The following release notes cover the most recent changes over the last 60 days. For a comprehensive list of product-specific release notes, see the individual product release note pages.
You can also see and filter all release notes in the Google Cloud Console or you can programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your
feed
reader, or add the feed URL directly: https://cloud.google.com/feeds/gcp-release-notes.xml
April 01, 2022
BigQuery MLBigQuery ML and Vertex AI Model Registry integration is available in preview. With this integration, BigQuery ML models can be sent to the Vertex AI Model Registry where you can manage the lifecycle of all your ML models. From the Vertex AI Model Registry, you can organize your BigQuery ML models and deploy directly to endpoints.
Cost analysis by project ancestry, including folder-level costs, now available in BigQuery Export and Reports
Viewing your costs by project ancestry helps you do things like analyze costs by folder or organization. For example, if you use folders in an organization to represent cost centers (such as DevOps or Finance), you can effectively configure your report or query to group all costs by those cost centers.
Billing Reports
In the Cloud Billing Console Reports page, you can now Group by Project hierarchy and filter on Folders & Organizations, to analyze costs by project ancestry (such as folders or organizations).
Group costs by project ancestry – In the Reports page, when you group by Project hierarchy, the report returns a row for each unique combination of Organization > Folder > Project, and the table includes columns for Project, Project ID, Project number, and Project hierarchy. The values listed in the Project hierarchy column show Organization name > Folder name.
Filter costs by project ancestor(s) – In the Reports page, when you filter by Folders & Organizations, the report returns costs for all projects that are associated with any of the selected folders/organizations in their project ancestry.
In the Cloud Billing Console Cost breakdown report, you can now filter on Folders & Organizations, to analyze costs by project ancestry (such as folders or organizations).
- Filter costs by project ancestor(s) – In the Cost breakdown report, when you filter by Folders & Organizations, the report returns costs and credits aggregated for all projects that are associated with any of the selected folders/organizations in their project ancestry.
To learn more about organizations, folders, and project hierarchy, see Billing reports: Analyzing your costs by project hierarchy.
Cloud Billing data export to BigQuery
In the Cloud Billing usage cost data that exports to BigQuery, you can now see resource hierarchy metadata that describes a project's ancestry, including:
project.ancestors.resource_name– An identifier containing the resource hierarchy type and ID (for example, folders/234)project.ancestors.display_name– A name that you create for the resource (for example, DevOps)
The project.ancestors metadata is available in both the Standard usage cost export and Detailed usage cost export. To help make resource hierarchy levels easier to identify in the BigQuery data tables, the ancestor data includes the resource display name (a human-readable name that you create) and the relative resource hierarchy names (immutable ID numbers representing each project/folder/organization).
For more details about project.ancestry_numbers and project.ancestors, see
Cloud Data Fusion version 6.6.0 is generally available (GA).
Cloud Functions (1st gen) has added support for Google-managed Artifact Registry at the Preview release level.
You can now specify PATCH requests in a FHIR bundle. This feature is available in Preview. See Executing a PATCH request in a FHIR bundle for more information.
Cloud SQL for MySQL now supports minor versions 8.0.27 and 8.0.28. To upgrade your existing instance to the new version, see Upgrade the database minor version.
Google Cloud Armor now supports TCP Proxy load balancers and SSL proxy load balancers in public preview. For more information, see the security policy overview.
Vertex AI Model Registry is available in Preview. Vertex AI Model Registry is a searchable repository where you can manage the lifecycle of your ML models. From the Vertex AI Model Registry, you can better organize your models, train new versions, and deploy directly to endpoints.
March 31, 2022
Anthos clusters on bare metalRelease 1.11.0
Anthos clusters on bare metal 1.11.0 is now available for download. To upgrade, see Upgrade Anthos on bare metal. Anthos clusters on bare metal 1.11.0 runs on Kubernetes 1.22.
Containerd is the default runtime in Anthos clusters on bare metal. Support for Docker as a container runtime on Kubernetes nodes will be removed from Anthos clusters on bare metal starting with version 1.13.0. If you use a node image based on Docker container runtime, please migrate your workloads to a Containerd node image as soon as possible. For more details, see Containerd node images.
The structure of the Anthos clusters on bare metal documentation is substantially different from previous versions. For details, see New documentation structure.
Kubernetes 1.22 has deprecated certain APIs, and a list of these deprecated APIs can be found in Kubernetes 1.22 deprecated APIs. In their manifests and API clients, customers need to replace references to the deprecated APIs with references to the newer API calls. For more information, see Deprecated API Migration Guide.
On January 31, 2022, CentOS 8 reached its end of life (EOL). As a result of the EOL, yum repositories stopped working for CentOS, which causes cluster creation and cluster upgrade operations to fail. For a workaround and more information, see Cluster creation or upgrades fail on CentOS.
Improved cluster lifecycle functionalities:
Upgraded Anthos clusters on bare metal to use Kubernetes version 1.22.
Updated
cert-managerto version 1.5.4.Added error messaging in the
bmctlcommand line interface to better surface cluster installation or upgrade failure.Incorporated audit logs into
bmctlsnapshots.Added ability for registry mirror users to customize
containerdconfiguration and have it automatically mirror public registry hosts other thangcr.io.Changed
bmctl updatecommand so that it extracts manifests before updating a cluster.Added feature so that a cluster's
kubeconfigfile automatically renews when the cluster is upgraded and the kubeconfigSecretis renewed whenever cluster reconciliation takes place.Added support for Red Hat Enterprise Linux (RHEL) and CentOS 8.5.
Added warning to
bmctlcommand thatdocker containerRuntimewill not be supported in version 1.13 of Anthos cluster on bare metal.Added support for specifying CIDR blocks in the
NoProxysection of the cluster's configuration file.Added Service CIDR to
NoProxysection of a cluster's configuration file by default in order to fix a multinic in proxy environment issue.Fixed a multinic in proxy environment issue. Whenever the
NO_PROXYenvironment variable is set, it includes the Service CIDR from the cluster specification.
Networking:
GA: Added egress Network Address Translation (NAT) gateway capability to provide persistent, deterministic routing for egress traffic from clusters. For more information, see Configure an egress NAT gateway for external communication.
GA: Added option for BGP bundled load balancer which advertises Load Balancer (LB) Virtual IP addresses (VIPs) to the network using the Border Gateway Protocol (BGP). This feature supports topologies across multiple subnets and can provide greater load-balancing bandwidth than bundled Layer 2 mode.
GA: Enabled SR-IOV. This feature allows you to configure Virtual Functions (VFs) on the supported devices on the nodes of their cluster. It also allows you to define the kernel module you want to bind to the VF.
GA: Enabled IPv4/IPv6 dual-stack support. Clusters can be deployed in a dual-stack network in which IPv4 and IPv6 addresses are assigned to both nodes and pods. By default, IPv4 is in island mode and IPv6 is in flat mode (a simplified network topology).
GA: Enabled static flat network (without BGP). This feature lets you configure a flat mode network for IPv4 addresses. A pod's IPv4 address is visible and routable within the same Layer 2 domain, without having to masquerade as the node's IP address.
Preview: Enabled Dynamic Flat IP with Border Gateway Protocol (BGP) support. This feature lets you configure flat mode using BGP in clusters with the help of Anthos Network Gateway and BGP. In this mode, the pod's IP address is visible and routable without masquerading across multiple subdomains. Currently supports advertising IPv4 and IPv6 routes over IPv4 sessions.
Fixed issue in which new MAC addresses of re-imaged nodes weren't updated.
Observability:
GA: Enabled collection of multiple network interfaces (multinic) logs from clusters. Logs are collected as system logs and are sent to Cloud Logging without charge to the customer.
Preview: Added Summary API metrics. These metrics provide CPU, memory, and storage statistics about pods, containers, and nodes.
Updated fluent-bit (
stackdriver-log-forwarder) cri parser to avoid matching time fields multiple times.Upgraded
kube-state-metricsfrom version 1.9 to 2.4. This service generates metrics about Kubernetes API objects such as deployments, nodes, and pods.Upgraded Metric Server from version 0.3.6 to 0.4.5. Metrics Server retrieves metrics from kubelets and exposes them through the Kubernetes Metrics API.
Security:
Preview: Added secure computing mode (
seccomp) support. Running containers with aseccompprofile improves the security of a cluster because it restricts the system calls that containers are allowed to make to the kernel.Added ability to disable rootless mode for system containers. Since version 1.10.0, Kubernetes control planes and Anthos clusters on bare metal system containers run as non-root containers by default.
Fixed CA rotation issues by increasing the
ca-rotationtimeout for admin clusters. While verifying that a static pod has been restarted after manifest update, the current hash is retrieved before the manifest changes are applied.
Known issues:
Deprecated metrics
Several Anthos metrics have been deprecated and, starting with this release, data is no longer collected for these deprecated metrics. If you use these metrics in any of your alerting policies, there won't be any data to trigger the alerting condition. For more information, including instructions to migrate to updated replacement metrics, see Deprecated metrics affects Cloud Monitoring dashboard in Known Issues.
For information about the latest known issues, see Anthos on bare metal known issues in the Troubleshooting section.
Release 1.10.3
Anthos clusters on bare metal 1.10.3 is now available for download. To upgrade, see Upgrade Anthos on bare metal. Anthos clusters on bare metal 1.10.3 runs on Kubernetes 1.21.
Fixes:
- The following container image security vulnerabilities have been fixed:
Known issues:
For information about the latest known issues, see Anthos on bare metal known issues in the Troubleshooting section.
On March 31, 2022, we released an updated version of Apigee X.
You can now use Private Service Connect (PSC) to connect to Apigee. This architectural pattern eliminates the need to create managed instance groups to forward requests from the global load balancer to Apigee. For details, see Using Private Service Connect.
The international public dataset for Data Signals for Google Search Trends is now available in Preview and available in the Google Cloud Marketplace and Analytics Hub.
Improved carbon accounting for Retail API
Improved carbon accounting for many AI services (these services aren't covered in 2021)
Improved mapping between Google Cloud services and internal resource use. This changes the carbon footprint of some Google Cloud services and adds other Google Cloud Services, like Networking, to the list of covered services.
Updated carbon model to version 4
The SAP SLT Replication plugin is generally available (GA). You can replicate your data continuously and in real time from SAP sources into BigQuery with this plugin in Cloud Data Fusion versions 6.4.0 and later.
Cloud Functions (1st gen) support for customer-managed encryption keys (CMEK) is now at the General Availability release level.
The Cloud Healthcare API offers single-region support in the us-east1 (South Carolina) region.
The Cloud Healthcare API offers single-region support in the us-west1 (Oregon) region.
The Cloud Healthcare API offers single-region support in the us-west3 (Salt Lake City) region.
Support for creating an Eventarc trigger for a Workflows destination on the Eventarc page in the Cloud Console is now available in Preview.
(2022-R7) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
Version 1.21.6-gke.1503 is now the default version.
The following control plane and node versions are now available:
The following control plane versions are no longer available:
- 1.19.16-gke.6100
- 1.20.12-gke.1500
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.18 to 1.19.16-gke.6800 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.19 to version 1.19.16-gke.6800 with this release.
Stable channel
The following versions are now available in the Stable channel:
The following versions are no longer available in the Stable channel:
- 1.19.16-gke.6100
- 1.20.12-gke.1500
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.18 to 1.19.16-gke.6800 with this release.
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.19 to 1.19.16-gke.6800 with this release.
Regular channel
- Version 1.21.6-gke.1503 is now the default version in the Regular channel.
- The following versions are now available in the Regular channel:
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.6-gke.1503 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.21.6-gke.1503 with this release.
Rapid channel
- Version 1.22.7-gke.1500 is now the default version in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.21.10-gke.1300
- 1.23.4-gke.1600
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.10-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.10-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.23.5-gke.200 with this release.
(2022-R07) Version updates
Version 1.21.6-gke.1503 is now the default version.
The following control plane and node versions are now available:
The following control plane versions are no longer available:
- 1.19.16-gke.6100
- 1.20.12-gke.1500
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.18 to 1.19.16-gke.6800 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.19 to version 1.19.16-gke.6800 with this release.
(2022-R07) Version updates
The following versions are now available in the Stable channel:
The following versions are no longer available in the Stable channel:
- 1.19.16-gke.6100
- 1.20.12-gke.1500
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.18 to 1.19.16-gke.6800 with this release.
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.19 to 1.19.16-gke.6800 with this release.
(2022-R07) Version updates
- Version 1.21.6-gke.1503 is now the default version in the Regular channel.
- The following versions are now available in the Regular channel:
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.6-gke.1503 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.21.6-gke.1503 with this release.
(2022-R07) Version updates
- Version 1.22.7-gke.1500 is now the default version in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.21.10-gke.1300
- 1.23.4-gke.1600
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.10-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.10-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.23.5-gke.200 with this release.
Maintenance Windows are now Generally Available for Memorystore for Memcached.
Support for creating an Eventarc trigger on the Workflows page in the Cloud Console is now available in Preview.
March 30, 2022
Anthos Service Mesh1.13.1-asm.1 is now available.
Anthos Service Mesh 1.13 includes the features of Istio 1.13 subject to the list of Anthos Service Mesh supported features.
Managed Anthos Service Mesh isn't rolling out to the rapid release channel at this time. You can periodically check this page for the announcement of the rollout of Managed Anthos Service Mesh to the rapid channel. See Select a managed Anthos Service Mesh release channel for more information.
Anthos Service Mesh now supports GKE on GCP and On-premise combined in a hybrid mesh as a public preview feature. See Install Anthos Service Mesh and Set up a multi-cluster mesh for more information.
Anthos Service Mesh now supports GKE on GCP and Amazon EKS combined in a multi-cloud mesh as a public preview feature. See Install Anthos Service Mesh and Set up a multi-cluster mesh for more information.
Enabled a single Cloud API (mesh.googleapis.com), which automatically enables all required Cloud APIs for Anthos Service Mesh.
In general, the Service dashboards support all current versions of Anthos Service Mesh. Historically, the Anthos Service Mesh release notes attempted to announce each of these dashboard updates. Going forward, the Anthos Service Mesh release notes will no longer explicitly announce dashboard updates but reserve the space for significant new feature announcements.
Anthos Service Mesh 1.10 is no longer supported. For more information, see Supported versions.
The following resource types are now publicly available through the Export APIs (ExportAssets and BatchGetAssetsHistory) and the Feed API:
- Dataplex
dataplex.googleapis.com/Lakedataplex.googleapis.com/Taskdataplex.googleapis.com/Zonedataplex.googleapis.com/Asset
Two new organization policy constraints are now available in Preview to help ensure CMEK usage across an organization:
constraints/gcp.restrictNonCmekServicesrequires CMEK protection.constraints/gcp.restrictCmekCryptoKeyProjectslimits which Cloud KMS keys are used for CMEK protection.
To learn more, see CMEK organization policies.
This is the General Availability release of Google Distributed Cloud Edge (version 1.0.0).
For information about the latest known issues, see Known issues in this release of Distributed Cloud Edge.
Creating and managing data transfers with the gcloud command-line tool is now generally available (GA).
You can use gcloud commands to perform agent installation, manage agent pool lifecycles, and orchestrate transfer jobs. This launch simplifies writing scripts to automate transfer workflow.
The GA launch adds support for transfers between file systems, metadata preservation, and manifests. It also introduces the gcloud transfer authorize command to inspect and grant required permissions for transfers.
March 29, 2022
Apigee XOn March 29, 2022, we released an updated version of Apigee X (1-7-0-apigee-28).
| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries |
March 28, 2022
BigQuery MLThe Wide-and-Deep model is now generally available (GA). For more information, see the Wide-and-Deep sections in the end-to-end user journey page.
Cloud Composer 1.18.4 and 2.0.8 release started on March 28, 2022. Get ready for upcoming changes and features as we roll out the new release to all regions. This release is in progress at the moment. Listed changes and features might not be available in some regions yet.
If the /dags, /data, /logs, or /plugins folder is deleted in an environment's bucket, Cloud Composer re-creates this folder.
New version aliases for Cloud Composer images. Now you can specify the latest version of Airflow 2 with composer-2-airflow-2 and composer-1-airflow-2 aliases. The new composer-1-airflow-1 alias points to the latest version of Airflow 1.
(Cloud Composer 2) Increased the safe interval for tasks executed during maintenance windows. Tasks that take less than 55 minutes to execute are not impacted by maintenance operations.
The description of Composer Compute CPU SKUs was changed from "CPU" to "mCPU", to simplify the invoice interpretation. There are no changes in the actual Cloud Composer pricing model.
Improved the validation of custom IP ranges that are specified when an environment is created. The validation is more extensive and redundant error messages were removed.
(Cloud Composer 2) Fixed a problem when an unhealthy web server is not restarted.
