GCP News - 2026-08-14

2026-08-14
最終更新: 2026-08-27 21:31:31 JST

Google Cloud Release Notes

August 14, 2026

詳細を表示

App Engine flexible environment .NET

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine flexible environment Go

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine flexible environment Java

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine flexible environment Node.js

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine flexible environment PHP

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine flexible environment Python

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine flexible environment Ruby

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine flexible environment custom runtimes

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine standard environment Go

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine standard environment Java

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine standard environment Node.js

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine standard environment PHP

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine standard environment Python

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

App Engine standard environment Ruby

Feature

To improve security, starting in August 2026, App Engine opts your application into TLS version 1.2 and later. You can opt out until the end of August 2026. Starting in September 2026, App Engine might permanently block insecure traffic with TLS version 1.1 and earlier. For more information, see Secure minimum TLS.

Carbon Footprint

Announcement

As detailed in our 2026 Environmental Report (p. 22), Google is now using Granular Certificates purchased from the marketplace to strategically match more of our load on an hourly basis. To accurately incorporate these certificates into the Cloud customers' allocation of carbon intensity calculations, the July 2026 semi-annual methodology refresh will be delayed by one month. We will provide further updates once the revised data is available.

Cloud Logging

Announcement

The Telemetry API for logs ingestion is generally available (GA). You can ingest OTLP logs into Cloud Logging by using an OpenTelemetry Collector, an OTLP exporter, and the Telemetry API. For more information, see OTLP ingestion overview.

Compute Engine

Feature

Generally available: You can use zonal and global extension policies in VM Extension Manager to automatically install and manage extensions, such as the Ops Agent, on a fleet of VMs and to ensure consistent extension states across your project.

To improve observability of enforcement states and guest agent activities, you can view VM extension logs by using Cloud Logging. These logs help you identify and troubleshoot issues with VM extensions.

For more information, see About VM Extension Manager.

Cortex Framework

Announcement

Release 7.0.3

Fixed

  • Resolved an issue where SapBdcProductBuilder incorrectly enforced SAP-versioned sections (ecc, s4, common) in table_settings.

Gemini Enterprise

Feature

Gemini Enterprise: Gemini 3.7 Flash available in the mobile app

Gemini 3.7 Flash is generally available (GA) in the Gemini Enterprise mobile app. Mobile app users can select and use the Gemini 3.7 Flash model for their conversations within the app. To make the model available, administrators must turn on the Gemini 3.7 Flash feature toggle in the Google Cloud console.

For more information, see:

Google Kubernetes Engine

Change

(2026-R34) Version updates

GKE cluster versions have been updated.

New versions available for upgrades and new clusters.

The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades.

Rapid channel

Regular channel

Stable channel

  • Version 1.35.6-gke.1250000 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.13-gke.1011000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1287000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1057002 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1163012 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1241004 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Extended channel

No channel (deprecated)

  • Version 1.35.6-gke.1641000 is now the default version for cluster creation.
  • The following versions are now available:
  • The following node versions are now available:
  • The following versions are no longer available:
    • 1.33.13-gke.1011000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.8-gke.1278000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1287000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1057002 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1163012 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1241004 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.36.2-gke.1346000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.36.3-gke.1244000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.36.3-gke.1253000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Security

(2026-R34) Security updates

This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release.

To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image:

GKE version Container-Optimized OS version Details
1.31.14-gke.2579000 cos-117-18613-675-37 cos-117-18613-675-37 release notes
1.32.13-gke.2268000 cos-117-18613-675-37 cos-117-18613-675-37 release notes
1.33.13-gke.1462000 cos-121-18867-528-36 cos-121-18867-528-36 release notes
1.35.7-gke.1150000 cos-125-19216-532-62 cos-125-19216-532-62 release notes
1.37.0-gke.1173000+preview cos-129-19506-299-60 cos-129-19506-299-60 release notes

Change

(2026-R34) Version updates

  • Version 1.35.6-gke.1250000 is now the default version for cluster creation in the Stable channel.
  • The following versions are now available in the Stable channel:
  • The following versions are no longer available in the Stable channel:
    • 1.33.13-gke.1011000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1287000 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1057002 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1163012 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1241004 is deprecated in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Change

(2026-R34) Version updates

Change

(2026-R34) Version updates

Change

(2026-R34) Version updates

  • Version 1.35.6-gke.1641000 is now the default version for cluster creation.
  • The following versions are now available:
  • The following node versions are now available:
  • The following versions are no longer available:
    • 1.33.13-gke.1011000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.8-gke.1278000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.34.9-gke.1287000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1057002 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1163012 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.35.5-gke.1241004 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.36.2-gke.1346000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.36.3-gke.1244000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
    • 1.36.3-gke.1253000 is deprecated. This version will be removed in 90 days, or at the end of support, if sooner.
  • Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:

Change

(2026-R34) Version updates

Google SecOps

Feature

[Spotlight Feature] Monitor your data latency with the Health Hub

This feature is in public preview. The Health Hub now includes two new tables to track the ingestion latency at both the source level and the log-type level. In addition, you can select a specific source or log type to open the Data Health Deep Dive page and view detailed information about ingestion latency. For more information, see Monitor health of data sources.

Key capabilities include:

  • Improve end-to-end visibility and reduce mean time to debug (MTTD): Google SecOps calculates latency at both the source level and the log type level to improve end-to-end visibility and help reduce the mean time to debug (MTTD) for delayed logs.
  • Monitor ingestion latency by source: View the ingestion latency for each individual data source.
  • Monitor ingestion latency by log type: View the ingestion latency for each individual log type.
  • View detailed information about ingestion latency: Select a specific source or log type to open the Data Health Deep Dive page and view detailed information about ingestion latency.

Identity and Access Management

Feature

You can use custom constraints with Organization Policy to provide more granular control over specific fields for Agent Identity resources, such as agentidentity.googleapis.com/AuthProvider. For more information, see Use custom organization policies for Agent Identity. This feature is in GA.

Feature

Agent Identity VPC Service Controls (VPC Service Controls) integration is generally available. You can add the Agent Identity API (agentidentity.googleapis.com) and Agent Identity Credentials API (agentidentitycredentials.googleapis.com) to a service perimeter and specify agent identities in ingress and egress rules.

For more information, see Agent Identity overview.

Policy Controller

Change

Policy Controller version 1.24.1 is now available.

VPC Service Controls

Feature

Generally available (GA) support for the following integrations:

Google Cloud Blog (AI & ML)

Using BigQuery Graphs with measures for trusted agentic workloads

詳細を表示

When enterprises transition from using simple chat assistants to autonomous, agentic workloads, they quickly run into a hard truth: Agents are prone to inaccurate insights when working with directly raw tables. 

BigQuery Graph helps organizations move beyond flat, static tables to represent enterprises exactly how they exist in the physical world: as interconnected business entities with real-world dependencies. With the support of measures in BigQuery Graph (preview), we are unifying governed metrics with relationship mapping. This allows your agents to reason across complex dependencies captured in graphs with precision of measures.

Why relationships matter

Traditional data structures are blind to multi-hop business context, causing AI agents to make incorrect operational decisions:

  • The concrete problem: If a retailer has an agent who is asked why winter jacket sales dropped 12% in Seattle, it can query flat tables to report the what (the 12% dip). But it fails at the why because it cannot trace the relational path: Seattle ordersdistribution centerssuppliers delayed by regional storms.

  • The risk of disjointed systems: Lacking relationship context, the agent suggests an irrelevant 15% markdown campaign, needlessly eroding margins. Furthermore, maintaining separate systems - where one team maps supplier relationships in a separate graph database while another maintains SQL metrics - forces your agent to stitch these stacks together at runtime. This process is slow, expensive, and leads to inconsistent KPI calculations.

Measures in BigQuery Graph solves this by letting you map existing tables to a property graph in-place with zero ETL. This unified setup enables a logical evolution of inquiry:

  1. Metadata grounding establishes what data you have.

  2. Business metrics (measures) calculate how your business performed.

  3. Relationship mapping (graph) uncovers why it happened.

Under the hood

Historically, standard SQL joins during graph traversals duplicate rows, leading to incorrect aggregation calculations. BigQuery Graph solves this natively.

Data modelers define a MEASURE (like SUM or AVG) directly within the Property Graph DDL. Using standard SQL via the GRAPH_EXPAND function and the AGG aggregator, the engine resolves the structural graph paths before evaluating metrics. This ensures your agent is smart enough to know when it needs a calculator (SQL) and when it needs a map (graph).

Because public projects like bigquery-public-data are strictly read-only, you must map the logical property graph inside your own project using a placeholder variable (YOUR_PROJECT_ID), while directly referencing the read-only public tables as nodes and edges.

code_block
<ListValue: [StructValue([('code', '-- 1. Map the graph inside YOUR project \r\n\r\n\r\nCREATE OR REPLACE PROPERTY GRAPH `YOUR_PROJECT_ID.YOUR_DATASET.thelook_ecommerce_graph`\r\nNODE TABLES(\r\n `bigquery-public-data.thelook_ecommerce.users` AS User\r\n KEY(id)\r\n LABEL User PROPERTIES(id, city, country),\r\n `bigquery-public-data.thelook_ecommerce.orders` AS Order\r\n KEY(order_id)\r\n LABEL Order PROPERTIES(\r\n order_id, \r\n MEASURE(AVG(num_of_item)) AS avg_items_per_order,\r\n MEASURE(SUM(num_of_item)) AS total_items\r\n )\r\n)\r\nEDGE TABLES(\r\n `bigquery-public-data.thelook_ecommerce.orders` AS OrderedBy\r\n SOURCE KEY(order_id) REFERENCES Order(order_id)\r\n DESTINATION KEY(user_id) REFERENCES User(id)\r\n LABEL ORDERED_BY\r\n);\r\n\r\n-- 2. Query your new graph with standard SQL—using standard {Label}_{Property} column outputs\r\nSELECT\r\n User_city AS city,\r\n ROUND(AGG(Order_avg_items_per_order), 2) AS agg_avg_items,\r\n ROUND(AGG(Order_total_items), 2) AS agg_total_items\r\nFROM GRAPH_EXPAND("YOUR_PROJECT_ID.YOUR_DATASET.thelook_ecommerce_graph")\r\nGROUP BY User_city\r\nORDER BY agg_total_items DESC\r\nLIMIT 10;'), ('language', ''), ('caption', <wagtail.rich_text.RichText object at 0x7ff5dd464410>)])]>

Democratizing graph intelligence in BigQuery Studio

To make managing and deploying these relationship networks frictionless for both developers and business users, we have built native, intuitive operational tools directly into BigQuery Studio:

  • Visual graph modeler: A no-code, drag-and-drop interface inside BigQuery Studio that lets you visually build, edit, and map property graphs, nodes, and edges without writing complex DDL scripts manually.

<div class="article-module h-c-page">
  <div class="h-c-grid">


<figure class="article-image--large
  
  
    h-c-grid__col
    h-c-grid__col--6 h-c-grid__col--offset-3
    
    
  ">

  
  
    
    <img alt="1" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/1_CXQhslw.gif" />
    
    </a>
  
</figure>


  </div>
</div>
  • Conversational Analytics (CA) integration: Users can interact with the graph naturally. Instead of guessing table joins, Conversational Analytics agents navigate the deterministic, relationship-aware map of the graph, converting natural language questions into precise, boundary-constrained GoogleSQL or ISO GQL queries. This prevents model hallucinations and enforces semantic consistency.
<div class="article-module h-c-page">
  <div class="h-c-grid">


<figure class="article-image--large
  
  
    h-c-grid__col
    h-c-grid__col--6 h-c-grid__col--offset-3
    
    
  ">

  
  
    
    <img alt="2" src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/2_23oI53E.gif" />
    
    </a>
  
</figure>


  </div>
</div>

Unified semantics: Native Looker integration

To avoid maintaining fragmented logic stacks, business metrics must live at the data layer. By integrating Looker (LookML) natively with BigQuery Graphs as in-database analytic models, you define logic once at the core:

  • Database-managed models (sql_analytic_model_name): Point Looker directly to your database-defined BigQuery Graph using sql_analytic_model_name to map standard LookML dimensions and measures directly to your graph properties.
  • Looker-managed models (derived_analytic_model): Define your BigQuery Graph schema directly inside your LookML view using derived_analytic_model. Looker will dynamically generate and execute the SQL DDL statements to maintain the graph inside BigQuery.
  • Enterprise DevOps workflows: Manage your graph's entire lifecycle using the Looker IDE, Git-based version control, and Continuous Integration (CI). Core KPIs (like Churn Rate) remain completely identical, verified, and trusted.