Google Cloud release notes

Stay organized with collections Save and categorize content based on your preferences.

The following release notes cover the most recent changes over the last 60 days. For a comprehensive list of product-specific release notes, see the individual product release note pages.

You can also see and filter all release notes in the Google Cloud console or you can programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly: https://cloud.google.com/feeds/gcp-release-notes.xml

April 10, 2023

BigQuery

The limit for maximum result size (20 GiB logical bytes) when querying Azure or Amazon Simple Storage service (S3) data is now generally available (GA). Querying Azure and Amazon S3 data are now subject to the following quotas and limitations:

  • The maximum row size is 10 MiB. For more information, see Quotas for query jobs.

  • If your query uses the ORDER BY clause and has a result size larger than 256 MB, then your query fails. Previously, this limit was 2 MB. For more information, see Limitations.

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for bigquery/storage/apiv1beta1

1.50.0 (2023-04-03)

Features
  • bigquery/connection: Add spark connection properties type (#7570) (499b489)
  • bigquery/migration: Add request_source field and update formatting (#7586) (c967961)
  • bigquery/reservation: Add edition/autoscale related fields (#7608) (2b7bb66)
  • bigquery/storage/managedwriter: Decouple connections and writers (#7314) (7d085b4)
  • bigquery/storage/managedwriter: Introduce location routing header (#7663) (cf06802)
Bug Fixes
  • bigquery/storage/managedwriter: Fix option propagation (#7669) (f684e16)
Documentation
  • bigquery/reservation: Mention that some fields are deprecated (597ea0f)

The results for queries against table snapshots can now be returned from cache.

Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigtable

2.20.3 (2023-04-03)

Dependencies
  • Upgrade shared dependencies to 3.6.0 and monitoring to 3.15.0 (#1688) (c0bad0d)
Cloud Run

When deploying a new revision, Cloud Run now starts enough instances of the new revision before directing traffic to it. This reduces the impact of new revision deployments on request latencies, notably when serving high levels of traffic.

Cloud Spanner

Cloud Spanner integration with Data Catalog is now available in Preview in the europe-central2 region.

For more information, see Manage resources using Data Catalog.

Dataflow

Dataflow cost monitoring is now available in preview.

SAP on Google Cloud

Cloud Storage Backint agent for SAP HANA version 1.0.25

Version 1.0.25 of the Cloud Storage Backint agent for SAP HANA is now available. This version includes logging enhancements.

For more information about the agent, see Cloud Storage Backint agent for SAP HANA overview.

April 07, 2023

Cloud Data Loss Prevention

To help you understand and test the discovery service, Cloud DLP has made it easier for you to test profiling on a single table. You can profile up to 25 tables at no additional charge, one at a time. Only tables that are less than or equal to 1 TB in size can be profiled for free. For more information, see Profile a table in test mode.

Cloud Run

Support for Identity-aware Proxy (IAP) with Cloud Run to use identity and context to guard access to your applications is now at general availability (GA).

Document AI Warehouse

Datetime properties filtering is supported in the Document AI Warehouse UI.

Identity-Aware Proxy

Support for Identity-aware Proxy (IAP) with Cloud Run to use identity and context to guard access to your applications is now at general availability (GA).

Sovereign Controls by Partners

The following products are now supported. See Supported products for more information:

  • Cloud DNS
  • Cloud Interconnect
  • Cloud Load Balancing
  • Cloud NAT
  • Cloud Router
  • Cloud VPN
  • Identity and Access Management (IAM)
  • Identity-Aware Proxy
  • Network Connectivity Center
  • Virtual Private Cloud
  • VPC Service Controls

April 06, 2023

AlloyDB for PostgreSQL

AlloyDB for PostgreSQL is available in us-west2 (Los Angeles). For more information, see AlloyDB locations.

Assured Workloads

The EU Regions and Support compliance regime now supports the following products. See Supported products for more information:

  • Cloud DNS
  • Cloud Interconnect
  • Cloud Load Balancing
  • Cloud NAT
  • Cloud Router
  • Cloud VPN
  • Identity-Aware Proxy
  • Network Connectivity Center
  • Virtual Private Cloud
  • VPC Service Controls

The EU Regions and Support with Sovereignty Controls compliance regime now supports the following products. See Supported products for more information:

  • Cloud DNS
  • Cloud Interconnect
  • Cloud Load Balancing
  • Cloud NAT
  • Cloud Router
  • Cloud VPN
  • Identity-Aware Proxy
  • Network Connectivity Center
  • Virtual Private Cloud
  • VPC Service Controls
BigQuery

The add data demo guide walks you through the process of adding data to BigQuery through popular sources and is now in preview.

Cloud Database Migration Service

You can now set up cascading read replicas after you migrate data to a Cloud SQL destination instance using Database Migration Service. To find out how to set up cascading read replicas for a Cloud SQL for MySQL instance, click here. To find out how to set up cascading read replicas for a Cloud SQL for PostgreSQL instance, click here.

Cloud Functions

Cloud Functions now supports the use of the Yarn 2 package manager with private Node.js modules.

Cloud Load Balancing

Regional external and regional internal HTTP(S) load balancers now support using Cloud Run services as backends for the load balancer. This is configured using a serverless network endpoint group (NEG).

For details, see:

This feature is available in General availability.

Forwarding rules for external TCP/UDP network load balancers can now be configured to direct traffic coming from a specific range of source IP addresses to a specific backend service (or target instance). This is called traffic steering.

For details, see:

This capability is in General availability.

Cloud Run

Regional external and regional internal HTTP(S) load balancers now support using Cloud Run services as backends for the load balancer. This is configured using a serverless network endpoint group (NEG).

For details, see:

This feature is available in General availability.

Cloud SQL for MySQL

Cascading Replicas is now generally available when migrating from external servers. You can now configure migrated replicas to have read replicas under them before promoting them to primary replica. To learn more, see External Server Cascading Replicas.

Cloud SQL for PostgreSQL

Cascading Replicas is now generally available when migrating from external servers. You can now configure migrated replicas to have read replicas under them before promoting them to primary replica. To learn more, see External Server Cascading Replicas.

Dataproc

New Dataproc Serverless for Spark runtime versions:

  • 1.1.10
  • 2.0.18
  • 2.1.0-RC7
Deep Learning Containers

M106 Release

  • Miscellaneous software updates.
Deep Learning VM Images

M106 Release

  • Rolled back a previous change in which Jupyter dependencies were located in a separate Conda environment.
  • Miscellaneous software updates.
Storage Transfer Service

Support for Manifest in Storage Transfer Service is now generally available (GA). You can use Manifest to transfer a specific list of objects, object versions, and files from cloud and on-premises sources. Programmatic users can use the output of an upstream operation generating a list of files and objects as an input for Storage Transfer Service to act upon.

Transcoder API

Overlays can now be created using PNG images (with or without transparency).

Vertex AI Workbench

M106 Release

The M106 release of Vertex AI Workbench user-managed notebooks includes the following:

  • Rolled back a previous change in which Jupyter dependencies were located in a separate Conda environment.
  • Fixed a bug in which kernels used by notebooks did not contain the specified machine learning frameworks.
  • Miscellaneous software updates.
reCAPTCHA Enterprise

reCAPTCHA Enterprise Mobile SDK v18.1.2 is now available for Android.

This version contains the following changes:

  • Returns network error instead of internal error in cases where the network is extremely slow, but doesn't fail by the timeout.
  • Removed non sdk api violation.

April 05, 2023

Anthos Attached Clusters

This release includes the following Anthos attached clusters platform versions:

  • 1.21.0-gke.1
  • 1.22.0-gke.1
  • 1.23.0-gke.3
  • 1.24.0-gke.2
  • 1.25.0-gke.2

This release fixes the following vulnerabilities:

Anthos clusters on AWS

You can now launch clusters with the following Kubernetes versions:

  • 1.23.16-gke.2800
  • 1.24.10-gke.1200
  • 1.25.6-gke.1600
  • Fixed an issue that could cause cluster upgrades to fail if certain types of validating admission webhooks are registered.
  • (1.24 only) Fixed Cilium security ID propagation so that IDs are properly passed in the tunnel header when requests are forwarded to Services of type NodePort and LoadBalancer.
Anthos clusters on Azure

You can now launch clusters with the following Kubernetes versions:

  • 1.23.16-gke.2800
  • 1.24.10-gke.1200
  • 1.25.6-gke.1600
  • Fixed an issue that could cause cluster upgrades to fail if certain types of validating admission webhooks are registered.
  • (1.24 only) Fixed Cilium security ID propagation so that IDs are properly passed in the tunnel header when requests are forwarded to Services of type NodePort and LoadBalancer.
App Engine standard environment Node.js

The Node.js runtime now supports the use of Yarn 2 for configuring private modules hosted in Artifact Registry.

BigQuery

Non-incremental materialized views support most SQL queries, including OUTER JOIN, UNION, and HAVING clauses, as well as analytic functions. This feature is in preview.

Cloud Monitoring

A new interface for creating charts with Metrics Explorer is in Public Preview. For more information, see Create charts with Metrics Explorer.

Cloud Storage

Cloud Storage FUSE is now available in Preview. You can use Cloud Storage FUSE to mount and access storage buckets as local file systems.

Google Kubernetes Engine

The g2-standard machine family with NVIDIA L4 is available in Preview for node pools in clusters running GKE version 1.22 and later. To select the machine family, use the --machine-type flag in your create command.

Identity and Access Management

Workforce identity federation and workload identity federation can now accept encrypted SAML assertions. The feature is generally available (GA). To use the feature, locate the Create the workload identity pool and provider section in the configuration guide for your identity provider and follow the gcloud CLI instructions for the SAML workflow.

Virtual Private Cloud

General Availability: Private Service Connect endpoints with consumer HTTP(S) controls support accessing regional Google APIs and published services using the following load balancers:

  • Regional internal HTTP(S) load balancer
  • Regional external HTTP(S) load balancer

April 04, 2023

Anthos Service Mesh

1.17.2-asm.1 is now available for in-cluster Anthos Service Mesh.

You can now download 1.17.2-asm.1 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.17.1 subject to the list of supported features. Anthos Service Mesh 1.17.2-asm.1 uses Envoy v1.25.2.

Managed Anthos Service Mesh 1.17 is rolling out to the rapid release channel soon. You can periodically check this page for the announcement of the rollout of managed Anthos Service Mesh to the rapid channel. See Select a managed Anthos Service Mesh release channel for more information.

The Envoy projects recently disclosed a series of CVEs that can expose Anthos Service Mesh to remotely exploitable vulnerabilities. The fixes for these CVEs are already included in 1.17.2-asm.1. For more information, see the security bulletin.

Anthos Service Mesh now supports multi-cluster, multi-network meshes on Anthos clusters on Azure. See Install Anthos Service Mesh for more information.

The asmcli flag --option vm used by the now deprecated Compute Engine virtual machine feature has been removed.

1.14.6-asm.11 is now available for in-cluster Anthos Service Mesh.

This patch release contains the fixes for the security vulnerabilities listed in GCP-2023-002 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.

1.15.7-asm.1 is now available for in-cluster Anthos Service Mesh.

This patch release contains the fixes for the security vulnerabilities listed in GCP-2023-002. For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.

1.16.4-asm.2 is now available for in-cluster Anthos Service Mesh.

This patch release contains the fixes for the security vulnerabilities listed in GCP-2023-002. For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.

BigQuery

BigQuery is now available in the Israel (me-west1) region.

Cloud Bigtable

The Cloud Bigtable documentation has been updated to include guidance on using regional endpoints. For details, see Regional endpoints.

Cloud Build

Users can generate Supply chain Levels for Software Artifacts (SLSA) build provenance information for standalone Maven and Python packages when they upload artifacts to Artifact Registry using new fields available in the Cloud Build config file. This feature is generally available. For more information, see Build and test Java applications and Build and test Python applications.

Cloud Functions

You can now use uppercase letters and underscores in the function name you specify for a 2nd gen function when you deploy the function.

Compute Engine

Preview: Accelerator-optimized (G2) machine types are now available on Compute Engine. Each G2 machine type has a fixed number of NVIDIA® L4 GPUs attached to support your next generation graphics performance workloads. The G2 machine types are available in the following three regions:

  • Iowa, North America: us-central1-a,b
  • Netherlands, Europe: europe-west4-a
  • Singapore, APAC: asia-southeast1-b
Dataproc Datastream

Datastream support for BigQuery as destination is now generally available (GA). For more information, click here.

Datastream support for PostgreSQL as source is now generally available (GA). For more information, click here.

Google Cloud Deploy

Google Cloud Deploy now provides the ability to use a canary deployment strategy, supported in preview.

Translation Hub

The maximum number of admin-created and user-created translation templates has increased. For more information, see Usage limits in Quotas and limits.

To simplify portal creation, you can have Translation Hub automatically enable the portal's service account. For more information, see Enable users to request translations.

Vertex AI

The Vertex AI Matching Engine service now offers Preview support for deploying an index to a public endpoint. For information about how to get started, see Matching Engine Setup.

Vertex AI Prediction

You can now view logs for Vertex AI Batch Prediction jobs in Cloud Logging.

April 03, 2023

Anthos Service Mesh

Anthos clusters on AWS (previous generation) is deprecated as of April 1, 2023. Therefore, Anthos Service Mesh no longer supports Anthos clusters on AWS (previous generation). For more information, see the deprecation announcement.

Anthos clusters on VMware

Anthos clusters on VMware 1.14.3-gke.25 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.14.3-gke.25 runs on Kubernetes 1.25.5-gke.100.

The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.14, 1.13, and 1.12.

We now allow storage DRS to be enabled in manual mode.

  • We now backfill the OnPremAdminCluster OSImageType field to prevent an unexpected diff during cluster update.

  • Fixed an issue where gkectl diagnose cluster didn't check the health of control-plane Pods for kubeception user clusters.

  • Fixed an issue where the user-cluster node options and startup script used the cluster version instead of the node pool version.

Fixed the following vulnerabilities:

Apigee Integration

On April 3, 2023 we released an updated version of the Apigee Integration.

Secret Manager - Access task (Preview)

The Secret Manager - Access task lets you access secret versions that are stored in Cloud Secret Manager from your integration.

For more information, see Secret Manager - Access task.

Apigee hybrid

hybrid 1.8.6

On April 3, 2023 we released an updated version of the Apigee hybrid software, 1.8.6.

Bug ID Description
274292101 In certain circumstances, environment-scoped KVMs in hybrid could cause rollback issues for MART.
271266079 Removed port 80 from the default Kubernetes service of Apigee Ingress Gateway.
267691299 The Apigee controller uses a dedicated apigee-manager Kubernetes service account, instead of using the default SA.
267666187 When using a custom Kubernetes service for the Apigee ingress gateway, you can disable the creation of a default load balancer. See Managing Apigee ingress gateway.
266814873 In certain circumstances, retrieving encrypted KVM entries could fail with an error. This fix ensures that MART will be able to successfully function for environment-scoped KVM entries, even if the encryption key is used in the Org Env configuration or when the keys contain non-UTF8 characters. There is no change to KVM data.
263840644 Fixed a conflict with an existing ASM on the cluster.
245619397 In Apigee hybrid, fluentbit support now includes the NO_PROXY environment variable.
223320630 mTLS-related client variables are now set by the Apigee runtime.
Bug ID Description
275002360 Security fixes for fluent-bit.
This addresses the following vulnerabilities:
274112103 Security fixes to the Apigee Controller and Apigee Watcher.
This addresses the following vulnerabilities:
App Engine standard environment PHP

The PHP 8.2 runtime for App Engine standard environment is now available in preview.

Application Integration

Secret Manager - Access task

The Secret Manager - Access task lets you access secret versions that are stored in Cloud Secret Manager from your integration.

For more information, see Secret Manager - Access task.

BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigquery

2.24.4 (2023-03-30)

Bug Fixes
  • QueryWithStructsParameters sample mismatch (#2610) (71f9f55)
Dependencies
  • Update dependency com.google.apis:google-api-services-bigquery to v2-rev20230318-2.0.0 (#2607) (a328eb2)
  • Update dependency com.google.cloud:google-cloud-bigquerystorage-bom to v2.34.2 (#2619) (e4aa0fe)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.6.0 (#2612) (eac97ac)
  • Update github/codeql-action action to v2.2.9 (#2608) (24aac14)

Python

Changes for google-cloud-bigquery

3.9.0 (2023-03-28)

Features
Bug Fixes
  • Keyerror when the load_table_from_dataframe accesses a unmapped dtype dataframe index (#1535) (a69348a)

3.8.0 (2023-03-24)

Features
  • Add bool, int, float, string dtype to to_dataframe (#1529) (5e4465d)
  • Add default LoadJobConfig to Client (#1526) (a2520ca)
  • Expose configuration property on CopyJob, ExtractJob, LoadJob, QueryJob (#1521) (8270a10)
Bug Fixes
  • Loosen ipywidgets restrictions further to address ipython compatibility issues (#1531) (50e5026)
Chronicle

Google has added Australia (Sydney) as a new region for Chronicle customers. Chronicle can now store customer data in this region. This also adds a new regional endpoint for Chronicle APIs at https://australia-southeast1-backstory.googleapis.com/.

Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Node.js

Changes for @google-cloud/bigtable

4.5.0 (2023-03-20)

Features
  • Add npm run compile to the testproxy command (#1258) (52c06a2)
Bug Fixes
  • Always set the retry attempt to 0 for now (#1251) (5ee6f19)

Java

Changes for google-cloud-bigtable

2.20.2 (2023-03-29)

Bug Fixes
  • Higher application blocking latency precision (#1676) (45ce93b)
  • Make ChangeStreamRecord interface serializable (#1685) (b97badb)
  • Mark readRow requests as unary operations (#1679) (f88bb67)
Cloud Functions

Cloud Functions has added support for a new runtime, PHP 8.2, at the Preview release level.

Cloud Load Balancing

Internal HTTP(S) load balancers and internal TCP proxy load balancers now support global access. By default, clients for these load balancers must be in the same region as the load balancer. With global access enabled, clients can access the load balancer from any region. They still must be in the same VPC network as the load balancer or in a VPC network that's connected to the load balancer's VPC network by using VPC Network Peering.

For instructions, see the following:

This capability is in General availability.

Cloud Logging

Cloud Logging now uses one service account and writer identity for all the sinks in a resource container that route logs to an external resource. Cloud Logging creates the service account the first time a log sink in the resource container is created or updated.

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-logging

3.14.7 (2023-03-28)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.6.0 (#1308) (febcf49)
Cloud Monitoring

The time-range selector in select Cloud Monitoring pages has been updated to support a larger set of time range options, such as preset times, custom start and end times, and relative time ranges.

You can now configure metric-based alerting policies to send repeated notifications for open and acknowledged incidents. For more information, see Send repeated notifications.

Cloud Workstations

Cloud Workstations is beginning the migration of preconfigured base images to Ubuntu as their base OS. The last images built using Debian are tagged with :last-debian in Artifact Registry to allow more time for you to make adjustments to custom images.

Dataflow

A weekly digest of client library updates from across the Cloud SDK.

Python

Changes for google-cloud-dataflow-client

0.8.3 (2023-03-23)

Documentation
  • Fix formatting of request arg in docstring (#177) (22668f6)
Eventarc

Support for specifying the encoding of the event payload data as either application/json or application/protobuf through an eventDataContentType field is available.

Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Python

Changes for google-cloud-datastore

2.15.1 (2023-03-24)

Documentation
  • Fix formatting of request arg in docstring (#428) (da86a02)
  • Improve query API documentation (#430) (915daf5)

Java

Changes for google-cloud-datastore

2.14.2 (2023-03-29)

Documentation
Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.6.0 (#1035) (b2f4cb3)
  • Update gapic-generator-java to 2.16.0 (8c96c55)
Google Kubernetes Engine

GKE now supports a streamlined Fleet registration process, allowing users to register their clusters to a Fleet directly when clusters are created using the gcloud command. For more information, see Register a GKE cluster to your fleet.

Secret Manager

Secret Manager support for zone separation is now generally available.

A weekly digest of client library updates from across the Cloud SDK.

Python

Changes for google-cloud-secret-manager

2.16.1 (2023-03-23)

Documentation
  • Fix formatting of request arg in docstring (#409) (925d05a)
Transcoder API

Batch mode is now supported. You can use it to create thousands of jobs that will be processed on a first in, first out basis.

Vertex AI

The Vertex AI Model Registry now offers Preview support for model copy between regions. For information about how to copy your model between regions, see Copy models in Model Registry.

April 01, 2023

Cloud Storage

March 31, 2023

Access Approval

Access Approval supports Cloud Composer in the GA stage.

Anthos clusters on bare metal

Cluster lifecycle improvements 1.13.1 and later

Starting with Anthos clusters on bare metal release 1.13.1, you can use the Google Cloud console or the gcloud CLI to create admin clusters. For more information, see the documentation for your version of Anthos clusters on bare metal:

Bare Metal Solution

You can now view Bare Metal Solution infrastructure metrics in the Google Cloud console. This feature is generally available (GA).

BeyondCorp Enterprise

The BeyondCorp Enterprise Client Connector is deprecated as of March 15, 2023, and is planned for shut down on December 31, 2023. Contact your account team with any questions.

Cloud Bigtable

Cloud Bigtable instance and table metadata is now automatically synced to Data Catalog, a feature of Dataplex, for improved data discovery and governance. Metadata is not synced for a project with an organization policy that restricts resource locations. To get started, see Manage data assets using Data Catalog. This feature is available in Preview.

You can now use Key Visualizer for Cloud Bigtable to analyze tables that are at least 1 GB. Previously, the minimum table size required for Key Visualizer was 30 GB. For more information on troubleshooting with Key Visualizer, see the Key Visualizer overview.

Cloud Composer

(Cloud Composer 2) Access Approval is now generally available (GA). See Access Approval overview and Access Approval supported services for more information.

Cloud Logging

Effective 1 April 2023, storage costs apply to logs data retained longer than 30 days. For pricing details, see Cloud Logging pricing summary. Prior to 1 April 2023, there are no charges for retaining logs longer than 30 days. To review the billable storage for your log buckets, go to the Logs Storage page of the Google Cloud console.

Cloud Spanner

Cloud Spanner integration with Data Catalog is now available in Preview. Data Catalog is a fully managed, scalable metadata management service within Dataplex. It automatically catalogs metadata about Cloud Spanner instances, databases, tables, columns, and views. For Preview, integration with Data Catalog is not available in the europe-central2 region.

For more information, see Manage resources using Data Catalog.

Cloud TPU

Cloud TPU now supports Tensorflow 2.11.1. For more information see the TensorFlow 2.11.1 release notes.

Cloud Workstations

You can use a pre-customized snapshot as the source of a Persistent Disk in Cloud Workstations. For more information, see About disk snapshots. See also the sourceSnapshot within GceRegionalPersistentDisk field added to the following REST API resources: workstation configurations, and source_snapshot in the following RPC resources: workstations.v1beta.

Cloud Workstations is available in the following region:

  • asia-northeast1 (Japan)

For more information, see Locations.

Compute Engine

Generally available: You can use the Regional disk replica state metric in Cloud Monitoring to track the states of your regional Persistent Disk zonal replicas. You can also use the metric data to determine the replication state of your regional Persistent Disk volumes.

Learn more about zonal replication for regional Persistent Disk and how to monitor the states of regional Persistent Disk zonal replicas.

Deep Learning Containers

M105 Release

  • The following Deep Learning Containers images are now available with Python 3.10 on Debian 11:

    • TensorFlow 2.11 CPU (us-docker.pkg.dev/deeplearning-platform-release/gcr.io/tf-cpu.2-11.py310:latest)
    • TensorFlow 2.11 GPU with Cuda 11.3 (us-docker.pkg.dev/deeplearning-platform-release/gcr.io/tf-gpu.2-11.py310:latest)
    • PyTorch 1.13 with Cuda 11.3 (us-docker.pkg.dev/deeplearning-platform-release/gcr.io/pytorch-gpu.1-13.py310:latest)
    • Base CPU (us-docker.pkg.dev/deeplearning-platform-release/gcr.io/base-cpu.py310:latest)
    • Base GPU with Cuda 11.3 (us-docker.pkg.dev/deeplearning-platform-release/gcr.io/base-cu113.py310:latest)
  • The following Deep Learning Containers images are now available with Python 3.9 on Debian 11:

    • TensorFlow 2.6 CPU (us-docker.pkg.dev/deeplearning-platform-release/gcr.io/tf-cpu.2-6.py39:latest)
    • TensorFlow 2.6 GPU with Cuda 11.3 (us-docker.pkg.dev/deeplearning-platform-release/gcr.io/tf-gpu.2-6.py39:latest)
  • Miscellaneous bug fixes and improvements.

Deep Learning VM Images

M105 Release

  • The following Deep Learning VM images are now available with Python 3.10 on Debian 11:

    • TensorFlow 2.11 CPU (tf-2-11-cpu-debian-11-py310)
    • TensorFlow 2.11 GPU with Cuda 11.3 (tf-2-11-cu113-debian-11-py310)
    • PyTorch 1.13 with Cuda 11.3 (pytorch-1-13-cu113-debian-11-py310)
    • Base CPU (common-cpu-debian-11-py310)
    • Base GPU with Cuda 11.3 (common-cu113-debian11-py310)
  • The following Deep Learning VM images are now available with Python 3.9 on Debian 11:

    • TensorFlow 2.6 CPU (tf-2-6-cpu-debian-11-py39)
    • TensorFlow 2.6 GPU with Cuda 11.3 (tf-2-6-cu113-debian-11-py39)
  • Jupyter-related libraries have been moved to a different Conda environment, separate from the one containing machine learning frameworks and base software libraries.

