tune the adaptation as follows:
On the problematic flows and pages, disable auto speech adaptation by enabling manual speech adaptation without adding phrases.
If your agent is unable to recognize certain words and phrases, add those phrases to the adaptation with no boost.
If your agent is still unable to recognize certain words and phrases after step 2, duplicate those phrases so that you have one without boost and one with boost.
If you notice speech recognition issues in Dialogflow ES, you can mitigate by using the speechContexts field at runtime which overrides auto speech adaptation or by updating your agent design.
Cloud Storage Backint agent for SAP HANA version 1.0.31
Version 1.0.31 of the Cloud Storage Backint agent for SAP HANA is available. This version fixes client libraries to enable Cloud Logging capabilities.
For more information about the agent, see Cloud Storage Backint agent for SAP HANA overview.
Styles are now supported in Neural2 voices through SSML. The following styles are supported
<google:emotion name="apologetic">
<google:emotion name="calm">
<google:emotion name="empathetic">
<google:emotion name="firm">
<google:emotion name="lively">
- en-us-Neural2-F
- en-us-Neural2-J
October 24, 2023
Apigee UIOn October 24, 2023 we released an updated version of the Apigee UI.
Bug ID | Description |
---|---|
301458133 | Fixed an issue in which saving a previously deployed proxy or shared flow revision resulted in the error "revision revision_name is immutable." You are now prompted to create a new revision in this case. |
On October 24, 2023, we released an updated version of Apigee (1-11-0-apigee-7).
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.
With this release, the HeaderName
element is available as a child element of Authentication
. This element appears in the ServiceCallout and ExternalCallout policies, and in the TargetEndpoint proxy configuration.
By default, when an Authentication
configuration is present, Apigee generates and injects a bearer token into the Authorization
header, in the message sent to the target system. The new HeaderName
element allows the configuration to specify the name of a different header to hold that bearer token.
Bug ID | Description |
---|---|
294293907 | Fixed issue with Google authentication for gRPC-based target servers. |
292454825 | Fixed issue causing Null Pointer Exception when creating or updating an API product. |
291784631 | Implemented fix to permit the use of hyphens (-) in flow variables used to define target URLs in <HTTPTargetConnection> . |
267229604 | Fixed issue where updates to a TLS truststore reference were not reflected for in-use southbound target server connections. |
277353680 | Fixed issue causing target server HealthMonitors to continue beyond revision or deletion of the proxy.Target health checks are now terminated as soon as the proxy is removed from the runtime (undeployed or deleted). Note: There may be a delay between removal of the proxy and termination of the target server health checks. |
N/A | Upgraded infrastructure and libraries. |
Remote Agents 1.4.4
- Added support for all SDK calls over remote agents
- Improved managing integrations over the remote agent leading to a more overall stable product experience
- Publisher Python version upgraded to Python 3.11
Remote Agents 1.4.4
- Remote agent actions do not return script results in the same way local actions return them (ID #45682680)
- Users unable to change the remote agent environment via agent CLI
Ops Agent version 2.43.0 introduces support for Compute Engine Arm VMs that are running SLES 15 and OpenSUSE Leap 15. For more information, see Support for Compute Engine Arm VMs.
Ops Agent version 2.43.0 introduces support for Compute Engine Arm VMs that are running SLES 15 and OpenSUSE Leap 15. For more information, see Support for Compute Engine Arm VMs.
Config Controller now uses the following versions of its included products:
- Config Connector v1.110.0, release notes
- Anthos Config Management v1.16.1, release notes
cos-105-17412-226-17
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.133 | v23.0.3 | v1.7.7 | v470.199.02(default),v535.104.12(latest) |
Sync TCPX changes to commit 3cac7b2856a0
Updated app-containers/containerd to 1.7.7.
Sync TCPX changes to commit da99a91cffb1
Update latest NVIDIA GPU drivers to 535.104.12.
cos-97-16919-404-4
Kernel | Docker | Containerd | GPU Drivers |
COS-5.10.197 | v20.10.24 | v1.6.21 | v470.199.02(default),v535.104.05(latest) |
Upgraded net-misc/curl to version 8.4.0. This resolves CVE-2023-38545.
Fix CVE-2023-42756 in COS kernel.
Runtime sysctl changes:
- Added: net.ipv4.tcp_migrate_req: 0
- Changed: fs.file-max: 813432 -> 813422
- Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_recd: 0 -> 3
- Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_sent: 0 -> 3
cos-93-16623-461-42
Kernel | Docker | Containerd | GPU Drivers |
COS-5.10.177 | v20.10.24 | v1.6.20 | v450.248.02(default),v535.104.12(latest),v470.199.02(R470 for compatibility with K80 GPUs) |
Update latest NVIDIA GPU drivers to 535.104.12.
Fixed CVE-2023-42752 in the Linux kernel.
cos-101-17162-336-9
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.133 | v20.10.24 | v1.6.21 | v470.199.02(default),v535.104.12(latest) |
Update latest NVIDIA GPU drivers to 535.104.12.
Inter-service communication in a microservices setup: Updated the architecture, design guidance, and deployment steps based on the latest demo application.
Studio voices now support 5,000 bytes of either text or SSML input per synthesis request.
Long Audio Synthesis now supports Studio voices.
Long Audio Synthesis now supports SSML inputs.
October 23, 2023
BigQueryCustom data masking now supports an expanded list of functions, including SHA hash functions with salt. This feature is in preview.
Control access to single-project budgets
If you are a billing account-level user and are creating a budget for a single project, you can now prevent project users such as Project Owners and Project Editors from making changes to the budget. This prevents inadvertent changes to budgets that you might be tracking at the Cloud Billing account level.
Budgets for project users is now Generally Available
Project users such as Project Owners, Project Editors, and Project Viewers in Google Cloud can now create budgets and stay on top of their cloud costs, without needing additional permissions to access Cloud Billing accounts. Budgets for project users enables project users to take ownership of their costs, plan for the spend in the projects that they own, and proactively manage cost exceptions.
You can now assign custom roles to users who can create, modify and delete single-project budgets for the projects they have access to.
Project users can use the Google Cloud console or the Cloud Billing Budget API to manage budgets for projects.
Cloud Data Fusion supports patch revisions. These revisions apply bug fixes between major releases. For more information, see Versioning in Cloud Data Fusion.
The Cloud Data Fusion version 6.7.3.1 patch revision is generally available (GA). It introduces retries in the platform transaction layer to handle a PSQLException
error thrown from broken database connections (CDAP-19949 and CDAP-20722).
A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.
You can configure your synthetic monitors to collect log data and trace data for your outbound HTTP requests when you use the generic template. This feature is in Public Preview. For more information, see Samples for synthetic monitors.
Cloud Spanner PostgreSQL now supports the SELECT DISTINCT
statement. For more information, see SELECT.
The Cloud Spanner to BigQuery template for batch pipelines is available in preview.
A weekly digest of client library updates from across the Cloud SDK.
Python
Changes for google-cloud-dataflow-client
0.8.5 (2023-10-09)
Documentation
- Minor formatting (94b4f73)
The 2.7.0 version of the open-source Dataform framework is available. This update introduces explicitly listed column names in incremental insert statements. For more information, see the 2.7.0: Updates for Dataform GCP incremental SQL release on GitHub.
New Dataproc Serverless for Spark runtime versions:
- 1.1.36
- 2.0.44
- 2.1.23
Dataproc now collects the dataproc.googleapis.com/job/yarn/vcore_seconds
and dataproc.googleapis.com/job/yarn/memory_seconds
job-level resource attribution metrics to track YARN application vcore and memory usage during job execution. These metrics are collected by default and are not chargeable to customers.
Dataproc now collects a dataproc.googleapis.com/node/yarn/nodemanager/health
health metric to track the health of individual YARN node managers running on VMs. This metric is written against the gce_instance
monitored resource to help you find suspect nodes. It is collected by default and is not chargeable to customers.
Dialogflow CX has added the following prebuilt components:
Filestore is now available in Berlin (europe-west10
region).
You can now deploy Cloud Run jobs, in addition to Cloud Run services.
The Cloud Storage FUSE CSI driver now enforces injected sidecar containers to follow the Restricted Pod security standard. This change is available in v0.1.6 of the driver, and in GKE clusters with control planes running the following versions: 1.24.17-gke.2146000, 1.25.14-gke.1466000, 1.26.9-gke.1494000, 1.27.6-gke.1506000, and 1.28.2-gke.1157000 or later.
Added support for Committed use discounts for Memorystore for Redis Cluster.
October 20, 2023
Cloud DomainsOn September 7, 2023 Squarespace acquired all domain registrations and related customer accounts from Google Domains. For more information about how this change affects Cloud Domains, see Cloud Domains feature deprecation, Google Domains FAQ, and Cloud Domains FAQ.
Workforce identity federation is available.
Support for the PostgreSQL ARRAY data type is now added in Datastream.
Eventarc support for internal HTTP endpoints as event destinations is available in Preview. For more information, see the guide and the tutorial.
Cloud Armor for regional HTTP(S) load balancers is now Generally Available. For more information, see the Security policy overview.
New Autopilot clusters created with versions 1.24.17-gke.2146000, 1.25.14-gke.1466000, and 1.26.9-gke.1494000 or later are now provisioned with e2-small default nodes, which are removed immediately after cluster creation. With this change, DaemonSets are guaranteed to schedule on all candidate nodes if you follow best practices for DaemonSets on Autopilot.
You can now use the GKE API to apply Resource Manager tags to your GKE resources. GKE attaches these tags to the underlying Compute Engine VMs. You can use these tags to selectively enforce Cloud Firewall network firewall policies. This feature is available in Public Preview in GKE version 1.28 and later.
October 19, 2023
Anthos Config ManagementPolicy Controller has been updated to include a more recent build of OPA Gatekeeper (hash: 3e66ee2).
The constraint template library includes a new template: K8sAvoidUseOfSystemMastersGroup
. For reference, see the Constraint template library.
The constraint template library includes a new template: K8sPSPWindowsHostProcess
. For reference, see the Constraint template library.
Policy Controller bundles have been updated to the following versions: asm-policy-v0.0.1
: 202309.0
, cis-k8s-v1.5.1
: 202309.0
, cost-reliability-v2023
: 202309.0
, nist-sp-800-190
: 202309.0
, nist-sp-800-53-r5
: 202309.0
, nsa-cisa-k8s-v1.2
: 202309.0
, pci-dss-v3.2.1
: 202309.0
, policy-essentials-v2022
: 202309.0
, psp-v2022
: 202309.0
, pss-baseline-v2022
: 202309.0
, pss-restricted-v2022
: 202309.0
. For reference, see Policy Controller bundles overview.
Updated the Open Telemetry image from 0.54.0 to 0.86.0 to address security vulnerabilities. otelcontribcol:v0.86.0
contains breaking changes. For more information about these changes, see the full changelog for opentelemetry-collector-contrib.
Fixed a recurring transient error in the RootSync and RepoSync API. Transient errors are retried internally and surfaced to RootSync and RepoSync if failed eventually.
Anthos clusters on VMware 1.16.2-gke.28 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.16.2-gke.28 runs on Kubernetes 1.27.4-gke.1600.
The following issue is fixed in 1.16.2-gke.28:
- Fixed the known issue where a non-HA Controlplane V2 cluster is stuck at node deletion until it timesout.
The following vulnerabilities are fixed in 1.16.2-gke.28:
Container-optimized OS vulnerabilities:
Ubuntu vulnerabilities:
Windows vulnerabilities:
Anthos clusters on VMware 1.14.9-gke.21 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.14.9-gke.21 runs on Kubernetes 1.25.13-gke.200.
The following issues are fixed in 1.14.9-gke.21:
- Fixed the known issue where a non-HA Controlplane V2 cluster is stuck at node deletion until it timesout.
The following vulnerabilities are fixed in 1.14.9-gke.21:
Critical container vulnerabilities:
High-severity container vulnerabilities:
Container-optimized OS vulnerabilities:
Ubuntu vulnerabilities:
Windows vulnerabilities:
The maximum memory available for script evaluation in the Data Transformer Script task is 300 MB. For the list of all the applicable limits, see Quotas and Limits.
On October 19, 2023, we released an updated version of Apigee
Looker Studio Integration
This release includes the public preview of Looker Studio Integration, which connects Apigee data to Google's Looker Studio. Looker Studio is a powerful and flexible tool that you can use to display Apigee data in fully customizable dashboards and reports.
The maximum memory available for script evaluation in the Data Transformer Script task is 300 MB. For the list of all the applicable limits, see Quotas and Limits.