(Cloud Composer 1) In-cluster builds for PyPI package installations no longer fail when the constraints/compute.requireShieldedVm policy is turned on.
(New Cloud Composer 1 environments) The minimum disk size for environment nodes is changed from 20 GB to 30 GB.
(Cloud Composer 1) Fixed problems with upgrading to Cloud Composer 1.18.* from earlier versions of Cloud Composer.
Fixed a problem with "Environment health" and "Worker Pod eviction" metrics occasionally not reporting new time-series points.
Cloud Composer 1.18.4 and 2.0.8 images are available:
- composer-2.0.8-airflow-2.2.3
- composer-2.0.8-airflow-2.1.4
- composer-1.18.4-airflow-2.2.3
- composer-1.18.4-airflow-2.1.4
- composer-1.18.4-airflow-1.10.15 (default)
Cloud Composer 1.15.1 has reached its end of full support period.
User-defined labels are now included in PagerDuty, Pub/Sub, Webhooks, and email notifications, and you can also view these labels on the details pages of alerting policies and incidents. To learn how you can create user-defined labels that contain severity information and attach those labels to alerting policies or incidents, see Add severity levels to an alerting policy.
Cloud Run reports a new Cloud Monitoring metric: Container Startup Latency, measuring the startup time of container instances.
Error Reporting now supports Webhooks and Slack as notification channels. For more information, see Create notification channel.
Splitting IIS sites into individual containers
Previously to break down N discovered IIS sites into individual containers, you had to manually edit the migration plan to include one site at a time and generate containers artifacts N times. This new feature enables automatic breakdown of N discovered sites into N individual containers in one iteration through a parameter on the migration plan. For more information, see Split a single VM into multiple containers.
Replatform Tomcat applications to containers enhancements
The Tomcat application replatforming flow now enables you to manually specify a Tomcat server installation directory before the migration. This allows you to override the related automatic discovery in cases where you know and would like to provide an exact location. For more information see, Adding a target project.
Building and deploying containers with Skaffold
Skaffold yamls generated as part of the migration artifacts for Tomcat, WebSphere and Linux system container flows now help you to accelerate container image builds and deployments to GKE and Anthos clusters
Migrate for Compute Engine v5.0 as a migration support
Currently, Migrate for GKE and Anthos uses Migrate for Compute Engine 4.X to enable workload migration from VMWare on-premise, AWS EC2, and Azure VM environments to GCP. To simplify setup and elevate the operator experience migrating from inventories in these environments, we now offer using the new Migrate for Compute Engine v5.X managed service. This new integration is now in public preview. For more information, see Enabling Google services and configuring service accounts.
In-place migration on Anthos Bare Metal Clusters
Support has been added for implementing Anthos clusters on Bare Metal as processing clusters to perform migrations for on-premise workloads. This public preview offering will serve customers who would like to deploy on-premises workloads on Anthos Bare Metal clusters allowing the migration to containers to take place on-premise as well. For more information see, Configuring a processing cluster on Anthos on Bare Metal.
Replatform Websphere applications to containers
Version 1.11 introduces a new public offering for replatforming VMs based on WebSphere applications into containers using tWAS (traditional WebSphere Server) container image or Open Liberty community images. Migrate for Anthos and GKE now enables: * Detecting VMs that host WebSphere servers * Discovering WebSphere applications using the IBM binary scanner tool * Splitting the applications into individual containers to increase agility in deployment and operation management * Generating docker file, deployment spec and other artifacts that support deployment to Google modern application platforms and Day2 operations.
208040681: Resolved operating system field 'disappearing' after running guest level discovery.
194186514: Resolved migrations done in Anthos on AWS might succeed even though the files were not uploaded.
Uninstall might be stuck when a sourcesnapshot CRD cannot be deleted. To workaround this please run kubectl edit sourcesnapshot -n v2k-system and remove all finalizers
204879458: If image repository permissions are invalid, the migration will get stuck in the ExtractImage step instead of the UploadImage step
225638684: OpenLiberty containers may fail to run web applications deployed as WAR archives.
218855996: Windows global path variables and short folders names are not migrated.
223553376: Secrets created by migctl, for example when creating a source provider, may not always be cleaned up when the objects that depend on them are deleted. For example when issuing migctl source delete.
216537540: migctl cannot be used to upgrade the Migrate installation newer than the migctl version. For example, if migctl is version 1.9.0, it cannot upgrade a cluster to 1.11.0.
March 25, 2022
Artifact RegistryArtifact Registry support for attaching tags to repositories is now in Preview. Tags are key-value pairs that you can use to group repositories and other resources across Google Cloud for reporting, auditing, and access control within your Google Cloud organization.. To learn more, see Tagging repositories.
Cloud Bigtable support for Cloud EKM is generally available (GA). You can now choose an externally managed key when you protect your data using customer managed encryption keys (CMEK). Cloud EKM includes Key Access Justification, which lets you view the reason for each Cloud EKM request.
Cloud EKM now supports Cloud Bigtable and Log Storage in Cloud Logging. For more information, see Cloud External Key Manager.
Cloud Logging now supports organization policies that can enforce CMEK protection. For information, see CMEK organization policies.
All instances with a compute capacity of at least one node (1,000 processing units) now have a data storage allotment of 4 TB per node, an increase from 2 TB per node. Relatedly, instances smaller than one node now have a data storage allotment of 409.6 GB for every 100 processing units.
Customer-managed encryption key (CMEK) organization policy constraints are now available in Preview.
* constraints/gcp.restrictNonCmekServices allows you to control which resources require the use of CMEK.
* constraints/gcp.restrictCmekCryptoKeyProjects allows you to control the projects from which a KMS key can be used to validate requests.
* You can use both constraints together to enforce the use of CMEK from allowed projects.
New & Updated processors available
The following Lending DocAI processors are now available for trusted testers. Access to the trusted testers program is limited and granted on a case by case basis. If you would like to be considered please fill out the DocAI Processor Access Request Form:
New Experimental processors to support new document types:
- Form VA Loan Discharge Statement Processor
- Form USDA Conditional Statement Processor
- Form 1017 Processor
- Form Biweekly Payment Rider Processor
- Form VBA26 1805 Processor
- Form VBA26 6393 Processor
- Form MERS Rider Processor
Updated Experimental processors:
- Form 4506-T Processor
- Form 4506-C Processor
- Form HUD54114 Processor
- Form HUD92900WS Processor
- Form HUD92800 Processor
- Form 1040-NR Processor
- Form HUD92900LT Processor
- Form VBA26 8923 Processor
- Form HUD92900A Processor
- FORM_1005_PROCESSOR
Added ability to set the number of cores available per node in a cluster to meet your application-specific requirements during cluster creation. When you use a custom core count, any future expansions or maintenance of that cluster will also use the custom core count.
The public IP service now supports the ICMP protocol, and default firewall rules for new projects expand the previous outbound rule to allow outbound TCP, UDP, and ICMP any.
Users with Google Cloud projects created before March 8, 2022 must contact Cloud Customer Care to enable the allow-icmp-to-internet firewall rule.
IAM Conditions now provides resource attributes for Apigee X. You can use these resource attributes to grant access to a subset of your Apigee X resources.
Maintenance Windows are now Generally Available for Memorystore for Redis.
Workflows is now available in the following regions:
asia-east1(Changhua County, Taiwan)asia-northeast1(Tokyo, Japan)asia-south1(Mumbai, India)australia-southeast1(Sydney, Australia)northamerica-northeast1(Montréal, Québec)us-west1(The Dalles, Oregon)
March 24, 2022
Anthos Config ManagementNew Nomos CLI ARM binaries for Linux and Mac (darwin) are now available. Users on these platforms can now install with gcloud components install nomos. The new binary versions will be included in Anthos Config Management downloads.
You can now specify apply and delete ordering using the new config.kubernetes.io/depends-on annotation. To learn more, see Declare resource dependencies between resource objects.
Added dependency enforcement to skip apply of objects whose dependencies are not successfully applied and fully reconciled.
Added support for multiple RootSync objects on the same cluster and multiple RepoSync objects in the same namespace. To learn more, see Configure syncing from multiple repositories.
Added new fields to the ResourceGroup inventory object to distinguish between actuation status and reconciliation status, as well as the intended actuation strategy (apply or delete) before actuation.
Updated the spec.override.resources field on RootSync and RepoSync to let you override the default resource amounts (for example, CPU or memory) requested by the corresponding containers of the reconciler Deployment. To learn more, see Troubleshoot Config Sync.
Increased the config-management-operator container memory request to 100Mi.
Increased the reconciler-manager container memory request to 50Mi and memory limit to 200Mi.
Increased the admission-webhook container memory request to 100Mi and memory limit to 250Mi.
Fixed individual resource object status to correspond to actuation and reconciliation of the latest specification from Git, not just reconciliation status of the last specification that was successfully applied.
Anthos clusters on VMware 1.9.5-gke.2 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.9.5-gke.2 runs on Kubernetes v1.21.5-gke.1200.
The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.10, 1.9, and 1.8.
Fixed issue: Failure to register admin cluster during creation.
- If the cluster registration failed when creating a 1.9.5 admin cluster, you can upgrade to later versions after version 1.9.5 without applying the documented mitigation.
Fixed high-severity CVEs:
On March 24, 2022, we released a new version of the Apigee Analytics software.
We welcome your feedback about the anomaly events feature in Advanced API Operations. If you have received an anomaly alert, you can send feedback about the alert in the API Monitoring Investigate dashboard by clicking the Anomaly Feedback button at the top of the Anomaly Event Details pane.
hybrid v1.6.6
On March 24, 2022 we released an updated version of the Apigee hybrid v1.6.6 software.
For information on upgrading, see Upgrading Apigee hybrid to version 1.6.
| Bug ID | Description |
|---|---|
| 224577096 | Support Added for Anthos Service Mesh 1.12 |
| 204368970 | Fixed a bug in TLS variables population |
| 199952038 | The apigeectl command uses the new --restore flag to restore Cassandra to a previously saved snapshot. For more information, see Restoring in a single region. |
hybrid v1.5.9
On March 24, 2022 we released an updated version of the Apigee hybrid v1.5.9 software.
For information on upgrading, see Upgrading Apigee hybrid to version 1.5.
| Bug ID | Description |
|---|---|
| 224577096 | Support Added for Anthos Service Mesh 1.12 |
| 204368970 | Fixed the bug in TLS variables population |
Support for Serverless VPC Access connectors in Shared VPC host projects is now at general availability (GA). Learn about the advantages of this method and how to configure connectors in host projects.
Support for Serverless VPC Access connectors in Shared VPC host projects is now at general availability (GA). Learn about the advantages of this method and how to configure connectors in host projects.
Support for Serverless VPC Access connectors in Shared VPC host projects is now at general availability (GA). Learn about the advantages of this method and how to configure connectors in host projects.
Support for Serverless VPC Access connectors in Shared VPC host projects is now at general availability (GA). Learn about the advantages of this method and how to configure connectors in host projects.
Support for Serverless VPC Access connectors in Shared VPC host projects is now at general availability (GA). Learn about the advantages of this method and how to configure connectors in host projects.
Support for Serverless VPC Access connectors in Shared VPC host projects is now at general availability (GA). Learn about the advantages of this method and how to configure connectors in host projects.
Support for Serverless VPC Access connectors in Shared VPC host projects is now at general availability (GA). Learn about the advantages of this method and how to configure connectors in host projects.
Support for Serverless VPC Access connectors in Shared VPC host projects is now at general availability (GA). Learn about the advantages of this method and how to configure connectors in host projects.
Support for Serverless VPC Access connectors in Shared VPC host projects is now at general availability (GA). Learn about the advantages of this method and how to configure connectors in host projects.
The following resource types are now publicly available through the Export APIs (ExportAssets and BatchGetAssetsHistory), the Feed API, and the Search APIs
(SearchAllResources and SearchAllIamPolicies):
- Datastream
datastream.googleapis.com/ConnectionProfiledatastream.googleapis.com/PrivateConnectiondatastream.googleapis.com/Stream
- Anthos clusters on-prem
anthos.googleapis.com/ConnectedCluster
- Database Migration Service
datamigration.googleapis.com/ConnectionProfiledatamigration.googleapis.com/MigrationJob
Support for Serverless VPC Access connectors in Shared VPC host projects is now at the General Availability release level. Learn about the advantages of this method and how to configure connectors in host projects.
Support for Serverless VPC Access connectors in Shared VPC host projects is now at general availability (GA). Learn about the advantages of this method and how to configure connectors in host projects.
Config Controller now uses version 1.77.0 for Config Connector (release notes)
March 23, 2022
Anthos clusters on bare metalRelease 1.9.6
Anthos clusters on bare metal 1.9.6 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.9.6 runs on Kubernetes 1.21.
Fixes:
- The following container image security vulnerabilities have been fixed:
- CVE-2021-43824
- CVE-2021-43825
- CVE-2021-43826
- CVE-2021-21654
- CVE-2021-21655
- CVE-2021-23606
- CVE-2021-21657
- CVE-2021-21656
- CVE-2021-23635
- CVE-2022-23648
- CVE-2021-45960
- CVE-2021-3996
- CVE-2021-3995
- CVE-2021-45960
- CVE-2022-22823
- CVE-2022-22824
- CVE-2022-22822
- CVE-2022-23852
- CVE-2022-23990
- CVE-2021-43618
- CVE-2022-22825
- CVE-2022-22827
- CVE-2021-46143
- CVE-2022-22826
Known issues:
When you upgrade Anthos clusters on bare metal from a version with a security patch to the next minor release, we recommend that you upgrade to the highest patch version to ensure that you have the latest security fixes. Always review the release notes before upgrading so that you're aware of what has changed, including security fixes and known issues. Upgrading to a lower release version isn't supported.
For information about the latest known issues, see Anthos on bare metal known issues in the Troubleshooting section.
The following resource types are now publicly available through the Analyze Policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning):
- Dialog ES API
dialogflow.googleapis.com/ConversationProfiledialogflow.googleapis.com/KnowledgeBase
- Vertex AI
aiplatform.googleapis.com/PipelineJobaiplatform.googleapis.com/MetadataStoreaiplatform.googleapis.com/ModelDeploymentMonitoringJob
Storage Transfer Service now enforces the Resource Location Restriction, which is part of the Org Policy Service. This allows an organization to define the allowed regions in which location-based Google Cloud resources, such as transfer jobs, can be created.
To learn how Storage Transfer Service chooses the region in which to run a transfer job, refer to Location of Storage Transfer Service jobs.
March 22, 2022
Apigee XOn March 22, 2022, we released an updated version of the Apigee X software.
Support for conditions in IAM policies
You can add resource conditions in your IAM policies. A resource condition lets you have granular control over your Apigee resources. For more information, see Adding resource conditions in IAM policies.
The data type of the COLUMN_DEFAULT column in the information schema COLUMNS table has changed from BYTES to STRING. This aligns better with industry standards and enables future improvements to Cloud Spanner.
The Cloud Talent Solutions dashboard management tool has added a Jobs and Companies page, which displays job statistics and metadata. You can use this page to troubleshoot data issues. The Jobs and Companies page has three tabs:
- On the Summary tab, see the latest job count snapshots and a visualization of job count statistics over time.
- On the Job Metadata tab, search for specific jobs and their available metadata.
- On the Exports tab, export your metadata to a BigQuery table for further analysis.
For more about this new feature, see the Jobs and Companies data documentation.
General purpose Tau T2D VMs have limited availability in London (europe-west2-a,c). If you are interested in trying out T2D, speak to your Google Cloud Account Team. For pricing details, see VM instance pricing.
Preview: You can now share sole-tenant node groups with other projects or your entire organization.
There is a misconfiguration with Simultaneous Multi-Threading (SMT), also known as Hyper-threading, on GKE Sandbox images. The misconfiguration leaves nodes potentially exposed to side channel attacks such as Microarchitectural Data Sampling (MDS) (for more context, see GKE Sandbox documentation). We do not recommend using the following affected versions:
- 1.22.4-gke.1501
- 1.22.6-gke.300
- 1.23.2-gke.300
- 1.23.3-gke.600
For instructions and more details, see the GKE security bulletin.
March 21, 2022
Anthos clusters on AWSAnthos clusters on AWS now supports clusters in the ap-southeast-2 region. For more information, see Supported regions.
Anthos clusters on Azure now supports clusters in the australiaeast region. For more information, see Supported regions.
Support for Firebase Remote Config, Firebase Alerts, and Firebase Test Lab triggers is now in Preview. This only applies to Cloud Functions (2nd gen).
Customer-managed encryption keys (CMEK) for Logs Storage are now Generally Available (GA). CMEK lets you create, control, and manage encryption keys to meet your data compliance needs. For details, see Manage the keys that protect Logging storage data .
Added functionality in the companyDisplayNames filter to support fuzzy matching.