  • Miscellaneous bug fixes and improvements.

Google Cloud VMware Engine

VMware Engine nodes are now available in the following additional region:

  • Santiago (southamerica-west1)

VMware Engine nodes are now available in the following additional zone:

  • London, England (europe-west2-b)
Google Kubernetes Engine

(2023-R08) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters

The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.

No channel

Stable channel

  • The following versions are now available in the Stable channel:
  • Version 1.24.10-gke.2300 is now the default version in the Stable channel.
  • The following versions are no longer available in the Stable channel:
    • 1.21.14-gke.14600
    • 1.22.17-gke.4000
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to 1.21.14-gke.15800 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to 1.22.17-gke.5400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to 1.23.16-gke.1400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to 1.24.10-gke.2300 with this release.

Regular channel

  • The following versions are now available in the Regular channel:
  • Version 1.24.10-gke.2300 is now the default version in the Regular channel.
  • The following versions are no longer available in the Regular channel:
    • 1.21.14-gke.18100
    • 1.22.17-gke.5400
    • 1.24.9-gke.3200
    • 1.25.6-gke.1000
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.14-gke.18800 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.22.17-gke.6100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to 1.23.16-gke.2500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to 1.24.10-gke.2300 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to 1.24.10-gke.2300 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to 1.25.7-gke.1000 with this release.

Rapid channel

  • The following versions are now available in the Rapid channel:
  • Version 1.26.2-gke.1000 is now the default version in the Rapid channel.
  • The following versions are no longer available in the Rapid channel:
    • 1.22.17-gke.5400
    • 1.23.16-gke.1400
    • 1.24.11-gke.1000
    • 1.25.6-gke.1000
    • 1.26.1-gke.1500
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.22.17-gke.6100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to 1.23.16-gke.2500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.24.12-gke.500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to 1.25.7-gke.1000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to 1.25.7-gke.1000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to 1.26.2-gke.1000 with this release.

(2023-R08) Version updates

  • The following versions are now available in the Stable channel:
  • Version 1.24.10-gke.2300 is now the default version in the Stable channel.
  • The following versions are no longer available in the Stable channel:
    • 1.21.14-gke.14600
    • 1.22.17-gke.4000
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to 1.21.14-gke.15800 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to 1.22.17-gke.5400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to 1.23.16-gke.1400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to 1.24.10-gke.2300 with this release.

(2023-R08) Version updates

  • The following versions are now available in the Regular channel:
  • Version 1.24.10-gke.2300 is now the default version in the Regular channel.
  • The following versions are no longer available in the Regular channel:
    • 1.21.14-gke.18100
    • 1.22.17-gke.5400
    • 1.24.9-gke.3200
    • 1.25.6-gke.1000
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.14-gke.18800 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.22.17-gke.6100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to 1.23.16-gke.2500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to 1.24.10-gke.2300 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to 1.24.10-gke.2300 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to 1.25.7-gke.1000 with this release.

(2023-R08) Version updates

  • The following versions are now available in the Rapid channel:
  • Version 1.26.2-gke.1000 is now the default version in the Rapid channel.
  • The following versions are no longer available in the Rapid channel:
    • 1.22.17-gke.5400
    • 1.23.16-gke.1400
    • 1.24.11-gke.1000
    • 1.25.6-gke.1000
    • 1.26.1-gke.1500
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.22.17-gke.6100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to 1.23.16-gke.2500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.24.12-gke.500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to 1.25.7-gke.1000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to 1.25.7-gke.1000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to 1.26.2-gke.1000 with this release.

(2023-R08) Version updates

Security Command Center

Security Command Center supports CIS Google Cloud Computing Foundations Benchmark v1.3.0.

The following detectors are new for v1.3.0:

  • Access transparency disabled
  • Cloud Asset API disabled
  • Dataproc CMEK disabled
  • Essential contacts not configured
  • Flow logs settings not recommended

The following detectors have been updated:

  • Audit logging disabled

For more information about Security Command Center support for standards and compliance, see the following:

Vertex AI Workbench

M105 Release

The M105 release of Vertex AI Workbench user-managed notebooks includes the following:

  • The following user-managed notebooks images are now available with Python 3.10 on Debian 11:

    • TensorFlow 2.11 CPU (tf-2-11-cpu-notebooks-debian-11-py310)
    • TensorFlow 2.11 GPU with Cuda 11.3 (tf-2-11-cu113-notebooks-debian-11-py310)
    • PyTorch 1.13 with Cuda 11.3 (pytorch-1-13-cu113-notebooks-debian-11-py310)
    • Base CPU (common-cpu-notebooks-debian-11-py310)
    • Base GPU with Cuda 11.3 (common-cu113-notebooks-debian11-py310)
  • The following user-managed notebooks images are now available with Python 3.9 on Debian 11:

    • TensorFlow 2.6 CPU (tf-2-6-cpu-notebooks-debian-11-py39)
    • TensorFlow 2.6 GPU with Cuda 11.3 (tf-2-6-cu113-notebooks-debian-11-py39)
  • Jupyter-related libraries have been moved to a different Conda environment, separate from the one containing machine learning frameworks and base software libraries.

March 30, 2023

Artifact Registry

Artifact Registry is now available in the me-central1 region (Doha, Qatar).

Assured Workloads

The Australia Regions with Assured Support compliance regime is now generally available.

BigQuery

BigQuery ML documentation is now integrated with BigQuery documentation to unify resources for data analysis and machine learning tasks such as inference. BigQuery ML documentation resources include:

BigQuery Partner Center, which can be used to discover and try validated partner applications, is now generally available (GA). In addition, the Google Cloud Ready - BigQuery initiative has added 14 new partners.

Chronicle

UDM Search - Grouped fields

Grouped fields are aliases for groups of related UDM fields. You can use them to query multiple UDM fields at the same time without typing each field individually. For example, you can use the IP address grouped field to search for an IP address across most of the common UDM IP address fields.

You can match a grouped field using a regular expression and using the nocase operator. Reference lists are supported. Grouped fields can be used in combination with regular UDM fields. Grouped fields also have a separate section in Quick Filters.

Cloud Interconnect

Dedicated Cloud Interconnect support is available in the following colocation facilities:

  • Ooredoo QDC5 (Qatar Data Center Ooredoo), Doha
  • Quantum Switch (QSDC), Doha

For more information, see the Locations table.

Cloud Key Management Service

Cloud KMS is available in the following region:

  • me-central1

For more information, see Cloud KMS locations.

Cloud Monitoring

The link for the Managed Prometheus page in Cloud Monitoring now goes to the PromQL tab on the Metrics Explorer page.

Cloud Run

The following new region is now available: me-central1.

Cloud SQL for MySQL

Support for me-central1 (Doha) region.

Cloud SQL for PostgreSQL

Support for me-central1 (Doha) region.

Cloud SQL for SQL Server

Support for me-central1 (Doha) region.

Cloud Spanner

You can create Cloud Spanner regional instances in Doha, Qatar (me-central1).

Cloud Storage

Cloud Storage is now available in Doha, Qatar (me-central1 region).

Cloud VPN

Cloud VPN is now available in region me-central1 (Doha, Qatar).

Pricing is available on the Cloud VPN pricing page.

Cloud Workstations

You can use container output logging to view standard output and standard error logs generated by a workstation container.

Compute Engine

Generally available: Doha, Qatar, Middle East me-central1-a,b,c has launched with E2 and N2 VMs available in all three zones.

See VM instance pricing for details.

Preview: Persistent Disk Asynchronous Replication (PD Async Replication) provides low recovery point objective (RPO) and low recovery time objective (RTO) block storage replication for cross-region active-passive disaster recovery. For more information, see About Persistent Disk Asynchronous Replication.

Config Connector

Config Connector version 1.102.0 is now available.

Added support for IAMAccessBoundaryPolicy resource.

Fixed a bug causing diff detection on reservedIpRange field in RedisInstance.

Added mode, remoteRepositoryConfig, virtualRepositoryConfig fields to ArtifactRegistryRepository

Added scheduling.maintenanceInterval field to ComputeInstance.

Added scheduling.maintenanceInterval field to ComputeInstanceTemplate.

Added groupPlacementPolicy.maxDistance field to ComputeResourcePolicy.

Added deletionPolicy field to ComputeSharedVPCServiceProject.

Added protectConfig field to ContainerCluster.

Added transferSpec.sinkAgentPoolName, transferSpec.sourceAgentPoolName fields to StorageTransferJob.

Added spec.bitbucketServerTriggerConfig, spec.github.enterpriseConfigResourceNameRef fields to CloudBuildTrigger.

Added spec.diskEncryptionKey.rsaEncryptedKey field to ComputeDisk.

Added spec.rateLimitOptions.enforceOnKeyConfigs field to ComputeSecurityPolicy.

Added spec.kubeletConfig.podPidsLimit field to ContainerCluster.

Added spec.kubeletConfig.podPidsLimit field to ContainerNodePool.

Added spec.instanceType field to SQLInstance.

Dataflow

Dataflow is now available in Doha (me-central1).

Dataproc

Dataproc is now available in the me-central1 region (Doha).

Google Kubernetes Engine

The me-central1 region in Doha, Qatar is now available.

Secret Manager

Secret Manager is now available in the following region:

  • me-central1

For more information, see Secret Manager locations.

Virtual Private Cloud

For auto mode VPC networks, added a new subnet 10.212.0.0/20 for the Doha me-central1 region. For more information, see Auto mode IP ranges.

reCAPTCHA Enterprise

reCAPTCHA Enterprise Mobile SDK v18.1.2 is now available for iOS.

This version contains the following changes:

  • Fix for the memory corruption bug.
  • Refinement of fix for the bug affecting execute() on the devices running iOS 11, 12 and 13.
  • Returns network error instead of internal error in cases where the network is extremely slow, but not doesn't fail by the timeout.

March 29, 2023

AlloyDB for PostgreSQL

AlloyDB Omni is available in Preview. AlloyDB Omni is a downloadable edition of AlloyDB for PostgreSQL that lets you run a containerized AlloyDB database engine in your own computing environment.

Artifact Registry

Artifact Registry is now available in the europe-west12 region (Turin, Italy).

BigQuery

Compute (analysis) is now generally available (GA) in three new BigQuery editions: Standard, Enterprise, and Enterprise Plus. These editions support the slots autoscaling model to meet your organizations' needs and budgets.

Autoscaling slots are now generally available (GA). Autoscaling slot reservations and commitments created during the feature's preview have been set to BigQuery Enterprise edition.

Chronicle

The following supported default parsers have changed. Each is listed by product name and ingestion label, if applicable.

  • Area1 Security (AREA1)
  • AWS Security Hub (AWS_SECURITY_HUB)
  • Azure AD (AZURE_AD)
  • Carbon Black (CB_EDR)
  • Cisco ASA (CISCO_ASA_FIREWALL)
  • Cisco Switch (CISCO_SWITCH)
  • Cloud Audit Logs (N/A)
  • CrowdStrike Falcon (CS_EDR)
  • Darktrace (DARKTRACE)
  • Elastic Windows Event Log Beats (ELASTIC_WINLOGBEAT)
  • Google Chrome Browser Cloud Management (CBCM) (N/A)
  • Hashicorp Vault (HASHICORP)
  • Illumio Core (ILLUMIO_CORE)
  • Linux Auditing System (AuditD) (AUDITD)
  • ManageEngine ADAudit Plus (ADAUDIT_PLUS)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Netskope (NETSKOPE_ALERT)
  • Office 365 (OFFICE_365)
  • Okta (OKTA)
  • Palo Alto Networks Firewall (PAN_FIREWALL)
  • Seqrite Endpoint Security (EPS) (SEQRITE_ENDPOINT)
  • STIX Threat Intelligence (STIX)
  • Trend Micro Vision One (TRENDMICRO_VISION_ONE)
  • Unix system (NIX_SYSTEM)
  • VMware vRealize Suite (VMWARE_VREALIZE)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • Workspace Alerts (WORKSPACE_ALERTS)
  • ZScaler NGFW (ZSCALER_FIREWALL)

For details about changes in each parser, see Supported default parsers.

Cloud Data Fusion

In Cloud Data Fusion version 6.8.1, Dataproc clusters no longer require the following OAUTH scope to function: https://www.googleapis.com/auth/cloud-platform.

Cloud Data Loss Prevention

The legacy version of the STREET_ADDRESS infoType detection model will stay available until further notice. Previously, this legacy model was scheduled to be removed on 19 June 2023.

Cloud Healthcare API

FHIR search results are limited by the response size. For more information, see Pagination and sorting and Including additional resources in search results.

Cloud Logging

When you create a log view and use the source() function in your filter, the argument to the function is now validated to ensure that it is a single string representing a project, folder, billing account or organization.

Cloud SQL for PostgreSQL

The rollout of the following PostgreSQL minor versions, extension versions, and plugin versions is currently underway:

Minor versions

  • 10.21 is upgraded to 10.22.
  • 11.16 is upgraded to 11.17.
  • 12.11 is upgraded to 12.12.
  • 13.7 is upgraded to 13.8.
  • 14.4 is upgraded to 14.5.

Extension and plugin versions

  • plv8 is upgraded from 3.1.2 to 3.1.4.
  • wal2json is upgraded from 2.3 to 2.4.
  • pgTAP is upgraded from 1.1.0 to 1.2.0.
  • PostGIS is upgraded from 3.1.4 to 3.1.7.
  • pg_partman is upgraded from 4.5.1 to 4.7.0.
  • pg_wait_sampling is upgraded from 1.1.3 to 1.1.4.
  • pg_hint_plan is upgraded from 1.3.7 to 1.4.
  • pglogical is upgraded from 2.4.1 to 2.4.2.

If you use a maintenance window, then the updates to the minor, extension, and plugin versions happen according to the timeframe that you set in the window. Otherwise, the updates occur within the next few weeks.

The new maintenance version is [PostgreSQL version].R20230316.02_02. To learn how to check your maintenance version, see Self service maintenance. To find your maintenance window or to manage maintenance updates, see Find and set maintenance windows.

Cloud Workstations

Cloud Workstations is available in the following regions:

  • asia-south1 (India)
  • us-east4 (Virginia, North America)

For more information, see Locations.

Dataflow

The Dataflow VM image has been updated to include mitigations for multiple vulnerabilities by upgrading to cos-97-16919-235-30. For the full list of mitigations, see the Container-Optimized OS release notes.

Dataflow jobs started on or after March 29, 2023 will run VM instances that use this image.

Document AI Warehouse

Allow users to upload and view TIFF file types in the UI.

Firestore

Firestore no longer limits the number of writes that can be passed to a Commit operation or performed in a transaction. Previously, the limit was 500. Limits for request size and the transaction time limit still apply.

Firestore in Datastore mode

Firestore in Datastore mode no longer limits the number of entities that can be passed to a Commit operation. Previously, the limit was 500. The limit for request size still applies.

Google Kubernetes Engine

Starting from GKE 1.26, cluster autoscaler can drain Pods from multiple nodes in parallel. The removal criteria are not changing, so the end state after scale down is going to be the same, but it will be achieved faster.

March 28, 2023

Anthos Service Mesh

The control_plane field in the service mesh fleet feature API (for example, gcloud container fleet mesh update --control-plane ...) is deprecated. Instead, use the management field. For more information, see Provision managed Anthos Service Mesh.

Anthos clusters on bare metal

Release 1.12.9

Anthos clusters on bare metal 1.12.9 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.12.9 runs on Kubernetes 1.23.

FIxes:

The following container image security vulnerabilities have been fixed:

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

Artifact Registry

Artifact Registry repositories with gcr.io domain support are now generally available. These repositories can host your existing Container Registry images and automatically redirect requests for gcr.io hosts to corresponding Artifact Registry repositories.

BigQuery

You can now use the tf_version training option to specify the Tensorflow (TF) version during model training. By default, tf_version is set as '1.15'. If you want to use TF2 with Keras API, you can add tf_version = '2.8.0' when creating the model.

You can now use the xgboost_version training option to specify the XGBoost version during model training. By default, xgboost_version is set as '0.9'. You can choose XGBoost version 1.1 by specifying xgboost_version = '1.1'.

You can now use the instance_weight_col training option to identify the column containing weights for each data point in the training dataset. Currently the instance_weight_col option is only available for boosted tree and random forest models with non-array feature types.

You can now import model artifacts saved in ONNX, XGBoost, and TensorFlow Lite formats into BigQuery for inference, allowing you to leverage models built in popular frameworks directly within the BigQuery ML inference engine.

You can also host models remotely on Vertex AI Prediction and do inference with BigQuery ML, removing the need to build data pipelines manually.

You can do inference with Google Cloud's state of the art pretrained models using Cloud AI service table-valued functions (TVFs) to get insights from your data. The TVFs work with Cloud Vision API, Cloud Natural Language API and Cloud Translation API.

These features are in preview. To enroll to use this feature, complete the enrollment form.

Cloud Healthcare API

A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.

Cloud SQL for MySQL

The changes in the September 15, 2022 Release Notes entry for read replica maintenance are now available. Cloud SQL read replicas follow the maintenance settings for the primary instance, including the maintenance window, rescheduling, and the deny maintenance period. During the maintenance event, Cloud SQL maintains the replicas before maintaining the primary instance. For more information, see How does maintenance affect read replicas?

Cloud SQL for PostgreSQL

The changes in the September 15, 2022 Release Notes entry for read replica maintenance are now available. Cloud SQL read replicas follow the maintenance settings for the primary instance, including the maintenance window, rescheduling, and the deny maintenance period. During the maintenance event, Cloud SQL maintains the replicas before maintaining the primary instance. For more information, see How does maintenance affect read replicas?

Cloud SQL for SQL Server

The changes in the September 15, 2022 Release Notes entry for read replica maintenance are now available. Cloud SQL read replicas follow the maintenance settings for the primary instance, including the maintenance window, rescheduling, and the deny maintenance period. During the maintenance event, Cloud SQL maintains the replicas before maintaining the primary instance. For more information, see How does maintenance affect read replicas?

Cloud SQL now exposes 38 new metrics. These metrics improve observability of Cloud SQL for SQL Server instances, helping you investigate performance issues and resource bottlenecks. You can find these metrics in the Metrics explorer within the Monitoring dashboard.

For more information about these metrics, see Cloud SQL Metrics.

Compute Engine

Generally Available: You can test how workloads running on sole-tenant nodes behave during a host maintenance event, and see the effects of the sole-tenant VM's host maintenance policy on the applications running on the VMs.

For more information, see Simulate host maintenance events on sole-tenant nodes.

Confidential VM

Confidential Space is now generally available.

Confidential Space is designed to let parties share sensitive data with a mutually agreed upon workload, while they retain confidentiality and ownership of that data. Such data might include personally identifiable information (PII), protected health information (PHI), intellectual property, cryptographic secrets, and more. Confidential Space helps create isolation so that data is only visible to the workload and the original owners of the data.

Config Controller

Config Controller now uses the following versions of its included products:

Dataflow

Vertical Autoscaling now supports batch jobs.

Dataproc

New sub-minor versions of Dataproc images:

  • 1.5.87-debian10, 1.5.87-rocky8, 1.5.87-ubuntu18
  • 2.0.61-debian10, 2.0.61-rocky8, 2.0.61-ubuntu18
  • 2.1.9-debian11, 2.1.9-rocky8, 2.1.9-ubuntu20

Dataproc cluster creation now supports the pd-extreme disk type.

Dataproc on GKE now disallows update operations.

Dataproc on GKE diagnose operation now verifies that the master agent is running.

Document AI Warehouse

BigQuery Connector (preview): Supports batch exports of document metadata into BigQuery, which enables users to do data analysis, create reports and dashboards. For example, data visualization using BI dashboards.

Eventarc

Eventarc support for creating triggers for direct events from Cloud Dataflow is available in Preview.

Identity Platform

Play Integrity is now supported for client-side authentication on Android applications. For more information, see Authenticate with Firebase on Android using a Phone Number.

Memorystore for Redis

Self-service maintenance is now Generally Available for Memorystore for Redis.

Migrate to Containers

On March 27, 2022 we released version 1.1.0 of the Migrate to Containers modernization plugins.

Learn how to Upgrade Migrate to Containers plugins.

Preview: Added support for refactoring WordPress Servers running on Apache2 Linux to containers, which lets you deploy WordPress sites as containers on GKE, GKE Autopilot clusters, Anthos clusters, and Cloud Run.

For more information, see Migrate a WordPress site.

Introduced the following features for JBoss migration:

  • Support for JBoss versions has been extended and Migrate to Containers now supports migration of JBoss EAP versions 7.0 - 7.4 to equivalent Wildfly community based container images, besides migrations of Wildfly versions 8.1.0 - 26.1.1.
  • Secrets are now automatically created from extracted security realms configuration and key-stores. This new feature fixes potential security risks and lets you update secrets without having to recreate images.
  • The targetImageHome property has been added to the migration plan to allow users to specify an alternative container image with a different JBOSS_HOME location.
  • The ExcludeFiles property has been added to the migration plan, which lets you explicitly exclude files and directories from the container image.
  • The data migration feature now automates the creation and mounting of a Persistent Volume Claim (PVC) for the $JBOSS_HOME/standalone/data directory. This directory is available for use by services that require storing content in the file system.

Filtering out files located at /tmp when discovering Tomcat application dependencies.

Docker images may contain broken symlinks. Ensure that the tar archive artifacts added to dockerfile don't contain symlinks that don't resolve to another file in the archive. If they do, either retrieve the files from the source VM and add them to the dockerfile manually, or replace the symlinks in the source VM and perform extraction again.

SAP on Google Cloud

Update from SUSE for the Python hook scripts in SAPHanaSR

According to SUSE's recently updated guidance, all Python hook scripts should be used directly from the SAPHanaSR package. If the scripts are moved or copied to another directory, then the regular SUSE package update will not keep those copies updated.

To align with this update from SUSE, make sure to use the scripts directly from the SAPHanaSR package location. Also, Google Cloud has done the following:

  • Published the Terraform module version 202303280902 and Deployment Manager template version 202303280902, which use the hook scripts directly from the SAPHanaSR package.
  • Updated the guidance to enable the SAP HANA HA/DR provider hook in the manual SAP HANA HA deployment guide for SLES.

For information from SUSE, see Setting up HANA HA/DR providers.

Vertex AI

Vertex AI Pipelines cost showback with billing labels is now generally available (GA). You can now use billing labels to review the cost of a pipeline run, along with the cost of individual resources generated from Google Cloud Pipeline Components in the pipeline run. For more information, see Understand pipeline run costs.

March 27, 2023

Apigee hybrid

hybrid 1.9.1

On March 27, 2023 we released an updated version of the Apigee hybrid software, 1.9.1.

Bug ID Description
269738951 The example network policies are now included in the apigeectl/examples/network-policies directory. see Configuring Kubernetes network policies.
271266079 Removed port 80 from the default Kubernetes service of Apigee Ingress Gateway.
270371160 In Apigee hybrid v1.9.0, we removed certain insecure TLS ciphers. Apigee hybrid supports the TLS cipher suites supported by the Boring FIPS build of Envoy. You can now specify specific cipher suites with the virtualhosts.cipherSuites configuration property in your overrides.
269451743 In certain circumstances, upgrading from Apigee hybrid v1.8.3 to v1.9.0 could fail with an error message when creating the virtual hosts.
268696297 Providing a Kubernetes secret for Cassandra and Redis components is now supported. See cassandra.auth.secret and redis.auth.secret in the Configuration properties reference.
267691299 The Apigee controller uses a dedicated apigee-manager Kubernetes service account, instead of using the default SA.
267666187 When using a custom Kubernetes service for the Apigee ingress gateway, you can disable the creation of a default load balancer. See Managing Apigee ingress gateway.
266989915
266919136
In some circumstances, Apigee could return incorrect developer credentials for an app, unless the specific app was selected when requesting the credentials.
266814873 In certain circumstances, retrieving encrypted KVM entries could fail with an error. This fix ensures that MART will be able to successfully function for environment-scoped KVM entries, even if the encryption key is used in the Org Env configuration or when the keys contain non-UTF8 characters. There is no change to KVM data.
266594584 Websocket was failing in asm 1.15. This was due to incompatible capitalization in variable names between the Anthos Service Mesh overlay.yaml file and the and the Envoy filter apigee-envoyfilter.yaml file.
266411394 Added support for Azure Front Door request headers to /healthz health check.
265374889 Fixed an issue where in some circumstances the Java Callout would to fail due with the following error: Failed to execute JavaCallout. Could not initialize class org.jose4j.jwa.AlgorithmFactoryFactory2.
260342163 Fixed a narrow scenario where threads in runtime pods ended up consuming 100% CPU.
245619397 In Apigee hybrid, fluentbit support now includes the NO_PROXY environment variable.
Bug ID Description
275002360 Security fixes for fluent-bit.
This addresses the following vulnerabilities:
274112103 **Security fixes to the Apigee Controller and Apigee Watcher. This addresses the following vulnerabilities:
BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Node.js

Changes for @google-cloud/bigquery

6.2.0 (2023-03-22)

Features
Bug Fixes

Java

Changes for google-cloud-bigquery

2.24.3 (2023-03-24)

Dependencies
  • Update actions/checkout action to v3.5.0 (#2600) (f38d9f1)

2.24.2 (2023-03-22)

Dependencies
  • Update github/codeql-action action to v2.2.8 (#2593) (d306ad8)

2.24.1 (2023-03-21)

Dependencies
  • Update cloud client dependencies (7b07779)
  • Update dependency com.google.cloud:google-cloud-bigquery to v2.23.2 (7b07779)
  • Update dependency com.google.cloud:google-cloud-bigquery to v2.24.0 (7b07779)
  • Update dependency com.google.cloud:google-cloud-bigquerystorage-bom to v2.34.1 (7b07779)
  • Update dependency com.google.cloud:google-cloud-bigtable to v2.20.1 (7b07779)
  • Update dependency com.google.cloud:libraries-bom to v26.10.0 (7b07779)

2.24.0 (2023-03-21)

Features
Dependencies
  • Update actions/checkout action to v3.4.0 (#2575) (6935a1e)
  • Update actions/upload-artifact action to v3.1.2 (#2571) (aa0c70e)
  • Update cloud client dependencies (#2583) (dcacc31)
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.15.0 (#2577) (eaf09d6)
  • Update dependency com.google.apis:google-api-services-bigquery to v2-rev20230311-2.0.0 (#2578) (aab037c)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.5.0 (#2580) (1764eeb)
  • Update dependency com.google.cloud:google-cloud-storage to v2.20.0 (#2559) (8a854db)
  • Update github/codeql-action action to v2.2.7 (#2572) (105f5ee)

BigQuery now supports change data capture (CDC) by processing and applying streamed changes in real-time to existing data using the BigQuery Storage Write API. This feature is in preview.

Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigtable

2.20.1 (2023-03-21)

Bug Fixes
  • If new_partitions is size 0, do not enforce size check (#1673) (07bcfd9)
Dependencies
  • Update dependency com.google.cloud:google-cloud-monitoring-bom to v3.14.0 (#1668) (06f9615)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.5.0 (#1670) (74cebf3)
Cloud Composer

Cloud Composer 2 now supports access with external identities through workforce identity federation.

Fixed a problem where upgrade checks were failing for some Cloud Composer 2 environments. This issue was affecting environments where Cloud Build can't be used to install PyPI packages.

The default value for the dag_dir_list_interval Airflow configuration option is changed from 30 to 120 seconds.

Increased the timeout for environment operations performed by Cloud Build to 35 minutes.

Cloud Composer 2.1.11 and 1.20.11 images are available:

  • composer-2.1.11-airflow-2.4.3 (default)
  • composer-2.1.11-airflow-2.3.4
  • composer-1.20.11-airflow-1.10.15
  • composer-1.20.11-airflow-2.4.3
  • composer-1.20.11-airflow-2.3.4
Cloud Functions

Cloud Functions has added support for a new runtime, Go 1.20, at the General Availability release level.

Cloud Healthcare API

The Cloud Healthcare API offers single-region support in the me-west1 (Tel Aviv, Israel) region.

Cloud Logging

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-logging

3.14.6 (2023-03-20)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.5.0 (#1301) (9fa6f05)

The Cloud Logging API now supports the following region:

  • Doha: me-central1
Cloud SQL for SQL Server

Cloud SQL now supports the Linked Servers functionality of SQL Server. You can use this capability to integrate data from multiple sources and distribute queries across multiple servers. To learn more, see About linked servers.

The Cloud SQL Active Directory (AD) Diagnosis tool helps you troubleshoot issues that you might face while connecting to AD-enabled Cloud SQL for SQL Server instances, using an on-premises AD domain.

Cloud Spanner

A monthly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-spanner

6.37.0 (2023-03-03)

Features
Bug Fixes
Dependencies
  • Update dependency com.google.api.grpc:proto-google-cloud-spanner-executor-v1 to v1.3.0 (#2306) (8372250)
  • Update dependency com.google.cloud:google-cloud-monitoring to v3.13.0 (#2311) (6ba613b)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.4.0 (#2312) (266c49c)
  • Update dependency com.google.cloud:google-cloud-trace to v2.12.0 (#2313) (e5f76c6)
  • Update dependency org.json:json to v20230227 (#2310) (badcc14)

6.38.0 (2023-03-20)

Features
  • Add option to wait on session pool creation (#2329) (ff17244)
  • Add PartitionedUpdate support to executor (#2228) (2c8ecf6)
Bug Fixes
  • Correct the proto field Id for field data_boost_enabled (#2328) (6159d7e)
  • Update executeCloudBatchDmlUpdates. (#2326) (27ef53c)
Dependencies
  • Update dependency com.google.cloud:google-cloud-monitoring to v3.14.0 (#2333) (9c81109)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.5.0 (#2335) (5eac2be)
  • Update dependency com.google.cloud:google-cloud-trace to v2.13.0 (#2334) (c461ba0)

Python

Changes for google-cloud-spanner

3.28.0 (2023-02-28)

Features
  • Enable "rest" transport in Python for services supporting numeric enums (#897) (c21a0d5)

3.29.0 (2023-03-23)

Features
  • Add new fields for Serverless analytics (#906) (2a5a636)
Bug Fixes
  • Correct the proto field ID for field data_boost_enabled (#915) (428aa1e)
Documentation
  • Fix formatting of request arg in docstring (#918) (c022bf8)
Cloud TPU

Cloud TPU now supports Tensorflow 2.12.0. For more information see the TensorFlow 2.12 release notes.

Confidential VM

Confidential Space. The assertion.swversion attestation assertion now verifies the Confidential Space image version number the workload is being run on, with the result returned as a list. Previously the assertion was used to determine whether the workload was running on a production or debug Confidential Space image, and the result was returned as an integer. You now determine if a production or debug image is being used with the assertion.dbgstat assertion.

Confidential Space. The assertion.submods.confidential_space.support_attributes assertion can be used to verify the support status of the Confidential Space image being used. It can be used, for example, to ensure that the workload is running on the latest version of the Confidential Space image.

Dataproc

New sub-minor versions of Dataproc images:

  • 1.5.86-debian10, 1.5.86-rocky8, 1.5.86-ubuntu18
  • 2.0.60-debian10, 2.0.60-rocky8, 2.0.60-ubuntu18
  • 2.1.8-debian11, 2.1.8-rocky8, 2.1.8-ubuntu20
Dataproc Metastore

Metadata federation now supports Dataplex lakes as a metadata source (in preview)

Dialogflow

Dialogflow CX now provides the TO_NUMBER system function.

Document AI

The Document AI OCR Processor (Doc OCR) now has the following features:

  • The OCR Processor supports language hints. The OCR engine prefers your specified languages over inferred languages. To use this feature, set process_options.ocr_config.hints.language_hints with a list of BCP-47 language codes in your API request to the OCR Processor.
  • The OCR Processor supports the option to populate symbol-level data in the document response. If enabled, the field document.pages.symbols is populated. To use this feature, set process_options.ocr_config.enable_symbol=true in your API request to the OCR Processor.
  • A proto converter tool that converts a Document proto to an AnnotateFileResponse proto. This conversion lets you compare the responses between the Document AI OCR processor with the Vision API, which can help you migrate to the Document AI OCR processor from Vision API with minimal downstream changes. For details, see Document AI Toolbox.
  • The OCR Processor supports a heuristics layout detection algorithm, which serves as an alternative to the current ML-based layout detection algorithm. You can choose the layout algorithm that best suits your needs. To use this feature, set process_options.ocr_config.advanced_ocr_options= legacy_layout in your API request to the OCR Processor.

For the Document AI OCR Processor (Doc OCR), you can enable document quality assessments for all processor versions instead of a specific processor version, such as pretrained-ocr-v1.1-2022-09-12. If you enable document quality assessment, Doc OCR produces a quality score that's based on the document's readability. Quality scores range from 0 to 1, where 1 is perfect quality. Quality scores are returned in the image_quality_scores field on the Page object. All detected issues are labeled as quality or defect and sorted in descending order by confidence value. To use this feature, set process_options.ocr_config.enable_image_quality_scores= true in your API request to the OCR Processor.

Google Distributed Cloud Edge

This is a patch release of Google Distributed Cloud Edge (version 1.3.1).

The following changes have been introduced in this release of Distributed Cloud Edge:

  • The Kubernetes control plane has been updated to version 1.24.9-gke.2500.
  • The Kubernetes container daemon (containerd) has been updated to version 1.6.6-gke.1.
  • The Kubernetes worker node agent (kubelet) has been updated to version 1.24.7-gke.5.

The following issues have been resolved in this release of Distributed Cloud Edge:

  • Errors in the NodeSystemConfigUpdate custom resource definition that shipped with Distributed Cloud Edge 1.3.0 have been corrected. The outputs of the affected status fields are now accurate.

This release of Distributed Cloud Edge contains the following known issues:

  • If you have enabled the Anthos VM Runtime virtual machine subsystem, disabling it removes the network-controller-manager service and its container. This renders Distributed Cloud Edge networking inoperable. To prevent this, keep the Anthos VM Runtime virtual machine subsystem enabled on your Distributed Cloud Edge deployment. If the subsystem has been disabled, re-enable it by following the steps in Enable the Anthos VM Runtime support on Distributed Cloud Edge to restore Distributed Cloud Edge networking to an operable state.
Network Intelligence Center

Network Topology now supports TCP and UDP traffic for certain traffic paths. For more information, see Network Topology overview.

Pub/Sub

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for pubsub/apiv1

1.30.0 (2023-03-22)

Features
  • pubsub: Update iam and longrunning deps (91a1f78)
Bug Fixes
  • pubsub: Check response of receipt modacks for exactly once delivery (#7568) (94d0408)

Java

Changes for google-cloud-pubsub

1.123.7 (2023-03-21)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.5.0 (#1532) (d63fba7)

Python

Changes for google-cloud-pubsub

2.15.2 (2023-03-20)

Documentation
SAP on Google Cloud

Google Cloud's Agent for SAP version 1.2

Version 1.2 of the Google Cloud's Agent for SAP is now available. This version includes bug fixes and supportability enhancements.

For more information, see What's new with Google Cloud's Agent for SAP.

VPC Service Controls

Preview stage support for the following integration:

Vertex AI Workbench

M105 Release

The M105 release of Vertex AI Workbench managed notebooks includes the following:

  • Fixed an issue wherein a runtime with idle shutdown enabled doesn't detect activity and shuts down.
  • Fixed an issue wherein the runtime data disk runs out of space and prevents access.
  • Fixed an issue wherein end user credentials are not preserved after shutdown.
  • Changed Health Agent logging levels from DEBUG to INFO.

March 24, 2023

Access Approval

Access Approval supports Certificate Authority Service in the GA stage.

Access Approval supports Firestore in the Preview stage.

Access Transparency

Access Transparency supports Certificate Authority Service in the GA stage.

Anthos clusters on bare metal

Release 1.14.3

Anthos clusters on bare metal 1.14.3 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.14.3 runs on Kubernetes 1.25.

Fixes:

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

App Engine flexible environment .NET

You can now use ssh to log in to App Engine flexible environment instances that use only internal IP addresses.

App Engine flexible environment Go

You can now use ssh to log in to App Engine flexible environment instances that use only internal IP addresses.

App Engine flexible environment Java

You can now use ssh to log in to App Engine flexible environment instances that use only internal IP addresses.

App Engine flexible environment Node.js

You can now use ssh to log in to App Engine flexible environment instances that use only internal IP addresses.

App Engine flexible environment PHP

You can now use ssh to log in to App Engine flexible environment instances that use only internal IP addresses.

App Engine flexible environment Python

You can now use ssh to log in to App Engine flexible environment instances that use only internal IP addresses.

App Engine flexible environment Ruby

You can now use ssh to log in to App Engine flexible environment instances that use only internal IP addresses.

App Engine flexible environment custom runtimes

You can now use ssh to log in to App Engine flexible environment instances that use only internal IP addresses.

App Engine standard environment Go

The Go 1.20 runtime for App Engine standard environment is now generally available.

Backup and DR

Backup and DR Service release 11.0.4.568 is now available. This release includes:

Backup and DR Service now supports archive snapshots for Compute Engine instance backups.

Simplified experience for updating backup/recovery appliances from the management console.

Cloud Key Management Service

Cloud EKM now supports coordinated external keys.

Coordinated external keys let you create and manage keys in a compatible external key management system from Cloud KMS over a VPC network. For more information, see EKM key management from Cloud KMS.

Thales CipherTrust Cloud Key Manager is the first external key management partner system that is compatible with EKM key management from Cloud KMS.

Cloud Monitoring

Google Cloud Managed Service for Prometheus: You can use the OpenTelemetry Collector to scrape standard Prometheus metrics and report them to Managed Service for Prometheus. For more information, see Get started with the OpenTelemetry Collector.

Cloud TPU

Cloud TPUs now support the PyTorch 2.0 release, via PyTorch/XLA integration. On top of the underlying improvements and bug fixes in PyTorch's 2.0 release, this release introduces several features, and PyTorch/XLA specific bug fixes.

Beta Features

PJRT runtime

  • Checkout our newest document; PjRt is the default runtime in 2.0.
  • New Implementation of xm.rendezvous with XLA collective communication which scales better (#4181)
  • New PJRT TPU backend through the C-API (#4077)
  • Use PJRT to default if no runtime is configured (#4599)
  • Experimental support for torch.distributed and DDP on TPU v2 and v3 (#4520)

FSDP

  • Add auto_wrap_policy into XLA FSDP for automatic wrapping (#4318)

Stable Features

Lazy Tensor Core Migration

  • Migration is completed, checkout this dev discussion for more detail.
  • Naively inherits LazyTensor (#4271)
  • Adopt even more LazyTensor interfaces (#4317)
  • Introduce XLAGraphExecutor (#4270)
  • Inherits LazyGraphExecutor (#4296)
  • Adopt more LazyGraphExecutor virtual interfaces (#4314)
  • Rollback to use xla::Shape instead of torch::lazy::Shape (#4111)
  • Use TORCH_LAZY_COUNTER/METRIC (#4208)

Improvements & Additions

  • Add an option to increase the worker thread efficiency for data loading (#4727)
  • Improve numerical stability of torch.sigmoid (#4311)
  • Add an api to clear counter and metrics (#4109)
  • Add met.short_metrics_report to display more concise metrics report (#4148)
  • Document environment variables (#4273)
  • Op Lowering
    • _linalg_svd (#4537)
    • Upsample_bilinear2d with scale (#4464)

Experimental Features

TorchDynamo (torch.compile) support

  • Checkout our newest doc.
  • Dynamo bridge python binding (#4119)
  • Dynamo bridge backend implementation (#4523)
  • Training optimization: make execution async (#4425)
  • Training optimization: reduce graph execution per step (#4523)

PyTorch/XLA GSPMD on single host

  • Preserve parameter sharding with sharded data placeholder (#4721)
  • Transfer shards from server to host (#4508)
  • Store the sharding annotation within XLATensor(#4390)
  • Use d2d replication for more efficient input sharding (#4336)
  • Mesh to support custom device order. (#4162)
  • Introduce virtual SPMD device to avoid unpartitioned data transfer (#4091)

Ongoing development

  • Ongoing Dynamic Shape implementation
    • Implement missing XLASymNodeImpl::Sub (#4551)
    • Make empty_symint support dynamism. (#4550)
    • Add dynamic shape support to SigmoidBackward (#4322)
    • Add a forward pass NN model with dynamism test (#4256)
  • Ongoing SPMD multi host execution (#4573)

Bug fixes & improvements

  • Support int as index type (#4602)
  • Only alias inputs and outputs when force_ltc_sync == True (#4575)
  • Fix race condition between execution and buffer tear down on GPU when using bfc_allocator (#4542)
  • Release the GIL during TransferFromServer (#4504)
  • Fix type annotations in FSDP (#4371)
Data Catalog

Data Catalog is now available in Dallas (us-south1). For more information on region and feature availability, see regions.

Dataform

Workspace compilation overrides are available in Preview.

Dataproc

Upgrade Python to 3.11 and Conda to 23.1 in Dataproc Serverless for Spark runtime 2.1

Firestore

OR queries now available in Preview.

Firestore in Datastore mode

OR queries now available in Preview.

March 23, 2023

Anthos Config Management

Alpha release of AssignImage mutator, which allows mutation of Docker image paths. For reference, see AssignImage under Mutation in the OPA Gatekeeper documentation.

The constraint template library includes a new template: VerifyDeprecatedAPI. For reference, see the Constraint template library.

The constraint template library's K8sPodsRequireSecurityContext template now supports an exempt-list of Images using the new exemptImages parameter. For reference, see Constraint template library.

The constraint template library's K8sRequireCosNodeImage template now supports an exempt-list of OS images using the new exemptOsImages parameter. For reference, see Constraint template library.

Policy Controller has been updated to include a more recent build of OPA Gatekeeper (hash: 8170c5f).

Stopped exposing the "unable to load /repo/source/error.json" transient error in the RootSync and RepoSync API.

Fixed an issue in the nomos CLI so that it works for standalone Config Sync.

Fixed an issue causing a Kubernetes Service object not syncing without the .spec.ports field being specified.

Fixed an issue of accidental deletion of resources caused by a race condition between *-sync, hydration-controller and reconciler containers.

Anthos Service Mesh

In April 2023, enabling mesh.googleapis.com will automatically enable trafficdirector.googleapis.com, networkservices.googleapis.com, and networksecurity.googleapis.com. These APIs will be required for managed Anthos Service Mesh. You will be able to safely disable them on a project or fleet that has no managed Anthos Service Mesh clusters.

Configuring Certificate Authority connectivity through a HTTP CONNECT-based proxy is now generally available (GA). For more information, see Configure Certificate Authority connectivity through a proxy.

Apigee Integrated Portal

On March 23, 2023 we released an updated version of Apigee integrated portal.

Users are now able to enable the content security policy feature for their portal for Apigee and Apigee hybrid. Previously, this feature was available in Apigee Edge only.

See: Configure a content security policy

Bug ID Description
272794133 When setting a user account to Inactive, a notice is now displayed indicating that this setting affects the login behavior only for built-in identity provider accounts.
267502391 Improved error messages for invalid input to various endpoints.
265051231 Default assets (images) added to a newly created portal used to show up as size 0px x 0px. Now they show their proper size.
253037871 Users are now able to enable the content security policy feature for their portal for Apigee and Apigee hybrid. Previously, this feature was available in Apigee Edge only.
Apigee X

On March 23, 2023, we released an updated version of Apigee.

Public preview release of Advanced API Security abuse detection

Advanced API Security's new abuse detection feature lets you view security incidents involving your APIs. Abuse detection uses Google's machine learning algorithms to detect API traffic patterns that are a sign of malicious activity targeting your APIs.

Abuse detection includes two new types of detection rules powered by machine learning models:

  • Advanced Anomaly Detection: Detects unusual patterns of API traffic.
  • Advanced API scraper: Detects attempts to extract information from APIs for malicious purposes.

The two new detection rules, Advanced Anomaly Detection and Advanced API Scraper, are not available for organizations with VPC Service Controls. We are actively working to resolve this issue.

App Engine flexible environment Go

Go 1.18 and 1.19 are now generally available. These versions require you to specify an operating system version in your app.yaml. Learn more.

Artifact Registry

The immutable tags setting is now in Preview for Docker repositories. When tags are immutable, you cannot change the image digest that a tag references in the repository. You can configure this setting when you create a repository or change the setting on an existing repository.

Bare Metal Solution

You can now provision multiple storage volumes to attach to the existing servers in a single configuration request through Google Cloud console intake form.

Chronicle

The SentinelOne Alert feed has been enhanced to enable you to configure the feed to ingest both alerts and threats or only threats.

When the Is alert API subscribed checkbox is selected in the application, or when the isAlertApiSubscribed field is set to true in the API request, the feed will ingest both alerts and threats. When the checkbox is deselected, or the isAlertApiSubscribed field is set set to false in the API request, only threats are ingested. This configuration is available when creating a new feed. Existing feeds were enhanced in a previous release to ingest both alerts and threats.

Only configure the feed to ingest both alerts and threats if you have subscribed to alerts in SentinelOne. If you have not subscribed to alerts in SentinelOne, then configure the feed to ingest threats only.

Cloud Bigtable

Cloud Bigtable is now available in the europe-west12 (Turin) region. For more information, see Bigtable locations.

Cloud Interconnect

Dedicated Cloud Interconnect support is available in the following colocation facilities:

  • Telecom Italia Cebrosa Campus, Turin

For more information, see the Locations table.

Cloud Key Management Service

Cloud KMS is available in the following region:

  • europe-west12

For more information, see Cloud KMS locations.

Cloud Run

The following new region is now available: europe-west12.

Cloud SQL for MySQL

Cloud SQL for MySQL now supports minor version 8.0.32. To upgrade your existing instance to the new version, see Upgrade the database minor version.

Support for europe-west12 (Turin) region.

Cloud SQL for PostgreSQL

Support for europe-west12 (Turin) region.

Cloud SQL for SQL Server

Support for europe-west12 (Turin) region.

Cloud Spanner

You can create Cloud Spanner regional instances in Turin, Italy (europe-west12).

Cloud Storage

Cloud Storage is now available in Turin, Italy (europe-west12 region).

Objects smaller than 128KiB stored in buckets with Autoclass enabled are no longer managed by Autoclass.

  • Such objects are not subject to the Autoclass management fee and are statically set to Standard Storage.
  • Any such objects in Autoclass buckets that are currently stored in a different storage class are being transitioned to Standard Storage automatically and free of charge.
Cloud VPN

Cloud VPN is now available in region europe-west12 (Turin, Italy).

Pricing is available on the Cloud VPN pricing page.

Compute Engine

Generally available: Turin, Italy, Europe europe-west12-a,b,c has launched with E2, N2, N2D, and T2D VMs available in all three zones. See VM instance pricing for details.

Config Controller

Config Controller Autopilot is now Generally Available (GA). Get started here.

Dataflow

Dataflow is now available in Turin (europe-west12).

Dataproc

Dataproc is now available in the europe-west12 region (Turin).

Google Kubernetes Engine

The europe-west12 region in Turin, Italy is now available.

Recommender

The export to BigQuery feature now supports custom pricing and non-project scoped recommendations.

The global Recommender Viewer role is now available to get view access to all insights and recommendations available.

Secret Manager

Secret Manager is now available in the following region:

  • europe-west12

For more information, see Secret Manager locations.

Security Command Center

The March 20, 2023 release of the Google Cloud SCC content pack for sending Security Command Center data to Cortex XSOAR is generally available.

This version includes support for multiple Google Cloud organizations, bug fixes, and supportability improvements.

For information about downloading and installing the new content pack, see Upgrade the Google Cloud SCC content pack.

The version 3.0 release of the Google SCC App for QRadar, which lets you send Security Command Center data to QRadar v7.4.1FP2+, is generally available.

This version includes support for multiple Google Cloud organizations, bug fixes, and supportability improvements.

For information about downloading and installing the new application, see Upgrade the Google SCC app.

The version 3.0 release of the Google SCC App for ELK, which lets you send Security Command Center data to Elastic Stack, is generally available.

This version includes support for multiple Google Cloud organizations, bug fixes, and supportability improvements.

For information about downloading and installing the new application, see Upgrade the Docker container.

The version 2.0 release of the Google SCC Add-on For Splunk and the Google SCC App For Splunk, which let you send Security Command Center data to Splunk, is generally available.

This version includes support for multiple Google Cloud organizations, bug fixes, and supportability improvements.

For information about downloading and installing the new applications, see Upgrade Google SCC App for Splunk and Google SCC Add-on for Splunk.

VPC Service Controls

Preview stage support for the following integration:

Virtual Private Cloud

For auto mode VPC networks, added a new subnet 10.210.0.0/20 for the Turin europe-west12 region. For more information, see Auto mode IP ranges.

March 22, 2023

Apigee X

On March 22, we released an updated version of Apigee X.

Customize SSL certs for access routing when provisioning Apigee Pay-as-you-go organizations.

Users can now select existing self-managed SSL certs when customizing access routing during Apigee Pay-as-you-go provisioning. For more information, see Step 4: Customize access routing .

Receive Cloud console notifications when Pay-as-you-go provisioning completes.

While provisioning is in progress, users can navigate away from the Apigee provisioning page and monitor notifications in the Cloud console for updates when provisioning completes.

BigQuery

BigQuery now supports Unicode column naming using international character sets, alphanumeric and special characters. Existing columns can use these new capabilities using the RENAME command. This feature is now in preview.

Cloud Data Fusion

In Cloud Data Fusion versions 6.8.0 and 6.8.1, there's a known issue that may cause the following error: Unsupported program type: Spark. The first time a pipeline that only contains actions runs on a newly created or upgraded instance, it succeeds. However, following pipeline runs that also include sources or sinks may fail with this error. For updated settings, see Troubleshooting.

Cloud Interconnect

In addition to the existing values of 1440 and 1500, Cloud Interconnect now lets you configure your VLAN attachments with an MTU value of 1460. This configuration setting is available for all VLAN attachments for both Partner Interconnect and Dedicated Interconnect.

To minimize the risk of packet loss, Google recommends that you configure the same MTU value on your VPC network, on-premises routers, and associated VLAN attachments whenever possible.

The default MTU for VLAN attachments that you create for Cloud Interconnect is still 1440.