Security Command Center Premium adds real-time threat detection for Google Cloud Backup and DR Service. Event Threat Detection, a Security Command Center Premium service, released new rules for Google Cloud Backup and DR Service. Security Command Center can now do the following:
- Detect Backup and DR actions that result in data destruction.
- Detect Backup and DR actions that inhibit inhibit system recovery.
Documentation has been added to explain how to colocate the VMs for a job by using a compact placement policy. For example, use compact placement policies to reduce the latency between VMs for jobs with tightly coupled tasks, such as tasks that communicate using MPI libraries.
For more information, see Reduce latency by using compact placement policies.
Stored procedures for Apache Spark are now available without enrollment. This feature is in preview.
View granular cost data from Dataflow usage in Cloud Billing exports to BigQuery
You can now view granular Dataflow cost data in the Google Cloud Billing detailed export. Use the resource.name
or resource.global_name
field in the export to view and filter your detailed Dataflow usage.
Review the schema of the Detailed cost data export.
View granular cost data from BigQuery usage in Cloud Billing exports to BigQuery
View granular cost data from BigQuery in Cloud Billing exports to BigQuery
You can now view granular BigQuery cost data in the Google Cloud Billing detailed export. Use the resource.name
or resource.global_name
field in the export to view and filter your BigQuery Dataset and Jobs costs.
Compute resources can now be reserved in advance for use with GKE. Create a future reservation to request assurance of important or difficult-to-obtain capacity in advance. There are no additional costs for creating future reservation requests. You only start to pay when Compute Engine provisions the reserved resources, and you're charged at the same cost as on-demand reservations.
(2023-R22) Version updates
GKE cluster versions have been updated. There are no version updates for 2023-R21.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- The following control plane and node versions are now available:
Stable channel
- There are no new releases in the Stable release channel.
Regular channel
- There are no new releases in the Regular release channel.
Rapid channel
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel: 1.28.1-gke.201, 1.28.1-gke.1066000
(2023-R22) Version updates
There are no version updates for 2023-R21.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel: 1.28.1-gke.201, 1.28.1-gke.1066000
(2023-R22) Version updates
There are no version updates for 2023-R21.
- The following control plane and node versions are now available:
Backup and DR Service threat detectors available in Security Command Center Premium
Event Threat Detection, a built-in service of Security Command Center, released new rules for the Google Cloud Backup and DR service to Preview. Security Command Center can now detect the following:
- Backup and DR actions that inhibit system recovery
- Backup and DR actions that result in data destruction
For more information, see:
- Backup and DR in Event Threat Detection rules
- What is Backup and DR Service?
October 18, 2023
BatchDocumentation has been added to explain how to securely reference sensitive data in a job by using Secret Manager secrets for encryption. For example, use secrets to protect sensitive data when defining custom environment variables or protect login credentials when accessing private container images from Docker Registry.
For more information, see Protect sensitive data using Secret Manager with Batch.
The BigQuery migration assessment is now available for Apache Hive in preview. You can use this feature to assess the complexity of migrating data from your Apache Hive data warehouse to BigQuery.
The following supported default parsers have changed. Each is listed by product name and log_type
value, if applicable.
- Azure AD Directory Audit (
AZURE_AD_AUDIT
) - Check Point (
CHECKPOINT_FIREWALL
) - Chronicle SOAR Audit (
CHRONICLE_SOAR_AUDIT
) - Cisco Internetwork Operating System (
CISCO_IOS
) - Cisco Meraki (
CISCO_MERAKI
) - Cisco Web Services Manager (
CISCO_WSM
) - Cloud Audit Logs (
N/A
) - Cloudflare (
CLOUDFLARE
) - CrowdStrike Falcon (
CS_EDR
) - ESET Threat Intelligence (
ESET_IOC
) - GitHub (
GITHUB
) - Gitlab (
GITLAB
) - Infoblox DNS (
INFOBLOX_DNS
) - JumpCloud Directory Insights (
JUMPCLOUD_DIRECTORY_INSIGHTS
) - Kolide Endpoint Security (
KOLIDE
) - McAfee ePolicy Orchestrator (
MCAFEE_EPO
) - Microsoft Azure Activity (
AZURE_ACTIVITY
) - Microsoft Azure Resource (
AZURE_RESOURCE_LOGS
) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT
) - Microsoft SQL Server (
MICROSOFT_SQL
) - Netskope Web Proxy (
NETSKOPE_WEBPROXY
) - OpenSSH (
OPENSSH
) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR
) - Silverfort Authentication Platform (
SILVERFORT
) - Vectra Stream (
VECTRA_STREAM
) - VMware ESXi (
VMWARE_ESX
) - VMware NSX (
VMWARE_NSX
) - Windows Applocker (
WINDOWS_APPLOCKER
) - Windows Defender ATP (
WINDOWS_DEFENDER_ATP
) - Windows DNS (
WINDOWS_DNS
) - Windows Event (
WINEVTLOG
) - Windows Event (XML) (
WINEVTLOG_XML
) - Windows Hyper-V (
WINDOWS_HYPERV
) - Workspace ChromeOS Devices (
WORKSPACE_CHROMEOS
) - Zscaler (
ZSCALER_WEBPROXY
) - ZScaler DNS (
ZSCALER_DNS
)
The following log types, without a default parser, were added. Each is listed by product name and log_type
value, if applicable.
- ADVA Fiber Service Platform (
ADVA_FSP
) - Bluecat Address Manager (
BLUECAT_AM
) - Fortinet Switch (
FORTINET_SWITCH
) - GCP Google Kubernetes Engine Context (
GCP_KUBERNETES_CONTEXT
) - Kion (
KION
) - Kiteworks (
KITEWORKS
) - Nokia Router (
NOKIA_ROUTER
) - Ntopng (
NTOPNG
) - Opnsense (
OPNSENSE
) - Oracle HCM Human resources platform solution (
ORACLE_HCM
) - MS Powershell Transcript (
POWERSHELL_TRANSCRIPT
) - RAD ETX (
RAD_ETX
) - Spamhaus (
SPAMHAUS
) - UpGuard (
UPGUARD
) - Vsftpd (
VSFTPD
)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
The Cloud Data Fusion SAP SLT No RFC Replication plugin version 0.11.0 is available in the Hub in Cloud Data Fusion enterprise edition versions 6.8.0 and later. It differs from the existing SAP SLT Replication plugin in the following ways:
- All data and metadata file formats are in JSON.
- No SAP RFC inbound calls occur in the SAP SLT No RFC Replication plugin. Accessing schemas and data from the SAP system no longer requires an SAP connection. Metadata and data extraction are sourced from the Cloud Storage bucket.
Support for Customer Managed Encryption Keys (CMEK) is now available for Cloud Tasks. To learn more, see the documentation on using CMEK with Cloud Tasks.
For documents with many fields that don't require indexing, you can now add collection-level index exemptions on all fields in a collection group. To learn more, see Add a collection-level exemption. This feature is generally available (GA).
New SAP NetWeaver certification: C3D series of general-purpose machine types
For use with SAP NetWeaver, SAP has certified the Compute Engine general-purpose machine types c3d-standard
and c3d-highmem
.
For more information, see Certified C3D machine types for SAP NetWeaver.
Container Threat Detection, a built-in service of Security Command Center Premium, has launched a new detector, Unexpected Child Shell, in Preview.
The detector monitors all process executions and generates a finding if a process that does not normally invoke shells spawns a shell process.
For more information, see Container Threat Detection detectors.
October 17, 2023
Anthos Service MeshManaged Anthos Service Mesh 1.17 is rolling out in the rapid channel.
Additionally, the rollout of managed Anthos Service Mesh version 1.16 to the regular channel has completed.
See Select a managed Anthos Service Mesh release channel for more information.
hybrid v1.10.3-hotfix.3
On October 17, 2023 we released an updated version of the Apigee hybrid software, v1.10.3-hotfix.3.
- To install the hotfix, follow the instructions in Upgrading Apigee hybrid to version 1.10.
- For information on new installations, see The big picture.
Bug ID | Description |
---|---|
303292806 | Set backup utility to only connect to Cassandra server pods in the apigee namespace. |
300542690 | Added dedicated service accounts for Apigee Connect, Redis, and UDCA to prevent Kubernetes from automatically injecting credentials for a specified ServiceAccount or the default ServiceAccount. |
Service Extensions callouts are available for Google Cloud Application Load Balancers, excluding Classic.
By using this feature, you can direct your load balancers to make gRPC calls to user-managed or partner-hosted applications from within the Cloud Load Balancing data processing path. These applications can then apply various policies or functions, such as header or payload manipulation, security screening, or custom logging on the traffic before returning the traffic to the load balancer for further processing.
For details, see the following topics in the Service Extensions documentation:
Service Extensions is in Preview.
You can now view error groups on your custom dashboards. This feature is GA. For information when using the Cloud Console, see Display logs and errors on a custom dashboard. For information about using the API, see Dashboard with an ErrorReportingPanel widget.
Cloud SQL supports InnoDB page compression for MySQL 5.7 and MySQL 8.0 and later.
You can now import transaction log backups. This can help you reduce downtime when migrating to Cloud SQL using backups.
Query Optimizer version 6 is generally available, and is the default optimizer version.
Generally available: c3d-standard
, c3d-highmem
, c3d-highcpu
, and c3d-standard-lssd
machine types for general-purpose C3D VMs are generally available.
Release 3.2
All release notes published on this date are part of the 3.2 release.
Voice Virtual Agent assignment, transfers to parent queue: You can now assign voice Virtual Agent transfers to top-level queues. In the IVR, the end-user will hear all of the sub and leaf queue options below the top-level queue as long as they are active. See the Virtual Agents documentation for details.
New permissions added to call recordings and chat transcripts: A new role permission External Storage
is now available. This role offers you the ability to define whether users should have access to call recordings and/or chat transcripts when they are stored in external storage and without a CRM. When inactive, users won't be able to access these files from either the Completed
Calls or Chats monitoring pages or associated downloadable reports. Shared links to these files fall under the same permissions. See the Agent & team configuration page for more information.
New language support: Polish, Czech, Australian English, Hungarian is now supported for all channels. You can set up these new languages on the Settings > Languages & Messages page. See the language support page for a complete list of supported languages.
Kustomer API rate limit improvements: The API rate limits for customers integrating with Kustomer have been improved. see the Kustomer documentation for more information.
Call management: Agent status breakthrough: New feature Agent Status Breakthrough is now available. This feature allows you to to route incoming calls to agents, even when they are in a status that traditionally did not support receiving calls. This setting can be enabled at Operations Management > Agent Status. To designate a status as a breakthrough status, use the Edit function in the Agent Status List. The breakthrough status feature can be configured at the queue level as well as for specific DAPs. See the documentation for details.
Custom Notification Tones: You can now upload custom audio files for incoming call and chat notifications, as well as new chat messages. See the documentation for details.
Call recording: Third party recording without agent: You can now record calls if an agent leaves after adding a third party. This can be configured at Settings > Calls > Call Details > Call Recording. See the documentation for details.
Virtual Agent pass data parameters updates: CCAI Platform has enhanced the ability to pass session-based contextual data to Virtual Agents (VA). You can now leverage valuable real-time information during call routing and Dialogflow sessions. The following dynamic parameters are now available: DNIS / TFN (the number the user dialed), Latest Agent ID, Latest Agent Email, Queue Language, Latest Sentiment Score, and Overall Sentiment Score. Additionally, you can now configure static or dynamic CCAI Platform metadata parameters at the mobile queue level. See the data parameters page for details.
When an outbound campaign call fails during auto-dial due to telephony issues, the agent will now move into Available status rather than Wrap-up.
Fixed an issue where disabled Agent Statuses were still visible to custom roles.
Fixed an issue where agents were not moving into wrap up status after completing transfer to a queue with a Virtual Agent assigned to it.
Fixed an issue where agents were seeing calls on the Calls > Connected page that were disconnected. Calls in which no participant is detected as active will now be automatically cleared and finished.
ssh_authentication_config
and service_account
fields are available in the google_dataform_repository
Dataform Terraform resource.
You can now view error groups on your custom dashboards. This feature is GA. For information when using the Cloud Console, see Display logs and errors on a custom dashboard. For information about using the API, see Dashboard with an ErrorReportingPanel widget.
The sum()
and average()
aggregation functions are now available.
Service Extensions callouts are available for Google Cloud Application Load Balancers, excluding Classic.
With the introduction of this feature, users instruct load balancers to forward traffic from within the Cloud Load Balancing data processing path through gRPC to user-managed or partner-hosted applications. These applications can apply various policies or functions, such as header or payload manipulation, security screening, or custom logging on the traffic before returning the traffic to the load balancer for further processing.
For details, see Cloud Load Balancing extensions overview.
Personalized Service Health supports AlloyDB for PostgreSQL and Resource Manager API.