Config Connector version 1.78.0 is now available.
Fixed issue where users could not switch between the field singleClusterRouting and the fields multiClusterRoutingUseAny and multiClusterRoutingClusterIds in BigtableAppProfile resources.
Fixed issue where users could not update the policy in ResourceManagerPolicy resources.
Fixed issue where users could not switch between the field github.push and the field github.pullRequest in CloudBuildTrigger resources (Issue #357).
M91 Release
- PyTorch 1.11 and PyTorch XLA 1.11 are now available in both Deep Learning Containers and Deep Learning VM Images.
- Fixed an R package installation issue for R Deep Learning Containers and Vertex AI Workbench.
M91 Release
- PyTorch 1.11 and PyTorch XLA 1.11 are now available in both Deep Learning VM Images and Deep Learning Containers.
- Updated NVIDIA drivers to 470.57.02.
- Upgraded Compute Engine Virtual Ethernet (GVE) to 1.3.0.
Support for Firebase Alerts triggers is now in Preview.
(2022-R6) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
The following control plane and node versions are now available:
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.19 to 1.20.15-gke.1000 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to 1.20.15-gke.1000 with this release.
Stable channel
- Version 1.20.15-gke.1000 is now the default version in the Stable channel.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.19 to 1.20.15-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to 1.20.15-gke.1000 with this release.
Regular channel
The following versions are now available in the Regular channel:
The following versions are no longer available in the Regular channel:
- 1.20.15-gke.1000
- 1.21.6-gke.1503
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.19 to 1.20.15-gke.2500 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.20.15-gke.2500 with this release.
Rapid channel
- Version 1.22.7-gke.900 is now the default version in the Rapid channel.
The following versions are now available in the Rapid channel:
The following versions are no longer available in the Rapid channel:
- 1.21.10-gke.400
- 1.22.6-gke.1500
- 1.23.4-gke.1300
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.10-gke.1300 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.10-gke.1300 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to 1.22.7-gke.300 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.23.4-gke.1600 with this release.
(2022-R6) Version updates
The following control plane and node versions are now available:
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.19 to 1.20.15-gke.1000 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to 1.20.15-gke.1000 with this release.
(2022-R6) Version updates
- Version 1.20.15-gke.1000 is now the default version in the Stable channel.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.19 to 1.20.15-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to 1.20.15-gke.1000 with this release.
(2022-R6) Version updates
The following versions are now available in the Regular channel:
The following versions are no longer available in the Regular channel:
- 1.20.15-gke.1000
- 1.21.6-gke.1503
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.19 to 1.20.15-gke.2500 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.20.15-gke.2500 with this release.
(2022-R6) Version updates
- Version 1.22.7-gke.900 is now the default version in the Rapid channel.
The following versions are now available in the Rapid channel:
The following versions are no longer available in the Rapid channel:
- 1.21.10-gke.400
- 1.22.6-gke.1500
- 1.23.4-gke.1300
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.10-gke.1300 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.10-gke.1300 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to 1.22.7-gke.300 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.23.4-gke.1600 with this release.
Fixed bug in App controller, made App.Status.RouteConditions as an optional field.
March 18, 2022
Cloud Asset InventoryThe following resource types are now publicly available through the Export APIs (ExportAssets and BatchGetAssetsHistory), the Feed API, and the Search APIs
(SearchAllResources and SearchAllIamPolicies):
- Dialog ES API
dialogflow.googleapis.com/ConversationProfiledialogflow.googleapis.com/KnowledgeBase
Using Cloud EKM with a Virtual Private Network is now generally available. This means you can access your external key manager with a private endpoint.
See Using Cloud EKM with VPC to learn more.
Cloud TPU now supports Tensorflow 2.6.3. For more information see TensorFlow 2.6.3 release notes.
March 17, 2022
BigQueryThe BigQuery slot recommender is now available in Preview. The slot recommender creates recommendations for customers using on-demand billing. These recommendations help you to understand the cost and performance tradeoffs of purchasing different amounts of slot capacity.
The following resource types are now publicly available through the Export APIs (ExportAssets and BatchGetAssetsHistory) and the Feed API:
- Network Connectivity API
networkconnectivity.googleapis.com/Hubnetworkconnectivity.googleapis.com/Spoke
Starting from June 1, 2022, new versions of Cloud Composer will no longer support Python 2.
The apache-airflow-providers-google package has operators for Cloud Composer, starting from version 6.4.0.
The Logs tab in Cloud Console is now generally available (GA).
Environment labels are now propagated to the environment's bucket.
Improved the syncing of DAGs and plugins to Airflow components. Objects named "." are ignored when syncing.
(Cloud Composer 1) It is no longer possible to select the e2-micro machine type.
Cloud Composer 1.18.3 and 2.0.7 images are available:
- composer-2.0.7-airflow-2.2.3
- composer-2.0.7-airflow-2.1.4
- composer-1.18.3-airflow-2.2.3
- composer-1.18.3-airflow-2.1.4
- composer-1.18.3-airflow-1.10.15 (default)
Cloud Composer 1.15.0 has reached its end of full support period.
Config Controller now uses version 1.75.0 for Config Connector (release notes)
Dataflow now supports the following Google-provided templates in GA:
- Pub/Sub Subscription to BigQuery
- Pub/Sub Topic to BigQuery
- Pub/Sub Avro to BigQuery
- Pub/Sub Proto to BigQuery
- Pub/Sub to Pub/Sub
- Pub/Sub to Cloud Storage Avro
- Pub/Sub to Cloud Storage Text
- Cloud Storage Text to BigQuery (Stream)
- Cloud Storage Text to Pub/Sub (Stream)
- Change Data Capture to BigQuery (Stream)
- Apache Kafka to BigQuery
- BigQuery export to Parquet (via Storage API)
- Firestore to Cloud Storage Text
- Cloud Spanner to Cloud Storage Text
- Cloud Storage Text to BigQuery
- Cloud Storage Text to Firestore
- Cloud Storage Text to Pub/Sub (Batch)
- Apache Cassandra to Bigtable
- Datastream to Cloud Spanner
- File Format Conversion
- Bulk Compress Cloud Storage Files
- Bulk Decompress Cloud Storage Files
- Firestore Bulk Delete
- Streaming Data Generator to Pub/Sub, BigQuery, and Cloud Storage
New sub-minor versions of Dataproc images:
1.5.59-debian10, 1.5.59-ubuntu18, and 1.5.59-rocky8
2.0.33-debian10, 2.0.33-ubuntu18, and 2.0.33-rocky8
Migrate for Compute Engine allows you to employ a VPC-SC service perimeter and communicate with select services using your migrate connector.
For more information about using a VPC-SC perimeter, see the secure your migrations in a service perimeter documentation.
Preview stage support for the following integration:
Beta stage support for the following integration:
March 16, 2022
BigQueryYou can now explicitly specify a schema for BigQuery external tables created over Parquet, ORC, and Avro file formats. Previously, the schema was always auto-detected using the last lexicographic file.
Database Migration Service now supports version 14 of Cloud SQL for PostgreSQL. Click here to access the documentation.
General-purpose Tau T2D virtual machine instances are available in the following regions and zones:
- Northern Virginia (us-east4-a,b,c)
- South Carolina (us-east1-b,c,d)
- Frankfurt (europe-west3-a,b,c)
- Sydney (australia-southeast1-a,b,c)
- Taiwan (asia-east1-a,b,c)
See VM instance pricing for details.
Config Connector version 1.77.0 is now available.
Added support for IdentityPlatformConfig resource.
Added support for ARM binaries.
Starting in GKE version 1.22, the Compute Engine persistent disk CSI driver is generally available for Windows clusters.
Read replicas are now Generally Available for Memorystore for Redis.
March 15, 2022
Anthos clusters on VMwareAnthos clusters on VMware 1.8.8-gke.1 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.8.8-gke.1 runs on Kubernetes v1.20.12-gke.1500.
The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.10, 1.9, and 1.8.
Fixed high-severity CVEs:
Container vulnerabilities:
Kernel vulnerabilities (ubuntu only):
Containerd vulnerabilities:
Fixed critical CVEs:
- Container vulnerabilities:
Fixed issue where
osImagefield is not updated for Windows Server OS node pools during cluster upgrade.
- Clusters with
enableDataplaneV2enabled can experience connectivity issues between Pods due toanetddaemons (running as a Daemonset) entering a software deadlock. While in this state, it will see stale nodes (previously deleted nodes) as its peers and miss newly added nodes as its new peers. If you have experienced this issue, restart theanetddaemons to refresh the peer nodes, and connectivity should be restored.
On March15, we released version 1.7x of Apigee X (1-7-0-apigee-22).
GraphQL policy now supports JSON-encoded payloads.
KVM pagination support now available.
Note: When using the GraphQL policy, you can only provide one graphQL schema for verification in an environment.
| Bug ID | Description |
|---|---|
| 209622008 | Dynamic updates to rate in spike arrest are now reflected immediately. |
| 219523719 | Fix to address CPU and memory consumption when debug-session is enabled with response-status as the filtering criteria. |
All released artifacts that start with version 2.x.x use the open source release mechanism. Released artifacts that start with version 1.9.9xx or earlier use the internal build system. See the appengine-java-standard repository for more details.
The following GKE versions fix a known issue in which random TCP connection resets might happen for GKE nodes that use Container-Optimized OS with Docker (cos). To fix the issue, upgrade your nodes to any of these versions:
- 1.20.15-gke.3400 and later
- 1.21.10-gke.1300 and later
- 1.22.7-gke.1300 and later
- 1.23.4-gke.1300 and later
Fixed bug in App controller, made App.Status.RouteConditions as an optional field.
March 14, 2022
Anthos clusters on bare metalRelease 1.8.9
Anthos clusters on bare metal 1.8.9 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.8.9 runs on Kubernetes 1.20.
Fixes:
- The following container image security vulnerabilities have been fixed:
Known issues:
When upgrading Anthos clusters on bare metal from a version with a security patch to the next minor release, we recommend that you upgrade to the highest patch version to ensure that you have the latest security fixes. Always review the release notes before upgrading so that you're aware of what has changed, including security fixes and known issues. Upgrading to a lower release version isn't supported.
For information about the latest known issues, see Anthos on bare metal known issues in the Troubleshooting section.
The Java 17 runtime for App Engine standard environment is now available in Preview.
The Ruby 3.0 runtime for App Engine standard environment is now available in Preview.
Cloud Functions has added support for the following new runtimes at the Preview release level:
Starting October 1, 2022, we'll apply an outbound data processing charge of $0.008 - $0.012 per GB (based on region) to all Cloud Load Balancing products in order to maintain consistency and alignment with the variable costs of the services across our Cloud Load Balancing portfolio. The charge will be called Outbound data processed by load balancer and the price will mirror the existing price for the Inbound data processed by load balancer charge.
If you are on an existing contract, your prices will not change for the lifetime of the contract, or until renewal.
The current internal HTTP(S) load balancer pricing already includes this charge, so no changes are being made there.
To learn more about this change, see the Google Cloud Blog post: Unlock more choice with updates to Google Cloud's infrastructure capabilities and pricing.
Backend subsetting for internal TCP/UDP load balancers lets you scale your internal TCP/UDP load balancer to support a larger number of backend VM instances per internal backend service.
This feature is in General availability.
On October 1, 2022, certain prices in Cloud Storage will be changing. For a list of pricing changes, see the announcement.
Generally available: Compute Engine now supports Suspend and Resume in General Availability.
Fixed the issue causing the Compute Engine API Quotas page in the Cloud Console to display duplicate API quota groups.
(2022-R5) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- Version 1.21.9-gke.1002 is now the default version.
The following control plane and node versions are now available:
The following control plane versions are no longer available:
- 1.19.16-gke.3600
- 1.20.11-gke.1300
- 1.20.11-gke.1801
- 1.22.4-gke.1501
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.18 to 1.19.16-gke.6100 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.19 to 1.20.15-gke.300 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to 1.20.15-gke.300 with this release.
Stable channel
- Version 1.20.15-gke.300 is now the default version in the Stable channel.
The following versions are now available in the Stable channel:
The following versions are no longer available in the Stable channel:
- 1.19.16-gke.3600
- 1.20.11-gke.1801
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.18 to 1.19.16-gke.6100 with this release.
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.19 to 1.20.15-gke.300 with this release.
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to 1.20.15-gke.300 with this release.
Regular channel
- Version 1.21.9-gke.1002 is now the default version in the Regular channel.
- Version 1.20.15-gke.1000 is now available in the Regular channel.
- Version 1.20.15-gke.300 is no longer available in the Regular channel.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.19 to 1.20.15-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.9-gke.1002 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.21.9-gke.1002 with this release.
Rapid channel
- Version 1.22.7-gke.300 is now the default version in the Rapid channel.
The following versions are now available in the Rapid channel:
The following versions are no longer available in the Rapid channel:
- 1.21.9-gke.1002
- 1.22.6-gke.1000
- 1.23.4-gke.300
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.10-gke.400 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.10-gke.400 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to 1.22.6-gke.1500 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to 1.23.4-gke.1300 with this release.
If you specify --enable-dataplane-v2 in a Windows LTSC node pool running GKE version 1.22.7-gke.1300, Windows nodes cannot join the cluster.
(2022-R5) Version updates
- Version 1.21.9-gke.1002 is now the default version.
The following control plane and node versions are now available:
The following control plane versions are no longer available:
- 1.19.16-gke.3600
- 1.20.11-gke.1300
- 1.20.11-gke.1801
- 1.22.4-gke.1501
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.18 to 1.19.16-gke.6100 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.19 to 1.20.15-gke.300 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to 1.20.15-gke.300 with this release.
If you specify --enable-dataplane-v2 in a Windows LTSC node pool running GKE version 1.22.7-gke.1300, Windows nodes cannot join the cluster.
(2022-R5) Version updates
- Version 1.22.7-gke.300 is now the default version in the Rapid channel.
The following versions are now available in the Rapid channel:
The following versions are no longer available in the Rapid channel:
- 1.21.9-gke.1002
- 1.22.6-gke.1000
- 1.23.4-gke.300
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.10-gke.400 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.10-gke.400 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to 1.22.6-gke.1500 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to 1.23.4-gke.1300 with this release.
If you specify --enable-dataplane-v2 in a Windows LTSC node pool running GKE version 1.22.7-gke.1300, Windows nodes cannot join the cluster.
(2022-R5) Version updates
- Version 1.20.15-gke.300 is now the default version in the Stable channel.
The following versions are now available in the Stable channel:
The following versions are no longer available in the Stable channel:
- 1.19.16-gke.3600
- 1.20.11-gke.1801
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.18 to 1.19.16-gke.6100 with this release.
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.19 to 1.20.15-gke.300 with this release.
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to 1.20.15-gke.300 with this release.
(2022-R5) Version updates
- Version 1.21.9-gke.1002 is now the default version in the Regular channel.
- Version 1.20.15-gke.1000 is now available in the Regular channel.
- Version 1.20.15-gke.300 is no longer available in the Regular channel.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.19 to 1.20.15-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.9-gke.1002 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.21.9-gke.1002 with this release.
Between April 2, 2022 and December 31, 2022, transfers using Storage Transfer Service will not result in Cloud Storage charges for certain transfer scenarios.
For more details, refer to the Storage Transfer Service pricing page.
A new client_zone label is added to the Connected Streams metric. The new label might introduce a breaking change. The change creates a stream discontinuity, which might have some effect on your monitoring, depending on whether you configured an alert on this metric.
March 11, 2022
Cloud LoggingYou can now collect RabbitMQ logs from the Ops Agent, starting with version 2.12.0. For more information, see Monitoring third-party applications: RabbitMQ.
You can now collect WildFly metrics from the Ops Agent, starting with version 2.12.0. For more information, see Monitoring third-party applications: WildFly.
March 10, 2022
Anthos Service MeshThe Istio project recently disclosed a CVE that can expose Anthos Service Mesh to remotely exploitable vulnerabilities. For more information, see the security bulletin.
1.12.5-asm.0 is now available.
This patch release contains the fixes for the security vulnerability listed in GCP-2022-010. For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
1.11.8-asm.0 is now available.
This patch release contains the fixes for the security vulnerability listed in GCP-2022-010. For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
1.10.6-asm.2 is now available.
This patch release contains the fixes for the security vulnerability listed in GCP-2022-010. For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
The following resource types are now publicly available through the resource search API (SearchAllResources) and policy search API (SearchAllIamPolicies):
- Network Management API
networkmanagement.googleapis.com/ConnectivityTest
Database Migration Service now supports adding dump flags for data dump customizations to migration jobs for Cloud SQL for MySQL instances. Click here to access the documentation.
Cloud Spanner now offers committed use discounts. You can get significantly discounted prices in exchange for your commitment to use Cloud Spanner compute resources continuously for a year or longer.