Dataplane v2 for Cloud Interconnect is fully available for customers using Dedicated Interconnect or Partner Interconnect in the following regions:

  • asia-east2 (Hong Kong)
  • asia-northeast3 (Seoul)

All new VLAN attachments that you create in these regions are automatically provisioned on Dataplane v2. Existing VLAN attachments for these regions can be migrated to Dataplane v2. You can migrate existing attachments yourself by re-creating the attachments, or you can request and schedule an assisted migration. Contact Google Cloud Support for assistance.

For the list of all regions that are Dataplane v2-enabled, see the Locations table (Dedicated Interconnect) or Supported service providers (Partner Interconnect).

Cloud Logging

Log buckets in the following regions can now be upgraded to use Log Analytics:

  • asia-northeast1
  • australia-southeast1
  • europe-west1
  • europe-west2
  • northamerica-northeast1
  • us-east1
  • us-west2

For more information, see Supported regions.

Document AI Warehouse

Policy Engine:

  • Modify RuleSet APIs logic to auto-populate RuleId field during create RuleSet call and allow Rules update using existing RuleId
  • Publish action messages by default will include Schema name, Document name, RuleSet name, Rule Id, Action Id and trigger type information.
Google Kubernetes Engine

(2023-R07) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters

The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.

No channel

  • The following control plane and node versions are now available:

  • The following control plane versions are no longer available:

    • 1.21.14-gke.14100
    • 1.22.17-gke.3100
    • 1.25.6-gke.200
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to 1.21.14-gke.14600 with this release.

  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to 1.22.17-gke.4000 with this release.

  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to 1.22.17-gke.4000 with this release.

  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to 1.25.6-gke.1000 with this release.

Stable channel

  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.22.17-gke.3100
    • 1.23.16-gke.1100
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to 1.22.17-gke.4000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to 1.23.16-gke.1400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to 1.23.16-gke.1400 with this release.

Regular channel

  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.21.14-gke.15800
    • 1.22.17-gke.4000
    • 1.23.16-gke.1100
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.14-gke.18100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.22.17-gke.5400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to 1.23.16-gke.2500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to 1.23.16-gke.2500 with this release.

Rapid channel

  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.21.14-gke.18100
    • 1.22.17-gke.4300
    • 1.24.10-gke.2300
    • 1.25.6-gke.200
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.14-gke.18800 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.22.17-gke.5400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to 1.23.16-gke.2500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.24.11-gke.1000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to 1.25.6-gke.1000 with this release.

(2023-R07) Version updates

  • The following control plane and node versions are now available:
  • The following control plane versions are no longer available:

    • 1.21.14-gke.14100
    • 1.22.17-gke.3100
    • 1.25.6-gke.200
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to 1.21.14-gke.14600 with this release.

  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to 1.22.17-gke.4000 with this release.

  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to 1.22.17-gke.4000 with this release.

  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to 1.25.6-gke.1000 with this release.

(2023-R07) Version updates

  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.22.17-gke.3100
    • 1.23.16-gke.1100
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to 1.22.17-gke.4000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to 1.23.16-gke.1400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to 1.23.16-gke.1400 with this release.

(2023-R07) Version updates

  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.21.14-gke.15800
    • 1.22.17-gke.4000
    • 1.23.16-gke.1100
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to 1.21.14-gke.18100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to 1.22.17-gke.5400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to 1.23.16-gke.2500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to 1.23.16-gke.2500 with this release.

(2023-R07) Version updates

  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.21.14-gke.18100
    • 1.22.17-gke.4300
    • 1.24.10-gke.2300
    • 1.25.6-gke.200
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to 1.21.14-gke.18800 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to 1.22.17-gke.5400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to 1.23.16-gke.2500 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to 1.24.11-gke.1000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to 1.25.6-gke.1000 with this release.
Vertex AI Vision

Model event management with Cloud Functions and Pub/Sub

The Vertex AI Vision event management feature lets you generate and send event notifications through Pub/Sub topics by:

  • Enabling supported models* to output to Cloud Function for data processing and events generation.
  • In-product support to send generated event to configured Pub/Sub topics.
  • An easy configuration of the event management system in the Vertex AI Vision Studio.

* GA event management is available for the following models:

  • Occupancy analytics pre-trained model
  • Vertex AI custom-trained models imported into a Vertex AI Vision application

For more information, see the Enable model event notification with Cloud Functions and Pub/Sub.

March 21, 2023

Anthos Service Mesh

With Envoy versions 1.22 and later, the default minimal TLS version for servers changed from 1.0 to 1.2. Therefore, for Anthos Service Mesh version 1.14 and later, the default minimum TLS version for gateway servers is 1.2. If you need to configure the minimal TLS version on an Anthos Service Mesh gateway server to be lower than 1.2, then you can configure the minProtocolVersion parameter.

In Anthos Service Mesh versions 1.9 and earlier, the server-side minimum TLS version for Anthos Service Mesh workloads was 1.0. In Anthos Service Mesh versions 1.10 and later, the server-side minimum TLS version for Anthos Service Mesh workloads is configured to be 1.2 to improve TLS security. For better security, Anthos Service Mesh does not support configuring the minimum workload TLS version to be lower than 1.2.

Anthos clusters on AWS (previous generation) will be deprecated as of April 1, 2023. Therefore, Anthos Service Mesh will not support Anthos clusters on AWS (previous generation) starting April 1, 2023. For more information, see the deprecation announcement.

Anthos clusters on bare metal

Release 1.13.6

Anthos clusters on bare metal 1.13.6 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.13.6 runs on Kubernetes 1.24.

Fixes:

The following container image security vulnerabilities have been fixed:

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

Cloud Data Loss Prevention

The STREET_ADDRESS infoType detection model that was previously only accessible by setting InfoType.version to latest has been promoted to be the default detection model for this infoType.

To use the new model, leave InfoType.version unset, or set it to latest or stable. To use the old detection model, set InfoType.version to legacy. You can continue to use the legacy model until 19 June 2023 (90 days from the time of this change).

Cloud Endpoints

As of March 21, 2023, the Cloud Endpoints Portal is no longer available. API traffic managed by Cloud Endpoints is not affected by this change. For more information, see Cloud Endpoints Portal deprecation.

Cloud Healthcare API

Viewing FHIR store metrics is generally available (GA).

Cloud Load Balancing

Network Load Balancing now supports user-specified weights on the backend service. This allows you to manage the backend load distribution of your load balancer and avoid overloading them.

For details, see:

This feature is in General Availability.

Cloud SQL for MySQL

The changes listed in the June 10 Release Notes entry for faster machine type changes have been postponed for Cloud SQL for MySQL.

Cloud SQL for PostgreSQL

Smaller read replicas are now available for Cloud SQL. Read replicas no longer require the same or more CPUs and RAM than their primary instances.

Cloud Spanner

The following functions and expressions have been added to the GoogleSQL dialect:

Compute Engine

Your automated processes might fail if they use API response data about your resource-based commitment quotas. For more information, see Known issues.

Dataform

Dataform in Preview is available in the following regions:

  • australia-southeast1
  • southamerica-east1
Dialogflow

Dialogflow CX sentiment analysis now supports all regions supported by Dialogflow CX and over 70 new languages.

Eventarc

Support for triggering a workflow within a service perimeter using VPC Service Controls is generally available (GA).

Google Cloud Armor

Preview mode is now Generally Available for advanced network DDoS protection, allowing you to receive all the logging and telemetry about the detected attack without enforcing the mitigation.

Google Kubernetes Engine

Starting on March 21, 2023, traffic to k8s.gcr.io will be redirected to registry.k8s.io, following the community announcement. This change will happen gradually to reduce disruption, and should be transparent to the majority of GKE clusters.

To check for edge cases, and mitigate a potential impact, follow the step-by-step guidance in k8s.gcr.io Redirect to registry.k8s.io - What You Need to Know.

Pub/Sub

Pub/Sub is now available in Turin, Italy (europe-west12).

Generally available: In projects protected by a service perimeter, and if using Eventarc to route events to Workflows destinations, you can create a new push subscription through Eventarc where the endpoint is set to a Workflows execution. To know more, see Set up a service perimeter using VPC Service Controls.

Vertex AI

Vertex AI supports running Explainable AI on certain types of BQML models when they are added to the Vertex AI Model Registry (GA). To learn more, see Explainable AI for BigQuery ML models.

Vertex AI Feature Store

The ability to delete feature values from an entity type is now generally available (GA). The following features are available:

Links to additional resources:

Video Stitcher API

Slates and CDN keys are now created using long-running operations.

Workflows

Support for triggering a workflow using Eventarc within a VPC Service Controls perimeter is generally available (GA).

March 20, 2023

BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for bigquery/storage/apiv1beta1

1.49.0 (2023-03-16)

Features
  • bigquery: Add support for storage billing model (#7510) (0132ca9), refs #6978
  • bigquery: Update iam and longrunning deps (91a1f78)

Python

Changes for google-cloud-bigquery

3.7.0 (2023-03-06)

Features
  • Add connection_properties and create_session to LoadJobConfig (#1509) (cd0aaa1)
  • Add default_query_job_config property and property setter to BigQuery client (#1511) (a23092c)
Documentation

The following AutoML Tables model features are now generally available:

  • Availability in additional regions.
  • CMEK support in available regions except multi-regions US and EU.
  • OPTIMIZATION_OBJECTIVE now accepts two additional options:
    • MAXIMIZE_PRECISION_AT_RECALL
    • MAXIMIZE_RECALL_AT_PRECISION
Certificate Authority Service

General Availability: You can create resources such as certificate authorities (CA) and certificate authority pools with X.509 name constraints. Name constraints on CA resources are enforced when issuing certificates, which lets you control which names are permitted or excluded.

For more information, see CA certificate name constraints.

Cloud Build

You now have the option to use default logs buckets stored within your own project in the same region as your build. You can enable this feature by setting the defaultLogsBucketBehavior option in your build config file. When you use this option, you gain more control over data residency. Using logs within your own project also allows you to fine-tune access permissions and object lifecycle settings for your build logs. This feature is generally available. For more information, see the Store and manage build logs page.

Cloud Data Fusion

Salesforce plugins version 1.4.4 is available in all supported Cloud Data Fusion versions with the following changes:

Cloud Spanner

You can now use Google Cloud tags to group and organize your Cloud Spanner instances, and to condition Identity and Access Management (IAM) policies based on whether an instance has a specific tag. For more information, see Control access and organize instances with tags.

Cloud Storage

The following US regions are now available for dual-region storage:

  • Los Angeles (us-west2)
  • Salt Lake City (us-west3)

The following EU regions are now available for dual-region storage:

  • Warsaw (europe-central2)
  • Madrid (europe-southwest1)
  • Frankfurt (europe-west3)
  • Milan (europe-west8)
  • Paris (europe-west9)
Cloud Workstations

Newly-created clusters write vm_assignments and disk_assignments platform logs to Cloud Logging, indicating when VM instances and persistent disks are allocated to a workstation.

Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Python

Changes for google-cloud-ndb

2.1.1 (2023-02-28)

Bug Fixes
  • Query options were not respecting use_cache (#873) (802d88d), closes #752
Documentation
  • Note that we support Python 3.11 in CONTRIBUTING file (#872) (982ee5f)
  • Use cached versions of Cloud objects.inv files (#863) (4471e2f), closes #862
Migrate to Containers

On March 20, 2022 we released Migrate to Containers 1.14.1.

Migrate to Containers now supports Workforce identity federation.

Documentation restructured to provide better visibility of high-level tasks.

Using Anthos for VMware processing clusters for containerisation of VMware sources is now deprecated and is planned to be supported till July 2023.

The following issues were fixed:

  • migctl setup uninstall failure - source snapshot is not deleted. This is happening when the corresponding source provider was already deleted.
  • Starting a migration from the UI page "Sources & Candidates" might get stuck on a "retrying" step.

The following are open issues:

  • migctl migration status sometimes prints an error message before the migration table. This message does not indicate a concrete problem and can be ignored.
  • The UI fails when performing "Processing Cluster Add" having Resource Location Org Policy. To overcome that the processing cluster installation should be done using migctl and the target region should be provided using --gcp-region.
  • Creation of multiple source providers at the same time might cause timeouts. If this happens, delete and recreate source provider objects that failed to be created.
  • Replicated VM deletion might hang depending on other object deletion. To prevent this from happening, delete the Migrate to Virtual Machines (M2VM) source after deleting the corresponding Migration objects. Otherwise, if this happens, delete the M2VM replications manually.
  • Generated Kubernetes deployment specifications might contain invalid (non-DNS1123 compliant) container names when such names appear in the source VM. To prevent this from happening, go over the migration plan before generating artifacts and change the names to be DNS1123 compliant.
Pub/Sub

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for pubsub/apiv1

1.29.0 (2023-03-13)

Features
  • pubsub: Add google.api.method.signature to update methods (aeb6fec)
  • pubsub: Add REST client (06a54a1)
  • pubsub: Add schema evolution methods and fields (ee41485)
  • pubsub: Add support for schema revisions (#7295) (369b16f)
  • pubsub: Add temporary_failed_ack_ids to ModifyAckDeadlineConfirmation (aeb6fec)
  • pubsub: Make INTERNAL a retryable error for Pull (aeb6fec)
Bug Fixes
  • pubsub/pstest: Fix panic on undelivered message (#7377) (98dd29d)
  • pubsub: Allow updating topic schema fields individually (#7362) (f09e059)
  • pubsub: Dont compare revision fields in schema config test (#7317) (e364f7a)
  • pubsub: Fix bug with AckWithResult with exactly once disabled (#7319) (c88fbdf)
  • pubsub: Pipe revision ID in name in DeleteSchemaRevision (#7519) (e211635)
Documentation
  • pubsub: Add x-ref for ordering messages docs: Clarify subscription expiration policy (aeb6fec)
  • pubsub: Clarify BigQueryConfig PERMISSION_DENIED state (aeb6fec)
  • pubsub: Clarify subscription description (aeb6fec)
  • pubsub: Mark revision_id in CommitSchemaRevisionRequest deprecated (2fef56f)
  • pubsub: Replacing HTML code with Markdown docs: Fix PullResponse description docs: Fix Pull description (aeb6fec)
  • pubsub: Update Pub/Sub topic retention limit from 7 days to 31 days (aeb6fec)

Java

Changes for google-cloud-pubsub

1.123.6 (2023-03-14)

Dependencies
  • Update dependency com.google.cloud:google-cloud-bigquery to v2.23.2 (#1512) (60e889e)

Python

Changes for google-cloud-pubsub

2.15.1 (2023-03-14)

Bug Fixes
  • Set x-goog-request-params for streaming pull request (#884) (0d247e6)
Vertex AI

Vertex AI Prediction

You can now use N2, N2D, C2, and C2D machine types to serve predictions.

Virtual Private Cloud reCAPTCHA Enterprise

reCAPTCHA WAF express protection is now available in Preview. For more information about this feature, see Features for integration with WAF service providers.

March 19, 2023

Cloud Vision API Product Search

Product Search legacy category migration

The legacy categories "apparel", "homegoods", and "toys" have been upgraded. See the December 5, 2022 release note for more information.

March 18, 2023

Cloud Composer

If your environment interacts with Google Ads, make sure to upgrade it to Cloud Composer version 2.1.10 and 1.20.10 (or later versions) before March 29, 2023.

On this date, the Google Ads API v11 is sunset. The google-ads version 20.0.0 communicates with the supported Google Ads API v12.

(Airflow 2.3.4 and 2.4.3 only) The Google Ads Python library (google-ads) package is updated to version 20.0.0.

(Airflow 2.3.4 and 2.4.3 only) The apache-airflow-providers-google package was upgraded to version 2023.3.14+composer. This version is based on the public version 8.9.0 with the following changes:

  • Use google-ads==20.0.0

The source code for the apache-airflow-providers-google package version 2023.3.14+composer is available on GitHub.

5 new Airflow metrics are now available in Cloud Monitoring. For more information, see Monitor environments with Cloud Monitoring.

Cloud Composer 2 environments no longer create airflow.cfg and env_var.jsonfiles in the environment's bucket.

(Composer 2 only) The instance_name field for Airflow Webservers in new environments is now by default set to the Composer Environment name.

(Airflow 2) The Airflow metadata database size metric now reports more accurate values after the data is deleted from the database.

Cloud Composer 2.1.10 and 1.20.10 images are available:

  • composer-2.1.10-airflow-2.4.3 (default)
  • composer-2.1.10-airflow-2.3.4
  • composer-1.20.10-airflow-1.10.15
  • composer-1.20.10-airflow-2.4.3
  • composer-1.20.10-airflow-2.3.4

Airflow 2.2.5 is no longer included in Cloud Composer images.

Cloud Composer versions 2.0.7 and 1.18.3 have reached their end of full support period.

March 17, 2023

Anthos clusters on VMware

Anthos clusters on VMware 1.13.6-gke.32 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.13.6-gke.32 runs on Kubernetes 1.24.10-gke.2200.

The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.14, 1.13, and 1.12.

  • Fixed an issue with Anthos Identity Service to better scale and handle concurrent authentication requests.

  • Fixed an issue where component-access-sa-key was missing in the admin-cluster-creds Secret after admin cluster upgrade.

Fixed the following vulnerabilities:

Apigee X

On March 17, we released an updated version of Apigee X (1-9-0-apigee-23).

With this release we removed certain insecure TLS ciphers for northbound traffic. You can find the full list of supported ciphers in the FIPS build of Envoy.

Bug ID Description
N/A Upgraded infrastructure and libraries.
Backup and DR

If you are in a region where Hyperdisk Extreme is available, then a mount as a new Compute Engine instance may fail unless you change the boot disk disktype away from Hyperdisk Extreme. This is because images cannot be created using Hyperdisk Extreme disks. In addition, the target instance requires 64 CPUs or more and each disk being created must be 64 GB or larger.

If you are in a region where Hyperdisk Extreme is available, then a mount to an existing Compute Engine instance may fail unless you change the disktype away from Hyperdisk Extreme. This is because the target instance requires 64 CPUs or more and the disk being created needs to be 64 GB or larger.

Bare Metal Solution

You can now use the interactive serial console to access your Bare Metal Solution servers. This feature is generally available (GA).

Cloud Billing

Starting from March 15, 2023, in your Billing BigQuery exports and all Cloud Billing reports in the Google Cloud console, the service description for Cloud Monitoring (formerly Stackdriver) has changed from Stackdriver Monitoring to Cloud Monitoring.

If you have BigQuery queries or visualizations that filter data based on the Cloud Monitoring service description, you must update those queries.

Cloud Functions

Cloud Functions has added support for customer-managed encryption keys for 2nd gen functions at the Preview release level.

Cloud Spanner

Support for the GoogleSQL-dialect THEN RETURN clause and the PostgreSQL-dialect RETURNING clause is now generally available. For more information, see THEN RETURN and RETURNING.

The following functions have been added to the GoogleSQL dialect:

Cloud Storage

Expanded Cloud Storage monitoring dashboards are now generally available (GA).

  • Available metrics include server and client error rates, write request counts, network ingress rates, and network egress rates.
  • Dashboards can be filtered by bucket location.
  • Dashboards are customizable, including the ability to set up alerts.
Cloud Workstations

Cloud Workstations is available in the following regions:

  • europe-west6 (Switzerland)
  • europe-west9 (France)

For more information, see Locations.

Compute Engine

End of life: On May 31, 2023, Ubuntu 18.04 LTS (Bionic) will reach end of life and the images deprecated on Google Cloud. If you use Ubuntu 18.04 LTS images in your project, review Ubuntu LTS end of life.

Dataproc Security Command Center

Virtual Machine Threat Detection, a built-in service of Security Command Center, launched the following detectors to Preview.

  • Defense Evasion: Unexpected kernel code modification
  • Defense Evasion: Unexpected kernel read-only data modification
  • Defense Evasion: Unexpected ftrace handler
  • Defense Evasion: Unexpected interrupt handler
  • Defense Evasion: Unexpected kernel modules
  • Defense Evasion: Unexpected kprobe handler
  • Defense Evasion: Unexpected processes in runqueue
  • Defense Evasion: Unexpected system call handler

These modules analyze runtime Linux kernel integrity to detect common evasion techniques used by malware.

The following attributes were added to the Finding object of the Security Command Center API.

  • cloudDlpInspection
  • cloudDlpDataProfile

The cloudDlpInspection attribute provides details about the results of a Cloud Data Loss Prevention (Cloud DLP) inspection job. The cloudDlpDataProfile attribute provides the name of a Cloud DLP data profile that is associated with a finding.

For more information, see the Security Command Center API documentation for the Finding object.

Event Threat Detection, a built-in service of Security Command Center Premium, has launched the Initial Access: Excessive Permission Denied Actions rule to General Availability. This rule detects events where a principal repeatedly triggers permission denied errors across multiple methods and services.

For more information about Event Threat Detection findings, see Event Threat Detection rules.

VPC Service Controls

Preview stage support for the following integration:

reCAPTCHA Enterprise

reCAPTCHA Enterprise for WAF integration with Fastly is now available in Preview. For more information, see Integrate with Fastly.

March 16, 2023

API Gateway

Fixed issue where API Gateway used the IP address of the Google Cloud Load Balancer (GCLB) (specifically the address of the forwarding rule) to validate IP-restricted API keys in requests proxied by a GCLB. API gateway now correctly validates IP-restricted API keys using the IP address of the client calling the GCLB.

Cloud Healthcare API

A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.

Dataproc

New sub-minor versions of Dataproc images:

  • 1.5.85-debian10, 1.5.85-rocky8, 1.5.85-ubuntu18
  • 2.0.59-debian10, 2.0.59-rocky8, 2.0.59-ubuntu18
  • 2.1.7-debian11, 2.1.7-rocky8, 2.1.7-ubuntu20
Deep Learning Containers

M104 Release

  • Added the following packages:
    • google-cloud-artifact-registry
    • google-cloud-bigquery-storage
    • google-cloud-language
    • keyring
    • keyrings.google-artifactregistry-auth
  • Fixed a bug in which curl could not find the right SSL certificate path by default.

TensorFlow Enterprise 2.1 has reached the end of its support period. See Version details.

Deep Learning VM Images

M104 Release

  • Added the following packages:
    • google-cloud-artifact-registry
    • google-cloud-bigquery-storage
    • google-cloud-language
    • keyring
    • keyrings.google-artifactregistry-auth
  • Fixed a bug in which curl could not find the right SSL certificate path by default.

TensorFlow Enterprise 2.1 has reached the end of its support period. See Version details.

Text-to-Speech

Cloud Text-to-Speech now offers Long Audio Synthesis. This new API can be used to synthesize texts longer than 5 KB. For more information about API usage using the command line, see Create long audio from text by using the command line.

Vertex AI Workbench

M104 Release

The M104 release of Vertex AI Workbench user-managed notebooks includes the following:

  • Fixed a regression in which jupyter-user metadata was ignored.
  • Enabled access to the Jupyter Gateway Client configuration by using the notebook-enable-gateway-client and gateway-client-url metadata tags.
  • Added the following packages:
    • google-cloud-artifact-registry
    • google-cloud-bigquery-storage
    • google-cloud-language
    • keyring
    • keyrings.google-artifactregistry-auth
  • Fixed a bug in which curl could not find the right SSL certificate path by default.

TensorFlow Enterprise 2.1 has reached the end of its support period. See Version details.

Workflows

Support for a Transcoder API connector is available in Preview.

reCAPTCHA Enterprise

reCAPTCHA Enterprise Mobile SDK v18.1.1 is now available for iOS.

This version contains the following changes:

  • Fixed the issue that generated multiple warnings when archiving apps.
  • Fixed an issue affecting execute() on iOS 11, 12, and 13.
  • Removed Protobuf as a dependency on CocoaPods.

March 15, 2023

App Engine flexible environment Python

Python 3.8, 3.9, 3.10, and 3.11 are now generally available. These versions require you to specify an operating system version in your app.yaml. Learn more.

Chronicle

The following supported default parsers have changed. Each is listed by product name and ingestion label, if applicable.

  • BloxOne Threat Defense (BLOXONE)
  • Carbon Black (CB_EDR)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco ISE (CISCO_ISE)
  • Cisco Meraki (CISCO_MERAKI)
  • CrowdStrike Falcon (CS_EDR)
  • Duo Administrator Logs (DUO_ADMIN)
  • Elastic Audit Beats (ELASTIC_AUDITBEAT)
  • Elastic Windows Event Log Beats (ELASTIC_WINLOGBEAT)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • FortiGate (FORTINET_FIREWALL)
  • Imperva CEF (IMPERVA_CEF)
  • Infoblox (INFOBLOX)
  • JAMF CMDB (JAMF)
  • Juniper (JUNIPER_FIREWALL)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Microsoft IIS (IIS)
  • Nyansa Events (NYANSA_EVENTS)
  • Office 365 (OFFICE_365)
  • Onfido (ONFIDO)
  • Palo Alto Networks Firewall (PAN_FIREWALL)
  • Samba SMBD (SMBD)
  • Sentinelone Alerts (SENTINELONE_ALERT)
  • SentinelOne EDR (SENTINEL_EDR)
  • SonicWall (SONIC_FIREWALL)
  • Symantec VIP Gateway (SYMANTEC_VIP)
  • Tanium Threat Response (TANIUM_THREAT_RESPONSE)
  • Unix system (NIX_SYSTEM)
  • VMware NSX (VMWARE_NSX)
  • Windows Defender ATP (WINDOWS_DEFENDER_ATP)
  • Workspace Activities (WORKSPACE_ACTIVITY)

For details about changes in each parser, see Supported default parsers.