New Vertex AI Vector Search Console
Vector Search has launched a console experience in Google Cloud for creating and deploying indexes, now available in Preview. From the console, you can create indexes, and create public or VPC endpoints for your indexes, and deploy. For more information, see Manage indexes.
Vertex AI Vector Search Improvements
Vector Search has improved the initial index creation process for smaller indexes (<100MB), reducing time to build from about 1 hour to about 5 mins. To get started, see Vector Search quickstart to create an index.
October 16, 2023
App Engine flexible environment PythonPython 3.12 is now available in preview.
Python 3.12 is now available in preview.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigquery
2.33.2 (2023-10-11)
Bug Fixes
Dependencies
- Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.29.0 (#2911) (052f5c2)
- Update dependency com.google.apis:google-api-services-bigquery to v2-rev20230925-2.0.0 (#2921) (f0fb64f)
- Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.33.0 (#2912) (e053494)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.17.0 (#2931) (25a94f1)
- Update github/codeql-action action to v2.22.0 (#2926) (33ce4ae)
- Update github/codeql-action action to v2.22.1 (#2934) (7ae7b99)
- Update ossf/scorecard-action action to v2.3.0 (#2927) (93bfd8e)
You can now use DLP functions to support encryption and decryption between BigQuery and DLP, using AES-SIV. This feature is in preview.
The following changes are available in the Unified Data Model.
- New enum fields were added:
SecurityResult.IoCStatsType
andSecurityResult.VerdictType
. - A new field was added to
EntityMetadata
:feed
. - A new field was added to
Network
:ip_subnet_range
. - New fields were added to
SecurityResult
:last_updated_time
andverdict_info
. - A new field was added to
Label
:rbac_enabled
. - A new field was added to
SecurityResult.Association
:region_code
. - New fields were added to
User
:last_login_time
,last_password_change_time
,password_expiration_time
,account_expiration_time
,account_lockout_time
, andlast_bad_password_attempt_time
. - A new value was added to the
Network.ApplicationProtocol
enum:GRPC
. The following new values were added to the
Resource.ResourceType
enum:POD
CONTAINER
FUNCTION
RUNTIME
IP_ADDRESS
DISK
VOLUME
IMAGE
SNAPSHOT
REPOSITORY
CREDENTIAL
LOAD_BALANCER
GATEWAY
SUBNET
For a list of all fields in the Unified Data Model, and their descriptions, see the Unified Data Model field list.
A weekly digest of client library updates from across the Cloud SDK.
Airflow 2.6.3 is available in Cloud Composer images.
Airflow 2.6.3 consolidates the logic for handling tasks that are stuck in the queued state:
- The
[kubernetes]worker_pods_pending_timeout
,[celery]stalled_task_timeout
, and[celery]task_adoption_timeout
Airflow configuration options are deprecated and merged into the[scheduler]task_queued_timeout
option. - In Cloud Composer, the default value of the
[scheduler]task_queued_timeout
option is set to 40 minutes. - If your environment uses a custom value for any of the deprecated Airflow configuration options, please clear the overrides before upgrading. If the values are not cleared, the longest timeout of all deprecated options is selected upon upgrading.
- If required, you can override the value of the
[scheduler]task_queued_timeout
option in your environment. - For more information about other changes between Airflow versions 2.5.3 and 2.6.3, see Airflow release notes.
Cloud Composer 2.4.6 images are available:
- composer-2.4.6-airflow-2.6.3
- composer-2.4.6-airflow-2.5.3 (default)
- composer-2.4.6-airflow-2.4.3
Cloud Functions now supports the Python 3.12 runtime at the Preview release level.
You can now create log buckets in the us-west8 region. For a complete list of supported regions, see Supported regions.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-logging
3.15.11 (2023-10-10)
Dependencies
Changes to the Autoclass feature that were announced on July 17, 2023 begin taking effect today.
cos-105-17412-226-10
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.133 | v23.0.3 | v1.7.6 | v470.199.02(default),v535.104.05(latest) |
Updated app-containers/containerd to v1.7.6.
Synced TCPX changes to commit 90ce0a6aa201.
Updated cos-gpu-installer to v2.1.9.
Upgraded net-misc/curl to v8.4.0. This resolves CVE-2023-38545.
Fixed CVE-2023-38039 in net-misc/curl.
Fixed CVE-2023-4244 in the Linux kernel.
Fixed CVE-2023-5197 in the Linux kernel.
Fixed CVE-2023-42756 in COS kernel.
Fixed CVE-2023-42753 in the Linux kernel.
cos-101-17162-336-7
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.133 | v20.10.24 | v1.6.21 | v470.199.02(default),v535.104.05(latest) |
Fixed CVE-2022-48560 in dev-lang/python package.
Upgraded net-misc/curl to v8.4.0. This resolves CVE-2023-38545.
Fixed CVE-2023-38039 in net-misc/curl.
Fixed CVE-2023-5197 in the Linux kernel.
Fixed CVE-2023-42756 in COS kernel.
Fixed CVE-2023-42753 in the Linux Kernel.
Runtime sysctl changes:
- Changed: fs.file-max: 813043 -> 813032
- Changed: kernel.threads-max: 63551 -> 63552
- Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_recd: 0 -> 3
- Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_sent: 0 -> 3
- Changed: user.max_cgroup_namespaces: 31775 -> 31776
- Changed: user.max_ipc_namespaces: 31775 -> 31776
- Changed: user.max_mnt_namespaces: 31775 -> 31776
- Changed: user.max_net_namespaces: 31775 -> 31776
- Changed: user.max_pid_namespaces: 31775 -> 31776
- Changed: user.max_time_namespaces: 31775 -> 31776
- Changed: user.max_user_namespaces: 31775 -> 31776
- Changed: user.max_uts_namespaces: 31775 -> 31776
cos-97-16919-353-53
Kernel | Docker | Containerd | GPU Drivers |
COS-5.10.186 | v20.10.24 | v1.6.21 | v470.199.02(default),v535.104.05(latest) |
Updated cos-gpu-installer to v2.1.9.
Fixed CVE-2023-38039 in net-misc/curl.
Fixed CVE-2023-42753 in the Linux Kernel.
cos-93-16623-461-40
Kernel | Docker | Containerd | GPU Drivers |
COS-5.10.177 | v20.10.24 | v1.6.20 | v450.248.02(default),v535.104.05(latest),v470.199.02(R470 for compatibility with K80 GPUs) |
Upgraded net-misc/curl to v8.4.0. This resolves CVE-2023-38545.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for dataflow/apiv1beta3
0.9.2 (2023-10-12)
Bug Fixes
- dataflow: Update golang.org/x/net to v0.17.0 (174da47)
Dataproc Metastore now supports multi-regional configurations.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-datastore
2.17.3 (2023-10-10)
Dependencies
Architecting disaster recovery for cloud infrastructure outages: Added DR guidance for Access Transparency.
Filestore Enterprise now supports backups on GKE, allowing you to make reliable copies of your data to be stored for later use. To trigger backups on Filestore Enterprise, use Kubernetes volume snapshots. Backups are currently not supported for Filestore Enterprise instances with multishares enabled.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-pubsub
1.125.6 (2023-10-10)
Dependencies
- Update dependency com.google.cloud:google-cloud-bigquery to v2.33.1 (#1756) (239f474)
- Update dependency com.google.cloud:google-cloud-core to v2.25.0 (#1764) (72404ea)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.17.0 (#1765) (a447292)
- Update dependency com.google.protobuf:protobuf-java-util to v3.24.4 (#1760) (10a64c6)
Public preview: Pub/Sub BigQuery subscriptions now support BigQuery change data capture.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for secretmanager/apiv1
1.11.2 (2023-10-12)
Bug Fixes
- secretmanager: Update golang.org/x/net to v0.17.0 (174da47)
The Long Audio Synthesis API now supports the following languages: English, Spanish, French, German, Japanese, Hindi, Italian, Korean, Portuguese, Thai, Vietnamese, Danish, Filipino.
There is no longer billing differentiation for Cloud Text-to-Speech Offline Custom Voice API calls. See the <ReportedUsage>
documentation for more details.
October 13, 2023
Apigee XOn October 13, 2023, we released an updated version of Apigee (1-11-0-apigee-6).
Bug ID | Description |
---|---|
304681330 | Security fix for apigee-ingress. This addresses the following vulnerability: CVE-2023-44487 |
305127632 | Security bulletin published. GCP-2023-032 |
Description
A Denial-of-Service (DoS) vulnerability was recently discovered in multiple implementations of the HTTP/2 protocol (CVE-2023-44487), including the Apigee Ingress (Anthos Service Mesh) server used by Apigee X. The vulnerability could lead to a DoS of Apigee API management functionality.
Affected Products
Deployments of Apigee X that are accessible through a Google Cloud Network Load Balancer (Layer 4), or a custom layer 4 load balancer, are affected. A hotfix is being applied to all Apigee X instances. Your Apigee X instances will be automatically updated within the next few days.
Unaffected products
Apigee X instances which are accessed only via Google Cloud Application Load Balancers (Layer 7) are not affected. This includes deployments that have HTTP/2 enabled for gRPC proxies.
What Should I Do?
All Apigee X instances will be automatically updated within the next few days. Customers do not need to take any actions.
What Vulnerabilities Are Addressed By These Patches?
The vulnerability, CVE-2023-44487, allows an attacker to execute a denial-of-service attack on Apigee ingresses.
hybrid v1.10.3-hotfix.2
On October 13, 2023 we released an updated version of the Apigee hybrid software, v1.10.3-hotfix.2.
- To install the hotfix, follow the instructions in Upgrading Apigee hybrid to version 1.10.
- For information on new installations, see The big picture.
Bug ID | Description |
---|---|
304681330 | Security fix for apigee-ingress. This addresses the following vulnerability: CVE-2023-44487 |
305127632 | Security bulletin published. GCP-2023-032 |
hybrid v1.9.4-hotfix.1
On October 13, 2023 we released an updated version of the Apigee hybrid software, v1.9.4-hotfix.1.
- To install the hotfix, follow the instructions in Upgrading Apigee hybrid to version 1.9.
- For information on new installations, see The big picture.
Bug ID | Description |
---|---|
304681330 | Security fix for apigee-ingress. This addresses the following vulnerability: CVE-2023-44487 |
305127632 | Security bulletin published. GCP-2023-032 |
Description
A Denial-of-Service (DoS) vulnerability was recently discovered in multiple implementations of the HTTP/2 protocol (CVE-2023-44487), including the Apigee Ingress (Anthos Service Mesh) server used by Apigee hybrid. The vulnerability could lead to a DoS of Apigee API management functionality.
Affected Products
Apigee hybrid instances that allow HTTP/2 requests to reach the Apigee Ingress are affected. Customers should verify if the load balancers fronting their Apigee hybrid ingresses allow for HTTP/2 requests to reach the Apigee Ingress service.
What Should I Do?
Apigee hybrid customers will need to upgrade to one of the following patch versions:
- v1.10.3-hotfix.2 which will be released by Friday, October 13, 2023
- v1.9.4-hotfix.1 which will be released by Friday, October 13, 2023
What Vulnerabilities Are Addressed By These Patches?
The vulnerability, CVE-2023-44487, allows an attacker to execute a denial-of-service attack on Apigee ingresses.
Generally available: C3 VMs support Compute Engine flexible committed use discounts (CUDs).
Compute Engine flexible CUDs allow you to commit to a minimum hourly spend amount and use vCPUs and/or memory in any of the projects within your Cloud Billing account, across any region, and belonging to any eligible machine types. Learn more about Compute Engine Flexible CUDs and how to purchase flexible commitments.
If you want to modify a future reservation request using the Compute Engine API, the paths
query parameter is deprecated. Instead, use the updateMask
query parameter.
For more information, see Modify future reservation requests.
Preview: You can now use workforce identity federation with OS Login.
Formatting of Dataform core and JavaScript code is available.
New Dataproc Serverless for Spark runtime versions:
- 1.1.35
- 2.0.43
- 2.1.22
(2023-R20) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- The following control plane and node versions are now available:
- The following control plane versions are no longer available: 1.24.17-gke.1963000, 1.25.14-gke.1256000, 1.26.9-gke.1256000
Stable channel
- There are no new releases in the Stable release channel.
Regular channel
- There are no new releases in the Regular release channel.
Rapid channel
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel: 1.24.17-gke.1963000, 1.25.14-gke.1256000, 1.26.9-gke.1256000
Containers running in nodes in GKE version 1.28.1-gke.201 or later don't need to have privileged mode enabled to access TPUs. When upgrading a cluster to 1.28.1-gke.201 or later, we recommend removing privileged: true
from the securityContext
of any TPU workload. To learn more, see Deploy TPU workloads.
