GCP News - 2026-07-29

2026-07-29
最終更新: 2026-08-27 21:31:25 JST

Google Cloud Release Notes

July 29, 2026

詳細を表示

App Engine standard environment Go

Feature

Support for enabling only needed legacy bundled services using the app_engine_bundled_services field is in General Availability.

App Engine standard environment Java

Feature

Support for enabling only needed legacy bundled services using the app_engine_bundled_services field is in General Availability.

App Engine standard environment PHP

Feature

Support for enabling only needed legacy bundled services using the app_engine_bundled_services field is in General Availability.

App Engine standard environment Python

Feature

Support for enabling only needed legacy bundled services using the app_engine_bundled_services field is in General Availability.

BigQuery

Feature

The BigQuery Data Transfer Service now supports incremental data transfers when transferring data from Klaviyo to BigQuery. This feature is supported in Preview.

Bigtable

Feature

You can use the Google Cloud console to manage row key schemas for your Bigtable tables. This feature is in Preview.

Cloud Key Management Service

Feature

Cloud KMS Autokey with same-project key storage (formerly known as Autokey for delegated key management) is generally available. Autokey with same-project key storage can be used on its own or alongside Autokey with dedicated-project key storage (formerly known as Autokey for centralized key management).

For more information, see Enable Cloud KMS Autokey. To learn how to set guardrails to constrain how Autokey is used in your organization, see Control Autokey usage.

Cloud SQL for MySQL

Feature

Cloud SQL for MySQL now supports significantly faster re-encryption of instances and replicas protected by customer-managed encryption keys (CMEKs), and re-encryption now completes with zero downtime. The steps to re-encrypt your instances and replicas are unchanged, but the operation now re-encrypts the underlying disks in-place, without creating re-encryption backups.

For more information, see Re-encrypt an existing CMEK-enabled instance or replica.

Cloud SQL for PostgreSQL

Feature

Cloud SQL for PostgreSQL now supports significantly faster re-encryption of instances and replicas protected by customer-managed encryption keys (CMEKs), and re-encryption now completes with zero downtime. The steps to re-encrypt your instances and replicas are unchanged, but the operation now re-encrypts the underlying disks in-place, without creating re-encryption backups.

For more information, see Re-encrypt an existing CMEK-enabled instance or replica.

Cloud SQL for SQL Server

Feature

Cloud SQL for SQL Server now supports significantly faster re-encryption of instances and replicas protected by customer-managed encryption keys (CMEKs), and re-encryption now completes with zero downtime. The steps to re-encrypt your instances and replicas are unchanged, but the operation now re-encrypts the underlying disks in-place, without creating re-encryption backups.

For more information, see Re-encrypt an existing CMEK-enabled instance or replica.

Cloud Scheduler

Change

Cloud Scheduler is available in the following locations:

  • europe-west8 (Milan, Italy)
  • europe-west9 (Paris, France)
  • us-south1 (Dallas, United States)

Cloud Service Mesh

Feature

For the clusters using TRAFFIC_DIRECTOR implementation, IP auto-allocation with DNS Proxy is now supported in Rapid release channel.

Compute Engine

Feature

Public preview: you can create a machine image that includes or excludes specific non-boot disks attached to a source Compute Engine instance. For more information, see Create a machine image from specific disks. You can also create a new disk by restoring a specific individual disk from a machine image without creating a new Compute Engine instance. For more information, see Create a disk from a machine image.

Confidential VM

Feature

Confidential VM instances with AMD SEV on C3D and C4D machine types now support configurations with more than 255 vCPUs.

Datastream

Feature

You can now create a Datastream stream directly from the instance or database overview page in Spanner using the automated flow.

For more information, see Create a Spanner stream using the automated flow.

Gemini Enterprise

Feature

Gemini Enterprise: New data stores and support for new actions (Preview)

The following data stores are available in Public Preview:

Additionally, support for new actions is available in Public Preview for the following data stores:

  • AirOps: Suggest Brand Kit edits and write grid.
  • Egnyte: Create comments, create folders, create links, and upload files.
  • Google Stitch: Edit screens.
  • Lovable: Deploy projects, enable databases, send messages, and set workspace knowledge.
  • Smartsheet: Add favorites, create sheets, create workspaces, and update rows.

For more information, see Connect a third-party data source.

Google SecOps

Change

Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.

The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.