Cloud Endpoints

The shutdown of the Cloud Endpoints Portal is approaching. On or after March 21, 2023, the Cloud Endpoints Portal will no longer be available. API traffic managed by Cloud Endpoints is not affected by this change. For more information, see Cloud Endpoints Portal deprecation.

Cloud Interconnect

Dataplane v2 for Cloud Interconnect is fully available for customers using Dedicated Interconnect or Partner Interconnect in the following regions:

  • asia-east1 (Taiwan)
  • asia-southeast1 (Singapore)

All new VLAN attachments that you create in these regions are automatically provisioned on Dataplane v2. Existing VLAN attachments for these regions can be migrated to Dataplane v2. You can migrate existing attachments yourself by re-creating the attachments, or you can request and schedule an assisted migration. Contact Google Cloud Support for assistance.

For the list of all regions that are Dataplane v2-enabled, see the Locations table (Dedicated Interconnect) or Supported service providers (Partner Interconnect).

March 14, 2023

BigQuery

The Lineage tab in the table properties page lets you track how your data moves and transforms through BigQuery. This feature is now generally available (GA).

Channel Services

All public SKU groups, including 8 Google Cloud Marketplace SKU groups are now available for repricing in the Partner Sales Console (PSC). You can can use the new SKU groups in repricing configurations to pass the granular margin to your customers. You can also view and download the list of SKUs in these SKU groups.

You can search for SKU groups by both name and ID.

Cloud Bigtable

When you restore a backup, if the destination cluster doesn't have enough nodes to store the new table, Cloud Bigtable returns a FAILED_PRECONDITON error message. Previously, a RESOURCE_EXHAUSTED error was returned.

Cloud Data Fusion

Oracle plugins version 1.8.6 is available in Cloud Data Fusion versions 6.7.1, 6.7.2, and 6.7.3. Oracle plugins version 1.9.2 is available in Cloud Data Fusion versions 6.8.0 and later. These plugin versions have the following changes:

For the Oracle Batch Source, fixed a backward compatibility issue. In plugin versions 1.8.3, 1.9.0, and earlier, Cloud Data Fusion maps the Oracle NUMBER data type with undefined precision and scale to CDAP decimal(38,0) , which can cause data loss due to rounding errors. In plugin versions 1.8.4, 1.8.5, and 1.9.1, the Oracle NUMBER data type with undefined precision and scale maps to the CDAP string data type by default, which preserves all decimal digits. In versions 1.8.6 and 1.9.2, the Oracle NUMBER data type with undefined precision and scale gets mapped to CDAP string by default and lets you edit the output schema to use the older mapping to decimal(38, 0) data type. For more information, see Oracle batch source plugin converts NUMBER to string (PLUGIN-1535 ).

Cloud Logging

The Logging Query Language now supports a built-in SEARCH function that you can use to find strings in your log data. The SEARCH function is in preview. For more information, see SEARCH function.

Cloud SQL for MySQL

Cloud SQL for MySQL now supports 106 new database flags. See supported flags for more information.

Contact Center AI Platform

The CCAIP integration with Kustomer now offers the following new custom enhancement options:

  • Call transfer information is now posted as a comment.
  • Administrators can now create custom fields from CCAIP.
  • Administrators can now create custom Account and Record fields by going to: Developer Settings > Custom fields for Account and Record. See the Kustomer documentation for details.

Salesforce multi-number lookup: You can now configure CCAIP to look up an account across multiple phone number fields in Salesforce. This makes it easier to connect different support sessions to a single account for consumers who have multiple phone numbers, such as mobile, home, or work numbers. Additionally, you can now assign all phone numbers to one account rather than having to set up separate contacts for each number. The Account Lookup section now offers the following settings:

  • Phone number lookup fields : This updated configuration enables you to select multiple phone numbers, such as mobile, account phone, account fax. You can then associate these numbers with the same account.
  • Phone number primary fields: This field enables you to select the phone number field to be used when you create a new CRM account.

For more information, see the Salesforce CRM documentation.

Dialogflow (DF) Wrap-up events are now captured as custom events. Every time a customer ends their session with a Virtual Agent for any reason (for example, consumer abandon, call failure), a new DF Wrap-up custom event is sent to the Dialogflow CX (for example, handled by VA). This enables the VA to react to the event and perform any desired session wrap-up process(es). For more inforation, see the Dialogflow documentation.

New data parameters for Virtual Task Assistant: Virtual Task Assistant now has the ability to send parameters, supports multiple languages, and includes a dedicated settings panel. Admins can now specify the data parameters that can be gathered and sent to Virtual Task Assistants, including the new dynamic parameter Agent Form. See the data parameters documentation for details.

Twinning: Twinning is a new feature that allows a primary extension (for example, web adapter) and a secondary extension (for example, mobile phone number) to operate as a single phone.

Twinning is ideal for support agents who are frequently on the go, since it allows them to forward support calls to their preferred phone number while also allowing them to handle calls at their desk using their web adapter. Another example is a front desk phone set up as the office's primary extension; you can use Twinning to forward those calls to a mobile phone.

For details, see the Twinning documentation

Agent Adapter Improvements:

  • Updated active state styling of the in-call buttons (for example, Mute and Hold) to provide agents with greater clarity when the buttons are in an active state.
  • The in-call button labels no longer update when you toggle between the active and inactive state. Mute and Hold no longer update to "Unmute" and "Pause" respectively.
  • Improved color contrast ratios of the following UI elements for better legibility:
    • The Logout button.
    • The Save & Close button during the Wrap-up phase.
    • The Wrap-up Exceeded informational text.
    • The tabs in the chat overview list.

Domain Based Access Control: You can configure CCAIP to restrict the set of domains able to frame the agent adapter and admin portal. This provides protection against clickjacking attacks.

An Admin can configure the domain allowlist by going to: Developer Settings > Domain Based Access Control. Configuration changes might take up to 1 minute to take effect.

Existing customers will have an empty allowlist by default. To enable this feature, the allowlist must be populated with each domain currently framing the agent adapter. Domains that are not configured will be blocked. New customers will have an allowlist containing the domain of the CCAIP instance itself to allow the agent adapter to be framed by the admin portal. Additional domains will be blocked from framing the agent adapter until they are configured in the allowlist.

See Domain based access control for details.

We resolved an issue in the Queue settings where the menu numbers on a queue continued to display even when the queue setting was set to Hide.

We resolved an issue where chat shortcuts were not appearing consistently in the Agent Adapter.

A new audio chime has been added to the Agent Adapter to indicate when an agent connects with a customer on a call. We also updated the existing audio chimes for these events:

  • Agent joins
  • Member joins
  • Call Disconnects
  • Member Leaves

DTMF Support Capability You can now select the DTMF checkbox during Virtual Task Assistant and Virtual Agent setup to ensure that DTMF tones are supported.

Custom CRM, Extended OAuth and nested parameter support: The following enhancements have been added to the Custom CRM integration offering:

  • Extended OAuth Authentication support.
  • Handling nested parameters in the API endpoints configuration.

Fixed an issue where the ringtone would sometimes not play in the preview dialer.

Co-browse disabled: We have disabled and removed references to Co-browse functionality while the feature undergoes internal review/approval.

MS Dynamics: Updated default user functionality and improved Virtual Agent record assignment: You can now assign a CRM Admin user as the default user for all CRM actions and events where no specific agent has been identified. After enabling this Default User option in Developer Settings, you can set the default user for all Customer Support Virtual Agent sessions as well. See the Virtual Agent documentation for details.

Google Cloud VMware Engine

Resource name translation will be required after April 2023.

For more information on resource name translation, see Resource Name Translation.

Identity Platform

Identity Platform has updated several quotas. View the updated quotas from Identity Toolkit API > Quotas on the APIs & Services page in the Google Cloud console.

Looker

Looker 23.4 release includes the following changes, features, and fixes.

Support for YAML LookML is scheduled to end in the latter part of June 2023. All YAML LookML projects will generate a warning to this effect upon project validation, and all instances of YAML LookML must be translated to New LookML by this date.

The unversioned Denodo dialect was deprecated in Looker as of January 31, 2023. Any queries run against it will return an error. The updated dialects (Denodo 7 or Denodo 8) continue to be supported. However, customers running Denodo 7 are encouraged to move to Denodo 8.

The New Users Page and New Groups Page Labs features are now generally available. These features add a host of performance improvements to the Users and Groups pages, including pagination options on the Groups page.

The download dashboard modal now allows CSV download without Chromium. If the user is an admin, a message about installing Chromium is displayed.

The Support Access page in the Admin panel now contains a link to an upgraded support access audit dashboard.

The Looker Studio Connector and Connected Sheets features are now available for all Looker-hosted instances, including those Looker-hosted on AWS and Azure. Previously, these features were available only for instances that were Looker-hosted on Google Cloud. A Looker admin must enable these features in the new BI Connectors Admin page.

The new logging feature allows Looker to collect metrics on the number of NFS read, write, open, and status operations.

The Performant Field Picker Labs feature offers more refined search options, which let users more quickly and efficiently search for fields in large Explore field pickers.

The Query Reload custom filter in the Automagic Heatmap now correctly maintains the rendered data after every refresh. Previously, Looker removed the custom filter when a user refreshed a query.

The grid visualization feature now correctly styles different column types using classic themes and contrasting colors.

The Create Connection and Edit Connection pages have received a design refresh for improved clarity and usability.

Distinct measure types such as count_distinct and sum_distinct now bring through their filter values when referenced in a number type measure.

When New LookML Runtime is enabled, fields of type: parameter are no longer automatically added to the SELECT statement of generated SQL queries. Any references to parameter type fields using Liquid will still apply to SQL queries.

Secure Web Proxy

Cloud Secure Web Proxy supports TLS inspection, which helps you intercept the TLS traffic, inspect the encrypted request, and enforce security policies. This feature is supported in Preview.

Virtual Private Cloud

Hybrid subnets are available in Preview. A hybrid subnet combines an on-premises subnet and a VPC subnet into a single logical subnet. You can migrate individual workloads and instances from the on-premises subnet to the VPC subnet over time without needing to change IP addresses.

March 13, 2023

Apigee API hub

On March 13, 2023 Apigee API hub released a new version of the software.

FieldSet artifacts that are attached to an API are now displayed in the API overview page.

Batch

In the Google Cloud console, the Job details page has been updated to include an Events tab, which lists the job's status events and contains a link to the job's logs.

To view the Events tab, follow the steps to describe a job using the console.

BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigquery

2.23.2 (2023-03-07)

Bug Fixes
  • External table definition parquet format options (#2535) (eb45973)
Documentation

You can now specify translation configurations in the BigQuery Interactive SQL Translator and use it to debug Batch SQL translator jobs. This feature is now in preview.

Cloud Composer

PyPI package installation is now possible in network setups with maximum transmission unit (MTU) of 1280 bytes or more. This issue was affecting environments where Cloud Build cannot be used to install PyPI packages.

Fixed the issue where BigQuery tasks in the deferrable mode failed when data lineage was enabled.

Cloud Composer 2.1.9 and 1.20.9 images are available:

  • composer-2.1.9-airflow-2.4.3 (default)
  • composer-2.1.9-airflow-2.3.4
  • composer-2.1.9-airflow-2.2.5
  • composer-1.20.9-airflow-1.10.15
  • composer-1.20.9-airflow-2.4.3
  • composer-1.20.9-airflow-2.3.4
  • composer-1.20.9-airflow-2.2.5

Cloud Composer versions 2.0.6 and 1.18.2 have reached their end of full support period.

Compute Engine

Generally available: Hyperdisk provides the fastest block storage for Compute Engine for your high-end, memory intensive workloads. Hyperdisk volumes are durable network storage devices that your VMs can access, similar to Persistent Disk. For more information, see About Hyperdisk.

Filestore Firestore

Support for the europe-west4 (Netherlands) region.

Firestore in Datastore mode

Support for the europe-west4 (Netherlands) region.

Identity and Access Management

Workforce identity federation now supports browser-based sign-in. The feature is generally available (GA). To use it, see Browser-based sign-in in Obtain short-lived tokens for workforce identity federation, or locate the Browser-based sign-in section in the configuration guide for your identity provider.

Pub/Sub

A weekly digest of client library updates from across the Cloud SDK.

Node.js

Changes for @google-cloud/pubsub

3.4.1 (2023-03-08)

Bug Fixes
  • Update minimum google-gax to avoid taffydb vulnerabilities (#1695) (11372e6)

3.4.0 (2023-03-06)

Features
  • Add google.api.method.signature to update methods (1e28405)
  • Add temporary_failed_ack_ids to ModifyAckDeadlineConfirmation (1e28405)
  • Make INTERNAL a retryable error for Pull (#1681) (1e28405)
Bug Fixes
  • Don't do multiple drains per publish() in message queues unless requested (#1691) (d9b3a63)

General availability: You can now update the schemas that you create in Pub/Sub. Before you do so, read the guidelines. The change is being rolled out in a phased manner over the rest of the week.

SAP on Google Cloud

New SAP HANA certification: Hyperdisk Extreme

For use with SAP HANA, SAP has now certified the Compute Engine disk — Hyperdisk Extreme.

Hyperdisks provide the fastest block storage for Compute Engine for your high-end, memory-intensive SAP HANA workloads. Hyperdisks are durable network storage devices that your VMs can access, similar to persistent disks. For more information, see:

SAP HANA: minimum sizes for persistent disks reduced

Baseline performance improvements for PD-SSD and PD-Balanced have allowed us to reduce the minimum PD size required for most Compute Engine VM types running SAP HANA. This enables you to optimize your SAP HANA workloads by reducing costs and releasing quota related to disk storage.

We have also updated our Terraform configurations for SAP HANA to use the reduced sizes.

For more information, see Minimum sizes for SSD-based persistent disks and Hyperdisks in the SAP HANA planning guide.

Disk related enhancements for automating SAP HANA deployments with Terraform

The Terraform configurations that Google Cloud provides for automating SAP HANA deployments, now support the following disk related enhancements:

  • Using the argument disk_type, you can now specify the default disk type that you want to deploy for your SAP volumes. This argument also supports Hyperdisk Extreme.
  • By default, all SAP volumes are now mounted on separate SSD-based persistent disks or Hyperdisks. Using the argument use_single_shared_data_log_disk, you can specify if you want to mount all SAP volumes on a single disk.
  • For scale-up deployments, using the argument include_backup_disk, you can now specify if you want to deploy a disk for the SAP HANA backup volume.

These enhancements are available when you automate the deployment of SAP HANA on Google Cloud with Terraform configurations that use the module version 202303130717 or later.

For more information, see the deployment guide for your scenario.

Google Cloud's Agent for SAP version 1.1

Version 1.1 of the Google Cloud's agent for SAP is now available. This version includes bug fixes and supportability improvements.

For more information, see What's new with Google Cloud's Agent for SAP.

Secret Manager

Support for aliases in Secret Manager is now generally available. You can use an alias to get and access a version using a resource path name. A given alias string can only be bound to a single version. You can, however, assign multiple aliases to a secret version.

March 11, 2023

Cloud Run

Cloud Run healthcheck probes now support container port configuration.

March 10, 2023

Access Approval

Access Approval supports Certificate Authority Service in the Preview stage.

BigQuery

The CREATE TABLE AS SELECT statement now lets you filter data from files in Amazon S3 and Azure Blob Storage before transferring results into BigQuery tables This feature is in preview.

Chronicle

The [all namespaces] menu item in Asset view will be removed on July 1, 2023. This change will not impact the ability to view and filter events assigned the default namespace, using the [untagged] menu item, or to view and filter events with custom namespace labels that were assigned to incoming logs.

Cloud Logging

Log-based metrics on log buckets are now generally available (GA). In addition to features available in the preview, the GA release includes the ability to create bucket-level log-based metrics in the Google Cloud console.

Starting with version 2.28.0, the Ops Agent limits the amount of disk space it can use to store buffer chunks. The Ops Agent creates buffer chunks when logging data can't be sent to the Logging API. Without a limit, these chunks might consume all available space, interrupting other services on the VM. When a network outage causes buffer chunks to be written to disk, the Ops Agent now uses a platform-specific amount of disk space to store the chunks.

Cloud Monitoring

You can now have Cloud Monitoring send an email that contains a dashboard URL to people or groups in your organization. For more information, see Share dashboards.

Dataform

Dataform in Preview is available in the following regions:

  • asia-south1
  • europe-west6
Dataproc

Upgraded Spark BigQuery connector version to 0.28.1 in 1.1 and 2.1 Dataproc Serverless for Spark runtimes.

Filestore Recommender

Cloud Functions minimum instances recommendations are now available in Preview.

VPC Service Controls

Preview stage support for the following integration:

Virtual Private Cloud

Connectivity to Private Service Connect endpoints used to access a managed service is supported over VLAN attachments for Cloud Interconnect. This feature is available in General Availability.

Consumption of IP addresses in Private Service Connect NAT subnets is improved for service attachments that are created after March 1st, 2023. For more information, see NAT subnets. This improvement is available in General Availability.

March 09, 2023

Anthos clusters on bare metal

Cluster lifecycle improvements 1.13.1 and later

Starting with Anthos clusters on bare metal release 1.13.1, you can use the Google Cloud console or the gcloud CLI to upgrade admin and user clusters managed by the Anthos On-Prem API. If your cluster is at version 1.13.0 or lower, you must use bmctl to upgrade the cluster.

For more information about using the console or the gcloud CLI for upgrades, see the documentation for your version of Anthos clusters on bare metal:

Chronicle

The SentinelOne Alert feed has been enhanced to ingest both alerts and threats. No change is needed to the feed configuration. If data contains both alerts and threats, then both types of data will be ingested.

Cloud Logging

You can now route logs through the Log Router of another Google Cloud project. The logs can then be managed by the other Google Cloud project, which includes log-based metrics, log-based alerts, and other log sinks. For more information, see Route logs to supported destinations.

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for logging/apiv2

1.7.0 (2023-02-27)

Features
  • logging: Add (*Logger). StandardLoggerFromTemplate() method. (#7261) (533ecbb)
  • logging: Add REST client (06a54a1)
  • logging: Rewrite signatures and type in terms of new location (620e6d8)
Bug Fixes
  • logging: Correctly populate SourceLocation when logging via (*Logger).StandardLogger (#7320) (1a0bd13)
  • logging: Fix typo in README.md (#7297) (82aa2ee)

Java

Changes for google-cloud-logging

3.14.5 (2023-03-02)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.4.0 (#1290) (84d42ae)
Cloud Spanner

Cloud Spanner fine-grained access control is now generally available. Fine-grained access control combines the benefits of Identity and Access Management (IAM) with traditional SQL role-based access control. For more information, see About fine-grained access control.

Dataform

Query preview in a workspace is available in Preview.

Dataproc Metastore

Dataproc Metastore 2 is now Generally Available (GA). Dataproc Metastore 2 provides horizontal scalability through fine grained scaling options. For more information, see Datproc Metastore versions.

The Spanner database type is generally available (GA).

Auxiliary versions is generally available (GA).

Google Cloud VMware Engine

VMware Engine nodes are now available in the following additional region:

  • Delhi (asia-south2)
Network Intelligence Center

Network Topology now includes cross-project metrics for network traffic sent across Shared VPC or VPC Network Peering boundaries within the same organization. For more information, see Network Topology overview.

March 08, 2023

Apigee API hub

On March 8, 2023, the Apigee Registry API documents were updated to include the Google APIs Explorer panel.

The Google APIs Explorer has been added to the Apigee Registry API documents. The Try this method panel acts on real data and lets you try Google API methods without writing code.

Cloud Data Fusion

SAP BW OHD, SAP ODP, SAP OData, SAP SLT, and SAP Table plugins version 0.8 is generally available (GA) in Cloud Data Fusion versions 6.8.0 and later.

Cloud Interconnect

Dataplane v2 for Cloud Interconnect is fully available for customers using Dedicated Interconnect or Partner Interconnect in the following regions:

  • europe-west2 (UK)
  • northamerica-northeast1 (Montréal)

All new VLAN attachments that you create in these regions are automatically provisioned on Dataplane v2. Existing VLAN attachments for these regions can be migrated to Dataplane v2. You can migrate existing attachments yourself by re-creating the attachments, or you can request and schedule an assisted migration. Contact Google Cloud Support for assistance.

For the list of all regions that are Dataplane v2-enabled, see the Locations table (Dedicated Interconnect) or Supported service providers (Partner Interconnect).

Cloud Monitoring

You can now use the gcloud CLI to configure a snooze, which prevents Cloud Monitoring from sending notifications or creating incidents during specific time periods. You can also configure a snooze by using the Google Cloud Console and the API. For more information see Create and manage snoozes.

Network Intelligence Center

You can now see allow rules that are no longer active based on usage patterns and trends. For more information, see Allow rules with no hits based on trend analysis.

You can now see shadowed rule insights for hierarchical firewall policies and global network firewall policies in Firewall Insights. For more information, see Firewall Insights categories and states.

Resource Manager

You can now create dry-run organization policies to monitor how policy changes would impact your workflows before they are enforced.

Secret Manager

Support for Annotations in Secret Manager is now generally available. Annotations are used to define custom metadata about a secret.

Transfer Appliance

ta check is a command line tool to detect and help fix configuration issues with Transfer Appliance and Edge Appliance.

March 07, 2023

Anthos clusters on AWS

You can now launch clusters with the following Kubernetes versions:

  • 1.23.16-gke.200
  • 1.24.9-gke.2000
  • 1.25.5-gke.2000
  • Fixed an issue where certain errors weren't propagated and reported during cluster create/update operations.
  • Fixed an issue with AWS EFS CSI driver where EFS hostnames can't be resolved when AWS VPC is configured to use a custom DNS server.
  • Updated Anthos Identity Service to better handle concurrent authentication webhook requests.
  • Updated fluent-bit to v1.9.9 to fix CVE-2022-42898.

This release fixes the following vulnerabilities:

Anthos clusters on Azure

You can now launch clusters with the following Kubernetes versions:

  • 1.23.16-gke.200
  • 1.24.9-gke.2000
  • 1.25.5-gke.2000
  • Fixed an issue where certain errors weren't propagated and reported during cluster create/update operations.
  • Updated Anthos Identity Service to better handle concurrent authentication webhook requests.
  • Updated fluent-bit to v1.9.9 to fix CVE-2022-42898.

This release fixes the following vulnerabilities:

Anthos clusters on VMware

Anthos clusters on VMware 1.14.2-gke.37 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.14.2-gke.37 runs on Kubernetes 1.25.5-gke.100.

The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.14, 1.13, and 1.12.

We no longer silently skip saving empty files in diagnose snapshots, but instead collect the names of those files in a new empty_snapshots file in the snapshot tarball.

  • Fixed an issue where user cluster data disk validation used the cluster-level datastore vsphere.datastore instead of masterNode.vsphere.datastore.

  • Fixed an issue with Anthos Identity Service to better scale and handle concurrent authentication requests.

  • Fixed an issue where component-access-sa-key was missing in the admin-cluster-creds Secret after admin cluster upgrade.

  • Fixed an issue where user cluster upgrade triggered through the Google Cloud console might flap between ready and non-ready states until CA rotation fully completes.

  • Fixed an issue where gkectl diagnose cluster might generate false failure signals with non-vSphere CSI drivers.

  • Fixed an issue where admin cluster update doesn't wait for user control-plane machines to be re-created when using ControlPlaneV2.

Fixed the following vulnerabilities:

BigQuery Cloud Load Balancing

The Cloud Load Balancing Console now allows you to see the equivalent API code for actions you take in the Console. When you create or update a load balancer, before you click Create or Update, you can click Equivalent Code to view the load balancer API resources that will be created, updated, or deleted.

This capability is in Preview.

Cloud Run

You can now authenticate to a Cloud Run service by including a Google-signed OpenID Connect ID token in the X-Serverless-Authorization header if your application already uses the Authorization header for custom authorization.

Cloud Storage

In buckets with turbo replication enabled, objects uploaded using XML API multipart uploads are now included in the turbo replication RPO.

Google Kubernetes Engine

Backend Service-based external Network load balancers are now generally available with GKE. Regional Backend Service is a foundational element of a Google Cloud Load Balancer and using it for your external LoadBalancer Services will unlock new capabilities going forward. To learn more, see how to deploy a backend service-based external network load balancer.

Identity and Access Management

You can now set an expiry time for all newly created service account keys in your project, folder, or organization. This feature is generally available (GA).

March 06, 2023

Access Approval

Access Approval supports Cloud NAT in the GA stage.

AlloyDB for PostgreSQL

Cloud Client libraries for the AlloyDB Admin API are in Preview. Supported languages include C++, C#, Go, and Java.

Anthos clusters on VMware

Cluster lifecycle improvements versions 1.13.1 and later

You can use the Google Cloud console or the gcloud CLI to upgrade user clusters managed by the Anthos On-Prem API. The upgrade steps differ depending on your admin cluster version. For more information, see the version of the documentation that corresponds to your admin cluster version:

1.12.6 patch release

Anthos clusters on VMware 1.12.6-gke.35 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.12.6-gke.35 runs on Kubernetes v1.23.16-gke.2400.

The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.14, 1.13, and 1.12.