Starting in GKE 1.28.1-gke.1066000, two new TPU usage metrics are available: TensorCore utilization and Memory Bandwidth utilization.
(2023-R20) Version updates
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel: 1.24.17-gke.1963000, 1.25.14-gke.1256000, 1.26.9-gke.1256000
(2023-R20) Version updates
- The following control plane and node versions are now available:
- The following control plane versions are no longer available: 1.24.17-gke.1963000, 1.25.14-gke.1256000, 1.26.9-gke.1256000
Vertex AI Search: Customer-managed encryption key integration for the EU
Customer-managed encryption keys (CMEK) is available in the EU as an allowlisted preview feature.
If you store your data in an EU multi-region data store, you can provide your own encryption key to protect your data at rest.
For information, see Customer-managed encryption keys.
October 12, 2023
Access ApprovalAccess Approval supports Access Context Manager in the GA stage.
Access Transparency supports Access Context Manager in the GA stage.
Anthos clusters on VMware 1.15.5-gke.41 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.15.5-gke.41 runs on Kubernetes 1.26.7-gke.2500.
The following issues are fixed in 1.15.5-gke.41:
- Fixed the issue that server-side preflight checks fail to validate container registry access on clusters with a private network and no private registry.
- Fixed the known issue where a non-HA Controlplane V2 cluster is stuck at node deletion until it timesout.
- Fixed the known issue where upgrading or updating an admin cluster with a CA version greater than 1 fails.
- Fixed the issue where the Controlplane V1 stackdriver operator has
--is-kubeception-less=true
specified by mistake. - Fixed the known issue that causes the secrets encryption key to be regenerated when upgrading the admin cluster from 1.14 to 1.15, resulting in the upgrade being blocked.
The following vulnerabilities are fixed in 1.15.5-gke.41:
High-severity container vulnerabilities:
Container-optimized OS vulnerabilities:
Ubuntu vulnerabilities:
The following geography functions are now generally available (GA):
ST_LINESUBSTRING
: Gets a segment of a single linestring at a specific starting and ending fraction.ST_HAUSDORFFDISTANCE
: Gets the discrete Hausdorff distance between two geometries.
New searchable fields are now available.
The following searchable fields are now publicly available through the resource search API (SearchAllResources
).
effectiveTagKeys
effectiveTagValues
effectiveTagValueIds
The following search result fields are now publicly available through the resource search API (SearchAllResources
).
tags
effectiveTags
You can now configure the format of the timestamp in your query results in the Logs Explorer. For more information, see Logs Explorer overview: Configure the Time column.
The Node.js and Python client libraries now have parallelized upload and download options, improving their performance.
- Both client libraries have improved bulk uploads, bulk downloads, large object uploads, and large object downloads.
Preview: The following metrics are now available to help you monitor your Persistent Disk and Hyperdisk volume performance:
Average I/O latency (
compute.googleapis.com/instance/disk/average_io_latency
)Average I/O queue depth (
compute.googleapis.com/instance/disk/average_io_queue_depth
)
To learn more about these metrics and how to view them, see Review disk metrics.
New Dataproc on Compute Engine subminor image versions:
- 2.0.80-debian10, 2.0.80-rocky8, 2.0.80-ubuntu18
- 2.1.28-debian11, 2.1.28-rocky8, 2.1.28-ubuntu20, 2.1.28-ubuntu20-arm
Dialogflow CX generative feedback now supports more languages.
Dialogflow CX launched generative playbooks with restricted access.
Dialogflow CX spelling correction now supports all regions, but is limited to five languages.
Cloud Storage Backint agent for SAP HANA version 1.0.30
Version 1.0.30 of the Cloud Storage Backint agent for SAP HANA is available. This version reverts the google-cloud-storage
client library to an earlier version so that API call retries work correctly.
For more information about the agent, see Cloud Storage Backint agent for SAP HANA overview.
You can now transfer data from Amazon S3 via your CloudFront domain. Learn more.
October 11, 2023
AlloyDB for PostgreSQLAlloyDB Omni is now generally available (GA).
In AlloyDB Omni version 15.2.1 and earlier, after a failover, when you promote a standby instance, incremental backups from the newly promoted instance might conflict with the existing backup files, and the backups might fail.
As a workaround, move the conflicting files into a separate directory.
The AlloyDB Omni Kubernetes Operator is now available in Preview. This extension to the Kubernetes API lets you deploy and manage AlloyDB Omni on a Kubernetes cluster.
Users can now set an IP range size and starting IP address for private connections in Bitbucket Data Center using the peeredNetworkIpRange
. This feature is generally available. To learn more, see Build repositories in Bitbucket Data Center in a private network.
Cloud Functions (2nd gen) now supports Shared VPC ingress at the General Availability release level. Shared VPC traffic is now considered "internal" for functions that are connected to the Shared VPC network.
Shared VPC ingress is now at general availability (GA). Shared VPC traffic is now considered "internal" for Cloud Run services that are connected to the Shared VPC network.
Cloud Spanner has made improvements that provide higher throughput for instances located in select Spanner regional and multi-region instance configurations. These improvements are available without additional cost or any configuration changes. For more information, see Performance improvements.
Colab Enterprise is now generally available (GA). Colab Enterprise combines the popular collaborative features of Colaboratory with the security and compliance capabilities of Google Cloud. Colab Enterprise includes:
- Sharing and collaborating functionality, with IAM access control.
- Google-managed compute and runtime provisioning, with configurable runtime templates.
- Integrations with Vertex AI and BigQuery.
- Inline code completion with Duet AI (Preview) assistance.
- End-user credential authentication for running your notebook code.
- Idle shutdown for runtimes (Experimental).
To get started, see Introduction to Colab Enterprise or create a notebook and start coding.
Generally available: You can configure stateful IP addresses in a managed instance group. Stateful IP addresses are preserved when VM instances in the group are repaired, updated, and re-created. For more information, see Configuring stateful IP addresses in MIGs.
cos-dev-113-17965-0-0
Kernel | Docker | Containerd | GPU Drivers |
COS-6.1.55 | v24.0.5 | v1.7.6 | v535.104.05(default, latest),v470.199.02(R470 for compatibility with K80 GPUs) |
Upgraded app-containers/containerd to v1.7.6.
Upgraded cos-gpu-installer to v2.1.9.
Upgraded dev-util/gn to v2121.
Upgraded chromeos-base/google-breakpad to v2023.06.01.191934-r222.
Upgraded chromeos-base/debugd-client to v0.0.1-r2559.
Upgraded chromeos-base/shill-client to v0.0.1-r4030.
Upgraded chromeos-base/chromeos-common-script to v0.0.1-r561.
Upgraded chromeos-base/session_manager-client to v0.0.1-r2649.
Fixed CVE-2023-4911 in sys-libs/glibc.
Fixed CVE-2023-38039 in net-misc/curl.
Fixed CVE-2023-42756 in COS kernel.
Fixed CVE-2023-5345 in COS kernel.
Fixed CVE-2023-5197 in the Linux kernel.
cos-93-16623-461-39
Kernel | Docker | Containerd | GPU Drivers |
COS-5.10.177 | v20.10.24 | v1.6.20 | v450.248.02(default),v535.104.05(latest),v470.199.02(R470 for compatibility with K80 GPUs) |
Upgraded cos-gpu-installer to v2.1.9.
Fixed CVE-2023-38039 in net-misc/curl.
Fixed CVE-2023-42753 in the Linux Kernel.
cos-97-16919-353-53
Kernel | Docker | Containerd | GPU Drivers |
COS-5.10.186 | v20.10.24 | v1.6.21 | v470.199.02(default),v535.104.05(latest) |
Upgraded cos-gpu-installer to v2.1.9.
Fixed CVE-2023-38039 in net-misc/curl.
Fixed CVE-2023-42753 in the Linux Kernel.
cos-105-17412-156-69
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.120 | v23.0.3 | v1.7.2 | v470.199.02(default),v535.104.05(latest) |
Upgraded cos-gpu-installer to v2.1.9.
Fixed CVE-2023-38039 in net-misc/curl.
Fixed CVE-2023-42753 in the Linux kernel.
cos-109-17800-0-51
Kernel | Docker | Containerd | GPU Drivers |
COS-6.1.42 | v24.0.5 | v1.7.2 | v535.104.05(default, latest),v470.199.02(R470 for compatibility with K80 GPUs) |
Fixed CVE-2023-38039 in net-misc/curl.
Fixed CVE-2023-5197 in the Linux kernel.
API 3.0 and API 3.1 have been removed in Looker 23.18.
Clustrix database support has been removed. Any existing connections to a Clustrix database will fail to run in Looker 23.18.
Performance improvements have been made to query preparation time by front-loading LookML model compilation during production deployments.
To prevent confusion with SSO authentication, the SSO embed feature has been renamed Signed embed.
For LookML projects that use the New LookML Runtime, an error has been added: "Datagroup names may only include letters, numbers and underscores." Starting in Looker 23.18, datagroups will generate an error if they contain hyphens or any characters besides letters, numbers, and underscores.
The Get embed URL option from a dashboard, a Look, or an Explore can now generate a signed embed URL.
Embedded Looks now support themes, so the Get embed URL dialog now shows a theme selector for Looks.
The manage_project_connections_restricted
permission lets users edit a subset of settings for new and existing connections.
The New Schedules Page Labs feature updates the interface of the Admin settings - Schedules page.
An issue with drilling for transposed tables has been fixed. Drilling for transposed tables now performs as expected.
The Box Shadow theme now performs as expected for static and tile LookML dashboards.
Fixed date field values were not being displayed correctly when referenced by Liquid in the label
or html
LookML parameter. This feature now performs as expected.
Unreferenced custom fields from drill URL have been removed.
Looker 23.18 includes the following changes, features, and fixes.
Expected Looker (original) deployment start: Monday, October 16, 2023
Expected Looker (original) final deployment and download available: Thursday, October 26, 2023
Expected Looker (Google Cloud core) deployment start: Monday, October 23, 2023
Expected Looker (Google Cloud core) final deployment: Friday, November 3, 2023
Public preview is now available for the Open SQL Interface. The Open SQL Interface allows access to Looker models and Explores for applications (such as Tableau) that use JDBC to connect to data sources. For Looker (original) instances, enable the SQL Interface Experimental Labs feature on the Looker instance. (Only Looker-hosted instances support this Labs feature.) For Looker (Google Cloud core) instances, fill out the Looker SQL Interface Pre-GA Agreement interest form. The Google team will enable your instance for the SQL Interface feature.
IAM permissions have been clarified and made more visible in the Looker (Google Cloud core) documentation.
The in-app support in the Help menu has been updated to integrate with the Google Cloud console. You will see in-app support only if you have purchased at least a Standard Support service with Google Cloud Customer care.
Preview: Migrate to Virtual Machines now supports migrating VMs to the C3, H3, and M3 machine types. These machine types support non-volatile memory express (NVMe) and Google Virtual NIC (gVNIC). Before you migrate your VMs to any of these machine types, ensure that source VMs support NVMe and gVNIC. For more information on different machine types that support NVMe and gVNIC, go to the Machine series comparison section, click Choose VM properties to compare, and select Disk interface type and Network interfaces.
October 10, 2023
Anthos Service Mesh1.18.4-asm.0 is now available for in-cluster Anthos Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2023-031 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
1.17.7-asm.0 is now available for in-cluster Anthos Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2023-031 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
1.16.7-asm.10 is now available for in-cluster Anthos Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2023-031 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
The following new data transformer functions are available:
Manifest XML - Converts the specified input JSON object into an XML string.
Parse XML - Parses the specified input XML string into a JSON object.
IAM Conditions for fine-grained access
IAM Conditions lets you define and enforce conditional, attribute-based access control for Google Cloud resources, including Application Integration resources. For more information, see Add IAM conditions.
You can now view the detailed summary of an integration from the Integration designer. For more information, see View integration details.
The following new data transformer functions are available:
Manifest XML - Converts the specified input JSON object into an XML string.
Parse XML - Parses the specified input XML string into a JSON object.
IAM Conditions for fine-grained access
IAM Conditions lets you define and enforce conditional, attribute-based access control for Google Cloud resources, including Application Integration resources. For more information, see Add IAM conditions.
You can now view the detailed summary of an integration from the Integration designer. For more information, see View integration details.
Support for user-defined service account
You can now configure a service account of your choice for an integration. The option to select a service account is displayed to you during the integration creation step.
While creating a custom parser, you can use the preview option to view the UDM output. In the preview, you can use the statedump filter plugin to validate the internal state of a parser. For more information, see Validate data using statedump plugin.
The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning).