Document AI is now generally available (GA) in the following new locations:
europe-west3asia-southeast1
You must request access to use the new locations. For more information, see Regional and multi-regional support.
In GKE version 1.23.2-gke.300 and later, you can now use network tags to dynamically apply firewall rules to nodes in your GKE Autopilot clusters and auto-provisioned GKE Standard node pools without disrupting running workloads.
March 09, 2022
Cloud Asset InventoryThe following resource types are now publicly available through the Analyze Policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning):
- Certificate Authority Service
privateca.googleapis.com/CaPoolprivateca.googleapis.com/CertificateAuthorityprivateca.googleapis.com/CertificateRevocationListprivateca.googleapis.com/CertificateTemplate
- DLP
dlp.googleapis.com/DlpJobdlp.googleapis.com/DeidentifyTemplatedlp.googleapis.com/InspectTemplatedlp.googleapis.com/JobTriggerdlp.googleapis.com/StoredInfoType
The _type and _since parameters are available for the fhirStores.export method. You can use these parameters to filter resources from exporting. This increases the speed of the export process and eliminates unwanted export data.
Cloud TPU now supports Tensorflow 2.5.3 and 2.7.1. For more information see TensorFlow 2.5.3 release notes and TensorFlow 2.7.1 release notes.
The following GKE versions fix a known issue in which the CAP_NET_BIND_SERVICE file capability was dropped from the metrics-server. To fix the issue, upgrade your control plane to any of these versions:
- 1.21.9-gke.1002 and later
- 1.21.10-gke.400 and later
- 1.22.6-gke.300 and later
- 1.22.7-gke.300 and later
- 1.22.7-gke.900 and later
- 1.23.4-gke.300 and later
Basic Tier instances now preserve data during scaling and maintenance. For a full list of operations/scenarios that cause a cache flush for the Basic Tier, see cache flush for Basic Tier.
March 08, 2022
Cloud BillingReport filters now support the display of IDs in addition to names in the filter panels.
In the Cloud Billing Console, when you are viewing the options displayed in the filter panels for Subaccounts, Projects, Services, and SKUs, you can now see both the option name and the option ID (for example, project name and project ID). The ID displays below each option name. Previously, only the name was displayed when viewing the list of options in a filter panel. View an example of the Services filter panel, before and after the update.
With the addition of the ID, you can do the following:
- Within a filter panel, search by name or by ID (for example: "BigQuery" or "services/24E6-581D-38E5").
- More easily match a filter option to an invoice line item. For example, instead of searching for the "Active Storage" SKU, you can search for SKU ID "services/24E6-581D-38E5/skus/947D-3B46-7781".
- You can use partial values when searching within a filter panel, and you will get back all matching results. For example, you can type to filter on "storage" or "24e6" or "7781".
Learn more about using filters in Cloud Billing Reports and the Cost breakdown report.
(Available without upgrading) New version aliases for Cloud Composer images. Now you can specify the latest version of Cloud Composer 2 with composer-2-airflow-x.y aliases. New composer-1-airflow-x.y aliases point to the latest version of Cloud Composer 1.
(Airflow 2) Added a new try-number label to Airflow task log entries.
(Cloud Composer 1) Fixed a problem with web server metrics not being reported or being reported partially.
(Available without upgrading) DAG UI now correctly handles invalid serialized DAG data.
Improved the handling of errors generated during update and upgrade operations because of an invalid pip.conf configuration file.
(Airflow 1) The apache-airflow-backport-providers-google package is updated to version 2022.2.22.
Cloud Composer 1.18.2 and 2.0.6 images are available:
- composer-2.0.6-airflow-2.2.3
- composer-2.0.6-airflow-2.1.4
- composer-1.18.2-airflow-2.2.3
- composer-1.18.2-airflow-2.1.4
- composer-1.18.2-airflow-1.10.15 (default)
Cloud Composer 1.14.5 has reached its end of full support period.
You can now see and manage the views of your Cloud Spanner databases from the Google Cloud Console. To do so, visit a database's Overview page, and then click the Views tab.
Setting a minimum CPU platform for node pools created by node auto-provisioning using the autoscaling.autoprovisioning_node_pool_defaults.min_cpu_platform field is deprecated. This field will be removed in a future release. In GKE versions 1.23 and later, you can request a minimum CPU platform at the workload level using a node selector or node affinity rule for cloud.google.com/requested-min-cpu-platform. For instructions, refer to Minimum CPU platform.
Storage Transfer Service now offers more control over preserving metadata when transferring between Cloud Storage buckets. Choose to retain or discard metadata including object ACLs, customer-managed encryption keys (CMEK), temporary holds, and object creation time. In addition, storage class can be set to any supported value, allowing you to change storage class at scale.
For details, refer to Metadata preservation.
General availability for the following integration:
March 07, 2022
AnthosAnthos component releases for February, 2022
Anthos clusters on VMware:
- February 07, 2022: Security bulletin
- February 10, 2022: 1.10.1 patch release
- February 11, 2022: Security bulletin
- February 14, 2022: Security bulletin
- February 17, 2022: 1.8.7 patch release
- February 23, 2022: 1.9.4 patch release
- February 24, 2022: Security bulletin
Anthos clusters on bare metal:
- February 01, 2022: 1.8.8 patch release
- February 04, 2022: Security bulletin
- February 25, 2022: 1.10.2 patch release and security bulletin
- February 28, 2022: 1.9.5 patch release
Anthos clusters on AWS:
- February 04, 2022: Security bulletin
- February 22, 2022: 1.21.6 patch release
- February 24, 2022: aws-1.10.2-gke.0 (previous generation) patch release
Anthos clusters on Azure:
- February 04, 2022: Security bulletin
- February 11, 2022: Security bulletin
- February 14, 2022: Security bulletin
- February 22, 2022: 1.21.6 patch release
Anthos Config Management:
Anthos Service Mesh:
- February 04, 2022: Managed Anthos Service Mesh patch release
- February 22, 2022: 1.10.x, 1.11.x, and 1.12.x patch release
Connect:
Cloud Run for Anthos:
Migrate for Anthos and GKE:
- N/A
Cloud Logging:
Cloud Monitoring:
Added Terraform support for Cloud Functions (2nd gen).
Generally available: NVIDIA® T4 GPUs are now available in the following additional regions and zones:
- Council Bluffs, Iowa, North America :
us-central1-c - Eemshaven, Netherlands, Europe :
europe-west4-a
For more information about using GPUs on Compute Engine, see GPUs on Compute Engine.
New sub-minor versions of Dataproc images:
1.5.58-debian10, 1.5.58-ubuntu18, and 1.5.58-rocky8
2.0.32-debian10, 2.0.32-ubuntu18, and 2.0.32-rocky8
Fixed bug where clusters created via Dataproc Hub failed with Unit
file jupyter.service does not exist error.
Fixed bug where clusters created with Kerberos failed with SSL
Certificate string is too long error.
Support for Firebase Remote Config and Firebase Test Lab triggers is now in Preview.
(2022-R4) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- The following control plane and node versions are now available:
The following control plane versions are no longer available:
- 1.19.16-gke.1500
- 1.21.5-gke.1802
- 1.22.3-gke.1500
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.18 to 1.19.16-gke.3600 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.19 to 1.19.16-gke.3600 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to 1.21.6-gke.1503 with this release.
Stable channel
The following versions are now available in the Stable channel:
The following versions are no longer available in the Stable channel:
- 1.19.16-gke.1500
- 1.20.11-gke.1300
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.18 to 1.19.16-gke.3600 with this release.
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.19 to 1.19.16-gke.3600 with this release.
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to 1.21.5-gke.1805 with this release.
Regular channel
- The following versions are now available in the Regular channel:
The following versions are no longer available in the Regular channel:
- 1.20.12-gke.1500
- 1.21.5-gke.1805
- 1.22.3-gke.1500
- 1.22.4-gke.1501
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.19 to 1.20.15-gke.300 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.6-gke.1503 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.21.6-gke.1503 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to 1.22.6-gke.300 with this release.
Rapid channel
- Version 1.22.6-gke.1500 is now the default version in the Rapid channel.
The following versions are now available in the Rapid channel:
The following versions are no longer available in the Rapid channel:
- 1.21.9-gke.300
- 1.21.9-gke.1001
- 1.22.4-gke.1501
- 1.22.6-gke.300
- 1.23.3-gke.1100
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.9-gke.1002 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.9-gke.1002 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to 1.22.6-gke.1000 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.23.4-gke.300 with this release.
Identity Service for GKE is now generally available. You can authenticate to GKE clusters with external identity providers that use OpenID Connect (OIDC).
(2022-R4) Version updates
- The following control plane and node versions are now available:
The following control plane versions are no longer available:
- 1.19.16-gke.1500
- 1.21.5-gke.1802
- 1.22.3-gke.1500
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.18 to 1.19.16-gke.3600 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.19 to 1.19.16-gke.3600 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to 1.21.6-gke.1503 with this release.
(2022-R4) Version updates
- The following versions are now available in the Regular channel:
The following versions are no longer available in the Regular channel:
- 1.20.12-gke.1500
- 1.21.5-gke.1805
- 1.22.3-gke.1500
- 1.22.4-gke.1501
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.19 to 1.20.15-gke.300 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.6-gke.1503 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.21.6-gke.1503 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to 1.22.6-gke.300 with this release.
(2022-R4) Version updates
Version 1.22.6-gke.1500 is now the default version in the Rapid channel.
The following versions are now available in the Rapid channel:
The following versions are no longer available in the Rapid channel:
- 1.21.9-gke.300
- 1.21.9-gke.1001
- 1.22.4-gke.1501
- 1.22.6-gke.300
- 1.23.3-gke.1100
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.9-gke.1002 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.9-gke.1002 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to 1.22.6-gke.1000 with this release.
Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.23.4-gke.300 with this release.
(2022-R4) Version updates
The following versions are now available in the Stable channel:
The following versions are no longer available in the Stable channel:
- 1.19.16-gke.1500
- 1.20.11-gke.1300
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.18 to 1.19.16-gke.3600 with this release.
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.19 to 1.19.16-gke.3600 with this release.
Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to 1.21.5-gke.1805 with this release.
Exactly once delivery gives you the ability to receive any successfully published message exactly once.
For more information, see Exactly once delivery.
To support a rich query experience on complex array elements, the contains() filter function was introduced. You can use this function in your finding queries to do the following:
- Exact element matching: Match array elements that contain the exact string,
"example". - Specific number operations: Match array elements that are greater than or equal to
100. - Complex filtering against array structures: Match array elements that contain property
xwith a corresponding valuey.
For more information, see Filtering on array-type fields.
Vertex AI Feature Store online store autoscaling is available in Preview. The online store nodes automatically scale to balance performance and cost with different traffic patterns. The offline store already scales automatically.
You can now mount Network File System (NFS) shares to access remote files when you run a custom training job. For more information, see Mount an NFS share for custom training.
This feature is in Preview.
Google Cloud Pipeline Components SDK v1.0 is now generally available.
You can now enable and use reCAPTCHA Enterprise on Google Cloud without enabling billing for your Google Cloud project. For more information, see Billing information.
March 04, 2022
BigQuerySession support for BigQuery is now generally available (GA). In addition to the features available in the preview, you can:
You can now organize your dashboard widgets into collapsible groups. For more information, see Organize dashboard widgets.
Public Preview: You can set the maximum amount of time that Compute Engine waits before terminating or restarting an unresponsive VM. For more information, see Set VM availability policies.
Config Connector version 1.75.0 is now available.
Added support for BillingBudgetsBudget resource.
Added support for EventarcTrigger resource.
Added support for LoggingLogView resource.
Added field spec.rule[].rateLimitOptions into ComputeSecurityPolicy resource.
Added fields spec.addonsConfig.gcpFilestoreCsiDriverConfig and spec.clusterAutoscaling.autoProvisioningDefaults.imageType into ContainerCluster resource.
Added fields spec.maintenancePolicy and spec.maintenanceSchedule into RedisInstance resource.
Added fields spec.transferSpec.awsS3DataSource.roleArn, spec.transferSpec.posixDataSink and spec.transferSpec.posixDataSource into StorageTransferJob resource.
Added field status.selfLink into NetworkServicesGateway,NetworkServicesGRPCRoute, NetworkServicesHTTPRoute, NetworkServicesMesh and NetworkServicesTCPRoute resources.
StorageTransferJob: Fields spec.schedule and spec.transferSpec.awsS3DataSource.awsAccessKey are no longer required.
You can now use the Apache Beam SDK for Go to create batch Dataflow pipelines. This feature is in Preview.
Some unexpected paths to access the node VM on GKE Autopilot clusters could have been used to escalate privileges in the cluster. These issues have been fixed and no further action is required. The fixes address issues reported through our Vulnerability Reward Program.
For instructions and more details, see the GCP-2022-009 security bulletin.
Public clusters created on GKE versions 1.22 and later, and created between October 28, 2021 and February 17, 2022 use Private Service Connect (PSC). Therefore, each control plane is assigned to a private IP address from the cluster node subnet.
For public clusters created outside of this time frame or with a different GKE version, the control plane has a public IP address by default.
March 03, 2022
Anthos clusters on VMwareAnthos clusters on VMware 1.10.2-gke.34 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.10.2-gke.34 runs on Kubernetes 1.21.5-gke.1200.
The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.10, 1.9, and 1.8.
Changes
gkectl diagnosenow reports a broken cluster caused by an admin cluster registration error during creation.
Fixes
Fixed issue: Failure to register admin cluster during creation
- You can upgrade an admin cluster to version 1.10.2 without applying the documented mitigation, even if the cluster failed to register with the provided gkeConnect configuration during its creation. You can fix the registration issue by running
gkectl update adminwith the correct gkeConnect configuration after upgrade. - If the cluster registration failed when creating a version 1.10.2 admin cluster, no mitigation is needed to upgrade to later versions after version 1.10.2.
- You can upgrade an admin cluster to version 1.10.2 without applying the documented mitigation, even if the cluster failed to register with the provided gkeConnect configuration during its creation. You can fix the registration issue by running
Fixed ".local" DNS lookup issue caused by Ubuntu 20.04 systemd-resolved configuration changes.
Fixed issue where Docker bridge IP incorrectly used 172.17.0.1/16 instead of 169.254.123.1/24.
Fixed unexpectedly high network traffic to monitoring.googleapis.com in a newly created cluster.
Fixed an issue that admin cluster creation or upgrade might be interrupted by temporary vCenter connection issue.
Fixed critical CVEs:
Fixed this high-severity CVE:
When cluster autoscaling is enabled in a Dataplane-v2 cluster, scale down may sometimes take longer than expected. For example, it may take approximately 20 minutes instead of 10 minutes as in a normal case.
Envoy adapter v2.0.5
On March 3, 2022 we released a new version of Apigee Adapter for Envoy v2.0.5.
Security release to address a Denial of Service (DoS) risk in the prometheus library. See CVE-2022-21698.
On March 3, 2022, we released new features for the Public Preview of configurable API proxies. To learn more, see Introduction to configurable API proxies.
HTTP request transforms are now available for use with configurable API proxies.
With HTTP request transforms, configurable API proxy developers can quickly rewrite HTTP request paths, header, and query parameters using HTTP Request Transforms. Rewriting is enabled using a simple configuration that can reference incoming path template segments, header values, or query parameter values.
For more information, see HTTP request transforms for configurable proxies.
Google authentication for securing targets is now supported when using configurable API proxies.
With this feature, configurable API proxy developers can secure their Google backend services using Google OAuth and automatically grant access to authorized API consumers. This offers the advantage of seamless integration with other Google services, without requiring API producers to manage private keys.
For more information, see Securing targets for configurable proxies.
Southbound mTLS can be enabled for use with configurable API proxies .
By adding south bound mTLS functionality to configurable proxies, Apigee customers can seamlessly maintain their current usage of mTLS when transitioning to the use of configurable proxies, or increase security for communications between existing configurable proxies and their backends.
For more information, see Enable south bound mTLS for configurable proxies.
Configurable API proxies now support the use of template variables.
Apigee property sets can be used to specify template variables for configurable API proxies in archive deployments. This feature enables customers to use string templates in their proxy configuration YAML files.
For more information, see Template variables for configurable proxies.
You can now use a combination of zonal NEGs (of type GCE_VM_IP_PORT) and hybrid NEGs (of type NON_GCP_PRIVATE_IP_PORT) as backends for your global external HTTP(S) load balancers. For all supported backend combinations, see the table at Backend services.
You can now view aggregated Cloud Spanner statistics related to transactions, reads, queries, and lock contentions in Cloud Monitoring. Additionally, the retention period for these metrics at one-minute intervals has been increased from six hours to six weeks.
You can now use deny policies to prevent principals from using certain permissions, regardless of the roles they're granted. This feature is in Preview.