  • Fixed a bug where KSASigningKeyRotation always shows as an unsupported change during user cluster update.
  • Fixed an issue with Anthos Identity Service to better scale and handle concurrent authentication requests.

  • Fixed an issue where component-access-sa-key was missing in the admin-cluster-creds Secret after admin cluster upgrade.

Fixed the following vulnerabilities:

App Engine standard environment Ruby

The Ruby 3.20 runtime for App Engine standard environment is now available in preview.

Backup and DR

Backup and DR Service now supports logging and alerting via Cloud Logging and Cloud Monitoring. It:

  • Supports centralized logging of backup events.
  • Enables users to view backup events in Cloud Logging with custom filters.
  • Enables users to configure alerts for backup events via email, SMS, Slack, PagerDuty, and more – all within Cloud Monitoring.
Batch

Batch is available in the following regions:

  • asia-south1 (Mumbai)
  • asia-east1 (Taiwan)
  • europe-west3 (Frankfurt)
  • southamerica-west1 (Santiago)
  • us-east4 (Northern Virginia)

For more information, see Locations.

BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for bigquery/storage/apiv1beta1

1.48.0 (2023-03-01)

Features
  • bigquery/connection: Add cloud spanner connection properties - serverless analytics (#7487) (14771b1)
  • bigquery/storage/managedwriter: Mark managedwriter as GA (#6804) (3d3eeda)

Java

Changes for google-cloud-bigquery

2.23.1 (2023-03-02)

Dependencies
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.14.0 (#2545) (ad78ebb)
  • Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.18.0 (#2546) (60e45e4)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.4.0 (#2547) (2588582)
Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Node.js

Changes for @google-cloud/bigtable

4.4.0 (2023-03-01)

Features
  • Add new_partitions field for CloseStream for Cloud Bigtable ChangeStream (#1247) (ecbdb52)

Java

Changes for google-cloud-bigtable

2.20.0 (2023-03-02)

Features
  • Add getNewPartitions method to CloseStream for Bigtable ChangeStream (#1655) (8847fed)
  • Add new_partitions field for CloseStream for Cloud Bigtable ChangeStream (#1654) (0e283bf)
Bug Fixes
  • Fix StackOverflow in ChangeStreamStateMachine due to excessive mods (#1648) (9e11106)
  • Use org.threeten.bp.Duration for ReadChangeStreamQuery::heartbeatDura… (#1652) (87261a9)
Dependencies
  • Update dependency com.google.cloud:google-cloud-monitoring-bom to v3.13.0 (#1656) (1c632ec)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.4.0 (#1657) (c7a3e29)

Python

Changes for google-cloud-bigtable

2.17.0 (2023-03-01)

Features
  • Add new_partitions field for CloseStream for Cloud Bigtable ChangeStream (#740) (1adcad4)

2.16.0 (2023-02-27)

Features
  • Enable "rest" transport in Python for services supporting numeric enums (c5116e0)
  • Publish the Cloud Bigtable Change Streams (c5116e0)
Bug Fixes
  • Add context manager return types (beb5bf3)
  • deps: Require google-api-core>=1.34.0,>=2.11.0 (c5116e0)
Documentation
  • Add documentation for enums (beb5bf3)
Cloud Healthcare API

A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.

Cloud Monitoring

You can now view and list incidents on your custom dashboards. For more information, see Display incidents on a dashboard.

Config Controller

Config Controller now uses the following versions of its included products:

Dataform

Dataform in Preview is available in the following regions:

  • asia-northeast1
  • europe-west2
  • europe-west3
  • us-east1
Dataproc

Added stronger validations to disallow upper-case characters in template IDs per Resource Names guidance, which allows Workflow template creation to fail fast instead of failing at workflow template instantiation.

Added decision metric field in Stackdriver autoscaler logs.

Filestore

Filestore data is compliant with at-rest and in-use data residency requirements pursuant with Google Cloud terms of service.

Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Python

Changes for google-cloud-datastore

2.14.0 (2023-02-28)

Features
  • Enable "rest" transport in Python for services supporting numeric enums (6785908)
Documentation
  • Minor documentation formatting and cleanup (6785908)

Java

Changes for google-cloud-datastore

2.13.6 (2023-03-02)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.4.0 (#1001) (a230e03)
Google Cloud Deploy

Google Cloud Deploy now provides the ability to deploy to multiple targets at the same time, supported in preview.

Pub/Sub

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-pubsub

1.123.5 (2023-03-03)

Dependencies
  • Update dependency com.google.cloud:google-cloud-core to v2.12.0 (#1509) (6f70d8a)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.4.0 (#1510) (0d0ece7)
Secret Manager

A weekly digest of client library updates from across the Cloud SDK.

Python

Changes for google-cloud-secret-manager

2.16.0 (2023-02-28)

Features
  • Enable "rest" transport in Python for services supporting numeric enums (10c02e5)
Text-to-Speech

Text-to-Speech now offers a Spanish Studio voice, cloud-es-US-Studio-B, in addition to its existing English Studio voices.

March 03, 2023

Cloud Spanner

Added support for the JSONB array data type in the PostgreSQL dialect. For more information, see Work with JSONB data.

Dialogflow

Dialogflow CX now provides a setting for choosing the voice for speech synthesis.

Google Kubernetes Engine

(2023-R06) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters

The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.

No channel

Stable channel

  • Version 1.24.9-gke.3200 is now the default version in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.21.14-gke.14100
    • 1.23.14-gke.1800
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to version 1.21.14-gke.14600 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.21.14-gke.14600 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.16-gke.1100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to version 1.23.16-gke.1100 with this release.

Regular channel

  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.22.17-gke.3100
    • 1.23.16-gke.200
    • 1.25.6-gke.200
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.4000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.16-gke.1100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.23.16-gke.1100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.25.6-gke.1000 with this release.

Rapid channel

  • Version 1.26.1-gke.1500 is now the default version in the Rapid channel.
  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.21.14-gke.15800
    • 1.22.17-gke.4000
    • 1.23.16-gke.1100
    • 1.24.10-gke.1200
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to version 1.21.14-gke.18100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.4300 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.16-gke.1400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.10-gke.2300 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.24.10-gke.2300 with this release.

(2023-R06) Version updates

(2023-R06) Version updates

  • Version 1.24.9-gke.3200 is now the default version in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.21.14-gke.14100
    • 1.23.14-gke.1800
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to version 1.21.14-gke.14600 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.21.14-gke.14600 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.16-gke.1100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to version 1.23.16-gke.1100 with this release.

(2023-R06) Version updates

  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.22.17-gke.3100
    • 1.23.16-gke.200
    • 1.25.6-gke.200
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.4000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.16-gke.1100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.23.16-gke.1100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.25.6-gke.1000 with this release.

(2023-R06) Version updates

  • Version 1.26.1-gke.1500 is now the default version in the Rapid channel.
  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.21.14-gke.15800
    • 1.22.17-gke.4000
    • 1.23.16-gke.1100
    • 1.24.10-gke.1200
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.20 to version 1.21.14-gke.18100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.4300 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.16-gke.1400 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.10-gke.2300 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.24.10-gke.2300 with this release.
Identity and Access Management

The IAM documentation has been reorganized. We made the following changes:

  • Reorganized the left-hand navigation for the Guides tab.
  • Removed the Support tab and relocated its documents to the Resources and Guides tabs.
Vertex AI

Pre-built containers to perform custom training with TensorFlow 2.11, PyTorch 1.12, or PyTorch 1.13 are now generally available (GA).

March 02, 2023

Anthos clusters on bare metal

Release 1.12.8

Anthos clusters on bare metal 1.12.8 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.12.8 runs on Kubernetes 1.23.

Fixes:

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

Apigee UI

On March 2, 2023, we released an updated provisioning experience for Apigee users creating Pay-as-you-go organizations from the Apigee UI. All Apigee users creating new organizations with Pay-as-you-go billing can access the simplified onboarding experience, whether they are provisioning from the Apigee UI or the Google Cloud console.

App Engine flexible environment Java

The Java runtime versions 11 and 17 are now available in preview, and are built on modern and secure operating systems (Ubuntu 18 and 22). These new runtime versions use Google Cloud's buildpacks and require updates to your app.yaml. Learn more.

BigQuery

The WITH RECURSIVE clause is now generally available (GA). This clause lets you include one or more recursive common table expressions (CTEs) in a query.

Cloud Composer

Cloud Composer 2.1.8 and 1.20.8 images are available:

  • composer-2.1.8-airflow-2.4.3 (default)
  • composer-2.1.8-airflow-2.3.4
  • composer-2.1.8-airflow-2.2.5
  • composer-1.20.8-airflow-1.10.15
  • composer-1.20.8-airflow-2.4.3
  • composer-1.20.8-airflow-2.3.4
  • composer-1.20.8-airflow-2.2.5
Dataproc

Release Dataproc Serverless for Spark runtime 2.1 preview:

  • Spark 3.4.0-rc1
  • BigQuery Spark Connector 0.28.0
  • Cloud Storage Connector 2.2.11
  • Conda 22.11
  • Java 17
  • Python 3.10
  • R 4.2
  • Scala 2.13
Dialogflow

The Dialogflow CX maximum number of flows per agent has been increased from 20 to 50.

Transcoder API

You can now set the language code and display name for text and audio streams.

Workflows

Workflows is available in the following additional regions:

  • asia-northeast3 (Seoul, South Korea)
  • asia-southeast2 (Jakarta, Indonesia)
  • me-west1 (Tel Aviv, Israel)
  • southamerica-west1 (Santiago, Chile)

Support for limiting the maximum number of concurrent branches or iterations within a parallel step is generally available (GA).

March 01, 2023

Anthos clusters on VMware

A new vulnerability (CVE-2022-4696) has been discovered in the Linux kernel that can lead to a privilege escalation on the node. Anthos clusters on VMware running v1.12 and v1.13 are impacted. Anthos clusters on VMware running v1.14 or later are not affected.

For instructions and more details, see the Anthos clusters on VMware security bulletin.

Anthos clusters on bare metal

Release 1.14.2

Anthos clusters on bare metal 1.14.2 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.14.2 runs on Kubernetes 1.25.

Fixes:

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

Apigee Connectors

On March 1, 2023, we released updates to connectors for Apigee.

The following new connectors are available in preview:

The IBM MQ connector now supports requestReply messages.

The Cloud Storage connector now supports the following actions for file operations:

  • UploadObject
  • DownloadObject
  • MoveObject
  • CopyObject
  • DeleteObject

The MongoDB connector now supports the following actions:

  • InsertDocument
  • UpdateDocument
  • DeleteDocument
  • GetDocument
Apigee UI

On March 1, 2023, we released an updated version of the Apigee UI.

Public preview release of the Apigee UI in the Google Cloud console

This release includes a new version of the Apigee UI that is integrated with the Google Cloud console. The new UI makes it easier to perform Apigee tasks that are managed in the Cloud console. We welcome your feedback on the new UI: click Send Feedback at the top of the UI.

For now, you can continue to use the classic Apigee UI if you wish: just click Back to Classic Apigee in the new UI.

The following tabs in the classic Apigee UI have not yet been implemented in the Apigee UI in the Cloud console, but they will be available there soon:

  • Develop > Integrations
  • API Security
  • Monetization
  • Analyze > API Metrics > Cache Performance,
  • Analyze > API Metrics > Target Performance
  • Analyze > Developers
  • Analyze > End Users
  • Publish > Portals

If you need to use these features, you can do so by switching to the classic Apigee UI.

This release will be rolled out over the next week, so you might not be able to view the new Apgee UI until the rollout is complete.

Chronicle

Schedule Chronicle dashboard reports

You can schedule the delivery of Chronicle dashboard reports over email for both the default dashboards and custom dashboards. In addition to setting the time interval, email address, and format to deliver the report, you can also set the pagination details and test the delivery of the report. For more information, see Schedule Chronicle dashboard reports.

Chronicle Feed Management enhanced the support for the Qualys VM log type to include Qualys VM Detections API. See the Feed Management documentation for information.

The following supported default parsers have changed. Each is listed by product name and ingestion label, if applicable.

  • 1Password (ONEPASSWORD)
  • Airlock Digital Application Allowlisting (AIRLOCK_DIGITAL)
  • Apache (APACHE)
  • Atlassian Confluence (ATLASSIAN_CONFLUENCE)
  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • Azure AD Directory Audit (AZURE_AD_AUDIT)
  • Azure Cosmos DB (AZURE_COSMOS_DB)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Compute Engine (GCP_COMPUTE)
  • CrowdStrike Detection Monitoring (CS_DETECTS)
  • CrowdStrike Falcon (CS_EDR)
  • Cybereason EDR (CYBEREASON_EDR)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • Forcepoint NGFW (FORCEPOINT_FIREWALL)
  • FortiGate (FORTINET_FIREWALL)
  • Google Chrome Browser Cloud Management (CBCM) (N/A)
  • iBoss Proxy (IBOSS_WEBPROXY)
  • JumpCloud Directory Insights (JUMPCLOUD_DIRECTORY_INSIGHTS)
  • Juniper Mist (JUNIPER_MIST)
  • Kubernetes Node logs (KUBERNETES_NODE)
  • Microsoft Azure Activity (AZURE_ACTIVITY)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Okta (OKTA)
  • Okta Access Gateway (OKTA_ACCESS_GATEWAY)
  • Palo Alto Networks Firewall (PAN_FIREWALL)
  • pfSense (PFSENSE)
  • Salesforce (SALESFORCE)
  • Sentinelone Alerts (SENTINELONE_ALERT)
  • SentinelOne EDR (SENTINEL_EDR)
  • Signal Sciences WAF (SIGNAL_SCIENCES_WAF)
  • SonicWall (SONIC_FIREWALL)
  • Windows Event (WINEVTLOG)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Yubico OTP (YUBICO_OTP)
  • Zscaler Private Access (ZSCALER_ZPA)

For details about changes in each parser, see Supported default parsers.

Cloud Logging

You can now use the gcloud CLI to do the following:

  • Create a log bucket and upgrade that bucket to use Log Analytics.
  • Upgrade an existing log bucket to use Log Analytics.
  • Create a linked dataset in BigQuery.

For more information, see Configure log buckets.

Log buckets in the following regions can now be upgraded to use Log Analytics:

  • us-central1
  • us-west1
  • asia-south1

For more information, see Supported regions.

Cloud Spanner

Change streams are now supported for PostgreSQL-dialect databases.

Google Kubernetes Engine

A new vulnerability (CVE-2022-4696) has been discovered in the Linux kernel that can lead to a privilege escalation on the node. GKE clusters, including Autopilot clusters, are impacted. GKE clusters using GKE Sandbox are not affected. For instructions and more details, see the GKE security bulletin.

Security Command Center

The legacy version of the Findings tab in the Security Command Center dashboard in the Cloud console is now deprecated. Similar functionality is currently available in the new version of the Findings tab.

After March 31, 2023, the option to use the legacy Findings tab will be removed from the dashboard. After that date, you will be able to work with findings in the console only by using the newer, default version of the Findings tab.

For more information about working with Security Command Center findings by using the default Findings tab, see Work with findings in the Security Command Center.

February 28, 2023

Anthos Service Mesh

1.14.6-asm.9 is now available for in-cluster Anthos Service Mesh.

You can now download 1.14.6-asm.9 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.14.6 subject to the list of supported features.

App Engine flexible environment Node.js

The Node.js 18 runtime is now available in preview, and is built on a modern and secure operating system (Ubuntu 22). This new runtime version uses Google Cloud's buildpacks and requires updates to your app.yaml. Learn more.

Cloud Data Fusion

Cloud Data Fusion version 6.8.1 is generally available (GA). This release is in parallel with the CDAP 6.8.1 release.

Changes in Cloud Data Fusion 6.8.1:

  • Cloud Data Fusion supports upgrades for real-time pipelines that have a Kafka Consumer Streaming source from version 6.8.0 to 6.8.1 after you upgrade your environment.

  • Starting in Cloud Data Fusion 6.8.1, Dataproc clusters require the following OAUTH scope to function: https://www.googleapis.com/auth/cloud-platform. This scope is no longer required as of March 29, 2023.

  • March 17, 2023 release note addition: The Oracle Batch Source version 1.9.1 (which comes with Cloud Data Fusion 6.8.1) reads the Oracle NUMBER data type with undefined precision and scale as a string in Cloud Data Fusion. In previous versions, Cloud Data Fusion reads the Oracle NUMBER data type with undefined precision and scale as decimal (38,0), which could result in data loss. For more information, see Troubleshooting (PLUGIN-1119).

Fixed in 6.8.1:

  • Fixed an issue in instances with role-based access control where deployment and validations failed with read time out error after a short time.

  • Fixed an issue that caused replication assessment for Oracle by Datastream to fail when an instance had role-based access control.

  • Fixed an issue that allowed reading secure keys in the system namespace with only the Data Fusion Viewer role (datafusion.viewer) or Instance Accessor role (datafusion.accessor). For more information about predefined roles for role-based access control in Cloud Data Fusion, see the Role-based access control (RBAC) overview.

  • Fixed an issue where the Replication Source plugin's event reader was not stopped by the Delta worker when there were errors, which caused leakage of the plugin's resources (CDAP-20394).

  • Fixed an issue that occurred in certain upgrade scenarios, where pipelines didn't have the Use Connection property set and the UI didn't display a plugin's connection properties, such as Project ID and Service Account Type (CDAP-20392).

  • Fixed an issue that caused pipelines to fail if they used a connection property, such as the Service Account JSON property, that used a secure macro with JSON as the value (CDAP-20271).

  • For Oracle by Datastream Replication sources, fixed an issue where the Review Assessment page would freeze when a selected or manually-entered table didn't exist in the source database (CDAP-20257).

  • For Oracle by Datastream Replication sources, fixed an issue where the Select tables and transformations page failed to load the list of tables and displayed the error deadline exceeded when the source database contained a large number of tables (CDAP-20199).

  • Fixed an error in security-enabled instances that caused pipeline launch to fail and return a token expired error when evaluating secure macros in provisioner properties (CDAP-20146).

  • For MySQL Replication sources, fixed an issue that caused Replication jobs to fail during the initial snapshot, if the job included a runtime argument with the Debezium property, binary-handling-mode (CDAP-20121).

  • For Replication jobs, increased retry duration for API calls to update state/offsets in Replication jobs (CDAP-20028).

  • Fixed an issue that prevented upgrades for MySQL and SQL Server Replication jobs in version 6.6.0. Upgrades are supported from version 6.6.0 to 6.7.3 and 6.8.1 (CDAP-19622).

  • Fixed upgrades for Oracle by Datastream Replication jobs. You can upgrade Oracle by Datastream Replication jobs from Cloud Data Fusion versions 6.6.0 and 6.7 to version 6.8.1. (CDAP-20013).

Cloud Data Fusion version 6.7.3 is generally available (GA). This release is in parallel with the CDAP 6.7.3 release.

March 17, 2023 release note addition: The Oracle Batch Source version 1.8.5 (which comes with Cloud Data Fusion 6.7.3) reads the Oracle NUMBER data type with undefined precision and scale as a string in Cloud Data Fusion. In plugin versions 1.8.3 and earlier, Cloud Data Fusion reads the Oracle NUMBER data type with undefined precision and scale as decimal (38,0), which could result in data loss. For more information, see Troubleshooting (PLUGIN-1119).

Fixed in 6.7.3:

  • Fixed an issue that allowed reading secure keys in the system namespace with only the Data Fusion Viewer role (datafusion.viewer) or Instance Accessor role (datafusion.accessor). For more information about predefined roles for role-based access control in Cloud Data Fusion, see the Role-based access control (RBAC) overview.

  • Fixed an issue in the BigQuery Replication Target plugin that caused Replication jobs to fail when the BigQuery target table already existed. The new version of the plugin will automatically be used in new Replication jobs (CDAP-19599).

  • Fixed an issue that prevented upgrades for MySQL and SQL Server Replication jobs in version 6.6.0. Upgrades are supported from version 6.6.0 to 6.7.3 and 6.8.1 (CDAP-19622).

  • Fixed an issue that prevented upgrades for Oracle by Datastream Replication jobs in version 6.6.0. Upgrades are supported from versions 6.6.0 , 6.7.0, 6.7.1, and 6.7.2 to version 6.7.3 (CDAP-20013).

  • Fixed an issue that caused pipelines to fail if they used a connection property, such as the Service Account JSON property, which used a secure macro with JSON as the value (CDAP-20271).

  • Fixed an issue that occurred in certain upgrade scenarios, where pipelines didn't have the Use Connection property set and the UI didn't display a plugin's connection properties, such as Project ID and Service Account Type (CDAP-20392).

  • Fixed an issue where the Replication Source plugin's event reader was not stopped by the Delta worker when there were errors, which caused leakage of the plugin's resources (CDAP-20394).

  • Fixed an error in security-enabled instances that caused pipeline launch to fail and return a token expired error when evaluating secure macros in provisioner properties (CDAP-20146).

  • In the Oracle Batch Source (version 1.8.4 and earlier), when the source data included fields with the NUMBER data type with undefined precision and scale, Cloud Data Fusion read it as decimal and set the precision to 38 and the scale to 0. If any values in the field had scale other than 0, values were rounded, which could have resulted in data loss. If the scale for this field is overridden in the plugin output schema, the pipeline fails.

    In Oracle batch source version 1.8.5, you can edit the scale of the CDAP decimal data type in the output schema. The overridden value is used to map to the Oracle NUMBER data type without failing the pipeline. If there are any numbers present in the fields with a scale greater than the scale defined in the plugin, Cloud Data Fusion rounds the values based on the scale you set in the output schema. For example, if you specify precision=10, scale=3, the value 123.4567 is rounded to 123.457. For more information about setting precision and scale in a plugin, see Changing the precision and scale for decimal fields in the output schema (PLUGIN-1433).

  • Improved performance for batch pipelines with MySQL sinks (PLUGIN-1374).

  • For Database plugins (version 2.9.3), fixed a security issue where the database username and password were exposed in the logs (CDAP-20235).

Cloud Functions

Cloud Functions now supports the Python 3.11 runtime at the General Availability release level.

Cloud SQL for MySQL

Cloud SQL now supports the ability to get details for a Cloud SQL user for a database instance using the API or gcloud. To learn more about the new method, see Cloud SQL Admin API REST Resource.

Cloud SQL for PostgreSQL

Cloud SQL now supports the ability to get details for a Cloud SQL user for a database instance using the API or gcloud. To learn more about the new method, see Cloud SQL Admin API REST Resource.

Cloud SQL for SQL Server

Cloud SQL now supports the ability to get details for a Cloud SQL user for a database instance using the API or gcloud. To learn more about the new method, see Cloud SQL Admin API REST Resource.

Cloud Translation

For document translations, added support for Microsoft DOC, PPT, and XLS files. For more information, see Supported formats.

Compute Engine

Generally available: When creating a reservation, you can now include a compact placement policy to specify that VMs should be located as close to each other as possible to reduce network latency. Learn how to create a reservation that specifies a compact placement policy.

Dataproc

--properties=dataproc:agent.ha.enabled=true can now be used to enable the Dataproc Agent in high availability mode. This property is supported by Dataproc Image versions 2.0 and above.

Dialogflow

The Dialogflow CX audio input duration limit has been increased from one minute to two minutes.

Filestore

High Scale and Enterprise tier instances now support overlapping permissions (GA).

Vertex AI

A new custom training overview page is available. The new overview page covers the following topics:

  • What is custom training?
  • Benefits of custom training on Vertex AI.
  • How custom training works.
  • Custom training workflow.

February 27, 2023

AlloyDB for PostgreSQL

AlloyDB for PostgreSQL is available in the following regions:

  • asia-east1 (Taiwan)
  • asia-east2 (Hong Kong)
  • asia-northeast2 (Osaka)
  • asia-northeast3 (Seoul)
  • asia-south1 (Mumbai)
  • asia-southeast2 (Jakarta)
  • australia-southeast1 (Sydney)
  • australia-southeast2 (Melbourne)
  • europe-central2 (Warsaw)
  • europe-north1 (Finland)
  • europe-west2 (London)
  • europe-west6 (Zurich)
  • us-east1 (South Carolina)
  • us-east4 (Northern Virginia)
  • us-west1 (Oregon)
  • us-west3 (Salt Lake City)

For more information, see AlloyDB Locations.

App Engine standard environment Python

The Python 3.11 runtime for App Engine standard environment is now generally available.

BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for bigquery/storage/apiv1beta1

1.47.0 (2023-02-22)

Features
  • bigquery/storage: Add default_value_expression to TableFieldSchema (#7400) (1244b3f)
  • bigquery: Add support for session in load jobs (#7418) (f9ff2ca)
Bug Fixes
  • bigquery: Avoid double-channel-close during context cancellation (#7467) (ca4b2ef)

Java

Changes for google-cloud-bigquery

2.23.0 (2023-02-22)

Features
Dependencies
  • Update cloud client dependencies (#2526) (4d88ccc)
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.13.0 (#2533) (ed2cb74)
  • Update dependency com.google.apis:google-api-services-bigquery to v2-rev20230210-2.0.0 (#2530) (62ff092)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.3.0 (#2534) (f1bcc33)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.20 (#2527) (5fe5e74)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.20 (#2528) (554e75d)

Python

Changes for google-cloud-bigquery

3.6.0 (2023-02-22)

Features
  • Adding preserveAsciiControlCharacter to CSVOptions (#1491) (f832e7a)
Bug Fixes
  • Annotate optional integer parameters with optional type (#1487) (a190aaa)
  • Loosen ipywidget dependency (#1504) (20d3276)
  • Removes scope to avoid unnecessary duplication (#1503) (665d7ba)
Dependencies
  • Update minimum google-cloud-core to 1.6.0 (a190aaa)

You can set default values on columns in your BigQuery tables. This feature is now generally available (GA).