- MachineImage for Compute Engine
compute.googleapis.com/MachineImage
A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.
Starting October 10, 2023, mirror.gcr.io
is transitioning to being hosted on Artifact Registry. This change is taking place on a region by region basis, and doesn't require you to change your usage of mirror.gcr.io
unless you are using it within a VPC service perimeter.
For information on how to use mirror.gcr.io
in a VPC service perimeter after the transition to being hosted on Artifact Registry, see Using Artifact Registry with VPC Service Controls.
M112 release
- Miscellaneous bug fixes and improvements.
M112 release
- CUDA 12.1 VM images are available with the following image names:
common-cu121-debian-11-py310
common-cu121-ubuntu-2004-py310
- Miscellaneous bug fixes and improvements.
Deletion operation can't be successful when raw document is missing
A Denial-of-Service (DoS) vulnerability was recently discovered in multiple implementations of the HTTP/2 protocol (CVE-2023-44487), including the golang HTTP server used by Kubernetes. The vulnerability could lead to a DoS of the Google Kubernetes Engine (GKE) control plane. GKE clusters with authorized networks configured are protected by limiting network access, but all other clusters are affected. For more information, see the GCP-2023-030 security bulletin.
Generally Available: Migrate to Virtual Machines from an Azure source lets you migrate VM instances running on Azure to Google Cloud Compute Engine.
M112 release
The M112 release of Vertex AI Workbench user-managed notebooks includes the following:
- Miscellaneous bug fixes and improvements.
October 09, 2023
BatchJob limits have increased to 100,000 tasks per task group and 5,000 parallel tasks per job. Learn more about Quotas and limits.
The BeyondCorp Enterprise Policy Remediator is in Preview. You can use the Policy Remediator to provide users with actionable steps that they can take to remediate access denied issues.
For more information, see Remediate denied access with the Policy Remediator.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for bigquery/storage/apiv1beta1
1.56.0 (2023-10-05)
Features
- bigquery/analyticshub: Add Subscription resource and RPCs (#8612) (9992249)
- bigquery: Add external dataset reference (#8545) (1001acf)
- bigquery: Add media options to LoadConfig (#8640) (62baf56)
Bug Fixes
- bigquery/storage/managedwriter: Automatic retry for multiplex test (#8601) (6ef1945)
- bigquery: Dependency detection on proto conversion (#8566) (763ab5d)
Documentation
- bigquery/datatransfer: Update transferConfig.name description to indicate that it supports both formats (0449518)
Python
Changes for google-cloud-bigquery
3.12.0 (2023-10-02)
Features
- Add
Dataset.storage_billing_model
setter, useclient.update_dataset(ds, fields=["storage_billing_model"])
to update (#1643) (5deba50) - Search statistics (#1616) (b930e46)
- Widen retry predicate to include ServiceUnavailable (#1641) (3e021a4)
Bug Fixes
- Allow
storage_billing_model
to be explicitly set toNone
to use project default value (#1665) (514d3e1) - Relax timeout expectations (#1645) (1760e94)
- Use isinstance() per E721, unpin flake8 (#1659) (54a7769)
Documentation
Queries now support additional ways to work with grouping sets, which include:
GROUP BY GROUPING SETS
clause (new): Produce aggregated data for one or more grouping sets.GROUP BY CUBE
clause (new): Produce aggregated data for all grouping set permutations.GROUP BY ROLLUP
clause (update): You can now include groupable items sets in this clause.GROUPING
function (new): Check if a groupable value in theGROUP BY
clause is aggregated.
This feature is in preview.
Adding descriptions to the columns of a view is now generally available (GA). Use the CREATE VIEW
or ALTER COLUMN
DDL statements to add descriptions.
BigQuery is now available in the Dammam (me-central2) region.
BigQuery ML is now available in the Dammam (me-central2) region.
BigQuery Data Transfer Service is now available in the Dammam (me-central2) region.
A weekly digest of client library updates from across the Cloud SDK.
A weekly digest of client library updates from across the Cloud SDK.
Python
Changes for google-cloud-logging
3.8.0 (2023-10-03)
Features
When you install the Ops Agent on a Compute Engine VM by using the Cloud Monitoring VM Instances dashboard or the Observability tab on a Compute Engine VM details page, the agent is now installed with an Ops Agent OS policy. This installation method replaces the prior set of manual steps. For more information, see Installing the agent by using the Google Cloud console.
When you install the Ops Agent on a Compute Engine VM by using the Cloud Monitoring VM Instances dashboard or the Observability tab on a Compute Engine VM details page, the agent is now installed with an Ops Agent OS policy. This installation method replaces the prior set of manual steps. For more information, see Installing the agent by using the Google Cloud console.
The cross db ownership chaining
flag is deprecated for all SQL Server versions.
For cross-database access, use the Microsoft tutorial for signing stored procedures with a certificate.
Cloud Spanner batch write is now available in Preview. You can use Spanner batch write to commit multiple mutations non-atomically in a single request with low latency. For more information, see Modify data using batch write.
Cloud Spanner Vertex AI integration now supports Vertex AI Generative AI text embeddings and the text-bison
model. For more information, see Get Vertex AI text embeddings.
When you install the Ops Agent on a Compute Engine VM by using the Observability tab on a Compute Engine VM details page, the agent is now installed with an Ops Agent OS policy. This installation method replaces the prior set of manual steps. For more information, see Installing the agent by using the Google Cloud console.
Generally available: H3 VMs, designed for compute-intensive high performance computing (HPC) workloads, are now generally available. For more information, see H3 machine series.
You can now use the CCAI Insights API to ingest audio conversation data in bulk from a Cloud Storage bucket. Optionally, you can apply redaction prior to import and transcribe the audio using custom Speech-to-Text settings. See the documentation for details.
Announcing the General Availability (GA) release of Dataproc Serverless for Spark Interactive sessions.
A weekly digest of client library updates from across the Cloud SDK.
Node.js
Changes for @google-cloud/datastore
8.2.1 (2023-10-03)
Bug Fixes
8.2.0 (2023-10-02)
Features
Bug Fixes
Go
Changes for datastore/admin/apiv1
1.15.0 (2023-10-06)
Features
Bug Fixes
Best practices for running tightly coupled HPC applications: Updated to include guidance for H3 compute-optimized VMs.
Architectures for high availability of PostgreSQL clusters on Compute Engine: Added information about the write-ahead log and the Log Sequence Number.
If you are using a third generation machine series (for example, C3), GKE configures Local SSD volumes as the local ephemeral storage by default. You no longer need to specify the --ephemeral-storage-local-ssd
flag when provisioning clusters or node pools. When you configure Local SSD volumes as raw block storage with the --local-nvme-ssd-block
flag, specifying the count
value is now optional.
Cloud IDS threat detections available in Security Command Center
Threats that are detected by Cloud IDS, a Google Cloud intrusion detection service, are now included in the findings that are issued by the Event Threat Detection service of Security Command Center. This feature is available in Preview.
For more information, see:
- Cloud IDS in Event Threat Detection rules
- Cloud IDS overview
'ta mount' and 'ta unmount' are command line tools offering the user the ability to mount their own NFS or CIFS shares onto the appliance.
Learn more about how to mount to an appliance.
Vertex AI Search and Conversation: Renamed in the console and documentation
The Google Cloud console and the documentation at cloud.google.com have been updated to show the current product name for Vertex AI Search and Conversation. On the console, look for "Search and Conversation".
You might see the old name (Generative AI App Builder) in some places—for example, in the API reference.
October 06, 2023
Apigee Advanced API SecurityOn October 6, 2023, we released an updated version of Advanced API Security.
Public Preview of Advanced API Security Actions
Advanced API Security's new Security Actions feature lets you create security actions that define how Apigee handles detected traffic. You can create the following security actions:
Deny actions, which deny requests that meet specified conditions, for example, originating at an IP address that has been identified as a source of abuse.
Flag actions, which let requests pass through, but add headers to requests to identify them as suspicious.
Allow actions, which are used to override deny actions in specific cases when the request is trusted.
Backup and DR Service 11.0.7.404 is now available to update your backup/recovery appliance. Refer to these instructions to update your appliance.
The new Backup and DR Service update policy requires updating all backup/recovery appliances older than version 11.0.3 to maintain product support and avoid restrictions on enabling backups for new entities. Learn more.
Added support to restore PostgreSQL database backup images to an alternate location. Learn more.
Backup and DR agent is enhanced to support Rocky Linux 8.7 operating system version. See support matrix.
Backup and DR agent now supports Rocky Linux 8.7 on Oracle 19c database. See support matrix.
Backup and DR agent now supports RHEL 8.4 on Oracle 21c database. See support matrix.
Cloud Bigtable instance, cluster, and table metadata is automatically synced to Data Catalog, a feature of Dataplex, for improved data discovery and governance. This feature is generally available (GA).
The Cloud Healthcare API offers multi-region support in the Europe (eu) region.
Generally available: NVIDIA L4 GPUs are now available in the following additional regions and zones:
- APAC
- Seoul, South Korea (
asia-northeast3-b
)
- Seoul, South Korea (
- Europe
- St. Ghislain, Belgium (
europe-west1-b
) - Frankfurt, Germany (
europe-west3-b
)
- St. Ghislain, Belgium (
- North America
- Council Bluffs, Iowa: (
us-central1-c
) - Las Vegas, Nevada (
us-west4-a,c
)
- Council Bluffs, Iowa: (
For more information about using GPUs on Compute Engine, see GPU platforms.
New Dataproc on Compute Engine image version 2.2
is available for preview with upgraded components.
New Dataproc on Compute Engine subminor image versions:
- 2.0.79-debian10, 2.0.79-rocky8, 2.0.79-ubuntu18
- 2.1.27-debian11, 2.1.27-rocky8, 2.1.27-ubuntu20, 2.1.27-ubuntu20-arm
- 2.2.0-RC2-debian11, 2.2.0-RC2-rocky9, 2.2.0-RC2-ubuntu22
Upgraded Hadoop version from 3.3.3
to 3.3.6
in the latest Dataproc on Compute Engine 2.1 image version.
New Dataproc Serverless for Spark runtime versions:
- 1.1.34
- 2.0.42
- 2.1.21
Upgraded the Cloud Storage connector version to 2.2.17 in the latest Dataproc Serverless for Spark runtimes.
Added the gs.http.connect-timeout
and gs.http.read-timeout
properties in Flink to
set the connection timeout and read timeout for java-storage client
in the latest Dataproc on Compute Engine 2.1 image version.
Added the gs.filesink.entropy.enabled
property in Flink to enable entropy
injection in filesink Cloud Storage path in the latest Dataproc on Compute Engine 2.1 image version.
A previously published release note on December 14, 2022 has been updated. Support for migration of GKE Autopilot clusters' datapath provider to Dataplane V2 has been paused. We will update this release note when migration support resumes.
October 05, 2023
Access TransparencyAccess Transparency supports Firebase Security Rules in the Preview stage.
On October 5, 2023 we released an updated version of Apigee integrated portal. This release includes general improvements to performance and availability.
Batch is available in the following regions:
australia-southeast2
(Melbourne)europe-west8
(Milan)europe-west12
(Turin)me-west1
(Tel Aviv)northamerica-northeast2
(Toronto)southamerica-east1
(São Paulo)us-east5
(Columbus)
For more information, see Locations.
The BigQuery migration assessment is now available for Snowflake in preview. You can use this feature to assess the complexity of migrating data from your Snowflake data warehouse to BigQuery.
Certificate Authority Service is now available in the following region:
- me-central2
For more information, see Certificate Authority Service locations.
The following supported default parsers have changed. Each is listed by product name and log_type
value, if applicable.