  • Airlock Digital Application Allowlisting (AIRLOCK_DIGITAL)
  • AIX system (AIX_SYSTEM)
  • Akamai DataStream 2 (AKAMAI_DATASTREAM_2)
  • Akamai SIEM Connector (AKAMAI_SIEM_CONNECTOR)
  • Apache (APACHE)
  • Arcsight CEF (ARCSIGHT_CEF)
  • Armis Alerts (ARMIS_ALERTS)
  • Aruba Switch (ARUBA_SWITCH)
  • Atlassian Cloud Admin Audit (ATLASSIAN_AUDIT)
  • Linux Auditing System (AuditD) (AUDITD)
  • Avaya Aura Experience Portal (AVAYA_AURA)
  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • AWS CloudWatch (AWS_CLOUDWATCH)
  • AWS Control Tower (AWS_CONTROL_TOWER)
  • Microsoft Azure Activity (AZURE_ACTIVITY)
  • Azure AD (AZURE_AD)
  • Azure AD Organizational Context (AZURE_AD_CONTEXT)
  • Azure Application Gateway (AZURE_GATEWAY)
  • Azure Key Vault logging (AZURE_KEYVAULT_AUDIT)
  • Microsoft Azure Resource (AZURE_RESOURCE_LOGS)
  • Blue Coat Proxy (BLUECOAT_WEBPROXY)
  • BeyondTrust (BOMGAR)
  • Cato Networks (CATO_NETWORKS)
  • Check Point (CHECKPOINT_FIREWALL)
  • Check Point Harmony (CHECKPOINT_HARMONY)
  • Chrome Management (CHROME_MANAGEMENT)
  • ChromeOS XDR (CHROMEOS_XDR)
  • Cisco ASA (CISCO_ASA_FIREWALL)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco FireSIGHT Management Center (CISCO_FIRESIGHT)
  • Cisco ISE (CISCO_ISE)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Switch (CISCO_SWITCH)
  • Cisco UCM (CISCO_UCM)
  • Claroty Xdome (CLAROTY_XDOME)
  • Claude Compliance Logs (CLAUDE_COMPLIANCE_LOGS)
  • HP Aruba (ClearPass) (CLEARPASS)
  • Cloudflare (CLOUDFLARE)
  • Palo Alto Cortex XDR Alerts (CORTEX_XDR)
  • CrowdStrike Falcon (CS_EDR)
  • Darktrace (DARKTRACE)
  • EfficientIP DDI (EFFICIENTIP_DDI)
  • F5 ASM (F5_ASM)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • Fastly CDN (FASTLY_CDN)
  • FireEye eMPS (FIREEYE_EMPS)
  • FireEye HX (FIREEYE_HX)
  • FireEye NX (FIREEYE_NX)
  • Forcepoint Proxy (FORCEPOINT_WEBPROXY)
  • FortiGate (FORTINET_FIREWALL)
  • Fortinet FortiAnalyzer (FORTINET_FORTIANALYZER)
  • Fortinet FortiClient (FORTINET_FORTICLIENT)
  • Fortinet Switch (FORTINET_SWITCH)
  • GCP Cloud Audit (GCP_CLOUDAUDIT)
  • Security Command Center External Exposure (GCP_SECURITYCENTER_EXTERNAL_EXPOSURE)
  • Gitlab (GITLAB)
  • Google Threat Intelligence IOC (GTI_IOC)
  • AWS GuardDuty (GUARDDUTY)
  • Huawei Switches (HUAWEI_SWITCH)
  • IBM Security Access Manager (IBM_SAM)
  • Microsoft IIS (IIS)
  • Illumio Core (ILLUMIO_CORE)
  • Imperva SecureSphere Management (IMPERVA_SECURESPHERE)
  • Infoblox (INFOBLOX)
  • Infoblox DHCP (INFOBLOX_DHCP)
  • Jamf pro context (JAMF_PRO_CONTEXT)
  • Mobile Endpoint Security (LOOKOUT_MOBILE_ENDPOINT_SECURITY)
  • Apple macOS (MACOS)
  • McAfee IPS (MCAFEE_IPS)
  • Micro Focus iManager (MICROFOCUS_IMANAGER)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • Microsoft Defender for Office 365 (MICROSOFT_DEFENDER_MAIL)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Microsoft Sentinel (MICROSOFT_SENTINEL)
  • Microsoft SQL Server (MICROSOFT_SQL)
  • Mimecast URL Logs (MIMECAST_URL_LOGS)
  • MISP Threat Intelligence (MISP_IOC)
  • NetApp ONTAP (NETAPP_ONTAP)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Unix system (NIX_SYSTEM)
  • Office 365 (OFFICE_365)
  • Okta (OKTA)
  • Onapsis (ONAPSIS)
  • OpenVPN (OPEN_VPN)
  • Oracle Fusion (ORACLE_FUSION)
  • Ping Identity (PING)
  • Proofpoint Sendmail Sentrion (PROOFPOINT_SENDMAIL_SENTRION)
  • SailPoint IAM (SAILPOINT_IAM)
  • Salesforce (SALESFORCE)
  • Sendmail (SENDMAIL)
  • Sentinelone Alerts (SENTINELONE_ALERT)
  • ServiceNow Audit (SERVICENOW_AUDIT)
  • ServiceNow CMDB (SERVICENOW_CMDB)
  • ServiceNow Security (SERVICENOW_SECURITY)
  • SonicWall (SONIC_FIREWALL)
  • STIX Threat Intelligence (STIX)
  • Tanium Threat Response (TANIUM_THREAT_RESPONSE)
  • Thinkst Canary (THINKST_CANARY)
  • ThreatConnect IOC V3 (THREATCONNECT_IOC_V3)
  • ThreatLocker Platform (THREATLOCKER)
  • Varonis (VARONIS)
  • VMware ESXi (VMWARE_ESX)
  • Windows DNS (WINDOWS_DNS)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • wiz.io (WIZ_IO)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Zoom Operation Logs (ZOOM_OPERATION_LOGS)

The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.

  • Adobe Experience Platform (ADOBE_EXPERIENCE_PLATFORM)
  • AudioCodes Session Border Controller (AUDIOCODES_SBC)
  • Azure Application Gateway for Containers (AZURE_GATEWAY_CONTAINERS)
  • Azure Logic Apps (AZURE_LOGIC_APPS)
  • Azure NAT Gateway Flow (AZURE_NATGW_FLOW)
  • Broadcom DX NetOps Spectrum (BROADCOM_DX_NETOPS_SPECTRUM)
  • Carto Activity (CARTO_ACTIVITY)
  • Claude Code Observability (CLAUDE_CODE_OBSERVABILITY)
  • Cyble Attack Surface Management (CYBLE_ASM)
  • Cyble Brand Intelligence & Protection (CYBLE_BIP)
  • Darkweb IQ (DARKWEB_IQ)
  • Ellio Threat Intelligence (ELLIO_THREAT_INTEL)
  • Exeon NDR (EXEON_NDR)
  • Gravitee (GRAVITEE)
  • Kaspersky anti targeted attack (KASPERSKY_ANTI_TARGETED_ATTACK)
  • Microsoft Copilot Interaction (MICROSOFT_COPILOT_INTERACTION)
  • OSTTRA MarkitWire (OSTTRA_MARKITWIRE)
  • Proofpoint Adaptive Email Security (PROOFPOINT_ADAPTIVE_EMAIL_SECURITY)
  • Secomea GateManager (SECOMEA_GATEMANAGER)
  • Trend Micro Vision One Risk Event (TRENDMICRO_VISION_ONE_RISK_EVENT)
  • TXOne EdgeIPS (TXONE_EDGEIPS)
  • Vectra Respond UX (VECTRA_RUX)
  • Zoho CRM (ZOHO_CRM)

Feature

View prebuilt parser version content

You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is inactive, you can still see the content of the new preview version for this parser.

Google SecOps Marketplace

Change

Active Directory: Version 44.0

  • Added optional Connection Timeout and Receive Timeout parameters to configure network connectivity limits in the following action:

    • Enrich Entities

Change

Anomali ThreatStream: Version 18.0

  • Updated API output handling in the following action:

    • Enrich Entities

Change

Google Threat Intelligence: Version 20.0

  • Added support for CHILDHASH and PARENTHASH entity types in the following action:

    • Enrich Entities
  • Added Entity Type Filter parameter to allow configuring entity types for notifications in the following connector:

    • Google Threat Intelligence - Livehunt Connector

Change

Microsoft 365 Defender: Version 28.0

  • Updated case syncing logic in the following action:

    • Sync Alerts
  • Updated alert processing logic in the following connector:

    • Microsoft 365 Defender - Incidents Connector

Change

Siemplify: Version 112.0

  • Added Update Enabled Connectors Only filtering option in the following job:

    • Response Integration & Connector Upgrade Job

Change

Vertex AI: Version 8.0

  • Added support for multi-region endpoints across the integration configuration.

Google SecOps SIEM

Change

Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.

The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.