The multivariate time-series forecasting model ARIMA_PLUS_XREG is now available to on-demand users.

Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigtable

2.19.2 (2023-02-21)

Bug Fixes
  • Change types for Cloud Bigtable Changestream methods (#1639) (908d70f)
Dependencies
  • Update shared deps to 3.3.0 and monitoring to 3.12.0 (#1643) (1a54fbf)
Cloud Functions

Cloud Functions has added support for a new runtime, Ruby 3.2, at the Preview release level.

New performance recommendations are supported for Cloud Functions, which analyze cold starts and suggest setting up minimum instances to improve function performance. At the Preview release level.

Cloud Logging

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-logging

3.14.4 (2023-02-21)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.3.0 (#1282) (58ac608)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.20 (#1279) (296cce1)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.20 (#1280) (6363196)
Cloud Run

When session affinity is enabled on a Cloud Run service that is splitting traffic between multiple revisions, requests from the same clients are now routed to the same revision. When updating the traffic splitting configuration, Cloud Run minimizes the number of clients that are redirected to a new revision.

Cloud Spanner

A monthly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-spanner

6.36.0 (2023-02-08)

Features
  • Support UNRECOGNIZED types + decode BYTES columns lazily (#2219) (fc721c4)
Bug Fixes
Dependencies
  • Update dependency com.google.cloud:google-cloud-monitoring to v3.11.0 (#2262) (d566613)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.2.0 (#2264) (b5fdbc0)
  • Update dependency com.google.cloud:google-cloud-trace to v2.10.0 (#2263) (96f0c81)

6.36.1 (2023-02-21)

Bug Fixes
  • Prevent illegal negative timeout values into thread sleep() method while retrying exceptions in unit tests. (#2268) (ce66098)
Dependencies
  • Update dependency com.google.api.grpc:proto-google-cloud-spanner-executor-v1 to v1.2.0 (#2256) (f0ca86a)
  • Update dependency com.google.cloud:google-cloud-monitoring to v3.12.0 (#2284) (0be701a)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.3.0 (#2285) (bb5d5c6)
  • Update dependency com.google.cloud:google-cloud-trace to v2.11.0 (#2286) (3c80932)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.20 (#2280) (685d1ea)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.20 (#2281) (f2aabc2)

Node.js

Changes for @google-cloud/spanner

6.7.1 (2023-01-23)

Bug Fixes

6.7.2 (2023-02-17)

Bug Fixes
  • Tests emit empty metadata before emitting unspecified error (14ef031)

Go

Changes for spanner/admin/database/apiv1

1.44.0 (2023-02-01)

Features
  • spanner/spansql: Add support for ALTER INDEX statement (#7287) (fbe1bd4)
  • spanner/spansql: Add support for managing the optimizer statistics package (#7283) (e528221)
  • spanner: Add support for Optimistic Concurrency Control (#7332) (48ba16f)

Python

Changes for google-cloud-spanner

3.27.1 (2023-01-30)

Bug Fixes
  • Add context manager return types (830f325)
  • Change fgac database role tags (#888) (ae92f0d)
  • Fix for database name in batch create request (#883) (5e50beb)
Documentation
  • Add documentation for enums (830f325)

The new System insights dashboard displays metrics and scorecards for the resources that your instance or database uses and helps you get a high-level view of your system's performance. For more information, see Monitor instances with system insights.

Confidential VM

The service account attached to a Confidential Space workload VM now requires the confidentialcomputing.workloadUser role to generate an attestation token. If you receive a permission denied message for confidentialcomputing.locations.list on your existing workload, add the role to the VM service account.

Datastream

Terraform now supports Datastream private connectivity, connection profile, and stream resources. For more information, see Getting started with Terraform and Datastream.

Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Node.js

Changes for @google-cloud/datastore

7.3.2 (2023-02-17)

Bug Fixes

Java

Changes for google-cloud-datastore

2.13.5 (2023-02-17)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.3.0 (#994) (ce8df48)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.20 (#989) (f71ccd9)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.20 (#990) (5e984c8)
Google Cloud Deploy Pub/Sub

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-pubsub

1.123.4 (2023-02-22)

Dependencies
  • Update dependency com.google.cloud:google-cloud-bigquery to v2.23.0 (#1496) (713d727)

1.123.3 (2023-02-22)

Dependencies
  • Update dependency com.google.cloud:google-cloud-bigquery to v2.21.0 (#1470) (105c293)
  • Update dependency com.google.cloud:google-cloud-bigquery to v2.22.0 (#1489) (665436c)
  • Update dependency com.google.cloud:google-cloud-core to v2.10.0 (#1464) (8cab4e2)
  • Update dependency com.google.cloud:google-cloud-core to v2.11.0 (#1490) (c42474a)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.3.0 (#1491) (e5e3227)
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.20 (#1484) (8206d12)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.20 (#1485) (d0e9b2a)

Python

Changes for google-cloud-pubsub

2.15.0 (2023-02-22)

Features
  • Add google.api.method.signature to update methods (3dd43d6)
  • Add temporary_failed_ack_ids to ModifyAckDeadlineConfirmation (3dd43d6)
Bug Fixes
  • Add service_yaml_parameters to py_gapic_library BUILD.bazel targets (3dd43d6)
  • Move global import in publisher sample (#866) (271a46d)
  • Port proto changes (#871) (3dd43d6)
Documentation
  • Clarify BigQueryConfig PERMISSION_DENIED state (3dd43d6)
  • Clarify subscription description (3dd43d6)
  • Fix Pull description (3dd43d6)
  • Fix PullResponse description (3dd43d6)
  • Replacing HTML code with Markdown (3dd43d6)
  • Update Pub/Sub topic retention limit from 7 days to 31 days (3dd43d6)

February 24, 2023

Access Approval

Access Approval supports Cloud Composer in the Preview stage. For the complete list of supported services, see Supported services.

Apigee hybrid

hybrid v1.8.5

On February 24, 2023 we released an updated version of the Apigee hybrid software, v1.8.5.

For information on upgrading, see Upgrading Apigee hybrid to version 1.8.

Bug ID Description
266594584 Websocket was failing in asm 1.15. This was due to incompatible capitalization in variable names between the Anthos Service Mesh overlay.yaml file and the and the Envoy filter apigee-envoyfilter.yaml file.
266411394 Add support for Azure Front Door request headers to /healthz health check.
260372012 Requests failed with 500 response and keyvaluemap.service.ErrorDuringDecryption error after upgrade to Hybrid 1.8. Note: Fixed in Apigee hybrid 1.8.4 and newer.
245619397 In Apigee hybrid, fluentbit support now includes the NO_PROXY environment variable.
181569522 You can now create a new environment with the same name as a deleted environment without needing to perform manual clean-up tasks first.
Cloud Composer

The default Composer version is changed to Cloud Composer 2.

The default Cloud Composer image used for operations is now the latest version of Cloud Composer 2, unless the image-version parameter is explicitly specified.

The composer-latest-airflow-* version aliases now point to Cloud Composer 2.

24 new Airflow metrics are now available in Cloud Monitoring. For more information, see Monitor environments with Cloud Monitoring.

The apache-airflow-providers-google package is upgraded to the public version 8.9.0 in images with Airflow 2.4.3 and 2.3.4. For more information about changes, see the apache-airflow-providers-google page.

Cloud Composer 2.1.7 and 1.20.7 images are available:

  • composer-2.1.7-airflow-2.4.3 (default)
  • composer-2.1.7-airflow-2.3.4
  • composer-2.1.7-airflow-2.2.5
  • composer-1.20.7-airflow-1.10.15
  • composer-1.20.7-airflow-2.4.3
  • composer-1.20.7-airflow-2.3.4
  • composer-1.20.7-airflow-2.2.5

Cloud Composer versions 2.0.4, 2.0.5, 1.18.0, and 1.18.1 have reached their end of full support period.

Cloud SQL for MySQL

The Cloud SQL Proxy Operator is now available in public preview. The Cloud SQL Proxy Operator is an open-source Kubernetes operator that automates connecting workloads in a GKE cluster to Cloud SQL databases. To learn more about the Cloud SQL Proxy Operator, see About the Cloud SQL Proxy Operator.

Cloud SQL for PostgreSQL

The Cloud SQL Proxy Operator is now available in public preview. The Cloud SQL Proxy Operator is an open-source Kubernetes operator that automates connecting workloads in a GKE cluster to Cloud SQL databases. To learn more about the Cloud SQL Proxy Operator, see About the Cloud SQL Proxy Operator.

Cloud SQL for SQL Server

The Cloud SQL Proxy Operator is now available in public preview. The Cloud SQL Proxy Operator is an open-source Kubernetes operator that automates connecting workloads in a GKE cluster to Cloud SQL databases. To learn more about the Cloud SQL Proxy Operator, see About the Cloud SQL Proxy Operator.

February 23, 2023

Anthos Config Management

Increased the helm-sync container CPU request to 50m. For information on resource requirements, see Resource requests.

Updated the spec.override.resources field on RootSync and RepoSync objects to let you override the default resource amounts (for example, CPU or memory) requested by the helm-sync container.

Anthos clusters on bare metal

Release 1.13.5

Anthos clusters on bare metal 1.13.5 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.13.5 runs on Kubernetes 1.24.

Fixes:

Known issues:

For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.

BigQuery

Authorized stored procedures are now in preview. This feature lets you share stored procedures with users or groups without giving them direct access to the underlying tables.

Cloud Data Fusion

FTP Plugins versions 3.1.0 and 3.2.0 are generally available (GA) in Cloud Data Fusion versions 6.7.2+ and 6.8.0+, respectively. They include support for more file formats and properties. An issue was fixed in the FTP Batch Source that caused pipelines to fail when running with Dataproc 2.0. For more information, see the CDAP Hub release log.

Cloud Data Loss Prevention

Data profiles generated at the column level include the following metrics:

  • Estimated null proportion: an approximate proportion of null values in a column, categorized as high, medium, low, or very low.
  • Estimated uniqueness: an estimate of how much of the data in a column is unique, categorized as high, medium, or low.

For more information on these metrics, see the Metrics reference.

Cloud Load Balancing

Network Load Balancing logging and Internal TCP/UDP Load Balancing logging are now available in General availability.

Cloud Logging

The time-range selector in the Logs Explorer has been updated to support a larger set of time range options, such as preset times, custom start and end times, and relative time ranges. For more information, see Use the time-range selector.

Dataproc

Upgrade Spark to 3.3.2 and its dependencies in 1.1 and 2.0 Dataproc Serverless for Spark runtimes:

  • Jackson to 2.13.5
  • Jetty to 9.4.50.v20221201
  • ORC to 1.8.2
  • Protobuf to 3.21.12
  • RoaringBitmap to 0.9.39
Document AI Warehouse

TIFF file UI rendering support: when calling GetDocument API for a TIFF file, the API will return a converted PNG image inside cloud_ai_document field.

Users do not need to grant the Cloud Storage roles to the Document AI Warehouse service account during the provisioning process.

February 22, 2023

Anthos Service Mesh

1.15.5-asm.2 is now available for in-cluster Anthos Service Mesh.

You can now download 1.15.5-asm.2 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.15.5 subject to the list of supported features.

BigQuery

Fixed linked datasets querying shared dataset that has data ingested through streaming inserts or the BigQuery Storage Write API.

Cloud DNS

Health checks for internal load balancers and automatic failovers in Cloud DNS routing policies are now available in GA.

Cloud Interconnect

HA VPN over Cloud Interconnect is generally available. With HA VPN over Cloud Interconnect, you can use Cloud VPN to encrypt your Cloud Interconnect traffic by deploying HA VPN tunnels over your VLAN attachments.

For more information, see the HA VPN over Cloud Interconnect overview.

Cloud Shell

Cloud Code Extension updated to 1.21.2

Cloud Code now uses a single activity bar icon to reduce the amount of space on screen and consolidate all explorers to a single convenient view. Additionally the update incorporates new Cloud Functions capabilities, improved snippet accuracy for Cloud APIs, and new Compute Engine functionality, and more! Review the Cloud Code release notes for a complete list of features, updates, and fixes.

Cloud Shell Editor is built with Theia 1.34.0

Review the Theia release notes for a complete list of features/updates/bug fixes.

Terraform Extension updated to 2.25.2

Review the Terraform Extension release notes for a complete list of features/updates/bug fixes.

Golang Extension updated to 0.37.1

See the Golang Extension release notes for a full list of features/updates/bug fixes.

Cloud VPN

HA VPN over Cloud Interconnect is generally available. With HA VPN over Cloud Interconnect, you can use Cloud VPN to encrypt your Cloud Interconnect traffic by deploying HA VPN tunnels over your VLAN attachments.

For more information, see the HA VPN over Cloud Interconnect overview.

Compute Engine

Generally available: You can upgrade the term of your 1-year commitments and convert them into 3-year commitments to get a higher discount percentage for your committed resources and continue receiving the discounts for a longer time period.

For more information, see Upgrade the term of commitments.

Google Cloud VMware Engine

VMware Engine private clouds support the addition of a Trusted Platform Module (TPM) 2.0 virtual cryptoprocessor to a virtual machine.

For details about this feature, see About Virtual Trusted Platform Module.

Google Kubernetes Engine

(2023-R05) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters

The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.

No channel

  • Version 1.24.9-gke.3200 is now the default version.
  • The following control plane and node versions are now available:
  • The following control plane versions are no longer available:
    • 1.21.14-gke.7100
    • 1.22.15-gke.1000
    • 1.22.15-gke.2500
    • 1.22.16-gke.1300
    • 1.22.16-gke.2000
    • 1.25.5-gke.2000
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to version 1.21.14-gke.14100 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to version 1.25.6-gke.200 with this release.

Stable channel

  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.22.16-gke.2000
    • 1.24.9-gke.1500
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.24.9-gke.3200 with this release.

Regular channel

  • Version 1.24.9-gke.3200 is now the default version in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.21.14-gke.14600
    • 1.22.16-gke.2000
    • 1.23.14-gke.1800
    • 1.24.9-gke.2000
    • 1.25.5-gke.2000
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to version 1.21.14-gke.15800 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.16-gke.200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.9-gke.3200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.24.9-gke.3200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.25.6-gke.200 with this release.

Rapid channel

  • Version 1.25.6-gke.1000 is now the default version in the Rapid channel.
  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.22.17-gke.3100
    • 1.23.16-gke.200
    • 1.24.9-gke.3200
    • 1.26.1-gke.200
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.4000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.16-gke.1100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.10-gke.1200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.6-gke.1000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.25.6-gke.1000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.1-gke.1500 with this release.

(2023-R05) Version updates

  • Version 1.24.9-gke.3200 is now the default version.
  • The following control plane and node versions are now available:
  • The following control plane versions are no longer available:
    • 1.21.14-gke.7100
    • 1.22.15-gke.1000
    • 1.22.15-gke.2500
    • 1.22.16-gke.1300
    • 1.22.16-gke.2000
    • 1.25.5-gke.2000
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to version 1.21.14-gke.14100 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to version 1.25.6-gke.200 with this release.

(2023-R05) Version updates

  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.22.16-gke.2000
    • 1.24.9-gke.1500
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.24.9-gke.3200 with this release.

(2023-R05) Version updates

  • Version 1.24.9-gke.3200 is now the default version in the Regular channel.
  • The following versions are now available in the Regular channel:
  • The following versions are no longer available in the Regular channel:
    • 1.21.14-gke.14600
    • 1.22.16-gke.2000
    • 1.23.14-gke.1800
    • 1.24.9-gke.2000
    • 1.25.5-gke.2000
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to version 1.21.14-gke.15800 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.16-gke.200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.9-gke.3200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.24.9-gke.3200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.25.6-gke.200 with this release.

(2023-R05) Version updates

  • Version 1.25.6-gke.1000 is now the default version in the Rapid channel.
  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.22.17-gke.3100
    • 1.23.16-gke.200
    • 1.24.9-gke.3200
    • 1.26.1-gke.200
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.4000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.16-gke.1100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.10-gke.1200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.6-gke.1000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.25.6-gke.1000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.1-gke.1500 with this release.
VPC Service Controls

Preview stage support for the following integration:

February 21, 2023

Anthos Service Mesh

1.16.2-asm.2 is now available for in-cluster Anthos Service Mesh.

You can now download 1.16.2-asm.2 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.16.2 subject to the list of supported features.

Managed Anthos Service Mesh 1.16 isn't rolling out to the rapid release channel at this time. You can periodically check this page for the announcement of the rollout of managed Anthos Service Mesh to the rapid channel. See Select a managed Anthos Service Mesh release channel for more information.

Anthos Service Mesh now supports multi-cluster meshes on Amazon EKS and Microsoft AKS. See Install Anthos Service Mesh and Set up a multi-cluster mesh outside Google Cloud for more information.

Anthos Service Mesh now supports Mesh CA on all supported platforms.

Anthos Service Mesh now supports Anthos Clusters on Azure as a preview feature.

Anthos Service Mesh 1.13 is no longer supported. For more information, see Supported versions.

App Engine flexible environment Go

The Go runtime versions 1.18 and 1.19 are now available in preview and are built on a modern and secure operating system (Ubuntu 22). These new runtime versions use Google Cloud's buildpacks and require updates to your app.yaml. Learn more.

App Engine flexible environment Python

The Python runtime versions 3.8, 3.9, 3.10, and 3.11 are now available in preview and are built on modern and secure operating systems (Ubuntu 18 and 22). These new runtime versions use Google Cloud's buildpacks and require updates to your app.yaml. Learn more.

Backup and DR

Google Cloud Backup and DR is now available under Google Cloud terms of service.

BigQuery Cloud Interconnect

Dataplane v2 for Cloud Interconnect is fully available for customers using Dedicated Interconnect or Partner Interconnect in the following region:

  • us-east1 (South Carolina)

All new VLAN attachments that you create in these regions are automatically provisioned on Dataplane v2. Existing VLAN attachments for these regions can be migrated to Dataplane v2. You can migrate existing attachments yourself by re-creating the attachments, or you can request and schedule an assisted migration. Contact Google Cloud Support for assistance.

For the list of all regions that are Dataplane v2-enabled, see the Locations table (Dedicated Interconnect) or Supported service providers (Partner Interconnect).

Cloud Storage

You can now attach a maximum of 50 tag bindings to a storage bucket.

Compute Engine

Generally available: NVIDIA® T4 GPUs are now available in the following region and zones:

  • Warsaw, Poland, Europe: europe-central2-b,c

For more information about using GPUs on Compute Engine, see GPU platforms.

Generally available: The image import tool now supports importing SUSE Linux Enterprise Server 15 SP4 and SUSE Linux Enterprise Server 15 SP4 for SAP images to Google Cloud.

Regional metrics for Compute Engine API limits are now available. Regional migration of API limits reduces the scope of global or multi-regional outages. For more information about the new regional metrics and changes in API limits, see API rate limits.

Due to this change, you might want to update your Cloud Monitoring dashboards, queries and alerts to use the regional metrics. For more information, see Migrate Compute Engine API quota from global metrics to regional metrics.

Config Connector

Config Connector version 1.101.0 is now available.

Disabled fast dependency reconciliation during resource deletion.

Adjusted default reconciliation interval for the following resources:

  • BigtableInstance: 3600 seconds (1 hour)
  • BigtableTable: 3600 seconds (1 hour)
  • ServiceUsage: 3600 seconds (1 hour)
  • ComputeSslCertificate: 0 seconds (This resource does not support any updates)

Graduated the following resources from alpha to stable: NetworkServicesGateway, NetworkServicesGRPCRoute, NetworkServicesHTTPRoute, NetworkServicesMesh, NetworkServicesTCPRoute, NetworkServicesTLSRoute.

Removed GameServicesRealm resource.

Added spec.externalDataConfiguration.referenceFileSchemaUri field to BigQueryTable.

Added spec.gitFileSource.githubEnterpriseConfigRef, spec.repositoryEventConfig and spec.sourceToBuild.githubEnterpriseConfigRef fields to CloudBuildTrigger.

Added spec.edgeSecurityPolicyRef and spec.localityLbPolicies fields to ComputeBackendService.

Added spec.scheduling.maxRunDuration field to ComputeInstance.

Added spec.resourcePolicies and spec.scheduling.maxRunDuration fields to ComputeInstanceTemplate.

Added spec.shareSettings field to ComputeNodeGroup.

Added spec.tcpTimeWaitTimeoutSec field to ComputeRouterNAT (#692).

Added spec.adaptiveProtectionConfig.autoDeployConfig field to ComputeSecurityPolicy.

Added spec.bindings.members.memberFrom.serviceIdentityRef field to IAMPartialPolicy (#722).

Added spec.memberFrom.serviceIdentityRef field to IAMPolicyMember (#722).

Added spec.ipConfiguration.enablePrivatePathForGoogleCloudServices field to SQLInstance.

spec.settings.diskType is now immutable in SQLInstance.

Fixed a bug that could cause controllers to become stuck on an outdated CRD version.

Datastream

You can now set the number of maximum concurrent backfill tasks for a stream using the Datastream API. To learn more, see Manage streams.

Discovery Engine API

Discovery for Media

Preview recommendations is now available in Preview mode.

Use this feature to preview and evaluate what documents your serving configs will recommend to your users. This allows you to test models and serving configs quickly before you go into production.

For information about this feature, see Preview Recommendations.

Document AI

This launch upgrades the lifecycle stage of the Custom Document Extractor (CDE) component of the DocAI Workbench from Public Preview to Generally Available (GA). CDE covers essential workflows for developing custom document extraction processors with end-to-end UI support:

  • Data import
  • Schema creation and annotation
  • Processor model training
  • Evaluation and troubleshooting
  • Model deployment and version management
  • Human-in-the-loop (HITL) integration for "last-mile" processor quality assurance

Notable new Generally Available Custom Document Extractor (CDE) features include:

  • Public APIs
  • Automatic schema label creation from pre-labeled documents
  • Schema label data type and occurrence editable pre-training
  • New DocAI Toolkit with a labeled document converter

The following features have been upgraded:

  • Processor Gallery
  • Schema editor
  • Labeling UI
  • Training pipeline
  • Manage versions table
Google Distributed Cloud Edge

This is a minor release of Google Distributed Cloud Edge (version 1.3.0).

The following new features have been introduced in this release of Google Distributed Cloud Edge:

The following changes have been introduced in this release of Distributed Cloud Edge:

  • Getting information about a Machine resource now returns the version of the Distributed Cloud Edge cluster stack.
  • You can now connect Distributed Cloud Edge clusters to a Virtual Private Cloud network in a Cloud project other than your Distributed Cloud Edge cluster project.
  • When creating a cross-project VPN connection, you can no longer specify a VPC project service account. Distributed Cloud Edge now uses your cluster project service account.
Live Stream API

Added content encryption support

Added new channel events: mute, unmute, return to program, and switch input

Added the timecode feature which supports synchronizing media workflows with live stream content

Vertex AI Workbench

M104 Update

This update of the M104 release of Vertex AI Workbench managed notebooks includes the following:

  • Fixed a bug where local and remote kernels are not displayed. This happens when remote kernels are not accessible.
  • Minor bug fixes and improvements.
Workflows

An issue where one shared variable in a subworkflow overwrote another in a calling subworkflow during a workflow's execution is resolved. This affected calling a subworkflow with a parallel step from within a parallel step.

February 20, 2023

Apigee API hub

On February 20, 2023 Apigee API hub released a new version of the software.

Bug ID Description
264686707 Vertical scrollbars would not appear if the taxonomy and lifecycle stage tables overflowed the page.
264409346 The API list failed to load if there were over 1,000 APIs registered.
Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Node.js

Changes for @google-cloud/bigtable

4.3.0 (2023-02-10)

Features
  • Publish the Cloud Bigtable Change Streams (#1237) (000a353)
Bug Fixes

Java

Changes for google-cloud-bigtable

2.19.1 (2023-02-16)

Bug Fixes
  • Change the return type of Heartbeat::getEstimatedLowWatermark to long (#1631) (a101494)
  • Fix connectivity error count calculation (#1632) (0803785)
  • test: Fix flaky test (#1633) (fc29cd3)
Dependencies
  • Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.20 (#1626) (0865023)
  • Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.20 (#1627) (782e81f)
Cloud Healthcare API

A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.

Compute Engine

Preview: You can autoscale a regional managed instance group with a BALANCED target distribution shape. With the BALANCED shape, the autoscaler is aware of the capacity in each zone and creates VMs in zones that have resource availability. For more information, see Autoscaling a regional MIG.

Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Node.js

Changes for @google-cloud/datastore

7.3.1 (2023-02-17)

Bug Fixes
  • deps: Roll back dependency @google-cloud/datastore to ^7.2.0 (#1069) (1677c53)

7.3.0 (2023-02-16)

Migrate to Virtual Machines

Preview: Migrate to Virtual Machines from an Azure source lets you migrate Azure VM instances to Compute Engine.

February 17, 2023

Access Context Manager

The ability to add individual VPC networks to a perimeter is generally available (GA).

Previously, all VPC networks in a host project were added to a perimeter. You can now do the following:

  • Add individual VPC networks as members of a perimeter.
  • Create an ingress rule to authorize individual VPC networks to access a perimeter.
Chronicle

Search API

The query limit for the udmSearch method has been increased from 60 to 120 queries per hour (QPH). The maximum number of events which can be returned using the udmSearch method has been increased from 1,000 to 10,000.

UDM Search

You can now specify single-line comments and block comments in UDM search. You can also now use UDM search to find values of type float (floating point numbers) and bool (boolean).

Cloud Logging

You can create log buckets that use Log Analytics and upgrade existing log buckets to use Log Analytics by using the Logging API. For more information, see Create a bucket.

Cloud Monitoring

You can now install pre-defined alerting policies for services integrated with Cloud Monitoring from the Monitoring Integrations page and from the Observability tab on the pages for Kubernetes Engine clusters and workloads. For more information about these installable policies, see Install alerting policies.

To view details of your user-defined metrics, use the Metrics diagnostics page, which can now be accessed through the navigation pane of Cloud Monitoring. For more information, see View information about your user-defined metrics.

Dataproc

New sub-minor versions of Dataproc images:

  • 1.5.82-debian10, 1.5.82-rocky8, 1.5.82-ubuntu18
  • 2.0.56-debian10, 2.0.56-rocky8, 2.0.56-ubuntu18
  • 2.1.4-debian11, 2.1.4-rocky8, 2.1.4-ubuntu20
Google Cloud Deploy

Google Cloud Deploy now uses Skaffold 2.0 as the default Skaffold version for all target types.

Google Kubernetes Engine

In Standard clusters with GKE version 1.26 and later, you can now audit workloads to validate if they are compatible with Autopilot clusters. Use kubectl get audit to see the cluster objects.

Network Intelligence Center

Connectivity Tests now include dual-stack instances with both IPv4 and IPv6 addresses, including instances with multiple network interfaces. For more information, see Create and run Connectivity Tests.

VPC Service Controls

The ability to add individual VPC networks to a perimeter is generally available (GA).

Previously, all VPC networks in a host project were added to a perimeter. You can now do the following:

  • Add individual VPC networks as members of a perimeter.
  • Create an ingress rule to authorize individual VPC networks to access a perimeter.

February 16, 2023

AlloyDB for PostgreSQL

Continuous backup and recovery is in Preview. This feature protects your clusters from data-loss events by letting you recover their data from any moment within a configurable window.

Cloud Logging

Version 2.25.1 of the Ops Agent introduces health checks. When the Ops Agent starts, it performs a series of checks for conditions that prevent the agent from running correctly. If the agent detects one of the conditions, it writes a message to its health-check log and exits. For more information, see Find Ops Agent troubleshooting information.

Cloud Monitoring

Version 2.25.1 of the Ops Agent introduces health checks. When the Ops Agent starts, it performs a series of checks for conditions that prevent the agent from running correctly. If the agent detects one of the conditions, it writes a message to its health-check log and exits. For more information, see Find Ops Agent troubleshooting information.

The Ops Agent now provides Preview support for NVIDIA GPU metrics, including metrics reported from the NVIDIA Management Library (NVML) and the Data Center GPU Manager (DCGM).

When you install the GPU-enabled version of the Ops Agent, NVML metrics are collected automatically. DGCM metrics are available as a third-party integration. For information about configuring the integration, see NVIDIA Data Center GPU Manager. The reference document for Ops Agent metrics includes tables for the NVML metrics and the DCGM metrics.

Cloud Run

You can now deploy public container images from Docker Hub to Cloud Run.

Cloud Spanner

The Cloud Spanner regional endpoints feature has been moved to a future release. It is not currently available.

Compute Engine

Preview: C3 VMs are now available in the following regions:

  • Council Bluffs, Iowa, North America : us-central1
  • Ashburn, Virginia, North America: us-east4
  • Eemshaven, Netherlands, Europe : europe-west4

Preview: You can now use a GPU-enabled Ops Agent to track GPU utilization and GPU memory usage rates for Linux virtual machine instances that have attached GPUs.

Through an available integration with NVIDIA's Data Center GPU Manager (DCGM), you can also track metrics such as Streaming Multiprocessor (SM) block utilization, SM occupancy, SM pipe utilization, PCIe traffic rate, and NVLink traffic rate.

For more information, see Monitoring GPU performance on Linux VMs.

Resource Manager

The organization restrictions feature has entered General Availability. The organization restrictions feature helps security administrators to prevent data exfiltration due to phishing or insider attacks. The organization restrictions feature restricts access only to resources in authorized Google Cloud organizations. For more information, see Introduction to organization restrictions.

Text-to-Speech

Text-to-Speech offers these new voices. See the supported voices page for a complete list of voices and audio samples.

  • cloud-eu-ES-Standard-A
  • cloud-gl-ES-Standard-A
reCAPTCHA Enterprise

reCAPTCHA Enterprise Fraud Prevention is available in Preview.

You can use reCAPTCHA Enterprise Fraud Prevention to protect payment transactions against attacks such as carding, stolen instrument fraud, and account takeover payment fraud. For more information, see Protect payment transactions.

February 15, 2023

Batch BigQuery

You can now make a dataset and the tables in that dataset case-insensitive when you create a dataset or alter a dataset. This feature is generally available (GA).

In the Explorer pane, the resource corresponding to the focused tab is now selected. This feature is generally available (GA).

In the Explorer pane, you can now see all the resources in the searched resource's level by clicking Show more. This feature is generally available (GA).

Chronicle

The following supported default parsers have changed. Each is listed by product name and ingestion label, if applicable.

  • 1Password (ONEPASSWORD)
  • Atlassian Jira (ATLASSIAN_JIRA)
  • AWS GuardDuty (GUARDDUTY)
  • Azure AD Directory Audit (AZURE_AD_AUDIT)
  • Azure AD Organizational Context (AZURE_AD_CONTEXT)
  • Carbon Black (CB_EDR)
  • Cisco Stealthwatch (CISCO_STEALTHWATCH)
  • Cisco WLC/WCS (CISCO_WIRELESS)
  • Cloudflare WAF (CLOUDFLARE_WAF)
  • CrowdStrike Detection Monitoring (CS_DETECTS)
  • CrowdStrike Falcon (CS_EDR)
  • Cybereason EDR (CYBEREASON_EDR)
  • DigitalArts i-Filter (DIGITALARTS_IFILTER)
  • F5 ASM (F5_ASM)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • Google Chrome Browser Cloud Management (CBCM) (N/A)
  • Imperva (IMPERVA_WAF)
  • Imperva Database (IMPERVA_DB)
  • Ipswitch MOVEit Transfer (IPSWITCH_MOVEIT_TRANSFER)
  • Linux Auditing System (AuditD) (AUDITD)
  • Microsoft AD FS (ADFS)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Mobileiron (MOBILEIRON)
  • Netskope Web Proxy (NETSKOPE_WEBPROXY)
  • Palo Alto Cortex XDR Events (PAN_CORTEX_XDR_EVENTS)
  • Palo Alto Networks Firewall (PAN_FIREWALL)
  • Samba SMBD (SMBD)
  • Sentinelone Alerts (SENTINELONE_ALERT)
  • SentinelOne Deep Visibility (SENTINEL_DV)
  • SentinelOne EDR (SENTINEL_EDR)
  • SonicWall (SONIC_FIREWALL)
  • Trend Micro AV (TRENDMICRO_AV)
  • VMware vCenter (VMWARE_VCENTER)
  • Windows DNS (WINDOWS_DNS)
  • Windows Event (WINEVTLOG)

For details about changes in each parser, see Supported default parsers.

Cloud Data Loss Prevention

The VAT_NUMBER infoType detector can identify Belgium VAT numbers.

For more information about VAT_NUMBER and other built-in infoType detectors, see InfoType detector reference.

Cloud Interconnect

Dataplane v2 for Cloud Interconnect is fully available for customers using Dedicated Interconnect or Partner Interconnect in the following regions:

  • us-west1 (Oregon)
  • europe-west4 (Netherlands)

All new VLAN attachments that you create in these regions are automatically provisioned on Dataplane v2. Existing VLAN attachments for these regions can be migrated to Dataplane v2. You can migrate existing attachments yourself by re-creating the attachments, or you can request and schedule an assisted migration. Contact Google Cloud Support for assistance.

For the list of all regions that are Dataplane v2-enabled, see the Locations table (Dedicated Interconnect) or Supported service providers (Partner Interconnect).

Cloud Monitoring

You can now configure uptime checks to include a user-defined content-type header. For more information, see the customContentType field of the UptimeCheckConfig structure.

Cloud Translation

Glossaries are now supported for the recently added 24 languages.

  • Assamese
  • Aymara
  • Bambara
  • Bhojpuri
  • Dhivehi
  • Dogri
  • Ewe
  • Guarani
  • Ilocano
  • Konkani
  • Krio
  • Kurdish(Sorani)
  • Lingala
  • Luganda
  • Maithili
  • Meiteilon(Manipuri)
  • Mizo
  • Oromo
  • Quechua
  • Sanskrit
  • Sepedi(Pedi)
  • Tigrinya
  • Tsonga
  • Twi (Akan)
Transcoder API

Validation checks added for segmentDuration and gopDuration for all video codecs as outlined in the documentation. This change was released earlier this month.

Translation Hub

Glossaries are now supported for the recently added 24 languages.

  • Assamese
  • Aymara
  • Bambara
  • Bhojpuri
  • Dhivehi
  • Dogri
  • Ewe
  • Guarani
  • Ilocano
  • Konkani
  • Krio
  • Kurdish(Sorani)
  • Lingala
  • Luganda
  • Maithili
  • Meiteilon(Manipuri)
  • Mizo
  • Oromo
  • Quechua
  • Sanskrit
  • Sepedi(Pedi)
  • Tigrinya
  • Tsonga
  • Twi (Akan)
reCAPTCHA Enterprise

reCAPTCHA Enterprise account defender is now generally available (GA).

You can use this feature to detect and prevent account-related fraudulent activities.

February 14, 2023

Apigee hybrid

hybrid v1.7.6

On February 14, 2023 we released an updated version of the Apigee hybrid software, v1.7.6.

For information on upgrading, see Upgrading Apigee hybrid to version 1.7.

Bug ID Description
268445095 The validateOrg flag can be set to false to bypass upgrade validation errors when configuration includes HTTP Forward proxy. You can use this to avoid upgrade errors caused by HTTP proxy settings.
262699558 The watcher component no longer fails when using Kubernetes Secret to store hybrid service account secret.
181569522 You can now create a new environment with the same name as a deleted environment without needing to perform manual clean-up tasks first.
218567150 The ingress gateway is now configured to consistently preserve UUID in the x-request-id header.
Note: This setting does have some impact on tracing in the ingress gateway. For more information, see pack_trace_reason in "UUID (proto)" in the envoy documentation. (Also fixed in Apigee hybrid v1.8.3)
259264961 Added support for ASM v1.15. Please see Known issue 266452840
Artifact Registry

Artifact Registry remote repositories and virtual repositories are now in Preview. These features help you to optimize your build and deployment workflows.

  • Remote repositories cache artifacts from external sources, including Docker Hub, Maven Central, PyPI, and the npm registry.
  • Virtual repositories provide a single access point to download artifacts from multiple remote or standard repositories. Each upstream repository has a set priority to protect against issues with dependency confusion.
Cloud Composer

(Cloud Composer 2) The default version of Airflow is changed to 2.4.3.

(Cloud Composer 2) Fixed the problem where the Composer Agent Kubernetes workload generated warnings about failed pods during the environment creation.

Fixed environment upgrade checks that were failing for environments in some Cloud Composer 2 versions.

Cloud Composer 2.1.6 and 1.20.6 images are available:

  • composer-2.1.6-airflow-2.4.3 (default)
  • composer-2.1.6-airflow-2.3.4
  • composer-2.1.6-airflow-2.2.5
  • composer-1.20.6-airflow-1.10.15 (default)
  • composer-1.20.6-airflow-2.4.3
  • composer-1.20.6-airflow-2.3.4
  • composer-1.20.6-airflow-2.2.5

Cloud Composer versions 2.0.3 and 1.17.10 have reached their end of full support period.

Compute Engine

Tau T2A VMs now support secure boot.

Dataform

Dataform in Preview is available in the following regions:

  • asia-southeast1
  • europe-west1
  • us-west1
Dialogflow

Dialogflow CX added regional support for some system entities. The following system entities:

  • @sys.person
  • @sys.address
  • @sys.geo-city
  • @sys.geo-country
  • @sys.geo-state

are now available in the following regions for English (en), French (fr), Italian (it), German (de), and Spanish (es) languages:

  • europe-west1
  • europe-west2
  • europe-west3
  • northamerica-northeast1
SAP on Google Cloud

Google Cloud's Agent for SAP is now generally available (GA)

To simplify agent installation and operation, while also enabling access to new products, Google Cloud's Agent for SAP v1.0 combines Google Cloud's monitoring agent for SAP NetWeaver with new Process Monitoring and Workload Manager Validation functionalities.

In addition to collecting and sending information required by SAP to the SAP Host Agent, on Linux, now you can opt in and enable other functionalities, all built into the same agent. The new optional functionalities include collection of Process Monitoring metrics, such as high-availability cluster status and information, and collection of Workload Manager Validation metrics, a way to automatically evaluate your workloads against best practices.

For more information, see What's new with Google Cloud's Agent for SAP.

Google Cloud's monitoring agent for SAP NetWeaver is deprecated, and is replaced by Google Cloud's Agent for SAP. For information about new installations or how you can upgrade, see Google Cloud's Agent for SAP operations guide.

Support for the monitoring agent for SAP NetWeaver ends on February 14, 2024.

Vertex AI

Vertex AI Prediction

Pre-built PyTorch containers for serving predictions from PyTorch models is generally available (GA).

Vertex AI Matching Engine now supports Private Service Connect in Preview. To learn how to set up a a Private Service Connect instance, see Using Private Service Connect.

Video Stitcher API

Video Stitcher API can now insert ads served by Google Ad Manager (GAM) into live streams and VOD assets.

February 13, 2023

Access Approval

Access Approval supports Artifact Registry in the GA stage.

Anthos clusters on VMware

Anthos clusters on VMware 1.13.5-gke.27 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.13.5-gke.27 runs on Kubernetes 1.24.9-gke.2500.

The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.14, 1.13, and 1.12.

  • Updated the Ubuntu image to ubuntu-gke-op-2004-1-13-v20230201 using node kernel version 5.4.0.1062.60.

  • Instead of ignoring snapshots files with empty content, we save their names in a new file named empty_snapshots.

During preflight checks and cluster diagnosis, we now skip PVs and PVCs that use non-vSphere drivers.

Fixed the following vulnerabilities:

App Engine standard environment Go

The Go 1.20 runtime for App Engine standard environment is now available in preview.

BigQuery

A weekly digest of client library updates from across the Cloud SDK.

Go

Changes for bigquery/storage/apiv1beta1

1.46.0 (2023-02-06)

Features
Bug Fixes
  • bigquery: Create/update an isolated dataset for collation feature (#7256) (b371558)
  • bigquery: Fetch dst table for jobs when readings with Storage API (#7325) (0bf80d7), refs #7322

Java

Changes for google-cloud-bigquery

2.22.0 (2023-02-08)

Features
  • Add collation for Case sensitive string column (#2490) (3257737)
Dependencies
  • Update arrow.version to v11 (major) (#2495) (94ed060)
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.11.0 (#2482) (e6ffb9b)
  • Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.12.0 (#2512) (09f280d)
  • Update dependency com.google.cloud:google-cloud-bigquerystorage-bom to v2.31.0 (#2499) (c0a393c)
  • Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.15.0 (#2483) (5c2bf69)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.2.0 (#2513) (02832dd)

You can now create materialized views over BigLake metadata cache-enabled tables to reference structured data stored in Cloud Storage. This feature is in preview.

Cloud Bigtable

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-bigtable

2.19.0 (2023-02-10)

Features
Bug Fixes
  • Modify ConvertExceptionCallable to retry on Goaway (#1588) (cf752ea)
Documentation
  • Fix javadoc code example for awaitOptimizeRestoredTableAsync (#1617) (8b23bb9)

2.18.4 (2023-02-06)

Dependencies
  • Update dependency com.google.cloud:google-cloud-monitoring-bom to v3.11.0 (#1609) (88be13e)
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.2.0 (#1610) (15db117)
Cloud Functions

Cloud Functions has added support for a new runtime, Go 1.20, at the Preview release level.

Cloud Healthcare API

A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.

Cloud Logging

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-logging

3.14.3 (2023-02-06)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.2.0 (#1269) (e196a80)
Cloud Spanner

As of today, the list compute price for the following 9-replica Spanner multi-region configurations has been reduced: nam-eur-asia1 and nam-eur-asia3. For more details, see Cloud Spanner pricing.

Dataflow

A weekly digest of client library updates from across the Cloud SDK.

Python

Changes for google-cloud-dataflow-client

0.8.2 (2023-02-07)

Bug Fixes
  • Raise not implemented error when REST transport is not supported (#170) (44651ca)
Eventarc

Eventarc is available in the region: me-west1 (Tel Aviv, Israel).

Firestore in Datastore mode

A weekly digest of client library updates from across the Cloud SDK.

Node.js

Changes for @google-cloud/datastore

7.2.0 (2023-02-09)

Features
  • Add dynamic routing header annotation to DatastoreV1 (b023ab4)
  • Added Snooze API support (b023ab4)
  • Added SuggestConversationSummary RPC (b023ab4)
  • New transaction options for datastoreV1 (b023ab4)
Bug Fixes

Java

Changes for google-cloud-datastore

2.13.4 (2023-02-06)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.2.0 (#975) (f94bd37)
Pub/Sub

A weekly digest of client library updates from across the Cloud SDK.

Java

Changes for google-cloud-pubsub

1.123.2 (2023-02-06)

Dependencies
  • Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.2.0 (#1474) (5fccae4)

Python

Changes for google-cloud-pubsub

2.14.1 (2023-02-08)

Bug Fixes
  • Add context manager return types (4f690b9)
Documentation
  • Add documentation for enums (4f690b9)
  • Mark revision_id in CommitSchemaRevisionRequest as deprecated (#861) (09b846d)
Vertex AI

Support for resource-level IAM policies for Vertex AI featurestore and entityType resources is generally available (GA). For more information, see Control access to resources.

February 10, 2023

Access Approval

Access Approval supports Cloud NAT in the Preview stage. For the complete list of supported services, see Supported services.

Config Controller

Config Controller now uses the following versions of its included products:

Dataproc

Dataproc Serverless for Spark now supports unconditional TTL to batches. The workload will be terminated after the TTL without waiting for work to complete.

Dataproc Serverless for Spark now supports statically-sized Dataproc Serverless for Spark batch workloads with more than 500 executors.

Add support for filters when listing batches. Batches may be filtered on one or more of batch_id, batch_uuid, state, or create_time (for example, state = RUNNING AND create_time < "2023-01-01T00:00:0Z"). See Filter expressions for more information.

Generate a warning when initialization actions are used in a cluster created with a driver node group.

The default Dataproc Serverless for Spark runtime version has changed to 2.0.

Google Kubernetes Engine

(2023-R04) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters

The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.

No channel

  • Version 1.24.9-gke.2000 is now the default version.
  • The following control plane and node versions are now available:
  • The following control plane versions are no longer available:
    • 1.21.14-gke.5300
    • 1.22.17-gke.1400
    • 1.22.17-gke.1900
    • 1.24.7-gke.900
    • 1.24.8-gke.401
    • 1.25.5-gke.1500
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to version 1.21.14-gke.7100 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to version 1.21.14-gke.7100 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.23.14-gke.1800 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.24.8-gke.2000 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to version 1.25.5-gke.2000 with this release.

Stable channel

  • Version 1.21.14-gke.14600 is now available in the Stable channel.
  • The following versions are no longer available in the Stable channel:
    • 1.21.14-gke.5300
    • 1.21.14-gke.7100
    • 1.21.14-gke.8500
    • 1.22.15-gke.2500
    • 1.23.13-gke.900
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to version 1.21.14-gke.14100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.22.16-gke.2000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.14-gke.1800 with this release.

Regular channel

  • Version 1.24.9-gke.2000 is now the default version in the Regular channel.
  • The following versions are no longer available in the Regular channel:
    • 1.21.14-gke.7100
    • 1.21.14-gke.8500
    • 1.22.15-gke.1000
    • 1.22.15-gke.2500
    • 1.22.16-gke.1300
    • 1.23.14-gke.401
    • 1.24.8-gke.2000
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to version 1.21.14-gke.14600 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.16-gke.2000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.14-gke.1800 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.24.9-gke.2000 with this release.

Rapid channel

  • Version 1.25.6-gke.200 is now the default version in the Rapid channel.
  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.22.16-gke.2000
    • 1.22.17-gke.1400
    • 1.22.17-gke.1900
    • 1.23.15-gke.1400
    • 1.23.15-gke.1900
    • 1.24.8-gke.2000
    • 1.24.9-gke.1500
    • 1.24.9-gke.2000
    • 1.25.5-gke.2000
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.16-gke.200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.9-gke.3200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.24.9-gke.3200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.25.6-gke.200 with this release.

(2023-R04) Version updates

  • Version 1.24.9-gke.2000 is now the default version.
  • The following control plane and node versions are now available:
  • The following control plane versions are no longer available:
    • 1.21.14-gke.5300
    • 1.22.17-gke.1400
    • 1.22.17-gke.1900
    • 1.24.7-gke.900
    • 1.24.8-gke.401
    • 1.25.5-gke.1500
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to version 1.21.14-gke.7100 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to version 1.21.14-gke.7100 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.23.14-gke.1800 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.24.8-gke.2000 with this release.
  • Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to version 1.25.5-gke.2000 with this release.

(2023-R04) Version updates

  • Version 1.21.14-gke.14600 is now available in the Stable channel.
  • The following versions are no longer available in the Stable channel:
    • 1.21.14-gke.5300
    • 1.21.14-gke.7100
    • 1.21.14-gke.8500
    • 1.22.15-gke.2500
    • 1.23.13-gke.900
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to version 1.21.14-gke.14100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.22.16-gke.2000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.14-gke.1800 with this release.

(2023-R04) Version updates

  • Version 1.24.9-gke.2000 is now the default version in the Regular channel.
  • The following versions are no longer available in the Regular channel:
    • 1.21.14-gke.7100
    • 1.21.14-gke.8500
    • 1.22.15-gke.1000
    • 1.22.15-gke.2500
    • 1.22.16-gke.1300
    • 1.23.14-gke.401
    • 1.24.8-gke.2000
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.20 to version 1.21.14-gke.14600 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.16-gke.2000 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.14-gke.1800 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.24.9-gke.2000 with this release.

(2023-04) Version updates

  • Version 1.25.6-gke.200 is now the default version in the Rapid channel.
  • The following versions are now available in the Rapid channel:
  • The following versions are no longer available in the Rapid channel:
    • 1.22.16-gke.2000
    • 1.22.17-gke.1400
    • 1.22.17-gke.1900
    • 1.23.15-gke.1400
    • 1.23.15-gke.1900
    • 1.24.8-gke.2000
    • 1.24.9-gke.1500
    • 1.24.9-gke.2000
    • 1.25.5-gke.2000
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.3100 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.16-gke.200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.9-gke.3200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.24.9-gke.3200 with this release.
  • Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.25.6-gke.200 with this release.
Identity and Access Management

Workforce identity federation is generally available (GA). The feature lets you use an external identity provider to authenticate and authorize users to access supported Google Cloud products.

Looker

Looker 23.2 is released. The Looker 23.2 release includes the following changes, features, and fixes.

The Use Legacy Internal Query API legacy feature is now disabled by default. When this feature is disabled, Explores, Looks, and SQL Runner use the upgraded internal API for running queries. Upgrading the internal query API does not affect applications that use the externally available Looker API.

Users will no longer be able to view legacy dashboards unless a Looker admin turns on the Can use Legacy Dashboards legacy flag on the instance. This is in preparation for the complete deprecation of legacy dashboards in Looker 23.6.

When users are running model-based SQL Runner queries, the New Query Admin page should not show Error fetching requested Queries.

The Admin > Usage page now uses the new dashboard experience.

Error logging for cookieless embed has been improved. Additional error details are logged if an issue is detected while Looker is processing a cookieless embed request.

The Presto and Trino dialects now support the approximate parameter.

A new Center Dashboard Title dashboard control on the Admin > Themes page lets you center dashboard titles on embedded dashboards.

A new parameter, Email Domain Allowlist, has been added to the external settings API. This parameter takes an array of email domains of type: string as input. Email Domain Allowlist validates these email domains and saves them to the email domain allowlist if the domains are valid.

Looker has added merged_queries and join_fields as legal types for extending dashboards.

Dashboard URLs in alerts are now rendered as expected.

An issue has been fixed where a persistent derived table (PDT) that was referenced in the SQL of the query and a dependency of another PDT that was both referenced in that same SQL query and required with a direct join would not build unless the parent PDT was also required to be rebuilt in that query. This occurred only when New LookML Runtime was enabled.

The gray theme in Grid visualizations now works as expected.

VPC Service Controls

Preview stage support for the following integration:

Vertex AI

When performing distributed training, Vertex AI properly sets the primary replica in CLUSTER_SPEC as workerpool0 instead of chief. For details, see Format CLUSTER_SPEC.