- AWS Cloudtrail (
AWS_CLOUDTRAIL
) - Azion (
AZION
) - Azure AD Organizational Context (
AZURE_AD_CONTEXT
) - Blue Coat Proxy (
BLUECOAT_WEBPROXY
) - Cisco ACS (
CISCO_ACS
) - Cisco FireSIGHT Management Center (
CISCO_FIRESIGHT
) - Cisco ISE (
CISCO_ISE
) - Cisco Umbrella DNS (
UMBRELLA_DNS
) - Cloud Intrusion Detection System (
GCP_IDS
) - Cloudflare (
CLOUDFLARE
) - Compute Context (
N/A
) - Corelight (
CORELIGHT
) - Darktrace (
DARKTRACE
) - F5 ASM (
F5_ASM
) - FireEye (
FIREEYE_ALERT
) - HAProxy (
HAPROXY
) - Hashicorp Vault (
HASHICORP
) - HP Procurve Switch (
HP_PROCURVE
) - IBM Security Verify SaaS (
IBM_SECURITY_VERIFY_SAAS
) - Imperva (
IMPERVA_WAF
) - Ionix (
IONIX
) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT
) - MISP Threat Intelligence (
MISP_IOC
) - Office 365 (
OFFICE_365
) - Oracle Cloud Infrastructure Audit Logs (
OCI_AUDIT
) - Sendmail (
SENDMAIL
) - Tanium Audit (
TANIUM_AUDIT
) - Tanium Stream (
TANIUM_TH
) - Thycotic (
THYCOTIC
) - Unix system (
NIX_SYSTEM
) - VMware ESXi (
VMWARE_ESX
) - VMware NSX (
VMWARE_NSX
) - VMware vCenter (
VMWARE_VCENTER
) - WatchGuard (
WATCHGUARD
) - Windows DNS (
WINDOWS_DNS
) - Windows Event (
WINEVTLOG
) - Workspace Activities (
WORKSPACE_ACTIVITY
) - Workspace Alerts (
WORKSPACE_ALERTS
) - Zeek JSON (
BRO_JSON
) - Zscaler CASB (
ZSCALER_CASB
)
The following log types, without a default parser, were added. Each is listed by product name and log_type
value, if applicable.
- AWS_EMR (
AWS_EMR
) - Azure Application Gateway (
AZURE_GATEWAY
) - CloudBolt (
CLOUDBOLT
) - DNSFilter (
DNSFILTER
) - GitGuardian Enterprise (
GITGUARDIAN_ENTERPRISE
) - GoAnywhere MFT (
GOANYWHERE_MFT
) - IBM Security Identity Manager (
IBM_SIM
) - Jamf Pro MDM (
JAMF_PRO_MDM
) - MultiPay (
MULTIPAY
) - Palo Alto Networks IoT Security (
PAN_IOT
) - Raritan Dominion SX II (
RARITAN_DOMINION
)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
Cloud Composer 2 is now available in Milan (europe-west8), Berlin (europe-west10), and Turin (europe-west12).
Fixed a problem where newly-created Airflow workers ignored the SIGTERM signal, which could lead to task failures.
Cloud Composer 2.4.5 images are available:
- composer-2.4.5-airflow-2.5.3 (default)
- composer-2.4.5-airflow-2.4.3
Ops Agent version 2.42.0 introduces support for Compute Engine Arm VMs that are running Ubuntu 22.04 LTS (Jammy Jellyfish). For more information, see Support for Compute Engine Arm VMs.
Dashboard-wide filters now apply to the Logs Panel widget. For more information, see Filter the log entries.
Cloud Spanner sampled query plans are now available in GA. You can view samples of historic query plans and compare the performance of a query over time. For more information, see Sampled query plans.
Cloud TPU now supports TensorFlow 2.13.1. For more information see the TensorFlow 2.13.1 release notes.
You can now show logs and events as inline messages when exploring a trace. For more information, see Find and explore traces.
(2023-R19) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- The following control plane and node versions are now available:
Stable channel
- The following version is no longer available in the Stable channel: 1.26.5-gke.2100
Regular channel
- There are no new releases in the Regular release channel.
Rapid channel
- The following versions are now available in the Rapid channel:
An issue was previously reported with running certain commands in container images when Image streaming is enabled. See the August 31, 2023 release note for details. This issue is fixed in the following minor versions:
- 1.25 with the patch versions 1.25.14-gke.1351000 and later.
- 1.25 with the patch versions 1.26.9-gke.1345000 and later.
- 1.27 with the patch versions 1.27.6-gke.100 and later.
- 1.28 with the patch version 1.28.1-gke.1157000 and later.
To receive the fix, upgrade your nodes to an applicable patch version.
(2023-R19) Version updates
- The following control plane and node versions are now available:
(2023-R19) Version updates
- The following version is no longer available in the Stable channel: 1.26.5-gke.2100
(2023-R19) Version updates
- The following versions are now available in the Rapid channel:
(2023-R19) Version updates
- There are no new releases in the Regular release channel.
Ray on Vertex AI is now available in Preview
Ray is an open-source framework for scaling AI and Python applications. Ray provides the infrastructure to perform distributed computing and parallel processing for your machine learning workflow.
You can now create Ray clusters and develop your Ray applications on Vertex AI. This feature is in Preview. For more information, see Ray on Vertex AI overview.
October 04, 2023
BigQueryYou can now copy tables across regions. This feature is now in preview.
Chronicle Curated Detections has been enhanced with new detection content for Google Cloud threats. These new rule sets help identify reconnaissance and exploitation behavior from open source Kubernetes tools.
The submit_parser
command now has an option to skip validation if no logs are found. For more information, see the Chronicle CLI user guide.
Dedicated Cloud Interconnect support is available in the following colocation facilities:
- CyrusOne Phoenix - Phoenix
For more information, see the Locations table.
Generally available: NVIDIA L4 GPUs are now available in the following additional regions and zones:
- Singapore(
asia-southeast1-a
)
For more information about using GPUs on Compute Engine, see GPU platforms.
Confidential Space. A new image (confidential-space-230901) is now available. This image provides improved logging capabilities and increases the file descriptor limits. For more information, see the Changelog.
Log rotation is misconfigured on nodes running a COS-based image type (cos_containerd
). This affects all COS-based nodes running version 1.28 or higher. As a result of this issue, your logs may fill up the disk and cause your nodes to be marked as 'Not Ready' and to be auto-repaired. As a workaround, use a privileged DaemonSet to change the logrotate path to /usr/bin/
instead of /usr/sbin/
in Systemd unit kube-logrotate.service
.
Network Analyzer now includes an insight that gives a summary of the IP address utilization of all the subnet ranges. This insight is already available in Recommender API and Cloud Logging. For more information, see IP address utilization summary insights.
ABAP SDK for Google Cloud, version 1.5 is generally available (GA)
Version 1.5 of the ABAP SDK for Google Cloud is generally available (GA). This version of the SDK offers extended ABAP client libraries to build and deploy ML and AI-driven solutions using a wide range of Google Cloud services.
This SDK also enables use of the OAuth 2.0 framework to authenticate to Google Cloud APIs using OAuth 2.0 client credentials.
For more information, see What's new with the ABAP SDK for Google Cloud.
Model tuning for the textembedding-gecko
model is now available in Preview
You can now use supervised fine-tuning to tune the textembedding-gecko
model. This feature is in (Preview).
For more information, see Tune text embeddings.
Vertex AI Prediction
You can now use C3 machine types to serve predictions.
Vertex AI Feature Store
The new and improved Vertex AI Feature Store is now available in Preview. With the new Vertex AI Feature Store you can streamline your feature management in the following ways:
Store and maintain your offline feature data in BigQuery, taking advantage of the data management capabilities of BigQuery. In the new Vertex AI Feature Store, BigQuery serves as the offline store. You don't need to copy or import feature data to an offline store in Vertex AI.
Register your feature data sources in BigQuery by creating feature groups and features.
Define online serving clusters called online store instances; and then serve features from one or more BigQuery data sources, by aggregating them in a feature view within an online store instance. Use Optimized online serving for ultra-low latency needs and Cloud Bigtable online serving for high data volumes.
Retrieve vector embeddings stored in BigQuery for real-time serving.
For more information, see About Vertex AI Feature Store.
October 03, 2023
BigQueryThe following Google Cloud Blockchain Analytics datasets are now available in Preview and available through the Public Datasets Program and Analytics Hub:
The Chronicle SIEM user interface has a new top-level navigation to help you access the most commonly used Chronicle SIEM features. It works much the same as the navigation for Chronicle Security Operations. The new navigation menu expands from the left side of the screen, replacing the 9-dot icon at the top right. It is designed to make it easier to find information and resources and to help you work more efficiently. The Chronicle homepage can be accessed by clicking the Chronicle logo at the top left of the page. Reference lists can now be found within the Search page or the Rules Editor page.
Release 6.2.36
GA - 14th October, 2023
Internal security fixes
Oozie to Airflow tool version 2.0 is available. The new version of the tool supports Airflow 2.
Oozie to Airflow tool converts Apache Oozie workflows into Apache Airflow DAGs. For more information, see the project's page in PyPI and the oozie-to-airflow repository on GitHub.
cos-dev-113-17935-0-0
Kernel | Docker | Containerd | GPU Drivers |
COS-6.1.55 | v24.0.5 | v1.7.3 | v535.104.05(default),v470.199.02(R470) |
Upgraded chromeos-base/chromeos-dbus-bindings to v0.0.1-r2787.
Upgraded chromeos-base/chromeos-common-script to v0.0.1-r554.
Fixed CVE-2023-42753 in the Linux kernel.
cos-109-17800-0-47
Kernel | Docker | Containerd | GPU Drivers |
COS-6.1.42 | v24.0.5 | v1.7.2 | v535.104.05(default),v470.199.02(R470) |
Updated cos-gpu-installer to v2.1.9.
Fixed CVE-2023-42753 in the Linux kernel.
cos-93-16623-461-36
Kernel | Docker | Containerd | GPU Drivers |
COS-5.10.177 | v20.10.24 | v1.6.20 | v450.248.02(default),v470.199.02(R470),v535.104.05 |
Fixes CVE-2023-2163 in the Linux Kernel.
cos-101-17162-279-57
Kernel | Docker | Containerd | GPU Drivers |
COS-5.15.120 | v20.10.24 | v1.6.21 | v470.199.02(default),v535.104.05 |
Updated cos-gpu-installer to v2.1.9.
Dataplex BigLake integration is generally available (GA). Dataplex BigLake integration lets you upgrade a Cloud Storage bucket to managed, creating BigLake tables and Object tables instead of external tables. This allows the application of column-level, row-level, and table-level policies, enabling fine-grained security and dynamic data masking.
Managed Microsoft AD is available in the me-central2
(Dammam) region. For more information, see Deploy domain controllers in additional regions.
Retail Search: Facet controls
You can create facet controls that apply to search and browse operations. These help you control facets values without editing your catalog and set the ranking of facet keys.
Numerical facets have been improved: intervals are calculated but they can also be customized.
The facet controls are:
- Ignore facet values
- Replace facet values
- Set numerical intervals
- Remove facets
- Force return facets
For more information, see Facets for search.
TorchServe is used to host PyTorch machine learning models for online prediction. Vertex AI provides pre-built PyTorch model serving containers which depend on TorchServe. Vulnerabilities were recently discovered in TorchServe which would allow an attacker to take control of a TorchServe deployment if its model management API is exposed. Customers with PyTorch models deployed to Vertex AI online prediction are not affected by these vulnerabilities, since Vertex AI does not expose TorchServe's model management API. Customers using TorchServe outside of Vertex AI should take precautions to ensure their deployments are set up securely.
For more information, see the Vertex AI security bulletin.
October 02, 2023
Anthos Attached ClustersThis release includes the following Anthos attached clusters platform versions:
- 1.25.0-gke.7
- 1.26.0-gke.5
- 1.27.0-gke.2
1.25.0-gke.7, 1.26.0-gke.5, and 1.27.0-gke.1
Resolved an issue affecting EKS environments in which Kubernetes resource metrics weren't successfully scraped from the kubelet
when a node's name within the cluster didn't match that same node's hostname.
1.25.0-gke.7 and 1.26.0-gke.5
This release fixes the following vulnerabilities:
- Fixed CVE-2023-24539
- Fixed CVE-2023-24540
- Fixed CVE-2023-29400
You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:
You can now launch clusters with the following Kubernetes versions. Click on the following links to see the release notes associated with these patches:
Upgrading an admin cluster with always-on secrets encryption enabled might fail.
An admin cluster upgrade from 1.14.x to 1.15.0 - 1.15.4 with always-on secrets encryption enabled might fail depending on whether the feature was enabled during cluster creation or during cluster update.
We recommend that you don't upgrade your admin cluster until a fix is available in 1.15.5. If you must upgrade to 1.15.0-1.15.4, do the steps in Preventing the upgrade failure before upgrading the cluster.
For information on working around an admin cluster failure because of this issue, see Upgrading an admin cluster with always-on secrets encryption enabled fails. Note that the workaround relies on you having the old encryption key backed up. If the old key is no longer available, you will have to recreate the admin cluster and all user clusters.
You can now use Bare Metal Solution's self-service functionality to order your resources after executing a one-time Order Form. This feature is generally available (GA). For more information, see Order Bare Metal Solution resources.
A weekly digest of client library updates from across the Cloud SDK.