Add a feature that supports adding node selectors for Kf Builds to isolate Kf Build pods in specific node pool.
Remove Config Connector as a dependency of Kf.
Storage Transfer Service now supports Cloud Client Libraries, which are the recommended option for accessing Cloud APIs programmatically. This launch significantly reduces the amount of code you need to write; see Getting started and Migrating to the Cloud Client Library for more details.
Beta stage support for the following integration:
Support for VPC Service Controls is now in Beta stage.
March 02, 2022
Anthos Service Mesh1.12.4-asm.2 is now available.
Anthos Service Mesh includes the features of Istio 1.12 subject to the list of Anthos Service Mesh supported features.
Anthos Service Mesh now supports certificate templates with the Certificate Authority Service integration. See Install default features and CA Service for more information.
The operating system of the machine that Cloud Build uses to run builds has been upgraded to Debian 11. This results in faster build start up time when you run builds on:
e2-highcpu-8ore2-highcpu-32in the default pool.- Any of the available machine types in a private pool.
You can now configure automatic exports of Security Command Center findings to a BigQuery dataset. For more information, see Export findings to BigQuery for analysis.
The vulnerability.cve.upstreamFixAvailable attribute was added to the Finding object. This is a boolean field that specifies whether a Common Vulnerabilities and Exposures (CVE) fix is available. For more information, see the API documentation for the Finding object.
March 01, 2022
Apigee hybridhybrid v1.5.8
On March 1, 2022 we released an updated version of the Apigee hybrid v1.5.8 software.
For information on upgrading, see Upgrading Apigee hybrid to version 1.5.
| Bug ID | Description |
|---|---|
| 219523719 | Fix to address the CPU and memory consumption when debug-session is enabled with response-status as the filtering criteria. |
| 217386412 | Change the property set logging level to fine when property is not found. |
| 215773113 | Setting the securityPolicy appeared to have no effect for specific configurations. |
| 209484701 | Invalid client IP sent to analytics. |
| 189233354 | Distributed tracing with Jaeger would error out. |
| Bug ID | Description |
|---|---|
| N/A | Multiple security fixes including CVE-2019-5021. |
Support for Python repository hostnames ending in pypi.pkg.dev is no longer available. If you use commands that reference hosts with LOCATION-pypi.pkg.dev you must replace these references with LOCATION-python.pkg.dev.
The pypi.pkg.dev hostname was available when Python repositories were available in alpha, and alpha users were notified about the change.
Cloud Composer 2 supports Customer Managed Encryption Keys (CMEK).
Java Client for Cloud Composer version 1.1.3 is released. You can use this library to interact with Cloud Composer API from Java.
A new multi-region instance configuration is now available in North America - nam13 (Iowa/Oklahoma/Salt Lake City).
Released Query Optimizer version 4. Version 3 remains the default optimizer version in production.
gRPC endpoint protocol is available in Preview.
Google Cloud Deploy is now available in the following region: asia-northeast3 (Seoul)
February 28, 2022
Agent AssistAgent Assist is now GA. GA status applies to the following features:
Release 1.9.5
Anthos clusters on bare metal 1.9.5 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.9.5 runs on Kubernetes 1.21.
Fixes:
- The following container image security vulnerabilities have been fixed:
Known issues:
When you upgrade Anthos clusters on bare metal from a version with a security patch to the next minor release, we recommend that you upgrade to the highest patch version to ensure that you have the latest security fixes. Always review the release notes before upgrading so that you're aware of what has changed, including security fixes and known issues. Upgrading to a lower release version isn't supported.
For information about the latest known issues, see Anthos on bare metal known issues in the Troubleshooting section.
hybrid v1.6.5
On February 28, 2022 we released an updated version of the Apigee hybrid v1.6.5 software.
For information on upgrading, see Upgrading Apigee hybrid to version 1.6.
| Bug ID | Description |
|---|---|
| 217386412 | Change the property set logging level to fine when property is not found. |
| 215773113 | Setting the securityPolicy appeared to have no effect for specific configurations. |
| 211787541 | Errors displayed in synchronizer logs for stale contracts. |
| 209484701 | Invalid client IP sent to analytics. |
| 204905727 | GenerateResponse was hanging on response flow when enabled=true. |
| 191853747 | Apigee Workload Identities not working for specific configurations. |
| 173566787 | Reuse existing target IPs if DNS resolution fail on DNS cache refresh. |
| 111777025 | LookupCache: cachehit was shown false in trace when the actual value was true. |
| Bug ID | Description |
|---|---|
| 204994504 | Container Vulnerability fixed: CVE-2018-12934. |
| N/A | Multiple security fixes including CVE-2019-5021. |
The following resource types are now publicly available through the Export APIs (ExportAssets and BatchGetAssetsHistory) and the Feed API:
- Firestore
firestore.googleapis.com/Database
(New environments only) Temporary Pub/Sub topics created during environment operations are now labeled.
(Airflow 2) The google-cloud-datastore package was added to the list of preinstalled packages.
(Airflow 2) Fix the problem with task logs not being exported to Cloud Logging.
(Airflow 1) The apache-airflow-backport-providers-google package is updated to version 2022.2.11.
(Cloud Composer 2) Fixed the problem with an environment having 0 workers after an unsuccessful upgrade operation is rolled back.
(Available without upgrading) Improved the handling of errors in DAG UI for tasks without a set operator.
Cloud Composer 1.18.1 and 2.0.5 images are available:
- composer-2.0.5-airflow-2.2.3
- composer-2.0.5-airflow-2.1.4
- composer-1.18.1-airflow-2.2.3
- composer-1.18.1-airflow-2.1.4
- composer-1.18.1-airflow-1.10.15 (default)
Cloud Composer 1.14.4 has reached its end of full support period.
Cloud HSM resources are now available in the following regions:
asia1eur3eur4nam3nam4nam6nam9
For information about which locations are supported by Cloud KMS, Cloud HSM, and Cloud EKM, see Cloud KMS locations.
GA: Google Cloud Managed Service for Prometheus, Google Cloud's fully managed, Prometheus-compatible monitoring solution, is now generally available. You can use the managed service anywhere that you use standard Prometheus today. The collector retains all expected Prometheus functionality, such as local storage and rule evaluation.
Managed Service for Prometheus also offers managed data collection in Kubernetes environments, reducing the complexity of deploying, scaling, sharding, configuring, and maintaining the collectors. For more information, see Google Cloud Managed Service for Prometheus.
Cloud SQL for MySQL 8.0.26 is now the default minor version. To upgrade your existing instance to the new version, see Set the MySQL minor version.
Fixed the issue causing metadata batch sync from Dataproc Metastore to Data Catalog to not work.
M90 Release
- CUDA has been upgraded from 11.3.0 to 11.3.1 to address some NCCL issues.
- VSlim GPU TensorFlow containers are available and have a significantly smaller size.
- TensorFlow 2.7 containers are re-released.
M90 Release
- Vertex AI sample notebooks are now included in the
/usr/share/tutorialsfolder. - Instances now allow the Jupyter options for disabling terminals and deleting files instead of sending them to the trash or recycling bin.
In M90 release instances, gRPC 1.44.0 can generate spurious error logs, though this doesn't affect the VM's ability to boot up. A fix is planned for the next release.
Eventarc triggers for Workflows is now available in Preview.
Deploying your application to Anthos user clusters is now supported in preview.
Specify which Terraform version is used to deploy your Terraform configurations in new or existing solutions.
Eventarc triggers for Workflows is now available in Preview.
February 25, 2022
Anthos clusters on bare metalRelease 1.10.2
Anthos clusters on bare metal 1.10.2 is now available for download. To upgrade, see Upgrade Anthos on bare metal. Anthos clusters on bare metal 1.10.2 runs on Kubernetes 1.21.
Functionality changes:
A preflight check now verifies whether your node machine has enough disk space before starting an install.
Updated the
bmctl check cluster --snapshotcommand so that snapshots now capture information about pods in cluster namespaces.Updated the
bmctl check cluster --snapshotcommand so that snapshots now capture information about cluster API machines andkubeadminSecrets.
Fixes:
Fixed issue in which the edge profile's request to reserve resources is lost during the upgrade process.
Fixed
bmctl upgradecommand so that the log fileupgrade-cluster.logis generated in thebmctl-workspace/cluster/logsdirectory.Fixed issue in which the non-root login didn't have the proper permissions to perform
bmctl backuporbmctl restore.Fixed a Node Problem Detector service that sometimes failed to run on nodes after a cluster installation or upgrade.
The following container image security vulnerabilities have been fixed:
Known issues:
For information about the latest known issues, see Anthos on bare metal known issues in the Troubleshooting section.
Security bulletin (1.8, 1.9, and 1.10)
Envoy recently released multiple security vulnerability fixes. The vulnerabilities affect Anthos clusters on bare metal, because Envoy is used for Metrics Server.
For instructions and more details, see the GCP-2022-008 security bulletin.
Cloud Data Fusion version 6.6.0 is in Preview. This release is in parallel with the CDAP 6.6.0 release .
Features in 6.6.0:
- Cluster reuse is generally available (GA).
- Predefined autoscaling is available in Preview.
- Cloud Data Fusion flow control prevents you from submitting too many requests, which can cause stuck or failed pipeline runs. It applies to API and scheduled pipeline launch requests for batch and real-time pipelines and replication jobs. It is available in Preview.
Changes in 6.6.0:
- To enable cluster reuse, the runtime property
system.profile.properties.clusterReuseEnabledis no longer required. - The new default value of the Dataproc profile Max Idle Time property is 30 minutes. Previously, it had no default value.
- The new limit for previewing data in the Pipeline Studio is 5000 records.
- Pagination is supported for Lifecycle Microservices List applications.
To prevent out of memory errors due to large lineages, a limit has been set for published lineage messages. For more information, see the CDAP
metadata.messaging.publish.size.limitdocumentation.Fetch Size is supported in the following plugins with the new default of 1000 rows:
Fixed in 6.6.0:
- Improved instance stability. Fixed a number of system service unavailability cases resulting in the message "Necessary services are experiencing intermittent problems" and API call failures.
- Fixed an issue that caused pipelines to fail when a Database Batch Source included a decimal column with precision greater than 19.
- Fixed an issue that caused pipelines with a Conditional plugin that were running on MapReduce to fail.
- Fixed an issue that caused pipelines with a Conditional plugin and running on Spark to fail.
- Fixed an issue that caused validation to fail for Cloud Storage Multi File Sinks.
Cloud Run now supports using less than one CPU. Refer to CPU limits for details. (Available in public preview.)
The Envoy project recently discovered a set of vulnerabilities. All issues listed below are fixed in Envoy release 1.21.1.
For more information, see the GCP-2022-008 security bulletin.
February 24, 2022
Anthos Config ManagementThe constraint template library includes new templates: K8sPSPAutomountServiceAccountTokenPod, RestrictNetworkExclusions, and K8sDisallowAnonymous.
The template library's K8sContainerRatios template supports a new field: cpuRatio.
The template library's K8sRestrictRoleBindings template now supports regular expression matching of role/clusterRole names by using the regexMatch field.
The template library's K8sProhibitRoleWildcardAccess template now allows roles and clusterRoles specified in the constraint to be exempted from the policy.
A set of template library's templates now include the exemptImages parameter, which exempts specific containers from the policy. Those templates are:
- K8sPSPAllowPrivilegeEscalationContainer
- K8sPSPAppArmor
- K8sPSPCapabilities
- K8sContainerLimits
- K8sContainerRatios
- K8sPSPHostNetworkingPorts
- K8sImageDigests
- K8sPSPPrivilegedContainer
- K8sPSPProcMount
- K8sPSPReadOnlyRootFilesystem
- K8sPSPSeccomp
- K8sPSPSELinuxV2
- K8sPSPAllowedUsers
- K8sContainerLimits
Fixed an issue in the hydration-controller container causing the reconciler Pod crash looping when there is a malformed or missing kustomization.yaml in the base directory.
Fixed a memory leak in the Config Sync reconciler container that led to high memory utilization or Pod restarts due to out-of-memory errors.
Anthos Clusters on AWS aws-1.10.2-gke.0 (previous generation) is now available. Clusters in this release support the following Kubernetes versions:
- 1.21.9-gke.1900
- 1.20.15-gke.1900
- 1.19.16-gke.7700
This release includes fixes for the following CVEs:
The Envoy project recently discovered a set of vulnerabilities. All issues listed in the security bulletin are fixed in Envoy release 1.21.1. For more information, see the GCP-2022-008 security bulletin.
On February 24, 2022 we released an updated version of the Apigee Integrated Portal software.
| Bug ID | Description |
|---|---|
| 216299743 | Inconsistent button icon for delete in Pages. Updated the page delete button from (circle with x) to (trash can). |
| 210539825 | CSS compiler should gracefully handle errors with unexpected form. Fixed a rare issue where some custom CSS payloads would result in an Internal Server Error. |
| 205579028 | 500s caused by could not get auth token for GCP. Periodically, under high load, GCP Authentication would fail on the backend and return a 500 internal exception. |
| 194226935 | Update site pages to link to Quickstart documentation. The Quick Start tutorial is no longer embedded in the portal. See Build your first portal in the Apigee documentation. |
The following resource types are now publicly available through the Export APIs (ExportAssets and BatchGetAssetsHistory), the Feed API, and the Search APIs (SearchAllResources and SearchAllIamPolicies):
- Cloud Healthcare API
healthcare.googleapis.com/ConsentStorehealthcare.googleapis.com/Datasethealthcare.googleapis.com/DicomStorehealthcare.googleapis.com/FhirStorehealthcare.googleapis.com/Hl7V2Store
Due to a change in a recent maintenance update, the changes listed in the February 4 Release Notes entry have been applied to some instances but postponed for the others. In the Google Cloud Console, you can determine if the maintenance update was applied. Specifically, on the Instance Overview page, review the instance's operations and logs for an occurrence of a maintenance operation since January 27.
The restrict authentication types organizational constraint is now in Preview. * The constraint allows you to restrict the authentication types that can be used in requests for Cloud Storage resources.
December 2021, Config Controller became Generally Available (GA). Config Controller is a managed service to provision and orchestrate Anthos and Google Cloud resources. For information on Config Controller, see Config Controller overview.
Config Controller now uses the following versions of its included products:
- Anthos Config Management v1.10.2, release notes
- Config Connector v1.74.0, release notes
(2022-R3) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- Version 1.21.6-gke.1503 is now the default version.
- Control plane and node version 1.19.16-gke.6800
- Control plane and node version 1.20.15-gke.1000
- Control plane and node version 1.21.5-gke.1805
- Control plane and node version 1.21.6-gke.1503
- Control plane and node version 1.21.9-gke.1001
- Control plane and node version 1.22.3-gke.1500
- Control plane and node version 1.22.4-gke.1501
- Control plane and node version 1.22.6-gke.1000
- Node version 1.18.20-gke.6101 is now available.
- Node version 1.21.6-gke.1501 is now available.
- Node version 1.21.9-gke.1000 is now available.
- The following control plane versions are no longer available:
- 1.19.15-gke.1801
- 1.21.6-gke.1500
- Node version 1.21.6-gke.1500 is no longer available.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to 1.21.6-gke.1503 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to 1.22.6-gke.300 with this release.
Stable channel
- Version 1.19.16-gke.3600 is now available in the Stable channel.
- Version 1.21.5-gke.1805 is now available in the Stable channel.
- The following versions are no longer available in the Stable channel:
- 1.19.15-gke.1801
- 1.21.5-gke.1802
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to 1.21.5-gke.1805 with this release.
Regular channel
- Version 1.21.6-gke.1503 is now the default version in the Regular channel.
- Version 1.21.5-gke.1805 is now available in the Regular channel.
- Version 1.21.6-gke.1503 is now available in the Regular channel.
- Version 1.22.4-gke.1501 is now available in the Regular channel.
- The following versions are no longer available in the Regular channel:
- 1.20.11-gke.1801
- 1.21.5-gke.1802
- 1.21.6-gke.1500
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.6-gke.1503 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.21.6-gke.1503 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to 1.22.4-gke.1501 with this release.
Rapid channel
- Version 1.22.6-gke.300 is now the default version in the Rapid channel.
- Version 1.21.9-gke.1001 is now available in the Rapid channel.
- Version 1.22.6-gke.1000 is now available in the Rapid channel.
- Version 1.22.6-gke.1500 is now available in the Rapid channel.
- Version 1.23.3-gke.1100 is now available in the Rapid channel.
- The following versions are no longer available in the Rapid channel:
- 1.21.6-gke.1500
- 1.22.3-gke.700
- 1.22.3-gke.1500
- 1.23.2-gke.300
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.9-gke.1001 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.9-gke.1001 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.23.3-gke.1100 with this release.
GKE nodes that use Container-Optimized OS with Docker (cos) may experience random TCP connection resets when two pods on the same node communicate using a Kubernetes ClusterIP Service.
For more information, see GKE Node images known issues.
(2022-R03) Version updates
- Version 1.21.6-gke.1503 is now the default version.
- Control plane and node version 1.19.16-gke.6800
- Control plane and node version 1.20.15-gke.1000
- Control plane and node version 1.21.5-gke.1805
- Control plane and node version 1.21.6-gke.1503
- Control plane and node version 1.21.9-gke.1001
- Control plane and node version 1.22.3-gke.1500
- Control plane and node version 1.22.4-gke.1501
- Control plane and node version 1.22.6-gke.1000
- Node version 1.18.20-gke.6101 is now available.
- Node version 1.21.6-gke.1501 is now available.
- Node version 1.21.9-gke.1000 is now available.
- The following control plane versions are no longer available:
- 1.19.15-gke.1801
- 1.21.6-gke.1500
- Node version 1.21.6-gke.1500 is no longer available.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to 1.21.6-gke.1503 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to 1.22.6-gke.300 with this release.
(2022-R03) Version updates
- Version 1.19.16-gke.3600 is now available in the Stable channel.
- Version 1.21.5-gke.1805 is now available in the Stable channel.
- The following versions are no longer available in the Stable channel:
- 1.19.15-gke.1801
- 1.21.5-gke.1802
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to 1.21.5-gke.1805 with this release.
(2022-R03) Version updates
- Version 1.21.6-gke.1503 is now the default version in the Regular channel.
- Version 1.21.5-gke.1805 is now available in the Regular channel.
- Version 1.21.6-gke.1503 is now available in the Regular channel.
- Version 1.22.4-gke.1501 is now available in the Regular channel.
- The following versions are no longer available in the Regular channel:
- 1.20.11-gke.1801
- 1.21.5-gke.1802
- 1.21.6-gke.1500
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.6-gke.1503 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.21.6-gke.1503 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to 1.22.4-gke.1501 with this release.
(2022-R03) Version updates
- Version 1.22.6-gke.300 is now the default version in the Rapid channel.
- Version 1.21.9-gke.1001 is now available in the Rapid channel.
- Version 1.22.6-gke.1000 is now available in the Rapid channel.
- Version 1.22.6-gke.1500 is now available in the Rapid channel.
- Version 1.23.3-gke.1100 is now available in the Rapid channel.
- The following versions are no longer available in the Rapid channel:
- 1.21.6-gke.1500
- 1.22.3-gke.700
- 1.22.3-gke.1500
- 1.23.2-gke.300
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.9-gke.1001 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.9-gke.1001 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.23.3-gke.1100 with this release.
Security Command Center can automatically send findings, assets, and security sources to the following SIEM and SOAR platforms:
Read Security Bulletin GCP-2022-008 about Envoy security vulnerabilities and update Envoy proxies in your Traffic Director installation to Envoy release 1.21.1.
February 23, 2022
Anthos clusters on VMwareAnthos clusters on VMware 1.9.4-gke.3 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.9.4-gke.3 runs on Kubernetes v1.21.5-gke.1200.
The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.10, 1.9, and 1.8.
Fixes
Upgraded Cilium to version 1.10.5.
- This upgrade also fixed the issue where unreachable node endpoints caused application 503 errors. Previously, when
cilium-health statuswas run in anetd daemons, the output showed stale remote nodes.
- This upgrade also fixed the issue where unreachable node endpoints caused application 503 errors. Previously, when
Fixed unexpectedly high network traffic to monitoring.googleapis.com in a newly created cluster.
Fixed these high-severity CVEs:
When cluster autoscaling is enabled in a Dataplane-v2 cluster, scale down may sometimes take longer. For example, it may take approximately 20 minutes instead of 10 minutes as in a normal case.
The following resource types are now publicly available through the resource search API (SearchAllResources) and policy search API (SearchAllIamPolicies):
- Vertex AI
aiplatform.googleapis.com/PipelineJob
Support for Knative Serving 1.1.2 is now available in version 1.23.0-gke.17 of Cloud Run for Anthos on Google Cloud.
The following GKE minor versions are supported:
- 1.19 with Anthos Service Mesh 1.10
- 1.20 with Anthos Service Mesh 1.10
- 1.21 with Anthos Service Mesh 1.11 or 1.12
If your primary instance uses a private IP address, you can now select an allocated IP range for clones and replicas created from the instance.
If your primary instance uses a private IP address, you can now select an allocated IP range for clones and replicas created from the instance.
If your primary instance uses a private IP address, you can now select an allocated IP range for clones and replicas created from the instance.
NVIDIA 510 driver not yet supported for GPUs running on Compute Engine, see Known issues.
Public preview: Public tags that provide less strict access control as compared to private tags for searching and viewing tags is rolled out to all Data Catalog regions with minimal disruption and in a controlled way. Public tags support simple search and search with predicates while private tags support only search with predicates.
Networking Connectivity Center now supports the use of a third-party network virtual appliance in any Google Cloud region for the following use cases:
- Providing site-to-cloud connectivity
- Providing connectivity or managing traffic between VPC networks
A third-party network virtual appliance could be an SD-WAN router, a firewall appliance, a load balancer, or another appliance, as long as it uses BGP. After you create a Network Connectivity Center spoke to represent your router appliance instance, it can exchange routes dynamically with Cloud Router.
To view a list of partners whose solutions are integrated with Network Connectivity Center, see Network Connectivity Center partners.
For more information about Network Connectivity Center, see the product overview.
February 22, 2022
Anthos Service MeshThe Istio project recently disclosed a series of CVEs that can expose Anthos Service Mesh to remotely exploitable vulnerabilities. For more information, see the security bulletin.
1.12.4-asm.1 is now available.
This patch release contains the fixes for the security vulnerabilities listed in GCP-2022-007. For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
1.11.7-asm.1 is now available.
This patch release contains the fixes for the security vulnerabilities listed in GCP-2022-007. For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
1.10.6-asm.1 is now available.
This patch release contains the fixes for the security vulnerabilities listed in GCP-2022-007. For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
Kubernetes version 1.21.6-gke.1500 is now available. For more information, see the Kubernetes OSS release notes.
You can now launch clusters in the ap-northeast1 and sa-east-1 AWS regions.
Fixed CVE-2021-4154, see GCP-2022-002 for more details.
Fixed CVE-2022-0185, see GCP-2022-002 for more details.
Kubernetes version 1.21.6-gke.1500 is now available. For more information, see the Kubernetes OSS release notes.
You can now launch clusters in the brazilsouth Azure region.
Fixed CVE-2021-4154, see GCP-2022-002 for more details.
Fixed CVE-2022-0185, see GCP-2022-002 for more details.
Fixed CVE-2021-4034, see GCP-2022-004 for more details.
Fixed CVE-2021-43527, see GCP-2022-005 for more details.
On February 22, 2022 we released an updated version of the Apigee UI software.
The following accessibility improvements have been made in the Apigee UI:
- In the Develop > API Proxies view, the screen reader now reads "Create new proxy" for the Create New button
- In the Traffic column of the API Proxies view, the screen reader now reads the traffic tooltip text, and the tooltip has been removed.
- In the Last Modified column, the screen reader now reads a message like "5 months ago on Sep 17, 2021 6:21 PM," and the tooltip has been removed.
- Hovering the mouse in the Action column now displays a menu showing the Delete item, to make it accessible.
The help text in the project selector menu at the top of the UI was out of date. The information has now been updated.
Proxy/sharedflow undeployment was failing in the new Proxy Editor. This has been fixed.
Zonal Cloud DNS zones are now available in Preview.
You can create private DNS zones that are scoped only to a Google Cloud zone.
You can now stream and export FHIR resources to BigQuery using the FHIR analytics schema with support for repeated extension columns and contained resources as JSON strings.
You can now collect Apache CouchDB logs from the Ops Agent, starting with version 2.11.0. For more information, see Monitoring third-party applications: CouchDB.
You can now collect Apache Hadoop logs and metrics from the Ops Agent, starting with version 2.11.0. For more information, see Monitoring third-party applications: Hadoop.
You can now collect Apache HBase logs and metrics from the Ops Agent, starting with version 2.11.0. For more information, see Monitoring third-party applications: HBase.
You can now collect Apache ZooKeeper logs from the Ops Agent, starting with version 2.11.0. For more information, see Monitoring third-party applications: ZooKeeper.
You can now collect WildFly logs from the Ops Agent, starting with version 2.11.0. For more information, see Monitoring third-party applications: WildFly.
Metrics Explorer and charts on dashboards have a new metric selection interface. For more information, see Select metrics when using Metrics Explorer.
You can now collect Apache ActiveMQ metrics from the Ops Agent, starting with version 2.11.0. For more information, see Monitoring third-party applications: ActiveMQ.
You can now collect Apache Hadoop metrics and logs from the Ops Agent, starting with version 2.11.0. For more information, see Monitoring third-party applications: Hadoop.
You can now collect Apache HBase metrics and logs from the Ops Agent, starting with version 2.11.0. For more information, see Monitoring third-party applications: HBase.
You can now collect MongoDB metrics from the Ops Agent, starting with version 2.11.0. For more information, see Monitoring third-party applications: MongoDB.
You can now collect RabbitMQ metrics from the Ops Agent, starting with version 2.11.0. For more information, see Monitoring third-party applications: RabbitMQ.
Support for applying a path pattern when filtering is now available in Preview.
GKE Gateway traffic management is now in Preview for GKE 1.22 and later version clusters. You can now autoscale Pods or dynamically shift traffic between clusters based on Service traffic capacity.
The Istio project recently disclosed a series of CVEs that can expose Istio on GKE to remotely exploitable vulnerabilities. For more information, see the security bulletin.
1.6.14-gke.9 is now available. This patch release contains the fixes for the security vulnerabilities listed in GCP-2022-007. For more information, see Upgrading operator based 1.6 Istio to the latest patch release.
1.4.11-gke.4 and 1.4.10-gke.23 are now available. These patch releases contain the fixes for the security vulnerabilities listed in GCP-2022-007. For more information see Upgrading 1.4 Istio to the latest patch release.
MITRE ATT&CK framework details related to findings are now available as finding attributes for all Security Command Center services. The framework explains tactics and techniques for attacks against cloud resources, and provides remediation guidance. Although these attributes are available across all built-in and integrated services, only Container Threat Detection and Event Threat Detection are populating them at this time. For more information, see the API documentation for the Findings object.
February 21, 2022
Apigee IntegrationOn February 21, 2022 we released an updated version of the Apigee Integration software.
| Bug ID | Description |
|---|---|
| N/A | Cloud Pub/Sub trigger having same topic in multiple region fails. You can now create a Cloud Pub/Sub trigger for the same topic in multiple regions. Because of this fix, your already existing Cloud Pub/Sub trigger may now execute multiple times. Contact Apigee support if you notice this problem. However, if you haven't used the Cloud Pub/Sub trigger in your integrations, you can ignore this fix. |
Cloud Domains now supports the following new TLDs:
- .day
- .contact
- .de
- .nl
- .autos
The annual price for the following two TLDs has changed to $15:
- .boats
- .homes
For details, see Cloud Domains Pricing.
Network Load Balancing introduces a new monitoring resource type loadbalancing.googleapis.com/ExternalNetworkLoadBalancerRule that lets you monitor all the supported protocols including TCP, UDP, ESP, and ICMP.
For details, see Monitoring Network Load Balancing.
This feature is available in General Availability.
February 19, 2022
Dataproc MetastoreFixed the issue causing Dataproc Metastore service creation to fail with the error NO_MATCHING_ACCESS_LEVEL due to a known issue where dns.googleapis.com is in the service perimeter but not in the allowlist.
February 18, 2022
Cloud BuildThe organization policy for integrations with services such as GitHub is now generally available. Users can now apply the policy to control triggered builds from external services, such as GitHub. To learn more, see Limiting builds triggered from external services.
VPC Service Controls support for Cloud Build is now generally available. For instructions on using this feature, see Using VPC Service Controls.
Config Connector version 1.74.0 is now available.
Added support for PrivateCACertificateAuthority resource
Fixed topicRef in CloudBuildTrigger (Issue #605).
Added support for Enhanced Flexibility Mode (EFM) with primary worker shuffle mode on Spark for image version 2.0.
General Availability (GA) release of new Rocky Linux based images: 1.5.57-rocky8 and 2.0.31-rocky8. These images are replacing CentOS images which are EOL.
Dataproc Serverless for Spark now uses runtime version 1.0.4, which updates GCS connector to 2.2.5 version.
New sub-minor versions of Dataproc images:
1.5.57-debian10, 1.5.57-ubuntu18, and 1.5.57-rocky8
2.0.31-debian10, 2.0.31-ubuntu18, and 2.0.31-rocky8
Upgraded Cloud Storage connector version to 2.2.5 in image version 2.0.
Upgraded Cloud Storage connector version to 2.1.7 in image version 1.5.
CentOS images are EOL. 1.5.56-centos8 and 2.0.30-centos8 are the final CentOS based images. CentOS images are no longer supported and will not receive new releases.
New Versions of Procurement Processors
We have launched a new Google Pretrained version of the following procurement processors with various quality improvements:
The changes from the old Google default next version have been applied to the new Google Pretrained version. The old Google default version is still available and will not be deprecated for at least 180 days.
Checking for the existence of a key in a list is supported.
February 17, 2022
Anthos clusters on VMwareAnthos clusters on VMware 1.8.7-gke.0 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.8.7-gke.0 runs on Kubernetes v1.20.12-gke.1500.
The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.10, 1.9, and 1.8.
Fixes:
Fixed high-severity CVEs:
Updated the Java SDK to version 1.9.95.
The following resource types are now publicly available through the resource search API (SearchAllResources) and policy search API (SearchAllIamPolicies):
- Vertex AI
aiplatform.googleapis.com/MetadataStoreaiplatform.googleapis.com/ModelDeploymentMonitoringJob
DAG UI is available in Preview.
(Cloud Composer 2) Tasks that take less than 25 minutes to execute are not impacted by maintenance operations. Cloud Composer waits until such tasks are finished before the maintenance operation starts.
You can now configure how missing data is treated in alerting policies. Currently, if data stops arriving, the alerting policy repeats the previous measurement, so open incidents stay open. You can now treat missing data as violating the condition so an active condition stays active, or treat it as non-violating so that an active condition closes. For more information, see Partial metric data.
The install-monitoring-agent.sh installation script for the Cloud Monitoring agent for Linux has been decommissioned. See the Installing the Cloud Monitoring agent guide for the latest installation procedures.
Dynamic port allocation for Cloud NAT is available in General Availability.
Cloud SQL now supports the use of tags on instances. Tags are key-value pairs you can apply to your resources, such as a project or a Cloud SQL instance, which are used for fine-grained access control. To learn more, see Access control with Google Cloud tags. To use tags now, see Attach and manage tags on Cloud SQL instances.
Cloud SQL now supports the use of tags on instances. Tags are key-value pairs you can apply to your resources, such as a project or a Cloud SQL instance, which are used for fine-grained access control. To learn more, see Access control with Google Cloud tags. To use tags now, see Attach and manage tags on Cloud SQL instances.
Cloud SQL now supports the use of tags on instances. Tags are key-value pairs you can apply to your resources, such as a project or a Cloud SQL instance, which are used for fine-grained access control. To learn more, see Access control with Google Cloud tags. To use tags now, see Attach and manage tags on Cloud SQL instances.
Dataplex Explore is available in Preview. Explore provides a fully-managed, serverless data exploration experience that enables you to query your data using Apache SparkSQL queries and Jupyter notebooks.
A script that checks if a project or organization is using an unsupported Dataproc image is available for downloading (see Unsupported Dataproc versions).
Kubernetes Network Policy API allows specifying range of ports (see KEP on port ranges) on which the policy is enforced in GKE 1.22 and later versions. If you specify endPort field in a Network Policy, it might not take effect in Dataplane V2 based on the cluster configuration. This API will be supported in Calico Network Policy enabled clusters but not in Dataplane V2 clusters.
For more information, see GKE Dataplane V2 known issues.
February 16, 2022
BigQueryRemote functions are now available for preview. Remote functions allow you to implement your function in other languages than SQL and Javascript, or with libraries or services which are not allowed in BigQuery user-defined functions.
Dynamic compression allows Cloud CDN to automatically compress responses as they are being served between the origin and the client. The size of the data sent over the network is reduced by 60% to 85% in typical cases. This feature is supported in Preview.
Cloud Functions has added support for low-configuration access to private dependencies on Artifact Registry in in Node.js and Python.
Cloud Shell Editor is now built with Theia 1.21.0
For a complete list of features, updates, and bug fixes, see the Theia release notes.
.NET 6.0 Support added.
Cloud Shell and the Cloud Shell Editor now support .NET 6.0 development.
Debian 11
Cloud Shell is now built on top of Debian 11. For a full list of updates, see the Debian 11 release notes.
Upcoming switch to Python 3
Cloud Shell will soon default to Python 3. Python 2 will still be included as a development tool in Cloud Shell and may be invoked by issuing the python2 command.
New documentation for licenses and appending licenses.
T2D machines are now available in the following regions and zones:
- St. Ghislain, Belgium:
europe-west1 - The Dalles, Oregon:
us-west1
See VM instance pricing for details.
Profiling Dataflow pipelines with Cloud Profiler is generally available (GA). Use Dataflow integration with Cloud Profiler to monitor pipeline performance.
General availability for the following integration:
You can now use a pre-built container to perform custom training with TensorFlow 2.8.
February 15, 2022
AI Platform TrainingRuntime version 2.8 is available. You can use runtime version 2.8 to train with TensorFlow 2.8, scikit-learn 1.0.2, or XGBoost 1.5.2. Runtime version 2.8 supports training with CPUs, GPUs, or TPUs.
See the full list of updated dependencies in runtime version 2.8.
On February 15, 2022 we released an updated version of the Apigee UI software.
New Overview Tab in Proxy Editor
We have released a new version of the Overview tab in the Proxy Editor. See Introducing the new Proxy Editor.
Note: The new features in this release will be rolled out over the next week, so you might not be able to view them until the rollout is complete.
The UI now shows a warning when an API Product is in legacy format, stating that some of the displayed fields might be legacy fields.
| Bug ID | Description |
|---|---|
| 201759530 | Operations that did not have methods defined were not appearing in the operations table in the API Products UI |
| 199814779 | The test button in Admin > Environments > Keystores was not working correctly. The button has been temporarily removed from the UI. |
On February 15, 2022 we released an updated version of the Apigee X software.
Backend target routing with Private Service Connect
You can now use Private Service Connect (PSC) to connect Apigee with backend target services running in VPC networks other than the one that is peered with your Apigee organization. For details, see Southbound networking patterns.
Node.js apps now support private dependencies hosted on an Artifact Registry Node.js package repository. To include private dependencies, list the Artifact Registry repository and configure settings for authenticating with the registry in your .npmrc file.
Python 3 apps now support private dependencies hosted on an Artifact Registry Python registry. To include private dependencies, add the Artifact Registry URL and the relevant packages in your requirements.txt file.
On-Demand Scanning for Go packages is now generally available.
You can scan your container images and identify Go package vulnerabilities.
The table clones feature in BigQuery is now in Preview. A table clone is a lightweight, writable copy of a table. You are only charged for storing the data in a table clone that differs from its base table.
The DeleteSubject method has been added to the Chronicle Role-Based Access Control (RBAC) API. DeleteSubject enables you to remove user and group role assignments.
Cloud Composer 1.18.0 and 2.0.4 release started on February 15, 2022. Get ready for upcoming changes and features as we roll out the new release to all regions. This release is in progress at the moment. Listed changes and features might not be available in some regions yet.
(Cloud Composer 1) Starting from this version, newly created environments use Python 3.8 as the default Python version. Python 3.6 is no longer available. If you upgrade an existing environment to 1.18.0 and later versions, the Python version changes from Python 3.6 to Python 3.8.
(Cloud Composer 2) Environment creation no longer fails if the default Compute Engine service account is deleted in a project.
Cloud Composer 1.18.0 and 2.0.4 images are available:
- composer-2.0.4-airflow-2.2.3
- composer-2.0.4-airflow-2.1.4
- composer-1.18.0-airflow-2.2.3
- composer-1.18.0-airflow-2.1.4
- composer-1.18.0-airflow-1.10.15 (default)
Airflow 2.0.2 is no longer included in Cloud Composer images.
Cloud Composer 1.14.3 has reached its end of full support period.
Internal TCP/UDP Load Balancing now supports source-IP address session affinity (CLIENT_IP_NO_DESTINATION) in Public Preview.
Config Controller now uses version 1.10.1 for Anthos Config Management (release notes)
Data Catalog now supports cataloguing and searching data entries from Dataplex lakes, zones, tables, and filesets. For more information, see the Dataplex documentation and Data Catalog documentation.
Dataplex is generally available (GA). Dataplex is an intelligent data fabric that helps organizations to centrally manage, monitor, and govern their data across data lakes, data warehouses, and data marts with consistent controls, providing access to trusted data and powering analytics at scale.
Dataproc images prior to 1.3.95, 1.4.77, 1.5.53, and 2.0.27 are deprecated and cluster creations based on these images will fail starting 2/28/2022.
Beginning on February 21 2022, the VMware Engine operations team will perform essential maintenance of the network infrastructure to improve equipment robustness and apply security patches. Users affected by this upgrade will receive an email with planned maintenance dates and times.
For details about the upgrade and steps to prepare, see Service announcements.
A security vulnerability, CVE-2022-0492,
has been discovered in the Linux kernel's cgroup_release_agent_write function.
The attack uses unprivileged user namespaces, and under certain circumstances, this
vulnerability can be exploitable for container breakout.
For more information, see the GCP-2022-006 security bulletin.
Service Directory integration with Traffic Director is available in Preview .
After you register a service with Service Directory, the integration makes services in the service registry available to the applications in your mesh and to gateways configured by Traffic Director. Your service mesh and self- managed gateways can then send traffic to these services
Traffic Director is now integrated with Service Directory. After you register a service with Service Directory, the integration makes services in the service registry available to the applications in your mesh and to gateways configured by Traffic Director. Your service mesh and self- managed gateways can then send traffic to these services.
February 14, 2022
Anthos clusters on AzureA security vulnerability, CVE-2022-0492,
has been discovered in the Linux kernel's cgroup_release_agent_write function.
The attack uses unprivileged user namespaces and under certain circumstances this
vulnerability can be exploitable for container breakout. For more information, see the
GCP-2022-006 security bulletin.
A security vulnerability, CVE-2022-0492, has been discovered in the Linux kernel's cgroup_release_agent_write function. The attack uses unprivileged user namespaces, and under certain circumstances, this vulnerability can be exploitable for container breakout. For more information, see the
GCP-2022-006 security bulletin.
The INFORMATION_SCHEMA.STREAMING_TIMELINE_* views are now generally available (GA).
The QUALIFY clause, which lets you filter the results of analytic functions in Google Standard SQL, is now generally available (GA).
BigQuery reliability guide is now available. This guide describes how to build solutions with BigQuery that meet your application's needs for availability, durability, consistency, and data recovery. Topics include the following:
- Import reliability - Managed storage, methods, load jobs, and the Storage Write API
- Query reliability - Slots, reservations, and job optimization.
- Read reliability - Read methods, consistency concerns including quotas and limits, and the Storage Read API.
- Disaster planning - Disaster considerations and their mitigation.
BigQuery ML time series ARIMA_PLUS now trains models 5 times faster than previous training.
This release adds filters to ListCustomers. You can use these filters to exclude selected customers from search results. For more information, visit our article about these new filters.
Support for configuring triggers to use a particular service account is now generally available. To learn more, see Configuring user-specified service accounts.
Cloud Functions has released Cloud Functions (2nd gen), available at the Preview release level. Cloud Functions (2nd gen) is Google Cloud's next-generation Functions-as-a-Service offering. This new version of Cloud Functions comes with an advanced feature set, giving you more powerful infrastructure, advanced control over performance and scalability, more control around the functions runtime, and triggers from over 90 event sources.
See the Cloud Functions (2nd gen) documentation for details.
Virtru is now available as a supported Cloud EKM partner. See Supported key managers to learn more.
You can now configure default storage regions and disabled _Default sinks for your Google Cloud organizations and all of their new projects and folders. For details, see Configure default resource settings for Logging.
You can now collect Apache Solr metrics and logs from the Ops Agent, starting with version 2.10.0. For more information, see Monitoring third-party applications: Solr.
You can now collect Apache Kafka metrics and logs from the Ops Agent, starting with version 2.10.0. For more information, see Monitoring third-party applications: Kafka.
You can now collect MongoDB logs from the Ops Agent, starting with version 2.10.0. For more information, see Collect logs from third-party applications: MongoDB.
You can now collect Apache Solr metrics and logs from the Ops Agent, starting with version 2.10.0. For more information, see Monitoring third-party applications: Solr.
You can now collect Apache Kafka metrics and logs from the Ops Agent, starting with version 2.10.0. For more information, see Monitoring third-party applications: Kafka.
You can now collect Apache CouchDB metrics from the Ops Agent, starting with version 2.10.0. For more information, see Monitoring third-party applications: CouchDB.
You can now collect Apache ZooKeeper metrics from the Ops Agent, starting with version 2.10.0. For more information, see Monitoring third-party applications: ZooKeeper.
You can now collect Elasticsearch metrics from the Ops Agent, starting with version 2.10.0. For more information, see Monitoring third-party applications: Elasticsearch.
Kubernetes 1.23 is now available in the Rapid channel. Before upgrading, read the Kubernetes 1.23 Release Notes, especially the action required and deprecation sections. Also, read the guide for ensuring compatibility of webhook and aggregated API server certificates before the upgrade.
Added support for enabling read replicas (preview) on existing instances. For more information, see Behavior of enabling read replicas on an existing instance. Also added the capability to perform version upgrade and manual failover operations on instances that use read replicas.
SAP NetWeaver certifications: T2D AMD-based general-purpose machine types
For SAP NetWeaver, SAP now certifies Compute Engine general-purpose T2D series machine types with the AMD EPYC Milan CPU platform.
For more information, see T2D general-purpose machine types.
February 11, 2022
Anthos clusters on AzureA security vulnerability, CVE-2021-43527, has been discovered in any binary that links to the vulnerable versions of libnss3 found in NSS (Network Security Services) versions prior to 3.73 or 3.68.1. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. For more information, see the GCP-2022-005 security bulletin.
A security vulnerability, CVE-2021-43527, has been discovered in any binary that links to the vulnerable versions of libnss3 found in NSS (Network Security Services) versions prior to 3.73 or 3.68.1. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS.
For more information, see the GCP-2022-005 security bulletin.
Cloud Scheduler jobs for HTTP or Pub/Sub Targets can be deployed in multiple GCP Regions around the world and no longer require that an App Engine application be deployed.
Cloud Spanner now optimizes the way it processes groups of similar statements in DML batches, significantly improving the speed at which it performs batched data writes under certain conditions.
Config Connector version 1.73.0 is now available.
Added support for ComputeFirewallPolicyAssociation resource.
Added support in IAMPartialPolicy and IAMPolicy to cover Organization and BillingAccount resources.
Fixed spec.target.targetHTTPProxyRef issue in ComputeForwardingRule (Issue #596).
CRD go clients (alpha) have moved to pkg/clients/generated/client/clientset/versioned/ package.
Config Controller is now supported in region us-east1.
Config Controller now uses the following versions of its included products:
- Anthos Config Management v1.9.1, release notes
- Config Connector v1.72.1, release notes
Performing import, export, backup, or restore on Spanner-backed services now returns a 4XX error since these operations aren't supported.
Added additional mutual exclusion validation for Data Catalog and Spanner-backed services.
Fixed the issue causing request_count metric spikes due to a bug in the logic of our metrics reporting pipeline.
Eventarc is now Payment Card Industry Data Security Standard (PCI DSS)-compliant.
A security vulnerability, CVE-2021-43527, has been discovered in any binary that links to the vulnerable versions of libnss3 found in NSS (Network Security Services) versions prior to 3.73 or 3.68.1.
Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS.
For more information, see the GCP-2022-005 security bulletin.
SAP NetWeaver certifications: C2D AMD-based compute-optimized machine types
For SAP NetWeaver, SAP now certifies Compute Engine compute-optimized C2D series machine types with the AMD EPYC Milan CPU platform.
For more information, see C2D compute-optimized machine types.
February 10, 2022
Anthos clusters on VMwareAnthos clusters on VMware 1.10.1-gke.19 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.10.1-gke.19 runs on Kubernetes v1.21.5-gke.1200.
The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.10, 1.9, and 1.8.
- Removed unintentional infrastructure log lines from the cluster snapshot.
Upgraded the Connect Agent version to 20211210-01-00.
- This upgrade also fixed the issue where the Connect Agent restarts unexpectedly on either a newly-created cluster or an existing cluster that uses Anthos Identity Service to manage the Anthos Identity Service ClientConfig.
Fixed two high severity CVEs:
Fixed the short metric probing interval issue that sends a high volume of traffic to the monitoring.googleapis.com endpoint in a cluster.
If your admin cluster failed to register with the provided
gkeConnectspec during creation, upgrading to a later 1.9 or 1.10 release will fail with the following error:failed to migrate to first admin trust chain: failed to parse current version "": invalid version: "" failed to migrate to first admin trust chain: failed to parse current version "": invalid version: ""If you have experienced this issue, follow these instructions to fix the gkeConnect registration issue before you upgrade your admin cluster.
BigQuery Omni now supports INFORMATION_SCHEMA.JOBS_* and INFORMATION_SCHEMA.RESERVATION* views. This feature is in Preview. For more information, see View resource metadata (AWS) and View resource metadata (Azure).
Your regional preferences, including date and time formatting, are now supported in the Logs Explorer.
Generally available: Compute-optimized C2D machine types are now generally available. C2D machine types are built on top of third generation AMD EPYC Milan processors and are a great fit for high-performance computing (HPC) workloads. For more information, see Compute-optimized machine family.
Versions 1.21.9-gke.300, 1.22.6-gke.300, and 1.23.2-gke.300 contain a fix for a race condition which could result in erroneously detaching all endpoints from network endpoint groups for a short period.
Access-related details are now available as finding attributes for all Security Command Center services. These attributes relate to an access event associated with a finding. They contain details such as the caller's IP address, which service and method was called, and what region the access event occurred in. Although access-related attributes are available across all built-in and integrated services, they're only populated by Event Threat Detection at this time. For more information, see the API documentation for the Findings object.
For Vertex AI featurestore resources, the online store is optional. You can set the number of online nodes to 0. For more information, see Manage featurestores.
February 09, 2022
Cloud LoggingCompute Engine resource names, alongside their corresponding resource IDs, are now supported in the Logs Explorer. For details, see View Compute Engine logs.
The configured container arguments are now correctly overriding arguments defined inside the container image. This change applies to new services only.
Public Preview: You can now use the security keys registered for 2-Step Verification in your Google account to connect to VMs that use OS Login. For more information, see Enable security keys with OS Login.
SAP NetWeaver certifications: N2D series Compute Engine VMs on the AMD EPYC Milan CPU platform
For SAP NetWeaver, SAP now certifies Compute Engine N2D series machine types with the AMD EPYC Milan CPU platform.
For more information, see N2D general-purpose machine types.
February 08, 2022
Apigee Integrated PortalOn February 8, 2022 we released an updated version of the Apigee Integrated Portal software.
| Bug ID | Description |
|---|---|
| 212421254 | Consumers can access teams in a portal for which they have no IDP account. Before, a consumer could access a team as long as they were added to the team and had an IDP account in the same organization as the team. Now they can only access the team if they are added as a member and have an IDP account in the same portal as the team. |
| 209436418 | Display asset file sizes in megabytes. Asset file size was being incorrectly displayed in mebibytes and is now shown in megabytes. |
| 207130598 | Improve asset upload error messages. Improved an error message when an unsupported image type was uploaded. |
| 205963075 | New portal name rules are not enforced on backend. The same portal name rules that were already enforced on the front end are now also enforced on the backend. |
| 205881764 | Cannot delete mobile logo/favicon in Apigee X/Hybrid. Fixed a bug where Apigee X and Hybrid customers could not delete mobile logos or favicons. |
| 205629978 | Broken HTML after portals v2 migration. The live portal of the upgraded portal will not be displayed correctly after migrating a portal from v1 to v2. |
| 205581372 | Users endpoint should not crash when passed an invalid Enum value. Passing an invalid sortBy value to the providers/{scope}/users endpoint is now handled gracefully. |
| 196875216 | Team does not exist exceptions should not be reported as 500s. When API producers attempted to retrieve a team which does not exist, they got an uniformative 500. Now they get an easy-to-read 404. |
On February 8, 2022 we released an updated version of the Apigee UI software.
| Bug ID | Description |
|---|---|
| 212782769 | An issue prevented editing a new target server that used a keystore reference, and selecting a key alias when using a keystore. |
On February 8, 2022 we released an updated version of the Apigee X software.
| Bug ID | Description |
|---|---|
| N/A | Upgraded infrastructure and libraries |
Chronicle Forwarder
For the Chronicle Forwarder to function properly, an additional firewall rule is needed for host oauth2.googleapis.com. This information has been added to both the Windows and Linux versions of the Forwarder documentation.
Starting in February 2022, if you have committed use discounts (CUDs), Google Cloud Billing calculates the attribution for your fees and credits every hour, to help you track costs faster and more accurately.
Learn about how your CUD fees and credits are attributed across your resources.
Network Load Balancing now supports load-balancing ESP (Encapsulating Security Payload) and ICMP (Internet Control Message Protocol) traffic. To handle these protocols, you specify the new L3_DEFAULT protocol on the load balancer's forwarding rule.
For details, see:
- Forwarding rule protocols for backend service-based network load balancers
- Setting up Network Load Balancing for multiple protocols
This feature is available in General Availability.
External TCP/UDP Network Load Balancing now allows you to configure a connection tracking policy. A connection tracking policy introduces the following new properties to let you customize your load balancer's connection tracking behavior:
To learn about how connection tracking works, see Backend selection and connection tracking.
To learn how to configure a connection tracking policy, see Configure a connection tracking policy.
This feature is available in General Availability.
Network Load Balancing introduces a new monitoring resource type loadbalancing.googleapis.com/ExternalNetworkLoadBalancerRule that lets you monitor all the supported protocols including TCP, UDP, ESP, and ICMP.
For details, see Monitoring Network Load Balancing.
This feature is available in Preview.
You can now view information about your user-defined metrics by using the Diagnostics tab located on the Metrics Explorer page. The Diagnostics tab displays summary information about the user-defined metrics your project injests, charts usage metrics, lists all user-defined metrics. You can use features on this page to create alerts, view audit logs, and get detailed information about individual metrics. For more information, see View metric diagnostics.
You can now configure private uptime checks by using the Cloud Console. For more information, see Create private uptime checks.
Cloud SQL supports the max_parallel_maintenance_workers, max_parallel_workers,
max_parallel_workers_per_gather, and max_pred_locks_per_transaction flags:
max_parallel_maintenance_workerssets the maximum number of parallel workers that can be started by a single utility command.max_parallel_workerssets the maximum number of workers that the system can support for parallel operations.max_parallel_workers_per_gathersets the maximum number of workers that can be started by a single Gather or Gather Merge node.max_pred_locks_per_transactioncontrols the average number of object locks allocated for each transaction.
For more information, see Supported flags.
Cross-region replication is now generally available in Cloud SQL for SQL Server.
You can use replication to scale the use of data in a database without degrading performance. Other reasons include migrating or maintaining data duplicates between regions.
For more information, see Replication in Cloud SQL.
Query statistics now cover DML statements, including inserts, updates, and deletes.
Added support for upgrading the Redis version of an instance to any higher version.
Support for agent pools is now generally available (GA) .
You can use agent pools to create isolated groups of agents as a source or sink entity in a transfer job. This enables you to transfer data from multiple data centers and filesystems concurrently, without creating multiple projects for a large transfer spanning multiple filesystems and data centers.
February 07, 2022
Anthos clusters on VMwareA security vulnerability, CVE-2021-4034, has been discovered in pkexec, a part of the Linux policy kit package (polkit), that allows an authenticated user to perform a privilege escalation attack. PolicyKit is generally used only on Linux desktop systems to allow non-root users to perform actions such as rebooting the system, installing packages, restarting services, and so forth, as governed by a policy.
For instructions and more details, see the GCP-2022-004 security bulletin.
Cloud Build's Bitbucket Server and Bitbucket Data Center integration is now generally available. Users can build repositories from Bitbucket Server and Bitbucket Data Center, including on-premises instances. For more information, see Building repositories from Bitbucket Server and Building repositories from Bitbucket Data Center.
Airflow 2.2.3 is available in Cloud Composer images.
(Airflow 2.2.3) Support for Deferrable Tasks is not available in Cloud Composer yet.
Cloud Composer 1.17.10 and 2.0.3 images are available:
- composer-2.0.3-airflow-2.2.3
- composer-2.0.3-airflow-2.1.4
- composer-2.0.3-airflow-2.0.2
- composer-1.17.10-airflow-2.2.3
- composer-1.17.10-airflow-2.1.4
- composer-1.17.10-airflow-2.0.2
- composer-1.17.10-airflow-1.10.15 (default)
Cloud Composer versions 1.14.0, 1.14.1, and 1.14.2 have reached their end of full support period.
This release fixes an issue in which Audit Logs for PATCH operations on managed zones and DNS server policies were not being generated.
Using the new Integrations page in the Google Cloud Console, you can now configure third-party application integrations that the Ops Agent supports. The Integrations page provides links to install instructions, displays example dashboards, and lists the metrics and logs that the Ops Agent collects for each integration. For more information, see Manage integrations
Bidirectional Forwarding Detection (BFD) for Cloud Router is Generally Available (GA).
Cloud SQL supports the wal_receiver_timeout and wal_sender_timeout flags:
- The
wal_receiver_timeoutflag ends replication connections that are inactive for the specified time. - The
wal_sender_timeoutflag, which is for detection by the ending server, ends replication connections that are inactive for the specified time.
For more information, see Supported flags.
SQL Server 2019 is now the default version. See Database versions and version policies.
Cloud Spanner's CPU Utilization metrics now provide grouping by all task priorities: low, medium, and high.
Relatedly, Cloud Spanner's monitoring console now lets you view the CPU utilization of your instance by operation type, filtered by task priority.
Added cluster_type field to job and operation metrics in Cloud Monitoring.
Google Cloud Armor Rate Limiting is now in General Availability.
The deprecated product field on the provider Entitlement resource has been updated. The field now correctly populates the product, quote, or offer depending on the entity that was purchased. If you want to use other fields to view this information, see REST Resource: providers.entitlements.
Previously, the following Event Threat Detection rules were made temporarily unavailable because they were generating extraneous findings:
Persistence: New API MethodPersistence: New Geography
The underlying issue has been resolved. These rules are now operational. For more information, see Event Threat Detection rules.
Security Health Analytics, a built-in service of Security Command Center, released the OPEN_GROUP_IAM_MEMBER detector to General Availability.
February 04, 2022
Anthos Service MeshUsing the fleet feature API to set up managed Anthos Service Mesh with automatic control plane management is now available as a preview feature in the rapid, regular, and stable release channels. For more information, see Configure managed Anthos Service Mesh with fleet API.
A security vulnerability, CVE-2021-4034, has been discovered in pkexec, a part of the Linux policy kit package (polkit), that allows an authenticated user to perform a privilege escalation attack. PolicyKit is generally used only on Linux desktop systems to allow non-root users to perform actions such as rebooting the system, installing packages, restarting services etc, as governed by a policy.
Anthos clusters on AWS is unaffected.
For instructions and more details, see the GCP-2022-004 security bulletin
A security vulnerability, CVE-2021-4034, has been discovered in pkexec, a part of the Linux policy kit package (polkit), that allows an authenticated user to perform a privilege escalation attack. PolicyKit is generally used only on Linux desktop systems to allow non-root users to perform actions such as rebooting the system, installing packages, restarting services etc, as governed by a policy.
Anthos clusters on AWS is unaffected.
For instructions and more details, see the GCP-2022-004 security bulletin.
A security vulnerability, CVE-2021-4034, has been discovered in pkexec, a part of the Linux policy kit package (polkit), that allows an authenticated user to perform a privilege escalation attack. PolicyKit is generally used only on Linux desktop systems to allow non-root users to perform actions such as rebooting the system, installing packages, restarting services etc, as governed by a policy.
For instructions and more details, see the GCP-2022-004 security bulletin
Security bulletin (all minor versions)
A security vulnerability, CVE-2021-4034, has been discovered in pkexec, a part of the Linux policy kit package (polkit), that allows an authenticated user to perform a privilege escalation attack. PolicyKit is generally used only on Linux desktop systems to allow non-root users to perform actions, such as rebooting the system, installing packages, restarting services, as governed by a policy.
For instructions and more details, see the GCP-2022-004 security bulletin.
The following PostgreSQL minor versions and extension versions are now available. If you use maintenance windows, you might not yet have these versions. In this case, you will see the new versions after your maintenance update occurs. To find your maintenance window or manage maintenance updates, see Finding and setting maintenance windows.
- 14.0 is upgraded to 14.1.
- 13.4 is upgraded to 13.5.
- 12.8 is upgraded to 12.9.
- 11.13 is upgraded to 11.14.
- 10.18 is upgraded to 10.19.
- 9.6.23 is upgraded to 9.6.24.
Additionally, the following extensions have been upgraded. For more information about these and other extensions, see PostgreSQL extensions.
- The pglogical extension is upgraded to 2.4.1.
The pgaudit extension is upgraded as follows:
- For PostgreSQL 14, upgraded to 1.6.1.
- For PostgreSQL 13, upgraded to 1.5.1.
- For PostgreSQL 12, upgraded to 1.4.2.
- For PostgreSQL 11, upgraded to 1.3.3.
- For PostgreSQL 10, upgraded to 1.2.3.
- For PostgreSQL 9.6, upgraded to 1.1.4.
Generally available: Support for the Intel Ice Lake processor on general purpose N2 VMs has reached general availablity.
Generally available: The n2-node-128-864 sole-tenant node type.
Creating a Dataproc Metastore service results in the error NO_MATCHING_ACCESS_LEVEL due to dns.googleapis.com in the service perimeter but not in the allowlist. To work around this issue, remove dns.googleapis.com from the perimeter during API calls.
Data Catalog sync users must request roles/metastore.metadataViewer to view synced Dataproc Metastore entries in Data Catalog. The roles/metastore.Admin and roles/metastore.Editor no longer support metastore databases and tables permissions.
The request_count metric spikes due to a bug in the logic of our metrics reporting pipeline.
A security vulnerability, CVE-2021-4034, has been discovered in pkexec, a part of the Linux policy kit package (polkit), that allows an authenticated user to perform a privilege escalation attack. PolicyKit is generally used only on Linux desktop systems to allow non-root users to perform actions such as rebooting the system, installing packages, restarting services etc, as governed by a policy. GKE clusters are not affected.
For instructions and more details, see the GCP-2022-004 security bulletin.
You will not be able to create new node pools that use a Docker node image starting with GKE v1.23 when:
- Creating a new cluster,
- Adding a node pool to an existing cluster, or
- Using Node Auto-provisioning (NAP) with
--autoprovisioning-image-typeset to Docker node images. - For existing clusters, you will also not be able to change the value of
--autoprovisioning-image-typeto Docker node images.
If you are upgrading your GKE clusters from GKE v1.22 to v1.23, then you will be able to continue using:
- Docker node pools that were configured before the upgrade.
- Cluster Autoscaler on Docker node pools.
- Node Auto-provisioning (NAP) with
--autoprovisioning-image-typeset to Docker node images if it was configured before upgrading to v1.23. However, we highly recommend you to migrate to GKE node images that use the Containerd container runtime.
For your reference, below are the GKE node images for the Containerd and Docker container runtimes:
- Containerd container runtime (recommended):
cos_containerd,ubuntu_containerd,windows_ltsc_containerd,windows_sac_containerd - Docker container runtime (unsupported starting with v1.24):
cos,ubuntu,windows_ltsc,windows_sac
Containerd is the default runtime on GKE. Most user workloads do not have dependencies on the container runtime. Support for Docker as a container runtime on Kubernetes nodes will be removed from OSS Kubernetes and GKE starting with v1.24. If you use a node image based on Docker container runtime, please migrate your GKE workloads to a Containerd node image as soon as possible. For more details, see Containerd node images.
Traffic Director new service routing APIs are available in preview. The new APIs simplify routing and service mesh configuration with new Mesh, Gateway, and Route resources.
Related to this change, new options are available for automated Envoy deployment.
February 03, 2022
BigQueryThe BigQuery migration assessment is now available in Preview. Use this feature to assess the complexity of migrating from your current data warehouse to BigQuery.
BigQuery ML Hyperparameter tuning is now generally available (GA). You can use this feature to improve model performance by searching for the optimal hyperparameters when training ML models using CREATE MODEL statements.
To learn more, check out the following topics:
You can now save a copy of a chart on a predefined dashboard to one of your custom dashboards by selecting Add to Custom Dashboard from the More Options menu on the chart. When you select a custom dashboard, you also have the option of renaming the copied chart.
Cloud TPU now supports Tensorflow 2.8.0. For more information, see TensorFlow 2.8.0 Release Notes.
Rate limits for all Compute Engine requests have the following changes:
- All per-user rate limits are removed.
- Rate limits are now enforced in 1-minute (60-second) intervals instead of 100-second intervals.
- Due to this change, you might receive more 403
rateLimitExceedederrors when bursting.- Although per-second rate limits increased slightly, the enforcement intervals are now shorter, so the maximum number of requests per enforcement interval is slightly reduced overall. For example, the default Queries group's rate limit is changing from 20 requests per second with a maximum of 2000 requests per 100 seconds to 25 requests per second with a maximum of 1500 requests per 60 seconds.
Additionally, rate limits are now documented for the following groups:
- Instance list referrer requests
- Instance get serial port output requests
For details, see API rate limits.
Duplicate API quota groups are displayed in the Cloud Console. For more information about requesting API quota, see Known issues.
In the Data Catalog table details page, there is now an additional section called Schema and column tags that lets you view the applied schema and their values. For more information, see View table details.
Google Cloud Deploy is now available in the following regions:
northamerica-northeast1(Montréal)asia-northeast1(Tokyo)
(2022-R02) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- Control plane and node version 1.19.16-gke.6100 is now available.
- Control plane and node version 1.20.15-gke.300 is now available.
- Control plane and node version 1.21.9-gke.300 is now available.
- Control plane and node version 1.22.6-gke.300 is now available.
- Control plane version 1.21.5-gke.1302 is no longer available.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.18 to 1.19.16-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.19 to 1.19.16-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to 1.21.6-gke.1500 with this release.
Stable channel
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.18 to 1.19.16-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.19 to 1.19.16-gke.1500 with this release.
Regular channel
- Version 1.22.3-gke.1500 is now available in the Regular channel.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.19 to 1.20.12-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.6-gke.1500 with this release.
Rapid channel
- Version 1.22.4-gke.1501 is now the default version in the Rapid channel.
- Version 1.21.9-gke.300 is now available in the Rapid channel.
- Version 1.22.6-gke.300 is now available in the Rapid channel.
- Version 1.23.2-gke.300 is now available in the Rapid channel.
- Version 1.21.5-gke.1802 is no longer available in the Rapid channel.
- Version 1.23.1-gke.500 is no longer available in the Rapid channel.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.6-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.6-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to 1.22.4-gke.1501 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.23.2-gke.300 with this release.
(2022-R02) Version updates
- Version 1.22.3-gke.1500 is now available in the Regular channel.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.19 to 1.20.12-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.6-gke.1500 with this release.
(2022-R02) Version updates
- Version 1.22.4-gke.1501 is now the default version in the Rapid channel.
- Version 1.21.9-gke.300 is now available in the Rapid channel.
- Version 1.22.6-gke.300 is now available in the Rapid channel.
- Version 1.23.2-gke.300 is now available in the Rapid channel.
- Version 1.21.5-gke.1802 is no longer available in the Rapid channel.
- Version 1.23.1-gke.500 is no longer available in the Rapid channel.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.6-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.21.6-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to 1.22.4-gke.1501 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.23.2-gke.300 with this release.
(2022-R02) Version updates
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.18 to 1.19.16-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.19 to 1.19.16-gke.1500 with this release.
(2022-R02) Version updates
- Control plane and node version 1.19.16-gke.6100 is now available.
- Control plane and node version 1.20.15-gke.300 is now available.
- Control plane and node version 1.21.9-gke.300 is now available.
- Control plane and node version 1.22.6-gke.300 is now available.
- Control plane version 1.21.5-gke.1302 is no longer available.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.18 to 1.19.16-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.19 to 1.19.16-gke.1500 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to 1.21.6-gke.1500 with this release.
Generally available: Managed Microsoft AD now supports the use of tags on domains.
Pub/Sub Lite now supports regional Lite topics that replicate data to a secondary zone.
SAP HANA certifications: N2 series Compute Engine VMs on the Intel Ice Lake CPU platform
SAP now certifies Compute Engine N2 series machine types with the Intel Ice Lake CPU platform. The new SAP HANA certifications include two new machine sizes, n2-highmem-96 and n2-highmem-128.
For more information, see Certified Compute Engine VMs for SAP HANA.
SAP NetWeaver certifications: N2 series Compute Engine VMs on the Intel Ice Lake CPU platform
SAP now certifies Compute Engine N2 series machine types with the Intel Ice Lake CPU platform. The new SAP NetWeaver certifications include two new machine sizes, n2-highmem-96 and n2-highmem-128.
For more information, see N2 general-purpose machine types.
Secret manager now supports data checksums when adding or accessing a secret version.