  • Airlock Digital Application Allowlisting (AIRLOCK_DIGITAL)
  • AIX system (AIX_SYSTEM)
  • Akamai DataStream 2 (AKAMAI_DATASTREAM_2)
  • Akamai SIEM Connector (AKAMAI_SIEM_CONNECTOR)
  • Apache (APACHE)
  • Arcsight CEF (ARCSIGHT_CEF)
  • Armis Alerts (ARMIS_ALERTS)
  • Aruba Switch (ARUBA_SWITCH)
  • Atlassian Cloud Admin Audit (ATLASSIAN_AUDIT)
  • Linux Auditing System (AuditD) (AUDITD)
  • Avaya Aura Experience Portal (AVAYA_AURA)
  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • AWS CloudWatch (AWS_CLOUDWATCH)
  • AWS Control Tower (AWS_CONTROL_TOWER)
  • Microsoft Azure Activity (AZURE_ACTIVITY)
  • Azure AD (AZURE_AD)
  • Azure AD Organizational Context (AZURE_AD_CONTEXT)
  • Azure Application Gateway (AZURE_GATEWAY)
  • Azure Key Vault logging (AZURE_KEYVAULT_AUDIT)
  • Microsoft Azure Resource (AZURE_RESOURCE_LOGS)
  • Blue Coat Proxy (BLUECOAT_WEBPROXY)
  • BeyondTrust (BOMGAR)
  • Cato Networks (CATO_NETWORKS)
  • Check Point (CHECKPOINT_FIREWALL)
  • Check Point Harmony (CHECKPOINT_HARMONY)
  • Chrome Management (CHROME_MANAGEMENT)
  • ChromeOS XDR (CHROMEOS_XDR)
  • Cisco ASA (CISCO_ASA_FIREWALL)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco FireSIGHT Management Center (CISCO_FIRESIGHT)
  • Cisco ISE (CISCO_ISE)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Switch (CISCO_SWITCH)
  • Cisco UCM (CISCO_UCM)
  • Claroty Xdome (CLAROTY_XDOME)
  • Claude Compliance Logs (CLAUDE_COMPLIANCE_LOGS)
  • HP Aruba (ClearPass) (CLEARPASS)
  • Cloudflare (CLOUDFLARE)
  • Palo Alto Cortex XDR Alerts (CORTEX_XDR)
  • CrowdStrike Falcon (CS_EDR)
  • Darktrace (DARKTRACE)
  • EfficientIP DDI (EFFICIENTIP_DDI)
  • F5 ASM (F5_ASM)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • Fastly CDN (FASTLY_CDN)
  • FireEye eMPS (FIREEYE_EMPS)
  • FireEye HX (FIREEYE_HX)
  • FireEye NX (FIREEYE_NX)
  • Forcepoint Proxy (FORCEPOINT_WEBPROXY)
  • FortiGate (FORTINET_FIREWALL)
  • Fortinet FortiAnalyzer (FORTINET_FORTIANALYZER)
  • Fortinet FortiClient (FORTINET_FORTICLIENT)
  • Fortinet Switch (FORTINET_SWITCH)
  • GCP Cloud Audit (GCP_CLOUDAUDIT)
  • Security Command Center External Exposure (GCP_SECURITYCENTER_EXTERNAL_EXPOSURE)
  • Gitlab (GITLAB)
  • Google Threat Intelligence IOC (GTI_IOC)
  • AWS GuardDuty (GUARDDUTY)
  • Huawei Switches (HUAWEI_SWITCH)
  • IBM Security Access Manager (IBM_SAM)
  • Microsoft IIS (IIS)
  • Illumio Core (ILLUMIO_CORE)
  • Imperva SecureSphere Management (IMPERVA_SECURESPHERE)
  • Infoblox (INFOBLOX)
  • Infoblox DHCP (INFOBLOX_DHCP)
  • Jamf pro context (JAMF_PRO_CONTEXT)
  • Mobile Endpoint Security (LOOKOUT_MOBILE_ENDPOINT_SECURITY)
  • Apple macOS (MACOS)
  • McAfee IPS (MCAFEE_IPS)
  • Micro Focus iManager (MICROFOCUS_IMANAGER)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • Microsoft Defender for Office 365 (MICROSOFT_DEFENDER_MAIL)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Microsoft Sentinel (MICROSOFT_SENTINEL)
  • Microsoft SQL Server (MICROSOFT_SQL)
  • Mimecast URL Logs (MIMECAST_URL_LOGS)
  • MISP Threat Intelligence (MISP_IOC)
  • NetApp ONTAP (NETAPP_ONTAP)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Unix system (NIX_SYSTEM)
  • Office 365 (OFFICE_365)
  • Okta (OKTA)
  • Onapsis (ONAPSIS)
  • OpenVPN (OPEN_VPN)
  • Oracle Fusion (ORACLE_FUSION)
  • Ping Identity (PING)
  • Proofpoint Sendmail Sentrion (PROOFPOINT_SENDMAIL_SENTRION)
  • SailPoint IAM (SAILPOINT_IAM)
  • Salesforce (SALESFORCE)
  • Sendmail (SENDMAIL)
  • Sentinelone Alerts (SENTINELONE_ALERT)
  • ServiceNow Audit (SERVICENOW_AUDIT)
  • ServiceNow CMDB (SERVICENOW_CMDB)
  • ServiceNow Security (SERVICENOW_SECURITY)
  • SonicWall (SONIC_FIREWALL)
  • STIX Threat Intelligence (STIX)
  • Tanium Threat Response (TANIUM_THREAT_RESPONSE)
  • Thinkst Canary (THINKST_CANARY)
  • ThreatConnect IOC V3 (THREATCONNECT_IOC_V3)
  • ThreatLocker Platform (THREATLOCKER)
  • Varonis (VARONIS)
  • VMware ESXi (VMWARE_ESX)
  • Windows DNS (WINDOWS_DNS)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • wiz.io (WIZ_IO)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Zoom Operation Logs (ZOOM_OPERATION_LOGS)

The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.

  • Adobe Experience Platform (ADOBE_EXPERIENCE_PLATFORM)
  • AudioCodes Session Border Controller (AUDIOCODES_SBC)
  • Azure Application Gateway for Containers (AZURE_GATEWAY_CONTAINERS)
  • Azure Logic Apps (AZURE_LOGIC_APPS)
  • Azure NAT Gateway Flow (AZURE_NATGW_FLOW)
  • Broadcom DX NetOps Spectrum (BROADCOM_DX_NETOPS_SPECTRUM)
  • Carto Activity (CARTO_ACTIVITY)
  • Claude Code Observability (CLAUDE_CODE_OBSERVABILITY)
  • Cyble Attack Surface Management (CYBLE_ASM)
  • Cyble Brand Intelligence & Protection (CYBLE_BIP)
  • Darkweb IQ (DARKWEB_IQ)
  • Ellio Threat Intelligence (ELLIO_THREAT_INTEL)
  • Exeon NDR (EXEON_NDR)
  • Gravitee (GRAVITEE)
  • Kaspersky anti targeted attack (KASPERSKY_ANTI_TARGETED_ATTACK)
  • Microsoft Copilot Interaction (MICROSOFT_COPILOT_INTERACTION)
  • OSTTRA MarkitWire (OSTTRA_MARKITWIRE)
  • Proofpoint Adaptive Email Security (PROOFPOINT_ADAPTIVE_EMAIL_SECURITY)
  • Secomea GateManager (SECOMEA_GATEMANAGER)
  • Trend Micro Vision One Risk Event (TRENDMICRO_VISION_ONE_RISK_EVENT)
  • TXOne EdgeIPS (TXONE_EDGEIPS)
  • Vectra Respond UX (VECTRA_RUX)
  • Zoho CRM (ZOHO_CRM)

Feature

View prebuilt parser version content

You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is inactive, you can still see the content of the new preview version for this parser.

Managed Service for Apache Airflow

Feature

Airflow 3.2.2 is available in Managed Airflow (Gen 3).

Change

(Airflow 3.2.2) The Multi-Team Airflow feature isn't available. The [core]multi_team Airflow configuration option is set to False and it isn't possible to override it.

Fixed

(Airflow 3.2.2) Backported #69877 to restore the ability to deliver failure and retry alerts through a pluggable email backend (configured through the [email]email_backend Airflow configuration option).

Change

(Managed Airflow Gen 3 with Airflow 2) Default triggerer resources are changing to 1 vCPU and 2 GB memory to match Airflow 3 defaults. This change is available in the Google Cloud CLI, Terraform, and Cloud Composer API and is gradually rolling out in the Google Cloud console.

Fixed

A correct error message is now generated when an environment creation request fails because of malformed network and subnetwork identifiers.

Fixed

(Available without upgrading) The correct default task priority weight of 1 is now shown for tasks in the Google Cloud console.

Change

New Airflow builds are available in Managed Airflow (Gen 3):

Change

New images are available in Managed Airflow (Gen 2):

Deprecated

The following Managed Airflow versions and builds have reached their end of support period: composer-3-airflow-2.10.5-build.10, composer-3-airflow-2.9.3-build.30, composer-2.13.8-airflow-2.9.3, and composer-2.13.8-airflow-2.10.5.

reCAPTCHA

Feature

The Agent overview dashboard is available on the Google Cloud Fraud Defense home page. This dashboard helps you monitor and analyze automated agent traffic on your site by distinguishing verified agents from suspected agents.

For more information, see Monitor agent traffic.