Node.js
Changes for @google-cloud/bigquery
7.3.0 (2023-09-28)
Features
Bug Fixes
Java
Changes for google-cloud-bigquery
2.33.1 (2023-09-28)
Bug Fixes
2.33.0 (2023-09-27)
Features
Bug Fixes
Dependencies
- Update actions/checkout action (#2893) (e3655af)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.16.1 (#2892) (e1d9871)
- Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.27 (#2885) (2237ca2)
- Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.27 (#2886) (539b4e6)
- Update github/codeql-action action to v2.21.4 (#2829) (599e3b3)
- Update github/codeql-action action to v2.21.8 - abandoned (#2897) (ab4e1d0)
- Update github/codeql-action action to v2.21.8 (#2889) (b568026)
- Update github/codeql-action action to v2.21.9 (#2901) (33a729f)
BigQuery native integration in Looker Studio enables monitoring features for Looker Studio queries, improves query performance, and supports many BigQuery features. This feature is in preview.
The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning).
- Identity and Access Management
iam.googleapis.com/PolicyV2
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigtable
2.27.3 (2023-09-29)
Bug Fixes
Dependencies
A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-logging
3.15.10 (2023-09-27)
Dependencies
Python
Changes for google-cloud-logging
3.7.0 (2023-09-25)
Features
- Add ConfigServiceV2.CreateBucketAsync method for creating Log Buckets asynchronously (30f24a8)
- Add ConfigServiceV2.CreateLink method for creating linked datasets for Log Analytics Buckets (30f24a8)
- Add ConfigServiceV2.DeleteLink method for deleting linked datasets (30f24a8)
- Add ConfigServiceV2.GetLink methods for describing linked datasets (30f24a8)
- Add ConfigServiceV2.ListLinks method for listing linked datasets (30f24a8)
- Add ConfigServiceV2.UpdateBucketAsync method for creating Log Buckets asynchronously (30f24a8)
- Add LogBucket.analytics_enabled field that specifies whether Log Bucket's Analytics features are enabled (30f24a8)
- Add LogBucket.index_configs field that contains a list of Log Bucket's indexed fields and related configuration data (30f24a8)
- Log Analytics features of the Cloud Logging API (30f24a8)
Bug Fixes
- Add async context manager return types (30f24a8)
- Add severity to structured log write (#783) (31a7f69)
- Handle exceptions raised when fetching Django request data (#758) (5ecf886)
- Unintended exception omittion (#736) (022dc54)
Documentation
The Metrics management page in Cloud Monitoring now lets you create alerting policies and charts for metrics that have no associated alerting policies or custom dashboards. For more information, see View and manage metric usage.
You can now import your Grafana dashboards into Cloud Monitoring. For more information, see Import Grafana dashboards into Cloud Monitoring.
You can now configure notifications for Google Chat spaces. For more information, see Create and manage notification channels.
For Cloud SQL Enterprise edition and Cloud SQL Enterprise Plus edition, you can restore backups across instances of different editions.
For Cloud SQL Enterprise edition and Cloud SQL Enterprise Plus edition, you can restore backups across instances of different editions.
If you use the latest preconfigured base images for JetBrains IDEs, the .vmoptions
and .properties
files persist across workstations. For more information, see Customize JetBrains IDE vmoptions and properties.
Dialogflow CX speech adaptation can now be configured manually.
Support root folder filtering
Filestore enterprise tier backups are now generally available.
A weekly digest of client library updates from across the Cloud SDK.
Python
Changes for google-cloud-ndb
2.2.2 (2023-09-19)
Documentation
GKE now delivers insights and recommendations if users have installed webhooks that intercept system resources or webhooks that have no available endpoints. To learn more, see Ensure control plane stability when using webhooks.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-pubsub
1.125.5 (2023-09-28)
Dependencies
- Update gapic-generator-java to 2.26.0 (935849c)
1.125.4 (2023-09-28)
Dependencies
1.125.3 (2023-09-27)
Dependencies
- Update dependency com.google.cloud:google-cloud-core to v2.24.1 (#1737) (48a4432)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.16.1 (#1738) (e2cf7c1)
- Update dependency org.apache.avro:avro to v1.11.3 (#1740) (971b35f)
- Update dependency org.xerial.snappy:snappy-java to v1.1.10.4 security (70ba500)
- Update dependency org.xerial.snappy:snappy-java to v1.1.10.5 (#1746) (a4b1994)
Cloud Storage Backint agent for SAP HANA version 1.0.29
Version 1.0.29 of the Cloud Storage Backint agent for SAP HANA is available. This version sets the default value of the HTTP_READ_TIMEOUT
parameter to -1
; no timeout.
For more information about the agent, see Cloud Storage Backint agent for SAP HANA overview.
Private Service Connect service connectivity automation is available in General Availability. Service connectivity automation lets service producers automate deployment and service connectivity to eligible managed services on behalf of consumers.
Private Service Connect backends with published service targets can be added to global external TCP proxy Network Load Balancers. This feature is available in Preview.
September 30, 2023
Cloud FirewallStarting September 30, 2023, you will be charged for the Cloud Firewall Standard feature—fully qualified domain name (FQDN) objects. For more information about billing, see Cloud Firewall pricing.
VMware Engine nodes are now available in the following additional zone:
- Tel Aviv (
me-west1-b
)
September 29, 2023
Access ApprovalAccess Approval supports Vertex AI Search in the Preview stage.
Access Transparency supports Vertex AI Search in the Preview stage. For the complete list of services that Access Transparency supports, see Supported services.
Anthos clusters on VMware 1.16.1-gke.45 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.16.1-gke.44 runs on Kubernetes 1.27.4-gke.1600.
The Prometheus and Grafana add-ons field, loadBalancer.vips.addonsVIP
is deprecated in 1.16 and later. This change is because
Google Managed Service for Prometheus
replaced the Prometheus and Grafana add-ons in 1.16.
The following issues are fixed in 1.16.1-gke.45:
- Fixed the
known issue
that
gkectl repair admin-master
returns kubeconfig unmarshall error. - Fixed the known issue that GARP reply sent by Seesaw doesn't set target IP
- Fixed the known issue that Seesaw VM may be broken due to low disk space
- Fixed the known issue that false warnings might be generated against persistent volume claims.
- Fixed the known issue that caused CNS
attachvolume
tasks to appear every minute for in-tree PVC/PV after upgrading to Anthos 1.15+.
The following vulnerabilities are fixed in 1.16.1-gke.44:
High-severity container vulnerabilities:
Container-optimized OS vulnerabilities:
Anthos clusters on VMware 1.14.8-gke.37 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.14.8-gke.37 runs on Kubernetes 1.25.12-gke.2400.
The following issues are fixed in 1.14.8-gke.37:
- Fixed the disk full known issue on Seesaw VM due to no log rotation for fluent-bit.
The following vulnerabilities are fixed in 1.14.8-gke.37:
High-severity container vulnerabilities:
Container-optimized OS vulnerabilities:
Release 1.14.9
Anthos clusters on bare metal 1.14.9 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.14.9 runs on Kubernetes 1.25.
Fixes:
Fixed an issue to prevent cluster upgrades from starting on a node before either all Pods have been drained or the Pod draining timeout has been reached.
Fixes:
The following container image security vulnerabilities have been fixed in version 1.14.9:
High-severity container vulnerabilities:
Medium-severity container vulnerabilities:
Low-severity container vulnerabilities:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
On September 29, 2023, we released an updated version of Apigee.
New attributes for Pay-as-you-go pricing are generally available (GA).
Apigee updated its Pay-as-you-go pricing model, making it possible for customers to onboard at a significantly reduced initial cost and right-size their ongoing expenses to usage.
To learn more about the updated Pay-as-you-go pricing experience, see Pay-as-you-go (updated attributes) pricing overview.
Standard and extensible API proxies are generally available (GA).
Standard and extensible API proxies are generally available for use with Apigee organizations.
For more information about standard and extensible API proxies, see API proxy types.
HTTPModifier and ReadPropertySet policies and templating support for message
The HTTPModifier policy can change an existing request or response message and provides a subset of the functionality already available in the AssignMessage policy. See HTTPModifier policy.
The ReadPropertySet policy reads property sets and populates flow variables with the results. See ReadPropertySet policy.
HTTPModifier and ReadPropertySet are standard policies. Proxies built exclusively with standard policies are called standard proxies and can be deployed to any environment type. See Pay-as-you-go (updated attributes) pricing overview.
With this release, template support for message
New environment types are generally available (GA).
With this release, Apigee introduces three distinct environments that have access to varying degrees of Apigee capabilities and costs: Base, Intermediate, and Comprehensive.
For more information, see Apigee Pay-as-you-go environment types.
Apigee API Analytics add-on for Pay-as-you-go organizations is generally available (GA).
With this release, Apigee API Analytics is available as a paid add-on capability for Pay-as-you-go organizations. The add-on can be enabled in any Apigee Intermediate or Comprehensive environment. For more information, see Manage the Apigee API Analytics add-on.
One click provisioning for Apigee Pay-as-you-go organizations is generally available (GA).
Simplify your onboarding experience with one click provisioning for new Pay-as-you-go organizations, using smart default configurations. To learn more, see Provision Apigee with one click.
Updated pricing attributes in Subscription plans are available.
To get started with subscription plans that include new pricing attributes (consistent with Pay-as-you-go pricing), contact your Google Cloud sales specialist.
For more information, see Apigee Subscription 2024 entitlements. Apigee hybrid is not available in the new subscription plan at this time.
As a BigQuery administrator, to monitor your organization's slots utilization and BigQuery jobs' performance over time, use can now use administrative query inspector. This feature is now generally available.
Airflow triggerer is now generally available (GA).
The cost of the environments.ExecuteAirflowCommand
and environments.StopAirflowCommand
operations is reduced from 100 to 25 quota units.
The apache-airflow-providers-google
package is upgraded to version 10.9.0 in images with Airflow 2.5.3 and 2.4.3. For more information about changes, see the apache-airflow-providers-google changelog from version 10.7.0 to version 10.9.0.
Cloud Composer 2.4.4 images are available:
- composer-2.4.4-airflow-2.5.3 (default)
- composer-2.4.4-airflow-2.4.3
Cloud Composer versions 2.0.28, 2.0.27, 1.19.11, and 1.19.10 have reached their end of full support period.
Cloud Load Balancing introduces the global external Proxy Network Load Balancer. The global external Proxy Network Load Balancer is implemented on globally distributed GFEs and supports advanced traffic management capabilities. This load balancer can be configured to handle either TCP or SSL traffic by using either a target TCP proxy or a target SSL proxy respectively. Global external proxy Network Load Balancers support backends such as instance groups, hybrid NEGs, and Private Service Connect NEGs.
Load balancers that are already deployed in the classic mode are renamed as classic Proxy Network Load Balancer in the console.
For details, see the External proxy Network Load Balancer overview.
To set up a global external Proxy Network Load Balancer, see the following pages:
This capability is in Preview.
With the launch of global external Proxy Network Load Balancer, we now support three deployment modes with the external Proxy Network Load Balancer—classic (General Availability), Regional (General Availability) and global (Preview). No changes have been made to the API.
For details, see the External proxy Network Load Balancer overview.
Typically with HTTPS communication, the authentication works only one way: the client verifies the identity of the server. For applications that require the load balancer to authenticate the identity of clients that connect to it, both a global external Application Load Balancer and a global external Application Load Balancer (classic) support mutual TLS (mTLS).
With mTLS, the load balancer requests that the client send a certificate to authenticate itself during the TLS handshake with the load balancer. You can configure a trust store that the load balancer uses to validate the client certificate's chain of trust.
For details, see the following:
- Mutual TLS authentication
- Set up mutual TLS with signed certificates
- Set up mutual TLS with a private CA
- Set up mutual TLS for a global external Application Load Balancer (classic)
- Set up mutual TLS for a global external Application Load Balancer
This capability is in General Availability.
Ops Agent versions 2.39.0 and 2.40.0 crash if you use them on Compute Engine VMs with attached GPUs. Use Ops Agent version 2.38.0, or versions 2.41.0 and newer, on VMs with attached GPUs.
Ops Agent versions 2.39.0 and 2.40.0 crash if you use them on Compute Engine VMs with attached GPUs. Use Ops Agent version 2.38.0, or versions 2.41.0 and newer, on VMs with attached GPUs.
Config Connector version 1.110.0 is now available.
Added MutatingWebhookConfigurationCustomization
and ValidatingWebhookConfigurationCustomization
to support the customization on webhook timeouts.
Added value validation for resource requests and limits in the customizable ControllerResource
and NamespacedControllerResource
CRDs.
Promoted CertificateManagerCertificate
, CertificateManagerCertificateMap
, CertificateManagerCertificateMapEntry
and CertificateManagerDNSAuthorization
from v1alpha1
to v1beta1
.
Promoted RunService
from alpha
stability to stable
stability.
- Renamed field
spec.template.containerConcurrency
tospec.template.maxInstanceRequestConcurrency
. - Fixed the IAM support by removing the support of "IAM conditions" on this resource.
