GCP News - 2026-08-12

2026-08-12
最終更新: 2026-08-27 21:31:31 JST

Google Cloud Release Notes

August 12, 2026

詳細を表示

Access Approval

Feature

Agent Identity is generally available (GA).

Access Transparency

Feature

Agent Identity is generally available (GA).

Apigee API hub

Feature

Configure and deploy MCP servers with gcloud CLI

You can use the gcloud apihub locations configure-and-deploy-server command to configure and deploy API hub Model Context Protocol (MCP) servers to an attached Apigee runtime. Define MCP tools inline or by referencing a YAML or JSON specification file to expose your API hub operations for agent integrations.

For more information, see gcloud CLI for API hub.

BigQuery

Announcement

Table Explorer behavior has moved to the Reference panel. Table Explorer has been deprecated. For more information, see "Use the Reference panel" in Run a query.

Bigtable

Feature

You can use parameterized views in Bigtable to dynamically filter data ranges for logical views based on application context and mitigate SQL injection risks. This feature is generally available (GA). For more information, see Parameterized views overview.

Feature

You can use the CLUSTER_ATTRIBUTE() filter to restrict continuous materialized view processing to specific clusters. This function lets you isolate views within an instance. This feature is generally available (GA). For more information, see Non-deterministic SQL functions.

Cloud Trace

Feature

The following remote MCP servers automatically generate a trace span for tools/call operations. These spans can help you understand the behavior of your agentic applications. For more information, see Investigate MCP calls using Trace.

  • Cloud Billing
  • Personalized Service Health

Feature

Google Cloud Observability automatically generates trace exemplars for charts on custom dashboards that display the result of a SQL query when the query runs against your trace data and satisfies some constraints. The exemplars link the SQL query result to specific traces. This feature is in Preview.

For more information, see Generate and display trace exemplars.

Cloud Workstations

Feature

Cloud Workstations supports Compute Engine suspend and resume in Preview. You can configure workstation VMs to suspend when they reach their idle timeouts, referred to as auto-sleep in the Google Cloud Console, rather than shutting down and deleting the VM, by using the IdleAction workstation configuration setting.

Gemini Enterprise

Feature

Gemini Enterprise: GitHub connector with data federation

The GitHub connector with data federation is generally available (GA) in Gemini Enterprise. The connector lets you search and act on GitHub repositories, issues, and pull requests directly from the Gemini Enterprise agent, with tool actions such as creating branches, adding issue comments, merging pull requests, and pushing files.

For more information, see the Connect GitHub with data federation documentation.

Feature

Gemini Enterprise: AlphaEvolve HPC solution

The AlphaEvolve HPC solution provides a distributed, containerized infrastructure for running large-scale evolutionary code optimization experiments on Google Cloud. If your evaluations require specialized hardware or exceed the resource limits of a single machine, use the AlphaEvolve HPC solution.

For more information, see AlphaEvolve for HPC use cases.

Gemini Enterprise Agent Platform

Feature

CodeMender CLI: Sandbox enabled by default

This release updates the CodeMender CLI default behavior:

  • Sandbox enabled by default: The CLI now runs commands inside the process-level sandbox by default to protect your workstation. You can disable the sandbox in your config.yaml, by passing --sandbox=false to CLI commands, or bypass it using the --unrestricted flag.

For more information, see Install the CLI and configure.

Google Kubernetes Engine

Change

(2026-R33) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.12-gke.1270000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1131000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

No channel (deprecated)

Security

(2026-R33) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2543000 cos-117-18613-675-28 cos-117-18613-675-28 release notes
1.32.13-gke.2231000 cos-117-18613-675-28 cos-117-18613-675-28 release notes
1.33.13-gke.1414000 cos-121-18867-528-21 cos-121-18867-528-21 release notes
1.34.10-gke.1079000 cos-125-19216-532-42 cos-125-19216-532-42 release notes
1.35.7-gke.1027000 cos-125-19216-532-25 cos-125-19216-532-25 release notes
1.36.3-gke.1244000 cos-129-19506-299-60 cos-129-19506-299-60 release notes

Change

(2026-R33) Version updates

  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.12-gke.1270000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1131000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Change

(2026-R33) Version updates

Change

(2026-R33) Version updates

Change

(2026-R33) Version updates

Change

(2026-R33) Version updates

Google SecOps

Feature

[Spotlight Feature] Analyze feed activity with Cloud Logging

This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project (BYOP) Google Cloud project. You can now monitor, debug, and troubleshoot Google SecOps ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in the Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.

This visibility into push- and pull-based ingestion mechanisms provides the following capabilities:

  • Investigate telemetry: Use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console.
  • Debug feeds: Use the Debug with logs option on the Feed management page to open Logs Explorer pre-filtered for a specific feed.
  • Filter routed logs: Configure exclusion filters in the Log Router to exclude specific logs, such as Storage Transfer Service (STS) logs, from being routed to Cloud Logging.

For more information, see Analyze feed activity with Cloud Logging.

Google SecOps Marketplace

Feature

CyberArk Credential Provider: Version 5.0

  • The following new job has been added:

    • Sync Integration Credentials Job

Feature

Microsoft Graph Mail: Version 45.0

  • The following new actions have been added:

    • Block Domain
    • Block Sender
    • Delete Inbox Rules
    • List Rules
    • Remove Block Domain
    • Remove Block Sender

Feature

Microsoft Graph Mail Delegated: Version 22.0

  • The following new actions have been added:

    • Block Domain
    • Block Sender
    • Delete Inbox Rules
    • List Rules
    • Remove Block Domain
    • Remove Block Sender

Change

Active Directory: Version 45.0

  • Fixed an issue in the following action where entity properties were incorrectly reset on update:

    • Enrich Entities

Change

AWS WAF: Version 14.0

  • Updated integration dependencies.

Change

Cisco Umbrella: Version 21.0

  • Fixed an issue in the following action where entity attachment failed due to a bytes object serialization error:

    • Get Domain Security Info

Change

CrowdStrike Falcon: Version 81.0

  • Added the ability to use device IDs as input parameters in the following actions:

    • Hide Hosts
    • Contain Endpoint
    • Download File
    • Execute Command
    • Get Host Information
    • Lift Contained Endpoint
    • List Host Vulnerabilities
    • On-Demand Scan
    • Run Script

Change

Enrichment

  • Fixed an issue in the following action where unsupported entity types were selected during enrichment:

    • Whois

Change

GitSync

  • Fixed an issue in the following action where the Include Playbook Blocks parameter was ignored when a folder allowlist was used:

    • Push Playbook

Change

Microsoft 365 Defender: Version 30.0

  • Added support for GCC High tenants by dynamically constructing API token scopes and adding a configurable API Root parameter in the following connector:

    • Microsoft 365 Defender - Incidents Connector
  • Improved error handling and alert processing mechanisms in the following job:

    • Sync Alerts

Change

Microsoft Graph Mail: Version 45.0

  • Fixed an issue in the following action where an unhandled exception occurred when a user mailbox was not found:

    • Get Mailbox Account Out Of Facility Settings

Change

Microsoft Graph Mail Delegated: Version 22.0

  • Fixed an issue in the following action where an unhandled exception occurred when a user mailbox was not found:

    • Get Mailbox Account Out Of Facility Settings

Google SecOps SIEM

Feature

[Spotlight Feature] Analyze feed activity with Cloud Logging

This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project (BYOP) Google Cloud project. You can now monitor, debug, and troubleshoot Google SecOps SIEM ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.

This visibility into push- and pull-based ingestion mechanisms provides the following capabilities:

  • Investigate telemetry: Use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console.
  • Debug feeds: Use the Debug with logs option on the Feed management page to open Logs Explorer pre-filtered for a specific feed.
  • Filter routed logs: Configure exclusion filters in the Log Router to exclude specific logs, such as Storage Transfer Service (STS) logs, from being routed to Cloud Logging.

For more information, see Analyze feed activity with Cloud Logging.

Identity and Access Management

Change

The workflow for creating workforce identity pool providers in the Google Cloud console changed. After submitting the initial provider configuration, the console directs you to a centralized page to configure provider attributes, including attribute mappings, attribute conditions, and extra attributes.

For more information, see Manage workforce identity pools and providers.

Managed Service for Apache Spark

Announcement

New Managed Service for Apache Spark (formerly Google Cloud Serverless for Apache Spark) subminor runtime versions:

  • 1.2.86
  • 2.2.86
  • 2.3.39

Key updates in these runtime versions include:

  • OpenLineage updates: In the 2.3 runtime:
    • Upgraded OpenLineage to version 1.49 to support lineage for tables created using the Lakehouse Runtime catalog.
    • Fixed a segmentation fault when OpenLineage parses complex SQL query strings.

Network Intelligence Center

Feature

Connectivity Tests supports using a Cloud Run job as a source endpoint for connectivity testing.

For more information, see Test from a Cloud Run job to a destination.

Secret Manager

Fixed

Parameter Manager enforces the location organization policy (constraints/gcp.resourceLocations) on resources in the global location.

If your organization policy restricts allowed resource locations, you must explicitly allow the global location in the policy. Otherwise, attempts to create global resources fail.

This helps ensure that Parameter Manager consistently applies the location organization policy checks to global resources.

For more information, see Defining resource locations.

Google Cloud Blog (AI & ML)

Looker’s semantic layer governs Gemini Enterprise data for user trust

詳細を表示

For organizations deploying AI agents at scale, there’s often a critical divide between structured and unstructured data. While large language models (LLMs) excel at parsing text documents, emails, and PDFs, they can struggle when presented with raw enterprise databases. Meanwhile, standard natural-language-to-SQL (NL2SQL) models often guess how database schemas fit together, which can lead to unpredictable queries, inconsistent metrics, and AI hallucinations that erode user trust. 

Gemini Enterprise brings the best of Google AI to every employee through an intuitive chat interface that acts as a single front door for AI in the workplace. And now, Looker’s governed semantic layer serves as the trusted foundation for structured data within Gemini Enterprise, enabling trusted self-service business intelligence for all Gemini Enterprise users. With this integration, Looker analysts and admins can publish conversational agents natively into their Gemini Enterprise environments via the Agent-to-Agent (A2A) protocol. Now, organizations can provide their AI-accelerated taskforce with robust and trusted tools, powered by real-time analytics, that they can explore in natural language in addition to their daily workspace workflows. Making it easy to offer conversational agents in Gemini Enterprise expands discoverability and promotes a data-driven culture, while reducing friction to adoption.

Bringing a semantic foundation to structured and unstructured data

By combining Looker’s semantic layer with Gemini Enterprise, you can query both structured databases and unstructured documents in plain English, all in one place. Instead of jumping between dashboards and other tools to understand your numbers, teams can instantly connect hard metrics with real-world context to solve problems and make decisions faster.

<div class="article-module h-c-page">
  <div class="h-c-grid">


<figure class="article-image--large
  
  
    h-c-grid__col
    h-c-grid__col--6 h-c-grid__col--offset-3
    
    
  ">

  
  
    
    <img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/1_Ei9b2UE.gif" />
    
    </a>
  
    <figcaption class="article-image__caption "><p>Publishing Looker agents for consumption in Gemini Enterprise</p></figcaption>
  
</figure>


  </div>
</div>

Minimize AI hallucinations

If you ask the typical AI chatbot to calculate "revenue" or "churn rate" against an unstructured cloud database, it has to guess which tables to join, which filters to apply, and which timestamps to trust. This can result in different people asking the same question, only to get completely different answers.

Looker’s semantic layer eliminates this guesswork, serving critical context to Gemini Enterprise in the form of codified data, allowing the agent to give deterministic, predictable responses.

code_block
<ListValue: [StructValue([('code', '[ Gemini Enterprise Chat UI ] \r\n │\r\n (A2A Protocol / NLP)\r\n ▼\r\n [ Looker Governed Agent ] ──► Generates Deterministic SQL\r\n │\r\n [ Looker Semantic Layer ] ──► Business-Approved Definitions & Logic\r\n │\r\n ▼\r\n [ Enterprise Data Cloud ] ──► (BigQuery, AlloyDB, Spanner, etc.)'), ('language', ''), ('caption', <wagtail.rich_text.RichText object at 0x7ff5dd534d90>)])]>

When a Gemini Enterprise user requests a business KPI in Gemini Enterprise, the request is routed directly to a Looker agent. The semantic layer generates deterministic, precise SQL based on version-controlled business logic. This helps ensure when an executive asks for "Revenue," they get the exact, governed enterprise metric — not a guess.

Robust governance and secure access management

Data governance and security are critical when introducing AI to enterprise data warehouses. Organizations can’t risk corporate information being loosely ingested, indexed, or exposed outside of strict permissions.

Looker’s integration with Gemini Enterprise is built on a zero-risk pass-through architecture, processing the data, but not writing to persistent storage. Gemini Enterprise does not ingest, replicate, or store your underlying database records. Instead, the integration operates safely and securely over the A2A protocol, following these core tenets:

  • OAuth authorization: In order to interact with a Looker agent within Gemini Enterprise, end users provide a secure, one-time OAuth consent. This binds their Gemini session to their specific Looker credentials.

  • Strong governance enforcement: Because the architecture relies on live pass-through queries, Looker’s existing row-level and column-level access controls are maintained.

  • Strict security isolation: If a user does not have permission to view, say, sensitive regional payroll or financial rows within the Looker platform, the Looker agent actively restricts that data in the Gemini environment. Should an agent be published to the Agent Gallery to simplify discovery, it still does not bypass the security controls that you established.

Technical capabilities and enterprise readiness

Deploying Looker agents natively into Gemini Enterprise via the A2A protocol doesn't just make it smarter — it makes it more interactive and interoperable, without sacrificing security. Here are some of the features you’ll find in this release.

Rich visual interactivity: support for charts

They say a picture is worth a thousand words. When users interact with Looker agents inside Gemini Enterprise, the platform goes beyond textual explanations and provides native, interactive data charts. If a user asks for a visual trend—such as monthly sales performance or regional distribution—the Looker agent maps the database response with rich, presentation-ready visualizations directly inside the universal chat box.

Note: If you published Looker agents in Gemini Enterprise prior to Looker release 26.12, we recommend updating or refreshing them to take advantage of these enhanced visualization capabilities.

Interoperability with first- and third-party agents

Looker agents published to Gemini Enterprise can understand context across different agents and data sources. Leveraging standard communication frameworks, these agents can securely share structured, governed insights with other first-party Google Cloud agents like the Deep Research Agent or external third-party agents to create structured workflows. This enables complex multi-agent orchestration, where an enterprise operational agent can pull data from a Looker agent to feed into a separate productivity or supply-chain workflow.

Looker-based user authentication

To preserve enterprise governance, this integration implements a robust, identity-centric authentication model. Users are required to provide a one-time OAuth consent, binding their active Gemini Enterprise session securely to their underlying Looker credentials. This helps ensure that every conversational query hitting your databases is authenticated at the user level, enforcing pre-existing Looker permission structures, row-level data access filters, and column-level masking rules — no exceptions.

Trusted data in Gemini Enterprise

The future of work is agentic. Gemini Enterprise provides a single, secure architecture to deploy a global digital task force,empowering your business with the best of Google AI for developers, employees, and customers.

The integration of Looker with Gemini Enterprise not only brings trusted data analytics to business users but also adds rich interactivity, visual charts, and data storytelling directly into their everyday workspace. As business users embrace this agentic new way of working, they aren't just getting text answers; they are getting presentation-ready visualizations that bring operational metrics to life and deliver complex insights. 

To get started, learn how to publish your data agents in Gemini Enterprise to make your agent’s predefined context and analytics available to your entire organization.