- Removed field
status.resourceGeneration
.
Resource BigQueryTable(v1beta1):
- Added
spec.tableConstraints
field. - Added
spec.materializedView.allowNonIncrementalDefinition
field.
Resource ComputeInstance(v1beta1):
- Added
spec.networkInterface.items.internalIpv6PrefixLength
field. - Added
spec.networkInterface.items.ipv6Address
field.
Resource ComputeInstanceTemplate(v1beta1):
- Added
spec.networkInterface.items.internalIpv6PrefixLength
field. - Added
spec.networkInterface.items.ipv6Address
field.
Resource ContainerCluster(v1beta1):
- Added
spec.enableFqdnNetworkPolicy
field. - Added
spec.nodeConfig.confidentialNodes
field.
Resource ContainerNodePool(v1beta1):
- Added
spec.nodeConfig.confidentialNodes
field.
Resource DialogflowCXFlow(v1alpha1):
- Added
spec.eventHandlers.items.triggerFulfillment.conditionalCases
field. - Added
spec.eventHandlers.items.triggerFulfillment.setParameterActions
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.channel
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.conversationSuccess
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.liveAgentHandoff
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.outputAudioText
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.payload
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.playAudio
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.telephonyTransferCall
field. - Added
spec.transitionRoutes.items.triggerFulfillment.conditionalCases
field. - Added
spec.transitionRoutes.items.triggerFulfillment.setParameterActions
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.channel
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.conversationSuccess
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.liveAgentHandoff
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.outputAudioText
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.payload
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.playAudio
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.telephonyTransferCall
field.
Resource DialogflowCXPage(v1alpha1):
- Added
spec.entryFulfillment.conditionalCases
field. - Added
spec.entryFulfillment.setParameterActions
field. - Added
spec.entryFulfillment.messages.items.channel
field. - Added
spec.entryFulfillment.messages.items.conversationSuccess
field. - Added
spec.entryFulfillment.messages.items.liveAgentHandoff
field. - Added
spec.entryFulfillment.messages.items.outputAudioText
field. - Added
spec.entryFulfillment.messages.items.payload
field. - Added
spec.entryFulfillment.messages.items.playAudio
field. - Added
spec.entryFulfillment.messages.items.telephonyTransferCall
field. - Added
spec.eventHandlers.items.triggerFulfillment.conditionalCases
field. - Added
spec.eventHandlers.items.triggerFulfillment.setParameterActions
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.channel
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.conversationSuccess
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.liveAgentHandoff
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.outputAudioText
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.payload
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.playAudio
field. - Added
spec.eventHandlers.items.triggerFulfillment.messages.items.telephonyTransferCall
field. - Added
spec.form.parameters.items.defaultValue
field. - Added
spec.form.parameters.items.fillBehavior.repromptEventHandlers
field. - Added
spec.form.parameters.items.fillBehavior.initialPromptFulfillment.conditionalCases
field. - Added
spec.form.parameters.items.fillBehavior.initialPromptFulfillment.setParameterActions
field. - Added
spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.channel
field. - Added
spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.conversationSuccess
field. - Added
spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.liveAgentHandoff
field. - Added
spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.outputAudioText
field. - Added
spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.payload
field. - Added
spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.playAudio
field. - Added
spec.form.parameters.items.fillBehavior.initialPromptFulfillment.messages.items.telephonyTransferCall
field. - Added
spec.transitionRoutes.items.triggerFulfillment.conditionalCases
field. - Added
spec.transitionRoutes.items.triggerFulfillment.setParameterActions
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.channel
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.conversationSuccess
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.liveAgentHandoff
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.outputAudioText
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.payload
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.playAudio
field. - Added
spec.transitionRoutes.items.triggerFulfillment.messages.items.telephonyTransferCall
field.
Resource RunJob(v1beta1):
spec.template.template.volumes[].secret.items[].mode
is now optional.
Resource SecretManagerSecret(v1beta1):
- Added
spec.replication.auto
field.
Resource SecretManagerSecretVersion(v1beta1):
- Added
spec.deletionPolicy
field.
Resource StorageBucket(v1beta1):
spec.autoclass.enabled
is now mutable.
Resource VertexAIIndexEndpoint(v1alpha1):
- Added
spec.publicEndpointEnabled
field. - Added
status.publicEndpointDomainName
field.
Dataplex is available in the following regions:
- Delhi (
asia-south2
) - Melbourne (
australia-southeast2
) - Toronto (
northamerica-northeast2
)
Dialogflow CX launched two new integrations in preview:
This is a follow-up message to the release note regarding blue-green upgrades from September 18, 2023. You can now resume upgrading clusters with the blue-green upgrade strategy as the issue with rollback functionality has been fixed. GKE is no longer blocking automatic upgrades due to this issue.
containsOnly()
function released to General Availability.
You can now use the containsOnly()
function to query findings with an array-type attribute or subfield that only contains values that match the specified filter, and no other values.
For more information, see The containsOnly
function.
Vertex AI Search (Enterprise Search): Customer-managed encryption key integration
Customer-managed encryption keys (CMEK) is available as an allowlisted preview feature.
If you store your data in a US multi-region data store, you can provide your own encryption key to protect your data at rest.
For information, see Customer-managed encryption keys.
Vertex AI Search (Enterprise Search): Search tuning
Search tuning is available as an allowlisted preview feature. You provide additional training data in the form of query and segment pairs. We use this data to tune the model for your app.
For information, see Improve search results with search tuning.
Vertex AI Search (Enterprise Search): VPC Service Controls are GA
Virtual Private Cloud Service Controls support for Enterprise Search is generally available (GA).
For more information, see Supported products and limitations in the VPC Service Controls documentation. For general information about VPC Service Controls, see Overview of VPC Service Controls.
Vertex AI Search (Enterprise Search): Data location
Vertex AI Search may be configured for data location pursuant to the "Data Location" section of the Service Specific Terms.
For information about data residency in Vertex AI Search, see Enterprise Search locations.
Vertex AI Search (Enterprise Search): Support for Access Transparency
Access Transparency supports Vertex AI Search in preview.
For more information, see Enable Access Transparency in Enterprise Search.
Vertex AI Search (Enterprise Search): Citations for search with follow-ups
Citations indicate from which search results specific sentences in the summary are taken.
For more information, see Configure the summary.
Vertex AI Search (Enterprise Search): Ignore adversarial queries and non-summary seeking queries for search with follow-ups
Ignore adversarial queries can stop generation of summaries that are unsafe or violate policy.
Non-summary seeking queries stop generation of summaries that aren't helpful for some queries.
For more information, see Configure the summary.
Vertex AI Search (Enterprise Search): Additional languages supported
Search, snippets, and other features are now supported in the following languages:
- Arabic
- Chinese (Simplified)
- Greek
- Hebrew
- Japanese
- Korean
- Polish
- Russian
See Languages.
Private Service Connect backends support using an external regional TCP proxy load balancer or an internal regional TCP proxy load balancer to access published services. These features are available in General Availability.
September 28, 2023
AlloyDB for PostgreSQLAlloyDB secondary clusters now support read pool instances.
The IL2 compliance program is now generally available. For a list of IL2-compliant Google Cloud products, see the Supported products page.
The following BigQuery ML point-in-time lookup functions are now in preview. These functions let you specify a point-in-time cutoff when retrieving features for training a model or running inference, in order to avoid data leakage.
- Use the
ML.FEATURES_AT_TIME
function to use the same point-in-time cutoff for all entities when retrieving features. - Use the
ML.ENTITY_FEATURES_AT_TIME
function to retrieve features from multiple points in time for multiple entities.
You can now use IAM conditions to control access to BigQuery resources. This feature is in preview.
Certificate Manager supports Mutual TLS (mTLS) authentication. This feature is generally available (GA).
You can now configure your alerting policy documentation with custom subject lines. For more information, see Configure the subject line of notifications.
The following pg_wait_sampling and rdkit flags are generally available:
pg_wait_sampling flags
- cloudsql.enable_pg_wait_sampling: enable the
pg_wait_sampling
extension for Cloud SQL for PostgreSQL instances. - pg_wait_sampling.history_size: set the size of the in-memory ring buffer for history sampling, in terms of the number of samples.
- pg_wait_sampling.history_period: set the time interval for history sampling, in milliseconds.
- pg_wait_sampling.profile_period: set the time interval for profile sampling for wait events, in milliseconds.
- pg_wait_sampling.profile_pid: specify whether the wait profile that accumulates samples for each process and waits event is collected for each process or for all processes.
- pg_wait_sampling.profile_queries: specify whether the wait profile is collected for each query or for all queries.
rdkit flags
- rdkit.tanimoto_threshold: set the threshold value for the Tanimoto similarity operator.
- rdkit.dice_threshold: set the threshold value for the Dice similarity operator.
- rdkit.do_chiral_sss: specify whether stereochemistry is used in substructure matching.
- rdkit.do_enhanced_stereo_sss: specify whether enhanced stereo is used in substructure matching.
- rdkit.sss_fp_size: set the size of the fingerprint used for substructure screening, in bits.
- rdkit.morgan_fp_size: set the size of morgan fingerprints, in bits.
- rdkit.featmorgan_fp_size: set the size of featmorgan fingerprints, in bits.
- rdkit.layered_fp_size: set the size of layered fingerprints, in bits.
- rdkit.rdkit_fp_size: set the size of rdkit fingerprints, in bits.
- rdkit.hashed_torsion_fp_size: set the size of topological torsion bit vector fingerprints, in bits.
- rdkit.hashed_atompair_fp_size: set the size of atom pair bit vector fingerprints, in bits.
- rdkit.reaction_sss_fp_size: set the size of the structural chemical reaction fingerprint, in bits.
- rdkit.reaction_difference_fp_size: set the size of the difference chemical reaction fingerprint, in bits.
- rdkit.reaction_sss_fp_type: specify the type of structural chemical reaction fingerprint.
- rdkit.reaction_difference_fp_type: specify the type of difference chemical reaction fingerprint.
- rdkit.ignore_reaction_agents: specify whether agents of a chemical reaction are taken into account.
- rdkit.agent_FP_bit_ratio: specify the weight of the impact of agents contained in a chemical reaction fingerprint.
- rdkit.move_unmmapped_reactants_to_agents: specify whether unmapped reactant agents of a chemical reaction are taken into account.
- rdkit.threshold_unmapped_reactant_atoms: set the ratio of allowed unmapped reactant atoms.
- rdkit.init_reaction: specify whether the reaction is ready for use.
- rdkit.difference_FP_weight_agents: specify the weight factor for agents compared to reactants and products in reaction difference fingerprints.
- rdkit.difference_FP_weight_nonagents: specify the weight factor for reactants and products compared to agents in reaction difference fingerprints.
- rdkit.avalon_fp_size: set the size of avalon fingerprints, in bits.
Beginning Oct 30, 2023, Cloud Storage will change how it enforces egress bandwidth quotas.
- Instead of using the same default value for all projects, egress bandwidth quotas will depend on each project's history, such whether the billing account is in good standing.
- For most projects, egress bandwidth quotas will either remain unchanged or will increase.
- Once this change takes effect, you can view your project's egress bandwidth quotas in the Console.
New Dataproc on Compute Engine subminor image versions:
- 2.0.78-debian10, 2.0.78-rocky8, 2.0.78-ubuntu18
- 2.1.26-debian11, 2.1.26-rocky8, 2.1.26-ubuntu20, 2.1.26-ubuntu20-arm
Upgraded the Cloud Storage connector version to 2.2.17 in the latest 2.0 and 2.1 Dataproc on Compute Engine image versions.
Upgraded Hive version from 3.1.2
to 3.1.3
in the latest Dataproc on Compute Engine 2.0 image version.
(New guide) Design secure deployment pipelines: Best practices for designing secure deployment pipelines based on your confidentiality, integrity, and availability requirements.
When you create a release using the gcloud CLI version 445, 446, or 447, you might encounter an error
where gcloud requires the clouddeploy.config.get
permission. To fix this issue, upgrade to gcloud CLI version 448 or greater.
After January 15, 2024, some Policy Intelligence features will only be available for customers with organization-level activations of Security Command Center. For more information, see Billing questions.
Using Policy Troubleshooter to troubleshoot deny policies is generally available.
SAP HANA Fast Restart enabled using Terraform
SAP HANA Fast Restart is enabled when you deploy SAP HANA on Google Cloud using the sap_hana
or sap_hana_ha
Terraform module, version 202309280828
or later. The fast restart option is enabled through the enable_fast_restart
Terraform argument, which by default is set to true
.
For more information, see the deployment guide for your SAP HANA scenario.
Preview stage supported for the following integration: